Video summary
The CNCF Technical Oversight Committee public meeting held on August 18, 2026, opened with administrative updates and a review of white papers concerning storage landscapes and Dragonfly I/O bottlenecks, inviting community feedback via GitHub pull requests. A central theme of the gathering was an in-depth evaluation of the ecosystem's health after a decade of development, where data from LFX Insights revealed critical patterns such as the concentration of pull request reviews among single individuals, discrepancies between listed and active maintainers, and declining activity post-milestone. These findings prompted the committee to discuss calibrating graduation criteria for projects that often lack updates reflecting current governance standards, leading to a proposal for a "graduation refresher" approach designed to sustain ecosystem vitality without imposing new governance levels, potentially utilizing automation and AI tools.
Specific project reviews highlighted both progress and challenges across various initiatives. Meshery continued its security self-assessment while awaiting one final adopter interview, and Cloud Native PG moved forward with scheduling interviews and advancing governance recommendations. OpenEBS was nearing the completion of its review, whereas Cubelet's graduation path required attention to a governance skew favoring IBM and Red Hat despite having three lined-up adopters. Other projects like Open Classroom Management were preparing draft due diligence reports, Carmada had resolved blocking issues, and JPC conducted two interviews that necessitated further follow-up. Particular concern was raised regarding Oxia, Subs, and Virtual Cubelet, with Virtual Cubelet flagged for warnings due to a lack of activity from its primary maintainer, Matteo Merl, over the past two weeks.
The committee clarified that signing the Contribution Agreement remains the critical step for maintaining LF project status, distinguishing it from other items which serve as best practices. Given concerns about single-maintainer projects and the potential need for archival, Brandt agreed to follow up with maintainers to discuss their options and the nuances between CNCF and LF project statuses. The meeting concluded with a brief Q&A session that expressed gratitude to the host for facilitating a robust discussion on project health, followed by thanks to all attendees for their participation and feedback. After a short two-minute break, the group prepared to reconvene the following week, emphasizing that future expansion must be managed responsibly to ensure sustainable growth rather than pursuing scale at any cost.
Read the full video transcript
Morning.
>> Morning.
>> Hey folks.
>> Hello everyone.
>> Ahmed back from all your travels.
>> Yes, finally back home.
Nice.
>> Welcome everybody.
>> Awesome.
>> Hello. Hello.
Thank you Katie for joining us. Katie is
our host today.
Yay.
I presume we should wait a bit more
before we start sharing the screen.
>> Yeah,
we always have that huge rush of, you
know, tag members or community people
right after an election and then it kind
of dies off and back to mostly TOC
members. It'll pick back up again soon,
closer to
CubeCon,
so we probably don't have to wait too
much longer.
Awesome. Glad to see Marina Yan.
Katie, do you want to share the slide?
Otherwise, we can have um Bob or Rian.
>> I am I'm happy to share.
>> Okay.
>> Should be fine. Just making sure that I
can't.
Okay,
one second.
I think I have everything ready. Okay.
Okay, I cannot. I need to refresh them.
I have a new laptop. Never mind. Can
anyone share, please?
>> Barbara, do you have it up?
>> Yeah. Ren, do you want to or should I?
>> I go through that every time. Katie,
>> you have it ready. Bob, please do. I
need to look for it.
>> Okay, one moment.
>> I found it. Let me share.
>> Great. And is these recorded as well?
>> Yep. The public one is auto started to
record. Got it. Um, cool.
Hello everyone. Uh, thank you for
joining for our public TOC meeting. Um,
as usual, we have the LF antitrust
policy notice. Pretty much please be
respectful to everyone in the community
and abide by our kind of contact. Um, we
do have a few agenda items that we'd
like to discuss today. Of course, we
have the recurring items as well. Um,
I think let me
let me share this. I think this is the
Yes. Yes, Bob. That's the one. Can
anyone share that?
The GitHub issue.
One sec.
>> Work in progress. Okay.
Wonderful. Um so uh as usual as I
mentioned we have uh some recurring
items. Uh we currently we don't have any
open votes. Uh so I mean well we can
click on the link but we don't have
anything open. Uh we don't have to do
any kind of reviews in that regard. Uh
next let's look into um reviewing and
assessing the projects in moving levels
uh especially the new ones that came in.
And currently we should have
four of them. Uh so we have a few of
them in uh evaluation with the TC. We
have new ones which are cages, nets, jpc
and cube armor. Um
as you can see two of them are going for
incubation and two of them are going for
graduation as well.
Do we want to get any two sponsors
within this call?
Should we do it one by one?
Um, actually I think everybody is tied
up right now. The only one that might be
available is Mario and I don't see him
on the call. I did ping him to see if he
would take up K agent.
So,
and have not heard back.
So I think right now closing out the
other ones.
>> Okay. So it seems like all of the TC's
have something assigned. Um the good
news most of them are in adopter
interviews which usually is supposed to
be one of the later stages. So hopefully
we're going to have a few more TCS
available uh to take on new due
diligences for these projects as well.
Um, should we move next to review the TC
board?
Um, so as you Oh, there's a lot of new
things happening. It's 112. There's a
lot of things happening. Um,
how do you want to address this, Karina?
Do we want to go for the latest items? I
think right now um probably go to our
agenda and then while
while we're discussing that let's see
what we can close out on the board
because there's a lot of stale issues on
the board um and then come back and
revisit that.
>> Sounds good. Uh so in addition to these
recurring items uh as mentioned we have
a special agenda or a prepped agenda for
today. Um the first item is to have a
reminder to the community members to
review the white papers that we are
having currently um on um storage
landscape and dragonfly for IO block uh
bottlenecks as well. Um so I the both of
the white papers are linked here. I
definitely encourage you to have a read
through and provide reviews accordingly.
I think that's going to be very very
valuable.
Thank you, Bob.
Yeah.
Does anyone have any kind of maybe
comments or perhaps any anything that
they would like to discuss in it in
regards to the white papers at the
moment?
So regarding those two white papers uh
in which do you know kind of which phase
are these like are they uh looking for
just open for reviews?
Should we just go and and comment on
those uh pull requests?
>> Yes, ideally commenting on the PR is um
the best the best way. Again it's it's
transparent. It also encourages open
discussion as well. So I definitely
encourage you to do so directly.
Karina
um wanted to so the landscape V3
um there's a lot of great additions to
it and so it' be great to see other um
eyes on that one and thank you Brandt
for your comments on that one in your
review. It's awesome.
So, it's nice to see another white paper
out. Um, it looked like there was a
another performance paper that was
linked off the white paper that I asked
for removal for right now because it
wasn't published and that was a great
catch rant. However, I would love to see
that one published because it's still an
important area. So TOC liaison for uh
tag infrastructure
um be great to um make sure that that
one's getting out too a new one.
Um and then this second white paper the
is a minor update to the AI scheduling
one. So that's a really quick review
too. Thanks Katie.
>> Awesome. Thank you Karina.
Great.
Cool. Uh so I think the biggest item of
discussion is evaluating the overall
CNCF ecosystem project health. Uh so
a bit of preview because I'm going to
focus more on the graduate graduated
projects as well and um Karina is going
to do a full introduction of uh some of
the work and some of the reviews that
she has been doing. Um but I think it's
very very important to understand that
the CNCF ecosystem has had 10 years of
development and within these 10 years of
development we had varied levels of or
different criterias and different ways
to evaluate projects for different
maturity levels. I think in the last
years we have been better at being very
declarative in terms of the criteria
that you use and provide um guidance if
especially if there is any kind of
exceptions and also document those
exceptions as well. So I think we've
been better at documenting and being
transparent with the community on how
these evaluations are happening. At the
same time, we need to recognize that uh
we still need to look back and have some
level of calibration across projects
within the same maturity level. Um now
of course we have a lot of tooling uh a
lot of um dashboards. We have the LFX
insights which is quite helpful and has
been evolving quite well within the
latest years as well. So we have more
metrics um and with metrics we can also
perceive some of these discrepancies
between the projects as well. Um Karine,
I know of course you you've done all the
work on this one. Can you provide
perhaps an overview of this and then I
can focus on the graduated um projects
too?
>> Yeah, definitely. So some of this is a
rehash because we went through and
discussed the governance criteria
updates and we had the spec criteria
updates also. So TOC again has been
focused on um providing more clarity um
while also giving room for
there is always going to be some
subjectivity. Um however some of the
patterns that through looking out of the
projects and again thank you to the LFX
insights team um for pulling together
all the data um that they do on the back
end. Um so looking at the data and
looking at all the projects across the
ecosystem so namely 72 projects across
incubating and graduated
um because there's over 200 in the
ecosystem but
um
some highlights um review concentration
so there's maybe one or two people
actually reviewing PRs
all right So, a lot of projects have one
person merging, but a better indicator
of health is how many people are
reviewing PRs,
right? Um, and in some cases,
um, the data showed that the same person
might be merging their own PR.
So, those are some good things to look
at. Also,
when the TOC looks at projects and
removing levels, there is obviously the
TOC looks at um the diversity of the
maintainers. Um if we go back and do
another review to see who's actually
active, there's a big discrepancy there.
On paper, again, it may be that um
there's good diversity. However, in
practice, um, we need to keep an eye on
and work with the projects, um, that may
not have as much active diversity.
Um, we've also seen some postmilestone
activity decline. What this means is
there's a huge push, right, to move to
another level where whether it's
incubating or graduated. Um and then
after moving to that level, we'll see a
decline in contributions, diversity,
etc. Um
that's another um area that the TOC
needs to keep an eye on
and uh and thankfully we can see that
through the data. Um and that just means
that we can um keep reaching out to
projects and making sure that the
ecosystem and specifically the projects
remain healthy for the ecosystem.
Um
looked at in the data um
should have updated this to predictable
organization instead of vendor. Um but
really it's organizations that maybe we
could see indicators earlier that are
perhaps moving from one project to
another project. And that just means
that the CNCF, the foundation can step
in and the project's team to help um
gain maintainers for the project if
another organization or group of
maintainers has moved on. Um, and this
is something that's just been seen.
It's um, we'll see it also as projects
mature. Um, we'll see groups of
maintainers move on to newer sandbox
projects. So, it's um, it's just signs
of a healthy ecosystem too.
Um something that was interesting too is
uh there's some projects that maybe the
primary organization
um that contributes to the project has
been acquired multiple times by other
companies.
Um that's also normal in you know the
system that we all work and live in.
However, what that means is a loss of
um
I'm reaching for the right word. Um
institutional knowledge. There we go.
Close. [laughter] But institutional
knowledge. Uh and that's why we keep uh
writing everything down, right? And then
iterating and if it's inaccurate, we
keep continuing. And I loved what um I
know Kevin brought this up at the panel
in Japan.
Um making sure that all our context is
captured.
Um and that helps us scale and helps the
projects be sustainable. So thanks Kevin
for those words of wisdom.
Um and then uh the last one that I put
here, it says five patterns, but it's
actually six. Um actually no it's five
but we do so uh another thing that was
great to see is that there are a lot of
indicators that projects are ready to
move to the next level.
So we've been doing a big push to um get
through the backlog. However um we have
a number of projects that are ready for
whether it's incubating or graduation.
And so the TOC, it's good to proactively
um reach out to get these projects into
the backlog um so they're ready. Um and
I think the TOC is ready to see them in
the queue too.
Um also uh the criteria updates for
governance again. Um we merged a lot.
That'd be good for community and others
to review the merges and then the new
documents. There will be a blog going
out. Um,
it almost went out yesterday, but I
pulled it back because I wanted the TOC
members here to review it again to make
sure that um, what we're publishing the
TOC continues to stand behind. Um, so
you'll see that going out. I don't
believe it's next week, but then week
after. Um, however, it's all based on
the information that's already been
merged.
Thanks, Katie.
And, uh, and then back to you, Katie.
Yes.
Um
actually actually in regards to the five
new patterns observed within the
ecosystem um I was I mean everyone has
discussed about AI and so forth but I'm
wondering if with the help yes we can
see perhaps few maintainers but perhaps
with the help of the the coding
assistant the assistants and AI in
general they are capable to maintain
more. I'm just wondering if this is
something that we would be able to
observe. Um just putting it out there if
anyone has any kind of comments or any
observations or insights into that. Um
but the next one is of course we have
our graduated projects. We currently
have 29 of them. Um the graduated
projects are supposed to represent
mature uh stable uh projects within our
ecosystem. they are pretty much the um
northern stars in kind of the area that
they actually operate in. Um also we
have have to recognize that the
graduated projects well actually we have
to recognize that as the TUC's when the
project is graduated we don't have as
much interaction or follow up with the
projects and I think we need to
recognize that and perhaps uh remediate
that as well. Um now this comes
especially uh when it comes to as I
mentioned we have uh evolved our
criteria throughout many years and it's
only natural because again we had
multiple uh situations and kind of use
cases that we need to consider and
evolve the criteria accordingly. However
we did not necessarily retrofited some
of these new criteria to the old
projects. So for projects who have
graduated for example 5 to 7 years ago
um the criteria was very different than
what we are using using now. Um so I
think it's very important for us to
have some level of calibration because
we want to ensure uh some level of
similarity what it actually means to be
graduated within CNCF. Um and perhaps
this is where we need to be a bit more
proactive in reaching out to the
graduate projects and help them perhaps
retrofit some of these criteria as well.
Um I um I know Karina has been working
in the background uh doing a very
comprehensive report around the
gratitude projects and some of the gaps
that we uh I mean the projects would
need to fill but I think that's going to
be for some of the future sessions. This
is mostly for us to kind of see some of
the upcoming work within the TUC. Um I
think however this is very important. We
have to do actually we need to care for
our graduate projects. These are again
the ones who have the biggest
communities. um and the ones who are
some of the gravitational points within
our ecosystem. So I think here as well
Karina you proposed a freel approach um
for monitoring the graduated projects.
Um I mean I have my perspective of it.
Would you like to introduce yours as
well and then we can go for it?
Um so I pulled this from
and I thought I included the link but
let me go find it unless Bob or somebody
else finds it first. um pulled it from
the discussions that we had in other TOC
issues um because this has been a hot
topic for a couple of years now. Um so
tag reboot was a topic for several years
and as the TOC is
trying to move faster um and I know we
all try to avoid the term bike shedding
but we'd like to not bike shed and move
forward. Um
anyway, what I would like to say is that
these
um the layered approach is from the
documentation and it'd be good to uh
discuss this as a group on whether this
is the right approach. Um are there
alternatives that we would like to
discuss and um what you think Katie?
>> Yes, thank you. So, I think I posted the
original issue. It's something that
Ricardo opened in 2024. It's been a
while. Um, but also I think
um the TUC has changed massively the the
way that we operate and trying to be
very proactive not just in evaluating
projects but to oversee the entire
ecosystem and to actually hold the
entire vision for the ecosystem and I
think this is what's important. um the
issue is there. I think it's quite
important to understand that this um
again has been recognized by the TC. We
just need kind of the time frame. We
need a planning and actually implement
this as well. Um so yeah, this is pretty
much to discuss um how do you see this?
Um how perhaps you see we should
approach this? If you have perhaps any
feedback that would be very very
helpful.
Yes, Brand
>> I I think there's probably a lot of
unspoken agreement on like the overlays
of all these things together. Um, which
I think are really interesting and
really fun opportunities to
like actively explore. So when I see the
discussion on like the five patterns of
like risks and things like that of
looking at projects that are maybe ready
for moving levels that haven't applied
um as well as the overlay of projects
that have applied but maybe aren't
ready. Um and then the overlay of what
we've mentioned with insights uh metrics
all the things that we can automate.
all all of that feels like there's a
like a a theme in there and I I'm
certainly not the one that's proposing
something novel here cuz I'm sure
everyone's thinking about it but like
that automation piece right in the
middle of like
evaluating graduated evaluating projects
that need to move evaluating projects
that shouldn't move like there it seems
like there's a pretty common theme here
and especially when I look at that first
comment by Justin Capos on 1496
and like it it just comes right full
circle of like hey the the problem is
still the life cycle of managing these
um one one one of the problems maybe not
the only problem but um kind of like
acknowledging that and looking at like
how do we not spend time on things that
don't need the time yet as when I think
about what's maybe in the in the backlog
for application that should be postponed
till later. Um
really interesting. I'm I'm really
really excited about like trying to pick
away at that.
Thank you, Brian. Um I think some some
followup thoughts here. Um you're right.
I think with the TUCC's uh we have to be
very very specific with our time and
actually where we put our resources
because as you mentioned like you've
seen even at the beginning we have new
projects that are in the queue but we
don't have the TC's to actually do the
due diligence uh not not yet at least um
so we have to be very very um I want to
say maybe selective is the right word we
have to be concentrated pretty much um I
would love also again like because we
have the tooling of AI and I'm I'm
pretty sure that a lot of us are using
AI in some capacity in terms of
automating some of they work. Uh perhaps
this is something that we can leverage
to have like a mockup due diligence
process. So it's not going to be a full
QC um due diligence, but perhaps
something of an automated report saying
that you need to still fulfill this
required criteria. Um or actually
fulfill everything and this is the right
time for you. So perhaps
providing this milestones for for the
projects a bit more practically might be
helpful for them. But again only if this
can be automated.
Any other feedback comments?
Perhaps you are working with a graduated
project well like you're using a
graduated project uh that have has
graduated maybe 2017 2019 uh time frame.
Um
how do you see their interaction with
the community? Perhaps you have any
concerns or maybe kudos.
Yes, Karina. Well, Mauricio, I think
Karina, you're first.
Um, I'll let Mauricio go first. Go
ahead.
>> Just uh I I guess just a quick comment
about that. Like I worked for at least
two projects that graduated and uh well
very close with two projects that
graduated and that was exactly the the
feeling. It's like as soon as they
graduated they stopped thinking about
it, right? So my feeling always was
about that like how do you create like a
continuous process that after graduation
like TLC or like the the tax or a group
basically suggest what the project
should do next right and after
graduation it feels to me that they
should enter into the new phase where
they will just keep getting advice and
there will be a stream of advice coming
uh towards the projects based on more
mature projects in the ecosystem. So you
can start like gracing the maturity of
all the projects kind like in a like in
another order way. Um I do feel that
defining the process might make some
sense like and again again I haven't
been in those discussions uh so far but
I would love to kind like understand
before automating something I would love
to understand what the process is and
what the objective is right when I see
the layers I do understand kind like
what the the the overall picture is but
when you go into the concrete right like
if you pick one project what is this
project should be doing based on
recommendation from this group or other
groups into the CNCF. That's the kind of
thing that I would like to see there.
So hopefully that makes sense. Yes. Um I
think currently the way that we were
looking at the graduation refresher is
again it's a refresh. Um it is not
supposed to be a new level of due
diligence. It's not supposed to be a new
label. It's however supposed to be um
perhaps a credibility coefficient for
the community that the project is still
kind of aware and involved and actively
looking to kind of lies and partner with
CNCF throughout their journey. Uh so uh
I think at this stage what we're looking
for is to understand what are some of
the items that are missing. I think
again like we Karina has done the report
as well and some of the items are like
they're missing a security assessment or
it hasn't been done for a few years. So
perhaps we we can open an issue for them
to concentrate on that. Perhaps um
they're missing a release. MD file
because that was a topic of discussion
that was introduced um again after like
a very particular use case that we have
to evaluate within the CNCF and then we
require that from all the projects but
then that applies to future projects not
necessarily to the past projects. So
things like that just making sure that
everything is calibrated. Um supposed to
be very action based and very practical
as well. Um and again as as Karina
mentioned at the beginning um I mean new
patterns in terms of how the ecosystem
behaves but when it comes to I think one
of the biggest challenges for all the
projects not only graduated projects is
organization diversity in terms of
contributions. Um but I think that can
be tackled in a different way as well.
So we are looking to understand where
what they can do to calibrate their
criteria but also what we can do in
order to sustain their health within
CNCF. Karina.
>> Um, so one of the the flags and again
it's been 10 years. Um,
the security self assessments especially
with all the security concerns right now
in the ecosystem, right? uh this tax
security has done an amazing job with
one coming out with the security
assessment and then two jumping in and
helping ask the questions of the project
and help review their assessment. Um the
assessment came out after some of these
projects moved to the level that they're
at. So at the time it wasn't required as
criteria. Um, so bringing them up to the
current level
um that we're at in the ecosystem would
be healthy overall. And a quick reminder
for the TOC is that um it's in our
charter that right now we cannot ask
governance changes of graduated
projects. That would have to be a
request back to the governing board.
However, for technical requirements,
other um road map, uh release, etc., all
the criteria updates that we've made
based on health of projects and what
we've seen. Um
it absolutely would be great to engage
with the projects to make sure that
they're meeting the current level of
maturity that is expected in the
ecosystem.
So the security self assessment was one.
Oh, go ahead Katie. No, like I was just
kind of giving the the nods here. Uh
security is a very important aspect
especially now with like so many CVs
coming up with again the more code you
have the more security risks you
potentially have and everything is
multiplying now. Um so yeah security is
very important aspect of this I would
say.
Oh,
>> no one said that.
[laughter]
>> You didn't say that.
>> Yeah.
>> Um, and Brent, I see you written here. I
wanted to give you um kind of uh
the spot to speak next, but Karina, do
do you want to finish anything or can we
invite Brent to speak?
>> Go ahead. Yes, please.
Bren,
>> I I think I'm still kind of processing a
lot of this on the fly with
conversations that have been had
previously. So tag security and
compliance we've we've talked about a
lot of things over the history of just
my involvement with a tag and and much
before I even joined um to kind of the
the layer of like what is the
possibility um supply chain security it
has a lot of different I want to say
threads to pull on but one of them was
very much like the the angle of like
securing the project like source itself
self um and trying to think about like
how to maybe do that independent of the
platform that's hosting it. Um, and me
from a like TOC reviewer standpoint, I
think like I would get a lot of value
out of not only what's coming from
insights, not only what's coming from
like the OpenSSF
like badges and things like that that
kind of look at maybe more of the
platform layer, um, but what can come
from like the source layer that gives me
confidence about like what what is
implemented, what's happened, and what
security auditing can be done.
Um, and so I know we've talked
more than a few times about like
solutions in that space. Um, and and we
have the expertise in our tags to like
pursue um, a lot of these opportunities.
And so I'm trying to look at things from
like the initiative layer of like what
would be a great new initiative that
could exist and and that was one of them
when we talked about kind of the
systemic issues of who is approving and
merging and who contributed the change.
um like we have we have all the
expertise and the tooling to maybe
validate some of these things but
controlling some of the
platform layer it can be very difficult
I I believe across the landscape um to
control those rule sets to enforce them
um where maybe there are alternative
tools and initiatives in place that
could could solve some of these
I mean to Bob's comment, I think it
sounds easy. It's not easy as well. Um
yeah, getting especially across
projects, getting them to use um
similar approaches. It is challenging,
but I think again that was by design
because we didn't want to get involved
so low into the project development as
well. Um, so yeah, it's it's it's a bug
and it's a feature at the same time. Uh,
Marina Moore, do you have any any
insights? I think Karina tagged you as
well.
I don't think I have anything in
addition to what to what Brand said
really. Um, I definitely think that um
there's probably space for something in
tax security and compliance to help out
with this. I'm not sure exactly what
shape that'll take yet, but yeah.
Yeah, the tax security was definitely
crucial to a lot of this especially.
Um, cool.
Anything else perhaps you'd like to
discuss? Karina,
>> I was just going to mention that it
would we have to be definitely careful
that we're not overloading tag security.
Um,
they're sustainable right now. We want
to make sure that they remain Yeah.
Um so how do we scale what they're doing
um through some of the automation
um and insights and then to Brand's
point the initiatives that maybe
introduce more automation and guidance.
>> I I also again I I agree on this. I
think automation now is might be more
achievable. I'm not going to say easier,
but more achievable with with some of
the new tooling on the market as well.
Um,
so yeah, tell us how we can help you as
well.
I think one of the results of of this
discussion we're going to open a new
issue on the TSC repository because as
mentioned the uh issue related to this
initiative for graduation refresher was
open two years ago. Um
and perhaps like now we just need to
kind of make sure that it's uh it has
all of the relevant kind of status of
the ecosystem and our approach to
implementing that as well. Uh so any
kind of feedback or comments definitely
welcome on the on the issue as well the
new one. So again I know I know a lot of
Karina has the uh the draft um issue
over there so hopefully she's going to
share that soon with us.
>> Yeah
>> and I think Oh god.
Um I said definitely I wanted to
highlight another
um thing that was outstanding uh that
we've talked about that goes with the
health um issue. If you recall the sub
project maturity levels
um at the last maintainer summit in
Amsterdam
uh we had a session talking about
maturity levels and um maintainers from
Argo
project um discuss their maturity levels
and their project and that they would
like further guidance too. Um, so
I don't know if this group would like to
since Katie it's um your show today with
the time whether that's also an open
discussion. So just wanted to throw that
out there.
>> I mean we have the time we we still have
uh 20 minutes as well and I think we
just have only one one point to discuss
of discussion on the agenda. Um
I plus one to this uh even if we don't
discuss this with today definitely we
need to return to this topic. Um there
has been a lot of again like when we're
doing the due diligence especially
throughout incubation graduation we see
uh that a project is not just one
repository it's a collection of
repositories and this is especially the
case if they have uh different kind of
plugins or different offerings for
different proh cloud providers and so
forth. Um and that has been their uh
their choice of implementing that. Um
currently again historically we do not
have um um a way of
declaratively saying that all of the
criteria applies to everything within
the or um perhaps we need to be very
declarative in that regard. Um but yeah,
looking to see what the group here has
in terms of feedback, thoughts
or maybe we can open an issue and
discuss about that.
Yeah, sounds like I see some nods. Um
yeah. Okay, we can always come back to
this one as well. Uh and then the final
item on the agenda was uh the due
diligence pipeline and open items. Um so
I think this is looking at our current
projects
>> and the TC work
>> our current projects. Yes.
>> Yeah.
So I think we've
is this looking at the TC work kind of
board or do you want to focus
specifically on the open health issues?
I think it's a combination but yeah
>> first first would be the applications to
move levels.
>> Yes, I think we've we've done that at
the beginning.
>> Um usually um if we want
>> Yes. I'm sorry. Um,
>> no, no, no. Because we only looked at
the new ones. We didn't look at the the
current ones. So, um, we currently have
cozy stack where we are. Are we looking
are we looking from the due diligence
kind of standpoint? Yes.
>> Um, start with um the adopter
interviews, I think.
>> Okay, let's do that.
So looking at the adopter interviews, we
have Meshery and here we have Karina and
brand.
Um, so the quick update on meshy and
I'll add it to the comment today is that
there's one outstanding interview this
week and then um the security self
assessment that we just talked about.
There's a lot of discussion on that
issue and it's great that the project
actually they were really
self-reflective and very honest in the
uh self assessment which has made for
some really great discussions. So it's
really good to see project doing that.
Uh so I see that one wrapping up um
before the end of August.
Um
and that's it for me.
>> Cool. I think the next one is cloud
native PG and I think Karina and and
Brent I think you're collaborating on
this one too.
Um focus right now is close out mesh and
brand is scheduling the interviews for
the cloud native PG for the adopters the
um they've been working on their
governance um from recommendations so
it's great to see how fast they jumped
on that. They've been a very responsive
project and uh so right now it's
coordination since the uh main uh person
that we've been working with is on the
other side of the world. So it's time
zones and
I see that one probably wrapping in
September.
Nice. Uh open EBS. I don't think we have
Alex on the call. I haven't seen him.
Alex gave a quick update um since he's
last minute on travel today. Alex um
will work to wrap this one up this week
and send it out for review. So if
everybody can review that when he sends
it out.
>> Wonderful. Um the next one is Cubert
Graduation and I think we have Jeremy.
>> Yeah. Hey, how's it going folks? Um,
we've been struggling to get adopter
interviews for this, but Andrew from the
Cubert project has come in uh real
clutch and we've got three people lined
up to do um different ones across
different industries. So, it's a really
good cross-section um across a bunch of
different time zones. So, scheduling
these is going to be a little rough, but
I'll add everybody to um that was in the
thread to uh to be optional if you want
to sit in on those. Um we also have an
ongoing discussion with them about um
governance. Uh it's pretty heavily
skewed towards IBM and Red Hat. So just
wanted to get some uh some move movement
from them and a little bit of a plan on
how to remediate that a little bit as we
go forward. But other than that, it's
looking pretty good.
>> I know it's been a tough one to get
adopters for this one. So but it's
looking good. So yeah, I'm hopeful that
we can do this. Um, the next one is open
classroom management and we have Joseph
and Kevin. I think Joseph was FAK for
today's meeting. Kevin,
>> yeah, I can give update. So, uh, I'm,
uh, just putting together the, uh, uh,
drafted DD report and, uh, no blocking
issues so far. Um and and also I'm uh
just putting uh together some of the
non-blocking uh feedback and we will
share it to the uh project maintainers
and also uh for the adopter interviews
um Ricardo has done uh some of the
adopter interviews and I'm working with
him to uh uh put together more details
and uh also uh all The adopter interview
[clears throat] reports need to be uh
reviewed by the doctors.
Yeah, that's that's all for the updates.
>> Thank you, Kevin. Uh next we have
Carmada. And here we have Ahmed and
Chad.
>> Yep, that one is in for TOC review. Um
Karina provided some comments on there.
Um, I'm just incorporated those Karina
and I'm going to reach out to Hungai and
team about that blocking issue to have
them get that resolved.
But, yep, it's it's in for review.
>> Awesome. That means we just need to also
update the status, right?
>> Yeah, I need to move it. You're going to
say something, Karina?
>> Yeah, it looks like um
it looks like he he's on top of it.
Okay, looks like he's already remediated
those items.
>> Uh, great. I will go look at that.
Verify.
>> Nice.
>> Great. Uh, thank you, Chad. And then we
have KCP and we have Mauricio and Alex.
Mauricio.
>> Yes, Alex is not here. Uh, yeah. So, uh,
we were scheduling, uh, a doctor
interviews. I think that we did two
already and uh I was on holidays until
yesterday so I haven't had a chance to
catch up with Alex but yeah I know that
we did two uh and those were kind of
okay like the second one wasn't perfect
uh but yeah I need to catch up with Alex
on this one this week I don't know if
he's away for the entire week I need to
check
but this is moving forward
>> cool uh I think he mentioned he might be
back this week but Yeah.
>> Mhm.
>> Um, cool. Uh, Karina, do we do we still
want to look at the new assigned
projects because um what's currently in
progress? It's pretty much uh kind of
initiatives and level changes which is
with CNCF stuff. So, I wonder if we want
to look for those.
>> Um, not the new ones right now. I'd say
we do a quick review on the archive
candidate.
So, um, we also have a few open health
issues. Um, perhaps we can review them,
too.
Yes.
Yes. Um, so we have Oxia, uh, subs and
virtual cublet at the moment.
Yeah,
we don't have anyone assigned to this.
Um,
how do you want to go for this? Karina,
>> um, it looks like because it's the
onboarding deadline, uh, Daniel and
Rion, would you like to give an update
on this one?
>> Yeah, I'm just looking at their
onboarding issue. Um, yes. So, we put a
new automation that flags ones that have
not completed on boarding at 3, six, and
nine months, I think. Rihanna, maybe you
can correct me. Uh, so that's why this
one was flagged as onboarding warning.
Um,
they have just a few basic things. I
mean, the important things, the IP,
the transfer to GH, all that stuff is in
good shape. there's just a few open
tasks like they haven't just done the
SSO dance to connect to open SSF to
start on a badge. Uh they haven't
started on the security MD or governance
MD. Um and I think the largest remaining
task would be just getting them into
license scanning. That's the big one for
us. But um I think the next step is to
follow up directly
with um with the primary maintainer. Who
is
Merlmat? Who's Merl? Matteo Merly.
Um looks like he's got no GitHub
activity last two weeks. He might be on
PTO, but um that's probably next step.
>> Mhm.
It's interesting. Um because I don't
think we've had a case like that before.
And I'm looking at the project. I mean,
I'm looking here. Um, but it's it's
officially like they're using the
sandbox kind of label, which is not
entirely true. Uh, as well. So, I'm
wondering if in the worst case scenario,
we'll have actually have to archive it
before
they actually on board it.
Do we have a deadline for that perhaps?
like if they
>> nonresponsive because they they're using
the thing is like the way I'm seeing it
they they're using the CNCF label but
they're not fully kind of leazing with
CNCF to fully on board either. So it's
kind of in a gray area.
>> Yeah. And kind of the the key lynch pin
for whether it's LF project or not from
our from staff point of view is if
they've signed the contribution
agreement. That's that's the big one
because that activates them in PCC that
unlocks all the the services. Um, and
then there's some things that are on the
onboarding that that are kind of like
best practices that we expect projects
that are in sandbox to need to go
through over time. Um, but but that's
kind of the big um, and this is why we
do it now much early in the pro process
is getting the trademark, the IP, the
contribution agreement signed and
completed. So that's that's really the
most important thing
>> um, from an LF point of view.
>> Okay. Um, thank you for the update.
Let's keep monitoring. Interesting case.
Um the next one we had was uh the new
ones of course virtual cublet. We have
Jeremy already speaking about this.
Seems like there is a new cut release.
Jeremy, do you want to speak through
this?
>> Yeah.
>> Yeah. Sorry about that. Um it's uh it
has had a release. Uh it looks like that
was last month. Um there's a little bit
of activity in the Slack channel. Um but
I think it's still in the same kind of
position where there's really only one
like real active maintainer. Some people
doing some contributions. Like if we
look at the the release that was cut, um
there's some documentation updates, some
deprecated things that allowed them to
bump to Kubernetes 135. a couple of bug
fixes. Um, a lot of lot of updates. Um,
but a bunch of these were first-time
contributors. Uh, I think most of the
changes that landed were first- time
contributors. So, that's a good sign, I
guess. But, um,
still seems maybe like it needs uh
some more attention from the maintainer
side.
any insights perhaps why we had this new
I mean I presume are these new
contributors coming in because they're
worried the project is unhealthy as a
result of that
>> uh I think Cisco is working on a
provider and some of the
>> changes were related to that I think
they might be from Cisco but
>> right I mean we need contributions so
Yeah, I think it might be worthwhile to
follow up with Pierce to ask because the
last comment on this issue was from
October. Um, and there hasn't been like
a public update on the health issue
since then. Um,
actually there's one inside of the uh,
sorry, not this issue. There's one
inside of the virtual cublet repo that
was opened.
Still open that Ricardo opened. The last
comment on that was that uh he's no
longer working with VK, but he's here to
try and help anybody who wants to
contribute.
>> Here's the uh here's the link to that.
I'll put it in the chat.
>> I'm looking for this one as well. Yeah,
got it.
Yeah, got it, too. Yeah. Uh, one face.
Yeah. Um, okay.
Karina, should we find someone who would
like to proactively reach out to the
maintainers and ping them?
Would anyone be willing to reach out to
the maintainers?
>> I worked on this in the past. So, like I
I'm happy to reach out to to peers. Um I
know from the Microsoft side we have
flow investment in this and it was a
Microsoft thing originally.
>> I was uh
looking at the activity in the project
um to see and then I can follow up with
you Jeremy if you're going to reach out
to them.
>> Okay.
Uh the re just quickly is that it's a
single reviewer, single or so. So it's
just it's a single person maintaining
this project. Um it overall it it
doesn't meet the requirements, but it'd
be good to do one more followup before
moving to archival or moving to vote for
whether to archive, I should say. Sorry.
>> Sounds good. Um and we also have SOPs.
Um
the the project has questions.
So for Brandt the and this might be a
good followup for for you is the
it sounds like the project would still
like to know their options. Um the
governing board uh there's really no
good way forward for the project. The
governing board most likely would deny
an exception. Um we don't have a strong
case for the project um unless they can
provide
one. However,
the
the project has outstanding questions on
what it means to perhaps move to being
an LF project instead of a CNCF project.
Um, and what that entails. Um, so
instead of a full TOC meeting since I
think your time is so valuable. Um,
Brandt, if you'd like to take the
followup on that one. I will.
>> Awesome. Fantastic.
>> Sounds good. And I think we are complete
with our agenda.
Yes. Um, we have three minutes. Anything
perhaps we should have discussed and we
didn't. Any follow-up comments? Anything
you want to bring up in these three
minutes?
>> Maybe someone who didn't speak today
would like to speak. Yeah,
>> I was just going to thank you Katie for
a good that was a great discussion on
project health. Um
>> I am looking forward to
>> I'm I'm looking forward to this again.
Um it's great to see that you see being
proactive in this regard. Um and
actually crafting initiatives and time
for this. uh I think it's very valuable
again because we are growing and we are
growing a lot. So it's crucially
important for us to do it sustainably
and not just for the sake of growing. So
uh with that no more philosophy. Thank
you very much everyone who attended
today. Thank you very much for your
feedback as well. Uh I'll give you two
minutes back and see you next week.
Bye folks.