Skip to main content
Version: 1.0

App Lifecycle

The app lifecycle pipeline takes an application definition and fully deploys it to a Kubernetes cluster using manifest generation and Flux GitOps, without any manual YAML authoring.

End-to-End Flow​

From Deploy to live

The four stages the Deploy Application wizard shows. Select a stage for details.

Select a stage to see what happens behind it.

App Service​

App Service is the manifest generation engine. It takes a declarative schema and produces production-ready Kubernetes YAML .

Generated resources:

  • Deployment — with resource requests/limits, env vars, health probes
  • Service — ClusterIP by default; LoadBalancer if service.type: LoadBalancer
  • HorizontalPodAutoscaler — when autoscaling.enabled: true
  • Ingress — when ingress.enabled: true
  • ConfigMap — for non-secret environment variables
  • ServiceAccount — dedicated service account per application
  • NetworkPolicy — default deny-all ingress with explicit allow rules

Preview endpoint:

POST http://localhost:8091/api/v1/preview
Content-Type: application/json

{
"app": {
"name": "payments-api",
"namespace": "payments",
"type": "api",
"containers": [
{
"name": "payments-api",
"image": "registry.example.com/payments-api:v1.2.3",
"ports": [{ "containerPort": 8080 }],
"resources": {
"requests": { "cpu": "100m", "memory": "128Mi" },
"limits": { "cpu": "500m", "memory": "512Mi" }
}
}
],
"service": { "enabled": true },
"autoscaling": { "enabled": true, "minReplicas": 2, "maxReplicas": 10 }
}
}

Returns a multi-document YAML string suitable for kubectl apply -f -.

app-controller​

Repo: o-apps/app-controller · Language: Go (controller-runtime)

A standard Kubernetes controller that reconciles KubeOperaApp custom resources.

KubeOperaApp CRD​

apiVersion: kubeopera.io/v1alpha1
kind: KubeOperaApp
metadata:
name: payments-api
namespace: default
spec:
appID: abc-123
schema:
app:
name: payments-api
namespace: payments
# ... full kubegenic schema
git:
url: https://github.com/org/fleet-repo
branch: main
secretRef: fleet-git-credentials # K8s Secret with ssh-privatekey or password
flux:
interval: 5m
targetNamespace: payments
prune: true
status:
phase: Ready
gitPath: apps/payments/payments-api
fluxGitRepository: payments-api-source
fluxKustomization: payments-api-sync
lastSyncedAt: "2025-04-18T14:23:01Z"

Git Authentication​

The secretRef points to a Kubernetes Secret containing either:

  • ssh-privatekey — for SSH-based Git authentication
  • password — for HTTPS with a personal access token

Flux Integration​

The controller creates two Flux CRs using unstructured objects (no Flux import required):

# GitRepository — tells Flux where to pull manifests from
apiVersion: source.toolkit.fluxcd.io/v1
kind: GitRepository
metadata:
name: payments-api-source
spec:
url: https://github.com/org/fleet-repo
ref:
branch: main
interval: 5m
secretRef:
name: fleet-git-credentials
# Kustomization — tells Flux what to apply
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: payments-api-sync
spec:
sourceRef:
kind: GitRepository
name: payments-api-source
path: apps/payments/payments-api
targetNamespace: payments
prune: true
interval: 5m

Environment Variables​

VariableServiceDescription
APP_CONTROLLER_ENABLEDkubeopera-apiSet true to enable CRD creation on app save
FLUX_GIT_URLkubeopera-apiFleet repository URL
FLUX_GIT_BRANCHkubeopera-apiBranch (default: main)
FLUX_GIT_SECRET_REFkubeopera-apiKubernetes Secret name for Git credentials
FLUX_TARGET_NAMESPACEkubeopera-apiDefault namespace for app deployment
FLUX_INTERVALkubeopera-apiFlux reconcile interval (default: 5m)