Name
Vendor neutrality guidance for CNCF projects
Short description
Standardize vendor-neutrality expectations for CNCF projects across governance rules, container image metadata, and infrastructure ownership.
Responsible group
TOC
Does the initiative belong to a subproject?
Yes
Subproject name
Project Reviews
Primary contact
TBD
Additional contacts
@angellk (TOC Chair, DD finding source)
Origin
DD finding (automated)
Initiative description
This initiative is a request from the TOC. During due diligence reviews, the TOC evaluates projects against incubation and graduation criteria. When the same finding appears across multiple projects, it signals an ecosystem-wide gap that would be better addressed through standardized guidance than repeated per-project recommendations.
This finding has appeared in 24 of 42 DD reports (57%) scanned over the last 5 years, including #2198 (HAMi), #1919 (Crossplane), #1468 (wasmCloud), #1862 (KServe), #1923 (OpenFGA), #1820 (Knative), and others. The most recent DD to surface this was HAMi incubation DD (merged 2026-07-02).
DDs routinely flag vendor-neutrality concerns across three areas: (1) governance docs lacking written vendor-neutrality rules, (2) container images using employer-specific LABEL maintainer values or email addresses instead of project-neutral contacts, and (3) project infrastructure (websites, release pipelines, security contacts) tied to a single vendor. The CNCF vendor-neutrality guidelines exist but are not operationalized into specific, checkable requirements for DD reviewers.
Scope: Translate the CNCF vendor-neutrality guidelines into actionable requirements for projects at each maturity level. Cover governance documentation (written vendor-neutrality rules), container image metadata (OCI annotations, project-neutral contacts), infrastructure ownership (domains, CI/CD, release signing), and website content (commercial product links, sponsor visibility).
Timeline: TBD
Deliverable(s) or exit criteria
Tracking document for meeting and progress
TBD
Name
Vendor neutrality guidance for CNCF projects
Short description
Standardize vendor-neutrality expectations for CNCF projects across governance rules, container image metadata, and infrastructure ownership.
Responsible group
TOC
Does the initiative belong to a subproject?
Yes
Subproject name
Project Reviews
Primary contact
TBD
Additional contacts
@angellk (TOC Chair, DD finding source)
Origin
DD finding (automated)
Initiative description
This initiative is a request from the TOC. During due diligence reviews, the TOC evaluates projects against incubation and graduation criteria. When the same finding appears across multiple projects, it signals an ecosystem-wide gap that would be better addressed through standardized guidance than repeated per-project recommendations.
This finding has appeared in 24 of 42 DD reports (57%) scanned over the last 5 years, including #2198 (HAMi), #1919 (Crossplane), #1468 (wasmCloud), #1862 (KServe), #1923 (OpenFGA), #1820 (Knative), and others. The most recent DD to surface this was HAMi incubation DD (merged 2026-07-02).
DDs routinely flag vendor-neutrality concerns across three areas: (1) governance docs lacking written vendor-neutrality rules, (2) container images using employer-specific LABEL maintainer values or email addresses instead of project-neutral contacts, and (3) project infrastructure (websites, release pipelines, security contacts) tied to a single vendor. The CNCF vendor-neutrality guidelines exist but are not operationalized into specific, checkable requirements for DD reviewers.
Scope: Translate the CNCF vendor-neutrality guidelines into actionable requirements for projects at each maturity level. Cover governance documentation (written vendor-neutrality rules), container image metadata (OCI annotations, project-neutral contacts), infrastructure ownership (domains, CI/CD, release signing), and website content (commercial product links, sponsor visibility).
Timeline: TBD
Deliverable(s) or exit criteria
Tracking document for meeting and progress
TBD