OSPOlogy Day KubeCon + CloudNativeCon EU
📍 Room Access and Registration
The sessions will take place in rooms L103-104. To access Entrance L, all attendees must first pick up their badge at either Entrance C or Entrance K, then exit the venue and re-enter through Entrance L to reach the meeting room. You can find the venue entrances here: https://www.rai.nl/en/the-location/floor-plan
OSPOlogy Day CloudNative Amsterdam
Immerse yourself in a dynamic day of interactive roundtable discussions and peer-driven knowledge exchange designed to help organizations navigate open source management, strategy, and operations. OSPOlogy Day CloudNative is your gateway to connecting with open source managers, offering opportunities to tackle real-world challenges on open source strategy in cloud native environments. Hosted by CNCF in collaboration with the TODO EU Chapter, this event brings together open source leaders for guided discussions with mentors.
The Call for Submissions closed on February 25. Lightning talks and facilitated discussions with mentors are now live in the agenda below
Please note: People who RSVP for this OSPOlogy co-located event, all attendees must be registered with an all-access pass for KubeConKubeCon + CloudNativeCon to access the meeting space.
Format
The meeting begins with 2-3 speaker lightning introductions, followed by small group discussions where participants tackle real-world challenges, demo tooling, etc with peer support and guidance. All discussions are held under Chatham House Rules.
Who Should Attend
This event is designed for open source professionals working at organizations or with previous experience in open source management:
-
C-level and senior technical leaders
-
Engineering managers and platform team leads
-
Open Source Program Office (OSPO) leaders
-
Professionals focused on supply chain security, upstream contribution, and community engagement
Sessions
| Time | Format | Title | Speaker / Facilitator(s) | Affiliation |
|---|---|---|---|---|
| 1:00 PM - 1:05 PM CET | Intro | Welcome to OSPOlogy Day Cloud Native | Ana Jimenez | The Linux Foundation |
| 1:05 PM - 1:15 PM CET | Lightning Talk | Open Source Security: Developer Responsibility or Compliance Checklist? | Ram Iyengar | OpenSSF |
| 1:15 PM - 1:25 PM CET | Lightning Talk | Compliance Gate for Restricted Environments | Sjoerd van Leent | Alliander N.V. |
| 1:25 PM - 1:35 PM CET | Lightning Talk | When Open Source Momentum Dies: Knowing When to Evolve... or Let Go | David Hirsch | Dynatrace |
| 1:35 PM - 1:45 PM CET | Lightning Talk | Getting Started With the OSPO Book for Open Source Managers | Jan van den Berg | Ahold Delhaize |
| 1:45 PM - 1:55 PM CET | Lightning Talk | From Policy to Practice: Open Source in the Dutch Public Sector | Gina Plat | Dutch Ministry of the Interior and Kingdom Relations |
| 2:00 PM - 3:00 PM CET | Facilitated Discussion | Scaling LF/CNCF Trainings and Certs in a Large Corporate Enterprise | Sebastian Grüner | E.ON |
| 2:00 PM - 3:00 PM CET | Facilitated Discussion | How Will the CRA Affect CNCF Projects? | Natali Vlatko, Mirko Boehm | Cisco; The Linux Foundation |
| 3:00 PM - 4:00 PM CET | Facilitated Discussion | Making Your License Policy Easy to Communicate and Enforce | Nico Rikken | Alliander N.V. |
| 3:00 PM - 4:00 PM CET | Facilitated Discussion | Contributing and Open-Sourcing at Scale in Large Organizations | Thomas Steenbergen | AboutCode Foundation / SIVON OSPO |
Program Committee
| Name | Affiliation |
|---|---|
| Ana Jiménez Santamaría | The Linux Foundation |
| Gergely Csatari | Nokia |
| David Hirsch | Dynatrace |
| Natali Vlatko | Cisco |
| Sebastian Grüner | E.ON |
| Stephen Augustus | Bloomberg |
| Thomas Steenbergen | AboutCode Foundation / SIVON OSPO |
A big thank you to all speakers, mentors, and program committee members for helping shape OSPOlogy Day Cloud Native and for contributing your time, expertise, and support to make this event possible
-
1:00 PM - 1:05 PM CET
Welcome to OSPOlogy Day Cloud Native
in-personSPEAKERS -
1:05 PM - 1:15 PM CET
Open Source Security: Developer Responsibility or Compliance Checklist?
in-personRam Iyengar, OpenSSF
Showcase on how tools can be used to make informed decisions about open source projects used in building products to allow engineers to build freely and compliance to be maintained without compromise
SPEAKERS -
1:15 PM - 1:25 PM CET
Compliance Gate for Restricted Environments
in-personSjoerd van Leent, Aliander N.V.
Lighning talk on how to set up a pipeline for building sofware deliverables with integrated verification of license and security compliance alongside signing and attestation of the deliverable based on experience with Tekton, DependencyTrack, Syft and Cosign
-
1:25 PM - 1:35 PM CET
When Open Source Momentum Dies: Knowing When to Evolve... or Let Go in-person
in-personDavid Hirsch, Dynatrace
What are early signs that a project or community is stagnating? Who should be responsible for naming decline? or Why is ending a project seen as failure? This lighning talk explores how to recognize early signals of declining momentum and how to respond responsibly. Participants will discuss whether graceful shutdown is a leadership skill, who has the authority to make such decisions, and how fear of failure often prolongs unhealthy project states.
SPEAKERS -
1:35 PM - 1:45 PM CET
Getting Started With The OSPO Book for Open Source Managers
in-personJan van den Berg, Ahold Delhaize A practical introduction to the OSPO Book, guiding open source managers through its core chapters on strategy, governance, policy, compliance, security, community engagement, and metrics to help organizations build and mature their open source management practices
SPEAKERS -
1:45 PM - 1:55 PM CET
From Policy To Practice; Open Source in The Dutch Public Sector
in-personGina Plat, Dutch Ministry of Interior and Kingdom Relations
Lightning talk on how open source is done in practice within the dutch public sector showcasing two projects: Dutch Government Codeplatform, a shared development environment based on Forgejo designed to modernize software development processes, facilitate cloud deployment, and simplify open-sourcing; and MijnBureau, a sovereign open-source workspace for government agencies that builds upon the La Suite/OpenDesk initiatives from the French and German governments
SPEAKERS -
2:00 PM - 3:00 PM CET
Facilitated Discussion | How CRA will affect CNCF projects?
in-personNatali Vlatko, Cisco | Mirko Boehm, Linux Foundation Europe
The EU CRA has several effects on open source foundations and the consumers of open source projects. In this discussion I would like to discover CNCF staff's thoughts about CRA and how CNCF will fulfill the steward obligations and if CNCF will support the manufacturer due diligence with voluntary attestation? How the CRA steward obligations will effect a CNCF project? Will CNCF provide voluntary attestation on the CNCF projects? Will attestation be mandatory for certain maturity level in CNCF?
SPEAKERS -
2:00 PM - 3:00 PM CET
Facilitated Discussion | Scaling LF/CNCF trainings and certs in a large corporate enterprise
in-personSebastian Grüner, E.on
As distributed corporate enterprise and CNCF enduser we use a lot of CNCF projects internally on a large scale. But in contrast to that the rate of employees that are interested in project specific trainings and certifications has remained extremely low. How do you provide trainings on scale?; How do you handle the cost and cost-distribution involved?; How do you approach engineers and engineering managers about open source specific trainings?; Do you have internal engagement with engineers about training opportunities?
SPEAKERS -
3:00 PM - 4:00 PM CET
Facilitated Discussion | Contributing and Open-Sourcing at Scale in Large Organizations
in-personThomas Steenbergen, AboutCode Foundation and SIVON OSPO
As more organizations embrace open source, the challenge shifts from mere participation to effective scaling: how do large enterprises contribute meaningfully to open source ecosystems like Cloud Native while ensuring regulatory compliance, security, collaboration, and internal alignment? In this session, we’ll explore strategies and lessons learned from fostering open source contributions among hundreds, if not thousands, of developers and teams. Discussion points will include developing effective governance frameworks, balancing company objectives with community values, and navigating legal and compliance barriers without hampering engineering progress. We'll also delve into strategies for sustaining key technologies that are critical to the organization’s success.
SPEAKERS -
3:00 PM - 4:00 PM CET
Facilitated Discussion | Making your license policy easy to communicate and enforce
in-personNico Rikken, Alliander N.V.
Share best-practices in making a license policy that can be enforced and can be communicated to developers so they know how to comply. In what format is your license policy stored? In what ways do you enforce your license policy? What percentage of cases does require human review?How do developers learn about your license policy?What challenges do you face in communicating your license policy?
SPEAKERS