When Sovereignty Policy Threatens the Infrastructure It Depends On
Cloud native exists because thousands of contributors from every region built shared infrastructure together. European sovereignty policy, including the Cyber Resilience Act, the EU Sovereign Tech Fund, and certification discussions, aims to improve security and accountability. But interpreting sovereignty as nationally controlled code risks fracturing the collaboration model that made Linux and cloud native successful. Fragmentation would undermine trillions of dollars of value that open source has already delivered globally.
Code as Global Commons, Deployments as Regional Choices
Melen’s distinction separates code sovereignty from deployment sovereignty. The code itself stays a global commons, shared, open, and collaboratively developed. Deployments can be fully sovereign. Any region or state can run infrastructure that complies with local laws, security requirements, and policies. The innovation layer stays global. The operational layer adapts to regional needs. This framing lets European governments meet compliance goals without requiring separate, nationally maintained code forks that break the upstream model.
CRA Compliance and the Shift from Consumer to Contributor
The Cyber Resilience Act’s compliance deadline is approaching. Teams across Europe now scrutinize software supply chains, map dependencies, track vulnerability management, and evaluate how projects are maintained. CRA introduces security process expectations beyond passive use. Organizations can no longer treat open source as free infrastructure they consume without obligation. The required shift: from consuming to actively supporting the health and sustainability of the projects they depend on.
Foundations as the Governance Layer for Open Source Health
CNCF and similar foundations provide governance structures, coordinate security practices, support compliance efforts, and create a protected layer for maintainers. But foundations are not institutions separate from the community. They are contributors, maintainers, companies, and users working together. Companies that benefit most from open source must step up and support the projects they depend on. Those getting the most value carry the greatest obligation to keep the work going.
Notable Quotes
same time, deployments can be sovereign. Jan Melen · ▶ 01:33
foundations are not just institutions. Jan Melen · ▶ 02:55
Key Takeaways
- Interpreting sovereignty as nationally siloed code risks breaking the global open source model.
- Code stays a shared global commons; deployments adapt to regional laws and compliance requirements.
- The Cyber Resilience Act requires organizations to actively sustain the open source projects they consume.
- Companies benefiting most from open source carry the greatest obligation to fund and support maintainers.
About the Speaker(s)
Jan Melen is General Manager at Ericsson Software Technology and an expert in networking, open-source software, and cloud technologies with over two decades of experience. Since 2019 he has led a team dedicated to CNCF open-source projects, built Ericsson’s Kubernetes distribution, and championed an upstream-first culture across the company’s open-source contributions.