KubeCon has grown into a week-long marathon, packed with so much activity that one person can barely cover it all. For this recap, Dan walks through everything leading up to the main event, from the Maintainer Summit to the co-located sessions. I take over once the main conference begins. And along the way, Donia joins in to reflect on what makes this community so special. Between us, we cover the full story from Atlanta. Dan: For some, KubeCon can stretch to five solid days, and that can be even more if we’re attending additional events such as Rejekts. But for most they start with day “minus 1” (That’s minus 1 to KubeCon starting) which is the Maintainer Summit! Maintainer Summit For those that haven’t attended a Maintainer Summit it is a fantastic opportunity to both meet the maintainers of various CNCF projects, including projects such as Kubernetes and Cilium and to discuss the trials and tribulations of managing and maintaining Open Source projects. This year the summit included a lot of discussion around the impact of AI, both namely around what tools in the AI space are proving to be a benefit when managing a project but potentially more important was discussion about how to handle AI generated submissions. A lot of maintainers are already very busy meeting the demands that an open source project creates and the influx of AI generated code has the potential to be detrimental to the project and its maintainers. Isovalent eBee Quest Once the maintainers summit came to a close we hosted the Isovalent eBee Quest, where things became very competitive to complete the most Isovalent labs during the event in order to win various prizes! Attendees also earned the very much coveted Isovalent Credly Badges, which can proudly be displayed on LinkedIn. Great fun, and maybe some angry typing, was had by all. The following day was KubeCon day 0 (arrays start at zero, keep up 🙂), which is the co-located events day including CiliumCon. CiliumCon CiliumCon (which is often known as Cilium & eBPF Day depending on the KubeCon) is a half-day about all things Cilium: from new features to end-users providing an overview of how they’re using Cilium. Unfortunately due to the issues with plane travel during KubeCon we were missing a speaker, but fortunately we managed to bring Thomas Graf (one of the creators of Cilium) on stage and pepper him with questions all around the inception of Cilium and his thoughts on all things cloud native. Cloud Native University For those attending KubeCon for the first time or for people who are just finding their feet in the world of Kubernetes the Cloud Native University is a fantastic event to begin to understand the basics and core concepts whilst getting to meet the community. Our own Donia presented a gentle introduction into Kubernetes Security and Network Policies. VM on Kubernetes Day One of the key themes at KubeCon this year was the desire/need to find a new platform for virtual machines, and luckily we had the VM on Kubernetes Day event hosted at the Atlanta aquarium (which is amazing, but also it can be distracting to present on stage whilst a beluga whale swims around in the distance). This event had a fantastic panel where the discussion about how cloud native networking, storage and platforms would need to evolve in order to make Virtual Machines on Kubernetes an effective solution. Additionally we at Isovalent delivered an additional talk about the things people will need to consider with regards to networking when moving virtual machines to a Kubernetes platform. Once the co-located events wrapped up and the crowds began to make their way toward the main halls, it already felt like this KubeCon was shaping up to be full of news and surprises. With that, I will hand things over to Nico who picks up the story from the moment the main event begins. Nico: Thanks Dan. KubeCon opened with the announcement that ended up defining the entire week. Let’s walk through the stories and conversations that shaped KubeCon Atlanta 2025. Ingress NGINX retirement steals the show The biggest news coming out of KubeCon was the announcement that the popular Ingress NGINX controller is being retired by March 2026. This sent shockwaves through the community, given how widely it is used in production. It wasn’t a flashy AI demo or a shiny new internal developer portal that had people buzzing. It was the very real deprecation of a critical piece of infrastructure, used by half users according to our recently launched State of Kubernetes Networking report. Naturally, vendors rushed to put out their own messaging, including us (Dean published a great blog post right after the announcement to help users migrate to Cilium’s Ingress and Gateway API implementation). At our booth the following day, I had three Cilium users come up and ask how they could switch. They weren’t wondering which vendor's implementation was better. They just wanted to know how to start using Cilium’s. The answer is simple: flip a Helm flag. That’s pretty much it. This was the one topic that got people thinking hard on their way home. It felt immediate and practical in a way that a lot of the AI talk didn’t. The other aspect around the deprecation is slightly unsavoury: I saw a handful of angry reactions to the Ingress retirement announcement - ignoring the fact that the maintainers had been asking for support for months, if not years (Kat captured it perfectly in her comment). Thankfully, those responses were rare. What stood out far more was the way most of the community rallied around the maintainers. That didn’t come as a surprise. The cloud native ecosystem continues to be a welcoming and inclusive space. Let me hand the mic over to Donia to reflect on it. Celebrating the Humans of Cloud Native Donia: Yes, if there’s one thing KubeCon reminds us of every year, it’s this: open source is powered by people, and people are gloriously diverse. This year felt especially vibrant with the launch of Merge-Forward, the new CNCF umbrella initiative uniting seven communities (Deaf and Hard of Hearing, Blind and Visually Impaired, Stuttering and Speech Diversity, Women in Cloud Native, Deep Roots, Friends of Dorothy, Neurodiversity) dedicated to diversity in cloud native. Think of it like a Git merge, but for humans: no conflicts, only collaboration. Isovalent was proud to support that mission in multiple ways: Renewing our commitment to the Dan Kohn Scholarship, making it possible for engineers from underrepresented backgrounds to attend. Carla and Donia spent time with recipients, sharing their stories, answering questions, and building genuine connections. Helping host and facilitate the Women in Cloud Native Gathering, creating a space for connection, mentorship, and visibility. Amplifying Merge-Forward during a TechStrong interview, raising awareness about its mission and the importance of supporting the next generation of maintainers the ecosystem urgently needs. Supporting diversity isn’t a side project. It strengthens the community, the ecosystem, and the technology itself. Join the #merge-forward channel on CNCF slack workspace. Multi-zone setups aren't optional anymore Nico: A few weeks before the event, AWS us-east-1 had a pretty serious outage, which had an widespread impact of cloud-hosted services and applications. It’s not the first one - this particular region supports a big chunk of the internet - and it won’t be the last. And clearly it’s not just AWS but the other major cloud providers that will keep on having hiccups (I am writing this while CloudFlare is recovering from its own failure). People are starting to think about multi-zone, multi-cluster, and even multi-region topologies now. During our annual Hive Mind Mingle party, I spoke with an internal Cisco team already running Cilium Cluster Mesh across AWS availability zones. When the outage hit, their services stayed online (they only lost access to management tools). Cluster Mesh isn’t the only technology required for highly-tolerant Kubernetes platforms but it does simplify service discovery and load balancing and is a networking feature that many of our surveyed users are planning for. Kubernetes networking is getting smarter Marino Wijay said it well: networking is hot again. Of course Cilium and eBPF continue to get a ton of attention, but projects like DRANET are showing that we’re far from done. DRANET, which I mentioned in my January predictions post, uses Kubernetes’ Dynamic Resource Allocation API to help workloads like AI and ML get better network performance. Think of it as a cleaner way to get high-performance networking for pods that need access to RDMA or similar interfaces. Instead of hacking something together, it lets Kubernetes handle it natively. During the keynote, DRANET was donated from Google to the CNCF. That reminded me of another momentous occasion in Kubernetes networking when Thomas opened a pull request live proposing that Cilium become a Graduated project during KubeCon 2022 in Detroit. Three years on, Cilium remains the only graduated project in the Cloud Native Networking category. Let's hope for the DRANET team their project follows a similar trajectory. AI is cool, but not everyone is sure what to do with it As has been the theme for the past few KubeCon (and as I pointed out earlier this year in my KubeCon London recap), there was no shortage of AI hype. Agentic AI this, ML-that. Some of it was pretty cool. A lot of it felt disconnected from the average engineer’s day-to-day. A lot of people seemed unsure what to make of the AI push. Do the KubeCon attendees actually care? This comes from someone who is about to publish some AI-focused content of their own, so I’m not throwing stones. But the mismatch between the AI buzz and the questions people were actually asking was noticeable. VMs on Kubernetes is happening, slowly Dan said it - there’s definitely momentum behind running VMs on Kubernetes. We saw it with the dedicated co-located event. We saw it in the crowd sizes. People like the idea of managing VMs and containers in one place. The problem is that it’s still pretty rough. Networking in particular is clunky. You end up routing traffic through multiple abstraction layers, and the performance hit is real. Daniel Borkmann gave a talk ("QEMU in the Fast Lane: Accelerating KubeVirt Networking with eBPF") on how to clean this up, proposing some solid ideas on how to bring VM networking closer to line rate using eBPF. His session dug into how Netkit could streamline the entire path and cut out unnecessary overhead. If you care about VM performance, that one’s worth watching. We’ll get there. But right now, anyone running VMs on Kubernetes is doing it with a lot of duct tape. Tetragon is entering its breakout phase In past KubeCons, I had to explain what Tetragon was, what it could do, and why it mattered. That has changed. This year, people were already evaluating it. In many cases, they were running it in production. The message is consistent. Tetragon is powerful. It can see and control everything from process execs to network flows to file access - and tools with that much capability usually come with a bit of complexity. The Tetragon team is working on this. Expect more out-of-the-box policies and an easier on-ramp experience. Cisco rolling Tetragon out across its entire switching and routing portfolio (I don’t think I am exaggerating when I say that’s millions of devices) is a strong signal to the rest of the market that the project is mature. See you in Amsterdam Donia, Dan and I are now going to recharge our batteries before back-to-back Amsterdam conferences in early 2026: Cisco Live and KubeCon. See you there?