Complete GitOps Project on Kubernetes | ArgoCD + GitHub Actions + Terraform (Real-World Demo)
vijay giduthuri
0:00 / 0:00
Complete GitOps Project on Kubernetes | ArgoCD + GitHub Actions + Terraform (Real-World Demo)
2ย 684 ะฟัะพัะผะพััะฐ ยท 2 ะผะตัััะฐ ะฝะฐะทะฐะด
vijay giduthuri
5,04ย ััั. ะฟะพะดะฟะธััะธะบะพะฒ
2ย 684 ะฟัะพัะผะพััะฐ ยท 2 ะผะตัััะฐ ะฝะฐะทะฐะด
๐๐ฅ๐จ๐ฎ๐๐๐ข๐ญ๐๐ก๐๐ง โ ๐
๐ฎ๐ฅ๐ฅ-๐๐ญ๐๐๐ค ๐๐ฎ๐ฅ๐ญ๐ข-๐๐ข๐๐ซ๐จ๐ฌ๐๐ซ๐ฏ๐ข๐๐๐ฌ ๐
๐จ๐จ๐-๐๐๐ฅ๐ข๐ฏ๐๐ซ๐ฒ ๐๐ฅ๐๐ญ๐๐จ๐ซ๐ฆ:
CloudKitchen is a cloud-native microservices food-delivery application where users can browse restaurants, add items to their cart, place orders, make payments, and track deliveries โ similar to Swiggy, Zomato, or Uber Eats. The main focus of this project is to showcase a complete end-to-end DevOps lifecycle on Google Cloud Platform using ๐๐ข๐ญ๐๐ฉ๐ฌ.
๐๏ธ ๐๐ซ๐๐ก๐ข๐ญ๐๐๐ญ๐ฎ๐ซ๐ โ The app is built using ๐ฆ๐ข๐๐ซ๐จ๐ฌ๐๐ซ๐ฏ๐ข๐๐๐ฌ ๐๐ซ๐๐ก๐ข๐ญ๐๐๐ญ๐ฎ๐ซ๐ with 9 services โ a React frontend and 8 Go backend services (auth, user, restaurant, menu, order, payment, delivery, notification). Data is stored in PostgreSQL with 8 separate schemas (one per service) inside a single shared database โ 12 tables in total.
๐๐๐๐ ๐๐๐ญ๐๐ญ๐ซ๐๐๐ฆ is used as an async event bus for inter-service communication (e.g., order.placed โ payment + notification services subscribe and react), and Redis handles session caching.
โธ๏ธ ๐๐ฎ๐๐๐ซ๐ง๐๐ญ๐๐ฌ & ๐๐ง๐๐ซ๐๐ฌ๐ญ๐ซ๐ฎ๐๐ญ๐ฎ๐ซ๐ โ Everything runs on ๐๐จ๐จ๐ ๐ฅ๐ ๐๐ฎ๐๐๐ซ๐ง๐๐ญ๐๐ฌ ๐๐ง๐ ๐ข๐ง๐ (๐๐๐). The GCP infrastructure (VPC, subnets, firewalls, Cloud NAT, Artifact Registry, bastion VM, and static IP) is created using ๐๐๐ซ๐ซ๐๐๐จ๐ซ๐ฆ with a clean modular structure. The application is deployed using a custom ๐๐๐ฅ๐ฆ ๐๐ก๐๐ซ๐ญ that creates 51 Kubernetes resources with one command โ 9 Deployments, 2 StatefulSets (Postgres + NATS), 12 Services, ConfigMaps, Secrets, HPAs, and one Traefik IngressRoute with path-based routing.
โ๏ธ ๐๐/๐๐ ๐ฐ๐ข๐ญ๐ก ๐๐ข๐ญ๐๐ฎ๐ ๐๐๐ญ๐ข๐จ๐ง๐ฌ + ๐๐ซ๐ ๐จ๐๐ โ Continuous Integration is handled by ๐๐ข๐ญ๐๐ฎ๐ ๐๐๐ญ๐ข๐จ๐ง๐ฌ and Continuous Delivery by ๐๐ซ๐ ๐จ๐๐ โ following the true ๐๐ข๐ญ๐๐ฉ๐ฌ pattern. The CI pipeline builds all 9 Docker images in parallel using a matrix strategy, scans them with ๐๐ซ๐ข๐ฏ๐ฒ for HIGH/CRITICAL vulnerabilities, pushes them to Artifact Registry, and commits the new image tags back to the repository. ArgoCD (running inside the cluster) detects the commit, re-renders the Helm chart, and automatically rolls out the new pods โ with zero manual kubectl or helm upgrade steps. Uses the ๐๐ฉ๐ฉ-๐จ๐-๐๐ฉ๐ฉ๐ฌ pattern with 5 child Applications managing the app, ingress, TLS, monitoring, and logging stacks.
๐ ๐๐จ๐ง๐ข๐ญ๐จ๐ซ๐ข๐ง๐ & ๐๐จ๐ ๐ ๐ข๐ง๐ โ Set up with Prometheus, Grafana, Alertmanager, Loki, and Promtail. Each service exposes a /metrics endpoint that Prometheus scrapes every 15 seconds. Grafana shows 8 custom per-service dashboards with request rate, error rate, latency (p50/p95/p99), CPU, memory, and live logs โ all on one screen. Promtail runs as a DaemonSet on every node collecting container logs and shipping them to Loki. Alertmanager fires alerts on pod failures, high 5xx error rates, high latency, or crash-loops.
๐ ๐๐๐๐๐ & ๐๐๐ โ Handled by ๐๐๐ซ๐ญ-๐ฆ๐๐ง๐๐ ๐๐ซ with ๐๐๐ญ'๐ฌ ๐๐ง๐๐ซ๐ฒ๐ฉ๐ญ. Free browser-trusted SSL certificates are issued automatically via the HTTP-01 challenge, and Traefik terminates TLS on port 443. All HTTP traffic is permanently redirected to HTTPS with a 308 Redirect middleware, and certificates auto-renew every 75 days โ zero manual intervention.
๐ ๐๐๐ & ๐๐จ๐ฆ๐๐ข๐ง ๐๐๐๐๐ฌ๐ฌ โ The application is accessible through a custom domain managed via ๐๐จ๐๐๐๐๐ฒ ๐๐๐ pointing to the Traefik LoadBalancer's static IP. All components โ the food-delivery frontend, all 8 backend APIs, ArgoCD, Grafana, Prometheus, and Alertmanager โ are accessible under the same domain with different URL paths, all secured with HTTPS.
๐ ๐๐ซ๐จ๐ฃ๐๐๐ญ ๐๐จ๐ฎ๐ซ๐๐ ๐๐จ๐๐ & ๐๐จ๐ง๐ง๐๐๐ญ ๐๐ข๐ญ๐ก ๐๐
๐ ๐๐ข๐ญ๐๐ฎ๐ ๐๐๐ฉ๐จ๐ฌ๐ข๐ญ๐จ๐ซ๐ฒ: https://github.com/vijaygiduthuri/clo...
๐ผ ๐๐ข๐ง๐ค๐๐๐๐ง: www.linkedin.com/in/vijay-giduthuri-ab9075222
โ๏ธ ๐๐๐๐ข๐ฎ๐ฆ ๐๐ฅ๐จ๐ ๐ฌ: ย ย /ย vijaygiduthuri67ย ย
#DevOps #DevSecOps #CloudComputing #GoogleCloud #GCP #GKE #Kubernetes #Microservices #CloudNative #Docker #Containers #Terraform #InfrastructureAsCode #IaC #Helm #HelmCharts #GitHubActions #CICD #ArgoCD #GitOps #AppOfApps #Traefik #IngressController #Prometheus #Grafana #Monitoring #Observability #Alertmanager #Loki #Promtail #Logging #LetsEncrypt #cert-manager #HTTPS #SSL #NATS #JetStream #EventDriven #Golang #ReactJS #PostgreSQL #Redis #Nginx #LoadBalancer #ArtifactRegistry #Trivy #SoftwareEngineering #PortfolioProject