Loading…
7-9 October, 2026
Prague, Czechia
View More Details & Registration
Important Note: Timing of sessions and room locations are subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.



Venue: Small Hall (Floor 0) clear filter
arrow_back View All Dates
Wednesday, October 7
 

11:20 CEST

Evolving the YAML Family (without Breaking the World) - Ingy döt Net, YAML LLC
Wednesday October 7, 2026 11:20 - 12:00 CEST
YAML turned 25 this year.
It is essential to Kubernetes, Docker, Ansible, CI pipelines, and config files for everything in between.
That ubiquity is both a gift and a curse: every change risks breaking something, somewhere, silently.
So how do you grow a data language that a billion files depend on without risk of catastrophe?

Ingy döt Net helped invent YAML and he now maintains the YAML Specification and The YAML Family (libyaml, go-yaml, PyYAML, YAMLStar, YAMLScript etc).
In this talk he'll show how he plans to grow YAML by extension: a plugin system that can deeply affect YAML behavior in completely configurable ways.
Plugin APIs include schema association, tab indent, standard functions, comment support include i18n.
This is being delivered first to go-yaml with the rest of the Family to follow.
The work and its real world feedback will guide future changes to the specification.
Speakers
avatar for Ingy dot Net

Ingy dot Net

Invented YAML, YAML LLC
Ingy döt Net is one of the original inventors of the YAML data language, and its primary maintainer. He is also the active maintainer of go-yaml, the YAML framework trusted by Kubernetes and much of its ecosystem,
Wednesday October 7, 2026 11:20 - 12:00 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

13:30 CEST

How Git Clone Took Down Our CI for 20 Days - Yathartha Goenka, Mercari, Inc.
Wednesday October 7, 2026 13:30 - 14:10 CEST
One morning, CI across ~1,800 repos ground to a near-total halt. HTTP 401 from github.com, everywhere. Deterministic, not flaky. Valid tokens, healthy rate limits. GitHub support said "anti-abuse." We said "which abuse?"

Twenty days and 17,863,537 log records later, we'd gone deeper into git's open source plumbing than we ever intended: how git negotiates HTTP auth, what it leaks in user-agents, which config knobs actually matter under load, and how its defaults — sensible on a laptop — behave pathologically behind Kubernetes NAT at 50,000 CI runs a day.

This talk is a forensic walkthrough of git's HTTP transport, told through an outage: the red herrings, the tcpdumps, the fixes that didn't work, the fix that did. You'll leave knowing what git clone really does when you're not looking — and how to configure it so it never makes you look guilty.

Bring popcorn.
Speakers
avatar for Yathartha Goenka

Yathartha Goenka

Platform Engineer, Mercari, Inc.
A platform engineer at Mercari Japan, leading projects around DX, distributed systems and AI. Been working with backend development using Golang, CI/CD, cloud infrastructure, and scalable system design. Been learning more about the quiet ways a platform can fall over than I ever meant... Read More →
Wednesday October 7, 2026 13:30 - 14:10 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

14:25 CEST

Kata at Scale: The Hidden Cost of Running VMs Behind Every Container - Kavitha Daula & Ann Wallace, Edera
Wednesday October 7, 2026 14:25 - 15:05 CEST
There is a big difference between getting Kata Containers running in a proof of concept and operating a large multi-tenant Kata environment for years.

This talk is a practical, vendor-neutral look at what becomes hard after the demo works. Once every pod carries a lightweight VM lifecycle behind it, platform teams are no longer operating only Kubernetes. They are also operating guest kernels, guest images, VMMs, hypervisor behavior, virtio devices, runtime and agent version skew, and a second debugging surface under the container platform.

We will walk through production issues that show up at scale: guest kernel CVEs and regressions, host/guest kernel drift, CNI and tap-device networking, virtio-fs and storage durability semantics, fragmented observability, boot storms, vCPU oversubscription, memory accounting drift, NUMA behavior, GPU passthrough, VFIO/IOMMU lifecycle, upgrade matrices, and incident ownership.

This is not a criticism of Kata. Kata solves a real open source isolation problem. The goal is to help operators understand the operational work required to run VM-isolated containers safely and sustainably in production.
Speakers
avatar for Kavitha Daula

Kavitha Daula

VP of Engineering, Edera
Kavitha Daula is the VP of Engineering at Edera, where she leads the development of secure, high-performance container runtime technologies. Previously, she was Senior Director at GEICO, driving innovations in OS, containers, and language runtimes, including a custom Linux distro... Read More →
avatar for Ann Wallace

Ann Wallace

VP of Customer Experience, Edera
Ann Wallace is the VP of Customer Experience at Edera. Before Edera, she held leadership and architecture roles in security and cloud at Okta, Shopify, Google, and Nike. Ann speaks regularly at conferences on topics like compliance, container security, and using storytelling to make... Read More →
Wednesday October 7, 2026 14:25 - 15:05 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

15:35 CEST

Embracing Service-Oriented Connectivity Across OpenStack and Kubernetes - Mitsuhiro Tanino & Rei Shimizu, LY Corporation
Wednesday October 7, 2026 15:35 - 16:15 CEST
Modern infrastructure platforms increasingly combine OpenStack VMs, Kubernetes Pods, managed platforms, and external services, yet connectivity models often remain fragmented across runtime boundaries and tied to infrastructure-specific constructs such as IP-based ACLs.

This session presents how LY Corporation introduced a service-oriented connectivity model across OpenStack and Kubernetes environments. Rather than extending Kubernetes-native service mesh concepts to VM workloads, we introduced a runtime-independent service abstraction where connectivity and policy are defined consistently across VMs, Pods, PaaS instances, and external resources.

Under this model, services become the primary unit for service discovery, authentication and authorization, ACL management, and traffic control, independent of the underlying runtime or network topology. A sidecar proxy enforces service-to-service policy consistently across both OpenStack-managed VMs and Kubernetes workloads.

We cover the architectural design, OpenStack and Kubernetes integration for service registration and identity propagation, and lessons from migrating production workloads at scale.
Speakers
avatar for Mitsuhiro Tanino

Mitsuhiro Tanino

Senior Software Engineer, LY Corporation
Mitsuhiro Tanino is a senior software engineer who has been working for LY Corporation since 2019. He has experience to contribute OpenStack Cinder project for several years and also contributed Kubernetes sig-storage for several years. His current working area is operating hyper-scale... Read More →
avatar for Rei Shimizu

Rei Shimizu

Senior Software Engineer, LY Corporation
Rei Shimizu is working as Software Engineer for Private Cloud in LY Corporation.
Wednesday October 7, 2026 15:35 - 16:15 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

16:30 CEST

Life Finds a Way , Sandboxed Agents, Observable Verdicts - Henrik Rexed, Dynatrace
Wednesday October 7, 2026 16:30 - 17:10 CEST
"Life, uh, finds a way." So do AI agents. Give one a tool, and a prompt-injected README will teach it to spawn a shell. CVE-2025-59528 (CVSS 10.0) and Google's Antigravity sandbox escape proved the same thing twice in 2025: the agent didn't break the sandbox , either the sandbox was missing, or the electric fence was in the wrong place.
This talk is a tour of Jurassic Park, rebuilt on Kubernetes. The paddock walls are containers. The electric fence is kubernetes-sigs/agent-sandbox, swapping gVisor for Kata Containers under the same CRD. The control room is OpenTelemetry where invoke_agent, execute_tool, and tool.policy_check spans turn every isolation verdict into queryable telemetry.
We will deploy OpenClaw ,an open-source AI agent gateway inside a Sandbox resource on Cluster API, watch the agent attempt three different escapes, and ship policy decisions as first-class spans. Help shape OpenTelemetry semconv #3583 before the park opens.
Speakers
avatar for Henrik Rexed

Henrik Rexed

Cloud Native Advocate, Dynatrace
Henrik is a Cloud Native Advocate at Dynatrace, the leading Observability platform. Prior to Dynatrace, Henrik has worked more than 15 years, as Performance Engineer. Henrik Rexed Is Also one of the Organizer of the conferences named WOPR, KCD Austria and the owner of the Youtube... Read More →
Wednesday October 7, 2026 16:30 - 17:10 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

17:25 CEST

Teaching BIND9 New Tricks: A Rust Operator for Declarative DNS on Kubernetes - Erick Bourgeois, RBC Capital Markets
Wednesday October 7, 2026 17:25 - 18:05 CEST
Authoritative DNS is one of the last holdouts against declarative, GitOps-style management. BIND9 still serves a huge share of the world's zone data, but it's driven imperatively: hand-edited zone files, rndc reload, and brittle automation glued on top. bindy is an open-source Kubernetes operator, written in Rust on kube-rs, that closes the gap. It models zones and records as custom resources and continuously reconciles a running BIND9 against them, leaving no orphaned zone file behind.
This talk walks through the architecture of bindy and its sibling projects, bindcar, a sidecar that exposes RNDC operations over a typed API, and hornet, a Rust zone-file parser, then digs into the operator-engineering lessons that transfer to anyone writing controllers in Rust. We'll cover splitting selection from synchronization to avoid reconcile loops, using the reflector and store, modeling ownership and status conditions, and where Rust and kube-rs paid off versus Go's controller-runtime.
Attendees leave with a concrete, reusable pattern for wrapping any stateful, non-cloud-native daemon in a declarative Kubernetes API, and three open-source projects they can adopt, fork, or contribute to.
Speakers
avatar for Erick Bourgeois

Erick Bourgeois

Head of Kubernetes Platform Engineering, Director, RBC Capital Markets
Erick Bourgeois is a platform engineering specialist focused on Kubernetes operators and infrastructure automation for regulated industries. Creator of Bindy, an open-source DNS controller built in Rust, Erick brings expertise in cloud-native architecture, compliance frameworks (SOX... Read More →
Wednesday October 7, 2026 17:25 - 18:05 CEST
Small Hall (Floor 0)
  Cloud & Orchestration
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -