Chainguard News: Libraries, VMs and Datadog Partnership with Julian Dunn
At its inaugural Assemble event, Chainguard announced several exciting products and partnerships that, together, demonstrate how the company is rethinking secure software development from the ground up, helping organizations create safer code from scratch, reduce critical vulnerabilities, and give back crucial time to engineers.
Transcript
Hey everyone. Welcome back here to Techstrong tv. You know, I'm really happy to have our next guest on here.
He hasn't been on Techstrong tv. We were talking nine, 10 years perhaps. com, March of 2014 was our first publication.
And, uh, those first two years, I mean, when you talk DevOps, it was all chef and Puppet, maybe a little Bil and Jenkins. And, and Julian was a key, key person at Chef, and he'd always come on and keep us informed of what was happening there. I want to introduce you to Julian Dunn, senior Director, product Management at Chain Guard.
Julian, it's a pleasure to see you. Yeah, it's great to see you too, Alan. It's been a while.
Well, you haven't changed a bit, Gotten a little older. Just a little inside joke. We were talking off camera.
So Julian, I mentioned you were at Chef, but you know, for people who are familiar with Julian Dunn's, uh, life story here, give us a sense of your journey. Yeah, well, uh, as you say, Alan, we got to know each other at Chef. And, you know, prior to that I was a DevOps engineer and a software developer.
Um, but I moved into product management at Chef, and then I took a little bit of a detour too, uh, at Chef. And then from there I went to PagerDuty and did some product marketing for them, uh, for a couple of years. Helped to take them IPO and PagerDuty felt also a great company.
Also very, very adjacent to the DevOps, uh, category. Sure. Uh, then I had an incredible opportunity to move to GitHub and help them to, uh, scale the GitHub actions product.
And I was there for about two and a half years. And as you folks know, in the DevOps community, you know, GitHub actions is, and nowadays it's sort of your predominant CICD, uh, platform, a lot of developers use for that and for, uh, automation. And then I had the opportunity to come here to Chain Guard, which is a little bit different, but it's still adjacent to DevOps.
Um, but, you know, chain Guard is in the, the cybersecurity space. And if you're not familiar with Chain Guard, uh, chain Guard basically is the safe source for open source. Um, we make, uh, well, our first product was, uh, container images that were, uh, loaded, zero vulnerabilities.
'cause you know, a lot of the containers that you actually download out there have hundreds of vulnerabilities on day one, the ones that you get off the internet. And we thought, how can we actually fix this? This is actually not a good way, um, for developers to start building things.
Um, and so it actually turned out to be really hard, but I love hard problems. Uh, and so I, I wanted to join a company that was solving those hard problems and bringing real value, uh, to, to developers and DevOps engineers and, and platform engineers. And that's change our data if you're not familiar with us.
Absolutely. You know, I, I became aware of chain guard, I'm going to say four or five years ago maybe. 'cause it really, you know, I I as Cube Con, so four or five years were coming, you know, towards the end of covid, let's call it.
And, um, you know, all of a sudden this company was like secretariat coming around the, the, the, the curve there for the Belmont Stakes. It started coming on strong. Everybody was talking about it in, in at CubeCon and, and, and, you know, a lot of cloud native, uh, events.
And so, you know, part of what my job here is, is, hey, you gotta be aware of these things. And it's a great story. Of course, you guys, I think announced, was it, was it CubeCon, uh, Europe in London, a a a a huge round?
Or was it maybe subsequent to that you guys recently had a large fundraising round announced as well, right? We did. We, we raised a series D and that was just announced recently.
Um, and that's hot on the guilds of the Series C that we raised last year. Yep. So things are really happening there.
Um, actually we're here today 'cause you got a bunch of news you're gonna share with us, Julian. That's right. I do.
We had our inaugural conference, uh, chain Guard Assemble, and that was a couple months ago. Um, and as I, as I mentioned, when I first joined the company, we had one product and that was chain guard containers. Um, but we, you know, what it takes to, like I said, the problems that is really, really hard to go and solve to make those zero vulnerability zero CBE containers means that we had to build a whole set of automation, what we call a factory under the hood that continuously monitors a lot of different open source projects out there, figures out which ones need to be rebuilt, rebuilt all the ones on top of it that depend on that one, and basically ship those containers to customers very, very quickly within the, you know, within seven days.
There's a critical security vulnerability that's, that's, um, that's found. And then one of the things that, or several of the things that our customers said to us is they started adopting these containers was, well, now that you have this automation, is there anything else you could apply this to? Look, we have a set of problems over in our, you know, application libraries.
These are, for example, in the Java ecosystem. These would be your jars, um, that, that are used as, as dependencies for your Java software or in the Python world. These are your wheels that you use under your Python code.
Is there anything you folks can do to build a product around this? And we looked into it and said, yes, we could, we can use that automation in the factory to, to move up the stack towards developers and help developers be able to reduce, um, security vulnerabilities. Um, now, uh, in the libraries world, the vulnerabilities happen in a different sort of layer, which is at the build and distribution points of libraries.
You go back in the history, you sort of like look at the history of where attacks are coming out. And by the way, you know, you just, you can just pay attention to the news every week. Alan, I'm sure you touch on this too, but just like every week it seems like there's a security vulnerability in this area.
Library isn't nine times outta 10 or more frequently and spokes that are trying to attack Maven Central pi, PI N-P-M-J-S, these distribution points. Or they're trying to attack my old stopping ground, the GitHub action and try to compromise that workflow so that malicious content is being uploaded to those distribution points. That's a lot easier for attackers to go after than to actually break into GitHub itself, that source code.
Uh, because you know, these, those those platforms, the, the phis and the Mavens of the world or Maven Centrals of the world are set up for kind of like the creator economy makes it really easy for folks to, to share and to upload new content there, right? So you get typo squatting attacks and things like this. So what we're doing in change our libraries is, hey, if the source code is what's hardest to break into, why don't we go back and try to find the source coordinates for all the top the popular libraries going back a few years and try to build those from source in the same factory that we have for container images and then offer those in a secure offering to our folks, to our customers.
And we've gotten a lot of, um, a lot of interest from enterprises, fortune 500 companies, you know, folks are looking at this and being like, my, the risk surface here is, is too high for me. I really love that solution, um, of, of, of Chino libraries. And then the other announcement that we made, Alan was also, you know, folks saying, Hey, you know, I still have a lot of virtual machines in my estate and the predominant use case for virtual machines vis-a-vis chain guard is, well, containers have to run somewhere.
They're just not uploaded magic to the cloud. They're still executing on some, some machine more often than not, that's some kind of virtual machine or what you might call a container host up there, right? It runs container D and a bunch of other services and things like that.
And we thought, what would it take for us to extend what we already kind of know is chain guard os, if you will, and extend it to be able to, to, to meet a, a virtual machine use case. So what would that take? It would require us to build a kernel.
It would require us to build system D and a few other services and container D and these cloud agents and things like this all from source and then ship, ship customers. That virtual machine image that they can plug directly into either a hosted, um, Kubernetes service like an ela, uh, EKS and Amazon Elastic Kubernetes service, or maybe in their own Kubernetes clusters where they're bringing their own container host. So we announced that as well at at chain guard assembly.
You kind of think of that as almost like going the opposite direction in this pyramid, in the stack, right? Of going down the stack more towards the bare metal. So we, we think we we're trying to protect the supply chain software supply chain at all levels of the stack.
Um, and so we think, you know, with this, with, with these two announcements, it's a robust platform that we now have to go and do that for customers. So before we go into maybe more announcements, let's, let's hit these two in terms of libraries. You know, I, I recently, I was at RSA conference, I don't even remember, was it two weeks ago or a week?
It was two Ago. I was there. Two hours, yeah, two weeks.
Yeah. Where are you at? You shouldn't come by and say hello.
We, we did our DevSecOps thing that we always do 10 year, 10th year anniversary of it on Monday at, at the Moscone Center, and then I was at, uh, broadcast alley all week, but I was talking to the folks from Sona Type, you talked about Maven and everything, you know, they've come out now I call it a firewall that sits in front of the repos. And so when you are downloading from the libraries components or what have you, it's actually checking, is it really the what you think it is? Is it compromised?
Is it, is it an old version or a new version? And there are some people who for whatever reason need to use an old version, but you gotta be aware of, you know, the, the exposure there. And to me, this, this was Julian, this makes so much sense, right?
I I had almost put the onus on every repo library kind of source that, hey, you, you have a duty to put a border control, right? Border controls are a big thing in this world today. God knows, I don't want to go there, but, you know, we should have them at repos certainly and, and be doing something about that.
How does libraries play into that at chain guard? And then we'll come back to the vm. Yeah, I think, you know, one of the thing things is that, you know, those types of firewalls are useful in, in some ways for signaling to folks.
What are the risk levels, you know, using sort of heuristic analysis. Yeah. As you pointed out, there's some type of few other products out there as well.
They're sort of trying to grade things or whatever and use heuristic or sometimes even AI or ML analysis of, of projects and things like that, you know, they are helpful to a certain extent. Um, what I would say is that, you know, there's a, just the flood of how the, the volume of how libraries versions change. New things are published all the time.
Sometimes things become malicious over time. It's not like the library itself that that author was, was doing anything malicious, but somebody, some, sometimes a nation state actor is realizing the popularity of some library and then without that author even knowing is going and doing and, and kind of perverting it and changing that library and creating new versions that don't exist and uploading them to these repository systems, right? Um, so the firewall is one line of defense against that.
But another line of defense is let's just go back to that source code again and, and just build it directly from the source code and what the intent of that actual author was. And then you can avoid some of these attacks. You can avoid these mystery versions that don't exist out there that that author never created, because you're never consulting a system in which they publish, right?
You're, you're, you're, you're sort of bypassing that, however libraries does plug into these systems that, you know, for, for grading, for, for rating, because we have all the build information and the provenance and things like that of what we've done and our build system that can be helpful for folks, you know, using these types of, um, policy and curation as well. Absolutely. Let's talk VMs now a second.
Look, it's no secret, right? Broadcom tripled the price of the licensing on some, uh, VMware and right, wrong or indifferent. It's given people pause to evaluate, do I wanna stay OnPrem running my own VMware?
Do I wanna finally make a move to a cloud, maybe use their virtual machines? Do I just run or wanna run cou you know, a Kubernetes kind of on bare metal system, if you will? Yeah.
Um, or, or some combination thereof. Is that driving any of this chain guard VM That is not primarily, I mean we're, I'm aware obviously of that macro environment, and I think it's helpful as folks move to the cloud. Uh, it's helpful to, to products that are targeting VM workloads.
It's not really, uh, what, what drove this move? This move, again, I would say was driven by customers saying, look, I still have all these problems with trying to patch my, you know, virtual machine environments. I have, uh, perhaps compliance regulations in my virtual machine environments.
You know, I, I don't necessarily have, if I try to solve these problems, sometimes I don't have portable solutions across clouds. Most customers are multi-cloud today. I mean, sure they have a predominant cloud in most cases.
They have an incumbent cloud, but many of them are running specialized workloads in other clouds. They're looking kind of for one vendor that can help them to maintain virtual machines with very low or zero vulnerabilities, but can also keep current with the necessary software as they're doing virtual machine workload. So this is like the kernel and the container d and all these sorts of things.
Um, so that was the main motivation to try to get into, to get into this market. Right. All right.
So Julia, we covered some announcements that your recent, uh, as you mentioned, first ever user event like that. Bring us up to the minute. What else, what else you got for us?
Yeah, we're announcing this is really exciting, Alan, today. So, uh, as I mentioned at Assemble, we announced sh guard libraries just for the Java ecosystem, and today we're announcing sh guard libraries for the Python ecosystem. Very similar value proposition.
Same thing. We're building Python code from source, which looks a lot different than Java. It's an interpreted language.
So what does that mean? Mm-hmm. The building is slightly different, right?
It's more like packaging stuff into these wheels that, that get installed by pip. Um, but we, what we found in the service of doing this, we found there's also some, and we'll be published in some more blog posts about some of this material in the coming weeks. One of the things we found, um, in the Python world, uh, with libraries is there's a lot of, uh, folks out there that don't realize there's a lot of, uh, C code and things like this that's actually bundled into Python.
And a lot of that C code is untraceable. Nobody knows what the source of that is. Or cus or a lot of folks are building and uploading these things to the pi pies of the world are bundling a lot of, uh, just sort of like, uh, you know, vendor libraries, what we call right shared objects and putting them in their, their libraries.
And that stuff is untraced and you don't necessarily know what the code path of some of that stuff is and whether or not the, the Python code is actually calling into for that stuff. And so, you know, by building everything from source, including these sort of like embedded shared objects or the C code, we are providing full traceability over the Python code that's running in your world, including any of these what we call native libraries. So I think this is a really exciting, um, announcement for us.
As you, as you know, Alan Python obviously is used predominantly in the AI world. You know, I, I have a personal fear that a lot of folks are kind of rushing to market would AI products and sort of like security is an after fun. No, you think so?
Yeah. Well, you know, the way, but the way to fix this a is for folks to just start left, right? You have to make it easy for folks to start on something good.
If you try to add security later on after the horse has already left the barn, it's pretty hard to go and do that. Right? That's why scanning alone doesn't solve your problems.
And so it's really important for us to bring an offering like this to market, to get folks to start good so that down the road when they're worrying about these things, right, they're secured, they're already on something that's good, right? It's zero friction how we've kind of like made these libraries work zero friction to developers and doesn't change the developer workflow at all. We're providing just higher quality substitute libraries for developers to use that are built in our hardened factory environment and they don't notice a thing when they go and adopt this product.
It is important, you know, and unfortunately Julian, it's an old story with security mm-hmm. Always sort of bolted on after the fact instead of built in from the get go. Um, but, you know, but things psy and things do change and, and this is a great way of, of getting ahead of it because I've never met a developer who says, you know, I'd really like to develop some low quality code.
Exactly. They all, they all wanna develop quality and have security. It's just a question of the friction, as you mentioned.
Yep. What else you got got for us? Um, well we also have a couple other features that we announced that, uh, chain Guard assembled.
They're related to the container. Um, the container product that I didn't mention, you know, one of which is again, these are all based on sort of customer requests and demand. You know, one of them is customers ask us in the container world, um, is there more that you can do to help us to customize the images that you're giving to us?
You know, and, and sort of, uh, it started with the, I would say the bulk of the request from customers are very much around, Hey, I already purchased a couple of images from you, but we're not totally microservice oriented yet, so I need to stick a couple of different images together. You know, I have a workload that's maybe like go and node js or something. Well I already own those two images the way that I can kind of compose them together.
I call it like the mix tape of images. And we said, yeah, absolutely. We can build a service for you to go and do that.
And we call that custom assembly. Um, and that's something that we have, you know, on the truck today. Customers can use it.
Um, and in the future we're gonna be expanding that to other different types of customization that, that folks are asking us to do, um, for their container images. And that just eases the burden for those platform teams who are trying to fan out, um, and, and have these images widely adopted by, by customers inside, inside the organization. And another thing that we announced at Assemble and which is really interesting, um, and it's also a function of how we're able to do this feature, um, is because we own the spectrum, we control these different components and the dependencies and, and and things like that.
There's a feature called what, uh, what we call EOL Grace period. And you know, there's a lot of companies that can't move quite as quickly, um, to upgrade everything in time for when software goes EOL and things like this. And we thought, you know, could we extend some of the, uh, coverage in terms of like low vol, lower zero vulnerabilities for some of the stuff we already built, um, to stuff that's going EOL or maybe has already gone EOL.
So we thought, hey, we can't do anything. If the main package, let's say that's engine X or something, if that goes end of life and, and that primary package accumulates some security vulnerabilities, there's not a lot we can do because that maintainer isn't moved on, decided they're not gonna maintain that anymore. But if there's vulnerability that we can fix from its dependencies under the hood, if we can manipulate the dependency tree and we can bring some of the vulnerabilities, we can eliminate the vulnerabilities that are under the hood by bumping to new versions and assuming that Topal package like N engine X still compiles, then we have successfully kept that image out of zero and zero vulnerabilities.
And so folks can continue to use that. Now of course they're still taking on the operational risk of running something that's end of life, but it just gives them an extra, extra little bump. It's what we call it a grace period for them to get to buy themselves a little time to get off that old version while still maintaining a good security posture.
I love it, Julian, for people who wanna stay up on not just chain guard technology, but all that's going on 'cause you guys certainly have a lot going on. dev? We have a blog there.
Um, and it's got product announcements, it's got engineering announcement and things like that. I did also wanna mention, you know, chain Guard does have a starter image tier. So we do provide, you know, somewhere in the neighborhood of 50 to 60 of our images, the latest versions of them.
So it's a rolling version plus that you can experience the value of chain guard and the value of the zero vulnerabilities and the S bonds and the attestations, all that for free. Um, and then if you want older versions or, uh, you know, other, other software that we don't have on the truck outside of those sixties. And the rest of that is, is a paid plan.
But there's a way for you to kind of try and experience chain guard's value, um, without having to, without having to contact contact sales. So please check that out. I love it.
People like to check stuff out without having to contact sales. You and I know that. Mm-hmm.
Julian, then it's great seeing you. Now that I know you're here, I expect to have yarn here a lot more often. I definitely try to make that happen.
Alan, it's good to see you again. All right, my friend. You be well.
Good luck. You. Sounds like you guys are running on all cylinders there, so it's all good.
Chain guard Julian Dunn, senior director of Product Manager in here on Techstrong tv. We're gonna take a break. We'll be back with more.