1 00:00:00,000 --> 00:00:09,760 I know it's 1 to 2, so some of you again sacrificed your lunch. 2 00:00:09,760 --> 00:00:18,040 Anyone here who was also at the Rust talk? Wow, you sacrificed two lunch periods for 5 00:00:19,040 --> 00:00:24,040 I also have to know who was there because I can't repeat the same jokes now, can I? 6 00:00:24,040 --> 00:00:26,040 So hello, welcome to my talk. 7 00:00:26,080 --> 00:00:31,600 I'm going to give a little bit of a talk about how and also why you'd be interested in building 8 00:00:31,600 --> 00:00:34,600 your own cloud service provider from scratch. 9 00:00:34,600 --> 00:00:41,600 No Azure, AWS, GCP, I know we've got all these GDEs, but ignore them for now, we're doing it from scratch. 11 00:00:41,600 --> 00:00:45,600 We do local first, right? Digital sovereignty. 13 00:00:49,600 --> 00:00:51,600 We'll see how it goes. 14 00:00:51,600 --> 00:00:55,600 So yeah, this is me several years ago. 15 00:00:56,160 --> 00:00:58,160 I had short hair, small rack. 16 00:00:58,160 --> 00:01:00,160 Now I have big rack, big servers. 17 00:01:00,160 --> 00:01:08,160 A bit about me, I have a website, I have Mastodon, and GitHub, and some of my 18 00:01:08,160 --> 00:01:11,160 interests include server stuff. 19 00:01:11,160 --> 00:01:13,160 As you can see I have a mini server rack here. 20 00:01:13,160 --> 00:01:17,160 Now I've got a much bigger server rack, it's big enough for me to sleep in. 21 00:01:17,160 --> 00:01:21,160 Much bigger servers as well. 22 00:01:21,720 --> 00:01:25,720 I work in Kubernetes and infrastructure and all that kind of stuff. 23 00:01:25,720 --> 00:01:29,720 And for some reason I decided I'm going to work on Kubernetes at work, 24 00:01:29,720 --> 00:01:33,720 and when I get home, my hobby is going to be Kubernetes on the home lab. 25 00:01:33,720 --> 00:01:36,720 So work at work, work at home. 26 00:01:36,720 --> 00:01:40,720 This talk is influenced a lot by my homelab. 27 00:01:40,720 --> 00:01:46,720 And also by the fact that I'm one of the organizers of Cloud Native Mauritius. 28 00:01:47,280 --> 00:01:51,280 It's a community group, kinda like the MSCC, PyMUG, etc, for cloud native stuff. 30 00:01:53,280 --> 00:01:57,280 Now is there anyone here not familiar with what cloud native means? 31 00:01:59,280 --> 00:02:01,280 Wow, nobody raised their hand. 32 00:02:01,280 --> 00:02:05,280 If you don't raise your hand, I can't answer your question, 33 00:02:05,280 --> 00:02:08,280 and then you go home and you go, Alex, what is cloud native? 34 00:02:08,280 --> 00:02:12,280 And then you're going to make a LinkedIn post and be like "I did not understand cloud native" 36 00:02:12,840 --> 00:02:16,840 This is us. 37 00:02:19,840 --> 00:02:21,840 I mean, you can't even be sure this is us. 38 00:02:21,840 --> 00:02:25,840 I just chose a random pixel somewhere near us here. 39 00:02:25,840 --> 00:02:27,840 And this is a problem. 40 00:02:27,840 --> 00:02:29,840 I mean, we're all Mauritians here. 41 00:02:29,840 --> 00:02:33,840 This is a talk I gave at KubeCon in Amsterdam, and you'd be surprised at how few Europeans 42 00:02:33,840 --> 00:02:35,840 or Americans know where Mauritius is. 44 00:02:34,840 --> 00:02:36,840 So that was important. 45 00:02:36,840 --> 00:02:37,840 It's relevant here as well. 46 00:02:38,840 --> 00:02:40,840 We're all very familiar with our geographical position. 47 00:02:40,400 --> 00:02:44,400 Somewhere in the Indian Ocean, a little speck of dust, 48 00:02:44,400 --> 00:02:48,400 far from big cloud giants in Europe, in America, and so on. 49 00:02:50,400 --> 00:02:54,400 So I'm a bit sad about this. 50 00:02:54,400 --> 00:02:56,400 There was this Reddit post a while back 51 00:02:56,400 --> 00:02:58,400 which compiled all the data centres 52 00:02:58,400 --> 00:03:02,400 from Azure, Amazon, Google, and Facebook, 53 00:03:02,400 --> 00:03:06,400 and the concentration of the data centres around the world. 54 00:03:06,400 --> 00:03:08,400 And look at this. 55 00:03:08,960 --> 00:03:10,960 America, plenty. 56 00:03:10,960 --> 00:03:12,960 Europe, many. 57 00:03:12,960 --> 00:03:14,960 East Asia, you've got many. 58 00:03:14,960 --> 00:03:16,960 Here is Africa. 59 00:03:16,960 --> 00:03:18,960 We've got so little capacity here. 60 00:03:18,960 --> 00:03:20,960 It's a bit sad. 61 00:03:20,960 --> 00:03:24,960 During the panel of digital sovereignty, 62 00:03:24,960 --> 00:03:28,960 I remember hearing the number floating around that 63 00:03:28,960 --> 00:03:36,960 Africa represents 0.6% of data centre capacity in the world by megawatts. 65 00:03:37,520 --> 00:03:39,520 That's so little. 66 00:03:39,520 --> 00:03:41,520 You've got so little compute in the entirety of Africa, 67 00:03:41,520 --> 00:03:43,520 which, I mean, is kind of big, right? 68 00:03:43,520 --> 00:03:47,520 So this made me sad. 69 00:03:49,520 --> 00:03:51,520 We do have local cloud providers. 70 00:03:51,520 --> 00:03:53,520 Don't worry, all slides are light mode now. 71 00:03:53,520 --> 00:03:55,520 We do have a few local CSPs. 72 00:03:55,520 --> 00:03:57,520 We've got Cloud.MU, 73 00:03:57,520 --> 00:03:59,520 which is one we've known for quite a while. 74 00:03:59,520 --> 00:04:01,520 Hodi, I met them yesterday. 75 00:04:01,520 --> 00:04:03,520 I forgot about them for a while. 76 00:04:03,520 --> 00:04:05,520 You have Mauritius Telecom, 77 00:04:06,080 --> 00:04:08,080 which has cloud offerings now, I think. 78 00:04:08,080 --> 00:04:10,080 I'm not sure to what extent it's public. 79 00:04:10,080 --> 00:04:12,080 I've heard the prices are outrageous. 80 00:04:12,080 --> 00:04:14,080 Sorry. 81 00:04:13,080 --> 00:04:15,080 Anyone from MyT here? 82 00:04:15,080 --> 00:04:18,080 The booth is right outside. I don't want to... 84 00:04:20,080 --> 00:04:24,080 But MyT's prices are outrageous. Go harass them later. 86 00:04:24,080 --> 00:04:28,080 Emtel as well, they had plans for cloud. 88 00:04:28,080 --> 00:04:30,080 I haven't heard much about the public side of it. 89 00:04:30,080 --> 00:04:32,080 At least, you know, with Cloud.MU... 90 00:04:32,080 --> 00:04:34,080 Where's my mouse? 91 00:04:36,080 --> 00:04:38,080 There it is. 92 00:04:38,080 --> 00:04:42,080 At least with CloudMU, you have a very public website 93 00:04:42,080 --> 00:04:46,080 You can just go to VPS hosting, virtual servers, 96 00:04:46,080 --> 00:04:48,080 and then you can actually get your stuff here, right? 97 00:04:50,080 --> 00:04:52,080 It's something. 98 00:04:52,080 --> 00:04:54,080 But local cloud service providers 99 00:04:54,080 --> 00:04:56,080 in Mauritius are what I call old school. 100 00:04:56,080 --> 00:05:02,080 When you go to AWS or GCP, or those big tech conglomerates in Europe and America, 103 00:05:02,080 --> 00:05:04,080 they have a lot to offer, and not just compute. 104 00:05:04,640 --> 00:05:06,640 They offer load balancers, 105 00:05:06,640 --> 00:05:08,640 managed databases, manage Kubernetes. 106 00:05:08,640 --> 00:05:10,640 So much stuff. 107 00:05:10,640 --> 00:05:14,640 S3. Do we have S3 in Mauritius? 109 00:05:14,640 --> 00:05:18,640 In Mauritius, we have VPS, basically only. 111 00:05:18,640 --> 00:05:20,640 It's very expensive. 112 00:05:20,640 --> 00:05:22,640 If anyone here has ever tried a hobby project 113 00:05:22,640 --> 00:05:26,640 on cloud.mu or looked at MyT's offerings, it's expensive. 115 00:05:26,640 --> 00:05:28,640 Even accounting for the fact 116 00:05:28,640 --> 00:05:30,640 that hardware around the world 117 00:05:30,640 --> 00:05:32,640 is more expensive nowadays, 118 00:05:32,640 --> 00:05:34,640 it's very, very bad. 119 00:05:34,640 --> 00:05:36,640 So a lot of companies, because of that, 120 00:05:36,640 --> 00:05:38,640 instead of going towards 121 00:05:38,640 --> 00:05:40,640 cloud offerings, they'll 122 00:05:40,640 --> 00:05:44,640 prefer to run Windows VMs on VMware on prem. 124 00:05:44,640 --> 00:05:48,640 And there's many things wrong with that statement. 126 00:05:48,640 --> 00:05:52,640 Local CSPs, at least at the time I was writing this, 128 00:05:52,640 --> 00:05:54,640 I think it's changed since, 129 00:05:54,640 --> 00:06:00,640 they still rely heavily on humans 132 00:06:00,640 --> 00:06:04,640 When I wanted a VPS at CloudMU 134 00:06:04,640 --> 00:06:06,640 I had to 135 00:06:06,640 --> 00:06:08,640 do the payment. It was approved, I think, 136 00:06:08,640 --> 00:06:10,640 manually, and then a guy had to actually 137 00:06:10,640 --> 00:06:12,640 provision the VM. 138 00:06:12,640 --> 00:06:14,640 I don't think it's like that anymore, but... 139 00:06:16,640 --> 00:06:18,640 [audience]: not like that anymore. 140 00:06:18,640 --> 00:06:20,640 It was like that very recently. 141 00:06:20,640 --> 00:06:22,640 But with this kind of small-scale approach 142 00:06:22,640 --> 00:06:25,640 and attitude that we're taking towards infrastructure, it 144 00:06:26,640 --> 00:06:28,640 is never going to compare to hyperscalers 145 00:06:28,640 --> 00:06:31,640 Even compared to Europe we're nothing 147 00:06:31,640 --> 00:06:34,640 And Europe as well, they have OVH and Hetzner 148 00:06:34,640 --> 00:06:38,640 are still nothing compared to AWS and GCP 150 00:06:38,640 --> 00:06:42,640 And yeah, as I mentioned, I do cloud-native stuff, Kubernetes. 152 00:06:42,640 --> 00:06:44,640 Cloud-native takes the backbench, we don't 153 00:06:44,640 --> 00:06:48,640 talk about cloud-native here, we still do Windows VMs, Linux VMs. 155 00:06:48,640 --> 00:06:50,640 That's the offering. 156 00:06:50,640 --> 00:06:52,640 So I wanted to change that. 157 00:06:52,640 --> 00:06:56,640 Another problem is the connectivity. I mean, we've 159 00:06:56,640 --> 00:06:58,640 had problems in the past, haven't we? 160 00:06:58,640 --> 00:07:00,640 We had SAFE which got broken, we had 161 00:07:00,640 --> 00:07:03,640 some on the west side of Africa which got broken. 162 00:07:03,640 --> 00:07:04,640 Another one which got 163 00:07:04,640 --> 00:07:06,640 broken around, what was it, 164 00:07:06,640 --> 00:07:10,640 between Madagascar and somewhere. 166 00:07:10,640 --> 00:07:12,640 It's bad. 167 00:07:12,640 --> 00:07:14,640 And another thing I was doing when I was researching 168 00:07:14,640 --> 00:07:16,640 this whole topic 169 00:07:16,640 --> 00:07:18,640 is that bandwidth is surprisingly expensive. 170 00:07:18,640 --> 00:07:22,640 Everyone here has home internet, right? 172 00:07:22,640 --> 00:07:27,640 At home, it's 200 Mbps download, 30 Mbps upload. 174 00:07:27,640 --> 00:07:32,640 Now, of course, you don't get 200 download, 30 upload to Europe or America. 177 00:07:32,640 --> 00:07:36,640 But just that speed alone, I think it's 179 00:07:36,640 --> 00:07:40,640 2000-ish rupees a month, so let's say 40-ish euros. 181 00:07:40,640 --> 00:07:42,640 I have friends, they were telling me 182 00:07:42,640 --> 00:07:46,640 "Yeah Alex, well I have 8 gigabit internet at home." 184 00:07:46,640 --> 00:07:49,640 8 gigabits! And he pays 80 euros a month. 186 00:07:50,640 --> 00:07:52,640 It's insane just how little 187 00:07:52,640 --> 00:07:54,640 internet capacity we have. 188 00:07:54,640 --> 00:07:56,640 So yeah, Mauritius has the 189 00:07:56,640 --> 00:08:00,640 "SAFE" undersea cable as our main connection 191 00:08:00,640 --> 00:08:02,640 to the rest of the world. 192 00:08:02,640 --> 00:08:07,640 And so, as I mentioned when those cables got damaged, 194 00:08:07,640 --> 00:08:10,640 we had huge latency spikes to Europe. 196 00:08:10,640 --> 00:08:12,640 US was inaccessible. I couldn't watch 197 00:08:12,640 --> 00:08:14,640 YouTube, you couldn't watch Netflix, it was awful. 198 00:08:14,640 --> 00:08:18,640 We had to go outside, look at the sun and touch grass. 200 00:08:18,640 --> 00:08:20,640 But, yeah, 201 00:08:20,640 --> 00:08:22,640 Sorry? 202 00:08:22,640 --> 00:08:24,640 Oh, 203 00:08:24,640 --> 00:08:26,640 [audience member touches ground] carpet, doesn't count 205 00:08:28,640 --> 00:08:32,640 And yeah, I wanted to have symmetric 1 gigabit, just symmetric! 207 00:08:32,640 --> 00:08:34,640 And you don't have that offering on home plans. 208 00:08:34,640 --> 00:08:38,640 You've got to go with business plans and that costs a fortune. 210 00:08:38,640 --> 00:08:43,640 Okay, so why am I complaining? I do a lot of complaining these days. 212 00:08:43,640 --> 00:08:46,640 I complain in my last talk, I'm complaining again 214 00:08:46,640 --> 00:08:48,640 I'm complaining because a lack of local infrastructure means that we 215 00:08:48,640 --> 00:08:52,640 depend a lot on foreign systems and companies 217 00:08:52,640 --> 00:08:54,640 [someone walks in] Hello, there's plenty of space in front for you. 218 00:08:56,640 --> 00:09:00,640 [he's dressed very well] Sorry, you look like someone important, do you work for MyT by any chance? 220 00:09:00,640 --> 00:09:02,640 Guy From MyT: Yes! [audience laughs] 221 00:09:04,640 --> 00:09:08,640 Nobody tell him what we were talking about before he arrived 223 00:09:08,640 --> 00:09:10,640 Pleasure to have you. 224 00:09:10,640 --> 00:09:12,640 Sorry, I like to engage 225 00:09:12,640 --> 00:09:15,640 with the audience, hopefully you'll find me funny 227 00:09:15,640 --> 00:09:18,640 Alright, so! A lack of local infrastructure means high 228 00:09:18,640 --> 00:09:22,640 dependency on foreign systems and companies 230 00:09:22,640 --> 00:09:24,640 Yeah, I don't even have to elaborate, we're all familiar with this. 231 00:09:24,640 --> 00:09:28,640 Push to cloud, a lot of companies and even the government, possibly, 233 00:09:28,640 --> 00:09:32,640 went with things like AWS, GCP, which 235 00:09:32,640 --> 00:09:34,640 if we go back a few slides, 236 00:09:34,640 --> 00:09:36,640 all the way here in South Africa. 237 00:09:36,640 --> 00:09:38,640 And then we've got an undersea cable 238 00:09:38,640 --> 00:09:42,640 joining us right now, so... problem 240 00:09:42,640 --> 00:09:44,640 Owning our data and our infrastructure 241 00:09:44,640 --> 00:09:48,640 is very important nowadays, given geopolitical tensions. 243 00:09:48,640 --> 00:09:50,640 I mean, there's certain presidents 244 00:09:50,640 --> 00:09:54,640 somewhere around the world who are crazy. 246 00:09:54,640 --> 00:09:56,640 And that causes problems for us, because 247 00:09:56,640 --> 00:09:58,640 one day they'll be like: 248 00:09:58,640 --> 00:10:00,640 "Oh, I want Diego Garcia, I'm going to put tariffs, 249 00:10:00,640 --> 00:10:02,640 I'm going to cut off internet, I'm going to do 250 00:10:02,640 --> 00:10:04,640 this, I'm going to do that. 251 00:10:04,640 --> 00:10:06,640 And that was the 252 00:10:06,640 --> 00:10:08,640 case for the ICC, 253 00:10:08,640 --> 00:10:10,640 where they lost access to 254 00:10:10,640 --> 00:10:14,640 their mails to Microsoft 365, and plenty of stuff. 255 00:10:14,640 --> 00:10:16,640 All because the government was like, "we don't like what you're doing". 257 00:10:16,640 --> 00:10:20,640 And at the same time, by outsourcing all of our infrastructure 259 00:10:20,640 --> 00:10:24,640 to, you know, Google Cloud/AWS, we are handicapping 261 00:10:24,640 --> 00:10:26,640 both local companies and local talent. 262 00:10:26,640 --> 00:10:28,640 And we've got a lot of cool 263 00:10:28,640 --> 00:10:34,640 people here, I mean DevCon's shown you, we've got many cool people in tech. 265 00:10:34,640 --> 00:10:36,640 We should make the most of it, right? 266 00:10:36,640 --> 00:10:40,640 Okay, so a quick detour on sovereign infrastructure. 268 00:10:40,640 --> 00:10:46,640 NextCloud is not a replacement for Google Drive or Microsoft Drive. 271 00:10:46,640 --> 00:10:50,640 OVH and Hetzner, which are European offerings, 273 00:10:50,640 --> 00:10:54,640 they are not even full replacements for the American hyperscalers. 275 00:10:54,640 --> 00:10:58,640 Now, what is a full replacement, a good comparison, is Airbus against Boeing. 277 00:10:58,640 --> 00:11:06,640 Both produce planes, commercial, and Airbus, which is the EU version 281 00:11:06,640 --> 00:11:08,640 appeared much later. It wasn't easy 282 00:11:08,640 --> 00:11:10,640 at all for Airbus to become 283 00:11:10,640 --> 00:11:12,640 a thing, and even nowadays both companies 284 00:11:12,640 --> 00:11:16,640 are having their share of challenges. 286 00:11:16,640 --> 00:11:18,640 What I mean is, Airbus and Boeing have what I would 287 00:11:18,640 --> 00:11:20,640 call feature parity. They both offer the same thing. 289 00:11:22,640 --> 00:11:24,640 Us in tech, we like to compromise 290 00:11:24,640 --> 00:11:26,640 to compromise. We'll say, 291 00:11:26,640 --> 00:11:29,640 We'll say "well, you can't do that, 292 00:11:29,640 --> 00:11:32,640 but it doesn't matter, you can do this other thing instead". 294 00:11:32,640 --> 00:11:34,640 But I want to do *that*. 295 00:11:34,640 --> 00:11:40,640 If I can't get a plane with so many seats from Airbus 298 00:11:40,640 --> 00:11:42,640 Then Airbus is not the same as Boeing. 299 00:11:42,640 --> 00:11:46,640 So replacement is only possible when all the demands, even the 301 00:11:46,640 --> 00:11:48,640 niche ones, are met. I was 302 00:11:48,640 --> 00:11:52,640 talking the other day, there's Microsoft Office 304 00:11:52,640 --> 00:11:54,640 People say, "just use Libreoffice. It's the same thing, isn't it?" 305 00:11:54,640 --> 00:11:58,640 Except we've got decades of technical debt, things like 307 00:11:58,640 --> 00:12:00,640 HR payrolls, which are still working on 308 00:12:00,640 --> 00:12:04,640 mail merge, made for Microsoft Word 2000. 310 00:12:04,640 --> 00:12:10,640 I'm not that old to know those technologies, so, you know, just take my word for it. 313 00:12:10,640 --> 00:12:14,640 Back in 2024, I gave a workshop at Devcon. 315 00:12:14,640 --> 00:12:16,640 It was in Port Louis, not here. 317 00:12:16,640 --> 00:12:21,640 It was for Kubernetes, because I like doing Kubernetes, I want to 318 00:12:21,640 --> 00:12:24,640 teach more people about cloud-native technologies. 319 00:12:24,640 --> 00:12:26,640 So I ran that workshop on Kubernetes, and, 321 00:12:26,640 --> 00:12:28,640 attendees participated on many things, 322 00:12:28,640 --> 00:12:30,640 laptops, tablets, and phones, 323 00:12:30,640 --> 00:12:32,640 which means you had a cocktail 324 00:12:32,640 --> 00:12:34,640 of operating systems, Windows, 325 00:12:34,640 --> 00:12:38,640 macOS, Linux, Android, iOS, Apple's tablet... 327 00:12:38,640 --> 00:12:40,640 You get the gist. 328 00:12:40,640 --> 00:12:42,640 So many different flavors, 329 00:12:42,640 --> 00:12:44,640 and even within Linux, you've got 330 00:12:44,640 --> 00:12:46,640 Arch, you've got Ubuntu, you've got 331 00:12:46,640 --> 00:12:50,640 Gentoo, so many choices, right? 333 00:12:50,640 --> 00:12:52,640 And workshops, they need consistent 334 00:12:52,640 --> 00:12:54,640 environments, because I can't have all of you 335 00:12:54,640 --> 00:12:56,640 come to a workshop someday, with your 336 00:12:56,640 --> 00:12:58,640 laptops, and we're going to spend an hour debugging. 337 00:12:58,640 --> 00:13:00,640 Why is it working on his laptop, 338 00:13:00,640 --> 00:13:02,640 but not his? Is the firewall a problem? 339 00:13:02,640 --> 00:13:04,640 You use UFW, you use 340 00:13:04,640 --> 00:13:06,640 firewalld, the commands are going to be different. 341 00:13:06,640 --> 00:13:08,640 So at the end of the day, I said, well, 342 00:13:08,640 --> 00:13:12,640 the cloud was needed, but at what cost? 344 00:13:12,640 --> 00:13:14,640 I wanted to have a look at running 345 00:13:14,640 --> 00:13:16,640 a cloud. 346 00:13:16,640 --> 00:13:20,640 Well, here are my options, okay? 348 00:13:20,640 --> 00:13:22,640 Proxmox, it's an easy 349 00:13:22,640 --> 00:13:24,640 and very free way to run VMs. 350 00:13:24,640 --> 00:13:26,640 You've got the option of cloud VMs, 351 00:13:26,640 --> 00:13:28,640 which, I mean, they're VMs, 352 00:13:28,640 --> 00:13:30,640 so they're kind of expensive. At the time, 353 00:13:30,640 --> 00:13:32,640 there was cloud.mu. 354 00:13:32,640 --> 00:13:34,640 Another one was a shared 355 00:13:34,640 --> 00:13:36,640 Kubernetes cluster, so everyone 356 00:13:36,640 --> 00:13:38,640 who was attending would 357 00:13:38,640 --> 00:13:40,640 maybe have their own namespace with their own service 358 00:13:40,640 --> 00:13:42,640 account, and you'd have 359 00:13:42,640 --> 00:13:44,640 role based access control to split them 360 00:13:44,640 --> 00:13:46,640 apart, so I can't delete 361 00:13:46,640 --> 00:13:48,640 someone else's workload, for example. 362 00:13:48,640 --> 00:13:52,640 And that year I had been at Kubecon in France, 364 00:13:52,640 --> 00:13:54,640 and the another of people, they gave 365 00:13:54,640 --> 00:13:56,640 a workshop on their platform 366 00:13:56,640 --> 00:13:58,640 called HobbyFarm, which gave me a lot of 367 00:13:58,640 --> 00:14:00,640 inspiration for this project. 368 00:14:00,640 --> 00:14:02,640 It was an entire lab platform, 369 00:14:02,640 --> 00:14:04,640 free and open source, 370 00:14:04,640 --> 00:14:06,640 self-hostable, 371 00:14:06,640 --> 00:14:08,640 but the only downside is, even though it's 372 00:14:08,640 --> 00:14:10,640 self-hostable, it still relied on stuff like 373 00:14:10,640 --> 00:14:12,640 AWS or DigitalOcean, 374 00:14:12,640 --> 00:14:14,640 which means it's not free. 375 00:14:14,640 --> 00:14:16,640 And for the workshop, 376 00:14:16,640 --> 00:14:18,640 there were like 50 people, so if I 377 00:14:18,640 --> 00:14:20,640 want to have a Kubernetes cluster 378 00:14:20,640 --> 00:14:22,640 per person, then we're looking at 3 VMs 379 00:14:22,640 --> 00:14:24,640 per person, 150 VMs, 380 00:14:24,640 --> 00:14:26,640 and I don't have any money by the end of it. 381 00:14:28,640 --> 00:14:30,640 So my question at the end of the day was 382 00:14:30,640 --> 00:14:32,640 how do we build a cloud? And finally 383 00:14:32,640 --> 00:14:34,640 we get into the central topic. 384 00:14:34,640 --> 00:14:36,640 So, what is a 385 00:14:36,640 --> 00:14:38,640 cloud? Well, cloud 386 00:14:38,640 --> 00:14:40,640 is someone else's computer. 387 00:14:40,640 --> 00:14:42,640 Everyone's heard this, it's a recurring 388 00:14:42,640 --> 00:14:44,640 joke. Let me elaborate 389 00:14:44,640 --> 00:14:46,640 on it a little bit more. You've got isolation, 390 00:14:46,640 --> 00:14:48,640 so the different users 391 00:14:48,640 --> 00:14:50,640 must still stay separate 392 00:14:50,640 --> 00:14:52,640 and unable to interact. I can't see someone 393 00:14:52,640 --> 00:14:54,640 else's database, I can't log in as someone else, 394 00:14:54,640 --> 00:14:56,640 you know, needs to be isolated. 395 00:14:56,640 --> 00:14:58,640 Cloud, so someone else's computer, 396 00:14:58,640 --> 00:15:00,640 someone else's hardware, you don't manage 397 00:15:00,640 --> 00:15:02,640 that hardware in-house yourself. 398 00:15:02,640 --> 00:15:04,640 And then, my 399 00:15:04,640 --> 00:15:06,640 personal thing is, it has to be automated. 400 00:15:06,640 --> 00:15:08,640 Everything must run without 401 00:15:08,640 --> 00:15:10,640 human intervention, so I can be 402 00:15:10,640 --> 00:15:12,640 sick, I can be on holiday, and nothing's going 403 00:15:12,640 --> 00:15:14,640 to break. I'm not gonna get a call and say 404 00:15:14,640 --> 00:15:16,640 yeah, well, I need to provision a new VM. 405 00:15:18,640 --> 00:15:20,640 By cutting the human out of the loop, 406 00:15:20,640 --> 00:15:22,640 I don't need someone like me on standby 407 00:15:22,640 --> 00:15:24,640 24-7, it will 408 00:15:24,640 --> 00:15:26,640 run without human intervention, it will be 409 00:15:26,640 --> 00:15:28,640 easily scaled. 410 00:15:32,640 --> 00:15:34,640 Finally, I've decided I'm going 411 00:15:34,640 --> 00:15:36,640 to make a cloud. I've got 412 00:15:36,640 --> 00:15:38,640 to look now, do I want to do VMs, 413 00:15:38,640 --> 00:15:40,640 like virtual private servers, or 414 00:15:40,640 --> 00:15:42,640 containers? And remember, I'm 415 00:15:42,640 --> 00:15:44,640 approaching this from the perspective of someone who does a lot of 416 00:15:44,640 --> 00:15:46,640 cloud native. I do Kubernetes 417 00:15:46,640 --> 00:15:48,640 every day. So I have 418 00:15:48,640 --> 00:15:50,640 an allergy to virtual machines. 419 00:15:50,640 --> 00:15:52,640 They're heavy, you've got stuff like 420 00:15:52,640 --> 00:15:54,640 hardware emulation, 421 00:15:54,640 --> 00:15:56,640 each VM has its own 422 00:15:56,640 --> 00:15:58,640 kernel, has its own OS, it's a waste 423 00:15:58,640 --> 00:16:00,640 of space. Anyone here who uses 424 00:16:00,640 --> 00:16:02,640 Windows? 425 00:16:04,640 --> 00:16:06,640 Alright. 426 00:16:06,640 --> 00:16:08,640 Any Windows. 427 00:16:08,640 --> 00:16:10,640 You just open task manager, you see 428 00:16:10,640 --> 00:16:12,640 at idle, it's eating half your RAM, 429 00:16:12,640 --> 00:16:14,640 your CPU's spiking, your battery doesn't 430 00:16:14,640 --> 00:16:16,640 last very long, you're gonna cry. 431 00:16:16,640 --> 00:16:18,640 Stuff like that. 434 00:16:22,640 --> 00:16:24,640 Containers on the other hand, they're small, 435 00:16:24,640 --> 00:16:26,640 they're lightweight, and they scale very fast. 436 00:16:26,640 --> 00:16:28,640 That being said, 437 00:16:28,640 --> 00:16:30,640 VMs having separate kernels 438 00:16:30,640 --> 00:16:32,640 means they're most, yeah. 439 00:16:42,640 --> 00:16:44,640 *audience question about running containers in VMs* 439 00:16:42,640 --> 00:16:44,640 You'll see my logic, my reasoning 440 00:16:44,640 --> 00:16:46,640 in a minute. So yeah, VMs 441 00:16:46,640 --> 00:16:48,640 at the end of the day, they're more secure, 442 00:16:48,640 --> 00:16:50,640 you get better isolation. 443 00:16:50,640 --> 00:16:52,640 Containers, 444 00:16:52,640 --> 00:16:54,640 you can share networking and 445 00:16:54,640 --> 00:16:56,640 storage much more easily 446 00:16:56,640 --> 00:16:58,640 by having many small containers. 447 00:16:58,640 --> 00:17:02,640 The room is very full, I mean it's stressful 449 00:17:02,640 --> 00:17:06,640 audience: You're lucky, the other session is not happening. 451 00:17:06,640 --> 00:17:08,640 Hi everyone, we are Trash Talking 452 00:17:08,640 --> 00:17:10,640 local cloud service providers and building our own. 453 00:17:10,640 --> 00:17:12,640 There's a guy from MyT here, 454 00:17:12,640 --> 00:17:14,640 he scares me. 455 00:17:14,640 --> 00:17:16,640 So yeah, thank you. 456 00:17:16,640 --> 00:17:18,640 There's space in front, 457 00:17:18,640 --> 00:17:20,640 a few more seats. 458 00:17:20,640 --> 00:17:22,640 Containers, you can share networking and storage 459 00:17:22,640 --> 00:17:24,640 much more easily than with VMs. 460 00:17:24,640 --> 00:17:26,640 And containers at the end of the day are cloud native-first. 461 00:17:26,640 --> 00:17:28,640 Your question, ask it 462 00:17:28,640 --> 00:17:30,640 to me at the end. 463 00:17:30,640 --> 00:17:32,640 Now, all of this 464 00:17:32,640 --> 00:17:34,640 is good, I still wanted Kubernetes. 465 00:17:34,640 --> 00:17:36,640 So I discovered this thing 466 00:17:36,640 --> 00:17:38,640 called Virtual Clusters. 467 00:17:38,640 --> 00:17:40,640 Maybe you're familiar with Kubernetes 468 00:17:40,640 --> 00:17:42,640 in Docker; "KinD". 469 00:17:42,640 --> 00:17:44,640 You might be running microk8s or something 470 00:17:44,640 --> 00:17:46,640 locally on your laptop, dev 471 00:17:46,640 --> 00:17:48,640 environments and stuff, it's really cool. 472 00:17:48,640 --> 00:17:50,640 Perfect for testing, 473 00:17:50,640 --> 00:17:52,640 but again, I don't want people to install things 474 00:17:52,640 --> 00:17:54,640 on their laptops. That's not the cloud. 475 00:17:54,640 --> 00:17:56,640 Virtual Clusters on the other hand, 476 00:17:56,640 --> 00:17:58,640 they can be deployed to an existing Kubernetes 477 00:17:58,640 --> 00:18:02,640 cluster, and you have Kubernetes in Kubernetes 479 00:18:02,640 --> 00:18:04,640 At the time of me writing this, there are two main options, 480 00:18:04,640 --> 00:18:06,640 there's VCluster, 481 00:18:06,640 --> 00:18:08,640 Virtual Cluster, from a company called Loftlabs, 482 00:18:08,640 --> 00:18:10,640 another one called K3K from 483 00:18:10,640 --> 00:18:12,640 the Rancher and Suse People. 484 00:18:12,640 --> 00:18:14,640 I'm already a fan of the Rancher and Suse people 485 00:18:14,640 --> 00:18:16,640 because I run K3S at home, 486 00:18:16,640 --> 00:18:18,640 there's rke2, there's a lot of 487 00:18:18,640 --> 00:18:20,640 nice things in that ecosystem. 488 00:18:20,640 --> 00:18:22,640 So, yeah. 489 00:18:22,640 --> 00:18:24,640 Let's have a quick talk about K3K and 490 00:18:24,640 --> 00:18:26,640 vCluster. 491 00:18:26,640 --> 00:18:28,640 There's space in front, in the middle. 492 00:18:28,640 --> 00:18:30,640 You provision Virtual 493 00:18:30,640 --> 00:18:32,640 Clusters on a host. 494 00:18:32,640 --> 00:18:34,640 These Virtual Clusters are going to live in their own 495 00:18:34,640 --> 00:18:36,640 pods containers for the 496 00:18:36,640 --> 00:18:38,640 un-initiated. 497 00:18:40,640 --> 00:18:42,640 Since you escaped from the other talk, 498 00:18:42,640 --> 00:18:44,640 anyone here who does not know 499 00:18:44,640 --> 00:18:46,640 Kubernetes or Cloud Native... 500 00:18:46,640 --> 00:18:48,640 Oh, come on. 501 00:18:48,640 --> 00:18:50,640 You can raise your hand. I'm not going to judge. 502 00:18:50,640 --> 00:18:52,640 Okay, a few 503 00:18:52,640 --> 00:18:54,640 raised hands. Kubernetes is 504 00:18:54,640 --> 00:18:56,640 a framework for running distributed 505 00:18:56,640 --> 00:18:58,640 compute. You can have many servers, 506 00:18:58,640 --> 00:19:00,640 physical servers, which are clustered together. 507 00:19:00,640 --> 00:19:02,640 By clustering them together, 508 00:19:02,640 --> 00:19:04,640 you can just say, I want to run 509 00:19:04,640 --> 00:19:06,640 maybe Nginx. I want to run 510 00:19:06,640 --> 00:19:08,640 my website. And it will just throw 511 00:19:08,640 --> 00:19:10,640 that workload onto your physical 512 00:19:10,640 --> 00:19:12,640 servers. You can have as many 513 00:19:12,640 --> 00:19:14,640 physical servers as you want, which 514 00:19:14,640 --> 00:19:16,640 means that if I were to unplug one of them, 515 00:19:16,640 --> 00:19:18,640 your server is still going to stay 516 00:19:18,640 --> 00:19:20,640 working. And Cloud Native 517 00:19:20,640 --> 00:19:22,640 is... 518 00:19:26,640 --> 00:19:28,640 I'll just show the landscape. 519 00:19:28,640 --> 00:19:30,640 So, the CNCF is 520 00:19:30,640 --> 00:19:32,640 a branch of the Linux Foundation. 521 00:19:32,640 --> 00:19:34,640 CNCF stands for Cloud Native Computing Foundation. 522 00:19:34,640 --> 00:19:38,640 They are the branch which does a lot of 524 00:19:38,640 --> 00:19:40,640 Cloud Native stuff. But what does 525 00:19:40,640 --> 00:19:42,640 Cloud Native mean? It's everything 526 00:19:42,640 --> 00:19:44,640 built Cloud-first. 527 00:19:44,640 --> 00:19:46,640 So, the whole 528 00:19:46,640 --> 00:19:48,640 ecosystem kind of revolves around 529 00:19:48,640 --> 00:19:50,640 Kubernetes. Not strictly, but that's the 530 00:19:50,640 --> 00:19:52,640 reality. And you have a bunch 531 00:19:52,640 --> 00:19:54,640 of projects, 532 00:19:54,640 --> 00:19:56,640 which... Let's just filter by CNCF 533 00:19:56,640 --> 00:19:58,640 projects here. All of these 534 00:19:58,640 --> 00:20:00,640 projects are open source stuff. 535 00:20:00,640 --> 00:20:02,640 A lot of it is written in Go, so Go developers 536 00:20:02,640 --> 00:20:04,640 have stuff for you to do. 537 00:20:06,640 --> 00:20:08,640 You've got 538 00:20:08,640 --> 00:20:10,640 applications which are 539 00:20:10,640 --> 00:20:12,640 pre-written for managing basically 540 00:20:12,640 --> 00:20:14,640 everything. If you want to have 541 00:20:14,640 --> 00:20:16,640 massive, I really mean 542 00:20:16,640 --> 00:20:18,640 insanely huge databases, you've got 543 00:20:18,640 --> 00:20:20,640 things like Vitess. I think 544 00:20:20,640 --> 00:20:22,640 YouTube runs off Vitess. 545 00:20:22,640 --> 00:20:24,640 Very big stuff, but very complicated 546 00:20:24,640 --> 00:20:26,640 as well. If you want to do 547 00:20:26,640 --> 00:20:28,640 storage, you've got stuff like Rook 548 00:20:28,640 --> 00:20:30,640 and Ceph, Longhon, 549 00:20:30,640 --> 00:20:32,640 you've got networking stuff. 550 00:20:32,640 --> 00:20:34,640 This is a whole ecosystem, 551 00:20:34,640 --> 00:20:36,640 what you call Cloud Native, which is 552 00:20:36,640 --> 00:20:38,640 a bunch of 553 00:20:38,640 --> 00:20:40,640 free and open source projects which work together. 554 00:20:40,640 --> 00:20:42,640 They do really cool stuff. 555 00:20:42,640 --> 00:20:44,640 From my perspective, I'm an organizer of 556 00:20:44,640 --> 00:20:46,640 Cloud Native Mauritius, it's 557 00:20:46,640 --> 00:20:48,640 the future, at least, if not the present, 558 00:20:48,640 --> 00:20:52,640 of infrastructure and servers 560 00:20:54,640 --> 00:20:56,640 It's been that for 10 years, it's still not the thing in Mauritius. 561 00:20:56,640 --> 00:20:58,640 Anyways, 562 00:20:58,640 --> 00:21:00,640 back on track. 563 00:21:00,640 --> 00:21:02,640 Thank you, whoever raised their 564 00:21:02,640 --> 00:21:04,640 hands, because plenty of people didn't, and I know 565 00:21:04,640 --> 00:21:06,640 they don't know Kubernetes. 566 00:21:06,640 --> 00:21:08,640 Stop being shy, I won't bite you. 567 00:21:08,640 --> 00:21:10,640 I will laugh at you. 568 00:21:10,640 --> 00:21:12,640 Virtual clusters live in pods, 569 00:21:12,640 --> 00:21:14,640 the containers on your host 570 00:21:14,640 --> 00:21:16,640 cluster, and will expose 571 00:21:16,640 --> 00:21:18,640 the API server for people to work 572 00:21:18,640 --> 00:21:20,640 with. You've got the option 573 00:21:20,640 --> 00:21:22,640 to pass through host resources, stuff 574 00:21:22,640 --> 00:21:24,640 like storage class, ingress class, 575 00:21:24,640 --> 00:21:26,640 configmap, secrets... If you're not familiar 576 00:21:26,640 --> 00:21:30,640 with all of this, Kubernetes is a great thing to learn 578 00:21:30,640 --> 00:21:32,640 These are all, you know, like configuration 579 00:21:32,640 --> 00:21:34,640 or other facilities 580 00:21:34,640 --> 00:21:36,640 like when I showed the 581 00:21:36,640 --> 00:21:38,640 landscape of earlier. 582 00:21:38,640 --> 00:21:40,640 Virtual clusters, they are isolated across 583 00:21:40,640 --> 00:21:42,640 different namespaces, so 584 00:21:42,640 --> 00:21:44,640 it helps keep things a bit more secure. There's 585 00:21:44,640 --> 00:21:48,640 a space in front for the newcomers 587 00:21:48,640 --> 00:21:50,640 Okay, so there's some other Cloud Native tech 588 00:21:50,640 --> 00:21:52,640 that I use for my project of 589 00:21:52,640 --> 00:21:54,640 building a Cloud at home. 590 00:21:54,640 --> 00:21:56,640 There's Longhorn, it does 591 00:21:56,640 --> 00:21:58,640 distributed and low resource 592 00:21:58,640 --> 00:22:00,640 intensive storage, 593 00:22:00,640 --> 00:22:02,640 so I can replicate storage across my servers. 594 00:22:02,640 --> 00:22:04,640 At the block level, if I do 595 00:22:04,640 --> 00:22:06,640 a write to a volume on one server, 596 00:22:06,640 --> 00:22:08,640 it will be replicated to another. 597 00:22:08,640 --> 00:22:10,640 And this is great because if that server dies, 598 00:22:10,640 --> 00:22:12,640 your data is safe. 599 00:22:12,640 --> 00:22:14,640 And we had an incident at work recently. 600 00:22:14,640 --> 00:22:16,640 Bad stuff. Data's fine, 601 00:22:16,640 --> 00:22:18,640 but yeah. 602 00:22:18,640 --> 00:22:20,640 You've got Traefik. 603 00:22:20,640 --> 00:22:22,640 You can also think of Nginx. Nginx 604 00:22:22,640 --> 00:22:24,640 Ingress got deprecated recently. 605 00:22:24,640 --> 00:22:26,640 But Traefik is an Ingress class. 606 00:22:26,640 --> 00:22:28,640 It does Gateway API. 607 00:22:28,640 --> 00:22:30,640 And for those of you who may not 608 00:22:30,640 --> 00:22:32,640 be in the Cloud Native world, 609 00:22:32,640 --> 00:22:34,640 it's sort of like a reverse proxy. 610 00:22:34,640 --> 00:22:36,640 I've got Cert Manager. 611 00:22:36,640 --> 00:22:38,640 Cert Manager is a really cool tool 612 00:22:38,640 --> 00:22:40,640 to automatically provision TLS certs, 613 00:22:40,640 --> 00:22:42,640 at least in my case it's from Let's Encrypt. 614 00:22:42,640 --> 00:22:46,640 And finally, the glue which holds everything together, 616 00:22:46,640 --> 00:22:48,640 the foundation of the whole stack, is 617 00:22:48,640 --> 00:22:50,640 K3S, my choice of Kubernetes. 618 00:22:50,640 --> 00:22:52,640 Much like you have 619 00:22:52,640 --> 00:22:54,640 Linux, which exists as Red Hat Linux, 620 00:22:54,640 --> 00:22:56,640 Suse Linux, 621 00:22:56,640 --> 00:22:58,640 Ubuntu, Arch, 622 00:22:58,640 --> 00:23:00,640 etc. You also have flavors 623 00:23:00,640 --> 00:23:02,640 of Kubernetes. So I chose 624 00:23:02,640 --> 00:23:04,640 K3S. It's nice and lightweight. 625 00:23:04,640 --> 00:23:06,640 Okay. 626 00:23:06,640 --> 00:23:08,640 Getting a bit closer 627 00:23:08,640 --> 00:23:10,640 to my actual project. So my actual 628 00:23:10,640 --> 00:23:12,640 project is called KRaft, not the 629 00:23:12,640 --> 00:23:14,640 cheese. I'm not good 630 00:23:14,640 --> 00:23:16,640 at naming. I will take name suggestions 631 00:23:16,640 --> 00:23:18,640 if anyone has any good ones. 632 00:23:18,640 --> 00:23:20,640 KRaft, I named it like this. The K is 633 00:23:20,640 --> 00:23:22,640 for Kubernetes. And 634 00:23:22,640 --> 00:23:24,640 KRaft, as in to craft, 635 00:23:24,640 --> 00:23:26,640 means to build stuff, 636 00:23:26,640 --> 00:23:28,640 to do stuff, and then 637 00:23:28,640 --> 00:23:30,640 yeah. I don't 638 00:23:30,640 --> 00:23:32,640 know. Give me better names, guys. 639 00:23:32,640 --> 00:23:34,640 So it's a 640 00:23:34,640 --> 00:23:36,640 combination of Rust and Static HTML. 641 00:23:36,640 --> 00:23:38,640 I'm not a front-end developer. 642 00:23:38,640 --> 00:23:40,640 There are some front-end developers among us. 643 00:23:40,640 --> 00:23:42,640 They'll say that my website 644 00:23:42,640 --> 00:23:44,640 might look ugly. 645 00:23:44,640 --> 00:23:46,640 But the main magic 646 00:23:46,640 --> 00:23:48,640 is the Rust backend. 647 00:23:48,640 --> 00:23:50,640 I chose Rust because I wanted an excuse to write 648 00:23:50,640 --> 00:23:52,640 in Rust. I like the language and I don't like 649 00:23:52,640 --> 00:23:54,640 GO. That's offensive to some people 650 00:23:54,640 --> 00:23:56,640 as well. Anyways, 651 00:23:56,640 --> 00:23:58,640 triggering everyone in the room. 652 00:23:58,640 --> 00:24:00,640 So the backend, it handles 653 00:24:00,640 --> 00:24:02,640 everything from authentication, cluster 654 00:24:02,640 --> 00:24:04,640 creation, workspaces. I'll get to that 655 00:24:04,640 --> 00:24:06,640 in a minute. It's really cool. And 656 00:24:06,640 --> 00:24:08,640 basically the entire lifecycle of your virtual 657 00:24:08,640 --> 00:24:10,640 clusters. The front-end 658 00:24:10,640 --> 00:24:12,640 itself is a UI for people to 659 00:24:12,640 --> 00:24:14,640 go clicky clicky because I know not everyone lives 660 00:24:14,640 --> 00:24:16,640 in a terminal. You like the website, 661 00:24:16,640 --> 00:24:18,640 you go click, click, click. It works for 662 00:24:18,640 --> 00:24:20,640 you. The Rust side is 663 00:24:20,640 --> 00:24:22,640 built on Actix Web. And this was 664 00:24:22,640 --> 00:24:24,640 built a long time ago when I was still learning 665 00:24:24,640 --> 00:24:26,640 about Rust, so it's not perfect. 666 00:24:26,640 --> 00:24:28,640 Actix Web is 667 00:24:28,640 --> 00:24:30,640 a small framework, a bit like 668 00:24:30,640 --> 00:24:32,640 Flask for those familiar with 669 00:24:32,640 --> 00:24:34,640 Python development. And 670 00:24:34,640 --> 00:24:38,640 it's very bare bones and gives you the 672 00:24:38,640 --> 00:24:40,640 possibility to customize a lot of things. 673 00:24:40,640 --> 00:24:42,640 Because it's so bare bones, I wrote my own 674 00:24:42,640 --> 00:24:44,640 authentication. It's 675 00:24:44,640 --> 00:24:46,640 probably vulnerable. 676 00:24:46,640 --> 00:24:48,640 Please pentest it. PRs welcome. 677 00:24:48,640 --> 00:24:50,640 And lastly, I've got 678 00:24:50,640 --> 00:24:52,640 resource handling. This is not 679 00:24:52,640 --> 00:24:54,640 yet something I've 680 00:24:54,640 --> 00:24:56,640 opened up. I wanted the possibilities 681 00:24:56,640 --> 00:24:58,640 of managing resources, 682 00:24:58,640 --> 00:25:00,640 monitoring cluster use, and 683 00:25:00,640 --> 00:25:02,640 so that I know who is eating all the 684 00:25:02,640 --> 00:25:04,640 RAM on my server because RAM's expensive, guys. 685 00:25:04,640 --> 00:25:06,640 The resource 686 00:25:06,640 --> 00:25:08,640 handling actually what it does is reads the metrics 687 00:25:08,640 --> 00:25:10,640 server and then puts it in a nice 688 00:25:10,640 --> 00:25:12,640 format for the UI. 689 00:25:12,640 --> 00:25:14,640 Okay. 690 00:25:14,640 --> 00:25:16,640 Oh, I was supposed to replace this. 691 00:25:18,640 --> 00:25:20,640 Let's see, let's see, let's see. 692 00:25:24,640 --> 00:25:26,640 Let's see. Does this work? 693 00:25:28,640 --> 00:25:30,640 It works. Great. 694 00:25:32,640 --> 00:25:34,640 So this was the old stuff. 695 00:25:34,640 --> 00:25:36,640 I had separated the authentication, 696 00:25:36,640 --> 00:25:38,640 the cluster management, 697 00:25:38,640 --> 00:25:40,640 the resource management. These are all 698 00:25:40,640 --> 00:25:42,640 three separate things. 699 00:25:42,640 --> 00:25:44,640 And you'll notice I did these two in Rust 700 00:25:44,640 --> 00:25:46,640 and then I went with Python and Flask 701 00:25:46,640 --> 00:25:48,640 for the last one because I got lazy. 702 00:25:48,640 --> 00:25:50,640 And if you're not in my Rust 703 00:25:50,640 --> 00:25:52,640 talk, I just want to point out, these two do 704 00:25:52,640 --> 00:25:54,640 most of the work. They use 10 megs of RAM. 705 00:25:54,640 --> 00:25:56,640 This one uses 300 megs of RAM. 706 00:25:56,640 --> 00:25:58,640 It makes me sad. So that's why 707 00:25:58,640 --> 00:26:00,640 you'll see between this old 708 00:26:00,640 --> 00:26:02,640 screenshot and now, you'll see 709 00:26:02,640 --> 00:26:04,640 the Python thing's not here anymore. It all got 710 00:26:04,640 --> 00:26:06,640 rewritten into KRaft Core. 711 00:26:06,640 --> 00:26:08,640 12 MB of RAM, guys. 712 00:26:08,640 --> 00:26:10,640 And I'm sure it will 713 00:26:10,640 --> 00:26:12,640 that your Kubernetes cluster will 714 00:26:12,640 --> 00:26:14,640 time out 715 00:26:14,640 --> 00:26:16,640 before my program does. 716 00:26:16,640 --> 00:26:18,640 Okay. 717 00:26:18,640 --> 00:26:20,640 Along the road, I made 718 00:26:20,640 --> 00:26:22,640 this crate. So crate is like a package 719 00:26:22,640 --> 00:26:24,640 called k3k-rs. 720 00:26:24,640 --> 00:26:26,640 In the whole 721 00:26:26,640 --> 00:26:28,640 cloud native landscape, Rust is not 722 00:26:28,640 --> 00:26:30,640 the first choice. Go is. 723 00:26:30,640 --> 00:26:32,640 By that being said, there is this 724 00:26:32,640 --> 00:26:34,640 project called kube-rs. It's 725 00:26:34,640 --> 00:26:36,640 a crate (package) for 726 00:26:36,640 --> 00:26:38,640 interacting with Kubernetes resources directly 727 00:26:38,640 --> 00:26:40,640 from Rust. It's an actually 728 00:26:40,640 --> 00:26:42,640 approved, like CNCF approved thing. 730 00:26:44,640 --> 00:26:46,640 I wanted to re-implement 731 00:26:46,640 --> 00:26:48,640 those k3k CRDs, 732 00:26:48,640 --> 00:26:50,640 so custom resources, 733 00:26:50,640 --> 00:26:52,640 into Rust structs. 734 00:26:52,640 --> 00:26:54,640 So like classes, if you 735 00:26:54,640 --> 00:26:56,640 are from an object-oriented perspective. 736 00:26:56,640 --> 00:26:58,640 So that I would benefit from 737 00:26:58,640 --> 00:27:00,640 type safety and 738 00:27:00,640 --> 00:27:02,640 many other features that Rust provides. 739 00:27:02,640 --> 00:27:04,640 It should have been at my other talk if you wanted to 740 00:27:04,640 --> 00:27:06,640 know more about it. 741 00:27:06,640 --> 00:27:08,640 So k3k-rs, it's 742 00:27:08,640 --> 00:27:10,640 an off-shoot project which re-implements all 743 00:27:10,640 --> 00:27:14,640 the CRDs of the main k3k project 745 00:27:14,640 --> 00:27:16,640 And has plenty of convenience functions to 746 00:27:16,640 --> 00:27:18,640 manage those resources. 747 00:27:18,640 --> 00:27:20,640 I believe I have, yes, 748 00:27:20,640 --> 00:27:22,640 I have. 749 00:27:22,640 --> 00:27:24,640 So this is two lines of code. 750 00:27:24,640 --> 00:27:26,640 Let client, client, 751 00:27:26,640 --> 00:27:28,640 try default.await. 752 00:27:28,640 --> 00:27:30,640 All this does is create a 753 00:27:30,640 --> 00:27:32,640 client to interact with the Kubernetes API. 754 00:27:32,640 --> 00:27:34,640 And then the second one, 755 00:27:34,640 --> 00:27:36,640 let list. It's a 756 00:27:36,640 --> 00:27:38,640 list of clusters. 757 00:27:38,640 --> 00:27:40,640 You just list clusters in 758 00:27:40,640 --> 00:27:42,640 the namespace and you pass the namespace to it. 759 00:27:42,640 --> 00:27:44,640 So in two lines I've reduced 760 00:27:44,640 --> 00:27:46,640 what would be a lot of manual work - 761 00:27:46,640 --> 00:27:48,640 maybe you're re-implementing stuff into 762 00:27:48,640 --> 00:27:50,640 just these two lines. 763 00:27:50,640 --> 00:27:52,640 And I know a lot of you 764 00:27:52,640 --> 00:27:54,640 maybe don't do Rust. It's a bit of a niche language. 765 00:27:54,640 --> 00:27:56,640 That's why I like it, I guess. 766 00:27:56,640 --> 00:28:00,640 This is YAML in Rust 768 00:28:00,640 --> 00:28:02,640 You can probably read most 769 00:28:02,640 --> 00:28:04,640 of this even if you're not a Rust person. 770 00:28:04,640 --> 00:28:06,640 All the way at the top here, 771 00:28:06,640 --> 00:28:08,640 I'm just defining a cluster schema. 772 00:28:08,640 --> 00:28:10,640 And it's a type of 773 00:28:10,640 --> 00:28:12,640 k3krs cluster. It's a cluster type 774 00:28:12,640 --> 00:28:16,640 with some metadata. It's got a name, 776 00:28:16,640 --> 00:28:18,640 test cluster, a namespace which is 777 00:28:18,640 --> 00:28:20,640 k3k namespace. And the rest is just 778 00:28:20,640 --> 00:28:22,640 default. In the spec itself 779 00:28:22,640 --> 00:28:24,640 you just define things, for example you've got 780 00:28:24,640 --> 00:28:26,640 servers. 781 00:28:26,640 --> 00:28:28,640 Servers 1, agent 0. 782 00:28:28,640 --> 00:28:30,640 Commented out because those are defaults, 783 00:28:30,640 --> 00:28:34,640 but your entire YAML file is now just in Rust. 785 00:28:34,640 --> 00:28:36,640 And it will also tell you, for example 786 00:28:36,640 --> 00:28:38,640 if you pass a string instead of an 787 00:28:38,640 --> 00:28:40,640 integer as port it will tell you 788 00:28:40,640 --> 00:28:42,640 and refuse to compile. 789 00:28:42,640 --> 00:28:44,640 So that's some cool stuff. 790 00:28:46,640 --> 00:28:48,640 Now UI people in the audience 791 00:28:48,640 --> 00:28:50,640 behold my ugly creation 792 00:28:50,640 --> 00:28:52,640 while I drink some water. 794 00:29:00,640 --> 00:29:02,640 I'll sound less like Kermit the frog now. 795 00:29:02,640 --> 00:29:04,640 So this is the 796 00:29:04,640 --> 00:29:08,640 UI I made. It's very rudimentary. 798 00:29:08,640 --> 00:29:12,640 You can see that I do infrastructure because it's very functional. 800 00:29:12,640 --> 00:29:14,640 Create a cluster, view clusters, 801 00:29:14,640 --> 00:29:16,640 read me and your account. That's all you need. 802 00:29:16,640 --> 00:29:20,640 Has anyone here used AWS? Have you logged into 804 00:29:20,640 --> 00:29:22,640 the console? Have you seen all the options 805 00:29:22,640 --> 00:29:24,640 and have you nearly cried and said 806 00:29:24,640 --> 00:29:26,640 I want to go work on a farm, I don't want to 807 00:29:26,640 --> 00:29:28,640 do tech anymore. 808 00:29:28,640 --> 00:29:30,640 I went through that as well. 809 00:29:30,640 --> 00:29:32,640 So that's the landing page. 810 00:29:32,640 --> 00:29:34,640 You have an account. 811 00:29:34,640 --> 00:29:36,640 The dummyuser 812 00:29:36,640 --> 00:29:38,640 you've got passwords, you can set 813 00:29:38,640 --> 00:29:40,640 your password, you can delete your account. 814 00:29:40,640 --> 00:29:42,640 What more do you need? 815 00:29:42,640 --> 00:29:44,640 It's GDPR compliant by the way. 816 00:29:44,640 --> 00:29:46,640 You delete this, it deletes everything. 817 00:29:48,640 --> 00:29:50,640 I won't keep anything about you. 818 00:29:50,640 --> 00:29:52,640 Okay, in terms of 819 00:29:52,640 --> 00:29:54,640 creating a cluster. 820 00:29:54,640 --> 00:29:56,640 Ah, funny name. 821 00:29:56,640 --> 00:29:58,640 You just pass the cluster name and then 822 00:29:58,640 --> 00:30:00,640 if you want a custom domain attached 823 00:30:00,640 --> 00:30:02,640 to your cluster, you'll pass up as a TLS-SAN here. 824 00:30:02,640 --> 00:30:06,640 So the certificates will be generated accordingly. 826 00:30:06,640 --> 00:30:08,640 So here I just named the cluster help me 827 00:30:08,640 --> 00:30:10,640 and then you click submit and it's done. 828 00:30:10,640 --> 00:30:12,640 Guys, do you have any idea how complicated 829 00:30:12,640 --> 00:30:14,640 it is to go through like the cloud 830 00:30:14,640 --> 00:30:16,640 providers' consoles and not 831 00:30:16,640 --> 00:30:18,640 shoot yourself in the foot with bad configuration? 832 00:30:18,640 --> 00:30:20,640 Here it's simple. You give a name, 833 00:30:20,640 --> 00:30:22,640 you say submit. It's fine. 834 00:30:22,640 --> 00:30:24,640 So then you 835 00:30:24,640 --> 00:30:26,640 have view clusters. So I've got 836 00:30:26,640 --> 00:30:28,640 a test cluster, I've got one for 837 00:30:28,640 --> 00:30:30,640 cloud native community. It gives you the name, 838 00:30:30,640 --> 00:30:32,640 an endpoint and the kubeconfig for you to 839 00:30:32,640 --> 00:30:34,640 download. For those 840 00:30:34,640 --> 00:30:36,640 not familiar with Kubernetes, the kubeconfig 841 00:30:36,640 --> 00:30:40,640 is a file with certificates and stuff which 843 00:30:40,640 --> 00:30:42,640 is what authenticates you with the server 844 00:30:42,640 --> 00:30:46,640 for you to do things with Kubernetes 846 00:30:46,640 --> 00:30:50,640 Another really cool thing is 848 00:30:50,640 --> 00:30:52,640 you can view the cluster, sure, 849 00:30:52,640 --> 00:30:54,640 and you also have cluster logs. So you can 850 00:30:54,640 --> 00:30:56,640 get logs from your cluster right in your browser. 851 00:30:56,640 --> 00:30:58,640 You can copy it, you can refresh it, 852 00:30:58,640 --> 00:31:00,640 stuff like that. You get all your information. 853 00:31:00,640 --> 00:31:02,640 So example, this is the server logs 854 00:31:02,640 --> 00:31:04,640 you can just see here and if anything 855 00:31:04,640 --> 00:31:06,640 is out of the ordinary. 856 00:31:06,640 --> 00:31:08,640 It's right there. 857 00:31:08,640 --> 00:31:10,640 And workspaces. 858 00:31:10,640 --> 00:31:12,640 This is something I'm really, really proud of. 859 00:31:12,640 --> 00:31:18,640 When I was done with the whole virtual cluster side of things, 861 00:31:18,640 --> 00:31:20,640 I was like, great! 862 00:31:20,640 --> 00:31:22,640 Your cluster will live on the cloud, 863 00:31:22,640 --> 00:31:24,640 ie my servers, 864 00:31:24,640 --> 00:31:26,640 and all you have to do is install kubectl, 865 00:31:26,640 --> 00:31:28,640 the command line tool, 866 00:31:26,640 --> 00:31:30,640 on your own laptop, and done! 868 00:31:31,640 --> 00:31:33,640 That's all you have to do. 869 00:31:33,640 --> 00:31:35,640 You only have to install kubectl. 870 00:31:35,640 --> 00:31:38,640 Then I was like, you still have to install kubectl, 871 00:31:38,640 --> 00:31:40,640 and I don't want people to have to go through that 873 00:31:40,640 --> 00:31:44,640 Because, it is still a platform dependent thing. 875 00:31:44,640 --> 00:31:46,640 You might want autocomplete, you might want 876 00:31:46,640 --> 00:31:48,640 some nicer features. 877 00:31:48,640 --> 00:31:50,640 And then all of that will need more configuration 878 00:31:50,640 --> 00:31:52,640 on your end. So workspaces 879 00:31:52,640 --> 00:31:54,640 is a terminal in your browser 880 00:31:54,640 --> 00:31:58,640 which comes with all the utilities, everything, 882 00:31:58,640 --> 00:32:00,640 all the command line tools that you would like to have. 883 00:32:00,640 --> 00:32:04,640 So you can see here, this is a workspace right here. 885 00:32:04,640 --> 00:32:06,640 It is in the browser. It's running 886 00:32:06,640 --> 00:32:08,640 just bash in the browser basically. There's kubectl 887 00:32:08,640 --> 00:32:10,640 kubecolor, which gives 888 00:32:10,640 --> 00:32:12,640 some nice colors to your stuff. 889 00:32:12,640 --> 00:32:14,640 k9s, for those familiar with Kubernetes, it's a nice 890 00:32:14,640 --> 00:32:16,640 UI to manage your stuff. Of course 891 00:32:16,640 --> 00:32:20,640 you get git, fish, wget, vim, iputils, 893 00:32:20,640 --> 00:32:22,640 stuff for you to debug your 894 00:32:22,640 --> 00:32:24,640 cluster and work with it. 895 00:32:24,640 --> 00:32:26,640 And so other nice things you have, you have alias 896 00:32:26,640 --> 00:32:28,640 k for kubectl 898 00:32:30,640 --> 00:32:32,640 That's a... 899 00:32:32,640 --> 00:32:34,640 It's a necessity. 900 00:32:34,640 --> 00:32:36,640 Because sometimes I'm going to go to a terminal 901 00:32:36,640 --> 00:32:38,640 and type k, it's not found and 902 00:32:38,640 --> 00:32:40,640 I'm annoyed. You also have kubectl 903 00:32:40,640 --> 00:32:44,640 with autocompletion, another nice thing. 905 00:32:44,640 --> 00:32:46,640 And the way I made this workspace is actually kind of neat 906 00:32:46,640 --> 00:32:48,640 because initially I made 907 00:32:48,640 --> 00:32:50,640 a Dockerfile as one does. 908 00:32:50,640 --> 00:32:52,640 And it was just installing 909 00:32:52,640 --> 00:32:54,640 packages. I installed fish, I installed kubectl, 910 00:32:54,640 --> 00:32:56,640 I added the files 911 00:32:56,640 --> 00:32:58,640 or changed some config files. 912 00:32:58,640 --> 00:33:00,640 And I was like, but there's other ways of doing this. 913 00:33:00,640 --> 00:33:02,640 This is actually the first time I 914 00:33:02,640 --> 00:33:04,640 experimented with making 915 00:33:04,640 --> 00:33:06,640 containers with Nix. 916 00:33:06,640 --> 00:33:08,640 Because in Nix, I just had to specify 917 00:33:08,640 --> 00:33:10,640 all the packages I wanted and some of the configuration 918 00:33:10,640 --> 00:33:12,640 and the welcome message 919 00:33:12,640 --> 00:33:14,640 and it just creates the container for me. 920 00:33:14,640 --> 00:33:16,640 I'd send a talk about 921 00:33:16,640 --> 00:33:18,640 nix containers. It's still a bit advanced 922 00:33:18,640 --> 00:33:20,640 for my level, but it works. 923 00:33:20,640 --> 00:33:22,640 And 924 00:33:22,640 --> 00:33:24,640 yeah, so you can run 925 00:33:24,640 --> 00:33:26,640 neofetch. The container itself 926 00:33:26,640 --> 00:33:30,640 is built on Suse containers. 928 00:33:30,640 --> 00:33:32,640 You can see the host, this is my actual host, the kernel. 929 00:33:32,640 --> 00:33:34,640 This is probably vulnerable to 930 00:33:34,640 --> 00:33:36,640 at least 10 of the vulnerabilities discovered 931 00:33:36,640 --> 00:33:38,640 in the last week, right? We've got AI, 932 00:33:38,640 --> 00:33:41,640 everyone's finding vulnerabilities in the kernel these days. 934 00:33:42,640 --> 00:33:44,640 Copyfail definitely would work. 935 00:33:44,640 --> 00:33:46,640 So yeah, you get the packages. 936 00:33:46,640 --> 00:33:48,640 Shell is bash, you also have fish. I'm a fish person. 937 00:33:48,640 --> 00:33:52,640 And, you have some other stats listed. 939 00:33:52,640 --> 00:33:56,640 So that's workspaces for you! 941 00:33:56,640 --> 00:33:58,640 And recently I realized I 942 00:33:58,640 --> 00:34:00,640 was doing all my admin work from the terminal. 943 00:34:00,640 --> 00:34:02,640 I ran a workshop with the Cloud Native 944 00:34:02,640 --> 00:34:04,640 people not that long ago. 945 00:34:04,640 --> 00:34:06,640 And I said, well, 946 00:34:06,640 --> 00:34:08,640 it's not cool because the cleanup - 947 00:34:08,640 --> 00:34:10,640 I've got to do it manually. So instead, 948 00:34:10,640 --> 00:34:12,640 let's have an admin view so you can view 949 00:34:12,640 --> 00:34:14,640 all your users. E-mails obviously 950 00:34:14,640 --> 00:34:16,640 not shown by default. 951 00:34:16,640 --> 00:34:18,640 You have beta codes, 952 00:34:18,640 --> 00:34:20,640 so, I'm giving codes out to 953 00:34:20,640 --> 00:34:22,640 close friends to break my stuff. 954 00:34:22,640 --> 00:34:24,640 They haven't broken much yet. Clifford? 955 00:34:24,640 --> 00:34:26,640 You haven't broken it yet? 957 00:34:28,640 --> 00:34:34,640 Some other beta codes, none of these are enabled anymore. 960 00:34:34,640 --> 00:34:36,640 You can try. 961 00:34:38,640 --> 00:34:40,640 So 962 00:34:40,640 --> 00:34:42,640 I mentioned at the beginning the requirements 963 00:34:42,640 --> 00:34:44,640 for Cloud is to keep everyone isolated, 964 00:34:44,640 --> 00:34:46,640 keep everyone safe. So a major 965 00:34:46,640 --> 00:34:48,640 focus has also been on keeping your 966 00:34:48,640 --> 00:34:50,640 workloads safe. Users, for starters, 967 00:34:50,640 --> 00:34:52,640 will interact only with their virtual APIs, 968 00:34:52,640 --> 00:34:55,640 with isolated ETCD 969 00:34:55,640 --> 00:34:56,640 ETCD being the data store 970 00:34:56,640 --> 00:34:58,640 for Kubernetes, for those unfamiliar. 971 00:34:58,640 --> 00:35:00,640 Which also means that you're 972 00:35:00,640 --> 00:35:02,640 not, you can never 973 00:35:02,640 --> 00:35:04,640 have the same ETCD 974 00:35:04,640 --> 00:35:06,640 data store as someone 975 00:35:06,640 --> 00:35:08,640 else using the platform. 976 00:35:08,640 --> 00:35:10,640 Clusters themselves are separated by 977 00:35:10,640 --> 00:35:12,640 namespace within Kubernetes, 978 00:35:12,640 --> 00:35:14,640 isolated through network policies. So your 979 00:35:16,640 --> 00:35:18,640 workloads can't reach workloads 980 00:35:18,640 --> 00:35:20,640 from other people, nor can they reach other devices 981 00:35:20,640 --> 00:35:22,640 on my home network. 982 00:35:22,640 --> 00:35:24,640 Don't worry Ma, everything's safe. 983 00:35:24,640 --> 00:35:26,640 Secured by pod security 984 00:35:26,640 --> 00:35:28,640 admission level, so you can 985 00:35:28,640 --> 00:35:30,640 have unrestricted 986 00:35:30,640 --> 00:35:32,640 baseline restricted. 987 00:35:32,640 --> 00:35:34,640 And then each cluster has its own core DNS. 988 00:35:34,640 --> 00:35:40,640 So another cool separation thing. 991 00:35:40,640 --> 00:35:42,640 Virtual cluster policies is another 992 00:35:42,640 --> 00:35:44,640 thing. And don't worry, I'm nearly done with 993 00:35:44,640 --> 00:35:46,640 technical stuff. They give me a lot more 994 00:35:46,640 --> 00:35:48,640 control over these K3K clusters and 995 00:35:48,640 --> 00:35:50,640 resources by letting me implement resource 996 00:35:50,640 --> 00:35:52,640 quotas, so nobody's going to eat all my RAM. 997 00:35:52,640 --> 00:35:54,640 Default resource limits, 998 00:35:54,640 --> 00:35:56,640 and requests. Again, so you don't eat all my RAM. 999 00:35:56,640 --> 00:35:58,640 Allowed mode. 1000 00:35:58,640 --> 00:36:00,640 What does that one do again? Oh, 1001 00:36:00,640 --> 00:36:02,640 you can have shared clusters. 1002 00:36:02,640 --> 00:36:04,640 So right now this is running in shared, which means 1003 00:36:04,640 --> 00:36:06,640 you'll still use 1004 00:36:06,640 --> 00:36:10,640 my host's ingress, my host's storage layer. 1006 00:36:10,640 --> 00:36:12,640 You don't have to install that yourself. It's ready to 1007 00:36:12,640 --> 00:36:14,640 go out of the box like you'd expect, you know, 1008 00:36:14,640 --> 00:36:16,640 with AWS or similar. 1009 00:36:16,640 --> 00:36:18,640 So what resources 1010 00:36:18,640 --> 00:36:20,640 to sync? Again, I have ingress and 1011 00:36:20,640 --> 00:36:22,640 storage being synced across. 1012 00:36:22,640 --> 00:36:24,640 Pod security admission level. 1014 00:36:26,640 --> 00:36:28,640 Anyway, priority class. 1015 00:36:28,640 --> 00:36:30,640 Some of these configs 1016 00:36:30,640 --> 00:36:32,640 isn't really needed, but yeah. You have max 1017 00:36:32,640 --> 00:36:34,640 resource limits or requests because 1018 00:36:34,640 --> 00:36:36,640 RAM is expensive, guys. 1019 00:36:36,640 --> 00:36:40,640 And you can disable network policy, but I'm not doing that 1021 00:36:40,640 --> 00:36:42,640 A while ago I 1022 00:36:42,640 --> 00:36:44,640 had a friend, she helped me 1023 00:36:44,640 --> 00:36:46,640 test it out. This was in the very early days. 1024 00:36:46,640 --> 00:36:50,640 And I gave her a beta code. 1026 00:36:50,640 --> 00:36:52,640 She named the cluster 1027 00:36:52,640 --> 00:36:54,640 something like, helpmeplease. 1028 00:36:54,640 --> 00:36:56,640 She downloaded 1029 00:36:56,640 --> 00:36:58,640 the kubeconfig, so you can see 1030 00:36:58,640 --> 00:37:00,640 export kubeconfig here, and then 1031 00:37:00,640 --> 00:37:02,640 got the nodes, and was like, it's alive!! 1032 00:37:02,640 --> 00:37:04,640 Very surprised because obviously 1033 00:37:04,640 --> 00:37:06,640 my stuff is not expected to work, right? 1034 00:37:06,640 --> 00:37:08,640 I was also surprised because I 1035 00:37:08,640 --> 00:37:10,640 expected my stuff to not work. 1036 00:37:10,640 --> 00:37:12,640 You can see. She said, I'm so 1037 00:37:12,640 --> 00:37:14,640 surprised. I have no faith in myself. It's right. 1038 00:37:14,640 --> 00:37:16,640 We found some fun 1039 00:37:16,640 --> 00:37:18,640 bugs together, like 1040 00:37:18,640 --> 00:37:20,640 you get a 200 response, but it still says 1041 00:37:20,640 --> 00:37:22,640 an error occurred somewhere. 1042 00:37:22,640 --> 00:37:24,640 And finally, 1043 00:37:24,640 --> 00:37:26,640 at midnight, so I wasn't there when she witnessed 1044 00:37:26,640 --> 00:37:28,640 the thing happen, she said, wow, listen. 1045 00:37:28,640 --> 00:37:30,640 It's not covered by TLS 1046 00:37:30,640 --> 00:37:32,640 and there's HSTS, but 1047 00:37:32,640 --> 00:37:34,640 it actually works. And she said 1048 00:37:34,640 --> 00:37:36,640 she's impressed. I impressed 1049 00:37:36,640 --> 00:37:38,640 someone. 1050 00:37:38,640 --> 00:37:40,640 And a lady. 1051 00:37:40,640 --> 00:37:42,640 I didn't want to say it, 1052 00:37:42,640 --> 00:37:44,640 but I knew someone was going to say it. 1053 00:37:44,640 --> 00:37:46,640 I'm disappointed. 1054 00:37:46,640 --> 00:37:48,640 Okay. 1055 00:37:48,640 --> 00:37:50,640 So there's still some stuff 1056 00:37:50,640 --> 00:37:52,640 in progress. At the 1057 00:37:52,640 --> 00:37:54,640 time I made this, I was waiting on some 1058 00:37:54,640 --> 00:37:56,640 hardware. I needed more disks. 1059 00:37:56,640 --> 00:37:58,640 Those arrived recently. 1060 00:37:58,640 --> 00:38:00,640 Then a rabbit ate my fiber cable. 1061 00:38:00,640 --> 00:38:02,640 And then MyT generously 1062 00:38:02,640 --> 00:38:04,640 came to replace the fiber cable. 1063 00:38:04,640 --> 00:38:06,640 Thank you. There's a 1064 00:38:06,640 --> 00:38:08,640 Helm chart on the way to deploy 1065 00:38:08,640 --> 00:38:10,640 Kraft easily so that 1066 00:38:10,640 --> 00:38:12,640 you can host your own cloud service provider 1067 00:38:12,640 --> 00:38:14,640 from your own computer. 1068 00:38:14,640 --> 00:38:16,640 Some more hosting features and options. 1069 00:38:16,640 --> 00:38:18,640 Like you see, 1070 00:38:18,640 --> 00:38:20,640 initially I started out by comparing the Airbus 1071 00:38:20,640 --> 00:38:22,640 to Boeing, saying that's the only comparison 1072 00:38:22,640 --> 00:38:24,640 which has feature parity. 1073 00:38:24,640 --> 00:38:26,640 So I want Mauritius to have 1074 00:38:26,640 --> 00:38:28,640 a lot more options. 1075 00:38:28,640 --> 00:38:30,640 S3, someone mentioned 1076 00:38:30,640 --> 00:38:32,640 Cloudflare Pages. You see, 1077 00:38:32,640 --> 00:38:34,640 plenty of features like this which don't exist 1078 00:38:34,640 --> 00:38:36,640 here. You've got to make the hop to 1079 00:38:36,640 --> 00:38:38,640 South Africa for that, at least. 1080 00:38:38,640 --> 00:38:40,640 So yeah, some of those 1081 00:38:40,640 --> 00:38:42,640 features like that, I'd love to have them 1082 00:38:42,640 --> 00:38:44,640 integrated as well. 1083 00:38:44,640 --> 00:38:46,640 I wanted to make my own 1084 00:38:46,640 --> 00:38:48,640 virtual cluster solution because I found limitations 1085 00:38:48,640 --> 00:38:50,640 in K3K. And it's in Go. 1086 00:38:50,640 --> 00:38:52,640 I can't contribute to it. 1087 00:38:52,640 --> 00:38:55,640 So I'm like, I'm gonna rewrite it in Rust! 1088 00:38:55,640 --> 00:38:56,640 [silence] 1089 00:38:56,640 --> 00:38:58,640 Nobody's laughing. 1090 00:38:58,640 --> 00:39:00,640 Some backup and 1091 00:39:00,640 --> 00:39:02,640 restore because backing up data is 1092 00:39:02,640 --> 00:39:04,640 useful. And yeah, some 1093 00:39:04,640 --> 00:39:06,640 annoying K3K bugs which I'm still 1094 00:39:06,640 --> 00:39:08,640 working through. 1095 00:39:08,640 --> 00:39:10,640 So yeah, that's it from me. 1096 00:39:10,640 --> 00:39:12,640 Here's my website, Telegram 1097 00:39:12,640 --> 00:39:14,640 and Mastodon. 1098 00:39:14,640 --> 00:39:16,640 So if you want to reach out, I'll be around the convenience 1100 00:39:22,640 --> 00:39:24,640 I risk not getting a yellow card today. 1101 00:39:24,640 --> 00:39:27,640 I'm very proud of it. Pleased and proud of myself 1102 00:39:27,640 --> 00:39:28,640 So yeah, does anyone have any questions or comments? 1104 00:39:30,640 --> 00:39:32,640 Alex, you are 1105 00:39:32,640 --> 00:39:34,640 insane. 1106 00:39:34,640 --> 00:39:36,640 Yes. Oh No. 1107 00:39:38,640 --> 00:39:40,640 Ish: He's going to buy it from you. 1108 00:39:42,640 --> 00:39:44,640 Ish: He's got a lot of money. Let's talk later. 1109 00:39:46,640 --> 00:39:49,640 MyT: So why not using something like OKD4 and then build on that? 1110 00:39:49,640 --> 00:39:52,640 MyT: It already has a lot of stuff. 1112 00:39:52,640 --> 00:39:56,640 I'm not familiar. I've never heard of OKD4 1114 00:39:58,640 --> 00:40:00,640 Clifford: This room last year. 1115 00:40:00,640 --> 00:40:02,640 Sorry? 1116 00:40:02,640 --> 00:40:04,640 Clifford: OKD is an upstream project for OpenShift. 1118 00:40:06,640 --> 00:40:08,640 Oh, OpenShift! 1119 00:40:08,640 --> 00:40:10,640 Ish: Upstream. 1120 00:40:10,640 --> 00:40:12,640 Clifford: The community version, yes. 1121 00:40:12,640 --> 00:40:14,640 Yes. Well, I mean, you have 1122 00:40:14,640 --> 00:40:16,640 the choice. 1123 00:40:16,640 --> 00:40:18,640 When I was making this, I 1124 00:40:18,640 --> 00:40:20,640 had a bad 1125 00:40:20,640 --> 00:40:22,640 taste in my mouth from Red Hat. 1126 00:40:22,640 --> 00:40:24,640 Well, not Red Hat in particular, but 1127 00:40:24,640 --> 00:40:26,640 very American-aligned companies. 1128 00:40:28,640 --> 00:40:30,640 Clifford: I mean, it's open source. 1129 00:40:30,640 --> 00:40:32,640 Yeah, improved on it. 1130 00:40:32,640 --> 00:40:34,640 Maybe. 1131 00:40:34,640 --> 00:40:36,640 But you've got plenty of options. Actually, 1132 00:40:36,640 --> 00:40:38,640 it's not specific to 1133 00:40:38,640 --> 00:40:40,640 your underlying Kubernetes distribution. 1134 00:40:40,640 --> 00:40:42,640 You can run K3S, rke2, 1135 00:40:42,640 --> 00:40:44,640 OpenShift, plain KubeADM . 1136 00:40:44,640 --> 00:40:46,640 Anything will work. 1137 00:40:46,640 --> 00:40:48,640 So I wanted to keep it as open 1138 00:40:48,640 --> 00:40:50,640 as possible. 1139 00:40:50,640 --> 00:40:52,640 That good? 1140 00:40:52,640 --> 00:40:54,640 PR, is that alright? 1141 00:40:54,640 --> 00:40:56,640 Yes. 1142 00:40:56,640 --> 00:40:59,640 Joki: "Do you offer it as a container" 1144 00:40:59,640 --> 00:41:02,640 "so that somebody that sets up a Homelab could just" 1145 00:41:02,640 --> 00:41:06,640 "run it as a host instantly?" 1147 00:41:06,640 --> 00:41:10,640 "Like, supporting you, that we get redundancy" 1150 00:41:12,640 --> 00:41:14,640 "about, your Homelab, 20 other Homelabs?" 1151 00:41:16,640 --> 00:41:18,640 Spreading homelabs is not a thing 1152 00:41:18,640 --> 00:41:20,640 I've considered. It still just matters 1153 00:41:20,640 --> 00:41:22,640 about the host Kubernetes there. 1154 00:41:22,640 --> 00:41:24,640 So if you want to join your nodes 1155 00:41:24,640 --> 00:41:26,640 to my cluster, then 1156 00:41:26,640 --> 00:41:28,640 that would work as redundancy. 1157 00:41:28,640 --> 00:41:32,640 Joki: "You're maybe even having replication" 1159 00:41:32,640 --> 00:41:34,640 "between different, you know," 1160 00:41:34,640 --> 00:41:36,640 "like creating a zone." 1161 00:41:38,640 --> 00:41:40,640 Yes... You see, Ish, I'm going to retire from 1162 00:41:40,640 --> 00:41:44,640 La Sentinelle. I'm just going to end up working on this full-time. 1164 00:41:46,640 --> 00:41:48,640 But another thing on the self-hosting 1165 00:41:48,640 --> 00:41:50,640 thing is there's a Helm chart, so 1166 00:41:50,640 --> 00:41:52,640 most of the stuff are 1167 00:41:52,640 --> 00:41:56,640 just right here as Helm templates. 1169 00:41:56,640 --> 00:41:58,640 So even if you're not part of my cluster 1170 00:41:58,640 --> 00:42:00,640 you can still run it on your own. 1171 00:42:00,640 --> 00:42:02,640 Joki: "I would, but it's easy to run" 1172 00:42:02,640 --> 00:42:06,640 "I mean, the thing is what are the necessary steps" 1174 00:42:06,640 --> 00:42:10,640 "to set up my own Homelab with the same setup." 1178 00:42:14,640 --> 00:42:16,640 "So you install on a host system, install KRaft, and have those templates." 1181 00:42:20,640 --> 00:42:22,640 It's very simple. You install 1182 00:42:22,640 --> 00:42:24,640 Kubernetes on your host, then you do Helm install 1183 00:42:24,640 --> 00:42:26,640 and you point to this repository. 1184 00:42:26,640 --> 00:42:28,640 You have some 1185 00:42:28,640 --> 00:42:30,640 sensible defaults for values here. You just 1186 00:42:30,640 --> 00:42:32,640 customize that and then you're good to go 1188 00:42:34,640 --> 00:42:36,640 Yes? 1189 00:42:36,640 --> 00:42:38,640 Audience: "OKD, you would have" 1190 00:42:38,640 --> 00:42:40,640 "a similar conflict with Kubernetes." 1191 00:42:40,640 --> 00:42:44,640 "There's a specific project that was done" 1193 00:42:44,640 --> 00:42:48,640 "seven years ago that's called Incus that's based on LXC and LXD" 1195 00:42:48,640 --> 00:42:50,640 "That is the exact use case" 1196 00:42:50,640 --> 00:42:52,640 You said several things 1197 00:42:52,640 --> 00:42:55,640 I don't know. So what did you say first of all? 1198 00:42:55,640 --> 00:42:58,640 "So OKD would be similar because it's OpenShift." 1200 00:42:58,640 --> 00:43:00,640 Yeah, that's established. Kubernetes is Kubernetes. 1201 00:43:00,640 --> 00:43:02,640 "The other one is called Incas which is a fork of LXC." 1203 00:43:04,640 --> 00:43:06,640 "INCUS" 1204 00:43:06,640 --> 00:43:08,640 Which is a fork of? 1205 00:43:08,640 --> 00:43:10,640 "which is a fork of LXC." 1206 00:43:10,640 --> 00:43:12,640 "LXC." 1207 00:43:12,640 --> 00:43:14,640 Oh, LXC! 1208 00:43:14,640 --> 00:43:16,640 Linux Containers. 1209 00:43:16,640 --> 00:43:18,640 "Yeah." Okay. 1210 00:43:18,640 --> 00:43:20,640 "I helped on that project" 1211 00:43:20,640 --> 00:43:22,640 "and it was made for security projects" 1212 00:43:22,640 --> 00:43:24,640 "to host the" 1213 00:43:24,640 --> 00:43:26,640 Do we have any Google people in the room? 1214 00:43:26,640 --> 00:43:28,640 There's a problem here. 1215 00:43:28,640 --> 00:43:30,640 Joki: "No, it's the second one." 1216 00:43:30,640 --> 00:43:32,640 Okay, it's fine. I'm sorry. 1219 00:43:36,640 --> 00:43:38,640 "The first Google link." 1220 00:43:38,640 --> 00:43:44,640 "It was made for security and for pen testing entire environments" 1223 00:43:44,640 --> 00:43:46,640 "and so it would be ideal" 1224 00:43:46,640 --> 00:43:48,640 "You wouldn't have to do a lot of hardening" 1225 00:43:48,640 --> 00:43:50,640 "It's made for internet-based" 1226 00:43:50,640 --> 00:43:54,640 "security applications and it's been public for 10 years" 1228 00:43:54,640 --> 00:43:56,640 It's again, not something 1229 00:43:56,640 --> 00:43:58,640 that I've looked into. I wanted to make my own 1230 00:43:58,640 --> 00:44:00,640 solution, but also 1231 00:44:00,640 --> 00:44:02,640 the thing about Kraft is that I did 1232 00:44:02,640 --> 00:44:04,640 just want to make something 1233 00:44:04,640 --> 00:44:06,640 myself. I wanted an excuse to write Rust. 1234 00:44:08,640 --> 00:44:10,640 Ish: "By the way, that" 1235 00:44:10,640 --> 00:44:14,640 "Incus project you say was created by Aleksa Sarai" 1237 00:44:14,640 --> 00:44:16,640 No. 1238 00:44:16,640 --> 00:44:20,640 Ish: "On the page it's written, created by Aleksa Sarai." 1240 00:44:20,640 --> 00:44:24,640 Ish: "You met that guy while he worked at Suse." 1242 00:44:24,640 --> 00:44:26,640 Ish: "You probably forgot his face." 1243 00:44:26,640 --> 00:44:28,640 Definitely. 1244 00:44:28,640 --> 00:44:30,640 Audience: "But it was [unintelligible]" 1245 00:44:30,640 --> 00:44:32,640 Ish: "Yeah, but it was created by that guy, man." 1246 00:44:32,640 --> 00:44:40,640 Ish: "It could have been maintained by Navin Ramgoolam it doesn't matter" 1246 00:44:40,640 --> 00:44:44,640 Ish: "And he had the lucky chance to meet the guy in Germany." 1248 00:44:44,640 --> 00:44:46,640 Ish: "That was the point." 1249 00:44:46,640 --> 00:44:48,640 Alright, so are there any other 1250 00:44:48,640 --> 00:44:50,640 questions people interested 1251 00:44:50,640 --> 00:44:52,640 or, you know, because I 1252 00:44:52,640 --> 00:44:54,640 realize we do have a bit of a non-cloud 1253 00:44:54,640 --> 00:44:56,640 native audience here. So, yeah, 1254 00:44:56,640 --> 00:44:58,640 if anyone's got any questions. Is the next speaker 1255 00:44:58,640 --> 00:45:00,640 in the room? Mum: "Clifford!" 1256 00:45:00,640 --> 00:45:02,640 Oh, that's you! Right, of course. 1257 00:45:02,640 --> 00:45:04,640 Okay, so 1258 00:45:04,640 --> 00:45:06,640 we can keep going. 1259 00:45:06,640 --> 00:45:10,640 Joki: "It's already in my hand" (yellow card for timekeeping) 1261 00:45:10,640 --> 00:45:12,640 Joki: "Not for you, not for you." 1262 00:45:12,640 --> 00:45:14,640 Joki: "would have been, you know, like somebody asking questions." 1264 00:45:16,640 --> 00:45:18,640 Alright, so, any other 1265 00:45:18,640 --> 00:45:20,640 questions of people who are curious? 1266 00:45:20,640 --> 00:45:22,640 There's the Cloud Native 1267 00:45:22,640 --> 00:45:26,640 community, so cloudnativemauritius.com 1269 00:45:30,640 --> 00:45:32,640 cloudnativemauritius.com, long URL, 1270 00:45:32,640 --> 00:45:36,640 ugly website, we are sysadmins, not frontend people 1272 00:45:36,640 --> 00:45:38,640 We have a telegram you can join here. 1273 00:45:38,640 --> 00:45:40,640 We have a matrix server which is 1274 00:45:40,640 --> 00:45:42,640 unmaintained. But, yeah, you can 1275 00:45:42,640 --> 00:45:44,640 see what we're doing over here. 1276 00:45:44,640 --> 00:45:46,640 We've got events coming up if you want to get in touch, 1277 00:45:46,640 --> 00:45:48,640 get involved, 1278 00:45:48,640 --> 00:45:50,640 I'd be happy for you to reach out. 1279 00:45:50,640 --> 00:45:54,640 All good? No more questions? 1281 00:45:58,640 --> 00:46:00,640 Honestly, I'm so disappointed 1282 00:46:00,640 --> 00:46:02,640 we made it in time. Joki, can you give me 1283 00:46:02,640 --> 00:46:04,640 a yellow card just for the sake of it, please? 1284 00:46:04,640 --> 00:46:06,640 Joki: "Fair play, fair play." 1285 00:46:06,640 --> 00:46:08,640 Joki: "All good."