Avi Freedman, Kentik | KubeCon + CloudNativeCon North America 2023
Kentik announces the general availability of Kentik Kube for rapidly troubleshooting networking issues within Kubernetes. Learn more from Avi Freedman at KubeCon.
Transcript
This is Textron tv. Hi everybody. Welcome back to Kku Con 2023 here in Chicago.
What of great announcements happening at the show? And I have the privilege of being joined by Avi Friedman. Avi is with Kenty.
Welcome. Thank you very much. It's great to be here again.
Good to have you here. And some exciting, well, first of all, what do you do at Ken Tech? Tell us a little bit about your role.
I'm one of the co-founders and I run the company, so I am a, uh, nerd, but also nerd about business as well as technology now. Fantastic. I wanna make sure we got that in.
Yeah. Um, so tell us a little bit about what kind of things you're talking about, the show, maybe some announcements. Sure.
So Ken Tech is a network observability company. We have an observability based platform, but we've been replacing the appliances and Windows software that the network that the IT industry and network industry has been using. And we've always taken a pretty broad approach of what is infrastructure, and that's included cloud native.
So we've had some Kubernetes visibility, but here we're launching Kube, which is even more visibility into the entire Kubernetes state, east state, integrated with the visibility about how all the clusters connect to each other between clouds across the internet, through the hybrid infrastructure. So we're pretty excited about that. Great.
Mysteries of Kubernetes. Oh, Of networking Kubernetes. Exactly.
Raider, you know, uh, the Raiders of the last ARC of Kubernetes here are digging into that. Exactly. Well, there's a lot myth that all this stuff talks to each other.
Cloud native by extrasensory perception, but ultimately the network somewhere is connecting all this stuff together. What Is it? The things we don't understand is magic.
Right, Exactly. Just something about that Sufficiently advanced technology is indistinguishable from magic. Yes.
I think that was Personal plus. That's the quote I was thinking of that I couldn't remember. Yeah.
Um, so, so tell us, I mean, you, you're coming from originally coming from a network perspective on observability. Yeah. As you embrace Kubernetes, is that still looking at it from, for a network or operations audience?
Or you think, you know, some people approach it as a developer kind of view into what's happening? Or are there multiple personas that you take? We're generally gonna be the place where the infrastructure network teams, whether it's architecture, operations, infrastructure are gonna be living, but often the security team, developers, the cluster operations, they'll come into KENTY to look at something that's, again, if they, especially if they need to look outside of the Kubernetes infrastructure and figure out where there's an issue between, but understanding pods and namespace and processes and all that, we're bringing that all together, but tying it to the rest of the infrastructure.
So we are more infrastructure or network persona based, but we have users in many other groups inside the company. And we also have partnerships with new relics and logic, other observability companies where we'll feed them data, you know, with our view. Uh, but like many people here, we have an EVPF agent taking EVPF approach as a great way to get that kind of enriched telemetry from the Kubernetes infrastructure, EBF being able to be processes inside the Right kernels, f being able to look at the traffic where the kernel's aware of it and bring in a lot of enrichment so that you can see not just something happened from this port to that, but what process, what application and what Kubernetes context in terms of pod and namespace and all that, it's actually running in.
Interesting. How, how is the, um, infrastructure maybe kind of platform and, and network groups, how are they taking on Kubernetes? This is a lot to learn.
Yeah. I mean, it's complex to anybody, right? Whether you're an infrastructure, software infrastructure or app or you know, cloud kind of person.
Um, are there things you, you can do to help people kind of gain an understanding of how Kubernetes functions, what the purpose of a cluster and a pod and all this stuff, all those agents and things that are part of the architecture? Yeah. Well, there's a couple things we help them with.
One is the state of the Kubernetes infrastructure. The other is what's running on top of it and how it's performing or not. Because running inside Kubernetes as opposed to on routers and switches, you can actually see performance.
You can see application traffic. You can see again that Kubernetes context. So we're not, we're primarily trying to understand how are the applications inside Kubernetes running.
But a byproduct of what we're doing is that sometimes the network people that are trying to understand is the Kubernetes cluster itself having a problem. Uh, you know, Kent take is helping with that. And the first version of what we did only looked at traffic that was active at a given time.
But because Kubernetes so dynamic, uh, we needed a more complete vision. So what we're launching with Kinte COB is looking at the entire estate, the entire state, whether there's actually traffic there or not, which helps, especially when there's problems with load balancing, problems with orchestration, which are some of that Kubernetes complexity that you mentioned? Mm-Hmm.
Now our persona, the people that are primarily using Ken Dick are probably not the people that own that, but they do need to figure out meantime to innocence. Is this something that that team should be looking at? And so that's where we're helping them.
And then if that team needs to see why does my network team, why does my cloud team think there's a problem, then they'll come into Ken Dick or we'll be pushing data to look at that. So primary user are the infrastructure focused, but going up the stack as people do the debugging, which is typically, we're not trying to be the LA the last line debugging monitoring platform for the Kubernetes infrastructure itself, but we do need visibility into the entire state of it. Yeah, it's interesting 'cause you're obviously getting a good visibility into the application.
Yeah. What are the environment that that's operating on? How is it performing?
You mentioned security. Why does security come into this? Well, network has always been a key source of food for security people.
Where kentex started on the internet and cloud side, denial of service attacks have always been a very big thing. And coming at it from an observability perspective instead of an appliance perspective, we've always, since 2014 when we launched, stored everything. So we don't do roll ups.
You can always ask any questions. So we are a forensic platform. We're just very OP focused on the operational use cases.
But just as sometimes we have cluster operations team come in and use US security teams when they find out that Tik has all this data come and say, let's use that. And we don't charge per user. So we try to go adjacent and get those security teams using it.
But again, we're not the complete platform for the soc. But if they're looking for that forensic capability to say what happened last week, last month, integrate threat feeds and understand maybe this traffic from a process to the outside world that there shouldn't be. Kent Tech has the visibility on that and very forensically.
So it's in that adjacent world where they're trying to do things, they don't really have a good platform for it. And Kent Tech can be that typically, again, it's a partner organization inside that company that's buying it, but then we're enabling that security team to get that kind of functionality. So there we're partnering with CrowdStrike Sentel one type companies to be part of that security ecosystem rather than trying to be that we're only a couple hundred people, so there's a limit to how much we can do.
Yeah. It's a big o several big o oceans to boil right, too. Yeah.
There's different Terminology. I mean, it's all the same stuff. Underneath networking is just tunnels and routing tables and Protocols And, but it's got different names and bugs in every cloud and every on-prem.
So there's a limited world that any one company can play in until they get to a certain size. That's one of the things that, you know, in, in my work, it's trying to find common denominators is like in the security world, we all know about, we talk about ports and protocols Yeah. And the world and APIs and things do to protect that.
And it's very much what we think about in cloud native microservice. And I think that the Kubernetes world has to bring to the security and the traditional operation worlds is going from ports and protocols to ports and protocols and processes. Mm-hmm.
Right. Because typically even in a world where you had ADPI solution in a security team, you didn't really know what was happening inside the computer. And EVPF gives you a tremendous ability to get that instrumentation.
Now it's got some challenges because it only sees what terminates on the kernel. Right. So if you've programmed your kernel to ignore certain stuff, most EDPF solutions won't actually see that traffic.
We come at it from a little old person perspective. So we see all that, but we'll, even if you're not running Kubernetes, we'll see that there was traffic attempted dropped, you know, so that makes it interesting to security teams also. Interesting.
So, um, Tik Kube, is that available now or are you kind of in preview or it's fully No, We previewed it all last year and it's fully launched right now. Remember, people give it a shot. Very good.
So is is it hosted? Is it, I can download it, run in my data center? What's the model?
Kent is hosted where we, we run it as a cloud service. Um, we do run private clusters for people that are of a certain size and won't let their data out. But we're not licensed software that someone installs and manages.
Okay. We do have agents that are largely open source, or at least source available that people can run to in the EVPF world, observe traffic or encrypt telemetry so that it, it's not going unencrypted over the internet. Well, you also have the, um, the kind of, uh, privacy controls regulatory environment, you know, in certain Countries we all have to deal with of the largest enterprise and service providers in the world.
So that's something we had to deal with since when we started. Yeah. I would imagine you did pretty early on.
Yeah. Well, and it's, and it's evolving all the time. Too hard to keep up with it.
What, what was the, um, kind of greatest thing that you learned from the time you started your kind of beta preview to, to launch? What did you learn from your customers user, people working With it. It was, it was sort of non-obvious given our background, but the big thing that we had everyone saying was, I want to see the entirety of my Kubernetes estate even for things that are inactive right now.
Hmm. Okay. And the way that we first built Kente Cobe with EVPF was we were really taking an EVPF only view, but we needed to build metrics scraping and understanding to go reach out and API scrape to understand the entirety of the Kubernetes infrastructure, even if there was no EVPF visibility for some of the debugging and meantime to innocence, things to make sense.
So that was what we built over the last six months. And that, that is part of what we launched. Coming at it from a traffic perspective, we figured, well, there's no traffic, it's not a problem.
But on both the operations and security sides, we saw people asking to see more. We figured that was more something they would get from Datadog or, or New Relic or one of the other companies that they might use as a larger observability application focused. But apparently there's some gaps there too, and we're happy to fill those.
Is that because of the kind of the ephe ephemeral nature of, you know, exactly. It's, it's, you know, what's here now is not what was there then, right? And I need that full context.
Yeah, yeah. To see something historically and be able to aggregate it, they really needed to see even the things that are ephemeral. But also most of our customers have some portions of Kubernetes where they're not able to run EVPF traffic observation with us or competitors of larger observability players.
And sometimes you see traffic going there, but to be able, so in Ken Tech, we have a very broad ability to enrich traffic. So by taking data from the Kubernetes metadata, even if there's no eeb PF agent installed, even if you're just looking at NetFlow from a router on the other side, we can still know what pod and namespace it went to by updating, you know, on a second timeframe, all that ephemeral orchestration and taking all the rest of the network data and applying it. So Interesting that, that's a sizable challenge.
You don't need me to tell you that, But we started trying to understand the entire internet, all the users and DNS traffic across the entire internet. So this is large scale, but only the same kind of scale that we've been running at since we started Our bigger problems. Right.
Yeah. Yeah. Um, I, I'm curious, one of the things we always have to deal with is variations, variance, different distributions of Kubernetes service provider versions.
Yeah. What, what are the ones that you've, I, I mean, do you work with pretty much everybody's Kubernetes or you had to kind of selectively be able to figure out which ones you're gonna be able to work with? I Mean, so far looking at the common APIs has been sufficient.
We have a static binary, we haven't any issues running it. We've probably run on six different Kubernetes. We can call them distributions, uh, as demon sets without an issue on the Eeb PF side.
And then the API side has been pretty common. So I would say the clouds are much more of a pain in the ass, uh, to both build fork 'cause they're all different and then they change pretty frequently and rapidly. So, Uh, I can imagine We've done the same thing already for VPC flow logs and OCI, Amazon, Google, you know, Azure trying to make sense of not just it as SS log like you'd see in CloudWatch, but looking at the APIs building topology, it's actually been much harder in the cloud than for Kubernetes.
Why, Why is that? You know, you're talking about VPCs, I mean, we think of VPNs being pretty standard from a protocol standpoint, but what is it that's challenging about That? Well, as I said, you know, underneath the cloud providers like to pretend it's not networking, but it is, it's routing tables and filters.
ackles At some level. Yes. It's got, it's got eventually.
Right. And, but they all have their own weird names and primitives. In this cloud, you can have one VM being multiple VPCs, one interface being multiple V vp and that one you can't.
And then to figure out some of them in real, like Google's very good at, well, both giving you performance data, but also they'll put a lot of that metadata in the flow log. But Amazon and Azure, you need to go reach their APIs and figure out what it is and, and, and join it. Okay.
So they're all different in terms of what they support. They use different nomenclature for the same things. They have different primitives.
And so as a vendor we have to unify all that. And, you know, in different ways, companies like Aviatrix or Al Qra are trying to solve that problem from a networking substrate, from an observability perspective, we still need to form one model and unify it. And it's just been harder.
'cause there's more work to do and more variance than the Kubernetes ecosystem. You mean they're all on standardizing on a set of MIBs and we'll be able to No, redate out a device. Talk to me, you'll talk to me at, uh, maybe by reinvent time we're doing some stuff to unify streaming telemetry, which is the Oh, interesting.
Hipster version of SNMP. With SNMP. But I shouldn't preview that, that release too much, but I think it kind of did a little bit, but, okay.
Okay. Well that's okay. It's out there.
Okay, Good. Um, so, uh, if folks wanna check out, um, yeah, connect Ken Tic, sorry, kinetic. Ken tick Coob, uh, what can they do?
How, how can they kick some Tires? We're company in Kinetic in our own way. Kinetic.
Yes. What we're here, it's nice and it's a nice little slip. Yeah.
We're here at KB Con, so we've got a booth, we're here the whole time. com. K-E-N-T-I-K.
Uh, I'm happy to hear from you. com or Avi Friedman on LinkedIn, Twitter, X, whatever. Well, it's nice and I would imagine, um, you're kind of a, a solution.
Usually you can point data to, to a cloud, a cloud offering like that. Yeah. Very easily.
And start to see what, what you can do with it. Yeah. People can sign up, self-serve.
If you don't wanna deal with us, you can sign up, sending us telemetry, start using it. We have a built-in self-driving demo so people can see it, what it looks like in the cloud offering, even before they send traffic to it's Fully populated. Yeah, exactly.
Kind of get to that point. It's synthesized traffic. It's not a customer's actual traffic, but Yeah.
Yeah. It's interesting. Yeah, I actually talked with the company for developer, kind of that they actually did monitored their own development environment Yeah.
With their product. We do, but we can't share that. Yeah.
There's some of that, that might be a little bit of a security concern. Security concern, Customer, customer IP addresses and stuff that are That's True. Yeah.
A little bit of data leakage. Yeah. Different problem we wanna solve.
Yeah. Since the core of what we do is always been traffic data and then we've branched out from there. Our customers are very sensitive that it's, it's not our data, it's their data.
So. Yeah. Yeah.
Very good point. I understand that. Well, good.
Well, uh, congratulations. Thank you Very much on The much, and I can, you, you were describing what you learned and what you had to go back and Yeah. And add to, to, to give that fuller picture.
That's not a small effort in the middle of a Okay. We would like to go ga. Oh Yeah, Absolutely.
It's just a little bit of tuning of Book fix. We have four other products too, so, you know, but, uh, Yes. Oh, by the way, right.
We're keeping Another Yes. But we have a great team and when customers are driving it, it's much easy. It's very easy.
If you have, you know, multiple customers saying, okay, but I need this and then it will be bigger, or I need this, you know, to buy it, then it's much better than when you're building on a thesis. And we're at the scale where we have that. So Customer always wins.
I mean, that's, those, those arguments are usually better solved. We do everything they want, but we try to be driven by by what they want. Yeah.
Well, I mean, thanks for talking with us. Thank You very much. Great news.
Thank you for having me, Your progress. And we look forward to more great things from You. Thank you.
As I said, and The streaming kind of announcement we sort of talked about, not Announcement this be telemetry, uh, the, the, the metrics side we'll talk about more, you know, in, in a few months. Okay. So is that as we're gonna talk about it at reinvent or you think, Uh, we might reinvent or maybe slightly after.
Yep. Okay. All right.
Well, we'll be there, so, okay. Okay, cool. Alright, Avi, congrats.
Thank you very much. Good To chat. All right.
Be sure and, uh, check out Kente and Kente, Cobe and all the other products, services that are available. And, uh, it's always fun talking with people who are creating kind of great new things and the amount of effort and care and passion it takes to do that. It's always a lot easier when their customer's right there asking you for it.
So it's good to hear that's happened with Kente. We'll be back right back with our next interview. So stay tuned from here at Kon 2023 in Chicago.





