KubeCon + CloudNativeCon Europe

Project Lightning Talk: A Curator’s Guide to the CNCF Landscape - Katherine Druckman

15:07 · 23 Mar 2026 – 26 Mar 2026 · YouTube

About this talk

In this session, Katherine Druckman, head of community and partnership engagement at JetBrains, explores the Cloud Native Computing Foundation (CNCF) landscape, aiming to provide guidance for newcomers attending KubeCon. She highlights the CNCF's mission to foster cloud native computing, emphasizing the significant growth of its projects and community involvement. Katherine explains the maturity levels of CNCF projects, which include sandbox, incubating, and graduated stages, and underlines the importance of project sustainability and governance. She offers practical advice on how to navigate this vast ecosystem, evaluate project health, and find opportunities for contribution, while also discussing tools such as Clone Monitor that help assess project viability. The session concludes with encouragement for attendees to engage with the community and contribute to open source initiatives.

Full transcript

So, hi. Welcome. Fellow uh software artists. Uh today I will be your tour guide through the CNCF landscape, which is um just as lovely as a Van Gogh landscape and probably just as confusing. So, so think of it as a we're we're going to do a little map and also a little bit of a survival guide. Um the CNCF ecosystem can feel a bit overwhelming, right? Especially

if you're new to it. I Show of hands, who is who is here for their first KubeCon? Ah, that's what I was expecting. This happens So, I've done this a few times now and every time and that is the most exciting thing about getting to do this talk is to welcome the newcomers. So, we're going to talk a little bit about also maybe how to navigate KubeCon.

So, um so yes, we're going to talk about a little practical way to explore the landscape, evaluate projects, and maybe maybe even find a path to contribute. I am Katherine Druckman. I am head of community and partnership engagement at JetBrains. I am also uh an open source advocate. I am a community nerd and a recovering engineer. Um some people Usually that gets a bigger laugh, but I

feel like that usually resonates with people. They know what I mean when I'm like, "Yeah, I'm kind of recovering from the software engineering days." Yeah, these days I'm really you know, excited about open source and AI and how all that intersects as I'm sure you are as well, but uh I I also really enjoy helping people find their way through software landscapes like this one. So, here's

our little quick plan. We're going to We're going to talk talk a little bit about the CNCF then walk through the landscape. Um so, you're all here. So, I'm guessing most of you know the CNCF at at least a high level. Uh its mission is to make cloud native computing ubiquitous. Uh but the numbers are still worth taking a pause on, right? We've got over 200 projects.

That's pretty wild. Hundreds of thousands of contributors, hundreds of member organizations, and a very large community. So, this isn't just like a random collection of tools. This is a thriving ecosystem. How many of you are contributors already to CNCF projects? Fantastic. If you are not yet, I hope maybe after today you will be excited to to dip your toe into that. So, it's also useful, I think,

to understand that the CNCF falls under the Linux Foundation. And that matters because this gives projects a neutral home, um and governance structures, and hopefully ensures long-term sustainability and support for these projects. So, when organizations adopt CNCF projects, they're not just looking at code. We're looking at stewardship, and we're looking at sustainability, and the ability of a project to survive beyond any single maintainer or vendor. Uh

so, this is this is the project count over time, which is a little bit wild, right? Uh you know, you especially in the last, oh, I don't know, 5 years, it's really kind of taken off. This is what happens, I think, when you give open source engineers a little too much caffeine. Uh we get excited about new ideas and try to get our sandbox projects in. I'll

talk a little bit about what that means in just a second. Uh but over time, you know, the number has steadily increased, and that, I think, helps explain why the landscape feels so huge and overwhelming, and you don't necessarily know where to start. Uh but the big takeaway isn't just that it's growing, um it's that it keeps kind of changing a little bit. So, that's why we

need to be able to filter and evaluate and revisit decisions as this ecosystem evolves. But before we get to the landscape itself, I want to talk a little bit about maturity levels. So, each CNCF project has a maturity level. The three main ones, sandbox, incubating, and graduated. There are also sometimes projects do get archived if they don't take off or if they reach end of life. That's

an important process as well, but a project usually starts as an idea, which is the the spirit of the sandbox project. It's where experimentation begins. Projects are early, they're being explored, and they're still kind of proving themselves. But then as a project gains momentum, more contributors, more adoption, more community energy around it, it can move to incubating. At that point it probably has some evidence of sustainability.

but it hasn't yet met the bar for graduation. But officially speaking, if you go to the website, it will tell you graduated and incubating projects are considered stable and are used successfully in production environments, both incubating and graduated. Um to become graduated, a project needs to show a few things. One of them is committed to at least two organizations. It needs documented governance structure. It needs neutrality,

established provable neutrality, and it has to meet the Linux Foundation core infrastructure initiative best best practices requirements. In other words, it's it's it's more about pop It's more than just popularity, right? It's it's you have to show that this project is stable and it's hopefully going to be here for the long haul. and then one one more thing is is the the transition from sandbox to incubating

to graduated, it can be a very long process. It is a marathon, not a sprint. But these these will kind of help you understand where where projects are in their maturity once you're checking them out on the landscape. So, this is the landscape. That's what it looks like. I'm going to go to it in the actual browser window in just a second if I could figure out

how cuz I always struggle with that. But yeah, so it's it's it looks like a wall of logos, right? Logos, categories, what is all this? It's broken down into various categories and various maturity levels. We can filter. We're going to look at that in just a second, but I just kind of, you know, I think when people first visit it, they looks like a pretty overwhelming poster,

but it is not. So, we're going to dig a little deeper. But, I also wanted to, before we get into it, plug really quickly the fact that there is now this thing called ask.cncf.io and it is interactive and AI-powered like everything is these days and you can ask it a lot of these questions, too. And I think it can help you solve some problems. So, now that

we know the history of the CNCF and what the landscape is, where do we begin? Seems a bit overwhelming, but let's start with a problem. What are we trying to accomplish? What part of your stack needs a little help? Once you figure out what you need and how to find it, the landscape stops being intimidating and starts being a little more useful. I'm, you know, I'm going

to get back to this and for now I want to Let's see if we can do this. Oh, look at that. Look, I have a browser window there. Oh, cool. Okay, except I can't see it. How do I mirror it? You know what? I'm going to do this. No, I'm not going to do that. Well, you know what? We're going to just going to look at it.

Okay, so a couple If we go to the top here, make sure you can still hear me. Let's look at our filters because this is where it starts getting actually useful. So, I want everybody to know that you can do things like filter only graduated projects. Now, I don't want you to get into that mindset where you think that you have a project has to be graduated

for you to use it because that's absolutely not true. But, you'll see some probably familiar names that you've maybe interacted with a little bit before, right? Projects like Helm, projects like Kubernetes itself. These things are quite mature and have met the bar. But let's dig into Helm a little bit. It's a project near and dear to my heart. It's something I like to talk about, especially about

project sustainability, it's one of those tools that's so good you forget about it. And then you forget that maybe you should contribute occasionally. So, okay, where's my cursor? I've lost Okay, cool. This is awkward. Yes, thank you. That would be fantastic. Thank you so much. Okay, now I'm going to turn my back to you. It's weird, but that's totally okay. Is it on? I don't know. Anyway.

Um I think it's not on. So, let's look at what you can do when you evaluate all these different projects, There is something cool, if you scroll down, and it is called Clo Monitor. What is Clo Monitor? It is a big question. Okay, no, it it's definitely in existence. Okay, so Clo Monitor is this cool uh evaluation tool, and it is frequently updated with kind of a

scoring system, which I think is kind of useful. When you're talking about looking at what projects you're going to both consume and possibly contribute to. So, here's something neat, right? And and I don't want people to think also that this is a that a red red X is something to avoid. That's not true. I like to look at the red X's as opportunities. It's an opportunity where

maybe something in that project could be improved. And maybe the person to do that improvement is one of you. So, when you're going through these projects and looking at um you know, various aspect Look at road map, for example, has a red X. Well, what does that mean? Maybe that's an opportunity for you to step up. If you're relying on this project to help keep it going

and help it get a better score. So, this is not a you know, it's not a hard and fast rule where you have to say, "Well, everything has to have a benchmark of X number." I mean, you may decide you want to set that policy, but that's kind of a up to you to do your due diligence, right? Look at these projects as living breathing ecosystems and

think of them as uh in terms of places where you might want to So, let's go back to the landscape Oh, crap. How do I get out of this? I can't see. There we go. Okay. So, another thing that I really wanted to talk about before uh I talk too much and run out of time is note in the top corner there is this handy little What

is that? Um I can't tell you how long it took me to figure out that that was there. Maybe years of interacting with this landscape. Um it you can download all the projects as an Excel file. And why do you want to do that? Because it it makes it easier to read. And it shows you the last time the project had a security audit. So, I think

that's pretty cool. our slides and we'll go from there. No. Okay. Yeah, here we go. here's what I want I also want to talk talk to you a little bit bit about. When you're going through this landscape, I like to think of kind of a process for evaluating projects. Um because you need to know why you want to pick and choose any of these things, right? Once

you once you take once you use a project and you need to depend on it, you kind of own it a little bit. And I I get have a little bit of a soapbox I get on about that and I won't do that today, but you you're taking ownership of this thing and you're going to rely on it. So so we want to we want to think

about first why we need to use these projects, right? What are you what are you looking to solve? So the other thing use that use that landscape to narrow by maturity and category, right? Where in the stack is it going to go? Third, you want to look at project health looking looking at tools like Clone Monitor, but you're also going to want to look at things manually.

When you're evaluating project, dig into the issue queues, look and see what's going on with the project. Look at things like OpenSSF Scorecard. Look at the things like the security audits. All of these will paint a picture of the status of a project. And then the next thing, right? Experiment. Test it out in your staging environments. Kick the tires. And then maybe see if you can get

involved in the community, right? Contribute. Small contributions help. Opening issues in the issue queues helps. Uh and then rinse and repeat the world is the the landscape changes fast, projects evolve, and and you got to keep up. So I wanted to again talk about what is this Clone Monitor thing and here's a a little bit better explanation. Um it's just a really nice way to get a

gut check on project health. It checks against best practices, indicators across documentation, community, security, and code. It is helpful for beginners because it turns a vague question of like is this a healthy project into at least a number, right? It is kind of a nice easy way to get at a glance an idea of the status of a project. Uh but again, most importantly, red marks are

not a disqualifier. Um just you know, might be an opportunity for for contribution. I wanted to talk a little bit about how it started, right? Um it started off a lot smaller. So this used to be a lot easier. I also wanted to talk just a little bit Oh, this is a a little bit of another checklist. If you want to a lot of people like to

take snap pictures of this one, but but yeah, look look beyond popularity. Start with the maturity stage. Then look at release cadence. Is the project active? Check things like maintainer diversity. Are multiple organizations involved in this project or is it dependent on one person or one company? Look at gaps. Look at security status. Don't ignore license and governance. That's all very relevant to look at that. These

matter a lot in enterprise settings because you need to be able to rely on it, not just know that it works. I wanted to do a quick shout-out before I'm almost out of time for WasmEdge, some other undiscovered WasmEdge is a nice example of kind of something that catches people's attention because it speaks to portability and lightweight execution. I threw it in there because my fellow artist

who is with the Rust Foundation and we wanted to make sure to let you know about it. The other thing I wanted to quickly tell you about, don't don't just check out the landscape. Join the community and that's something that you're going to want to do here at KubeCon. And the people in the community come from all different companies, lots of different projects, but it's also people

like, you know what, go check out the the merch booth. Those people are pretty cool, too. If you want to hang out with me, I'm I'm very happy to help you navigate this. I am I will be across the street at JetBrains from 6:00 to to 9:00 p.m. You can hang out with me there or you can find me at the event and I am very happy

to say hi and I am out of time.