Skip to content

CNCF Incubation Readiness: Roadmap from Sandbox to Incubating #1187

Description

@arska

Goal

Move K8up from CNCF Sandbox to Incubating status. This issue tracks requirements, current state, gaps, and concrete next steps.

Current State (March 2026)

K8up has been a CNCF Sandbox project since 2021. Production-ready since 2019, 971 GitHub stars, 109 forks, 92+ contributors over project lifetime.

LF Insights Metrics (dashboard)

Metric Value Assessment
Health Score 73% Good
Quarterly Active Contributors 12 Needs growth
Contributor Retention 25% Needs improvement
Contributor Dependency 2 people = 51%+ High risk
Org Dependency 1 org = 51%+ Blocker
GitHub Stars 971 Decent
Active Days 211/365 Good
Issue Resolution Time 54 days avg OK
Build & Release Score 100% Excellent
Access Control Score 100% Excellent
Legal Score 43% Needs work
Quality Score 71% Good
Governance Score 50% Needs work

Requirements Assessment

✅ MET

Requirement Evidence
Governance documented GOVERNANCE.md
Maintainers listed with affiliations OWNERS.md (5 maintainers)
Code of Conduct CNCF CoC adopted
CODEOWNERS + branch protection Configured
SECURITY.md Added (#1167)
OpenSSF Best Practices badge Project #5388
Signed releases Cosign keyless OIDC via GoReleaser
Access controls (2FA, branch protection) Enforced
ADOPTERS.md 4 organizations listed
CNCF ecosystem integrations Kubernetes, Prometheus, Helm
Contributing guide In docs site
Public comms (Slack) CNCF #k8up channel
Public meetings Monthly, first Monday
Architecture docs architecture.adoc
Public roadmap GitHub Projects #2
Release process documented release.adoc
User/install docs docs.k8up.io (Antora)

⚠️ PARTIALLY MET

Requirement Current State Gap
Multi-org maintainers All 5 from VSHN Need 1-2 from other orgs
Maintainer lifecycle Governance exists but steering committee "to be built" Formalize onboarding/offboarding/emeritus
3+ independent adopters 4 listed in ADOPTERS.md Need 5-7 contacts willing to do TOC interviews
Contributor activity 12 quarterly, 25% retention Target 20+ quarterly, improve retention
Vendor neutrality VSHN-dominated maintainership and direction Demonstrate multi-org governance
OpenSSF Best Practices 100% Badge exists but LF Insights shows Legal 43%, Governance 50% Audit and fix gaps

❌ NOT MET

Requirement What's Needed
Security Self-Assessment Complete TAG Security template
TAG engagement Present to TAG Operational Resilience or complete a General/Domain Technical Review

Proposed Roadmap

Phase 1: Quick Wins (1-2 months)

  • Audit and reach 100% on OpenSSF Best Practices badge
  • Grow ADOPTERS.md to 8-10 organizations; identify 5-7 willing to do TOC interviews
  • Formalize maintainer lifecycle in GOVERNANCE.md (onboarding, offboarding, emeritus)
  • Fix Legal score — audit DCO/license compliance across all 7 repos
  • Create "good first issue" labels and contributor onboarding docs

Phase 2: Community Building (3-6 months)

  • Recruit 1-2 maintainers from outside VSHN (candidates: active external contributors from b1-systems, community members)
  • Establish contributor ladder (contributor → reviewer → maintainer)
  • Improve contributor retention from 25% toward 50%+
  • Grow quarterly active contributors from 12 to 20+
  • Set up regular office hours or contributor mentoring sessions

Phase 3: CNCF Process (6-9 months)

  • Complete Security Self-Assessment with TAG Security
  • Present to TAG Operational Resilience or request General Technical Review
  • Prepare incubation application using CNCF TOC template
  • Submit application to cncf/toc

References

Source for Requirements

All requirements are from the official CNCF TOC Incubation Application Template (v1.6). Key required items:

  • Security Self-Assessment: Required — "Document Security Self-Assessment" (TAG Security guide)
  • TAG engagement: Required — "Engage with the domain-specific TAG(s) to increase awareness through a presentation or completing a General Technical Review" → TAG Operational Resilience
  • Adopters: Required — "at least 3 independent + indirect/direct adopters" with TOC verification interviews (5-7 contacts)
  • OpenSSF Best Practices badge: Required — "Achieve the OpenSSF Best Practices passing badge" → K8up badge

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions