{"id":44823,"date":"2021-08-09T09:16:40","date_gmt":"2021-08-09T01:16:40","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=44823"},"modified":"2021-08-09T09:16:44","modified_gmt":"2021-08-09T01:16:44","slug":"demystifying-cloud-native-networking","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2021\/08\/09\/demystifying-cloud-native-networking\/","title":{"rendered":"Demystifying cloud-native networking"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><em>By Guy Matthews<br>Editor of NetReporter<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The most important evolution in IT over the past few years has undoubtedly been the rise of cloud-native application architectures. There has been a steadily growing awareness of the benefits to be gained from deploying loosely coupled microservices using containers, for the most part orchestrated with Kubernetes. The likely trend for the foreseeable future is for more and more workloads to leverage technologies like these. \u00a0<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cPerhaps what is less understood are the implications for the networking and connectivity needed to support these environments,\u201d says Brad Casemore, VP Research, Datacenter and Multicloud Networking, IDC.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">He notes that by no means all of the enterprises going through a migration towards cloud-native compute have a network that is fit for purpose: \u201cWhen it comes to cloud-native application environments, and supporting the needs of developers and DevOps teams, networking can be complex,\u201d he notes. \u201cKubernetes has specific network requirements, as do native architectures, and many of them are beyond the scope of traditional network infrastructure.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The complexity becomes especially acute up at Layer 7, says Casemore: \u201cIt\u2019s at the application layer where microservices connect to one another,\u201d he explains. \u201cIt&#8217;s very important to understand how the network needs to be adapted to meet these requirements. Containers are obviously changing how applications are developed, but they&#8217;re also changing how applications connect to each other. Most of the container focus has been on orchestration. But the network is also critical for these production deployments, and must have cloud-native attributes. It has to be intelligently automated, elastically scalable, and secure. And there&#8217;s a greater need in this environment to have visibility and observability because of the dynamism of containers.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To get a view from ground level, Casemore spoke to a selection of stakeholders in the cloud-native industry. Thomas Graf is Co-Founder and CTO with open source development specialist Isovalent, creator of Cilium, a popular cloud-native networking project. He has noted a lot of investment by enterprises into meeting the unique requirements of cloud-native environments: \u201cSome of these needs are obvious, around things like scalability and performance,\u201d he observes. \u201cIt won\u2019t be long before the number of container network ports worldwide exceeds the number of virtual ports in virtual machines, similar to the move from physical servers to virtual machines. There are therefore a number of transformations that need to happen.\u201d&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Galeal Zino, Co-Founder &amp; CEO of Zero Trust platform developer NetFoundry, has his own take on the challenge: \u201cI wouldn&#8217;t say our customers are looking to modernize their networks, I would say they are looking to eliminate their networks,\u201d he claims. \u201cThey are trying to develop and deliver secure applications, but in a far more agile, extensible, high velocity manner than they were able to do on prem. They therefore need programmable secure application connections. Instead of essentially moving the network to the cloud or modernizing the network, the challenge is more like how to get rid of the network. The network is a means to an end, at the end of the day.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Pere Monclus, VP and CTO of Networking with software developer VMware, is in broad agreement: \u201cWhen you talk to customers that are thinking in terms of cloud model map transformation, they stop thinking of the network as a standalone entity,\u201d he says. \u201cIt&#8217;s not about compute, storage and networking, or ports, switches and routers. It&#8217;s about choosing an application platform to run applications. How do I run application resiliency, how do I get consistent security across multiple environments, how do I have on demand elasticity of my applications, how do I bring a solution observability to my apps?\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Zino of NetFoundry sees security as a central cloud-native challenge: \u201cThe reality in today&#8217;s world of massively distributed applications is dealing with threats like the recent spate of ransomware attacks,\u201d he believes. \u201cThe only way to do this at scale, with automation, is to do it with code in an intentional built-in manner. You can call it secure by design or Zero Trust. There&#8217;s no way to securely deliver applications in an agile automated way without actually putting that code directly into the app from the start.\u201d&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We are headed for a world of distributed computing and the processing of workloads across a spectrum of compute, from far edge all the way to cloud, envisions Zino. \u201cWe&#8217;ve often been in the position of having to choose between either really strong security and agility and automation and business velocity,\u201d he says. \u201cDone right, we don\u2019t have to make that compromise. That means doing everything as code, abstracting away from security networking infrastructure, and actually being able to avoid a choice between security and agility, instead having both as programmable constructs.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Not every enterprise, of course, is approaching the challenge of cloud-native connectivity from a Year Zero perspective. Monclus of VMware believes many enterprises are still divided between on prem environments and cloud environments: \u201cIdeally all roles should work together to achieve an end-to-end networking experience, from physical to virtual, to service meshes,\u201d he says. \u201cBut in certain cases you still have a traditional networking definition, and that&#8217;s fine. But it can create tensions.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One big question when approaching cloud-native migration is do you buy a solution in, or build it yourself? Graf of Isovalent has seen cloud-native projects where the solution has been almost entirely developed by an end-user. In other instances the user is looking to buy: \u201cWe&#8217;re also sometimes seeing a mix,\u201d he adds. \u201cTo me what connects it all together is the open source component. The model that we see more frequently and more successfully is when customers find a way to successfully work with cloud-native vendors together, but also gain influence into the future development of the product. Cloud-native is still a very young market, so there is still ample possibility and opportunity for customers to influence and drive the product forward. That&#8217;s been our approach to developing our solutions.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Zino of NetFoundry agrees that the two migratory approaches \u2013 buy or build &#8211; are not necessarily mutually exclusive: \u201cThey&#8217;re very complimentary and supplementary,\u201d he says. \u201cIf I take NetFoundry customers as an example, they&#8217;re leveraging both our open source as well as our services. For us, it\u2019s about making sure that our customers don&#8217;t need to choose between security and agility, and that&#8217;s fundamentally the most important problem they have. If they can have both agility and security, then they can win as a business.\u201d&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Monclus explains that VMware is working to help small and medium enterprises to transition to cloud-native principles in a secure manner: \u201cWe\u2019re approaching it in two ways,\u201d he explains. \u201cAs a platform transformation or as a component transformation, depending on the problem that the customer may have, addressing it both ways, and with a strong spin of offering the products and services, SaaS and on prem, with on prem licenses.\u201d&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Graf of Isovalent says the company created its Cilium project with very much this intention in mind: \u201cThe overall goal is for application teams to have the same user experience, whether they deployed to a local laptop, or to a multi cluster Kubernetes environment at massive scale,\u201d he says. \u201cFrom a user experience it should be the same. Networking should not be an added complexity. In order to implement and provide this there are a lot of requirements that come up from a networking perspective. We are providing a universal network plane that works exactly the same across different cloud providers, whether you&#8217;re in the cloud or on prem. We&#8217;re decoupling that and adding a connectivity layer on top. Even more important are additional security requirements that have been mentioned by others, so that\u2019s Zero Trust, least privilege.&nbsp; It&#8217;s about being able to run the same network policies in a Google Cloud or in an Amazon Cloud. It&#8217;s the ability to understand service identities instead of talking about network endpoints, but also from an overall observability perspective.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Graf says the need for observability has gone well beyond what observability solutions have provided so far: \u201cWe can go deeper, and understand the processes inside of a container, such as which individual process has done what at the network level. That&#8217;s the level of granularity and visibility that security demands these days.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But in the final analysis, have enterprises truly started to embrace cloud-native at C-level? Are we talking a common senior management currency yet, or something still below the radar?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cThere\u2019s a broad spectrum of enterprise sophistication,\u201d believes Casemore of IDC. \u201cSome have adopted cloud-native application environments extensively, and C-level executives in those organizations understand the benefits and value associated with that transition, and other organizations are just getting started, and they have yet to fully grasp the opportunities and challenges that are inherent in the shift. The vast majority of enterprises are relatively early on their journeys, and more work needs to be done by the industry to promote a complete understanding of the benefits and implications of going cloud-native. That includes communicating exactly how networking must adapt to meet the challenge.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>There has been a steadily growing awareness of the benefits to be gained from deploying loosely coupled microservices using containers, for the most part orchestrated with Kubernetes. The likely trend for the foreseeable future is for more and more workloads to leverage technologies like these. \u00a0<\/p>\n","protected":false},"author":7,"featured_media":44634,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,26],"tags":[148,1923,857,1130],"class_list":["post-44823","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","category-opinions","tag-cloud-computing","tag-cloud-security","tag-cloud-services","tag-cloud-technology"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/44823","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=44823"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/44823\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/44634"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=44823"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=44823"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=44823"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}