Disclosure up front: I work for croit, which sells Ceph and appears in the tables below. I have tried to be as critical about us as about everyone else. Every number comes from the public git history, Ceph’s own in-tree records, or a named public statement — all reproducible, all listed in the references at the end.

Ceph holds up a lot of kit that nobody thinks about. Proxmox clusters, OpenStack, Kubernetes, national research labs, banks, telcos, particle accelerators. Twenty years on, it is still the first answer when somebody wants block, file and object storage out of one cluster built from ordinary hardware.

So who writes it, who maintains it, and who runs it?

Not “who is on the mailing list” or “who spoke at Cephalocon”. I cloned ceph/ceph, took every non-merge commit authored in the ten years to 2026-08-27, and mapped the authors onto companies using Ceph’s own .organizationmap plus a documented set of corrections. Then I took Ceph’s in-tree governance file and traced all 38 Steering Committee members to the employer in their own published address. Then I went looking for who says publicly that they run it.

That comes to 69,613 commits from 1,718 people across 478 organisations. It is a better picture than I expected going in, and not the one I set out to write.

The Decade

RankOrganisationCommitsShare
1Red Hat42,35460.8%
2SUSE6,1918.9%
3IBM4,3086.2%
4Intel2,0663.0%
5ZTE1,1761.7%
6QiAnXin9001.3%
7Ceph Foundation6911.0%
8Mirantis5660.8%
9IONOS4980.7%
10China Mobile3970.6%
11Proxmox2540.4%
12croit2420.3%
13Cloudbase Solutions2390.3%
14Bloomberg2310.3%
15XSKY2250.3%
—Clyso 181, Huawei 159, Inspur 155, Cafe Bazaar 130, CERN 121, SK Telecom 120, UMCloud 106, Deutsche Telekom 105, EasyStack 103, ISCAS 99, Tencent 83, and 460 more organisations
—No employer visible in the address6,2959.0%

Rows 1 and 3 are the same team. On 4 October 2022 Red Hat and IBM announced that Red Hat’s entire Ceph team was moving to IBM, with IBM taking over Red Hat’s Foundation sponsorship and helping fund the upstream test lab. The people did not change; their email addresses are still migrating, one engineer at a time, four years later.

Add them: 46,662 commits. 67.0% of the decade.

Sit with that before anything else, because it is the deal that makes Ceph exist. One company has paid dozens of engineers to build and look after distributed storage it then gives away. Ten years of it, through two takeovers and a change of parent. Nobody made them do it.

The Last Three Years

RankOrganisationCommitsShare
1Red Hat7,27345.0%
2IBM3,81823.6%
3QiAnXin5973.7%
4Ceph Foundation5263.3%
5IONOS4983.1%
6Intel2791.7%
7Proxmox2491.5%
8Bloomberg2201.4%
9croit1571.0%
10Clyso1530.9%
11Cafe Bazaar1180.7%
12ISCAS (Institute of Software, Chinese Academy of Sciences)990.6%
—No employer visible in the address2,00812.4%

16,160 commits. Red Hat plus IBM: 11,091, or 68.6%.

One company's share of Ceph, over a decade and over three yearsThe share does not move. What is inside it does.Ten years to 2026-08-2769,613 commitsRed Hat  60.8%IBM 6.2%SUSE 8.9%everyone else  24.1%Red Hat + IBM: 46,662 commits, 67.0%Last three years16,160 commitsRed Hat  45.0%IBM  23.6%SUSE: 13everyone else  31.4%Red Hat + IBM: 11,091 commits, 68.6%SUSE was the second-largest contributor of the decade. In the last three years it wrote13 commits, and in 2025 and 2026 none at all.
The one-company share barely moves between the decade and the recent window — 67.0% against 68.6%. What changes is everything around it.

The Resilience Nobody Talks About

Here is the bit I did not expect, and it is the best thing in the whole exercise.

Ceph has already survived the two events this data would tell you to fear, and it did not flinch.

Its creator, Sage Weil, wrote 7,517 commits over the decade — more than any organisation except Red Hat, SUSE and IBM. In 2017 alone he wrote 2,184 commits, 21.5% of the entire project by himself. He stepped back in October 2021 after 17 years; his last commit is dated 2022-01-20.

Its second-largest contributor of the decade, SUSE, wrote 6,191 commits and peaked at 1,839 in one year. Then it cancelled SUSE Enterprise Storage for Rancher’s Longhorn and wound down: 463 in 2021, 110 in 2022, 14 in 2023, 10 in 2024, nothing since.

Both inside the same five years. If a project this concentrated were brittle, that is when it would have snapped.

It did not. The commit rate this year is 14.6 a day against 14.8 last year. Flat. Releases kept coming. The governance was rebuilt into an Executive Council and a 38-person Steering Committee, and it held.

YearTotal commitsRed Hat + IBMShareEveryone else
201610,2865,83456.7%4,452
201710,1586,94268.3%3,216
20188,0995,26565.0%2,834
20199,0005,93465.9%3,066
20208,3615,23062.5%3,131
20217,3814,51761.1%2,864
20224,7312,93762.0%1,794
20234,6343,31571.5%1,319
20245,4103,57166.0%1,839
20255,3893,73069.2%1,659
20263,4952,32966.6%1,166

(2026 runs to 27 August, about eight months.)

Between 57 and 72 per cent from one vendor, every year for a decade. Volume is down on the 2016 peak, which is what happens when a project stops rebuilding its foundations and starts looking after them. The last three years are flat, or a shade up.

Ceph commit volume by year — the share holds, the total halvesCommits per year, and who wrote themCeph main branch, non-merge commits, by author date03k6k9k12k201657%201768%201865%201966%202063%202161%202262%202372%202466%202569%2026*67%Red Hat + IBM — one team since October 2022everyone elseSUSE peaks: 1,839Sage Weil leavesSUSE: 110 in 2022, 14 in 2023, 0 by 2026* 2026 runs to 27 August; plotted at its current daily rate of 14.6 commits, against 14.8 for 2025.
Commit volume by year, split between the Red Hat/IBM team and everyone else. Marked: SUSE’s peak and exit, and Sage Weil’s departure. Ceph absorbed both without a change in cadence.

Ceph Outlived the Companies That Built It

This is the decade’s real story, and you cannot see it in a three-year window at all.

Look at rows 2, 5, 8, 10, 13 and 15. SUSE, ZTE, Mirantis, China Mobile, Cloudbase Solutions, XSKY — plus Inspur, EasyStack, UMCloud, Kylin, UnitedStack, Xtao, Istuary and more further down. Between them, well over 10,000 commits. Nearly all of it has stopped.

  • SUSE: 6,191 commits, peaked 2020, now zero.
  • ZTE: 1,176 commits, 1,071 in 2016 alone, last commit 2020.
  • Mirantis: 566 commits, gone.
  • XSKY, EasyStack, Inspur, UMCloud, Kylin, UnitedStack: the OpenStack-era storage cohort, all wound down.

Every one of those was a company betting a product on Ceph. The products got cancelled or pivoted. And Ceph is still here, shipping at the same rate, with their code still in the tree and somebody else looking after it.

The best illustration is the dashboard. Over the decade, src/pybind/mgr/dashboard looks like this:

src/pybind/mgr/dashboard, ten yearsCommitsShare
SUSE1,40836.6%
Red Hat1,17730.6%
IBM73419.1%
No employer visible47812.4%

The Ceph dashboard was mostly SUSE’s work. SUSE then left the project entirely. In the last three years the same directory is 57.5% IBM and 30.3% Red Hat, and the dashboard is still shipping and still gaining features.

That is upstream-first development doing the exact job it is for. A vendor put a lot in, the vendor left, and the users kept the software. Had SUSE built that dashboard as a closed layer bolted on top, the way plenty of storage vendors would have, it would have died with the product line. It went upstream instead, so it lived.

The Next Decade Is Being Built by Several Companies at Once

Crimson is the ground-up rewrite of the OSD — the daemon that owns your disks — on the Seastar framework, aimed at the thread-per-core model modern NVMe demands. It is the biggest bet on Ceph’s next ten years. Over the decade:

src/crimson, ten yearsCommitsShare
Red Hat3,03852.1%
Intel1,26921.8%
QiAnXin82414.1%
No employer visible4507.7%

And over the last three years, Red Hat and IBM together are a minority of it at 45.4%, with QiAnXin on 28.4% and Intel on 13.4%.

The most important thing being built in Ceph right now really is a multi-company job. Not one vendor’s roadmap with a few contributors bolted on — three outfits doing heavy engineering on the same subsystem, in public, for years.

QiAnXin deserves a note, because it is not a name most storage people know. It is a Chinese enterprise cybersecurity company, founded as a Qihoo 360 subsidiary in 2014 and spun out around 2016; Qihoo 360 sold its remaining 22.6% stake to firms affiliated with China Electronics Corporation in April 2019, and CEC held 38.3% by the 2020 IPO filing. The corporate history is legible in the git log: their lead contributor, Xuehan Xu, has commits under @360.cn in 2017 and 2018 and @qianxin.com from 2021. A security company with no storage product to sell has put 900 commits into Ceph’s future OSD. That is an open project working the way it says on the tin.

Who Maintains Ceph, and Who Pays Them

Writing code is one thing; holding the keys is another. Ceph keeps its governance in the repository, in doc/governance.rst, and the Ceph Steering Committee is listed there by name and email. That makes the maintainer-to-employer question answerable from a primary source instead of guesswork.

Thirty-eight seats, traced to the employer in each member’s own listed address:

EmployerSeats
Red Hat16
IBM9
Clyso3
Personal address (Anthony D’Atri, Myoungwon Oh)2
croit — Igor Fedotov1
Bloomberg — Joseph Mundackal1
Intel — Yingxin Cheng1
Ceph Foundation — Zac Dover1
XSKY — Haomai Wang1
ZTE — Xie Xingguo1
Ubiquiti — Yehuda Sadeh1
11:11 Systems — David Orman1

Red Hat and IBM hold 25 of 38 seats — 65.8%. Against 67.0% of the decade’s commits and 68.6% of the last three years’. The governance body mirrors the code almost exactly, which is the healthy way round: the people doing the work have the say, and as such nobody holds a veto they have not earned.

Ceph Steering Committee seats by employer — 25 of 38 are one companyWho maintains Ceph, by who pays them38 seats on the Ceph Steering Committee, from the address each member lists in doc/governance.rstRed HatIBMClysopersonal addressone seat each169328croit, Bloomberg, Intel, Ceph Foundation, XSKY, ZTE, Ubiquiti, 11:11 SystemsRed Hat + IBM: 25 of 38 seats, 65.8%Against 67.0% of the decade's commits and 68.6% of the last three years'.The committee mirrors the code.XSKY and ZTE still hold seats. Neither company has committed a line to Ceph since 2020.Five of the 38 have no commit since 2021, or none at all. Steering is not the same job as writing code —but two of those seats belong to companies that have left the project entirely.
The 38 Ceph Steering Committee seats by the employer in each member’s listed address, from doc/governance.rst. The committee’s composition tracks the commit distribution closely.

Two details are worth pulling out, and both say something good.

XSKY and ZTE still hold seats. Neither company has committed a line since 2020 — Haomai Wang’s last commit is 2020-03-18, Xie Xingguo’s 2020-07-24 after 750 commits in the decade. Ceph has not turfed them out. A project that keeps a seat warm for the people who built large parts of BlueStore and the OSD, years after their employer walked off, is not one that treats contributors as disposable.

Yehuda Sadeh sits on the committee with an @ui.com address. He wrote RADOS Gateway — the S3 and Swift front door onto RADOS, the Reliable Autonomic Distributed Object Store that everything else in Ceph sits on — starting at DreamHost in 2008, through Inktank, Red Hat and IBM: 972 commits in the decade alone and thousands before it. He was still writing cephx crypto code in July 2025. Then in June 2026 he made exactly one commit, doc: governance/csc: update email address, changing his own entry to Ubiquiti. He changed employer and kept his seat. Your standing travels with you here, and that is one of the better things about working in the open.

The Component Leads

The component leads own each subsystem day to day:

ComponentWhat it isLeadEmployer
CephadmCluster deployment and managementAdam KingRed Hat
CephFSThe POSIX file systemVenky ShankarRed Hat
CrimsonThe next-generation OSDMatan BreizmanRed Hat
DashboardThe web management interfaceAfreen MisbahIBM
RADOSThe object store everything else sits onRadosław ZarzyńskiRed Hat
RBDRADOS Block Device — virtual disksIlya DryomovRed Hat
RGWRADOS Gateway — the S3 and Swift layerAdam Emerson, Eric IvancichRed Hat
NVMe-oFNVMe over Fabrics gatewayAviv CaroIBM
SeastoreCrimson’s storage backendYingxin ChengIntel

Ten named leads, nine at Red Hat or IBM, and Seastore — Crimson’s storage backend — led from Intel. Above them sits the three-person Executive Council created when Sage Weil left: Dan van der Ster (Clyso), Neha Ojha (Red Hat), Patrick Donnelly (IBM). Clyso holds a third of the top governance body on 0.3% of the decade’s commits — the council was built around judgement and standing, not headcount.

The Maintainers Moved, and the Code Stayed

The strongest argument for Ceph being a real commons rather than one company’s product is what happens when its maintainers change jobs. Every one of these is traceable through addresses in the repository:

Maintainer (current employer)Career, per the git logLast commit
Igor Fedotov (croit) — BlueStoreMirantis (2015–17) → SUSE (2017–24) → croit (2021–)2026-08-24
Kefu Chai (Proxmox) — core, buildRed Hat (2015–22, 4,770 commits) → XSKY → Proxmox (2025–)2026-08-18
Radosław Zarzyński (Red Hat) — RADOS leadMirantis (2015–17) → Red Hat (2017–)2026-06-16
Dan van der Ster (Clyso) — Executive CouncilCERN (2013–22) → Clyso (2023–)2026-03-18
Zac Dover (Ceph Foundation) — documentationindependent → Clyso → Ceph Foundation2026-07-23
Yehuda Sadeh (Ubiquiti) — RGW authorDreamHost → Inktank → Red Hat → IBM → Ubiquiti2026-06-08
Mark Nelson (Clyso) — performanceDreamHost → Inktank → Red Hat → Clyso2024-04-16
Xuehan Xu (QiAnXin) — CrimsonQihoo 360 (2017–18) → QiAnXin (2021–)2026

Three employers each, four in some cases, and the work carried on through every move. Igor Fedotov has now outlived two of his employers’ Ceph strategies and still maintains the engine that puts your bytes on disk. So the honest answer to “what if a vendor leaves” is this: the engineers keep going.

Who Actually Runs Ceph

Contributions are only half of it. Here is who says out loud that they run Ceph, with the numbers they published themselves.

OrganisationPublicly stated deployment
CERN, the European Organization for Nuclear Research19 production clusters, ~73 PB raw, plus 5 more in a new datacentre — the storage backbone under CERN’s IT cloud
BloombergObject stores from hundreds of TB to over 8 PB; added 6 PB of raw capacity live, a 50% increase to an online cluster, in under an hour
Wikimedia FoundationFive production Ceph clusters — block for Cloud VPS, S3 via multisite RGW, and CephFS for Airflow, Dumps and ML-Lab
DigitalOceanCeph powers its Block Storage service via RBD, with “hundreds of enterprise-class SSDs” per region and 3× replication across servers and racks
OVHcloud“Persistent storage for virtual machines is ensured by Ceph RADOS Block Device” in its On-Prem Cloud Platform
ProxmoxShips Ceph as the built-in hyperconverged storage option in Proxmox VE

CERN is worth a closer look, because it is the most detailed public account anybody has published. From a September 2024 CERN IT talk by Enrico Bocchi:

CERN Ceph, by applicationRaw sizeClusters
Blocks — OpenStack Cinder/Glance, HDD 3× replica25.1 PB5
Blocks — Flash, EC 4+2976 TB2
File system — OpenStack Manila, K8s/OKD, HPC, HDD 3× replica13.4 PB5
File system — Flash, 3× replica1.7 PB4
Objects — S3, Swift, Backups, HDD EC 4+228.2 PB2
Objects — multi-site, EC 4+23.6 PB1

EC 4+2 is erasure coding, four data chunks to two parity. HPC is high-performance computing, K8s is Kubernetes and OKD is its upstream distribution. The figures are raw capacity, before replication and coding overhead.

Nineteen production clusters, run on the stated principle “don’t put all your eggs in the same basket”, with five more going into a new datacentre. The service history is a quiet advert for the software: 300 TB proof of concept in 2013, 3 PB in production for RBD by the December, 3 PB to 6 PB expanded with no downtime in 2016, S3 and CephFS in production in 2018, an entire CephFS cluster physically relocated with no downtime in 2022, kernel RBD in production in 2023.

What it carries at CERN is the telling part: GitLab, OpenStack, OpenShift, Kubernetes, Harbor, Jenkins, Grafana, Kafka, OpenSearch, InfluxDB, HTCondor, Slurm, Jupyter, Spark, Zenodo, Indico, and the virtualisation of NFS, AFS and CVMFS. Ceph is not a side experiment there. It is the floor the rest of the building stands on.

And the community-wide figure, from the Linux Foundation’s own Squid release announcement: 1 exabyte of data across more than 3,000 Ceph clusters.

That Exabyte Is a Floor, Not a Total

This is the part worth stopping on, because it changes how you read every adoption number about Ceph.

Ceph’s telemetry is opt-in. You only get counted if somebody runs ceph telemetry on --license sharing-1-0. Everybody who never ran it is invisible, and in practice that is most people, because it is not the default and nothing nags you about it.

Now add Proxmox. Proxmox VE ships Ceph as its hyperconverged storage option: three nodes, a few clicks in the web UI, pveceph under the hood, and you have a Ceph cluster. A very large number of people are running Ceph in production without ever thinking of themselves as Ceph users at all. They are Proxmox users. They never joined a mailing list, they will never write a testimonial, they have not turned telemetry on, and they appear in none of the tables above.

Every small hosting company, managed service provider, university department, homelab that quietly went into production and three-node office cluster in that bracket is a real Ceph deployment that no figure in this post counts. Same goes for anybody getting Ceph through Rook on Kubernetes, or inside a vendor appliance that never says what is under the lid.

So 1 EB across 3,000 clusters is the number from the clusters that put their hand up. The real installed base is a good deal bigger and nobody knows by how much. That is an odd spot for infrastructure software to be in — normally the vendor knows, because you had to buy a licence — and it is a direct result of the thing being free.

478 Organisations Have Put Code In

The commit log doubles as a roster of who runs Ceph at scale, because a company that sends patches is nearly always a company running the thing. Over the decade 478 distinct organisational email domains turn up, 140 of them with five commits or more.

The names, grouped, from the git log alone:

  • Chip, disk and hardware makers: Intel, Samsung, Seagate, SanDisk, Western Digital, Quantum, Mellanox, Lenovo, Fujitsu, Hitachi, Nokia, Arm, Linaro, HiSilicon, Synology, 45Drives
  • Clouds and hosts: DigitalOcean, OVH, IONOS, Akamai, Linode, Hetzner, Binero, City Network, iland, 11:11 Systems, Vexxhost, StackHPC, Canonical, Deutsche Telekom, China Telecom, China Unicom, China Mobile, Chunghwa Telecom
  • Internet and enterprise users: Bloomberg, eBay, GoDaddy, Flipkart, Wikimedia, Naver, LINE, Kakao, SK Telecom, Alibaba, Tencent, Baidu, ByteDance, Kuaishou, UnionPay, SenseTime, Sangfor, Micro Focus, MITRE, Igalia, Walmart Labs
  • Storage vendors and integrators: SUSE, Mirantis, XSKY, EasyStack, Inspur, UMCloud, Kylin, UnitedStack, H3C, Xtao, Eisoo, Cloudin, Istuary, ProphetStor, SoftIron, Bigtera, Cloudbase Solutions, Digiware, Bisect, 42on, croit, Clyso, Proxmox, DreamHost
  • Research and education: CERN, the Institute of Software at the Chinese Academy of Sciences (ISCAS), Pennsylvania State University, Boston University, the University of Michigan, Carnegie Mellon University, plus the Foundation’s Associate members — FAS Research Computing at Harvard, the Greek Research and Technology Network (GRNET), Monash University, the South African Radio Astronomy Observatory (SARAO), the Science and Technology Facilities Council (STFC), SWITCH, SLAC at Stanford, and the Center for Research in Open Source Software (CROSS) at UC Santa Cruz

Not all of those are current, and that is the point of looking at a decade. It shows the full span of who has leaned on this software hard enough to send patches back, and how wide that spread has been.

The Players Who Say They Back Ceph, Against What They Ship

The Foundation’s tiered membership is where companies declare support. The tiers do not track engineering, and the clearest illustration comes from the three Diamond members quoted in the Linux Foundation’s own Ceph Squid release announcement.

Diamond memberWhat they said publiclyCommits, last 3 years
IBM — Vincent Hsu, IBM Fellow, CTO & VP of IBM Storage“reinforce our trust in Ceph and our commitment to open source”11,091 (with Red Hat)
Bloomberg — Matthew Leonard, Head of Storage Engineering“Our Diamond Membership is a symbol of our commitment to the future of Ceph and its growing community”220
45Drives — Doug Milburn, Co-founder and President“our unwavering commitment to open-source excellence”0

IBM’s statement is backed by the largest engineering commitment in the project’s history, and then some. Bloomberg’s is backed by 220 commits, a Steering Committee seat, and an 8 PB production estate they talk about openly — a serious contribution by any measure. 45Drives builds and sells Ceph hardware appliances and funds the shared infrastructure; that is a genuine contribution too, and it is not code.

The full picture across the tiers:

MemberTierCommits, last 3 years
IBMDiamond11,091 (with Red Hat)
BloombergDiamond220
CLYSODiamond153
45DrivesDiamond0
Western DigitalPlatinum0
42onGold1
croitSilver157
DigitalOceanSilver13
CanonicalSilver9
OVHcloud, Sony, OSNexus, CloudFerroSilver0 each

And in the other direction — four of the top seven contributors are not members at all:

ContributorCommitsMember?
QiAnXin597No
IONOS498No
Intel279Not any more
Proxmox249No
Foundation tier against commits — the money and the code are unrelatedWhat they pay, against what they wroteCeph Foundation tier vs commits to main, 2023-08-27 to 2026-08-27200400600 commitsDIAMONDIBM, with Red Hat11,091Bloomberg220CLYSO15345Drivesnothing at allPLATINUMWestern Digitalnothing at allGOLD42on1SILVERcroit157DigitalOcean13Canonical9six other Silver membersnothing at all, all sixNOT MEMBERSQiAnXin597IONOS498Proxmox249Cafe Bazaar118The six Silver members with nothing: OVHcloud, Sony Interactive Entertainment, OSNexus,CloudFerro, Intelligent Systems, LongVan. Two of the four top-tier members wrote nothing. Thethird- and fifth-largest contributors to Ceph are not members at all.
Foundation tier against commits over the last three years. Sponsorship and engineering are different contributions — the tiers measure the first, not the second.

I do not read that as hypocrisy and I would rather nobody else did either. Foundation money pays for the upstream test lab, the continuous integration that gates every pull request, Cephalocon and the community staff — things Ceph could not do without, and things a hardware vendor shipping Ceph appliances is right to fund. Western Digital, DigitalOcean and OVHcloud all sell products that lean on Ceph, and they pay into the commons that keeps it going. That is a fair trade.

The practical takeaway is narrow: read the members page as a list of who funds the shared infrastructure, and the commit log for who writes the code. They are different questions with different answers, and both answers are useful.

The Founders, Eight Years On

The Foundation launched on 12 November 2018. The roster is on the record twice — the Linux Foundation announcement and the wire copy — and they agree exactly: thirteen Premier members, ten General, eight Associate.

Against the members page today: four of thirteen Premier members are still listed under their own name (Canonical, DigitalOcean, OVHcloud, Western Digital), five if you count IBM as Red Hat’s seat. Two of ten General members remain — croit and Intelligent Systems.

And all eight Associate members are still there. Their full names, as the founding announcement gives them:

  • Boston University Information Services and Technology
  • CERN — the European Organization for Nuclear Research
  • FAS Research Computing, Harvard University
  • The Greek Research and Technology Network (GRNET)
  • Monash University, Melbourne
  • The South African Radio Astronomy Observatory (SARAO)
  • The Science and Technology Facilities Council (STFC) at UK Research and Innovation (UKRI)
  • The Center for Research in Open Source Software (CROSS) at the University of California, Santa Cruz — where Ceph was written in the first place, as Sage Weil’s PhD work with Scott Brandt, Ethan Miller, Darrell Long and Carlos Maltzahn; the original 2006 paper is still hosted on ceph.io

Eight for eight, over eight years.

The paying members churned. The universities and research labs, who join at no cost, have stuck it out eight years without one of them leaving. Those are the people running Ceph at scale for science, and not one has walked.

The Quincy documentation still carries the member list as it stood around 2022, which gives the halfway point: twelve of the twenty-four commercial members in that snapshot have since gone, exactly half. Ceph’s cadence across that period did not change.

On croit, since it is my employer and one of the survivors. croit GmbH joined as a founding General member on day one and is still a member eight years later — a longer run than Intel, SUSE, ZTE, Arm or Samsung managed. It is also 0.3% of the decade’s commits. Sticking around is not the same as building, and I am not about to dress up longevity as contribution for the company that pays me.

The Manual Is One Person, and the Foundation Pays for Him

Row 7 of the decade table is “Ceph Foundation”, 691 commits. That is very nearly one man.

Zac Dover has 1,060 commits over the decade, almost entirely documentation. Over the last three years he is 28.4% of everything in doc/ — the single largest contributor, ahead of both Red Hat and IBM. His address history runs @gmail.com, then @clyso.com, then @proton.me, mapped in Ceph’s own records to the Ceph Foundation.

doc/, last three yearsCommitsShare
Ceph Foundation49928.4%
No employer visible38321.8%
Red Hat37921.5%
IBM33318.9%

doc/ is the one directory where the biggest single contributor is neither Red Hat nor IBM, and it shows. The Ceph manual is better than most infrastructure software this size manages. Paying for a technical writer who answers to no vendor is the smartest thing the Foundation does with the money.

Individuals Can Still Move the Needle

The top individuals of the decade, grouped by author name:

PersonDecade commitsEmployer(s)
Sage Weil7,517Red Hat — creator, left 2022
Kefu Chai5,538Red Hat → Proxmox
Casey Bodley2,472Red Hat
Patrick Donnelly2,330Red Hat → IBM
Jason Dillaman1,629Red Hat — left 2021
Radosław Zarzyński1,607Mirantis → Red Hat
Samuel Just1,415DreamHost → Inktank → Red Hat
John Mulligan1,300Red Hat
Yingxin Cheng1,202Intel
Zac Dover1,060Ceph Foundation
Yehuda Sadeh972Red Hat → IBM → Ubiquiti
Alfredo Deza930Red Hat — left 2019

Twenty-one people wrote half the decade’s commits; ninety-one wrote 80%. That is normal for a big C++ codebase, and it is also why individuals count for so much here.

The clearest proof the door is open: fifth place in the last three years is one engineer at IONOS. Max Kellermann has 498 commits since 2024 — more than Intel, Proxmox, Bloomberg, croit or Clyso managed as companies — across src/mds, src/common, src/mon, src/tools, src/librbd, src/mgr and src/rgw. He is 19.3% of all CephFS metadata work in the window, second only to Red Hat.

Nobody appointed him. He turned up and started fixing things, and three years on he is one of the busiest contributors to a project run by a Fortune 50 company. You can still walk into Ceph and matter.

Proxmox is the other side of the same coin: 249 commits in the last three years, 241 of them from Kefu Chai since 30 September 2025. Proxmox went from nothing to a top-ten Ceph contributor in eleven months by hiring one good engineer.

RGW: Where the Work Actually Is

If you want to know where Ceph’s engineering goes, the answer is object storage, and the reason is simple: RGW has the furthest to go before it matches the thing it competes with.

src/rgw is the largest functional subsystem in Ceph over the decade — 6,958 commits, ahead of Crimson’s 5,827, the OSD’s 4,499, the dashboard’s 3,848, BlueStore’s 2,560 and CephFS’s 2,546. It is four times the size of the block layer’s effort. In the last three years it took 1,705 commits, second only to Crimson, and Crimson is a greenfield rewrite. On shipping code, RGW is the biggest ongoing feature programme in the project.

Amazon’s S3 is a moving target with a huge API surface, and every year it grows features that customers then expect from anything calling itself S3-compatible. So RGW chases it. Count the last three years of RGW commit subjects by feature area and the shape of that chase is plain:

RGW work in the last 3 yearsCommits mentioning it
Multisite replication94
Accounts94
IAM — identity and access management72
Policy71
Bucket notifications69
STS (temporary credentials)67
Topics50
Roles47
Restore41
POSIX / filesystem gateway40
Server-side encryption (SSE)38
Multipart upload32
Lifecycle16
KMS — key management service12
S3 Select11
Checksums11
Cloud transition10
Versioning, CORS, object lock, bucket logging, tagging28 combined

(Keyword counts over 1,705 commit subjects, so a commit can appear in more than one row — the point is the distribution, not a precise total.)

That is not maintenance. That is identity accounts, roles and policies, session tokens, bucket notifications and topics, SSE-KMS, object lock, lifecycle rules, S3 Select, checksums, cloud tiering and multisite replication — the AWS feature list, being built out. Read the recent subjects and you find SigV4 signature-verification work, x-amz-content-sha256 handling, presigned URLs. Fiddly compatibility detail, the sort that only matters because somebody’s client library expects Amazon’s exact behaviour and will fall over without it.

It is also why RGW has the most mixed contributor list of the big subsystems. Over the decade Red Hat is 64.3% of it, but Bloomberg (8.6% in the recent window) and Cafe Bazaar (6.2%) are in there too — companies running large object stores in production, fixing the things that bite them.

If you are weighing Ceph up for S3 work, this is the number that should settle you. The gap to Amazon is why RGW gets more attention than anything else in the tree, and the largest single engineering effort in the project is pointed at closing it.

RBD: Stable Code, Not a Decline

src/librbd is Ceph’s block device — what Proxmox uses, what OpenStack Cinder uses, what most Kubernetes Container Storage Interface drivers use. If you run Ceph, you probably run RBD. Its commit graph looks like this:

RBD commits by year — a component settling into maintenanceCommits to src/librbd, by yearCeph's block device — what Proxmox, OpenStack Cinder and most Kubernetes CSI drivers use01002003004004312015477201625820172762018209201945520201652021852022492023742024452025192026Feature work substantially completeJason Dillaman wrote 281 of 2020's 455commits — persistent write-back cache andcrypto — then RBD settled intomaintenance.2026 runs to 27 August. This is not decline — it is a mature component being maintainedrather than rebuilt.
Commits to src/librbd by year. The heavy feature work finished around 2020 — Jason Dillaman wrote 281 of that year’s 455 commits, on the persistent write-back cache and crypto — and the component has since settled into maintenance.

159 commits in the last three years, about one a week, against 1,705 for RGW and 1,944 for Crimson.

That is what stable code looks like, and it is a feature. Block storage over RADOS is a solved problem. RBD has had snapshots, clones, layering, mirroring, encryption, live migration and a persistent cache for years, and there is nothing like the S3 API racing off ahead of it, because what a hypervisor wants from a block device has barely changed in a decade. The feature work is done. What is left is upkeep: bug fixes, keeping step with the kernel, the odd performance win.

Set it against RGW on purpose. RGW takes ten times the commits because it has ten times as far left to go. RBD has not, so it does not. A component that has stopped changing shape is not a component going to seed — and if librbd suddenly took 400 commits a year I would want to know what had gone wrong, because those are my virtual machine disks it is holding.

The one thing worth knowing is that it puts the expertise in very few heads. RBD is more or less Ilya Dryomov, who looks after both ends — upstream Ceph and the Linux kernel rbd driver. That is about the best setup going, and it is still one person deep. Which tells you who to ask, not whether to deploy.

Where the Work Sits

The same mapping across the tree, decade and recent window side by side:

AreaDecade leaderShareLast 3 years leaderIBM group, last 3y
src/mds — CephFS metadataRed Hat78.5%Red Hat 56.4%73.9%
src/osd — current OSDRed Hat69.7%Red Hat 56.9%84.0%
src/cephadm — deploymentRed Hat66.8%Red Hat 73.7%92.0%
src/rgw — S3Red Hat64.3%Red Hat 56.1%66.7%
src/librbd — blockRed Hat61.1%Red Hat 76.7%83.0%
src/crimson — next OSDRed Hat52.1%Red Hat 42.0%45.4%
doc/ — the manualRed Hat45.6%Ceph Foundation 28.4%40.5%
src/os/bluestore — engineRed Hat36.9%IBM 46.5%54.2%
src/pybind/mgr/dashboardSUSE 36.6%IBM 57.5%87.8%

Two things to read off this. Ownership: the closer to the parts a vendor sells — deployment tooling, the GUI — the more it is one company; the further out — the next-generation OSD, the storage engine, the manual — the more crowded, and that is where the room is if you want to contribute somewhere not already owned.

Volume: by total commits over the decade, the ranking is RGW 6,958, Crimson 5,827, the OSD 4,499, the dashboard 3,848, the monitors 2,896, BlueStore 2,560, CephFS 2,546, RBD 1,750, cephadm 1,685. Effort tracks distance-to-done, not deployment share. RGW is first because S3 parity is a long way off; RBD is near the bottom because block storage is finished.

BlueStore deserves its own line. It is the engine that writes your bytes to disk, and over the last three years the second-largest contributor after IBM is croit at 18.1% — Igor Fedotov, its principal maintainer, at a company of a few dozen people. My employer, so weigh me accordingly. The point stands whoever signs his cheque: a small company can employ the maintainer of one of the most safety-critical components in the stack, and the project is better for it.

Who Holds the Merge Button

I counted merges too — 7,893 in the last three years, attributed to whoever pressed the button:

OrganisationMergesShare
Red Hat3,89249.3%
IBM1,59720.2%
Ceph Foundation5246.6%
Proxmox2022.6%
Intel1361.7%
croit761.0%

69.5% of merges against 68.6% of commits. The gate and the work are the same shape. This is not one company writing the code and another controlling what lands, which is the failure mode actually worth worrying about in corporate open source. Ceph does not have it.

Where the Numbers Come From

All of it is reproducible. Ceph maintains its own contributor-to-organisation mapping in the repository — .organizationmap, alongside .mailmap, .peoplemap and .githubmap — and documents the command to use it.

git clone --filter=blob:none --no-checkout https://github.com/ceph/ceph.git
cd ceph
git show HEAD:.organizationmap > /tmp/orgmap

# Ceph's own documented method, over the last ten years
git log --no-merges --since=2016-08-27 --until=2026-08-27 --pretty='%aN <%aE>' \
  | git -c mailmap.file=/tmp/orgmap check-mailmap --stdin \
  | sort | uniq -c | sort -rn | head -30

# the maintainer-to-employer mapping, straight from the repo
git show HEAD:doc/governance.rst | sed -n '/^.. _csc:/,/^\.\. _ctl:/p' \
  | grep -oE '\* [^<]+<[^>]+>'

Run the first and you get a smaller IBM than mine, because the official map is out of date. It does not know aainscow@uk.ibm.com, bill_scales@uk.ibm.com, ylifshit@ibm.com, rkachach@ibm.com, leonid.usov@ibm.com or the li-*.ibm.com machine-generated hostnames. Using the project’s own tooling understates the concentration.

My corrections on top of the map:

  • Any address ending ibm.com — including uk.ibm.com, il.ibm.com, in.ibm.com, de.ibm.com and the li-*.ibm.com forms — is IBM.
  • redhat.com and inktank.com are Red Hat, shown separately from IBM but the same team since October 2022.
  • Seven personal addresses are attributed to employers where the repository itself proves it: sage@newdream.net (Red Hat), idryomov@gmail.com (listed as idryomov@redhat.com in Ceph’s own doc/governance.rst), max.kellermann@gmail.com (IONOS), xxhdx1985126@gmail.com (QiAnXin), yuvalif@yahoo.com (IBM), yingxincheng@gmail.com (Intel), shraddha.agrawal000@gmail.com (IBM).
  • Everything else keeps its domain. Personal addresses stay “no employer visible” rather than being guessed at.

Caveats I cannot fix. Commits are a rough unit — a careful 900-line refactor counts once, forty typo fixes count forty times, and nothing here is weighted. Email domains are imperfect: 9.0% of the decade shows no employer, and some of those people are certainly paid to write Ceph. Review is invisible in git — Ceph reviews in GitHub pull requests, not Reviewed-by: trailers, of which I found twelve in three years; the most important gate in the project leaves no trace in a clone. Figures are main only, so backports to stable branches are uncounted, which understates the maintenance work. And every adoption figure here is a floor, for the telemetry reason set out above.

Where a claim rests on a date I have used the author date; where it rests on somebody’s employer, an address they published themselves.

What I Take From This

Ceph is a corporate-funded project with a real community round the edges, and it has been that way its whole commercial life. That is not a dig. Somebody has to pay engineers to look after distributed storage at this scale, and for ten years somebody has.

I will not pretend Ceph is typical, because I checked. LWN’s statistics for Linux 6.15 record 2,068 developers from at least 195 employers with the largest single company, Intel, on 12.0% of changesets. Ceph is 1,718 people over a decade with one company on 67.0%. The kernel spreads its corporate dependence across dozens of firms. Ceph packs it into one. That is a real difference, and “everyone does this” would be a lazy way to wave it off.

But here is what ten years of data says about whether that matters, and it is a better answer than I went looking for:

Ceph is tough in the way that counts. It lost the man who wrote it, who was doing a fifth of the work. It lost SUSE, its second-largest contributor and the author of the dashboard. It lost ZTE, Mirantis, XSKY, EasyStack, Inspur and half the Foundation’s founding members. The commit rate today is within two per cent of last year’s. Twenty years of storage engineering sits in that tree under LGPL-2.1 or LGPL-3, and nobody can close it, relicense it or take it back.

The maintainers are portable. Fedotov has kept BlueStore going through three employers. Kefu Chai went from Red Hat to Proxmox and carried on. Sadeh wrote RGW at DreamHost and changed his committee address to Ubiquiti this June. When a company walks, its people often stay.

The door is properly open. One engineer at IONOS became the fifth-largest contributor in three years. Proxmox got into the top ten on one hire. A security firm with no storage product is building a fifth of the next-generation OSD. 478 organisations have sent patches. If you want in, there is nothing stopping you but the work.

The userbase is far bigger than anybody can measure. An exabyte across 3,000 clusters is what put its hand up through opt-in telemetry, and CERN on its own accounts for nineteen production clusters. Every Proxmox hyperconverged cluster, every Rook deployment, every vendor appliance with Ceph under the lid is real production use that no published figure counts. Software this widely and this quietly deployed does not just disappear.

Effort goes where the gap is, not where the users are. RGW is the biggest programme in the project — 6,958 commits over the decade — because catching Amazon on S3 is a long chase against a moving target. RBD sits near the bottom because block storage is done. A low commit count on a mature component is a finished job, not a warning, and reading those two numbers the wrong way round is the easiest mistake going with data like this. I made it myself on the first pass.

Judge suppliers on commits, not on tiers. The history is public and four lines of shell will show you who actually looks after the thing you are about to depend on. Closed storage does not offer you that at any price.

So if you are weighing Ceph up: the concentration is worth knowing when you are planning five years out, and it is no reason to hold back. A mature block layer. The project’s biggest engineering effort aimed squarely at S3 parity. A future OSD being built by three companies at once. A manual better than most. Governance that came through losing its founder. A decade of review done in the open, 478 organisations’ worth of work in the tree, and a licence whose worst case is a fork rather than a dead end. On the evidence of 69,613 commits, this project is in good health.

And count it yourself if you doubt me. The commands are up there, the data is public, and nowt in this post needs taking on trust — mine or anybody else’s.

References

Ceph project sources

Ceph Foundation and the Linux Foundation

Deployments

Companies

Comparison