cncf / cncf/toc

[Incubation] Higress Incubation Application

Open
#2,291 2 comments 0 reactions 0 assignees View on GitHub
dd/needs-triage kind/dd level/incubation needs-triage toc
Dominant language
HTML
Stars
1.9k
Forks
724
Avg merge
6d 12h
Merged PRs (30d)
4

Description

# Review Project Moving Level Evaluation

[x] I have reviewed the TOC's [moving level readiness triage guide](https://github.com/cncf/toc/blob/main/operations/dd-toc-guide.md#initial-triageevaluation-prior-to-assignment), ensured the criteria for my project are met before opening this issue, and understand that unmet criteria will result in the project's application being closed.

# Higress Incubation Application

v1.6

This template provides the project with a framework to inform the TOC of their conformance to the Incubation Level Criteria.

Project Repo(s):

- [higress-group/higress](https://github.com/higress-group/higress), primary repository

Supporting governance and community documentation is maintained in [higress-group/community](https://github.com/higress-group/community). Other repositories within the project scope are listed under Sub-Projects below.

Project Site: [https://higress.ai/en/](https://higress.ai/en/)

Sub-Projects: `higress-console`, `higress-standalone`, `plugin-server`, and `wasm-go`. Their scope and status are documented in [GOVERNANCE.md](https://github.com/higress-group/community/blob/main/GOVERNANCE.md).

Related Projects: None declared for this application. Higress integrates with and builds on CNCF projects including Kubernetes, Envoy, Istio, Prometheus, and OpenTelemetry, but does not claim those projects as Higress subprojects.

Communication: The official public and private-purpose channels are listed in [COMMUNITY.md](https://github.com/higress-group/community/blob/main/COMMUNITY.md). Public channels include GitHub Issues, Pull Requests, Discussions, Discord, and the monthly [Higress Community Meeting](https://github.com/higress-group/community/blob/main/MEETINGS.md).

Project points of contact:

- Yuanxiao Zhao, [@EndlessSeeker](https://github.com/EndlessSeeker), 1766508902@qq.com
- Yiquan Dong, [@CH3CHO](https://github.com/CH3CHO), ch3cho@qq.com

- [ ] (Post Incubation only) [Book a meeting with CNCF staff](http://project-meetings.cncf.io) to understand project benefits and event resources.

Not applicable at the time of application.

## Incubation Criteria Summary for Higress

### Application Level Assertion

- [x] This project is currently Sandbox, accepted on 2026-04-13, and applying to Incubation.

The [Sandbox application](https://github.com/cncf/sandbox/issues/445) was accepted in 2026, and [project onboarding](https://github.com/cncf/sandbox/issues/481) was completed on June 17, 2026.

- [ ] This project is applying to join the CNCF at the Incubation level.

Not applicable because Higress is already a CNCF Sandbox project.

### Adoption Assertion

_The project has been adopted by the following organizations in a testing and integration or production capacity:_

- Ant Digital
- Kuaishou
- Trip.com Group
- Vipshop
- Labring, the company behind Sealos

The public evidence is maintained in [ADOPTERS.md](https://github.com/higress-group/community/blob/main/ADOPTERS.md). The expanded adopter list was merged in [community#8](https://github.com/higress-group/community/pull/8).

**Adopter Interviews:** Five adopter questionnaires were submitted on September 4, 2026 for Ant Digital, Kuaishou, Trip.com Group, Vipshop, and Labring/Sealos, with each submission linked to this application. All contacts have agreed to participate in the CNCF interview. Public identification in the Due Diligence remains subject to company approval. CNCF interviews and TOC verification remain pending.

## Application Process Principles

### Suggested

- [ ] **Engage with domain-specific TAG(s) to present the technical architecture of the project.**

This has not yet been completed. We are available to present the architecture if requested during review.

### Required

- [x] **Complete a [General Technical Review (GTR)](../toc_subprojects/project-reviews-subproject/general-technical-questions.md).**

The project assessment is complete and published in [general-technical-review.md](https://github.com/higress-group/community/blob/main/docs/cncf/general-technical-review.md). The external Project Reviews request is open in [cncf/toc#2266](https://github.com/cncf/toc/issues/2266) and is awaiting triage and reviewer assignment. The CNCF DD triage guide states that projects should not be blocked while CNCF associates review and upload vetted snapshots.

- [x] **Complete a [Governance Review](../toc_subprojects/project-reviews-subproject/governance-review-template.md).**

The project assessment is complete and published in [governance-review.md](https://github.com/higress-group/community/blob/main/docs/cncf/governance-review.md). The external Project Reviews request is open in [cncf/toc#2267](https://github.com/cncf/toc/issues/2267) and is awaiting triage and reviewer assignment. The CNCF DD triage guide states that projects should not be blocked while CNCF associates review and upload vetted snapshots.

- [x] **All project metadata and resources are [vendor-neutral](https://contribute.cncf.io/maintainers/community/vendor-neutrality/).**

Higress can be deployed on any conformant Kubernetes cluster in public cloud, private cloud, on-premises, or local environments. It does not require an Alibaba Cloud account, API, or commercial service. Project governance gives no company a reserved seat, veto, or preferred decision weight. Alibaba Cloud's commercial Higress offering is a downstream distribution and has no special authority over the open source project. The project's vendor-neutral governance is documented in [GOVERNANCE.md](https://github.com/higress-group/community/blob/main/GOVERNANCE.md).

- [x] **Review and acknowledgement of expectations for [Sandbox](https://sandbox.cncf.io) projects and requirements for moving forward through the CNCF Maturity levels.**

Higress completed Sandbox onboarding on June 17, 2026, and acknowledges the current Incubation criteria and ongoing CNCF project obligations.

- [ ] **Due Diligence Review.**

Completion of this due diligence document, resolution of concerns raised, and presented for public comment satisfies the Due Diligence Review criteria.

This application requests the review. DD, public comment, resolution of concerns, and TOC decision remain to be completed.

- [x] **Additional documentation as appropriate for project type, e.g.: installation documentation, end user documentation, reference implementation and/or code samples.**

Installation, operations, end-user documentation, examples, and API references are available from the [Higress documentation site](https://higress.ai/en/docs/latest/overview/what-is-higress/) and the [primary repository](https://github.com/higress-group/higress).

## Governance and Maintainers

Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject if completed as a suggested item prior to application.

### Suggested

- [ ] **Complete a Governance Review with the Project Reviews subproject**

[cncf/toc#2267](https://github.com/cncf/toc/issues/2267) is open and awaiting triage and reviewer assignment.

- [x] **Governance has continuously been iterated upon by the project as a result of their experience applying it, with the governance history demonstrating evolution of maturity alongside the project's maturity evolution.**

Governance, maintainer lifecycle, vendor neutrality, security roles, project scope, and public meeting processes are maintained through public pull requests in the [community repository](https://github.com/higress-group/community).

- [x] **If the project has subprojects: subproject leadership, contribution, maturity status documented, including add/remove process.**

Subproject scope, status, governance, and lifecycle are documented in [GOVERNANCE.md](https://github.com/higress-group/community/blob/main/GOVERNANCE.md).

### Required

- [x] **Clear and discoverable project governance documentation.**

See [GOVERNANCE.md](https://github.com/higress-group/community/blob/main/GOVERNANCE.md).

- [x] **Governance is up to date with actual project activities, including any meetings, elections, leadership, or approval processes.**

The governance model uses public lazy consensus and public issue or pull request records. Current meeting and leadership information is linked from the community repository.

- [x] **Governance clearly documents [vendor-neutrality](https://contribute.cncf.io/maintainers/community/vendor-neutrality/) of project direction.**

See the Vendor Neutrality section of [GOVERNANCE.md](https://github.com/higress-group/community/blob/main/GOVERNANCE.md#vendor-neutrality).

- [x] **Document how the project makes decisions on leadership, contribution acceptance, requests to the CNCF, and changes to governance or project goals.**

See the Decision Making section of [GOVERNANCE.md](https://github.com/higress-group/community/blob/main/GOVERNANCE.md#decision-making).

- [x] **Document how role, function-based members, or sub-teams are assigned, onboarded, and removed for specific teams (example: Security Response Committee).**

Function-based teams are covered in [GOVERNANCE.md](https://github.com/higress-group/community/blob/main/GOVERNANCE.md#function-based-teams). Security Response Team membership and responsibilities are documented in [SECURITY.md](https://github.com/higress-group/higress/blob/main/SECURITY.md#security-response-team).

- [x] **Document a complete maintainer lifecycle process (including roles, onboarding, offboarding, and emeritus status).**

Roles, nomination, annual review, affiliation updates, offboarding, removal, and emeritus status are documented in [MAINTAINERS.md](https://github.com/higress-group/community/blob/main/MAINTAINERS.md).

- [x] **Demonstrate usage of the maintainer lifecycle with outcomes, either through the addition or replacement of maintainers as project events have required.**

The maintainer roster was formally established through [higress#3754](https://github.com/higress-group/higress/pull/3754), and the lifecycle process and 2026 activity and affiliation review were documented through [higress#4177](https://github.com/higress-group/higress/pull/4177). [community#10](https://github.com/higress-group/community/pull/10), merged on September 3, 2026, records the review and its outcome in the canonical maintainer documentation. The project applied the lifecycle review and retained all seven maintainers as active. No project event required an addition, replacement, or emeritus transition, so the project did not manufacture an artificial personnel change solely for this application.

- [x] **Maintainer affiliations are current and a policy is in place requiring updates within 30 days of employment changes.** _(If affiliations have lapsed, document how the project identified and corrected them.)_

Current affiliations are maintained in [MAINTAINERS.md](https://github.com/higress-group/community/blob/main/MAINTAINERS.md). [community#10](https://github.com/higress-group/community/pull/10), merged on September 3, 2026, added the explicit requirement that maintainers update their affiliation within 30 days of an employment or organizational affiliation change.

- [x] **Document complete list of current maintainers, including names, contact information, domain of responsibility, and affiliation.**

See [MAINTAINERS.md](https://github.com/higress-group/community/blob/main/MAINTAINERS.md).

- [x] **A number of active maintainers which is appropriate to the size and scope of the project.**

Higress currently documents seven active project maintainers and public activity evidence for the annual roster review.

- [x] **Code and Doc ownership in Github and elsewhere matches documented governance roles.**

Project-wide maintainers are documented in [MAINTAINERS.md](https://github.com/higress-group/community/blob/main/MAINTAINERS.md), while day-to-day path ownership is delegated through repository `CODEOWNERS`, including the [primary repository rules](https://github.com/higress-group/higress/blob/main/CODEOWNERS).

- [x] **Document adoption and adherence to the CNCF Code of Conduct or the project's CoC which is based off the CNCF CoC and not in conflict with it.**

See [CODE_OF_CONDUCT.md](https://github.com/higress-group/community/blob/main/CODE_OF_CONDUCT.md).

- [x] **CNCF Code of Conduct is cross-linked from other governance documents.**

It is linked at the beginning of [GOVERNANCE.md](https://github.com/higress-group/community/blob/main/GOVERNANCE.md).

- [x] **All subprojects, if any, are listed.**

See Project Scope and Subprojects in [GOVERNANCE.md](https://github.com/higress-group/community/blob/main/GOVERNANCE.md#project-scope-and-subprojects).

## Contributors and Community

Note: this section may be augmented by the completion of a Governance Review from the Project Reviews subproject.

### Required

- [x] **Contributor ladder with multiple roles for contributors.**

Higress documents Contributor, Code owner, and Maintainer roles in [GOVERNANCE.md](https://github.com/higress-group/community/blob/main/GOVERNANCE.md#roles) and [CONTRIBUTING_EN.md](https://github.com/higress-group/higress/blob/main/CONTRIBUTING_EN.md).

- [x] **Clearly defined and discoverable process to submit issues or changes.**

See [CONTRIBUTING_EN.md](https://github.com/higress-group/higress/blob/main/CONTRIBUTING_EN.md).

- [x] **Project must have, and document, at least one public communications channel for users and/or contributors.**

Public GitHub channels, Discord, community groups, and meetings are listed in [COMMUNITY.md](https://github.com/higress-group/community/blob/main/COMMUNITY.md).

- [x] **List and document all project communication channels, including subprojects (mail list/slack/etc.). List any non-public communications channels and what their special purpose is.**

See [COMMUNITY.md](https://github.com/higress-group/community/blob/main/COMMUNITY.md).

- [x] **Up-to-date public meeting schedulers and/or integration with CNCF calendar.**

The monthly schedule and joining information are documented in [MEETINGS.md](https://github.com/higress-group/community/blob/main/MEETINGS.md), with a recurring entry on the [LFX public calendar](https://zoom-lfx.platform.linuxfoundation.org/meetings/higress). Meeting notes are published in the [meetings directory](https://github.com/higress-group/community/tree/main/meetings).

- [x] **Documentation of how to contribute, with increasing detail as the project matures.**

See [CONTRIBUTING_EN.md](https://github.com/higress-group/higress/blob/main/CONTRIBUTING_EN.md).

- [x] **Demonstrate contributor activity and recruitment.**

Public evidence includes [GitHub contributors](https://github.com/higress-group/higress/graphs/contributors), [recent activity](https://github.com/higress-group/higress/pulse), [CNCF DevStats](https://higress.devstats.cncf.io/), and open [`help wanted`](https://github.com/higress-group/higress/issues?q=is%3Aissue+is%3Aopen+label%3A%22help+wanted%22) and [`good first issue`](https://github.com/higress-group/higress/issues?q=is%3Aissue+is%3Aopen+label%3A%22good+first+issue%22) issues.

## Engineering Principles

### Suggested

- [x] **Roadmap change process is documented.**

See [ROADMAP.md](https://github.com/higress-group/community/blob/main/ROADMAP.md).

- [x] **History of regular, quality releases.**

See [GitHub Releases](https://github.com/higress-group/higress/releases) and the versioned [release notes](https://github.com/higress-group/higress/tree/main/release-notes).

### Required

- [x] **Document project goals and objectives that illustrate the project’s differentiation in the Cloud Native landscape as well as outlines how this project fulfills an outstanding need and/or solves a problem differently. _This can also be satisfied by completing a General Technical Review._**

The project purpose, differentiation, and use cases are documented in the [project README](https://github.com/higress-group/higress/blob/main/README.md) and [General Technical Review](https://github.com/higress-group/community/blob/main/docs/cncf/general-technical-review.md).

- [x] **Document what the project does, and why it does it - including viable cloud native use cases. This can also be satisfied by completing a General Technical Review.**

See the [project README](https://github.com/higress-group/higress/blob/main/README.md) and [General Technical Review](https://github.com/higress-group/community/blob/main/docs/cncf/general-technical-review.md).

- [x] **Document and maintain a public roadmap or other forward looking planning document or tracking mechanism.**

See [ROADMAP.md](https://github.com/higress-group/community/blob/main/ROADMAP.md) and the [published roadmap](https://higress.ai/en/docs/latest/overview/roadmap/).

- [x] **Document overview of project architecture and software design that demonstrates viable cloud native use cases, as part of the project's documentation. _This can also be satisfied by completing a General Technical Review and capturing the output in the project's documentation._**

See [docs/architecture.md](https://github.com/higress-group/higress/blob/main/docs/architecture.md) and the [General Technical Review](https://github.com/higress-group/community/blob/main/docs/cncf/general-technical-review.md).

- [x] **Document the project's release process.**

See [RELEASE.md](https://github.com/higress-group/higress/blob/main/RELEASE.md).

## Security

Note: this section may be augmented by a joint-assessment performed by TAG Security and Compliance if completed as a suggested item prior to application.

### Suggested

- [ ] **Complete a joint security assessment with TAG Security and Compliance**

This has not been completed. The Security Self-Assessment has been reviewed and approved in [cncf/toc#2268](https://github.com/cncf/toc/pull/2268), and Higress is available for a joint assessment if requested.

### Required

- [x] **Clearly defined and discoverable process to report security issues.**

See [SECURITY.md](https://github.com/higress-group/higress/blob/main/SECURITY.md).

- [x] **Enforcing Access Control Rules to secure the code base against attacks (Example: two factor authentication enforcement, and/or use of ACL tools.)**

The protected `main` branch requires one approval, a Code Owner review, and successful `license/cla`, `build`, `lint`, and `Analyze (go)` checks against the current base branch. Force pushes and branch deletion are disabled. Build, Go vet, and CodeQL workflows are maintained in the public repository.

- [x] **Document assignment of security response roles and how reports are handled.** _(This is distinct from the security reporting process above — document who is responsible for triaging and responding to reports, not just where to send them. For reference, see the [Kubernetes Security Response Committee](https://github.com/kubernetes/committee-security-response) as a model for named membership, documented responsibilities, and a clear escalation path.)_

Named Security Response Team membership, triage, fix, review, release, disclosure, conflict, and escalation responsibilities are documented in [SECURITY.md](https://github.com/higress-group/higress/blob/main/SECURITY.md#security-response-team).

- [x] **Document [Security Self-Assessment](https://tag-security.cncf.io/community/assessments/guide/self-assessment/).**

The project copy is published in [security-self-assessment.md](https://github.com/higress-group/community/blob/main/docs/cncf/security-self-assessment.md). The canonical CNCF copy is proposed in [cncf/toc#2268](https://github.com/cncf/toc/pull/2268), where the latest version has received reviewer approval and is awaiting CNCF merge.

- [x] **Achieve the [Open Source Security Foundation (OpenSSF) Best Practices passing badge](https://www.bestpractices.dev/).** _(Link to your bestpractices.dev project page below.)_

Higress has a current [OpenSSF Best Practices Passing badge](https://www.bestpractices.dev/projects/12667), with all Passing-level criteria reported as complete.

## Ecosystem

### Suggested

N/A

### Required

- [x] **Publicly documented list of adopters, which may indicate their adoption level (dev/trialing, prod, etc.)**

See [ADOPTERS.md](https://github.com/higress-group/community/blob/main/ADOPTERS.md), including environment and use case information.

- [x] **Used in appropriate capacity by at least 3 independent + indirect/direct adopters, (these are not required to be in the publicly documented list of adopters)**

Kuaishou, Trip.com Group, Vipshop, and Labring are independent from the project's primary contributing vendor and report production use. Ant Digital is also publicly listed but is not relied upon to satisfy the independence minimum.

- [ ] **TOC verification of adopters.**

Five adopter questionnaires were submitted on September 4, 2026. CNCF interviews and TOC verification remain pending. Any published interview summary remains subject to final adopter approval.

- [x] **Clearly documented integrations and/or compatibility with other CNCF projects as well as non-CNCF projects.**

Integrations and compatibility with Kubernetes, Gateway API, Envoy, Istio, Prometheus, OpenTelemetry, OCI registries, service registries, model providers, and related systems are documented in the [General Technical Review](https://github.com/higress-group/community/blob/main/docs/cncf/general-technical-review.md), architecture documentation, project README, and user documentation.

## Specification Project Information (if applicable)

Not applicable. Higress is a software project and does not define normative behavior intended for independent third-party implementation.

## Additional Information

The following CNCF review artifacts are already available or in progress:

- [General Technical Review request, cncf/toc#2266](https://github.com/cncf/toc/issues/2266)
- [Governance Review request, cncf/toc#2267](https://github.com/cncf/toc/issues/2267)
- [Security Self-Assessment PR, cncf/toc#2268](https://github.com/cncf/toc/pull/2268), approved by a reviewer and awaiting merge

The project is ready to answer reviewer questions, join Project Reviews meetings, and provide additional evidence during due diligence.

Contributor guide

Open the contributing guide

Research direction

Start by reading the application criteria and the linked community/GOVERNANCE.md, MAINTAINERS.md, SECURITY.md, and review documents. Check the pending due-diligence, public-comment, CNCF review, and TOC decision steps, including cncf/toc#2266 and #2267. Done means the required review concerns are addressed and the TOC reaches a decision.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.