Kevin Bocek, Venafi | KubeCon + CloudNativeCon Europe 2023
Kevin Bocek, VP ecosystem and community for Venafi, discusses AI generated code, the omnipresent cloud era, the rise of the platform engineering team, and more.
Transcript
This is texturing TV. Hello, and we're back at kubecon plus Cloud nativecon Europe and we're talking with Kevin bochik about workloads in there identities Kevin. Welcome the show Mike great to be here.
We're closing out the show. It's this and then beer this is the last one you're standing in between me and appearance and I'm you guys announced that the show and ability to attach identities to work loads. What does that mean how to that maybe help with the whole zero trust conversation?
Yeah trying to have yeah, you know walk me through what's going on with this. Well, when you think about Cloud native, I like to think about as like identity require technology because it's been built to run anywhere. Your cloud my cloud their Cloud which means that we got to know what's good or bad friend or Foe and that all comes down to Identity which in the case of machines as machine identity that's things like TLS certificates spiffy IDs codesigning certificates and what we announced today was Firefly.
It's a new product venify Firefly and it brings machine identities closest possible to the workloads close as possible to the applications. What we see is developers and engineers. They've been trying it to do it the old-fashioned way.
They've been trying to make their secrets manager. issue certificates that are close to the application that may be even tried to use an old-fashioned pki That's slow. It requires lots and some infrastructure.
It requires managing State and Firefly now makes it easy. It's the name says Fireflight comes and go so it's a machine identity issuer that issues TLS certificates spiffy IDs. You can spin up 50 a hundred a thousand of them.
And they live only as long as the workload they actually only run in memory. So they come and they go they issue you're able to use those identities for authentication like Mutual TLS authentication if you can use it with service mesh. The great thing though then is all for the security teams because security teams have been a bit in the dark actually really in the dark when it comes to Cloud native identities Firefly dust doesn't make it easy for the platform teams to build.
It gives the security teams the observability now and policy control. So they get to bring the same Enterprise policy that they've been using and traditional workloads or web services and Firefly automatically inherits that it gets it actually from the control plane that's running in the cloud so developers love it security team is sitting back with smiles. So is this specific to Cloud native workloads?
But so there's an also work with Legacy workloads and monoliths and whatnot or is it really about microservices and those types of workloads that we aren't kubecon but there is a world outside of guptcocking. Yeah, so it works not only in a kubernetes cluster not only works with service mesh, but it can run anywhere that a Docker container can run so that could be as an Amazon Instant. It could be in Azure.
It could be running back in your data center. At not just in kubernetes and we support so the engineers here are going to get Smiles we support grpc graphql and rest interfaces and addition to it works with istio. And also with cert manager cert manager is the de facto way that you get certificates inside of kubernetes.
So yeah, it works there and everywhere else. Will we get a more resilient approach to certificates because every now and again you'll hear a story about somebody didn't renew a certificate in the whole thing crashed and it was because of some renewal issue. So in your approach, can I automate that process a little bit more?
Can I make sure that the certificates are running and that they're up to date? Hey, I used to be a software engineer and let me tell you I wasn't dreaming of machine identity. It's a certificates on the weekend.
So yeah, it absolutely brings a more consistent more reliable and actually safer experience for the developers but also for the security team because they get one way of now bringing a machine identity issuer close to the application whether that's in kubernetes. Or in the cloud in the data center, so you can spin up fireflies wherever you want to the architects now, they're happy because fireflies work. Yeah with my service mesh.
It runs with my Mutual TLS applications for authentication in the cloud. All one way but multiple applications. And that then means more reliable because it brings the policies from the control plane that the security team have set up.
That actually now they're going to support so the configuration errors the expirations go away. But also too if you think what our security teams really worried about they're worried about unauthorized access. So the the policies now around authentication that these identities are used for like TLS certificates with mutual TLS or spiffy.
Under the control of the security team. It's approved so that risk now of unauthorized access goes down and it goes down even exponentially more because fireflies only live. For as long as the workloads live and that's something that's really really different and the past with the secrets manager or maybe old school pki those certificates have lived.
Well beyond the workloads which opens the opportunity for an adversary to get them and get in. Everywhere you go. Somebody is talking about zero trust and everybody nods their head as if they know what that means and what it's about but it's not really something you can go out and buy per se it's more of a philosophy is when you peel it back though.
It seems like identity is at the core of zero trust. So do you think that you know, we're really doing is moving beyond traditional network security at the perimeter level and getting more granular down. Even the workload identity.
Is that part of what's happening right here? Yeah, I mean zero trust is just always authenticated down all the way down as you can just post as possible to the application and that's what Firefly is absolutely meant to do bring the identities as close as possible to the application as possible. And also make it easy because that's what Architects consistent Engineers really want.
So it's a big enabler for zero trust. It allows you to get now always consistent authentication whether that's your running in kubernetes, you're running a service. Mesh.
You've got Cloud workloads that are using Mutual TLS. Yeah, it's consistent and you're then you're not opening the door though because I could think oh, yeah, I'm gonna bring certificates to every workload. But then you use an old fashioned way of doing it.
That actually could open the door the possibility for more risk, whether unreliability from things like expirations or an attacker finding them. Well beyond the workloads life and yet Firefly as the name implies comes up goes away and big big zero trust enabler. as we kind of work this through Who's in charge of this stuff these days?
Is it the developers or the security teams or somebody else for that matter who's leading? The charge? Ultimately the security team is responsible because they're responsible for security.
That's their job their responsible for defending the business. The engineers and platform teams are making decisions about technology to use do we use cert manager? Do we use istio for service?
Mesh what flavor of kubernetes we're going to use openshift or we're going to use eks and Amazon or All the Above. And the security team then needs to make sure that that's safe. No security team is going to make the decision about yeah, which flavor of kubernetes to use that's going to be the engineering in the platform teams.
So security has to be is accountable and responsible for making sure. The identities are safe. The containers the workloads are authenticated that's their job.
And yeah Firefly really fits with that. I think the thing that the challenge is though for security teams is the technology is changing so quickly look at the projects that you see here at the cncf. There's a new project that seems All the time every letter in the alphabet more that's a that's really tough for security teams to keep up with and so they're hungry to find ways to first get observability.
Just what is being used. And then how can we bring policies that we've been using with keeping the business safe? In to the cloud native environments and that's what we've been working on with firefly.
So we'll be working also on with our offering TLS protect for kubernetes get visibility First for security teams get policy control, but don't change what the platform engine teams are using let them use what they love. As you think this through for a minute. You describe the identity sits travels with the workloaders essentially, you know workloads don't move all that often, but when they do move, it's a pain.
Right? Right. How does it do that?
How does the identity remain attached to the work? Right? So you're issuing identities to work loads and the old-fashioned way was that you have an application here and the issue of the identity would be all the way back in the data center across networks.
And of course, it's just some writers certificate Authority somewhere and those would live for years. I mean certificate Authority so fashioned way or measured actually in decades, you know, so the idea now is in what Architects and platform teams want to do is not only do you get the applications the workloads but all the services that enable them get those as close as possible. So for example with firefly when your workloads come up in kubernetes, they're requesting.
Machine identities TLS certificates your service mesh is making requests inside of the control plane for certificates. And then you might have yeah applications that work out in Google cloud and they're using something like grpc to talk with firefly, but it's it's literally right next to can even be in the same cluster. Issuing those machine identities and that's something really different than in the past.
We have to go all the way back back in time like a time machine back to the 1990s. So how does that certificate get recorded if it's close to the workload and and the app and how do I how does something externally validate the certificate? Yeah.
Yeah. So fireflies when you spend them up, they connect back to the cloud control plane the venify control plane, they registered themselves and then they become authenticated with an issue where an issuing certificate that all gets recorded back in the cloud. And that establishes then authentication because it comes actually Enterprise approved all of those different places where you're going to be performing authentication actually already has those trusted certificates.
So yeah, that's how fireflies can spin up and down. And when they go away yet, they're no longer able to issue identities for authentication, but all of that it's recorded in the cloud and distributed out to Applications. All right, folks, you heard it here fireflies of the new way to manage certificates Kevin.
Thanks for being on the show. Thanks. Mike.
Great to see you and see you. Hey guys. Thanks for spending the day with us.
It's been an awesome exciting Adventure in terms of content and the new ideas and new thoughts and guess what? We're gonna do it again tomorrow. So tune in we'll see you guys later.
Thanks for spending the day with us.





