惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
P
Palo Alto Networks Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
P
Privacy & Cybersecurity Law Blog
Security Archives - TechRepublic
Security Archives - TechRepublic
阮一峰的网络日志
阮一峰的网络日志
Recent Announcements
Recent Announcements
P
Proofpoint News Feed
H
Hacker News: Front Page
H
Help Net Security
云风的 BLOG
云风的 BLOG
H
Heimdal Security Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
L
Lohrmann on Cybersecurity
C
Check Point Blog
Google DeepMind News
Google DeepMind News
Forbes - Security
Forbes - Security
P
Proofpoint News Feed
Google DeepMind News
Google DeepMind News
I
InfoQ
The GitHub Blog
The GitHub Blog
The Cloudflare Blog
I
Intezer
L
LINUX DO - 最新话题
K
Kaspersky official blog
Attack and Defense Labs
Attack and Defense Labs
C
CERT Recently Published Vulnerability Notes
aimingoo的专栏
aimingoo的专栏
S
SegmentFault 最新的问题
NISL@THU
NISL@THU
人人都是产品经理
人人都是产品经理
雷峰网
雷峰网
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Vercel News
Vercel News
C
Cyber Attacks, Cyber Crime and Cyber Security
T
Threatpost
Y
Y Combinator Blog
S
Security Affairs
Latest news
Latest news
T
Threat Research - Cisco Blogs
T
Tailwind CSS Blog
C
Cisco Blogs
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
P
Privacy International News Feed
Jina AI
Jina AI
Apple Machine Learning Research
Apple Machine Learning Research
Cisco Talos Blog
Cisco Talos Blog
T
Troy Hunt's Blog
S
Securelist
MongoDB | Blog
MongoDB | Blog

Superuser

A Hybrid Private Cloud as an AI Factory – Superuser How India’s Payment Backbone Runs on Open Source – Superuser What AI Builders Can Learn From a Decade of Open Source CI – Superuser How Pinaka ZTi Builds Sovereign Clouds Governments Can Actually Trust – Superuser KDDI’s Private Cloud Supporting Communications – Superuser When Vietnam’s Cloud Infrastructure Is No Longer the Bottleneck – Superuser Sovereign AI Cloud – Superuser Why Digital Sovereignty Depends on Invisible Labor – Superuser Ongoing Development and Next Steps for DOCOMO and Tacker – Superuser Why AI Agents Need Stronger Sandboxing and What the Kata Containers Community Is Doing About It – Superuser A Guide to Manila Security and Terraform Integration – Superuser A Strategic Growth Opportunity for Open Infrastructure – Superuser NTT DOCOMO’s Tacker Activity – Superuser NTT DOCOMO’s Journey of Virtualization for Mobile Networks – Superuser How Rapifuzz CyberKshetra Built a Scalable Cyber Range on OpenStack (and Cut Costs by 60%) Integration of the Octavia module (Load Balancer as a Service) in an OpenStack Cloud Environment – Part 2 – Superuser OpenStack Case Study: CloudVPS – Superuser The 10th China Open Source Hackathon Recap: Projects, Talks, and More – Superuser Inside CERN’s Open Data portal – Superuser Taking the OpenStack ops manuals to the next level – Superuser Making your first contact with OpenStack – Superuser How tech giant Tencent uses OpenStack – Superuser Managing port level security in OpenStack – Superuser Using Ansible 2.0 to launch a server on OpenStack – Superuser Simple auto scaling environment with Heat – Superuser
How France’s National Railway Runs on Open Source – Superuser
Allison Price · 2026-04-13 · via Superuser

When Thomas Comtet took the keynote stage at KubeCon + CloudNativeCon Europe 2026 in Amsterdam, he opened with a set of numbers that put the room in perspective. SNCF, France’s national railway operator, employs 284,000 people worldwide, carries five million passengers every single day, operates 15,000 trains daily, and runs more than 2,000 applications in production. It is among the world’s largest mass transit operators, and its Île-de-France commuter network alone ranks as the second-busiest in the world after Tokyo’s.

For an organization of that scale, security, reliability, safety, and cybersecurity are existential concerns. So when the conversation turns to digital sovereignty, SNCF has a very particular take on the subject.

“At SNCF, we use a slightly different terminology,” Comtet told the audience. “We prefer to call it strategic autonomy, something more into action and less royalist.”

That framing shaped the entire keynote, delivered jointly by Comtet, Head of Container and Cloud Native Platforms at SNCF, and Yann Rotilio, Senior Staff Engineer and Kubernetes Specialist. Their message was clear: sovereignty for SNCF has never been about retreating behind the walls of a private data center. It is about assembling valuable, reliable, interchangeable, and non-toxic solutions into platforms where applications can be wisely hosted, whether in public clouds, private clouds, or at the edge.

From Cloud Migration to Cloud Maturity

SNCF’s cloud transformation story began in 2018 with the launch of a large-scale migration program. Eight years later, the results speak for themselves. Today, 70% of SNCF’s 2,000-plus applications run across public clouds, modernized through containers, serverless architectures, and managed services. The remaining 30% stay in SNCF’s own data centers, placed there through a systematic application classification process that determines which workloads are permitted to move to the public cloud and which must remain on-premises.

The technology mix tells its own story: roughly 45% of applications rely on fully managed cloud services, 30% are cloud-native workloads, and 25% run on virtual machines or bare metal. Comtet noted that even after eight years of running Kubernetes clusters, demand from internal teams continues to grow. “We’re now working with the late majority of our internal adopters,” he said, “and the demand is still skyrocketing.”

Kubernetes as the Control Plane

Kubernetes quickly became a central pillar of SNCF’s transformation. The company now operates more than 200 Kubernetes clusters across Azure and AWS, with Kubernetes powering roughly 30% of its application portfolio. But what SNCF learned along the way was more than just operational.

“Kubernetes is not just a container orchestrator,” the keynote abstract explains. “It is the control plane for modern application platforms.” SNCF discovered that Kubernetes performs best when it runs on infrastructure that is predictable, programmable, and fully under your control. Networking, storage, compute, and load balancing all need to be designed to serve Kubernetes rather than constrain it.

That insight became the guiding principle for SNCF’s private cloud strategy.

Why OpenStack

To bring public-cloud-grade capabilities to its on-premises workloads, SNCF needed an infrastructure layer that could deliver full automation and programmability beneath Kubernetes. In 2023, the team selected OpenStack.

The decision was deliberate. OpenStack provides the foundation that enables SNCF to deliver a cloud-native platform with public cloud parity while maintaining its sovereignty and governance requirements. It also serves a second, equally important purpose: providing straightforward VM-based infrastructure for workloads that do not need the complexity of a container orchestration platform. As the keynote abstract put it, “simple solutions for simple needs.”

The final slide of the presentation told that story visually, listing the full roster of OpenStack projects SNCF uses in production: Keystone, Nova, Glance, Neutron, Horizon, Cinder, Heat, Telemetry, Swift, Ironic, Trove, Kolla, Magnum, Sahara, Barbican, TripleO, and Zaqar. It is a comprehensive deployment by any measure.

From Draisine to TGV

One of the keynote’s most memorable moments came from Rotilio, who used a railway metaphor to describe how SNCF’s on-premises Kubernetes capabilities have evolved. When the team first created on-prem clusters six years ago, infrastructure options were limited. The result was operational and resilient, but it fell far short of being a practical alternative to managed public cloud services.

“We didn’t want a ‘Draisine,’” Rotilio said, referencing the hand-powered rail cart. “We needed a TGV.”  Train à Grande Vitesse is a high-speed train capable of reaching up to 320 km/h (200 mph).

The problem, he explained, was automation. So the team decided to rebuild everything from scratch, “purposefully assembling layer upon layer of modern open source foundations” to expand the platform’s capabilities. The keynote slides illustrated this transformation through a spider chart spanning five dimensions: app automation, control-plane management, node lifecycle, load balancing, and storage. The early platform barely registered on any axis. The rebuilt version, powered by what Rotilio described as “cloud native integration,” filled the chart almost completely.

That bedrock of open source projects includes not just OpenStack but also a wide array of Cloud Native Computing Foundation (CNCF) tools: Helm, KEDA, OPA, ORAS, and many others, all selected because they meet SNCF’s criteria of being valuable, reliable, interchangeable, and non-toxic.

Recognition on the KubeCon Stage

SNCF’s work did not go unnoticed by the broader community. At the same KubeCon event, the CNCF recognized SNCF with its 2026 Top End User Award for the company’s large-scale cloud migration and innovative private cloud strategy. The award citation highlighted how SNCF uses Kubernetes as a unified abstraction layer across public and private environments and specifically called out OpenStack’s role in providing public-cloud parity, full automation, and operational control.

It is the kind of validation that underscores a point the OpenInfra community has been making for years: OpenStack and Kubernetes are not competing technologies. They are complementary layers in a modern infrastructure stack, and organizations operating at scale are proving that every day. A combination we often refer to as the OpenInfra Blueprint, an open source infrastructure combination that has become a standard in the global market. 

What Comes Next

The overall result of SNCF’s journey, as the speakers described it, is a high-performance, open source platform where Kubernetes serves as the consistent abstraction layer across every environment, public and private alike. Applications can be modernized at scale while the organization retains full control of its infrastructure’s future.

For an operator responsible for the safety and mobility of millions of people every day, that combination of agility and control is what strategic autonomy actually looks like in practice. And for the open source community, SNCF’s story is a powerful reminder that the projects we build together run some of the most critical infrastructure on the planet.

  • Author
  • Recent Posts

Allison Price

Allison is the VP of Marketing & Community at the OpenInfra Foundation (previously the OpenStack Foundation). Her mission is to continue the storytelling of the global community by building relationships with the developers, operators and ecosystem around global open source communities. In her free time, she likes to listen to Celine Dion, rank local margaritas, and travel.

Allison Price