Project Lightning Talk: Flux - What is it & What's New? - Tamao Nakahara, Community Maintainer

Tamao Nakahara, Community Maintainer

KubeCon + CloudNativeCon Europe 2025 · Project Lightning Talk

Watch on YouTube

Visual summary for Project Lightning Talk: Flux - What is it & What's New? - Tamao Nakahara, Community Maintainer by Tamao Nakahara, Community Maintainer
Visual summary for Project Lightning Talk: Flux - What is it & What's New? - Tamao Nakahara, Community Maintainer by Tamao Nakahara, Community Maintainer

Key moments

  1. 0:00 Introduction: Flux's core value propositions
  2. 1:00 Flux: The originator and foundation of GitOps
  3. 2:00 Key features: Lightweight, multi-cluster, Helm SDK
  4. 2:50 New health checks with Common Expression Language (CEL)
  5. 4:00 Latest integrations: UI, Operator, Gen AI architecture
  6. 4:50 Flux's security-first design and audits
  7. 5:30 Conclusion and where to find more information

Project Lightning Talk: Flux - What is it & What's New?

Speakers: Tamao Nakahara, Community Maintainer

Conference: KubeCon EU

YouTube: https://www.youtube.com/watch?v=k7Wcd9HdXAY

Overview

This talk provides a concise yet comprehensive update on Flux, a graduated project within the Cloud Native Computing Foundation (CNCF). Presented by Tamao Nakahara, a Flux community maintainer, the session highlights Flux's foundational role in the GitOps ecosystem and its continuous evolution to meet modern CI/CD demands. The talk underscores Flux's commitment to security-first design, scalability, and progressive delivery capabilities like canary and blue/green deployments. It aims to inform both new and existing users about Flux's core strengths, recent advancements such as enhanced health checks and new integrations, and its widespread adoption across diverse enterprises, including financial, healthcare, and government sectors. The presentation reinforces Flux's position as a robust, reliable, and secure platform for automating Kubernetes deployments.

Nakahara emphasizes that Flux is often the unseen engine powering GitOps functionality in major cloud providers like Azure and AWS, making it a critical, albeit sometimes unacknowledged, component of many organizations' Kubernetes strategies. The talk serves as a vital update for anyone leveraging or considering GitOps for their infrastructure, offering insights into how Flux addresses key operational challenges such as automation, reliability, and security in complex, multi-cluster environments. It showcases the project's maturity and its ongoing efforts to adapt to emerging trends, including the integration of AI/ML workflows.

Background

▶ Watch: Introduction: Flux's core value propositions (0:00)

The concept of GitOps, pioneered by Flux, posits that the desired state of an application and infrastructure should be declared in Git, serving as the single source of truth. Flux continuously monitors Git repositories for changes and automatically reconciles the cluster's actual state with the declared state. This paradigm shift from imperative, script-based deployments to declarative, Git-driven automation has become an industry standard for managing Kubernetes applications. Flux has been at the forefront of this movement for years, achieving graduated project status within the CNCF, a testament to its maturity, widespread adoption, and strong community support.

Before Flux, organizations often grappled with "cobbled together" CI/CD systems, characterized by manual configurations, inconsistent deployments, and a lack of reliable version control for infrastructure. This led to operational friction, increased error rates, and difficulty in scaling deployments. Flux emerged to address these pain points by offering a standardized, automated, and auditable approach to Kubernetes operations. Its design principles prioritize reliability, enabling organizations to meet DORA metrics for release speed and stability, and security, making it a trusted choice for highly regulated industries. Furthermore, its lightweight and fast architecture, coupled with multi-everything capabilities (multi-tenant, multi-Git, multi-cluster), ensures it can adapt to diverse and complex organizational needs, facilitating faster Kubernetes adoption and experimentation.

Key Findings

▶ Watch: Key features: Lightweight, multi-cluster, Helm SDK (2:00)

The talk highlighted several significant advancements and key findings regarding the Flux project's evolution and capabilities:

  1. Enhanced Health Checks with Common Expression Language (CEL): A major new feature is the availability of more granular health checks utilizing Common Expression Language (CEL). This allows users to define precise conditions for cluster status and readiness, enabling sophisticated dependency management, robust handling of race conditions, and more targeted notifications. This significantly improves the reliability and observability of deployments.
  2. Simplified Multi-Cluster Management via Cluster API Integration: Flux continues to strengthen its integration with Cluster API, which simplifies the management and provisioning of Kubernetes clusters across various environments. This integration streamlines multi-cluster operations, making them more scalable and less complex for organizations.
  3. Improved User Interfaces (UIs): The Headlamp team has been working closely with Flux to develop a highly usable UI. While specific new features weren't detailed, the collaboration signifies a commitment to enhancing the user experience and making Flux more accessible.
  4. Flux Operator for Streamlined Bootstrap: A new Flux operator has been introduced to make the Flux Bootstrap process even more convenient. This operator automates and streamlines many of the initial setup processes, reducing manual effort and accelerating adoption.
  5. Reference Architecture for Generative AI (Gen AI) Workloads: Helix, the speaker's employer and a Flux user, has released reference architecture demonstrating how Flux can be used for version controlling and deploying Large Language Models (LLMs). This highlights Flux's adaptability to emerging technologies and its utility in managing complex AI/ML pipelines.
  6. Continuous Security Enhancements: Flux maintains its security-first design, evidenced by successful CNCF security audits, the use of Kubernetes RBAC, and the recent addition of GitHub App authentication. These measures reinforce its suitability for highly sensitive environments.

Technical Deep Dive

▶ Watch: New health checks with Common Expression Language (CEL) (2:50)

Flux operates on the core principle of GitOps, where the desired state of a Kubernetes cluster is declared in a Git repository. This repository acts as the single source of truth, and Flux continuously monitors it for changes. When a change is detected, Flux automatically reconciles the cluster's actual state to match the declared state. This declarative approach, backed by Git's version control capabilities, provides an immutable, auditable, and repeatable deployment process.

At its heart, Flux leverages a set of Kubernetes controllers that watch for specific custom resources (CRs) representing Git repositories, Helm charts, and Kubernetes manifests. These controllers ensure that the resources specified in Git are applied to the cluster. For instance, the Source Controller fetches artifacts from Git, Helm repositories, or OCI registries, while the Kustomize Controller and Helm Controller apply these configurations to the cluster.

One of Flux's significant strengths lies in its native Helm SDK integration. Unlike some GitOps tools that might wrap Helm or use simplified templating, Flux directly utilizes the Helm SDK. This ensures full compatibility with existing Helm charts, allows for efficient management of releases, and prevents the need for duplicating configuration logic. This native integration is particularly beneficial in multi-cluster environments, where managing numerous Helm releases across different clusters can become complex. Flux simplifies this by providing a unified, Git-driven approach to Helm chart deployment and lifecycle management.

Flux is designed to be multi-everything:

  • Multi-tenant: It supports multiple teams or users deploying to the same cluster with appropriate isolation, often enforced through Kubernetes RBAC (Role-Based Access Control).
  • Multi-Git: It can pull configurations from various Git providers (GitHub, GitLab, Bitbucket) and even multiple repositories simultaneously.
  • Multi-cluster: Its architecture is inherently suited for managing fleets of Kubernetes clusters. This is further enhanced by its deep integration with Cluster API. By using Cluster API, Flux can not only manage applications deployed to clusters but also manage the lifecycle of the clusters themselves (provisioning, upgrading, deprovisioning) from Git, providing an end-to-end GitOps experience for infrastructure. This integration simplifies operations significantly for organizations running a large number of clusters.

A notable technical advancement is the introduction of health checks using Common Expression Language (CEL). CEL is a lightweight, open-source expression language designed for evaluating expressions quickly and safely. By integrating CEL, Flux users can define highly granular conditions for determining the health and readiness of deployed applications and infrastructure. For example, instead of a simple "is the pod running?", users can define expressions like "the average CPU utilization of pods in deployment X is below 70% AND the number of successful HTTP requests to service Y is above 95%." This fine-grained control is crucial for:

  • Dependency Management: Ensuring that dependent services are truly ready before deploying an application.
  • Race Condition Mitigation: Precisely defining when a resource is stable, preventing premature actions.
  • Granular Notifications: Triggering alerts only when specific, meaningful health thresholds are crossed, reducing alert fatigue.

Security is a cornerstone of Flux's design. It builds upon Kubernetes' native RBAC to enforce least-privilege access, ensuring that Flux controllers only have the necessary permissions to perform their tasks. The recent addition of GitHub App authentication provides a more secure and robust method for Flux to interact with Git repositories, avoiding the use of personal access tokens and leveraging GitHub's native security model. Furthermore, Flux has undergone multiple independent security audits through the CNCF, consistently demonstrating a strong security posture. This robust security foundation makes Flux a trusted choice for highly regulated environments, including financial institutions, healthcare providers, and government agencies.

Finally, Flux's extensibility fosters a vibrant community that continuously builds integrations and adds value. This includes various UIs, like the one developed in collaboration with the Headlamp team, and specialized operators, such as the new Flux operator for streamlined bootstrapping. This ecosystem ensures that Flux remains adaptable and can integrate seamlessly into diverse cloud-native workflows.

Demo / Proof of Concept

▶ Watch: Flux's security-first design and audits (4:50)

The talk, being a lightning session, did not include a live, interactive demo of Flux's capabilities. However, the speaker did highlight a significant practical application that serves as a proof of concept for Flux's adaptability and utility in emerging domains.

Specifically, it was mentioned that Helix, the speaker's company and a Flux user, has published reference architecture demonstrating how Flux can be effectively utilized for version controlling Large Language Models (LLMs). This is a crucial area as Generative AI (Gen AI) becomes more prevalent, requiring robust methods for managing the lifecycle of AI models, their configurations, and their deployment. This reference architecture essentially acts as a blueprint, showcasing how Flux's GitOps principles can be extended beyond traditional application and infrastructure deployments to manage complex AI/ML pipelines, ensuring that LLMs are deployed reliably, securely, and with full auditability, much like any other cloud-native application. This demonstrates Flux's flexibility and its ability to adapt to cutting-edge technological requirements, even without a live demonstration during the talk itself.

Defensive Implications

▶ Watch: Conclusion and where to find more information (5:30)

Flux's design and features offer significant defensive implications for organizations operating Kubernetes environments, particularly in the context of CI/CD pipeline security and operational resilience.

Firstly, the core GitOps methodology enforced by Flux provides a robust security baseline. By treating Git as the single source of truth for all infrastructure and application configurations, Flux ensures that:

  • Immutability: Deployments are consistent and repeatable. Any deviation from the desired state in Git is automatically reconciled, preventing configuration drift and unauthorized manual changes. This reduces the attack surface by eliminating ad-hoc modifications.
  • Auditability: Every change to the infrastructure is tracked in Git with a commit history, including who made the change and when. This provides a clear, immutable audit trail, invaluable for forensic analysis in case of a security incident and for compliance requirements.
  • Rollback Capability: In the event of a faulty deployment or a detected vulnerability, rolling back to a previous known good state is as simple as reverting a Git commit, offering a rapid recovery mechanism.

Secondly, Flux's security-first design is explicitly mentioned and backed by tangible features. The project's consistent success in CNCF security audits provides a high level of assurance regarding its internal security posture, meaning the tool itself is less likely to introduce vulnerabilities. The integration of Kubernetes RBAC ensures that Flux controllers operate with the principle of least privilege, restricting their actions only to what is necessary, thereby minimizing the potential blast radius if a component were compromised. The recent addition of GitHub App authentication further strengthens this by providing a more secure and granular way for Flux to interact with Git repositories, moving away from less secure personal access tokens and leveraging GitHub's native security mechanisms. This is critical for protecting the integrity of the source of truth.

Thirdly, Flux's capabilities in progressive delivery (canary, blue/green deployments) directly contribute to defensive strategies. By enabling gradual rollouts of new features or security patches, organizations can:

  • Reduce Blast Radius: If a new deployment introduces a bug or a vulnerability, it only affects a small subset of users or infrastructure, allowing for quick detection and mitigation before widespread impact.
  • Improve Reliability: The ability to test changes in a live environment incrementally enhances the overall stability and security of the system by catching issues early.

Fourthly, the new health checks with Common Expression Language (CEL) provide advanced operational visibility that can be crucial for defense. Granular health checks allow security and operations teams to define precise conditions for system health, beyond just "running." This means:

  • Early Anomaly Detection: Custom CEL expressions can monitor for unusual behavior or specific security indicators, potentially identifying anomalous states that might precede or signify an attack.
  • Dependency Awareness: Understanding and enforcing dependencies ensures that services come up in the correct order and maintain their integrity, preventing cascading failures or vulnerabilities arising from misordered deployments.

Finally, the talk highlighted the understanding that CI/CD pipelines are often vulnerable areas targeted by attackers. By adopting a GitOps tool like Flux, which is designed with security as a core tenet and integrates robust authentication and authorization mechanisms, organizations can significantly harden their CI/CD processes. This proactive approach helps protect against supply chain attacks and ensures that the path from code commit to production is as secure as possible.

Key Takeaways

  • Flux is a Mature GitOps Standard: As a graduated CNCF project, Flux is a foundational and widely adopted tool for GitOps, often powering cloud provider offerings.
  • Security-First Design: Flux prioritizes security, featuring Kubernetes RBAC, GitHub App authentication, and a history of successful CNCF security audits, making it suitable for highly regulated environments.
  • Enhanced Operational Control with CEL Health Checks: New granular health checks powered by Common Expression Language (CEL) provide advanced control over dependency management, race conditions, and notifications for increased reliability.
  • Multi-Everything for Scalability: Flux is inherently multi-tenant, multi-Git, and multi-cluster, with deep integration with Cluster API to simplify large-scale Kubernetes management.
  • Progressive Delivery Built-In: It enables advanced deployment strategies like canary and blue/green, crucial for reliable and safe software releases.
  • Adaptable to Emerging Technologies: Flux's extensibility is demonstrated through new UIs, operators, and reference architectures for managing Generative AI (Gen AI) workloads like LLMs.

About the Speaker(s)

Tamao Nakahara is a dedicated Community Maintainer for the Flux project, a graduated project within the CNCF. Her involvement signifies a deep commitment to the project's development, community engagement, and strategic direction. In addition to her role as a maintainer, Tamao also works for Helix, a company that actively utilizes Flux, providing her with valuable real-world experience and insight into the practical applications and challenges faced by Flux users. Her dual role as both a core contributor and an end-user gives her a unique perspective on Flux's capabilities and its evolution.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This lightning talk on Flux, a foundational CNCF project, delivered a remarkably high signal-to-noise ratio. The speaker, a Flux maintainer, provided concrete updates on critical features like Common Expression Language (CEL) driven health checks and a practical reference architecture for managing Large Language Models (LLMs) via GitOps. It's a valuable update that demonstrates real technical progression and practical utility for anyone serious about secure, scalable Kubernetes operations.

Heather Calloway (CISO) — STRONG ACCEPT

This lightning talk effectively updates the audience on Flux, a critical GitOps project, emphasizing its foundational role in enterprise Kubernetes deployments. It showcases significant advancements in security, operational control via CEL health checks, and scalability for multi-cluster environments. For any CISO, this reinforces Flux's commitment to auditability, reliability, and secure automation, directly addressing the institutional accountability and resilience required in modern cloud-native strategies, especially in highly regulated sectors.

→ Top-rated talks at KubeCon + CloudNativeCon Europe 2025

All talks from KubeCon + CloudNativeCon Europe 2025