Empathy in Product Management: Insights from Solo.io’s Keith Babo
Keith Babo highlights Solo.io’s role as a billion-dollar company providing networking solutions like service mesh and API gateways. The discussion includes platform engineering, AI integration challenges, and the significance of security in AI projects. Keith also emphasizes Solo.io commitment to open source contributions, particularly in the Kubernetes ecosystem.
Transcript
Hey everyone. Welcome back here to Tech Drunk tv. Our next guest up today is Keith Babo.
Keith is the Chief Product Officer. It's solo io. You know, Keith, I'm only, I'm never sure to just say solo or solo.
Do io. How do you guys refer to it? We load balance between the two options.
io. Yeah. Alright.
So I can't go wrong. Yeah, Exactly right. Sounds good.
Um, Keith, before we discuss solo, let's discuss you a little bit. You, you are chief product officer here, but give us kind of how you wound up over here. What, what's your story been?
Yeah, for sure. So I've been at Solo for, for four years now. A Adi started the company that's seven and a half, eight years ago.
Uh, and, uh, boy, what, what a great rocket ship ride of, you know, everything we've done in the community and, and helped customers. And, uh, but before this, I actually worked at, this is the first startup I've ever worked at. Uh, it's so low.
Really? Yeah. Um, it was, uh, sun, or excuse me, red Hat before that.
I worked at Red Hat for 10 years. Uh, amazing journey. You know, like the, the original, the OGs and the open source community, uh, around Linux and R and then built incredible businesses outside of that was there for the birth of Kubernetes and OpenShift and, you know, great, great company.
Um, uh, but really wanted to like, get out into the, the building a business scene and you know, like, and, and indeed had already built an incredible business at Solo. Uh, but just like the, the trajectory and customer acquisition and all the great problems we were solving here, it's, it's been, it's been fantastic. So, uh, other interesting fact is that most of my career still has been in engineering.
I switched to product about halfway through my tenure at, uh, at Red Hat. So, uh, yeah, highly recommend to the audience, uh, giving product management a try, even if it's just for a year. Everybody should do that job for at least one year.
You know what, I, I've spoken to a lot of folks who moved, who made that switch sort of from engineering to what they call the business side. Yeah, yeah. Running product and stuff like that.
And I, I do agree with you. You know, I, so I've, I've co-founded about four, five venture backed startups. I was, I've been a startup guy my whole career in tech almost.
Mm-hmm. Well, pretty much, yeah. I mean, I've grown companies to be pretty big, but, you know, they started as startups and, um, and as, and I've been CEO now or, and then CSO I've had a lot of C-level stuff.
I think the more pots you could put your fingers in to taste what it's like, the more empathetic you are and the more and the better of a leader you are. Right. Um, if you understand what, what it takes to get someone, and, and that by the way, that's pure DevOps, right.
Empathy for what the next person is doing, right. And what their job entails because it's so, it's so easy to just say, Hey, it worked on my machine. You know?
Absolutely. Empathy. We'll, again, it's a Key principle of DevOps and just in general, like, if you are not in this business to help customers, then what are you doing basically?
Right. Get out. Right, exactly.
Yeah. Exactly. If you're that, and I, I think that, you know, if you're that bitter pity, Right?
And like if it's what you're doing, your current job, whether you're in customer success or engineering or you know, or marketing, like you're helping customers in some way today, but if you really want to touch all the different ways a business can actually help a customer found a company like you acted, like, you'll de that'll do it, right? But product also touches all those areas. So that's why I say like, even on a rotational basis, like it, it'll make you a year end product will make you a better engineer or make you a better market or make you better at customer success and support, like whatever your role is.
Yeah. Give product a try. That's my commercial.
Excellent. Yeah. All right.
Good for you Keith. And you know, if I had to pick one sort of big company that held onto its startup lineage longer than others would be Red Hat, right? It took IBM years and years to kill that startup.
Kinda of no Comments on that Particular aspect. You can't say anything. You probably don't stock there, but, but listen, You know, I'm with you.
That was absolutely a pirate ship mentality in the most positive way possible. And I think it goes back to open source and like the ethos of, of open source. And that was such a deep, I I could not believe what a deep part of the Red Hat culture that was and how much they, em embraced open source and open communities.
Yeah. Or part of the DNA and uh, you know, and that was the best way to build a business. And it has become, everyone has replicated that model now.
All like Started, well Red Hat was the poster child, right? People would say Red Hat, I'm not Red Hat. Open source business models are a failure except Red Hat.
Yeah. You always, except Red Hat. Um, anyway, but eat, it's lucky to have you at solo and, you know, four years there.
You've gotten, you've got enough startup under your belt now to, you know, understand I do What it's like, I think a deep, like it's, uh, and it's funny, just another quick aside there from a product perspective is that no other company has done 100% open source like Red Hat has, right? Yeah. And I think no other company will.
They just hit the right market, right? Leadership. Yeah.
It was, timing is everything. You're right. Yeah.
And, and you're right. There's other models, you know, that we've seen in the market around license swaps, rug pulls with stuff and this kind of thing. You know, I think the open core model is, is the best thing for open source community members and the best things for companies, you know, to pay the engineers and the people that are working on that open source technology.
Uh, I think ADI has really nailed the combination of being really active in the community and showing leadership in the community, uh, and being fully committed to open source and then also like meeting customers with enterprise features and our open core model. So I really enjoy that about here and, and we're really deeply do It. Yeah.
Well I, I'll tell you, I know indeed, um, probably almost since she started that company, six, seven years I'll bet. 'cause I know it was before, uh, uh, COVID. Mm-hmm.
So it's, it's gonna be a while, but, and you know, I'm, I'm a fan, right? Yeah. I've always been a fan of her.
I think she's a great CEOA great advocate for, for the market, but you know, Keith, not everyone out here is gonna be familiar with Solo for, for our listeners maybe who say, yeah, I think I heard that, or I saw something, you know, open source Yeah. Match maybe. Yeah.
What Tell people what SOLO is. Sure. Yeah.
Yeah. So, and it's, uh, and funny enough, like one of our product brands Blue, they may have heard of that and not even know like solo. Yes.
Yeah. The open source, right? So, um, so I, I think that one of the things that's really enjoyable and fun about Solo as, as you mentioned, people might not have heard of us, were like the billion dollar company that, that you've never heard of and that you use indirectly every day of your life.
Like if you are buying a phone or ordering a meal or traveling through an airport or interacting with your favorite LLM, like all of these businesses run our technology as a core part of their infrastructure where Tier zero infrastructure, those customers. And that's a tremendous privilege for us to cus partner with those customers. It exposes us to use cases and scale, uh, that are directly responsible for success because as we implement and help those customers get to production and scale and production, then we're actually basically contributing those back into the product and scaling to more customers.
So, um, it's a great environment to be in. It's been fantastic that we get to partner with the customers that we do. Our specific area in how we help these customers is that the networking layer, as you mentioned, service mesh is one aspect of that, which is, as services talk to one another in a cluster, you want zero trust, mTLS and this type of thing.
Strong identity controls also at the edge of your network as traffic's coming in, like ingress, we're helping customers with API gateways and how they're bringing traffic, traffic securely into their cluster. And then even if you're consuming services outside your cluster or egress, we have a gateway and a mesh that helped with that as well. And that was the foundation of this company.
And really what we helped platform teams build platforms as a product. What is a product that gives self-service to developers, but has the guardrails to remain secure, observable, and resilient in production. Um, and that is our bread and butter and, and how we've helped so many cus hundreds of customers, um, and, and really expose us maybe to one of the next things we're gonna talk about is a new type of workload in the marketplace around AI and agent apps.
Just wanted to note what time we mentioned AI for the first start. We went pretty far. I feel we did us.
That was damn good. Damn good, Keith. But before we jump into ai, let me, let me talk a little bit.
Platform engineering, IDP, golden Path, all of this kind of stuff. Yeah. Keith, do, where does solo fit into that platform engineering?
Is it part of the golden path? Mm-hmm. Is it helping Id manage IDP or it really comes sort of after the IDP right after codes generated.
It's more how do I get it out the, out the door, right. How do we get it out there? Yeah.
I would think it's more like we have a, a philosophy, and this is driven from a de here that, you know, our technology should be delightful to use and boring to run, right? And the idea is mm-hmm. This thing's, this stuff that takes care of security, observability, resiliency.
You don't even want your developers to know it's there. It's part of the infrastructure and it's there when you hit peak traffic hours at, you know, basically meal times if you're a fast food chain, right? Or there's a new iPhone launch and you're looking to, to scale to that traffic, right?
This is when you care basically, right? And that's the, you know, delightful to use aspect of it. You wanna know what's secure by default.
You wanna know that you can basically load balance or rate limit traffic, you know, dynamically at runtime. But you wanna do this in a way where it never impacts developers. And I think that's where it gets into the whole IDP universe and giving developers self-service is that our entire API and surface area for configuration, our product set is all declarative in nature, right?
So fully embraces GitOps and, and infrastructure and configuration as code every bit of our API and feature surface area gets into a file, gets checked into Git, gets progressively rolled out to whatever environment you wanna apply it to, and gets instantly reconciled if you need to roll forward or roll back. And I think that's really the key pluggability point there, is that we want our customers, and we see this all the time, building customized developer and portal experiences for their customers, their internal and external consumers. And behind the scenes, they're leveraging our APIs to actually do the, the things they need to do underneath the covers.
Fair enough. All right. Let's, let's go in with both feet here into agentic ai.
And as you said, you know, this is, this is top of mind for platform engineers, developers, DevOps, everybody, especially in the tech world. Ai, and, and it's funny, I was on a webinar last week and the presenter said something like, well, you know, that happened during the age of generative ai, but that's passed now we're in agentic AI that quick, right? We, we barely got this thing working right?
But we're, that's yesterday's news. Today's news is agentic ai, but it just like with the generative, we don't know what we don't know. I feel like, I feel like we're just at the beginning of the beginning, not the end of the beginning.
Yeah. But talk to me, Keith, about how do you guys look at, you know, how platform engineers can harness agentic AI for good knowing that hey, there might be some gotchas that are gonna pop up. I've, I've always embraced going back to developers real quick because I wanna set up something that I think is a critical point here for platform teams and just organizations in general as they're adopting Gen AI and Gentech, whatever, whatever you wanna call it, is that, like, I've always had this philosophy and I, someone long ago in my career, uh, I coined this phrase, so it's not me, but like that code has no value until delivered to production up until that point.
It's a cost center basically. Right? The moment it gives in production and delivers value to end customers, then it has value basically, right?
Mm-hmm. If we see these stats on the number of a agentic and AI pilots and POCs that never reap production, how real is that? Basically, if it's not in production, it's not real, right?
So we have to ask ourselves like, I'm not saying AI as a technology is not real. What I'm saying is we're clearly missing something, right? We're missing something in getting these initial projects, especially like, yes, there could be a problem with finding use case fit or selecting the right, you know, kind of workflow to, to focus on.
But ultimately we got to get these things into production, right? And what's holding us back from getting them into production and it's how am I gonna audit and explain the behavior of these agents as I have applications integrating with LLMs? What data are they sending and getting back?
How do I know that's not gonna get hijacked or exfiltrated, right? Like these tools, these everything's an Mt p tool server all of a sudden basically, right? Do I just hook this up to Salesforce and let agents go crazy with these tools and do whatever they want?
Right? These are really significant concerns and it represents a little bit of a shift that we're seeing in the market now over the last six months where platform teams, initially they were not in the decision for what was gonna happen with this AI budget and how AI projects are gonna be rolled out. They were completely left out of that.
Right? Now all of a sudden when these projects are not getting to production, now we're seeing these platform teams get embraced and brought into this decision making process to understand how you're gonna really get these things into production. So make no mistake about it, like a AI and agen applications and initiatives are going to get to production.
It's going to happen, but it's only gonna happen with the platform team involved. And I'm really happy to see that happening right now. Yeah, Yeah.
I, I agree with you. I, you know, I, I was talking to someone earlier today and I said, you know, there's a little Lee iaccoca thing going on here. You could lead, follow or just get out of the way.
Yeah. But, but this train's coming, it's actually left the station, right. That train's moving.
Um, but, but, but here's the thing and, and it's the thing about all of this AI on one hand, it, it's like a gift from God, you know what I mean? Yeah. It's like, it's almost magical in some of the things that it could do for you and stuff.
On the other hand, as you pointed out, it's still relatively unproven at a commercial production mm-hmm. Level. And then secondly, we're still finding out what are the downsides?
What are the costs? What are the gotchas? Yeah.
Right. That, that we, the unintended consequences, if you will, that we, we just did it really recognize and because you know, you, until you, until you deepen this up to your ears Yeah. Um, you don't really know what you're in for.
You don't I, but listen, I mean, the thing why there's so much I think like pressure here is that people realize there's gonna be significant first mover advantage to the people that figure this out. Yes. Basically.
So fortune favors the brave and the brave companies that push forward here, like with the right guardrails in place will win in their market segments. Right? And so, like, and I a hundred percent believe that.
And so if we think about what we're doing from like an open source standpoint and a product standpoint, we're trying to focus on enabling product teams to build secure agent platform. So be that basically that infrastructure on which these agents will run. So you get the security and observability for like, for security on alone.
Like, I've got MCP tool servers, who knows how that been secure? Can I put a gateway in front of that and isolate communication to tool servers so I can be these agents or these users have specific access to these tools, right? Can I do that?
And basically constrain it, not only just when an agent wants to talk to a tool, but when a user, when an agent is acting on behalf of a user when acting to a tool basically, and I need to down scope those permissions. There's some very like significant and nuanced differences between ag agentic workloads and classic workloads. And that was a major gap in Kubernetes.
Kubernetes gonna be the foundation for this. It's gonna be the platform you run on, but we need to address and fill in those gaps. And that's exactly what we've done.
The open source projects like K agents and uh, and agent gateway. And that's why those projects, by the way, are in the CNCF and the Linux Foundation respectively, because this is a real gap in the market. It is, it is.
And and I don't want to diminish that, but while you're talking, something pop my head I wanted to say before I forget, is that these also create new attack surfaces from a security point of view. And so, and that's something we can't forget either, that by using these things, it's a new, it's a new vector. It is from potential security And you're going to enter into this and like you're gonna get to production without getting hacked or exploited by adopting some of the same fundamental principles that have been security best practice all along, right?
Like zero trust principle of least privilege, for example, right? So like you're going to enter into this saying, I've got secured tool servers and by default it's gonna be denial, basically no one can access them. And then I'm gonna selectively a open up and, and, and give permissions to specific use cases that have access to these tools.
And then I'm gonna watch that really closely with a very focused use case, basically, right? And as everything goes well, then it's gonna gimme more confidence to start to expand and extend. And so I think it's like, it's really that time.
And the same thing with IDPs. You know, the, the, the goal there is if you're gonna be successful in a launch of an internal developer portal or an internal developer platform, show value as fast as possible, get as concentrated on a specific value that you can deliver to developers or platform teams and do that as fast as you can and then incrementally build. And I think we'll see the same thing with these AI initiatives where we get to very tightly scope things that prove ROI prove that they're not exploitable or presenting security risks.
And then we'll get that confidence and start to gradually expand from there. But you've got to land that first use case first, which requires like a secure platform to do it on. Agreed, agreed, agreed, agreed.
So how solo play into this? Yeah, so as I mentioned, like we're very active as a, as a, as an open source company. Uh, it, we donated a project that we, we noticed this gap, let's see, boy, this was back in qca London.
So a de and I announced, uh, the contribution that what we announced K agent as a project and then quickly turned around and uh, and donated that to CNCF just based on how active that community was getting. And, and, and really what that gap in the Kubernetes ecosystem was that there was nothing that actually filled that gap of how do I deploy agents and tools to Kubernetes and get all these like, normal controls around self-service connectivity observability for those just like I do my classic workloads. Um, and then at the code activity layer specifically, we noticed that there's protocols like MCP and A two A, they're very different than classic protocols.
And you need to dis yes, like you have, you need a purpose built data plane for those things. We build agent gateway from the ground up and rust based of all of our experience in Istio and Envoy and the rust based, uh, Z tunnel in, in, in ambient mode in Istio, um, and funneled that all into this concentrated implementation around AgTech protocols, um, and LLM protocols. Uh, and that's agent gateway.
So we started there and now we're bringing that all into, uh, uh, you know, the, the products, uh, portfolio as well. So it's great to see the, the open source and community momentum and then also, uh, as that's delivered in, in, in our products. Excellent.
So obviously the website is solo io. It's, that's why we've been saying that name. But Keith, people can get in the information on all this on, on, on the website at this point.
Yes. And I'll tell you that in about, uh, two weeks, you're gonna see, check out the site now and then, uh, come back, uh, around mid-September. You're gonna see some very exciting updates and, and announcements there as as well.
Well, was a tease like that. We better have you back on soon. Love.
I was now see you at CubeCon, but we better, you better get back here before November then, my friend. Okay, awesome. Yeah.
Alrightyy Keith, thanks for joining us. Appreciate the update. Say hello, edit and everyone at solo and, uh, well it looks like we're going to hear from you in a couple weeks.
Awesome, Alan, it was a great conversation. Thanks for having me. My pleasure.
Keith Babo, chief product officer solo io here on Text Drunk tv. We're gonna take a break. We'll be back.