# KubeCon + CloudNativeCon Japan — Schedule

Machine-readable mirror of the schedule page. Generated 2026-09-11.

- Source: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/
- Sessions: 142 across 3 days
- Times are the event's local times, exactly as published. Timing and rooms are subject to change.
- Each session links back to the schedule page, which opens that session's details.

## Tracks

- Keynote Sessions (17)
- Project Opportunities (16)
- AI + ML (15)
- Maintainer Track (13)
- Security (9)
- Observability (8)
- Cloud Native Experience (7)
- Operations + Performance (7)
- Breaks (6)
- Sponsor Demos (6)
- Platform Engineering (5)
- Experiences (5)
- ⚡Lightning Talks (4)
- Connectivity (4)
- Registration + Badge Pick-up (3)
- Sponsor + Community-Hosted Co-located Events (3)
- Cloud Native Novice (3)
- Data Processing + Storage (3)
- CNCF-Hosted Co-located Events (2)
- Solutions Showcase (2)
- Application Development (2)
- Emerging + Advanced (2)

## Tuesday, July 28, 2026

### 07:30–18:00 · Registration + Badge Pick-up

- Room: 2F | Foyer
- Track: Registration + Badge Pick-up
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1221396

### 09:00–12:30 · KeycloakCon Hosted by CNCF - Half-Day Event | [Pre-Registration Required]

- Room: 3F | 313+314
- Track: CNCF-Hosted Co-located Events
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1233371
- Event Website: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/co-located-events/keycloakcon/

KeycloakCon is a half-day single-track conference that brings together the Keycloak community. The event offers a platform for technical talks, professional growth, and networking opportunities. Attendees will gain insights from Keycloak developers and maintainers, explore the latest features and updates, and learn from real-world use cases. This is a valuable opportunity to engage directly with Keycloak experts and fellow users, deepening your understanding and expanding your network.

For questions regarding this event, please reach out to cncfcolocatedevents@linuxfoundation.org.

### 13:00–19:00 · Japan Community Day hosted by Cloud Native Community Japan (CNCJ) | [Pre-Registration Required]

- Room: 4F | 411+412 (Track 1), 4F | 414+415 (Track 2)
- Track: Sponsor + Community-Hosted Co-located Events
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1231464
- Event Website: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/co-located-events/japan-community-day/

Japan Community Day is set to be a comprehensive and engaging gathering for professionals interested in cloud-native technologies. It will bring together attendees of KubeCon + CloudNativeCon Japan and members of various local meetup communities, Special Interest Groups (SIGs) and Subgroups within CNCJ to foster collaboration, learning, and contribution to the cloud-native ecosystem. The event is structured to offer multiple tracks with multiple themes, each targeting a different aspect of cloud-native development and community involvement.

Update: Japan Community Day is sold out!

Register for KubeCon + CloudNativeCon Japan and join the Japan Community Day waitlist.

Should you have any questions, please contact us at cncj@googlegroups.com.

### 13:25–17:00 · ArgoCon Hosted by CNCF - Half-Day Event | [Pre-Registration Required]

- Room: 3F | 313+314
- Track: CNCF-Hosted Co-located Events
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1233372
- Event Website: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/co-located-events/argocon/

ArgoCon is designed to foster collaboration, discussion, and knowledge sharing on the Argo Project, which consists of four projects: Argo CD, Argo Workflows, Argo Rollouts and Argo Events.

For questions regarding this event, please reach out to cncfcolocatedevents@linuxfoundation.org.

### 13:30–20:30 · Cloud Native Telecom Meetup Japan 2026 Hosted by NTT Docomo | [Pre-Registration Required]

- Room: Offsite Event
- Track: Sponsor + Community-Hosted Co-located Events
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1236976
- Event Website: https://cntm2026.peatix.com/view

Please note that this is an off-site Sponsor-hosted Co-located event located in Tokyo which is approximately 1 hour away from Yokohama.

Address: docomo R&D OPEN LAB ODAIBA | 12F, 2-3-2, Daiba, Minato-ku, Tokyo, Japan

Cloud Native Telecom Meetup Japan 2026 is a pre-event of KubeCon + CloudNativeCon Japan, bringing together telecom operators, cloud providers, and open-source innovators. Explore real-world use cases, 5G/6G evolution, and cloud-native networking through expert talks and discussions.

Participants will learn about:
Real-world telecom use cases using Kubernetes
Cloud-native network functions (CNFs)
Platform engineering for telecom workloads
Latest trends in CNCF projects applied to telecom

To learn more and register for the Cloud Native Telecom Meetup Japan 2026 - https://cntm2026.peatix.com/view

For questions regarding this event, please contact: Nobuyuki Tamaoki, ntamaoki@virtualtech.jp

### 17:30–21:00 · KubeAuto Day Japan with Kelsey Hightower Hosted by Cast AI | [Pre-Registration Required]

- Room: Offsite Event
- Track: Sponsor + Community-Hosted Co-located Events
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1276381
- Event Website: https://kubeauto.day/japan

Running Kubernetes used to mean babysitting it. AI is starting to change that, and KubeAuto Day is where engineers come to compare notes on what's actually working in production versus what just sounds good on a conference slide.

Kelsey Hightower is coming to Japan for this one. You've probably watched his talks. Now you can argue with him in person over coffee.

Here's the deal: no vendor booths, no sales pitches. Engineers talking to engineers about applying AI to Kubernetes, getting rid of config drift, and automating the FinOps grind. Plus AIOps, building AI agents that don't fall over, and zero-touch control planes.

Mostly you'll be in a room with SREs, DevOps leads, and platform folks who deal with the same headaches you do.

If you're tired of fighting the same fire every week, come spend the day with us.

会場でお会いしましょう。

To learn more and register for the event - https://kubeauto.day/japan
For questions regarding this event, please contact: contact@kubeauto.day

Please note that this is an off-site Sponsor-hosted Co-located event.

## Wednesday, July 29, 2026

### 08:00–18:00 · Registration + Badge Pick-up

- Room: 2F | Foyer
- Track: Registration + Badge Pick-up
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1221390

### 09:30–09:45 · Keep Cloud Native Moving: Building Japan's Platform for Open Innovation

- Room: 1F | Main Hall
- Speakers: Jonathan Bryce, Chris Aniszczyk
- Track: Keynote Sessions
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1283167

Cloud native has become the operating model for modern software, but AI is redefining what comes next. As organizations build sovereign AI platforms, deploy inference at scale, and introduce autonomous agents into production, the demands on cloud native infrastructure are rapidly scaling. From Kubernetes and platform engineering to observability, networking, and distributed systems, the cloud native ecosystem is becoming the foundation for trustworthy AI.

Japan offers a unique perspective on this transformation. With nearly one million cloud native developers and an infrastructure strategy that blends on-premises systems, hybrid cloud, and cloud native technologies, Japanese organizations are demonstrating that there is no single path to modernization. As AI adoption accelerates, these strengths position Japan to help shape the next generation of intelligent infrastructure.

In this keynote, Jonathan Bryce and Chris Aniszczyk will explore how the CNCF community is enabling the next wave of AI infrastructure, why open source collaboration matters more than ever, and how every developer, from first-time contributors to experienced maintainers, can help keep cloud native moving.

### 09:47–09:50 · Infinite Agents, Finite Kubernetes

- Room: 1F | Main Hall
- Speakers: Mohammad Mikal Bin Amrul Halim Gan
- Track: Keynote Sessions
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1283170

The rise of autonomous agents introduces a radically volatile workload profile: short-lived, heavy-compute pods that demand instant GPU/CPU access and vanish. In this keynote, we deconstruct a fundamental Infrastructure paradox: infinite agent demand versus strictly finite physical compute, space, and power. Using a simple trade-off curve as our focal point, we present an architectural vision to safely scale for the autonomous future.

### 09:52–09:55 · The Next Evolution of Kubernetes: GPU-Centric Infrastructure for AI Workloads

- Room: 1F | Main Hall
- Speakers: Takao Indoh
- Track: Keynote Sessions
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1283171

With the emergence of generative AI and Agentic AI, the role of Kubernetes is shifting from CPU-based cloud infrastructure to GPU-centric infrastructure.

Faced with constraints such as explosively growing computational demand, GPU shortages, and soaring electricity costs, Kubernetes must optimize the use of available resources to sustainably scale AI workloads. In the case of Agentic AI in particular, a single request generates numerous downstream tasks, resulting in unpredictable computational demands, making it increasingly difficult to address these challenges with traditional cloud design philosophies alone.

In this presentation, we will introduce Fujitsu's perspective on the new challenges facing cloud-native infrastructure in the AI era, along with our solution based on Composable Disaggregated Infrastructure.

### 09:57–10:07 · Building a Multi-Tenant AI Platform with the CNCF Ecosystem

- Room: 1F | Main Hall
- Speakers: Aya Igarashi
- Track: Keynote Sessions
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1283172

As AI technology advances, a multi-tenant computing infrastructure has become essential for supporting diverse user workloads. Building a multi-tenant platform to handle various workloads, including AI and ML, relies heavily on Kubernetes' powerful extensibility and careful integration with CNCF ecosystem technologies. In this session, we will share the design philosophy behind our Kubernetes platform. We will provide a high-level overview of our platform's architecture and discuss how we leverage cloud-native projects to orchestrate complex workloads.

Attendees will gain practical insights into building infrastructure that keeps pace with the evolving open-source landscape.

### 10:09–10:14 · How Subaru Accelerated AI Model Development for Next-Generation EyeSight with Kubernetes

- Room: 1F | Main Hall
- Speakers: Ryoji Kobayashi
- Track: Keynote Sessions
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1283173

Subaru is developing AI models in-house to further improve the recognition accuracy of next-generation EyeSight.

As AI development activities expanded, the team faced several challenges, including large ML container images, manual deployment operations, and increasingly complex machine learning workflows.

To address these challenges, Subaru built a Kubernetes-based AI model development platform using cloud native technologies such as Harbor, Envoy Gateway, MetalLB, Argo CD, Helm, and Argo Workflows.

These improvements reduced container image pull time from approximately three hours to three minutes, enabled GitOps management for 25 application definitions, and automated machine learning workflows.

In this session, Subaru will share how it used Kubernetes and CNCF technologies to address key challenges in AI model development and accelerate its development workflow.

### 10:16–10:19 · From 5 to 1,300+ Clusters: Declarative Scaling for Private Kubernetes

- Room: 1F | Main Hall
- Speakers: Shota Yoshimura
- Track: Keynote Sessions
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1283174

LY Corporation operates one of Japan’s largest private Kubernetes platforms, managing more than 1,300 clusters and 40,000+ nodes with only 15 platform engineers. This 3-minute keynote will share how LY uses Kubernetes custom resources and controllers to define infrastructure declaratively and automate cluster provisioning, scaling, upgrades, and recovery across OpenStack-based private infrastructure. Using the platform architecture diagram as the focal point, the talk will show how declarative automation reduced provisioning from weeks to hours, enabled zero-downtime operations, and turned Kubernetes into a self-service platform for product teams.

### 10:21–10:24 · Out of the Box, at Multi-Region Scale: How Hyundai Scales Its Platform

- Room: 1F | Main Hall
- Speakers: Jaewoo Choi
- Track: Keynote Sessions
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1283176

Hyundai Motor Group runs its global platform on hCloud, its own in-house private cloud, and provides open source tooling for its CI/CD pipelines. A single Argo CD instance now manages 5,000+ Applications across 300+ Kubernetes clusters worldwide, growing by hundreds of new Applications every month, while a multi-region Harbor registry holds 60k+ artifacts across 5k+ repositories, replicated across 3 regions to balance data-residency regulation with performance.

### 10:25–10:45 · Closing Remarks

- Room: 1F | Main Hall
- Track: Keynote Sessions
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1283335

### 10:45–11:30 · Coffee Break ☕

- Room: 3F | 301-304 + Foyer
- Track: Breaks
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1221316

### 10:45–19:15 · Solutions Showcase

- Room: 3F | 301-304 + Foyer
- Track: Solutions Showcase
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1221386

Visit our sponsors in the Solutions Showcase to try the latest demos, watch live presentations, talk to experts, check out job opportunities, and score some swag.

In order to facilitate networking and business relationships at the event, you may choose to visit a third party’s booth or to access sponsored content. You are never required to visit third-party booths or to access sponsored content. When visiting a booth or participating in sponsored activities, the third party will receive some of your registration data. This data includes your first name, last name, title, company, address, email, standard demographics questions (i.e. job function, industry), and details about the sponsored content or resources you interacted with. If you choose to interact with a booth or access sponsored content, you are explicitly consenting to receipt and use of such data by the third-party recipients, which will be subject to their own privacy policies.

### 10:45–14:45 · Project Pavilion | Wednesday AM Project Tables

- Room: 3F | 301-304
- Track: Project Opportunities
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1276307

Wednesday AM Project Tables | 10:45 - 14:45

T-1 CoHDI
T-2 Cilium
T-3 OpenChoreo
T-4 Community-Led Events + TCGs
T-5 Longhorn
T-6 HAMi
T-7 k0s
T-8 CoCC

### 10:50–11:20 · Gold Sponsor In-Booth Demos

- Room: 3F | 301-304 + Foyer
- Track: Sponsor Demos
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1288093

Sponsor: Datadog
Demo: AIで進化するKubernetesモニタリング
Booth Number: G7

In order to facilitate networking and business relationships at the event, you may choose to visit a third party’s booth or access sponsored content. You are never required to visit third party booths or to access sponsored content. When visiting a booth or participating in sponsored activities, the third party will receive some of your registration data. This data includes your first name, last name, title, company, address, email, standard demographics questions (i.e. job function, industry), and details about the sponsored content or resources you interacted with. If you choose to interact with a booth or access sponsored content, you are explicitly consenting to receipt and use of such data by the third-party recipients, which will be subject to their own privacy policies.

### 11:30–11:33 · Project Lightning Talk: Opening Remarks

- Room: 3F | 313+314
- Speakers: Hoon Jo
- Track: Project Opportunities
- Labels: Project Lightning Talks
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1232419

### 11:30–12:00 · Beyond Power and Magic: Forging Stable eBPF Tools for the Post-Demon King Era

- Room: 3F | 315
- Speakers: Kenta Tada, Carla Gaggini
- Track: Cloud Native Novice
- Labels: Any, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1191889
- Slides: https://sessionize.com/download/ydatnei~SFKAemCpwMCM26TwL1Sse9.pdf~beyond-power-and-magic_-forging-stable-ebpf-tools-for-the-post-demon-king-era.pdf

The Demon King is dead. The cluster is stable... until the next kernel upgrade.

In the early days, eBPF felt like powerful magic—quick, flexible, and capable of solving deep system problems. But as eBPF tools enter production, the focus shifts to durability. Your spells must survive kernel upgrades, platform changes, and continuous operation. The challenge isn't what eBPF can do, but how to make it stable.

This talk takes a “post-game” RPG approach to eBPF, exploring the challenges that arise after the main quest. We’ll compare classic spells like kprobes and tracepoints with newer magical contracts like fentry/fexit and kfuncs, analyzing their long-term stability. We’ll uncover how BTF and CO-RE act as ancient runes, allowing programs to adapt across kernels without constant rewrites. Finally, we'll share practical lessons on choosing the right abstractions so your tools survive every unexpected boss fight. Our party of platform engineers will learn to wield this magic sustainably!

### 11:30–12:00 · User Namespaces in Production: Enabling Root in Containers with RWX

- Room: 4F | 414+415
- Speakers: Kohei Sugihara, Toru Komatsu
- Track: Security
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194757
- Slides: https://sessionize.com/download/itfagkem~VMUXDTok7SV8vFzHG9Zndb.pdf~user-namespaces-in-production-enabling-root-in-containers-with-rwx.pdf

User Namespaces improve the security of multi-tenant Kubernetes by separating UID/GID between container and host. However, bringing them into production faces a big wall on providing ReadWriteMany (RWX) shared storage. With User Namespaces, volume mounts used on the ID-mapped mount in Linux, but its file system support depends on each filesystem implementation, so there is a case where we cannot apply it for existing remote filesystems.

Our Kubernetes AI/ML platform has multiple storage systems already, and migrating all existing data to another supported filesystem was not a realistic option. Instead of replacing the storage layer, we chose to use NRI to adjust mount definitions at container startup, allowing both User Namespaces and RWX shared volume for existing storage environments.

In this session, we will share the design decisions behind this approach, and practical lessons for introducing User Namespaces into a production Kubernetes platform with existing data assets.

### 11:30–12:00 · OCI is not Git: Rethinking the GitOps Source of Truth for a Kubernetes-Native World

- Room: 5F | 501
- Speakers: Michael Crenshaw, Robin Lieb
- Track: Platform Engineering
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194386

GitOps started with a simple idea: Git is the source of truth. But as the ecosystem matures, OCI is increasingly used to ship Kubernetes config, and the gaps are becoming hard to ignore. Git gives you history, blame, diffing, and PR-based review for free. OCI gives you content-addressable, distribution-ready, airgap-compatible artifacts. Yet the industry is replacing one with the other as though the properties of Git were incidental, not foundational.

This talk introduces Kokumi, an experimental config delivery tool designed for an OCI-first world. Kokumi integrates with Helm and Kustomize to define per-environment config, renders OCI artifacts, and delivers them via Argo CD. This functionality is wrapped in a beautiful UI that feels like the future of Kubernetes deployment.

What does the future of OCI-Ops look like? This talk won’t have all the answers. But it will offer a glimpse into the future and spark the audience’s imagination so that we can build that future together.

### 11:30–12:00 · How to Evolve Your LLM Self-Hosting Platform: A Practical Guide to Adopting Advanced Optimizations

- Room: 5F | 502
- Speakers: Shingo Omura, Yiyang Zhan
- Track: AI + ML
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194846
- Slides: https://sessionize.com/download/vnakmeo~U85LPNKMnwsmtJUvthiBWu.pdf~how-to-evolve-your-llm-self-hosting-platform-a-practical-guide-to-adopting-advanced-optimizations.pdf

When self-hosting LLMs, adopting advanced inference technologies prematurely drastically increases deployment complexity. How should engineers evaluate these tools and determine the right time to introduce them?
Through a real-world case study, the speakers will share their journey of evolving a minimal vLLM architecture into a robust multi-tenant platform using Envoy AI Gateway and Athenz. They will highlight how establishing this foundation—enabling authentication, rate limiting, and crucial tenant-level usage statistics—is a vital use case for safely supporting multiple teams.
Building on this operational foundation, they will discuss their ongoing evaluation and incremental adoption of advanced optimizations like P/D disaggregation and intelligent routing using actual production bottlenecks.
Attendees will learn what each optimization improves, the operational trade-offs, and the optimal timing to introduce them with manageable complexity.

### 11:30–12:00 · A Decade of Cilium Around the World

- Room: 5F | 503
- Speakers: Liz Rice, Hiroki Hanada
- Track: Maintainer Track
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228195
- Slides: https://sessionize.com/download/xnagseg~s93rGzGentSMsb4ThoG51G.pdf~kcj-cilium-maintainers.pdf

Cilium is now 10 years old, and has become the de-facto standard secure networking solution Kubernetes. This session gives updates on the latest developments in Cilium and showcases how its eBPF-powered stack is transforming and simplifying networking and runtime security in Kubernetes environments and beyond.

You’ll hear from Cybozu about why they chose Cilium for efficient networking, L4 load balancing, and network policy, and learn how it supported their migration of services from VMs to Kubernetes on bare metal and enabled secure, scalable operation of their platform in production.

You’ll also hear about community activities around the Cilium project and learn how to get involved, as the project moves into its second decade!

### 11:35–11:40 · Project Lightning Talk: Argo CD at Scale: 5 Features You Should Not Miss!

- Room: 3F | 313+314
- Speakers: Nitish Kumar
- Track: Project Opportunities
- Labels: Argo, Project Lightning Talks
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228165

As organizations scale their GitOps adoption with Argo CD, new challenges begin to emerge, such as monorepos' slow down reconciliation, artifact updates don't always trigger deployments, and safe rollouts or deletions across clusters become harder to control. What works for 20 applications often struggles at 1,000. Performance, scalability, and lifecycle management are now critical concerns for platform teams running Argo CD in production.

In this talk, I'll explore five powerful features that were introduced in the Argo CD recent releases, such as shallow clone feature, OCI registry webhooks support, etc. Together, these improvements make Argo CD faster, more event-driven and safer for large-scale deployments If you're running Argo CD in production or planning to scale, these updates will significantly change how you think about GitOps operations.

### 11:42–11:47 · Project Lightning Talk: What’s New in k0s: Lightweight Kubernetes Without Compromise

- Room: 3F | 313+314
- Speakers: Prithvi Raj
- Track: Project Opportunities
- Labels: Project Lightning Talks, k0s
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228166

k0s, the zero-friction Kubernetes distribution, has been steadily evolving bringing fresh capabilities and smarter defaults without bloating its minimal footprint.

In this lightning talk, I’ll highlight the latest updates in the k0s project with k0s release 1.35, including the enhanced Windows support, updates to the storage, recent improvements in HA setup, multi-node bootstrapping, air-gapped deployments, and cloud-native enhancements.

Whether you're running edge clusters or want a developer-friendly K8s distro that “just works,” k0s is worth a fresh look. Come get a fast-paced tour of what's new, what’s next, and why it matters.

### 11:49–11:54 · Project Lightning Talk: New Frontiers for OpenTelemetry - A Roadmap for the Future

- Room: 3F | 313+314
- Speakers: Ted Young
- Track: Project Opportunities
- Labels: OpenTelemetry, Project Lightning Talks
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1283896

OpenTelemetry (OTel) has become the industry standard for observability. In this session, we will highlight how OTel is shaping the future of observability with architectural, protocol, and ecosystem updates aimed at handling complex cloud-native environments and cutting-edge agentic systems. We will touch upon key initiatives in OTel including GenAI observability with standardized semantic conventions and instrumentation, high cardinality support with Arrow and dynamic configurations, profiling signal support and OTel Blueprints. Join in to learn about what’s in progress and what’s coming!

### 11:56–12:01 · Project Lightning Talk: CoHDI: Dynamic Hardware Composition for AI‑Era Kubernetes Workloads

- Room: 3F | 313+314
- Speakers: Naoki Oguchi
- Track: Project Opportunities
- Labels: CoHDI, Project Lightning Talks
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228168

Kubernetes has traditionally been optimized for deploying workloads on homogeneous servers in cloud environments. However, the rapid adoption of AI workloads is fundamentally changing this assumption, requiring Kubernetes to operate on increasingly heterogeneous hardware, including GPUs and other accelerators.

Efficiently utilizing limited and expensive hardware resources has become a critical challenge. This talk introduces CoHDI (Composable Hardware in Disaggregated Infrastructure), a CNCF Sandbox project that explores dynamic hardware composition by attaching and detaching high‑value devices based on workload demand.
The talk outlines how this approach aligns with ongoing Kubernetes efforts for safe dynamic hardware allocation, including binding conditions that allow scheduler to declaratively wait for required devices. Attendees will gain a concise understanding of why dynamic hardware composition is becoming essential for AI‑era Kubernetes and how the community is addressing it.

### 12:03–12:08 · Project Lightning Talk: Kairos: Immutable OS and Lifecycle Management for Kubernetes Fleets

- Room: 3F | 313+314
- Speakers: William Rizzo
- Track: Project Opportunities
- Labels: Kairos, Project Lightning Talks
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228169

Kairos is an open source, immutable Linux OS for managing fleets across public cloud, on-prem, and edge environments. It can be built on familiar distributions like Ubuntu, Fedora, and openSUSE, or run with Hadron, a minimal Linux focused on upstream alignment and the needs of image-based immutable systems.

Kairos works with or without Kubernetes. It supports lightweight distributions such as k3s and k0s, while lifecycle operations are handled by the Kairos Operator, enabling full node upgrades directly from Kubernetes.

This session highlights recent project updates and introduces Kairos CAPI, our implementation of the Kubernetes Cluster API for provisioning and managing Kairos nodes using standard Kubernetes workflows.

With features like trusted boot, atomic upgrades, rollbacks, and factory reset, Kairos offers a consistent, portable way to manage distributed systems.

### 12:10–12:40 · Don't Start With 500 Clusters: Patterns in Scaling Multi-Cluster Kubernetes Using Cluster API

- Room: 1F | Main Hall
- Speakers: Nibir Bora, Matt Morrison
- Track: Cloud Native Experience
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1191836

This session presents case studies from two companies that independently arrived at the same conclusion: Cluster API as the declarative foundation for fleet-scale Kubernetes. One runs 100+ multi-tenant clusters with its entire stack running on Kubernetes. The other provisions isolated clusters per customer across SaaS, BYOC, and self-managed deployments. Both replaced days of manual toil with automated pipelines.

Kubernetes was designed for a single cluster. But scale ceilings, blast radius, tenant isolation, compliance, and cloud migrations force real businesses into managing 100s of clusters. Most companies should not start here: this talk covers why. But some have no choice.

Attendees will leave with:
- A decision framework for when multi-cluster is necessary versus premature.
- What forced scale-out and how it was solved at two companies.
- A tested pattern for managing 100s of Kubernetes clusters using Cluster API.
- When to build custom operators versus compose existing tools.

### 12:10–12:15 · Project Lightning Talk: Longhorn: What's New & What's Next for Cloud Native Persistent Storage

- Room: 3F | 313+314
- Speakers: Divya Mohan
- Track: Project Opportunities
- Labels: Longhorn, Project Lightning Talks
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228171

Longhorn equips clusters with lightweight, cloud native capabilities, including incremental snapshots, disaster recovery, and RWX support—free from vendor dependencies. In this session, Divya Mohan explores this year's project updates and provides structured insights into the roadmap. The session also aims to outline actionable paths for new contributors by highlighting contribution opportunities within the project.

### 12:10–12:40 · Ground Control to Cloud Native: Safe Deployments for a Growing SAR Satellite Constellation

- Room: 3F | 315
- Speakers: Upendra Gurugubelli, Masaya Arai
- Track: Operations + Performance
- Labels: Any, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194287
- Slides: https://sessionize.com/download/iomgahqe~S3xpm6Dx2VaPqebt7qeFwC.pdf~kubecon-cloudnativecon-japan-2026_ground-control-to-cloud-native.pdf

When your Kubernetes deployments must avoid interrupting a live satellite link 500km above Earth, standard rollout strategies fall short. Synspective operates a constellation of SAR observation satellites where ground systems maintain stateful connections during passes. A deployment at the wrong moment risks losing contact with a satellite in orbit. Each satellite has different communication windows, and as the constellation scales toward 30+ satellites by 2030, manual coordination becomes impossible.

This session presents how Synspective adopted cloud native practices across two mission-critical ground subsystems. First, how Argo CD replaced manual CIOps with declarative GitOps pipelines, delivering auditable, reproducible deployments across multiple environments. Second, how Argo Rollouts enables progressive delivery gated by real-time satellite pass schedules (AOS/LOS windows) from ground station APIs, ensuring releases never interrupt active communications.

### 12:10–12:40 · AIOps: (near) Zero-Touch Production Rollout Fixes

- Room: 4F | 414+415
- Speakers: Kevin Dubois, Carlos Sanchez
- Track: Application Development
- Labels: Beginner, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1145821
- Slides: https://sessionize.com/download/kvaxcez~DiPHh8PrqMdx6iVrYbGe3Q.pdf~kubecon-jp26-kevin-dubois-carlos-sanchez.pdf

Despite our best efforts in testing software, software rollouts can still go wrong, and the process to roll back and find a fix can be painful and complex. Tools like Argo Rollouts provide a robust foundation to ease the pain, but with AI we can revolutionize the developer experience around it. This session shows how you can elevate your release process by:

- Analyzing rollout failures using AI agents that connect to your cluster to gather logs and metrics.
- Employing intelligent, cloud based coding agents that can make code corrections based on the failure analysis and create automated PRs and timely notifications.
- Embracing Human-in-the-Loop oversight by allowing developers to review and course correct if needed.This strategic combination of Cloud Native tools leads to significantly reduced Mean Time To Recovery (MTTR) and a more resilient, productive developer experience. Join us to discover the future of seamless software delivery!

### 12:10–12:40 · Scaling In Kubernetes Safely on On-Prem KaaS Across 1,300+ Clusters and 40,000+ Nodes

- Room: 5F | 501
- Speakers: Shota Yoshimura
- Track: Platform Engineering
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194825
- Slides: https://sessionize.com/download/ujbatve~wECiLyJbNqemMN3AuMqZk1.pdf~scaling-in-kubernetes-safely-on-on-prem-kaas-across-1300-clusters-and-40000-nodes.pdf

Many Kubernetes talks focus on scaling out to support growth, but large platforms also need safe ways to scale in. This is especially true for on-premises Kubernetes as a Service, where unused node capacity affects hardware procurement, rack capacity, and long-term operations.

This talk shares how we built a custom controller to consolidate underutilized worker nodes safely across 1,300+ clusters and 40,000+ nodes. At this scale, underutilized nodes were no longer isolated inefficiencies but a meaningful capacity problem. We needed a more conservative model than a general-purpose autoscaler could provide, so the controller uses observed node usage, seven-day peak metrics, minimum replica guarantees, and machine-group-level safety checks before taking action.

We will also cover safeguards including graceful shutdown expectations, DaemonSet termination ordering, and node deletion behavior designed to minimize user impact.

### 12:10–12:40 · kube-scheduler-evaluator: Evaluating Kubernetes Schedulers at Hyperscaler Scale in Seconds

- Room: 5F | 502
- Speakers: Rihito Bannai, Hidehito Yabuuchi
- Track: AI + ML
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1193392
- Slides: https://sessionize.com/download/zwahtel~YfiUqfLr1fupDRvsCqUjsZ.pdf~kubeconcloudnativecon-japan-2026-fa-biao-zi-liao-.pdf

As AI/ML workloads grow in importance on Kubernetes, evaluating schedulers at scale is critical yet costly. Running tens of thousands of real jobs across thousands of nodes is expensive, and training jobs can take days — making real-time evaluation impractical. Existing tools fall short: scheduler_perf is limited to micro-benchmarks, and kwok/kind still run in real time.

We developed kube-scheduler-evaluator, an open-source framework with three key capabilities:

Go-Based Scenarios: Define large-scale workloads programmatically using Go, not static YAML.
Virtual Time: Decouple simulation from wall-clock time — a multi-day cluster trace with thousands of GPU jobs can complete in seconds.
Flexible Execution: Run as a single binary with emulated controllers, or connect to kwok, kind, or a real cluster.

Attendees will learn how to evaluate schedulers using kube-scheduler-evaluator and how to apply the results to accelerate scheduler development.

### 12:10–12:40 · Rook: Intro and Deep Dive with Ceph

- Room: 5F | 503
- Speakers: Satoru Takeuchi, Deepika Upadhyay, Dan van der Ster
- Track: Maintainer Track
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228183
- Slides: https://sessionize.com/download/ilnabbe~UZs2unVJNc14R4xkTXSEiv.pdf~kubecon_cloudnativecon_japan_2026_rook.pdf

The Rook project will be introduced to attendees of all levels and experience. Rook is an open source cloud-native storage operator for Kubernetes. Rook integrates Ceph, a famous open source distributed storage, with Kubernetes. This session will cover various scenarios to show how Rook configures Ceph to provide stable block, shared file system, and object storage for your production data. Rook was accepted as a graduated project by the Cloud Native Computing Foundation in October 2020.

### 12:17–12:22 · Project Lightning Talk: Spiderpool Unlocks Fine-Grained RDMA Observability for AI Inference

- Room: 3F | 313+314
- Speakers: Weizhou Lan
- Track: Project Opportunities
- Labels: Project Lightning Talks, Spiderpool
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228172

AI inference jobs using models of various sizes may run concurrently on a node, and also introduce cross-node RDMA communication. The lack of RDMA observability means performance bottlenecks go unnoticed and hardware remains underutilized, and node-exporter’s provision of only node-level RDMA metrics can not meet these demands.

Recently, Spiderpool has unlocked full RDMA observability. Multiple RDMA devices via SR-IOV are assigned to each pod, each with its own fixed IP address. This enables each pod’s RDMA traffic to be visible even at the switch’s link level. Additionally, Spiderpool collects RDMA metrics for each pod and node, and provides multi-layer Grafana dashboards aggregating metrics at the node, AI job, and pod levels. Especially in multi-tenant AI inference clusters, this helps identify hot applications and detect communication bottlenecks. This talk will explain how the solution boosts troubleshooting efficiency by over 60% through practical cases.

### 12:24–12:29 · Project Lightning Talk: youki: What's New and What's Next?

- Room: 3F | 313+314
- Speakers: Yuta Nagai
- Track: Project Opportunities
- Labels: Project Lightning Talks, youki
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228174

youki is a Rust-based OCI runtime and the only low-level container runtime within the CNCF ecosystem. It is invoked by Kubernetes and containerd to create and manage isolated Linux processes based on OCI bundles.

While established runtimes like runc and crun are widely adopted, youki continues to evolve through active development and contributions.

In this session, we will explore youki's architecture and its path toward the 1.0.0 release, with a primary focus on improving compatibility with runc as a key requirement for real-world adoption.

Beyond this, we will highlight additional efforts, including integration with libkrun for VM-based container isolation and the implementation of seccomp support natively in Rust to remove the dependency on libseccomp. We will also share how youki collaborates with related CNCF projects in these areas.

Attendees will leave with a clear understanding of youki's current state, its challenges, and how to get involved.

### 12:31–12:36 · Project Lightning Talk: Lima in 5 Minutes: From Containers to AI Sandboxing

- Room: 3F | 313+314
- Speakers: Ansuman Sahoo
- Track: Project Opportunities
- Labels: Lima, Project Lightning Talks
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228175

Initially created for local containers, Lima has since grown into a universal sandboxing tool for developers. In this talk, I will introduce Lima!

What would you do if an AI coding assistant hallucinated and attempted to delete your local workspace? As AI agents become integrated into our daily workflows, running them locally on your host machine is becoming a security risk.

You'll also learn about Lima's new support for GPU acceleration, MCP servers, and protective sync modes, and how you can safely run your AI agents entirely in a VM or connect to the VMs from the host. Come see how Lima is helping to make local container development and AI experimentation fast, easy, and safe!

### 12:38–12:40 · Project Lightning Talk: Closing Remarks

- Room: 3F | 313+314
- Speakers: Hoon Jo
- Track: Project Opportunities
- Labels: Project Lightning Talks
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1232420

### 12:40–14:10 · Lunch 🍲

- Room: 3F | 301-304 + Foyer
- Track: Breaks
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1221382

### 13:00–13:30 · Gold Sponsor In-Booth Demos

- Room: 3F | 301-304 + Foyer
- Track: Sponsor Demos
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1288095

Sponsor: AWS Japan
Demo: From Models to Agents - Running LLM-Powered AI Applications on Amazon EKS Auto Mode
Booth Number: G8

Sponsor: Microsoft
Demo: The developer experience with AKS Desktop and VS Code
Booth Number: G1

In order to facilitate networking and business relationships at the event, you may choose to visit a third party’s booth or access sponsored content. You are never required to visit third party booths or to access sponsored content. When visiting a booth or participating in sponsored activities, the third party will receive some of your registration data. This data includes your first name, last name, title, company, address, email, standard demographics questions, and details about the sponsored content or resources you interacted with. If you choose to interact with a booth or access sponsored content, you are explicitly consenting to receipt and use of such data by the third-party recipients, which will be subject to their own privacy policies.

### 13:30–14:00 · Gold Sponsor In-Booth Demos

- Room: 3F | 301-304 + Foyer
- Track: Sponsor Demos
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1288094

Sponsor: Tintri
Demo: Tintri VMstore 〜Kubernetes を学習して動的にマネージメントするデータプラットフォーム〜
Booth Number: G2

In order to facilitate networking and business relationships at the event, you may choose to visit a third party’s booth or access sponsored content. You are never required to visit third party booths or to access sponsored content. When visiting a booth or participating in sponsored activities, the third party will receive some of your registration data. This data includes your first name, last name, title, company, address, email, standard demographics questions (i.e. job function, industry), and details about the sponsored content or resources you interacted with. If you choose to interact with a booth or access sponsored content, you are explicitly consenting to receipt and use of such data by the third-party recipients, which will be subject to their own privacy policies.

### 14:10–14:40 · Towards Sustainable Multi-Cluster Management in Real-World Academic Infrastructure

- Room: 1F | Main Hall
- Speakers: Jinwang Mok, ChangHyeon Im
- Track: Cloud Native Experience
- Labels: Any, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1193536
- Slides: https://sessionize.com/download/imraqvex~3Pi8NnavbhnA5LdgZw7ZPx.pdf~kubecon_cloudnativecon_japan_2026_-_towards_multi-cluster_management.pdf

Research labs face distinct challenges: heterogeneous hardware, stateful services, and student operators who learned Kubernetes on the job—accumulating legacy no one dares untangle.

Our environment: four bare-metal clusters over 100GbE—a 2PB Rook-Ceph lake, a 22-GPU cluster (7 types incl. L40S, A100), edge devices—run by grad students. We call our unified multi-cluster target "ScaleX-POD". Migrating demands two hurdles: risk-free live migration and tenant isolation.

First, extracting a management cluster from production while external tenants actively run—transferring ArgoCD ownership without orphaning pods or storage, dry-running via vcluster. We share what broke and what we would change. Second, Kyverno-enforced isolation: PSS Restricted, default-deny NetworkPolicies, namespace-scoped RBAC—containing blast radius during and after migration.

Attendees gain failure lessons, migration trade-offs, and a PR-based workflow to reduce knowledge loss across operator transitions.

### 14:10–15:20 · Your First Kubernetes Contribution: A Hands-on Guide to Documentation Localization

- Room: 3F | 315
- Speakers: Ian Y. Choi, Wonyong Hwang
- Track: Cloud Native Novice
- Labels: Beginner, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1192211
- Slides: https://sessionize.com/download/imyaskem~DeNq4Yj2ftkn76w1VRdj5K.pdf~kubecon-cloudnativecon-japan-2026-your-first-kubernetes-contribution-a-hands-on-guide-to-documentation-localization.pdf

Many developers want to contribute to Kubernetes but struggle to find a practical starting point. Documentation contributions provide an accessible way to begin while learning Kubernetes.

In this hands-on tutorial, participants will learn how to make their first contribution through documentation and localization. We will introduce the documentation workflow, explain collaboration with SIG Docs maintainers, and walk through the process step by step.

Using examples from Korean and Japanese localization communities, attendees will see how contributors move from simple documentation updates to upstream discussions and community collaboration.

Participants will learn how to identify documentation issues, understand workflows, and navigate the contribution process. By the end, attendees will know how to start contributing and how localization supports broader participation in the cloud native community.

### 14:10–14:40 · Detecting Compromised CI with eBPF and Cilium Tetragon

- Room: 4F | 414+415
- Speakers: Liz Rice
- Track: Security
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1193018
- Slides: https://sessionize.com/download/iynatheq~YV6wjQ3YUbMPRgD6M8Kx7Q.pdf~kcj-tetragon-in-ci.pdf

CI/CD pipelines are a prime target for attackers. Recent incidents, such as the Trivy workflow compromise, show how CI can be abused to execute untrusted code and exfiltrate sensitive data.

Tetragon, the eBPF-based runtime security component of the Cilium project, is widely used to protect Kubernetes workloads. This talk shows how it can also be applied to CI environments such as GitHub Actions to detect compromised jobs and prevent data exfiltration.

After a brief introduction to how Tetragon leverages eBPF, this talk demonstrates its use in GitHub Actions, providing runtime signals that reveal malicious behavior. You’ll see concrete examples of policies that observe process and network activity to detect unexpected outbound connections and identify compromised jobs in real time.

Attendees will learn practical techniques to use Tetragon to detect and prevent malicious behavior in ephemeral CI environments.

### 14:10–14:40 · Sustainability by Design: Leveraging DRA for Energy-Efficient Kubernetes Clusters

- Room: 5F | 502
- Speakers: Sunyanan Choochotkaew, Faseela Kundattil
- Track: Operations + Performance
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1144619
- Slides: https://sessionize.com/download/hnaztep~SiAjhou5okN43Ztgm4baXb.pdf~sustainability_by_design.pdf

Imagine a city where every machine automatically chooses the cleanest, most efficient energy source before starting work—so the whole system runs smarter and greener. Today, Kubernetes schedules workloads with little awareness of energy use. Workloads rarely see the energy characteristics of the hardware they run on, especially accelerators, and even when they do, it seldom maps to user-facing cost or SLOs.

Dynamic Resource Allocation (DRA) brings this vision closer to reality. Device providers can expose energy consumption and efficiency as attributes, letting Kubernetes prioritize energy-efficient devices. Tools like Kepler can use these metrics to estimate node energy use, powering carbon-aware multi-cluster scheduling and energy-driven autoscaling (e.g., KEDA).

We’ll explore the challenges of treating energy as a schedulable resource, demo a proof-of-concept for energy-aware device selection and power capping, and look ahead to ideas like scheduling on remaining energy capacity.

### 14:10–14:40 · Kubeflow 2026 State of the Union: Orchestrating the Full ML Lifecycle

- Room: 5F | 503
- Speakers: Yash Pal, Anya Kramar, Valentina Rodriguez Sosa
- Track: Maintainer Track
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228192

Kubeflow has grown into a comprehensive ecosystem that powers end-to-end machine learning on Kubernetes.

In this session, we provide a holistic ""State of the Union"" update across all major working groups. We will walk the audience through the lifecycle of a modern model, demonstrating how the unified SDK and Notebook Workspaces simplify authoring.

We will then trace how these workloads transition into scalable Kubeflow Pipelines, undergo distributed training and hyperparameter tuning via Trainer v2 and Katib, and are finally cataloged in the Model Registry before being deployed via KServe.

We will conclude by outlining the upcoming project roadmap and providing updates on how we can improve core Kubeflow components or build integration bridges to adjacent OSS AI projects.

### 14:10–14:40 · Becoming an Impactful CNCF Member

- Room: 4F | 411+412
- Speakers: David Palilonis, Danielle Cook
- Track: Experiences
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1236996
- Slides: https://sessionize.com/download/ixrarzen~QZdC7t4pQY57KZ8vys665Q.pdf~kubecon-japan-yokohama-becoming-and-impactful-cncf-member.pdf

This session is your guide to becoming an impactful and effective CNCF member. We’ll cover the tangible benefits and responsibilities of membership, including providing project support, contributing code, fostering diversity, and participating in governing bodies. We will debunk common misconceptions and provide a clear framework for how a company, large or small, can actively shape the future of cloud native technologies. You will walk away with actionable steps and a deeper appreciation for the collaborative "movement" that drives innovation at the CNCF.

### 14:50–15:20 · The State of Cloud Native: The Shift Towards AI

- Room: 1F | Main Hall
- Speakers: Katie Gamanji
- Track: Cloud Native Experience
- Labels: Beginner
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1154416

With Kubernetes established as the foundation of platform deployment, the cloud native ecosystem continued to evolve to meet the demands of the growing end user community. Today, the landscape stands at an inflection point, beyond containers, where AI is rapidly becoming an integral part of established and emerging projects.

This talk examines the current state of the ecosystem through the lens of the AI shift. It explores the established patterns, governance models, and community structures that stabilized the cloud native landscape and are now becoming the blueprint for a mature open source AI landscape.

The session takes a reverse engineering approach to understanding where the ecosystem is headed. The attendees will learn how core principles, such as openness, vendor neutrality, interoperability, and an open community, are becoming the driving forces behind this next wave of transformation and the shift towards AI.

### 14:50–14:55 · ⚡Lightning Talk: How Writing a Cluster Inventory API Plugin Led Me to Maintainership

- Room: 3F | 313+314
- Speakers: Kahiro Okina
- Track: ⚡Lightning Talks
- Labels: Beginner, Cloud Native Experience, Japanese
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1183851
- Slides: https://sessionize.com/download/itvaixfe~XotTCZ9hCH4ifw6cymcFjK.pdf~how-writing-a-cluster-inventory-api-plugin-led-me-to-maintainership.pdf

A spec without implementers is just a document. When KEP-5339 introduced the plugin specification for SIG-Multicluster's Cluster Inventory API, there were zero official plugins, no usage examples, and no implementation guidance.

In this session, I'll share how I became the first plugin implementer: building a Secret Reader plugin based on the KEP spec, designing a kubeconfig secret reader plugin that went beyond the spec, driving improvements back to the KEP itself, and eventually earning maintainership. I'll cover the design decisions I made, the mistakes I didn't avoid, and how I built trust with existing maintainers along the way.

You'll walk away with concrete patterns for earning trust in a Kubernetes SIG and enough knowledge to start writing your own Cluster Inventory API plugin. You'll also see how a project with no implementers can grow into an ecosystem when the community shows up.

### 14:50–15:20 · Running Wasm Inside Your Storage Cluster with CSI and Gateway API

- Room: 4F | 414+415
- Speakers: Ho Kim, SangJoon Park
- Track: Data Processing + Storage
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1193296
- Slides: https://sessionize.com/download/hrahun~WDwexSVWNZAWcta9MaDmpR.pdf~cdl-v1r16.pdf

The cloud-native world has long embraced separating compute from storage. But AI workloads are exposing a new bottleneck: the network itself.

Vendors respond by preprocessing data to cut bandwidth, or integrating RDMA and specialized hardware for faster transfers. The first still saturates the network during preprocessing. The second trades openness for hardware lock-in.

We took a third path: running user-defined WebAssembly code directly inside the storage cluster, as close to the NVMe devices as possible. Unlike SQL pushdown, computation is free-form. Unlike a compute cluster, data never leaves the storage nodes.
We will share how we used CSI and Gateway API on Kubernetes to expose this as a cloud-native, open-source capability.
Along with the dead ends we hit, the benchmarks we ran, and the security boundaries we have not yet crossed.

The project is open source. We want the community to tell us what comes next!

### 14:50–15:20 · Evolving Platform Primitives: Beautiful Platforms with kro

- Room: 5F | 501
- Speakers: Jakob Möller, Adam Crowder
- Track: Platform Engineering
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194896
- Slides: https://sessionize.com/download/iuntalke~KHQiJCdp9aBdg6wPsXx8RE.pdf~evolving-platform-primitives-kubecon-japan-2026-to-submit.pdf

Great platforms aren’t built by adding more tools, they’re built by designing great primitives. Yet most teams glue raw Kubernetes resources together with templates, scripts, and custom controllers, leaving developers to navigate
complexity the platform should hide.

This session reframes platform building as a two-step process: define your abstractions as composable primitives and let Kubernetes handle the rest.

Using kro (Kube Resource Orchestrator), attendees will see how to author self-service APIs that compose any Kubernetes resources, with dependency ordering, dynamic wiring, and status rollup handled automatically.

They’ll learn to design API surfaces for platform consumers, when to choose graph-based composition over writing operators, and how to ship opinionated golden paths without losing flexibility.

Attendees will leave with a practical mental model for platform abstractions that scales with their organization.

### 14:50–15:20 · Manufacturing Alerts to ReActive Agents: Self-Evolving AI Agents on K8S for Predictive Maintenance

- Room: 5F | 502
- Speakers: Seungtae Moon
- Track: AI + ML
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194881

Most predictive maintenance systems send alerts based on thresholds – notify when a sensor reading crosses a limit, then leave root-cause analysis and decision making to engineers.

This session presents the architecture of a self-evolving AI Agent system designed for manufacture domain on a Kubernetes-based platform. Rather than building a single monolithic agent, the speaker shows three key design decisions: (1) a ReAct-based cognitive architecture with a modular skills engine, (2) a hierarchical multi-agent deep search architecture using a multi-perspective pattern with cross-reference synthesis, and (3) a self-evolving mechanism where the agent detect repeated interaction patterns via reflection and autonomously registers new skills.

Attendees will leave with a concrete architecture for building AI Agent systems that run as cloud native microservices on Kubernetes – designed to be modular, observable, and extensible across any industrial domain.

### 14:50–15:20 · Open Source Meets Production MaaS: GMI Inference Engine and Karmada for Global AI Inference

- Room: 5F | 503
- Speakers: Xiaokang Wang
- Track: Maintainer Track
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228196
- Slides: https://sessionize.com/download/ijyakiw~Q5HBTdxzB2CbMy2MqiPbUQ.pptx~kubecon-cloudnativecon-japan-2026-branded-powerpoint.pptx

Global AI inference across 40+ regions and 5+ GPU vendors needs more than GPU capacity. It also needs a practical way to govern clusters, distribute control-plane artifacts, and maintain consistent operations at scale. GMI Inference Engine is GMI Cloud’s Kubernetes-native inference platform, with intelligent routing, heterogeneous resource abstraction, GPU page fault, and entropy-aware placement. This talk shows how GMI uses Karmada, a CNCF-incubating project, to improve multi-cluster governance, CRD distribution, failover readiness, and platform delivery for global AI services.

Agenda

- Business challenges in running global AI inference across regions and GPU vendors
- Where Karmada helps: multi-cluster governance, CRD distribution, failover, and consistency
- Where GMI Inference Engine helps: routing, GPU awareness, elasticity, and placement
- How open-source Karmada supports GMI’s production platform
- Lessons learned and collaboration opportunities for the community

### 14:57–15:02 · ⚡Lightning Talk: Learning Kubernetes From Logs: Building a Foundation for Future Troubleshooting

- Room: 3F | 313+314
- Speakers: Kakeru Ishii
- Track: ⚡Lightning Talks
- Labels: Beginner, Cloud Native Novice, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194135
- Slides: https://sessionize.com/download/xsanvev~SZrYZFjFPhFiXPD992Srbj.pdf~learning-kubernetes-from-logs.pdf

A Deployment creates a ReplicaSet, which creates Pods, and eventually, the kubelet and containerd execute them. While this Kubernetes lifecycle is fundamental, understanding the theory differs greatly from observing it in practice. Few have witnessed these component interactions firsthand.

In this session, attendees will explore the behavior of basic resources and controllers from a logging perspective. The presentation will trace these behaviors using logs—from audit logs and kube-controller-manager logs, down to containerd logs. By focusing on fundamental resources like Deployments and Services, observing them through logs will significantly deepen participants' understanding of how Kubernetes operates under the hood.

Drawing on years of experience supporting Google Kubernetes Engine, the speaker will share foundational knowledge applicable to troubleshooting clusters on any provider. Attendees will leave knowing exactly where to start looking to prepare for their next incident.

### 15:04–15:09 · ⚡Lightning Talk: 1 Year, 15 Certs, Zero Kubernetes at Work: How I Became a Golden Kubestronaut

- Room: 3F | 313+314
- Speakers: Yu Misaki
- Track: ⚡Lightning Talks
- Labels: Beginner, Cloud Native Novice, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1187775
- Slides: https://sessionize.com/download/igmaclet~ExwDmdcp1q1HHQMw2myJAU.pdf~kubecon2026_lt_misaki.pdf

The speaker never set out to collect certifications. He just thought Kubernetes looked cool.

It started with watching a colleague deploy workloads and seeing nodes scale up automatically — all visible in real time through k9s. That curiosity led to CKA — which took two attempts. But passing revealed how much the next exams overlapped, so he kept going and earned Kubestronaut. Then a new question: "What about all the CNCF technologies I've never touched?" A Raspberry Pi home lab turned unfamiliar tools into genuine interests — and before he knew it, all 15 certifications were done in 14 months, without ever using Kubernetes at work.

This lightning talk traces that unplanned chain reaction. Attendees will learn:

- All you need is curiosity — no production experience or employer support required
- One step leads to the next — each exam opens a door to the next; momentum builds naturally
- The hardest part is the first step — don't aim for 15; just try the one that interests you

### 15:11–15:16 · ⚡Lightning Talk: From First Contribution to Maintainer: An OSS Journey Inside youki

- Room: 3F | 313+314
- Speakers: Yusuke Sakurai
- Track: ⚡Lightning Talks
- Labels: Beginner, Cloud Native Experience, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1191137

OSS contributions can reshape how you learn and join a community. But for many engineers, the path from newcomer to maintainer remains a black box. How do you choose your first issue, build trust, and earn a role?
In this session, two engineers share how they became Reviewer and Maintainer of youki, an OCI-compliant container runtime written in Rust.
- Moving from consumer to creator: How creating issues, not just claiming them, turns one-off contributions into sustained involvement.
- Getting PRs merged with fewer round trips: How to grasp the reviewer's perspective, split changes effectively, and reach merge faster.
- Earning a role: How a clear vision for the project builds the trust that leads to Reviewer and Maintainer status.
- Scaling your impact: How Umbrella Issues bring in new contributors and move the project further than any single person can.
Everything here comes from real PRs and review threads inside youki. Take back how to get past the walls most contributors run into.

### 15:15–19:15 · Project Pavilion | Wednesday PM Project Tables

- Room: 3F | 301-304
- Track: Project Opportunities
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1276317

Wednesday PM Project Tables | 15:15 - 19:15

T-1 Kairos
T-2 Headlamp
T-3 Keycloak
T-4 Community-Led Events + TCGs
T-5 kubeflow
T-6 Open Cluster Management
T-7 Akri
T-8 Istio

### 15:20–15:50 · Coffee Break ☕

- Room: 3F | 301-304 + Foyer
- Track: Breaks
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1221374

### 15:50–16:20 · Sandbox for Agentic Application with Cloud Native Stack

- Room: 1F | Main Hall
- Speakers: Xu Wang, Yu Hu
- Track: Cloud Native Experience
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1193243

Now a days, the applications are moving to agentic. On the other hand, as the codes fetched or generated by agents can not be treated as trusted product and we should keep our confidential data and infra control plane untouchable by the agent directly.

Based on existing (proved) Kubernetes infrastructure, we (kata container developers, ant open source team, and Japan AI team) build the sandbox services with agent-sandbox, Kata Containers, dragonfly, and pvm kernel virtualization driver, which make the service not only secure, but also secure enough.

Live demo will be shown in this session.

### 15:50–16:10 · Sponsored Demo: Secure, Portable, Operable: A Strategy for Modern Services

- Room: 3F | 313+314
- Speakers: Grégory Schiano Lomoriello
- Track: Sponsor Demos
- Labels: Any, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1282579

This session shows a practical way to build and operate microservices with the Canonical ecosystem. We’ll cover orchestration, operators, and building small, secure Ubuntu-based container images. We’ll also show how we can reduce container image size and attack surface, and how the same tooling can be used across Kubernetes and virtual machines. The focus is on real application delivery: services that are easier to deploy, monitor, scale, and maintain.

### 15:50–16:20 · I Tested 7 So You Only Need 1: Your First Gateway API Migration in 5 Minutes

- Room: 3F | 315
- Speakers: Hoon Jo
- Track: Cloud Native Novice
- Labels: Beginner, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1182975
- Slides: https://sessionize.com/download/iokhadte~hBr3fSYZGaxdwqykAepm8i.pdf~kccnc-japan2026-i-tested-7-so-you-only-need-1-your-first-gateway-api-migration-in-5-minutes_hoon-jokuberneteslab.pdf

Your team just heard Ingress NGINX retired. Someone has to migrate to Gateway API, and that someone is you. Where do you start?

This session is for beginners who never touched Gateway API. This PoC tested 7 implementations across 17 scenarios and distilled the simplest path for your first migration.

The core is a live 5-minute challenge on a split screen. One side runs continuous curl against a working Ingress endpoint. Then the Ingress gets deleted and curl starts failing. Using ingress2gateway, the config is converted, Gateway API resources are deployed with the same IP, and the same curl recovers without changing the URL. The audience watches the full cycle: working, broken, recovered.

Structure: what changed and why (5 min), core concepts and why this path from 7 tested implementations (5 min), live 5-minute migration challenge (10 min), next steps and the Gateway Readiness Score (5 min), Q&A (5 min). Attendees leave ready to try on their own cluster.

### 15:50–16:20 · Taming Billions of Rows: Data Lifecycle Management Lessons from a Cloud-Native Database Migration

- Room: 4F | 414+415
- Speakers: Ruslan Kadyrov
- Track: Data Processing + Storage
- Labels: Any, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194844
- Slides: https://sessionize.com/download/ilzakid~BWRqJYjw6dzFitebuUcw8Q.pdf~taming_billions_of_rows_ruslan_kadyrov.pdf

As systems scale, data rarely disappears - only accumulates. For large-scale platforms, this creates a hidden but critical problem: unbounded data growth becomes a primary driver of infrastructure cost and migration risk.

At Mercari, one of our core MySQL tables reached billions-scale records as the platform expanded. During our migration to a cloud-native distributed database (TiDB), we discovered that historical, inactive data - not live traffic - had become a significant factor influencing cost and migration complexity.

This talk presents a real-world case study of designing and executing a large-scale data lifecycle management strategy, focusing on reducing the impact of dormant records that no longer contribute to active user workflows, while preserving full user-facing functionality and data accessibility.

This session focuses on practical patterns for managing data growth in cloud-native environments and highlights why data lifecycle management must be part of any scalable platform strategy - not an afterthought.

### 15:50–16:20 · Turning Platform Engineering Work into Business Value Leadership Understands

- Room: 5F | 501
- Speakers: Danielle Cook, Simon Forster
- Track: Cloud Native Experience
- Labels: Any, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1140658

Platform engineering teams are building powerful cloud native capabilities: internal platforms, automation, self-service infrastructure, and better developer experiences. But many struggle to explain why this work deserves investment.

This session shares real-world examples of organizations evaluating cloud native tools and platforms and how they successfully connected technical platform improvements to measurable business impact.

We’ll show how teams translated developer productivity, operational efficiency, and platform maturity into language executives use for funding decisions. You’ll see the exact materials, metrics, and framing that helped teams secure buy-in for cloud native investments.

Whether you’re building an internal platform or modernizing infrastructure, this talk provides practical guidance on how to position your work as a business enabler - not just a technical upgrade.

### 15:50–16:20 · From Experiment to Enterprise: Scaling an AI Agent for Code Review

- Room: 5F | 502
- Speakers: Adam Phan
- Track: AI + ML
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194119
- Slides: https://sessionize.com/download/inovtaj~BKmmVoMHf2WVivs63ZM6Uj.pdf~from-experiment-to-enterprise-scaling-an-ai-agent-for-code-review.pdf

At enterprise scale, rolling out internal AI Agents in production becomes a platform challenge that spans confidentiality, governance, review quality, and cost. This session examines how Sony Interactive Entertainment’s Engineering Enablement team took a code review AI Agent from early experimentation to production rollout across more than 400 internal PlayStation repositories.

The talk explores the architectural and operational tradeoffs behind introducing AI-assisted reviews on a shared enterprise platform while protecting confidential code, satisfying security and compliance requirements, and scaling Kubernetes workloads to meet demand. It covers rollout and governance patterns, quality evaluation, cost control, and the operational boundaries between human judgment and AI-generated feedback.

Attendees will leave with practical patterns for introducing and operating AI-assisted development workflows on a shared enterprise platform.

### 15:50–16:20 · Identities and Authentication for your Agents with Keycloak

- Room: 5F | 503
- Speakers: Takashi Norimatsu, Alexander Schwartz
- Track: Maintainer Track
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228194
- Slides: https://sessionize.com/download/iovmaste~BTNVTpsKLrNsF9Hb6NdD6S.pdf~2026-07-29-kubeconjp2026_yokohama_v1_0.pdf

AI agents and agentic workflows revolutionize the way we build applications, and the market is expanding rapidly. One of the developing standards of this integration is MCP.

The more capabilities we provide to agents and the more we integrate them, the more emphasis is on accurate and effective authorization for their activities.

Keycloak supports the authorization part of MCP. In this session, we will introduce the different versions of MCP, the capabilities of Keycloak, and show you how to configure Keycloak for using is as an authorization server for agents.

We also summarize other AI-related capabilities of Keylcoak like dynamic client registration, CIMD, and leveraging existing workload identities. Then we’ll look ahead at what AI features are on the roadmap of Keycloak in the coming months.

### 15:50–17:40 · Maintainer Meet-Up

- Room: 4F | 411+412
- Track: Project Opportunities
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1266421

The Maintainer Meetup is for CNCF Maintainers to share best practices, dive into contributing processes, and solve common problems across projects.

### 16:30–17:00 · Beyond the Code: Fostering Shared Vision and Technical Leadership in CNCF Communities

- Room: 1F | Main Hall
- Speakers: Kevin Wang, Karena Angell, Faseela Kundattil, Mauricio "Salaboy" Salatino, Katie Gamanji
- Track: Cloud Native Experience
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194974

For active contributors in the cloud-native ecosystem, the greatest challenge is often not code, but transitioning to a broader perspective: how to leverage influence to guide a project toward a healthier, sustainable community. True open-source leadership is never about power grabbing or acquiring titles; it is rooted in facilitating consensus and building a shared vision across a diverse, multi-vendor ecosystem.
In this panel, CNCF technical and community leaders will combine their macro-level perspectives with hands-on governance experience to deconstruct how to naturally establish technical influence by fostering consensus.

Key topics to be covered:
- The Mindset Shift: Evolving from a tactical "issue solver" to a strategic community steward.
- Shared Vision: Transcending corporate interests for genuine, vendor-neutral consensus.
- Navigating Conflicts: Resolving technical disagreements to keep projects moving forward.
- Sustainability: Empowering others and building healthy mentorship pipelines.

### 16:30–16:50 · Sponsored Demo: MCP Auth Demo: CIMD with Keycloak

- Room: 3F | 313+314
- Speakers: Tatsuya Kurosaka
- Track: Sponsor Demos
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1282583
- Slides: https://sessionize.com/download/gxanyej~GxpKv4X6V3d6BEk7wKPgeT.pdf~kurosaka_kubeconjapan2026_demosession.pdf

"As AI integrations mature, authorization has become a key architectural concern. The latest MCP authorization specification (2025-11-25 ver.) redefines how client identity is handled in dynamic environments, and Keycloak now supports these requirements.
This session explains the core ideas behind the latest MCP authorization model and what it requires from an authorization server. It focuses on the use of Client ID Metadata Documents (CIMD) as a method for client identification, highlighting how dynamically provided client metadata influences authorization decisions and operational responsibilities.
The session includes a live demonstration showing how Keycloak supports the latest MCP authorization model in practice. Attendees will see how Keycloak processes CIMD-based client information and enforces authorization decisions, illustrating how MCP authorization flows can be implemented using standard Keycloak capabilities."

### 16:30–17:00 · From Tool Calls to Context Fabric: Building AI-Native Observability for Platform Engineering

- Room: 3F | 315
- Speakers: Deepak Choudhary, Dheeraj Kapur
- Track: Observability
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194636
- Slides: https://sessionize.com/download/ibonfag~H9x168ctY39op51cx7ZQX4.pdf~kubecon.pdf

When an engineer asks "Why is this service failing?", the answer is rarely in one place. Metrics live in Prometheus, logs in Loki, anomaly signals elsewhere, and operational knowledge in runbooks. Existing AI approaches—RAG, Text-to-PromQL, single-tool copilots—each work well in one domain but struggle to connect signals across them. We present an AI context fabric for platform observability that links services, metrics, logs, anomalies, and documentation ahead of time using knowledge graphs, metadata caches, and cross-domain relationship modeling, all exposed to agents via Model Context Protocol (MCP). Instead of forcing agents to piece together raw, fragmented data, the fabric hands them grounded, cross-domain context. Our architecture combines a schema cache for instant metadata discovery, a documentation knowledge graph with semantic edges, and a metrics catalog—unified through MCP. The result: faster root cause analysis, sharper reasoning, and significantly lower token cost.

### 16:30–17:00 · Changing the Engine Mid-Flight: Zero-Downtime Ceph Upgrades

- Room: 4F | 414+415
- Speakers: Cuong Nguyen
- Track: Data Processing + Storage
- Labels: Advanced, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1192985
- Slides: https://sessionize.com/download/ciftabve~TkFtUe7fbfjMviHhd9hhLL.pdf~ceph_upgrade-kubecon_cloudnativecon_japan_2026.pdf

"Upgrade Ceph in our telco cloud with zero downtime." That is a mandatory requirement every 1–2 years to ensure security patches, bug fixes, and continued support from vendors and the community. We have a Ceph Cluster version 18.x.x with 10–50 nodes deployed on bare-metal running 5G Core workloads (AMF, UPF,...).
This talk covers a first-hand Reef → Squid upgrade with three real failure scenarios:
- Monitor quorum loss: root cause analysis, recovery sequence, and how to prevent quorum degradation during daemon rolling restarts
- OSD storms triggered by rebalancing that threatened cluster stability
- Incompatible client versions silently blocking the upgrade path

Beyond failure recovery, we'll share the upgrade sequencing strategy we developed — covering pre-flight checks, daemon upgrade ordering (MGR → MON → OSD → MDS/RGW).
Attendees leave with a reusable pre-upgrade checklist and sequencing framework for bare-metal Ceph in high-stakes environments.

### 16:30–17:00 · Vulnerability Response for Large Open Source Projects

- Room: 5F | 501
- Speakers: Jo Guerreiro, Charline Voinot
- Track: Security
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1193847
- Slides: https://sessionize.com/download/wzalbep~3nGzWxJDgYHZ6mmkb3aVXA.pdf~kubecon-japan-2026-vulnerability-response-for-large-open-source-projects.pdf

Vulnerability management is an evolving topic that was hard pre-coding agents and can now become overwhelming for security and authentication teams. Add to that multi-version support, multi-tenancy and separate deployment waves and you have the recipe for an unmitigated headache.
Join Grafana’s journey in this topic as we deep dive into how we handled CVE-2023-3128 three years ago and how we handle vulnerability classification and patch distribution, from our cloud environment to millions of Grafana instances worldwide, today.
You’ll learn how to distinguish between a vulnerability and an intended feature, how to orchestrate the rollout of a vulnerability patch and how to remain transparent to your community of users without placing their deployments at risk. When maintainers face increasing pressure from a high volume of pull requests and AI-generated vulnerability reports, there is a critical need to refine and advance our security practices.

### 16:30–17:00 · From Model Serving to Distributed Inference: How llm-d Evolves AI Platforms on Kubernetes

- Room: 5F | 502
- Speakers: Kay Yan, Linbo He
- Track: AI + ML
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194013
- Slides: https://sessionize.com/download/ibujbam~WcHMv9fPaghzriNgGpSBmT.pdf~from-model-serving-to-distributed-inference.pdf

This session explores how platform teams can evolve from basic model serving to production-grade distributed inference on Kubernetes. KAITO streamlines model onboarding and lifecycle management with curated presets, GPU node auto-provisioning, autoscaling, OpenAI-compatible endpoints, and support for runtimes such as vLLM. llm-d extends this foundation with inference-aware scheduling, KV-cache-aware routing, cross-node cache coordination, prefill/decode disaggregation, and workload-aware autoscaling. Rather than treating deployment and inference routing as separate concerns, this talk presents a practical reference architecture that brings both together on Kubernetes. It also explains how Gateway API Inference Extension can serve as a common interface, including InferencePool, Endpoint Picker, and Body Based Routing, and when teams should move from basic serving to distributed inference.

### 16:30–17:00 · SIG Scheduling Update: Transition from Pod to Workload Scheduling

- Room: 5F | 503
- Speakers: Kensei Nakada, Yuki Iwai
- Track: Maintainer Track
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228185
- Slides: https://sessionize.com/download/gowhag~XRuFvy2qREeAzV9iHG79Qs.pptx~sig-scheduling-update-transition-from-pod-to-workload-scheduling.pptx

"Over the past year, SIG Scheduling has been redefining how Kubernetes approaches scheduling—moving from a Pod-centric model toward a holistic, Workload-aware architecture. This shift influences not only the scheduler internals, but also many external components which interact or integrate with kube-scheduler over a new set of APIs.

In this session, we will walk through the major scheduling enhancements introduced in recent releases and explain how they fit into the broader Workload-Aware Scheduling initiative. We will also share updates from related sub-projects, including Kueue and the Descheduler.

Finally, we will present what is on the agenda for the future releases, summarize community contributions and outline opportunities to help in shaping the future of Kubernetes scheduling."

### 16:30–17:30 · Women's Community Gathering

- Room: 4F | 413
- Track: Experiences
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1273970

Women’s Gatherings enable meaningful networking, peer mentorship, collaboration, and sustained engagement. They create intentional opportunities to amplify the voices of individuals who identify as women and non-binary, celebrate achievements, and strengthen representation across the ecosystem.

### 17:10–17:40 · How Community Infrastructure Helped Grow Taiwan’s Open Source Contributors

- Room: 1F | Main Hall
- Speakers: Ching Kuo, ChengHao Yang
- Track: Cloud Native Experience
- Labels: Beginner, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194873

Access to real infrastructure is one of the biggest barriers for people who want to learn Kubernetes and contribute to open source. To lower that barrier, the Cloud Native Taiwan User Group created Infra Labs, a community-supported platform that provides free infrastructure resources for students, developers, and open source communities in Taiwan.

This talk shares two connected stories: how a local community built shared infrastructure to support learning and collaboration, and how ChengHao Yang used Infra Labs to start learning Kubernetes in 2023, wrote 30 articles, contributed to Kubespray in 2024, became a reviewer, and later became a Kubespray maintainer in 2025. The session shows how community-built infrastructure can reduce barriers, create opportunities, and help grow the next generation of open source contributors.

### 17:10–17:40 · From 165 Days to 30 Minutes: Breaking Enterprise Silos with Platform Engineering

- Room: 3F | 315
- Speakers: Aoi Nishijima, Moeka Okamura, Kohei Yamamoto
- Track: Platform Engineering
- Labels: Beginner, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1192547
- Slides: https://sessionize.com/download/invactek~hsjh64ZyKmfvQMgJSWH3Jz.pdf~from-165-days-to-30-minutes-breaking-enterprise-silos-with-platform-engineering.pdf

How can an enterprise developer start coding in 30 mins instead of 165 days? Platform Engineering is often idealized in greenfield environments, but large enterprises face a labyrinth of legacy processes. At JAL Digital, 4,000 engineers supporting 500 systems were bound by silos—requiring 15 departments and 40+ forms for environment setup, hitting a staggering 165-day lead time.
We share our journey of transforming this rigid organization through a true cultural shift focusing on three pillars: Mixed Teams to end "us vs. them" conflicts, Autonomy as Fuel by letting teams choose their own tech like Backstage to ignite passion, and Small Wins by targeting high-friction bottlenecks first to gain trust.
We will demonstrate an architecture that automates legacy approvals into a "one-click" experience. This story is for every engineer—especially the next generation—trapped in bureaucracy. Learn practical, human-centric steps to build a platform developers actually want to use.

### 17:10–17:40 · A Practical, Research‑Backed Introduction to Cloud‑Native Kernel‑Bypass Networking

- Room: 4F | 414+415
- Speakers: Kenichi Yasukata
- Track: Emerging + Advanced
- Labels: Beginner, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194581
- Slides: https://sessionize.com/download/ynavjeo~s7WjomeDp9fFk1dAA8smsG.pdf~kubecon_cloudnativecon_japan_2026-yasukata.pdf

As cloud‑native systems scale, achieving predictable low-latency and high-throughput networking has become a key challenge. Overheads introduced by conventional networking stacks increasingly limit performance for latency‑sensitive workloads.

This session serves as an introductory guide to kernel‑bypass technology, providing a structured path for understanding the topic from fundamentals to emerging research. It begins with core concepts and explains why kernel bypass can deliver significant performance improvements. The talk then introduces advances in user‑space TCP/IP stacks, including the speaker’s own research, and discusses essential design choices, trade‑offs, and experimental results approaching near‑hardware‑level performance.

Finally, the session connects these ideas to practice by outlining Kubernetes‑oriented deployment models and integration challenges, helping attendees understand current capabilities and future directions of high‑performance cloud‑native networking.

### 17:10–17:40 · Lessons From Five+ Years of Fluent Bit: Building a Global-Scale Observability Agent

- Room: 5F | 501
- Speakers: Hiroshi Hatake
- Track: Observability
- Labels: Advanced, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1151826

Fluent Bit is a vendor-neutral telemetry agent for processing logs, metrics, and traces in resource-constrained environments. Over five years, it has grown from a lightweight log forwarder into a core component of global observability pipelines.

In production, non-UTF-8 inputs (e.g., GBK, Shift-JIS) are now a baseline requirement, not an edge case. This session shares lessons from maintaining Fluent Bit as a CNCF project: multi-telemetry support, edge performance constraints, and character encoding ambiguity. We’ll cover key design trade-offs, the architectural impact of non-UTF-8 logs, and boundary conversions such as UTF-16→UTF-8 as systemic challenges.

We’ll also show a practical, offline workflow to validate deterministic encoding-conversion rules against existing specifications and uncover hard-to-spot edge cases.

### 17:10–17:40 · Beyond Single-Cluster Limits: Scaling GPU Workloads Across Kubernetes with Virtual Nodes

- Room: 5F | 502
- Speakers: Kunal Das, Esmira Bayramova
- Track: AI + ML
- Labels: Advanced
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194756

Our ML platform team hit a wall when GPU demand became unpredictable. Fine-tuning jobs queued for hours on busy days while expensive on-prem GPUs sat idle on others. Adding cloud GPU clusters solved capacity but fractured our workflow , developers juggled multiple kubeconfigs, Kueue couldn't see cross-cluster queues,workloads couldn't failover because "multi-cluster" was really just isolated clusters with shared dashboards.

In this talk, we walk through how we used Liqo's virtual node pattern to unify 5 heterogeneous clusters , mixing on-prem A100/ H100 nodes with cloud spot GPU instances from cloud providers , into a single schedulable topology. We'll share how the vanilla Kubernetes scheduler handles placement using standard node selectors and affinities, how Cilium's cluster mesh compared to Liqo's WireGuard-based network fabric for cross-cluster pod traffic, and how we integrated Kueue for unified job queuing across the virtual cluster.

### 17:10–17:40 · Longhorn: Intro, Deep Dive and Q&A

- Room: 5F | 503
- Speakers: Derek Su
- Track: Maintainer Track
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228188
- Slides: https://sessionize.com/download/tka~Gr1FGyTLUwUJaL6CxonNuC.pdf~kubeconjp26-longhorn.pdf

Longhorn is a cloud-native, distributed block storage solution built for Kubernetes and various workloads, including containers and virtual machines. It is widely integrated as an infrastructure component in other software platforms, adopted across diverse environments, and operates on both dynamic and immutable systems, with hundreds of thousands of deployments worldwide. Currently sponsored by CNCF, it is an incubating project working toward graduation. In this presentation, we will update you on recent major releases, future plans, the community, user adoption stories, and cross-project collaborations. Additionally, it provides an overview of Longhorn's architecture and design, along with a detailed look at the key maturity milestone for the V2 data engine in the recent Longhorn 1.12 release.

### 17:45–19:15 · Welcome Reception 🎉

- Room: 3F | 301-304 + Foyer
- Track: Experiences
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228420

Join us onsite for drinks, appetizers, and conversations with old and new friends in the Solutions Showcase. Explore the exhibit booths to learn more about the latest technologies, browse special offers and job posts, and much more.

In order to facilitate networking and business relationships at the event, you may choose to visit a third party’s booth or to access sponsored content. You are never required to visit third-party booths or to access sponsored content. When visiting a booth or participating in sponsored activities, the third party will receive some of your registration data. This data includes your first name, last name, title, company, address, email, standard demographics questions (i.e. job function, industry), and details about the sponsored content or resources you interacted with. If you choose to interact with a booth or access sponsored content, you are explicitly consenting to receipt and use of such data by the third-party recipients, which will be subject to their own privacy policies.

## Thursday, July 30, 2026

### 08:00–16:30 · Registration + Badge Pick-up

- Room: 2F | Foyer
- Track: Registration + Badge Pick-up
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1221412

### 09:30–09:35 · Where Will Cloud Native Take You?

- Room: 1F | Main Hall
- Speakers: Jeffrey Sica
- Track: Keynote Sessions
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1283179

The cloud native community is more than open source projects, it's a place for individuals to learn new skills, build a professional network, and accelerate a\ career. Whether your first step is earning a certification, joining a local community, fixing documentation, or contributing code, every new participant brings fresh ideas and energy that keep cloud native moving. In this keynote, Jeffrey Sica will share practical ways to get involved and show how building your cloud native journey can help shape both your career and the future of the global community.

### 09:44–09:47 · 1 Year, 15 Certs, a Raspberry Pi Home Lab: How I Became a Golden Kubestronaut

- Room: 1F | Main Hall
- Speakers: Yu Misaki
- Track: Keynote Sessions
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1283186

It started with watching a colleague deploy workloads and seeing nodes scale up automatically — all visible in real time through k9s. That curiosity led to CKA — which took two attempts. But passing revealed how much the next exams overlapped, so he kept going and earned Kubestronaut. Then a new question: "What about all the CNCF technologies I've never touched?" A Raspberry Pi home lab turned unfamiliar tools into genuine interests — and before he knew it, all 15 certifications were done in 14 months. This lightning talk traces that unplanned chain reaction. Attendees will learn: 1. All you need is curiosity — no experience required 2. One step leads to the next — each exam opens a door to the next; momentum builds naturally 3. The hardest part is the first step — don't aim for 15; just try the one that interests you

### 09:49–09:52 · Take the First Step, Grow with Cloud Native Community Japan

- Room: 1F | Main Hall
- Speakers: Ziyi Xie
- Track: Keynote Sessions
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1283252
- Slides: https://sessionize.com/download/iclajpef~fRJ2zmyV3tkstJ86WkYNJo.pptx~take-the-first-step-grow-with-cloud-native-community-japan.pptx

Cloud Native Community Japan (CNCJ) connects people across Japan through local meetups, topic-focused communities, collaboration with related organizations, and programs that help newcomers explore upstream contribution. This session introduces the many ways to get involved—from taking a first step into the cloud native community to sharing experiences and contributing to the wider CNCF ecosystem. It also highlights CNCJ’s latest activities and new opportunities to connect, collaborate, and make an impact both locally and globally.

### 09:54–09:57 · OpenTelemetry Celebrates Graduation and the Next Era of Agentic Observability

- Room: 1F | Main Hall
- Speakers: Alolita Sharma, Ted Young
- Track: Keynote Sessions
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1283189

Seven years after the unification of OpenTracing and OpenCensus, OpenTelemetry celebrates its CNCF graduation—having successfully conquered production security and scale, stabilized semantic conventions, and unified all four core data signals into a single interoperable fabric. As OpenTelemetry enters its next frontier, we are thrilled to unveil a new era of intelligent observability—propelling native support for Agentic AI, high-efficiency OTel-Arrow transport, continuous profiling, and smart, entity-driven sampling.

Come celebrate and join in to build the next generation of open-source observability.

### 09:59–10:02 · Large-Scale Edge Management with Kubernetes: The Tech Behind Stable Operation of 200 EV Chargers

- Room: 1F | Main Hall
- Speakers: Ryota Yonekura
- Track: Keynote Sessions
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1283245

PowerX operates more than 200 EV chargers around Japan, and keeping them running reliably is the single most critical challenge for our service. Managing software across a large number of edge devices while maintaining reliability has always been a major burden for our SRE team. In particular, achieving consistent operations in an environment where devices with limited resources are intermixed proved especially difficult.
In this keynote, we'll summarize the solution we put into practice to address these challenges: building a large-scale edge management system on top of Kubernetes.

Why did we choose Kubernetes from among the many available options, and why did we then adopt k0s specifically?

How did we design a hybrid cluster connecting the cloud (GKE) with the edge?

How do we efficiently collect metrics from resource-constrained devices, and how do we switch between OpenTelemetry's push-based and pull-based approaches to ensure observability?

### 10:04–10:14 · Navigating the Identity Abyss in the AI‑Native Era

- Room: 1F | Main Hall
- Speakers: Yuichi Nakamura
- Track: Keynote Sessions
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1283246

As AI-native systems become mainstream, a growing number of standards around identities are emerging to support governance of Agentic AI ecosystems like MCP - even small misusage of standards can lead to a major incident.

The keynote introduces two key CNCF initiatives with strong activities in Japan, that is helpful to navigate the complex landscape. First, IAM White Paper, which provides practical guidance for building secure identity foundations for cloud native systems including AI platforms. Second, Keycloak, a leading open-source IAM solution that is actively implementing the latest standards for Agentic AI.

Join us to explore how the cloud native community is building trust, security, and interoperability for the AI-native era.

### 10:16–10:19 · What is a Virtual Power Plant (VPP) ? : Green Tech and the Modernization of the Grid

- Room: 1F | Main Hall
- Speakers: LeRenzo Malcom
- Track: Keynote Sessions
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1283250
- Slides: https://sessionize.com/download/ipcabced~MrNidoG5iufwsVfCr9jnAP.pdf~20260724_japan-main-talk_v001.pdf

The Grid Is Becoming a Distributed System

Energy systems face pressure from geopolitical shocks, electrification, extreme weather, and digital infrastructure. The grid needs more than new generation; it needs flexibility.

Japan makes this challenge tangible. Its energy self-sufficiency rate is around 15%, while roughly 70% of electricity generation depends on fossil fuels. Yet Japan targets 40–50% renewable electricity by FY2040 as demand rises from data centers, semiconductor manufacturing, and electrification.

As solar, batteries, EVs, and heat pumps spread, valuable grid resources are moving into homes and cities. Virtual Power Plants coordinate these devices as one software-defined energy asset, shifting demand, storing renewable energy, and improving resilience.

This keynote explores why the grid behaves like a distributed system, and how cloud-native patterns can help operate it.
The next power plant may be one million homes, batteries, and EVs, coordinated by software.

### 10:21–10:24 · How CNCF Projects United Two Countries' Engineers to Solve AI's Power-and-Land Problem

- Room: 1F | Main Hall
- Speakers: Kazuki Sato
- Track: Keynote Sessions
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1289569

As AI's appetite for compute keeps growing, a single urban data center hits a hard physical wall — not racks, but power and land. No amount of expansion at one site solves it. It's a challenge the whole world shares, and one that hits especially hard in Japan, where land is scarce.

So instead of expanding one site, NTT DOCOMO BUSINESS distributed GPUs across Japan. Over a wide-area L2 network built on IOWN APN (All-Photonics Network) technology, we operate eight data centers — more than 2,000 km from Sapporo to Fukuoka — as a single Kubernetes cluster. But a fast network alone isn't enough. The real challenge is making that distributed capacity usable as one: multiple tenants in secure isolation, existing workloads running as-is, with the feel of a single site. We made that real with cloud native technologies — above all, KubeVirt.

What matters most is who built it: engineers from Japan and Korea, brought together by open source. Because Kubernetes and KubeVirt gave us a shared language, NTT DOCOMO BUSINESS and SK Telecom could design as equals across a national border. Our takeaway: a challenge the whole world shares can be addressed on the common ground of CNCF, where companies and countries co-create a solution together. This one was built by engineers in Japan and Korea — and from here in Japan, we want to take this distributed architecture to a world facing the same wall.

### 10:26–10:45 · Closing Remarks

- Room: 1F | Main Hall
- Track: Keynote Sessions
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1283336

### 10:45–11:30 · Coffee Break ☕

- Room: 3F | 301-304 + Foyer
- Track: Breaks
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1221380

### 10:45–15:50 · Solutions Showcase

- Room: 3F | 301-304 + Foyer
- Track: Solutions Showcase
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1221388

Visit our sponsors in the Solutions Showcase to try the latest demos, watch live presentations, talk to experts, check out job opportunities, and score some swag.

In order to facilitate networking and business relationships at the event, you may choose to visit a third party’s booth or to access sponsored content. You are never required to visit third-party booths or to access sponsored content. When visiting a booth or participating in sponsored activities, the third party will receive some of your registration data. This data includes your first name, last name, title, company, address, email, standard demographics questions (i.e. job function, industry), and details about the sponsored content or resources you interacted with. If you choose to interact with a booth or access sponsored content, you are explicitly consenting to receipt and use of such data by the third-party recipients, which will be subject to their own privacy policies.

### 10:45–13:00 · Project Pavilion | Thursday AM Project Tables

- Room: 3F | 301-304
- Track: Project Opportunities
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1276321

Thursday AM Project Tables | 10:45 - 13:00

T-1 CoHDI
T-2 Cilium
T-3 Lima
T-4 Community-Led Events + TCGs
T-5 Longhorn
T-6 OVN-Kubernetes
T-8 OpenEverest

### 10:50–11:20 · Gold Sponsor In-Booth Demos

- Room: 3F | 301-304 + Foyer
- Track: Sponsor Demos
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1291620

Sponsor: Red Hat
Demo: Demonstration of Dynamic Scoring in ACM
Booth Number: G4

In order to facilitate networking and business relationships at the event, you may choose to visit a third party’s booth or access sponsored content. You are never required to visit third party booths or to access sponsored content. When visiting a booth or participating in sponsored activities, the third party will receive some of your registration data. This data includes your first name, last name, title, company, address, email, standard demographics questions (i.e. job function, industry), and details about the sponsored content or resources you interacted with. If you choose to interact with a booth or access sponsored content, you are explicitly consenting to receipt and use of such data by the third-party recipients, which will be subject to their own privacy policies.

### 11:30–12:00 · SBOMit: Making SBOMs Accurate with Attestations

- Room: 3F | 313+314
- Speakers: Marco De Vincenzi, Justin Cappos
- Track: Security
- Labels: Beginner, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1193066

Software Bill of Materials (SBOM) adoption is accelerating, driven by regulatory mandates and high-profile supply chain incidents. However, a critical and underappreciated problem persists: SBOMs can be inaccurate. Traditional SBOM generation tools rely on static analysis or package manifests, approaches that routinely miss dynamically downloaded dependencies, build-time artifacts, and network-fetched components.
This talk introduces SBOMit, an OpenSSF project, a supply-chain security framework that solves the accuracy problem by generating SBOMs from in-toto attestations captured at build time. Rather than inferring what was used, SBOMit observes and records it, leveraging the witness tool to trace filesystem reads and writes, process execution, and outbound network connections during the actual build. Every dependency encountered during the build is captured and cryptographically authenticated. The resulting SBOM is not a best guess; it is a verified record of what was built.

### 11:30–12:00 · Standardizing Industrial IoT observability with OpenTelemetry

- Room: 3F | 315
- Speakers: Alolita Sharma
- Track: Observability
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1186424

What happens when “observability” meets industrial “IoT”?
In this session, we will dive into where OpenTelemetry can be used in IIoT environments. We will also cover how to use OTel’s flexible architecture to observe industrial equipment, inform preventative maintenance, and ensure quality control (QC).
Join in to learn about how to configure the OpenTelemetry Collector to handle industrial protocols (e.g., MQTT, OPC-UA) alongside standard OTLP (OpenTelemetry Protocol) to bridge “shop floor” data to cloud-native “top floor” pipelines. And learn to leverage OpenTelemetry metrics and traces for preventative maintenance and real-time QC alerting.

### 11:30–12:00 · Beyond Translation: The Journey of Building the Japanese Kubernetes SIG Docs Community

- Room: 4F | 414+415
- Speakers: Aoi Takahashi, Junya Okabe
- Track: Maintainer Track
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228189
- Slides: https://sessionize.com/download/qinoh~42agHtcP6ncLX7XyV7Mn5U.pdf~kubecon-cloudnativecon-japan-2026.pdf

While Kubernetes powers the world, its ""English-first"" nature can be a daunting barrier. SIG Docs bridges this gap through localization, but how do we keep these efforts sustainable? This session explores the Japanese team’s journey in cultivating one of the project's most active localization communities. Forget dry history lessons – we’re delivering a hands-on roadmap and examples for new contributors. You’ll walk away knowing exactly how to navigate the SIG Docs repository and land your first PR.

We’ll also ""pull back the curtain"" on our real-world struggles: managing relentless upstream velocity, ensuring technical accuracy at scale, and the honest debates shaping our future workflow. Whether you’re a documentation veteran or a first-time contributor, you’ll learn how we built a localized ecosystem in Japan that empowers users worldwide.

### 11:30–12:00 · Running OpenSearch at Scale in High-Traffic Gaming Systems

- Room: 5F | 501
- Speakers: Siddharth Vijay
- Track: Operations + Performance
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194751

Running OpenSearch in a poker platform means no margin for error. Fraud detection can't wait. Player stats APIs can't lag. And the cluster doesn't care about your traffic spikes.
We operate OpenSearch under mixed workloads: high-volume writes from hand histories and gameplay events, aggregation-heavy fraud queries, and latency-sensitive reads serving live player statistics. Standard deployment advice doesn't survive this combination.
This talk is purely operational. We cover JVM heap sizing under write pressure, threadpool tuning for bulk ingestion and search isolation, shard sizing, rollover strategies, and capacity planning for uneven traffic — with the specific mitigations we applied after hitting queue saturation, GC pauses, and hot shards in production.
We also cover index lifecycle management, retention tradeoffs, and monitoring signals that matter when OpenSearch sits in your request path.
You'll leave with concrete operational guidance well beyond basic deployment patterns.

### 11:30–12:00 · Pluggable Interception: Using ExtAuthz and ExtProc in gRPC using xDS

- Room: 5F | 502
- Speakers: Pawan Bhardwaj
- Track: Connectivity
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1185705
- Slides: https://sessionize.com/download/iwzakpev~WntFCEYB3jGaSnur6gVya1.pdf~pluggableinterceptionkubeconjapanfinal.pptx.pdf

This talk introduces service extentions added in gRPC: ExtAuthz and ExtProc. Instead of relying on external proxies for interception, gRPC has added support for side channel callout to external services via xDS.

ExtAuthz: Perform real-time authorization by shipping peer identity and metadata to external services. It enables dynamic "allow/deny" decisions before an RPC is processed.

ExtProc: Provide deep packet interception for headers and gRPC message bodies using a specialized "GRPC" processing mode. It allows for sophisticated payload transformation, PII masking and message level filtering.

This enables "Security as a Service" model by decoupling complex logic from application and centralising it into pluggable , xDS managed services.

This session is a technical roadmap for developers looking to inject custom security , logging and business logic directly into gRPC data plane.

### 11:30–12:15 · The Ultimate Kubestronaut Trivia Challenge !

- Room: 4F | 413
- Speakers: Christophe Sauthier
- Track: Experiences
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1282807

Are you ready to put your stellar Kubernetes expertise to the test? Welcome to the exclusive Kubestronaut Trivia Challenge at KubeCon Japan! This isn't just any quiz; it’s a high-energy, fast-paced technical showdown designed exclusively for Kubestronauts.

Expect questions that will challenge your deep understanding of the CNCF ecosystem, community lore, and everything it takes to achieve the 5-certification status.

IMPORTANT ACCESS REQUIREMENTS:
This session is strictly reserved for the Kubestronauts. To gain entry and participate, you must be wearing your official Kubestronaut Jacket or your Golden Kubestronaut Beanie.

Come show off your knowledge, connect with your peers, and above all, have an amazing time together. Let’s celebrate the community, share some laughs, and see who takes home the ultimate bragging rights.

### 12:10–12:40 · Scalable Security and Compliance in the Age of AI

- Room: 3F | 313+314
- Speakers: Eddie Knight
- Track: Security
- Labels: Any, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1171622
- Slides: https://sessionize.com/download/ikxaxned~YQcyAwNnQ1ZQpUiSgduk2D.pdf~scalable-security-and-compliance-in-the-age-of-ai-eddie-knight.pdf

After studying a data set of 37,000 dependency upgrade recommendations made by AI coding assistants, and following the review of 200,000 active and downloadable malicious OSS packages, clear gaps and opportunities have been identified: Old defense strategies are working less, and new attack patterns are working more. This talk explores those findings, then provides listeners with a clear path to success through several emergent tools and guidance from the Linux Foundation ecosystem.

### 12:10–12:40 · From Statsd to OpenTelemetry: Atlassian's Metrics Platform Migration at Scale

- Room: 3F | 315
- Speakers: Iris Grace Endozo, Farzad Vazirnia
- Track: Observability
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1191835
- Slides: https://sessionize.com/download/fuxla~RbEMSZTsipM5QyygCebkNp.pdf~from-statsd-to-opentelemetry-real.pdf

OpenTelemetry has become the industry standard for Observability: a single, vendor-neutral framework for metrics, traces and logs backed by CNCF. But adopting it is a different story when you already have a legacy but stable
observability platform that "works" from collection to pipeline processing to storage.

At Atlassian, the Observability team ran statsd as a bespoke metrics pipeline for years: high-performance statsd servers collecting and aggregating metrics from around 100k hosts across 14 regions. It served the team well but the cracks were showing: UDP-only ingestion, no support for traces or logs and standards increasingly out of step with where the ecosystem was heading.

This talk walks through why the team migrated to an OpenTelemetry Collector-based pipeline and landed everything in their metrics backend without downtime or data loss. It covers how they executed at scale and the strategy for full OTLP-native adoption and what it unlocks for unified Observability.

### 12:10–12:40 · From User to Contributor: A Quick Guide to kubectl & kustomize

- Room: 4F | 414+415
- Speakers: Yugo Kobayashi, Maciej Szulik
- Track: Maintainer Track
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228191
- Slides: https://sessionize.com/download/gkabkeu~7DSsDfsXvJnS8vbDvBvau9.pdf~kubecon-japan-2026-sig-cli.pptx.pdf

Have you ever wondered how kubectl and kustomize enhancements are designed and built? Curious why your favorite feature request wasn't accepted?

In this session, the SIG CLI maintainers will first provide an introduction to developing kubectl and kustomize commands. We will discuss conventions and patterns focused on usability, consistency, and testability. We will then dive into kubectl and kustomize command internals by walking through existing command structure. We will cover effective use of client-go (the library that powers communication with the Kubernetes API server) and other essential libraries for building versatile commands. We'll also share tips on how to best engage with the SIG CLI community, where to ask questions, and how to turn a one-time contribution into an ongoing role in the project.
Leave this session ready to open your first pull request and become an active part of the Kubernetes community.

### 12:10–12:40 · Score-Driven Multi-Cluster Management: An Evaluation Framework for Decision-Making

- Room: 5F | 501
- Speakers: Kazuma Takeuchi, Joydeep Banerjee
- Track: Operations + Performance
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1192623
- Slides: https://sessionize.com/download/rcahxer~s1U4HgPPWZuxje7dkz887N.pdf~kubecon_yokohama_dsf.pdf

As large AI platforms scale across multiple clusters, static placement policies are reaching their limits. Decisions must reflect live conditions such as GPU utilization, power efficiency, and other operational metrics rather than fixed rules alone.

In this talk, we introduce the Dynamic Scoring Framework, a new Add-on for Open Cluster Management that brings real-time telemetry into multi-cluster placement and policy decisions. Lightweight agents collect metrics from sources such as Prometheus, evaluate them through modular scoring APIs, and feed results into the central hub. This hybrid design balances distributed scoring and centralized control for scalable, flexible decision-making.

Through an architecture deep dive and a demo of resource optimization with the framework, we show how score-based decisions improve resource efficiency in AI infrastructure. Attendees will learn score-based management patterns and how to apply them beyond AI workloads.

### 12:10–12:40 · Breaking the Single-Network Barrier: A Cross-Domain Look at Kubernetes Multi-Networking

- Room: 5F | 502
- Speakers: Lionel Jouin, Sunyanan Choochotkaew, Masaharu Kanda, Surya Seetharaman, Sara Qasmi
- Track: Connectivity
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194563

Kubernetes multi-network support has been a long-standing challenge, the journey toward native multi-network capabilities has been complex and slow. But why? This panel brings together experts from diverse domains to discuss scenarios such as high-performance networking with advanced capabilities like RDMA for AI/ML, telco, and cloud gaming, network isolation for security, compliance, and multi-tenancy, VM connectivity and connectivity to on-premises infrastructure such as datacenter VLANs or EVPN fabrics. Together, they will examine the architectural challenges of integrating multiple networks into Kubernetes, recent upstream developments such as the DRA feature, and how communities such as SIG Network and WG Device Management are driving progress across the ecosystem. Join this interactive session to learn where multi-network support stands today, where it's heading, and to engage directly with upstream contributors and maintainers to share questions and real-world use cases.

### 12:10–12:40 · Designing a Hybrid AI Platform on Kubernetes

- Room: 5F | 503
- Speakers: Aoi Kamide
- Track: AI + ML
- Labels: Beginner, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194148
- Slides: https://sessionize.com/download/gbatjek~BnaStQK66LuxSiDj6uMhQJ.pdf~designing-a-hybrid-ai-platform-on-kubernetes.pdf

As generative AI and LLM adoption accelerates, cloud-based platforms face challenges including ongoing RAG costs, increased data transfer overhead, and security concerns around sensitive data. While shifting workloads on-premises is considered, this introduces new complexities such as GPU selection, OSS integration, and application and model lifecycle management.
To address these challenges, we designed a hybrid AI platform leveraging edge GPUs.
In this session, we present an implementation built on edge GPU servers running k3s, with Rancher for cluster and GPU workload management. We deployed dify on-premises as the AI development platform and built a hybrid AI Agent architecture combining local RAG with on-premises and cloud LLMs. Starting from natural language queries, the Agent interprets intent and interacts with business APIs when needed to generate responses. We share the overall architecture and key insights from development.

### 12:40–14:10 · Lunch 🍲

- Room: 3F | 301-304 + Foyer
- Track: Breaks
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1221375

### 13:30–15:50 · Project Pavilion | Thursday PM Project Tables

- Room: 3F | 301-304
- Track: Project Opportunities
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1276322

Thursday PM Project Tables | 13:30 - 15:50

T-1 Kairos
T-2 Headlamp
T-3 Keycloak
T-4 Community-Led Events + TCGs
T-5 kubeflow
T-8 OpenEverest
T-7 youki

### 14:10–14:40 · Shared GPU Scheduling & Proactive Autoscaling: A Production Blueprint for 1000+ GPUs

- Room: 1F | Main Hall
- Speakers: Jeonghyun Kim, Reza Jelveh
- Track: AI + ML
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1182713

SNOW Corp. operates 1,000+ A100 GPUs serving 200 million users across three top-ranked GenAI applications (Snow, Epik, B612), handling 1,200+ AI workflows subject to extreme traffic volatility from viral AI trends.

The core bottleneck was Kubernetes' native GPU scheduling, which treats GPUs as atomic resources — forcing a 2x over-provisioning penalty on Train-to-Inference pipelines with no reliable visibility into actual GPU saturation.

This talk covers integrating HAMi for vGPU virtualization and extending KEDA with a custom Consumer Saturation metric for proactive autoscaling, hiding warm-up latency by scaling before traffic arrives.

We’ll detail the implementation: scheduler config, Prometheus metrics, and multi-region scaling via Helm GitOps. Results: >50% GPU waste cut and 91% faster recovery during surges. You’ll get a production blueprint for efficient, shared GPU platforms.

### 14:10–14:40 · Runtime Security at Scale with eBPF: Hybrid Detection and Root Cause Analysis in CloudNative Systems

- Room: 3F | 313+314
- Speakers: Yogeshwara Krishna Kota, Rutuj Waghare
- Track: Security
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1193404

Modern Kubernetes workloads make it increasingly difficult to understand what is really happening at runtime. Traditional observability tools often miss critical low-level behaviours, especially across process execution.
In this talk, we present a kernel-level observability approach powered by Sauron eBPF that captures high-fidelity runtime signals directly from the Linux kernel. By tracking process lifecycle events, the system builds a unified, real-time view of workload behaviour.
On top of this telemetry, we introduce a Graph-AI analytics layer: data feed an AI engine that learns semantically meaningful node embeddings and models the process tree as a temporal graph. This allows the system to capture both node-level behaviour and inter-node temporal relationships, enabling the detection of anomalies that traditional approaches typically miss.

### 14:10–14:40 · Designing for High-cardinality Metrics

- Room: 3F | 315
- Speakers: Walther Lee, Aleksandr Krivoshchekov
- Track: Observability
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194062

Large applications will overload your monitoring system. In Kubernetes, every pod created has the side effect of adding new series to your metrics. Even a simple rollout and rollback triples your cardinality!

While Prometheus and OTel have solutions like recording rules, stream aggregation, and sharding, all of them come with tradeoffs.

At Reddit, we found these options insufficient until we decided to look at the problem from a different angle. We designed a stateless algorithm for collecting metrics, that doesn’t sacrifice accuracy or performance, and doesn’t spike cardinality as pods come and go. In production, it cut compute costs by 90%.

This talk is an intuitive and visual look at the algorithm, the challenges and experiments. You’ll learn about why it works where current options don’t, and will leave with a solid grasp of how to implement it in any time-series database.

### 14:10–14:40 · Behind the CNCF IAM Whitepaper: AuthN & AuthZ in Cloud Native Systems

- Room: 4F | 414+415
- Speakers: Yoshiyuki Tabata, Hiroyuki Wada
- Track: Maintainer Track
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228193
- Slides: https://sessionize.com/download/hnabced~fprUKajGCStLzGQ74fFtPt.pdf~behind-the-cncf-iam-whitepaper_-authn-authz-in-cloud-native-systems-8.pdf

In March 2026, CNCF TAG Security and Compliance published the CNCF Identity and Access Management (IAM) Whitepaper, providing practical guidance on how authentication and authorization should be designed and implemented in cloud native systems.

Presented by the authors of the whitepaper, this session explains the intent, scope, and architectural decisions behind the document. Rather than introducing IAM products or implementation details, the talk focuses on how the TAG structured authentication and authorization requirements into two reusable reference patterns, Basic and Advanced, and how each pattern defines its trust boundaries and enforcement responsibilities.

By sharing the reasoning behind these design choices, this session aims to help architects and developers apply the IAM Whitepaper as a shared architectural baseline when designing, reviewing, and evolving authentication and authorization mechanisms in cloud native systems.

### 14:10–14:40 · The Evolution of GitOps in Platform Engineering

- Room: 5F | 501
- Speakers: Artem Lajko
- Track: Platform Engineering
- Labels: Beginner, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1156110
- Slides: https://sessionize.com/download/ipsajor~NF9K1CSu1bUX2WVR3rbLoT.pdf~the-evolution-of-gitops-in-platform-engineering-artem-lajko.pdf

GitOps in 2017 as a simple model for application delivery, built around four core principles. Today, it has evolved into a central part of platform engineering, where teams operate large numbers of clusters and shared platform services.

This talk shows how GitOps has evolved over time, why early approaches break at scale, and how everything-as-code enabled automation while also creating configuration sprawl. Tools like Argo CD, Helm, and Kustomize made scaling possible, but often hide the real state of a system.

We will look at the limits of Git as a state store and why file-based, pull-driven reconciliation does not scale well. This led to OCI-based delivery, Gitless GitOps, and new approaches that aim to provide a real, operable state store.

Platform teams need visibility, regulation like the Cyber Resilience Act requires a clear infrastructure supply chain, and AI-driven operations depend on access to the final, real manifests.

### 14:10–14:40 · Beyond Wasm: How Dynamic Modules Let You Extend Envoy Proxy in Go, Rust, or Any Language

- Room: 5F | 502
- Speakers: Rohit Agrawal, Takeshi Yoneda
- Track: Connectivity
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1192943
- Slides: https://sessionize.com/download/itcahteb~WNbhKPtYVxou3zesqZE2qP.pptx~beyond-wasm_-extend-envoy-proxy-in-go-rust-or-any-language.pptx

Envoy powers Istio, Cilium Proxy, Envoy Gateway, and thousands of production deployments. But extending it is hard today. C++ filters mean maintaining a fork. WASM delivered sandbox overhead, limited extension points, and a stalling ecosystem.

We built Dynamic Modules to fix this and are now using it at Databricks and Netflix. They let you write Envoy extensions as shared libraries in Go, Rust, or any language with a C ABI. Near-native performance, no sandbox, no rebuild. Both companies are replacing C++ forks and Wasm with native Rust, cutting tail latency and memory use while shipping features faster.

As Envoy maintainers and co-authors, we cover how Go/Rust SDKs work across 12+ extension points including network filters, LB policies, and custom clusters. We'll have a live demo of a Rust TLS Transport Socket enabling kernel TLS (kTLS) which is impossible today with BoringSSL and what this means for Istio, Cilium, and Envoy Gateway users who need extensibility without C++ or WASM.

### 14:10–14:40 · Conformance for Inference: How We Reduced Bad Deploys on a GPU Platform

- Room: 5F | 503
- Speakers: Aditya Soni, Hrittik Roy
- Track: AI + ML
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194934

Inference on GPUs fails in repetitive ways: wrong image or artifact, mismatched CUDA or runtime, undersized GPU memory, bad resource requests, or a model that passes offline checks but regresses under real traffic. On a shared k8s GPU platform, those mistakes become multi-tenant incidents - noisy neighbors, OOMKills, SLO breaches, and rollbacks that waste accelerator time.

This talk describes how one team built conformance for inference workloads, checks applied before production traffic, covering container and model artifacts, GPU capacity and visibility contracts, health and readiness semantics, and minimum observability (metrics/traces where used).

Attendees leave with a practical checklist they can reuse:
- How to separate “builds” from “serving” conformance,
- How to catch regressions early, and
- How to align GPU scheduling and quotas with inference SLOs.

We will share what worked, what did not, what teams pushed back on, and a short checklist for platform and app owners.

### 14:10–15:20 · Peer Group Mentoring

- Room: 4F | 413
- Track: Experiences
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1273972

Peer Group Mentoring allows participants to meet with experienced open source veterans across many CNCF projects. Mentees are paired with 2 – 8 other people in a pod-like setting to explore technical, community, career, and certification questions together.

If you're interested in attending as a Mentee, seats are first come first served.
If you're interested in being a Mentor, please sign up by July 10.

https://www.surveymonkey.com/r/Japan26Mentor

### 14:50–15:20 · Shared Yet Isolated at Scale: Building Multi-Tenant Inference Platform on Kubernetes

- Room: 1F | Main Hall
- Speakers: Yuto Hiraki, Yusuke Tanaka
- Track: AI + ML
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1193361
- Slides: https://sessionize.com/download/iqyabcew~9jMfdtEo9q6dvVzTEtsu7L.pdf~kubeconyokohama2026_sharedyetisolatedatscale.pdf

As AI Agent adoption grows, so does LLM usage and the cost of running it. A self-hosted LLM inference platform is one approach enterprises are exploring to regain control over costs, security, and governance. But it comes with a real challenge: teams have different use cases, access patterns, and security requirements. Some only need an API endpoint, while others need full administrative control. Traditional namespace isolation falls short of meeting both. At the same time, high GPU utilization is critical to keeping cost per token low. Shared yet isolated, at scale - how do you resolve that contradiction?
In this talk, we share practical insights from building an LLM inference platform on Kubernetes - covering tenant isolation, dynamic and granular GPU allocation, and the trade-offs in between. We'll show how we resolved that contradiction, with practical patterns.

### 14:50–15:20 · Sealed for All: Multi-Party Confidential Computing, No Trust

- Room: 3F | 313+314
- Speakers: Ryota Hashimoto, Takahiro Kambara
- Track: Security
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194977
- Slides: https://sessionize.com/download/ibxatio~RvKhfNAzndLVMUPARjWvM5.pdf~sealed_for_all-multi-party_confidential_computing-no_trust_v18_distrib.pdf

As cross-organizational data collaboration becomes central to modern computing, protecting sensitive data and proprietary code during joint processing is a growing challenge. Confidential Computing (CC), based on hardware-enforced Trusted Execution Environments (TEEs), enables data to be processed securely without being exposed. This session introduces "Multi-Party Confidential Computing (MPCC)," a concept where multiple data providers and application owners contribute their assets to a shared computation while keeping both data and applications confidential from one another. Rather than relying on access control or mutual trust, this model uses TEEs and file encryption to enforce runtime isolation between parties. The speakers will show how key mechanisms — attestation coordination across multiple TEEs, auditability after execution, and isolation from the underlying cloud — can be realized with open source technologies including Kata Containers and Confidential Containers.

### 14:50–15:20 · Repurposing OpenTelemetry Traces as Test Data: Breaking the Cost Barrier in System Migration

- Room: 3F | 315
- Speakers: Yoshiki Fujikane
- Track: Observability
- Labels: Any, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194861
- Slides: https://sessionize.com/download/nlatrec~KMxurHkf8vMu5GQYSVpF48.pdf~repurposing-opentelemetry-traces-as-test-data_-breaking-the-cost-barrier-in-system-migration.pdf

Proving a new system matches the old one is the hardest part of legacy migration. Writing equivalence tests from scratch is slow and expensive.

The fix is to repurpose what the live system already emits: capture request/response pairs as OTel trace spans and treat them as ground truth for testing the replacement.

A PoC on a Java-to-Go migration confirmed this works. Four CRUD endpoints were instrumented; the spans drove E2E tests covering all four.

OTel's standard conventions don't capture HTTP response bodies, so observability traces aren't automatically useful for testing. Custom attributes are required.

The PoC also tested OBI (opentelemetry-ebpf-instrumentation), which traces without code changes. Basic coverage works. But adding custom attributes via eBPF is impractical, so OBI alone isn't enough for test-quality traces.

You'll leave knowing when OTel traces are sufficient for migration testing, when they're not, and whether OBI closes the gap.

### 14:50–15:20 · WG-Batch Updates: What’s New and What Is Next?

- Room: 4F | 414+415
- Speakers: Michał Woźniak, Yuki Iwai
- Track: Maintainer Track
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228186
- Slides: https://sessionize.com/download/iffadked~HSxouJDyzB1JzV1QqfTD3e.pdf~kubecon-japan-2026-wg-batch.pptx.pdf

This session explores recent developments in the Kubernetes ecosystem designed to meet the growing demand for AI training and inference workloads.

First, we survey the landscape of ecosystem projects, highlighting recent enhancements to the core Kubernetes Job API - the foundational building block for these initiatives - alongside the latest updates to JobSet.

Second, we demonstrate Kueue’s capabilities as a robust AI/ML platform, showcasing how features like Multi-Cluster dispatching, Fair Sharing, and Topology-Aware Scheduling maximize hardware utilization across tenants.

Finally, we detail our collaboration with SIG Scheduling on "Workload-Aware Scheduling," which aims to deeply integrate batch semantics into the core scheduler.

### 14:50–15:20 · Maximizing Launch Reliability: Controlled Lift-off for Reliable Application Startup on Kubernetes

- Room: 5F | 501
- Speakers: Hiroshi Hayakawa
- Track: Operations + Performance
- Labels: Advanced, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194625
- Slides: https://sessionize.com/download/iqjagnen~MjtBLVhfuaQD27j5vgRANZ.pdf~maximizing-launch-reliability-controlled-lift-off-for-reliable-application-startup-on-kubernetes.pdf

Launch reliability is critical for applications on Kubernetes that restart frequently. Cold starts from cache initialization and JIT compilation can degrade performance and trigger startup failures, causing serious downtime during rollouts and reducing the effectiveness of horizontal pod autoscaling.

The recent Kubernetes feature In-place Pod Resize enables CPU bursting to improve launch reliability through infrastructure-level scaling. However, it does not address application-layer unreadiness and may introduce risks such as noisy neighbor issues or unexpected runtime behavior.

In this session, he will explore recent trends and practices for improving launch reliability and examine real-world In-place Pod Resize. Furthermore, he will propose a strategy using a purpose-built open source controller designed to mitigate these risks and ensure comprehensive readiness. You will leave this session with actionable insights to achieve reliable, production-grade launches on Kubernetes.

### 14:50–15:20 · What is a Virtual Power Plant (VPP) ? : Green Tech and the Modernization of the Grid

- Room: 5F | 502
- Speakers: LeRenzo Malcom
- Track: Application Development
- Labels: Any, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1193722
- Slides: https://sessionize.com/download/xxagver~EB5zPDr7bYMf27TvfjL8u9.pdf~20260724_japan-keynote_v001.pdf

Virtual Power Plants (VPPs) are reshaping the energy grid by turning thousands of distributed IoT devices—solar systems, batteries, EV chargers—into one coordinated, cloud-native asset. At Enpal, we operate one of Europe’s largest residential solar fleets and are building a next-generation VPP platform to orchestrate it.

This talk explores what it really means to build a power plant in software—and why developing for IoT looks nothing like typical cloud app development.

You’ll learn:

- How the electrical grid works (with examples!)
- How a Virtual Power Plant works—from household solar to market bidding
- How Enpal’s IoT and cloud systems coordinate to optimize energy use and revenue in real time
- What design patterns (Kubernetes, KubeEdge, Dapr, event streaming) make it possible to treat 100,000+ homes like a distributed cluster
- How VPPs make money—through flexibility markets, load shifting, and price arbitrage

### 14:50–15:20 · Who's Using That GPU? Identity-Aware Access Control for Kubernetes GPU Workloads

- Room: 5F | 503
- Speakers: Peter ONeill, Kunal Kushwaha
- Track: AI + ML
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194784

Who requested that GPU, why do they have it, and when will they give it back? In most clusters running DRA, nobody knows. Any user with basic RBAC can claim a GPU with no identity verification, no justification, and no expiry.
This talk fixes that. The speaker demos an open-source validating admission webhook that intercepts DRA ResourceClaim creation and enforces identity-aware policy: human authentication via Dex, group-based device class authorization, mandatory justification, team budget enforcement, and time-based constraints. SPIRE issues workload SVIDs to create a cryptographic identity chain from human to GPU device. A TTL controller automatically reclaims GPUs when sessions expire.
The live demo walks through five denial scenarios and a full approval-to-cleanup lifecycle using only CNCF-aligned tooling. Attendees leave with a deployable architecture and open-source repo.

### 15:20–15:50 · Coffee Break ☕

- Room: 3F | 301-304 + Foyer
- Track: Breaks
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1221377

### 15:50–16:20 · The Great Doubt: What Building an AI Agent Taught Us About Trust

- Room: 1F | Main Hall
- Speakers: Nicole van der Hoeven
- Track: AI + ML
- Labels: Any, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1192171
- Slides: https://sessionize.com/download/yzacse~p6oXTjxTGjWZ3Y56zQkLrp.pdf~the-great-doubt-what-building-an-ai-agent-taught-us-about-trust_2026-07-28_22-44.pdf

When we started building an AI assistant for observability, we thought the hard part would be making it smart. We were wrong. The hard part was knowing when to trust it.

AI agents hallucinate, forget context, and confidently give wrong answers. Traditional testing doesn't catch these failures. What's needed is evaluation grounded in systematic doubt.

This talk shares lessons from shipping an AI agent to production: how to build a golden dataset of use cases you must get right, how to use LLM-as-judge when there's no ground truth, and how to use OpenTelemetry traces to debug eval failures. You'll also hear what's still unsolved: evaluating multi-agent handoffs and closing the feedback loop between what users ask and what your evals cover.

Kyoto School philosopher Nishitani Keiji called this "The Great Doubt" (大疑): questioning every assumption until only what survives is real. For AI agents, that's not philosophy. It's the job.

### 15:50–16:20 · Container Forensics for Kubernetes: Building an Evidence Pipeline with Open Source Tools

- Room: 3F | 313+314
- Speakers: Jie Wu, Pulkit Garg
- Track: Security
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194921
- Slides: https://sessionize.com/download/gqardef~Tb1BXveAgfz8H5RcJ46sUf.pdf~kubecon-japan-2026.pdf

Your container just got compromised. But Kubernetes is ephemeral by design: the pod restarts in 30 seconds, and when it does, the memory, processes, and ephemeral filesystem are gone. How do you investigate something that no longer exists?

The cloud native ecosystem has gotten good at prevention and detection, but once an alert fires, actually figuring out what happened is still a gap.

This session walks through a forensics pipeline we built from open source tools, with a live demo of a simulated attack. Falco detects suspicious activity, Falco Talon automatically captures syscalls and network traffic, and we analyze the evidence in StratoShark, a Wireshark-style tool for system calls. We'll also show how the Kubernetes Checkpoint API can freeze container runtime state for offline inspection.

Attendees will walk away knowing how to set up automated evidence capture with Falco Talon, analyze captures in StratoShark, and trigger forensic checkpoints in their clusters.

### 15:50–16:20 · OTel meets Wasm: Rethinking OpenTelemetry Collector Extensibility

- Room: 3F | 315
- Speakers: Kotaro Inoue, Tsuzuki Tsuchiya
- Track: Observability
- Labels: Advanced, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194684
- Slides: https://sessionize.com/download/ccabgepu~GUgJkyvfVxn31PsaHGcJyd.pdf~otel-meets-wasm-rethinking-opentelemetry-collector-extensibility.pdf

OpenTelemetry Collector is a flexible, vendor-neutral telemetry pipeline, but extensibility is still more operationally expensive than it should be. The contrib distribution offers many community components, yet some teams cannot adopt the full binary as-is because they require tighter control over included functionality and security posture. Building a smaller collector with only the necessary components is possible, but in practice, it often means maintaining a custom build pipeline just to support relatively small extensions. This talk explores an alternative model for dynamically customizing the OpenTelemetry Collector with WebAssembly. Instead of rebuilding and redistributing the entire collector binary for each change, custom receiver, processor, and exporter logic can be introduced in a more decoupled way. The session examines what this model enables, where it fits, where it falls short, and what trade-offs emerge around safety, portability, performance, and operations.

### 15:50–16:20 · SIG API Machinery in the era of AI: updates

- Room: 4F | 414+415
- Speakers: Federico Bongiovanni
- Track: Maintainer Track
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228184
- Slides: https://sessionize.com/download/jjaudse~UTLuaYKBRus2xYDz4eMEEW.pdf~sig-api-machinery-in-the-era-of-ai-kubecon-japan-2026.pdf

Will speak about SIG API Machinery advancements in 1.36 and 1.37, and how AI / ML is influencing the future and the roadmap of our SIG and the Kubernetes Control Plane.

### 15:50–16:20 · Is Your Kubernetes Disaster Recovery Actually Ready?

- Room: 5F | 501
- Speakers: Saiyam Pathak, Saloni Narang
- Track: Operations + Performance
- Labels: Advanced, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194745

68% of organizations experienced data loss from disasters last year, costing an average of $4.5 million per incident. Yet a 2026 DR survey found that questions about Kubernetes DR received almost no responses, suggesting most teams do not know how container workloads are covered in recovery planning. In this session, the speaker takes an honest look at where Kubernetes DR stands today.
The talk walks through tools like Velero, Longhorn, and storage-level replication options, then covers architecture patterns from active-passive to GitOps-based recovery. But the core of this session is what remains broken: no atomic multi-PV snapshot for databases, no native cross-cluster failover, no standard for application-unit DR, and almost nobody tests DR end to end.
The session ends with open questions: Are we treating backup as DR? Who actually owns Kubernetes DR? Should there be a CNCF working group for DR standards? Attendees leave with a clearer picture of their own gaps.

### 15:50–16:20 · CoHDI: A CNCF Sandbox Project for Dynamic Hardware Composability in Kubernetes

- Room: 5F | 502
- Speakers: Naoki Oguchi, Hidetsugu Sugiyama, Michele Gazzetti, Jyothsna Deshpande, Kensuke Koda
- Track: Emerging + Advanced
- Labels: Advanced, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1190934
- Slides: https://sessionize.com/download/iioblau~EAtcDiqwZn8ydySC1SprPt.pdf~kubecon2026cohdi.pdf

The CoHDI (Composable Hardware in Disaggregated Infrastructure) project enables the dynamic attachment and detachment of hardware resources, such as GPUs, in Kubernetes-based cloud native environments. Recently accepted as a CNCF Sandbox project, CoHDI marks an important step toward flexible and efficient infrastructure orchestration. This session introduces the paradigm established by CoHDI and its core value, including improved resource utilization and cross-vendor interoperability. It outlines CoHDI's internal architecture, focusing on three components: the Composable DRA Driver, Dynamic Device Scaler, and Composable Resource Operator. The talk explains Kubernetes integration and how CoHDI connects multi-vendor composable infrastructure into containerized platforms. Through real-world use cases such as on-demand GPU scaling, dynamic device reuse, and resource sharing in multi-tenant environments, it shows how CoHDI improves operational efficiency and concludes with future direction.

### 15:50–16:20 · Architecting Secure Agentic Workflows on Kubernetes: A Financial Sector Case Study

- Room: 5F | 503
- Speakers: Vincent Caldeira, Morgan Foster
- Track: AI + ML
- Labels: Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1177775

As organizations move beyond basic LLM integrations toward autonomous agentic workflows, the infrastructure required to support these systems grows increasingly complex. Running multi-agent architectures in production introduces unique challenges around tool discovery, secure access, and traffic routing.

This session explores how to leverage Kubernetes and cloud-native abstractions to develop, test, and deploy AI agents at scale. Using a reference architecture leveraging the Kagenti project, we will demonstrate how to construct a secure, scalable agentic environment. The talk covers unifying tool access via an MCP Gateway, enforcing zero-trust workload identity with SPIFFE/SPIRE, and standardizing inter-agent communication.

To illustrate these concepts, we will walk through a real-world financial use case: an autonomous agent that securely accesses market data and executes simulated transactions using financial tools over MCP, demonstrating end-to-end cloud-native deployment.

### 16:30–17:00 · Topology-Aware Scheduling for AI Training & Inference with Kueue

- Room: 1F | Main Hall
- Speakers: Michał Woźniak, Wei Huang
- Track: AI + ML
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194393
- Slides: https://sessionize.com/download/ccacpetga~3kdpYuNWjFoLTykJKnFqMv.pdf~kubecon-japan-2026-tas-in-kueue.pdf

Kueue, the Kubernetes-native workload orchestrator, helps run AI workloads at scale with multi-tenant quota management and advanced scheduling.

In this session, we show through a case study at the Meta Superintelligence Lab how Kueue provided the right quota and scheduling layer for large-scale AI training and inference across complex, heterogeneous GPU topologies, enabling a shift from an in-house platform to an open-source stack on Kubernetes.

We then dive into Kueue’s multi-layer Topology-Aware Scheduling (TAS) for modern clusters with hierarchical network fabrics. We cover the main concepts and algorithms behind Hierarchical TAS, and show why multi-layer TAS was critical for this transition.

We close with other cutting-edge Kueue capabilities, including Workload-Aware Scheduler integration, elastic workloads, and multi-cluster job scheduling with MultiKueue.

### 16:30–17:00 · AuthZEN in Practice: Standardizing Authorization for Cloud Native Platforms and Agents

- Room: 3F | 313+314
- Speakers: Yoshiyuki Tabata
- Track: Security
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194198
- Slides: https://sessionize.com/download/xjappek~Gz4w41Fj4MoVcSAx9Zk2FT.pdf~authzen-in-practice-standardizing-authorization-for-cloud-native-platforms-and-agents.pdf

As AI agents gain broader access to APIs and infrastructure, "authorization" is becoming central to both security and governance. Agentic AI systems highlight fine grained, real time authorization challenges that are shared more broadly by cloud native platforms.
Authorization has long been fragmented by vendor specific designs and implementation dependent interfaces. In January 2026, the OpenID Foundation finalized the AuthZEN Authorization API 1.0, defining a standard interface for authorization interactions. This specification has attracted strong interest, and multiple projects are now working toward supporting AuthZEN, including Keycloak, an open source IAM project.
In this session, Yoshiyuki Tabata introduces the core concepts of AuthZEN and presents an end to end demo using Keycloak. The demo walks through token issuance, authorization evaluation, and policy decision enforcement, using a simple agent driven scenario to show how AuthZEN can be applied in cloud native ecosystems.

### 16:30–17:00 · One Binary, Two Ecosystems: Embedding Prometheus Exporters with OCB

- Room: 3F | 315
- Speakers: Kyle Eckhart, Arthur Sens
- Track: Observability
- Labels: Beginner, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1189149
- Slides: https://sessionize.com/download/idraqte~hNmp4FzLxWub9cLrteN6vV.pdf~one-binary-two-ecosystems.pdf

Prometheus exporters are typically consumed as scrape targets. But what changes when they can be embedded directly into custom OpenTelemetry Collector distributions built with the OpenTelemetry Collector Builder (OCB)?

This session explores how that shift creates a new operational model for observability teams, platform engineers, and users who rely on Prometheus exporters today. Instead of treating exporters only as external endpoints, teams can run them as Collector components and integrate them more directly into telemetry pipelines.

The talk also examines an important ecosystem question this model brings into focus: how to expose semantic convention-compatible telemetry from Prometheus exporters.

Attendees will leave with a clearer understanding of what this approach unlocks, where Prometheus exporters and Collector receivers overlap, and what this means for the future of interoperability between the two communities.

### 16:30–17:00 · Dynamic Modules in Envoy Gateway: API Design, Safety, and Operability

- Room: 4F | 414+415
- Speakers: Kota Kimura, Huabing (Robin) Zhao
- Track: Maintainer Track
- Labels: English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1228187

Envoy’s dynamic modules provide a high-performance way to extend HTTP processing, but turning that capability into a gateway feature introduces important questions around safety, API design, and operability. This talk shows how Envoy Gateway supports dynamic modules with Kubernetes-native APIs that separate infrastructure registration from policy-based attachment on Gateways and Routes. We explain how this maps to Envoy’s `dynamic_modules` HTTP filter and discuss the practical issues that make extensibility supportable in production, including filter ordering, invalid references, lifecycle behavior, and packaging. Using a real module composition approach as a case study, we compare bundled shared libraries with runtime-loaded plugins and highlight the tradeoffs for gateway and platform maintainers.

### 16:30–17:00 · Image-Based Bare-Metal Provisioning with Metal3.io, Cluster API and Kubernetes

- Room: 5F | 501
- Speakers: Kashif Khan, Ganesh Vasudevan
- Track: Operations + Performance
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1190384

Operating Kubernetes on bare metal has traditionally relied on PXE workflows, custom scripts, and manual intervention, leading to drift, inconsistent provisioning, and high operational overhead at scale. In this talk, we present a production case study adopting Metal3.io, Cluster API, and Ironic to enable fully declarative, Kubernetes-native bare-metal lifecycle management.

By modeling servers as Kubernetes resources via the BareMetalHost API and using image-based provisioning, we achieve deterministic node lifecycle operations, eliminating configuration drift and ensuring convergence to a validated state. Provisioning time was reduced by ~40%, with cluster bring-up dropping from hours to under 30 minutes. Failure recovery and hardware replacement are now handled through kubernetes native reconciliation, removing manual processes.

This approach aligns bare-metal operations with cloud-native patterns, demonstrating how Kubernetes can unify infrastructure management across environments

### 16:30–17:00 · The Road to Cilium: Migrating 150+ Kubernetes Clusters at Airbnb

- Room: 5F | 502
- Speakers: Yifei Sun
- Track: Connectivity
- Labels: Advanced, English
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1171327
- Slides: https://sessionize.com/download/ibnavot~9zkfYN7Uq7PcLTdedMoekJ.pdf~tb-544_-kubecon_cloudnativecon_japan_2026_-_airbnb-cilium-migration-google-slides.pdf

Airbnb migrated from AWS VPC CNI to Cilium across 150+ Kubernetes clusters to unlock eBPF-based capabilities like kube-proxy replacement and cluster-wide network policy. This talk shares lessons from that journey. While grounded in Airbnb’s experience, the patterns and lessons apply broadly to teams operating Kubernetes at scale.

We cover pod lifecycle performance testing at scale, using AWS VPC CNI as a reference. We’ll dive into how differences in IPAM configuration, EC2 API interactions, and workload identity allocation introduce scalability bottlenecks, particularly under high-churn data and batch workloads (e.g., Spark).

We also discuss rollout strategies across cluster, node, and pod levels, exploring the trade-offs of each. Finally, we’ll walk through practical solutions for challenges like dual-stack environments and circular dependencies during bootstrap. Attendees will leave with a safe, incremental rollout approach for large-scale Cilium adoption.

### 16:30–17:00 · Beyond the DC Walls: Building a Nationwide GPU Fabric with KubeVirt and Wide-Area L2

- Room: 5F | 503
- Speakers: Kazuki Sato, Jian Li
- Track: AI + ML
- Labels: English, Intermediate
- Link: https://events.linuxfoundation.org/kubecon-cloudnativecon-japan/program/schedule/?id=1194272
- Slides: https://sessionize.com/download/iszavtez~sqePpmio8YbTjdSLnQLru6.pdf~kubecon-japan-beyond-the-dc-walls.pdf

Cloud-native AI infrastructure faces a "physical wall" of power and land limits. To solve this, NTT and SKT built a "Nationwide GPU Fabric", merging a 1,000km+ high-speed L2 network (IOWN APN) with Kubernetes and KubeVirt to operate distributed DCs (Sapporo to Fukuoka) as a single cluster.

We deep-dive into the architecture, performance, and future of GPU orchestration beyond a single DC.

- Distributed vs. Traditional DCs: Achievable workloads and trade-offs across a 1,000km+ fabric from Sapporo to Fukuoka.
- Fabric-Aware Topology Alignment: We demonstrate how our solution maps long-haul IOWN APN constraints into KubeVirt VMs, maintaining high-performance GPU peer communication (NCCL) across 1,000km as a single, virtualized cluster.
- DRA Feature: We share KubeVirt’s static limits and the potential of DRA for dynamic orchestration.Attendees walk away with a concrete blueprint to shatter the "walls" of a single DC — a scalable solution for global urban AI infrastructure challenges.

