Sonny Shi and Jorge Castro, Stacklet | KubeCon + CloudNativeCon NA 2022
Sonny Shi, principal engineer at Stacklet, and Jorge Castro, community manager at Stacklet, join Alan Shimel at KubeCon to discuss cloud custodian, a rules engine for cloud that ensures a compliant, secure and cost-efficient infrastructure.
Transcript
This is texturing TV. Hey everyone. We're back here live in Detroit to keep Concord nativecon.
I've got some folks from the cloud custodian project and stack lit up. Let me introduce you first to my far right is George Castro? He's the community manager for cloud custodian as well as more.
He's gonna tell us more welcome George and sitting to my immediate right? I guess that would make it. It's sunny.
She Sunny is an engineer both with stat Clinton Cloud custodian as well. Correct, maybe you today. Yep.
Welcome and thanks for being here. So guys, I guess we really need to start off with Clark custodian What's it about? So Cloud custodian actually is a large an older project than you would think 20 2015.
Yeah, it was initially started by the folks at Capital One the lead architect being Kapil fanga Valu. And over time they were using custodian internally and Capital One decided to donate the project to the cncf along with all the other ecosystem. Projects that are in here so fast forward later.
We just graduated moving not graduated moving to incubation. Okay. Wow.
Yeah, that's hopefully in the cards but a little out there. Yeah, and now it's it's interesting because we have a wide variety of Affiliated organizations that are contributing to clock custodian and not just backlit and it's become very popular in an important piece to a lot of organizations critical infrastructure. Yeah and Clarkston.
It's a rules engine for your Cloud. So governance is code ensuring that you're deploying your infrastructure and a compliance secure cost-efficient way. We have a really simple easy to use easy to understand language that lets you do that custom rules.
So we're excited to be here at UConn this year. So it seems you know, look this hits on security. It's a little bit on finops.
right It touches a lot of faces another thing. I just want to point out for our audience. Maybe you may not be aware is that you know Folks at Capital One.
They were one of the first kind of thanks financial institutions who really Embrace open source, not only you know, there are plenty of organizations who use open sorry, but they Embrace those sorts in that not only did they use. Open source, you know in some existing open source projects. They actually develop.
A lot of code a lot of product or a lot of projects that they then open source and they donated in the case like clock sodium to cncf which has allowed the community to run with it. All right, you got to company like stacklet 5 custodian, but, you know give credit where credit due to the folks of Capital One. But so it's in incubation or sandbox incubation incubation from the same.
Right. So give us an idea. What what's new in releases with Cloud custodian?
Yeah, so I think the thing I'll lead off and then that Sunny will explain. One of the things we're really excited about is custodian is already used. Production at the cloud provider level Amazon Google Azure and this week we've started the move to be able to bring that power into the kubernetes cluster from simple things, like ensuring tagging works to being able to kind of look at your infrastructure more holistically as opposed to well.
We need policies for our all of our Cloud resources and our provider. But we also need Cloud policies in our cluster. And if those things aren't matching that's kind of friction that we are looking to get rid of because it's really nice when you can have that consistent infrastructure.
Yeah, and you know, we're excited to announce that we have new kubernetes support coming into Cloud custodian, of course here at kubecon. It's a thing on everyone's mind. We've had kubernetes support since 2018, but we're announcing specifically.
It's a mission controller support. So being able to dynamically admit and deny a warn on objects coming into the cluster. Oh, yeah.
Okay. It'd be great for people doing things like label compliance or ensuring images are coming from the right registry stuff like that. The other thing that we're bringing out is terraform support.
So being able to shift some of your governance concerns more to the left as opposed to, you know, checking that things are deployed correctly. You can check to make sure that people are declaring the In their terraform code the right way so you don't run into the headache later on. I love it, excellent, and you'd mentioned a little bit about you know, it's a little bit of security.
It's a little bit of finops and I think over the last six months we've seen the financial attention for doing things like that. And you also talked about You know Banks and consumers have open source have been kind of in this territory already because they might be in regulated Industries. and what we call a well-managed cloud is You have a few things the infrastructure that you think you need right the ideal theoretical infrastructure, which is some ideal unicorn.
You're never going to get to. And then what you're paying for? And sometimes those three numbers don't match.
And that kind of sucks. So I like to think of it in a way is a lot of people are looking at the finops face thinking they're you know, what were my low-hanging fruit, you know and let me reap that low hanging fruit what tools like custodian and other compliance tools in the space allow you to do is Give you that opportunity but then allow you to add your own pace shift left. So when the infrastructure comes up, it's already up with what you intended to be.
And so I found especially I mean relatively new to this space and I have found that sometimes you can't just say well this is how it is and it's like a hard thing because you're developers you need time for organizations to understand. You know moving the culture from you know, we could just run everything we want but we still want you to innovate we still want people to innovate. We just want to give them those guardrails to do it.
However long term the idea is to just come up the way that you intend in the first place to give your developers that confidence to innovate, you know, without accidentally leaving an open bucket or any of the other things that people are struggling with. Yeah, and I think like you mentioned the the project came out of Capital One and you know, it's a large Enterprise and it's a realistic project right? It's not saying that you have to come in and like if you're not doing things XYZ way, then you can't use the software meet you where you're at.
If you've got a whole bunch of stuff that's out there that you wish was in a better State. We've got Advent driven policies full policies all sorts of stuff to help you get incrementally there and drive that behavior change at your company. Yeah, excellent attack, but the behavior change I think sometimes people forget that.
So you get it. That's the long-term benefit and sophisticated organizations have started to identify that. Cloud custodian dot IO, okay.
You can go check it out. Let's let's go into Stockland a little bit. So everything I've described a lot of people when I said they're like that is amazing.
I want to do all that and then you look at the complexity of the infrastructure that people have multiple regions multiple clouds clusters all over the world different time zones. How do you manage your off hours and things like that? And they're like I want to do that.
I just don't have time to research all of this stuff. I mean it's a it's a rabbit hole. So if you would just want that the Clickety click and you get the expertise of someone like sunny or some of the folks that have that production experience at that scale.
That's what stack that gives you just the time that into your business analytics. You know, that number that you want to drive to how are you going to to get there custodians just it's just a tool. It's always going to be a Unix Tool It's Like a Knife.
But people are here for the full meal. Yeah, I think yes definitely builds upon what cloudstone has it is built on cloud custodian and we've got additional great products such as asset DB and a Communications Hub to really help drive that drive that forward inside your organization because we want people to have a well-covering cloud too. I think like, you know Rising tide to live Soul ships and if everybody's getting into a lot more well-governed space and we can go work on other cool problems, right?
So we don't want you to spend time stressing out about your governance if we've got the tool for you to help you get there. I think that's a great thing. io.
That's right. Just making sure we get him out there right guys. They're domain.
Yeah. Yeah, so you made the cloud custodian announcements really kind of in the beginning today's only Wednesday. So beginning of the week carry coupon.
Yeah, so we actually had a governance this code day last week where some of that stuff was sort of in preview, but here today we want to make sure that you know, people are wearing and find out the good news. Cool man George Sunny. Thanks for coming on and being on Tech strong with us today.
I appreciate it. Thanks for having us keep doing what you doing. It's a great project.
All right. io here on techstrong TV. We're gonna take a break in Detroit.
That's the motor cars go around. We'll be back in a little bit.
