One OCI deployed, promoted, and rolled out through Argo CD and Flux

A repository document, rendered for the site. View source markdown.

Generated at: 2026-07-30T12:38:02.000Z UTC · source: committed helm-expt evidence for this rendered repository document.

This is one continuous live test. It starts with literal Kubernetes objects in an OCI artifact. ConfigHub imports those objects without running Helm and keeps a base -> development -> staging chain. The reviewed staging objects are then exported as one anonymous OCI package. Argo CD pulls that exact package on two clusters, and Flux pulls the same digest on a third cluster.

Result

pass. One literal Kubernetes OCI was imported and republished by ConfigHub with the same specs and user metadata plus a ConfigHub origin annotation, then promoted in sequence through development and staging and exported as one anonymous OCI package. Two Argo CD controllers and one Flux controller reconciled that exact digest. Fingerprinted cub-scout receipts confirm that all three live object sets match the reviewed package and all three NGINX Deployments reached two ready replicas.

StepResultEvidence
Build and pull the literal input OCIpasssha256:ba9d5aa8f05766037d61f2ed04bfed5543bc5e7328cce193a3c577fe9071d714; pulled objects matched the committed NGINX catalog base.
Import the OCI into ConfigHubpass5 Units; source digest recorded; Kubernetes fields matched. The receipt names the internal comment marker ignored during comparison.
Publish the same configuration from ConfigHubpassInput sha256:ba9d5aa8f05766037d61f2ed04bfed5543bc5e7328cce193a3c577fe9071d714; ConfigHub output sha256:72c5d6470b0c2a260dae933791046cc5b7544bcd3263a803f4763e94d65d3ca5; 5 objects kept the same specs and user metadata. ConfigHub added confighub.com/origin.
Create the environment chainpassbase -> development -> staging.
Change one reviewed fieldpassDeployment replicas changed from 1 to 2.
Promote to developmentpassThe dry run showed the replica change without applying it. The promotion then applied the change and cleared the pending update.
Promote to stagingpassThe dry run showed the replica change without applying it. The promotion then applied the change and cleared the pending update.
Publish the ConfigHub staging releasepasssha256:6633e6a2174ea4f54ec011ad8c8549a85f63e0abc000a19abad132a8fad5db9b.
Export the portable OCIpass5 objects; sha256:b90a1d56c878d18040bc8a92545eed0e8a1913d64ab960a887c2fc8004e22b55; anonymous pull.
Roll out through Argo CDpassBoth Argo CD controllers reported the portable OCI digest and both workloads became ready.
Roll out through FluxpassThe Flux OCIRepository and Kustomization became ready at sha256:b90a1d56c878d18040bc8a92545eed0e8a1913d64ab960a887c2fc8004e22b55; the workload reached 2/2 ready replicas.

Argo CD controller feedback

ClusterArgo syncArgo healthOCI revisionExact objectsReady replicasCurrent objectsResult
hx-oci-flow-20260729-s3t-aSyncedHealthysha256:b90a1d56c878d18040bc8a92545eed0e8a1913d64ab960a887c2fc8004e22b555/52/25/5pass
hx-oci-flow-20260729-s3t-bSyncedHealthysha256:b90a1d56c878d18040bc8a92545eed0e8a1913d64ab960a887c2fc8004e22b555/52/25/5pass

Flux controller feedback

ClusterOCI sourceKustomizationOCI revisionReady replicasResult
hx-oci-flow-20260729-s3t-fluxReadyReadysha256:b90a1d56c878d18040bc8a92545eed0e8a1913d64ab960a887c2fc8004e22b552/2pass

Live observation receipts

cub-scout checked the reviewed staging files against all three live clusters. The object receipts compare the five namespaced Kubernetes objects and their authored fields, using the named Kubernetes zero-default normalization profile for fields the API server may omit. The convergence receipts check that all five objects are current, including the NGINX Deployment at two ready replicas. Each receipt records a one-hour freshness boundary and a fingerprint that can be validated later.

ClusterObject receiptFingerprintWorkload receiptFingerprint
hx-oci-flow-20260729-s3t-aobject matchsha256:78f1cf6b4a7e3a556bfc916884abe3635e95910737eadbfe2639aacb5b0d749bworkload convergencesha256:91cbd10d7615d51376dd25c806c39d526fca058bcc34597d9cf8d7b148ff1a6c
hx-oci-flow-20260729-s3t-bobject matchsha256:fc72200157343b96f959766b15d1602925227cce8eaba9bc438525e5d5efde13workload convergencesha256:3b167764a7b61675a95a24784dde1a5da195d5c8a20a967ff5539093506b4f22
hx-oci-flow-20260729-s3t-fluxobject matchsha256:5a50be6aec6b2f042c244f00ffbc3a92d293a05628bb23ad5126c9f9f941e54dworkload convergencesha256:ffaaf94dfd009988e3756985014bbdc7d280ffa70e61c8c6bcb6dc270eb22aed

What this proves

What this does not prove

The run removed all three kind clusters, both ConfigHub cluster Spaces, the three workload Spaces, the temporary registry, and the generated local files.