Skip to content

[Initiative]: Vendor neutrality guidance for CNCF projects #2231

Description

@angellk

Name

Vendor neutrality guidance for CNCF projects

Short description

Standardize vendor-neutrality expectations for CNCF projects across governance rules, container image metadata, and infrastructure ownership.

Responsible group

TOC

Does the initiative belong to a subproject?

Yes

Subproject name

Project Reviews

Primary contact

TBD

Additional contacts

@angellk (TOC Chair, DD finding source)

Origin

DD finding (automated)

Initiative description

This initiative is a request from the TOC. During due diligence reviews, the TOC evaluates projects against incubation and graduation criteria. When the same finding appears across multiple projects, it signals an ecosystem-wide gap that would be better addressed through standardized guidance than repeated per-project recommendations.

This finding has appeared in 24 of 42 DD reports (57%) scanned over the last 5 years, including #2198 (HAMi), #1919 (Crossplane), #1468 (wasmCloud), #1862 (KServe), #1923 (OpenFGA), #1820 (Knative), and others. The most recent DD to surface this was HAMi incubation DD (merged 2026-07-02).

DDs routinely flag vendor-neutrality concerns across three areas: (1) governance docs lacking written vendor-neutrality rules, (2) container images using employer-specific LABEL maintainer values or email addresses instead of project-neutral contacts, and (3) project infrastructure (websites, release pipelines, security contacts) tied to a single vendor. The CNCF vendor-neutrality guidelines exist but are not operationalized into specific, checkable requirements for DD reviewers.

Scope: Translate the CNCF vendor-neutrality guidelines into actionable requirements for projects at each maturity level. Cover governance documentation (written vendor-neutrality rules), container image metadata (OCI annotations, project-neutral contacts), infrastructure ownership (domains, CI/CD, release signing), and website content (commercial product links, sponsor visibility).

Timeline: TBD

Deliverable(s) or exit criteria

  • Guidance document: vendor-neutrality requirements by maturity level
  • Container image metadata template (OCI annotations, Dockerfile LABEL patterns)
  • Vendor-neutrality checklist for DD reviewers
  • DD checklist item update — PR to incubation and graduation application templates

Tracking document for meeting and progress

TBD

Metadata

Metadata

Assignees

No one assigned

    Labels

    init/not-startedInitiative has been accepted, but not started (in the backlog)kind/initiativeAn initiative or an item related to imitative processesneeds-triageIndicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied)sub/project-reviewsTOC Project Review Subproject

    Type

    No type

    Projects

    Status
    New
    Status
    status/new
    Status
    No status
    Status
    No status
    Status
    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions