Discover CNCF TAG Runtime: Advancing Cloud-Native Innovation from AI to Edge

KubeCon + CloudNativeCon Europe 2025 · Session

Overview

This talk, presented by key leaders from the CNCF TAG Runtime, offers a comprehensive look into the group's current structure, its diverse contributions to the cloud-native ecosystem, and a significant impending organizational reboot. The speakers, including Danielle from Microsoft, Steve Rust from Okabi/Lenode, Alexander Kaneki from Intel, and Ricardo Aravina, articulate the expansive scope of TAG Runtime, which extends far beyond traditional container runtimes to encompass critical areas such as AI, edge computing, WebAssembly, and specialized operating systems.

Watch on YouTube

Visual summary for Discover CNCF TAG Runtime: Advancing Cloud-Native Innovation from AI to Edge
Visual summary for Discover CNCF TAG Runtime: Advancing Cloud-Native Innovation from AI to Edge

Key moments

  1. 0:00 Introduction to TAG Runtime and speakers
  2. 2:00 Defining CNCF Technical Advisory Groups (TAGs)
  3. 4:00 Current CNCF TAG structure and responsibilities
  4. 5:08 Understanding the broad scope of TAG Runtime
  5. 6:05 Highlighting key projects under TAG Runtime
  6. 8:00 Overview of AI Working Group and whitepapers
  7. 9:45 Cross-community efforts in WebAssembly (Wasm)

Discover CNCF TAG Runtime: Advancing Cloud-Native Innovation from AI to Edge

Speakers: Danielle, PM for Microsoft and Co-chair of TAG Runtime; Steve Rust, Principal Architect at Okabi/Lenode; Alexander Kaneki, Intel, working on Kubernetes, CNCF, and the Container Orchestrated Devices Working Group; Ricardo Aravina, Co-chair of TAG Runtime.

Conference: KubeCon EU

YouTube: https://www.youtube.com/watch?v=-yOKr2DOJ_o

Overview

This talk, presented by key leaders from the CNCF TAG Runtime, offers a comprehensive look into the group's current structure, its diverse contributions to the cloud-native ecosystem, and a significant impending organizational reboot. The speakers, including Danielle from Microsoft, Steve Rust from Okabi/Lenode, Alexander Kaneki from Intel, and Ricardo Aravina, articulate the expansive scope of TAG Runtime, which extends far beyond traditional container runtimes to encompass critical areas such as AI, edge computing, WebAssembly, and specialized operating systems.

The core message underscores the necessity of adapting the CNCF's internal structure to accommodate its explosive growth. With the number of projects surging from approximately 50 to over 200 in just five to six years, the existing Technical Advisory Group (TAG) framework required an overhaul to maintain integrity, increase quality, and foster community engagement more effectively. The proposed restructure, featuring new TAGs and flexible mechanisms for initiatives and sub-projects, aims to enhance agility and streamline the process for community contributions, ensuring the CNCF can continue to support innovation across the rapidly evolving cloud-native landscape. This presentation is crucial for anyone seeking to understand the strategic direction of the CNCF and the technical underpinnings driving its future.

Background

▶ Watch: Introduction to TAG Runtime and speakers (0:00)

The Cloud Native Computing Foundation (CNCF) operates with the support of Technical Advisory Groups (TAGs), which serve as crucial conduits between the CNCF Technical Oversight Committee (TOC) and the broader community. As defined by the speakers, a TAG "scales to contribute by the CNCF technical and user committee while retaining integrity and increasing quality in support of the CNCF mission." In essence, TAGs assist the TOC with technical reviews, facilitate community discussions, and provide expertise across various domains.

The genesis of the current restructuring effort lies in the exponential growth of the CNCF ecosystem. As highlighted in the talk, the number of projects under the CNCF umbrella has ballooned from around 50 five to six years ago to approximately 209 today, including archived projects. This rapid expansion necessitated a re-evaluation of the existing eight TAGs (Observer, Networking, Storage, Cloud Native Security, Delivery, App, and Runtime, among others) to ensure efficient coordination, project guidance, and community support. TAGs are responsible for reaching out to projects, facilitating presentations, conducting project reviews, bootstrapping new initiatives, publishing white papers, and managing working groups through bi-weekly meetings, often serving as the initial point of contact for projects engaging with the CNCF.

The TAG Runtime, the focus of this presentation, has historically held a particularly broad mandate. Its scope extends beyond mere container runtimes to include workload orchestration, diverse workload types, operating systems, virtualization, edge computing, and device management. More recently, it has also become the home for many AI initiatives within the CNCF. This expansive remit reflects the foundational nature of runtime technologies across the cloud-native stack, making it a critical hub for innovation and cross-cutting concerns. Examples of projects under its purview include Flatcar (incubating), KubeEdge (graduated), WasmCloud (graduated), containerd, CRI-O, Yuki (a new Rust-based container runtime), Knative, K3S, and K0S.

Key Findings

▶ Watch: Current CNCF TAG structure and responsibilities (4:00)

The talk unveiled several critical findings regarding the state of the CNCF ecosystem and the strategic evolution of its TAG structure. Foremost among these is the undeniable and accelerating growth of cloud-native projects. With over 200 projects now under the CNCF, the existing operational model, while effective for a smaller landscape, required significant adaptation to maintain governance, quality, and community engagement. This led to the fundamental finding that the entire TAG structure needed a comprehensive reboot to foster greater agility and support the community's expanding needs.

Within the existing TAG Runtime, the presentation highlighted its role as a vibrant epicenter for innovation across a remarkably diverse set of domains. It demonstrated that "runtime" in the cloud-native context encompasses far more than just container execution environments, extending into areas like AI, edge computing, WebAssembly, and specialized operating systems. Key achievements from this broad scope include:

  • Significant Project Milestones: The successful graduation of projects like KubeEdge and WasmCloud, and the incubation of Flatcar, underscore TAG Runtime's impact on maturing critical cloud-native technologies. The acceptance of K0S and Yuki (a container runtime written in Rust) into the sandbox further exemplifies the continuous innovation fostered within the group.
  • Pioneering AI Initiatives: The Cloud Native AI Working Group has been instrumental in publishing foundational white papers, including the "Cloud Native AI White Paper" released in Paris, and is actively developing additional papers on AI security, scheduling challenges (particularly for GPUs), and sustainability—addressing crucial, emerging concerns.
  • WebAssembly Standardization: The Web Assembly Working Group has made tangible contributions, notably with updates to the OCI artifact layout specifically designed for Wasm, demonstrating effective cross-community collaboration with entities like the Bytecode Alliance and W3C.
  • Groundbreaking Device Orchestration: Perhaps one of the most significant announcements was the 1.0 release of the Container Orchestrated Devices (COD) Working Group's specification. This milestone represents a unique achievement, as the COD WG is one of the very few CNCF working groups that produces and owns code, providing a fundamental building block for how devices are exposed within containers.

The overarching finding is the strategic shift towards a more flexible and scalable CNCF structure. The upcoming reboot will introduce five new, broader TAGs (Developer Experience, Workload Foundations, Infrastructure, Operational Resiliency, Security and Compliance) and new organizational entities: Sub-projects (long-lived, with direct TOC or TAG engagement), Initiatives (short-lived, focused on specific deliverables like code or specs), and Community Groups (for general discussions). This restructure directly addresses the need for the CNCF to remain agile and responsive to its rapidly growing and diversifying project landscape, with TAG Runtime's core concerns mapping directly to the new "Workload Foundations" TAG.

Technical Deep Dive

▶ Watch: Understanding the broad scope of TAG Runtime (5:08)

The TAG Runtime's activities span a wide array of technically sophisticated areas, with several working groups producing impactful specifications, white papers, and even code.

The Container Orchestrated Devices (COD) Working Group stands out as a unique entity within the CNCF. Originating from a discussion at a KubeCon San Diego lunch table, this working group has evolved into one of the only CNCF groups that produces and owns code—specifically, a specification. Its core purpose is to define how devices are exposed inside containers, serving as a fundamental, low-level building block for higher-level systems. This specification is crucial for enabling the integration of specialized hardware with cloud-native workloads. The talk proudly announced the 1.0 release of the COD specification several days prior to KubeCon EU, marking a significant milestone. This specification is already being utilized by critical projects such as DRA (Device Resource Allocation), and its principles are reflected in common line usage within container runtimes like Podman and Docker, as well as CRI-O. The working group continues its work on maintenance and is actively exploring new features, including anticipated support for network interfaces, which was recently merged into the OCI runtime specification. This demonstrates a continuous effort to align with evolving industry standards and address emerging hardware integration needs.

The Cloud Native AI Working Group addresses the dual challenge of running AI workloads efficiently on cloud-native infrastructure and leveraging AI to enhance cloud-native operations (ee.g., AI Ops and integrating Large Language Models (LLMs) with Kubernetes). This group tackles complex technical problems, particularly around GPU management and scheduling challenges for AI workloads, which demand significant and specialized computational resources. Their output includes several key white papers: the foundational "Cloud Native AI White Paper" (published in Paris), an "AI Security White Paper," a "Scheduling Challenges White Paper" focusing on GPU allocation, and a "Sustainability AI White Paper" addressing the substantial energy consumption associated with AI and GPUs. The work here is highly interdisciplinary, often overlapping with the Batch System Initiative due to the resource-intensive, batch-oriented nature of many AI/ML training tasks.

The WebAssembly (Wasm) Working Group focuses on integrating WebAssembly into the cloud-native ecosystem. Wasm offers a sandboxed, efficient runtime for various workloads, and its adoption is growing. A key technical contribution from this group has been the updates to the OCI artifact layout specifically for Wasm modules. This standardization effort ensures that Wasm artifacts can be managed and distributed consistently within the Open Container Initiative framework, facilitating broader adoption and interoperability. The working group also actively collaborates with the Bytecode Alliance and contributes to W3C standards, highlighting its commitment to driving Wasm's technical evolution and integration.

Finally, the Batch System Initiative (BSI) working group is dedicated to defining specifications, CR (Custom Resource) types, and resources tailored for batch processing efforts. This includes projects like KubeFlow and KubeQueue, which are essential for managing discrete, often long-running, and resource-intensive jobs. As mentioned, there is significant overlap between BSI and the AI Working Group, as many AI/ML training and inference tasks fall under the batch processing paradigm, requiring efficient utilization of resources like GPUs, CPUs, and memory. The BSI aims to provide the necessary tooling and best practices for optimizing these critical workloads.

Demo / Proof of Concept

▶ Watch: Overview of AI Working Group and whitepapers (8:00)

This particular talk focused on organizational structure, working group initiatives, and strategic planning rather than a live technical demonstration or proof of concept. As such, no specific demo was presented during the session.

Defensive Implications

▶ Watch: Cross-community efforts in WebAssembly (Wasm) (9:45)

While the talk primarily focused on organizational structure and technical innovation, several aspects carry significant defensive implications for security professionals operating in cloud-native environments.

Firstly, the Cloud Native AI Working Group's initiative on an "AI Security White Paper" is of paramount importance. As AI workloads become increasingly integrated into critical systems, securing the entire machine learning lifecycle—from data ingress and model training to inference and deployment—becomes a top priority. Defenders must anticipate new attack vectors targeting model integrity (e.g., adversarial attacks), data privacy, and the underlying infrastructure that supports AI. This white paper, once published, will likely provide crucial guidance and best practices for mitigating these emerging threats, and security teams should actively monitor its development and recommendations.

Secondly, the Container Orchestrated Devices (COD) Working Group's 1.0 specification for exposing devices within containers is a foundational security concern. While enabling powerful hardware acceleration, improper configuration or vulnerabilities in device drivers and orchestration mechanisms can lead to severe security breaches. Attackers could exploit device access to achieve privilege escalation, access sensitive data, or compromise the host system. The upcoming support for network interfaces in the OCI spec, influenced by the COD WG's work, adds another layer of complexity, requiring careful consideration of network segmentation and access control for containerized applications interacting directly with network hardware. Defenders need a deep understanding of how devices are exposed and managed within their containerized environments to properly secure them.

Thirdly, the growing emphasis on WebAssembly (Wasm), with its dedicated working group and updates to the OCI artifact layout, presents both opportunities and challenges for defense. Wasm's sandboxed nature is inherently beneficial for security, providing a more isolated execution environment than traditional containers in some contexts. However, defenders must ensure the integrity and provenance of Wasm modules, guard against supply chain attacks, and understand the security implications of Wasm runtimes like WasmCloud and WasmEdge. Misconfigurations in the Wasm runtime or vulnerabilities in the host environment could still be exploited.

Finally, the impending CNCF TAG restructure itself has a direct defensive implication. The creation of a dedicated "Security and Compliance" TAG signifies a formalized and centralized focus on security within the CNCF ecosystem. This new TAG will serve as a vital resource for defenders, offering a platform for sharing best practices, conducting security reviews of projects, and driving security-focused initiatives. Security professionals are encouraged to engage with this new TAG, contribute their expertise, and leverage its outputs to enhance the security posture of their cloud-native deployments. The structure aims to facilitate easier creation of "initiatives," which could include rapid responses to emerging security threats or the development of specific security tools and guidelines.

Key Takeaways

  • The CNCF is undergoing a significant organizational restructure, moving from eight to five new Technical Advisory Groups (TAGs) and introducing flexible "Sub-projects," "Initiatives," and "Community Groups" to manage exponential project growth (from ~50 to over 200 in 5-6 years) and foster community agility.
  • The former TAG Runtime is evolving into the core of the new Workload Foundations TAG, continuing its crucial role in advancing diverse runtimes, orchestration, specialized operating systems, and cutting-edge workloads like AI, Edge, and WebAssembly.
  • The Container Orchestrated Devices (COD) Working Group achieved a major milestone with the 1.0 release of its specification, standardizing how hardware devices are exposed to containers—a unique accomplishment as one of the few CNCF working groups to produce and own code.
  • Cloud Native AI and WebAssembly are critical areas of innovation, with the AI Working Group producing foundational white papers on AI security, scheduling (especially for GPUs), and sustainability, while the WebAssembly Working Group contributes to OCI artifact layout updates for Wasm.
  • The restructure aims to empower communities to more easily spin up initiatives and collaborate, ensuring the CNCF remains responsive to the rapidly evolving needs of the cloud-native landscape.
  • Defenders should pay close attention to the new Security and Compliance TAG, as well as the security implications arising from device orchestration (COD WG), AI security initiatives, and the integration of WebAssembly into cloud-native runtimes.

About the Speaker(s)

The talk was presented by a panel of distinguished experts deeply involved in the CNCF TAG Runtime. Danielle, a PM for Microsoft, serves as a co-chair for TAG Runtime, bringing industry perspective and leadership to the group's strategic direction. Steve Rust, a Principal Architect at Okabi (also known as Lenode), focuses on cloud-native initiatives, contributing his extensive experience in architecting scalable cloud solutions. Alexander Kaneki from Intel is a key contributor to the Kubernetes and CNCF stack, specializing in runtimes, resource optimization, and is particularly active in the Container Orchestrated Devices Working Group and the development of the CDI specification. Ricardo Aravina is another long-standing co-chair for TAG Runtime, having served in this role for approximately four years, providing continuity and deep institutional knowledge to the group's efforts.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This KubeCon talk from the CNCF TAG Runtime leadership provides a crucial update on the foundation's organizational restructure, driven by exponential project growth. It details the shift to new TAGs, initiatives, and sub-projects designed to enhance agility and community engagement. More importantly, it highlights significant technical achievements from the current TAG Runtime, including the 1.0 release of the Container Orchestrated Devices (COD) specification, foundational white papers from the Cloud Native AI Working Group (especially on AI security), and WebAssembly (Wasm) integration with OCI. This is essential signal for anyone building or defending in the cloud-native space.

Heather Calloway (CISO) — STRONG ACCEPT

This talk provides a critical overview of the CNCF's strategic organizational reboot and the evolving scope of its TAG Runtime, now transitioning into the Workload Foundations TAG. The exponential growth of cloud-native projects necessitated a fundamental restructure, which includes the creation of a dedicated Security and Compliance TAG. For security leaders, understanding these foundational changes to cloud-native governance, coupled with the work on AI security, WebAssembly, and the 1.0 release of the Container Orchestrated Devices specification, is crucial for anticipating future risks and directing institutional defense strategies. This is not a talk about a specific vulnerability…

→ Top-rated talks at KubeCon + CloudNativeCon Europe 2025

All talks from KubeCon + CloudNativeCon Europe 2025