Loading…
Open Source Summit + Embedded Linux Conference North America...
May 18-20, 2026
Minneapolis, MN
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit North America 2025 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Central DaylightTime (UTC -5). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.


Venue: 200C (Level Two) clear filter
arrow_back View All Dates
Tuesday, May 19
 

11:00am CDT

Panel Discussion: Building an Enterprise Platform for Production-Ready AI Agents - Jothsna Praveena Pendyala, Infosys Ltd; Brett Smith, SAS; Steve Taylor, DeployHub; Sundeep Bobba, Southwest Airlines
Tuesday May 19, 2026 11:00am - 11:30am CDT

Speakers
avatar for Sundeep Bobba

Sundeep Bobba

Tech Lead Cloud DevOps Engineer, Southwest Airlines
Sundeep Bobba is a Tech Lead Cloud DevOps Engineer at Southwest Airlines with 15+ years of experience building large-scale, cloud-native CI/CD and automation platforms. He leads enterprise DevOps modernization supporting millions of customers and billions in digital revenue. He is... Read More →
avatar for Brett Smith

Brett Smith

Distinguished Software Developer, SAS
Distinguished Software Architect/Engineer/Developer with 25+ years of experience.
Specialties: Event Driven Automation, Continuous Integration/Delivery/Testing/Deployment, Supply Chain Security, AI Security
Expertise: Linux, packaging, and tool design.

Currently Engineering an... Read More →
avatar for Steve Taylor

Steve Taylor

CTO, DeployHub
Steve Taylor is a technology leader and innovator with deep expertise in service-based architecture, DevSecOps, open-source security, and secure software delivery. As CTO of DeployHub, he leads product strategy focused on build and release automation, vulnerability management, and... Read More →
avatar for Jothsna Praveena Pendyala

Jothsna Praveena Pendyala

Senior Data Scientist, Infosys Ltd
Jothsna Pendyala is a Senior Data Scientist and AI Engineer focused on enterprise AI platforms, agentic AI systems, and production-ready AI applications. Her work centers on building secure, scalable, and reliable AI solutions for enterprise environments, with expertise in AI platform... Read More →
Tuesday May 19, 2026 11:00am - 11:30am CDT
200C (Level Two)

11:35am CDT

Lightning Talk: It's Friday! - Alon Nisser, Zencity
Tuesday May 19, 2026 11:35am - 11:45am CDT
It's Friday afternoon, and you've got plans for this evening. You've just finished the feature. you push to main and click deploy. OR DO YOU?
Let's talk about Friday deployments and what they can teach us.
Speakers
avatar for Alon Nisser

Alon Nisser

Principal engineer, Zencity
Software developer. currently in Zencity.io. Writing software as a hobby and as a profession. Strong opinions on things. Open source aficionado. Trying to make a difference.
Sometimes software makes we wonder if I'd be better off being a farmer
Tuesday May 19, 2026 11:35am - 11:45am CDT
200C (Level Two)
  cdCon

11:50am CDT

Platform Engineering: Herding the Electric Sheep - Brett Smith, SAS
Tuesday May 19, 2026 11:50am - 12:15pm CDT
A talk about platform engineering, DevOps, DevSecOps, sprawl, chaos, compliance, and security. Why engineer an Internal Developer Platform when I have DevOps? DevOps works fine when you are a 20 person start-up but it often doesn't scale to Enterprise level development efforts. When you have 3000 developers with different needs and you are responsible for EO compliance and security a modular self-service platform is a good choice to build. In this talk I cover the challenges we have faced in a 3000 developers enterprise and how we are working to address them. I also cover how we are working on automating, integration, and scaling the creation of our internal developer platform. Leveraging SBOMs, SLSA, and other tools to help build out a secure and compliant platform. Attendees will learn the benefits and challenges of Platform Engineering
Attendee Takeaways
Answers for the following questions:
- Do we need a Platform Engineering Team?
- Is an IDP the right solution for my situation?
- What does a large scale IDP look like?
- What does it take to support a large scale IDP?
- What does security and compliance look like in an IDP?
Speakers
avatar for Brett Smith

Brett Smith

Distinguished Software Developer, SAS
Distinguished Software Architect/Engineer/Developer with 25+ years of experience.
Specialties: Event Driven Automation, Continuous Integration/Delivery/Testing/Deployment, Supply Chain Security, AI Security
Expertise: Linux, packaging, and tool design.

Currently Engineering an... Read More →
Tuesday May 19, 2026 11:50am - 12:15pm CDT
200C (Level Two)
  cdCon

12:20pm CDT

Lightning Talk: Where Deployment Authority Lives: A Cloud Native Design Pitfall in GitOps - Kim Schaefer, Game Plan Tech
Tuesday May 19, 2026 12:20pm - 12:30pm CDT
Many cloud-native GitOps systems quietly treat a Git merge as both a change proposal and a deployment authorization. While this works in low-risk environments, it collapses two very different responsibilities into a single decision. As systems grow more complex, that shortcut creates ambiguity around authorization, accountability, and audit trails that many environments simply cannot tolerate.

In this lightning talk, we’ll reframe that assumption as a cloud-native architectural concern, not just a tooling or security issue. Using GitOps as the example, we’ll look at how proposal, approval, and enforcement often become unintentionally coupled, and why that coupling makes it harder to reason about who is actually allowed to deploy.

The talk will walk through the architectural implications of letting Git act as the final authority, including where deployment decisions truly occur and how auditability and accountability can be lost when authority boundaries are unclear. We’ll then show how treating deployment authorization as a first-class architectural concept leads to clearer responsibility boundaries and more defensible cloud-native systems.
Speakers
avatar for Kim Schaefer

Kim Schaefer

Senior DevOps Engineer, Game Plan Tech
Kim Schaefer is a Senior DevOps and Cloud Engineer specializing in Kubernetes, GitOps, and secure platform engineering. Kim designs and operates production Kubernetes platforms on Google Cloud, including approval-gated GitOps systems that balance automation with explicit deployment... Read More →
Tuesday May 19, 2026 12:20pm - 12:30pm CDT
200C (Level Two)
  cdCon

12:45pm CDT

Bring Your Lunch, We'll Bring Our Notebooks: Securing Software Workflows - Tabatha DiDomenico, G-Research Open Source; Kadi McKean, ReversingLabs; Stacey Potter, OpenSSF & Katherine Druckman, JetBrains
Tuesday May 19, 2026 12:45pm - 1:45pm CDT
Somewhere along the way, the security ecosystem started asking you to add more steps, update more plugins, and generate more outputs without asking what that actually costs you.

We asked for feedback during a lunch time session at cdCon last year. The feedback was blunt, honest and exactly why we are back for this open-floor discussion hosted by the OpenSSF Developer Relations (DevRel) community. No slides, no demos, no pitches. This is a no-shame venting session with purpose; bring your lunch, your coffee, and your honest feedback. We want to hear from the people implementing and operating these tools. Share where security tools are missing the mark and what's standing between "this is a good idea" and "this is actually working for us."

This session leads directly into sessions with OpenSSF project maintainers, so the people who can act on your feedback will already be in the room.
Speakers
avatar for Katherine Druckman

Katherine Druckman

Head of Community and Partnership Engagement, JetBrains
Katherine Druckman is a senior technologist, speaker, and longtime advocate for open ecosystems. She specializes in developer experience, combining software ecosystem strategy, content creation, and community building, grounded in a foundation of hands-on software engineering experience... Read More →
avatar for Tabatha D.

Tabatha D.

OSS Security Engineer, G-Research Open Source
Tabatha DiDomenico is part of the Open Source team at G-Research focusing on supply chain security, secure open source practices, and community and developer relations.

Tabatha is president of Security BSides Orlando, co-host of the GR-OSS Out podcast and holds an MS in Cybersecurity from the University of South Florida. She has spoken at conferences including Black Hat Tools Arsenal, SOSS Fusion, ShmooCon, and Grace Hopper Celebration... Read More →
avatar for Kadi McKean

Kadi McKean

OSS Community Manager, ReversingLabs
Kadi is passionate about the DevOps / DevSecOps community since her days of working with COBOL development and Mainframe solutions. At ReversingLabs she collaborates with developers and security researchers to help entities prioritize their open source risk, reduce technical debt... Read More →
avatar for Stacey Potter

Stacey Potter

Community Manager, OpenSSF
Stacey brings extensive experience in open source community building, marketing, and event coordination. With a background spanning projects like Minder, Flux and Flagger, OpenFeature, and Keptn, she has played a key role in fostering engagement and driving adoption across cloud-native... Read More →
Tuesday May 19, 2026 12:45pm - 1:45pm CDT
200C (Level Two)
  cdCon
  • Audience Experience Level Any

2:10pm CDT

Security Things: How OpenSSF’s Technical Initiatives Keep You Safe From the Upside Down! - Stacey Potter, OpenSSF & Katherine Druckman, JetBrains
Tuesday May 19, 2026 2:10pm - 2:40pm CDT
As a sister foundation to the Continuous Delivery Foundation (CDF) under the auspices of The Linux Foundation, the Open Source Security Foundation’s (OpenSSF) mission is to make it easier to sustainably secure the development, maintenance, release, and consumption of open source software (OSS). This includes fostering collaboration within and beyond the OpenSSF, establishing best practices, and developing innovative solutions.

In this hour long session, we’ll connect real problems to OpenSSF solutions, then invite OpenSSF Working Group Leads and Project Maintainers to demo their respective projects in shortlightning rounds that show you how they’ll make your DevOps, CI/CD, or Platform Engineering lives easier to secure!
Speakers
avatar for Stacey Potter

Stacey Potter

Community Manager, OpenSSF
Stacey brings extensive experience in open source community building, marketing, and event coordination. With a background spanning projects like Minder, Flux and Flagger, OpenFeature, and Keptn, she has played a key role in fostering engagement and driving adoption across cloud-native... Read More →
avatar for Katherine Druckman

Katherine Druckman

Head of Community and Partnership Engagement, JetBrains
Katherine Druckman is a senior technologist, speaker, and longtime advocate for open ecosystems. She specializes in developer experience, combining software ecosystem strategy, content creation, and community building, grounded in a foundation of hands-on software engineering experience... Read More →
Tuesday May 19, 2026 2:10pm - 2:40pm CDT
200C (Level Two)
  cdCon

2:45pm CDT

Lightning Talk: Offensive and Defensive Strategies for Addressing Open-Source Vulnerabilities - Tracy Ragan, DeployHub, Inc.
Tuesday May 19, 2026 2:45pm - 2:55pm CDT
Open-source software is foundational to modern application development, but it has also become one of the fastest-moving and hardest attack surfaces to defend. For years, organizations have relied on “shift-left” security to catch vulnerabilities early in the lifecycle. While necessary, this approach alone is no longer sufficient. New vulnerabilities are disclosed daily, often long after software is deployed, leaving IT teams struggling to understand what is truly at risk in production and how quickly they must respond.

In this session, Tracy reframes software supply chain security around the realities of live systems. She explains why teams must move beyond offensive, prevention-only strategies and refocus on rapid detection, prioritization, and response for newly reported vulnerabilities attacking live systems. Tracy also addresses how the pursuit of a zero-vulnerability posture has driven alert fatigue and burnout among developers, security teams, and CIOs.

Attendees will learn how to manage vulnerability alert noise, shorten response times, and focus remediation, protecting open-source-driven systems without slowing delivery or exhausting the teams responsible for them.
Speakers
avatar for Tracy Ragan

Tracy Ragan

CEO, DeployHub
Tracy is a recognized expert in software supply chain security and DevSecOps, specializing in managing complex, decoupled architectures. She is the CEO of DeployHub, a scalable post-deployment vulnerability detection platform that empowers software to 'self-heal' by automatically... Read More →
Tuesday May 19, 2026 2:45pm - 2:55pm CDT
200C (Level Two)
  cdCon

3:00pm CDT

GitOps Gone Wild: Hardening Delivery Pipelines for the AI Era - Julien Semaan, Kubex & Corey McGalliard, Akamai
Tuesday May 19, 2026 3:00pm - 3:20pm CDT
GitOps promises safety and automation, but it will faithfully ship your mistakes at scale. With AI-assisted coding and emerging autonomous agents in the loop, those mistakes now move faster than humans can fully reason about their impact.

This talk dissects real-world GitOps failures where tiny configuration changes triggered outages, overly trusted pipelines amplified risk, and AI-generated patches were merged without understanding their consequences. None of these incidents were tooling failures. They were safety failures.

We’ll show how teams put guardrails back in place by enforcing policy before merge, using progressive rollouts to contain blast radius, applying Crossplane constraints to keep infrastructure changes reversible, and adding automated verification gates that catch problems before they reach production.
Speakers
avatar for Corey McGalliard

Corey McGalliard

Engineering Manager, Akamai Cloud
My team and I power and protect life online by building an internal, opinionated Kubernetes platform that meets Akamai's change-safety, security, and compliance expectations while delivering an excellent developer experience. I'm interested in distributed computing and platform engineering... Read More →
avatar for Julien Semaan

Julien Semaan

Head of k8s Engineering @Kubex | CNCF TAG DevEx Tech Lead, Kubex
Julien is the Head of Kubernetes Engineering at Kubex and a Tech Lead with the CNCF TAG for Developer Experience. With deep roots in open source and cloud-native systems, he has been working with Kubernetes since 2017 and has led multiple product transitions to cloud-native archi... Read More →
Tuesday May 19, 2026 3:00pm - 3:20pm CDT
200C (Level Two)
  cdCon
  • Audience Experience Level Any

3:25pm CDT

Lightning Talk: Built Clean. Receipts Attached - Adolfo García Veytia, Carabiner Systems & Alex Zenla, Edera
Tuesday May 19, 2026 3:25pm - 3:35pm CDT
Security frameworks such as SLSA require software builds to run in isolated environments to guarantee they are “free of unintended external influence”. In practice, this means full control of the runtime environment and every dependency entering a build, ensuring no malware slips into released software
But how can you verify isolation after the fact? How do you know a container image or binary was compiled in a truly hermetic environment, free from tampering processes or hidden tooling? Can you confidently prove your release used only the dependencies declared in your SBOM?
In this talk, Marina and Puerco will demonstrate practical techniques to verify build isolation and runtime characteristics. Want cryptographic proof of hermetic builds? We’ll show it. Need confidence in software components and complete SBOM coverage? Covered. Trace provenance to the exact VM that executed the build? Absolutely.
Using Cocoon, an open source build packager running inside Edera Protect isolated zones, we will verify attested machine identity via SPIFFE SVIDs, environment features, and SBOM completeness, all enforced with reusable policy code powered by technologies like in-toto, SLSA and Sigstore.
Speakers
avatar for Alex Zenla

Alex Zenla

CTO, Edera
Alex is a Founder & CTO at Edera, building technology for securing containers using hypervisors in Rust. She has contributed to many open source projects including Chromium, Chromium OS, Dart, and Ubuntu, some as early as 11 years old. Alex started in the corporate world at the age... Read More →
avatar for Adolfo Garcia Veytia

Adolfo Garcia Veytia

Founding Engineer, Carabiner Systems
Adolfo García Veytia (@puerco) is one of the Kubernetes SIG Release Technical Leads and actively works on the Release Engineering team. He specializes in improving the software that drives the automation behind the Kubernetes release process. He is also the creator of the OpenVEX... Read More →
Tuesday May 19, 2026 3:25pm - 3:35pm CDT
200C (Level Two)
  cdCon

3:35pm CDT

Lightning Talk: Where Does Your Policy Actually Live? - Dadisi Sanyika, Sol Duara, Inc.
Tuesday May 19, 2026 3:35pm - 3:45pm CDT
Your organization has a policy requiring all artifacts to pass security scanning before deployment. Simple enough. But you use three CI systems, so Team A implements it in Jenkins with a Groovy shared library, Team B uses a GitHub Actions reusable workflow, and Team C builds it into GitLab CI includes.

Same intent. Three implementations. Three syntaxes. Three maintenance burdens.

Now an auditor asks: "Prove these are equivalent."

This lightning talk examines what happens when policy lives inside tools versus above them. We'll look at an architectural pattern in which tools emit events upward and receive decisions downward via CDEvents, while policy logic lives in a single, auditable location. The tools keep doing tool things. Nothing changes, but everything works.

You'll leave with one question worth asking in your next architecture review: "Where does our policy actually live?" The answer has implications for maintenance burden, audit readiness, and the extent to which consistent governance can scale.
Speakers
avatar for Dadisi Sanyika

Dadisi Sanyika

CEO, Sol Duara, Inc.
I am the Governing Board Chair for the Continuous Delivery Foundation (Linux sub-foundation) and the CEO of Sol Duara, Inc. Previously, at Apple, I led a team of engineers dedicated to improving the Continuous Deployment experience for teams and the community. Our contributions are... Read More →
Tuesday May 19, 2026 3:35pm - 3:45pm CDT
200C (Level Two)
  cdCon

4:20pm CDT

eBPF and Open Source Code Ensure the Security of Your Clusters CI/CD Pipeline. - Hudson Coutinho, Linker Bank
Tuesday May 19, 2026 4:20pm - 4:40pm CDT
In this talk, I'll show how what happens DURING the build and deployment can be fatal.
Using eBPF, we created an Open Source app that monitors the kernel in real time to detect access to secrets, suspicious commands, and data exfiltration at the exact moment they occur.
In my consulting work, I've seen real-world scenarios where compromised runners handed over database secrets and cloud keys without anyone noticing.
The pipeline is a huge blind spot in current security.
Speakers
avatar for Hudson Coutinho

Hudson Coutinho

Hudson Coutinho, Devs On The Road
Bachelor's degree in Information Systems, postgraduate degree in artificial intelligence and cybersecurity.
12 years of experience accelerating the delivery, scalability, and resilience of software for national and international companies, leading high-performance multidisciplina... Read More →
Tuesday May 19, 2026 4:20pm - 4:40pm CDT
200C (Level Two)
  cdCon
  • Audience Experience Level Any

4:45pm CDT

Awards and Closing Ceremony - Mark Waite, Independent
Tuesday May 19, 2026 4:45pm - 4:55pm CDT

Speakers
avatar for Mark Waite

Mark Waite

Independent Consultant, Self-employed

Tuesday May 19, 2026 4:45pm - 4:55pm CDT
200C (Level Two)
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Audience Experience Level
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -