Identity-based Cross-cluster Fabrics
Igor Tarasenko, Co-founder & CTO, Bayware
Identity-based Cross-cluster Fabrics Igor Tarasenko, Co-founder - - PowerPoint PPT Presentation
Identity-based Cross-cluster Fabrics Igor Tarasenko, Co-founder & CTO, Bayware 2 Computation vs Networking Common platform Infra as code Agility Service portability Cross-domain Linux Virtualization DevOps/CICD Containers Any cloud
Igor Tarasenko, Co-founder & CTO, Bayware
2
Identity-based cross-cluster fabrics | Igor Tarasenko, Co-funder & CTO | April 2019 | www.bayware.io
Common platform Infra as code Agility Service portability Cross-domain Linux Virtualization DevOps/CICD Containers Any cloud 1990s 2000s 2005-10 2010s 2018→ SDN VNFs/Vendor-specific APIs 2010s 2015→
C O M P U T A T I O N N E T W O R K I N G
Service Mesh
Provide applications instant and transparent cross-domain networking while eliminating low-level and repetitive configuration of legacy objects
3
Identity-based cross-cluster fabrics | Igor Tarasenko, Co-funder & CTO | April 2019 | www.bayware.io
Application-level networking on L4-7
4
Identity-based cross-cluster fabrics | Igor Tarasenko, Co-funder & CTO | April 2019 | www.bayware.io
So what becomes of L2-3?
5
Identity-based cross-cluster fabrics | Igor Tarasenko, Co-funder & CTO | April 2019 | www.bayware.io
L2-3 network could be flat – no services beyond simple forwarding…
becoming a jumble of CNF/VNFs
from the application manifest
with respect to flow-level security
away in a flat world If Then
6
Identity-based cross-cluster fabrics | Igor Tarasenko, Co-funder & CTO | April 2019 | www.bayware.io
is authenticated and authorized
flows can exist in the network
compliance
application, i.e. proxies
to pass proxies
without proxy next to each microservice CISO requirements Leading Application requirements
7
Identity-based cross-cluster fabrics | Igor Tarasenko, Co-funder & CTO | April 2019 | www.bayware.io
What if L2-3 had attributes of service mesh?
8
Identity-based cross-cluster fabrics | Igor Tarasenko, Co-funder & CTO | April 2019 | www.bayware.io
network policy in the form of declarative service graph
interconnected Linux-based policy execution nodes
nodes to instantiate flow according to the service graph
9
Identity-based cross-cluster fabrics | Igor Tarasenko, Co-funder & CTO | April 2019 | www.bayware.io
Complete network and security setup derived directly from existing deployment manifest, e.g. application service graph
10
Identity-based cross-cluster fabrics | Igor Tarasenko, Co-funder & CTO | April 2019 | www.bayware.io
Flow Instantiation
11
Identity-based cross-cluster fabrics | Igor Tarasenko, Co-funder & CTO | April 2019 | www.bayware.io
Identity-based cross-cluster fabrics | Igor Tarasenko, Co-funder & CTO | April 2019 | www.bayware.io *Patent and patent pending