Decide whether the proposed GitOps action preserves a reproducible render, a single owner per resource, a bounded deletion set, and customer-path acceptance. Distinguish a healthy last-good workload from a fresh approved deployment.
Review these lessons
- GitOps render locks: identify every input behind an applied manifest
- Kustomize overlays: review the complete environment diff
- GitOps ownership transfer: keep one reconciler authoritative per resource
- GitOps pruning: preview deletions as a separate release action
- GitOps verification: separate source sync, resource health, and user success
- GitOps source outages: distinguish last-good operation from fresh deployment
- GitOps rollback: return desired state and controller authority together
- Fleet promotion: bound the number of clusters changed at once
Other checks
Common Mistakes
- Do not equate a source commit with the final rendered release.
- Do not let auto-sync erase an emergency rollback without an intent change.
