In October 2023, the Rafay team participated at HashiConf 2023 in San Francisco. We had several users ask us last week about our thoughts on the conference itself and things we presented and demonstrated. In this blog, we will briefly describe our learnings and observations from this major conference.
In late Sep 2023, we had the opportunity to speak, present and participate at DevOpsCon 2023 in New York City. In this blog, we will briefly describe what we presented at the conference and our observations about the event itself.
DevOpsCon is a global conference focused on CI/CD, Kubernetes Ecosystem, Agile & Lean Business. If you live outside the United States, you may want to attend one of their conferences in other cities such as Munich, Singapore, London and Berlin.
This year's conference in New York was held at the Marriott near Brooklyn Bridge which is a fantastic location, literally right across from the Brooklyn Bridge and NYU Engineering.
Our goals at this conference were very simple.
Educate the attendees about various approaches for secure access to Kubernetes clusters and their pros/cons.
Attend other sessions, meet practitioners and learn about their challenges and how they are solving these.
In our recent release, we added support for in-place upgrades of your EKS clusters provisioning based on Kubernetes v1.27.
Our customers have shared with us that they would like to provision new EKS clusters using new Kubernetes versions so that they do not have to plan/schedule for Kubernetes upgrades for these clusters right away. As a result, we generally introduce support for new cluster provisioning for the new Kubernetes version first and then follow up with support for zero touch in-place upgrades.
Note
Organizations that wish to perform sophisticated checks for API deprecation etc are strongly recommended to use Rafay's Fleet Operations for Amazon EKS.
Our recent release update adds support for a number of new features and enhancements. This blog is focused on support for Kubernetes v1.28 with Rafay MKS (i.e. upstream Kubernetes for bare metal and VM based environments).
Both new cluster provisioning and in-place upgrades of existing clusters are supported. As with most Kubernetes releases, this version also deprecates and removes a number of features. To ensure there is zero impact to our customers, we have made sure that every feature in the Rafay Kubernetes Operations Platform has been validated on this Kubernetes version.
Azure recently added support for Kubernetes v1.27 for AKS clusters. Customers can now use Rafay to provision new AKS clusters based on Kubernetes v1.27 as well.
This version of AKS was Generally Available (GA) starting July 2023 and go end of life in July 2024 i.e. with a 12 month support runway.
Note
Customers have shared with us that they would like to provision new AKS clusters based on new Kubernetes versions so that they do not have to plan/schedule for Kubernetes upgrades for these clusters right away. For the last few releases, we have introduced support for new cluster provisioning for the new Kubernetes version first and then follow up with support for zero touch in-place upgrades.
In a short few weeks, on 11th Oct, 2023, Kubernetes clusters based on Amazon EKS v1.23 will reach end of support. In this blog, we describe Rafay's reference implementation of a fleet upgrade plan that will help users perform in-place upgrades of their EKS v1.23 clusters to EKS v1.24 with zero risk to application downtime.
The Center for Internet Security (CIS) benchmark for Kubernetes consists of secure configuration guidelines especially for Kubernetes infrastructure set-up. These benchmarks encapsulate best practice security recommendations for configuring Kubernetes to support a strong security posture. The CIS Kubernetes Benchmark is written for the open source, upstream Kubernetes distribution and intended to be as universally applicable across distributions as possible.
In this blog, we describe how our customers perform CIS benchmark scans of their fleet of Kubernetes clusters using Rafay.
Last week, HashiCorp announced that they would be adopting the Business Source License for future releases of its products. In this blog, we describe how and if this impacts Rafay customers.
There is no impact to our mutual customers and users due to this recent license change by HashiCorp.
Many of our customers benefit from our native support of HashiCorp product offerings, such as Terraform and Vault, and our strong partnership ensures that they will continue to do so. In this blog, I'll describe these integrations, and provide more detail on the recent licensing change.
In our recent release, we added support for plugins in the web based kubectl shell that users have access to after they authenticate to their Rafay Org. In this blog, we will describe how we have enhanced the developer experience for users of this feature by providing them with a "grep plugin".
Rafay's zero trust kubectl web shell is one of the most heavily used features by users of the Rafay platform because it provides secure kubectl access to authenticated users from any device from anywhere. They just need a web browser to login and perform kubectl operations on their cluster.
Customers have shared with us that they would like to provision new EKS clusters using new Kubernetes versions so that they do not have to plan/schedule for Kubernetes upgrades for these clusters right away. For the last few releases, we have introduced support for new cluster provisioning for the new Kubernetes version first and then follow up with support for zero touch in-place upgrades.