GitOps with ArgoCD and Flux
wshobson/agents
Sets up GitOps continuous delivery for Kubernetes with ArgoCD or Flux, covering installation, repository layout, sync policies, progressive delivery and secrets.
GitOps expertise covering ArgoCD, Flux, declarative infrastructure management, drift detection and reconciliation, environment promotion strategies, secrets in GitOps, multi-cluster management, and…
$ npx skills add FerroxLabs/wayland --skill gitops-practitioner -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install FerroxLabs/wayland gitops-practitioner --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitioner .claude/skills/gitops-practitioner && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "gitops-practitioner" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitioner into .claude/skills/gitops-practitioner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gitops-practitioner", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitionerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add FerroxLabs/wayland --skill gitops-practitioner -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install FerroxLabs/wayland gitops-practitioner --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .agents/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitioner .agents/skills/gitops-practitioner && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "gitops-practitioner" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitioner into .agents/skills/gitops-practitioner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gitops-practitioner", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add FerroxLabs/wayland --skill gitops-practitioner -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install FerroxLabs/wayland gitops-practitioner --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitioner .cursor/skills/gitops-practitioner && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "gitops-practitioner" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitioner into .cursor/skills/gitops-practitioner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gitops-practitioner", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/FerroxLabs/wayland.git --path src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitioner--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add FerroxLabs/wayland --skill gitops-practitioner -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install FerroxLabs/wayland gitops-practitioner --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitioner .gemini/skills/gitops-practitioner && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "gitops-practitioner" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitioner into .gemini/skills/gitops-practitioner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gitops-practitioner", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install FerroxLabs/wayland gitops-practitionerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add FerroxLabs/wayland --skill gitops-practitioner -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .github/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitioner .github/skills/gitops-practitioner && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "gitops-practitioner" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitioner into .github/skills/gitops-practitioner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gitops-practitioner", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add FerroxLabs/wayland --skill gitops-practitioner -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install FerroxLabs/wayland gitops-practitioner --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitioner .opencode/skills/gitops-practitioner && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "gitops-practitioner" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitioner into .opencode/skills/gitops-practitioner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gitops-practitioner", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
gitops-practitionerGitOps expertise covering ArgoCD, Flux, declarative infrastructure management, drift detection and reconciliation, environment promotion strategies, secrets in GitOps, multi-cluster management, and…
Gitops Practitioner is an agent skill from FerroxLabs/wayland. GitOps expertise covering ArgoCD, Flux, declarative infrastructure management, drift detection and reconciliation, environment promotion strategies, secrets in GitOps, multi-cluster management, and progressive delivery with GitOps workflows. Use when the user asks about gitops practitioner, gitops practitioner best practices, or needs guidance on gitops practitioner implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering GitOps and Container orchestration. It works with Argo CD, Kubernetes and Git. The repository describes itself as: Wayland - The AI Agent That Perceives. Reasons. Acts. Evolves. The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4c030c7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
kubectlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use kubectl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Gitops Practitioner loads about 2.8k tokens when it runs. Until then it costs about 129 tokens; SKILL.md has 645 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from FerroxLabs/wayland at commit 4c030c7, republished under its Apache-2.0 licence (© FerroxLabs). 645 words, ~2,751 tokens.
.claude/skills/gitops-practitioner/SKILL.md (or your agent's skills folder).You are an expert GitOps practitioner who manages infrastructure and application deployments declaratively through Git. GitOps is not just "infrastructure as code stored in Git." It is a specific operational model: Git is the single source of truth, a reconciliation loop continuously ensures the live state matches the desired state in Git, and all changes flow through pull requests.
| Principle | Meaning | Implementation |
|---|---|---|
| Declarative | System state described, not scripted | Kubernetes manifests, Helm charts |
| Versioned and Immutable | Desired state stored in Git | All config in Git, tagged releases |
| Pulled Automatically | Agents pull desired state, not pushed by CI | ArgoCD/Flux polls Git |
| Continuously Reconciled | Agent corrects drift automatically | Controller loop detects and fixes divergence |
PUSH-BASED (traditional CI/CD):
Developer -> Git -> CI Pipeline -> kubectl apply -> Cluster
PROBLEMS:
- CI system has cluster credentials (security risk)
- No drift detection (manual changes go unnoticed)
PULL-BASED (GitOps):
Developer -> Git <- Agent (in cluster) -> Cluster
BENEFITS:
- Agent runs INSIDE the cluster (no external credentials)
- Continuous reconciliation (drift auto-corrected)
- Git is the audit logapiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: my-api
namespace: argocd
spec:
project: default
source:
repoURL: [reference URL]
targetRevision: main
path: apps/my-api/overlays/production
destination:
server: [reference URL]
namespace: my-api
syncPolicy:
automated:
prune: true
selfHeal: true
allowEmpty: false
syncOptions:
- CreateNamespace=true
- PrunePropagationPolicy=foreground
retry:
limit: 5
backoff:
duration: 5s
factor: 2
maxDuration: 3m# root-app.yaml
apiVersion: argoproj.io/v1alpha1
kind: Application
metadata:
name: root
namespace: argocd
spec:
source:
repoURL: [reference URL]
path: apps
targetRevision: main
destination:
server: [reference URL]
namespace: argocd
syncPolicy:
automated:
selfHeal: true
prune: trueapiVersion: argoproj.io/v1alpha1
kind: ApplicationSet
metadata:
name: cluster-apps
namespace: argocd
spec:
generators:
- git:
repoURL: [reference URL]
revision: main
directories:
- path: apps/*
template:
metadata:
name: '{{path.basename}}'
spec:
project: default
source:
repoURL: [reference URL]
targetRevision: main
path: '{{path}}'
destination:
server: [reference URL]
namespace: '{{path.basename}}'
syncPolicy:
automated:
prune: true
selfHeal: trueapiVersion: source.toolkit.fluxcd.io/v1
kind: GitRepository
metadata:
name: my-app
namespace: flux-system
spec:
interval: 1m
url: [reference URL]
ref:
branch: main
---
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: my-app
namespace: flux-system
spec:
interval: 5m
path: ./apps/my-api/production
prune: true
sourceRef:
kind: GitRepository
name: my-app
healthChecks:
- apiVersion: apps/v1
kind: Deployment
name: my-api
namespace: my-api| Feature | ArgoCD | Flux |
|---|---|---|
| UI | Full web UI | No built-in UI (use Weave GitOps) |
| Multi-cluster | Central control plane | Each cluster runs its own Flux |
| RBAC | Granular per-app/project | Kubernetes-native RBAC |
| Image automation | ArgoCD Image Updater | Built-in Image Automation |
| Best for | Teams wanting UI, multi-cluster | Kubernetes-native, composable |
| Drift Type | Cause | Fix |
|---|---|---|
| Configuration drift | Manual kubectl edit | selfHeal auto-reverts |
| Desired state drift | Git not updated after change | Update Git to match intent |
| Image drift | Container updated outside Git | Update Git with new image tag |
# ArgoCD: Ignore fields managed by controllers
spec:
ignoreDifferences:
- group: apps
kind: Deployment
jsonPointers:
- /spec/replicas # Let HPA manage replicas
- group: ""
kind: Service
jqPathExpressions:
- .spec.clusterIP # Assigned by Kubernetesrepo/
├── base/
│ ├── deployment.yaml
│ ├── service.yaml
│ └── kustomization.yaml
├── overlays/
│ ├── dev/
│ │ └── kustomization.yaml
│ ├── staging/
│ │ └── kustomization.yaml
│ └── production/
│ └── kustomization.yamlPromotion is a PR that updates the overlay for the target environment:
# overlays/production/kustomization.yaml
apiVersion: kustomize.config.k8s.io/v1beta1
kind: Kustomization
resources:
- ../../base
patches:
- target:
kind: Deployment
name: my-api
patch: |
- op: replace
path: /spec/replicas
value: 3
- op: replace
path: /spec/template/spec/containers/0/image
value: registry.com/my-api:v1.2.3apiVersion: image.toolkit.fluxcd.io/v1beta2
kind: ImagePolicy
metadata:
name: my-api
spec:
imageRepositoryRef:
name: my-api
policy:
semver:
range: ">=1.0.0"
---
apiVersion: image.toolkit.fluxcd.io/v1beta1
kind: ImageUpdateAutomation
metadata:
name: my-api
spec:
interval: 5m
sourceRef:
kind: GitRepository
name: my-app
git:
commit:
author:
name: fluxbot
email: flux@company.com
messageTemplate: "chore: update my-api to {{.NewImage}}"
push:
branch: main
update:
path: ./apps/my-api
strategy: Setters| Approach | Tool | How It Works |
|---|---|---|
| Sealed Secrets | Bitnami | Encrypt secrets; only cluster can decrypt |
| External Secrets | ESO | Sync from Vault/AWS SM/GCP SM |
| SOPS | Mozilla SOPS | Encrypt files in Git with KMS |
# External Secrets Operator
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: my-api-secrets
spec:
refreshInterval: 5m
secretStoreRef:
name: aws-secretsmanager
kind: ClusterSecretStore
target:
name: my-api-secrets
data:
- secretKey: DATABASE_URL
remoteRef:
key: production/my-api
property: database_urlPushing from CI instead of pulling: Running kubectl apply from CI pipelines gives CI cluster credentials and bypasses reconciliation. Use CI to update Git; let the agent deploy.
Manual kubectl edits: Changes get overwritten by reconciliation or create undetected drift. All changes go through Git.
Storing secrets in Git unencrypted: Use Sealed Secrets, External Secrets Operator, or SOPS.
One repo for app code and manifests: Every app commit triggers a deployment. Separate repos for source and manifests.
Ignoring health checks: Without health checks, broken deployments show as "synced."
Use this skill when:
Do NOT use this skill when:
# Gitops Practitioner Analysis
## Context Assessment
[Situation summary and constraints]
## Recommended Approach
[Primary recommendation with rationale]
## Implementation Steps
1. [Step with specific details]
2. [Step with specific details]
3. [Step with specific details]
## Trade-offs and Considerations
- [Key trade-off 1]
- [Key trade-off 2]
## Next Steps
- [Immediate action item]
- [Follow-up action item]Input: "Help me implement gitops practitioner for a medium-scale production application"
Output: A structured analysis covering current state assessment, recommended gitops practitioner approach with specific patterns, implementation roadmap with milestones, and risk mitigation strategies tailored to the application scale and constraints.
© FerroxLabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitioner of FerroxLabs/wayland.
Open the folder on GitHubat commit 4c030c7
Gitops Practitioner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Gitops Practitioner this skillFerroxLabs/wayland | 608 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| GitOps with ArgoCD and Fluxwshobson/agents | 40k | 11 repos | ~1.5k | Automated safety check: Pass | MIT | |
| Argocd GitopsBagelHole/DevOps-Security-Agent-Skills | 1.1k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Implementing Gitopsancoleman/ai-design-components | 526 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Argocd Gitopssickn33/agentic-awesome-skills | 47k | 1 repos | ~2.6k | Automated safety check: Pass | MIT | |
| Kubernetes ArchitectCybereason-Public/owLSM | 280 | 8 repos | ~2.6k | Automated safety check: Pass | GPL-2.0 |
wshobson/agents
Sets up GitOps continuous delivery for Kubernetes with ArgoCD or Flux, covering installation, repository layout, sync policies, progressive delivery and secrets.
BagelHole/DevOps-Security-Agent-Skills
Implement GitOps with ArgoCD for declarative Kubernetes deployments.
ancoleman/ai-design-components
Implement GitOps continuous delivery for Kubernetes using ArgoCD or Flux.
sickn33/agentic-awesome-skills
Implement GitOps with ArgoCD for declarative Kubernetes deployments.
Cybereason-Public/owLSM
Expert Kubernetes architect specializing in cloud-native infrastructure, advanced GitOps workflows (ArgoCD/Flux), and enterprise container orchestration.
Jeffallan/claude-skills
Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.
FerroxLabs/wayland
Install, start, connect, and troubleshoot visualization companion projects for Aion/OpenClaw, with Star-Office-UI as the default recommendation.
FerroxLabs/wayland
OpenClaw usage expert: Helps you install, deploy, configure, and use OpenClaw personal AI assistant.
FerroxLabs/wayland
Set up TVControl end to end: install the connector, start TradingView Desktop with its control port open, load a watchlist export, add the indicators they use, and leave a working chart.
FerroxLabs/wayland
End-to-end guide for designing, running, and analyzing A/B tests including experiment design, statistical significance, sample size calculation, common pitfalls, and advanced testing patterns.
FerroxLabs/wayland
Complete academic writing guide covering thesis and dissertation structure, journal article format using IMRaD, literature review methodology, citation management, the peer review process, and…
FerroxLabs/wayland
Web accessibility expertise covering WCAG 2.2 conformance, audit methodology, ARIA patterns, keyboard navigation, screen reader testing, focus management, form accessibility, and automated vs manual…
Works with
Categories
GitOps expertise covering ArgoCD, Flux, declarative infrastructure management, drift detection and reconciliation, environment promotion strategies, secrets in GitOps, multi-cluster management, and…. Gitops Practitioner is an agent skill from FerroxLabs/wayland. GitOps expertise covering ArgoCD, Flux, declarative infrastructure management, drift detection and reconciliation, environment promotion strategies, secrets in GitOps, multi-cluster management, and progressive delivery with GitOps workflows.
Gitops Practitioner fits situations like: the user asks about gitops practitioner; gitops practitioner best practices; needs guidance on gitops practitioner implementation; the user needs a different specialized skill.
Run `npx skills add FerroxLabs/wayland --skill gitops-practitioner -a claude-code`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitioner in FerroxLabs/wayland) into .claude/skills/gitops-practitioner in your project. Claude Code loads it when a task matches its description.
Run `npx skills add FerroxLabs/wayland --skill gitops-practitioner -a codex`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/devops-cloud/gitops-practitioner in FerroxLabs/wayland) into .agents/skills/gitops-practitioner in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add FerroxLabs/wayland --skill gitops-practitioner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gitops-practitioner, .gemini/skills/gitops-practitioner, .github/skills/gitops-practitioner and .opencode/skills/gitops-practitioner in your project.
Going by SKILL.md and its folder, Gitops Practitioner needs the command-line tools its instructions call (kubectl).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Gitops Practitioner is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Gitops Practitioner: GitOps with ArgoCD and Flux (wshobson/agents, 40k stars), Argocd Gitops (BagelHole/DevOps-Security-Agent-Skills, 1.1k stars), Implementing Gitops (ancoleman/ai-design-components, 526 stars) and Argocd Gitops (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
FerroxLabs (a GitHub user) maintains it in FerroxLabs/wayland, which has 608 GitHub stars. The repository holds 1,194 skills in this directory. The repository was last updated on October 6, 2026.
Source: FerroxLabs/wayland on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.