ADR-004: GitOps with Flux, Kustomize and SOPS
Status: Accepted Date: 2026-10-10
Context
The cluster must be rebuildable from git, and every change reviewable and revertible. The team already ran this setup for vgu-graduation (its ADR-004).
Decision
Flux reconciles Kustomize manifests from fuisl/coipe-infra onto k3s. Upstream Helm charts are used where they exist. Secrets are encrypted with SOPS and age. Flux image automation follows the main-<timestamp>-<sha> tags that fuisl/coipe CI pushes to GHCR and commits each bump.
Alternatives considered
- Argo CD: capable, but heavier on small nodes.
- Manual
kubectl apply: drifts and can't be audited.
Consequences
- The age private key is critical: losing it means re-encrypting and rotating every secret. It never appears in git or chat; who holds it and its escrow copy is recorded in
fuisl/coipe-infra. - GHCR images are private, so Flux needs a pull secret.