Liam Randall – WebAssembly: Future of Cloud-Native Applications with WasmCloud
Attendees will understand the industry wide trends driving the development of higher order technology abstractions, understand strategies for adopting them in their own organizations and understand the impacts of distributed cloud-native architectures.
Transcript
Hi, I'm Liam Randall for Textron Cloud native days 2022 and I'm here today to talk to you about webassembly and the future of cloud native applications and wasm Cloud. A huge thanks to the Textron team for having us here today A little bit about me and why you might want to have a conversation. I'm a Serial entrepreneur that specialized in open source.
I'm currently chair of the cloud native Computing Foundation webassembly day, and I'm currently the CEO and founder of cosmonic. I've spent a ton of time building Cloud native Solutions specifically focused on the intersection of cloud native Enterprise and security. I launched the first kubernetes distribution called critical stack ages ago and sold that to Capital One where I went on to lead Innovation working on incredible platforms such as was awesome Cloud, which we're here to talk about today and Cloud custodian as well as a whole lot of other software.
You can find me online at hectoman on Twitter LinkedIn and all the social media. Feel free to reach out and collaborate or say. Hello friend me on LinkedIn all the things.
So what are we here to talk about today? I really like to help you align on what I think is the biggest opportunity in your organization. And generally when I say opportunities what I really mean is problems and throughout today, you're gonna have a lot of people talk to you about technology, but I'd really like to talk to you about your people and about the engineers in your organization and what you're spending your budget on because while a lot of money and time is spent talking about technology what people really care about is efficiency and how quickly we can together transform the lives of your customers and your communities and then deliver positive engaging experiences.
That's what everyone really expects. So we're gonna focus on the experience that your developers have and how we can help make those developers more productive and more efficient. So let's start with a question here and you can you should see a little chat window here.
I'm in the in the chat as well. And if you want to engage with me here, I'd love to have a discussion about what you Think is the most expensive part of your application lifecycle because as we've looked at this problem and as I discovered running a large organization at Capital One was that the entire development life cycle is incredibly frictionful when you think about starting with that first napkin sketch that first whiteboard image and taking that through deploying scaling operating managing and the forbidding maintaining there's friction all throughout the process. The way that we build software today, we're pulling in hundreds of dependencies and libraries into the application layer, which drives those high medium and lows in those response periods.
The way we think about delivering things like reliability the abilities of software reliability scalability repeatability. Those things are incredibly frictionful. We think about operating across AWS availability zones regions or even multiple clouds and data centers.
It's very frustrating experience and time-consuming to take something from I have an idea to I have something in production and running around the world. And in the last 20 years we've seen these Progressive platforms be developed. You know, we many of us remember bringing developers into the planning phase and The Ordering of specific equipment, you know, we would talk about ordering a server with a specific, you know Dell perk for RAID controller and running the drives and the particular configuration and as a community and as an industry is we have discovered these layers that are common across dozens or hundreds or all of our applications such as the CPU and the computer layer the networking layer the operating system layer, we've increasingly improved the lives of our developers.
We realize that we couldn't solve the problems of tomorrow with the technology of today. And so we've seen and lived through these iterations of virtualization the rise of VMware and later AWS of containerization and the rise of the large hyperscale Cloud providers and kubernetes as an idea to make a common orchestration layer across those Cloud providers But the reality is is that containers and kubernetes do not fix the applications. They've really helped to drive the last 10 years of computing the great lifting shift into the cloud if you will, but they still leave us with problems of portability of problems of security and problems of tight coupling of capabilities.
If you're running in a specific cloud provider today, your applications may not be portable outside of that cloud provider because you're using specific Services think about using RDS in AWS, for example, or dynamodb and Azure these things tend to hold us into time and the idea that containers are tightly coupled with a specific CPU as well as with Linux mean that you're you're applications aren't portable to all the places that you want to build them. Because the modern Enterprise and the modern developer are looking at both platforms that span different CPUs, but that at platforms that transcend clouds edges and even consumer devices down at the end of the spectrum and if we consider what came before kubernetes is wonderful and is clearly a part of our future solutions that we're developing and innovating should be compatible with layers like kubernetes and clouds, but they shouldn't necessarily be dependent upon them because where platforms leave off today and where we expect developers to deliver their code. There's a tremendous Gap in capabilities that lead to frustration that lead to rework that lead to time.
Time spent if we dig into this a little bit. This isn't just the technical cloud computing controls. This is all of the non-functional requirements that enterprises that organizations that security that compliance that operations all bring to bear on Modern application development.
If we think about this as a percentage of code, we have found working with many large Enterprises that non-functional requirements as a percentage of a developed code base dominate The functional requirements. If you're a bank for example, and you're building an API to calculate an interest rate, you might contribute one or two percent of code to a template that includes 98% of non-functional requirements all of the other things that you need to do. And if you're an organization, you probably recognize that what I would ask you next is I'm here in the chat.
How are you working to make developers more productive in your environment? The most common solution that I've seen people are developing and building on things like Java spring boot is to take a template and to give developers the golden image, you know, we know that they need to check large list of requirements to get things into production. So let's give them a solution where a 90% of the box is already checked and we found as we've analyzed code bases that there are some downside consequences to that if we are a large Enterprise or even an individual developer building our application, we're starting with these templates what happens is across large Enterprises if you're a large insurance company or if you're a retailer you have likely hundreds.
If not thousands of applications some of the larger customers that we're working with our building over 20,000 unique applications. And what happens is is that if you start to look at the forest instead of in the individual trees, the forest is nearly identical that AC. Thousands of applications we have code bases that are completely the same except we're managing those code bases and those applications on an application by application basis.
We it's very similar problem that we've had before we think back to managing cloud apis or managing operating systems or managing computers or managing data centers. Previously we were individually managing those layers and we're still doing that today within our applications. Generically across a huge variety of Industries as well as a huge variety of client types.
We typically see that most applications are over 95% boilerplate code that's just downloaded from the internet other GitHub repositories and then incorporated into each individual applications. Now an obvious opportunity here is to think about making common rails and platforms and that's generically not a new idea as we talked earlier about, you know, virtualization about containerization about kubernetes. We have continued to raise the bar and work from the bottoms up towards simplifying the lives of our developers with common abstractions and believe it or not the second most popular solution inside the cncf the cloud native Computing Foundation.
The home of kubernetes is actually istio. And the istio is the new entrance a new entrant and one of the things that it says is hey if we're gonna connect all these apis to a network what are the common things they would need they might need distributed tracing. They might need authentication and other services.
Let's make that a part of a common Rail and our observation with Wasim cloud and our intent and open sourcing this project in 2018 was why stop at layer 3 Why simply think about making things below this network service layer common platforms what would happen and what kind of experience could we offer our developers? If we raise that all the way we have to layer 7 and that was where the idea for wasm cloud was born. And in 2018 and the early 2019, we launched a platform.
We're originally called waxo suit, you know, we're kind of nerdy we were thinking, you know, it's like an exoskeleton for your code like some kind of super application Mac Warrior, you know with all of the you know, hot swappable things that you would need and we settled on Watson Club later and you'll see why in just a few minutes but what we enabled was a type of right once run everywhere experience and I know stop you've heard this before Java Silverlight Flash and other proprietary type Solutions and here to tell you today that this is different because we're riding on what I think is the next epic of Technology webassembly. So a round of hands or over in the chat window here who's heard of webassembly and what context have you heard it? If you have it's it might be one of the innovating players that's moving in this into the space.
When you look at people like Adobe the previous creator of flash by the way, moving in and launching all of their Creative Suite online and running things like Photoshop in the browser. This is possible due to a new standard only the fourth language for the web. That's managed by the w3c about enables this and webassembly is similar to ideas that you've heard before I'd like I mentioned Java and Silverlight and Flash but it's a little bit different the webassembly is not a plug-in that comes from a particular vendor to drive an agenda and an ecosystem.
This is a community standard coordinated by an organization called the bike could Alliance managed as a standard through the w3c that's already running on all of your common web browsers mobile devices and servers today. It's what I like to think of it and describe it as think of it as a virtual CPU that you can sort of use to virtualize an individual application when it's running inside of another app or inside of a web browser or on x86 or on arm. It's safe and secure.
Everything is sandbox. It's a compilation Target. So multiple languages like rust like c++, increasing or pretty soon like Python and many other languages can be compiled down to webassembly in which case they become portable and they can run in your browsers and on your servers.
Now what's amazing is is like a lot of other technologies that we're originally developed for the web think like JavaScript many of us have realized that there are probably bigger implications on the server side. And when we think about what's important in running in places like browsers are security and performance as well as portability and webassembly gives us this huge opportunity to enable incredible portability even within a single cloud provider. For example, if you're running in only AWS today, I'm sure you've seen the price and performance difference on this new Gravitron based CPUs that they have which are of course arm CPUs as opposed to the classic x86 the same arm standard that is available in the new max.
If you're using if you're fortunate enough to be using one of those the price to Performance ratio is disruptively amazing and webassembly enables you to take applications and not care about where you're compiling them for where is containers. Typically when you shim in a bootstrap an application into one you're compiling it for a specific CPU. In a particular Target, but beyond portability.
We also have incredible attributes around security webassembly delivers a denial by default experience that's capability driven. So when you take your application and you compile it down for webassembly, it's a reactive and sandbox, which means that you can call into it to make it run but by default it doesn't have access to anything. So Capability driven model for security is something you're already.
Familiar with you know, when you think about your iPhone or your browser tap asking you can this application give you notifications or can this application access the microphone or camera that's capability driven security and webassembly drives and raises the bar for security significantly when you're thinking about these explicit capability grants. So our view of the world is is that webassembly is already being adopted. It's the one technology that if you're in this room, if you're the type of person that comes to Cloud native day, you're already adopting and likely using webassembly.
It's the magic that powers applications such as Google Earth figma many of the applications that run on cosmonic open source was awesome Cloud applications, you know, lots of other things that are out in the community. And this is a technology that is certain to transcend. Not only the web development side, but also the cloud native side.
So when we think about how technology has evolved webassembly is wonderful because it's compatible with your significant Investments that you're already making in Cloud native, but it's also not dependent upon them. It opens up new places where you can take your code without recompiling or without changing it and then when we think about what webassembly is, not today webassembly is not that easy to use. So what are the opportunities that we saw with the standard emerging was a way to make webassembly easier to adopt for Enterprises and that's what Blossom Cloud does for you.
When we think about at a really high level what was and Cloud does is it creates an additional abstraction so that when you bring your business logic, you compile it down to a little web assembly module a wasmlet if you will and you're able to run that seamlessly across Stacks edges clouds and providers like kubernetes. What it does is it pulls all of that non-functional code out and makes it like a Lego block that you can choose to plug in now, what's powerful is is that these Lego blocks can be hot swapped between different Cloud providers. So you could easily move an application from using RDS in AWS the type of database to a type of database.
You might only find in Azure or a type of database that you might only find in gcp. So it reduces the lines of code and software as well as the maintenance and refactoring cost in building and running and maintaining your applications it targets that critical developer. Life cycle, so what it means is that you're developers are not just a little bit more productive that developers can go from sketch to scale that developers can be up to 10 times more productive when they're developing using modern tools.
Think about the incredible performance gains that you get by giving your developers things like access to an AWS account instead of waiting months for new equipment or new software services to be spun up and provisioned you get frictionless Innovation, you get the ability to fearlessly innovate in your applications. And that bar is just continuing to be raised with Technologies such as was in Cloud. Our point of view is is that your Enterprise applications should compose of 95% business logic and only five percent boilerplate code versus today's world where your applications are likely 95% business logic.
So I'd ask you over in the chat. What would you be able to accomplish for your customers? If you're developers, we're 10 times more efficient and productive than they were today.
What kind of world would you be able to unlock? What problems would you be able to solve? How can you make the lives of your customers better?
When we think about this this feels like the natural progression of tech, which is we mentioned has been driven. I'm in a Bottoms Up approach and if you're sitting in a world today where we have already abstracted away from operating systems with containers and we're abstracting away from cloud providers with kubernetes the next obvious layer and Target is these application libraries that are embedded in baked into each application and that's what we hope webassembly helps you to solve now as as a team and as a community, I'd love to introduce this webassembly is a standard and wazam cloud is actually an open source project. That's now a part of the cloud native Computing Foundation.
We donated last year because the community and the project had absolutely exploded in use and in use cases as I'll give you a high level and some of the really neat things that we've seen people like Adobe and BMW doing in our community. So when we think about what is Watson Cloud any easy way to understand it is to think of wasm cloud is very similar to what Java spring boot does for you. It's like an application template or if you think about how a software platform like react helps you to develop uis, very quickly was in cloud is to react what what react does for HTML or Watson Cloud does for webassembly what react does to HTML my apologies?
So let's talk through the stack here. So at the very bottom we have this little virtual CPU the standard this is what's running in your browsers what can run in your servers what runs on a variety of edge providers that are out there and this is a thought of as a portable CPU. It's very fast it encourage about one or two percent performance penalties, but because we're not incurring all the cost of starting up a full operating system like we do with containers the cold start time for webassembly is very very small in some cases only a milliseconds or sometimes even shorter than that webassembly is very fast, very efficient technology.
It's also very basic. It just lets you send bites in and then Bites come out. So what was Cloud does is wazam cloud is this high level framework that gives you things like a portable CQ CPU Lego block or a message queue or Eventing libraries or lots of other types of pluggable blocks that you can pull together to build your application underneath the hood.
It's designed to be incredibly scalable. It's built using the same technology. That's enabled platforms such as WhatsApp to scale the billions of users under the hood Elixir and it really helps you not only to solve the design but also the scaling opportunities that you have with your applications so developers decide and just call out high level features that they need.
As capability providers capability providers can be written and this is an open ecosystem. So like all great software was in cloud is completely pluggable. We just had Intel and BMW contribute to powerful building blocks in a tensorflow capability provider and a Microsoft Onyx capability provider.
They're both really interested in bringing machine learning to their edges and running applications that are portable to any Cloud even their own. Honest, we mentioned while some cloud is open source, you can take this wherever you'd like to go on top of this you implement your business logic. So you write your functions and we enforce the idea that your code should be stateless and reactive here.
And what that means to you is is that you can scale that code now unlimited within a single process you could scale from one to even on my local MacBook here. I can these actors are very small. I can run, you know, 10,000 of these actors.
You can also run them horizontally across multiple processes. And the neat thing is is that out of the box. There's a message bus that automatically connects all of the laws and Cloud instances in a lattice and this message but bus lets you use capabilities whether they're remote or not.
So you can do really neat application architectures, which we'll see in just a minute as we talk about some of the case studies you could for example be running while some cloud in gcp and use capab. These or databases that are in AWS you could open up a port on AWS to serve content but behind the scenes these capability providers might be running on your laptop or on some Edge device. It gives you the ability to write code and seamlessly move it across this lattice all without recompilation.
Now our community has absolutely exploded in the last year we've gone from around a dozen developers that have been working on this for a while to that Avalanche moment. We're now we have over 120 organizations that are contributing that are building and the best thing about being in the cmcf is not only the community and the camaraderie that you get from being there but it's the transparency and the assurance that because we're in the cncf that we have, you know, as a community. We have shared and common governance.
We have Open Standards, you know, we have transparency. You can look and generate these reports for yourself on who's involved in the community. And what where are they committing?
And we've seen some really cool applications. Some of which I've linked here with these QR codes. Feel free to scan these or find these online banking Santander came to kubecon recently and they did an awesome demo of doing live failovers between gcp and AWS.
How would you even do that today? You have to start thinking about layer three connections on kubernetes was on cloud makes it very easily just spin these up on different CPUs in managed kubernetes and you're connected out of the box. Adobe did a really powerful demonstration where they were able to take microservices and move them down to the user's browser.
And why was that powerful was because not only did they increase the performance and have the same quality of the application. It was good and it was fast, but they also were no longer paying for the compute. It was also cheaper they got all three in that case and then we recently had BMW do a talk at Cube Connie you I'll get that a link to the notes or drop it here in a chat where they did an awesome distributed quality assurance demonstration with the new tensorflow capabilities that they had helped to create in conjunction with Intel and running on edge devices with neat is is that they were able to develop on their MacBooks seamlessly push it to an edge device running on a Google Coral AI with a TPU and then also migrate that to their kubernetes and they're back at So regardless of what you're doing and what industry you're building for we all have these shared tenants and if the last 10 years of Technology was all about the Great Lift and shift into the cloud.
The next 10 years is all about this great build-up to the edge and frankly. It's all about. How are we building distributed software to help transform the lives of your customers.
We'd love to join you, please join our open source come out and find us on the web and we'd love to talk to you more about how you can take the common criteria that you have in every application mobile first real time available, 24/7 personalized and proactive and build distributed applications to delight and impress your customers. I've written about this about the why I think this is the biggest Trend in Computing. It's not just because that's where the data is on the edges.
There's regulatory reasons that are driving this there's data locality reasons that are driving this there is privacy and security. Never mind. See and determinism limited deliberate autonomy.
There's lots of reasons that are driving this you can read about them here in this article in the new stack that I published last year. But and in the meantime, I'd love for you to join us. We have a great live.
com where you can learn about these new technologies and go through some live training here. This is an example of a live class that you can have to learn about how to use while Some Cloud it'll provision live containers for you. Don't even need to install anything learn about this writing your browser.
com where you can learn about our coming distributed application platform for the Enterprise. I'm Liam Randall. I'll be in the chat.
I really look forward to engaging with you here on Twitter and throughout the day at Tech a strong Cloud native 2022. Thank you very much and have a great day.





