Exploring Kubernetes, WebAssembly and Cloud-Native Modernization – EP14
A Narrative on Cloud Native Trends and DevSecOps The cloud-native landscape is evolving rapidly, driven by technological advancements and changing business needs. As evidenced by the upcoming Kubecon + CloudNativeCon NA event, there’s a growing interest in technologies like WebAssembly (Wasm) and Kubernetes.
Wasm, once primarily confined to the browser, is making significant inroads into server-side applications. This trend is underscored by the fact that nearly 40% of organizations are already using Wasm, and this number is expected to increase further in the coming years.
Meanwhile, cloud adoption continues to accelerate. Organizations are increasingly leveraging multiple cloud providers to enhance flexibility and resilience. A significant majority (94%) now use at least two clouds for production applications, and over two-thirds (65%) employ four or more.
Kubernetes has emerged as a pivotal platform for DevOps and platform engineering. Its ability to streamline application deployment and management is driving its popularity. However, there’s a notable gap between organizations’ desire for frequent releases and their current capabilities. Only a small percentage (8%) of organizations are able to release code hourly, while a much larger proportion (24%) aspire to achieve this level of agility.
The growing adoption of CI/CD pipelines is another key trend. The integration of DevSecOps practices into these pipelines is essential to ensure application security throughout the development lifecycle. While CI testing was relatively uncommon just a few years ago, its adoption has surged, reflecting a growing emphasis on automation and AI-driven security.
Transcript
Hello, and welcome to this episode of DevOps Dialogues. My name is Paul Nash. I'm the practice lead for the app dev practice at the Futurum Group, and I'm joined by Mitch today.
Mitch, wanna introduce yourself? Hey, happy to be here with you, Paul, on DevOps di dialogue. I'm Mitch Ashley.
I'm a Chief Technology advisor with Futurum Group, working with Paul, and, you know, the app dev, DevOps, and cybersecurity space. And, uh, also come from the tech strong world, uh, through that acquisition where I'm, uh, CTO as well. So, good to be here, man.
Yeah, great to have you. I mean, this is a, a really exciting time and I love to have you as my partner in crime in this, in this journey that we're on with, uh, with regards to DevOps and, and platform engineering and DevSecOps and all the fun stuff that goes along with it. Uh, you know, we have this event coming up that's kind of focused around is kuka, that's small event.
I think you've heard of it, uh, once or twice, but It's been in all the papers. Yeah, I remember that. Yeah, they say, But, you know, it's, uh, it's really exciting to me because, you know, uh, there's a lot happening in the space.
I know that there's a lot of transition with the big vendors out there. Also, those smaller vendors are coming up. The emerging vendors are really kind of taking, you know, bites out of the market.
Right. Um, you know, couple of things that really excite me is, is, you know, like Wasm and Cloud Native, what's happening in Cloud native, uh, talking about the Kubernetes platforms, how that's helping with DevOps, platform engineering, and then of course, DevSecOps is always, always a talk of interest. But like, let's, let's start with talking about in the context of what we expect to see out of the show.
It's only a few, it's a few weeks away, right? It's like, it's, it's, you know, coming up. But I mean, I really get excited about it.
We're talking lot of pre briefs around this. What are your thoughts on, you know, on was web assembly? Well, uh, let me, uh, just add one, one perspective too on it.
You know, um, it's become a show that used to be just about primarily Kubernetes, and now it's really cloud, cloud native applications, app dev, you know, data, all parts of it, right? Much more a practitioner show. And to your point about asking about Wasm, you know, the, it's got a lot of interest, um, especially at the edge of the network.
And that ties right in with yes, we thinking we're gonna be doing more AI at the edge. Yes. The edge is not just smartphones and, and, and computers.
It's kiosks and point of sale of devices and, you know, apps that are running in grocery stores and doctor offices and hospitals and everything. So was Wasm is exciting, you know, as a delivery platform for operating or operational platform for running applications. Um, and, uh, it, it's, it's kind of fun to see it evolving along with the edge and applications, uh, use cases for it.
So, you know, I know you and I have been talking to companies like Fairmont, Fairmont and others. Fer. I always say that wrong.
Um, and others that are in this space. Um, so I know, what do you think? What's happening in Woz and what are we gonna see maybe?
Yeah, I mean, I, I have of course my, my opinions, but I mean, I'm, I'm an analyst. I go back to data, right? I look at data and I look at it, you know, recent study I ran, uh, we were asking about that.
I, I talk about past, present, and future with the monetization strategy of applications. And we were asking about walls, and we were seeing how 39% of respondents indicated that they're actively using web assembly today, uh, as part of the use case, which is surprising to me. And they said over the next two years, we saw that number jump up to 42%.
Now, I think it's interesting because in 2022, you know, I, I was having conversations with Ferion, Matt Butcher over there, and, and Liam met Cosmo and, and Liam Randall and, and, and Scott Johnson at Docker. And where do I have these conversations, right? How this, this, hey, this quo thing.
Is it cool? It's like, yeah, it's kind of exploratory. It's, it's happening.
2023, in my opinion, was really the pivot point for wasm, right? It really helped drive, uh, the adoption. And, and really why was because they wasm added multi-threaded support as well as dotnet support.
Um, prior to that, the use cases was like Python and, and bi bi applications, and it was really good for processing. But now with the adoption of T net and, um, you know, using multi-threaded applications, help is a whole bunch of different, uh, new use cases here. Right.
The other thing I like what you said on the edge, the reason why I like what you said on the edge is because when you look at the edge companies like, uh, Zita, right? For example, working on, uh, orchestration of Kubernetes clusters at the edge, they're looking at these, uh, different scenarios that are out there. The, the challenge that the Edge has is, you know, you have Intel processors, you have EMD processors, you have, uh, you know, arm processors.
You have all sorts of different technologies. Well, wza kind of harmonizes all that. You don't have to recompile the code, right?
You can utilize, only build that 10% of business logic and keep 90% of the code without recompiling. That's brilliant. Right?
So using it at the edge, I think the orchestration piece comes in. So from a cloud native in front kind of a growth perspective, web assembly has legs, but it also, uh, it's still in its infancy. I think It's still early, but it, it's kind of the next generation of that promise that if you remember way back into the Java introduction of Right Once Run anywhere because of the Java time, Java runtime environment.
It's not the same thing of course that we're talking about. But wasm is like the current generation of that delivering on that promise. And to your point, the variation in endpoint devices, even down to the, you know, this revision of hardware that you're running on with this chip for wifi or whatever it might be, can be, you know, mind-numbingly or frustratingly aggravating to manage all those variances and differences.
And, you know, that's one of the things that really helps abstract that away. Well, absolutely. So, but like when we look at this and we pivot to, you know, other topics that are coming up at Cougar, right?
Look, of course, cloud native is going to be the topic of choice. And the, you know, the, the discussion of Choice Cloud native is interesting to me, right? And, and I've been doing this trending study for past four years on distributed cloud, multi-cloud environments.
We were seeing, like, you know, a couple years ago, eight in, in 2022, we saw that 89% of organizations were using two or more clouds that jumped up to 92% in 23 and 90. And now in 24, our research shows that that's 94% of two, uh, of cloud, uh, I'm sorry, organizations using two or more clouds. 65% are using four or more clouds.
And that's for production applications, not SaaS based application, but production applications, SaaS based. Actually, we have some data this year showing that 93%, uh, I'm sorry, 97% of organizations are using, uh, two or more. So there's a lot of cloud adoption.
Any, any net new, um, applications being built. I was just on a recording with, uh, with Mike zd, and we were talking about this, uh, uh, you know, about the cloud native now, and we were talking about new applications being built, and then we were saying, well, is it all we wanna be on cloud native? And my response is, yeah, I mean, cloud native is really where net new applications being developed.
The question and I wanna see out of this event is 88%, according to our research, 88% of heritage applications are still running in that siloed environment and, and a heritage environment. Not all those applications need to be refactored into cloud native. They can be encapsulated into cloud ready state and be a system of record and build new systems of engagement in the front end that access it.
What are your thoughts on the evolution as it, you know, if you look at these, these, you know, KubeCon and these, uh, these other there events, you think that there's no other product out there except for cloud native products, but I don't think that's true. Well, you know, there, there's, you know, flavors of cloud native, right? There's microservices and containers and service mesh and things like that.
Um, which is kind of where I came from on Cloud native. But there's also the broader built for, built for and operate in the cloud, leveraging cloud services, multi-cloud, you know, can mean kinda lots of things. And I think that's part of that evolution of KU Con.
It's not just about running Kubernetes. Um, though we do have Kubernetes at the edge, you know, K three and K zero, and all kinds of variations of that, of that happening. I, I think it's, it's backing it up for a second.
It's about modern day architectures. I mean, we did this, uh, survey question once. I wish I had the results from it.
Uh, but we asked, you know, the question of is this cloud native require DevOps? And the, and the answer was essentially yes. The, the ability to produce and mass produce that many number of microservices at some velocity, now you're talking about more than things can, people can handle.
And you know, by their hands, by their computers, you know, on inter a personal one-to-one basis, it's gotta be automated. And matter of fact, that's what part of what enables Cloud native is those DevOps processes where you, you're the truly follow DevOps or you're applying some of the practices. It's automation, it's testing and, and unit and deploying into test environments.
It's, you know, CICD process, et cetera. So it's, I think it's a mo I think it was a modern way of creating applications, whether it's the DevOps part of it, or strictly cloud native with microservices or kind a larger definition of cloud native. That is, that's how people are doing things.
Yeah. Look, I agree. I mean, I think that you're spot on to, uh, a, a lot of this, I think that there's, uh, interesting perspective is when you look at, uh, research around this, uh, in our latest study, we found that 24% of respondents indicate that they wanna release code on an hourly basis, yet only 8% able to do so.
Mm-Hmm. The, the companies that are able to do so are you, if you were, you hit the, the, the nail on the head. They're running DevOp methodologies, they're doing software, agile software development methodologies.
They're running, you know, infrastructure as code, um, and they're doing, uh, uh, you know, using, uh, give repositories to get the code out the door quickly. So it's repeatable, faster kind of delivery for faster cadence. Business KPIs are driving that.
Those are the, the expectation results. With that said, when we look at those business KPIs and how they're driving these results, um, there's this need, or there has been a need for, uh, we've seen over the years that this growth of, of, uh, Kate's or Kubernetes kind of platforms that are out there, right? We see that, um, you were mentioning that, you know, building out your Kubernetes environments or building out your microservices environ, we see in our, uh, recent observability study that 43% of, uh, respondents indicate that their, their, uh, production applications are running 30, 30 to 60% of their production applications are running in a microservices environment.
Hmm. So my question to you, Mitch, is, you know, I've been following this space for quite some time. You've been in this space for quite some time.
Uh, you know, the, the Kubernetes platform vendors that were out there, right? You know, the companies like Raye or, uh, D two iq, for example, uh, D two IQ being a being acquired by Nutanix Rae, now expanded from just Kubernetes to more looking at holistic the environment. Why, if you look, you know, when you look at these different platforms, right?
Net Hopper has one, and HUMANeX has another one for DevOps and platform engineering. If you look at these different platforms that are out there, I felt, you know, that the Kubernetes platform was going to take off to help accelerate the adoption of Kubernetes. But in turn, it seems like there's been a con a consolidation of that market where, like, like I said, Nutanix buy and D two IQ, right?
And, um, you know, Rafa expanding their portfolio for growth. Why do you think that they're looking at expanding their portfolios from these just Kubernetes specific platforms to more holistically across virtual lives violence? Well, first of all, I feel like you're inviting me to play, so I gotta throw out a few statistics of my own too.
So I did, to validate what you're saying. 'cause uh, we just completed a study, a DevOps study, and where we asked, are you using cloud native? Are you using Kubernetes and microservices?
And our results were 57% we're doing that. Another 22 are considering. Yeah.
So it's real. I mean, kinda looking at it data that's kind of validating each other to your question though. I, I think what, what's we're experiencing, and this also has backed up some of the results of the widespread adoption of DevOps kind of process, of how we create software I, is that we're, we're evolving from lots of siloed solutions.
I need a this and a that and this, that, and then I'll assemble that together and create my application. You know, I get this from Rafa and I get this from somebody else, or whatever it might be. And now we're seeing, um, consolidation, and I don't wanna call it homogenization, but I don't, I don't want to deal with 25 people to create a platform.
I want people to help create a platform for me, right? Think about platform engineering, whether that's my DevOps tool pan, and I'm gonna go to a GitLab that's, uh, you know, more of a DevOps platform, um, or Jfr or somebody like that. Or, you know, like you, like you're talking about, um, the deploying environment.
Even even saw it with, um, you know, Broadcom had some announcements around, um, VMware and Tanz about doing things in on premise, you know, similar to what you would do in the cloud. I think people are looking for ways to try to simplify some of that complexity, um, because the more complex we're, we're not gonna stop adding things to their environment, right? It's just a natural of our industry.
But you have to have ways of, okay, let me start to take out some complexity so I can handle the new things that are coming in. And I think that's part of this trend. Also, just the competitive nature of the environment, right?
The, the market. Okay, I can't be just a single thing there. I've gotta be able to provide more value and help my customers meet the velocity and, and, you know, acceleration that they're being asked to meet.
Yeah. And Mitch, absolutely. Uh, you know, I want to comment on, you know, the data points, because I think it's, IM, I think it's also very important.
You know, I, 25 years, five years ago, I transitioned from the vendor world to being an analyst. And, uh, 25 years in the vendor world, I would work with the analyst community and absolutely not just get one data point from one analyst, say, that's where I'm gonna go with it. I go to all the data analysts try.
So I, I love the fact that like, you know, in the analyst community that we can, we can share each other's views and it, and, and it, and you know, frankly, even though our data matched, you know, lines up, I also like when that doesn't match, because it's like, what happened? Like, how is that different? So it's kind of good to validate that, but, you know, look, speak spec, uh, speaking of data to Angie and, and your complexity comment, in our recent observability research, we found that 75% of respondents use six to 15 different tools to gather insights for their information around, you know, around their environment.
That's hugely complex. Not surprising. The very next question was, are you looking to change your observability tool in 2024?
And 53% said yes, because they wanna move towards more of a, like you were talking about a full stack observability solution. Mm-Hmm. So it's really interesting.
But when we, when we look at that, I, I wanna kind of pivot a little bit over to from observability, kind of reach into that DevSecOps space, right? Because I think DevSecOps out of KubeCon is going to be very, very interesting. Um, you know, I think that there's been some consolidation of the market, but there's also new approaches that are coming in, coming out of RSA and coming out of different, uh, black hat.
You'd see that there's a, a number of different things that are happening in the security space that, you know, I, I believe that Cocum might be able to kind of, uh, kind of unpack some of that. What are your thoughts? Well, it, it, like all of this is, you know, going through its evolution and maturity cycles.
And here, here's my just kind of high level view of, of DevSecOps is we've been through the shift left period. Let's make it the developer's problem. We've been through the, let's move it left.
So we design security into the process. We've moved into the code scanning and doing things like vulnerability scanning, things like that to help create more secure code. But I think supply chain security has pointed out to us software supply chain security, a couple things, as in the security world where I also come from, you know, if you don't secure at all, and you know, you, you, the, the three walls of the house are secured, but the back is wide open, is not secure, right?
And so that's what DevSecOps is evolving to is think it on two planes. The first plane is how we create software that we created in a way that it's secure. So we're designing good API, we have good A, API, um, um, management and lifecycle management and security built into how we do that, how we design our applications, et cetera, all the way through delivering it into production environments.
I just pick out a, but AppSec, if you wanna think of it that way. And then the stack of course, that it's running on the, whether it's the kind of software infrastructure, the Kubernetes, et cetera, all the way down to the cloud infrastructure stack. The second plane is, because this is where also where supply chain security comes in, is what about the underlying tool chain and all the processes that are used to create that, right?
It might be one thing to have secure cars on the highway, but the, the highways suck. Well, guess what? You don't have security.
Same thing with our underlying, um, tool chain that we use all the way through the entire DevOps process. So there's a lot more focus on, for example, how do I use some of the principles from security? Things like isolation, segmentation, so that if something happens upstream, my CICD doesn't get, uh, compromised, right?
Because same thing happens there is get in here and then move laterally and get to the, get to the goods, right? You know, where you can insert your code or do whatever damage that you're doing. I think that's what we're evolving to.
And that's why you see, uh, people kind of repositioning themselves as DevSecOps companies, not 'cause they have a little bit of security, but they, they're addressing it more in a lifecycle standpoint. Not that it's all solved, but I think, you know, customers don't have to solve that all on their own either, right? It's a hard enough problem, uh, stitching together a set of tools and now we can do it with platforms.
How do we do that with security? That's my view of it. Yeah.
I, and I love it. I love the, the, the perspective. I mean, you know, I think when I think about it, I think that, um, when I think about what you were talking about, I was thinking about, you know, introducing another, uh, injection point into the CSCD pipeline, which you have the security injection point, you know, you already have your, your CSCD pipeline and you have your telemetry pipeline, you have your security pipeline.
So you have all these different things you have to match. And you know, I, I agree with your assessment that, you know, there's a lot of companies out there that are trying to address and pivot themselves to be more, I, I focused on this, but I'm gonna take a different spin, a little bit different spin and say that a lot of these companies, um, also the organizations that delivering it, they are accountable and they're, they are accountable for their actions. And, and frankly, with the executive orders that are put in place right now with defines and, and, and the reputation that organizations have to deal with, and also the, just the impact of the overall business, uh, security is, is a very strong, uh, area, you know, and I think that there's a lot here to unpack and a lot to talk about.
And I'm definitely looking forward to, you know, connecting with the, the, the, the vendors that, you know, we have nice strategic relationship with. I, I slim ai, for example, slim ai. They do a great job at swimming down that, uh, that containerization.
I love that approach, uh, from a, from an application perspective, that's very interesting to me. I'm looking forward to meeting with Steve and Harness and all the companies in the, in the, in the DevSecOps space as well. So what's happening, um, at KubeCon, I, I, I also wanna make a, I don't know, a shameless plug to the fact that we're doing application development field day, uh, right before, um, uh, KubeCon.
So on the, on the Tuesday and Wednesday of, of that week, uh, if you're coming to KubeCon anyways, app Dev Field Day is right there. It's a, it's an, it's an event that really helps streamline and, and kind of gets your message out there, but also gets the, the delegates in the room to help talk about, uh, you know, what their perspectives are for what the solution is. So any thoughts on App Dev Field Day?
Yeah, it, uh, you know, it's, it's relatively new to me. I've experienced a couple, matter of fact, I'm doing the AI one that's, uh, that's, uh, right upon us here. It, it, it's an experience with, like, imagine yourself where if you are having a vendor, a technology supplier, you're considering you, you wanna have the conversation that you'd like to have with him, but you wish you had more perspective, depth, other things to it.
That's what the delegates bring to this. You know, it's, it's, you're listening in on a group of people who are asking the questions you wish you had thought to ask. And that's what this online event is where you can watch it, you know, in real time.
Um, and it's not to make the vendor scorer, we're not trying to do that. That's not the case. It's, it's really just thinking through, okay, if we're AP up, let's talk about it.
If we're talking about, you know, uh, AI applying AI into the, uh, IDE and into the development process, what are some of the issues that come out? How do we think about that? What are good ways to solve that?
Is there something that you do with that? Those kind of things. So I think as a practitioner consumer of the kind of technologies for the vendors that are gonna be at App Dev Field Day, it's a great way to like, kinda watch the professional tennis match, right?
Without having, and you don't have to play in front of an audience. You can, you can play it on your own at whatever level you are. Don't worry about it.
Yeah, absolutely, Mitch, I'm looking forward to it. It's gonna be another great event. I mean, I know the last one was fantastic.
We had a lot of, uh, a lot of viewers on the, on the live stream. We had the follow up was fantastic. So I'm really looking forward to it.
Mitch, it's been a pleasure. Looking forward to seeing you at Ku Con forward to seeing you, working with you on a, a couple of different events here. Also, the audience here, um, you know, to hit, hit us up.
I mean, Mitch and I are both gonna be at KU Con, I believe, and I know I am. Uh, so hit us up and we're gonna, we're gonna, you know, be more than happy to talk to you about any of these, uh, data points that we threw out there. But I'd also, anything you want to talk about, uh, in our insights.
Uh, but thank you and thank you for watching and, uh, enjoy your day. Have a good Day. Thanks everybody.
We'll see you Kon. If not before.



