Containerization is really the hot topic these days, but it is similar to the term "microservices" -- not necessarily something new, but just really taking effect, says Derek Collison, Founder and CEO of Apcera.
This video discusses the massive decomposition of software systems underway and how containerization is proving to be especially effective.
"If we really want to build faster, we actually build less and we assemble more...," says Collison.
In 2016, technical innovation, combined with evolutionary trends, will bring rapid organizational changes and new competitive advantages to enterprises capable of adopting new technologies. Not surprisingly, however, the same dynamics will mean competitive risk for organizations that have not positioned themselves to easily absorb (and profit from) new technological changes. The following predictions touch on some of the areas in IT that I think will see the biggest evolutions in 2016 and beyond.
Hadoop: old news in 24 months. Within the next two years, no one will be talking about big data and Apache Hadoop—at least, not as we think of the technology today. Machine Learning and AI will become so good and so fast that it will be possible to extract patterns, perform real-time predictions, and gain insight around causation and correlation without human intervention to model or prepare raw data. In order to function effectively, automated analytics typically need to be embedded in other systems that bring forth data. Next-generation AI-enabled machine learning systems (aka “big data,” even though this term will soon fade away), will be able to automatically assemble and deliver financial, marketing, scientific and other insights to managers, researchers, executive decision makers and consumers—giving them new levels of competitive advantage.
Microservices will change how applications are developed. Containers will disrupt the industry by giving organizations the ability to build less and assemble more since the cost of the isolation context is so small, fast and cheap. While microservices are inherently complex, new platforms are emerging that will make it possible for IT organizations to innovate at speed without compromising security, or performing the undifferentiated heavy lifting to construct these micro-service systems in production. With robust auditing and logging tools, these platforms will be able to reason and decide how to effectively manage all IT resources, including containers, VMs and hybrids.
The container ecosystem will continue to diversify and evolve. The coming year will see significant evolution in the container management space. Some container products will simply vanish from the market, while certain companies, not wanting to miss out on the hype, will simply acquire existing technology to claim a spot in the new ecosystem. This consolidation will shrink the size of the playing field, making viable container management choices easier for IT decision makers to identify. Over time, as container vendors seek to differentiate themselves, those that survive will be the ones that demonstrate the ability to orchestrate complex and blended workloads, in a manner that enterprises can manage with trust. The container will slowly become the most unimportant piece of the equation.
True isolation and security will continue to push technology forward. Next year, look for creative advances in enabling technology, such as hybrid solutions, consisting of fast and lightweight virtual machines (VMs) that wrap containers, micro-task virtualization and unikernels. This is already beginning to happen. For example, Intel's Clear Containers (which are actually stripped-down VMs) use no more than 20 MB of memory each, making them look more like containers in terms of server overhead, and spin up in just 100-200 milliseconds. The goal here is to provide the isolation and security required by the enterprise, combined with the speed of the minimalist “Clear Linux OS.” Unikernels, another emerging technology, possess meaningful security benefits for organizations because they have an extremely small code footprint, which, by definition, reduces the size of the “attack surface.” In addition, unikernels feature low boot times, a performance characteristic always in favor with online customers who have dollars to spend and the burgeoning micro-services crowd.
This coming year is set to be a busy one. Technology is advancing at a pace that has never been seen before. The rise of machine learning in agile enterprises will truly transform the way information is gathered, analyzed and used. Microservices and containers are going to change the way software systems are designed and built, and we’ll see a lot of movement and acquisitions within the container ecosystem. And, as always, security will be a prominent concern; however, much of the new technology adopted next year will be built upon a foundation of isolation and security, not bolted on as an afterthought. Innovation that doesn’t compromise security will be a welcome change. 2016 is shaping up to be an exciting year.
About the Author
Derek Collison is CEO and founder of Apcera, provider of the trusted cloud platform for global 2000 companies. An industry veteran and pioneer in large-scale distributed systems and enterprise computing, Derek has held executive positions at TIBCO Software, Google and VMware. While at Google, he co-founded the AJAX APIs group and went on to VMware to design and architect the industry’s first open PaaS, Cloud Foundry. With numerous software patents and frequent speaking engagements, Derek is a recognized leader in distributed systems design and architecture and emerging cloud platforms.
Got an idea for a Blueprint column? We welcome your ideas on next gen network architecture. See our guidelines.
Ericsson and AT&T demonstrated a Telco Virtualized Network Function (VNF) running in a Platform-as-a-Service (PaaS) environment that is integrated with OpenStack.
The demo at this week's OpenStack Summit in Tokyo showcased a fast and secure deployment of the virtualized Web Communication Gateway (vWCG) in Apcera's container-based, policy-driven PaaS environment that is fully integrated with OpenStack. The demo showed audio and video communications between multiple Web browsers utilizing the vWCG deployed in an OpenStack-integrated PaaS environment.
"AT&T and Ericsson have been working together on a prototype to demonstrate the deployment of a Telco VNF in an OpenStack-based PaaS environment. This specific prototype showcased a fast and secure deployment of the virtualized Web Communication Gateway (vWCG) - a Telco VNF - in Apcera's container-based policy-oriented PaaS environment that is fully integrated with OpenStack," stated Toby Ford, Assistant Vice President, IT Operations Strategic Realization, AT&T.
"Ericsson is leading the development of both Infrastructure-as-a-Service (IaaS) and PaaS environments that are integrated with OpenStack for deploying VNFs on Telco networks. This demonstration showed how a complex VNF such as vWCG can be deployed using Apcera's PaaS technology with a few clicks of a mouse. This is an important step toward fast, secure and policy-integrated deployment of Telco VNFs on micro-services-based containers," stated Magnus Arildsson, Head of IaaS and PaaS, Ericsson.
"The partnership between Ericsson and Apcera has accelerated the development of a micro-services-based PaaS environment suitable for deploying Telco VNFs. This PoC paves the way for cost-effective, efficient deployment of VNFs and further collaboration with Telco operators to integrate carrier-grade requirements with Apcera's trusted cloud platform," stated Derek Collison, CEO and founder, Apcera.
Apcera, a San Francisco-based start-up developing an IT platform-as-a-service (PaaS) that enables enterprises to securely and transparently control the allocation and consumption of IT resources on premise and in the cloud, has extended its Hybrid Cloud Operating System (HCOS) for Mirantis OpenStack. This enables OpenStack users to safely and automatically connect with multiple public clouds, including Amazon Web Services (AWS), VMware vSphere, and Google Compute Engine (GCE). Applications can be shared, moved and governed consistently and securely across all clouds, from a single technology platform. Apcera’s policy-driven HCOS delivers enhanced security and workload mobility for OpenStack by extending fine-grained policy and strong governance functionality across all cloud environments.
Additionally, Apcera will be included in the OpenStack Community Application Catalog.
“From our inception, we have strongly supported the open source community,” said Derek Collison, founder and CEO of Apcera. “As adoption of the hybrid cloud takes hold, it becomes even more critical that open source solutions have the same level of security and governance offered by traditional commercial solutions. By partnering with Mirantis, the leader in OpenStack technology, we are able to deliver the most secure platform for OpenStack users and create a bridge to extend OpenStack interoperability across the public cloud.”
“Many enterprises today want to combine the power of OpenStack with other public and private clouds,” said Mirantis CEO Adrian Ionel. “By certifying Apcera with Mirantis OpenStack, our customers have this ability at their fingertips, backed with the ubiquitous policy and governance enabled by Apcera’s Hybrid Cloud Operating System.”
by Harsh Karmarkar, Director, Solutions Consultants, Alliances & Channels at Apcera
Enterprises today are looking to hybrid cloud to achieve a range of goals: to cut costs; enable a more flexible workforce; offer better customer service; and achieve greater scale. But in an era of “Big Data”, escalating security concerns, and an ever more fragmented set of technology functions being moved to the cloud, fulfilling those goals requires an IT management approach that offers holistic visibility into all resources being used, both on- and off-premise—and a way to consistently govern their use.
This is where policy comes in. But all too often, enterprises are trying to apply traditional, domain-specific policy approaches to a hybrid IT landscape that is defined by an inordinate amount of complexity—and which stubbornly resists being tamed by cobbled-together point solutions.
Defining Policy
Policy in general has been a catch-all term, and one with many definitions. Policy is seen as covering everything from defining explicit corporate rules for employee interactions with customers, to ensuring compliance with legal and regulatory constraints like HIPAA, to defining basic firewall rules—and everything in-between.
As a result, traditional policy approaches unfortunately often define rules through sweeping documents, or are specific to a granular domain. So what happens is that every network utility and access control system, and every subsystem and service, has its own set of implemented policies that may or may not conform to the overarching enterprise business goals, and which may not talk to each other, let alone be holistically manageable by IT.
Fortunately, there is an increasing acceptance of the fact that existing policy approaches are inadequate, and that the more there can be a consistent language and construct for identity and location of both users and data, the easier it is to have an overarching view of what the data is, where it is and who’s looking at.
Ultimately, the goal of any holistic policy approach must be to implement the rules that have been put in place by the business itself and by regulatory bodies for governing data and data access. That policy engine should use an automated rules framework to fulfill those rules, by allowing or disallowing any given action at any given time by any given employee on any given system, across both cloud-based and on-prem IT environments.
Challenges of a Hybrid Architecture
The hybrid cloud has mostly been the playground of development and testing—but that’s beginning to change. Now that many enterprises are moving into hybrid production environments, and the data perimeter is being extended into third-party domains, there’s concern about how to understand what’s being housed where, how to safeguard sensitive data and how to maintain performance in a complex environment, without adding overhead to the process.
Generally speaking, enterprises have been taking two approaches for managing the hybrid IT environment.
For one, IT can clearly separate within their management systems what’s on-premise and what’s not, and build a few links to gain elastic scale and the ability to move workloads around. But more often than not, there’s no unified tooling or governance, so it results in two management structures, a lack of overall visibility and unevenly applied operational rules.
The other approach is to treat all of the data and functions as though they were on-premise. But that gives administrators less control over the remote environment, and if organizations have sensitive information housed remotely, data sovereignty issues can arise.
Policy in both cases can lend value.
Best Practices for Hybrid Implementations
A key place to begin building a policy framework is to ask what, ultimately, are the business goals that policy should enable? Is it effective resource allocation? Is it achieving certain performance or SLA-related benchmarks? Does the enterprise need a geographic view of, say, software licensing term compliance? Is cyber security the main focus? Or is it all of the above and more?
From there, the policy engine must have a grammar that dovetails with the business’ operational language. For instance, an enterprise may define security levels by color. But to third parties, what’s contained in, say, the purple or orange zones is completely unfamiliar. So policy engines for hybrid architectures have to map how enterprises internally view their assets and information to any third-party widely accepted language and processes.
Today’s approaches are also often defined by what employees can’t do. But that blacklist approach is not very extensible in terms of adapting to evolving enterprise realities. For instance, accessing social media may have been a prohibited activity two years ago—but now tweeting and updating Facebook may be critical for an employee to do his or her job.
IT administrators can instead take a white list approach, which explicitly allows each and every approved activity. This ensures that people are only performing actions that IT understands and can manage. Often, the evaluation of one policy rule drives the next policy decision within the situation’s specific context. So, the idea of identity—a sense of who has the right to do what—becomes critically important.
Approaching policy this way may take a bit more time up front to set up, but it helps optimize the IT environment in the long run.
Another basic implementation issue has to do with how policy is enforced. Many enterprises use a centralized engine that evaluates policy compliance, which is then enforced in a distributed way, out in a remote cluster. But whenever there is distributed enforcement and centralized evaluation, it allows for gaps in rules application and inconsistencies.
A better approach is to ensure that every actor within the system is governed locally by the set of policies that can specifically affect him or her. So, the policy engine for both the evaluation and enforcement of compliance is distributed to all of the agents in the system, both in on-premise and remote environments.
That means that there’s no queue for a central engine to make decisions. So whether the infrastructure has 10 actors or 10,000, scaling doesn’t result in a bigger drain on the central IT management structure.
This type of implementation is a fundamentally different approach to architecting the policy brain than what we typically see emerging in the hybrid cloud. But for forward-thinking enterprises, taking steps now to accommodate the complexities of unstructured data, multiple user types and a hodgepodge of domains will give them the ability to programmatically control what an app or workload does, without requiring the IT staff to write code or resort to other manual practices. Thus, they will find themselves delivering better customer service, driving efficiencies and safeguarding operations across the board, for now and in the future.
About the Author
Harsh Karmarkar leads the Alliances pre-sales team for Apcera.
About Apcera
Based in San Francisco, California, Apcera has deployed the world's first policy-driven platform for global 2000 companies. Continuum, Apcera's flagship product is a PaaS++ that deploys, orchestrates and governs a diverse set of workloads, on premise and in the cloud. In September 2014, Ericsson purchased majority interest in Apcera, though Apcera remains an independent company.
Mobile World Congress will showcase lots of innovation in radio access technologies, says Derek Collison, founder and CEO of Apcera. But once the flood of data arrives on the network, how do you trust it and how do you know which clouds services can tap into it. Apcera is introducing its Hybrid Cloud Operating System as a trusted platform to run anywhere.
Apcera, a start-up backed by Ericsson that offers a Platform-as-a-Service (PaaS) that deploys, orchestrates and governs workloads on premise and in the cloud, announced a partnership with Tropo to provide telcos and developers a platform for building and delivering mission-critical communications apps. Tropo specializes in real-time telco APIs. These will now be offered running on Apcera's Continuum policy-driven platform-as-a-service (PaaS). The planned joint solution will be deployed by a Tier 1 carrier in 2015.
Tropo's APIs allow telcos, developers and enterprises to quickly create and deploy real-time voice, video and messaging apps.
“Apcera is a young, agile company that is leveraging its innovative technology to reinvent the PaaS market, much like Tropo has done in the communications-as-a-service space,” said Jason Goecke, CEO and president of Tropo. “Our solutions are perfect complements to each other, and bringing them together will give our customers a great opportunity to leverage a leading-edge PaaS to speed new cloud-based communications apps to market, while ensuring a high level of security.”
Apcera's Continuum PaaS++ ensures reserved capacity and more fine-grained control over resources, including network and service access.
“Tropo shares our vision for delivering the platform and solutions telcos require to develop new offerings to differentiate themselves in a competitive market,” said Derek Collison, founder and CEO of Apcera. “We look forward to working with Tropo to showcase the ease with which new, high-performance communications apps can be quickly developed and securely deployed with our respective offerings.”
In September 2014, Ericsson announced its acquisition of a majority stake in Apcera, a San Francisco-based start-up developing an IT platform-as-a-service (PaaS) that enables enterprises to securely and transparently control the allocation and consumption of IT resources on premise and in the cloud. Financial terms were not disclosed. Apcera's Continuum PaaS works across cloud, on premise and hybrid environments. Ericsson said the addition of Apcera's technology enables it to provide cloud automation to run all workloads and use cases, while providing complete control for infrastructure.
Apcera was founded in 2012 with investment from True Ventures, Kleiner Perkins Caufield & Byers, Rakuten, Andreessen Horowitz and Data Collective. The cinoabt was started by former Google and VMware executive Derek Collison with the intent of bridging the divide between developers and ops organizations with an enterprise-class platform that integrates policy and security from the start.