Endpoint Management and Security – Zach Wasserman, Fleet
As a successful developer and entrepreneur in his field, Zach will touch on his career trajectory, share his expertise in endpoint management and security, and discuss what makes him get up every day. He will also go into the technical details of developing the first GitOps-driven, open-source, cross-platform device management (MDM) platform and discuss how IT departments can leverage it to overcome numerous challenges imposed by proprietary platforms.
Transcript
This is Textron tv. Hey everyone, welcome back here to techron tv. I'm really happy to introduce you to our next guest.
It's his first time with us here on Text Strong tv, and it's kind of the first time we're gonna introduce you to his company. I'd like you all to say hello to Zach Wasserman. Zach is the co-founder and c t o of a company called Fleet, f l e e t.
com. Hey Zach, welcome to Tech Trunk tv. It's nice to have you on here, Alan.
Thank you so much for having me. My pleasure. So Zach, before we jump into fleet and, and all that you guys do, and, and there's a lot here, let's start with kind of the Zach story, right?
Share, if you don't mind, with the audience, a little bit about your journey. Sure, Yeah, absolutely. So, I mean, I, I was a child of the nineties, born in, born in 1990, and I grew up in the, in the Bay Area near Silicon Valley, seeing the stories of, of tech and things like Google blowing up.
And I was a young nerd reading the newspaper and who liked math and stuff, and somehow got the idea in my head that I wanted to get into computers. com crash happened, I think I was still too young and immune to, to notice the ups and downs, but the idea of working with computers really stuck with me. And so I, you know, I ended up studying computer science and university, dabbled in cybersecurity a bit, working with some really, with a really interesting professor, uh, at Matt Blaze and some, some grad students doing research on radio protocols that, that federal agencies were moving towards.
And we found all sorts of ways to break them and, and that got my, my taste wet into cybersecurity. Um, so it was, it, it was both, you know, a desire to work with computers, to do entrepreneurship, and then to figure out how to kind of, uh, build and, and understand and break things as well. That kind of brings me to where I'm at today.
Very cool. com days and got the scars to prove it. Um, and it's interesting back then, you know, we didn't have cybersecurity programs in college or high schools or anything, and most of my friends who were in security got into security in one of two ways.
Either they were kind of drafted, they were network people and back then network security was really network security or endpoint security, that's where you were. And, and so they were network people who wound up doing network security or the, the, the real good hacker dudes were people who just got off on breaking things, right? They wanted to understand how to break things and then how to build it back so it wouldn't be so easy to break the next time.
Right? And, and I think that is, that's like core critical to, to the whole security mindset right now. We call it cyber to the whole cyber mindset, right?
Is, hey man, I, I like trying to figure out how if things could be broken and if so, how and how can I make 'em better? So, you know, I I think you're in good company there. Um, you were very involved also in the open source community though, correct?
Yeah, that's right. And open source was always something that, that fascinated me. Again, as a child of, of Berkeley, California and, uh, you know, ha having some, having some not, let's not say radical parents, but living in a place that was fairly radical and the idea of open source and this kind of mixture of, of capitalism and communal effort together was always something that really fascinated me.
And, and that's, you know, that's really become the story of my career is finding that open source is a way to kind of link narratives through across different companies across different kind of economic interests. But being able to bring that impact across that whole journey has been so exciting. And, you know, so I'm, I'm sure we'll talk about it in a minute, but that the journey really started at, at Facebook as I got to start work, I helped create OSS Query, which we opened source there, which the plan was immediately to open source it, and we did within six months of creating it.
And you know, that's a project that's been now open source for almost 10 years and been the foundation of my career across a bunch of different endeavors. Very cool. We're gonna talk a lot about os Query as, as it relates to Fleet as well, but let, let's jump, let's jump a little bit into Fleet, right?
Um, tell us, you know, I mean, you're one of the co-founders, you're a C T O give, give us kind of the fleet story, the background here. Yeah, I mean, the story of Fleet is, is really that, that Fleet was something that I originally helped build at my prior company Collide. And we built Collide Fleet and we released it open source as we kind of pivoted towards building a SaaS product that was a bit of, of a, a different product, but we thought people are, would be interested in Fleet, and Fleet was an OSS query manager essentially.
So osquery is a piece of software that runs on endpoints. So Mac, Linux and Windows computers and reports information about what's going on. We built essentially a management server so that you could, you could configure those agents, you could collect the data coming up from them, and then we just kind of released it open source and abandoned it in some sense.
But the amazing thing, and the thing that really drew me to it was people started using it and as Kali kind of pivoted through various ideas in my eyes, people weren't using that stuff so much. And I was always really excited about, about doing things that people cared about. And so I got drawn back towards this open source project, which again, you know, is kind of really caused me the concepts around that.
And so I ended up kind of working on Fleet as the sole developer after I had left Collide. I was kind of like the, the the one man band running an open source project. And then in 2020 I was approached by Sid C Brandy, the c e o of GitLab, who's now working on, uh, you know, of course he still runs GitLab, but he's also got his open Core ventures now and he's looking out for open source maintainers and saying, let's build companies around this.
So essentially that's what, that's what SSID came to me and said like, Hey, let's build a company out of what you're doing with Fleet. And he connected me with Mike McNeil, who's now our c e o and my co-founder. And we started building, you know, from the one man band up into a, a real company, figured out how to kind of build a business model around this that was different than the consulting model that I was working with on my own.
And, and, you know, three years later, almost to the day, I think it's, uh, you know, uh, it's a week from Monday is our three year anniversary of, of starting working on this. So three years later here we are. That's great, man.
Congratulations. So it, it sounds like sid's, uh, open Core Ventures was the kind of the seed money on this. That's right.
I, I thought you guys had raised, and I don't remember, I go through so many of these man, there was some other investors as well, though. There was a round that was done. So there was, so it's a, it was a pre-seed, if you will, with ssid.
Mm-hmm. And then we raised a, a series, uh, or a seed and then a series A later with C rv. So they are Oh, very cool.
Are C R V and, and Reed Christian at C RV are, are now our main investors. Uh, and SSID continued to participate as well. Great.
And we have no Sids and Fred. Awesome. Yeah.
Oh yeah. Yeah. Uh, and Sid has been a great mentor to us.
And, you know, for folks who are out there who are interested in, in company building, the, the GitLab handbook that's public out there is such a wealth of information and it's something that we've modeled so much of the fleet company off of what SID'S done at GitLab, and it's incredibly useful, incredibly inspiring. And again, like that transparency I think is just so refreshing and so interesting and hearkens back to the, the spirit of open source in my eyes. Yeah, no, it's, it's literally an open book, right?
Uh, you know, we've been following GitLab pretty much since they came out and, uh, had, we've had sit on here many, not recently, but we've had sit on many, many times. Actually, Ashley Kramer from GitLab is doing a panel with us on our DevOps experience virtual, along with a bunch of other DevOps c uh, CEOs. So it should be pretty cool.
Anyway, um, so let, let's talk about the relationship though, between OSS Query and Fleet, right? Because, you know, you spoke about open source and, and you know, when you were kid in Berkeley, I, I call that the, the, the, the Cathedral and Bizarre, uh, hit, you know, era of open source with Dr. Richard Stallman and, you know, all of that good stuff.
And then we, we kind of graduated from that into what I call Big Brother open source, where every open source project had a, you know, a big brother who, who really owned it and managed it. And unfortunately sometimes just for their own benefit, you know, they, they talked a good game about the community, but a lot of it was for their own benefit. And then of course, we, you know, now we're in what I call the foundation era of open source, where a, a lot of these open source projects are administered by like organizations like the Linux Foundation or Cloud Native, or you know, there, there's many foundations out there, the Apache Foundation, um, and, and that allows, would be competitors to work together, right?
For the good of us, all right? 'cause that Rising Tide kinda lifts all boats and, um, fleet and, and so the relationship between Fleet and OS Query to me is, is kinda one of these new foundational error things where, hey, look, you, you were there for OSS Query, you helped, you know, birth that, right? You were very involved.
It's part of LF now, isn't it? That's right. OSS query.
Yep. And so you were there helping maintain it and everything, and now we have sort of a commercial entity that is capitalizing. I don't put anyone can go start a company and capitalize on, on what's out there with it.
But let, let's talk about that relationship. Is Fleet a commercial version of OSS Query or more in that open core model where OSS Query gives us, you know, these core functions that are part of the open source, uh, product project and then Fleet is building on freemium premium type of functionality that rides on top of that? Yeah, it's a bit of both.
I'd say. I mean, oss create on its own is a very, very capable tool for pulling data from endpoints. And just as a quick summary for folks who don't know, essentially it exposes endpoint data as though it were a relational database.
And in fact, it actually uses SQ l light under the hood. So you have the kind of the full SQL light syntax to write queries there. But osquery is just the agent.
It's really powerful. It pulls a bunch of great information, again, across Mac, Linux, and Windows. But being able to collect telemetry on an individual system is really just a small part of the problem that security teams and IT teams are trying to solve.
And so what Fleet does is kind of integrates the system across not just the endpoints, but also including server to manage everything, a way to drive insights based on what we're, what you're finding. So we've built like these higher level concepts on top of OSS query and on top of being able to operate individual agents very effectively and very efficiently on Mach on machines, but it's not enough. And so then, you know, as we move towards more solutions, then, then fleet builds things on top, like being able to pull a software inventory of the device from the devices that are connected, and then being able to identify which of those pieces of software have vulnerabilities, for example.
And that's not something that re does at all. Always query lets you on a single device, pull the software inventory essentially, but then there's so much more that needs to be done. And so Fleet layers that kind of stuff on top.
And then, you know, fleet allows you to do things like specify organizational policies. Maybe these are compliance policies, uh, based on frameworks, or maybe these are just security best practices that you wanna enforce. And Fleet will help you see across all of your devices and all your platforms.
How is the compliance with those policies, and again, osquery can allow you to answer those questions, but Fleet really provides sort of the higher level abstractions and the coordination across all the devices. So Osquery is, you know, was built to be efficient to be deployed to Facebook's production, right? And at one time was deployed, uh, to over a million probably servers at Facebook.
Um, so at scale It's Yeah, that, that, that scale and, and it's deployed, you know, massively at, at places like Apple and Google as well. Like, it's, it's really huge. Um, but those places have whole teams who can figure out how to turn a tool into a solution.
And, and in a lot of ways, fleet is figuring out how to turn this tool into a solution for anyone who's, you know, essentially a little bit smaller than your Apple, Google, Facebook. But certainly organizations with up to hundreds of thousands of computers that they manage are working with Fleet and, and using it to kind of drive those insights with Osquery. Yep.
You know, I, I think another thing where the market has really kind of changed, and I don't know if people's perceptions have caught up, Zach, is, you know, when we talk about endpoint management, a lot of people still think of like, you know, lower on the food chain or, you know, beyond the edge. Laptops, desktops, phones, tablets, those are endpoints. But we live in a world today where endpoints, they're not even just servers, they're instances, they're containers, they're APIs, right?
These are all, you know, all the many. And then, and then of course there's, there is IOT devices that, but that's kind of like endpoint. But, so there's many, you know, the, when we say endpoint, we're not talking about desktop management anymore.
We're talking about, you know, if we look at our network and, and there's a core though, that core is often distributed as well, just about every node, it's almost node management instead of endpoint manage, right? I wish we should adopt that word or that term node management because there's so much, there's so many identities, there's so many, you know, more than just endpoints that we used to think about. Yeah.
In, in my eyes, any sort of individual unit of compute that can be accessed and controlled is, is essentially an endpoint, No doubt about it. Yeah, I mean, as of today, fleet and with OSS Gray focuses, you know, primarily on Mac, Linux, windows with some container support as well, and some Kubernetes support as well. We've also just added like a Chrome OS extension that allows you to get some of that telemetry there, Chromebooks Mm-hmm.
Yeah. For Chromebooks. So, but I, but I think that, you know, mobile devices certainly are endpoints.
And, and I think that, uh, especially, you know, with the rise of containerization, you, you've, we've got like nested layers of endpoints as well where like a node that runs containers in a, in a Kubernetes cluster for example, that's an endpoint. But then the containers themselves, I think are also endpoints, essentially. Well, you, you know, you know where this really, when I talk to the folks, like in the certificate space, like a Digi Cert or a Tigo or someone like that, you know, every single container has its own unique identify, uh, identity in its own unique certificate for the most part.
And, you know, then the numbers start getting crazy, right? I mean, you know, you wanna talk about hyperscale that it, it really goes up quickly. Um, where a million is at table stakes, you know, that's nothing.
I mean, so it, it's crazy, but you know, it, it is a, it is a, uh, it's a real issue that, you know, device management, fleet management, like the name fleet in your, you know, we, we think of that, or I think of that goes on mold of where it was in 2005 or even 2010. And it's a, it's a brave new world now. It's very different.
Um, speaking about that though, look, ai, everybody's talking about generator of ai. How, how, what, what's the AI story over at Fleet? How is it helping you, just looking at it still hurting you?
What do you, what do you think? Yeah, I mean, fleet is focused on getting people the, the data that they need to make decisions. And we're not, we're not incorporating a AI into the fleet product as of today.
Like, we're really focused on continuing to get people the, the, the accurate and timely data that they need and to give them the capabilities to manage these things. And, and AI is not a portion of that. And I think that, you know, where we might find AI more in the future is, you know, fleet has also entered the space of active management of devices.
So through the M D M protocols on, on Mac, which released this year, and Windows, which we will release by the end of this year, you know, we're, we're starting to get more active. And I think that there's, there's probably a space for AI to come in some and allow people to write kind of natural language and convert that into, uh, more structured queries about devices or configurations that get pushed to devices. But again, I think that we're, we're really focusing on, on the, the, the facts, the, the facts of the devices.
And I think that that ai, you know, can supplement based on the actions there, but really it's gonna be that it's the ground truth that we wanna collect. And so AI is not gonna be a core part, I think, of, of what we do. What about in terms of security, though?
I mean, you, you guys are doing kind of like scanning and, you know, c v e, uh, kind of, you know, severity kind of stuff. I mean, I I, in, in talking to some of the vulnerability kind of folks, you know, they're using AI to kind of help them along there. Yeah, yeah.
And I mean, and I think people throw the word AI around, uh, all, you know, all over the place these days. 'cause it's, it's hot to use. And certainly I think if you're looking at a vulnerability management program, like you want to probably be able to do some correlations to understand the risk, uh, that that is implied by a vulnerability being present on a device or that kind of thing.
And I'm not sure, I'm not sure that it's, you know, quite these, this generative AI, large language model kind of stuff is really gonna drive the right, the right insights there. I think it's probably actually more just stepping back to the sort of the more fundamental, um, you know, earlier ai MLOps, kind of like machine learning, AI ops kind of thing. Yeah, I think it's, it's really more the fundamental stuff and finding the right ways to put those primitives together to assist humans in their prioritization kind of efforts, that that's the thing that's gonna make the most impact.
Very cool. Um, I'm just trying to make sure we covered everything in here. com is, is the website.
You guys are also obviously as part of OSS query that it's out on GitHub, thousands and thousands of stars people can get in there. Do you find that most of your Fleet DMM customers are people who've already, you know, they start with OSS Query, certainly they, or dabble with OSS Query and then say, Hey man, this might be a little bit, you know, I'm ready to move on. So I, I, you know, I, I had friends in CloudBees, for instance, who had started the Jenkins project, right?
They got it down to a science where they knew when like an open source Jenkins user was ready to migrate to the, you know, premium version. Yeah. Do you have a similar kind of thing between OSS Query and Fleet?
Yeah, I mean, I think that we're the really obvious choice for the, the product category, if you will, which is very niche of, of OSS Query Fleet Manager. Like we've been doing that, uh, or essentially, you know, the Fleet Code base and the fleet has been doing that longer than anyone. And that goes back, you know, three years before the, the founding of the company to back to six years.
And certainly in the first, uh, year or so of the existence of, of Fleet as a company, our customers were folks who were already using OSS Query and we're using it for fleet management. And I think that as we've been evolving and as we've been like we, like I said, moving to these sort of higher level abstractions and driving more at, AT solutions and not just tools. We are getting more people who've heard of osquery and think it could be useful in their organization and they just will do their initial deployment with Fleet.
And then even people who don't even really know what Osquery is, and they just know that they have challenges relating to configuring and managing and retrieving telemetry from devices. So there's definitely, in some sense, there's like a chasm crossing that we're making here where we move out of the, of the really niche, the really powerful niche and important niche for a lot of people, but into something that's more widely accessible and more digestible for folks who don't have that background on, you know, what is always query and, and why should they care. And I think that bodes well for the company, right?
Because it kind of breaks you out into a whole new funnel, if you will. Anyway, Zach, we're way past 15 minutes, but I enjoy talking with you, so I figured we, we'd keep it going. People.
com to find out more. Zach, we wish you lots of luck with Fleet and keep us posted and, uh, we'll, we'll be following we're fans. Thank you so much for having me, Alan.
Zach Wasserman, co-founder, C T O Fleet here on Tech Drunk tv. We'll be back in a minute.