Image Title

Search Results for North America 2018:

Jonathan Weinert, Bosch North America | InterBike 2018


 

(techno music) >> Hey, welcome back everybody, Jeff Frick here with theCUBE. We're in Reno, Nevada at the Reno Convention Center. It's InterBike 2018, I think it's like 20,000 people, haven't got the official count yet, but this is an amazing show, it's all about bicycles. We came because we want to learn more about eBikes, and really, this kind of last mile thing that's goin' on, mobility, and right at the center of the eBike revolution is a company that's been around forever, and that's Bosch, and we're happy to have Jonathan Weinert. He's a sales and marketing manager for the Bosch eBikes. Jonathan, great to see you. >> Great to see you, Jeff. >> So, I don't know if everybody knows, you guys power like half of all the eBikes that are out there. You guys are completely in bed with all these manufacturers with really, the industry leading system. >> Thank you, yes, the Bosch eBike system, you'll find it world wide on about 70 different bike brands throughout the world. Here in North America, we're on about 30 different brands, from Trek to Electra to Cannondale. And they power all types of bikes, so commuter bikes, cargo bikes, fat bikes, mountain bikes, any type of bike that you can think of can use the Bosch eBike system to amplify the rider's power and help you go further, higher, farther, less sweat or sweat it out, whatever you want. >> Right, it's like the magic power. >> Exactly, magic carpet ride. >> The main components are you got the drive unit, which is really the heart of the system. >> Yes. >> The battery obviously to provide the power, then the control unit that's up on top of the handlebars, so you can control it. >> Exactly. >> So we were talking before we turned the cameras on, of kind of the history, you guys have been at this for like nine years, I believe you said? >> Exactly, yeah, we invented this system nine years ago, it was a combination of technology from our automotive business. So an electric power steering motor, married with technology from our power tools business, the lithium iron battery pack. And we also had some sensors, torque sensors and electronics and we put these technologies together, and the engineers back then, what they wanted to do is create something to make cycling still feel like cycling but help you conquer hills. >> Right. >> And go farther and use the bike more. >> Right, it's pretty interesting cause there's a whole lot of data that's feeding that software and the algorithms to make those feedback loops smooth, make 'em feel like bicycling, so it's really you're riding on software. >> Exactly, you're riding on software and we have three sensors that are capturing your input. Torque sensor from the pedals, how fast you're pedaling, and wheel speed. And those three sensor measurements go into the electronics and tell the motor how much extra oomph to give you. >> Right, but you have to be pedaling right? >> You always have to be pedaling, yeah. >> That's one of the data inputs. >> Exactly, these are all pedal assist eBikes, and they only assist you when you pedal, no throttle, and they can assist you up to 20 miles per hour, or 28 miles per hour for our speed system. >> Right, we saw that last night in the gazelle, they had one of the 28 mile an hour bikes. >> Yeah, which is great for people that have long distance commutes or they want to do these huge adventure rides, so yeah, both are great. >> Now, what about the maintenance for these types of systems I mean it looks like a pretty closed system. >> It is totally closed, yeah. >> It's totally closed. >> Yeah, the maintenance, they last a long time, they're warrantied for two years, but if you have a problem with anything, you take it to the dealer, the dealer takes the component off, sends it to Bosch and gives you a new one. You don't have to open anything or solder anything. >> Right, right. >> Yeah, no. It's automotive grade, sort of service and diagnostics. >> Right, so the other thing we're seeing all over the show floor here again is all about the data. There's so much more data available to the riders. We were just at the Garmin booth and I don't know how many different data sets that they can track, in terms of your pedal pressure. >> Yes. >> Whether you're tipping back and forth, whether you're even, and you guys are actually pulling some of that external data back into your systems, right? For a unified experience for the rider. I think you said, a heart rate sensor for instance? >> Exactly, that's the newest feature that we're showcasing at InterBike today, the Kiox display. Which connects man and machine, or woman and machine. You can wear a heart rate monitor and as you're riding, you can see your heart rate on your device. Which is great if you want to train on an e-mountain bike. Sometimes you want to keep your heart rate in a certain range. Sometimes you want to make sure it doesn't go above a certain limit. >> Right. Yeah, so it's our first step into connectivity. Many more connectivity features will follow. >> Right, so I'm just curious from your perspective on the bike industry, cause you sit in kind of this, cat bird seat, since you deal with so many different kinds of bikes. And I was amazed at how much of the mountain bike adoption of the eBikes is happening here. Have you seen within your dealers, kind of this new opportunity to leverage electronics and a motor to kind of reinvigorate the brands, reinvigorate the models, and reinvigorate, you know, many of the, just a wide range of cool form factors that we're seeing all over the floor? >> Yeah, so nine years ago, Bosch coupled with Haibike. Haibike sort of created this segment of e-mountain biking by putting the motor in a unique way into the bike, and since then this e-mountain bike trend has really taken off, it's huge in Europe. You'll see e-mountain bikes all over the ski resorts there. They're allowing families to e-mountain bike together, to bike together, just like they ski together in the winter. So it's reinvigorating ski resorts and we see ski resorts here in the US, also embracing e-mountain bikes. Mammoth Mountain just allowed class one e-mountain bikes on all their bike park trails. So e-mountain biking is really spreading through this resort and other resorts, North Star, right up the road. >> Right and I wonder on the city side, again, lessons we can learn from Europe, cause it seems like the regulations are, you know, they're always a little bit behind the technology in terms of, you know, how are eBikes treated. Are they a bike, are they a motor vehicle? And I know there's some laws but it still seems a little bit confused and cities aren't quite ready to realize that an eBike is better than a car, in terms of so many things happening in the city. Are you guys involved in that, kind of industry consortium and how do you see that evolving? >> So we've been involved with several other bike companies and PeopleForBikes to create a framework, how to regulate eBikes. And we've divided eBikes into three classes. Class one, two and three, pedal assist, throttle, anyway. Setting up this definition of the three classes of eBikes, we've created this eBike law in California and nine other states throughout the country. So now they know how to regulate eBikes and these three classes and they can limit where each class can go on the roads. And with this regulation, we're seeing the eBike adoption in these states really start to pick up, now that they're easier to regulate. >> Right, well Jonathan, really a cool story and it's been really fun to watch Bosch, especially as you guys have gone from your long history in the auto parts world to this new exciting space. So thanks for taking a few minutes and congrats. >> Oh, my pleasure, Jeff, thank you. >> Alright, he's Jonathan, I'm Jeff, you're watching theCUBE, we're at InterBike in Reno, Nevada. Thanks for watching, see you next time. (techno music)

Published Date : Sep 21 2018

SUMMARY :

We're in Reno, Nevada at the Reno Convention Center. So, I don't know if everybody knows, you guys power and help you go further, higher, farther, The main components are you got the drive unit, so you can control it. and the engineers back then, what they wanted to do that's feeding that software and the algorithms and tell the motor how much extra oomph to give you. and they can assist you up to 20 miles per hour, Right, we saw that last night in the gazelle, or they want to do these huge adventure rides, I mean it looks like a pretty closed system. sends it to Bosch and gives you a new one. Yeah, no. Right, so the other thing we're seeing and you guys are actually pulling Sometimes you want to keep your heart rate in a certain range. Yeah, so it's our first step into connectivity. on the bike industry, cause you sit in kind of this, and we see ski resorts here in the US, cause it seems like the regulations are, you know, and PeopleForBikes to create a framework, and it's been really fun to watch Bosch, Thanks for watching, see you next time.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
MichaelPERSON

0.99+

HowardPERSON

0.99+

MariaPERSON

0.99+

Laura HeismanPERSON

0.99+

LauraPERSON

0.99+

JamaicaLOCATION

0.99+

Mark FaltoPERSON

0.99+

DavidPERSON

0.99+

DavePERSON

0.99+

JeffPERSON

0.99+

JohnPERSON

0.99+

Jeff FrickPERSON

0.99+

Dave ValantePERSON

0.99+

CaliforniaLOCATION

0.99+

2006DATE

0.99+

2012DATE

0.99+

Dan SavaresePERSON

0.99+

CompaqORGANIZATION

0.99+

JoePERSON

0.99+

EMCORGANIZATION

0.99+

Paul GillanPERSON

0.99+

RonPERSON

0.99+

JonathanPERSON

0.99+

DellORGANIZATION

0.99+

CiscoORGANIZATION

0.99+

RhondaPERSON

0.99+

Jonathan WeinertPERSON

0.99+

Steve BamaPERSON

0.99+

twoQUANTITY

0.99+

two yearsQUANTITY

0.99+

VegasLOCATION

0.99+

BangaloreLOCATION

0.99+

2009DATE

0.99+

John TroyerPERSON

0.99+

Amazon Web ServicesORGANIZATION

0.99+

EuropeLOCATION

0.99+

IndiaLOCATION

0.99+

2018DATE

0.99+

FortyQUANTITY

0.99+

MondayDATE

0.99+

MarkPERSON

0.99+

SeptemberDATE

0.99+

San FranciscoLOCATION

0.99+

Dave MatthewsPERSON

0.99+

AdobeORGANIZATION

0.99+

Sanjay PoonenPERSON

0.99+

Trevor DavePERSON

0.99+

BenPERSON

0.99+

1999DATE

0.99+

VMwareORGANIZATION

0.99+

Jonathan SecklerPERSON

0.99+

Howard EliasPERSON

0.99+

16 acreQUANTITY

0.99+

10QUANTITY

0.99+

80 percentQUANTITY

0.99+

JapanLOCATION

0.99+

200 acreQUANTITY

0.99+

BMCORGANIZATION

0.99+

$50 millionQUANTITY

0.99+

Ricardo Villadiego, Cyxtera | RSA North America 2018


 

>> Announcer: From downtown San Francisco, it's theCUBE, covering RSA North America 2018. >> Hey, welcome back everybody, Jeff Frick here with theCUBE. We're at the RSA conference in San Francisco 40,000 plus people talking about security, gets bigger and bigger every year. Soon it's going to eclipse Oracle Open World and Sales Force to be the biggest conference in all of San Francisco. But we've got somebody who's been coming here he said for 16 years, Ricardo Villidiego, the EDP and GM Security and Fraud for Cyxtera. Did I get that right, Cyxtera? >> Cyxtera. >> Jeff: Cyxtera Technologies, great to see you. >> Thank you Jeff, it's glad to be here. >> So you said you've been coming here for 16 years. How has it changed? >> Yeah, that's exactly right. You know it's becoming bigger, and bigger, and bigger I believe this is a representation of the size of the prowling out there. >> But are we getting better at it, or is it just the tax service is getting better? Why are there so many, why is it getting bigger and bigger? Are we going to get this thing solved or? >> I think it is that combination within we have the unique solution that is going to help significantly organizations to get better in the security landscape I think the issue that we have is there's just so many now use in general and I think that now is a representation of the disconnection that exists between the way technologies are deploying security and the way technologies are consuming IT. I think IT is completely, has a evolved significantly and is completely hybrid today and organizations are continuing to deploy security in a way like if we were in the 90s. >> Right. >> And that's the biggest connection that exists between the attacks and the protection. >> But in the 90s we still like, or you can correct me, and we can actually build some big brick walls and a moat and a couple crocodiles and we can keep the bad guys out. That's not the way anymore. >> It is not a way. And look, I believe we're up there every protection creates a reaction on the adversary. And that is absolutely true in security and it is absolutely true in the fraud landscape. Every protection measure will push the adversary to innovate and that innovation is what, for good and for bad, has created this big market which we can't complain. >> Right, right. So for folks that aren't familiar with Cyxtera give them the quick update on what you guys are all about. >> So see, I think Cyxtera is here to conquer the cyber security space. I think what we did is we put together technologies from the companies that we acquire. >> Right. >> With a combination of the call center facilities that we also acquired from Centurylink to build this vision of the secure infrastructure company and what we're launching here at the RSA conference 2018 is AppGate 4.0 which is the flagship offering around secure access. Secure access is that anchor up on which organizations can deploy a secure way to enable their workforce and their party relationships to get access the critical assets within the network in a secure way. >> Okay, and you said 4.0 so that implies that there was a three and a two and probably a one. >> Actually you're right. >> So what are some of the new things in 4.0? >> Well, it's great it gives it an evolution of the current platform we lounge what we call life entitlements which is an innovative concept upon which we can dynamically adjust the permitter of an an end point. And the user that is behind that end point. I think, you know, a permitter that's today doesn't exist as they were in the 90s. >> Right, right. >> That concept of a unique permitter that is protected by the firewall that is implemented by Enact Technology doesn't exist anymore. >> Right. >> Today is about agility, today is about mobility, today is about enabling the end user to securely access their... >> Their applications, >> The inevitable actions, >> They may need, right. >> And what AppGate does is exactly that. Is to identify what the security processor of the end point and the user behind the end point and deploy a security of one that's unique to the specific conditions of an end point and the user behind that end point when they're trying to access critical assets within the network. >> Okay, so if I heard you right, so instead of just a traditional wall it's a combination of identity, >> Ricardo: It's identity. >> The end point how their access is, and then the context within the application. >> That's exactly right. >> Oh, awesome so that's very significant change than probably when you started out years ago. >> Absolutely, and look Jeff, I think you know to some extent the way enterprises are deploying security is delusional. And I say that because there is a reality and it looks like we're ignoring ignoring the reality but the reality is the way organizations are consuming IT is totally different than what it was in the 90s and the early 2000s. >> Right. >> The way organizations are deploying security today doesn't match with the way they're consuming IT today. That's where AppGate SDP can breach that gap and enable organizations to deploy security strategies that match with the reality of IT obstacles today. >> Right. If they don't get it, they better get it quick 'cause else not, you know we see them in the Wall Street Journal tomorrow morning and that's not a happy place to be. >> Absolutely not, absolute not and we're trying to help them to stay aware of that. >> Right. Alright, Ricardo we'll have to leave it there we're crammed for time but thanks for taking a few minutes out of your day. >> Alright Jeff, thank you very much I love to be here. >> Alright. He's Ricardo I'm Jeff you're watching theCUBE from RSAC 2018 San Francisco. (upbeat music)

Published Date : Apr 18 2018

SUMMARY :

Announcer: From downtown San Francisco, it's theCUBE, and Sales Force to be the biggest So you said you've been coming here for 16 years. the size of the prowling out there. that now is a representation of the disconnection that And that's the biggest connection that exists But in the 90s we still like, in the fraud landscape. So for folks that aren't familiar with Cyxtera technologies from the With a combination of the call center facilities Okay, and you said 4.0 so that implies And the user that is behind that end point. that is protected by the firewall that is Today is about agility, today is about mobility, and the user behind that end point when and then the context within the application. than probably when you started out years ago. and the early 2000s. and enable organizations to deploy security and that's not a happy place to be. them to stay aware of that. Right. I love to be here. He's Ricardo I'm Jeff

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
JeffPERSON

0.99+

RicardoPERSON

0.99+

Ricardo VilladiegoPERSON

0.99+

Ricardo VillidiegoPERSON

0.99+

Jeff FrickPERSON

0.99+

CenturylinkORGANIZATION

0.99+

EDPORGANIZATION

0.99+

CyxteraORGANIZATION

0.99+

tomorrow morningDATE

0.99+

Enact TechnologyORGANIZATION

0.99+

90sDATE

0.99+

todayDATE

0.99+

San FranciscoLOCATION

0.99+

16 yearsQUANTITY

0.99+

TodayDATE

0.99+

early 2000sDATE

0.98+

40,000 plus peopleQUANTITY

0.98+

threeQUANTITY

0.98+

oneQUANTITY

0.98+

Cyxtera TechnologiesORGANIZATION

0.97+

RSA conference 2018EVENT

0.94+

Wall Street JournalTITLE

0.93+

GM Security and FraudORGANIZATION

0.93+

twoQUANTITY

0.93+

2018DATE

0.9+

yearsDATE

0.87+

RSACEVENT

0.87+

Open WorldEVENT

0.86+

RSA North America 2018EVENT

0.85+

AppGateTITLE

0.84+

CyxteraPERSON

0.8+

Sales ForceORGANIZATION

0.77+

RSA conferenceEVENT

0.74+

RSA North AmericaORGANIZATION

0.72+

OracleORGANIZATION

0.7+

AppGate 4.0EVENT

0.7+

4.0OTHER

0.7+

every yearQUANTITY

0.64+

couple crocodilesQUANTITY

0.64+

theCUBEORGANIZATION

0.61+

measureQUANTITY

0.59+

SDPORGANIZATION

0.5+

Matt Cauthorn, ExtraHop | RSA North America 2018


 

>> Announcer: From downtown San Francisco, it's theCUBE, covering RSA North America 2018. >> Hey, welcome back everybody. Jeff Frick here with theCUBE. We're at the RSA Conference in downtown San Francisco. Forty thousand plus security experts really trying to help us all out. Protect our borders not so much, but protects access to these machines, which is harder and harder and harder everyday with bring your own devices and all these devices. So really, it's a different strategy. And we're really excited to have ExtraHop back, we had ExtraHop on last year for the first year, he's Matt Cauthorn, the VP of security at ExtraHop. So Matt, what do you think of the show? >> Oh, amazing. Absolutely amazing. Super packed, been walking like crazy. Got all my steps in, its fantastic. >> Alright, so you guys have been in network security for a long time? >> Yeah so we've been, so we live in the East-West corridor, inside the enterprise, inside the perimeter doing wire data analytics, and network security analytics. Our source of data is the network itself. >> Okay. And the network is increasing exponentially with all the traffic that's going through, the data sources are increasing exponentially with all the traffic going through. >> That's right. >> So how are you guys keeping up with the scale, and what's really the security solution that you guys are implementing? >> So the point you make is really interesting. Yes, it is increasing exponentially, and as a data source the network is the only sort of observational point of truth in the entirety of IT. Everything else is sort of self-reported. Logs, end points, those are very valuable data sources, but as an empirical source of truth, of evidence, the network wins. That assumes you can scale. And that assumes you're fluent with the protocols that are traversing the network, and you're able to actually handle the traffic in the first place. And so for us just this week, we announced a 100gb per second capable appliance, which you know is an unprecedented amount of analytics from the network's perspective. So we're very proud about that. >> So what are you looking for? What are some of the telltale signs that you guys are sniffing for? >> So generally, we auto-classify and auto-discover all of the behaviors on the wire. From the devices themselves, to the services that those devices expose, as well as the transactions that those devices exchange. And so from a context perspective, we're able to go far deeper than almost anyone else in the space, that we know of at least. Far deeper and far more comprehensive sort of analysis as it relates to the network itself. >> And the context is really the key, right? Tag testing what, why, how. System behavior, that's what you're looking for? >> A great example is a user logging into a database, that might be part of a cluster of databases, and understanding what the user's behavior is with the database, which queries are being exchanged, what the database response is in the first place. Is it an error, is it an access denied? And does this behavior look like a denial of service, for example. And we can do all of that in real time, and we have a machine learning layer that sits over top and sort of does a lot of the analytics, and the sort of insights preemptively on your behalf. >> And it's only going to get crazier, right? With IOT and 5g. Just putting that much more data, that many more devices, that much more information on the network. Yeah, so IOT in particular is interesting, because IOT is challenging to instrument in traditional ways, and so you really do have to fall back to the network at some point for your analysis. And so that's where we're very, very strong in the IOT world and industrial controls, SCADA and beyond. Healthcare, HL7 for example. So we're able to actually give you a level of insight that's really, really difficult to get otherwise. >> And we've been hearing a lot of the keynotes and stuff, that those machines, those end points are often the easiest path in for the bad guys. >> Yes they are. >> An enormous security camera or whatever, because they don't have the same OS, they don't have all the ability to configure the protections that you would with say a laptop or a server. >> That's right. There's a surprising number of IOT devices out there that are running very, very old. And vulnerable operating systems are easy to exploit. >> Alright, so Matt I guess we're into Q2 already, hard to believe the years passing by. What's priorities for 2018 for you and ExtraHop? >> So we've announced a first class, purpose-built security solution this year, and really the plan is to continue the sort of momentum that we've accrued. Which is very encouraging, the amount of interest that we've had. It's hard to keep up, frankly. Which is fantastic. We want to continue to build on that, grow out the use cases, grow out the customer base and continue our success. >> Alright Matt, well we'll keep an eye on the story, and thanks for stopping by. >> Great, thank you. Appreciate it. >> Alrighties Matt, I'm Jeff, you're watching theCUBE from RSA Conference, San Francisco. Thanks for watching.

Published Date : Apr 18 2018

SUMMARY :

Announcer: From downtown San Francisco, it's theCUBE, he's Matt Cauthorn, the VP of security at ExtraHop. Oh, amazing. Our source of data is the network itself. the data sources are increasing exponentially and as a data source the network is the only all of the behaviors on the wire. And the context is really the key, right? and the sort of insights preemptively on your behalf. that much more information on the network. are often the easiest path in for the bad guys. that you would with say a laptop or a server. that are running very, very old. hard to believe the years passing by. and really the plan is to continue and thanks for stopping by. you're watching theCUBE from RSA Conference, San Francisco.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
JeffPERSON

0.99+

Matt CauthornPERSON

0.99+

Jeff FrickPERSON

0.99+

MattPERSON

0.99+

2018DATE

0.99+

San FranciscoLOCATION

0.99+

last yearDATE

0.99+

ExtraHopORGANIZATION

0.99+

this weekDATE

0.98+

Q2DATE

0.97+

firstQUANTITY

0.96+

this yearDATE

0.93+

100gb per secondQUANTITY

0.9+

theCUBEORGANIZATION

0.86+

first yearQUANTITY

0.85+

downtown San FranciscoLOCATION

0.81+

NorthLOCATION

0.79+

Forty thousand plus security expertsQUANTITY

0.78+

first placeQUANTITY

0.76+

SCADAORGANIZATION

0.69+

RSAORGANIZATION

0.68+

ExtraHopCOMMERCIAL_ITEM

0.56+

RSA ConferenceEVENT

0.56+

HealthcareORGANIZATION

0.55+

RSA ConferenceORGANIZATION

0.5+

AmericaLOCATION

0.5+

RSA North America 2018TITLE

0.47+

HL7TITLE

0.39+

5gOTHER

0.35+

Michael Daniel, Cyber Threat Alliance | RSA North America 2018


 

>> Narrator: From downtown San Francisco it's the Cube covering RSA North America 2018. >> Hey, welcome back, everybody. Jeff Frick here with the Cube. We're at the RSA conference in downtown San Francisco, 40,000 plus professionals all about security and one of the big themes is how do we work together? How do we leverage our collective knowledge, look for patterns to help, you know, be better against the bad guys, and one of the really big forces for that is the Cyber Threat Alliance and we're really excited to have Michael Daniel, the president and CEO of Cyber Threat Alliance. Michael, great to see you. >> Thanks for having me. >> So, talk about kind of the genesis of this because it's such an important concept that, yes, we're competitors on this floor but if we work together, we can probably save ourselves a lot of work. >> Absolutely, I mean, part of the idea behind the Cyber Threat Alliance is that no matter how big you are, no matter how broad your coverage is of cyber security company, no one individual company ever sees all of the threats all of the time. >> Jeff: Right. >> And, so that, in order to better protect their customers and clients, sharing that threat intelligence at speed at scale is a very fundamental part of being a much better cyber security company. >> So, how hard of a sell was that a year ago? I think you started it a year ago, announced it, and how's the ecosystem kind of changed over the last year? >> Well, I would say that, you know, it's not like I run into anybody that says, "You know, Michael, that's a really "stupid idea, we shouldn't do that." Right, it's really finding the way for a cyber security company to fit it into their business model. >> Right. >> To be able to consume the threat intelligence at a speed that matters and really be able to bake it into their products. That's usually the hard part. Conceptually, everybody agrees that this is what we need to do. >> Right, and then, how 'about just the nitty gritty nuts and bolts of, you know, how do you share information? How is it picked up, how is it communicated? What are the protocols? I'd imagine that's not too simple. >> That's right, and one of the things that we settled on was we use the STIX format because it's an open format that everybody can translate back and forth. We had to build in a lot of business rules to actually make sure that people were playing fair. You know, for example, we actually require all of our members to share. So, you can't just join the alliance and consume information, you actually have to give in order to receive. >> Right, and you've got some really kind of high-level, lofty goals that you've built this around in terms of doing good for the greater good, kind of beyond the profitability of an individual customer transaction. I wonder if you can speak to a few of those. >> Well, sure, so the part of the idea behind the way that CTA is structured is that we're a 501 C6, so we're a non-profit, right, and the idea is that we function to help raise the level of cyber security across the digital ecosystem and actually enable our member companies to compete more effectively because they have better intelligence that their products and services are based on, but we, ourselves, are not in it to make money. >> Right, right, right, alright, Michael. Unfortunately, we're up against the time. >> Absolutely. >> So, we're going to have to leave it there, but love the work that you guys are doing and it makes so much sense for people to work together. >> Well, thank you very much, thank you for having me. >> Alright, he's Michael from Cyber Threat Alliance. I'm Jeff from the Cube. You're watching us from the RSA conference San Francisco, thanks for watchin'. (soft electronic beat)

Published Date : Apr 18 2018

SUMMARY :

Narrator: From downtown San Francisco it's the Cube and one of the big themes is how do we work together? So, talk about kind of the genesis of this the Cyber Threat Alliance is that no matter And, so that, in order to better protect Right, it's really finding the way To be able to consume the threat intelligence just the nitty gritty nuts and bolts of, That's right, and one of the things of doing good for the greater good, and the idea is that we function to help raise Right, right, right, alright, Michael. so much sense for people to work together. I'm Jeff from the Cube.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
JeffPERSON

0.99+

MichaelPERSON

0.99+

Michael DanielPERSON

0.99+

Jeff FrickPERSON

0.99+

Cyber Threat AllianceORGANIZATION

0.99+

San FranciscoLOCATION

0.99+

a year agoDATE

0.99+

40,000 plus professionalsQUANTITY

0.99+

last yearDATE

0.99+

oneQUANTITY

0.98+

RSAEVENT

0.93+

501 C6OTHER

0.93+

CubeORGANIZATION

0.72+

RSAORGANIZATION

0.69+

2018DATE

0.63+

STIXOTHER

0.62+

NorthLOCATION

0.54+

CubeCOMMERCIAL_ITEM

0.53+

AmericaORGANIZATION

0.41+

Derek Manky, Fortinet | RSA North America 2018


 

>> Narrator: From downtown San Francisco it's the Cube covering RSA North America 2018. >> Hey, welcome back, everybody, Jeff Frick here at the Cube. We're at RSA's security conference, about 40,000 plus. I don't know, I got to get the number. The place is packed, it's a mob scene. Really excited to be here and joined by Derek Manky We saw Derek last year from Fortinet. Great to get an update, Derek, what do you think of the show this year? >> It's getting big for sure, as I said. That's an understatement. >> I know. >> This is my tenth year coming to RSA now, yeah. >> It's your tenth? >> And just to see how it's changed over 10 years is phenomenal. >> Alright. So, one of the things you want to talk about that you probably weren't talking about 10 years are swarms of bots. >> Yeah. >> What the heck is going on with swarms of bots? >> There's been a lot of changes on that front too, so the bad guys are clever, of course, right? If we look at 10 years ago, there was a lot of code, you know, crime kits, crime services that were being created for infrastructure. That led up to some more, you know, getting affiliates programs, kind of, business middle men to distribute crime. So, that drove a lot of the numbers up, but, literally, in the last three quarters, if we look at hacking activity, the number has doubled from FortiGuard labs. It's gone from 1.1 million to 2.2 to 4.4 million just over the last three quarters. So, we're looking at a exponential rise to attacks. The reason that's happening is because automation >> Right. >> And artificial intelligence is starting to be put into black cat code, and so the swarm concept, if you think of bees or ants in nature, what do they do? They work together, it's strength in numbers from a black cat's point of view. >> Right, right. >> They work together to achieve a common goal. So, it's intent based attacks, and that's what we're starting to see as precursors as some code, right? These IoT bot nets, we're actually seeing nodes within the bot net that can communicate to each other, say, "Hey, guys, I found this other target in the network. "Let's go launch a DDOS attack "or let's all try to take different "bits of file information from those targets." So, it's that swarm mentality where it takes the attacker more and more out of the loop. That means that the attack surge is also increasing in speed and becoming more agile too. >> So, the bad news, right, is the bad guys have all the same tools that the good guys have in terms of artificial intelligence, machine learning, automation, software to find and they don't have a lot of rules that they're supposed to follow as well. So, it kind of puts you in a tougher situation. >> Yeah, we're always in a tough situation for sure. You know, I would say, for sure, that when it comes to the tools, a lot of the tools are out there, they custom develop some tools. I would have to say on the technology side when it comes to security members especially collaborating together and the amount of infrastructure that we have set up, I think we have a foot up on the attackers there, we're at an advantage, but you're absolutely right, when it comes to rules, there are no rules when it comes to the black cat attackers and we have to be very careful of that, how we proceed, of course, right. >> And that's really the idea behind the alliance, right, so, that you guys are sharing information. >> Yeah. >> So, you're sharing best practices, you're picking up patterns. So, everybody's not out there all by themselves. >> Absolutely, it's strength in numbers concept on our end too. So, we look at Cyber Threat Alliance, Fortinet being out founding member working with all other leading security vendors in this space is how we can team up against the bad guys, share actionable intelligence, deploy that into our security controls which makes it a very effective solution, right. By teaming up, stacking up our security, it makes it much more expensive for cyber criminals to operate. >> Right, that's good. >> Yeah. >> That's a good thing. >> Yeah, yes. >> And then, what about kind of this integration of the knock and the sock? >> Yeah. >> Because security's so much more important for all aspects of the business, right? It's not layered on, it's not stand alone. It's really got to be integrated into the software, into the process and the operations. >> Absolutely, so, the good news is, if you look at things like we're doing with the security fabric, a lot of it is how do we integrate, how do we bring technology and intelligence down to the end user so that they don't have to do day-to-day mundane tasks, right? Talking about the swarm networks, what's happening on the black cats' side, attackers are gettin' much quicker so defense solutions have to be just as quick if not faster, and so that's what the knock sock integration is about, right, how we can take network's security visibility, put it into things like our FortiAnalyzer manager sim appliances, right, be able to bring those solutions so, again, to when it comes to a knock and sock operation, how do you bring visibility into threats? How do you respond to those threats? More importantly, how do you also have automated security defense, so agile defense, put up? >> Right. >> We talk about concepts like agile macrosegmentation, right? That's something we're doing with Fortinet, how we can look at attacks and actively lock down attacks as they're happening is a really concept, right? >> So, really, just to isolate 'em within kind of where they've caused the harm, keep 'em there until you can handle 'em and not let 'em just go bananas all over the orientation. >> Yeah, yeah, so you can think of it as, like, an active quarantine. We've also launched our threat intelligence services. So, this is bringing the why. There's a lot of intelligence out there. There's a lot of logs. We have, now,, threat intelligence services that we bring to security operation centers to show them here are the threats happening on your network. Here is why it is a threat. Here's the capabilities of the threat and here's how you respond to it. So, it helps from a CSOL perspective prioritized response on the incident response model to threats as well. >> Alright, well, Derek, we've got to let it go there. We are at a super crazy time crunch. >> I know. >> We'll get you back into the studio and have a little bit more time when it's not so crazy. >> Okay, I appreciate it. >> Alright, he's Derek Manky, I'm Jeff Frick. You're watching the Cube from RSA 2018, thanks for watchin'. (soft electronic beat)

Published Date : Apr 18 2018

SUMMARY :

Narrator: From downtown San Francisco it's the Cube I don't know, I got to get the number. It's getting big for sure, as I said. to RSA now, yeah. And just to see how it's changed So, one of the things you want to talk about that you So, that drove a lot of the numbers up, and so the swarm concept, if you think it takes the attacker more and more out of the loop. So, the bad news, right, is the bad guys the amount of infrastructure that we have set up, And that's really the idea behind the alliance, right, So, everybody's not out there all by themselves. So, we look at Cyber Threat Alliance, for all aspects of the business, right? So, really, just to isolate 'em within kind of on the incident response model to threats as well. We are at a super crazy We'll get you back into the studio Alright, he's Derek Manky, I'm Jeff Frick.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
Jeff FrickPERSON

0.99+

DerekPERSON

0.99+

Derek MankyPERSON

0.99+

FortinetORGANIZATION

0.99+

tenth yearQUANTITY

0.99+

1.1 millionQUANTITY

0.99+

tenthQUANTITY

0.99+

Cyber Threat AllianceORGANIZATION

0.99+

last yearDATE

0.99+

4.4 millionQUANTITY

0.99+

FortiGuardORGANIZATION

0.99+

this yearDATE

0.99+

10 years agoDATE

0.97+

2.2QUANTITY

0.97+

over 10 yearsQUANTITY

0.96+

RSAORGANIZATION

0.94+

2018DATE

0.93+

about 40,000 plusQUANTITY

0.91+

oneQUANTITY

0.9+

agileTITLE

0.88+

10 yearsQUANTITY

0.8+

San FranciscoLOCATION

0.79+

CSOLORGANIZATION

0.77+

RSATITLE

0.73+

FortiAnalyzerTITLE

0.69+

CubeTITLE

0.67+

last three quartersDATE

0.62+

NorthLOCATION

0.59+

CubeORGANIZATION

0.58+

numbersQUANTITY

0.51+

RSA NorthTITLE

0.48+

AmericaORGANIZATION

0.41+

AmericaLOCATION

0.29+

Dr. Chase Cunningham, Forrester Research | RSA North America 2018


 

>> Narrator: From downtown San Francisco it's theCUBE covering RSA North America 2018. >> Welcome back everybody, Jeff Frick here with theCUBE. We're at the RSA Conference North America 2018 downtown San Francisco. 40,000 plus people swarming all over Moscone to the north to the south and to the west. We're excited to have our next guest on. He's Chase Cunningham, principal analyst at Forrester. Chase, great to meet you, welcome. >> Thanks for having me. >> Absolutely, so you just had an interesting blog post. Was Zero Trust on a beer budget. >> Yeah. >> What is that all about? >> Well, so Zero Trust is a pretty simple concept about accepting failure, if you will, and focusing on the internal and moving outward. And basically the premise was, I had friend of mine ask me if he could do Zero Trust for his small company. And I said sure, let's go get a beer and we'll figure this out. And literally, in about half an hour we had a Zero Trust strategy in place for less than 40 grand and his infrastructure is way more secure and it's really simple. >> So that's pretty interesting because, you Know it's easy for big companies that have a lot of resources or the big puddle of Cloud companies have a lot of resources to put a lot of implementation into place. But as we look around this conference tons and tons of companies, it's a lot harder for small and medium businesses either to have the expertise or the budgets to really bring in what they need to secure things. So what were some of the insights from your beer exercise? >> Sure, so it was really simple. If you really think about where the majority of the threat comes from, the network is there and everybody uses it but who accesses the network? The users, the individuals, the devices, everything else. So the first thing we did was we're going to lock down identity and access management because I know if I can control that I've made a fundamental shift into power position for myself. And the next thing we did was we said look you guys don't really own intellectual property but you send emails. We're going to put stuff in place to encrypt every email you send whether you like it or not. So between those two simple things, identity access management and sort of data email encryption we put a really strong security platform in place and it didn't break the bank and it wasn't really hard to do and it's something that you can get better as it goes on. >> Right. And I'm curious, had he had an event or he was just trying to get ahead of the curve? >> He had had some weird stuff showing up. He's in esports, right, so he doesn't have actual intellectual property but he's worried because if they get dossed or they get hacked or they get ransomware for every minute they're down they're losing viewers and that's business and money for them. >> Right, so it kind of ties back to this kind of next gen access where it's really important with the identity but the other one is the context. Who is it and where are they trying to get in? Do they usually come in that way? Do they usually have access? So that's another really way to kind of isolate the problems that might come in the front door. >> Yeah, and you know the, years ago the next gen firewall was really the thing to integrate lots of functions across the network and that's all there. It still exists and it's still necessary but really when you break it down and look at historically where the threats have come from and where the compromises have come from, it's access and if you can't control that you don't have the capability of actually stopping bad things from happening. >> Right, right, so as you look around and you've been coming to this probably for a couple years, as this space evolves. You know, kind of what are your general impressions? I mean, on one hand, so many vendors, so many activities. On the other hand, it was like, we've been at this for a while or are we just stuck in this race and we just got to keep running? >> Well I think we're going to continue running the race but interestingly enough there's buses driving by now with Zero Trust all over the side of it. And I'm glad to see that that strategy is starting to take hold because the problem I have is you can Frankenstein technology together all day long but if you don't have a strategic guidepost that everybody understands from the board down to the network engineer you're going to get it wrong. You're going to miss and so I'm a fan of simplicity and force multipliers and to me the Zero Trust strategy sort of drives that forward. >> All right, well Chris thanks for taking a few minutes. Everyone can log onto your site, take a look at the blog. Thanks for stopping by. >> Thanks for having me. >> All right, he's Chris Cunningham from Forrester. I'm Jeff Frick from theCUBE. Thanks for watching from RSAC 2018.

Published Date : Apr 18 2018

SUMMARY :

Narrator: From downtown San Francisco it's theCUBE to the south and to the west. Absolutely, so you just had an interesting blog post. about accepting failure, if you will, and focusing So that's pretty interesting because, you Know and it's something that you can get better as it goes on. And I'm curious, had he had an event or he was He's in esports, right, so he doesn't have actual Right, so it kind of ties back to this kind of Yeah, and you know the, years ago the next gen firewall Right, right, so as you look around and force multipliers and to me the Zero Trust Thanks for stopping by. Thanks for watching from RSAC 2018.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
Jeff FrickPERSON

0.99+

Chris CunninghamPERSON

0.99+

ChrisPERSON

0.99+

Chase CunninghamPERSON

0.99+

Forrester ResearchORGANIZATION

0.99+

firstQUANTITY

0.99+

MosconeLOCATION

0.99+

40,000 plus peopleQUANTITY

0.99+

Zero TrustORGANIZATION

0.99+

less than 40 grandQUANTITY

0.99+

ChasePERSON

0.98+

about half an hourQUANTITY

0.97+

two simple thingsQUANTITY

0.92+

years agoDATE

0.91+

RSACEVENT

0.9+

2018DATE

0.9+

ForresterORGANIZATION

0.89+

San FranciscoLOCATION

0.89+

theCUBEORGANIZATION

0.89+

RSA North AmericaORGANIZATION

0.89+

RSA Conference North America 2018EVENT

0.86+

oneQUANTITY

0.81+

tons and tons of companiesQUANTITY

0.79+

FrankensteinPERSON

0.78+

Dr.PERSON

0.77+

couple yearsQUANTITY

0.66+

downtown San FranciscoLOCATION

0.66+

ForresterLOCATION

0.55+

2018EVENT

0.5+

RSAORGANIZATION

0.42+

AmericaLOCATION

0.3+

NorthTITLE

0.25+

Bill Mann, Centrify | RSA North America 2018


 

>> Narrator: From downtown San Francisco it's TheCUBE covering RSA North American 2018. >> Hey, welcome back everybody. Jeff Frick from TheCUBE. We're on the floor at the RSA Conference 2018. 40,000 plus people packed in Moscone North, South, West, and we're excited to be here. It's a crazy conference, Security's top of mind obviously and everybody is aware of this. And our next guest, he's Bill Mann, chief product officer from Centrify. Bill, great to see you. >> Great to see you. >> So you guys have a lot of stuff going on but what I think what's interesting to me is you guys have this kind of no trust as your starting foundation. Don't trust anybody, anything, any device. How do you work from there? Why is that the strategy? >> Well that strategy is because we've got a really new environment now. A new environment where we have to appreciate that the bad actors are already within our environment. And if you stop believing that bad actors are already in your environment, you have to start changing the way you think about security. So it's a really different way of thinking about security. So what we call this new way of thinking about security is zero trust security. And you might have heard this from Google with BeyondCorp and so forth. And with that as the overarching kind of way we are thinking about security, we're focusing on something called NextGenAccess. So how do you give people access to applications and services where they're remote. They're not on the network and they're not behind a firewall because who cares about the firewall anymore because it's not secure. >> Right. So there's four tenants of NextGenAccess. One is verify the user, verify the device that they are coming from so they're not coming from a compromised device. Then give them limited access to what they are trying to access or what we call Limit Privilege and Access. And that last one is learn and adapt which is this kind of pragmatic viewpoint which is we're never going to get security right day one, right? To learn and adapt and what we're doing look at auto tune logs and session logs to change your policy and adapt to get a better environment. >> So are you doing that every time they access the system? As they go from app to app? I mean how granular is it? Where you're consistently checking all these factors? >> We're always checking the end factor and where we use an actual machine learning to check what's happening in the environment and that machine learning is able to give that user a better experience when they are logging in. Let's say Bill's logging into Salesforce.com from the same location, from the same laptop all the time. Let's not get in the way right? But if Bill the IT worker is going from a different location and logging into a different server that's prompting for another factor of authentication because you want to make sure that this is really Bill. Because fundamentally you don't trust anybody in the network. >> And that's really what you guys call this NextGenAccess, right? [Bill]- That right, that's right, that's right. >> It's not just I got a VPN. You trust my VPN. I got my machine. Those days are long gone. >> Well VPNs, no no to VPNs as well, right? We do not trust VPNs either. >> So a bit topic ever since the election, right, has been people kind of infiltrating the election. Influencing you know how people think. And you guys are trying to do some proactive stuff even out here today for the 2018 election to try to minimize that. Tell us a little bit more about it. >> Yeah we call it Secure The Vote. And if the audience has looked at the recent 60 Minutes episode that came on. That did a really good that walked everybody through what was really happening with the elections. The way you know the Russians really got onto the servers that are storing our databases for the registration systems and changed data and created chaos in the environment. But the fundamental problem was compromised credentials. I mean 80% of all breaches believe it or not have to do with compromised credentials. They are not around all the things we think are the problem. So what we're doing here with Secure The Vote is giving our technology to state and local governments for eight months for free. And essentially they can then upgrade their systems, right? So they can secure the vote. So fundamentally securing who has access to what and why and when. And if you look at the people who are working on election boards, they're volunteers, there are a lot of temporary staff and so forth. >> Right, right. >> So you can imagine how the bad guys get into the environment. Now we've got a lot of experience on this. We sell to state and local governments. We've seen our technology being used in this kind of environment. So we're really making sure that we can do our part in terms of securing the election by providing our technology for free for eight months so election boards can use our technology and secure the vote. >> So how hard is it though for them to put it in for temporary kind of situation like that? You made it pretty easy for them to put it in if they are not an existing customer? >> Absolutely I mean one of the things, one of the fallacies around this whole NextGenAccess space is the fact that it's complicated. It's all SAS-Space, it's easy to use, and it's all in bite-sized chunks, right? So some customers can focus on the MFA aspects, right? Some customers can focus on making sure the privileged users who have access to the databases, right, are limiting their access right? So there's aspects of this that you can implement based upon where you want to be able to, what problem you want to be able to solve. We do provide a very pragmatic best practices way of implementing zero trust. So we are really providing that zero trust platform for the election boards. [Jeff]- Alright well that's great work Bill and certainly appreciated by everybody. We don't want crazy stuff going on in the elections. >> Absolutely. >> Jeff: So we'll have to leave it there. We'll catch up back in the office. It's a little chaotic here so thanks for taking a few minutes. >> Thank you very much. >> Alright, he's Bill Mann and I'm Jeff Frick. You're watching TheCUBE from RSCA 2018. Thanks for watching. (bright music)

Published Date : Apr 18 2018

SUMMARY :

Narrator: From downtown San Francisco it's TheCUBE We're on the floor at the RSA Conference 2018. So you guys have a lot of stuff going on So how do you give people access to applications And that last one is learn and adapt which is this kind Let's not get in the way right? And that's really what you guys call It's not just I got a VPN. Well VPNs, no no to VPNs as well, right? And you guys are trying to do some proactive stuff And if the audience has looked So you can imagine So there's aspects of this that you can implement Jeff: So we'll have to leave it there. Thanks for watching.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
Jeff FrickPERSON

0.99+

JeffPERSON

0.99+

Bill MannPERSON

0.99+

eight monthsQUANTITY

0.99+

80%QUANTITY

0.99+

BillPERSON

0.99+

NextGenAccessORGANIZATION

0.99+

CentrifyORGANIZATION

0.99+

GoogleORGANIZATION

0.99+

BeyondCorpORGANIZATION

0.99+

40,000 plus peopleQUANTITY

0.98+

OneQUANTITY

0.98+

oneQUANTITY

0.98+

todayDATE

0.98+

RSA Conference 2018EVENT

0.97+

zero trustQUANTITY

0.97+

four tenantsQUANTITY

0.96+

Moscone NorthLOCATION

0.95+

zeroQUANTITY

0.95+

RSA North AmericaORGANIZATION

0.92+

2018DATE

0.89+

TheCUBEORGANIZATION

0.87+

60TITLE

0.79+

Secure The VoteOTHER

0.76+

Salesforce.comOTHER

0.75+

San FranciscoLOCATION

0.73+

RussiansPERSON

0.71+

TheCUBETITLE

0.71+

Limit PrivilegeOTHER

0.68+

day oneQUANTITY

0.66+

RSA North American 2018EVENT

0.63+

RSCAEVENT

0.6+

electionEVENT

0.57+

SpaceOTHER

0.56+

The VoteTITLE

0.54+

SASORGANIZATION

0.53+

MinutesQUANTITY

0.49+

AccessOTHER

0.48+

SecureOTHER

0.47+

Misha Govshteyn, Alert Logic | RSA North America 2018


 

(upbeat music) >> Announcer: From downtown San Francisco, it's theCUBE covering RSA North America 2018. Hey welcome back everybody, Jeff Frick here with theCUBE. We're at RSA's North American Conference 2018 at downtown San Francisco. 40,000 plus people talking about security. Security continues to be an important topic, an increasingly important topic, and a lot more complex with the, having a public cloud, hybrid cloud, all these API's and connected data sources. So, it's really an interesting topic, it continues to get complex. There is no right answer, but there's a lot of little answers to help you get kind of closer to nirvana. And we're excited to have Misha Govshteyn. He's the co-founder and SVP of Alert Logic, CUBE alumni, it's been a couple years since we've seen you, Misha, great to see you again. >> That's right, I'm glad to be back, thank you. >> Yeah, so since we've seen you last, nothing has happened more than the dominance of public cloud and they continue to eat up-- >> I think I predicted it on my past visits. >> Did you predict it? Wow that's good. >> But I think it happened. >> But it's certainly happening, right. Amazon's AWS' run rate is 20 billion last reported. Google's making moves. >> Their conference is bigger than ours right now. >> Is it? >> That's 45,000 people. >> Yeah, it's 45,000, re:Invent, it's nuts, it's crazy. and then obviously Microsoft's making big moves, as is Google cloud. So, what do you see from the client's perspective as the dominance of public cloud continues to grow, yet they still have stuff they have to keep inside? We have our GDPR regs are going to hit in about a month. >> Well one thing's for sure is, it's not getting any easier, right? Because I think cloud is turning things upside down and it's making things disruptive, right, so there's a lot of people that are sitting there and looking at their security programs, and asking themselves, "Does this stuff still work? "When more and more of my workloads "are going to cloud environments? "Does security have to change?" And the answer is obviously, it does but it always has to change because the adversaries are getting better as well, right. >> Right. >> There's no shortage of things for people to worry about. You know when I talk to security practitioners, the big thing I always hear is, "I'm having a good year if I don't get fired." >> Well it almost feels like it's inevitable, right? It's almost like you're going to, it seems like you're going to get hit. At some way, shape, or form you're going to get hit. So it's almost, you know how fast can you catch it? How do you react? >> That's a huge change from five years ago, right? Five years ago we were still kind of living in denial thinking that we can stop this stuff. Now it's all about detection and response and how does your answer to the response process works? That's the reason why, you know last year, I think we saw a whole bunch of noise about, you know machine learning and anomaly detection, and AI everywhere and a whole lot of next-generation antivirus products. This year, it seems like a lot of it is, a lot of the conversation is, "What do I do with all this stuff? "How do I make use of it?" >> Well then how do you leverage the massive investment that the public cloud people are making? So, you know, love James Hamilton's Tuesday night show and he talks about just the massive investments Amazon is making in networking, in security, and you know, he's got so many resources that he can bring to bear, to the benefit of people on that cloud. So where does the line? How do I take advantage of that as a customer? And then where are the holes that I need to augment with other types of solutions? >> You know here's the way I think about it. We had to go through this process at Alert Logic internally as well. Because we obviously are a fairly large IT organization, so we have 20 petabytes of data that we manage. So at some point we had to sit down and say, "Are we're going to keep managing things the way we have been "or are we going to overhaul the whole thing?" So, I think what I would do is I would watch where my infrastructure goes, right. If my infrastructure is still on-prem, keep investing in what you've been doing before, get it better, right? But if you're seeing more and more of your infrastructure move to the cloud, I think it's a good time to think about blowing it up and starting over again, right? Because when you rebuild it, you can build it right, and you can build it using some of the native platform offerings that AWS and Azure and GCP offer. You can work with somebody like Alert Logic. There's others as well right, to harness those abilities. I'll go out on a limb and say I can build a more secure environment now in a cloud than I ever could on-prem, right. But that requires rethinking a bunch of stuff, right. >> And then the other really important thing is you said the top, the conversation has changed. It's not necessarily about being 100% you know locked down. It's really incident response, and really, it's a business risk trade-off decision. Ultimately it's an investment, and it's kind of like insurance. You can't invest infinite resources in security, and you don't want to just stay at home and not go outside. Now that's not going to get it done. So ultimately, it's trade-offs. It's making very significant trade-off decisions as to where's the investment? How much investment? When is the investment then hit a plateau where the ROI is not there anymore? So how do people think through that? Because, the end of the day there's one person saying, "God, we need more, more, more." You know, anything is bad. At the other hand, you just can't use every nickel you have on security. >> So I'll give you two ends of the spectrum right, and on one end are those companies that are moving a lot of their infrastructure to the cloud and they're rethinking how they're going to do security. For them, the real answer becomes it's not just the investment in technology, and investing into better getting information from my cloud providers, getting a better security layer in place. Some of it is architecture right, and some of the basics right, there's thousands of applications running in most enterprises. Each one of those applications on the cloud, could be in its own virtual private cloud, right. So if it gets broken into, only one domino falls down. You don't have this scenario where the entire network falls down, because you can easily move laterally. If you're doing things right in the cloud, you're solving that problem architecturally, right. Now, aside from the cloud, I think the biggest shift we're seeing now, is towards kind of focusing on outcomes, right. You have your technology stack, but really it's all about people, analytics, data. What do you, how do you make sense of all this stuff? And this is classic I think, with the Target breach and some of the classic breaches we've seen, all the technology in the world, right? They had all the tools they needed. The real thing that broke down is analytics and people. >> Right, and people. And we hear time and time again where people had, like you said, had the architecture in place, had the systems in the place, and somebody mis-configured a switch. Or I interviewed a gal who did a live social hack at Black Hat, just using some Instagram pictures and some information on your browser. No technology, just went in through the front door, said, you know, hey, "I'm trying to get the company picnic "site up, can you please test this URL?" She's got a 100% hit rate! But I think it's really important, because as you said, you guys offer not only software solutions, but also services to help people actually be successful in implementing security. >> And the big question is, if somebody does that to you, can you really block it? And the answer a lot of times is, you can't. So the next battlefront is all about can you identify that kind of breach happening, right? Can you identify abnormal activity that starts to happen? You know, going back to the Equifax breach, right, one of the abnormal things that happened that they should've seen and for some reason didn't, you know, 30 web shells were stood up. Which is the telltale sign of, maybe you don't know how you got broken into, but because there's a web shell in your environment you know somebody's controlling your servers remotely, that should be one of those indicators that, I don't know how it happened, I don't know maybe I missed it and I didn't see the initial attack, but there's definitely somebody on a network poking around. There's still time, right? There's, you know for most companies, it takes about a hundred days on average, to steal the data. I think the latest research is if you can find the breach in less than a day, you eliminate 96% of the impact. That's a pretty big number right? That means that if you, the faster you respond, the better off you are. And most people, I think when you ask 'em, and you ask 'em, "Honestly assess your ability to quickly detect, respond, eradicate the threat." A lot of them will say, "It depends" But really the answer is "Not really." >> Right, 'cause the other, the sad stat that's similar to that one, is usually it takes many, many days, months, weeks, to even know that you've been breached, to figure out the pattern, that you can even start, you know, the investigation and the fixing. >> Somewhat not surprising, right? I don't think there's that many Security Operation Centers out there, right? There's not, you know, not every company has a SOC right? Not every company can afford a SOC. I think the latest number is, for enterprises, right, this is Fortune 2000, right, 15% of them have a SOC. What are the other 85% doing? You know, are they buying a slice of a SOC somewhere else? That's the service that we offer, but I think, suffice to say, there's not enough security people watching all this data to make sense of it right. That's the biggest battle I think going forward. We can't make enough people doing that, that requires a lot of analytics, right. >> Which really then begs, for the standalone single enterprise, that they really need help, right? They're not going to be able to hire the best of the best for their individual company. They're not going to be able to leverage you know best-in-breed, Which I think is kind of an interesting part of the whole open-source ethos, knowing that the smartest brains aren't necessarily in your four walls. That you need to leverage people outside those four walls. So, as it continues to morph, what do you see changing now? What are you looking forward to here at RSA 2018? >> So I made some big predictions five years ago, so I'll say you know, five years from now, I think we're going to see a lot more companies outsource major parts of their security right, and that's just because you can't do it all in-house right. There's got to be a lot more specialization. There's still people today buying AI products right, and having machine learning models they invest in to, there's no company I'm aware of, unless they're, you know, maybe the top five financial firms out there, that should have a, you know, security focused data scientist on staff, right? And if you have somebody like that in your environment, you're probably not spending money the right way, right. So, I think security is going to get outsourced in a pretty big way. We're going to focus on outcomes more and more. I think the question is not going to be, "What algorithm are you using to identify this breach?" The question is going to be, "How good are your identifying breaches?" Period. And some of the companies that offer those outcomes are going to grow very rapidly. And some of the companies that offer just, you know, picks and shovels, are going to probably not do nearly as well. >> Right. >> So five years from now, I'll come back and we'll talk about it then. >> Well, the other big thing, that's going to be happening in a big way five years from now, is IoT and IIoT and 5G. So, the size of the attacked surface, the opportunities to breach-- >> The data volume. >> The data volume, and the impact. You know it's not necessarily stealing credit cards, it's taking control of somebody's vehicle, moving down the freeway. So, you know, the implications are only going to get higher. >> We collect a lot of logs from our customers. Usually, the log footprint, grows at three times the rate of our revenue and customers, right. So, you know, thank god-- >> The log, the log-- >> The log volume grows-- >> volume that you're tracking for a customer, grows at three times your revenue for that customer? >> That's right. I mean, they're not growing at three times that rate, annually right, but annually, you know, we've clocked anywhere between 200% to 300% growth in data that we collect from them, IoT makes that absolutely explode, right. You know, if every device out there, if you actually are watching it, and if you have any chance of stopping the breaches on IoT networks, you got to collect a lot of that data, that's the fuel for a lot of the machine learning models, because you can't put human eyes on small RTUs and you know, in factories. That means even more data. >> Right, well and you know the model that we've seen in financial services and ad-tech, in terms of, you know, an increasing amount of the transactions are going to happen automatically, with no human intervention, right, it's hardwired stuff. >> So I think it's that balance between data size and data volume, analytics, but most important, what do you feed the humans that are sitting on top of it? Can you feed them just the right signal to know what's a breach and what's just noise? That's the hardest part. >> Right, and can you get enough good ones? >> That's right. >> Underneath your own, underneath your own shell, which is probably, "No", well, hopefully. >> I think building this from scratch for every company is madness, right. There's a handful of companies out there that can pull it off, but I think ultimately everybody will realize, you know, I'm a big audio nerd so I Looked it up, right, you used to build all of your own speakers, right. You'd buy a cabinet and you'd buy some tools, and you would build all the stuff. Now you go to the store and you buy an audio system, right? >> Right, yeah, well at least audio, you had, speakers are interesting 'cause there's a lot of mechanical interpretations about how to take that signal and to make sound, but if you're making CDs you know you got to go, with the standard right? You buy Sonos now, and Sonos is a fully integrated system. What is Sonos for security, right? It doesn't exist yet. And that's, I think that's where Security as a Service is going. Security as a Service should be something you subscribe to that gives you a set of outcomes for your business, and I think that's the only way to consume this stuff. It's too complex for somebody to integrate from best-of-breed products and assemble it just the right way. I think the parallels are going to be exactly the same. I'm not building my car either, right? I'm going to buy one. Alright Misha, well, thanks for the update, and hopefully we'll see you before five years, maybe in a couple and get an update. >> We'll do some checkpoints along the way. >> Alright. Alright, he's Misha, I'm Jeff. You're watching theCUBE from RSA North America 2018 in downtown, San Francisco. Thanks for watching. (techno music)

Published Date : Apr 18 2018

SUMMARY :

of little answers to help you get kind of closer to nirvana. Did you predict it? But it's certainly happening, right. as the dominance of public cloud continues to grow, And the answer is obviously, it does There's no shortage of things for people to worry about. So it's almost, you know how fast can you catch it? That's the reason why, you know last year, and you know, he's got so many resources and you can build it using some of At the other hand, you just can't use and some of the classic breaches we've seen, But I think it's really important, because as you said, And the answer a lot of times is, you can't. to figure out the pattern, that you can even start, There's not, you know, not every company has a SOC right? So, as it continues to morph, what do you see changing now? And some of the companies that offer just, you know, So five years from now, the opportunities to breach-- So, you know, the implications are only going to get higher. So, you know, thank god-- and you know, in factories. Right, well and you know the model what do you feed the humans that are sitting on top of it? Underneath your own, underneath your own shell, and you would build all the stuff. I think the parallels are going to be exactly the same. RSA North America 2018 in downtown, San Francisco.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
MishaPERSON

0.99+

AmazonORGANIZATION

0.99+

Jeff FrickPERSON

0.99+

JeffPERSON

0.99+

Misha GovshteynPERSON

0.99+

100%QUANTITY

0.99+

96%QUANTITY

0.99+

last yearDATE

0.99+

James HamiltonPERSON

0.99+

30 web shellsQUANTITY

0.99+

20 billionQUANTITY

0.99+

20 petabytesQUANTITY

0.99+

SonosORGANIZATION

0.99+

15%QUANTITY

0.99+

MicrosoftORGANIZATION

0.99+

Alert LogicORGANIZATION

0.99+

85%QUANTITY

0.99+

less than a dayQUANTITY

0.99+

GoogleORGANIZATION

0.99+

45,000 peopleQUANTITY

0.99+

45,000QUANTITY

0.99+

five years agoDATE

0.99+

This yearDATE

0.99+

Five years agoDATE

0.99+

AWS'ORGANIZATION

0.99+

two endsQUANTITY

0.99+

one endQUANTITY

0.99+

thousandsQUANTITY

0.99+

200%QUANTITY

0.99+

AWSORGANIZATION

0.99+

CUBEORGANIZATION

0.98+

oneQUANTITY

0.98+

GDPRTITLE

0.98+

one personQUANTITY

0.98+

Tuesday nightDATE

0.97+

300%QUANTITY

0.97+

singleQUANTITY

0.97+

three timesQUANTITY

0.97+

EquifaxORGANIZATION

0.96+

theCUBEORGANIZATION

0.95+

Black HatORGANIZATION

0.94+

five financial firmsQUANTITY

0.94+

one thingQUANTITY

0.93+

RSA 2018EVENT

0.93+

one dominoQUANTITY

0.93+

about a hundred daysQUANTITY

0.93+

40,000 plus peopleQUANTITY

0.92+

Each oneQUANTITY

0.89+

North American Conference 2018EVENT

0.86+

todayDATE

0.85+

downtown San FranciscoLOCATION

0.83+

InstagramORGANIZATION

0.82+

Fortune 2000ORGANIZATION

0.8+

applicationsQUANTITY

0.79+

about a monthQUANTITY

0.79+

San FranciscoLOCATION

0.77+

GodPERSON

0.7+

five yearsQUANTITY

0.7+

five yearsDATE

0.69+

2018DATE

0.68+

North America 2018EVENT

0.65+

RSA North AmericaTITLE

0.63+

coupleQUANTITY

0.62+

RSAORGANIZATION

0.6+

GCPTITLE

0.6+

SecurityTITLE

0.58+

RSAEVENT

0.51+

annuallyQUANTITY

0.51+

AzureORGANIZATION

0.5+

nickelQUANTITY

0.48+

TargetORGANIZATION

0.45+

RSA North America 2018EVENT

0.43+

Michael DeCesare, ForeScout Technologies | RSA North America 2018


 

>> Announcer: From downtown San Francisco, it's theCUBE. Covering RSA North America 2018. >> Hey welcome back everybody, Jeff Frick here with theCUBE. We're at RSA North America 2018 in San Francisco. 40,000 plus people talking security, enterprise security, cloud security, a lot going on. It just continues to get more and more important. And we're really excited for our next guest who's been playing in the enterprise space for as long as I can remember, which has been a little while. Mike Decesare, he's the CEO and President of ForeScout. Mike, great to see you. >> Started my career off when I was one. (Jeff laughs) So, I've been in this for a long time. >> You have been in it a long time. So you guys now you're all about, right so there's so much stuff going on in security and security is one of these things that I have to look at it as kind of like insurance. You can't put every last nickel in security, but at the same time, you have to protect yourself. The attack surfaces are only growing with IIoT and we were at an autonomous vehicle show, and 5G is just coming around the corner, and all these connected devices and APIs. So you guys have a pretty unique approach to how you top level think about security called visibility. Explain that to us. >> So visibility is the next big thing in the world of cybersecurity and the dynamic is very basic. It's, for 20 plus years, CIOs and CSOs were substantially able to control everything that was on their network. You'd buy your servers and Windows machines and Blackberries for your employees and then there was very little tolerance for other devices being on those organization's networks. And what happened 10 years ago this year, with the birth of the iPhone was that CIOs, those same CIOs now had to deal with allowing things onto their network that don't subscribe to those same philosophies and when you can't buy it and outfit it with security before you put it into the environment. And that's the gap that ForeScout closes for organizations is we have an agentless approach which means we plug into the network infrastructure itself and we give customers visibility into everything that is connected to their network. >> So that begs a question, how do you do that without an agent? I would imagine you would put a little agent on all the various devices. So what's your technique? >> We actually don't. That's the secret sauce of the company is that >> okay >> you know over 10 years ago, we recognized this IoT trend coming because that's, that's the thing in the world of IoT is unlike the first kind o' 20 years of the internet, there was a substantially smaller number of operating systems, most of them open. The different characteristic about the current internet is that many of these use cases are coming online as closed proprietary operating systems. The example I use here is like your home. You know, you get a Nest thermostat and you put in on your network and it monitors, you know, heating and cooling but the device, the operating system, the application is all one consumer device. It doesn't run Windows. You can't install antivirus on you Nest thermostat. So our approach is we plug into the network infrastructure. We integrate to all of the network vendors, the firewall vendors, the wireless controlling vendors and we pull both active and passive techniques for gathering data off those devices and we translate that into a real-time picture of not just everything connected to the network but we know what those devices are without that client having to do anything. >> So you have what you call device cloud or yeah, ForeScout device cloud. So is that, is that a directory of all potential kind of universe of devices that you're querying off of or is that the devices within the realm of control of your of your clients directly? >> It's the second. It's the, so the way that our product works is we plug into the network infrastructure so anything that requests an IP address, whether is wired and wireless in the campus environment, whether it's data center or cloud in the data center environments or even into the OT space, anything that requests an IP address pops onto our radar the second it requests that address. And that cloud that we've built, that we've had for about nine months, we already have three million devices inside, almost three and a half million devices, is a superset of all of the different devices across our entire install base just from the clients that have been willing to share that data with us already. And that gives us optimism because what that becomes is a known set of fingerprints about all known devices so the first time that we discover a Siemens camera that might be a manufacturer, the company might have ten thousand of those in the environment, the first time that we see that device, we have to understand the pattern of traffic off that device, we label that as a security camera and any other customer world-wide that's has that same device connects, we instantaneously know it's a Siemens security camera. So we need the fingerprint of those devices once. >> Right, and so you're almost going to be like the GE Predix of connected devices down the road potentially with this cloud. >> We won't go there on that. >> He won't go there, alright. We've talked to Bill Ruh a lot of times but he does an interesting concept. The nice thing 'cause you can leverage from a single device and knowledge across the other ones which is so, so important on security so you can pick up multiple patterns, repeated patterns et cetera. >> One of the best parts about ForeScout is the fact that we deployed incredibly quickly. We have clients that have almost a million devices that got live in less than three months. And the reason we're able to do that is we plug into the infrastructure, and then our product kind o' does its own thing with very little effort from the client where we compare what we have in this repository against what they have in their environment. We typically get to an 80 or 90% auto-classification meaning that we know 80 or 90% of the time, not just what's on the network but what that device is and then the other 20% is where we have the implementation where we go through and we look at unique devices. It might be a bank has some model of ATM we've never seen before or a healthcare company has beds or machines on a hospital floor that we haven't recognized before. And the first time that we see each of those devices uniquely, we have to go through the process of fingerprinting it which means that we're looking for the unique pattern of traffic that's coming off a, you know, a router, a switch and a firewall and we're ingesting that and we're tagging that device and saying anytime we see that unique pattern of traffic, that's a certain device, a security camera or what have you. >> Right. >> The reason's that useful is then we get to put a policy in place about how those devices are allowed to behave on the network. So if you take something like the Mirai Botnet which hit about a year ago, was the thing that took down a big chunk of the Northeast, you know, utilities and you know, internet, it infected, it was a bot that infected security cameras predominantly. Nobody thought twice about having security cameras in their environment, but they're the same as they are in your house where you know, you put it online, you hit network pair and it's online. >> Right. >> But that bot was simply trying to find devices that had the default password that shipped from the security manufacturer and was able to be successful millions of time. And with our product in place, that couldn't happen because when you set us up, we would know it's a security camera, we'd put a policy in place that says security camera can speak to one server in the data center called the security camera server. And if that device tries to do anything more criminal, if it tries to dial the internet, if it tries to break into your SAP backend, any of those activities, we would give the customer the ability to automatically to take that device offline in real time. >> Right, so you're... >> And that's why our clients find us to be very useful. >> Right, so you're really segregating the devices to the places they're supposed to play, not letting 'em out of the areas they're supposed to be. Which is the >> Absolutely. >> Which is the classic kind of back door way in that the bad guys are coming in. >> Our philosophy is let everything onto the network. We take a look at that traffic. We give you a picture of all those devices and we allow each customer to put an individual policy in place that fences that in. If you take the other extreme like a Windows machine in a corporate environment, our typical policy will be you know, do you have Windows 2009 or later? 'Cause most customers have policies they don't want XP in their environments anymore. But we enforce it. So if an XP device hits the network, we can block that device or we can force a new version down. If you have Symantec, has it got a dat file update? If you've got Tenable, has it had a scan recently? If you've got, you know, any of the other products that are out there that are on those machines, our job is to enforce that the device actually matches the company's policy before that device is allowed in. >> Before you let it. Alright. >> And if at any time that it's on that network, it becomes noncompliant, we would take that device offline. >> You know, with the proliferation of devices and continuation growth of IoT and then industrial IoT, I mean, you guys are really in a good space because everything is getting an IP address and as you said, most of them have proprietary operation systems or they have some other proprietary system that's not going to allow, kind o' classic IT protections to be put into place. You've really got to have something special and it's a pretty neat approach coming at it from the connectivity. >> It's the secret sauce of the company is we recognized many years ago that the the combination of not just there being very few operating systems but they were all open. Windows, Lennox, right? I mean, you can buy a Windows machine and you can install any product you want on it. But we saw this trend coming when the next wave of devices was going to be massively heterogeneous and also in many cases, very closed. And you know, you mentioned the example of the OT space and that's one of the other, the third biggest driver for us in our business is the OT space because when you looking a WanaCry or a NotPetya and you see companies like Maersk and FedEx and others that are, that are publicly talking about the impact of these breaches on their earnings calls. What those companies are waking up and realizing is they've got 25 year old systems that have run, you know, an old version of Microsoft that's been end-of-life decades ago and the bad actors have proven very adept at trying to find any entry point into an organization, right, and the great news for ForeScout is that really lends itself very much towards our age-endless approach. I mean, many of these OT companies that we're in, devices that are in their manufacturing facilities don't even have an API. There were built so long ago so there's no concept of interacting with that machine. >> Right >> So for us, allowing that device to hit the Belden switches and then be able to interrogate the traffic coming off those switches let's us do the same thing that we do in the campus world over in the OT world as well. >> Good spot to be. So RSA 2018, what are ya looking forward to for this week? >> This is just massive in size. It's like speed dating. From a customer's perspective too, I mean, I meet so many customer's that come here and able to meet with 30 or 40 vendors in a single week and it's no different, you know, for the providers themselves so. You know, we've got some really, kind o' really high profile big wins, you know, it's very coming for us to be doing deals at this point that get up over a million devices so they're very high profile so it's a great chance to reconnect with customers. You know, one of the things I didn't mention to you is that kind o' the, the whole thing that we do of identifying devices and then understanding what they are and allowing those policies to get put in places, that's fundamentally done with our own IP, and the connections into the switch and firewall vendors. But we've built this whole other ecosystem of applications in the world of orchestration that set on top of our products. We integrate the firewall vendors, the vulnerability management vendors, the EDR vendors, the AV vendors, so it's a great chance for us to reconnect with you know, those vendors as well. In fact, we're doing a dinner tonight with CrowdStrike. They're one of our newer partners. Very excited about this week. It brings a lot of optimism. >> Well, great story Mike and excited to watch it to continue to unfold. >> We appreciate you giving us some time. >> Alright, thanks for stopping by. That's Mike Decesare. I'm Jeff Frick. You're watching theCUBE from RSA North America 2018. Thanks for watchin'. Catch you next time. (techno music)

Published Date : Apr 18 2018

SUMMARY :

Announcer: From downtown San Francisco, it's theCUBE. Mike Decesare, he's the CEO and President of ForeScout. So, I've been in this for a long time. but at the same time, you have to protect yourself. and the dynamic is very basic. all the various devices. That's the secret sauce of the company and it monitors, you know, heating and cooling or is that the devices within the realm of control of your about all known devices so the first time that we discover a of connected devices down the road from a single device and knowledge across the other ones is the fact that we deployed incredibly quickly. So if you take something like the Mirai Botnet that had the default password that shipped from the not letting 'em out of the areas they're supposed to be. Which is the classic kind of back door way in that So if an XP device hits the network, Before you let it. it becomes noncompliant, we would take that device offline. and as you said, most of them that are publicly talking about the impact of these breaches and then be able to interrogate Good spot to be. You know, one of the things I didn't mention to you is that and excited to watch it to continue to unfold. Catch you next time.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
Jeff FrickPERSON

0.99+

30QUANTITY

0.99+

80QUANTITY

0.99+

25 yearQUANTITY

0.99+

Mike DecesarePERSON

0.99+

SymantecORGANIZATION

0.99+

FedExORGANIZATION

0.99+

MicrosoftORGANIZATION

0.99+

Michael DeCesarePERSON

0.99+

Bill RuhPERSON

0.99+

MaerskORGANIZATION

0.99+

90%QUANTITY

0.99+

MikePERSON

0.99+

20 plus yearsQUANTITY

0.99+

first timeQUANTITY

0.99+

less than three monthsQUANTITY

0.99+

eachQUANTITY

0.99+

GEORGANIZATION

0.99+

SiemensORGANIZATION

0.99+

JeffPERSON

0.99+

20%QUANTITY

0.99+

San FranciscoLOCATION

0.99+

XPTITLE

0.99+

three million devicesQUANTITY

0.99+

40,000 plus peopleQUANTITY

0.99+

40 vendorsQUANTITY

0.99+

tonightDATE

0.99+

ForeScout TechnologiesORGANIZATION

0.99+

CrowdStrikeORGANIZATION

0.99+

twiceQUANTITY

0.99+

iPhoneCOMMERCIAL_ITEM

0.99+

one serverQUANTITY

0.99+

Windows 2009TITLE

0.99+

ten thousandQUANTITY

0.98+

ForeScoutORGANIZATION

0.98+

each customerQUANTITY

0.98+

about nine monthsQUANTITY

0.98+

WindowsTITLE

0.98+

secondQUANTITY

0.97+

oneQUANTITY

0.97+

almost three and a half million devicesQUANTITY

0.97+

single deviceQUANTITY

0.97+

OneQUANTITY

0.97+

firstQUANTITY

0.97+

NotPetyaORGANIZATION

0.96+

this weekDATE

0.96+

bothQUANTITY

0.96+

WanaCryORGANIZATION

0.95+

over a million devicesQUANTITY

0.95+

RSA North AmericaORGANIZATION

0.93+

10 years ago this yearDATE

0.93+

almost a million devicesQUANTITY

0.92+

third biggest driverQUANTITY

0.9+

millions of timeQUANTITY

0.9+

ForeScoutTITLE

0.89+

LennoxORGANIZATION

0.88+

Mirai BotnetORGANIZATION

0.82+

2018DATE

0.8+

TenableORGANIZATION

0.78+

20 yearsQUANTITY

0.78+

about a year agoDATE

0.75+

RSA 2018EVENT

0.75+

decades agoDATE

0.75+

over 10 years agoDATE

0.74+

NortheastLOCATION

0.74+

single weekQUANTITY

0.73+

many years agoDATE

0.72+

SAPORGANIZATION

0.64+

waveEVENT

0.59+

2018EVENT

0.54+

theCUBEORGANIZATION

0.54+

BeldenORGANIZATION

0.33+

Sean Cunningham, ForgePoint Capital | RSA North America 2018


 

>> Presenter: From downtown San Francisco, it's theCUBE, covering RSA North America 2018. >> Hey, welcome back, everybody. Jeff Frick here with the theCUBE. We're in downtown San Francisco with RSA North America 2018 40,000 plus professionals talking about security, enterprise security. It's a growing field, it's getting baked into everything. There's a whole lot of reasons that this needs to be better and more integrated into everything that we do, as opposed to just kind of a slap on at the end. And, who better to have on, who's investing at the cutting edge, keeping an eye on the startups than Sean Cunningham, our next guest. He's a managing director ForgePoint Capital, the newly named, so welcome to ForgePoint Capital, I guess. (Sean laughs) >> Thanks, Jeff, we're pretty excited about it. So, we were branded Trident Capital Cybersecurity. We're a 300 million dollar cybersecurity only fund, we closed the fund about a year and a half ago. We've invested in a dozen companies, and we decided that now is a great time to rebrand ForgePoint really tells more about what we're doing, we're forging ahead with our Series A, Series B funded companies, as well as a few growth equity. So, it made a lot of sense, but we're pretty excited about the market, and obviously RSA, with 1700 cybersecurity companies makes it interesting. >> Right, so you've been at this for a while. I wonder if you can speak to some of the macro trends as we've seen the growth of cloud, the growth of IoT will soon be more industrial IoT, enabled by 5G. We've got all these automated systems and financial services trading, and ad tech that we're going to see more and more of that automated transaction happening. You've got APIs and everything's connected to everything else to enable my application. So, really really exciting, and huge, growing threat surface if you will, but at the same, these are the technologies that are driving forward. So, what are you seeing from your, seat at the table some of the newer, more innovative startups? >> Jeff, I think you should probably tell me. You have all the answers there. >> I talked to a lot of smart people, that's the benefit of the job. >> I think the only two buzzwords you left off was Bitcoin and fraudulent payments. >> Oh, we can work a little blockchain in if you want. >> Yeah, but it is absolutely a bit of an interesting environment. I've been doing it since 2000 with Intel Capital for 15 years, but what's really changed, what hasn't changed is the fact that it's all about the hackers are able to monetize this. So, that's not going away. The biggest change are the, I guess, overt nation state attacks. So, between all of those things, the drivers are just continuing to force cybersecurity to become better and better. And, that's why the innovative startups are really, you're seeing these 1700, because the legacy companies can't fix these problems. And, you know, you talk about all these different paths for hackers to get in. It's absolutely the case and we are really big on areas, as you mentioned Jeff, the automation. It has to be about automating. It has to be about having a real solution for a real problem. You know, you look at, let's say 1500 of these security startups, a lot of them are about technology for the sake of technology. So, we're pretty excited about a couple of areas. One, is application security. If you think about the Equifax hack, you know, it's as simple as getting into the website and being able to hack into all of the PII data if you will. And, we've invested in a company called Prevoty and what they do is they make it easy for the application security folks to meet with the DevOps folks and inject the software into these applications. The reason why that's really interesting is, if you think about how long it takes for the DevOps guys to get all their new updates out, through that whole cycle, when you could automate that process and reduce that time to market, that's what it's really all about. >> So, what's your take on GDPR. You know, it's past a little while ago, the enforcement comes into place next month. It's weird what's going on with Facebook right now. I don't ever hear GDPR in the conversation of what's going on, and yet, it's just around the corner and it seems like it would be part of that conversation. DC is just king of a Y2K moment, where there's a lot of buzz and the date hits and we get past it and then we kind of move on with our lives, or is this really a fundamental shift in the way that companies are going to have to manage their data? >> Well, I can show you my scars from investigating compliance companies. I think the winners in that space, from a business standpoint are going to be the consultant companies, initially and at some point then, the legacy guys are going to be also involved, as well as some of the startups. But, clearly, until you see some of the large penalties happen, there's not going to be a lot of movement. There's going to be a lot of hand waving and consulting firms are trying to figure out what's your problem, how do we solve it. So, you're going to see, I'm sure, around the floor a lot of GDLP stuff, but we're being very cautious about where we invest there because, as you say, Y2K and a lot of this is going to be a lot fud. The legacy guys are going to say, oh we can handle that. Same as they did with cloud. Look how long it's taking cloud to get adopted, my God. I mean-- >> Right. >> GDRP is a big piece of that. We did investments in that space, around CASB, it's called. And, we invested in a company called Prelert. It had great traction, but then it just kind of topped out. So, it's going to be investable space and there's going to be a lot of money dumped in there because it's, you know, the Lemming effect. All VCs are going to follow that. >> Right. >> We'll see what happens. >> And then on the cloud, you know, with the growth of public cloud with Amazon and Azure and Google Cloud Platform, and they've got significant resources that they're investing into the security of their clouds and their infrastructure. And, yet, we still hear things happen all the time where there's some breach because somebody forgot to turn a switch from green to blue, or whatever. How did the startups, you know, kind of find their path within these huge public cloud spaces to find a vector that they can concentrate on, that's not already covered by some of these massive investments that the big public cloud people are making? >> Yeah, I think some of the, you know you point something out, I mean we got to think about cloud, you think about the public cloud, you think of private cloud and hybrid model and so on. I think that's really where things are going to to be for a while. The big guys, the big companies, enterprises are not putting a lot of their crown jewels out in the public clouds, yet. And, so the private clouds are equally important to them. And, so they have to be secured. And, the public cloud, you know, there's definitely they have some good security, but they quietly are implementing security from innovative companies also. They're not as public about it because they want to have they're already secure, so don't worry about me, but there's a lot of opportunity there. >> Okay, and then when CIOs are talking about security and thinking about security, ultimately they cannot be 100 percent secure, right, it's just you cannot be. >> It's called job security. >> Yeah, job security for us, right. But, I was thinking of this kind of as an insurance model. At some point, you get kind of the law of diminishing returns and you got to start making business trade-offs for the investment. How are these people thinking about this, at the same time, seeing their competitors and neighbors showing up on the cover of the Wall Street Journal breach after breach after breach? What's the right balance? How should they be thinking about managing risk, and thinking of a risk problem as opposed to kind of a castle problem? >> Yeah, and that's the biggest problem with CIOs and CSOs right now. It's all about what's good enough. Where do I reach that threshold? And, so there is definitely buyer fatigue. And, I think it's a matter, there are companies out there that look at the risk profile and are actually giving ratings of, what is your environment look like. We just invested in a spin out from, we helped spin out a company called CyberCube out of Symantec, and it's insurance. And, they're looking at, from a cyber insurance perspective, of what's your risk profile within your organization and selling and that data from Symantec as well as the data they have and going back to the insurance, the under buyer and saying, hey, we can show you the risk profile of this company and you can properly price your cyber insurance now. We all know how large the cyber insurance market is, so there's a lot of opportunities in that space to really look at the risk factors. >> Alright, well before I let you go, to go visit all the 117 startups, which will be looking for your cheque, I'm sure. >> Human ATM. >> What is one or two things that you think about in some of the more progressive startups that you talk about that still hasn't kind of hit the public eye yet. That they should be thinking about, or that we're going to be talking about in a couple years that's still kind of below the radar? >> Yeah, you know, if I told you then everyone else would be-- >> That's true. >> So, I have to be a little careful. You know, I think the interesting thing is, you know, a bit of a contrarian view. Is, if you think about consumer space, people don't really want to invest. Investors don't want to put money in the consumer, but you think about Symantec again, LifeLock. Identity protection, 2.3 billion dollars Symantec paid to get LifeLock. That's a lot of money. But, if you think about five years ago, how many consumers would pull out their Visa card to buy security. So, we think that there's really a potential opportunity on the consumer side. Now, AV is pretty well scorched earth. A lot of places, a lot of these endpoint things are scorched earth, but consumer might be an interesting place to be able to take these enterprise applications and, what I call, the consumerization of security, and take some of those interesting application and solutions and bring them down to the consumer in a bundle type of environment. >> Yeah, well certainly with all the stuff going on with Facebook now, people's kind of reawakening at the consumer level of what's really happening would certainly be fuel for that fire. >> We have an investment in a company called IDEXPERTS, which does breach remediation and our goal right now is we're continuing to add products from that space to be able to give the consumers a very robust offering. >> Alright, Sean, well thanks for taking a few minutes out of your day from prospecting. >> Yeah, pleasure. >> Over on the floor, he's Sean Cunningham, I'm Jeff Frick. You're watching theCUBE from RSA North America 2018 in downtown San Francisco. Thanks for watching, I'll see you next time. (upbeat music)

Published Date : Apr 18 2018

SUMMARY :

Presenter: From downtown San Francisco, it's theCUBE, as opposed to just kind of a slap on at the end. about the market, and obviously RSA, So, what are you seeing from your, seat at the table You have all the answers there. I talked to a lot of smart people, I think the only two buzzwords you left off and being able to hack into all of the PII data if you will. and the date hits and we get past it Y2K and a lot of this is going to be a lot fud. a lot of money dumped in there because it's, you know, How did the startups, you know, kind of find their path And, the public cloud, you know, there's definitely 100 percent secure, right, it's just you cannot be. and you got to start making business trade-offs Yeah, and that's the biggest problem with CIOs Alright, well before I let you go, to go visit all about in some of the more progressive startups So, I have to be a little careful. at the consumer level of what's really happening to be able to give the consumers a very robust offering. of your day from prospecting. Over on the floor, he's Sean Cunningham, I'm Jeff Frick.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
JeffPERSON

0.99+

Sean CunninghamPERSON

0.99+

SymantecORGANIZATION

0.99+

Jeff FrickPERSON

0.99+

SeanPERSON

0.99+

ForgePoint CapitalORGANIZATION

0.99+

oneQUANTITY

0.99+

100 percentQUANTITY

0.99+

15 yearsQUANTITY

0.99+

1500QUANTITY

0.99+

PrelertORGANIZATION

0.99+

2.3 billion dollarsQUANTITY

0.99+

AmazonORGANIZATION

0.99+

Y2KORGANIZATION

0.99+

2000DATE

0.99+

117 startupsQUANTITY

0.99+

PrevotyORGANIZATION

0.99+

next monthDATE

0.99+

IDEXPERTSORGANIZATION

0.99+

GDPRTITLE

0.99+

Series BOTHER

0.99+

FacebookORGANIZATION

0.98+

two thingsQUANTITY

0.98+

Series AOTHER

0.98+

CyberCubeORGANIZATION

0.98+

Intel CapitalORGANIZATION

0.97+

1700 cybersecurityQUANTITY

0.97+

EquifaxORGANIZATION

0.97+

Trident Capital CybersecurityORGANIZATION

0.97+

five years agoDATE

0.96+

two buzzwordsQUANTITY

0.96+

300 million dollarQUANTITY

0.95+

OneQUANTITY

0.93+

CASBORGANIZATION

0.93+

a year and a half agoDATE

0.93+

40,000 plus professionalsQUANTITY

0.92+

1700QUANTITY

0.9+

5GORGANIZATION

0.87+

San FranciscoLOCATION

0.87+

ForgePointORGANIZATION

0.87+

dozen companiesQUANTITY

0.86+

GoogleORGANIZATION

0.86+

LifeLockORGANIZATION

0.84+

2018DATE

0.82+

downtown San FranciscoLOCATION

0.81+

RSA North AmericaORGANIZATION

0.81+

GDLPORGANIZATION

0.79+

Visa cardCOMMERCIAL_ITEM

0.78+

Wall Street JournalORGANIZATION

0.75+

theCUBEORGANIZATION

0.75+

DevOpsTITLE

0.73+

LifeLockCOMMERCIAL_ITEM

0.73+

GDRPORGANIZATION

0.71+

earthLOCATION

0.71+

RSA North America 2018TITLE

0.67+

aboutDATE

0.66+

AzureORGANIZATION

0.62+

RSAORGANIZATION

0.62+

Cloud PlatformTITLE

0.62+

AmericaORGANIZATION

0.61+

2018EVENT

0.61+

DCORGANIZATION

0.6+

RSA NorthTITLE

0.59+

couple yearsQUANTITY

0.53+

Y2KEVENT

0.49+

Jason Brvenik, NSS Labs | RSA North America 2018


 

>> Announcer: From downtown San Francisco, it's The Cube, covering RSA North America 2018. >> Welcome back, Jeff Frick with The Cube. We're at RSAC, the RSA Conference North American in San Francisco, 2018. 40,000 people, it's an amazingly huge and growing conference, 'cause security is obviously at the forefront of everything, especially as everything moves to devices and services and cloud, we can't forget security and we're excited to have somebody who's kind of got to a third-party validation kind of point of view on the marketplace to get their perspective. It's Jason Brvenik and he is the Chief Technology Officer for NSS Labs. So, Jason, great to meet you. >> Great to meet you. >> So for people that aren't familiar with NSS Labs, give us kind of the overview of what you guys are all about. >> We work with enterprises to understand their needs in security, and then, build and create test environments that create real-world conditions to assess whether or not a product is a good fit. We create comparable environments, so that we can understand fundamentally whether or not the products are delivering on their claims. >> Right, and recently you've done some work around the data center intrusion prevention systems group test. >> Mm-hmm. >> It's a mouthful. What is that all about? >> Well, that's all about the recognition that data centers are the keys to access for most organizations and appropriately protecting them is not as easy as deploying a firewall. You need to have much greater inspections on the interactions with systems, whether or not security's being provided within the application layers, being properly secured, and so, latency and performance and effectiveness against attacks are all measured and then presented in a set of group test reports. >> Right. So, must be getting increasingly complex, 'cause there's all these different components now that build up a solution. Right? It's not just one set of applications, that you're pulling maybe public data sources, you've got a bring-your-own-devices, you've got this huge string of things that are all pulled together. How do you incorporate that into your testing? How do you figure out how these things work together? 'cause ultimately, that increases your attack surface area, vulnerabilities, I would imagine. >> Certainly, and we create an environment, an architecture that we propose, that based on our interactions with the enterprises, it's fairly representative of what an enterprise would have, and then we create or simulate the types of interactions you would have with the different systems, generate attacks against them, and measure whether or not the products are able to sustain a concerted attack from an adversary. All the way into creating evasive techniques, so that an attack that is known to be blocked by a technology, we would apply different techniques to make it evasive and see if we can evade the security controls and to measure those. >> So how accurate are people, not to call anybody up, but how accurate are people in assessing the effectiveness of their own products and solutions? >> That's an interesting mixed bag. >> I'm sure it must run the gamut, right? >> It does, it does. >> Well, we don't want to call out any, beat anybody up, but I would imagine there are some that are just, Are they just looking at the wrong thing? Or how do you sort that all out? >> It's interesting to see the different perspectives that exist in the security space. Everything from just make the pain stop, where they want to do simple signature blocking to, we really want to understand what's happening and dig deep into the protocols and interactions and understand what's an appropriate interaction beyond whether or not there's an attack there. The fundamental premise we have in our space is there's an absolute shortage of talent in the security space that understands that just because the standard says something should be, doesn't mean that an attacker has to adhere to it. And so there's a ton of breaks in that. >> Dang. And what are some of the things that people just miss as the attack surfaces change? And I just think of the fully automated systems like we've seen in ad tech and advanced financial trading systems that are now moving more and more into an increasing group of applications that are going to be IoT-enabled, they're all going to be connected with 5G moving very quickly, so the potential for problems becomes pretty significant if there's a bad actor that gets inserted into that process. >> Certainly and it's interesting that the attackers seem to have automation down pretty well. They can get in and move laterally pretty quickly. >> Right. >> And ferreting out attacker behavior from just bad user behavior can be very difficult. The presumptions that a lot of technologies because the standard says something should be, it will be, create these situations where people aren't effectively looking for the ambiguities and standards, and those are abused all the time. When you look at embedded devices, they get deployed and they stay for 10 years. >> Jeff: Right. >> That's 10 years of technical data that's just deployed and waiting to be exercised and exploited, and having a good general hygiene on an operational environments to understand where these rifts are is probably the biggest gap in the Enterprise world. On the security side, the reliance on standards and the reliance on assumptions of what should be tend to continue, come back, and bite vendors, all right? >> It's funny. So you say just general hygiene and we talked about that in one of the prior interviews where often we'll hear, say, there's a Amazon breach or something and you get to the second paragraph and it's because somebody forgot to set a configuration in the right way, so it's not necessarily the technology or the infrastructure or the safeguards that are put up, it's just somebody forgot to turn the switch on. >> It is. >> So, why these things, general hygiene is still such a problem, is it just because it's so complex, things are moving so fast, people are just too busy? Is it a symptom of dev ops? >> We're human, we're human. >> There we go. >> There's a 1000 things demanding our attention all the time, and without solid processes and procedures, it's easy to miss something. And it's easy in the moment when you've got a big project that needs to launch to say that can wait until next week and then the next big project comes along and next week is here and it waits until the week after. Next thing you know, it's forgotten and you've got an old piece of architecture, infrastructure or security out there that just isn't being maintained anymore. >> Right. >> It's one of the reasons we created an environment that strives to do what we call continuous security validation. So even if you had the best security technologies in the world, it's indistinguishable from no security at all until a breach occurs, right? And so, continuous security validation allows us to look at live attacks that you're usually going to face, measure whether or not your security is deployed, is delivering all protections against them, and highlights there's a gap, simply because you're human. The best technology in the world isn't going to work if you're not managing it well. >> Right. So, are you creating kind of like a digital twin of the key components of my environment back in your lab? Or are you putting things in my system so that you can do this kind of continual monitoring? >> We create, effectively, a virtual remote office and then deploy your security controls and then we attack that remote office for you. And measure whether or not your security controls are being effective and whether or not your people with those controls are able to respond effectively. >> So what's been the impact of public cloud? Of the rise of public cloud? Both obviously, for those applications that are sitting in the public cloud from the Enterprise perspective, but now it's creating this kind of hybrid situation where they've still got stuff in the data center, they've got stuff in the public cloud, there's probably some stuff that's migrating in between, maybe it's tested to have in the public cloud and it gets deployed internally, or maybe they're trying to do a lift-and-shift out of the data center, so how has the rise of public cloud and with the hybrid cloud and multi-cloud environments impacted your guys' world? >> Oh, the biggest shift there, I think, is in the proliferation of what otherwise would have been well-controlled development environments into production environments. It's so easy to move what evolved in developing a technology into a production world without going in and paying attention whether or not all of the right elements are in play. So it used to be you developed it, then you moved it into QA and then from QA, it got moved into production. Now you go right from Dev to Production and QA kind of happens in the background. >> Right, right. And we talked in an earlier conversation, too, which is before then this security would be layered on after the test dev, once it was moving in production. Well, let's slap some security on it, but now it's got to be incorporated in from day one, so another huge opportunity, I guess, to miss that, as you roll that into production. >> It seems like nobody ever thinks about security first. It just isn't the function. No developer ever wakes up in the morning and thinks, I need to do security and then develop features. Their life is all around delivering the value that the customers are looking for and security prevents them creating the feature velocity they want to deliver. There's always a push-and-pull there to get the right balance and it's easy when you're not under sustained attack to believe that security isn't important. >> So how do people adjust kind of their thinking around security? Or is it just below the surface, or it's presumed? How does it become more of an ongoing part of the conversation and a feature that's always baked in during the development versus kind of an afterthought or, oh my gosh, my neighbor just got hacked or there's a big story in the Wall Street Journal? >> I think what we're seeing now in the evolution of software and development is the supply chain involved. It used to be you created systems from scratch and you built it from scratch and you had the opportunity to layer security in as you were going. You would find a weakness, you would design around it, you would overcome it. Now it's more of an assemblage of components to produce an outcome, and the security wasn't built in when the component was built, you've pretty much lost that opportunity and it's hard to go retrofit that. I think we're going to soon see the next phase where these components are start building security assumptions in up front, but it's going to be a long time, much like IoT where things are deployed forever, where we start seeing that supply chain evolve on its own and you can assemble secure software from the start. >> Yeah, it's amazing that's it's still kind of an afterthought when these things are in the newspaper every day and it's almost an assumption maybe we're getting a little numb to the thing that you're going to be breached and you're going to have an issue and how do you react to it? How quickly can you find it? How do you limit the damage? Because it seems like everybody's getting breached every day. >> Especially, when you consider we have decades of technical data. There are companies that still run their businesses on mainframes that haven't been produced in 20 years. >> I didn't even think of that part of it. All right, last question before I let you go, Jason. Big, big week this week at RSA. What are you looking forward to? >> Ah, I'm looking forward to really the evolution of advanced end point technologies, the delivery of visibility to the enterprise, that can do new response actions based on new knowledge. I'm looking forward to the growth of automation. Automation as it relates to security elements, so we can reduce the human element. >> Jeff: Right. >> And the mistakes that are made. >> Yeah, 'cause we certainly need it, 'cause it is easy to make mistakes when you've got a 1000 little tasks, right? >> It is. >> All right, Jason. Well, thank you for taking a few minutes of your day and stopping by. >> Thanks for having me. >> All right. He's Jason, I'm Jeff. You're watching The Cube. We're at RSAC 2018 North America in San Francisco. Thanks for watching. (exciting music)

Published Date : Apr 18 2018

SUMMARY :

Announcer: From downtown San Francisco, it's The Cube, It's Jason Brvenik and he is the Chief Technology Officer So for people that aren't familiar with NSS Labs, to assess whether or not a product is a good fit. the data center intrusion prevention systems group test. What is that all about? that data centers are the keys to access How do you incorporate that into your testing? and to measure those. and dig deep into the protocols and interactions that are going to be IoT-enabled, the attackers seem to have automation down pretty well. because the standard says something should be, and the reliance on assumptions of what should be and it's because somebody forgot to set a configuration And it's easy in the moment It's one of the reasons we created an environment of the key components of my environment back in your lab? and whether or not your people with those controls and QA kind of happens in the background. after the test dev, and thinks, I need to do security and then develop features. and the security wasn't built in and how do you react to it? Especially, when you consider we have decades What are you looking forward to? the evolution of advanced end point technologies, and stopping by. We're at RSAC 2018 North America in San Francisco.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
JasonPERSON

0.99+

Jeff FrickPERSON

0.99+

Jason BrvenikPERSON

0.99+

JeffPERSON

0.99+

10 yearsQUANTITY

0.99+

NSS LabsORGANIZATION

0.99+

AmazonORGANIZATION

0.99+

next weekDATE

0.99+

20 yearsQUANTITY

0.99+

1000 thingsQUANTITY

0.99+

second paragraphQUANTITY

0.99+

oneQUANTITY

0.99+

San FranciscoLOCATION

0.99+

40,000 peopleQUANTITY

0.99+

decadesQUANTITY

0.99+

BothQUANTITY

0.98+

RSAORGANIZATION

0.98+

1000 little tasksQUANTITY

0.97+

one setQUANTITY

0.97+

Wall Street JournalTITLE

0.96+

this weekDATE

0.96+

day oneQUANTITY

0.94+

2018DATE

0.91+

RSA North America 2018EVENT

0.9+

North AmericaLOCATION

0.88+

The CubeTITLE

0.86+

The CubeORGANIZATION

0.85+

RSA Conference North AmericanEVENT

0.84+

RSAC 2018EVENT

0.77+

RSA North AmericaORGANIZATION

0.74+

firstQUANTITY

0.72+

one of the reasonsQUANTITY

0.7+

The CubeCOMMERCIAL_ITEM

0.64+

RSACORGANIZATION

0.6+

technical dataQUANTITY

0.59+

ndQUANTITY

0.52+

Tim Jefferson, Barracuda Networks | RSA North America 2018


 

(upbeat music) >> Announcer: From downtown San Francisco, it's theCUBE. Covering RSA North America 2018. >> Welcome back everybody, Jeff Frick here, with theCUBE. We're at RSA Conference 2018 in downtown San Francisco, 40,000 plus people, it's a really busy, busy, busy conference, talking about security, enterprise security and, of course, a big, new, and growing important theme is cloud and how does public cloud work within your security structure, and your ecosystem, and your system. So we're excited to have an expert in the field, who comes from that side. He's Tim Jefferson, he's a VP Public Cloud for Barracuda Networks. Tim, great to see you. >> Yeah, thanks for having me. >> Absolutely, so you worked for Amazon for a while, for AWS, so you've seen the security from that side. Now, you're at Barracuda, and you guys are introducing an interesting concept of public cloud firewall. What does that mean exactly? >> Yeah, I think from my time at AWS, one of my roles was working with all the global ISVs, to help them re-architect their solution portfolio for public cloud, so got some interesting insight into a lot of the friction that enterprise customers had moving their datacenter security architectures into public cloud. And the great biggest friction point tend to be around the architectures that firewalls are deploying. So they ended up creating, if you think about how a firewall is architected and created, it's really designed around datacenters and tightly coupling all the traffic back into a centralized policy enforcement point that scales vertically. That ends up being a real anti-pattern in public cloud best practice, where you want to build loosely coupled architectures that scale elastically. So, just from feedback from customers, we've kind of re-architected our whole solution portfolio to embrace that, and not only that, but looking at all the native services that the public cloud IaaS platforms, you know, Amazon, Azure, and Google, provide, and integrating those solutions to give customers the benefit, all the security telemetry you can get out of the native fabric, combined with the compliance you get out of web application and next-generation firewall. >> So, it's interesting, James Hamilton, one of my favorite people at AWS, he used to have his Tuesday Nights with James Hamilton at every event, very cool. And what always impressed me every time James talked is just the massive scale that Amazon and the other public cloud vendors have at their disposal, whether it's for networking and running cables or security, et cetera. So, I mean, what is the best way for people to take advantage of that security, but then why is there still a hole, where there's a new opportunity for something like a cloud firewall? >> I think the biggest thing for customers to embrace is that there's way more security telemetry available in the APIs that the public cloud providers do than in the data plane. So most traditional network security architects consider network packets the single source of truth, and a lot of the security architecture's really built around instrumenting in visibility into the data plane so you can kind of crunch through that, but the reality is the management plane on AWS and Azure, GCP, offer tremendous amount of security telemetry. So it's really about learning what all those services are, how you can use the instrument controls, mine that telemetry out, and then combine it with control enforcement that the public cloud providers don't provide, so that kind of gives you the best of both worlds. >> It's interesting, a lot of times we'll hear about a breach and it'll be someone who's on Amazon or another public cloud provider, and then you see, well they just didn't have their settings in the right configuration, right? >> It's usually really kind of Security 101 things. But the reality is, just because it's a new sandbox, there's new rules, new services, you know, and engineers have to kind of, and the other interesting thing is that developers now own the infrastructures they're deploying on. So you don't have the traditional controls that maybe network security engineers or security professionals can build architectures to prevent that. A developer can inadvertently build an app, launch it, not really think about security vulnerabilities he put in, that's kind of what you see in the news. Those people kind of doing basic security misconfigurations that some of these tools can pick up programmatically. >> Now you guys just commissioned a survey about firewalls in the cloud. I wonder if you can share some of the high-level outcomes of that survey. What did you guys find? >> Yeah, it's similar to what we're chatting. It's just that, I think, you know, over 90% of enterprise customers acknowledge the fact that there's friction when they're deploying their datacenter security architectures, specifically network security tools, just because of the architectural friction and the fact that, it's really interesting, you know, a lot of those are really built because everything's tightly coupled into them, but in the public cloud, a lot of your policy enforcement comes from the native services. So, for instance, your segmentation policy, the route tables actually get put into the, when you're creating the networking environment. So the security tools, a network security tool, has to work in conjunction with those native services in order to build architectures that are truly compliant. >> So is firewall even the right name anymore? Should it have a different name, because really, we always think, all right, firewall was like a wall. And now it's really more like this layered risk management approach. >> There's definitely a belief, you know, among especially the cloud security evangelists, to make sure people don't think in terms of perimeter. You don't want to architect in something that's brittle in something that's meant to be truly elastic. I think there's kind of two, you know the word firewall is expanding, right, so more and more customers are now embracing web application firewalls because the applications are developing are port 80 or 443, they're public-facing web apps, and those have a unique set of protections into them. And then next-generation firewalls still provide ingress/egress policy management that the native platforms don't offer, so they're important tools for customers to use for compliance and policy enforcement. They key is just getting customers to understand thinking through specifically which controls they're trying to implement and then architect the solutions to embrace the public cloud they're playing in. So, if they're in Azure, they need to think about making sure the tools they're choosing are architected specifically for the Azure environment. If they're using AWS, the same sort of thing. Both those companies have programs where they highlight the vendors that have well-architected their solutions for those environments. So Barracuda has, you know, two security competencies, there's Amazon Web Services. We are the first security vendor for Azure, so we were their Partner of the Year. So the key is just diving in, and there's no silver bullet, just re-architecting the solutions to embrace the platforms you're deploying on. >> What's the biggest surprise to the security people at the company when they start to deploy stuff on a public cloud? There's obviously things they think about, but what do they usually get caught by surprise? >> I think it's just the depth and breadth of the services. There's just so many of them. And they overlap a little bit. And the other key thing is, especially for network security professionals, a lot of the tools are made for software developers. And they have APIs and they're tooling is really built around software development tools, so if you're not a software developer, it can be pretty intimidating to understand how to architect in the controls and especially to leverage all these native services which all tie together. So it's just bridging those two worlds, you know, software development and network security teams, and figuring out a way for them to collaborate and work together. And our advice to customers have been, we've seen comical stories for those battles between the two. Those are always fun to talk about, but I think the best practice is around getting, instead of security teams saying no, I think everybody's trying to get culturally around how do I say yes. Now the burden can be back to the software development teams. The security teams can say, here the list of controls that I need you to cover in order for this app to go live. You know, HIPAA or PCI, here are these compliance controls. You guys chose which tools and automation frameworks work as part of your CI/CD pipeline pr your development pipeline, and then I'll join your sprints and you guys can show incrementally how we're making progress to those compliance. >> And how early do they interject that data in kind of a pilot program that's on its way to a new production app? How early do the devs need to start baking that in? >> I think it has to be from day zero, because as you embrace and think through the service, and the native services you're going to use, depending on which cloud provider, each one of those has an ecosystem of other native services that can be plugged in and they all have overlapping security value, so it's kind of thinking through your security strategy. And then you can be washed away by all the services, and what they can and can't do, but if you just start from the beginning, like what policies or compliance frameworks, what's our risk management posture, and then architect back from that. You know, start from the end mine and then work back, say hey, what's the best tool or services I can instrument in. And then, it may be, starting with less cloudy tools, you know, just because you can instrument in something you know, and then as you build up more expertise, depending on which cloud platform you're on, you can sort of instrument in the native services that you get more comfortable with then. So it's kind of a journey. >> You got to start from the beginning. Bake it in from the zero >> Got to be from the zero. >> It's not a build-on anymore. All right Tim, last question. What are we looking forward to at RSA this week? >> I'm very cloud-biased, you know, so I'm always looking at the latest startups and how creative people are about rethinking how to deploy security controls and just kind of the story and the pulse around the friction with public cloud security and seeing that evolve. >> All right, well I'm sure there'll be lots of it. It never fails to fascinate me, the way that this valley keeps evolving and evolving and evolving. Whatever the next big opportunity is. All right, he's Tim Jefferson, I'm Jeff Frick, thanks for stopping by. You're watching theCUBE. We're at RSAC 2018 in San Francisco. Thanks for watching. (upbeat techno music)

Published Date : Apr 18 2018

SUMMARY :

Announcer: From downtown San Francisco, it's theCUBE. Tim, great to see you. Absolutely, so you worked for Amazon for a while, for AWS, And the great biggest friction point tend to be around is just the massive scale that Amazon and the other and a lot of the security architecture's really built around developers now own the infrastructures they're deploying on. the high-level outcomes of that survey. just because of the architectural friction and the fact So is firewall even the right name anymore? just re-architecting the solutions to embrace So it's just bridging those two worlds, you know, and the native services you're going to use, Bake it in from the zero What are we looking forward to at RSA this week? the story and the pulse around the friction with Whatever the next big opportunity is.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
Tim JeffersonPERSON

0.99+

Jeff FrickPERSON

0.99+

AmazonORGANIZATION

0.99+

AWSORGANIZATION

0.99+

JamesPERSON

0.99+

James HamiltonPERSON

0.99+

Barracuda NetworksORGANIZATION

0.99+

Amazon Web ServicesORGANIZATION

0.99+

San FranciscoLOCATION

0.99+

TimPERSON

0.99+

443OTHER

0.99+

oneQUANTITY

0.99+

BothQUANTITY

0.99+

twoQUANTITY

0.99+

GoogleORGANIZATION

0.98+

over 90%QUANTITY

0.98+

40,000 plus peopleQUANTITY

0.97+

each oneQUANTITY

0.97+

Security 101TITLE

0.97+

RSAC 2018EVENT

0.96+

both worldsQUANTITY

0.96+

port 80OTHER

0.96+

AzureTITLE

0.96+

egressORGANIZATION

0.96+

this weekDATE

0.96+

RSA Conference 2018EVENT

0.94+

RSAORGANIZATION

0.94+

BarracudaORGANIZATION

0.94+

ingressORGANIZATION

0.93+

HIPAATITLE

0.89+

single sourceQUANTITY

0.88+

first securityQUANTITY

0.87+

downtown San FranciscoLOCATION

0.85+

two worldsQUANTITY

0.84+

day zeroQUANTITY

0.84+

two security competenciesQUANTITY

0.81+

my rolesQUANTITY

0.74+

AzureORGANIZATION

0.72+

RSA North AmericaORGANIZATION

0.71+

theCUBEORGANIZATION

0.69+

RSA North America 2018EVENT

0.62+

2018DATE

0.58+

TuesdayEVENT

0.57+

zeroQUANTITY

0.5+

NightsDATE

0.44+

Dave Frampton, SumoLogic | RSA North America 2018


 

>> Narrator: From downtown San Francisco, it's theCUBE, covering RSA North America 2018. >> And welcome back everybody, Jeff Frick here with theCUBE. We're at the RSA Conference in San Francisco, it's 40 thousand plus people talking security, really one of the biggest conferences in San Francisco, and security continues to be an ever increasing and important topic, and more and more complex and complicated and multifaceted. We're excited to have really an innovator who just recently sold his company to Sumo Logic, he's Dave Frampton, VP of security solutions now at Sumo Logic. Dave, great to see you. >> Dave: Good to be here. >> So you guys were relatively a relatively small team working on a very specific piece of this giant pie. So, tell us a little bit about what you're doing and what attracted Sumo Logic to you. >> FactorChain, acquired by Sumo Logic in Q4 of last year was focused on building an investigation platform to really help security analysts very quickly and completely identify, for an individual threat or alert of which they get an avalanche every day, what happened, where did it spread, and then what should be done about it, more importantly. >> It's funny 'cause we talk often, at all these conferences, right, everybody in the keynote will talk about it, "six months before you know you've been breached", or two years, or whatever the average, it changes all the time. But nobody ever really talks about once you've figured it out, then what? So that's really what you guys are about, the "then what?" So what are some of the things that people do wrongly, and what are some of the immediate triage and best practices that people should be aware of if they're not already? >> It's a great question, there's really a difficult work flow that exists when you start digging into one of these indicators of compromise or alerts, typically an analyst is trying to connect the dots across huge numbers of systems and huge data sets. They may have to go to five to ten different systems, run queries which take a long time to run and then take a long time to interpret, kind of stitch together the clues across all of them, and this process can often take 30 minutes, an hour, or even two hours against an inflow rate of hundreds of these per day. So there's sort of this expanding backlog of uninvestigated urgent threats. In many cases, people only get to about 10% of the most urgent threats or alerts that come in to their security operation center, or SOC. And FactorChain's innovation was to develop some new techniques to help human analysts quickly connect the dots across these huge data sets. Integrate a lot of those different systems, so you can go to one place, see huge, deep connections between data sets, and then kind of put it all together in a very concise work flow that helps you get through this process just a lot faster, a lot more skilled. >> So are you identifying patterns of past behavior, 'cause you have a database of how these things work, are you looking for consistency of behavior within one system in others, I mean, what are some of the, obviously you're not going to tell us your secret sauce, but what are some of the tricks and tips that enable you to speed up that process? It's scary to hear that they have hundreds of high priority that they can't get to. >> There's two main components of trying to accelerate this whole work flow. The first one is trying to help analysts very quickly get insight into how variables change in an environment. This investigation process is little bit like a game of whack-a-mole, you're following a particular user or particular machine, but then the name will change, and then there'll be another variable introduced but it will change four times, and you're left to try to figure out which one of these changes map to the original. This process just repeats over and over again. So part of our insight was to try to figure out how to chain, hence the name FactorChain, all of these variable changes together in a very, very concise way, so you can help the analyst find the right path through the data and ignore all the false trails, get back on the trail when they lose the trail. So it's really sort of a data navigation and insight, sort of the key core of FactorChain's innovation. >> So a big factor, shouldn't use that word again, but we'll use it again, factor happening today in the industry is everything going to cloud, right? A huge percentage of business going to cloud. AWS is up to 20 billion dollar run rate and Sumo is a big partner, and Microsoft and Google are trying to catch up from behind, and IBM's got a cloud. So cloud's a big thing and there's more and more cloud. Also, we're in this API economy now, so whether I want to use public data sets and inject those into my processes, or I've got partners that I'm, I'm connecting all these things via API's and I still have my on-prem stuff, or the stuff that just can't go to cloud or legacy for whatever reason. So the environment is becoming way more complex, the number of third party people that you're playing nice with is becoming much, much larger, and a lot of these connections are completely automated, right, when you look at ad tech and some of the financial trading systems. So how does that increasing complexity play into what you guys are doing? >> The migration to the cloud is putting enormous disruptive pressure on some of these traditional security processes. You think about, the old world involved a security operations center and a small team of analysts just going through this list of alerts that were sent in by their infrastructure. The cloud really challenges that in two fundamental ways. I think one of them you hit really well in your description of it, which is just the sheer surface area of possible attack has increased so dramatically. You hit all the key points, there's automated processes, there's a lot of customer facing and production security that didn't exist in the old worlds, so you have so many more ways for the attackers to get in. But importantly, there are new sources of information which are critical to actually orchestrating the defense, to figuring out what to pay attention to and how to pay attention to it. Application layer information is much more relevant in a cloud context. And you have a lot of the infrastructures being standardized underneath, but a lot of the interesting insight might be from the application. Is this a customer or is it a partner? Is it a sensitive piece of information or application, or not? There's all sorts of context which needs to be brought in to the forensic process to help the investigators really get to the bottom of what happened and where did it spread. There's also a need to collaborate across security and other functions in IT in a much more seamless, horizontal way. A typical example would be an analyst in the SOC might understand an awful lot about security forensics but may not really understand some of this application context or even how to interpret some of the application logs at all. So you really need a horizontal collaboration involving IT operations, you hear a lot about DevOps and sort of DevSecOps, you need a much more collaborative work flow, not just a common data set, which I think everybody recognized a few years back, but also common analytics and a common work flow, common tooling that they can collaborate in the same system on the same investigation. And so those are the ways in which the traditional security industry and the boundaries around its processes and its tools are really being challenged and disrupted by the migration to the cloud, and at Sumo Logic, this is sort of at the center of where we live. We live in a world where people are rapidly migrating to the cloud, looking for monitoring and troubleshooting and security analytics, functionality. As they do that, looking at modern applications and how their architectures are changing and what implications that has for security. So we have our sights squarely set on sort of creating that new model for that new cloud-oriented environment. >> Right, and then how much do you work with other applications, which I guess in the past may have been thought of as competitive, but when you're in an environment with all these integrated systems at a customer, and there's probably tremendous benefit to sharing some level of information in terms of the signature of threats and when threats are coming in. I'm sure there's ton of great data that, if shared across people on the good side of the fence, will probably be to the benefit of all. So has that been changing, is that evolving, how do you see kind of working with other apps within, let's just pick the AWS cloud for example, within a particular customer, whether it's AWS directly or other partners in the ecosystem? >> Right, well first, you hit it, I mean, this function of security operations has to be agnostic, right? You have to be open to ingesting context from whichever system and whichever vendor and whatever source it might come from. And so these ecosystems are really important, and integration so that you can quickly, not only take in information from third parties, but then quickly get trending and visualization and really bring insight to that data. And so to that end, Sumo Logic's a leader in the AWS ecosystem, we've been built from the ground up on AWS, and we have rich partnerships with the vast majority of the ecosystem of tools that surround the AWS environment. So we can bring that in and very quickly deliver insight, make correlations, figure out what you need to pay attention to, and then do this investigation work flow that we were talking about earlier. >> Alright, crazy times. So, 40 thousand people here, what are you looking forward to for the next couple of days here at RSAC? >> I think a couple of things. One is, I think everyone is focused, right now, on the upcoming deadline for GEPR, and sort of data protection, data privacy, how do we identify within our data what might be subject to some of these regulations and new compliance requirements, and then how many of those overlap. Though the best of intentions, it creates some dilemmas about how to approach problems, such as for example, right to be forgotten. And I think seeing the community come together and sort of in a live venue, which is really what the show is all about, and kind of discuss and debate those issues, I think that's one. Two is the center of what we've been talking about, is the impact of modern application architectures and cloud on some of these old, traditional security practices and models. And that's why we have a bigger presence this year at the show, because we think that's something that is going to change the way things have been done in the security industry, and we want to be a part of that conversation and obviously giving previews of our upcoming products that address some of those problems. Looking forward to a good week. >> Should be good of a week for you, be busy. >> Dave: Absolutely. >> Thanks for taking a few minutes, and again congratulations on the acquisition with Sumo, great marriage I'm sure, and look forward to following the story. >> Thanks so much. >> Alright, he's Dave Frampton, I'm Jeff Frick. You're watching theCUBE from RSAC 2018 San Francisco. Thanks for watching.

Published Date : Apr 18 2018

SUMMARY :

it's theCUBE, covering RSA North America 2018. and security continues to be an ever increasing and what attracted Sumo Logic to you. and then what should be done about it, more importantly. and what are some of the immediate triage and best practices and then take a long time to interpret, that enable you to speed up that process? and ignore all the false trails, in the industry is everything going to cloud, right? and disrupted by the migration to the cloud, Right, and then how much do you work and integration so that you can quickly, So, 40 thousand people here, what are you looking forward to Two is the center of what we've been talking about, and again congratulations on the acquisition Thanks for watching.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
MichielPERSON

0.99+

AnnaPERSON

0.99+

DavidPERSON

0.99+

BryanPERSON

0.99+

JohnPERSON

0.99+

IBMORGANIZATION

0.99+

MichaelPERSON

0.99+

ChrisPERSON

0.99+

NECORGANIZATION

0.99+

EricssonORGANIZATION

0.99+

KevinPERSON

0.99+

Dave FramptonPERSON

0.99+

MicrosoftORGANIZATION

0.99+

Kerim AkgonulPERSON

0.99+

Dave NicholsonPERSON

0.99+

JaredPERSON

0.99+

Steve WoodPERSON

0.99+

PeterPERSON

0.99+

Lisa MartinPERSON

0.99+

NECJORGANIZATION

0.99+

Lisa MartinPERSON

0.99+

Mike OlsonPERSON

0.99+

AmazonORGANIZATION

0.99+

DavePERSON

0.99+

Michiel BakkerPERSON

0.99+

FCAORGANIZATION

0.99+

NASAORGANIZATION

0.99+

NokiaORGANIZATION

0.99+

Lee CaswellPERSON

0.99+

ECECTORGANIZATION

0.99+

Peter BurrisPERSON

0.99+

OTELORGANIZATION

0.99+

David FloyerPERSON

0.99+

Bryan PijanowskiPERSON

0.99+

Rich LanePERSON

0.99+

KerimPERSON

0.99+

Kevin BoguszPERSON

0.99+

Jeff FrickPERSON

0.99+

Jared WoodreyPERSON

0.99+

LincolnshireLOCATION

0.99+

KeithPERSON

0.99+

Dave NicholsonPERSON

0.99+

ChuckPERSON

0.99+

JeffPERSON

0.99+

National Health ServicesORGANIZATION

0.99+

Keith TownsendPERSON

0.99+

WANdiscoORGANIZATION

0.99+

GoogleORGANIZATION

0.99+

MarchDATE

0.99+

NutanixORGANIZATION

0.99+

San FranciscoLOCATION

0.99+

IrelandLOCATION

0.99+

Dave VellantePERSON

0.99+

Michael DellPERSON

0.99+

RajagopalPERSON

0.99+

Dave AllantePERSON

0.99+

EuropeLOCATION

0.99+

March of 2012DATE

0.99+

Anna GleissPERSON

0.99+

SamsungORGANIZATION

0.99+

Ritika GunnarPERSON

0.99+

Mandy DhaliwalPERSON

0.99+

Edna Conway, Cisco | RSA North America 2018


 

>> Announcer: From downtown San Francisco, it's theCUBE covering RSA North America 2018. >> Hey welcome back everybody, Jeff Frick here with theCUBE. We're in San Francisco at RSA conference 2018, as 40,000 plus professionals talking about security. It's quickly becoming one of the biggest conferences that we have in San Francisco right up there with Oracle OpenWorld and Salesforce.com, pretty amazing show and we're excited to get some of the insight with some of the experts that are here for the event and all the way from the East Coast, from New Hampshire Edna Conway's joining us, she's a chief security officer, global value chain for Cisco, Edna great to see you. >> Oh I'm delighted to be here Jeff, thank you. >> Absolutely so we're glad to get you out of the 21 degree weather that you said was cold and sleety when you departed. >> Cold and sleety, spring in New Hampshire, although it's not much nicer here in San Francisco. >> No, it's a little dodgy today. Well anyway let's jump into it. So you're all about value chain. What exactly when you think about value chain, explain to the people, what are you thinking? >> You know that's a great question because we define the value chain as the end to end life cycle for any solution. So it could be hardware, it could be software, it could be a service, whether it's a service afforded by a person, or a service afforded by the cloud. >> Now it's interesting because the number of components in a solution value chain just continue to grow over time as we have the API economy, and clouds, and all these things are interconnected so I would imagine that the complexity of managing and then by relation securing that value chain must be getting harder and harder over time as we continue to add all these, kind of API components to the solution. Is that what you see in the field? >> I think there's a challenge there without a doubt, but sometimes that interconnection actually gives you a hook in right, and so what we've been thinking about for years now is, is there a way to actually define a simple high level architecture that can be flexible and elastic with some rigidity that allows you to identify what your core goals are, and then allows those third party ecosystem members to join you in the effort to achieve those goals in a way that works for their business. >> Right and then how does open source play in that? Because that's also an increasing component of the value chain, is that integrated into more and more either just overtly, or you're implementing an open source solution or you've got all these people that are kind of open source plus and what they're building and delivering to the market. >> Yeah open source is a great challenge without a doubt. I think the way in which to deal with open source is to understand where you're getting it from, just like all third party ecosystem members. Who are they? What are they doing for you? And more precisely how are you going to utilize them and take a risk based approach to where you're embedding them. >> Right. >> Right. Not all things are created equally. And so your worry needs to be different depending on the utilization. >> Right. The risk based approach is a great comment because cause security in a way to me is kind of like insurance, you can't be ultimately secure unless you just lock the doors and sit in there by yourself. So it's always kind of this risk trade off, benefit versus trade off, and really a financial decision as to how much do you want to invest in that next unit of security relative to the return. So when you're thinking about it from a risk modeling basis versus just, you know, we're putting up the moat and nobody's coming in, which we know doesn't work anymore. What are some of the factors to think about so that you're achieving the right level of success at the right investment? >> I think there are a number of things to think about, and the primary one I would say is, look at what I believe is the currency of the digital economy which is trust. And in order to build trust what you need to do is understand the risks that you're taking. And those risks need to measured in the language of business. So all of a sudden, it becomes really clear when you know what someone is doing for you, and you know how they're doing it, and the invasiveness of your inquiry and partnership with them actually needs to be adjusted, and all of a sudden you develop not only a baseline, but an opportunity to enhance your trust for, let's take an example. So Cisco's working with Intel, we're going to deploy Intel threat detection technology, our first instantiation of that will be tetration. Clearly they're a third party ecosystem member. >> Right, right. >> And they have been for some time. Now what we're thinking about is how does Intel go about deploying that capability? And not only that, but how are we going to utilize it? And our view is if you take CPU telemetry and you combine it with our edge as well as our network telemetry, you have a better solution down the road, better solution for alerts, better solution for quicker decisions for the inevitable. That risk based approach says we're embedding into and partnering at a core solution level. >> Right. >> That's a different area of inquiry then somebody, we were talking earlier and I said, you know, if you're a sheet metal provider on the external part of a chassis, great. >> Don't they love the diligence on that piece? >> Quality due diligence, but security limited, yeah? >> So but it's interesting because on one hand you're opening up kind of new kind of threat surfaces if you will, the more components that are in a solution from the more providers. On the positive side, now you're leveraging their security expertise within the components that they're bringing to the solution. So as most things in life right, it's really kind of two sides of the same coin, opening up more threats, but leveraging another group of resources who have an expertise within that piece of the value chain. >> Absolutely. Look none of us make something from nothing, you know, the reality is we're relying more and more on the digital economy on those third parties. So understanding precisely how they're doing something is important, but we also have to be respectful of one another's intellectual property. And that is a unique wrinkle in a day and age of integration that we haven't seen previously. The other thing I think that's really important is we're seeing a wonderful, I think explosion of IOT, there's a downside obviously, the question is have folks deployed their IOT in a way that included the security community. You should have security at the table, but what IOT does is give you edge visibility that you've never had before. So I see it as a positive, but it needs to be informed by things like AI, it needs to be informed by things like machine learning, and they need to be gates within at the end of the day where the information is managed, which is at the network. >> Right, cause again it's just another entry point in as well, so good thing, bad thing. I want to circle back on kind of the boardroom discussion that we talked about a little bit earlier. Everyone's talking about securities and board conversation, clouds and board conversation, a lot of these big, kind of IT transformational things that are happening are now being elevated to the board cause everybody's a digital company and everybody's a digital business. When you want to talk to the board, and how should people talk to the board about security vis a vis kind of this risk analysis versus just a pure, you know, we're secure, or we're not secure, and I'm sure every CEO and board is worried for that announcement to come out in the paper that they were breached some time ago. And you almost think it's inevitable at some point in time, so what does the board discussion look like? How's the board decision changing as security gets elevated beyond kind of the basics? >> So let me answer that in the context of value chain security. >> Absolutely. >> I think we need to get to the point where security speaks the language of business. We need to walk into the board and say we have an architecture, we are deploying measures to achieve the architecture at a certain level of compliance and goal setting across the ecosystem on a risk based approach. Fabulous words, I'm a board member. What does that mean to me? >> Help me, help me, gimme a number. Exactly, well, and the number comes out of tolerance levels. So if you have this architecture and you have goals set we have 11 domains, we set goals flexibly based on the nature of the third party and what they do for us. Now we have a tolerance level and guess what you can report? I'm at tolerance, I'm above tolerance, I'm below tolerance. And if you start to model through a variety of techniques, there are a number of standards out there and processes some folks have written about them, where you can translate that risk of tolerance into dollars if you're in the US or currency of your choice and the reality is you're walking in and saying at tolerance means this degree of risk, below tolerance means I've reduced my risk to this. It might afford you an opportunity to say hmmm, perhaps you can share some of that benefit with me to take the program to a new level. >> Right, right or in a different area. >> About tolerance, higher degree of risk, what do we do about it? Now you're speaking the language of business. >> So that's pretty old school business right? I want to talk to you about something that's a little bit newer school which is block chain. And you've used the word trust I don't know how many times in this interview, we'll check the transcript, but trust is a really important thing obviously, and some people have said that they view block chain as trust as a service. I'm just curious to get your perspective as we hear more and more about block chain, and big companies like IBM and a lot of companies are putting a bunch of resources behind it, where do you see block chain fitting? What is Cisco's position or I don't know if they have a official position yet as block chain now is introduced into this world of trust. >> So I think we're all looking at it, Cisco included block chain is an incredibly useful tool without a doubt. I'm not sure that block chain's going to solve world hunger or world peace. >> Shoot. >> However, just as we said trust has elements of use artificial intelligence to inform your decisions, achieve a higher degree of trust, what you can have is a set of let's say, hashes, date and time stamps, as something passes through the network because remember, if the currency is trust the integrity of the data is the fuel that allows you to earn trust. And digital, digital ledger technology or block chain is something that I think allows us to develop what I call a passport for the data. So we have a chain of custody, you know I'm an old homicide prosecutor from many, many, years ago chain of custody was important in the trial so too chain of custody of your data and your actions across the full spectrum of a life cycle add a degree of integrity we've never had the ability to do easily before. >> Interesting times. >> Alright Edna well thank you for spending some of your day with us, I'm sure you have a crazy, busy RSA planned out for the next couple days so thanks again. >> My pleasure, thank you so much for having me. >> Alright she's Edna Conway, I'm Jeff Frick. You're watching theCUBE from RSA Conference 2018 thanks for watching. (theme music)

Published Date : Apr 18 2018

SUMMARY :

Announcer: From downtown San Francisco, it's theCUBE and all the way from the East Coast, from New Hampshire Absolutely so we're glad to get you out of the 21 degree Cold and sleety, spring in New Hampshire, explain to the people, what are you thinking? or a service afforded by the cloud. Is that what you see in the field? to join you in the effort to achieve those goals of the value chain, is that integrated into more and more And more precisely how are you going to utilize them depending on the utilization. What are some of the factors to think about so that you're And in order to build trust what you need to do And our view is if you take CPU telemetry and you combine we were talking earlier and I said, you know, On the positive side, now you're leveraging their security Look none of us make something from nothing, you know, beyond kind of the basics? So let me answer that in the context of of compliance and goal setting across the ecosystem and the reality is you're walking in and saying Now you're speaking the language of business. I want to talk to you about something that's a little bit I'm not sure that block chain's going to solve the integrity of the data is the fuel that allows you Alright Edna well thank you for spending Alright she's Edna Conway, I'm Jeff Frick.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
IBMORGANIZATION

0.99+

EdnaPERSON

0.99+

Jeff FrickPERSON

0.99+

CiscoORGANIZATION

0.99+

JeffPERSON

0.99+

Edna ConwayPERSON

0.99+

San FranciscoLOCATION

0.99+

21 degreeQUANTITY

0.99+

New HampshireLOCATION

0.99+

two sidesQUANTITY

0.99+

USLOCATION

0.99+

11 domainsQUANTITY

0.99+

40,000 plus professionalsQUANTITY

0.99+

todayDATE

0.99+

RSAORGANIZATION

0.98+

Salesforce.comORGANIZATION

0.98+

RSA conference 2018EVENT

0.97+

Oracle OpenWorldORGANIZATION

0.96+

oneQUANTITY

0.96+

IntelORGANIZATION

0.93+

RSA Conference 2018EVENT

0.92+

first instantiationQUANTITY

0.92+

East CoastLOCATION

0.9+

RSA North America 2018EVENT

0.82+

theCUBEORGANIZATION

0.68+

couple daysDATE

0.62+

yearsQUANTITY

0.56+

America 2018EVENT

0.46+

yearsDATE

0.45+

NorthLOCATION

0.4+

Daniel Berg, IBM Cloud & Norman Hsieh, LogDNA | KubeCon 2018


 

>> Live from Seattle, Washington it's theCUBE, covering KubeCon and CloudNativeCon North America 2018. Brought to you by Red Hat, the Cloud Native Computing Foundation, and its ecosystem partners. >> Hey, welcome back everyone, it's theCUBE live here in Seattle for day three of three of wall-to-wall coverage. We've been analyzing here on theCUBE for three days, talking to all the experts, the CEOs, CTOs, developers, startups. I'm John Furrier, Stu Miniman, with theCUBE coverage of here at dock, not DockerCon, KubeCon and CloudNativeCon. Getting down to the last Con. >> So close, John, so close. >> Lot of Docker containers around here. We'll check it on the Kubernetes. Our next two guests got a startup, hot startup here. You got Norman Hsieh, head of business development, LogDNA. New compelling solution on Kubernetes give them a unique advantage, and of course, Daniel Berg who's distinguished engineer at IBM. They have a deal. We're going to talk about the startup and the deal with IBM. The highlights, kind of a new model, a new world's developing. Thanks for joining us. >> Yeah, no problem, thanks for having us. >> May get you on at DockerCon sometimes. (Daniel laughing) Get you DockerCon. The container certainly been great, talk about your product first. Let's get your company out there. What do you guys do? You got something new and different. Something needed. What's different about it? >> Yeah, so we started building this product. One thing we were trying to do is finding a login solution that was built for developers, especially around DevOps. We were running our own multi-tenant SaaS product at the time and we just couldn't find anything great. We tried open source Elastic and it turned out to be a lot to manage, there was a lot of configuration we had to do. We tried a bunch of the other products out there which were mostly built for log analysis, so you'd analyze logs, maybe a week or two after, and there was nothing just realtime that we wanted, and so we decided to build our own. We overcame a lot of challenges where we just felt that we could build something that was easier to use than what was out there today. Our philosophy is for developers in the terms of we want to make it as simple as possible. We don't want you to manage where you're going to think about how logs work today. And so, the whole idea, even you can go down to some of the integrations that we have, our Kubernetes integration's two lines. You essentially hit two QCTL lines, your entire cluster will get logged, directly logged in in seconds. That's something we show often times at demos as well. >> Norman, I wonder if you can drill in a little bit more for us. Always look at is a lot of times the new generation, they've got just new tools to play with and new things to do. What was different, what changes? Just the composability and what a small form factor. I would think that you could just change the order of magnitude in some of the pricing of some of these. Tell us why it's different. >> Yeah, I mean, I think there's, three major things was speed. So what we found was that there weren't a lot of solutions that were optimized really, really well for finding logs. There were a lot of log solutions out there, but we wanted to optimize that so we fine-tuned Elasticsearch. We do a lot of stuff around there to make that experience really pleasurable for our users. The other is scale. So we're noticing now is if you kind of expand on the world of back in the day we had single machines that people got logs off of, then you went to VMware where you're taking a single machine and splitting up to multiple different things, and now you have containers, and all of a sudden you have Kubernetes, you're talking about thousands and thousands of nodes running and large production service. How do you find logs in those things? And so we really wanted to build for that scale and that usability where, for Kubernetes, we'll automatically tag all your logs coming through. So you might get a single log line, but we'll tag it with all the meta-data you need to find exactly what you want. So if I want to, if my container dies and I no longer know that containers around, how am I going to get the logs off of that, well, you can go to LogDNA, find the container that you're looking for, know exactly where that error's coming from as well. >> So you're basically storing all this data, making it really easy for the integration piece. Where does the IBM relationship fit in? What's the partnership? What are you guys doing together? >> I don't know if Dan wants to-- >> Go ahead, go ahead. >> Yeah, so we're partnering with IBM. We are one of their major partners for login. So if you go into Observability tab under IMB Cloud and click on Login, login is there, you can start the login instance. What we've done is, IBM's brought us a great opportunity where we could take our product and help benefit their own customers and also IBM themselves with a lot of the login that we do. They saw that we are very simplistic way of thinking about logs and it was really geared towards when you think about IBM Cloud and the shift that they're moving towards, which is really developer-focused, it was a really, really good match for us. It brought us the visibility into the upmarket with larger customers and also gives us the ability to kind of deploy globally across IBM Cloud as well. >> I mean, IBMs got a great channel on the sales side too, and you guys got a great relationship. We've seen that playbook before where I think we've interviewed in all the other events with IBM. Startups can really, if they fit in with IBM, it's just massive, but what's the reason? Why the partnership? Explain. >> Well, I mean, first of all we were looking for a solution, a login solution, that fit really well with IKS, our Kubernetes service. And it's cloud-native, high scale, large number of cluster, that's what our customers are building. That's what we want to use internally as well. I mean, we were looking for a very robust cloud-native login service that we could use ourselves, and that's when we ran across these guys. What, about a year ago? >> Yeah, I mean, I think we kind of first got introduced at last year's KubeCon and then it went to Container World, and we just kept seeing each other. >> And we just kept on rolling with it so what we've done with that integration, what's nice about the integration, is it's directly in the catalog. So it's another service in the catalog, you go and select it, and provision it very easily. But what's really cool about it is we wanted to have that integration directly with the Kubernetes services as well, so there's the tab on the Integration tab on the Kubernetes, literally one button, two lines of code that you just have to execute, bam! All your logs are now streaming for the entire cluster with all the index and everything. It just makes it a really nice, rich experience to capture your logs. >> This is infrastructure as code, that's what the promise was. >> Absolutely, yes. >> You have very seamless integration and the backend just works. Now talk about the Kubernetes pieces. I think this is fascinating 'cause we've been pontificating and evaluating all the commentary here in theCUBE, and we've come to the conclusion that cloud's great, but there's other new platform-like things emerging. You got Edge and all these things, so there's a whole new set, new things are going to come up, and it's not going to be just called cloud, it's going to be something else. There's Edge, you got cameras, you got data, you got all kinds of stuff going on. Kubernetes seems to fit a lot of these emerging use cases. Where does the Kubernetes fit in? You say you built on Kubernetes, just why is that so important? Explain that one piece. >> Yeah, I mean, I think there's, Kubernetes obviously brought a lot of opportunities for us. The big differentiator for us was because we were built on Kubernetes from the get go, we made that decision a long time ago, we didn't realize we could actually deploy this package anywhere. It didn't have to be, we didn't have to just run as a multi-tenant SaaS product anymore and I think part of that is for IBM, their customers are actually running, when they're talking about an integrated login service, we're actually running on IBM Cloud, so their customers can be sure that the data doesn't actually move anywhere else. It's going to stay in IBM Cloud and-- >> This is really important and because they're on the Kubernetes service, it gives them the opportunity, running on Kubernetes, running automatic service, they're going to be able to put LogDNA in each of the major regions. So customer will be able to keep their logged data in the regions that they want it to stay. >> Great for compliance. >> Absolutely. >> I mean, compliance, dreams-- >> Got to have it. >> Especially with EU. >> How about search and discovery, that's fit in too? Just simple, what's your strategy on that? >> Yeah, so our strategy is if you look at a lot of the login solutions out there today, a lot of times they require you to learn complex query languages and things like that. And so the biggest thing we were hearing was like, man, onboarding is really hard because some of our developers don't look at logs on a daily basis. They look at it every two weeks. >> Jerry Chen from Greylock Ventures said machine learning is the new, ML is the new SQL. >> Yup. (Daniel laughing) >> To your point, this complex querying is going to be automated away. >> Yup. >> Yes. >> And you guys agree with that. >> Oh, yeah. >> You actually, >> Totally agree with that. >> you talked about it on our interview. >> Norman, wonder if you can bring us in a little bit of compliance and what discussions you're having with customers. Obviously GDPR, big discussion point we had. We've got new laws coming from California soon. So how important is this to your customers, and what's the reality kind of out there in your user base? >> Yeah, compliance was, our founders had run a lot of different businesses before. They had two major startups where they worked with eBay, compliance was the big thing, so we made a decision early on to say, hey, look, we're about 50 people right now, let's just do compliance now. I've been at startups where we go, let's just keep growing and growing and we'll worry about compliance later-- >> Yeah, bite you in the ass, big time. >> Yeah, we made a decision to say, hey, look, we're smaller, let's just implement all the processes and necessary needs, so. >> Well, the need's there too, that's two things, right? I mean, get it out early. Like security, build it up front and you got it in. >> Exactly. >> And remember earlier we were talking and I was telling you how within the Kubernetes service we like to use our own services to build expertise? It's the same thing here. Not only are they running on top of IKS, we're using LogDNA to manage the logs and everything, and cross the infrastructure for IKS as well. So we're heavily using it. >> This also highlights, Daniel, the ecosystem dynamic of having when you break down this monolithic type of environments and their sets of services, you benefit because you can tap into a startup, they can tap in to IBM's goodness. It's like somewhat simple Biz Dev deal other than the RevShare component of the sales, but technically, this is what customers want at the endgame is they want the right tool, the right job, the right product. If it comes from a startup, you guys don't have to build it. >> I mean, exactly. Let the experts do it, we'll integrate it. It's a great relationship. And the teams work really well together which is fantastic. >> What do you guys do with other startups? If a startup watches and says, hey, I want to be like LogDNA. I want to plug into IBM's Cloud. I want to be just like them and make all that cash. What do they got to do? What's the model? >> I mean, we're constantly looking at startups and new business opportunities obviously. We do this all the time. But it's got to be the right fit, alright? And that's important. It's got to be the right fit with the technology, it's got to be the right fit as far as culture, and team dynamics of not only my team but the startup's teams and how we're going to work together, and this is why it worked really great with LogDNA. I mean, everything, it just all fit, it all made sense, and it had a good business model behind that as well. So, yes, there's opportunities for others but we have to go through and explore all those. >> So, Norman, wonder if you can share, how's your experience been at the show here? We'd love to hear, you're going to have so many startups here. You got record-setting attendance for the show. What were your expectations coming in? What are the KPIs you're measuring with and how has it met what you thought you were going to get? >> No, it's great, I mean, previous to the last year's KubeCon we had not really done any events. We're a small company, we didn't want to spend the resources, but we came in last year and I think what was refreshing was people would talk to us and we're like, oh, yeah, we're not an open source technology, we're actually a log vendor and we can, and we'll-- (Stu laughing) So what we said was, hey, we'll brush that into an experience, and people were like, oh, wow, this is actually pretty refreshing. I'm not configuring my fluentd system, fluentd to tap into another Elasticsearch. There was just not a lot of that. I think this year expectation was we need the size doubled. We still wanted to get the message out there. We knew we were hot off the presses with the IMB public launch of our service on IBM Cloud. And I think we we're expecting a lot. I mean, we more than doubled what our lead count was and it's been an amazing conference. I mean, I think the energy that you get and the quality of folks that come by, it's like, yeah, everybody's running Kubernetes, they know what they're talking about, and it makes that conversation that much easier for us as well. >> Now you're CUBE alumni now too. It's the booth, look at that. (everyone laughing) Well, guys, thanks for coming on, sharing the insight. Good to see you again. Great commentary, again, having distinguished engineering, and these kinds of conversations really helps the community figure out kind of what's out there, so I appreciate that. And if everything's going to be on Kubernetes, then we should put theCUBE on Kubernetes. With these videos, we'll be on it, we'll be out there. >> Hey, yeah, absolutely, that'd be great. >> TheCUBE covers day three. Breaking it down here. I'm John Furrier, Stu Miniman. That's a wrap for us here in Seattle. Thanks for watching and look for us next year, 2019. That's a wrap for 2018, Stu, good job. Thanks for coming on, guys, really appreciate it. >> Thanks. >> Thank you. >> Thanks for watching, see you around. (futuristic instrumental music)

Published Date : Dec 13 2018

SUMMARY :

Brought to you by Red Hat, the CEOs, CTOs, developers, startups. We're going to talk about the startup and the deal with IBM. What do you guys do? And so, the whole idea, even you can go down and new things to do. and all of a sudden you have Kubernetes, What are you guys doing together? about IBM Cloud and the shift that they're moving towards, and you guys got a great relationship. Well, I mean, first of all we were looking for a solution, Yeah, I mean, I think we kind of first got introduced And we just kept on rolling with it so what we've done that's what the promise was. and it's not going to be just called cloud, It didn't have to be, we didn't have to just run in each of the major regions. And so the biggest thing we were hearing was like, machine learning is the new, ML is the new SQL. is going to be automated away. you talked about it So how important is this to your customers, so we made a decision early on to say, Yeah, we made a decision to say, and you got it in. And remember earlier we were talking and I was telling you of having when you break down this monolithic type And the teams work really well together which is What do you guys do It's got to be the right fit with the technology, and how has it met what you thought you were going to get? I mean, I think the energy that you get Good to see you again. Hey, yeah, absolutely, That's a wrap for us here in Seattle. see you around.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
IBMORGANIZATION

0.99+

Jerry ChenPERSON

0.99+

Daniel BergPERSON

0.99+

Norman HsiehPERSON

0.99+

NormanPERSON

0.99+

SeattleLOCATION

0.99+

John FurrierPERSON

0.99+

Cloud Native Computing FoundationORGANIZATION

0.99+

Stu MinimanPERSON

0.99+

CaliforniaLOCATION

0.99+

Red HatORGANIZATION

0.99+

eBayORGANIZATION

0.99+

JohnPERSON

0.99+

two linesQUANTITY

0.99+

last yearDATE

0.99+

DanPERSON

0.99+

Greylock VenturesORGANIZATION

0.99+

2018DATE

0.99+

DanielPERSON

0.99+

three daysQUANTITY

0.99+

KubeConEVENT

0.99+

ElasticTITLE

0.99+

OneQUANTITY

0.99+

IBMsORGANIZATION

0.99+

two thingsQUANTITY

0.99+

Seattle, WashingtonLOCATION

0.99+

DockerConEVENT

0.99+

LogDNAORGANIZATION

0.99+

two guestsQUANTITY

0.98+

one pieceQUANTITY

0.98+

IMBORGANIZATION

0.98+

StuPERSON

0.98+

IKSORGANIZATION

0.98+

single machinesQUANTITY

0.98+

single machineQUANTITY

0.98+

IBM CloudORGANIZATION

0.98+

IMB CloudTITLE

0.97+

one buttonQUANTITY

0.97+

KubernetesTITLE

0.97+

twoQUANTITY

0.97+

eachQUANTITY

0.96+

oneQUANTITY

0.96+

CUBEORGANIZATION

0.96+

CloudNativeConEVENT

0.96+

todayDATE

0.94+

CloudNativeCon North America 2018EVENT

0.94+

single log lineQUANTITY

0.93+

KubeCon 2018EVENT

0.93+

thousandsQUANTITY

0.92+

firstQUANTITY

0.91+

GDPRTITLE

0.91+

about 50 peopleQUANTITY

0.91+

Container WorldORGANIZATION

0.91+

day threeQUANTITY

0.9+

this yearDATE

0.9+

two major startupsQUANTITY

0.9+

threeQUANTITY

0.89+

EdgeTITLE

0.88+

DevOpsTITLE

0.88+

EUORGANIZATION

0.87+

about a year agoDATE

0.86+

a weekQUANTITY

0.86+

ElasticsearchTITLE

0.85+

Tuan Nguyen, Cisco | KubeCon 2018


 

>> From Seattle, Washington, it's theCUBE covering KubeCon and CloudNativeCon North America 2018 brought to you by Red Hat, the Cloud Native Computing Foundation and it's ecosystem partners. >> Hello everyone, welcome back to theCUBE's coverage here. Day three of wall to wall coverage at KubeCon, CloudNativeCon 2018, here in Seattle, theCUBE's been breaking it down all week. I'm John Furrier with Stu Miniman. Our next guest is Tuan Nguyen who is the principal engineer in technical marketing, cloud products and solutions at Cisco Systems. Tuan, welcome to theCUBE. Thanks for joining us. >> Thanks for having me. Thank you. >> So obviously, cloud has been a big part of Cisco. We've seen at Cisco Live last year and Cisco Barcelona. >> Yeah. >> Got your big European event coming up, Cisco Live in Europe. >> Yes. >> Cloud has been a big part of the CEO's conversations on stage. >> Yes. >> Cisco's going all in on cloud, DevNet. >> Yeah. >> DevNet Create, two communities. You guys got a cloud native vibe going on in Cisco. >> Yeah, we do. >> Cloud centered. You got some products that are addressing this. >> Right. >> This is a, shift for Cisco, big time. >> Yeah. >> You've in the cloud, but this is like all. It feels like an all in. >> Right, right. Yeah, yeah, so what we've been evangelizing to people here is that Cisco is a software company, right? We certainly have a very strong heritage in our enterprise relationships related to our hardware platforms but we're transitioning and we're really making that conversion to being a software company. Cisco has been acquiring talent and technology in the past couple years. We've developed some strong relationships with Google and AWS as well and we developed these reference architectures that our customers can buy as kind of a single unit and get the support that they need from us. >> Yeah. >> So. >> We covered your recent announcement with AWS. >> Yes. >> Really nice, elegantly designed Kubernetes strategy where using EKS over here, you got the Cisco stuff on here so it's seamless experience for the customer which is great, congrats, I think that's a great announcement. I think it's directionally correct. I think that's what customers want. But I want to ask you a bigger question I want to get your opinion on, perspective. When you look at Kubernetes, what we're hearing here at the show from end users and from the emerging start ups that are contributing is that, breaking down the monolithic application into a series of granule sets of services is what everyone is doing. That's clearly, that microservices, a variety of other things, Kubernetes can connect that. But it's the network that brings it together. >> Right. >> So we're seeing the policy knobs inside Kubernetes as being a very strategic benefit. We had one expert say, "A lot of people "aren't taking advantage of those policy knobs. "This is a great opportunity." >> Right. >> You guys are, (laughing) as networked as you could be at Cisco. This is your DNA. >> Yeah. >> How are you guys looking at Kubernetes? Are you looking at the policy knobs? How do you talk to your customers about this new opportunity with Kubernetes? >> Yeah. >> What's the real up side-- >> Yeah. >> For your customers with Kubernetes? >> Yeah. So one, you mentioned, we see Kubernetes as very pervasive so we offer an on prem version of Kubernetes and of course, you know, we partner with Google and with AWS to deliver on cloud versions of Kubernetes and related to policies, application policies, in the form of Istio and network policies or security policies in the form of a network interface. Our on prem solution offers three types of CNIs. So we're very flexible in that way and certainly if you are a Cisco customer and you have a Cisco ecosystem of hardware platforms then we natively integrate into those platforms and we let you leverage your existing investments, yeah. >> So if I look at it that way, then I'm saying, okay, I'm good with Cisco right now. >> Yeah. >> Do I have to change anything with Kubernetes? What's the impact to me, as a Cisco customer? >> Yeah. >> Is this added value? Consistent environment? What's the impact to the customer's day to day, operational? (laughing) >> Sure, sure. Yeah. >> Environment? >> Yeah, so our customers are asking us to tie both VM based and container based workloads into CICD, so we obviously, with with our ACI/CNI we give them the capability to construct policies in Kubernetes that end up on the hardware platform, right? That's number one. Then we also have a hardware registry, we have security policies, that can be carried across different platforms, so in your private cloud and VMware and OpenStack, you can carry those same policies. For us, we've got application delivery, frameworks and platforms, that deliver the application in the form of both VM and container based as well as bare metal and we kind of unify the user experience, when it comes to application deployment in Kubernetes. >> Yeah, so Tuan, I'm actually glad that we got you towards the end of what we've been talking about here because one of the things we've been teasing apart is, multi clouds, in many ways, is like what we've been talking about a long time about multi vendor. >> Yeah. >> And the networking space is an area that we really understand. You know, what worked and what didn't work in a multi vendor world and the management piece was often the breaking point because just stitching all those together, we've looked for the last few years, customers have multi cloud and getting their arms around that and how do I manage that, can be a real challenge. >> Yeah, yeah. >> We know Cisco's making investments, they've made acquisitions. Tell us, what have we learned from the past? What's different about this now that will make it successful where management has been one of the pitfalls for quite a long time? >> Yeah, yeah. So I think what we've learned from the past is that customers are asking us for policies that can span across the multi cloud, right? So, whereas certain platforms will give you a hybrid cloud experience, Cisco is investing in things like VPN meshed apologies into CSR, in ASR, in protecting workloads as they move across different cloud targets. And then also in the provisioning and life cycle management. We feel that customers want the capability to run applications in any cloud environment and under any type of overlay or underlay networking platforms, yeah. >> Tuan, one of the things that you talk about not only getting your arms around it but there is multi axis's that I need to optimize for. One of the ones, of course, sorting out is cost. So, you know, where does Cisco sit in this environment? The big shift that I think was really highlighted for me last year, going to Cisco Live is, it used to be most of what I'm managing, I control. >> Right. >> Today, most of the network and most of the environments that I'm in charge of? They're outside of my purview. >> Right. >> With doing that multi cloud world. >> Right. >> So how I make sure that I don't, you know, get myself in trouble with the CFO? >> Right. >> Or have unexpected things come up? >> Right, right, yeah. I came through a software acquisition called CliQr Technologies and CliQr Technologies is that one tool that gives you that experience and allows you to see cloud cost. So cloud cost from a hourly, metered perspective but also from a budgeting perspective. And we're adding additional components into our platform that gives you like true cost for all of your compute, all of your network, your storage, your services like Lambda and then also makes recommendations on the instant sizes that you need to use. We have policies like suspension policies that help our customers to save on their cloud bill. In a lot of ways, the life cycle management aspect of applications is something that differentiates us from other cloud management platforms. >> Talk about the cost side and the cost of ownership. I've always been talking about the cloud as the TCO or total cost of ownership, changes a bit. What are some of the challenges that you've seen the customers having that you guys are helping with? When you look at integrating security, networking and application performance and management? Cause it's not siloed anymore. >> Yeah. >> They're integrating together. >> That's right. >> This is a new dynamic. >> Right, right. >> What's state of the art? What are you guys doing? You guys address that? What are some of the customer challenges? Just, what's your thoughts on that area? >> Yeah so most of the time there are two basic challenges to this. One is, you know bringing the cloud economy into the private cloud consumption is something that our platform does. And then also being able to visualize all the costs. Helping our customers to make good decisions about what types of workloads run where best and whether it's, so we enable, obviously, VMs as well as cloud native, container based, micro services to co-exist in a single platform so we'll deploy VMs and containers in a hybrid fashion. >> Yeah. >> Or we'll deploy them into the same and we'll give you the utilization of those workloads based on dollar amounts, based on run time and also based on the type of workload. >> So here's the curve ball question for you. Now multi cloud comes into the equation? >> Yeah. >> How do you guys deal with that because workload, in some cases, I've heard from customers that refactoring those workloads is a problem. >> Right. >> So if I'm going to run true multi cloud, I'm going to have multiple clouds, I need networks to know, have smarts, around where I want to put that and do I want it in different geography maybe or region? So the network has the intelligence on a lot of things. >> Right. >> How are you guys addressing the multi cloud component? >> Yeah, yeah. >> With workload? Without refactoring? >> Yeah. So because we can compose applications that consist of both VMs and containers, right? One of the projects, just one of the use cases that we worked on with our relationship with Google was to, from cloud center, to deploy cloud native workloads in GKE that would navigate and basically traverse the VPN network to go back into the on prem target in order to access a database that was kind of a legacy database using an API URL. So that whole workflow was something that we solved for with our reference architecture so, you know, we obviously have the portfolio of products that allows our customers to take advantage of both hardware, software and networking and security and monitoring all in one reference architecture. >> A lot of opportunities for you guys. I think you're positioned well. We've covered you guys on the DevNet, DevNet Create. >> Yeah. >> You're seeing the cloud center, this dashboard kind of model of looking at the operations side, the development side. A lot of changes. Really kind of fit right into your wheelhouse. >> Yes, yeah. >> I think the Kubernetes policy knobs, it's a big story that I'm walking away with on this trip and saying, wow, policy sounds like a networking thing. Networking guys love policy. >> Yeah. >> If you can automate it? >> Yeah, that's right. >> And managed the costs? >> Yeah. >> It's a good thing. >> Yeah. >> Thanks for coming on, appreciate your insight. >> Thank you, thank you very much. >> CUBE coverage here, day three continues. I'm John Furrier with Stu Miniman. Stay with us for wall to wall coverage here at KubeCon, CloudNativeCon. We'll be right back with more, after this short break. (upbeat techno music)

Published Date : Dec 13 2018

SUMMARY :

brought to you by Red Hat, to theCUBE's coverage here. Thanks for having me. cloud has been a big part of Cisco. Got your big European event of the CEO's conversations on stage. Cisco's going all in You guys got a cloud native that are addressing this. This is a, You've in the cloud, and get the support announcement with AWS. experience for the customer the policy knobs inside Kubernetes as networked as you could be at Cisco. and we let you leverage your So if I look at it that way, Yeah. that deliver the application actually glad that we got you and the management piece has been one of the pitfalls learned from the past One of the ones, of course, and most of the environments on the instant sizes that you need to use. and the cost of ownership. Yeah so most of the time into the same and we'll So here's the curve How do you guys So the network has the One of the projects, A lot of opportunities for you guys. You're seeing the cloud center, that I'm walking away with on this trip appreciate your insight. to wall coverage here

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
CiscoORGANIZATION

0.99+

GoogleORGANIZATION

0.99+

AWSORGANIZATION

0.99+

John FurrierPERSON

0.99+

Cloud Native Computing FoundationORGANIZATION

0.99+

SeattleLOCATION

0.99+

Red HatORGANIZATION

0.99+

Stu MinimanPERSON

0.99+

CliQr TechnologiesORGANIZATION

0.99+

Tuan NguyenPERSON

0.99+

EuropeLOCATION

0.99+

OneQUANTITY

0.99+

KubeConEVENT

0.99+

last yearDATE

0.99+

bothQUANTITY

0.99+

last yearDATE

0.99+

Cisco SystemsORGANIZATION

0.99+

TuanPERSON

0.99+

Seattle, WashingtonLOCATION

0.98+

oneQUANTITY

0.98+

two communitiesQUANTITY

0.98+

TodayDATE

0.98+

CloudNativeCon North America 2018EVENT

0.98+

one toolQUANTITY

0.97+

CloudNativeCon 2018EVENT

0.97+

two basic challengesQUANTITY

0.97+

Cisco LiveEVENT

0.97+

day threeQUANTITY

0.96+

CloudNativeConEVENT

0.96+

one expertQUANTITY

0.95+

Cisco BarcelonaORGANIZATION

0.95+

single unitQUANTITY

0.95+

KubernetesTITLE

0.94+

theCUBEORGANIZATION

0.94+

single platformQUANTITY

0.93+

ACI/CNIORGANIZATION

0.92+

Day threeQUANTITY

0.9+

LambdaTITLE

0.89+

OpenStackTITLE

0.85+

three typesQUANTITY

0.84+

DevNetTITLE

0.84+

DevNetORGANIZATION

0.83+

KubeCon 2018EVENT

0.8+

KubernetesORGANIZATION

0.8+

one referenceQUANTITY

0.79+

EKSORGANIZATION

0.76+

last few yearsDATE

0.72+

GKETITLE

0.7+

EuropeanOTHER

0.67+

CloudTITLE

0.64+

DevNet CreateORGANIZATION

0.61+

casesQUANTITY

0.59+

couple yearsDATE

0.58+

Joe Beda, Heptio | KubeCon 2018


 

>> From Seattle, Washington, it's theCUBE covering KubeCon and CloudNativeCon North America 2018. Brought to you by Red Hat, the Cloud-Native computing foundation and its ecoystem partners. >> Everyone welcome back to theCUBE's exclusive coverage here live in Seattle for KubeCon and CloudNativeCon 2018. I'm John Furrier with Stu Miniman, breaking down all the content and the analysis, opinion, getting all the data, sharing that with you, three days of wall-to-wall coverage, we're in day three winding down, great event. Our next guest is one of the stars of the show here, original Kubernetes, a pioneer, Joe Beda, also the Kube founder at Heptio, recently sold to VMware in acquisition. Startup only what, two years old? >> Yeah, about two years. >> About two years. Welcome back to theCUBE, great to see you. >> Thanks for having me. >> Google. Great work you've done with Craig and with pioneering Kubernetes, Heptio startup. >> Yep, yep. >> Got taken off the table as you were ramping up. Congratulations! >> Thank you so much! It's been a little bit of a wild ride, I can tell you that. >> So first question for you is, I don't want to get into the whole VMware thing, we're going to hit that up in VMworld next year. But as you look at the ecosystem of Kubernetes, I mean, you've got to be looking at this sayin, "Hey, we knew this was going to be big." You guys have been running it with Borg and where that came from in the DNA. The magic wand almost was kind of passed out. Hey, this happened! It's kind of happening in a big way. What's your reaction? How do you feel at an emotional level? What's the vibe going on in your mind right now? >> I mean, I look at this and it blows my mind. I think we knew that we had a possibility with Kubernetes to do something big, we could feel it. I don't think we ever expected this, to be honest. The thing, though, that I think surprises me, and it was both about building startup and building a company, but also seeing the community grow, is that every time you hire a new person to do a startup, every time you have somebody join the community and start contributing, it's like it's another cylinder in the engine. And it really starts taking it in directions that you had no idea it was going to to go into. And so, I look around here and this is a product of a community. This is not a product of any single company, any single set of folks. I mean, you start things snowballing and interesting things happen, but it really is a group effort. >> It's so hard to do a startup. You know, I've done a lot of startups. We've done a lot of interviews with startups. It's hard. You got to start a company, you got to do all that legal work, then you've got to get the momentum, and it's capped off by the validation, certainly by VMware, who announced heavily at the VMworld, Pat Gelsinger said that Kubernetes is the dial tone. (laughs) And I'm like, okay, I guess. We were talking earlier, it's the ethernet. I've called it the TCP/IP. So, all the analogies come to this enabling kind of capability. And that's where we see a lot of the value. Where do you see the opportunities for the ecosystem to innovate. I mean, getting some clear visibility around the stability. But now value is starting to get created. What's your thoughts on value creation? Where are some areas that are ripe? >> Yeah, well, I think a couple of things. I think we're at the point now where it's about how do we bring these technologies to new people, to new audiences, to folks who might not have heard about it, don't quite get it. How do we make this stuff more relevant to them? So we're moving out of this technology-focus phase, into this phase that's focused on solution and value that's delivered. And this isn't always about innovation and building on top. Some of it is about different ways to do it, and also just, you know, having these ideas just permeate, right? And as technologists, we build on incredibly complicated technology. We look at, say, something like AWS. If you were to approach that brand new without any idea of the history there, it would be incredibly intimidating. But it's been around long enough, it's grown organically, that everyone's like, "Oh yeah, I totally understand all that stuff." It just takes time sometimes for these technologies to become understood, to become part of the fabric of what people assume the technical skill set is. And I think that's a big part of what we're seeing starting to happen now, too. >> Joe, I want to get your viewpoint. When I think about the last ten, fifteen years, the whole discussion of hybrid cloud, multicloud, portability, even thinking about things from a VMware context, or from a cloud-computing context, it seems like we have a lot of false starts and false expectations about, you know, we've listed Pat Gelsinger and Andy Jassy and others who talk about the three laws of the cloud. We're not changing physics. And Kubernetes is super-important for multicloud, but portability was kind of thrown out there. I want to get you to help us tease out what it is, what it isn't, and how do you see multicloud today? >> Yeah, so I mean, first, on the topic of false starts, there's this popular narrative that, oh, it's going to be this, now this is the hot thing, now it's this. And the reality is that main frames are still around. Technologies don't disappear, it's an additive type of thing. So it's not like, say for example, Kubernetes or Serverless or machine learning, right? It's all of those things working together and I think, if you look at it in that way, it doesn't feel like a false start. It just seems like we're adding more different techniques, more technologies onto the pile. In terms of where I see this stuff going, I think multicloud and compatibility do go hand-in-hand. From the very start, we never wanted to pretend that Kubernetes was going to be this magic layer that was going to make differences between different environments disappear. What we did want to do, though, was actually find the commonalities and minimize the extra differences that didn't need to be there. And so a lot of times, when I talked to customers, I don't say, "Hey, don't use this special service in this cloud." I don't tell them that. What I do say, though, is, "If you are going to start using those things, "do it in an eyes-open type of way. "Understand the trade-offs, "understand why you're doing it" versus just willy-nilly adopting technologies cuz they look nice and shiny, and that's what you want to do, right? So I think, whether you're adopting Kubernetes, whether you're adopting a specific cloud technology, whether you're moving to cloud versus actually building automatable infrastructure on prem, make sure that you're thoughtful about how you enter those types of decisions. >> The way the feedback we hear from people here on theCUBE this week and other places as well, is, pick a problem to solve. Don't boil all of the ocean, get in there, use Kubernetes for what you think you can nail a problem on, iterate from there. That's the common theme. Now as you guys pivot over to VMware, they've been investing a lot in their strategy also with AWS, RDS is now on VMware, they'd look at Kubernetes as a great opportunity to bridge on-premises and cloud. So it's clear to see why they like it. Explain for the folks watching who are fans of you and Craig and Heptio, what's next for you guys? You joined VMware, you just closed the deal, you're principal engineer at VM where you're in the business unit side, share some of the specifics that you can on what's going to happen next. >> Yeah, I think it's too early for me to speak on sort of a grand strategy across VMware. I think I'm still mapping things out and understanding things. What I can talk about is the way that we were thinking about the market from Heptio's point of view. And every indication that I've seen that this is actually very, very compatible for VMware. A lot of the keynotes that you saw here at KubeCon Show, that adoption curve, where we're in the early phase versus the early majority, that type of thing, and I think there's some truth to that. But I also think that there's an axis to that, that actually isn't shown up there, around the different personas that you see adopt different technologies inside of the enterprise organization. And so the strength of somebody like VMware, and I think the early adopters for things like Kubernetes, are that operator persona. And we're seeing an evolution of that persona as it starts to come to grips with the world of the cloud. We're moving from a place where things are ticket-based, human intensive, to how do we move to API-driven, policy-drive types of things, right? And so that's obviously where the cloud is. But how do we take those learnings, how do we take those lessons and actually apply those things on problems? And so our goal from Heptio's point of view, and I think it's incredibly well-aligned with VMware, and an enormous opportunity, is taking the VMware-faithful, the folks who do go to VMworld, that have built careers on that solution, how do we help them move their career forward, move their positioning forward in a way that doesn't eliminate their jobs, but actually helps them be smart in a modern world where cloud is actually part of the landscape. >> We had Aparna on from Google, and you know Aparna from your Google days, and she was making a comment about these new personas, new opportunities, new jobs that are opening up based on Kube. Okay, great, we see some of that. And then we've done rift on the idea that Kubernetes also is a uplift for existing roles: system architect, Network Guy, Server Guy, and then the VMware operator that had been wearing virtual machines, this is a lift for them. Talk about what specifically is going to get them jazzed up, is it the policy knobs on Kubernetes, what's going to really appeal to people below Kubernetes and what's really going to appeal to the developers above Kubernetes? >> Well, for centralized IT within an organization, cloud has been a challenge, right? If, I'm not thinking of a specific customer, but it's not insane to think about something like a developer who wants to write an app, they have to file a ticket, it can take anywhere from two weeks to three months to get stuff provisioned, right? And they're sitting there twiddling their thumbs waiting to actually get that stuff ready. Meanwhile, they take their credit card, go to a cloud, get a machine up and running within 30 seconds, and get their app shipped. So while they're waiting on that ticket, they can get that app shipped, and then they dare their manager to deny the credit card charge when it comes due. That is a challenge for centralized IT which oftentimes has not had any competition. Now, all of a sudden, they find themselves in a situation where they're competing with cloud for the hearts and minds of their own customers, for their developers. And different organizations have reacted to this in different ways. Some of them had said, we're just going to explode out IT and actually say to different business units, "You own your own destiny." But, depending on the enterprise, depending on the goals, depending on their requirements around regulatory needs, around policy, around cost controls, around mobility of developer skills across the organization, that may or may not work for them. And so, for me, the bridge forward for that centralized IT, is really one of giving them the power tools so they can actually serve their customers better in a world where cloud exists. >> Yeah. Their jobs! That's their job to serve the business. >> Well, I mean, the bar has been raised, right? And so we want to help them meet that challenge. >> Awesome. >> Joe, I want to get your thoughts on this growing ecosystem. I said in our open this morning, we've been looking for the last five years or so. Where is that independent, cloud-computing show? And sitting here with 8 thousand people, and another 2 thousand people are in the hallways or on the wait list and things like that. It's here, and there's all of these projects into multiple communities come together. How does it feel that Kubernetes, was it kind of the first domino to help tip something broader with CloudNative? >> I mean it feels really good, to be honest. I think one of the things that we saw Heptio as, and I think VMware is actually in a great position also, is to be a neutral party that really is on the side of customers as they enter this complex world where they're dancing with elephants that are the big cloud providers. And I think that there is an enormous appetite for customers to actually have trusted partners in that world. Now, with respect to the conference, I think, what I love doing is I love being on the floor here, I love talking to people, I love going to the session tracks. That's where I think the heart of this conference is. Some of the contributor community days that happened on Monday that don't get a lot of coverage, the big headlines are one thing but there really is an undercurrent of community that's happening in this conference that is really something pretty special. >> I think that's a great point, and, at least what I've seen that's contributed, you know, the Envoy Group, tomorrow there's the Operators Group, this is not a monolithic community, it's not like, look, I've been at VMworld for years. It was about virtualization and primarily a single product from a single company and everything that wrapped around it. This is not a vendor doing it, there's all of these. I talked to the people that all they care about is Helm, we talked about all these different pieces, and many of them tie into what was going on at Kubernetes, but there's just so much diversity, and it's a common ground for everybody to work together. >> And I think, this is one of the things that I think has been interesting about the CNCF is that there is no, there is an idea that we want to create a set of projects that work well together, but there also is the realization that there is no one way to skin the cat, there is no one way to solve a problem. So there is room for projects to disagree, there's room for projects to experiment, there is room for folks to try and find their audience and be successful. >> That's the modern upgrade in my mind, to, not going against the open source ethos but also innovating with it, You're balancing commercial so you just, I think they've got to apply this upstream concept called CNCF where the downstream benefits for commercialization, you can still do the open source community thing while having an impact downstream to IT and just regular developers. This is the trend we see at Enterprise when we talk to the customers, we talk to other people, IT has been outsourced for decades. Now there has to be a competitive advantage, and we have the competition thing that you pointed out. And the smart CIO CX's are bringing developers in to create a competitive advantage, and it's a new reset. And, not throwing away networks, they're not throwing away compute and storage. They're going to change it. And I think this is where the real tailwind is. Do you agree with that or what's your thoughts? >> The way I like to think about it is that, and I'm using company names here as an example, but I think there is this race between Tesla learning how to become a car company versus, say, Ford or GM learning how to become a software company, right? And that dynamic is playing itself out across every single industry. And I think there is not a CEO or CIO or board out there that doesn't realize that the way for us to be relevant in the future is to turn software into, not just a cost-center and something we deal with, but something that becomes a fundamental advantage and driver of our business. >> Every industry: media, software! We're a software company that happens to do media, with theCUBE. You're totally right, it's just like-- >> Any industry. This is why Amazon's getting into grocery stores. >> It's integration. This is a completely new horizontal dynamic with a little bit of special machine learning at the outlay. >> We're moving into a software-defined world, for sure. >> Joe, been great to have your commentary here on theCUBE. Thanks for sharing. Congratulations on the acquisition. Super outcome, the numbers floating out there. It's pretty large, good deal. We have no comment. (laughs) >> Open source! >> Read DCSE C file. >> Open source business models are changing, but the value is still the same. Those who create the value can extract it. That's the ethos of open source, of course theCUBE as well. Thanks for watching. Stay with us for more coverage after this short break.

Published Date : Dec 13 2018

SUMMARY :

Brought to you by Red Hat, and the analysis, opinion, Welcome back to theCUBE, great to see you. and with pioneering Kubernetes, Got taken off the table I can tell you that. What's the vibe going on is that every time you hire for the ecosystem to innovate. and also just, you know, having and how do you see multicloud today? and minimize the extra differences share some of the specifics that you can around the different personas that you see is it the policy knobs on Kubernetes, and then they dare their manager to deny That's their job to serve the business. Well, I mean, the bar or on the wait list and things like that. that are the big cloud providers. I talked to the people that And I think, this is one of the things And I think this is where that doesn't realize that the way that happens to do media, This is why Amazon's machine learning at the outlay. We're moving into a Congratulations on the acquisition. but the value is still the same.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
FordORGANIZATION

0.99+

John FurrierPERSON

0.99+

Andy JassyPERSON

0.99+

Joe BedaPERSON

0.99+

Pat GelsingerPERSON

0.99+

AmazonORGANIZATION

0.99+

JoePERSON

0.99+

Stu MinimanPERSON

0.99+

two weeksQUANTITY

0.99+

GMORGANIZATION

0.99+

MondayDATE

0.99+

VMwareORGANIZATION

0.99+

Red HatORGANIZATION

0.99+

Envoy GroupORGANIZATION

0.99+

VMworldORGANIZATION

0.99+

AWSORGANIZATION

0.99+

SeattleLOCATION

0.99+

KubeConEVENT

0.99+

three monthsQUANTITY

0.99+

2 thousand peopleQUANTITY

0.99+

first questionQUANTITY

0.99+

tomorrowDATE

0.99+

next yearDATE

0.99+

CraigPERSON

0.99+

8 thousand peopleQUANTITY

0.99+

Seattle, WashingtonLOCATION

0.99+

oneQUANTITY

0.99+

three lawsQUANTITY

0.99+

TeslaORGANIZATION

0.99+

HeptioORGANIZATION

0.98+

KubernetesTITLE

0.98+

KubeCon ShowEVENT

0.98+

this weekDATE

0.98+

HeptioPERSON

0.98+

firstQUANTITY

0.98+

theCUBEORGANIZATION

0.98+

three daysQUANTITY

0.97+

GoogleORGANIZATION

0.97+

fifteen yearsQUANTITY

0.97+

about two yearsQUANTITY

0.97+

Cloud-NativeORGANIZATION

0.97+

CloudNativeCon North America 2018EVENT

0.96+

Operators GroupORGANIZATION

0.96+

AparnaPERSON

0.96+

bothQUANTITY

0.96+

single productQUANTITY

0.96+

BorgPERSON

0.96+

KubernetesPERSON

0.96+

CloudNativeCon 2018EVENT

0.96+

About two yearsQUANTITY

0.95+

first dominoQUANTITY

0.93+

single companyQUANTITY

0.93+

KubeORGANIZATION

0.92+

KubernetesORGANIZATION

0.92+

todayDATE

0.91+

single setQUANTITY

0.91+

decadesQUANTITY

0.89+

last five yearsDATE

0.87+

CNCFORGANIZATION

0.86+

DCSE CTITLE

0.85+

two years oldQUANTITY

0.82+

KubeCon 2018EVENT

0.82+

tenQUANTITY

0.81+

this morningDATE

0.81+

thingsQUANTITY

0.81+

one thingQUANTITY

0.8+

day threeQUANTITY

0.8+

single industryQUANTITY

0.78+

Stephan Fabel, Canonical | KubeCon 2018


 

>> Live, from the Seattle, Washington. It's theCUBE, covering KubeCon and CloudNativeCon, North America 2018, brought to you by Red Hat, the Cloud Native Computing Foundation and it's ecosystem partners. >> Welcome back everyone. We're live here in Seattle for theCUBE's exclusive coverage of KubeCon and CloudNativeCon 2018. I'm John Furrier at Stuart Miniman. Our next guest Stephan Fabel, who is the Director of Product Management at Canonical. CUBE alumni, welcome back. Good to see you. >> Thank you. Good to see you too. Thanks for having me. >> You guys are always in the middle of all the action. It's fun to talk to you guys. You have a pulse on the developers, you have pulse on the ecosystem. You've been deep in it for many, many years. Great value. What's hot here, what's the announcement, what's the hard news? Let's get to the hard news out of the way. What's happening? What's happening here at the show for you guys? >> Yeah, we've had a great number of announcements, a great number of threads of work that came into fruition over the last couple of months, and now just last week where we announced hardware reference architectures with our hardware partners, Dell and SuperMicro. We announced ARM support, ARM64 support for Kubernetes. We released our version 1.13 of our Charmed Distribution of Kubernetes, last week And we also released, very proud to release, MicroK8s. Kubernetes in a single snap for your workstation in the latest release 1.13. >> Maybe explain that, 'cause we often talk about scale, but there is big scale, and then we're talking about edge, we're talking about so many of these things. >> That's right. >> That small scale is super important, so- >> It really is, it really is, so, MicroK8s came out of this idea that we want to enable a developer to just quickly standup a Kubernetes cluster on their workstation. And it really came out of this idea to really enable, for example, AIML work clouds, locally from development on the workstation all the way to on-prem and into the public cloud. So that's kind of where this whole thing started. And it ended up being quite obvious to us that if we do this in a snap, then we actually can also tie this into appliances and devices at the edge. Now we're looking at interesting new use cases for Kubernetes at the edge as an actual API end point. So it's a quite nice. >> Stephan talk about ... I want to take a step back. There's kind of dynamics going on in the Kubernetes wave, which by the way is phenomenal, 8000 people here at KubeCon, up from 4000. It's got that hockey stick growth. It's almost like a Moore's Law, if you will, for the events. You guys have been around, so you have a lot of existing big players that have been in the space for a while, doing a lot of work around cloud, multi-cloud, whatever ... That's the new word, but again, you guys have been there. You got like the Cisco's of the world, you guys, big players actively involved, a lot of new entrants coming in. What's your perspective of what's happening here? A lot of people looking at this scratching their head saying: Okay I get Kubernetes, I get the magic. Kubernetes enables a lot of things. What's the impact to me? What's in it for me as an enterprise or a developer? How do you guys see this market place developing? What's really going on here? >> Well I think that the draw to this conference and to technology and all the different vendors et cetera, it's ultimately a multi-cloud experience, right? It is about enabling workload portability and enabling the operator to operate Kubernetes, independently of where that is being deployed. That's actually also the core value proposition of our charmed Kubernetes. The idea that a single operational paradigm allows you to experience, to deploy, lifecycle manage and administer Kubernetes on-prem, as well as any of the public clouds, as well as on other virtual substrates, such as VMware. So ultimately I think the consolidation of application delivery into a single container format, such as Docker and other compatible formats, OCI formats right? That was ultimately a really good thing, 'cause it enabled that portability. Now I think the question is, I know how to deploy my applications in multiple ways, 'cause it's always the same API, right? But how do I actually manage a lot of Kubernetes clusters and a lot of Kubernetes API end points all over the place? >> So break down the hype and reality, because again, a lot of stuff looks good on paper. Love the soundbites of people saying, "Hey, Kubernetes," all this stuff. But people admitting some things that need to be done, work areas. Security is a big concern and people are working on that. Where is the reality? Where does the rubber meet the road when it comes down to, "Okay, I'm an enterprise. What am I buying into with Kubernetes? How do I get there?" We heard Lyft take an approach that's saying, "Look, it solved one problem." Get a beachhead and take the incremental approach. Where's the hype, where's the reality? Separate that for us. >> I think that there is certainly a lot of hype around the technology aspect of Kubernetes. Obviously containerization is invoked. This is how developers choose to engage in application development. We have Microservices architecture. All of those things we're very well aware of and have been around for quite some time and in the conversation. Now looking at container management, container orchestration at scale, it was a natural fit for something like Kubernetes to become quite popular in this space. So from a technology perspective I'm not surprised. I think the rubber meets the road, as always, in two things: In economics and in operations. So if I can roll out more Kubernetes clusters per day, or more containers per day, then my competitor ... I gain a competitive advantage, that the cost per container is ultimately what's going to be the deciding factor here. >> Yeah, Stephan, when I think about developers how do I start with something and then how do I scale it out in the economics of that? I think Canonical has a lot of experience with that to share. What are you seeing ... What's the same, what's different about this ecosystem, CloudNative versus, when we were just talking about Linux or previous ways of infrastructure? >> Well I think that ultimately Kubernetes, in and of itself, is a mechanism to enable developers. It plays one part in the whole software development lifecycle. It accelerates a certain part. Now it's on us, distributors of Kubernetes, to ensure that all the other portions of this whole lifecycle and ecosystem around Kubernetes, where do I deploy it? How do I lifecycle manage it? If there's a security breach like last Monday, what happens to my existing stack and how does that go down? That acceleration is not solved by Kubernetes, it's solved for Kubernetes. >> Your software lives in lots and lots of environments. Maybe you can help clarify for people trying to understand how Kubernetes fits, and when you're playing with the public cloud, your Kubernetes versus their Kubernetes. The distinction I think is, there's a lot of nuance there that people may need help with. >> That's true, yeah. So I think that, first of all, we always distance ourself from the notion of having our Kubernetes. I think we have a distribution of Kubernetes. I think there is conformance, tests that are in place that they're in place for a reason. I think it is the right approach, and we won't install a fourth version of Kubernetes anytime soon. Certainly, that is one of the principles we adhere to. What is different about our distribution of Kubernetes is the operational tooling and the ability to really cookie-cutter out Kubernetes clusters that feel identical, even though they're distributed and spread across multiple different substrates. So I think that is really the fundamental difference of our Kubernetes distribution versus others that are out there on the market. >> The role of developers now, 'cause obviously you're seeing a lot of different personas emerging in this world. I'm just going to lay them out there and I want to get your reaction. The classic application developer, the ones who are sitting there writing code inside a company. It could be a consumer company like Lyft or an enterprise company that needs ... They're rebuilding inside, so it's clear that CIOs or enterprises, CXOs or whatever the title is, they're bringing more software in-house, bringing that competitive advantage under application development. You have the IT pro expert, practitioner kind of role, classic IT, and then you got the opensource community vibe, this show. So you got these three things inter-playing with each other, this show, to me feels a lot like an opensource show, which it is, but it also feels a lot like an IT show. >> Which it also is. >> It also is, and it feels like an app development show, which it also is. So, opportunity, challenge, is this a marketplace condition? What's you thoughts on these kind of personas? >> Well I think it's really a question of how far are you willing to go in your implementation of devops cultural change, right? If you look at that notion of devops and that movement that has really taken ahold in people's minds and hearts over the last couple of years, we're still far off in a lot of ways and a lot of places, right? Even the places who are saying they're doing devops, they're still quite early, if at all, on that adoption curve. I think bringing operators, developers and IT professionals together in a single show is a great way for the community and for the market to actually engage in a larger devops conversation, without the constraint of the individual enterprise that those teams find themselves in. If you can just talk about how you should do something better and how would that work, and there is other kinds of personas and roles at the same table, it is much better that you have the conversation without the constraint of like a deadline or a milestone, or some outage somewhere. Something is always going on. Being able to just have that conversation around a technology and really say, "Hey, this is going to be the one, the vehicle that we use to solve this problem and further that conversation," I think it's extremely powerful. >> Yeah, and we always talk about who's winning and who's losing. It's what media companies do. We do it on theCUBE, we debate it. At the end of the day we always like ... There's no magic quadrant for this kind of market, but the scoreboard can be customers. Amazon's got over 5000 reputable customers. I don't know how many CNCF has. It's probably a handful, not 5000. The customer implications are really where this is going. Multi-cloud equals choice. What's your conversations like with customers? What do you see on the customer landscape in terms of appetite, IQ, or progress for devops? We were talking, not everyone's on server lists yet and that's so obvious that's going to be a big thing. Enterprises are hot right now and they want the tech. Seeing the cloud growth, where's your customer-base? What are those conversations like? Where are they in the adoption of CloudNative? >> It's an extremely interesting question actually, because it really depends on whether they started with PaaS or not. If they ever had a PaaS strategy then they're mostly disillusioned. They came out, they thought it was going to solve a huge problem for them and save them a lot of money, and it turns out that developers want more flexibility than any PaaS approach really was able to offer them. So ultimately they're saying, "You know what, let's go back to basics." I'll just give you a Kubernetes API end point. You already know how to deal with everything else beyond that, and actually you're not cookie-cuttering out post ReSQueL- >> Kubernetes is a reset to PaaS. >> It really does. It kind of disrupted that whole space, and took a step back. >> All right, Stephan, how about Serverless. So a lot of discussion about Knative here. We've been teasing out where that fits compared to functions from AWS and Azure. What's the canonical take on this? What are you hearing from your customers? >> So Serverless is one of those ... Well it's certainly a hot technology and a technology of interest to our customers, but we have longstanding partnerships with Galactic Fog and others in place around Serverless. I haven't seen real production deployments of that yet, and frankly it's probably going to take a little bit longer before that materializes. I do think that there's a lot of efforts right now in containerization. Lots of folks are at that point where they are ready to, and are already running containerized workloads. I think they're busy now implementing Kubernetes. Once they have done that, I think they'll think a little bit more about Serverless. >> One of the things that interest me about this ecosystem is the rise of Kubernetes, the rise of choice, the rise of a lot of tools, a lot of services, trying to fend off the tsunami wave that's hit the beach out of Amazon. I've always said in theCUBE that that's ... They're going to take as much inland territory on this tsunami unless someone puts up a sea wall. I think this is this community here. The question is, is that ... And I want to get your expert opinion on this, because the behemoths, the big guys are getting richer. The innovation's coming from them, they have scale. You mentioned that as a key point in the value of Kubernetes, is scale, as one of those players, I would consider in the big size, not like a behemoth like an Amazon, you got a unique position. How can the industry move forward with disruption and innovation, with the big guys dominating? What has to happen? Is there going to change the size of certain TAMs? Is there going to be new service providers emerging? Something's got to give, either the big guys get richer at the expense of the little guys, or market expands with new categories. How do you guys look at that? Developers are out there, so is it promising look to new categories, but your thoughts. >> I think it's ... So a technology perspective certainly would be, there could be a disruptive technology that comes in and just eats their lunch, which I don't believe is going to happen, but I think it might actually be a more of a market functionality actually. If it goes down to the economics, and as they start to compete there will be a limit to the race to the bottom. So if I go in on an economical advantage point as a public cloud, then I can only take that so far. Now, I can still take it a lot further, but there's going to be a limit to that ultimately. So, I would say that all of the public clouds, we see that increasingly happening, are starting to differentiate. So they're saying, "Come to me for IML." "Come to me for a rich service catalog." "Come to me for workload portability," or something like that, right? And we'll se more differentiation as time goes on. I think that will develop in a little bit of a bubble, to the point where actually other players who are not watching, for example, Chinese clouds, right? Very large, very influential, very rich in services, they can come in and disrupt their market in a totally different way than a technology ever could. >> So key point you mentioned earlier, I want to pivot on that and get to the AI conversation, but scale is a competitive advantage. We've seen that on theCUBE, we see it in the marketplace. Kubernetese by itself is great but at scale it gets better, got nobs and policy. AI is a great example of where a dormant computer science concept that has not yet been unleashed ... Well, it gets unleashed by cloud. Now that's proliferating. AI, what else is out there? How do you see this trend around just large-scale Kubernetes, AI and machine learning coming on around the corner? That's going to be unique, and is new. So you mentioned the Chinese cloud could be a developer here. It's a lever. >> Absolutely, we've been involved with kubeflow since the early days. Early days, it's barely a year, so what early days? It's a year old. >> It's yesterday. >> So a year a ago we started working with kubeflow, and we published one of the first tutorials of how to actually get that up and running and started on Ubuntu, and with our distribution of Kubernetes, and it has since been a focal point of our distribution. We do a couple of things with kubeflow. So the first thing, something that we can bring as a unique value preposition is, because we're the operating system for almost all GKE, all of AKS, all EKS, such a strong standing as an operating system, and have strong partnerships with folks like NVIDIA. It was kind of one of the big milestones that we tried to achieve and we've since completed, actually as another announcement since last week, is the full automatic deployment of GPU enablement on Kubernetes clusters, and have that identical experience happen across the public clouds. So, GPGPU enablement on Kubernetes, as one of the key enablers for projects like kubeflow, which gives you machine learning stacks on demand, right? And then a parallel, we've been working with kubeflow in the community, very active, formed a steering committee to really get the industry perspective into the needs of kubeflow as a community and work with everybody else in that community to make sure that kubeflow releases on time, and hopefully soon, and a 1.0, which is due this summer, but right now they're focused on 0.4. That's a key area of innovation though, opportunity. >> Oh, absolutely. >> I see Amazon's certainly promoting that. What else is new? I've got one last question for you. What's next for you guys? Get a quick plugin for Canonical. What's coming around the corner, what's up? >> We're definitely happy to continue to work on GPGPU enablement. I think that is one of the key aspects that needs to stay ... That we need to stay on top of. We're looking at Kubernates across many different use cases now, especially with our IoT, open to core operating system, which we'll release shortly, and here actually having new use cases for AIML inference. For example, out at the edge looking at drones, robots, self-driving cars, et cetera. We're working with a bunch of different industry partners as well. So increased focus on the devices side of the house can be expected in 2019. >> And that's key these data, in a way that's really relevant. >> Absolutely. >> All right, Stephan, thanks for coming on theCUBE. I appreciate it, Canonical's. Great insight here, bringing in more commentary to the conversation here at KubeCon, CoudNativeCon. Large-scale deployments as a competitive advantage. Kubernetes really does well there: Data, machine learning, AI, all a part of the value and above and below Kubernatese. We're seeing a lot of great advances. CUBE coverage here in Seattle. We'll be back with more after this short break. (digital music)

Published Date : Dec 13 2018

SUMMARY :

North America 2018, brought to you by Red Hat, Good to see you. Good to see you too. You guys are always in the middle of all the action. in the latest release 1.13. Maybe explain that, 'cause we often talk about scale, and into the public cloud. What's the impact to me? and enabling the operator to operate Kubernetes, that need to be done, work areas. I gain a competitive advantage, that the cost per container in the economics of that? in and of itself, is a mechanism to enable developers. that people may need help with. Certainly, that is one of the principles we adhere to. You have the IT pro expert, practitioner kind of role, What's you thoughts on these kind of personas? and really say, "Hey, this is going to be the one, At the end of the day we always like ... You already know how to deal It kind of disrupted that whole space, and took a step back. What's the canonical take on this? of interest to our customers, One of the things that interest me about this ecosystem and as they start to compete there will be a limit around the corner? since the early days. in that community to make sure What's coming around the corner, what's up? So increased focus on the devices side of the house in a way that's really relevant. AI, all a part of the value and above and below Kubernatese.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
StephanPERSON

0.99+

2019DATE

0.99+

Stephan FabelPERSON

0.99+

NVIDIAORGANIZATION

0.99+

SeattleLOCATION

0.99+

Cloud Native Computing FoundationORGANIZATION

0.99+

John FurrierPERSON

0.99+

CanonicalORGANIZATION

0.99+

DellORGANIZATION

0.99+

Red HatORGANIZATION

0.99+

AmazonORGANIZATION

0.99+

AWSORGANIZATION

0.99+

last weekDATE

0.99+

KubeConEVENT

0.99+

CiscoORGANIZATION

0.99+

SuperMicroORGANIZATION

0.99+

yesterdayDATE

0.99+

8000 peopleQUANTITY

0.99+

last MondayDATE

0.99+

one partQUANTITY

0.99+

CloudNativeConEVENT

0.99+

ServerlessORGANIZATION

0.99+

LyftORGANIZATION

0.99+

two thingsQUANTITY

0.98+

oneQUANTITY

0.98+

a yearQUANTITY

0.98+

Seattle, WashingtonLOCATION

0.98+

LinuxTITLE

0.97+

a year a agoDATE

0.97+

first thingQUANTITY

0.97+

KubernetesTITLE

0.97+

first tutorialsQUANTITY

0.96+

CloudNativeCon 2018EVENT

0.96+

UbuntuTITLE

0.96+

threeQUANTITY

0.96+

ChineseOTHER

0.96+

OneQUANTITY

0.95+

one problemQUANTITY

0.95+

waveEVENT

0.95+

kubeflowTITLE

0.95+

single showQUANTITY

0.94+

5000QUANTITY

0.94+

last couple of monthsDATE

0.94+

CUBEORGANIZATION

0.93+

AKSORGANIZATION

0.93+

fourth versionQUANTITY

0.92+

KuberneteseTITLE

0.92+

one last questionQUANTITY

0.92+

this summerDATE

0.92+

4000QUANTITY

0.91+

CNCFORGANIZATION

0.91+

MicroK8sORGANIZATION

0.91+

KubeCon 2018EVENT

0.91+

singleQUANTITY

0.87+

ARMORGANIZATION

0.87+

last couple of yearsDATE

0.86+

firstQUANTITY

0.85+

single containerQUANTITY

0.85+

North America 2018EVENT

0.84+

CoudNativeConORGANIZATION

0.83+

Hussein Khazaal, Nuage Networks | KubeCon 2018


 

>> From Seattle, Washington, it's theCUBE! Covering KubeCon and CloudNativeCon North America 2018. Brought to you by Red Hat, the Cloud Native Computing Foundation, and it's ecosystem partners. >> Welcome back everyone, it's theCUBE's live coverage, day three of three days of coverage here at KubeCon 2018, and CloudNativeCon put on by the Linux Foundation and CNCF. I'm John Furrier with theCUBE with Stu Miniman, breaking down all the action. Our next guest is Hussein Khazaal, who's the Vice President of Marketing and Partners of Nuage Networks. Thanks for coming on, good to see you! >> Thanks, John, good to see you. >> Love that shirt, automation... >> Yeah. >> That's the theme. >> That is! (chuckles) >> Cloud native, cloud operations, thanks for coming on. So take a minute just to talk about what you guys are doing with the show, what's the key value proposition you guys are part of, what conversations you're having. >> Right so, for Nuage we basically deliver a software-based virtual networking solution. And a lot of our customers appreciate the value it brings because they have multi cloud environments, they have workloads in on-prem. Those are mixed, some VM, some bare metal, some containers, they have workloads in public cloud, and what we enable them with our software is to stitch all that together using an API-driven networking model that has policy applied to the workload, and you have that mixed workload environment with network policy and security built into that platform. And that's kind of where we help not really break what Kubernetes brings to developers, but maintain that, giving the IT and infrastructure folks the ability to have visibility control and maintain that. >> We were just talking with a partner from Google, we always talk to the same companies, so some of the senior people at AWS, and all the clouds. Obviously cloud operations is what everyone wants, that's the preferred environment, whether you're on-premises or in the cloud, Edge is now on the horizon. Storage, networking and compute is still the core, it's just a little bit different. But there's new jobs that are emerging around Kubernetes, you see the job board, but it's also revitalizing older roles, the network guy, the storage guy, the server guy, traditional IT enterprises are seeing those roles transform. So I got to ask you, as you guys are in the middle of all the networking side, how do see that person, that role, that piece of the puzzle in an IT enterprise change with Kubernetes? >> Absolutely, I mean, the one thing that we had some of our customers do is that these roles are no longer defined by a specific, you have to have these mixed skills, you have to understand what the developer needs as an infrastructure person, and the developer needs what kind of tools that they need to implement so you can do your job, and that's why Kubernetes, and when you're talking about networking and security, you have to understand Linux, you have to understand programming, to be able to give the developers the tools that they need to develop and understand the requirements and then by the same token, they need to make sure that from an intercom perspective, you need to understand, you still need the visibility, you still need control, right? And that balance can only be achieved if you kind of do the exchange roles, right? You get to work with the developers, and then the developers need to look at infrastructure and that's kind of where you stick at Kubernetes, and with what Red Hat is doing with OpenShift, and a lot of the vendors in terms of integrating with CNI, to be able to plug in and tap in and be able to deliver that security and that relief. >> I get what you're saying. I think you've got a great thread there that I want to pull on a little bit. So, I think back at networking over the last few decades, we used to call it multi-vendor, now we call it multi-cloud, we've been talking about automation forever, but it's different now. So, I think that thread you were going on is part of that answer, but explain why now, multi cloud and automation, what's that's real about that compared to what we were talking about the dominant, hardware-led environment that we lived in for decades? >> Absolutely, I mean just you look at how people develop, look at containers, the lifetime of a container is very short compared to like a monolithic application, things that are more dynamic. Some enterprises need to scale up operations, and then that's where they kind of... So early on it was more like a developer testing things in their lab and when you go into production and the rate and the scale at which you operate, dictates that, you know, look, I need to work in public cloud, I need to work with bare metal, and then that, the amount of the infrastructure guys meet that demand otherwise those enterprises are not going to be able to serve their end customers. And that's why they're kind of working with us, and even the community's coming together to address these, and we're looking with-- for performance with the vendors and then even for networking and that's what's driving that. >> Yeah, I want to get your reaction, I was talking to somebody here at the show and they said "Kubernetes is a reset for SDN." >> Yep, it is! I mean the thing is, Kubernetes as it is is perfect, there's no reason to reinvent the wheel, right? There's a lot of adaption from developers' infrastructure. What we're trying to do is build around it, you'll see orchestration on top, you'll see networking, this is such a good thing that everybody is, and you can see by the level of attendance, the level of interest, and engagement, now what we're trying to do is like grow the operation. What are the problems that are left for an enterprise to solve? And that's the multi-cloud piece, right? How do you do policy, network and security policy in that hybrid environment, right? For example, you look at a retailer, they have users using mobile apps, they have remote stores, they have data centers, they have public cloud, and then they're using containers (mumbles) how do you stitch all that together? And that's for us, the challenge that we're addressing. >> And Kubernetes gives you a lot of policy knobs, how are you guys seeing that opportunity? 'Cause that's where people see that kind of piece. >> The three letters, API, right? This API makes integration such an easy thing to do. And then we have obviously, using a CNI plug-in from a (mumbles) perspective, to be able to work in that eco-system and deliver what we do. We have, obviously you guys know that in OpenStack, they're running Kubernetes inside OpenStack and then you have people running Kubernetes on bare metal, right? But it's still Kubernetes and that's how we're able to serve our customers to kind of stitch between between those different stories. >> Alright, Hussein, let's talk about security. So, you know, when containers first came out it was all this argument of how do I architect it? Do I have to shove the thing in a VM, or now is it a micro VM? How do I make sure I ensure security? What's working well? What do we still have a lot of work to do in the security space? >> I think if you look at the three areas: visibility, protection and then the third one is dynamic further response, right? So you can't protect what you can't see and visibility is kind of the first thing that we as networking, because we move packets around, can deliver to the enterprise. The second one is isolation, is that everything you have in a pod is contained. Now between pods, if you're running in public cloud, as a bank, you may want to encrypt that traffic, right? You need to do some level of protection, whether that's in-flight protection or separation between them. The third one is, as you're moving things around and you see bad things happen, you need to not wait for a person, because you're looking at scale, like thousands of these instances that are moving around. The network is intelligent enough to act based on rules that you give it to, like if there's a threat, we'll just quarantine the source or remove traffic. This combination is what's missing and that's kind of what a lot of... >> I think that's an opportunity that's clear, but most people look at networking and say "oh, let's move it from A to B, point A to point B." It's now so much more than that, it's more headroom. What is the specific headroom on top of that? Because there's a lot of security opportunities, things are moving around, you can see the bad guys and all kinds of different threats, but not just moving packets, it's other things. What's the other key things that people should pay attention to when really designing these architectures? >> So the one thing, obviously, when you're doing things in a lab, you're not really going by scale. You're not looking at throughput, latency, things like that that's part of networking and that's kind of the work we're doing with some of the, like Mellanox, you know? On terms of providing high-throughput, providing low latency for specific applications. The other one is, how do you provide that intelligence? Like all this data has to go somewhere to be processed, to work with other security solutions. Those are the two things that maybe people don't give that much thought early on, but as you scale your operations, they become real bottlenecks for you. >> So I want to get a chance for you to get a plug in for the company, DevOps. This infrastructure, this code has kind of been kicking around since the beginning. It's actually happening, a programmable infrastructure. You know, at the app layer for coding, but now network's programmable. What are you guys doing in that area? How are you guys extending that value proposition to your customers? Why are they going with you guys? Why are you guys winning? What's the one thing that people should know about in order to come to you guys? >> Flexibility and openness, that's the key one. We are hardware agnostic, any switch, any network, any hypervisor, any CMS, content management system, that's our focus is our networking and security. Similar to Kubernertes, you can run Kubernetes anywhere. That's how we provide networking and we have an open eco-system that gives you scale, performance and security without really limiting your options. And the thing is, we have all, going forward, like people can do stuff on premises today, they may move to cloud, we don't lock you in to one architecture. The architecture's fluid and it could be whatever. You may see the future one way today, but in a couple of months as we all know, things change. >> Why would someone call you guys up? What's the paying point? What's the value? When will they know, oh okay I've got to get Nuage involved? >> Scale, multi-cloud, that's basically it. If you're looking for multi-cloud, multiple workloads and you're running things at scale, you need to talk to us because that's basically where we help you solve it. >> Hussein, talk a little bit about how Edge fits into it too. You know when you think back to even before cloud, think back to the XSPs. Networking securities have always been the choke point, physics still rules the day. We know it's only getting more complicated with Edge, more surface area for security, but I have to imagine that applies into what you're doing. >> Absolutely, I mean we've done, so as you decompose these things and you move them apart, your attack services increase, right? So the security is, as you move, those communication channels have to be protected somehow. We have an extension which is basically part of getting into the Edge, adding more intelligence at the Edge, because that traffic is coming from the Edge to the core, it goes to public cloud. And being able, as a networking solution, to steer that traffic securely using encryption or whatever have you in terms of visibility, provides those enterprises with a secure, sound platform to really do their business. >> What's your take on the show? 8,000 people up from 4,000. We were comparing it earlier to Adobe's Reinvent. A rising tide, is it a tsunami? >> Absolutely, I mean I couldn't believe the number when they said it because obviously we saw they'd sold out the tickets, but coming here to see all that many people and there have been earlier shows and the growth is tremendous. >> Well thanks for coming for coming on and sharing your insight and congratulations on the scale, we love it. Data, scale, programmable networks, it's all part of the new evolution of cloud native. It's on premises, it's in the cloud, multiple workloads, multiple clouds. This is the choice everyone has, they're rebuilding. Don't forget networking compute and storage, it's still a Holy Trinity there. Congratulations, thanks for coming on. >> Thank you very much. >> More live coverage here at theCUBE, here in Seattle for KubeCon and CloudNativeCon, day three of three days of coverage, this is theCUBE, we'll be right back after this short break. (upbeat music)

Published Date : Dec 13 2018

SUMMARY :

Brought to you by Red Hat, the Linux Foundation and CNCF. what you guys are doing with the show, the ability to have visibility that piece of the puzzle and a lot of the vendors in So, I think that thread you were going on and when you go into production here at the show and they said and you can see by the how are you guys seeing that opportunity? and then you have people Do I have to shove the thing in a VM, and you see bad things happen, What is the specific and that's kind of the work in order to come to you guys? Similar to Kubernertes, you can run Kubernetes anywhere. you need to talk to us You know when you think So the security is, as you move, earlier to Adobe's Reinvent. and the growth is tremendous. This is the choice everyone KubeCon and CloudNativeCon,

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
Hussein KhazaalPERSON

0.99+

SeattleLOCATION

0.99+

John FurrierPERSON

0.99+

Stu MinimanPERSON

0.99+

Cloud Native Computing FoundationORGANIZATION

0.99+

GoogleORGANIZATION

0.99+

JohnPERSON

0.99+

Linux FoundationORGANIZATION

0.99+

AWSORGANIZATION

0.99+

Red HatORGANIZATION

0.99+

HusseinPERSON

0.99+

4,000QUANTITY

0.99+

two thingsQUANTITY

0.99+

KubeConEVENT

0.99+

Nuage NetworksORGANIZATION

0.99+

8,000 peopleQUANTITY

0.99+

third oneQUANTITY

0.99+

second oneQUANTITY

0.99+

CNCFORGANIZATION

0.99+

three daysQUANTITY

0.99+

thousandsQUANTITY

0.99+

KubeCon 2018EVENT

0.99+

CloudNativeConEVENT

0.98+

AdobeORGANIZATION

0.98+

Seattle, WashingtonLOCATION

0.98+

three areasQUANTITY

0.98+

NuageORGANIZATION

0.98+

LinuxTITLE

0.98+

todayDATE

0.97+

OpenStackTITLE

0.97+

three lettersQUANTITY

0.96+

one thingQUANTITY

0.96+

first thingQUANTITY

0.96+

CloudNativeCon North America 2018EVENT

0.96+

firstQUANTITY

0.94+

decadesQUANTITY

0.94+

KubernetesTITLE

0.93+

OpenShiftTITLE

0.91+

Vice PresidentPERSON

0.9+

theCUBEORGANIZATION

0.9+

day threeQUANTITY

0.89+

CNITITLE

0.89+

oneQUANTITY

0.88+

KubernertesTITLE

0.82+

one wayQUANTITY

0.8+

EdgeORGANIZATION

0.78+

last few decadesDATE

0.78+

KubernetesORGANIZATION

0.7+

ReinventTITLE

0.68+

DevOpsORGANIZATION

0.67+

EdgeTITLE

0.62+

CloudTITLE

0.5+

MellanoxPERSON

0.37+

Aparna Sinha, Google Cloud | KubeCon 2018


 

>> From Seattle, Washington, it's theCUBE. Covering KubeCon and CloudNativeCon North America 2018. Brought to you by Red Hat. The Cloud Native Computing Foundation and it's ecosystem partners. [techno Music] >> Okay, welcome back everyone. It's theCUBE's live coverage in Seattle for KubeCon and CloudNativeCon 2018. I'm John Furrier with theCUBE. Stu Miniman. Breaking down all the action. Talking to all the thought leaders, all the experts, all the people making it happen. We're here with Aparna Sinha who's the group product manager, Kubernetes, Google Cloud. Also one of the power women of the Cloud at Google, according the Forbes. I wrote the story. Great to see you again. >> Thank you, great to be here with you. >> Thanks for coming on. >> CUBE alumni. Great to have you on. I want to get your prospective. One when you've seen a lot of action, certainly overseeing the group engineering team at Google and all the Kubernetes action. A lot of contribution, a lot of activity, that you guys are leading. >> Yes. >> And quite frankly enabling and contributing to the community. So, congratulations and thanks for that work. Kubernetes certainly looking good. People are pumped up. >> Very much. >> 8,000 people. A lot of activity. A lot of new things around that you guys are always kind of bringing into, the Geo, knative, a lot things. You gave a key note. What's your focus here this year? What's the message from Google? >> Yeah, well as you pointed out, this is the largest KubeCon ever. 8,000 people, 2,000 on the wait list. And people are telling me here that this is the... This is here to stay, right? It's in the early majority going to the mainstream very much like you kind of think about virtualization was 10 years ago. So that's the momentum that I'm seeing here, that I'm hearing here. My keynote was about the community. Thanking the community first of all. So I talked about how open-source really, success in contingent on contribution. And so, I started by showing the contribution over the last one year, the companies that are contributing. And 80% of contributions are by at least 10 entities. One of them is individual contributors. 40% percent I think was Google, which is still staggeringly high. And then the next highest was Red Hat. And so I think in many of the keynotes, we've been calling out the contributors because it's really important. 1.13, the 13th release of Kubernetes shipped last week. A lot of stability, a lot of GA features, and the uptake in the enterprise. The other thing I called out was just the amount of job opportunity in Kubernetes >> Yeah >> 230% growth in the last year. You see here so many customers that are here to talk about their experience. But also they're here to hire. >> Yeah. And there recruiters on the floor, so it's been I think a huge economic value add. And we feel very proud of that. >> Yeah, Aparna, great point. We've been talking about the end users. I always loved... There's a job board right outside the hall here and it's just covered. Big giant white board there. Bring us inside a little bit. I mean Google's always fascinating people. What's the hiring situation there? What's your team lookin' like? Is anybody smart enough to actually go work there? >> Google, I think we've been very, very fortunate in that we've had the original board team that started the Kubernetes project. And so we have a really, really deep bench because we've been running containers since the beginning. So now 15 years of experience with that, which many people tell me, I think that the reason that Kubernetes is so successful is because it's not new actually, right? >> Yeah >> It's been tried and true at scale. So, we have quite a bit of that, but we've been building this community and a lot of folks have been hired in through the community-- >> Yeah >> into Google. And really amazing, amazing people. So yeah. >> The thing about we had Brian Grant on yesterday and Tim Hockin -- Yes. >> Who was talking about some of those early board days. >> Yes. I want to ask you your point of about the hiring because I think this is a interesting dynamic. Open-source is key to your strategy. We've talked many times about how you guys are committed to open source, but what's interesting is not just net new jobs are available, we're seeing a revitalization around traditional roles like the network engineer under Kubernetes. Looking at the policy knobs that your folks pointed out that's... They think it's underutilized. And then on top of Kubernetes, new things are going on that's getting the app kind of server guy-- >> Yeah. >> Kind of energized. >> Yeah. >> It's kind of enabling a lot of thing, actions that's transforming existing jobs. >> That's right. >> And bringing new ones. >> Talk about that dynamic because you see it from both sides. >> Yes >> You've got SREs, site reliable engineers. >> Yes >> You've got developers. But, Now enterprises are now trying to adopt... >> That's right >> You guys are hitting that note. Talk about that dynamic. >> That's right, so I've been talking to a lot of customers here, it's been non-stop. I've not been able to attend any talks or keynotes. And I'm seeing two things. One there's the kind of operations now called platform teams. And they're under tremendous pressure. They're doing incredible work. Incredible. And they're energized. They're really... So one of the customers I was talking to was moving from VMs on EC2 to containers on GCE on Kubernetes. Google Cloud. And in the last one year, they looked... Honestly, they looked miserable because they have worked so hard in doing that transfomation. Turning their application from a VM-based application into containers. But you could also see that they were so happy and so successful because of the impact that it's had. And so and then I asked them so like, "What is driving that?" This is different customer. What is driving that? And it's really... As soon they get that environment up and running, and this is a large enterprise bank that I was talking to, this other one, their developers are just all over it. And they have, they have hundreds of services running within six months. And they're like, "Well we just got this platform up. "We still have to figure how we're going to upgrade it." But it's... So those are the two constituents. The developers are happy. >> The integration and delivery changes the makeup of how teams work. So that's one thing we're seeing here. And the other one is just scale. >> Yeah. >> So that seems to be the area. Now I got to ask you, as you guys look at... As you guys are doing the work on the enterprise side, you guys, I know you're working hard, I talk to Jennifer a lot, Jennifer Lynn, as well and we've talked before, are used to doing the work. But there's still a lot more work done. Where do you guys see the work that this community value opportunities for participants in the eco-system to fill white spaces? Where are the value lines starting to be drawn? Can you comment? >> Yeah, so I see two or three different areas. One of the areas is of course hardening. And that's why Janet Quill gave the keynote about "Kubernetes is boring and that's a good thing". And that's been something we've been working on for the last year at least. Adding a lot more security capabilities. Adding a lot more just moving everything to GA, right? Adding a lot more hooks in the enterprise storage and into enterprise networking. Building up the training and building up the partners that'll do the implementations. All of those things I think are very, very healthy. >> Yeah. >> Cause I see them. You probably talked to the CNCF. They're helping a lot with the certification and the training. So that's one piece of enterprise adoption. I think the other piece is the developer experience. And that's where a lot of the talks here, my key note as well, I demoed Istio and Knative on top of GKE. The developer experience is ultimately this whole thing. My perspective, this whole thing is about making your developers more productive. And developers have been driving this transition. Again going back to those customer examples. So that's getting a lot easier. >> Yeah, Aparna, I'd love you to talk a little about Knative. So, I know the excitement is there. Products only been around for five months. I remember at your show last summer it was announce and roll. Trying to understand exactly what it is. It's like, wait, wait is serverless going to kill Kubernetes? And how does this fit? How does this work with all the various services in the Cloud? Maybe just understand where we are. >> Right. >> What it is, what it isn't. >> Right. >> Again, so the heritage of serverless, I'm going to go back to Google, right? We have the first serverless offering in the world like 10 years ago. And so that's based on containers. Underneath it's based on containers. That's why we knew that with Kubernetes that's the right foundation for building serverless. And it actually, I think, we sort of held back for the longest time. And a couple of years ago there were one, two, and then 15, and then 17 serverless frameworks that just kind of all popped up around Kubernetes, on top of Kubernetes. I remember the first demo in the community. Here's this serverless piece. And at some point, a little bit over a year ago we decided that actually serverless is really important to our customers, to our users. The majority of Kubernetes tends to be on-prem, actually. And so it's important to them to have serverless capabilities on-prem. So then we need to make sure it's stable and it's something that's standard. >> I think it's a really important point... I talked to some people that are in the serverless ecosystem that is living on a AWS and they say, "You can't build serverless on-prem "because then you're racking "and stacking and dealing with it." And it's not... We know there's servers underneath of it and it's just system calls and how we consume that. But maybe explain the nuances to how this is important and we understand it. >> Yeah. >> There's not like a solution out there. >> Yeah. >> Server meshes, there's a lot of options out there right now. >> Yeah. >> So. >> A lot of things, because this is an open-source community, a lot of things come from the users. So when the user says, "You know what, actually need "the serverless capability on-prem. "Why? "Because I've got this developer group and I don't want "them to have to muck with the infrastructure. "I don't want them to have access to the infrastructure. "I want to just give them a simple interface "where they're going to write their applications "and the rest is taken care of for them." Right? And then I want to be able to bill them on a per-use basis. So, it's... Yeah there's someone managing the server. Someone building actually the severless capability and that's the platform team. That's the guys that I talked about that are working very hard these days happily. But, working very hard. >> And these are the new personas, by the way-- >> Yeah. >> In the enterprise. This is new kind of new re-architecting of how enterprises are creating value. These new platform teams. >> Right. >> This is the opportunity. Well I got to ask you, you know everyone that watches theCUBE knows I'm a big fan of scale. Love Amazon scale. I love Google scale. I love the enterprise market. And I want to get your thoughts... I want you to take a minute to explain the culture at Google Cloud. Because it's a separate building. Give you an opportunity to share. But you guys are working hard to go after the enterprise. It's not like a new thing. But the enterprise is interesting. It's not so much the best technology that wins. It's grit. It's almost like a street fight. You got to go out. You got to win those battles. Get all the work done. Hit those features. You can't just roll into town and say we've got great technology. We're Google. You guys recognize this. And I want you to share the culture you guys are building and how you guys are attacking the enterprise. What's the guiding principles? What are some of the core tenants? >> Yeah, yeah. So you know my entire life has been spent in enterprise software. >> Yeah. >> I do think that enterprises respect Google Cloud. I work very closely with them. And they respect certainly the engineering prowess. Like, "Wow. I need that." >> Yeah. Right? Especially you see all these enterprises that are being transformed by technology. Their industry is being transformed by technology. Whether that's in transportation, or it's in retail, or it's in media. And they want the best. They want the latest. Right? And they also don't necessarily have the skills, like you said, right? So they're looking for a partner that'll both help them scale up but also provide them all of that guidance. And the one thing you asked about culture at Google. I think we are a revolutionary company. We are willing to do lots of things. Lots of things that you wouldn't expect. And that's why you saw GK on-prem from my team, right? The first, kind of, Kubernetes on-prem offering from a cloud provider. Managed by a cloud provider. And that's really... I mean we've seen tremendous, tremendous interest in that. Tremendous feedback from our users and new customers. People that hadn't thought about it. Hadn't thought about Google, necessarily before that have said, "Wow. If you are going to come and help me on-prem "with this, I'm ready. "Give it to me now. "Because I trust you and I know I want to go to the Cloud. "So it's the right step for me. "You have the right incentives." Right? "And you're the open cloud, which is important to me "because I may want to be multi cloud." So that's the piece that is... >> You got the enterprise chops. You've spent your whole career there. I know Jennifer as well. >> Yes. >> A lot of people you guys have hired. >> Right. >> The good news is you've got a market that's changing. So you don't have to come in and replicate the old IT. So that's an opportunity at Google. How are you guys attacking that, that beachhead? Because you have the check. What's the vibe? What's the grit? What's it like... How you guys attacking the enterprise? What do you see as opportunities knowing the enterprise of old-- >> Yeah >> As it shifts to new kind of method? >> Yeah. >> What's the core? >> I think about the problems the users are having. I think about what is the problem the customer is facing. And so... And then breaking that down and solving that for them. I mean that's what's important, right? And so some of the problems I see is one they need a developer platform. And the developer platform sometimes cannot be in the Cloud. When I talk to large financial institutions, there's so much compliance and regulation and things that have to be on-prem. That it has to be on-prem. And they try to move to the Cloud and some things will do it. But the majority, like 90% is on-prem. And so they need an agile development environment and there's no holding it back. Because, like I said, there's all this transformation. Their developers need that environment today. So you have to provide that. That's one use case. We provide an on-prem development and agile development environment. Best in class. Your developers are super happy. Your business is going to do well. The other thing I see, and I see this a lot in retail, but also in hospitality at some of these very kind of brick and mortar enterprises is the edge. They need a solution at their edge location. Thousands, these are thousands of branch locations. We've even got this use case with Chick-fil-A, right? And a lot of times this is... A lot of different use cases, but a lot of time the common thing is that they're collecting data. They're doing some processing at that site and then they're doing further processing in the Cloud. And so it's a connected, but an intimately, it's not always connected.... Intimately connected environment. So that's the second big use case. Edge retail or just edge. There's so many... For me, it's one of the most exciting. There's so many examples of that. >> Awesome. >> Aparna, first of all, just so many goodness I want to say thank you to Google because everything from I heard at the show Google wasn't giving out swag because it actually went to charitable givings instead of spending that money. One of the things we always look is open-source is, how much more value is being created for the eco-system not just the vendor that started it. And it is a really tough balance. We've seen it fail many times. Do you step too far back? And how much do you engage? How do you strike that bound? For the last five to 10 years, we've been saying, "Where is the independent place where we can have that "conversation about cloud?" We think found it at this show. I mean we've been here for three years now. Google Cloud, phenomenal event. Our teams loves to be there, but this feels like overnight has turned into oh wait, here's the show we were looking at to have that conversation. To have that commons where we can come together and there's so many diversity of people, diversity of projects in here. Many which have very disconnected from original Kubernetes and everything, so. It's been fascinating to watch and have to imagine your team is... When you watch that first piece go and everything that's built around it. It's got to be amazing. >> My team loves this event. We have literally I think 300 people here. And a lot of them are core maintainers. Everybody is a contributor, but they are core maintainers of the Kubernetes project. The Istio project. The Knative project. And I think the best thing here is just interacting with our users. Because this is a developer, this is a developer conference, primarily. There's a lot of businesses here. >> Yeah >> With their kind of director level executives. But primarily it's an action-oriented hands-on audience. And you just... These customer meetings that I have, we review their architecture and we're like... It's an engineer to engineer conversation. >> Yep. >> And so how can we make that better? And sometimes they're contributing back and it makes the whole project better. >> Yeah. The thing, too, is it's an engineering, it's a developer conference, true. But what's interesting about that evolution as it modernizes, those end users are developers. >> That's right. >> And so the end user aspect of this show. >> That's right. >> Is the developer piece. >> That's right. >> It never used to be like that. Used to be COMDEX or some big event. >> Yeah. >> And then people just selling their stuff. >> Yeah. >> Doing business. The end user participation... >> Yes. >> Is not a consumption conversation, it's a contribution. >> Right. And end users are all over the spectrum of sort of really, really hands-on. Very, very smart to just give me something that works and I respect all of that, right? And we were actually very far here in terms of GKE. Giving you something that you really don't need to get in, that's fully managed, right? But then on the other hand we had Uber on stage earlier today in their keynote talking about how they've built all of this advanced capability on GKE. And that's a power user. That's using all their capabilities. Like custom additions and an operator. And it's just really gratifying I think for us to work with them and for us to see the user base as well as the community. So the ecosystem. Google. I thinks it's very important for us to have and create economic opportunity for our partners. And you'll see that with GKE on-prem. We're partnering heavily on that one. And you'll see that also in our marketplace. Our Kubernetes marketplace. So many of the companies that have come out of this ecosystem are now part of selling through Google Cloud. >> Aparna, thank you for your time. I know you've had to move some things around to come here. Great to have you on. I love your leadership at Google, it's phenominal. You've got the enterprise chops building out heavily over there. Congratulations. And for more CUBE interviews check out theCUBE dot net. You can check out Aparna's other good news. Of course search her name on Forbes. I wrote a story about her featuring her. Talking about her background and her passion. Always great to have her on theCUBE and get some commentary from Google. Of course, theCUBE is breaking down live coverage. Been there from the beginning of KubeCon and now CloudNativeCon, the Linux Foundation. Bringing you all the analysis and insight. Be back with more coverage after this short break. [Techno Music]

Published Date : Dec 13 2018

SUMMARY :

Brought to you by Red Hat. Great to see you again. and all the Kubernetes action. and contributing to the community. A lot of new things around that you guys are always kind of And so, I started by showing the contribution You see here so many customers that are here to And there recruiters on the floor, so it's been I think a There's a job board right outside the hall here that started the Kubernetes project. and a lot of folks have been hired in And really amazing, amazing people. and Tim Hockin -- Yes. that's getting the app kind of server guy-- It's kind of enabling a lot of thing, because you see it from both sides. You've got developers. You guys are hitting that note. And in the last one year, they looked... And the other one is just scale. So that seems to be the area. One of the areas is of course hardening. and the training. So, I know the excitement is there. And so it's important to them to have But maybe explain the nuances to how this is important Server meshes, there's a lot of options and that's the platform team. In the enterprise. And I want you to share the culture you guys are building So you know my entire life has been spent And they respect certainly the engineering prowess. And the one thing you asked about culture at Google. You got the enterprise chops. and replicate the old IT. And so some of the problems I see is For the last five to 10 years, we've been saying, And a lot of them are core maintainers. And you just... and it makes the whole project better. as it modernizes, those end users are developers. Used to be COMDEX or some big event. The end user participation... So many of the companies that have come and now CloudNativeCon, the Linux Foundation.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
JenniferPERSON

0.99+

Tim HockinPERSON

0.99+

Jennifer LynnPERSON

0.99+

twoQUANTITY

0.99+

John FurrierPERSON

0.99+

Aparna SinhaPERSON

0.99+

Janet QuillPERSON

0.99+

AparnaPERSON

0.99+

GoogleORGANIZATION

0.99+

OneQUANTITY

0.99+

SeattleLOCATION

0.99+

15 yearsQUANTITY

0.99+

Stu MinimanPERSON

0.99+

three yearsQUANTITY

0.99+

Red HatORGANIZATION

0.99+

80%QUANTITY

0.99+

90%QUANTITY

0.99+

last weekDATE

0.99+

hundredsQUANTITY

0.99+

oneQUANTITY

0.99+

UberORGANIZATION

0.99+

last yearDATE

0.99+

five monthsQUANTITY

0.99+

2,000QUANTITY

0.99+

Brian GrantPERSON

0.99+

yesterdayDATE

0.99+

Cloud Native Computing FoundationORGANIZATION

0.99+

300 peopleQUANTITY

0.99+

8,000 peopleQUANTITY

0.99+

17QUANTITY

0.99+

both sidesQUANTITY

0.99+

AmazonORGANIZATION

0.99+

firstQUANTITY

0.99+

ThousandsQUANTITY

0.99+

10 years agoDATE

0.99+

KubeConEVENT

0.99+

15QUANTITY

0.99+

first pieceQUANTITY

0.99+

GALOCATION

0.99+

first demoQUANTITY

0.99+

two thingsQUANTITY

0.98+

bothQUANTITY

0.98+

Seattle, WashingtonLOCATION

0.98+

AWSORGANIZATION

0.98+

13th releaseQUANTITY

0.98+

KnativeORGANIZATION

0.98+

last summerDATE

0.98+

two constituentsQUANTITY

0.98+

CUBEORGANIZATION

0.97+

KubernetesORGANIZATION

0.97+

Google CloudORGANIZATION

0.97+

CloudNativeCon 2018EVENT

0.97+

KubernetesTITLE

0.97+

IstioORGANIZATION

0.96+

Linux FoundationORGANIZATION

0.96+

Chick-fil-AORGANIZATION

0.96+

CloudNativeCon North America 2018EVENT

0.96+

this yearDATE

0.96+

theCUBEORGANIZATION

0.96+

10 yearsQUANTITY

0.95+

six monthsQUANTITY

0.95+

40% percentQUANTITY

0.95+

EC2TITLE

0.93+

Max Schulze, NBF | KubeCon 2018


 

>> From Seattle, Washington, it's 'theCUBE' Covering KubeCon and CloudNativeCon North America 2018, brought to you by 'redhat' The CloudNative computing foundation and it's ecosystem partners. (upbeat music) >> Hello everyone and welcome back to live CUBE coverage here at Seattle for KubeCon, CloudNativeCon2018. I'm John Furrier. Stu Miniman, breaking down all the action here for CloudNative, trend, a lot of ecosystem partners, a lot of new developers, a lot of great open-source action in the cubes here covering it. We've been there from the beginning, our next guest and user, Max Schulze, Advisor and Founder of NBF, welcome to the CUBE, thanks for coming on. >> Thank-you, thank-you for having me. >> So tell me about what you're working on. You are doing something pretty compelling with Kubernetes and CloudNative, take a minute to explain what you do. >> Yeah actually, we are advising a very large energy utility in the Nordics and what we're trying to do with Openshift and Kubernetes is actually to shift loads between different data centers based on power availability. So if you have wind and solar power, you know that you only get energy when the wind is blowing so you really need to be able to match that load of the data center with the actually energy production which is quite challenging to be honest. >> Max you have different take on 'Follow-the-sun' that we used to talk about in IT I'm guessing, yes? >> Yes >> Take us inside a little bit, the sustainability is really interesting and how some of the power, you know, usage and heat and everything and maybe you can explain that a little bit before we get into the data. >> Of course, so generally how we got to a sustainable data center source was that in the Nordics you see a big growth of data centers in general so all the hyperscalers: Google, Microsoft, AWS. They are all coming to build data centers in Nordics. It's cold, power is cheap, you have lots of renewable energy available and we started to think 'Okay, but they have two problems essentially.' They generate a lot of heat, which is just emitted into the atmosphere so it's wasted, and the second problem is that they want 100% reliable power and reliable power you only get from nuclear, you get from gas, coal fire power plants not from renewables. So we looked into this, and we started to think about okay can we maybe get the heat out? Can we extract the heat from a data center and inject it into district heating grids and actually heat homes? With a hyperscale data center from Microsoft, 300 megawatts you can heat about 150,000 homes, that's quite significant. >> Yeah and how are you doing that? I mean I talked to a company once that was like 'Oh well we're going to, you know, we'll just distribute the servers different places and there will be ambient heat off of it.' But you're extracting the heat and sharing it. Explain that a little bit more. >> So most existing data center projects, they extract the heat out of the air but that's really inefficient. You get to about 100 degrees Fahrenheit which is not uh high quality heat. So what we want is 140 degrees Fahrenheit, about 60 degrees celsius, which means that we have to use liquid. So we have to use water in this case and we use a cooling system that is quite ironic from a start up in Germany called Cloud & Heat that uses hot water to cool servers. So the water really flows at a very very high speed through the data center and on it's way picks up a very low amount of temperature and we get out the temperature, we get out the water at 140 degrees Fahrenheit and we put it in at 120 degrees Fahrenheit. So it's quite, not a big difference, but it flows at a very high speed. >> So it makes it work? Makes the numbers work. >> Exactly. And so what's the home count again you mentioned one hyperscale data center, like a Microsoft data center powers heat for how many homes? >> About 150,000 homes from 300 megawatts worth of data center. >> And you guys put this into a grid so that's, does the location of the homes need to be nearby, is there a co-location kind of map or? >> Yeah actually, in order to do this we have to move data centers closer to cities. But luckily, data centers actually want to be closer to cities because your closer to peering points and one of the reasons why they usually can't come closer to cities is because power is not available near a city. So we um try, we can give them both. Right, they can come closer to the city and we can give them power, and we get the heat in return. So, so everybody wins. >> Yeah so I mean, a lot of the discussion we've had is the interaction between software and my data center infrastructure. You've got a story of software, with you know, actual like city underneath the infrastructure. Maybe you got to help explain how that was built out, what tools you're using and walk us through this all. >> So we originally started with Openstack, which was the first test because we need, in order to do this heat extraction we need to also steer really the software, the workloads that run on the data center because you know a chip only gets hot when the server actually does something so we really had to figure this out. We started with Openstack and then we started looking into load shifting which immediately brought us to Kubernetes and then Openshift because you can use the internal scheduler to basically force loads across different locations. We connect it to our energy systems, to our forecasting systems and to our heat load management systems and then basically push workloads around. Right now we have two sites where we test this and it's not as easy as it sounds. And we basically want to move workloads, concentrate them where we want, we have heat. So um yeah, Redhat is helping us a lot doing this but still it's not that easy. >> Yeah yeah, it's interesting. You know, I think back you know, virtualization was about you know, how can we drive some utilization and get some out? You really want to you know, concentrate and run things hot. >> Yeah, exactly. >> Quite inter- Alright tell us about your involvement in this ecosystem, you know, what brings you to the show this week, what do you get out of coming to a show like this? >> Yeah, actually I came because Redhat invited us to talk at the Openshift gathering at the beginning of the conference. And generally, we don't really have a commercial interest in making data centers or data infrastructure sustainable, we, we don't gain anything from that, but we believe it's necessary. If you look at the growth curve of data centers you can really see that they will consume more and more power, and then the power they consume is not compatible with renewable energy. So we are hoping that we can influence people and we come here to tell people our story and we actually get great feedback from most of the nerds. >> Well it's a great story. It's one of those things where you're starting to see data centers trying to solve these problems. It's great with the renewable energy, having that kind of success story is really huge. Um, You mentioned that data centers want to be close to cities. I got to ask the question, in Europe, well you've lived around a lot of places. Is there a more cloud city oriented, like is it London, you got Paris, you got... I know Amazon's got data centers in Ireland. Is there certain cities that are more CloudNative culture? How would you break down the affinity towards CloudNative? If you had to map Europe, which major countries and cities would you think are advanced, cloud thinking vs. tire kickers or you know, people just kind of just trying it? >> In Europe there is a region called the FLAP region, that's Frankfurt, London, Amsterdam and Paris. Those are where you have the highest concentration of data centers, but it terms of CloudNative adoption, I would say that probably in the UK you have the most adoption rates and in the Netherlands. Germany is always, I am German so I can say this, we are always a bit behind in terms of cloud technology because we're a bit scared and we don't know- >> You'll watch everyone test it out and then you guys will make it go faster. (john laughs) >> Maybe, maybe, maybe a bit more efficient but uh, generally I think the cloud adoption rate in Germany is the lowest and the UK and the Netherlands is the highest I would say, yeah. >> Awesome, well thanks so much. Congratulations on your success, we'll keep following you and when we're in Europe we're going to come by and say hello. Thanks for coming and sharing the stories. The CUBE, breaking down all the action at KubeCon, CloudNativeCon. I'm John with Stu Miniman. Day 2, we got three days of wall to wall coverage. Thanks for watching. (upbeat techno music)

Published Date : Dec 13 2018

SUMMARY :

2018, brought to you by in the cubes here covering it. minute to explain what you do. load of the data center with some of the power, you know, and the second problem is Yeah and how are you doing that? So we have to use water in this case Makes the numbers work. you mentioned one hyperscale data center, of data center. the city and we can give them with you know, actual like So we originally started You really want to you know, and we actually get great How would you break down the in the UK you have the most it out and then you guys will Netherlands is the highest I would we'll keep following you

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
IrelandLOCATION

0.99+

EuropeLOCATION

0.99+

Max SchulzePERSON

0.99+

AmazonORGANIZATION

0.99+

John FurrierPERSON

0.99+

MicrosoftORGANIZATION

0.99+

GermanyLOCATION

0.99+

Stu MinimanPERSON

0.99+

GoogleORGANIZATION

0.99+

100%QUANTITY

0.99+

AWSORGANIZATION

0.99+

UKLOCATION

0.99+

ParisLOCATION

0.99+

two sitesQUANTITY

0.99+

JohnPERSON

0.99+

NetherlandsLOCATION

0.99+

AmsterdamLOCATION

0.99+

LondonLOCATION

0.99+

FrankfurtLOCATION

0.99+

300 megawattsQUANTITY

0.99+

120 degrees FahrenheitQUANTITY

0.99+

second problemQUANTITY

0.99+

140 degrees FahrenheitQUANTITY

0.99+

NordicsLOCATION

0.99+

two problemsQUANTITY

0.99+

RedhatORGANIZATION

0.99+

oneQUANTITY

0.99+

SeattleLOCATION

0.99+

Seattle, WashingtonLOCATION

0.99+

KubeConEVENT

0.99+

bothQUANTITY

0.99+

three daysQUANTITY

0.98+

CloudNativeORGANIZATION

0.98+

this weekDATE

0.98+

johnPERSON

0.98+

first testQUANTITY

0.98+

CloudNativeConEVENT

0.98+

about 150,000 homesQUANTITY

0.98+

NBFORGANIZATION

0.98+

about 100 degrees FahrenheitQUANTITY

0.97+

CloudNativeCon2018EVENT

0.97+

about 60 degrees celsiusQUANTITY

0.97+

About 150,000 homesQUANTITY

0.97+

CloudNativeCon North America 2018EVENT

0.96+

KubeCon 2018EVENT

0.92+

RedhatPERSON

0.92+

Day 2QUANTITY

0.89+

OpenshiftEVENT

0.87+

CUBEORGANIZATION

0.86+

OpenstackORGANIZATION

0.84+

FLAPLOCATION

0.79+

HeatORGANIZATION

0.74+

GermanLOCATION

0.72+

KubernetesORGANIZATION

0.7+

CloudNativeOTHER

0.6+

OpenshiftORGANIZATION

0.57+

KubernetesTITLE

0.51+

dataQUANTITY

0.5+

Roland Barcia, IBM Hybrid Cloud | KubeCon 2018


 

>> Live from Seattle, Washington it's theCUBE covering KubeCon and CloudNativeCon North America 2018 brought to you by Red Hat the Cloud Native Computing Foundation and it's Ecosystem Partners. >> Well, everyone welcome back to theCube's live coverage here in Seattle for KubeCon and CloudNativeCon 2018. I'm John Furrier with Stu Miniman. Three days of coverage around the Cloud Native growth, around the Ecosystem around open source, and the role of micro servers in the cloud. Our next guest is Roland Barcia who's the IBM Distinguished Engineer for IBM's Hybrid Cloud. Welcome to theCube. >> Thank you, glad to be here. >> Thanks for joining us. Being a Distinguished Engineer of IBM is a pretty big honor so congratulations. >> Thank you. >> it means you got technical chops so we can get down and dirty if we want to. >> Sure. >> I want to get your take on this because a lot of companies in IT are transforming and then that's been called digital transformation, it's happening and cloud has developed scale. And the wish list if you had the magic wand that could make things do better is actually happening. Supernetting's actually creating some goodness that if you had the magic wand, if I asked that question three years ago, if you had a magic wand what would an environment look like? Seamless operations around the cloud, so it's kind of happening. How are you guys positioned for this? Talk about the IBM cloud, what you're doing here, and how you see this cloud native market exploding. It's almost 8,000 people here up from 4,000 last year. >> Yeah, that's a great question I think. I work a lot with our enterprise clients. I'm part of what's called the IBM Cloud Garage, so I'm very customer facing. And often times, we're seeing that there is different paces of a journey. And so for example, I worked with a client that started building a cloud native application. They built about 60 micro services. And at the end of that, they were deploying it as one job which means they defeated the whole purpose of micro service architecture. And so what we really need to think about is an end to end journey. I think the developers are probably the more modern role in an enterprise, but we're starting to see modernization of an operations team for example, and adopting culture, and cutting down the walls of IT organizational groups into mixed squads, adopting something like a Spotify model. And I think a lot of the challenges in adopting kubernetes is really in cultural aspects and in enterprise. Does that make sense? >> Yeah. And because network guys are different than the app guys, and now they have policy knobs on kubernetes they can play with. Network guys love policy. >> Yeah, and they're fighting over ownership, right? >> Roland indeed. We look at that modernization, the application modernization really is that long home intent. And what we hear here is you need to be able to meet customers where they are. Sure, there's some stuff they're building shiny and new and have the developers, but enterprises have a lot of application and therefore there's a grand spectrum. What do you hear from customers? What's the easy part and where's the parts they're getting stuck? >> Yeah, so I think the easy part is writing the application. I think where they're getting stuck is really scaling it to the enterprise, doing the operations, doing the DevOps. I always tell people that a modernization journey might be better started by taking a certain class of applications like middleware where we have a WebSphere heritage from IBM, and saying why don't we take a look at containerizing that. We've built tools like Transformation Advisor that'll scan your WebSphere applications and tell you what do you need to change in that middleware application to make it behave well in a containerized platform. Then from there, you build your DevOps engine, your DevOps pipeline and you really start to get your operations teams going in delivering containers, delivering applications as containers. And then getting your policies and your standards in place. Then you can start opening up around innovation and start really driving towards building cloud native new applications in addition to that. >> One of those areas we've been talking about in the industry for decades is automation. The conversation's a little bit different these days. Maybe you can bring us up to speed about what's different than say it was earlier days. >> Yeah, I think IT organizations have always done a bit of automation. I think they write scripts, they automate builds. I think the mantra that I use is automate everything, right? Organizations need to really start to automate in a new way. How I deliver containers, but delivering the app is not enough. I need to automate all levels of testing in a modern way. Test driven development is big. At the IBM Cloud Garage, we have something we call the IBM Cloud Garage Method which really takes a set of practices like test driven development, pair programming, things out of lean startup, extreme programming, and really start to help enterprises adopt those practices. So I say why can't we automate end to end performance testing in the pipeline, and functional testing, and writing them early and in the beginning of projects? That way, as I'm deploying containers which are very dynamic, along with configuration, and along with policy you're testing it continuously. And I think that level of automation is what we need to get to. >> Talk about security as well 'cause security's one of those things where it's got to be baked in upfront. You got to think about it holistically. It's also now being pulled out of IT, it's more of a board function because the risk management is one hack you could get crushed. And so you got to have security. And the container there's a security boundary issue, so it's important. >> Last week we met with an insurance company. We did a workshop. And they walked us through all the compliant steps that they need to go through today. How they do it with traditional middleware and virtual machines and hardware and it was a very, what I'm going to say governance driven process. And so a lot of checks and balances, stop don't move forward, which is really the industry for developing and innovating is going the opposite way: self service and enabling. And there's a lot of risk with that. And so what we're really trying to do with technology is like Multicloud Manager, technology we have around multicluster, management is how do I do things like I want to check which clusters are Hipaa compliant and which ones are out. How do i force that policy? >> That's smart. >> Now that everything is software driven, software developed, there's an opportunity to really automate those checks. >> So your point automate everything. >> Yeah, I want to automate everything. >> Governance is a service. (laughing) >> Yeah, that's right. And actually, that can help get away from error prone human checks where they had all these tons of documents of all different policies they have to go through can now be automated in a seamless way. >> So compliance and governance could be a stumbling block or it can be just part of the software. That's what you're getting at here. >> That's right, that's what I'm getting at. I think the transition is look at it as an opportunity now that everything is software driven, use software disciplines that developers are used to in those security roles and those CSO roles, etc. >> So I want to ask you a question. So one of the things we're seeing obviously with the cloud is it's great for certain things, and then on premises it has latency issues. We saw Amazon essentially endorse this by saying RDS on VMware on premises. They announced Outpost had reinvent oh, latency. Things aren't moving into the cloud as fast. So you're going to see this hybrid environment. So hybrids, we get that, it's been around, check. No real discussion other than it's happening. The real trend is multicloud, right? >> That' right. >> And so multicloud is just a modern version of the word multi vendor about the client server days. So systems were a multi vendor man choice. This is a fundamental thing. It's not so much about multicloud as it is about choice. How do you guys see that? You are in an environment where you have a lot of customers who don't have one cloud, so this is a big upcoming trend in 2019. >> Most of our clients have at least five different clouds that they deal with, whether it be an IaaS, a PaaS, a SaaS base solution. What we're seeing as a trend is we talked about on premise and private and enterprise is I think is 80% of workloads are still in the data center. And so they want to build that private cloud environment as a transitionary point to public, but what we're seeing across the multicloud space is I'm going to say a new integration space. So if you really think 15 years ago, SOA and enterprise service bosses in a very centralized fashion, I think there's a new opportunity for integration across clouds and on-prem in a more decentralized way. So I think integration is kind of the next trend that we're seeing in this multicloud space because the new applications that we're seeing with cognitive data AI are mixing data sources from multiple clouds and on-prem and needing to control that in a hybrid control plane is key. >> It's funny, the industry always talks about these buzzwords, multicloud. If we're talkin' about multicloud, then it's a problem. The idea of infrastructure as code it's not even use the word multicloud. I mean, if you think about it, if you're programming the infrastructure and enabling the stuff under the covers, why even talk about cloud? It should be automated, so that's the future state, but in reality, that's kind of what enterprisers are tryin' to think about. >> They are, and I think it's a tension between innovation and moving fast and control, right? The enterprisers want to move fast, but they want to make sure that they don't break security protocol, that they don't break resiliency that they're maybe have used to with their existing customers and applications. I do think the challenge is how operations teams and management teams start to act like developers to get to that point. And I think that's part of the journey. >> Open source obviously a big part of this show, and that's open source, people contribute upstream It's great stuff. IBM is a big contributor, and it'll be even more when Red Hat gets into the mix. So upstream's great, but as you got 8,000 people here, you're startin' to see people talkin' about business issues, and other things. One of the downstream impacts of this conference being so open source centric is the IT equation and then just the classic developer. So you have multiple personas now kind of interacting. You got the developer, you got the IT architect, cloud architect pro whatever, and then you got the open source community members. Melting pot: good, challenges, thoughts? >> So I think it's so developers love that, right? I think from an enterprise perspective, there are issues. We're seeing a lot of our clients with our private cloud platform ask us to build out what's called air gapped environment which is how do I build up an open source style ecosystem within my enterprise. So things like getting an artifactory registry or a Docker registry or whatever type of registry where I get certified, open source packages in my enterprise that I've gone and done security vulnerability scans with, or that I've made sure that I look at every layer from the Linux kernel all the way up to whatever software is included. So what we're seeing is how do I open the aperture a bit, but do it in a more responsible fashion I think is the key. >> Yeah, and that's for stability, right? So Stu, one of things I've been talkin' about and want to get your thoughts on this role is that you got the cloud as a scalable system then one of the things that's being discussed in Silicon Valley now for the first time, we've been sitting on theCube for years, is the cloud's a system. It's just some architecture, it's network distributing, computing, art paradigm, all that computer science has been around for awhile, right? >> Yes, yes. >> So if you've been a systems person whether hardware or whatever, operating systems, you get cloud. But also you got the horizontal specialism of applications that are using machine learning and data and applications which is unique on top. So you have the collision of those two worlds. This is kind of a modern version of two worlds that we used to call systems and apps, but they're happening in a real dynamic way. What's your thoughts on this? Because you got the benefits of horizontally scalable cloud and you now have the ability to power that so we're seeing things like AI, which has been around for a long, long time, have a renaissance because now you got a lot of compute. >> That's right, and I think data is the real big challenge we're seeing with a lot of our clients. They have a lot of it in their enterprise, they don't want to unlock it all right away. We recently did what's called IBM Cloud Private for Data, in which we brought in a set of technologies around our AI, our Watson core to really start leveraging some of those tools in a private manner. And then what we're seeing is a lot of applications that are moving to the cloud have a data drag. It might start as something as simple as caching data and no SQL databases, but very quickly they want to learn a lot more about that data. So we're seeing that mix happening all the time. >> We've had it, we've had someone say in theCube ML's the new SQL. >> Yeah. >> Because you're starting to see SQL abstraction layers are a beautiful thing if they're connected. So I want to get your thoughts on this because everyone's kind of in discovery mode right now. Learning, there's a lot of education. I mean, we're talkin' about real, big time players. Architects are becoming cloud architects. Sysadmins are becoming operators for large infrastructure scale. You see network guys goin' wait a minute, if I don't get on the new network programmable model I'm going to be irrelevant. So a lot of persona changes in the enterprise. How are you guys handling that with customers? I know you guys have the expert program. Comment on that dynamic. >> I think what we're doing is we use the IBM Cloud Garage to bring in practices like the Spotify method where we start pushing things like >> What's the Spotify method? >> Spotify method is a way of doing kind of development where rather than having your disciplines of architects, development, operations, we're now splitting teams, let's say functionally, where I have mixed disciplines in a squad and maybe saying hey, the person building the account team has an SRE, an ops guy, a dev guy all within their same squad. And then maybe have guilds across disciplines, right? And so what we do at the Garage is we bring 'em in to one of the Garages. We have four team locations worldwide. Maybe do your first project. Then we build enablement and education around that, bring it back to the enterprise and start making that viral. And that's what we're doing in the IBM Cloud Garage. >> So not a monolithic thing, breakin' it down, integrating multiple disciplines, kind of like a playlist. >> Yeah, that's right. And I think the best way to do it is to practice it, right, in action. Let's pick a project rather than talking about it. >> If I had to ask you in 2019, what is the IT investment going to look like with kubernetes impact? How does kubernetes change the IT priorities and investments for an enterprise? >> Yeah, so I think you'll see kubernetes become a vehicle for enterprises to deliver content. So one, the whole area around helm and other package managers as a way to bundle software. I think as people build more clusters, multicluster management is going to be the big trend of how do I deal now with clusters that I have in public cloud and private cloud, all different clouds? And I think that integration layer that I talked about where what does modern integration look like across kubernetes based applications. >> Someone asked me last week at Reinvent hey, can't we just automate kubernetes? And then I was like, well it's kind of automated now. What's your thoughts on that? >> So I think when someone asks a question what does it mean to automate that I think the kubernetes stack really sits on top of IaaS infrastructure. And so for example, our IBM Cloud Private you can run it on zLinux or Power. And we have a lot of IBM folks that run multi architecture clusters. And therefore, they still need a level of automating how I create clusters over IaaS and there's technologies like Terraform and others that help with that, but then there's also automating standing up the DevOps stack, automating deployment of the applications over that stack. And I think they mean automating how I use kubernetes in an environment. >> So 2019, the year of programmability and automation creating goodness around kubernetes. >> Yeah, absolutely, >> Roland, thanks for comin' >> Thank you, it was great. >> on theCube, thanks for that smart insight. TheCube coverage here, day two winding down. We got day three tomorrow. This is theCube covering KubeCon and CloudNativeCon 2018. We'll be right back with more day two coverage after this short break. (happy electronic music)

Published Date : Dec 13 2018

SUMMARY :

brought to you by Red Hat the Cloud Native and the role of micro Being a Distinguished Engineer of IBM is and dirty if we want to. And the wish list if And at the end of that, they different than the app guys, and have the developers, and tell you what do you in the industry for decades is automation. And I think that level of automation And the container there's a security that they need to go through today. there's an opportunity to Governance is a service. And actually, that can help or it can be just part of the software. I think the transition is So one of the things of the word multi vendor is kind of the next trend that's the future state, And I think that's part of the journey. One of the downstream do I open the aperture a bit, is that you got the cloud and you now have the ability to power that that are moving to the We've had it, we've had someone changes in the enterprise. in the IBM Cloud Garage. kind of like a playlist. And I think the best way to do it is So one, the whole area And then I was like, well and others that help with that, So 2019, the year of for that smart insight.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
IBMORGANIZATION

0.99+

John FurrierPERSON

0.99+

2019DATE

0.99+

Roland BarciaPERSON

0.99+

SeattleLOCATION

0.99+

AmazonORGANIZATION

0.99+

80%QUANTITY

0.99+

Stu MinimanPERSON

0.99+

Silicon ValleyLOCATION

0.99+

Red HatORGANIZATION

0.99+

Last weekDATE

0.99+

Cloud Native Computing FoundationORGANIZATION

0.99+

KubeConEVENT

0.99+

last weekDATE

0.99+

8,000 peopleQUANTITY

0.99+

two worldsQUANTITY

0.99+

Seattle, WashingtonLOCATION

0.99+

first projectQUANTITY

0.99+

three years agoDATE

0.99+

ReinventORGANIZATION

0.99+

OutpostORGANIZATION

0.99+

first timeQUANTITY

0.98+

one jobQUANTITY

0.98+

SpotifyORGANIZATION

0.98+

Three daysQUANTITY

0.98+

tomorrowDATE

0.98+

4,000QUANTITY

0.97+

WebSphereTITLE

0.97+

todayDATE

0.97+

CloudNativeCon North America 2018EVENT

0.97+

CloudNativeCon 2018EVENT

0.97+

about 60 micro servicesQUANTITY

0.97+

oneQUANTITY

0.96+

one cloudQUANTITY

0.96+

15 years agoDATE

0.96+

last yearDATE

0.96+

SQLTITLE

0.95+

day threeQUANTITY

0.95+

Linux kernelTITLE

0.95+

OneQUANTITY

0.94+

one hackQUANTITY

0.94+

almost 8,000 peopleQUANTITY

0.94+

day twoQUANTITY

0.93+

decadesQUANTITY

0.91+

RolandORGANIZATION

0.91+

tons of documentsQUANTITY

0.88+

theCubeORGANIZATION

0.87+

KubeCon 2018EVENT

0.84+

Hybrid CloudCOMMERCIAL_ITEM

0.83+

zLinuxTITLE

0.81+

StuPERSON

0.81+

five different cloudsQUANTITY

0.75+

VMwareORGANIZATION

0.71+

DockerTITLE

0.71+

DevOpsTITLE

0.69+

RolandPERSON

0.69+

TerraformTITLE

0.66+

Cloud GarageTITLE

0.66+

theCubeCOMMERCIAL_ITEM

0.66+

WatsonTITLE

0.65+

yearsQUANTITY

0.64+

four teamQUANTITY

0.64+

MulticloudTITLE

0.63+

IBM cloudORGANIZATION

0.63+

TheCubeCOMMERCIAL_ITEM

0.58+

Transformation AdvisorORGANIZATION

0.56+

Dan Kohn, CNCF | KubeCon 2018


 

>> Live from Seattle, Washington it's the CUBE covering KubeCon and CloudNativeCon North America 2018. Brought to you by Red Hat, the Cloud Native Computing Foundation, and its ecosystem partners. >> Hey, welcome back, everyone. We are here live with CUBE coverage at KubeCon, CloudNativeCon 2018 in Seattle. I'm John Furrier with Stu Miniman your hosts all week, three days of coverage. We're in day two. 8,000 attendees, up from 4,000, spanning to China, in Europe, everywhere, the CNCF is expanding. The Linux Foundation, and the ecosystems expanding, we're here with Dan Kohn who's the executive director of the CNCF. Dan, great to see you. I know you work hard. (laughs) I see you out in China. You've done the work. You guys and the team have taken this hockey stick as it's described on the Twittersphere, really up and to the right, you've doubled, it's almost like Moore's law for attendance. (laughs) Doubling every six months. It's really a testament of how it's structured, how you guys are managing it, the balances that you go through. So congratulations. >> So thank you very much, and I'm thrilled that you guys have been with us through that whole ride, that we met here in Seattle two years ago at the first KubeCon we ran with 1,000 attendees. And here we are eight times higher two years later. But I absolutely do need to say it is the community that's growing, and we try and organize them a little bit and harness some of that excitement and energy and then there is a ton of logistics and effort that it takes to go from 28 members to 349 and to put on an event like this, but we do have an amazing team at the Linux Foundation and this is absolutely an all hands on deck where the entire events team is out here and working really hard. >> You guys are smart, you know what you're doing, and you have the right tone and posture, but you set it up right, so it's end user driven, it's open-source community as the core of the event, and you're seeing end users that have contributed, they're now consuming, you have vendors coming in, but you set the nice playbook up, and the downstream benefits of that open-source core has impacted IT, developers, average developers, and this is the magic. And you guys don't take too many hard stands on things, you take a good enough stand on the enablement piece of it. This is a critical piece. Explain the rationale because I think this is a success formula. You don't go too far and say, here's the CNCF stack. >> Right. >> You pull back a little bit on that and let the ecosystem enable it. Talk about that rationale because I think this is an important point. >> Sure and I would say that one of the huge advantages that CNCF has had is that we came later after a lot of other projects. So our parent, the Linux Foundation, has been around for 15 years. We've been able to leverage all of their expertise. We've looked at some of the mistakes that OpenStack, and Apache, and IETF, and other giants who came before us did, and our aspiration has always been to make entirely new mistakes rather than to replicate the old ones. But as you mentioned end user is a key focus, so when you look at our community, how CNCF is set up, we have a governing board that's mainly vendors, it does have developer and other reps on it. We have our technical oversight committee of these nine experts, kind of like our supreme court, and then we have this end user community that is feeding requirements and feedback back to the other group. >> I want to ask you about the structure, and I think this is important because you guys have a great governance model, but you have this concept of graduation. You have Kubernetes, and it's really solid, people are very happy with it, and there's always debates in open-source as you know, but there's a concept of graduating. Anyone can have projects, and explain that dynamic. 'Cause that's, I've heard people say, oh that's part of the CNCF, and well it hasn't graduated, but it's a project. It's important as a laddering there, explain that concept. I think this is important for people to understand that you're open, but there's kind of a model of graduation. What does it mean? >> Sure and it, people have said, oh you mean they've graduated, so they've left now, right? Like the kids leaving the home. And it's definitely not that model. Kubernetes is still very much part of CNCF. We're happy to do it. But we think that one of CNCF's functions is as a signaling and a marketing to enterprise users. And we like the cliche of crossing the chasm where we talk about 2018 was really the year that Kubernetes crossed the chasm. Went from as early adopters who'd been using it for years and were thrilled with it but they actually jump over now to the early majority. I will say though that the late majority, the laggards, the skeptics, they're not using these technologies yet. We still have a ton of opportunity for years to come on that. So we say the graduated projects, which today is not just Kubernetes but also Prometheus and Envoy. Those are the ones that are suitable for really any enterprise company, and that they should feel confident these are very mature, serious technologies for companies of all size. The majority of our projects are incubating. Those are great projects, technically capable, companies should absolutely use them if the use case fits, but they're less mature. And then we have this other category of the Sandbox, 11 projects in there, and we say look, these are incredibly promising. If you are technical enough and you have the use cases, you absolutely should consider it, but they are less mature. And then our hope is to help the projects move along that graduation phase. >> And that's how companies start. Bloomberg's plan, I thinking jumping into Sandbox, they'll start getting some code in there that'll attract some people, they get their code, they don't have to come back after the fact and join in. So you have the Sandbox, you've got projects, you've got graduation, so. >> Now Bloomberg's a little bit unusual, and I like them as an example where they have, I don't know if they mentioned this, but almost a philosophy not to spend money on software. And of course that's great. All of our projects are free and open-source, and they're willing to spend money on people, and they hire a spectacular group of engineers, and then they support everything in-house. But in reality, the vast majority of end users are very happy to work with the vendor, including a lot of our members, and pay for some of that support. And so a Bloomberg can be a little bit more adventurous than many, I think. >> Dan, I wonder if you can provide a little bit of context. I hear some people look at really kind of the conformance and certification that the CNCF does. And I think in many ways learn from the mistakes of some of the things we've done in the past because they'll see there's so many companies, it's like, well there's too many distributions. Maybe you could help explain the difference between a distribution-- >> Sure. >> And what's supported and how that makes sense. >> And I think when you look back at, and we just had, CNCF just had our three-year birthday this week, we have a little birthday cake on Twitter and everything. But if you look at all the activities we've been involved in over those three years, KubeCon, CloudNativeCon, we have a service provider program, we've done a lot of marketing, helping projects, I think it's the certification and the software conformance is the single thing that we've had done that's had the biggest impact on the community. And the idea here is that we wanted a way for individual companies to be able to make changes to Kubernetes because they all want to, but to still have confidence that you could take the same workload and move it between the different public clouds, between the different enterprise distros or just vanilla Kubernetes that you download or different installers out there. And so the solution was an open-source software conformance project that anyone can download these tasks and run them, and then a process where people upload the test results and say, yes my implementation is still conformant. I've made these changes, but I haven't broken anything. And we really have some amazing cases of our members, some of our biggest members, who had turned off APIs, maybe in their public cloud for good reasons. They said, oh this doesn't apply or we don't, but that's exactly the kind of thing that can cause incompatibility. >> Yeah, I mean that's critically important, and the other thing that is, what I haven't heard, is there's so many projects here. And we go to the Amazon show and it's like, I'm overwhelmed and I don't know what to do, and I can't keep up with everything. I'm actually surprised I don't hear that here because there are pockets, and this is multiple communities, not like a single monolithic community, so you've got, you know Envoy has their own little separate show and Operators has a thing on Friday that they're doing, and there's the Helm community and sometimes I'm putting many of the pieces together, but oftentimes I'm taking just a couple of the pieces. How do you manage this loosely coupled, it's like distributed architecture. >> Loosely coupled is a key phrase. I think the big advantage we have is our anchor tenant of Kubernetes has its own gravitational field. And so from a compatibility standpoint, we have this, excuse me, certification program for Kubernetes and then all of the other projects essentially ensure they're orbiting around and they ensure that they're compatible with Kubernetes, that also ensures they're compatible with each other. Now it's definitely the case that our projects are used beyond just Kubernetes. We were thrilled with Amazon's announcement two weeks ago of commercial support for Envoy and talking about how one of the things they loved about Envoy is that is doesn't just work on Kubernetes, they can use it on their proprietary ECS platform on their regular EC2 environment as well. And that's true for almost all of our projects. Prometheus is used in Mesos, is used in Docker Swarm, is used in VMs, but I do think that having so much traction and momentum around Kubernetes just is a forcing function for the whole community to come together and stay compatible. >> Well you guys did a great job. That happened last year. It's really to me is an example of a historic moment in the computer industry because this is a modern version of enabling technology that's going to enable a lot of value creation, a lot of wealth creation, a lot of customer, and it's all in a new way, so I think you guys really cracked the code on that and continued success. You've obviously had China going gangbusters, you're expanding, China by the way is one of the largest areas we've reported on Siliconangle.com and the CUBE in the past. China has emerged as one of the largest contributors and consumers of open-source given the rise of all the action going on in China. >> And we've been thrilled to see that, and I mean there was just the example yesterday where etcd is now the newest project, the newest incubating project in CNCF, and the co-creator of that and really the lead maintainer for it left CoreOS when it was acquired by Red Hat and is now with Alibaba. And he's originally from China. He is helping Alibaba just who's a platinum member of CNCF, who's been offering a certified Kubernetes service, but they're now looking at how they can move much more of their internal workloads over to it. JD.com has 25,000 servers. That's the second biggest retailer in China. >> It's a constituent. >> I was there six times last year. >> I know you were. >> I ran into you once in a hotel lobby. (laughing) >> What are you doing in China? It's huge, we're here. This is a big dynamic. This is new. I mean this is a big force and function. >> And to have so much energy, and I do also want to really emphasize the two-way street, that it's not just Chinese companies adopting these technologies that started in the US. >> They're contributing. >> We were thrilled a month ago to have Harbor come in as an incubating project and that started in China and is now being used across the world. >> Dan, 2019, you've got three shows again, Barcelona, Shanghai, and San Diego. >> Exactly. >> Of course the numbers are going to be up and to the right, but what else should we be looking for? >> So I think the two, so definitely China, we're going to continue doing it there, we continue to be relations serverless, we're thrilled with the progress of our serverless working group. They have this new cloud event spec, we have all of the different major clouds participating in it. The third area that I think you're going to see us that is somewhat new is looking at telcos. And our vision is that you can take a lot, most networking code today is done in virtual machines called virtual network functions. We think those should evolve to become cloud native network functions. The same networking code running in containers on Kubernetes. And so this is actually going to be our first time with a booth at Mobile World Congress in Barcelona in February. And we're going to be talking about-- >> Makes a lot of sense. IOT, over the top, a lot of enablement there. Makes inefficiencies in that inefficient stacks. >> Yeah, and on the edge as well. >> Dan, thanks for coming out, I appreciate it. Again, you've done the work, hard work, and continue it, great success, congratulations. I know it's early days still but. >> I hope it is. At some date Kubernetes is going to plateau. But it really doesn't feel like it'll be 2019. >> Yeah, it definitely is not boring. (laughing) Even though we had much more, Dan. >> Dan Kohn, executive director of the CNCF. Here inside the CUBE, breaking it all down, again, another successful show. Just the growth, this is the tsunami, it's a rise of Kubernetes and the ecosystem around it, creating values, the CUBE coverage, live here in Seattle. I'll be back with more coverage after this short break. I'm John Furrier with Stu Miniman. Be right back. (upbeat music)

Published Date : Dec 13 2018

SUMMARY :

it's the CUBE covering KubeCon of the CNCF. at the first KubeCon we ran and the downstream benefits and let the ecosystem enable it. and then we have this end user community and I think this is important because of crossing the chasm after the fact and join in. and pay for some of that support. and certification that the CNCF does. how that makes sense. and the software conformance and the other thing that and talking about how one of the things and the CUBE in the past. and really the lead maintainer I ran into you once in a hotel lobby. I mean this is a big force and function. And to have so much as an incubating project and that started Barcelona, Shanghai, and San Diego. And our vision is that you can take a lot, IOT, over the top, a and continue it, great is going to plateau. Even though we had much more, Dan. and the ecosystem around it,

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
AlibabaORGANIZATION

0.99+

Dan KohnPERSON

0.99+

ChinaLOCATION

0.99+

Cloud Native Computing FoundationORGANIZATION

0.99+

John FurrierPERSON

0.99+

SeattleLOCATION

0.99+

AmazonORGANIZATION

0.99+

Stu MinimanPERSON

0.99+

twoQUANTITY

0.99+

Linux FoundationORGANIZATION

0.99+

USLOCATION

0.99+

Red HatORGANIZATION

0.99+

JD.comORGANIZATION

0.99+

28 membersQUANTITY

0.99+

EuropeLOCATION

0.99+

DanPERSON

0.99+

2019DATE

0.99+

25,000 serversQUANTITY

0.99+

CNCFORGANIZATION

0.99+

last yearDATE

0.99+

FebruaryDATE

0.99+

2018DATE

0.99+

yesterdayDATE

0.99+

six timesQUANTITY

0.99+

eight timesQUANTITY

0.99+

KubeConEVENT

0.99+

349QUANTITY

0.99+

MoorePERSON

0.99+

BarcelonaLOCATION

0.99+

BloombergORGANIZATION

0.99+

three showsQUANTITY

0.99+

three-yearQUANTITY

0.99+

three yearsQUANTITY

0.99+

three daysQUANTITY

0.99+

KubernetesTITLE

0.99+

1,000 attendeesQUANTITY

0.99+

FridayDATE

0.99+

Seattle, WashingtonLOCATION

0.99+

11 projectsQUANTITY

0.99+

two years agoDATE

0.99+

nine expertsQUANTITY

0.99+

third areaQUANTITY

0.99+

first timeQUANTITY

0.99+

MesosTITLE

0.99+

two years laterDATE

0.98+

San DiegoLOCATION

0.98+

a month agoDATE

0.98+

singleQUANTITY

0.98+

two weeks agoDATE

0.98+

PrometheusTITLE

0.98+

ApacheORGANIZATION

0.98+

Docker SwarmTITLE

0.98+

15 yearsQUANTITY

0.97+

todayDATE

0.97+

oneQUANTITY

0.97+

Siliconangle.comORGANIZATION

0.97+

Diane Mueller & Rob Szumski, Red Hat | KubeCon 2018


 

>> Live from Seattle, Washington, it's theCUBE, covering KubeCon, and CloudNativeCon North America 2018. Brought to you by Red Hat, the CloudNative Computing Foundation, and the Antigo System Partners. >> Hey, welcome back everyone live here in Seattle for the theCUBE's coverage of KubeCon and CloundNativeCon 2018. I'm John Furrier, theCUBE with Stu Miniman, breaking down all the action. Three days of coverage, we're in day two. A lot of action at Open-source. 8,000 attendees, up from 4,000 North America, they were in China, they were all over Europe. The community's growing in a massive way. We had two great guests from Red Hat, all making it happen, part of the community. We've got Diane Mueller, whose theCUBE alumni director of community development, many times on theCUBE, good to see you, and Rob Szumski, principal product manager, both at Red Hat. Guys, thanks for coming on. Great to see you again. >> Yeah, glad to be here. - Great to be here. >> So the world's changing a lot, and there was some news recently around Red Hat. I can't remember what it was. Recently, something big news, but you guys have been big players in Open-source for years. We always cover it, we always wax on about the origination of it and how the evolution, but the CloudNative piece has gotten so real, and your role in it particularly, we've had many conversations, going maybe back to the OpenStack days of how OpenShift was developing, then the bet on Kubernetes that you made, Core OS acquisition, those two things I think, to me, at least from my perspective, really catalyzed a lot of things at the right time, right? So, from there, just a lot of things has just been happening really in a good way. Big tail wind for you guys, CloudNative app developers are using Open-source, CI/CD pipeline, and then also policy based up under the hood, completely big shift in moving the game down the field. So big congratulations first of all. But what's new? What's the update? >> The update is Operators. I think the next big thing that we are really focusing on, and that's a game changer for all the second day operations type things, and we'll make Rob talk about it in detail, is the rise of Kubernetes' Operators. It's not a scary thing, it's not like terminator day, or anything like that, but it is really the thing that helps us make the service catalogs, the Kubernetes marketplaces really accessible to all of the data bases as a service, and all of the other things, and takes out some of the complexity of delivering applications and database  as a Service to anybody running Kubernetes anywhere. >> Take a minute to explain Operator, real quick, and then we can jump into it, because I think this is a fundamental trend, that we're seeing. Developer trend is pretty obvious, it's been that word for awhile, CloudScale, ML, machine learning, and all the goodness around application development, but the Operator side of it has been an IT thing. But now you guys have a different, a new approach that's winning. What is it? What is Operator? >> Well, it's Kubernetes that has the approach, and I'll let you-- >> Yeah, so it's basically like the rise of containers was great, because you could take a single container and package an application and give to somebody, and know that they can run it successfully. And Operator does that for a distributed system in the exact same way. So you're using all the Kubernetes primitives, so you're not reinventing service discovery, and seeker management, and all that. And you can give somebody an entire Kafka stack, or a machine learning stack, or whatever it is, these very complex distributed systems, and have them run it without having to be an expert. They need to know Kafka at a high level, but not exactly all the underpinnings of it, because that's all baked in the software. >> And the benefit and the impact of the organization is what? >> And just to clarify, so this was added in, I believe Kubernetes is like 1.7, it's something that's in there, it's not something Red Hat specific- >> Yeah, it's like-- >> So you're extending Kubernetes so that you have a custom resource definition, which is an extensible mechanism for saying, hey, I've got a deployment or a staple set, but what if I want to have a new object called a MongoDB? That knows how to deploy, and manage, and upgrade MongoDB. So that's the extension mechanism that we're using. >> Yeah, so you got to think, there's certain applications that this is going to make, just a lot easier how I manage them, deploy them, things like that. Any specific examples you want to share as to-- >> All the clustered data bases. >> There's a lot of the application side in this model have been very excited about this. >> So its all the vendors and partners that want a hybrid Cloud story, just targeting Kubernetes, and we're using Kubernetes under the hood, and then everybody wants to run like a staple data base tier, whether that's Mongo and Couchbase, and Cassandra, whatever. And these are all distributed systems. >> Alright, so I want you to just perch, you said a hybrid Cloud. Explain that model, because there's just something in general discussion that is hybrid or multi means I'm running multiple places, I'm not necessarily stretching an application, but I have instances there, just want to make sure we're on the same page. >> So this would be more the compatibility that you're programming against when you're building an operator, is Kubernetes. It's not a Cloud offering, it's not OpenShift, so you're just targeting Kubernetes, and so you can run MongoDB on prem, in the Cloud, and have it function the exact same, by standing up one of these Operators. And then if that Operator has higher level constructs for how to do multi-cluster aware data rebalancing, you can take advantage of that too. >> And the Open-source status of this product is what? >> It's all Open-source, it's all in the github repos, there's a Google group for Operator framework, that anyone can come and participate in. We hold SIG meetings on the third Friday of every month, 9 a.m. Pacific Time, and it's a completely Open-source project. There's a whole framework around it, so there's the Operator SDK, the Operator Lifecycle Management, and Operator metering, all the tooling there to help people build and manage these Operators, and it's all being built out there in the open with the community's support and feedback loops. >> What's the feedback? What's the top feedback you guys are getting right now? Seeing right now? >> I have to say, this is really, like I've been hanging out with you guys like for the past three, four months on this topic, trying to get my head around it and everything, and we came here and we had two sessions, an intro session and a deep dive session, intro yesterday, deep dive today. Today's deep dive, the room was about 250 people, and they're were people outside of it-- >> Security guards blocking people from coming in. >> Nobody could come in and it's like, it's insane. It's like, everybody needs these things, and everybody wants to figure out that, and when you ask people in the room whose building one, half the room raises their hands. It's just crazy. This thing crept up on us really, maybe not on Core OS, okay, it crept up on me very quickly, and it's very rapid adoption. We have a Kubernetes Operators workshop on Friday, so not only do we have pre-conference days of like OpenShift Cons that are huge now, but now we're starting to book end, CNCF events and put on other things, just because, and that, we had 100 seats that we were hoping we would fill, and it sold out in like minutes once it got in there, and there's a waiting list of like 300 people. It is like one of, aside from Knative, and all the other wonderful hot things too, it is one of the most interesting developments I think right now. >> Thirst for the content. Would it impact? >> Yeah, and you can get all of the documentation is out there now, and people are already building them. We have a list of 50 community Operators. It's just, it's phenomenal how quickly it's growing. >> You know, Diane and Rob, it's funny because you know, we do so many of these theCUBE interviews, and this is our 10th year doing theCUBE coming up, and I remember the conversations going back in the OpenStack days, we would ask questions like, if you had a magic wand, what would you like, hope to have happened, right? And you know, those are parts of the evolution, where it's like, it's aspirational, things are being built. It seems now with Kubernetes, it's almost like, wait a minute, it's actually, this is like the goodness is so compelling, above and below Kubernetes that it's almost like uncomprehendible. You think about, oh this is actually happening. Finally the kinds of steady state kind of operational things that have been a pain in the butt for years-- >> Yeah, the toil, it's gone, for the most part. >> Yeah. >> So Rob, I've been having a lot of just thinking back to, you're employee number two at Core OS, when I first talked to Core OS, it was, we're going to build all of these individual tools, and we're going to Open-source them, and it's going to be good. We watched this just rising ecosystem and the CNCF, and it feels like what's nice and what's different that I see, compared to some previous things, is it's not one product or even a small group of companies. It's, I have this tool kit, and some of them work together, but many of them are independently used. We've talked to your peers earlier about it, etCD. etCD is totally stand alone, doesn't need to be Kubernetes. What have you seen, if you go back to that original vision, would Core OS just been, part of this whole ecosystem, and done it, if this was available, and has this delivering on a promise that your team had hoped to work on? >> Yeah, so we've always filled in where we see gaps, and so something like etCD, the concept is not new, and it comes from Google, and they have a system internally, and as Brandon got up on stage and said, we needed that coordinate, reboot, to grow out, to cluster of machines. It didn't exist so we had to build it. Same thing with how we wanted to manage Linux. There was no distro that even resembled what we were doing. Wanted to do automatic upgrades, people thought that was crazy, so we had to go build it. And so, but we always adopted the best of breed technology, when it existed. In our early bet Kubernetes, we just saw, this is the thing, and went for it. I don't even remember what version, but it was months and months before it was zero point oh, or one point oh, so it was, we've been doing it forever. And you just see the right thing, and it's the little nugget that you need, and if you don't see it, then you build it. >> What are you surprised about Rob, in terms of the ecosystem now, you mentioned some goodness is happening, still a lot more to do, visibility around value creation, you're starting to see spots where value can be created in the ecosystem, which is great. Still more work areas, but what's surprising you? What do you see as opportunities, challenges? Your thoughts, because this vision of ease of use and programmability, is happening, right? So there's still more work to do. What's your vision there? What's your thoughts? >> I mean, I think self service is key, so this is like the rise of the Cloud comes from self service for developers, and Kubernetes gives you the right abstraction, where self service for VM's, like OpenStack, which is not quite at the level of what you want. You don't want a VM, you actually wanted a place to deploy an application, you wanted load balancing, you wanted service discovery, you didn't want like a bare Ubuntu VM, and so Kubernetes raises you up to where you're productive, and then it's about building stuff on top. But what's interesting, in the space is, we're still kind of competing on Kubernetes installers, and stuff like that, so we're not even really into like the phase where people are being super productive on the platform, other than these leading companies. So I think we'll democratize that, and we'll have a whole new landscape. >> And so 2019 you see as what being a key theme for Kubernetes? >> I think it'll be Core stuff built on top, like all the serverless frameworks, a bunch of container natives storage solutions, solving some of these problems that folks are reaching out to external machine learning, but bringing that onto the cluster, GPU support, that type of stuff. It's all about the workloads. >> And tradition end users, you have a huge install base, with Red Hat, well documented, as the end users start coming in and looking at CloudNative, and doing a reimagine of their environment, whether it's IT span, IT investments, to have a run their coding and the deployments. It's going to change. 2019's going to have an impact on what I call mainstream enterprise, for lack of a better description. What's the impact of those guys, 'cause now, they now have head room, they can do more, what's the main stream enterprise look like right now with the impact of Kubernetes? >> I think they're going to start deploying applications and get like lower the time to business value, much, much lower. And I was just talking to a customer, and they ordered bare metal machines like a year ago, and they're still not racked and in the data center. And so people are still getting over that type of stuff, but once you have like a shared Kubernetes layer, you can onboard teams like crazy. I mean, name spaces are free, quote, unquote, and you can get 35 engineering teams on a Kubernetes cluster super easy. >> So they can ramp up in development teams basically, as they bring value in-house, versus outsourcing everything. They start getting development teams, this is where the action is. >> I think you're also going to see the rise of those end users contributing back things, to the Kubernetes community and as Lyft, and Uber, and everybody are great examples of that. Uber with Jaeger, and Lyft is, we were just in the Operators thing, and they raised their hand that they are about to Open-source it, a few Operators that they're building and stuff, and you're just going to see people that you didn't normally see. Often these large foundation driven things are vendor driven, but I think what you see here, is the end user community is now embracing the Open-source, is getting the legal teams there, allowing them to share their things, because one, they get more people to maintain them, and more people working on them, but it's really I think the rise of the end user we'll see, as they start participating more and more in here. And that's the promise of Open-source. >> And that's where CNCF really made it's bones. It wasn't really vendor led per se, it was really end users, the guys building out their stuff for the first time. You see Lyft for instance, great example, you guys did a Core OS, this is like the new generational model. Final question before we break. I want to get this out there. Get a plug in for Red Hat. What are you guys, what's the focus for the show? What's the news? What's the big story for Red Hat here at KubeCon this year? >> I think it's Operators, that's what we're here talking about. It's a really big push to once again get smarter workloads onto the cluster. We've got a really great hybrid story, we've got a really great over the air upgrade story that we're bringing from some of the Core OS technology, and then the next thing is, once it's easy to run 35 clusters, we need a bunch of workloads to put on there. And so we want to save folks from the toil of running all those workloads as well, just like we did at the cluster level. >> Awesome. >> Well put. I couldn't add more. One of the things that Core OS did, you hit the nail on the head earlier, is when there was something missing, they helped us build it, and with the Operator SDK, and the Lifecycle Management, and the metering, and whatever else the tooling is, they have really been inspirational inside of Red Hat. And so they filled a number of gaps, and it's just been all Operators all the time right now. >> It's great when a plan comes together. You guys got a great tail wind. Congratulations on all the success, and it's just the beginning of the wave. It's theCUBE, covering the wave of innovation here at KubeCon CloudNativeCon 2018, we'll be back with more live coverage. Day two of Three days of Kube Coverage. We'll be right back. (upbeat music)

Published Date : Dec 13 2018

SUMMARY :

and the Antigo System Partners. Great to see you again. Yeah, glad to be here. but the CloudNative piece has gotten so real, and all of the other things, and all the goodness around application development, and package an application and give to somebody, And just to clarify, so this was added in, So that's the extension mechanism that we're using. that this is going to make, There's a lot of the application side So its all the vendors and partners on the same page. and have it function the exact same, It's all Open-source, it's all in the github repos, and we came here and we had two sessions, and all the other wonderful hot things too, Thirst for the content. Yeah, and you can get all of the documentation and I remember the conversations going back and it's going to be good. and it's the little nugget that you need, in the ecosystem, which is great. and so Kubernetes raises you up to where you're productive, but bringing that onto the cluster, GPU support, What's the impact of those guys, 'cause now, and get like lower the time to business value, So they can ramp up in development teams basically, And that's the promise of Open-source. What's the big story for Red Hat here at KubeCon this year? and then the next thing is, and it's just been all Operators all the time right now. and it's just the beginning of the wave.

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
Diane MuellerPERSON

0.99+

Rob SzumskiPERSON

0.99+

ChinaLOCATION

0.99+

Red HatORGANIZATION

0.99+

two sessionsQUANTITY

0.99+

SeattleLOCATION

0.99+

CloudNative Computing FoundationORGANIZATION

0.99+

DianePERSON

0.99+

John FurrierPERSON

0.99+

EuropeLOCATION

0.99+

RobPERSON

0.99+

UberORGANIZATION

0.99+

LyftORGANIZATION

0.99+

Stu MinimanPERSON

0.99+

100 seatsQUANTITY

0.99+

TodayDATE

0.99+

10th yearQUANTITY

0.99+

JaegerORGANIZATION

0.99+

Antigo System PartnersORGANIZATION

0.99+

FridayDATE

0.99+

35 clustersQUANTITY

0.99+

Core OSTITLE

0.99+

2019DATE

0.99+

todayDATE

0.99+

8,000 attendeesQUANTITY

0.99+

MongoDBTITLE

0.99+

KubeConEVENT

0.99+

GoogleORGANIZATION

0.99+

Three daysQUANTITY

0.99+

LinuxTITLE

0.99+

yesterdayDATE

0.99+

KafkaTITLE

0.99+

CNCFORGANIZATION

0.99+

KubernetesTITLE

0.98+

300 peopleQUANTITY

0.98+

bothQUANTITY

0.98+

Seattle, WashingtonLOCATION

0.98+

35 engineering teamsQUANTITY

0.98+

one pointQUANTITY

0.98+

CloudNativeCon North America 2018EVENT

0.98+

first timeQUANTITY

0.98+

zero pointQUANTITY

0.98+

two great guestsQUANTITY

0.97+

BrandonPERSON

0.97+

one productQUANTITY

0.97+

theCUBEORGANIZATION

0.97+

CloundNativeCon 2018EVENT

0.97+

firstQUANTITY

0.97+

two thingsQUANTITY

0.96+

OpenShiftTITLE

0.96+

this yearDATE

0.96+

oneQUANTITY

0.96+

second dayQUANTITY

0.96+

50 community OperatorsQUANTITY

0.95+

OneQUANTITY

0.95+

9 a.m. Pacific TimeDATE

0.95+

Day twoQUANTITY

0.95+

single containerQUANTITY

0.95+

UbuntuTITLE

0.95+

OpenStackTITLE

0.94+

North AmericaLOCATION

0.94+

about 250 peopleQUANTITY

0.94+

day twoQUANTITY

0.92+

CloudNativeTITLE

0.92+

a year agoDATE

0.91+

four monthsQUANTITY

0.9+

4,000QUANTITY

0.9+

OpenShift ConsEVENT

0.9+

Steven Bower, Bloomberg | KubeCon 2018


 

>> Live from Seattle,Washington, it's theCUBE. Covering KubeCon andCloudNativeCon North America 2018 brought to you by Red Hat, the Cloud Native Computing Foundation, and it's ecosystem partners. >> Hey, welcome back everyone,live Cube coverage here at KubeCon, CloudNativeCon2018 in Seattle. I'm John Furrier with Stu Miniman hosting three days of coverage. Wall to wall, 8,000 people,double from last year, North America, expanding intoChina, Europe, everywhere. The CNCF is expanding, so is Kubernetes. The rise of Kubernetes has spawned the Cloud Native movement going mainstream that's ecosystem driven. We got a great guest here. Steven Bower, data andanalytics infrastructure lead at Bloomberg, featuredthem on siliconangle.com in one of our special reportsand user using Kubernetes and the variety of Cloud Native. Steven welcome to theCUBE. >> Thanks for having me. >> Thanks for coming on,award winning end user, given all the end users,everyone's kind of award winning. >> Yeah, yeah, yeah. >> Congratulations. Bloomberg's known, we've covered you guys, great development team. You guys have a lot ofengineers at Bloomberg as well as being a media company on cable, Bloomberg terminal, everything else. You've got a lot of datascience, you've got a lot of engineers, you're building stuff. What's the focus on Kubernetes? Where are you using it? How are you contributing? What's the dynamic? Why are you winning with Kubernetes? >> Sure, that's a good question. I think, well we're usingit all over the place in lots of different things. We have a huge engineeringteam that does all kinds of different things. So in the area that I manage,which is data and analytics infrastructure, we have been we basically managedatabases and search engines and all kinds of other tech like that. What we've ended uprealizing is that we built something that looks a lot like Kubernetes but doesn't work nearlyas well for all of those different systems, tomanage them at scale. You know, we're talkingthousands of instances of post cross and solar andall kinds of different things and having a singletool, or single platform which we can kind of levelup all of those things really makes a lot of sense in terms of not necessarily like cuttingcosts and things like that 'cause that's actuallynot as interesting to me as actually allowing theteams that manage those things to actually contribute to those projects, contribute to solar or postcross and stuff like that and free them from havingto spend a lot of time managing infrastructure. >> Tim Hopkins said, itwas just on theCUBE here before you came on,from Google, one of the co-leads on Kubernetesat gkegoogles@cloud. He said something interesting. I want to get your reaction to this. One of the benefits of Kubernetesis to give the confidence that deployments are going to be reliable and that confidence gets a flywheel and then people startshipping more as a matter of course of the business,not like oh my God we got to push a new code,oh my God, fingers crossed, press the button. The old model was fingers cross, go, QA, no, no, confidence, theconfidence and the iteration. Is that where you'reseeing the value, too? Does that relate to you? Does that make sense to you?Does that resonate with you? >> Yeah, it definitely does. A lot of the models thatwe're trying to move towards are really like declarative model of both how we develop software andthen how we deploy software and then how we manage it in production. Kubernetes offers that, thatecosystem across the board. That's been really, trying to think of a great way to put this. Being able to have that tooland being able to do that and the repeatability. In the world that I livein, everything we do we don't do one of it,we do, I think we run something like 2000 solar clusters. So all we're doing all daylong is just stamping out the same thing over and overagain and if I can build one system that doesthat very, really cleanly and simply and then I canuse that same system for running post tests orrunning something else that gives us the confidenceand we can test it, we can run it on our laptops. Our developers can developand do all that kind of stuff and it works the same everywherethey go and we can just rinse, lather, repeat kind of. >> So Steve, step back for a second. Your infrastructure, is thisall Bloomberg Data Center's? How does cloud fit into the discussion? >> Yeah, I mean, we dohave some infrastructure running in the cloud but primarily it's all on prem and data center. In my world it's all onmetal because we have all these data systemsthat need direct access to SSDs and MME andall this kind of stuff. >> Can you give us, withoutsharing state secrets, a little bit of the scaleof what you're doing? I love data's at the centerof what you're doing there. We can all understand howimportant data is to your business but talk aboutwhat the requirements are that why you have some special requirements that thetypical enterprise wouldn't. >> Sure, I think, youcan look at Bloomberg as a media company, wehave news, all that stuff. We obviously have the Bloomberg terminal and really what drives that terminal, it's all kinds of software but in the end it's data, right, andit's all kinds of data. What is that definition,big data and all these whatever stuff that everyonewas pitching five years ago. We have all of those problems. We have data that is movingat millions of ticks a second. We have enormous data sets. We have really complex data sets like people scanning courtfilings from tiny little courts all around thecountry and sending that data in and we have tonormalize that and put it in. So all these crazy differenttypes of information. They are both demanding interms of the complexities of parsing data and puttingthem and structuring them into those systems as wellas the scale so we have some pretty enormous andhigh performance systems that require us and kindof drive us to that need for metal and very focused on performance in all different aspects. >> Great, wonder, give us your engagement with this ecosystem here. One of the big questionscoming in is okay, Kubernetes, the thingwe here from the CNTF is well, it's getting kind of boring. I don't know that I agree with the term. I understand they'resaying it's becoming mature and therefore there's less drama around it which is good but this ecosystemis anything but boring. You ask a user like yourself, you've got complex requirements. There's more than 30different projects a year. What do you use out of here? What do you build yourself? What do you contribute to? How do you consideropen-source contributions? It's a big nut and wedon't have a ton of time but if you could scratch thesurface on some of those. >> I think the number onelesson that I've learned from this ecosystem isthat it's moving so rapidly that when we decide tobuild something on our own we have a talk tomorrow aboutour data science platform which we built about ayear-and-a-half, two-years ago. By the time we were ready to talk about it and everything like that,you have all the other different technologiesthat have moved forward. So it made us realize thatif we're going to start something internally,a new project, either A we should go look and seewhat's out there and contribute to that or we should juststart it in open source to begin with rather thanthat oh, let's build it and then we'll open source it. >> Chasing your tail kind of thing. >> Yeah, it's like we have tobecome part of the ecosystem in our entirety. >> That brings up a good question. I want to ask you this incontext of thinking about your peers that mightnot be as progressive as Bloomberg on the tech side. You guys certainly do a greatjob and it's well documented. Classic IT shop, racking andstacking servers and boxes and now we got the wholedigital transformation thing going on, same old, same old but now, 2019, real impact. The investments they'remaking on how to change their IT, their data isnow in front of them. They have to deal with them. This is right front andcenter 'cause companies are realizing they'regoing to go out of business if they don't actually make the adoption 'cause the data's super valuable. So how do you see the Kubernetesand the CNC of ecosystem changing the investment practices of a classic enterprise IT? You know, if your peerscalled you and said hey Steven, hey help me out,what's the secret playbook? Where do I go? I don't want to get, Igot to make some changes. What do they change? What's the impact of theinvestment with Kubernetes? What's the end game? What's the real impact? >> I think, it's a toughthing, right, 'cause Bloomberg is really notlike your typical IT shop. We are a software company at heart and so that makes us alittle bit different. When I talk to other people,I say that in the sense that not a lot of companiescan afford to decide to make a project open-- >> 'cause they outsource everything. >> Right, outsource it. Well, I mean-- >> They outsource everything. >> That's actually a huge change though. We're not sitting heretalking about hundreds of commercial products that are owned by a small handful of vendorsthat are multi-million dollar investments foreverything we're doing. We're talking about lotsof little tiny companies that have products thatare really, really valuable that are in the open sourceworld that we can get our hands on and startworking with before we even make a decision about talkingabout support or whatever. There's all kinds of technologies that, I walk into this room andthese are like friends all around 'cause we'veworked with all their software and we're like hey, theseguys have a company now. This was just a GitHubrepo a couple years ago and I think that that's abig change and embracing that, that's probablyreally hard for your typical kind of IT shop where theywant to have this clear line of I can call techsupport and get someone on the phone and that's like the main-- >> The classic old software model but it's changed. >> So Steve, one of thethings we're trying to get some insight on here isit's not just running Kubernetes in production,it's what am I doing with it. How does that change my business? I understand ML is a big pieceof what you're doing there. Give us some insight as to how does this transform your business? Does it transform your business? >> Specifically on the MLside and we'll talk about this actually that's kind of thefocus of our talk tomorrow so I don't want to stealtheir thunder too much but a lot of it was really about looking at okay, how did ML, deep ML people work? How did they want to work? If you ask an ML personwhat they really want they want an infinitely scalable cluster that it's just theirs and they want to an assay to manage all theinfrastructure for them and a data engineer to managecleaning up all the data and all these things and they wanted that all to themselves and not haveto share it with anyone else. So a lot of what we try tofigure out is how we can actually deliver that to themand it really has transformed. Once people realize that onour platform they had access to an enormous pool of GPUs,it went from oh, I want to work on my box and can you giveme GPUs on my one little box to wow, I can dohyper-parameter tuning across hundreds of GPUs overnight or during the day or whatever their needs are. It really unlocked people's capabilities and they're actuallylike, they went from being skeptical of a systemthat they had to share and things like that 'causeit actually just works and that's really the-- >> That's really thedopamine effect for them. They can see value withouthaving to go through the slogging of the configurationsand the normal stuff >> Yeah, exactly.>> that they had to do. >> Authentication. >> So we've been hearingthreads of the CICD pipeline is a big benefit,which you're kind of seeing as well but whatwe're also seeing people building below Kubernetes seeing storage and networking getting better. How do you see that holistically? Are you seeing is thenetwork more performant, that notion of programmabilitybecomes now part of it, automation, it's software. Everyone has to build software. In fact, I talked to theVP of Technology Innovation at Proctor and Gamble andhe's saying hey, we outsourced everything, I got to start hiring software so maybe not as big asBloomberg but the trend is let's get more software people on board but they still got networks,they still got storage, they still got the gear. What's the impact, the under-the-hood? >> Yeah, I think it'scomplex because you typically have these structures thatare built inside companies where you have a networkingteam and you have an infrastructure, ahardware team and whatever. One of the SREs on my team the other day, he was like, do you thinkwe can talk to the network team about puttingsoftware on their switches? That's a really interestingquestion to start asking and he actually had areally good use case. That makes a lot of sense, maybewe should think about that. And then dealing with, there'sobviously the technology aspect of that but there's also skillsets. Someone that's been workingwith a bunch of switches for a bunch of years isn'tnecessarily a programmer, used to a typical CICDprocess and things like that. >> On the flip side, I thinkthat's cool to recognize the networking guy butwe heard Tim Hopkins say there's a lot of policyknobs in Kubernetes that the networking guyscould potentially take advantage of so it mightwork the other way. Are the network guys looking at Kubernetes saying hey, or are theynot yet that sophisticated but they would love, they'd love policy. Network guys write policy. Wouldn't you want-- >> Yeah, yeah, oh absolutely. It's actually one of thebiggest draws of using Kubernetes in our ecosystem. We've made heavy use ofapplying network policy down to the workload level which means that from a securityperspective, if I know that I'm transmittingdata between two different places and I've only openedup assets for that one application, for thatone particular use case, rather than saying well,I know that I'm running the same workload on thesame box and I got to open it up for everyoneon that box but maybe someone might use thatthing but maybe they won't and like worrying about stuff like that, it's like no, I can runa workload and I know that these are the only two end points that it can talk to. >> Oh, that's a relief. That's like, hey, we're done. >> So for them this is their panacea. I know exactly whatworkloads are doing exactly what on the network andwhat they're capable of so that's been-- >> That's real progress. That's progress. >> Oh, it's huge progress, yeah. And we've been able todo things that we used to not be able to do for years. >> Talk about the-- >> I just had a quicklittle question there. You mentioned you've gotten SREs. When did you pick that up asa term that you called there and how do you see if you talk a little bit to the skill set and the jobs of peoplethat you have inside. >> Bloomberg's a big companyso the terminology of it and what actuallyindividual teams are doing is probably a little bitvaried across the organization. It's been something that'scome in over probably the last two to three years at Bloomberg. In my organization, it wasactually really interesting 'cause when I started off with, you know, you read the Google book and whatever. What I did is I wentto the guys on my team that were going to becomethe SREs for the organization and I had them write thismanifesto about how we should build and deploy and managesoftware and I didn't tell them necessarily up front thatthis is what was going to happen but when they finishedwriting that and agreed that this is how thingsshould work and they argued for a while, I said, okay,now go build all the tooling to make this easy forpeople to do, all right. And that's what we, and thenthey've just been building off their tooling. Turns out when you're workingwith a lot of the tools and the CNTF and then with Kubernetes, that's actually not that hard. There's lots of thingsthere that are just easy when you get to that place and so that's the kind of journey we'vebeen on to really try to build that infrastructure andthey've done a good job. The engineers downstream of them the speed that they're able to develop and the assurance that there was a CVE forKubernetes two weeks ago and we patched it theafternoon the CVE came out. Being able to do that in anysort of company of scale is I've worked a lot ofbanking and stuff like that in my past and it's unheard of to be able to deploy things in that speed. >> And that's really, Imean this is the goodness of clouds, the goodnessof having that kind of consistency operationally. It's funny you use SRE,that's a Google term. It's a great term andyou've got developers, you got operations kindof working together now. That's the magic. Well Steven, thank you so much for sharing this great insight on theCUBE. Certainly great valuefor the folks watching. Lot of traction, a lot ofpeople, end users contributing and consuming Kubernetes,building around it. Great trend, it's really fun to watch. A lot of composable servicesup and down the stack so congratulations. Steve Bower, Data andAnalytics Infrastructure Lead at Bloomberg. This is theCUBE bringingyou all the action, sharing the data here at KubeCon. This is theCUBE. We'll be right back withmore after this short break. (electronic music)

Published Date : Dec 12 2018

SUMMARY :

brought to you by Red Hat, and the variety of Cloud Native. given all the end users,everyone's kind of award winning. What's the focus on Kubernetes? So in the area that I manage,which is data and analytics One of the benefits of Kubernetesis to give the confidence A lot of the models thatwe're trying to move towards How does cloud fit into the discussion? running in the cloud but primarily a little bit of the scaleof what you're doing? it's all kinds of software but in the end One of the big questionscoming in is okay, and everything like that,you have all the other Yeah, it's like we have tobecome part of the ecosystem What's the impact of theinvestment with Kubernetes? and so that makes us alittle bit different. Right, outsource it. that are in the open sourceworld that we can get but it's changed. How does that change my business? actually deliver that to themand it really has transformed. the slogging of the configurationsand the normal stuff What's the impact, the under-the-hood? One of the SREs on my team the other day, advantage of so it mightwork the other way. the same workload on thesame box and I got to That's like, hey, we're done. So for them this is their panacea. That's real progress. to not be able to do for years. and the jobs of peoplethat you have inside. and the CNTF and then with Kubernetes, A lot of composable servicesup and down the stack

SENTIMENT ANALYSIS :

ENTITIES

EntityCategoryConfidence
Stu MinimanPERSON

0.99+

StevenPERSON

0.99+

StevePERSON

0.99+

Tim HopkinsPERSON

0.99+

John FurrierPERSON

0.99+

Steve BowerPERSON

0.99+

Steven BowerPERSON

0.99+

BloombergORGANIZATION

0.99+

Cloud Native Computing FoundationORGANIZATION

0.99+

Bloomberg Data CenterORGANIZATION

0.99+

Red HatORGANIZATION

0.99+

SeattleLOCATION

0.99+

2019DATE

0.99+

GoogleORGANIZATION

0.99+

last yearDATE

0.99+

North AmericaLOCATION

0.99+

8,000 peopleQUANTITY

0.99+

KubeConEVENT

0.99+

two weeks agoDATE

0.99+

Seattle,WashingtonLOCATION

0.99+

two end pointsQUANTITY

0.98+

five years agoDATE

0.98+

siliconangle.comOTHER

0.98+

KubernetesTITLE

0.98+

two-years agoDATE

0.97+

Proctor and GambleORGANIZATION

0.97+

one applicationQUANTITY

0.97+

bothQUANTITY

0.97+

two different placesQUANTITY

0.96+

CloudNativeCon2018EVENT

0.96+

oneQUANTITY

0.96+

three daysQUANTITY

0.96+

tomorrowDATE

0.96+

more thanQUANTITY

0.96+

OneQUANTITY

0.95+

three yearsQUANTITY

0.94+

EuropeLOCATION

0.94+

CNCFORGANIZATION

0.94+

one systemQUANTITY

0.94+

North America 2018EVENT

0.92+

SRETITLE

0.91+

CNTFORGANIZATION

0.89+

2000 solar clustersQUANTITY

0.89+

single platformQUANTITY

0.87+

couple years agoDATE

0.85+

millions of ticksQUANTITY

0.85+

Data andAnalyticsORGANIZATION

0.85+

hundreds of GPUsQUANTITY

0.85+

doubleQUANTITY

0.84+

KubeCon 2018EVENT

0.82+

a yearQUANTITY

0.81+

one little boxQUANTITY

0.79+

GitHubrepoORGANIZATION

0.77+

about ayear-and-a-halfDATE

0.76+

twoQUANTITY

0.76+

hundreds of commercial productsQUANTITY

0.75+

cloudORGANIZATION

0.74+

yearsQUANTITY

0.74+

Cloud NativeTITLE

0.74+

Technology InnovationORGANIZATION

0.67+

a secondQUANTITY

0.66+

KubernetesPERSON

0.63+

KubernetesORGANIZATION

0.62+

multi-millionQUANTITY

0.62+