Alex Jones, Canonical | KubeCon + CloudNativeCon NA 2022
Alex Jones, Director of Kubernetes Engineering at Canonical, joins Alan Shimel to discuss the history of Canonical’s Kubernetes involvement. Additionally, they talk about strict confinement, a snap confinement level that provides complete isolation, as well as partnering with vendors to build Cluster API.
Transcript
This is texturing TV. Hi everyone. We're back here live in Detroit for kubecon day three of our coverage from the show floor and I'm really happy to be joined by our next guest.
His name is Alex Jones. Alex is with canonical. Most of you know who canonical is but for those who don't they are probably best known as the people behind Ubuntu one of the most popular Linux desktops.
In the world or Linux distributions, I think is that right? I'm always thinking Linux. That's something for nomenclature there.
Yeah a little bit sorry, but Linux distributions in the world Alex. Welcome to Tech strong TV. Thanks for being here.
Before we jump into the whole canonical and I'm blunto and all of that a little bit Who's Alex Jones for? All right. Sure.
So I'm from London UK two kids. I work economical for about a year. Now.
I'm an engineering director today. I focus on kubernetes but a lot of my stories in the open source world and that's really where that intersection of. Hey, this is a company that I like because they do a lot of Open Source work.
Yeah. So I work in the cncf. I'm a tech delivery lead for app delivery, which is one of the working groups that helps companies that want to bring their open source into the cncf figure out how to do that great aside from that.
I'm also doing a lot of advisory work and so it was a really good match when canonical said. Hey, we really want to take our kubernetes offerings to the next level. We need somebody to help lead that and so I found myself doing that and that's why I'm here today.
Great. I love it. So.
Let's talk about the canonical kubernetes offerings. Right one of the great things about Linux distributions. And again, our audience is technically I don't have to tell them it's but yeah, you know, what package is does it come with Yeah by default what packages are available and obviously as cool and containers.
He came you know this whole Cloud native stack if yeah as they became more prevalent. All of the Linux this year's we're saying okay. We we need to ship native with with scoop.
And what have you if you can and I don't know if you even know this, but could you give us a history maybe of canonicals? Kubernetes involvement there. Yeah, I think that it started with the realization that Ubuntu is being used for about 63% of all kubernetes distributions in the world.
Almost two thirds. Yeah as as the host OS and that's pretty staggering right it is but the other way to look at that is it's an incredible responsibility because that's on a knife edge, right? You know how fickle the community can be if something doesn't work.
They're gonna get rid of it. Right? So we thought how do we double down really capitalize on this?
So we look to the folks that are using it the hyperscalers the companies that started out thinking we love Ubuntu, you know, 204 like focal and Beyond how do we take that and actually start to make it run really well, so we start building up Partnerships. We start saying look we have lots of different types of Ubuntu. We can Slimline it we can turn on Colonel modules for you.
We can do whatever you need. And those Partnerships became more substantial over time. They started going back and forth and we actually had some quite deep engineering conversations and around about that time.
We also started Experimenting with well, let's look at what kubernetes looks like in the in the Ubuntu ecosystem. You might have heard that snap is one of our sort of jewels in our crown of what we think it makes a really good way of delivering open source projects for those of you who may not offend to be familiar. It's a little bit like apt right except for SNAP runs on a demon.
It was auto updating. So I go snap and stall something snap install, you know chromium Etc. How we how do we fit that in with this kubernetes idea that kubernetes is multi-node, you know ability to build bring out customers.
Well being canonical our job is to simplify things right? Everything's complicated out. There.
We make our we you know, we we make our sort of value prop in that area of let's make it simple. So microcakes came about it was the idea of how do you create a single binary of kubernetes and make it installable just like a web browser, right? I want to have a kubernetes.
I want to get rid of a kubernetes and microgates absolutely took off. Around about the same time. There was also the juju project at canonical and JuJu was set, you know, standing up open stack standing up VM standing up what not and it kind of went to and too with like, hey, we've got microcapes that's been a roaring success.
We feel like we could also do something with Juju to stand up kubernetes and lower behold. We put our first distribution out of kubernetes. I think was around 116, maybe 18 prior to my time.
And there was a real appetite to manage not only open stack not only kubernetes but kubernetes on openstack with Ubuntu and so you're starting to build this ecosystem that you can control from sis admins who are super familiar with with openstack, you know, they know Cinder they know neutral they know all the parts work and they now feel comfortable that hey I know how kubernetes can be deployed on top of this and that we're not only upgrading their technology. We're upgrading how they feel about it as well. And so we were introducing that new angle of folks into this community as world.
Love it. Excellent. You mentioned platform.
One of the kind of buzzwords was starting to hear more of its platform Engineers. Right right platform engineering. It's a new buzzword maybe but I don't think it's a new role quite frankly, but that's me.
I'm all. What is canonical and winter are you guys saw kind of embracing this? new role or at least not a new role but this new I you know, we have srees.
Yeah to me. They were Ops people. Platform Engineers are sort of Ops people too.
But you know, what, do you what do you think about all it's like on it? Well, I mean really kubernetes is Linux, right? If you think about it, a lot of the drivers are just changing the fire the IP tables, right?
So yeah, I think platform engineer kind of is Cut From the Same Cloth of it's a way of describing a context boundary of what are the things you care about. I'm a person that cares about the platform and that domain boundary has a lot of stuff inside of it. Yeah.
I think it's the the gradual inflation of your domain scope because a platform engineer can now be observability. It could also be like, it could be the day one day too. We all know that sis admins have gone out of gone out of favor now, but we still do a lot of the day to operations upgrades updates, but no no that's now platform engineering right?
I think the term has been reinvented because with the reinvention of the title also trying to reinvent the practice. Yeah, so that's my my feeling on this actually. All right.
So I think we've done a great job of laying this all out. Let's talk now about what you know, Harry kubecon news from canonical. All right talk.
Well, let's we're super excited because we have a couple of key things that we wanted to bring to keep calm one of which is called strict confinement. I told you about snaps I told you about apps I compared them snaps is basically a process it runs. It does the updates on your packages.
But there's also something else that snaps can do they have apparma profiles around them. So when I install say Firefox chromium in a strictly confined snap, it's sandboxed. You can't get out of that.
Right? So let's think about applying that to kubernetes with microcakes. What if I took kubernetes in a snap and put app armor around it.
You see 1500 security companies all trying to solve the problem of container escapes what happens if somebody, you know mounts the sis folder or mounts the prop directory from their pod well with constrict confinement, that means that as soon as you try and hit the Linux kernel, this is no I don't think so. It gives you a denied exemption. So what exception so what's really interesting here is when you combining those Technologies, I mean app armor and SE links have been around a while.
But when you bring it into that modern context like I was saying with IP tables your suddenly able to solve a modern problem that's been created from container orchestration with traditional tooling so strict confinements interesting, but the secondary impact of that is Ubuntu core our immutable operating system only runs with strict. Diamond a bunch of Chorus for it's for cars. It's for factories.
It's for iot. So now when we have a strictly confined microcakes and Ubuntu core we have kubernetes and cars. We now have folks in automotive folks in energy at base stations for Telco who want kubernetes strictly confined.
They can't afford to be even stressing about somebody who could jump out of their container. They need an immutable operating system. They need real-time kernel as well who has a stronger kernel story than Ubuntu and I think I think there are maybe I can't think of anybody I would say that right but It jokes aside.
It's like this narrative. It's all coming together. All the chapters of the book are coming together to build a story.
That's really compelling. So that's our first message. And if I have time I'll say the second take you time.
I don't see anyone elsewhere. All right. Well, that's that's awesome.
So this the second part of this this kind of reinvigoration of all of our products is that we're shifting to Solutions right was solutioning for business problems as part of that. I mentioned Juju. We also acknowledge not everybody in the world uses Juju right there people that might use other provisioning and deployments tools.
So therefore we took a look at kubernetes. We took a look at cncf and we realize that cluster API is extremely powerful tool and so we have partnered with several different vendors to build cluster API, but also to bring into their tooling so we built a provider for micro cakes and we're building one for Charmed Kate which is our other distribution of kubernetes. Now what that means is suddenly Partners who say are we only do Cappy?
They're like, oh canonical do cluster API. We can show them in our UI we can provision their clusters. So if you are a shop that until now is doing just a traditional vanilla kubernetes on AWS on Oracle Cloud Etc.
You now have the choice Pick micro cakes, you know the choice it's too big charm cage as well. And what that does is it gets Ubuntu onto those clouds and with Ubuntu come the snaps that run these and they're upgrade Story the whole story. Yeah, excellent.
Hey, we are running low on time. You know, I here's an important kind of thing. We should all be mindful of the cncf is part of the Linux Foundation, right?
That's Linux. Foundation and Linux is still a integral critical. foundational piece of this whole cloud-native story and and I think you just made that case very eloquently for people who want to get more information about all this.
com slash kubernetes great. Hey Alex. Thank you on it's check it out canonical.
com is easy. Yeah like okay IO yeah. Check it out.
We're gonna take a break. We're still live here in Detroit. We'll be back in a moment.
