The sovereign supply chain for Canada's classified Kubernetes.
A Canadian-incorporated Kubernetes supply chain vendor. Northfleet supplies the bundle protocol, attestation chain, and tamper-evident audit trail that cleared engineering teams apply to their Protected B and Secret Kubernetes clusters on Canadian-jurisdictional infrastructure. The customer brings the cluster; Northfleet supplies the trust path between build and apply. Northfleet holds no customer data and no customer signing keys, and the architecture assumes the vendor can be compromised or compelled: compelling Northfleet does not produce a silent backdoor.
northfleetsecurity.ca · Field notes · Contact
This organization hosts open-source utilities that contribute to the shared procurement vocabulary for Canadian defence engineering teams. Both are Apache 2.0.
- cpcsc-l1-self-assessment — A self-assessment template for the 13 controls that comprise Level 1 of the Canadian Programme for Cyber Security Certification. Verbatim PSPC content, approximately 70 individual determination statements, one row per attestation criterion in the CSV. Effective April 1, 2026 as a procurement gate for Canadian defence contracts.
- itsg33-kubernetes-protected-b-mapping — A mapping of the Government of Canada Protected B / Medium control profile (CCCS ITSP.10.033-01, which superseded ITSG-33 Annex 4A Profile 1 in April 2026) to Kubernetes mechanisms, bucketed by admin-implemented, workload-implemented, and external (where upstream Kubernetes alone is insufficient).
Neither utility encodes Northfleet implementation specifics. They are public framework content with a community usability layer.
If you are evaluating sovereign infrastructure for classified workloads, the conversation is open at northfleetsecurity.ca. A briefing follows first contact.