KubeEdge DeepDive: Architecture, Use Cases, and Project Graduation Updates - Fei Xu & Hongbing Zhang

Fei Xu, Hongbing Zhang

KubeCon + CloudNativeCon Europe 2025 · Session

Overview

This talk provides a comprehensive deep dive into KubeEdge, a pioneering cloud-native edge computing project, covering its architecture, diverse use cases, and significant milestone of achieving CNCF graduation. Presented by Fei Xu, a full-time maintainer of the KubeEdge project, and Hongbing Zhang from Huawei Cloud, the session illuminates how KubeEdge extends Kubernetes capabilities to the edge, addressing the unique challenges of distributed environments with unstable network connectivity and resource constraints.

Watch on YouTube

Visual summary for KubeEdge DeepDive: Architecture, Use Cases, and Project Graduation Updates - Fei Xu & Hongbing Zhang by Fei Xu, Hongbing Zhang
Visual summary for KubeEdge DeepDive: Architecture, Use Cases, and Project Graduation Updates - Fei Xu & Hongbing Zhang by Fei Xu, Hongbing Zhang

Key moments

  1. 0:00 Introduction and KubeEdge project journey
  2. 3:00 KubeEdge core architecture overview
  3. 6:00 IoT device management features
  4. 7:00 Edge Mesh: Edge application communication
  5. 8:00 KubeEdge project security updates
  6. 8:30 Sedna: Edge-Cloud AI Framework introduction
  7. 9:30 Cloud-Edge joint inference demonstration
  8. 10:30 Real-world commercial use cases

KubeEdge DeepDive: Architecture, Use Cases, and Project Graduation Updates

Speakers: Fei Xu, Full-time Maintainer, KubeEdge Graduated Project; Hongbing Zhang, Product Design & Development, Edge Computing, Huawei Cloud

Conference: KubeCon EU

YouTube: https://www.youtube.com/watch?v=WuMyfaF0UeM

Overview

This talk provides a comprehensive deep dive into KubeEdge, a pioneering cloud-native edge computing project, covering its architecture, diverse use cases, and significant milestone of achieving CNCF graduation. Presented by Fei Xu, a full-time maintainer of the KubeEdge project, and Hongbing Zhang from Huawei Cloud, the session illuminates how KubeEdge extends Kubernetes capabilities to the edge, addressing the unique challenges of distributed environments with unstable network connectivity and resource constraints.

KubeEdge stands out as the first CNCF graduated project specifically tailored for edge scenarios, signifying its maturity, widespread adoption, and robust community support. The speakers meticulously outline the project's journey from a CNCF sandbox to its current status, emphasizing its open governance model and global contributor base. The talk is crucial for developers, architects, and organizations looking to deploy and manage containerized applications and IoT devices seamlessly across vast, geographically dispersed edge locations while maintaining the familiar Kubernetes experience.

Background

▶ Watch: Introduction and KubeEdge project journey (0:00)

The proliferation of IoT devices and the increasing demand for real-time data processing at the network's edge have created a significant paradigm shift in computing. Traditional cloud-centric architectures often struggle with the inherent limitations of edge environments, such as intermittent network connectivity, high latency, limited bandwidth, and diverse hardware landscapes. Managing thousands or even millions of nodes and applications at these distributed edge locations, where a vast amount of data is generated, presents a complex operational challenge.

KubeEdge emerged as a solution to this burgeoning problem, aiming to bring the power and flexibility of Kubernetes to the edge. The core idea is to enable orchestration, deployment, and management of applications and IoT devices directly at the edge, rather than solely relying on a centralized cloud. Prior attempts often involved custom, fragmented solutions or simply pushing container orchestrators designed for stable data centers into unstable edge environments, leading to inefficiencies and operational overhead. KubeEdge's fundamental innovation lies in its design to operate effectively despite the unstable network between the cloud and edge, ensuring autonomy and resilience for edge workloads. It achieves this by making minimal modifications to the Kubernetes master in the cloud while introducing specialized components at the edge to handle local operations and synchronize with the cloud when connectivity permits.

Key Findings

▶ Watch: IoT device management features (6:00)

The presentation highlighted several key findings and architectural components that define KubeEdge's unique approach to edge computing:

  • Modular Architecture: KubeEdge is structured into three distinct parts: the Cloud part (Kubernetes master + CloudCore), the Edge part (EdgeCore + IoT device management), and the IoT devices part (Mapper). This clear separation allows for optimized management across the cloud-edge continuum.
  • Light Kubelet Integration: The EdgeCore component, residing at the edge, integrates a specialized, lightweight version of Kubelet. This light Kubelet is optimized by removing unused features from the standard Kubernetes Kubelet, making it suitable for resource-constrained edge nodes.
  • Robust IoT Device Management: KubeEdge provides native support for managing IoT devices. This is facilitated through Custom Resource Definitions (CRDs) in the Kubernetes master, specifically DeviceModel (for defining device types and capabilities) and DeviceInstance (for managing specific device instances). The Mapper component at the edge connects diverse IoT devices to the KubeEdge cluster, enabling data collection and control.
  • Edge Mesh for Intra-Edge Communication: The Edge Mesh sub-project addresses the challenge of application communication between edge nodes that may not have direct connectivity. It provides essential network services, including DNS functionality, to enable seamless communication for edge applications across different sites.
  • Sedna: Edge-Cloud Collaborative AI Framework: Sedna, a sub-project within KubeEdge under SIG AI, is an edge-cloud collaborative AI framework. It enables advanced AI scenarios like joint inference and federated learning, allowing AI workloads to be intelligently distributed and coordinated between cloud and edge for improved efficiency and reduced latency.
  • Enhanced Security Posture: KubeEdge has achieved significant security milestones, being one of the first CNCF projects to reach L3 of the supply chain level. It integrates fuzzing for vulnerability detection and has publicly released its threat model and security protection analysis, demonstrating a strong commitment to security.
  • Project Graduation and Community: KubeEdge's graduation as a CNCF project, the first in the edge scenario, underscores its maturity and broad industry adoption. The project boasts an open governance model, a diverse global contributor base, and numerous partnerships across various industries.
  • Latest Release Features: Recent updates include support for batch node processing (e.g., batch node join-in), IPv6 for cloud-edge communication, and mount logage me framework support for device management. Kubernetes dependency has also been upgraded to the latest version, and a new KubeEdge dashboard has been released.

Technical Deep Dive

▶ Watch: KubeEdge project security updates (8:00)

KubeEdge's architecture is meticulously designed to extend Kubernetes' declarative management capabilities to the edge, focusing on resilience and efficiency in challenging environments.

At its core, KubeEdge splits the traditional Kubernetes control plane components, with the Kubernetes master residing in the cloud, operating without modification. This is a crucial design choice, allowing KubeEdge to leverage the existing Kubernetes ecosystem and tooling.

The Cloud Part of KubeEdge introduces a custom component called CloudCore. Its primary role is to act as a bridge between the Kubernetes master and the edge nodes. CloudCore is specifically developed to handle the inherent instability of the cloud-edge network. It uses a WebSocket protocol for robust, persistent, and efficient communication, transmitting pod metadata and other control plane information from the cloud to the edge. This mechanism ensures that even with intermittent connectivity, messages are eventually delivered and state is synchronized.

On the Edge Part, the central component is EdgeCore. EdgeCore is a daemon that runs on each edge node and is responsible for managing applications and communicating with the CloudCore. A key innovation within EdgeCore is its integration of a light Kubelet. Unlike the full Kubelet designed for stable data center environments, KubeEdge's light Kubelet is streamlined, with unnecessary features removed to reduce its footprint and resource consumption, making it suitable for resource-constrained edge devices. When metadata for a pod or application is received from CloudCore via WebSocket, it's first processed by a Hub within EdgeCore, then stored locally in an EdgeStore (a local database). This local storage enables edge autonomy, meaning that if the connection to the cloud is lost, applications running on the edge node can continue to operate without interruption, and the state can be reconciled once connectivity is restored. The light Kubelet then uses this stored metadata to manage and run containers on the edge node.

IoT Device Management is a cornerstone of KubeEdge's offering. It allows Kubernetes to manage not just containerized applications but also physical IoT devices. This is achieved through Kubernetes CRDs. The DeviceModel CRD acts as a template, defining the properties, protocols, and expected behaviors of a class of IoT devices (e.g., a temperature sensor with a specific data format). The DeviceInstance CRD represents an actual physical device connected to an edge node, referencing a DeviceModel and providing specific configuration for that instance. An interface called Device Management Interface is defined within EdgeCore to abstract device interactions. To connect diverse, often proprietary, IoT devices to the KubeEdge cluster, a component called Mapper is deployed. Mappers are specific to device protocols (e.g., Modbus, MQTT, Bluetooth) and translate device-specific communications into KubeEdge's standardized APIs, allowing data collection and control from the cloud via DeviceInstance CRDs.

For networking within the edge, the Edge Mesh sub-project is critical. In many edge scenarios, edge nodes cannot directly communicate with each other due to network segmentation, NAT traversal issues, or diverse network topologies. Edge Mesh solves this by creating a virtual network overlay that enables inter-application communication between pods running on different edge nodes. It provides services akin to a service mesh, including DNS functions for service discovery, and ensures that edge applications can reliably connect to each other regardless of their physical network location or direct connectivity.

The Sedna sub-project focuses on Edge-Cloud Collaborative AI (HAI). Its architecture comprises a Global Manager in the cloud, responsible for high-level AI task management, coordination, and model/dataset management. A Local Controller runs on both cloud and edge nodes, acting as a bridge for AI workload orchestration. Workers are the actual execution units for AI tasks, capable of running in both cloud and edge environments. Crucially, Sedna includes a lib (library) within the worker that facilitates collaboration between edge and cloud AI workloads. This enables advanced scenarios like joint inference, where a less complex "shadow model" runs on the edge for fast, local decisions, and if its confidence level is unmet, the request is forwarded to a more powerful "deep model" in the cloud. Another key capability is federated learning, where models are trained locally on edge data, and only model updates (not raw data) are sent to the cloud for aggregation, preserving data privacy and reducing bandwidth. An example of joint inference involved camera devices feeding data to multiple edge nodes (H1, H2, H3) running shadow models, with the cloud node hosting the deep model for complex or low-confidence inferences.

The latest KubeEdge releases have further enhanced its capabilities, introducing support for batch node processes, such as batch node join-in, simplifying the onboarding of large numbers of edge devices. IPv6 support for cloud-edge communication ensures future compatibility and addresses the growing demand for IP addresses. Furthermore, KubeEdge continuously upgrades its Kubernetes dependency to the latest version, ensuring compatibility with the broader Kubernetes ecosystem and leveraging new features. The introduction of a new KubeEdge dashboard also improves usability and management.

Demo / Proof of Concept

▶ Watch: Sedna: Edge-Cloud AI Framework introduction (8:30)

While the talk did not feature a live technical demonstration or a specific proof of concept, the speakers presented several compelling real-world case studies that effectively illustrate KubeEdge's capabilities and the problems it solves. These case studies served as practical demonstrations of how KubeEdge is deployed and delivers value in diverse industrial scenarios.

For instance, in commercial vehicles, KubeEdge enables AI models to run locally on trucks, identifying potential issues before they occur, even in remote areas with signal loss. This reduces maintenance costs and improves fleet management. In offshore oil fields, KubeEdge facilitates on-site data handling and machine failure prediction, ensuring stable operations and a safer environment despite weak or absent network connectivity to the cloud. The project's autonomy feature ensures that edge applications continue running smoothly even if the cloud connection is lost or the edge OS restarts. Additionally, KubeEdge is used in Content Delivery Networks (CDNs) to predict traffic and ensure only necessary content is fetched from the cloud, leading to faster loading times and improved CDN performance. These examples, alongside mentions of applications in intelligent transportation, smart energy, industrial intelligence, and robotics, effectively showcased KubeEdge's practical utility without requiring a live, complex technical demo.

Defensive Implications

▶ Watch: Real-world commercial use cases (10:30)

For organizations operating or planning to deploy edge computing infrastructure, KubeEdge offers significant defensive advantages and strategic considerations:

  1. Enhanced Operational Resilience: KubeEdge's edge autonomy feature, where EdgeCore and EdgeStore enable local operation even without cloud connectivity, is a critical defensive measure against network outages. This ensures business continuity for critical edge workloads in environments like remote industrial sites, oil rigs, or vehicles where internet access is unreliable. Defenders should prioritize designing applications to leverage this autonomy.
  2. Decentralized Security Posture: By pushing intelligence and processing to the edge, organizations can reduce reliance on constant cloud communication, thereby minimizing the attack surface associated with long-haul data transmission. However, this also shifts security responsibilities to the edge. Robust TLS connections between edge and cloud, as highlighted in the Q&A, are essential.
  3. Supply Chain Security and Fuzzing: KubeEdge's achievement of L3 of the supply chain level and integration of fuzzing for vulnerability detection are strong indicators of its commitment to security. Organizations adopting KubeEdge benefit from this inherent security focus. Defenders should ensure they maintain this posture by keeping KubeEdge components updated and integrating similar supply chain security practices into their custom edge applications.
  4. IoT Device Security and Management: The structured approach to IoT device management via CRDs (DeviceModel, DeviceInstance) and the Mapper component provides a centralized, Kubernetes-native way to manage and secure potentially vulnerable IoT devices. This allows for standardized configuration, monitoring, and updates, which are crucial for reducing the attack surface of diverse device ecosystems. Defenders should leverage these features to enforce security policies and manage device lifecycles.
  5. Efficient Resource Utilization and Cost Reduction: By performing computation at the edge, organizations can reduce the volume of data sent to the cloud, lowering bandwidth costs and improving data privacy. This also means less sensitive data might traverse public networks.
  6. Collaborative AI for Threat Detection: The Sedna sub-project enables edge-cloud collaborative AI, which can be leveraged for advanced threat detection and anomaly analysis directly at the edge. Deploying "shadow models" for initial inference can quickly flag suspicious activities, while "deep models" in the cloud can provide more thorough analysis for complex threats, enabling faster response times.
  7. Day-2 Operations and Compliance in Constrained Environments: The Q&A session highlighted the challenges of day-2 operations, security updates, and regulatory compliance in highly constrained environments like offshore oil rigs. Defenders must plan for offline or limited-connectivity update mechanisms, robust patch management strategies, and ensure KubeEdge deployments meet specific industry certifications and compliance requirements (e.g., private networks, strict update windows). KubeEdge's design for weak network connectivity and autonomy helps facilitate these challenges.

Key Takeaways

  • KubeEdge is a CNCF graduated project and the first in the edge computing scenario, extending Kubernetes' orchestration capabilities to the network edge.
  • Its architecture is designed for unstable cloud-edge network connectivity, utilizing components like CloudCore and EdgeCore with a light Kubelet for autonomous edge operations.
  • KubeEdge provides robust IoT device management through Kubernetes CRDs (DeviceModel, DeviceInstance) and the Mapper component, enabling centralized control of diverse devices.
  • The Edge Mesh sub-project facilitates reliable inter-application communication between edge nodes, even without direct network connectivity.
  • Sedna is an integral sub-project enabling edge-cloud collaborative AI for joint inference and federated learning, optimizing AI workloads and data privacy.
  • The project prioritizes security, achieving L3 of the supply chain level and integrating fuzzing for continuous vulnerability detection.
  • KubeEdge is being actively used in diverse industries, including commercial vehicles, offshore oil fields, and CDNs, demonstrating its practical value in challenging environments.

About the Speaker(s)

Fei Xu is a full-time maintainer of the KubeEdge project, which has achieved the significant milestone of becoming a CNCF graduated project. His role involves the ongoing development, maintenance, and strategic direction of this pioneering cloud-native edge computing solution.

Hongbing Zhang is associated with Huawei Cloud, where he focuses on the product design and development of edge computing solutions. He is also responsible for providing comprehensive solutions to end customers, leveraging technologies like KubeEdge to address their specific edge computing needs.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This KubeEdge deep-dive delivers a robust, technically sound overview of a critical project in the edge computing landscape. Presented by project maintainers, it meticulously details KubeEdge's architecture, including the light Kubelet, EdgeCore's autonomy mechanisms, and advanced sub-projects like Edge Mesh and Sedna for collaborative AI. The talk effectively communicates the practical challenges KubeEdge addresses, particularly unstable network connectivity and resource constraints at the edge, and highlights its significant maturity through CNCF graduation and strong security posture.

Heather Calloway (CISO) — STRONG ACCEPT

This deep dive into KubeEdge effectively articulates how the project extends Kubernetes to the challenging edge environment, prioritizing resilience and operational autonomy. Its robust security posture, including L3 supply chain certification and integrated fuzzing, is a critical enabler for trust. The structured approach to IoT device management via CRDs offers a clear path for governance and accountability over a notoriously vulnerable attack surface, making it highly relevant for security leaders grappling with distributed risk.

→ Top-rated talks at KubeCon + CloudNativeCon Europe 2025

All talks from KubeCon + CloudNativeCon Europe 2025