Mike Malone, Smallstep | KubeCon + CloudNativeCon NA 2022
Mike Malone, founder and CEO of Smallstep, joins Mitch Ashley at KubeCon to discuss how Smallstep is giving people the tools to customize and integrate into their environments in an intuitive, user-friendly way.
Transcript
This is Textron TV. Hey, welcome back text wrong TV. We're here streaming live from kubecon in Detroit kutcon, 2022.
So lots of great folks matter of fact, I have a new person joining us here is Mike Malone. Mike is CEO with small steps or welcome Mike. Thanks for having me.
Yeah glad to have you so tell us about yourself and tell us about small steps. Yeah. So I'm CEO founder at small staff but my background I'm a software engineer.
I'm a distribute systems guy actually and small staff. I we do certificate management for internal infrastructure for production infrastructure. A lot of our users and customers are deploying our significant management infrastructure into proven Edis environments, which is why we're here but more broadly our technology allows you to issue certificates and use GLS or https to secure connections to databases cues, you know web help admission controllers kubernetes.
There's themselves internally microservice intercommutication all that stuff. Very good. Is that as it happens?
I didn't know that before but actually I have the background and digital certificate. Yeah ran a business for the cable industry for their cable modems and all that stuff. So very cool.
Well one thing one thing I can imagine you can validate for me. I don't imagine developers want to spend a lot of time managing certificates, right? They just wanted to work the played for me.
I don't care about rotate. Yes. I want them to rotate I want to be secure but they didn't want to muck with it, right they wanted to to work for them and kind of be out of the way, but be secure that's I would say, that's absolutely correct.
And that's been a big focus of you know, and differentiator for our technology as sort of compared to what existed prior to the justifying our existence. Like. I suppose is, you know, focus and philosophy on automation ease of use and also miss use prevention putting sort of guard rails around it.
We like to make easy things easy hard things possible and just keep you sort of in that safe. So some other tools are just way too easy. Screw up and screwing up when it's security infrastructure can be sort of existential.
So, you know, that's a big Focus as well. You know, a lot of my close friends are you know in the software Engineers software developers and when things I hear frequently is I can tell when a product was built by a developer or was built designed to build by a develop versus a product up great product, but it might it's not meant for developers. Right and I know coming up through the digital certificate world that's been security service, right and Security Experts, you know, 400 digital certificates and going way back to the early days of that.
How did you approach it differently with you know, your background your experiences a software engineer? Yeah. I know exactly what you're saying.
I think it's like a million small things. Right? But that's my world right like prior to starting this company.
I was a software engineer. So I think it comes largely down to interfaces documentation tutorials how you integrate into the broader software ecosystem. So giving people the tools to sort of customize and integrate into their environments without having to sort of like like can forcing them to conform to your tool set but just, you know, using standard best practices implementing standards.
So we Implement like Acme for example, which a lot of people are familiar with because that's how they get certificates for their website from let'singcrypt. Well, you can use that technology for your internal certificate management needs using small staff, which means if you've already figured out how to operationalize something like cert bot or jets that certain manager for your Career Cluster. You know, you've got alerts and audit logs and everything set up there.
You can just take that exact same, you know, you have that experience. You have that knowledge. You just point it stand up a small step certificate manager instance Point all that stuff at this new certificate Authority and and you know, all of this characteristics sort of translate over.
So I think it's a lot of little edge things like that just being thoughtful about what are the workflows and experiences that developers end users are going to be exposed to on a dated basis and really focusing on optimizing those and making them sort of Delightful. Yeah, it makes a lot of sense. I mean, sometimes you want to take something you can already do and make it better other times.
This is like look, I don't already know way of doing this. I've already implemented. It just do it the same way or similar enough that I don't have to learn something new.
It seems like another difference is of course developers want to you know, they went apis they wanted to be able to manage it control it through code. Yeah, not not everything needs a gooey UI right that's appropriate part of it, too. I would guess that probably ever pretty API Centric approach.
Yeah. In fact, maybe do an extreme like We have a lot of functionality that hasn't fully made its way into product UI like the only way to use it is through API or through our command line tool. We do have an interesting challenge around API because you know being asymmetric cryptography, you know, best practice.
There is you want to generate the keys where they're being used. Which is a subtle security sensitive operation that a lot of developers don't necessarily have deep experience with so more often. We see people integrating with using our CLI in the hand office sort of on disc like a certificate issued by CLI in like a system to unit file or something like that.
And then the application loads it from this, but absolutely I mean, these are the things that we put a lot of thought a lot of energy into Building sort of you know, these deeper sort of automated infer automated management capabilities. Yeah, a lot of things like logging and do the stuff. I know I would normally do do you service the certificate Authority then for the developers or do you work with third party cert?
We've already we are open core. So probably should lead with that. So so, you know, you can download and run our open source tool chain.
We have a certificate Authority component and then we have a command line interface to CLI does a lot of interesting things if you're at all interested in cryptography and security you should download the steps CLI, it can work with Jason web tokens and a lot and you know a bunch of other things but it also is that primary interface to our stuff CA which is our open source certificate Authority and then we have our small step certificate manager platforms. com sign up there's a free tier you can try it all out create create a certificate Authority that is fully managed. But yours so it's just for your internal needs you can customize it configure it.
You can write templates for you know, the sorts of certificates that you want to issue. They're sort of granular access controls. And so yeah, we we can run a certificate Authority on your behalf for your internal pki but if you worked on digital Studio certificates us as users don't know this, but they're not a million literally but they're like hundreds of parameters that you can set and very and it I'm guessing you probably have figured out what some of the best Configurations are for kubernetes or for you know API interfaces.
Yeah, so going back to ease of use and Missy's prevention. Yeah out of the box, you're gonna get a certificate that it has, you know, very opinionated configuration. That's good for TLS client and server.
Use. There are a lot of things that you can tune. And you know, you could go deep on something like the key type, you know ecdsa versus RSA or like what sort of elliptic curve cryptography videos frankly like that's probably not the low hanging fruit or like how you're going to be compromised.
So, you know, we made a lot of I think good valid decisions there and you know, I'm very confident saying if you sort of like spin it up and use it, you're gonna be in a really good position, but then there are thousands of knobs, you know, there's a lot of flexibility but doing it right up front not so you might upgrade, you know scheme or whatever. Technology, but doing that right up front prevents you from having to go fix problems that naive deployed all these certificates all over. I've got to go update push right and you know a big problem with certificate management and a lot of environments is that they don't even have that visibility into what needs to change if they wanted to make a change right there.
A lot of certificate management infrastructure is really shoe string and bubble gum without any sort of like Sim integration or alerting or you know, there's no inventory of like these are all the certificates that exist in my infrastructure. So those are you know, in addition to the course of the management problem. There's their sort of you know, some of the adjacent issues that are platform addresses.
I would also guess that this has got to help with governance and compliance and Audits and you know developers love that here. Nobody nobody except the Auditors or I suppose but we don't like to go through those things but it is necessary and we wanted to be as easy as possible. Yeah, right and there's few issues that we have to immediate.
Yeah. Yeah, certainly, you know, a lot of our customers are undergoing stock too ISO background PCI, and and this technology does help address some of those controls in a really, you know, it really hard and like provides real Security benefits. I feel like a lot of the frustration with compliance is that Something that can be sort of security theater.
We feel like we're religious wars about whether what's right or untrue. A lot of complaints is actually saying here's what we're going to do and then you just have to prove you're doing that you just and you don't go to extreme of you know, one step at a time. Don't take it too far make your job harder.
So is this your first coupon that you've you have a booth here ice we do have a booth. Yeah. So if you're here, come on by we got some really cool crypto means cryptography t-shirts are given away and stickers and you know, all that good stuff.
No books and pens that it's not my first good time though. I attended What was it? It would have been pre-covid in Seattle.
I think it was like 2019 area. Yeah 19 a long time ago. Yeah, it seems like it seems like a long time.
Yeah, it's nice to be back in a person. Well good. com.
Okay. Wonderful. Well Mike thanks for joining us and good luck at the show and hopefully we get a lot of folks checking out your stuff.
I mean I love that you come from the development World buildings building this Ford developers by developers Etc. Right right approach monster coming. We'll talk to you soon.
Great talking. We will be back with our next interview. So hang tight and we'll be coming to you from kubecon live streaming.
See you soon.
