Session
GitOps Security Anti-Patterns: When Your Repo Becomes the Breach
GitOps is widely adopted for its simplicity, auditability, and automation but it is often treated as inherently secure. In reality, many GitOps setups introduce critical security blind spots where a compromised repository, CI pipeline, or token can directly lead to a production breach.
In this talk, we will explore the most common GitOps security anti-patterns seen in real Kubernetes environments. These include secrets stored in Git, over-privileged CI/CD tokens, untrusted pull requests modifying production manifests, missing admission controls, and weak RBAC and branch protection rules.
Using concrete examples and realistic attack scenarios, I will show how these issues can be exploited in practice and how teams can fix them using policy as code, image and commit signing, admission controllers, and least-privilege access. Attendees will leave with a clear checklist to harden their GitOps workflows without sacrificing developer velocity.
Mohamed Ali Mellah
Cloud-Native & Kubernetes Engineer
Munich, Germany
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top