Enterprise forFlux CD
Contact us

ControlPlane Enterprise

Flux Distribution

An enterprise-ready distribution of Flux CD and ecosystem tools. Fully hardened by ControlPlane's security team, end-to-end tested for production use.

why enterprise

Everything upstream Flux has, hardened for production

24/7 support from the people who build Flux

Production incidents, upgrade assistance, and architecture reviews handled around the clock by CNCF Flux core maintainers and ControlPlane security engineers. Nobody knows Flux better.

Guaranteed security backports

The enterprise distribution guarantees security updates and bug fix backports for the last three minor versions of Flux.

Hardened images

FIPS-compliant hardened container images for the GitOps Toolkit controllers, in-sync with the upstream CNCF Flux releases.

Extended Kubernetes compatibility

End-to-end tested with the latest six minor releases of Kubernetes, plus RedHat OpenShift and the LTS versions provided by AWS EKS, Azure AKS, and Google GKE.

Zero CVEs with remediation SLAs

Container images, OS packages, and Go dependencies are scanned and patched on a daily basis.

Read the overview →

24/7 incident support

On-call access to Flux core maintainers

Zero known CVEs

Images scanned and patched daily

FIPS 140-3

Approved cryptography end to end

Signed images

Authenticity verified with Cosign

SBOMs and VEX documents

Dependency transparency and exploitability status

distribution channels

Pick the variant that fits your compliance posture

Distroless

Hardened Google Distroless-based Flux images with no shell or package managers, reducing the attack surface and eliminating entire classes of CVEs.

Available as distroless and distroless-fips. The FIPS variant is built with the Go FIPS 140-3 mode, restricting TLS and SSH to FIPS-approved settings.

Mainline

Alpine Linux-based images fully compatible with the upstream Flux feature set.

The major difference between the Flux upstream images and the ControlPlane mainline images is the continuous scanning and CVE patching for the container base images, OS packages, and Go dependencies.

Compare the distribution channels in the docs →

delivery pipeline

A SLSA-compliant path from source to production

The build, test and release pipeline developed by ControlPlane is compliant with the SLSA security framework (Build Level 3). The distribution comprises Open Source components: the CNCF Flux controllers (Apache 2.0) and the Flux Operator (AGPL 3.0).

Explore the security architecture →
patch

CVE patches and hotfixes applied to the Flux components

build

FIPS-compliant binaries and multi-arch container images

test

Conformance tests across Kubernetes and OpenShift versions

sign

Cosign signatures, SBOMs, and VEX documents generated

publish

Container images available to customers

seamless migration

Adopt in minutes, leave whenever you want

Zero-downtime migration

Moving from upstream Flux to the enterprise distribution is a one-field change: point the FluxInstance at the ControlPlane registry and the operator rolls out the hardened controllers in place, without interrupting reconciliation.

No vendor lock-in

The distribution is 100% compatible with the upstream APIs and manifests. Switching back to the CNCF images is the same one-field change in reverse.

Read the installation guide →

advanced delivery

Built the way regulated teams ship

Time-Based Delivery

Keep GitOps automation inside your change-management process. With reconciliation schedules, Flux applies changes only during approved windows, so CAB slots and peak business hours are enforced by the platform instead of by convention.

Read the time-based delivery guide →

Gitless GitOps

Take the Git server out of the critical path. Production clusters pull versioned, signed OCI artifacts from container registries, which suits air-gapped environments and removes the need for Git credentials inside the cluster.

Learn about Gitless GitOps →

air-gapped operations

Run disconnected without falling behind

One-command mirroring

The Flux Operator CLI copies the entire distribution, controller images, operator, and Helm charts, to your private registry, verifying image signatures before the transfer.

Automated offline updates

Patch releases and CVE fixes roll out from your own registry on your schedule, applied in-cluster by the Flux Operator without internet egress.

Read the air-gapped guide →

enterprise addons

Extend the distribution across your platform

Enforce identity policies, streamline incident response, and operate GitOps at scale with the Flux Web UI, the Flux MCP Server, and the Dex identity provider, all covered by ControlPlane's SLA for CVE remediation and FIPS compliance.

Explore the enterprise addons →

Talk to the Flux team at ControlPlane

Get a demo of the enterprise distribution and a subscription tailored to your environment.