ITOM Visibility & Cloud Accelerate Academy – Enhance your Kubernetes visibility with CNO-V 2.0
Al righty so good morning good afternoon and good evening everyone and welcome to this amazing session of our visibility and Cloud accelerated Academy today we're going to talk about a very hot topic as I possibly was already mentioning in a social media posts is a very hot topic for this year and a lot of VI have been uh demonstrating interest around the topic we're talking about kubernetes visibility and specifically Cloud native operations for visibility in its latest version today's session is uh part of the live on service now webinar series which is a very successful series that has been going on for now many many months and years and it's really helping to speed deployment uh the adoption and really helping you achieve value faster with our Solutions and uh we' have seen many different episodes so please make sure that you don't lose the recordings of of our previous episodes of the visibility and Cloud acceler Academy and if you want to see the full schedule and make sure that you're in the loop not to miss any of the future events please make sure to scan this QR code or to leverage the link that it's now being shared in the chat now a a few housekeeping items for today for those of you that have been attending the sessions you already know that the Q&A uh feature is the one that we are mainly using in order to interact with the product management team and please make sure that your line is muted and uh for this session it will be recorded and it will be shared on the service now Community Forum after the session whenever you're asking questions also make sure that you introduce yourself will love to really hear who you are and after this session and you'll be prompted out to fill out a short survey so please make sure you Prov provide us with feedback as it's very important for us now I would like to make sure that you also understand there will be two polls today so these polls are very useful for us but especially are useful uh to make these sessions a little bit more interactive of course we'll be looking after your questions in the Q&A box and we have experts today to answer your questions both live and Via chat so please make sure you're as interactive as you usually are and if you're new to this series I'm sure you'll do a great job in that sense too now for those of you that don't know me my name is John Mario deluigi and I'm part of the outbound product management team for item and I'm specifically covering item visibility and Cloud accelerate and to today with me we have great Superstars I would say uh we have sh in t which have an outstanding experience in the item uh side of things and specifically with service now we have I purposely Rec called atal is the item Chief Architect officer because he is basically the uh main uh and the most distinguished engineer that we have in the iton space and Sh is definitely the most famous I would say in the product management side of the house so please Shri and T introduce yourself yeah good morning team uh suban I lead the inbound product team for Discovery visibility business uh so happy to collaborate hi hello I'm tal indeed I'm enger engineer with itom and really focused on kubernetes containers Cloud native fantastic thank you Shri and tal I'm sure that everyone will appreciate your expertise today now safe Arbor notice this applies because we could potentially make forward looking statements today um and so please be aware of those and then let's get into the content now I would like to start with a little bit of the why we're talking about Cloud uh visibility and Cloud native visibility specifically as a matter of fact when talking to our customers we always realize that there are common Trends in terms of challenges that they're trying to address either they're trying to make sure that their Cloud native state is more secure so they're they're trying to assess their kubernetes um security posture and they want to make sure that all the software pieces or the software components I would say and software installations inside those environments are safe and are compliant with their policies and then we have let's say Asset Management teams that want uh to make sure that the software is compliant in terms of Licensing so they need to have all the granular information about their software installations inside containers to so that they can assess the uh policy compliance against their internal rules and then are there other opportunities in terms of minimizing the spend over those licenses if they're not needed or uh in in case of optimizing the cost overall in terms of number of Licensing all these aspects need to be discovered and then we have the it op a teams that need to make sure that all the services that are offered need to be very healthy and uh they uh want to really predict any issues before they even happen and how can they automate the remediation of those issues before they actually impact the business so it's all about tying up all the potential issues inside those environments to the business now these three common uh Trends are really uh I would say common um across different companies different different Enterprises in all different sectors and the outcomes of the cloud native visibility are practically how uh with service now uh we help them to um overcome those challenges and really achieve value we're talking about again security from the security perspective uh having a centralized cmdb with the latest and greatest information about the containerized environment helps these companies to uh prioritize their response to whatever uh potential alerts or potential incidents that they have based on the business impact so uh the business aware cmdb is very useful for them in these situations then we have the software Asset Management use case whenever a uh compliant and and enriched cmtb uh make sure that the software Asset Management teams have full information about the software that is installed so they can guarantee compliance and optimize spend and then we have the uh it operations teams that also uh will leverage a properly populated cmtb with all the data about their Cloud native Technologies in order to really have full visibility of the software that is installed inside those environments so we can uh eventually have two different uh perspectives to this we're uh either uh taking the service context in order to ensure that the all the services that are offered internally are compliant and are guaranteeing the uh level of uh operational efficiency that is uh potentially uh guaranteed or needs to be achieved and then we have the visibility aspect where we have full transparency across different uh kubernetes platforms and kubernetes environments now um talking about again just kubernetes visibility service now allows you to populate your cmdb from all these different kubernetes and Cloud native uh platforms it allows you uh to populate either for self-hosted of managed kubernetes environment uh and basically to have a huge uh amount of information so increase your visibility on these environments by having more information about the kubernetes topology what tags are being deployed for those resources or what is the software that has been installed as we were just saying before and again the service context is always at the center of these outcomes and we have always the uh near realtime visibility across these different platforms so again we are analyzing different environments but all merg into one single cmtv that's the uh common Trend I would say uh around our Solutions and then the outcomes are already uh the ones that we basically mentioned earlier on we're talking about an improved uh security posture for these kubernetes environments and an improved uh spend or I would say reduced spend for the software that is installed inside those environments and we have more compliance especially when we have regulatory um standards such as PCI Pi Etc and overall the service context uh is definitely always kept in mind especially for aops uh and uh event management use cases at the end of the day now we said that we're going to have some polls in today's session and this is the first one that I'm going to launch right now so we want to know from you uh which are the methods that are you're currently using to discover your kubernetes and Cloud native environments and you can select between the third party tools that you might be using or schedule disc Discovery runs using Discovery patterns or manage kubernetes Discovery via eks AKs in gke are you using the cloud native operations maybe the first version of CNO or uh are you even doubting about discovering kubernetes and containers I see many interesting answers here so thank you very much for being this involved I see a great audience today and a lot of answers coming in um we're going to give another few second so please uh submit your input here and we will share the data right now today we have a very rich session where sh is going to lead us through the content and then we're going to have t uh leading the demo session so uh we'll make sure to cover as much as we can for sure okay so I'm going to end the poll now and share the results with you uh we can see that the vast majority I would say 52% uh was selecting schedule Discovery runs using patterns followed by by uh those of you that are still evaluating why to discover kubernetes and containers we partially try to address uh some of those uh reasons in the previous slides but of course we'll get deeper into that and then uh third party tools are also quite popular followed by manage kuet Discovery and uh CN interestingly enough so please inut in the Q&A box if you're using the new version or the old version that's very useful and very uh interesting to know and now just the second poll before sh is going to present so I'm going to launch this one as well we want to really understand what are the use cases that you will be using the discovered kubernetes and containers for are you going to enable vulnerability management use cases or rather software Asset Management once as we saw before to evaluate your licenses or the aops use cases to really understand more about the business impact or otherwise are you evaluating devops change use cases or even regulatory in compliances cases we know that especially around Cloud native uh Technologies there have been more strict Regulatory and uh compliance aspects to them so uh that's also another interesting point I see a lot of you that participating there so thanks very much for this great engagements another 5 seconds and I'm going to close this poll so I'll close it in five4 three and two one okay we can share the results and we can see that software asset management is the most popular use case they will leverage the uh discovery of the kubernetes 4 and then we have vulnerability management just coming after that 51% of you selecting that use case then we have very similar percentages for both devops change and Regulatory Compliance use cases and then aops as well so if you have any other options please make sure to use the Q&A Button as well so I think sh I'm going to stop sharing my screen and you can go ahead with the reason why you should discover uh let's say why you should Leverage The Cloud n visibility thank you again appreciate it uh so let's start with why right so this is again one of the primary narrative uh that we wanted to make sure that everyone is uh know uh taking uh notes on when we think about a data platform right we have multiple consumers at the end we are collecting data to drive these outcomes so some of the examples that Gan talked about hey there are multiple consumers of this data right so here kubernetes is an estate where you have all the modern applications being deployed and when you think about these Farms right there are multiple uh consumers uh who want to consume this data primarily from the angle of either sres or your vulnerability management or your asset managers worrying about license calculations that's need to happen know in the kubernetes environment or other Regulatory Compliance in fact U just this week uh know I was contacted by one of the largest bank right where the Auditors uh really challenge the bank saying hey do you have the complete visibility of all the microservices who's the uh service owner and they want to validate whether these microservices are not accessing any uh no critical customer data which is sitting in PCI networks and so on so you're going to see multiple challenges that demands near realtime visibility into the kubernetes estate uh and this is one place like where know you're going to see know some fantastic use cases uh know like saying hey okay once I have complete visibility to all my estate uh no firstly I need a single pen of glass right one of the largest Telco companies uh no they just have 330 kubernetes clusters and imagine the massive amount of uh uh no infrastructure that's powering up all those kubernetes estate uh the change management uh that has to happen uh the capacity planning that has to happen uh clearly identifying how am I going to load balance all my applications to different know of these clusters so you need a single pain of class so that's where the data platform comes in for a rescue so firstly like I'm going to know dig deep into why and then I'll go into narrative on how you can collect this data so start with why so the first and foremost like could cuetes is an fascinating infrastructure it is a becoming a de facto know standard what we are seeing with our customer basis kubernetes open shift ECS and and slowly like uh no other providers are facing out but we see this top three as uh the main container orchestration platforms and when you have applications running on them the first thing that you need is like complete visibility to all the Clusters all the notes name spaces Services pods uh because once you have complete visibility to your clusters to your microservices kuity services uh know that are being hosted uh know your node infrastructure that is supporting your kubernetes your workloads are know that's currently uh know being discovered uh from Discovery all the parts that are running in Docker images and many of you may ask like hey hey this is an U formal estate why do we need to go and discover this kind of a new formal estate the primary reason is like looking at from audit compliance uh looking at from vulnerability management a zero day vulnerability that's hitting your estate you need to understand how many of those uh Docker images that are impacted by that vulnerability what services are impacted how do I communicate contact that uh Services team how do I engage an action framework to go after that U that setup but having that uh visibility is number one right so secondly when you think about from the uh software decomposition software Bild of material now which is again becoming slowly a mandate uh know uh in the sensitive Industries uh you need this kind of visibility uh where uh you cannot just have uh uh a visibility towards okay I have a Docker image is running 100 pods and these are all running containers and so on but you need to get visibility inside the docker image for which again like uh know we introduced uh uh something called called software decomposition capability where if you take an image we can actually go inside that image and we can see all the packages uh know that images uh is constructed of and this is another place like where we have seen know several Banks several insurance companies coming back to us and saying how can I do technology life cycle management how do I track how many of those Docker images have open source library in today's software World almost 70% ofof software has some kind of an open source Library so the next time the lock 4G or op SSL vulnerabilities are exposed then how do I track know how many of those uh Services team are being impacted how many of those Services team are public facing and addressing some of those uh um know your code business services and that is the place where visibility becomes the code Foundation because once you get visibility to all the estate you might have seen like know some of the topology data that that gets curated because the most interesting thing is like okay out of know these topologies many customers use key value pars primarily to uh add application context we have the tag based service mapping which pretty much know becoming the de facto uh standard of creating all the application Services uh and then connecting with the common service data model um no but the most interesting thing is the service context awareness right for those microservices so where you have a near realtime visibility into your estate uh you have complete visibility into your kubernetes services Parts clusters name spaces Services workloads all those data sets are all coming into your data platform in near Real Time with event driven Discovery and then using taags you are building that context and if you have no service mesh like estto again we connect all the microservice to microservice communication and this topology uh no team is the data Foundation because once you have that right multiple consumers can consume this data starting with your sres right so where you may have like uh all your microservices and you want to have an SRE Launchpad on all those microservices how these services are doing right we correlate the alerts from Prometheus we correlate the alerts from all the kubernetes container no Monitoring Solutions either it's din TR or any other APM Solutions and and we bind it with the know application services so that the service owners know can then text get paged know on the impact and all the s SLO no calculations can happen on the software Asset Management side we go inside the container we can collect all the software decomposition uh the team can create software B materials for the docker images which is becoming a kind of mandatory know task for from the compliance and governance uh and socks audits side uh and from the vulnerability management it is an fascinating use case because majority of you know will have a software container scanning technology right so this is one common question you you get asked like say okay I have different software that's targeting those container Docker images why I should know go and collect that data and see cmdb you know the basic answer is like okay your container vulnerability scanning technology can tell you what kind of uh uh know uh software decomposition and having vulnerabilities it can uh know we can tie the knots with the CV data but something that is interesting with uh our solution is uh like let's take Prisma uh no Cloud as an example know where we have an integration with twist lock right which brings in all the uh the image and the corresponding vulnerabilities but what we will get by combining the power of uh visibility data is the underlying uh know decomposition and understanding how that impact is uh know being tied up so in this example a Prisma cloud and twist lock integration can only say that this specific Docker image has vulnerabilities but from the operational state right when you wanted to create an vulnerability management task to go and remediate you need to connect the dots on saying okay this Docker image how many of those uh microservices are using who's a service owner how am I going to create a and risk mitigation framework for the uh DeVos team to go and address some of those vulnerabilities what applications are impacted so this is the know the power of data platform this is why know you need to have complete visibility know into your kubernetes estate so I kind of explained now why you need this visibility with some quick demo narratives and now we will see how you can get this visibility we provide four simple options uh for our customers uh to get visibility into the estate majority of you are using pattern based approach uh it's again evident from the survey results as well because this is how how initially uh know the uh content was delivered right primarily all you need is access to Cluster with a basic o or token and the magic can happen where the discovery goes and crawls and finds out all the relationships dependencies and bring all that estate into cmdb and then uh we had many customers uh uh started hosting uh know services in Cloud uh like especially eks AKs G a and uh customers did ask like saying hey I already I'm doing Cloud Discovery can I use the same Cloud Discovery and automatically go and uh discover uh know those Services right so that was the second evolution and then like we went after two new no offerings so like primarily we're going to talk about the CNO which is the cloud native operations and the service graph approach the service graph approach uh know is something that we again had different webinar where we explain pretty much otel has become the standard of uh know collecting the Telemetry data especially tracing data from these services and service now did an acquisition in the space uh and now we have built an uh connector right primarily to bring back all that critical dependency data uh know from your kubernetes estate uh so that's again being offered as otel connector all visibility customers are entitled to this uh but now today's topic is cloud native operations right which is again going back to the very old concept of agent versus agentless right so in the first version of CNO uh we came out with uh an package of both agent client collector and mid server which is all packaged under um you know one unit and uh simple oneliner command once you install it and all that critical topology gets discovered and sent to service now uh but one thing that were we kind of learned know in this architecture is okay it is still heavy uh now why do we need agent why do we need like mid server if I'm just doing visibility because all majority of our customers were asking is just give me the near real time updates right the package should be super simple and give me on line uh know deployment option so that uh it's it's easy to deploy uh know from dockerhub so this is what we have done with the CNO 2.0 which is primarily know the the internal code name called KS and fer it's super lightweight uh code based developed know with the go language and this code like pretty much it sits inside the kuties ecosystem for each cluster uh know this part like will continuously scan and will ship the payload to service now so the cloud native operations for visibility 2.0 it is shipped through store. service no.com all you have to do is like download agent client collector for visibility the latest package that was shipped in Feb 2023 upgrade your pattern content every month we ship new patterns so the discovery and service mapping pattern Store app get to the latest uh uh no version that was shipped in Feb 20123 and you will have all the necessary backend uh content that will enable you to deploy CNO so with this uh software update from store. serv.com you will have backward compatibility uh for at least three releases uh you get the content it's a lightweight architecture very simple installation with Helm and we're going to show you step by step on how that installation happens and tal is going to do a live demo as well from the architecture side as I said the uh know the um overall Plumbing work is super simple right it's uh it's an part that's sitting inside a cluster uh it's continuously listening for updates from kubernetes API server uh the first time you deploy the Pod we do the complete Discovery and thereafter right we're going to get Delta updates the core concept is near real time because of the eup formal estate right you need near real time secondly many customers often say that like hey managing tokens becomes very very difficult uh know and this is one place like where we say that like hey we give you a package with online Helm command uh know you install the package and that's good to go right so anytime a new cluster is being built right it's now part of your pipeline uh where you use this Helm command and install this pod and that automatically discovers all the kubernetes estate and will send uh know uh the data uh to your kubernetes from the kubernetes estate to your service now instance in near real time no credentials are needed no setup is needed right it it's just like a matter of you install the latest package give the instructions to your kubernetes administrator to take advantage of the setup so let's look at like what all things needed uh know on the kubernetes estate and as I said a live demo is just waiting for you the first step is like you go on create a name space right so once you have the name space then you need to have a know a secret uh to communicate to service now instance so so here in this case as you can see we are giving uh know a very simple uh know command line option for you to go and create the secret and once the secret is uh know created then uh know we go and uh know have the image uh set up ready and finally uh oneliner Helm command to install the cluster uh just four simple steps uh you know your uh pod is ready the Pod is all ready to uh know send live data on infrastructure topology uh all the tags uh all the relationships to service now um it's a very simple uh installer right we we strongly encourage you to try this in know your Supra and once you're happy with the results right so then know you can take a decision on whether to use agentless or Agent B like in this case like the pattern based approach or the uh cnob based approach right for getting visibility into estate so once you install it within few minutes like all the uh necessary pods gets dis know discovered and you would start seeing all the topology data the payload getting processed by cmdb identification and reconcillation engine uh know and you you can either use the old dashboard like on the left navigation side you would see uh know a dashboard for kubernetes or you can use the new Cloud operations workspace kubernetes the inventory view that again gives you the slicing and dicing of all the data that you wanted to visualize this is primarily for the consumers like the kubernetes administrators or your asset managers or security team whoever who wants to access this data right so just try to create an Ackle and give them the access that they wanted to see um and once the CNO is deployed right on the left navigation side you would also see uh know a place where something gets registered like like if you have like say hundreds of clusters you're going to see 100 uh uh lines here of Informer where it will be saying that hey I'm I'm ready to know give all the data and you're going to see all that informa based um data sets primarily the informa versions uh know when the know the full scan was completed the continuous discoveries turned on mainly for the event driven Discovery uh you would see the cluster names and pods and so on uh so this is primarily an Administration view of uh know all the registered Informer code and once uh know you you are you've deployed it and it's all functioning well right you always wanted to have some kind of a tribl shooting mechanism to grab locks or to look at Informer to restart Informer or to have some kind of tool chain primarily for your Administration activities so you can click on these Informer and you would be able to see a set of uh Self Service option for your support ability so typically if you are even opening up a case like your support engineer may ask you to grab informal logs right and attach to the case so you do have those supportability requirements met with the Informer and take advantage of it right the first uh uh no few customers uh we would like to see like know how you can deploy it please reach out to me or Steve or Gan like know where you are facing some challenges or you want us uh know to work with you know we will again be happy to uh know collaborate and explore path so with that note right um let's lock and roll with the demo from tal Capon tal over to you all right so all right so you see my screen not yet you see my screen yeah we can yes so I'm going to focus indeed on the CNO metal of copulating the cmdb so what we have now is in my cmdb I currently have one cluster with with few pods so what I'm going to show now is how do I uh install this client this Informer and the cmdbs so the first thing is to either identify or create a namespace or I already created namespace and the next thing is to put the uh the secret in it so let me show you how the secret command is looking so this is the command basically what you need to do is to create a user identify user on your instance with the specific wall that is required and then create the secret I already created the secret so I'm not going to run this again and the last thing is to run the home command so this is the command what what do we have here here is the Nam space this is the name space that I previously created created here I need to change the no to yes this is for legal purposes just to say that I'm uh they accepted the terms here I need to put the sorry the instance name and near here I need to put the cluster name and but I have the option to let the system pick the name from the current context of the uh cluster that I'm connected to so once I have that then I can uh click enter the system will pull their Helm chart from the internet and will install it in my cluster and in this case my cluster is in eks in in Amazon so now it is installed let me see what's going on so the system is telling me you know you can run this command in order to see if everything is running so I see that my part is already running and if I would like to take a look at the logs I'll type this so what you see here is the system is first bringing all the information on the relevant resources like Services pods nods Etc from the kubernetes API server and this is the only time when the system will go to the API server and ask for to get all the the full inventory of services from now from that point on it will only listen to changes and report them to to the instance so now the system sent started to send information to the uh H to the instance and this is done via regular table that is also used by Discovery called the eccq so no new mechanism here if I'll go to my uh dashboard here I see now that I have to Cluster and this one was just created if I'll dive to this one you will see that we already have uh most or all the elements that are discoverable in this in this cluster we have couple of nodes we have pods Services Nam spaces everything that the other methods are bringing we we also bring here so now we like to demonstrate the dynamic nature of this uh application so let me go back to kubernetes clusters dashboard so here I see here that there are 34 pods so what I'm going to do now is I'm going to create a new window here let me just make it a little bit bigger and I'm going to add an additional pod that that will be in Apache web server pod and I am going to do this by second so a new pod was created and if I'll go back to this screen that is showing the logs I'll see in a second that the system picked some changes and is preparing them to be sent to the instance so why do we have here more than one item one resource because a pod it just it's not just a pod a pod is one resource but in the cmdb we also have the container we have the container image we have the Linux server and the node associated with the squad we have the cluster itself we have the name space so everything is being sent to the instance and now if I'll go and refresh here we now have 35 let me click here and sort it by most recent discovery so now we have here a new pod that we just created and if I'll dive into this pod you will see all the information that sh was talking about okay so this is a part but this is also connected to a specific image and this associated with specific container it runs on specific ER kubernetes node so you have all this information and in addition you have the labels and annotation that are coming with this P so for example in this case we have owner we have application and this will serve us in in creation of the tag Based Services but also can serve you to automate flows that are related to this image for example you can create associate specific resources and populate the assignment group so once you have some incident or vulnerability related to a pod and image a deployment or whatever namespace whatever resource in kubernetes you will know exactly you can automate the task around it so if I'll go to the dependency Services dependency views you see a visualization of all those of all this information the Pod the image rep repo in which report and so forth course and once you want to uninstall that's is that is simple as well so if I'll go here so this is one command it will remove the Pod will remove all the related resources that we brought into the cmdb and everything is clean so this is basically it the main difference is again it's a Simplicity no need to enter credentials into the service now instant everything is done in a single T commands and it's basically um simpler and faster than the other methods which are still relevant this is from my side yeah fantastic T um we can wrap up for today there have been a lot of questions and a lot of interactions but um before we do that I just wanted to please make sure that for those of you that missed the link um just please make sure that you enroll into the live on service now webinar series I just posted Link in chat there and so you'll be up to dat with all these events we are always here uh once a month primarily hosting very uh interesting sessions on typically either how to master the product usage of what's already existing or as of today we'll be presenting new uh break uh breakthrough technology and solutions and we'll be uh basically showcasing how to use them and how to get value with them now uh before we close this session please make sure that you uh spend the just two minutes to provide us with feedback on the session as that's very very important for us and that really helps us making sure that uh we perfect this uh Academy and uh again we really appreciate your contributions throughout the today's session so uh huge thanks not only to uh Shri and T for their great uh sessions and uh great contributions for today but also thanks to everyone in the back end specifically to Steve Emerson that is still a great PIR of this uh webinar series and always giving great contributions I've SE I've seen other uh colleagues of us that have been greatly contributing shout out to do Schulz so thanks all and uh we're looking forward to see you in uh next month's session so make sure you don't miss that one and the recording for today's session will be available on the very same registration page uh for these events in a few days together with the de themselves so again thanks all it was great having you and we look forward to see you soon have a great rest of your day
https://www.youtube.com/watch?v=9PN4q-ZTCQw