Quantum-Ready Kubernetes: How Do We Get There?
KubeCon + CloudNativeCon Europe 2025 · Session
Overview
This panel discussion at KubeCon EU delves into the burgeoning intersection of quantum computing and Kubernetes, exploring the critical steps required to prepare cloud-native ecosystems for a quantum-safe future. Featuring experts from Broadcom, VMware, IBM Research, Keyfactor, and CERN, the talk unpacks the theoretical and practical implications of integrating quantum workloads and securing existing infrastructure against future quantum threats. The panelists collectively emphasize that while quantum computing may seem distant, proactive preparation is essential to avoid significant security and operational challenges down the line.

Key moments
- 0:00 Introduction: Quantum Computing and Kubernetes Challenge
- 2:10 Quantum Hype vs. Real-World Cloud Services
- 3:00 CERN's Two Main Quantum Computing Initiatives
- 4:15 US Government Mandates & Practical Quantum Use Cases
- 5:55 Quantum's Impact on Kubernetes Asymmetric Cryptography
- 6:40 Cryptographic Inventory (C-SBOMs) & Harvest-Now-Decrypt-Later
- 7:55 Ongoing Community Work on Post-Quantum Cryptography
Quantum-Ready Kubernetes: How Do We Get There?
Speakers: Nikita, Principal Engineer, Broadcom; Natalie Fischer, Product Manager, VMware by Broadcom; Nigel Jones, IBM Research; Thomas Koson, Chief PKI Officer, Keyfactor; Ricardo, Platforms Infrastructure Team Lead, CERN
Conference: KubeCon EU
YouTube: https://www.youtube.com/watch?v=SsTUGO9YbnQ
Overview
This panel discussion at KubeCon EU delves into the burgeoning intersection of quantum computing and Kubernetes, exploring the critical steps required to prepare cloud-native ecosystems for a quantum-safe future. Featuring experts from Broadcom, VMware, IBM Research, Keyfactor, and CERN, the talk unpacks the theoretical and practical implications of integrating quantum workloads and securing existing infrastructure against future quantum threats. The panelists collectively emphasize that while quantum computing may seem distant, proactive preparation is essential to avoid significant security and operational challenges down the line.
The discussion highlights two primary facets of this transition: first, the urgent need to address post-quantum cryptography (PQC) to safeguard data and communications against quantum attacks, and second, how Kubernetes can effectively orchestrate the complex, hybrid classical-quantum workloads that will define the next era of computation. The speakers underscore that quantum computing is not poised to replace classical systems but rather to augment them, necessitating a robust, agile, and secure integration strategy within the cloud-native landscape. This forward-looking conversation serves as a critical call to action for the Kubernetes and broader open-source communities to begin shaping the standards, tools, and practices for a quantum-ready future.
Background
▶ Watch: Introduction: Quantum Computing and Kubernetes Challenge (0:00)
The emergence of quantum computing, once largely confined to theoretical research, is rapidly transforming into a tangible reality with significant implications for cybersecurity and high-performance computing. While the "AI hype" has dominated recent technological discourse, the panelists stress the urgency of initiating conversations around quantum now to avoid future crises. The core problem stems from the vulnerability of most modern asymmetric cryptography – the bedrock of internet security – to quantum attacks. Algorithms like RSA, Elliptic Curve Cryptography (ECC), and Diffie-Hellman rely on mathematical problems that are computationally intractable for classical computers but can be efficiently broken by a sufficiently powerful quantum computer using algorithms such as Shor's algorithm.
This looming threat is underscored by concrete governmental directives, such as the US government's 2022 announcement mandating support for quantum computing by 2035. This timeline, coupled with the "harvest now, decrypt later" threat model – where adversaries can capture encrypted data today and decrypt it once quantum computers are mature – necessitates immediate action. Organizations like CERN are already deeply involved in quantum initiatives, not just in developing algorithms but also in managing these complex workloads. IBM, a pioneer in quantum computing, offers quantum services in the cloud, allowing researchers and developers to experiment with these systems. The historical parallel with the AI boom serves as a reminder that cloud-native technologies, particularly Kubernetes, are expected to adapt and integrate new paradigms rather than be replaced, making the current efforts to define a quantum-ready strategy crucial.
Key Findings
▶ Watch: CERN's Two Main Quantum Computing Initiatives (3:00)
The panel identified several key findings and insights regarding the path to quantum-ready Kubernetes:
- Quantum Computing will Augment, Not Replace: A central theme was that quantum computers are specialized tools designed to solve specific, complex problems that are intractable for classical computers. They will not replace traditional computing but will instead augment existing classical systems, forming hybrid workloads where classical machines handle pre- and post-processing, and quantum processors tackle the computationally intensive core.
- Urgent Transition to Post-Quantum Cryptography (PQC) is Imperative: The vulnerability of current asymmetric cryptographic algorithms (RSA, ECC) to quantum attacks necessitates a rapid and widespread migration to post-quantum cryptographic (PQC) algorithms. This transition is not merely an upgrade but a fundamental shift in how security is implemented across all layers of the cloud-native stack, including mTLS, digital signatures, JSON Web Tokens (JWTs), and code signing.
- Kubernetes is Essential for Orchestrating Hybrid Quantum Workloads: Just as Kubernetes has proven indispensable for orchestrating AI/ML workloads, it will play a critical role in managing and deploying hybrid classical-quantum applications. Its flexibility and extensibility make it a suitable platform for controlling the complex lifecycle of quantum experiments, from resource allocation to data retrieval and integration with classical components.
- Cryptographic Agility is a Foundational Requirement: Future-proofing systems requires cryptographic agility, meaning the ability to easily update and switch cryptographic algorithms without extensive code changes or infrastructure overhauls. Hardcoding specific algorithms like RSA or EC is no longer viable; systems must be designed for configurability and rapid adaptation to new PQC standards.
- Significant Challenges Remain in Standardization and Resource Management: The quantum computing landscape is still nascent, lacking comprehensive standardization for workload definition, costing models, and device interfaces. This makes procurement, resource allocation, and interoperability between different quantum hardware providers extremely challenging. The scarcity of quantum computing resources further complicates development and deployment efforts.
- Community and Open Source Collaboration are Crucial: The scale of the quantum transition demands collaborative efforts across the open-source community. Projects like OpenSSL are already integrating PQC algorithms, and initiatives within the Linux Foundation (e.g., PQCA) and the CNCF are vital for developing shared standards, tools, and best practices.
Technical Deep Dive
▶ Watch: US Government Mandates & Practical Quantum Use Cases (4:15)
The technical discussion centered on two main areas: securing existing systems with post-quantum cryptography (PQC) and orchestrating quantum workloads within a Kubernetes environment.
Securing with Post-Quantum Cryptography
The fundamental challenge lies in the fact that virtually all modern security in Kubernetes and the broader cloud-native ecosystem relies on asymmetric cryptography (e.g., RSA, ECC), which is vulnerable to quantum attacks. The transition to PQC involves:
- Cryptographic Agility: This is paramount. Systems must be designed to be agile, allowing for easy updates and changes to cryptographic algorithms. This means moving away from hardcoding specific algorithms (like RSA or EC) in applications and infrastructure components. Instead, configurations should enable dynamic selection and updates of cryptographic primitives as new PQC standards mature.
- PQC Algorithms: The National Institute of Standards and Technology (NIST) has standardized initial quantum-safe algorithms, such as ML-DSA (for digital signatures) and ML-KEM (for key establishment). Open-source projects are already integrating these:
- The Post-Quantum Cryptography Association (PQCA), a Linux Foundation project, is working on high-assurance implementations of these standard-track algorithms.
- OpenSSL 3.5, for example, is expected to add support for some PQC algorithms, which will then filter up through the software stack. Project maintainers must be aware of these dependencies and ensure their projects can leverage these updates.
- Cryptographic Inventory (C-SBOMs): Just as Software Bill of Materials (SBOMs) are crucial for supply chain security, Cryptographic Bill of Materials (C-SBOMs) are emerging as a standard to document cryptographic usage within software components. Understanding what cryptography is being used, where, and for what purpose is the first step in identifying vulnerabilities and prioritizing the PQC migration effort. This helps address the "harvest now, decrypt later" threat by identifying high-value, long-lived data that needs immediate protection.
- Infrastructure Modernization: A prerequisite for PQC adoption is modernizing the underlying infrastructure. This includes ensuring TLS 1.3 is widely adopted, as it offers better cryptographic agility and security features compared to older versions like TLS 1.2. Components within Kubernetes clusters must also be easily upgradable and not stuck with legacy cryptographic implementations.
- Resource Implications: PQC algorithms often involve larger key sizes and potentially larger packet sizes compared to their classical counterparts. This can lead to increased resource consumption (e.g., CPU, bandwidth) for certain operations. While this might be negligible for many applications, it could have a significant impact on very high-volume transactions or resource-constrained environments. Early testing and experimentation are crucial to understand these performance implications.
Running Quantum Workloads on Kubernetes
Kubernetes' role in orchestrating quantum workloads is primarily focused on managing hybrid classical-quantum scenarios:
- Hybrid Workload Management: Quantum computing is not a standalone solution; it integrates with classical computing. This means pre-processing data on classical machines, sending relevant parts to a quantum computer for specialized computation, and then performing post-processing and analysis back on classical systems. Kubernetes is seen as the ideal orchestrator for these complex, multi-stage workflows.
- CERN's Approach: Ricardo from CERN provided concrete examples:
- Beam Calibration: Using quantum algorithms to calibrate proton beams in particle accelerators, a task that requires live, high-speed optimization. This involved validating quantum algorithms with a live proton beam.
- Quantum Machine Learning (QML): Applying QML to Higgs boson analysis, where classical machine learning algorithms are used for dimensionality reduction of complex detector data, followed by quantum algorithms for deeper analysis. This hybrid approach addresses the current limitation of quantum computers regarding problem dimensionality.
- Remote Quantum Resources: Quantum computers are typically not on-site; they are accessed remotely, often through cloud providers. This necessitates an HPC (High-Performance Computing)-like integration model where workloads are submitted to remote quantum services, and results are fetched back. Kubernetes, with its capabilities for managing external services and multi-cluster deployments, is well-suited to bridge this gap.
- Orchestration Challenges: Despite Kubernetes' strengths, integrating quantum workloads presents unique challenges:
- Lack of Standardization: There is no universal standard for defining units of computation, measuring workload efficiency, or costing across different quantum computer providers. This makes procurement, resource allocation, and performance comparison difficult.
- Device-Specific Algorithms: Many quantum algorithms are optimized for specific quantum hardware architectures, leading to a lack of portability and requiring careful management of which workloads run on which devices.
- API Inconsistencies: Quantum computer providers currently offer diverse APIs, complicating integration into a unified Kubernetes-managed workflow. Standardized APIs would greatly benefit the ecosystem.
- Resource Scarcity: Access to quantum computers is limited, mirroring the current scarcity of GPUs for AI/ML workloads, making efficient scheduling and access management critical.
IBM's Nigel Jones highlighted that Kubernetes is critical even for quantum service providers. The actual quantum computation is a small part; the bulk involves pre- and post-processing, control, CI/CD, logging, and authentication – all of which rely heavily on Kubernetes.
Demo / Proof of Concept
▶ Watch: Cryptographic Inventory (C-SBOMs) & Harvest-Now-Decrypt-Later (6:40)
As a panel discussion, the session did not feature a live technical demonstration or proof of concept in the traditional sense. However, the panelists discussed several real-world applications and tools that serve as practical examples of quantum computing in action and the ongoing efforts to make it accessible.
Ricardo from CERN provided compelling examples of quantum computing being applied to significant scientific challenges:
- Beam Calibration: At CERN, quantum algorithms have been investigated and validated with a live proton beam to optimize the calibration of particle accelerator beams. This represents a tangible application where quantum computation offers a potential advantage for a highly complex, real-time problem.
- Quantum Machine Learning for Higgs Analysis: In the realm of high-energy physics, CERN is exploring quantum machine learning algorithms for the analysis of data from particle detectors, particularly in the context of Higgs boson discovery. This involves a hybrid approach where classical machine learning is used for initial data reduction due to the dimensionality constraints of current quantum hardware, with quantum algorithms then performing more specialized analysis.
Beyond CERN, other practical applications were mentioned:
- Drug Discovery: Pharmaceutical companies like Pfizer are reportedly using quantum computing to test molecules, accelerating research and development processes.
- Logistics Optimization: Quantum algorithms, often in conjunction with AI, are being explored for optimizing routes and supply chain logistics, aiming for greater efficiency.
For developers and researchers interested in getting started, the Kiskit SDK was highlighted. Kiskit is an open-source toolkit developed by IBM for developing quantum applications. It allows users to write quantum programs that can be run on quantum simulators or actual quantum hardware accessible via cloud services. This toolkit serves as a crucial entry point for experimentation and learning, enabling individuals to explore quantum algorithms and their potential applications without needing direct access to physical quantum computers initially. These examples collectively illustrate that quantum computing is moving beyond theoretical pursuit into practical, albeit early-stage, real-world deployments.
Defensive Implications
▶ Watch: Ongoing Community Work on Post-Quantum Cryptography (7:55)
The insights from this panel provide critical guidance for defenders preparing for the quantum era. The primary defensive implication revolves around the urgent need for a proactive and strategic approach to post-quantum cryptography (PQC) and the secure orchestration of future workloads.
- Conduct a Cryptographic Inventory (C-SBOMs): Defenders must gain a comprehensive understanding of all cryptographic algorithms currently in use across their entire infrastructure, applications, and data. Implementing or adopting C-SBOMs (Cryptographic Bill of Materials) is crucial for this. This inventory will help identify where asymmetric cryptography (RSA, ECC) is used, which is vulnerable to quantum attacks.
- Prioritize Data Protection against "Harvest Now, Decrypt Later": Not all data has the same lifespan or value. Defenders should identify and prioritize high-value, long-lived data that, if captured today, would still be sensitive and valuable in 5-10 years. This data is particularly vulnerable to the "harvest now, decrypt later" threat, where encrypted information is intercepted now and stored, awaiting decryption by future quantum computers. Applying PQC to protect such data should be an immediate priority.
- Implement Cryptographic Agility: Design and build systems with cryptographic agility as a core principle. This means avoiding hardcoding cryptographic algorithms and instead ensuring that cryptographic primitives and protocols can be easily updated and swapped out without significant architectural changes. This will be vital for a smooth transition to PQC standards as they evolve and mature. Platform engineers should advocate for configurable crypto in all components.
- Modernize Infrastructure and Dependencies: Ensure the underlying infrastructure supports modern security protocols. Specifically, migrating to TLS 1.3 is a critical step, as it offers enhanced security and better cryptographic agility. Project maintainers and platform teams should also ensure their dependencies (e.g., OpenSSL) are up-to-date and integrating PQC support as it becomes available (e.g., OpenSSL 3.5).
- Prepare for Resource Impact of PQC: Be aware that PQC algorithms may involve larger key sizes and increased computational overhead. Defenders should start planning for potential impacts on network bandwidth, CPU utilization, and storage, especially for high-volume or resource-constrained environments. Early testing with PQC implementations can help identify and mitigate these performance bottlenecks.
- Engage with Open Source and Community Initiatives: The quantum transition is a collective effort. Defenders should actively participate in and monitor open-source projects (like those under the PQCA and OpenSSL) that are developing and integrating PQC. Engaging with community forums, such as potential new CNCF working groups on quantum, will provide valuable insights and opportunities to shape future standards and best practices.
- Start Experimenting and Learning: Encourage security teams and developers to begin experimenting with quantum computing toolkits like Kiskit SDK. Understanding the fundamentals of quantum computing and its unique properties will be crucial for anticipating threats and designing effective defenses. Access to quantum services through public cloud providers makes this experimentation accessible.
- Consider Ethical Implications: The panel briefly touched on the ethical considerations of releasing powerful quantum capabilities. While not a direct defensive action, security professionals should be aware of the broader societal implications and advocate for responsible development and deployment of quantum technologies to minimize potential misuse.
Key Takeaways
- Quantum computing will augment, not replace, classical systems: It's a specialized tool for specific problems, leading to a future of hybrid classical-quantum workloads.
- The transition to post-quantum cryptography (PQC) is urgent and critical: Modern asymmetric cryptography is vulnerable to quantum attacks, necessitating a proactive and widespread migration to quantum-safe algorithms.
- Kubernetes is indispensable for orchestrating hybrid quantum workloads: Its flexibility and extensibility make it the ideal platform for managing the complex interplay between classical pre/post-processing and quantum computation.
- Cryptographic agility is a foundational requirement for future-proofing systems: Designing systems that can easily update and switch cryptographic algorithms is crucial to adapt to evolving PQC standards.
- Significant challenges in standardization and resource management persist: The nascent quantum ecosystem lacks uniform standards for workload definition, costing, and device interfaces, and access to quantum hardware remains scarce.
- Proactive learning and community involvement are essential: Individuals and organizations should start learning about quantum computing, experiment with available toolkits, and contribute to open-source initiatives to help shape the quantum-ready future.
About the Speaker(s)
The panel brought together a diverse group of experts from leading technology companies and research institutions:
- Nikita (Principal Engineer, Broadcom): The moderator for the panel, Nikita has extensive experience in the Kubernetes space and is now deeply interested in quantum computing, aiming to foster more discussion on the topic at events like KubeCon.
- Natalie Fischer (Product Manager, VMware by Broadcom): Working alongside Nikita in the Kubernetes area stack, Natalie brings a product management perspective to the challenges of integrating quantum computing into cloud-native environments.
- Nigel Jones (IBM Research): Involved in post-quantum cryptography and quantum services at IBM, Nigel focuses on making quantum capabilities available through the cloud and understanding the intersection of quantum and AI. He also works with the Post-Quantum Cryptography Association (PQCA).
- Thomas Koson (Chief PKI Officer, Keyfactor): With 30 years of experience in cybersecurity, public key infrastructure (PKI), and open source, Thomas is deeply engaged in the hottest topics surrounding PQC standardization and cryptographic agility.
- Ricardo (Platforms Infrastructure Team Lead, CERN): Ricardo leads the platforms infrastructure team at CERN, overseeing cloud-native and machine learning deployments, and is now actively exploring quantum computing management. He is involved in CERN's Open Quantum Institute and Quantum Technology Initiative, and also a member of the CNCF Technical Oversight Committee (TOC).
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
This panel cut through the usual future-tech fluff, providing a genuinely useful and urgent call to action for the cloud-native community regarding quantum computing. Instead of shallow hype, it delivered concrete insights on post-quantum cryptography (PQC) migration, the "harvest now, decrypt later" threat, and Kubernetes' role in orchestrating hybrid classical-quantum workloads. The speakers, particularly those from CERN and IBM Research, brought much-needed credibility and real-world examples, making this a critical strategic briefing for anyone building or defending modern infrastructure.
Heather Calloway (CISO) — STRONG ACCEPT
This panel provides a crucial strategic overview for security leaders grappling with the long-term implications of quantum computing. It effectively translates the theoretical threat of quantum attacks into concrete governance and business risks, emphasizing the immediate imperative for post-quantum cryptography adoption and the critical role of Kubernetes in orchestrating future hybrid workloads. While not a deep technical guide, it delivers clear, actionable directives for CISO and security programs to begin planning for a quantum-safe future, underscoring the need for cryptographic agility and a comprehensive cryptographic inventory.