ContainerDays: GitOps at Scale, Why Your Hub-and-Spoke Architecture is a Security Risk
Presented by Artem Lajko and Gianluca Mardente. Hub-and-Spoke has become the default architecture for many GitOps platforms, but at scale a push-based hub holding privileged credentials for every cluster becomes a single point of compromise for the whole fleet.
The talk uses Argo CD and Sveltos as contrasting examples and shows how an agent-based, pull-driven approach keeps the operational simplicity of Hub-and-Spoke while removing inbound access and centralized superuser credentials, reducing the blast radius and enabling clean multi-tenancy boundaries. It includes a live demo of GitOps at scale.