Designing Scalable CI/CD Pipelines for Regulated Enterprises Using Kubernetes and GitOps

Authors

  • Shashi Kumar Munugoti

DOI:

https://doi.org/10.22399/ijcesen.4619

Keywords:

Continuous Integration And Delivery, Kubernetes Orchestration, GitOps Methodology, Zero-Trust Security Architecture, Regulatory Compliance Automation, DevSecOps Pipeline Design

Abstract

Legacy software delivery practices pose difficulties in regulated industries such as financial services, healthcare, and government, where organizations must comply with governance requirements throughout the software delivery lifecycle while protecting sensitive information. Most common continuous integration and continuous delivery CI/CD pipelines lack auditability and traceability and include manual processes, which are a bottleneck in the release process to production systems. Environment inconsistencies lead to deployment failures and configuration drift across infrastructure tiers. The article presents an architectural framework combining Kubernetes orchestration with GitOps methodology for regulated enterprise environments. Declarative configuration management establishes Git repositories as authoritative sources for infrastructure state. Pull-based deployment models eliminate direct pipeline access to production clusters. Zero-trust security principles ensure continuous verification of access requests regardless of network origin. Policy-driven automation embeds compliance validation throughout the build and deployment stages. Admission controllers enforce governance rules at deployment time without manual intervention. Comprehensive observability mechanisms provide audit capabilities satisfying regulatory examination requirements. The framework enables organizations to accelerate deployment frequency while preserving rigorous change management controls. Separation of duties occurs naturally through pull request approval workflows. The architectural patterns presented address fundamental gaps in traditional CI/CD implementations for highly regulated operational contexts.

References

[1] Ruth G. Lennon, "DevOps Best Practices in Highly Regulated Industry," ResearchGate. [Online]. Available: https://www.researchgate.net/profile/Ruth-Lennon-2/publication/362452940_DevOps_Best_Practices_in_Highly_Regulated_Industry/links/64c80998b1baa70467f9f027/DevOps-Best-Practices-in-Highly-Regulated-Industry.pdf

[2] Yehia Elkhatib, "An Evaluation of Service Mesh Frameworks for Edge Systems," ACM, 2023. [Online]. Available: https://dl.acm.org/doi/pdf/10.1145/3578354.3592867

[3] Roshan N. Rajapakse et al., "Challenges and solutions when adopting DevSecOps: A systematic review," arXiv, 2021. [Online]. Available: https://arxiv.org/pdf/2103.08266

[4] Marcela Ruiz et al., "Why don’t we trace? A study on the barriers to software traceability in practice," Requirements Engineering, 2023. [Online]. Available: https://link.springer.com/content/pdf/10.1007/s00766-023-00408-9.pdf

[5] BRENDAN BURNS et al., "Borg, Omega, and Kubernetes," System Evolution, 2016. [Online]. Available: https://spawn-queue.acm.org/doi/pdf/10.1145/2898442.2898444

[6] Dr. Ramesh Babu Chellappan, "The Future of DevOps: Intelligent, Secure and Scalable Software Delivery," ResearchGate. [Online]. Available: https://www.researchgate.net/profile/Ramesh-Babu-Chellappan/publication/387127506

[7] MOJTABA SHAHIN et al., "Continuous Integration, Delivery and Deployment: A Systematic Review on Approaches, Tools, Challenges and Practices," IEEE Access, 2017. [Online]. Available: https://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=7884954

[8] Ramakrishna Pittu, "From Monoliths to Micro services: A Comprehensive Framework for Enterprise Cloud-Native Transformation," Sarcouncil Journal of Multidisciplinary, 2025. [Online]. Available: https://sarcouncil.com/download-article/SJMD-156-2025-436-441.pdf

[9] Yuanhang He et al., "A Survey on Zero Trust Architecture: Challenges and Future Trends," Wiley, 2022. [Online]. Available: https://onlinelibrary.wiley.com/doi/pdf/10.1155/2022/6476274

[10] Pooyan Jamshidi et al., "Microservices: The Journey So Far and Challenges Ahead," IEEE Software, 2018. [Online]. Available: https://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=8354433

Downloads

Published

2025-12-30

How to Cite

Shashi Kumar Munugoti. (2025). Designing Scalable CI/CD Pipelines for Regulated Enterprises Using Kubernetes and GitOps. International Journal of Computational and Experimental Science and Engineering, 12(1). https://doi.org/10.22399/ijcesen.4619

Issue

Section

Research Article