Kubernetes Maturity – Cloud Native Now Podcast EP10
Mike and Paul Nashawaty, practice lead for application development for the Futurum Group, dive into the latest update to Kubernetes before moving on to what platforms are best for running cloud-native applications. Then the discussion shifts to Broadcom’s Tanzu strategy, the state of Kubernetes cybersecurity and the rise of WebAssembly (Wasm).
Transcript
Hey folks, welcome back to the Cloud Native Now podcast. We've taken a little bit about hiatus while we get some new players involved, and my new partner is Paul Nadi from the FU Group. And if you've been under a rock that FU tour and group acquired Techstrong Group, which is the pairing company for Cloud native now.
So we're gonna be working this podcast together from here on out. All welcome. Thank you Micah.
Glad to be here. It's exciting times. I'm really excited about the acquisition and about what we're doing, and mainly just really excited about the space.
It's really, really, uh, growing and, and, uh, you know, what's happening in the space. Totally. So let's just jump in.
30, and there's a lot of new capabilities in there. The ones that kinda leaped out at me were in the alpha side of it where they were talking about the ability to, uh, have read only data and they also had an ability to, uh, have more control over how you route traffic from and to an end point from the Kubernetes cluster. And I scratched my head a little bit and I applaud them for these capabilities, but I wonder from a seasoned IT perspective, if you're kind of like looking at that going, you know, I kind of thought we would've had these capabilities by now.
And there's one of these kind of, you know, moments where the senior, your IT people are probably going well, bless their little hearts. They figured that out. Yeah.
And Mike, you know, it's, it's really interesting. You would think that's some of the IT maturity or Kubernetes is really kind of already adopting some of the, the fundamentals that you would think that were part of the, the platform and, and what's happening with cloud native and, and, and cloud native a adoption for those applications. Really, um, you know, really kind of need some of those, those, uh, new features.
Like, so when, so, but what I do like about this release is there is, you know, parameters that allow for dynamic resource allocation. There's, there's, uh, node memory swapping that really has that support and also username spaces and pods, right? That's a big factor when it comes to management, especially across distributed cloud environments, right?
When you look at distributed cloud environments and having to do the, the, uh, efficiencies and security across the cluster is important to have that as well. What is your sense of where are enterprises on this journey with, I mean, I've talked to some folks and they're still running clusters as far back as Kubernetes one point 12, and, um, some folks are calling for more of a long-term release edition of Kubernetes that they can maybe stabilize on because they're not fully wanted to. The whole DevOps motion where they're only gonna be three releases behind.
And I think a lot of folks are hesitant to touch a cluster because they don't know what APIs are deprecated from one to the other, and they don't know what will break. Yeah, it's a great point. I mean, I think the thing that we have to take into consideration here is what we see in organizations in our research, we see that skill gap is a major challenge, right?
In developing these new applications is probably top of mind for not probably, but according to our research, we see it is top of mind to CIOs. They need to modernize, right? The, the, the focus on modernization and there's such a backlog of, of, uh, heritage applications that either need to be refactored or frankly just maybe even just encapsulated into a, a VM to move to the cloud, right?
So there's a lot of kind of areas, but to your point of, you know, deprecated features and, and, and, you know, API calls that may or may not be there and such, then the challenge with that not being current is because this is such an emerging, uh, rapidly emerging en environment, um, adding things like, you know, resource base pools or autoscaling and, and, and, you know, and and common expression languages. Those are nice features, right? Great features for those outpatient that need it.
But really what's more important is when it comes to efficiencies and secure security is key, right? If you're not, um, if you're not updated to the latest version and you don't have to, you may have, uh, introduce a security call, then you may not even know. And that's a problem with those bots and customers.
So it's important to stay up date it, There's a lot of debate about when to use Kubernetes these days. And, um, it was a subject of discussion over at the, uh, recent Google Cloud next conference. And part of the issue was there are two ways of going after this.
There are basic container services that I can use to deploy my application that are more accessible to your average developer. And there is no Kubernetes, and Google has one, and I'm pretty, I think Amazon has one as well. Um, or I can use Kubernetes, which is a little more complex and seems to require the developer to know more about what the underlying infrastructure is about.
Are we getting better at sorting out which platform to use? When for what? It's a great question.
You know, I mean, I had the same discussion with Bobby Allen, right? He's, uh, he's responsible for the, the, uh, product manager at Google Cloud. And, you know, one of the main focus points, um, he and Richard were all talking about the fact that there needs to be a simplification process to building these applications, right?
To, to really accelerate development teams to move forward and providing a, a platform, uh, you know, being out at that event, it was, it was huge, right? There was 30,000 plus people there, there was a lot of, uh, interest. So that just shows me that there's a lot of, uh, interest in learning my interest in understanding how to take their existing organizations to the next level, where they're going and where are they hard of modernizing.
But I will, I will say that, you know, according to our research, what we found is in our latest, just out this week, so this is new, new data this year, this week, um, and our latest observability study, we see that 93% of organizations are running on two or more clouds, right? And 93%, um, sounds like a lot, but this is production applications running on two more clouds. So if they're doing this, so, you know, what, what I was talking to Bobby about and and Richard about was the fact that, does Google provide, uh, a reason to go with native functionality exclusively?
Or is it really more looking at dis across these distributed cloud environments and harmonizing the deployment across these environments to make it more ease of use across these multiple, uh, ecosystems, right? So that same study, we were finding that 20% of respondents indicated that application portability was critical to their arrive, and 67% said it was very important. So that in my mind is saying, if you're delivering on Google, and if Google has made, uh, it easier to deploy and you can get an enhancement of native functionality, then by all means go for it, right?
And do it. But if you're looking at an ecosystem where you have multiple clouds, uh, you know, our last year's data, we saw that, uh, 65% of organizations were not four more clouds. So they're running on four or more clouds, and you have to develop in each one of those different hyperscalers.
Um, that means you have to have developer skillset to do that. And if you have that developer or skillset in in house to do that, that's a unicorn. You pay them what they, what, whatever they need because you'll never find them again.
But, um, but then there's other, other approaches. So do you go with, uh, I don't know, in open, uh, in an OpenShift, or do you go to a tan zu? Do you go to one of these types of platforms to harm it?
Us? There still are options, and you just have to look at the best path for your business. All right, well, we'll come back to Tan Zu in a minute, but I wanna ask you a little bit more about this observability study, because we've talked about that topic on this show in the past, and it seems like it's a slow role.
A lot of folks are, um, still relying on monitoring tools that, you know, just basically let them track a set of predefined metrics. And when I talk to folks about observability, they kind of get the fact that the environments are becoming more complex and they need something more. But, uh, they also look at me and go, this stuff is great, but I'll be honest, I have no idea what questions to ask this thing.
Yeah, it's, it's a fair point. I mean, when I look at the bell curve of observability practices within organizations over the last three years I've been doing trending data across the observability market and, and the challenges the states has had. And, and our global study this year, we have 848 respondents globally.
It's, it's a great study. It has a lot of data asking specifics about mature, right? Asking specifics about what tools people are using and why they're doing those, using those tools.
But to answer your question, I think that the, there's every step of the stage, like if you look at the, if you look at the curve, right? There's the, the outliers on the right, probably a small percentage are fully mature, right? And fully get what an observability practice meets their organization.
And then there's a large percentage on the left, and I wouldn't even call it out wires, but there's a large percent on the left that are kind of on that emerging education monitoring, alerting, understanding what's going on in the environment. But then you get that bell in the middle that, that, that get bridge into the tracing and, and, and understanding, um, the logs and then taking actionable insights. Um, but then, you know, that's the piece that, uh, many organizations are looking to get to in that maturity curve.
And then according to our research, we're seeing that, um, that's where the, the trending is going. So over the last three years, we've seen that trending, moving upwards towards that, that bell in the middle, where the people are using that, uh, full stack, full stack observability solutions in a, in a platform approach versus individual tools. Because the individual tools not only increases your TCO, but it also increases your complexity.
And previously what I just said, skill gap is a major issue. Well, Speaking of that skills, Gavin, we were gonna talk about Tan Z and Broadcom and the VMware saga that goes on there. But if you look at tanz, what they seem to be saying is they wanna unify what we're kind of calling platform engineering and also provide a platform that makes it easier for developers to build and deploy these cloud native applications.
And when I talk to the developer community, it kind of goes like, this is a small handful of full stack developers who can really manage to work with Kubernetes. And then they seem to have spent the last few years convincing IT operations teams to deploy it, who seem to like it now because it gives them a centralized platform and a common set of APIs. But then it turns out the rest of the developer community seems to be dragging their heels on this because it's just too hard for them to work with.
And I hear VMware and Red Hat and all these other folks promising that they have a better app dev environment, but I'm not seeing like everybody rush into it. Yeah, and it's a great point. Uh, you know, I think part of the challenge is, is there's a, like any, any solution Tan Zu fell into this, uh, scenario.
They had to be, they, there was two, two things that happened. One, as they were growing the platform, they were very broad in their kind of approach, but then they were also at the same time, very methodical about, Hey, we wanna focus on Sprint, we wanna focus on spring apps, right? And, and make sure that those, that's the focus areas.
So, but where the developers were not adopting, uh, you know, the platforms, this is where, you know, I think that if there was a, a broader approach to other application platforms or, you know, just different development languages, there may have been more adoption of tan Zu. Um, I, I do think that Broadcom acquisition and, uh, VMware and, and Tan Zu, and specifically, I'm not gonna go into all those other details, but one specifically on Tan Zu, one of the things that developers do like is flexibility and choice. Um, when we look at what recently occurred with, with Broadcom, the deprecation of 50 plus or 54 different products within Teton Zu platform, they, they took away, uh, or I should say the VMware platform, they took away a lot of that flexibility, right?
But they said, well, that, but in order to get it, you have to buy, you know, the platform, right? And, and I can appreciate that, but sometimes that breaks the model of what a developer's looking do. Um, I, I, I had the, uh, pleasure of speaking with Ragu before he, uh, moved on.
And, you know, one of the things that, uh, we talked about was the context of providing developers with a bag of bits, right? You don't wanna provide bag of bits to developers because they just don't know what to do with it once, frankly, it's just not useful. But also providing them a full blown platform doesn't exactly give the flexibility that they may need.
So I understand it from the Broadcom perspective. I do, I I think that it makes a lot of sense to simplify the, the sales notion, simplify the user experience and make it easier for the, for the customers to absorb the products. But you can't take away that functionality that they, that they once had and the platform only to make it simpler or to deploy.
And I think there's a lot of work to be done there, because otherwise it's the platform engineering team shows up and says, this is our platform, and now shall write to this thing. And the developers look at them and just shake their head and go, I think I got something else I need to do. So we'll see what happens, but we will, Yeah, for sure.
Work, Work will be done there. Um, I'd also like to jump into security. And this week we saw a couple of things where, um, TTR is making it easier to do authentication in, uh, Kubernetes.
And, um, I don't know if you saw Red Hat has a bunch of new tools this week talk aimed at developers to, um, make it easier for them to build more secure applications. Do you think security was an afterthought in Kubernetes? And is that situation getting better?
Yeah, I mean, security is obvi obviously. Uh, you know, a way that you have to go slower to go faster, right? If you, um, don't, uh, have a secure solution, you just compromise your entire organ organization.
So with regards to, uh, you know, the tetra kind of announcement and utilizing, uh, Istio with Service Match for ways to deploy and manage, um, I, you know, I, I think that the Istio kind of deployment, um, in, in Kubernetes secrets, you know, uh, deployment really helps with providing a, a, a more secure, uh, way to dynamically manage the allocation authentication, really without having to write too many, too much more code, right? So that's a plus. Um, the question is, is do you wanna add sidecars to your environment?
So do you want to have this kind of, uh, way or approach I do, like, um, is the's ambient approach to, to doing this kind of a more kind of collection of response. So you can have that cross, uh, east west traffic that way and have it secure with the ambient approach. But I think that, um, you know, obviously having, um, the, the security elements within your application is critical to the business success.
You, you can't launch a new application and go, okay, it's full of security holes and it shuts down your business. That's just not acceptable. I think different when, uh, Istio filing gains traction.
I think 90% of those folks are gonna be running the ambient version when all is said and done. 'cause it seems like it's a lot lighter and a lot easier for developers to wrap their heads around. I agree.
I mean, I think it's, uh, it's, and I think I would say that Istio and, uh, all the vendors that support Istio, uh, you know, that, that, uh, put solutions to market are definitely looking at that, uh, that approach. All right. Last topic that I want to get to is wasm web assembly.
We saw Cosmo, again, was talking about how they're gonna enable Wasm on Kubernetes. And I get some folks out there who, you know, are saying, wasm will replace containers. This will be the thing that will, uh, make it more portable, shall we say, because everything will run naturally on either Windows or Linux or wherever else you may care to run the thing.
And that seemed like a lot of promise. I seem to remember hearing this for the first time 30 years ago, when some Java guys who were hanging around talking about, um, right, once why anywhere, right? Um, is, wasn't for real in your mind, or is it still in the realm of interesting in computer science?
Oh, for sure. Well, this is, so I'm glad you saved the, the best topic for last, in my opinion. 'cause I love was, I love, I could talk all bit on this, um, but you know, cosm Mon is, is definitely one of the companies out there that is kind of leading a charge around this, right?
Whether it's Taylor Thomas or Liam Randall that it kind of like, I've, I've had many conversations with Liam about, you know, the vision of where they're going, what they're doing, and the adoption curve. You know, I'll tell you that, like from a wasm perspective, um, you know, I've been writing on wasm for a number of years, probably about three, four years now, I've been writing a wza, right? And when it, in 2000, in 2022, you know, it was like, okay, this is kind of cute.
It does its thing, it's great for like Python and go applications good, right? But in 2023 was a breakthrough year for wza, right? net applications.
It added multi-threading. So now you're getting into like real applications, not just, not that Go and Python weren't real applications, but it's, the use cases are now much broader. And, you know, to answer your question, Mike, when we, when we look at, uh, I was at KU Con, uh, in Paris a couple weeks back, and you know, when I think about the, the keynote, right?
And companies like Ion were out there, right? Talking about laws and what's going on, but that's all well, and again, when vendors are talking about, you know, what they're doing, right? But then you get end users at the keynote at Kon talking about the, the advantages.
So, um, uh, Zeiss a manufacturing organization, it talked about 50% performance gains by using was, um, that it was impressive. That's a real use case. Like now you take what would, I would say, maybe, maybe an academic exercise to a reality of a use case that's, that is monetized, right?
That now you can take that and say, okay, this is really more than just, uh, something that's running as an incubator project in the CNCF or as a, you know, a sandbox where it's actually a real project in, in production in these organizations. And when we think of wasa, I, I like to talk about my as as, as my, you know, practice lead for app dev. I talk about the story of past, present, and future when we talked about applications, right?
So you have heritage applications, you have containerized and microservices applications, and then future I to think about WSO and I think of serverless and where that's going. And you made a comment, Mike, about does wza take the place of containers? Does WSO take the place of microservice and Kubernetes?
And I would say it like this, there's, I I, again, I I I'm gonna mention skill gap, right? There's a skill gap for organizations to refactor from the heritage applications to today's state of containerization. That skill gap of either a learning, um, container, container and microservices architectures or learning was in order to a web assembly in order to get to where they need to go is a, is a question like, do you, uh, invest in learning web assembly?
Because here's why. There's an advantage of use of web assembly if you're building applications. And as a developer, we know, um, that there is two to three times more applications being created today than just a few years ago with a fraction of the resources.
You just can't throw any more hands at the crawl. So using web assembly, all you need to focus on for the application development is the 10% of business logic, the 90% of the application, you don't need to worry, right? The other big factor is you don't need to recompile wasm applications, um, based on the underlying technology.
So if you think about was I'm on the factory floors or wasm in the, in the edge or edge locations, if you have, you know, edge locations that are IOT devices or, um, on processors or Intel or a MD, you don't have to recompile those applications to work at those locations. You could just use wasm and it, and it allows, you have modernized applications. Now, I will add one piece to it.
Kubernetes plays a factor here. You still will lead some way of orchestrating those cloud native applications across the ecosystem. That's when Kubernetes comes into play.
So Kubernetes and Wasm kind of go together. Containerization, microservices is the present state. That's where organizations are looking at.
But definitely it's a contender for future technology stacks. We shall see, when I look in at some of those wasm projects that are still in early stages, some of them smell like orchestration engines for wasm. So we'll see, uh, what's gonna happen here long term, because I mean, honestly, if you were gonna build an orchestration engine for Wasm as a brand new thing, would you use Kubernetes as the model for it, or would you say, yeah, maybe that was a cannon trying to kill a fly?
It's a good point. It's a really good point. I mean, what we're seeing in our research today, 39% of organizations are looking and using Lawson with production applications.
So that's a, that's a pretty good statement. And, and we will see. 'cause I mean, I think you're right.
I if, if they're blending today with what they already have in their ecosystems, that they already have Kubernetes, that makes sense. If they don't have Kubernetes, why put Kubernetes in if you don't need it? So it's a good point.
We will wait to see how it all comes together. Hey, Paul, I thoroughly enjoyed this conversation. It's great to have you on the team, and I'm looking forward to doing this every week.
Likewise. Thank you very much. All right.
And thank you all for listening or watching, depending on your mode of, uh, content, medium of the day, whichever one you're favoring of the moment. com and we'll get on the case. Until then, we'll talk to you next time.
