Stephen Chin, JFrog | Open Source Summit NA 2022
Transcript
This is Textron TV. Hey everyone, we're back. What a great day.
This has been here for us at the open. Source, Summit Linux Foundation open source Summit here in Austin and I couldn't think of a better person to end our day with them. My friend Stephen Chen Steven is of course with Jay frog he has a lot of hats he wears over there but we're gonna talk today specifically about an open source project that Stephen has been shepherding.
Is that a good word? Yeah. I mean, it's it's my bad idea.
So okay responsibility for good or bad. He's taking responsibility and that's not a bad thing. The name of the project is on his shirt here.
It's called Persia. So it's not Persia. It's Persia and and Stephen.
Let's start that what what's purse here about? So I I think the question is why Persia why before we get to white person? I think it's what purse here.
Okay, let's let's do what and we'll quickly go into why so what what we're building with Persia is we're building a decentralized package Repository. That will will essentially give you all the capabilities you're used to getting from from dockerhub from Maven Central from PI from npm. But in a vendor-neutral decentralized infrastructure.
We're also you can rely upon having a very high level of security because we're building everything from source, which we provide to to the end users. I love this idea. Why did it take so long?
It's a hard problem. Yeah. No, it is a hard problem and right but we've built plenty of repositories.
Yeah, so I think one of the things I think we we all know this from working in devops and the repository spaces, there are Dozens of different Integrations with Upstream languages technology is package managers and they they all they're very specific to the language. They have different benefits. They have different ways of approaching immutability versioning how you handle conflicts with upstream dependencies.
And while that's that's great that we have all this, you know unique infrastructure. It makes it very hard to have a high level of security to evolve the ecosystem and frankly a lot of the package managers which have been around for a long time suffer from some inherent security risks, which you use just by using them in the central repositories, which they rely upon. so I've got comments thoughts that I'd like your thoughts on on this number one.
I've wondered for a long time why we wouldn't have one repo to rule them all. Why do we need this United Nations of repos for every damn language, even with all due respect even within Jay frog every year I go to swamp up or one of the jail and that we oh, we're just announcing artifactory for go artifactory for this language artifactory. Why can't we have one repository to rule them all?
Yeah, so I think I think it's a it's an interesting problem. So for example artifactory one of the things which were known for is being the Switzerland of devops. Yep.
So artifactory speaks every repository manager every different formats. There's over 30 different formats. We just announced binary Swift protocol support.
It's very very hard work to build something which integrates across different languages different ecosystems and to understand all these different domains and do it. Well. And I think that's one of the problems we're trying to solve with Perseus.
Not just a jfrog project. We're collaborating with Docker. We're collaborating with Oracle.
We're collaborating with deploy Hub and future way in Huawei. So we have a what growing a wide and growing set of companies which are contributing to the project and we all have our own Goals, in terms of like languages ecosystems platforms secure build Technologies. We're bringing to the table.
But I think when when you we do this together as companies and we build a decentralized infrastructure on Technologies, which are Next Generation web 300 and scalable. Then this really helps us to to solve the problem and to fundamentally secure this critical piece of infrastructure for open source. So look when I hear you talking about Multiple companies being involved to me.
This is crying out for a foundation. So what what's been the thought around making Percy a part of a foundation? Yeah.
So I think that obviously when you have an open source project like this, we want it to be a full open source stack. We want it to be vendor neutral. And a great place for this is the the Linux foundation in general.
I mean Linux Foundation does a great job of this you can see this with the number of vendors involved in cncf involved in all the other efforts which they have. And I think where we were kind of Landing with Persia is a big part of our focus and like the current phase two infrastructure. We're building is this verified build infrastructure to build from source to binaries.
It's sitting on top of tecton and sitting on top of CD events. It's using a bunch of the Technologies which are part of the CD foundation. And as a project we're thinking it really good alignment with the continuous delivery foundation.
And we actually just this morning we chat with the technical oversight committee got a really good response from them. And I think that that's progressing well and hopefully we'll be part of a vendor-neutral foundation soon to further Advance the project because I think that gives the some neutrality which we need to become a standard. Absolutely.
That's great news, you know, look you and I even talk all the time right CD Foundation is it's about two years old now. And it went through a time where you know, the initial leadership moved on they recently put a new a chair in and some new board members and it seems to have revitalized CDF and and look it's part of the Linux Foundation, right so you yeah, you know you yeah, not that I mean the CD Foundation fundamentally has some really really strong projects finger attack on Jenkins. Absolutely with the new leadership Fati is joining as the general manager right?
Also, I'm the chair of the governing board new folks coming in to the marketing committee and proposing projects. So I think this is this is kind of like a Renaissance of the city Foundation where it's going through another transformation and the the new projects coming in are broadening the portfolio from being pure continuous delivery Technologies to bridging out to security to observability everything you would need to build an end-to-end devops platform entirely on open source Technologies. Love it.
I like this another reason I think at the end of the day from how you describing, Persia. It's not just about security. It really is about how do we how do we decentralize our you know, I digress but I went up to see lionesses keynote this morning one of the things I guess I knew but I didn't know was that not only did he Start Linux right create a Linux, but he created get.
Right. He's pretty cool when you think about it and it I'm the idea of having a decentralized repo like this. I don't know if it was something he envisioned.
When they did get all those years ago or not, but I it's so much there's so much that can be done there. Yeah, it could be set free. It's you know, you can set these repos free to some level now.
No, I think I think a good parallel to that is like one of the ways which I've described people the level of change and Innovation going into Persia. is it's it's essentially good for binaries, right? We're building the the decentralized Switzerland of binaries so that now you can get all of your here verified packages from this decentralized infrastructure and something else which Linus torvold said in his keynote this morning as well was that their seriously looking at rust not really for building device drivers, but for doing some Linux kernel development and we we made the same assessment when we start the Persia project and are actually building the entire project in Rust Because it gives you we believe today the best high-performance verifiable language were you you can you can have a higher level of security guarantee on the code you're writing then if you built it and for example like c c plus yeah you go and other Technologies.
Well look, Today's choices around languages are nearly infinite. Today Russ may look like a really good one. Five years from now three years from now something cool comes out.
You kick yourself. All right, which I comported to that. You know, you say that but most languages were using today but been around for 20 plus years, so Really yet most languages were using but when it's the compiler technology and the tool chain and like getting things to the level where you can build production grade software is it's a decade of investment on any of the languages you're using today.
And the the languages people are most reliant on like python Java. Our old jobs. No doubt.
I've been around for a long time. But it does seem like every graduates turning going for their PHD designs their own language. It's all another story.
I want to I want to so first I want to wish you a lot of luck with Persia. When do you no pressure, but what do you think we might hear? Some news on this CD foundation.
And yeah, so I mean in terms of the project you can already go and try it Percy that I/O the peer-to-peer system is entirely functional. We have a backing authorized server which will give you with our partner Docker official Docker images off the percya network. Great, which is awesome.
We're working at the CD Foundation to apply for incubating status. So we're very hopeful but of course, you know, we want to go through the right technical vetting process there. And I think that the new stuff I mentioned kind of this phase two work on our verified build infrastructure should be ready by the end of the year.
So we're moving aggressively but doing it in a collaborative. Oh by the end of the year six months is not a lot. All right, let me switch gears with you.
So I've been listening all day to people talk about Supply so forth supply chain security. and I I just wonder why we haven't put more emphasis on the repo. organizers To clamp down on knowingly out of date insecure vulnerable.
Artifacts or code or whatever that they're repo contains. Right, if you know I get that there's a freedom issue here. Right?
If someone wants to use this old version because they have a good reason for using it knowing of the insecurities and so be it but why aren't we doing a better job of warning people that hey don't use this unless you ever really good reason. Okay, so I think that First of all, if this is a hard problem and it is there is a lot of discussion efforts going into it and I I think you can categorize the type of work going into it into three buckets. So one set of work is going into Shoring up.
The the current central repositories and there's a there's a great working group that's part of open ssf which is dedicated towards this. They have a plan which both companies are currently investing in which requires some funding to improve for example signatures of people submitting to Central repositories having like more secure namespacing and verification of domains, and there's a whole bunch of things which are either inconsistently or not. Well applied from a security standard for Central repositories.
The second class of things which I think is important for this is security disclosures. So different security research firms, and we've been doing this a lot from our security research team at jfrog both research vulnerabilities. They disclose vulnerabilities first to the the person who's responsible or owns the asset, which is vulnerable.
So and a lot of our recent disclosures have been basically malware or problems in central repositories. We found a exploit Um targeted at Azure developers, which was in npm where they specifically checked in packages with the Azure namespace left off. It's essentially a typo squading attack.
They got a lot of hits on this and we reported it and had them pulled before it became an issue. But like you need vulnerability research teams who are looking for this and helping to remediate it. And I think that the third one getting back to the Persia project is frankly.
We need a Next Generation infrastructure, which is secure by I don't think the repos were build for that particular. Yeah. So so the functional the fundamental table Stakes are do you have secure validation?
Are you building from source and and can you verify and build a build materials off of it? And that's not true today of all the central repositories great. Hey man, we're about at the time.
Is there anything we missed on this? No, I mean this is this has been a great conversation. I mean, I've been enjoying open the open source Summit here in Austin and I would say that for folks watching, you know, join us out here next year because this is an amazing event.
Just the networking the interactions. It's sessions a great too. I'll be on yes the ones I've been able to jump in on but also just mention that it is tomorrow and Thursday and there is a virtual there.
But yeah, absolutely, you know streaming this virtually you can check that out too is I've mentioned earlier. Anyway Stephen. Thank you so much.
Quick shout out also next month. It's next month. Yeah y'allah devops in Tel Aviv, July 18th.
See you and we will be there. I think we're gonna be doing our thing there. Actually, I'm on a panel there, but we're also broadcasting and hope to see you there.
All right, we're gonna close out day two. Well, it's really day one, but it's our day two coverage of Open Source Summit here and Austin with the Lennox Foundation. We'll be back tomorrow.
I think we're on around 9:30 or 10:00 o'clock Austin time. And we'll see you then until then. Have a great day everyone.
We're out.