Loading…
25-27, August 2025
Amsterdam, Netherlands
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2025 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Central European Summer Time, CEST (UTC +2). To see the schedule in your preferred timezone, please select from the drop-down menu to the right. 

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.

Venue: Emerald Room clear filter
Monday, August 25
 

11:20 CEST

Dig Smart: Building a Reliable Cloud Native DNS for Modern Networks - Joel Studler & Fabian Schulz, Swisscom
Monday August 25, 2025 11:20 - 12:00 CEST
Join us for a tech talk where we'll demonstrate how we operate and automate a highly available, geo-redundant DNS service for Swisscom's 5G mobile network using a cloud-native tech stack. We'll provide an in-depth look into our multi-cluster architecture that leverages ExternalDNS, PowerDNS, and CoreDNS. Additionally, we'll showcase how the system behaves when a cluster breaks down, and how we monitor and troubleshoot this multi-cluster setup at scale.

This talk will be particularly interesting for those with demanding DNS requirements—such as applications which require rare DNS resource records like NAPTR—as well as engineers and architects tasked with building a DNS service using cloud-native tools who, due to compliance, governance, or availability concerns, cannot use publicly available DNS-as-a-service offerings.
Speakers
avatar for Fabian Schulz

Fabian Schulz

Senior DevOps Engineer, Swisscom
Fabian Schulz is a cloud architect and Kubernetes specialist known for his expertise in building resilient cloud-native solutions. Currently at Swisscom, he focuses on designing next generation 5G core services using open-source technologies. With a passion for innovation, Fabian... Read More →
avatar for Joel Studler

Joel Studler

DevOps Engineer and System Architect, Swisscom
Joel is a DevOps Engineer currently in a team that builds the cloud native 5G core at Swisscom. He is experienced in infrastructure automation, software defined networking and highly available databases and passionate about automation. He is CK* certified and has written several CRD/Operator... Read More →
Monday August 25, 2025 11:20 - 12:00 CEST
Emerald Room
  Cloud & Containers
  • Audience Experience Level Any

13:30 CEST

Reliable and Cost-Effective: Open Storage Strategies for Kubernetes - Shriya Mulay, IBM
Monday August 25, 2025 13:30 - 14:10 CEST
As the modern applications running on Kubernetes become more dynamic, a reliable stateful storage becomes essential. These applications don’t just need storage; they need it to be fast, intelligent, and cost-effective. 
With so many open source tools available—like Rook-Ceph, NooBaa, and Longhorn—how do you pick the right one? And once you do, how do you make sure it’s reliable and doesn’t break the budget?

In this session, we’ll discuss how one can use open storage in Kubernetes—what works well, what causes problems, and how to avoid common mistakes. We’ll cover storage for different use cases (like block, file, and object), and talk about features like dynamic provisioning, snapshots, and scaling.

Whether you're a developer, architect, or admin, this session will help you understand how to choose, deploy, and manage open source storage in Kubernetes.
Speakers
avatar for Shriya Mulay

Shriya Mulay

Technical Support Professional, IBM
Shriya has over 7 years of experience in Software Defined Storage technologies, including Ceph, Gluster, Rook-Ceph, and NooBaa. She works closely with cloud-native platforms like Kubernetes, focusing on observability, troubleshooting, and data management. Shriya is passionate about... Read More →
Monday August 25, 2025 13:30 - 14:10 CEST
Emerald Room
  Cloud & Containers

14:25 CEST

Chain Reaction: Remixing CNCF’s Supply Chain Security Guide for 2025 - John Kjell, ControlPlane
Monday August 25, 2025 14:25 - 15:05 CEST
The original version of the CNCF Security TAG’s Supply Chain Security Best Practices was published in May 2021. To say “a lot has changed” since then would be a dramatic understatement—software supply chain attacks cost over $45 billion in 2023, with projections exceeding $80 billion by 2026.

In this talk, we'll take a whirlwind tour of the latest updates to the newly released second version of the Supply Chain Best Practices guide. One of the most significant changes is the increased adoption and maturity of SBOMs and attestations, supported by a rapidly growing ecosystem of tools for generating, verifying, and consuming this metadata.

We’ll explore how the open source community has responded to rising threats with a surge of new tools, improved standards, and broader best practice adoption—and how to chain these tools together for maximum impact.

We’ll showcase key open source projects from across the CNCF and OpenSSF ecosystems, including in-toto, TUF, SLSA, Guac, bomctl, SBOMit, and protobom.
Speakers
avatar for John Kjell

John Kjell

Principal Consultant, ControlPlane
John is a maintainer for the Witness and Archivista sub-projects under in-toto. Additionally, John is a co-chair to CNCF's TAG Security and active with multiple projects within the OpenSSF. Prior to ControlPlane, John was the Director of Open Source at TestifySec and an engineering... Read More →
Monday August 25, 2025 14:25 - 15:05 CEST
Emerald Room
  Cloud & Containers

15:35 CEST

Managing Telco Infrastructure and Applications at Scale: An Open Source Approach - Kashif Khan, Ericsson
Monday August 25, 2025 15:35 - 16:15 CEST
Telco infrastructure is rapidly evolving to adopt cloud-native paradigms, but operating Kubernetes in telecom-grade environments brings unique challenges—stringent SLAs, real-time performance, and complex hybrid infrastructure. At Ericsson, we've embraced the open source ecosystem to build scalable, resilient, and fully automated platforms tailored to telco needs. This talk presents our technical journey in managing large-scale infrastructure using Kubernetes, Cluster API, and multiple open-source providers—including Metal3 for bare metal provisioning and Cluster API Provider OpenStack (CAPO) for cloud-based workloads. We’ll demonstrate how we orchestrate heterogeneous environments, spanning bare metal and OpenStack-based compute, through a unified, declarative lifecycle approach. We’ll also cover observability and alerting using tools like Prometheus and more, as well as real-world strategies for zero-downtime upgrades, failure remediation, and long-term cluster maintenance—all aligned with demanding telecom-grade requirements like high availability and real-time traffic handling.
Speakers
avatar for Kashif Khan

Kashif Khan

Open Source Architect, Ericsson
Kashif Khan is a maintainer of the CNCF project Metal3.io for 5+ years. He works as an open source Architect and Product Owner for Ericsson Software Technology, Finland. He holds a PhD in Computer Science. Kashif is a research and open source enthusiast and his current area of interest... Read More →
Monday August 25, 2025 15:35 - 16:15 CEST
Emerald Room
  Cloud & Containers

16:30 CEST

Building Europe's Cloud Future: NeoNephos' Platform Mesh - Mirza Kopic, SAP SE & Marvin Beckers, Kubermatic
Monday August 25, 2025 16:30 - 17:10 CEST
The open source Platform Mesh project, is part of an open reference architecture for building a multi-provider cloud-edge continuum that should span the European continent. Some of the central questions the project wants to answer are: How can the different service offerings across a wide array of providers be unified? How can they communicate in a common language?

We discuss how a combination of Cloud Native building blocks (kcp and kube-bind, among others) is used to create the foundation for the next generation of cloud platforms. We demonstrate a prototype which meshes together Kubernetes-like APIs that allows us to consume services across multiple control plane instances, instantiating what we call the “Platform Mesh”. Platform Mesh is a project in the newly founded Linux Foundation sub-foundation, NeoNephos, originating from the ApeiroRA initiative.

This talk is for operators of cloud service providers and internal developer platforms (IDPs), giving them an outlook at a technology that unifies both worlds and creates a standard to consume services from (nearly) everywhere.
Speakers
avatar for Mirza Kopic

Mirza Kopic

Principal Software Engineer and Lead Architect, SAP SE
Mirza Kopic is a Principal Engineer and Lead Architect with ApeiroRA Platform Mesh project. Previously Mirza has worked in many different roles, including managing global analytics teams, working with Machine Learning teams and leading diverse projects in the that involve kubernetes... Read More →
avatar for Marvin Beckers

Marvin Beckers

Team Lead, Kubermatic
Marvin is a team lead and senior software engineer at Kubermatic, maintainer for the kcp project and CNCF Ambassador. He started out as a Linux sysadmin, and found himself gradually turning into a software engineer while automating Kubernetes cluster operations. He has been working... Read More →
Monday August 25, 2025 16:30 - 17:10 CEST
Emerald Room
  Cloud & Containers
 
Tuesday, August 26
 

11:00 CEST

Build Distroless Containers the Easy Way: From Full Fat To Featherweight With Unbase_oci - Nikolas Kraetzschmar, SAP
Tuesday August 26, 2025 11:00 - 11:40 CEST
Tired of wrangling dependencies to craft distroless containers from scratch? unbase_oci flips the script.

Instead of painstakingly building up from a minimal base, you start with a comfortable, fully-featured container—think debian or ubuntu—and develop as usual. Then, with one simple command, unbase_oci automatically strips your image down to the bare essentials by comparing it to the base and keeping only what’s truly needed.

No more trial-and-error to get your distroless image just right. Write normal Dockerfiles, enjoy all your debugging tools during dev, and let unbase_oci do the slimming for production.

It’s Bash. It’s fast. It’s minimal. It works with any OCI image and requires nothing but standard Unix tools and your container engine of choice.

Let’s stop over-engineering minimalism. Build smart, then unbase.
Speakers
avatar for Nikolas Kraetzschmar

Nikolas Kraetzschmar

Software Engineer, SAP
Focused on building a streamlined, security-hardened Linux for container and Kubernetes environments, with a keen interest in C programming and security.
Tuesday August 26, 2025 11:00 - 11:40 CEST
Emerald Room
  Cloud & Containers
  • Audience Experience Level Any

11:55 CEST

Cloud Native IoT: OTA Updates and Device Repurposing With K8s - Anastassios Nanos & Charalampos Mainas, Nubis PC
Tuesday August 26, 2025 11:55 - 12:35 CEST
This session presents an open-source system for integrating resource-constrained IoT devices like ESP32-based MCUs into k8s-managed environments. It covers secure device onboarding using Entity Attestation Tokens (EATs) and OpenDICE, where devices generate cryptographic identities from hardware-embedded secrets and attest their state during registration and OTA updates.

Devices are discovered using Akri, which exposes them as addressable Kubernetes resources. Firmware is built and packaged as OCI artifacts, stored in standard registries, and deployed via a k8s "FlashJob" operator that lives alongside the Akri framework. Upon deployment, prior to joining the cluster, devices are onboarded and validated via Akri's discovery handler. When repurposed, devices are validated again, to ensure end-to-end attestation of both hardware and software components.

The session focuses on concrete mechanisms for OTA management, hardware-rooted identity, and distributed execution targeting constrained systems under k8s control.
Speakers
avatar for Anastassios Nanos

Anastassios Nanos

Systems Researcher, NUBIS PC
I am a Researcher in Computer Systems and I am currently working on the lower-level parts of the stack to attack issues related to performance, scalability, power-efficiency and security in hypervisors.
avatar for Charalampos Mainas

Charalampos Mainas

Systems Software Engineer, Nubis PC
Charalampos Mainas is a systems engineer who is very interested in virtualization technologies and operating systems. His main focus is on finding ways to improve the performance and scalability of lightweight VMMs. Moreover, he has considerable experience with unikernel stacks, porting... Read More →
Tuesday August 26, 2025 11:55 - 12:35 CEST
Emerald Room
  Cloud & Containers

14:10 CEST

Server Partitioning Without VMs - for Flexibility and Performance - Antti Kervinen, Intel & Feruzjon Muyassarov, Ericsson Software Technology
Tuesday August 26, 2025 14:10 - 14:50 CEST
Efficient use of servers with tens or hundreads of CPUs most often requires partitioning it so that only a fraction of CPUs is disclosed to a set of containers. This improves performance, hardware utilization, and mitigates the noisy neighbor problem.

In this session, you will learn about very flexible CPU and memory partitioning that enables squeezing maximum performance from the server. For instance, you will see how to arrange containers into dynamically growing and shrinking CPU sets. How to group containers into CPU sets based on their names, labels, QoS classes, or namespaces. How to pre-allocate isolated CPUs for latency critical containers. How to let containers burst outside their partitions if there are free CPUs. And without forgetting observability, how to view existing partitions in the cluster in detail, including exact CPUs and containers in each partition.

We use NRI plugins and the balloons policy for demonstrating this, without limitations of Kubernetes CPU manager, or overhead of VMs. That said, this partitioning makes sense inside large VMs, too.
Speakers
avatar for Antti Kervinen

Antti Kervinen

Cloud Orchestration Software Engineer, Intel
Antti Kervinen is a Cloud Orchestration Software Engineer working at Intel, whose interest in Linux and distributed systems has led him from academic research of concurrency to the world of Kubernetes. When unplugged, Antti spends his time outdoors discovering wonders of nature... Read More →
avatar for Feruzjon Muyassarov

Feruzjon Muyassarov

Software Engineer, Ericsson Software Technology
Feruzjon Muyassarov is a Software Engineer focused on Kubernetes optimization and resource management. At Ericsson Software Technology, he works on enhancing performance and hardware integration in cloud-native systems.https://www.linkedin.com/in/fmuyassarov/
Tuesday August 26, 2025 14:10 - 14:50 CEST
Emerald Room
  Cloud & Containers

15:05 CEST

Containers Live Migration: What’s There, What’s Missing, What’s Next? - Daniel Simionato, ControlPlane
Tuesday August 26, 2025 15:05 - 15:45 CEST
Moving a running workload from one host to another transparently without disrupting its execution flow (“live migration”) is a solved problem for virtual machines, but still poses challenges for containers.

Current checkpoint and restore functionalities in both Kubernetes and LXD are somewhat limited or not completely fleshed out, and moving containers from one host to another involves either spinning up new replicas or stopping and restarting the containers, which is undesirable for stateful workloads like databases, machine learning or deep learning jobs.

Projects like CRIU (https://criu.org/Main_Page) and DMTCP (https://github.com/dmtcp/dmtcp) propose different approaches to offer checkpointing and restore functionalities in containers, but there is still no streamlined solution in LXD and Kubernetes.

In this lightning talk, we’ll go over the current state of the art, with a quick demo of what’s currently available, describing what’s missing and what will be the future developments to achieve seamless container live migration.
Speakers
avatar for Daniel Simionato

Daniel Simionato

Cloud Native Engineer, ControlPlane
Daniel Simionato is currently a Cloud Native Engineer at ControlPlane. Tinkerer at heart, he spent the majority of his career in a terminal tending or architecting Linux systems and Kubernetes clusters. When he’s not pressing keys in front of light boxes, he enjoys climbing and... Read More →
Tuesday August 26, 2025 15:05 - 15:45 CEST
Emerald Room
  Cloud & Containers

16:20 CEST

Your Containers Aren’t Alone: Demystifying Container Isolation - Marina Moore, Edera
Tuesday August 26, 2025 16:20 - 17:00 CEST
How do you know your container workloads aren’t being viewed or altered by other workloads running in the same environment? Many technologies promise to isolate workloads from each other, but what do these technologies actually do, and which one is right for your workloads? In this talk we will discuss why people use multi-tenency to run containers from multiple users in the same cluster, the risks of multi-tenency, and what we can do about these risks. We will survey technologies with different levels of container isolation, from relying on namespaces to using virtual machines to using separate hardware. Each level of isolation is right for some use cases, so we will discuss the pros and cons of each. You’ll come away with a new understanding of how you can keep containers secure from each other and an understanding of the tradeoffs of various container isolation technologies.
Speakers
avatar for Marina Moore

Marina Moore

Research Scientist, Edera
Marina Moore is a Research Scientist at Edera. She is a maintainer of The Update Framework (TUF), a CNCF graduated project that provides secure software update and delivery. She is also a chair of CNCF's TAG Security where she contributes to security assessments and whitepapers, as... Read More →
Tuesday August 26, 2025 16:20 - 17:00 CEST
Emerald Room
  Cloud & Containers
 
Wednesday, August 27
 

11:00 CEST

The Security Guardian: Using OpenSearch for Real-Time Threat Detection - Meha Bhalodiya, Red Hat
Wednesday August 27, 2025 11:00 - 11:40 CEST
Imagine this: your systems are humming along smoothly when, without warning, an unseen adversary slips through the cracks. A small vulnerability leads to a large-scale security breach. Could it have been prevented? Absolutely—with the right tools and strategy.

In this session, I’ll embark on an interactive journey into how OpenSearch becomes the vigilant guardian of your infrastructure. Starting with real-world scenarios, we'll explore how to harness OpenSearch’s powerful features to detect anomalies, correlate logs, and respond to threats in real-time.

You’ll see how simple queries can expose hidden patterns, dashboards can visualize attack vectors, and machine learning models can predict threats before they occur. But it’s not just about the tools—we’ll dive into best practices for deploying OpenSearch in complex environments and ensuring it scales with your security needs.

Join me to learn how OpenSearch transforms security operations, turning chaos into clarity and ensuring you stay one step ahead of cyber threats.
Speakers
avatar for Meha Bhalodiya

Meha Bhalodiya

Software Quality Engineer, Red Hat
A Software Quality Engineer at Red Hat, where I work with the OpenShift Container Platform team.
Wednesday August 27, 2025 11:00 - 11:40 CEST
Emerald Room
  Cloud & Containers
  • Audience Experience Level Any

11:55 CEST

Deploy AI in 20MB: Lightweight Containers for Open Source Developers - Miley Fu, Second State
Wednesday August 27, 2025 11:55 - 12:35 CEST
Containerization has enabled powerful deployment workflows—but traditional Linux containers can be heavyweight, especially for LLMs or AI workloads on resource-restraint environments.

This session introduces WebAssembly as an alternative for deploying small, single-purpose AI functions. We’ll demonstrate how to build a simple AI service in Rust, compile it to Wasm, and compare the runtime footprint and deployment model with a traditional Python or Linux container-based equivalent. The focus will be on practical constraints: image size, memory use, startup time, and runtime isolation. We’ll also walk through running them (along open source LLMs) in sandboxed environments, even without root access, and why this matters for cross-platform efficient and secure deployment. The session is geared toward beginners who may already be familiar with Docker but are looking for faster, more portable alternatives to run open source LLMs in real-world environments.

Ideal for devs exploring open-source AI tooling, local-first agents, or edge inferencing.
Speakers
avatar for Miley Fu

Miley Fu

Founding Member, Second State
Miley is the co-chair and keynote speaker for KubeCon+Open Source Summit and AI Dev 2024. With over 6 years of experience working on WasmEdge runtime in CNCF sandbox as a founding member, she talks at KubeCon, KCD Shenzhen, CloudDay Italy, DevRelCon, Open Source Summit Japan, AWS... Read More →
Wednesday August 27, 2025 11:55 - 12:35 CEST
Emerald Room
  Cloud & Containers

14:10 CEST

Another Cluster Bites the Dust... and That’s Just Fine! - Davide Bianchi & Graziano Casto, Mia-Platform
Wednesday August 27, 2025 14:10 - 14:50 CEST
Why keep your cluster alive when you’re not using it? Let it bite the dust, every night, and that’s just fine. With Crossplane and kube-green, you can unlock ephemeral environments that spin up when you code and shut down when you rest. Imagine a development setup that dynamically provisions complex infrastructure for testing, then automatically scales down during off-hours – like nights and weekends.

In this talk, we’ll show you how Platform Engineering can orchestrate this smart, on-demand model, so developers can focus on building applications, not babysitting clusters. You’ll see the integration in action, explore the impact on cost, efficiency, and sustainability, and discover how to shift from static uptime to dynamic, eco-friendly infrastructure. Save money, reduce emissions, and let your clusters rest – because we will rock you, but not all night long.
Speakers
avatar for Davide Bianchi

Davide Bianchi

Principal Engineer, Mia-Platform
Principal Engineer at Mia-Platform. Passionate about Open Source and Green Software in the Cloud Native world.
avatar for Graziano Casto

Graziano Casto

DevRel Engineer, Mia-Platform
Graziano is a software engineer and passionate about agile development and product management. Formerly a developer of distributed systems in enterprise environments and a product manager, he focuses on sharing the myriad beauties of the cloud-native world. Active in international... Read More →
Wednesday August 27, 2025 14:10 - 14:50 CEST
Emerald Room
  Cloud & Containers

15:05 CEST

NeoNephos' OpenMFP and Platform Mesh: Building Composable Enterprise Architectures - Bastian Echterhölter & Mirza Kopic, SAP SE
Wednesday August 27, 2025 15:05 - 15:45 CEST
OpenMFP addresses the critical challenge of fragmented user experiences in enterprise environments by establishing a unified architectural framework for micro frontend composition. The platform creates seamless digital UX by standardizing how distributed UI components integrate while preserving team autonomy and eliminating redundancies of core functionalities.

Platform Mesh establishes interoperability between multiple providers by building upon the Kubernetes API and resource model. Developers and admins can discover, access, and order services from various sources through their beloved kubectl.

The architectural implementation leverages a GraphQL layer that orchestrates resources through the Kubernetes Resource Model (KRM), secured by a fine grained authorization approach (ReBAC) with OpenFGA.

These complementary technologies power diverse applications: Internal Developer Platforms, enterprise marketplaces and self-service portals. We'll demonstrate how NeoNephos projects reduce cognitive load, accelerate development, and support European cloud sovereignty. The talk shows how open source solutions are reshaping enterprise platform patterns through composable architecture.
Speakers
avatar for Bastian Echterhölter

Bastian Echterhölter

Principal Software Engineer and Lead Architect, SAP SE
Bastian is a Principal Software Engineer and Lead Architect the OpenMFP NeoNephos project, bringing 18 years of professional experience across consulting and product development. His work centers on cloud native technologies, DevOps practices, and enhancing Developer Experience, with... Read More →
avatar for Mirza Kopic

Mirza Kopic

Principal Software Engineer and Lead Architect, SAP SE
Mirza Kopic is a Principal Engineer and Lead Architect with ApeiroRA Platform Mesh project. Previously Mirza has worked in many different roles, including managing global analytics teams, working with Machine Learning teams and leading diverse projects in the that involve kubernetes... Read More →
Wednesday August 27, 2025 15:05 - 15:45 CEST
Emerald Room
  Cloud & Containers
  • Audience Experience Level Any

16:20 CEST

Integrating EPSS and CVSS in Open Policy Agent To Quarantine Real-world Vulnerabilities - Nigel Douglas, Cloudsmith
Wednesday August 27, 2025 16:20 - 17:00 CEST
CVSS (Common Vulnerability Scoring System) and EPSS (Exploit Prediction Scoring System) are both valuable tools for vulnerability management, but they serve different purposes. CVSS assesses the inherent severity of a vulnerability, whereas EPSS estimates the likelihood of that vulnerability being exploited in the wild. At Cloudsmith, we integrate open source projects like EPSS and the Trivy scanner for CVSS analysis into Open Policy Agent (OPA) to strengthen supply chain enforcement.

In this session, we’ll examine four recent CVEs that highlight the contrast between these two approaches—cases where vulnerabilities score highly under CVSS but have a low EPSS probability, and others with high EPSS scores (indicating strong exploit potential) that had not yet been published in the NIST CVE database at the time of artifact scanning. These examples underscore the importance of leveraging both CVSS and EPSS in a comprehensive vulnerability management strategy.

We’ll also explore how open-source tools like OPA can be used to enforce these security controls effectively within the software supply chain.
Speakers
avatar for Nigel Douglas

Nigel Douglas

Head of Developer Relations, Cloudsmith
Nigel Douglas is the Head of Developer Relations at Cloudsmith. He champions Cloudsmith’s developer ecosystem by creating compelling educational content, engaging with developer communities, and promoting Cloudsmith as the go-to solution for artifact management and supply chain... Read More →
Wednesday August 27, 2025 16:20 - 17:00 CEST
Emerald Room
  Cloud & Containers
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Audience Experience Level
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.