Keynote: CNCF at 10: Navigating Challenges, Embracing Opportunit... J. Sandoval, L. Rice, K. Gamanji
J. Sandoval, L. Rice, K. Gamanji
KubeCon + CloudNativeCon Europe 2025 · Keynote
Overview
This keynote address, delivered by J. Sandoval, Liz Rice (Chief Open Source Officer at Isovalent, Cisco), and Katie Gamanji (Senior Field Engineer at Apple) at KubeCon EU, offered a profound reflection on the Cloud Native Computing Foundation (CNCF)'s first decade. Marking a significant milestone, the speakers delved into the foundational principles that led to the CNCF's inception, the pivotal moments that shaped its growth, and the persistent challenges and emerging opportunities that will define its future. The talk served as both a historical retrospective and a forward-looking strategic discussion, highlighting the community-driven ethos that underpins the cloud-native ecosystem.

Key moments
- 0:00 Introduction and CNCF's foundational principles
- 2:00 Dan Khan's pivotal impact on careers and community
- 4:10 Emergence of interfaces for standardization and interoperability
- 4:55 Kubernetes' success through vendor neutrality
- 6:00 Discussion on navigating technical and organizational challenges
Keynote: CNCF at 10: Navigating Challenges, Embracing Opportunities
Speakers: J. Sandoval, L. Rice, K. Gamanji
Conference: KubeCon EU
YouTube: https://www.youtube.com/watch?v=rACTrbTnFqY
Overview
This keynote address, delivered by J. Sandoval, Liz Rice (Chief Open Source Officer at Isovalent, Cisco), and Katie Gamanji (Senior Field Engineer at Apple) at KubeCon EU, offered a profound reflection on the Cloud Native Computing Foundation (CNCF)'s first decade. Marking a significant milestone, the speakers delved into the foundational principles that led to the CNCF's inception, the pivotal moments that shaped its growth, and the persistent challenges and emerging opportunities that will define its future. The talk served as both a historical retrospective and a forward-looking strategic discussion, highlighting the community-driven ethos that underpins the cloud-native ecosystem.
The discussion began by tracing the CNCF's origins back to the very launch of Kubernetes, recalling the initial vision for a foundation that would foster a harmonized, interoperable, and vendor-neutral environment for cloud-native technologies. It celebrated the unsung heroes and critical decisions that enabled Kubernetes to become the industry standard, moving beyond the early "orchestrator wars." The speakers emphasized the crucial role of community, governance, and strategic technical decisions in navigating the complex landscape of open-source development.
Ultimately, the keynote underscored the CNCF's enduring mission: to make cloud-native computing ubiquitous, accessible, and inclusive for the entire industry, not just a few major players. By examining past successes and failures, and by proactively identifying future gaps, the foundation aims to continue driving innovation and ensure the long-term sustainability and health of its projects and the vibrant community built around them.
Background
▶ Watch: Introduction and CNCF's foundational principles (0:00)
The genesis of the Cloud Native Computing Foundation can be traced back to the very early days of Kubernetes, as highlighted by J. Sandoval's archival dive into the initial launch talks. Craig McClucky, in one of the foundational speeches, articulated a clear vision: a need for a foundation to move everything to cloud-native computing, emphasizing that it should be an effort by the entire industry, not just a select few. This nascent foundation was envisioned to focus on a harmonized set of technologies, provide reference architectures, ensure interoperability, fill ecosystem gaps, and create a safe space for industry engagement. Following this, Jim Zlin laid out the pragmatic guidelines essential for such a foundation's growth, including robust governance, clear membership criteria, defined ecosystem development strategies, and meticulous intellectual property management. These principles, though perhaps not fully grasped at the moment of their utterance, became the bedrock upon which the CNCF was built.
A critical, often overlooked, figure in the CNCF's formative years and ongoing success is Dan Khan. Both Liz Rice and Katie Gamanji shared personal anecdotes illustrating Khan's profound impact. Katie Gamanji recounted how Khan approached her during a Kubernetes forum in Sydney, encouraging her to join the Technical Oversight Committee (TOC) even before she fully understood its significance for open-source governance. Gamanji herself was a recipient of a KubeCon scholarship in 2018, a testament to the Dan Khan Scholarship program, which has since donated millions of dollars, benefiting over 7,000 individuals and fostering diversity within the community. Liz Rice similarly credited Khan for inviting her to be a program co-chair in 2018, and later for building her confidence to stand for the TOC, where she served for three years. Khan's consistent efforts to identify and empower individuals underscore the human element vital to the CNCF's thriving community.
The technical landscape preceding the CNCF's dominance was characterized by a fragmented ecosystem. As Liz Rice noted, it was not immediately obvious which container orchestrator would prevail, with several competing options vying for supremacy. Kubernetes' eventual triumph was largely attributed to the CNCF's role as a neutral foundation, which instilled confidence in its adoption by various cloud providers and end-users alike. The need for standardization was recognized even before the CNCF's formal establishment, exemplified by efforts like the Open Container Initiative (OCI), which aimed to drive alignment around container image and runtime specifications. This early push for common ground set the stage for the CNCF's subsequent success in fostering a collaborative, rather than purely competitive, environment.
Key Findings
▶ Watch: Dan Khan's pivotal impact on careers and community (2:00)
The keynote identified several pivotal moments and key contributions that have defined the CNCF's journey over the past decade:
- Emergence of Interfaces and Standardization: A critical turning point was the introduction of standardized interfaces for core components like container runtimes and networking. Katie Gamanji highlighted how this innovation, exemplified by the Container Runtime Interface (CRI) and Container Network Interface (CNI), achieved a delicate balance. It brought essential standardization to the ecosystem, ensuring interoperability between different components, while simultaneously embracing the principle of extensibility. This approach allowed vendors to innovate by building on existing integrations and plugins, offering end-users a diverse selection of tools to choose from, benchmark, and tailor to their specific platform requirements.
- Kubernetes' Ascendancy and Vendor Neutrality: Liz Rice pointed out that Kubernetes emerged as the de facto standard for container orchestration largely due to the CNCF's role as a neutral foundation. This neutrality was instrumental in building trust among diverse stakeholders, enabling broad adoption by numerous cloud providers and end-users. The confidence that a neutral body could govern such a critical open-source project was a defining factor in its widespread success, ensuring that no single vendor controlled its destiny.
- Impact of Governance and Project Growth: The Technical Oversight Committee (TOC) played a crucial role in the exponential growth of projects within the CNCF. Speakers noted that changes in governance, particularly the expansion of TOC membership, directly correlated with an increase in project contributions and maturity. This structured approach to oversight and guidance helped steer projects from initial sandbox stages through incubation to graduation, ensuring technical alignment and community health.
- Overcoming Challenges – Composability and Alignment: Not all aspects of growth were without hurdles. The intentional decision not to mandate a single opinionated solution, but rather to foster composable architectures, while beneficial for flexibility, led to a complex landscape that could be difficult for users to navigate. However, this complexity was viewed as a necessary trade-off for the extensive choice available. A prime example of overcoming alignment challenges was the journey of OpenTelemetry. Starting as two separate projects, it required significant effort to harmonize specifications and merge, ultimately graduating to become a unified, widely adopted standard for observability.
- Identifying Future Gaps and Opportunities: Looking ahead, the TOC is proactively identifying gaps within the ecosystem to encourage future innovation and contributions. Katie Gamanji outlined three key domains:
- Multicluster management and observability: This remains a significant challenge, especially for organizations employing cross-provider strategies, requiring individual configuration, scaling, and comprehensive observability across disparate clusters.
- Cost spending and sustainability: With the increasing adoption of cloud-native architectures, there's a growing focus on managing cloud costs and reducing the carbon footprint. The TOC seeks more collaboration in this area.
- Infrastructure provisioning and secret management: These areas have long been persistent gaps in the ecosystem, and the TOC aims to surface them for increased innovation and tooling development.
- Importance of End-User Involvement: The growing end-user community is increasingly vital, providing invaluable feedback on what works and what doesn't. This engagement translates into practical artifacts like reference architectures and end-user technology radar reports, which serve as crucial guides for building effective cloud-native systems.
Technical Deep Dive
▶ Watch: Emergence of interfaces for standardization and interoperability (4:10)
The CNCF's success over the past decade is deeply rooted in several core technical philosophies and architectural decisions that have fostered an ecosystem of innovation, interoperability, and resilience. A primary technical driver was the emergence of interfaces, particularly the Container Runtime Interface (CRI) and Container Network Interface (CNI). These interfaces acted as crucial abstraction layers within Kubernetes. Instead of tying Kubernetes to a single container runtime or networking solution, CRI and CNI defined standard APIs that allowed various implementations (e.g., containerd, CRI-O for runtimes; Calico, Cilium, Flannel for networking) to plug into the Kubernetes control plane seamlessly. This technical decision was revolutionary, enabling vendors to develop competitive, specialized solutions while guaranteeing a baseline of interoperability. It transformed Kubernetes from a monolithic orchestrator into a highly modular and extensible platform, directly contributing to its rapid adoption and the explosion of the cloud-native landscape.
The concept of composable architectures is another cornerstone of the CNCF's technical approach. Rather than dictating a "one-size-fits-all" solution, the foundation encouraged the development of specialized components that could be combined and customized to meet diverse organizational needs. While this approach offers unparalleled flexibility and allows end-users to tailor their environments precisely, it also presents a significant challenge: navigating the vast and often complex landscape of available projects. The CNCF Landscape map, though daunting, is a visual representation of this composable philosophy, showcasing the breadth of tools available for every layer of the cloud-native stack.
The journey of OpenTelemetry serves as an excellent case study illustrating both the technical challenges and the strategic successes of the CNCF in fostering technical alignment. OpenTelemetry emerged from the merger of two previously competing observability projects: OpenTracing and OpenCensus. Technically, this involved harmonizing two distinct sets of specifications, APIs, and data models for distributed tracing, metrics, and logging. The CNCF provided the neutral ground and governance structure necessary to facilitate this complex technical convergence. The result is a unified, vendor-agnostic standard that simplifies the collection and export of telemetry data, demonstrating the foundation's ability to drive consensus on critical technical infrastructure, even when faced with significant initial divergence.
Looking forward, the TOC has explicitly highlighted several technical gaps that represent significant opportunities for future innovation and development within the cloud-native ecosystem:
- Multicluster Management and Observability: The technical complexities of operating distributed applications across multiple Kubernetes clusters, especially in cross-provider strategies (e.g., hybrid cloud or multi-cloud deployments), are substantial. This involves challenges in unified cluster provisioning, consistent configuration management, global load balancing, shared identity and access management, and, crucially, aggregated observability. Technical solutions are needed for collecting, correlating, and visualizing telemetry data (logs, metrics, traces) from disparate clusters and cloud environments into a single pane of glass, enabling effective troubleshooting and performance optimization at scale. This often requires advanced service mesh capabilities, global control planes, and sophisticated data aggregation techniques.
- Cost Spending and Sustainability: This domain, while seemingly operational, has significant technical underpinnings. Optimizing cloud-native deployments for both financial cost and environmental impact ("carbon footprint") requires sophisticated tooling. This includes technical solutions for real-time resource usage monitoring, intelligent auto-scaling algorithms that consider both performance and cost, FinOps integration with cloud-native platforms, and potentially "green coding" practices that minimize computational waste. Developing tools that can analyze resource consumption patterns, identify inefficiencies, and recommend optimizations across dynamic Kubernetes workloads is a key technical challenge.
- Infrastructure Provisioning and Secret Management: These areas represent long-standing pain points in cloud-native operations. Infrastructure provisioning often involves managing complex dependencies, immutable infrastructure principles, and integrating with diverse cloud APIs. The demand is for more declarative, GitOps-driven approaches that can provision and manage underlying infrastructure (VMs, networks, databases) consistently alongside application deployments. Secret management is another critical technical challenge, requiring robust solutions for storing, distributing, and rotating sensitive credentials (API keys, database passwords, certificates) securely across a dynamic and ephemeral cloud-native environment. This necessitates integration with dedicated secret stores (e.g., HashiCorp Vault, cloud provider secret managers), secure injection mechanisms (e.g., CSI Secret Store driver), and stringent access control policies (e.g., least privilege, just-in-time access).
To guide projects through these technical challenges and into the CNCF ecosystem, the TOC has streamlined its processes for sandbox inclusion, incubation, and graduation. The TOC repository serves as a publicly available resource, offering declarative guidance, a backlog of ongoing work, and, importantly, closed issues that act as successful case studies for past due diligence efforts. This transparency helps project maintainers understand the technical and operational criteria for advancing their projects within the foundation.
Demo / Proof of Concept
▶ Watch: Kubernetes' success through vendor neutrality (4:55)
As a keynote address focused on the strategic overview, historical reflection, and future direction of the Cloud Native Computing Foundation, this talk did not include a technical demonstration or a proof of concept. The discussion remained at a high-level, analytical plane, emphasizing organizational growth, community dynamics, and broad technical trends rather than specific implementations or live code examples.
Defensive Implications
▶ Watch: Discussion on navigating technical and organizational challenges (6:00)
While this keynote was not a security-focused talk, the identified challenges and future directions within the cloud-native ecosystem carry significant defensive implications that security professionals must consider.
- Multicluster Management and Observability: The complexity of managing multiple clusters, especially across different cloud providers, directly impacts an organization's security posture. A fragmented approach to security in multicluster environments can lead to inconsistent policy enforcement, blind spots in threat detection, and difficulties in maintaining a unified identity and access management (IAM) strategy. Defenders need robust solutions for centralized security policy orchestration, consistent network segmentation, and aggregated security observability across all clusters. This includes tools that can correlate security events from diverse sources, enforce global compliance standards, and provide a consolidated view of potential threats, preventing attackers from exploiting inconsistencies between clusters.
- Secret Management: The persistent gap in infrastructure provisioning and secret management tooling is a critical security concern. Inadequate secret management practices, such as hardcoding credentials, storing them insecurely, or failing to rotate them regularly, are among the most common causes of data breaches. Defenders must advocate for and implement robust, cloud-native secret management solutions. This involves integrating dedicated secret stores, utilizing mechanisms for secure secret injection (e.g., Kubernetes Secrets Store CSI driver), implementing strong encryption for secrets at rest and in transit, and enforcing strict least-privilege access controls. The goal is to eliminate static credentials and ensure that sensitive information is managed dynamically, securely, and with a full audit trail.
- Cost Spending and Sustainability: While seemingly unrelated to security, the focus on cost spending and sustainability can indirectly enhance defensive capabilities. Efficient resource utilization (FinOps) means fewer unmanaged or forgotten resources that could become an attack surface. Moreover, a well-optimized and monitored infrastructure is generally easier to secure. Resources allocated for security tooling and personnel are often scrutinized; demonstrating cost efficiency in general operations can free up budget for critical security investments. Furthermore, better observability for cost can be leveraged for security monitoring, as unusual resource spikes might indicate malicious activity (e.g., cryptojacking).
- Project Governance and Due Diligence: The CNCF's emphasis on stringent TOC processes for project inclusion, incubation, and graduation has positive implications for supply chain security. By providing clear guidance and conducting thorough due diligence, the CNCF aims to ensure that projects entering its ecosystem meet certain quality, stability, and potentially security standards. For defenders, this means a reduced risk of incorporating insecure or poorly maintained components into their cloud-native stacks. However, defenders must still perform their own due diligence, as even graduated projects can introduce vulnerabilities. The transparency of the TOC repository, with its public backlog and closed issues, provides valuable insight into the evaluation process, allowing security teams to assess the rigor applied to projects they might consume.
- Vendor Neutrality and Interoperability: While a strength for innovation, the principle of vendor neutrality and interoperability also means that defenders must navigate a diverse ecosystem of tools and vendors. This necessitates a proactive approach to security best practices that are agnostic to specific vendor implementations. Security teams must ensure that their security policies, controls, and monitoring capabilities are consistently applied across heterogeneous environments, regardless of the underlying CNI, CRI, or service mesh chosen. This requires a deep understanding of the security implications of each component and the ability to integrate security tooling across various cloud-native technologies.
Key Takeaways
- The CNCF's decade of success is built on foundational principles of vendor neutrality, interoperability, and robust governance, stemming from the initial vision for Kubernetes.
- The introduction of standardized interfaces like CRI and CNI was a pivotal technical decision, enabling massive innovation and choice while ensuring core system interoperability.
- Dan Khan played an instrumental, often understated, role in fostering diversity and leadership within the community, directly impacting the careers of many, including the speakers.
- Key challenges for the next decade include addressing the complexities of multicluster management and observability, optimizing for cost spending and sustainability, and improving infrastructure provisioning and secret management tooling.
- Projects seeking CNCF inclusion must be intentional about their purpose, align with business interests, and actively build a community; inclusion is not a magic bullet for adoption.
- Maintaining the sustainability of the community, including supporting maintainers and balancing the diverse interests of all stakeholders (projects, individuals, vendors, end-users), is crucial for the CNCF's continued growth and health.
About the Speaker(s)
J. Sandoval served as the host and moderator for this keynote, demonstrating a deep historical perspective and appreciation for the CNCF's journey, referencing early Kubernetes launch talks and acting as the catalyst for the retrospective discussion.
Liz Rice is the Chief Open Source Officer at Isovalent, a Cisco company. A highly influential figure in the cloud-native community, she previously served a three-year term on the CNCF's Technical Oversight Committee (TOC) and was a program co-chair for KubeCon, highlighting her extensive experience in governance and community leadership. Her insights often focused on the importance of vendor neutrality and the foundational role of open source.
Katie Gamanji is a Senior Field Engineer at Apple and a prominent member of the CNCF Technical Oversight Committee (TOC). She shared her personal journey, including being a recipient of a KubeCon scholarship in 2018, underscoring her commitment to community inclusivity and growth. Katie is actively involved in initiatives like the "tag reboot" within the TOC, aiming to restructure community groups for the next decade of cloud-native evolution.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This keynote, celebrating CNCF's first decade, transcends typical retrospectives by offering deep insights into the foundational principles, critical technical decisions (like CRI/CNI), and the often-unseen human element that shaped the cloud-native ecosystem. Delivered by highly credible speakers from the Technical Oversight Committee, it provides invaluable insider signal on the strategic direction, governance evolution, and, crucially, explicitly identifies key technical gaps—such as multicluster management, secret management, and sustainability—that will drive innovation and demand attention from architects and security professionals in the coming years.
Heather Calloway (CISO) — STRONG ACCEPT
This keynote offered a valuable strategic overview of the Cloud Native Computing Foundation's first decade, critically examining its foundational principles, governance, and pivotal role in standardizing the cloud-native ecosystem. While not a deep dive into specific security controls, its clear articulation of future ecosystem gaps—particularly around multicluster management, secret management, and cost/sustainability—provides essential context for CISOs and security leaders to anticipate and address emerging risks and strategic investments. The talk effectively translates complex ecosystem dynamics into actionable insights for institutional planning and risk ownership.