Project Lightning Talk: A Curator’s Guide to the CNCF Landsca... Katherine Druckman and Lori Lorusso
About this talk
This talk provides an overview of the Cloud Native Computing Foundation (CNCF) landscape, helping attendees navigate the overwhelming ecosystem of cloud-native technologies. The speaker, Lori, discusses the various project maturity levels within the CNCF, including sandbox, incubating, and graduated projects, explaining their significance in terms of sustainability and community involvement. The session introduces tools like askcncf.io, KubeMonitor, and filters for exploring the CNCF landscape efficiently. The speaker emphasizes the importance of community engagement and contributing to projects, encouraging attendees to find opportunities that align with their interests and expertise. Overall, the presentation aims to empower attendees with the knowledge to make informed decisions about the tools they use in cloud-native environments.
Full transcript
Welcome fellow software artists. So today Lori and I except actually Vincent Van Gogh and I I am um Rembrandt today. Two very famous and well known Oh, sorry. We got to fix our uh Did you do mirror or did you do? >> do anything. It didn't give me an op >> Oh, okay. So There we See, there we go. Okay, go back to the go back a
slide. There we go. Okay, now we're now we're cooking. Um with fire. Do you see the similarities, Van Gogh? >> See, see, now it starts to make sense, right? The outfits. Okay. The things we do for open source, guys. The things we do. >> Yes. So we are your tour guides through the CNCF landscape, which is uh as I said earlier, as lovely as a Van Gogh
landscape and just as confusing. Uh so we're going to give you a little bit of a map and survival guide uh because the ecosystem can feel a bit overwhelming. Show of hands, how many of you are here for your first KubeCon? Yeah. >> Nice. >> Awesome. So we're going to talk we're going to talk to you about the CNCF landscape. And we're going to talk to you
hopefully a little bit about what else you can do at KubeCon, so let let let's keep it going. Uh this is me. You can find me that QR code will work. Uh please find me. Actually, I love answering questions and helping people figure out their way through this really rather confusing world uh that is software. All right. So my name is Lori. I am the director of
outreach for the Rust Foundation. I'm also a CNCF ambassador, so really stoked that a lot of you are having your first uh KubeCon. How many of you were here for Catherine's presentation this morning? Not too many. >> Okay. So it'll be similar yet different uh but thanks for coming back and there'll be more talks. Also, I always love to put a picture of my kid with me
on there. That was Halloween and she did her own makeup and it was frightening. Moving on. Moving along. So, here's a a quick a quick plan for our gallery tour. We're going to tell you a little bit about the CNCF. We're going to get into the landscape. Yeah, and then yeah, let's just keep moving. Who cares about this slide? Okay, this is the good stuff. So, this
is super exciting. You could like take a nap during our presentation if you'd like after you ate lunch because there's this new tool called askcncf.io that is using Dosu and it's basically anything you want to know, it will tell you. So, you can type in whatever you got going on, any kind of questions you have. If you have questions after the talk and we're not around and
you want to learn some more, go ahead and go to and yeah, George worked really hard on it. I don't know if you guys know George Castro or not. Go to the project pavilion, meet him, meet everybody there. Um, you know Robert but he's just I don't know where he Oh, there he is. Um, so yeah, anyways, that is something I wanted to plug. So, if you
don't want to pay attention, uh, you don't have to but I hope that you do. So, what is the Cloud Native Computing Foundation and Catherine, I love you but we got to work on your technical skills. so the mission of the Cloud Native Cloud Native Computing Foundation is to make computing ubiquitous which is just like a funny word of just saying everybody should be on it. There
are 209 projects at the CNCF which is huge. There are almost 300,000 contributors. You've got 765 members. How many of you know if your company is a member of the CNCF? Does anybody? Do you know that depending on your membership level you get like access to free training? You get credits so that you can become Kubernetes certified, CKA certified, all kinds of certifications. There's all kinds of
levels. Um so, make sure you check out what you have so that you don't uh miss out on an opportunity to get free training based on your membership level. And the crazy thing is there's 135,000 plus Cloud Native Community members. And here, I think at KubeCon this week there'll be about 13,000 of us all hanging out in the hallways doing all kinds of fun stuff. Okay, Linux
Foundation. So, uh I don't know if you know this, but the Linux Foundation is the main foundation that houses the uh CNCF. So, it's the home of everything. It's uh it's the neutral home. It's got governance. It's got structures. It's got trust, stewardship, and sustainability. But, I think the thing that you really should be interested in is there are 900 open source projects under the Linux Foundation,
3 million developers, 777,000 plus developers contributing code, 51 million lines of code, blah blah blah. All things to say is you are amongst the best people when you're at the Linux Foundation events because you're amongst your people who are all in on the code. But, what you don't know or maybe don't know if you're new to the CNCF is that there are three levels of projects. You
have sandbox, incubating, and graduated. And sometimes you get also archived. So, what does archive mean? It means the project didn't survive. It does not to say that it was a bad project, but what it means is maybe something else was built on top of it and so that project went away. Maybe the maintainers decided that they didn't want it anymore and they stopped using it or it
just was obsolete because something else came along. What you'll notice is that the most of the product projects are in the green. And the green is sandbox. So, if you're not currently contributing to a CNCF project, those are good ones cuz they're new, they're exciting, they're on the edge, they're trying to get to that level, which is the next level, which is incubation, and then um finally
graduated. Okay, so we talked a little bit about sandbox incubating and graduated What does that mean? Uh this is this refers to maturity levels, right? Within the CNCF. When you contribute a project to the CNCF, it starts as a sandbox project, right? What is a sandbox project? Uh it really just starts as kind of an idea, right? You don't necessarily have a community built around it. You
don't necessarily have a lot of contribution. Um but it's it's it's an early stage project. They're still proving themselves to communities and um recruiting contributors. As a project then gains a little bit more momentum and gains more adoption, more contributors, that sort of thing, it can then go up to the next level, which is incubating. it has a little bit of evidence of sustainability, probably, but has
not yet met the requirements for graduation. Now, officially, if you go to the website, it's going to tell you that graduated and incubating projects are considered stable and are used successfully in production environments. So, I don't want you to think that if a project isn't graduated, that it is not suitable for production, because that is not necessarily the case. But, to become graduated, a project needs to
show adoption. It needs to show committers from at least two organizations, for example. It needs documented governance and structure. Uh neutrality is a big one, right? And it has to meet the Linux Foundation Core Infrastructure Initiative Best Practices requirements. So, in other words, it's, you know, it's not a popularity contest. And the important thing to remember here is that it is a marathon, not a sprint. Yeah,
it's a marathon to get in and it's a marathon to get out, but it's totally worth it because of all the innovation that happens from within. So, now we're just going to go ahead and jump into the CNCF landscape. So, I know this looks like a lot and it is a lot, but we're going to show you how to get around it a little bit. So, this
Do you want to switch to mirroring so it's easier? >> I don't know how to do that. Here, let Oh. It's about battery. Never mind, I can't see it. >> Okay, cool. Oh, wait, here it is. Screen mirroring. Oh, for this. Okay, never mind. Uh, there we go. Okay. So, if you go up to the top and then you Okay, so what >> Here, I'll do it.
Anyways, are we >> to get into full Okay. I love you, Katherine. I really do. >> It needed to be on mirroring, not extended. It didn't ask me. >> I can't see with this >> anything. There we go. There's the landscape. All right, so that's the landscape. So, >> to let you talk. I'll I'll navigate. They look like a bunch of logos, but they're actually live. And
when you click on one of them, so let's click on one. I I love Helm. Helm. >> Shout out to Helm. I always go to. It gives you all of the stats of the project that CNCF is currently tracking, which is really cool. It tells you when it started, what level it's at, how many contributors it has, all of these great things that you need to be
aware of when you're looking at whether you're going to bring this into your stack or not. And one of the tools that is super cool and is with every CNCF project um that is in the landscape is KubeMonitor. KubeMonitor gives you all the deets on the insides and outs of what your project is and gives you a health score so you can determine if this is something
that you want to, again, bring into your stack or something maybe that you want to contribute to. Anything in green is a check that's worked. Uh, anything in red needs help like we need to So, these are things that the project needs be aware of and needs to update so that it can have all green checks. Just because it doesn't have a 100 doesn't mean it's not
a good project. It just lets you know where there are areas for improvement or areas that you can do things with. And if you see there is a red X right next to contributing. So, if Helm is a project that you use and you want to, you know, work with the with the old guys, you know, be a be a fresh set of eyes on a on
a project that a lot of people use already, it's an opportunity for you to contribute there. Yes. So, the big takeaway here is just because you see red X's does not mean it's a deal breaker, right? It's an opportunity. Uh especially look, you know, documentation has a slightly lower score. That's a great opportunity to get involved in a project and contribute. So, let's go back to the
landscape. Uh let's look at filters, right? Yes. So, when you're looking at this right off the bat, you're like, "Okay, this is a lot." But, what's really cool is they built in a filter tool. This didn't used to exist. And what it does, it helps you filter. So, we can go ahead and look at all of the graduated projects. Oops, graduated. Or incubating, whichever. Okay? Graduated. Graduated.
Um and then let's just go ahead and hit apply. Let's just see like of the 209 projects at the CNCF, these are all the projects that have graduated. Do those projects look familiar to you? Right? Because you're probably adopted them and using them in your stack. You can click on, again, any of those projects and it'll give you the same sort of report like Crossplane just recently
graduated. You can scroll down. You can go to their CLOMonitor. Go go Oh, and they're at an 89. >> score. But, nobody's perfect. And that's okay. There is no rule about what score you need to look at. It's really about doing due diligence. It's really about evaluating the projects and various metrics. Another tool that's really helpful when you are in the landscape is the download tool. Oh,
fabulous. Right here. >> So, right there in the corner, you can download it and it gives you a snapshot in an Excel spreadsheet. >> one right there. projects.csv And it gives you uh when they had their last security audit, like how many of you are in interested in security? Okay. More people need to raise their hands on that one. >> of you are forced to care about
How many of you feel victimized by your security teams? No, just kidding. >> is a really good like snapshot of you can learn when they had their last security audit. So, if your boss is like up your you know what saying, we are only going to use tools that have had like successful security audits past a certain point, you can download that and it'll be in an
easy spreadsheet. You can go ahead and um you know, pick a date range and go from there. Okay. Let's go back to our handy-dandy slideshow. And we're at our last minute. So, there we go. This is KubeMonitor. Get familiar. Make friends. Very helpful. It's not black and white. Evaluate projects. Do your due diligence. Look at project health. Look at contributor diversity. Look at all the things. What?
Go back. Oh, go back. So, I think like what we're trying to say is that yes, the CNCF landscape when you look at it on the whole is very much wow, this is extremely overwhelming and now these ladies just gave us even more overwhelming information to look at cuz there's so much more information that's out there and like why do we need to have all this information?
And it's what Katherine said, you need to do your due diligence. You need to make sure like what you're doing and what you're using, you can go back to your higher-ups and say, this stack is solid and this is why. Or we should contribute to this project because this project is essential for us to get X, Y, and Z done and right now we're only getting X
and Y. So, maybe we can donate some developer hours so that we can push Z to the end. So, there's all kinds of opportunities and hidden information in that clue monitor report that you can use to justify what tools you want to bring into your stack. And the great thing is, too, is that you have all of the information, the GitHub repo, everything there so you can
just click, click, click away and find a contributor or maintainer that you can ask questions to and make sure you're getting the relevant information that you need for your project. How many of you are working on projects right now at the Okay. So, we got a lot of end users in here. How many want to? >> Yeah, how many want to be contributors? Yes. Okay, well, today
is the day. Now you have a way of kind of looking at all of the projects. You can filter out by what is your interest. If it's not security, is it is it observability? Is Find the Find the gap in your stack and and and uh find your solution in the landscape. Um I think we have like 1 minute. Yeah, we have less than a >> So,
yeah. Love a Helm. Little shout-out to Wasm Edge. But finally, let's talk about the community. Th- This week, you're going to find lots of opportunities to meet people, talk to them. Find us on LinkedIn. We'll put the slides up. Um Yeah. Just Make friends. Make friends. Kiss your maintainers. The I mean, hug them. Whatever. I don't know what's happening here, but the hallway track is really important.
If this is your first KubeCon or maybe your first conference and you don't know what the hallway track is, literally means having conversations in the hallway. So, don't be afraid to like talk to your neighbor, you know, when you're at lunch, sit with people you don't know, and just start having discussions about what's interesting to you because that's the way that open source works, right? >> Yes.
And if you want to find one of us uh both of us later, this is where we'll be and we can uh happily ask answer any questions you might have about the CNCF All right. Thanks, y'all.
More from this event
See all 436 talks →
Best of KubeCon + CloudNativeCon Amsterdam 2026
2:17
The Quiet Work of Forever: Sustaining Open Source Communities - O. Hope Amaechi-Okorie, JSON Schema
26:24
Evolving KServe: The Unified Model Inference Platform for Both Predictive and... F. Spolti & J. Lee
32:40
Preventing S3 Cost Storms: Applying Cortex’s Efficiency Lessons to I/O-Heav... A. Fishman-Lichterman
5:32