werf is an open-source command-line tool for CI/CD to Kubernetes. It builds container images from Dockerfiles, deploys applications with Helm charts, tracks the rollout of resources, distributes release artifacts and cleans up the container registry. It uses Git as the single source of truth ("giterminism"), caches builds automatically, tags images by content and rebuilds only what changed.
werf is released under the Apache 2.0 licence and is a CNCF Sandbox project. It was originally created by Flant, a Kubernetes services company; the sources reviewed give conflicting information on where Flant is based, so no country is stated here. The tool is distributed as a binary that you run on your own build infrastructure, so the code, pipelines and registry contents stay where you operate them. As there is no vendor-hosted service, the jurisdiction question mainly concerns the CI platform, registry and cluster you combine it with.