Skip to content

Latest commit

 

History

52 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Socle

OpenSSF Scorecard PR static checks License

Open source GitOps distribution for managed Kubernetes clusters — EKS, GKE, AKS and Scaleway Kapsule.

Pick your cloud, pick your modules. Socle ships as one signed OCI artifact pulled by Flux: upgrading your whole platform means bumping one version in Git.

How it works

  • Foundations — one OpenTofu root module per cloud: network, managed cluster, identities, Flux bootstrap. OpenTofu provisions and steps away.
  • Catalog — à la carte modules (cert-manager, external-dns, monitoring, ...) shipped as HelmReleases. Cloud resources a module needs (IAM roles, DNS access, ...) are provisioned in-cluster by Crossplane — 100% GitOps, no out-of-band scripts.
  • Upgrades — the whole socle is published as a cosign-signed, SemVer-tagged OCI artifact. Your cluster pins one tag; Flux pulls, verifies and reconciles the rest in dependency order.

Status

Pre-0.1.0 — under active construction. Nothing is installable yet.

Security

See SECURITY.md. Please report vulnerabilities through private vulnerability reporting, never in public issues.

License

Apache-2.0

About

Open source GitOps distribution for managed Kubernetes clusters — EKS, GKE, AKS, Scaleway Kapsule. One signed OCI artifact, à la carte modules, upgrading = bumping one version.

Topics

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages