Metal3: From Sandbox to Incubation in Six Years

▶ Watch (0:01)

Metal3 manages bare-metal machines from Kubernetes. Give it a rack of empty servers and it returns a small cloud you can operate. The project started in 2019, joined the CNCF sandbox in 2020, and spent five years there before earning incubation on August 27, 2025. KubeCon EU 2026 marks the sixth or seventh project update the team has presented on the conference stage. All previous updates are available on YouTube.

Community Health After Incubation

▶ Watch (1:35)

Between incubation day and this talk, the project recorded 36,000 individual GitHub actions and shipped 59 releases across five components. Mirantis joined as a new adopter. The maintainer count and unique human contributor count both grew. Rozmán stressed “human contributors” specifically, noting five or six bots now run in the project. The team held weekly community meetings and two full-day meetups. Copilot was added for code review and to monitor a large CI pipeline.

Multi-Tenancy for Physical Servers

▶ Watch (3:03)

Metal3 represents each physical server as a bare-metal host object in Kubernetes. The team is building an intermediate layer so consumers can file a bare-metal host claim, receive a machine, and return it without knowing anything about the underlying hardware. When released, the host gets cleaned and restored to its default state. Proposals are accepted and pull requests are already open. Rozmán called this a challenging problem to implement well.

Provisioning Security from First Boot

▶ Watch (4:10)

Metal3 touches machines before they have an operating system, which means security work starts at firmware. The team is hardening iPXE, Redfish booting, BMC access, disk encryption at early boot stages, and boot process attestation. Machines may arrive with old firmware or never have been used before. Each of those conditions opens a different attack surface. Active development covers all of them, with proposals already accepted and code in progress.

OCI Images, Multi-Architecture, and Switch Management

▶ Watch (4:53)

OCI images were not historically the default disk format for physical servers. Metal3 is changing that: the goal is for provisioning agents, operating system images, and everything above them to ship through standard OCI pipelines, producing fully provisioned clusters. The team is also expanding multi-architecture support, testing IPv6-only deployments, and adding plugins to speed provisioning. The largest near-term announcement: Metal3 will soon manage physical network switches, not just servers.

Notable Quotes

we recorded 36,000 individual GitHub actions. We released 59 releases across all of the fine five components that we provide releases for. Ádám Rozmán · ▶ 02:02

We have to now specifically state that not AI contributors. We have like five six bots running in our projects. Ádám Rozmán · ▶ 02:26

one of the biggest news in our community is that very very soon, we will offer not just server management, but also physical switch management. Ádám Rozmán · ▶ 05:48

Key Takeaways

  • Metal3 reached CNCF incubation on August 27, 2025, after five years in sandbox.
  • 36,000 GitHub actions and 59 releases shipped in the months since incubation.
  • Physical switch management is the next major capability coming to Metal3.

About the Speaker(s)

Ádám Rozmán is a Senior Developer at Ericsson Software Technology with over eight years across embedded, DevOps, and cloud roles. He has contributed to Metal3 as an upstream developer since July 2021 and presented project updates at multiple KubeCon editions.