Exploring Innovation and Efficiency at SUSE with Andreas Prins – SUSECON 2025
Andreas Prins shares insights about his role at SUSE and the importance of product marketing following acquisitions. The discussion highlights technological innovations, including the launch of DevX for developers and a curated library of compliant applications. Security and compliance are key focuses, along with AI’s impact on observability.
Transcript
This is Textron tv. Hi everyone. It's Alan Shimel for Techron TV back here at Scon.
My next guest is someone actually I know of long time before Suse even entered the picture. He's my friend Andreas Prins. I first met Andreas.
Geez, it wasn't Amsterdam, it was before Amsterdam. I think it Was Zia laps At Zia. Yeah.
CID No, it was Jenkins wrote in Nice. Where we were sitting in the glass Box. What a trip that was.
Yes. Nice. I had that goldfish old, you remember?
I know, I know. A nice, nice, what a great place to do. It was.
Oh yeah. I brought my wife with me to that one, and we still talk about that trip. We did Monte Carlo.
I did con look. We're stuck here in Orlando. There's worse places to be than Orlando, but it's not nice.
Um, it's Nice. Yes. Andreas, why don't we start, what's your current role at suse?
Yeah, so after the, uh, acquisition of Stack State eight months ago, uh, obviously we focused very much on integrating the companies. And I'm currently transitioned to a role in the SUSE Cloud Native business unit, if you like. Really much focused on product marketing.
So we have great engineering, great products management, but the kind of the mission gap was product marketing. And that's important. Hey, if you have great products, how do you bring the value alive for your customer?
And then product marketing is what you need to do. So go to market strategies, a lot of enablement work, um, and a lot of marketing towards customers, prospects. Absolutely.
Yeah. And you mentioned Stacks State. You were the CEO of Stack State before you were CEO.
You ran product there as well, right? Yeah, yeah. So long background in in products and engineering leadership roles.
Yes. Uh, in in many startup and scale ups. And then lately before becoming the CEOI run product for Stack State and now known as Souse Observability.
Excellent. And to me last night, well, we're gonna talk about what I saw at the, excuse me, in the solution showcase last night. You, you gave us a, a demo and a look called sort of a peek into the near term future.
And it was the first time that I saw, let's call it the whole picture of the Susa strategy. And I was, I was with Mitchell Ashley, who, who you know, and I, I walked outta there and I said, Mitchell, I never realized Susa had the A to Z of this whole stack. Yeah.
It it, and I don't think a lot of our people out there know, you know, a, a common thing, Andreas, that I hear from people, whether it's in cloud native or security, not so much technology in general take 'cause AI's changing everything. But they all say, where's the innovation? I don't see any new innovation.
I, you know, I learned a long time ago that 99% of what we do in tech is evolutionary. Exactly. Exactly.
Only 1% at best Yeah. Is revolutionary. So if you wanna see it, innovation, sometimes you gotta do it in stop frames, you know what I mean?
And look at it over the breadth of a year or two to see that innovation happening. I had a moment like that last night when, when you were showing me, uh, the diagrams and everything in there. Um, some may look at it and say, well, what's innovative about it?
Well, I don't, you know, what's innovative about it is it's, it's not making new parts, but it's combining it artists. Exactly. Yeah.
In a way that haven't been combined before under one roof, one easy to use thing. They may think I'm crazy. What is he talking about?
Yeah. Al's just rambling again. Explain to our audience what you showed me last night.
Yeah. So what we launched here at suzuko is what we call DevX validated designs. DevX referring to the developer experience.
Because what we, uh, if you think about innovation or not, but platforms are a commodity, right? Kubernetes established around for more than 10 years. CI/CD tools, very saturated market.
Everyone applies it. Uh, s code practices, decorative nature, standardized practice. So from a platform or technology perspective, well, what's innovative that you can add there, but what is super important, if you think about larger enterprises, you really wanna focus on adding business value innovation.
And what we thought about here at suse Cloud Native is really, okay, if we have this rich set of capabilities that support cluster management, that support private registry, that has a rich curated set of application containers, how can we level that up and really focus on helping out software developers get their application from commit to clouds, or actually from code to cloud, if you like, really in minutes. And that's what we're launching with the DevX validated design. So what whatso developer experience and the validated designs is we really try to, so what I like here, just a sidestep, the philosophy of SUSE is choice.
And you could argue that's a positive thing. And I'm, I'm warm heartedly agreeing there, right? Because a lot of open source is coming less open, uh, it's closing up.
Uh, right? There are hard connections required, but what the beauty is of choices, you can, you can pick the downside, you could argue is that the time to value might be a little longer. So we don't have a lot of, or heads a lot of opinionated stacks, right?
That say, Hey, if you use these tools in this way together, you can get from code to cloud to literally in minutes. And that's what we've launched with our first validated design, a, a blueprint, a architecture that articulates how to use the various cloud native solutions we provide, but more important, a description on how to do that. And a installation script if you like, to get to these tools very, very quickly.
And that helps platform engineering teams more important businesses to not focus so much on the platform, but on the innovation that's happening on top of the platform. I wanna dive into pieces of this, but before I do, I'm afraid I'll forget for people who wanna see this, the diagrams of DevX that you showed me yesterday, we're on the suse, is it on the SUSE website yet? Yeah, definitely.
So it's, uh, it's published in our documentation open source community, right open. So it's, it's out there in the open. We've launched our first, um, validated design, and we're really looking forward for partners to start contributing to that.
There's a code repository behind, uh, we'll share the link on, on blog post and, and socials pretty soon. Yeah. Excellent.
Alright, so you brought up these repositories. Our audience is familiar with repositories, whether we're talking about Artifactory or Maven or, or docker, uh, uh, container repository, et cetera. You guys took a different take on repositories because to me, repositories are like fishing in a sewer, you know, you don't want to eat the fish that you catch outta that water, but you guys are taking a different take on it.
Yep. Explain what you're doing. Yep.
Yeah, so what we, uh, what we did about a year ago is we launched what we call suse application collection. And, um, that is a rich library of applications, single containers or helm charts that are fully curated. And the curated parts, or the nature effectively means we take an open source project, um, and we allow customers to use that in a safe, compliant way in their organization.
And to do that, there needs to, a lot of stuff needs to happen. And what we do is actually we rease them to souse Linux images, very small footprint images. And that's powerful.
Uh, because if you spread, let's say a Prometheus or a project 2,005,000 times, right? And the container is only half the size, well, you save a lot, uh, but smaller also means the smaller attack surface, uh, right. So if we throw out libraries and other stuff, we don't need, right?
It's, it's also less a tech service. So that's, that's one part, rebase it. Then second of what we do is we make sure that it's, it has a software bill of materials.
We know exactly what are the libraries in there, what is the version, as well as what is the license. Because if you're just open source and imagine an enterprise with high co compliancy rules, pulling in a container with the wrong license type, you're liable. Um, and we, we put that all together in an sbo, a software bill of material.
And that is important because then other solutions can actually query that and say, Hey, I don't wanna have a Apache to the zero licenses. Well, you can articulate a policy and it's then no longer possible to pull in that container. And then probably the last piece is all these containers, uh, images are continuously scanned for security, uh, important.
So you know exactly, hey, how many vulnerabilities they're in, and if there's a new upstream version released that's being, uh, curated again through our pipeline, sometimes in minutes, most of the time under two hours, a new version available. And then engineering teams, again, don't need to focus on continuously updating the base images. They will just pick what is in application collection and put their CI/CD, their build pipelines on top of that and use every time a kind of the latest test it and push that into the org.
And, and this comes with using suse. This isn't like end user organizations don't have to do this anymore. It is all sort of automated.
Automated in there. Yes. Yeah.
Big time. It's A beautiful thing, isn't it? Yeah.
Yeah, Absolutely. You mentioned a little bit about security. It's more than just scanning containers though, as part of this whole Dev x talk a little bit about security and then let's talk about something you don't know a lot about observability.
Yeah. It's still did. Difficult point.
Yeah. So if we more and more we start to realize that security is not, so we have a solution called SUSE security focused on container and network scanning. Um, but that's not only security.
We have solution application collection providing you great compliancy type of elements. But what we really start to realize is many of our capabilities, they have portions of the security and the compliance puzzle. So think about your airbox settings, right?
Where you say, Hey, I have a team and the team only has access to this namespace. Well, that's an element of compliance. If you then not only do that in your cluster management, but to propagate it into your observability solution, the team managing the app in the namespace only have access to see that data because there might be confidential data in the logs or in trace or whatever.
Um, so we start to realize that security is everywhere, right? In all the distinct capabilities. Um, and that is also in the devex validated designs.
You really start to benefit from the building blocks around security and compliance in that single flow. That way you can push from code to cloud, uh, all the way through. And then at the end, so SUSE application collection really, I would say contributes at the start of a process, say, where an engineering team picks a particular container and starts to develop on that.
Whereas SUSE security does container scanning and network security at runtime really contributes at the end. So then imagine you detect something, right? The vulnerability or whatever that is.
Then again, kind of closing the loop, the DevOps principle, right? And you start over again, you pull a new version, you build it, you deploy it, you run it in production. And by doing so, reducing it.
So I mean eight months. Uh, but the more, I mean, the more I start to understand that it's really the combination of all these capabilities that will help enterprises, uh, increase security, uh, measures. So you're only here eight months.
It, it seems longer. It feels longer. Does Andres It does.
Um, you know what, you haven't mentioned ai though. Everybody's talking about ai. What can we expect near term, little longer term maybe of, of incorporating some AI elements, maybe agent type AI to make this even better.
Yeah. Well, I'm definitely A big don't say anything that's gonna get us in trouble though. Please.
No, no, No, no. So one, I do think too, one element I wanna touch upon in particular is, uh, the observability aspects. Oh, that's right.
Of, uh, of ai. And I feel most comfortable speaking about that. So SO'S observability, um, as it is, is a platform for observing almost anything.
Uh, we're very much focused on that, but rancher can, manages, observability can observe, but we've learned in the last few months that it's actually a platform to do much more with. So we're launching also SUSE observability for ai, a very pre-packaged, um, integration, right? An extension, I could argue of sous observability that is focused on AI workloads, giving insights on energy consumption, GPU, uh, workload distribution and all these type of elements.
And that is in particular important because right, it's massive from a footprint perspective. Um, and you really wanna observe that in a, in a very detailed way. So that's what I love, right?
That a platform is useful for more than just single technology being Kubernetes or different flavor. Absolutely. But you, you, but you hit on something there, Andreas, that I think is important for the audience, right?
At the end of the day though, you don't operate data centers. Seuss is very much in the data center business, and the data center business is crazy. Right now.
Everybody's pledging hundreds of billions of dollars to build AI data centers. I don't know where we're gonna get the energy to run all of these AI data centers or to cool them down or whatever. But the fact of the matter is we need to be more efficient.
Yeah. Right? We need to be able to do more with less when it comes to data centers, data center space is at a premium, more so in the private data center than even in the public cloud.
Yeah. How's suse kinda working in that or how you, I mean, it plays into your strengths. Yeah, definitely.
So there, there are a couple ways of, of how we approach that. So many people take the cloud very much from a finops perspective, right? So they take it from a costing perspective, but down the line, it's not about cost, right?
It's actually about the utilization degree of your clusters in your namespace. And we do actually two things already in there. So through the application collection, you can get to a curated version of open cost, right?
So really assessing your entire landscape, what's running where, what are the costs, et cetera. So that's the way more finops oriented, right? You would scale it down for financial reasons.
The other element I would articulate, I would say is probably even more interesting is that what we do with SUSE observability, so think about massive clusters that you're operating with very low, uh, utilization degrees, right? So overprovision, uh, elements with SUSE observability out of the books, we provide you straightaway insights, uh, on how that is at the cluster level out of this, at the namespace level, how that this at the surface level. So although we don't have automated actions to remediate, we do provide insights on, um, on CPU, on disc memory utilization.
And that is where it starts. And where suse observability takes a slightly different angle, we not only answer, say, Hey, this is how it's utilized. What we do is we demonstrate, you say, Hey, in this cluster, these are the business applications or the namespace that, that are operating because scaling something down always has a business risk attached.
Uh, because yeah, there might be an app that needs to scale up every night, right? So you don't see that in the window of six hours, but before that six hours, it does that every time. Um, so we really try to let the business understand what it is you have running and how that's utilizing it so you can take conscious decisions to scale it down or to right, to shuffle workloads around, um, et cetera, should, and that's applicable just on, on normal applications, but equally applicable to the AI space.
Yeah. Andreas, you've got a great stage to play on here. Good for you, man.
I'm happy for you. So congratulations. Keep up the great Work.
Definitely To you and all of the SUSE people, Andreas Prins here at Suan. We're gonna take a break. Hey, we've got more videos from Suan coming at you, so stay tuned as Alan Shimel will be back.