Project Lightning Talk: A Hitchhiker's Guide to the CNCF Landscape - Lori Larusso & Gerald Venzl

Lori Larusso, Gerald Venzl

KubeCon + CloudNativeCon Europe 2025 · Project Lightning Talk

Overview

In a KubeCon EU lightning talk, Lori Larusso and Gerald Venzl presented "Project Lightning Talk: A Hitchhiker's Guide to the CNCF Landscape," offering attendees a concise yet comprehensive tour of the vast and often overwhelming Cloud Native Computing Foundation (CNCF) ecosystem. The talk served as a practical guide to navigating the CNCF Landscape, an interactive map showcasing hundreds of projects, and critically, how to assess the health and maturity of these projects using tools like CLOMonitor. The speakers underscored the importance of understanding project lifecycle, leveraging community resources, and the tangible benefits of active participation in the cloud-native space.

Watch on YouTube

Visual summary for Project Lightning Talk: A Hitchhiker's Guide to the CNCF Landscape - Lori Larusso & Gerald Venzl by Lori Larusso, Gerald Venzl
Visual summary for Project Lightning Talk: A Hitchhiker's Guide to the CNCF Landscape - Lori Larusso & Gerald Venzl by Lori Larusso, Gerald Venzl

Key moments

  1. 0:00 Introduction, speakers, and talk agenda
  2. 1:10 Understanding CNCF: mission, numbers, and membership benefits
  3. 2:30 Brief history of CNCF and key milestones
  4. 3:20 Understanding the CNCF project lifecycle: Sandbox to Graduation
  5. 5:20 Visualizing CNCF project growth over time
  6. 6:10 Navigating the complex CNCF landscape
  7. 7:15 Practical guide: filtering projects in the CNCF landscape

Project Lightning Talk: A Hitchhiker's Guide to the CNCF Landscape

Speakers: Lori Larusso, Head of Community at Percona; Gerald Venzl, VP for Dev Initiatives at Oracle

Conference: KubeCon EU

YouTube: https://www.youtube.com/watch?v=_r7blpGA1Fw

Overview

In a KubeCon EU lightning talk, Lori Larusso and Gerald Venzl presented "Project Lightning Talk: A Hitchhiker's Guide to the CNCF Landscape," offering attendees a concise yet comprehensive tour of the vast and often overwhelming Cloud Native Computing Foundation (CNCF) ecosystem. The talk served as a practical guide to navigating the CNCF Landscape, an interactive map showcasing hundreds of projects, and critically, how to assess the health and maturity of these projects using tools like CLOMonitor. The speakers underscored the importance of understanding project lifecycle, leveraging community resources, and the tangible benefits of active participation in the cloud-native space.

This session was particularly relevant for anyone engaged with cloud-native technologies, from developers and architects seeking reliable tools to security professionals evaluating open-source component risks. With the rapid expansion of the CNCF – now boasting 28 projects, 257,000 contributors, and 756 member organizations – discerning trustworthy and production-ready solutions has become a significant challenge. Larusso and Venzl's guide provides a methodical approach to cutting through the noise, empowering users to make informed decisions about project adoption and to identify opportunities for valuable community contribution. Their insights aim to transform the complex landscape from a bewildering maze into a navigable resource for innovation and operational excellence.

Background

▶ Watch: Introduction, speakers, and talk agenda (0:00)

The journey into cloud-native computing, largely spearheaded by Kubernetes, began over a decade ago, with Google partnering with the Linux Foundation in 2014. This collaboration led to the founding of the Cloud Native Computing Foundation (CNCF) in 2015, with Kubernetes joining in 2016. Since then, the CNCF has grown exponentially, becoming the steward of a massive and diverse collection of open-source projects essential for building and operating cloud-native applications. This rapid expansion, while fostering innovation, has also created a challenge: how do users and organizations effectively navigate this ever-growing ecosystem?

The CNCF categorizes its projects into distinct maturity phases, a crucial framework for evaluating their readiness for production use:

  • Sandbox: This initial phase is for new projects with early traction and a clear alignment with the CNCF mission. It's a proving ground where projects can experiment, gather feedback, and begin to build a community. Many projects enter this phase, but not all progress further.
  • Incubating: Projects that demonstrate a healthy growth trajectory, a strong community, and increasing adoption move into incubation. At this stage, they are typically considered suitable for production use cases, though they are still maturing and evolving. They must show a consistent maintenance record and a commitment from their maintainers.
  • Graduated: This is the highest level of maturity, reserved for projects that have achieved widespread adoption, robust governance, and sustained commitment from multiple organizations. Graduated projects are expected to have thriving adoption rates, committers from at least two organizations, a documented governance process, and meet the Linux Foundation's Core Infrastructure Initiative best practices badge. These projects are considered highly reliable and stable for critical production environments.

Currently, the CNCF landscape features over 200 projects, with a significant number in the sandbox phase, a healthy contingent in incubation, and 31 projects having achieved graduation status. This structured progression provides a vital indicator of a project's stability and community support, informing users about the level of risk and commitment associated with adopting a particular technology. Beyond project maturity, the speakers highlighted that the Linux Foundation manages the CNCF, offering benefits like training credits to member organizations, an often-underutilized perk that can significantly aid in skill development and certification within the cloud-native domain.

Key Findings

▶ Watch: Brief history of CNCF and key milestones (2:30)

The central finding of Larusso and Venzl's talk is the profound utility of the CNCF Landscape as a dynamic, interactive catalog, coupled with the crucial insights provided by CLOMonitor for project evaluation. They highlighted that while the landscape can initially appear overwhelming, its sophisticated filtering capabilities transform it into an indispensable tool for targeted discovery. The speakers demonstrated how users can narrow down hundreds of projects to a manageable selection based on critical criteria such as maturity level (graduated, incubating), project status (non-archived), and specific domains (e.g., security and compliance).

A particularly significant finding was the introduction and practical application of CLOMonitor (Cloud Native Open Source Monitor). This tool moves beyond superficial metrics like GitHub stars, offering a deep, multi-faceted assessment of a project's health. It evaluates aspects ranging from documentation quality and licensing best practices to community engagement (e.g., Slack presence, meeting schedules) and crucial security practices like signed releases and token permissions. The talk effectively demonstrated that a project's CLOMonitor score, while not a definitive "good or bad" indicator, provides a transparent snapshot of its operational and security readiness, highlighting specific areas where a project excels or needs improvement.

The speakers used CubeScape and Helm as concrete examples to illustrate these points. CubeScape, a security-focused project, showed a strong CLOMonitor score of 94, yet still had identifiable areas for contribution, such as signed releases and token permissions. In contrast, Helm, a widely adopted Kubernetes package manager, presented an 86 on CLOMonitor, revealing specific deficiencies in documentation (scoring 73) and an outdated list of adopters. This demonstrated that even highly popular and graduated projects have opportunities for community contribution, directly improving their health and reliability. The key takeaway here is that proactive due diligence, facilitated by the CNCF Landscape and CLOMonitor, is paramount for selecting robust cloud-native tools and for fostering a healthier open-source ecosystem through informed contribution.

Technical Deep Dive

▶ Watch: Understanding the CNCF project lifecycle: Sandbox to Graduation (3:20)

The technical core of the talk revolved around the practical application of the CNCF Landscape and the deep analytical capabilities of CLOMonitor. The CNCF Landscape, accessible at landscape.cncf.io, is a comprehensive, interactive map categorizing all projects within the CNCF ecosystem. It visually represents the various domains of cloud-native technology, from application definition and development to orchestration, runtime, and platform management.

The speakers provided a step-by-step guide on how to effectively use the landscape's filtering mechanisms to identify relevant projects:

  1. Project Status Filtering: Users can select to view only CNCF projects, excluding archived projects which are no longer actively maintained or deemed relevant by the Technical Oversight Committee (TOC). This immediately narrows the focus to viable projects.
  2. Maturity Level Selection: A critical filter allows users to select projects based on their maturity phases: sandbox, incubating, or graduated. For production environments, focusing on "graduated" and "incubating" projects is often recommended, as these have demonstrated greater stability and community support.
  3. Category-Specific Search: The landscape allows filtering by specific categories, such as "security and compliance." This enables users to quickly identify tools relevant to particular operational needs.
  4. License Type: Users can also filter by open-source licenses, ensuring compliance with organizational policies.

Once a project is selected from the filtered list, the landscape provides a detailed profile page. This page aggregates vital information, including the number of GitHub stars (acknowledged as a "vanity metric" but still present), the total number of contributors, and the date of the last contribution. These metrics offer an initial glance at a project's popularity and activity.

However, the true technical deep dive comes from CLOMonitor. When a user clicks on a project, its CLOMonitor score and detailed report become accessible. CLOMonitor performs an automated, ongoing assessment across several critical dimensions:

  • Repository Health: Analyzes the project's GitHub repository for best practices, including .github templates, issue/PR templates, and contributing guidelines.
  • Documentation: Evaluates the presence and quality of key documentation, such as README.md, CHANGELOG.md, CODE_OF_CONDUCT.md, and LICENSE.md. For example, Helm received a 73% score for documentation, indicating specific areas for improvement.
  • License: Verifies the presence of a valid open-source license, ensuring legal clarity for adoption.
  • Community: Assesses community engagement metrics, such as the presence of a Slack channel, community meetings, and a clear governance structure. Helm's Slack presence was noted as "weird" in its CLOMonitor report.
  • Security: This is a crucial area for defenders. CLOMonitor checks for practices like signed releases and proper token permissions. For instance, CubeScape, despite its high overall score of 94, showed opportunities for improvement in these specific security areas.
  • Best Practices: Checks for adherence to general open-source best practices, including a clear roadmap and an up-to-date list of adopters. Helm was specifically called out for not having its adopter list updated.
  • Artifacts: For projects that produce deployment artifacts, such as Helm charts, CLOMonitor evaluates their quality and adherence to standards.

Each of these categories contributes to an overall CLOMonitor score (e.g., 94 for CubeScape, 86 for Helm). The report isn't just a number; it provides granular details, often with red "X" marks indicating specific deficiencies and green checkmarks for compliance. This level of detail empowers users to conduct thorough due diligence, understand a project's strengths and weaknesses, and even identify specific tasks for potential contribution, such as improving documentation or implementing signed releases. The speakers emphasized that CLOMonitor is project-specific, with projects determining when the API call comes in for updates, ensuring that the data reflects the project's current state as managed by its maintainers.

Demo / Proof of Concept

▶ Watch: Navigating the complex CNCF landscape (6:10)

The speakers conducted a live demonstration of navigating the CNCF Landscape website (landscape.cncf.io), effectively illustrating its capabilities and the insights provided by CLOMonitor. The demo began by showcasing the initial, expansive view of the landscape, which, as Lori Larusso noted, can appear "convoluted, beautiful, crazy" with "tons of projects, lots of boxes."

The first step in the demonstration was to apply filters to narrow down the project selection. The speakers clicked on the "filters" button, initiating a series of choices:

  1. CNCF Projects Only: They selected to view only projects officially part of the CNCF.
  2. Exclude Archived: Crucially, they deselected "archived" projects, focusing on those actively maintained and relevant.
  3. Maturity Filter: To find stable and production-ready projects, they filtered for "graduated" and "incubating" projects, excluding "sandbox" projects for this particular search.
  4. Category Filter (Security): Gerald Venzl then asked the audience about their interest in security, leading them to apply the "security and compliance" category filter.
  5. License Filter: They also ensured "open source" licenses were selected, though other license types are available for filtering.

After applying these filters, the vast landscape was dramatically reduced to a focused set of security-oriented, mature, and actively maintained open-source projects. This visually demonstrated the power of the filtering mechanism in transforming an overwhelming resource into a targeted list.

The speakers then proceeded to interact with specific projects to showcase the CLOMonitor reports:

  • CubeScape: They clicked on CubeScape, a security project, to reveal its detailed profile. The CLOMonitor score of 94 was highlighted, with Larusso emphasizing that this is a "great score" but not necessarily a perfect one. They scrolled down the report, pointing out specific areas of assessment: repository health, documentation, licensing, community, and security. Under the "security" section, they noted that CubeScape passed most checks but had opportunities for improvement in "signed releases" and "token permissions." Larusso playfully linked this to the audience's earlier non-response to being contributors, suggesting these as immediate areas for community involvement.
  • Helm: Next, they examined Helm, the widely used Kubernetes package manager. Despite its prevalence, Helm showed a CLOMonitor score of 86. The speakers used this as a prime example of why due diligence is essential, even for popular projects. They pointed out specific deficiencies in Helm's report: its "documentation" score was 73, and its "adopters" list was not updated. Venzl highlighted the "Slack presence" as "weird." These findings served to underscore that a lower score doesn't disqualify a project but rather indicates areas where users might need to contribute, or where the project might not fully meet specific internal requirements. Larusso even suggested a "super easy pull request" for users to update Helm's adopter list.

The live demo effectively conveyed how the CNCF Landscape and CLOMonitor function as a powerful duo, enabling users to efficiently discover, evaluate, and contribute to cloud-native projects. It demonstrated that even in a short lightning talk, these tools can provide actionable insights for navigating a complex ecosystem.

Defensive Implications

▶ Watch: Practical guide: filtering projects in the CNCF landscape (7:15)

For security professionals and organizations adopting cloud-native technologies, the insights from this talk carry significant defensive implications. The CNCF Landscape and CLOMonitor offer powerful tools to enhance supply chain security, improve risk assessment, and guide secure project adoption.

Firstly, the ability to filter projects by maturity level (especially graduated and incubating) is a primary defensive measure. Opting for projects that have undergone rigorous vetting, demonstrated sustained community support, and met the Linux Foundation's best practices (as is the case for graduated projects) significantly reduces the risk of integrating unstable, unmaintained, or potentially vulnerable components into production systems. This helps organizations prioritize reliability and security from the outset.

Secondly, CLOMonitor is an invaluable asset for open-source software supply chain security. Before adopting any cloud-native project, security teams can leverage CLOMonitor to perform detailed due diligence. Key areas of defensive interest include:

  • Security Best Practices: CLOMonitor's checks for signed releases and token permissions are critical. The absence of signed releases can indicate a vulnerability to tampering or malicious injection in the software distribution pipeline. Poor token permissions can expose repositories to unauthorized access or compromise. Identifying these gaps, as seen with CubeScape, allows defenders to either choose alternative projects, plan for compensatory controls, or contribute directly to fix the issues.
  • Maintainer Activity and Community Health: A project with an active community, multiple contributors, and a healthy governance model is generally more resilient to security vulnerabilities. CLOMonitor's insights into contributor numbers, last contribution dates, and community engagement (like active Slack channels or regular meetings) can signal whether a project is actively maintained and responsive to security reports. A project losing maintainers or with infrequent contributions poses a higher long-term security risk.
  • Documentation and Licensing: Clear documentation, including security policies and incident response procedures (though not explicitly checked by CLOMonitor, inferred from overall documentation health), is crucial for understanding how to securely operate a project. Correct and clear licensing ensures legal compliance and allows organizations to understand their rights and obligations when using the software.

Furthermore, the talk implicitly encourages a proactive defensive stance through community contribution. By identifying areas where projects like Helm have lower scores (e.g., documentation at 73% or an outdated adopter list), security teams can contribute to improving these aspects. Enhancing documentation, especially around security configurations or operational guides, directly strengthens the defensive posture for all users of that project. Contributing to security-specific fixes or implementing missing best practices (like signed releases) directly hardens the software supply chain.

Finally, understanding the benefits of CNCF membership, including access to training and certifications, empowers security professionals to stay current with the latest cloud-native security practices and tools. This continuous learning is vital for adapting to the rapidly evolving threat landscape in cloud environments. In essence, the CNCF Landscape and CLOMonitor provide a transparent, data-driven framework for making informed security decisions, fostering a more secure cloud-native ecosystem through vigilance and collaborative improvement.

Key Takeaways

  • CNCF Landscape is an essential navigation tool: The landscape.cncf.io website provides a comprehensive, interactive map of the cloud-native ecosystem, enabling users to filter and discover projects based on maturity, category, and other vital criteria.
  • CLOMonitor offers deep project health insights: This tool (Cloud Native Open Source Monitor) provides a detailed, multi-faceted assessment of project health, going beyond superficial metrics to evaluate documentation, licensing, community activity, and critical security practices like signed releases and token permissions.
  • Project maturity guides adoption decisions: The CNCF's project phases (sandbox, incubating, graduated) are crucial indicators of a project's stability and readiness for production, with graduated projects offering the highest level of reliability and community support.
  • Due diligence is paramount, even for popular projects: As demonstrated with Helm (CLOMonitor score 86), even widely adopted projects can have areas for improvement (e.g., documentation at 73%, outdated adopter lists), necessitating thorough evaluation before integration.
  • Community contribution strengthens the ecosystem: Identifying gaps in CLOMonitor reports (e.g., missing signed releases in CubeScape, or poor documentation in Helm) presents direct opportunities for users to contribute, improving the overall health, security, and sustainability of open-source projects.
  • CNCF membership offers tangible benefits: Organizations that are CNCF members can leverage perks like Linux Foundation training credits, providing valuable resources for skill development and certification in cloud-native technologies.

About the Speaker(s)

Lori Larusso is the Head of Community at Percona, a leading open-source database software and services company. She is a highly active member of the cloud-native community, serving as a CNCF ambassador, a CDF ambassador, and a DK SIG chair. Her extensive involvement in these key organizations highlights her deep commitment to fostering open-source collaboration and community growth within the cloud-native space.

Gerald Venzl holds the position of VP for Dev Initiatives at Oracle. Like Lori Larusso, he is a dedicated CNCF ambassador, contributing to the foundation's mission of making cloud-native computing ubiquitous and accessible. Additionally, Gerald sits on the S SQL standards committee, demonstrating his broad expertise in both modern cloud technologies and foundational data management standards.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This lightning talk, "A Hitchhiker's Guide to the CNCF Landscape," by Lori Larusso and Gerald Venzl, is a highly practical and impactful session for anyone navigating the sprawling cloud-native ecosystem. It provides a methodical approach to evaluating open-source projects using the CNCF Landscape and, more importantly, the CLOMonitor tool. For security professionals, this offers invaluable, actionable intelligence for supply chain risk assessment and informed project adoption, moving beyond superficial metrics to detailed health indicators. The speakers' deep expertise shines through, delivering a clear and concise guide that empowers users to make better decisions and contribute…

→ Top-rated talks at KubeCon + CloudNativeCon Europe 2025

All talks from KubeCon + CloudNativeCon Europe 2025