GitOps at Scale: Implementing ArgoCD for 500+ Daily Deployments on EKS
As engineering teams scale, traditional CI/CD pipelines often become the biggest bottleneck. Here is how we decoupled CI from CD and adopted a pull-based GitOps architecture with ArgoCD to support over 500 production deployments a day.
The Push-Based Pipeline Bottleneck
In a traditional "push-based" model, your CI server (like Jenkins or GitHub Actions) is responsible for building the artifact and then authenticating with your Kubernetes cluster to run kubectl apply or helm upgrade.
This works fine for a few microservices, but as you scale past 50+ services, you encounter several systemic issues:
- Security: The CI server requires god-mode credentials to the production cluster.
- Drift: If someone manually edits a resource in the cluster, the CI server doesn't know until the next deployment.
- Concurrency: Multiple pipelines trying to deploy simultaneously often cause state locks and race conditions.
Enter GitOps and ArgoCD
GitOps is a paradigm where a Git repository acts as the single source of truth for your infrastructure and application state. ArgoCD is a declarative, GitOps continuous delivery tool specifically built for Kubernetes.
Instead of the CI server pushing to the cluster, the CI server simply updates a Git repository containing Kubernetes manifests (or Helm charts). ArgoCD, running inside the cluster, detects the change, pulls the new manifests, and reconciles the cluster state to match the Git state.
The Architecture
Our target architecture separated the Application code from the Infrastructure/Deployment configuration.
# 1. Developer pushes code to application repo
# 2. CI builds Docker Image & pushes to ECR
# 3. CI updates the image tag in the manifests repo
git commit -m "chore: bump user-service to v1.2.4"
git push origin mainArgoCD continuously monitors this manifests repository. Within 3 minutes of the commit, ArgoCD initiates a synchronization, applying the new deployment manifest natively within the cluster.
The Results: Developer Velocity
By migrating to ArgoCD, we saw immediate, measurable benefits:
- Zero CI/CD Security Risk: External CI systems no longer need AWS IAM access to the EKS cluster.
- Instant Rollbacks: Reverting a bad deployment is as simple as running
git reverton the manifests repo. ArgoCD instantly syncs the cluster back to the previous known-good state. - Configuration Drift Eliminated: Manual changes made via
kubectlare instantly detected as "Out of Sync" and can be automatically overwritten by ArgoCD.
Struggling with Complex Deployments?
Velocity Stream specializes in building self-service Internal Developer Platforms (IDPs) and GitOps pipelines that let your engineers focus on shipping features, not debugging deployments.
Schedule a Platform Consultation
