Unified Kubernetes Networking: Project Calico and SUSE Rancher
Broadcasting live from the bustling show floor at SUSECON in Prague, Techstrong Group’s Alan Shimel sits down with Tigera Product Manager Aadhil Abdul Majeed to explore the rapidly evolving world of Kubernetes networking. Abdul Majeed breaks down how Project Calico has transformed from a foundational container network interface into a unified networking platform that seamlessly integrates Envoy and Istio to deliver robust Zero Trust microsegmentation and deep eBPF observability. The two also dive into Tigera’s deep-rooted partnership with SUSE, highlighting how Calico’s pluggable data plane empowers Rancher users with the ultimate choice and resilience for managing complex cloud-native workloads.
Transcript
Hey everyone. Good morning, and welcome to our day two. It's actually day three, but they call it day two here because we had zero day.
But anyway, this is the third day we're doing our Techstrong TV interviews from Prague at SUSECON, and it's been a great event these last couple of days. ai. com.
In any event, though, let me introduce you to our first guest for today. Excuse me. His name is Adil Abdul Majeed.
Yep. I hope I got that right. Yep, that sounds good.
Okay, and Adil is with Tigera. Adil, welcome to Techstrong TV, man. It's great to have you on here.
Yeah, same here, Alan. Thanks for having me. So let's start off talking about you maybe a little bit.
Right. Give people a sense of your journey, of how you came to be here. Right.
So currently, I'm a product manager at Tigera, and Tigera, we are the maintainers of the well-known open source project, Project Calico, in the Kubernetes space. Mm-hmm. We've been in the space for a while now, pretty much since the inception of Kubernetes.
And me, myself, I'm currently in product, but I've had roles in customer success, in delivery engineering, as well as support roles as well in the past. So I've worn many different hats throughout my career, and yeah, glad to be here right now. I'm glad to have you.
Part of open source project. Yep. For folks maybe who are not familiar with Tigera, you mentioned Calico, and that's probably one of the most popular product service that Tigera has.
Yep. But give people a sense of what Tigera is and what Calico is. Correct.
So Tigera, we are the maintainers of Project Calico. So Calico is what we call a container network interface plug-in for Kubernetes. Mm-hmm.
We've pretty much been around since the inception of Kubernetes as a platform. Okay. And the CNI provides the networking layer in the Kubernetes technology stack.
So we are responsible in ensuring that workloads in a cluster can seamlessly as well as securely discover and communicate with each other, right? Love it. So we're an open source project, and we've been partners with SUSE going back many years right now, and we have many joint customers.
Tigera, as a CNI, powers hundreds of thousands of clusters across the globe. And over the years, we've matured as an open source project, and now we offer what we call a unified networking platform for Kubernetes. I love it.
Yep. Where can people get more information on Tigera and Calico? Yeah.
io, which is our website. io, and you can find all about the open source Project Calico, as well as some of our commercial offerings as well. Love it.
All right. Let me pivot now, and we'll go maybe a little deeper into Calico. A lot of people know Calico as a networking tool for cloud native, but the branding, the messaging now is it's a unified platform.
Correct. How should they rethink that? Right.
Connect the dots for us. Got it. Yeah, so the CNI, which was what Calico was known for, which is also called a container network interface plug-in.
The CNI is responsible for plumbing, so to speak, to provide the underlying plumbing so workloads can communicate with each other. But when you look at a Kubernetes networking stack, it can get pretty complex, especially when you are deploying this in production, as well as in on-premise and cloud environments. We now see Kubernetes in the edge as well.
And Kubernetes has also emerged as the de facto platform for running AI workloads. And if you listen to some of the keynotes at SUSE, Kubernetes is also used to run virtual machines, right? So you've got different type of workloads, different use cases deployed in this platform known as Kubernetes, and networking can get pretty complex pretty fast, right?
So when you think about networking, you've got to think about how you bring packets into the cluster, how workloads within the cluster communicate with each other, as well as how packets egress the cluster. And along the way, you have to apply many different types of controls. And for those controls, there tends to be different solutions out there.
Right. So with the unified platform, what we've done is we've built most of the solution stack, as well as incorporated some other open source projects such as Envoy for Gateway API- Mm-hmm ... as well as Istio for Service Mesh- Mm-hmm ...
to offer what we call a unified platform- That's the platform ... that can cater to all these requirements in the networking stack. Right.
Got it. So- Makes sense now. Yeah.
So my background's in security. Right. Been in security long time, 25 plus years.
Security's all about zero trust. Correct. It has been for a while.
AI is forcing us, I think, to really, especially agentic AI- Right ... you got to start with a zero trust kind of mindset and build it from there. Correct.
But when we talk about zero trust inside of Kubernetes, inside of the cloud native architecture, it's not just a slogan. Correct. Right?
How does Calico help with that? That's right. So when it comes to zero trust, I think in security, there's this term, it's called defense in depth, right?
Yep. You got to apply that principle for zero trust as well. I think one common mistake we see users doing is they may enforce the concepts of zero trust within a certain layer in the stack and forget about other layers in the stack.
Right? Yes. So when you think about a cluster such as Kubernetes, you've got the networking layer.
Right. And this is basically about which workloads can communicate with which other workloads. So you've got to start with a solid foundation when you're enforcing zero trust, and that's where things like micro-segmenting your workloads comes into play.
Right. But you also have to think about zero trust at higher layers in the stack. So if you look at the services layer, that's where you need things like mutual TLS for security.
You need a mechanism whereby you can attest your workloads, right? And now when it comes to agentic AI, you've got to rethink identity as well within the context of agents and what agents are allowed to do in an AI application or an agentic AI application. Right?
So what we encourage users to do is think about it in terms of layers and how you enforce the zero trust concepts in each of those layers. Good. Yep.
That's good one on that. KubeCon was recently in Amsterdam- Yep ... as you probably know, I'm sure.
Yep. I was there. Uh-huh.
Observability, as big as Kubernetes is- Right ... observability as a whole is even bigger. And as we've moved to AI-generated code- Yeah ...
AI scanning security- Yes ... observability has become even more important. Correct.
Right? So now when we look at observability, it's kind of changed the game for SREs- Yep ... for DevOps engineers, for platform engineers.
All of these teams have to be working together, and observability becomes sort of the common picture that we look at. Yep. Is that something that you are seeing in Calico as well, in teams, and how are you helping that?
Yeah, that's a really good question. I like how you framed it. Observability becomes this common picture for different teams, right?
So within Calico, we are present in certain layers of the stack, and for those layers, we use a technology known as eBPF to offer deep observability from the kernel, from the Linux kernel. We're able to extract those matrices and logs that then users can forward to an observability stack. We offer our own opinionated dashboards as well.
Right. And we offer those templates as well that they could replicate in their own observability stacks. Right.
But when it comes to observability, like you mentioned, again, you've got to think about it in layers. There are different layers to a Kubernetes technology stack, and you want to make sure what type of logs, matrices, or traces you want to capture from each of those layers so that you get a holistic picture of not just your application, but also the infrastructure that supports that application. Right?
So we predominantly help from the networking space. Calico also has a product that's currently under incubation for the agentic AI space, where we offer some of those agent-to-agent communication traces and spans as well. But that's a more forward-looking solution for us.
But currently, at the networking and the services layer, we offer logs and traces that users can then develop dashboards over in their observability stack. I love it. Last question because- Yep ...
15 minutes goes quick, as we mentioned. Of course, we're here at SUSECON. Yep.
Let's talk, and you mentioned you're a longtime partner of SUSE. How does Calico plug into SUSE's platform? Right.
Joint customers want to know. Yeah, absolutely. If you look at SUSE within Rancher, RKE, as well as K3s, Calico is offered as a CNI.
If you listen to some of the keynotes at SUSE, it's all about choice. Right. And we've partnered with SUSE for a long time now to offer Calico as an option, a networking option within the SUSE Kubernetes platforms.
Right? And if you look at some of the key themes here, which is choice, resilience, sovereignty- Right ... Calico aligns with SUSE very well on those principles.
Right? So when it comes to choice, especially in terms of how you deploy the CNI, we have what we call a pluggable data plane. So we support Linux, eBPF, Windows as well.
Right? So because users want choice when it comes to what type of data plane they want to implement in their clusters. Right.
So we're very well aligned with SUSE on those lines. We also work with the open source community. Right.
We work with the special interest groups to develop the open standards and protocols. And SUSE very much comes from an open source philosophy. Sure.
And again, we are very well aligned on that as well. And on the engineering and the support front, our teams collaborate together to ensure that customers, our joint customers, get the desired level of support and assistance as they roll out these solutions. Right?
So we've had a very good partnership. We're excited to be here at SUSECON, and we hope to strengthen this partnership as well going forward for our users and customers. Beautiful.
The last thing, looking into this camera. Right. Where can they go find out more information about Tigera and Calico?
All right. io. And I imagine on GitHub as well?
Yes, GitHub, we have Project Calico in GitHub. It's an open source project. Feel free to check it out, and feel free to contribute as well.
We're excited to invite other users to participate in the growth of this project. Thank you so much for coming. Thanks, Alvin.
Thank you. Hey, we've got a lot more today, so stay tuned. We're here at SUSECON.