TLS Protect for Kubernetes – Shivajee Samdarshi, Venafi
Shivajee Samdarshi, chief product officer at Venafi, talks about TLS Protect for Kubernetes which enables security and platform teams to easily and securely manage cloud native machine identities, such as TLS, mTLS and SPIFFE, across all of an enterprise’s multi-cloud and multi-cluster Kubernetes environments.
Transcript
This is texturing TV. Hey everyone, welcome back to text drunk TV. I am happy to have it's the first time he's been on Tech strong TV, but in talking off camera, we realized we've known each other for it's probably eight maybe ten years even something like that a long time because that's the way the security World works.
It's kind of Six Degrees of Separation. It's pretty tight Community. I want to introduce you to Shivamji some Dosha some Dashi and I mispronounced it.
Say it right for us. Shivajee Samdarshi. And watching some dark sheet.
Okay, that's right. So from Darcy and I originally met each other some dark she was was it VP of engineering or CEO with white hat maybe of engineering at at white hat white hat security which of course was bought by Antietam. I'm not here to do a history lesson.
But white hat was one of the very first companies that brought pen testing as a service if you will what you know, right right to it made very popular for everyone to be able to do pen testing and it was a kind of a watershed. moment in the security world, but you're now it at venify venifies the company that I think most of our audience maybe if it's at least have heard the name they've been around a while leader in in identity, especially machine identity type of certificates and and security but I can't tell the story. Why don't you tell the story?
Thanks, Alan. Yes, so just stepping back and you know identity. I think all of us, you know that has inherent to who we are just as as people and so we understand identity very well, but we understand it as United most of us, right everyone's kind of, you know, making travel Arrangements logging into a travel site using their identity checking their email.
So it's pervasive you don't even necessarily think about it. But if you think about what's going on in the background and in the changes that have happened over the last 20 years more and more machines and machines more broadly. The definition of machine is actually quite broad.
It isn't as you think about, you know, physical Hardware virtual Hardware containers Services. These are all machines that act on our behalf to Make our lives easier. Now what we don't think about it is that when these machines communicate with each other to perform tasks that we want automate activities.
How do they identify each other? So the notion of identity is inherent even to machines. It's just something that we don't see every day.
So don't think about it. But for those of us who are in the business of running platforms of you know, making sure that the infrastructure is up and running to support more applications. I identity and machine identity is something that is key.
We that is just inherent to how we build and secure modern applications. And so Something that is not super visible, but machine identities are everywhere and over the last 20 years. Alan is you know, all of us who've been in the industrialized that the proliferation of machines compared to let's say human beings.
We think there are lots of evenings on Earth and you know, it's growing our population is growing but nearly not as fast as the number of machines are growing and the types of machines that are growing which means machine identities, you know, the numbers are just exploding and just like we think about Humanity's and managing them and securing them. You've got to think about machine identities as well. That's why it's so important and verify is a Pioneer in the space from the early days of you know, at each effect.
You can think of infrastructure as modern at that point in time and it keeps getting modernized we've been present right from the day when this category did not exist and people didn't think about it as a category to now when it is pervasive and we are the category leaders creators and leaders in the space. And you know here is where we are now. It's a it's a concept that is exists.
And it's you know, it's well deployed. Absolutely. Well, not only is it well deployed and it is a kind of you the sheer numbers of machine identity, you know Dwarfs.
people, you know individuals identity and and so when you dealing with that You know big a number you have to do something about it, right? You know, what was the number? I saw recently iot devices by 2030 55 billion or some number like that.
Right a crazy number and you know, what a lot of people I think don't realize is like in the world of cloud native. Right where every single instance every single container. Has its own unique identity its own unit.
It needs its own protection. So when we think about microservices architecture you know and and the whole Cloud native way of You know developing and deploying and operating software. The amount of machine identities involved there is just I mean it blows up rather quickly very quickly.
And that's the change that's happened over the last few years and you know, there are some differences that unlike human identities machine ID is also very ephemeral right and certain classes like you're talking microservices, but they come and go. Yeah. Sorry, the average container is is about five seconds or something is what I remember hearing right very very small, right?
Yeah, and so they you know, how do you manage and what do identities mean that word because it's still important that when a you know in that world a service is talking to another service that you know that the service you're talking to is trusted you have to establish that in very, you know fraction of second. Sure. Sure.
I guess that's a good segue. You guys really identify recently came out with a new product a product announcement. Share if you can with our audience.
Yeah, that's a exciting launch TLS protect for kubernetes. Again, if you think about at modern application infrastructure, you know, perhaps a few years back, you know, kubernetes was kind of on The Cutting Edge now, it's well accepted and deployed in all of the modern organizations. I don't think if you were to go talk to a bank or a healthcare provider.
Everyone has deployed kubernetes. In fact, we have customers who are retail customers who are deploying kubernetes even in their stores. And so think about a point of sales system that's running community.
So very widely deployed. The offering that we brought to the market is if you think about the security Persona within modern Enterprises, they are responsible for the security posture of the organization. Historically super comfortable with understanding load balancers wax, you know VMS and managing that because that at one point in time was the modern infrastructure that supported the applications that drove the business.
Well, the modern infrastructure has become more virtualized and become containerized and is now moved on to kubernetes, but typically the audience that's standing up the kubernetes platform is it and you know is the platform engineering teams Within These large organizations and their responsible for not just that, you know standing up but operating it and also Forex, you know, making sure that it's secure the challenge for the current security personas within large Enterprises that they do not have visibility into machine identities in kubernetes, so You know, we have some very large customers in finance Healthcare and they're what we see is. The security personas have a good understanding of machine identities within at the Enterprise that I would say on classic infrastructure. but when it comes to communities and the modern application infrastructure They don't have as good visibility or policy controls over that.
So this is really this offering is really about Bridging the Two Worlds making it super simple for the security audience to get visibility into the modern application infrastructure at the same time ensuring that the platform engineering teams can continue to comply with the security policies of the organization get the applications out quickly without slowing down. So the this offering kind of brings Machine identity management to the kubernetes world connects the security audience with you know, the modern application infrastructure. And so this this is a you know, a tremendous kind of extension of capabilities that the security audience already had on their existing infrastructure, and now expanding that out.
So that's what You know, it's also I think a sign of the continuing maturation of this Cloud native microservices kubernetes. Infrastructure, right. That's right oftentimes.
Unfortunately security is kind of a trailing indicator rather than a leading indicator, but the fact that you know, the leader in machine identity is now focusing in here and having this type of offering I think. Helps legitimize that look this is this is a big Market. Absolutely.
People are doing it now. And and you've got to be security cannot be an afterthought all of us. I can bet you all our audiences here have been affected by one breach or another at one time another right?
And so this is not something that's an afterthought cannot be no cannot be is right. so let me turn to business if I can. How is this package sold offered by then if I how do people engage with it?
So this is you know at multiple levels first something that I should mention is. It's built on a foundation called certain manager. So if you were to go to any platform engineering team, I mean I can say that with Fair bit of confidence because even in my previous life, you know, when we were notified my previous life when I was building an as a service one platform at let's say white had security certain manager was one of the foundational elements for managing the life cycle of certificates within kubernetes cluster already well adopted accepted and that's the case today.
It's open source. We are the creators and contributors, you know offset manager to cncf so now it's part of cncf and so we'll accept it as part of the kubernetes standard architecture if you will. Already present everyone's using it whether think about it not they're using it every day.
It's in the open source realm. So it makes it very easy to adopt and use. So TLS protect for kubernetes is actually built on top of the capabilities that the open source cert manage all you provides.
So that's kind of the foundation that exists and is adopted already. So nothing that most platform engineering teams need to do they're already using it. So what we've done is built and as a service set of capabilities That provide the security and the platform engineering teams the convenience to connect.
They can have both visibility a security teams can have visibility into issuance of certificates and also can specify policies that comply with the Enterprise, you know security policies and then connect basically certain manager with the set of capabilities are you know on the cloud and these are as a service capability. that now you can connect them get visibility into your cluster and also provide policy controls over what certificates get issued in the cluster or on the Ingress, so Two components one as cert manager and then the other is the as a service components. So they consume it as a service really the short answer on this Allen.
Excellent. com. com and you can kind of try it out and that's now we've got that out of the way.
Plans, right we've been talking all morning with guests here today around RSA any plans for venify at RSA that you can share. Yes, so, you know, we will be meeting, you know, our customers and partners, you know on the sidelines of RSA. We will be you know, TLS protect for kubernetes is going to be actually keep part of that conversation because I think for most our customers prospects they already know and understand what the value we provide for them broadly.
This now extends our each into modern application infrastructure. So this is going to be a big part that conversation that we're going to have. You know, I'm just thinking off top my head but actually the week before RSA.
I'm gonna be in Amsterdam. For a cubecon cloud nativecon, which is of course the big conference for the whole kubernetes and Cloud native. I don't know if I don't remember seeing venify there in years before if you're planning on being there.
So so the reason perhaps that you haven't seen it is that we acquired cert manager and the court Technologies through jet stack and just yeah, so perhaps that's why it's not popped up but you will see us visit the cert manager Boot and we are you know, we are present. We have a fairly robust presence there. So yes going forward you'll likely see us as benefit but we've been present but just under a different kind of name got it.
Well, we will be doing live videos and both of those events and then I guess it'll be next fall is you can't cloud nativecon in America. I think it's in Chicago. Come see us.
Yeah. Well come see us and we'll do a little video while we're there. It would be great to see you in person again.
Yes. Absolutely. Yes.
All right, my friend. It's fantastic to have you on here. Go check out the new cert manager kubernetes TLS from venify.
We're gonna take a break. Text Rock TV and we'll be right back.