App Lifecycle
The app lifecycle pipeline takes an application definition and fully deploys it to a Kubernetes cluster using manifest generation and Flux GitOps, without any manual YAML authoring.
End-to-End Flow
From Deploy to live
The four stages the Deploy Application wizard shows. Select a stage for details.
App Service
App Service is the manifest generation engine. It takes a declarative schema and produces production-ready Kubernetes YAML .
Generated resources:
Deployment— with resource requests/limits, env vars, health probesService— ClusterIP by default; LoadBalancer ifservice.type: LoadBalancerHorizontalPodAutoscaler— whenautoscaling.enabled: trueIngress— wheningress.enabled: trueConfigMap— for non-secret environment variablesServiceAccount— dedicated service account per applicationNetworkPolicy— default deny-all ingress with explicit allow rules
Preview endpoint:
POST http://localhost:8091/api/v1/preview
Content-Type: application/json
{
"app": {
"name": "payments-api",
"namespace": "payments",
"type": "api",
"containers": [
{
"name": "payments-api",
"image": "registry.example.com/payments-api:v1.2.3",
"ports": [{ "containerPort": 8080 }],
"resources": {
"requests": { "cpu": "100m", "memory": "128Mi" },
"limits": { "cpu": "500m", "memory": "512Mi" }
}
}
],
"service": { "enabled": true },
"autoscaling": { "enabled": true, "minReplicas": 2, "maxReplicas": 10 }
}
}
Returns a multi-document YAML string suitable for kubectl apply -f -.
app-controller
Repo: o-apps/app-controller · Language: Go (controller-runtime)
A standard Kubernetes controller that reconciles KubeOperaApp custom resources.
KubeOperaApp CRD
apiVersion: kubeopera.io/v1alpha1
kind: KubeOperaApp
metadata:
name: payments-api
namespace: default
spec:
appID: abc-123
schema:
app:
name: payments-api
namespace: payments
# ... full kubegenic schema
git:
url: https://github.com/org/fleet-repo
branch: main
secretRef: fleet-git-credentials # K8s Secret with ssh-privatekey or password
flux:
interval: 5m
targetNamespace: payments
prune: true
status:
phase: Ready
gitPath: apps/payments/payments-api
fluxGitRepository: payments-api-source
fluxKustomization: payments-api-sync
lastSyncedAt: "2025-04-18T14:23:01Z"
Git Authentication
The secretRef points to a Kubernetes Secret containing either:
ssh-privatekey— for SSH-based Git authenticationpassword— for HTTPS with a personal access token
Flux Integration
The controller creates two Flux CRs using unstructured objects (no Flux import required):
# GitRepository — tells Flux where to pull manifests from
apiVersion: source.toolkit.fluxcd.io/v1
kind: GitRepository
metadata:
name: payments-api-source
spec:
url: https://github.com/org/fleet-repo
ref:
branch: main
interval: 5m
secretRef:
name: fleet-git-credentials
# Kustomization — tells Flux what to apply
apiVersion: kustomize.toolkit.fluxcd.io/v1
kind: Kustomization
metadata:
name: payments-api-sync
spec:
sourceRef:
kind: GitRepository
name: payments-api-source
path: apps/payments/payments-api
targetNamespace: payments
prune: true
interval: 5m
Environment Variables
| Variable | Service | Description |
|---|---|---|
APP_CONTROLLER_ENABLED | kubeopera-api | Set true to enable CRD creation on app save |
FLUX_GIT_URL | kubeopera-api | Fleet repository URL |
FLUX_GIT_BRANCH | kubeopera-api | Branch (default: main) |
FLUX_GIT_SECRET_REF | kubeopera-api | Kubernetes Secret name for Git credentials |
FLUX_TARGET_NAMESPACE | kubeopera-api | Default namespace for app deployment |
FLUX_INTERVAL | kubeopera-api | Flux reconcile interval (default: 5m) |