Skip to content

Commit

Permalink
Charter Docs (#2)
Browse files Browse the repository at this point in the history
* adding feedback from issue #1

Signed-off-by: Dunbar-Hall, Ian <[email protected]>

* adding feedback on limited access

Signed-off-by: Dunbar-Hall, Ian <[email protected]>

* Update charter.md with more contributors

Co-authored-by: Ian Dunbar-Hall <[email protected]>
Signed-off-by: Taylor Dolezal <[email protected]>

* Update CHARTER.md with the latest feedback

Signed-off-by: Taylor Dolezal <[email protected]>

---------

Signed-off-by: Dunbar-Hall, Ian <[email protected]>
Signed-off-by: Taylor Dolezal <[email protected]>
Signed-off-by: Taylor Dolezal <[email protected]>
Co-authored-by: Taylor Dolezal <[email protected]>
Co-authored-by: Taylor Dolezal <[email protected]>
  • Loading branch information
3 people committed Apr 6, 2023
1 parent c05c653 commit 8058979
Showing 1 changed file with 74 additions and 0 deletions.
74 changes: 74 additions & 0 deletions charter.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,74 @@
# CNCF Public Sector User Group Charter

Primary Authors: [@onlydole](https://github.com/onlydole)


Approved on: April 6th, 2023

Reviewed and contributed to by:

- [@riffingonsoftware](https://github.com/riffingonsoftware)
- [@idunbarh](https://github.com/idunbarh)
- [@AlanHohn](https://github.com/AlanHohn)

## Meetings

- Biweekly on Thursdays @ 10 AM Pacific Time

## Introduction

This charter describes the operations of the CNCF Public Sector User Group, which focuses on developing and sharing cloud native practices for public sector organizations that are building and operating cloud native infrastructure or applications.

This user group (UG) produces supporting material and best practices for end users in the public sector and provides guidance and coordination for CNCF projects working within the group's scope.

## Mission

The mission of the CNCF Public Sector User Group is to:

- Collaborate on areas related to developing, distributing, deploying, managing and operating secure cloud native workflows that can be used by organizations in the public sector vertical.
Develop informational resources including guides, tutorials, and white papers to give the community an understanding of best practices, trade-offs, and value-adds.
- Identify useful CNCF projects and contexts.
- Share information about gaps and opportunities for improvement with the CNCF ecosystem.

## Areas considered in Scope

The CNCF Public Sector User Group focuses on the following topics of the lifecycle of cloud-native applications:

- Isolated Environment Cloud Native Computing
- _An isolated environment is an environment that, because of locality or security constraints, is never connected to a broader network (airgapped) and must therefore be provisioned and maintained through media transfer (sneakernet)._
- Far Edge Cloud Native Computing
- _The far edge refers to systems that, because of size, weight, and power (SWAP) or locality constraints, is limited in scalability of computing resources and in connectivity to broader networks._
- Limited Access Cloud Native Computing
- _Limited access refers to cloud environments that, because of security classification or citizenship requirements, have physical connectivity restrictions and specialized regulatory approvals for data processing._

The group will work on developing best practices, fostering collaboration between related projects, working on improving tool interoperability, as well as proposing new initiatives and projects when blank spots in the current landscape are identified.

For CNCF projects, the scope of the Public Sector User Group engages, amongst others, with the application management focused ones, for example:

- Guidance on meeting different government compliance requirements (US Specific examples include [FIPS 140-2](https://csrc.nist.gov/publications/detail/fips/140/2/final) and [FedRamp](https://www.fedramp.gov/)

## Areas considered out of Scope

Anything not explicitly considered in the scope above. Example include:

- Discussion of information that is restricted such as export controlled. Separate non-CNCF sessions can be organized by User Group members that meet participant government requirements.

## Roadmap

- Track CNCF Project adoption of [White House Executive Order on Improving the Nation’s Cybersecurity](https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/) guidance.
- Provide guidance on governance models for CNCF sensitive projects that address steering concerns within the spirit of open source.
- Open Source Memo on the benefits for open source and where the risk profile is for CNCF projects.
- Breaking down regulatory guidance and mapping to CNCF projects / gaps
- Collate and recommend data standards and formats for open source transparency (licensing, SBOM, build infra, contributors, governance).
- Break down Government Open Source Requirements and mapping implementation of capabilities to CNCF projects.
- Mapping compliance of security or other items from Government requirements (WH Executive Order 14028) to CNCF Project processes to show what CNCF projects are compliant.

## Governance

### Cross-group relationships

The Public Sector is a broad vertical within Cloud Native computing; therefore this TAG may collaborate with other CNCF UGs, TAGs, and projects on various efforts.

## Contact

- [Slack Channel (#public-sector-ug)](https://cloud-native.slack.com/archives/C04RQ9L9KFS)

0 comments on commit 8058979

Please sign in to comment.