Session
Gitless GitOps with FluxCD
The GitOps model gave us traceable, declarative infrastructure. But relying on Git access from your clusters comes with downsides, network complexity, access control challenges, and audit gaps. This talk presents an evolved approach: keep Git as your truth, but push OCI-packaged artifacts to a registry where FluxCD can pull and reconcile securely.
You’ll learn how to: - Build and package Kubernetes manifests into OCI images with tooling like flux push or oras - Use image tags (e.g., latest, staging, stable) to decouple promotion from Git branching - Sign artifacts using keyless signatures via Sigstore (cosign) to enforce trust and verify integrity - Store and distribute SBOMs and VEX alongside manifests for audit-ready compliance - Onboard teams or tenants with minimal friction, no need to give them Git access to the cluster.
Michael Fornaro
Staff DevOps Engineer | Easygo
Melbourne, Australia
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top