Skip to content

docs(process): add governance best practices for CNCF projects - #2224

Closed
angellk wants to merge 2 commits into
cncf:mainfrom
angellk:governance-best-practices
Closed

docs(process): add governance best practices for CNCF projects#2224
angellk wants to merge 2 commits into
cncf:mainfrom
angellk:governance-best-practices

Conversation

@angellk

@angellk angellk commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

Summary

Adds a governance best practices document to process/ with data-driven recommendations for CNCF projects at each maturity level (sandbox, incubating, graduating). Links added to process/README.md under Project Resources and Guide Posts.

What This Document Provides

Based on the TOC's governance analysis of 71 graduated and incubating CNCF projects:

  • What the data shows — multi-org projects graduate at 2.07x the rate of single-org; 7 of 35 graduated projects show post-graduation concentration; all 7 lacked org-balance mechanisms at incubation
  • Sandbox recommendations (9 items) — establish governance infrastructure that enables future diversification
  • Incubation recommendations (10 items) — org-balanced voting, multi-level contributor ladder, vendor neutrality enforced not just stated, maintainer lifecycle demonstrated
  • Graduation recommendations (4 items) — governance/code alignment verified, succession planning, contributor ladder producing external maintainers
  • Anti-patterns — cosmetic diversity, voter cap without org balance, governance/code divergence, documented-but-never-used processes, silent maintainership, foundation shopping
  • Exemplary patterns — org-balanced voting, steering committee with org caps, active emeritus process, community manager role, end-user governance seats
  • Practice period guidance — for projects with >75% LFX org dependency and no org-balance mechanism
  • Links to CNCF resources — templates, guides, and examples on contribute.cncf.io

What This Does NOT Do

  • Does not replace the incubation or graduation criteria
  • Does not name specific projects (neutral framing)
  • Does not mandate — provides recommendations with rationale

Related

Signed-off-by: Karena Angell karena.angell@gmail.com

@angellk
angellk requested a review from a team as a code owner July 6, 2026 03:15
@github-actions github-actions Bot added needs-triage Indicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied) needs-kind Indicates an issue or PR that is missing an issue type or kind (a kind/foo label) labels Jul 6, 2026
@github-actions github-actions Bot added the needs-group Indicates an issue or PR that has not been assigned a group (toc or tag/foo label applied) label Jul 6, 2026
Data-driven governance recommendations for projects at each maturity
level (sandbox, incubating, graduating), based on the TOC's governance
analysis of 71 graduated and incubating CNCF projects.

Covers:
- Org-balanced voting as the strongest predictor of sustained diversity
- Contributor ladder with multiple roles
- Maintainer lifecycle demonstrated not just documented
- Vendor neutrality enforced not just stated
- Security response roles, related project disclosure
- Steering committee with org caps
- Governance practice period for high-concentration projects
- Anti-patterns to avoid (cosmetic diversity, foundation shopping, etc.)
- Links to CNCF templates and resources on contribute.cncf.io

Added link to governance best practices in process/README.md under
Project Resources and Guide Posts.

Signed-off-by: Karena Angell <karena.angell@gmail.com>
- LFX Insights as corroboration, not primary verification source
- Org-balance mechanism required at graduation, recommended at incubation
- Contributor ladder "as applicable" qualifier at graduation
- Affiliation 30-day update policy with lapse remediation at incubation
- Security response roles reference Kubernetes SRC as model
- Post-graduation health check: biennial, not annual
- Add Org-Balanced Voting template to resources

Signed-off-by: Karena Angell <karena.angell@gmail.com>
@angellk
angellk force-pushed the governance-best-practices branch from a31683d to 08b15ce Compare August 10, 2026 18:43
@angellk

angellk commented Aug 10, 2026

Copy link
Copy Markdown
Contributor Author

Closing this PR. The content is now covered across purpose-built locations rather than a standalone best practices document that would need to stay in sync with all of them:

Governance guidance for projects (narrative "why" and "how"):

  • CNCF blog post: "Governance Guidance for CNCF Projects: Choosing the Right Structure for Your Project's Size and Stage" (submitted, in review) -- covers three governance models, org-balanced voting, anti-patterns, transition points, and per-level recommendations

Authoritative criteria ("what is required"):

Implementation templates ("how to implement"):

TOC operational guidance (practice period for high-concentration projects):

This was the one unique piece from this PR not covered elsewhere, and it belongs in the DD guide (TOC-facing operational guidance) rather than a project-facing best practices document.

@angellk angellk closed this Aug 10, 2026
@github-project-automation github-project-automation Bot moved this from New to Done in CNCF TOC Board Aug 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-group Indicates an issue or PR that has not been assigned a group (toc or tag/foo label applied) needs-kind Indicates an issue or PR that is missing an issue type or kind (a kind/foo label) needs-triage Indicates an issue or PR that has not been triaged yet (has a 'triage/foo' label applied)

Projects

Status: Done
Status: No status
Status: No status
Status: No status

Development

Successfully merging this pull request may close these issues.

2 participants