Xander Gryzwinski, Microsoft | KubeCon + CloudNativeCon Europe 2023
Microsoft’s Xander Gryzwinski discusses several updates in Kubernetes, including in-place vertical pod auto-scaling, read/write once access mode, and sidecar functionality.
Transcript
This is texturing TV. Hello and welcome back to cubecon plus Cloud nativecon Europe. We're here with Xander germanski from Microsoft talking about the latest updates in kubernetes Xander.
Welcome the show. Yeah. Thanks for having me.
So walk us through some of the highlights. I mean, it seems like we're now on a pace for updates three times a year. It seems where we're going.
What's left to be done. I mean, you're on one point two seven, right? Yeah.
It's it's interesting. I think I've heard a lot of people call this one like the first big boring release for kubernetes, which in a sense is reassuring right because like it's reached a certain level of feature stability, but there's there's still some things happening here and I think the one that I'm particularly excited about we just reach Alpha this time around which is the in place vertical pod Auto scaling. I think a lot of folks are excited about that and I know there's a lot of chatter around the sidecar functionality too and The other one that I think on the storage side that I see a lot of people interested in is the read/write Once access mode.
So restricting a storage volume, so only one POD at a time can interact with it. Those are some of the top line stuff in almost sounds like we're getting a lot more capability to kind of automate things within the platform. And is that part of the whole effort to make it simpler?
Yeah, I think it's it's that and there's the recognition that you know, I think the cross plain project has kind of embraced this the recognition that kubernetes really can be more than just a container orchestrator and like really taking advantage of the way that the control plane operates and and kind of treating it more like a full-fledged declarative Resource Management model and I think some of the new functionality that we see is is embracing that in a sense on the storage side. Are we starting to see more stateful applications early on there was this passionate debate about stateless only and you should only store Dade outside the cluster and now it seems like Hey, we're gonna run a database on the Clusters. So we've seen more of that.
Yeah. I think the functionality has come a long way on Sig storage is definitely one of the most active bodies in the project submitting new features when we're doing these releases. I do think the debate is just a spirited is that ever was but the function reality really has come a long way.
Do you think kubernetes is becoming more accessible to mere mortals? It used to be I have to be something of a software engineer to run this but it feels like as it moves into the Enterprise that you know, your traditional it administrator can now manage this in in some reasonable fashion. I hope so is is the answer to that one and it's it's it is hard to be objective about it in a sense because I've been involved with the project for so long now that it all The Primitives are and I'm used to it.
So it's kind of hard to take that like objective view on on how easy it is to get started. I hope it's getting better. And I think in the ways that it is a lot of it is owed to the Fantastic ecosystem developed by like a lot of companies that are here, you know building abstractions on top of kubernetes to make it as easy as possible to get started.
So what is the community looking forward to next? What do you guys thinking about or what's being kicked around? I think so on the release side specifically we've really been pushing forward on a lot of the newer supply chain security stuff and I operate more on the process side release.
So I I can't go into extensive detail, but the religion has been really pushing forward on getting all of our images signed and verified and making sure that we are on the bleeding edge of supply chain security practices for how we release kubernetes. one of the questions that at least I hear from folks is there was a nice separation between kubernetes and the control plane and a lot of people to add value but now there's so many people adding value that people are saying is there a need for some lower standard for management layer that's common to all these things versus having seven or eight different consoles all using different Primitives entirely. So is that something that you know, where is the new?
Where is that line of where the platform should begin and end in your mind or is that has that changed in any way? Yeah, I think. I guess I don't know if I can answer that definitively.
I think I do see a lot of people kind of. Taking advantage of that that kind of control plane layer as they build out more operators and things like that and that to me that does seem to be kind of the base layer now is like that that API server and like like I mentioned before declarative Resource Management model and yeah, I guess I I don't have a fantastic answer that I will watch the space and see what happens. What's your best advice to folks?
What have you seen people do well when they first get into kubernetes and then as they go down the journey and they start deploying fleets of clusters, you know, what's what's working for people and is it just kind of experimentation and trial and error? Is there a pattern to the madness? There's a little bit of that.
I think one of the things that I for sure see is. As people grow their platforms things like policy and security and just raw Resource Management often take a back seat in the early days and it's something to be considered further down the line but it ends up being a huge burden for people to kind of step back and address that later on when you've already got a large number of workloads running on the Clusters. So I think as far as advice goes it would be, you know, consider things like policy security and just general Resource Management from day one to ensure that like as you scale that's gonna stay sustainable.
9. Whatever they got going what's been the challenge and kind of getting people to stay current on kubernetes as they go forward seems like Bad habits are don't want to die. Yeah, it does always end up being like breaking API changes and things like that.
And I I know there's been a lot of Buzz at this event around long term supports in kubernetes kind of extending that support window. I do also think the other side of that is we will see some effort put into making the upgrade process easy. You're going forward because I know releasing three times a year it becomes untenable for a lot of people including some platforms that I've worked on in the past.
And yeah, I think not a great answer yet today, but I hope that in the future we can get to a place where that is addressed and it becomes a lot easier to get those upgrades done. How many release Cycles are you guys working on at the same time? It seems like there's already a group working on the next one and I think probably a Planning Group for the one after that.
So it seems like you at least you're working. A year out it moves pretty quickly. I think the the window that we have between when a release ends and when a new one starts.
Probably a single digit number of days at this point. And so when we were wrapping up 127, I'd say we started putting in nominations and getting the team together for 128 probably about two to three weeks before we wrapped up 127. And so they had a little bit of a buffer time to start organizing and then I expect they'll they'll kick off full steam ahead in the next couple weeks here.
And yeah, it's it rolls pretty quick at this point and it's not uncommon for something to move from 127 to 128 to 129 depending on who votes for it. And what where how everybody feels it's raining. Yeah, we pretty regularly see features roll from One release to the next sometimes a feature will stay in alpha or beta for multiple releases at a time.
Sometimes they intend to be included, you know going from alpha to Beta in a release and that gets delayed for one reason or another it things aren't really finalized until the enhancements freeze deadline which occurs three to four weeks into a release cycle So if folks wanted to get involved and kind of contribute to this project, you know, where can they engage because I think a lot of them sometimes they're intimidated. They feel like kubernetes is like yeah, it's a small Elite group of Rocket scientists Bill and software. So, you know, do you need more folks to help out and if so how we always need more folks to help out and I think you know before I got involved with the project I myself was super intimidated by it.
Like I've been an engineer in the past, but I'm a pm today. I don't really write code anymore. And so I think the one thing that I always try to communicate to people is regardless of like how technically you consider yourself there is rooming the project for contribution from people of all different backgrounds and skill sets.
So on the release side, the release team has a structured Shadow program that we run to bring in new contributors and then on the release engineering side, which is where we could really use some help at this point. We're always looking for for Folks to step up and try to provide what help we can there the best way really is to just get on the mailing lists for the various cigs and start showing up to the meetings. And you know, I think one good thing the community has going for it is that folks are really welcoming and you know, we'll take the time to help new contributors get started.
All right, folks you're hurting here. They're looking for volunteers and I know you're out there. So all you got to do is follow the directions Xander.
Thanks for being. Yeah. Thank you.
All right thing about we'll be back in a minute.





