Project Lightning Talk: Stir to Combine: Creating Porter Mixins - Sarah Christoff, Maintainer

Sarah Christoff, Maintainer

KubeCon + CloudNativeCon Europe 2025 · Project Lightning Talk

Overview

In this KubeCon EU lightning talk, Sarah Christoff, the lead maintainer for Porter, introduced attendees to this cloud-native, tool-agnostic project. Porter is a CNCF sandbox project designed to address the common pain points developers face when orchestrating a multitude of disparate DevOps tools at scale within large organizations. It aims to streamline the deployment of applications, execution of pipelines, and setup of complex systems by wrapping these tools and their configurations into immutable container images.

Watch on YouTube

Visual summary for Project Lightning Talk: Stir to Combine: Creating Porter Mixins - Sarah Christoff, Maintainer by Sarah Christoff, Maintainer
Visual summary for Project Lightning Talk: Stir to Combine: Creating Porter Mixins - Sarah Christoff, Maintainer by Sarah Christoff, Maintainer

Key moments

  1. 0:00 Introduction to Porter: a cloud-native, tool-agnostic CNCF project.
  2. 1:20 Understanding Porter Mixins: extending functionality for DevOps tools.
  3. 2:07 Defining Porter bundle actions and simplified user experience.
  4. 2:30 Deploying Porter with the Kubernetes Operator for cluster management.
  5. 3:20 Leveraging Porter with CI/CD pipelines like Flux and Argo CD.
  6. 3:55 Porter in action: Microsoft marketplaces and F5 cost savings.
  7. 4:30 Join the Porter community: maintainers, contributors, and enthusiasts.

Project Lightning Talk: Stir to Combine: Creating Porter Mixins

Speakers: Sarah Christoff, Maintainer

Conference: KubeCon EU

YouTube: https://www.youtube.com/watch?v=4YVSW8UuHac

Overview

In this KubeCon EU lightning talk, Sarah Christoff, the lead maintainer for Porter, introduced attendees to this cloud-native, tool-agnostic project. Porter is a CNCF sandbox project designed to address the common pain points developers face when orchestrating a multitude of disparate DevOps tools at scale within large organizations. It aims to streamline the deployment of applications, execution of pipelines, and setup of complex systems by wrapping these tools and their configurations into immutable container images.

Porter achieves this by building upon the Cloud-Native Application Bundles (CNAB) specification, an open-source standard leveraging the OCI specification. The core innovation lies in its ability to enable best practices across diverse technologies, allowing organizations to define, deploy, and manage their infrastructure and applications consistently. Christoff highlighted how Porter simplifies the developer experience by abstracting underlying complexity, while providing powerful extensibility through its mixin architecture, which allows integration with virtually any DevOps tool.

The significance of Porter lies in its potential to standardize and secure the software supply chain and infrastructure deployments. By providing a unified approach to managing the lifecycle of applications and their dependencies, from installation to uninstallation and upgrades, Porter helps reduce configuration drift, improve auditability, and lower operational costs. The talk underscored Porter's role in fostering a more efficient, reliable, and "cloud-native" way to manage complex distributed systems.

Background

▶ Watch: Introduction to Porter: a cloud-native, tool-agnostic CNCF project. (0:00)

The modern cloud-native landscape is characterized by an explosion of specialized DevOps tools. While each tool excels in its specific domain – be it infrastructure provisioning with Terraform, package management with Helm, or container orchestration with Kubernetes – integrating them into cohesive, repeatable, and scalable workflows presents a significant challenge. Developers often find themselves "gluing together" these disparate tools through custom scripts, environment variables, and manual processes, leading to fragility, inconsistency, and a steep learning curve. This ad-hoc integration becomes particularly problematic in large enterprises where diverse teams, technologies, and compliance requirements must be met.

This challenge led to the inception of Porter, a project born from the direct experience of developers struggling with these integration pains at scale. Porter's foundational technology is the Cloud-Native Application Bundle (CNAB) specification. CNAB is an open-source, vendor-neutral specification designed to package distributed applications and their dependencies. It leverages the Open Container Initiative (OCI) specification, meaning CNAB bundles are essentially OCI-compliant images that can be stored and distributed via standard container registries. This approach provides a robust, immutable, and verifiable packaging format for entire application lifecycles.

Prior to Porter, solutions often involved complex CI/CD pipelines that, while automating tasks, still required deep knowledge of each individual tool and intricate scripting to manage their interactions and state. Porter aims to elevate this abstraction, providing a higher-level framework that not only packages these tools but also defines how they interact, manage credentials, and maintain their state across various environments. This shift reduces the burden on individual developers and operations teams, allowing them to focus on desired outcomes rather than the mechanics of tool orchestration.

Key Findings

▶ Watch: Defining Porter bundle actions and simplified user experience. (2:07)

Porter's core contribution is its ability to streamline the orchestration of disparate DevOps tools into a unified, managed experience. The key findings and mechanisms presented in the talk include:

  1. Cloud-Native Application Bundles (CNAB) as the Core Packaging Unit: Porter leverages CNAB, an open-source specification built upon OCI, to package applications and their dependencies. These bundles are defined in YAML and encapsulate all necessary logic, tools, and configurations for actions like install, uninstall, and upgrade, as well as custom actions like plan or teardown. This ensures immutability and portability of deployments.
  1. Extensible Mixin Architecture: A fundamental concept in Porter is the mixin. Mixins are extensions that teach Porter how to interact with specific DevOps tools. Each mixin pulls its own container image and defines the logic for how that tool should be executed within a Porter bundle. This design allows for seamless integration with a wide array of tools, including Terraform, Helm, Kubernetes, OpenTofu, and Spin. The speaker emphasized the ease with which custom mixins can be created, stating it can be done "in five minutes," provided one understands the target DevOps tool.
  1. Simplified User Experience: For end-users, Porter abstracts the complexity of the underlying YAML configurations and tool orchestrations. Users interact with bundles through simple commands like porter install or porter uninstall, passing only necessary environment variables. This creates a curated experience, where users only see "what you have defined as their reality," significantly reducing operational overhead and potential for misconfiguration.
  1. Secure Credential Management: Porter provides robust mechanisms for managing sensitive information. It can pull credentials from various secure sources, including local machine environment variables, Vault, or Azure Key Vault, as well as local files or files on the host machine. This promotes best practices for security and avoids hardcoding sensitive data within bundles.
  1. Kubernetes Operator for Cloud-Native Management: Porter offers a Kubernetes operator that allows Porter itself to be installed and managed within a Kubernetes cluster in a "cloud-native way." This operator runs inside the cluster, manages Porter installations, and uses MongoDB as a state store to reconcile the desired state of bundles within the cluster. This enables automated updates and ensures bundles are always running their most up-to-date versions, facilitating integration with GitOps tools like Flux and Argo CD.
  1. Real-World Use Cases Demonstrating Value: The talk highlighted practical applications of Porter:
  • Microsoft Marketplaces: Used for Platforms-as-a-Service (PaaS) deployments, where bundles define a desired state, and users provide variables (e.g., cloud provider, Key Vault configuration) to deploy into their specific environments.
  • F5 Cost Optimization: F5 leverages Porter to automatically tear down testing resources after tests are completed, significantly reducing cloud bills and optimizing resource utilization for SRE and cloud infrastructure teams.

These findings collectively demonstrate Porter's capability to act as a powerful aggregation and orchestration layer, bringing consistency, security, and efficiency to complex cloud-native operations.

Technical Deep Dive

▶ Watch: Deploying Porter with the Kubernetes Operator for cluster management. (2:30)

Porter's architecture is rooted in the principles of immutability, extensibility, and abstraction, primarily centered around its use of Cloud-Native Application Bundles and a modular mixin system.

At its core, Porter relies on the Cloud-Native Application Bundle (CNAB) specification. A CNAB is an OCI-compliant artifact that packages all the necessary components for an application's lifecycle management. This includes the application itself, its dependencies, and the tooling required to install, upgrade, and uninstall it. Porter bundles are defined in YAML files, adhering to the CNAB specification. These YAML definitions specify the actions (e.g., install, upgrade, uninstall) and the steps for each action. For instance, an install action might involve provisioning infrastructure with Terraform, then deploying an application with Helm.

A crucial component of Porter's flexibility is its mixin system. Mixins are essentially plugins that extend Porter's capabilities to interact with specific DevOps tools. When a bundle specifies a particular tool, Porter uses the corresponding mixin. Each mixin defines how to:

  1. Pull its own container image: This ensures that the specific version of the tool (e.g., Terraform v1.5, Helm v3.10) is encapsulated and isolated.
  2. Specify how to run the tool: The mixin contains the logic to execute commands against the tool within its container. For example, the terraform mixin knows how to run terraform init, terraform plan, and terraform apply.

The talk specifically mentioned several existing mixins:

  • Terraform: For infrastructure as code provisioning.
  • Helm: For Kubernetes package management.
  • Kubernetes: For direct interaction with Kubernetes APIs.
  • OpenTofu: An open-source alternative to Terraform.
  • Spin: For serverless WebAssembly applications (from Fermyon).

The extensibility of mixins means that if an organization uses a proprietary tool or a niche open-source project, they can easily create a custom mixin to integrate it into their Porter workflows. This involves defining the mixin's container image and the commands it should execute for various bundle actions.

Porter's bundles are designed to manage credentials securely. Instead of embedding sensitive information directly into the YAML, Porter allows bundles to pull credentials from external, secure sources. This includes:

  • Local machine environment variables.
  • Dedicated secrets management systems like HashiCorp Vault.
  • Cloud-specific key management services such as Azure Key Vault.
  • Local files or files mounted from the host machine.

This approach encourages a robust security posture by centralizing secret management and preventing sensitive data from being hardcoded or exposed in version control.

For organizations operating extensively within Kubernetes, Porter offers a Kubernetes Operator. This operator facilitates the deployment and management of Porter itself inside a Kubernetes cluster. The operator is responsible for:

  • Installing Porter: Deploying the necessary Porter components within the cluster.
  • Managing Porter Installations: Overseeing the lifecycle of Porter bundles deployed via the operator.
  • State Management: Utilizing MongoDB as a persistent state store. This database tracks the current state of all Porter installations within the cluster, allowing the operator to reconcile the actual state with the desired state defined in the bundles.
  • Automated Updates: When a new version of a Porter bundle is published, the operator can automatically detect and apply the update, ensuring that deployments remain current.

This operator-based approach enables seamless integration with GitOps workflows. By defining Porter bundles as Kubernetes custom resources and storing them in a Git repository, tools like Flux CD or Argo CD can be used to continuously synchronize the desired state from Git to the cluster. The Porter operator then interprets these custom resources and executes the corresponding bundle actions, creating a fully automated, declarative infrastructure and application management pipeline. The speaker specifically mentioned having an Argo CD demo, highlighting this integration capability.

Demo / Proof of Concept

▶ Watch: Porter in action: Microsoft marketplaces and F5 cost savings. (3:55)

While this lightning talk did not feature a live, step-by-step demonstration of Porter in action, Sarah Christoff effectively conveyed its proof of concept through a discussion of its real-world applications and integration capabilities. The mention of an existing Argo CD demo indicates that Porter is designed to integrate seamlessly with modern GitOps workflows, where the desired state of infrastructure and applications is declared in Git and continuously reconciled in the cluster.

The most compelling evidence of Porter's efficacy came from the specific use cases highlighted:

  1. Microsoft Marketplaces and PaaS Deployments: Porter is utilized within Microsoft for building and deploying Platform-as-a-Service (PaaS) offerings. This scenario exemplifies Porter's ability to standardize complex deployments. A Porter bundle can define a desired state for a service, including all its underlying infrastructure and application components. Users in a marketplace can then interact with this bundle, providing only the necessary variables (e.g., their cloud provider, Key Vault configuration, desired region) to deploy the service into their specific environment. Porter handles the intricate orchestration of tools like Terraform and Helm behind the scenes, ensuring consistent and compliant deployments across diverse user contexts. This acts as a powerful abstraction layer, simplifying the consumption of complex cloud services.
  1. F5's Cost Optimization Initiative: A practical example of Porter's direct business impact was shared from F5. Here, Porter is employed to manage testing resources. A common challenge in cloud environments is the accidental persistence of testing infrastructure after tests are completed, leading to unnecessary cloud expenditures. F5 uses Porter bundles to not only provision these testing resources but crucially, to ensure they are reliably torn down once testing is finished. This automated cleanup process, facilitated by Porter's explicit uninstall or custom teardown actions, has resulted in significant cost savings for F5, directly benefiting their Site Reliability Engineering (SRE) and cloud infrastructure teams. This demonstrates Porter's value beyond initial deployment, extending to the full lifecycle management and optimization of resources.

These examples, though not live demonstrations within the talk itself, serve as robust proof points for Porter's capabilities in delivering standardization, automation, and tangible business benefits in enterprise cloud-native environments.

Defensive Implications

▶ Watch: Join the Porter community: maintainers, contributors, and enthusiasts. (4:30)

While Porter is primarily an orchestration and automation tool, its design principles and operational capabilities have significant defensive implications for organizations managing cloud-native infrastructure and applications.

  1. Standardization and Immutability for Security Baselines: Porter bundles, by design, encapsulate all necessary tools and configurations into immutable container images based on the CNAB/OCI specification. This immutability drastically reduces configuration drift, a common source of security vulnerabilities. Defenders can establish and enforce security baselines within these bundles, ensuring that every deployment adheres to predefined security policies, hardening guides, and compliance requirements. Any deviation from the golden image would be immediately detectable.
  1. Enhanced Supply Chain Security: By bundling all deployment logic and dependencies into a single, versioned artifact, Porter contributes to a more secure software supply chain. If bundles are signed and verified, organizations can ensure that only trusted and unaltered deployment logic is executed. This helps mitigate risks associated with malicious code injection or unauthorized changes to deployment pipelines. The use of specific container images for mixins also ensures that the exact versions of tools are used, preventing unexpected behavior from tool updates.
  1. Secure Credential Management Best Practices: Porter's ability to pull credentials from secure, centralized sources like Vault or Azure Key Vault is a critical defensive feature. It discourages the insecure practice of embedding secrets directly into configuration files or version control. This significantly reduces the attack surface for credential theft and ensures that secrets are managed according to organizational security policies, including rotation and access control.
  1. Controlled Access and Reduced Blast Radius: By abstracting complex deployment processes behind simple porter install or porter uninstall commands, Porter enables a more granular approach to access control. Instead of granting developers broad access to raw infrastructure tools (e.g., direct kubectl access or Terraform state manipulation), organizations can grant permissions only to execute specific Porter bundles. This limits the "blast radius" of potential errors or malicious actions, as users interact with a predefined, validated workflow rather than having unconstrained access to underlying systems.
  1. Automated Resource Cleanup and Cost Optimization (Security by Design): The F5 example highlights how Porter can enforce automated resource teardown. From a defensive perspective, this is crucial for preventing resource sprawl and the creation of "ghost" resources. Unmanaged or forgotten resources (e.g., old VMs, unattached storage volumes, test environments) often become security liabilities, remaining unpatched, unmonitored, or containing sensitive data. Automated cleanup ensures that ephemeral resources are properly decommissioned, reducing the attack surface and potential for data exfiltration or unauthorized access.
  1. Declarative State Reconciliation for Continuous Compliance: The Kubernetes Operator with its MongoDB state store enables continuous reconciliation of the desired state. This means that if a security-critical configuration (e.g., network policy, security group rule) is tampered with manually, the operator can detect the deviation and automatically revert it to the desired, secure state defined in the bundle. This capability is invaluable for maintaining continuous compliance and enforcing security posture automatically.

In summary, Porter, by promoting immutability, centralized secret management, controlled execution, and automated state reconciliation, provides a robust framework that implicitly enhances the security posture of cloud-native environments.

Key Takeaways

  • Porter is a cloud-native, tool-agnostic CNCF sandbox project designed to orchestrate and manage disparate DevOps tools and their configurations.
  • It leverages Cloud-Native Application Bundles (CNAB), an open-source specification built on OCI, to package applications and their dependencies into immutable container images for consistent deployment.
  • Mixins are Porter's core extensibility mechanism, allowing it to integrate with virtually any DevOps tool (e.g., Terraform, Helm, Kubernetes, OpenTofu, Spin) by defining how to pull and execute the tool's container image.
  • The Kubernetes Operator facilitates cloud-native deployment of Porter within a Kubernetes cluster, managing installations, reconciling state via MongoDB, and integrating with GitOps tools like Flux and Argo CD.
  • Porter simplifies complex deployments for end-users, abstracts underlying complexity, and enforces best practices for credential management, leading to benefits like cost savings (F5) and standardized PaaS deployments (Microsoft).
  • The project actively seeks community contributions and maintainers, fostering an open-source ecosystem around cloud-native orchestration.

About the Speaker(s)

Sarah Christoff is the Lead Maintainer on Porter. Her role involves guiding the development and direction of the Porter project, which is a CNCF sandbox project aimed at solving the challenges of integrating and orchestrating diverse DevOps tools in cloud-native environments. Her expertise lies in understanding the pain points developers face with tool sprawl and crafting solutions that promote best practices through immutability and automation.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Porter addresses a critical pain point in cloud-native development: the chaotic integration of diverse DevOps tools. Its foundation on CNAB and an extensible mixin architecture offers a robust, immutable, and secure way to define, deploy, and manage complex systems. The talk, delivered by the project's lead maintainer, clearly articulates the technical solution, its practical impact on organizations like Microsoft and F5, and its significant defensive implications, making it a highly valuable contribution for anyone grappling with tool sprawl and supply chain security.

Heather Calloway (CISO) — STRONG ACCEPT

This lightning talk on Porter presents a compelling solution for orchestrating disparate DevOps tools, which has significant implications for enterprise security and governance. By leveraging Cloud-Native Application Bundles, Porter delivers immutability, reduces configuration drift, and streamlines deployments, addressing critical challenges in software supply chain security and operational consistency. The real-world examples from Microsoft and F5 clearly demonstrate its tangible business impact, from cost optimization to standardized PaaS deployments, making it a valuable tool for any organization struggling with cloud-native complexity and seeking to enhance their security posture…

→ Top-rated talks at KubeCon + CloudNativeCon Europe 2025

All talks from KubeCon + CloudNativeCon Europe 2025