Loading…
7-9 October, 2026
Prague, Czechia
View More Details & Registration
Important Note: Timing of sessions and room locations are subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.



Venue: Small Hall (Floor 0) clear filter
arrow_back View All Dates
Friday, October 9
 

11:05 CEST

Lightning Talk: Declarative Systems Still Have Hidden State - Kim Schaefer, Game Plan Tech
Friday October 9, 2026 11:05 - 11:15 CEST
Declarative infrastructure promises reproducibility: desired state is defined, controllers reconcile drift, and redeployments should behave predictably.

Except they often don’t.

This talk explores the hidden operational state declarative systems quietly depend on: webhook certificates cached in cluster resources, infrastructure dependencies that survive deletion, controller ordering assumptions, persistent node state, and lifecycle coupling reconciliation engines cannot see.

These problems become especially visible when infrastructure spans multiple systems or workloads take minutes rather than seconds to initialize.

Using real operational examples from Kubernetes and GitOps environments, this lightning talk examines why “delete and redeploy” frequently fails to produce clean state and why many reliability problems are actually hidden state-management problems.

The core lesson: declarative systems still depend on operational history, even when the infrastructure appears fully declarative.
Speakers
avatar for Kim Schaefer

Kim Schaefer

Senior DevOps Engineer, Game Plan Tech
Kim Schaefer is a Senior DevOps and Cloud Engineer focused on Kubernetes, GitOps, and secure platform engineering. She designs and operates production Kubernetes platforms with a focus on deployment reliability and automation in constrained environments.

Kim's work centers on bu... Read More →
Friday October 9, 2026 11:05 - 11:15 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

11:15 CEST

Lightning Talk: One Line of YAML Leaks Your Secrets: The Pwn-Request Pattern - Arpit Jain, Self Employed
Friday October 9, 2026 11:15 - 11:25 CEST
A pull_request_target trigger plus ref: ${{ github.event.pull_request.head.sha }} in a checkout step. That combination lets any external contributor run arbitrary code with your repository's secrets and write token. This is the "pwn request" pattern, and it's in production workflows across some of the most popular open-source projects on GitHub.

I'll use a real finding (a CRITICAL-severity pwn request I discovered and privately disclosed in an Apache project) to explain how the attack works: what pull_request_target does differently from pull_request, why adding permissions: read-all doesn't protect you, and why the attacker needs nothing beyond opening a pull request.

Then I'll show the three mitigations that work: splitting into unprivileged build and privileged post-processing steps, using persist-credentials: false, and gating on the head repo matching the base.
Speakers
avatar for Arpit Jain

Arpit Jain

Security Researcher, Self Employed
Supply-chain security researcher focused on CI/CD pipeline vulnerabilities. Audits GitHub Actions workflows across CNCF, sigstore/SLSA, OpenSSF, and US federal government orgs (cisagov, GSA) for exploitable patterns: pwn requests, unpinned actions, token-scope misconfigurations. Has... Read More →
Friday October 9, 2026 11:15 - 11:25 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

11:25 CEST

Lightning Talk: Beyond Immutable Machines: Introducing Cluster API In-Place Updates - Lennart Jern, Ericsson Software Technology
Friday October 9, 2026 11:25 - 11:35 CEST
Cluster API (CAPI) is by now a relatively mature project with many adopters using it in production already for years. Despite this, or perhaps rather thanks to it, CAPI keeps evolving, growing and adding new features. In this session, I'll present one of the most recent features: in-place updates.

In-place updates marks an important change to a fundamental assumption in CAPI. Traditionally, the Machines were considered mostly immutable. Any change required a replacement where new Machines were created and old Machines deleted. This method of operation has served CAPI well, and continues to do so, but it is not without pain points. With in-place updates, it is now finally possible to avoid replacement. This opens the door for unique use-cases and solutions, such as Talos, where each node's lifecycle can be managed through a built-in controller in the node itself.

Come learn about this new feature in CAPI, and how to make use of it!
Speakers
avatar for Lennart Jern

Lennart Jern

Senior Developer, Ericsson Software Technology
Lennart Jern is a senior developer at Ericsson with more than 6 years experience from the CNCF ecosystem. He works mainly on open source projects related to the Cluster API and is a maintainer for the Cluster API Metal3 and OpenStack infrastructure providers as well as the Baremetal... Read More →
Friday October 9, 2026 11:25 - 11:35 CEST
Small Hall (Floor 0)
  Cloud & Orchestration
  • Audience Experience Level Any

11:35 CEST

Lightning Talk: Prove It: Is Your Kubernetes App Cloud Native? - Martin Matyáš, Tieto
Friday October 9, 2026 11:35 - 11:45 CEST
Everyone claims their app is cloud-native. But how to prove it?

CNTi Testsuite, an open-source Linux Foundation project, provides automated tests that validate cloud-native best practices such as security, scalability, and upgradability. While designed for telecom CNFs, it works for any Kubernetes application.

In this lightning talk, I’ll show how you can run CNTi Testsuite in minutes to objectively measure cloud-native maturity and uncover hidden gaps in Kubernetes workloads.
Speakers
avatar for Martin Matyáš

Martin Matyáš

Lead Cloud Engineer, Tieto
Lead cloud engineer with 20+ years of experience in application development and testing mostly in telecom industry. Worked on various aspects of Telecom software, from platforms, applications, test tools, continuous integration. Active member and maintainer of LFN's CNTi communit... Read More →
Friday October 9, 2026 11:35 - 11:45 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

11:55 CEST

Your Agent Did What? Forensic Observability for Systems That Don’t Leave Obvious Footprints - Adriana Villela, Dynatrace & Kasper Borg Nissen, Dash0
Friday October 9, 2026 11:55 - 12:35 CEST
The GenAI observability space is fragmented right now. OpenInference, OpenLLMetry, framework-specific conventions are all solving the same problems with incompatible attribute names. That made sense when OTel’s GenAI support was thin. It makes less sense today.

OTel is where this converges. Getting there from where most teams actually are isn’t obvious. Kasper and Adriana cover the current landscape, how the genainormalizer processor bridges the gap at the collector layer, and what a realistic path to OTel-native GenAI observability looks like.

Then the harder question: your agent just deleted a database. What does your telemetry actually tell you? Non-deterministic systems don’t leave obvious footprints, and most teams discover that at the worst possible time.
Speakers
avatar for Adriana Villela

Adriana Villela

Principal Developer Advocate, Dynatrace
Adriana Villela is a blogger, host of the Geeking Out podcast, CNCF Ambassador, OpenTelemetry Community Manager, and maintainer of the OpenTelemetry End User SIG. By day, she focuses on Observability and OpenTelemetry, as a Principal Developer Advocate at Dynatrace. By night, she... Read More →
avatar for Kasper Borg Nissen

Kasper Borg Nissen

Principal Developer Advocate, Dash0
Kasper is a CNCF Ambassador, former KubeCon+CloudNativeCon Co-Chair, Golden Kubestronaut, KCD Organizer, and CNCG Group Organizer. He co-founded Cloud Native Nordics to unite meetups across the region. At Dash0, he helps make observability easy for developers by advocating for better... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

14:00 CEST

Container Metrics on Diverse Hardware: Driving Observability, Efficiency, and Real-Time Autoscaling - Sambhav Jain & Digvijay Singh Shekhawat, Uber
Friday October 9, 2026 14:00 - 14:40 CEST
Uber runs about 4 million containers on over 150,000 hosts. Our fleet includes a mix of cgroupv1 and v2 hosts, multiple cloud providers, and multiple Linux kernel versions. Tracking container performance at this massive scale is a difficult engineering challenge, including the cost of storing them. We currently process 60 million data points every second to keep everything running smoothly.

We run Cadvisor and open-source Nvidia and AMD GPU metrics exporters to reliably and affordably collect and store these metrics. This infrastructure is vital for our real-time autoscaling, which ensures our services stay online. We also use these metrics to track memory usage and keep costs low for our AI workloads. Despite maintaining all the critical use cases, we have saved around $ 4 million compared to last year by changing how we collect and store data.

We will share how we use these metrics to detect and prevent system failures before they affect users. Attendees will learn practical patterns for operating container metrics at scale. We will also discuss the hard lessons we learned while building a reliable metrics system for a complex global fleet.
Speakers
avatar for Sambhav Jain

Sambhav Jain

Software Engineer, Uber
Sambhav Jain currently works as a Software Engineer at Uber on the container runtime team. Primarily working on container resource metrics and distributed container registry systems at Uber.
Before Uber, Sambhav worked at Cockroach Labs in the Database Performance team and at Confluent in the Kafka Connect team... Read More →
avatar for Digvijay Singh Shekhawat

Digvijay Singh Shekhawat

Software Engineer, Uber
I've always loved solving problems. As a kid, that passion started with mathematics, which led me to competitive programming and eventually computer science.

At Uber, I was one of the founding engineers on the AI Solutions team, helping build Uber's new gig platform from the gr... Read More →
Friday October 9, 2026 14:00 - 14:40 CEST
Small Hall (Floor 0)
  Cloud & Orchestration
  • Audience Experience Level Any

15:40 CEST

Cloud Native Open RAN Across 1,000 Km: A GitOps Deployment With Duranta and Sylva - Sagar Arora, OpenAirInterface Software Alliance & Guillaume Grao, Orange Innovation
Friday October 9, 2026 15:40 - 16:20 CEST
The telco industry has been on a cloudification journey for over a decade. In the context of Radio Access Networks (RAN), this deep transformation is primarily driven by Open RAN initiatives. This talk illustrates how RAN is gradually embrassing cloud native benefits. Key synergies between Sylva and Duranta open-source projects are driving this transformation:
- Sylva provides a telco-grade cloud stack, enabling scalable and reliable cloud infrastructure.
- The Duranta project focuses on developing RAN network functions using cloud-native design patterns to promote innovation and interoperability.

A live demo will highlight the role of Open RAN interfaces in Duranta. It will showcase a FluxCD-based GitOps deployment of Duranta’s Open RAN Distributed Unit (O-DU), Centralized Unit Control Plane (O-CU-CP), and Centralized Unit User Plane (O-CU-UP) network functions on a Telco Cloud. The deployment will follow the Sylva GitOps approach. Sylva will orchestrate multiple Telco Clouds to showcase central, regional, and far-edge deployment scenarios across two labs located approximately 1,000 km apart.
Speakers
avatar for Sagar Arora

Sagar Arora

Solutions Architect, OpenAirInterface Software Alliance, OpenAirInterface Software Alliance
Sagar Arora holds a Ph.D. in mobile communications from Sorbonne University, France. His thesis title was “Cloud-native Network Slice Orchestration in 5G and Beyond”. At OpenAirInterface, he takes care of the on-premises data center, 5G radio equipment, and CD pipelines. He engages... Read More →
avatar for Guillaume Grao

Guillaume Grao

O-RAN and 5G Solution integrator, Orange Innovation
Working for Orange Innovation in different position: from C++ developper to an O-RAN and 5G Solution integrator
Friday October 9, 2026 15:40 - 16:20 CEST
Small Hall (Floor 0)
  Cloud & Orchestration
  • Audience Experience Level Any

16:30 CEST

Scatter-Gather in Sharded Worlds: Implementing Resilient Cluster Scans Without Starving Shards - Sakshi Nasha, Cohesity & Primanshu Choudhary, GetYourGuide
Friday October 9, 2026 16:30 - 17:10 CEST
Have you ever run a global pattern search or database scan across a large cluster, only to watch your application latency skyrocket and healthy nodes suddenly drop offline?

When applications outgrow a single instance, global data scanning becomes a major distributed systems bottleneck. High-level frameworks try to mask this complexity with simple abstractions, forcing the client driver to execute a "scatter-gather" pattern: fanning out parallel cursor queries to thousands of logical shards and merging the reactive results on the fly. If designed naively, a single slow shard or an unindexed query can exhaust the client's connection pool, leak memory, and starve production read/write traffic.

In this practical, code-focused session, we will open up the engine hood of high-performance drivers using live examples from the Valkey-Glide ecosystem. We will show you how to safely bridge high-level data abstractions down to sharded sockets without risking cascading timeouts.
Come Join us, to build Resilient Cluster Scans Without Starving Shards!
Speakers
avatar for Sakshi Nasha

Sakshi Nasha

Software Engineer, OpenSource Contributor, Cohesity
Sakshi Nasha is a Software Engineer with a passion for building software and driving diversity in tech. An open-source enthusiast and OpenSearch Ambassador, she actively contributes to FOSS communities and speaks internationally on topics including GO, APIs, Security, PostgreSQL and... Read More →
avatar for Primanshu Choudhary

Primanshu Choudhary

Software Engineer 2, GetYourGuide
Primanshu is a Software Engineer at GetYourGuide, working in the Reviews team, he focuses on improving the performance and scalability of reviews system serving 400M+ requests per day with low latencies. He is a database enthusiast who enjoys solving real world problems, applies pragmatic... Read More →
Friday October 9, 2026 16:30 - 17:10 CEST
Small Hall (Floor 0)
  Cloud & Orchestration
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -