SlideShare a Scribd company logo
©2019 VMware, Inc.
Run and Operationalize
Kubernetes in Production
VMware Enterprise PKS Overview
February 2019
Confidential │ ©2019 VMware, Inc. 22
Enterprises are Embracing Cloud Native Methodology
Container technology is being adopted across all industries
Increase
Developer
Productivity
Deliver Better
Customer
Experiences
Accelerate
Time-to-Market
Gain
Operational
Efficiency
Confidential │ ©2019 VMware, Inc. 33Confidential │ ©2018 VMware, Inc.
Kubernetes has Become the De Facto Container Orchestrator
Source: Cloud native Computing Foundation User Survey 2018
0%
10%
20%
30%
40%
50%
60%
70%
80%
90%
Kubernetes Docker Mesos
Confidential │ ©2019 VMware, Inc. 44Confidential │ ©2018 VMware, Inc.
Challenges of Running Kubernetes in Production
Source: Cloud native Computing Foundation User Survey 2018
0%
5%
10%
15%
20%
25%
30%
35%
40%
45%
VMware Enterprise PKS Addresses These Challenges
5©2019 VMware, Inc.
VMware Enterprise PKS
©2019 VMware, Inc.
VMware Enterprise PKS
• Deploy clusters on demand
• Simplified Patching,
Upgrading, Scaling
• Integration with platform
pipeline
Easy to Use and
Maintain
• NSX-T Micro-
segmentation
• Rotate, Repair, Repave
• Image CVE scanning,
Content Trust
Highly Secure by
Default
• Wavefront
• vRealize Log Insight
• Network Insight
• vRealize Automation
• Prometheus, Jaeger,
Grafana, Istio
• Cluster as a unit of
tenancy
• Namespace as a unit
of tenancy
• LDAP/AD Integration
Flexible
Multi-Tenancy
• Health Monitoring and
Self-healing
• Kubernetes manages app
layer availability
• BOSH manages
infra/cluster layer
availability
Highly Available “Dial
Tone” Kubernetes
Highly Integrated
Ecosystem
VMware Enterprise PKS is a turnkey solution for organizations that want to deploy and operate an
integrated, validated upstream Kubernetes footprint
©2019 VMware, Inc. 7
Kubernetes is Only One Layer of the Container Service Stack
Image Registry
Framework Lifecycle Management
Security and Networking
Persistence
Virtual Infrastructure
Physical Infrastructure
Monitoring,Logging,Analytics
Cluster Health Monitoring, Healing and
Lifecycle Management
Scheduling,
Orchestration, Service Creation
vSAN, Hatchway
vSphere
Physical Infrastructure
NSX-T
Enterprise PKS Control Plane
BOSH (cluster LCM)
Kubernetes
Harbor
vRealizeSuite
©2019 VMware, Inc. 8
BOSH
NSX-T
Service Brokers
etcd worker etcd workermaster
PKS Control Plane
Kubernetes Cluster
VMware Enterprise PKS
Security
Container
Registry
master
Kubernetes Cluster
vRealize
Automation
vRealize
Log Insight
vRealize
Operations
vRealize
Network
Insight
Wavefront
by VMware
VMware Enterprise PKS: Marketecture
vSphere
vSAN
Public Clouds
Public Cloud Storage
Confidential │ ©2019 VMware, Inc.
Who is VMware Enterprise PKS Built For?
IT
Operator
– PRE (Platform Reliability
Engineering)
– Deploy, Scale, Operate VMware
PKS
– Physical Infrastructure is Operated
– Network & Security Control Policy
is defined
• Developers
– Writes code, code deployed using CI/CD
– Focus on business problems and innovation
• Application Dev/Ops owner
– Automate Everything
– Agile
– Serve developers
• Platform Reliability Engineers
– Platform is Reliable
– Capacity Is planned for
– Platform is Secured & Controlled
– Platform is Auditable
Application
Dev/Ops Owner
Platform
Reliability Engineer
Developers
– Develop, Deploy, Scale,
Monitor Apps
– Innovation of Business
Capability as Cloud native
Apps
– Create K8s cluster, scale
clusters and maintain the
health customers
– Provide developer access
to the cluster
Confidential │ ©2019 VMware, Inc. 1010Confidential │ ©2018 VMware, Inc.
A turnkey solution to provision, operate and manage enterprise grade Kubernetes clusters
VMware Enterprise PKS
Latest stable native Kubernetes,
CNCF certified
Production-grade Kubernetes based
container platform
Deep integration with NSX-T for
networking and security
Globally supported on
vSphere, GCP, AWS, and Azure
Secure, enterprise-grade container
registry
Consistent infrastructure for traditional
and modern applications
11©2019 VMware, Inc.
Addressing the Common
Kubernetes Challenges
Complexity
Scaling Deployment
Networking
Storage
Monitoring & Logging
Security
Confidential │ ©2019 VMware, Inc. 1212Confidential │ ©2018 VMware, Inc.
• Constant monitoring and self-healing of VMs
• Easy scaling and patching for clusters
• Rolling upgrades to latest Kubernetes release
• High availability and multi-AZ support
VMware Enterprise PKS Simplifies “Day 1” and “Day 2” of Kubernetes Clusters
• Deploy Kubernetes cluster on
demand
• Simple API and CLI interface
Day 2 “Operate”
Day 1 “Build”
Confidential │ ©2019 VMware, Inc. 1313Confidential │ ©2018 VMware, Inc.
IaaS
Node
Node
Kubernetes
Cluster Services
API
Cluster3
NSX-T
vSphere
VMware PKS includes:
• VMWare PKS Control Plane,
CFCR
• NSX-T, Harbor, Service Broker
• BOSH Release for Kubernetes
• Configures Day 1 of
- CFCR
- vSphere/Public Clouds
- NSX Integration
- Harbor
• Manages Day 2 of
Kubernetes Clusters
- Scaling
- Patching
- Upgrades
- Failures
CFCR
Kubernetes
(As a BOSH Release)
BOSH
(Deploys/Manages VMs & state)
CPI
CNI
Harbor
Private Container
Registry
The value of BOSH
VMware Enterprise PKS - “How it Works”
Node
Node
Node
Kubernetes
Cluster Services
API
Node
Node
Node
Kubernetes
Cluster Services
API
Node
Cluster1
Cluster2
Service
Broker (s)
API
#pks create-cluster K8s-1 -n 3#pks create-cluster K8s-2 -n 3#pks create-cluster K8s-3 -n 3#pks resize K8s-3 –n 5
VMware PKS Control Plane
VM
VM
VM
VM
VM
VM
VM
VM
VM
Node
Node
Kubernetes
Cluster Services
API
Cluster3 Node
Node
Node
VM
VM
VM
VM
VM
14©2019 VMware, Inc.
Addressing the Common
Kubernetes Challenges
Complexity
Scaling Deployment
Networking
Storage
Monitoring & Logging
Security
Confidential │ ©2019 VMware, Inc. 1515Confidential │ ©2018 VMware, Inc.
Best-in-Class Kubernetes Networking with NSX-T
NSX-T is included in VMware Enterprise PKS to enable
• Networking virtualization and automation for Kubernetes
• Complete set of Layer 2 through Layer 7 networking services
• Pod-level networking and micro-segmentation
• Rich set of management and troubleshooting tools
• Layer 4 load balancer (not just layer 7 load balancer) for
supporting a wider range of applications
• Security policy that can apply to both your containers and VMs
workloads
Confidential │ ©2019 VMware, Inc. 1616Confidential │ ©2018 VMware, Inc.
Canal
Comparing NSX-T to Open Source Networking Options
L2
L3 (North/South)
L4 – Security Policy
Load Balancing
VM & K8s Connectivity
End-to-End
Configuration & troubleshooting
Ops tools & central stats
Flannel
L2 only (East/West Pod Traffic)
Calico
L3/L4 (IP Tables)
NGINX/HA Proxy
Load balancing
No End-to-End configuration & troubleshooting
New ops tools + Different locations for stats
NSX-T
Only for Kubernetes Networking
Confidential │ ©2019 VMware, Inc. 1717
Container Networking & Security Operations
NSX-T Operational
Tools
• Traceflow
• Port Mirroring
• Port Connection
Tool
• Spoofguard
• Syslog
• Port Counters
• IPFIX
17
NSX-T Traceflow
With NSX-T you are gain deep visibility into the container networks, and you can use the same
troubleshooting tools we created for VM based workloads
18©2019 VMware, Inc.
Addressing the Common
Kubernetes Challenges
Complexity
Scaling Deployment
Networking
Storage
Monitoring & Logging
Security
Confidential │ ©2019 VMware, Inc. 19
Persistent Storage with Kubernetes
• You need a storage platform with the right Cloud
Provider (Storage Plugin) for Kubernetes
• You must configure the Kubernetes Cluster and all
the nodes
– Configuration Management everywhere
• Available features & functionality dictated by storage
platform keeping up with Kubernetes releases
• Maintaining the “Platform” over time
– Update all your configuration management
– End-to-end Testing (Compatibility of System)
– High risk of snowflakes
Must have available Kubernetes
Cloud Provider
Node
Node
Node
Kubernetes Cluster
Services
API
V
V
V
CP
CP
CP
CP
Storage Platform
VM
VM
VM
Confidential │ ©2019 VMware, Inc. 20
VMware Enterprise PKS Provides Persistent Storage for Running
Stateful Apps on Kubernetes
• Entire HCL of storage products under vSphere Supported with Kubernetes
• Operational Consistency - Existing Storage Operations, Tooling, and SPBM
• Self Service Storage provisioning through Storage Class Mapping to SPBM Policies
• VMware Enterprise PKS delivers the consistent, repeatable configuration & maintenance of
Hatchway
Kubernetes Consumption
• Storage Class = Regular
• Storage Class = Fast
• Storage Class = Encrypted
• Storage Class = Dedup
• Storage Class = …
K8s API
SPBM
• Thin
• SSD
• Encrypted
• Dedup
• …
vSphere
Any Supported
Storage on HCL
vSAN|VMFS|NFS
Datastore
Project
Hatchway https://github.com/vmware/hatchway
21©2019 VMware, Inc.
Addressing the Common
Kubernetes Challenges
Complexity
Scaling Deployment
Networking
Storage
Monitoring & Logging
Security
Confidential │ ©2019 VMware, Inc. 2222Confidential │ ©2018 VMware, Inc.
Automated deployment & configuration from infrastructure to applications
Monitoring & Logging at Scale with VMware Integration
Infra K8s Containers Apps
Application
Dev/Ops Owner
Platform
Reliability Engineer
vRLI
vRops Wavefront
Confidential │ ©2019 VMware, Inc.
Wavefront & VMware Enterperise PKS Integration
K8s Monitoring Integration w/
Wavefront by VMware
• Pre-Integrated with VMware PKS
• Predefined K8s Alerts
• Comprehensive Dashboards
• Self-Service Metrics Analytics for both
Developers and Operators
Platform
Reliability Engineer
Application
Dev/Ops Owner
Troubleshoot Issues
at Cloud Speed
Trend & Alert
on Anomalies
Visualize Cloud Apps
at Hyperscale
Confidential │ ©2019 VMware, Inc. 2424Confidential │ ©2018 VMware, Inc.
Wavefront + VMware Enterprise PKS Dashboard
Confidential │ ©2019 VMware, Inc.
vRealize Log Insight and VMware Enterprise PKS Integration
K8s Logging Integration w/
vRealize Log Insight
• Configured via VMware PKS Tile
• Aggregates, Tags, & Ships all logs
to vRLI
• Searchable tags:
Cluster, Pod, Namespace,
Container
• SSL Encryption of Data in Transit
• Log Ingestion Rate Limiting
vRLI
Master / Worker
Nodes Logs
K8s Cluster Events
POD StdOut &
StdErr
vRLI Interactive Analytics
26©2019 VMware, Inc.
Addressing the Common
Kubernetes Challenges
Complexity
Scaling Deployment
Networking
Storage
Monitoring & Logging
Security
Confidential │ ©2019 VMware, Inc.
VMware Enterprise PKS Provides Container Security at all levels from infrastructure to
Application
Infrastructure
StorageCompute Networking
Container
Mgmt.
NameSpace
vSphere Google Cloud Platform
Hybrid
NameSpace
NameSpace NameSpace
Container
Mgmt.
NameSpace NameSpace
NameSpace
Operator admin
IAM
• Role Based Access
Control (RBAC)
• Identity Management
• Credential Stores
Events &
Monitoring
• Incident Reporting
• Event Management
• Full Stack Monitoring
Build Pipelines
NameSpace
Platform LCM
Kubernetes Cluster Kubernetes Cluster
Apps Apps
Micro-
service
Micro-
service
Micro-
service
Micro-
service
Micro-
service
Micro-
service
Micro-
service
Micro-
service
Platform LCM
• Repair
• Repave
• Rotate
Container
Management
• Vulnerability Scanning
• Content Trust
• Centralized Policy
Control
Infrastructure
• Cluster Segmentation
• Flow Tracing
• NameSpace
Segmentation
LDAP/AD
Integration
IAM
VNFM
WaveFront
vRealize
Operations
Monitoring
VNFM
WaveFront
App Monitoring
Confidential │ ©2019 VMware, Inc.
• user management & access control
• role-based access control
• AD/LDAP integration
• Security vulnerability scanning
(Clair)
• content trust - image signing
• policy based image replication
• audit and logs
• Restful API
• open-source under Apache 2
license
Harbor – Enterprise Grade Private Registry
Project Harbor was accepted
into CNCF as its first container
registry open source project
Confidential │ ©2019 VMware, Inc. 2929Confidential │ ©2018 VMware, Inc.
Why VMware Enterprise PKS?
Entire Lifecycle of the Kubernetes
Clusters
Latest Stable Open Source
Kubernetes
Multiple Clusters On-Demand
Best-in-Class Kubernetes Networking
End-to-End K8s Infrastructure
Provisioning
Enterprise Private
Container Registry
Persistent Storage
Integrates With VMware SDDC &
Multi-Cloud
©2019 VMware, Inc.
Thank You
Please email any questions to PowerPoint@vmware.com

More Related Content

What's hot

Concourse, Spinnaker, Cloud Foundry, Oh My! Creating Sophisticated Deployment...
Concourse, Spinnaker, Cloud Foundry, Oh My! Creating Sophisticated Deployment...Concourse, Spinnaker, Cloud Foundry, Oh My! Creating Sophisticated Deployment...
Concourse, Spinnaker, Cloud Foundry, Oh My! Creating Sophisticated Deployment...
VMware Tanzu
 
Pivotal Platform: A First Look at the October Release
Pivotal Platform: A First Look at the October ReleasePivotal Platform: A First Look at the October Release
Pivotal Platform: A First Look at the October Release
VMware Tanzu
 
Cloud-Native Operations with Kubernetes and CI/CD
Cloud-Native Operations with Kubernetes and CI/CDCloud-Native Operations with Kubernetes and CI/CD
Cloud-Native Operations with Kubernetes and CI/CD
VMware Tanzu
 
Unlock Sustainable Kubernetes Services for TAS
Unlock Sustainable Kubernetes Services for TASUnlock Sustainable Kubernetes Services for TAS
Unlock Sustainable Kubernetes Services for TAS
VMware Tanzu
 
Pivotal Developer-Ready Infrastructure Slides
Pivotal Developer-Ready Infrastructure SlidesPivotal Developer-Ready Infrastructure Slides
Pivotal Developer-Ready Infrastructure Slides
VMware Tanzu
 
Pivotal Platform - December Release A First Look
Pivotal Platform - December Release A First LookPivotal Platform - December Release A First Look
Pivotal Platform - December Release A First Look
VMware Tanzu
 
vSphere with Kubernetes Virtual Event- June 16, 2020
vSphere with Kubernetes Virtual Event- June 16, 2020vSphere with Kubernetes Virtual Event- June 16, 2020
vSphere with Kubernetes Virtual Event- June 16, 2020
VMware Tanzu
 
Building Developer Pipelines with PKS, Harbor, Clair, and Concourse
Building Developer Pipelines with PKS, Harbor, Clair, and ConcourseBuilding Developer Pipelines with PKS, Harbor, Clair, and Concourse
Building Developer Pipelines with PKS, Harbor, Clair, and Concourse
VMware Tanzu
 
Tanzu Standard
Tanzu StandardTanzu Standard
Tanzu Standard
VMware Tanzu
 
Migrating from Self-Managed Kubernetes on EC2 to a GitOps Enabled EKS
Migrating from Self-Managed Kubernetes on EC2 to a GitOps Enabled EKSMigrating from Self-Managed Kubernetes on EC2 to a GitOps Enabled EKS
Migrating from Self-Managed Kubernetes on EC2 to a GitOps Enabled EKS
Weaveworks
 
From Pivotal to VMware Tanzu: What you need to know
From Pivotal to VMware Tanzu: What you need to knowFrom Pivotal to VMware Tanzu: What you need to know
From Pivotal to VMware Tanzu: What you need to know
VMware Tanzu
 
Packaging and Distributing Applications for Kubernetes
Packaging and Distributing Applications for KubernetesPackaging and Distributing Applications for Kubernetes
Packaging and Distributing Applications for Kubernetes
VMware Tanzu
 
Pivotal Cloud Foundry 2.6: A First Look
Pivotal Cloud Foundry 2.6: A First LookPivotal Cloud Foundry 2.6: A First Look
Pivotal Cloud Foundry 2.6: A First Look
VMware Tanzu
 
Kubernetes 1.21 release
Kubernetes 1.21 releaseKubernetes 1.21 release
Kubernetes 1.21 release
LibbySchulze
 
VMworld 2015: Build and Run Cloud Native Apps in your Software Defined Data C...
VMworld 2015: Build and Run Cloud Native Apps in your Software Defined Data C...VMworld 2015: Build and Run Cloud Native Apps in your Software Defined Data C...
VMworld 2015: Build and Run Cloud Native Apps in your Software Defined Data C...
VMworld
 
Kubernetes for the VI Admin
Kubernetes for the VI AdminKubernetes for the VI Admin
Kubernetes for the VI Admin
Kendrick Coleman
 
2009-dec02_Dell
2009-dec02_Dell2009-dec02_Dell
2009-dec02_Dell
Agora Group
 
Modern Application Configuration in Kubernetes
Modern Application Configuration in KubernetesModern Application Configuration in Kubernetes
Modern Application Configuration in Kubernetes
VMware Tanzu
 
Devops lifecycle with Kabanero Appsody, Codewind, Tekton
Devops lifecycle with Kabanero Appsody, Codewind, TektonDevops lifecycle with Kabanero Appsody, Codewind, Tekton
Devops lifecycle with Kabanero Appsody, Codewind, Tekton
Winton Winton
 
VMworld 2015: Containers without Compromise - Persistent Storage for Docker C...
VMworld 2015: Containers without Compromise - Persistent Storage for Docker C...VMworld 2015: Containers without Compromise - Persistent Storage for Docker C...
VMworld 2015: Containers without Compromise - Persistent Storage for Docker C...
VMworld
 

What's hot (20)

Concourse, Spinnaker, Cloud Foundry, Oh My! Creating Sophisticated Deployment...
Concourse, Spinnaker, Cloud Foundry, Oh My! Creating Sophisticated Deployment...Concourse, Spinnaker, Cloud Foundry, Oh My! Creating Sophisticated Deployment...
Concourse, Spinnaker, Cloud Foundry, Oh My! Creating Sophisticated Deployment...
 
Pivotal Platform: A First Look at the October Release
Pivotal Platform: A First Look at the October ReleasePivotal Platform: A First Look at the October Release
Pivotal Platform: A First Look at the October Release
 
Cloud-Native Operations with Kubernetes and CI/CD
Cloud-Native Operations with Kubernetes and CI/CDCloud-Native Operations with Kubernetes and CI/CD
Cloud-Native Operations with Kubernetes and CI/CD
 
Unlock Sustainable Kubernetes Services for TAS
Unlock Sustainable Kubernetes Services for TASUnlock Sustainable Kubernetes Services for TAS
Unlock Sustainable Kubernetes Services for TAS
 
Pivotal Developer-Ready Infrastructure Slides
Pivotal Developer-Ready Infrastructure SlidesPivotal Developer-Ready Infrastructure Slides
Pivotal Developer-Ready Infrastructure Slides
 
Pivotal Platform - December Release A First Look
Pivotal Platform - December Release A First LookPivotal Platform - December Release A First Look
Pivotal Platform - December Release A First Look
 
vSphere with Kubernetes Virtual Event- June 16, 2020
vSphere with Kubernetes Virtual Event- June 16, 2020vSphere with Kubernetes Virtual Event- June 16, 2020
vSphere with Kubernetes Virtual Event- June 16, 2020
 
Building Developer Pipelines with PKS, Harbor, Clair, and Concourse
Building Developer Pipelines with PKS, Harbor, Clair, and ConcourseBuilding Developer Pipelines with PKS, Harbor, Clair, and Concourse
Building Developer Pipelines with PKS, Harbor, Clair, and Concourse
 
Tanzu Standard
Tanzu StandardTanzu Standard
Tanzu Standard
 
Migrating from Self-Managed Kubernetes on EC2 to a GitOps Enabled EKS
Migrating from Self-Managed Kubernetes on EC2 to a GitOps Enabled EKSMigrating from Self-Managed Kubernetes on EC2 to a GitOps Enabled EKS
Migrating from Self-Managed Kubernetes on EC2 to a GitOps Enabled EKS
 
From Pivotal to VMware Tanzu: What you need to know
From Pivotal to VMware Tanzu: What you need to knowFrom Pivotal to VMware Tanzu: What you need to know
From Pivotal to VMware Tanzu: What you need to know
 
Packaging and Distributing Applications for Kubernetes
Packaging and Distributing Applications for KubernetesPackaging and Distributing Applications for Kubernetes
Packaging and Distributing Applications for Kubernetes
 
Pivotal Cloud Foundry 2.6: A First Look
Pivotal Cloud Foundry 2.6: A First LookPivotal Cloud Foundry 2.6: A First Look
Pivotal Cloud Foundry 2.6: A First Look
 
Kubernetes 1.21 release
Kubernetes 1.21 releaseKubernetes 1.21 release
Kubernetes 1.21 release
 
VMworld 2015: Build and Run Cloud Native Apps in your Software Defined Data C...
VMworld 2015: Build and Run Cloud Native Apps in your Software Defined Data C...VMworld 2015: Build and Run Cloud Native Apps in your Software Defined Data C...
VMworld 2015: Build and Run Cloud Native Apps in your Software Defined Data C...
 
Kubernetes for the VI Admin
Kubernetes for the VI AdminKubernetes for the VI Admin
Kubernetes for the VI Admin
 
2009-dec02_Dell
2009-dec02_Dell2009-dec02_Dell
2009-dec02_Dell
 
Modern Application Configuration in Kubernetes
Modern Application Configuration in KubernetesModern Application Configuration in Kubernetes
Modern Application Configuration in Kubernetes
 
Devops lifecycle with Kabanero Appsody, Codewind, Tekton
Devops lifecycle with Kabanero Appsody, Codewind, TektonDevops lifecycle with Kabanero Appsody, Codewind, Tekton
Devops lifecycle with Kabanero Appsody, Codewind, Tekton
 
VMworld 2015: Containers without Compromise - Persistent Storage for Docker C...
VMworld 2015: Containers without Compromise - Persistent Storage for Docker C...VMworld 2015: Containers without Compromise - Persistent Storage for Docker C...
VMworld 2015: Containers without Compromise - Persistent Storage for Docker C...
 

Similar to Enterprise pks overview

Pivotal Container Service : la nuova soluzione per gestire Kubernetes in azienda
Pivotal Container Service : la nuova soluzione per gestire Kubernetes in aziendaPivotal Container Service : la nuova soluzione per gestire Kubernetes in azienda
Pivotal Container Service : la nuova soluzione per gestire Kubernetes in azienda
VMware Tanzu
 
VMware Tanzu Introduction
VMware Tanzu IntroductionVMware Tanzu Introduction
VMware Tanzu Introduction
VMware Tanzu
 
VMware Tanzu Kubernetes Connect
VMware Tanzu Kubernetes ConnectVMware Tanzu Kubernetes Connect
VMware Tanzu Kubernetes Connect
VMware Tanzu
 
Transformace IT s technologiemi VMware
Transformace IT s technologiemi VMwareTransformace IT s technologiemi VMware
Transformace IT s technologiemi VMware
MarketingArrowECS_CZ
 
Vmware Tanzu Kubernetes Connect(Spanish)
Vmware Tanzu Kubernetes Connect(Spanish)Vmware Tanzu Kubernetes Connect(Spanish)
Vmware Tanzu Kubernetes Connect(Spanish)
GabrielaRodriguez182401
 
vSphere7 with Tanzu
vSphere7 with Tanzu vSphere7 with Tanzu
vSphere7 with Tanzu
VMware Tanzu
 
Application Portability with Kubernetes (CMP310-S) - AWS re:Invent 2018
Application Portability with Kubernetes (CMP310-S) - AWS re:Invent 2018Application Portability with Kubernetes (CMP310-S) - AWS re:Invent 2018
Application Portability with Kubernetes (CMP310-S) - AWS re:Invent 2018
Amazon Web Services
 
ENT208 Transform your Business with VMware Cloud on AWS
ENT208 Transform your Business with VMware Cloud on AWSENT208 Transform your Business with VMware Cloud on AWS
ENT208 Transform your Business with VMware Cloud on AWS
Amazon Web Services
 
Deploying Elastic Self-Service Load Balancing
Deploying Elastic Self-Service Load BalancingDeploying Elastic Self-Service Load Balancing
Deploying Elastic Self-Service Load Balancing
Avi Networks
 
Application Modernization with PKS / Kubernetes
Application Modernization with PKS / KubernetesApplication Modernization with PKS / Kubernetes
Application Modernization with PKS / Kubernetes
Paul Czarkowski
 
VMware Application Catalog - Overview for vExperts[35].pdf
VMware Application Catalog - Overview for vExperts[35].pdfVMware Application Catalog - Overview for vExperts[35].pdf
VMware Application Catalog - Overview for vExperts[35].pdf
Martin Hosken
 
VMworld 2015: Container Orchestration with the SDDC
VMworld 2015: Container Orchestration with the SDDCVMworld 2015: Container Orchestration with the SDDC
VMworld 2015: Container Orchestration with the SDDC
VMworld
 
Achieving DevSecOps Outcomes with Tanzu Advanced- March 22, 2021
Achieving DevSecOps Outcomes with Tanzu Advanced- March 22, 2021Achieving DevSecOps Outcomes with Tanzu Advanced- March 22, 2021
Achieving DevSecOps Outcomes with Tanzu Advanced- March 22, 2021
VMware Tanzu
 
Software Defined — The Ubiquitous Digital Foundation_Robert Ames_Digital Tran...
Software Defined — The Ubiquitous Digital Foundation_Robert Ames_Digital Tran...Software Defined — The Ubiquitous Digital Foundation_Robert Ames_Digital Tran...
Software Defined — The Ubiquitous Digital Foundation_Robert Ames_Digital Tran...
scoopnewsgroup
 
Achieving DevSecOps Outcomes with Tanzu Advanced- May 25, 2021
Achieving DevSecOps Outcomes with Tanzu Advanced- May 25, 2021Achieving DevSecOps Outcomes with Tanzu Advanced- May 25, 2021
Achieving DevSecOps Outcomes with Tanzu Advanced- May 25, 2021
VMware Tanzu
 
VMware_Cloud_on_AWS_Whats_New_with_Aug_2018_Release_JW-Default.pptx
VMware_Cloud_on_AWS_Whats_New_with_Aug_2018_Release_JW-Default.pptxVMware_Cloud_on_AWS_Whats_New_with_Aug_2018_Release_JW-Default.pptx
VMware_Cloud_on_AWS_Whats_New_with_Aug_2018_Release_JW-Default.pptx
RichieBallyears
 
Pulling Back the Curtain - Robert Ames
Pulling Back the Curtain - Robert AmesPulling Back the Curtain - Robert Ames
Pulling Back the Curtain - Robert Ames
scoopnewsgroup
 
July 28: Tanzu Mission Control: Resolving Kubernetes fragmentation across Dev...
July 28: Tanzu Mission Control: Resolving Kubernetes fragmentation across Dev...July 28: Tanzu Mission Control: Resolving Kubernetes fragmentation across Dev...
July 28: Tanzu Mission Control: Resolving Kubernetes fragmentation across Dev...
VMware Tanzu
 
AWS Summit Singapore 2019 | VMware: The Fastest Path to Hybrid Cloud
AWS Summit Singapore 2019 | VMware: The Fastest Path to Hybrid CloudAWS Summit Singapore 2019 | VMware: The Fastest Path to Hybrid Cloud
AWS Summit Singapore 2019 | VMware: The Fastest Path to Hybrid Cloud
AWS Summits
 
Evolve or Fall Behind: Driving Transformation with Containers - Sai Vennam - ...
Evolve or Fall Behind: Driving Transformation with Containers - Sai Vennam - ...Evolve or Fall Behind: Driving Transformation with Containers - Sai Vennam - ...
Evolve or Fall Behind: Driving Transformation with Containers - Sai Vennam - ...
CodeOps Technologies LLP
 

Similar to Enterprise pks overview (20)

Pivotal Container Service : la nuova soluzione per gestire Kubernetes in azienda
Pivotal Container Service : la nuova soluzione per gestire Kubernetes in aziendaPivotal Container Service : la nuova soluzione per gestire Kubernetes in azienda
Pivotal Container Service : la nuova soluzione per gestire Kubernetes in azienda
 
VMware Tanzu Introduction
VMware Tanzu IntroductionVMware Tanzu Introduction
VMware Tanzu Introduction
 
VMware Tanzu Kubernetes Connect
VMware Tanzu Kubernetes ConnectVMware Tanzu Kubernetes Connect
VMware Tanzu Kubernetes Connect
 
Transformace IT s technologiemi VMware
Transformace IT s technologiemi VMwareTransformace IT s technologiemi VMware
Transformace IT s technologiemi VMware
 
Vmware Tanzu Kubernetes Connect(Spanish)
Vmware Tanzu Kubernetes Connect(Spanish)Vmware Tanzu Kubernetes Connect(Spanish)
Vmware Tanzu Kubernetes Connect(Spanish)
 
vSphere7 with Tanzu
vSphere7 with Tanzu vSphere7 with Tanzu
vSphere7 with Tanzu
 
Application Portability with Kubernetes (CMP310-S) - AWS re:Invent 2018
Application Portability with Kubernetes (CMP310-S) - AWS re:Invent 2018Application Portability with Kubernetes (CMP310-S) - AWS re:Invent 2018
Application Portability with Kubernetes (CMP310-S) - AWS re:Invent 2018
 
ENT208 Transform your Business with VMware Cloud on AWS
ENT208 Transform your Business with VMware Cloud on AWSENT208 Transform your Business with VMware Cloud on AWS
ENT208 Transform your Business with VMware Cloud on AWS
 
Deploying Elastic Self-Service Load Balancing
Deploying Elastic Self-Service Load BalancingDeploying Elastic Self-Service Load Balancing
Deploying Elastic Self-Service Load Balancing
 
Application Modernization with PKS / Kubernetes
Application Modernization with PKS / KubernetesApplication Modernization with PKS / Kubernetes
Application Modernization with PKS / Kubernetes
 
VMware Application Catalog - Overview for vExperts[35].pdf
VMware Application Catalog - Overview for vExperts[35].pdfVMware Application Catalog - Overview for vExperts[35].pdf
VMware Application Catalog - Overview for vExperts[35].pdf
 
VMworld 2015: Container Orchestration with the SDDC
VMworld 2015: Container Orchestration with the SDDCVMworld 2015: Container Orchestration with the SDDC
VMworld 2015: Container Orchestration with the SDDC
 
Achieving DevSecOps Outcomes with Tanzu Advanced- March 22, 2021
Achieving DevSecOps Outcomes with Tanzu Advanced- March 22, 2021Achieving DevSecOps Outcomes with Tanzu Advanced- March 22, 2021
Achieving DevSecOps Outcomes with Tanzu Advanced- March 22, 2021
 
Software Defined — The Ubiquitous Digital Foundation_Robert Ames_Digital Tran...
Software Defined — The Ubiquitous Digital Foundation_Robert Ames_Digital Tran...Software Defined — The Ubiquitous Digital Foundation_Robert Ames_Digital Tran...
Software Defined — The Ubiquitous Digital Foundation_Robert Ames_Digital Tran...
 
Achieving DevSecOps Outcomes with Tanzu Advanced- May 25, 2021
Achieving DevSecOps Outcomes with Tanzu Advanced- May 25, 2021Achieving DevSecOps Outcomes with Tanzu Advanced- May 25, 2021
Achieving DevSecOps Outcomes with Tanzu Advanced- May 25, 2021
 
VMware_Cloud_on_AWS_Whats_New_with_Aug_2018_Release_JW-Default.pptx
VMware_Cloud_on_AWS_Whats_New_with_Aug_2018_Release_JW-Default.pptxVMware_Cloud_on_AWS_Whats_New_with_Aug_2018_Release_JW-Default.pptx
VMware_Cloud_on_AWS_Whats_New_with_Aug_2018_Release_JW-Default.pptx
 
Pulling Back the Curtain - Robert Ames
Pulling Back the Curtain - Robert AmesPulling Back the Curtain - Robert Ames
Pulling Back the Curtain - Robert Ames
 
July 28: Tanzu Mission Control: Resolving Kubernetes fragmentation across Dev...
July 28: Tanzu Mission Control: Resolving Kubernetes fragmentation across Dev...July 28: Tanzu Mission Control: Resolving Kubernetes fragmentation across Dev...
July 28: Tanzu Mission Control: Resolving Kubernetes fragmentation across Dev...
 
AWS Summit Singapore 2019 | VMware: The Fastest Path to Hybrid Cloud
AWS Summit Singapore 2019 | VMware: The Fastest Path to Hybrid CloudAWS Summit Singapore 2019 | VMware: The Fastest Path to Hybrid Cloud
AWS Summit Singapore 2019 | VMware: The Fastest Path to Hybrid Cloud
 
Evolve or Fall Behind: Driving Transformation with Containers - Sai Vennam - ...
Evolve or Fall Behind: Driving Transformation with Containers - Sai Vennam - ...Evolve or Fall Behind: Driving Transformation with Containers - Sai Vennam - ...
Evolve or Fall Behind: Driving Transformation with Containers - Sai Vennam - ...
 

Recently uploaded

Quarkus Hidden and Forbidden Extensions
Quarkus Hidden and Forbidden ExtensionsQuarkus Hidden and Forbidden Extensions
Quarkus Hidden and Forbidden Extensions
Max Andersen
 
A Sighting of filterA in Typelevel Rite of Passage
A Sighting of filterA in Typelevel Rite of PassageA Sighting of filterA in Typelevel Rite of Passage
A Sighting of filterA in Typelevel Rite of Passage
Philip Schwarz
 
Top 7 Unique WhatsApp API Benefits | Saudi Arabia
Top 7 Unique WhatsApp API Benefits | Saudi ArabiaTop 7 Unique WhatsApp API Benefits | Saudi Arabia
Top 7 Unique WhatsApp API Benefits | Saudi Arabia
Yara Milbes
 
GlobusWorld 2024 Opening Keynote session
GlobusWorld 2024 Opening Keynote sessionGlobusWorld 2024 Opening Keynote session
GlobusWorld 2024 Opening Keynote session
Globus
 
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
Shahin Sheidaei
 
Text-Summarization-of-Breaking-News-Using-Fine-tuning-BART-Model.pptx
Text-Summarization-of-Breaking-News-Using-Fine-tuning-BART-Model.pptxText-Summarization-of-Breaking-News-Using-Fine-tuning-BART-Model.pptx
Text-Summarization-of-Breaking-News-Using-Fine-tuning-BART-Model.pptx
ShamsuddeenMuhammadA
 
Globus Connect Server Deep Dive - GlobusWorld 2024
Globus Connect Server Deep Dive - GlobusWorld 2024Globus Connect Server Deep Dive - GlobusWorld 2024
Globus Connect Server Deep Dive - GlobusWorld 2024
Globus
 
Webinar: Salesforce Document Management 2.0 - Smarter, Faster, Better
Webinar: Salesforce Document Management 2.0 - Smarter, Faster, BetterWebinar: Salesforce Document Management 2.0 - Smarter, Faster, Better
Webinar: Salesforce Document Management 2.0 - Smarter, Faster, Better
XfilesPro
 
Beyond Event Sourcing - Embracing CRUD for Wix Platform - Java.IL
Beyond Event Sourcing - Embracing CRUD for Wix Platform - Java.ILBeyond Event Sourcing - Embracing CRUD for Wix Platform - Java.IL
Beyond Event Sourcing - Embracing CRUD for Wix Platform - Java.IL
Natan Silnitsky
 
Enterprise Software Development with No Code Solutions.pptx
Enterprise Software Development with No Code Solutions.pptxEnterprise Software Development with No Code Solutions.pptx
Enterprise Software Development with No Code Solutions.pptx
QuickwayInfoSystems3
 
In 2015, I used to write extensions for Joomla, WordPress, phpBB3, etc and I ...
In 2015, I used to write extensions for Joomla, WordPress, phpBB3, etc and I ...In 2015, I used to write extensions for Joomla, WordPress, phpBB3, etc and I ...
In 2015, I used to write extensions for Joomla, WordPress, phpBB3, etc and I ...
Juraj Vysvader
 
Understanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSageUnderstanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSage
Globus
 
AI Pilot Review: The World’s First Virtual Assistant Marketing Suite
AI Pilot Review: The World’s First Virtual Assistant Marketing SuiteAI Pilot Review: The World’s First Virtual Assistant Marketing Suite
AI Pilot Review: The World’s First Virtual Assistant Marketing Suite
Google
 
Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus Compute wth IRI Workflows - GlobusWorld 2024Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus
 
How to Position Your Globus Data Portal for Success Ten Good Practices
How to Position Your Globus Data Portal for Success Ten Good PracticesHow to Position Your Globus Data Portal for Success Ten Good Practices
How to Position Your Globus Data Portal for Success Ten Good Practices
Globus
 
GraphSummit Paris - The art of the possible with Graph Technology
GraphSummit Paris - The art of the possible with Graph TechnologyGraphSummit Paris - The art of the possible with Graph Technology
GraphSummit Paris - The art of the possible with Graph Technology
Neo4j
 
Custom Healthcare Software for Managing Chronic Conditions and Remote Patient...
Custom Healthcare Software for Managing Chronic Conditions and Remote Patient...Custom Healthcare Software for Managing Chronic Conditions and Remote Patient...
Custom Healthcare Software for Managing Chronic Conditions and Remote Patient...
Mind IT Systems
 
BoxLang: Review our Visionary Licenses of 2024
BoxLang: Review our Visionary Licenses of 2024BoxLang: Review our Visionary Licenses of 2024
BoxLang: Review our Visionary Licenses of 2024
Ortus Solutions, Corp
 
First Steps with Globus Compute Multi-User Endpoints
First Steps with Globus Compute Multi-User EndpointsFirst Steps with Globus Compute Multi-User Endpoints
First Steps with Globus Compute Multi-User Endpoints
Globus
 
Pro Unity Game Development with C-sharp Book
Pro Unity Game Development with C-sharp BookPro Unity Game Development with C-sharp Book
Pro Unity Game Development with C-sharp Book
abdulrafaychaudhry
 

Recently uploaded (20)

Quarkus Hidden and Forbidden Extensions
Quarkus Hidden and Forbidden ExtensionsQuarkus Hidden and Forbidden Extensions
Quarkus Hidden and Forbidden Extensions
 
A Sighting of filterA in Typelevel Rite of Passage
A Sighting of filterA in Typelevel Rite of PassageA Sighting of filterA in Typelevel Rite of Passage
A Sighting of filterA in Typelevel Rite of Passage
 
Top 7 Unique WhatsApp API Benefits | Saudi Arabia
Top 7 Unique WhatsApp API Benefits | Saudi ArabiaTop 7 Unique WhatsApp API Benefits | Saudi Arabia
Top 7 Unique WhatsApp API Benefits | Saudi Arabia
 
GlobusWorld 2024 Opening Keynote session
GlobusWorld 2024 Opening Keynote sessionGlobusWorld 2024 Opening Keynote session
GlobusWorld 2024 Opening Keynote session
 
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
Gamify Your Mind; The Secret Sauce to Delivering Success, Continuously Improv...
 
Text-Summarization-of-Breaking-News-Using-Fine-tuning-BART-Model.pptx
Text-Summarization-of-Breaking-News-Using-Fine-tuning-BART-Model.pptxText-Summarization-of-Breaking-News-Using-Fine-tuning-BART-Model.pptx
Text-Summarization-of-Breaking-News-Using-Fine-tuning-BART-Model.pptx
 
Globus Connect Server Deep Dive - GlobusWorld 2024
Globus Connect Server Deep Dive - GlobusWorld 2024Globus Connect Server Deep Dive - GlobusWorld 2024
Globus Connect Server Deep Dive - GlobusWorld 2024
 
Webinar: Salesforce Document Management 2.0 - Smarter, Faster, Better
Webinar: Salesforce Document Management 2.0 - Smarter, Faster, BetterWebinar: Salesforce Document Management 2.0 - Smarter, Faster, Better
Webinar: Salesforce Document Management 2.0 - Smarter, Faster, Better
 
Beyond Event Sourcing - Embracing CRUD for Wix Platform - Java.IL
Beyond Event Sourcing - Embracing CRUD for Wix Platform - Java.ILBeyond Event Sourcing - Embracing CRUD for Wix Platform - Java.IL
Beyond Event Sourcing - Embracing CRUD for Wix Platform - Java.IL
 
Enterprise Software Development with No Code Solutions.pptx
Enterprise Software Development with No Code Solutions.pptxEnterprise Software Development with No Code Solutions.pptx
Enterprise Software Development with No Code Solutions.pptx
 
In 2015, I used to write extensions for Joomla, WordPress, phpBB3, etc and I ...
In 2015, I used to write extensions for Joomla, WordPress, phpBB3, etc and I ...In 2015, I used to write extensions for Joomla, WordPress, phpBB3, etc and I ...
In 2015, I used to write extensions for Joomla, WordPress, phpBB3, etc and I ...
 
Understanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSageUnderstanding Globus Data Transfers with NetSage
Understanding Globus Data Transfers with NetSage
 
AI Pilot Review: The World’s First Virtual Assistant Marketing Suite
AI Pilot Review: The World’s First Virtual Assistant Marketing SuiteAI Pilot Review: The World’s First Virtual Assistant Marketing Suite
AI Pilot Review: The World’s First Virtual Assistant Marketing Suite
 
Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus Compute wth IRI Workflows - GlobusWorld 2024Globus Compute wth IRI Workflows - GlobusWorld 2024
Globus Compute wth IRI Workflows - GlobusWorld 2024
 
How to Position Your Globus Data Portal for Success Ten Good Practices
How to Position Your Globus Data Portal for Success Ten Good PracticesHow to Position Your Globus Data Portal for Success Ten Good Practices
How to Position Your Globus Data Portal for Success Ten Good Practices
 
GraphSummit Paris - The art of the possible with Graph Technology
GraphSummit Paris - The art of the possible with Graph TechnologyGraphSummit Paris - The art of the possible with Graph Technology
GraphSummit Paris - The art of the possible with Graph Technology
 
Custom Healthcare Software for Managing Chronic Conditions and Remote Patient...
Custom Healthcare Software for Managing Chronic Conditions and Remote Patient...Custom Healthcare Software for Managing Chronic Conditions and Remote Patient...
Custom Healthcare Software for Managing Chronic Conditions and Remote Patient...
 
BoxLang: Review our Visionary Licenses of 2024
BoxLang: Review our Visionary Licenses of 2024BoxLang: Review our Visionary Licenses of 2024
BoxLang: Review our Visionary Licenses of 2024
 
First Steps with Globus Compute Multi-User Endpoints
First Steps with Globus Compute Multi-User EndpointsFirst Steps with Globus Compute Multi-User Endpoints
First Steps with Globus Compute Multi-User Endpoints
 
Pro Unity Game Development with C-sharp Book
Pro Unity Game Development with C-sharp BookPro Unity Game Development with C-sharp Book
Pro Unity Game Development with C-sharp Book
 

Enterprise pks overview

  • 1. ©2019 VMware, Inc. Run and Operationalize Kubernetes in Production VMware Enterprise PKS Overview February 2019
  • 2. Confidential │ ©2019 VMware, Inc. 22 Enterprises are Embracing Cloud Native Methodology Container technology is being adopted across all industries Increase Developer Productivity Deliver Better Customer Experiences Accelerate Time-to-Market Gain Operational Efficiency
  • 3. Confidential │ ©2019 VMware, Inc. 33Confidential │ ©2018 VMware, Inc. Kubernetes has Become the De Facto Container Orchestrator Source: Cloud native Computing Foundation User Survey 2018 0% 10% 20% 30% 40% 50% 60% 70% 80% 90% Kubernetes Docker Mesos
  • 4. Confidential │ ©2019 VMware, Inc. 44Confidential │ ©2018 VMware, Inc. Challenges of Running Kubernetes in Production Source: Cloud native Computing Foundation User Survey 2018 0% 5% 10% 15% 20% 25% 30% 35% 40% 45% VMware Enterprise PKS Addresses These Challenges
  • 6. ©2019 VMware, Inc. VMware Enterprise PKS • Deploy clusters on demand • Simplified Patching, Upgrading, Scaling • Integration with platform pipeline Easy to Use and Maintain • NSX-T Micro- segmentation • Rotate, Repair, Repave • Image CVE scanning, Content Trust Highly Secure by Default • Wavefront • vRealize Log Insight • Network Insight • vRealize Automation • Prometheus, Jaeger, Grafana, Istio • Cluster as a unit of tenancy • Namespace as a unit of tenancy • LDAP/AD Integration Flexible Multi-Tenancy • Health Monitoring and Self-healing • Kubernetes manages app layer availability • BOSH manages infra/cluster layer availability Highly Available “Dial Tone” Kubernetes Highly Integrated Ecosystem VMware Enterprise PKS is a turnkey solution for organizations that want to deploy and operate an integrated, validated upstream Kubernetes footprint
  • 7. ©2019 VMware, Inc. 7 Kubernetes is Only One Layer of the Container Service Stack Image Registry Framework Lifecycle Management Security and Networking Persistence Virtual Infrastructure Physical Infrastructure Monitoring,Logging,Analytics Cluster Health Monitoring, Healing and Lifecycle Management Scheduling, Orchestration, Service Creation vSAN, Hatchway vSphere Physical Infrastructure NSX-T Enterprise PKS Control Plane BOSH (cluster LCM) Kubernetes Harbor vRealizeSuite
  • 8. ©2019 VMware, Inc. 8 BOSH NSX-T Service Brokers etcd worker etcd workermaster PKS Control Plane Kubernetes Cluster VMware Enterprise PKS Security Container Registry master Kubernetes Cluster vRealize Automation vRealize Log Insight vRealize Operations vRealize Network Insight Wavefront by VMware VMware Enterprise PKS: Marketecture vSphere vSAN Public Clouds Public Cloud Storage
  • 9. Confidential │ ©2019 VMware, Inc. Who is VMware Enterprise PKS Built For? IT Operator – PRE (Platform Reliability Engineering) – Deploy, Scale, Operate VMware PKS – Physical Infrastructure is Operated – Network & Security Control Policy is defined • Developers – Writes code, code deployed using CI/CD – Focus on business problems and innovation • Application Dev/Ops owner – Automate Everything – Agile – Serve developers • Platform Reliability Engineers – Platform is Reliable – Capacity Is planned for – Platform is Secured & Controlled – Platform is Auditable Application Dev/Ops Owner Platform Reliability Engineer Developers – Develop, Deploy, Scale, Monitor Apps – Innovation of Business Capability as Cloud native Apps – Create K8s cluster, scale clusters and maintain the health customers – Provide developer access to the cluster
  • 10. Confidential │ ©2019 VMware, Inc. 1010Confidential │ ©2018 VMware, Inc. A turnkey solution to provision, operate and manage enterprise grade Kubernetes clusters VMware Enterprise PKS Latest stable native Kubernetes, CNCF certified Production-grade Kubernetes based container platform Deep integration with NSX-T for networking and security Globally supported on vSphere, GCP, AWS, and Azure Secure, enterprise-grade container registry Consistent infrastructure for traditional and modern applications
  • 11. 11©2019 VMware, Inc. Addressing the Common Kubernetes Challenges Complexity Scaling Deployment Networking Storage Monitoring & Logging Security
  • 12. Confidential │ ©2019 VMware, Inc. 1212Confidential │ ©2018 VMware, Inc. • Constant monitoring and self-healing of VMs • Easy scaling and patching for clusters • Rolling upgrades to latest Kubernetes release • High availability and multi-AZ support VMware Enterprise PKS Simplifies “Day 1” and “Day 2” of Kubernetes Clusters • Deploy Kubernetes cluster on demand • Simple API and CLI interface Day 2 “Operate” Day 1 “Build”
  • 13. Confidential │ ©2019 VMware, Inc. 1313Confidential │ ©2018 VMware, Inc. IaaS Node Node Kubernetes Cluster Services API Cluster3 NSX-T vSphere VMware PKS includes: • VMWare PKS Control Plane, CFCR • NSX-T, Harbor, Service Broker • BOSH Release for Kubernetes • Configures Day 1 of - CFCR - vSphere/Public Clouds - NSX Integration - Harbor • Manages Day 2 of Kubernetes Clusters - Scaling - Patching - Upgrades - Failures CFCR Kubernetes (As a BOSH Release) BOSH (Deploys/Manages VMs & state) CPI CNI Harbor Private Container Registry The value of BOSH VMware Enterprise PKS - “How it Works” Node Node Node Kubernetes Cluster Services API Node Node Node Kubernetes Cluster Services API Node Cluster1 Cluster2 Service Broker (s) API #pks create-cluster K8s-1 -n 3#pks create-cluster K8s-2 -n 3#pks create-cluster K8s-3 -n 3#pks resize K8s-3 –n 5 VMware PKS Control Plane VM VM VM VM VM VM VM VM VM Node Node Kubernetes Cluster Services API Cluster3 Node Node Node VM VM VM VM VM
  • 14. 14©2019 VMware, Inc. Addressing the Common Kubernetes Challenges Complexity Scaling Deployment Networking Storage Monitoring & Logging Security
  • 15. Confidential │ ©2019 VMware, Inc. 1515Confidential │ ©2018 VMware, Inc. Best-in-Class Kubernetes Networking with NSX-T NSX-T is included in VMware Enterprise PKS to enable • Networking virtualization and automation for Kubernetes • Complete set of Layer 2 through Layer 7 networking services • Pod-level networking and micro-segmentation • Rich set of management and troubleshooting tools • Layer 4 load balancer (not just layer 7 load balancer) for supporting a wider range of applications • Security policy that can apply to both your containers and VMs workloads
  • 16. Confidential │ ©2019 VMware, Inc. 1616Confidential │ ©2018 VMware, Inc. Canal Comparing NSX-T to Open Source Networking Options L2 L3 (North/South) L4 – Security Policy Load Balancing VM & K8s Connectivity End-to-End Configuration & troubleshooting Ops tools & central stats Flannel L2 only (East/West Pod Traffic) Calico L3/L4 (IP Tables) NGINX/HA Proxy Load balancing No End-to-End configuration & troubleshooting New ops tools + Different locations for stats NSX-T Only for Kubernetes Networking
  • 17. Confidential │ ©2019 VMware, Inc. 1717 Container Networking & Security Operations NSX-T Operational Tools • Traceflow • Port Mirroring • Port Connection Tool • Spoofguard • Syslog • Port Counters • IPFIX 17 NSX-T Traceflow With NSX-T you are gain deep visibility into the container networks, and you can use the same troubleshooting tools we created for VM based workloads
  • 18. 18©2019 VMware, Inc. Addressing the Common Kubernetes Challenges Complexity Scaling Deployment Networking Storage Monitoring & Logging Security
  • 19. Confidential │ ©2019 VMware, Inc. 19 Persistent Storage with Kubernetes • You need a storage platform with the right Cloud Provider (Storage Plugin) for Kubernetes • You must configure the Kubernetes Cluster and all the nodes – Configuration Management everywhere • Available features & functionality dictated by storage platform keeping up with Kubernetes releases • Maintaining the “Platform” over time – Update all your configuration management – End-to-end Testing (Compatibility of System) – High risk of snowflakes Must have available Kubernetes Cloud Provider Node Node Node Kubernetes Cluster Services API V V V CP CP CP CP Storage Platform VM VM VM
  • 20. Confidential │ ©2019 VMware, Inc. 20 VMware Enterprise PKS Provides Persistent Storage for Running Stateful Apps on Kubernetes • Entire HCL of storage products under vSphere Supported with Kubernetes • Operational Consistency - Existing Storage Operations, Tooling, and SPBM • Self Service Storage provisioning through Storage Class Mapping to SPBM Policies • VMware Enterprise PKS delivers the consistent, repeatable configuration & maintenance of Hatchway Kubernetes Consumption • Storage Class = Regular • Storage Class = Fast • Storage Class = Encrypted • Storage Class = Dedup • Storage Class = … K8s API SPBM • Thin • SSD • Encrypted • Dedup • … vSphere Any Supported Storage on HCL vSAN|VMFS|NFS Datastore Project Hatchway https://github.com/vmware/hatchway
  • 21. 21©2019 VMware, Inc. Addressing the Common Kubernetes Challenges Complexity Scaling Deployment Networking Storage Monitoring & Logging Security
  • 22. Confidential │ ©2019 VMware, Inc. 2222Confidential │ ©2018 VMware, Inc. Automated deployment & configuration from infrastructure to applications Monitoring & Logging at Scale with VMware Integration Infra K8s Containers Apps Application Dev/Ops Owner Platform Reliability Engineer vRLI vRops Wavefront
  • 23. Confidential │ ©2019 VMware, Inc. Wavefront & VMware Enterperise PKS Integration K8s Monitoring Integration w/ Wavefront by VMware • Pre-Integrated with VMware PKS • Predefined K8s Alerts • Comprehensive Dashboards • Self-Service Metrics Analytics for both Developers and Operators Platform Reliability Engineer Application Dev/Ops Owner Troubleshoot Issues at Cloud Speed Trend & Alert on Anomalies Visualize Cloud Apps at Hyperscale
  • 24. Confidential │ ©2019 VMware, Inc. 2424Confidential │ ©2018 VMware, Inc. Wavefront + VMware Enterprise PKS Dashboard
  • 25. Confidential │ ©2019 VMware, Inc. vRealize Log Insight and VMware Enterprise PKS Integration K8s Logging Integration w/ vRealize Log Insight • Configured via VMware PKS Tile • Aggregates, Tags, & Ships all logs to vRLI • Searchable tags: Cluster, Pod, Namespace, Container • SSL Encryption of Data in Transit • Log Ingestion Rate Limiting vRLI Master / Worker Nodes Logs K8s Cluster Events POD StdOut & StdErr vRLI Interactive Analytics
  • 26. 26©2019 VMware, Inc. Addressing the Common Kubernetes Challenges Complexity Scaling Deployment Networking Storage Monitoring & Logging Security
  • 27. Confidential │ ©2019 VMware, Inc. VMware Enterprise PKS Provides Container Security at all levels from infrastructure to Application Infrastructure StorageCompute Networking Container Mgmt. NameSpace vSphere Google Cloud Platform Hybrid NameSpace NameSpace NameSpace Container Mgmt. NameSpace NameSpace NameSpace Operator admin IAM • Role Based Access Control (RBAC) • Identity Management • Credential Stores Events & Monitoring • Incident Reporting • Event Management • Full Stack Monitoring Build Pipelines NameSpace Platform LCM Kubernetes Cluster Kubernetes Cluster Apps Apps Micro- service Micro- service Micro- service Micro- service Micro- service Micro- service Micro- service Micro- service Platform LCM • Repair • Repave • Rotate Container Management • Vulnerability Scanning • Content Trust • Centralized Policy Control Infrastructure • Cluster Segmentation • Flow Tracing • NameSpace Segmentation LDAP/AD Integration IAM VNFM WaveFront vRealize Operations Monitoring VNFM WaveFront App Monitoring
  • 28. Confidential │ ©2019 VMware, Inc. • user management & access control • role-based access control • AD/LDAP integration • Security vulnerability scanning (Clair) • content trust - image signing • policy based image replication • audit and logs • Restful API • open-source under Apache 2 license Harbor – Enterprise Grade Private Registry Project Harbor was accepted into CNCF as its first container registry open source project
  • 29. Confidential │ ©2019 VMware, Inc. 2929Confidential │ ©2018 VMware, Inc. Why VMware Enterprise PKS? Entire Lifecycle of the Kubernetes Clusters Latest Stable Open Source Kubernetes Multiple Clusters On-Demand Best-in-Class Kubernetes Networking End-to-End K8s Infrastructure Provisioning Enterprise Private Container Registry Persistent Storage Integrates With VMware SDDC & Multi-Cloud
  • 30. ©2019 VMware, Inc. Thank You Please email any questions to PowerPoint@vmware.com