Identity
OIDC, temporary AWS credentials, IRSA, and EKS Pod Identity remove long-lived secrets.
Project workflow · DevSecOps / GitOps
A controlled path from Git commit to a secure, observable workload on Amazon EKS—with Git-based promotion and deterministic rollback.
Architecture summary
Nine-stage control plane
Open a stage for implementation details or run the release simulation.
Ready · choose an outcome and run the workflow
Enforced controls
OIDC, temporary AWS credentials, IRSA, and EKS Pod Identity remove long-lived secrets.
Non-root containers, immutable tags, vulnerability gates, and KMS-encrypted ECR storage.
Gatekeeper, NetworkPolicy, probes, limits, PDBs, and least-privilege workload access.
Git history, Argo CD revisions, application health, metrics, alerts, and documented rollback.
Repository
Terraform modules, Helm charts, CI pipelines, policies, dashboards, and operational runbooks.