[{"data":1,"prerenderedAt":282},["ShallowReactive",2],{"blog-en-cncf-project-maturity-graduation-criteria-production":3,"blog-related-en-cncf-project-maturity-graduation-criteria-production":231,"blog-en-cncf-project-maturity-graduation-criteria-production-alt":220},{"id":4,"title":5,"author":6,"body":7,"date":214,"description":215,"extension":216,"image":217,"locale":218,"meta":219,"navigation":220,"path":221,"seo":222,"stem":223,"tags":224,"__hash__":230},"blog\u002Fblog\u002Fen\u002Fcncf-project-maturity-graduation-criteria-production.md","10,000 GitHub Stars Isn't a Diploma. Why the Real Criterion for Choosing a CNCF Project Isn't Commit Count but Maturity Stage","Kubo Team",{"type":8,"value":9,"toc":205},"minimark",[10,15,19,26,37,46,50,53,59,68,103,106,110,119,125,140,143,147,150,156,169,178,191,195,198],[11,12,14],"h2",{"id":13},"why-working-open-source-software-stops-being-maintained-six-months-later","Why \"Working\" Open Source Software Stops Being Maintained Six Months Later",[16,17,18],"p",{},"When engineers add a new tool to a Kubernetes cluster, the first stop is usually GitHub. Star count, last commit date, how fast issues get answered. These are useful signals, but they barely tell you whether a project will still be alive a year from now.",[16,20,21],{},[22,23],"img",{"alt":24,"src":25},"Comparison diagram contrasting CNCF project popularity and sustainability","https:\u002F\u002Fcdn.kubo.hexabase.io\u002Fimages\u002Fblog\u002Fcncf-project-maturity-graduation-criteria-production\u002Fsection01.webp",[16,27,28,29,36],{},"The Cloud Native Computing Foundation (CNCF) currently oversees hundreds of projects, including 38 Graduated and 36 Incubating projects (",[30,31,35],"a",{"href":32,"rel":33},"https:\u002F\u002Fwww.cncf.io\u002Fprojects\u002F",[34],"nofollow","CNCF's official project list",", as of August 2026). If you're deciding to adopt a tool in your Kubernetes ecosystem just because \"it's a CNCF project,\" you're only looking at half the picture. CNCF projects sit at clearly defined maturity stages, and the stage a project occupies changes how much risk you're actually taking on when you put it into production.",[16,38,39,40,45],{},"Many tools, including lightweight Kubernetes distributions like ",[30,41,44],{"href":42,"rel":43},"https:\u002F\u002Fwww.rancher.com\u002Fproducts\u002Fk3s",[34],"K3s",", enter the ecosystem at the experimental \"Sandbox\" stage. Bringing a Sandbox-stage project into a production K3s cluster means accepting the full risk that the development team changes direction or a maintainer walks away.",[11,47,49],{"id":48},"sandbox-incubating-graduated-reading-the-three-stages-through-the-lens-of-is-it-production-ready","Sandbox \u002F Incubating \u002F Graduated — Reading the Three Stages Through the Lens of \"Is It Production-Ready?\"",[16,51,52],{},"CNCF's maturity stages aren't a one-time badge; they're an actively monitored status maintained by the Technical Oversight Committee (TOC). TOC meetings routinely include due diligence for new graduation requests and follow-up tracking of already-graduated projects — \"Graduated\" is not a title you earn once and keep forever.",[16,54,55],{},[22,56],{"alt":57,"src":58},"Hierarchy diagram showing the requirements at each of the Sandbox, Incubating, and Graduated stages","https:\u002F\u002Fcdn.kubo.hexabase.io\u002Fimages\u002Fblog\u002Fcncf-project-maturity-graduation-criteria-production\u002Fsection02.webp",[16,60,61,62,67],{},"Translating CNCF's official ",[30,63,66],{"href":64,"rel":65},"https:\u002F\u002Fgithub.com\u002Fcncf\u002Ftoc\u002Fblob\u002Fmain\u002Fprocess\u002Fgraduation_criteria.md",[34],"project lifecycle definition"," into something practitioners can actually use, there are three main things worth checking.",[69,70,71,79,85],"ul",{},[72,73,74,78],"li",{},[75,76,77],"strong",{},"Independent production adoption",": To move to Incubating, a project needs documented evidence of multiple independent adopters that the TOC judges to be of sufficient scale and quality. That's a different bar from a single company open-sourcing its internal tool.",[72,80,81,84],{},[75,82,83],{},"Committer diversity across organizations",": Graduated status requires committers spanning multiple organizations. This matters because it determines whether development can continue even if the founding company gets acquired, exits, or changes strategic direction.",[72,86,87,90,91,96,97,102],{},[75,88,89],{},"Proof of security practices",": Whether a project holds the ",[30,92,95],{"href":93,"rel":94},"https:\u002F\u002Fopenssf.org\u002Fprojects\u002Fbest-practices-badge\u002F",[34],"OpenSSF Best Practices Badge"," (formerly the CII Best Practices Badge) is another useful signal. The badge is a self-certified attestation covering ",[30,98,101],{"href":99,"rel":100},"https:\u002F\u002Fgithub.com\u002Fcoreinfrastructure\u002Fbest-practices-badge\u002Fblob\u002Fmain\u002Fdocs\u002Fcriteria.md",[34],"six categories",", including vulnerability reporting processes, build reproducibility, and static analysis practices.",[16,104,105],{},"In other words, if you bring a Sandbox-stage project that doesn't meet these criteria into a production cluster, you should go in assuming you'll be the one handling any future migration or fork on your own.",[11,107,109],{"id":108},"why-harbors-graduated-status-became-a-reason-to-choose-it","Why Harbor's \"Graduated\" Status Became a Reason to Choose It",[16,111,112,113,118],{},"As a concrete example, look at Harbor, the container registry project. Harbor joined CNCF in July 2018, reached Incubating status that same November, and reached Graduated status in June 2020 (",[30,114,117],{"href":115,"rel":116},"https:\u002F\u002Fwww.cncf.io\u002Fprojects\u002Fharbor\u002F",[34],"CNCF's Harbor project page","). With vulnerability scanning, image signing, RBAC, and replication built in, Harbor sits on the critical path of production operations as a container registry — and its Graduated status became a meaningful backstop for adoption decisions.",[16,120,121],{},[22,122],{"alt":123,"src":124},"Timeline showing Harbor's journey from joining CNCF in 2018 to reaching Graduated status in 2020","https:\u002F\u002Fcdn.kubo.hexabase.io\u002Fimages\u002Fblog\u002Fcncf-project-maturity-graduation-criteria-production\u002Fsection03.webp",[16,126,127,128,133,134,139],{},"The same trajectory shows up in other major projects. ",[30,129,132],{"href":130,"rel":131},"https:\u002F\u002Fwww.cncf.io\u002Fprojects\u002Fcert-manager\u002F",[34],"cert-manager",", the certificate automation project, joined CNCF in November 2020, reached Incubating in September 2022, and reached Graduated in September 2024. The GitOps tool Argo graduated in December 2022, and the service mesh Envoy joined the ranks of graduated projects as the third project to do so, following Kubernetes and Prometheus. Kubernetes itself only reached the status of ",[30,135,138],{"href":136,"rel":137},"https:\u002F\u002Fwww.linuxfoundation.org\u002Fpress\u002Fcloud-containers-virtualization\u002Fcloud-native-computing-foundation-announces-kubernetes-first-graduated-project",[34],"CNCF's first-ever graduated project"," in March 2018 after building up a documented governance structure and a committer base spanning multiple organizations.",[16,141,142],{},"The common thread across all of these is clear: none of them graduated simply because they had a rich feature set. They graduated because they built a structure where multiple organizations share responsibility for operating the project. When you're making a technology selection decision, what you should actually be evaluating isn't the feature list — it's whether that structure exists.",[11,144,146],{"id":145},"designing-a-production-k3s-cluster-that-absorbs-this-selection-cost-for-you","Designing a Production K3s Cluster That Absorbs This Selection Cost For You",[16,148,149],{},"That said, researching the CNCF maturity stage of every individual component and checking committer diversity for each one is real, ongoing operational overhead. Plenty of infrastructure teams are redoing this research from scratch every time they make a technology selection.",[16,151,152],{},[22,153],{"alt":154,"src":155},"Architecture diagram showing a standard K3s cluster with Rancher, cert-manager, and Prometheus\u002FGrafana built in","https:\u002F\u002Fcdn.kubo.hexabase.io\u002Fimages\u002Fblog\u002Fcncf-project-maturity-graduation-criteria-production\u002Fsection04.webp",[16,157,158,159,164,165,168],{},"One way to handle this is to bake that selection cost into the underlying stack itself. ",[30,160,163],{"href":161,"rel":162},"https:\u002F\u002Fkubo.hexabase.io\u002F",[34],"Kubo"," provides a production-grade Kubernetes environment built on K3s with the Rancher management plane, automated certificate management via ",[30,166,132],{"href":130,"rel":167},[34],", and standard monitoring via Prometheus + Grafana, all pre-integrated. Instead of evaluating each CNCF project one by one and assembling your own stack, you get a foundation of components with an established production track record already in place — a value proposition that sits between fully managed Kubernetes services like EKS\u002FAKS and building everything yourself.",[16,170,171,172,177],{},"For industries with strict security requirements that need on-premises operation, ",[30,173,176],{"href":174,"rel":175},"https:\u002F\u002Fwww.hexabase.com\u002Fproduct\u002Fkubo\u002Fon-premise",[34],"Kubo On-Premise"," is also worth considering, since it lets you reproduce the same standard stack while retaining full data sovereignty. How much you can reduce the cost of re-researching CNCF maturity criteria at the stack-selection stage is a quiet but significant factor in how much bandwidth your operations team has left for everything else.",[16,179,180,181,184,185,190],{},"If you're currently weighing whether to bring a Sandbox-stage project into production, it's worth comparing it against ",[30,182,163],{"href":161,"rel":183},[34],"'s standard stack to see whether that risk is really worth taking. If you're unsure, you can also reach out via ",[30,186,189],{"href":187,"rel":188},"https:\u002F\u002Fwww.hexabase.com\u002Fcontact-us\u002F",[34],"Contact Us"," to talk it through.",[11,192,194],{"id":193},"summary","Summary",[16,196,197],{},"When choosing a CNCF project, GitHub star count and commit frequency are just entry-level signals. What actually matters is whether the project has reached the Sandbox, Incubating, or Graduated maturity stage — and what that stage tells you about whether multiple organizations are sharing responsibility for its continued operation. Projects like Harbor, cert-manager, and Argo didn't earn production trust through a rich feature set; they earned it through a mature operating structure.",[16,199,200,201,204],{},"Before you add a new piece of open source software to your Kubernetes cluster, take a moment to check what stage it's currently at. And consider putting a standard stack like ",[30,202,163],{"href":161,"rel":203},[34]," on the table as a foundation that saves you from repeating that check every single time — it's one more way to protect your operations team's long-term capacity.",{"title":206,"searchDepth":207,"depth":207,"links":208},"",2,[209,210,211,212,213],{"id":13,"depth":207,"text":14},{"id":48,"depth":207,"text":49},{"id":108,"depth":207,"text":109},{"id":145,"depth":207,"text":146},{"id":193,"depth":207,"text":194},"2026-08-19","When adopting CNCF projects for your Kubernetes stack, are you judging them by GitHub stars and name recognition alone? Learn the Sandbox\u002FIncubating\u002FGraduated maturity framework and the Harbor case study to know what to check before production.","md","https:\u002F\u002Fcdn.kubo.hexabase.io\u002Fimages\u002Fblog\u002Fcncf-project-maturity-graduation-criteria-production\u002Feyecatch.webp","en",{},true,"\u002Fblog\u002Fen\u002Fcncf-project-maturity-graduation-criteria-production",{"title":5,"description":215},"blog\u002Fen\u002Fcncf-project-maturity-graduation-criteria-production",[225,226,227,228,229],"k3s","kubernetes","cncf","oss-governance","container-registry","m5lFSutEh4xs4r0V3tLuqYLA0oGtvoniAGC5bklGafs",[232,239,247,255,263,273],{"path":233,"title":234,"description":235,"date":236,"tags":237},"\u002Fblog\u002Fen\u002Fk3s-harbor-private-registry-docker-hub-rate-limit","The Morning Docker Hub's Free Tier Freezes Up, Your K3s Cluster Quietly Grinds to a Halt: When to Run Your Own Harbor","Docker Hub's pull rate limit is an increasingly real risk to image pulls on production K3s clusters. Kubo explains the design decisions and hidden costs of self-hosting Harbor, a CNCF Graduated project.","2026-08-23",[225,226,238,229,227],"harbor",{"path":240,"title":241,"description":242,"date":243,"tags":244},"\u002Fblog\u002Fen\u002Fkubernetes-ebpf-inspektor-gadget-observability","No strace. No Sidecars. Still Debuggable: Inspektor Gadget's Answer for Seeing Inside Kubernetes with eBPF","When you can't add a privileged container or inject a sidecar into a production Kubernetes cluster, how do you diagnose Pod traffic and syscalls? We explain how the eBPF tool Inspektor Gadget works, and what happened to it in 2026.","2026-08-15",[225,226,245,246,227],"ebpf","observability",{"path":248,"title":249,"description":250,"date":251,"tags":252},"\u002Fblog\u002Fen\u002Fkubernetes-ai-inference-reversal-conformance-design","Inference Has Overtaken Training: What KubeCon Japan Revealed About Kubernetes Cluster Design in the AI Era","AI compute demand has flipped from training to inference, with inference compute projected to reach 1.5x training capacity by 2030. Drawing on KubeCon Japan discussions and the CNCF AI Conformance Program, this article outlines what Kubernetes\u002FK3s clusters need to look like in the inference era.","2026-08-01",[226,225,253,227,254],"ai-inference","managed-kubernetes",{"path":256,"title":257,"description":258,"date":259,"tags":260},"\u002Fblog\u002Fen\u002Fcncf-graduated-project-oss-selection-criteria","Should You Trust the CNCF 'Graduated' Badge? What TOC Public Meetings Reveal About the Unglamorous Reality of the Review Process","The CNCF 'Graduated' badge is not a safety certificate. Drawing on TOC public meeting notes and official documentation, this article explains the real review process behind Sandbox, Incubating, and Graduated status, and how to judge OSS maturity before adopting it in production.","2026-07-23",[227,226,225,261,254,262],"oss","governance",{"path":264,"title":265,"description":266,"date":267,"tags":268},"\u002Fblog\u002Fen\u002Fk3s-container-image-security-supply-chain-checklist","'Scanned' Is Not a Production Clearance Certificate: K3s Container Image Security From Signing to Admission Control","Container security guidelines often stop at 'we run a scanner.' This guide walks through the practical checklist you need to pass before production in K3s: minimal base images, vulnerability scanning, SBOM generation, signing, and admission control.","2026-08-24",[225,226,269,270,271,272],"container-security","image-scanning","sbom","supply-chain-security",{"path":274,"title":275,"description":276,"date":277,"tags":278},"\u002Fblog\u002Fen\u002Fkubernetes-cost-management-eks-aks-billing-visibility","Your EKS Bill Only Makes Sense at Month-End: Why Kubernetes Costs Are Structurally 'Discovered Too Late'","Why do Kubernetes costs on EKS\u002FAKS balloon unexpectedly? We break down how autoscaling and cross-AZ billing hide costs, and explore how K3s-based managed infrastructure turns them into a fixed cost.","2026-08-22",[225,226,279,254,280,281],"cost-optimization","aks","finops",1787649514851]