CNCF ecosystem and projects
The CNCF landscape, the sandbox, incubating and graduated maturity levels and what each requires, and which graduated project does which job.
Exam tasks: 4.2 (cloud native ecosystem: CNCF landscape, project maturity, the role of key projects)
The decision: given a job (route traffic, store metrics, sync from Git, enforce policy), which CNCF project does it, and how mature is that project?
CNCF in context
- The Cloud Native Computing Foundation is part of the Linux Foundation. It was founded in 2015 with Kubernetes as its first project, donated by Google.
- CNCF is vendor-neutral: it owns project trademarks and pays for shared infrastructure, events and audits. The projects themselves are run by their maintainers.
- The Governing Board handles budget and marketing. The Technical Oversight Committee (TOC) decides which projects join and how they move between levels. See Community and governance.
- The CNCF Landscape (landscape.cncf.io) maps thousands of cloud native products and projects by category. Being on the landscape does not make something a CNCF project; many entries are commercial products.
Maturity levels
| Level | What it signals | Typical requirements |
|---|---|---|
| Sandbox | Early-stage project the CNCF wants to give a neutral home | Aligned with cloud native, TOC accepts the application. Low bar on adoption |
| Incubating | Real production users and a healthy contributor base | Due diligence by the TOC, documented adopters, a sustainable flow of commits and maintainers |
| Graduated | Mature, stable, broadly adopted | Committers from more than one organization, an independent security audit, an OpenSSF Best Practices badge, documented governance, TOC supermajority vote |
| Archived | Retired or inactive project | Kept for reference; no longer promoted |
- Projects can enter at sandbox or incubating; they don't have to start at the bottom.
- Maturity describes the project and community, not a guarantee that it fits your use case.
Exam signal
"Which level requires an independent security audit?" is Graduated. "Which level is for early, experimental projects?" is Sandbox. Questions that list three real levels plus a made-up one ("Beta", "Certified", "Alpha") want you to spot the fake.
Graduated means feature-complete
Graduation is about governance, security process and adoption. Graduated projects keep shipping alpha features (Kubernetes adds alpha APIs every release). Don't confuse CNCF maturity with Kubernetes API levels (alpha, beta, stable).
Who does what: graduated projects
Levels change over time, so check cncf.io/projects before you rely on one. The projects below are all graduated.
| Job | Project | One-line role |
|---|---|---|
| Orchestration | Kubernetes | Container orchestration platform |
| Container runtime | containerd, CRI-O | Run containers for the kubelet through the CRI |
| Cluster data store | etcd | Consistent key-value store holding Kubernetes state |
| Cluster DNS | CoreDNS | Default DNS server for Services and Pods |
| Proxy | Envoy | L7 proxy used as the data plane of many meshes and gateways |
| Networking | Cilium | eBPF-based CNI plugin, network policy and observability |
| Service mesh | Istio, Linkerd | mTLS, traffic management and telemetry between services |
| Metrics | Prometheus | Pull-based metrics collection, time series storage, alerting rules |
| Tracing | Jaeger | Distributed trace storage and UI |
| Telemetry standard | OpenTelemetry | Vendor-neutral APIs, SDKs, OTLP and the Collector |
| Logging | Fluentd (with Fluent Bit) | Collect, filter and route logs |
| Packaging | Helm | Package manager for Kubernetes: charts, releases, rollback |
| GitOps and workflows | Argo, Flux | Argo CD and Flux sync clusters from Git; Argo also has Workflows and Rollouts |
| Policy | Open Policy Agent (OPA), Kyverno | Policy as code. OPA uses Rego; Kyverno uses Kubernetes-style YAML |
| Runtime security | Falco | Detects suspicious behaviour from kernel events |
| Certificates | cert-manager | Issues and renews TLS certificates as Kubernetes resources |
| Workload identity | SPIFFE, SPIRE | SPIFFE is the identity standard; SPIRE implements it |
| Supply chain | TUF, in-toto | Secure update delivery and verifiable build steps |
| Registry | Harbor | Container registry with scanning, signing and replication |
| Storage | Rook | Runs Ceph storage as a Kubernetes operator |
| Event-driven and serverless | KEDA, Knative, CloudEvents | Event-based autoscaling, serverless platform, event format spec |
| Infrastructure as APIs | Crossplane | Manage cloud resources through Kubernetes APIs |
| Container images from source | Buildpacks | Build OCI images from source without a Dockerfile |
| Multi-cluster and edge | Karmada, KubeEdge | Schedule across clusters; extend Kubernetes to edge devices |
| Distributed app runtime | Dapr | Sidecar APIs for state, pub/sub and service calls |
| Machine learning | Kubeflow | ML pipelines and training on Kubernetes |
| Databases | Vitess, TiKV | Sharded MySQL; distributed transactional key-value store |
A few common incubating projects you may see: Backstage (developer portals), Thanos and Cortex (scaling Prometheus), OpenCost (cost allocation), Longhorn (block storage), Tekton (CI/CD pipelines), and the CNI specification itself.
Not every famous tool is a CNCF project
Docker, Terraform, Grafana and Jenkins appear in cloud native stacks but are not CNCF projects. Jenkins belongs to the CD Foundation, another Linux Foundation group. If an option asks for a CNCF project, cross these off.
Neighbouring foundations and standards bodies
- Open Container Initiative (OCI): a separate Linux Foundation project that defines the image, runtime and distribution specs. runc is its reference runtime.
- OpenSSF: open source security foundation (Scorecard, Best Practices badge, Sigstore).
- CD Foundation: continuous delivery projects such as Jenkins and Spinnaker.
Scenarios
The security audit and multi-organization committer requirements belong to graduation. Incubating projects have production users but not necessarily an audit. Sandbox is the early stage. "Stable" is a Kubernetes API maturity term, not a CNCF level.
Flux (like Argo CD) is a GitOps controller that pulls from Git and reconciles the cluster. Helm packages and installs charts but doesn't watch Git on its own. Prometheus collects metrics, and Envoy is a proxy.
Kyverno is a policy engine whose policies are Kubernetes resources written in YAML, and it can validate, mutate or generate objects at admission. OPA also enforces admission policy but uses the Rego language. Falco detects runtime behaviour after Pods start, and cert-manager handles certificates.
Further reading
Cloud native principles
What "cloud native" means in the CNCF definition, microservices vs monoliths, immutability and declarative APIs, autoscaling with HPA, VPA, Cluster Autoscaler and KEDA, and serverless with Knative.
Community and governance
How the CNCF is run (Governing Board, TOC, the five TAGs), how Kubernetes is run (Steering Committee, SIGs, working groups, KEPs), the release cycle, and the open standards that keep the ecosystem pluggable.