Open Source at Thales: Securing the Edge


Apr 20 2026

illustrationHD.avif

Thales has been steadily building its Open Source presence over the past years, evolving from a consumer of open technologies to an active contributor recognized across major foundations includingthe CNCF, the Linux Foundation, and the Eclipse Foundation.

Backed by a dedicated Open Source Program Office and a passionate engineering community, Thales engineers now contribute to landmark projects such as Kubernetes and the Linux kernel. All contributions and publications are visible on our GitHub organization: https://github.com/thalesgroup .

OW2Con 2026 is the perfect stage to highlight one of the most concrete results of this journey: a production-grade, Open Source security building block born from real operational constraints.

How Thales Encrypts Kubernetes Secrets with Hardware Roots of Trust?

At our booth, we will be demonstrating k8s-kms-plugin, a lightweight Go service developed by ThalescortAIx Labs & Thales Cyber Security Products that solves a critical yet often overlooked problem: bydefault, Kubernetes stores its secrets in cleartext in the ETCD database.

k8s-kms-plugin bridges Kubernetes' KMS v2 encryption API with local hardware roots of trust like TPM 2.0 chips or USB HSMs such as the Thales SafeNet eToken Fusion, Luna General Purpose HSMs or Yubico YubiHSM2 through the PKCS#11 standard interface. The result is strong data-at-rest encryption with a minimal footprint, no dependency on a remote KMS appliance, and full support for key rotation.
And we are already working on PKCS #11 v3.2 open implementation for Post Quantum Cryptography support.

Join us to see a live encryption and emergency data wipe scenario running on an edge k3s cluster!