Kyverno – Jim Bugwadia, Nirmata
As cloud native policy management project Kyverno approaches turning two, CNCF has moved it from sandbox to incubating status. Operating and maintaining Kubernetes is complex, and that complexity compounds with the disparate components that make up the modern cloud applications many enterprises find mission critical. This often leaves companies struggling to make additions to crucial areas like Kubernetes governance and compliance capabilities which reduce exposures to policy violations and potential data breaches. To address these pain points, Kyverno was launched into open source. Alan gets the scoop from Jim Bugwadia.
Transcript
This is texturung TV. Hey everyone. We're back on text junk.
TV here, I've got another great interview. I want to introduce you to the CEO of a company named nermada. His name is Jim baguardia.
Hey, Jim, welcome to text John TV. Thank you. Alan pleasure to be here.
Yes. So Jim, you know what, we're gonna get into modern and a bunch of stuff in a second but let's start with you. Why don't you give maybe a quick background on your own story to our audience?
Absolutely. Yes, almost software engineer and you know, my career has been in the Telecom Network management type of space. So that's where after graduation work that company is like Bell Labs Motorola working on, you know, managing complex systems and telephony wild wireless networks.
But of course as the internet came about and as we moved into distributed systems kubernetes what we myself and my co-founders that they're not what we focus on is managing the complexity across kubernetes deployments, right? So we see that as the new infrastructure and the way systems will be built from now on. Well certainly kubernetes in the whole Cloud native stack.
If you will has become the new the new compute stack, right, especially in Greenfield situations with New York, you know new application, but even Brownfield people are migrating to a kubernetes. I actually did a session that we recorded for our up down upcoming. I don't know if by the time people see this but August 10th, we have Cloud native content Cloud native event virtual that we're putting on a text wrong and our keynote was a fireside chat.
I did with Tim Hawkins one of the original kubernetes right members over Google and one of the things we really spoke about is kind of Fleet Management and more. a complex wood distributed kubernetes deployments right more clusters and you know, it's it's a big difference between between having a kubernetes cluster or two or kubernetes, you know a couple of instances versus a full-blown Enterprise scale engagement and but that's also a sign of that market maturing and Cloud native really becoming the new compute stack Jim. You mentioned the company's name was nomada.
Why don't you give us a little background about nirmada, right? So by the way in their Mata means architect in indoor and language, right? So we thought it was fitting for what we do in terms of distributed kind of system and a control plane for distributed systems.
So nermata is in the kubernetes governance and acts as a management and control plane. And what we envisioned is, you know, ask kubernetes mature that there would be kubernetes tax across data centers cloud and Edge and just like you mentioned the problem is really shifted from how do I bring up that first cluster? How do I manage hundreds or in some cases?
Even thousands of clusters across different geographies, right? So if you kind of think of this as a vast Network and you have applications that you want to manage across these set of infrastructures the governance and the management of that becomes very complex. That's what we you know set out to solve and that's what we're solving at nirmada.
I love it. Jim well, we can talk more about no matter in a little bit, but you know one of the Central kind of themes around no matter you guys have not sponsored. I don't know what the word is.
But you you've gotten behind or were you the original developers of an open source project? Right Vernon. Yes, and that could and that project governor was become part of the CNC Apple.
What was it about two years ago now three years ago. That's right. It was November 2020 when we donated it.
Yes. Yep, so coming up on two years and it recently and look our audience is pretty cloud-native Savvy. They get the whole sandbox.
You know graduating kind of thing. So Governor actually recently had a graduation over at cncf, correct? That's correct.
We graduated from sandbox to incubating. Which is a you know, what's in a name, but it's a big step. It's a big step at cncf.
Right and I don't want to put you on the spot, but can you like what is the what's the difference? Yeah boxes great question. Right.
So cncf of course is the governing body behind kubernetes for me tears Lincoln the Cross Plains Argo CD several other projects like that wasn't several like 40 42 or something. Yeah. So and then you know, the the process of becoming a cncf project is of course the TOC the technical oversight committee has to accept projects and to sandbox so they have to align with the mission of cncf but sandbox is a fairly, you know, I wouldn't say easy but fairly, you know achieveable phase.
But once you're in sandbox, then the project is kind of measured on a number of different attributes and criteria and there's some criteria or fairly stringent criteria from getting from sandbox to incubating and once once you achieve incubating, you know, the next PATH is graduated which a few projects like of course kubernetes and Prometheus have achieved but today out of the hundreds of you know, companies and projects and different folks in the cncf. Maybe there's a handful of like 20 to 30 projects which are in that incubating phase. So what that means cncf now A project they have done some due diligence on it in terms of production users behind who are you know, what vouch for the project and you know, they see a clear need for that project to exist within the cncf landscape.
Yep. That was great description of it. And thank you.
Let's talk about the project itself though. What would you do? Yes, the governor is a policy engine designed for kubernetes.
Right? So like I mentioned, you know, when we started nirmata and as we built out our management plane, one of the things we saw is that in kubernetes first off you have several different roles, right? You have developers operators security teams all trying to make sense of how to do things in this new way.
And we saw policies policies expressed as a digital construct being essential to bring all these roles together. So we often talk about devops and deaf secops, but why not codify that and express that in a policy which security team can also manage and you know kind of have their view on but then developers and others are provided that guardrails automatically. So the You know kind of innovation we brought in with kiberno is we said well policies are not just for enforcement and validating configurations, but they can also be used for automation.
So right from the beginning caverno was very good at being able to automate configurations based on certain triggers. So now kubernetes becomes programmable by security teams by operation schemes to say if you know, I create a new construct like a namespace maybe certain things have to happen and that becomes repeatable and automated so really to scale kubernetes. We saw the need for policies as being part of the building block part of the stack much like you need networking and compute and other elements and keverno became you know, the solve this need becoming something native in kubernetes for policy management.
Got it. since fantastic now Of course. no matter right Where do you take?
Where do you take it next right beyond the open source? Yeah, so Governor sits inside each kubernetes cluster as part of the control plane. So it acts as an admission controller and also does periodic background scans.
It's really running in each cluster. Now again, if you have this Fleet of clusters, what you want is some Global policies and then you want to build things like compliance standards Etc on those policy building blocks. So that's where their mother fits in our focus is kubernetes governance and policy management for multi-cluster multi-cloud, you know, which includes of course Edge and near Edge type of deployment and that's what nirmada provides as a SAS and cloud-based solution.
So you're providing converter is a SAT space solution. Number one, right? And then number two you add some premium functionality for large clusters.
And and deployments in kubernetes deployments, correct? Exactly. Yes for solving problems.
Like okay if policies are managing my security and my automation, how do I make sure my policies are working? How do I get the auditing and reporting for that? Right?
How do I achieve my compliance? And those are the types of problems? We solve through their mother.
Got it. And then I don't want to get too far in the weeds. But just how is that packaged and sold and I mean, it's a SAS.
I assume people have come to the website and sign up for it. Exactly. io.
There's a pretrial to get started with if you have give or no it automatically detects, you know Governor running inside your clusters and immediately start showing you, you know reporting on it like things like ball security to even you know, CIS benchmarks do things like compliance at NSA hardening guidelines for kubernetes ETC. So you immediately get a sense of your posture how good you're doing with your clusters and where you could potentially improve and of course, you know for larger deployments we have other form factors, but the primary enablement model is just through that extremely easy to get started and we also offer like, you know Enterprise, of course. important not just for the governor engine, but all of the other portions required including a curated set of policies, which most Enterprises will need to get started with excellent websites for all of these things the main source of information for kivarno so we highly encourage everybody, you know using kubernetes to go check that out and join the community.
The cncf is a very warm and welcoming community. So come say hello and you know would love to see folks in one of our next upcoming meeting Portland tomorrow com, right so you can find information including our trial access over there. So I just want to make sure we get these right because people are listening.
They don't know neur matter is n i r m a t a drum. Yes. com for the SAS and and premium functionality on top of kuberno.
That's right. Excellent. Jim.
It's been a well. It's up. It's been a few months since gubernet kubecon over in Valencia.
Where looking forward to Detroit. I think in October his teachers, right Rock City any new news from no matter other than the graduation that you want to Maybe you look lots of exciting announcements coming up. But for the governor project as well as nirmata for kiverno, you know our road map, of course, it's public so I can you know, discuss that it so we are looking at features like yam old signing which will be add another layer of security as well.
As you know, bringing in the concept of identities and approval just certain key workflows. We're also have some Integrations which are further improving on the software supply chain security side. So some really good set of features give her no the community is driven by a lot of end users.
So always looking to kind of improve and extend their matters stay tuned. We will be in announcing more features, of course around the kubernetes policy and governance space. Actually, well look we're planning on being in Detroit, you know live.
For kubecon, I hope to see you there. Maybe we could sit down and meet in person and continue the discussion. Would love to thank you Alan.
Alrighty, Jim baguardia CEO co-founder at Norman or the people behind Governor or well the cncf project now a incubated cncf project, but go check him out. Caberno Denio. com Jim.
Thanks for being here. We're gonna take a break on Tech strong. We're going to be right back.
Thank you.