KubeEdge Graduation Journey: Creating a Diverse and Collaborative Open S... Yue Bao & Hongbing Zhang
Yue Bao, Hongbing Zhang
KubeCon + CloudNativeCon Europe 2025 · Session
Overview
In this insightful KubeCon EU presentation, Yue Bao and Hongbing Zhang delved into the remarkable journey of KubeEdge, the industry's first cloud-native edge computing framework, culminating in its recent graduation as a CNCF (Cloud Native Computing Foundation) project. The talk highlighted KubeEdge's evolution from a nascent open-source project in 2018 to a mature, widely adopted platform, emphasizing the critical role of a diverse and collaborative multi-vendor community in achieving this significant milestone. The speakers explored KubeEdge's technological advancements, its impact across various industries, and the strategic community governance models that underpinned its success.

Key moments
- 0:55 KubeEdge achieves CNCF graduated project status
- 2:35 KubeEdge's journey: sandbox, incubation, and major adoption
- 4:00 First cloud-native vehicle and satellite powered by KubeEdge
- 5:50 Vision for a multi-domain, multi-scenario edge computing platform
- 7:00 Deep dive into Sedna: KubeEdge's edge-cloud collaborative AI
- 11:40 KubeEdge's community statistics and path to graduation
KubeEdge Graduation Journey: Creating a Diverse and Collaborative Open Source Community
Speakers: Yue Bao, Maintainer, Huawei Cloud; Hongbing Zhang, TSC Member
Conference: KubeCon EU
YouTube: https://www.youtube.com/watch?v=mrKx1M0Idbg
Overview
In this insightful KubeCon EU presentation, Yue Bao and Hongbing Zhang delved into the remarkable journey of KubeEdge, the industry's first cloud-native edge computing framework, culminating in its recent graduation as a CNCF (Cloud Native Computing Foundation) project. The talk highlighted KubeEdge's evolution from a nascent open-source project in 2018 to a mature, widely adopted platform, emphasizing the critical role of a diverse and collaborative multi-vendor community in achieving this significant milestone. The speakers explored KubeEdge's technological advancements, its impact across various industries, and the strategic community governance models that underpinned its success.
The core of KubeEdge's mission is to provide a consistent experience for applications, resources, data, and device collaboration between the cloud and the edge. This consistency is vital in an era where compute increasingly extends beyond traditional data centers to a multitude of geographically distributed and resource-constrained edge devices. The presentation underscored how KubeEdge addresses the unique challenges of edge environments, such as limited connectivity, fragmented data, and the complexities of deploying and managing AI workloads.
The talk is particularly relevant for developers, architects, and organizations grappling with the complexities of edge computing deployments. It not only showcases KubeEdge's technical prowess and extensive real-world applications—ranging from large-scale highway systems to cloud-native satellites and smart vehicles—but also offers a blueprint for building and sustaining a healthy, inclusive open-source community. For anyone interested in the future of cloud-native technologies at the edge or the dynamics of open-source project growth, this presentation provides valuable lessons and a comprehensive overview of a critical infrastructure project.
Background
▶ Watch: KubeEdge achieves CNCF graduated project status (0:55)
The proliferation of IoT devices, AI at the edge, and the increasing demand for real-time processing have driven the need for robust edge computing solutions. Traditional cloud-centric architectures often fall short in these environments due to latency constraints, bandwidth limitations, and privacy concerns associated with sending all data to a central cloud. The inherent challenges of edge environments — including limited data samples, fragmented infrastructure, intermittent network connectivity, and the high cost of model updates and maintenance for AI applications — necessitated a new approach. This is the problem space KubeEdge was designed to address.
KubeEdge emerged in 2018 as an open-source project, quickly gaining traction for its innovative approach to extending Kubernetes capabilities to the edge. Its fundamental premise is to bring the familiar cloud-native orchestration and management paradigms to edge nodes, enabling a seamless continuum between cloud and edge. In 2019, KubeEdge was donated to the CNCF as a sandbox project, marking the beginning of its journey within the broader cloud-native ecosystem. The project rapidly progressed, achieving incubation status in 2020, a testament to its growing community, adoption, and technical maturity.
Over its journey, KubeEdge has demonstrated impressive growth and scale. As of the talk, it boasts over 8,000 GitHub stars, 2,200 forks, and a community comprising more than 1,500 contributors from over 100 organizations worldwide. This broad engagement reflects the project's ability to attract and sustain a diverse developer base. Early large-scale deployments, such as its use in a China highway electronic toll connection system managing over 100,000 edge nodes across multiple provinces by 2020, highlighted its robust capabilities. Further demonstrating its versatility, KubeEdge powered the first cloud-native vehicle and the world's first cloud-native satellite launched to space in 2021. The latter presented unique challenges due to rapid movement and intermittent connectivity to ground stations, which KubeEdge successfully navigated by enabling AI model deployment and data processing directly on the satellite. These milestones underscore KubeEdge's foundational role in addressing the complex and varied demands of modern edge computing across diverse and challenging environments.
Key Findings
▶ Watch: First cloud-native vehicle and satellite powered by KubeEdge (4:00)
The presentation highlighted several pivotal findings and achievements that underscore KubeEdge's success and its significance within the cloud-native landscape. Foremost among these is KubeEdge's graduation as a CNCF project in October 2023. This is a monumental achievement, as the speakers noted that out of over 200 projects managed by the CNCF, only about 20 have achieved graduation status, making it a truly challenging and exclusive milestone. This graduation signifies KubeEdge's stability, maturity, widespread adoption, and a robust governance model that meets the stringent requirements of the CNCF Technical Oversight Committee (TOC).
Another key finding is KubeEdge's demonstrated scalability and performance. A large-scale testing report released in 2022 confirmed KubeEdge's capability to support over 100,000 edge nodes and 1 million edge pods on a single cluster. This level of scalability is critical for industrial-grade deployments and positions KubeEdge as a leading solution for vast edge infrastructures. The project's commitment to supporting a multi-domain, multi-scenario edge computing platform was also a significant finding, evidenced by the establishment of various Special Interest Groups (SIGs) and working groups, including SIG AI, SIG Device IoT, and MEC Working Groups, which cater to diverse application areas like AI, IoT, and Mobile Edge Computing.
The talk also revealed KubeEdge's strong commitment to security and interoperability. In 2023, KubeEdge achieved SLSA Level 3 (Supply-chain Levels for Software Artifacts) verification, a crucial certification that attests to the project's secure development practices and supply chain integrity. Furthermore, the emphasis on hardware compatibility testing and certification ensures that KubeEdge can integrate seamlessly with a wide array of edge hardware and operating systems, which is vital for real-world deployments. The speakers also highlighted the importance of open and transparent governance as a key criterion for graduation, emphasizing that the project's success is not solely technical but also hinges on its community structure, decision-making processes, and fostering a diverse partnership ecosystem spanning industry, academia, and research institutions. This holistic approach to project development and community building proved instrumental in KubeEdge's journey to graduation.
Technical Deep Dive
▶ Watch: Vision for a multi-domain, multi-scenario edge computing platform (5:50)
KubeEdge is fundamentally designed to extend the cloud-native paradigm from the data center to the edge, providing a unified management and orchestration experience. Its core architecture facilitates edge-cloud collaboration, ensuring that applications, resources, data, and devices can interact seamlessly across distributed environments. This is achieved through sophisticated mechanisms for edge-cloud scheduling, orchestration, and runtime management, allowing developers to deploy and manage workloads on edge nodes with the same tools and workflows they use for cloud-based Kubernetes clusters.
A significant technical contribution of KubeEdge is its focus on specific edge challenges through dedicated sub-projects and enhancements:
- Sedna: Cloud-Edge Collaborative AI Sub-project
Released in 2021, Sedna is KubeEdge's answer to the unique challenges of deploying and managing AI workloads at the edge. Edge AI often struggles with limited data samples, data fragmentation, and the high cost associated with model updates and maintenance. Sedna addresses these by providing cross-edge-cloud dataset and model management. It supports advanced training and inference frameworks, including:
- Joint Inference: This mechanism allows edge devices to process data locally. For straightforward cases, inference is completed at the edge, minimizing latency and bandwidth usage. However, for "difficult cases" or those requiring higher accuracy, the relevant data is intelligently sent to the cloud for more powerful and accurate inference. This optimizes resource utilization and ensures high-quality results.
- Incremental Learning: Sedna facilitates continuous model improvement. Inference results from the edge are sent back to the cloud, where they contribute to updating and refining the AI model. The newly updated model is then deployed back to the edge in real-time, ensuring that edge AI capabilities are constantly evolving and improving without manual intervention.
Sedna is designed to support many mainstream AI frameworks and offers enhanced interfaces for developers to quickly integrate third-party algorithms, making it a flexible and powerful tool for edge AI development.
- EdgeMesh
Another crucial sub-project, EdgeMesh, addresses the complexities of network communication between edge nodes. In distributed edge environments, nodes often reside in different networks, behind NATs, or with intermittent connectivity. EdgeMesh provides a robust solution for communication between edge nodes across disparate networks, enabling reliable service discovery and secure communication, which is essential for distributed applications at the edge.
- KubeRover: Robotics Solution
Launched in 2023, KubeRover is a specialized robotics solution built on KubeEdge. It extends KubeEdge's orchestration capabilities to robotic systems, enabling the management, deployment, and update of robot applications and AI models from the cloud, leveraging the existing edge-cloud collaboration framework.
KubeEdge's technical planning is not limited to a single area but is committed to building a multi-domain, multi-scenario edge computing platform. This is reflected in its support for various application domains, including AI, IoT, MEC (Multi-access Edge Computing), and Robotics. The project continually enhances KubeEdge itself in areas like edge-cloud scheduling, orchestration, and edge runtime to improve efficiency and performance. Furthermore, KubeEdge places a strong emphasis on hardware compatibility, aiming to support a broader range of hardware, operating systems, and devices with various protocols. A hardware compatibility testing and certification program is in place to ensure seamless integration and reliable operation across diverse edge ecosystems. The project's ability to manage over 100,000 edge nodes and 1 million edge pods on a single cluster, as demonstrated in its large-scale testing report, highlights its robust architecture and scalability engineering. Lastly, the achievement of SLSA Level 3 security verification in 2023 underscores KubeEdge's commitment to building a secure supply chain for its software artifacts, a critical technical aspect for enterprise adoption.
Demo / Proof of Concept
▶ Watch: Deep dive into Sedna: KubeEdge's edge-cloud collaborative AI (7:00)
While this specific KubeCon EU talk did not feature a live, in-session demonstration of KubeEdge in action, the speakers frequently referenced real-world deployments and past demonstrations that serve as powerful proofs of concept. They highlighted KubeEdge's application in a large-scale China highway electronic toll connection system managing over 100,000 edge nodes and its role in the world's first cloud-native satellite launched to space in 2021.
Furthermore, the speakers mentioned previous KubeCon events where specific use cases were showcased:
- At KubeCon Europe 2021, the application of KubeEdge and its Sedna sub-project in satellite applications was shared, demonstrating how AI models could be deployed and data processed on rapidly moving satellites with intermittent ground station connectivity.
- At KubeCon China last year, KubeEdge collaborated with NIO to demonstrate its applications in smart driving, illustrating its capabilities in real-time processing and orchestration for autonomous vehicle systems.
These examples, while not live demonstrations within this particular talk, serve as compelling evidence of KubeEdge's practical utility, scalability, and adaptability across highly demanding and diverse industrial scenarios. The project encourages interested parties to explore more use cases on its official website or engage with the KubeEdge booth for further discussions and insights into its deployments.
Defensive Implications
▶ Watch: KubeEdge's community statistics and path to graduation (11:40)
For organizations operating or planning to deploy edge computing infrastructure, KubeEdge offers significant defensive advantages by providing a robust, scalable, and securely governed cloud-native framework. The project's journey to CNCF graduation and its technical achievements directly translate into tangible benefits for defenders.
Firstly, KubeEdge's strong emphasis on community governance and transparency ensures a well-maintained and actively developed codebase. The presence of a Technical Steering Committee (TSC) and various Special Interest Groups (SIGs), including a dedicated security group, means that security concerns are systematically addressed throughout the project's lifecycle. This open development model fosters early identification and remediation of vulnerabilities, providing a more secure foundation than proprietary or less actively managed alternatives.
Secondly, the achievement of SLSA Level 3 (Supply-chain Levels for Software Artifacts) verification in 2023 is a critical defensive implication. SLSA Level 3 signifies that KubeEdge employs strong controls to protect its software supply chain, including requiring source control, hermetic and reproducible builds, and verified provenances. For organizations concerned about supply chain attacks—a growing threat vector—adopting KubeEdge provides a higher degree of assurance regarding the integrity and authenticity of the software components they deploy to their edge environments. This reduces the risk of malicious code injection or tampering from source to deployment.
Thirdly, KubeEdge's demonstrated scalability (supporting over 100,000 edge nodes and 1 million edge pods) means it can handle extensive deployments without compromising stability or introducing new attack surfaces due to architectural weaknesses. Its features like EdgeMesh, which facilitates secure communication between edge nodes across different networks, are vital for maintaining network segmentation and preventing unauthorized lateral movement within distributed edge infrastructures.
Finally, for edge AI deployments, the Sedna sub-project offers defensive benefits. By enabling joint inference and incremental learning, Sedna helps manage sensitive data at the edge, reducing the need to transmit all raw data to the cloud. This data locality can enhance privacy and compliance by minimizing data exposure. Furthermore, the ability to deploy updated models in real-time through incremental learning ensures that AI models at the edge are consistently using the latest, potentially more secure, versions, reducing the window of opportunity for exploits targeting outdated models.
In summary, KubeEdge provides a comprehensive framework that aligns with modern security best practices for edge deployments. Its secure supply chain, transparent governance, scalable architecture, and specialized features for edge AI contribute to a stronger defensive posture, allowing organizations to confidently extend their cloud-native operations to the often-vulnerable edge. Defenders should consider KubeEdge as a foundational element for building resilient and secure edge computing ecosystems.
Key Takeaways
- KubeEdge's CNCF Graduation: KubeEdge has successfully graduated as a CNCF project, signifying its maturity, widespread adoption, and robust governance model, a rare achievement among the many CNCF projects.
- Scalability and Industry Adoption: KubeEdge demonstrates exceptional scalability, supporting over 100,000 edge nodes and 1 million edge pods on a single cluster, with proven applications in diverse, demanding environments like highway systems, smart vehicles, and even cloud-native satellites.
- Advanced Edge AI Capabilities: The Sedna sub-project provides sophisticated solutions for cloud-edge collaborative AI, addressing challenges like limited data, fragmentation, and model maintenance through features like joint inference and incremental learning.
- Strong Security Posture: KubeEdge achieved SLSA Level 3 verification, underscoring its commitment to a secure software supply chain and providing enhanced assurance against supply chain attacks for edge deployments.
- Open Governance and Diverse Community: The project's success is attributed to its open and transparent governance model, active Technical Steering Committee (TSC), and a highly diverse community of 1,500+ contributors from over 100 organizations, fostering continuous innovation and stability.
- Ubiquitous Cloud-Native Edge: KubeEdge extends the cloud-native paradigm beyond data centers, enabling consistent orchestration and management for a wide range of edge scenarios including IoT, MEC, and robotics, making cloud-native technologies truly ubiquitous.
About the Speaker(s)
Yue Bao is a maintainer of the KubeEdge community and works at Huawei Cloud. His involvement in the KubeEdge project highlights his expertise in cloud-native edge computing and open-source community development.
Hongbing Zhang is a member of the KubeEdge Technical Steering Committee (TSC) and plays a crucial role in overseeing the KubeEdge community and project. His leadership is instrumental in guiding the project's technical direction and fostering its growth within the CNCF ecosystem.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
KubeEdge's journey to CNCF graduation is a compelling case study in open-source project maturity. The speakers, deeply embedded in the project, provided a substantive overview of KubeEdge's robust architecture, its specific solutions like Sedna for edge AI and EdgeMesh for inter-node communication, and its impressive scalability. The achievement of SLSA Level 3 is a critical signal for anyone concerned with supply chain security in edge deployments, making this a highly impactful session for cloud-native architects and defenders.
Heather Calloway (CISO) — STRONG ACCEPT
The KubeEdge graduation talk presents a compelling case for its strategic adoption in secure edge computing. Its robust governance, CNCF graduation, and critical SLSA Level 3 security verification directly address significant institutional risks, particularly concerning supply chain integrity. For security leaders, this offers a mature, operationally proven framework to mitigate business exposure and enable advanced AI and IoT capabilities at the edge.