KubeRusted
Spinning up your cluster…

CGOA exam prep — Certified GitOps Associate

Free CGOA (Certified GitOps Associate) practice: the 5 official domains, exam-style questions, a timed practice exam and more.

Play the CGOA map → · Official CGOA exam page

GitOps Terminology (20%)

Desired state, state drift, reconciliation, state store, feedback loop, rollback

GitOps Principles (30%)

Declarative, versioned and immutable, pulled automatically, continuously reconciled

Related Practices (16%)

Configuration as Code, Infrastructure as Code, DevOps and DevSecOps, CI and CD

GitOps Patterns (20%)

Deployment, release and progressive delivery patterns, pull vs event-driven, architecture

Tooling (14%)

Manifest formats and packaging, state stores, reconciliation engines, integrations

Practice questions

In OpenGitOps terms, what is "desired state"?

Answer: The aggregate of configuration data sufficient to recreate the system. It excludes persistent application data such as database contents.

What is "actual state"?

Answer: How the running system currently is. Reconciliation compares actual with desired state.

What does "drift" describe?

Answer: Actual state moving away from desired state. Drift can come from manual changes, failures or other actors.

What is reconciliation?

Answer: The process of ensuring actual state matches desired state. It is triggered whenever there is a divergence.

What is a state store?

Answer: A system storing immutable versions of desired state declarations. Git is the canonical example; access control and auditing are required.

In OpenGitOps, what does "continuous" mean?

Answer: Reconciliation keeps happening — not that it must be instantaneous. The glossary defines "continuous" to match industry use.

What is a "declarative description"?

Answer: Configuration describing the desired operating state without the procedure to reach it. It separates configuration from implementation.

What is meant by "feedback" in the OpenGitOps glossary?

Answer: How previous attempts to apply desired state affected actual state, informing the next action. GitOps follows control theory and operates in a closed loop.

Which of these are part of a GitOps-managed software system?

Answer: Runtime environments with the resources under management; Management agents within each runtime; Policies controlling access to repositories and runtimes. These three parts are listed in the OpenGitOps glossary.

What does "pull" mean in GitOps?

Answer: Software agents fetch desired state from the state store themselves. Agents must be able to access the state store at any time.

Which event should trigger reconciliation in GitOps?

Answer: Any divergence — a new desired state or unintended drift. This is what distinguishes GitOps from trigger-driven CI/CD.

What is a rollback in GitOps?

Answer: Declaring a previous desired state (e.g. reverting a commit). The agent then reconciles to it.

Why is Git a natural state store?

Answer: Immutable history, access control, auditing and review workflows. Pull requests add review before desired state changes.

Which is NOT desired state in the OpenGitOps sense?

Answer: The rows stored in a production database. Persistent application data is generally excluded.

What is a "reconciler" or GitOps agent?

Answer: Software that observes actual state and applies desired state. Argo CD and Flux controllers are reconcilers.

What is an "environment" in GitOps practice?

Answer: A target runtime (e.g. staging, production) with its own desired state. Environments are usually separate folders, overlays or repos.

How many OpenGitOps principles are there?

Answer: Four. Declarative, Versioned and Immutable, Pulled Automatically, Continuously Reconciled.

Which principle requires desired state to be expressed declaratively?

Answer: Principle 1: Declarative. A system managed by GitOps must have its desired state expressed declaratively.

Which principle requires complete version history?

Answer: Versioned and Immutable. Desired state is stored immutably, with complete version history.

A deployment script runs `kubectl scale` and `kubectl set image` in sequence. Which principle does it violate?

Answer: Declarative. Imperative steps describe how, not what.

Editing a YAML file directly on the GitOps server’s disk violates which principle?

Answer: Versioned and Immutable. Changes must go through the versioned, immutable state store.

A CI job pushes manifests into the cluster with kubectl after each build. Which principle is missing?

Answer: Pulled Automatically. Agents should pull desired state rather than having it pushed in.

An agent applies Git once per day but never checks for manual changes in between. Which principle is weak?

Answer: Continuously Reconciled. Agents continuously observe actual state and attempt to apply desired state.

Why does "Pulled Automatically" improve security?

Answer: The runtime does not need to expose credentials or inbound access to an external pusher. Credentials stay inside the environment being managed.

What benefit does "Versioned and Immutable" give during an incident?

Answer: You can see exactly what changed and when, and revert to a known-good version. Version history is an audit trail.

Which is a declarative artifact?

Answer: A Kubernetes Deployment manifest. It describes the end state.

Does GitOps require Kubernetes?

Answer: No — the principles apply to any system whose desired state can be declared and reconciled. Kubernetes is the most common target because its API is declarative.

Does GitOps require Git specifically?

Answer: No — any state store that is versioned and immutable with access control can work. OCI registries and buckets are used too.

How does continuous reconciliation handle a deleted resource that is still in Git?

Answer: The agent recreates it. Actual state is driven back to desired state.

Which practice best keeps desired state immutable?

Answer: Changes only through commits/PRs; protected branches; no force-pushes. History must be complete and tamper-evident.

A team stores Kubernetes Secrets in plain text in Git to satisfy "declarative". What is the problem?

Answer: Secrets would be exposed — encrypt them (e.g. SOPS, Sealed Secrets) or reference an external store. Desired state can include references to secrets without the plaintext.

What does "pulled automatically" not forbid?

Answer: Webhooks that notify the agent to pull sooner. A notification still results in the agent pulling.

Which statement about the principles is correct?

Answer: All four must hold together for a system to be GitOps. OpenGitOps defines GitOps as the set of these principles.

How do imperative emergency fixes fit with GitOps?

Answer: They become drift — capture the fix in the state store or the agent will revert it. Many teams pause auto-sync deliberately during incidents and then commit the fix.

What does an agent do if it cannot apply desired state (e.g. invalid manifest)?

Answer: Report the failure through feedback and keep trying/alerting. Feedback closes the loop for humans and automation.

Why are declarative descriptions easier to review?

Answer: Reviewers see the intended end state, not a sequence of side effects. Diffs of desired state are meaningful in pull requests.

What does immutability of versions mean in practice?

Answer: A given version of desired state never changes; new changes create new versions. Tags and commits identify exact states.

Which principle makes an environment rebuildable from scratch?

Answer: Declarative (together with a versioned state store). If the full desired state is declared, a new environment can be reconciled from it.

In GitOps, where should a change to production replicas be made?

Answer: In the state store (e.g. a commit changing replicas). Otherwise it is drift and will be reverted.

What is the relationship between reconciliation and the Kubernetes controller pattern?

Answer: Both observe actual state, compare with desired state and act — GitOps applies it to the whole system. Kubernetes is itself built on reconciliation loops.

What is Infrastructure as Code (IaC)?

Answer: Managing infrastructure through machine-readable definition files. Terraform, OpenTofu, Pulumi and Crossplane are common tools.

How does GitOps relate to IaC?

Answer: GitOps adds versioned storage, pull-based delivery and continuous reconciliation to IaC definitions. IaC alone may still be applied manually or by push.

What is Configuration as Code?

Answer: Managing application and system configuration as versioned files. Same review and history practices as application code.

What is DevSecOps?

Answer: Integrating security practices into the whole development and operations lifecycle. Security checks run in pipelines and as policies.

How does GitOps support DevSecOps?

Answer: Pull requests, signed commits and policy checks on desired state before it is applied. Every change is reviewable and auditable.

In a GitOps workflow, what does CI typically produce?

Answer: Tested, versioned artifacts (images) and updates to desired state. CI builds; the GitOps agent deploys.

What is continuous delivery?

Answer: Keeping software always in a releasable state and delivering it through automation. GitOps is one way to implement CD.

What is continuous deployment, as opposed to continuous delivery?

Answer: Every change that passes the pipeline goes to production automatically. Continuous delivery may keep a manual approval before production.

Which DevOps practice shortens feedback for developers?

Answer: Small, frequent changes with automated tests. Smaller changes are easier to review and roll back.

Why separate application source repos from configuration (deployment) repos in some GitOps setups?

Answer: Different change cadences and access rights; CI updates config without touching app code. It is a common pattern, not a principle.

What does policy as code mean?

Answer: Expressing rules (security, compliance) as versioned code that is evaluated automatically. OPA/Gatekeeper and Kyverno are examples.

Which tool type checks desired-state manifests in CI before they reach the state store’s main branch?

Answer: Linters and policy checks (e.g. kubeconform, conftest, kyverno CLI). Shift-left validation catches errors early.

What is progressive delivery?

Answer: Gradually exposing a new version while measuring it, with automatic rollback. Canary, blue-green and feature flags are progressive delivery techniques.

Which tools add progressive delivery to GitOps on Kubernetes?

Answer: Argo Rollouts; Flagger. Both automate traffic shifting and analysis.

What is a feature flag?

Answer: A runtime switch that turns functionality on or off without redeploying. It decouples release from deployment.

What is the difference between deployment and release?

Answer: Deployment puts code into an environment; release exposes it to users. Progressive delivery and feature flags exploit the difference.

What is the pull-based pattern’s main trade-off versus event-driven only?

Answer: Polling adds some latency but catches drift and missed events. Most tools combine both: webhooks for speed, a polling interval as the safety net.

What is a "hub and spoke" GitOps architecture?

Answer: A central management cluster runs the reconciler for many target clusters. Central view, but the hub holds credentials to every spoke.

What is a benefit of running a reconciler inside each cluster?

Answer: Smaller blast radius and no inbound credentials from outside. Each cluster pulls its own desired state.

How do teams usually promote a change from staging to production with GitOps?

Answer: A pull request that updates production’s desired state (e.g. image tag). The same artifact moves through environments.

Why are long-lived branches per environment often discouraged?

Answer: Branches drift apart and merges become error-prone; folders/overlays are easier to compare. Directory-per-environment keeps all environments visible in one place.

What is a monorepo approach for GitOps configuration?

Answer: All environments and apps in one repository, separated by directories. Polyrepo splits by team or app instead; both are valid.

How can image updates be automated in GitOps?

Answer: An image automation controller detects new tags and commits the update to Git. Flux image automation and Argo CD Image Updater do this.

What is a canary analysis?

Answer: Comparing metrics of the new version against thresholds or the baseline to decide promotion. Failing analysis triggers an automatic rollback.

How should secrets be handled in a GitOps repository?

Answer: Encrypted (SOPS, Sealed Secrets) or referenced from an external secret manager. The repository may be widely readable.

What is a dependency between GitOps-managed apps, e.g. CRDs before custom resources, usually solved with?

Answer: Ordering mechanisms such as sync waves (Argo CD) or dependsOn (Flux Kustomization). Reconcilers apply in a defined order.

What is "configuration drift detection" useful for in audits?

Answer: Proving production matches the approved, versioned configuration. Drift is visible in the reconciler’s status.

What is the event-driven pattern in GitOps?

Answer: A webhook or event tells the reconciler that new desired state exists. The reconciler still pulls the state itself.

Which Flux resource points at a Git repository to watch?

Answer: GitRepository. Kustomization and HelmRelease consume sources such as GitRepository and OCIRepository.

Which Flux resource applies manifests from a source path?

Answer: Kustomization (kustomize.toolkit.fluxcd.io). It is Flux’s own CRD, distinct from Kustomize’s kustomization.yaml.

Which Flux resource installs a Helm chart?

Answer: HelmRelease. HelmRepository or OCIRepository is the chart source.

Which Argo CD resource defines one deployed app?

Answer: Application. ApplicationSet generates many Applications.

Which are common manifest packaging formats in GitOps?

Answer: Helm charts; Kustomize overlays; Plain YAML. Reconcilers render them into Kubernetes manifests.

Which tool can encrypt values inside YAML files while keeping keys readable?

Answer: SOPS. Flux decrypts SOPS natively; Argo CD via plugins.

What does Bitnami Sealed Secrets provide?

Answer: A SealedSecret that only the in-cluster controller can decrypt into a Secret. The encrypted SealedSecret is safe to commit; only the cluster holds the private key.

Which Flux component sends notifications to Slack or commit statuses?

Answer: notification-controller (Provider and Alert resources). It also handles incoming webhooks (Receiver).

Which CLI bootstraps Flux into a cluster and commits its own manifests to Git?

Answer: flux bootstrap. Flux then manages itself from the repository.

Which CNCF graduated tools are GitOps reconciliation engines?

Answer: Argo CD; Flux. Both are graduated CNCF projects.

How do GitOps tools integrate with observability?

Answer: Exposing metrics and events about sync status and reconciliation errors. Alert on failed or long-pending reconciliations.

An engineer scales a Deployment by hand and the cluster no longer matches Git. What is this called?

Answer: State drift. Drift is the gap between actual and desired state; reconciliation is what removes it.

Under GitOps, how do you roll back a bad release?

Answer: Revert the change in the state store and let the reconciler apply it. Desired state is the source of truth; changing the cluster directly would just be drift.

Which are the four OpenGitOps principles?

Answer: Declarative; Versioned and immutable; Pulled automatically; Continuously reconciled. OpenGitOps v1.0.0 defines exactly these four principles.

Why is "pulled automatically" considered more secure than CI pushing to the cluster?

Answer: Cluster credentials stay inside the cluster instead of in the external CI system. With pull, the agent reaches out; no outside system needs write access to the environment.

A reconciler that only acts when a new commit arrives misses which principle?

Answer: Continuously reconciled. Drift with no new commit would never be corrected — reconciliation must be continuous.

In a GitOps setup, what is the usual job of the CI pipeline?

Answer: Build and test, publish the artifact, then update the desired state (e.g. bump the image tag). CI produces artifacts and changes the state store; the GitOps agent handles deployment.

Crossplane or Terraform definitions committed to Git are an example of…

Answer: Infrastructure as Code. IaC defines infrastructure in versioned files; GitOps can then reconcile it.

Why keep periodic polling even when webhooks trigger syncs?

Answer: It catches drift and missed webhooks, keeping reconciliation continuous. Event-driven gives speed; the periodic loop is the safety net.

Which pattern shifts traffic gradually and rolls back automatically when metrics degrade?

Answer: Progressive delivery (canary with automated analysis). Argo Rollouts and Flagger implement this pattern on top of GitOps.

Which are GitOps reconciliation engines?

Answer: Argo CD; Flux. Jenkins is CI; Prometheus is monitoring. Argo CD and Flux are CNCF graduated GitOps tools.

Besides Git, which can serve as a GitOps state store?

Answer: An OCI registry holding versioned, immutable artifacts. Any store with versioned, immutable history works; Flux and Argo CD can read OCI artifacts.