ControlPlane Enterprise
Flux Distribution
An enterprise-ready distribution of Flux CD and ecosystem tools. Fully hardened by ControlPlane's security team, end-to-end tested for production use.
why enterprise
Everything upstream Flux has, hardened for production
24/7 support from the people who build Flux
Production incidents, upgrade assistance, and architecture reviews handled around the clock by CNCF Flux core maintainers and ControlPlane security engineers. Nobody knows Flux better.
Guaranteed security backports
The enterprise distribution guarantees security updates and bug fix backports for the last three minor versions of Flux.
Hardened images
FIPS-compliant hardened container images for the GitOps Toolkit controllers, in-sync with the upstream CNCF Flux releases.
Extended Kubernetes compatibility
End-to-end tested with the latest six minor releases of Kubernetes, plus RedHat OpenShift and the LTS versions provided by AWS EKS, Azure AKS, and Google GKE.
Zero CVEs with remediation SLAs
Container images, OS packages, and Go dependencies are scanned and patched on a daily basis.
24/7 incident support
On-call access to Flux core maintainers
Zero known CVEs
Images scanned and patched daily
FIPS 140-3
Approved cryptography end to end
Signed images
Authenticity verified with Cosign
SBOMs and VEX documents
Dependency transparency and exploitability status
distribution channels
Pick the variant that fits your compliance posture
Distroless
Hardened Google Distroless-based Flux images with no shell or package managers, reducing the attack surface and eliminating entire classes of CVEs.
Available as distroless and distroless-fips. The FIPS variant is built with the Go FIPS 140-3 mode, restricting TLS and SSH to FIPS-approved settings.
Mainline
Alpine Linux-based images fully compatible with the upstream Flux feature set.
The major difference between the Flux upstream images and the ControlPlane mainline images is the continuous scanning and CVE patching for the container base images, OS packages, and Go dependencies.
delivery pipeline
A SLSA-compliant path from source to production
The build, test and release pipeline developed by ControlPlane is compliant with the SLSA security framework (Build Level 3). The distribution comprises Open Source components: the CNCF Flux controllers (Apache 2.0) and the Flux Operator (AGPL 3.0).
Explore the security architecture →CVE patches and hotfixes applied to the Flux components
FIPS-compliant binaries and multi-arch container images
Conformance tests across Kubernetes and OpenShift versions
Cosign signatures, SBOMs, and VEX documents generated
Container images available to customers
seamless migration
Adopt in minutes, leave whenever you want
Zero-downtime migration
Moving from upstream Flux to the enterprise distribution is a one-field change: point the FluxInstance at the ControlPlane registry and the operator rolls out the hardened controllers in place, without interrupting reconciliation.
No vendor lock-in
The distribution is 100% compatible with the upstream APIs and manifests. Switching back to the CNCF images is the same one-field change in reverse.
advanced delivery
Built the way regulated teams ship
Time-Based Delivery
Keep GitOps automation inside your change-management process. With reconciliation schedules, Flux applies changes only during approved windows, so CAB slots and peak business hours are enforced by the platform instead of by convention.
Read the time-based delivery guide →Gitless GitOps
Take the Git server out of the critical path. Production clusters pull versioned, signed OCI artifacts from container registries, which suits air-gapped environments and removes the need for Git credentials inside the cluster.
Learn about Gitless GitOps →air-gapped operations
Run disconnected without falling behind
One-command mirroring
The Flux Operator CLI copies the entire distribution, controller images, operator, and Helm charts, to your private registry, verifying image signatures before the transfer.
Automated offline updates
Patch releases and CVE fixes roll out from your own registry on your schedule, applied in-cluster by the Flux Operator without internet egress.
enterprise addons
Extend the distribution across your platform
Enforce identity policies, streamline incident response, and operate GitOps at scale with the Flux Web UI, the Flux MCP Server, and the Dex identity provider, all covered by ControlPlane's SLA for CVE remediation and FIPS compliance.
Explore the enterprise addons →Talk to the Flux team at ControlPlane
Get a demo of the enterprise distribution and a subscription tailored to your environment.