GitOps at Scale: Why Your Hub-and-Spoke Architecture is a Security Risk

Watch the demo to see Sveltos in action below.

ContainerDays: GitOps at Scale, Why Your Hub-and-Spoke Architecture is a Security Risk

Presented by Artem Lajko and Gianluca Mardente. Hub-and-Spoke has become the default architecture for many GitOps platforms, but at scale a push-based hub holding privileged credentials for every cluster becomes a single point of compromise for the whole fleet.

The talk uses Argo CD and Sveltos as contrasting examples and shows how an agent-based, pull-driven approach keeps the operational simplicity of Hub-and-Spoke while removing inbound access and centralized superuser credentials, reducing the blast radius and enabling clean multi-tenancy boundaries. It includes a live demo of GitOps at scale.

https://www.youtube.com/watch?v=2E6XiNMoE74

Stuck?

Join our community for help.