The honest version of build versus buy
If you have a strong platform team and unusual requirements, building on Argo CD or Flux is a good choice, and many excellent teams run that stack. This page is not an argument that DIY is wrong. It lists what the DIY route includes once it covers everything a production platform does.
GitOps engines are no longer the hard part. Argo CD installs in minutes, and managed versions exist, for example in Amazon EKS. The work is in everything around the engine.
What the full toolchain includes
A platform that covers what Ankra covers usually needs these pieces.
- Clusters. Terraform or Crossplane modules per provider, kubeadm or k3s bootstrapping where there is no managed service, and an autoscaler set up for each cloud.
- Delivery. Argo CD or Flux, a repository layout, promotion with Kargo or conventions, and a secrets operator.
- CI. Runners, image builds, Semgrep, Checkov and Trivy, a gate that blocks a failing image, a registry and preview environments.
- Security posture. A workload scanner, somewhere to store and triage findings, and a way to rank them by real exploitation.
- Cost. OpenCost for allocation, plus your own analysis for right-sizing and provider choices.
- Backups. Velero, database-aware backups and restore tests.
- Alerts. Alertmanager routing to the right channel for each team.
- AI. MCP servers for each tool, an AI client and rules for what it may change.
Each piece is good software, and each has its own upgrade cycle. Argo CD ships a minor release roughly every quarter, Kargo has announced a 2.0 rewrite, and External Secrets Operator paused releases in 2025 for lack of maintainers before it recovered. In March 2026 a compromised Trivy release (CVE-2026-33634) showed that scanners themselves need watching. Somebody on your team owns all of that.
What stays the same with Ankra
The parts of GitOps you want are unchanged. With a repository connected, Git holds every change, and commits you push are applied. Add-ons are standard Helm releases, so helm list and helm rollback still work, and your configuration is plain Helm values and Kubernetes YAML in an Ankra-defined layout. Hand edits are kept, because Ankra only overwrites the files it owns.
What changes
The pieces you would build become the product.
The engine is built in. Ankra’s deployment engine runs through its agent. Changes apply immediately, and drift is checked on a schedule that backs off to every 30 minutes once a stack is stable. There is no Argo CD or Flux to run. Clusters created before the native engine keep Argo CD until they are migrated.
Stacks set the order. A stack declares which add-on depends on which, so the database comes up before the service that needs it. A versioned stack profile is instantiated on each cluster with its own inputs, and Ankra shows which deployments have fallen behind the latest version.
Delivery is one path. Applications generate build files for your repository, Ankra Pipelines test, build and scan in your own cluster, only the image that passed the gate is published, and every successful build deploys. Pull-request previews give each change its own environment. Ankra can also convert existing workflows from GitHub Actions and GitLab CI.
Day two is included. The Security Center ranks running-workload vulnerabilities by CISA KEV and EPSS. Cloud Cost estimates spend and reprices clusters on other providers. Backups go to a bucket you own, and notification routing sends each alert to the right channel.
The AI sees all of it. Ankra’s assistant reads logs, events, manifests, stack history, Git and pipeline runs from one place. It drafts stacks from a description, analyses alerts and opens fix pull requests on GitHub. Every write waits for a person by default.
Limits to check
Ankra makes choices that a DIY toolchain leaves open. Check them against your requirements.
- the GitOps repository must be on GitHub or Bitbucket Cloud, and Applications and previews need GitHub
- several documented pipeline stage kinds, including in-pipeline approval and deploy stages, do not run yet
- Ankra’s control plane is a hosted service in the EU, with on-premises setup by arrangement on Enterprise
- air-gapped clusters are not supported, because the agent needs an outbound connection
When DIY is still the right call
- You have platform engineers whose full-time job is the platform, and you want it that way.
- You need a fully self-hosted or air-gapped stack today.
- Your delivery model is deeply custom, for example progressive delivery you have invested years in.
If none of those apply, compare the full toolchain, not just the engine, with keeping Git as the source of truth on a platform that runs the rest.
Try the comparison yourself
The free plan includes 30 worker vCPU for good, with no credit card. Import an existing cluster with one Helm command, connect your Git repository, and compare a real release with your current process.
Reviewed 9 October 2026 against Argo CD 3.5, Flux 2.9, Kargo 1.12 and the linked documentation. Tools and features change.