Rafay - The vCenter for Kubernetes? CTO Briefing
Transcript
computer so let's see you know we the the problem statement that we're talking about before we hit record was vmware i think has even if vmware stays course and goes to 10 zoo route i think a couple of problems that is obvious to not just my audience who primarily have are typically big vmware customers and this is the conversation that i've had as they thought about whether or not they're going to embrace kenzu or if they're going to go like the open shift route of some
other uh distro and not just distro because it's less about the distro it's more about the ecosystem is one is tenzu the right path to go down uh because there's vsphere supporting every distribution of kubernetes and you can get that somewhere else or is there another solution you know the customers are looking at eks uh anthos uh just a number of things i've had other smart startups on you know um creating alternative application development platforms to open shift that's more kubernetes centric and i know the
openshift guys will get irritated when i say openshift isn't kubernetes centric i made the argument that when i buy openshift i'm buying open shift it may be based on kubernetes today but i'm committing to openshift and i want uh i want red hat to take care of me no matter what the underlay is just as when they made the shift from uh their previous platform whatever they want to call it to kubernetes that i'm buying that and i'm buying that opinionated system but that there's a
bunch of in between like there's a lot of mup in between like openshift and tanzu they're not the same thing in the sense that i'm solving the same problem how are you guys kind of viewing that and where you're taking me and and you know that traditional traditional vcenter customer that has all of this heterogeneous environment to maintain how are you guys helping to step in and fill some of that engineering yeah so i think the the first step is so there's on-prem where v center
is the king and then there's the cloud maybe you wrote a blog at some point in the last couple of weeks talking about um how you know bmw arguably should have been the king of cloud because they're the bm's they are the libyan company but you know there's more ec2 out there than vm instances so any enterprise that says i'm going to go to the cloud what my recommendation with them is uh the cloud provider probably has a pretty good kubernetes offering you should use it
right so if you're in amazon you should use a gas azure you should use aks but then the same customer also has on-prem environments right so b center is something they have and then you have a bunch of options right so as one example be here graph a b we've packaged a really um you know easy to use upstream based kubernetes distributions equipadium based and what we've done is we've taken upstream bits and we packaged them fully uh kind of taking care of the life cycle
of kubernetes says that you know you can effectively press a button and get clusters up and add nodes and upgrades and all the things that you would do with kubernetes you can do uh with our solution and many customers and the reason why we took this path is because customers an example from this morning somebody asked me the question so what if i need to fire off in here uh which is a fair question right because if you don't do our job they should be stuck
um yeah no problem similar to how in in us we can help you spin up eks cluster so if you sort of fire us you see guess we take our bits and go home you got to go figure out general automation with tks similarly on premises we use qbdm as a core uh or k3 sometimes depending on the situation and you can you just have a kubernetes cluster left so what we've done is we made a decision that look the kubernetes distribution game is over that
was over some time ago you're going to had this conversation back in valencia in spain that coupon um eks is one aks is one and then upstream kubernetes has one the underlay is b sphere or ec2 whatever right and we're gonna sell you the automation the visibility the governance and the operational security that you need on top of google that's where we built our business now to the specific question you asked about you know customers are looking at vcenter versus tanzu i think there are like
everybody's at the every customer which means everybody's gotta be scared and uh customer uh vendors like raphael there are other way to do this also what we have to do is we have to provide to our customers integrations and and alternative integrations where if they're in amazon it works with the amazon you know kind of ecosystem if it's on on-prem vcenter it works with the vcenter ecosystem which means we should be able to call the vcr api and you know do the things that need to
happen so that we sell today right so to me being there offer on-premise is our best friend because everybody is an every customer tanzu is who we compete with but then with tanzania this is my opinion um you know i don't work at vmware uh my opinion is i think many of my patriots right other companies in this space i think they're missing the point of what it is that customers want to do i think i think what everybody thinks is that the biggest problem customers
are trying to solve for is they're the cluster and they make another assumption that they consumption then everybody's got this massive skill set available in their companies that can solve for you know the policy and the blueprint and the backup and and the get-offs and all these things you're gonna magically have all these people who can do all these things and i think both of those are not true uh a i think the distribution was over but then b i think the pain is is more
around the operationalization of kubernetes and enterprise which is not the same as bringing up a cluster so i would agree with you i think one of the challenges that organizations are facing is this talent gap and it's exaggerated i had a conversation about ransomware and someone asked me someone related a a story to me and said a vp of infrastructure asks if linux machines are susceptible to ransomware and the person didn't laugh because that is just the level of sophistication at the enterprise level there aren't
people who know how to deploy a cluster or even after you've deployed the cluster doing something as simple as checking for the doing a cube cuddle to check for the number of pots running on a specific or a number of uh of containers running on a pod they don't have to do that like that's not a thing they that they do i typically go to vcenter and vcenter tells me what vms are running on each node and that's the level and that then i go off
and do backup policy and do the things that people hired me to do so when i initially looked at kubernetes this was a couple years ago a few years ago actually i'm looking at it was uh i was an early kubernetes denier not that kubernetes doesn't do what it says it does but that the complexity to deploy kubernetes in an enterprise was too much not to for it to be accepted at scale and i think i'm still right i think for it to be accepted at
scale the talent isn't there to do it number one problem in my in my opinion so i guess the question is how are you solving that problem because it is and it's not a dig it's just complex it is what it is it's complex yeah look i think um this has happened again and again in industry i'm sure i mean when we spoke in valencia i was talking about you know my favorite platform of the world which is v center right i think we sort of
translated awesome and we sort of cb center as this simple tool that solves for vms but actually it solves for vms and access and networking and storage and all these other things that you need to have you know work well super capitalism yeah right complexity but it is super complex what it does see that's the thing right it it addresses the complexity so that enterprises don't have to have an army to solve each of these problems every time i provision storage every time i provision new
storage it is very straightforward if i right-click go to provision new storage to my vcenter all of my nodes see it that whole activity is like super complex like every every s every esi host has to be given access control to the storage it has to be given the path to the storage and the virtual [Music] lungs have to be assigned there's a whole lot of stuff going on on the background so complex but for the v admin i don't need a storage admin anymore i
can just once my storage array is deployed i can do this with a couple of button clicks that's where we're at on the on the vc side of the equation so as we introduce kubernetes to these same folks that level of automation isn't there mostly yeah so let's talk about see this is the perspective right um why why aren't there tools that can be used by cube admins you said vm elements right so why is there not a cuban right a cube admin does exist because
there is no one person who can do this job for the most part in the tools like comes right you need many many people right and um this was our premise when we started working on platform um when we were raising a series a uh keith and i would tell bc is the story right i would say look we're gonna solve these a problems or crazy things right and they would say no this is not possible it's crazy it's never gonna happen go away right it
was really hard to raise money and then of course you built it right and if you'll allow me five minutes i'll actually show you show you a quick demo um uh just to kind of give you a sense of what's possible and you are the oscar architecture i want to show you and i wanted to show a picture of the architecture it's a very different way of thinking about the problem uh that allows us to scale that now you built it now it's actually easier right
uh we had this idea of sort of building a b center right the and you said it bm admin we want to make the cube admin successful that's the job right now whether they're building an eks cluster or an eks cluster or on-prem too bad i mean base culture or topo b center they shouldn't have to understand or care about the underlying complexity which you didn't have right and i would posit that we have accomplished that right right you know whatever i think a good way
to to kind of continue to just see it like the yeah sure so let me do two things then if you and please stop me or direct me or push me in any direction you want i'll i'll show a like uh just a um architecture diagram high level where does rocket live in the world yeah and then we'll just you know by the way our documentation it's all open everything we do is open uh in terms of probably protect what we build and in fact soon
enough we're also going to put our own we're so far ahead it doesn't matter so a key thing we've done here i'm going to a page called ztaa zero cross cube metal accents um we built essentially a a proxy so many of the team members here have a proxy background um they kind of see proxy and everything um the way we run our product on the internet is this green box in the middle this is a rapid controller it's a single box but it's actually a
very complex micro services based application that's running on egas so we run our application on kubernetes right it runs in multiple regions so it's a highly available system uh we run it across three regions right now uh and three is these three regions um this service is what all of my customers clusters are reaching out to so all of my customers customer clusters each customer will have many many customers they all are running and operating them whether this cluster is provisioned by graphic or not it
doesn't matter if they're running an operator and this operator is basically reaching out to ram now on the other side user system whatever right they need to connect to the cluster traditionally the way uh you know tube carter works is you know you do this right you connect to the queue vpn you don't want the customer to do that because exposing the qbp on the internet is a problem right that's a security issue but then people end up deploying vbns and jump posts and you know
the standard things right but then let's say you have a vpc per customer make it more interesting most enterprises have a aws account per international team right so let's save 100 internal teams each has a dev account and a product how many business accounts do you have 200 how many how many uh jumpers do you have right you need a spreadsheet to figure out where to go that's just crazy but in our world what happens is a user or system they need to interact with the
kubernetes cluster they think they talk to the cluster directly actually unbeknown to them we run a number of proxies on the internet these orange boxes these are highly available they were spread all over the internet they are actually the end point that your cube cuddle commands hit or your cube api calls it and then you authenticate you authorize you and once we know who you are we connect the cluster this way this is software defined perimeter sdp the security concept applied to kubernetes but the beauty
of this is yes it's it makes it simple no mediums or no jumpers that's the immediate effect but the but the benefit of this is now we can actually take a lot of the control that happens inside the cluster and make it central so the auth is happening outside it's not happening inside in fact the service account is also being created outside not inside so a lot of the you know the oidc overhead and whatnot decks these things don't have to happen anymore it's all happening
outside of the cluster everything is happening centrally so instantly the enterprise gets centered management and control over all of the clusters these clusters can be in the telco network in ews in azure on-prem at the edge doesn't really matter single pane of glass you see out of the box so if i'm an auditor i'm going to ask if i'm the audience and every author that may not access but if i'm the auditor i'm gonna ask you know what give me trace back from when a cube
cuddle command was issued on the proxy and uh under keith's name it keeps the the uh the the security object and it happened on the actual cluster how do i do that traceability all the way back to the id that that performed the action on and it doesn't even have to be the id the the instance how do i log what keith has done all the way down to the actual instance on the physical or virtual host i'm showing it to you right now on the
screen so in the last hour uh you know uh i don't know okay well i'm just going to first support engineers what is this guy done across all the clusters or one of the clusters or what are the commands that he started the cube cuddle level centrally audited across all of my clusters in a single kind of class out of the box this happens this is a side effect by the way this is a side effect of the architecture that all its audit is now simple
every enterprise needs it it just happens so then i can just trace back uh i'm sure that there's some type of event id i can correlate to what happened on the cl on the physical cluster yes sir all right yeah oh this is this is rock solid right so now that's pretty that's pretty straightforward that's how proxy works yeah the developers will see developers don't care right that's not my problem i'm going to just download my q config i can do this from an ap i'm
just showing a ui because it's just a better demo then i download my config i'll do what i need to do right i don't care i'm good i got my bitcoin ticket i can hit any of these clusters anywhere any of these clusters anywhere right and i do my job but as the admin i get to see everything okay so that's that's the core proxy but now that you have a proxy that as you know the beauty of proxies is you can overload anything it's a
proxy right you sort of have control so then we said well what else can we do right so on this proxy uh we can provision infrastructure so by the way this is a this is a multi-tenant system in that of course it's sas so we have multi-tenant system but then each of my customers i'm logged in as a as an organization admin into one account right so one company this company is running eleven e gas clusters and like eight on prem clusters and they have a
gas cluster they have a bunch of different things going on this is a typical enterprise right they got all kinds of clusters but then this company has 47 different teams running inside the company some of these guys are running two plus or somebody's learning one somebody's sharing a buffer so if i go see my buddy benny my buddy buddy doesn't he doesn't care that there's 20 whatever customers in the company he cares about the fact that his team has two clusters one of them has a
problem right now so there's visibility now it's a proxy right you can you can see everything in one place so now when benny logs in because of his his identity is different from khasi he's going to see a different view his view is this now he can go interact with his clusters he can you can see what's going on on them let's go to the one cluster that's working uh okay i can see what's inside the cluster in fact i can jump in into the cluster
and i can see all the pods running this cluster again everything single in a glass right again it's a proxy right so visibility comes really naturally it should right uh uh and you can see a whole lot of information inside of the software by the way not only this you can it's going to pop over fairly you can let me find a cluster that actually has been upgraded in the past against a proxy right so you can do a lot of things uh you can upgrade
clusters that's a neat guess cluster i can just press a button and i can upgrade your cluster so we still haven't really talked about a whole lot of the cool things the product does but these are the things that people spend time on right you upgrade clusters just press a button now you want to update the ami press the button i can imagine since i'm using a proxy i can do a ton of things i can do some a b testing i can do some canary
deployments i can do all kinds of things that the in theory that a proxy should enable me to do because i'm putting a abstraction layer in between the container admin the cube admin and the laurel layer piece so in theory you know i should have some vcenter like functionality let's you know let's talk about you know what we do in vcenter every day all day which is you know the concept of a v motion but i don't need v motion in the same sense that i
need it for containers that i needed in uh in the vmware world i need to transfer not necessarily compute storage computer memory i need to transfer processes and and applications let's say from on-prem to the public cloud or of the cloud to on-prem a sticky thing happens even with kubernetes we say kubernetes is easy yes it's easy when everyone does it exactly the same when i need to deploy uh when i need to expose public ips in vcenter that's different than what i need to expose
public ips in eks the it is too completely the the underlay is different so in theory if i had a shim or proxy in between the two solutions the cube admin can move workloads or environments from on-prem to the public cloud without the uh cube admin understanding how to plumb any of that stuff that's theory so in practice what do you guys how do you guys do that type of stuff in practice yeah so we've sort of we've rethought how what a what a stack looks
like so in our world there's kubernetes then there's add-ons that run on top of kubernetes one of them would be a load balancer by the way and then there is the application so we want the application to not actually care about the atoms and the reason why we did that is because if it's on-prem maybe you want to use metal led but in the cloud in aws you're going to use elb right but as an application developer i don't care right right so as an application
developer i want to deploy that right we call it a workload so i can deploy an app called uh do i have one of my yeah i do let's see if it's there right there so i can deploy an app and so we came up with this concept called placement so i can say i want to deploy an application to actually give you a real example so i'm going to deploy an application to a label and the label is uh this is a good one okay
eks1.21 if you're running eks1.21 i don't have any one word so here's what's going to happen wrap it runs a reconciliation drift so if it finds at some point in the future that some cluster as this label is going to auto deploy the application to that name you don't have to oh that makes it invisible to the developer which is the the the ideal state of kubernetes to say that you know what i want to deploy it to a label and then there's the cube admin
that worries about connecting the labels to the environment that's somebody else's job yep and i think that's the the thing that i wanted to get into the somebody else's job let me give you some background we did a uh a nice size report on the different vmware cloud options so vmware cloud in oci or vmware vsphere and oci vmware cloud on aws vmware uh cloud engine and google compute engine vsphere underneath in all of them the delta is so when i'm in vcenter everything works like
vcenters should work like if i you know if i need to do a snapshot of a vm or right click do a snapshot of vm what happens underneath in the underlay is is magical however if i'm the v admin and i want to make the uh if i want to make a if i want to create a new network and that new network has a public ip address how i do that in in google versus uh oracle versus aws versus microsoft there's two different ways to
do it in each platform and i have to know each way yeah yeah i would argue that uh maybe maybe instead of trying to find a way to solve them all you know what kind of one ring to rule them all maybe we should just concede that there would be different options right yes but then make sure that there need to know it and there are people who are not right so the infrastructure layer right those people need to know the infrastructure engineers need to know
right so for example uh like if you're in aws you're gonna eat your deployments from dns engine you're probably gonna need i'm sure i'm gonna run an elb here somewhere like you'll need a cert manager you need some things that are specific to your device but then if you're running on pram you mean engine x or metal lb or some variation there are right so what should happen is and this is how we can approach the problem we created this concept called blueprints so the idea
is that i have a standard blueprint and go to the environment which is more stuff going on i'll go to a different team called default there many many things so i have an eks blueprint and i have a you know i don't know a guest blueprint and then i have an on friend right so as somebody in the team which is a central organization like the center of excellence team they're going to say that for my eks blueprint i must have start manager aob risk controller
cloud watch insert whatever that is will be controllers these things but then if i'm on premises i must admit lb and nginx is the is the controller when i provision my infrastructure my cluster i should just consume this blueprint and then i don't care right so the idea is that if he can create this model where there's separation of duties some people come and set a policy my blueprint should be x y and z but then when i provision a cluster i can pick so i
can say my blueprint should be whatever x right and i want to use the e guess and then i don't care all i care about is i need a cluster i want self service so my in my my it organization is giving me self-service options by the way i mean using the ui for this most people don't do this in the ui if they do this from like get off to this point and i'm happy to show you that also uh but then the blueprint determines
the underlying uh bakeries right so it takes care of the bakeries of the underlying uh cloud or on-prem environment but that is not the problem of the guy when the ordeal who needs the cluster so that they can deploy their application right i think that to i'm sorry so the in order so this is pretty cool so if i have a scenario it enables like a lot of scenarios that we talk about in kubernetes but someone has to have the knowledge to kind of stitch it
all together so an example would be i have a depth development team and i have a production team the development team uh writes applications based on what the to be intended state will be and they and i presented them the rafa platform as they as their kubernetes cluster with they can have very similar labels as to the production team's capabilities but that underlying infrastructure as the cube admin that underlying infrastructure is plumbed to vmware vsphere or vmware vcenter resources that same team can then move it
over to let's say a sre or production to deploy and they have a very similar uh set of labels in in raffi and maybe they're just changing one one letter and the in the label or whatever but they're using the same terraform they're using the same deployment and management things to deploy is just and it all looks the same the only difference may be the labels that i'm sending the application to yeah exactly show you an example of a spec file that you can use to
provision infrastructure clusters i'll use as an example then we can go look at other things so here's a file that represents a cluster in this file of course i defined like you know where it says project and so this is like damn qa pod you know china us whatever right so it's a it's an isolation company and depending on the isolation not either either depending on your roles in the community then i'm saying i need a blueprint uh in this case it's default but it could
be anything of certain version right and the point here is when this cluster is provisioned yes it's going to be guest clustered doesn't mean anything right just a cluster it needs to have a personality right so then give it a certain personality deploy these 20 things on it et cetera et cetera and oh by the way then set up a certain number of new groups this file is a very simple way to manage things because the baby bill traffic is that so i talked about zero
trust before another core component in the platform is it's actually built on get ups so if my customer wants to use argo reflux that's okay right this is an open system you can do anything but this platform actually is built on githubs so we have get ops pipelines built into the product you don't need to go back on the product if you don't wanna if you want it's great right and the reason why we say look here's one good reason why you could use our product
it's multi-stage but b two reasons one is you can actually run your terrifying jobs from rocket and you can pull your terraform jobs from gates number one yeah so if you're at the beginning stages of but i don't even have a cluster yeah if you're if you're at the beginning stages of adopting kubernetes if you're very early then you can use these workflows and then expand them out to as far as you want to go or if you've already had workflows so if you're you know
already a huge terraform shop and you've built some stuff around there you just you know reversed it just bring it more yeah you're bringing them over from wherever you are yeah you're plugging in from there now now here's a really nice thing we've got here so from git to the system right so in my git ripple i have some some stuff sitting and i want to create an environment for one of my new team members okay so we have automation where you can basically create an
like an entire landing zone for a team and say hey this cut this thing they need clusters they need blueprints whatever right in this specific branch let's say team new one right so go to this branch teamviewer one under pads so key this part of this team called me one and he's gonna bear clusters and blueprints as keith is putting together his cluster specs so you're going to write a cluster spec which is this file you're going to check it in it's not going to get
approved yet your pull request is sitting there somebody else was the infrastructure admin is going to approve your request and the instant approval requires approval rather than a fantastic and rapids gonna start provisioning clusters for you with the right blueprint and potentially if the labels are set up already with the right application a single file can generate an entire environment it's not based that's one use case let's say that i want to be the internal service provider of service providers so i want to give and
this is the appeal i think of the idea of tanzu to an extent is to say that you know what we'll just give i'm worried about resources like finance resources i want people to go in and say i want to provision five clusters i want to provision two customers i want auto scaling but i want to put some boundaries around it but i want them i want it to look like i want it to look like there's infinite resources but there's not infinite resources when they
do uh uh uh uh when they request resources they'll get a return that was denied or whatever just like in aws if i go and go to provision something that that's not available to me i'm going to get a reach i'm going to get a return to errors so i want to be that type of provider to my service my internal service yeah yeah we've talked through that so you can we have a concept for templates in your product where you can literally set ground rules
so you can say let's say there's a template for qa which says i'm using this ee cas as an example that applies anywhere you can only deploy using this uh im roll and you can overwrite it you can only be in london or write it i will allow you maybe two versions of kubernetes 1.21 and 1.22 i will allow you to only use a specific uh uh blueprint standard and you can't change it and we want now google the classroom so you can actually lock people
down in a certain environment and you can do way more than that by the way you can say for example you can only use a certain vpc you can only use certain note groups you can only use certain instance types so you can actually make it such that a developer comes and says hey i need a qa i'm in qa because they are in qa their role is qa which means they can only go to a certain template and they can only spin up a cluster
with one node or whatever you listen right you can lock it down to that extent or you can open it up to whatever you want so now you can do true self service so i guess the end to kind of wrap up begin to wrap up is what does this do that a tenzoo or anthos or these platforms that want to because all of them advertise the same thing with the conception of maybe has eks they acknowledge that there's other you know kubernetes clusters somewhere else
and they are going they would run it whereas google and vmware absolutely embrace that there's other kubernetes clusters and you either have the tanzu uh abstraction layer or you have the uh anthos abstraction layer where does this kind of make opinions or offer stuff that the other solutions don't so i think the the market is going in all of us are going in the same direction fundamentally right which is our customers need you know seven eight nine ten different things solved in one platform because it
just the problem is too complex right so on this call today we've been focused on infrastructure right which is which is an important piece but it's one piece right the thing other things that matter everybody wants to deploy gatekeeper policies right everybody so we built a native integration where you tell me i need a gateway policy and then the underlying gatekeeper configuration the additional controller you want to do backup and restore tell me i want to do about i want to back up a node or
or sorry a cluster and only the control pane or vpcs we will take care of everything you want to deploy applications we have a gear ops model we take up everything you want to do secrets management you've already built it uh you want to do a data application you've already built it you want to integrate registry so you don't have to share your full secrets for with every developer you want chargebacks people to you want a catalog we built it the point is that we i
think this team here graphic we fundamentally understand the roadmap of our devops team right and what else is coming right so we're working on network policy management service mesh management but each and everything that my devops customer has to deal with inside the company i want to deliver to them as a as a support service that is built into this platform so they don't need to go buy yet another product that's it's my job it's not their job so that's pretty ambitious uh yes it is
yeah you know i was on the on you know talking about valencia i was on the bus ride in munich from one terminal to the other and i was listening to this guy who worked for one of the agencies the eu agencies and he was telling uh one of the other attendees how they're headed to their third service mesh uh because the other two were too complicated and i think and my guess after talking to a bunch of service mesh people my guess is that the
service mesh itself wasn't too complicated it was their ability to operationalize either of the two and getting the data that they need so you think about all the things that a service mesh does if you think about all the things that a messaging service does or uh or all the different components that you know that cncf chart is big for a reason and the thing that vcenter does well is that it i can change a lot of stuff in vcenter if i want to but 98
of customers probably should like exactly right yeah they're exactly right see that's exactly the right approach right so we what we do is as an example right so most of the enterprise customers you talk to they use hashicorp1 so we have a first-class integration you want to bring in something else we support that too that's a little bit more but we take one or two options and we just knock him out right we just make it perfect but then we've done this again and again look
you said this is ambitious this is a crazy plan it's not ambitious it's crazy but it turns out that this is the crazy team to begin we've done it right it's not it's not a story it's a product it works it's my complaint is what i've been complaining about for the past five years about kubernetes it is for better or worse the enterprise has high expectations about what this type of production workload looks like i think people have underestimated the transition or the journey to cloud
native we cut our teeth we hit our heads up against a lot of these problems early in the build out of like like our industry has grown up during the vm world and we've solved a lot of problems during that time period and now we have to solve the same problems again and that tribal knowledge has been lost to an extent or that tribal knowledge to do and build or the patience or the uh the the governance and acceptance of the time that it takes to
rebuild a lot of this stuff so when a person like me looks at kubernetes and looks at the work that needs to be done in the enterprise it team to get there like where's where's the horses where how do i how do i get there that's a lot of talent that i don't have and if i had it i'd probably have them solving different problems and they'd be working on something else but there's so much to do here and uh [Music] look we knew this was
going to be a crazy plan we had to hunker down for a long time to get this right and you know we have a few minutes left on this on this conversation so i'll share one example of something that is actually relatively trivial but it's important to tell you about right so let's say you have a registry that all your developers use so the way your cluster will talk to the registry is there's something called a pull secret so you need a secret to talk to
the registry so you can call a container the traditional model is you take the secret and you put it into a yama file and uh that's you know then you push you know so now the problem with that is the yama file is sitting there it's sitting in the git ripple right so your secrets are not sitting in the github that's a problem so what people do is they say well okay we should solve that problem by encrypting the secret and what if we could provide
a way where remember we are proxy right we could provide a reference to this to the registry and because we have a proxy we could change the value when the file hits the cluster so don't ever expose the pool secret to your developers we rafa have built a model because again we have proxy we can do all of these things we will change the value while the file is going through the proxy to the customer so we built a model for that this is a small
example of the work we've done here and this is what it takes to build an enterprise product right enterprises care about this stuff and then that actually introduces another thing you know as i think about hashicorp vault and uh the what happens when i use a proxy to access multiple clusters where that also creates an opportunity is to have roles that can transcend cloud environments so like in aws i can assign a role to a pod or application and i am gives me the ability to
kind of do some super powerful things but that's only within the boundary of aws so if i have a proxy that's accessing all of my clusters on my behalf in theory i can shoot i can create roles that transcend all of my clusters across different infrastructures yes sir you can and we have so look i'm logged in as a guidance pc this is an on-prem cluster but this is a kubernetes like this is an on-prem cluster i'm going to cut it into this cluster and do
what i need to do okay boom all right and then when i look at my seven seconds account my identity in this cluster right a service account was created nine seconds ago didn't exist it got created right now now i'm going to do the same thing with the on-prem cluster this would be a little bit slower than the cranial cluster and i'll do this the first time and boom into one else uh so this account minus n that'll be the system 10 seconds ago i went
to two different clusters and my identity was created just in time and inserted into these clusters one's an eks cluster one's on premises why does it matter because we have a proxy this is the beauty of this model this is why i'm so convinced that we have the right answer for this market we have really thought i said bb is unfair my colleagues i'm just as my colleagues have done a really good job here right there they've really i mean they're near the problem right this
is the like as a developer if i have to now rethink my strategy when i go to the on-prem cluster versus gas versus aks that is burden on me as a developer i don't care i want to write my app i want to debug my app i want to move on and look when i did these two cube curls could you tell the difference was there any difference it's the exact same experience because there's a proxy in them and that applies everywhere be it registration secrets
get ops cue cuddle application deployment it doesn't matter we've so we've really thought about how to make it the same experience while at the same time not obviating the need for the infrastructure you know changes right eks will have alp and on-prem will have llb that is not my problem that's somebody else's problem they'll manage that i'll manage my separation of duties while at the same time getting the best out of each platform that's that's the solution that seems like we have uh built here all
right sir well i appreciate you taking the time out thanks keith