Techstrong TV January 7, 2026
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, everyone. Welcome back here to Tech Drunk tv. You know, as we go into the new year, I couldn't think of a better way to kick it off than with my friend James Wickett.
com, like in 20 13, 20 14. Of course, uh, especially as we got into the whole DevSecOps thing, James was one of the, it was one of the early kind of prophets in the wilderness, if you will, with rugged DevOps and all of this stuff. And I always knew he was destined to have his own company, that he had that passion to go found something and build it.
And so I was thrilled when he started Drive run Security, but I, I don't wanna tell James whole story. James has to tell his story. James, welcome to Tech Drunk tv, man.
It's good to see you. Yeah, yeah. Thanks, Alan.
I, I appreciate it. It is, it's, uh, it's been a, it's been a fun journey, hasn't it? Like, you know, kind through Yes, it has the Devon DevSecOps, the DevOps era, kind of just all that stuff we've been been working on, and, and you, you've really done a great job kind of building the community, helping people understand what's, what's going on, uh, with boots on the ground, uh, in the world.
So we always appreciate, um, your, your coverage. Appreciate you, man, your Leadership there. Yeah.
Thank you. Yeah. I appreciate it.
Yeah. Talk to us. Yeah.
It's, and, uh, yeah, yeah, sure. Okay. So look, what's the big deal, right?
Everything's AI these days, right? And everybody's talking about it, uh, six ways, uh, differently. And, and, and I think like, there is, there is an issue with, uh, AI is like, we're building AI applications in all the systems and all the, uh, uh, in all, all the workflows we have in, in any enterprise, in any organization that we have today.
And the, the issue with that is that, um, we don't really know, uh, the risks that we're facing, right? Like, we're, we're taking sort of like an untrusted compute model, and we're putting that into, into our system. So, um, but, but to back up on the, on that, like, uh, Alan, I started the company because I felt like, yeah, we did the shift left thing, but like, man Shift left really never delivered anything for developers that was as tangible as I think that we wanted to, right?
Like, we saw incremental gains, but we never saw, like, you know, I, I kind of, I looked up and I, I knew like developers weren't having a good time. And I talked to my co-founder Ken, and I was like, we gotta, we gotta start something. Like, we gotta help developers have a good time with security.
And a lot of it is because we took a lot of tools as an industry, I'm just kinda using a, a stereotype here, but as an industry, we took a lot of tools, uh, that were made for like a different era, a different user, uh, and kind of for forced them on developers, uh, sort of like retrofitted that. And so, um, that, yeah, that's, that was kinda like the genesis of like why we started dry run security. 'cause we wanted it to be like, you just dry run your code and security just sort of happens for you.
And like, and, and it, and it makes it easy. Uh, I don't know if you remember when we first started, we were always talking about the security buddy. Like, you know, we mm-hmm.
We didn't have the language of agents. We didn't, you know, but even from the very beginning, we were like, yeah, we're gonna build, we're gonna build a security buddy, uh, for developers, and it's gonna be like right there helping them, helping them make this happen. Um, and so, uh, the companies, uh, we're, we're now in our, we're inter we will be in entering our third year in January, uh, kind of moved out of, out of stealth and into, uh, shipping, um, uh, products for, for customers.
And like, um, right now I think we, this, this month we'll have done 250,000 code reviews, and then this month alone, uh, for our customers. And so I remember when we were happy, we did like three in a week or 10 in a week, you know? No, no.
That, you know, it's called Scale. Been my friend. Right?
It's Good for you. Yeah. It's been growing.
Yeah. You know, you know, James, in hindsight, so I'm gonna ask you to answer this truthfully. Okay?
Yeah. In hindsight, in hindsight, it seems like dry run security, its whole mission, and the idea behind it is like tailor made right? For AI and Agentic ai.
Yeah. Were you thinking AI when you guys first started talking about this three, four years ago? No, no.
We, we launched in, um, or we, we kind of went to go fundraise in 2022. And the thing that we were working on at that point was, um, how to have better sec like security that didn't like waste everybody's time. And so we were trying to make some connection points between DAST and sast.
And the, the reality is we were really hunting for like, what's really exploitable and what's not. I mean, I know that we've had a lot of talk about reachability, but we were really on the hunt for exploitability. Um, and so that's, that's what we did our, in fact, our first six months, we, um, we built some really cool stuff, uh, that later we've more or less kind of trashed, you know, because we had people try it.
And a, it was really incredible to get people to try it. Like, I couldn't even get my friends to take the five to 10 minutes to try it. They were like, oh, yeah, yeah, sure, next week.
Okay, I'll be free next week. Right? And so, um, Always next week.
Yeah. And so we can, but at the same time, while we were building that, we were also, uh, doing a lot of experimentation with ai because we saw, even from those early days that AI would be something that could help us deliver, uh, you know, our documentation. We felt like there could be that chat buddy that could work out there, there could be some other components that we could, could put in place.
But as we experimented with more and more, uh, we really built AI from the core ground up. So right now, um, when we talk with customers, we talk about our four key agents that we ship. We ship our PR code review agent.
We ship, we ship, um, a, a custom policy agent. We have an insights agent, and then we have a, a new agent that's gonna be launching, uh, in January that we'll, we'll be talking about coming soon. Uh, and, and, uh, you know, spoiler alert, it's gonna be looking across, you know, all the code bases and kind of do some really interesting stuff for folks.
Very cool. Yeah. Very cool.
We'll, we'll, we'll be on the lookout for that. Yeah. James, before we go further for people wanna get more information on Dry Run security, what's the website?
Yeah, it's just dry run security. Um, and, and, uh, our, the, the kind of the, the guide, one of the reasons, like we were, we were talking about, um, what would be good for, I think for your audience and your listeners is like we, uh, we wrote Building Secure AI applications, which is a in-depth 40 page guide, uh, with a reference Architecture that's in depth Controls on it. Yeah.
Yeah. We, we kind of were like, we wanted to put a lot of bones on, or a lot of meat on the bones for like the OO top 10. And so like the o os top 10 for LLM applications, which is radically different from the O os top 10 for, you know, regular web applications.
Yeah. You know, before we jump into that though, James, I feel like, you know, everyone talks about AI today, as you said earlier, six ways from Sunday. It's all people talk about.
Yeah. But we we're, we're, we're really crappy on definitions. Yeah.
Do you know, so what, what is an AI application to you? Okay. Yeah.
So What define an AI application? Yeah. When, when we think of AI applications, and whenever we're talking about, uh, people using, um, l os inside of their product.
So this can be, um, small things of like, Hey, I, I'm putting a, a new chatbot inside of my, um, outside of my website to interact with, with users, and I'm providing this, uh, with that, and I'm hooking in some backend data for that. Um, it could be, uh, internal, uh, applications. It can be MCP servers.
Uh, it can be ways you're, you're leveraging, um, uh, LMS or SLMs to inside of your, your applications. And so it, we kind of think of it out broad scope, but it's a, uh, and I, and I know that, you know, you just asked me to, to define it, and I give you another kind of broad definition, but it is like anywhere in organizations where, uh, they're leveraging and putting LLMs into production for, you know, usage with either internal data or ex external, uh, facing stuff. Excellent.
Yeah. I, you know what? That's as good as any 'cause I, I think one of the problems we have in with AI these days is just agreeing on basic definitions, right?
Yeah. And, and so I think that's a good way of looking at it. Um, I think it's, uh, Alan, for, for me, it's like it, whenever you put an LLM in, you're, you're changing the risk model for your application.
Um, because, because now you've given it access. You're, you're, and, and you've given access to different data types. You've given it, um, uh, access to do, uh, some probabilistic decisioning, um, on your, on your system.
And, um, totally. Okay. I think that, I think I'm very bullish on, on that.
I think that's really great. But, uh, it does change, like what, um, what you have to look for from like a risk perspective. You know, for me, James, so this is before my time, but you've probably heard these stories too, right?
When the telephone first came out, it wasn't like person to person. Yeah. It was kind of a party line where, uh, you know, anyone could listen it.
Yeah. I think when you bring an LLM in, I mean, the good part of it's that you have access to the entire corpus of that ll m's information Scope. Yeah.
Scope, yeah. Yeah. The bad part of it is everything you give give it, it basically ingest as well if you're not careful about it.
Right. You know, unless you take precautions and, and so you're getting this information from everywhere and you know, the old saying crap in, crap out. Right?
You don't know where that information necessarily came from. Yeah. And you don't know what, what's going in there.
So, and so the, it's almost like mirror image of, of security issues around these AI applications. Right. And, and I, I assume in the guide, you, you've gotta address both of those.
That's right. Yeah. Yeah.
You can, we, uh, have some things like, uh, we, we talk about excessive agency. Uh, we talk about, uh, the different types of guardrails and policies after you put in place, uh, for that, um, we, there, there is, yeah. It's, it is, it is very different.
And like how you, how you think about what, what data it has access to is, is like, gotta be, you know, forefront, forefront of mind. And, um, I, the thing that, that's interesting to me, Alan, is like, um, we haven't, we don't have conversations where anybody's not using it, like everyone's experimenting with it to, to some degree or another. Um, and then there's, there's a bit of a, a hurry up on like, well, what kind of, what kind of controls or how do we safeguard this?
Or whatever. And, and that, that conversation, um, I think that's gonna be the, one of the main conversations we have in the, the next year, two years, uh, is, is around that, you know? So, But, but you know what, James, that's not a new conversation, conversation No.
For security, is it? Right? No, it's always, you know, you guys, hey, the train's pulled outta the station, hop on this moving train and make it better or make it secure in this case.
Yep. But, you know, but the train's already moving. And, and so, you know, we can't dig in our heels and say, Hey, go slow, or, or be careful.
No, people are going as fast as they can, it seems, because there's such pressure to AI eyes, ai, everything, you know? Yeah, yeah. Um, James, well, And, and there's that discovery of value the business needs the value.
Yeah. And so it's like, Hey, look, we, we see the a path to value through through ai. So that is a, uh, that that is gonna be a feature where security has to come alongside and, and enable that, right?
So, yeah. But here's the funny thing. Yeah.
I don't know if we've found the killer app for AI yet, Right? Yeah. Well, certainly we're, I mean, Drive run security is certainly the killer app for, Okay, there you go.
You stepped up there. That was a softball, James. Yeah.
Yeah. But, but you know, seriously, like we look at development, what you, what you said there is a hundred percent true. I've seen, I've seen, uh, studies, 90% of developers are using AI and helping them develop code, right?
90%. Yeah. 40% of those 90, almost half.
Right. Don't trust it. Don't trust it.
For sure. 65% of those 90% think it introduces instabilities into their code base, but still 90% use it. There's something almost illogical about that.
I, I mean, what's the definition of insanity, right? I I use it even though I know, I, even though I don't trust it, even though I pretty sure it, it introduces instabilities, I'm going to use it anyway. Why?
Because everyone's using it and they tell us that's what we should do it at some level. What a disconnect. Well, I, I think they, they are also seeing the value of like, being able to go faster because like, they, like some, some engineers and, and it depends on the engineer, and I think that depends on the company and certainly depends on, um, which, uh, you know, which coding assistant tools you're using and your stack there.
So I think that there, there is some, some disclaimers around all that, but yeah, I think like the, there, there are enough benefits of like how much code, uh, velocity, like we're able to see, um, you know, I can't, you know, we, we've been, uh, doing a lot of customer adding throughout the year, but like, and I mentioned we're at like 250,000 code reviews a month, right? But like, even within like a certain customer like Slice, um, like we've seen them continue to grow faster with the same or marginal amount of, uh, developers. Now, I, I don't have like a pre-baked number for you, but I wouldn't be Surprised.
One and a half for Two x or so. Yeah, Yeah. No, I've seen numbers.
Yeah. The story supposedly is we're four X-ing the amount of code regenerate four x That's crazy. Crazy.
Four x. Yeah. I don't know if we're four X-ing the security of that code.
No. Yeah. And that really is, is the crux of it, isn't it?
Yeah. Yeah. Well, and, and the, the, the real issue too is that a lot of these tools, um, from the last generation of pattern matching tools, they, um, they weren't really doing a good job before.
Um, and, and not, not to, to discredit them. They had the tool that there was, there, they had, you know, regular expressions and be able to do matching and stuff like that, right? Nor normal, normal, um, opposite of stuff.
But, um, it, they, they underperformed in, um, abilities where they had to find logic problems, uh, authorization issues, stuff that like really took like human coder viewers. And that's why we spent all the money on bug bounties through the industry. I'm talking at large here, spent all the money at bug bounties.
We spent all the money on like, uh, human coder viewers doing that. Um, I'll tell you a funny story. Alan, uh, uh, let's see, about four months ago, uh, showed up to a customer.
We ran a free, uh, free complimentary scan against their code base, and we handed them the results, um, and they said, yeah, just email it and then, and then, uh, we will, we'll meet on Monday. And so that was on a Friday. Well, on Mon on Monday, when, when he showed up, the customer was like a little bit incredulous, uh, uh, felt like he was a little bit angry with us.
Um, and we were kind of like surprised by that. And I was like, Hey, what's, what's the, what's the deal? And he's like, well, I looked through this and you found 20 real issues out of the 20, the 20 issues you reported, all 20 were real.
I filed bug tickets. I went through every single one of 'em over the weekend. And, uh, and I've been using this, I won't name it, but have you been using this other product for six years?
Six years in the same code base? They've never told me any of this. This is all like net new information for me.
And so, um, I think like we have to realize like, there's some really positive benefits we can get out of all apps, of course. And this from, We've also gotta realize that ignorance is bliss. Sometimes.
There is that. There is that, yeah. Yeah.
It's like, Hey, there is new work. But, but wouldn't you rather, I, I, I feel like, and maybe I'm too much of a purist, but I would rather know about that earlier. Um, and I wanna shift that left and then, and instead of paying the penalty of the bug bounties, the No, I, I, I do, I do think to a certain degree, ignorance is bliss when it comes to these things.
Yeah. No harm, no foul. Because, you know, and this goes to the whole, as you know, I've been in security a long time.
I think there were a lot of people, very content to be just another zebra in the herd and hope that the lion doesn't pick them on any given day. Right. And, and so Yeah, I know I got some Oh, us top 10 issues.
I know we've got some stuff, we'll get to it. Yeah. But, you know, I don't have the resources.
I don't have the know-how, I don't have this, that, or the other thing, why I could fix all these things now. And I'm not banging anyone, but it, it's almost the nature of the beast in security, right? Because we're so used to just, we do the best we can.
Yeah. Right. It's not perfect.
Yeah. And, you know, there is that mentality that I think we have to overcome. James, I want to turn back to this guide.
Yeah. Yeah. 40 pages chock full Chalk Full of, of best practices, emerging practices on building and securing your AI applications.
Yeah. If I had to say, James, what are the three biggest things people should take out of this? Or they definitely should go check this out.
Yeah. What do you think they were? Okay.
I think that, yeah, that's, uh, I think that, um, number one, we put reference architectures in there. So we put, um, we've taken a couple slices of what a, uh, AI application looks like, and then we put in like, the type of controls, uh, you can affect both at a runtime and a code level. So I think like, just getting it for the reference architectures, that's, that's really good.
And, and it's all free. You can get it on our website. If you wanna download like a portable, like a PDF or something, um, you can do that.
But, uh, it's all just like available, uh, publicly ungated on, on our website. Um, but so, so, so one, one is the reference architectures. They're incredible.
Two, we, um, we've kind of said for each of the, uh, oasp, uh, uh, areas, uh, functional areas, like something like excessive agency or prompt injection, we suggest to vendors, uh, like that you can look at both on the, on the runtime and on the, uh, on the code side, uh, to help do prevention or control or things we think that are interesting there. Um, so if you're kind of in like a, you're in a shopping kind of mood or you have a problem with this kind of thing like that, that is a real helpful, uh, guide, uh, for that it helps you isolate, uh, which ones would be good. Yes.
Dry run is in there. We're of course, like, we're, we're a vendor, but like other companies are in there as well. It's not just like a buy dry run and solve all your problems.
It's, it's far from that. Right? It's just like we're, uh, sure.
Yeah. We're one, one piece of the pie there. And then I, I, the one thing that I like, uh, the most about the guide is that we also tell stories like concrete, uh, examples, either from the news or from our own, uh, our own, uh, experience.
And so, um, one of the things that, that's a funny one for us is, uh, uh, I think it was in July, Alan, we spent, uh, maybe two grand, uh, $1,800 and about a 24 hour period for one customer who wrote one policy that went a little bit haywire, and it was running nonstop and doing that. So, um, whenever people commit code, we have our custom policies come in and they're able to look for, for problems. Um, and then they also have access to go back into the code base and find, and I'm sorry, excuse me.
They would have, they're able to go back in the code base and find, uh, other code that might be related to the problem that you've described. Well, this, uh, policy didn't have enough guardrails internally on that. And it started looking across the whole code base and trying to like, do a bunch of analysis, and it just wouldn't stop kind of pulling in GitHub.
And this is one for one of our bigger customers. And as they continue to write, uh, more code, I think they probably shipped 50 or a hundred port request during that, that day, or that, that time period. Um, our policies, uh, you know, it was just, it's just threading out and it's just like trying to, you know, look at, look at all the code and do a ton of analysis for it.
So it was basically running hot for, you know, 24, 30, 30 hours. So, so, you know, we have our own, our own internal scars. You know, we're building, uh, AI systems just like everybody else.
And so, um, you know, we're, we're a small startup, but I could imagine that happening to like a, a big, uh, you know, you know, fortune 100, fortune 50 company, and, and that being, uh, you know, a, a half a million dollar hiccup or a million dollar hiccup, right? So, um, but even for us, like, for us to spend that amount of money in, in that window is, was, uh, was crazy. But that, that's the kind of stuff is like, we're, we're trying to add in, uh, uh, we as the organ, as the, the global we, um, we're trying to add in LLMs and build AI applications in our systems, and it's just, it's gonna impact this in ways we, we didn't really see before the type matches for what we've had before, right?
It's like, yeah, we've pegged all of our CPUs, or we've blown out memory, or we've, or the connection pool's expended. Like we've, we already have that, that model of, of working in, in, uh, in, uh, our computer science lives. But yeah.
Um, yeah, this is just a new way for us to kind of see some of the same patterns, uh, arise that we've had before. So it begs the question, right? So I think back, James, the first company I started Tristar Web.
Okay. 95, 96, we, okay. We became what became a hosting, we didn't call it hosting, but eventually it would became known as web hosting.
Yeah. And, you know, I used to monitor the, so I was the overnight, you know, it was your company, you gotta, you're the chief, you know this now, right? Yeah.
You're chief cook and bottle washer. So I would go overnight and monitor things and, and those are the things I used to have to watch my CPU usage, my disc usages, the bail, you know, all of the monitoring kind of dashboard. Yeah.
You think we'll have a, an AI security dashboard? Is that something drive, run? Yeah.
Maybe has in its future? Yeah, I think we, we kind of stop at the build the build time. So we're really concerned with, uh, we do provide, uh, code level insights across like all the ways you're using, uh, ai, all the MCP, uh, uh, services or, or that you might be, uh, discovering.
Um, but yeah, I think that there is like, uh, kind of a host of like, uh, like we're seeing a rise Phoenix and some, uh, LLM uh, operations, uh, dashboards spin up. And so yeah, I think we will have more of an ai, um, ops, I, I guess, yeah, we'll have ai, ai Ops, not, not AI ops that we used to use that word, a new, a new version, A new AI ops. Yeah.
You know? Yeah. Words are hard, right?
But, but I, but I think like this ai, the, the, an AI SOC too, but the mm-hmm. But, but not just, I think a lot of the AI soc companies now are mostly concerned with like, just replacing the, the SOC function with AI function or augmenting that. But I think to your point is like we, um, we'll still need some sort of like, what are all the AI agents doing?
Right? And then, and then understanding like their, both their access and like keeping in, keep an eye on it. So, um, no, you know, I think one of the things that's helpful for me, and it's always a frame frame, is like, people ask, well, why is this so different?
I'm like, well, you have, you had developers, uh, writing code, and that's a probabilistic system. And, and, and so like a deterministic system, like a pattern matching tool just was, was always struggling to keep up. Now we have like, yep.
A probabilistic system developer using another probabilistic system, uh, ai. Mm-hmm. And, and so, um, that is not going to result in like a, a better outcome for, you know, the, the, the pattern matching approaches, right?
You actually need another, It's not like a negative number and a negative number equal a positive number. Yep. Yeah.
You actually need A-A-L-L-M based AI security system looking for that. Right. And we use internally, even we have, like our exploitability thing that I mentioned at the top is like our, uh, you know, we have a way to judge, like we use LLMs as judges of the other LLMs performances, and like, so the agents, you know, kind of will put that pressure on each other.
Very cool. Yeah. James, I'm assuming the guide is available to anyone who goes to dry run security.
They could download it. Yep, Yep, yep. Dry run security, there's a big, uh, there's, it's either under our resources tab or we have a banner.
Uh, and we'll have that banner up for, for several, uh, several weeks here. Um, and, uh, probably even through RSA, um, and can go check that out. But we'll have that.
Very cool. We'll, we're doing, you know, this year far, I say we usually do the DevSecOps thing on Monday. Uh, this year we're doing it on AI native dev or securing AI native dev.
Yeah. And we've got like Patrick and, uh, guy Ani from that community coming down to talk and stuff. It's, it's gonna be interesting.
That's great. Looking forward to it. Hopefully I'll see you there.
Okay. I'll Be there. I'll be there.
Yeah. Well, you, I count on seeing you. It's gonna be fun stuff.
I'll talk to you about it. Anyway, James, we're about outta time. I want to thank you for coming on here.
Continued success. Keep doing what you're doing, a dry run. It's, it's exciting.
For those of you watching this go to Dry Run Security, download this guide on building secure AI applications. Can't hurt James. Happy New year to you and the family, and I will, uh, speak to you soon.
Speak to you soon. Thanks Alan for having me. Alright, James Wick it, CEO co-founder Dry Run Security here, talking about their new guide on building secure AI applications.
We're gonna take a break on Textron. We'll be back. Hey, everyone.
We're back here with our day three last day coverage of, uh, our time at AWS Reinvent. Uh, this guy's no stranger to our tech strong audience. He's always either on a webinar showing him how to use Kubernetes, trying to make Kubernetes easy.
Some say that's an impossible dream. Um, or on Techstrong TV, talking Cloud native and KU with me, he's my friend Andy Suman of Fairwinds. Andy, it's great to see you.
Good To see you. Thanks for having Me. You know, for people who haven't caught you before on either tech drunk TV or any of the webinars, give 'em a little bit of your background.
Yeah, Sure. So I'm a long time infrastructure guy. I've spent, well, my entire career working in infrastructure.
I've spent the last nine years working exclusively with Kubernetes. Uh, now I'm the CTO at Fairwinds, and we help people run Kubernetes. We try to make it easy, like you said, And like I said, in some cases it could be a bit of an impossible task.
But, you know, it's, it's funny, Andy, we, you know, we're, we're sponsored by Ser, uh, you are Sudman, we're sponsored by Susa here at, it's the last day. I'm getting a little punchy. It's, uh, it's A long, Uh, you know, we're sponsored by Susa at, at at here at AWS reinvent, and we've been spending a lot of time talking to the, uh, rancher guys about multi cluster Gotcha.
Kubernetes management. I'm sure that's something that's near and dear to you. Yeah.
I mean, we manage quite a few clusters for all of our customers. We're familiar with rancher, lots of, um, lots of multi cluster stuff. I think, you know, the one question we all have to ask is, um, where's the data live, right?
Yeah. Everybody was say like, we wanna go multi-region, we wanna go multi cluster. And I say, that's great.
Where's your data gonna live? Because that's the thing that's harder to move between clusters. I, I agree with you, and especially in a world of data sovereignty and, and all of those things that you're dealing with, right?
Absolutely. But you know, what I found, and, and maybe, and I might be wrong 'cause I'm not the expert you are, but a lot of time, multi cluster Kubernetes happens quite by accident, right? You're, you are doing a Kubernetes project over here and you spin up a cluster.
I'm, we're in the same company, we just don't talk. Yeah. I spin one up over here.
Jill spins one up there, Bob and Harry over there. And before you know it, damn, we got four Kubernetes clusters we're managing, but they're all kind of standalone. But, you know, okay, now we gotta get a fishing and we want to bring 'em together.
Yep. So I, I call that like the accidental multiple Kubernetes cluster. Yeah.
We have a name for it. Uh, our sales team knows this term. It's cluster proliferation problem.
Uh, CPP. Yeah. Yeah.
So, okay. We run into a lot of folks that have that, mostly large companies, lots of teams, different business units. They end up with a vast number of clusters.
The cost gets outta control. Um, and usually when we work with those folks, we work with them to consolidate into a platform. And so their end goal is let's get down to a manageable number of clusters managed by us at Fairwinds, hopefully, um, and build a platform on top of that so that all of these developers aren't managing all of their own clusters.
And the goal is let's make it easy for them while also getting control and governance and policy in place. Um, it's a lofty goal, but, uh, it's can be very successful for folks. Absolutely.
Wow. Um, you know what, this was a good way though, of introducing what Fairwinds does. And, and that You ticked me right up.
I I did not even realizing it, but, but that is the kind of the, the bread and butter of Fairwinds, right? You've got people who have these, uh, proliferating clusters Yep. And you have people who are saying, Hey, I wanna modernize and move over, you know, from to a mo, you know, maybe I'm going from VMware and I'm, I'm moving to another virtualized environment, but I want to go cloud native.
I, you know, I want to go to a microservices architecture. Yeah, yeah. Any architecture really, but yeah, microservices one, one way.
Um, I had something I was gonna say and I lost it. It's okay. We're live, so we just gotta keep rolling.
So I'm gonna come up with something here for you then. Um, you know, I just recorded or played our shim, my shimmy says that I do every week, a little 10 minute video on LinkedIn and X. But one of the, the, the theme of this week was, Hey, man, DevOps cloud native and platform engineering are alive and well here at AWS reinvent.
And, and my thought was, you know, when I first got out here, I was just like, bowled over with all the agentic AI announcements. It seemed like all AI all the time, right? Yeah.
And, um, but in talking to people and having conversations, you know, I'm hearing, well, one of the agent AI agents, Amazon came outwards with the DevOps, they're calling it a DevOps agent. Mm-hmm. I don't know if I'd call it a DevOps agent just yet, but, but they have plans.
They have big plans for it. Yeah. But hearing a lot about DevOps, a lot about cloud native, right?
Cloud native is the choice. If you're looking for transformation modernization, you wanna move maybe from on-prem to the cloud. Not all the way you wanna do a hybrid, you want to, you know, um, cloud native has had a strong showing here at the show.
Absolutely. And, and platform engineering is no longer a fad or a niche. It's, it, I think it's taken its place alongside the other two in, Hey, this, this is how we build software.
Yeah. How we run software. Absolutely.
Absolutely. You know, I, I think at Cube Gun we talked about, we've launched a product to help people build those internal platforms, and it's entirely based on cloud native software, because we really believe that is the future of platform and where it's going. And I think we could see it from Amazon as well with the announcement of the managed AR OCD and Crow Yeah.
Act, or a CK, um, you know, they're doubling down on Cloud native as well. And so it's not going anywhere. It's here to stay.
And it will be, you know, the future of platform and DevOps engineering as we as we know it. You know, thinking back to the rancher announcement, what you just said is, is managed cloud native, the future, I mean, you guys manage for your clients, but you are also, you could come in, set 'em up and parachute back out, right? Yeah, Absolutely.
Um, now, I, I had a similar experience in the cyber. We didn't call it cyber the InfoSec space when I was there, which was after about 15 years, 10, 12 years, I realized that most organizations just weren't capable of managing their own security. It was, they didn't have the, they didn't have the budget, they didn't have the expertise.
And quite frankly, they didn't have the, the stomach for it. Uh, are we at the same place in Cloud native? I think so.
With the larger companies, that's absolutely true. You know, a lot of our customers, it's, it's one of one or two of those three things. It's either they don't have the time or the budget or the people, and I'll generally rolls back to budget or they could do it, but they don't want to because they'd rather focus on business impacting things.
And that's what we enable is, you know, let us do the things that you don't have the stomach for or don't care about, or don't have the time for, uh, and you can focus on your business. Right. Always had that philosophy of, you know, outsource what isn't your core competency.
Yeah. I learned, I also learned that the hard way, the dot coms, I had helped start a company. We wound up going public.
Uh, we were what they call an A SP application search. So there's no cloud, there's no liket, three lines of your in, ah, the catch meow internet. I remember this.
And, um, we're, we're offering hosted Lotus Notes, Oracle, PeopleSoft. And, and the lesson we learned is if it's not core and critical, those are the two things, right? Yeah.
Something could be core to your, to your DNA, in your case, Kubernetes expertise, cloud native expertise or critical. Your business can't run without it. It, you don't give up things that are core and critical.
Right. If it's core or critical, you might give it up. Right.
If it's not core or critical, you absolutely should give it up. Yeah, absolutely. Right?
Because otherwise you're just wasting money. Yeah. And I think for a lot of companies, the, the intricacies of managing a cloud native environment, managing any IT environment, if you're not an IT company, you know, it, it's hard.
But Cloud native in particular, because, you know, Kubernetes really never came with a chimey uneasy kind of button. No. No.
Batteries were never Included. No batteries. Security were never included.
There never included. No. Uh, crazy default was never included.
So what, what kind of, uh, you, you guys have a presence on the floor and everything. Yep. Yep.
What, what kind of, what are you hearing from people? You know, one of the biggest surprises to me, um, this is the first time we've had a booth at Reinvent. Mm-hmm.
Um, and, uh, in the past it's always been, you know, I always just kind of assumed that we'd get about 10, 15% of people using Kubernetes. That has changed, um, in, at this show. Oh, absolutely.
This show, it's 85, 90% of people really, you Think it's that high that I talked to, are using Kubernetes. And maybe that's 'cause they're stopping by a booth that says Kubernetes on it. Well, but, uh, go Figure.
But I'm talking to so many more people that are using Kubernetes or planning to move to it from some other container orchestration or something like that. So it's a huge number. Uh, it's, it's good to see That is that is, you know, I, so now you got me curious.
I'm gonna have to ask everyone I talk to. 85 sounds really high. Yeah.
Uh, you said confirmation bias on my part. Yeah, no, but you know, the big picture number I always am told is that about 15% of payloads on the cloud are cloud native. Mm-hmm.
Now, a lot of that is because it's legacy stuff, right? Yeah. Yeah.
I'm sure there's quite a lot still that, you know, people aren't talking about. Um, and it's also that, you know, I've said this in the past is that they're probably using Kubernetes, the company is, but what percentage of their workloads are Running are running it. That's a smaller number.
You're absolutely, that's a, that's a real distinction. Yeah. Because I think what it is is Greenfield products very well may be 85% co.
Yeah, absolutely. I think so. Brownfield, again, people may not have the stomach to do that transformation.
Right. Or the need, I mean Right. Don't break what's not, If it's not broken, don't Fix it.
Yeah. Don't fix what's not broken. Exactly.
Absolutely. Um, So this was your FI didn't realize this. This was fair One's first time exhibiting here.
Yeah. Yeah. Coming back next year Probably.
Yeah. Yeah. Worth it.
Good. Good conversations. Good customers.
Yep. Yeah. Good show for you.
All the right people are here. Yep. Really good, good conversations.
And, you know, the parties are fun too. The par, you know. Yeah.
We did a, uh, a thing at the sphere last night with you. A wizard of ours was pretty cool. That's Cool.
Yep. Um, wanted to talk to you a little bit about f forget the AWS for a second. Fair Winds.
Yeah. Anything new coming down the pike you want to share? Um, nothing that we didn't talk about at CubeCon, but I'd love to share, you know, our new product IDP Quickstart.
So we are, I talked about a little bit a minute ago, but we are putting together with AWS, um, they've built an app mod blueprints repository that helps you build a platform from open source. Uh, they did a couple of sessions on it this week, A couple of workshops. Yeah.
We're gonna be running another one with them, uh, next week, I believe. com if anybody's looking. Um, and we will show you the, the product that we're going to be building, which is get you started with a platform faster than you could probably build it yourself.
'cause the biggest problem with platforms is that people spend two, three years building a platform because it's such a complex task. And so AWS and Us together have made that much simpler, uh, kind of prepackaged it up for you, and then we can customize it to your business needs and then you can build on top of that to, to serve your developers. So, I love it.
Yeah. Anything else you want to share? No.
Alright. Come to reinvent. It's a long week.
It's fun. But, uh, it Is a long week, but I, uh, it's worth it. You you're heading home today?
Tomorrow. Tomorrow. Good for you.
Yeah, me too. Yeah. All right.
Hey, you know what? We didn't mention Fairwinds website. com.
There you go. Andy. It's always good to see you, man.
I don't know when I, well, I'm not doing you, you guys don't do Q Con in Europe, do you? Uh, we will sometimes we'll have a person there, but we won't have a booth. No, I'm actually, I'm not.
Mike ards gonna cover Q Con. You're first. It's the same week as the RSA conference.
Oh. So I'm out in San Francisco that week. Gotcha.
But we'll talk, and you guys are always on with your webinars and everything else around. We'll do something. All right.
Sounds Good. Hey, we're live, we're at AWS reinvent on day three. We still got some great content coming up for you.
Great interviews. Stay tuned. Hey guys, thanks for the throw.
We're here with Brian Longs, the CEO of adaptive Security, and they're in the whole business of training end users to recognize phishing attacks and all kinds of other good training things. And they recently picked up $81 million in additional funding from the folks at well among others, Bain and Nvidia, and the Open AI fund. But we're gonna jump into exactly what they're doing and how they're planning to do things.
Brian, welcome the show. Hey, thanks so much for having me, Mike. Good to be here.
All right. Um, some folks are kind of skeptical these days in the age of AI about what we can do to help employees recognize these types of attacks. 'cause they're getting more sophisticated.
So from your perspective, what is the state of the art these days? What can we do for employees and, and, and how can we win this thing? Yeah, so for the state of the art, um, I think it's deep take personas.
So being able, you know, ai, being able to impersonate an individual with voice and likeness, but also with open source intelligence, uh, about that person, you know, what they do, where they're located, their family members, their job, all that information so they can really, you know, easily mimic that person, uh, in order to, you know, accomplish whatever the nefarious goal is of the attacker. Um, and, you know, in terms of what we can do, you know, number one, I think we need to make the, uh, workforce aware of what this threat is capable of and how quickly it's changing. I think most people, you know, if you kind of live in the, the security bubble and you see these things over and over again, uh, you know, you, you get a little overexposed and kind of assume that everyone knows about the threat and, and understands it.
Um, but, you know, the, the average person has no idea what the capabilities are, and it's gonna take a long time for us to continue to educate them as that threat changes. So, you know, number one I think is awareness. Uh, number two is controls.
You know, most companies are still adjusting their controls for the remote work world that, uh, you know, still a lot of companies offer, um, and, uh, aren't even beginning to adjust their controls for, you know, things like artificial intelligence and DeepFakes and stuff like that. So I think number one, awareness, number two, controls. Do these new attacks that are getting more sophisticated have any tells that people should be looking for?
I mean, when you're training folks, what is it you're hoping that they can identify? Yeah, look, I, I think over the last couple years, you know, we have seen tells, but, you know, the models have gotten smarter and smarter to get rid of those tells. You know, it, it used to be things like, you know, look for the eyes or look for irregular, repetitive movements, um, you know, things like that.
But the models have gotten better at getting rid of, uh, some of those issues. Um, I, I think if it's a, a prerecorded video, um, it's, it's gotten really good at it for real time generation of video. It still has some quirks.
It's probably 85 to 90% there, but I, IE even if you're looking for those quirks, you know, I think in the next 6, 9, 12 months, those are also gonna, you know, kind of disappear. So, you know, I think number one is, you know, going back to process and controls, you know, if someone is asking you to do something that breaks the process, you really need to, uh, think twice and not do it. Um, you know, number two I think is, you know, when you're asking someone is asking you to keep something secret, uh, you know, or, or, or do something urgently again, um, th those are kind of the, the telltale signs of an attack.
Mm-hmm. Are there things that we can do with AI ourselves to recognize these AI attacks? And is that gonna be kind of a compliment to the training?
Yeah, we, we can look at, at, at Adaptive, we try to think like the attackers. So what we'll do is, number one, we will analyze the organization, uh, in order to understand where the greatest threats potentially lie in the organization based on public data that's out there. So, you know, we'll find everything that's out there on you, Mike, and, uh, across the different large language models, you know, other public sources and data.
And then number two, we'll put those into the same large language models that attackers might use. Right. And from that, we'll see, uh, what the potential ways are that, uh, someone could be, uh, attacked.
Right? And then number three, um, is we will, uh, then take steps to, you know, either, uh, run simulated attacks, um, you know, using AI in a, you know, safe and secure manner and ensuring all of the data is properly secure, um, and see if someone, you know, falls for one of those simulated attacks. And then that, um, helps us understand where the controls break down and where the organization either needs to train that individual or adjust their controls.
So even in the age of AI investments, $81 million is nothing to sneeze at. What are you guys planning on doing? What's your strategy or what's the area of focus for that investment?
Yeah, look, we've just seen such, uh, huge growth in the, uh, AI based social engineering attacks. So things like deep fakes, deep fake attacks grew by 17 x from 2023 to 2024 with over a hundred thousand attacks just last year. And this year we're seeing, you know, over half of the, uh, conversations we're having with CISOs, we, we hear that they have experienced one of these type of, you know, deep fake attacks.
We're, we're also seeing them grow a lot over new channels like voice, uh, and SMS, you know, outside of email where they may not even have monitoring and things like that. So all that has, has led us to say, man, we, we need to move faster on our side to protect organizations, and we're gonna invest, you know, that, that new capital in adding people to our, um, r and d team, so we can try to stay, uh, as, as, uh, as ahead as we possibly can. Although, you know, it's an arms race and sometimes you feel like you're ahead, sometimes you feel like you're behind, uh, but you know, you try to go as fast as you can.
How easy is it to generate the deep fake these days? I think early on people were thinking, you know, it requires a significant amount of skill, but we also see historically the rise of things like ransomware as a service. So, am I gonna see maybe, or maybe we already are deep fake as a service.
Yeah. Look, I, it's, it's so easy now. Um, you know, it can really be done by anyone from, you know, a young kid, an 8-year-old, and an 80-year-old.
I mean, it doesn't matter. Anyone can do, uh, DeepFakes now, and you don't have to be technical, you know, you can make 'em in, in just, uh, a few minutes putting some things together, um, to, to generate them. You know, we have tools in our own platform that allow, you know, people to, to run these sort of simulations, um, with just three seconds of audio and a single image.
So, you know, how you can think about that in your own life is, um, you know, Hey, is your picture out there anywhere? Do you have a LinkedIn picture? And then number two, you know, if I call your cell phone, is it gonna be your own voice on the voicemail?
If it is, then I have everything I need to make a deep fake of you. What is your sense of how proactive are organizations being about these particular threats? Or is it something that they kinda wake up to one morning when they've already been attacked and then they go, we gotta do something about this?
I mean, um, you know, I'm hopeful that maybe we're being more proactive, but historically that's not been the case. So what's happening this time around? Yeah, I mean, I, I, I think that we do see unfortunately, um, a a large growth in these types of attacks.
And as a result, you know, we, we, we do deal with folks that are coming in, um, you know, sort of to, to get their medicine. That being said, um, you know, we have seen over 500 customers, um, just this year, um, add adaptive, you know, to their, their set of protection tools because, you know, over, I think over like 80% of them have not, you know, currently had a significant incident, but, um, are, are trying to get ahead of it. So I, I do think organizations are recognizing the need to, to get ahead of this quickly.
And, uh, we're gonna continue to see that, you know, I I think unfortunately grow, uh, tremendously next year because look, the, the big factors here that, that drive this, number one, it's getting a lot cheaper to run these attacks. The models are getting significantly cheaper. And then number two, um, it's becoming much more available.
com, which is a, a leading provider of large language models, you'll find over 2 million different models that you can access now over 2 million. So there's a ton of models out there, it's really cheap to run 'em, you could even run 'em on a smartphone these days, right? It used to think, oh, I gotta get, you know, the, the newest and fastest chip and I've, it's gotta take me 10 minutes and then I'll get it.
No, a lot of these things run instantly now and they're really cheap. Mm-hmm. Um, so what ultimately differentiates adaptive, because there's a lot of players in this training space already, but, you know, if someone comes to you and say, you know, why should we go with you guys?
What are you telling 'em? Yeah, look, I think number one, um, is on the training side, our focus on protecting organizations from these type of AI powered threats, right? So with our platform, you're gonna be able to access hundreds of different trainings that address this next generation of threats.
Number two, our trainings are extremely specialized by vertical, by role, and by organization. So you can change anything that you want, uh, within our, within our trainings instantly based on your own organization's needs. Or we also have this really cool tool that allows you to create net new training content in just a couple minutes with ai.
So you can say, Hey, I wanna make a new training on, you know, deep fakes for hospitals in this region, you know, for nurses, um, that's three minutes long. And it, you know, and then just a couple minutes later, it'll make a training with all of the custom generated images and videos and animations and audio narration all specific to that audience. So it just makes it very, very tailored, uh, to the individual organization.
And then number two, we also offer phishing that utilizes these next generation channels. So we do real time deep fake phone call phishing, um, into help desks into individuals, uh, into voicemails. We also can do SMS based, uh, phishing simulations that will drive two to three x higher failure rates than, uh, email.
And then we also do generative AI email simulations where it uses more personalized conversational messaging within the email, um, to, you know, sort of test the, their organizations wherewithal that that can often get around traditional email security vendors. Yeah. So what's that one thing you see people encountering over and over again that just makes you shake your head a little bit and say, Hey folks, maybe we should be a little bit smarter about this?
Well, I mean, you know, where to begin, uh, within, within the security world, but I, I, I think probably the, uh, the, the biggest thing that I, I shake my head a little bit over is when you ask the, the, you know, a security person sometimes, and you say, okay, you know, I understand we're focused on, on an email security and you know, we, we will talk a lot about email security, but what about, you know, the realtime voice or, or SMS, they say, you know, people don't have corporate phones at our company, so we don't need to worry about that, right? Um, you know, we, you know, people bring their own devices and what they do on their devices is up to them. And that's not my job, right?
My job is just to, to secure corporate owned, uh, you know, items. And, you know, to me, I, I shake my head a little bit at that because I think, look, the, the job, and look, I think the security people at companies are heroes and, and, and are incredibly important. And, um, I, I think it's, uh, uh, a really, really, uh, important thing at the organization.
But I think that security extends beyond just corporate email, right? I think it extends to really try to protect our team in every channel that they may be, uh, encountering these types of threats. And the reality is that the attackers are surging in SMS invoice.
And just because it doesn't belong, you know, that that cell phone doesn't belong to the company. That doesn't mean our, our defenses should stop there. Folks, you heard in here, the attackers are getting not only more pernicious, but they're getting clever by the day.
And well, these deep fake things are here, whether you like it or not. Hey, Brian, thanks for being on the show. Hey, great to be here.
Thanks again, Mike. Take care. All right, and back to you guys in the studio.
Do you know where your data is? Can you make your data come together into some useful place? Is it spread all around the world?
How's your AI gonna work with things that are all around the world? Does the speed of light get in the way? What about power, cooling energy, all this and more on the Tech Field Day podcast.
Welcome To the Tech Field Day podcast. We'll bring together a group of it technical experts to discuss a single idea about key concepts in the industry. This podcast features a variety of perspectives from members of the Tech Field Day delegate community.
It's often a recorded association with one of our events, of course, tech Field Day, part of the future and Group. And this podcast is also published on our sister company Site Techstrong tv. On this special episode with, uh, hammer Space, we'll be discussing how modern data mobility is challenging the laws of physics.
But before we have the discussion, it's meet who's gonna be on our massive panel today. Hi, Kurt Kine. I am the Senior Director of AI marketing here at Hammer Space, and I'm super happy to be joining today And I'll go next.
My name is Jim Jones. I'm the senior product Architect at 1111 Systems. Jack Poller, founder and principal analyst for Paradigm Technica.
And I'm Andy Banta, storage janitor. And I'm Alistair Cook, of course, the event lead here at Tech Field Day. And nice to get the band back together again, because the last time the five of us were together was at AI Infrastructure Field day three.
And what we've seen is that getting data in the right place is absolutely vital for building your AI applications, your AI infrastructure. Getting business value out of that data is very much dependent on getting the right data in the right places. And yet we have this fundamental law of physics.
It's the speed of light. You can't move anything, particularly data faster than 300,000 meters per second. Um, I'm remembering the speed of light, right?
Uh, it's been a long time since I've needed to use it. Uh, yeah. When we've got this data being generated all around the world by large organizations, we need lots of it in the same place, or at least access to it from the same place to build out our large applications.
And I think it's one of the challenges is that the speed of light can't be fixed, but there's some technologies around that can make it less of an impact for us. And we've seen those across a few of the different technologies that we've seen for building these AI infrastructure data centers. Um, Kurt, I kind of, uh, brought this, uh, this topic because it's, it's very much the sort of thing that you're working on with customers on a regular basis.
It's indeed. Um, and, you know, figuring out how you overcome each of the variables, um, that are influencing how we're working with all of this data is definitely, um, something that we're thinking a lot about, right? The fact that power is now the most expensive thing in the data center, um, that, you know, being able to acquire accelerated computing is really tough.
Um, you know, most folks aren't even considering building out these large infrastructures on-prem because it's just far too expensive. And our data center is just far too constrained. And, uh, then add onto that, the fact that everybody has this distributed nature these days.
How do you unify everything if your own organization is out there in all sorts of regions generating data on the edge, uh, but then your compute might be located somewhere else as well in somebody's cloud. Um, and so being able to bridge that, um, and figuring out, you know, what is the representative data set so you aren't moving all of your data all the time. Um, it's, it's a big challenge for sure.
Right. And I, I think, uh, you know, you touched on the other aspect of physics that we really need to pay attention to here, where it's not just the speed of light, but it's also the density of energy necessary. Uh, one of, of the things that we talked about at AI Infrastructure Field Day was, uh, was your open flash platform, which is part of the Open compute project.
Uh, and shortly after the, uh, that field day event, I did attend the open compute project, uh, um, conference. And there were jokes around there that it should have been renamed the Open Cooling project because most of the things that were being displayed on the floor were actually had to do with cooling, uh, cooling of the compute pro, uh, the compute systems rather than actually the data itself. Uh, I did have a chance to stop by the Hammer space booth there and, uh, put my hands on one of your open flash platform, uh, trays, which was kind of interesting.
I didn't actually have a chance to go anywhere else, or I did not see any other, other open Flash platform trays while I was there. Uh, but it's, uh, I know that you guys were working with several other companies, uh, um, ex site and, uh, I don't recall who else you were working with, but, uh, it's, uh, it'd be interesting to actually see one of those in, in action at some point. Yep.
Yep. We're getting close. Um, that, uh, tray that you saw, there was actually our initial POC, um, and we've had a ton of learnings by building that, uh, right.
Things around airflow, um, things around serviceability. Um, and so we're, we are working to refine, refine that platform, refine that design with a lot of input, um, from various flash vendors, uh, from various hardware vendors, um, as well as looking at some requirements from, um, different software vendors in addition to us. So, um, it's something that we've, um, heard a lot of interest from.
And yeah, we really hope that that, um, coalesces around this design and, and, um, starts seeing some, some broader, uh, adoption. But yeah, the whole concept behind, behind that there was that there is a more efficient way, um, to just store data. Um, and part of that is just getting out of the way of the data.
Um, you know, the more layers that you put in between the data and the processing, um, is going to introduce additional latencies, uh, and additional power requirements. And so, uh, in the case of OFP, right, our goal is to just remove the storage server completely, right? We're putting, um, the infrastructure software directly on A DPU, uh, that's low power, still high, a fairly high performance, uh, and then connecting that to the flash, so, you know, a very direct connection.
Uh, and, you know, we're kind of labeling it nothing but Nick. So, um, you've got your nick, you've got your flash, you've got a direct path from your processing. Um, and, and I think that's a big, um, part of it.
Uh, that's the infrastructure part of it. Uh, and then I think just dealing with the massive data challenge is the other big rock to move. I think one of the things that makes the Open Flash project project work, uh, especially with Hammer space, is that you don't actually need to have any data surfaces on the plates or on the chassis themselves, on the trays themselves, because you're actually taking, taking care of the data services through the Hammer space data services, Right?
Yeah. We've got a centralized, what we call our anvil server, um, and that's the thing that does all the metadata operations, um, and is outside of the data path, um, and allows us to utilize, yeah, open standard Linux, uh, and NFS, uh, on those, uh, systems to be able to handle the, the data transactions. I think Andy, one, one of the things is that we love playing with hardware and, you know, hardware's cool, and we're all geeks, and that's all good.
But thinking about sort of the problem at a higher level, one of the things we've learned over the course of the, the AI infrastructure field day, not field day three, field day two field day one, is that the, arguably the most expensive component other than the power plant itself is the GPUs. And the big problem is the GPUs right now, while being hard to obtain, they're also sitting idle 70% of the time, right? And that's because they can't get the data.
I think we focus on we being not only us here in the podcast, but we as an industry like to focus on the hardware and throwing hardware solutions at it. And what if we tweak this component and make this component faster? And we've heard from how do you make the ethernet faster and how do you make the switches faster, and how do you make this, and how do you make that faster?
But the architectural problem is how do I have terabytes or petabytes or multi petabytes of data? How do I get that from where it lives into the training environment, and then get it, then feed that into the G-P-D-P-U environment. And I think that's the, the sort of the physics problem that we're sort of wandering around, talking around, but not talking about is we have, how do you get a petabyte of data into a processing environment that can consume that almost instantly?
And then what do you do from there? I'd say it, it, it's interesting from a couple, couple different points, because you're gathering that data, you know, probably not where you're processing it initially, but from a application, you know, we're gonna spend millions of dollars to create a model, or we're gonna spend, you know, probably millions of dollars, even if we're not doing, you know, quote unquote AI creating a model, et cetera, et cetera, et cetera. We're just gathering it.
It costs lots of money to develop those applications regardless of what they are. And every time we have to change those to allow for data migration, data movement, whatever it is, or, or data expansion, we have to, you know, that incurs costs that include incurs downtime or, you know, maybe from the, you know, PHY physics of the, how fast can I get this capability out to the market or to my consumer? It slows things down.
And that's where I was really impressed with what Hammer space was doing with the unified namespace, was it lets me hide any number of sins, if you will, underneath the covers. You know, I may, I may have a NAS floating over here, or I may have an object storage in 17 different platforms, but as far as my developers, as far as my consumers are concerned, that's one, that's one endpoint, that's one set of credentials and things just work. And that's, you know, where that gets important.
Um, you know, in my day job, I'm dealing with customers that are wanting to move from point A to point B, um, to chase cost the physical as the physics, as in the, how much does it cost physical, uh, side of things every day. And it's incredibly painful to do that, um, one because it costs money to move the data, but more importantly, your application has to be able to support that kind of thing. Um, and so I, I really love that kind of capability to, to further us as technologists to be able to not have to worry about, well, where is my data that may well be at the edge where I've gathered it or maybe my data center or maybe somewhere else and not have to care about it.
Well, I think that's, uh, fundamentally been a big part of what's been missing from the conversation, uh, in ai, right? Is, um, mainly because the industry has been focused on these really, really large developments, right? This initial training of these massive l lms and, you know, everybody's been focused on just that interface between the storage and the processors, and how do I get enough data into the processors, um, from the storage system.
So peak storage performance, right, has been a lot of the conversation, um, and, you know, has served that side of AI very, very well. Um, you know, and we see parallel file systems and really specialized systems, um, being developed for that. Um, but for the other 98% of people who want to do something with ai, we haven't talked about, okay, how do I get my arms around my organization's data?
What do I have? And then once I realized that it's yeah, out there on 50 different silos, how do I then identify our representative data set and make sure that's what we're moving rather than, oh, the way I solve my silo problem is by implementing a new silo and migrating all my data into that new silo, which is gonna take forever, is not going to really help you identify for on an ongoing basis, oh, these are the key pieces of information I need to ingest into my representative data set, and then process against that, whether that's on premises computing or somewhere in the cloud, right? We need to reduce the data problem in the first place to be able to take advantage of all these things.
That's, that's one of the, the other things that was talked about at that AI field day was the, the tier zero concept that you, uh, you've put together where you take advantage of the NVME drives are actually on the GPU servers and use that as, uh, a very local tier where you can migrate the data into and have, have very fast access to it, uh, and just have it presented out of each one of the GPU servers as an NFS store that's shared, shared and consumed by Hammer space. And, you know, it's, um, what, uh, you know, Molly kind of early on and talked, talked about, um, how the name Hammer space came up, which is, uh, the, the space outside of frame and the cartoons where the, where people reach off and they, uh, you know, find something that's off frame and, and make use of it. One of the things that I really liked about the, this most recent presentation by Hammer space is that you kind of did talk about, uh, where you're breaching off frame to grab the various different things where you, you talked about the Tier zero and whatever, uh, interesting concept.
And it also was a, um, it, it was also an interesting way of talking about how to get the speed, the, getting back to the speed of flight issue that we were talking about, how to get the speed you need to feed the GPUs that Jack was meshing, where, you know, GPUs are always hungry, you always need to feed them. Yeah, I think, um, you know, there are a few, um, key things that we're addressing with Tier zero. Um, and it's not just right providing high performance, um, access to the, the local GPUs with that and VME, but, um, there's some other market realities that are developing, uh, that make this very, very interesting, right?
If you're, um, actually purchasing right on premises, GPU computing, you've got these NVME devices that are coming with it and are inside of those servers, um, and we're seeing or beginning to see a really, really constrained flash market where, you know, the hyperscalers and really large, um, organizations have really cornered the market on available flash. Um, and so if you are struggling to find that flash within your environment to be able to create a high performance tier, well, hey, we can help you reclaim that flash that you already have on premises in those GPU servers. Um, another, um, advantage is, um, you know, some of the hyperscalers have really, um, adopted high performance networks for their AI computing.
Others are still using, you know, standard enterprise networking, um, with, you know, abstraction layers between the storage, um, and that AI computing and what we're able to do with folks like, um, Oracle and, um, Microsoft is actually place the data within the servers. So you as a customer to those clouds know that you're getting the maximum performance, um, out of those systems rather than having your, you know, data sitting in a blob somewhere and hoping it's getting into that GPU system fast enough. Yeah.
Growing on my VM world or my VMware background, it's kind of like what vsan was 15, 20 years ago, or 10, 15 years ago, uh, where you're making use of local storage because it's there. Yep. And we don't love the virtualization word.
We aren't storage virtualization. That's not what we're doing. Um, but VMware analogy is very, very close.
The, the, the funny thing is, you know, the, the trite saying is actually true, which is everything will, is new again, right? And it's, this is not new stuff. As Andy mentioned, we've been reclaiming local storage for a long time.
Uh, databases used to have database administrators who sold job. It was to, uh, place your data in the most advantageous spot for speed of access or speed of update. And, you know, local tiering and caching was something that, uh, 40 years ago, uh, I visited a Ford plant where they used A CDC cyber nine 60 supercomputer as the local cache for a cray supercomputer, because that was the only thing that could feed the cray quickly enough, right?
And, you know, and a lot of what we're talking about here is that management of data, both the physical placement of the data as well as the management of what data do you need and when do you need it in order to feed the best. You know, I think that the whole systems thinking of this is not a, a set of isolated decisions, isolated components, but it is actually a, a system that interacts together and that you've gotta get coherent across multiple pieces of infrastructure, whether it's the networking, the storage, the compute layers, but also across those multiple locations. And this is one of the challenges we've had as enterprise organizations have grown progressively, right?
Back when Jack was working with these creative supercomputers, you couldn't have 20 or 30 of them spread around the world. Now we have 20 or 30 data centers spread around the world, each of which is generating vast amounts of data that we're trying to get a coherent view of and get coherent value outta. I think one of the really vital things to think about that Kurt touched on was that generating foundation models, taking that common internet for all ingesting that, and training your foundation model is completely different to an organization that wants to fine tune a model or to use a, a rag solution to do inference, the actual workload type.
The data flows are completely different. And the messy enterprise world where we, we have one of everything, sometimes three or four of everything, uh, and we need to somehow get the intelligence out of all of these things. And as Kurt says, we don't wanna just pour all of that into a new silo and pay again for storing all of that data in the new silo that's gonna, uh, supposedly unify and show us everything.
Of course, we know that by the time we built that silo, we've got 15 other sources of data that maybe our silo can't accommodate, and now we've gotta build another silo of silos. So I, I think there's some very different sets of challenges for enterprise organizations, but as Jack says, these are not entirely new things. These are things we have seen over years and years.
Well, an AI is just the current variant of the conversation of the, this is the application that's driving this need. You know, it's as, as you were speaking, Kurt, the thought that came to my head was, we, you know, one of the things that you're trying to do is you're trying to loosely couple the loosely coupled things. You know, we've been talking about making our more, our applications less, you know, aware of what's going on in the infrastructure for literally decades at this point.
And as we abstract out of that, all of that is just trying to make it to where, okay, so today it's ai, the next conversation may be quantum computing or the conversation past that may be, you know, you know, something from the Jetsons as far as I know. Uh, and, and you know, the, anytime that we can abstract, you know, the, the interface from the infrastructure, we're just making our life much easier as we iterate from this thing to the next. For sure.
And I think flexibility and agility are two big driving, um, characteristics behind Hammer space. Um, because right, it's not always about bringing the data to the compute either, right? Some, sometimes it's gonna be about bringing the compute to the data, right?
So our friends at Nvidia continue to churn out different solutions that, um, you know, go all over the place. You've got 'em in the robots themselves, you've got 'em in all the, the sensors. You've got 'em in region, um, you've got 'em in your data center, and then you've got 'em in the cloud, right?
And it's horses for courses. And so, um, I think even getting back to Jack's point, right? Each of these steps has been done before, right?
Um, we've done this in cycles over and over again. Um, what we're really looking to do is, yes, we're solving it for the unstructured data challenge, right? Which is, has its own unique headaches, um, where prior right?
With, you know, maybe the structured, it's been much easier. It's been a, a smaller challenge. Um, but now we're dealing with disparate types of data.
We're, you know, the size of the data generally, um, is, is much, much bigger on an individual file level. And, um, the, the demands are constantly changing. And how we process that data, um, is constantly changing.
And so, you know, introducing agility and flexibility is key so that you aren't locked into a single architecture where it's monolithic in the data center or even monolithic in the cloud. Um, you need to be able to tune everything and do it without doing it manually. Yeah.
This, this topic actually came up at open compute, uh, OCP and at Super Compute, where the idea that, you know, what is currently being talked about is AI was simply HPC or High Performance Computing three years ago, and that was the exact space that Hammer space was playing in three years ago as well. And the, the use cases are the, the infrastructure needed is incredibly similar between HBC and ai, uh, with the, the difference being that HPC actually strives to come up with the correct answers. And AI just makes stuff up.
I think the, the four letter word you're looking for, Annie, is Hadoop, Which was all about moving compute to the storage rather than storage to compute. But that's a four letter word, and we won't go there. But it, it's, um, you know, I, your Hammer space goes in trying to address a problem that is needed in these types of compute environments, and you've, you, um, you have a variety of innovative ways to actually accomplish that, For sure.
And you know, the, the other important point being there is, you know, we are not looking to develop our own walled garden either. Um, we want to be able to give our customers choice when it comes to the different things that they do. So, um, you know, things as subtle as, you know, our, how are you embedding a Vector database into your solution?
Um, we see some people saying, be the one appliance for everything, um, that you need to do for ai, and you don't have a choice, right? Um, that's one perspective. And yeah, in many ways, that makes some of the decision and implementation simpler.
Um, at the same time, um, it locks you into their vision in their silo. Um, whereas we're looking to give you that flexibility and choice when it comes to decisions like that, as well as the decisions behind, you know, the actual infrastructure that you're using in the location that you're using it, um, and having a solution that sits in the middle that then automates the administration of all of that data movement is where we see our key value. And we're gonna have, uh, plenty more conversations around some of that key value and the problems we're trying to solve for people through ai, both through further episodes of the Tech Field Day podcast, but also at future AI infrastructure, ai, uh, field day events as well.
There. This is definitely a place that we like to have our conversations, as you can probably tell, but we don't have time for all of those conversations today. So, before we close out for today, where can people connect with you to carry on this conversation?
Maybe learn a little bit more about the things you, you've been thinking about, the things that are important to you? So I'm always available, uh, on LinkedIn. Um, you, you know, my name's Kurt Kine, K-U-C-K-E-I-N is the last name.
Um, so you can always connect with me there, um, as well as I'm, you know, always publishing stuff, uh, on our website, blogs, things like that. Do feel free to reach out through that as well. Yeah.
info or pick your social media platform up to and including LinkedIn. And I'm Kool Aid it there. com, our corporate, uh, site, as well as on LinkedIn, security Boulevard and other social media sites.
And you can find me on LinkedIn, uh, at Andy Banta, uh, on Sky, and on my, for my own content. com. And of course, I'm Alice Deko, and you can find me all over the tech field day, as well as on social media, uh, LinkedIn.
Uh, you may also find me as Deta NZ since I live here in New Zealand. So thank you for listening to this episode of the Tech Field Day podcast. If you've enjoyed our conversation, our discussion with our delegates, please subscribe on YouTube or your favorite podcast application.
So don't miss a single episode. As always, give us a rating, nice review. Tell us how wonderful we're we.
Like that this podcast was brought to you by Tech Field Day, the home of it experts from across the enterprise, and of course, a part of the Futureum Group for upcoming events and more episodes, head to tick field day com slash podcast us on tech tv, maybe even on your smart. Uh, thanks for listening, and we will see you next week. Hey, everyone, we are live here at AWS Reinvent, continuing our coverage of day one.
A lot going on a lot of ai, a lot of agentic ai. You know what? I don't hear a lot about Cloud.
AWS reinvent used to be all about cloud. Now we're talking ai, but we're gonna talk some security. One of my favorite topics, I want to introduce you two and make, I'm gonna mess up his name, but we practiced it 12 times and I still didn't get it right.
Sneel, Ben Shimo Shimo. I won almost, I wanna say Shlomo, and I keep Shimo, but he likes to be called Ben. Ben, what's, thank you for coming on to Text Drug tv.
It's great to have you on here, man. Thank You for having me. So, from the name, I'm gonna guess you, maybe you have some Israeli roots.
Yeah. But You live, you're a New Yorker, New Jersey, like me. So I guess that makes us kind of almost related, but, um, tell us about your journey.
How, how did you come here? Yeah, definitely. So, currently based in New York, almost in the past 10 years, uh, been in cybersecurity for many years, as you all know.
Uh, I'm Israeli originally, so we started the journey in the military. Uh, I'm not 8,200. You're Not 82?
No, My 1200 Is a few. Not 8,200, But actually 8,200 is quite big, yes. To the place that I used to serve.
I used to serve in more of a secret service. Okay. The Prime Minister office, which is, uh, more boutique, more unique, uh, harder to get into if you're 8,200.
Don't hate me, but we're better. Okay. Hey, he said it.
Not me, but go ahead. So, yeah, we, um, basically moved to the states after, um, managing a lot of cybersecurity, public company research division, building from scratch, really, really passionate about research, anything related to vulnerabilities, attacks, offensive security defense. And, uh, I found myself in, in New York as like one of the big companies.
I build their product, they couldn't sell their product to the ciso, and I was blown away because such a great product, we need to explain the value. And when I moved to the states, uh, I was really kind of exposed to, no matter how good product you're building, you need to be close to the customer. You need to be really close to the team, you need to close to the security executives and explain to them what's going to come next.
Mm-hmm. The thing with security is like, check, if you're playing, if you're trying to survive the next week or maybe the next year, you're probably going to fail in year two. In year three.
So when I moved to the states, one of my biggest goal was to educate them, right? And like, what's coming up next to build a strategy in the right way. I used to be a CISO as well, and managing security organization over 100 people.
Um, um, very quickly, um, after that built a startup, uh, a couple of really good friends, uh, named Cider Security very quickly. I Know them well. Sure.
Yeah. So really quickly, uh, we had a huge success. We sold it to Palo Alto Network.
Mm-hmm. Spot of Prisma Cloud. And, um, I ended up loving the cyber, uh, security and startup.
I'm like, wow. I can do, I can build, I can do whatever I want, versus enterprise. That was a little bit slower.
Yeah. So I decided to take some time off after the exit, and my co-founder, uh, who I didn't know was going to be my co-founder, called me. His name is Uri based in Boston.
And he's like, Hey, so I have something interesting for you. I got to a point. He managed vulnerability management and cloud security for Akamai from Cambridge.
And he is like, Hey, I got to zero vulnerabilities in three of the massive Akamai environment. I'm like, great. Will you accepted the risk?
Everyone can accept risk. It's like, no, no, no, no. Actually remediate it.
Actually. It's like, excuse me. Look, vulnerability management is never happened.
It never happened, never happened. Vulnerability management is a list of problems everyone have, and you just wait for, you know, s****y defense and bad things will happen, but it is what it is, right? And he's like, no, no.
I was able to do something about it. Uh, it sounds very promising. I opened a plane, went to Boston, and I spent a few days with Uwe.
And what he showed me, I was blown away because I couldn't achieve it with the best team in the world of security people for all the decade I'm in cybersecurity. And this is where I realized that vulnerability management, the dead market of vulnerability management, exposure management is, can be solved. We can actually win the vulnerability battle.
Call me skeptical, but okay, I'm listening. You got my attention. So after a long journey of speaking to over 100 good friends, CISOs and large enterprises, and also smaller one, everyone were, we're skeptical.
What we ask him is like, Hey, if we can come in and take your backlog, your vulnerability backlog, and all these vulnerabilities that you're getting from Tenable, from Wiz, from AWS inspector for, and we'll talk about AWS later on while we are here, but all this crazy vulnerability data from on-prem, from the cloud, take all this vulnerability data. You can sift through it. You don't have enough people in the team to review it.
And then you have walk workflows, but you cannot automate vulnerability management because it's deterministic. Every CV is different, every vulnerability is different, and the environment is different. So how can you automate?
You can't, this is why we're failing. And I ask him, it's like, if I can take this problem and automatically reduce 90% of that backlog automatically without any human touch, just eliminate it and leave you with that 10 or maybe 5% to actually handle. It's like, that sounds good.
That sounds great. That's great prioritization. And then I, then they told me, what about remediation?
I was like, okay. So once we have that 10 or 5%, I know, and we practice that and we identify it, take that five to 10% and simulate remediation and give you that one, two, or three steps that you need in order to reduce Back to the buck. Exactly.
That's exactly what we're saying in our website. Mm-hmm. And they say like, that's amazing.
If I have something like that, I will, I will buy it. We, uh, close the seed round in a month really quickly. We just took the money, great investors, and we build ze security, which is the current company we're at today.
Very excited about it. So that's basically the story of, Of you and Security. Yeah.
And ui. So Let me give you a little background. I, I've been inside, but we didn't call it cyber, we called it security.
I've been in security 30 years. Information security InfoSec. Yep, Exactly.
And, um, I actually, I've co-founded a couple companies, one of which was called Still Secure back in 2001. And we in 2003 came out with a vulnerability management product. And back then it was very different.
Back then you had to convince people to do a scan once a year. Mm-hmm. It was like pulling teeth.
But when you, but it was job security for the security guy. 'cause you would do the scan, you'd deliver like a telephone book of vulnerabilities. Let's say I give it to him for Christmas or New Year's, you know, you're from New York.
It was like painting the Veno Bridge. Amazing. You know how they paint Theno Bridge?
Amazing. They start on one end, it takes 'em a whole year to finish, to finish. And then when they're done, you know what they do, they go back and start again on the other Best job security ever.
That was vulnerability management. It was almost by design that you didn't get to zero vulnerabilities. So then people got smarter.
They said, look, we don't need to get to zero vulnerabilities. We should only worry about the vulnerabilities that are exploitable, reachable real. You know, I had, I had a friend, I don't know if you've ever heard of this guy, giddy Cohen, Skybox security.
Yeah, of course. Giddy just started a new company too. I know.
Um, you know, and that was one of when I first saw his attack maps is what he called them, right? Mm-hmm. That was a revelation.
I was like, wow, this is great. Now I only have to worry about 20%, 25%, Which is a couple of millions. It's Still a couple of still job security.
Yeah. But unfortunately, it's been almost by design that we never get to zero vulnerabilities. And as a matter of fact, even you mentioned, we were talking off camera about black hat.
I was a black hat in August. I was talking to a friend of my, uh, two friends who actually just, uh, just starting a new company. They just raised money now.
And, um, their, their thing is, look, forget all these vulnerabilities. There's only a handful that are real mm-hmm. That are responsible for incidents and just focus in on those.
That's good. If I knew exactly which ones to focus in on, you know, that's like the old, he's an old joke. A plumber comes and says, the lady says, I don't have heat.
A plumber says, let me look. He takes out his pipe and he, he bangs the, he takes out his wrench and he bangs the pipe with the wrench, and the heat starts working. The lady says, oh my God, what do I owe you?
He says, $250. She says, $250. All you did was bang your wrench on the pipe.
He said, oh, no. That was free knowing where to bang my wrench on the pipe. $250.
I love that. Yeah. I, I'm going to use that.
Tell you got it. This is awesome. It's yours.
Wow. But that's the thing about vulnerabilities, right? If you know, which of the ones that are exploitable are dangerous, you can mitigate.
But to get to zero, I'm not gonna ask you to give away secrets here, but what is the secret to getting to zero vulnerabilities? So what we, and I'm, I don't know if we want to get to zero. Okay.
I don't think we need to get to zero. Yeah. But we definitely need, like, why do the, the world need is important.
Since you start talking about scanning today, scanning is mandatory. Yes. You have requirements, right?
You have continuous regulators. You have auditors More than that. If you want to provide services as a SaaS company to customers, you need to have an SLA.
Yep. And what happened in 2025, these regulators, uh, re requirements are stop asking you for visibility. Because visibility, everyone knows everyone of that list of vulnerabilities, right?
Mm-hmm. Everyone can scan. Everyone's scanning today, even SMBs, they're require to.
But now the regulators starting to ask, because again, I will, I will give some more information because I think it's important. Over 60% of incidents today, and this is vouch number, are related directly to vulnerabilities that were known to the organization. Absolutely.
I think it's higher than 60. I think it's close to 80. I'm, I'm just basing on ENT report and Verizon report.
Yep. The time to exploit this vulnerability were reduced in the past three years in 19%. Now it's less than a day.
Last year in 2024 was less than three days before that it was five. So we got to less than A day. Remember what it was?
30, 45 days. Exactly. It keeps going down.
So regulators, cyber insurance, your customers want, if you have something critical, they want you to commit to an SLA, and God forbid something happened. You miss your SLA, your regulators will come after you, especially if you're a highly regulated environment. Yep.
Most of our customers are biotech, financial services, health, and even SaaS company that provides services to these healthcare. And Today, look, it's, it's about who your third parties are. Yeah.
Right? It's not who you are. It's who they are.
So, you know, and further down The list, and they want to get these deals. It's like, Hey, I cannot get these deals because I cannot commit. Or they're committing.
But now they need to deliver a seven days or six days critical vulnerability in production remediation. Absolutely. It's the whole SOC too.
And all of these other Yeah. Kinda audience. And what we actually realize is there is a need, like not in zero vulnerability.
There is a need in remediation. Yeah. And how we do what we do is basically, you cannot automate, but you can AI it.
So we using different type of LLM models, we acting as an army of security engineers that going one by one of these vulnerabilities. And it doesn't matter if they have high score or low score. It doesn't matter if they're being exploited in the wild or not exploited in the wild, they're in your environment.
Yeah. And what I need to tell you, if in your environment this vulnerability is actually risky or not, and you'll be surprised how the more, the most advanced scanners, these tools that you paying million dollars to, they giving you this list of vulnerabilities with attack path, with what will happen if, but they're not correlating that with your environment. No.
So you have an open SSH vulnerabilities, right? That open SSH vulnerability have requirements for exploitation. You need to run the service with specific permission.
That asset that is vulnerable need to live in specific environment, environment terms. Without them, this vulnerability can never be exploited. And to understand that you need to send someone to do this test.
Yeah. That's exactly what our gent k uh, uh, capabilities are. Wait, I needed to say it.
You You said it. Wait, but you made a long time till you mentioned it. Look, exactly.
We're here at AWS reinvent. I don't hear them talking about cloud. I hear them talking about AgTech ai.
So talk to me about how your agent is working to do this. Uh, we actually announced, uh, we are going to have an announcement, uh, early next year. But in a reinvent, we doing a private preview of a new capability that was very, very interesting to all of our AWS enterprise customers.
AWS investing a lot in security. Yes, they are. And we call it native security controls.
So they're allowing today DevOps and, and platform teams and engineering teams that build a cloud to build a cloud in a secure by default way. And they have a lot of native capabilities around resources. You can build policies around services.
You can have security policies without paying money, just using the native capabilities of the cloud. If you will look in these native security capabilities, and you will correlate that information. The hard work that your cloud architect actually infuse into your cloud correlate that with your vulnerability backlog that you need to solve.
You will realize very fast that many of these native security controls basically reducing 50 to 60 to sometimes 70% of your attack surface. But because you're not marrying these two together, you, you dunno, that means that you can focus on vulnerabilities that were already diffused and solved by and mitigated by these amazing AWS cloud native controls that you have. So one of the capabilities of our agenda AI is to look and understand your policies around services, resources, encryptions, VPCs, microsegmentation in your cloud, and understand if this remote code execution vulnerability can actually exist.
Even if you take into consideration these policies, most of them are not exploitable. Right. That's the idea.
I love it. It's great. You already, you, you don't have a problem.
You already solved the problem and you don't know that you solved it. You know, some, some part of me sits here and says, did it take AI agents agent AI to reach this level? Like, it's always bothered me to tell you the truth, why we didn't do better with this problem.
Right. I I was working on it 2003, 22 years ago Ago. It's a technology limitation.
It's not a need limitation. We always have that need. I think we've always had the need.
I I always thought we didn't have the will. Right. People, people talk a good game, but their hands don't reach their pockets when it comes time to, to really prioritize.
But this makes it easier more, it, it's, I don't want to say automated, but it, it's just, it's easier to, to do this. You can win. I love it.
Yeah. I, I agree. We, We are giving a lot of, I I, I'm really proud of it, but we are giving more life years to our security engineering.
Yeah. Every time we talk to a team and the team sounds tired and unmotivated mm-hmm. This is the team we want to work with, the teams that have these backlog of vulnerabilities that every day of their life is chasing down this Vulnerability.
Look, this is a whole big problem. You, you've been in security long enough, you know this. Right?
The, the depression of, because for those of us who've been in security a long time, we have a lot of people in security who are, they suffer from depression. They, it, the, the, the, the issue is, it's like what does winning look like in security About that question, Whitney is, I didn't get breached today. Mm-hmm.
Right. Did I not got breached 'cause I was the zebra in the herd and the lion ain't someone else today. Or because I did a good job, or I convinced my CISO and the board how to manage risk, what, you know, what's acceptable risk or not.
And, and so anything that I think Im improves that is, is an amazing thing. I was gonna ask you what Zest security's doing here at AWS, but you already answered that Ben, so that's fantastic. Um, what has been, so there are security people here, but there's everyone here, there's CIOs, CI, SSOs, there's there, do people understand, like the security people obviously do, but does the CIO does the cloud engineers understand what a, a load this is off of their chest, right off of their shoulders?
Mm-hmm. I don't think they care. No.
I think at the end of the day, part Of the problem too, I like, it's not part of the problem as much as, you know, we, me managing over 100 people, I knew everyone personally and I cared. Right. When you walk in a large enterprise, you like many times you can't do that.
You don't know what the security team in the trenches actually going through. Even not the ciso. Yeah.
Not talking about the CEO and the COO. What I, what I actually, um, what what what I like to surface is if your security team, if your vulnerability management team that in charge of prioritizing vulnerabilities and fight the vulnerabilities are drowning, which they are, it's going to bubble up into management problem. It's going to bubble up in audits.
It's going to bubble up the way you look in front of your customers that asking you about what do you do about this? What do you do about that? It's going to bubble up when you have a red team or penetration test.
It's going to look bad when you have a customer that's saying like, Hey, I asked you about this couple of days ago, what's going on? And we're getting these emails, right? So the management team needs to look good and needs to act good.
And it start from the vulnerability. It start from the team. So what I'm, I'm basically telling this COO and CIO is like today you have a backlog of do you have vulnerabilities?
It's like, yes. Do you want to eliminate a and at least 90% of these vulnerabilities without spending money and asking favors from the CTO and engineering team without asking and pushing tickets into teams that need to build your business? It's like, yes, of course.
It's like I can guarantee you that with agent AI infuse into your exposure management program, your program, you don't need to hire 200 security engineer. You can walk with your existing team, maybe add some more people if you want to, but you can win. If you infuse AI into that operation, you can open less ticket.
But each and every ticket you give to your engineering team, that ticket was 20 or 30% of your risk reduction. Got it. And that's what they like, they, they sync numbers.
Right. But at the end of the day, I'm helping the vulnerability management team. Yeah.
And if they do a better job, the COO, the CFO even will be happier. They don't understand that. But it's okay.
That's my job to make sure that both sides agree to embrace our technology. This will get, like, these guys will get their executive report and the vulnerability management will get an amazing, amazing tool that will make them survive the holidays. We need to survive the holidays.
Right. Well always. But then there's always another holiday.
You know, Ben, we're running low on time. I want to just make sure we hit a couple of things for people out there who, like what they're hearing, what's the website to go to here? io.
io. Very Z-E-S-T-Z-S-T zes, like the lemon zest. Yeah.
io. And we're very transparent about what we do and about our technology, and we have our customers use cases there. Everything you need to know.
It's in the website if you want to see it live. If you don't believe what you're reading, which is okay, we have a dedicated security team that can show you a 30 demo, 30 minutes demo and actually to see it by yourself. And we also have, um, um, a free, we just announced a few months ago, a free remediation assessment, really, which is not a risk assessment.
We're not showing you your problems. Right. Uh, we are basically showing you, uh, the probability of your remediation operation.
How can you remediate more with less? And it, it takes, I think, seven days of the platform to run, analyze, and get you everything you need without having any sales calls during that time. So, absolutely.
Yeah. io? Yeah.
Hey, I think you're onto something, man. Good for you. Thank you so much.
I really enjoyed the Convers I enjoyed having you on here. We'll have you on again, Z Security io. Go check it out.
Look, this is, this is, uh, this is kind of a holy grail a little bit if you've been in vulnerability management and security like I have. So go check it out for yourselves. I'd love to hear what you say about it.
Enjoy the rest of reinvent. I will. Thank you.
All right. We're live. We'll be back with more.
Stay tuned. All right folks. Uh, very warm.
Welcome. My name is Raj, and with me is Par. Uh, we'll be introducing ourselves, but today we are talking about golden parts or spaghetti pipelines, the dark radar of platformers.
It's, uh, influenced by a lot of Star Wars. Uh, I wouldn't say that I'm a Star Wars fan, but, uh, I think, uh, I've watched quite a bit. So we, we are gonna be talking about how platform engineering has, uh, evolved in today's world and what, uh, you know, platform engineering has come up to.
And we'll introduce a cool open source project in ent. Uh, obviously, uh, that's how I have summarized the talk for you. Again, my name is Raj.
I'm A-C-N-C-F ambassador and a community manager at Antes by Journey. Started off with kiosk engineering, a lot of things around litmus chaos. And now I have been doing a lot of platform engineering, K Zeros called Open, SDN.
Uh, other than that, I, uh, from a community aspect, I run KCD Bangalore, uh, platform engineering meetup. So you can connect with me on my socials perhaps. Would you like to introduce C sf?
Mm-hmm. Sure. Fr thanks.
Uh, yeah, so I'm Harit Thanks folks for tuning in. Uh, I'm the OPO lead at es, uh, opo, for those of you who don't know, it's open source program office. So, um, the typical role of osbo would be to focus on the upstream contributions and, um, contributing to the open source community.
And we at marant are especially focused at the Kubernetes ecosystem. So we work around technologies such as cluster API, um, um, and we open telemetry in Prometheus, Grafana, you know, for the observability stack and, and so on. Yeah, happy to be here.
Alright, thank you so much. Har, uh, for the agenda, I think I have given an intro already on what we will be talking about. Usually I don't keep a set agenda in place because, you know, you can stop me when you want.
It's, uh, obviously being recorded. So we'll try to cover as much as possibly, we talk about a lot of platform engineering and a lot of, uh, uh, a lot about the tooling as well. How, uh, real IDP might look like.
So, we'll, we'll find out what we'll talk about. But before I start, before I start talking about, you know, what's, what's there, what, uh, platform engineering, what's the platform engineering ecosystem looking like today? I'll just start from the, the developer ecosystem itself, and if you can see my screen well and clear, this is hello translated in a hundred languages.
Uh, there are so many more languages, there's so much more that you can translate hello to, but in the developer ecosystem, it looks something like this, the CNCF landscape. And that is what is expected from developers. Developers are expected to learn tooling.
They're expected to learn different kind of tooling. Uh, beyond writing code, developers are expected to run learn container and time chaos, engineering, networking, CICD, uh, building pipeline, streaming messaging policies. And developers don't want to learn so much tooling.
Developers want to be writing and shipping the best code. They don't want to be testing. And, you know, being involved with qa, being involved with learning CNCF tooling and implementing that, running it in queing production.
But that is what the ecosystem looks like today. That is how, uh, enterprises or teams are functioning today. Uh, developers are expected to do so much that there's a developer toil, developer experience takes a hit.
And that is where the idea of, you know, DevOps came in. The idea of, you know, moving from, uh, the old school way of development to, you know, having the ops side of things to make shipping easier came in. And that in itself has become tough.
I mean, if you have to talk about DevOps engineering today, there's a sense of change or the sense of, uh, you know, shift from DevOps in itself. But before I introduce that, and before I talk a lot more about cloud native technology, let's talk about how cloud was meant to be. The idea was a data center interacting with the public cloud environment.
That is what customers or developers or the idea of cloud brought in. But this is the reality we have today. Multiple cloud providers has AWS Azure, uh, people are hosting their, uh, infrastructures on private cloud edge environments.
And there are so many APIs under the hood that eventually it has become a complex distributed system or a complex distributed infrastructure. And the idea of, uh, you know, container orchestrators was to make it simpler with Docker Swamp, to Mezo to Kubernetes, where the community thought that Kubernetes is that one single source of truth or a powerful scheduler, a powerful container orchestrator. But this is what we have eventually reached too.
Kubernetes has matured, but we, we can see that even if we are using Kubernetes under the hood as the orchestrator, it's Kubernetes, which is, you know, being used, uh, as, as an orchestrator in your Azure environments or your AWS environments or your GCP environments, edge environments. But there are still multiple APIs under the hood. It's, it's very hard to manage these multi-cloud, multi cluster deployments.
And the ideation that we had with, you know, by bringing platforms and Kubernetes as the common control plane, was that Kubernetes will remove these, uh, uh, complications, these dependencies and Kubernetes will act as the single source of truth or the manager to these multi-cloud, multi cluster environments. But where we are, where are we today? I mean with, uh, you know, platform engineering and the concept in itself, I believe platform engineering is not a new concept platform as a product is platform engineering has existed for as long as we have known.
DevOps in itself had the idea of building platforms and, uh, ensuring that the developer experience is eased out. Developers are able to ship code faster, and they're able to, uh, basically build, uh, build an infrastructure out of different tooling. But platform as a product is how it changes the ecosystem is that now you are trying to shape tools that are predefined.
You're using the CNC of technology. You are, uh, using AI native technology. You are hosting it on different, uh, cloud environments or your VMs or on your GPUs.
So the, the idea is to ship a ready-made standard approach to developers where they don't have to do much. They are shipped something that they have access to. There's an interactive UI per se, or there are interactive tools that they can choose from.
There's a marketplace if you want to choose, uh, your csis, your CNIs, your container registries, your runtimes, everything is shipped to you as a complete total platform, which I believe a lot of it has been achieved by, say, Heroku or the other, other options that are out there. But as I said, platform engineering has evolved to shape platform as a product where you can use your multi cluster multicloud environments with ease. But before that, let me just go back to the topic of DevOps.
What's the current state of DevOps? Is DevOps actually DevOps right now? I, I believe that DevOps as a concept can never die.
DevOps as a concept will always exist and mature. It's, it's similar to suggesting that, you know, say, uh, uh, you know, development in itself might die and AI might take over. It's, it's, it's similar to saying that, you know, Python or go might become, uh, redundant and some new coding language can take over.
I believe that, uh, DevOps in itself has evolved and platform engineering has become the subset of DevOps today. That's how I, I look at it, and I believe the, and large enterprises will still focus on the DevOps side of it, because if you have not improved your DevOps, then how can you even look at implementing platform engineering as a concept or platform engineering in your different teams? Because, you know, there are different teams.
They want to have a standard approach. And if you're not following the right DevOps practices, or if you're not following the right DevOps mindset, then reaching the platform engineering maturity is, is, is impossible. In, in my, in my opinion, I, and I believe the viewers will watch this, uh, presentation, uh, on, on 30th, they'll, they, they agree that, you know, maturing your DevOps practices can help you mature your platform engineering goals in itself.
And DevOps challenges are driving platform engineering. What went wrong with DevOps that, uh, you know, platform engineering came in as, as a niche or as a concept. I mean, before DevOps, you were, uh, developers writing code.
They were unit testing, but after DevOps came in, they had to write code, they had to build their pipelines, they had to write code for their builds, and then they had to write code for monitoring metrices. And then came the unit testing side of things. And as I spoke about, developers don't want to learn about FRA and new tooling.
There's a slow developer onboarding and cognitive overload and developer burnout has actually hindered developer growth. Or you can say the amount of input of productivity that developers can come in with. And that is where we, uh, you know, consider platform engineering from a cost perspective, from a reliability perspective, there are so many outages, kiosk engineering, incident management, reliability engineering, uh, you know, uh, debugging, uh, integration testing has improved so much.
So, you know, to, to address these critical outages incidents, to find out what's going wrong, to ensure that your systems are consistent. And even if you are, uh, you are making changes or you know, you're adding features to your systems, because the infrastructures are so dynamic and in, in nature, there's a shift left, uh, resiliency or development happening. You need to ensure that, you know, if your production releases are happening frequently, say in a month, you're accelerating your cloud native journey, adding tooling.
You have to consider the platform engineering approach where you're standardizing the approach and you're ensuring that, you know, you are shipping code in terms of a platform or an internal developer portal, IDP as, as the world popularly knows, but there's a dark side to the realm. There's a dark side to platform engineering. Even if the idea of platform engineering is to focusing on self-service, internal platform, streamlining, software delivery, platform engineering has not been, you know, subdued or, or performed in the right way.
The, the platforms that we are trying to build today, uh, they, they are overly complex in nature. Uh, they are, I mean, teams are platform engineers as personas, but they have not reached the right approach to it. And I, I'll cover some dark side why we, instead of building the right golden parts of the right, uh, uh, platforms, we have, you know, created spaghettis.
If, if you say, so how, how I've defined the talk or why is it all over the place? The first point, of course, uh, too many stormtroopers over the complex platforms, uh, there's lack of focus on the core needs. You have to begin by addressing the most pressing challenges faced by the developers.
You have to add features iteratively rather than, you know, adding all of the features together. There has to be a minimal viable product mindset. You have to prioritize features based on real world requirements.
There has to be regular, uh, reviews, periodically assessing what's going wrong, why the platforms, uh, uh, I, uh, are having redundant features, or is there a complexity issue that you're facing with your platform building in itself, uh, there's a lack of developer adoption, uh, develop. Even the most well built platforms become inec ineffective because developers are hesitant. You need to have a user centric design build platforms with developers, uh, in mind, focusing on their us, uh, usability, their intuitive, it should have an intuitive interface, need to demonstrate value.
Show developers how the platform reduces the cognitive overload and enhances their productivity. You need to constantly support them, uh, offer, uh, robust documentation, have an accessible support system, uh, ensure that the developer onboarding is easy and, you know, developers are able to adopt it in a, in a structured way. I believe platform engineering is missing the real goal.
Many organizations jump into platforms as I spoke about, but they don't have a purpose in place. So I believe education and training, conducting the right workshops, uh, sessions, familiarizing them with the platforms and incremental rollout as you, as i, as you say, gradually, uh, changing the engineering practices or moving from the old school software delivery model, having the right feedback loops in place, actively, uh, solicit and act on feedback from users, which is your de developers. I'll, I'll talk about platform democracy and idea or concept I really believe in.
But yeah, uh, you need to find out the real goal. What is the real evil, if I have to say? So, uh, you, you, the, the idea of trying to integrate legacy architecture organizations with leg legacy systems want to integrate it to modern platform practices.
And that is not how it's, it's supposed to be approached. You need to have a modular design where, you know, you need to ensure that your legacy systems are able to interact in the right way with your platforms. They have to be, uh, there has to be gradual modernization rather than immediate, uh, modernization or, you know, just pumping in the resources or the funds and ensuring that, uh, you know, your platforms are compatible in nature.
And then you have to use your middleware, right? You need to ensure that you're bridging the gap from your older tech to your modern platforms. There is a Kubernetes sprawl, as I spoke about CNCF landscape is growing like a banyan tree.
Uh, there are roots and branches that, uh, people or developers cannot access so easily. You need to standardize your tooling, have a curated list of tools that your organization or your, uh, platform needs. You need to assess the ROI, what's, uh, the return to investment on the effectiveness and the tooling that you're using.
And then you have to have a consolidate effort where you know, your developers, your stakeholders, your decision makers, your customers in itself are, are able to, uh, you know, have a consolidate effort towards, uh, your platform goals. Security is the important, uh, open SSF has been doing a commendable job. Uh, there's, uh, you know, your, your centralized, uh, platforms become threats to, uh, any sort of security issues.
You need to ensure that there's a security by design principle that you have calling where it's not just about the platform's design, but you have the right r back controls the right encryptions. There's regular auditing in place, and of course, you have to educate your teams in terms of security and how you can minimize the human aspect to it as well. Tele isn't easy.
I mean, scalability and performance bottlenecks are there. You need to ensure that you're planning for scale load testing. Again, conduct regular performance and operation testing, identify and address the bottleneck.
And then of course, dynamic scaling. You need to implement auto-scaling mechanisms to handle the variable workloads effectively and efficiently. Uh, I think this is the second last point that I have.
Cost optimization is missing. Uh, we often see that people have built platforms approach software delivery in a certain way, but there's no proactive cost optimization. Cloud costs, uh, resources or resource optimization, or there are other tools.
I mean, open cost cube cost out there that you need to ensure that you are having the right, right resource utilization and you, you're able to improve your overall efficiency by, uh, and at, at the same time, you're reducing your resources and your high operational costs. And lastly, of course, observability. Uh, without proper monitoring, metrices logging, uh, you cannot have a platform.
I believe that you cannot identify how your platform is performing if you don't have the right observability in place. You need to define your metrices. You need to define the right SLOs, SLIs your MTTs, uh, how your system is, uh, behaving, say in a steady state, or when a new tooling or dynamic scaling happens, how your systems behave.
And you have to have automated alerts in place to find out the critical events. The, the scenarios in itself with this, I have, I believe I have covered some main platform challenges, but one platform challenge that I believe needs to be addressed at a higher level is platform engineering needs to be democratic. Platform engineering has evolved through multiple stages from, you know, a rigid separation between development and operation teams to the emergence of DevOps to eventually centralized platform teams.
I believe to address this, there has to be a platform group where multiple teams on different focus areas have to come together. It can be the producers or the consumers. So the idea is to make platforms democratic, you need to redefine your roles.
Producers are no longer the only platform teams. They include your internal teams, your executives, your compliance folks, and then your, uh, eventual customers as well who are eventually consuming. These platforms have to become a pla part of your platform group to ensure that your platforms are safer, faster, and obviously are enabling the developer self-service as the, the idea of a developer self-service as the eventual goal.
And as I spoke about platform needs, platform engineering needs multi cluster configurations. While you are creating your IDP, you need to ensure that you're able to manage your multi cluster configurations, your AI ml, uh, uh, you know, there, there, there's an AI ML workload side of it, or, uh, your platforms are moving towards an AI ops, ML ops approach. There's hybrid multi-cloud environments.
We have spoken about, uh, it, most enterprises are deploying, uh, hybrid environments. You have your Edge IOT environments, which are, which have to be highly available, uh, in nature. There are multi-tenant teams.
There. You have to maintain isolation between different teams. And obviously there are country specific data, so in laws as well, where, which you have to comply while building your platforms.
And the major challenge of building these multi cluster platforms is that, uh, the, the ideal goal or ideal scenario is single application cluster or having multiple, uh, alpha providers ensuring that your dynamic on demand clusters are placed in the right way, but it serves a lot of challenges. Your workloads are inconsistent. There are no right policies in place.
Operational, uh, goals are not met. It becomes complex. And then there's a tooling sprawl or Kubernetes sprawl as I spoke about.
And that is where you need the right manager or the right, uh, tool to ensure that you're able to manage your, uh, uh, golden parts. Well, there's no Kubernetes sprawl. Uh, you know, your beachhead services are not being managed well or your services while you are managing these multi cluster environments.
Even if you're using Kubernetes as your scheduler, you need to ensure that you are doing it right, because I have seen Kubernetes being used in mainframe IBM mainframes as well. And this is how I have envisioned the platforms of today. This is a simple example.
I have taken, I have worked, uh, uh, uh, with, uh, antes today on platform engineering, where back when I was at harness, you were doing a lot of software delivery. So I believe that, you know, you need to ensure that there's the right IDP framework in place for your smooth developer onboarding, your security tooling. I've taken an example of Paco, that it has to be in place to ensure that you're orchestrating, uh, your security, or you have the software supply chain assurance, the CICD, of course, that's the foundation of your platform to ensure that you're delivering your software faster.
You have the GitHubs in place, getting in the pipelines in place. Then comes your resilience engineering, which is your service reliability management, your kiosk engineering, error tracking, incident management, and eventually your, you know, optimizing your cost and your process, which is your cloud cost management, your software delivery, uh, software engineering insights that I believe completes the structure of your platform and builds the right foundation. And this is how I have layered it into different steps or different, uh, processes, frameworks.
And I, I hope that, you know, eventually folks will watch this talk or will build their platforms tomorrow, will follow the sort of, follow these, these steps or have these, uh, different modules in, in their platform in itself. One last point before baat takes over and talks a lot about multi cluster platform engineering and tooling, infrastructure has coded, I believe Terraform, uh, brought in the boom in terms of bringing, bringing the platform mindset. But, uh, there's a core role that infrastructure as code has played, uh, in terms of platform engineering.
It has enabled platform standardization and reusability. Uh, the, the idea of platform engineering, uh, is obviously to build the right IDPs and IAC helps encode these platforms as reusable or composable components. Uh, you, you, you are able to drive, uh, uh, you know, uh, uh, environmental, uh, I mean, it, it, it allows you to have the right environment to be replicated.
Uh, if, if it's working on your machine and you have to work, uh, you have to ensure that you are, uh, using it in a different dev environment or a staging environment or a broad environment. You get, you have to have the automation and the consistency in place so that even if there are rollbacks or, or there's a, there's a disaster, uh, recovery mechanism that has to kick in it, it becomes simpler. And then obviously, last couple of points I'll co cover quickly.
In the interest of time, you have to have the foundations of self, uh, developer, self-service or self-service portals. You are templating the, the infrastructure as code templating has to be, you know, say a catalog based, uh, so that you can provision it in, say your, uh, you know, your in IDP framework, say a backstage or a human tech or a port, and then obviously supporting, uh, the, the GitHubs and DevSecOps practices, you need to ensure that they, they are following the right security and compliance practices. There's a vault secrets management in place.
There's a workflow, a workflow orchestration, say, using Argo CD or Flux. And then, uh, developer experience tools and, uh, MLS are, are in place perfectly with this. I'll allow Haat to take over to talk about a little bit about multi cluster platform engineering and what we have.
So barat, uh, you can, you can take it from here. Alright, folks, so problems, problems, problems, right? Uh, we heard a lot of problems, uh, a lot of challenges in, as we like to call it in corporates.
Let's not call it a problem. Let's call it an opportunity. Yeah.
So in terms of the challenges that we spoke about and the opportunities to fix the multi cluster multicloud problem, we have a bunch of them. Um, the previous slide talked about IAC, um, that's, that's one of the most common ones that's been currently used. But of course, IAC brings in a lot of dependencies with itself, right?
So if you talk about this structural, um, step-by-step kind of thing that we can see how we can solve it, there's the DIY open source solution where I see also fits into this category, right? But then of course, you have to handle all of this on your own. Um, it, it brings in a lot of operational burden and the expertise dependency on those particular tools.
And then there are proprietary solutions, which are great, of course. Um, but the biggest challenge with that is if not today, if not tomorrow, eventually one day we're gonna run into the vendor lock in problem. Um, we've seen this a lot happen lately, but one of the things that everybody will instantly recognize is of course, um, VMware, right?
With the whole Broadcom situation, people felt boxed in, locked into that particular platform, and they want to get out. So this will always almost happen. With that in mind, we wanna talk about an enterprise grade open source solution, which honestly has been, um, the business model of many good open source companies like Red Hat and, and, and others, right?
So here in the IDP solution that TU was mentioning earlier, the bottommost layer remains the infrastructure. It could be your clouds, it could be your on-prem, it could be public or private clouds. And then the topmost layer is your application delivery, where your end user applications rely on, right?
I wanna talk about the middle layer, which we are trying to like focus on, which could be the platform orchestrator, right? So we need a mechanism to figure out how do I provision, um, Kubernetes clusters and across clouds consistently, and then how do I also ensure that the D two operations are going as per the plan as well? That's the layer we're gonna focus on.
So this is where we wanna focus on this open source project called as ent, where we have a platform engineering solution in, in like, you know, three segments, let's say cluster management, state management, and then observability. So observability and finops, I'm, I'm just gonna group them, and that's probably the most straightforward one to talk about, where observability is just having eyes and years on what's going on with their platform, right? It could be locking, it could be metrics, it could be costs and so on.
Then the left side of, uh, the screen, the cluster management and state management are the mirror images of, of, um, day zero and day two operations. While cluster management helps define your infrastructure configuration, state management helps define your services configuration. I'm gonna be showing a live example, uh, soon.
But essentially that's, that's the key thing that I wanna convey. Cluster cluster management is infrastructure and state management is services. So if you look at the generations or, or the transition of how things, um, have, you know, gone ahead, right from 2014, which is like early days of Kubernetes, all the way to, let's say 20, 23, 24, is that there's been early adopters, and then there's, um, OpenShift, which is a very opinionated, opinionated way of Kubernetes, and of course, um, on the great vendor solutions.
And then as we progress, we can see that there's a good, um, community driven solutions right now where Kubernetes has been the fabric that is orchestrating all the major workloads. And in order to develop this, we have platforms, right, which is ent. So here's where we encapsulate like sort of all the open source components that, uh, are used in ent.
Uh, like I said, the whole thing is driven by existing open source projects. Cluster management is taken care primarily by cluster API and all the other cloud providers like capo for OpenStack, Kappa for AWS, capsi for Azure and so on, right? And then there's the K zero s and Cosmo, which is the Kubernetes distro, K zero s, that's, that's what, uh, is underneath.
And the control plane manager, which is cosmic Trump, and similarly in state management or service orchestration, asto in flux. And then in the observability side of things, we have a whole bunch of other, um, um, you know, open source solutions. So this slide basically shows, uh, another layer of IDP and how we basically have it if we are doing completely DIY kind of solution, right?
So in terms of observability, we have like cube cost, Grafana, PROEs and all that. And then kinu, and then, you know, RabbitMQ and all these bunch of services. And if we go to the next slide, we can see how all these complexities are simplified into the three layers that we're talking about, where it's all encapsulated for you and delivered to you as a single platform catalog.
io is like, like a sim like an analogy for, for us to understand this is mobile apps have play store and service templates has catalog. That's it. Any application that you wanna deploy, um, for example, Argo cd, right?
Which is one of the common things we use for our c So it's available as a service template, and all you need to do is do a helmet install and then specify which particular chart you wanna deploy it. That's it, it's as simple as that. Here we have like multiple applications, right?
And all of these are, you know, um, tested and, and, uh, they have gone through like E two E tests and manual testing, and then they're uploaded onto catalog. But in case you have an application that is not intended to be public, we can still use your own application and just make sure that we specify the proper OCI parts for the chart. So what I mean to say is, even if the application is not public, you can still upload it to your own catalog, uh, as a helm chart and then specify that during the installation that is supported as well.
I wanna show a live example of how we use Cord in order to provision a Kubernetes cluster on OpenStack. So I've chosen OpenStack to be an example for this demo where we can simulate the same thing across multiple clouds as well. So first, let me show, um, like, let, let me set up a bit of context.
Currently, we are on a kind cluster, which we, we will use as a management cluster, and this cluster will be the base in order to manage hundreds of clusters. Then we've got our cluster templates, right? As you can see, these are cluster templates, and you can see that each one exists for a particular variant of a particular cloud.
And today we are gonna be using the OpenStack standalone control plane template, right? And then similarly, the equivalent of this, we have service templates. So for the example that I'm gonna show, I just used a Nvidia GPO operator, right?
So service templates can be installed onto your cluster just like, uh, what I showed earlier using helm upgrade, install, and specifying chart. For now, on my cluster, I just had these two, and I'm gonna be using this one. And then finally, let's take a look at the cluster deployment that defines this configuration, which is what I mentioned as a single YAML file to define both the infrastructure specific configuration as well as the services configuration.
So your cluster deployment references the template, which you want to use based on the cluster, um, based on the cloud, it references the credential, which I just, um, applied before this. And then this is typical infrastructure configuration changes from cloud to cloud. And over here I'm using T 2 45, which is a flavor of, um, I mean, which is a GPO flavored instance, right?
But for the control plane, I'll be using a normal CPU only instance. And then services I just mentioned, what kind of services I wanna be, I want installed on this cluster. So for now, I mentioned the GP operator, and that's it.
So in the interest of time, I had already applied this cluster deployment just before the talk and cord controller takes this configuration, reads the infras prospect stuff, understands the template, uses the credential, and uses, you know, the rest of the infrastructure configuration and actually deploys a cluster on OpenStack. Once the cluster is deployed, then it would also figure out the service spec and it would deploy the particular service on that cluster. So let's check out, so this one, I've already checked out the particular cluster, and if I do a configure view, as you can see, this is the one which we have provisioned, right?
And then the service configuration, um, just to, just to let you know, since we chose the Nvidia GPO operator, IT does installed that, and then the operator has, has done whatever job it has to do, right? Which is to let the cluster know that this is a GPU enabled cluster. And how do we confirm that this is working by describing the note, right?
Let's describe the worker node. There you go. com/gpu, and here we go.
So essentially, the Nvidia GP operator told our Kubernetes cluster that this particular instance as a worker node, um, which is G-P-U-G-P-U enabled and added this label so that the workloads can utilize this particular label. And yeah, that's it, right? So in case you want to, um, scale this, all you would need to do is add more services onto the single yam.
So we can easily imagine putting this particular YAML file into a GitHubs enabled repository, and your platform engineers would just need to work with this YAML file, update a version, let's say, for example, or add more services like Istio in case that's a service that we interested in and according to do the job of picking up that configuration and coming back here and applying that on the child cluster. I think with that just, uh, prri, I'm gonna pass it over to you so that you can just, um, finish with the community stuff Folks who are watching this talk. You can scan this QR to access the cord GitHub.
Uh, feel free to check it out. Feel free to check out the components. There are different repos, the KCM, the KSM, the C and other repos that give you access to everything about coordinate.
This is the main repo, and if you're on the CNC of Slack, uh, you can join the coordinate channel or scan this QR to join the CNC of Slack, and then join the Cord Channel to be a part of the community. Once again, thank you so much everyone, and thank you so much, uh, uh, Brian and folks at Techstrong for, uh, helping record this. And yeah, I hope you'll love this talk and join Cord, uh, and the CORD community.
Hey everyone, welcome to another live text on gang. No, we're not robots, but they seem to be everywhere. Mike, John Schwartz, Terry Robinson, it's great to have you here live on the gang today.
We're happy to be continuing this live TV experiment. I, I feel like it's, we're all mice in the lab here, but hopefully it'll work. This is the first time we're trying it with people.
A lot of people remote. I'm not in studio today. John is out in Las Vegas.
It's CES Terry. Terry's still behind the brick in front of the brick wall. Think it's Saint Valentine's Day massacre or something.
But, uh, I know, and of course Mike Azar joins us. Mike, as I mentioned, John's out in CESI think that's John on the screen here. It's not some new humanoid robot, but robots are everywhere.
True. John's been eliminated. He's, he's over in you.
He's over there. John, John is our man on the ground at CES this week. So it seems like from out here, at least John in New York, that robotics, once again is like everywhere at CES.
And I know that, you know, we talk a little bit about this yesterday with Nvidia and what they were doing and the, and, and we mainly talk about course, which are kind of becoming like a new robot, but there was a lot of announcements that are related to robots. So what's your sense, you know, are the robots taking over? They are, they're taking over our homes.
They're taking over our manufacturing, they're taking over our roads, they're taking over our skies, they're taking over everything. They'll probably be taking our jobs pretty soon. So watch out.
Um, so there were a bunch of things last night actually. I went to the Lenovo, this Lenovo events, and it was, there was just a ton of announcements as you would expect. Jensen Wong was there, what a surprise.
But one of the things they did that really got my attention, and I actually went to get a live demo of it, it was this mule type of robot that carries, uh, heavy, heavy amounts of, of material at dangerous sites. And it's being used, um, in China, and it'll be used in the US at energy related sites for inspections and moving cargo. That was pretty cool.
It's also incredibly expensive. Uh, it's probably upwards of, uh, 200, 200 grand, but you know, if you can afford it, why not? Um, there was also, uh, at the, on the home level, there was something called Robo Rock, which has this, uh, vacuum.
It's very mobile, very flexible, it got a lot of attention. Um, segway has lawnmowers, again, these are expensive, 2,500 bucks, but the idea is they do repetitive tasks and maybe they start, they use them on college campuses or large venues to take care of maintenance. Um, and um, as you mentioned, Mike Nvidia and the cars, it, it was ubiquitous and, and it kind of made me think about, this is all about convenience if you can afford it, but it's also about eventually changing the way jobs are done, especially dangerous jobs or repetitive jobs are, are thankless jobs.
And that kind of made me think about what that might mean for the labor force going forward. And, um, it was kind of, it was a dystopian, to be honest, and, uh, while convenient and, and awesome and cool, like they, all the words they always use is CES To me, it's also somewhat troubling on where we're headed as this stuff gets smarter and, uh, more ubiquitous. Mm-hmm.
Alan, over the break you had some, uh, comments about where we were heading with AI and the fact that it was gonna be in the physical world on an article that you posted. Um, what is your sense of, you know, are we, from a society perspective, ready for all this Space? The final frontier?
You know, I, we could, we could wr our hands and clutch our pearls and, and talk about dystopian and unsettled, it's not gonna stop it. Robots are coming, robots are going to do a lot of physical labor and, and not just donkey work with all due respect, you know, carrying heavy loads into mine shafts or something like that. I, I think you're gonna have robot.
We already have robots that do surgery, right? Yeah. Right.
That's pretty delicate right there. Pretty fine tuned. You, you're gonna have robots that do a lot of physical, uh, activity, a lot of physical jobs.
Now what does that mean for us? Right? And, and you know, it's funny, uh, tomorrow on my shimmy says the, the title is what exactly are all these AI jobs anyway, right?
Because that's the thing we're hearing every time someone John says, what you say about, wow, it's, it's dis it's discerning that we're going to, you know, lose all of these jobs. People say, oh, but AI's gonna create a lot more jobs than it takes. Well, what exactly are those jobs?
And, and, you know, I don't want to let the cat outta the bed. You're gonna have to watch Shimmy says tomorrow. But basically, hey, someone has to work those robots.
Hey, so, so I, I, that, that's a good point you brought that up, Alan, because I'm, I'm, during the demo last night on stage, there was this robot at the Lenovo event at the sphere there I, I was watching off stage. There were two guys that were controlling the robots. And so those were, I guess, ostensibly jobs created for the robot.
But they're highly specialized people and, um, these are really expensive robots that do a lot of, that do the work of many people. So the, the math is kind of a little bit off kilter, but again, we'll see. I mean, I, i wonder what these jobs are too, by the way.
I I think you're gonna have mixed groups of workers, some of them being physical AI or robots or whatever you want to call them, mixed in with people, right? And, and I said space in the beginning because I, I came across an article, Mike, and that was in what I wrote about where, you know, a lot of the so-called architects of ai, right? Uh, the Times Men of the Year are, are saying that space represents the next great place for jobs.
And you could foresee like going to an asteroid and mining an asteroid for metal, where the robots are actually out on the surface of the asteroid, you know, actually mining the metals and so forth. But there's humans, it's some control ship or some control outpost somewhere near that asteroid, if not on the asteroid, who kind of oversee all of this and schedule all this and communicate. So it won't be a, like a fully robotic mission.
It'll be a joint effort of people. I, boy, I dunno whether to think that is, I'm sorry. Go ahead.
Sorry. I was just say, I've seen that, I've seen that movie Alan though, real quick, because, you know, that's when they declare independence from Earth and then they set up a whole nother country, right? Well, No, first someone says, open the pod bay doors.
See, I was, Terry, what do you wanna say? I was just gonna say, I don't know whether to think that's like super cool or super like scary and distressing for the reasons you just said, Mike, you know, like, when did they take over, turn on us and, you know, but also just to be, I, I don't know, in a outpost in space directing robots to do things also sounds a little like, not a Joyful, but you looked at it. I, I, I, you know, I, I will tell you, I, over the week, over the break, I had the chance, a friend of mine's friend came down to spend some time with us.
We were out on the boat. This gentleman works for Blue, uh, yeah. Uh, Jeff Bezos, this his space, blue Origin, Blue Origin.
And I'm gonna tell you, he, he showed me videos that stuff that we don't really see, see origin publicly of, of stuff they're doing. And I am more convinced than ever that our children, our children's children will work in space. And that, So there's, there's different, So our generation thought we might work in space.
I mean, you asked If, well, we did go to the moon once. Well, Yeah. And, and then you asked if we're prepared for this or are ready for this.
Well, maybe, heck yeah. If you watch the Jetsons when you were a kid, you know, you thought that this is where the future was gonna be, maybe a little bit sooner than you know, than it, than it is, right? Well, you, You here, Terry, I'm glad you said that.
'cause this goes again, I'm gonna talk about this tomorrow in my shimmy says, but here's a Shimel law for you. Shimmy says law, the future never happens as fast as we think it will. Mm-hmm.
Until it does, Until it does. Suddenly it's there, right? We grew up to go to the moon, we're gonna have the Jetsons, we're gonna have the flying cars, and then we're gonna have things like AI and quantum and robots doing all these things.
And they always seem three to five years away, three to fusion energy, three to five years away. And then all of a sudden it's here. And we're not Time out.
Somebody already has that law. It's called, you know, the future's already here, and it's just unevenly distributed. So that already exists.
So I got a copyright claim already, right? But I wanna come back to like earth here. Space is nice, but let's talk about something near in the near term.
I think that, you know, having a robot that's gonna go in and put out a fire so I don't have to send a fire department in there is priceless. You know, that's 200, 250 grand no problem. Having, um, a robot that, you know, eliminates somebody's job that is, you know, making 60 grand a year.
But the robot costs 200 to $300,000 a year. I'm not sure that math works. So The robot doesn't cost two to 300 grand a year.
The robot, well, It'll, the price will, the, the, the price will, the price will drop, you know? So I was just anecdotally this morning, I was waiting in line for the Starbucks to open at five 30, and I was behind a lady who works for Caterpillar. So I started talking to her because, um, I did an interview with the CTA people, the people who run this organiza this, this show, uh, Gary Shapiro.
And they were mentioning agriculture, and I asked her about, about the impact on the jobs. And I said, you know, this is gonna be really interesting, but like in manufacturing, are we gonna see a decline in people working in the fields or people gathering? And she said, well, a little shift.
And I was like, well, to what? And she just smiled. So I'm sure they have a plan, but that always worries me.
Mm-hmm. I mean, look, you know, this'll bleed into our next section. Well, so John, Are they talking security at all there?
Are they talking security at all there? Because, uh, Robots, they did, actually they did. So, uh, we, we can talk about it.
Yeah. They, they talk about security. They talked about green and, and, and the environment and energy consumption, which I think we're gonna maybe be talking about later.
I, I'll bring that up Later. Weren't, they weren't support on the spot. It was, well, they were, they, they're very touchy about this.
Lenovo and Nvidia in particular kept going over this is, this will save energy costs. This will minimize the amount that's, that's necessary to make this all happen. Red flag.
Yeah. So let me, let me return to what Mike's saying though. So guys, you gotta trust the market.
You've got to trust the market. No sane business owner is gonna pay 200 grand a year for a robot to do the job that a 50 KA year worker does. Just to be cool, right?
This, this reminds me, I, I, you know, my, my son was accepted to the Kelly School at Indiana University. I went with him to accepted students day. And I got into a beef with an economics professor there because he said that the, the, well, what do you expect from Indiana?
But he said that the minimum wage, minimum wage creates artificial jobs, right? It gets in the way of progress. And that, you know, they're just giving people, in essence, busy work.
And this goes back to the article I wrote, we don't want to create AI jobs that are busy work jobs, right? Because the market doesn't work that way. I don't need to create busy work jobs that are not economically viable.
If I could get, if I could get a machine to do that job faster, cheaper, better, I'm going to use the machine. The market's gonna force me to, otherwise someone else will. And they'll put me outta business.
Unless I'm going to get subsidies or something from the government for giving people work, give 'em a shovel, shovel and have them dig dams in the Tennessee Valley, right? I, I don't think we're gonna come to that again though. So my only, my only, the only thing that really bothers me about this is if, say you have a $200,000 robot, what if it does the job of say seven to eight people who make $40,000 a year?
So the math is gonna work to the advantage of those who can afford the robots and don't have to worry about benefits, for instance, and don't have to worry about, uh, somebody getting injured on site, um, or lawsuits. So that's, that's kind of where I, I see some of this headed. But that, as you said, Alan, let's let the market play itself out.
And it's gonna take several years. And I'm sure, uh, wolf, Wolf, we always find our way with technology. I think There, there will be jobs we haven't thought of.
I wish we had a better plan because I'm afraid that a lot of those people who are not gonna be going to work and their identity is wrapped up in their job, are gonna decide that, you know, they don't like the way the world is going and they're gonna vote in a way that might be suboptimal for our robotic future. Well, yes. Vote.
Well talk them to today's us is isn't this what happened in manufacturing in the, in the seventies, eighties, nineties, and early? Right? Isn't, isn't this why we find ourselves in the position we're in, hillbilly allergy and all of this stuff where you have vast swaths of the rust belt that have been made obsolete, Right?
Right. Mm-hmm. Yeah.
And you're taking away more than their jobs. It's like their, their dignity, their Identity, everything. Yeah.
So that's tough stuff. I say send them to space Or underwater. Or underwater.
No, I mean, this is gonna be an issue, right? You're gonna have, and, and don't gimme the retraining. 'cause you're not gonna get some 50-year-old beer guzzling dude in, in Fort Wayne, Indiana to become a robotic engineer.
It don't work like that. But hopefully his son will be, or his daughter will be. Right?
And, and there's gonna be a disruption and displacement of a generation. See, and that's the thing. I mean, oftentimes when it happened, look what happened.
Like in Detroit, you know, when all those car jobs went away and assembly line, whatever, um, there was like a lost generation in there because first of all, the people that had been doing it didn't support the younger people coming through. 'cause they couldn't see a pathway for them to be, you know, they, they couldn't carry on the family tradition of working on the line and, you know, whatever. And until, uh, Michigan was doing this kind of interesting thing, their economic development com, uh, committee about training kids and helping kids, uh, in schools develop like cyber programs because cars had computers and cars had security issues and all of that.
And it was finally the first time that an older generation could relate to the, the younger ones coming up and feel that connection. But that was a long time coming. That was decades.
Yeah. Bruce Springsteen writes songs about this. So is Billy Joel, right?
Yeah. I wanna hear what those songs are gonna be going forward. Yeah.
We we've gotta move on to our B block, but it's AI is gonna write them combination. Yep. So here in our live, uh, version, we don't really take break.
We, we transition. So we're gonna transition into our B block and we're gonna talk, you know, in the same vein, data centers, the $8 trillion albatross around our next that would, well maybe it's not an albatross, but there's an $8 trillion price on our heads. And, uh, Mike th there's articles out here, right?
Reports. Yeah. Let me, so let me walk through the fundamentals of the, of the report from JLL who's a commercial real estate company that specializes on a lot in data centers deals.
And they're saying that they'll be, um, 200 gigawatts of data center capacity by 2030, which is a 14% compound annual increase with about half of the workloads on those environments being AI driven. And there's also saying that things will bifurcate in two different directions. One is we'll see AI data centers for training move to areas where energy is super cheap.
And then we'll also have data centers that are showing up near, closer to the internet connection point because there'll be applications that are highly latency sensitive and we need the AI to run in real time. And they're saying that, you know, we're building out for this level of capacity and that most of that capacity is already committed for. However, they are also noting that, um, getting funding for these projects is already starting to become difficult because there are concerns that maybe we are starting to overbid to the point where we're not gonna see that level of return on investment.
And we don't know what the future of AI looks like in terms of large models versus small models and how much capacity we may or may not need. So there's a lot of unknowns here. And Alan, I know you also wrote about the fact that people are investing in data centers and these things aren't creating a whole lot of new jobs either.
So, and then as you kinda look at the, the outlook from here, what's your assessment? So my assessment is that 14% year over year growth is not enough to meet the $8 trillion number. Quite frankly.
I think, you know, I think that's actually a very conservative number to bring 200, just 200 gigawatts on by 20, 34 years from now. Um, you know, because we better make it up in the back half 'cause we got $8 trillion committed to these things. Now that being said, it's still a pie in the sky number.
'cause where the hell you getting 200 gigawatts worth of energy to power these things and, and enough water to cool 'em down, assuming that there's a market need for that kind of capacity. And even if there is it, it's a bit of a letdown, then you get into the whole Arvin Krishna argument, which is that's great, but this is a flawed model that's not profitable. So what the hell are we doing?
And then let me put one more stick on the camel's back. 1 di billion dollar data center being built. And this was a multi-phase, let me be clear, multi-phase data center, five phases between now and like 2035 were four or five different huge buildings as part of this AI factory.
And it was going to create, not, not counting the construction jobs. Yes, they'll be jobs constructing these things, but those are temporary and transient permanent jobs created in the data center. All of 37, 3 7.
Now, yes, it'll generate a lot of property tax though. The, the, the locality, the municipality in the article you'll see is talking about a 70% tax abatement if they do this. So they're only gonna collect 30% of the actual property taxes that are due there.
What's it going to cost people living there and increased energy expenses? We don't know. But for 37 jobs, unless we're gonna take all that property tax and pay it out to people in some kind of basic income, whatever they call that, right?
Uh, the basic income, everyone will get on the dole and on the government and we could all sit home, drink iron head beer, watch football and t-shirts or something. What, what exactly are we, what is this the future we want? Is this the, you know, this ain't Star Trek.
No, but you know, I think a lot of these things are also popping up in, in economies or are regions that are desperate for something, right? Um, I present to you my home state of Louisiana, uh, water soaked, uh, oil and gas soaked Louisiana, which they have high hopes for, um, for data centers there, right? And, and so Meta's got their big one in the northern eastern, uh, uh, corner of the state.
But now in my, uh, the, the town where I grew up, Shreveport, Louisiana, they're just wanting to build a data center, uh, you know, in town basically. And the planning commission, uh, nixed it as did the citizens, but the city council just over overruled them toward the end of last year. And that was the big discussion.
What are the resources that are gonna be taken? What's the yield for us? I mean, this is an indiscriminate data center.
Nobody knows what it might, you know, who might attach themselves to it. But, you know, there's a, I think an estimate there that it would be no more than like a hundred jobs. Yeah, no, they're not, they're not laid these data centers.
They're not laid. Can I, can I make this, can I make this political? Because I think this is all really politically tinged.
And I also think it's that part of this tech bro, uh, mandate or dream. So they want, and they promise to spend billions of dollars on these facilities, trillions and the trillions, right? And the White House says, oh, we're manufacturing in the us we're gonna build in the us we're gonna bring jobs back to the us.
There's a total disconnect. But just based on what you, what you found out, Alan, and, and what Terry just mentioned, there are gonna be a lot of these facilities not employing very many people and who's gonna benefit most or the, the, the tech companies that are using, or, and I'll tell you who else you gonna better, they're passing the cost along John. It's the real, it's a real estate play.
And look who's the president? Absolutely. This is When Lauren Hammer, everything looks like a nail, You know, and I, I, and I don't mean to be the guy who stir the pot, but this really does p**s me off.
Wait, wait, wait time, Terry, will the citizens of your hometown vote out the city council over this issue, even No part Of Louisiana? Not Because they, they consistently vote against themselves, you know, on, on just about everything. So the city council will probably stay right in place.
Maybe they'll lose one, you know, one, one seat or something. But Billy Allergy, But it's, you know, there's all this hope. It's a depressed place that city, you know, when you look at it.
Mm-hmm. Growing up it had 250,000 people. It's like about 180 now or maybe less.
There's just been a, a flight out, even kind of starting with my generation of leaving town and going to Dallas or going to New Orleans or going someplace else where there's more economic opportunity. So I think people are pinning their hopes on this because there's some desperation there. And it's also, you, you Know, It lives and dies on oil and gas.
It's in the middle of the Haynesville shale. It lives and dies. You Know, you, you, me, you mentioned meta in this facility in Louisiana that made me think back to a couple of years ago when I was in Kansas City and the outskirts of the airports, which is pretty desolate area.
Honestly. Meta was building a major data center, and this was the hope and dreams of everyone. Oh, this is gonna make us a, a tech center.
And I, when I see this, it just, I Mean, it just happens time and again. So that, but that's the fallacy of the data center dream. It doesn't make you a tech center because quite frankly, where a data center is located really has nothing to do with the jobs that, that technology is, is enabling and empowering because, well, I I will say one thing about the Shreveport area, and this is maybe the only thing that could help change for, for good for them is Barksdale Air Force Base, the SAC command is right there.
That's a very important base and it's highly, they, they've developed a highly technical, you know, staff and whatever. And, and so look, I there's no doubt that military bases are hub zones or development zones, right? Supporting the base, supporting the soldiers there.
How much Is that gonna be, you know, how much does that really yield for the overall community? That's not the data set. Here's the problem.
Our economy, and so much of, you know, Mike, that's why I I, the the study you cited to start this whole conversation from the real estate firm, I, to me it's suspect because it's a real estate firm. They think of jobs as construction workers. I've got carpenters, electricians, concrete folks, a HVAC people, and it's gonna take us three years to build this billion dollar colossus.
And they're gonna, we're gonna invest a billion dollars in the real estate and the building of it. We're gonna have a shiny building. And, and so much of America, so much wealth, not just the current occupant of the White House, so much wealth in America has been created by real estate.
You know what they say by land, god's not making it anymore, right? Yeah. And, and so we are geared towards real estate deals like this, right?
And that's why you see people like Trump and Kushner and, and these real estate folks, this is something they understand. They may not know Jack squat about AI and GPUs and what Jenssen's talking about, but they know about real estate and construction. And that to them is the, the, the, the grail, not the jobs that are gonna be there once the construction's done.
Right. And if we don't wind up using the data center, there's money to be made and tearing it down. But I also think the locals are also, uh, they're also locals are not counting on the fact that if, you know, if you talk to folks in Virginia, they'll tell you about this is data centers are damn loud.
And, you know, suddenly, you know, that is not just some quiet building sitting on the corner. This thing is starting to, you know, hum in your ear every day and it becomes part of your, your life. But, but Mike, we're a country that accepted black lung disease for people to go and work steel mines or iron mines.
Well, and we're going back to that. I mean, we're reduce, we regulation is They don't care. I think what they will care about is when their electric bill goes up, then they'll, so That's, that's interesting because it's, it's CES that's, that's an undercurrent these companies are trying to get ahead of that argument about in terms of energy usage.
So Lenovo is, is going overboard. And then at the Nvidia events, so I'm trying to, I'm trying to figure out the password is for the, for the wifi at the event, and the events password is green, you know, fill in the blanks. And, and it's just, you know, it's just this, they started a, a corporate blog about how they're environmentally conscious and how they're responsible citizens.
So that's, that's part of, of selling the, the dream. I think. I think Matt, I think Matt is gonna decide that paying the electric bill for all the locals in Shreveport or wherever the hell it is, is around the era.
So they're gonna make that issue go away. Yeah. Well, I wanna, I mean, I, I didn't get to read the article, but I sort of bookmarked it someplace there, there's a huge thing out, uh, just a few days ago on Memphis, right?
Because there's that, that data center that's like in Memphis or right in that area or whatever, and the quality of life issues, like the quality of life and the, the problems that residents have been having, I think Noy was, uh, one of them, Alan. Um, you know, it, it just, people just don't think, but I was actually encouraged. I've been on a couple of, uh, threads online, uh, with, with, uh, different groups in Shreveport and there are a lot of knowledgeable people who, you know, were kind of saying, you know, we gotta think about the noise thing.
We gotta think about how much, you know, we're, we're footing the bill for the power where, you know, what's, where's the water gonna come from? Yes, Louisiana's soaked with the water but what, you know, uh, that doesn't necessarily translate into the resources that a data center needs to you function. So anyway, a robust, a more robust discussion than I thought.
But people have gotten fairly astute down there on some things, because that's Mike Johnson's district and they've had to pay attention to what, uh, Yeah. You know, the one, the one thing that is, that I really like about ai, one, the one thing that that undercurrent I really like about the whole topic about AI is people are more, more engaged with this technology than any other technology I've ever come across. They, uh, have an active, um, curiosity about how it's going to impact them, and they're actually doing some of their own research to, to see what the repercussions are gonna be.
'cause it's so inevitable. So it, it, to me, it's encouraging actually that people, uh, are looking into the impact in line. I, I think AI is the technology people love to hate.
I think people are distrustful of it. You know, they, they see it. Yeah.
They wanna learn about, yeah. And so they wanna know, but they, they don't like it. They don't like, the more they they read, the more they learn, the less they, And they're duped by it all the time.
I mean, so, Yeah. We'll see. Hey, we, we've gotta, we've gotta transition once again, I gotta come up with a better word than transition, but, um, we, we Really, We, we need to move along here to our C block, and we're not gonna talk about robots and jobs being taken.
We're actually maybe gonna talk about some new cybersecurity jobs. Like, oh, we're always talking about new side, the, the o the, the, the mythological cybersecurity jobs gap. Right.
Between skills and jobs. But Mike, we, we've got a new, a new article out on this. Yeah.
Yeah. Terry wrote this based on a report from, I think it's KPMG, right? Yeah.
And they're forecasting that we'll see a significant increase in cybersecurity spending in 2026. And this comes off a year where a lot of people pulled in their horns 'cause they were uncertain about the economy. But maybe the economy's not as bad as people thought because well, uh, we don't know.
Or in certain segments is better than other places. But whenever the driver is, it also seems like the nature of the battle is changing, Terry. And Well, we gotta invest to keep up the fight.
'cause the bad guys are changing their tactics. Well, yeah. And I'm just gonna, I, I, I'm not gonna throw a lot of water on this, but just gonna harken back to something that Alan said about the future, that, you know, it, it, it's slow and coming until it finally does.
Right. It just, uh, you know, it, we think it's gonna, I think that's the same thing with like cybersecurity budgets. Um, uh, we start saying, you know, oh, they're getting bigger.
They're getting bigger until they don't. Right. Or until they cut back.
So, I, I don't wanna be too pie in the sky about, you know, the, the results of this, of this, uh, study. But yes, it's the KPMG cybersecurity survey, um, for 2025. And, you know, I think their overall message here that, so more than half of the people surveyed said their budgets were gonna increase between six and 10%, which is, you know, pretty significant stuff.
Um, but I think the overall, uh, you know, analysis by KPMG on this was that, um, maybe security like zooming up like this or going up like this is gonna point to this sort of boom that's happening. That people and organizations are finally seeing, um, cybersecurity as fundamental to business or an accelerator for business and not just a cost center, which we've been talking about forever. And key to the, in to innovation, you know, reducing risk and all of that.
That these are all topics that, um, I think we discuss quite, quite regularly. Um, you Know, I've been in security a long time, Terry. Mm-hmm.
And, and like, like, like Spring follows winter and Summer follows Spring, and these are the days of our lives. Every year, about two to three months before RSA, we start seeing the surveys come out. And lo and behold, security is the top priority.
It is eight, number one, top of the heap. We are putting our budgets in. I can't wait to buy the latest technology because the bad guys have gotten smarter, but we're catching up.
And, and Ladi, Dodi do da. And then sometimes right after RSA right before Black Hat, we, we, we start hearing how we're losing the battle. We've had more breaches this year than last year, and historically high.
And the cost per breach is terrible. And it's the same old, same old, and our corporate fat cats still have T-Rex arms that don't reach their pockets. And those budget money never gets spent.
Well, that's, yeah. So that's, I could have wrote this for them and saved them a couple of dollars. I could have had some robots do it cheap.
Um, Well, you know, yes. And I mean, that's what I mean, it's like you get these kind of, oh, this real positive thing, but then suddenly the reality is not, uh, it doesn't, it doesn't bear out. Right.
Um, but I, I think part of what was interesting about this is there's a lot of effort going into, um, resilience. And then not, not, you know, not surprisingly, our old buddy AI is driving so much of the security concerns and so much of the pitch for dollars. And, um, and they, they have some traction now within, maybe because of what we were talking about.
People are doing the research, they, you know, are interested. Uh, they're AI curious, right? But they also are AI averse and, and they're worried about what it's gonna mean for security.
And so, uh, they're appropriately putting money toward that. But how it actually gets used in the future, or if it gets used, or if it makes a real difference, that's an, those are other questions altogether. I don't, you know, Agreed.
I, I think the other thing, you know, one of the, the cycles I've seen in security over the years is, let's call it the innovation cycle, right? We have years where, you know, you get the VCs ringing their hands or, or lamenting, or there's no innovation in security. We don't see anything new.
It's the same old, same old, it didn't work before. What makes you think it's gonna work now? And then they're looking for innovation, you know, and then someone comes up with a next gen firewall or a next gen this, or a future proof that, and, and all of a sudden innovation springs like flowers, you know, crocuses in the spring, um, AI is that innovation point for the security industry, whether it's using security to make our AI more secure, right?
So let's, let's secure AI generated code. That's innovation. Even though, what's the difference between securing AI generated code and human generated code?
All code is code. It's the same technology, but we're gonna slap a let's secure AI generated code security tool on it. And ooh, I've got innovation and everyone gets excited and I'll open up my budget a bit.
So it's securing against ai. Or the other fact pattern you're gonna see is I'm using AI to make us more secure, right? Here's my innovation.
What we were using before was not AI enabled, so it sucked, but now I've got AI and it's gonna be a lot more better. It's securing your code or securing your infrastructure, or securing your insider threats or what have you. And so AI rep AI itself, the fact that it's AI enabled represents the innovation, right?
Either one of those fact patterns or enough to get corporate boards to write checks because they see innovation. It's like in politics, people always vote for change in security. They vote for innovation, Right?
And, and that's, I think one thing that this study, you know, if you dive deep into it, sort of touches on in the people that I talk to, is that idea of innovation and that idea of security cutting across business rather than just being confined to the security question itself, right? It allows for innovation, it allows for risk reduction, you know, so supposedly. Um, but if you think it's gonna create more jobs because these budgets have gotten bigger To Shreveport baby, I would say I'm hopeful on the following points, right?
I think that AI will significantly reduce the time to investigate security incidents. And I think we raised an inordinate amount of time doing that. And so I'm hopeful that the job itself will become a little more enjoyable, and maybe I'll even be more successful, simply because, you know, I can ask in ai, you know, what is the probability of the root cause of this thing?
And it'll come back to me in something in natural language. I may not take that as gospel, but at the very least, I'm like a little further down the road to figuring out what went wrong with this thing, right? And then secondarily, I think that, you know, security people, if you talk to them, they are burnt out and a lot of them are tired of, you know, running through those data analytics exercises.
And if we can shorten that and reduce that, you know, maybe the whole job becomes more enjoyable. I don't think AI is gonna replace the need for security people anytime soon. But I think that there's a lot to be said for spending some money to make that task a more successful and b, less tedious.
Yeah. And, and again, I mean, I think you're right about that, and I don't think it's gonna replace, you know, in the near term, but there is a prevailing sentiment that they're not, these bigger bud budgets aren't gonna translate into additional jobs, right? They might not, you might not be cutting jobs with ai, but the additional jobs, it's just gonna let you use your same small team and it's gonna scale because you've got the dollars and you've got AI and, you know, whatever.
It's gonna, it's gonna eliminate jobs that never existed because we had all these open positions that nobody fulfilled, anyone, nobody Fulfilled. Yeah. What was it?
The 3 million, whatever. Yeah. So maybe, yeah, the annual story about how this 3 million open positions in cybersecurity will go away.
But, you know, Never, never, there Seem to be a lot of these, like these circular narratives in cybersecurity, right? Yeah. No, yeah.
I mean, it's like, it's like, it's just an insane Yeah. Process, right? It is.
It, it, you know, when you hear long enough and you recognize the patterns, and especially when you could map them to RSA and black hat, there's definitely a cycle that's controlled by those two shows. There's a cycle of security reports, news product release. Yeah.
Now, you know, that said, right, we talk about all those open positions, and this is a, an example of one, but, you know, there's a kid over here in Westchester who's got a master's in cybersecurity. He's tendon bar because he can't find a job in the space. So, but he's got his degree, but he never got experience.
That may be what it is, but, you know, so breaking into the field is still not easy. No. That, that hasn't changed.
And that's the biggest thing I hear from people. You know, all these kids who actually took cybersecurity in school, I, when I came up, no one took cybersecurity in school. Well, what's cybersecurity Mean?
Or InfoSec, I know. Well, so maybe Even on a broader scale though, like, I, sorry, Terry, but even on a broader scale, not just cybersecurity, any type of people coming outta college are gonna be facing the same reality. It's, there are a lot of studies showing that right now it's our job, job market entry level is really hard.
It's a difficult market. And I remember a few years back, they even talked about in law firms how, you know, kids are coming out of college. And I know Alan, you and I both had kids that, uh, that passed the bar this year or last year and, you know, or whatever, uh, onto their careers.
But, um, they were talking about the, the, the, just the practical things that they couldn't do that now these law firms were gonna, were having to hold sessions to train kids. So it makes me wonder in the area of security, and, and given how hard it is to get in, if there's better ways to coordinate between states and the federal government and businesses and, and colleges and universities, to have a pipeline that's stronger. So you're not just, you know, you don't just shoot out of the university and then, oh my God, where No, I think it goes to are, are these programs, cybersecurity, for instance, preparing people for the real world, for the real job.
That's why I like programs like Northeastern University that has their, uh, co-op program where they actually help you get a job while you're still in school. And you, you, you know, six months of your school you're working, and then six months you're in school and six months you're working in school. We need more programs like that.
I think that having some poor guy get a frigging master's degree in cybersecurity. Right. Well, and that goes back to what I was saying earlier in Detroit about the car thing.
I mean, the economic development co commission there did a really good thing about engaging junior high and high schools and then engaging universities and the car companies. So these kids would, some, sometimes know as far back as, you know, their freshman year in high school, that there was a pathway for them and a job waiting for them when they got out of university, if they stayed like, sort of on this track. 'cause everybody was on board and they built a strong pipeline.
Now, I don't know what's happened to it in the meantime 'cause I looked into that several years back and, you know, uh, pre pandemic. So I don't, I don't know what ultimately happened there, but, um, it was, they were really trying to build that strong, you know, pipeline and make it practical for kids. Like they're working on cyber projects while they were in high school and actually getting hands on experience, high school, college, and then into the real world.
So, so what impact do you think AI will have on all that? 'cause I hear from, you know, a lot of the seasoned people in security or even DevOps or whatever, that they're saying that, you know, well, I'm using AI now instead of some junior kid to take care of a task. And so there's fewer entry level positions by definition.
Well, right. And then of course, that creates a gap too, doesn't it? And pipeline further down, because you don't have people that have had this hands-on training or apprenticeships or whatever.
They, they do. You skipped that, that Either that or we need to change the education system so that the people who are coming out of the schools are not as junior as they are today. Well, That's, that's right.
And that's why I think that's a, that's a, a collaboration between business, government and, and, and, uh, education. You know, I think that's, you know, In California, in in, yeah. In California, they're trying to do that.
Newsom has tried to, tried to do this where he is kind of incorporating, integrating the government and, and the education system to better prepare students for ai. And I think, you know, it goes back to stem. Um, and I think AI in a sense accelerates this, but, we'll, I mean, again, these, these, these things are good in, in concepts, but in reality, you, you actually do need a practical education.
You need hands-on training, right. Especially when you're in college, Right? Mm-hmm.
But that's, I mean, that's it. If it's done right, you get that too, don't you? I mean, the universities work and the government works with business, and you get that hands-on training all the way down the line.
But I, I don't know, you know, it's, I don't see a lot of states committing to that at this point in time. But I, I don't know if it's the state's responsibility. I, I think, you know, I think it's the school's responsibility to prepare their students for jobs.
I think it's the student's responsibility. I think it's the market at play. I think industry has to tell universities this.
Oh, Well, yeah. In California though, it's just because, like, it's such a vested interest though in terms of, in terms of the tech education that try to keep the jobs within the state or keep the companies here. Um, that I think that that's, it's purely motivated by that.
And the educators have to, my wife's a teacher, so it's, it's, it's a frustrating process and, and given how, I won't get into the politics and education system, but it, it, things move slowly, grind slowly Everywhere, Right? But back in the day, you know, you used to become like a, if you wanted a job in a space, you know, you, you basically were a junior apprentice for like three or five or four years before you actually got to be a full-time employee or whatever it was. So maybe were going back to the future.
I don't know. Yeah. There was also the Apprentice, That's where I came into this conversation, thought this convers First Trump administration.
There, there was an apprentice program that they was much value who, that Mark Benioff talked to about And where did that go? Fired The Apprentice. You fired, you're done.
Trump and The Apprentice. Yeah. Yeah.
All right. Hey, we're over time though. We gotta end this live text on gang.
We hope you've enjoyed it. Hey, appreciate the, uh, con the comment on LinkedIn from Mr. Singer.
Always appreciate all comments. We'll try to incorporate them as we go forward. But we're out for now.
We've got Textron TV coming up behind this. And, um, Terry, John, Mike, thanks for joining, John. Enjoy the rest of, uh, your Vegas trip there, Terry.
We'll, I'm leaving soon. Okay. Well, flight.
I'm getting the Hell outta here Now. Alright, well, you've put your time into Vegas. You got, you got your three day limit on Las Vegas, right?
Yeah, I, I hit the 72 hours, Mike. I'm Done. I get it.
But until next time, there's Allen Humel for the gang. We're out. We hope everyone's enjoyed it.
Hey, everyone, welcome back here to Tech Drunk tv. You know, as we go into the new year, I couldn't think of a better way to kick it off than with my friend James Wickett. com, like in 20 13, 20 14, of course, uh, especially as we got into the whole DevSecOps thing, James was one of the, was one of the early kind of prophets in the wilderness, if you will, with rugged DevOps and all of this stuff.
And I always knew he was destined to have his own company, that he had that passion to go found something and build it. And so I was thrilled when he started Drive Run Security. But I, I don't wanna tell James whole story.
James has to tell his story. James, welcome to Tech Drunk tv, man. It's good to see you.
Yeah, yeah. Thanks, Alan. I, I appreciate it.
It is, it's, uh, it's been a, it's been a fun journey, hasn't it? Like, you know, coming through. Yes, it has the Devon DevSecOps, the DevOps era, kind of just all that stuff we've been been working on, and, and you, you've really done a great job kind of building the community, helping people understand what's, what's going on, uh, with boots on the ground, uh, in the world.
So we always appreciate, um, your, your coverage. Appreciate You, man, your Leadership there. Yeah.
Thank you. Yeah. I appreciate it.
Well, Yeah, talk to us. It's, and, uh, yeah, yeah, sure. Okay.
So look, well, what's the big deal, right? Everything's AI these days, right? And everybody's talking about it, uh, six ways, uh, differently.
And, and, and I think like, there is, there's a issue with, uh, AI is like, we're building AI applications in all the systems and all the, uh, uh, in all, all the workflows we have in, in any enterprise, in any organization that we have today. And the, the issue with that is that, um, we don't really know, uh, the risks that we're facing, right? Like, we're, we're taking sort of like an untrusted compute model, and we're putting that into, into our system.
So, um, but, but to back up on, on that, like, uh, Alan, I started the company because I felt like, yeah, we did the shift left thing, but like, man Shift left really never delivered anything for developers that was as tangible as I think that we wanted to, right? Like, we saw incremental gains, but we never saw, like, you know, I, I kind of, I looked up and I, I knew like developers weren't having a good time. And I talked to my co-founder Ken, and I was like, we gotta, we gotta start something.
Like, we gotta help developers have a good time with security. And a lot of it is because we took a lot of tools as an industry, I'm just kinda using a, a stereotype here, but as an industry, we took a lot of tools, uh, that were made for like a different era, a different user, uh, and kind of for forced them on developers, uh, sort of like retrofitted that. And so, um, that, yeah, that's, that was kinda like the genesis of like why we started Dry Run Security.
'cause we wanted it to be like, you just dry run your code and security just sort of happens for you. And like, and, and it, and it makes it easy. Uh, I don't know if you remember when we first started, we were always talking about the security buddy.
Like, you know, we mm-hmm. We didn't have the language of agents. We didn't, you know, but even from the very beginning, we were like, yeah, we're gonna build, we're gonna build a security buddy, uh, for developers, and it's gonna be like right there helping them, helping them make this happen.
Um, and so, uh, the companies, uh, we're, we're now in our, we're in, we will be entering our third year in January, uh, kind of moved out of, out of stealth and into, uh, shipping, um, uh, products for, for customers. And like, um, right now, I think we, this, this month we'll have done 250,000 code reviews then this month alone for our customers. And so I remember when we were happy, we did like three in a week or 10 in a week, you Know?
Yeah. No, know that you know's. Called Scales my friend.
Right? It's been Good for you. Yeah.
It's been growing. Yeah. You know, you know, James, in hindsight, so I'm gonna ask you to answer this truthfully.
Okay? Yeah. In hindsight, in hindsight, it seems like dry run security, its whole mission, and the idea behind it is like tailor made right?
For AI and Agentic ai. Yeah. Were you thinking AI when you guys first started talking about this three, four years ago?
No, no. We, we launched in, um, or we, we kind of went to go fundraise in 2022. And the thing that we were working on at that point was, um, how to have better sec like security that didn't like waste everybody's time.
And so we were trying to make some connection points between DAST and sast. And the real reality is we were really hunting for like, what's really exploitable and what's not. I mean, I know that we've had a lot of talk about reachability, but we were really on the hunt for exploitability.
Um, and so that's, that's what we did our, in fact, our first six months, we, uh, we built some really cool stuff, uh, that later we've more or less kind of trashed, you know, because we had people try it. And a, it was really incredible to get people to try it. Like, I couldn't even get my friends to take the five to 10 minutes to try it.
They were like, oh, yeah, yeah, sure, next week. Okay, I'll be free next week. Right?
And so, um, It's always next week. Yeah. And so we can, but at the same time, while we were building that, we were also, uh, doing a lot of experimentation with ai because we saw, even from those early days that AI would be something that could help us deliver, uh, you know, our documentation.
We felt like there could be that chat buddy that could work out there, there could be some other components that we could, could put in place. But as we experimented with more and more, uh, we really built AI from the core ground up. So right now, um, when we talk with customers, we talk about our four key agents that we ship.
We ship our PR code review agent. We ship, we ship, um, a, a custom policy agent. We have an insights agent, and then we have a, a new agent that's gonna be launching, uh, in January that we'll, we'll be talking about coming soon.
Um, and, and, uh, you know, spoiler alert, it's gonna be looking across, you know, all the code bases and kind of do some really interesting stuff for folks. Very cool. Yeah.
Very cool. We'll, we'll, we'll be on the lookout for that. Yeah.
James, before we go further for people wanna get more information on Dry Run security, what's the website? Yeah, it's just dry run security. Um, and, and, uh, our, the, the kind of the, the guide, one of the reasons, like we were, we were talking about, um, what would be good for, I think for your audience and your listeners is like we, uh, we wrote Building Secure AI applications, which is a in depth 40 page guide, uh, with a reference That's In depth controls on it.
Yeah. Yeah. We, we kind of were like, we wanted to put a lot of bones on, or a lot of meat on the bones for like the o os top 10.
And so like the o os top 10 for LLM applications, which is radically different from the O os top 10 for, you know, regular web applications, regular. Yeah. Um, You know, before we jump into that though, James, I feel like, you know, everyone talks about AI today, as you said earlier, six ways from Sunday.
It's all people talk about, but we we're, we're, we're really crappy on definitions, you know? Yeah. So what, what is an AI application to you?
Okay. Yeah. So what Defines an AI application?
Yeah. When, when we think of AI applications, and whenever we're talking about, uh, people using, um, LOLs inside of their product. So this can be, um, small things of like, Hey, I'm, I'm putting a, a new chat bot inside of my, um, on side of my website to interact with, with users, and I'm providing this, uh, with that, and I'm hooking in some backend data for that.
Um, it could be, uh, internal, uh, applications. It can be MCP servers. Uh, it can be ways you're, you're leveraging, um, uh, LLMs or SLMs to inside of your, your applications.
And so it, we kind of think of it about broad scope, but it's a, uh, and, and I know that, you know, you just asked me to, to define it, and I give you another kind of broad definition, but it is like anywhere in organizations where, uh, they're leveraging and putting lls into production for, you know, usage with either internal data or ex external, uh, facing stuff. Excellent. Yeah.
I, you know what? That's as good as any 'cause I, I think one of the problems we have in with AI these days is just agreeing on basic definitions, right? Yeah.
And, and so I think that's a good way of looking at it. Um, I think it's Alan f for me, it's like it, whenever you put an LLM in, you're, you're changing the risk model for your application. Um, because, because now you've given it access, you're, you're, and, and you've given it access to different data types.
You've given it, um, uh, access to do, uh, some probabilistic decisioning, um, on your, on your system. And, um, totally. Okay.
I think that, I think I'm very bullish on, on that. I think that's really great. But, uh, it does change, like what, um, what you have to look for from like a risk perspective.
You know, for me, James, so this is before my time, but you've probably heard these stories too, right? When the telephone first came out, it wasn't like person to person. Yeah.
It was kind of a party line where, uh, you know, anyone could listen in. Yeah. I think when you bring an LLM in, I mean, the good part of it is that you have access to the entire corpus of that ll m's information Scope.
Yeah. Scope, yeah. Yeah.
The bad part of it is everything you give give it, it basically ingests as well if you're not careful about it. Right. You know, unless you take precautions and, and so you're getting this information from everywhere and you know, the old saying crap in, crap out.
Right? You don't know where that information necessarily came from. Yeah.
And you don't know what, what's going in there. So, and so the, it's almost like mirror image of, of security issues around these AI applications. Right.
And, and I, I assume in the guide, you, you've gotta address both of those. That's right. Yeah.
Yeah. You can, we, uh, have some things like, uh, we, we talk about excessive agency, uh, we talk about, uh, the different types of guardrails and policies after you put in place, uh, for that, um, we, there, there is, yeah. It's, it is, it is very different.
And like how you, how you think about what, what data it has access to is, is like, gotta be, you know, forefront, forefront of mind. And, um, I, the thing that, that's interesting to me, Alan, is like, um, we haven't, we don't have conversations where anybody's not using it, like everyone's experimenting with it to, to some degree or another. Um, and then there's, there's a bit of a, a hurry up on like, well, what kind of, what kind of controls or how do we safeguard this?
Or whatever. And, and that, that conversation, um, I think that's gonna be the, one of the main conversations we have in the, the next year, two years, uh, is, is around that, you know? So, But, but you know what, James, that's not a new conversa conversation for security, is it?
Right? No, it's always, you know, you guys, hey, the train's pulled outta the station, hop on this moving train and make it better or make it secure in this case. Yep.
But, you know, but the chain's already moving and, and so, you know, we can't dig in our heels and say, Hey, go slow or, or be careful. No, people are going as fast as they can, it seems, because there's such pressure to AI eyes, ai, everything, you know? Yeah, yeah.
Um, James, well, And, and there's that discovery of value the business needs the value. Yeah. And so it's like, Hey, look, we, we see the a path to value through through ai.
So that is a, uh, that that is gonna be a feature where security has to come alongside and, and enable that, right? So, yeah. But here's the funny thing.
Yeah. I don't know if we've found the killer app for AI yet, Right? Yeah.
Well, certainly we're, I mean, driver And security is certainly the killer app for, Okay, there you go. You stepped up there. That was a softball, James.
Yeah. Yeah. But, but you know, seriously, like we look at development, what, what you said there's a hundred percent true.
I've seen, I've seen, uh, studies, 90% of developers are using AI and helping them develop code, right? 90%. Yeah.
40% of those 90, almost half. Right? Don't trust it.
Don't trust it. For sure. 65% of those 90% think it introduces instabilities into their code base, but still 90% use it.
There's something almost illogical about that. I, I mean, what's the definition of insanity, right? I I use it even though I know, I, even though I don't trust it, even though I am pretty sure it, it introduces instabilities, I'm going to use it anyway.
Why? Because everyone's using it and they tell us that's what we should do at, at some level. What a disconnect.
Well, I, I think they, they are also seeing the value of like, being able to go faster because like, they're, like some, some engineers and, and it depends on the engineer, and I think that depends on the company and certainly depends on, um, which, uh, you know, which coding assistant tools you're using in your stack there. So I think that there, there is some, some disclaimers around all that, but yeah, I think like the, there, there are enough benefits of like how much code, uh, velocity, like we're able to see. Mm-hmm.
Um, you know, I can't, you know, we, we've been, uh, doing a lot of customer adding throughout the year, but like, and I mentioned we're at like 250,000 code reviews a month, right? But like, even within like a certain customer like slice, um, like we've seen them continue to grow faster with the same or marginal amount of, uh, developers. Now, I, I don't have like a pre-baked number for you, but I wouldn't be surprised.
No, no. So I, I have seen Two x or so. Yeah.
Yeah. No, I've seen numbers. Yeah.
The story supposedly is we're four X-ing the amount of code we generate four x That's crazy. Crazy for X. Yeah.
I don't know if we're for X-ing the security of that code. No. Yeah.
And that really is, is the crux of it, isn't it? Yeah. Yeah.
Well, and, and the, the, the real issue too is that a lot of these tools, um, from the last generation of pattern matching tools, they, um, they weren't really doing a good job before. Um, and, and not, not to, to discredit them. They had the tool that there was, there, they had, you know, regular expressions and be able to do matching and stuff like that, right.
Nor normal, normal, um, opposite of stuff. But, um, it, they, they underperformed in, um, a abilities where they had to find logic problems, uh, authorization issues, stuff that like really took like human code reviewers. And that's why we spent all the money on bug bounties through the industry.
I'm talking at large here, spent all the money at bug bounties. We spent all the money on like, uh, human code reviewers doing that. Um, I'll tell you a funny story, Alan, uh, uh, let's see, about four months ago, uh, showed up to a customer.
We ran a free, uh, free complimentary scan against their code base, and we handed them the results, um, and they said, yeah, just email it. And then, and then, uh, we, we will, we'll meet on Monday. And so that was on a Friday.
Well, on Mon on Monday, when, when he showed up, the customer was like a little bit incredulous. Uh, I felt like he was a little bit angry with us. Um, and we were kind of like surprised by that.
And I was like, Hey, what's, what's the, what's the deal? And he's like, well, I looked through this and you found 20 real issues out of the 20, the 20 issues you reported, all 20 were real. I filed bug tickets.
I went through every single one of 'em over the weekend. And, uh, and I've been using this, I won't name it, but I've even been using this other product for six years. Six years in the same code base.
They've never told me any of this. This is all like net new information for me. And so, um, I think like we have to realize like, there's some really positive benefits we can get out of all apps, of course.
And this istic One, we also gotta realize that ignorance is bliss. Sometimes There is not That there is that. Yeah.
Yeah. It's like, Hey, there is new work, but, but wouldn't you rather, I, I, I feel like, and maybe I'm too much of a purist, but I would rather know about that earlier. Um, and I wanna shift that left and then, and instead of paying the penalty of the bug bounties, the No, I, I, I do, I do think to a certain degree, ignorance is bliss when it comes to these things.
Yeah. No harm, no foul, because Yeah. And this goes to the whole, as you know, I've been in security a long time.
I think there were a lot of people, very content to be just another zebra in the herd and hope that the lion doesn't pick them on any given day. Right. And, and so Yeah, I know I got some os top 10 issues.
I know we've got some stuff, we'll get to it. Yeah. But, you know, I don't have the resources.
I don't have the know-how, I don't have this, that, or the other thing, why I could fix all these things now. And I'm not banging anyone, but it, it's almost the nature of the beast insecurity, right? Because we're so used to just, we do the best we can.
Yeah. Right. It's not perfect.
Yeah. And, you know, there is that mentality that I think we have to overcome. James, I want to turn back to this guide.
Yeah. Yeah. 40 pages chock full Chalk Pool of, of best practices, emerging practices on building and securing your AI applications.
Yeah. If I had to say, James, what are the three biggest things people should take out of this? Or they definitely should go check this out.
Yeah. What do you think they were? Okay.
I think that, yeah, that's, uh, I think that, um, number one, we put reference architectures in there. So we put, um, we've taken a couple slices of what a, uh, AI application looks like, and then we put in like, the type of controls, uh, you can affect both at a runtime and a code level. So I think like, just getting it for the reference architectures, that's, that's really good.
And, and it's all free. You can get it on our website. If you wanna download like a portable, like a PDF or something, um, you can do that.
But, uh, it's all just like available, uh, publicly ungated on, on our website. Um, but so, so, so one, one is the reference architectures. They're incredible.
Two, we, um, we've kind of said for each of the, uh, oasp, uh, uh, areas, uh, functional areas, like something like excessive agency or prompt injection, we suggest vendors, uh, like that you can look at both on the, on the runtime and on the, uh, on the code side, uh, to help do prevention or control or things we think that are interesting there. Um, so if you're kind of in like a, you're in a shopping kind of mood or you have a problem with this kind of thing like that, that is a real helpful, uh, guide, uh, for that it helps you isolate, uh, which ones would be good. Yes.
Dry run is in there. We're of course, like we're, we're a vendor, but like other companies are in there as well. It's not just like a buy dry run and solve all your problems.
It's, it's far from that. Right? It's just like we're, uh, sure.
Yeah. We're one, one piece of the pie there. And then I, I, the one thing that I like, uh, the most about the guide is that we also tell stories like concrete, uh, examples, either from the news or from our own, uh, our own, uh, experience.
And so, um, one of the things that, that's a funny one for us is, uh, uh, I think it was in July, Alan, we spent, uh, maybe two grand, uh, $1,800 in about a 24 hour period for one customer who wrote one policy that went a little bit haywire, and it was running nonstop and doing that. So, um, whenever people commit code, we have our custom policies come in and they're able to look for, for problems. Um, and then they also have access to go back into the code base and find, and I'm sorry, excuse me.
They have, they're able to go back in the code base and find, uh, other code that might be related to the problem that you've described. Well, this, uh, policy didn't have enough guardrails internally on that, and it started looking across the whole code base and trying to like, do a bunch of analysis and it just wouldn't stop kind of pulling in GitHub. This is one for one of our bigger customers.
And as they continue to write, uh, more code, I think they probably shipped 50 or a hundred port less during that, that day or that that time period. Um, our policies, uh, you know, it is just, it's just threading out and it's just like trying to, you know, look at, look at all the code and do a ton of analysis for it. So it was basically running hot for, I mean, 24, 30, 30 hours.
So, so, you know, we have our own, our own internal scars. You know, we're building, uh, AI systems just like everybody else. And so, um, you know, we're, we're a small startup, but I could imagine that happening to like a, a big, uh, you know, you know, fortune 100, fortune 50 company, and, and that being, uh, you know, a half a million dollar hiccup or a million dollar hiccup, right?
So, um, but even for us, like, for us to spend that amount of money in, in that window is, was, uh, was crazy. But that, that's the kinda stuff is like, we're, we're trying to add in, uh, uh, we as the organ, as the, the global we, um, we're trying to add in LLMs and build AI applications in our systems, and it's just, it's gonna impact us in ways we, we didn't really see before the type matches for what we've had before, right? It's like, yeah, we've pegged all of our CPUs or we've blown out memory, or we've, or the connection pool's expended.
Like we've, we already have that, that model of, of working in, in, uh, in, uh, our computer science lives. But yeah. Um, yeah, this is just a new way for us to kind of see some of the same patterns, uh, arise that we've had before.
So it begs the question, right? So I think back, James, the first company I started Tristar Web. Okay.
95, 96, we, okay. We became what became a hosting, we didn't call it hosting, but eventually it became known as web hosting. Yeah.
And, you know, I used to monitor the, so I was the overnight, you know, it was your company, you gotta, you're the chief, you know this now, right? Yeah. You're chief cook and bottle washer.
So I would go overnight and monitor things and Yeah. And those are the things I used to have to watch my CPU usage, my disc usages, the bandwidth, you know, all of the monitoring kind of dashboard. Yeah.
You think we'll have a, an AI security dashboard, is that something drive, run? Yeah. Maybe has in its future?
Yeah, I think we, we kind of stop at the build the build time. So we're really concerned with, uh, we do provide a code level insights across like all the ways you're using, uh, ai, that all the MCP, uh, uh, services or, or that you might be, uh, discovering. Um, but yeah, I think that there is like, uh, kind of a host of like, uh, like we're seeing a rise Phoenix and some, uh, LLM uh, operations, uh, dashboards spin up.
And so yeah, I think we will have more of an ai, um, ops, I, I guess, yeah, we'll have ai, AI Ops, not AI ops that we used to use that word, a new, a new version, A new AIOps. Yeah. You, yeah.
Words are hard, right? But, but I, but I think like this ai, the, the, an AI SOC too, but the mm-hmm. But, but not just, I think a lot of the AI soc companies now are mostly concerned with like just replacing the, the SOC function with AI function or augmenting that.
But I think to your point is like we, um, we'll still need some sort of like, what are all the AI agents doing, right? And then, and then understanding like their, both their access and like keeping in, keep an eye on it. So, um, no, you know, I think one of the things that's helpful for me, and it's always a frame frame is like people ask, well, why is this so different?
I'm like, well, you have, you had developers, uh, writing code and that's a probabilistic system. And, and, and so like a deterministic system, like a pattern matching tool just was, was always struggling to keep up. Now we have like, yep, a probabilistic system developer using another probabilistic system, uh, ai.
Mm-hmm. And, and so, um, that is not going to result in like a better outcome for, you know, the, the, the pattern matching approaches, right? Do you actually need another, It's not like a negative number and a negative number equal a positive number.
Yep. Yeah. You actually need a, uh, LLM based AI security system looking for that.
And we use internally even we have like our exploitability thing that I mentioned at the top is like our, uh, you know, we have a way to judge, like we use LLMs as judges of the other LLMs performances and like, so the agents, you know, kind of will put that pressure on each other. Very cool. Yeah.
James, I'm assuming the guide is available to anyone who goes to drive run security. They could download it. Yep, Yep, yep.
Dry run security, there's a big, uh, there, it's either under our resources tab or we have a banner. Uh, and we'll have that banner up for, for several, uh, several weeks here. Um, and, uh, probably even through RSA, um, and kinda go check that out, but we'll have that.
Very cool. We're, we're doing, you know, this year for RSA, we usually do the DevSecOps thing on Monday. Uh, this year we're doing it on AI native dev or securing AI native dev.
Yeah. And we've got like Patrick and, uh, guy PNI from that community coming down to talk and stuff. It's, it's gonna be interesting.
That's great. Looking Forward to it. Hopefully.
I'll see. Okay, I'll, there, I'll be there. Yeah.
Well, I count on seeing you. It's gonna be fun style. I'll talk to you about it.
Anyway, James, we're about outta time. I want to thank you for coming on here. Continued success.
Keep doing what you're doing, a dry run. It's, it's exciting. For those of you watching this go to Dry run, do security, download this guide on building secure AI applications.
Can't hurt James. Happy New year to you and the family, and I will, uh, speak to you soon. Speak to you soon.
Thanks, Alan, for having me. All right. James Wickett, CEO co-founder Dry Run Security here, talking about their new guide on building secure AI applications.
We're gonna take a break on text and we'll be back. Hey, everyone, we're back here with our day three last day coverage of, uh, our time at AWS reinvent. Uh, this guy's no stranger to our tech strong audience.
He's always either on a webinar showing him how to use Kubernetes, trying to make Kubernetes easy. Some say that's an impossible dream. Um, or on tech drunk TV talking cloud native and KU with me, he's my friend Andy Suman of Fairwinds.
Andy, it's great to see you. Good To see you. Thanks for Having me.
You know, for people who haven't caught you before on either tech drunk TV or any of the webinars, give 'em a little bit of your background. Yeah, Sure. So I'm a long time infrastructure guy.
I've spent, well, my entire career working in infrastructure. I spent the last nine years working exclusively with Kubernetes. Uh, now I'm the CTO at Fairwinds, and we help people run Kubernetes.
We try to make it easy, like you said, And like I said, in some cases it could be a bit of an impossible task. But, you know, it's, it's funny, Andy, we, you know, we're, we're sponsored by Suor. Uh, you're pseudo man.
We're sponsored by Susa here at, it's the last day. I'm getting a little punchy. It's, it's A long, uh, You know, we're sponsored by Susa at, at, at here at AWS reinvent, and we've been spending a lot of time talking to the, uh, rancher guys about multi cluster Gotcha.
Kubernetes management. I'm sure that's something that's near and dear to you. Yeah, I mean, we manage quite a few clusters for all of our customers.
We're familiar with rancher, lots of, um, lots of multi cluster stuff. I think, you know, the one question we all have to ask is, um, where's the data live, right? Yeah.
Everybody was there. Like, we wanna go multi-region, we wanna go multi cluster. And I say, that's great.
Where's your data gonna live? Because that's the thing that's harder to move between clusters. I, I agree with you, and especially in a world of data sovereignty and, and all of those things that you're dealing with, right?
Absolutely. But you know, what I found, and, and maybe, and I might be wrong 'cause I'm not the expert you are, but a lot of time multi cluster Kubernetes happens quite by accident, right? You're, you are doing the Kubernetes project over here and you spin up a cluster.
I'm, we're in the same company, we just don't talk. Yeah. I spin one up over here.
Jill spins one up there, Bob and Harry over there, and before you know it, damn, we got four Kubernetes clusters we're managing, but they're all kind of standalone. But you know, okay, now we gotta get efficient and we wanna bring 'em together. Yep.
So I, I call that like the accidental multiple Kubernetes cluster. Yeah. We have a name for it.
Uh, our sales team knows this term. It's cluster proliferation problem. Uh, CPP.
Yeah. Yeah. So, okay.
We run into a lot of folks that have that, mostly large companies, lots of teams, different business units. They end up with a vast number of clusters. The cost gets outta control.
Um, and usually when we work with those folks, we work with them to consolidate into a platform. And so their end goal is let's get down to a manageable number of clusters managed by us at Fairwinds, hopefully, um, and build a platform on top of that so that all of these developers aren't managing all of their own clusters. And the goal is let's make it easy for them while also getting control and governance and policy in place.
Um, it's a lofty goal, but uh, it's can be very successful for folks. Absolutely. Wow.
Um, you know what, this was a good way though of introducing what Fairwinds does and, and that You take me right up. I did not even realizing it, but, but that is the kind of the, the bread and butter of Fairwinds, right? You've got people who have these, uh, proliferating clusters Yep.
And you have people who are saying, Hey, I wanna modernize and move over, you know, from to a mar, you know, maybe I'm going from VMware and I'm, I'm moving to another virtualized environment, but I want to go cloud native. I, you know, I want to go to a microservices architecture. Yeah, yeah.
Any architecture really, but yeah, microservices one, one way. Um, I had something I was gonna say and I lost It. It's okay.
We're live, so we just gotta keep rolling. So I'm gonna come up with something here for you then. Um, you know, I just recorded or played our shim, my shimmy says that I do every week, a little 10 minute video on LinkedIn and X, but one of the, the, the theme of this week was, Hey man, DevOps cloud native and platform engineering are alive and well here at AWS reinvent.
And, and my thought was, you know, when I first got out here, I was just like, bowled over with all the agentic AI announcements. It seemed like all AI all the time, right? Yeah.
And, um, but in talking to people and having conversations, you know, I'm hearing, well, one of the agentic AI agents, Amazon came outwards with the DevOps, they're calling it a DevOps agent. Mm-hmm. I don't know if I'd call it a DevOps agent just yet, but, but they have plans.
They have big plans for it. Yeah. But hearing a lot about DevOps, a lot about cloud native, right?
Cloud native is the choice. If you're looking for transformation modernization, you wanna move maybe from on-prem to the cloud. Not all the way you wanna do a hybrid, you want to, you know, um, cloud native has had a strong showing here at the show and, and platform engineering is no longer a fad or a niche.
It's, it, I think it's taken its place alongside the other two in, Hey, this, this is how we build software. Yeah. How we run software.
Absolutely. Absolutely. You know, I, I would think at Cube Gun we talked about, we've launched a product to help people build those internal platforms, and it's entirely based on cloud native software.
Yeah. Because we really believe that is the future of platform and where it's going. And I think we could see it from Amazon as well with the announcement of the managed ROCD and Crow Yeah.
Act or a CK, um, you know, they're doubling down on Cloud native as well. And so it's not going anywhere. It's here to stay and it will be, you know, the future of platform and DevOps engineering as we as we know it.
You know, thinking back to the rancher announcement, what you just said is, is manage cloud native, the future, I mean, you guys manage for your clients, but you are also, you could come in, set 'em up and parachute back out, right? Yeah, Absolutely. Um, now, I, I had a similar experience in the cyber.
We didn't call it cyber the InfoSec space when I was there, which was after about 15 years, 10, 12 years, I realized that most organizations just weren't capable of managing their own security. It was, they didn't have the, they didn't have the budget, they didn't have the expertise, and quite frankly, they didn't have the stomach for it. Uh, are we at the same place in Cloud native?
I think so. With the larger companies, that's absolutely true. You know, a lot of our customers, it's, it's one of one or two of those three things.
It's either they don't have the time or the budget or the people that all generally rolls back to budget or they could do it, but they don't want to because they'd rather focus on business impacting things. And that's what we enable is, you know, let us do the things that you don't have the stomach for or don't care about, or don't have the time for, uh, and you can focus on your business. Right.
I've always had that philosophy of, you know, outsource what isn't your core competency. Yeah. I learned, I also learned that the hard way, the dot coms I had helped start a company, we wind up going public.
Uh, we were what they call an A SP application searcher. So there's no cloud, there's no like t three lines of your in the gets meow internet. I remember that.
And, um, we're, we're offering hosted Lotus Notes, Oracle, PeopleSoft, and, and the lesson we learned is if it's not core and critical, those are the two things, right? Yeah. Something could be core to your, to your DNA, in your case, Kubernetes expertise, cloud native expertise or critical, your business can't run without it.
It, you don't give up things that are core and critical. Right. If it's core or critical, you might give it up.
Right. If it's not core or critical, you absolutely should give it up. Yeah, absolutely.
Right? Because otherwise you're just wasting money. Yeah.
And I think for a lot of companies, the, the intricacies of managing a cloud native environment, managing any IT environment, if you're not an IT company, you know, it, it's hard. But cloud native in particular, because, you know, Kubernetes really never came with a me uneasy kinda button. No, no.
Batteries were never Included. No batteries, security never included there Never included. No.
Uh, crazy defaults was never included. So what, what kind of, uh, you guys have a presence on the floor and everything. Yep.
Yep. What, what kind of, what are you hearing from people? You know, one of the biggest surprises to me, um, this is the first time we've had a booth at Reinvent.
Mm-hmm. Um, and, uh, in the past it's always been, you know, I always just kind of assumed that we'd get about 10, 15% of people using Kubernetes that has changed, um, in, at Oh, absolutely. Absolutely.
It's 85, 90% of people really, you Think it's that hot That I talked to are using Kubernetes. And maybe that's 'cause they're stopping by a booth that says Kubernetes on it. But, uh, go Figure.
But I'm talking to so many more people that are using Kubernetes or planning to move to it from some other container orchestration or something like that. So it's a huge number. Uh, it's, it's good to see That is, that is, you know, I, so now you got me curious.
I'm gonna have to ask everyone I talk to. 85 sounds really high. Yeah.
Uh, like you said, confirmation bias on my part. Yeah, No. You know, the big picture number I always am told is that about 15% of payloads on the cloud are cloud native.
Hmm. Now, a lot of that is because it's legacy stuff, right? Yeah.
Yeah. I'm sure there's quite a lot still that, you know, people aren't talking about. Um, and it's also that, you know, I've said this in the past is that they're probably using Kubernetes, the company is, but what percentage of their workloads are Running are running it.
That's A smaller number. And that You're right. Absolutely.
That's a, that's a real distinction. Yeah. Because I think what it is, is Greenfield products very well may be 85%.
Cool. Uh, yeah, absolutely. I think so.
Brownfield, again, people may not have the stomach to do that transformation. Right. Or the need, I mean Right.
Don't Break what's not, if It's not broken, don't fix it. Yeah. Don't fix what's not broken.
Exactly. Absolutely. Um, so this was your FI didn't realize this, this was Fair Wind's.
First time exhibiting here. Yeah. Yeah.
Coming back next year Probably. Yeah. Yeah.
Worth it. Good. Good conversations.
Good customers. Yep. Yeah.
Good show for you. All the Right people are here. Yeah.
Really good, good conversations. And, you know, the parties are fun too. The party, you know.
Yeah. We did a, uh, a thing at the Sphere last night with you. A wizard of ours was pretty cool.
That's cool. Yep. Um, wanted to talk to you a little bit about Forget, uh, AWS for a second.
Fair Winds. Yeah. Anything new coming down the pike you want to share?
Um, nothing that we didn't talk about at CubeCon, but I'd love to share, you know, our new product, IDP Quickstart. So we are, I talked about a little bit a minute ago, but we are putting together with AWS, um, they've built an app mod blueprints repository that helps you build a platform from open source. Uh, they did a couple of sessions on it this week, A couple of workshops.
Yeah. We're gonna be running another one with them, uh, next week, I believe. com if anybody's looking.
Um, and we will show you the, the product that we're going to be building, which is get you started with a platform faster than you could probably build it yourself. 'cause the biggest problem with platforms is that people spend two, three years building a platform because it's such a complex task. And so, AWS and Us together have made that much simpler, uh, kind of prepackaged it up for you, and then we can customize it to your business needs and then you can build on top of that to, to serve your developers.
So, I love it. Yeah. Anything else you wanna share?
No, it's alright. Come to reinvent. It's a long week.
It's fun. It is A long week, but I, yeah, it's worth it. You're heading home today?
Tomorrow. Tomorrow. Good for you.
Yeah, me too. Yeah. All right.
Hey, you know what we did mention Fairwinds website. com. There you go.
Andy. It's always good to see you, man. I don't know when I, well, I'm not doing you, you guys don't do Q Con in Europe, do you?
Uh, we will sometimes we'll have a person there, but we won't have a booth. No, I'm actually, I'm not. Mike ards gonna cover Q Con Europe first.
It's the same week as the RSA conference, so I'm out in San Francisco that week. Gotcha. But we'll talk, and you guys are always on with your webinars and everything else around.
We'll do something. All right. Sounds good.
Hey, we're live, we're at AWS reinvent on day three. We still got some great content coming up for you. Great interviews.
Stay tuned. Hey guys, thanks for the throw. We're here with Brian Longs, the CEO of adaptive Security, and they're in the whole business of training end users to recognize phishing attacks and all kinds of other good training things.
And they recently picked up $81 million in additional funding from the folks at Well among others, Bain and Nvidia, and the Open AI fund. But we're gonna jump into exactly what they're doing and how they're planning to do things. Brian, welcome the show.
Hey, thanks so much for having me, Mike. Good to be here. All right.
Um, some folks are kind of skeptical these days in the age of AI about what we can do to help employees recognize these types of attacks. 'cause they're getting more sophisticated. So from your perspective, what is the state of the art these days?
What can we do for employees and, and, and how can we win this thing? Yeah, so for the state of the art, um, I think it's deep take personas. So being able, you know, ai, being able to impersonate an individual with voice and likeness, but also with open source intelligence, uh, about that person, you know, what they do, where they're located, their family members, their job, all that information so they can really, you know, easily mimic that person, uh, in order to, you know, accomplish whatever the nefarious goal is of the attacker.
Um, and, you know, in terms of what we can do, you know, number one, I think we need to make the, uh, workforce aware of what this threat is capable of and how quickly it's changing. I think most people, you know, if you kind of live in the, the security bubble and you see these things over and over again, uh, you know, you, you get a little overexposed and kind of assume that everyone knows about the threat and, and understands it. Um, but, you know, the, the average person has no idea what the capabilities are, and it's gonna take a long time for us to continue to educate them as that threat changes.
So, you know, number one, I think is awareness. Uh, number two is controls. You know, most companies are still adjusting their controls for the remote work world that, uh, you know, still a lot of companies offer, um, and, uh, aren't even beginning to adjust their controls for, you know, things like artificial intelligence and DeepFakes and stuff like that.
So I think number one, awareness, number two, controls. Do these new attacks that are getting more sophisticated have any tells that people should be looking for? I mean, when you're training folks, what is it you're hoping that they can identify?
Yeah, look, I, I think over the last couple years, you know, we have seen tells, but, you know, the models have gotten smarter and smarter to get rid of those tells. You know, it, it used to be things like, you know, look for the eyes or look for irregular, repetitive movements, um, you know, things like that. But the models have gotten better at getting rid of, uh, some of those issues.
Um, I, I think if it's a, you know, prerecorded video, um, it's, it's gotten really good at it for real time generation of video. It still has some quirks. It's probably 85 to 90% there, but I, IE even if you're looking for those quirks, you know, I think in the next 6, 9, 12 months, those are also gonna, you know, kind of disappear.
So, you know, I think number one is, you know, going back to process and controls, you know, if someone is asking you to do something that breaks the process, you really need to, uh, think twice and not do it. Um, you know, number two I think is, you know, when you're asking someone is asking you to keep something secret, uh, you know, or, or, or do something urgently again, um, the, those are kind of the, the telltale signs of an attack. Mm-hmm.
Are there things that we can do with AI ourselves to recognize these AI attacks? And is that gonna be kind of a compliment to the training? Yeah, we, we can look at, at, at Adaptive, we try to think like the attackers.
So what we'll do is, number one, we will analyze the organization, uh, in order to understand where the greatest threats potentially lie in the organization based on public data that's out there. So, you know, we'll find everything that's out there on you, Mike, and, uh, across the different large language models, you know, other public sources of data. And then number two, we'll put those into the same large language models that attackers might use.
Right. And from that, we'll see, uh, what the potential ways are that, uh, someone could be, uh, attacked. Right?
And then number three, um, is we will, uh, then take steps to, you know, either, uh, run simulated attacks, um, you know, using AI in a, you know, safe and secure manner, and ensuring all of the data is properly secure, um, and see if someone, you know, falls for one of those simulated attacks. And then that, um, helps us understand where the controls break down and where the organization either needs to train that individual or adjust their controls. So even in the age of AI investments, $81 million is nothing to sneeze at.
What are you guys planning on doing? What's your strategy or what's the area of focus for that investment? Yeah, look, we've just seen such, uh, huge growth in the, uh, AI based social engineering attacks.
So things like deep fakes, deep fake attacks grew by 17 x from 2023 to 2024, with over a hundred thousand attacks just last year. And this year we're seeing, you know, over half of the, uh, conversations we're having with CISOs, we, we hear that they have experienced one of these type of, you know, deep fake attacks. We're, we're also seeing them grow a lot over new channels like voice, uh, and SMS, you know, outside of email where they may not even have monitoring and things like that.
So all that has, has led us to say, man, we, we need to move faster on our side to protect organizations, and we're gonna invest, you know, that, that new capital in adding people to our, um, r and d team. So we can try to stay, uh, as, as, uh, as a head as we possibly can. Although, you know, it's an arms race and sometimes you feel like you're ahead, sometimes you feel like you're behind.
Um, but, you know, you try to go as fast as you can. How easy is it to generate the deep fake these days? I think early on people were thinking, you know, it requires a significant amount of skill, but we also see historically the rise of things like ransomware as a service.
So, am I gonna see maybe, or maybe we already are deep fake as a service. Yeah. Look, I, it's, it's so easy now.
Um, you know, it can really be done by anyone from, you know, a young kid, an 8-year-old, or an 80-year-old. I mean, it doesn't matter. Anyone can do, uh, deep fakes now, and you don't have to be technical.
You know, you can make 'em in, in just, uh, a few minutes putting some things together, um, to, to generate them. You know, we have tools in our own platform that allow, you know, people to, to run these sort of simulations, um, with just three seconds of audio and a single image. So, you know, how you can think about that in your own life is, um, you know, Hey, is your picture out there anywhere?
Do you have a LinkedIn picture? And then number two, you know, if I call your cell phone, it's gonna be your own voice on the voicemail. If it is, then I have everything I need to make a deep fake of you.
What is your sense of how proactive are organizations being about these particular threats? Or is it something that they kinda wake up to one morning when they've already been attacked and then they go, we gotta do something about this? I mean, um, you know, I'm hopeful that maybe we're being more proactive, but historically that's not been the case.
So what's happening this time around? Yeah, I mean, I, I, I think that we do see unfortunately, um, a a large growth in these types of attacks. And as a result, you know, we, we, we do deal with folks that are coming in, um, you know, sort of to, to get their medicine.
That being said, um, you know, we have seen over 500 customers, um, just this year, um, add adaptive, you know, to their, their set of protection tools because, you know, over, I think over like 80% of them have not, you know, currently had a, a significant incident, but, um, are, are trying to get ahead of it. So I, I do think organizations are recognizing the need to, to get ahead of this quickly. And, uh, we're gonna continue to see that, you know, I, I think unfortunately grow, uh, tremendously next year because look, the, the big factors here that, that drive this, number one, it's getting a lot cheaper to run these attacks.
The models are getting significantly cheaper. And then number two, um, it's becoming much more available. com, which is a, a leading provider of large language models, you'll find over 2 million different models that you can access now over 2 million.
So there's a ton of models out there, it's really cheap to run 'em, you could even run 'em on a smartphone these days, right? It used to think, oh, I gotta get, you know, the, the newest and fastest chip that I've, it's gotta take me 10 minutes and then I'll get it. No, a lot of these things run instantly now, and they're really cheap.
Mm-hmm. Um, so what ultimately differentiates adaptive, because there's a lot of players in this training space already, but, you know, if someone comes to you and say, you know, why should we go with you guys? What are you telling 'em?
Yeah, look, I think number one, um, is on the training side, our focus on protecting organizations from these type of AI powered threats, right? So with our platform, you're gonna be able to access hundreds of different trainings that address this next generation threats. Number two, our trainings are extremely specialized by vertical, by role, and by organization.
So you can change anything that you want, uh, within our, within our trainings instantly based on your own organization's needs. Or we also have this really cool tool that allows you to create net new training content in just a couple minutes with ai. So you can say, Hey, I wanna make a new training on, you know, deep fakes for hospitals in this region, you know, for nurses, um, that's three minutes long.
And it, you know, and then just a couple minutes later, it'll make a training with all of the custom generated images and videos and animations and audio narration, all specific to that audience. So it just makes it very, very tailored, uh, to the individual organization. And then number two, we also offer phishing that utilizes these next generation channels.
So we do real time deep fake phone call phishing, um, into help desks into individuals, uh, into voicemails. We also can do SMS based, uh, phishing simulations that will drive two to three x higher failure rates, then, uh, email. And then we also do generative AI email simulations where it uses more personalized conversational messaging within the email, um, to, you know, sort of test the, the organization's wherewithal that that can often get around traditional email security vendors.
Yeah. So what's that one thing you see people encountering over and over again? It just makes you shake your head a little bit and say, Hey, folks, maybe we should be a little bit smarter about this.
Well, I mean, you know, where to begin, uh, within, within the security world, but I, I, I think probably the, uh, the biggest thing that I, I shake my head a little bit over is when you ask the, the, you know, a security person sometimes, and you say, okay, you know, I understand we're focused on, on email security and you know, we, we, we will talk a lot about email security, but what about, you know, the realtime voice or, or SMS? They say, you know, people don't have corporate phones at our company, so we don't need to worry about that, right? Um, you know, we, you know, people bring their own devices and what they do on their devices is up to them.
And that's not my job, right? My job is just to, to secure corporate owned, uh, you know, items. And, you know, to me, I, I shake my head a little bit at that because I think, look, the, the job, and look, I think the security people at companies are heroes and, and, and are incredibly important.
And, um, uh, I think it's, uh, uh, a really, really, uh, important thing at the organization. But I think that security extends beyond just corporate email, right? I think it extends to really try to protect our team in every channel that they may be, uh, encountering these types of threats.
And the reality is that the attackers are surging in SMS in voice. And just because it doesn't belong, you know, that that cell phone doesn't belong to the company, that doesn't mean our, our defenses should stop there. Folks, I heard in here, the attackers are getting not only more pernicious, but they're getting clever by the day.
And well, these deep fake things are here, whether you like it or not. Hey, Brian, thanks for being on the show. Hey, Great to be here.
Thanks again, Mike. Take care. All right, and back to you guys in the studio.
Do you know where your data is? Can you make your data come together into some useful place? Is it spread all around the world?
How's your AI gonna work with things that are all around the world? Does the speed of light get in the way? What about power, cooling energy, all this and more on the Tech Field Day podcast.
Welcome to the Tech Field Day podcast, where we'll bring together a group of it technical experts to discuss a single idea about key concepts in the industry. This podcast features a variety of perspectives from members of the tech field, a delegate community. It's often a record, an association with one of our events, of course, tech Field as part of the FU and group.
And this podcast is also published on our sister company Site Techstrong tv. On this special episode with, uh, hammer Space, we'll be discussing how modern data mobility is challenging the laws of physics. But before we have the discussion, let's meet who's gonna be on our massive panel today.
Hi, I'm Kirk Kine. I am the senior director of AI marketing here at Hammer Space. I'm super happy to be joining today, And I'll go next.
My name is Jim Jones. I'm the senior product Architect at 1111 Systems, Jack Poller, founder and principal analyst for Paradigm Technica. And I'm Andy Banta, storage janitor.
And I'm Alice Cook, of course, the event lead here at Take Field Day. And it's nice to get the band back together again, because the last time the five of us were together was at AI Infrastructure Field day three. And what we've seen is that getting data in the right place is absolutely vital for building your AI applications, your AI infrastructure, getting business value out of that data is very much dependent on getting the right data in the right places.
And yet we have this fundamental law of physics. It's the speed of light. You can't move anything, particularly data faster than 300,000 meters per second.
Um, I'm remembering the speed of light, right? Uh, it's been a long time since I've needed to use it. Uh, yet when we've got this data being generated all around the world by large organizations, we need lots of it in the same place, or at least access to it from the same place to build out our large applications.
And I think that's one of the challenges is that the speed of light can't be fixed, but there's some technologies around that can make it less of an impact for us. And we've seen those across a few of the different technologies that we've seen for building these AI infrastructure data centers. Um, Kurt, I kind of, uh, brought this, uh, this topic because it's, it's very much the sort of thing that you are working on with customers on a regular basis.
It is indeed. Um, and, you know, figuring out how you overcome each of the variables, um, that are influencing how we're working with all of this data is definitely, um, something that we're thinking a lot about, right? The fact that power is now the most expensive thing in the data center, um, that, you know, being able to acquire accelerated computing is really tough.
Um, you know, most folks aren't even considering building out these large infrastructures on-prem because it's just far too expensive. And our data center is just far too constrained. And, uh, then add onto that, the fact that everybody has this distributed nature these days.
How do you unify everything if your own organization is out there in all sorts of regions generating data on the edge, uh, but then your compute might be located somewhere else as well in somebody's cloud. Um, and so being able to bridge that, um, and figuring out, you know, what is the representative data set, so you aren't moving all of your data all the time. Um, it's, it's a big challenge for sure.
Right. And I, I think, uh, you know, you touched on the other aspect of physics that we really need to pay attention to here, where it's not just the speed of light, but it's also the density of energy necessary. Uh, one of the, the open compute project, uh, and shortly after the, uh, that field day event, I did attend the open compute project, uh, um, conference.
And there were jokes around there that it should have been renamed the Open Cooling project because most of the things that were being displayed on the floor were actually had to do with cooling, uh, cooling of the compute pro, uh, the compute systems rather than actually the data itself. Uh, I did have a chance to stop by the Hammer space booth there, and, um, put my hands on one of your open flash platform, uh, trays, which was kind of interesting. I didn't actually have a chance to go anywhere else, or I did not see any other, other open Flash platform trays while I was there.
Uh, but it's, uh, I know that you guys were working with several other companies, uh, um, was ex site, and, um, I don't recall who else you were working with, but, uh, it's, uh, it'd be interesting to actually see one of those in, in action at some point. Yep. Yep.
We're getting close. Um, that, uh, Trey that you saw, there was actually our initial POC, um, and we've had a ton of learnings by building that, uh, right. Things around airflow, um, things around serviceability.
Um, and so we're, we are working to refine, refine that platform, refine that design with a lot of input, um, from various flash vendors, uh, from various hardware vendors, um, as well as looking at some requirements from, um, different software vendors in addition to us. So, um, it's something that we've, um, heard a lot of interest from, and yeah, we really hope that that, um, coalesces around this design and, and, um, starts seeing some, some broader, uh, adoption. But yeah, the whole concept behind, behind that there was that there is a more efficient way, um, to just store data.
Um, and part of that is just getting out of the way of the data. Um, you know, the more layers that you put in between the data and the processing, um, is going to introduce additional latencies, uh, and additional power requirements. And so, uh, in the case of OFP, right, our goal is to just remove the storage server completely, right?
We're putting, um, the infrastructure software directly on A DPU, uh, that's low power, still high, fairly high performance, uh, and then connecting that to the flash. So, you know, a very direct connection. Uh, and, you know, we're kind of labeling it nothing but Nick.
So, um, you've got your nick, you've got your flash, you've got a direct path from your processing. Um, and, and I think that's a big, um, part of it. Uh, that's the infrastructure part of it.
Uh, and then I think just dealing with the massive data challenge is the other big rock to move. I think one of the things that makes the Open Flash project project work, uh, with, especially with Hammer space, is that you don't actually need to have any of the data services on the plates or on the chassis themselves, on the trace themselves, because you're actually taking, taking care of the data services through the Hammer space data services, Right? Yeah.
We've got a centralized, what we call our anvil server, um, and that's the thing that does all the metadata operations, um, and is outside of the data path, um, and allows us to utilize, yeah, open standard Linux, uh, and NFS, uh, on those, uh, systems to be able to handle the, the data transactions. I think Andy, one, one of the things is that we love playing with hardware and, you know, hardware cooling, we're all geeks, and that's all good. But thinking about sort of the problem at a higher level, one of the things we've learned over the course of the, the AI infrastructure field days, not field day three, field day two field day one, is that the, arguably the most expensive component other than the power plant itself is the GPUs.
And the big problem is the GPUs right now, while being hard to obtain, they're also sitting idle 70% of the time, right? And that's because they can't get the data. I think we focus on we being not only us here in the podcast, but we as an industry like to focus on the hardware and throwing hardware solutions at it.
And what if we tweak this component and make this component faster? And we've heard from how do you make the ethernet faster, and how do you make the switches faster, and how do you make this, and how do you make that faster? But the architectural problem is, how do I have terabytes or petabytes or multi petabytes of data?
How do I get that from where it lives into the training environment, and then get it, then feed that into the GPU DPU environment? And I think that's the, the sort of the physics problem that we're the sort of wandering around talking around, but not talking about, about, is we have, how do you get a petabyte of data into a processing environment that can consume that almost instantly? And then what do you do from there?
I'll say, it, it, it's interesting from a couple, couple different points, because you're gathering that data, you know, probably not where you're processing it initially, but from a application, you know, we're gonna spend millions of dollars to create a model, or we're gonna spend, you know, probably millions of dollars, even if we're not doing, you know, quote unquote AI creating a model, et cetera, et cetera, et cetera. We're just gathering it. It costs lots of monies to develop those applications regardless of what they are.
And every time we have to change those to allow for data migration, data movement, whatever it is, or, or data expansion, we have to, you know, that incurs costs that include incurs downtime or, you know, maybe from the, you know, PHY physics of the, how fast can I get this capability out to the market or to my consumer? It slows things down. And that's where I was really impressed with what Hammer space was doing with the unified namespace, was it lets me hide any number of sins, if you will, underneath the covers.
You know, I may, I may have a NAS floating over here, or I may have an object storage in 17 different platforms, but as far as my developers, as far as my consumers are concerned, that's one, that's one endpoint, that's one set of credentials and things just work. And that's, you know, where that gets important. Um, you know, in my day job, I'm dealing with customers that are wanting to move from point A to point B, um, to chase cost the physical as the physics, as in the, how much does it cost physical, uh, side of things every day.
And it's incredibly painful to do that, um, one because it costs money to move the data, but more importantly, your application has to be able to support that kind of thing. Um, and so I, I really love that kind of capability to, to further us as technologists to be able to not have to worry about, well, where is my data that may well be at the edge where I've gathered it or maybe my data center or maybe somewhere else and not have to care about it. Well, I think that's, uh, fundamentally been a big part of what's been missing from the conversation, uh, in ai, right?
Is, um, mainly because the industry has been focused on these really, really large developments, right? This initial training of these massive LLMs and, you know, everybody's been focused on just that interface between the storage and the processors, and how do I get enough data into the processors, um, from the storage system. So peak storage performance, right, has been a lot of the conversation, um, and, you know, has served that side of AI very, very well.
Um, you know, and we see parallel file systems and really specialized systems, um, being developed for that. Um, but, but for the other 98% of people who want to do something with ai, we haven't talked about, okay, how do I get my arms around my organization's data? What do I have?
And then once I realized that it's yeah, out there on 50 different silos, how do I then identify our representative data set and make sure that's what we're moving rather than, oh, the way I solve my silo problem is by implementing a new silo and migrating all my data into that new silo, which is gonna take forever, is not going to really help you identify for on an ongoing basis, oh, these are the key pieces of information I need to ingest into my representative data set, and then process against that, whether that's on premises computing or somewhere in the cloud, right? We need to reduce the data problem in the first place to be able to take advantage of all these things. That's, That's one of the, the other things that was talked about at that AI field day was the, the tier zero concept that you, uh, you've put together where you take advantage of the MVME drives are actually on the GPU servers and use that as, uh, a very local tier where you can migrate the data into and have, have very fast access to it, uh, and just have it presented out of each one of the GP servers as an NFS store that's shared, shared and consumed by Hammer space.
And, you know, it's, um, uh, you know, Molly kind of early on and talked, talked about, um, how the name Hammer space came up, which is, uh, the, the space outside of frame and the cartoons where the, where people reach off and they, uh, you know, find something that's off frame and, and make use of it. One of the things that I really liked about the, this most recent presentation by Hammer space is that you kind of did talk about, uh, where you're beaching off frame to grab the various different things where you, you talked about the Tier zero and whatever, uh, interesting concept. And it also was a, um, it, it was also an interesting way of talking about how to get the speed, the, getting back to the speed of flight issue that we were talking about, how to get the speed you need to feed the GPUs that Jack was meshing, where, you know, GPUs are always hungry, you always need to feed them.
Yeah, I think, um, you know, there are a few, um, key things that we're addressing with Tier zero. Um, and it's not just right providing high performance, um, access to the, the local GPUs with that and VME, but, um, there's some other market realities that are developing, uh, that make this very, very interesting, right? If you're, um, actually purchasing on premises GPU computing, you've got these NVME devices that are coming with it and are inside of those servers, um, and we're seeing or beginning to see a really, really constrained flash market where, you know, the hyperscalers and really large, um, organizations have really cornered the market on available flash.
Um, and so if you are struggling to find that flash within your environment to be able to create a high performance tier, well, hey, we can help you reclaim that flash that you already have on-premises in those GPU servers. Um, another, um, advantage is, um, you know, some of the hyperscalers have really, um, adopted high performance networks for their AI computing. Others are still using, you know, standard enterprise networking, um, with, you know, abstraction layers between the storage, um, and that AI computing and what we're able to do with folks like, um, Oracle and, um, Microsoft is actually place the data within the servers.
So you as a customer to those clouds know that you're getting the maximum performance, um, out of those systems rather than having your, you know, data sitting in a blob somewhere and hoping it's getting into that GPU system fast enough. Yeah. Growing on that VM world or my VMware background, it's kind of like what vsan was 15, 20 years ago, or 10, 15 years ago, uh, where you're making use of local storage because it's there.
Yep. And we don't love the virtualization word. We aren't storage virtualization.
That's not what we're doing. Um, but VMware analogy is very, very close. The, the, the funny thing is, you know, the, the trite saying is actually true, which is everything will, is new again, right?
And it's, this is not new stuff. As Andy mentioned, we've been reclaiming local storage for a long time. Uh, databases used to have database administrators who sold job.
It was to, uh, place your data in the most advantageous spot for speed of access or speed of update. And, you know, local tiering and caching was something that, uh, 40 years ago, uh, I visited a Ford plant where they used A CDC cyber nine 60 supercomputer as the local cache for a cray supercomputer, because that was the only thing that could feed the cray quickly enough, right? And, you know, and a lot of what we're talking about here is that management of data, both the physical placement of the data as well as the management of what data do you need and when do you need it in order to feed the beast.
Yeah, I think that the whole systems thinking of this is not a, a set of isolated decisions, isolated components, but it is actually a, a system that interacts together and that you've gotta get coherent across multiple pieces of infrastructure, whether it's the networking, the storage, the compute layers, but also across those multiple locations. And this is one of the challenges we've had as enterprise organizations have grown progressively, right? Back when Jack was working with these creative supercomputers, you, you couldn't have 20 or 30 of them spread around the world.
Now we have a 20 or 30 data centers spread around the world, each of which is generating vast amounts of data that we're trying to get a coherent view of and get coherent value outta. One of the really vital things to think about that Kurt touched on was that generating foundation models, taking that common internet for ingesting that, and training a foundation model is completely different to an organization that wants to fine tune a model or to use a, a rag solution to do inference. The actual workload type, the data flows are completely different.
And the messy enterprise world where we, we have one of everything, sometimes three or four of everything, uh, and we need to somehow get the intelligence out of all of these things. And as Kurt says, we don't wanna just pour all of that into a new silo and pay again for storing all of that data in the new silo that's gonna, uh, supposedly unify and show us everything. Of course, we know that by the time we built that silo, we've got 15 other sources of data that maybe our silo can't accommodate, and now we've gotta build another silo of silos.
So I, I think there's some very different sets of challenges for enterprise organizations, but as Jack says, these are not entirely new things. These are things we have seen over years and years. Well, and AI is just the current variant of the conversation of the, this is the application that's driving this need.
You know, it's as, as you were speaking, Kurt, the thought that came to my head was, we, you know, one of the things that you're trying to do is you're trying to loosely couple the loosely coupled things. You know, we've been talking about making our more, our applications less, you know, aware of what's going on in the infrastructure for literally decades at this point. And as we abstract out of that, all of that is just trying to make it to where, okay, so today it's ai, the next conversation may be quantum computing or the conversation past that may be, you know, you know, something from the Jetsons as far as I know.
Uh, and, and you know, the anytime that we can, you know, the, the, the interface from the infrastructure, we're just making our life much easier as we iterate from this thing to the next. For sure. And I think flexibility and agility are two big driving, um, characteristics behind Hammer space.
Um, because right, it's not always about bringing the data to the compute either, right? Some, sometimes it's gonna be about bringing the compute to the data, right? So our friends at Nvidia continue to churn out different solutions that, um, you know, go all over the place.
You've got 'em in the robots themselves, you've got 'em in all of the sensors, you've got 'em in region, um, you've got 'em in your data center, and then you've got 'em in the cloud, right? And it's horses for courses. And so, um, I think even getting back to Jack's point, right?
Each of these steps has been done before, right? Um, we've done this in cycles over and over again. Um, what we're really looking to do is, yes, we're solving it for the unstructured data challenge, right?
Which is, has its own unique headaches, um, where prior right? With, you know, maybe the structured, it's been much easier. It's been a, a smaller challenge.
Um, but now we're dealing with desperate types of data where, you know, the size of the data generally, um, is, is much, much bigger on an individual file level. And, um, the, the demands are constantly changing. And how we process that data, um, is constantly changing.
And so, you know, introducing agility and flexibility is key so that you aren't locked into a single architecture where it's monolithic in the data center or even monolithic in the cloud. Um, you need to be able to tune everything and do it without doing it manually. Yeah.
This, this topic actually came up at Open Compute, uh, OCP and at Super Compute, where the idea that, you know, what is currently being talked about is AI was simply HPC or High Performance Computing three years ago, and that was the exact space that Hammer space was playing in three years ago as well. And the, the use cases are the, the infrastructure needed is incredibly similar between HBC and ai. Uh, with the, the difference being the HPC actually strives to come up with the correct answers, and AI just makes stuff up.
I think that the four letter word you're looking for, Annie, is Hadoop, which was all about moving compute to the storage rather than storage to compute. But that's a four letter word, and we won't go there, There, but it, it's, um, you know, I, your Hammer space goes in trying to address a problem that is needed in these types of compute environments, and you've, you, um, you have a variety of innovative ways to actually accomplish that, For sure. And you know, the, the other important point being there is, you know, we are not looking to develop our own walled garden either.
Um, we want to be able to give our customers choice when it comes to the different things that they do. So, um, you know, things as subtle as you know, are how are you embedding a Vector database into your solution? Um, we see some people saying, we'll be the one appliance for everything, um, that you need to do for ai, and you don't have a choice, right?
Um, that's one perspective. And yeah, in many ways, that makes some of the decision and implementation simpler. Um, at the same time, um, it locks you into their vision and their silo.
Um, whereas we're looking to give you that flexibility and choice when it comes to decisions like that, as well as the decisions behind, you know, the actual infrastructure that you're using and the location that you're using it. Um, and having a solution that sits in the middle that then automates the administration of all of that data movement is where we see our key value. And we're gonna have, uh, plenty more conversations around some of that key value and the problems we're trying to solve for people through ai, both through further episodes of the Tech Field Day podcast, but also at future AI infrastructure, ai, uh, field day events as well.
There. This is definitely a place that we like to have our conversations, as you can probably tell, but we don't have time for all those conversations today. So, before we close out for today, where can people connect with you to carry on this conversation?
Maybe learn a little bit more about the things you, you've been thinking about, the things that are important to you? So I'm always available, uh, on LinkedIn. Um, you, you know, my name's Kurt Kine, K-U-C-K-E-I-N is the last name.
Um, so you can always connect with me there, um, as well as I'm, you know, always publishing stuff, uh, on our website, blogs, things like that. Do feel free to reach out through that as well. Yeah.
And I can be found on the internet at Coolaid Info or pick your social media platform up to and including LinkedIn. And I'm coolaid it there. com, our corporate, uh, site, as well as on LinkedIn Security Boulevard and other social media sites.
And you can find me on LinkedIn, uh, at Andy Banta, uh, on Blue Sky, and on my, for my own content. You can find that at andy banta blue, uh, substack com. And of course, I'm Alice Cook, and you can find me all over the tech field day, as well as on social media, uh, LinkedIn.
Uh, you may also find me as deas NZ since I live here in New Zealand. So thank you for listening to this episode of the Tech Shield Day podcast. If you've enjoyed our conversation, our discussion with our delegates, please subscribe on YouTube or your favorite podcast application, miss a single episode.
As always, give us a rating, nice review, tell us how wonderful we're we. Like that this podcast was brought to you by Tech Field Day, the home of it experts from across the enterprise, and of course, a part of the future. com/podcast of us on Techstrong tv, maybe even on your smart device.
Uh, thanks for listening and we will see you next week. Hey everyone, we are live here at AWS Reinvent, continuing our coverage of Day one Lot going on a lot of ai, a lot of agentic ai. You know what, I don't hear a lot about Cloud.
AWS Reinvent used to be all about cloud. Now we're talking ai, but we're gonna talk some security. One of my favorite topics, I want to introduce you two and make, I'm gonna mess up his name, but we practiced it 12 times and I still didn't get it right.
Sne, Ben Schmo, Schmo, almost, I wanna say Shlomo and I keep Schmo, but he likes to be called Ben. Ben, what's, thank you for coming on to Text Drug tv. It's great to have you on here, man.
Thank you for having me. So from the name, I'm gonna guess you, maybe you have some Israeli roots. Yeah.
But You live, you're a New Yorker, New Jersey, like me. So I guess that makes us kind of almost related, but, um, tell us about your journey. How, how did you come here?
Yeah, definitely. So currently based in New York, almost in the past 10 years, uh, been in cybersecurity for many years, as you all know. Uh, I'm Israeli originally, so we started a journey in the military.
Uh, I'm not 8,200. You're not 82? No, My hundred Is what is a few, not 8,200, But actually 8,200 is quite big.
Yes. To the place that I used to serve. I used to serve in more of a secret service.
Okay. The Prime Minister office. Mm-hmm.
Which is, uh, more boutique, more unique, uh, harder to get into if you're 8,200. Don't hate me, but we're better. Okay.
Hey, he said it, not me, but go ahead. So, yeah, we, um, basically move to the states after, um, managing a lot of cybersecurity, public company, research division, building from scratch, really, really passionate about research, anything related to vulnerabilities, attacks, offensive security defense. And, uh, I found myself in, in New York as like one of the big companies.
I build their product, they couldn't sell their product to the ciso and I was blown away because such a great product, we need to explain the value. And when I moved to the states, uh, I was really kind of exposed to, no matter how good product you're building, you need to be close to the customer. You need to be really close to the team, you need to close to the security executives and explain to them what's going to come next.
Mm-hmm. The thing with security is like check if you're playing, if you're trying to survive the next week or maybe the next year, you're probably going to fail in year two. In year three.
So when I moved to the states, one of my biggest goal was to educate them right in like, what's coming up next to build a strategy in the right way. I used to be a CISO as well, and managing security organization over 100 people. Um, um, very quickly, um, after that built a startup, uh, a couple of really good friends, uh, named Cider Security very quickly.
We sold, I Know them well. Sure. Yeah.
So really quickly, uh, we had a huge success. We sold it to Palo Alto Network. Mm-hmm.
Part of Prisma Cloud. And, um, I ended up loving the cyber, uh, security and startup. I'm like, wow, I can do, I can build, I can do whatever I want versus enterprise.
That was a little bit slower. Yeah. So I decided to take some time off after the exit, and my co-founder, uh, who I didn't know was going to be my co-founder called me.
His name is Uri based in Boston. And he's like, Hey, so I have something interesting for you. I got to a point, he manage vulnerability management and cloud security for Akamai from Cambridge.
Sure. And he is like, Hey, I got to zero vulnerabilities in three of the massive Akamai environment. I'm like, great, Julie, you accepted the risk.
Everyone can accept risk. It's like, no, no, no, no. Actually remediate it.
Actually. It's like, excuse me. Look, vulnerability management is never happened, never happened, never happened.
Vulnerability management is a list of problems everyone have. And you just wait for, you know, s****y defense and bad things will happen, but it is what it is, right? And it's like, no, no, I was able to do something about it.
Uh, it sounds very promising. I opened a plane, went to Boston, and I spent a few days with Uwe. And what he showed me, I was blown away because I couldn't achieve it with the best team in the world of security people for all the decade I'm in cybersecurity.
And this is where I realized that vulnerability management, the dead market of vulnerability management, exposure management is, can be solved. We can actually win the vulnerability battle. Call me skeptical, but okay, I'm listening you.
My Skeptical. So after a long journey of speaking to over 100 good friends, CISOs and large enterprises, and also smaller one, everyone we're skeptical. What we ask him, it's like, Hey, if we can come in and take your backlog, your vulnerability backlog, and all these vulnerabilities that you're getting from Tenable, from Wiz, from AWS inspector for, and we talk about AWS later on while we here, but all these crazy vulnerability data from on-prem, from the cloud, take all this vulnerability data, you can sift through it.
You don't have enough people in the team to review it. And then you have work workflows, but you cannot automate vulnerability management because it's deterministic. Every CV is different, every vulnerability is different and the environment is different.
So how can you automate? You can't. This is why we're failing.
And I ask him like, if I can take this problem and automatically reduce 90% of that backlog automatically without any human touch, just eliminate it and leave you with that 10 or maybe 5% to actually handle. It's like, that sounds good. That sounds great.
That's great prioritization. And then I, then they told me, what about remediation? I was like, okay.
So once we have that 10 or 5% I know and we practice that, then we identify it, take that five to 10% and simulate remediation, give you that one, two or three steps that you need in order to reduce Back to the buck. Exactly. That's exactly what we're saying in our website.
Mm-hmm. And they say like, that's amazing. If I have something like that, I will, I will buy it.
We, uh, close a seed round in a month really quickly. We just took the money, great investors, and we built ZE security, which is the current company we're at today. Very excited about it.
So that's basically the story of, Of you and Zes ze security. Yeah. And Uwe, So lemme give you a little background.
I, I've been inside, but we didn't call it cyber, we called it security. I've been in security 30 years. Information security.
InfoSec. InfoSec. Yep.
Exactly. And, um, I actually, I've co-founded a couple companies, one of which was called still Secure back in 2001. And we in 2003 came out with a vulnerability management product.
And back then it was very different. Back then you had to convince people to do a scan once a year. Mm-hmm.
It was like pulling teeth. But when you, but it was job security for the security guy. 'cause you would do the scan, you'd deliver like a telephone book of vulnerabilities.
Let's say I give it to 'em for Christmas or New Year's, you know, you're from New York. It was like painting the Veno Bridge. You know how they paint Theno Bridge?
They start on one end, it takes 'em a whole year to finish, to finish. And then when they're done, you know what they do, they go back and start again on the other Best job security ever. That was vulnerability management.
It was almost by design that you didn't get to zero vulnerabilities. So then people got smarter. They said, look, we don't need to get to zero vulnerabilities.
We should only worry about the vulnerabilities that are exploitable, reachable real. You know, I had, I had a friend, I don't know if you ever heard of this guy, giddy Cohen, Skybox Security. Yeah, Of course.
Giddy just started a new company know too. I know. Um, you know, and that was one of when I first saw his attack maps is what he called them, right?
Mm-hmm. That was a revelation. I was like, wow, this is great.
Now I only have to worry about 20%, 25%, which Is a couple of millions. It's Still a couple of still job security. Yeah.
But unfortunately, it's been almost by design that we never get to zero vulnerabilities. And as a matter of fact, even you mentioned, we were talking off camera about black hat. I was a black hat in August.
I was talking to a friend of mine, uh, two friends who actually just, uh, just starting a new company. They just raised money now. And, um, their, their thing is, look, forget all these vulnerabilities.
There's only a handful that are real mm-hmm. That are responsible for incidents and just focus in on those. That's good.
If I knew exactly which ones to focus in on, you know, that's like the old, he's an old joke. A plumber comes and says, the lady says, I don't have heat. A plumber says, let me look.
He takes out his pipe and he, he bangs the, he takes out his wrench and he bangs the pipe with the wrench and the heat starts working. And the lady says, oh my God, what do I owe you? He says, $250.
She says, $250. All you did was bang your wrench on the pipe. He said, oh no, that was free.
Knowing where to bang my wrench on the pipe is $250. I love that. I I'm going to use that.
Tell you got it. It's yours. Wow.
This, but that's the thing about vulnerabilities, right? If you know, which of the ones that are exploitable are dangerous, you can mitigate. But to get to zero, I'm not gonna ask you to give away secrets here, but what is the secret to getting to zero vulnerabilities?
So what we, and, um, I don't know if we want to get to zero. Okay. I don't think we need to get to zero.
Yeah. But we definitely need, like, why do the, the world need is important since you start talking about scanning. Today's scanning is mandatory.
Yes. You have requirements, right? You have continuous regulators.
Yep. You have auditors. More than that, if you want to provide services as a SaaS company to customers, you need to have an SLA.
Yep. And what happened in 2025, these regulators, uh, re requirements are stop asking you for visibility. Because visibility, everyone knows everyone have that list of vulnerabilities, right?
Mm-hmm. Everyone can scan. Everyone's scanning today, even SMBs.
Yeah. They're required to. Yeah.
But now the regulators starting to ask, because again, I will, I will give some more information because I think it's important. Over 60% of incidents today, and this is vouch number, are related directly to vulnerabilities that were known to the organization. Absolutely.
I think it's higher than 60. I think it's close to 80. Um, I'm, I'm just basing on ENT report and Verizon report.
Yep. The time to exploit this vulnerability were reduced in the past three years in 19%. Now it's less than a day.
Last year in 2024 was less than three days. Before that it was five. So we got less than A day.
Less. It was 30, 45 days. Exactly.
It keeps going down. So regulators, cyber insurance, your customers want, if you have something critical, they want you to commit to an SLA and God forbid something happened. You miss your SLA, your regulators will come up to you, especially if you highly regulated environment.
Yep. Most of our customers are biotech, financial services, health, and even SaaS company that provide services to this healthcare. And today, look, it's, it's about who your third parties are.
Yeah. Right. It's not who you are.
It's who they are when, so, you know, and further down the road And they want to get these deals. It's like, yeah, I cannot get these deals because I cannot commit. Or they're committing, but now they need to deliver a seven days or six days critical vulnerability in production remediation.
Absolutely. It's the whole SOC two and all of These other Yeah. Audits.
And, and what we actually realize is there is a need, like not in zero vulnerability. There is a need in remediation. Yeah.
And how we do what we do is basically, you cannot automate, but you can AI it. So we using different type of LLA models, we acting as an army of security engineers that going one by one of these vulnerabilities. And it doesn't matter if they have high score or low score.
It doesn't matter if they're being exploited in the wild or not exploited in the wild, they're in your environment. Yeah. And what I need to tell you, if in your environment this vulnerability is actually risky or not, and you'll be surprised how the more, the most advanced scanners, these tools that you paying million dollars to, they're giving you this list of vulnerabilities with attack path, with what will happen if, but they're not correlating that with your environment.
No. So you have an open SSH vulnerabilities, right. That open SSH vulnerability have requirements for exploitation.
You need to run the service with specific permission. That asset that is vulnerable need to live in specific environment, environment terms. Without them, this vulnerability can never be exploited.
And to understand that you need to send someone to do this test. Yeah. That's exactly what our agent ai, uh, uh, capabilities are.
Wait, I needed to say it. You said it. We, but you made a long time till you mentioned it.
Look, we're here at AWS reinvent. I don't hear them talking about cloud. I hear them talking about agent ai.
So talk to me about how your agent is working to do this. Uh, we actually announce, uh, we're going to have an announcement, uh, early next year, but in a reinvent, we doing a private preview of a new capability that was very, very interesting to all of our AWS enterprise customers. AWS investing a lot in security.
Yes, they are. And we call it Native security controls. So they're allowing today DevOps and, and platform teams and engineering teams that build a cloud to build a cloud in a secure by default way.
And they have a lot of native capabilities around resources. You can build policies around services. You can have security policies without paying money, just using the native capabilities of the cloud.
If you will look in this native security capabilities and you will correlate that information. The hard work that your cloud architect actually infuse into your cloud correlate that with your vulnerability backlog that you need to solve. You will realize very fast that many of these native security controls basically reducing 50 to 60 to sometimes 70% of your attack surface.
But because you're not marrying these two together, you, you don't know. That means that you can focus on vulnerabilities that were already diffused and solved by and mitigated by this amazing AWS cloud native controls that you have. So one of the capabilities of our agenda AI is to look and understand your policies around services, resources, encryptions, VPCs, microsegmentation in your cloud, and understand if this remote code execution vulnerability can actually exist.
Even if you take into consideration these policies, most of them are not exploitable. Right. That's the idea.
I love it. It's great. You already, you, you don't have a problem.
You already solved the problem and you don't know that you solved it. You know, some, some part of me sits here and says, did it take AI agents agentic AI to reach this level? I, it's always bothered me to tell you the truth, why we didn't do better with this problem.
Right. I I was working on it 2003, 22 years ago It ago. It's a technology limitation.
It's not a need limitation. You, we always have that need. I think we've always had the need.
I I always thought we didn't have the will. Right. People, people talk a good game, but their hands don't reach their pockets when it comes time to, to really prioritize.
But this makes it easier more, it, it's, I don't wanna say automated, but it, it's just, it's easier to, to do this. You can win. I love it.
Yeah. I, I agree. We are giving a lot of, I I, I'm really proud of it, but we giving more life years to our security engineering.
Yeah. Every time we talk to a team and the team sounds tired and unmotivated, this is the team we want to work with. The teams that have these backlog of vulnerabilities that every day of their life is chasing down these, Look, this is a whole big problem.
You, you've been in security long enough, you know this. Right. The, the depression of, because for those of us who've been in security a long time, we have a lot of people in security who are, they suffer from depression.
They, it, the, the, the, the issue is, it's like what does winning look like in security? That question winning is, I didn't get breached today. Mm-hmm.
Right. Did I not get breached? 'cause I was the zebra and the herd and the lion ain't someone else today.
Or because I did a good job, or I convinced my CISO and the board how to manage risk, what, you know, what's acceptable risk or not. And, and so anything that I think Im improves that is, is an amazing thing. I was gonna ask you what Zest security's doing here at AWS, but you already answered that Ben, so that's fantastic.
Um, what has been, so there are security people here, but there's everyone here, there's CIOs, CI, SSOs, there's that. Do people understand, like the security people obviously do, but does the CIO there, the cloud engineers understand what a, a load this is off of their chest, right off of their shoulders? Mm-hmm.
I don't think they care. No. I think at the end of the day, it's part Of the problem too.
I like, it's not part of the problem as much as, you know, we, me managing over 100 people, I knew everyone personally and I cared. Right. When you walk in a large enterprise, you like many times you can't do that.
You don't know what the security team in the trenches actually going through. Even not the ciso not talking about the CEO and the COO. What I, what I actually, um, what what what I like to surface is if your security team, if you vulnerability management team that in charge of prioritizing vulnerabilities and fight the vulnerabilities are drowning, which they are, it's going to bubble up into management problem.
Yeah. It's going to bubble up in audits. It's going to bubble up the way you look in front of your customers that asking you about what you do about this, what you do about that, it's going to bubble up when you have a red team or penetration test.
It's going to look bad when you have a customer that's saying like, Hey, I asked you about this couple of days ago, what's going on? And we're getting these emails, right? So the management team needs to look good and needs to act good.
And it's start from the vulnerability made, start from the team. So what I'm, I'm basically telling this COO and CIO is like, today you have a backlog of, or do you have vulnerabilities? It's like, yes.
Do you want to eliminate a and at least 90% of these vulnerabilities without spending money and asking favors from the CTO and engineering team without asking and pushing tickets into teams that need to build your business? It's like, yes, of course. It's like, I can guarantee you that with agent AI infuse into your exposure management program, your C program, you don't need to hire 200 security engineer.
You can walk with your existing team, maybe add some more people if you want to, but you can win. If you infuse AI into that operation, you can open less ticket. But each and every ticket you give to your engineering team, that ticket was 20 or 30% of your risk reduction.
Got it. And that's what they like, they, they sync numbers. Right.
But at the end of the day, I'm helping the vulnerability management team. Yeah. And if they do a better job, the COO, the CFO even will be happier.
They don't understand that. But it's okay. That's my job to make sure that both sides agree to embrace our technology.
This will get, like, these guys will get their executive report and the vulnerability management will get an amazing, amazing tool that will make them survive the holidays. We need to survive the holidays, right? Yeah.
Always. But then there's always another holiday. Um, you know, Ben, we're running low on time.
I want to just make sure we hit a couple of things for people out there who, like what they're hearing, what's the website to go to here? io. io.
Very Zs t Zs t zes, like the Lemon Ze. Yeah. io.
And we're very transparent about what we do and about our technology, and we have our customers use cases there. Everything you need to know. It's in the website if you want to see it live.
If you don't believe what you're reading, which is okay, we have a dedicated security team that can show you a 30 demo, 30 minutes demo and actually to see it by yourself. And we also have a, um, a free, we just announced few months ago, a free remediation assessment, really, which is not a risk assessment. We're not showing you your problems, right.
Uh, we are basically showing you, uh, the probability of your remediation operation. How can you remediate to more with less? And it, it takes, I think, seven days of the platform to run, analyze, and get you everything you need without having any sales calls during that time.
So Absolutely. Yeah. io.
Yeah. Hey, I think you're onto something, man. Good for you.
Thank you so much. I really enjoyed it conversation. I enjoyed having you on here.
io. Go check it out. Look, this is, this is, uh, this is kind of a holy grail a little bit if you've been in vulnerability management and security like I have.
So go check it out for yourselves. I'd love to hear what you say about it. Enjoy the rest of reinvent.
I will. Thank you. All Right.
We're live. We'll be back with more. Stay tuned.
All right folks. Uh, very warm. Welcome.
My name is Raj, and with me is, uh, we'll be introducing ourselves. But today we are talking about golden parts or spaghetti pipelines, the dark radar of platformers. It's, uh, influenced by a lot of Star Wars.
Uh, I wouldn't say that I'm a Star Wars fan, but, uh, I think, uh, I've watched quite a bit. So we, we are gonna be talking about how platform engineering has, uh, evolved in today's world and what, uh, you know, platform engineering has come up to. And we introduce a cool open source project in ent.
Uh, obviously, uh, that's how I have summarized the talk for you. Again, my name is Raj. I'm A-C-N-C-F ambassador and a community manager at antes.
My journey started off with Kios Engineering, a lot of things around litmus chaos. And now I have been doing a lot of platform engineering, K zero ent, open, SDN. Uh, other than that, I, uh, from a community aspect, I run KCD Bangalore, uh, platform engineering meetup.
So you can connect with me on my socials. Har, would you like to introduce yourself? Mm-hmm.
Sure. Fritz, thanks. Uh, yeah, so I'm Paris.
Thanks folks for tuning in. Uh, I'm the Osbo lead at Marant, uh, OSBO, for those of you who don't know, it's open source program office. So, um, the typical role of osbo would be to focus on the upstream contributions and, um, contributing to the open source community.
And we at marant are especially focused at the Kubernetes ecosystem. So we work around technologies such as cluster API, um, um, Selto and the Open Telemetry in Prometheus, Grafana, you know, for the observability stack and, and so on. Yeah, happy to be here.
Alright, thank you so much. Hara, uh, for the agenda, I think I have given an intro already on what we will be talking about. Usually I don't keep a set agenda in place because, you know, you can stop me when you want.
It's, uh, obviously being recorded. So we'll try to cover as much as possible. We talk about a lot of platform engineering and a lot of, uh, uh, a lot about the tooling as well, how a real IDP might look like.
So we, we'll find out what we'll talk about. But before I start, before I start talking about, you know, what's, what's there, what, uh, platform engineering, what's the platform engineering ecosystem looking like today? I'll just start from the, the developer ecosystem itself, and if you can see my screen well and clear, this is hello translated in a hundred languages.
Uh, there are so many more languages, there's so much more that you can translate hello to, but in the developer ecosystem, it looks something like this, the CNCF landscape. And that is what is expected from developers. Developers are expected to learn tooling.
They're expected to learn different kind of tooling. Uh, beyond writing code, developers are expected to run, learn container, run time, kiosk engineering, networking, CICD, uh, building pipeline streaming messaging policies. And developers don't want to learn so much tooling.
Developers want to be writing and shipping the best code. They don't want to be testing. And, you know, being involved with qa, being involved with learning CNCF tooling and implementing that, running it in squeezing production.
But that is what the ecosystem looks like today. That is how, uh, enterprises or teams are functioning today. Uh, developers are expected to do so much that there's a developer toil, developer experience takes a hit.
And that is where the idea of, you know, DevOps came in. The idea of, you know, moving from, uh, the old school way of development to, you know, having the ops side of things to make shipping easier came in. And that in itself has become tough.
I mean, if you have to talk about DevOps engineering today, there's a sense of change or the sense of, uh, you know, shift from DevOps in itself. But before I introduce that, and before I talk a lot more about cloud native technology, let's talk about how cloud was meant to be. The idea was a data center interacting with a public cloud environment that is what customers or developers or the idea of cloud brought in.
But this is the reality we have today, multiple cloud providers. There's AWS Azure, uh, people are hosting their, uh, infrastructures on private cloud edge environments. And there are so many APIs under the hood that eventually it has become a complex distributed system or a complex distributed infrastructure.
And the idea of, uh, you know, container orchestrators was to make it simpler with Docker Swamp, to Mesos to Kubernetes, where the community thought that Kubernetes is that one single source of truth or a powerful scheduler, powerful container orchestrator. But this is what we have eventually reached to Kubernetes has matured, but we, we can see that even, even if we are using Kubernetes under the hood as the co orchestrator, it's Kubernetes, which is, you know, being used, uh, as, as an orchestrator in your Azure environments or your AWS environments or your GCP environments, edge environments. But there are still multiple APIs under the hood.
It's, it's very hard to manage these multi-cloud, multi cluster deployments. And the ideation that we had with, you know, bringing platforms and Kubernetes as the common control plane was that Kubernetes will remove these, uh, uh, complications, these dependencies and Kubernetes will act as the single source of truth or the manager to these multi-cloud, multi cluster environments. But where we are, where are we today?
I mean, with, uh, you know, platform engineering and the concept in itself, I believe platform engineering is not a new concept platform as a product is platform engineering has existed for as long as we have known. DevOps in itself had the idea of building platforms and, uh, ensuring that the developer experience is eased out. Developers are able to ship code faster, and they're able to, uh, basically build, uh, build an infrastructure out of different tooling.
But platform as a product is how, how it changes the ecosystem is that now you are trying to ship tools that are predefined. You are using the CNC of technology. You are, uh, using a native technology.
You are hosting it on different, uh, cloud environments or your VMs, or on your GPUs. So the, the idea is to ship a ready-made standard approach to developers where they don't have to do much. They are shipped something that they have access to.
There's an interactive UI per se, or there are interactive tools that they can choose from. There's a marketplace if you want to choose, uh, your csis, your CNIs, your container registries, your runtimes, everything is shipped to you as a complete total platform, which I believe a lot of it has been achieved by, say, Heroku or the other, other options that are out there. But as I said, platform engineering has evolved to shape platform as a product where you can use your multi cluster multicloud environments with ease.
But before that, let me just go back to the topic of DevOps. What's the current state of DevOps? Is DevOps actually DevOps right now?
I, I believe that DevOps as a concept can never die. DevOps as a concept will always exist and mature. It's, it's similar to suggesting that, you know, say, uh, uh, you know, development in itself might die and AI might take over.
It's, it's, it's similar to saying that, you know, Python or go might become, uh, redundant and some new coding language can take over. I believe that, uh, DevOps in itself has evolved and platform engineering has become the subset of DevOps today. That's how I, I look at it, and I believe the at large enterprises will still focus on the DevOps side of it, because if you have not improved your DevOps, then how can you even look at implementing platform engineering as a concept or platform engineering in your different teams?
Because, you know, there are different teams. They want to have a standard approach. And if you're not following the right DevOps practices, or if you're not following the right DevOps mindset, then reaching the platform engineering maturity is, is, is impossible.
In, in my, in my opinion, I, and I believe the viewers will watch this, uh, presentation, uh, on, on 30th, they'll, they, they agree that, you know, maturing your DevOps practices can help you mature your platform engineering goals in itself. And DevOps challenges are driving platform engineering. What went wrong with DevOps that, uh, you know, platform engineering came in as, as a niche or as a concept.
I mean, before DevOps, you were, uh, developers were writing code, there were unit testing, but after DevOps came in, they had to write code, they had to build their pipelines, they had to write code for their builds, and then they had to write code for monitoring metricses. And then came the unit testing side of things. And as I spoke about, developers don't want to learn about FRA and new tooling.
There's a slow developer onboarding and cognitive overload and developer burnout has actually hindered developer growth. Or you can say the amount of input of productivity that developers can come in with. And that is where we, uh, you know, consider platform engineering from a cost perspective, from a reliability perspective, there are so many outages, kiosk engineering, incident management, reliability engineering, uh, you know, uh, debugging, uh, integration testing has improved so much.
So, you know, to, to address these critical outages incidents, to find out what's going wrong, to ensure that your systems are consistent. And even if you are, uh, you are making changes or you know, you're adding features to your systems, because the infrastructures are so dynamic and in, in nature, there's a shift left, uh, resiliency or development happening. You need to ensure that, you know, if your production releases are happening frequently, say in a month, you're accelerating your cloud native journey, adding tooling, you have to consider the platform engineering approach where you're standardizing the approach and you're ensuring that, you know, you are shipping code in terms of a platform or an internal developer portal, IDP as, as the world popularly knows, but there's a dark side to the realm.
There's a dark side to platform engineering. Even if the idea of platform engineering is to focusing on self-service, internal platform, streamlining, software delivery, platform engineering has not been, you know, subdued or, or performed in the right way. The, the platforms that we are trying to build today, uh, they, they are overly complex in nature.
Uh, they are, I mean, teams are platform engineers as the personas, but they have not reached the right approach to it. And I'll, I'll cover some dark side why we, instead of building the right golden parts or the right, uh, uh, platforms, we have, you know, created spaghettis. If, if you say, so how, how I've defined the talk or why is it all over the place?
The first point, of course, uh, too many stormtroopers overly complex platforms, uh, there's lack of focus on the core needs. You have to begin by addressing the most pressing challenges faced by the developers. You have to add features iteratively rather than, you know, adding all of the features together.
There has to be a minimal viable product mindset. You have to prioritize features based on real world requirements. There has to be regular, uh, reviews, periodically assessing what's going wrong, why the platforms, uh, uh, i, I, uh, are having redundant features, or is there a complexity issue that you're facing with your platform building in itself?
Uh, there's a lack of developer adoption, uh, develop. Even the most well built platforms become ine ineffective because developers are hesitant. You need to have a user-centric design build platforms with developers, uh, in mind, focusing on their use, uh, usability, their intuitive, uh, it should have an intuitive interface, need to demonstrate value.
Show developers how the platform reduces the cognitive overload and enhances their productivity. You need to constantly support them, uh, offer, uh, robust documentation, have an accessible support system, uh, ensure that the developer onboarding is easy. And, you know, developers are able to adopt it in a, in a structured way.
I believe platform engineering is missing the real goal. Many organizations jump into platforms as I spoke about, but they don't have a purpose in place. So I believe education and training, conducting the right workshops, uh, sessions, familiarizing them with the platforms and incremental rollout as you, as I, as you say, gradually, uh, changing their engineering practices or moving from the old school software delivery model, having the right feedback loops in place, actively, uh, solicit and act on feedback from users, which is your de developers.
I'll, I'll talk about platform democracy and idea or concept I really believe in. But yeah, uh, you need to find out the real goal. What is the real evil, if I have to say?
So, uh, you, you, the, the idea of trying to integrate legacy architecture organizations with leg legacy systems want to integrate it to modern platform practices. And that is not how it's, it's supposed to be approached. You need to have a modular design where, you know, you need to ensure that your legacy systems are able to interact in the right way with your platforms.
They have to be, uh, there has to be gradual modernization rather than immediate, uh, modernization or, you know, just pumping in the resources or the funds and ensuring that, uh, you know, your platforms are compatible in nature. And then you have to use your middleware, right? You need to ensure that you're bridging the gap from your older tech to your modern platforms.
There is a Kubernetes sprawl, as I spoke about CNCF landscape is growing like a banyan tree. Uh, there are roots and branches that, uh, people are developers cannot access so easily. You need to standardize your tooling, have a curated list of tools that your organization or your, uh, platform needs.
You need to assess the ROI, what's, uh, the return to investment on the effectiveness and the tooling that you're using. And then you have to have a consolidate effort where you know, your developers, your stakeholders, your decision makers, your customers in itself are, are able to, uh, you know, have a consolidated effort towards, uh, your platform goals. Security is the important, uh, open SSF has been doing, uh, commendable job.
Uh, there's, uh, you know, your, your centralized, uh, platforms become threats to any sort of security issues. You need to ensure that there's a security by design principle that you're following, where it's not just about the platform's design, but you have the right r back controls the right encryptions. There's regular auditing in place, and of course, you have to educate your teams in terms of security and how you can minimize the human aspect to it as well.
Tele isn't easy. I mean, scalability and performance bottlenecks are there. You need to ensure that you're planning for scale load testing.
Again, conduct regular performance and operation testing, identify and address the bottleneck. And then of course, dynamic scaling. You need to implement auto-scaling mechanisms to handle the variable workloads effectively and efficiently.
Uh, I think this is the second last point that I have. Cost optimization is missing. Uh, we often see that people have built platforms approach software delivery in a certain way, but there's no problem cost optimization, cloud costs, uh, resources or resource optimization, or there are other tools.
I mean, open cost cube cost out there that you need to ensure that you are having the right, right resource utilization and you are able to improve your overall efficiency by, uh, and at, at the same time, you are reducing your resources and your high operational costs. And lastly, of course, observability. Uh, without proper monitoring, metrices logging, uh, you cannot have a platform.
I believe that you cannot identify how your platform is performing if you don't have the right observability in place. You need to define your metrices. You need to define the right SLOs, SLIs your MTTs, uh, how your system is, uh, behaving, say in a steady state, or when a new tooling or dynamic scaling happens, how your systems behave.
And you have to have automated alerts in place to find out the critical events. The, the scenarios in itself with this, I have, I believe I have covered some main platform challenges, but one platform challenge that I believe needs to be addressed at a higher level is platform engineering needs to be democratic. Platform engineering has evolved through multiple stages from, you know, a rigid separation between development and operation teams to the emergence of DevOps to eventually centralized platform teams.
I believe to address this, there has to be a platform group where multiple teams on different focus areas have to come together. It can be the producers or the consumers. So the idea is to make platforms democratic, you need to redefine your roles.
Producers are no longer the only platform teams. They include your internal teams, your executives, your compliance folks, and then your, uh, eventual customers as well who are eventually consuming. These platforms have to become a part, part of your platform group to ensure that your platforms are safer, faster, and obviously are enabling the developer self-service as the, the idea of a developer self-service as they eventually goal.
And as I spoke about platform needs, platform engineering needs multi cluster configurations while you are creating your IDP need to, to ensure that you're able to manage your multi cluster configurations, your AI ml, uh, uh, you know, there, there, there's an AI ML workload side of it, or, uh, your, the platforms are moving towards an AI ops, ML ops approach. There's hybrid multicloud environments. We have spoken about, uh, it, most enterprises are deploying, uh, hybrid environments.
You have your edge IOT environments, which are, which have to be highly available, uh, in nature. There are multi-tenant teams. There.
You have to maintain isolation between different teams. And obviously there are country specific data, so in laws as well, where, which you have to comply while building your platforms. And the major challenge of building these multi cluster platforms is that, uh, the, the ideal goal or ideal scenario is single application cluster or having multiple, uh, alpha providers ensuring that your dynamic on demand clusters are placed in the right way, but it serves a lot of challenges.
Your workloads are inconsistent. There are no right policies in place. Operational, uh, goals are not met.
It becomes complex. And then there's a tooling sprawl or Kubernetes sprawl as I spoke about. And that is where you need the right manager or the right, uh, tool to ensure that you're able to manage your, uh, uh, golden parts.
Well, there's no Kubernetes sprawl. Uh, you know, your beachhead services are not being managed well or your services while you're managing these multi cluster environments. Even if you're using Kubernetes as your scheduler, you need to ensure that you are doing it right, because I have seen communities being used in mainframe IBM mainframes as well.
And this is how I have envisioned the platforms of today. This is a simple example. I have taken, I have worked, uh, uh, uh, with, uh, ante today on platform engineering, where back when I was at harness, you were doing a lot of software delivery.
So I believe that, you know, you need to ensure that there's the right IDP framework in place for your smooth developer onboarding, your security tooling. I've taken an example of Paco, that it has to be in place to ensure that you're orchestrating, uh, your security, or you have the software supply chain assurance, the CICD, of course, that's the foundation of your platform to ensure that you're delivering your software faster. You have the GitHubs in place, getting in the pipelines in place.
Then comes your resilience engineering, which is your service reliability management, your kiosk engineering, error tracking, incident management, and eventually your, you know, optimizing your cost and your process, which is your cloud cost management, your software delivery, uh, software engineering insights that I believe complete the structure of your platform and build the right foundation. And this is how I have layered it into different steps or different, uh, processes, frameworks. And I, I hope that, you know, eventually folks will watch this talk or will build their platforms tomorrow, will follow the sort of, follow these, these steps or have these, uh, different modules in, in their platform in itself.
One last point before ETH takes over and talks a lot about multi cluster platform engineering and tooling infrastructure has scored, I believe Terraform, uh, brought in the boom in terms of bringing, bringing the platform mindset. But, uh, there's a core role that infrastructure has scored, has played, uh, in terms of platform engineering. It has enabled platform standardization and reusability.
Uh, the, the idea of platform engineering, uh, is obviously to build the right IDPs and IAC helps encode these platforms as reusable or composable components. Uh, you, you, you are able to drive, uh, uh, you know, uh, uh, environmental, uh, I mean, it, it, it allows you to have the right environment to be replicated. Uh, if, if it's working on your machine and you have to work, uh, you have to ensure that you are, uh, using it in a different dev environment or the staging environment at a pro environment.
You need, you have to have the automation and the consistency in place so that even if there are rollbacks or, or there's a, there's a disaster, uh, recovery mechanism that has to kick in it, it becomes simpler. And then obviously, last couple of points I'll cover quickly and interest of time. You have to have the foundations of self, uh, developer self-service or self-service portals.
You, you are templating the, the infrastructure as code templating has to be, you know, say a catalog based or so that you can provision it in, say your, uh, you know, your in IDP framework, say a backstage or a human tech or a port, and then obviously supporting, uh, the, the GitHubs and DevSecOps practices, you need to ensure that they, they are following the right security and compliance practices. There's a vault secrets management in place. There's a workflow, uh, workflow orchestrations, say using Argo CD or plugs.
And then, uh, developer experience tools and, uh, your DLS are, are in place perfectly with this. I'll allow Barat to take over to talk about a little bit about multi cluster platform engineering and what we have. So barat, uh, you can, you can take it from here.
Alright, folks, so problems, problems, problems, right? Uh, we heard a lot of problems, uh, a lot of challenges and as we like to call it in corporates, let's not call it a problem. Let's call it an opportunity.
Yeah. So in terms of the challenges that we spoke about and the opportunities to fix the multi cluster multicloud problem, we have a bunch of them. Um, the previous slide talked about IAC, um, that's, that's one of the most common ones that's been currently used, but of course, IAC brings in a lot of dependencies with itself, right?
So if you talk about this structural, um, step by step kind of thing that we can see how we can solve it, there's the DII open source solution where IAC also fits into this category, right? But then of course, you have to handle all of this on your own. Um, it, it brings in a lot of operational burden and the expertise dependency on those particular tools.
And then there are proprietary solutions, which are great, of course. Um, but the biggest challenge with that is if not today, if not tomorrow, eventually one day we're gonna run into the vendor login problem. Um, we've seen this a lot happen lately, but one of the things that everybody will instantly recognize is of course, um, VMware, right?
For the whole Broadcom situation, people felt boxed in, logged into that particular platform, and they want to get out. So this will always almost happen. With that in mind, we wanna talk about an enterprise grid open source solution, which honestly has been, um, the business model of many good open source companies like Red Hat and, and, and others, right?
So here in the IDP solution that was mentioning earlier, the bottommost layer remains the infrastructure. It could be our clouds, it could be your on-prem, it could be public or private clouds. And then the top most layer is your application delivery, where your end user applications rely on, right?
I wanna talk about the middle layer, which we are trying to like focus on, which could be the platform orchestrator, right? So we need a mechanism to figure out how do I provision, um, Kubernetes clusters and across clouds consistently, and then how do I also ensure that the D two operations are going as per the plan as well? That's the layer we're gonna focus on.
So this is where we wanna focus on this open source project called as ent, where we have a platform engineering solution in, in like, you know, three segments, let's say cluster management, state management, and then observability. So observability and finops, I'm, I'm just gonna group them, and that's probably the most straightforward one to talk about, where observability is just having eyes and ears on what's going on with their platform, right? It could be logging, it could be metrics, it could be costs and so on.
Then the left side of, uh, the screen, the cluster management and state management are the mirror images of, of, um, day zero and day two operations. While cluster management helps define your infrastructure configuration, state management helps define your services configuration. I'm gonna be showing a live example, uh, soon.
But essentially that's, that's the key thing that I wanna convey. Cluster a cluster management is infrastructure and state management is services. So if you look at the generations or, or the transition of how things, um, have, you know, gone ahead, right from 2014, which is like early days of Kubernetes all the way to let's say 20, 23, 24, is that been early adopters?
And then there's, um, OpenShift, which is a very opinionated, opinionated way of humanities and of course, um, on the great vendor solutions. And then as we progress, we can see that there's a good, um, community driven solutions right now where Kubernetes has been the fabric that is orchestrating all the major workloads. And in order to develop this, we have platforms, right, which is current.
So here's where we encapsulate like sort of all the open source components that, uh, are used and co uh, like I said, the whole thing is driven by existing open source projects. Cluster management is taken care primarily by cluster API and all the other cloud providers like capo for OpenStack, CAPA for AWS, cab Z for Azure and so on, right? And then there's the K zero RS and Cosmo, which is the Kubernetes distro, kz RS, that's, that's what, uh, is underneath.
And the control plane manager, which is Cosmo tron and similarly in state management was service orchestration is sw to, is in flux. In the observability side of things, we have a whole bunch of other, um, uh, you know, open source solutions. So this slide basically shows, uh, another layer of IDP and how we basically have it if we are doing completely DIY kind of solution, right?
So in terms of observability, we have like cube cost, Grafana, Prothe and all that. And then kinu, and then, you know, RabbitMQ and all these bunch of services. And if we go to the next slide, we can see how all these complexities are simplified into the three layers that we're talking about, where it's all encapsulated for you and delivered to you as a single platform catalog dot cord io is like a sim like an analogy for, for us to understand this is mobile apps have play store and service templates has catalog.
That's it. Any application that you wanna deploy, um, for example, Argo cd, right? Which is one of the common things we use for our cd.
So it's available as a service template, and all you need to do is do a helmet install and then specify which particular chart you wanna deploy it. That's it, it's as simple as that. Here we have like multiple applications, right?
And all of these are, you know, um, tested and, and, uh, they have gone through like E two E tests and manual testing, and then they're uploaded onto catalog. But in case you have an application that is not intended to be public, we can still use your own application and just make sure that we specify the proper OCI part for the chart. So what I mean to say is, even if the application is not public, you can still upload it to your own catalog, uh, as a helm chart and then specify that during the installation that is supported as well.
I wanna show a live example of how we use Cord in order to provision Kubernetes cluster on OpenStack. So I've chosen OpenStack to be an example for this demo where we can simulate the same thing across multiple clouds as well. So first let me show, um, like, let, let me set up a bit of context.
Currently we are on a kind cluster, which we we'll use as a management cluster, and this cluster will be the base in order to manage hundreds of clusters. Then we've got our cluster templates, right? As you can see, these are cluster templates and you can see that each one exists for a particular variant of a particular cloud.
And today we are gonna be using the OpenStack standalone control plane template, right? And then similarly, the equivalent of this, we have service templates. So for the example that I'm gonna show, I just used a Nvidia GPO operator, right?
So service templates can be installed onto your cluster just like, uh, what I showed earlier using helm upgrade, install, and specifying chart. For now on my cluster, I just had these two and I'm gonna be using this one. And then finally, let's take a look at the cluster deployment that defines this configuration, which is what I mentioned as a single YAML file to define both the infrastructure specific configuration as well as the services configuration.
So your cluster deployment references the template, which you want to use based on the cluster, um, based on the cloud, it references the credential, which I just, um, applied before this. And then this is typical infrastructure configuration changes from cloud to cloud. And over here I'm using T 2 45, which is a flavor of, um, I mean, which is a GPU flavored instance, right?
But for the control plane, I'll be using a normal CPU only instance. And then services I just mentioned, what kind of services I wanna be, I want installed on this cluster. So for now, I mentioned the GP operator and that's it.
So in the interest of time, I had already applied this cluster deployment just before the talk and cord controller takes this configuration, reads the Infras spec stuff, understands the template, uses the credential, and uses, you know, the rest of the infrastructure configuration and actually deploys a cluster on OpenStack. Once the cluster is deployed, then it would also figure out the service spec and it would deploy the particular service on that cluster. So let's check out, so this one, I've already checked out the particular cluster, and if I do a configure view, as you can see, this is the one which we have ed, right?
And then the service configuration, um, just to, just to let you know, since we chose the Nvidia GPO operator, IT has installed that, and then the operator has, has done whatever job it has to do, right? Which is to let the cluster know that this is a GPU enabled cluster. And how do we confirm that this is working by describing the node, right?
Let's describe the worker node. There you go. com/gpu, and here we go.
So essentially the Nvidia GP operator told our Kubernetes cluster that this particular instance has a work note, um, which is G-P-U-G-P-U enabled and added this label so that the workloads can utilize this particular label. And yeah, that's it, right? So in case you want to, um, scale this, all you would need to do is add more services onto the single yam.
So we can easily imagine putting this particular YAML file into a GitHubs enabled repository, and your platform engineers would just need to work with this EML file, update a version, let's say for example, or add more services like Istio in case that's a service that we're interested in and according to do the job of picking up that configuration and coming back here and applying that on the child. I think with that just, uh, prri, I'm gonna pass it over to you so that you can just, um, finish with the community stuff Folks who are watching this talk. You can scan this QR to access the cord GitHub.
Uh, feel free to check it out. Feel free to check out the components. There are different repos, the KCM, the KSM, the cough and other repos that give you access to everything about Cordon.
This is the main repo. And if you're on the CNCF Slack, uh, you can join the cordon channel or scan this QR to join the CNCF Slack and then join the Cordon channel to be a part of the community. Once again, thank you so much everyone, and thank you so much, uh, uh, Brian and folks at TECHSTRONG for, uh, helping record this.
And yeah, I hope you'll love this talk and join cord, uh, and the community.