VMware's Container Story - CTO Advisor 080

Keith visited the VMware campus and did a series of interviews with VMware. Those videos can found at ctodose .com . In this interview, Keith challenges the GM of VMware’s Cloud Services B/U. What is the BU, what is VMware’s container strategy, and why should VMware’s customers follow VMware’s lead into cloud-native? Subscribe iTunes | RSS

Transcript 3,531 words · about 24 min to read

Machine-generated from the episode audio and not hand-corrected, so names and technical terms may be imperfect. The audio is authoritative.

Welcome to episode 80 of the CTO Advisor Podcast. This is a replay of a video interview I did with Paul Fazon, the General Manager of VMware's Cloud Native BU. VMware has three cloud-focused BUs, the Cloud Platform BU, the Cloud Services BU, and the Cloud Native BU. Now, you may ask yourself, cloud and VMware, there's kind of the 800-pound gorilla in the room, which is the AWS service that they're offering with VMware Cloud, and thinking, what's left of the story? Well, VMware has been under attack from years ago when it comes to OpenStack, and now containers.

Containers should bypass the virtualization layer and run on bare metal directly and replace VMware. So VMware has traditionally approached this head-on with their OpenStack integration that they did earlier, and now there's a whole bunch of services around containers. Are these services something that the enterprise should take seriously, OpenStack solution, while there's some interest in the overall solution and that being OpenStack in Asia and with service providers, the container and container orchestration story has, I think, gotten lost a little bit. So I go head-to-head with Paul.

Why should enterprise CTOs pay attention to VMware story versus that with Red Hat with their OpenShift story? IBM has a solid functions-as-a-service solution in WISC. All of the cloud providers from Azure to Google to AWS all have very solid container and container orchestration stories. Why should enterprise CTOs invest resources into VMware solution, PKS? Fascinating conversation. I hope you enjoy it as much as I did in creating the content. Hey, how's it going? com with another CTO Dose. We're still here on the beautiful campuses of VMware.

Paul, you guys are going to make me really jealous as I go back to Chicago. One, we don't have nearly as much green in our office space. The campus is just beautiful. I mean, it's all the turtle passing thing, which is notoriously VMware-specific thing. So I'm joined with Paul Faison, GM of the cloud platform, cloud services, cloud native, which business? I am the general manager of the cloud native business unit here at VMware. So cloud native. We'll talk to the cloud services group in a little bit, Milan and his team.

But talk to me, what is the role of the cloud native group within VMware? Really simple. Anything to do with containers falls into my group. So how we think about supporting development teams wanting to work with containers, how we think about monitoring applications that are deployed in containers, how we think about networking solutions around containers, security solutions, whether in the kind of more traditional sense with SDN style networks, or in the future, as you start to think about services mesh in higher level networking services, all of that kind of falls into the cloud native world here at VMware.

So some of the products that fall on your group is VIC, VMware Integrated Containers. I was just at DockerCon Europe, talked to your team about the VMware's use cases in the Docker API, Docker space, PKS, which we'll get into a little bit. And is Python, is that part of your group or you guys just integrate with Python? Photon OS. I'm sorry, Photon. So Photon OS is a VMware homegrown Linux distribution. It now underpins just about all of the VMware products in our portfolio.

And it's also something that we're looking at using with other products around the Dell Technologies family. It is straightforward. It is a lightweight, very modern Linux distribution. We've got very quick patching capabilities. It allows us to control our own destiny so that when we need to hit a patch of security vulnerability, for instance, around vSphere in the distribution that it goes out on, it's quick and easy for us to do that without having to work with third parties to figure all that out.

So dogfooding a little bit. If it's a VMware OVA, then it's more likely Photon or it's on a path to become Photon. Largely speaking today, most things are. There's a few cases where there are some things that happen in the data plane, like with NSX, some of the elements of NSX aren't yet there, but they're on a path to get there. So when I think about containers, I think Docker, Kubernetes, even Mesosphere. There's a ecosystem outside of VMware. Cloud Foundry uses containers.

Cloud Foundry, CNCF. There's CoreOS, even competitors, Red Hat. But when I think of VMware and containers, the two don't meld. I'm thinking about stateful workloads that I need to vMotion stuff in and out of, consistent databases, just an operating model that there's this whole pets versus cattle. I think about, when I think about VMware, whether it's myth or reality, I think about pets. So help dismiss that. Why should people pay attention to VMware's cloud-native story? So our customers, of which there are hundreds of thousands of them out there, they live in a multifaceted world, right?

There is no, if I look at an enterprise customer today, they've got applications running on systems that were originally thought of back in the 70s and 80s, sitting alongside applications that have just been modernized that are running in containers. And our customers are looking for a common substrate, a common infrastructure service, to run all of those applications without having to reinvent the wheel each time a new abstraction gets defined. And so when you think about it, a container is a new type of virtualized workload.

You use the pets versus cattle analogy. I think there's two ways of looking at that. There's the actual workload type and the service that is actually exposed by the infrastructure, whether the infrastructure is a private cloud infrastructure or a public cloud infrastructure. I can guarantee you that our friends at Amazon, as an example, when they think about the EC2 control plane, they're using the service, millions of customers around the world. It's not a pets versus cattle discussion with them. That is a very important, crucial element in their architecture.

That's just the foundation of EC2 is the foundation of their services. So similarly, when we talk about private cloud, for which VMware is the leading player on the planet today. In the private cloud world, the private cloud control plane, which is largely grounded in vSphere, and you add NSX and vSAN or VMware Cloud Foundation overall, that is the control plane. That is our EC2 equivalent control plane for private cloud. So our customers have, they put a lot of dependencies on that to help them run their businesses.

And so the things that sit on top of that, I think you can refer to as either pets or cattle, but that control plane itself is a very important part of how they run their business. And our approach to PKS, working collaboratively with Pivotal on this, this is a shared R&D project between Pivotal and VMware, is around bringing a Kubernetes solution to the VMware Cloud Foundation install base that exists on the planet today. And to allow customers to turn the question, a lot of times customers have started down the path of, is it VMs or containers?

It's not an or question, it's an and question. Every one of our customers has application profiles going back 10, 20 years, and we'll have those application profiles around for a long time. So we need to take that and give them a continuum. So before we get started into the PKS discussion, let's talk about that initial foundation, Amor, that's built on vSphere and VMware core product suite, NSX and included. I've gotten some facts about this comment, maybe about two years ago. I said, you know what?

A container sounds like the perfect workload to run inside of a VM. Because at the end of the day, I don't care if it's bare metal, as if I'm a developer, I don't care if it's a bare metal piece of infrastructure that my container is running on. I don't care if it's a virtual machine. You have no, as long as it's friction free to the developers. As long as I, back then, just as long as I could say Docker up and pull my image and deploy my image.

Infrastructure, I don't care. I think that's bared out. When you look at Netflix, Netflix has their tightest container orchestration that they built themselves. They said, you know what? The flexibility of building a VM, I mean, taking a VM based infrastructure, in this case, EC2, and being able to carve up EC2 instances based on these smaller container instances has created a greater level of efficiency, even, and translating to some real savings for their cloud-based infrastructure. So I think there's some validity in saying, you know what?

This isn't a VM versus container conversation. This is a VM and container sort of conversation. For us, at the VMware Foundation level, how do you allow customers and their development teams, right? IT exists to serve developers. Developers exist to serve the line of business, which exists to serve customers, ultimately, and customers, right? So if you think about that food chain, our VMware Cloud Foundation has been developed and it continues to evolve to enable IT to best serve developers in a private cloud environment and expanding into a hybrid cloud environment with our VMC offering.

If I think about, there are certainly companies out there that have the deep technical expertise and the chops to build this themselves and open source some projects and make it available for others to take advantage of. But as we've seen in the past, there's a number of projects you can point to, but just because something's open source doesn't mean it is straightforward and easy for an enterprise customer to deploy and to operationalize. One of the most popular books in Kubernetes space is Kelsey Hightower's Kubernetes the Hard Way.

So let me learn how to do Kubernetes from the bolts and pieces of taking the downstream project and just deploying that. So let's talk about the competitive landscape as we move into PKS. I look at Kubernetes. There's no limit to the number of companies that's telling me that they can manage Kubernetes for me, from Docker to Red Hat to Novata. There's a ton of companies that can manage Kubernetes for me. So they can take that, put it on top of VMware vSphere's base infrastructure and manage that.

Where is VMware adding value where these other players can't? On a number of fronts. Number one, we are going to deliver, this will bear out with our customers over time, so I'm excited to let them do the talking for me as we get into this year. But first and foremost, no one is going to be able to integrate Kubernetes into vSphere as deeply as VMware can. And so I go back to that, is it an or comment or an and comment between VMs and containers?

It's an and comment. And so we're going to make it as easy on vSphere to serve up a Kubernetes cluster as you can get a VM today. And so to an IT administrator looking to service different lines of business, different development teams, to be able to have choices of these different tools on one platform is incredibly valuable. So let's talk about that from a practical level. I'm a VMware administrator. A developer has come to me and says, you know what, I want containers and I want to build a production app based on containers.

I panic because I'm thinking, you know what, I have to go out and create a Docker host. And then I have to take a Kubernetes, I have to put that inside of a Kubernetes cluster. And then I have to manage that separate from my vSphere environment, completely different landscape. But why? Because that's what the industry is telling me I have to do. Containers have to be on bare metal. So let's unpack that a little bit because it's interesting. So all of the biggest public cloud providers on the planet, their container offerings all land in VMs.

Yes. Point number one. Point number two. And I'd put vSphere's DRS, Dynamic Resource Scheduling, up against resource scheduling in any other platform on the planet right now in terms of private cloud or operating systems. It is not only the most efficient in the world, it's been designed in partnership with many of the leading x86 chip vendors on the planet to make best use of the x86 hardware that's available today. So we can take advantage of your hardware resources better than bare metal, right?

And we've got some studies out there that actually demonstrate those points. And then the third point I'd bring up, I go back to the first argument I made is that customers don't want to stand up independent silos just to deliver a new abstraction. They want their infrastructure service to support multiple abstractions. Otherwise you're reinventing compute, you're reinventing networking, you're reinventing security, you're reinventing compliance, auditing, monitoring, logging. The list goes on and on. It's absolutely absurd and insane to think real enterprise customers at scale are going to replicate all this over and over again just because an abstraction changes.

So you're saying two months down the road or two quarters down the road, they're gonna do it again for serverless and for functions? It's crazy. Most customers, what I'm seeing play out in most customers is that the initial container exploration and adoption starts with a very forward-looking group that has been given very limited resources and they have to go out and kind of figure out how to get this stood up quickly and easily in their world and make it work just for their one project.

But the next step after that is, how do I make this work for the 95% of my installation, 95% of my data centers? And that always comes back to the typical enterprise checklist of things that have to be accommodated to most adequately support their business. And so I have the conversation about bare metal with customers quite a bit. I mean, when we point out some of the things that they're gonna ultimately bump up against, it usually comes back to a little bit of a smile.

And I get it. Not quite, I told you so, but I told you so. This is not, and I told you, listen, there's virtualization, vSphere-based virtualization is better than hardware today. It's better than bare metal today because it takes such good advantage of that underlying infrastructure. I would imagine. I'm not a PKS expert, but if I was running a VMware vSphere environment, I would wanna say, I look at something like a Kubernetes and cluster management and workload placement. And I think to myself, you know what?

That sounds a little bit like, it may be a little bit less capable than DRS. When I think of DRS and automatic workload redistribution, the vast majority of container workloads are still legacy applications that have been repackaged. They're still pets. They might be in a container format. There's a couple of trends emerging. There are traditional applications that have been repackaged. And the end result is the operator around that application gets the efficiency gains of working in a containerized environment versus an operating system, which is awesome.

But then there's also the second emerging trend around ISV package software and some middleware package software. That is, you know, if you think about, I'm gonna date myself a little bit here. If you go back a little ways and you remember the traditional three-tiered application architectures, the web front end, you've got your middleware, your database on the backend and how that was all networked and firewalled together with load balancers at every layer. People are now, you know, a lot of the app customization started and containerization started with the web front end because that's what customers see.

And that's where you look at, like my favorite example is looking at Amazon's website. And as you load a product page, you can see all the different microservices running inside of that page, right? It's a really good, how I explain microservices to my mom. But beyond that, as you get deeper into the package software, the middleware, and then some of the data services on the backend, you know, they're not as, what's the word? They're not as, they require a little bit more care and feeding, right, candidly.

And so we're seeing that emerge as kind of a new class of application components that will land in PKS. And so we're taking a lot of care to work with a growing number of ISV partners to make sure that their solutions, even though they're packaging and testing on generic Kubernetes, that we do some further testing with them in a PKS environment on top of our VMware Cloud Foundation, much like VMware did from the other side with our hardware partners, with our hardware compatibility list, which is still industry-leading after 20 years of existence, is still by far industry-leading compared to any other infrastructure platform out there.

We're taking that similar approach now with ISVs in terms of certifying them through our PKS offering. And so you'll see that start to come out a lot more. So a basic question, can, let's say that I have a traditional application or even one of these newer applications, they're long running containers. They're state, the containers will run for days or months. Can DRS take that containerized application and move it to another workload as demand for a single host accelerates? Like, do I still get the functionality of something like a DRS, even though I'm running the workload in a container that PKS has managed?

We give you the, so the short answer is yes. We give you the tools to do what is best for your applications. And like I said before, I think VMware and vSphere does that better than any infrastructure compute platform on the planet. How you use that, customers are still figuring out how they want to use the tools that are available on a VMware virtualized infrastructure for their app modernization processes. A lot of times, just like with the earlier days of DRS, customers started with it turned on to, tell me what to do, but don't do it for me, right?

I forget the exact name of it. Manual or something like that, right? And over time, they gradually turn that dial up so that DRS started doing more and more for them in an automated fashion. With containers, with containerized applications, a lot of people want to take the conservative approach. Okay, let's start. What would you suggest we do? Over time, they'll dial that up. And I think that's just part of the learning process for enterprise customers as they're going through how to best make use of the technologies that are now available in our private cloud environment.

So Paul, I really enjoyed the conversation. Are you guys going to be at Dell Technologies World in a few months? We are going to be all over the place over the next few months. We're going to be at Dell Technologies World. There's a number of container-related shows that we're doing. There's a shout out to the open source community. We're going to open source leadership summit up in Sonoma next week. So we'll be up there. So there's a lot of stuff that we're going to be doing over the next few weeks, next few months, excuse me.

But you're going to see us showing up in a lot of places. So Paul, with that, I'd like to thank you for joining the CTO Dose. I'd love to actually talk about community and a bunch of other aspects of what it means for a large enterprise service provider and technology company, et cetera, such as VMware to get involved in something as community driven it is as Kubernetes. That by itself could probably be a whole other session, but I really appreciate you talking and clearing up some of the myths and truths about PKS.

You want to find out more about VMware cloud native offerings. I'm assuming there's a website. There is. I'll get you the, we'll get you the link. You can put it in the show notes. com. I think under products and BU's, you can find the cloud native group. Until then, talk to you next CTO Dose. Stay tuned, more coverage from VMware's campus where we're going to talk to the cloud services group, understand the difference between the cloud native group, cloud services, and what that has to offer enterprise VMware customers.

Talk to you next CTO Dose. com, me on Twitter, at CTO Advisor.