Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Hashiconf NA 2019 Tooling for the modern cloud ...

Hashiconf NA 2019 Tooling for the modern cloud native application stack

The modern cloud native application stack typically consists of different runtimes whether it be virtual machines, Kubernetes, or serverless and cloud hosted services. How do you use the tools you know and love to build across these different environments? We will share how HashiCorp and Microsoft are collaborating in open source to provide an integrated, consistent tooling experience. Whether it be securing Kubernetes secrets with Vault, having a Consul-based service mesh that spans Virtual Machines and Kubernetes, or even packaging your application stack up in a portable bundle, we’ll share how we are making it easier for you to bring your favorite HashiCorp tools to Azure.

Lachlan Evenson

September 11, 2019
Tweet

More Decks by Lachlan Evenson

Other Decks in Technology

Transcript

  1. What we hear from customers How do I integrate Consul

    as a service mesh for Kubernetes and VMs? How do I secure secrets in Kubernetes with Vault? How can I bundle up my application and all its dependencies into a single unit? @LachlanEvenson @ritazzhang
  2. And when we dig deeper Remove integration pain Use tooling

    they already trust Flexibility @LachlanEvenson @ritazzhang
  3. Our team 100% open source Vendor neutral Strive to provide

    standardized solutions @LachlanEvenson @ritazzhang
  4. Lachlan Evenson @LachlanEvenson • Program Manager in Azure Container Compute

    • HashiCorp fan circa 2013 • Upstream Consul Helm chart maintainer • Kubernetes 1.16 release lead • CNCF Ambassador • Using and contributing to open source software for 8 years
  5. Rita Zhang @ritazzhang • Software Engineer in Azure Container Compute

    • Maintainer of Secrets Store CSI Driver • Maintainer of Open Policy Agent Gatekeeper (Kubernetes policy controller)
  6. Why Consul as a service mesh? Supports multiple runtimes May

    span networks Production ready Flexible @LachlanEvenson @ritazzhang
  7. Integrating Consul into Kubernetes •Runs on Kubernetes •Configurable via Service

    Mesh Interface (SMI) •Use Kubernetes native tooling @LachlanEvenson @ritazzhang
  8. • What if I already use HashiCorp Vault in my

    company? • Why should Kubernetes be any different? • Instead of storing my application secrets in etcd, is it possible to store them in Vault and use them in my Kubernetes applications? @LachlanEvenson @ritazzhang
  9. Why Secrets Store CSI Driver? Separation of concerns Supports multiple

    secrets store providers Application portability Community designed and maintained @LachlanEvenson @ritazzhang
  10. Container Storage Interface (CSI) Driver Standard for exposing third- party

    storage systems to containerized workloads Once the CSI plugin is deployed on the cluster, users can create volumes Once the Volume is attached, the data in it is mounted into the container's file system @LachlanEvenson @ritazzhang
  11. Secrets Store CSI driver [Vault Provider] Master Node API Server

    Kubelet Pod Pod Secrets Store CSI Driver Volume Mount path: /etc/foo Pod https://github.com/deislabs/secrets-store-csi-driver @LachlanEvenson @ritazzhang
  12. Case Study: How can I bundle up my application and

    all its dependencies into a single unit?
  13. Why Cloud Native Application Bundles (CNAB)? the tools you already

    use any configuration needed for your app distributed via existing mechanisms @LachlanEvenson @ritazzhang
  14. Building bundles with Porter • Your app and its baggage:

    installed • Smart bundles out-of-the-box • Bundle management: simplified https://github.com/deislabs/porter @LachlanEvenson @ritazzhang
  15. Cloud Native Application Bundle Demo •Create a bucket •Deploy Kubernetes

    Cluster •Provision PostgreSQL Database Cluster •Deploy Spring Music and connect it to PostgreSQL •All on Digital Ocean https://github.com/jeremyrickard/do-porter @LachlanEvenson @ritazzhang