Shauli Rozen, Armo | KubeCon + CloudNativeCon Europe 2023
Shauli Rozen discusses Cubescape and the importance of kubernetes security.
Transcript
This is texturung TV. Hey everyone. We're back here live in Amsterdam at cubecon continuing our day one coverage of cloud nativecon and kubecon.
I'm really happy to introduce you now to show show Rosen Charlotte is the CEO. Yep of armo AR m o so welcome. Thank you for having me my pleasure.
So let's start a little bit about your background. Yeah. No problem.
I'm you know, I've been around for a while engineer by profession kind of like did my move into the business world when I did my MBA at the University of Pennsylvania and the Walton Business School Was a Management Consultant for a while before coming back to Tech? Where is my passion? I was this I was a strategy officer for a startup called optimove which we took from like zero to 40 million dollars in a few years before actually funding armor today together with my co-founders and been doing that for the last few years really enjoying that.
What could be bad? Yeah, you know, yep. Tell us the almost story.
So I'm oh what what we're about is kubernetes security. We feel like kubernetes is a little bit of a different beast in the kubernetes or in the security landscape in the sense that many of the security decisions are moved actually to the devops and Metro the responsibility it moved to the devops not to mention the different. You know complexity of security within kubernetes with all of the different configurations and declarative motions of it.
So, you know, we are the company behind cubescape which is probably the largest of fastest growing kubernetes security open source project right now. We donated it to cncf just towards the end of last year. It's the first cubecon after that and it's kind of excitation.
Yeah, we had the first like cncf could be cubescape meeting maintenance meeting. We're like over 40 people coming which is super interesting super fun to have so it's really really exciting times. Absolutely.
So tell us about cube steak. So keepscape basically takes your kubernetes cluster scans it for misconfigurations vulnerabilities are back always access control over privileges and puts all of that across all of your cluster in a single. pain of glass for any developer and devops person to look at it is basically running as an operator within your cluster takes all the data out and makes it available to you.
We've seen it growing we have you know hundreds of thousands of users already using it. It's great to be part of that Community, you know, slack Channel active. Everybody should join the slack channel.
It's a cncf channel very vibrant GitHub Community super exciting. So let me ask you a question. Yes between you and I how much of a difference have you seen in the community?
since cubescape became an official cncf product logic so I would say that if you think the best way to look at it, I would say is volume versus quality. So it's not that the volume of the community. Exploded it was large before it is still large, but we don't see like a tremendous ramp up but we've seen more and more quality contributors and quality participants since your Johnson CF the move to the cncf slack from our own slack.
So then now the discussions there are much more deep much deeper discussions much more quality discussions. So I think that's the biggest I would say contribution that we got from cmcf and also the level of credibility, you know, we have much more credibility now as a part of the sincere love it now. You know, it used to be sort of a rare thing.
But today it's very common that you have a commercial entity. Created maintains an open source project run by Linux Foundation Foundation. Yeah, and then the commercial entity builds the commercial business around this.
Yes, sometimes it's like an open core where they're offering additional modules other times they offer it is a hosted service that's version. Yeah versus having to run it yourself other education support Etc. What is armo doing around cubescape?
So our monetization model is based as you said and I think that's the most logical one on a managed service Cloud solution. So we have developed a SAS version on top of cubescape, which is called the armor platform and uses a user can get accessibility two cubescape because all of the Clusters without the hassle of managing it installing it configuring everything. So that's the main monetization venue that we're going through.
The second one is an Enterprise version on fermententrifice version that we basically give support for we give all the you know, all of the surroundings that you need in order to run it safely and securely in your environment. fair enough and so that's offered like as a SAS type of yeah program monthly and so forth. Where is the What what not you but customers.
You know, they initially I'm gonna assume they initially download the open source project. Yes. I think they look at it.
They like it. They see it. What is it that kind of puts them over to say Okay.
I want to do the Managed service version. Yeah, so I think one of the things is that our managed service. Is also built-in twos so you have a free tier that you can sign up for free up to certain number of walking nodes and you can test it out.
So that puts down the barrier of actually moving into that and seeing that if it works for you very very low so we get thousands of users like every month joining that service and then when they see that and they love it and they increase the usage then moving them to a paid version is really about you know, you see the value let's connect and let's see, you know, how we can make it worthwhile. Excellent. Excellent So we hit on a bunch of things anything we missed so, you know one thing that I probably should mention is that we launched a new feature.
Actually, you're probably mentioned that yesterday. That'd be a good idea. Yeah, which I believe is like super important and and super relevant for users, which is basically we call it the relevancy feature which is you know, today people scam containers all the time and you scan the entirety of the container and you can libraries that you are not actually using and you get hundreds or maybe thousands of different vulnerabilities.
We identified at 60% of them actually in software artifacts that you are not using in your environment. So while we are in your environment, we know what's running in your environment. We can deep prioritize them and we actually reduce like 70% of the walk and the critical vulnerabilities and that's something that we uses asked us for and I think it's a it's a great thing that we're heading to the system.
Where did they get more information on that? Well, first of all almost that's the easiest thing to go. Let's make sure almost SEC arm or SEC Dad I am.
Yep, okay. Accidentally and what about Cube Escape? Where can they it's a GitHub?
So just Google the cubescape and our GitHub will be the first result actually go there. The relevancy feature is also available there, which is something amazing. Not many people, you know do that and contribute to the open source such Innovative things, right?
So I really recommend you to check it out. Excellent. Hey, thanks for coming on Pleasure the rest of Uconn.
We're live in Amsterdam. We're gonna be right back with another guest and just a hot minute here. Stay tuned.





