Enterprise forFlux CD
Contact us

ControlPlane Enterprise

Flux Distribution

An enterprise-ready distribution of Flux CD and ecosystem tools. Fully hardened by ControlPlane's security team, end-to-end tested for production use.

why enterprise

Everything upstream Flux has, hardened for production

24/7 support from the people who build Flux

Production incidents, upgrade assistance, and architecture reviews handled around the clock by CNCF Flux core maintainers and ControlPlane security engineers. Nobody knows Flux better.

Guaranteed security backports

The enterprise distribution guarantees security updates and bug fix backports for the last three minor versions of Flux.

Hardened images

Hardened container images for the GitOps Toolkit controllers, in-sync with the upstream CNCF Flux releases.

Extended Kubernetes compatibility

End-to-end tested with the latest six minor releases of Kubernetes, plus RedHat OpenShift and the LTS versions provided by AWS EKS, Azure AKS, and Google GKE.

Zero CVEs with remediation SLAs

Container images, OS packages, and Go dependencies are scanned and patched on a daily basis.

Read the overview →

FIPS 140-3

Approved cryptography end to end

Signed images

Cosign signatures backed by GitHub OIDC

SBOMs and VEX documents

SPDX inventories and OpenVEX exploitability status

distribution channels

Pick the variant that fits your compliance posture

Distroless

Hardened Google Distroless-based Flux images with no shell or package managers, reducing the attack surface and eliminating entire classes of CVEs.

Available as distroless and distroless-fips. The FIPS variant is built with the Go FIPS 140-3 mode, restricting TLS and SSH to FIPS-approved settings.

Mainline

Alpine Linux-based images fully compatible with the upstream Flux feature set.

The major difference between the Flux upstream images and the ControlPlane mainline images is the continuous scanning and CVE patching for the container base images, OS packages, and Go dependencies.

Compare the distribution channels in the docs →

delivery pipeline

A SLSA-compliant path from source to production

The build, test and release pipeline developed by ControlPlane is compliant with the SLSA security framework (Build Level 3). The distribution comprises Open Source components: the CNCF Flux controllers (Apache 2.0) and the Flux Operator (AGPL 3.0).

Explore the security architecture →
patch

CVE patches and hotfixes applied to the Flux components

build

FIPS-compliant binaries and multi-arch container images

test

Conformance tests across Kubernetes and OpenShift versions

sign

Cosign signatures, SBOMs, and VEX documents generated

publish

Container images available to customers

migration

Adopt in minutes, leave whenever you want

Zero-downtime migration

Moving from upstream Flux to the enterprise distribution is a one-field change: point the FluxInstance at the ControlPlane registry and the operator rolls out the hardened controllers in place.

No vendor lock-in

The distribution is 100% compatible with the upstream APIs and manifests. Switching back to the CNCF images reverts that one line.

Read the installation guide →

advanced delivery

Control when changes land, and where they come from

Time-Based Delivery

Keep GitOps automation inside your change-management process. With reconciliation schedules, Flux applies changes only during approved windows, so CAB slots and peak business hours are enforced by the platform instead of by convention.

Read the time-based delivery guide →

Gitless GitOps

Take the Git server out of the critical path. Production clusters pull versioned, signed OCI artifacts from container registries, which suits air-gapped environments and removes the need for Git credentials inside the cluster.

Learn about Gitless GitOps →

air-gapped operations

Run disconnected without falling behind

One-command mirroring

The Flux Operator CLI copies the entire distribution, controller images, operator, and Helm charts, to your private registry, verifying image signatures before the transfer.

Automated offline updates

Patch releases and CVE fixes roll out from your own registry on your schedule, applied in-cluster by the Flux Operator without internet egress.

Read the air-gapped guide →

enterprise addons

Extend the distribution across your platform

The Flux Web UI, the Flux MCP Server, and the Dex identity provider add live delivery status, AI-assisted troubleshooting, and OIDC single sign-on to the distribution, under the same CVE remediation and FIPS commitments.

Explore the enterprise addons →

Talk to the Flux team at ControlPlane

Get a demo of the enterprise distribution and a subscription tailored to your environment.