“The developer shouldn’t have to know how to program NSX, or know what the security isolation boundaries are,” continued Fazzone. “But they should know that their organization has taken steps to unify the networking approach between the containerized applications and the traditional applications running in VMs, and take advantage of that ‘service’ offered by IT to extend the NSX-T support up into their container platform, versus just defaulting to the Layer 2 default that’s available in the open source community — so that their organization can realize that complete connectivity model in a consistent way.”
“Harbor is a privately hosted registry, which allows running either on-premises or in any of the major cloud vendors, making it a possibility for organizations that cannot use a public container registry or want to implement a multi-cloud strategy. Harbor started as an internal VMware project and became open source in 2016. Multiple partners, including companies like Pivotal and Rancher, either use Harbor for their container-based environment or work together with Harbor to give the possibility of running the project on their infrastructure. For instance, the Pivotal Container Service includes Harbor as its built-in container registry. For Rancher, Harbor is one of the packages you can deploy to provide a container registry. Moreover, Harbor gives the option to set up multiple instances of these registries on several of these platforms simultaneously and allows replication between them. Through the signing and vulnerability scanning capabilities provided by the project, it turns these into trusted resources.”
“CNCF has reason to be magnanimous beyond the Chocolate Factory prize money – cloud-oriented enterprise software is all the rage. According to CNCF stats published on Wednesday, production usage of CNCF projects has increased more than 200 per cent on average since December 2017 and evaluation – companies testing said code – has risen 372 per cent…. Among CNCF survey respondents – 2,400 IT-types mostly from the US and Europe – 40 per cent of those from enterprise companies (5,000+ employees) report running Kubernetes in production. Over the whole set of people answering the survey, 58 per cent said they are using Kubernetes in production, with 42 per cent considering it for future deployment.”
Networking considered hard: “The amusing thing is that they wanted to connect a GKE On-Prem install running on VSphere for the demo. They could not get a public IP, so they just used MiniKube. Frankly, I think the demo at #GoogleNext2018 was far more amazing connecting MiniKube.”
“The latter piece can be the tricky one when using containers to develop microservices. How do you link up all the component parts when they may be spread across a cluster of server nodes, and instances of them are continually popping up and later being retired as they are replaced by updated versions? In a service-oriented architecture (SOA), which microservices can be seen as the evolutionary heir to, this kind of task is analogous to that taken care of by an enterprise service bus (ESB). So what is needed is a kind of cloud-native version of an ESB…. This is the job that Istio, a relatively new open source project, aims to fill. It is officially described as a service mesh, because parts of it are distributed across the infrastructure alongside the containers it manages, and it sets out to meet the requirements of service discovery, load balancing, message routing, telemetry, and monitoring – and, of course, security.”
