Cloud Field Day 24 Delegate Roundtable Discussion
Transcript
This is our final session. This is one of the sessions that I really enjoy because we get to talk to some of my favorite people. These are the delegates that, uh, I get to, um, invite to join me here and, uh, get to spend the time off camera with them as well.
They're some of the, the smartest, most fun people that you get to spend time with. Uh, if you'd like to become a delegate, of course, there's a submission form up the top on the Tech Field day website. We wanted to have a bit of a round table discussion of people's impressions and, uh, things that we didn't really talk about as we had the last, uh, day and a half of presentations where it was all focused on what the individual presenting companies were talking about.
And in this round table, we want to talk a little bit more about the things are that are on our minds, uh, particularly those of us who are working practically with these products who have to put them into very complex, uh, very brownfield kind of environments, and who are trying to navigate what's the right thing to do for our customers. And, um, what I saw was, was that we have a feeling that a hybrid cloud or private cloud is turning into a real thing, but it's a different thing to public cloud. I think we saw particularly oxide morpho.
So a couple of companies that are very much about this is your on-premises cloud, and it looks like a cloud only. It doesn't look like the public clouds. Please start leaping in and joining me in this conversation, because I don't wanna monologue for half an hour.
I, I had, I had a little context dissonance, um, because a, some of what was presented as hybrid cloud felt a little like multi-cloud to me. But then, you know, I hate, even though I participate in them all the time, these all the time, these semantic discussions. And I, one note that I took at some point was, um, is hybrid cloud just really just storage now?
It's just, you know, storage, tiering. Um, I, I, I don't know. But, um, one theme we saw was this idea, this, which I really thought of as a multi-cloud idea, which is put your workload where you wanna put it, right?
Move it as you wanna move it. That's not multi-cloud. In my, uh, considered opinion, my considered opinion is you can put different parts of an application wherever you want to put them, and they can interact together.
Um, the, the, the, the really neat thing that I think we saw though was throughout this field day was this enablement of placing a workload in a place that you want to put it for all the various reasons you need to, and still have the observability, the management, it, a lot, these vendors are driving towards that. Whether it's the happy, easy, quick, if, you know, multi rack home of an oxide, or it is a, um, multi environment management with all of the compliance and, but, you know, uh, uh, reliability bells and whistles of a, of, of an HPE. So I, I wanted to hit on, on one of the things you said in there about that, um, having your data everywhere and putting the bit of your application where you need, and it's getting execution on different places has always been the easy, easy part.
Getting the data in those places has been different. Kimberly, have you seen a lot of change in the last few months around, or last couple of years around making data available wherever the workload is going to be? Because there's simple physics involved in a lot of that.
Yeah, I think that's what, where the on-prem part of the on-premise issue is, is actually why the things are staying on-prem. Um, the data sovereignty, the how hard it is to, uh, move the data, um, in terms of the problems with physics. So the concept that everything was gonna end up in a public cloud has just not happen from an enterprise.
And there's many, many companies that still have very large environments sitting there. So we are seeing people like the oxide look at ways to bring a secure environment on-prem. We're seeing things like pure storage saying, okay, so you're gonna have data on stor, you're gonna have data on-prem, I'm gonna be able to manage it up on the cloud, um, as well move it to where I need to be, where the appropriate places, as you were talking about guy.
And, and then you see, you know, the piece of what HPE was talking about, which was this, um, cloud operations capability of saying, I've got different environments. Let me manage it where it most appropriately would be managed, but give me a control plane to simplify that environment. So, yeah.
And while we're sitting on this corner, I wanted to bring in Karen, because Karen's insight around the difference between storage and data is always important. Yes. Storage companies talk about data when they actually mean storage.
Yeah. Uh, did have you seen things changing? Uh, did you see anything that, So definitely this week I saw better understanding of what the rest of the outside the storage world, what we think data management and data classification and data governance are.
It's still really behind those of us that have been doing data management, data governance for multiple decades. But I think now at least I'm seeing a better understanding of it, like related to the sovereignty issue for data sovereignty, is that the message I took that wasn't said was that for many enterprises, the vendors believe that the cloud isn't meeting their data sovereignty needs. And that to me was sort of a revelation in that yes, data sovereignty is actually very hard to deal with because like the big thing that happens with most cloud services is that yeah, you can store your, you can choose the region where you store the data, but some of the, the surrounding services require that data be to be exposed in another region that you might, so that means people like the EU data centers and the Chinese clouds and all of that, they can't make use of many services in that cloud provider.
So maybe their cost benefit risk is way off. And maybe that's what's driving a need to manage data sovereignty better. So, you know, to go along with that, right?
We had the, the, the confluence of both the, the Broadcom VMware debacle, we also had Microsoft, right with the, with the lawsuit or not the, with the court case in, uh, Paris, where they would said, you know, obviously if there was French, uh, owners' data, uh, and they were asked by the US based on the cloud act to give it up, they would, they would've no choice. That kind of blew up that, that became sovereignty became all of a sudden conversation one A if a AI was, uh, was one. So there's a lot of that going on.
And so I, I think the reality though is that there's gonna be ongoing change, right? You never, you can't predict the future. You don't know what AI things you're gonna do.
You're not gonna know what new compliance things are gonna come about. You're not, you're not gonna, you know, some governments are gonna deregulate to try to help business. So, uh, I think, you know, going back also to what Kai was saying about hybrid cloud and, and, you know, being able to move these workloads and data sets around, um, I, you know, what I work on a lot is, is the, is an architecture of optimizing for data placement in a way that, um, it can be used in all the different places, either in place where you have compute in the cloud or compute in a service using the data in place.
Now, it may sound, yeah, there's physics involved. That's only a problem if it's a problem. Some workloads are fine with that, some are not.
So if they, when they're not, you obviously have to get a copy of that data to the place where the workload has to run. That's data motion, right? So these technologies like Electra, like other companies Pure, that can get that stuff up there and, you know, purity does that, it automates that data transfer, right?
Um, so when these storage companies talk about governance and compliance, they really, you know, where you, where you stand depends on where you sit, right? They see it from their perspective, but the reality is that they are enablers of being able to achieve those compliance, those governance tasks by the folks who will use them, but they don't in themselves achieve that stuff, right? And that's sometimes they fall over on that.
Sometimes they get a little over their skis on what they can, what they do in those worlds. And sometimes they don't even have a full understanding of those terms. And it demon it's demonstrated a lot of those, those presentations.
But, um, overall when you took at like oxide approaching their, uh, their kind of private cloud, um, fortress I'll call it, uh, because it's, it's all controlled and completely, you know, attested for, I think that's a great, I think that's gonna be a great option for people to move Kubernetes workloads or even KVM or, or, you know, kind of other virtual machine type performance that in order to achieve, I think it's all gonna be driven by this, this, this, this desire for sovereignty and governance, right? Workload, right time. Um, but the data architecture is kind of separate to that.
It, so you have to have the data architecture kind of set up to, to do this kind of change, to move data where you gotta move it, but the workloads, they're ephemeral, they can go wherever they want, but you have to have the right, yeah. You know, architecture and networking for all that. So it's kind of two planes of existence.
So there, there's, so I both agree and disagree with con on, on the fact that it's, yeah, it's data moving all over the place. The workloads need to move, but they're almost like two separate, independent, but somewhat related motions, right? That's conflicting.
But, uh, but that's why no one's answered it. 'cause it's a complex topic. It's Still in, it's, it's complicated.
And, and the other element are around this, and one that Mike and I talk about a bit is the financial operations around this is having completely different models. We, we talked a little bit about having, um, different models that Glen, you brought it up, uh, in the last presentation. But, uh, just how do you financially manage this, this diversity of platforms you're ending up on and work out where is the right place from both compliance, but also from cost and capability?
How does, how does that matrix all to put Together? I mean, that's where a lot of the on-premise stuff kind of falls down compared to public cloud is public cloud. It's entirely consumption based.
You know exactly what you're spending, um, by a minute, public private cloud, a lot of those costs are hidden, right? And you don't see them until later, if ever. Right?
There's the cost of the acquiring the equipment and racking and stacking it and, and all that. That's clear. But the, the power costs, the cooling costs, the personnel costs are things that aren't usually baked into the total cost of ownership of that private cloud.
True. I would actually argue that it's the exact opposite. Hmm.
So one of the big challenges companies have right now, and why they're doing repatriation is because dealing with ai, they're getting hit with The bill shock. Yeah. Yeah.
Mm-hmm. Bills because they don't have visibility to it. And you have things like our, uh, an AI agent that, you know, to get started costs 20, $30 a month and you start developing it, and then you deploy it and your cost spiral not from 20 to 70 or 20 to a hundred Yeah.
But to a hundred thousand dollars a month. And the shock is incredible and it's unbudgeted, and you can't not spend that because you have this service now that's valuable. So you want to repatriate that.
And that's the other part of the financial thing that's coming up, which I sort of alluded to and brought up with oxide folks, is there was a change in the tax law this year that allows large corporations to write off a hundred percent of their CapEx in this calendar year, in the calendar year, not having to, uh, depreciate it over a five or seven year term that is waking people up to the fact that they actually do get a tax benefit. And OPEX is no longer as competitive as it used to be to CapEx. There's now a very, a valid reason to build CapEx and bring things OnPrem again, One place in the world.
I think that That all changed in the us Yes. Is What I'm saying in the, I think one thing that I keep thinking about is the complexity of running an IT operation in 2025. Um, all of the things you guys have been talking about, endless lists of security threats, um, the need and imperative to turn I, um, AI into something that is monetizing for the organization, and then repatriation and the complexity of, um, building out infrastructure at this.
At the same time, staffing remains one of the cha biggest challenges for IT organizations. And so one of the things that I really like to hear from many vendors is simplification, whether it's oxides, rackham, stack them, Lego racks. I mean, they're, they're very cool.
Or just, you know, the simplification of point and click provisioning from HPE. We saw the vendor community is focused in on that. Now, whether they can deliver and whether this is something where IT shops are feeling confident about, um, deploying these private clouds without having to worry about, you know, key staff departures, ruining their, um, their operations.
I think that's something that the proof is still in the pudding. 0 for fusion mm-hmm. 0?
Well, our guys at UCLI really wanna use it, and they don't wanna go over there. So if you want them to be able to take the advantage of the simplification, you also have to give the guys that know how to make it all happen and have that, you know, knowledge base, give 'em the tools that they wanted to use, um, at the same time. So you just can't.
Yeah. We talk about simplification now, make Everything, Yeah. We talk about simplification, but you know, the reality is that, you know, we talking about, like, we heard the storage story from HP today, right?
And, um, they announced, you know, R-D-M-A-O, uh, you know, over object for, uh, for that electro bot, the x uh, 10,000. Right? So obviously that implies that that's gonna be sitting next to GPU.
Great. Um, the reality though, uh, and, and the way, uh, you're gonna have some organizations that are going and put in, you know, go and buy the new, you know, GPU, the, the Blackwell stuff and soon the Vera Rubbin stuff. But this stuff's all requiring liquid cooling.
Um, which changes the game from an operational perspective, which I think is gonna drive a lot of company, a lot of enterprise customers to prefer to use GPUs as a service providers for that kind of stuff. Because it's one thing to have an air cooled environment, this is where things get physical. Um, and, and if you can get away with that, that's great.
You can manage it and you can understand it more like a traditional IT environment. Once you start bringing in liquid cooling and things like that, things get a little different. Um, and, and most folks don't know how to, how to operationalize that.
And they might get somebody to help you, some manage service in your colo to go and do that. But that's still happening, right? That that's not, uh, a thing yet.
Um, in some places it is. And, um, I could talk about that in time, but, uh, I just think it's gonna drive a lot of enterprises to say, you know what? That's too much of a headache.
That's really not my wheelhouse. So when I see these storage folks come out with these, you know, RDMA over this, these, these, you know, this fast RDMA, uh, you know, object storage that are meant for training, maybe tuning, um, it's like, okay, but that's gonna be meant for the, that the storage system needs to be in the GP unit service provider. Um, not in an enterprise itself.
I, I'm gonna need to get my data, my lakehouse my data pipeline. I may wanna do that on, you know, I don't need the R AMI stuff. I just need, you know, I just need more like a, a regular pipeline.
Maybe I need that tokenization and embedding done there, that's great. But to do, but I don't, I don't need that kind of performance or that, that specific type of performance that's gonna go somewhere else. I, it's, it's, I'm questioning the, the confluence of these things.
Mm-hmm. Because this stuff is not simple to manage at all from a physical perspective. And that's where we're having also a bigger shortfall of people.
We need real engineers, like physical plant engineers to, to help with this. Yeah. It's, it's that discussion from, you know, oxide was talking about they're being really power efficient, 15 kilowatt rack, um, that's a, that's a ceiling on, it's managed to be at that ceiling.
You're at AI infrastructure field day, they're talking about 200 kilowatt, 300 kilowatts, 600 in RA Rubin. So 600 kilowatt racks and that your data center's gotta be built for that 800 Volts. So all of a sudden it's, it's 40 racks worth of power being consumed in one rack.
And, and this absolutely is, as, as, um, Glen's saying there's a huge amount of engineering change. Mm-hmm. And you have to have a data center that's built for it.
So I completely agree that you'll see neo clouds being the way most of, of that high density, high performance GPU is being delivered for many companies. Now, put that in context of all the things am Morpheus was saying, moving to workloads. Like, if I gotta use those guys, that means I'm gonna have to have compute over there.
Not GPU, but also CPU compute to do stuff there. Right? So what is that gonna look like?
It's a whole other set of apps. I I think kind of to your point, like o one of the things I think gets lost in the AI conversation, just in general. 'cause everyone gets so excited about ai, everyone wants to do it.
Um, they don't point out that doing AI means very different things, different people. Absolutely. There are people that are gonna go buy thousands of GPUs, liquid cooling is an issue for them, and they're on a whole different level, but there's mm-hmm.
You know, and they do need that very fast storage, um mm-hmm. But there's only a handful of those, uh, you know, real hyperscale, uh, organizations. For other people, it's as simple as, okay, I'm just going to use, you know, an open AI endpoint.
I don't need to really train it. I'm just gonna set up, um, rag or, so it, there's just, there's different levels, but I think, um, the conversation just becomes, everyone's doing ai. Um, this is what you need.
Good point. Yeah. I, I think another interesting departure filling out what you said, Mitch, was the fact that there's, you know, I was just looking through my notes from AI infrastructure field, right?
And which is exactly six months ago today, either way, which is interesting. And the thrust was, um, how are we gonna get GPU power to people as quickly as possible? And, you know, you're gonna need all these, you know, huge power demands to, uh, uh, kind of like a, a drumbeat of do we really need to do that in a lot of cases, right?
What people are applying AI to could just as well run on A CPU, right? Certainly inference, you can make the case that a lot of the inference would certainly work there. Um, so I, I found interesting that some of the vendors we talked to were kind of pushing back on that a bit, right?
Especially oxide, of course, because well, they have the story, but the other thing, especially with the Fortinet folks is again, I don't know why the CIOs and why the CISOs have not got the CIOs or the CTO's ears on the, uh, we were talking about CPS and the huge exposure, right? That we saw Fortinet demonstrate yesterday to, um, things we didn't even think of where you, you know, as they were demoing, right? That, Hey, tell me what advanced stuff I can do, please tell me.
And essentially root kit, you know, an environment because somebody decided to, you know, over the weekend to impress their boss, they vibe coded a website, which has all of these vulnerabilities that now we've quadrupled or quintupled our attack vector sphere, if you will. And to me, it's just this rush towards ai, because I don't know, your buddies on the golf cart course are doing it too. So Jim, that's not, it's just, yeah, that's not entirely fair because it's not just the applications that are vibe coded over the weekend.
That wasn't example they gave, okay. It's an inherent misunderstanding of how AI operates and how these models work. Okay.
So really quite sophisticated. Um, really AI practitioners right now don't even understand this. Yeah.
Mm-hmm. And, um, that the vulnerabilities that exist in that way are inherent to the models, how they're trained, how the rag works, how they're tuned, what data they're exposed to. Yeah.
And the focus, um, that is only emerging now from what I see on data curation, data limitations, guardrails around DA data. Mm-hmm. That's just, that's incipient right now, right?
People are suddenly go like, think about MCP, just MCP alone, who in their right mind publishes a protocol and adopts it left, right, and center? That actually starts with open access. It's, yeah, it's right.
It's, yeah. Karen over here is showing her horrified face. Well, so during the, the Fortinet, um, presentation yesterday, I think, you know, we kind of started off ly had a question about, okay, but AI is just another workload, so what's unique about protecting ai?
And then they went through their examples of exploiting agents and things like that. And then kind of at the end, I think Karen had a question, um, or more comment about, you know, I'd like to see an example of, um, you know, an inside actor threat. Mm.
But the thing is, I think one of the things that makes AI unique, um, as a threat is when you have an agent with tools that have permissions in your environment, it's kind of, it kind of becomes an inside threat. Mm. Yeah.
Absolutely. And I think's a term that she used was colloquial, or they use colloquial, is that the language we're using to talk to the ai and the agent is just normal language. I don't have to know how to do the definitive coding.
And so I'm asked, and I can explore You, you can social engineer the ai, its social engineering, Social social engineering, the AI and the AI agents talking to the AI agents, and then, oh, you know, all of a sudden I've got just said, I've got the tools to, to go and do the hacking. The Interesting thing about sort of what Fortinet showed, and I think what a lot of the other vendors showed is different perspectives on how to think about the entire cloud infrastructure, right? And, and I'll use the, the, the US colloquialism of, uh, when all you have are nails, everything looks like a hammer.
And if you are a storage provider, you look at things through the lens of storage and you say, how do we manage the world through storage? And oh, we have excess CPU, so we can put, uh, uh, uh, an AI agent and, and an LLM and an MCP server in the middle of our storage. And, uh, I think Jim, somebody like Glen might have said, you know, just because you can, doesn't mean you should, right?
But then you, you know, you step back from Fortinet and you look at oxide and hp, um, they have a different view of what's the, what's your perspective, your a hundred thousand foot level of what my infrastructure looks like and how do I manage it? And I think managing your infrastructure is where the value is not in the infrastructure components themselves. Uh, HPE is a hardware purveyor, and so they still want to talk about hardware, but the real value they're bringing isn't the fact that they can put CPUs and disk drives in your data center.
The value they're bringing is their ability to span and manage this environment across your environment. And more, um, uh, oxide took a different perspective of we're gonna build a specific environment that is well managed from top to bottom in order to provide you that same capability in a different way. You got something next?
Oh, I, I was still just thinking of the, the, when, when you were talking about social engineering, the, the agents, there's even you, you sometimes there's rules where it can't give you an answer and you just have to rephrase what you're asking. Yes. And you're still going to get it.
Like he had, he gave the example yesterday, just putting an exclamation point at the end of it meant that now I'm yelling and Oh, okay. Yeah. Actually here's, here's the answer.
Yeah. We saw at one field day, I can't remember which one, that you could flirt with an agent to get it to give up its goods, or you could bully it, those two Things. Wow.
Wow. And because they really are, okay, this sounds like an insult, but it's like talking to a toddler who has a new iPhone in that they don't know what they don't know and they don't understand risk. And, but you can do that.
And that's, when I think of compute, I never think that way. So it's having to do this adjustment on how AI works that has really got of other things. And I think one of the thing, one of my concerns was, and I know they're limited on time, is that we only really saw one presentation that addressed AI protection or security from the role of AI vulnerabilities and threats.
So almost all, again, thinking about storage, people are gonna think about how to protect storage with access controls and our back, but those aren't gonna help you if someone has updated every GitHub repository out there to spoil the training data. You know, it's not just access controls for security. And I'm worried that we're going out and building AI infrastructure and AI storage without thinking about how our security needs have changed because of that.
Right. It's funny, this isn't security field day, but the theme that possible around every trend I ot, public cloud AI is, oh, we forgot about to build security into this, and now we need to backpedal mm-hmm. Yeah.
Figure out how to shoehorn it in instead of developing it to be more secure from the ground up. And MCP is just the late latest example of that. When are we gonna learn as an industry, I guess is the ultimate question.
I Mean, we should be thinking about security upfront. Yeah. Somebody else's problem.
I'm developing the product, somebody else needs to figure out how to secure it. Right? Yeah.
Well, also, okay, also considering a lot of these developers are now using AI tools, and now they've shown like 235% more, you know, security errors in the code that AI is producing, you must wonder if, uh, whose side they're on because They've been trained on public repositories. Mm-hmm. And most really good work database designs coding are usually not public repositories.
So the training data is severely biased towards much more informal practices. Mm-hmm. I'll say, yeah.
If it's, if it's been trained on the code that I've written Exactly, it would be terrible. Code Got help solved. And, and it probably is, since I have repost sitting up and publicly on GitHub, uh, I think in, in terms of that social engineering of the ai, it's important to, to remember that a AI typically understands the association between everything, but has no understanding of the meaning of the thing.
And so it can't apply judgment. You've gotta put external judgment, the external guardrails, you've gotta wrap security around it. And this is why when one of the vendors I talked to recently, I don't think it was somebody who was here this week, uh, I was saying, do you have a an an API gateway that sits in front of your LLM engine?
Um, they said, no, we just got MCP. I said, uh, yeah, yeah. Um, that's, that's not enough.
You shouldn't be putting this stuff all out Public Feel like oxide was the closest thing to a real cloud that we saw as far as a private cloud goes. I like a public cloud, like a public cloud, clean a sheet that I saw, um, that the other vendors are kind of like, they're just cobbling together things a little bit and it doesn't necessarily feel like a cloud. Well, that's the, those are the two approaches, aren't they?
Yeah. There's the single source and the, there's the best breed enablement. Yeah.
And so oxides the single source, um, yeah. And they, they, they're, they're really saying, there's a line we're not going past, but below that line, it's a hundred percent oxide. Yeah.
Super simple, super expensive, bing, bang, boom. You know? But, uh, uh, for the most part, what we were seeing in terms of unification was we connect everybody and can connect everybody, and we are partnering or planning to partner with everybody, and you can bring it all together at this level, whatever the, whatever spot layer they chose.
So To, you know, hear, hear that, I mean, it's really clean. It's because it's a sweep the floor strategy. Yeah.
Mm-hmm. Right? And sweep the floor strategies.
Yeah. You, you're starting, you, you had an opportunity to start all over again and build it up. But the reality of these enterprises, that's not gonna happen.
We have legacy systems that have been there that nobody wants to touch, because if you touch the things, they go bump in the night and everybody goes screaming and everything and all that other stuff. So there's a piece of this to say, how do you move forward and bring simplification to this very complex environment that continues to speed up, you know, constantly. Um, and I think that's, you know, what you're seeing that HPE is doing.
And also as when we look at control planes for the data side, that's, you know, like what Pure is doing and others are doing, that's what the control planes are all about, is how do I simplify in envi environments that are there today? Um, I mean, I, I know, I think we're all jazzed about the oxide stuff, things because the concept of like, wow, that's really cool stuff. You know, it's, it's hardware.
I know somebody said that's not even interesting, but it's still hard. It's very hard. It's really cool.
It is very interesting. And the hardware is very interesting. The oxide provides, definitely provides hardware value.
Yeah. As well as software value. When you look at the other vendors that we're talking about, the real value that they're providing is in how you're managing the infrastructure, the control plane.
Mm-hmm. Right? Not the computer data plane.
The value that they're really providing.