Fahad Rizqi, Tigera | KubeCon + CloudNativeCon Europe 2023
At KubeCon, Fahad Rizqi discusses how the adoption of Kubernetes is increasing and how network security is becoming paramount as applications move into production.
Transcript
This is texturing TV. Hello and welcome back to kubecon plus Cloud nativecon Europe and we're talking with Fahad risky who's from Tijera and they're the drivers of the Calico open source project for networking and I feel at least that we've been talking about networking in kubernetes environments for a long time, but it's coming into its own now. We're starting to see enough clusters be deployed in production environments.
So what's your sense of what is the current state of maturity around networking in these environments? Yeah, no, that's a good question. So what we're seeing obviously is as more and more companies are adopting, you know, kubernetes environments and these environments are scaling now and more and more production workloads Mission critical workloads are being deployed.
So as that adoption is increasing both the networking and network security piece is becoming, you know Paramount as not just a day, you know day one problem but Day Zero problem that they're trying to solve for so everything from networking network security to all the other security pieces that need to be put into place in order to ensure that these production workloads and Mission critical applications our secure right? So so that's that's what we're seeing. It's it's becoming front and center as these applications are getting into production.
Where does Calico fit in the ecosystem if I walk around the show floor? I see everything from Ingress controllers to application connectivity service meshes in there. And then you guys essentially have at least in my opinion a network overlay are these things alternatives to each other or they complementary and you know, what what consists of the networking stack might look like?
Yeah. Yeah, so, you know from me networking and network security and security perspective. Yeah, you'll see a lot of different companies here that are providing different components of of the stack from a from our perspective from a catalogical perspective.
Obviously Calico is known for providing the the networking and network policy piece. But what we've done now with Calico Cloud, you know, it's our offering called Calico cloud and Calico Enterprise we've taken in you know, several steps further where we have now brought in. Those different security components into one place and essentially what we're seeing there is what we've done there is become a One-Stop shop Plug and Play solution for all your security needs for your kubernetes environment.
So everything from network security to build time security runtime security and deploy time security. So we provide a One-Stop shop Plug and Play. So we've evolved Calico from just a networking play to you know, like I said from network security build time runtime and departime security as well because all of those components are not part of the stack and it's just not just about networking anymore.
You got it. You know now you have to be able to secure the entire infrastructure. Same question on the security front I can walk around here.
And there's a three dozen Point products, right? Is security and network operations converging now essentially and that makes it easier for me to kind of manage the whole thing at a reasonable cost. But from your perspective, are you seeing customers actually doing that?
That's a great question. Yeah. Absolutely.
We're seeing that you know, we're seeing this across the board really where you know, a lot of companies especially the companies that are they don't have the expertise because right now what companies are running into the issues that companies are running into is not being able to hire people fast enough, you know you and and not having people with the right expertise either and then when you do hire somebody then being able to enable them and get them trained up so they prefer someone to come in and you know, take that entire piece off of the table for them and say okay the the networking and the security and the build time runtime deploy Time network security, you know become that One Stop Shop and take that headache away from us, right. So we're seeing companies absolutely do that right now. What makes networking and kubernetes environments different from traditional networking because I think a lot of folks have some understanding of traditional networking with kubernetes has some nuances to it.
So what should people be aware of? Yeah, that's that's a great question. So from a networking perspective, obviously, you know now you're dealing in a completely different realm from your traditional networks, you know, you don't have your you know static IP addresses.
Everything is dynamic everything all your IP addresses are ephemeral. These workloads are ephemeral. So that provides a different level of complexity when it comes to networking and network security.
Right? So, you know, your traditional architectures that you have they just don't work in this in this environment anymore. So what a lot of times what companies want to do we see that is they say Okay.
I want to extend what I'm doing on my traditional networking into the kubernetes environment. And that's where we come in and provide the education to these customers to say to a lot of these companies and say look, this is the this is how you should be doing it. This is how other companies are doing it because it is a completely different mindset on how you need to You know approach the network security and the networking and and the security piece of it.
We talked about the convergence of networking and security but it also seems like networking itself is being more tightly coupled to devops workflows and you're starting to see devops teams kind of programmatically managing Network Services alongside everything else. So is that a trend we should expect to see to continue. Absolutely.
I mean, especially in companies that are say more mid-sized to smaller companies where you know, they don't have a separate team for say, you know, there's no separate platform team or networking team and a separate security team where these teams are a lot more closely aligned in smaller companies or there's one team that's kind of doing it all on the devops side. They're doing the platform side. They're doing the security side.
They're doing the networking side. And so a lot of these teams now are responsible for doing it. All right just being able to do the networking part the security part and the network, you know the network security part there as well.
So you we're seeing that across the board where now because there's just one team kind of doing it all they have a more holistic view of what needs to be done from start to finish to secure that workload. The perception is is that kubernetes is hard and that networking's even harder still is this becoming more accessible to mere mortals? Absolutely, you know that's where you know companies like ours, you know, like tigera come in and you know make it accessible and easy for them to be able to do the the networking and network security part because yeah it is it is it is hard but you know, we've as a company we've accumulated, you know, six years of doing very complex and deploying very complex kubernetes networking network security and security projects unlike any anybody else at large companies midsize companies smaller companies.
So we're able to bring those expertise to these companies and say this is how you should be doing networking. These are these are the best practices right? So Once your best advice to folks in terms of getting started what have you seen customers do that?
Maybe others might find in advisable or their tips there you can share that. So it says hey this is how to get this done a little more. Faster and reliably.
Yeah. Yeah, you know obviously, you know, I can talk about that all day but you know, you know a few things that you know, like I said, the one number one piece that everybody all customers are running into is just not being able to find enough people have the expertise on staff to be able to manage and deploy, you know in complex kubernetes environments and so, you know being able to come to you know One Stop Shop type of solution to kind of help them with, you know, get help them get started. You know what we see with our customers is, you know, they'll start off small and you know with smaller products non-prod and production clusters and then this truly start applying non-production workloads, and then they start to apply production workloads as those expertise get, you know, they increase their expertise and you know, we also do see that people underestimate the complexity.
Also overestimate the time to deployment and that's where you know again tiger comes in and helps them with that because we have those expertise. We have that knowledge base to be able to help them with that day zero day one problem of being able to deploy and then security becomes a big blocker for them right because you cannot go, you know, the question that comes to them before they deploy production application is what about security? How are we going to secure this environment?
And so what the one of the mistakes that we see people do is they don't think about security from a day Zero perspective, right? They have to start thinking about security from a days. You're a perspective.
They think about security as a day one day two problem. And so that's they get blindsided by that and my advice would be start thinking about security well in advance of you know, as you're designing your your clusters think about security holistically from that. Are the bad guys starting to find cruises applications?
I mean, you know, we've been thinking about security as an afterthought for a long time and I think we build the apps. But yeah, it seems to me like the apps that are being deployed on kubernetes are kind of high value targets. They are they are and as more and more Mission critical production applications are starting to get applying on on kubernetes environments.
They are a hundred percent becoming targets of the the bad guys out there and we'll see, you know, I predict over the next year. We'll see more and more news coming out of you know, breaches happening because of you know, folks targeting kubernetes environments. So that is 100% happening right now.
All right, folks. It's been a long time in coming but networking and security and kubernetes land is finally happening Fahad. Thanks for being on the show.
Thank you. Thank you for having me. All right, and we'll be back in a couple of minutes.





