Hi folks,
Ahead of the next meeting, I wanted to give the SIG an early look at something we'd like to discuss there.
We're putting together a proposal for a new Working Group, WG Workload Conformance, and are asking SIG Apps to co-sponsor alongside SIG Architecture. CNCF is already onboard with the proposal, and there is a consensus that they will host and oversee the operation of the CNCF Kubernetes Workload Conformance Program. The proposed working group would set the technical direction for the certification.
The problem it addresses: Certified Kubernetes verifies the cluster infrastructure layer, but nothing verifies the workloads running on top of it. Workloads routinely break on cluster upgrades due to deprecated APIs, ship insecure defaults, mis-size resources, or fail to survive node drains; and every end-user ends up re-auditing every workload themselves. The WG would define an open, objectively verifiable specification for workload runtime behavior plus the tooling to verify it, then hand both to a subproject under SIG Architecture.
Full proposal: https://docs.google.com/document/d/1BGc4xVcrpQDEDVdGbj5DAvce_VRCSz9zRvQ-5FIdzrM/edit
I've put this on the agenda for our next meeting on Aug 17th at 9AM Pacific and would appreciate folks skimming the docs beforehand so we can spend the time on discussion rather than a first read. Happy to answer questions here on the list in the meantime.