Top Banner
Delivering Policy & Trust to the Hybrid Cloud June 10, 2015 Derek Collison Founder and CEO, Apcera
59
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Delivering Policy & Trust to the Hybrid Cloud

Delivering Policy & Trust to the Hybrid Cloud

June 10, 2015

Derek Collison Founder and CEO, Apcera

Page 2: Delivering Policy & Trust to the Hybrid Cloud

What is Policy?

Page 3: Delivering Policy & Trust to the Hybrid Cloud

A JOKE Really In today’s increasingly complex world

Page 4: Delivering Policy & Trust to the Hybrid Cloud

A Tale of “4” Worlds

• Non-Existant

• Manual and Disconnected

• Semi-Automated, with Loose or No Enforcement

• Security Focused Only - The world on NO!

Page 5: Delivering Policy & Trust to the Hybrid Cloud

What should it look like?

Page 6: Delivering Policy & Trust to the Hybrid Cloud

What it should look like• Systemic - Complete - Pervasive

• Enforceable

• Changeable - Adaptable - Pluggable

• Understandable - Approachable

• Auditable

Page 7: Delivering Policy & Trust to the Hybrid Cloud

Why do we need it?

Page 8: Delivering Policy & Trust to the Hybrid Cloud

Risk

Governance Compliance

Page 9: Delivering Policy & Trust to the Hybrid Cloud

Risk

Governance Compliance?

Page 10: Delivering Policy & Trust to the Hybrid Cloud

We need TRUST!

Page 11: Delivering Policy & Trust to the Hybrid Cloud

Do you Trust?

• Your systems?

• Your processes?

• Your people?

Page 12: Delivering Policy & Trust to the Hybrid Cloud
Page 13: Delivering Policy & Trust to the Hybrid Cloud

They trusted me!

Page 14: Delivering Policy & Trust to the Hybrid Cloud

They trusted me! WHY??

Page 15: Delivering Policy & Trust to the Hybrid Cloud

- Do you Trust?

• Your systems? YES!

• Your processes? YES!

• Your people? Uh.. NO.. (But we don’t care)

Page 16: Delivering Policy & Trust to the Hybrid Cloud

Why Now?

Page 17: Delivering Policy & Trust to the Hybrid Cloud

Three Things

Page 18: Delivering Policy & Trust to the Hybrid Cloud

Three Things Three major things!

Page 19: Delivering Policy & Trust to the Hybrid Cloud

MicroServices

DevOps Hybrid Cloud

Page 20: Delivering Policy & Trust to the Hybrid Cloud

Increasing COMPLEXITY!

Page 21: Delivering Policy & Trust to the Hybrid Cloud

Complexity

Page 22: Delivering Policy & Trust to the Hybrid Cloud

Dawn of MicroServices

Page 23: Delivering Policy & Trust to the Hybrid Cloud

Complexity - Dawn of MicroServices

• Want to build faster? Build LESS!

• Services will WIN the Hybrid CLOUD!

• Systems will NEVER be simpler than TODAY!

Page 24: Delivering Policy & Trust to the Hybrid Cloud

Things Will Never Be Simpler Than Today

+

Data: Always growing and changing (44X in 2020 from 2014 level)

API’s: We are living in the “API Economy” — constantly growing, constantly evolving

Services: Always growing and adding new capabilities

+

24

Page 25: Delivering Policy & Trust to the Hybrid Cloud

Policy in the Hybrid Cloud

Page 26: Delivering Policy & Trust to the Hybrid Cloud

Hybrid Cloud

Private Cloud

Public Cloud

Year of Hybrid

Page 27: Delivering Policy & Trust to the Hybrid Cloud

Delivering Policy and Trust for the Hybrid Cloud

27

Connecting all clouds, with a single,

policy-driven system

Page 28: Delivering Policy & Trust to the Hybrid Cloud

Let’s go under the Hood

Page 29: Delivering Policy & Trust to the Hybrid Cloud

This could be complex

• RBAC vs ABAC vs ACL/DAC

• XACML vs Datalog

• PCI, SOX, HIPPA, ISO 27001, FISMA

Page 30: Delivering Policy & Trust to the Hybrid Cloud

KISS Principle

Page 31: Delivering Policy & Trust to the Hybrid Cloud

Keep it Simple

Page 32: Delivering Policy & Trust to the Hybrid Cloud

I like Simple

Page 33: Delivering Policy & Trust to the Hybrid Cloud

Let’s start

• What are we describing?

• What do we want to control?

Page 34: Delivering Policy & Trust to the Hybrid Cloud

System Datamodel

Page 35: Delivering Policy & Trust to the Hybrid Cloud

Simplified System Datamodel

• Packages (bag of bits)

• Jobs -> Instances

• Links -> Channels

Page 36: Delivering Policy & Trust to the Hybrid Cloud

Basic Policy Realms

Page 37: Delivering Policy & Trust to the Hybrid Cloud

Simplified System Datamodel

• Packages (bag of bits) • What’s allowed? How do we find vulnerabilities?

• Jobs -> Instances • CPU, Memory, Disk, Network?, Placement

• Links -> Channels • Access, QoS, SLAs

Page 38: Delivering Policy & Trust to the Hybrid Cloud

What Else?

Page 39: Delivering Policy & Trust to the Hybrid Cloud

Also Needed• Additional Realms

• Identity, Authorization, Audit, etc • Policy itself - the system turing test

• Simple Policy Language

• Namespaces

Page 40: Delivering Policy & Trust to the Hybrid Cloud

Example

Page 41: Delivering Policy & Trust to the Hybrid Cloud
Page 42: Delivering Policy & Trust to the Hybrid Cloud
Page 43: Delivering Policy & Trust to the Hybrid Cloud
Page 44: Delivering Policy & Trust to the Hybrid Cloud

Architecture

Page 45: Delivering Policy & Trust to the Hybrid Cloud

Bi-Directional Graph

Secure Message Bus

Distributed Policy Evaluation & Enforcement

Page 46: Delivering Policy & Trust to the Hybrid Cloud

What really Matters?

Page 47: Delivering Policy & Trust to the Hybrid Cloud

Service Access Change Mgmt

Page 48: Delivering Policy & Trust to the Hybrid Cloud

Service Access Example

Page 49: Delivering Policy & Trust to the Hybrid Cloud

APCERA CONFIDENTIAL

49

Service Access in a Hybrid World

Private Cloud

RDS

Page 50: Delivering Policy & Trust to the Hybrid Cloud

APCERA CONFIDENTIAL

50

Service Access in a Hybrid World

Private Cloud

HTTP

RDS

Page 51: Delivering Policy & Trust to the Hybrid Cloud
Page 52: Delivering Policy & Trust to the Hybrid Cloud

APCERA CONFIDENTIAL

52

Service Access in a Hybrid World

Private Cloud

HTTP

RDS

Page 53: Delivering Policy & Trust to the Hybrid Cloud

APCERA CONFIDENTIAL

53

Service Access in a Hybrid World

Private Cloud

HTTP

RDS

Page 54: Delivering Policy & Trust to the Hybrid Cloud

State of the Policy World

Page 55: Delivering Policy & Trust to the Hybrid Cloud

The Policy World Today• People and Paper based

• BMC, CA, IBM • Legacy

• OpenStack Congress • OpenStack centric in a Hybrid World

Page 56: Delivering Policy & Trust to the Hybrid Cloud

Summary

Page 57: Delivering Policy & Trust to the Hybrid Cloud

A single, policy-driven, system — a connective fabric — that sits above all clouds, private and public

Purpose built for the Hybrid Cloud

Reduces complexity and invites change, all while enabling enterprise-wide governance and maximum

agility

“System of Trust”

The Right Approach to Policy

Page 58: Delivering Policy & Trust to the Hybrid Cloud

Thank You!

Page 59: Delivering Policy & Trust to the Hybrid Cloud

Questions?