I see a lot of teams reaching for managed services immediately, but there's value in understanding the baseline. Running your own control plane with kubeadm and layering GitOps on top gives you full control over the security posture and compliance tooling. Here's how I set up Flux on a bare-metal kubeadm cluster, focusing on the security aspects often missed.
First, bootstrap a kubeadm cluster with some hardened defaults. I modify the kubeadm config to enforce stricter controls from the start.
```yaml
# kubeadm-config.yaml
apiVersion: kubeadm.k8s.io/v1beta3
kind: ClusterConfiguration
kubernetesVersion: "1.28"
apiServer:
extraArgs:
audit-log-path: /var/log/kubernetes/audit.log
audit-policy-file: /etc/kubernetes/audit-policy.yaml
controllerManager:
extraArgs:
bind-address: "127.0.0.1"
scheduler:
extraArgs:
bind-address: "127.0.0.1"
networking:
podSubnet: "192.168.0.0/16"
serviceSubnet: "10.96.0.0/12"
---
apiVersion: kubeadm.k8s.io/v1beta3
kind: InitConfiguration
nodeRegistration:
kubeletExtraArgs:
protect-kernel-defaults: "true"
```
Once the cluster is up, install Flux with a focus on least-privilege IAM for its components. Don't use the bootstrap script blindly; inspect the manifests.
```bash
export GITHUB_USER=youruser
export GITHUB_REPO=yourrepo
flux bootstrap github
--owner=$GITHUB_USER
--repository=$GITHUB_REPO
--branch=main
--path=./clusters/production
--personal
--components-extra=image-reflector-controller,image-automation-controller
```
Key security and operational points I enforce:
* **Image Scanning Integration**: The `image-reflector-controller` is useless without a policy engine. I always pair this with Trivy or Grype in the CI that pushes images, and use `image-policy-controller` to enforce allow-lists.
* **Secret Management**: Flux does NOT handle secrets natively. Use a sealed-secrets or external secrets operator. Never commit raw secrets.
* **Network Policies**: Flux creates `gitrepositories` and `kustomizations` as CRDs. You must write Network Policies allowing the `flux-system` namespace to talk to the kube-api, and to any private git repositories.
* **Compliance & SBOM**: Use the `flux` CLI to generate an SBOM of the Flux components themselves. Track this in your artifact repository.
The main advantage of this setup is transparency. You own the entire stack, can audit every component, and integrate security scanning at every layer—from the base OS of the nodes, to the container images Flux uses, to the manifests it deploys. The operational overhead is higher than a managed service, but for regulated environments, the control is non-negotiable.
patch early
patch early