---
icon: material/source-branch
---

10x uses a [GitOps-based](https://www.redhat.com/en/topics/devops/what-is-gitops){target="\_blank"} approach to configuration management: a secure, version-controlled, auditable record of every change, applied across distributed environments.

The engine pulls configuration over two delivery lanes that share the same loop: a user-managed Git repository ([`@github`](https://doc.log10x.com/config/github/)) and a Kubernetes ConfigMap ([`@kubernetes`](https://doc.log10x.com/config/k8s/)). It polls each for changes and hot-reloads in place, so an edit on either lane converges across every consuming pod within one poll. The change history is the single source of truth, reviewed, diffed, and revertible with existing tools whether it lands as a Git commit or a ConfigMap edit.

Changes reach a lane two ways. An AI agent proposes them through the [log10x MCP](https://doc.log10x.com/apps/mcp/): `configure_engine` produces the per-pattern action plan and the `gh` PR command that lands it on the Git lane, and `set_gitops_repo` points the loop at the right repository. The same plan is the `log10x-action-intent` file the [Kubernetes lane](https://doc.log10x.com/config/k8s/) serves from a ConfigMap. An operator can edit either lane by hand instead. The engine treats both identically.

### :material-hammer-wrench: Getting started

1. Fork the [Config Repo](https://github.com/log-10x/config/fork){target="\_blank"} into a GitHub account.

2. Create a new branch for the app configuration (e.g., `acme-receiver`)

3. Edit [app config](https://doc.log10x.com/config/app/) files Use GitHub’s built-in file editor or clone the repository to make changes locally. See the documentation of each [app](https://doc.log10x.com/apps) for its available configuration options.

4. Commit and Push Changes.

5. Follow the deployment procedure for your specific app (Reporter, Receiver, or Retriever) under [apps](https://doc.log10x.com/apps/) to deploy 10x with the new configuration.

### :material-trophy-award: Best Practices

:material-source-branch: Branch Strategy: Use separate branches for different [apps](https://doc.log10x.com/apps) and environments to maintain configuration isolation and enable safe parallel development.

:material-shield-key: Secret Management: Never commit sensitive credentials to Git. Use [JavaScript expressions](https://doc.log10x.com/config/yaml#javascript-expressions) with [TenXEnv.get()](https://doc.log10x.com/api/js/#TenXEnv.get) to access runtime environment variables:
```yaml
apiKey: $=TenXEnv.get("API_SECRET")
dbPassword: $=TenXEnv.get("DB_PASSWORD")
```

:material-git: Repository Sync: Regularly [sync](https://doc.log10x.com/config/github) with the base repository to receive security patches, feature updates, and performance improvements; for values that change per cluster, [load them from a Kubernetes ConfigMap](https://doc.log10x.com/config/k8s/) instead of forking the repo per cluster.

:material-tag: Version Tags: Tag stable configurations for production deployments to enable quick rollbacks and maintain deployment history.

:material-file-check: Configuration Validation: Test configuration changes in development environments before merging to production branches.

:material-account-group: Access Control: Implement branch protection rules and code review requirements for production configuration changes.
