CNCF [Cloud Native Computing Foundation]
Sometimes, Lipstick Is Exactly What a Pig Needs! - Abby Bangser, Syntasso & Whitney Lee, VMware
updated
KubeArmor leverages Linux security modules (LSMs) such as AppArmor, SELinux, or BPF-LSM to enforce the user-specified policies. KubeArmor generates rich alerts/telemetry events with container/pod/namespace identities by leveraging eBPF.
Mofi (@moficodes) takes a first look at Kubearmor and how it works for securing your Kubernetes application.
Don't miss out! Join us at our next Flagship Conference: KubeCon + CloudNativeCon North America in Salt Lake City from November 12 - 15, 2024. Connect with our current graduated, incubating, and sandbox projects as the community gathers to further the education and advancement of cloud native computing. Learn more at kubecon.io
0:00 - Introduction
1:12 - Live Learning and Interactive Format
3:08 - CNCF Code of Conduct and Updates
5:23 - What is Kubernetes DRA?
10:41 - Nvidia GPU Operator
16:12 - Demonstrating DRA Setup
31:13 - Extensive DRA Functionality Testing
49:00 - Conclusion and Look Ahead
Lightning Talk: Gain Platform Superpowers with the KEBAP Stack! - Engin Diri, Pulumi
Kelsey Hightower once wrote that Kubernetes is a platform for building platforms, and I couldn't agree more. Since then, there has been significant evolution in this domain. A key insight is that Kubernetes is still too complex for just anyone within an organization. Its low level of abstraction leads to a high cognitive load for users. Welcome to the KEBAP stack, a composable Internal Developer Platforms (IDP) comprised of four open-source tools that form the layers of this IDP: (K)ubernetes, (E)xternal Secrets Operator, (B)ackstage, (A)rgo CD, and (P)ulumi. The KEBAP stack adheres to GitOps principles, a cornerstone of a robust, secure, and scalable IDP. Each layer of the KEBAP stack unlocks unique capabilities within your IDP by meeting the requirements of GitOps implementation, offering the flexibility to add more tools as you advance on your IDP journey. This session will not only provide a high-level overview of the KEBAP stack but will also demo the KEBAP stack.
GitOps: Keeping It Light, Bright, and Deployed Right with OpenShift! - Meha Bhalodiya & Dheeraj Singh Jodha, Red Hat
Based on parameters, how can one allow the dynamic generation of application instances? How can teams efficiently manage configurations across multiple environments, reducing manual efforts and ensuring consistency in large-scale deployments? To address these situations, we have OpenShift GitOps. Yes, you heard it right! We have a one-stop solution for such issues, including automation within the software development lifecycle, managing application configurations as code, etc. Join us on an interactive journey as we unravel the intricacies of OpenShift GitOps and the game-changing Operator Framework. Discover how this approach fosters collaboration between development and operations teams, automates deployments, and ensures security through the entire application lifecycle. Whether you're a developer, operator, or DevOps enthusiast, this session promises actionable insights, real-world use cases, and a closer look at how OpenShift GitOps accelerates agility in your continuous delivery pipelines. Don't miss this opportunity to unlock the full potential of GitOps with OpenShift!
Progressive Delivery for Micro-Services Using Argo Rollouts and the Downward API - Kostis Kapelonis, Codefresh
Progressive Delivery is an advanced deployment method that allows for zero-downtime application releases. Argo Rollouts is a Kubernetes controller that allows you to adopt progressive delivery in the form of blue/green and canary deployments. By default the Argo Rollouts controller has a very limited scope and only works with a single Kubernetes service. Teams that have adopted microservices have no guidance on how to use Argo Rollouts in a distributed environment where a single “application” might contain services and other external systems such as queues, caches and databases. These microservices might have dependencies between them or they could be deployed in an independent manner, and the question is how to apply progressive delivery for the whole application. In this talk we will see how to use Argo Rollouts in a distributed application that not only has multiple microservices but also needs external resources such as queues and databases which we also need to take into account when using blue/green and canary releases.
Don't GitOps Into a Blackhole - Rakshit Gondwal, Keptn
Tired of adding different tests, security, and SLO checks to deployments, or are you tired of connecting your GitOps tooling to various observability platforms? Join us in our talk as I'll briefly explain how you can use Keptn to simplify your GitOps principles. Learn how Keptn enables you to have pre and post-checks and evaluations for your deployments, reducing the need to implement various tests and SLO checks. Learn how you can connect your observability tools to your GitOps tooling in a more unified way. Don’t miss out as I'll be sharing my experience while contributing to Keptn and also demoing the tool itself.
Kubernetes as a Platform Framework: Journey from IaC Pipelines to K8s APIs - Christina Andonov, AWS
As organizations scale their cloud adoption, they continue to find bottlenecks in their ability to deploy new workloads due to the shear number of resources centralized teams must manage. Developers at these organizations must traverse through multiple workflows—stitching together outputs from multiple pipelines—to deploy their applications. These delays result in new workloads or features taking up to 6-12 months to launch into production. Attempting to remove the bottleneck of centralized teams and empower developers, technical leadership is driving self-service automation initiatives commonly referred to as platform engineering. This presentation covers why platform engineering is trending, why new tools and methodologies are required, real-world customer use-cases, and how to get started. Additionally we’ll demo how to build a modern platform using OSS CNCF tools like Argo, Crossplane, and Gatekeeper.
May the GitOps Be with You: Conquering Network ACL Challenges - Tushar Gupta, Google
Network ACLs are essential for protecting networks of all sizes. They play a pivotal role in protecting data from external threats. Despite their importance, configuring Network ACLs accurately is far from straightforward. Traditional approaches to managing Network ACLs often result in bottlenecks, configuration errors, and limited visibility, challenging network security teams with complexity that can hinder operational efficiency and create security vulnerabilities. Implementing manual changes across firewalls, routers, and load balancers is prone to misconfigurations and inconsistencies that can inadvertently expose services, leaving networks vulnerable. GitOps offers a promising solution by integrating Network ACL management into a CI/CD pipeline, which can then provide automated testing and validation, leading to greater accuracy and security. This talk will explore how GitOps principles drive the automation of ACL deployments. This automation minimizes manual intervention, enforces policy as code, and provides an auditable change tracking system. These benefits streamline network security practices and address the shortcomings of traditional ACL management.
How Integrating ArgoCD with Crossplane Compositions Enabled a Unified GitOps Workflow - Vaibhav Chopra, Expedia Group
we established a cohesive GitOps workflow, complementing ArgoCD GitOps declarative deployment functionality with crossplane paradigm to enable Kubernetes style api to provision cloud resources, With compositions we did manage creation of multiple managed resources as a single object now changes to both application and infrastructure are defined, versioned and automated together and this also unlocks a single pane of ArgoCD UI for users, providing visibility of application sets as well as the Infrastructure , ArgoCD becomes agnostic for manifest changes reflection whether its application or S3 storages or Load balancers
Empower Developers with GitOps-Driven Kubernetes Cluster Provisioning - Praseeda Sathaye, Amazon
This session demonstrates an innovative GitOps approach to streamline Kubernetes cluster provisioning and configuration. Through live demo, we will showcase how open-source tools like Argo CD, Argo Events, Argo Workflows, and Crossplane can be integrated to build an automated, event-driven workflow. Once a cluster is provisioned, it is automatically registered with the central GitOps platform, freeing developers from manual configuration and allowing them to seamlessly deploy applications. The demo will highlight key benefits including: 1. Automated cluster provisioning powered by GitOps 2. Seamless registration of new clusters with the central platform 3. Event-driven workflow using Argo Events and Argo Workflows 4. Effortless application deployment for developers 5. Increased efficiency and consistency through infrastructure-as-code Sample code will be available in a public Github repo for attendees to replicate the solutions in their own environments. Join us to see these leading-edge technologies in action and elevate your Kubernetes cluster management.
Scaling Kubernetes Fleet Management Using GitOps Bridge - Blake Romano, Imagine Learning & Carlos Santana, AWS
When building Internal Developer Platforms you typically use an Infrastructure as Code tool like Terraform or Pulumi to deploy the core infrastructure and you use a GitOps Controller to deploy Kubernetes manifests that can deploy core components of your Kubernetes cluster like your CNI and Service Mesh. Establishing a way to connect your IaC and your GitOps Configuration has been a challenge. The GitOps Bridge is a pattern that bridges the gap between IaC and GitOps Manifests. Adopting this pattern allows you to manage a fleet of Kubernetes Clusters while being able to dynamically pass in outputs from your Infrastructure as Code. Hear how adopting this pattern allows you to speed up GitOps adoption at scale in your organization.
GitOps Pipelines: Everything Everywhere All at Once - Christian Hernandez, Akuity
When we talk about CI/CD, we often think of it as an end to end, linear, process. However, with modern cloud native computing, this ceases to be the case. The reality is your pipelines are hyperdimensional with many branches that can also branch out. This becomes a challenge when dealing with GitOps. In the pursuit of ever-faster and more-frictionless application delivery, GitOps excels at continuous delivery to single environments. Yet leading, open-source GitOps platforms offer little to accommodate modern deployment pipelines that span many stages, regions, and clouds, and may involve lengthy verification processes. These missing features often force GitOps practitioners to inappropriately fall back on CI platforms and bespoke automation, resulting in complex and fragile deployment pipelines. This talk will zero in on an alternative: patterns that address these challenges while remaining true to established GitOps principles – and an emerging open-source implementation of those patterns. Kargo promises to address these challenges in a declarative fashion while complementing GitOps practitioners’ current crop of favorite tools, such as Kustomize, Helm, Argo CD, and Flux.
Accelerating GitOps Adoption with Flux - Ed Boykin, CoreCard, Inc.
The Innovation group at CoreCard is tasked with rewriting 20-year-old legacy software as cloud native microservices running on Kubernetes. Multiple development teams need to work at high velocity and deploy to multiple environments each day. They decided to implement GitOps processes to increase developer productivity, and platform security, consistency, and observability. Flux was a major component to aid in the successful adoption of GitOps in just 2 months. The session will introduce the background and reasons leading to implementing GitOps to solve several challenges. A top challenge being how do we improve environment consistency and change accountability without affecting team velocity. It will cover how and why Flux contributed to the solutions, for instance Flux’s support for Helm charts and kustomizations allowed existing charts and manifests to be reused. Finally, they will show measurable improvements, plus the future roadmap to continuously improve the processes.
Closing Remarks - Christian Hernandez, Akuity
Ease the Pain of Platform Engineers with Argo CD by Leveraging Kustomize Templates - Pratik Singh, NASDAQ
Onboarding teams to deploy applications requires a LOT of YAML. To speed up this process, and cut down on writing new YAML, we can provide some simple and easy-to-use Kustomize templates. These when combined with Argo CD create a seamless, self-service experience. Standardizing your deployments with Kustomize and Argo CD across teams, brings predictability, easier maintenance, and faster time to resolution in change management. In this talk, we’ll share strategies for making application provisioning more self-service by leveraging the best of Argo CD and using ready-made Kustomize templates. Instead of annoying maintainers for change requests, users can self-serve testing and customisation in their own sandboxes. The key is clever usage of App Project RBAC, and marrying that into the Kustomize structure in git to provide a simple Developer Platform experience. The result is expert teams have an easy way to operate, and new teams have an standard way to start with Kubernetes.
GitOps, the Final Frontier: Proposing, Promoting, and Reverting - Michael Crenshaw, Intuit & Omer Azmon, Intuit Inc
Intuit has been at the forefront of GitOps. GitOps tooling has perfected the art of continuous reconciliation: you push your change to git, the change goes to Kubernetes. But our experience at Intuit has shown us that the user’s experience of continuous deployment involves three other critical activities: proposing a change, promoting that change, and rolling back problematic changes. GitOps so far has been relatively un-opinionated about those parts of the experience. In this talk, we will propose an opinionated GitOps workflow encompassing all parts of the process and how automatic management of both change previews and Pull Requests is a critical part of that workflow. We will outline the necessary tooling to make that process as seamless as continuous reconciliation is today. We will take the audience through the entire user experience, and we will preview how new tooling can make the process delightful. And we will discuss how this new workflow would solve problems Intuit has encountered in our GitOps experience. By the end of the talk, the audience will have a new vision of what the future of GitOps should be and some concrete steps to start making that vision a reality.
Sinking Atlantis – How Breaking up Our Infrastructure Monorepos Saved Us from Pull Request Purgatory - Donnie Laughton, Recursion
Several years ago, the Recursion Engineering Infrastructure team naively adopted GitOps practices by connecting our GitOps tools (including atlantis and argocd) to broadly scoped infrastructure-as-code (IaC) monorepos. This allowed us to maintain positive control over changes to our infrastructure and allowed our software engineers to focus on application development. As we scaled, having our engineering infrastructure team in the release path started to decrease release velocity and 'pulled' us into PR purgatory. Over this past year, we reimagined our infrastructure provisioning patterns and refactored our IaC codebase with a focus on breaking out application-specific IaC into dedicated 'bounded context repos'. The result has empowered our software engineering teams with self-service resource provisioning while simultaneously making our infrastructure easier to reason over and maintain. In this talk, we will go over two different GitOps repo patterns for IaC, the pros and cons of each, how we made the pivot from one to the other and why we did it when we did.
Lightning Talk: DORA metrics in a GitOps World: Conflict or Conflux? - Ram Iyengar
DORA metrics are designed to function as a north star for a software delivery process. GitOps enables an automated and declarative means towards software delivery. This lightning talk is intended to explore the result of bringing these two paradigms together and examining what emerges from the admixture. It is well known that metrics provide objective data to gauge speed (deployments), efficiency (lead time), quality (failure rate), and resilience (recovery time). In a world without these measurements - teams navigate blindly, risking slow releases, buggy software, and costly downtime. For a world that intends to adopt GitOps, would the DORA framework be an appropriate fit? Do the two realms have a natural fit? Will DORA fall short of meeting the needs of the GitOps methodology? Come to the talk to find out!
Empowering the GitOps Future with AI - Guangya Liu, IBM
The GitOps paradigm has revolutionized how we manage deployments in cloud-native systems. With the rise of generative AI and its widespread discussion in recent times, the question arises: What happens when we combine GitOps and AI? What benefits can GitOps derive from AI? In this talk, the speaker will dive into the exciting intersection of GitOps and AI, specifically the emerging field of generative AI and large language model, explore the potential of leveraging AI to empower GitOps workflow. By harnessing AI capabilities, envision a future where GitOps embraces intelligent automation, to eliminate manual intervention, streamline deployment process, and enhance collaboration via natural language interface. During the talk, there will be a showcase on how fine-tuned AI models can be applied to popular GitOps tool such as Argo CD or Flux CD, allowing people to express the desired changes to Kubernetes resource in human-readable format, to enhance the Kubernetes resource management.
Welcome + Opening Remarks + OpenGitOps Project Updates - Stacey Potter & Christian Hernandez
Continuous Delivery: The Missing Piece in the GitOps-OCI Security Puzzle - Sushrut Athavale, Harness
In the ever-evolving landscape of containerized environments, the intersection of GitOps and OCI presents a formidable challenge in maintaining the integrity and trustworthiness of container images. While OCI promises secure, trusted delivery through image signing, the GitOps paradigm introduces a paradox – how to sign code when everything is stored as code? Join us in this breakout session as we delve into the heart of this dilemma, exploring the complications of GitOps with OCI. We'll unravel the complexities of maintaining trust in containerized deployments and introduce a game-changing solution: Continuous Delivery.
Extending Argo CD with Health Checks and Resource Actions - Gerald Nunn, Red Hat
Custom Resource Definitions (CRDs) are becoming more and more popular in Kubernetes particularly with the increased use of operators. Managing Custom Resources (CRs) derived from CRDs effectively in Argo CD is essential to get the most of these resources. In this demo heavy session we will cover the following while building out a concrete example: 1. What are custom health checks and resource actions 2. The importance of creating these for Argo CD for the best operational experience 3. A quick primer on creating them using LUA 4. How to efficiently write and debug these locally 5. Best practices when writing your own. 6. Participate in the upstream Argo CD community by contributing new or updated health checks and resource actions.
Understanding Exploitability with VEX, EPSS, and Other Standard Frameworks - Ayse Kaya, Root
As the complexity of software systems continues to grow, ensuring their security becomes paramount. This necessitates a comprehensive understanding of the reachability & exploitability of vulnerabilities within software applications. This call for papers aims to provide a high-level overview of four essential concepts in the field of software security: Vulnerability Exposure Factor (VEX), Exploit Probability and Severity Score (EPSS), Common Vulnerability Scoring System (CVSS), and Software Bill of Materials (SBOMs). This can be streamlined through a process of generating and managing Software Bill of Materials (SBOMs) for compliance purposes, as well as automating policy and GitOps practices for improved security postured.
Scaling a GitOps Platform at Adobe - Aaren J & Ko Uchiyama, Adobe
GitOps is a fantastic paradigm to manage your application lifecycle with, but its requirements, especially regarding continuous reconciliation of state, are complex at scale. At Adobe we went from 0 to 10,000 Kubernetes services, composed of dozens of resources each, being continuously reconciled across over 350 clusters in 28 different geos. The journey thus far wasn't without its challenges. The lessons learned provided a wealth of information that will help us tackle the unknowns ahead and we'd like to share them with you. We've gathered technical learnings - such as limitations and scaling requirements of our Kubernetes clusters and ArgoCD - and non-technical - such as effective disaster response and vendor engagement. In this talk I'll show the learnings we've found to be valuable for others who are on their own journey to build and scale a GitOps-driven platform, with some focus on the scaling of our ArgoCD and Argo Workflows based platform through dynamic routing of workloads. Attendees will leave with an understanding of how they might implement and scale a GitOps-driven platform at their organization, so that they can drive their platform to success.
What's New with Flux? - Priyanka Ravi, G-Research
In the fast-paced world of software development, achieving seamless and efficient continuous delivery is paramount. Flux, a leading open-source GitOps toolkit, has been a game-changer in empowering teams to automate and optimize their deployment pipelines. The recent 2.2 release elevates the Flux experience to new heights, and this talk will cover the basics as well as long-awaited new features. Specifically, Flux has helped teams get out of drudgery with enhanced automation. With v2.2 there is improved observability of Helm releases. Flux is also designed to be extensible, and this talk will cover improved integration with popular Kubernetes tools such as Helm and Kustomize. The new release is designed to streamline the entire deployment lifecycle, and this talk will include actual use cases and stories from Flux users who are on v.2.2. By the end of this talk, you'll be equipped with the knowledge and insights needed to harness the full potential of Flux's latest release, empowering your team to achieve faster, more reliable deployments in the era of modern software development.
How Kubernetes easily scales up and down, adapting to demand;
How to build more resilient, secure, and observable systems;
The promise of optimizing resource utilization and saving costs (if implemented correctly).
We hope you can join us!


