Priyanka Sharma and Frederick Kautz, CNCF and SPIFFE | DevOps Connect 2022
Priyanka Sharma, executive director of CNCF, and Frederick Kautz, steering committee member of SPIFFE, take the stage at DevOps Connect 2022 to discuss the success of CNCF and keys to strategically thinking about cloud native security.
Transcript
Hello everybody. I'm Priyanka Sharma and I'm the executive director of the cloud native Computing foundation and with me here today. I have my friend and contributor in the organization Frederick Katz.
Do you want to say hello Frederick? Hello. All right.
So today we're gonna be talking about Cloud native and devsecops. As I said, I'm the executive director for cncf. I also spend time with startup companies and in the past I was a board member and before that a contributor in cncf, so I've been in open source a long time.
I've spent my entire career working in technology and the most fun part of it and the most longest stretch recently has been in developer tools and products and boy, it's been a blast. Doing this work, of course, you know there is there's no avoiding it you're gonna run into security problems security people and security processes and I've been you know looking at RSA for such a long time. So it was a huge honor when Mark said we could come and speak here.
So this is a very cool experience for me. Frederick why don't you introduce yourself? Okay first can you hear me in the back?
Perfect. And some oh you go. Okay.
How about now? Perfect. Okay.
So I am Frederick couch. I am a collaborator with the cncf part of that collaboration includes being part of the speed Inspire steering committee. A lot of my time is also spent with the security technical Advisory Group.
So when we'll talk a little bit more about that soon. I'm also a co-founder of the network service mesh project which is a cncf Sandbox project and I also advise many organizations with zero trust architecture and I've written a co-authorative book with with some other people in the cncf on zero trust topics formally. I was also part of the Linux Foundation Public Health steering committee.
I did a lot of work in networking and storage and I was also very early contributor to Docker Circa early 2013. And with that I will hand it back to to Priyanka. Thank you very much sure and Frederick does all of this on top of a day job people so I was doing it but we are glad he is here.
Today, I'll share with you a brief introduction of the cloud native Computing Foundation think of it as cncf101 and then Frederick will give an intro to Cloud native security why it's important and how you too can participate. So what is cncf how many folks here have I have already familiar with the foundation raise your hand? All right majority of you.
That's great. So you probably already know that the cncf hosts critical components of the global technology infrastructure the the software that helps build the software is where we're at. We help you with resource utilization where when you're thinking about compute how will your application actually run in production and how will you observe it?
How will you manage it? That's what comes in the cloud native bucket. Our mission is to make Cloud native Computing.
Ubiquitous. We've said Cloud native many times. Was that what is it?
Really mean? Right. So let's take a very quick history lesson.
If y'all remember in the 2000s it was the era of sun Microsystems. There was non-virtualized Hardware. They did some big cool things.
with the coming of VMware virtual machines became really popular and that changed how we did infrastructure for software. Over time with AWS compute got in the hands of developers. And I think that was very revolutionary and was the beginning of the trends that we see today more and more Innovations happened and Docker as the alarm show familiar really made containers mainstream.
And based on the basis of that Foundation. The kubernetes project by Google came into the foray and did container orchestration today. It is the de facto standard for container orchestration the cloud native era formerly started when Google donated kubernetes to the Linux Foundation Under The cncf Entity and that is where The news story of software development and delivery really took off from the past of large monolithic applications.
We started we found it feasible now to break our application into pieces services and microservices that were Loosely coupled and fairly independent. With the help of containers and Docker we could containerize these specific services and then using kubernetes dynamically orchestrate those containers up and down so that we have the best resource utilization a very simplified example that I try to share with people is if you think of any Commerce application that is having a Black Friday sale the Black Friday sale area is going to get the most amount of traffic that time and you want to have the most amount of resources available there and not be disturbing the rest of the app or wasting resources on rest of the app and using Cloud native principles. You can very comfortably do that.
So that's what we mean when we say cloud native, right? and today this this wave has really taken off. We are 128 open source projects.
We are one over 158,000 contributors from around the world representing 187 countries. that Is big numbers which is cool. But there are seven point one million developers who are really part of this Cloud native ecosystem, utilizing our projects our practices and our processes.
If so, we are not only just a big ecosystem. We're very fast equal growing ecosystem. But in fact the fastest growing open source community in the world if you just look back the last year.
In May 2021. We had 96 projects six months later. We were at 114 in October.
And today we're at 128. Same and I think the most impressive stats are around the contributors a year ago 123,000. six month Mark 137,000 and today as I mentioned 158,000 Plus countries represented by the contributors.
That's what that means. Is 177 a year ago 186 six months ago and now 187. This is the one where we're starting to lag a little bit, but I think there is a ceiling of how far we can go so not much room left over there.
All these numbers are just to share the speed with which Cloud native keeps growing. Our projects which I shared are over 128 we have in three categories graduated are the most robust production ready projects out there where we have taken into consideration their security their observability and all those pieces to put our stamp of approval and tell you that hey feel free to use this project. It comes with the cncf stamp of approval is you will see here.
There's open policy agent which helps with security policies and governance. There's also a lot of observability with Prometheus and fluently and with Envoy you have that the data plan with which you can actually understand what's going on. So these projects together are critical to any one security Journey, but they themselves also go through rigorous security Audits and processes to ensure their production ready.
Incubated projects are a little bit younger and going starting to go through these processes, but are in progress. Let's say that there are some really cool security projects here such as Falco you will see so does and they're widely used so doesn't mean that they are too early. Sandbox is where all the fun Innovation happens where you have new technologies coming in people just coming together to collaborate and see what they can accomplish together.
And when you think of the project maturities the like sandboxes like the early innovators and then incubating is the somewhat early adopters at this point. I would say the pragmatists are using incubating projects and the graduated projects have been used by the late majority and conservative folks. This is just like a pair just a framework that the book Crossing the chasm created which I'm sharing here for you with you.
We built on the success of all these projects and the work done by these contributors. One of whom is standing here cncf enjoys the membership of 800 plus member companies. Six continents represented Antarctica just won't join.
We are trying our best. Every major cloud provider is a member most of them at the Platinum level and end users companies who utilize Cloud native Technologies, but don't buy and sell products and services don't sell they buy products and services are called end users and we have the largest network of any open source Foundation. Here's like a list of logos that you can see and maybe your companies are represented here.
And again, I show these primarily to demonstrate the scope of cloud native today. Why are these organizations adopting our projects? Well, Resource efficiency is essential more services less servers who doesn't want that?
Improved resiliency and availability no matter if a specific application machine or even data center Fields, you will have resiliency of your product. multi-cloud and hybrid Cloud give people choices of vendors and cloud-native projects enable that Ultimately, we're bringing higher development velocity with minimal risk. So ship fast without breaking things.
That's pretty great. And because of that the scope of cloud native keep in keeps increasing we're relevant to Edge Computing relevant to artificial intelligence security is a big part of our story and that's why I think it's essential for you to learn about. What is the cloud native security story before I hand over to Frederick just lost points.
I'll make are that we're the fastest growing open source community in the world. We have thousands and thousands of people so many projects. And we have become the scaffolding of the pandemic era.
So Frederick with that I'll hand over to you. So but before we jump in let's talk a little bit about context. We just saw that cloud native is is ubiquitous drought throughout the various Industries and part of the problem is that we cannot make the assumption that the previous generation of Technologies carry that all of the practices we take there carry over.
So there is a gap between our assumptions and the reality and the attackers use that difference between those assumptions and and what is actual in order to perform their attacks. So when we when we have a mismatch within those two, that's when we start to see various attacks that lead to loss of confidentiality such as data recent exfiltration or lack of Integrity with ransomware denial of services more forging of identity and so on and to make matters even worse many of the regulations and policies that we set up have alsified those assumptions and there is an opportunity cost. So whenever you perform a an action to secure your system that that particular action you take takes time takes resources and that that is time that you know that you could have spent perhaps securing in a different way.
So if you are trying to secure modern systems in using previous generation Approach not to say that you shouldn't in every scenario, but you have to make decisions that align towards the car is this the most effective place that I can be spending my time, like what are the economic cost of what I am doing? So what has changed the biggest change that I see within the cloud native infrastructure space is that we are moving from a static environment to a more Dynamic environment. So we used to have an environment where people would stand up a serve a server or virtual machine and it would be given an IP address.
It would be within a perimeter the and there would be very little shifting with there be very little changes within those environments outside of change Windows. There is a high and so now we have the we are starting to move away from that. We're starting to see paradigms such as zero trust come around as they responds to this to this change.
And so there's also a higher expectation of more scalability more more work to be that that we expect our systems to do and we have so this higher degree of connectivity between systems the primary driver of that, even though we have this infrastructure change, the biggest driver that is actually from the business side. So it's not the fact that we're moving more towards micro. Services that's causing that change it's literally that businesses business requirements are shifting with the expectations and the new in the new infrastructures that are coming around and they're they're changing in tandem with each other and the end result is that we end up with a heterogeneous environment because all those old systems, they don't go away they they stick around some of them we replace but they're still places that run mainframes still places that run that run virtual machines with a specific application on top of them that are still running a monolith and also Cloud native technology.
So whatever we do we have to acknowledge we have diversity there and we have to work in a heterogeneous environment the tools that we build have to work across those environments not purely only for the open source space in many scenarios. And so why have the Ascension change again? They're changed back directly to changes in the business requirements.
So the executives are starting to look at how do we increase the team's capability using Cloud native. How do we decrease cost? How do we normalize a team skill so that I can move them from Project to project and there and they're achieving that through the adoption of cloud native through through application teams, having more agility to make changes themselves as this post to having to go to some it or or infrastructure group in order to make those changes.
And we're also starting to see a common apis that work across across clouds in order to achieve that as well. And so when we started looking at how do we achieve a security security approach the top predictor of success is going to be executive buy-in. In fact, you go ask any cissp person or CSO what what their primary way to to achieve success is you have together get that executive buy it if you don't have that right now spend that time and so every every system that is ran.
We also look at it has to look at the human-oriented processes. So we don't run infrastructure or applications and in isolation, they're running within within a human oriented process. Where what is the software development life cycle?
What is it? What is the supply chain proven is where did this come from? How do I deploy this thing out all of it human context.
So with that we also want to move towards establishing technology standards. How do we move towards Mutual TLS? How do we how do we start to to give out workload identities that we can buy in again start to enforce those policies against those applic?
Nations and of course Automation and employment through Cloud native Technologies in order to in order to achieve that So now that we have this. New paradigm that is starting that is now massive and how do we start? How do we secure these like where if you're this is your if you're trying to get into this like where should you start the very first place?
I would recommend you start is with the cloud native security y paper with that. There's also the supply chains the supply chain security why paper as well? The first one is targeted primarily towardsisos and cto's but also has a lot of valuable information for people who are technical further down.
It's more it's more the supply one is more detailed. It's more aimed towards people who are who are Architects or or the various project product and program managers also highly recommend that you join the community. So there's several ways.
You can join the community. So the first one is as Priyanka showed that you have the cncf membership which gives you access to to peers and places that can help facilitate that we also have people who are experts who are working on these things that are in slack through mailing list we Have the cncf security technical advisor group. I'll go more into what they do in a few moments.
And we're always looking for contributors and on contributions of all types if all you do is you come and tell us what you are doing. That is a contribution that is useful information for us. It is a signal we can use to make to make better decisions.
If you are a document if you write documentation, or if you if you're a programmer, please come in and contribute if you are looking to deploy at system. We all also have a certain a certification out that you can use in order to in order to learn about and guide your learning and demonstrate to to your employers that that you know a little bit about or more than a little bit about securing a cloud native environment. And so in terms of a robot for security, these are the main things that we put into the cloud native security white paper.
They covers various layers of cloud native from the life cycle to the distribution storage. How do you access the network? The runtime environments talks about how do you secure each of these particular items?
We also look at security Assurance which includes things like, how do we how do you threat model that you what you should do in terms of instant response. How do you establish your security principles and stacks? We also have sections on compliance.
This is particularly important for regulated environments where you will see audits over over time. And so how do you set it up to show that you're matching the nist sp800-53 or the correct ISO standards or whatever other environment that you're that you're in so all of these topics have an entry point within the cloud native security why paper to help you come up with an overall strategy of how to secure your your environments all of this work is produced through the cloud native security tag. So the key the key responsibilities include publishing resources on this.
So why papers we have a lexicon and dictionary we have control catalogs reproducing we look at Best Practices. What are anti-patterns. We also work with the projects to create block architectures and threat models to help them perform in some scenarios or some self audits that occur in some scenarios.
We drive third-party audits in order to work out what what needs to be fixed within those environments or within those projects. By the way. If you want or have experience with running an audit, we need people who do that we're actively looking for people that is one of the easy ways to come in and contribute.
So even if you've never done it before we have people who can help you perform an audit and then from there you can then drive the next one and help someone else learn as well. So we we also identify and review projects so that through the security assessments. We also identify and review projects for the for the cncf.
So a new projects that come in will often go through this particular group to to have a review done on them. We also looked across pollinate knowledge not only within the cncf but also with other organizations as well. We also talk with various external standards.
We have people who talk to to Nest we have people talk to CSA and various other in various other groups and a lot of that is coordinated not all of it. But most of it is is ran through the security tax. So this is a high impact area that if you want to help secure or learn about security than this is one good place that you can use to to join that.
Here five minutes. Thank you very much. Cncf also provides strategic assistance.
So this is more for your Executives. So one of the problems that a lot of Engineers tend to have is that the engineers understand. Hey, this is this is cloud native.
We're going to use this to perform some action we want but sometimes it's hard to get the executive team lined up or the executive teams want to know what should I do? What should I bring into my environment so that we can move to Cloud native. So the cncf specializes in helping provide that kind of strategic that that strategic advice there's all they also Drive things to help with training with quarterly analyst reports member Summits and so on.
So if you if this is an area that is of interest to you definitely consider joining in with the cncf and tapping into some of that strategic help. So the key takeaways is that the cncf host some of the highest profile open source projects there is real work going on here. That is high impact.
And we invite you to come join us in order to make this a better space not only for you for your own company but also for for other companies and if you need the Strategic advice, there is a there is help available when you need it. So with that again where to get involved technical Advisory Group, they meet every Wednesday at 10 AM Pacific so mark that on your calendars if you're interested in joining, we also have the the certification as well. So if you're looking to operate, please come join us on the complete.
Please take the take take the certification. We also announced a new Cloud native security white paper a few weeks ago at kubecon. So the white paper that I mentioned before is literally we fully up today as of as of maybe three two or three weeks.
I think yeah. So if you if you read it before that's also an opportunity to learn more there's new information that's in there, especially around ransomware and and other similar topics. Frederick saying join us in any kid facility at that you can and one of the easiest and most fun ones is joining our Flagship conferences.
You've gone and Cloud nativecon as Mark was talking we were in Valencia Spain for it do three weeks ago at this point at times a blur and soon we'll be back at it in Detroit, Michigan, October 24th to 228 22 and 23 will be cool located events, including Cloud native security console highly highly recommend you check our conference out and consider attending it's good opportunity to learn have but also a really good opportunity to have fun and specifically Yes, specifically we highly recommend attend Cloud native security con. You can apply to speak there's a link in the slides, which I'm sure you can get July 25th is the deadline and one of the best ways to learn about Cloud native security happens there with the capture the flag that we host which is super fun. And there are Six Flags and you can like I can do a system and get there.
It's the best way to learn highly recommend you show up learn with your peers and have a great time. It's been so lovely chatting with you. Thank you so much.
But by the way, the capture the flag that we run usually most participants in the previous ones. We've ran do manage to capture a flag, even if they've never done it before. So if you have zero experience with capturing flags, that is okay because we have it's designed as a learning X as a learning process not to say not purely for for the bragging rights is all Six Flags walks away with so, thank you.
Thank you.





