CNCF Sandbox 2028 Second-Credential Dossier¶
Target review: 2028. Evidence last verified: 2026-08-01. Status: not ready to submit.
CNCF Sandbox is a possible second foundation credential, considered only after Fgentic is accepted into LF AI & Data Sandbox and the foundations confirm that their asset-custody requirements are compatible. This dossier is not an active application, a dual-hosting promise, a forecast of acceptance, or authority to accept legal terms.
Fgentic is currently an independent project. The public repository was created on 2026-07-10, its documentation site is live, and it has published v0.1.0 and the latest release, v0.1.1. Its dated source snapshot records one maintainer and no named adopter. Those facts are maturity signals, not CNCF-published numeric eligibility thresholds.
The two strategic risks to resolve before a 2028 review are:
- sustained project maturity supported by externally verifiable use, contribution, and release evidence; and
- clear separation of the public project from paid Fmind services, so a reviewer can identify exactly what is public and what, if anything, a foundation would receive.
Sources and refresh rule¶
The source snapshot below was current when checked on 2026-08-01:
- Fgentic repository evidence snapshot, the exact
maincommit used for dated project facts; - CNCF Sandbox application form, last changed 2026-05-26;
- CNCF Sandbox process and review examples, last changed 2026-06-10;
- CNCF project lifecycle, last changed 2026-04-16;
- non-binding Sandbox Reviewer Guide, last changed 2025-09-06;
- General Technical Review questions, last changed 2026-04-25;
- CNCF Allowlist License Policy, last changed 2025-10-29;
- CNCF license-exception register, last changed 2026-06-04; and
- LF AI & Data project lifecycle, last changed 2026-01-29.
Immediately before any application:
- Refresh every source, form label, policy, exception, and repository fact.
- Confirm LF AI & Data status and obtain written guidance on foundation custody before treating CNCF as compatible.
- Replace repository links with immutable links to the exact submitted release or commit.
- Have the maintainer supply identity-bound contacts, confirm asset authority, and personally accept any current legal terms.
Published process versus project strategy¶
| Topic | Accurate treatment on 2026-08-01 |
|---|---|
| LF AI & Data acceptance first | Fgentic's current project strategy, not a CNCF requirement. |
| Project maturity | A real case-by-case review risk. CNCF calls Sandbox early and experimental, while its process gives a postponement example involving a project less than six months old; neither creates a fixed age, star, adopter, or maintainer threshold. |
| Product/service separation | A required form answer and an explicit reviewer concern. This is the second strategic risk. |
| Maintainer diversity | Useful sustainability evidence. The form requires a maintainers file, but the published sources set no “three maintainers from two employers” threshold. |
| Reference distribution | Not a categorical blocker in the pinned form, lifecycle, process, or reviewer guide. The application must make the independently reusable product boundary clear. |
| Named adopters and upstream relationships | Valuable maturity evidence, not published Sandbox minima. |
| License scope | Submission-time due diligence over the exact donated code, dependencies, and distribution model. The allowlist policy does not list MPL-2.0; existing exceptions are precedent, not automatic coverage for mautrix/go. |
| Trademark, accounts, signatory, and policy acceptance | Human and legal submission mechanics, not substitutes for product readiness. |
Copy-ready application answers¶
These headings reproduce the pinned form labels. Text marked HUMAN is deliberately not accepted on the maintainer's behalf.
Basic project information¶
Project summary¶
Fgentic is reusable, Kubernetes-native software for governed human-to-agent and cross-organization agent collaboration over Matrix and A2A.
Project description¶
The product is the Matrix-to-A2A bridge and its standalone Helm chart. The Go Matrix Application Service converts an explicit agent mention into an A2A request, preserves room and sender attribution, applies bounded routing and admission controls, and returns the result as a non-authoritative Matrix notice. An adopter can install the bridge into a compatible homeserver without adopting Fgentic's full platform.
The same public repository includes policy modules, conformance evidence, and a full Kubernetes reference distribution that proves the bridge in context. Fgentic does not replace an agent framework, gateway, model server, identity provider, observability system, or Matrix distribution. It composes open protocols and independently maintained projects while owning the collaboration, trust, packaging, and federation seam. See Architecture & Vision, Open Agentic Stack, and the Bridge Specification.
Project details¶
Org repo URL (provide if all repos under the org are in scope of the application)¶
N/A. The application would cover one repository, not every repository in the fmind-ai organization.
Project repo URL in scope of application¶
https://github.com/fmind-ai/fgentic
The whole public repository would be available for technical review because it contains both the reusable product and its reference distribution. That does not predetermine the legal contribution scope: immediately before application, the maintainer must inventory the exact Fgentic-owned code, trademarks, accounts, and other assets proposed for contribution. Independently distributed upstream components are not Fgentic assets.
Additional repos in scope of the application¶
N/A.
Website URL¶
https://fmind-ai.github.io/fgentic/
Roadmap¶
https://github.com/fmind-ai/fgentic/milestones
Roadmap context¶
GitHub milestones are the executable release ladder; docs/roadmap.md preserves dated history rather than creating a second plan. Work is publicly discussed in issues and linked to acceptance criteria. Fgentic remains pre-1.0 under the stability contract.
Contributing guide¶
https://github.com/fmind-ai/fgentic/blob/main/CONTRIBUTING.md
Code of Conduct (CoC)¶
https://github.com/fmind-ai/fgentic/blob/main/CODE_OF_CONDUCT.md
Adopters¶
https://github.com/fmind-ai/fgentic/blob/main/ADOPTERS.md
As of 2026-08-01, the file has no named entry. CNCF publishes no adopter minimum for Sandbox; externally verifiable use remains important maturity evidence.
Maintainers file¶
https://github.com/fmind-ai/fgentic/blob/main/MAINTAINERS.md
As of 2026-08-01, the file lists one maintainer from Fmind. The pinned CNCF form requires a maintainers file but publishes no maintainer-count or employer-diversity threshold. Fgentic nevertheless treats broader, sustained maintainership as a sustainability goal under GOVERNANCE.md.
Security policy file¶
https://github.com/fmind-ai/fgentic/blob/main/SECURITY.md
The policy provides private reporting, response targets, supported-version scope, and links to the project's security evidence. It is not an independent audit or a CNCF security review.
Standard or specification?¶
N/A. Fgentic implements Matrix, A2A, MCP, Kubernetes, Gateway API, and OIDC surfaces; its topic specifications document project behavior and do not claim standards authority.
Business product or service to project separation¶
HUMAN — confirm immediately before application. The public project record on 2026-08-01 exposes the Fgentic code and packaging in this repository under Apache-2.0 and discloses no enterprise edition, private Fgentic source repository, or Fgentic SaaS product. The declared service model allows Fmind to sell deployment, integration, operation, and support; the intended boundary is that those services unlock no separate project capabilities. The maintainer must verify that the public record remains complete and that no non-public product changes this answer before copying it.
The reusable product is the Matrix-to-A2A bridge and standalone chart; the full platform is a public reference distribution that proves those artifacts in context. Third-party components remain governed and distributed by their upstream projects and would not be proposed as Fgentic assets.
Cloud native context¶
Why CNCF?¶
Fgentic first seeks LF AI & Data Sandbox acceptance as the foundation path aligned with agent infrastructure. In 2028, after sustained external use and contribution evidence exists, CNCF could provide a complementary cloud-native review surface around the bridge's Kubernetes packaging and integrations. Any review first confirms that the then-current LF AI & Data custody is compatible; it makes no dual-hosting assumption.
The technical case would center on Fgentic's reusable bridge, chart, policy modules, and conformance evidence—not ownership of upstream projects or endorsement of the reference distribution. The submission-day asset inventory would define the legal contribution scope separately.
Benefit to the landscape¶
Fgentic adds a reusable Matrix-to-A2A application-service boundary for governed, federated human-agent collaboration: explicit agent routing, sender and room attribution, bounded task lifecycle, signed remote-agent identity, and admission controls. Its differentiator is cross-organization collaboration without anchoring every participant to one SaaS tenant.
Cloud native 'fit'¶
Fgentic is containerized, declaratively packaged, and Kubernetes-native. Flux reconciles Helm and Kustomize resources; Gateway API defines routes; SOPS protects GitOps secrets; and NetworkPolicy, workload identity, immutable image digests, metrics, and offline render validation are deployment contracts. The bridge remains independently installable through its standalone chart.
Cloud native 'integration'¶
Kubernetes runs the workloads; kagent hosts compatible local agents; agentgateway governs agent, model, and tool traffic; Flux reconciles delivery; cert-manager and Gateway API provide certificate and routing primitives; CloudNativePG provides scoped state; and Prometheus and OpenTelemetry carry operational signals. Matrix, A2A, MCP, and OIDC remain open protocol boundaries. See Open Agentic Stack for ownership and claim limits.
Cloud native overlap¶
Fgentic does not replace an agent runtime, gateway, model server, GitOps controller, database, observability system, identity provider, or Matrix homeserver. It owns the Matrix-to-A2A collaboration boundary, cross-organization trust controls, standalone packaging, and conformance evidence.
The larger deployment in this repository is a reference distribution and acceptance surface for that reusable software. The pinned CNCF application, lifecycle, process, and reviewer guidance contain no categorical exclusion for a repository that also carries a reference deployment; this product boundary is evidence for reviewers, not a guarantee of eligibility.
Similar projects¶
The dated Competitive Landscape compares the closest collaboration products and open-source alternatives. kagent and agentgateway are complementary building blocks rather than substitutes: Fgentic supplies the human collaboration and federation boundary around compatible agents and gateways. Refresh the comparison immediately before application.
Landscape¶
No. A 2026-08-01 search of the Cloud Native Landscape source found no Fgentic entry. Issue #66 tracks the separate listing path.
Insights¶
No Fgentic project entry was identified in LFX Insights on 2026-08-01. Recheck by repository URL immediately before application.
CNCF policies¶
Trademark and accounts¶
HUMAN — unchecked. Inventory every trademark, domain, account, package, and repository in scope; confirm current custody and transfer authority; then review and personally accept the live policy if an application proceeds.
IP policy¶
HUMAN — unchecked. The maintainer and proposed signatory must review the live CNCF IP Policy and contribution terms. This dossier accepts neither.
Will the project require a license exception?¶
Fgentic project code is Apache-2.0. The bridge snapshot retrieves maunium.net/go/mautrix v0.29.0 under MPL-2.0 as a Go build dependency. MPL-2.0 is not on the general allowlist, the exception register contains precedents, and no package-specific exception for mautrix/go is claimed. If that dependency remains in the submitted scope, the applicant will request CNCF's current determination and any required exception.
Reference manifests also point to unmodified AGPL-licensed images in upstream registries. Fgentic does not vendor, rebuild, mirror, redistribute, or link those images into its binaries, and would not propose them as donated Fgentic code. Their treatment must be confirmed against the exact submitted scope rather than pre-classified as requiring an exception merely because the reference distribution can retrieve them. See Licensing & Foundation Strategy §10 and NOTICE.
Project "Domain Technical Review"¶
No. As of 2026-08-01, Fgentic has not completed a CNCF technical review or received CNCF endorsement. The current Sandbox process makes TAG technical input optional. Prepare current Day-0 answers near application time rather than preserving a volatile review transcript for 2028.
Contact information¶
Application contact email(s)¶
fgentic@fmind.ai
HUMAN: confirm that this public project address is monitored and appropriate before submission. Add individual addresses only with their approval.
Contributing or sponsoring entity signatory information¶
HUMAN — do not infer or publish private identity data. The contributing party must provide the exact identity, address, entity type, authority, title, and contact data required by the live form.
Additional information¶
CNCF contacts¶
None is recorded in the public project record as of 2026-08-01. Do not name a CNCF or TAG participant without consent and direct familiarity with the project.
Additional information¶
Fgentic should be evaluated as experimental, not production-proven. Its public evidence includes two pre-1.0 releases, source and integration tests, signed artifacts, a federation lab, and documented security limits. The public record has no named adopter, published independent security audit, or completed foundation review. The project seeks a foundation relationship only for the reusable software and governance it owns; upstream Matrix, kagent, agentgateway, and other components remain outside that scope.
2028 readiness decision¶
| Strategic gate | State on 2026-08-01 | Evidence required for the 2028 review |
|---|---|---|
| LF AI & Data accepted first | Not accepted | Accepted proposal and executed hosting/custody record. |
| Sustained maturity | Too early to assess | Multi-release history plus externally verifiable use and contribution evidence; no invented numeric CNCF threshold. |
| Public project/service separation | Documented, unreviewed | Independently verified inventory of the exact Fgentic-owned contribution scope and every paid Fmind service or capability. |
Even if all three rows are satisfied, submission remains discretionary. The review can conclude that CNCF adds insufficient value, foundation custody is incompatible, the process changed, or the project is still not ready.
Submission-day human checks remain separate:
- Confirm current foundation custody and obtain any necessary coordination or consent.
- Review current IP, trademark, contribution, and account-transfer terms.
- Confirm contacts, signatory authority, and private identity data.
- Pin the exact release, commit, repositories, assets, and dependency inventory in scope.
- Refresh the form, technical questions, Landscape and LFX state, project facts, and licensing determination.
- Record any application, custody determination, and outcome in #464.