Graduated Project Updates - KubeCon + CloudNativeCon Europe 2025

KubeCon + CloudNativeCon Europe 2025

KubeCon + CloudNativeCon Europe 2025 · Session

Watch on YouTube

Visual summary for Graduated Project Updates - KubeCon + CloudNativeCon Europe 2025 by KubeCon + CloudNativeCon Europe 2025
Visual summary for Graduated Project Updates - KubeCon + CloudNativeCon Europe 2025 by KubeCon + CloudNativeCon Europe 2025

Key moments

  1. 0:00 Cilium 1.17, Hubble, and Tetragon updates
  2. 1:00 OPA project introduction and Rego policy example
  3. 2:16 Fluent Bit V4: smarter processors, tracing, Zig support
  4. 3:08 Rook: complete storage solution for Kubernetes with Ceph
  5. 4:09 Istio's Ambient Mesh: Z-tunnel and Waypoint proxies
  6. 4:55 Istio Ambient Mesh is generally available today

Graduated Project Updates - KubeCon + CloudNativeCon Europe 2025

Speakers: KubeCon + CloudNativeCon Europe 2025

Conference: KubeCon EU

YouTube: https://www.youtube.com/watch?v=T_EDE6DDqYc

Overview

This talk, "Graduated Project Updates," delivered at KubeCon + CloudNativeCon Europe 2025, provided a rapid-fire overview of the latest advancements and upcoming features from several foundational CNCF graduated projects. Rather than a single deep dive into one technology, the session served as a crucial update for the cloud-native community, highlighting how these mature projects continue to evolve to meet the ever-increasing demands for performance, security, observability, and resilient infrastructure. The projects featured include Cilium, Open Policy Agent (OPA), Fluent Bit, Rook, and Istio, each presenting key developments that reinforce their roles in the cloud-native ecosystem.

The updates collectively underscore the ongoing innovation within the CNCF landscape, demonstrating how these battle-tested solutions are adapting to new challenges, from securing eBPF operations and enhancing policy-as-code capabilities to optimizing telemetry pipelines and simplifying service mesh deployments. For practitioners, this talk offered a concise yet comprehensive look at the cutting edge of cloud-native development, providing actionable insights into new features that can immediately benefit their deployments. It emphasized the community-driven nature of these projects and their commitment to addressing real-world operational complexities.

Background

▶ Watch: Cilium 1.17, Hubble, and Tetragon updates (0:00)

The rapid evolution of cloud-native architectures, characterized by microservices, containers, and Kubernetes, has introduced both unprecedented agility and significant operational complexities. Each of the projects highlighted in these updates emerged to address specific, critical challenges within this dynamic environment.

Cilium was born from the need for advanced networking and security capabilities that could keep pace with the ephemeral nature of containerized workloads. Traditional network overlays struggled with performance and granular policy enforcement at scale. Cilium leverages eBPF (extended Berkeley Packet Filter), a powerful in-kernel technology, to provide high-performance networking, load balancing, and security observability without modifying application code or requiring sidecars for basic network functions.

Open Policy Agent (OPA) addresses the pervasive challenge of consistent policy enforcement across heterogeneous environments. As applications become distributed and deployed across various platforms (Kubernetes, APIs, CI/CD pipelines, databases), maintaining uniform authorization and governance rules becomes a monumental task. OPA provides a unified, declarative policy language, Rego, to externalize policy decisions from application logic, enabling organizations to implement "policy as code" and centralize their authorization frameworks.

Fluent Bit emerged as a solution to the exploding volume of telemetry data (logs, metrics, traces) generated by cloud-native systems. While essential for observability, inefficient data collection and processing can overwhelm infrastructure, leading to delayed insights and increased operational costs. Fluent Bit was designed to be a lightweight, high-performance telemetry pipeline, capable of efficiently collecting, processing, and routing data from diverse sources to various destinations, specifically optimized for resource-constrained environments like edge devices or containers.

Rook tackles the critical problem of persistent storage in Kubernetes. While Kubernetes provides orchestration for stateless applications, stateful workloads require robust, highly available storage solutions that are natively integrated with the orchestrator. Rook transforms commodity hardware into an enterprise-grade storage platform within Kubernetes, leveraging established storage technologies like Ceph to provide block, file, and object storage. It simplifies the deployment and management of complex storage systems, making them cloud-native.

Finally, Istio was developed to address the inherent complexities of microservices communication, offering a service mesh to secure, control, and observe traffic between services. While powerful, early service mesh implementations often faced criticism for their operational overhead and resource consumption due to the sidecar proxy model. Istio's evolution has been driven by the need to deliver the benefits of a service mesh (mTLS, traffic management, observability) with reduced complexity and a lighter operational footprint.

Together, these projects represent the ongoing effort within the cloud-native community to mature the ecosystem, providing robust, scalable, and secure foundations for modern applications.

Key Findings

▶ Watch: Fluent Bit V4: smarter processors, tracing, Zig support (2:16)

The "Graduated Project Updates" session unveiled a series of significant advancements across five pivotal CNCF projects, each contributing to enhanced performance, security, and operational efficiency within cloud-native environments.

Cilium announced the release of Cilium 1.17, bringing a host of new networking features and performance enhancements. A highlight was the continued evolution of Tetragon, its runtime security component, which now boasts the ability to detect suspicious activity on the system and, critically, to audit and protect eBPF operations themselves. This represents a significant step forward in securing the eBPF layer. The project's recognition by the CNCF Technology Landscape Radar as a top choice for multicluster environments, alongside 24 new case studies, underscored its widespread adoption. Hubble, Cilium's observability component, also received updates with dynamic metric configuration and new metrics for deeper network visibility.

Open Policy Agent (OPA) showcased its growing versatility in enabling "policy as code" across a broader range of applications, from traditional user authorization and Kubernetes admission control to emerging use cases like AI system guard rails. The core finding was the continuous refinement of its purpose-built policy language, Rego, making it easier and more consistent for developers and operators to implement complex policies across diverse tools and frameworks.

Fluent Bit unveiled Fluent Bit V4, a major release focused on enhancing its performance and capabilities as a lightweight telemetry pipeline. Key findings included the introduction of smarter processors with new conditional logic, significantly increasing flexibility and power in data transformation. V4 also brings advanced tracing with tail sampling, crucial for efficient debugging in high-volume environments, and Zig language support for developers, expanding its extensibility. Enhanced security features for enterprise deployments and further performance improvements solidify its position.

Rook highlighted several advancements in its Kubernetes storage solution, particularly around its integration with Ceph. For object storage, the updates included more flexible S3 bucket policy configurations, enhanced RGW (Rados Gateway) configuration, and support for multiple object stores with shared Ceph pools. The CSI (Container Storage Interface) driver was improved with the addition of volume group snapshots, ensuring data consistency across multiple volumes. Furthermore, Rook now supports mirroring across clusters for Rados namespaces, complementing existing mirroring for pools and images, which significantly boosts disaster recovery and data availability strategies. The upcoming Rook version 1.17 was also teased.

Finally, Istio presented its innovative Ambient Mesh architecture, directly addressing the common perception of service meshes being "too complex, too heavy." The key finding is Istio's successful re-architecture into a layered model that promises all the value of a service mesh with significantly reduced operational overhead. This model introduces Z-tunnel for transparent mTLS and low-level routing, and optional Waypoint proxies (based on Envoy) for higher-level API management and policies. This layered approach makes Ambient Mesh safer to roll out, easier to adopt, and more cost-effective, with the significant announcement that it is now GA (Generally Available).

Technical Deep Dive

▶ Watch: Rook: complete storage solution for Kubernetes with Ceph (3:08)

The technical advancements presented across the graduated projects showcase sophisticated engineering solutions to fundamental cloud-native challenges.

Cilium's technical core revolves around eBPF, which allows for programmable kernel-level networking and security. With Cilium 1.17, the project extends its robust network policy enforcement and load balancing capabilities, particularly benefiting multicluster environments. The most significant technical deep dive comes from Tetragon, Cilium’s runtime security engine. Tetragon leverages eBPF to observe and enforce policies on system calls, process executions, file accesses, and network events at a granular level. The new capability to audit and protect eBPF operations is a breakthrough. This involves Tetragon monitoring the loading and execution of eBPF programs themselves, ensuring that only authorized and legitimate eBPF code can run, thus preventing malicious eBPF injections or manipulations that could bypass traditional security controls. This adds a crucial layer of self-protection to the eBPF data plane. Hubble, Cilium's observability platform, further enhances visibility by leveraging eBPF to extract rich network flow data directly from the kernel, now with dynamic metric configuration.

Open Policy Agent (OPA) provides a declarative policy language called Rego. Rego policies are essentially data-driven rules that define what is allowed or denied. For instance, a policy to allow staff to update their own profiles would check user roles and resource ownership. OPA functions as an API-based decision engine, where applications query OPA for policy decisions, separating policy logic from application code. This enables consistent policy enforcement across diverse services, from Kubernetes admission controllers that validate resource deployments to API gateways and even custom applications. The concept of "guard rails around AI systems" suggests using OPA to enforce ethical guidelines, data access controls, or operational parameters for AI models.

Fluent Bit V4 introduces several technical advancements for its telemetry pipeline. The smarter processors with new conditional logic allow for more sophisticated data transformation and filtering. Operators can now define rules like "if a log message contains 'ERROR', then enrich it with X metadata and route it to Y destination, otherwise route it to Z." This conditional logic is critical for managing data volume and ensuring relevant data reaches the correct analysis tools. Advanced tracing with tail sampling is a key feature for performance and cost optimization. In high-volume distributed systems, collecting every trace can be prohibitively expensive. Tail sampling allows for intelligent selection of traces to be retained based on attributes observed at the end of the trace (e.g., only keep traces that resulted in an error or exceeded a certain latency threshold), ensuring critical traces are analyzed without overwhelming the system. The addition of Zig language support extends Fluent Bit's plugin ecosystem, offering developers a powerful, low-level language for writing high-performance data processing modules.

Rook's technical improvements focus on enhancing its robust Ceph integration for Kubernetes storage. The expanded S3 bucket policy support allows for more granular access control directly on object storage buckets, aligning with AWS S3 policy syntax for familiar management. More flexible RGW (Rados Gateway) configuration gives administrators greater control over the S3-compatible object storage interface. The ability to run multiple object stores with shared Ceph pools improves resource utilization and simplifies management. For CSI (Container Storage Interface), the introduction of volume group snapshots is a significant feature for data consistency. When an application uses multiple persistent volumes, a group snapshot ensures that all volumes are snapshotted at the exact same point in time. Finally, mirroring across clusters for Rados namespaces extends Ceph's disaster recovery capabilities. This allows entire namespaces of object data to be replicated between geographically dispersed Ceph clusters, ensuring high availability and resilience.

Istio's Ambient Mesh represents a fundamental architectural shift. The core innovation is splitting the service mesh data plane into two layers:

  1. Z-tunnel: This is a lightweight, transparent proxy responsible for mTLS (mutual TLS) encryption and low-level L4 routing. It operates at the node level, intercepting all traffic and establishing secure, encrypted connections between services without requiring a sidecar proxy per application pod. The transcript notes it "uses less CPU and has higher throughput than IB or WireGuard for the same traffic," implying a highly optimized L4 proxy.
  2. Waypoint proxies: These are optional, dedicated proxies, typically based on Envoy, that are deployed per service account or namespace. They handle higher-level L7 policies, such as traffic management (routing, retries, circuit breaking), advanced observability (metrics, tracing), and API management.

This layered model means that basic mTLS and L4 security are always on by default with minimal overhead, while L7 functionality can be added incrementally and selectively, providing a "pay-as-you-go" service mesh experience. This approach drastically simplifies adoption, reduces operational burden, and makes the service mesh infrastructure "hidden within your platform."

Demo / Proof of Concept

▶ Watch: Istio's Ambient Mesh: Z-tunnel and Waypoint proxies (4:09)

The "Graduated Project Updates" session primarily focused on announcing new features and architectural advancements rather than live, interactive demonstrations. However, Open Policy Agent (OPA) provided a concise, conceptual example to illustrate its core functionality.

The OPA demonstration involved a hypothetical scenario: a request from a user named Alice attempting to update an employee profile. The objective was to show how OPA's Rego policy language could enforce a rule allowing staff members to update only their own employee profiles.

The example presented two distinct outcomes:

  1. Allowed Access: When Alice, identified as a staff member, attempted to update her own profile, the policy evaluated her request against the defined rules. The rules would check if Alice's role included "staff" and if the user ID associated with the request matched the profile ID she intended to update. In this case, both conditions were met, and OPA returned an "allowed" decision.
  2. Denied Access: In contrast, when Alice attempted to update Bob's profile, the policy evaluation would find that while Alice was a staff member, the user ID in the request did not match the profile ID of Bob's profile. Consequently, OPA returned a "denied" decision, preventing the unauthorized update.

This simple yet effective example served as a proof of concept for OPA's ability to provide fine-grained, attribute-based access control and to enforce "policy as code." While not a live, interactive demo with a running system, it clearly articulated how OPA integrates with applications as an API-based decision service, allowing for consistent and externalized policy enforcement. The other projects presented their updates through verbal announcements and feature lists, indicating their new capabilities without a specific demo segment in this rapid-fire format.

Defensive Implications

▶ Watch: Istio Ambient Mesh is generally available today (4:55)

The updates from these graduated projects offer significant defensive implications for organizations operating cloud-native environments, enhancing security postures across networking, access control, observability, and data resilience.

Cilium and its Tetragon component provide powerful defensive capabilities. Cilium's eBPF-powered network policies enable highly granular, identity-aware segmentation, allowing defenders to restrict communication between workloads based on their identity rather than just IP addresses. Tetragon's new ability to audit and protect eBPF operations is a critical defensive innovation. By monitoring and enforcing policies on eBPF program loading and execution, Tetragon acts as a self-defense mechanism for the eBPF data plane itself, preventing sophisticated attackers from manipulating the kernel's eBPF capabilities for evasion or privilege escalation.

Open Policy Agent (OPA) is a cornerstone for implementing robust "policy as code" and zero-trust principles. By externalizing authorization logic with Rego, OPA allows defenders to define and enforce consistent security policies across the entire cloud-native stack, from Kubernetes admission control (preventing misconfigurations or insecure deployments) to API authorization and CI/CD pipelines. This consistency eliminates policy silos and reduces the risk of misconfigured access controls. The ability to add "guard rails around AI systems" highlights its potential for emerging defensive applications.

Fluent Bit V4 contributes to defensive strategies primarily through enhanced observability and security of telemetry data. Its new enterprise security features, though not detailed, suggest improvements in secure data handling and access controls. Efficient and secure collection of logs, metrics, and traces is fundamental for threat detection, incident response, and forensic analysis. The conditional logic in processors allows security teams to intelligently filter and route security-relevant events, ensuring that critical alerts are processed promptly.

Rook's advancements bolster data integrity and availability, which are vital for defensive resilience. The introduction of volume group snapshots ensures that backup and recovery processes for stateful applications maintain data consistency across all associated volumes. More importantly, mirroring across clusters for Rados namespaces provides a robust disaster recovery mechanism for object storage. In the event of an outage, critical data can be rapidly restored from a mirrored cluster, significantly reducing downtime and data loss.

Istio's Ambient Mesh architecture offers substantial defensive improvements by making mTLS (mutual TLS) significantly easier to adopt and manage. With Z-tunnel providing transparent mTLS for L4 traffic by default, defenders gain automatic, pervasive encryption and strong identity verification for all service-to-service communication. This eliminates the need for applications to manage certificates, reduces the attack surface, and ensures that only authenticated and authorized services can communicate. The optional Waypoint proxies allow security teams to selectively apply advanced L7 policies, such as request authorization, rate limiting, and egress controls, where deeper inspection is required, without incurring the overhead of a full sidecar mesh for every workload.

Key Takeaways

  • Cilium 1.17 and Tetragon's eBPF Protection: Cilium continues to advance eBPF-powered networking and security, with Tetragon now capable of auditing and protecting eBPF operations, adding a critical layer of self-defense for the kernel data plane.
  • OPA for Unified Policy as Code: Open Policy Agent (OPA) and its Rego language offer a consistent framework for policy enforcement across diverse cloud-native systems, including Kubernetes admission, API authorization, and emerging AI guard rails.
  • Fluent Bit V4's Enhanced Telemetry: Fluent Bit V4 delivers significant improvements in telemetry processing with conditional logic, advanced tracing via tail sampling, Zig language support, and enhanced enterprise security features for efficient and secure observability.
  • Rook's Robust Storage for Kubernetes: Rook enhances its Ceph-based storage solution with flexible S3 bucket policies, volume group snapshots for data consistency, and cross-cluster mirroring for Rados namespaces, bolstering data resilience and disaster recovery.
  • Istio Ambient Mesh Simplifies Service Mesh: Istio's new Ambient Mesh architecture provides a layered approach with Z-tunnel for transparent mTLS and optional Waypoint proxies for L7 policies, making service mesh adoption easier, more cost-effective, and less resource-intensive, now generally available.
  • Continuous Innovation in Graduated Projects: The updates demonstrate the ongoing commitment of CNCF graduated projects to address evolving cloud-native challenges, delivering mature, high-performance, and secure solutions.

About the Speaker(s)

The "Graduated Project Updates" session featured key contributors and maintainers from the respective CNCF projects, providing direct insights into their latest developments.

  • Liz Rice, associated with Cilium, opened the session, delivering updates on Cilium and its related components, Hubble and Tetragon. As a prominent figure in the cloud-native and eBPF communities, Liz Rice is known for her deep expertise in networking and security technologies.
  • Charlie, representing the Open Policy Agent (OPA) team, presented the advancements in OPA, highlighting its policy-as-code capabilities and the Rego language.
  • A representative from the Fluent Bit project provided an overview of the new features in Fluent Bit V4, focusing on its role as a high-performance telemetry pipeline.
  • Travis Rook, a maintainer with IBM, discussed the latest updates for Rook, the Kubernetes storage operator, emphasizing its Ceph integration and new features for data management and resilience.
  • Lou, one of the maintainers of Istio, closed the session by introducing the revolutionary Ambient Mesh architecture, explaining its benefits in simplifying service mesh deployments.

These speakers collectively represent the leadership and technical depth behind some of the most impactful graduated projects within the Cloud Native Computing Foundation.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This KubeCon session delivered a rapid-fire, highly substantive overview of critical advancements across several CNCF graduated projects: Cilium, OPA, Fluent Bit, Rook, and Istio. Far from rehashed content, the updates detailed significant technical evolutions, from Cilium's eBPF self-protection via Tetragon and Istio's GA Ambient Mesh architecture to Fluent Bit V4's advanced telemetry and Rook's enhanced Ceph mirroring. The talk provided invaluable, actionable insights for practitioners managing cloud-native infrastructure, showcasing continuous innovation in foundational tools.

Heather Calloway (CISO) — STRONG ACCEPT

This rapid-fire update on key CNCF graduated projects delivers critical intelligence for security leaders. It highlights mature, battle-tested solutions evolving to address core challenges in governance, resilience, and operational security. While the format necessitates brevity, the advancements in policy-as-code, eBPF protection, simplified service mesh, and robust storage directly inform strategic risk management and institutional accountability in cloud-native environments.

→ Top-rated talks at KubeCon + CloudNativeCon Europe 2025

All talks from KubeCon + CloudNativeCon Europe 2025