SlideShare a Scribd company logo
Confidential do not distribute
Successfully Shift Left Security in
Application Delivery with Weave
GitOps Enterprise and Upbound’s
Universal Crossplane
In partnership with:
2
Webinar Platform - FAQs
Using Zoom
• You are in listen only mode
• This webinar is being recorded
• Q&A session will follow the presentation, please use the Q&A panel to
submit questions
• Hit escape to exit full screen
• Slides and recording will be shared after the webinar
Technical Issues - please visit Zoom Help
https://support.zoom.us/hc/en-us/articles/206175806-Top-Questions
3
Dan Mangum
Principal Software Engineer,
Upbound
Dan Mangum is a Principal Software Engineer
at Upbound and a maintainer of the
Crossplane project. In addition to his work in
the Crossplane community, Dan has held
technical leadership roles in the upstream
Kubernetes community.
Paul Curtis
Principal Solutions
Architect, Weaveworks
Paul started as a developer working in
financial institutions. Paul proceeded to take
on technical account management at
Netscape & Sun, along with system and dev
operations at start ups. Paul now provides
field enablement and engineering in the big
data world.
Speaker introductions
Confidential do not distribute 4
The problem:
● Service and resource provisioning slows development
● Resources are spread between different environments (Kubernetes, VMs, Provider Services)
● Managing current state, recovery, and rollbacks is difficult
The solution:
● Declarative and auditable provisioning across all resources
● Application and resource lifecycle management with GitOps
● Policy enforcement across all resources
Shifting Security Left in Application Delivery
Confidential do not distribute 5
Weave GitOps Enterprise with Upbound demo
Weave GitOps Enterprise
● Policy guardrails for every declarative action
● Declarative deployment of applications and deployment pipelines across multiple clusters
● Declarative provisioning of Kubernetes clusters and bootstrapping services
Upbound
● All the benefits of GitOps across any resource
● Declarative, audited, and observable
● Lifecycle management of resources external to Kubernetes
Confidential do not distribute
Weaveworks is backed by solid investors
Weaveworks is a key partner with all the
major infrastructure and Kubernetes vendors
Weaveworks: the GitOps company
Weaveworks is deeply committed
to the Open Source Community
Confidential do not distribute 7
Test
IDE
Build
GitOps – An Operating Model for Cloud Native
Unifying Deployment,
Monitoring and Management.
Git as the single source of truth
of a system’s desired state
ALL intended operations are
committed by pull request
ALL diffs between intended and
observed state with automatic
convergence
ALL changes are observable,
verifiable and auditable
Kubernetes
GitOps
Continuous
Integration
GIT
“Immutability
Firewall”
Deployment
(clusters, apps)
Monitoring
Logging
(Observability)
Management
(operations)
Confidential do not distribute 8
Continuous Application Delivery -
use GitOps to deploy and operate
applications. Automation increases
deployment velocity and developer
productivity.
Weave GitOps - Use Cases
Kubernetes Everywhere - in the
cloud or the datacenter Kubernetes
is a universal platform that’s easy
to manage with GitOps.
DevOps Automation - Lifecycle
management of the entire platform.
All clusters and services, using
automation and policy.
1
4
2
5
3
6
Self-Service Platforms - a complete
platform giving developers
autonomy while ensuring
consistency and manageability.
Trusted Delivery - shift policy and
security left - governance, risk, and
compliance are non-negotiable.
Progressive Delivery - deploy
services across many environments
and regions reliably using GitOps
9
● Built on OPA standard - Rego
● Curated library of 100+ policies
● SOC II, PCI-DSS, GDPR, HIPAA, MITRE ATTACK
● Security, resilience and coding standards
● Validation throughout SDLC
○ Commit, Pull Request
○ Build
○ Deploy
○ Runtime
● Automatic remediation via pull request
Weave GitOps PaC
Shift Deployment Security Left with Weave GitOps & Upbound’s Universal Crossplane
Control Plane Revolution
11
🔥 3,000+ Companies in Production
🔥 7,000+ Slack channel members
🔥 6,000+ GitHub stars
🔥 40M+ Pulls on Docker Hub
🔥 Open Source and CNCF project
Scripting
• Legacy
• Imperative Configuration
Infrastructure As Code
(Terraform, Ansible, Chef)
• Declarative Configuration
• Configuration Management
• Provisioning Management
• Sprawling Complexity
Control Planes
The Crossplane Revolution
• Compliment IaC
• Declarative API
• Self-Service
• Full Automation
2020s
1990s
Who is
● Founders of
● Growing 700% YoY
● Commercial, Open-Core Company
○ Ease-of-Use: UX, Marketplace
○ Enterprise-Grade: Scalable, Secure, Controlled
○ Solution-Agnostic: Any cloud, Any
environment, Any service
● Complement, rather than compete
Who is
Why Now
Enterprises are Re-Platforming - Again!
Security Cost Multiple
Vendors
Developer
Productivity
Standardization
Enforcing best-practices and
controls consistently across
the entire organization
Future Proofing
Standardizing on Kubernetes
API
Abstractions
Interfaces Control
Plane
Infrastructure
Standardizing on Kubernetes + Crossplane
API
Abstractions
Interfaces Control
Plane
A
B
Infrastructure
Standardizing on Crossplane
Interfaces API
Abstractions
Control
Plane
A
B
C
D
Infrastructure
Standardizing Existing Processes
Interfaces API
Abstractions
Infrastructure
Control
Plane
A
B
C
D
IaC Vendors
An Extension of Kubernetes
Uniform Declarative Metadata
Asynchronous Controllers
Authorization Policy
Admission Control
Audit Logging
Composition - Low Code Controllers
External Naming and Identity
Cross Resource References
Connection Secrets
Package Manager
KRM XRM
19
Confidential do not distribute
Demo Architecture
1. Configure management cluster with UXP
and the Crossplane package for
Discourse on AWS
2. Create a pull request to a repository
added as a Weaveworks GitOps source
3. Observe policy violation
4. Fix policy violation
5. Weaveworks GitOps syncs manifest to
cluster
6. UXP provisions infrastructure and
application, providing the necessary
connection data
21
Confidential do not distribute
Questions?
(Please use the Q&A panel in your Zoom menu)
22
Whitepaper: Shifting Security Left with
GitOps and Trusted Delivery
https://bit.ly/3MvzXgQ
Learn more about Weave GitOps
www.weave.works/enterprise
Request a personal demo
www.weave.works/contact
Thank You
Next Steps
Sign Up
Create a Free Account
Learn More About UXP
Universal Crossplane
Visit the Marketplace
https://marketplace.upbound.io

More Related Content

What's hot (20)

PDF
GitOps: Git come unica fonte di verità per applicazioni e infrastruttura
sparkfabrik
 
PDF
GitOps is the best modern practice for CD with Kubernetes
Volodymyr Shynkar
 
PPTX
GitOps - Modern best practices for high velocity app dev using cloud native t...
Weaveworks
 
PDF
OpenShift 4, the smarter Kubernetes platform
Kangaroot
 
PDF
Open shift 4-update
SaeidVarmazyar
 
PPTX
DevOps Tutorial For Beginners | DevOps Tutorial | DevOps Tools | DevOps Train...
Simplilearn
 
PDF
GitHub Actions in action
Oleksii Holub
 
PPTX
Continues Integration and Continuous Delivery with Azure DevOps - Deploy Anyt...
Janusz Nowak
 
PDF
Kubernetes 101
Crevise Technologies
 
PDF
Getting Started with Kubernetes
VMware Tanzu
 
PDF
Gitops: the kubernetes way
sparkfabrik
 
PDF
Open shift 4 infra deep dive
Winton Winton
 
PDF
Exploring the power of OpenTelemetry on Kubernetes
Red Hat Developers
 
PDF
Free GitOps Workshop + Intro to Kubernetes & GitOps
Weaveworks
 
PDF
Slide DevSecOps Microservices
Hendri Karisma
 
PDF
Kubernetes Docker Container Implementation Ppt PowerPoint Presentation Slide ...
SlideTeam
 
PDF
DevOps - A Gentle Introduction
CodeOps Technologies LLP
 
PDF
[오픈소스컨설팅]쿠버네티스를 활용한 개발환경 구축
Ji-Woong Choi
 
PDF
Kubernetes Deployment Strategies
Abdennour TM
 
PPTX
Introduction to devops
UtpalenduChakrobortt1
 
GitOps: Git come unica fonte di verità per applicazioni e infrastruttura
sparkfabrik
 
GitOps is the best modern practice for CD with Kubernetes
Volodymyr Shynkar
 
GitOps - Modern best practices for high velocity app dev using cloud native t...
Weaveworks
 
OpenShift 4, the smarter Kubernetes platform
Kangaroot
 
Open shift 4-update
SaeidVarmazyar
 
DevOps Tutorial For Beginners | DevOps Tutorial | DevOps Tools | DevOps Train...
Simplilearn
 
GitHub Actions in action
Oleksii Holub
 
Continues Integration and Continuous Delivery with Azure DevOps - Deploy Anyt...
Janusz Nowak
 
Kubernetes 101
Crevise Technologies
 
Getting Started with Kubernetes
VMware Tanzu
 
Gitops: the kubernetes way
sparkfabrik
 
Open shift 4 infra deep dive
Winton Winton
 
Exploring the power of OpenTelemetry on Kubernetes
Red Hat Developers
 
Free GitOps Workshop + Intro to Kubernetes & GitOps
Weaveworks
 
Slide DevSecOps Microservices
Hendri Karisma
 
Kubernetes Docker Container Implementation Ppt PowerPoint Presentation Slide ...
SlideTeam
 
DevOps - A Gentle Introduction
CodeOps Technologies LLP
 
[오픈소스컨설팅]쿠버네티스를 활용한 개발환경 구축
Ji-Woong Choi
 
Kubernetes Deployment Strategies
Abdennour TM
 
Introduction to devops
UtpalenduChakrobortt1
 

Similar to Shift Deployment Security Left with Weave GitOps & Upbound’s Universal Crossplane (20)

PDF
Automated Provisioning, Management & Cost Control for Kubernetes Clusters
Weaveworks
 
PDF
Intro to GitOps with Weave GitOps, Flagger and Linkerd
Weaveworks
 
PDF
Deploying Stateful Applications Securely & Confidently with Ondat & Weave GitOps
Weaveworks
 
PDF
DX, Guardrails, Golden Paths & Policy in Kubernetes
Weaveworks
 
PDF
Weave GitOps - continuous delivery for any Kubernetes
Weaveworks
 
PDF
Cloud Native Engineering with SRE and GitOps
Weaveworks
 
PDF
Securing Your App Deployments with Tunnels, OIDC, RBAC, and Progressive Deliv...
Weaveworks
 
PDF
Accelerating Hybrid Multistage Delivery with Weave GitOps on EKS
Weaveworks
 
PDF
Hybrid and Multi-Cloud Strategies for Kubernetes with GitOps
Sonja Schweigert
 
PDF
Hybrid and Multi-Cloud Strategies for Kubernetes with GitOps
Weaveworks
 
PDF
Webinar: Capabilities, Confidence and Community – What Flux GA Means for You
Weaveworks
 
PDF
Weave GitOps 2022.09 Release: A Fast & Reliable Path to Production with Progr...
Weaveworks
 
PPTX
Expedite Enterprise Software Development with JIRA®, TeamForge® SCM, and Jenkins
CollabNet
 
PDF
Observe and command your fleets across any kubernetes with weave git ops
Weaveworks
 
PPTX
Moving from Legacy Development Tools to transformative DevOps with Enterprise...
Infostretch
 
PDF
Continuous Lifecycle London 2018 Event Keynote
Weaveworks
 
PDF
Enterprise CI as-a-Service using Jenkins
CollabNet
 
PPTX
Cloud Native Transformation (Alexis Richardson) - Continuous Lifecycle 2018 ...
Weaveworks
 
PDF
Free GitOps Workshop
Weaveworks
 
PDF
GitOps, Driving NGN Operations Teams 211127 #kcdgt 2021
William Caban
 
Automated Provisioning, Management & Cost Control for Kubernetes Clusters
Weaveworks
 
Intro to GitOps with Weave GitOps, Flagger and Linkerd
Weaveworks
 
Deploying Stateful Applications Securely & Confidently with Ondat & Weave GitOps
Weaveworks
 
DX, Guardrails, Golden Paths & Policy in Kubernetes
Weaveworks
 
Weave GitOps - continuous delivery for any Kubernetes
Weaveworks
 
Cloud Native Engineering with SRE and GitOps
Weaveworks
 
Securing Your App Deployments with Tunnels, OIDC, RBAC, and Progressive Deliv...
Weaveworks
 
Accelerating Hybrid Multistage Delivery with Weave GitOps on EKS
Weaveworks
 
Hybrid and Multi-Cloud Strategies for Kubernetes with GitOps
Sonja Schweigert
 
Hybrid and Multi-Cloud Strategies for Kubernetes with GitOps
Weaveworks
 
Webinar: Capabilities, Confidence and Community – What Flux GA Means for You
Weaveworks
 
Weave GitOps 2022.09 Release: A Fast & Reliable Path to Production with Progr...
Weaveworks
 
Expedite Enterprise Software Development with JIRA®, TeamForge® SCM, and Jenkins
CollabNet
 
Observe and command your fleets across any kubernetes with weave git ops
Weaveworks
 
Moving from Legacy Development Tools to transformative DevOps with Enterprise...
Infostretch
 
Continuous Lifecycle London 2018 Event Keynote
Weaveworks
 
Enterprise CI as-a-Service using Jenkins
CollabNet
 
Cloud Native Transformation (Alexis Richardson) - Continuous Lifecycle 2018 ...
Weaveworks
 
Free GitOps Workshop
Weaveworks
 
GitOps, Driving NGN Operations Teams 211127 #kcdgt 2021
William Caban
 
Ad

More from Weaveworks (20)

PDF
Weave AI Controllers (Weave GitOps Office Hours)
Weaveworks
 
PDF
Flamingo: Expand ArgoCD with Flux (Office Hours)
Weaveworks
 
PDF
Six Signs You Need Platform Engineering
Weaveworks
 
PDF
SRE and GitOps for Building Robust Kubernetes Platforms.pdf
Weaveworks
 
PDF
Webinar: End to End Security & Operations with Chainguard and Weave GitOps
Weaveworks
 
PDF
Flux Beyond Git Harnessing the Power of OCI
Weaveworks
 
PDF
How to Avoid Kubernetes Multi-tenancy Catastrophes
Weaveworks
 
PDF
Building internal developer platform with EKS and GitOps
Weaveworks
 
PDF
GitOps Testing in Kubernetes with Flux and Testkube.pdf
Weaveworks
 
PDF
Implementing Flux for Scale with Soft Multi-tenancy
Weaveworks
 
PDF
The Story of Flux Reaching Graduation in the CNCF
Weaveworks
 
PDF
Flux’s Security & Scalability with OCI & Helm Slides.pdf
Weaveworks
 
PDF
Flux Security & Scalability using VS Code GitOps Extension
Weaveworks
 
PDF
Robust Network Security and Observability with GitOps and Cilium
Weaveworks
 
PDF
Intro to GitOps & Flux.pdf
Weaveworks
 
PDF
Simplifying Hybrid Kubernetes with Weaveworks and EKS.pdf
Weaveworks
 
PDF
Building a Security First Approach Across Hybrid Cloud with GitOps and Policy...
Weaveworks
 
PDF
Security & Resiliency of Cloud Native Apps with Weave GitOps & Tetrate Servic...
Weaveworks
 
PDF
DevOps Automation with GitOps: Consistent and Secure End to End Deployments
Weaveworks
 
PDF
Trusted Application Delivery: Achieving Ultimate Security
Weaveworks
 
Weave AI Controllers (Weave GitOps Office Hours)
Weaveworks
 
Flamingo: Expand ArgoCD with Flux (Office Hours)
Weaveworks
 
Six Signs You Need Platform Engineering
Weaveworks
 
SRE and GitOps for Building Robust Kubernetes Platforms.pdf
Weaveworks
 
Webinar: End to End Security & Operations with Chainguard and Weave GitOps
Weaveworks
 
Flux Beyond Git Harnessing the Power of OCI
Weaveworks
 
How to Avoid Kubernetes Multi-tenancy Catastrophes
Weaveworks
 
Building internal developer platform with EKS and GitOps
Weaveworks
 
GitOps Testing in Kubernetes with Flux and Testkube.pdf
Weaveworks
 
Implementing Flux for Scale with Soft Multi-tenancy
Weaveworks
 
The Story of Flux Reaching Graduation in the CNCF
Weaveworks
 
Flux’s Security & Scalability with OCI & Helm Slides.pdf
Weaveworks
 
Flux Security & Scalability using VS Code GitOps Extension
Weaveworks
 
Robust Network Security and Observability with GitOps and Cilium
Weaveworks
 
Intro to GitOps & Flux.pdf
Weaveworks
 
Simplifying Hybrid Kubernetes with Weaveworks and EKS.pdf
Weaveworks
 
Building a Security First Approach Across Hybrid Cloud with GitOps and Policy...
Weaveworks
 
Security & Resiliency of Cloud Native Apps with Weave GitOps & Tetrate Servic...
Weaveworks
 
DevOps Automation with GitOps: Consistent and Secure End to End Deployments
Weaveworks
 
Trusted Application Delivery: Achieving Ultimate Security
Weaveworks
 
Ad

Recently uploaded (20)

DOCX
Python coding for beginners !! Start now!#
Rajni Bhardwaj Grover
 
PPTX
Future Tech Innovations 2025 – A TechLists Insight
TechLists
 
PDF
CIFDAQ Market Wrap for the week of 4th July 2025
CIFDAQ
 
PPTX
Q2 FY26 Tableau User Group Leader Quarterly Call
lward7
 
PDF
LOOPS in C Programming Language - Technology
RishabhDwivedi43
 
PDF
NLJUG Speaker academy 2025 - first session
Bert Jan Schrijver
 
PDF
Agentic AI lifecycle for Enterprise Hyper-Automation
Debmalya Biswas
 
PPTX
Designing_the_Future_AI_Driven_Product_Experiences_Across_Devices.pptx
presentifyai
 
PDF
NASA A Researcher’s Guide to International Space Station : Physical Sciences ...
Dr. PANKAJ DHUSSA
 
PDF
How do you fast track Agentic automation use cases discovery?
DianaGray10
 
PDF
Kit-Works Team Study_20250627_한달만에만든사내서비스키링(양다윗).pdf
Wonjun Hwang
 
PDF
Newgen Beyond Frankenstein_Build vs Buy_Digital_version.pdf
darshakparmar
 
PDF
“Squinting Vision Pipelines: Detecting and Correcting Errors in Vision Models...
Edge AI and Vision Alliance
 
PPTX
Agentforce World Tour Toronto '25 - Supercharge MuleSoft Development with Mod...
Alexandra N. Martinez
 
PDF
Go Concurrency Real-World Patterns, Pitfalls, and Playground Battles.pdf
Emily Achieng
 
PDF
“Computer Vision at Sea: Automated Fish Tracking for Sustainable Fishing,” a ...
Edge AI and Vision Alliance
 
PDF
Reverse Engineering of Security Products: Developing an Advanced Microsoft De...
nwbxhhcyjv
 
PDF
Bitcoin for Millennials podcast with Bram, Power Laws of Bitcoin
Stephen Perrenod
 
PDF
Transforming Utility Networks: Large-scale Data Migrations with FME
Safe Software
 
PPTX
COMPARISON OF RASTER ANALYSIS TOOLS OF QGIS AND ARCGIS
Sharanya Sarkar
 
Python coding for beginners !! Start now!#
Rajni Bhardwaj Grover
 
Future Tech Innovations 2025 – A TechLists Insight
TechLists
 
CIFDAQ Market Wrap for the week of 4th July 2025
CIFDAQ
 
Q2 FY26 Tableau User Group Leader Quarterly Call
lward7
 
LOOPS in C Programming Language - Technology
RishabhDwivedi43
 
NLJUG Speaker academy 2025 - first session
Bert Jan Schrijver
 
Agentic AI lifecycle for Enterprise Hyper-Automation
Debmalya Biswas
 
Designing_the_Future_AI_Driven_Product_Experiences_Across_Devices.pptx
presentifyai
 
NASA A Researcher’s Guide to International Space Station : Physical Sciences ...
Dr. PANKAJ DHUSSA
 
How do you fast track Agentic automation use cases discovery?
DianaGray10
 
Kit-Works Team Study_20250627_한달만에만든사내서비스키링(양다윗).pdf
Wonjun Hwang
 
Newgen Beyond Frankenstein_Build vs Buy_Digital_version.pdf
darshakparmar
 
“Squinting Vision Pipelines: Detecting and Correcting Errors in Vision Models...
Edge AI and Vision Alliance
 
Agentforce World Tour Toronto '25 - Supercharge MuleSoft Development with Mod...
Alexandra N. Martinez
 
Go Concurrency Real-World Patterns, Pitfalls, and Playground Battles.pdf
Emily Achieng
 
“Computer Vision at Sea: Automated Fish Tracking for Sustainable Fishing,” a ...
Edge AI and Vision Alliance
 
Reverse Engineering of Security Products: Developing an Advanced Microsoft De...
nwbxhhcyjv
 
Bitcoin for Millennials podcast with Bram, Power Laws of Bitcoin
Stephen Perrenod
 
Transforming Utility Networks: Large-scale Data Migrations with FME
Safe Software
 
COMPARISON OF RASTER ANALYSIS TOOLS OF QGIS AND ARCGIS
Sharanya Sarkar
 

Shift Deployment Security Left with Weave GitOps & Upbound’s Universal Crossplane

  • 1. Confidential do not distribute Successfully Shift Left Security in Application Delivery with Weave GitOps Enterprise and Upbound’s Universal Crossplane In partnership with:
  • 2. 2 Webinar Platform - FAQs Using Zoom • You are in listen only mode • This webinar is being recorded • Q&A session will follow the presentation, please use the Q&A panel to submit questions • Hit escape to exit full screen • Slides and recording will be shared after the webinar Technical Issues - please visit Zoom Help https://support.zoom.us/hc/en-us/articles/206175806-Top-Questions
  • 3. 3 Dan Mangum Principal Software Engineer, Upbound Dan Mangum is a Principal Software Engineer at Upbound and a maintainer of the Crossplane project. In addition to his work in the Crossplane community, Dan has held technical leadership roles in the upstream Kubernetes community. Paul Curtis Principal Solutions Architect, Weaveworks Paul started as a developer working in financial institutions. Paul proceeded to take on technical account management at Netscape & Sun, along with system and dev operations at start ups. Paul now provides field enablement and engineering in the big data world. Speaker introductions
  • 4. Confidential do not distribute 4 The problem: ● Service and resource provisioning slows development ● Resources are spread between different environments (Kubernetes, VMs, Provider Services) ● Managing current state, recovery, and rollbacks is difficult The solution: ● Declarative and auditable provisioning across all resources ● Application and resource lifecycle management with GitOps ● Policy enforcement across all resources Shifting Security Left in Application Delivery
  • 5. Confidential do not distribute 5 Weave GitOps Enterprise with Upbound demo Weave GitOps Enterprise ● Policy guardrails for every declarative action ● Declarative deployment of applications and deployment pipelines across multiple clusters ● Declarative provisioning of Kubernetes clusters and bootstrapping services Upbound ● All the benefits of GitOps across any resource ● Declarative, audited, and observable ● Lifecycle management of resources external to Kubernetes
  • 6. Confidential do not distribute Weaveworks is backed by solid investors Weaveworks is a key partner with all the major infrastructure and Kubernetes vendors Weaveworks: the GitOps company Weaveworks is deeply committed to the Open Source Community
  • 7. Confidential do not distribute 7 Test IDE Build GitOps – An Operating Model for Cloud Native Unifying Deployment, Monitoring and Management. Git as the single source of truth of a system’s desired state ALL intended operations are committed by pull request ALL diffs between intended and observed state with automatic convergence ALL changes are observable, verifiable and auditable Kubernetes GitOps Continuous Integration GIT “Immutability Firewall” Deployment (clusters, apps) Monitoring Logging (Observability) Management (operations)
  • 8. Confidential do not distribute 8 Continuous Application Delivery - use GitOps to deploy and operate applications. Automation increases deployment velocity and developer productivity. Weave GitOps - Use Cases Kubernetes Everywhere - in the cloud or the datacenter Kubernetes is a universal platform that’s easy to manage with GitOps. DevOps Automation - Lifecycle management of the entire platform. All clusters and services, using automation and policy. 1 4 2 5 3 6 Self-Service Platforms - a complete platform giving developers autonomy while ensuring consistency and manageability. Trusted Delivery - shift policy and security left - governance, risk, and compliance are non-negotiable. Progressive Delivery - deploy services across many environments and regions reliably using GitOps
  • 9. 9 ● Built on OPA standard - Rego ● Curated library of 100+ policies ● SOC II, PCI-DSS, GDPR, HIPAA, MITRE ATTACK ● Security, resilience and coding standards ● Validation throughout SDLC ○ Commit, Pull Request ○ Build ○ Deploy ○ Runtime ● Automatic remediation via pull request Weave GitOps PaC
  • 11. Control Plane Revolution 11 🔥 3,000+ Companies in Production 🔥 7,000+ Slack channel members 🔥 6,000+ GitHub stars 🔥 40M+ Pulls on Docker Hub 🔥 Open Source and CNCF project Scripting • Legacy • Imperative Configuration Infrastructure As Code (Terraform, Ansible, Chef) • Declarative Configuration • Configuration Management • Provisioning Management • Sprawling Complexity Control Planes The Crossplane Revolution • Compliment IaC • Declarative API • Self-Service • Full Automation 2020s 1990s Who is
  • 12. ● Founders of ● Growing 700% YoY ● Commercial, Open-Core Company ○ Ease-of-Use: UX, Marketplace ○ Enterprise-Grade: Scalable, Secure, Controlled ○ Solution-Agnostic: Any cloud, Any environment, Any service ● Complement, rather than compete Who is
  • 13. Why Now Enterprises are Re-Platforming - Again! Security Cost Multiple Vendors Developer Productivity Standardization Enforcing best-practices and controls consistently across the entire organization Future Proofing
  • 15. Standardizing on Kubernetes + Crossplane API Abstractions Interfaces Control Plane A B Infrastructure
  • 16. Standardizing on Crossplane Interfaces API Abstractions Control Plane A B C D Infrastructure
  • 17. Standardizing Existing Processes Interfaces API Abstractions Infrastructure Control Plane A B C D IaC Vendors
  • 18. An Extension of Kubernetes Uniform Declarative Metadata Asynchronous Controllers Authorization Policy Admission Control Audit Logging Composition - Low Code Controllers External Naming and Identity Cross Resource References Connection Secrets Package Manager KRM XRM
  • 19. 19 Confidential do not distribute Demo Architecture
  • 20. 1. Configure management cluster with UXP and the Crossplane package for Discourse on AWS 2. Create a pull request to a repository added as a Weaveworks GitOps source 3. Observe policy violation 4. Fix policy violation 5. Weaveworks GitOps syncs manifest to cluster 6. UXP provisions infrastructure and application, providing the necessary connection data
  • 21. 21 Confidential do not distribute Questions? (Please use the Q&A panel in your Zoom menu)
  • 22. 22 Whitepaper: Shifting Security Left with GitOps and Trusted Delivery https://bit.ly/3MvzXgQ Learn more about Weave GitOps www.weave.works/enterprise Request a personal demo www.weave.works/contact Thank You
  • 23. Next Steps Sign Up Create a Free Account Learn More About UXP Universal Crossplane Visit the Marketplace https://marketplace.upbound.io