Five Cloud-Native Trends for 2023 – Techstrong Con 2023
Going cloud-native is messy, complex and expensive. Although some organizations are doing well on their journey, others are struggling and concerned about operational costs, complexity and security.
In this talk, Mostafa Radwan will explore five cloud-native trends for 2023 and how they are helping businesses meet some of the challenges of going cloud native.
What We Will Cover:
eBPF, SBOMs, VEX, FinOps and KISS are five trends that could accelerate your cloud-native journey by reducing security risks, optimizing costs, and simplifying things by going back to basics.
Top 3 Takeaways:
Secure Your Software Supply Chain: Software supply chain attacks are on the rise, according to a recent study conducted by Aqua Security(*). eBPF, SBOMs, VEX are three critical tools to consider that can reduce the risk of such attacks.
FinOps is Your Friend: FinOps is a vital approach in going cloud-native to keep operational costs at bay. It can help teams rightsize infrastructure, communicate business value and optimize costs.
Use the KISS principle: As we build modern software systems, the overall complexity will increase over time. We should intentionally keep things simple and always question the addition of the next shiny tool that can add more complexity down the road.
Transcript
Good morning, good afternoon, or good evening to all of you. Hope you're having a great conference so far. This is Mustafa coming to you live from Chicago, Illinois.
I help it Leaders with their Cloud native journey to navigate it safely and securely and today I'll be sharing with you five Cloud native Trends. I've been seeing in the field with medium and Enterprise companies. Let's get started.
We'll share with you first some of the stories of one of my friends and other from one of the CEOs here when a company here in Chicago and then we'll try to establish a definition for cloud native because it can mean different things to different people. And then we'll share with you three Cloud native Trends specifically related to security and two related to the cloud native Journey or adoption. And then we'll wrap it up and happy to answer any of your questions.
So me meet Alex Alex is a friend of mine. He he runs. He's the head of Technology at Enterprise company Financial Services sector started the cloud Journey around 2017-2018.
We meet at the technical technology conference and we're talking about the different Cloud Trends back then cloud computing trans back then and he shared with me some of the struggle struggles. He and his team are facing. It started with Cloud.
They are not really sure but where to go. So is the experimented a bit the they had an instant with some sort of a bridge someone took over their ec2 innocence and ews and then they started some sort of Crypt mining. Luckily.
We were able to get discounts and reimbursement from AWS for that for that incident and very quickly. He realized things are very expensive. And things are getting more complex.
He always connect with me and say we need more help with X and Y and Z not necessarily me other vendors helping with different type of issues operations infrastructure as code and it never ends. And I couldn't help by but ask him about containers and kubernetes and he said don't get me started and kubernetes place. We are have a lot of of nightmares and on Fires to put out.
Alex issue was actually something totally different than technology. I will our talk about that in in a minute. Another story and this has been circulating over social media and the internet comes from David Hansen.
He is the publisher of a great book called rework defining how we do work play and the work life balance. He's the city of company built here in Chicago called 37 signals. And he shared publicly that they are leaving the cloud.
And within the next five years this is going to save them both seven million dollars. Why they took that decision he did some calculation with his staff and found out they are paying around getting 60,000 dollars per week that their Cloud built. After the gut hooked into kubernetes with I think one of the managed services and they didn't like it much the phone that managing it at the scale getting to a nightmare.
They figured they took kind of control of the situation decided to leave the cloud as I mentioned earlier also in terms of kubernetes and containers they decided kubernetes is not for them his take this is mainly for large Enterprises, which totally understandable 37 signal is a company of about 150 employees if we can estimate, you know, it's a software company. So let's say 50% of the head count is technology or it is it's pretty difficult at this size. Some companies are able to some are not they built their own framework to deploy containers because these can see the value of containers, but they don't want to come public.
Do you want to go back to the private to the private Cloud the data center and be able to their own framework that's called risk mrsk. You might want to check it out. I don't know what went wrong with David in terms of the adoption in general.
But another story just to give you an idea of some some that are exiting cloud. Remember my friend Alex so after. Back and forth and different discussions.
It turned out it's not necessarily technology. It has to do with the culture. at his organization and I'm not sure how we do things around here.
So whatever project you're thinking or a nation digital transformation initiatives you are taking it will boil down to the people implementing those plans and initiatives. You want to have a culture that those have seen in the field that exceeding accelerating their cloud? Usually have a culture of experimentation feeling fast learning it all not know it all and collaboration.
I know culture is very difficult to build and it's up to us and it leaders to to take that challenge and instill such culture in the organization without culture no matter what technology. Processes or tools you have is going to be a really difficult to move the needle forward. Alex problem was mainly about culture the team had that mindset of just the cloud just and another data center automation is kind of more of a script here and there is no standard by his way and just following the next the next Trend or playing with with the coolest toy around.
once he he and his team working on the culture things started to pick up and improve and it took them three years. Let's first establish a definition about Cloud native because it can be another buzzword. There are many two definitions around one comes from the cloud native Computing Foundation mainly around applications built.
Taken advantage of public hybrid or private Cloud. Those are occasions build mainly around the microservices architecture grounded in containers and then take advantage of the underlying future of cloud computing in general. You can think of it as applications grounded in containers in a brief.
On the other hand, you you hear Cloud native everywhere. When you deal with Cloud providers or some of the solutions built on those clouds. So for example, even ews S3 is a cloud native service because this is specific to AWS.
Azure directory active directory service is a cloud native service. So as snowflake because it's dealt on some of the different clouds are they necessarily using are the applications? It's certainly grounded in containers.
That might or might not be the case. So for the rest of the The Talk today, I'm going to be we're gonna mean here what cloud native is the first definition applications grounded in containers. The five Cloud native Trends.
I'm going to share with you are mainly ago and in two different categories security the top of mind for a lot of it leaders and teams. As well as their Journey for cloud adoption and Cloud native adoption in particular. Two Trends in Cloud native adoption is merely around different ops finops was organization that part of the Linux Foundation, but there are principles in Ops principles that we should be looking at closely and adopt to be able to manage costs over the the cloud native Journey also is to keep things simple and small.
And we'll talk about that there the security Trends we're going to be covering our around the software development materials. And its companion called the vix as well as edbf, which is a Linux. Kernel technology, but has now becoming more of a platform that we can build on to kind of do some conversions of all those metrics you contained application infrastructure Network and security.
They will all come under one umbrella using evpf. So why are we talking about software bill of materials and why this matters? About two years ago.
There was a executive order from the White House for all software companies or vendors providing software to the federal US federal government is to provide s bombs for those components. And you can think of it as bombs as putting your software under the telescope not necessarily as cold as scanning but understanding the dependency. It's more of a dependency solution.
So I can look at the software understand is my software for example using log4j and if it does which one. also s bombs can provide some sort of transparency meaning I am a software vendor. I'm gonna sell you my software.
I'm going to tell you all the components is built on top of it. So that will increase confidence and my relability on your software if if you change or use from example from an open source library to another Library. And aware of that change and if any risk, we can discuss it and solve the problem early on.
The reason we are doing is bombs is not necessarily because of the executive order. If you don't sell it to the to the to the federal government local or state government. This maybe is not relevant to you.
However, we all encounter that 2021. Look for review crisis. And we try to scramble to solve the problem.
in a very short period of time the good news is is bombs can help us prevent a situation like this. By understanding which parts or software are exposed. To that particular look for you issue Urban probability.
and but by doing so we can act our response time can be much much faster. Today you have at your fingerprints many tools. That allow you to generate s-bombs.
Aqua 3D some of probably most of you are familiar using for scanning for vulnerability also can provide you as well. Turn is another tool from VMware. And our beloved Docker tour, most of you probably use local command line before so you can do Docker s bomb whatever the images and you will get an s bomb.
It's more of like an SML or again Jason file that tells you who built this container or image. What components Is it built on? And then you can based on those components you can assess your risk and the different vulnerabilities it contains.
Question to to all of you. Do you think you might benefit from using s-bombs? And having used them in the past or planning to use them this year.
And if you if you did what is working for you and what is not working? Vix which is another we call it the companion of s bombs and they're not shell. It's a it's a document a file more of a tabular formatting.
If you can think of it that way that can tell us okay for those. different components And my software or the software that the vendor provided. Which of those Shelly care about or more exploitable than others?
We learned that the lesson from vulnerability scanning or code scanning. That we should do better job. in identifying signals from noise I don't want to go through an exercise of finding the needle in the haystack.
We all go through this is painful time-consuming and unproductive. A better way to look at this is okay. Hey, I'm gonna take a step back.
I know my software has lots of vulnerabilities. But which ones do I really care about? Which one are more exploitable the other and give me a scale for example from one to 10?
How exploitable is this vulnerability? That will make it way easier. for teams to be able to work with different vulnerabilities vulnerabilities in the supply chain are gonna pass through no matter what type of the scanning you are doing or what type of Guardians they have.
Eventually they will they will pass. the the dilemma here is or what we should be doing is shell I respond to this invest time and effort to money responding to this vulnerability or I can move forward because it's not exploitable to my environment or maybe I have certain features often my software that they really shouldn't care. And doing this early on can save us a lot of time and money, of course.
It's early days today for Islam. and vics but the good thing is it encourages. lots of collaboration and transparency between the software vendors and the software consumers Lots of tools are available today.
For example, the CPL chain guard has some of the tools that allow you to along with the S bombs. You have to be able to identify your risk doing so will help you way better in the future than just getting. Okay.
I have a thousand vulnerabilities have to deal with we're using text you can assess those and maybe you can narrow it down to maybe 10. or less that's something I can work on I can go through with them in a day or two fix them my software maybe if it's a software package. I open source package.
I can upgrade to the latest version and then rerun go through the same process again until I can get something I can move more forward. the third Cloud native Trend when it comes to Securities around edbf You can think of the different. observability application infrastructure networking they are convergent today because sometimes you might have issues in the application that might or might not be related to an issue in the infrastructure or Network.
Ebf is a nutshell is a Linux kernel technology that allow us to look at certain system calls. So if you run a process and application, it's a process in Linux. And then it's going to run.
Request certain system calls system calls go to the Linux kernel, for example, you want to print a character in the screen. You want to print the document you want to connect to the network all those sometimes or sort of system calls. Even BF allows us to run code.
Sandboxed calls so very very restrictive C programming language that can give us the ability to say okay for those processes that are runs. There are certain hooks when this event happened you can think of it like event based programming when this happens. I want to be notified for example a process trying to to run as root.
Actually I should be notified. That the opportunities or the use cases are endless. One of the big advantages of edvf in general is zero and instrumentation if you have done application performance monitoring before You know, they're usually two ways to go about it in terms of I have to instrument my application and instrumentation is just a fancy word for I have to change my app so that it emits or expose a certain metrics that can I can go and collect that for example Prometheus.
You can do that can do that for you or I have to install an Asian on a machine or a personal machine that will watch for what is happening and then send those Matrix onto the centralized port. centralized portal and both are very impressive. I have every single time there is an issue.
I have to go and instrument my code and that is very very invasive and I'm current consuming thing. I want to be able to minimize this also it adds a performance. There is a performance head by running an agent or every single time.
I have to go and instrument change my code. What if we can do all this without touching? The code of your application whatsoever.
All we have to do is write our own code. In and see or there are other tools you can do to tell the the Linux kernel through people. Hey, I want to monitor any process that runs in the in this in the system.
Remember containers are compared is a process. So I want to know every single time a process is running as root. That's just one example.
I want to get a list of all the containers are running as root and then with traffic going out I would go in traffic. My own experience with ebbf with the tool called pixie. Dixie runs on Linux systems and kubernetes kubernetes native to troubleshoot issues related to the cluster.
or applications running on the cluster I think it is run by it's was acquired by redhead. I was able to download and very downloaded and very quickly in less than three hours identify. What is the issue in the cluster and the application running on the cross?
It had to do with some sort of an infinite Loop and a Deadlock. While it's early days today, I want you to think of it as evbf as a platform. You can build the products and Solutions on.
One of the challenges today is it's only running. You have to run your code or write your code to for those event. Based programming is in C program.
However, there are some some tools. For example like BCC. You can run your codement python it will convert it to you to see language.
there are some Fantastic Tools to resources today we have From my friend a friend that lives rice. She has been very vocal about this and she shared a lot of things and conferences. So I would start from left to right that this is the the very left is Introduction and then it gets slightly harder as you get into the the very specifics and not some bolts of what is EDF and what to do about it.
You can all those books are available for free to this link from as of London is the company behind the psyllium Cloud cni the container. network interface I will leave it here for a second one more if you want to shut down the link and get the books. Going back to the cloud native adoption and journey.
Cncf realized truly days the two years ago that the cloud native journey is not easy, even though the published the cloud native trail map and steps to go about about Cloud native. It is very difficult for a small as well as large organizations. So after still being hundreds of their end users and some of the medium and large Enterprises in collaboration with the put together was called the the cloud native maturity model.
And it helps organization to know where they are and where they're going to starting from building which is running across her and not necessarily going to production, but we just getting started in a non-production environment. All the way to optimization where you have things running in production and you want to adopt it and Enterprise level Enterprise level adoption of cloud native. I highly recommend to take a look at it and see where you are or where you go into.
It's focuses around five single Five Pillars. So people process technology policy and business outcomes because sometimes we get involved with too much in the technology and we forget what is driving the business and delivering bad bit value to the business in terms of lower lower costs or increasing speed to Market. One of the trends in in the cloud native journey is finops.
As I mentioned earlier is organization with the Linux Foundation, but it's also principles that we can adopt at the organization. That will increase discussion between the different stakeholders. To be able to control Cloud courses.
You start with inform which is just getting a good understanding and awareness in the organization that clouds costs are going to increase. Or with our consumption if we are not careful, it's going to increase. And then you optimize this over time by monitoring and measuring your costs.
And then you go ahead and operate while you optimizing those costs by utilizing whole lot of tools. One of the reports came from flexera market research and consulting company in this year called. The 2023 state of cloud report Cloud cost is number one Cloud concern.
It used to be security. I know let it change it with the information or in and the rising costs everywhere. It is costing companies a lot.
There are many available tools today to us to help. I am sure AI is going to be to play a very important role here. Open cost is an open standard by a cube cost Cube cost is a tool that can monitor and optimize your Cloud your kubernetes cluster.
Cloud costs and in the private cloud data center or in the public cloud. You might want to check it out we have that's that's the standard they put together. It's an incubated cncf project and lots of things can come out of it Cube cost actually implemented open cost.
And it's available today for you to download and try. Question to the audience. I would love to hear from you.
What have you done to curb your cloud or kubernetes course? One of the other Trends is to keep it simple and small. My friend banking is he's a distinguished ingredient engineer at the American Express and he's a big fan of keeping it simple.
Yeah, he even though they have plenty of covenants clusters some of their database run a handful of containers managed by homegrown quote or Dockers warm, which is a simplified orchestrator for application containers, even though they can run thousands of clusters with many many notes. They decide to keep things simple. We all know that distributed systems are complex in nature.
What we want to do is to try to make it easier to manage. Our Cloud native journey by keeping it simple from the outset. One thing I can share with you.
It is way easier to manage many clusters than Mega or very big clusters always way the cost and benefits of each and you or new toy or tool and think long term. The cncf landscape is massive has many many tools. Am I adding a new tool to make my life easier or harder on the long term?
One one simple trick I'll leave you with the smaller. Your container image file is The smaller it is the less vulnerability. It has faster to ship and pull.
We all know Cloud natives complex since it's build on distributed systems. What have you done to simplify your Cloud native Journey? To recap we talked about five Cloud native Trends to related your Cloud native journey to keep it simple and small also to have a 10 Ops in your organization one.
If you start with one person, that's okay. If you have an entire centralized team, that's even better to always Monitor and measure your Cloud costs and optimize over time also in Cloud native security and to keep you from supply chain attacks. You better look into SS bombs fix and evf I want to thank you for for attending and feel free to reach out to me social media email.
I will be around here until the end of the conference. Thank you again and have enjoyed the rest of the conference.





