Sudhindra Rao, JFrog | KubeCon + CloudNativeCon NA 2022
Sudhindra Rao, Engineering Manager for Pyrsia at JFrog, joins Alan Shimel at KubeCon to give a deep dive into Pyrsia, an open source distributed package network that allows you to build packages from scratch, verify how the builds were done and still have a resilient and dependable network.
Transcript
This is texturing TV. Hey everyone, we're back. We're back here in Detroit.
I know you know, we're wrapping up today is our last day of coverage. We hope you've enjoyed three days here trying to give you just a little flavor of what's been going on icubecon talking to a lot of cncf folks and and CF folks as well and just people in the cloud native Community a lot of the vendors. My next guest is sohinjer Rao suit ninja is with Jay frog much like our previous guys Steven ginstein Chin Steve started talking about Persia.
boring And I from CDF spoke about Persia yesterday. But so ninja we're gonna put you on the on the on the spot here. We're gonna make you do the Persian teaching first of all about.
Thank you, and it's a pleasure to meet you. It's okay before we jump into Persia. Let's talk if you don't mind sharing with our audience a little bit of your story.
Yeah. So I I started 20 years ago now did all kinds of traditional software development did a lot of Open Source back in the day. Did Java Ruby all kinds of languages most recently before Jay frog I actually did some cncf projects work with Cloud Foundry built build the VMware tons of platform and sort of have some interaction with the community's community.
Right and now I when I came to Jay frog I was doing more of that and and that's where we started talking about. How open source Works how people trust open source and what are the parameters they use and that's where we found an opportunity to actually start a fresh project called Persia. That's what we're going to talk about today.
Absolutely. Thank you for going that out. So You know make believe Steve didn't say anything if my audience out here doesn't know anything about Persia.
Yeah, yeah, let me start with how we build our open source and how we trust it today. We just look at an open source project and say oh this has the most downloads and most GitHub stars. And you know, I know this person who built it and that's our trust my Vector, right and we just downloaded use it and then then curse ourselves when you see a well liability or an attack happens, right and it's it's mostly after the fact and what we are what we are looking at is trying to bring more trust more trust that doesn't depend on all these fluff things as we as we were talking about and and try to trust what is in the code base, right?
And and that's where percya comes in percya is is an open source distributed package Network, which allows you to build packages from scratch and have a trust mechanism that that builds on top of that you can verify how the builds were done. You know, who did those bills you can sign those packages using six store or whatever you're signing. Organism is and and still have a resilient Dependable Network where you can always have those packages available.
So you don't have to worry about if npm is down or whatever. You can still continue delivering production quality software and as the package stays on the network and then vulnerabilities discovered all that information is on the network. So you can just query that make release decisions on that.
Love it. now Percy was kind of conceived and built by Jay frog but it was donated to the CDF. Yes that happened like yesterday or day before on the on the CD Summit day on Tuesday through time.
So I got a prop here which which talks a little bit about it. Yeah, you're gonna use it. Hold it up there.
Yeah, let's talk about the what is that mean? What does that mean? Actually so from the from day one, we believe that anything that we have to do with open source has to be Community owned.
It cannot be owned by one company and one company can't be held the responsible to maintain it and be burden with it. Not just that it's too much too much power given to that one company. So we have we start we always started with with the thought in mind that how do we make it Community Driven?
So when we actually had our initial discussions within the next Foundation the idea was to bring Partners along and and have it have it like a group so we have we have deploy I have we have Docker we have we have future way. We have Oracle actually. Partnering with us Distributing the Persia Network across different clouds and bringing it up and maintaining it as a community and what we announced on on Tuesday was our official incubation with CDF.
Now that we are part of CDF we have we have the we have the force of CDF behind us to sort of attract contributors to sort of use that platform to promote what we are doing and and the talk that I did at CDF Summit day was how how does this matter for continuous delivery? Like the security is the aspect that we have been ignoring we have been talking about tools but it is it is about securing your software even before you start using it. That's where the partnership comes in love it and you know look we Interviewed a lot of people from a lot of different projects.
We spent a lot of time this week talking about sandbox incubation graduation. What are the different levels of Open Source projects within this kind of Linux Foundation model? Great.
I'll play with. It but evolved. io very simple to remember and at the at the footer of our website are all our links.
We have a Google group. We have a slack Channel it is all open. We also have meetings that happen every two weeks where we where we encourage community members to come and chat with us see if they're interested and we'll get them in and start contributing and they don't have to contribute code.
We need people who are ready to test. Try it out break it that's right because Know what look I've been involved in open source a long time. most open source projects have A hundred two hundred that's a great private.
Yeah, if you have 200 contributions of code. But those aren't the only roles you don't have to contribute code play with it break. It asks for new feature.
That's for new features. Yeah, come to our meeting. That's that's what makes these.
Yeah Communications. Yeah and have a conversation. Maybe we are doing things wrong.
Who knows? Yeah, bring bring that perspective to us. Any content.
We have had people coming from all like there are researchers coming to our meetings. There are people from working in cryptocurrency coming to our meeting saying what are you guys doing? Why are you using blocky?
Let me hear about it and they're like, oh, I didn't know that this use case existed, right? I agree. So we're trying to break new grounds and you you can help us with that.
Here's something specific to Perse you too. I'd like you to address they're going to be people out here who say Well, I'm a developer. This is a security.
Yeah, but this is really security for developers. Yes. So if you're developer, you should be involved vice versa.
They're gonna be people out here who are security people say this is really security for developers. No, this is not just for developers and it's not just security. It's not just was security either.
It's for both both ends meaning wild developing you want this information about whether are you using an open source binary that that has some security issues right as a security person you want to know what happened to those binaries how insecure they are what Well, everybody's exist. So first yeah actually has a provenance log, which you can query you can write automation. You can fail builds you can stop releases you can push stuff to production if you have an exceptional scenario, right?
So it gives all the tools For you to operate in both areas, right and and do security first or security lasts because we know that it needs to go along the chain not just you know, we just verified it when we were doing development and then forget about it. Exactly exactly. All right Percy.
You have p y r s i a. Yeah that I oh that I oh first. io.
Hey, it's part of CDF. If you're a developer looking to get smart about security between what so ninja said and Steve before him said this might be really something you want to check into for your security guide looking to help you develop in a devops teams. Great Project, Check It Out
