233 projects
Cloud Native Computing Foundation (CNCF)
The Cloud Native Computing Foundation (CNCF) is an open-source organization under the Linux Foundation that promotes the development and adoption of cloud-native technologies. It serves as a hub for projects that enable scalable, resilient, and portable applications in modern cloud environments.
575,518 contributors
$34B
Kubernetes
Kubernetes (K8s) is an open-source system for automating deployment, scaling, and management of containerized applications.
115,142
22,025
$5.8B
Helm
Helm helps you manage Kubernetes applications — Helm Charts help you define, install, and upgrade even the most complex Kubernetes application.
27,242
5,353
$21M
OpenTelemetry
OpenTelemetry makes robust, portable telemetry a built-in feature of cloud-native software. OpenTelemetry provides a single set of APIs, libraries, agents, and collector services to capture distributed traces and metrics from your application. You can analyze them using Prometheus, Jaeger, and other observability tools.
24,636
5,203
$320M
Argo
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.
22,717
5,409
$101M
gRPC
gRPC is a modern open source high performance RPC framework that can run in any environment. It can efficiently connect services in and across data centers with pluggable support for load balancing, tracing, health checking and authentication. It is also applicable in last mile of distributed computing to connect devices, mobile applications and browsers to backend services.
21,423
4,493
$150M
Prometheus
Prometheus is an open-source systems monitoring and alerting toolkit originally built at SoundCloud. Since its inception in 2012, many companies and organizations have adopted Prometheus, and the project has a very active developer and user community. It is now a standalone open source project and maintained independently of any company.
20,536
5,283
$36M
Keycloak
Keycloak is an open source Identity and access management solution aimed at modern applications and services. It makes it easy to secure applications and services with little to no code. Keycloak is based on standard protocols with an aim toward modern use cases and the flexibility to integrate with other solutions and prevent vendor lock in. Supported protocols include: OAuth2, OpenID Connect, User Managed Access 2.0 (UMA) and SAML 2.0.
16,570
2,578
$2.8B
Fluentd
Fluentd is an open source data collector for unified logging layer. Fluentd allows you to unify data collection and consumption for a better use and understanding of data.
13,441
2,923
$166M
Istio
Istio extends Kubernetes to establish a programmable, application-aware network using the powerful Envoy service proxy. Working with both Kubernetes and traditional workloads, Istio brings standard, universal traffic management, telemetry, and security to complex deployments.
13,323
2,889
$404M
Cloud Native Computing Foundation (CNCF)
The Cloud Native Computing Foundation (CNCF) hosts critical components of the global technology infrastructure. CNCF brings together the world’s top developers, end users, and vendors and runs the largest open source developer conferences.
12,145
3,553
$3.3B
Podman Container Management Tool
Podman: A tool for managing OCI containers and pods.
11,307
2,974
$150M
Kubeflow
Kubeflow is an open source machine learning platform built on Kubernetes that makes deploying and managing ML workflows on Kubernetes simple, portable and scalable. It provides end-to-end orchestration of machine learning pipelines, model training, serving, and experiment tracking.
10,250
2,292
$478M
Envoy
ENVOY IS AN OPEN SOURCE EDGE AND SERVICE PROXY, DESIGNED FOR CLOUD-NATIVE APPLICATIONS.
9,566
2,133
$3.6B
Harbor
Harbor is an open source container image registry that secures images with role-based access control, scans images for vulnerabilities, and signs images as trusted.
9,009
2,118
$41M
Backstage
Backstage is an open platform for building developer portals that helps organizations streamline software development by centralizing technical documentation, APIs, services, and tools into a unified interface. It provides a microservices architecture, plugin system, and tools for service catalogs, documentation, and infrastructure management.
7,756
2,270
$121M
cert-manager
cert-manager is a Kubernetes add-on to automate the management and issuance of TLS certificates from various issuing sources.
7,673
2,718
$32M
Etcd
A distributed, reliable key-value store for the most critical data of a distributed system.
7,534
1,811
$69M
NATS
NATS.io is a simple, secure and high performance open source messaging system for cloud native applications, IoT messaging, and microservices architectures.
7,447
1,733
$83M
Cilium
Cilium is an open source software for providing, securing and observing network connectivity between container workloads - cloud native, and fueled by the revolutionary Kernel technology eBPF.
7,419
2,105
$1.1B
Flux
Flux is a tool that automatically ensures that the state of your Kubernetes cluster matches the configuration you’ve supplied in Git. It uses an operator in the cluster to trigger deployments inside Kubernetes, which means that you don’t need a separate continuous delivery tool.
6,969
2,155
$19M
k3s
K3s is a highly available, certified Kubernetes distribution designed for production workloads in unattended, resource-constrained, remote locations or inside IoT appliances.
6,307
1,953
$11M
Containerd
An industry-standard container runtime with an emphasis on simplicity, robustness and portability
5,679
1,627
$104M
Jaeger
Monitor and troubleshoot transactions in complex distributed systems. As on-the-ground microservice practitioners are quickly realizing, the majority of operational problems that arise when moving to a distributed architecture are ultimately grounded in two areas: networking and observability.
5,479
1,439
$48M
Thanos
Open source, highly available Prometheus setup with long term storage capabilities.
4,890
1,393
$22M
Dapr
Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge.
4,854
1,069
$54M
Crossplane
Crossplane is an open source Kubernetes add-on that enables platform teams to assemble infrastructure from multiple vendors, and expose higher level self-service APIs for application teams to consume, without having to write any code.
4,521
1,283
$704M
Open Policy Agent
Stop using a different policy language, policy model, and policy API for every product and service you use. Use OPA for a unified toolset and framework for policy across the cloud native stack. Whether for one service or for all your services, use OPA to decouple policy from the service's code so you can release, analyze, and review policies (which security and compliance teams love) without sacrificing availability or performance.
4,446
1,221
$347M
KEDA
KEDA is a Kubernetes-based event-driven autoscaler. KEDA determines how any container in Kubernetes should be scaled based on the number of events that need to be processed. KEDA is a single-purpose and lightweight component that can be added to any Kubernetes cluster. It works alongside standard Kubernetes components like the Horizontal Pod Autoscaler and can extend functionality without overwriting or duplication. With KEDA you can specify the that apps you want to scale in an event-driven way while other apps continue to function. This makes KEDA a flexible and safe option to run alongside other Kubernetes applications and frameworks.
4,293
1,135
$212M
Rook
Rook turns distributed storage systems into self-managing, self-scaling, self-healing storage services. It automates the tasks of a storage administrator: deployment, bootstrapping, configuration, provisioning, scaling, upgrading, migration, disaster recovery, monitoring, and resource management.
4,276
1,311
$11M
Linkerd
Linkerd is a service mesh for Kubernetes and other frameworks. It makes running services easier and safer by giving you runtime debugging, observability, reliability, and security—all without requiring any changes to your code.
3,950
1,195
$114M
Distribution
A container registry project that is now a sandbox project from Docker.
3,938
1,329
$42M
Meshery
Lifecycle, performance, and configuration management across any service mesh.
3,865
736
$372M
OAuth2 Proxy
OAuth2 Proxy is a reverse proxy and static file server that provides authentication using OAuth2 providers to secure HTTP endpoints. It acts as a middleware to protect web applications by requiring users to authenticate via an OAuth2 provider before accessing protected resources.
3,803
1,207
$4.4M
Knative
Knative is an Open-Source Enterprise-level solution to build Serverless and Event Driven Applications.
3,683
981
$746M
Strimzi
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes in various deployment configurations.
3,565
833
$316M
External Secrets Operator
"External Secrets Operator (ESO) is a Kubernetes operator that integrates external secret management systems like AWS Secrets Manager, HashiCorp Vault, Google Secrets Manager, Azure Key Vault and many more. The operator reads information from external APIs and automatically injects the values into a Kubernetes Secret. ESO provides a user-friendly abstraction for the external API that stores the secrets for you. It allows you to manage access to the secret store for different tenants within your cluster and keeps the Kubernetes secrets in sync.
3,502
1,096
$8.1M
Atlantis
Atlantis is PR automation application that allows users to create PRs against a repository to run terraform via command comments.
3,489
1,024
$4.2M
Longhorn
Cloud native distributed block storage for Kubernetes
3,458
973
$436M
KubeVirt
KubeVirt technology addresses the needs of development teams that have adopted or want to adopt Kubernetes but possess existing Virtual Machine-based workloads that cannot be easily containerized. More specifically, the technology provides a unified development platform where developers can build, modify, and deploy applications residing in both Application Containers as well as Virtual Machines in a common, shared environment.
3,357
657
$3.3B
Kyverno
Kyverno is a policy engine designed for Kubernetes. With Kyverno, policies are managed as Kubernetes resources and no new language is required to write policies.
3,293
1,002
$83M
CoreDNS
CoreDNS is a DNS server. It is written in Go. It can be used in a multitude of environments because of its flexibility.
3,035
943
$4.2M
TiKV
A distributed transactional key-value database. Based on the design of Google Spanner and HBase, but simpler to manage and without dependencies on any distributed filesystem
2,870
698
$300M
Falco
Falco, the open source cloud-native runtime security project, is the defacto Kubernetes threat detection engine. Falco detects unexpected application behavior and alerts on threats at runtime.
2,861
767
$56M
Fluid Project
Fluid is an open, collaborative project to improve the user experience and inclusiveness of open source software. The Fluid community consists of an international team of partners, individuals, and institutions focused on designing inclusive, flexible, customizable, user-centered interfaces.
2,772
79
$88M
OpenEBS
OpenEBS is the leading storage solution for Kubernetes Kubernetes native; runs in userspace Open Source; no vendor lock-in The only multi cloud storage solution
2,486
657
$109M
CloudNativePG
A comprehensive open source platform designed to seamlessly manage PostgreSQL databases within Kubernetes environments.
2,410
781
$94M
Cloud Custodian
Cloud Custodian enables users to be well managed in the cloud. The simple YAML DSL allows you to easily define rules to enable a well-managed cloud infrastructure, that's both secure and cost optimized.
2,408
418
$39M
KubeEdge
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge.It is built upon kubernetes and provides fundamental infrastructure support for network, app. deployment and metadata synchronization between cloud and edge.
2,247
402
$346M
Dex
Dex is an identity service that uses OpenID Connect to drive authentication for other apps.
2,079
883
$2.4M
Kserve
The mission of the Project is to develop a highly scalable and standards based model inference platform on Kubernetes for Trusted AI.
2,062
422
$216M
Telepresence
Telepresence is an open source tool that lets you run a single service locally, while connecting that service to a remote Kubernetes cluster.
2,015
617
$8.2M
k0s
k0s is a lightweight, all-inclusive Kubernetes distribution that is designed to be simple to install and operate. It packages all required Kubernetes components into a single binary, making it easier to deploy and manage Kubernetes clusters across various environments.
1,989
705
$16M
emissary-ingress
An open source ingress controller and API Gateway for Kubernetes.
1,924
655
$37M
Vitess
Vitess is a database solution for deploying, scaling and managing large clusters of open-source database instances. It currently supports MySQL and MariaDB. It’s architected to run as effectively in a public or private cloud architecture as it does on dedicated hardware. It combines and extends many important SQL features with the scalability of a NoSQL database
1,912
486
$87M
MetalLB
MetalLB is a load-balancer implementation for bare metal Kubernetes clusters, using standard routing protocols.
1,817
564
$8.6M
Flatcar
Flatcar Container Linux is a container-optimized Linux distribution focused on security, reliability and ease of maintenance. It provides an immutable Linux operating system designed to run containerized applications, with automated updates and minimal overhead.
1,726
432
$206M
LitmusChaos
Litmus is one of the most promising open source chaos engineering frameworks that takes into account proper chaos engineering principles while providing autonomy and extensibility to the users.
1,723
422
$55M
Contour
Contour is a Kubernetes ingress controller using Envoy proxy.
1,677
469
$30M
SOPS
SOPS (Secrets OPerationS) is an editor in the form of a command-line tool and SDK designed to help manage encrypted files in a variety of structured (YAML, JSON, ENV, INI) and BINARY formats using a one of the supported Key Management Systems (KMS), PGP, or age.
1,666
738
$953K
Inclavare Containers
An innovation of container runtime with the novel approach of launching and attesting confidential container in hardware-enforced Trusted Execution Environment (TEE).
1,644
384
$130M