KubeCon + CloudNativeCon Europe

Keynote: Cloud Native in Europe: Regulation, Sovereignty, and the Future of Open Collab... Jan Melen

4:08 · 23 Mar 2026 – 26 Mar 2026 · YouTube

About this talk

This talk explores the implications of digital sovereignty on the open source ecosystem, specifically in the context of recent European legislation like the Cyber Resilience Act. The speaker discusses how sovereignty has emerged as a critical political objective, with the potential to fragment the global collaboration that has contributed to the success of technologies like Linux and cloud-native infrastructure. While supporting the notion of sovereign deployments that comply with local laws and security needs, the speaker emphasizes the importance of maintaining a shared global code commons. As organizations navigate a changing regulatory landscape, they must shift from merely using open source to actively supporting its health and sustainability. This collective effort, led by contributions from foundations and individual stakeholders, is essential to prevent fragmentation and ensure the continued growth of the open source ecosystem.

Full transcript

What if the biggest threat to open source today is not the technology, but how we interpret digital sovereignty? Across the world and in Europe, sovereignty has become the central political goal. We see it in legislations like Cyber Resilience Act, certification discussions, and in strategic initiatives like EU sovereign tech fund. These efforts are important. They aim to improve the security, accountability, and trust in digital infrastructure. But, there

is a risk that sovereignty is interpreted in in a way that we we actually risk the whole ecosystem and fragmenting it. And the very ecosystem that made sort of Linux and cloud native successful. Cloud native exists because of global open source collaboration model. Thousands of contributors from every region building shared infrastructure together. Infrastructure that supports incredible diversity of use cases. This is the promise that promise on

which we have built our success. If the sovereignty leads to fragmentation, we risk undermining the trillions of dollars the of value that open source has already brought globally. But there is a better way to think about so sovereignty. We should separate code sovereignty from the deployment sovereignty. The code itself remains global commons, shared, open, collaboratively developed. At the same time, deployments can be sovereign. Region and nation

state should absolutely be able to run their own infrastructure that complies with their s- laws, security requirements, and policies. So, in other words, sovereign deployments. The innovation layer remains global. The operational layer adapts to regional needs. As cloud-native adoption grows across Europe, the regulatory landscape is also changing how organizations engage with open source. Across Europe, uh teams are looking more carefully about the software supply chains, understanding

the dependencies, vulnerability management, and how projects are maintained over time. Legislation like CRA introduces expectations around the security processes. The timeline for complying with the CRA is approaching quickly. This means organizations need to move from simply consuming open source to actively supporting the health and sustainability of the projects. This is where open source foundations and communities become critical. Organizations like CNCF can help to provide governance structures,

coordinate the security practices, support compliance efforts, and create project layer for maintainers. But foundations are not just institutions. They are all of us, contributors, maintainers, companies, users, working together with the ecosystem, and keeping it healthy. Companies who benefit the most from the open source need to need to step up and support the projects they depend on. So, this is how sovereignty becomes a defining policy goal. We

need to be careful not to fragment the open source ecosystem that powers the uh modern infrastructure. Because of that, the goal should not be sovereign code bases. It should be uh something better. Digital sovereignty should not mean sovereign code bases. It should mean sovereign deployments built on shared code commons. And found foundations, meaning all of us here, have a critical role to play in supporting the projects

as they adapt to changing regulatory and economic landscape. While keeping the technology open, global, and compliant for everyone to build together. And with that, thank you. Have a nice KubeCon.