ContainerDays
Lets try Fedora Silverblue — an immutable desktop OS! - Adam Šamalik
updated
About the speakers:
Alexander Schaber: With a lifelong passion for technology, I embarked on my journey as a freelancer, honing my skills initially as a sysadmin. As the tech landscape evolved, I transitioned into the world of DevOps. Recognizing the transformative power of cloud and container technologies, I founded my own company, specializing in DevOps consulting.
Rene Schramowski: Driven by Open Source and Open Knowledge, René feels comfortable in the cloud native space with Kubernetes and OpenShift and has a passion for mobile development with Flutter. Working in the Community has a special place in his heart and by organizing events like OpenShift Anwendertreffen, Flutter Hamburg and DevFest Hamburg, he engages with it regularly.
In this talk, Cansu will share a practical and opinionated journey on how platform engineers can embrace AI, not as data scientists, but as enablers. From bootstrapping an internal AI platform with the tools you already know (like Kubernetes and containers) to supporting GenAI-specific needs like RAG, fine-tuning, and agents, this session will cover what stays, what changes, and where new responsibilities emerge.
Whether you're starting to explore AI in your organization or are deep in scaling it, this talk will help you position platform engineering at the center of your company’s AI transformation.
About the speaker:
Cansu Kavili Örnek: As an AI platform architect at Red Hat's AI Business Unit, Cansu is bridging DevOps & MLOps to build scalable AI platforms. Passionate about open source, platform engineering, and driving AI adoption. Focused on delivering real customer impact by aligning architectures with business outcomes ✨
In this talk, we’ll break down what virtual clusters are, why they’re becoming essential for platform engineering, and how they help teams balance speed, security, and efficiency. We’ll also take a deep dive into k3k, an open-source implementation of virtual clusters and explore a few concrete use cases.
Whether you’re focused on empowering developers, optimizing infrastructure costs, or simplifying operations, virtual clusters open up new possibilities for modern platforms.
You’ll walk away with a clear understanding of the benefits, trade-offs, and practical use cases for adopting virtual clusters in your own Kubernetes strategy.
About the speaker:
Rossella is a Director of Engineering in SUSE's Rancher group. Her journey at SUSE includes a series of impactful leadership roles, building on a foundation of significant contributions to the broader open-source community—including her time as a Core Reviewer for OpenStack Neutron and as a member of the Linux Foundation Networking's Technical Advisory Committee.
During my session you will learn how and why you should use network polices. I will give you an overview of currently available options to secure your pod network traffic. I will also demonstrate how to use regular network polices, cluster wide polices and host polices. During the demo we will focus on implementing polices to a running cluster. Showcasing software like Cilium and Hubble which can be extremely helpful in visualising cluster traffic. This talk should help you demystify network polices and give you some great arguments to get started with securing your production cluster.
About the speaker:
Simon Pearce is a Kubernetes & Cloud consultant at SysEleven working on improving the customer journey. He supported building MetaKube SysEleven's managed Kubernetes platform. Which currently hosts over 300 Kubernetes clusters. He resides in Berlin, Germany with his partner and their daughter Stella. Hobbies and interests include Cyclocross, Gravel cycling, gaming, Linux and home automation.
This session features a live demo with a Raspberry Pi, camera, and real-time AI detection. Watch as our edge device identifies raised hands, sends data to a Kubernetes cluster via KubeEdge, and visualizes results instantly.
We'll explore:
- Edge Kubernetes challenges: connectivity, resources, security
- KubeEdge's approach to decentralized workloads
- Real-world applications across industries
Join us to see how AI, Kubernetes, and edge computing converge to enable powerful new possibilities.
Additional notes
We will bring a raspberry pi with a camera to demonstrate edge computing and make it a bit more fun :).
About the speakers:
Antonia von den Driesch has been a platform engineer at Giant Swarm for 5 years and is currently working on development of Giant Swarms Industrial IoT platform which brings their managed Kubernetes product to Smart Factory customers.
Simon Weald is a Site Reliability Engineer living in the UK, working remotely for Giant Swarm. He’s into keeping infrastructure tidy, running Kubernetes clusters without drama, and helping dev teams ship things reliably. He spends most of his time thinking about observability, automation, and making sure systems behave when things go sideways. Simon’s got a strong interest in open source and likes to tinker with new tools in his spare time.
This abrupt termination can cause problems like data loss or system instability.
Thankfully, there's a better way: the graceful shutdown.
In this session we'll focus on Go applications running on Kubernetes.
Additional notes
I am the author of this article - https://packagemain.tech/p/graceful-shutdowns-k8s-go
About the speaker:
Alex Pliutau: Staff Software Engineer BINARLY | Docker Captain | Passionate about Backend, Go, DevOps, Kubernetes | Youtube: youtube.com/@UCI39wKG8GQnuzFPN5SM55qw
Additional notes
"Breaking Kubernetes for Fun and Profit" is a fast-paced, hands-on talk that dives into real-world security pitfalls lurking in many Kubernetes clusters. Through live demos and war stories, we’ll explore how simple misconfigurations — like overly permissive RBAC, exposed dashboards, or unscanned containers — can lead to full cluster compromise. You’ll see how attackers think, how they move laterally inside your cluster, and what tools can detect and stop them. This session isn’t just about breaking things — it’s about learning how to build safer, more resilient Kubernetes environments by thinking like a hacker.
About the speaker:
Ali Alp is a seasoned Distinguished Software Engineer and Architect with 15+ years in IT, specializing in Kubernetes, containerization, and cloud transformation. Passionate about Linux and building resilient, scalable systems. Expert in on-prem and cloud infrastructure, driving efficiency through modern architecture and automation.
In this talk we will highlight the Kubernetes Operator Pattern and the interaction with CRDs using a practical example, including architectural considerations and concrete code snippets.
Content of the talk:
- What exactly are Operators and CRD`s and how do they interact with each other
- What are the advantages of this pattern and what challenges could we face
- How do I easily create a template for my CRDs or operators with tools like kubebuilder?
- How do I write my own operator in Go
- The reconciliation loop - How Kubernetes controllers work in practice.
About the speakers:
My name is Michael Morlock, and I’ve been working in IT for around eight years with a focus on cloud-native software development. I primarily design and implement microservice architectures in Go and also have experience with front-end frameworks like SolidJS. At ATIX AG, I’ve gained hands-on experience with Kubernetes Operators, which I’ll explore in this talk using practical examples.
Vincent Welker is an expert in customized, application-centric container infrastructure with extensive experience. As a DevOps engineer, his knowledge ranges from software development to operations. He helps customers establish a DevOps culture and implements common technology stacks. His expertise is particularly in containerization and migration of existing applications.
- VerticalPodAutoscaler (VPA)
- HorizontalPodAutoscaler (HPA)
- Knative
- Kubernetes Event-driven Autoscaling (KEDA)
Through real scenarios—constant load, "business hours" patterns, spiky traffic, and varied container types—we’ll show how to set up, operate, and fine-tune these tools. You'll gain insights into their pros and cons, learn how to monitor them effectively, and evaluate their impact in different environments.
Additional notes
I am a creator of several tutorials on Killercoda:
- killercoda.com/ica-scenarios
- killercoda.com/postgresql-on-fire
Some of my recent sessions:
- youtu.be/eI7TDDa_Pm4?si=tRvz7yN0NIjE-bBn
- youtube.com/watch?v=8nF6t7qacpQ
- youtube.com/watch?v=eHgQO0Yh6pw
- youtube.com/watch?v=wmfdF4Z-uYc
About the speaker:
David Pech is an accomplished DevOps professional with 20 years of experience. Proficient in a wide array of technologies within the Kubernetes and CNCF ecosystem, with a focus on producing high-quality, sustainable software solutions. Known for a pragmatic and security-conscious approach to technology adoption. Passionate about educating and enabling teams in the adoption and understanding of cloud technologies.
Running databases, Kafka, Elasticsearch, and even cloud technologies, straight from your test code ensures environment config is always up-to-date and consistent during local development and in CI pipelines.
You’ll learn everything necessary to start adding powerful integration tests to your codebase without the headache of managing external service dependencies manually!
About the speaker:
Manuel de la Peña is an OSS Software Engineer at Docker where he maintains "Testcontainers for Go". In every job he tries to improve the quality of the software products and processes from the automation and testing point of view.
Manuel holds a BS in CS (UNED Spain), and a Matter degree in Research in Software Engineering (UNED Spain). You can find him on Internet as "mdelapenya" everywhere.
What makes this approach exciting is that we will use tools that the customer already had in place at the enterprise level. The goal was to create a first version of the platform that fits into the existing environment instead of introducing completely new technology.
Additional notes
Blog about this topic: medium.com/itnext/how-to-build-a-multi-tenancy-internal-developer-platform-with-gitops-and-vcluster-d8f43bfb9c3d
Webinar about this topic: youtube.com/watch?v=7p1GdyS7kmA
About the speaker: Artem Lajko, certified Kubestronaut and Platform Engineer, specializes in GitOps and Kubernetes scalability. Author of Implementing GitOps with Kubernetes, co-founder of connectii.io, and IT freelancer writing for ITNEXT.
As a Platform Engineering Ambassador, he drives adoption of Internal Developer Platforms, aiding companies in tech selection, best practices, and Open Source innovation.
However, some companies and developer teams are unsure about fully adopting API-first. They worry it might be hard to connect systems or require more planning at the start.
In this talk, we will take a closer look at these concerns to see if they are really as difficult as they seem. You'll be able to take away the key benefits of the API-first approach, especially for GoLang developers. Furthermore, we will discuss how tools such as oapi-codegen for OpenAPI and asyncapi-codegen for AsyncAPI can speed up development processes, improve workflows, and avoid common mistakes.
About the speakers:
Artur Iablokov is a software engineer at Lufthansa Industry Solutions, specializing in cloud-native development and architecture. With a solid track record across finance, energy, and logistics sectors, he spends most of his time building scalable microservices and crafting efficient APIs.
Benedikt Dahm is a software engineer at Lufthansa Industry Solutions.
Let me show you three different GitOps Promotion Tools: Kargo, GitOps Promoter, and Telefonistka. I will explain how they work, what the pros and cons are, and how you can apply them in your GitOps workflows. I also deep dive into the new emerging pattern of "rendered manifests" and how it influences the promotion process.
Additional notes
On this page, I have most of my public talks listed: sessionize.com/engin-diri
I am going to talk about following OSS tools:
- Argo CD
- Kargo
- GitOps Promoter
- Telefonistka
- Kubernetes
About the speaker:
Engin Diri: As a Senior Solutions Architect at Pulumi with over 15 years of experience in the IT industry, including roles at the Schwarz Group and W&W Versicherungen, I bring extensive expertise with an end-user and enterprise focus. Currently working for a startup while collaborating with enterprise clients has further enriched my experience!
About the speaker:
Christian Fritz is a software architect at QAware GmbH. He is enthusiastic about everything in the cloud-native environment and is currently concerned with the security between individual microservices.
While Kubernetes is designed for flexibility and scalability, it does not provide guarantees for performance-sensitive workloads by default. Without the right configurations, latency-sensitive applications can suffer from unpredictable scheduling, resource contention, and noisy neighbor effects.
This talk distills some of the lessons learned from running SpiceDB - a low-latency authorization system, on Kubernetes and how we got to 5ms p95 @ 1M Requests Per Second. The talk covers
1. Understanding and Mitigating Kubernetes Defaults
2. Advanced Resource Management Strategies
3. Scaling for Performance
By the end of this talk, attendees will understand the practical steps required to reduce unpredictable latency in Kubernetes environments. Whether you're running a global-scale system or fine-tuning a critical microservice, these best practices will help ensure your workloads run smoothly under the highest demands.
Additional notes
Have spoken at 100+ international conferences including AWS Re:Invent, KubeDay, Web Summit and more
A selection of talks can be found here: sohan.co/videos.html
About the speaker:
Sohan Maheshwar is a Lead Developer Advocate at AuthZed, based in the Netherlands. He started his career as a developer building mobile apps and has worked in the developer relations space since 2013, in companies such as Amazon, Fermyon and InMobi.
He has always been interested in emerging technologies and how it shapes the world around us.
At BaneNOR, we have all the bells and whistles, and platforms of all sorts. Application, data, integration, and everything from state of the art technology, to legacy systems. How this is structured is a continuous work in progress and evolves in tandem with what the community discovers. Every day try to give developers a good place to run applications, while keeping stakeholders up to date, while keeping everything secure and compliant.
In this presentation we want to go through some of our strategic technical and sociotechnical choices, as well as pain points, pitfalls and low-hanging fruits. All on board the Platform Engineering express train!
Additional notes
This session is an end-user story, and was presented for the first time at Platform Engineering day during KubeCon London 2025. We will present both the technical and non-technical side of building platforms, sharing both the highs and lows of the journey.
About the speakers:
Roberth Strand is a self-proclaimed "cloud automator", and works primarily with Platform Engineering, DevOps and Cloud Native technology. He has been awarded the title Microsoft Azure MVP, CNCF Ambassador, and has been an active speaker for several years, talking at everything from small local meetups to KubeCon.
Manfred Bjørlin: Azure Cloud architect and C# developer with a passion for integration and automation. But wait, it's more! Passion does not only have to be in tech! There is also a burning passion for neurodiversity and diversity in tech, across ages, genders, identities, etc... Loves integration, automation and data security. A back-end developer for over 20 years. Have worked with building integration platforms in Azure for several bigger organizations. Worked with .Net since early 2000, and Azure since launch. Have a big engagement for diversity at the workplace, everything from neurodiversity and gender identity to cultural background and visible and invisible disabilities.
Problem & Naive Solutions
The pattern solves the dual-write problem when storing data and publishing events. Writing to a DB first risks losing messages; writing to a queue first risks inconsistency. Holding a DB transaction open while sending events can exhaust connections.
Outbox Table & Relay
A safer approach is inserting events into an outbox table within the DB transaction. The challenge is efficiently reading and publishing them.
Implementations
Debezium (Java, CDC) has high memory overhead.
Polling in Go (SELECT + UPDATE) creates dead tuples.
Offset tracking avoids updates (Watermill SQL).
Logical replication in Go (jackc/pglogrepl) is promising but complex.
Outbox remains relevant in 2025, with emerging Go solutions.
About the speaker:
Nikolay Kuznetsov is a Senior Software Engineer at Zalando Finland. He is an author of pgx-outbox Go library and CDC (change data capture) enthusiast. He is a regular speaker at Go meetups in Helsinki and occasionally at international conferences.
Memory is finite, and mismanagement can lead to leaks, crashes, and poor performance. Garbage collection (GC) automates this process, but it comes with trade-offs. Go’s GC is designed for efficiency and low latency, but understanding its inner workings helps write better code.
In this talk, we’ll explore:
- Stack vs. heap allocations and why one is slower.
- What data is stored where.
- Escape analysis: how Go decides memory placement.
- How Go GC works and its impact on performance.
- Practical GC tuning strategies for optimizing applications.
By the end, you'll gain a deeper understanding of Go’s memory model and techniques to optimize your applications.
About the speaker:
Aleksandr Rybolovlev: I am an experienced software engineer and technical leader with a passion for Kubernetes and cloud-native development. With my background in networking, I bring a deep knowledge of distributed systems, performance optimization, and Linux internals. I am also a mentor, an open-source contributor, and an avid attendee of technology conferences.
The operator uses the same "claim" model found in Kubernetes – e.g. in the PersistentVolume Controller – to differentiate desired and observed states. The user only defines a high-level intent which the operator will process to reserve a resource, like IPs, in NetBox.
In this talk, we’ll demonstrate how the NetBox Operator simplifies the automation of MetalLB IP Address Pools, enabling zero-touch configuration for ingress networking in your Kubernetes clusters. We’ll also highlight advanced features like sticky IP assignments for power users. By simplifying resource management, the operator lets engineers focus on higher-level tasks, enhancing scalability and agility across infrastructures, including the 5G core.
Additional notes
The repositories for netbox-operator can be found here: github.com/netbox-community/netbox-operator
Previous Presentations:
- colocatedeventseu2025.sched.com/event/1uB8N
- NetBox Community Call: youtu.be/cYdocbdSzHs?t=1429
Evolving GitOps: Harnessing Kubernetes Resource Model for 5G Core - OSS Europe 2024 -
- sched.co/1ej4I
About the speaker:
Lea Brühwiler is a DevOps Engineer at Swisscom, with a focus on automation for cloud-native 5G core.
Are you ready for the CRA? Spoiler: Most aren't.
According to a Linux Foundation Survey, 62% of companies have low familiarity with the requirements. Don't get caught flat-footed. "CYA before CRA" isn't just a catchy phrase – it's your survival strategy.
Let's explore how Open Source already can help you to proactively assess and mitigate risks with tools for SBOM generation and threat detection. How you can use the same tooling OSS is using to identify vulnerabilities before they become compliance nightmares. Learn to turn compliance into a competitive advantage by demonstrating your commitment to security and Open Source. This is an opportunity for companies and the OSS community to unite and address the CRA's challenges collaboratively.
About the speaker:
Mario Fahlandt, a Kubermatic Customer Delivery Architect, focuses on cloud-native infrastructure and passionately supports the Open Source Community. He co-chairs Kubernetes SIG ContribEx, engages with CNCF Cross Project Tooling, and contributes to the GUAC SBOM platform.
He is also a Googlde Developer Expert and Community Leader for a GDG.
You’ll learn how to run both lightweight functions and long-running services globally, and trigger them over NATS, without relying on Kubernetes, FaaS platforms, or cloud vendor lock-in.
Through practical and fun examples, you’ll discover how NATS is becoming a simple, fast, and flexible distributed compute platform for the edge, data centers, and sovereign infrastructure.
About the speaker:
Luc Juggery: I’m a software engineer with 20+ years of experience in startups and large companies, including co-founding roles. I stay up to date through side projects, courses, and tech events, as a speaker or attendee. I’m passionate about containers, Kubernetes, DevOps, and Cloud Native ecosystem, and I love learning, teaching, and sharing knowledge.
The path isn't straight. What about CI when CD seems impossible? Or when nobody touches legacy code? Or security scans get ignored? This talk shares lessons about gradually introducing CI and Sec, modernizing resistant systems, and exploring AI at the edge. Balancing innovation with practicality takes experimentation, especially when adding responsible AI guardrails, context, and agentic workflows.
Tired of reinventing wheels? This session offers practical strategies that can save countless hours. Expect honest talk about debugging nightmares and overwhelming failures. We’ll demo how CI and AI change perspectives with embedded development and hardware in the loop. Bring your toughest problems – we’ll tackle them together live or after the talk.
About the speaker:
Michael Friedrich is a Staff Developer Advocate at GitLab, focus on Embedded DevSecOps and responsible AI adoption. “How does a computer work?” led him from Hardware/Software Systems Engineering to DNS, monitoring, and authoring GitLab training. Michael loves to educate and regularly speaks at industry events and meetups. When not traveling, he builds LEGO models and embedded hardware projects.
But what happens when facing more complex challenges? How do you debug advanced rules or test them in an automated way?
In this talk with a live demo, I will walk through practical techniques for working with Kyverno beyond the basics:
- Implementing advanced validation rules
- Exploring effective debugging strategies
- Using the Kyverno CLI and automated testing for quality assurance
By the end of this talk, you’ll be able to apply advanced policy techniques that make your Kubernetes workloads more secure and dependable.
About the speaker:
Marie Padberg is a DevOps Engineer at infologistix GmbH and passionate about Kubernetes and related security mechanisms. She supports customers in building secure, highly available container platforms based on Kubernetes, implementing services like container build pipelines and security mechanisms. Additionally, Marie provides training to help teams become familiar with cloud-native technologies.
About the speaker:
Alexandre Cabral is a Senior Software Engineer at Stone Co. Brazilian code breaker from Minas Gerais. Go GDE. A proud orange cat dad. Electronics Engineer. Co-founder of Tech Hub JF, a non-profit Brazilian tech events community. Mentor and international speaker, including GopherCon Latam and GoLab. Worked for companies from the US, Brazil and Germany. Some years ago I met the Gopher, and now I'm one of the Go lovers.
Using real-world examples, we demonstrate how infrastructure can be deployed across cloud and on-premises environments in a consistent, scalable, and developer-friendly way.
We show how OpenMCP enables developer self-service, ensures governance and compliance through policy-driven management (e.g. Kyverno), and promotes a clear separation between platform and application teams.
It's ideal for DevOps teams, platform engineers, and Kubernetes enthusiasts looking to build efficient, secure, and scalable platforms with Crossplane.
About the speakers:
Steffen Kelch: From early roots in web development and SAP consulting, my journey evolved through enterprise architecture to cloud-native solutions.
In my current role at Cloud Native Lifecycle Management @ SAP, I combine my expertise with cloud technologies to drive innovation and enterprise grade automation of infrastructure-as-data on a global scale.
Alfred Schmid: My journey began in 1985 with a C64 and a passion for solving problems through code. From BASIC to assembler demos, I’ve always explored what technology can do. Today, I work on Kubernetes-based solutions using Helm templating. I’m driven by curiosity, constantly exploring new tools to tackle real-world challenges and help customers stay ahead of the curve.
About the speaker:
Geetha Anne is a Solutions Architect and Customer Success professional specializing in big data management , storage , Kubernetes and Durable execution, with expertise in cloud-native and on-premises solutions. She ensures customer success and maturity by delivering effective, simplified solutions.
They introduce a new way to manage and standardize OS deployment and upgrades using tailored container images.
They reduce complexity across the enterprise by letting development, operations, and solution providers use the same container-native tools and techniques to manage everything from applications to the underlying OS, simplifying security and integrating the process of creating OS Images in your existing CI/CD workflows, allowing you to use the same logic for your application and your OS deployments.
During this session we will:
- Introduce bootc-containers concepts and building blocks
- Identify the core use cases and benefits bootc-containers introduce
- Demonstrate live how easy it is to build, deploy and manage updates/upgrades for a system based on bootc-containers.
About the speaker:
Alessandro Rossi is an EMEA Associate Principal Specialist Solution Architect for Red Hat Enterprise Linux with a passion for cloud platforms and automation. Alessandro joined Red Hat in 2021, but he's been working in the Linux and open source ecosystem since 2012.
He's done instructing and consulting for Red Hat and helped organization implementing large scale projects.
You’ll learn how even well-optimized backend systems can still face delays of several seconds due to network factors. We’ll introduce the "Time to Backend" metric, showing why focusing on broader network issues is more impactful than fine-tuning your code for micro-optimizations.
Join us to see how this metric helped improve monitoring systems and shift our focus from internal infrastructure to understanding the wider mobile ecosystem.
Additional notes
- Understanding the True Latency Impact: It's crucial to recognize that delays from mobile networks and internet providers can significantly affect application performance, often more than backend optimizations.
- The Importance of the 'Time to Backend' Metric: This new metric—tracking the time it takes for a request to reach your backend—helps identify hidden latency issues and provides more accurate insights into user experience.
- Focusing on End-to-End Performance: While backend optimization is essential, optimizing the entire request journey, including network-related delays, should be a priority to ensure faster, more reliable user experiences.
- Reevaluating Optimization Priorities: It's essential to shift focus from micro-optimizations to understanding and mitigating delays introduced by external networks and services like mobile providers, Cloudflare, and AWS.
- Improved Monitoring and Incident Management: Creating effective monitoring tools, such as dashboards and alerts based on the "Time to Backend" metric, helps identify and address issues more quickly, reducing the impact on users.
About the speaker:
Andrii Raikov has a total of 17 years of software engineering experience and has been very passionate about Go for the past 6 years. Over the past 4 years at Delivery Hero, he has adeptly harnessed Golang, excelling in constructing high-load applications, leveraging Golang's concurrency capabilities to engineer scalable solutions that optimise performance and handle substantial data processing tasks.
About the speakers:
Shibi Ramachandran is a seasoned technical leader with over a decade of experience in Software development and distributed systems architecture.
He loves open source and contributes to the open source community with his blogs and conferences.
Ram Mohan Rao Chukka is a Senior Software Engineer at JFrog R&D . Previously worked for startup companies like CallidusCloud (SAP Company), Konylabs. Loves Automation, Linux, openSource
We’ll dive deep into the magic of container runtimes—the software that makes containers tick—and explore the core concepts of namespaces and cgroups that enable isolation and resource control. Through a hands-on demo, we’ll go step-by-step to create a basic container runtime from scratch, offering you an unparalleled understanding of the building blocks behind tools like Docker.
Whether you’re an engineer curious about how containers work or a professional seeking to deepen your technical expertise, this session will equip you with the knowledge to innovate with confidence in the containerised world.
Additional notes
1. Why This Talk Matters
- Bridges the Knowledge Gap – Many developers use containers daily but lack a deep understanding of container runtimes. This session breaks down the internals, helping attendees grasp key concepts like namespaces, cgroups, and process isolation.
- Hands-On and Practical – The session isn’t just theoretical; it includes a step-by-step **live demo** where attendees see a container runtime built from scratch, making it engaging and highly educational.
- Relevant to Cloud-Native & DevOps Practitioners – As the cloud-native ecosystem grows, understanding how container runtimes work is becoming essential for DevOps engineers, SREs, and backend developers.
2. Speaker Credentials
- Deep Technical Expertise – With 15+ years in software engineering, extensive experience in Go, Kubernetes, and DevOps, and contributions to open-source container-related projects, I bring a wealth of knowledge and practical experience.
- Open-Source Contributor & Thought Leader – I maintain several Go libraries, have contributed to container-related tooling, and have spoken on topics like scaling Go applications and building high-performance architectures.
- Strong Presentation & Teaching Skills – My previous talks have been well-received for their clarity, real-world relevance, and ability to break down complex topics into digestible insights.
3. Alignment with the Conference/Community Goals
- This session aligns perfectly with themes around cloud-native, DevOps, and scalable system design, which are critical in modern software development.
- The talk encourages open-source contributions by showing how container runtimes work under the hood, potentially inspiring new contributors to projects like `runc`, `containerd`, and similar tools.
4. Takeaways for Attendees
- A clear understanding of how containers work internally.
- The ability to troubleshoot and optimise container-based deployments more effectively.
- The confidence to explore container runtime development and contribute to the cloud-native ecosystem.
This session will be a unique, insightful, and engaging experience, and I’m confident it will provide great value to attendees.
About the speaker:
Ajitem Sahasrabuddhe is a technology consultant with 15+ years of experience in Go, Kubernetes, and scalable architectures. A key open-source contributor, he maintains Go libraries like `uilive` and `urfave/cli`. As a mentor and thought leader, he drives innovation in DevOps, cloud computing, and high-performance engineering.
This talk is a double feature: first, how and why people are running k8s on mainframes, from container orchestration to networking and real-world use. Second, how we used an IBM mainframe to attest kata-based confidential containers, tying remote attestation into cloud-native infra using hardware that predates TCP/IP.
We’ll cover the architecture and what it means when big iron starts enforcing modern security. If you think mainframes are just old boxes in cold rooms, think again—they’re running your microservices and verifying your enclave signatures.
About the speaker:
Josephine Pfeiffer is a consultant specializing in developer productivity and infrastructure. She has worked for enterprises, SMEs, and startups in roles spanning platform engineering, DevOps, Site Reliability Engineering, and technology management.
She is an active open-source contributor, contributing to Kubernetes-related projects such as Backstage and Kube-burner.
intellectual property theft. We will have a look at the popular tool "cosign" and how it can be used for signing images. It will also be covered how cosign can be integrated into your CI/CD pipelines to automate the process. A small side lesson of this session will show how to use cosign with the infrastructure of the major public cloud providers (AWS, GCP, Azure). Finally, we will check out how the verification of your signed images can be incorporated into your Kubernetes environments (e.g. by using Kyverno).
This talk is aimed to everybody that wants to improve their image and Kubernetes deployment security in general. Throughout the session we will present short demos for all steps so you can see the entire setup in action.
About the speaker:
Rene Schach started his career as a platform engineer, enabling 100+ product teams within organizations to use cloud technologies in an easy, fast and governed manner.
Currently, he works as a Cloud Consultant at shiftavenue where he focuses on solving problems together with customers while empowering people to create a permanent benefit for them.
About the speaker:
Fabio Berchtold is a Cloud Engineer at Swisscom
As with many things, a great pipeline operates seamlessly in the background, while a poorly designed one becomes a constant irritation.
Are you publishing your artefacts every time the pipeline runs, running all steps in a sequence, or installing all the tools every time a new build starts?
In this talk, I will address these antipatterns and more I have encountered during my work as a consultant, explaining why I consider them such and what you should do instead.
After listening to this talk, you will better understand what makes a pipeline great and concrete things you can do to improve it and shorten the feedback loop.
About the speaker:
Raniz Raneland is a programmer, architect, speaker and coach at factor10. He is a problem solver who keeps track of the bigger picture. He is prestigeless, and loves sharing knowledge and ideas. Raniz has worked with system- and software architecture at several companies since 2010 and has been with factor10 since 2021. When not working he's into beer brewing, sourdough bread, 3D printing and triathlons.
To explore this, we conducted interviews and created a survey to gather information from various organizations. Our goal was to determine if they apply product thinking principles in their platform engineering efforts.
In this presentation, we will outline our research objectives and data collection methods. We will then share our initial findings, highlighting common strategies, challenges, and best practices in platform engineering. Attendees will learn how other companies build their platforms and how to apply these lessons to improve their own platforms.
Join us to discover our early findings and see how they can help you develop more effective, user-focused platforms in your organization.
About the speaker:
Dominik Schmidle is a Technical Product Manager at Giant Swarm and on a mission to simplify developers' lives by delivering intuitive developer platforms.
He has been in the IT industry for over 9 years, starting his journey as a Full Stack Software Engineer falling in love with DevOps and Product Organisations to later become a Product Manager for Cloud Technology.
On top of OpenAPI, Kubenix exposes the core Kubernetes API for the functional language Nix.
This enables a fully declarative description of Kubernetes workloads with the best reproducibility, thus making YAML templating obsolete.
Kubenix's Helm wrapper provides access to the large ecosystem of the de-facto package manager for Kubernetes while preserving Nix's qualities.
With the ability to build reproducible OCI container images with Nix, Kubenix both simplifies and improves the definition of Kubernetes workloads.
After briefly introducing Nix itself, this talk will showcase Kubenix with practical use cases ranging from simple Kubernetes manifests to complex application stacks.
Let's make our Kubernetes workloads both declarative and reproducible!
About the speaker:
Arik Grahl is a Senior Software Engineer living between Berlin and Barcelona and has more than 13 years of experience in full-stack development and operation of infrastructure on bare metal.
At the moment he mainly develops Golang applications close to K8s and the broader cloud native ecosystem.
Furthermore, he is excited about everything evolving around Nix(OS) and enjoys contributing to Nixpkgs.
Join us for rail-world tales packed with real wins and humorous stumbles, where teams confront the ups and downs of platform adoption. Explore with us lively stories of cross-team cooperation, pushing boundaries and advancing platform development and adoption.
About the speakers:
Gualter Baptista has 25+ years of experience in IT strategy, cloud-native platforms, and DevOps. He uniquely bridges C-level strategy with hands-on developer enablement, driving scalable platform adoption through automation, data-driven insights, and cross-team collaboration, empowering teams to thrive in complex environments.
Metin Yaylacioglu is a Platform Enablement Coach at DB Systel dedicated to empowering delivery teams with help-for-self-help as a core principle. With over 20 years in IT, he provides expert guidance during the adoption process for internal platforms, designs and delivers engaging classroom trainings, and creates clear, actionable onboarding documentation and video trainings.
What if we could have the best of both worlds - stronger security without the overhead? The key lies in specialization.! Unikernels and lightweight, single-purpose kernels tailored for a single application offer VM-grade isolation while maintaining minimal resource usage and fast boot times.
This talk introduces urunc, a novel container runtime that enables seamless execution and management of unikernels and similar technologies as containers. The session includes a technical deep dive into urunc's architecture, a live demo of unikernels in k8s, and real-world use cases highlighting the advantages of this approach.
Additional notes
Repository: github.com/nubificus/urunc
Blog posts:
- blog.cloudkernels.net/posts/urunc
- blog.cloudkernels.net/posts/wasm-urunc
Previous talks:
- OSS 2023: osseu2023.sched.com/event/1OGgY
- FOSDEM 2024: blog.cloudkernels.net/posts/wasm-urunc
- KubeCon 2024: kccnceu2024.sched.com/event/1YeRd/unikernels-in-k8s-performance-and-isolation-for-serverless-computing-with-knative-anastassios-nanos-ioannis-plakas-nubis-pc
- FOSDEM 2025: fosdem.org/2025/schedule/event/fosdem-2025-6284-less-overhead-strong-isolation-running-containers-in-minimal-specialized-linux-vms
About the speaker:
Charalampos (Babis) Mainas is a systems software engineer who is very interested in virtualization technologies and operating systems. His main focus is on finding ways to improve the performance and scalability of lightweight VMMs. Moreover, he has considerable experience with unikernel stacks, porting applications, language runtimes, and trying to bring them closer to production.
About the speakers:
Sebastian Graf is Professor for Cloud Infrastructures at the University for Applied Sciences and Arts Northwestern Switzerland where he focusses on everything related to SRE, DevOps, Cloud Nativeness and Infrastructures as sourcecode.
Before being a professor, he worked in both, startups as well as large organizations in different roles like Software Developer, Software Architect, DevOps Engineer, Product Owner as well as Product Manager.
Esra Siegert is a Cloud Native System Engineer and Kubestronaut.
Additional notes
Earlier Klutch talks where focused on the framework's core architecture while this talk is focus on illustrating the scale of database automation enabled by Klutch. It's a deep-dive.
About the speaker:
Julian Fischer, CEO of anynines, has dedicated his career to the improvement and automation of software operations. In more than fifteen years, he has built several application platforms with various open source automation tools. His latest passions are Data Service Automation, Cloud Foundry, BOSH and Kubernetes.
About the speaker:
Felix Wenzel is an accomplished Senior Consultant working for shiftavenue. He thrives on crafting inventive solutions and automating processes, with a keen focus on Azure, Terraform, and Kubernetes. Always exploring the dynamic landscape of cloud technologies and emerging tools, Felix embodies a spirit of continuous learning and sharing within the tech community. Notably, he contributed to projects with enterprise entities like ECB, BMW and BASF, supporting various areas on their Cloud journey.
Join us on our journey of evaluating the two CNCF projects Cilium and K8GB against real-world scenarios with complex multi-cloud deployments. Learn about the benefits, challenges and trade-offs you should expect when choosing a hybrid cloud strategy with Kubernetes!
A practical live demo will share our hands-on experience, pros and cons, alongside use-case-specific solution recommendations for your hybrid-cloud journey.
About the speakers:
Nicolai Ort is a Cloud Platform Engineer at DATEV, a German software house and IT service provider specializing in solutions for tax consultants, auditors and lawyers. He is an advocate for using and contributing to open-source technologies. Nicolai has gained experience across various roles across the IT industry, including software development, platform architecture and infrastructure-ops.
Tobias Schneck is a Principal Architect at Kubermatic, an open-source platform for Kubernetes management. He is a passionate advocate for open-source technologies and has a deep understanding of cloud-native infrastructure. Tobias has over 10 years of experience in the IT industry and has held various positions in development, operations, and architecture. He is a regular speaker at industry conferences and has written numerous blog posts and articles on cloud-native topics. Bringing the advantages of cloud native technologies and development workflows to everybody is his aim.
In this talk, we’ll start from the very basics, explaining what LLMs are and busting some common myths. We’ll break down the key terms with simple diagrams and analogies that are easy to digest. You’ll get a clear, beginner-friendly look at how LLMs work, why Kubernetes is perfect for running them, and how they fit together in the cloud-native world.
We’ll even walk through running an LLM on Kubernetes using vLLM for some practical insights and touch on how this opens the door to AIOps. If you’re curious about stepping into the AI ecosystem and understanding its cloud foundations, this talk is for you.
This talk will empower attendees with a clear grasp of the concepts of Artificial Intelligence, Machine Learning, and Generative AI, the terms that are often muddled with confusion and hype. By busting myths and explaining how they differ and intersect within cloud-native technologies, participants will gain a solid foundation to navigate these concepts confidently. They’ll learn practical skills, like deploying Large Language Models on Kubernetes with vLLM, sparking inspiration to innovate and build real solutions. This clarity and hands-on know-how encourage beginners to join the community, expanding participation and diversity. Attendees will leave with actionable strategies to contribute effectively, driving project adoption and sustainability.
About the speakers:
Saloni Narang is a Co-founder at kubesimplify and previously worked at SAP Labs. She has worked on different cloud tools, including GCP, Oracle, and AWS. She loves to read about new open-source tools. She is also a Docker Captain and CNCF Ambassador.
Saiyam Pathak is a Principal Developer Advocate at Loft Labs and founder of Kubesimplify and BuildSafe, simplifying cloud native tech and supply chain security. A Kubestronaut and thought leader, he’s worked at Civo, Walmart Labs, Oracle, and HP, focusing on Kubernetes and DevOps. He shares expertise via blogs, meetups, and a YouTube channel with ~200 videos, driving innovation.
About the speakers:
Christian Melendez helps customers to build fault-tolerant, elastic, reliable, and cost optimized workloads in AWS. He’s passionate about Kubernetes, programming, and building tech communities. Christian has spent 15 years working in different companies to build modern solutions using the cloud.
Jan is a KEDA maintainer and spends most of his time with open-source technologies. He contributed to and helped to maintain various parts of the Kubernetes ecosystem.
Let's deep dive into it through one concrete example. Learn how to move from reactive OPS to resilient, real-time remediation, proving that agent-based engineering isn't just talk - it's the new platform engineering paradigm and it is NOW.
About the speaker:
Sebastian Kister is a world wide renowned leader in enterprise transformation and C-Level consulting. Running for the CNCF Governance Board, he leads AUDI's Container Competence Center. With a startup background, he champions innovation and true transformation through a people-first approach, challenging the status quo and enabling real hands-on progress.
However, migrating to Cluster API can still be challenging, especially for organisations heavily invested in existing cluster management tools.
This talk presents Giant Swarm's journey from a custom operator-based Kubernetes cluster management system to Cluster API, including the live migration of hundreds of production clusters of major enterprises such as adidas and Vodafone.
The driving force for the migration will be covered, followed by challenges encountered during the migration, concluding with a discussion of the observed benefits and differences seen post-migration.
Attendees will come away with an understanding of potential risks and challenges to be considered when migrating to Cluster API, a better insight into the expectations and efforts required, and the benefits of using this upstream project.
About the speaker:
Joe Salisbury is VP Engineering at Giant Swarm. He’s tasked with making Giant Swarm an attractive work environment for engineers and generally a dope place to work. When he’s not ensuring engineering operational excellence, he can be found rowing and playing D&D, but just not at the same time… yet.
About the speaker:
Thore Bahr is part of the Pre-Sales organization as Solution Architect. His focus is on open source infrastructure projects and he has been advising customers for many years on the selection and introduction of modern platforms based on Linux and Kubernetes
Join us to explore these real-world "dragon encounters," uncovering how these low-level tools, built in pre-container days, challenge Kubernetes stability today. Together, we'll demystify their quirks, share strategies for troubleshooting, and arm you with battle-tested insights to keep your clusters harmoniously humming—and maybe even avoid your next unexpected "fun" day.
About the speaker:
Jussi Nummelin has been working with and building cloud-native technologies for the past 10 or so years, even before they were actually called “cloud native”. He’s excited to build technologies and tools to help bring cloud-native to the masses. Jussi is currently working at Mirantis Open Source Program Office and mainly focusing on k0s kube distro and the tooling around it.
About the speaker:
Thomas Alexander Thomaßen: With an extensive background in firefighting diverse customer problems onsite, consulting in infrastructural matters and sharing his knowledge as a Red Hat Certified Instructor in technical training courses as well as DevOps Culture and Practice transformations, Alexander likes to combine practical hands-on experience with open knowledge discussions and strives to enable his peers.
In this talk, we’ll explore why simply using tools doesn’t equal maturity — and how the CNCF’s Cloud Native Maturity Model can provide a structured framework to make Cloud Native practices tangible and open for discussion. Using two key perspectives — Platform and Workload — we’ll demonstrate how teams can self-assess, uncover blind spots, and derive meaningful next steps for their Cloud Native evolution.
About the speaker:
Kevin Schu is Director Cloud & DevOps Consulting at AOE in Wiesbaden. He helps clients move to the cloud, define their cloud strategy, and build high-performing DevOps teams. With a background as a backend developer and architect for scalable systems, he now focuses on public clouds, Infrastructure as Code, Zero Trust, CI/CD, and Kubernetes.


