Skip to content

Latest commit

 

History

5 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Fortplane

Fortplane is a security-focused Kubernetes platform baseline for connected, limited-egress, and air-gapped environments. It combines identity, policy enforcement, service networking, observability, backup, and runtime security into composable Zarf packages.

CI License: AGPL-3.0

What it demonstrates

  • Kubernetes platform composition with Zarf packages and bundles.
  • Admission and policy controls implemented with Pepr.
  • Identity-aware ingress through Keycloak, Istio, and Authservice.
  • Metrics, logs, dashboards, backup, and runtime detection.
  • Repeatable deployment patterns for constrained environments.
flowchart LR
    A["Zarf bundle"] --> B["Fortplane packages"]
    B --> C["Identity and ingress"]
    B --> D["Policy enforcement"]
    B --> E["Observability"]
    B --> F["Backup and runtime security"]
    C --> G["Kubernetes workload"]
    D --> G
    E --> G
    F --> G
Loading

Repository map

Path Purpose
packages/ Deployable platform layers and bundles
src/ Component definitions, Helm values, and Pepr policy code
bundles/ Development and integration bundle compositions
test/ Unit, integration, and browser-based validation
tasks/ Reproducible build, lint, and test workflows

Local validation

Requirements: Node.js 22 or later and npm.

npm ci
npm run format:check
npm run test:unit

Cluster-level packaging and integration tasks additionally require the UDS CLI, Zarf, Docker, Helm, and k3d. The detailed component guides under packages/, src/, and bundles/ retain upstream uds-* identifiers because they are compatibility-sensitive Kubernetes, Zarf, OCI, and configuration names.

Security model

Fortplane defaults to rejecting Pepr admission errors, separates platform capabilities into explicit packages, and supports offline artifact assembly. A real deployment still requires environment-specific threat modeling, image provenance controls, secret management, capacity planning, and recovery testing.

Report vulnerabilities through GitHub private vulnerability reporting. Do not place sensitive details in a public issue.

Provenance and licensing

Fortplane is maintained by Adrien Murillo. This repository contains a modified distribution of UDS Core. See NOTICE for provenance and retained attribution. Fortplane is distributed solely under GNU AGPL v3.0; no commercial license is offered by this repository.

About

Secure air-gapped Kubernetes platform foundation with policy enforcement and supply-chain controls.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages