Skip to main content

Run development GitOps and UAT

Use this how-to after an implementation pull request has passed its delivery gates. It separates image production, development deployment, acceptance testing, and production promotion.

What you will need​

  • The exact application commit and successful image-publication evidence
  • Immutable Nebula and Singularity image digests
  • Access to the rendered GitOps repository and its review workflow
  • The required journey IDs for the Feature or release candidate
  • The development endpoint after Argo CD reconciliation

Repository contract​

RepositoryResponsibilityArgo CD deploys it
corp-v1-aerosimApplication source, local tests, CI, OCI imagesNo
gondor-v1-tmpl-aerosimSingle-environment Copier/Jinja source, rendered separately for each environmentNo
gondor-v1-aerosim-devRendered development desired state onlyYes — development only
gondor-v1-aerosimRendered production desired state onlyYes — production only
corp-v1-aerosim-e2epnpm/Playwright journeys and evidence contractNo

The template represents one environment. Render it once with development inputs into gondor-v1-aerosim-dev, and render it separately with approved production inputs into gondor-v1-aerosim. Do not combine both environments in one rendered repository or copy rendered output between them.

The two targets are isolated on the Gondor Kubernetes cluster:

EnvironmentRendered repositoryNamespaceHost
Developmentgondor-v1-aerosim-devaerosim-developmenthttps://aerosim-dev.apps.lego-cloud.eu
Productiongondor-v1-aerosimaerosimhttps://aerosim.apps.lego-cloud.eu

Argo CD reconciles development through foundation Application 0630-aerosim-development-foundation and runtime Application 0640-aerosim-development. Development keeps its separate disposable PostgreSQL emptyDir and ExternalSecrets references to the existing Bitwarden ClusterSecretStore. Delivery owns development updates and applies them immediately after immutable images and exact-head evidence are available. Delivery must not modify gondor-v1-aerosim. Releases alone owns production promotion.

Deploy to development​

  1. Verify the application PR merged and the exact default-head CI and image-publication jobs succeeded.
  2. Resolve the full source commit and immutable image digests from the publication evidence.
  3. Set the development Copier inputs to the source revision and the Nebula and Singularity digests.
  4. Run the authoritative single-environment Copier render into gondor-v1-aerosim-dev.
  5. Confirm the development repository equals that render and no production repository change is present.
  6. Validate template tests, rendered YAML, immutable-selection tests, Argo reconciliation tests, policy checks, and git diff --check.
  7. If the reusable template changed, merge its reviewed pull request first. Merge the reviewed gondor-v1-aerosim-dev pull request without waiting for UAT or a production release request.
  8. Let Argo CD reconcile. Do not run routine kubectl apply or helm upgrade from CI or a contributor shell.
  9. Verify both development Applications report Synced and Healthy, the workloads are ready, the observed image IDs equal the selected digests, and the endpoint health check succeeds.

Freeze the UAT deployment tuple​

Record one immutable tuple before a journey starts:

application_commit
image_digests
rendered_GitOps_commit
rendered_GitOps_repository=corp-v1-aerosim/gondor-v1-aerosim-dev
ArgoCD_application
ArgoCD_sync_revision
ArgoCD_sync_status=Synced
ArgoCD_health_status=Healthy
environment=development
base_url
E2E_commit
required_journey_ids

If Argo CD reconciles a different revision while a run is active, invalidate the run and start again against the new tuple.

Execute UAT​

UAT tests only the deployment reconciled from gondor-v1-aerosim-dev; production is not a substitute for the development entry gate.

  1. Hand the tuple from corp-v1-aerosim-delivery to corp-v1-aerosim-uat.
  2. Fetch the exact E2E revision and run task validate.
  3. Execute the required smoke or regression journey set with UAT_BASE_URL set to the verified endpoint.
  4. Preserve JUnit and JSON results plus traces and screenshots for failures.
  5. Classify each failure as product, environment, test, or unresolved.
  6. Return product or environment failures to Kanban/Delivery. Delivery publishes a corrected immutable image set and a new GitOps revision before retest.
  7. Send UAT_PASSED evidence to Releases only when every required journey passed against one tuple.

Authenticated journeys use a runtime-generated Playwright storage-state path. Never commit cookies, credentials, tokens, .env files, or generated evidence containing personal data.

Promote through Releases​

A UAT pass does not authorize production. Releases additionally requires RootAtSkic's explicit release request and validates that the UAT tuple matches the intended candidate. Releases then renders the same single-environment Copier template with production inputs into gondor-v1-aerosim, promotes that reviewed revision, and independently verifies https://aerosim.apps.lego-cloud.eu plus rollback readiness before final DONE.

Channel path​

general → scope → architecture → kanban → delivery → uat → releases → general

A failed journey returns through uat → kanban/delivery; it does not bypass the approved Task lifecycle.