EP 280: DevSecOps & OpenShift w Kirsten Newcomer, Red Hat
In this DevOps Chat we chat with Kirsten Newcomer,Senior Principal Product Manager, Red Hat. It is a great discussion on the state of DevSecOps and how the Red Hat Open Shift team is trying to make it easier for devs, DevOps and cyber folks to work together to create more secure applications.
Transcript
com, Container Journal, Security Boulevard. You're listening to another DevOps chat. Welcome.
And I'd like to welcome to our DevOps chat Kirsten Newcomer of RedHat. Kirsten, welcome. Thank you, Alan.
Great to be here. So I'm Kirsten Newcomer. As you said, RedHat, my focus at RedHat is DevSecOps for cloud native applications.
Been working at RedHat for about four years, five years now. It's really kind of fun. I've managed to leverage kind of my all sorts of different elements of my background over the years.
I spent time at Rational Software, nine years working on developer tools, then some. Yeah, some time with BMC Blade Logic on the operations side of the world. Seven years at blackbox software focusing on solutions that help companies manage vulnerabilities and open source software.
And that led to the move to RedHat, where I get to focus on open shift security and dev check ups and sort of everything comes together. So Dev really does. I mean, definitely following your career, I think I know just about all of those companies intimately and with a lot of people.
I'm sure you never a lot of people would comment that we worked with. I bet you do. It's funny.
You see, you were rational, left, rational only to return to IBM. And so that it's you know, it's the circle of life right there. Big circle of life.
Yeah. So so I said, look, I did set copses, of course, something near and dear to us. We put on every year at the RSA conference our Deb sic ops.
Days or DevOps, I got DevOps connect up sick upstate's. We actually have the virtual event of that live on Thursday. I think it's the twenty six, my eyes fixed.
So, you know, it's it's it's something quite frankly, this whole security thing is the reason I got to New DevOps is I thought. What a great opportunity for security to to secure a law, the original said. Absolutely.
To do it. You know, when we look at, you know, the dad said Gob's in the DevOps world. Here's the we you can't help.
You must take notice of the impact that could Bernardes and the old crowd negative the movement has had on this. And I agree absolutely no big changes. Yeah.
And, you know, and it's really at the core of so much of what is being done right now from a from infrastructure point of view. And oftentimes I don't move people like everything else. Right.
I remember when the cloud came down and we move from client server and all this security. There's always that lag. Right.
Oh, yeah. We got to do security with this. And we had a little bit of that with Google daddies, I think.
Well, I think that's fair. Yeah. People were rushing to do Cuber lattes and an experiment with it.
Deploy it. And then someone started saying, wait a second, what about what about the security here? What about complaints?
What about this or not? And now I will tell you and I'm interested in your opinion. I thought the lag time was much shorter this time than what we've seen in the past.
Oh, I absolutely think so. And I think it's really interesting. A couple of things that that I've observed.
One is that I really think containers and Cuban artists have created a terrific opportunity to shift security left. And and I'll kind of be more explicit about that in a couple ways. But I fact have worked with a chief of cyber defense in the public sector who believes in evangel, ISIS.
That container's improve security. And I've stolen his line because I just actually think that that's really valid because of the changes in the model. You know, where the OS dependencies and the runtime, everything's kind of packaged together and you have that immutable container image that you're always deploying from.
You really can manage things in a new way. And not every team is ready for this. And not every team, not every security vendor is ready for this either.
So. So I think the opportunity has been twofold. One is to kind of adjust the thinking about security so that it no longer becomes something that happens at the end.
But that's that's still a process. That's still a lot of work. And the other thing is the security tooling space itself has historically been pretty siloed.
Right. There's been, you know, the OS layer security, the network layer. There's been kind of, you know, my seam in my soc that I'm that I'm working with and my cert management and secret my vaults.
And in none of them really were designed to work with a level of automation that Cuban artists and containers enable, which led to this really interesting opening for smaller companies. So a lot of startups that now have been around for a little while actually to start breaking down those silos and delivering security capabilities in a new way. That kind of really do fit the death sitcom's model because you get kind of one vendor bringing a set of capabilities that ranges from C ICD integration to runtime security to network security.
Really fascinating space to see how it's been evolving. It really has. The other thing that I will tell you here is that I was again encouraged by was when I first started seeing people talk about security for containers and Cuba Nettie's.
It really was like, let me scan your container for your abilities, right? And I'm thinking to myself, I don't care whether my code is in a container or in a hypervisor or on bare metal. A vulnerability scale is a vulnerability scale.
There's got to be more to this than just a more vulnerability skin. Absolutely. And that's that's, I think, where, as you mentioned early, that, you know, Cuber Natus really has come a long way in that space.
So there are things like if we think about so so absolutely vulnerability scans are fundamental and kind of people always understood those. They tend to have historically, they've happened a little too late in the lifecycle, making challenges for the app dev team and such, where we're seeing that shift left a lot. But then there's all these other range of things that you should be doing and can be doing to build security in to the platform.
And so when we saw, you know, pod security policies and Cuban artists, for example, that's a way that the coup bad men can take advantage of the Linux features that enable container isolation at the Cooper Netta Slayer and enforce things like ensure that a container doesn't run with unnecessary privileges. And so we are seeing more capabilities now that's still beefed up. So the community still has some work to do there.
But as you say, we're seeing more emphasis. And, you know, the open source Cuban at a security audit sponsored by the SNCF is a great example of that. Oh, absolutely.
And look, CSC has done yeoman's work here. They're really, really done a nice job with with the whole human rights project. So we good security.
You know, one of the one of the reasons we did a webinar yesterday, for instance, and was on the defrayed different cloud providers versions of Cuba, Nettie's garments. And we broadcast we had seven hundred and something people some great webinar, lot of great questions even on the YouTube afterwards. What a great questions.
S. or Sure. Gcp or whatever and setting up my cubie environment.
May not be the best thing for me because I grab to get one of the package distributions, if you will, or or a more complete solution, of which Cuban Nettie's is a piece like an open ship. Some others were mentioned ranter and shared, but open ship was the most popular one. And I think one of the reasons is people.
People want to know that security has been kind of built into it. Yeah. Beyond just the Q release, whether it's were bring four or five, would have you wondering, you know, what else has been wrapped around that?
Just say yes. Absolutely. And that's been a big focus for us at RedHat.
Really from the beginning, you know, an enterprise solution. And this is a place where so we've talked about changes in the security tooling that needed to be made to adjust to the technology. But by and large, the principles still apply.
You know, you still need audit logs, right? You still need to log data from the cluster itself. You need log data from the applications.
You need monitoring tools. And so and you need to think about host OS security as well. And so we've kind of really looked at the stack as a as kind of spanning all of those things.
And we want to make it as easy as possible to manage that solution as a as a solution. Right. And so that if you and plenty of folks do this, you know, and and get value from it.
But if you're in a situation where you can forward afford to kind of do a deal, DIY coop Burnetts, an ad in a logging stack and add in, you know, kind of all the different pieces that you really need for the enterprise solution, then you have to maintain them each separately in your maintaining the host OS separately as well. And so we've really focused recently, and especially with open shift for on automating everything which includes the the host operating system. So real core OS fedora choros available.
You know, it's an open source project. It's a container optimized operating system that we manage as part of the full platform. Makes it much easier to apply OS updates across your cluster.
You can do that in a way that has zero downtime for your well behaving apps. You can take a node out of out of service in the way you would. You know that Cuban artist manages it.
Update that with a patch to open shift or its components or the operating system itself. Put it back in service. And so kind of a combination of, you know, looking at the whole stack holistically, what is an enterprise need in order to ensure that they have a secure environment, a stable environment, a highly available environment, and making sure that we kind of leverage the terrific declarative and automation capabilities of Cooper, not as kind of throughout the whole stack.
Absolutely. I didn't realize until you decided to kind of put together all the pieces of what you guys are doing. It's pretty it's pretty amazing.
It's really cool. And one of it and one of the other fun things that we get to do is we actually so back to if we think about the host OS layer for a bit. Right.
If you need to scale your clusters, that means adding a new host and you've got the work involved to be sure that you, you know, deploy that infrastructure and that you secure that infrastructure according to your standards. And then you put Cooper Natus on top of it and, you know, add it to the cluster and you're ready to put workloads on it. And we're using the concept of Cuban artist operators to automate the components of open shift, including the host OS.
So we have a machine config operator. So if you're deploying open shift in a cloud, in a cloud where you can automate the addition of infrastructure easily, you can use the machine machine, config operator and the declarative nature of of of Cuban s. Right.
It's a container optimized OS. It's delivered primarily as as container images. The userspace is read only you've got that declaration of what a host should look like.
And you can just use the machine can fake operator to spin up new hosts and add them to your cluster. Excellent. You know, we would be.
Derelict in your duties? You guys said we didn't mention the whole Konbit 19. That's affected guess.
Yeah. In my mind, so are you, sir. First of all, I don't think a lot of what we're seeing right now and its effects are necessarily three week or six week or, you know, these things.
A lot of this stuff's going to stick. Yeah, I think one of the things that they're going to stick are people going to want more automation? Right, Absolutely.
And it's in their operations, in their infrastructure. And, you know, automation from a security point of is is kind of a double edged sword, right? We at least we know with from an oil, when things are automated from a screen point of view, we know we think we know exactly what's going to happen.
And so we can we can plan around that. On the other hand. Security people tend to get a little would they come out of Veracode.
dead ends here? What do you think? Yeah.
I know I agree with you. And I think one of the things that one of the ways that Cuban artists is kind of pushing the boundaries with security teams. So so, you know, and I talk to a lot of different security teams over time.
So it's kind of like, you know, they they're they're a little bit more comfortable with the idea of DevOps for the application layer at this point. Right. For those containerized apps that are going to be deployed, it's like, OK, they they they kind of have an idea of.
Yep, security, static analysis tools, integrated vulnerability scanners integrated. There's some cool new stuff coming out about, you know, that I'm seeing on the market where they're tools that are starting to evaluate the configures and the Docker files, too. That's really great.
But and then as we continue to move into the Ops space, right. With Cuban and US and the SDM, which is required for any Cuban artist cluster, and now we have service MASH added into the mix or SVO for for, you know, micro surface based communications that network security teams are uncomfortable with. Who's going to manage network policies at the Cuban artist layer.
And now I've got ServiceMaster SVO policies as well. And and who's responsible for those? And in the end, it's really about visibility.
So if we circle back to automation, we're really looking at infrastructure as code. You know, a good ops model that applies again to the to the Cuban atest layer to the configuration of the cube cluster as well. And we need to put in place you need the automation to get the best results, but you need to do it in a way that gives the security team visibility into the kinds of things they're used to seeing.
And so I think this is another way where we're starting to shift lefton in new ways. I'm also seeing solutions that help automatically generate network policies based on evaluating, you know, an environment or or a cert or automatic, you know, generating service mesh policies based on on evaluating the config for the apps. But all of that, you know, the network security guys aren't necessarily going to log into the cluster to look at that.
So how did they get the view they need to get and how do they help the app dev teams understand that that whole risk management and their security perspective. And so this is where it's not just about tools. It's about people and processes.
Right. And I think there's there's so much richness here, but you're absolutely right on it. You know, we can't do it without automation.
And so we're gonna have to help these people become comfortable with this shift while ensuring that they get the visibility. They need to know that things are being done in a way that meets their risk guidelines, their regulatory requirements and the security posture. They won't.
So to me, one of the fundamental things with with Deb Sack after one of the fundamental shifts in deficit jobs is, first of all, security people recognizing that they are not the only ones who care about security. Believe it or not, the developers and the DevOps folks, they do care about security, not be security trained people. They care about security.
I think the second thing with that is. Developer people have to rely on the DevOps teams have to realize that the security people are in there just to be the roadblock. And right there always be the people who say no.
Right. And what we're. So this has nothing to do with technology.
This is a people to people issue. Absolutely. And.
I think we're making real progress in that. And I and as a result, what we're seeing is security people paying for and improving security tools. That developers in DevOps teams are using on the Cougar Nettie's platform.
Yes. You know, that's the kind of the platform of choice now. And that to me, that's what keeps me optimistic about this.
Yeah, no, I'd agree. And also when we think about, you know, the broader landscape. I mean, there is the security threats are just ever evolving, ever changing.
And there aren't enough security trained professionals to go around. Right. There aren't enough cybersecurity folks, et cetera.
And so we have to figure out how do we help teams scale and collaboration is the way to do that. And you're right. I see the same thing you do, right, that the security team is approving those tools that are contained or native coop native tools that did help to ensure and in some ways think I don't mean this in a negative way, but in some ways they they kind of are pushed into that because the traditional tools that used to be used kind of at the back end of things aren't effective in a container and Cooper at its world.
And so they really do have to go with this shift that we're seeing in the vendor landscape. And it just opens up this terrific opportunity, though, for that collaboration and that shared knowledge, which, you know, is an adjustment for for people sometimes. Yeah.
Great. Great. Chris Kirschling, when we first started, I said the time goes really quick.
I'm only going to keep here 15 minutes. Well, that was 21 minutes. Ok.
Yeah, we did it. All right. We're going to have to play a wrap on this one.
Maybe we'll have you come back another time. And we do plan in you the conversation. All right.
Good. Great. It was great fun.
Thank you so much, Alan. Thank you. All right.
Here's Kirsten Newcomer, Red Hat. com Container Journal, Security Boulevard. You just listen to another DevOps chat stay well, everyone.