Secure Kubernetes Access with ngrok’s Alan Shreve at KubeCon Paris 2024
In this interview, ngrok founder and CEO Alan Shreve delves into the world of secure ingress into Kubernetes environments. Learn about the essentials of Kubernetes Ingress and the capabilities of our newly introduced Kubernetes Gateway. Alan explores the driving forces behind the Kubernetes Gateway API and the critical decisions organizations face when selecting it over Ingress Controllers. They also discuss ngrok’s use cases in both development and production for delivering apps and APIs.
Transcript
This is Techstrong tv. Hey everyone, it's Alan Shimmel, tech Strong tv. We are live from the beautiful city of Paris in springtime here at CubeCon EU or CubeCon Europe.
And, uh, this is supposed to be the biggest cute con ever. I was talking to some of the CNCF folks last night. They're expecting around 13,000 people for, uh, this week's event.
We're excited to be bringing you, uh, our coverage live this week, right from the show floor as usual. Um, our first guest, we've had him on here, actually a cube con in, uh, Chicago last time. Maybe we did Amsterdam too.
Alan, Uh, I think we did. Yeah. Yeah.
He's, he's a, he's a Cube con regular for us. Yeah, my friend Alan Shreve, he's the CEO of N Rock. That's Right.
It's a pleasure to Be here. Got, yeah. Alan, it's great to have you here.
Um, Alan, let's start off, not everyone out here is going to be familiar with roc, so before we talk about anything else, let's kind of settle that. Yeah. So, uh, ROC is the unified ingress platform for developers.
Uh, ROC uh, basically allows, uh, developers to create ingress into their Kubernetes clusters, uh, and, and any number of other clusters as well. Yeah, Absolutely. And your CEO, um, you've been at a, a few of these already.
I know it's early in the morning, day one, but what's been your impression so far of, of this Cube card? Uh, you know, uh, just really just got here and, uh, it looks like there's a tremendous amount of energy, uh, really excited to be here and, uh, yeah. Looks like a, a beautiful venue and a beautiful setup.
It, it certainly is. And, you know, we are, we're in the middle of the show floor. People are buzzing about.
I it's gonna take me a little while, I think, until I could kind of form some opinions. Sure. Anyway, Alan, let's talk about Eng Grock.
You guys really had some news that you're announcing here at Q Con. Share with our audience if you can. Yeah.
Uh, so we're very excited to be launching support for the Gateway, API, uh, the gateway. API is, uh, a, uh, news specification. Uh, it's, it's one that's been worked on for a while.
Uh, the most recent set of core resources for it, uh, we're, I believe, finalized, uh, around CubeCon Chicago time. And, uh, it is the successor to the well-known, uh, ingress, API. Yes.
And, uh, yeah, we're, we're really excited to be launching, uh, support for it in, in n Rock's prop. So when we say support for it, there's support and then there's support. Sure.
You know what I mean? Talk to me about the, the level of this support. You know, is it true API to API integration?
Is it, you know, exactly. What do we mean by that? Yeah, Of course.
Uh, so our, our initial support for, uh, the Gateway, API is, uh, just a, a developer preview to begin with, uh, which means we're supporting, uh, the majority of the core resources that are required for an implementation. Uh, and then we will be adding, uh, in the next, uh, couple months, uh, some additional support for some more of the extended, uh, pieces of the gateway, API, uh, including some custom extensions that work with, uh, some of our functionality that, uh, Eng Rock allows you to layer on to traffic as it enters, uh, your network. Very cool.
Very cool. Um, now is, it's great that they, you know, they're, they're kind of upgrading the ingress API to this gateway, API. What do you hear from your customers about that, though?
Is this is like a must have a killer kind of thing, or kind of Okay, nice, nice to have. Yeah. Uh, what we're seeing is really, uh, a lot of interest in the Gateway.
API, uh, customers, uh, are excited to be like early adopters of the new specification. Uh, specifically there are, uh, new, like the, the new API, the gateway. API is more expressive than the ingress API, which means it allows you to encode more capabilities into, uh, the objects that you create.
The ingress. API previously relied a lot on kind of like string annotations and things that were not type safe and not vendor portable. Uh, and the Gateway, API adds support and smooths out.
Uh, a lot of that for us specifically, uh, we're, we're very excited because, uh, our support for the Gateway, API, uh, works a little bit differently than, than most other vendors, uh, support for the Gateway, API, uh, unlike other vendors, our Gateway, API support actually extends to our entire global network. Okay. Um, most, uh, gateway, API support tends to be focused on, uh, providing that functionality within the cluster itself.
Right. The pods that are deployed are the ones that are providing the functionality, just like our ingress controller support our Gateway. API support works exactly the same way where it projects that functionality out to all of and rock's global points of presence, uh, which allows you to accelerate, uh, the, uh, the functionality that we provide via the Gateway, a i to a global audience.
Uh, and it also allows us to provide many of them in a, a global way, um, and can tell me a little bit more about that as well. Very cool. Um, look, cloud native, so we we're doing a report over at Techstrong called DevOps Next, and the premise of it is, is that we're kind of entering the next evolutionary phase of the, of the entire software development life cycle.
Yeah. DevOps included. Cloud Native has become much more mature, polished.
It, it's a defacto kind of standard. Now, what does that mean for ENG Rock? And is, is that what you are hearing from our customers or our customers?
Your customers? Sure. Uh, yeah.
I mean, uh, with evolutions like the, the gateway, API, I agree that we're seeing, uh, more and more polished, like layered onto the Kubernetes and, and cloud native ecosystems. Uh, we are seeing what that really like means for us as we like move into, uh, a next phase of like cloud native adoption is remember that that n Rock's origins and our support extend far beyond the Kubernetes ecosystem. Uh, but what it means for us is that we are seeing many customers adopting us through Kubernetes, uh, and through a cloud native way.
Whereas previously, they may have been, uh, adopting us through other means, like our agent, which can be deployed to create ingress. Uh, and we also have STKs that, uh, you can use to, to bake Gros ingress directly into applications itself. I think we might have talked about that.
Yeah, We did in Chicago, I think. Yep. Uh, so we're seeing, uh, you know, more and more folks, especially, uh, those who are using N Rock for production adopt us for production use cases through Kubernetes and, and cloud Native and cloud native, uh, and especially folks who are on the bleeding edge, folks who are using us for, uh, you know, new ML use cases.
Really like looking to adopt through, uh, the Kubernetes controller, uh, as well as like through the Gateway. A PII Think one of the other things in that theme though, Alan, is generally when you look at evolutions of systems and ecosystems, initially it's, it's what I call the cobble together phase, right? Where we take a bunch of point things and cobble them to make them work together.
Right? And so you have a lot of companies that have products, but as these cobble together solutions start to mature, a lot of those products become features, right. In a bigger product.
Do you see that happening yet here? And wondering what that means for Eng Rock's future For, for Eng Rock? Uh, that, that story makes a lot of sense, and it's one that we actually tell to our customers is that, uh, Eng Rock is a, uh, a piece of software infrastructure that integrates many different components into one.
Uh, what used to be what you used to cobble together for an ingress story was a layer fire firewall and a web application firewall. Exactly. Hashing layer an API gateway, uh, an ingress controller, a load balancer.
Uh, and what we're seeing in the ingress space and what we, you know, uh, help our customers deploy is an integrated solution that takes all of those pieces and unifies them into one package. When we speak about N Rock as the unified ingress platform for developers, that is really what we're speaking about, is this consolidation of different components, uh, into a single solution that doesn't require you to mix and match as many different pieces to, to really cobble together something, uh, to create a complete ingress story. Uh, the latest piece that we've just added, uh, uh, ourselves is a functionality for, uh, uh, essentially API gateways.
Uh, we've added to the product not to be confused with the Gateway API support, uh, but we've added a whole bunch of functionality that previously you would've needed to outsource to an API gateway, uh, into our unified platform. So I noticed you didn't use the P word platform. Well, you did.
Just at the end here. I Did. That's true.
So do you consider Eng Rock a a the entire thing a, a platform now then? Yeah, absolutely. Uh, you know, I think that's, that's been our vision from day one is it has been that Eng Rock is a platform that allows you to take any of the different pieces of, uh, an ingress story, and instead of deploying different solutions for them, that they are each features within our product that you can turn on and off when you need them.
Uh, so for instance, uh, our most recent set of like new features that we were just speaking about is support for, uh, API gateway functionality. We, uh, just released support for, uh, essentially global rate limiting, which allows you to rate limit access to any service that you Oh, very cool. Behind End Rock at a global scale.
Uh, so this is really about our servers creating coordinated layer to create great limiting on a global scale. Uh, and we also have added, uh, jot authentication, uh, and essentially like support for OIEC, uh, or Open Id connect identity providers mediating and federating identity access out to them, uh, to create essentially like, uh, authentication in front of APIs is really the Very Cool, latest piece that we've added As well. So you guys are just, I mean, you're just solidifying this whole thing.
It's, it's growing in all directions kind of thing. It's, uh, it's really exciting and we're really excited to create that simplified version of ingress for developers. What we really believe is that networking, and even the ingress story has often been about developers working with the assembly language of networking.
We are still requiring developers to think about ports and TLS certificates, uh, and essentially like these low level primitives TNS, uh, records and things like that, when developers really want to function at a higher layer, right? They wanna be thinking in terms of their application and the functionality that it delivers to them, and not down in the low level minutiae. Um, Love it.
Yeah. Alan, we're about outta time. I want you to look at this camera, if you can tell people where they can go to get started with Eng Rock and what's kind of the best on-ramp.
Yeah. com. Uh, all of our developer resources and documentation are there.
Uh, it's easy to get started, uh, just by signing up for a free account. And, uh, once, uh, you've, uh, once you've adopted that functionality, uh, we have, uh, pay as you go plans that allow you to start, uh, with just what you need and scale your usage as you, uh, adopt more. There you have it.
Our first interview live here at CubeCon in Paris. We are jam packed for the next three days, so tune in and, uh, stay tuned as we, we bring on our next guest. Alan, thank you so much, man.
It's a Pleasure to be here, Alan. Thank you. Enjoy, enjoy Q Con.
We'll take a quick break. We're gonna be back with our next one, as well as Mitch Ashley, Mike Ard, and the rest of the text on gang.