Loading...
Loading...

Kubernetes is rapidly emerging as the de facto operating system for AI, with two-thirds of organizations using it for generative AI inference and 82% adopting it in production. Its ecosystem — including tools like Kubeflow — enables organizations to build, scale, and retain control of AI systems through open, community-driven infrastructure. Bob Killen of CNCF and Liam Bollmann-Dodd of SlashData shared insights from recent reports showing that AI success still hinges on strong engineering fundamentals—especially internal developer platforms and overall developer experience.
While AI-generated code accelerates development, it shifts bottlenecks to DevOps, reliability, and security, increasing operational complexity. As a result, operator experience and well-defined guardrails have become critical to safely scaling AI. These controls help constrain both human and AI developers, reducing risk while enabling speed. At the same time, organizations are evolving team structures, expanding platform engineering groups to support internal users more effectively. Despite growing complexity, the core lesson remains consistent: open source innovation thrives on people, processes, and collaboration as much as on technology itself.
Learn more from The New Stack around the latest in Kubernetes and its emergence as an operating system for AI:
Kubernetes and AI: Are They a Fit?
How AI Is Pushing Kubernetes Storage Beyond Its Limits
Kubernetes and AI Are Shaping the Next Generation of Platforms
Join our community of newsletter subscribers to stay on top of the news and at the top of your game.
The Cloud Native Computing Foundation hosts critical components of the global technology infrastructure, including Kubernetes, Prometheus, and Envoy.
CNCF is the neutral home for collaboration, bringing together the industry's top developers, end users, and vendors.
Hello, everyone. I'm Jennifer Riggins for the new stack. We're here right on the floor at CubeCon Cloud NativeCon 2026.
You're up because we are in the EU, but last year it was not in the EU, so we changed it to Europe, not EU.
In Amsterdam, really good vibes, a really good day. We're talking today with Bob and Liam, and we're talking about two different reports that came out, I think, today, or they stole the deal.
And we're talking about just the state of Cloud Native and everything that's happening on the technology radar around.
These are not surprising topics, especially if you've been at CubeCon for the last 24 hours. Everything AI, everything platform engineering, and not surprisingly, everything with the developer experience and the operator experience, and the future of our lives or whatever.
So I'm so happy to have you both here. Do you want to each introduce yourselves, please?
Yeah, so my name is Liam Bowman. I'm the principal market research consultant at slash data. I've been working with CNCF and other Linux foundation organizations for about two years.
I am also the specialist on cloud and cloud deployments at a slash data when it comes to developer analysis.
I'm Bob Cullen. I am a senior technical program manager for the CNCF. I have been in the cloud native space for many years.
I've been creating like I'm stirring committee chair of like one of the six have just been involved in the space for a very long time.
Okay, CNCF cloud native computing foundation just for those that don't know, but if you're here, you're in the know.
So let's talk about that. I've never been a huge fan. I'm much less of a fan of the term AI native, but cloud native, no one was unless they were like created in the last 10 years or something.
Yeah, I need of nobody is yet because everyone had their shit before AI.
So with that.
What is a cloud native native developer? How do you identify that for the purposes of this and to decide this number of 20 million cloud native developers? What does that even need?
So that's the interesting thing like the definition of cloud native and a cloud developer has changed significantly.
It used to be someone that was using Kubernetes was using containers.
But now much more of the space is people consuming the technology that sits on top of Kubernetes.
It's going to be using it indirectly.
Like you have.
Yeah, so when we do the analysis, we don't ask people are you cloud native because basically no one is what it means.
And we're pretty fair that we had to be clear about how we understand it.
We ask a bunch of questions about technologies used in back end or cloud spaces.
And from those, we look at things like Kubernetes, container orchestration, containers, microservice, like a bunch of technologies people generally see as cloud native.
And if you use enough of them, we say this person is probably cloud native.
They may not call themselves there, but we would think they reflect someone who belongs in the cloud native community.
And that's where we get the very large 19.9 million number.
Very large, but also probably 40% of what AI told me was the amount of developers in the world.
So are the rest not cloud data.
What does that mean?
And yes.
So from my perspective, I think we are like possibly undercounting the number.
But the way we be undercounting it is, but what Bob said, which is that there's a whole bunch of technology built on cloud native principles of cloud native technologies that people just may not be aware they're using.
They just not realize that all this thing is all containers are all Kubernetes.
And they just not aware of that because they don't care.
It's not part of their drop description.
So we're possibly under reporting a chunk, but we also like we are being like quite loose.
And the fact that like someone who doesn't identify as cloud native, we will still give them that label, even if we think, because we think they're using enough technologies.
Good example, like give up actions.
They're all containers under the hood.
Yeah.
Okay.
So even if you were, but if you're using a SaaS product that also uses it with that count or no.
So in our survey specifically, they may not be identified as that because they have to be asked them like, which technology to use it.
And like we have like done follow ups and you can see that people like they'll say they use Kubernetes and we asked them what they do.
They have no idea what they're doing.
They just know that they just know they're using Kubernetes.
Yeah.
Like it's part of like the chain.
It's kind of a stack.
Yeah, yeah.
But like, so there's people like a kind of cloud native, but like maybe not in the way the CNCF and coupon with a necessarily think about these people.
But then like a part of the like broader community that is eventually going to be like bro in more more to buy CNC apps.
Good example.
In the last report, we had like a signal in drop in the like Kubernetes usage and like container usage.
But it wasn't an actual drop in usage.
It was just that the people are consuming a lot more of it and don't realize they're actually using it.
And that's we always say we always set that with APIs like the last 15 years.
Let's not talk about APIs.
Let's talk about what they do.
And that works for Kubernetes as well.
If it works.
But as one of the many themes of this conference, not surprisingly is open source under attack.
There AI is an amplifier of everything door of report said.
And that includes security attacks.
So is that a good thing this invisibility paradox that's around.
Kubernetes and to a lesser extent, the rest of the cloud native ecosystem.
But Kubernetes is a specific one.
It's a funny word too.
You go don't always know like what is that.
But on the other hand.
Is that good or is that good until things go wrong?
Nonorabilities.
I think for part of that, it's too full like yes, the like there's increased automated scanning.
There's especially automated like attacks on GitHub and things of that nature.
But we're also developing a lot more better tools at securing the systems.
And a lot more of tools of being able to like this MCP server for Kubernetes.
So I can go in there and look at it and like it'll make a bunch of suggestions to lock down the config.
So like I think security wise, it's going to be like a bit of back and forth for a while.
But like we will likely reach a sort of like.
Like equal state or at least like where we are.
Like where things have been, where things are now.
Does it matter though, because that was just to clarify, I think the number was.
It went from 60% of the people you survey was the survey just bigger this year and broader.
New they identified as cloud native or use containers.
So 40%.
So it could be an anomaly that you just talked to more people or broaden it or is it.
So basically what happened in the survey is that we took the understanding that those who are back end developers are not the only cloud native people.
And this was like a major kind of shortcoming.
And obviously when we decided to design this, cloud native was a very niche topic.
But then as they became more common, we had to basically say we have to be broader.
And even just opening up back ends from people who do like back end APIs, back and services to web back end developers.
So he brings in a whole bunch of developers who were just not cloud native in the same way.
So what we do every wave is they tried to like pull apart the original audience from within this audience.
And we find like the numbers gone from 60% to 58% among this life.
So that to me that implies that like there is a continuity among the of the people who were originally doing this.
It's kind of saved the same and it hasn't changed much.
But we both broaden what black back end meant.
So back end is not just back and services.
And then we also gave anyone who uses cloud the ability to see these questions about tech.
And suddenly that brings in like 95% of the audience use cloud in some way.
And then boom, you've got a massive, massive audience.
And we can then start to be like global level slices rather than just like sector level slices.
And then you have the AI developer of it all.
Yeah.
Which is a new source.
I guess are fairly.
I mean, they've all changed to LinkedIn like a year ago or two years ago.
But in the validity.
So how does their perception of the infrastructure change when you're bringing in these alleged AI developers?
It's kind of mixed.
A lot of tools and things that they are working with still like consume Kubernetes under the hood.
Because that's how they're doing their inference.
And in some cases, that's how they're doing their training.
They might be interacting with a library or something like Ray where there are some of the job.
But it's really going to like a Kubernetes cluster behind the scenes.
And I also think one of the things mentioned about security and like the kind of safety with AI making things like better and worse at the same time.
Is that one of the approach you can take is if you take the kind of developer platform internal tooling where you can basically prevent people from being dangerous to themselves.
You could control everything on your own or the security is done by someone who actually understands how security work.
All the pipelines that people who actually know how pipelines work.
So the AI developer, whether they are super competent medium competent like upscaled like downscaled.
You can basically just say they cannot destroy in our systems.
They are locked into what they do.
And then boy, you can kind of let them be a bit more dangerous because they can't actually break things.
We talk about this not too long ago with kind of like there's been a shift in like the like dev ops and the should like platform engineering and things like that.
Where it used to be much smaller teams where they were like both the dev and the ops and like people work on both.
And now we've seen the switch the like larger teams that are focused on platform engineering providing services for like their team.
Yeah to enable the teams internally.
Instead of having those people that are, you know, no both.
You're I think what you were saying like the smaller teams or like they're so split in like two different.
Yeah, like we've basically seen dev ops standardization kind of split into teams that do lock down everything behind a developer platform.
Like everything is controlled.
They have a team like a team that's well equipped with my resource.
And then the other side would be like, I want my developers to be on the cutting edge.
Like the developers are super controlled.
They provision everything they designed to control everything.
Well, well, but they but I think the view of it is like do you make your developers have like all the control in the world.
Or do you take the control away from the developers but make them focus on like products and services.
Yeah.
And I always say that there's no one way to do it.
Yeah.
It depends what you want to do.
Like and also there's a cultural thing like I joke that every SaaS company has the worst door metrics in the world.
Because none of them could ever launch something that doesn't fail.
Like there's no concept of launching around failure.
But they like that.
That's the kind of the culture like they want to be like I break things.
I smash things like things like we hot fix, we cold fix, we fix in production.
Like they like that culture.
If you were for a bank, you want no one to be able to do anything.
Yeah.
It isn't the most secure controlled thing ever.
And I think both are fine.
Like the shift left shift right to me is more of a whatever gets you a Ted talk rather than actual like divine class of things.
Yeah.
What gets you a cute contact?
Yeah.
I think you're going to still wait on that one.
We'll definitely go to platform after this.
But I have to ask because we are in the EU.
And the world is on fire.
One of the things that showed up is and I think this was the first time you've seen the highest level of hybrid cloud adoption.
Is that just because AI workloads are so expensive or is it really coming down?
Are you seeing people for the first time maybe paying attention to sovereignty or God forbid?
Is anyone paying attention to green ops or cost in this?
So I think I think it's regional.
I think it's regional dependent and I also think it's very all dependent.
So like in our analysis, you do find that like fintech insurance hardware.
They are really on hybrid like they that much much higher rates than like a SaaS company or like an e-commerce company.
So I think there is a lot of industry specific regulation that once they just make sure life easier if you're compliant in your thing.
And they also have a lot of these really large companies where they don't want some services to be on the same like the US cloud act has done a number to how a lot of European companies behave.
Like they just really cannot afford to be on it on like the big hyperscalers because they're the US cloud act under the current understanding in the EU.
Like is a risk to how the EU would legislate itself.
But at the same time you have what I think is missed a lot of time is to be in a cloud space.
We told the cloud people is that a lot of people just on on the cloud on hybrid cloud is like a kind of middle ground where they can they can they can push maybe the AI services to cloud maybe that big data system to cloud.
And they can keep what they want on their on premise thing a lot of those on premise investments into data centers like they are very expensive.
And if they have them, they're going to take advantage of them for as long as they possibly can.
Absolutely. And then just we have to talk about the job market.
There are people in this building.
Maybe not some expensive ticket to if you don't have a job, but everyone's looking for a job right now. I guess that's the nature of the tech industry anyway.
But traditionally.
When the job market's gone down open source contributions and usage goes up.
For various reasons, the cost and whatever, but we're bringing in this extra thing where it may be just easier to just build it yourself with AI.
Cheaper to just do that then maintain an open source project.
So, but we are also in a economic whirlwind and people less safe out their jobs.
What are you seeing in the data about jobs plus open source.
So I will say that in our data for the first time ever we did see a decline in the number of younger developers and less experienced development.
And obviously that the joke internally was are they just too busy looking for jobs to do our survey was there was obviously a comment we made.
And we don't know like we're you know the first with the first wave of the data.
We're not going to begin like saying the sky is falling on one wave of data, but it is worrying to see this.
And also I think what's more we're worrying is the the open source is building yourself of AI is a solution.
I don't think it's a real solution because like if you ever work in a SaaS company you realize the building a product building a service is like 1% of what it takes to actually run a product.
It is maintaining it can keep you working make sure regulations comply like I could go home right now and go on Claude code.
And they could spit out an equivalent version of Atlassian's products and it would break probably even a day because I would be something missed or something different.
Yeah, like that's just like one small example.
So I think open source is being hammered because people are being short short sighted.
I think the industry the moment is having a real cycle of short sightedness when it comes to so many layers of other purchases.
And I think this I could give I could go on like an hour long round about one case.
But like I think it is a short-sightedness that will come smacking back in a year or two.
And it will have like a good example. So like there was a talk where a person sang like you know they basically used AI to code something.
And it want to cost them a fair amount and actually like token usage and all that when little they just did a Google search they would have found an open source project that was mature.
That would have solved their problems.
So instead of actually like doing even a little bit of due diligence.
They went to you know just generating a solution that wanted to be worse than what is actually out there.
There was another instance where it like literally they had set up a AI crime job to do something that literally could have been done by a one line bash script.
And so that was much more both like computational like in in cost expensive for something that could have been done.
And much more maintainable by literally a one line script.
It's very interesting also because companies that are looking to get rid of junior developers.
They don't think they need it because of AI.
Maybe they should be looking at their opens. Maybe they should have an open source software bill of materials.
And then maybe they should be looking at where their risks are because that company could that maintain or could.
That is something that like I have stressed repeatedly.
They shouldn't pay two years to maintain.
Yeah, not enough of organizations are actually doing the due diligence to see to look at their risk.
And even these days of looking at the risk of using some of the commercial software that's coming about like.
When I walk organizations through developing a strategy like the first thing we go through is what are you using.
What would it cost for you to either fork and maintain.
Or trying to compete in open source project or find a competing like commercial product.
And then trying to weigh the numbers of how much that would cost to switch to any of them.
And that gives you an idea of whether like, okay, should we invest in open source project.
Or should we pursue one of these other solutions.
I also think that when when I was when Bob was bringing me into like more experience with the open source community.
I think one of the things that shocked me is how cheap paying a developer to be a very important part of a community project.
Like when like these big companies have like maintainers and contributors who are like very high up in the this project.
That means you can kind of dictate what that project does.
And like you get the contributions of everyone else helping.
And you are guiding it towards what's best for your services.
And who are like shocked this is so much cheaper than like, you know, building and maintaining entire systems of your own.
Absolutely. So I think we all agree on that.
And one of the piece in this and something that your tech radar deals with a lot is the platform engineering of it all.
Which can help with that software bill of materials.
It can help with onboarding junior developers things like that.
So what?
First of all, who's deciding what an IDP means anymore.
I thought that was really interesting for this.
I mean, you're going to collect that.
I want to know what that means.
So we do it in three different ways.
We do it differently in the tech radar as we do in our big survey.
So in the tech radar, we just asked them straight up like IDP.
And the reason we kind of do that is.
You say IDP or do you say eternal developer?
We say internal developer platform.
Okay.
And then there's also internal developer portal.
Yeah. Yeah.
So we say eternal developer platform and then we shorten the IDP.
And the reason we do that is.
We don't have enough questions to like really get very granular about it.
And these are people who say they used to have native and they say they've used these tools.
So we kind of hope that they have a bit of a context for it.
In our survey, our bigger survey, we don't ask them to give a platform.
We asked them like, do you have any of the following things in your organization?
Like, do you have standardized DevOps tools?
Do you have do you have an internal like we call it an internal like platform?
Like we use different words rather than just specifically saying IDP because.
We're all we're surveying like more than 12,000 developers from around the world with different languages.
We're different like exposure with those questions.
You can assert that they have an actual IDP or not.
Yeah, yeah.
So so we're with and then what we find is that we like in our big survey.
Like we've gone to 88% of people now have some form of standardization of tooling.
So that doesn't mean a platform that means like.
Maybe there's an official list of what tools you use or whether there's a.
A team that makes sure the tools work with their like services and stuff.
Like we're seeing a big shift like in general towards like I like like soft platform.
Which is like you don't have an actual platform.
But you're like there's a team that knows this is important.
Yeah.
And maybe they don't have enough support to do it fully.
But like this is kind of important that to do it overall.
It's very important on the other side platform engineering is just like the rest of the pipeline problem.
We've always was cybersecurity DevOps.
What is it like platform engineering cloud engineers.
We've always had a lack of talent.
And then we have layoffs.
And then it's not that people aren't talented by the way.
I mean there's just not enough people that know how to do it just to be clear.
Anyway lack of talent is.
But we add to that that there's maybe a 50% increase in lines of code that are going through.
And attacks and cybersecurity.
We don't know really.
So how can a platform help support that job funnel and what can open source projects.
How can open source somehow support this whole pipeline problem.
We've always had that's just more urgent.
There's more burnout than ever in these communities.
And then things get missed.
I can say at least when it comes to like the job market and things like that and getting a job.
So I was recruited by Google specifically for my open source contributions.
I was working.
I was working in academia has been in academia for like 20 years.
And was contributing to Kubernetes on the side as a passion project.
And literally got recruited that way.
And I know multiple other people that have had the same path.
A co-worker of mine, George Castro has because his kids are a whole bunch of like young students and things like that that have been working on his product.
Bluffin, which is a like Linux desktop type thing.
And they've all become like they were sending cash to the Linux kernel.
And they've the like a bunch of them have now moved on to get like jobs in tech and good jobs in tech.
So it's there and like that's how like for me like how open source can open the door is it is a public resume.
Of your you know.
And when I think one of the things vendors may miss with like the contributors is that like we asked questions about like why do you participate in an open source community that's owned by a vendor which like kind of feels like this is a billion dollar company.
Why am I helping them?
But when you ask developers that like I get to have my code reviewed by super experts.
I get to like be involved with a project which has high levels of utility and I get to be visible.
I think if vendors and these big companies don't do responsible stewardship around like younger developers.
They're not only missing out talent, but they're missing out the ability for the next generation to like build themselves up and to gain more like structures.
We're never going to have more senior developers without you and more junior developers.
Thank you both so much for this time we could go we really could go into the data the whole time.
And I would recommend everyone download the reports because there's a lot of data in there.
12,000 engineers I think you were cloud native developers you interviewed that's a lot of data and a lot of insights and.
Organizations a lot of thinking to see how you compare and how you're supporting your developers for success.
So thank you so much enjoy the rest of your keep on.
Thank you.
Thank you for having us.
The New Stack Podcast
