Building and Managing Private Clouds: OpenStack, Kubernetes, and the VMware Conundrum

In this episode of the CTO Advisor Podcast, Keith Townsend and guest Jason Benedicic dive deep into the challenges and opportunities surrounding private cloud solutions. As businesses grapple with the complexity of building private clouds, this conversation covers: The evolution of cloud strategies, from OpenStack to Kubernetes and VMware. The growing role of Kubernetes in [...]

Transcript 4,021 words · about 27 min to read

Machine-generated from the episode audio and not hand-corrected, so names and technical terms may be imperfect. The audio is authoritative.

Yet another episode of the CTO Advisor podcast, we're getting a pretty good cadence out and I have a LinkedIn post that probably has about 100,000 views at this point. And it's talking about OpenStack and OpenStack, not just as an alternative to VMware, but kind of this idea of building a private cloud. So I actually owe Jason this podcast episode from two VMworld Europe's ago. Jason, pronounce your last name for us. Benedict. I will give you a plus pronunciation of your name.

I wasn't even going to try. Jason has been in. The field he has been on the ground dealing with everything from public cloud, private cloud ish stuff, what to say, but mainly Kubernetes. And I think we've over the years, Jason, we've gotten to the point where we've kind of. Blended the lines between Kubernetes and private cloud. And while the technology conversation is interesting, we'll get to that. I think one of the things that's come an output of VMware's journey to cloud, this conversation around repatriation is sometimes business decisions get made that we don't necessarily agree with.

I don't know if you've ever experienced that. Yeah, I have. I mean, there are sometimes edicts that come from above, be it financial, be it some form of, you know, they still still get made on the golf courses. Sometimes these things happen and management can make decisions and you've got to just live with it. You got to roll with the punches, you know, kind of you can get sold a dream, but somebody's got to implement the nightmare at some point. It's one of the things I've said in the past, you know, and you got to get on with it.

There's might not be what you wanted, but you've still got to deliver the business outcomes. Right. So this has happened across even back in like the early virtualization days there. I remember customers that were told to get on the virtualization wagon that really didn't want to. They still wanted to do things. And I remember the early days of virtualizing things like Exchange or Oracle that the diehard fans were not into that. They really didn't want to get involved. So, you know, we've been here before.

It's not the first rodeo. Yeah, early in virtualization days, I had an IT manager come in after me at that ran a big virtualization project. He reversed the project. He went. We were completely virtualized. And he said, you know, this virtualization stuff isn't going to last. And he went back to bare metal, which is ironic. We're in one of those phases, I think. And I don't care if you're a technology executive, a technology practitioner. The business, quote unquote, makes decisions that we have to eat.

SAS is a great example of that. You know, you'll have marketing or sales or commercial go out and purchase and deploy Salesforce. And you're left with having to support Salesforce, whether you wanted it or not. This is, you know. This this. T. purist who have a very clear, I think, ideally, even where the business value is, because this is part of our jobs. T. T. have been around. So I want to establish some baselines first, Jason.

I think the basic one. Can you kind of describe the difference between public cloud? Private cloud kind of in this and what I call a not in between the two. Kubernetes is a facilitator of the two, and it can be very much used outside of either either operating model. Yeah. And I mean, so I cloud is an operating model and that that's the that's the important thing. So with the public cloud, you're getting some you're getting this new operating model, this new way of consuming the technology.

And that comes with a load of really nice benefits. You've got, you know, resource management that is easy to understand. I am and permissions and security and being able to talk to resources in a certain way. Mostly by being able to describe them or name the resources and talk between them. And that's all operated for you in the public model. Right. So the big hyperscale as they run all of this, they do all the upgrades, they do all the work.

You just consume the services and you can consume the different levels. So you've got your infrastructure as a service type level where you can run your VMS and things in the platform as a service level. And then even some software as a service and things, you know, beyond. So you've got the different levels of where you're consuming. But the overall operating model is that you you can consume named resources with a whole set of security and they all integrate in together.

What the private cloud kind of tries to do is try to emulate that model in in your existing data centers or in your hosted data centers with the hosting providers that are out there, the data center partners. And you bring the hardware, you bring the the components together. And the software that's out there is really trying to bring you that consumption model on top of these various levels of hardware. Now, you don't get don't always get the same level of extraction, abstraction, because not everybody's integrated in the same way.

Like one of the posts that we were talking about where you mentioned S3 and you don't get the same integration in a private cloud with S3 as you do in the public cloud right now. And there's there's some differences there with the IAM model and the resource naming. Kubernetes is kind of somewhere in between. Kubernetes gives you a an orchestration layer. And I know it started around containers. But I'm kind of seeing it start to develop a lot more in the we're talking a lot more about cube virtualization workloads or function workloads with things like Knative.

It's what started as container orchestration is coming to be a bit like a cloud operating API. So Kubernetes allows you to have this resource recognition. There is some IAM or some role based access in there that could be improved. But it gives you this kind of layer abstraction layer that you can use in a private cloud or a public cloud or anywhere in between, really. And so if we talk about the business side of it, it seems like just a few short years ago that businesses have adopted this cloud first mentality that thou shalt go to the cloud.

Everything we build, everything, not everything, not just everything we build, but everything we run will go to the private cloud. What we just I'm sorry, the public cloud, what we discovered was not to the surprise of many of us. The public cloud is a really bad operating model for monolithic and traditional applications that are built on VM that pay as you go model does not translate well. And we were naive to think of how much work it would be to convert these applications from these monolithic applications to these public cloud native resources.

Along came the idea of, well, why don't we just build a private cloud? We discovered that and that building a private cloud is really difficult. It deserves its own podcast episode. But the net of it was that public cloud providers are motivated by profit to build public clouds. So all of the resources needed to build a public cloud was available to you. I share a short message on LinkedIn of how I interviewed for to manage the OpenStack team at Comcast.

A year later, that entire team was at Wal-Mart building their OpenStack cloud. There's just not enough resources and financial motivation to build private cloud. In came kind of Kubernetes and Cloud Native Foundation, and they provided this in-between solution to us that you mentioned. This ability to run this abstracted layer, even if it's not true private cloud on premises or in the public cloud. We didn't need all of that. This brought us to Haktan and Broadcom buying VMware and VMware making the strategic decision that they're going to focus on building, helping customers build private clouds.

I have feelings about this because I have the pains of early 2012 to 2016, 2017, trying to build private clouds and realizing this is not a thing for the masses, for the enterprises. But one of the thoughts coming out of VMware. Explorer 2024 is that Haktan and his team is selling this above the CTO, CIO level and going straight to the business and saying you can save so much money with private cloud. So that leads us to our original conversation where we're tasked with folks like us are tasked with making this stuff work.

So we're going to dedicate the last little bit of this podcast to talking about what happens when your CXO comes to you and tells you to build a private cloud. What are our real options, Jason, for building a private cloud? And this is where it gets really interesting. So you mentioned the CNCF earlier, and I kind of think like the CNCF is a bit like going to Cheesecake Factory or Olive Garden. You've got this huge, huge menu. And there are so many things that are similar.

You know, the tastes of Italian food or Mexican food or whatever. You've got the same sort of things in the CNCF. You've got a huge number of service meshes or other orchestration components. You've got security, you've got storage, you've got so many things. And in business, a lot of time, you kind of just want that, you know, predefined sat down menu where someone's going to bring me these things. And it just, you know, these tastes go well together. And we don't have that from the CNCF at this point.

We don't just have a really nice menu of this all works well together. So as technologists, building that private cloud on the CNCF model at the moment is very similar to that early journey with OpenStack. You've got some teams out there that know what they're doing. They've done it before. They're really good at this, but they're not a huge number of people. And the people are vying for that talent across the industry. When we look at the VMware side of things, when VMware started in this space, they did something really well.

They made it simple. They built an army of practitioners. So I was in the early vExpert program. I've been on the vNinja training when they first introduced NSX and things like that. They did a really good job of getting an army of practitioners behind their technology. So you could go and pick up the right number of people to go and run a VMware data center. And that was whether that was before the VCF days. So I did this with the early vCloud director.

One of my previous employers, we were checking between VCD and OpenStack and Platform 9 and stuff back in that day. And we went with the vCloud director path, and that merged in and went built out to what VCF is now. And that company is still running one of the largest hosted VMware estates in the UK. It's easy. You can get the right number of people, the technology partnerships, the ecosystem. And this is a big thing I talk a lot about with other people is the ecosystem exists around VMware.

You've got your Veeams, you've got the networking software, you've got security software, you've got all of the big industry alliances were all there. So you've kind of got a real easy mode way of building a private data center, private cloud, in your own data centers or in hosted data centers. You've got good access to people. And while it might not seem as the new flashy, the new shiny, it's safe. It's cost effective because you've got access to that technology base of users.

It may not answer all the questions. And this is the bit that kind of where I see that either Broadcom and Hawk, they can really fill this bit is the operating model is not 100% there in their offering. So you don't get that same level of IAM that's just integrated. You don't get the same level of resource management if you were to bring in something like S3 or third party storage. You've got a lot more hardware options, and you don't get the same level of integration as you do in a public cloud.

So you've got a real nice way that they could level that up. Or somebody else is going to come along and package up. Maybe it's an evolution of OpenStack. Maybe it's an evolution of what's in the CNCF. Someone's going to come along and package up the easy mode of here's your private data center, private cloud in a box. It's easy to operate. We've got lots of training. We've got lots of ambassador programs or influencer programs. And kind of take, there's like a real big opening there.

And I'm not sure which way it's going to go. But at the moment, the way I see it with a lot of businesses is they're going to go with the path of least resistance. And while that might mean paying some higher bills through Broadcom I kind of see that working because the alternatives are just too hard right now for anyone but the biggest businesses. And I want to focus in on this too hard piece of it because it's not just the installer.

If you follow the OpenStack journey since the beginning of when Rackspace opened it, open sourced it, circa 2012, I think. I had, I downloaded the project. I think I got through the install. And then once I got through the install, I'm like, OK, what do I have? I didn't have anything. It was not a thing. Not in the same sense after you install a Windows server with Hyper-V or VMware vSphere host with ESX or ESXi at the time. You had something that you could run VMs on.

You had built-in abstractions and processes. OpenStack at that time was not that. You had to, it was basically, you know, if you think if VMware vSphere is a Lego kit, then OpenStack is a Lego block. And you have to end up, you know, kind of designing the end solution. Most enterprises, as you mentioned, are not equipped with that. That spirit in open source, I think, remains to this day, that these are not opinionated solutions. These are building blocks that you need master Lego builders to design and build the end solution.

But the thing that, you know, that kind of bit me in the end was what I didn't realize is that these things are not, don't remain static. You don't deploy OpenStack or Kubernetes or development platform and just leave it. Can you talk about kind of that experience that you need to continue to cultivate within your customer, internal customer base when you provide them a cloud platform, whether you're talking public cloud, private cloud, or something in between? Yeah, I mean, it's actually always been this way, but it never kind of got noticed as much.

You've always had to continue to iterate and build on the platform. I remember back from my days of building FlexPods and those kind of converged infrastructure stacks, there's a huge amount of maintenance, upgrade cycles, there's improvements or just, you know, firmware updates and things like that. So there's a lot of different areas where you have to keep moving, but then there's also things that you have to add or change. Projects get retired or, you know, I mean, especially with like some of the open source stuff.

When I first kind of started in the Kubernetes space, Service Mesh was just Istio. There wasn't really much more to it than that. And Istio is still here today and it's, you know, it's probably one of the most used, but you've got a lot more options and some of them just suit other people better. Like, you know, Istio is still quite hard. And some of the others are simpler or some of them have new or a better integration or a better experience.

And even when we look at sort of the managed Kubernetes providers, sometimes they will change. They may have gone with, you know, one kind of networking interface, Flannel, and maybe some next version around that they're going to move to Calico. You've got to keep on top of this. I mean, I've just mentioned five or six products in a couple of minutes. It's hard to keep on top of all of those things. It's hard to maintain the knowledge of all of those things and keep a running system and do migrations between them.

Like running a cloud is a full-time job for a team, you know, and often a business won't have a huge incentive to, where's the business benefit to running a cloud? There's no direct tangible metrics you can bring back to say this was, you know, worth the investment. So it can become, you know, a big cost center, and it's hard to explain, measure that benefit, and give it back. Even more so when, you know, it's a bit easier when you've got developers. So when you've got your own team of developers and your internal customers are software developers and you're providing functionality back to them and you're making the developer experience better, it can be easier to explain away.

But one of the things that we've missed a lot in the modern stacks is for people that don't have so much of that, the people that just may use commercial off-the-shelf software. VMware made that very easy. You've got virtual appliances, OVAs, all those things was kind of like a bit of an easy run for off-the-shelf software. There isn't, there's some of that in the container space, but not as much. And, you know, it's harder to show value for these kind of private clouds or public clouds when you're just using commercial off-the-shelf software.

So, yeah, it's a really hard one to prove the value and keep up to date with. And the other thing, staff turnover. You can train people up. I've been working training some people up with Kubernetes recently, and they get a couple of years of good skills and then they get more offers. And so, you know, their skill set is improved in such a way that they can go to the next big project. And that can be a real hard thing as well.

Turnover and retention is difficult. Yeah, I want to respect your time. There's one last topic that I'll just riff on a little bit, and that is the in-between. So you talked about, we've talked about one extreme, CNCF, taking the box of Legos, pouring it out on the desk, building and maintaining a private cloud. Then there's the VCF, the Lego kit way. What there is is a gap. There's a I would say VCF might get you 60, 70 percent there for the private cloud.

You have to build the rest. While it's not as resource intensive as building a private cloud from scratch, you do miss some nuance. e. Tanzu, or you want more capability, that still has to be built. You still need the talent to do that. You still need the product management to do that, to maintain those bits that you install yourself. And you still have to understand VMware's roadmap or a solution like VMware. It's not just VMware. You have to replace out the solution that you bring in temporarily.

So there is a lot of thought that needs to go into private cloud. A lot of us won't have a option. Private cloud will be thrust upon us. And whether we want to build one or not, we need to know these solutions. Jason, if people wanted to find out more about kind of your insights and your ideas around open source Kubernetes, private cloud, public cloud, where can they find that? So I can be found in a few different discords. On the internet, there's the Containercraft community, CCIO community, the 90 Days of DevOps community.

benedicic, and then I kind of stick to talking on LinkedIn and maybe get a blog up and running again at some point when I get some time there. But just one last thing on that kind of, when you're talking about that middle ground and why I mentioned the Containercraft community, I think what we might see is the rise of opinionated solution stacks. So with the Containercraft community, started by Kat Morgan and a couple others, what they're doing there is putting together curated, and I'm helping test some of this out, is that curated project lists.

So they're using Talos by Cidero Labs. They're using, you know, Kubernetes. There's Open Unison. There's all these kind of curated pieces together that we see in the software development world. So I see that with opinionated software development, software engineering stacks, NestJS and things like this. So I think we might see a nice kind of middle ground of you can have the opinionated kind of reference of a Lego set, but without buying from a particular vendor. And that's kind of, I think, an interesting place to go for the future.

So you hit on a really important topic, which I want to make sure I reinforce, which is community and the importance of having a community of folks who are going down a similar path to you. And you brought up Discord. I don't hang out in any Discords, but this seems to be the place that people who have these challenges meet. So as IT executives and practitioners think about how do they solve these solutions, where are some of the places to go to have these conversations?

Yeah, I mean, so there really are. So I'm in, well, something happened. I was in a lot of Slack groups last five years or so. And a lot of those have seemed to have migrated across to Discord. I mean, even the vExpert community moved over as well. It's a little bit harder to find, I've got to admit, because it's not as easily indexed. But, you know, I have, let me see. So there's the Home Ops Discord, the NetApp Discord, the Container Craft one.

There's some for Kubernetes. A lot of tech influencers have them as well now. Yeah, Raw Code Academy. Just, there's one from the A17, A16z guys. Yeah, another one for community. So yeah, send me a link to them and I'll add it to the show notes. So folks looking to, you know, jump into a community, get started, ask questions, we'll provide some resources. If you want to learn more about the future of the group, you can find us on the road, on the web.

You will find us on the road to, we'll be at NetApp Insight, where I will also see Jason in a couple of weeks. com. com. And you can find me on X at CTO Advisor. Talk to you next CTO Advisor podcast.