Utpal Bhatt and Fahad Rizqi, Tigera | KubeCon + CloudNativeCon NA 2022
Utpal Bhatt, CMO of Tigera, and Fahad Rizqi, vice president of sales at Tigera, join Alan Shimel at KubeCon to discuss Project Calico, a solution for open-source networking and cloud-native security.
Transcript
This is texturing TV. Hey everyone. We're back here live at kubecon in Detroit Cloud nativecon, continuing our coverage.
Well, it's day three of the event but day one here on the Expo floor. Hopefully you hear it. Well, it's pretty loud.
It's there's a lot of people and the show flow is really big but it's spread out. So it's not as dense, which I guess is good for covid and everything anyway. Our next guests are two folks from a company called tigera and they are the folks also behind project Calico.
And let me introduce you to them on my far right I have a would pop bot. Haha that your we missed that up. I apologize.
It's Life TV on my near right? And I might far right is for hard risky. Yes gentlemen.
Welcome. Thank you. Thanks for having us.
All right, so, you know, let's start I should before we jump in and take care of let's talk about who you guys are. So, how'd I apologize? You know, I went wrong name, but what do you you know, what what's your role at Tiger and maybe a little bit of your background?
You're absolutely so again, my name is fajard risky and the VP of sales here at tigeraira. So I head up we're like sales for for the company. Okay?
Yeah and your background from before take care or yeah, absolutely. So I've been in you know, startups and security for my entire career. So before this I was with the company called centrify and then oh, well, yeah and then and circle those and far away before that.
So yeah and circle when they were already tripwire before trip before tripwire. So I was there part of the acquisition and then a lot of friends. Yeah, maybe that's where I know you from that could be yeah Andrew storms and oh Elizabeth.
Oh, yeah a Kleinfeld absolutely like Murray was there and yeah, so, you know, you know the photo I know. Yeah well I also have a history. I I got 30 years in security.
I co-founded company called still secure. Okay, we're competitor. Actually that Circle.
Oh great tenable. Oh, yeah Stone follow us. Those were the days were the days.
Yeah. Anyway, Excellent Man welcome. Yeah Paul.
How about you? My name is Paul about and I'm the CM of taguera handle most marketing activities there as far as background goes I've spent over 20 years in the infrastructure or analytics and more recently in a security space prior to Tiger. I was at an AI and machine learning company called Cubo and then before that I was at neo4j, which is a graph database company.
It's very, yeah, so a lot of experience with open source and really excited to be here. Well, welcome to both of you. Let's talk a little bit about Targaryen as I mentioned there.
Also the folks behind the open. Source Calico. Yeah project.
I don't know if you want to start with tigerra. So I was Calico we can you know, maybe we can for the audience would be great. If you just recap the story so far and then we can build on top of the story great.
So we're tired of you're the creator of project Calico. So it all started back in 2016 where we introduced project Calico and open source project to solve container networking and security needs and the project has you know by far become the most popular and most adopted project whether you know, the most recent data dogs study or cncf study on the most adopted see nice, you know, Calico peers right at the top. We are among the top five Technologies on any contain Kubernetes image and we've been downloaded from the docker images over a billion times.
Wow, so, you know more than in a company's across 166 countries. So it's you know, it's stupendous. It's not safe.
Let me just be clear is calico. Part of is it a cncf project or it's your tiger. So Calico is is an open source project.
It's not part of the Sea of project where we work very closely with the cncf team. We are silver members of the silver of the of the cncf foundation you work very actively but yeah, I think a lot of the adoption is from the cncf community. Road this open source cncf communities such a dynamic.
Yeah. Yeah kind of and then you know from then on I mean maybe before they want to just take on to the the platform side of things, you know, since you have so you know over time I was like both said Calico has become tremendously popular as a cni. And so what we've done is over the last few years, we built commercial offerings on top of Calico called Calico Enterprise and Calico cloud and you know where that adoption initially started was from through the platform teams and these organizations and these teams were essentially building out their kubernetes platforms and what they needed initially and obviously even more so now is the networking and and the network security aspect of things.
So for a platform security and the platform team perspective, we you know, provide a host of use cases and solutions. More than solve a lot of use cases for them everything from like I said, you know networking and the network security piece. But within that you know, if for example, what we do is we provide things like DNS policy and egress access control.
So if anybody needs to access anything securely outside of the cluster they can or behind a firewall they can securely do that. Right? We provide very deep observability for that kubernetes environment.
So, you know, very deep flow logs to you know, service graph the packet inspection so very deep observability with kubernetes context and not just kubernetes contacts because Calico is such a powerful underlying policy engine. It gives you very deep observability that no other solution can really provide so very quickly a platform team can look at your your kubernetes environment can look at you know, a Calico Enterprise or Calico Enterprise. And you know dashboard and see very quickly, you know, what's happening on the network?
Whereas if something's going wrong wear something going wrong quickly pinpoint it and fix it and also because you know, we're not only detect we also prevent and mitigate again because we're a policy engine. So when we do detect something we'll provide recommend policies to say. Okay, how do you mitigate this attack from or mitigate something?
That's bad that's happening. Yeah, so, you know, so it's we provide a you know, we essentially if you think about it for the platform teams, we become the firewall for your kubernetes environment, right? We essentially become the firewall for that environment, right?
So yeah, we hear a lot about You know security networking and container kubernetes environment. Start thinking or hanging about Matt service smash, right and that becomes sort of the communication layer. For networking it's security to work it.
the way I'm hearing you describe it though is Calico and tigers sits below the service mesh layer, right right on Coop itself. Yeah, it's actually there or does it maybe I got it wrong. It's a great.
It's a great question. So when it comes to What so like I said it started off as the the container networking and security interface. But what Calico provides is the ability?
So when you talked when you talk about the service fashion or the primary use cases for a service mesh are security observability encryption. So when it comes to those types of capabilities, whether it's you're looking at it for a single cluster or you're looking at a cluster mesh. Calico can provide that because Calico enables connectivity between the Clusters the part-to-part communication it enables, you know policy the application of policies all the way from L3 to L7 layers, even at the HTTP layer and then it enables cross cluster observability.
So a lot of the functionality that an organization is looking for let's say if you're deploying a multi-cluster environment where you have microservices running across multiple clusters and you want to present a single management plane through which you want the services to be visible, you know, Calico can enable you to do that in an operationally much simpler way. We also integrate with service meshes, you know, if organizations want to use service mesh. Let's say for traffic shaping or for the core service mesh use cases, but for specifically for security observability encryption Calico does a lot of those a lot of those offers a lot of that among nationality.
and then one more thing that you know, we we do Is you know galico over the years we have expanded our footprint to cover the entire ci/cd pipeline. So all the way from vulnerability management with image scanning admissions controllers to kspm and then runtime security by looking at your container activity or by your network activity, you know, we can we can alert you on any type of thread. So our our value proposition really is that you know, it's a active security for your entire kubernetes platform, whether it's that helps you prevent threats from happening or prevent attacks from happening to detecting the attacks and then if attacks do happen mitigating those by deploying mitigating controls to prevent them from becoming into a disaster, right and you know, the last thing I mean about calicos is done is Ebpf is a is a very hard topic and you know, it's Calico support cbpf.
It's one of our primary data planes. So when we use a lot of vbpf in our solution as well for a lot of runtime threat detection and observability. Okay.
so what we're Calico leaves off in Tiger provides right? Where's the value at? Yeah, so when as we were talking about so Calico, oh open source is primarily addressing your networking.
I go and your network policy needs. Calico cloud and Calico Enterprise, which are built on the open source Foundation provided by Calico. There's what they they provide Advanced security observability and that's capable.
That's so more is a service correct? Not an open source tool that you kind of configuring yourself correctly. Yeah, and that's kind of the main thing here kind of foreign, correct.
So think of it as you know, networking a lot of what we provide for networking is it's free. It's in the open source to Maine a lot of security of durability capabilities in advance kind of multi-cluster capabilities. Those are in the commercial offering All right.
Let's pivot a little bit. Let's talk about how do people engage with this. How do they get started?
io. And you know, so for example with Calico Cloud you can get started very easily through the website you can you know, get a two week free trial there and get started and anybody can you know, go there and sign up and within 15 minutes, they'll be up and running and you know, that's the easiest way to engage with us and and also, you know, you can go through the website and ask for a demo or contact us and you know, and you know, we'll we'll reach out immediately really love it. Yeah good stuff now.
That's really that's for the service thing. People can go download the Open Source. Calico themselves and stall it on their own and and do all that for the for the what's called Calico is a service Calico cloud.
Still have to install kind of the agent. So whatever aren't your own. infrastructure, and then it communicates back to service security issues around that so The way it works is the management plane that we run is sitting on the on the in the cloud.
But you're the data plane is alongside your kubernetes bus route on your own right? And so what we're doing, you know, so that's kind of sitting inside your environment. And then what we're doing is we're collecting the metrics and sending it up to Calico Cloud.
So the so there's no security issues there love it actually and again, it's high gear that I owe t i g e r. Sorry, they don't hear this at home. You guys aren't hearing this, you know, but there's like a train that goes around here and it sounds like a car or something.
Yeah, but thank God the mics Mike get out filter it out. Anyway, it's Ty gear a t i g e r a dot i o that's right. And that's the place to go get all this information.
Absolutely. Yeah, and if you if you love Calico you love Calico Cloud for your security and obserability needs. Absolutely.
Excellent story you guys for hard Paul. Thank you for joining us. We're taking a break.
We're in Detroit. We're rap. Well, we probably have another hour, too.
Right of coverage today. We'll be back in just a moment.
