Kubernetes-native operators and deployment stack for OpenStack Hosted Control Planes.
Project website: cobaltcore.dev · Documentation: c5c3.github.io/cobaltcore · Issues: github.com/c5c3/cobaltcore/issues
CobaltCore (C5C3) is a Kubernetes-native OpenStack distribution for operating Hosted Control Planes. The
project website at cobaltcore.dev introduces CobaltCore as a whole. This repository
holds its control-plane stack: the declarative infrastructure manifests, one operator per OpenStack service,
and the c5c3-operator, which orchestrates the service operators as children of a single ControlPlane
resource. The operators are written in Go with the Operator SDK, controller-runtime, and Kubebuilder.
The Keystone operator is the reference implementation. Its CRD layout, sub-reconciler chain, webhooks, finalizers, and instrumentation are the patterns every other service operator follows. How the pieces fit together, including the implemented management/target-cluster topology, is described in the architecture documentation.
| Operator | OpenStack service | Managed by the ControlPlane |
|---|---|---|
| Keystone | Identity (reference implementation) | yes |
| Horizon | Dashboard | yes |
| Glance | Image | yes |
| Placement | Placement | yes |
| Barbican | Key manager | yes |
| Neutron | Networking (ML2/OVN) | yes |
| OVN | The SDN layer Neutron programs | referenced from the Neutron block |
| Cinder | Block storage | yes |
| Nova | Compute control plane | not yet, tracked in #1019 |
The c5c3-operator reconciles the ControlPlane and projects each
enabled service block onto a child CR of the matching service operator.
The service images are built for every OpenStack release defined under releases/, currently
2025.2 and 2026.1.
The first three quick starts run on a local kind cluster and need Docker Desktop or Podman; the fourth needs a metal-stack cluster:
- Quick Start: from
git cloneto an authenticated Keystone API call. - Quick Start (Extended): UI tours, the local-build path, the production HelmRelease, E2E, and Tempest.
- Quick Start (ControlPlane): a full ControlPlane through the c5c3-operator.
- Quick Start (metal-stack): the ControlPlane on a metal-stack cluster, with servers on two KVM hypervisors.
The short path to the infrastructure stack:
git clone https://github.com/c5c3/cobaltcore.git
cd cobaltcore
make install-test-deps
export PATH="${HOME}/.local/bin:${PATH}"
make deploy-inframake deploy-infra creates the cobaltcore kind cluster and installs the infrastructure stack, including
Flux, cert-manager, OpenBao, the MariaDB and Memcached operators, External Secrets, and the Envoy Gateway.
make teardown-infra deletes the cluster again.
| Path | Contents |
|---|---|
operators/ |
One Go module per operator, each with its API types, controllers, webhooks, and Helm chart, plus the shared operator-library chart |
internal/common/ |
The shared library: common types, conditions, config rendering, Kubernetes helpers |
images/ |
Multi-stage builds for the OpenStack service images, Tempest, and the python-base / venv-builder layers |
releases/ |
Per-release source refs, upper constraints, extra packages, and Tempest excludes |
patches/ |
Patches applied to the upstream OpenStack sources at image build time |
deploy/ |
FluxCD HelmReleases and kind overlays for the infrastructure stack and the operators |
tests/ |
Chainsaw E2E, chaos, multi-cluster, operator-upgrade, and Tempest suites |
docs/ |
The VitePress sources of the documentation site |
hack/ |
Scripts behind the Makefile targets and the CI workflows |
The operators and internal/common/ form one Go workspace (go.work). make test runs the unit
tests, make test-integration the envtest suites, and make lint the linters.
The documentation is published at c5c3.github.io/cobaltcore from the
sources under docs/:
- Architecture: the implemented topology and the core components.
- Guides: day-2 operations, key rotation, multi-tenant deployment, identity backends, storage backends, and target clusters.
- Reference: CRDs, reconcilers, events, metrics, and the infrastructure, CI/CD, and testing internals.
- Future: idea sketches for where the operators could go next.
The contributing section covers onboarding a new operator or OpenStack release, dependency management, the guide conventions, and the Nix development environment. Documentation prose follows STYLE_GUIDE.md.
Outstanding work is tracked in GitHub Issues. The issue tracker is the single source of truth for planned features, production-hardening gaps, and release milestones.
Found a vulnerability? Please report it privately through GitHub Private Vulnerability Reporting rather than opening a public issue. See SECURITY.md for the reporting process, scope, and response expectations.
CobaltCore is licensed under the Apache License 2.0. Source files carry SPDX license headers.