CIXpress Conductor¶
CIXpress Conductor is an experimental, pre-release implementation and is not a turnkey public installation. This page describes the implemented conductor service rather than a supported CI/CD product offering.
Purpose¶
Conductor is a Flask API that renders ordered Kubernetes Jobs from templates and configuration. A Redis-compatible backend (Redis or Valkey) carries execution state and events. Server-Sent Events (SSE) provides live updates to API clients.
flowchart LR
Client[Trigger and API clients] --> App[Conductor application]
Config[Authoritative configuration YAML] --> App
App --> Jobs[Kubernetes Jobs]
Jobs --> Monitor[Monitor pod]
Monitor --> Backend[Redis-compatible backend]
Backend --> App
App --> SSE[SSE clients]
App -. watchdog supervises .-> Monitor
Current Implementation¶
The experimental implementation includes:
- Template and configuration API endpoints.
- Generic and specialized trigger handlers.
- Ordered Kubernetes Job orchestration.
- A monitor that observes and reconciles Jobs, with limited watchdog recovery by the application.
- Runtime pipeline and log APIs.
- SSE for live execution updates.
- Helm deployment assets.
- Deployment-specific external job manifests and images used by reviewed specialized workflows.
Boundaries And Security¶
Flask has no user authentication or per-route authorization; the deployment proxy and ingress are the trust boundary. Default POST trigger bypasses are unauthenticated compatibility exceptions. Webhook validation occurs only when both a configured secret and the relevant request header are present.
The Kubernetes Role is broad. External manifests and images can create privileged execution paths, so they are deployment-owned inputs that must be reviewed and controlled. Templates and configuration may include organization-specific defaults and sensitive values; configuration Git history and DEBUG logs can expose sensitive data.
/app/backup/conductor-configuration.yaml is the authoritative configuration YAML. When configuration Git is enabled, its checkout is the startup authority; publication of configuration API writes is best effort, so an unpublished write can be lost when the application is replaced.
Not Claimed¶
This experimental overview does not claim a VM bundle, high availability, public artifacts, a self-hosted runner or executor matrix, Bitbucket integration, Slack or email notifications, scanning, canary or blue-green deployment, supported untrusted-Internet exposure, or supported production use.
Evaluation Status¶
Canonical implementation docs are maintained with the project; public source links appear when available. Evaluate Conductor only as experimental software in a controlled environment, after reviewing its templates, manifests, permissions, authentication boundaries, and external job images.