This article may have been created or edited in return for undisclosed payments, a violation of Wikipedia's terms of use. It may require cleanup to comply with Wikipedia's content policies, particularly neutral point of view. (February 2020) |
Abbreviation | CNCF |
---|---|
Formation | 2015 |
Type | 501(c)(6) organization |
Purpose | Building sustainable ecosystems for cloud native software |
General Manager | Priyanka Sharma |
CTO | Chris Aniszczyk |
Parent organization | The Linux Foundation |
Website | www |
The Cloud Native Computing Foundation (CNCF) is a Linux Foundation project that was started in 2015 to help advance container technology [1] and align the tech industry around its evolution.
It was announced alongside Kubernetes 1.0, an open source container cluster manager, which was contributed to the Linux Foundation by Google as a seed technology. Founding members include Google, CoreOS, Mesosphere, Red Hat, Twitter, Huawei, Intel, RX-M, Cisco, IBM, Docker, Univa, and VMware. [2] [3] Today, CNCF is supported by over 450 members. In order to establish qualified representatives of the technologies governed by the CNCF, a program was announced at the inaugural CloudNativeDay in Toronto in August, 2016. [4]
Dan Kohn (who also helped launch the Core Infrastructure Initiative) led CNCF as executive director until May 2020. [5] [6] The foundation announced Priyanka Sharma, director of Cloud Native Alliances at GitLab, would step into a general manager role in his place. [6] Sharma describes CNCF as "a very impactful organization built by a small group of people but [within] a very large ecosystem" and believes that CNCF is entering into a "second wave" due to increased industry awareness and adoption. [7]
In August 2018 Google announced that it was handing over operational control of Kubernetes to the community. [8] Since its creation, CNCF has launched a number of hosted sub-projects.
In January 2020, the CNCF annual report for the previous year was issued and reflected significant growth to the foundation across membership, event attendance, training, and industry investment. In 2019, CNCF grew by 50% since the previous year with 173 new members and nearly 90% growth in end-users. [9] The report revealed a 78% increase in the usage of Kubernetes in production. [10]
CNCF technology projects are cataloged with a maturity level of Sandbox, Incubated, and Graduated, in ascending order. [11] The defined criteria include rate of adoption, longevity and whether the open source project can be relied upon to build a production-grade product. [12]
CNCF's process brings projects in as incubated projects and then aims to move them through to graduation, which implies a level of process and technology maturity. [13] A graduated project reflects overall maturity; these projects have reached a tipping point in terms of diversity of contribution, community scale/growth, and adoption. [14]
The CNCF Sandbox is a place for early-stage projects, and it was first announced in March 2019. The Sandbox replaces what had originally been called the "inception project level". [15]
In July 2020, Priyanka Sharma stated that CNCF is looking to increase the number of open source projects in the cloud native ecosystem. [16]
Cilium provides networking, security, and observability for Kubernetes deployments using eBPF technology. It joined the CNCF at incubation level in October 2021 [17] and the CNCF announced its graduation in October 2023. [18]
containerd is an industry-standard core container runtime. It is currently available as a daemon for Linux and Windows, which can manage the complete container lifecycle of its host system. In 2015, Docker donated the OCI Specification to The Linux Foundation with a reference implementation called runc. Since February 28, 2019 it is an official CNCF project. [19] Its general availability and intention to donate the project to CNCF was announced by Docker in 2017. [20] [21]
CoreDNS is a DNS server that chains plugins. Its graduation was announced in 2019. [22]
Originally built at Lyft to move their architecture away from a monolith, Envoy is a high-performance open source edge and service proxy that makes the network transparent to applications. Lyft contributed Envoy to Cloud Native Computing Foundation in September 2017. [23]
etcd is a distributed key value store, providing a method of storing data across a cluster of machines. [24] It became a CNCF incubating project in 2018 at KubeCon+CloudNativeCon North America [25] in Seattle that year. [26]
Falco is an open source and cloud native runtime security initiative. It is the "de facto Kubernetes threat detection engine". [27] It became an incubating project in January 2020 [28] and graduated in February 2024. [29]
Harbor is an "open source trusted cloud native registry project that stores, signs, and scans content." [30] It became an incubating project in September 2019 [31] and graduated in June 2020. [32]
Helm is a package manager that helps developers "easily manage and deploy applications onto the Kubernetes cluster." [31] It joined the incubating level in June 2018 and graduated in April 2020. [33]
Istio is a service mesh technology. It was accepted by CNCF in September 2022 and graduated on July 12, 2023. [34] [35]
Created by Uber Engineering, Jaeger is an open source distributed tracing system inspired by Google Dapper paper and OpenZipkin community. It can be used for tracing microservice-based architectures, including distributed context propagation, distributed transaction monitoring, root cause analysis, service dependency analysis, and performance/latency optimization. The Cloud Native Computing Foundation Technical Oversight Committee voted to accept Jaeger as the 12th hosted project in September 2017 [36] and became a graduated project in 2019. [37] In 2020 it became an approved and fully integrated part of the CNCF ecosystem. [38]
Kubernetes is an open source framework for automating deployment and managing applications in a containerized and clustered environment. "It aims to provide better ways of managing related, distributed components across the varied infrastructure." [39] It was originally designed by Google and donated to The Linux Foundation to form the Cloud Native Computing Foundation with Kubernetes as the seed technology. [40] The "large and diverse" community supporting the project has made its staying power more robust than other, older technologies of the same ilk. [41] In January 2020, the CNCF annual report showed significant growth in interest, training, event attendance and investment related to Kubernetes. [42]
Linkerd is CNCF's fifth member project, and the project that coined the term “service mesh". [43] Linkerd adds observability, security, and reliability features to applications by adding them to the platform rather than the application layer, [44] and features a "micro-proxy" to maximize speed and security of its data plane. [45] Linkerd graduated from CNCF in July 2021. [46]
Open Policy Agent (OPA) is "an open source general-purpose policy engine and language for cloud infrastructure." [47] It became a CNCF incubating project in April 2019. [48] OPA graduated from CNCF in February 2021. [49]
A Cloud Native Computing Foundation member project, Prometheus is a cloud monitoring tool sponsored by SoundCloud in early iterations. In August 2018, the tool was designated a graduated project by the Cloud Native Computing Foundation. [14]
Rook is CNCF's first cloud native storage project. [50] It became an incubation level project in 2018 [51] and graduated in October 2020. [52]
SPIFFE is an open standard and framework for workload identity, much the same way that OAuth is an open standard and framework for human identity. It is built from the ground up to accommodate modern computing environments, which operate with systems scale and velocity (as opposed to human scale and velocity), while still maintaining interoperability with existing technologies like OAuth and X.509 Public key infrastructure. Unlike other identity standards, SPIFFE supports multiple credential types for a single identity, ensuring that the highly varied needs of production environments are consistently met without compromise. SPIFFE joined the CNCF as a sandbox project in 2018, was accepted to incubation in 2020, and graduated in 2022. [53]
SPIRE is an open source identity provider for workloads based on the SPIFFE framework. It is highly pluggable, and fills the attestation and issuance needs required by any workload identity solution. The plugin interfaces it exposes allows users to write integrations with in-house systems, build internal self-service portals, and more. It is a very powerful building block for issuing short-lived identity credentials to dynamic cloud workloads. SPIRE became a CNCF Graduated project in 2022. [54]
The Update Framework (TUF) helps developers to secure new or existing software update systems, which are often found to be vulnerable to many known attacks. TUF addresses this widespread problem by providing a comprehensive, flexible security framework that developers can integrate with any software update system. TUF was CNCF's first security-focused project and the ninth project overall to graduate from the foundation's hosting program. [55]
TikV provides a distributed key–value database. [56]
Vitess is a database clustering system for horizontal scaling of MySQL, first created for internal use by YouTube. It became a CNCF project in 2018 and graduated in November 2019. [57]
Contour is a management server for Envoy that can direct the management of Kubernetes' traffic. Contour also provides routing features that are more advanced than Kubernetes' out-of-the-box Ingress specification. VMWare contributed the project to CNCF in July 2020. [58]
Cortex offers horizontally scalable, multi-tenant, long-term storage for Prometheus and works alongside Amazon DynamoDB, Google Bigtable, Cassandra, S3, GCS, and Microsoft Azure. It was introduced into the ecosystem incubator alongside Thanos in August 2020. [59]
CRI-O is an Open Container Initiative (OCI) based "implementation of Kubernetes Container Runtime Interface". [60] CRI-O allows Kubernetes to be container runtime-agnostic. [61] It became an incubating project in 2019. [62]
gRPC is a "modern open source high performance RPC framework that can run in any environment." [63] The project was formed in 2015 when Google decided to open source the next version of its RPC infrastructure ("Stubby"). [64] The project has a number of early large industry adopters such as Square, Inc., Netflix, and Cisco. [63]
In September 2020, CNCF's Technical Oversight Committee (TOC) announced that KubeEdge was accepted as an incubating project. The project was created at Futurewei (a Huawei partner). KubeEdge's goal is to "make edge devices an extension of the cloud". [65]
In June 2020, API management platform Kong announced that it would donate its open-source service mesh control plane technology, called Kuma, to CNCF as a sandbox project. [66]
In July 2020, MayaData donated Litmus, an open source chaos engineering tool that runs natively on Kubernetes, to CNCF as a sandbox-level project. [67]
NATS consists of a collection of open source messaging technologies that "implements the publish/subscribe, request/reply and distributed queue patterns to help create a performant and secure method of InterProcess Communication (IPC)." [68] It existed independently for a number of years but gained wider reach since becoming a CNCF incubating project. [69]
Notary is an open source project that enables widespread trust over arbitrary data collections. [70] Notary was released by Docker in 2015 and became a CNCF project in 2017. [71]
OpenTelemetry is an open source observability framework created when CNCF merged the OpenTracing and OpenCensus projects. [72] OpenTracing offers "consistent, expressive, vendor-neutral APIs for popular platforms" [73] while the Google-created OpenCensus project acts as a "collection of language-specific libraries for instrumenting an application, collecting stats (metrics), and exporting data to a supported backend." [74] Under OpenTelemetry, the projects create a "complete telemetry system [that is] suitable for monitoring microservices and other types of modern, distributed systems — and [is] compatible with most major OSS and commercial backends." [75] It is the "second most active" CNCF project. [76] In October 2020, AWS announced the public preview of its distro for OpenTelemetry. [77]
Thanos enables global query views and unlimited retention of metrics. It was designed to be easily addable to Prometheus deployments. [59]
CNCF hosts a number of efforts and initiatives to serve the cloud native community, including:
CNCF hosts the co-located KubeCon and CloudNativeCon conferences, which have become a keystone events for technical users and business professionals seeking to increase Kubernetes and cloud-native knowledge. The events seek to enable collaboration with industry peers and thought leaders. [78] The North America event was moved to an entirely remote model for its 2020 season due to the COVID-19 pandemic. [79]
Event | Date | Place | Ref. |
---|---|---|---|
CloudNativeCon + KubeCon 2016 | Nov 8–9, 2016 | Seattle, Washington, United States | [80] |
CloudNativeCon + KubeCon Europe 2017 | March 29–30, 2017 | Berlin Congress Center, Berlin, Germany | [81] |
KubeCon + CloudNativeCon North America 2017 | Dec 6–8, 2017 | Austin Convention Center, Austin, Texas, United States | [82] |
KubeCon + CloudNativeCon Europe 2018 | May 2–4, 2018 | Bella Center, Copenhagen, Denmark | [83] |
KubeCon + CloudNativeCon China 2018 | Nov 14–15, 2018 | Shanghai Convention & Exhibition Center of International Sourcing, Shanghai, China | [84] |
KubeCon + CloudNativeCon North America 2018 | Dec 11–13, 2018 | Washington State Convention Center, Seattle, Washington, United States | [85] |
KubeCon + CloudNativeCon Europe 2019 | May 20–23, 2019 | Fira Gran Via, Barcelona, Spain | [86] |
KubeCon + CloudNativeCon + Open Source Summit China 2019 | Jun 25–26, 2019 | Shanghai Expo Centre, Shanghai, China | [87] |
KubeCon + CloudNativeCon North America 2019 | Nov 18–21, 2019 | San Diego Convention Center, San Diego, California, United States | [88] |
KubeCon + CloudNativeCon Europe 2020 | March 30-April 2, 2020 | Virtual [Note 1] | [89] |
KubeCon + CloudNativeCon North America 2020 | Nov 17–20, 2020 | Virtual [Note 2] | [90] |
KubeCon + CloudNativeCon Europe 2021 | May 4–7, 2021 | Virtual | [89] |
KubeCon + CloudNativeCon North America 2021 | Oct 12–15, 2021 | Los Angeles Convention Center, Los Angeles, California, United States | [91] |
KubeCon + CloudNativeCon Europe 2022 | May 16–18, 2022 | Feria Valencia, Valencia, Spain | [92] |
KubeCon + CloudNativeCon North America 2023 | November 6–9, 2023 | McCormick Place, Chicago, Illinois United States | [93] |
KubeCon + CloudNativeCon Europe 2024 | March 19–22, 2024 | Porte de Versailles, Paris, France | [94] |
CNCF's Diversity Scholarship program covers the ticket and travel to the KubeCon + CloudNativeCon conference. [95] In 2018, $300,000 in diversity scholarships was raised to enable attendees from diverse and minority backgrounds to make the journey to Seattle for KubeCon and CloudNativeCon. [96]
In August 2020, Priyanka Sharma stated that CNCF stands "in solidarity" with the Black Lives Matter movement. Sharma also stated that she was "personally involved in a project to eradicate racially problematic terminology from code" and that the foundation is "actively working to improve the gender and racial balance inside the cloud native ecosystem" while remaining committed to creating spaces and opportunities for LGBTQIA+, women, Black and Brown people, and differently-abled people, specifically in regards to KubeCon. [97]
One path toward becoming a Kubernetes-certified IT professional is the vendor-agnostic Certified Kubernetes Administrator (CKA) accreditation, which is relevant to admins who work across a range of cloud platforms. [98] There are tens of thousands of Certified Kubernetes Administrators (CKA) and Certified Kubernetes Application Developers (CKAD) worldwide. [99]
CNCF's Certified Kubernetes Conformance Program (KCSP) enables vendors to prove that their product and service conformant with a set of core Kubernetes APIs and are interoperable with other Kubernetes implementations. At the end of 2018, there were 76 firms that had validated their offerings with the Certified Kubernetes Conformance Program. [100]
In 2017, CNCF also helped the Linux Foundation launch a free Kubernetes course on the EdX platform [101] — which has more than 88,000 enrollments. [102] The self-paced course covers the system architecture, the problems Kubernetes solves, and the model it uses to handle containerized deployments and scaling. The course also includes technical instructions on how to deploy a standalone and multi-tier application. [102]
CNCF developed a landscape map that shows the full extent of cloud native solutions, many of which fall under their umbrella. [103] The interactive catalog gives an idea of the problems facing engineers and developers in deciding which products to use. This interactive catalog was created in response to the proliferation of third-party technologies and the resulting decision-fatigue engineers and developers often experience when selecting software tools. In addition to mapping out the relevant and existing cloud native solutions, CNCF's landscape map provides details on the solutions themselves including open source status, contributors, and more. [104]
The landscape map has been the subject of various jokes on Twitter due to the CNCF ecosystem's expansiveness and visual complexity. [105]
CNCF's Cloud Native Trail Map outlines the open source cloud native technologies hosted by the Foundation and outlines the recommended path for building a cloud native operation using the projects under its wing. The Cloud Native Trail Map also acts as an interactive and comprehensive guide to cloud technologies. [106]
CNCF's DevStats tool provides analysis of GitHub activity for Kubernetes and the other CNCF projects. Dashboards track a multitude of metrics, including the number of contributions, the level of engagement of contributors, how long it takes to get a response after an issue is opened, and which special interest groups (SIGs) are the most responsive. [107]
In June 2020, CNCF published the inaugural issue of the CNCF Technology Radar, an "opinionated guide to a set of emerging technologies" in the form of a quarterly paper. [108]
OS-level virtualization is an operating system (OS) virtualization paradigm in which the kernel allows the existence of multiple isolated user space instances, called containers, zones, virtual private servers (OpenVZ), partitions, virtual environments (VEs), virtual kernels, or jails. Such instances may look like real computers from the point of view of programs running in them. A computer program running on an ordinary operating system can see all resources of that computer. However, programs running inside of a container can only see the container's contents and devices assigned to the container.
OpenShift is a family of containerization software products developed by Red Hat. Its flagship product is the OpenShift Container Platform — a hybrid cloud platform as a service built around Linux containers orchestrated and managed by Kubernetes on a foundation of Red Hat Enterprise Linux. The family's other products provide this platform through different environments: OKD serves as the community-driven upstream, Several deployment methods are available including self-managed, cloud native under ROSA, ARO and RHOIC on AWS, Azure, and IBM Cloud respectively, OpenShift Online as software as a service, and OpenShift Dedicated as a managed service.
Docker is a set of platform as a service (PaaS) products that use OS-level virtualization to deliver software in packages called containers. The service has both free and premium tiers. The software that hosts the containers is called Docker Engine. It was first released in 2013 and is developed by Docker, Inc.
Kubernetes is an open-source container orchestration system for automating software deployment, scaling, and management. Originally designed by Google, the project is now maintained by a worldwide community of contributors, and the trademark is held by the Cloud Native Computing Foundation.
Mirantis Inc. is a Campbell, California, based B2B open source cloud computing software and services company. Its primary container and cloud management products, part of the Mirantis Cloud Native Platform suite of products, are Mirantis Container Cloud and Mirantis Kubernetes Engine. The company focuses on the development and support of container and cloud infrastructure management platforms based on Kubernetes and OpenStack. The company was founded in 1999 by Alex Freedland and Boris Renski. It was one of the founding members of the OpenStack Foundation, a non-profit corporate entity established in September, 2012 to promote OpenStack software and its community. Mirantis has been an active member of the Cloud Native Computing Foundation since 2016.
Virtuozzo is a software company that develops virtualization and cloud management software for cloud computing providers, managed services providers and internet hosting service providers. The company's software enables service providers to offer Infrastructure as a service, Container-as-a-Service, Platform as a service, Kubernetes-as-a-Service, WordPress-as-a-Service and other solutions.
Dan Kohn was an American serial entrepreneur and nonprofit executive who led the Linux Foundation's Public Health initiative. He was the executive director at Cloud Native Computing Foundation (CNCF), which sustains and integrates open source cloud software including Kubernetes and Fluentd, through 2020. The first company he founded, NetMarket, conducted the first secure commercial transaction on the web in 1994.
The Update Framework (TUF) is a software framework designed to protect mechanisms that automatically identify and download updates to software. TUF uses a series of roles and keys to provide a means to retain security, even when some keys or servers are compromised. It does this with a stated goal of requiring minimal changes and effort from repository administrators, software developers, and end users. In this way, it protects software repositories, which are an increasingly desirable target for hackers.
Prometheus is a free software application used for event monitoring and alerting. It records metrics in a time series database built using an HTTP pull model, with flexible queries and real-time alerting. The project is written in Go and licensed under the Apache 2 License, with source code available on GitHub, and is a graduated project of the Cloud Native Computing Foundation, along with Kubernetes and Envoy.
Container Linux is a discontinued open-source lightweight operating system based on the Linux kernel and designed for providing infrastructure for clustered deployments. One of its focuses was scalability. As an operating system, Container Linux provided only the minimal functionality required for deploying applications inside software containers, together with built-in mechanisms for service discovery and configuration sharing.
gVisor is a container sandbox developed by Google that focuses on security, efficiency and ease of use. gVisor implements around 200 of the Linux system calls in userspace, for additional security compared to Docker containers that run directly on top of the Linux kernel and are isolated with namespaces. Unlike the Linux kernel, gVisor is written in the memory-safe programming language Go to prevent common pitfalls which frequently occur in software written in C.
TiDB is an open-source NewSQL database that supports Hybrid Transactional and Analytical Processing (HTAP) workloads. Designed to be MySQL compatible, it is developed and supported primarily by PingCAP and licensed under Apache 2.0. It is also available as a paid product. TiDB drew its initial design inspiration from Google's Spanner and F1 papers.
Kubeflow is an open-source platform for machine learning and MLOps on Kubernetes introduced by Google. The different stages in a typical machine learning lifecycle are represented with different software components in Kubeflow, including model development (Kubeflow Notebooks), model training (Kubeflow Pipelines,Kubeflow Training Operator), model serving (KServe), and automated machine learning (Katib).
Cloud native computing is an approach in software development that utilizes cloud computing to "build and run scalable applications in modern, dynamic environments such as public, private, and hybrid clouds". These technologies, such as containers, microservices, serverless functions, cloud native processors and immutable infrastructure, deployed via declarative code are common elements of this architectural style. Cloud native technologies focus on minimizing users' operational burden.
A cloud-native network function (CNF) is a software-implementation of a function, or application, traditionally performed on a physical device, but which runs inside Linux containers. The features that differ CNFs from VNFs, one of the components of network function virtualization, is the approach in their orchestration.
Open Service Mesh (OSM) was a free and open source cloud native service mesh developed by Microsoft that ran on Kubernetes.
Ian Coldwater is an American computer security specialist, hacker, and speaker specializing in Kubernetes and cloud native security. They are a Senior Principal Security Architect at Docker, Inc., and co-chair the Kubernetes special interest group Kubernetes SIG Security.
Kelsey Hightower is an American software engineer, developer advocate, and speaker known for his work with Kubernetes, open-source software, and cloud computing.
eBPF is a technology that can run programs in a privileged context such as the operating system kernel. It is the successor to the Berkeley Packet Filter (BPF) filtering mechanism in Linux, and is also used in other parts of the Linux kernel as well.
Cilium is a cloud native technology for networking, observability, and security. It is based on the kernel technology eBPF, originally for better networking performance, and now leverages many additional features for different use cases. The core networking component has evolved from only providing a flat Layer 3 network for containers to including advanced networking features, like BGP and Service mesh, within a Kubernetes cluster, across multiple clusters, and connecting with the world outside Kubernetes. Hubble was created as the network observability component and Tetragon was later added for security observability and runtime enforcement. Cilium runs on Linux and is one of the first eBPF applications being ported to Microsoft Windows through the eBPF on Windows project.