Kubescape – Craig Box, ARMO
Craig Box, vice president of open source and community for ARMO, explains how an open source Kubescape project is advancing Kubernetes cybersecurity.
Transcript
This is texturong TV. Hey guys. Thanks for the throw.
We're here with Craig box who's vice president of Open Source and Community for armo and they're trying to build a true open source Community or kubernetes security and there's a project that goes with that and I'm gonna let Craig describe what that is Craig welcome the show. Thank you. It's great to be here.
we've seen open source take over just about every other aspect of it accept security and now we're starting to see some movement here in terms of Open Source projects as it relates to kubernetes security what is changing about the way we think about open source and security and and how should we be approaching that as a group and as a community I feel that the progression to open sources clearly happen through all of the platform pieces that lay underneath a few years back. It would be strange to say we're running Linux in any capacity and now it's just assume that everyone's going to be running most if not all of their infrastructure on top of Linux the same as largely true of kubernetes. The Assumption now is that people are using these platforms?
And so as we move further up the stack the question as well what kind of disruption to some degree but what kind of technology is going to be used and the default assumption for all new technology is that it will be open source people who are coming in from these platforms who are using Linux and they're using kubernetes more inclined to look at open source tooling. Another change that's happened because of those two Platforms in particular is the drive for technologies that can be administered and run by development teams as well as perhaps devops teams. And so there is also an assumption from those people that they're going to be able to come in and play with tools that they have visibility into they may or may not want to hack on the tools themselves, but they want to know that they can and they want to know that they have visibility into that.
So I feel that security tooling from the beginning has been driven from the top down very much a ciso kind of conversation and it's been something that is thrust upon development teams. It hasn't really provided them any kind of benefit of assume that their software was. Okay, and they had to run an antivirus platform.
They head to run some kind of security software. So am I looking at building this out as being a net wind to the developers like what can we do here to Ed? Quality of life benefits to those development teams to build a platform that is targeted to the developer to the devops person rather than a security team.
So it's trusted by the Security Professionals, but it's built in designed for the development teams. Many of us feel like we missed the opportunity once again where we have a new platform and we didn't focus on security up front. It was an afterthought.
So what exactly are you guys doing to close that Gap? And and what is this project gonna do? Yeah, the Three different parts of the life cycle that cubescape is going to take excess take action on you have your manifest violence you have the things that you're deploying into your software your yaml.
Your Helm files are so on you have the API server. You have the things that you actually running in the application and then you have the operating system. The worker nodes the things that run underneath and there have been some great software packages that have targeted one of those pieces in the past but keeps get really is the first open source platform that's aiming at all three of those that's looking at it into in system where people are able to look at the security hellistically across the estate and be able to verify not just at the time of their system being deployed but then afterwards so if someone's deployed something special something that downloaded off the internet that's relatively untrusted they're able to verify that there's no CVS or anything at that particular time.
They're able to validate their cluster against best practices from people like the NSA who are publishing guidance on how you should Harden the kubernetes cluster. And then you're also able to go later on and say well if that guidance updates if there's more information that comes out about what someone should be looking at. Then there's something continually watching the cluster and that's able to alert administrators and say all right.
Well these this is change. There's been the vulnerability come up in this thing. And this is something you might now need to pay attention to Is the responsibility for security shifting we hear a lot about the quote unquote shift left, but all the way to developers some people wonder because most developers.
I know when the security course came up as an elective. They basically didn't take it. So Or is it more a question of Leaning left?
And we're just trying to put more guardrails into say the devops workflow. So people don't make mistakes. What's their goal?
It can be. I think the easiest way to answer that is to ask about Administration and infrastructure that can shift lift or lean lift depending on your company and what it is that they're looking to do. You can have a small company where a single person or a set of people act as all of those roles by the time you get to a much larger company.
There is normally different there are normally different teams that deal with those particular functions, but it is good to be able to move that to be something that's earlier something that is either thought about earlier or at least is guarded in such a way that people don't need to worry about As we move to having more people deploy and manage their own workloads the developers who are responsible for building. Someone something are the best people to maintain it because they know what it is. There's no handoff to a different team or teams around the world.
It's best to have those people manage the software because they are the people who have the most Understanding of it but also they are the people who have the best incentive. Like if you know that something you build that you're on the hook for maintaining yourself, then you put more care and thought into how it can be maintained same. How big is the community today?
And what's your Ambitions for? It is a part of a Consortium today, or will it be part of a Consortium? What are you guys thinking?
yeah, I'm like, I could say I'm just about to stop this role and My experience is that having spent a lot of time evaluating software in the community that I'm really impressed with both cubescape and how ammo with positioning it it's something that's really easy to get started with it is part of the commercial product, but it is fully open source. And so we're looking to be clearer about the differentiation between that there is a commercial product. We don't necessarily want people to have to know about that or use it to get value out of the open source.
We also want to see people be able to take the open source cubescape project and use it with various other open source projects. I've been working a lot on istio over the last few years. We see a lot of people adopt that as a security platform.
So I'm looking in my new role as to how I can build Partnerships with other teams and how how I can make it an easy fit for people to run these things together. I'm looking at how we can grow the community of people who are passionate about having this here and let's say it might be strange to think of someone being passionate about running security tools, but having people who trust and understand that this is the right thing it is in the process. Now it keepscape is in the process now of being proposed to the cncf part of the project part of the thing.
We need to unravel there. Is that relationship between the commercial vendor? We've seen people in the past who have tried to Brand their company as being Enterprise product name, for example, and so there's no Real Clarity in terms of how to do that.
And so one of the things that I'll be looking at is how to maintain an identity is the creator of a project without necessarily being tied to the name of that project. And the way that you are you own both of those pieces yourself trademarks are tricky these days indeed. We have seen a lot of conversation about open source software Security in general.
There's been no ends of meanings and commissions you live in the open source security space of cloud native. Is there something that that Community can do to help the rest of the open source Community wrap their heads around all these issues because you know, the rest of the community is made up of outside of the Linux group and a couple of other projects. It's typically a small handful of people that are trying to figure out how to secure something like long for Jay shell and they need all the help they can get so is there something to be done here?
There's a couple of touch points and it's a bit perhaps to refer back to an XKCD comic but you will have seen the one where there's a big tower of bricks and there's one little tiny piece, which is this this piece of Open Source software is part-time maintained by someone in Nebraska who doesn't on the weekends and if that person takes the wrong week off for example, the entire internet Falls over. So it's interesting to to present let's not necessarily as a technical problem. But a it's a personal problem and it's a people problem.
This has been acknowledged by the work that's been done by the US government and it also came up in the results of the recent door survey that was published is that it's really a teams and trust issue is the more that your team is able to have psychological safety that actually correlates higher with secure outcomes than necessarily technological outcomes. and when it comes to open source software and how we keep software safe in general then large part. There is a funding question.
There are people who built a thing Etc. This is something that I like and I'm just going to put out there. They're not necessarily interested in working on that long term.
They're not building a business around it and some of those components like log4j you mentioned before some of them can become key parts of serious infrastructure. And then there is a community requirement to have those maintained it may not flow all the way back to the original person who created that it may be that companies need to look at spinning up teams for things that they work at may be that that's not sustainable. I don't necessarily feel that having The large companies who work on these or who use these projects you don't work on the pieces themselves for people who consume log for Jay.
They shouldn't all be expected to commit an engineer to managing and looking after this but with commercial software you do have some sort of vendor that you're able to go to and so I'd be interested in seeing what various organizations and government bodies do to find a way to replicate that for open source software to have some vendor body or Consortium or something which employees maintainers and is able to offer some sorts of guarantee and you can never have any true guarantee, but you could say all right. Well, we have people who are looking at this in the event that's only really these discovered. There's a place for it to be disclosed to there are people who can work on that who can get patches out in a commercial sense across the industry not just single vendors doing it for their own commercial and it's distributions, but who can look at this stuff and maintain it more for the benefit of everybody?
In your bill in a community and I think one of the issues that comes up frequently is it's great to have contributors, but there's a lot more that's needed. Right you need folks with documentation. We have guys wanted a fund some stuff.
They don't necessarily need to have their own developers. They could just you know, make a donation somewhere. So do you think people understand what it is the scope of open source project requires to be sustainable and you know, do we need to do a little more on the education there?
There's always more education that can be done. I think various vendors and people in the space have different opinions on this a lot of the work that I've done in istio over. The last few years is exactly the things that you've said, there is a great team of Engineers who are working on building them out.
That's not a thing that I'm doing Hands-On keyboard as often as I used to what I'm doing a lot more now is looking at how we can look at documentation how we can look presenting the project how we can look at relationships with groups like The cncf just led the process of getting istio transferred into the cncf. So there is a huge set of work to be done to manage an open source project outside of the effort of just writing the code and it's always good to get people involved in there and there are a lot of people who are interested in The life cycle of a project or a an open source program outside of writing the code that can be tapped on there who are willing to get involved kubernetes has done a great job at building a contributed Community around that for people who are looking to get involved in some kind of non-code fashion. I'll look to what learnings I can take from that and also my own experiences to how we build a community around cubescape, but there is always room for people who like to say that they're contributing to open source software to look at putting people other than full-time Engineers work on Project.
All right, folks. Well the wise man one said if we don't all hang together, we will surely hang separately. So Craig best of luck in your project and thanks for being on the show.
Thank you very much. And back to you guys in the studio.