Loading…
16-17 June
Learn More and Register to Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for KubeCon + CloudNativeCon Japan 2025 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Japan Standard Time (UTC+9:00)To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date." The schedule is subject to change and session seating is available on a first-come, first-served basis. 
Monday, June 16
 

08:00 JST

Badge Pick-Up
Monday June 16, 2025 08:00 - 18:00 JST
Monday June 16, 2025 08:00 - 18:00 JST
Foyer

09:30 JST

Keynote: Welcome + Opening Remarks - Chris Aniszczyk, CTO, Cloud Native Computing Foundation
Monday June 16, 2025 09:30 - 09:50 JST
Speakers
avatar for Chris Aniszczyk

Chris Aniszczyk

CTO, CNCF
Chris Aniszczyk is an open source executive and engineer with a passion for building a better world through open collaboration. He's currently a CTO at the Linux Foundation focused on developer relations and running the Open Container Initiative (OCI) / Cloud Native Computing Foundation... Read More →
Monday June 16, 2025 09:30 - 09:50 JST
Level 1 | Pegasus Ballroom
  Keynote Sessions
  • Content Experience Level Any
  • Presentation Language English

09:52 JST

Keynote: Platform Alchemy: Transforming Kubernetes Into Generative AI Gold - Alexa Griffith, Bloomberg & Mauricio "Salaboy" Salatino, Diagrid
Monday June 16, 2025 09:52 - 10:02 JST
As Generative AI reshapes the tech landscape, its tools and solutions often feel overwhelming and disconnected - like scattered elements waiting to be forged into something greater. What does a complete GenAI platform look like? And how does it differ from application-focused platforms many organizations already run?

We’ll guide you through a practical transmutation of your platforms to add GenAI features. We’ll first define the base elements needed to deploy LLM inference on Kubernetes. We’ll then blend key elements into the MVP stage, adding core enterprise AI components like an AI Gateway, shared interfaces via Dapr, and KServe-based deployment strategies. Finally, we’ll tackle advanced features - intelligent load balancing for LLMs, observability patterns, and cost optimizations.

More than a tools showcase, this session is packed with real lessons from enterprise GenAI platform engineers, to help transmute your platform into the philosopher’s stone for AI innovation.
Speakers
avatar for Mauricio Salatino

Mauricio Salatino

Software Engineer, Diagrid
Mauricio works as an Open Source Software Engineer at @Diagrid, contributing to and driving initiatives for the Dapr OSS project. Mauricio also serves as a Steering Committee member for the Knative Project and Co-Leading the Knative Functions initiative. He published a book titled... Read More →
avatar for Alexa Nicole Griffith

Alexa Nicole Griffith

Senior Software Engineer, Bloomberg
Alexa Griffith is a Senior Software Engineer on Bloomberg’s Cloud Native Compute Services organization. She works on building an inference platform for ML workflows and the open source project KServe. She enjoys solving engineering challenges at scale and writing code in Go. She... Read More →
Monday June 16, 2025 09:52 - 10:02 JST
Level 1 | Pegasus Ballroom
  Keynote Sessions, Platform Engineering
  • Content Experience Level Any
  • Presentation Language English

10:11 JST

Keynote: From ECS To Kubernetes (and Sometimes Back Again): A Pragmatist's Guide To Migration - Marc Hildenbrand, Canva
Monday June 16, 2025 10:11 - 10:21 JST
Migrating to Kubernetes offers numerous benefits, but few organizations start from "greenfields" circumstances. Many have critical services running on existing platforms, each leveraging unique capabilities. Transitioning these services to Kubernetes can be a complex and non-trivial challenge.

At Canva—a leading design and collaboration platform serving 220 million monthly active users—we recently undertook an ambitious project to migrate over 400 services from Amazon Elastic Container Service (ECS) to Kubernetes (EKS). These services now span 15,000 pods across two clusters on a typical day.

In this talk, we’ll share the strategies, tools, and processes Canva developed to achieve a (mostly) seamless migration with minimal disruption to our teams and users. Whether you're planning your own migration or just curious about what it takes to migrate at this scale, this session will provide practical insights and lessons learned.
Speakers
avatar for Marc Hildenbrand

Marc Hildenbrand

Staff Engineer, Canva
Marc is a software engineer with 20+ years of experience spanning gaming, consulting, finance, and cloud technologies. He’s served as CTO of a cloud-native consultancy, Lead Gamesystems Engineer for the MMO Lord of the Rings Online, and Developer Advocate for Kubernetes/Openshift... Read More →
Monday June 16, 2025 10:11 - 10:21 JST
Level 1 | Pegasus Ballroom
  Keynote Sessions, Platform Engineering

10:23 JST

Keynote: To Be Announced - Masaya Aoyama, Software Engineer, CyberAgent
Monday June 16, 2025 10:23 - 10:33 JST
Speakers
avatar for Masaya Aoyama

Masaya Aoyama

Senior Software Engineer, KaaS Product Owner, CyberAgent, Inc.
Masaya Aoyama is a Co-Chair for KubeCon + CloudNativeCon Japan 2025, and He is Senior Software Engineer and Product Owner of a managed Kubernetes platform at CyberAgent, Inc. He also serves as a Technical Advisor to 3-shake, Inc. and CREATIONLINE, Inc., both of which are CNCF member... Read More →
Monday June 16, 2025 10:23 - 10:33 JST
Level 1 | Pegasus Ballroom

10:33 JST

Keynote: Closing Remarks
Monday June 16, 2025 10:33 - 10:45 JST
Monday June 16, 2025 10:33 - 10:45 JST
Level 1 | Pegasus Ballroom
  Keynote Sessions
  • Content Experience Level Any
  • Presentation Language English

10:45 JST

Coffee Break ☕
Monday June 16, 2025 10:45 - 11:30 JST
TBA
Monday June 16, 2025 10:45 - 11:30 JST
TBA

10:45 JST

Solutions Showcase
Monday June 16, 2025 10:45 - 19:15 JST
TBA
Visit our sponsors in the Solutions Showcase to try the latest demos, watch live presentations, talk to experts, check out job opportunities, and score some swag.

In order to facilitate networking and business relationships at the event, you may choose to visit a third party’s booth or to access sponsored content. You are never required to visit third-party booths or to access sponsored content. When visiting a booth or participating in sponsored activities, the third party will receive some of your registration data. This data includes your first name, last name, title, company, address, email, standard demographics questions (i.e. job function, industry), and details about the sponsored content or resources you interacted with. If you choose to interact with a booth or access sponsored content, you are explicitly consenting to receipt and use of such data by the third-party recipients, which will be subject to their own privacy policies.
Monday June 16, 2025 10:45 - 19:15 JST
TBA

11:30 JST

A Journey and Lessons Learned To Enable IBM AIU Accelerators in Kubernetes - Takuya Mishina & Tatsuhiro Chiba, IBM Research
Monday June 16, 2025 11:30 - 12:00 JST
In this presentation, we will unveil the secrets and journey to enable an IBM's AI Accelerator in Kubernetes. We utilize wide range of tools and frameworks such as device plugin, custom scheduler, metrics exporter, webhooks and custom resources together to satisfy real requirements from various stakeholders - general users, cluster administrators and driver/runtime developers. Our device plugin and custom scheduler can accept special preference such as topology-aware allocation to enable RDMA, and webhook-based validator guides them to follow specification changes. To sync up allocation status among the components, we carefully defined a custom resource after performance estimation. From developer perspective, we provide various debug-purpose capabilities: for example, device allocation by PCI address for inspection, and pseudo device mode to achieve non-real-device test. In addition, multi-architecture support gives freedom of platform choice to all of the participants.
Speakers
avatar for Takuya Mishina

Takuya Mishina

Researcher, IBM Research
Takuya Mishina is a Staff Research Scientist at IBM Research - Tokyo. He has been working for enhancing cloud infrastructure lifecycle management such as security and compliance posture management. Recent interests include extending the automation mechanism to provide usable AI hardware... Read More →
avatar for Tatsuhiro Chiba

Tatsuhiro Chiba

Senior Technical Staff Member, IBM Research
Tatsuhiro Chiba is a STSM and Manager at IBM Research, specialized in performance optimization and acceleration of large scale AI and HPC workloads on Hybrid Cloud. He is leading a project to enhance OpenShift performance and sustainability for AI and HPC by exploiting various cloud... Read More →
Monday June 16, 2025 11:30 - 12:00 JST
Level 1 | Pegasus Ballroom A+B1
  AI + ML

11:30 JST

Choose Your Own Adventure: The Dignified Pursuit of a Developer Platform - Whitney Lee, CNCF Ambassador & Viktor Farcic, Upbound
Monday June 16, 2025 11:30 - 12:00 JST
Our hero, a running app in a K8s prod environment, knows they are destined for greater things! They’re serving end users, but the value of the cloud is not realized. Hero’s devs toil on custom integrations, deployment is brittle and slow, and security and governance are HARD. Hero longs for a developer platform with consistent and repeatable system building blocks.

It is up to you, the audience, to guide our hero’s transformation from a lost and confused app to one built on a solid foundation that abstracts away complexity and promotes innovation. In their fifth KubeCon ‘Choose Your Own Adventure’-style talk, Whitney and Viktor will present choices that an anthropomorphized app must make as they build an Internal Developer Platform, enabling the devs to have self-service access to widely used system capabilities. Throughout the presentation, the audience (YOU!) will vote to decide our hero's path! Can we navigate CNCF projects and build a platform before the session time elapses?
Speakers
avatar for Viktor Farcic

Viktor Farcic

Viktor Farcic, Upbound
Viktor Farcic is a lead rapscallion at Upbound, a member of the CNCF Ambassadors, Google Developer Experts, CDF Ambassadors, and GitHub Stars groups, and a published author. He is a host of the YouTube channel DevOps Toolkit and a co-host of DevOps Paradox.
avatar for Whitney Lee

Whitney Lee

Developer Advocate, CNCF Ambassador
Whitney is a CNCF Ambassador who is passionate about cloud native tools. Creative and driven, she has created and delivered two KubeCon keynotes, a VMware Explore keynote, and countless fun, funny, and informative community conference keynotes. You can catch her lightboard show... Read More →
Monday June 16, 2025 11:30 - 12:00 JST
Level 1 | Orion
  Cloud Native Novice
  • Content Experience Level Any
  • Presentation Language English

11:30 JST

Add Single-sign-on To Your Applications With Keycloak and Learn About Its Latest Features - Takashi Norimatsu, Hitachi & Marek Posolda, Red Hat
Monday June 16, 2025 11:30 - 12:00 JST
Keycloak is an Identity and Access Management (IAM) open-source software, and CNCF incubating project.
Use it to add single-sign-on and authentication to your applications and secure your services with minimum effort.

In the first part of this talk, we will introduce Keycloak and tell what Keycloak can do, how you can use Keycloak, where Keycloak is used and how Keycloak can resolve the issue that developers encounter when using IAM. We'll look behind the scenes how Keycloak is managed by maintainers, how you can contribute to Keycloak, which community activities are going on, and how you can participate in the activities.

In the second part of this talk, we will explain the latest updates of Keycloak and introduce new features, enhancements of existing features. We will also describe planned features and enhancements for the future.
Speakers
avatar for Marek Posolda

Marek Posolda

Mr., Red Hat
Marek works in Red Hat in Keycloak software engineering team. He works as Keycloak maintainer and focus especially on the protocol layers (OpenID Connect, OAuth 2, FAPI, SAML) and authentication layers. He has been working in Red Hat since 2009 on various middleware projects like... Read More →
avatar for Takashi Norimatsu

Takashi Norimatsu

Senior OSS Specialist, Hitachi, Ltd.
Takashi Norimatsu, Senior OSS Specialist, Hitachi, Ltd. is a maintainer of Keycloak. He has been implemented and contributed security features like Financial-grade API (FAPI) security profiles, W3C Web Authentication (WebAuthn) API support. He leads Keycloak's community "OAuth SIG... Read More →
Monday June 16, 2025 11:30 - 12:00 JST
Level 1 | Appollon

11:30 JST

Never Underestimate Memory Architecture - Bryan Boreham, Grafana Labs
Monday June 16, 2025 11:30 - 12:00 JST
Modern cloud servers are built on NUMA (Non-Uniform Memory Access) and SMT (Symmetric Multi-Threading, aka Hyperthreading) — but few engineers realize how much these technologies impact application performance.

NUMA means that your cloud server’s memory might be significantly slower to access, because it’s connected to a different CPU, while Hyperthreading makes a single CPU core pretend to be two, but not at twice the speed.

This talk will:
• Demystify NUMA & Hyperthreading — what they are, how they work, and why they matter.
• Explore Kubernetes integration—the (limited) ways Kubernetes interacts with NUMA.
• Show real-world performance impact — illustrated with measurements on AWS and Google Cloud.
• Give you visibility — how to use Prometheus metrics and Linux commands to view your servers’ NUMA and SMT configurations.

By the end of the session, you'll have an understanding of the issues, and the tools to measure and their impact on the performance of your workloads.
Speakers
avatar for Bryan Boreham

Bryan Boreham

Distinguished Engineer, Grafana Labs
Bryan Boreham is a Distinguished Engineer at Grafana Labs, working on highly scalable storage for metrics, logs and traces. Bryan's career has ranged from charting pie sales at a bakery to real-time pricing of billion-dollar bond trades. A contributor to many Open Source projects... Read More →
Monday June 16, 2025 11:30 - 12:00 JST
Level 1 | Pegasus Ballroom B2+C
  Operations + Performance

12:10 JST

Beyond Stock Outs: Scaling Inference on Mixed GPU Hardware With DRA - John Belamaric, Google & Jack Francis, Microsoft
Monday June 16, 2025 12:10 - 12:40 JST
Pods are PENDING?!? Ugh, none of the latest GPUs are available. But there are tons of older ones! If only you could tell Kubernetes “use the best GPU available, as long as it has 20GB+”...(enter: DRA).

Kubernetes’ Dynamic Resource Allocation (DRA) system, beta since 1.32, allows variations on which GPUs get allocated to Pods. You can write a flexible spec so that when the Deployment scales, Pods can land on whatever nodes have available GPUs. DRA works even if you need different numbers of devices for different hardware! This enables a new level of utilization and efficiency, saving your organization real money.

Combined with an advanced Node Autoscaler like Google’s Custom Compute Classes or Karpenter, you can spin up more VMs with whatever GPUs are available - or the most economical - all for a single Deployment. Scaling is simpler and more reliable, and your workload can scale even when your preferred type of GPU is stocked out.

Come learn how, and see it in action with a demo!
Speakers
avatar for John Belamaric

John Belamaric

Senior Staff Software Engineer, Google
John is a Sr Staff SWE, co-chair of K8s SIG Architecture and of K8s WG Device Management, helping lead efforts to improve how GPUs, TPUs, NICs and other devices are selected, shared, and configured in Kubernetes. He is also co-founder of Nephio, an LF project for K8s-based automation... Read More →
avatar for Jack Francis

Jack Francis

Principal Software Engineer, Microsoft
Jack works on open source Kubernetes from his basement in Portland, Oregon, USA. When he’s not working, he’s usually upstairs hanging out with his family. On occasion he straps on a guitar and turns the amp to 11.
Monday June 16, 2025 12:10 - 12:40 JST
Level 1 | Pegasus Ballroom A+B1
  AI + ML

12:10 JST

Safeguarding Your Applications - Achieving Zero Downtime During Kubernetes Upgrades - Kazuki Uchima & Kakeru Ishii, Google Cloud
Monday June 16, 2025 12:10 - 12:40 JST
Kubernetes cluster upgrades are frequent and can lead to unforeseen problems, including application downtime. Therefore, it is essential to understand the roles of each component that makes up a Kubernetes cluster and how they behave during an upgrade in order to safely upgrade the Kubernetes cluster and achieve zero downtime for your applications.

This session will explain the basics and practical practices to improve safety, and ensure zero downtime for your applications. In 30 minutes, we will provide an easy-to-understand explanation of everything from the roles of the main Kubernetes components to points to note during upgrades and recommended configurations to minimize or eliminate application downtime during the upgrade process. This session is recommended for those who are going to operate Kubernetes in earnest and those who are troubled by upgrades and want to learn how to prevent application downtime during Kubernetes cluster upgrades.
Speakers
avatar for Kazuki Uchima

Kazuki Uchima

Technical Solutions Engineer, Google Cloud
Kazuki Uchima is a Technical Solutions Engineer at Google Cloud, specializing in Cloud Native technologies with a focus on Kubernetes. He provides consulting, architecture design, and technical support for Cloud Native solutions.
Monday June 16, 2025 12:10 - 12:40 JST
Level 1 | Orion
  Cloud Native Novice

12:10 JST

Introduction To Vitess: Features and Architecture of a Distributed Database - Florent Poinsard, Manan Gupta & Deepthi Sigireddi, PlanetScale
Monday June 16, 2025 12:10 - 12:40 JST
Welcome to the Vitess introductory session! You will learn what Vitess is and explore its high-level architecture along with the powerful features it offers. We will also dive into
how Vitess is able to serve query traffic as a distributed database.
Our maintainers will finish the session by presenting the latest updates in recent Vitess releases, and give you a sneak peek into the exciting features they have planned for the next releases.
Speakers
avatar for Deepthi Sigireddi

Deepthi Sigireddi

Engineering Lead, PlanetScale
Deepthi is the Technical lead for Vitess, a CNCF graduated open source project. She also leads the Vitess engineering team at PlanetScale which offers a database service built on Vitess. She brings over 20 years of experience building scalable systems to this role. She enjoys speaking... Read More →
avatar for Manan Gupta

Manan Gupta

Software Engineer, PlanetScale
Manan Gupta is a software engineer at PlanetScale, where he works on Vitess and focuses on cluster management, high-availability features, and query-serving. He is a maintainer of Vitess and has a passion for designing and implementing robust and scalable solutions that deliver high... Read More →
avatar for Florent Poinsard

Florent Poinsard

Software Engineer, PlanetScale
Florent has been working at PlanetScale as a software engineer for over two years. He is a maintainer of Vitess, an open-source cloud-native database. He spends most of his weekends traveling, taking photos, and snowboarding when weather allows it.
Monday June 16, 2025 12:10 - 12:40 JST
Level 1 | Appollon

12:10 JST

New Cache Hierarchy for Container Images and OCI Artifact in Kubernetes Clusters Using Containerd - Toru Komatsu & Hidehito Yabuuchi, Preferred Networks, Inc.
Monday June 16, 2025 12:10 - 12:40 JST
One of the key bottlenecks in Kubernetes pod startup is the time taken to pull container images and OCI artifacts. It’s also costly to fetch large container images from the registry often. To tackle this problem, we developed a cache system with the following features:

* New Cache Hierarchy: Images pulled by pods are shared across the entire cluster, enabling cluster-wide optimization, not only cluster-local cache.
* Ninja: Users experience faster container image pulls without any changes on their part. Just like a ninja, the system stealthily enhances performance.
* Preheating: It supports pushing images to preheat the cache for subsequent pulls.

Deployed in a production cluster, the cache system has achieved a cache hit rate of around 95%, significantly reducing pod startup times and network communication with registries. Attendees will learn practical insights into leveraging cache and CRI to optimize image and OCI artifact pulls, ultimately enhancing cluster efficiency.
Speakers
avatar for Toru Komatsu

Toru Komatsu

Software Engineer, Preferred Networks, Inc.
Toru is the creator and lead developer of one of the CNCF Projects, Youki, an OCI runtime written in Rust. He is also a maintainer of the OCI Runtime Specification. Additionally, he is a member of Kubernetes and containerd and serves as a reviewer for runwasi. Toru is involved in... Read More →
avatar for Hidehito Yabuuchi

Hidehito Yabuuchi

Software Engineer, Preferred Networks, Inc.
Hidehito Yabuuchi is a Software Engineer at Preferred Networks, Inc. He has worked on on-premises Kubernetes clusters primarily for ML and HPC. His main interests are Kubernetes schedulers, container image registries, cooperation with public clouds, among others. He also has led the... Read More →
Monday June 16, 2025 12:10 - 12:40 JST
Level 1 | Pegasus Ballroom B2+C
  Operations + Performance

12:40 JST

Lunch 🍱
Monday June 16, 2025 12:40 - 14:10 JST
TBA
Monday June 16, 2025 12:40 - 14:10 JST
TBA

14:10 JST

⚡ Lightning Talk: Embracing Culture and Breaking Language Barriers: A Story of Fostering Global Opensource Communities - Sreeram Venkitesh, DigitalOcean
Monday June 16, 2025 14:10 - 14:15 JST
Open source communities are a celebration of our different cultures. The single reason open source communities are able to build and ship software like Kubernetes, which is used so widely, is because of the collaboration of people from all around the globe.

This also means a lot of challenges when people are working together, like language barriers, cultural differences and timezones. In this talk I'll be sharing some lessons I've learnt about fostering open source communities amidst the differences. In the last two years, serving in the K8s release team and as the SIG Docs New Contributor Ambassador, I've experienced first hand how challenges like language barriers can hinder enthusiastic contributors. This talk is about these different challenges and how we can overcome them.

In an effort to inspire everyone in the open source community to embrace our differences and welcome everyone as we work together, I'm learning Nihongo to attempt giving this talk in the Japanese language.
Speakers
avatar for Sreeram Venkitesh

Sreeram Venkitesh

Senior Software Engineer, DigitalOcean
Sreeram is a contributor to the Kubernetes project who is primarily active in SIG Release, SIG Contribex Comms and SIG Node. He was part of the Kubernetes release team from v1.29 to v1.32 and was the Enhancements sub-team lead for Kubernetes v1.31. He is also the subproject lead for... Read More →
Monday June 16, 2025 14:10 - 14:15 JST
Level 1 | Orion
  ⚡ Lightning Talks, Cloud Native Experience
  • Content Experience Level Any
  • Presentation Language Japanese

14:10 JST

Access AI Models Anywhere: Scaling AI Traffic With Envoy AI Gateway - Dan Sun, Bloomberg & Takeshi Yoneda, Tetrate.io
Monday June 16, 2025 14:10 - 14:40 JST
As Generative AI adoption increases, organizations face accelerating challenges in deploying, scaling, and managing access to diverse AI models across cloud and on-prem environments. Envoy AI Gateway utilizes Envoy Proxy’s powerful filter architecture and extensibility through ext-proc to deliver key features such as centralized credential management, intelligent model routing, and LLM token usage control.
As the first CNCF-backed open source AI gateway, Envoy AI Gateway is built on top of a robust, high performance Envoy Gateway to help democratize AI infrastructure for organizations of all sizes.

In this talk, we will dive into the architecture of Envoy AI Gateway to learn how it extends Envoy’s capabilities to efficiently manage AI-driven workloads for enterprise needs, while providing robustness, scalability, and adaptability in the rapidly-changing generative AI landscape. We will also showcase a demo of an AI agent seamlessly accessing models anywhere through a unified API.
Speakers
avatar for Dan Sun

Dan Sun

Team Lead, Bloomberg
Dan Sun is a software engineer team lead at Bloomberg. He is the co-founder and maintainer of KServe, an open source Serverless AI inference platform project. He is a co-founder of the Envoy AI Gateway project.
avatar for Takeshi Yoneda

Takeshi Yoneda

Open Source Software Engineer, Tetrate.io
Takeshi Yoneda is a software engineer at Tetrate.io, with contributions to numerous open source projects, including compilers and network proxies. He is a co-founder of the Envoy AI Gateway project.
Monday June 16, 2025 14:10 - 14:40 JST
Level 1 | Pegasus Ballroom A+B1
  AI + ML
  • Content Experience Level Any
  • Presentation Language English

14:10 JST

KubeVirt Community: Let's Talk Multiarch Support! - Andrew Burden, Red Hat & Howard Zhang, Arm
Monday June 16, 2025 14:10 - 14:40 JST
Last year we formalised two architecture Working Groups: S390x and ARM. Come and hear about how these important works are going from one of the WG chairs. You'll learn about ARM's plan for CDI support, IBM's contributions to run CDI on s390x architecture, and the KubeVirt community's progress in supporting CDI in multi-arch cluster environments.

We'll also provide a short community update about how these working groups are part of the KubeVirt community formalising its SIG structure, itself part of a larger maturation process that started with slowing our release cadence and also encapsulates changes to our design proposal (VEPs) process, feature prioritization, and our governance.
Speakers
avatar for Andrew Burden

Andrew Burden

Community Facilitator, Red Hat
I am a community facilitator for KubeVirt, a Cloud Native Computing Foundation incubating project that extends the Kubernetes API to provide for virtualization workloads to run natively alongside container workloads. You can learn more at kubevirt.io, and find all the community... Read More →
avatar for Howard Zhang

Howard Zhang

Staff Software Engineer, Arm
focus on container, K8S, virtulization on ARM64
Monday June 16, 2025 14:10 - 14:40 JST
Level 1 | Appollon

14:10 JST

No More Disruption: PlayStation Network’s Approaches To Avoid Outages on Kubernetes Platform - Tomoyuki Ehira & Shuhei Nagata, Sony Interactive Entertainment
Monday June 16, 2025 14:10 - 14:40 JST
At PlayStation Network, our Kubernetes platform with 50+ clusters handles massive amounts of user traffic every day, and the platform team consists of engineers in several global locations with different technological and cultural backgrounds.
Despite such scale and organizational complexity, we achieved remarkable stability in FY2024 so far, maintaining a notable 99.995% uptime for our platform.
In this session, we will share the key practices behind this success, including a controlled deployment strategy, robust scaling techniques, minimized manual intervention, and 24/7 operations spanning global regions. While these approaches may not be special individually, their consistent and disciplined application has been the foundation of our platform's stability.
Those who strive to achieve stable platform operation and organizations looking to expand or consolidate their platforms will leave with actionable strategies to enhance the reliability of their platform.
Speakers
avatar for Shuhei Nagata

Shuhei Nagata

Engineering Manager, Sony Interactive Entertainment
I'm an engineering manager at Sony Interactive Entertainment. I joined in 2017 and led a team that provided CI/CD pipelines and ECS infrastructure for PlayStation Network developers on the Japan site. Since 2021, I have been part of the global Internal Developer Platform team, leading... Read More →
avatar for Tomoyuki Ehira

Tomoyuki Ehira

Software Engineer, Sony Interactive Entertainment
I am a Software Engineer at Sony Interactive Entertainment, where I develop and operate the Kubernetes-based application platform for PlayStation Network. Although I am in my first year as a professional, my passion for Kubernetes and cloud-native technologies began during my student... Read More →
Monday June 16, 2025 14:10 - 14:40 JST
Level 1 | Pegasus Ballroom B2+C
  Operations + Performance

14:17 JST

⚡ Lightning Talk: Enhanced Service Redirection: eBPF Ensures the High Availability of Node-Local DNS - Weizhou Lan, Daocloud
Monday June 16, 2025 14:17 - 14:22 JST
Excessive DNS query pressure can cause CoreDNS failures, leading to a cluster-wide meltdown. Thus, per-pod or per-node DNS proxy is a common high-availability solution. By binding the clusterIP of the kube-dns service to the local node, node-local DNS can provide seamless DNS interception and proxying, meeting the demands of low latency and high throughput. However, proxy's breakdown can directly lead to access failures, lacking high availability.
To solve this issue, we use cgroup eBPF to implement enhanced service redirection for node-local DNS, inspired by Cilium's LocalRedirectPolicy. Based on the health status of the local proxy or the redirection QoS strategy, the query of the kube-dns service can be dynamically resolved to the local node-local DNS, otherwise normally forwarded to CoreDNS. This scheme is independent of the CNI, and could cooperate with kube-proxy, offer multiple service redirection strategies and provide production-grade quality assurance for node-local DNS.
Speakers
avatar for Weizhou Lan

Weizhou Lan

Senior Teach Leader, Daocloud
I currently serve as a Senior Tech Lead at DaoCloud, with over 14 years of engineering experience. I have had the experience of being a speaker at KubeCon three times. I am the initiator and maintainer of the CNCF sandbox project Spiderpool, and an active community member of Cilium... Read More →
Monday June 16, 2025 14:17 - 14:22 JST
Level 1 | Orion
  ⚡ Lightning Talks, Connectivity

14:24 JST

⚡ Lightning Talk: From Kernel To Kubernetes: Mapping eBPF-Detected Processes To Pods - Yuki Nakamura, mapbox
Monday June 16, 2025 14:24 - 14:29 JST
When a process like /usr/bin/curl runs in a pod (e.g., xwing in the default namespace), Tetragon detects it like bellow:

```
🚀 process default/xwing /bin/bash -c "curl https://ebpf.io/applications/#tetragon"
🚀 process default/xwing /usr/bin/curl https://ebpf.io/applications/#tetragon
💥 exit default/xwing /usr/bin/curl https://ebpf.io/applications/#tetragon 60
```

But how does it map that process to its pod?

This Lightning Talk explores how Tetragon connects the Linux kernel to Kubernetes by enriching eBPF-detected process data with Kubernetes metadata. I’ll break down how it extracts cgroup information from task_struct in kernel space and maps it to pod details using the Kubernetes API.
Speakers
avatar for Yuki Nakamura

Yuki Nakamura

Platform Engeneer, mapbox
- Master’s degree in Computer Science at the University of Tokyo - IBM - Mapbox Blog: https://yuki-nakamura.com/
Monday June 16, 2025 14:24 - 14:29 JST
Level 1 | Orion
  ⚡ Lightning Talks, Security

14:31 JST

⚡ Lightning Talk: Optimizing Web Applications by Offloading Heavy Processing To Kubernetes Jobs - Asami Okina, Craftsman Software, Inc.
Monday June 16, 2025 14:31 - 14:36 JST
While typical web applications do not require large amounts of resources constantly, there are cases where specific processes consume significant CPU and memory.
In this session, we will introduce an architecture that offloads such resource-intensive processes to Kubernetes Jobs.
We will explain specific methods for Job management, how to integrate web applications (Next.js, @kubernetes/client-node) with the Kubernetes API, methods for data integration between Jobs and web applications, and real-time tracking of Job progress in the UI, all while sharing practical examples. Furthermore, we will provide a detailed introduction to a pattern where Kubernetes Job definitions generated from applications are managed using ConfigMaps, enabling quick configuration switching between environments, and offer hints to optimize your applications in terms of cost, performance, and management.
Speakers
avatar for Asami Okina

Asami Okina

Software Engineer, Craftsman Software, Inc.
Focuses on cloud-native application development and operations centered on Kubernetes, holding CKAD and CKA certifications. Specializes in automation using GitHub Actions and loves reducing tedious work. Has expertise in designing and operating systems combining Web Application... Read More →
Monday June 16, 2025 14:31 - 14:36 JST
Level 1 | Orion
  ⚡ Lightning Talks, Application Development

14:38 JST

⚡ Lightning Talk: Practical Monitoring for Knative Serving - Kazuki Higashiguchi, Autify
Monday June 16, 2025 14:38 - 14:43 JST
Knative is a widely adopted CNCF-hosted software for running serverless applications using Kubernetes. Knative Serving consists of many system components, such as Activator, Autoscaler, Controller, Webhook, and Istio or Kourier as an ingress gateway. Therefore, end users need to implement monitors for common error patterns and best metrics from many metrics. However, there is relatively little knowledge and resources for Knative end users.

This talk will present a production case study of monitoring for Knative Service. Specifically, it will explain how we can monitor Knative control plane efficiency, reconciliation operations, pod scaling health, concurrency observation, HTTP request success rate, and more.
That includes how Knative components implement Prometheus metrics, metrics pipelines (on Google Kubernetes Engine), dashboards and alerts.

This case study will benefit existing Knative users and potential users considering employing Knative in their Kubernetes clusters.
Speakers
avatar for Kazuki Higashiguchi

Kazuki Higashiguchi

Senior Site Reliability Engineer, Autify
Kazuki Higashiguchi has more than 9 years of industrial experience, focusing on SRE and operational excellence. He is a Senior Site Reliability Engineer at Autify, a company serving AI-powered quality assurance platforms. He is mainly responsible for designing business infrastructure... Read More →
Monday June 16, 2025 14:38 - 14:43 JST
Level 1 | Orion
  ⚡ Lightning Talks, Observability

14:45 JST

⚡ Lightning Talk: Providing Sufficient PVCs for Your StatefulSets: Creating New Volumes Larger Than the PVCTemplate - Kaoru Esashika, Cybozu, Inc.
Monday June 16, 2025 14:45 - 14:50 JST
Have you ever used automatic PVC resizing tools in Kubernetes? Have you ever encountered a situation where newly created PVCs remained at the small, template-defined size, causing capacity shortages during restores or clones?

To address this challenge, this session introduces a new approach in pvc-autoresizer, one of the tools for automatically resizing PVCs. By aligning newly created PVCs with the largest capacity in the same group, it ensures that PVCs have sufficient space right from creation time. Using annotations and a Mutating Webhook, we avoid capacity shortages during restores by provisioning enough volume capacity immediately after a PVC is generated. We will also explain why we chose a Webhook-based method over a Controller-based one, along with the design trade-offs involved.

Anyone seeking to enhance reliability for stateful workloads should not miss this session. Learn how a new PVC management strategy can deliver more stable Kubernetes storage.
Speakers
avatar for Kaoru Esashika

Kaoru Esashika

Software Engineer, Cybozu, Inc.
He works at Cybozu, Inc. For the past three years, he has focused on the operation and development of the storage area for a new infrastructure using Kubernetes. His work includes developing and operating distributed storage with Rook and Ceph, and own CSI plugin, TopoLVM.
Monday June 16, 2025 14:45 - 14:50 JST
Level 1 | Orion
  ⚡ Lightning Talks, Data Processing + Storage

14:50 JST

Zero-Extraction Cold Starts: How FUSE-Streaming Slashed ComfyUI Cold Starts by 10x - Fog Dong, BentoML
Monday June 16, 2025 14:50 - 15:20 JST
Cold-start delays for GPU-heavy GenAI apps like ComfyUI aren’t just about speed—they’re architectural failures. While others optimize incremental steps, we eliminate entire phases: no image downloads, no layer extraction, no redundant model copies.

We introduce a radical Kubernetes-native pattern: Direct-to-GPU streaming via FUSE-mounted object storage (S3/GCS), bypassing legacy container workflows. By rearchitecting the snapshotter to support seekable, on-demand FUSE streaming, we enable:

- Instant container boot: Models/CUDA dependencies mount directly from object storage, avoiding registry bottlenecks (40MB/s → 900MB/s throughput)
- Zero-extraction overhead: Layers load incrementally via range-optimized fetches, eliminating Zstd unpack/copy latency
- True cold start elimination: ComfyUI pods activate in 90s (vs. 8+ mins) by co-locating model mounting and inference prep

We’ll dissect a live ComfyUI deployment using 100% OSS primitives to hack container internals in the session.
Speakers
avatar for Fog Dong

Fog Dong

Senior Software Engineer, BentoML
Fog Dong, a Senior Engineer at BentoML, KubeVela maintainer, CNCF Ambassador, and LFAPAC Evangelist, has a rich background in cloud native and AI infra. Previously instrumental in developing Alibaba's large-scale Serverless workflows and Bytedance's cloud-native CI/CD platform, she... Read More →
Monday June 16, 2025 14:50 - 15:20 JST
Level 1 | Pegasus Ballroom A+B1
  AI + ML

14:50 JST

Kubernetes SIG Node Intro and Deep Dive - Sergey Kanzhelev & Narang Dixita Sohanlal, Google; Paco Xu, DaoCloud; Hironori Shiina, Independent
Monday June 16, 2025 14:50 - 15:20 JST
These are exciting times for Kubernetes SIG Node. Come to our maintainers‘ track session to learn about the just released version 1.34 of Kubernetes, full of exciting improvements, and get a glance into the SIG Node roadmap. SIG Node owns components that control interactions between pods and host resources, including the Kubelet, Container Runtime Interface (CRI), and Node API. SIG Node is responsible for the Pod’s lifecycle from allocation to teardown, to liveness checks and shared resource management. We work with the various container runtimes, kernels, networking, storage, and more; anything a pod touches is SIG Node’s responsibility!

We will make a deep dive into the area of pod lifecycle starting with developments like evented PLEG as well as well established things like probes and handling the resource management when pod scaling.

Join this session to learn more about our SIG, and how you might get involved to make Node even better!
Speakers
avatar for Sergey Kanzhelev

Sergey Kanzhelev

Staff Software Engineer, Google
Sergey Kanzhelev is a seasoned cloud native maintainer. Sergey a chair of Kubernetes SIG node and one of the approvers. He is a co-founder of OpenTelemetry. He is working on both - engineering aspect of software and its practical application. With the Kubernetes, he is contributing... Read More →
avatar for Paco Xu

Paco Xu

Lead of open source team., DaoCloud
Paco is co-chair of KubeCon+CloudNativeCon China 2024, and a member of Kubernetes Steering Committee. Paco is a kubeadm maintainer and an active kubernetes contributor. He is the leader of the open-source team in DaoCloud. He organized KCD Chengdu 2022 and KCS China 2023, and... Read More →
avatar for Narang Dixita Sohanlal

Narang Dixita Sohanlal

Software Engineer, Google
Dixita Narang is a Software Engineer at Google on the Kubernetes Node team. With a primary focus on resource management within Kubernetes, Dixita is deeply involved in the development and advancement of the Memory QoS feature, which is currently in the alpha stage. She is a new contributor... Read More →
avatar for Hironori Shiina

Hironori Shiina

Software Engineer, Independent
Hironori has been working on platform software as a developer and a support engineer for 15+ years. He has been contributing to OSS related to his work such as OpenStack, Podman, etc. for 10 years. He is currently contributing on Kubernetes as an independent engineer.
Monday June 16, 2025 14:50 - 15:20 JST
Level 1 | Appollon

14:50 JST

Streamlined Baremetal Deployment: A Journey of Custom Controllers Integrated With OpenStack - Mitsuhiro Tanino & Masanori Kuroha, LY Corporation
Monday June 16, 2025 14:50 - 15:20 JST
As LY Corporation transitioned to developing a new private cloud infrastructure, we confronted significant challenges in managing over 6,000 baremetal servers through Kubernetes integrated with OpenStack, resulting in increased complexity, extended deployment times, and excessive resource consumption.

This session delivers how our custom controllers enhanced our approach, automating complex configurations and addressing disruptions in ArgoCD and Ansible, Kubernetes resource shortages, and scalability constraints.

We will focus on:

- Challenges in Existing Baremetal Provisioning: Explore the operational complexities and inefficiencies caused by scale, including deployment delays.

- Implementation of Custom Controllers: How we automated configurations and leading to faster, more reliable deployments with Helm.

- Enhancements in Resource Management: Techniques that streamlined processes and enhanced OpenStack integration, ultimately boosting operational simplicity and efficiency.
Speakers
avatar for Mitsuhiro Tanino

Mitsuhiro Tanino

Senior software engineer, LY Corporation
Mitsuhiro Tanino is a senior software engineer who has been working for LY Corporation since 2019. He has experience to contribute OpenStack Cinder project for several years and also contributed Kubernetes sig-storage for several years. His current working area is operating hyper-scale... Read More →
avatar for Masanori Kuroha

Masanori Kuroha

Software Engineer, LY Corporation
Masanori Kuroha has been working as a Cloud Software Engineer at LY Corporation since 2021. He is responsible for managing private clusters using OpenStack and operating Kubernetes clusters on physical machines. Recently, he focuses on customizing OpenStack Nova for internal purposes... Read More →
Monday June 16, 2025 14:50 - 15:20 JST
Level 1 | Pegasus Ballroom B2+C
  Operations + Performance

14:52 JST

⚡ Lightning Talk: What's New in Prometheus-Operator? - Ashwin Sriram, IIT-BHU
Monday June 16, 2025 14:52 - 14:57 JST
Join us for an exciting overview of the latest developments in Prometheus-Operator! This lightning talk will explore game-changing features, including the new ScrapeClasses for simplified monitoring configuration, DaemonSet Mode in PrometheusAgent for enhanced deployment flexibility, and expanded Service Discovery support across multiple cloud providers.

We'll explore how these additions, along with our improved documentation and new Scale Subresource capabilities, are making Prometheus-Operator more powerful and user-friendly than ever. You'll also learn about "poctl", our new command-line tool that is designed to handle Prometheus-Operator custom resources.

Plus, get a sneak peek into our roadmap and upcoming features that will shape the future of Kubernetes monitoring. Perfect for anyone interested in Kubernetes monitoring, this talk will equip you with knowledge about the latest tools to enhance your observability stack.
Speakers
avatar for Ashwin Sriram

Ashwin Sriram

Student, IIT-BHU
I'm an engineering student in my final year at IIT-BHU, majoring in metallurgy, but my heart truly lies in software engineering. I'm a maintainer for the Prometheus-Operator website repository, a role I earned after completing my GSoC mentorship. Through this experience, I've developed... Read More →
Monday June 16, 2025 14:52 - 14:57 JST
Level 1 | Orion
  ⚡ Lightning Talks, Observability

14:59 JST

⚡ Lightning Talk: VexLLM: Silence Negligible CVE Alerts Using LLM - Akihiro Suda, NTT
Monday June 16, 2025 14:59 - 15:04 JST
When using container image vulnerability scanners like Trivy, a large number of vulnerabilities may be detected. However, not all of them necessarily require an action. This is because not all libraries or command-line tools included in the container image are actually utilized.

For example, the `python:3.12.4` image includes a `git` binary with the vulnerability CVE-2024-32002. This vulnerability does not need an immediate action if it is known that the Python application being run does not execute `git` commands.

VEX (Vulnerability-Exploitability eXchange) formats such as OpenVEX can be used to suppress such false alarms.
However, VEX is still not widely adopted due to the difficulty of manual analysis and classification of vulnerabilities.

This presentation introduces VexLLM, a tool that helps writing VEX by leveraging LLMs. VexLLM is available as a plugin for Trivy.

GitHub: https://github.com/AkihiroSuda/vexllm
Speakers
avatar for Akihiro Suda

Akihiro Suda

Software Engineer, NTT
Akihiro Suda is a software engineer at NTT Corporation. He has been a maintainer of Moby (dockerd), BuildKit, containerd, runc, etc. He is also a founder of nerdctl and Lima (CNCF project).
Monday June 16, 2025 14:59 - 15:04 JST
Level 1 | Orion
  ⚡ Lightning Talks, Security
  • Content Experience Level Any
  • Presentation Language English

15:20 JST

Coffee Break ☕
Monday June 16, 2025 15:20 - 15:50 JST
TBA
Monday June 16, 2025 15:20 - 15:50 JST
TBA

15:50 JST

Scaling AI Responsibly: Building Ethical, Sustainable, and Cloud Native AI Systems - Amita Sharma & Vincent Caldeira, Red Hat; Mohit Suman, Salesforce; Shamsher Ansari, Platform9; Anusha Hegde, Nirmata
Monday June 16, 2025 15:50 - 16:20 JST
Panel Discussion - As AI continues to reshape industries, organizations face mounting pressure to scale AI systems responsibly while addressing challenges in efficiency, sustainability, and trust. This panel convenes leading experts to discuss how cloud-native technologies and CNCF projects are paving the way for scalable, ethical, and resource-efficient AI. Attendees will gain actionable insights into optimizing AI workflows, reducing environmental impact, and ensuring transparency in AI decision-making. From leveraging open-source tools to implementing cost-effective and ethical AI practices, this session will equip you with the knowledge to build AI systems that are both innovative and responsible. Discover how to harness the power of cloud-native ecosystems to drive AI transformation without compromising on sustainability or trust.
AI/ML engineers and data scientists looking to scale AI systems in cloud-native environments.
Speakers
avatar for Amita Sharma

Amita Sharma

AI/ML Engineering Manager, Red Hat
Amita is an Engineering Manager at Red Hat, leading Kubeflow Training, Feature Store. With 20 years of industry experience, including 14 years at Red Hat, she has held various roles. She is an active open-source contributor. Since 2011, she has contributed to the Fedora Project and... Read More →
avatar for Vincent Caldeira

Vincent Caldeira

CTO APAC, Red Hat
Vincent Caldeira, CTO of Red Hat in APAC, is responsible for strategic partnerships and technology strategy. Named a top CTO in APAC in 2023, he has 20+ years in IT, excelling in technology transformation in finance. An authority in open source and cloud-native technologies, Vincent... Read More →
avatar for Shamsher Ansari

Shamsher Ansari

Technical Product Manager, Platform9
Shamsher Ansari is a Technical Product Manager at Platform9, driving cloud-native infrastructure and Kubernetes solutions. With extensive experience in cloud, edge computing, and open-source technologies, he focuses on delivering scalable and cost-efficient products. Previously, at... Read More →
avatar for Anusha Hegde

Anusha Hegde

Senior Technical Product Manager, Nirmata
Anusha Hegde is a Senior Technical Product Manager at Nirmata, focusing on cloud security, Kubernetes policy management, policy-as-code automation, and building AI-first products while analyzing AI’s impact on her product and customers. Previously, she was a Tech Lead at VMware... Read More →
avatar for Mohit Suman

Mohit Suman

Senior Product Manager, Salesforce
Mohit Suman is a Product Management Leader at Salesforce, driving AI Observability, MLOps, and AI App Dev. With 12+ years in product strategy, engineering, and architecture, he builds scalable solutions for developer productivity. A passionate advocate for open source and public speaking... Read More →
Monday June 16, 2025 15:50 - 16:20 JST
Level 1 | Pegasus Ballroom A+B1
  AI + ML

15:50 JST

The Grand Adventure of Production Apps: Build, Break, and Survive! ~ A Kawaii Manga Journey Through - Aoi Motomura, Independent
Monday June 16, 2025 15:50 - 16:20 JST
"I've started to understand the basics of Kubernetes, but when it comes to running it in production, I can't quite imagine what kind of issues might arise..."
To ease these concerns, this session will use original characters, illustrations, and animations in a “cute manga” style to visually demonstrate how production applications can break and how to troubleshoot them.
In our story, the main application as a character takes center stage as the hero, venturing out on a grand journey—only to be "suddenly attacked by a monster" at the most inopportune moment. By following this storyline, you will learn both how applications fail and how to fix them. Additionally, just as an adventurer equips better armor to prepare for future battles, we will explore common issues and explain how to prevent them from happening in the first place.
Join us on an exciting adventure in "manga-style troubleshooting" and gain the confidence to tackle production Kubernetes challenges head-on!
Speakers
avatar for Aoi Takahashi

Aoi Takahashi

Site Reliability Engineer
I am an SRE at a major technology company, specializing in ensuring the reliability, scalability, and performance of a large-scale online learning platform. My work focuses on monitoring, automation, and incident response to maintain high availability for a wide user base. I also... Read More →
Monday June 16, 2025 15:50 - 16:20 JST
Level 1 | Pegasus Ballroom B2+C
  Application Development

15:50 JST

Longhorn: Intro, Deep Dive and Q&A - David Ko, SUSE
Monday June 16, 2025 15:50 - 16:20 JST
Longhorn is a widely adopted cloud-native storage solution with hundreds of thousands of installations in community and production environments. It supports various volume and access modes, CoW snapshots for space efficiency, and seamless CSI integration. Designed for enterprise readiness, it also offers out-of-cluster incremental backups for disaster recovery.

This talk covers Longhorn’s architecture, key features, community adoption, recent updates, and roadmap. We’ll also explore the V2 Data Engine—its next-generation storage backend—leveraging NVMe and ublk for high performance. Live demos will showcase how Longhorn maximizes volume capacity and efficiency with this new engine.
Speakers
avatar for David Ko

David Ko

Engineering Director, SUSE
A hands-on engineering leader and architect with over 15 years of software development experience, specializing in Microservices, distributed system design, CI/CD, automation, DevOps, containers, WASM, container orchestration (Kubernetes, Mesos), cloud computing, cloud-native solutions... Read More →
Monday June 16, 2025 15:50 - 16:20 JST
Level 1 | Appollon

15:50 JST

Platform Engineering Day 2: Why Service Iterations Are the Crux of Developer Platforms - Puja Abbassi, Giant Swarm
Monday June 16, 2025 15:50 - 16:20 JST
Everyone is talking about platform engineering. You see smooth demos of golden paths and self-service platforms. However, there’s a significant area of challenges that is less talked about and thus often neglected when designing developer platforms.

In this talk, we’ll explore the often-overlooked day 2 challenges that platform teams face. We’ll dissect the area of day 2 into the many sub-areas and challenges they pose. Drawing on real-world experiences, including notable migrations that many in this community have faced, we'll shed light on the pain behind developer platforms and discuss solutions to these issues. Among others, we’ll delve into practical strategies for managing versioning and rollouts, and highlight the significant hurdles encountered, such as dependencies on end user teams or GitOps.

Join us for insights, strategies, and stories from the trenches that will help you navigate the complexities of service iteration in developer platforms.
Speakers
avatar for Puja Abbassi

Puja Abbassi

VP Product, Giant Swarm
Puja Abbassi is the Vice President of Product at Giant Swarm, building a managed cloud native developer platform based on Kubernetes. In Kubernetes he focuses on extending Kubernetes with custom resources and controllers. With many years of Kubernetes experience and having been in... Read More →
Monday June 16, 2025 15:50 - 16:20 JST
Level 1 | Orion
  Platform Engineering
  • Content Experience Level Any
  • Presentation Language English

16:30 JST

Optimizing Data Locality and GPU Utilization for Training Workloads in Kubernetes - Haoyuan Li, Alluxio
Monday June 16, 2025 16:30 - 17:00 JST
As organizations scale their model training workloads in cloud-native environments, they face significant data processing and storage challenges: managing massive training datasets across distributed storage systems while ensuring optimal I/O performance. While Kubernetes excels at compute orchestration, the increasing distribution of data across multiple storage backends creates bottlenecks that impact training performance and infrastructure costs.

This presentation introduces a Kubernetes-native distributed caching system that utilizes NVMe storage to overcome data locality challenges. Haoyuan Li will also share real-world, large-scale production use cases to show how this architecture lowers data infrastructure costs, increases GPU utilization, and enables workload portability to navigate GPU scarcity challenges.
Speakers
avatar for Haoyuan Li

Haoyuan Li

Founder and CEO, Alluxio
Haoyuan Li is the Founder and CEO of Alluxio. He graduated with a Computer Science Ph.D. from the AMPLab at UC Berkeley. At the AMPLab, he co-created and led Alluxio (formerly Tachyon), an open-source virtual distributed file system. Before UC Berkeley, he got a M.S. from Cornell... Read More →
Monday June 16, 2025 16:30 - 17:00 JST
Level 1 | Pegasus Ballroom A+B1
  Data Processing + Storage

16:30 JST

Breaking Limits: Highly-Isolated and Low-Overhead Wasm Container - Soichiro Ueda, Kyoto University & Ai Nozaki, The University of Tokyo
Monday June 16, 2025 16:30 - 17:00 JST
Wasm is touted as the next generation of containers, offering a smaller, more secure, and more portable application format. However, challenges remain, particularly in achieving enough isolation for public clouds where multi-tenancy exists. This is because Wasm shares the host kernel between workloads like containers. To take full advantage of Wasm, there is still insufficient discussion on this problem.

To address the issue, we've developed a new Wasm runtime, Mewz. It runs a single Wasm module within a dedicated VM while also having a lightweight and specialized kernel (unikernel). This revolutionary execution model enables more secure and low-overhead Wasm containers. We've open-sourced the implementation, and Mewz is listed in the CNCF cloud native landscape! In this session, we'll explain the architecture of Mewz and why it's more isolated and low-overhead than ordinary Wasm runtimes. Building on this presentation, let’s discuss the future of cloud workloads powered by Wasm!
Speakers
avatar for Ai Nozaki

Ai Nozaki

Master Student, The University of Tokyo
Ai Nozaki is a Master's student at The University of Tokyo. She is a member of Mewz project. Her interest lies in WebAssembly, systems softwares and GPUs.
avatar for Soichiro Ueda

Soichiro Ueda

Student, Kyoto University
Master's Student in Computer Science at Kyoto University. Working on the Mewz project. Love cloud-native technologies and system software.
Monday June 16, 2025 16:30 - 17:00 JST
Level 1 | Pegasus Ballroom B2+C
  Emerging + Advanced

16:30 JST

Prometheus 3.0 and the New Governance: Setting the Project up for the Next Decade - Goutham Veeramachaneni, Grafana Labs
Monday June 16, 2025 16:30 - 17:00 JST
Prometheus joined the CNCF as its second project in 2016, nearly a decade ago. Ever since, Prometheus has the cloud native default for monitoring, and everyone using Kubernetes successfully is using Prometheus in some way or form.

We will give a short intro to Prometheus, it's strengths and top usecases.

We will also dive into the Prometheus 3.0 release, the new governance structure, and the roadmap for the next year. We will share how you can get involved and become a maintainer yourself.

We will also have a dedicated Q&A with the Prometheus maintainers.
Speakers
avatar for Goutham Veeramachaneni

Goutham Veeramachaneni

Product Manager / Engineer, Grafana Labs
Goutham is a Prometheus maintainer with experience maintaining the TSDB. After spending many years helping build and run the hosted Prometheus service at Grafana, he recently transitioned to PM, managing the Application Observability and OpenTelemetry products. He still hasn't lost... Read More →
Monday June 16, 2025 16:30 - 17:00 JST
Level 1 | Appollon

16:30 JST

Exploring Tenant-centric Strategies To Simplify Multi-cluster and Multi-cloud Complexities - Wei Huang & Fan Yang, Apple
Monday June 16, 2025 16:30 - 17:00 JST
Kubernetes is widely recognized as a platform for building platforms, but even with modern platform engineering techniques, managing an end-to-end release and deployment lifecycle remains challenging.

This talk will first analyze key pain points in platform engineering and propose a new perspective on infrastructure code by separating different personas’ views. We advocate for a tenant-centric API that prioritizes user experience—minimizing input, reducing learning curves, and abstracting cloud provider details to decouple desired resources from underlying specs.

Next, we’ll introduce a design for fanning out tenant resource claims, enhancing flexibility and extensibility through a code generation component and a Kubernetes-like labeling system. Finally, we’ll cover the glue that binds everything together: Pkl for templating and validation, Prow for GitHub event-driven automation, and Crossplane + ArgoCD as the claim realization engine.

Speakers
avatar for Wei Huang

Wei Huang

Software Engineer, Apple
Wei Huang is a Software Engineer at Apple, focusing on Kube scheduling and control plane. He has served as a co-chair of Kubernetes SIG-Scheduling for years. He is also the founder of two Kubernetes sub-projects, scheduler-plugins, and kwok.
avatar for Fan Yang

Fan Yang

Software Engineer, Apple Inc.
Software engineer at Apple
Monday June 16, 2025 16:30 - 17:00 JST
Level 1 | Orion
  Platform Engineering

17:10 JST

2-Node Kubernetes: A Reliable and Compatible Solution - Xin Zhang & Guang Hu, Microsoft
Monday June 16, 2025 17:10 - 17:40 JST
High availability in Kubernetes typically requires a 3-node setup to support etcd's Raft algorithm. But what if you could achieve HA with only 2 nodes, slashing infrastructure costs by over 30% without sacrificing reliability? This is a game-changer, especially for deployments in retail and manufacturing scaling across hundreds or thousands of locations.
Join us to explore a groundbreaking 2-node HA Kubernetes solution, built by evolving the Raft algorithm for etcd. Unlike alternatives that compromise on compatibility, our approach delivers etcd-based HA, which can tolerate both node failures and network partitioning like a traditional 3-node cluster. You can seamlessly transit between 3-node and 2-node cluster utilizing standard tools like kubeadm or CAPI. This approach requires only a simple shared storage witness.
In this session, we will unpack the mechanics of this innovation, demonstrate 2-node cluster provisioning, and showcase its resilience under real-world failure scenarios.
Speakers
avatar for Guang Hu

Guang Hu

Principal Product Manager, Microsoft
Guang Hu is a Principal Program Manager at Microsoft, where they lead strategic initiatives to enhance digital transformation and customer engagement. Guang has been instrumental in driving and contributing in bring Kubernetes for edge scenarios that leverage cloud-native solutions... Read More →
avatar for Xin Zhang

Xin Zhang

Principal Software Engineer, Microsoft
Joshua is a Principal Software Engineer at Microsoft, working on cutting-edge edge computing solutions. With over a decade of experience in Azure hybrid cloud services, he’s passionate about designing, implementing, and optimizing core algorithms to bring powerful capabilities to... Read More →
Monday June 16, 2025 17:10 - 17:40 JST
Level 1 | Pegasus Ballroom B2+C
  Emerging + Advanced
  • Content Experience Level Any
  • Presentation Language English

17:10 JST

Standardizing on Multi-Cluster App Topologies for Platforms With Linkerd - William Rizzo, Mirantis
Monday June 16, 2025 17:10 - 17:40 JST
As organizations scale their Kubernetes adoption, multi-cluster architectures are becoming the backbone of resilience, scalability, and compliance. However, building a unified developer experience across these clusters while abstracting operational complexities is a significant challenge.
In this session we’ll demonstrate how Cluster-API (CAPI), a declarative tool for Kubernetes lifecycle management and Linkerd, the powerful yet lightweight service mesh, can work together to simplify multi-cluster topologies for Internal Developer Platforms (IDP). By combining CAPI's robust cluster management with Linkerd’s seamless cross-cluster service communication, platform teams can deliver a streamlined and intuitive experience for developers, enabling them to focus on building and deploying applications without worrying about underlying infrastructure.
Speakers
avatar for William Rizzo

William Rizzo

Consulting Architect, Mirantis
William is a CNCF and Linkerd Ambassador, working at Mirantis as a Consulting Architect. He’s focused in helping customers designing, building, and running Developer Platform and Edge systems. He wore many hats, Engineering, Product Owner and Consulting. from HPC, Storage to Distributed... Read More →
Monday June 16, 2025 17:10 - 17:40 JST
Level 1 | Orion
  Platform Engineering

17:10 JST

Addons Need Love Too: Maintaining Addons for Better Cluster Security - Stevie Caldwell & Andy Suderman, Fairwinds
Monday June 16, 2025 17:10 - 17:40 JST
Projects both within and outside of the CNCF ecosystem provide additional capabilities for Kubernetes clusters. These "addons" become integral to the functioning of our clusters, but we don't often talk about their impact as a whole or managing them holistically as first-class citizens.

We know there are barriers to keeping things like addons up-to-date and that it can be difficult to get buy-in for allocating the time and resources for updating something that is working just fine (for now), especially if you’re multiple major versions behind. In this session we will help you understand and articulate the benefits of catching up and keeping addons updated and how to be proactive moving forward. You will walk away with some tools and strategies for navigating the complexity of the addon ecosystem and make the process as painless as possible. You will be able to create an action plan for improving the stability and security of your clusters and share that with stakeholders.
Speakers
avatar for Stevie Caldwell

Stevie Caldwell

Senior Tech Lead, Fairwinds
Stevie Caldwell is a Senior Site Reliability Engineering Technical Lead at Fairwinds. Stevie also participates in the R&D arm of Fairwinds where she contributes to Fairwinds’s open source projects. She has worked with Kubernetes for 6+ years, has presented at a number of webinars... Read More →
avatar for Andy Suderman

Andy Suderman

CTO, Fairwinds
Andy Suderman is CTO at Fairwinds, a managed Kubernetes-as-a-Service provider. Andy has worked with cloud native technologies for the last eight years helping organizations adopt and manage Kubernetes. Andy is the creator and primary developer of Goldilocks—an open source tool that... Read More →
Monday June 16, 2025 17:10 - 17:40 JST
Level 1 | Pegasus Ballroom A+B1
  Security

17:15 JST

Sailing Multi-host Inference for LLM on Kubernetes - Kante Yin, DaoCloud
Monday June 16, 2025 17:15 - 17:40 JST
Inference workloads are becoming increasingly prevalent and vital in Cloud Native world. However, it's not easy, one of the biggest challenges is large foundation model can not fit into a single node, such as llama3.1-405B or DeepSeek R1, which brings out the distributed inference with model parallelism, again, make serving inference workloads more complicated.

LeaderWorkerSet, aka. LWS, is a dedicated multi-host inference project aims to solve this problem, it's a project under the guidance of Kubernetes SIG-Apps and Serving Working Group. It offers a couple of features like dual-template for different types of Pods, fine-gained rolling update strategies, topology managements and all-or-nothing failure handlings.

What's more, vLLM, an inference engine, renowned for its performance and easy-to-use, has gained widespread popularity. In this presentation, we'll show you how to use LWS to deploy distributed inference with vLLM on Kubernetes.
Speakers
avatar for Kante Yin

Kante Yin

Software Engineer, DaoCloud
Kante is a senior software engineer and an open source enthusiast from DaoCloud, his work is mostly around scheduling, resource management and LLM inference. He actively contributes to upstream Kubernetes as SIG-Scheduling Maintainer and helps in incubating several projects like Kueue... Read More →
Monday June 16, 2025 17:15 - 17:40 JST
Level 1 | Appollon

17:45 JST

Welcome Reception 🎉
Monday June 16, 2025 17:45 - 19:15 JST
TBA
Join us onsite for drinks, appetizers, and conversations with old and new friends in the Solutions Showcase. Explore the exhibit booths to learn more about the latest technologies, browse special offers and job posts, and much more.

In order to facilitate networking and business relationships at the event, you may choose to visit a third party’s booth or to access sponsored content. You are never required to visit third-party booths or to access sponsored content. When visiting a booth or participating in sponsored activities, the third party will receive some of your registration data. This data includes your first name, last name, title, company, address, email, standard demographics questions (i.e. job function, industry), and details about the sponsored content or resources you interacted with. If you choose to interact with a booth or access sponsored content, you are explicitly consenting to receipt and use of such data by the third-party recipients, which will be subject to their own privacy policies.
Monday June 16, 2025 17:45 - 19:15 JST
TBA
 
Tuesday, June 17
 

08:00 JST

Badge Pick-Up
Tuesday June 17, 2025 08:00 - 16:30 JST
Tuesday June 17, 2025 08:00 - 16:30 JST
Foyer

09:30 JST

Keynote: Welcome Back + Opening Remarks
Tuesday June 17, 2025 09:30 - 09:35 JST
Tuesday June 17, 2025 09:30 - 09:35 JST
Level 1 | Pegasus Ballroom
  Keynote Sessions
  • Content Experience Level Any
  • Presentation Language English

09:37 JST

Keynote: KubeEdge Graduation Journey: Creating a Diverse and Collaborative Open Source Community From Scratch - Yue Bao, Huawei Cloud Computing Technology Co., Ltd. & Hongbing Zhang, DaoCloud
Tuesday June 17, 2025 09:37 - 09:47 JST
Recently,the health of open-source projects,particularly,vendor diversity and neutrality,has become a key topic of discussion. Many projects have faced challenges due to a lack of vendor diversity,threatening their sustainability. It is increasingly clear that setting up the right governance structure and project team during a project’s growth is critical.
KubeEdge,the industry's first cloud-native open-source edge computing project,has grown from its initial launch in 2018 to achieving CNCF graduation this year. Over the past few years, KubeEdge has evolved from a small project into a diverse, collaborative and multi-vendor community.
In this session, we will discuss the KubeEdge graduation journey, focusing on key strategies in technical planning, community governance, developer growth, and project maintenance that enabled its transformation into a thriving ecosystem. Join us to explore how to build a multi-vendor and diverse community, and how to expand into different industries.
Speakers
avatar for Yue Bao

Yue Bao

Senior Software Engineer, Huawei Cloud Computing Technology Co., Ltd.
Yue Bao serves as a software engineer of Huawei Cloud. She is now working 100% on open source, focusing on lightweight edge for KubeEdge. She is the maintainer of KubeEgde and also the tech leader of KubeEdge SIG Release and Node. Before that, Yue worked on Huawei Cloud Intelligent... Read More →
avatar for Hongbing Zhang

Hongbing Zhang

KubeEdge TSC Member, Chief Operating Officer, DaoCloud
Hongbing Zhang is Chief Operating Officer of DaoCloud. He is a veteran in open source areas, he founded IBM China Linux team in 2011 and organized team to make significant contributions in Linux Kernel/openstack/hadoop projects. Now he is focusing on cloud native domain and leading... Read More →
Tuesday June 17, 2025 09:37 - 09:47 JST
Level 1 | Pegasus Ballroom
  Keynote Sessions, Cloud Native Experience
  • Content Experience Level Any
  • Presentation Language English

09:55 JST

Keynote: Expanding Cloud Native Ecosystem From Japan - Yuichi Nakamura, Linux Foundation Japan Evangelist, Governing board of CNCF
Tuesday June 17, 2025 09:55 - 10:00 JST
Finally, the first KubeCon Japan is here, but it is an only start point. Japanese communities and companies are collaborating in CNCF Japan Chapter “Cloud Native Community Japan (CNCF)” to accelerate cloud native momentum in Japan and expand collaboration with other communities like FinOps Foundation and LF AI. In the talk, achievements of CNCJ since KubeDay Japan and forecast will be introduced.
Speakers
avatar for Yuichi Nakamura

Yuichi Nakamura

Head of OSPO, Hitachi,Ltd
Yuichi Nakamura, Ph.D has been engaged with OSS over 20 years, contributed to SELinux, given presentations in many OSS events such as Linux Security Summit, Embedded Linux Conference and KubeCon. He also launched ecosystem of business and OSS contribution model based on Keycloak in... Read More →
Tuesday June 17, 2025 09:55 - 10:00 JST
Level 1 | Pegasus Ballroom

10:14 JST

Keynote: To Be Announced - Sunyanan Choochotkaew, Staff Research Scientist, IBM Research
Tuesday June 17, 2025 10:14 - 10:24 JST
Speakers
avatar for Sunyanan Choochotkaew

Sunyanan Choochotkaew

Staff Research Scientist, IBM Research
Sunyanan Choochotkaew is a staff research scientist at IBM Research, specializing in distributed computing and performance acceleration on cloud platforms. She holds the role of maintainer of Kepler. She has made contributions to Environmental Sustainability TAG, operator framework... Read More →
Tuesday June 17, 2025 10:14 - 10:24 JST
Level 1 | Pegasus Ballroom

10:26 JST

Keynote: To Be Announced - Masaki Kimura, Engineer, Hitachi
Tuesday June 17, 2025 10:26 - 10:36 JST
Speakers
avatar for Masaki Kimura

Masaki Kimura

Engineer, Hitachi, Ltd.
Masaki Kimura is an OSS developer at Hitachi, Ltd. He has been working for improving Kubernetes. He is one of the main contributors to make raw block volume feature and CSI feature GA and CrossNamespaceVolumeDataSource feature alpha. He is an author of KEP-2839.
Tuesday June 17, 2025 10:26 - 10:36 JST
Level 1 | Pegasus Ballroom

10:36 JST

Keynote: Closing Remarks
Tuesday June 17, 2025 10:36 - 10:45 JST
Tuesday June 17, 2025 10:36 - 10:45 JST
Level 1 | Pegasus Ballroom
  Keynote Sessions
  • Content Experience Level Any
  • Presentation Language English

10:45 JST

Coffee Break ☕
Tuesday June 17, 2025 10:45 - 11:30 JST
TBA
Tuesday June 17, 2025 10:45 - 11:30 JST
TBA

10:45 JST

Solutions Showcase
Tuesday June 17, 2025 10:45 - 15:50 JST
TBA
Visit our sponsors in the Solutions Showcase to try the latest demos, watch live presentations, talk to experts, check out job opportunities, and score some swag.

In order to facilitate networking and business relationships at the event, you may choose to visit a third party’s booth or to access sponsored content. You are never required to visit third-party booths or to access sponsored content. When visiting a booth or participating in sponsored activities, the third party will receive some of your registration data. This data includes your first name, last name, title, company, address, email, standard demographics questions (i.e. job function, industry), and details about the sponsored content or resources you interacted with. If you choose to interact with a booth or access sponsored content, you are explicitly consenting to receipt and use of such data by the third-party recipients, which will be subject to their own privacy policies.
Tuesday June 17, 2025 10:45 - 15:50 JST
TBA

11:30 JST

Project Lightning Talks: Opening
Tuesday June 17, 2025 11:30 - 11:35 JST
Tuesday June 17, 2025 11:30 - 11:35 JST
Level 1 | Orion

11:30 JST

Should Our Project Join the CNCF? - Lenka Bočincová, Red Hat
Tuesday June 17, 2025 11:30 - 12:00 JST
Got an open source project? Considering submitting it to the CNCF (or another foundation)? Whether and when to do this is one of the biggest decisions you'll make in the life of your project. Joining a foundation changes things fundamentally, and whether or not this is a good decision is going to depend on where you are in your project's development and what your goals for the project currently are.

As a community architect in the Red Hat Open Source Program Office, I help projects with this decision. During this talk, I will share common things that projects need to consider before they make this important decision. I will also talk about common benefits and challenges that projects usually experience. After this talk you should have a better understanding of whether you should contribute the project to CNCF or not.
Speakers
avatar for Lenka Bocincova

Lenka Bocincova

Community architect, OSPO, Red Hat
I am a community architect at Red Hat, Open Source Program Office, where I work with open source projects related to Red Hat cloud native technologies and help them grow their communities. I enjoy a good cup of coffee and exploring cities on a bicycle :)
Tuesday June 17, 2025 11:30 - 12:00 JST
Level 1 | Pegasus Ballroom B2+C
  Cloud Native Experience

11:30 JST

Kubeflow Ecosystem: Unleash the Power of Cloud Native AI - Andrey Velichkevich, Apple & Yuki Iwai, CyberAgent, Inc
Tuesday June 17, 2025 11:30 - 12:00 JST
Since 2017, the Kubeflow community has embraced Kubernetes as the foundation technology for AI/ML workloads. Over the years, Kubeflow and Kubernetes communities have worked closely to make cloud native tools more accessible for AI/ML.

​​Today, Kubeflow ecosystem of projects covers entire AI/ML lifecycle - from data processing and feature engineering to large-scale LLM fine-tuning, optimization, and serving.

Its modular, microservice-based architecture gives organizations the flexibility to adopt specific tools or deploy the full Kubeflow distribution as a comprehensive ML platform.

In this session, speakers will share key updates from the latest Kubeflow 1.10 release, including new additions to the Kubeflow ecosystem, like Feast and community-driven initiatives to enhance the GenAI on Kubernetes with ML Experience working group, Kubeflow SDK, and LLM fine-tuning blueprints. Join us to see how the Kubeflow community continues to drive innovation in cloud native AI and LLMOps.
Speakers
avatar for Andrey Velichkevich

Andrey Velichkevich

Senior Software Engineer, Apple
Andrey Velichkevich is a Senior Software Engineer at Apple and is a key contributor to the Kubeflow open-source project. He is a member of Kubeflow Steering Committee and a co-chair of Kubeflow AutoML and Training WG. Additionally, Andrey is an active member of the CNCF WG AI. He... Read More →
avatar for Yuki Iwai

Yuki Iwai

Software Engineer, CyberAgent, Inc
Yuki is a Software Engineer at CyberAgent, Inc. He works on the internal platform for machine-learning applications and high-performance computing. He is currently a Technical Lead for Kubeflow WG AutoML / Training. He is also a Kubernetes WG Batch active member, Job API reviewer... Read More →
Tuesday June 17, 2025 11:30 - 12:00 JST
Level 1 | Appollon

11:30 JST

Multi Cluster Magics With Argo CD and Cluster Inventory or Don't Get Lost in the Clusterverse: Navig - Nick Eberts, Google
Tuesday June 17, 2025 11:30 - 12:00 JST
You probably have more than one cluster and there is a decent chance you are using Argo CD. Additionally, it is quite likely that you have a few other variations of Kubernetes cluster lists. We posit that writing glue code to stitch together these clusters lists is not an awesome use of your time. Thankfully the good folks in SIG-Multicluster built this super cool api for cluster lists, cluster profile/cluster inventory! We are going to show you how to use said fancy new list with Argo CD along with other multi-cluster tools across Kubernetes clusters hosted by different providers. There will be demos. Possibly Mustaches. And a decent amount of awful puns. So come on down to bear witness to some sweet multi-cluster abstractions that will surely get your heart rate up.
Speakers
avatar for Nick Eberts

Nick Eberts

Product Manager, Google
Nick is currently the product manager for GKE Fleets & Teams focusing on multi-cluster capabilities that streamline GCP customers experience while building platforms on GKE. He also is a Kubernetes contributor, participates in SIG-Multicluster, and has been part of the community since... Read More →
Tuesday June 17, 2025 11:30 - 12:00 JST
Level 1 | Pegasus Ballroom A+B1
  Platform Engineering

11:37 JST

Project Lightning Talk: Vitess: Unlimited Database Scalability - Deepthi Sigireddi, Technical Lead
Tuesday June 17, 2025 11:37 - 11:42 JST
Vitess is a massively scalable horizontal distributed database system built for MySQL. This session will provide a brief overview of the project followed by what makes Vitess so scalable. It will conclude with data and charts to demonstrate these scalability claims.
Tuesday June 17, 2025 11:37 - 11:42 JST
Level 1 | Orion

11:44 JST

Project Lightning Talk: Expanding your GitOps with New Pluggable PipeCD - Shinnosuke Sawada-Dazai, Maintainer
Tuesday June 17, 2025 11:44 - 11:49 JST
PipeCD offers a unified, intuitive interface for progressive delivery across diverse application platforms—whether you manage a single project or operate at an enterprise scale. As an open-source GitOps-style continuous delivery platform, it unlocks extensive pipeline customization through its new plugin architecture, with an alpha release planned before KubeCon Japan 2025. Developers can write custom plugins in Go, vastly expanding automation possibilities, from wrapping external tools like sqldef to personalizing notifications—well beyond official support.



We'll demonstrate how these user-defined capabilities enhance continuous delivery with plugin stages for tasks like validation steps, database migrations, or targeted Slack alerts. If you already use GitOps and want better ways to extend your pipelines, join us to see how PipeCD elevates automation and bridges the gap between standard deployments and specialized needs.
Tuesday June 17, 2025 11:44 - 11:49 JST
Level 1 | Orion

11:51 JST

Project Lightning Talk: OTel 2025: The Latest Milestones and What’s Next - Steve Flanders, Contributor
Tuesday June 17, 2025 11:51 - 11:56 JST
OpenTelemetry has transformed the observability landscape by moving beyond the traditional three pillars of traces, metrics, and logs. With these core components now stable, the project is expanding its reach to encompass even more facets of system monitoring and performance analysis. In this session, we will explore the latest advancements in OpenTelemetry, including the integration of profiling, which offers deeper insights into application performance by capturing detailed execution data. Additionally, we'll discuss the emerging concept of entities, which promises to provide a more holistic view of system components and their interactions. By expanding its capabilities, OpenTelemetry is not just enhancing the granularity and scope of observability but also setting the stage for more comprehensive and actionable insights. Join us to learn how these new developments can help you achieve unparalleled visibility into your systems and drive better operational outcomes.
Tuesday June 17, 2025 11:51 - 11:56 JST
Level 1 | Orion

11:58 JST

Project Lightning Talk: How Kubernetes Observes Containers: The Role of Container Runtime and cAdvisor in Metrics Collection - Ayato Tokubi, Maintainer
Tuesday June 17, 2025 11:58 - 12:03 JST
This presentation explores the internal mechanics of Kubernetes' metric collection system, focusing on how container runtime metrics are gathered and utilized to maintain Kubernetes. We will break down the roles of the Container Runtime and cAdvisor (Container Advisor) in collecting real-time resource usage data. Additionally, we will discuss current enhancement proposals related to metrics and explore the future of metric usage in Kubernetes.
Tuesday June 17, 2025 11:58 - 12:03 JST
Level 1 | Orion

12:05 JST

Project Lightning Talk: First Step to Open Source Contribution? 5 Tips I Learned from Mentorship - Suhyan Im, Contributor
Tuesday June 17, 2025 12:05 - 12:10 JST
Contributing to open source is a great opportunity to improve programming skills and collaborate with experts. However, taking the first step is not easy. This session will highlight 5 tips to help beginners navigate their open-source contribution journey. Suhyen graduated from the LitmusChaos Korean Mentorship Program, one of the many open-source programs where LitmusChaos, the CNCF incubating project, participates, and grew from a novice contributor to a project member. She will share tips learned through mentorship, including choosing a good starting project, getting faster code reviews, and more. Finally, with these tips, beginners can successfully complete the first step on their journey.
Tuesday June 17, 2025 12:05 - 12:10 JST
Level 1 | Orion

12:10 JST

Bridging Cultures: Kubernetes Upstream Training and Japan's Open Source Journey - Shu Muto & Ziyi Xie, NEC; Masahiro Kitamura, LY Corporation; Junya Okabe, University of Tsukuba; Masaki Kimura, Hitachi
Tuesday June 17, 2025 12:10 - 12:40 JST
This panel, featuring instructors from Kubernetes Upstream Training Japan, explores how this initiative has accelerated open-source involvement across the country since 2019. Our panelists will share personal stories, highlighting how the training lowers barriers, boosts motivation, and drives long-term community engagement. We’ll examine the current status of Japanese contributions to Kubernetes, discuss lessons learned from past participants, and propose strategies to strengthen future growth. Attendees can expect a candid conversation about nurturing collaboration, overcoming cultural and linguistic challenges, and fostering a thriving ecosystem. Whether you’re an aspiring contributor or a seasoned leader, join us to gain practical insights into cross-cultural community-building and discover the next chapter for cloud-native innovation in Japan.
Speakers
avatar for Masaki Kimura

Masaki Kimura

Engineer, Hitachi, Ltd.
Masaki Kimura is an OSS developer at Hitachi, Ltd. He has been working for improving Kubernetes. He is one of the main contributors to make raw block volume feature and CSI feature GA and CrossNamespaceVolumeDataSource feature alpha. He is an author of KEP-2839.
avatar for Masahiro Kitamura

Masahiro Kitamura

SRE, LY Corporation
Site Reliability Engineer at LY Corporation. Initiated and leading the Japanese localization team.
avatar for Shu Muto

Shu Muto

Open Source Strategy Professional, NEC Solution Innovators, Ltd.
Shu Muto is a maintainer for the Kubernetes Dashboard since Autumn 2019 and a chair for SIG UI. Previously, he contributed to the OpenStack Dashboard and its plugins as a core developer from 2015. Shu also develops WebRTC applications. He organizes Kubernetes Upstream Training Japan... Read More →
avatar for Ziyi Xie

Ziyi Xie

Software Engineer, NEC Solution Innovators, Ltd.
Xie Ziyi is an active contributor in the Kubernetes community, currently focusing on documentation and storage. She also serves as an instructor for new contributors at Kubernetes Upstream Training events in Japan. She has spoken at the Kubernetes Contributor Summit and KubeDay J... Read More →
avatar for Junya Okabe

Junya Okabe

Student, University of Tsukuba
Junya is passionate about cloud native technologies, especially Kubernetes, and is a professional in this field. He leads the localization of Kubernetes and CNCF documentation as a localization approver in SIG-Docs and a reviewer for several projects. Additionally, he is an active... Read More →
Tuesday June 17, 2025 12:10 - 12:40 JST
Level 1 | Pegasus Ballroom B2+C
  Cloud Native Experience
  • Content Experience Level Any
  • Presentation Language English

12:10 JST

WG-Batch Updates: What’s New and What Is Next? - Maciej Szulik, Defense Unicorns; Michał Woźniak, Google; Yuki Iwai, CyberAgent, Inc
Tuesday June 17, 2025 12:10 - 12:40 JST
Join WG Batch maintainers for an in-depth look at the latest improvements in the Kubernetes ecosystem for HPC, AI/ML, and large-scale data analytics.

Yuki and Michał will present Kueue, a Kubernetes subproject enabling multi-tenant workload scheduling and advanced resource management, highlighting the new enhancements such as Topology-Aware Scheduling, Multi-Cluster Job dispatching, and Fair Sharing. They will also share updates on the Kubernetes Job API, as well as the JobSet API which is going to be the foundation for the Kubeflow Trainer v2. Additionally they present the new CLI tools, kjob and kueuectl, to make it easier for ML researchers to iterate running their workloads using Kubernetes with Kueue.

The WG Batch was created in 2022 to address the rapidly growing need for the first-class support of batch workloads in Kubernetes. It unites experts from multiple SIGs and diverse communities with the objective to define roadmaps and to collaborate on designs and implementations.
Speakers
avatar for Maciej Szulik

Maciej Szulik

Staff Platform Engineer, Defense Unicorns
Maciej is a passionate developer with almost two decades of experience in many languages. Currently he's working on Kubernetes for Defense Unicorns. Whereas at night he is hacking on side projects with python. In his spare time he enjoys reading a good book or taking photos.
avatar for Michał Woźniak

Michał Woźniak

Mr, Google
Michał is a software engineer with background in computer science, a PhD in computational biology, and 5+ years of professional experience. In his current role he is focusing on enhancing the support for batch workloads in the Kubernetes ecosystem. Outside of work he enjoys playing... Read More →
avatar for Yuki Iwai

Yuki Iwai

Software Engineer, CyberAgent, Inc
Yuki is a Software Engineer at CyberAgent, Inc. He works on the internal platform for machine-learning applications and high-performance computing. He is currently a Technical Lead for Kubeflow WG AutoML / Training. He is also a Kubernetes WG Batch active member, Job API reviewer... Read More →
Tuesday June 17, 2025 12:10 - 12:40 JST
Level 1 | Appollon

12:10 JST

Cloud Native Scalability for Internal Developer Platforms - Hiroshi Hayakawa, LY Corporation
Tuesday June 17, 2025 12:10 - 12:40 JST
Platform Engineering enables developers to focus on business value-aligned tasks by providing internal developer platforms (IDPs) that automate non-essential tasks. Kubernetes is widely used as a foundation for IDPs thanks to its scalability and flexibility.

However, Kubernetes was designed as a general workload orchestrator, not a platform component. As a result, IDP builders must integrate additional Cloud Native technologies and customizations, which can create scalability bottlenecks. At LY Corporation, his team has developed a Kubernetes-based, multi-tenant IDP running over 140K pods, and they faced such scalability challenges.

In this session, he will discuss scalability bottlenecks faced in the IDP, including observability pipelines, access control, etc. He will also explore scaling strategies for IDPs and how they address real-world scalability issues. By the end of this session, you will gain deeper insights into scalability challenges from a platform builder’s perspective.
Speakers
avatar for Hiroshi Hayakawa

Hiroshi Hayakawa

Platform Engineer, LY Corporation
Hiroshi is a lead engineer for Kubernetes-based application platforms in LY Corporation's Private Cloud Division. The company operates numerous large-scale applications on its Kubernetes-based platform, and he excels in ensuring stable operations at scale on Kubernetes and driving... Read More →
Tuesday June 17, 2025 12:10 - 12:40 JST
Level 1 | Pegasus Ballroom A+B1
  Platform Engineering

12:12 JST

Project Lightning Talk: Intro to Kubernetes SIG ContribEx - Kaslin Fields, Co-chair
Tuesday June 17, 2025 12:12 - 12:17 JST
Kubernetes is the second largest open source project in the world, which means there's always work to do! To maintain and build on Kubernetes, contributors work together in focused groups called Special Interest Groups (SIGs). These groups align with important technically areas of the project like Networking, Node, Autoscaling,and more. But who makes sure those contributors have the tools and processes they need to do their work and grow their groups? Meet SIG Contributor Experience! Ever wonder how the Kubernetes project does things on GitHub, or how social media for the project is run? Come learn how you can contribute to make the Kubernetes community even more fun and welcoming by contributing to the Contributor Experience!
Tuesday June 17, 2025 12:12 - 12:17 JST
Level 1 | Orion

12:19 JST

Project Lightning Talk: Understanding Cilium's eBPF kube-proxy Replacement for High Performance Networking - Yusuke Suzuki
Tuesday June 17, 2025 12:19 - 12:24 JST
Kube-proxy is a networking component in Kubernetes that manages network rules to facilitate communication between services and pods across nodes in a cluster. It relies on iptables or IPVS for L3/L4 load balancing, which can become a performance bottleneck in large scale Kubernetes clusters.



Cilium offers a high-performance, scalable alternative by leveraging eBPF to replace kube-proxy entirely. This talk provides an overview of how Cilium's datapath implements ClusterIP, NodePort, and LoadBalancer services using eBPF. By the end of the talk, the audience will understand the core principles behind Cilium's eBPF-based service handling and gain the fundamental knowledge needed to apply it in production environments.
Tuesday June 17, 2025 12:19 - 12:24 JST
Level 1 | Orion

12:26 JST

Project Lightning Talk: Open Cluster Management turns 1.0.0 - Hip Hip Hooray! - August Simonelli, Supporter
Tuesday June 17, 2025 12:26 - 12:31 JST
Open Cluster Management supports SIG-Multicluster API’s and concepts whilst sprinkling in additional enhancements for managing real world multicluster and multicloud use cases..



Today’s talk will cover the recent 1.0.0 release and some of the key areas we are evolving OCM and multicluster:



- Multicluster hits prime time: why it was time for 1.0.0!

- Multicluster your AI: how OCM is supporting the future of workloads!

- Upcoming planned integrations with other platforms

- Real world implementation update: who’s using OCM today.

- Lightning roadmap: what’s coming next in 30 seconds!
Tuesday June 17, 2025 12:26 - 12:31 JST
Level 1 | Orion

12:33 JST

Project Lightning Talk: Visual and Collaborative Management of Kubernetes Resources and Apps Using Meshery - Sangram Rath, Maintainer
Tuesday June 17, 2025 12:33 - 12:38 JST
Modern infrastructures based on cloud-native platforms such as Kubernetes can become increasingly complex with many components, resources, and customizations, requiring engineers to handle intricate relationships and configurations across them. The complexity increases when they have to write and manage these infrastructures definitions, relationships and configurations using YAML.



Meshery, an open-source cloud-native manager, provides an intuitive visual interface called Kanvas, that allows platform engineers and developers to collaboratively design, deploy and manage Kubernetes resources and apps without writing YAML.



Join this lighting talk to see how Meshery makes Kubernetes more accessible, empowering users to visualize and manage complex relationships with ease.
Tuesday June 17, 2025 12:33 - 12:38 JST
Level 1 | Orion

12:40 JST

Project Lightning Talk: WasmEdge: Cross-platform, Lightweight, Embeddable Multi-modal LLM Runtime - Michael Yuan, Contributor
Tuesday June 17, 2025 12:40 - 12:45 JST
As large language model (LLM) applications continue to grow in popularity, the need to efficiently run and scale AI workloads across cloud and edge devices is becoming more critical. Rust and WebAssembly (Wasm) provide a powerful solution with portable bytecode that abstracts hardware complexities.



WasmEdge is a lightweight, high-performance, cross-platform runtime optimized for LLM inference. It implements the standard WASI-NN API, enabling developers to write code once and compile it to Wasm. The resulting Wasm file can then run seamlessly on any device. WasmEdge handles the translation and routing of Wasm calls to native libraries like llama.cpp, whisper.cpp, and sd.cpp, ensuring optimal performance across platforms.
Tuesday June 17, 2025 12:40 - 12:45 JST
Level 1 | Orion

12:40 JST

Lunch 🍱
Tuesday June 17, 2025 12:40 - 14:10 JST
TBA
Tuesday June 17, 2025 12:40 - 14:10 JST
TBA

12:47 JST

Project Lightning Talks: Closing
Tuesday June 17, 2025 12:47 - 12:52 JST
Tuesday June 17, 2025 12:47 - 12:52 JST
Level 1 | Orion

14:10 JST

Full Lifecycle API Management in Kubernetes With Envoy and WebAssembly - Brandon Kang, Akamai Technologies & Mostafa Radwan, Datadog
Tuesday June 17, 2025 14:10 - 14:40 JST
As cloud-native applications accelerate in complexity, managing APIs end to end is a top priority. This session introduces a next-generation, Kubernetes-native approach using Envoy Proxy and WebAssembly (Wasm) for dynamic, high-performance traffic control.

We’ll show how Wasm powers real-time policy enforcement, AI-assisted traffic analysis, and advanced rate limiting—without rebuilding Envoy. Attendees will learn how to implement Zero Trust principles, secure multi-tenant API gateways, and deliver external routes with minimal overhead.

Observability enhancements using eBPF and OpenTelemetry will demonstrate how to align trace data with runtime metrics for deeper insights. Finally, we’ll discuss developer onboarding, version governance, and lifecycle management to ensure long-term API success.

A live demo will illustrate ephemeral testing environments, rapid iteration, and how to achieve a future-proof, high-throughput API management layer in Kubernetes.
Speakers
avatar for Mostafa Radwan

Mostafa Radwan

Senior Solutions Engineer, Datadog
Mostafa is a technologist and consultant specialized in cloud native computing. He started his career as a software engineer before getting in the trenches of application and production support. He enjoys helping enterprise companies successfully adopt DevOps and cloud native technologies... Read More →
avatar for Brandon Kang

Brandon Kang

Principal Technical Solutions Architect, Akamai Technologies
Brandon Kang is a Principal Technical Solutions Architect at Akamai Technologies, specializing in cloud-native projects across Asia as a compute specialist.Before joining Akamai, he served as a Lead Software Engineer at Samsung, a Senior Program Manager at Microsoft, and a Service... Read More →
Tuesday June 17, 2025 14:10 - 14:40 JST
Level 1 | Pegasus Ballroom B2+C
  Application Development

14:10 JST

BGP Peering Patterns for Kubernetes Networking at Preferred Networks - Sho Shimizu, Preferred Networks, Inc. & Yutaro Hayakawa, Isovalent at Cisco
Tuesday June 17, 2025 14:10 - 14:40 JST
BGP (Border Gateway Protocol) is increasingly being used to connect Kubernetes networking with the rest of the IT estate, especially in large-scale and on-premises environments. However, the complexity of many network architectures requires users to have more flexibility and control over how they deploy BGP. Based on the experience at Preferred Networks, this session introduces key BGP peering patterns that enhance Kubernetes networking while maintaining operational simplicity, including:

1. The Sidecar BGP Peering Pattern: A method of running a dedicated BGP speaker alongside Kubernetes networking components, balancing automation with fine-grained control.
2. Native Routing over IP Clos Networks – A tunneling-free approach that integrates Kubernetes with large-scale BGP-based datacenter fabrics for better performance.

Based on real-world experience, we will share best practices and lessons learned, helping attendees design scalable and reliable Kubernetes networking with BGP.
Speakers
avatar for Sho Shimizu

Sho Shimizu

Software Engineer, Preferred Networks, Inc.
Sho Shimizu, software engineer at Preferred Networks, Inc., specializes in Kubernetes networking for AI/ML workloads. Since joining in 2019, he has developed a custom CNI plugin and is responsible for container networking architecture across the company's AI/ML infrastructure. Previously... Read More →
avatar for Yutaro Hayakawa

Yutaro Hayakawa

Software Engineering Technical Leader, Isovalent at Cisco
Working for Cilium at Isovalent. Linux Networking & BPF enthusiast.
Tuesday June 17, 2025 14:10 - 14:40 JST
Level 1 | Pegasus Ballroom A+B1
  Connectivity

14:10 JST

What's New in Open Source Kubernetes? - Kaslin Fields, Google
Tuesday June 17, 2025 14:10 - 14:40 JST
Kubernetes moves fast. With 3 releases per year, it's hard to keep up with what's new in open source - not to mention whatever distributions or managed services you may use on top of it. This session will explore some of the most exciting changes to Kubernetes over the last couple of years including:
* New features to support AI workloads
* The introduction of a native way to implement the Sidecar Pattern
* Removal of "In-Tree" Cloud & Storage Provider code
* The deprecation of Pod Security Policies (PSPs) and introduction of Pod Security Admission
* The transition of image registry from k8s.gcr.io to registry.k8s.io
and more!
Speakers
avatar for Kaslin Fields

Kaslin Fields

Developer Advocate, Google
Kaslin Fields is a Developer Advocate at Google Cloud, a Container enthusiast and creator of tech comics. She uses her knowledge of DevOps technologies and methodologies to help others as they enter the Cloud Native world. By creating comics about DevOps tech, she hopes to make learning... Read More →
Tuesday June 17, 2025 14:10 - 14:40 JST
Level 1 | Appollon

14:10 JST

Navigating Millions of Kafka Events in Real Time With OTel - Siddharth Vijay, Baazi Games & Shivay Lamba, Couchbase
Tuesday June 17, 2025 14:10 - 14:40 JST
How can real-time event streaming platforms, handling millions of events and complex data processing, maintain peak performance and reliability? Managing the same has previously been complex. The latest agent changes and addition of semantic convention in OpenTelemetry make it ideal to monitor highly distributed event streaming architectures (EDA) like Kafka. In this session we will discuss how these changes help standardize telemetry, explain the usage of span links for capturing several traces for a transaction in EDA.

The talk will also cover how Otel enables automatic anomaly detection particularly useful for identifying issues like Consumer Lag, Increased Latency in Event Processing, and Partition Failures. By leveraging context propagation, Otel tracks end-to-end latency across the entire Kafka ecosystem, including producers, brokers, and consumers.

The talk covers real-world examples from gaming platforms and data systems which have enabled Otel for Kafka monitoring.
Speakers
avatar for Shivay Lamba

Shivay Lamba

Developer Relations Engineer, Couchbase
Shivay Lamba is a software developer specializing in DevOps, Machine Learning and Full Stack Development. He is an Open Source Enthusiast and has been part of various programs like Google Code In and Google Summer of Code as a Mentor and is currently a MLH Fellow. He has also worked... Read More →
avatar for Siddharth Vijay

Siddharth Vijay

AVP Engineering & Head of DevOps, Baazi Games
Siddharth Vijay, AVP at Pokerbaazi and KubeCon India speaker, brings over 12 years of experience driving impactful projects in AI, Security, and Cloud. A firm advocate of open-source technologies, he has a proven track record of delivering practical solutions with real-world value... Read More →
Tuesday June 17, 2025 14:10 - 14:40 JST
Level 1 | Orion
  Observability

14:50 JST

Rook: Intro and Deep Dive With Ceph - Satoru Takeuchi, Cybozu, Inc.
Tuesday June 17, 2025 14:50 - 15:20 JST
The Rook project will be introduced to attendees of all levels and experience. Rook is an open source cloud-native storage operator for Kubernetes. Rook integrates Ceph, a famous open source distributed storage, with Kubernetes. This session will cover various scenarios to show how Rook configures Ceph to provide stable block, shared file system, and object storage for your production data. Rook was accepted as a graduated project by the Cloud Native Computing Foundation in October 2020.
Speakers
avatar for Satoru Takeuchi

Satoru Takeuchi

Senior Storage Engineer, Cybozu, Inc.
Satoru is a developer and an administrator of an on-premise Kubernetes cluster and Rook/Ceph clusters at Cybozu. He is a maintainer of Rook/Ceph. He gave some Rook maintainer sessions at past KubeCon + CloudNativeCons. He also made presentations at Ceph Virtual 2022 and Cephalocon... Read More →
Tuesday June 17, 2025 14:50 - 15:20 JST
Level 1 | Appollon

14:50 JST

Debugging OpenTelemetry: Ensuring Your Observability Signals Are Spot On - Kasper Borg Nissen, Dash0
Tuesday June 17, 2025 14:50 - 15:20 JST
OpenTelemetry has become the go-to framework for unifying observability signals across metrics, logs, and traces. However, implementing OpenTelemetry often comes with its own set of challenges: broken instrumentation, missing signals, and misaligned semantic conventions that undermine its effectiveness. Debugging these issues can be daunting, leaving teams stuck with incomplete or unreliable observability data.

In this session, Kasper will demystify the debugging process for OpenTelemetry. Attendees will learn how to identify and troubleshoot common issues, ensure signals are transferred correctly, and align instrumentation with semantic conventions for consistent insights. Through live demos, Kasper will showcase techniques for validating resource configurations, debugging signal pipelines, and building confidence in your observability setup. This session is designed for anyone looking to unlock the full potential of OpenTelemetry and create robust observability practices.
Speakers
avatar for Kasper Borg Nissen

Kasper Borg Nissen

Developer Relations, Dash0
Kasper is a Co-Chair for KubeCon+CloudNativeCon EU/NA, Kubestronaut, CNCF Ambassador, and co-founder of the Nordic meetup alliances, Cloud Native Nordics, where he also serves as Community Lead. He works in Developer Relations at Dash0, previously Lunar where he and his team built... Read More →
Tuesday June 17, 2025 14:50 - 15:20 JST
Level 1 | Orion
  Observability

14:50 JST

How Green Is My OpenTelemetry Collector? - Adriana Villela, Dynatrace & Nancy Chauhan, Student
Tuesday June 17, 2025 14:50 - 15:20 JST
We live in a world heavily dependent on technology, and this comes at an environmental cost. For example, data centres consume 2% of global power. As our systems become more complex, power consumption will only increase. We strive to understand our systems through Observability, and yet making our systems observable contributes to an increasing global tech carbon footprint.

Luckily, tools like Kepler and Kube-Green help us understand our carbon footprint, and take mitigating actions. The Kepler Exporter exposes statistics, including power consumption metrics, from an application running in a Kubernetes (k8s) cluster. Kube-Green is an operator used to reduce the CO2 footprint of k8s clusters.

In this talk, attendees will learn about Kepler & Kube-Green, how to deploy them, and through a demo, how to apply them to deploy the OTel Collector to reduce power consumption and costs. Attendees will walk away with tools and knowledge to deploy greener Collectors and other k8s infrastructure.
Speakers
avatar for Nancy Chauhan

Nancy Chauhan

Engineer | Co-Chair, CNCF TAG Environmental Sustainability | Founder, Women in Cloud Native Community, Student
I am Nancy Chauhan, a software engineer passionate about solving complex problems and enhancing software reliability. As a CNCF Ambassador, I engage with a global cloud-native community, contributing to open-source projects and fostering collaboration. I also founded the Women in... Read More →
avatar for Adriana Villela

Adriana Villela

Principal Developer Advocate, Dynatrace
Adriana Villela is a Principal Developer Advocate, helping companies achieve reliability greatness through Observability, SRE, & DevOps practices. Previously, she managed a Platform Engineering team & an Observability Practices team at Tucows. Adriana has worked at various large-scale... Read More →
Tuesday June 17, 2025 14:50 - 15:20 JST
Level 1 | Pegasus Ballroom A+B1
  Observability

14:50 JST

Mastering Authorization: Integrating Authentication and Authorization Data in Cloud Native Apps - Yoshiyuki Tabata, Hitachi, Ltd.
Tuesday June 17, 2025 14:50 - 15:20 JST
Authorization is one of the most important considerations for cloud-native applications, as highlighted by the OWASP Top 10. For a long time, there was no clear standard, making authorization a significant challenge for many implementers. The OpenID Foundation AuthZEN WG is now working on standards, focusing on interfaces between PEP (Policy Enforcement Point) and PDP (Policy Decision Point), which provides some hope.
However, managing authorization data remains challenging. Since this data is closely related to authentication data, architects often struggle with how the OP (OpenID Provider) and PDP should manage and integrate it. There are multiple methods, and the best approach varies by use case.
In this session, Yoshiyuki Tabata will explain various methods for managing and integrating authentication and authorization data. He will also describe implementation using Keycloak for OP and Topaz for PDP, providing valuable insights into effective data management.
Speakers
avatar for Yoshiyuki Tabata

Yoshiyuki Tabata

Senior OSS Consultant, Hitachi, Ltd.
He's a Senior OSS Consultant at Hitachi, Ltd. As an expert in IAM and APIs, he has provided numerous consultations over the past decade, including designing API and Authn/Authz platforms. He has actively contributed to CNCF TAG Security and has added significant functionalities to... Read More →
Tuesday June 17, 2025 14:50 - 15:20 JST
Level 1 | Pegasus Ballroom B2+C
  Security

15:20 JST

Coffee Break ☕
Tuesday June 17, 2025 15:20 - 15:50 JST
TBA
Tuesday June 17, 2025 15:20 - 15:50 JST
TBA

15:50 JST

Reimagining Cloud Native Networks: The Critical Role of DRA - Lionel Jouin, Ericsson Software Technology & Sunyanan Choochotkaew, IBM Research
Tuesday June 17, 2025 15:50 - 16:20 JST
As AI/ML, high-performance and telecom workloads are progressing in their cloud-native journey, the unique platform requirements inherent to the nature of their functionality are exposing the limitations of existing solutions such as Multus and device plugins. Device Resource Allocation (DRA) offers a fresh approach overcoming these challenges with better resource management for non-homogeneous platforms, topology-aware use cases and beyond! By leveraging the latest Kubernetes features, DRA Drivers are redefining the network interface configuration and enhancing capabilities for multi-network deployments. This talk explores the evolving cloud-native networking landscape and the trade-offs between extending Kubernetes and leveraging add-on components. We will delve into recent advancements including the network device status with KEP-4817, the virtual device allocation with KEP-5075 and the role of the CNI-DRA-Driver in shaping the future of cloud-native networking infrastructure.
Speakers
avatar for Lionel Joiun

Lionel Joiun

Software Engineer, Ericsson Software Technology
Lionel Jouin is a Software Engineer at Ericsson Software Technology, based in Stockholm, Sweden. He actively contributes to Kubernetes with a focus on bringing native support for secondary networks and its ecosystem including services and policies…. His contributions span SIG Network... Read More →
avatar for Sunyanan Choochotkaew

Sunyanan Choochotkaew

Staff Research Scientist, IBM Research
Sunyanan Choochotkaew is a staff research scientist at IBM Research, specializing in distributed computing and performance acceleration on cloud platforms. She holds the role of maintainer of Kepler. She has made contributions to Environmental Sustainability TAG, operator framework... Read More →
Tuesday June 17, 2025 15:50 - 16:20 JST
Level 1 | Orion
  Connectivity

15:50 JST

Envoy Gateway Policies: Unlocking the Full Power of Envoy Proxy for API Gateways - Huabing Zhao, Tetrate.io
Tuesday June 17, 2025 15:50 - 16:20 JST
Envoy Gateway is revolutionizing edge traffic management for cloud-native applications. It efficiently manages Envoy-based application gateways and extends Kubernetes Gateway API functionalities through custom resource definitions (CRDs).

This presentation will delve into Envoy Gateway's API extensions: ClientTrafficPolicy, BackendTrafficPolicy, SecurityPolicy, and EnvoyExtensionPolicy. We'll explore their practical applications in managing and securing edge traffic, showcasing advanced features like JWT authorization, rate limiting, OIDC integration, external processing, and WASM plugins.

Attendees will gain hands-on knowledge to implement these cutting-edge capabilities, staying ahead of Gateway API advancements. Join us to learn how Envoy Gateway is shaping the future of cloud-native networking and how you can leverage its power in your infrastructure today.
Speakers
avatar for Huabing Zhao

Huabing Zhao

Engineer, Tetrate.io
Huabing (Robin) Zhao is a software engineer at Tetrate and a CNCF ambassador. He has developed a managed service mesh product on the cloud and assisted a lot of users in deploying Istio service mesh in production. He also founded Aeraki Mesh, a CNCF sandbox project that facilitates... Read More →
Tuesday June 17, 2025 15:50 - 16:20 JST
Level 1 | Appollon

15:50 JST

The Future of Prometheus Exposition Format - Arthur Sens, Grafana Labs
Tuesday June 17, 2025 15:50 - 16:20 JST
OpenMetrics (OM) had a wild journey: it started as a project to standardize the Prometheus exposition format, and it became an entirely separate CNCF Incubating project. Even though the project had high maturity, it struggled for years to find tools to comply with the first version of the spec. Finally, in 2025, it was incorporated back into the Prometheus Github organization so Prometheus developers could lead the efforts for OM 2.0.

In this talk, Arthur, a Prometheus maintainer and OpenMetrics contributor, will walk you through the main challenges that tools like Prometheus and OpenTelemetry face when trying to comply with OpenMetrics 1.0 and how the community plans to address these challenges in OM 2.0.

The audience will also learn how changing an exposition format can make Prometheus and OpenTelemetry-Collector more memory-efficient while making their specifications easier to translate into each other!
Speakers
avatar for Arthur Silva Sens

Arthur Silva Sens

Senior Software Engineer, Grafana Labs
Arthur Sens is a Software Engineer at Grafana, focusing on Prometheus and OpenTelemetry interoperability. He is also an active member and maintainer for both communities. The only things that can take Arthur away from the computer are his passion for lifting unnecessarily heavy... Read More →
Tuesday June 17, 2025 15:50 - 16:20 JST
Level 1 | Pegasus Ballroom A+B1
  Observability

15:50 JST

Practical Cloud Native Compliance Automation With OSCAL Compass - Chris Butler, Red Hat & Takumi Yanagawa, IBM Research
Tuesday June 17, 2025 15:50 - 16:20 JST
Cloud presents many advantages to users in terms of flexibility, scalability and innovation. Unfortunately compliance has become more complex as standards and regulations are used by end consumers as a proxy for security of underlying platforms whose operations are opaque. Consequently platform providers have ever increasing compliance obligations.

Compliance-as-code encompasses many activities such as automation of system configuration and general DevSecOps approaches. One perpetual challenge is how to provide machine readable workflows which span from standard to audit to allow automation in a way that scales.

OSCAL-Compass, a CNCF sandbox project, provides tooling to manage both the compliance artefacts as code and link those artefacts to executable policies. This talk will provide practical introduction to using OSCAL compass to document and enforce compliance controls using two of its tools: Compliance Trestle and C2P (compliance2policy) in the context of Kubernetes clusters.
Speakers
avatar for Takumi Yanagawa

Takumi Yanagawa

Advisory Software Developer, IBM Research
Takumi is an advisory software developer working in IBM Research - Tokyo on AI for Code and Security. He has a strong background in DevOps engineer and AI Governance product development using cloud-native technologies. With several years of experience, he has worked on building and... Read More →
avatar for Chris Butler

Chris Butler

Senior Principal Chief Architect, Red Hat
Dr. Chris Butler is a Chief Architect in the APAC Field CTO Office at Red Hat. Chris’ focus is working with regulated clients who are building infrastructure, application and AI platforms. Chris facilitates co-innovation engagements with our clients and partners with our product... Read More →
Tuesday June 17, 2025 15:50 - 16:20 JST
Level 1 | Pegasus Ballroom B2+C
  Security

16:30 JST

From Moon Prism Power To eBPF Super Saiyan: A Guide To Cloud Native Security & Observability - Carla Gaggini, Isovalent at Cisco & Kenta Tada, Toyota Motor Corporation
Tuesday June 17, 2025 16:30 - 17:00 JST
Join us on an anime-powered journey to explore the power of eBPF in cloud native. Inspired by Sailor Moon and Dragon Ball GT, this talk breaks down how eBPF enhances observability, networking, and security, using the Sailor Guardians and Gohan to make eBPF approachable. We’ll break down topics like real-time observability by comparing it to psychic flames.
And just as unchecked power in anime can lead to chaos, eBPF’s immense capabilities need to be used wisely. Drawing from Dragon Ball GT's arc where the Dragon Balls become a threat, we’ll examine best practices for safe deployment of eBPF (e.g., LSM, verifier constraints, Linux Capability restrictions). Spoiler alert: our Sailor Guardians and Gohan will come out victorious, worry not!

By the end, you’ll gain a clear understanding of how to wield eBPF safely and effectively in cloud native environments, no Super Saiyan transformation required!
Speakers
avatar for Carla Gaggini

Carla Gaggini

Head of Global Community Events, Isovalent at Cisco
Carla has been managing events and communities since 2011, producing and running many conferences, meetups, webinars and hackathons. Formerly managing everything “WTF is Cloud Native” and “Software Circus”, she now buzzes around eBPF at Isovalent at Cisco. She is one of the... Read More →
avatar for Kenta Tada

Kenta Tada

Project Manager, Toyota Motor Corporation
Kenta Tada is an experienced Linux engineer and team lead who has worked with various organizations. He has contributed to the Linux kernel and BPF tools and has served as a reviewer for the system validator used in kubeadm. He also reviewed the Japanese translation of the book... Read More →
Tuesday June 17, 2025 16:30 - 17:00 JST
Level 1 | Pegasus Ballroom A+B1
  Cloud Native Novice
  • Content Experience Level Any
  • Presentation Language English

16:30 JST

Dynamic Provisioning and Capacity-Aware Scheduling for Local Storage - Yuma Ogami, Cybozu, Inc.
Tuesday June 17, 2025 16:30 - 17:00 JST
In this session, the speaker presents TopoLVM, a CSI plugin for local storage, and introduces an upcoming Kubernetes feature for local storage that he and his team are working on.

Local storage is promising for applications that require high I/O performance, like Elasticsearch and MySQL. TopoLVM provides many features like raw block volumes, resizing, and dynamic provisioning to manage local storage in Kubernetes easily. It also includes a capacity-aware pod scheduling feature that considers each node's local storage capacity.

Currently, this capacity-aware feature is achieved by a scheduler extender, which has two main issues:

1. Many admins don't have the right to install scheduler extenders.
2. The scheduler extender is TopoLVM specific.

To address these issues, he will introduce a KEP titled "KEP-4049: Storage Capacity Scoring of Nodes for Dynamic Provisioning." to be able to TopoLVM's scheduling logic for all CSI drivers without using scheduler extenders.
Speakers
avatar for Yuma Ogami

Yuma Ogami

Software Engineer, Cybozu, Inc.
He works at Cybozu, Inc. and spent four years involved in the operation and development of a server infrastructure using a custom system with VMs. For the past three years, he has focused on the operation and development of the storage area for a new infrastructure using Kubernetes... Read More →
Tuesday June 17, 2025 16:30 - 17:00 JST
Level 1 | Orion
  Data Processing + Storage

16:30 JST

Containerd: Project Update and Deep Dive - Akihiro Suda & Kohei Tokunaga, NTT; Kirtana Ashok, Microsoft; Akhil Mohan, VMware by Broadcom
Tuesday June 17, 2025 16:30 - 17:00 JST
containerd is a CNCF-graduated container runtime project widely used in the ecosystem to manage containers and other workloads in Kubernetes, Docker, and more.

Join containerd maintainers for an update and deep dive into the latest developments in containerd. This panel will feature discussion of the launch and adoption of containerd 2.0, what’s next in 2.1, 1.7’s transition into Extended support, and how LTS is going with 1.6. There will also be highlights into the new release cadence of the project . Topics will also include how the containerd project is involved with the Kubernetes Enhancement Proposal (KEP) process and highlight how the broader cloud native ecosystem is enhanced through extension points in containerd.
Speakers
avatar for Akihiro Suda

Akihiro Suda

Software Engineer, NTT
Akihiro Suda is a software engineer at NTT Corporation. He has been a maintainer of Moby (dockerd), BuildKit, containerd, runc, etc. He is also a founder of nerdctl and Lima (CNCF project).
avatar for Kohei Tokunaga

Kohei Tokunaga

Software Engineer, NTT
Kohei Tokunaga is a software engineer at NTT Corporation, a Japan-based telecommunication company. He is a reviewer of CNCF containerd and a maintainer of BuildKit. He has talked about topics around container runtimes and builders at Open Source Summit, FOSDEM and KubeCon+CloudNativeCon... Read More →
avatar for Akhil Mohan

Akhil Mohan

Software Engineer, VMware by Broadcom
Akhil works as a Software Engineer at VMware by Broadcom. An active contributor to projects in cloud native and container ecosystem. Akhil is a reviewer for containerd and a maintainer of kubernetes publishing-bot. He works mostly on container runtimes and kubernetes sig-node asp... Read More →
avatar for Kirtana Ashok

Kirtana Ashok

Software Engineer, Microsoft
Software Engineer at Microsoft working on Windows Containers/containerd/k8s/Azure Kubernetes Service; @containerd maintainer, k8s contributor.
Tuesday June 17, 2025 16:30 - 17:00 JST
Level 1 | Appollon

16:30 JST

Your SBOM Is Lying To You – Let’s Make It Honest - Justin Cappos & Yuchen Zhang, New York University
Tuesday June 17, 2025 16:30 - 17:00 JST
SBOMs (Software Bills of Material) are essential for improving visibility and security in the software supply chain. As open-source code drives modern development, organizations face growing security risks due to limited transparency in software dependencies. Attacks like SolarWinds (2020) and Kaseya (2021) highlight the urgent need for stronger software supply chain security.
However, SBOMs are often inaccurate. This talk explores why these inaccuracies occur, how attackers exploit them, and how to address these issues. A key challenge is dependency management file analysis (e.g., cargo.toml for Rust), which struggles to track components effectively.
Enter SBOMit, an OpenSSF sandbox project leveraging in-toto attestations to create cryptographically verifiable SBOMs. By capturing supply chain steps as they occur, SBOMit enhances accuracy, mitigates tampering risks, and strengthens security. This talk examines SBOMit’s role in improving SBOM reliability across the CNCF ecosystem.
Speakers
avatar for Justin Cappos

Justin Cappos

Professor, New York University
I am a professor at NYU who has been working on software supply chain security for more than 20 years. I am a maintainer / creator of the TUF, Uptane, and in-toto projects, which are all under the LF.
avatar for Yuchen Zhang

Yuchen Zhang

Postdoctoral Associate, New York University
Yuchen is currently a postdoctoral researcher with the Secure Systems Laboratory (SSL) at the Tandon School of Engineering, New York University. He obtained his Ph.D. from the Department of Computer Science at Stevens Institute of Technology. Prior to Stevens, he completed his undergraduate... Read More →
Tuesday June 17, 2025 16:30 - 17:00 JST
Level 1 | Pegasus Ballroom B2+C
  Security
  • Content Experience Level Any
  • Presentation Language English
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Content Experience Level
  • Presentation Language
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.