Security, Collaboration, and Community Commitment with David Nalley at KubeCon Europe 2025
Alan Shimel and David Nalley from AWS highlight the importance of open source software, David’s experience, and the evolution of security and business models in this space. The discussion emphasizes AWS’s dedication to the open source community through investments and contributions, particularly to PostgreSQL, and the collaborative nature of problem-solving within the community.
Transcript
This is Textron tv. Hey everyone, it's Alan Shimmer. We're back here at Kubernetes.
If you're watching our, uh, videos in chronological order as, as they're being published, this is our last video for day one of the open show floor. It's actually taking place here Wednesday, uh, at the Excel Center in London. We've had some great interviews.
We've really kind of dug in on what's going on, but we saved maybe the best for last for our first day here. I want to introduce you to David Nally. David's with AWS.
David, welcome to Techstrong tv. Man, it's great to have you on. Thank You so much for having me.
I, I know this is such a happening event with so many people here. I'm, I'm so happy I get to spend some time with you. I appreciate, I appreciate you making time.
You know, people watching this could really only see this. They don't see that, but, you know, this is a huge, this is my first time at Excel. This is a huge facility.
And you know, this, we're on the north, uh, expo hall. There's a south one as well. It really is just, It, it's a massive place, but I'll tell you, it feels kind of full.
Yeah, it's, I'm surprised. I, I mean, I saw, I came in a couple days early and looked at the place, and I'm like, this is massive. It's gonna feel empty.
It does not feel empty. There are some people, well, there is 12,000 odd people here. There are, Yeah.
Just a few. Yeah. Uh, but they did a beautiful job, uh, both the CNCF as well as the, the folks who, who maintain, manage Excel here.
But David, what, what I mentioned you're at AWS, but what's your role there? So, at AWS I'm the director of Open Source Software Strategy and marketing. Love it.
Um, uh, but open source is not new to me. I've been involved in open source for about two decades. Uh, I've worked pretty heavily at the Fedora project.
I've worked at a number of Apache projects, and most recently in November, I finished up, uh, four and a half year term as the President of the Apache Software Foundation. Oh, did you really? That's great.
I Did it. It, uh, it was a lot of fun. Uh, you know, it is, it's fascinating getting to work on open source and, and helping to build the organizations that make that possible, much like CNCF does here, uh, in the cloud native community.
Absolutely. You know, I, I've also been involved in open source software now for about 25 years. Uh, more on the security side.
I would say, you know, we had a golden age of open source software security in the early two thousands. Mm-hmm. Um, not that we don't have open source security software now, but we've seen a lot of, a lot of companies changed their licensing.
We have. Right. Um, I'm back in the days when if you didn't have a real OSI approved license, you weren't open source.
I don't care what you caught yourself. I think That's still the case today. I don't Know anymore.
You know, you, you, you from that school too. Yeah, absolutely. Absolutely.
And I, I think OSI has done a good job being a steward of the definition, and I think a lot of the principles that, uh, for the reason that that definition was created still apply. And I, I think, uh, I think we should tread carefully in getting away from that. I, I agree with you.
Because anything that waters it down, waters it down by definition. Right. And, You know, I think by definition, you know, the, whether you look at the OSSIS definition or the deviant free software guidelines are the four freedoms, uh, from the software free or Freedom, FSF, um, they, they all were about protecting the ability for users and hackers to work on software.
And so, uh, you know, when we think about maximum freedom for the people who are using the software, I think that, uh, that is still something that we should aspire to. And that doesn't mean that that's the only way to develop software. There's plenty of good and valuable for proprietary software, but it's not open source.
And people have come to expect that open source software is a public good and that it means specific things. So I, I think we ought to be really careful with applying that label software. Well, I think part of the issue is, you know, David, you've been around as long as I have with this stuff.
It used to, the old story used to be, can you make, can you have a successful open source company? Well, there was one, everyone said, well, there's one Red Hat. Right.
Red Hat was the model, the shining light on the hill mm-hmm. For open source business models. IBM paid a lot of money, as you know, uh, red Hat was very, and is very successful, but there are more than one way to skin the cat.
And then we've had other successful open source companies or models mm-hmm. That companies have followed. Um, however, I, I think, and I say this, I I'm a multiple time founder of companies myself, you get maybe a little buyer's remorse, right.
Where you say, man, I, I built this thing, but because it's open source, 97% of the people using the software really aren't paying me anything. Not only are they not paying, they're not not contributing anything. They're users.
Mm-hmm. And man, if I can only, if I could just convert 10% of them, how much more money would my company make? 'cause the, the average open source model, look, if you convert three to 4%, two to 3% of your user base, you're viable.
You convert 4% of your user base, you're printing money. But, you know, people wanna convert 15% of their user base and more. And, and so, and I don't begrudge, if you're a founder of a company or you own the IP or whatever on a project, you want to change it.
Absolutely. It's your prerogative. It, it's your decision.
It's your business, frankly. Sure. And, you know, your business has to pay employees.
They've got to, they've gotta pay leases on buildings, they've gotta pay for equipment. And all of that is, is, uh, a reasonable business decision that might be made. Uh, I just saw some research, uh, that I think is published this week, uh, uh, coming out of France where they looked over the past 25 years of startups and they compare startups that were creating proprietary software and startups who were creating open source software.
And the open source software was, uh, had greater returns on investment than the proprietary, all other things being equal. And so, yes, I, I completely understand that there are market forces that come into play and may make, uh, companies want to restrict licenses or to restrict who can take advantage of the open source software. And I think that's a careful business decision that that needs to be made.
Because in many ways, you are, you're making a long-term commitment when you're choosing a license. You're, uh, you're setting expectations with your customers and with your user base. And then they feel disrupted when you, when you change direction.
But still their choice to make. But, uh, the data that I saw in this paper, uh, is that generally open source and big generalizations. 'cause we're talking about a 25 year period.
Uh, generally open source tends to have greater return on investment than the proprietary software. Really. That's interesting.
You know, but of course, this is also one of the reasons I think, for the success of foundational ownership of open source software. 'cause people don't have to worry about having the rug pulled out from under them about a license change or a usage Change. Well, they don't, they don't have to worry about a license change, but there's other risks.
Absolutely. So, so one of the risks is even if it's at a foundation, if there's only a single company doing the work, that company can still stop doing the work. And so, I, I don't think that, you know, know foundations do a great job of setting up known governance, having trademarked policies, being a holder for intellectual property.
Uh, I don't think they're a panacea, and I don't think they solve all problems. But they, they provide a great place for people, especially competitors, to come together and collaborate to make the world a better place or to build Better software. That might be one of the biggest pluses, is it allows that coopetition Absolutely.
Right. Where we could do that. And AWS is a great example of this, right?
AWS historically has been a consumer of open source software for sure. But it's also been a, a, a benefactor of, of the foundations of open source software. And I imagine that's a lot of what your role is around.
Yeah. A lot of, a lot of what my team focuses on is looking at the open source software that's important to our customers and to our business, and saying, how do we make sure that our supply chain for this, uh, for this software is in a good state? And so that looks like a lot of different things because not all open source is the same.
Sometimes that means we need to, um, fund the foundation sometimes, like the C NCF f where we're already platinum members. Uh, but we recognize that there are a lot of demands on testing for things like Kubernetes. And we have to fund a lot of Kubernetes.
So we announced, uh, for instance, this week that we had, we were renewing our $3 million per annum funding on Kubernetes. So we give them 3 million in, in infrastructure costs, uh, so that they can do all of the testing that they need to do. They can, uh, all of the other infrastructure things they can take, take care of without having to worry.
Uh, so sometimes it looks like that, sometimes it looks like, Hey, there's one or two developers and these folks need some money and we need to fund them. And so we, we actually use, uh, a mechanism that, uh, GitHub has GitHub sponsors to get individual developers some money. Uh, and sometimes it's sponsoring longer term works.
For instance, we've engaged with the internet security research group and Alpha Omega at the open SSF Sure. And basically said, here's, here's a chunk of money. Let's go figure out how we improve the state of open source.
And particularly with, with both open source security. That's, that's a fantastic, like, are you guys gonna be at the open source summit in Denver? We will.
We certainly will. We're gonna have a presence there. We'll Be there too.
Maybe we can catch up. Maybe We'll catch up in di. Yeah.
Um, so look, a w s's commitment to the open source community, you know, and dollars and cents in the millions, if not tens, tens Of millions. Yeah. Easily.
But beyond, beyond, you know, just writing checks and or giving credits. Mm-hmm. It's a people commitment too, right?
Absolutely. They brought you on. You have a team here.
Talk about how you and your team are inter interfacing with the community. Yeah. So, uh, we're doing that in a number of ways.
And I'll, I'll tell you a couple of stories because we do a lot of work in open source and AWS is a big company, so I could spend like three hours telling you about the different teams doing fun things. So I'll try and keep that to just a couple. Uh, PostgreSQL is a, is a great example of a place where we're doing a lot of work and we've got a dedicated team set up.
So a bunch of engineers, uh, solely focused on working upstream in the project. Uh, I think the last set of numbers that I saw said that we were the number two largest contributor of code to PostgreSQL, which is, which is great. Uh, but the thing that actually encouraged me more is when I saw that we were the number one reviewer of code, Really?
And, And that's fascinating to me because one of my beliefs is, is that the constraint on open source communities is not the writing of code that that's valuable. It's needed important, but the number one constraint is being able to review the code that's coming in, make sure it's high quality, make sure it's secure tested, and then being able to build that out into production. And so seeing that, uh, this team that's dedicated to, to PostgreSQL at, um, at AWS was generating enough reviews to make us the number one reviewer of code, something I was really proud of.
'cause I think that that's part and parcel of making a very resilient community. Uh, and I, I will tell just one success story from, from that team. Uh, and, and there's a great presentation about this specific problem by Joe Conway, uh, who is one of the, uh, software managers, software development managers, uh, on that team.
And so he essentially, when we were operating PostgreSQL at scale, we have a, a service that delivers Postgres called RDS Relational Database Service. And when they were, uh, when they were operating this at scale, some of our customers were noticing, uh, weird oddities in query returns between versions. And that's not supposed to happen with a database.
Right. You know, you, you should be able to run a query and get the same Thing. Yeah.
That is sort of a, a, you know, a flag. Well, yeah. That, That, that's, that's this pla flag of something wrong.
So they spent a lot of time and they, they finally realized it had nothing to do with PostgreSQL the problem. The error was actually in Glip C Really. And Glip C was causing a collation problem.
They were able to identify this, and then when they went to fix it, they could have fixed it for AWS, they could have fixed it for the service and just went about their way. But they realized that Postgres does not control all of the environment. And so if you deploy Postgres on Red Hat Enterprise Linux, or you deploy it on suse, or you deploy it on Amazon Linux, you may end up with three different versions of Glip C.
And every version new version they release may increment Glip C as well. And so they had to go figure out how to solve this for PostgreSQL in general. Right.
Uh, because they can't control where Postgres is deployed. Even the project can't, uh, control how or where it's deployed. And so there's a great writeup, uh, uh, Joe Conway just gave a talk at the Southern California Linux Exfo about that work that is very, very deeply technical, but also like that is core plumbing work that has to be done.
And I'm, I'm proud that they're not just shipping features, but they're actually doing that long term maintenance work. So that, that's interesting because, you know, talking about OSI licenses, right? Most open source software with an OSI license, if you're using software and you changed the code there, something like this where you're fixing mm-hmm.
A library, there was an obligation to contribute that back Certainly under the copy left licenses. Absolutely. Yep.
And, but again, I don't know how many people live to the letter of the law on those anymore. Yep. And they would just keep it for, you know, their own thing and, and not contribute back.
But it's, but that's, but that's the spirit of open source, right? You, whatever's written is written and you want it agree to a license 'cause you just want free software. That that's fine.
They'll get you free software. But if you really look at what open source is about and what made it great, it is that you, you, you're paying it forward. You're doing what's best for the community.
And, and so that is, to me, that's really the spirit of open source here. I think it is. And you know, I, I think this, this conference certainly, uh, brings that out.
That that open source is about communities of people. And I think that those people, uh, come together around a problem, and they work together to solve that problem. And they work, you know, they'll discover other problems along the way that they'll also work together on.
And I think that, that, you know, we talk a lot about software and lots of debates around licenses and, uh, you know, the politics around licensing. But at the end of the day, open source is about people, people largely helping other people solve shared problems. And I, and I, you know, that used to be a lot of people used to get off on that, quite frankly.
Right? Yep. Including people like you, I'm sure.
Absolutely. And, um, it's good to see that it's still alive and well out there. And it's also, look, kudos to AWS for bringing you in on this and, and keeping that kinda spirit alive and well.
Well, I, and I, I wanna, I wanna be clear like, this isn't philanthropy. We're not doing this, this because we're generous. It's Coopetition.
This is, this is in our customer's best interest, which means it's in our best interest. And, you know, we have a business mandate to take care of our customers, and that means we're going to be contributing to open source in the process. Well, The rising tide lifts all the boats.
Absolutely. Absolutely. It does.
And that's what this is about. Because even as big as AWS is, and they're big, not big enough to run at this scale, I'll, I'll let you say that. We're not big enough.
Okay. You heard it from me. Yeah.
Yeah. That, that was you. I, I, I do think though that, um, what we have found over the years is that it's not just about solving technical problems in interesting ways.
It really is about, uh, that alone is not enough. Customers actually prefer open source. And, uh, they like being able to play with things and knowing that it's being developed in the open and knowing that there's an open roadmap.
And, uh, they have a high degree of trust in open source software. Yeah. And so, absolutely, time and time again, even though in many cases we started out writing something on our own.
And the container space is a great example of this. Uh, before Kubernetes existed as a thing, we had a service, and we still do, called ECS, uh, the Elastic Container Service. Yep.
And that was the container orchestration system for AWS 2014. When Kubernetes comes out, comes onto the scene, we looked at it and we said, well, that's interesting, but, you know, we already have a solution to this problem. Yep.
And it took a couple of years for our customers to tell us, Hey, we really like that open source thing over there. Well, But, And, and we launched a Kubernetes service If I was one of those betting sites. Right.
I don't even, I don't use them. I don't even know names. Kubernetes was probably not the favorite to be the orchestrator of choice early on.
I, I don't think so. I think if you look at the, it was short as heck. I think if you look at the landscape at the time, at least for open source orchestrators, I think things like, uh, Apache Mesos was a lot more compelling way Out there.
Yeah. I Mean, and Twitter, Twitter at the time was using Mesos for all of their workloads and What's had Docker Swarm, then Docker came on And Docker had the containers. Absolute, you would think.
Absolutely. You know, that was, that was probably the Oddsson favorite. Yep.
Right. If you're a betting man. Well, I think, I think what Kubernetes did successfully is they built a thriving, vibrant community, and the community was able to sway public opinion.
Yeah. I mean, kudos to Google, I guess, for it. Yeah.
So I, you know, there are people who say, go, if Google had to do it all over again, would they or would they not contribute Kubernetes? Yeah. I Don't know if they would or not.
I, but, you know, I, I can't, I can't prognosticate about things, potential things that might have happened, but think about the amazing value because they do. And it's, it's all around Us. Yeah.
Literally. I mean, literally, I think you said the number, 12,000 people, a Little over 12,000. Yeah.
The huge crowd here. And, you know, they're here celebrating, uh, this, they Call it KU Con, even though it's so, so cloud native con Yeah. Most people call it Q Con.
It's Q Con. Agreed. Hey, David, thank you for coming here.
Yeah, thank You so much. I appreciate the chance to Get to talk. You.
My pleasure. David Nally, head of open Source Strategy and Marketing. Is that right?
Yes, that's right for AWS It's gonna wrap up day one here at Q Con. Stay tuned. We have more coming.
I hope you've enjoyed it so far. But for now, this is Alan Hummel. We're out.