Deploy using Kubernetes Manifest
This topic explains how to deploy a sample application (Guestbook) using a publicly available Kubernetes manifest and Docker image with Harness Continuous Delivery (CD).
Harness CD offers two ways to deploy the Guestbook application:
- CD pipeline: You build a Harness pipeline that deploys the manifest to your target cluster.
- GitOps workflow: You install a Harness GitOps Agent, connect it to your Git repo and target cluster, and let Harness (using Argo CD) sync the desired state from Git into your cluster.
Sign up today to get started with Harness CD.
What will you learn in this topic?
- How to set up a delegate, secret, connectors, environment, service, and pipeline to deploy the Guestbook application.
- How to choose a rolling, canary, or Blue Green deployment strategy for your pipeline.
- How to install a Harness GitOps Agent and sync the desired state from your Git repository into your cluster using Argo CD.
- How to deploy the Guestbook application using the Harness UI, CLI, or Harness Terraform Provider.
Before you begin
Ensure you have the following:
- GitHub personal access token: A token with the
reposcope. Go to creating a personal access token to generate one. - Kubernetes cluster: Use your own cluster, or install K3D to run Harness Delegates and the sample application in a local development environment. Go to Delegate system and network requirements to review the requirements.
- Helm CLI: Install the Helm CLI to install the Harness Helm delegate.
- Forked example repository: Fork the harnesscd-example-apps repository through the GitHub web interface. Go to GitHub docs to fork a repository.
- Harness API token (CLI or Terraform method only): A token required to run the CLI or Terraform steps. Go to creating a personal API token to generate one.
Deploy the application
Harness resources such as delegates, secrets, and connectors can be created at the Account, Organization, or Project scope. For simplicity, this tutorial uses Project-scoped resources throughout. If you use resources from a different scope, update the configuration accordingly when you create connectors, environments, services, and the deployment pipeline.
Go to Organizations and projects to understand the Harness resource hierarchy and scopes.
You can deploy the Guestbook application using either a Harness CD pipeline or a Harness GitOps workflow.
Run the following command to check your system resources and optionally install a local cluster:
bash <(curl -fsSL https://raw.githubusercontent.com/harness-community/scripts/main/delegate-preflight-checks/cluster-preflight-checks.sh)
- CD Pipeline
- GitOps Workflow
Deploy with a CD pipeline
Harness CD pipelines allow you to orchestrate and automate your deployment workflows and push updated application images to your target Kubernetes cluster. Pipelines allow extensive control over how you want to progress artifacts through various development, test, staging, or production clusters, when running a variety of scans and tests to ensure the quality and stability standards you and your team have defined.
You can proceed with the tutorial using either the Harness user interface (UI) or the command-line interface (CLI).
- UI
- CLI
Perform the following steps to deploy the Guestbook application using the Harness CD Pipeline UI:
- Log in to Harness Manager.
- Select Projects, and then select Default Project.
- After selecting the project, configure the core resources Harness requires to run a deployment, including a delegate, a secret, two connectors, an environment, a service, and a deployment pipeline, as explained in the following sections.
For the pipeline to run successfully, follow the remaining steps as they are, including the naming conventions.
Delegate
The Harness Delegate is a service that runs in your local network or VPC to establish connections between the Harness Manager and various providers such as artifacts registries, cloud platforms, and so on. The delegate is installed in the target infrastructure, for example, a Kubernetes cluster, and performs operations including deployment and integration. Go to Delegate Overview to understand the delegate.
Perform the following steps to set up a delegate:
-
Under Project Settings, select Delegates.
-
Click New Delegate.
-
Select Kubernetes in the Select where you want to install your Delegate section.
-
In the Install your Delegate section, for this tutorial, install the delegate using Helm Chart.
-
Add the Harness Helm chart repo to your local helm registry using the following command.
helm repo add harness-delegate https://app.harness.io/storage/harness-download/delegate-helm-chart/ -
Update the repo using the following command:
helm repo update harness-delegate -
Copy and run the install command from the Delegate installation wizard as shown in the following example:
Here, the
ACCOUNT_ID,MANAGER_ENDPOINTandDELEGATE_TOKENare auto-populated values you will get from the wizard itself.helm upgrade -i helm-delegate --namespace harness-delegate-ng --create-namespace \harness-delegate/harness-delegate-ng \--set delegateName=helm-delegate \--set accountId=ACCOUNT_ID \--set managerEndpoint=MANAGER_ENDPOINT \--set delegateDockerImage=harness/delegate:23.03.78904 \--set replicas=1 --set upgrader.enabled=false \--set delegateToken=DELEGATE_TOKEN -
Select Verify to verify that the delegate is installed successfully and can connect to the Harness Manager.
You can also follow the Install Harness Delegate on Kubernetes or Docker steps to install the delegate using the Harness Terraform Provider or a Kubernetes manifest.
Secrets
Harness offers built-in secret management for encrypted storage of sensitive information. Secrets are decrypted when needed, and only the private network-connected Harness Delegate has access to the key management system. You can also integrate your own secret manager. Go to Harness Secret Manager Overview to understand secrets in Harness.
Perform the following steps to add a secret:
- Under Project Settings, select Secrets.
- Click New Secret, and then select Text.
- In the Add new Encrypted Text page,
- Select the Secret Manager. For example,
Harness Built-in Secret Manager. - Enter the Secret Name. For example,
harness_gitpat. - For the Secret Value, paste the GitHub personal access token you saved earlier.
- Add the Description (Optional) and Tags (Optional).
- Select Save.
- Select the Secret Manager. For example,
Connectors
Connectors in Harness enable integration with third party tools, providing authentication and operations during pipeline runtime. For instance, a GitHub connector facilitates authentication and fetching files from a GitHub repository within pipeline stages. Go to Connectors to explore connector how-tos.
Set up the GitHub connector
Perform the following steps to set up a GitHub connector:
- Copy the contents of github-connector.yml.
- In your Harness project in the Harness Manager, under Project Settings, select Connectors.
- Select Create via YAML Builder and paste the copied YAML in Step 1.
- Replace
GITHUB_USERNAMEwith your GitHub account username in the YAML (assuming you have already forked the harnesscd-example-apps repo as noted in Before You Begin). - In
projectIdentifier, verify that the project identifier is correct. You can see the Id in the browser URL (afteraccount). If it is incorrect, the Harness YAML editor suggests the correct Id. - Select Save Changes and verify that the new connector named
harness_gitconnectoris successfully created. - Select Connection Test under Connectivity Status to ensure the connection is successful.
Set up the Kubernetes connector
Perform the following steps to set up a Kubernetes connector:
- Copy the contents of kubernetes-connector.yml.
- In your Harness project, under Project Settings, select Connectors.
- Select Create via YAML Builder and paste the copied YAML in Step 1.
- Replace
DELEGATE_NAMEwith the installed Delegate name. To obtain the Delegate name, navigate to Project Settings, and then Delegates. - Select Save Changes and verify that the new connector named
harness_k8sconnectoris successfully created. - Select Connection Test under Connectivity Status to verify the connection is successful.
Environment
Environments define the deployment location, categorized as Production or Pre-Production. Each environment includes infrastructure definitions for VMs, Kubernetes clusters, or other target infrastructures. Go to Environments overview to understand environments.
Perform the following steps to set up an environment:
- In your Harness project, under Project Settings, select Environments.
- Click New Environment.
- In the New Environment page,
- Select YAML.
- Copy the contents of environment.yml, paste it into the YAML editor.
- Select Save.
- In your new environment, select the Infrastructure Definitions tab.
- Select Infrastructure Definition.
- In the Create New Infrastructure page,
- Select YAML.
- Copy the contents of infrastructure-definition.yml and paste it into the YAML editor.
- Select Save and verify that the environment and infrastructure definition are created successfully.
Services
In Harness, services represent what you deploy to an environment. You use services to configure variables, manifests, and artifacts. The Services dashboard provides service statistics such as deployment frequency and failure rate. Go to Services overview to understand services.
Perform the following steps to set up a service:
- In your Harness project, under Project Settings, select Services.
- Select New Service.
- On the Add Service page,
- Enter the service name. For example,
harnessguestbook. - Select Save.
- On the Configuration tab, select YAML option.
- Select Edit YAML, copy the contents of service.yml, and paste it into the YAML editor.
- Select Save. Verify that the service
harness_guestbookis successfully created.
- Enter the service name. For example,
Pipeline
A pipeline is a comprehensive process encompassing integration, delivery, operations, testing, deployment, and monitoring. It can use CI for code building and testing, followed by CD for artifact deployment in production. A CD Pipeline is a series of stages where each stage deploys a service to an environment. Go to CD pipeline basics to understand CD pipelines.
Pick a deployment strategy from the following:
- Rolling
- Canary
- Blue Green
Rolling deployments incrementally add nodes in a single environment with a new service version, either one-by-one or in batches defined by a window size. Rolling deployments allow a controlled and gradual update process for the new service version. Go to When to use rolling deployments to understand when to use them.
Perform the following steps to set up a pipeline with rolling deployment:
- In Default Project, select Pipelines.
- Select Create a Pipeline.
- In the Create new Pipeline page,
- Enter the name. For example,
guestbook_rolling_pipeline. - Enter a description (optional).
- Enter a tag (optional).
- Specify the YAML version. For example,
v0. - Select Inline to store the pipeline in Harness.
- Select Start with Template to create the pipeline with an existing template in Harness Manager.
- Select Start.
- Enter the name. For example,
- In the Pipeline Studio, toggle to YAML to use the YAML editor.
- Select Edit YAML to enable edit mode.
- Copy the contents of rolling-pipeline.yml.
- In your Harness pipeline YAML editor, paste the YAML.
- Select Save.
You can switch to the Visual pipeline editor and confirm the pipeline stage and execution steps as shown below.

A canary deployment updates nodes in a single environment gradually, allowing you to use gates between increments. Canary deployments allow incremental updates and ensure a controlled rollout process. Go to When to use Canary deployments to understand when to use them.
Perform the following steps to set up a pipeline with canary deployment:
- In Default Project, select Pipelines.
- Select Create a Pipeline.
- In the Create new Pipeline page,
- Enter the name. For example,
guestbook_canary_pipeline. - Enter a description (optional).
- Enter a tag (optional).
- Specify the YAML version. For example,
v0. - Select Inline to store the pipeline in Harness.
- Select Start with Template to create the pipeline with an existing template in Harness Manager.
- Select Start.
- Enter the name. For example,
- In the Pipeline Studio, toggle to YAML to use the YAML editor.
- Select Edit YAML to enable edit mode.
- Copy the contents of canary-pipeline.yml.
- In your Harness pipeline YAML editor, paste the YAML.
- Select Save.
You can switch to the Visual pipeline editor and confirm the pipeline stage and execution steps as shown below.

Blue Green deployments involve running two identical environments (staging and production) simultaneously with different service versions. QA and UAT are performed on a new service version in the staging environment first. Next, traffic is shifted from the production environment to staging, and the previous service version running on production is scaled down. Blue Green deployments are also referred to as red/black deployment by some vendors. Go to When to use Blue Green deployments to understand when to use them.
Perform the following steps to set up a pipeline with Blue Green deployment:
- In Default Project, select Pipelines.
- Select Create a Pipeline.
- In the Create new Pipeline page,
- Enter the name. For example,
guestbook_bluegreen_pipeline. - Enter a description (optional).
- Enter a tag (optional).
- Specify the YAML version. For example,
v0. - Select Inline to store the pipeline in Harness.
- Select Start with Template to create the pipeline with an existing template in Harness Manager.
- Select Start.
- Enter the name. For example,
- In the Pipeline Studio, toggle to YAML to use the YAML editor.
- Select Edit YAML to enable edit mode.
- Copy the contents of bluegreen-pipeline.yml.
- In your Harness pipeline YAML editor, paste the YAML.
- Select Save.
You can switch to the Visual pipeline editor and confirm the pipeline stage and execution steps as shown below.

Perform the following steps to install and access the Harness CLI:
- Download and configure the Harness CLI.
- MacOS
- Linux
- Windows
curl -LO https://github.com/harness/harness-cli/releases/download/v0.0.25-Preview/harness-v0.0.25-Preview-darwin-amd64.tar.gz
tar -xvf harness-v0.0.25-Preview-darwin-amd64.tar.gz
export PATH="$(pwd):$PATH"
echo 'export PATH="'$(pwd)':$PATH"' >> ~/.bash_profile
source ~/.bash_profile
harness --version
- ARM
- AMD
curl -LO https://github.com/harness/harness-cli/releases/download/v0.0.25-Preview/harness-v0.0.25-Preview-linux-arm64.tar.gz
tar -xvf harness-v0.0.25-Preview-linux-arm64.tar.gz
curl -LO https://github.com/harness/harness-cli/releases/download/v0.0.25-Preview/harness-v0.0.25-Preview-linux-amd64.tar.gz
tar -xvf harness-v0.0.25-Preview-linux-amd64.tar.gz
a. Open Windows Powershell and run the following command to download the Harness CLI:
Invoke-WebRequest -Uri https://github.com/harness/harness-cli/releases/download/v0.0.25-Preview/harness-v0.0.25-Preview-windows-amd64.zip -OutFile ./harness.zip
b. Extract the downloaded zip file and change directory to extracted file location.
c. Perform the steps below to make it accessible via terminal.
$currentPath = Get-Location
[Environment]::SetEnvironmentVariable("PATH", "$env:PATH;$currentPath", [EnvironmentVariableTarget]::Machine)
d. Restart terminal.
-
Clone the Forked
harnesscd-example-appsrepo and change directory.git clone https://github.com/GITHUB_ACCOUNTNAME/harnesscd-example-apps.gitcd harnesscd-example-appsnoteReplace
GITHUB_ACCOUNTNAMEwith your GitHub Account name. -
Log in to Harness from the CLI.
harness login --account-id ACCOUNT_ID --api-key HARNESS_API_TOKENnoteReplace
HARNESS_API_TOKENwith Harness API Token that you obtained in Before you begin section of this tutorial. -
After logging in and selecting the project, configure the core resources Harness requires to run a deployment, including a delegate, a secret, two connectors, an environment, a service, and a deployment pipeline, as explained in the following sections.
For the pipeline to run successfully, follow all of the following steps as they are, including the naming conventions.
Delegate
The Harness Delegate is a service that runs in your local network or VPC to establish connections between the Harness Manager and various providers such as artifact registries, cloud platforms, etc. The delegate is installed in the target infrastructure (Kubernetes cluster) and performs operations including deployment and integration. Go to Delegate Overview to understand the delegate.
Perform the following steps to set up a delegate:
-
Under Project Settings, select Delegates.
-
Click New Delegate.
-
Select Kubernetes in the Select where you want to install your Delegate section.
-
In the Install your Delegate section, for this tutorial, install the delegate using Helm Chart.
-
Add the Harness Helm chart repo to your local helm registry using the following command.
helm repo add harness-delegate https://app.harness.io/storage/harness-download/delegate-helm-chart/ -
Update the repo using the following command:
helm repo update harness-delegate -
Copy and run the install command from the Delegate installation wizard as shown in the following example:
Here, the
ACCOUNT_ID,MANAGER_ENDPOINTandDELEGATE_TOKENare auto-populated values you will get from the wizard itself.helm upgrade -i helm-delegate --namespace harness-delegate-ng --create-namespace \harness-delegate/harness-delegate-ng \--set delegateName=helm-delegate \--set accountId=ACCOUNT_ID \--set managerEndpoint=MANAGER_ENDPOINT \--set delegateDockerImage=harness/delegate:23.03.78904 \--set replicas=1 --set upgrader.enabled=false \--set delegateToken=DELEGATE_TOKEN -
Select Verify to verify that the delegate is installed successfully and can connect to the Harness Manager.
You can also follow the Install Harness Delegate on Kubernetes or Docker steps to install the delegate using the Harness Terraform Provider or a Kubernetes manifest.
Secrets
Harness offers built-in secret management for encrypted storage of sensitive information. Secrets are decrypted when needed, and only the private network-connected Harness Delegate has access to the key management system. You can also integrate your own secret manager. Go to Harness Secret Manager Overview to understand secrets in Harness.
Create a text secret from the GitHub PAT you generated in Before You Begin section:
harness secret --name harness_gitpat --type text --value <YOUR_GITHUB_PAT> apply
Connectors
Connectors in Harness enable integration with third party tools, providing authentication and operations during pipeline runtime. For instance, a GitHub connector facilitates authentication and fetching files from a GitHub repository within pipeline stages. Go to Connectors to explore connector how-tos.
GitHub connector
Perform the following steps to set up a GitHub connector:
- Replace
GITHUB_USERNAMEwith your GitHub account username in thegithub-connector.yaml. - In
projectIdentifier, verify that the project identifier is correct. You can see the Id in the browser URL (afteraccount). If it is incorrect, the Harness YAML editor will suggest the correct Id. - Create the GitHub connector using the following CLI command:
harness connector --file github-connector.yml apply --git-user <YOUR GITHUB USERNAME>
Kubernetes Connector
Perform the following steps to set up a Kubernetes connector:
-
In
kubernetes-connector.yml, confirm the delegate name is set tohelm-delegate(the name used in the Delegate step earlier). -
Create the Kubernetes connector using the following CLI command:
harness connector --file kubernetes-connector.yml apply --delegate-name helm-delegate
Environment
Environments define the deployment location, categorized as Production or Pre-Production. Each environment includes infrastructure definitions for VMs, Kubernetes clusters, or other target infrastructures. Go to Environments overview to understand environments.
Perform the following steps to set up an environment:
-
Run the following CLI Command to create Environments in your Harness project:
harness environment --file environment.yml apply -
In your new environment, add Infrastructure Definitions using the following CLI command:
harness infrastructure --file infrastructure-definition.yml apply
Services
In Harness, services represent what you deploy to environments. You use services to configure variables, manifests, and artifacts. The Services dashboard provides service statistics like deployment frequency and failure rate. Go to Services overview to understand services.
Run the following CLI command to create Services in your Harness Project.
harness service --file service.yml apply
Pipelines
A pipeline is a comprehensive process encompassing integration, delivery, operations, testing, deployment, and monitoring. It can use CI for code building and testing, followed by CD for artifact deployment in production. A CD Pipeline is a series of stages where each stage deploys a service to an environment. Go to CD pipeline basics to understand CD pipelines.
Pick a deployment strategy from the following:
- Canary
- Blue Green
- Rolling
A canary deployment updates nodes in a single environment gradually, allowing you to use gates between increments. Canary deployments allow incremental updates and ensure a controlled rollout process. Go to When to use Canary deployments to understand when to use them.
Run the following CLI Command for canary deployment:
harness pipeline --file canary-pipeline.yml apply
You can switch to the Visual editor and confirm the pipeline stage and execution steps as shown below.

Blue Green deployments involve running two identical environments (staging and production) simultaneously with different service versions. QA and UAT are performed on a new service version in the staging environment first. Next, traffic is shifted from the production environment to staging, and the previous service version running on production is scaled down. Blue Green deployments are also referred to as red/black deployment by some vendors. Go to When to use Blue Green deployments to understand when to use them.
Run the following CLI Command for blue-green deployment:
harness pipeline --file bluegreen-pipeline.yml apply
You can switch to the Visual pipeline editor and confirm the pipeline stage and execution steps as shown below.

Rolling deployments incrementally add nodes in a single environment with a new service version, either one-by-one or in batches defined by a window size. Rolling deployments allow a controlled and gradual update process for the new service version. Go to When to use rolling deployments to understand when to use them.
Run the following CLI Command for Rolling deployment:
harness pipeline --file rolling-pipeline.yml apply
You can switch to the Visual pipeline editor and confirm the pipeline stage and execution steps as shown below.

Execute the deployment pipelines
You can execute the pipeline deployment using any of the following:
- Manual - Start the pipeline on demand from the Harness UI whenever you want to perform a deployment.
- Automatic - Configure a trigger so the pipeline runs automatically in response to events such as Git commits, pull requests, or webhook notifications.
Every execution of a CD pipeline results in a deployment to the target environment.
Manual deployment
Perform the following steps to manually execute the deployment:
-
After configuring the pipeline, select Run to initiate the deployment.
-
Observe the execution logs as Harness deploys the workload and checks for steady state.
-
After a successful execution, you can check the deployment on your Kubernetes cluster using the following command:
kubectl get pods -n default -
To access the Guestbook application deployed by the Harness pipeline, port forward the service and access it at
http://localhost:8080kubectl port-forward svc/guestbook-ui 8080:80
Automatic deployment
Using Triggers
With Pipeline Triggers, you can start automating your deployments based on events happening in an external system. This system could be a Source Repository, an Artifact Repository, or a third party system. Any Developer with Pipeline Create and Edit permissions can configure a trigger in Harness.
Follow the Pipeline Triggers tutorial to see triggers in action.
Using API
You can also use the Harness API to manage resources, view, create/edit, or delete them.
Refer to the Get started with Harness API guide to learn how to use the API for automation.
Deploy your own application
You can use your own microservice application with this tutorial by following the steps below:
-
Use the same delegate that you deployed as part of this tutorial. Alternatively, deploy a new delegate, but remember to use a newly created delegate identifier when creating connectors.
-
If you intend to use a private Git repository that hosts your manifest files, create a Harness secret containing the Git personal access token (PAT). Subsequently, create a new Git connector using this secret.
-
Create a Kubernetes connector if you plan to deploy your applications in a new Kubernetes environment. Ensure to update the infrastructure definition to reference this newly created Kubernetes connector.
-
Once you complete all the aforementioned steps, create a new Harness service that uses Kubernetes manifests for deploying applications.
-
Establish a new deployment pipeline and select the newly created infrastructure definition and service. Choose a deployment strategy that aligns with your microservice application's deployment needs.
Harness GitOps (built on top of Argo CD) watches the state of your application as defined in a Git repo, and can pull (either automatically or on demand) these changes into your Kubernetes cluster, leading to an application sync.
Harness GitOps supports Argo CD as the GitOps reconciler.
Whether you are new to GitOps or an experienced practitioner, this tutorial helps assist you in getting started with Harness GitOps.
Deploy with Harness GitOps
Select any of the following options to get started with Harness GitOps.
- UI
- Terraform Provider
- CLI
Perform the following steps to access Harness GitOps using UI:
- Log in to Harness Manager.
- Select Projects, and then select Default Project.
- Select Deployments, and then select GitOps.
- Set up a GitOps Agent (connects Harness to your cluster), a Repository (what to deploy), a Cluster (where to deploy it), and an Application (which ties the Agent, Repository, and Cluster) as explained in the following sections.
GitOps Agent
A Harness GitOps Agent is a worker process that runs in your environment, makes secure, outbound connections to Harness, and performs all the GitOps tasks you request in Harness.
Perform the following steps to set up a GitOps Agent:
- Select Settings in your project.
- Select GitOps Agents.
- Click New GitOps Agent.
- On the Agent Installation page, for Do you have any existing Argo CD instances?,
- Select Yes if you already have a Argo CD Instance.
- Select No to install the Harness GitOps Agent.
- (No is selected) Harness GitOps Agent Fresh Install
- (Yes is selected) Harness GitOps Agent with existing Argo CD instance
Perform the following steps:
- Select Start.
- In the Name field, enter the name for the new Agent.
- In the GitOps Operator field, select Argo.
- In Namespace, enter the namespace where you want to install the Harness GitOps Agent.
- Harness GitOps Agent will have access to create or modify resources in other namespaces so this namespace doesn't necessarily have to be the same as the one where your apps are deployed. For instance, you can have
argocdas the namespace for installing the GitOps Agent (the example in the image below usesgitops-agentas the namespace). - Ensure that this namespace already exists on your Kubernetes cluster.
- Harness GitOps Agent will have access to create or modify resources in other namespaces so this namespace doesn't necessarily have to be the same as the one where your apps are deployed. For instance, you can have
- If Namespaced is selected, the Harness GitOps Agent is installed without cluster-scoped permissions, and it can access only those resources that are in its own namespace. You can select Skip Crds to avoid a collision if already installed.
- Select Continue.
- In the Install Agent page,
-
Select YAML or Helm Chart.

-
Download the Harness GitOps Agent script using the YAML or Helm Chart options.
- The YAML option provides a manifest file.
- The Helm Chart option offers a Helm chart file. Both can be downloaded and used to install the GitOps Agent on your Kubernetes cluster.
-
Run the command to run the installation as per the configurations selected in Step 4.2.
-
Select Continue and verify the GitOps Agent is successfully installed and can connect to Harness Manager.
-
Perform the following steps:
-
Select Start.
-
You can not edit any values in Overview page.
Harness GitOps Agent will have access to create or modify resources in other namespaces so this namespace doesn't necessarily have to be the same as the one where your apps are deployed. For instance, you can choose
argocdas the namespace for installing the GitOps Agent (the example in the image below usesgitops-agentas the namespace). Ensure that this namespace already exists on your Kubernetes cluster. -
Click Continue.
-
In the Install Agent page,
- Select YAML or Helm Chart.

- Download the Harness GitOps Agent script using the YAML or Helm Chart options.
- The YAML option provides a manifest file.
- The Helm Chart option offers a Helm chart file. Both can be downloaded and used to install the GitOps Agent on your Kubernetes cluster.
- Run the command to run the installation as per the configurations selected in Step 4.2.
- Select Continue and verify the GitOps Agent is successfully installed and can connect to Harness Manager.
- Select YAML or Helm Chart.
-
Once you have installed the Agent, Harness will start importing all the entities from the existing Argo CD Project.
Repositories
A Harness GitOps repository contains the declarative description of a desired state. The declarative description can be in Kubernetes manifests, Helm Chart, Kustomize manifests, and so on.
Perform the following steps to add a repository:
- Select Settings, and then select Repositories.
- Click New Repository.
- Specify Git as the repository type.
- In the Overview page,
- Enter a repo name.
- In GitOps Agent, select the Agent that you installed in your cluster and select Apply.
- In Git Repository URL, enter
https://github.com/GITHUB_USERNAME/harnesscd-example-appsand replaceGITHUB_USERNAMEwith your GitHub username. - Select Continue.
- In the Credentials page,
- Select Specify Credentials For Repository.
- Select HTTPS as the Connection Type.
- Select Anonymous (no credentials required) as the Authentication method.
- Select Save & Continue and wait for Harness to verify the connection.
- After successful verification, click Finish.
Clusters
A Harness GitOps Cluster is the target deployment cluster that is compared to the desired state. Clusters are synced with the source manifests you add as GitOps Repositories.
Perform the following steps to add a new cluster:
- Select Settings, and then select Clusters.
- Click New Cluster.
- In the Overview page,
- In the Name field, enter a name for the cluster.
- In GitOps Agent, select the Agent you installed in your cluster, and then select Apply.
- Select Continue.
- In the Details page,
- select Use the credentials of a specific Harness GitOps Agent.
- Select Save & Continue and wait for the Harness to verify the connection.
- After successful verification, click Finish.
Applications
GitOps Applications are how you manage GitOps operations for a given desired state and its live instantiation. A GitOps Application collects the Repository (what you want to deploy), Cluster (where you want to deploy), and Agent (how you want to deploy). You select these entities when you set up your Application.
Due to an update in the Kustomization Controller, the vanilla YAML files now need to include a namespace. The specific repository and path used in this example include the namespace field in the YAMLs.
Perform the following steps to add a new application:
-
Select Projects, and then select Default Project.
-
Select Deployments, and then select GitOps.
-
Select Applications.
-
Click New Application.
-
In the Overview page,
- Enter the Application Name. For example,
guestbook. - In GitOps Operator, select Argo.
- In GitOps Agent, select the Agent that you installed in your cluster.
- Select Continue.
- Enter the Application Name. For example,
-
In the Sync Policy page,
- Select Manual option.
- Ensure Apply Out of Sync Only and Auto-Create Namespace are checked under Sync Options settings.
- Use Foreground for the Prune Propagation Policy.
- Select Continue.
-
In the Source page,
- Select Repo URL option
- Enter the repository URL you created earlier.
- Select
masteras the Target Revision. - Use
workshop-guestbookfor the Path. - Select Continue.
-
In the Destination page,
- Select the cluster you previously created under Cluster.
- For Namespace, enter
guestbook. This is the target namespace for Harness GitOps to sync the application. - Click Finish.
-
Select Sync to synchronize the GitOps application state check and details.
-
Select Synchronize to initiate the deployment.
-
After a successful execution, you can check the deployment on your Kubernetes cluster using the following command:
kubectl get pods -n guestbookTo access the Guestbook application deployed via the Harness Pipeline, port forward the service and access it at
http://localhost:8080:kubectl port-forward svc/guestbook-ui 8080:80 -n guestbookA successful application sync displays the following status tree under Resource View.

Harness offers a Terraform Provider to help you declaratively manage Harness GitOps entities alongside your application and cluster resources. These steps help you using Terraform to create and install the GitOps Agent, define related Harness entities, and deploy a sample application to your cluster.
A Terraform Provider is a plugin that allows Terraform to define and manage resources using a particular software API. In this tutorial, these resources will be Harness entities.
Before proceeding:
- Generate a Harness API token.
- Ensure Terraform is installed on your local machine that can connect to your cluster.
Set up Harness Terraform Provider
Perform the following steps to set up Harness Terraform Provider:
-
Clone or download the Harness gitops-terraform-onboarding project.
git clone https://github.com/harness-community/gitops-terraform-onboarding.gitcd gitops-terraform-onboarding/ -
Initialize the Terraform configuration. This step will also install the Harness provider plugin.
terraform init
Input variables
Before provisioning the required Harness resources, update the Terraform input variables to match your environment.
Perform the following steps:
-
Open
terraform.tfvars. This file contains example values for the Harness entities that will be created.project_id = "default_project"org_id = "default"agent_identifier = "testagent"agent_name = "testagent"agent_namespace = "default"repo_identifier = "testrepo"repo_name = "testrepo"repo_url = "https://github.com/harness-community/harnesscd-example-apps/"cluster_identifier = "testcluster"cluster_name = "testcluster"env_name = "testenv"service_name = "testservice" -
In
terraform.tfvarsfile, change the value ofrepo_urlto your GitHub fork of theharnesscd-example-appsrepository. You can keep the other variable values as they are or rename them to suit your environment. -
Set
account_idandharness_api_tokenas Terraform environment variables. Your Account ID can be found in the URL afteraccountor when you are logged intoapp.harness.io.export TF_VAR_account_id="123abcXXXXXXXX"export TF_VAR_harness_api_token="pat.abc123xxxxxxxxxx…"
Never store your Harness API key in plain text or commit it to version control. Use an environment variable or a dedicated secrets manager.
Terraform module
A Terraform module is a collection of files that define the desired state to be enforced by Terraform. These files normally have the .tf extension.

Perform the following steps:
-
Open
agent.tffile. This file defines the GitOps Agent in Harness and then deploys the agent manifest to your cluster. The agent is created using theharness_platform_gitops_agentresource.resource "harness_platform_gitops_agent" "gitops_agent" {identifier = var.agent_identifieraccount_id = var.account_idproject_id = var.project_idorg_id = var.org_idname = var.agent_nametype = "MANAGED_ARGO_PROVIDER"metadata {namespace = var.agent_namespacehigh_availability = false}}If you have an existing Argo CD instance, change the
typeargument toCONNECTED_ARGO_PROVIDER. Otherwise leave as is. -
If you have made changes to any configuration files, verify the syntax is still valid.
terraform validate -
Preview the changes Terraform will make in Harness and your cluster.
terraform plan -
Apply the Terraform configuration to create the Harness and cluster resources. Type
yesto confirm when prompted.terraform applyObserve the output of
terraform applyas your resources are created. It may take a few minutes for all the resources to be provisioned.
Verify GitOps deployment
Perform the following steps to verify the GitOps deployment:
-
Log in to the Harness App.
-
Select Deployments, then GitOps.
-
Select Settings, and then select GitOps Agents.
-
Verify your GitOps Agent is listed and displays a HEALTHY health status.
-
Navigate back to Settings, and then select Repositories.
-
Verify your
harnesscd-example-appsrepo is listed with Active connectivity status. -
Navigate back to Settings, and then select Clusters.
-
Verify you cluster with its associated GitOps Agent is listed with Active connectivity status.
-
Select Application from the top right of the GitOps page.
-
Click the
guestbookapplication. This is the application your deployed from theharnesscd-example-appsrepo. -
Select Resource View to see the cluster resources that have been deployed. A successful Application sync will display the following status tree.

-
Return to a local command line. Confirm you can see the GitOps Agent and guestbook application resources in your cluster.
kubectl get deployment -n defaultkubectl get svc -n defaultkubectl get pods -n defaultTo access the Guestbook application deployed via the Harness Pipeline, port forward the service and access it at
http://localhost:8080:kubectl port-forward svc/guestbook-ui 8080:80
Cleaning up
If you no longer need the resources created in this tutorial, run the following command to delete the GitOps agent and associated Harness entities.
terraform destroy
terraform destroy removes the Harness entities but not the cluster resources it deployed. If you no longer need those, run the following commands to manually remove them:
kubectl delete deployment guestbook-ui -n default
kubectl delete service guestbook-ui -n default
You can also complete this tutorial using the Harness CLI. The following steps show how to configure the required resources and deploy the sample application using a GitOps workflow.
Perform the following steps:
-
Go to Install and configure the Harness CLI to set up the CLI.
-
Clone the Forked
harnesscd-example-appsrepo and change directory.git clone https://github.com/GITHUB_ACCOUNTNAME/harnesscd-example-apps.gitcd harnesscd-example-appsnoteReplace
GITHUB_ACCOUNTNAMEwith your GitHub Account name. -
Select Deployments, and then select GitOps.
-
Set up a GitOps Agent (connects Harness to your cluster), a Repository (what to deploy), a Cluster (where to deploy it), and an Application (which ties the Agent, Repository, and Cluster) as explained in the following sections.
GitOps Agent
A Harness GitOps Agent is a worker process that runs in your environment, makes secure, outbound connections to Harness, and performs all the GitOps tasks you request in Harness.
Perform the following steps to set up a GitOps Agent:
- Select Settings in your project.
- Select GitOps Agents.
- Click New GitOps Agent.
- On the Agent Installation page, for Do you have any existing Argo CD instances?,
- Select Yes if you already have a Argo CD Instance.
- Select No to install the Harness GitOps Agent.
- (No is selected) Harness GitOps Agent Fresh Install
- (Yes is selected) Harness GitOps Agent with existing Argo CD instance
Perform the following steps:
-
Select Start.
-
In the Name field, enter the name for the new Agent.
-
In the GitOps Operator field, select Argo.
-
In Namespace, enter the namespace where you want to install the Harness GitOps Agent. For this tutorial, use the
defaultnamespace to install the Agent and deploy applications. -
Select Continue. The Review YAML settings appear. This is the manifest YAML for the Harness GitOps Agent. You will download this YAML file and run it in your Harness GitOps Agent cluster.
kubectl apply -f gitops-agent.yml -n default -
Select Continue and verify the Agent is successfully installed and can connect to Harness Manager.
-
Before proceeding, store the Agent Identifier value as an environment variable for use in the subsequent commands:
export AGENT_NAME=GITOPS_AGENT_IDENTIFIERReplace
GITOPS_AGENT_IDENTIFIERwith GitOps Agent Identifier.
Perform the following steps:
-
Select Start.
-
In the Namespace field, enter the namespace where you want to install the Harness GitOps Agent. Typically, this is the target namespace for your deployment.
-
Select Next. The Review YAML settings appear. This is the manifest YAML for the Harness GitOps Agent. You will download this YAML file and run it in your Harness GitOps Agent cluster.
kubectl apply -f gitops-agent.yml -n default -
Once you have installed the Agent, Harness will start importing all the entities from the existing Argo CD Project
-
Before proceeding, store the Agent Identifier value as an environment variable for use in the subsequent commands:
export AGENT_NAME=GITOPS_AGENT_IDENTIFIERReplace
GITOPS_AGENT_IDENTIFIERwith GitOps Agent Identifier.
Repositories
A Harness GitOps repository contains the declarative description of a desired state. The declarative description can be in Kubernetes manifests, Helm Chart, Kustomize manifests, and so on.
Run the following command to create a repository using CLI:
harness gitops-repository --file guestbook/harness-gitops/repository.yml apply --agent-identifier $AGENT_NAME
Clusters
A Harness GitOps Cluster is the target deployment cluster that is compared to the desire state. Clusters are synced with the source manifests you add as GitOps Repositories.
Run the following command to create a cluster using CLI:
harness gitops-cluster --file guestbook/harness-gitops/cluster.yml apply --agent-identifier $AGENT_NAME
Applications
GitOps Applications are how you manage GitOps operations for a given desired state and its live instantiation. A GitOps Application collects the Repository (what you want to deploy), Cluster (where you want to deploy), and Agent (how you want to deploy). You select these entities when you set up your Application.
Run the following command to create an application using CLI:
harness gitops-application --file guestbook/harness-gitops/application.yml apply --agent-identifier $AGENT_NAME
Synchronize the application
After setting up the GitOps workflow, you can synchronize the application with your Kubernetes setup.
Perform the following steps:
-
Navigate to Harness UI > Default Project > GitOps > Applications.
-
Click your GitOps application.
-
Click SYNC and then Synchronize to kick off the application deployment.
-
Observe the Sync state as Harness synchronizes the workload under Resource View tab.

-
After a successful execution, you can check the deployment in your Kubernetes cluster using the following command:
kubectl get pods -n default -
To access the Guestbook application deployed via the Harness pipeline, port forward the service and access it at
http://localhost:8080:kubectl port-forward svc/kustomize-guestbook-ui 8080:80
Next steps
You have deployed the Guestbook application with Harness CD and GitOps using a Kubernetes manifest.
Continue your learning journey with the following:
- Variables and expressions: Parameterize your pipeline with reusable values and runtime inputs.
- Pipeline triggers: Run your pipeline automatically in response to Git events.
- Harness GitOps ApplicationSet tutorial: Explore GitOps ApplicationSets in more depth.