The Multi-Tool Problem Across Public, Private, and Sovereign Clouds

▶ Watch (0:02)

SAP runs workloads on public clouds in multiple regions, private clouds, and sovereign clouds. Each deployment historically used a different mix of tools: GitHub Actions here, Jenkins pipelines there, Terraform in some places, and click-ops for DNS configuration in others. No two environments agreed on an approach. Ott called the result “gigantic complexity that each and every engineering team has to cope with.” The goal became reducing many methodologies down to one, covering as many pieces of the stack as possible.

Kubernetes Resource Model as a Single Control Plane

▶ Watch (4:24)

Techritz framed the fix as straightforward: bring every resource, databases, DNS, secrets, and proprietary internal APIs, into the Kubernetes resource model. Crossplane handles cloud resources at AWS and GCP and can wrap internal APIs through custom providers. External Secrets Operator syncs secrets to runtime clusters. Flux or Argo CD reconcile desired state from Git. Teams that adopted this reported that managing resources “actually feels like real automation” compared to the shell scripts they had written before.

Open Control Plane: Tools as a Self-Service API

▶ Watch (7:35)

Installing Flux via CLI, then Crossplane via Helm, then upgrading External Secrets Operator separately, is impractical at scale across dozens of environments. Open Control Plane solves this by delivering all of those tools pre-installed and pre-configured. Engineers, including front-end developers and managers with no Kubernetes background, request a control plane and receive a kubeconfig back. The project runs on Gardener across all major cloud providers and supports local environments via kind, including Windows PCs and MacBooks.

Building People and Culture Alongside the Technology

▶ Watch (10:08)

Technology alone did not move the organization. The team ran monthly informal sessions with engineers, presenting relatable use cases with no prior knowledge required. They wrote beginner-friendly enablement guides, ran virtual and on-site workshops, and held hackathons to spread a contribution mindset. Working students produced a video series from the contribution material. Reusable coding samples and pipelines were shared so teams would not rebuild the same pieces independently. The community now exceeds 500 internal stakeholders and nearly 100 contributors.

Adoption Results and Measured Outcomes

▶ Watch (14:00)

After one and a half years of active rollout, teams using Open Control Plane reported cloud landscape rollout times cut by a factor of 10 and significantly increased operational confidence. Ott noted he could not share exact numbers, but adoption charts from the past 18 months show a clear upward trend inside SAP’s application engineering teams. The project has been donated to the NeoNephos Foundation, part of Linux Foundation Europe, and holds bi-weekly community calls every second Wednesday open to contributors with zero prior experience.

Notable Quotes

we still have people in our organization that might have limited to zero Kubernetes experience and of course we haven’t had solved this challenge of all those different internal APIs and proprietary services where no Kubernetes operator or crossplane provider exists Johannes Ott · ▶ 09:36

they’re already coming back to us sharing how this has increased their cloud landscape roll out time by times 10 or decreased it by times 10 and also significantly increased their roll out and operational confidence Johannes Ott · ▶ 14:10

never ever build a platform without its users Johannes Ott · ▶ 15:46

Key Takeaways

  • Open Control Plane delivers Crossplane, Flux, and External Secrets Operator as a single kubeconfig via self-service API.
  • SAP teams cut cloud landscape rollout time by a factor of 10 after adopting the stack.
  • Monthly informal sessions, hackathons, and beginner-friendly guides were as important as the technology itself.

About the Speaker(s)

Johannes Ott worked as an iOS developer before joining SAP as a full-stack engineer on cloud solutions. He repeatedly saw teams spending significant time writing custom orchestration tooling, which motivated him and colleagues to build a CNCF-based alternative and grow a community around it inside and outside the organization.

Maximilian Techritz is a Software Engineer and Developer Advocate at the Open Managed Control Plane project in the NeoNephos Foundation. His work focuses on multi-cloud platform design that goes beyond basic container orchestration.