DevOps and Docker Talk

Bret Fisher

Interviews and Q&A from my weekly YouTube Live show. Topics cover Docker and container tools like Kubernetes, Swarm, Cloud Native development, Cloud tech, DevOps, GitOps, DevSecOps, and the full software lifecycle supply chain. Full YouTube shows and more info available at https://podcast.bretfisher.com read less

Falco Logs Suspicious Events on Your K8s and Servers
6d ago
Falco Logs Suspicious Events on Your K8s and Servers
Bret and his co-host, Matt, are joined by Jason Dellaluce and Luca Guerra from Sysdig to talk about Falco, a tool I recommend for production clusters and knowing about any bad behavior on your servers. -------------------------------------★ Enroll now for my next Live course, GitHub Actions + Argo CD, scheduled for July 10-21. Go to bret.courses/autodeploy to sign up. ★------------------------------------Falco is a security tool I've mentioned multiple times on this show, because I mostly think that a low level security focused logging product is something that every production server needs. The ability to log unexpected events and behaviors on your Linux host is powerful and necessary to be able to audit what's really happening on your infrastructure outside of your app itself. Falco has been a CNCF incubating project for over four years, and I was immediately drawn to it in its early days, because it was container and Kubernetes aware and it could log and alert with default rules for everything, from someone starting a shell inside a container, to a bash history file being deleted, to a container trying to talk to the Kubernetes API. This episode will be useful for those of you new to tools like Falco and for those familiar with its basics, but also wanting to learn about newer features and use cases, which I did some learning on myself in this episode.Live recording of the complete show from April 6, 2023 is on YouTube (Ep. #210).★Topics★Falco websiteFalco on CNCFSupport this show and get exclusive benefits on Patreon, YouTube, or bretfisher.com!★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.comCreators & Guests Bret Fisher - Host Cristi Cotovan - Editor Beth Fisher - Producer Matt Williams - Host Jason Dellaluce - Guest Luca Guerra - Guest (00:00) - Intro(04:18) - Introducing the guests(07:19) - What is Falco? Why do we need it?(09:54) - What can Falco monitor?(19:05) - How are events logged?(32:53) - Does Falco classify alerts by severity?
DevPod for Dev Containers
May 26 2023
DevPod for Dev Containers
Bret is joined by Lukas Gentele and Rich Burroughs from Loft Labs to look at a new project called DevPod, that supports dev containers and VMs. It works with local Docker instances and AWS, GCP, Azure, and several other cloud providers. The project is compatible with Microsoft's DevContainer standard, which means it works with the VC Code standalone app and VS Code in the browser.-------------------------------------★ Enroll now for my next Live course, GitHub Actions + Argo CD, scheduled for July 10-21. Go to bret.courses/autodeploy to sign up. ★------------------------------------Lukas and Rich were on this show last year, showing off vcluster, which allows you to run a full Kubernetes cluster inside an existing Kubernetes namespace. In this episode, we announce the release of DevPod and also go through some demos. I'm already thinking of how I might use it in my own developer workflow.Live recording of the complete show from May 16, 2023 is on YouTube (Ep. #216). Includes demos.★Topics★DevPod websiteDevPod on TwitterSupport this show and get exclusive benefits on Patreon, YouTube, or bretfisher.com!★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.comCreators & Guests Bret Fisher - Host Beth Fisher - Producer Lukas Gentele - Guest Ruch Burroughs - Guest Cristi Cotovan - Editor (00:00) - Intro (04:43) - Introducing the guests(05:33) - Loft Labs and VCluster(07:40) - Introducing DevPod(12:33) - Why CLI plus GUI?(15:10) - DevPod use case(17:24) - Options for IDEs and port forwarding(20:14) - Using the Microsoft VS Code dev containers features(23:08) - Create dev environments locally or remotely(29:41) - Turning it on and off without having to go to the infrastructure(51:07) - How to get DevPod(51:54) - What's next? Share feedback.(59:06) - This is not a production deployment tool(01:03:21) - Wrap-up
Docker 2023 New Stuff
May 19 2023
Docker 2023 New Stuff
Bret and Matt are joined by two engineers in Docker's leadership - Chief Technology Officer Justin Cormack and Senior Manager of Developer Relations Michael Irwin, to talk about recent Docker Hub changes, as well as their latest product releases.-------------------------------------★ Enroll now for my next Live course, GitHub Actions + Argo CD, scheduled for July 10-21. Go to bret.courses/autodeploy to sign up. ★------------------------------------We touch on Docker's latest updates and announcements, focusing on the early releases of Docker Scout, Docker plus WebAssembly, and the Telepresence extension for Docker Desktop. We also look at Docker's version 23 release, its first major update in three years, with key changes including BuildKit becoming the default builder, the ability to run alternate containerd shims, and a return to semantic versioning. Other updates include new Swarm features and deprecation of older features, specifically older storage drivers.In the show we also cover Docker's recent announcement and subsequent retraction of a plan to require free Docker Hub organizations to move to different plans.Live recording of the complete show from March 23, 2023 is on YouTube (Ep. #208).★Topics★Docker v23 releaseDocker Hub org changesDocker ScoutTechnical preview of Docker+WasmTelepresence for Docker announcementSupport this show and get exclusive benefits on Patreon, YouTube, or bretfisher.com!★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.comCreators & Guests Justin Cormack - Guest Bret Fisher - Host Cristi Cotovan - Editor Beth Fisher - Producer Michael Irwin 🇺🇦 🕊 - Guest Matt Williams - Host (00:00) - Intro(04:50) - Docker version 23 release(07:31) - Docker's Hub Announcement and Retraction(09:34) - What does telepresence mean with Docker(12:12) - Should I switch to Kubernetes for development?(14:29) - Telepresence elevator pitch(22:24) - Telepresence connection scenarios(25:24) - How to connect with Telepresence?(32:59) - Bret's Jekyll Story(35:06) - What is available free in Scout?(37:09) - Scout is not a point-in-time scan(41:39) - James Buren's Scout Video(41:57) - Anyone can make an extension(43:58) - Favorite extensions(45:13) - Wasm technical preview(47:27) - Bret's interview with Nigel Poulton(50:21) - Question(54:25) - Docker 23 defaults to BuildKit(55:21) - Happy Birthday Docker(57:00) - Wrapping up
Contribute to Kubernetes
May 5 2023
Contribute to Kubernetes
Bret and Matt are joined by Chad Crowell of KubeSkills to walk through how you can contribute to Kubernetes open source.-------------------------------------★ Enroll now for my next Live course, GitHub Actions + Argo CD, scheduled for July 10-21. Go to bret.courses/autodeploy to sign up. ★------------------------------------ Chad started the kubeskills.com community and podcast to focus on learning Kubernetes by doing and in this episode, he's taking us through a detailed guide on how to get involved in the Kubernetes community.Although Kubernetes and other CNCF projects may seem big and complex with tons of activity, Chad helps us understand how the maturity of the projects and the community make it a much more pleasant onboarding experience for first-time contributors. We go through a wide range of resources and steps to help your first issue or pull request go smoothly.Live recording of this show from March 9, 2023 is on YouTube (Ep. #206).★Topics★Learning K8s by Open Source PDF slidesFirst Timers Only websiteK8s Contributor Community HomepageList of K8s SIGsK8s SlackOpen Sauced websiteK8s Contributors onboarding courseKube Cuddle podcast with Joe BedaLearning K8s Skills Support this show and get exclusive benefits on Patreon, YouTube, or bretfisher.com!★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.comCreators & Guests Bret Fisher - Host Cristi Cotovan - Editor Beth Fisher - Producer Matt Williams - Host Chad M. Crowell - Guest (00:00) - Intro(04:39) - Chad's Book(07:05) - Learning platforms(07:31) - Another way to learn(08:38) - SIGs(09:41) - Community or Contributor Experience SIG(12:00) - Volunteers(13:21) - For those who want to start contributing(15:44) - The different tags (16:42) - Good first issues(17:55) - Bret's first Docker fix(18:44) - Who determines the first issues?(20:31) - OpenSauced(21:10) - Finding the next steps after learning(21:53) - Dashboard to track contributions(22:36) - A very friendly community(24:24) - Who's paying for OpenSauced?(25:00) - How to build your rep on the internet(26:51) - Github Flow, Breaking it down(29:18) - Eddie Hub(30:04) - Assign yourself to the issue(30:44) - Compile Kubernetes(32:08) - Tracking the pull request lifecycle(33:38) - Changing the k8s reference issue(37:11) - Kubernetes Slack Channels(37:53) - SIG mailing lists(38:38) - Getting feedback before you do the work(40:12) - How do you give up and issue?(41:47) - Correlating issues with Slack(42:22) - Start with an issue first(43:18) - Random PRs don't go well(44:54) - Onboarding course(46:05) - Cheat sheet(46:20) - What Chad has learned from contributing(48:03) - Online resources(50:42) - Certifications and exams(52:40) - Matt's comment about a podcast(54:42) - Wrap up
Windows WSL and Containers in 2023
Apr 14 2023
Windows WSL and Containers in 2023
Bret is joined by fellow Docker Captain Nuno do Carmo to talk about desktop container solutions and the best Docker setup for Windows 11. -------------------------------------★ Enroll now for my next Live course, GitHub Actions + Argo CD, scheduled for July 10-21. Go to bret.courses/autodeploy to sign up. ★------------------------------------Nuno's a Docker Captain, Civo Ambassador, Microsoft MVP, and a big fan of Windows and Cloud Native. I've had him on the show before, because the more you use the Windows Subsystem for Linux and Docker Desktop, the more you'll want to use WSL.Nuno helps answer many questions such as where are the Linux files stored, managing the CPU and memory resources, backing up files in WSL, getting the host Windows Explorer into the Linux filesystem, getting back to the Windows file system from the Linux shell and more!Live recording of this show from February 23, 2023 on YouTube (Ep. #204). Includes demos.★Topics★Nuno's WSL blogBret's Docker Desktop alternatives listRancher Desktop websitePodman Desktop websiteSupport this show and get exclusive benefits on Patreon, YouTube, or bretfisher.com!★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.comCreators & Guests Bret Fisher - Host Beth Fisher - Producer Cristi Cotovan - Editor Nuno do Carmo - Guest (00:00) - Intro(02:46) - Episode intro(04:21) - Main show(04:33) - Reflecting on the Docker birthday(05:19) - Bret's Maven Course (05:21) - Introducing Nuno(06:28) - All starts with WSL(07:07) - Mac vs Windows(07:27) - WSL1 and WSL2(10:22) - Question Linux in VM vs WSL(14:45) - Filesystems and performance(16:28) - Setting yourself up for success with WSL(17:31) - WSL not installed by default with Windows(19:10) - Demo start (20:14) - Line endings issue in the past(20:50) - The tooling is WSL-aware(21:54) - VHDx(22:55) - Demo(26:16) - Bret re-explains it(28:55) - Question SSH into WSL(31:06) - Question How do you make a fresh WSL VM?(33:19) - Question What does mount show in Linux(34:31) - Question(35:22) - Taking snapshots with Raft WSL(36:02) - Question distros and VHDx files(37:39) - Deleting or losing your distros(39:11) - Question(41:39) - Ecosystem and options - the spreadsheet(44:05) - Demos(44:12) - Podman desktop(46:54) - Comment on Red Hat on Windows(48:07) - Rancher Desktop(55:13) - Demo(55:44) - Process isolation on Windows
Calico Networking for Kubernetes and More
Mar 31 2023
Calico Networking for Kubernetes and More
Bret is joined by Project Calico's Tomas Hruby from Tigera to dig into Calico CNI features for Kubernetes and beyond. -------------------------------------★ Enroll now for my next Live course, GitHub Actions + Argo CD, scheduled for July 10-21. Go to bret.courses/autodeploy to sign up. ★------------------------------------Calico can be used in a lot of places, including Linux, Windows, containers, bare metal, eBPF or iptables. Many of us learned about it as a CNI option for Kubernetes network and networking policy.Streamed live on YouTube on February 9, 2023.Unedited live recording of this show on YouTube (Ep. #202). Includes demos.★Topics★Project CalicoTigera WebsiteProject Calico on Tigera's WebsiteCreators & Guests Bret Fisher - Host Beth Fisher - Producer Cristi Cotovan - Editor Tomas Hruby - GuestSupport this show and get exclusive benefits on Patreon, YouTube, or bretfisher.com!★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com (00:00) - Intro(00:52) - About this episode(03:25) - Main show(03:30) - In today's episode(04:54) - How did Tomas get started with Calico?(05:22) - Projects are typically open source and SaaS(06:01) - Project Calico elevator pitch(07:20) - What can Calico do?(08:27) - The origins of Calico(09:07) - Docker got Kubernetes started(10:19) - Project Calico on Github(10:44) - Open source version is command-line driven(10:58) - Calico and the company behind it(11:22) - What makes Calico unique?(12:48) - EBPF(14:22) - EBPF and Calico(16:22) - Question(19:56) - Demo intro(20:27) - Question(21:12) - Question(22:19) - Question(23:09) - Vulnerabilities and threats(25:22) - Question(28:59) - Calico as service mesh(32:27) - What is Tomas excited about?(33:47) - EBPF real-time tooling
Faster Docker Builds with Depot
Mar 17 2023
Faster Docker Builds with Depot
Bret is joined by Kyle Galbraith and Jacob Gillespie, co-founders of Depot, to discuss their new solution to slow Docker builds. -------------------------------------★ Enroll now for my next Live course, GitHub Actions + Argo CD, scheduled for July 10-21. Go to bret.courses/autodeploy to sign up. ★------------------------------------If you've never dug into some of the details of Dockers BuildKit, that's the engine behind your Docker build command, then this episode is for you. I'm fairly confident that everyone who uses Docker will eventually come upon the problems that Kyle and Jacob were trying to solve with Depot. Their focus is on speeding up your Docker builds by doing them remotely, in a transparent way. They avoid you needing to rethink your workflows and CI automations and provide a CLI tool that's a drop-in replacement for the Docker build command. In this episode, we walked through the problems they can solve today with what I would call a unified shared build cache for your whole team, including your CI and automation tools. The way they are going about speeding up the Docker builds is something I wished Docker had done for us all along. I think it's still early days for the Depot product, but if you're suffering with long build image times it's already mature enough to be something I would consider as a replacement for the traditional Docker engine builds that we're all used to.Streamed live on YouTube on January 12, 2023.Unedited live recording of this show on YouTube (Ep. #198). Includes demos.★Topic Links★Depot websiteDepot on TwitterCreators & Guests Bret Fisher - Host Beth Fisher - Producer Cristi Cotovan - Editor Kyle Galbraith - Guest Jacob Gillespie - GuestSupport this show and get exclusive benefits on Patreon, YouTube, or bretfisher.com!★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com (00:00) - DDT MAIN(00:04) - Intro(02:47) - Bret's intro(04:18) - Main show(04:27) - Introducing the guests(04:47) - Today's topic(05:01) - Where did the idea for Depot come from?(06:20) - How it started(08:31) - Describing the problems(09:53) - The caching problem(11:43) - Docker caching default and in CI(14:39) - What is cache busting?(16:17) - Being deliberate about your CI environment(17:17) - What problems is Depot trying to solve?(19:21) - Replacing the Docker CLI with Depot(24:07) - Building for multi-platform(28:47) - Question(32:07) - Question(34:08) - Demo intro(34:39) - Modes of hosting(35:23) - Question(36:27) - What else does the UI offer?(40:15) - Getting started with Depot(41:22) - What's on the horizon?(42:24) - Outro
Better K8s Prometheus Alerts with Robusta
Mar 4 2023
Better K8s Prometheus Alerts with Robusta
-------------------------------------★ Enroll now for my next Live course, GitHub Actions + Argo CD, scheduled for July 10-21. Go to bret.courses/autodeploy to sign up. ★------------------------------------Bret is joined by Natan Yellin, the co-founder of Robusta.dev to talk Kubernetes and Prometheus monitoring, alerting, and maybe some CPU limit ranting. Robusta tries to fill the gap left by Kubernetes' own AlertManager which has a very specific and not so helpful way of describing events in your cluster. This makes it hard to diagnose the cause of the event and you're left with Google, StackOverflow and an awful lot of head-scratching. Robusta acts as a proxy between AlertManager and your notification platform of choice.In the show we talk about what Robusta is, how to deploy it in your clusters, and Natan also details some of the enhancements in their cloud offering that you can layer on top of that, which has a generous free tier.Streamed live on YouTube on January 5, 2023.Unedited live recording of this show on YouTube (Ep. #197). Includes demos.★Topics★Robusta WebsiteRobusta on GitHubKubeCon - Building a Runbook Automation System for Prometheus and KubernetesStop using K8s CPU limitsRecommended Pod SpecSend Push notifications to your phonePrometheus AlertManagerGrafana LabsKubewatch★Natan Yellin★Natan on TwitterNatan on LinkedIn★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com (00:00) - DDT MAIN(00:04) - Intro(02:47) - In today's episode (04:53) - Main show(05:21) - Introducing Natan(05:47) - Alert fatigue(06:23) - Where did the idea for Robusta come from?(10:10) - Someone has to do the job(11:11) - What does Robusta offer?(12:19) - Proxying the alerts and providing context(13:24) - Saving 10 to 30 minutes(15:42) - The open source Robusta repo(16:04) - The need to de-aggregate event data(17:03) - Example or demo(17:33) - Question about observability for microservices(20:32) - Tip 1 Consider using silences(21:43) - Tip 2 Monitor outcomes(22:17) - Don't ignore alerts because of fatigue(25:07) - Sending to different channels based on priority(26:36) - Question about sending messages to destinations(28:11) - Question(28:43) - Installing Robusta(29:36) - Demo set up commands(29:48) - Questions(30:05) - Demo Kubernetes-specific(30:59) - Multi-cluster question(33:26) - What does the SaaS platform do?(34:38) - Demo with SaaS(35:31) - kubectl not recommended(36:57) - Breaking the glass(40:09) - Question about notifications(42:08) - Getting started(43:18) - CPU limiting(44:09) - Soft limits on CPU in Kubernetes(46:29) - Bret's pod spec(51:16) - Outro Support this show and get exclusive benefits on Patreon, YouTube, or bretfisher.com!★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com
NGINX on Kubernetes, All The Details
Feb 17 2023
NGINX on Kubernetes, All The Details
-------------------------------------★ Enroll now for my next Live course, GitHub Actions + Argo CD, scheduled for July 10-21. Go to bret.courses/autodeploy to sign up. ★------------------------------------Bret is joined by two pros from the NGINX team, Robert Haynes and Brian Ehlert to break down the various use cases of NGINX on Kubernetes, and help you decide when and where you'll be using it.There's a lot going on around NGINX and I wanted to focus this conversation around NGINX on Kubernetes, and specifically the two ways you can run it for cluster ingress. We also get into some of the advanced scenarios of using NGINX, like caching and web application firewalls (WAF).Many of us are using NGINX somewhere in our clusters. I found it very interesting how Robert, Brian, and the team at F5 spend a lot of time showing customers how they can use it in many ways to avoid deploying additional products on their clusters. I'm a big fan of reducing complexity.Streamed live on YouTube on December 15, 2022.Unedited live recording of this show on YouTube (Ep. #195).★Topics★Intro to K8s networkingK8s + NGINXThe basic Kubernetes Ingress provider of NGINXThe official NGINX team Ingress CRD (more features)Gateway API for K8sMonitoring NGINXMonitoring NGINX with Prometheus★Brian Ehlert★Brian Ehlert on Twitter★Robert Haynes★Robert Haynes on Twitter★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com (00:00) - DDT MAIN(00:04) - Intro(02:47) - Custom intro(04:35) - Main show(04:40) - Introductions(04:59) - Today's topic(05:34) - Question: Common NGINX use cases(07:15) - NGINX's web server capabilities(08:05) - Common NGINX on Kubernetes considerations(11:22) - API gateway vs ingress(16:06) - Ingress configurations and policies(18:29) - CRD with ingress project(21:46) - When people adopt Kubernetes(24:27) - Free vs Paid version(29:11) - Question(29:21) - Last-minute risky annotations(33:46) - Validating NGINX configs(36:38) - Avoiding NGINX config manipulation(41:40) - Questions(42:54) - Monitoring in NGINX(44:26) - Prometheus exporter(45:53) - Question about caching(51:33) - Question(53:15) - Wrapping up(55:59) - Outro Support this show and get exclusive benefits on Patreon, YouTube, or bretfisher.com!★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com
Easy Kubernetes Auth and RBAC with Infra
Feb 3 2023
Easy Kubernetes Auth and RBAC with Infra
-------------------------------------★ Enroll now for my next Live course, GitHub Actions + Argo CD, scheduled for July 10-21. Go to bret.courses/autodeploy to sign up. ★------------------------------------Bret is joined by Matt Williams of Infra to show off their open source project Infra, which provides easy, centralized RBAC and auth to Kubernetes and more. Infra is a new company taking on simplifying centralized infrastructure, user authentication and permissions. Their open source tool by the same name is quite easy to start with. In this episode, Matt does a great job of explaining the pain points of Kubernetes user management, certificate distribution and revocation, and more pain points that Infra is bringing simplicity to.Streamed live on YouTube on November 10, 2022. Includes demos.Unedited live recording of this show on YouTube (Ep #191).★Topics★Infra WebsiteInfra on GitHubAll Day DevOps free conferenceMatt Williams===========Matt on TwitterMatt's YouTube Channel★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com (00:00) - DDT MAIN(00:04) - Intro(02:48) - Bret intro(03:47) - Main show (04:02) - Introducing Matt(04:34) - Today on the podcast(05:00) - Infra HQ and Company History(05:46) - How Infra came to be(08:34) - Datadog(10:28) - Infra and open source(11:53) - How Infra can help(12:18) - Core Infra functionality(13:50) - Bad idea(14:42) - Can't revoke certificates(18:05) - Painful Certificate Redistribution(19:05) - Why you need Infra(20:35) - Question(21:32) - Service accounts(22:16) - kubectl and pronunciations (23:51) - Question about OIDC(25:39) - Not just a Kubernetes tool(27:21) - Dealing with Keys is Hard(28:02) - Offboarding can be harder than Onboarding(30:18) - Workflow(31:15) - Demo intro(31:45) - End demo(31:56) - Cloud hosted and self-hosted(32:29) - Providers, Okta(33:56) - Is Infra GIOps Compatible?(36:47) - Quick summary of the demo for audio listeners(38:38) - Dumbed down roles?(40:02) - Question(40:46) - A tool to add to your toolbox(42:32) - Getting started and contributing(43:19) - Question(43:45) - Auditing in the future(44:43) - A Safe and Secure Model(45:46) - Wrapping up(47:36) - Outro Support this show and get exclusive benefits on Patreon, YouTube, or bretfisher.com!★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com
Trivy and Tracee, Aqua Security Tools
Jan 20 2023
Trivy and Tracee, Aqua Security Tools
-------------------------------------★ Enroll now for my next Live course, GitHub Actions + Argo CD, scheduled for July 10-21. Go to bret.courses/autodeploy to sign up. ★------------------------------------Bret is joined by Anaïs Urlichs of Aqua Security to talk container and Kubernetes security tools like trivy, kube-bench, tracee, and kube-hunter. I've been using trivy for over four years to scan for known vulnerabilities in my own container images and my clients.We also look at tracee, a new tool that is part of a new generation of tools that use the Linux kernel eBPF feature to investigate what's happening in real time on your servers. Anaïs is great as an explainer of Kubernetes and all cloud native things, and she's the creator of the 100 days of Kubernetes tutorials on her YouTube channel where she breaks down various cloud native topics for beginners. Based on what I've learned in this show from Anaïs, I plan to change how I use trivy so that it's scanning more things and more often in my CI automation pipelines.Streamed live on YouTube on November 3, 2022.Unedited live recording of this show on YouTube (Ep #190)★Topics★Aqua Security ToolsAqua Security on YouTubeTrivyTrivy-Operatorkube-benchtraceekube-hunter★Anaïs Urlichs★Anaïs on TwitterAnaïs' Newsletter Anaïs on YouTube 100 Days of Kubernetes★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com (00:00) - DDT MAIN(00:04) - Intro(02:47) - Custom intro(04:22) - Main show(04:26) - Introducing Anais(06:24) - Security Tools(06:50) - What is Aqua Security(08:06) - Not all security scanners are made equal(09:16) - What is Trivy?(09:55) - Misconfiguration scanning with Trivy (14:06) - Security vs Disruption(15:00) - Address vulnerabilities in the base image(16:05) - Question: Operator for Trivy(19:45) - Automating the tool(21:39) - Vulnerability fatigue(22:26) - Question: Go and No-go Criteria(26:07) - Tip Toe, Start Small(27:13) - Kube Bench(28:02) - Kube Hunter(30:03) - What is Tracee?(35:33) - What is the roadmap for implementing these tools?(41:51) - Outro Support this show and get exclusive benefits on Patreon, YouTube, or bretfisher.com!★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com
Software Supply Chain Security with Chainguard
Jan 6 2023
Software Supply Chain Security with Chainguard
-------------------------------------★ Enroll now for my next Live course, GitHub Actions + Argo CD, scheduled for July 10-21. Go to bret.courses/autodeploy to sign up. ★------------------------------------Bret is joined by two Chainguard co-founders, CEO Dan Lorenc and Head of Product, Kim Lewandowski, to break down the ins and outs of supply chain security and talk about Chainguard's approach to securing it. We dive into tools, including their new Wolfi Linux distro.We first talk about what that even is, because it's a buzzword right now, and not everyone's on the same page on what securing your supply chain even means in the world of software. Then we jump into base images for containers, and their project Wolfi. We talk a lot about Wolfi in this episode, because it has the potential to change how we build our containers.Streamed live on YouTube on October 13, 2022.Unedited live recording of this show on YouTube (Ep #188)★Topics★Chainguard WebsiteChainguard TwitterChainguard AcademyWolfiWolfi-based imagesSigstore★Dan Lorenc★Dan Lorenc on TwitterDan Lorenc on Linkedin★Kim Lewandowski★Kim Lewandowski on TwitterKim Lewandowski on Linkedin★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansHomepage bretfisher.com (00:00) - DDT MAIN(00:04) - Intro(02:48) - Custom intro(04:45) - Main show(04:58) - Introductions(05:18) - How did Chainguard get started?(06:17) - What is a supply chain?(08:24) - First Security Things(10:49) - The article and the base image(13:56) - Wolfi elevator pitch(16:43) - How do packages get into Wolfi?(20:43) - How do Wolfi packages work(23:51) - Chainguard Enforce(28:37) - Question about in-toto(31:02) - Preventing unsigned images in production(32:38) - Blocking vulnerable dependencies with policies(33:33) - Scanning on servers(35:56) - Question(37:47) - Question(39:44) - Getting started with Wolfi(41:51) - Where are they on Github (demo?)(42:44) - Question about vex(45:07) - What else?(45:34) - Chainguard Academy(47:18) - Professional services(51:26) - Wrapping up(51:50) - Outro Support this show and get exclusive benefits on Patreon, YouTube, or bretfisher.com!★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com
Best of DevOps 2022
Dec 23 2022
Best of DevOps 2022
-------------------------------------★ Enroll now for my next Live course, GitHub Actions + Argo CD, scheduled for July 10-21. Go to bret.courses/autodeploy to sign up. ★------------------------------------Bret is joined by Nirmal Mehta of AWS and engineering consultant Laura Tacho, for the annual Best of DevOps. We've started this trend of going through the year's best (and worst) of DevOps every December, everyone brings their topics, we mix them all up and try to get through all of it. This year, we came pretty close. We cover many topics in this year's episode, things like desktop GUIs for containers, the return of real-life conferences, Docker reaching a significant milestone, AI, ML, data platforms and much, much more.Streamed live on YouTube on December 8, 2022. Includes demos.Unedited live recording of this show on YouTube (Ep #194)★Topics★Full doc of topics (more than we could cover)Year of Desktop GUI’s for Container Dev and Cloud Native MgmtDocker Extensions List Rancher DesktopPodman DesktopLens commercialOpenLensk9s websiteKui websiteDevOps Survey TrendsOpenTelemetry Articles- Transforming IT Departments - Properly Explained and Demoed - Getting StartedKarpenter websiteeBPF and Profiling- Pixie- Parca★Laura Tacho★Laura's websiteLaura's CourseLaura on Twitter★Nirmal Mehta★Nirmal on LinkedinNirmal on MastodonNirmal on Twitter★Join my Community★New live course on CI automation and gitops deployments Best coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansHomepage bretfisher.com (00:00) - DDT MAIN(00:04) - Template intro(00:53) - Custom intro(06:19) - Main show(06:39) - Introducing the guests(07:14) - In today's episode(07:46) - The year of desktop GUIs(14:08) - In real life conferences(14:40) - Boom and Bust(15:24) - Will Jenkins go away?(16:33) - GitHub Actions(18:08) - Laura's Rubber-band Theory(21:03) - Revenue and Docker's comeback(22:56) - Other trends(23:05) - DORA report(24:15) - Increased security requirements(26:25) - Jumping on the security bandwagon(27:37) - Security by default(28:58) - Rapid fire Kubernetes happenings(30:00) - Bret's Maven Course(30:09) - Laura's teaching(30:58) - WASM+ Docker(31:32) - Slim.ai(32:23) - Open telemetry(37:31) - Carpenter(38:58) - Lack of staff(39:44) - AI(42:32) - Boosting productivity(46:32) - ML models developed and running in containers(48:08) - Wrapping up(48:34) - Outro Support this show and get exclusive benefits on Patreon, YouTube, or bretfisher.com!★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com
Docker: What's New from 2022
Dec 16 2022
Docker: What's New from 2022
-------------------------------------★ Enroll now for my next Live course, GitHub Actions + Argo CD, scheduled for July 10-21. Go to bret.courses/autodeploy to sign up. ★------------------------------------Bret is joined by Michael Irwin, Sr. Manager for DevRel at Docker, to review and demo our top 2022 new features and announcements from Docker Inc. We run through the very long list in this episode and sadly, had to skip over the smaller, nuance features or subtle changes and focused on the bigger things - a major one being Docker extensions - as well as Docker Hub support for OCI artifacts, like the Helm charts, volume, WASM, Hardened Docker Desktop, tilt.dev and much more.Streamed live on YouTube on December 1,  2022. Includes demos.Unedited live recording of this show on YouTube (Ep #193)★Topics★Docker Blog, "Products" category (most of our topics came from here)Recapping the last year of Docker Desktop (YouTube, September 2022)What's new in Docker Desktop (YouTube, DockerCon 2022, May 2022)What's new in Docker build (YouTube, DockerCon 2022, May 2022)★Michael Irwin★Michael on TwitterMichael's Website★Join my Community★Best coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansHomepage bretfisher.com (00:00) - DDT MAIN(00:04) - Template intro(02:47) - Custom intro(05:43) - Main show(05:54) - Welcome to Michael(07:18) - Keeping up with updates to our tools(09:57) - OCI artifacts(11:07) - What are OCI artifacts?(14:40) - WASM(18:29) - DEMO of WASM(25:10) - Question(25:37) - Question(27:36) - Question(29:23) - Question(33:25) - Extensions(36:34) - Question(38:35) - Question(41:31) - Dev Environments(44:45) - Compose v2(46:48) - Hardened Desktop(51:40) - Tilt(53:11) - Docker Desktop for Linux(54:55) - DSO Website(57:42) - More vulnerabilities every year(01:00:45) - Moving Dockerd image management to containerd(01:04:23) - Buildkit improvements(01:07:44) - Buildkit's link feature(01:11:53) - Stuff not covered(01:13:44) - Winding down(01:14:17) - Question(01:19:45) - Show and guest calendar(01:20:14) - Outro Support this show and get exclusive benefits on Patreon, YouTube, or bretfisher.com!★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com
Key DevOps Skills for Improving Your Expertise
Dec 9 2022
Key DevOps Skills for Improving Your Expertise
-------------------------------------★ Enroll now for my next Live course, GitHub Actions + Argo CD, scheduled for July 10-21. Go to bret.courses/autodeploy to sign up. ★------------------------------------Bret is joined by Brian Christner, a Docker Captain and Chief, Online Gaming for Grand Casino Baden (jackpots.ch), who returns to the show to discuss his top recommended skills for improving your DevOps expertise.Both Bret and Brian have been consultants on and off throughout their careers and also in positions where they needed to hire other engineers - often other DevOps engineers. They share their perspectives on the different types of DevOps roles and the various jobs they need to fill.In this episode, we thought it would be helpful to bring our experience on DevOps jobs and look at the most essential and in-demand skills throughout the industry.Streamed live on YouTube on October 6, 2022.Unedited live recording of this show on YouTube (Ep #187)★Topics★DevOps Foundations CourseEngineering Management Training from Laura TachoAwesome Docker resourcesAwesome Everything Lists on GitHubKubernetes This Month with Nigel PoultonAWS Cloud TrainingContainer Automation Examples by BretDocker Observability by Brain★Brian Christner★Brian on TwitterBrian on LinkedInBrian's Courses Promo Code TRAEFIK50 for 50% offBrian's GitHub Brian's Blog★Join my Community★Best coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansHomepage bretfisher.com (00:00) - DDT MAIN(00:04) - Intro(00:53) - Intro 2(03:41) - Main show(03:47) - Welcome(04:55) - Brian's corner of the internet(07:31) - Impact of certifications in the hiring process(07:55) - What's your pet project?(08:52) - What lights you up?(10:21) - Sharers rather than Knowers(11:45) - About clouds(18:29) - DevOps are enablers(19:43) - Be replaceable(21:52) - Soft Skills(22:14) - The many hats of Senior DevOps(22:17) - Encouragers(22:30) - Protectors(22:38) - Realistic(22:55) - Protect your team(23:21) - Say no(23:49) - Problem solvers(23:52) - Listeners(25:43) - Question(26:42) - Awesome Docker List(29:40) - DevOps is vast and wide(31:51) - Observability(33:42) - Choose what to measure(34:44) - Junior and Senior DevOps Skillsets(36:47) - Being proactive in measuring(38:57) - Question(40:01) - Use the built-in tools first(43:35) - Quick way to get your hands dirty(49:38) - Security(52:44) - Infrastructure-as-Code(56:45) - Being a generalist or a specialist(58:26) - Enable others to work without needing you(01:00:07) - Question(01:00:10) - Getting started with a cloud(01:03:05) - Nigel Poulton(01:03:52) - You can't be responsible for everything(01:05:47) - Are certifications mandatory?(01:08:28) - Deployment checklist question(01:09:16) - Question(01:14:08) - Question(01:14:54) - Announcements(01:17:06) - Outro Support this show and get exclusive benefits on Patreon, YouTube, or bretfisher.com!★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com
HashiCorp Vault for Kubernetes
Nov 25 2022
HashiCorp Vault for Kubernetes
-------------------------------------★ Enroll now for my next Live course, GitHub Actions + Argo CD, scheduled for July 10-21. Go to bret.courses/autodeploy to sign up. ★------------------------------------Bret is joined by Rosemary Wang from HashiCorp to show off Vault for Kubernetes, an an open source secrets provider.Rosemary is a return guest and does her usual fantastic job at explaining the complex topics around storing secrets, who needs Vault and why, running Vault on Kubernetes, the Vault storage backend and so much more.Streamed live on YouTube on September 29, 2022. Includes demos.Unedited live recording of this show on YouTube (Ep #186)★Topics★Vault websiteHashiCorp CloudRaft storage for Vault, how Raft worksExample repo: HashiCorp Vault for Development Teams★Rosemary Wang★Rosemary on TwitterRosemary on Linkedin★Join my Community★Best coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansHomepage bretfisher.com (00:00) - DDT MAIN(00:04) - Intro(02:48) - Bret intro(03:30) - Main show(03:46) - Course updates(04:06) - Introductions(05:09) - Today's Topic(06:18) - Anyone who doesn't need secret management?(09:07) - Elevator pitch for Vault(11:16) - Handling Rotation and Exit Strategies(13:43) - When do I need Vault?(16:29) - Question about Aquilas(16:48) - Vault is open source(18:44) - We ain't got time for that(19:35) - Can I run Vault on Kubernetes?(20:33) - Question: Where are Secrets Stored?(21:53) - Raft all the things(23:13) - Question: Vault and SSL Certificates(24:25) - Question and Demo(24:50) - Demo intro(25:20) - Demo(25:21) - Question about HSMs(25:44) - Question(26:38) - Question about Unsealed Tokens(29:12) - Question(31:36) - Bret's First Question about Toil(38:27) - Question: Password Managers and Vault(41:38) - Question(42:59) - Question(45:32) - Notes about Vault Agent Sidecar and Authentication(47:09) - Bret's Summary(50:42) - Question about Getting Started(51:38) - Starting with Sealed Secrets(54:24) - Wrap up(55:00) - Getting in touch with Rosemary(55:37) - What's next for Rosemary?(56:25) - Outro Support this show and get exclusive benefits on Patreon, YouTube, or bretfisher.com!★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com
Service Mesh in Docker Desktop with Meshery
Nov 11 2022
Service Mesh in Docker Desktop with Meshery
-------------------------------------★ Enroll now for my next Live course, GitHub Actions + Argo CD, scheduled for July 10-21. Go to bret.courses/autodeploy to sign up. ★------------------------------------Bret is joined by Lee Calcote and Nic Jackson, co-authors of the Service Mesh Patterns book, to discuss service mesh for Docker Desktop and Compose apps with the new Meshery extension for Docker desktop.They talk about what service mesh is and go into the new Measure extension for Docker Desktop, which is a CNCF sandbox project. One of its bigger features is to help you try out different service meshes and test them with only a few clicks. They also cover other features of their tools, such as the beta of MeshMap which helps you visualize your clusters and apply better practices to your service mesh.Streamed live on YouTube on September 22, 2022. Includes demos.Unedited live recording of this show on YouTube (Ep #185)★Topics★Learn Service MeshMeshery Docker Extension MeshMap Service Mesh Patterns Book★Nic Jackson, Principal Developer Advocate, HashiCorp★Nic on TwitterNic on LinkedinNic Jackson on YouTube Shipyard website★Lee Calcote, Founder and CEO, Layer5★Lee on TwitterLee on Linkedin★Join my Community★Best coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansHomepage bretfisher.com (00:00) - DDT MAIN(00:04) - Template intro(00:52) - Bret intro(03:47) - Main show(03:52) - The guests(04:33) - Lee and Layer5(05:49) - Nick and Hashicorp(07:45) - Lee and Nick(08:48) - Challenges of writing a book(09:31) - Layer5 and Meshery(10:32) - Meshery elevator pitch(12:40) - Service Mesh 101(13:10) - Retry(14:14) - Observability(15:23) - Question Docker Swarm Supports Docker Extensions?(17:33) - What does service mesh seem like?(18:32) - Platform engineering(25:48) - Distributed systems concerns(27:33) - preparation(28:10) - What would you use Meshery locally for?(29:44) - Mesh map(30:42) - Demo but mostly theoretical(34:39) - Visual designer(35:05) - Catalog of extensions(35:43) - Performance management(38:57) - Installing the extension(39:46) - Close to the end(40:06) - A lot going on online(40:48) - Shipyard(44:20) - Starship(44:38) - Wrapping up(44:49) - Status of the book(51:39) - Closing(51:55) - Outro Support this show and get exclusive benefits on Patreon, YouTube, or bretfisher.com!★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com
Cilium and eBPF with Liz Rice
Oct 28 2022
Cilium and eBPF with Liz Rice
-------------------------------------★ Enroll now for my next Live course, GitHub Actions + Argo CD, scheduled for July 10-21. Go to bret.courses/autodeploy to sign up. ★------------------------------------Bret is joined by Liz Rice, Chief Open Source Officer at Isovalent, the makers of Cilium, to discuss Cilium and eBPF. Liz Rice is back to give us more insight into eBPF and the Cilium project. Isovalent is the company that created and manages the Cilium Project, which does an increasing number of things for Kubernetes, including networking, CNI support, security, advanced networking stuff, and observability, as well as other things like load balancing. Liz is one of my go-to experts on how low-level Linux internals work. She's been speaking about container internals since the early days of Docker.Streamed live on YouTube on September 8, 2022.Unedited live recording of this show on YouTube (Ep #183)★Topics★Cilium websiteIsovalent websiteeBPFNetwork Policy Editor★Liz Rice★Liz Rice on TwitterLiz Rice's websiteBooks on Containers, eBPF, Kubernetes and Go★Join my Community★ Best coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansHomepage bretfisher.com (00:00) - DDT MAIN(00:04) - Intro(02:47) - Bret intro(03:35) - Main interview(03:38) - The merch store(04:33) - More merch talk(06:13) - Introductions(07:10) - What else Liz does(07:20) - Liz's books(08:16) - Brief history of EBPF(09:35) - Kernel modules before EBPF(10:40) - EBPF vs Kernel Modules(11:51) - EBFP is dynamically loaded(13:17) - Performance and Data Transfer(14:29) - Isovalent and Cilium (16:06) - How Cilium started(18:12) - Specific versions of the kernel?(19:26) - Where do we use EBPF in Kubernetes?(20:06) - CNI(21:56) - Question: Where can you start learning EBPF?(24:58) - Question(32:16) - All open source?(33:02) - Question Cilium as a service mesh(34:26) - Enabling certain features(35:33) - Question(36:05) - Question(37:14) - Question(39:15) - Wrapping up Cilium in cloud(40:16) - Offloading programs XDP(42:10) - Question about GUI(44:35) - Question(51:23) - Question(54:04) - EBPF on Windows?(55:07) - How is it implemented?(55:56) - Wrapping up Support this show and get exclusive benefits on Patreon, YouTube, or bretfisher.com!★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com
Kubescape Kubernetes Security with ARMO
Oct 21 2022
Kubescape Kubernetes Security with ARMO
-------------------------------------★ Enroll now for my next Live course, GitHub Actions + Argo CD, scheduled for July 10-21. Go to bret.courses/autodeploy to sign up. ★------------------------------------Bret is joined by Shauli Rozen, CEO and Co-Founder of ARMO, creators of Kubescape. Kubescape is a K8s open-source tool providing a multi-cloud K8s single pane of glass, including risk analysis, security compliance, RBAC visualizer, and image vulnerability scanning.I'm a fan of tools like this and specifically of Kubescape, which I use and recommend to my clients. The scanner can scan your YAML manifests of your Kubernetes resources. It can scan your live Kubernetes clusters. And it can scan the YAML in your Git repos, as well as the images themselves that you're deploying to Kubernetes. As ARMO calls it, it's a single pane of glass into your Kubernetes security. Streamed live on YouTube on September 1, 2022. Includes demos.Unedited live recording of this show on YouTube (Ep #182)★Topics★Kubescape's GitHub K8s Security Dashboard ARMO website★Shauli Rozen★Shauli on Twitter★Join my Community★Best coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansHomepage bretfisher.com (00:00) - DDT MAIN(00:04) - Main intro(00:53) - Custom intro(04:39) - Main show(04:43) - Introductions(05:37) - The Kubescape project(06:19) - Go to the developers (07:20) - Security low-handing fruit(08:13) - I just want to be a user(11:26) - Kubescape elevator pitch(13:54) - Good learning tool(14:42) - Linting(15:14) - Remediation(16:39) - The SaaS Version(18:13) - Does DevOps not care about security?(20:18) - A gap in terminology(22:25) - Security compliance and guidance(27:52) - GitOps Approach(29:32) - Asking about demo(30:13) - Question(31:15) - Become a contributor(32:49) - Demo intro(33:15) - Demo end part(33:20) - Question(33:50) - Visualizer(35:17) - Question(36:35) - Question(40:49) - Mindset differences(41:43) - Question(44:00) - Question(44:27) - Winding down(45:20) - How to get started(46:20) - Template outro Support this show and get exclusive benefits on Patreon, YouTube, or bretfisher.com!★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com
Slim and Secure Container Images with Slim.ai
Oct 14 2022
Slim and Secure Container Images with Slim.ai
-------------------------------------★ Enroll now for my next Live course, GitHub Actions + Argo CD, scheduled for July 10-21. Go to bret.courses/autodeploy to sign up. ★------------------------------------Bret is joined by Martin Wimpress and Pieter van Noordennen from Slim.ai to discuss some ways to slim down your Docker images and reduce the attack surface of your containers in the process.Many companies and projects have tried to do similar things before - Slim Images, Alpine Images, Distro List, Build Packs, and even Docker tried a few years back, to create intelligence and guidance around migrating legacy apps into slim production quality images. Those efforts were scrapped in 2019. The dual mandate of generating Docker images - easy to understand and as minimal as possible, with the lowest CVE vulnerability count - was not achieved by any of those projects. Automation and intelligence like Slim.ai is the future of building container images and also the future of complex monoliths and legacy apps with a lot of dependencies.Streamed live on YouTube on July 28, 2022. Includes demos.Unedited live recording of this show on YouTube (Ep #180)★Topics★Docker SlimSlim.ai★Martin Wimpress★Martin Wimpress on Twitter★Pieter van Noordennen★Pieter van Noordennen on Twitter★Join my Community★Best coupons for my Docker and Kubernetes coursesChat with us on our Discord Server DevOps FansHomepage bretfisher.com (00:00) - DDT MAIN(00:04) - Intro(00:53) - Custom intro(06:26) - Main show(06:45) - How Slim.ai started(09:01) - Complexities of shipping images(10:47) - DockerSlim(12:21) - Setting the stage for demo(14:56) - Demo intro (15:22) - Demo(15:27) - Bret's Question(24:14) - Different container composition options(25:30) - Demo intro 2(25:36) - Bret loves Docker Desktop and Extensions(29:22) - Pausing Docker(29:48) - The extension is the same as the SaaS(30:24) - It's free(30:57) - Demo?(30:57) - Distroless and optimized starting points(36:41) - Build engineering nightmare(38:09) - Not just security considerations(40:57) - Understanding dependency differences(42:28) - Question(43:57) - Slim cli(48:02) - Getting started(49:32) - Outro Support this show and get exclusive benefits on Patreon, YouTube, or bretfisher.com!★Join my Community★New live course on CI automation and gitops deploymentsBest coupons for my Docker and Kubernetes coursesChat with us and fellow students on our Discord Server DevOps FansGrab some merch at Bret's Loot BoxHomepage bretfisher.com