Project Lightning Talk: A Hitchhiker's Guide to the CNCF Landsc... Katherine Druckman & Lori Lorusso
Katherine Druckman, Lori Lorusso
KubeCon + CloudNativeCon Europe 2025 · Project Lightning Talk
Overview
The cloud-native ecosystem has experienced explosive growth over the past decade, transforming how organizations develop, deploy, and manage applications. This rapid expansion, while fostering innovation, has also created a complex and often overwhelming landscape for both new entrants and seasoned practitioners. In their KubeCon EU talk, "A Hitchhiker's Guide to the CNCF Landscape," Katherine Druckman, an Open Source Evangelist at Intel, accompanied by Gerald (filling in for Lori Lorusso), tackled this challenge head-on. Dressed as the 13th Doctor, Druckman metaphorically invited the audience into a TARDIS for a journey through the vast and intricate Cloud Native Computing Foundation (CNCF) Landscape.

Key moments
- 0:00 Welcome, speaker introductions, and talk overview
- 2:00 Why the CNCF landscape is important and how to use it
- 2:50 The CNCF's mission, scale, projects, and community
- 4:00 Brief history of the landscape's growth and proliferation
- 5:15 Understanding CNCF project status: Sandbox, Incubation, Graduation
- 5:40 Detailed explanation of the project adoption and maturity process
Project Lightning Talk: A Hitchhiker's Guide to the CNCF Landscape
Speakers: Katherine Druckman, Open Source Evangelist, Intel; Lori Lorusso
Conference: KubeCon EU
YouTube: https://www.youtube.com/watch?v=3s8EdlTi9bk
Overview
The cloud-native ecosystem has experienced explosive growth over the past decade, transforming how organizations develop, deploy, and manage applications. This rapid expansion, while fostering innovation, has also created a complex and often overwhelming landscape for both new entrants and seasoned practitioners. In their KubeCon EU talk, "A Hitchhiker's Guide to the CNCF Landscape," Katherine Druckman, an Open Source Evangelist at Intel, accompanied by Gerald (filling in for Lori Lorusso), tackled this challenge head-on. Dressed as the 13th Doctor, Druckman metaphorically invited the audience into a TARDIS for a journey through the vast and intricate Cloud Native Computing Foundation (CNCF) Landscape.
The core of the presentation centered on demystifying the CNCF Landscape, an interactive web-based map designed to categorize and visualize the myriad projects, products, and services within the cloud-native domain. Druckman and Gerald highlighted the critical need for such a tool in an environment where the sheer volume of projects can paralyze decision-making and hinder effective adoption. They emphasized not only what the landscape is but why it exists, providing attendees with practical guidance on how to navigate this essential resource to evaluate projects, identify areas for contribution, and make informed choices for their cloud-native strategies.
This talk is particularly pertinent for anyone operating within or considering a move to cloud-native architectures. It offers a crucial framework for understanding project maturity, health, and security, which are paramount concerns in modern software development. By illustrating the historical growth of the CNCF and detailing the functionalities of the landscape, Druckman and Gerald empowered the audience to move beyond the "overwhelming" perception and actively engage with the vibrant, ever-evolving cloud-native community.
Background
▶ Watch: Welcome, speaker introductions, and talk overview (0:00)
The genesis of the Cloud Native Computing Foundation (CNCF) can be traced back to 2014, with significant credit given to Google and the advent of Kubernetes. In its nascent stages, the cloud-native ecosystem was manageable, comprising only a handful of projects. Katherine Druckman reminisced about a time when it was possible to grasp the entire technology stack. However, this simplicity was short-lived. By 2018, the CNCF already boasted 31 projects, a number that has since proliferated into what Druckman describes as a "shocking number," making it increasingly difficult for individuals and organizations to maintain a comprehensive understanding of the available tools and technologies.
The CNCF itself operates under the umbrella of the Linux Foundation, a non-profit technology consortium dedicated to fostering the growth of open-source projects. The CNCF's mission is to make cloud-native computing ubiquitous, empowering every project and company with its capabilities. This mission has driven remarkable growth: the foundation now stewards 28 graduated projects, with a total of 257,000 and more project contributors, 756 CNCF members, and over 96,000 cloud-native community members. This scale, while indicative of widespread adoption and innovation, also underscores the complexity that led to the creation of the CNCF Landscape.
To bring order to this burgeoning ecosystem, the CNCF established a clear project lifecycle, which is also reflected in the landscape. Projects typically progress through three distinct phases:
- Sandbox: This initial phase is for newly accepted projects. To enter the Sandbox, a project must be selected and elected by a supermajority of the Technical Oversight Committee (TOC), indicating that it aligns with the CNCF's vision. Projects in this stage are often experimental, with smaller communities and less proven adoption. Users considering Sandbox projects are advised to conduct more extensive due diligence and potentially contribute to help them mature.
- Incubation: Once a project gains more users, grows its community, and perhaps sees some early production use, it can advance to the Incubation stage. While more mature than Sandbox projects, incubating projects haven't fully "graduated." Druckman noted that using an incubating project in production is possible, but it warrants additional scrutiny compared to more established projects. This stage is also a prime opportunity for contributors to help a project reach its full potential.
- Graduated: This is the highest level of maturity for a CNCF project. To graduate, projects must demonstrate thriving adoption rates, robust community engagement, and sustained development. Graduated projects are considered stable, widely adopted, and well-supported, offering a high degree of confidence for production environments. The CNCF foundation essentially "puts its hand in the fire" for these projects, affirming they meet all criteria for enterprise-grade use.
The overwhelming growth of projects, coupled with the varying levels of maturity, created a significant challenge for users. The sheer volume of choices, often without clear indicators of stability or security, necessitated a centralized, organized resource. This is precisely the problem the CNCF Landscape was designed to solve, providing a visual and informational guide to navigate the intricate world of cloud-native technologies.
Key Findings
▶ Watch: The CNCF's mission, scale, projects, and community (2:50)
The central revelation of the talk is the indispensable role of the CNCF Landscape as an authoritative, dynamic, and comprehensive guide to the cloud-native ecosystem. It serves as the primary tool for anyone seeking to understand, evaluate, and engage with the vast array of projects under the CNCF umbrella.
Firstly, the Landscape directly addresses the problem of information overload. What began as a simple list of a few projects has ballooned into hundreds, making it impossible for individuals to track manually. The Landscape provides a structured, categorized, and interactive interface that transforms this overwhelming data into actionable insights. It organizes projects into logical domains like automation, observability, storage, and networking, allowing users to quickly zoom into areas of interest.
Secondly, the talk underscored that the Landscape is not merely a directory but a powerful project evaluation platform. For each listed project, it presents critical metadata that helps assess its maturity, health, and community engagement. This includes the project's current status (Sandbox, Incubation, or Graduated), the date it achieved that status, the number of contributors, GitHub stars, and the date of its latest release. A project with no recent releases, for instance, is flagged as a potential red flag for production use, providing immediate guidance to users.
Thirdly, a significant finding highlighted by Druckman and Gerald is the integration of automated project health and security metrics directly into the Landscape. Specifically, the inclusion of a CLO Monitor score and security information derived from tools like OpenSSF Scorecard offers an unprecedented level of transparency and data-driven evaluation. The CLO Monitor score, ranging from 0 to 100, is a continuous, automated assessment of a project's overall health, encompassing factors like community activity, code quality, and development velocity. Similarly, the OpenSSF Scorecard integration provides a snapshot of a project's security posture, identifying potential vulnerabilities or areas needing improvement. These integrations empower users to make highly informed decisions, moving beyond mere popularity to objective measures of quality and security.
Finally, the talk emphasized that the Landscape is a catalyst for community involvement and contribution. By clearly presenting gaps, such as a low CLO Monitor score or a specific security vulnerability identified by the OpenSSF Scorecard, the Landscape actively encourages users to become contributors. It transforms potential "red flags" into opportunities for engagement, allowing individuals and organizations to "jump in" and help improve the projects they rely on, fostering a healthier and more secure cloud-native ecosystem for everyone.
Technical Deep Dive
▶ Watch: Brief history of the landscape's growth and proliferation (4:00)
The CNCF Landscape is far more than a static infographic; it is an interactive web-based platform designed for deep exploration of the cloud-native ecosystem. At its core, it visually organizes hundreds of projects, products, and services into a structured, categorized map. Users can navigate this map, which is divided into broad categories such as Application Definition & Development, Orchestration & Management, Runtime, Provisioning, Platform, Observability & Analysis, and Specialty Tools. Within each of these main categories, projects are further grouped into sub-categories (e.g., within Orchestration & Management, one finds sections for Scheduling, Workload Automation, Service Mesh, etc.). This hierarchical organization is crucial for managing the sheer volume of information.
When a user clicks on any project icon within the landscape, a detailed pop-up window or dedicated page appears, providing a wealth of information. This includes:
- Project Status: Clearly indicates if a project is in the Sandbox, Incubation, or Graduated phase, along with the date it achieved that status. This is a primary indicator of maturity and stability.
- GitHub Metrics: Essential for gauging community activity and developer interest. This typically includes the number of contributors and GitHub stars. While not a definitive measure of quality, a high number of stars and active contributors usually points to a vibrant project.
- Latest Release: The date of the last software release. An outdated release can signal a project that is no longer actively maintained, posing potential security or compatibility risks.
- Description and Links: A brief overview of the project's purpose, along with direct links to its GitHub repository, official website, documentation, and other relevant resources.
A standout technical feature of the CNCF Landscape is its integration with project health and security monitoring tools. The most prominent of these is the CLO Monitor score. CLO Monitor (Cloud Native Landscape Open Source Monitor) is an automated system that runs a series of checks on all projects within the landscape to assess their overall health and activity. The score, presented as a percentage (e.g., 99% for Kyo, as demonstrated in the talk), is derived from various metrics including:
- Community Activity: Frequency of commits, pull requests, issue resolution, and new contributors.
- Code Quality: Adherence to coding standards, test coverage, and static analysis results.
- Documentation: Availability and quality of user and developer documentation.
- Release Frequency: Consistency of new releases and patch updates.
- License Compliance: Verification of proper open-source licensing.
The CLO Monitor score provides a quick, objective snapshot for project evaluation, helping users identify well-maintained and active projects versus those that might be stagnating. Druckman cautioned that a perfect 99% score (like Kyo's) is rare, and users should expect to see scores in the 70s or 80s, which are still indicative of healthy projects.
Another critical integration for security-conscious users is the display of security information, primarily pulled from OpenSSF Scorecard. The OpenSSF Scorecard is an automated tool that assesses various security practices for open-source projects. It evaluates compliance with best practices such as:
- Branch Protection: Ensuring critical branches are protected from direct pushes.
- Signed Releases: Verifying that releases are cryptographically signed.
- Fuzzing: Using automated testing to find vulnerabilities.
- SAST/DAST: Employing Static Application Security Testing and Dynamic Application Security Testing.
- Dependency Updates: Regular updating of project dependencies to mitigate known vulnerabilities.
- Vulnerability Reporting: Having a clear process for reporting security issues.
The Landscape highlights these security checks, often presenting them with clear indicators (e.g., green checkmarks for compliance, red flags for non-compliance). As Druckman pointed out with Kyo, even a highly-rated project might have one "red thing" in its security report, which immediately signals an area for improvement and potential contribution.
Beyond the interactive visualization, the CNCF Landscape offers powerful filtering and search capabilities. Users can:
- Search by Name: Directly type in a project name to locate it.
- Filter by Status: Isolate projects based on their maturity (Sandbox, Incubation, Graduated). This is particularly useful for organizations with strict adoption policies.
- Filter by Category: Focus on specific technology domains.
- Sort by Metrics: Although not explicitly detailed in the talk, the underlying data allows for sorting by various metrics, enhancing project comparison.
Finally, a highly valuable, albeit briefly demonstrated, technical feature is the ability to download all landscape data. This functionality allows users to export the entire dataset, often in a structured format like CSV or JSON. This downloaded data includes all the information displayed on the website, such as project names, descriptions, statuses, GitHub metrics, CLO Monitor scores, and crucially, detailed security audit information and issues. This enables offline analysis, integration into internal evaluation systems, and more comprehensive due diligence beyond what is immediately visible on the interactive map.
Demo / Proof of Concept
▶ Watch: Understanding CNCF project status: Sandbox, Incubation, Graduation (5:15)
Katherine Druckman provided a live demonstration of the CNCF Landscape website, showcasing its interactive features and how users can effectively navigate its vast repository of projects. The demonstration served as a practical guide, moving from the overarching visual map to the granular details of individual projects.
The demo began by displaying the current, expansive version of the CNCF Landscape, contrasting it with a historical screenshot of its much smaller, earlier iteration. This stark visual comparison underscored the rapid growth of the cloud-native ecosystem and the necessity of the current, highly organized tool. Druckman then proceeded to illustrate the core functionalities:
- Project Exploration: She navigated the broad categories of the landscape, highlighting how projects are logically grouped. For instance, she pointed out sections for Observability or Automation, demonstrating how users can quickly locate relevant tools within their specific areas of interest.
- Drilling Down into Project Details: Druckman selected the project Kyo as an example to showcase the detailed information available for each entry. Upon clicking Kyo, a pop-up window appeared, revealing:
- Its Incubating status as of 2022, providing context on its maturity level.
- Metrics like the number of contributors and GitHub stars, offering insights into community engagement.
- The date of its latest release, which Druckman emphasized as a critical indicator of active maintenance and project health.
- CLO Monitor Score in Action: A key part of the demo involved highlighting Kyo's impressive CLO Monitor score of 99%. Druckman used this as an opportunity to explain what CLO Monitor is – an automated system performing a series of checks on projects – and to set expectations, noting that such a high score is unusual and users should typically expect scores in the 70s or 80s. This demonstrated how the score provides a quick, data-driven assessment of project health.
- Security Information from OpenSSF Scorecard: Druckman specifically drew attention to the security details displayed for Kyo, noting that this information is likely pulled from OpenSSF Scorecard. She pointed out the various security checks and, critically, identified one "red" item, indicating an area where Kyo could improve its security posture. This practical example effectively illustrated how the landscape can pinpoint specific security gaps, making it invaluable for due diligence and potential contributions.
- Filtering Capabilities: To show how to manage the overwhelming number of projects, Druckman demonstrated the filtering options. She specifically filtered the landscape to show only Graduated projects. This instantly narrowed down the view to the most mature and widely adopted projects, a common requirement for enterprises seeking stable solutions. She also mentioned the ability to filter by project name or category.
- Downloadable Data: Although a technical glitch prevented her from showing the actual downloaded file on screen, Druckman verbally emphasized the utility of the "download all" feature. She explained that users can download the entire dataset, which includes comprehensive information like security issues and audit reports, enabling deeper offline analysis.
The demonstration of selecting Chyros, another Sandbox project, further reinforced how the landscape provides immediate insights into maturity levels and health scores, even for newer projects. Overall, the demo was highly effective in illustrating the practical utility and depth of information available within the CNCF Landscape, transforming it from an abstract concept into a tangible, navigable resource.
Defensive Implications
▶ Watch: Detailed explanation of the project adoption and maturity process (5:40)
For security professionals, developers, and organizations operating in the cloud-native space, the CNCF Landscape is not just a directory but a critical defensive tool. It provides actionable intelligence that can significantly bolster an organization's security posture and mitigate risks associated with adopting open-source technologies.
- Informed Project Selection and Due Diligence: The Landscape empowers defenders to conduct thorough due diligence before integrating any cloud-native project into their stack. By providing immediate visibility into a project's maturity status (Sandbox, Incubation, Graduated), CLO Monitor score, and OpenSSF Scorecard results, security teams can make data-driven decisions. They can prioritize Graduated projects for production environments, knowing they have met stringent CNCF criteria for stability and adoption. For Incubating or Sandbox projects, the Landscape signals that additional scrutiny is required, prompting deeper security reviews, threat modeling, and potentially internal vulnerability assessments before deployment. This proactive approach helps avoid introducing unvetted or insecure components into critical systems.
- Risk Assessment and Vulnerability Identification: The integrated security information, particularly from the OpenSSF Scorecard, is invaluable for risk assessment. Defenders can quickly identify projects with known security weaknesses or those that fail to adhere to essential security best practices (e.g., lack of branch protection, unsigned releases, or inadequate vulnerability reporting processes). A "red flag" on a project's security report serves as an immediate warning, allowing teams to either avoid that project, allocate resources to mitigate identified risks, or engage with the project community to address the issues. The CLO Monitor score also contributes defensively by flagging projects with low activity or infrequent releases, which can become security liabilities due to unpatched vulnerabilities or lack of ongoing maintenance.
- Guiding Contribution for Security Improvement: The Landscape actively encourages a "shift-left" security mentality by highlighting areas where projects need help. If a project vital to an organization's operations shows a specific security weakness on its OpenSSF Scorecard, defenders can identify this gap and contribute directly to its resolution. This could involve submitting pull requests to implement missing security controls, improving documentation around secure usage, or participating in security audits. By contributing to upstream projects, organizations not only improve their own security but also strengthen the entire cloud-native ecosystem, embodying the shared responsibility model inherent in open source.
- Staying Abreast of the Evolving Threat Landscape: The cloud-native space is dynamic, with new projects emerging and existing ones evolving constantly. The Landscape provides a centralized, up-to-date view of this evolution. Security teams can regularly monitor the landscape for new projects that might introduce novel attack vectors or for updates to existing projects that could impact security configurations. The ability to download all project data enables ongoing analysis and integration with internal security intelligence platforms, ensuring that an organization's defensive strategies remain current with the state of cloud-native technologies.
- Fostering a Security-Conscious Culture: By openly displaying project health and security metrics, the CNCF Landscape promotes transparency and encourages a security-conscious culture within the cloud-native community. It provides a common language and set of metrics for discussing project security, empowering developers to consider security implications from the outset and fostering collaboration between security teams and development teams. The emphasis on "making friends" and "getting involved" from the speakers directly translates into building a stronger collective defense against threats.
In essence, the CNCF Landscape transforms the daunting complexity of cloud-native projects into a navigable, transparent, and defensible environment. It equips defenders with the knowledge and tools necessary to proactively manage risks, secure their cloud-native deployments, and contribute to a more robust and resilient open-source ecosystem.
Key Takeaways
- The CNCF Landscape is an indispensable tool for navigating the complex and rapidly expanding cloud-native ecosystem. It organizes hundreds of projects, products, and services into a structured, interactive map, addressing the "overwhelming" nature of the domain.
- Project maturity stages (Sandbox, Incubation, Graduated) are crucial indicators for adoption decisions. These stages, clearly displayed in the landscape, provide a framework for assessing a project's stability, community support, and readiness for production use, guiding users on the level of due diligence required.
- Automated health and security metrics, like the CLO Monitor score and OpenSSF Scorecard, offer critical, data-driven insights into project quality and risk. These integrations provide objective assessments of community activity, code quality, and adherence to security best practices, enabling informed evaluation beyond mere popularity.
- The Landscape provides comprehensive project details, including contributors, GitHub stars, and latest release dates, which are vital for assessing project vitality and maintenance. Infrequent releases or low activity can signal potential risks for long-term support and security.
- Powerful filtering, search capabilities, and downloadable data enhance the utility of the Landscape for in-depth analysis and strategic planning. Users can quickly find specific projects, filter by maturity, and export complete datasets for offline review or integration with internal systems, including critical security audit information.
- Active community involvement and contribution are essential for the health and security of the cloud-native ecosystem. The Landscape highlights areas where projects need help, encouraging users to become contributors and collectively improve the stability and security of the technologies everyone depends on.
About the Speaker(s)
Katherine Druckman is an Open Source Evangelist at Intel, deeply involved in fostering and promoting open-source initiatives. Her work extends to various communities, including the Open Source Security Foundation (OpenSSF) and the Open Platform for Enterprise AI Security (OPEAI Security), underscoring her commitment to security within open-source projects. For this particular KubeCon EU talk, Druckman embraced a playful persona, presenting as the "13th Doctor," inviting the audience on a metaphorical journey through the cloud-native landscape. Her expertise lies in connecting users with projects and encouraging active participation within the open-source community.
Lori Lorusso was listed as a co-speaker for the talk but was unable to attend. Gerald stepped in to co-present with Katherine Druckman. The transcript does not provide further biographical details for Lori Lorusso.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
This talk provides an invaluable, data-driven guide to navigating the overwhelming CNCF Landscape. It moves beyond a simple directory, demonstrating how to leverage integrated health (CLO Monitor) and security (OpenSSF Scorecard) metrics for informed project selection and risk assessment. For anyone grappling with cloud-native complexity, this is actionable intelligence that directly impacts defensive strategy and due diligence.
Heather Calloway (CISO) — STRONG ACCEPT
This talk effectively presents the CNCF Landscape as a critical operational intelligence tool for navigating the overwhelming cloud-native ecosystem. By providing clear data on project maturity, health, and security posture, it enables data-driven risk management and informed decision-making regarding technology adoption, significantly impacting an organization's security and resilience.