What K3s Is and Where It Stands in CNCF
K3s is a fully conformant Kubernetes distribution packaged as a single binary. A cluster is running in under 2 minutes. The design targets IoT and edge hardware where CPU and memory are constrained. K3s is currently a CNCF sandbox project, and the team is actively pursuing incubation. One blocker: the public adopters list is small. Buil asked any K3s user in the room to open a PR and add their name, noting it directly helps the incubation case.
Recent Releases: Go 1.25, containerd 2.2.2, and Secrets Encryption
Several concrete changes landed recently. K3s moved to Go 1.25 and upgraded to containerd 2.2.2, which matters for Dynamic Resource Allocation (DRA) and GPU attachment. A community contributor, now a maintainer, added a NYX snapshotter. Kine metrics expanded so operators can inspect database activity in more detail. Secrets encryption can now be toggled after initial deployment, removing the old requirement to decide at install time. S3 snapshot retention flags, previously local-only, now apply to S3-backed snapshots as well.
CNCF Citizenship: Inclusive Naming and Security Self-Assessment
Buil credited maintainer Orlin for a focused effort on CNCF compliance. The project completed inclusive naming updates and published a security self-assessment. K3s now runs regular public project meetings. Buil invited anyone to join those meetings, framing the project as open to outside contributors. These two items, inclusive naming and the self-assessment, are examples of work done specifically to meet CNCF incubation criteria rather than end-user feature requests.
What Comes Next: Gateway API, NFTables, Windows, and DRA
Four areas are on the near-term roadmap. Gateway API CRDs are not part of core Kubernetes, so each project installing K3s can end up with mismatched versions. The team wants to bundle them cleanly. NFTables support needs improvement. Windows support exists but is not complete, particularly for confidential containers via Kata. DRA for GPU consumption is a priority because two DRA APIs reached GA in Kubernetes 1.36. Gateway API and NFTables already have two maintainers assigned. The other three topics have no owners yet.
How to Contribute or Get Involved
Windows support, confidential containers, and DRA readiness need contributors. Buil gave two concrete ways to connect: a ContribFest session on Wednesday, and the project pavilion Wednesday and Thursday mornings. A QR code in the slides links to community meetings. Beyond code, Buil asked users to describe their K3s use cases directly to maintainers. He framed this as useful to the team: production use cases that maintainers rarely see help clarify which features matter most.
Notable Quotes
K3s is a fully conformant Kubernetes distribution. It’s it’s very lean because, yeah, we have a binary, you deploy it, and it doesn’t consume a lot of resources. Manuel Buil · ▶ 0:14
Our adopters list is ridiculously small. Manuel Buil · ▶ 0:52
For the rest of the topics, we have nobody. If you have some free cycles, if you would like to collaborate, if you would like to contribute to K3s, you are super welcome to do it. Manuel Buil · ▶ 3:48
We have like a wall that sometimes is hard for us, uh, to understand how it is being used. Manuel Buil · ▶ 4:34
Key Takeaways
- K3s starts a conformant Kubernetes cluster in under 2 minutes from a single binary.
- containerd 2.2.2 and Go 1.25 shipped recently, enabling DRA and GPU support improvements.
- Gateway API bundling, NFTables, Windows, and DRA for 1.36 need contributors now.
About the Speaker(s)
Manuel Buil is a Senior Software Engineer at SUSE and a K3s maintainer. He has spent almost a decade investigating and deploying network technologies in cloud platforms, working across SDN, NFV, CNF, multiple CNIs, and various Linux network technologies. He contributes upstream and has served on the OPNFV TSC.