Loading…
Attending this event?
In-person
November 12-15
Learn More and Register to Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for KubeCon + CloudNativeCon North America 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Mountain Standard Time (UTC -7). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date." The schedule is subject to change and session seating is available on a first-come, first-served basis. 
Hyatt Regency | Level 4 | Regency Ballroom BCD clear filter
Tuesday, November 12
 

9:01am MST

Welcome and Introduction: A Hitchhiker's Guide to the CNCF Landscape - Katherine Druckman and Lori Lorusso
Tuesday November 12, 2024 9:01am - 9:22am MST
“Get your hiking boots ready because we are about to traverse the wild, wonderful world of the CNCF Landscape. Why you ask? We currently have over 190 projects, and finding information about them can be a challenge. “Just go to the website” isn’t enough, sometimes you need a guide to show you the ropes. In these introductory sessions we will go over some of the diverse set of projects inside the CNCF so that you’re well equipped to find what you’re looking for at KubeCon.
Tuesday November 12, 2024 9:01am - 9:22am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

9:24am MST

TAG Contributor Strategy: Beyond the Checkbox: Humanizing Accessibility | Project Lightning Talk
Tuesday November 12, 2024 9:24am - 9:29am MST
Accessibility is often an afterthought, a checklist item rather than a fundamental right. That is especially true for people who have never met a person with a disability. While recognized as important, accessibility is still an abstract concept. This talk challenges that perception by sharing personal stories and practical insights, putting a human face to accessibility. This CNCF Deaf and Hard of Hearing WG talk aims to bridge the gap and foster empathy. Discover how to shift from mere compliance to empathy, building a truly inclusive environment where everyone feels valued and belonged. Attendees will leave inspired to become accessibility advocates in their own communities.
Tuesday November 12, 2024 9:24am - 9:29am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

9:31am MST

Buildpacks: Container Builds at Scale with Buildpacks | Project Lightning Talk
Tuesday November 12, 2024 9:31am - 9:36am MST
Cloud Native Buildpacks transform your application source code into images that can run on any cloud. They enable advanced caching mechanisms that improve performance at scale. They also allow for modularity and reuse, which ensure developers across your organization aren’t wasting cycles repeating what other teams have already done.

After this short talk, you’ll be able to run buildpacks with the Pack CLI and find off-the-shelf buildpacks in the Buildpack Registry, including those from Google, Heroku, and Paketo. Finally, you’ll learn how operators of large platforms use buildpacks to make their container builds as scalable as possible.
Tuesday November 12, 2024 9:31am - 9:36am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

9:38am MST

Flux: What's Flux and What's New? | Project Lightning Talk
Tuesday November 12, 2024 9:38am - 9:43am MST
Get a quick intro of GitOps and Progressive delivery using Flux, how to get started, and new capabilities with the last release of 2024.

We'll walk you through key features of Flux (a graduated project and GA) such as being multi-everything (multi-tenant, multi-cluster, etc.). And Flux works with your existing tools (like CI and Kubernetes tools).

We'll cover reliability and security reasons that Flux is the GitOps tool of choice for cloud vendors, global enterprises, and other companies.
Tuesday November 12, 2024 9:38am - 9:43am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

9:45am MST

Vitess: Arewefastyet: Benchmarking Vitess and Mentorship Stories | Project Lightning Talk
Tuesday November 12, 2024 9:45am - 9:50am MST
Join us for a lightning talk on ""arewefastyet"", the benchmarking tool used by Vitess. We will present the highlights of our benchmarking methods and share insights from the LFX Mentorship program. Our LFX mentee will present their work and share their experience with open-source contributions and the LFX Mentorship program.
Learn about the latest in Vitess performance and the role of mentorship in driving innovation.
Tuesday November 12, 2024 9:45am - 9:50am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

9:52am MST

Strimzi: Strimzi and the Future of Apache Kafka on Kubernetes | Project Lightning Talk
Tuesday November 12, 2024 9:52am - 9:57am MST
Strimzi is a CNCF incubating project focusing on running Apache Kafka on Kubernetes. It provides a set of operators and other tools to make data streaming on Kubernetes as simple as possible. This lightning talk will give a quick introduction to Strimzi and its capabilities. It will also provide an update on the current and planned work - go through the main changes and new features and cover the future plans.
Tuesday November 12, 2024 9:52am - 9:57am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

9:59am MST

Jaeger: Distributed Tracing with Jaeger and OpenTelemetry | Project Lightning Talk
Tuesday November 12, 2024 9:59am - 10:04am MST
In this session, we will provide project updates. Mostly focused on the future of Jaeger as we move towards our next major version V2, and further integration with the OpenTelemetry project. We will also include project updates since the last Kubecon in North America.
Tuesday November 12, 2024 9:59am - 10:04am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

10:06am MST

Kepler: How's Things Going in Kepler? | Project Lightning Talk
Tuesday November 12, 2024 10:06am - 10:11am MST
Kepler is envisioned for utmost transparency in estimating container power usage and offering insights into container energy efficiency and carbon footprint. Since Kepler's acceptance into the CNCF Sandbox one year ago, the project has significantly expanded its community and visibility. In this session, we will showcase our latest community engagements and updates, focusing on advancements in metric collection and power modeling. These include the adoption of cilium-go and the introduction of a new validation framework, promising to further enhance robustness.
Tuesday November 12, 2024 10:06am - 10:11am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

10:13am MST

OpenTelemetry: OpenTelemetry in Five Minutes | Project Lightning Talk
Tuesday November 12, 2024 10:13am - 10:18am MST
Why is OpenTelemetry so complicated? is a question that we hear -- a lot! There's a lot of reasons for it, and in this lightning talk, we'll briefly touch on the fundamentals behind the OpenTelemetry design and architecture, and why those design decisions help enable the projects goal of making observability a built-in feature of cloud-native software.
Tuesday November 12, 2024 10:13am - 10:18am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

10:20am MST

Prometheus: Celebrating Prometheus 3.0: All You Need To Know! | Project Lightning Talk
Tuesday November 12, 2024 10:20am - 10:25am MST
Prometheus is an open-source systems monitoring system, and a CNCF Graduated project.

This year Prometheus releases the 3.0 version, which comes with the new features, refreshed UI, UX cleanup, while building on top of what worked well for years!

Join this lightning talk to celebrate the Prometheus 3.0 version and learn what it enables for new and existing users, how to upgrade and how to get the most out of the new version!
Tuesday November 12, 2024 10:20am - 10:25am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

10:27am MST

OpenTelemetry: The OpenTelemetry Hero’s Journey: Working with Open Source Observability | Project Lightning Talk
Tuesday November 12, 2024 10:27am - 10:32am MST
Having correlated metrics, traces, and logs from our services and infrastructure is a vital component of observability. We will discuss what’s possible with OpenTelemetry and where the gaps are with today’s open source tools.
Tuesday November 12, 2024 10:27am - 10:32am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

10:34am MST

Inspektor Gadget: eBPF for Observability, Made Easy and Approachable | Project Lightning Talk
Tuesday November 12, 2024 10:34am - 10:39am MST
eBPF is a powerful tool for observability. But better tooling can make it even more powerful and, importantly, more approachable.
In this short talk, we’ll use the mechanisms Inspektor Gadget has for distributing and deploying eBPF programs to quickly build a data collection pipeline with eBPF that can be integrated with popular observability tools or one's own applications.
By the end of the talk, the audience should feel empowered to work with eBPF using the high-level tooling and integrate it into their systems and tooling.
Tuesday November 12, 2024 10:34am - 10:39am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

10:41am MST

OpenTelemetry: Understanding How OpenTelemetry Network Uses eBPF for Network Observability | Project Lightning Talk
Tuesday November 12, 2024 10:41am - 10:46am MST
The recent advancements in eBPF tooling, including the enhanced eBPF runtime embedded in the Linux kernel, the BPF Compiler Collection (BCC) for efficient kernel tracing, and the LLVM Compiler for converting C code to eBPF programs, have made it easier to provide always-on network visibility. OpenTelemetry Network leverages these foundational tools to provide out-of-the-box network observability for modern infrastructures.


In this talk, we'll explore the architecture of the OTel Network, focusing on its key components: the kernel collector, kubernetes collector, cloud collector, and reducer which together enable collecting, ingesting, aggregating, enriching, and exporting telemetry data collected from various sources. We'll show an end-to-end setup to demonstrate the use of these agents and reducer component to send data to the OTel collector. This session aims to equip end-users and contributors with the necessary information to get started with the OpenTelemetry Network project.
Tuesday November 12, 2024 10:41am - 10:46am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

10:48am MST

Fluentd: Fluent Bit - What's New? | Project Lightning Talk
Tuesday November 12, 2024 10:48am - 10:53am MST
In this short session we will do a highlight on what's new in Fluent Bit v3: new processors, integrations with OpenTelemetry, performance improvements and much more!
Tuesday November 12, 2024 10:48am - 10:53am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

10:55am MST

11:10am MST

Crossplane: The Many Layers of Crossplane - A Lightning Tour | Project Lightning Talk
Tuesday November 12, 2024 11:10am - 11:15am MST
Crossplane (https://www.crossplane.io/) and its user experience has matured greatly over the years and there are now numerous layers you can interact with while designing and building your internal developer platform powered by Crossplane.

Should you directly declare the cloud resources you want Crossplane to create, should you create developer friendly simplified abstractions on top, should you stick with YAML or use a more full featured high level programming language?

We will explore each of these layers in further detail and provide practical examples in this lightning tour of the broad possibilities offered by Crossplane, all of which lead to a reliable and robust control plane to manage everything in the cloud that your organization could need!
Tuesday November 12, 2024 11:10am - 11:15am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

11:17am MST

k8gb: Global Load Balancing, the Kubernetes Way | Project Lightning Talk
Tuesday November 12, 2024 11:17am - 11:22am MST
Discover how the k8gb project brings global load balancing to Kubernetes clusters. This talk will introduce the k8gb project, highlighting its core features such as global load balancing, high availability, seamless failover, and its new extensibility feature that allows integration with various resources like Gateways and non-HTTP Services. Learn about its architecture, real-world use cases, future plans, and how you can get involved.
Tuesday November 12, 2024 11:17am - 11:22am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

11:24am MST

gRPC: The gRPC "Standard Library" | Project Lightning Talk
Tuesday November 12, 2024 11:24am - 11:29am MST
gRPC has found widespread adoption in organizations around the world. You've probably written a protobuf yourself to define your own API. But did you know that the gRPC project actually defines several standard gRPC services that are generally applicable. In this talk, you will learn about gRPC's reflection, health, channelz, and status protos and how you can use them to get more out of your gRPC-based system.
Tuesday November 12, 2024 11:24am - 11:29am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

11:31am MST

KubeStellar: Multi-Cluster Configuration Management with KubeStellar | Project Lightning Talk
Tuesday November 12, 2024 11:31am - 11:36am MST
KubeStellar is a flexible solution for challenges associated with multi-cluster configuration management for edge, multi-cloud, and hybrid cloud
Tuesday November 12, 2024 11:31am - 11:36am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

11:38am MST

wasmCloud: Declarative WebAssembly Orchestration for Cloud Native Applications | Project Lightning Talk
Tuesday November 12, 2024 11:38am - 11:43am MST
wasmCloud released its 1.0 version in April of this year. Since then, the project has done everything but slow down. Maintainer Brooks Townsend demonstrates how wasmCloud enables users to build and orchestrate WebAssembly (Wasm) applications across distributed infrastructure. Learn how wasmCloud integrates the latest developments in WebAssembly standards to help users create and deploy applications “building block” style—connecting portable, interoperable Wasm components so they can focus on business logic. In this lightning project update, Brooks discusses wasmCloud’s component support, distributed networking, declarative orchestration, OpenTelemetry observability, the project roadmap, and more.
Tuesday November 12, 2024 11:38am - 11:43am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

11:45am MST

SIG Auth & SIG Storage: Secret Guardians - (Secrets Store) CSI Driver and Sync Controller | Project Lightning Talk
Tuesday November 12, 2024 11:45am - 11:50am MST
Applications running on Kubernetes require access to sensitive information (passwords, SSH keys and authentication tokens). But how do you configure your applications when the source of truth for these secrets is an external secret store? What if you need to store, retrieve and perform zero touch rotation of these secrets securely? Meet the (Secrets Store) CSI Driver and Sync Controller, sig-auth subprojects providing a simple way to retrieve secrets from enterprise-grade external stores such as Azure Key Vault, Google Secret Manager and HashiCorp Vault.

In this lightning talk, Anish will introduce you to the (Secrets Store) CSI driver and Sync controller and discuss trade-offs of the CSI driver versus Sync controller.
Tuesday November 12, 2024 11:45am - 11:50am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

11:52am MST

Open Cluster Management: Scheduling AI Workload Among Multiple Clusters | Project Lightning Talk
Tuesday November 12, 2024 11:52am - 11:57am MST
Open Cluster Management (OCM) addresses the challenges of managing multiple Kubernetes distributions, providing open APIs for cluster registration, workload distribution, dynamic placement of policies, and more. The placement concept allows dynamic selection of clusters, enabling users to replicate Kubernetes resources or run advanced workloads across member clusters. For instance, as an application developer, I can deploy workloads to clusters with the most available memory and CPU. With the rise of AI technology, there's an increasing need to schedule AI workloads based on GPU/TPU resources. In this talk, we will demonstrate how to utilize the extensible placement scheduling mechanism and a GPU/TPU resource collector addon. Using an addon template, this setup can provide an AddonPlacementScore, facilitating placement decisions based on GPU/TPU resources. This approach enables OCM API consumers to intelligently schedule AI workloads to the most optimal clusters.
Tuesday November 12, 2024 11:52am - 11:57am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

11:59am MST

KubeSlice: Migrate Kubernetes Services With Confidence! | Project Lightning Talk
Tuesday November 12, 2024 11:59am - 12:04pm MST
SREs have been constantly asked to look for solutions to help them migrate K8S services from one Cloud cluster to another Cloud cluster while continuing to provide secure access to managed Cloud services left behind in the original Cloud.

The K8S services securely access these managed services using private endpoint FQDN. When SREs are asked to move the K8S services to a different Cloud cluster they hit a roadblock - there is no easy solution to provide private endpoint FQDN access to a managed service from a remote Cloud cluster.

CNCF sandbox project KubeSlice solves this use case in an elegant way.

KubeSlice enables SREs to create a Slice across clusters and slice overlay network connects services in the clusters. An external services gateway on the Slice in the original Cloud cluster will provide access to managed services via alias service FQDN import. Services in other clusters can reach the cloud service via the same private endpoint FQDN resolved by the Slice DNS .
Tuesday November 12, 2024 11:59am - 12:04pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

12:06pm MST

Knative: Eventing Advances | Project Lightning Talk
Tuesday November 12, 2024 12:06pm - 12:11pm MST
Knative Eventing has learned a bunch of new tricks in the last year. In this talk, we’ll talk about advances in describing and controlling asynchronous messages between components, including authentication, authorization, and filtering.
Tuesday November 12, 2024 12:06pm - 12:11pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

12:13pm MST

Eraser: Cleaning Up Vulnerable Images from Kubernetes Nodes | Project Lightning Talk
Tuesday November 12, 2024 12:13pm - 12:18pm MST
Supply chain security is an increasingly important issue in cloud-native computing. It is common for pipelines to build and push images to the cluster, but uncommon for those images to be removed from a node’s local store once a CVE has been disclosed. Kubernetes has no built-in solution to this problem: its garbage collection only responds to disk pressure. As images become outdated, they present a risk as users may run a vulnerable container. Eraser, a CNCF sandbox project, is an open source solution that automates the scanning and removal of non-running images.
What distinguishes Eraser is that it gives more control over removal: the developer decides what gets removed and when. By default, Eraser uses Trivy to scan images based on a given threshold of vulnerability. Images can also be removed based on custom logic, including support for using different scanners.
The talk will begin with an overview of Eraser and discuss new features added to the project.
Tuesday November 12, 2024 12:13pm - 12:18pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

12:20pm MST

Linkerd: Adding Cluster-Agnostic Services to Linkerd - Design Considerations and Debates | Project Lightning Talk
Tuesday November 12, 2024 12:20pm - 12:25pm MST
Cluster-Agnostic Services (CAS) is a new feature in Linkerd which allows a single Service to transparently span multiple Kubernetes clusters while remaining resilient to failures in one or more clusters -- without needing to change the application. In this lightning talk, we'll discuss the design considerations and constraints navigated in the process of adding CAS to Linkerd. We discuss how this design process took into account prior art (such as work in SIG-Multicluster), explored a variety of designs, and focused on delivering a solution that was tractable, clear, explicit, simple, and valuable to Linkerd users.
Tuesday November 12, 2024 12:20pm - 12:25pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

12:27pm MST

Istio: Why Choose Istio in 2025 | Project Lightning Talk
Tuesday November 12, 2024 12:27pm - 12:32pm MST
With all of the cloud native and AI technology out there, it can be hard to figure out what technologies are best for your organization to adopt. Come to this quick lightning talk to figure out if Istio is right for you!
Tuesday November 12, 2024 12:27pm - 12:32pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

12:34pm MST

Kuma: What’s New in Kuma? | Project Lightning Talk
Tuesday November 12, 2024 12:34pm - 12:39pm MST
Kuma is an open source service mesh that delivers advanced security mechanisms, traffic management and observability for microservices. In this session, we’ll talk about the latest releases and most exciting features from each.

Highlights include:
- MeshPassthrough - a new policy that allows exposing external endpoints for “thick” clients through the mesh and support for wildcard DNS records.
- MeshExternalService - a new resource that overcomes existing limitations with the ExternalService resource.
- HostnameGenerator - a new resource that provides a way to generate custom domains inside your mesh.
- MeshService - a replacement for “kuma.io/service” tag that allows better scalability and allows adding metadata to a service.
- Namespaced policies - allow Kubernetes-native UX where all app-related resources are applied in the application’s namespace.
Tuesday November 12, 2024 12:34pm - 12:39pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

12:39pm MST

1:30pm MST

Project Overview: A Hitchhiker's Guide to the CNCF Landscape - Katherine Druckman and Lori Lorusso
Tuesday November 12, 2024 1:30pm - 1:45pm MST
“Get your hiking boots ready because we are about to traverse the wild, wonderful world of the CNCF Landscape. Why you ask? We currently have over 190 projects, and finding information about them can be a challenge. “Just go to the website” isn’t enough, sometimes you need a guide to show you the ropes. In these introductory sessions we will go over some of the diverse set of projects inside the CNCF so that you’re well equipped to find what you’re looking for at KubeCon.
Tuesday November 12, 2024 1:30pm - 1:45pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

1:47pm MST

Envoy: Highlights of Envoy Gateway v1.1.0 - What’s New and Improved | Project Lightning Talk
Tuesday November 12, 2024 1:47pm - 1:52pm MST
Envoy Gateway (EG) released its latest version, 1.1.0, on July 22. This update marks the first feature release since the 1.0.0 GA (General Availability) version and includes multiple new features and improvements. In this lighting talk, I will highlight some of the most important new features, including Wasm extension, non-k8s support, IP allow/deny list, stateful service support, etc.
Tuesday November 12, 2024 1:47pm - 1:52pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

1:54pm MST

Kubean: Unlocking Operational Efficiency - Simplify Cluster Lifecycle Management with Kubean | Project Lightning Talk
Tuesday November 12, 2024 1:54pm - 1:59pm MST
Kubean is a product-ready cluster lifecycle management tool built on the default kubespray engine.
It provides a declarative API, allowing us to deploy and manage clusters using a set of resource manifests.
The entire process is clear and concise.
We will introduce the core features of Kubean, along with some practical implementations in production environments.
Additionally, we will discuss the future development of the Kubean project, with the hope that Kubean can assist and alleviate the challenges people face in cluster management.
Tuesday November 12, 2024 1:54pm - 1:59pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

2:01pm MST

Kubernetes (SIG-CLI): How Do We Improve kubectl Without Breaking Users? | Project Lightning Talk
Tuesday November 12, 2024 2:01pm - 2:06pm MST
Quick session on how we are getting creative on the ways we implement new functionality and correct design decisions on your favorite 10 year old CLI tool!
Tuesday November 12, 2024 2:01pm - 2:06pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

2:08pm MST

Metal3: Metal3 Magics! What's New and Exciting? | Project Lightning Talk
Tuesday November 12, 2024 2:08pm - 2:13pm MST
This talk is a short format summary of the progress achieved by the Metal3 project and its community, particularly in last couple of years, aspiring for incubation. We will do a quick walkthrough of the latest and greatest features of the project and an overview of the road-map of the project.
Tuesday November 12, 2024 2:08pm - 2:13pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

2:15pm MST

Harbor: Harbor and the World of SBOMs | Project Lightning Talk
Tuesday November 12, 2024 2:15pm - 2:20pm MST
Discover how integrating SBOM (Software Bill of Materials) with Harbor enhances your software supply chain security. In this lightning talk, we'll cover:

- What is SBOM?: Quick overview of its role in software transparency.
- Integration with Harbor: Highlights of the SBOM integration in Harbor v2.11.
- Security Best Practices: Using SBOM to identify and address vulnerabilities.

Perfect for software engineers, DevOps professionals, and security enthusiasts looking to strengthen their software supply chain.
Tuesday November 12, 2024 2:15pm - 2:20pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

2:22pm MST

SlimToolkit: Improving DX with Containers - Making it Easy to Understand, Optimize, and Debug Your Containers | Project Lightning Talk
Tuesday November 12, 2024 2:22pm - 2:27pm MST
This talk will introduce the key capabilities in SlimToolkit: inspecting, minifying, and debugging containers that will enhance your developer experience with containerized applications.

We'll walk through a number of short examples showing how common container related problems can be addressed using various commands provided by the tool.

* Are the popular recommendations to create production-ready containers not possible in your environment, or is it just too much work?
* Do you find it difficult to understand what's in containers when you are fixing bugs or when you are selecting new containers to use?
* Is one of the reasons why you avoid using minimal container images the challenges of debugging them?
* Are you not sure what minimal container images are?

If you answered yes to any of these questions, or if you are curious about how this CNCF project can improve your overall container developer experience, this talk is for you.
Tuesday November 12, 2024 2:22pm - 2:27pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

2:29pm MST

Kyverno: Level Up Your Cluster - 5 Kyverno Policies You Need Now! | Project Lightning Talk
Tuesday November 12, 2024 2:29pm - 2:34pm MST
Struggling to secure your Kubernetes clusters and automate workloads? Kyverno offers a unique solution to combat configuration complexity! This fast-paced talk presents five real-world examples to show you how Kyverno can automate security and simplify workload management.
Tuesday November 12, 2024 2:29pm - 2:34pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

2:36pm MST

Open Policy Agent (OPA): That's One Small Bump for OPA, but One Giant Leap for Policy as Code | Project Lightning Talk
Tuesday November 12, 2024 2:36pm - 2:41pm MST
At last, OPA's made it to v1! Let's take a whistle-stop tour of what's involved in cutting a v1 release for a project over 3.5 billion downloads; its own language and large community. Get the latest updates, and glimpse into the future in this light speed overview!
Tuesday November 12, 2024 2:36pm - 2:41pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

2:43pm MST

Falco: Evolution of Real Time Cloud Security with Falco | Project Lightning Talk
Tuesday November 12, 2024 2:43pm - 2:48pm MST
Falco, the CNCF runtime security project, can continuously monitor your entire environment looking for suspicious activity. From bare metal servers to massive Kubernetes clusters made of hundreds of thousands of nodes to your cloud provider activity, Falco and its powerful detection rule system have you covered. In this Lightning Talk, Luca and Melissa will focus on how the Falco project is constantly evolving to meet defenders' needs by providing rich libraries of detection rules, making it easier to customize them, catch bypass attempts and bring light to every dark corner of modern cloud infrastructures.
Tuesday November 12, 2024 2:43pm - 2:48pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

2:50pm MST

Copa: Project Copacetic - Directly Patch Container Image Vulnerabilities | Project Lightning Talk
Tuesday November 12, 2024 2:50pm - 2:55pm MST
Maintaining secure container images and addressing new vulnerabilities quickly is a major challenge. To patch images, users face two options: wait for third-party authors to release updates, which can take weeks, or perform a full image rebuild, a time and resource-intensive process.
Project Copacetic (Copa) enhances the image patching process, reducing turnaround time and complexity. It integrates easily into existing build infrastructure, giving users greater control over their patching timeline and reducing costs.
Copa scans container images using tools like Trivy to generate a vulnerability report and parses the report for necessary OS-level package updates. It applies these updates to the target image using Buildkit (Docker’s default builder) to create a new patch layer on the original image. Copa can even patch distroless images by leveraging external tooling.
The talk will overview Copa, highlighting new features like scanner plugins and omitting reports to update all packages.
Tuesday November 12, 2024 2:50pm - 2:55pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

2:57pm MST

OpenFGA: The Cloud Native Way to Implement Fine Grained Authorization | Project Lightning Talk
Tuesday November 12, 2024 2:57pm - 3:02pm MST
This talk will be a short introduction to OpenFGA, a report on the state of the project and an exploration of different adoption use cases from companies all sizes.
Tuesday November 12, 2024 2:57pm - 3:02pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

3:04pm MST

Meshery: Visualizing Kubernetes Resource Relationships with Meshery | Project Lightning Talk
Tuesday November 12, 2024 3:04pm - 3:09pm MST
Meshery and its extensions empower you to navigate cloud native infrastructure in complex environments. This lighting talk delves into the human-computer interaction (HCI) principles that underpin MeshMap's intuitive visualization of Kubernetes resources and the various forms of inter/relationships with other CNCF projects' resources.

Human-Computer Interaction Principles in Meshery:

- Cognitive Load: How Meshery reduces cognitive load by presenting complex information in a structured and visually digestible manner.
- Mental Models: How Meshery aligns with users' mental models of Kubernetes environments, facilitating comprehension and navigation.
- Visual Perception: How Meshery leverages visual cues, colors, and layout to guide users' attention and highlight critical information.
Tuesday November 12, 2024 3:04pm - 3:09pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

3:09pm MST

3:25pm MST

CNCF Runtime TAG: CNCF Runtime TAG and the Cloud Native Runtime Landspace: AI, WASM, OS, Edge, Workloads, and More | Project Lightning Talk
Tuesday November 12, 2024 3:25pm - 3:30pm MST
In this lightning talk, we will introduce the CNCF Runtime TAG, discuss how we work with TOC and CNCF Runtime related projects, and highlight the work the TAG and the working groups have done to build guidance and write whitepapers for the ecosystem. Join us to find out how to contribute and participate in the CNCF Runtime community.
Tuesday November 12, 2024 3:25pm - 3:30pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

3:32pm MST

CRI-O: First Class AI Model Teleportation - OCI Volume Mounts in CRI-O and Kubernetes | Project Lightning Talk
Tuesday November 12, 2024 3:32pm - 3:37pm MST
Along with the Kubernetes community's corraling behind the usescases of generative AI comes a slew of implementation hurdles to overcome. One such hurdle is the problem of moving around bulky models. While many methods exist today, the SIG-Node and WG-Serving community sought to find a Kubernetes native approach. What better way than utilizing a foundational part of Kubernetes: the OCI distribution spec.

In this talk, we will discuss the process of designing KEP-4639, the status of the feature, and go through some real world use-cases for using OCI distribution methods we know, love and rely-upon to move AI models to your production servers.
Tuesday November 12, 2024 3:32pm - 3:37pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

3:39pm MST

WasmEdge: Cross-Platform, High-Performance, Lightweight, Embeddable Multi-Modal LLM Runtime | Project Lightning Talk
Tuesday November 12, 2024 3:39pm - 3:44pm MST
With the popularity of LLM apps, there is an increasing demand for running and scaling AI workloads in the cloud and on edge devices. Rust and Wasm offer a solution by providing a portable bytecode that abstracts hardware complexities. WasmEdge is a lightweight, high-performance and cross-platform LLM inference runtime. WasmEdge provides a standard WASI-NN API to developers. Developers only need to write against the API and compile to Wasm. The Wasm file can run on any device, where WasmEdge translates and routes Wasm calls to the underlying native libraries such as llama.cpp.
Tuesday November 12, 2024 3:39pm - 3:44pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

3:46pm MST

Spiderpool: DRA Helps Allocate RDMA Devices With GPU Affinity For AI Workload | Project Lightning Talk
Tuesday November 12, 2024 3:46pm - 3:51pm MST
Currently, the CNI barely meets some increasingly prominent network demands. Especially AI workloads requiring network cards in buck, the node scheduling could not simultaneously fullfill requirements for the macvlan master interface, subnet availability, and RDMA resources. Additionally, the physical affinity between the allocated network cards and GPU is not guaranteed to achieve high-performance transfers such as GPUDirectRDMA. Therefore, many end users complain and have to write complex network configurations in yaml and simply insert all network interfaces for pods to ensure device affinity, which is rigid.
Based on the practice requirements of popular tail-optimized AI network topology, in latest version, Spiderpool introduces DRA to uniformly declare various network configurations, schedule AI workloads to proper nodes, and automatically allocate network interfaces, IP addresses, and RDMA devices with GPU affinity on demand. This greatly enhances the flexibility in AI clusters.
Tuesday November 12, 2024 3:46pm - 3:51pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

3:53pm MST

5:30pm MST

⚡ Lightning Talk: `Kubectl Debug` Lacks an `IDE` Option. Let’s Fix That! - Mario Loriedo, Red Hat
Tuesday November 12, 2024 5:30pm - 5:35pm MST
Don't get me wrong. `kubectl debug` is one of my favorite `kubectl` commands. But probably because I like it so much, I am convinced it deserves more love! This talk will present a `kubectl debug` extension that starts an IDE in an ephemeral container for debugging purposes. This extension uses the DevWorkspace operator, which is capable of running lightweight cloud development environments, including the IDE, in containers. If you like debugging by adding breakpoints in an IDE rather than inspecting your application's logs, you should attend this talk.
Speakers
avatar for Mario Loriedo

Mario Loriedo

Senior Principal Software Engineer, Red Hat
Mario is a Senior Principal Software Engineer at Red Hat. He works on Podman and on container-based developer tools. He has been a CNCF Ambassador and the tech lead of the Eclipse Che project. He has co-created the Devfile (a CNCF Sandbox Project). He has been a speaker at conferences... Read More →
Tuesday November 12, 2024 5:30pm - 5:35pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

5:35pm MST

⚡ Lightning Talk: CloudEvents as APIs - Evan Anderson, Stacklok
Tuesday November 12, 2024 5:35pm - 5:40pm MST
Most of us are familiar with tools like gRPC and OpenAPI for modelling synchronous calls between different applications or microservices. Sometimes, the right way to extend an application is through an asynchronous notification, or an event. CloudEvents is a CNCF project to standardize the format of asynchronous notifications, to make it easier for different projects and applications to communicate. CloudEvents is an envelope to make it easy to exchange asynchronous messages; in this talk, I'll highlight three useful patterns to leverage CloudEvents to connect applications, using examples from Stacklok's own experience.
Speakers
avatar for Evan Anderson

Evan Anderson

Software Engineer, Stacklok
Co-founder and maintainer on Knative project. Member of sigstore-oncall. Previously worked on Google Compute Engine and Serverless (App Engine, Functions) and in SRE. Principal engineer at Stacklok. Ex-Google, ex-VMware. Author of Building Serverless Applications on Knative by O'Reilly... Read More →
Tuesday November 12, 2024 5:35pm - 5:40pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

5:40pm MST

⚡ Lightning Talk: Effortless, Sidecar-Less Mutual TLS and Rich Authorization Policies up and Running in 5 Minutes - Lin Sun, solo.io
Tuesday November 12, 2024 5:40pm - 5:45pm MST
Do you need zero trust or mutual TLS (mTLS) among your application pods? You may be able to manage certificates within your applications, but how would you handle automatic periodic certificate rotation? The evolution of sidecar-less service mesh technology enables mTLS among application pods with just a simple namespace label. No sidecars or application pod restarts are required. This approach provides immediate benefits, including cryptographic identity for application pods, and ensures session-based data confidentiality and integrity in pod communications. In just 5 minutes, Lin will demonstrate live how developers and operators can effortlessly enforce mTLS and rich Layer 7 (L7) authorization policies without any sidecars!
Speakers
avatar for Lin Sun

Lin Sun

CNCF TOC member and Head of Open-Source at solo.io, solo.io
Lin is the Head of Open Source at Solo.io, and a CNCF TOC member and ambassador. She has worked on the Istio service mesh since the beginning of the project in 2017 and serves on the Istio Steering Committee and Technical Oversight Committee. Previously, she was a Senior Technical... Read More →
Tuesday November 12, 2024 5:40pm - 5:45pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD
  ⚡ Lightning Talks, Security

5:45pm MST

⚡ Lightning Talk: Evaluating Scheduler Efficiency for AI/ML Jobs Using Custom Resource Metrics - Dmitry Shmulevich, NVIDIA
Tuesday November 12, 2024 5:45pm - 5:50pm MST
Kubernetes deployments frequently utilize custom resources beyond just CPU and memory, such as GPUs, which are essential for AI/ML workloads. While the Metrics API offers insights into CPU and memory usage at both the pod and node levels, it does not provide similar information for custom resources. Although resource requests for custom resources are specified in the pod spec, there is no visibility into how efficiently these resources are utilized at the node and cluster levels. To address this gap, we developed a Prometheus Node Resource Exporter tailored to monitor custom resources. Our case study focuses on evaluating the efficiency of Kubernetes schedulers when handling a high volume of AI/ML jobs, using GPU occupancy on the nodes as the primary indicator. In this lightning talk, we will present a comparative analysis of several scheduling frameworks based on the metrics collected by our custom exporter.
Speakers
avatar for Dmitry Shmulevich

Dmitry Shmulevich

Software Engineer, NVIDIA
Dmitry is a software engineer at NVIDIA with over 25 years of experience in software development, specializing in cloud computing for the past eight years. Throughout his career, he has made significant contributions to various systems and projects across the cloud stack. He is also... Read More →
Tuesday November 12, 2024 5:45pm - 5:50pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD
  ⚡ Lightning Talks, Observability
  • Content Experience Level Any

5:50pm MST

⚡ Lightning Talk: Future-Proofing Kubernetes: Impact of Storage Version Migration and Meaning of Resource Version (RV) - Nilekh Chaudhari, Microsoft
Tuesday November 12, 2024 5:50pm - 5:55pm MST
Kubernetes relies on API data being actively rewritten to support some maintenance activities related to at-rest storage. Two prominent examples are the versioned schema of stored resources (i.e., the preferred storage schema changing from v1 to v2 for a given resource) and encryption at rest (i.e., rewriting stale data based on a change in how the data should be encrypted). The simplest way to rewrite data is to issue no-op update requests via kubectl. This approach is problematic for any resource that can contain a large amount of data, such as Kubernetes secrets, and it is also impractical to perform without automation, as the number of resources that need migration is always growing. Storage Version Migration (SVM), which is now available as a built-in alpha API since Kubernetes v1.30, helps achieve this. However, the implementation of SVM has significant implications for the entire Kubernetes project and its ecosystem.
Speakers
avatar for Nilekh Chaudhari

Nilekh Chaudhari

Software Engineer, Microsoft
Nilekh is a Software Engineer at Microsoft, specializing in Kubernetes. He actively contributes to SIG Auth and SIG API Machinery and is a core maintainer of the Secrets Store CSI Driver, the Azure Provider for the Secrets Store CSI Driver, and the Gatekeeper Library project.
Tuesday November 12, 2024 5:50pm - 5:55pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD
  ⚡ Lightning Talks, Platform Engineering
  • Content Experience Level Any

5:55pm MST

⚡ Lightning Talk: Is Everyone O-KEDA? “Exciting” Lessons Learned in Our Journey to Use KEDA Pod Autoscaling - Brian Davis, Red Canary
Tuesday November 12, 2024 5:55pm - 6:00pm MST
We thought that changing our Kubernetes pod autoscaler seemed like a really straightforward thing to do. With relative ease, we yanked out our old custom pod autoscaler and replaced it with KEDA. We were impressed with the flexibility and control we now had in our cluster, but then discovered a set of really hard lessons that no one had anticipated. In this lightning talk, I’ll hit the highlights of secondary issues we encountered due to such a seemingly simple change, such as Docker Hub rate limits, Kubernetes metrics server failures and their exciting impact on our cluster, AWS rate limits, and late night fights with Argo CD for control of pod maximums. Lastly, I’ll share my personal favorite topic: the “Night Club Theory” of autoscaling tuning. If you or someone you love is thinking of changing your autoscaler, I recommend spending 5 minutes with me to learn the things you should be aware of before you make the switch!
Speakers
avatar for Brian Davis

Brian Davis

Principal Software Engineer, Red Canary
Brian Davis is a Principal Engineer at Red Canary and has built complex systems for the past two decades. His career started in signal processing algorithm research but has morphed through the years into software engineering, QA, system integration, system design, and architectur... Read More →
Tuesday November 12, 2024 5:55pm - 6:00pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

6:00pm MST

⚡ Lightning Talk: Kubernetes for Simulated Hardware in Radio Astronomy - Barbara Ojur, SARAO & Abednigo Matiba Lethole, South African Radio Astronomy Observatory(SARAO)
Tuesday November 12, 2024 6:00pm - 6:05pm MST
We use Kubernetes to deploy simulated hardware devices for the Square Kilometer Array (SKA), the world's largest radio telescope. The SKA has an Integrated Testing Facility (ITF) that tests subsystems before field deployment. One of those systems is our main focus for this lightning talk called the Dish Local and Monitoring and Control (LMC) system, which manages mid-frequency operations. Key Lightning Talk Points: - Dish LMC Components: Control, Monitoring, Communication Interface. - Kubernetes Utilization: - k9s: Manages and monitors deployments. - Networking: Simulates communication pathways. - Logging: Captures and analyzes system logs. Goals: - Presentation Aim: Share experiences and inspire adoption of our strategies. - Audience Takeaway: Understand Kubernetes' role in managing complex simulations. - Ecosystem Impact: Improve best practices and drive innovation.
Speakers
avatar for Abednigo Matiba Lethole

Abednigo Matiba Lethole

MR, South African Radio Astronomy Observatory(SARAO)
Abednigo Matiba Lethole is a Junior Software Engineer with over 2 years of experience at the South African Radio Astronomy Observatory (SARAO). Specializing in software development and radio astronomy applications, Abednigo is dedicated to advancing technological solutions in the... Read More →
avatar for Barbara Ojur

Barbara Ojur

Miss Barbara Ojur, SARAO
Barbara Apili Ojur is a software engineer from South Africa, Cape Town. She works for the South African Radio Astronomy Observatory and is seconded to the Square Kilometer Array Observatory which is an intergovernmental project, including countries such as Spain and Italy to mention... Read More →
Tuesday November 12, 2024 6:00pm - 6:05pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

6:05pm MST

⚡ Lightning Talk: Minimizing Data Loss Within the OpenTelemetry (OTel) Collector - Alex Kats, Capital One
Tuesday November 12, 2024 6:05pm - 6:10pm MST
The OTel collector is meant to serve as a reliable and highly performant data pipeline. However, as a single component in a wider observability architecture, it is only as reliable as the downstream platforms/services it exports data to. The OTel collector has several built in mechanisms that aim to minimize the impact of unhealthy downstream exporters, including an out of the box sending queue with an additional configuration parameter for persistent queueing. There is a new component in the OTel contrib distribution, the Failover Connector. The Failover Connector allows for dynamic routing or “failover” of telemetry data based on downstream exporter health. This provides significant improvement to the data resiliency of the collector, as telemetry data can be continuously exported to a set of stable secondary locations, while the issues with the primary are resolved.
Speakers
avatar for Alex Kats

Alex Kats

Software Engineer, Capital One
Alex is a software engineer at Capital One. Alex has significant experience within the Observability space, with an emphasis on OpenTelemetry (OTel). Alex is a member of the OpenTelemetry community and has been contributing to various components within the OTel toolset.
Tuesday November 12, 2024 6:05pm - 6:10pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

6:10pm MST

⚡ Lightning Talk: Running Kind Clusters with GPU Support Using Nvkind - Evan Lezar, NVIDIA
Tuesday November 12, 2024 6:10pm - 6:15pm MST
Kind is a powerful tool for running local Kubernetes clusters using Docker. It is particularly useful for testing, development, and CI/CD workflows, offering features like multi-node cluster support, easy configuration, and cross-platform compatibility. However, providing access to GPUs in Kind is not a very straightforward process. There is no standard way to inject GPUs into a Kind worker node, and even with a series of "hacks" to make it possible, post-processing is still needed to isolate different sets of GPUs to different nodes. In this lightning talk, we introduce nvkind – a wrapper around Kind that encapsulates the steps necessary to make GPUs available to Kind worker nodes. Ideally, GPU support would have been added to Kind directly, but many challenges exist to make this possible. This talk discusses those challenges, how we've overcome them with nvkind, and the steps needed to eventually support GPUs directly within Kind itself.
Speakers
avatar for Evan Lezar

Evan Lezar

Senior Systems Software Engineer, NVIDIA
Evan Lezar is a Senior Systems Software Engineer on the Cloud Native team at NVIDIA. His focus is making GPUs and other NVIDIA devices easily accessible from containerized environments. This includes driving development and adoption of the Container Device Interface (CDI).
Tuesday November 12, 2024 6:10pm - 6:15pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD
  ⚡ Lightning Talks, AI + ML
  • Content Experience Level Any

6:15pm MST

⚡ Lightning Talk: Safer Cluster Upgrades with Mixed Version Proxy - Richa Banker, Google
Tuesday November 12, 2024 6:15pm - 6:20pm MST
Upgrading Kubernetes clusters often presents numerous challenges, including potential downtime, compatibility issues, and the complexity of managing multiple versions. The Mixed Version Proxy feature introduced in Kubernetes 1.28 aims to mitigate these challenges. This talk will delve into the technical intricacies of the Mixed Version Proxy, exploring its design and implementation. We will then highlight the substantial benefits it offers for cluster upgrades, such as minimizing downtime and enhancing overall reliability. Attendees will gain practical knowledge through (possibly a demonstration) on enabling and utilizing the Mixed Version Proxy. Finally, we will provide insights into the future roadmap for this feature, including upcoming beta releases and enhancements.
Speakers
avatar for Richa Banker

Richa Banker

Richa Banker, Google
Currently a software engineer at Google. Exploring and contributing to OSS Kubernetes on the side.
Tuesday November 12, 2024 6:15pm - 6:20pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD
 
Wednesday, November 13
 

11:15am MST

Using Notary Project to Ensure Authenticity and Integrity of Artifacts Within the Enterprise - Toddy Mladenov, Microsoft & Tjark Rasche, Mercedes-Benz Tech Innovation GmbH
Wednesday November 13, 2024 11:15am - 11:50am MST
In this session, we will go over the steps and considerations the enterprise goes through to select a reliable and future-proof signing technology and improve the integrity and authenticity of their software artifacts. We will share the questions and constraints in the enterprise and how those were addressed by Notary Project. We will also provide an update on the latest features and the roadmap for Notary Project.
Speakers
avatar for Toddy  Mladenov

Toddy Mladenov

Principal Product Manager, Microsoft
Toddy has over 25 years of experience in software engineering and design, consulting, and product management for companies like Microsoft, T-Mobile, and SAP. He started his cloud journey 14 years ago as part of the Azure team. Since then, Toddy worked on large-scale cloud implementations... Read More →
avatar for Tjark Rasche

Tjark Rasche

Senior Software Engineer, Mercedes-Benz Tech Innovation GmbH
Tjark works as a Cloud Software Engineer at Mercedes-Benz Tech Innovation GmbH. He focuses on automating the cluster lifecycle, cluster security and integrating custom cluster addons with Kubernetes. He is also highly involved with the local Kubernetes community, founder of the Kubernetes... Read More →
Wednesday November 13, 2024 11:15am - 11:50am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

12:10pm MST

Emissary-Ingress: Version 4 and the Road Ahead - Flynn, Buoyant
Wednesday November 13, 2024 12:10pm - 12:45pm MST
Emissary-ingress 4.0 is shipping! This marks the first new major version in some years for Emissary, one of the first Kubernetes-native, self-service API gateways and ingress controllers, and it comes on the heels of some big changes in the project. In this session, we'll start with a quick overview of the need for ingress controllers in general, the benefits of self-service developer workflows, and how Emissary-ingress can help with these issues. We'll also talk about recent changes in the project, what Emissary 4 brings to the table, and how to get involved as a contributor, how to best offer feedback, and what's in store for the project in the future. Emissary's maintainer sessions are always great opportunities to talk directly with Emissary-ingress maintainers and make sure your voice is heard when it comes to the project's future -- looking forward to seeing you there!
Speakers
avatar for Flynn -

Flynn -

Tech Evangelist, Buoyant
Flynn is a tech evangelist at Buoyant, educating developers about Linkerd, Kubernetes, and cloud-native development in general. He has spent 40 years in software engineering (from the kernel up through distributed applications, with a common thread of communications and security throughout... Read More →
Wednesday November 13, 2024 12:10pm - 12:45pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

2:30pm MST

Kubernetes WG Device Management - Advancing K8s Support for GPUs - John Belamaric, Google; Patrick Ohly, Intel; Kevin Klues, NVIDIA
Wednesday November 13, 2024 2:30pm - 3:05pm MST
The goal of the recently formed WG Device Management is to enable simple and efficient configuration, sharing, and allocation of accelerators (such as GPUs and TPUs) and other specialized devices. This working group focuses on the APIs, abstractions, and feature designs needed to configure, target, and share the necessary hardware for both batch and serving (inference) workloads. The current focus of the working group is the Dynamic Resource Allocation (DRA) feature. Come to this talk to learn what we have delivered in Kubernetes 1.31, what is coming in 1.32 and beyond, and how you can influence the roadmap for Kubernetes support of accelerated workloads.
Speakers
avatar for Patrick Ohly

Patrick Ohly

Principal Engineer, Intel
Patrick Ohly is a software engineer at Intel GmbH, Germany. In the past he has worked on performance analysis software for HPC clusters ("Intel Trace Analyzer and Collector") and cluster technology in general (PTP and hardware time stamping). Since January 2009 he has worked for Intel... Read More →
avatar for Kevin Klues

Kevin Klues

Distinguished Engineer, NVIDIA
Kevin Klues is a distinguished engineer on the NVIDIA Cloud Native team. Kevin has been involved in the design and implementation of a number of Kubernetes technologies, including the Topology Manager, the Kubernetes stack for Multi-Instance GPUs, and Dynamic Resource Allocation (DRA... Read More →
avatar for John Belamaric

John Belamaric

Senior Staff Software Engineer, Google
John is a Sr Staff SWE, co-chair of K8s SIG Architecture and of K8s WG Device Management, helping lead efforts to improve how GPUs, TPUs, NICs and other devices are selected, shared, and configured in Kubernetes. He is also co-founder of Nephio, an LF project for K8s-based automation... Read More →
Wednesday November 13, 2024 2:30pm - 3:05pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

3:25pm MST

OpenTelemetry Project Update - Alolita Sharma, Apple; Juraci Paixão Kröhling, Grafana Labs; Ted Young, ServiceNow; Morgan Mclean, Splunk; Daniel Dyla, Dynatrace
Wednesday November 13, 2024 3:25pm - 4:00pm MST
This is the official OpenTelemetry session at Kubecon. OpenTelemetry started with distributed traces and metrics, but the project's vision has always been to provide whatever signals are needed from infrastructure, services, and more. This session will focus on what's coming next, including new signals and sources. Join to learn about OpenTelemetry's new logging functionality, including its two logging paths, the benefits of each, and real-world production examples. We'll show the power of the next wave of OpenTelemetry enhancements, including profiling and the insights that this unlocks in combination with distributed traces, and how we're extending your observability to client applications. We'll wrap up with a Q&A of 10+ project maintainers, who can speak to these topics and more.
Speakers
avatar for Morgan Mclean

Morgan Mclean

Director of Product Management, Splunk
Morgan is one of the co-founders of OpenTelemetry, and he sits on the project's governance committee and runs multiple initiatives within the project. He is a Senior Director of Product Management at Splunk, where he is responsible for the core platform behind Splunk Observability... Read More →
avatar for Juraci Paixão Kröhling

Juraci Paixão Kröhling

Software Engineer, Grafana Labs
Juraci Paixão Kröhling is a software engineer at Grafana Labs, a maintainer of the OpenTelemetry project, a member of the project's governing board and CNCF Ambassador. He has presented about distributed tracing, OpenTelemetry, and other related topics at conferences like KubeCon... Read More →
avatar for Daniel Dyla

Daniel Dyla

Senior Open Source Architect / OpenTelemetry GC, JS, Maintainer, Dynatrace
Daniel joined Dynatrace in 2015 working on the Davis Assistant natural language interface to the Dynatrace AI. He is an Open Source Architect, member of the W3C Distributed Tracing Working Group, OpenTelemetry specification contributor, maintainer of the OpenTelemetry JS client, and... Read More →
avatar for Ted Young

Ted Young

Director of Developer Education, ServiceNow
OpenTelemetry co-founder
avatar for Alolita Sharma

Alolita Sharma

Observability Engineering, Apple
Alolita Sharma is a member of OpenTelemetry GC, Observability TAG co-chair, CNCF End-User TAB Chair and Governing Board member. She leads Apple’s AIML observability teams. She contributes to open source, open standards at OpenTelemetry, Unicode, W3C. She has served on the boards... Read More →
Wednesday November 13, 2024 3:25pm - 4:00pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

4:30pm MST

CNI Updates and Direction! - Michael Zappa, Microsoft
Wednesday November 13, 2024 4:30pm - 5:05pm MST
The CNI or Container Networking Interface is one of the most important projects of Kubernetes and the surrounding ecosystem. Without it, nodes aren’t ready, and pods aren’t scheduled. This session will provide a brief overview of what the CNI is, where it intersects with Kubernetes, the latest updates, how you can get involved and the future of the CNI. We have talked a lot about CNI 2.0 and now it is becoming a reality. This will be the biggest change to the CNI however let's not get carried away, we will make this seamless for you! Attendees will leave with an understanding of what the CNI is and how it fits into the larger picture of Kubernetes networking so that you can contribute to the CNI community!
Speakers
avatar for Michael Zappa

Michael Zappa

Software Engineer, Microsoft
Hello, I am Zappa. I have been a technologist for over 20 years with a background in networking, systems, software and Devops engineering. I am a self-caught coder and started in the 6th grade. I am passionate about the ecosystem and container networking. My areas in the open-source... Read More →
Wednesday November 13, 2024 4:30pm - 5:05pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

5:25pm MST

Observability TAG Round-up and What’s New for AI Observability - Alolita Sharma, Apple & Chris Larsen, Netflix
Wednesday November 13, 2024 5:25pm - 6:00pm MST
The Observability TAG has been busy in 2024. We've been hard at work on exciting initiatives designed to address the challenges of large-scale observability. This session will provide an update on our activities, workgroups, and achievements. The cloud is undergoing a supernova event! Massive deployments of GPUs and NPUs running AI workloads are fueling a revolution, but implementing observability for this new ecosystem can easily devour your budget. As CNCF’s Observability TAG, we'll dive into the latest trends in observability that address the cost challenges of the AI Cloud. See what’s new to help manage observability data more effectively, optimize operational efficiency, and keep costs under control.
Speakers
avatar for Chris Larsen

Chris Larsen

Senior Software Engineer, Netflix, Netflix
Observability engineer focusing on cross telemetry correlation and maintainer of OpenTSDB.
avatar for Alolita Sharma

Alolita Sharma

Observability Engineering, Apple
Alolita Sharma is a member of OpenTelemetry GC, Observability TAG co-chair, CNCF End-User TAB Chair and Governing Board member. She leads Apple’s AIML observability teams. She contributes to open source, open standards at OpenTelemetry, Unicode, W3C. She has served on the boards... Read More →
Wednesday November 13, 2024 5:25pm - 6:00pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD
 
Thursday, November 14
 

11:00am MST

Artifact Hub: Discover, Analyze, and Share Cloud Native Artifacts - Matt Farina, SUSE
Thursday November 14, 2024 11:00am - 11:35am MST
Finding cloud native artifacts, from Helm charts to security policies, can be difficult with general search engines. Analyzing what you find can be a very manual process and you're going to miss out on some useful projects. Artifact Hub was created to ease the pain of cloud native artifact discovery and now provides for discovery and analysis of over 20 different types of cloud native artifacts. In this session you'll learn: • How Artifact Hub came into existence • How you can discover and analyze artifacts, right on Artifact Hub • Making your artifacts discoverable • Running your own instance of Artifact Hub • How you can contribute to the project
Speakers
avatar for Matt Farina

Matt Farina

Distinguished Engineer, SUSE
Matt works as a Distinguished Engineer at SUSE, where he works as the Chief Architect of the SUSE Rancher Team. He is a maintainer of multiple open source projects including Helm and Artifact Hub. Matt is an author, speaker, and regular contributor to open source.
Thursday November 14, 2024 11:00am - 11:35am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

11:55am MST

0.1 to 1.16: How Has Knative Fulfilled Its Vision? - Dave Protasowski, Broadcom & Evan Anderson, Stacklok
Thursday November 14, 2024 11:55am - 12:30pm MST
Knative 0.1 launched approximately 6 years ago. 0.1 promised a number of features, including supporting a developer workflow equivalent to AWS Lambda and other FaaS platforms, but with an “a la carte” design where each component could operate independently. How does that vision look 6 years and 40 releases later? Through the lens of a demo, where does Knative exceed the original vision, and where have things been dropped?
Speakers
avatar for Dave Protasowski

Dave Protasowski

Staff Engineer, VMware/Broadcom
Dave Protasowski is part of Knative Technical Committee and a Serving Working Group Lead. During the night he works at VMware/Broadcom. Prior he worked on Cloud Foundry things at Pivotal.
avatar for Evan Anderson

Evan Anderson

Software Engineer, Stacklok
Co-founder and maintainer on Knative project. Member of sigstore-oncall. Previously worked on Google Compute Engine and Serverless (App Engine, Functions) and in SRE. Principal engineer at Stacklok. Ex-Google, ex-VMware. Author of Building Serverless Applications on Knative by O'Reilly... Read More →
Thursday November 14, 2024 11:55am - 12:30pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

2:30pm MST

Cortex Intro: Multi-Tenant Scalable Prometheus - Charlie Le, Apple & Daniel Blando, Amazon
Thursday November 14, 2024 2:30pm - 3:05pm MST
Cortex provides horizontally scalable, highly available, multi-tenant, long term storage for Prometheus. In this talk, we will do an introduction of Cortex architecture and project status. We will also walk through those new features added to Cortex and how to utilize them efficiently in production.
Speakers
avatar for Charlie Le

Charlie Le

Senior Software Engineer, Apple
Charlie is a software engineer at Apple, specializing in building and scaling cloud native observability solutions and infrastructure. Deeply inspired by the collaborative spirit of open source, he actively contributes to projects like Cortex and OpenTelemetry, shaping the future... Read More →
avatar for Daniel Blando

Daniel Blando

AWS, Senior SDE, Cortex, Amazon
Daniel Blando is a Senior Software Engineer at AWS in the Amazon Managed Prometheus (AMP) team. He currently works with Cortex, Thanos, Prometheus among others open source projects. He is working to make Cortex more scalable and highly available recently focusing on the write path... Read More →
Thursday November 14, 2024 2:30pm - 3:05pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

3:25pm MST

Elevate Your Kubernetes Policy Game with Kyverno! - Vishal Choudhary, Nirmata; Lanting Chiang & Karen Tu, Robinhood Markets, Inc.
Thursday November 14, 2024 3:25pm - 4:00pm MST
Struggling to find the balance between robust security and empowering developers? Join Robinhood's platform engineers Karen and Lanting as they share their migration journey from custom solutions and PSPs, to policy as code with Kyverno. Go beyond the basics of resource validation and enforcement, and learn the power of Kyverno for policy as code lifecycle management, including testing, deployment, performance optimizations, exception management, and reporting. Plus, Vishal, a Kyverno maintainer, will present a game-changing new feature in Kyverno 1.12: etcd offloading for policy reports, which is critical for large production workloads. This session is a must-attend for platform engineers and Kubernetes administrators looking to leverage policy as code for self-service automation, security, and compliance.
Speakers
avatar for Karen Tu

Karen Tu

Robin Hood
avatar for Lanting Chiang

Lanting Chiang

Software Engineer, Robinhood Markets, Inc.
Software Engineer on the Software Platform - Container Orchestration team at Robinhood Markets, Inc.
avatar for Vishal Choudhary

Vishal Choudhary

Software Engineer, Nirmata
Vishal is a student and a software engineer, working on cloud-native projects focusing on governance and securing software supply chains for everyone! He is a maintainer of Kyverno and an active contributor at several other projects in the space. He is always looking to discuss tools... Read More →
Thursday November 14, 2024 3:25pm - 4:00pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

4:30pm MST

Secure Release Processes with in-Toto Policy Verification - John Kjell, TestifySec & Aditya Sirish A Yelgundhalli, New York University
Thursday November 14, 2024 4:30pm - 5:05pm MST
Ensuring software releases adhere to expected processes is crucial for both open-source projects and enterprise software. The in-toto project offers a solution by creating attestations for each step, providing verifiable evidence of compliance. Over the past five months, community contributors have worked to enhance the definition and capabilities of in-toto layouts to enforce policies for these attestations. This presentation will showcase the results of this effort, demonstrating how to create flexible policies for any software development lifecycle (SDLC) process, from source code commit to production release. We will explore how to formulate policies that verify attestations for code reviews, SBOM integrity, testing, vulnerability scans, build provenance (such as SLSA), and more. Join us to learn how to ensure your software development process is compliant and secure.
Speakers
avatar for Aditya Sirish A Yelgundhalli

Aditya Sirish A Yelgundhalli

Ph.D. Candidate, New York University
Aditya is a Ph.D. candidate at New York University where he researches software supply chain security. He is a maintainer of in-toto, which is incubated at the CNCF. He is also a contributor to TUF, another CNCF project, and a maintainer of gittuf, a sandbox project at the OpenSSF... Read More →
avatar for John Kjell

John Kjell

Director of Open Source, TestifySec
John is responsible for open source at TestifySec, a software supply chain security startup. He is a maintainer for the Witness and Archivista sub-projects under in-toto. Additionally, John is an active contributor to CNCF's TAG Security and multiple projects within the OpenSSF. Before... Read More →
Thursday November 14, 2024 4:30pm - 5:05pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

5:25pm MST

Longhorn: Intro, Deep Dive and Q+A - David Ko, SUSE
Thursday November 14, 2024 5:25pm - 6:00pm MST
Longhorn is a cloud-native, distributed block storage solution for Kubernetes, supporting persistent volume capacities and compatible with CSI protocols. It is designed for agnostic deployment across on-premises, edge, and cloud environments, serving as an independent storage solution within your cluster or as part of your broader infrastructure platform. Longhorn covers key data areas including data integrity, data locality, volume migration, replica rebalancing, automated volume operations, snapshot/revert, backup/restore, disaster recovery, data protection, data encryption, backing images for VM workloads, and so on. Besides, the new v2 data engine is under active development to enhance Longhorn's data plane performance. In this session, we will discuss the latest v2 status, like online replica rebuilding, new volume upgrade mechanism, volume trimming, and other significant features. We will also provide insights into the roadmap and engage in an in-depth discussion.
Speakers
avatar for David Ko

David Ko

Engineering Director, SUSE
David Ko, a senior engineering manager at SUSE, is currently leading the Longhorn project (CNCF incubating) and is primarily dedicated to open-source development. David is not just a project/product/team/people manager, but also a hands-on developer and architect with 10+ years of... Read More →
Thursday November 14, 2024 5:25pm - 6:00pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD
 
Friday, November 15
 

11:00am MST

Bloomberg's Journey to Manage Multi-Cluster Training Application with Karmada - Leon Zhou & Yao Weng, Bloomberg
Friday November 15, 2024 11:00am - 11:35am MST
Bloomberg provides an on-premises Data Science Platform using cloud-native software to support internal AI model training. It runs on Kubernetes spanning multiple data centers and featuring a diverse range of GPU types. However, managing such a large-scale and heterogeneous GPU environment poses many challenges, such as improving resource utilization, reducing operational costs, and scheduling workloads across different GPU types. In collaboration with the Karmada community, Bloomberg's Data Science Platform team has aimed to tackle these challenges by addressing multi-cluster batch job management problems. This talk will delve into the approaches the team has adopted, including: - Intelligently scheduling GPU workloads across multiple clusters - Using Karmada's resource interpreter to support Custom Resource Definitions (CRDs) on top of a multi-cluster architecture - Building a highly available Karmada control plane - Establishing a consistent training job submission interface
Speakers
avatar for Yao Weng

Yao Weng

Senior Software Engineer, Bloomberg
Yao Weng is a Senior Software Engineer on Bloomberg’s Data Science Platform engineering team. She has contributed extensively to optimizing the company’s Kubernetes environment for high performance compute, model inference, and workflow orchestration. Yao Weng obtained her Ph.D... Read More →
avatar for Leon Zhou

Leon Zhou

Software Engineer, Bloomberg
Leon Zhou is a software engineer on the Data Science Platform engineering team at Bloomberg. With prior NLP experience, he is now building ML platforms to facilitate machine learning development. He is interested in ML infrastructure to enable large-scale training and complex pipelines... Read More →
Friday November 15, 2024 11:00am - 11:35am MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

11:55am MST

WG Serving: Accelerating AI/ML Inference Workloads on Kubernetes - Eduardo Arango Gutierrez, NVIDIA & Yuan Tang, Red Hat
Friday November 15, 2024 11:55am - 12:30pm MST
The emergence of Generative AI (GenAI) has introduced new challenges and demands in AI/ML inference, necessitating advanced solutions for efficient serving infrastructures. The recently created Kubernetes Working Group Serving (WG Serving) is dedicated to enhancing serving workload on K8s, especially for hardware-accelerated AI/ML inference. This group prioritizes compute-intensive inference scenarios using specialized accelerators, benefiting various serving workloads such as web services and stateful databases. This session will dive into WG Serving's initiatives and workstreams. We will spotlight discussions and advancements in each workstream. We are also actively looking for feedback and partnership with model server authors and other practitioners who want to utilize powers of K8s for their serving workloads. Join us to gain insight into our work and learn how to contribute to advancing AI/ML inference on K8s.
Speakers
avatar for Yuan Tang

Yuan Tang

Principal Software Engineer, Red Hat
Yuan is a principal software engineer at Red Hat, working on OpenShift AI. Previously, he has led AI infrastructure and platform teams at various companies. He holds leadership positions in open source projects, including Argo, Kubeflow, and Kubernetes. He's also a maintainer and... Read More →
avatar for Eduardo Arango Gutierez DE

Eduardo Arango Gutierez DE

Senior systems software engineer, NVIDIA
Eduardo is a Senior Systems Software Engineer at NVIDIA, working on the Cloud Native Technologies team. Eduardo has focused on enabling users to build and deploy containers on distributed environments.
Friday November 15, 2024 11:55am - 12:30pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

2:00pm MST

Exploring KubeEdge: Architecture, Use Cases, and Project Graduation Updates - Yin Ding, Google & Hongbing Zhang, Daocloud
Friday November 15, 2024 2:00pm - 2:35pm MST
In this session, KubeEdge project maintainers will provide an overview of KubeEdge's architecture and its industry-specific use cases. The session will begin with a brief introduction to edge computing and its growing importance in IoT and distributed systems. The maintainers will then delve into the core components and architecture of KubeEdge, demonstrating how it extends Kubernetes' capabilities to manage edge computing workloads efficiently. They will share success stories and insights from organizations that have deployed KubeEdge in various edge environments, such as smart cities, industrial IoT, edge AI, robotics, and retail, highlighting the tangible benefits and transformational possibilities. Additionally, the session will introduce the certified KubeEdge conformance test, discuss advancements in technology and community governance within the KubeEdge project, and share the latest updates on the project's graduation status.
Speakers
avatar for Hongbing Zhang

Hongbing Zhang

Chief Operating Officer, Daocloud
Hongbing Zhang is Chief Operating Officer of DaoCloud. He is a veteran in open source areas, he founded IBM China Linux team in 2011 and organized team to make significant contributions in Linux Kernel/openstack/hadoop projects. Now he is focusing on cloud native domain and leading... Read More →
avatar for Yin Ding

Yin Ding

Engineering Manager, google
Yin Ding, an Engineering Manager at Google, lead the Kubernetes Hardening team and brings over 15 years of expertise in large-scale and distributed computing. As a co-founder of the CNCF KubeEdge open-source project and the TSC Chair of LF Edge Akraino, Yin Ding has made significant... Read More →
Friday November 15, 2024 2:00pm - 2:35pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

2:55pm MST

Nothing but NATS - Going Beyond Cloud Native - Byron Ruth & Kevin Hoffman, Synadia
Friday November 15, 2024 2:55pm - 3:30pm MST
These days building so-called cloud-native apps involves assembling a custom stack of tools 10x bigger than the app we're building. Additionally, applications increasingly need to expand out to the edge and cloud-native stacks simply don't work in those environments. Fortunately with NATS, we don't need a stack. In this session you'll see how we can leverage compute, storage, and connectivity to build cloud-to-edge native apps more powerful than ever, with less code, effort, and frustration.
Speakers
avatar for Byron

Byron

Byron Ruth, Synadia
Byron is the VP of Product and Engineering at Synadia, the company behind the NATS.io project. Prior to joining Synadia, he spent 14 years building software and systems in support of pediatric biomedical research. Outside of work, Byron enjoys running, cooking, yard work, and spending... Read More →
avatar for Kevin Hoffman

Kevin Hoffman

Engineering Director, Cloud Platform, Synadia
Kevin is addicted to building and designing distributed systems. He has been using NATS for years and is now building out platforms that run on it.
Friday November 15, 2024 2:55pm - 3:30pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD

4:55pm MST

Ten Years of gRPC: Looking Back and Looking Forward - Kevin Nilson, Google & Israel Shapiro, Broadcom
Friday November 15, 2024 4:55pm - 5:30pm MST
Over the past ten years, gRPC has become indispensable to a breathtaking array of engineering organizations. Join the maintainers look back at how gRPC got to where it is today, the way the software has grown, and the community along with it. Then, see what's in store for the future of gRPC in the decades to come.
Speakers
IS

Israel Shapiro

Cloud Native solutions architect, Broadcom
Israel works at Broadcom’s Enterprise Security Group as a Software Architect for the next generation Cloud Native Datapath of the Web Security Service.
avatar for Kevin Nilson

Kevin Nilson

Engineering Manager, Google
Kevin works at Google as a Software Engineer Manager on the gRPC team. At Google Kevin has worked on projects such as Chromecast, Google Home, Stadia and now gRPC. Kevin is a Java Champion and four time JavaOne Rock Star. Kevin has spoken at conferences such as Google I/O, JavaOne... Read More →
Friday November 15, 2024 4:55pm - 5:30pm MST
Hyatt Regency | Level 4 | Regency Ballroom BCD
 

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
  • 🚨 Contribfest
  • 🪧 Poster Sessions
  • AI + ML
  • Breaks
  • ⚡ Lightning Talks
  • Cloud Native Experience
  • Cloud Native Novice
  • CNCF-hosted Co-located Events
  • Connectivity
  • Data Processing + Storage
  • Emerging + Advanced
  • Experiences
  • Keynote Sessions
  • Maintainer Track
  • Observability
  • Operations + Performance
  • Platform Engineering
  • Project Opportunties
  • Registration
  • SDLC
  • Security
  • Solutions Showcase
  • Sponsor-hosted Co-located Event
  • Tutorials