Skip to content

Kargo

KICK can gate restarts on Kargo Stage promotion and verification activity when provider: Kargo is set.

Kargo promotion gate

Enable the integration

Set one of the supported toggles:

  • Helm value: integrations.kargo.enabled: true
  • Manager flag: --enable-kargo=true

Proof: Configuration reference.

Minimal policy

apiVersion: kick.corewire.io/v1alpha1
kind: KickPolicy
metadata:
  name: default
  namespace: kick-e2e-068
spec:
  discovery:
    workloadSelector: {}
  gitOps:
    provider: Kargo

Proof example: KICK-E2E-068 resources.

Required Argo CD Application annotation

KICK resolves the authorized Stage from this annotation on the Argo CD Application:

metadata:
  annotations:
    kargo.akuity.io/authorized-stage: kick-e2e-068:prod

Proof example: KICK-E2E-068 Application.

Gate behavior

  • Active Promotion or verification blocks the restart. Empty and non-terminal verification phases wait. Successful, Failed, Error, Aborted, and Inconclusive do not.
  • A configured verification with no record yet also waits when status.lastPromotion for the current Freight succeeded.
  • status.health is not a gate. A failed verification can still be the stale-Secret case.
  • After that activity settles, KICK proceeds to the Argo CD gate. Freshness still decides whether a restart is necessary.
  • Stages without spec.verification keep the promotion-only gate.

Proof: verification gate, unit tests.

Proof scenarios:

The e2e installer enables Kargo’s Rollouts integration and installs Argo Rollouts first. Kargo checks for AnalysisRun CRDs once at startup and otherwise runs as if verification were disabled (install-kargo.sh).

Optional reverification

spec.gitOps.reverifyAfterRestart defaults to false. When true, KICK stores the Stage, Freight-collection ID, and verification ID before the restart, then patches kargo.akuity.io/reverify with {"id":"<verification id>"} only after the rollout is fresh and those IDs are unchanged. It does not create a Promotion. A failed patch does not restart again.

The pre-restart read and the restart patch are not atomic. Freight history can advance in between; KICK then skips the annotation.

spec:
  gitOps:
    provider: Kargo
    reverifyAfterRestart: true

Proof: follow-up, KICK-E2E-076.

Safety cases

Feature mapping

Last updated on