Back to articles
Technology Insight

GitOps for Docker Swarm: Automating App Deployment with ArgoCD and HashiCorp Vault

June 2, 2026

Introduction to GitOps in a Docker Swarm Ecosystem

In the evolving landscape of DevOps, GitOps has emerged as a definitive paradigm for infrastructure and application lifecycle management. By treating Git repositories as the single source of truth for declarative infrastructure and applications, organizations achieve unprecedented levels of automation, auditability, and security. While Kubernetes remains the dominant platform for GitOps tools, many enterprise environments continue to rely on Docker Swarm due to its operational simplicity, lightweight footprint, and native integration with the Docker engine.

Bringing GitOps capabilities to Docker Swarm presents unique architectural challenges, primarily because native GitOps controllers like ArgoCD are built specifically for Kubernetes. However, by treating a lightweight Kubernetes cluster or management plane as the GitOps engine, we can orchestrate deployments across remote Docker Swarm clusters. This article provides an architectural blueprint for configuring a robust GitOps pipeline for Docker Swarm using ArgoCD for state synchronization and HashiCorp Vault for secure, centralized secret management.

The Architectural Blueprint

To implement GitOps on Docker Swarm without losing the simplicity of the Swarm data model, we introduce a hybrid control plane. The architecture relies on three primary pillars:

  • The Git Repository (Source of Truth): Contains declarative manifests defining the desired state of the Docker Swarm services, typically structured as Docker Compose or Docker Stack files.
  • ArgoCD (The GitOps Controller): Hosted on a minimal management plane, ArgoCD continuously monitors the Git repository and reconciles the desired state with the target environment.
  • HashiCorp Vault (The Secret Manager): Externalizes sensitive data (database credentials, API keys, certificates), ensuring that no plaintext secrets reside in the Git repository.
Operational Tip: By utilizing ArgoCD plugins or custom drivers, we can intercept the GitOps sync lifecycle to translate Kubernetes-native CRDs or generic manifests into native Docker Swarm stack deployment commands via the Docker API.

Step-by-Step Configuration Guide

1. Designing the Git Repository Structure

A well-structured Git repository is vital for a scalable GitOps workflow. We recommend dividing the repository into infrastructure definitions, global configuration, and application services. Below is an optimized directory layout:

├── apps/
│   ├── microservice-a/
│   │   ├── docker-compose.yml
│   │   └── secrets.env.tmpl
│   └── microservice-b/
│       └── docker-compose.yml
├── argocd/
│   ├── application.yaml
│   └── config-management-plugin.yaml
└── infrastructure/
    └── vault-agent-config.hcl

2. Setting Up ArgoCD to Manage External Swarm Clusters

Since ArgoCD does not natively speak "Docker Swarm API," we utilize an ArgoCD Config Management Plugin (CMP) or an intermediate agent. The plugin triggers during the synchronization phase, pulls the Docker Compose manifests, injects runtime variables, and applies them directly to the remote Swarm manager node using secure SSH tunneling or TLS-encrypted Docker sockets.

Here is an example of an ArgoCD Application manifest targeting our Swarm orchestration layer:apiVersion: argoproj.io/v1alpha1 kind: Application metadata: name: docker-swarm-app-stack namespace: argocd spec: project: default source: repoURL: '[https://github.com/enterprise/swarm-gitops.git](https://github.com/enterprise/swarm-gitops.git)' targetRevision: HEAD path: apps/microservice-a plugin: name: swarm-deployer-plugin destination: server: '[https://kubernetes.default.svc](https://kubernetes.default.svc)' namespace: swarm-control-plane syncPolicy: automated: prune: true selfHeal: true

3. Integrating HashiCorp Vault for Secure Secret Injection

Storing secrets in plaintext within a Git repository violates fundamental security principles. HashiCorp Vault solves this by acting as the centralized secrets provider. During the synchronization process, the ArgoCD custom plugin interacts with Vault using a secure AppRole or Kubernetes Authentication method.

The integration follows a strict lifecycle managed automatically upon Git commits:

  • ArgoCD detects a commit change and triggers the custom deployment plugin.
  • The plugin authenticates against the HashiCorp Vault API using pre-configured, short-lived tokens.
  • Vault verifies the identity and returns the requested secrets dynamically.
  • The plugin injects these secrets into the Docker Environment Variables or generates transient docker secret objects before initiating the docker stack deploy command.
  • Automating App Synchronization and Enforcement

    Once configured, the synchronization loop operates autonomously. When a developer modifies an application configuration or bumps an image version in the Git repository, the following automated sequence occurs:

    First, Git receives the push event and alerts ArgoCD via webhooks (minimizing synchronization latency). ArgoCD then performs a differential analysis, identifying that the cluster's current state diverges from the desired state defined in Git. Rather than applying changes directly to Kubernetes, the custom plugin executes a controlled sequence on the Docker Swarm leader node:

    export DOCKER_HOST="ssh://[email protected]"
    # Retrieve dynamic database secret from Vault
    DB_PASS=$(vault kv get -field=password secret/data/production/db)
    # Deploy the stack securely
    printf "$DB_PASS" | docker secret create db_password_v1 -
    docker stack deploy --compose-file docker-compose.yml my_enterprise_stack

    This ensures that configuration drift is eliminated automatically. If an operator manually modifies a service directly on the Docker Swarm CLI, ArgoCD will detect the discrepancy and overwrite it, enforcing the state declared within Git as the absolute authority.

    Best Practices for Production Environments

    Deploying GitOps at enterprise scale requires adherence to rigorous security and operational paradigms. Organizations adopting this workflow should implement the following recommendations:

    • Enforce Strict Least-Privilege Access: Ensure that the credentials utilized by ArgoCD to access remote Swarm managers are tightly restricted. Use dedicated SSH keys restricted to specific commands, or scoped Docker Context TLS certificates.
    • Implement Automated Secret Rotation: Leverage Vault's dynamic secret engines to periodically rotate system credentials. Configure your GitOps engine to automatically re-deploy stacks when secrets are updated.
    • Maintain Granular Audit Trails: Enable comprehensive access logging within HashiCorp Vault and commit verification within Git. Every deployment action must be traceable back to a specific pull request approval.

    Conclusion

    By blending the lightweight efficiency of Docker Swarm with the rigorous compliance of GitOps via ArgoCD and HashiCorp Vault, organizations can achieve a modern, automated deployment pipeline without the overhead of migrating to a full-scale Kubernetes infrastructure. This architecture ensures high delivery velocity, deterministic environment states, and robust enterprise security control.

    GitOps for Docker Swarm: Automating App Deployment with ArgoCD and HashiCorp Vault | DPTCloud