Keynote: Cloud Native in Europe: Regulation, Sovereignty, and the Future of Open... J. Melen (ASL)
About this talk
This talk discusses the pressing issue of digital sovereignty and its implications for the open source ecosystem. The speaker highlights how legislation like the Cyber Resilience Act and initiatives such as the EU Sovereign Tech Fund aim to enhance security and accountability in digital infrastructure. However, there is a concern that misinterpretation of sovereignty could fragment the collaborative global model that has driven the success of cloud-native technologies. The speaker proposes a distinction between code sovereignty, which should remain a global common, and deployment sovereignty, which can be tailored to meet local laws and requirements. As organizations across Europe adjust to a changing regulatory landscape, they are urged to actively support the sustainability of open source projects. The speaker emphasizes the importance of community engagement and governance through open source foundations in maintaining a healthy ecosystem that benefits everyone.
Full transcript
What if the biggest threat to open source today is not the technology, but how we interpret digital sovereignty? >> [snorts] >> Across the world and in Europe, sovereignty has become the central political goal. We see it in legislations like Cyber Resilience Act, certification discussions, and industrial initiatives like EU Sovereign Tech Fund. These efforts are important. They aim to improve the security, accountability, and trust in digital infrastructure.
But, there is a risk that sovereignty is interpreted in in a way that we we actually risk the whole ecosystem and fragmenting it. And the very ecosystem that made sort of Linux and cloud native successful. >> [clears throat] >> Cloud native exists because of global open source collaboration model. Thousands of contributors from every region building shared infrastructure together. Infrastructure that supports incredible diversity of use cases. This
is the promise that promise on which we have built our success. If the sovereignty leads to fragmentation, we risk undermining the trillions of dollars of value that open source has already brought globally. But, there is a better way to think about so- sovereignty. We should separate code sovereignty from the deployment sovereignty. The code itself remains global commons, shared, open, collaboratively developed. At the same time, deployments can
be sovereign. Region and nation state should absolutely be able to run their own infrastructure that complies with their s- laws, security requirements, and policies. So, in other words, sovereign deployments. The innovation layer remains global. The operational layer adapts to regional needs. As cloud-native adoption grows across Europe, regulatory landscape is also changing how organizations engage with open source. Across Europe, uh teams are looking more carefully about the
software supply chains, understanding the dependencies, vulnerability management, and how projects are maintained over time. Legislation like CRA introduces expectations around the security processes. >> The timeline for complying with the CRA is approaching quickly. This means organizations need to move from simply consuming open source to actively supporting the health and sustainability of the projects. This is where open source foundations and communities become critical. Organizations like CNCF can
help to provide governance structures, coordinate the security practices, support compliance efforts, and create project layer for maintainers. But foundations are not just institutions. They are all of us, contributors, maintainers, companies, users working together with the ecosystem, and keeping it healthy. Companies who benefit the most from the open source need to need to step up and support the projects they depend on. So, digital sovereignty a defining policy
goal, we need to be careful not to fragment the open source ecosystem that powers the uh modern infrastructure. Because of that, the goal should not be sovereign code bases. It should be uh something better. Digital sovereignty should not mean sovereign code bases, it should mean sovereign deployments built on shared code commons. And found foundations, meaning all of us here, have a critical role to play in supporting
the projects as they adapt to changing regulatory and economic landscape. While keeping the technology open, global, and compliant for everyone to build together. And with that, thank you. Have a nice KubeCon. >> [applause]
More from this event
See all 436 talks →
Best of KubeCon + CloudNativeCon Amsterdam 2026
2:17
The Quiet Work of Forever: Sustaining Open Source Communities - O. Hope Amaechi-Okorie, JSON Schema
26:24
Evolving KServe: The Unified Model Inference Platform for Both Predictive and... F. Spolti & J. Lee
32:40
Preventing S3 Cost Storms: Applying Cortex’s Efficiency Lessons to I/O-Heav... A. Fishman-Lichterman
5:32