ะŸะตั€ะตะนั‚ะธ ะบ ัะพะดะตั€ะถะธะผะพะผัƒ

Complete GitOps Project on Kubernetes | ArgoCD + GitHub Actions + Terraform (Real-World Demo)

vijay giduthuri

0:00 / 0:00

Complete GitOps Project on Kubernetes | ArgoCD + GitHub Actions + Terraform (Real-World Demo)

2ย 684 ะฟั€ะพัะผะพั‚ั€ะฐ ยท 2 ะผะตััั†ะฐ ะฝะฐะทะฐะด
vijay giduthuri
5,04ย ั‚ั‹ั. ะฟะพะดะฟะธัั‡ะธะบะพะฒ
2ย 684 ะฟั€ะพัะผะพั‚ั€ะฐ ยท 2 ะผะตััั†ะฐ ะฝะฐะทะฐะด
๐‚๐ฅ๐จ๐ฎ๐๐Š๐ข๐ญ๐œ๐ก๐ž๐ง โ€” ๐…๐ฎ๐ฅ๐ฅ-๐’๐ญ๐š๐œ๐ค ๐Œ๐ฎ๐ฅ๐ญ๐ข-๐Œ๐ข๐œ๐ซ๐จ๐ฌ๐ž๐ซ๐ฏ๐ข๐œ๐ž๐ฌ ๐…๐จ๐จ๐-๐ƒ๐ž๐ฅ๐ข๐ฏ๐ž๐ซ๐ฒ ๐๐ฅ๐š๐ญ๐Ÿ๐จ๐ซ๐ฆ: CloudKitchen is a cloud-native microservices food-delivery application where users can browse restaurants, add items to their cart, place orders, make payments, and track deliveries โ€” similar to Swiggy, Zomato, or Uber Eats. The main focus of this project is to showcase a complete end-to-end DevOps lifecycle on Google Cloud Platform using ๐†๐ข๐ญ๐Ž๐ฉ๐ฌ. ๐Ÿ—๏ธ ๐€๐ซ๐œ๐ก๐ข๐ญ๐ž๐œ๐ญ๐ฎ๐ซ๐ž โ€” The app is built using ๐ฆ๐ข๐œ๐ซ๐จ๐ฌ๐ž๐ซ๐ฏ๐ข๐œ๐ž๐ฌ ๐š๐ซ๐œ๐ก๐ข๐ญ๐ž๐œ๐ญ๐ฎ๐ซ๐ž with 9 services โ€” a React frontend and 8 Go backend services (auth, user, restaurant, menu, order, payment, delivery, notification). Data is stored in PostgreSQL with 8 separate schemas (one per service) inside a single shared database โ€” 12 tables in total. ๐๐€๐“๐’ ๐‰๐ž๐ญ๐’๐ญ๐ซ๐ž๐š๐ฆ is used as an async event bus for inter-service communication (e.g., order.placed โ†’ payment + notification services subscribe and react), and Redis handles session caching. โ˜ธ๏ธ ๐Š๐ฎ๐›๐ž๐ซ๐ง๐ž๐ญ๐ž๐ฌ & ๐ˆ๐ง๐Ÿ๐ซ๐š๐ฌ๐ญ๐ซ๐ฎ๐œ๐ญ๐ฎ๐ซ๐ž โ€” Everything runs on ๐†๐จ๐จ๐ ๐ฅ๐ž ๐Š๐ฎ๐›๐ž๐ซ๐ง๐ž๐ญ๐ž๐ฌ ๐„๐ง๐ ๐ข๐ง๐ž (๐†๐Š๐„). The GCP infrastructure (VPC, subnets, firewalls, Cloud NAT, Artifact Registry, bastion VM, and static IP) is created using ๐“๐ž๐ซ๐ซ๐š๐Ÿ๐จ๐ซ๐ฆ with a clean modular structure. The application is deployed using a custom ๐‡๐ž๐ฅ๐ฆ ๐œ๐ก๐š๐ซ๐ญ that creates 51 Kubernetes resources with one command โ€” 9 Deployments, 2 StatefulSets (Postgres + NATS), 12 Services, ConfigMaps, Secrets, HPAs, and one Traefik IngressRoute with path-based routing. โš™๏ธ ๐‚๐ˆ/๐‚๐ƒ ๐ฐ๐ข๐ญ๐ก ๐†๐ข๐ญ๐‡๐ฎ๐› ๐€๐œ๐ญ๐ข๐จ๐ง๐ฌ + ๐€๐ซ๐ ๐จ๐‚๐ƒ โ€” Continuous Integration is handled by ๐†๐ข๐ญ๐‡๐ฎ๐› ๐€๐œ๐ญ๐ข๐จ๐ง๐ฌ and Continuous Delivery by ๐€๐ซ๐ ๐จ๐‚๐ƒ โ€” following the true ๐†๐ข๐ญ๐Ž๐ฉ๐ฌ pattern. The CI pipeline builds all 9 Docker images in parallel using a matrix strategy, scans them with ๐“๐ซ๐ข๐ฏ๐ฒ for HIGH/CRITICAL vulnerabilities, pushes them to Artifact Registry, and commits the new image tags back to the repository. ArgoCD (running inside the cluster) detects the commit, re-renders the Helm chart, and automatically rolls out the new pods โ€” with zero manual kubectl or helm upgrade steps. Uses the ๐€๐ฉ๐ฉ-๐จ๐Ÿ-๐€๐ฉ๐ฉ๐ฌ pattern with 5 child Applications managing the app, ingress, TLS, monitoring, and logging stacks. ๐Ÿ“Š ๐Œ๐จ๐ง๐ข๐ญ๐จ๐ซ๐ข๐ง๐  & ๐‹๐จ๐ ๐ ๐ข๐ง๐  โ€” Set up with Prometheus, Grafana, Alertmanager, Loki, and Promtail. Each service exposes a /metrics endpoint that Prometheus scrapes every 15 seconds. Grafana shows 8 custom per-service dashboards with request rate, error rate, latency (p50/p95/p99), CPU, memory, and live logs โ€” all on one screen. Promtail runs as a DaemonSet on every node collecting container logs and shipping them to Loki. Alertmanager fires alerts on pod failures, high 5xx error rates, high latency, or crash-loops. ๐Ÿ”’ ๐‡๐“๐“๐๐’ & ๐’๐’๐‹ โ€” Handled by ๐œ๐ž๐ซ๐ญ-๐ฆ๐š๐ง๐š๐ ๐ž๐ซ with ๐‹๐ž๐ญ'๐ฌ ๐„๐ง๐œ๐ซ๐ฒ๐ฉ๐ญ. Free browser-trusted SSL certificates are issued automatically via the HTTP-01 challenge, and Traefik terminates TLS on port 443. All HTTP traffic is permanently redirected to HTTPS with a 308 Redirect middleware, and certificates auto-renew every 75 days โ€” zero manual intervention. ๐ŸŒ ๐ƒ๐๐’ & ๐ƒ๐จ๐ฆ๐š๐ข๐ง ๐€๐œ๐œ๐ž๐ฌ๐ฌ โ€” The application is accessible through a custom domain managed via ๐†๐จ๐ƒ๐š๐๐๐ฒ ๐ƒ๐๐’ pointing to the Traefik LoadBalancer's static IP. All components โ€” the food-delivery frontend, all 8 backend APIs, ArgoCD, Grafana, Prometheus, and Alertmanager โ€” are accessible under the same domain with different URL paths, all secured with HTTPS. ๐Ÿ“Œ ๐๐ซ๐จ๐ฃ๐ž๐œ๐ญ ๐’๐จ๐ฎ๐ซ๐œ๐ž ๐‚๐จ๐๐ž & ๐‚๐จ๐ง๐ง๐ž๐œ๐ญ ๐–๐ข๐ญ๐ก ๐Œ๐ž ๐Ÿ”— ๐†๐ข๐ญ๐‡๐ฎ๐› ๐‘๐ž๐ฉ๐จ๐ฌ๐ข๐ญ๐จ๐ซ๐ฒ: https://github.com/vijaygiduthuri/clo... ๐Ÿ’ผ ๐‹๐ข๐ง๐ค๐ž๐๐ˆ๐ง: www.linkedin.com/in/vijay-giduthuri-ab9075222 โœ๏ธ ๐Œ๐ž๐๐ข๐ฎ๐ฆ ๐๐ฅ๐จ๐ ๐ฌ: ย ย /ย vijaygiduthuri67ย ย  #DevOps #DevSecOps #CloudComputing #GoogleCloud #GCP #GKE #Kubernetes #Microservices #CloudNative #Docker #Containers #Terraform #InfrastructureAsCode #IaC #Helm #HelmCharts #GitHubActions #CICD #ArgoCD #GitOps #AppOfApps #Traefik #IngressController #Prometheus #Grafana #Monitoring #Observability #Alertmanager #Loki #Promtail #Logging #LetsEncrypt #cert-manager #HTTPS #SSL #NATS #JetStream #EventDriven #Golang #ReactJS #PostgreSQL #Redis #Nginx #LoadBalancer #ArtifactRegistry #Trivy #SoftwareEngineering #PortfolioProject