Asterrr's Handbook

CNCF ecosystem and projects

The CNCF landscape, the sandbox, incubating and graduated maturity levels and what each requires, and which graduated project does which job.

Exam tasks: 4.2 (cloud native ecosystem: CNCF landscape, project maturity, the role of key projects)

The decision: given a job (route traffic, store metrics, sync from Git, enforce policy), which CNCF project does it, and how mature is that project?

CNCF in context

  • The Cloud Native Computing Foundation is part of the Linux Foundation. It was founded in 2015 with Kubernetes as its first project, donated by Google.
  • CNCF is vendor-neutral: it owns project trademarks and pays for shared infrastructure, events and audits. The projects themselves are run by their maintainers.
  • The Governing Board handles budget and marketing. The Technical Oversight Committee (TOC) decides which projects join and how they move between levels. See Community and governance.
  • The CNCF Landscape (landscape.cncf.io) maps thousands of cloud native products and projects by category. Being on the landscape does not make something a CNCF project; many entries are commercial products.

Maturity levels

LevelWhat it signalsTypical requirements
SandboxEarly-stage project the CNCF wants to give a neutral homeAligned with cloud native, TOC accepts the application. Low bar on adoption
IncubatingReal production users and a healthy contributor baseDue diligence by the TOC, documented adopters, a sustainable flow of commits and maintainers
GraduatedMature, stable, broadly adoptedCommitters from more than one organization, an independent security audit, an OpenSSF Best Practices badge, documented governance, TOC supermajority vote
ArchivedRetired or inactive projectKept for reference; no longer promoted
  • Projects can enter at sandbox or incubating; they don't have to start at the bottom.
  • Maturity describes the project and community, not a guarantee that it fits your use case.

Exam signal

"Which level requires an independent security audit?" is Graduated. "Which level is for early, experimental projects?" is Sandbox. Questions that list three real levels plus a made-up one ("Beta", "Certified", "Alpha") want you to spot the fake.

Graduated means feature-complete

Graduation is about governance, security process and adoption. Graduated projects keep shipping alpha features (Kubernetes adds alpha APIs every release). Don't confuse CNCF maturity with Kubernetes API levels (alpha, beta, stable).

Who does what: graduated projects

Levels change over time, so check cncf.io/projects before you rely on one. The projects below are all graduated.

JobProjectOne-line role
OrchestrationKubernetesContainer orchestration platform
Container runtimecontainerd, CRI-ORun containers for the kubelet through the CRI
Cluster data storeetcdConsistent key-value store holding Kubernetes state
Cluster DNSCoreDNSDefault DNS server for Services and Pods
ProxyEnvoyL7 proxy used as the data plane of many meshes and gateways
NetworkingCiliumeBPF-based CNI plugin, network policy and observability
Service meshIstio, LinkerdmTLS, traffic management and telemetry between services
MetricsPrometheusPull-based metrics collection, time series storage, alerting rules
TracingJaegerDistributed trace storage and UI
Telemetry standardOpenTelemetryVendor-neutral APIs, SDKs, OTLP and the Collector
LoggingFluentd (with Fluent Bit)Collect, filter and route logs
PackagingHelmPackage manager for Kubernetes: charts, releases, rollback
GitOps and workflowsArgo, FluxArgo CD and Flux sync clusters from Git; Argo also has Workflows and Rollouts
PolicyOpen Policy Agent (OPA), KyvernoPolicy as code. OPA uses Rego; Kyverno uses Kubernetes-style YAML
Runtime securityFalcoDetects suspicious behaviour from kernel events
Certificatescert-managerIssues and renews TLS certificates as Kubernetes resources
Workload identitySPIFFE, SPIRESPIFFE is the identity standard; SPIRE implements it
Supply chainTUF, in-totoSecure update delivery and verifiable build steps
RegistryHarborContainer registry with scanning, signing and replication
StorageRookRuns Ceph storage as a Kubernetes operator
Event-driven and serverlessKEDA, Knative, CloudEventsEvent-based autoscaling, serverless platform, event format spec
Infrastructure as APIsCrossplaneManage cloud resources through Kubernetes APIs
Container images from sourceBuildpacksBuild OCI images from source without a Dockerfile
Multi-cluster and edgeKarmada, KubeEdgeSchedule across clusters; extend Kubernetes to edge devices
Distributed app runtimeDaprSidecar APIs for state, pub/sub and service calls
Machine learningKubeflowML pipelines and training on Kubernetes
DatabasesVitess, TiKVSharded MySQL; distributed transactional key-value store

A few common incubating projects you may see: Backstage (developer portals), Thanos and Cortex (scaling Prometheus), OpenCost (cost allocation), Longhorn (block storage), Tekton (CI/CD pipelines), and the CNI specification itself.

Not every famous tool is a CNCF project

Docker, Terraform, Grafana and Jenkins appear in cloud native stacks but are not CNCF projects. Jenkins belongs to the CD Foundation, another Linux Foundation group. If an option asks for a CNCF project, cross these off.

Neighbouring foundations and standards bodies

  • Open Container Initiative (OCI): a separate Linux Foundation project that defines the image, runtime and distribution specs. runc is its reference runtime.
  • OpenSSF: open source security foundation (Scorecard, Best Practices badge, Sigstore).
  • CD Foundation: continuous delivery projects such as Jenkins and Spinnaker.

Scenarios

Scenario
Which CNCF maturity level indicates a project has been adopted in production, passed an independent security audit, and has committers from multiple organizations?
Scenario
Ridgeback Logistics wants a CNCF graduated project that keeps clusters in sync with manifests stored in a Git repository. Which project fits?
Scenario
A security team wants to reject Pods that run as root, writing the rules as Kubernetes-style YAML rather than learning a new policy language. Which CNCF project is the best fit?

Further reading

On this page