KubeCon + CloudNativeCon Europe

Project Lightning Talk: A Curator’s Guide to the CNCF Landscape- Katherine Druckman and Lori Lorusso

15:23 · 23 Mar 2026 – 26 Mar 2026 · YouTube

About this talk

This talk provides an overview of the Cloud Native Computing Foundation (CNCF) landscape, aimed at helping newcomers navigate the complex ecosystem of cloud-native technologies. The speakers emphasize the importance of understanding project maturity levels, including sandbox, incubating, and graduated statuses, highlighting that many projects are still suitable for production even if not graduated. They introduce tools like askcncf.io for quick answers to questions and Clo Monitor for assessing project health. The session encourages attendees to contribute to CNCF projects and emphasizes building community connections at KubeCon, fostering collaboration and discussion among open-source enthusiasts.

Full transcript

Welcome fellow software artists. So today Lori and I except actually Vincent Van Gogh and I I am um Rembrandt today. Two very famous and well Oh, sorry. We got to fix our uh Did you do mirror or did you do? >> do anything. It didn't give me option. >> Oh, okay. So There See, there we go. Okay, go back to the go back a slide. There we

go. Okay, now we're now we're cooking. Um with fire. Do you see the similarities? Van Gogh >> See, see, now it starts to make sense, right? The outfits. Okay. >> [laughter] >> The things we do for open source, guys. The things we do. >> Yes. So we are your tour guides through the CNCF landscape, which is uh as I said earlier, as lovely as a Van Gogh

landscape and just as confusing. Uh so we're going to give you a little bit of a map and survival guide uh because the ecosystem can feel a bit overwhelming. Show of hands, how many of you are here for your first KubeCon? Yeah. >> Nice. >> Awesome. So we're going to talk we're going to talk to you about the CNCF landscape. And we're going to talk to you

hopefully a little bit about what else you can do at KubeCon, so let's let's keep it going. Uh this is me. You can find me that QR code will work. Uh please find me. Actually, I love answering questions and helping people figure out their way through this really rather confusing world uh that is software. All right. So my name is Lori. I am the director of outreach

for the Rust Foundation. I'm also a CNCF ambassador, so really stoked that a lot of you are having your first uh KubeCon. How many of you were here for Katherine's presentation this morning? Not too many. >> Okay. So it'll be similar yet different uh but thanks for coming back and there'll be more talks. Uh also I always love to put a picture of my kid uh with

me on there. That was Halloween and she did her own makeup and it was frightening. Moving on. Moving along. So here's a a quick a quick plan for our gallery tour. We're going to tell you a little bit about the CNCF. We're going to get into the landscape. Yeah. And then uh yeah, let's just keep moving. Who cares about this slide? Okay, this is the good stuff.

So this is super exciting. You could like take a nap during our presentation if you'd like after you ate lunch because there's this new tool called askcncf.io that is using Docusaurus and it's basically anything you want to know, it will tell you. So you can type in whatever you got going on, any kind of questions you have. If you have questions after the talk and we're not

around and you want to learn some more, go ahead and go to askcncf.io and uh yeah, George worked really hard on it. I don't know if you guys know George Castro or not. Go to the project pavilion, meet him, meet everybody there. Um you know Robert, but he's just I don't know where he Oh, there he is. Um so yeah, anyways, that is something I wanted to

plug, so if you don't want to pay attention, uh you don't have to, but I hope that you do. So what is the Cloud Native Computing Foundation? And Katherine, I love you, but we got to work on your technical skills. So the mission of the Cloud Native Cloud Native Computing Foundation is to make um computing ubiquitous, which is just like a funny word of just saying everybody

should be on it. Uh there are 209 projects at the CNCF, which is huge. There are almost 300,000 contributors. You've got 765 members. How many of you know if your company is a member of the CNCF? Does anybody? Do you know that depending on your membership level, you get like access to free training? You get credits so that you can become Kubernetes certified, CKA certified, all kinds

of certifications. There's all kinds of levels. Um so make sure you check out what you have so that you don't uh miss out on an opportunity to get free training based on your membership level. And the crazy thing is there's 135,000 plus cloud native community members and here I think at KubeCon this week there'll be about 13,000 of us all hanging out in the hallways doing all

kinds of fun stuff. Okay, Linux Foundation. So uh I don't know if you know this, but the Linux Foundation is the main foundation that houses the uh CNCF. So it's the home of everything. It's um it's the neutral home. It's got governance. It's got structures. It's got trust stewardship and sustainability. But I think the thing that you really should be interested in is there are 900 open

source projects under the Linux Foundation, 3 million developers, 777,000 plus developers contributing code, 51 million lines of code, blah blah blah. All things to say is you are amongst the best people when you are at the Linux Foundation events because you're amongst your people who are all in on the code. But what you don't know or maybe don't know if you're new to the CNCF is that

there are three levels of projects. You have sandbox, incubating, and graduated. And sometimes you get also archived. So what does archive mean? It means the project didn't survive. It does not to say that it was a bad project, but what it means is maybe something else was built on top of it and so that project went away. Maybe the maintainers decided that they didn't want it anymore

and they stopped using it or just was obsolete because something else came along. What you'll notice is that the most of the product projects are in the green and the green is sandbox. So if you're not currently contributing to a CNCF project, those are good ones cuz they're new, they're exciting, they're on the edge, they're trying to get to that level, which is the next level, which

is incubation, and then um finally graduated. Okay, so we talked a little bit about projects. What does that mean? Uh this is this refers to maturity levels, right? Within the CNCF. When you contribute a project to the CNCF, it starts as a sandbox project, right? What is a sandbox project? Uh it really just starts as kind of an idea, right? You don't necessarily have a community built

around it. You don't necessarily have a lot of contribution. Um but it's it's it's an early stage project. They're still proving themselves to communities and um recruiting contributors. As a project then gains a little bit more momentum and gains more adoption, more contributors, that sort of thing, it can then go up to the next level, which is incubating. it has a little bit of evidence of sustainability

probably, but has not yet met the requirements for graduation. Now, officially, if you go to the website, it's going to tell you that graduated and incubating projects are considered stable and are used successfully in production environments. So I don't want you to think that if a project isn't graduated, that it is not suitable for production because that is not necessarily the case. But to become graduated, a

project needs to show adoption. It needs to uh show committers from at least two organizations, for example. It needs documented governance and structure. Uh neutrality is a big one, right? And it has to meet the Linux Foundation core infrastructure initiative best practices requirements. So in other words, it's you know, it's not a popularity contest and the important thing to remember here is that it is a marathon,

not a sprint. >> Yeah, it's a marathon to get in and it's a marathon to get out, but it's totally worth it because of all the innovation that happens from within. So now we're just going to go ahead and jump into the CNCF landscape. So I know this looks like a lot and it is a lot, but we're going to show you how to get around it

a little bit. So this >> You want to switch to mirroring so it's easier. >> I don't know how to do that. Here, let Oh. Never mind, I can't see it. >> Okay, cool. >> Wait. No, wait. Here it is. Screen mirroring. Oh, for goodness. Okay, never mind. Uh here we go. Okay. So if you go up to the top and then you >> Okay, so Here,

I'll do it. Anyways, I can't get into full Okay. I love you, Katherine. I really do. >> It needed to be on mirroring, not extended. It didn't ask me. >> I can't see with this Oh. >> do anything. There we go. There we go. There's the landscape. >> So that's the landscape. So >> to you talk. I'll I'll let They look like a bunch of logos, but

they're actually live. And when you click on one of them, so let's click on one. Let's I love Helm. Helm. >> Shout out to Helm. I always go to. It gives you all of the stats of the project that CNCF is currently tracking, which is really cool. It tells you when it started, what level it's at, how many contributors it has, all of these great things that

you need to be aware of when you're looking at whether you're going to bring this into your stack or not. And one of the tools that is super cool and is with every CNCF project um that is in the landscape is Clo Monitor. Clo Monitor gives you all the deets on the insides and outs of what your project is and gives you a health score. So you

can determine if this is something that you want to again bring into your stack or something maybe that you want to contribute to. Anything in green is a check that's worked. Uh anything in red needs help. Like we need to So these are things that the project needs to be aware of and needs to update so that it can have all green checks. Just because it doesn't

have 100 doesn't mean it's not a good project. It just lets you know where there are areas for improvement or areas that you can do things with. And if you see there is a red X right next to contributing. So if Helm is a project that you use and you want to, you know, work with the with the old guys, you know, be a be a fresh

set of eyes on a on a project that a lot of people use already, it's an opportunity for you to contribute there. Yes, so the big takeaway here is just because you see red X's does not mean it's a deal breaker, right? It's an opportunity. Uh especially, look, you know, documentation has a slightly lower score. That's a great opportunity to get involved in a project and contribute.

So, let's go back to the landscape. Uh let's look at filters, right? Yeah, so when you're looking at this right off the bat, you're like, "Okay, this is a lot." But, what's really cool is they built in a filter tool. This didn't used to exist. And what it does, it helps you filter. So, we can go ahead and look at all of the graduated projects. Oops, >>

Or incubating, whichever. Okay? Graduated. >> Graduated. Um and then let's just go ahead and hit apply. Let's just see like of the 209 projects these are all the projects that have graduated. Do those projects look familiar to you? Right? Because you're probably adopted them and using them in your stack. You can click on, again, any of those projects and it'll give you the same sort of report

like Crossplane just recently graduated. You can scroll down. You can go to their Clone Monitor. Go, go, go. Oh, look at that. It's a solid score. >> But, nobody's perfect. And that's okay. There is no rule about what score you need to look at. It's really about doing due diligence. It's really about evaluating the projects and various metrics. Another tool that's really helpful when you are in

the landscape is the download tool. Oh, fabulous, right here. >> So, right there in the corner, you can download it and it gives you a snapshot in an Excel spreadsheet. >> That's the one right there, projects.csv. And it gives you uh when they had their last security audit. Like, how many of you are in interested in security? Okay, a lot of people need to raise their hands

on that one. >> How many of you are forced to care about How many of you feel victimized by your security team? No, just kidding. >> So, this is a really good like snapshot of you can learn when they had their last security audit. So, if your boss is like up your you know what saying, "We are only going to use tools that have had like successful

security audits past a certain point." You can download that and it'll be an easy spreadsheet. You can go ahead and um you know, pick your date range and go from there. Okay, let's go back to our handy-dandy slideshow. And with our last minute. So, uh there we go. This is Get familiar, make friends, very helpful. It's not black and white. Evaluate projects, do your due diligence. Look

at project health, look at contributor diversity. Look at all the things. What Go back. Oh, go back. So, I think like what we're trying to say is that yes, the CNCF landscape when you look at it on the whole is very much "Wow, this is extremely overwhelming and now these ladies just gave us even more overwhelming information to look at cuz there's so much more information that's

out there and like why do we need to have all this information?" And it's what Katherine said, you need to do your due diligence. You need to make sure like what you're doing and what you're using, you can go back to your higher-ups and say, "This stack is solid and this is why." Or we should contribute to this project because this project is essential for us to

get X, Y, and Z done and right now we're only getting X and Y. So, maybe we can donate some developer hours so that we can push Z to the end. So, there's all kinds of opportunities and hidden information in that Clone Monitor report that you can use to justify what tools you want to bring into your stack. And the great thing is, too, is that you

have all of the information, the GitHub repo, everything there. So, you can just click, click, click away and find a contributor or maintainer that you can ask questions to and make sure you're getting the relevant information that you need for your project. How many of you are working on projects right now at Okay, so we got a lot of end users in here. How many want to?

>> Yeah, how many want to be contributors? >> Yes. Okay, well, today is the day. Now you have a way of kind of looking at all of the projects. You can filter out by what is your interest. If it's not security, is it is it observability? Is Find the Find the gap in your stack and and and uh find your solution in the landscape. Um I think

we have like 1 minute. Yeah, we have less than a >> So, yeah. Love a Helm. Little shout-out to Wasm Edge. But, finally, let's talk about the community. The This week, you're going to find lots of opportunities to meet people, talk to them, find us on LinkedIn. We'll put the slides up. Um Yeah. Just make friends. Make friends. Kiss your maintainers. I mean, hug them. Whatever. I

don't know what's happening here, but the hallway track is really important. And if this is your first KubeCon or maybe your first conference and you don't know what the hallway track is, literally means having conversations in the hallway. So, don't be afraid to like talk to your neighbor, you know, when you're at lunch, sit with people you don't know, and just start having discussions about what's interesting

to you because that's the way that open source works, right? >> Yes, and if you want to find one of us both of us later, this is where we'll be and we can uh happily ask answer any questions you might have about the CNCF All right, thanks, y'all. >> [applause]