4 key components teams overlook when building a Kubernetes based developer platform

Kubernetes is becoming the de facto standard when it comes to application deployment and management, just like AWS did for Cloud Computing and VMware did for Enterprise Virtualisation. There is therefore a fair assumption that when your team starts designing a new developer platform for the dev teams to use, it will be backed by Kubernetes. Whether this is running on Cloud, in your Datacenter or both will depend on your organisation’s circumstances and requirements.

And while Kubernetes is a very capable platform, it requires additional components to make it a great platform for dev teams to use. While these components can be implemented after the platform has been designed and deployed, it becomes increasingly time consuming and costly to do so after the fact. In some circumstances it may even require a complete redesign/rebuild which is often not an ideal experience for dev teams. By keeping these 4 components at the forefront during the design and build stages of your platform you are setting yourself up for a great developer experience from Day One. Let’s go through each of these 4 components in a bit more detail.

Logging

When moving to a container based platform the first thing teams will notice is that it becomes more difficult to troubleshoot when and what happened on an application. Because of the inherent nature of containers being ephemeral, making sure that adequate logging is in place should be a top priority from the beginning. It will help you find issues in your apps faster, helping your dev teams to spend less time troubleshooting/bug fixing and more time developing new cool features for your customers.

Logs become incredibly important when auditing who done what where in your environment. Kubernetes is backed by an API which by default keeps track of all requests, once your environment starts growing this can easily generate millions of audit events per day.

It therefore becomes incredibly important that you choose a solution for storing and managing these events and logs. And while starting out, one solution may be sufficient to store and manage all of these logs, you will most likely end up with multiple solutions for each set of logs. The 3 sets of logs you should store at a minimum are:

Application logs

Application logs will assist you in troubleshooting application problems

System component logs

System component logs will assist you to troubleshoot issues on the platform itself

Audit events

Audit events will assist you when someone comes to ask you to let them know who deleted a namespace or scaled down the wrong deployment. It will also assist when the security teams come knocking after a possible system breach.

Some tools that you can look into include Elastic, Kibana, Fluentd, Graylog, Splunk, Datadog, Logstash, etc.

Kibana
Splunk

Monitoring

Moving to a cloud-native/microservice application architecture is difficult at the best of times, doing so without a monitoring solution that’s capable of assisting teams to troubleshoot effectively is a disaster waiting to happen.

Adopting cloud-native applications that could be running across 10s or even 100s of micro-services and possibly across multiple geographical regions is no mean feat. While this design can make applications extremely resilient it can also make it extremely difficult to troubleshoot when things go pear shaped, regardless of whether this was introduced via a change or a component failure.

As with the logging components, when starting out, one monitoring solution may be sufficient  to cover these requirements. However, as your environment starts to grow you’ll most likely realise that certain solutions shine in only a few areas and you’ll require multiple solutions to  make sure you have the best coverage. Make certain your solutions cover all components of your platform, from the application requests down to your cloud or on-prem infrastructure (yes, Public Clouds do not have 100% uptime).

Some open source products you could look into include Grafana, Kiali, Prometheus, Kuberhealthy, Thanos, OpenMetrics, etc.

Kiali
Grafana

Security

With the increased adoption of Kubernetes for application deployment and management, you are almost certainly guaranteed that it will receive a high level of focus from bad actors. This will also extend to any tool sets that interact with Kubernetes such as CI/CD platforms used to build and initiate deployments of applications.

While most of these security features and functions can be enabled/added onto after the fact, they are often time consuming tasks when doing so on a live environment and may even require a rebuild of a platform. Security standards for these platforms are constantly changing, sometimes even monthly, so building your platform from the beginning with a strong security baseline can help ease the burden of keeping it as secure as possible.

Moving to a micro-services architecture means that your attack surface increases exponentially. Where previously you had to make sure that your operating systems were patched and the software you were using didn’t have any vulnerabilities, you now also have to contend with the thousands and later tens or hundreds of thousands of containers running in your environment that could each potentially expose you to a system breach.

Some products you should look at using include Cert-Manager, Clair, Falco, Kube-Warden, Kyverno, Neuvector, Notary, OPA, Trivy, etc.

Neuvector

Training

While this topic is not a component you can deploy on your platform, it is in my opinion the most overlooked part when moving onto a Kubernetes platform.

At the end of the day, you are building a platform that will be used by a multitude of teams. It is therefore incredibly important that they understand the fundamentals of what makes it work as well as its capabilities and features.

Training should not just cover the platform support teams and as well as development teams, it should cover any team that interacts with the platform in any way. Whether this be the security teams that may be responsible for maintaining the security posture of the platform, to the network team that may become involved in troubleshooting some application connectivity issues.

Training is possibly the cheapest and easiest of these 4 components to implement. Training up teams of SMEs who can then cross-skill and then provide internal training can help keep costs to a minimum. There are also thousands of hours of free training resources available online for teams to consume. These resources constantly get updated as new tools and components get released.

Youtube is a great source of free professional grade training materials, you can also check out the below providers

https://www.cncf.io/certification/training/

https://kodekloud.com/

https://www.youtube.com/c/cloudnativefdn

CNCF Training
KodeKloud

Summary

In my opinion, these 4 components are often overlooked when building the first development platform. Teams then have to spend an incredible amount of resources to make sure that they get implemented as soon as possible. They are critical parts of the system and should be part of your solution before going live.

Windows left exposed (again…) by 0-day exploit found for IE 7, 8 & 9

Image

Microsoft has managed to do it yet again. A new 0-day exploit has been found for IE 7, 8 & 9 running on any version of Windows released in the last 10 years. Computers can get compromised simply by visiting a malicious website, which gives the attacker the same privileges as the current user.

Now would be a good time for you to switch to a web browser that doesn’t give you anything short of cancer like Chrome or Firefox.

Check out The Verge link for more info as well as the Metasploit link for the demos.

 

Google++++

Image

During today’s acquisition announcement of Nik Software, Vic Gundotra, Google’s Senior VP for Engineering let slip that Google+ has crossed the 400 million member mark and has over 100 million active users each month. This is a staggering number considering the fact that they had just over 250 million users in June. It is also an impressive number considering the fact that Google+ was only opened to the public just under a year ago (20 Sept 2011).

Google’s social network has been giving Facebook a hard time in recent months by refreshing it’s UI to make it more intuitive, leaving the daddy struggling to keep up.

Google snaps up the Seed

Image

Google has taken another step to rivalling Facebook feature wise (though UI wise they’re miles ahead) with the proposed acquisition of Nik Software, a German developer known for the popular photography app Snapseed.  Snapseed won Apple’s iPad App of the Year in 2011 and has amassed more than 9 million users during its first year of existence.

This should come as good news to Android users as Nik Software showcased a running version of Snapseed on Android at the beginning of the year but we’ve yet to see the apps release on Android. The acquisition would put Google in line with Facebook’s purchase of Instagram which prompted the Social Network giant to release its own Camera app on iOS just a few days after the announcement. The camera app features filters made famous on Instagram, allowing you to upload these filtered photos directly to Facebook.

So should we hope to see something similar to pop up in the not too distant future on the Google+ app? Let’s!

New iPhone! Same iPhone?

Image

So I’ve given a bit of time for the dust to settle before posting my thoughts regarding the iPhone 5 announcement on the 12th September. The reason for that is quite simple, to make sure that all the hype surrounding the announcement has settled and people are able to make a more informed decision (Yeah right…).

So I couldn’t help but feel a slight tinge of disappointment after the new iPhone was announced. Below is a shortened run-down of what the new iPhone will be about:

Bigger display, thinner body

So the most well leaked rumour about the new iPhone was finally revealed. The iPhone 5 now sports a 4 inch IPS LCD display running a 1136×640 resolution at 326 PPI. The body however has taken a diet with the iPhone measuring in at 7.6 mm thick and weighing only 112 grams. And while Apple loves to quote superb facts about their devices, the iPhone 5 is not the thinnest smartphone in the world (There are actually 6 other smartphones thinner than the iPhone 5). This screen also runs at 16:9 ratio meaning it’ll display widescreen videos properly without any black emptiness on the edges. The added real-estate means Apple have been able to add 1 extra row of icons to the homescreen and the majority if not all the apps designed by Apple have been re-written to take advantage of the extra space. Current apps will have to be updated, in their current state they’ll run in their standard resolution, with the extra space getting blacked out.

“Ultrafast Wireless”

No surprise here as Apple announced that the iPhone 5 would support LTE. So it has one chip, one radio and a dynamic antenna. One note to remember that Apple didn’t mention is that if you’re using a CDMA iPhone 5 you still won’t be able to use voice and data at the same time. Below is a list of supported wireless formats:

UMTS/HSPA, LTE, EDGE, HSPA+, HSUPA, HSDPA, GRPS, DC-HSDPA, 802.11a/b/g/n (2.4 GHz and 5 GHz)

Upgraded processor

The iPhone 5 will sport a new chip, the A6 which is supposed to be 2 x faster in the CPU and graphics department. Since there is no way of checking this performance out yet we’ll just take Apple at it’s word and trust that the phone will run smoothly.

Improved battery life

Apple has claimed that they’ve improved the battery life from the iPhone 4S on this new phone, however upon closer inspection it looks like the only thing that they’ve improved on is the standby time. Everything else is the same as the 4S.

iSight /FaceTime Cameras

Below are the specs for the new iSight (Rear) camera as well as the FaceTime (Front) camera:

iSight

8 MP sensor
3264 x 2448 max resolution
Backside illumination
Hybrid IR filter
Five-element lens
f/2.4 aperature
Panorama mode
1080p HD
Improved video stabilization
Face detection
Take photos while recording video

FaceTime

720p
Backside illumination
Face detection
FaceTime over 3G

The iPhone cameras are usually good so expect the minor bump in quality from the 4S lenses. On a smaller note, a major uproar has started in the U.S regarding running FaceTime over 3G and AT&T. According to AT&T, you won’t be able to run FaceTime over 3G unless you’re on a certain FaceTime Data Plan. While we’re yet to see this level of assness from our SP’s be prepared for what could come.

Wideband Audio

Or HD voice as it’s been touted in the press will allow clearer voice due to more of the band being utilised (Who really uses voice these days?). The phone will also feature 3 microphones to allow for better noise cancelation.

Lightning Connector

Apple announced their new connector for their devices going forward. The new 8-pin design will be reversible and you’ll get a free adapter with your iPhone so you can still use your 30-pin cable should you choose to do so. While this should allow you to use your old accessories with the iPhone 5 it’s not guaranteed to work with all accessories.

So that’s it. Apple showed off iOS 6 running on the iPhone 5 but there were no surprises with regards to the OS that was announced a few months ago. Apple have also released a list of iOS 6 Features available according to countries so you can check out what stuff you’ll be able to use off the bat.

iOS 6 Feature Availability

So Apple have released a device that is pretty much on par with what’s been available out there for the last 4 months and while everyone was expecting more, the drones will no doubt flock to buy this latest iteration of Apples pride and joy. You can check out a comparison of the latest smartphones available from the different OEM’s courtesy of The Verge:

SmartPhone OEM comparison

The switcharoo… For better or worse

Image

So for those few of you in the know will be aware that I’ve decided to make a switch to the Android OS for my new Smartphone contract for the next 2 years.

After coming to this decision the next choice was which phone to pick. I eventually went with the Samsung Galaxy S3. It’s probably the most fully featured Smartphone available on the market at the moment (Providing Apple pulls out a hail mary device this evening with it’s iPhone 5 announcement).

CyanogenMod 10 releases ‘M1’ builds

Image

So for those of you that like to keep your CM ROM’s up to date but don’t want to run the risk of loading nightly builds and bricking your devices, look no further… unless you’re standing too far.

CyanogenMod will now be releasing a monthly build at the start of each month for select devices meaning you’ll have a more stable release than the nightly build but won’t be as polished as a beta release.

So if you’re looking to spice up your sad life slightly head to the link below to see if you qualify for this Android goodness.

CyanogenMod Blog

Design a site like this with WordPress.com
Get started