Better Connectivity and Security Through Network Modernization – The Last Great Cloud Transformation EP5
As enterprises shift applications to the cloud and adopt hybrid work models, traditional networks have struggled to keep pace, becoming more complex, less agile, and unable to deliver the security, performance, and manageability needed for modern demands. Legacy designs don’t adequately support today’s cloud-centric and distributed work environments, leaving organizations in need of a cloud-era network approach. Cloud-delivered networking offers a solution, providing connectivity and security close to users while enhancing performance and protection. A connectivity cloud enables seamless, secure connections across global edge locations, granting administrators centralized visibility and control. By leveraging its flexibility, organizations can modernize incrementally, adapting their network to evolving requirements and creating a foundation for ongoing cloud-driven innovation.
Transcript
Hey everyone, it's Alan Shimmel at Techstrong. Welcome to another edition of the last Great Cloud transformation. It's no longer just my data center or my data centers.
It's no longer just my cloud infrastructure, maybe over at AWS right? Today. I have data centers.
I have multi-cloud presence, I have presence on the edge. My people do anything from anywhere at any time. We need, it's a whole new paradigm.
First of all, I want to introduce you to Mike Hamilton. Mike is the CIO at CloudFlare. Hey, Mike, welcome to the last great Cloud transformation.
Thanks so much for having me. It's great to be here today. So, Mike, CIO at CloudFlare.
Man, that's a job. That's a job. It's incredible.
That's gonna be one of the most complex networks in the world. Something like 21 or whatever percent it is of the internet actually passes through your network. How do you sleep at night?
Tell, tell, tell us. I mean, thankfully, thankfully for CloudFlare, this, this is in our DNA, this is what we get outta bed in the morning to do. I'm not alone.
If I was, if I was the, the key brains behind this, I think, uh, you know, I'd be really nervous all the time. But we have incredibly smart people from our C-suite all the way to every engineer that touches every line of code that's thinking about this all the time. And, and I would really say my favorite thing about the company, in fact, is, is being clever.
We're thinking about really what the next, the next way to approach this is like, how do we, how do we define not, not just follow or, or address concerns that our customers have, but how do we create the next world? How do we create the next paradigm that really makes data secure? And it really helps companies manage this global infrastructure.
The world has changed so much. I've had the good fortune. In fact, I started my career in public sector in 1998, approximately.
And, and everything was on-Prem back then. Uh, and my career was all on-prem through about 2011. I was fortunate, in fact, to be one of the first people to adopt virtualization.
I was a bare metal VMware guy back in like 2001, which at the time people thought I was a little bit crazy. They were like, what do you mean you're running 10 servers on one server and you know, what, how would this even work? And I'm showing them VCR controls on servers, and they're like, what?
Like, you can pause a server. What does that even mean? You know?
And then being able to move servers later was really cool. I've had the good fortune of, of having a career that had that strong foundation around data centers and virtualization. But I, I got, you know, my mind was kind of blown getting into the world where companies were being started entirely on SaaS.
You know, working in hypergrowth gave me a really good chance to say, in fact, when I, when I made that tradition in my career, I went from a startup to MuleSoft. And MuleSoft. Part of the appeal there was, they didn't have anything on-Prem.
There were like, everything was in the cloud. All their business applications were not in the cloud. But that advantage was really interesting me, because I was, I was thinking, you know, from my career, I want to have a challenge that's greenfield.
Like, I've never had to do this before. Nobody's had to do this before. How do I do it?
Um, and to end up with my career now today at CloudFlare is kind of mind blowing for me. Every day when I wake up, I'm like, wow, this is such an incredible company. Such an incredible time to be here, largely because we're starting to define how businesses run globally, and we're giving them a safe way to do that.
So I, you know, I think the responsibility, we take that responsibility really seriously here. And again, while I, I'm glad it doesn't all rest on my shoulders. We have a lot of smart people here, but, uh, if I were alone, I'd be way more stressed out than I am.
We have a great team here. Good for you. Hi, Mike.
From, from a, uh, fellow now former C-I-O-I-I. I, I'm with you there, brother. I understand that role.
You know, one of the great things about, wait a second, Mitchell, I haven't even introduced you yet. Well, you know, people know who I am. You don't have to anything.
Oh, go that. I'm Mitch Ashley, I'm CTO at Techstrong, and b, VP practice lead for, uh, DevOps and software application development. Um, you know, as you, you get to consume the services that your company creates, right?
As the network. And, uh, you know, there's a lot of innovation happening in the network, programmability of the network developers, you know, moving apps into it as opposed to just edge to edge kind of connection, security, all the things that go into it today. Um, I'm just curious how, you know, you, you obviously have to kind of keep the trains running on time, but you're also looking at how do you take advantage of, you know, what the company's introducing and the customers might be using.
How, how do you, how do you, what's your strategy around that? Well, I do have someone that, that runs customer zero for me, uh, with, with my guidance and direction that that person just started about a month ago. But we are, we have been using our own product for a very long time, and it's, it's actually really natural because we have a business to run and so do our customers.
And so it, I've run, I've run customer zero programs in the past, and it's generally like, I, I insist that we follow the exact same path that a customer follows. So it's like, we have an account, we have an admin panel, we file tickets with support. You know, we don't just run to someone's queue and try to find them.
Um, but then we do try to bump things and accelerate them. And it, what I think is most incredible, and what struck me the most about CloudFlare is how our technology can really meet our customers where they are. So we have all these different ways of on-ramping technologies.
Like you, you might say, Mike, I'm mostly on-Prem right now, or I have some on-Prem and some Amazon or some on-Prem and some Google, you know, I'm not quite the multi-cloud yet, or I still have some Unix box sitting in a closet somewhere. Um, you know, and, and I want to get this into a zero trust network. And, and our product is designed to do that.
It's designed to make it easy to get your network connected. And so it meets our customers where they are instead of asking them to change everything or, you know, hodgepodge something together and into some kind of word Goldberg machine. Because I think the way the world has changed, the way that, you know, our, our, our employees are no longer at home.
They expect to be able to be all over the place. Our applications are no longer in one place. There was so much you could control back in the day of saying like, we run that application on that server and that data center.
I can look at the traffic flows and control performance and blah, blah, blah. You know, that was one thing. Now the applications like WM in Salesforce's data center on the West coast, and I'm in, you know, NetSuite's data center over here, and like, the applications are really everywhere.
The users are everywhere. The world's totally changed. Uh, it's cool that to have a technology that meets our customers where they are, we understand that people have on-prem, we understand that they have cloud, we understand that they have SaaS applications, and, and so we're meeting them where we address it.
I get to do that internally. So my job is quite exciting, really. Um, and, and it's not that I don't go tap somebody on the shoulder, uh, that works on our product, but I do file a ticket first.
You know, where they live, I guess. Yeah, I do. I can still it.
I'm like, let's just say I can nudge things to make the move. Yeah, Absolutely. But you calling The ticket really nice email account you've got there.
Shame, if something happened to it, would you fix my problem? So, you know, when I look at cloud, what drives cloud transformation, what drives cloud transformation? So we get a lot of app modernization, driving cloud transformation, right?
In, in the old days, we used to just lift and shift our stuff from a private data center up to the cloud. That worked for all of six months. It didn't even work for six months.
We've quickly realized that that wasn't taking advantage of the cloud. And ever since then, we've been on this quest of transformation by app modernization. We, we are gonna, you know, micro thread, multi-thread, our apps, uh, microservice our apps, cloud data, modernize our applications to take advantage of the cloud.
And by and large, we're doing that a lot. There's a lot of app modernization going on out there. But, you know, just like in the book, the goal, which of course the Phoenix project is based on, right?
We just, when you clear up one bottleneck, the next bottleneck shows itself. So as we're modernizing applications now, we've run into network modernization. What we did before doesn't work in this new cloud native modernized application world, and we need to modernize our network.
The connectivity cloud is, is one example. But let's, you know, let's peel that onion back a few layers. Mike, what do we mean when we're talking network modernization like that?
I, I love that you started with applications because I think it's a really interesting way to talk about abstraction. If you think about, let's like rewind through my career for a second. Like the, the big thing about virtualization was that the network was fast enough to become a bus, and that you could actually, like, have memory and storage and compute being different places.
Like memory, you were in one place, storage was another place, and yet I could run an application that way. But the abstraction in that case was just about the hardware. Like we're abstracting the hardware away to make it more flexible so that servers don't die as easily.
You know? And, and, and it was easier to modernize them that way. If you kind of fast forward, like now to the cloud era where we put things in Amazon, what a lot of companies discovered on that journey was, oh, shoot, to your point on refactoring applications, um, this application's not designed for an availability zone structure.
Like, we want to do this cloud migration. We did lift and shift and oh no, this node went down in availability zone, whatever. And like, we lost something.
So that abstraction, you know, applications had to be refactored to take advantage of high availability scenarios in cloud environments, right? So the abstraction layer had to change. Then the next phase of abstraction is serverless, where it's like, Hey, look, I don't, I just built the application at this point.
I don't really need to think about, you know, the different three tier, like the database server, the API server, the web server. Like that was the abstraction layer we built in that world. The networks undergone a similar thing.
Um, but it's gone at a much slower rate because the innovation has had to come from the applications. The thing that serves the user from like an intent perspective. If we think about applications as like intent engines, somebody wants to accomplish something and they use the application to accomplish something because the network was like the roads that they used to accomplish that.
It was one of the later things to evolve. Like that's why we're not seeing it evolve quite as fast, because it's also expensive. You know, on-prem networks are expensive, they're complicated, and people have a certain level of comfort with them as well.
I know I did, like when I went from on-prem to full cloud, it was like, well, but I, I like my on-prem network. I have the inside, I have the outside, I have the DMZ. These are definitions.
I understand now my, my, uh, ERP applications on the cloud. You know, it's a, it's actually in someone else's data center, and I'm running it that way. And then I have these custom applications that are still behind the firewall that I'm trying to move on the other side of the firewall.
And so the dollars weren't going toward something with the network because it wasn't really the place the investment needed to go. The the key was like, how do I enable my users to accomplish things? So the network started to come later.
Now we live in this world where, where we have to think globally from like a performance perspective. And I'll, I'll give you an example of a challenge I faced in one of my roles where we had a big team in Argentina at this company, and they were like, man, Salesforce performance is really, really bad. And, and this is back in the days when I'd actually have to call the telecom and be like, Hey, you know, what's the deal?
What can I do about latency? You know, blah, blah, blah. And like, they changed something in a routing table.
I don't know why, you know, this was South America. Apparently you can change things routing tables in South America. I don't know if that's a good idea.
Got better and another application got worse, right? And so that was the trade off. And I remember thinking to myself back then, like, man, I need a way to bypass this.
Like, I, I need a way to, I need an abstraction layer of this. I, I don't want to call the carriers if I'm having one application performance issue in some of the part of the world, I need more flexibility. But that flexibility would've been really expensive too.
I would've had to buy pops in multiple carriers in multiple locations and do some kind of IP sec tunnel meshing to like make multiple pathways so that I can control the routing. And like, that's a drag. It's expensive.
It's hard to maintain. That's not gonna work. This transformation world that we're in now with connectivity cloud and this idea of a connectivity cloud is exactly that abstraction layer.
Why? Like, it doesn't make sense for thousands of customers around the world, thousands of companies around the world to build their own IPSec tunnels across different, you know, mesh networks and try to make this happen. SD-WAN kind of proved that that wasn't a great idea, by the way.
Like SD Gonna say, most people think Connect Cloud is put sd-wan at the edge and you're good. No, I was like, no, It was actually pretty complicated. Yeah, SD WAN tried to solve the problem exactly that way.
Multiple carriers, multiple sites, SVPN tunnels didn't exactly deliver what they were wanting. Instead, you started seeing companies pop up where they were saying like, Hey, we're maintaining a bunch of pops all over the world. You can connect to the closest pop and then we'll figure out how to make your traffic optimized.
But even that was a bit of a drag because you were still developing like IP sectors to these individual places. And so there's this extra layer of like, I'm encrypting the data through a tunnel and then it's gonna come back through this. And there's still choke points, uh, that, you know, so it's not the optimal thing.
Um, at CloudFlare we have technology that literally, uh, decides which path is the fastest on the fly based on circuit utilization. So compared to routing protocols, in routing protocol world, you're, you're picking fastest path based on speed. You might find a faster path, for example, that's like one hop is faster than the other hop, but overall that that path is faster.
But BGP only optimizes for certain types of path optimization. In our world, we're looking at like, what's the saturation point of a particular link? And should I send you this way versus this way based on the actual traffic dynamically in this moment for this packet?
And that's, that's one of the things I think is really cool about our technology is this idea that like, I can make performance really what, like great for end users. The user experience is incredible, uh, based on current conditions, which is, which is amazing. And I've nerding out with all these telecom networking terms you mentioned, uh, zero trust before.
You know that, that, that is a, a giant elephant E two, right? Two simple words. It sounds good, like a good idea, but implementing that strategy can be a handful.
H how is what you're doing with the connectivity cloud make that easier or at least the path to get there? I know it isn't all just the network, right? But love your thought, love to hear your thoughts on that.
So it's, I'll like, let's, let's like reminisce for a sec about, Hey, we're old. It's good with us. Absolutely.
Hey Allen, would you unplug the router? Yeah, go ahead. Yeah, I liked it.
He said BGPI. I'll be honest with you, I got a little swell coming on my face. There we go ahead.
Yeah, let's like reminisce a little bit. You know, know back in the day when, you know, like one of the, one of my gigs I I I, I had set up when I called a, a walled garden approach where if you were trying to get to the database vlan n and the data center, you had to VPN it, even if you're on the inside, right? Right.
And so I had to sort of develop this approach. The inside interface of the firewall had to allow VPN connections and then only the DB database admin had, right? To get to the vlan.
N Like, that was, that was a way that I secured it. Uh, you know, I, I had this concept of the outside and the inside and then differing, you know, microsegmentation of the data center in terms of how to secure the business and meet all of our compliance requirements. And VPN was how we did that back then.
But it was a pain because people had to log in twice. I logged into my laptop and then I logged into the VPN. Um, and, and so there's like a two step process and the end user doesn't, they shouldn't have to care.
They shouldn't have to think about it. The best security is the security that just works and is already there. Like the natural, when the natural thing to do is the secure thing to do, we're winning.
We know that, that the people are gonna be most likely to follow the path to least resistance. They're gonna do the thing that works well for them. And, and let's, let's face it, let's not put any more steps in between them and what they're trying to accomplish, right?
Like, we want them to be effective, we want them to, to work well. So that's the design. So rewinding again, like in the old school world, we did that with IPSec.
It was painful, it didn't work well. Uh, and, and people were frustrated, increased support costs. It was, it was very hard to manage.
Now let's wreck that whole paradigm too. We start moving applications out. My application's not behind the firewall anymore.
So the IP secal is kind of a waste. In fact, the IP secal made it worse because someone in Georgia's VPNing, the San Francisco to get you an application in New York. And now more applications are coming from different parts of the country.
And that perform like, oh no, my zoom call was terrible. Huh. That's weird.
Well, we routed all your Zoom traffic through the tunnel. Oh, man. Well, that means that, like, I added latency 'cause my Zoom traffic went all the way to one coast just to get to another coast.
Or the first person to join that meet call was, was in Japan. And so the pop that Google spun up for that meet call was in Japan. And like nobody's latency was good for that one.
You know, all these different things are happening. Um, now let's talk about how we would secure that in the modern world. So with every challenge that we've seen in terms of the evolution of the internet and applications and SaaS, we've created opportunities as well.
If the old firewall was here's some IP addresses, uh, and I'm filtering based on IP addresses and domains and blah, blah, blah, the new firewall is actually the person, the new firewall is who you are. What is the device you're on? Where are you right now?
Um, is your antivirus up to date? That's actually the new bit of information. And being able to make contextual decisions around which applications are you, you allowed to get to right now based on the context.
So like, I can now paint a picture with the zero trust world. I can paint the picture by having the zero trust client on their laptop. They, they're already authenticated to it, they don't know it's running.
You can see the icon, but it's, it really seamlessly disappears in the background. But now I'm evaluating your ability to access applications based on what I know about the device you're on. You're on a company device, but you're, um, you're in an airport in, you know, some other country, right?
Like, well, maybe I don't give you access to certain tiles in the single sign-on profile, because I don't want you to have that. You're in a place where you probably shouldn't use that, right? Or I wanna make sure that you're following the best path.
Um, the zero trust client can decide, for example, on the local machine that like, Hey, all Zoom traffic's just gonna get routed straight to Zoom. Like we, we don't need to route this through a tunnel because it's not gonna be any faster. In the case of our global network with all the pops that we have, our, our zero trust client could decide that it's faster to go through the, through our connectivity cloud, right?
So like the best, the best option wins the most performance options wins. But also the, the context of like, what security outcome am I trying to drive? Also wins like, hey, this, you know, this is sensitive data traffic, we're hitting our dashboard.
This needs to always go through the private network and never go through any kind of unsecured channel. So zero trust is a way of taking who someone is and the information about where they're right now and applying that to what kind of access that they need to have while also giving them performance enhancements. And by making the decision on the laptop or on the, the nearest edge, instead of like somewhere in a central firewall, the performance is naturally better.
Like you're making the decision fast, you're protecting the user more quickly. You've shifted it from that firewall from going back to headquarters to, you know, a basically intelligent app that knows what can take those rules, those policies, and also, you know, these costs routing and what's the best path there. But, but really that's the whole point of this is we shouldn't have to take anything back.
Yeah. Mm-Hmm. To the central to, to the land, to the, you know, to the big honk and box back there or whatever, or VPN Concentrator, right?
That's the whole point of having an edge and, and doing all that. I mean, you know, we, we wanna be done with that. Um, here's a worry.
I have though, Mike, and I'll ask you directly, there are only a handful of companies in the world I think that can provide this kind of solution, right? CloudFlare being one of them is that it's a great barrier to entry if you're a shareholder, right? Um, but is, is that putting all our eggs in in one basket kind of thing?
Do we need, like how do we, do we need more modernization as part of that modernization to have a broader set of options? Hard question. It is a hard question.
And I think, let's reminisce again. Okay. So, you know, back, but going back to the days when people moved their workloads to Amazon, right?
There's a lot of trust that had to go into that. Yes. That that massive amount of trust and Amazon learned on the fly.
Uh, I, I'll never forget the first time somebody pointed out Amazon EC2 to me, I spun up an instance and I did some network scanning on it, and I was like, this is terrifying. I could compromise this instance pretty fast because he spun up with a public IP address. He was completely unprotected when EC2 first launched.
It was like, whoa, who is? And so my boss had asked me back then, he was like, alright, so what do you think? And I was like, now is not the right time, but watch out.
Like this is gonna be a big deal. We had to trust these cloud providers over time to like get better at protecting things. But we still took the risk of siloing.
Like when you were in a w AWS's infrastructure, you're in their infrastructure. You use their terminology, you use the tools they give you. I mean, let's contrast that with a second before that, that that model, we, we, we all don't like, of like bringing everything into a VPN concentrator, your CEO, right?
Like in office, why did people do that? Well, I, I probably bought some product that's sniffing traffic that can decrypt it and help me understand threat analysis or whatever the reason companies felt safe bringing all the traffic home was that like, I can inspect it. I can try to figure out if something weird's going on, and I, and I can work with it that way.
But that didn't really work because the cost was performance. The cost was like, is anybody really looking at that intel? Um, how up to date is that Intel?
And, and you know, in the security space, these type of threat products change constantly. Like the security landscape is constantly changing. So I don't think there was ever really much of an advantage to that IPSec model where you bring everything in into your house and you inspect all the traffic.
But then when we moved to Amazon, it was like, wait, where's my package inspection? Like, how do I know what's going on? So I would say, first of all, to, to start to answer the question is like, we've been trusting other companies that have silos for years.
GCP has its own silo. Oracle Cloud has its own silo. You know, a a Azure has its own silo and their incompatible silos, um, the only compatibility layer they have is the open standard of IPSec.
They're like, we can talk over something that works anywhere else, but it really doesn't give us any advantages. So now zooming out for a second with companies that are providing this, this like glue that stitches all these different clouds together, and they're only being a handful of them. It's no less risky than it ever was to make the first leap of migration.
Um, but the performance has to be worth it. And so I think nobody wants to employ an army of network engineers to try to keep a thousands of IPSec tunnels online, um, to maintain this in-house and build some weird Goldberg approach, especially when the cost of doing this through provi through providers that are making this their core business is actually really, really low. The trust factor is no, not much different than the old trust factor used to be like, I have to trust somebody or else I can't do a business.
Um, but I, I would say that because we bet the farm on this, this is what we do that makes us accountable. Yeah. Like we are by nature accountable.
And, and one of the things that I love about CloudFlare is how we are accountable in ways that are, that are responsible, like Project Galileo, where we give away services to, to people who can't defend themselves so that they get all the protection of our cloud without connectivity, cloud without having to pay for it to make sure that their voice isn't lost and that someone can't decide to take their voice out. Um, we take this job very seriously and I think it, it is about following, following the intent. Like, you know, what, what, what do you do with this?
Like, we, we really do believe in building a better internet. And uh, I think that's critical. But to your point, there's only a handful of companies that are gonna be able to compete in this kind of space because the innovation is blazing fast.
Uh, and, and really something you want to get onto. And I, and I thought that the po the title of this was really fascinating to me on the transformation bit, because usually in my world, when you talk about transformation, it's like business process transformation. You know, can I take some antiquated process and turn it into a digital process?
But the network transformation's different because now it's more like treating Earth is, is a global network instead of my locations on earth. Yeah. As, as my individual networks.
And I think that's where the, the paradigm shift's starting to come. Agreed, agreed. Look, you know, this is a, this is the complexity of, of the, of the technology that we use today.
As I mentioned in the beginning, right? Sprinkle a little AI and really complicate things. It's only going to continue to, to become more complex over time.
LA maybe we could simplify what an end user's use, you know, it's easy for them to use. But behind that curtain, man, it, it, it's complicated. I, I wanted to talk a a little bit, and this is so a topic we have brought up on the last great cloud transformation, which is, look, whether you use AWS or Google or Microsoft or Oracle or any combination thereof, really the more the merrier as far as we're concerned here in terms of the connectivity cloud, right?
So there there is no, you know, so early on, you know, reminiscing early on, if you were AWS you were AWS, right? You were all in. The only thing we can contemplate was a hybrid cloud where maybe I'd keep some of my stuff back in my own data center and some on the public cloud.
But of course, in today's world, we've, we've realized that's probably not as realistic as I go to whichever public cloud is, right? For my particular, yeah, for this particular use case. They have other use cases here, use cases there.
And I do need something that kind of buys 'em, brings 'em together. Um, you, you know, you've been in this from the get go. When did you realize that this multi-cloud, 'cause it was, I it, I'll be honest, it surprised me.
I didn't see it coming. When did you realize that multi-cloud was gonna become sort of the way, the dominant way, the preferred method? Probably I was thinking back to like 2012 when I worked for a, a VoIP startup and we were using, we were OnPrem and we were using a, um, Amazon to develop VoIP at the edge on their side for customers.
Like how would VoIP work in an AWS context? And I was thinking like, man, this is a lot of eggs in one basket. Uh, and with, you know, Google's no slouch at cloud and they were talking about cloud, but it wasn't as mature yet.
And Amazon had this incredible explosion of Legos, like, because let's face it, they took open source products and productized them as services, right? Yep. So you just take open source software, productizing services, they're cranking out Legos as fast as you can.
It's like all of a sudden elastic search is Allego that you can just run my sequel with multi-site replication is something you can just run. Like they, they took the stack of the three tier web architecture and sort of made it a service, which is really interesting. And I was like, so initially I was worried about like, God, I hope somebody competes with 'em because it's, they're, they're, they're really far ahead.
They're, they work with Netflix pushed their envelope really hard. Like they, I think Netflix was one of the biggest customers that pushed Amazon to the edge and to the limit and forced 'em to rethink things. And I was watching Google come up and with less excitement, I was watching Azure come up and I was like, well, at least multi-cloud has to probably exist.
And I was thinking Azure adopters will probably be p people that feel safe with Microsoft, with, they have a lot of Microsoft applications and it will just naturally make sense for them. And then Google will be the, the other people that are like, just not just not Amazon or I need another cloud strategy, but like, I've been happy to see Google come up and really own it and make, you know, a great cloud product that has a lot more Legos and a lot more connectivity. They've got a good product going, Azure's doing a great job as well of making it easy for their customers to do business on the cloud and have options.
But we're seeing another move now back to colo and back to some on-prem things where companies are realizing that, you know what things, it's way cheaper for me to own the metal. It's way cheaper for me to run it myself, and I'm gonna move this workload. Part of my initial thing with, when I, when I go back for a second for like, oh my gosh, I hope there's competitors.
It's because I was like, man, this is a lot of eggs in one basket, and they can start to control our margins. So like, if I give Amazon too much business, they have too much control over my margins and I don't like that. But moving workloads is not trivial either.
And so my, my fear on multi-cloud early on was like everybody will need a multi-cloud strategy, but it will be optimized towards maintaining leverage. I need to maintain leverage and that leverage has to be material. I need to be able to act on it or else it's not really leverage, right?
All the while watching cloud providers try to compete with each other while also trying to escape commoditization, like commoditization, you know, yeah. Are gonna go down. Value added services are going to go up it.
To think about it in a less technical context, I think about baby carrots, which now you're probably going like, what the hell, Mike? Where where are you going? But seriously, you know, farmers growing carrots make very little money on carrots.
If I sell them raw in the store. All a baby carrot is, is a big carrot that's been chopped into little pieces and skinned like that's a baby carrot. But that value added product actually goes for more money.
Cloud providers do the same thing. They take something like, Amazon's a master of this. Take an open source product, run it as a service charge way more than it costs you to run it value added service.
Like they're nailing it. But me as the buyer, I need some control. I need to be able to control my costs.
And so a multi-cloud strategy is part of what I need to do that because I have to understand like the nuances between, you know, provider A and provider B and my applications and what those needs are. And so any multi-cloud strategy has to be centered around what am I trying to accomplish and what kind of continu business continuity do I need to maintain? So yeah, it, it's a fascinating world that we live in, but the, the multi-cloud thing had to happen because in a world where there's only one player, they can, they ultimately wouldn't be giving people any kind of choice.
Like, it, it's too expensive to run with just one player. Like they really control the cost. And I, I already think it's really expensive, um, because people leave workloads running, for example, you know, always you're, you're you're trying to figure out like, why is it I call 'em zombies, like somebody leaves zombie workloads running.
You're just like, man, the meter's running, like nobody's using this thing. Well yeah, we rack it up to dollar. It's good to manage.
Yeah. Like I think multi-cloud is hard to manage too, but it's also inevitable. We have to distribute our risk.
We have to distribute our workloads and make sure we maintain leverage and negotiations. So multi-cloud was natural, but it took a long time to get here. 'cause keep in mind, I was thinking about this in 2012, and like you really couldn't have a true multi-cloud strategy in 2012.
Even today, it's pretty hard to have one because workloads aren't exactly portable. Like there's some, there's some changes in that world, but they're not portable yet. No, I I I'm sorry.
Go ahead Mitch. So Many of us is, I was just gonna say, so many of us have kind of backed into it right through m and a activities. Yeah.
You know, we're this cloud now There's a lot of that pre Cloud and you had to, you know, what do you do to try to make sense of it just to operate it effectively, more or less, get to a point where that's part of your go forward strategy and what workloads can you distribute across those or move across those clouds? Not, not a simple question. I, to me it's more, you know, a thing I learned as I was growing up and, and got older was it's not the man, it's the tool and it's the right tool for the job.
I think for particular jobs, there are cloud providers as well as other options, right? My own colo or what have you, my own data center that are the right tool for the job. And I think the job of today's CI CIOs and, and architects is to figure out what's the right tool for this job?
What's the right domicile for this job? How do I use the connectivity cloud to glue that all together and make it look and appear and act as one contiguous infrastructure, but still use the right tool for the job? And I, I, I think that's what does it, And it, and it kind of goes back to the, to sort of ideal state of what a security tool would do, which is like, allow, I'll please allow me to maintain a policy and a posture consistently, right?
As security cloud is about that. Like, we have the same players, we have users, we have services, we have servers, we have applications, we have all these different things, but like, allow the policies to be uniformly applied and allow me to prove that I know what's going on. Agreed.
Agreed. Guys, this has been a tremendous conversation. I, you know, we went far off, we started with better connectivity and security through network modernization and we discussed a lot of that, but we discuss, we reminisced a lot as Mike would say.
And, uh, you know, we, it was good doing that. I look forward to continuing this line of conversation in future episodes of the last great tra last great cloud transformation, Mitchell, I think our next one is a live round table, isn't it? I believe so.
Yep. Yeah, we, we just definitely have one coming up. If You're watching this at home, check it out.
Make sure you register for the next live one, because I'm sure you've got questions. I can't promise Mike's gonna be there. He's, he's got a bit of a job to do when he is not doing this.
But if you've got questions around the things we're talking about today, we invite you to participate in there. Many thanks Mike to you and CloudFlare for, for participating and co-producing this with us. It's, these are the kinds of conversations that people like us enjoy.
We could talk all day about. Right. Good stuff.
I really flew by. I'm happy to join you anytime, but I had a great time talking to you today. Absolutely.
Well, we'll make sure we'll get you, you back here. Don't you worry. Um, Mitch, I didn't get a chance to introduce you, you jumped right in, but why don't you take the last word out then?
You know, I, I, I loved, I loved the walk back, you know, looking at kind of how we got to where we are, right? 'cause that informs where we go forward and there's so much, what, what's really changed is you said it, Mike, going from points on the earth to the earth is my cloud, right? That's my location.
And thinking about, you know, don't use your points of presence that you know about as your limitation. Just like, don't use your, you know, hauling traffic back to the v VPN concentrator or the center of the network, either. That's, it's a different paradigm.
It's a distributed processing network and, uh, there's a lot more things we can do with it. So it's an exciting future. We appreciate you, Mike, sharing your, your experience with it as well.
Alrighty, all on behalf of Techstrong and CloudFlare, thanks for joining us today. We'll be back with another show soon. Until then, everyone, good luck.
Take care.

