
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>clusternotes.io</title>
      <link>https://clusternotes.io/blog</link>
      <description>Notes from a cloud-native engineering journey — Kubernetes, observability, GitOps, Azure, AWS. Practical lessons, hands-on experiments, and how the pieces actually fit together.</description>
      <language>en-us</language>
      <managingEditor>kozlowski.softnet@gmail.com (Krzysztof Kozłowski)</managingEditor>
      <webMaster>kozlowski.softnet@gmail.com (Krzysztof Kozłowski)</webMaster>
      <lastBuildDate>Mon, 08 Jun 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://clusternotes.io/tags/gitops/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://clusternotes.io/blog/gitops-push-vs-pull</guid>
    <title>GitOps push vs pull — how the trust direction flips with ArgoCD</title>
    <link>https://clusternotes.io/blog/gitops-push-vs-pull</link>
    <description>Push and pull both deploy to Kubernetes, but they flip the direction of trust. Pull moves cluster credentials out of CI, makes drift visible, and turns Git into the cluster audit log. Here is the difference, what actually changes, and what pull does not solve.</description>
    <pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate>
    <author>kozlowski.softnet@gmail.com (Krzysztof Kozłowski)</author>
    <category>gitops</category><category>kubernetes</category><category>security</category>
  </item>

    </channel>
  </rss>
