AI Agent Security Risks, CUDA Portability, and Kubernetes Adoption at Scale | TSG Ep. 1006
Alan Shimel, Mike Vizard, Chris Blask, Kate Scarcella, and Sid Nag examine security flaws in Model Context Protocol (MCP) servers and clients—an emerging layer of infrastructure that enables AI agents to access enterprise data and execute actions.
The panel discusses why MCP-related vulnerabilities matter as agentic architectures expand, and what security teams should prioritize when granting AI systems access to sensitive resources and workflows.
Next, the gang looks at an effort to improve portability for GPU-accelerated workloads by translating NVIDIA CUDA to AMD ROCm, and what that could mean for infrastructure flexibility and vendor lock-in.
The episode closes with a look at cloud-native maturity and the state of Kubernetes, following a Cloud Native Computing Foundation survey reporting 82% Kubernetes adoption—plus what “adoption” really means across production environments.
Transcript
Hey everyone. Welcome to Tuesday's Textron Gang. We're live on Tuesday.
We're live every day of the week. Well, Monday to Friday. We don't do it Saturday and Sunday, but um, welcome to today's show.
We've got a lot to talk about. We've got a great gang to talk about it with. Let me introduce you to our gang for today.
We have got Sid Nag Sid, good to see you, to see Kate Scarcella. Hey, Kate. Hey.
That still Cyber Podcast episode's up, uh, be promoting it. I played yesterday on Text Drunk tv. We've got Chris Bloss looking good, Chris, and of course Mike Ard.
Mike, how are you today? I'm doing well. It's a little chilly, but all good.
You know what, it's even chilly in Florida today, so We're we're Where I about sympathy. Yeah, exactly. Well, it's relative.
It's relative. I get that it's relative, but it did, it did. You know, it was 80 degrees yesterday and then at night the wind came in and geez, it's gotta be in the fifties today, but it's gonna be in, I heard it's going down to 38.
My wife tells me over the weekend, Wow, did you break out an actual sweater? Where are we going with this? Um, well, I guess I did, I did make ready some sweaters for the weekend.
You know, you know what they say, right? Small is violet in the world. But, uh, anyway, you know, speaking of, of cold, it looks like MCP, which has been a darling since it came out about a year ago now, starting to show some warts.
Mike, what's the story? So under the heading of, you know, why we can't have Nice things, but a lot of folks have started to deploy their first wave of model context Protocol, MCP servers. These are the servers that provide access to data sources, to AI agents and AI applications.
It's originally developed by Anthropic, and now, you know, it's being advanced under the heading of the Linux Foundation. But, um, cybersecurity researchers surprise, surprise, have discovered these MCP servers and are testing them, and you'll be sad to hear, but there are actually flaws in these things in the first wave of these things. And it looks like, you know, we might have some issues.
And Kate, I'm wondering what your thoughts are here, but didn't we kinda rush this MCP thing out once more time? Oh man. So, right, so what caught my attention is that the new, new AI vulnerability is where it shows up.
We're spending a lot of time securing how AI agents are asked to do things, but for real risk is emerging in how they actually operate once they're running. That this distinction matters because it shifts AI security from prompt problems to system architectural problems. And I think for me it's like, what the heck?
How can we be surprised? I mean, this whole, i I, it's, it really is Groundhog's Day, and I know people are gonna get tired of me saying this, but we've seen this, this, this AI is basically augmented our augmented selves in how we're doing this. Um, and how we are running, um, AI agents.
It's, it's just that we're doing things, but we're doing them faster, and then we're surprised at the same vulnerabilities that they, they were before are showing up today. And it's like, I don't get it. It's the same architecture.
So what's the surprise here, folks? That's my question. What's the surprise?
Work with me here? Help me understand. What's the surprise?
I mean, it just boggles my mind that we develop protocols today, uh, without intrinsic security mechanisms built in. Like, have we not learned from this before? I just, this reminds me of that Capital One breach that happened on Amazon.
Remember that? Yeah. Oh yeah, I do.
Where everyone was bleeding Amazon and then the Apache server, those guys are running and they're left to some sort of SSRF flag on to test and then never turn it off. This is exactly Sid. Yes.
I mean, it's like, you know, it's unbelievable. And, and the fact that you have, I mean, essentially with, with agents, so the proliferation of all these agents reading so many new attack surfaces, I mean, it reminds me of my networking days, right? With you inject a new network element to the network, and not only do you need security built into that element, but you also need the networking protocols to have intrinsic security mechanisms built in.
Right. IP sac and all that was Genesis. Right?
Right, right. And here we are developing an MCP protocol today, and we haven't learned our lessons. So, I mean, come on guys.
It's a big game. And it's not surprising though, right? You know, it, like you say, Kate, you know, these overlooking in my, you know, short tenure in this over the last couple decades, we've been saying we should do these things.
And there's a lot of yes buts, yes. But that's really hard. And the WHI is, and we keep coming up with compensating controls.
They're good enough and whatever, but is we're, I I, I don't know if there's layers below this. I think we're driving down to the bedrock on these issues, right? Yeah.
That you have to do this. Yes. And there are no yes bots and, and look big fan of MCP, we use it all the time.
Agents running around, do all sorts of things. But if you don't have, if you're not tracking, if you're not authenticating, uh, authorizing and tracking the results of everything and checking across like good operational technology power grid people do and build serious systems that are really gonna be important, you do them a certain way that in cybersecurity and in information technology, we have been just saying, yeah. Yes.
But we'll do, we'll put this in here right now and you can count on not at the speed, not at the scale. No. Yeah.
So, so let me ask you this though. Do you think that there's some irony in the fact that we have spent billions over the last, I don't know, countless numbers of decades trying to secure data and then along comes an MCP server and we're like, yeah, sure. You know, just, you know, bidirectional open transfer, and, uh, you know, security be damned.
Well, you know what I'm doing right now? I'm looking for my string of pearls to clutch Shocked. Let me, let me just, let me just frame this up for you here.
I've got security people upset that we didn't think about security and just rushed headlong, torpedoes be damned into the abyss, right? You've got this whole MCP protocol that literally is a year old. It's a year old.
I think it came out last December, so maybe a year and a month, and it, within three months, it was the def facto standard Yeah. For how AI agents are gonna communicate with our data, with our infrastructure, with each other. You're blaming tigers for having stripes.
Yeah. Right? This is, this is the way, this is the way of the world in it.
We do it, we get it, we do it fast, we get it out there, you know, we'll fix it later. And, and then we find out about the security flaws, the security people clutch their pearls, you know, and, and, and we, we patch as we can until the next floor comes out, or until the next thing goes. Go ahead, Kate.
Yeah, no, I, okay, so first of all, I'm not clutching any pearls. Okay? Okay.
Um, because, because I'm not surprised, like one of the things that I've been saying no, is that we, we need to really, before we just like launch, I mean, security has been an afterthought for, for decades, right? I, I mean, you know, Sid, you talked about networking, you know, being, you know, part of, part of the network. I mean, I just remember walking into, um, very large organizations and being like, okay, clear text everywhere.
And, and you're just like, you know, the same thing is basically happening. And I want us to really take a pause because we can't, we've already seen this story played out. We know what happens.
You know, we're gonna be creating all these cybersecurity tools, doing bolt on, blah, blah, blah, blah, blah. We've seen the story. Why can't we actually write the ending on this?
I don't understand it, Chris. Right. You know?
Yeah. The stand up for security piece, right. You know, and, and what, what non-security people think is that security people are out here, you know, pu the perfect thing that there's a perfect thing we're not getting into.
And Alan, you've walked in the deck of my boat decks of my boats. I've done this show on two handmade solar powered boats that I slowly sailed up and down the coast of Florida for three years with hurricanes and madness. And you, you know, you can ish.
Those were not perfect boats by any stretch. We're not trying to build perfect cybersecurity by any stretch. We're not gonna make perfect MCPI don't frankly care if MMCP is secure or not.
I don't expect that it is. I will run in a way that it's insecurities known or unknown, won't sink my boats. And we can build these systems.
Security people actually know this really well. We're really pragmatic is the non-security people looking at over, over us and saying, I thought you wanted the per you, where's the perfect, there is no perfect, there's no perfect boat sink. Sometimes have two.
I don't know. We, we can build this. Well, it's not about vulnerabilities.
So Let me ask you this then. So this whole nonsense that we bang the drum about called security by design, just flat out b******t or what, Hey, hey, hey. Yeah.
I mean, I, I I, I, I'm appalled that commercial vendors didn't bother to harden this protocol on their own, right? I mean, it's one thing, it's one thing having, one thing, having a protocol as a standard is another thing where Anthropic git, MCP server had this flaw with prompt injection chaining, right? And then in the case of Microsoft, with the market down MCP server had a problem with SSRF.
So, hey, you know, okay, the standardized guys go and do their own thing. They develop a standard, but as a commercial vendor, it's their responsibility to harden these protocols. And they didn't do this.
I mean, that just, it just is just strange, I think. So maybe, maybe we need better collaboration between, uh, commercial vendors to look at these problems upfront and go beyond the standards, but agree to some sort of a, you know, way to speak to each other from a commercial vendor connectivity perspective, for lack of a better term that has these sort of hardening functionalities built in. Right?
So maybe that's way to go, I don't know. But you look at, you know, anthropic people watching the show, like, you know, it's a good company, good folks, it's the motivation cycle, right? You know, for everything I just said, you know, as a security person, I, I expect flaws.
However, I look at how we produce things, I said, you're exactly right. You know, what does the motivation stack in developing and releasing that? I think everybody involved did great work, love the code, but, you know, is there is our, our production motivation checking con the conversation, is that appropriate?
And the answer is no. So is that, is that, I'm wondering if there's a cost associated with doing these things. And because the AI adoption is still mostly a vendor conversation and less of a consumer conversation, you know, the cost factor is something people are not thinking about, and therefore they don't wanna jack up the cost by creating this additional hardening in the protocol, uh, and that that's resulting in these kinds of disasters, right?
I don't know, what do you guys think about that? And, You know, it's that, I, I think that is a possibility, but I, I think the bigger motivator here is there's a gold rush going on and everybody wants to be the first one in the creek panning for gold. And, and you know what I mean?
And so, oh, this MCP, we gotta get an MCP server out. Mike, how many pitches have we gotten from PR agencies over the last year announcing that one of their clients has now had their own MCP server out Thousands. And I can't wait to see which one of them winds up on the front page of some report somewhere saying that their platform was the very one used by cyber criminals to steal all kinds of interesting, sensitive data.
Yeah, absolutely. I mean, this is, but, but let's not blame ai. This isn't an AI specific issue.
Yeah. This is a, this is a pervasive issue within technology within development, where as much as we, you know, I've never seen a survey that didn't have security in the top three priorities, right? It's always in the top three.
But as many of those surveys as we've seen, the fact is if it gets in the way of getting stuff out to market fast, it loses Always. And, and I'm sorry, Mike, go ahead. No, no, I get it.
I, you know, that's the, that's the point right there. No, let me ask you what the outcome is. So here's the thing, do we go back and quote unquote fix this protocol?
Or are we gonna just add another overlay of security on top of it to make it more secure enough? No, it'll be, it'll be continued to be fixed. It's, it's evolving and extending and, and it'll be fixed.
But this is why, look, one of the biggest things in security I've seen over the last 10 years is the move from pure prevention to resilience, right? And if that's what you mean by Mike, by putting a layer of abstraction or something. And maybe that's one way of providing some resilience, but, you know, smart security people have moved over to resilience saying, Hey, we're not gonna stop trying to prevent things, but, but stuff's gonna happen.
And when stuff happens, we've gotta be prepared. Mm-hmm. And then I gotta go hunting around for every MSEP server and client that's out there, and then I gotta add some stuff on top of it to secure it.
And it's a lot of work for creating for these people. Yeah. But you know what?
We're getting rid of all these junior people. We gotta keep the, we gotta keep jobs here. And it's not on top, it's under, you know, it literally, you know, the UI died last year, right?
The user interface, the entire internet is gone and it's struggling along. We're trying to recreate it, adding more layers on top. And Mike, you're exactly right.
This cannot be solved this particular issue or security by layering more on top. You know, we need to build it right underneath. And you know, Alan, you're right, it's gotta be resilient.
But I think there's an opportunity here, there's a market opportunity. You know, my, my boss at Bell Labs once told me, you know, network management is an artifact of somebody who made an error in building the protocol, right? So if you didn't have the right network protocols, you need management on top of that.
So, So, so it's like, It's like the idea of a service mesh or a new sort of overlay capability or a, whatever MCP management, if you wanna call it. I mean, there's opportunity for tool vendors to go make a run at that, make tons of money, right? I mean, it's Absolutely.
We'll end on Sid's optimistic note here, right? There's, I'm in this room full of horse manure. I know there's a pony here somewhere.
Alright, let, let's, let's jump, let's jump to our next I let's jump to our next one. Breaking the AI lock in. You know, this is a, this is a shot at Nvidia.
Mike, what's the story? Yeah, this is kinda interesting. I think it's still in the realm of, uh, computer science project, but a fell on the Reddit forms that a MD has set up is claiming that he used Claude from, uh, anthropic to essentially find a way to reverse engineer some of the Cuda code so he could port it and run it on the A MD AI accelerators instead of NVIDIA's GP use.
And I think we've talked about the idea in the past that, you know, people will use AI to reverse engineer all kinds of interesting things. But, um, I guess, uh, Chris, when you look at this, what's your take on, you know, are we gonna see a lot more of this stuff? And do you think that, you know, people will start porting frameworks to different AI accelerators as a result?
Yes. You know, it's, so a week or two ago, I think I shared on, on this series, you know, I was talking to somebody who in the past had broken a lot of license, you know, software license, uh, codes, you know, and had that dark, dark pass where a person always funded. But they said something to me that said, there's no point in doing that anymore.
You, why, why bother breaking a license key if you can't have access to access to code? Just build your own, you know, just express the intent to have this functionality through a properly put together AI system and you will get that code. And that's where we're going.
And, and you can do it now. We do it, I do it all the time, right? You, we, and it is not a matter of re reverse engineering, it's just saying, I want this set of functionality, add this to the, what we have already do it in the way, you know, we always do it so I can trust it.
And, you know, when it blows up, it's not gonna take us down with it and you're done. You know, so the whole idea of being a vendor is different, right? And I, I've been there, seen it, done it, you know, here's the license key and so on and so forth.
I've, but I've been arguing since the beginning, since the early nineties that it's really about relationships. You know, in this, I guess I, at this age, I am here for the horror stories, but in, in Atlanta, the very first day of launching the border air firewall server, where these two folks came up, asked two sets of really good questions, and they came back and asked another question, I'm like, I really don't know the answer to that. And on my feet, I said, well, look, if you buy this firewall product, you can build one.
But what you're, what you're really buying is a relationship with people who do this for a living. And when, and if there's a vulnerability found, they will live on caffeine and anger until it's fixed. That's what's valuable.
Not the ability to have the code. Now, 30 something years later, we've gotten used to this idea that you're my customer and I've got you, you're locked into my ecosystem. Those days are over.
If you don't have a customer relationship, you will not have customers. Yeah. I, I, let me tell you, I think it's gonna take more than a relationship.
I, I think what we're looking at here is just such a major disruption in not just open source software, but all software, right? You know, no, no less than Patrick dubois who gave DevOps its name, posted something on LinkedIn the other day. I commented on that, you know, all these tools, he was using these open source tools.
A lot of them haven't been, been being updated lately with like, not, there's not a lot of new code being, um, added to the project or so forth. And he reached out to some people and it's because they were taking the open source code into their cord code or whatever and saying, Hey, this is the code base, but I want to add this functionality and it does it for them and it works pretty damn good. And they don't have to rely on the community or rely on the vendor to update that code.
Chris, what you are saying, and maybe you don't wanna say it 'cause you don't wanna get in trouble, but you could say, Hey, I like what Datadog does on observability and it uses Tel and these other things. Build me an app similar to that, that eases this. So Earl, so point that through for a minute.
Syd, I'm gonna ask you this question 'cause I think you're close to it. So does this turn all the software publishers into, you know, the 1970s equivalent of music publishers trying to figure out who's using cassette tapes to steal music? Because, you know, they're gonna be like, Hey, who used my code or who used my code to inspire this code?
That, and is that even feasible to discover? Yeah, I think there's definitely the element of, of what you just mentioned that jumps out at me when I read about this announcing. But I think if you look at NVIDIA's cuda, right?
It has been dominant. Why has it been dominant? Is because, you know, years of tooling libraries and the investment that actually makes switching out of the Nvidia ecosystem extremely challenging, right?
So I think the idea of cloud's code ability to port and attack order based capability into AMD's rock, and in 30 minutes, essentially a sales, the nvi cuda mote in many ways, right? So, I don't know if I answered your question directly, but I think it's a good thing because that, that reduces the dependency of the, the AI workloads strictly on NVIDIA's CDA functionality. That's in a lockin.
I mean, I know we often talk about NVIDIA's CDA functionality as a Switzerland of sorts that transcends Switzerland, Multiple LLMs from different vendors, right? So there's that, but in a way it's also a very lockin moat that people cannot get out of once you get into that. So, so when, when, when Claude does something like this where they take that and put it into a a MD rock and, you know, in 30 minutes, so less or whatever, I think that's a good thing.
If that's sort of my, my take on it. You Know what I, I, I just did an interview with my friend Paval Baron, uh, platform engineering labs, and he used the term infrastructure builder and I said, Paval, don't you mean platform engineer? He said, no, this is much bigger.
He said, today, we're all builders, we're all builders, we're all software builders, we're infrastructure builders. We are music builders, creative builders. What?
And that right there is the secret sauce of ai. It turns us all into builders. It turns us all into software engineers.
It turns us all into developers. It turns us all into publishers. That's scary.
Yeah. I think AI tools, but I actually Go ahead. Yeah, go ahead Kate.
I was gonna make a point which follow up with Alan's point, which is essentially, I think with this kind of stuff, you know, AI tools might actually drive more competitiveness, right? Sure. Ecosystem.
So to your point about Alan, uh, about music builders and that analogy, I think this really part of a broader trend where AI enhances developer productivity, right? So the more the merrier, the more folks can participate in this ecosystem, and that's a good thing. Yeah.
And that is, yeah, that's a, that's a great thing, I think, um, because it really does, I think, bring in the original intent when we started to think about computers and, and Chris, I'm sure you can understand this part about, um, the democratization, right? Of, of digital devices. And I mean, that's something that I think we who have been doing this, I guess all of us on this call have been doing this for a really long time, understand that original 10.
And I think AI actually does that for us. I think it, it equalizes this field that for some never even imagined and imagine it, you know, never even imagined that they could do something like this. So I think it's, it's a great, great equalizer.
And what I'll say is that when you're going down through your list, Alan, I noticed that you didn't mention cybersecurity. So I still think that cybersecurity is a after, after afterthought, unfortunately. But what I do think is, um, is that I, and my hope, um, is that there's, there's, there's code that should be thrown out.
And, and my hope is, is that as we become more productive citizens in this augmented selves, that, that we are becoming, that we dump the bad code. You know, that's my hope. So in all of it, I have a question for Alan.
How does anybody make any money in a world where I can just look at somebody else's software and just decide by intent to create my own version of it? That, and I'm probably not even using their core source code, because while I'm just copying the intent, Their functionality, I Let, I, let me take that one because go ahead. This is back to my old war story.
It's like you could have built a firewall yourself with open source code before the firewall market started. Most people don't because that's not their, their expertise, you know, and we're not gonna automate the entire universe, you know, we'll automate a lot of parts. And if it's scary to you, look, the freedom of speech is scary.
Open source is scary, democracy is scary. It's much, much easier. I don't know if any of you know any, any folks who grew up in under the Soviet Union and so forth, but is, is it really clear when you're 40 years old and the the wall fell, you never adjust it.
Too many choices how to, it's much easier to live inside a controlled environment. And if I'm scared because my position is threatened as a journalist, a, a, a professional or whatnot, maybe I should be, maybe I've gotten a little comfortable, you know, is there no value left in human activity anymore? That's that silly.
There's lots. Is there no decency, Senator? Yeah.
Um, No, but great point, Chris. I love it. Absolutely.
Yeah. But I mean, and that's exactly what I was getting at. Yeah, Yeah, yeah.
Mm-hmm. Yeah. Now I, but I'm gonna, let me, let me give you some good news so we don't end this on a pessimistic No, I Thought that was optimistic, or what do I, yeah, I got so, well, it's optimistic in, in terms for the every man, but if you, you know, if you're a shareholder in some tech companies right now, you, what are you burning your stock?
But, um, but here's the deal. Let, let's take music for instance. I could use AI and I could create some synthetic music, and it may be good, you may like what I create, it's going to write the words for me, it's gonna write the melody and I'm gonna play it.
I may have an AI person singing it, and you're gonna say, damn that Alan's creative. But then take those same tools and put them in the hand of a musician of a, of a professional who's from that vertical and the synthetic music they turn out's probably on hold a hell of a lot better than mine. The same thing putting coding tools in the hands of a professional developer versus a hack.
Yep. The same thing. Putting writing journalism tools in Mike's hands versus someone who's not a writer.
Right? So I think while it's a great equalizer across the board, it also is a great enhancer of what, where your skills already lie. So if you already have an affinity and a skillset, this enhances that.
Yeah, I agree. And I think that's something to think about. I think, again, back to your, I love your music analogy.
I mean, yeah, yeah. You can create all the music you want using ai, but, but you in Beethoven, Yeah, that's, yeah. But those are sort of, you're creating music based on maybe somebody else's musical, uh, works.
But I think the best music is created by musicians who can improvise in real time. Right? And that is what I always tell, you know, there's always this discussion on LinkedIn too.
I dunno if you guys follow, uh, whether AI can replace the, uh, um, the, the analyst community like us, right? Uh, I think, you know, it's almost impossible because what we do as analysts is not just follow a certain sequential path, like a what a com, what a transformer model would follow into the sequence transaction. But we do real time context switching when we are talking to a client, right?
Yeah. And that's the same with a good musician, A good musician improvising real time. They will not follow an AI algorithm to create music.
And I think that's the difference. So I think, I think where human expertise still matters in all aspects of AI in the AI world and high performance computing in this case in A GPU computing, right? Mike, you wanna say something?
I was just gonna say, you know, and I'm probably in this for here, but I would say, you know, just because AI tells me how to perform surgery doesn't mean I should do it on myself because well, just 'cause you can do something doesn't mean you should. Absolutely. All right, let's jump, let's jump, let's jump to our next, uh, segment.
Moving in maybe a little less ai, but cloud native clarity. See, the CNCF good folks at CNCF recently came out with a survey, Mike, about Kubernetes clusters. Yeah.
And they're pointing out in the latest report that I think it's 82% of the respondents said they're running Kubernetes in production. Now, you know, that varies widely from one organization to another, and not all of them are even running containers apparently. But, um, it does seem we've reached some sort of, uh, a crossing of the proverbial Rubicon when it comes to finally using Kubernetes.
It's only taken a decade or so. And, uh, we're this probably still a long way to go here, but Sid, you're an analyst. What's your assessment of what's going on in this cloud native computing marketplace as we know it?
Yeah, I mean, you know, cloud native is such a broad term, you know, it's so many, it means so many different things to so many different people. But I think one thing this highlights is that containerization and Kubernetes utilization is definitely the defacto standard for orchestrating, you know, containerized apps today, right? It's no longer as an emerging technology, right?
I mean, yeah, there's still virtualization clusters floating around and there's plenty of those. But I think this really highlights what does this do for, in terms of level of adoption for teams that previously resisted Kubernetes, right? So we had this whole evolution of Kubernetes that ran on bare metal versus ran running on virtualized environments.
And the natural thing to do was to run it on virtualized environments because nobody wanted to rip out the underlying layer, although it was more efficient to run it on bare matter, right? So, so I think really this really brings out the fact that Kubernetes is really part of the broader cloud operating system or the operating model. Uh, and I think the survey also highlights how organizations should prioritize investments across the whole cloud native construct of things like, uh, the service measures and CICD pipelines, observability, and all of that.
And then finally, I think, you know, what does it do for the AI workload, right? And, uh, and I think Kubernetes definitely is going to enhance running AI workflow, especially in the world of AgTech because, because of the efficiencies that are built into that Kubernetes layer, right? So running an operating system, uh, coupled with, you know, GPUs and, and software we talked about, CUDA, all of that, orchestrating all of that, I think Kubernetes has a huge role to play.
So that's sort of the dark horror. So the elephant in the room that we should probably talk about more in that from the context. Alan, here's the part of this thing that I'm struggling with.
So just because I downloaded Navy Open Telemetry and maybe I've got some other tool from the landscape, doesn't really make me cloud native, right? I mean, I technically, I guess I am, but uh, you know, I'm not really, so, you know, do we need to rethink or maybe redefine what it truly means to be cloud native in the sense that I've got workloads that can dynamically scale up and down because, you know, I'm leveraging Kubernetes to the full extent. And there's just a different level of maturity here that Cloud native really signifies that, you know, gets lost in the data.
You know, Mike, I wrote an article during Coup Con in, uh, Atlanta in November. I guess that was rankled some of the people at the, uh, CNCF as you know. Um, but the real point of the article was, look, there's more to Cloud Native and there's more to K con than Kubernetes today.
The fact of the matter is Tel Open Telemetry, which is the second biggest uh, uh, project in the CNCF is growing much faster than K is even and cube's growing. Make no mistake. This survey bears it out and they put it out for that reason.
But when you take Tel and Prometheus and Grafana and all of the observability projects together, it, it is like a Saturn to cube con's Jupiter, right? And the question then becomes is, is CNCF big enough for the two of them? Do we need to break out the, the, uh, observability projects?
'cause our Mike, to your point, does that really make you cloud native? Or does that just make you a good user of observability because they're independent of Kubernetes? A lot of the other 200 odd projects do revolve around Kubernetes, right?
Like moons of Jupiter. But the hotel and the, and the observability stuff is, is, is its own gravity. Well, and so that's what it is.
But the, the thing about this adoption is I don't think anyone's surprised to hear 82% of organizations are deploying, uh, Kubernetes based, uh, infrastructure. You know, it, it's been a couple years now where if any new greenfield, uh, projects you're developing are probably done 80, 80% of 'em, and the survey bears it out, 75 80% are based, you know, are on a cobe infrastructure. What's, what's really is the Kubernetes clusters.
So how many clusters of Kubernetes are running in a given app in a given infrastructure? Used to be 1, 2, 3, got very hairy, you got thing, you got people running dozens of clusters, hundreds of clusters of Kubernetes. And that's really, that's not easy, right?
That's the Kubernetes isn't easy to begin with. This is really hard. So to see in this survey that people are running clusters like that is, is really the sign of maturity more than the 82% number Said to Yeah, I was Gonna make another point.
I was sent some notes before I came to this discussion. The 82% number is not surprising. Absolutely right, Alan, but I, what caught my attention is 66% of respondents are running at least some AI inference workloads on Kubernetes clusters, Right?
And that's the key is, is Kubernetes going to be the orchestrator for our AI infrastructure? Or I think back to Cuda, I think Nvidia was making a play for Cuda to be the orchestration, the orchestration layer, the orchestrator, the Kubernetes for AI infrastructure. Nvidia is that, again, that again Goes back to the expansion of the Nvidia moat, right?
Yeah. Does the world worth want that direction is a question, right? Nvidia is depending on red and black, right?
They bought the people who make swarm, which is the alternative to Kubernetes for the C world and that they have invested a lot of stuff in Kubernetes. But let me come full circle here on that last session. Um, Chris, if I have a monolithic application running on a virtual machine, can I not use something like Claude to reverse engineer it in, well, maybe more than 30 minutes, but maybe an hour.
So it turns into a lovely cloud native application that I can run on Kubernetes. Just thinking In short, yes, if you can't do it now, you'll be able to do it in the future. But then it takes us back to the last segment.
You have to decide if you want to maintain it and support it or if you'd like someone else to be the, be the expert at that, you know? Well, no, But it could, it could certainly convert it to a microservices based model, right? Which would lend itself well to that.
But you know, to me the question is do you fix what ain't broke? Why, why would you do it? Do you have nothing else?
Do Is is all the rest of your, is everything else on your business to Just because Timmy jumped off the bridge, are you gonna join? Are we back to that again? Well, Well at least, at least the theory is, is that the application will scale up and down and cost less to run because it runs cloud native versus a monolithic app running on a virtual machine where you've got a bunch of static resources dedicated to, and it's Expensive to you.
Alright, so let me, I was a little late coming on seat on set today because I was having a meeting with our video team and I was hammering home that I want us to do editing of videos using ai. I want our ai, I want the AI to edit the videos. They're re like Textron gang, when do we switch from a full screen of Mike to the panel shot to Chris Talking should be easy enough.
Whoever's talking gets the main screen and then when no one's talking or there's people talking, it goes to the back. You know, it should be something AI could do. I don't need a person doing it.
And we went back and forth and back and forth and then came the real kicker. A lot of our videos, not yours Mike, 'cause you do yours on your computer, but a lot of our videos that we shoot here in studio are shot in 4K. They may not be played in 4K on your computers because streaming 4K is not easy and your computer may not play 4K video, but we shoot them here in studio in 4K to have the highest quality to begin with possible.
And those 4K videos, the average 4K video is somewhere between 16 and 20 gigabytes. Now, AI could edit, 'cause it's a relatively simple edit, but uploading that 16 to 20 gigs to the AI engine and what AI is going to cost us to edit through a 16 to 20 gigabit file. And it's, it's actually cheaper to have a human do it.
And that is the, the kicker until AI is economically cheaper to do it at a high quality like that, we shouldn't just because we could doesn't mean we should. So you mean spending $10 million to replace a couple of baristas in a coffee shop doesn't make a lot of economic Sense. Exactly.
com all over again. I, you know, it costs me, it costs me a dollar for every 80 cents I sell, but I'm gonna make it up in scale. Well, you're not, you're not.
Until we get that right, you're not doing it. And it comes full circle right to, to your first question to, you know, block a when we were talking, right? It's, it's, it's about the money at the end of the day, whether we like it or not, it's about money.
Yeah. So, so I, you know, I don't know if we should convert it to cloud native just 'cause we can't, So we shouldn't go build all those massive AI data centers. All these vendors are planning and investing billions and billions of dollars anymore.
Well Look at all the jobs it creates. Okay. That's right.
All right. Oh God. Alright, let's end it on that note, let's end it right there.
Hey gang, thanks that this was a lot of laughs. This was fun. It was good hearing smart people talk about these things.
I hope you've enjoyed it out there. We've got tech strong TV following up, Sid, Kate, Chris, thank you Mike as always. Thank you.
Um, I think we've got, uh, tech Field Day this week coming up, so stay tuned for that. Hey, there's a new episode of, uh, Mitchell and I still cyber starring this lady, Kate Scarsella in this episode you might wanna check out on Textron tv. Um, and we'll be back tomorrow with more gang.
Until then, this Alan Shimel we're out.