Agent skill

Gitops Practitioner

by FerroxLabs in FerroxLabs/wayland

GitOps expertise covering ArgoCD, Flux, declarative infrastructure management, drift detection and reconciliation, environment promotion strategies, secrets in GitOps, multi-cluster management, and…

Apache-2.0Auto-check passedDevOps & Cloud

Install Gitops Practitioner

skills CLI
$ npx skills add FerroxLabs/wayland --skill gitops-practitioner -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install FerroxLabs/wayland gitops-practitioner --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitioner .claude/skills/gitops-practitioner && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gitops-practitioner
GitHub stars
608
Token cost
~2.8k tokens
SKILL.md length
645 words
Files
1
Skills in repo
1,194
Repo updated
First seen
Licence
Apache-2.0

At a glance

GitOps expertise covering ArgoCD, Flux, declarative infrastructure management, drift detection and reconciliation, environment promotion strategies, secrets in GitOps, multi-cluster management, and…

  • Works in 5 steps: Pushing from CI instead of pulling:… → Manual kubectl edits: Changes get… → Storing secrets in Git unencrypted: Use… → …
  • The user asks about gitops practitioner
  • SKILL.md covers GitOps Principles, ArgoCD, Flux and Drift Detection, plus 8 more sections
  • Calls kubectl

What it does

Gitops Practitioner is an agent skill from FerroxLabs/wayland. GitOps expertise covering ArgoCD, Flux, declarative infrastructure management, drift detection and reconciliation, environment promotion strategies, secrets in GitOps, multi-cluster management, and progressive delivery with GitOps workflows. Use when the user asks about gitops practitioner, gitops practitioner best practices, or needs guidance on gitops practitioner implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering GitOps and Container orchestration. It works with Argo CD, Kubernetes and Git. The repository describes itself as: Wayland - The AI Agent That Perceives. Reasons. Acts. Evolves. The licence is Apache-2.0.

When your agent uses it

  • The user asks about gitops practitioner
  • Gitops practitioner best practices
  • Needs guidance on gitops practitioner implementation
  • The user needs a different specialized skill

Example prompts

  • “Use the gitops-practitioner skill to gitop expertise covering ArgoCD, Flux, declarative infrastructure management, drift detection and…”
  • “/gitops-practitioner”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Pushing from CI instead of pulling: Running kubectl apply from CI pipelines gives CI cluster credentials and bypasses reconciliation. Use…
  2. Manual kubectl edits: Changes get overwritten by reconciliation or create undetected drift. All changes go through Git.
  3. Storing secrets in Git unencrypted: Use Sealed Secrets, External Secrets Operator, or SOPS.
  4. One repo for app code and manifests: Every app commit triggers a deployment. Separate repos for source and manifests.
  5. Ignoring health checks: Without health checks, broken deployments show as "synced."

What it can do on your machine

Read from SKILL.md and the folder at commit 4c030c7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use kubectl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gitops Practitioner loads about 2.8k tokens when it runs. Until then it costs about 129 tokens; SKILL.md has 645 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~129
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from FerroxLabs/wayland at commit 4c030c7, republished under its Apache-2.0 licence (© FerroxLabs). 645 words, ~2,751 tokens.

Download SKILL.mdSave it as .claude/skills/gitops-practitioner/SKILL.md (or your agent's skills folder).
name
gitops-practitioner
description
GitOps expertise covering ArgoCD, Flux, declarative infrastructure management, drift detection and reconciliation, environment promotion strategies, secrets in GitOps, multi-cluster management, and progressive delivery with GitOps workflows. Use when the user asks about gitops practitioner, gitops practitioner best practices, or needs guidance on gitops practitioner implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.
license
Apache-2.0
metadata.author
foundry-skills
metadata.version
1.0.0
metadata.tags
devops cloud ci-cd
metadata.category
devops-cloud
metadata.subcategory
ci-cd-pipelines
metadata.disclaimer
none
metadata.difficulty
intermediate

GitOps Practitioner

You are an expert GitOps practitioner who manages infrastructure and application deployments declaratively through Git. GitOps is not just "infrastructure as code stored in Git." It is a specific operational model: Git is the single source of truth, a reconciliation loop continuously ensures the live state matches the desired state in Git, and all changes flow through pull requests.

GitOps Principles

The Four Principles
PrincipleMeaningImplementation
DeclarativeSystem state described, not scriptedKubernetes manifests, Helm charts
Versioned and ImmutableDesired state stored in GitAll config in Git, tagged releases
Pulled AutomaticallyAgents pull desired state, not pushed by CIArgoCD/Flux polls Git
Continuously ReconciledAgent corrects drift automaticallyController loop detects and fixes divergence
Push-Based vs Pull-Based
PUSH-BASED (traditional CI/CD):
  Developer -> Git -> CI Pipeline -> kubectl apply -> Cluster
  PROBLEMS:
  - CI system has cluster credentials (security risk)
  - No drift detection (manual changes go unnoticed)

PULL-BASED (GitOps):
  Developer -> Git <- Agent (in cluster) -> Cluster
  BENEFITS:
  - Agent runs INSIDE the cluster (no external credentials)
  - Continuous reconciliation (drift auto-corrected)
  - Git is the audit log

ArgoCD

Application Definition
yaml
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: my-api
  namespace: argocd
spec:
  project: default
  source:
    repoURL: [reference URL]
    targetRevision: main
    path: apps/my-api/overlays/production
  destination:
    server: [reference URL]
    namespace: my-api
  syncPolicy:
    automated:
      prune: true
      selfHeal: true
      allowEmpty: false
    syncOptions:
      - CreateNamespace=true
      - PrunePropagationPolicy=foreground
    retry:
      limit: 5
      backoff:
        duration: 5s
        factor: 2
        maxDuration: 3m
App of Apps Pattern
yaml
# root-app.yaml
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
  name: root
  namespace: argocd
spec:
  source:
    repoURL: [reference URL]
    path: apps
    targetRevision: main
  destination:
    server: [reference URL]
    namespace: argocd
  syncPolicy:
    automated:
      selfHeal: true
      prune: true
ApplicationSet
yaml
apiVersion: argoproj.io/v1alpha1
kind: ApplicationSet
metadata:
  name: cluster-apps
  namespace: argocd
spec:
  generators:
    - git:
        repoURL: [reference URL]
        revision: main
        directories:
          - path: apps/*
  template:
    metadata:
      name: '{{path.basename}}'
    spec:
      project: default
      source:
        repoURL: [reference URL]
        targetRevision: main
        path: '{{path}}'
      destination:
        server: [reference URL]
        namespace: '{{path.basename}}'
      syncPolicy:
        automated:
          prune: true
          selfHeal: true

Flux

Core Resources
yaml
apiVersion: source.toolkit.fluxcd.io/v1
kind: GitRepository
metadata:
  name: my-app
  namespace: flux-system
spec:
  interval: 1m
  url: [reference URL]
  ref:
    branch: main
---
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
  name: my-app
  namespace: flux-system
spec:
  interval: 5m
  path: ./apps/my-api/production
  prune: true
  sourceRef:
    kind: GitRepository
    name: my-app
  healthChecks:
    - apiVersion: apps/v1
      kind: Deployment
      name: my-api
      namespace: my-api
ArgoCD vs Flux
FeatureArgoCDFlux
UIFull web UINo built-in UI (use Weave GitOps)
Multi-clusterCentral control planeEach cluster runs its own Flux
RBACGranular per-app/projectKubernetes-native RBAC
Image automationArgoCD Image UpdaterBuilt-in Image Automation
Best forTeams wanting UI, multi-clusterKubernetes-native, composable

Drift Detection

Types of Drift
Drift TypeCauseFix
Configuration driftManual kubectl editselfHeal auto-reverts
Desired state driftGit not updated after changeUpdate Git to match intent
Image driftContainer updated outside GitUpdate Git with new image tag
Ignoring Managed Fields
yaml
# ArgoCD: Ignore fields managed by controllers
spec:
  ignoreDifferences:
    - group: apps
      kind: Deployment
      jsonPointers:
        - /spec/replicas       # Let HPA manage replicas
    - group: ""
      kind: Service
      jqPathExpressions:
        - .spec.clusterIP      # Assigned by Kubernetes

Environment Promotion

repo/
├── base/
│   ├── deployment.yaml
│   ├── service.yaml
│   └── kustomization.yaml
├── overlays/
│   ├── dev/
│   │   └── kustomization.yaml
│   ├── staging/
│   │   └── kustomization.yaml
│   └── production/
│       └── kustomization.yaml

Promotion is a PR that updates the overlay for the target environment:

yaml
# overlays/production/kustomization.yaml
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
  - ../../base
patches:
  - target:
      kind: Deployment
      name: my-api
    patch: |
      - op: replace
        path: /spec/replicas
        value: 3
      - op: replace
        path: /spec/template/spec/containers/0/image
        value: registry.com/my-api:v1.2.3
Automated Image Updates (Flux)
yaml
apiVersion: image.toolkit.fluxcd.io/v1beta2
kind: ImagePolicy
metadata:
  name: my-api
spec:
  imageRepositoryRef:
    name: my-api
  policy:
    semver:
      range: ">=1.0.0"
---
apiVersion: image.toolkit.fluxcd.io/v1beta1
kind: ImageUpdateAutomation
metadata:
  name: my-api
spec:
  interval: 5m
  sourceRef:
    kind: GitRepository
    name: my-app
  git:
    commit:
      author:
        name: fluxbot
        email: flux@company.com
      messageTemplate: "chore: update my-api to {{.NewImage}}"
    push:
      branch: main
  update:
    path: ./apps/my-api
    strategy: Setters

Secrets in GitOps

ApproachToolHow It Works
Sealed SecretsBitnamiEncrypt secrets; only cluster can decrypt
External SecretsESOSync from Vault/AWS SM/GCP SM
SOPSMozilla SOPSEncrypt files in Git with KMS
yaml
# External Secrets Operator
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
  name: my-api-secrets
spec:
  refreshInterval: 5m
  secretStoreRef:
    name: aws-secretsmanager
    kind: ClusterSecretStore
  target:
    name: my-api-secrets
  data:
    - secretKey: DATABASE_URL
      remoteRef:
        key: production/my-api
        property: database_url

Common Anti-Patterns

  1. Pushing from CI instead of pulling: Running kubectl apply from CI pipelines gives CI cluster credentials and bypasses reconciliation. Use CI to update Git; let the agent deploy.

  2. Manual kubectl edits: Changes get overwritten by reconciliation or create undetected drift. All changes go through Git.

  3. Storing secrets in Git unencrypted: Use Sealed Secrets, External Secrets Operator, or SOPS.

  4. One repo for app code and manifests: Every app commit triggers a deployment. Separate repos for source and manifests.

  5. Ignoring health checks: Without health checks, broken deployments show as "synced."

Show full SKILL.md (273 more words)Show less

GitOps Checklist

  • GitOps agent installed (ArgoCD or Flux) in each cluster
  • Manifests in dedicated Git repo (separate from app source)
  • Kustomize overlays per environment
  • Auto-sync with selfHeal and prune enabled
  • Drift detection alerting configured
  • Secrets via External Secrets Operator or Sealed Secrets
  • Health checks configured for all applications
  • RBAC configured for sync/supersede permissions
  • Image update automation for non-production environments
  • PR-based promotion workflow documented
  • Notifications on sync failures (Slack/Teams)
  • Disaster recovery tested (restore cluster from Git)

When to Use

Use this skill when:

  • Designing or implementing gitops practitioner solutions
  • Reviewing or improving existing gitops practitioner approaches
  • Making architectural or implementation decisions about gitops practitioner
  • Learning gitops practitioner patterns and best practices
  • Troubleshooting gitops practitioner-related issues

Do NOT use this skill when:

  • The question is about a fundamentally different technology domain
  • A more specific sibling skill covers the exact topic needed
  • The user needs a complete hands-on tutorial rather than expert guidance

Output Format

markdown
# Gitops Practitioner Analysis

## Context Assessment
[Situation summary and constraints]

## Recommended Approach
[Primary recommendation with rationale]

## Implementation Steps
1. [Step with specific details]
2. [Step with specific details]
3. [Step with specific details]

## Trade-offs and Considerations
- [Key trade-off 1]
- [Key trade-off 2]

## Next Steps
- [Immediate action item]
- [Follow-up action item]

Example

Input: "Help me implement gitops practitioner for a medium-scale production application"

Output: A structured analysis covering current state assessment, recommended gitops practitioner approach with specific patterns, implementation roadmap with milestones, and risk mitigation strategies tailored to the application scale and constraints.

Edge Cases

  • Legacy system integration: When gitops practitioner must coexist with legacy approaches, provide a gradual migration path rather than a complete rewrite
  • Scale mismatch: When the solution complexity exceeds the project scale, recommend a simpler approach and note when to revisit
  • Team skill gaps: When the team lacks experience with the recommended approach, include learning resources and simpler alternatives
  • Conflicting requirements: When constraints conflict (e.g., performance vs. maintainability), explicitly state the trade-off and recommend based on stated priorities

© FerroxLabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitioner of FerroxLabs/wayland.

Open the folder on GitHubat commit 4c030c7

Compare with similar skills

Gitops Practitioner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gitops Practitioner compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gitops Practitioner this skillFerroxLabs/wayland608—~2.8kAutomated safety check: PassApache-2.0
GitOps with ArgoCD and Fluxwshobson/agents40k11 repos~1.5kAutomated safety check: PassMIT
Argocd GitopsBagelHole/DevOps-Security-Agent-Skills1.1k—~2.4kAutomated safety check: PassMIT
Implementing Gitopsancoleman/ai-design-components526—~2.9kAutomated safety check: PassMIT
Argocd Gitopssickn33/agentic-awesome-skills47k1 repos~2.6kAutomated safety check: PassMIT
Kubernetes ArchitectCybereason-Public/owLSM2808 repos~2.6kAutomated safety check: PassGPL-2.0

Similar skills

  • Sets up GitOps continuous delivery for Kubernetes with ArgoCD or Flux, covering installation, repository layout, sync policies, progressive delivery and secrets.

    40k GitHub starsUsed in 11 repos~1.5k tokens
    DevOps & CloudAuto-check passed
  • Argocd Gitops

    BagelHole/DevOps-Security-Agent-Skills

    Implement GitOps with ArgoCD for declarative Kubernetes deployments.

    1.1k GitHub stars~2.4k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • Implementing Gitops

    ancoleman/ai-design-components

    Implement GitOps continuous delivery for Kubernetes using ArgoCD or Flux.

    526 GitHub stars~2.9k tokensUpdated 10 mo ago
    DevOps & CloudAuto-check passed
  • Argocd Gitops

    sickn33/agentic-awesome-skills

    Implement GitOps with ArgoCD for declarative Kubernetes deployments.

    47k GitHub starsUsed in 1 repo~2.6k tokens
    DevOps & CloudAuto-check passed
  • Kubernetes Architect

    Cybereason-Public/owLSM

    Expert Kubernetes architect specializing in cloud-native infrastructure, advanced GitOps workflows (ArgoCD/Flux), and enterprise container orchestration.

    280 GitHub starsUsed in 8 repos~2.6k tokens
    DevOps & CloudAuto-check passed
  • Kubernetes Specialist

    Jeffallan/claude-skills

    Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    DevOps & CloudAuto-check passed

More from FerroxLabs/wayland

All 1,194 skills in this repo
  • Star Office Helper

    FerroxLabs/wayland

    Install, start, connect, and troubleshoot visualization companion projects for Aion/OpenClaw, with Star-Office-UI as the default recommendation.

    608 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check: notes
  • Openclaw Setup

    FerroxLabs/wayland

    OpenClaw usage expert: Helps you install, deploy, configure, and use OpenClaw personal AI assistant.

    608 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Tvcontrol Setup

    FerroxLabs/wayland

    Set up TVControl end to end: install the connector, start TradingView Desktop with its control port open, load a watchlist export, add the indicators they use, and leave a working chart.

    608 GitHub stars~5.7k tokensUpdated yesterday
    Auto-check passed
  • Ab Testing Specialist

    FerroxLabs/wayland

    End-to-end guide for designing, running, and analyzing A/B tests including experiment design, statistical significance, sample size calculation, common pitfalls, and advanced testing patterns.

    608 GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Academic Writer

    FerroxLabs/wayland

    Complete academic writing guide covering thesis and dissertation structure, journal article format using IMRaD, literature review methodology, citation management, the peer review process, and…

    608 GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Accessibility Auditor

    FerroxLabs/wayland

    Web accessibility expertise covering WCAG 2.2 conformance, audit methodology, ARIA patterns, keyboard navigation, screen reader testing, focus management, form accessibility, and automated vs manual…

    608 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Gitops Practitioner

What does Gitops Practitioner do?

GitOps expertise covering ArgoCD, Flux, declarative infrastructure management, drift detection and reconciliation, environment promotion strategies, secrets in GitOps, multi-cluster management, and…. Gitops Practitioner is an agent skill from FerroxLabs/wayland. GitOps expertise covering ArgoCD, Flux, declarative infrastructure management, drift detection and reconciliation, environment promotion strategies, secrets in GitOps, multi-cluster management, and progressive delivery with GitOps workflows.

When should I use Gitops Practitioner?

Gitops Practitioner fits situations like: the user asks about gitops practitioner; gitops practitioner best practices; needs guidance on gitops practitioner implementation; the user needs a different specialized skill.

How do I install Gitops Practitioner in Claude Code?

Run `npx skills add FerroxLabs/wayland --skill gitops-practitioner -a claude-code`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitioner in FerroxLabs/wayland) into .claude/skills/gitops-practitioner in your project. Claude Code loads it when a task matches its description.

How do I install Gitops Practitioner in Codex?

Run `npx skills add FerroxLabs/wayland --skill gitops-practitioner -a codex`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitioner in FerroxLabs/wayland) into .agents/skills/gitops-practitioner in your project. Codex loads it when a task matches its description.

Can I use Gitops Practitioner in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add FerroxLabs/wayland --skill gitops-practitioner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gitops-practitioner, .gemini/skills/gitops-practitioner, .github/skills/gitops-practitioner and .opencode/skills/gitops-practitioner in your project.

What does Gitops Practitioner need to run?

Going by SKILL.md and its folder, Gitops Practitioner needs the command-line tools its instructions call (kubectl).

Does Gitops Practitioner access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Gitops Practitioner safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Gitops Practitioner use?

Gitops Practitioner is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gitops Practitioner use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Gitops Practitioner?

Skills that share tags, products or a category with Gitops Practitioner: GitOps with ArgoCD and Flux (wshobson/agents, 40k stars), Argocd Gitops (BagelHole/DevOps-Security-Agent-Skills, 1.1k stars), Implementing Gitops (ancoleman/ai-design-components, 526 stars) and Argocd Gitops (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gitops Practitioner?

FerroxLabs (a GitHub user) maintains it in FerroxLabs/wayland, which has 608 GitHub stars. The repository holds 1,194 skills in this directory. The repository was last updated on October 6, 2026.

Source: FerroxLabs/wayland on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.