Speaker

Steffen Kelch

Steffen Kelch

Principal Software Architect & Cloud Evangelist

Principal Software Architect & Cloud Evangelist

Ottobrunn bei München, Germany

Actions

From early roots in web development and SAP consulting, my journey evolved through enterprise architecture to cloud-native solutions.
In my current role at Cloud Native Lifecycle Management @ SAP, I combine my expertise with cloud technologies to drive innovation and enterprise grade automation of infrastructure-as-data on a global scale.

Area of Expertise

  • Information & Communications Technology
  • Manufacturing & Industrial Materials
  • Transports & Logistics

Topics

  • Cloud Native
  • Cloud & DevOps
  • Cloud Architecture
  • Cloud Automation
  • Cloud Evangelist
  • Infrastructure as Code
  • Infrastructure as Data
  • Kubernetes
  • enterprise open source
  • open source

OpenMCP – Enhancing the Development of a Kubernetes-Based Developer Platform

OpenMCP provides Crossplane to turn Kubernetes into a full control plane, enabling declarative infrastructure and service management through native Kubernetes APIs. This talk shows how OpenMCP simplifies the development and operation of developer platforms - without complex tools like Terraform or CloudFormation.
Using real-world examples, we demonstrate how infrastructure can be deployed across cloud and on-premises environments in a consistent, scalable, and developer-friendly way.
We show how OpenMCP enables developer self-service, ensures governance and compliance through policy-driven management (e.g. Kyverno), and promotes a clear separation between platform and application teams.
It's ideal for DevOps teams, platform engineers, and Kubernetes enthusiasts looking to build efficient, secure, and scalable platforms with Crossplane.

OCM: Rethinking Software Delivery with a Secure and Standardized Approach

The Open Component Model (OCM) introduces a technology-agnostic standard for secure software delivery, functioning as a Software Bill of Delivery (SBOD) that ensures integrity and provenance across the supply chain. OCM's unique identifier system enables seamless delivery across public cloud, on-premises, and air-gapped environments, while integrating with GitOps tools like Flux for automated, secure deployments.

Conquering openDesk.eu with kro.run & ocm.software for European Digital Sovereignty

openDesk.eu is the German government's sovereign digital workplace - 35+ open-source applications including Nextcloud, Element, OpenProject, Jitsi, and Collabora, all running on Kubernetes. The upstream project ships as Helmfiles.

In this talk I'll show how we rearchitected the openDesk deployment stack using two emerging CNCF-adjacent tools - Open Component Model (OCM.software) and Kubernetes Resource Orchestrator (KRO.run) - to solve three hard problems:

- Provenance & SBOM: How do you know every artifact you deploy is exactly what was built and hasn't been tampered with? OCM gives you component versioning, signing, and a full Software Bill of Materials out of the box.
- Dependency orchestration: How do you deploy 35 interdependent Helm releases in the right order, with readiness checks, without writing a custom operator? KRO's ResourceGraphDefinition turns implicit Helmfile ordering into an explicit, observable, self-healing dependency graph.
- Air-gap readiness: How do you make the entire stack relocatable to a sovereign cloud or disconnected environment? OCM's OCI transport layer lets you mirror the full component tree to any internal registry with one command.

The result: a single kubectl apply of one custom resource - kind: OpenDeskInstance - bootstraps the entire digital workplace. No CLI binaries embedded in your CD pipeline. No manual sync waves. Full drift detection via FluxCD.

I'll walk through the architecture, the real pain of migrating Helmfiles to FluxCD HelmReleases, and close with a demo showing an Kubernetes cluster becoming a running sovereign digital workplace.

All code is open-source and running today: github.com/platform-mesh/samples-opendesk-ocm-k8s-toolkit

- 45-minute slot preferred; content can be trimmed to 30 min by shortening the demo segment
- (Recorded) demo, no live cluster dependency - suitable for any conference setup
- Targets platform engineers and DevOps practitioners; assumes Kubernetes familiarity
- Speaker has deep end-to-end experience with the PoC including, fluxcd, kro.run, ocm.software and the helmfile migration pain
- Showcasing blueprint for advancing with European Digital Sovereignty

NeoNephos IPCEI-CIS WS2 Multi-Cluster Kubernetes

Delivering and deploying OpenDesk with Open Component Model to AirGap (40 min): How do you package, transport, and deploy a complete digital workplace platform across disconnected or air-gapped Kubernetes environments in the cloud-edge continuum? In this talk, we demonstrate a component-based approach using Open Component Model (OCM) and OCM aware Kubernetes Deployer to deliver OpenDesk - a comprehensive sovereign workplace platform. Our solution addresses the full lifecycle: OCM enables technology-agnostic packaging of Helm charts, container images, configurations and many more into self-contained components stored in OCI registries. We showcase automated CI/CD workflows that package OCM components, transfer them to OCI registry ready for air-gapped environments, and deploy across Kubernetes clusters using OCM aware Kubernetes Deployer. This approach solves critical challenges in sovereign cloud scenarios where internet connectivity is restricted or regulated.

NeoNephos Meeting Series - The next IPCEI-CIS Workstream 2 Multi Cluster Kubernetes (MCK) meeting session will be held on the 20th of January from 10:00-11:30 am CET.

January 2026

NeoNephos November Community Call

Introduction to Open Managed Control Plane project!

OpenMCP provides Crossplane to turn Kubernetes into a full control plane, enabling declarative infrastructure and service management through native Kubernetes APIs. This talk shows how OpenMCP simplifies the development and operation of developer platforms - without complex tools like Terraform or CloudFormation.
Using real-world examples, we demonstrate how infrastructure can be deployed across cloud and on-premises environments in a consistent, scalable, and developer-friendly way.
We show how OpenMCP enables developer self-service, ensures governance and compliance through policy-driven management (e.g. Kyverno), and promotes a clear separation between platform and application teams.
It's ideal for DevOps teams, platform engineers, and Kubernetes enthusiasts looking to build efficient, secure, and scalable platforms with Crossplane

November 2025

ContainerDays Conference 2025 Sessionize Event

September 2025 Hamburg, Germany

Cloud Native Summit 2025 Sessionize Event

July 2025 Munich, Germany

IPCEI-CIS WS2 Multi-Cluster Kubernetes - ApeiroRA - Shift Left Innovation for Software Supply Chains

Shift Left Innovation for Software Supply Chains:
As a product team, how do you package and transport arbitrary types of software for the multi-provider-cloud-edge continuum? As a DevOps team tasked with productizing that software product into a service, how do you deploy a given product in your part of the continuum and keep it up to date? In Apeiro, we have developed highly innovative and foundational lifecycle management tools and concepts that fully cover holistic packaging & transport, and security & compliance concerns, as well as GitOps guided automation. In this talk, we will demonstrate our standardized approach, and our shift left of deployment automation.

July 2025

Steffen Kelch

Principal Software Architect & Cloud Evangelist

Ottobrunn bei München, Germany

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top