OM DETTA AVSNITT
Control Plane CEO Doron Grinstein joins me to discuss how they’ve created an AI-native cloud API that virtualizes multi-cloud and hybrid cloud to simplify management and ship faster.
Watch the video of this episode.
🖥️ Watch demos from the live stream.
😇 My new GitHub Security workshop has launched! A free 2-hour workshop with hands-on labs to harden your repos and your workflows from common supply chain attacks. I'll cover how attackers are getting in, and then we'll lock down a sample repo so you know what needs to be done to protect your code. You'll leave with a deep understanding of risks and mitigations as well as a list of helpful tools to keep your repos safe, including my new "gasa" tool for scanning your repos and orgs.
★Show Links★
- https://controlplane.com
- https://docs.controlplane.com/introduction
- get a free month to experiment with. email doron@controlplane.com
Creators & Guests
- Cristi Cotovan - Editor
- Bret Fisher - Host
- Beth Fisher - Producer
- Doron Grinstein - Guest
You can also support this podcast by subscribing to my YouTube channel and my monthly newsletter at bret.news!
Grab the best coupons for my GitHub, Agents, Docker, and Kubernetes courses.
Join my cloud native DevOps community on Discord.
Grab some merch at Bret's Loot Box
Homepage bretfisher.com
- (00:00) - A single API for multicloud with Control Plane
- (04:42) - Introduction: Meet Doron Greenstein
- (09:36) - What Is Control Plane?
- (13:31) - The Union of All Clouds
- (15:25) - Adoption and Onboarding
- (18:59) - Eliminating Infrastructure Toil
- (24:01) - AI Agents in DevOps
- (29:19) - Infrastructure as Code in the Agent Era
- (33:04) - Small Teams and Non-Developers
- (37:35) - Compliance and the Data Problem
- (40:50) - Scaling, Secrets, and Audit Trails
- (44:48) - Cost Efficiency and Getting Started
I DETTA AVSNITT
VISA ANMÄRKNINGAR 🔗
UTSKRIFT 🔗
00:00:00,000 --> 00:00:03,440
Bret (2): were you sorta seeing where
this all could take us in terms of
2
00:00:03,530 --> 00:00:05,040
agents helping us in infrastructure
3
00:00:05,090 --> 00:00:09,540
Doron: we wanted to reduce the
cognitive load on engineers not
4
00:00:09,550 --> 00:00:13,629
having to stitch together Kubernetes,
Istio, Grafana, Prometheus, Vault,
5
00:00:13,630 --> 00:00:15,990
and all the CNCF, solutions out there.
6
00:00:16,090 --> 00:00:23,466
And we created an API that gives you
unified access to any cloud, any service,
7
00:00:23,566 --> 00:00:28,614
and we find that AI, if you just tell it,
"Create me the infrastructure," it's gonna
8
00:00:28,624 --> 00:00:34,104
duplicate a lot of resources: and it's
gonna be expensive, non-deterministic, and
9
00:00:34,104 --> 00:00:36,544
it's gonna be non-secure, non-compliant.
10
00:00:36,644 --> 00:00:40,394
And where is the logging, the metrics,
the tracing, the secrets management,
11
00:00:40,394 --> 00:00:42,484
the service discovery, the TLS, the DNS?
12
00:00:42,484 --> 00:00:44,584
And the list goes on and on.
13
00:00:44,684 --> 00:00:50,097
So what AI needs, just like an engineer
needs, is a reduced cognitive load.
14
00:00:50,117 --> 00:00:53,437
Give it a deterministic API
that says, "Hey, take my
15
00:00:53,437 --> 00:00:55,217
desired state and make it so.
16
00:00:55,317 --> 00:01:00,236
And by the way, make it so on any
cloud." It makes AI a lot more effective.
17
00:01:00,336 --> 00:01:05,026
we find AI in a perfect, intersection
because we can now make it do
18
00:01:05,076 --> 00:01:09,376
tricks that is otherwise very, very
expensive or even u- unattainable
19
00:01:16,105 --> 00:01:18,475
Bret (2): Welcome to another
episode of DevOps & Docker Talk.
20
00:01:18,515 --> 00:01:24,255
I'm your host, Bret, and in this one,
we go deep into the universal control
21
00:01:24,255 --> 00:01:29,595
plane for the cloud and the search for
the singular management system, which
22
00:01:29,695 --> 00:01:34,435
we have been doing my entire 30-year
career, been trying to find that perfect
23
00:01:34,435 --> 00:01:40,615
sweet spot of a tool that can manage
all of my infrastructure from one API.
24
00:01:40,895 --> 00:01:45,385
And what better person to have on
to talk about this than the CEO and
25
00:01:45,385 --> 00:01:50,605
co-founder of Control Plane, the company
building this unified API layer for
26
00:01:50,605 --> 00:01:52,165
controlling all your infrastructure.
27
00:01:52,465 --> 00:01:57,735
I'm having Doron Grinstein on the show,
and we go deep into what they're building,
28
00:01:57,745 --> 00:02:02,675
And he has a very similar story to me,
just trying to use the infrastructure
29
00:02:02,775 --> 00:02:07,275
that we had at the time and the tooling
we had at the time, and I have managed
30
00:02:07,285 --> 00:02:11,355
infrastructure for so long that I have
forgotten about all the tools that we've
31
00:02:11,365 --> 00:02:15,485
tried to use over the years to unify
everything, and we never quite get there.
32
00:02:15,485 --> 00:02:19,965
We get 60%, maybe if you're really
lucky, 80%, but then there's always
33
00:02:19,995 --> 00:02:22,075
that other thing that doesn't quite fit.
34
00:02:22,175 --> 00:02:25,195
And it's exciting to see a company
that's brave enough to take this
35
00:02:25,195 --> 00:02:26,725
on, because it's no small task.
36
00:02:26,735 --> 00:02:31,245
It's no small achievement to be able
to say you have a universal API control
37
00:02:31,245 --> 00:02:36,315
plane that you can access from the
browser or from Terraform or from Pulumi
38
00:02:36,325 --> 00:02:43,035
or from your agent harness, and it feels
like that's what they're achieving.
39
00:02:43,065 --> 00:02:45,005
And we walked through a bunch of demos.
40
00:02:45,005 --> 00:02:47,615
In fact, if you're interested in the
demos, go check out the link in the
41
00:02:47,665 --> 00:02:51,205
show notes to go to the live stream,
'cause we demoed for about an hour
42
00:02:51,215 --> 00:02:54,475
after the conversation, and, we
didn't put those into this podcast.
43
00:02:54,495 --> 00:02:56,865
So if you wanna check out all
those demos, go check the link.
44
00:02:57,215 --> 00:03:00,555
But we talk about everything from
how they onboard customers, what are
45
00:03:00,555 --> 00:03:03,955
their customers looking like in terms
of their infrastructure, and how are
46
00:03:03,955 --> 00:03:05,545
they managing it once they get there.
47
00:03:05,555 --> 00:03:07,155
Surprise, not a lot's changed.
48
00:03:07,165 --> 00:03:10,035
They still use Terraform or OpenTofu.
49
00:03:10,035 --> 00:03:13,865
All the things that they were using
before are compatible with their APIs.
50
00:03:13,875 --> 00:03:18,895
But they also have MCP and CLI tools
to manage this, and once you get into
51
00:03:18,895 --> 00:03:22,355
their interface, you realize that part
of what they can do, because they're
52
00:03:22,355 --> 00:03:26,785
agnostic and they want to operationalize
all of this across multi clouds, is
53
00:03:26,825 --> 00:03:30,265
they're setting up the Kubernetes
distributions across the clouds for you.
54
00:03:30,505 --> 00:03:35,585
They're making the decisions around how
the encrypted tunnels are gonna happen
55
00:03:35,595 --> 00:03:39,085
between the different providers, it
feels kind of like what Docker felt at
56
00:03:39,145 --> 00:03:42,765
first, where they had this old saying
at Docker of, "Batteries included, but
57
00:03:42,765 --> 00:03:46,455
swappable" and that is something that
I feel like I could call control plane.
58
00:03:46,455 --> 00:03:49,135
It feels like it's very easy out
of the box, but they hide a little
59
00:03:49,135 --> 00:03:52,155
bit of that complexity with their
opinionated defaults, which I like
60
00:03:52,155 --> 00:03:55,145
opinionated defaults, especially
when I agree with those opinions.
61
00:03:55,245 --> 00:03:59,665
And we dive into some of their extra
features that they're building on top
62
00:03:59,675 --> 00:04:04,175
of this universal control plane, like
a, a sandboxing approach that is so
63
00:04:04,175 --> 00:04:07,755
popular right now that we have agent
harnesses needing sandboxes, and we're
64
00:04:07,755 --> 00:04:12,665
now talking about the corporate vibe
coders, which I call app creators, the
65
00:04:12,665 --> 00:04:17,461
people that are outside of IT that maybe
need a safe space to experiment with
66
00:04:17,461 --> 00:04:22,541
ideas that they can then hand over to
either robots or humans to maybe develop
67
00:04:22,701 --> 00:04:24,151
further and get onto their production.
68
00:04:24,431 --> 00:04:28,901
Those people are coming, and us platform
engineers and DevOps engineers, we're
69
00:04:29,051 --> 00:04:32,901
having to deal with that problem, and it
feels like we need some solutions that
70
00:04:32,901 --> 00:04:37,671
help automate that middle layer out of the
way with a higher level of abstraction,
71
00:04:37,771 --> 00:04:38,891
and it looks like that's what they built.
72
00:04:38,991 --> 00:04:42,261
So let's get into my conversation
with Doron about Control Plane.
73
00:04:42,361 --> 00:04:43,251
welcome to the show.
74
00:04:43,261 --> 00:04:44,011
I'm glad to have you here.
75
00:04:44,111 --> 00:04:45,411
Doron: g-great to be here.
76
00:04:45,501 --> 00:04:46,141
looking forward to it
77
00:04:46,521 --> 00:04:50,721
Bret (2): Give us a little bit of your
background, Tell me the origin story,
78
00:04:50,756 --> 00:04:53,606
Doron: I ran a company, sold a
company, was chief architect at
79
00:04:53,606 --> 00:04:57,536
Dell, chief architect at, SAP, and
then ended up as, chief architect,
80
00:04:57,566 --> 00:04:59,936
for VMware for cloud services.
81
00:05:00,036 --> 00:05:04,899
And, at VMware, I missed my
interactions back at SAP with a guy
82
00:05:04,899 --> 00:05:10,569
named Dan Wilson, who was the best
DevOps/platform engineer I ever met.
83
00:05:10,669 --> 00:05:15,019
And what I wanted at VMware
was, Dan Wilson as a service.
84
00:05:15,119 --> 00:05:20,939
And, I really saw hundreds of,
outside customers and internal teams
85
00:05:20,979 --> 00:05:25,489
struggle with Kubernetes, Istio,
Grafana, Prometheus, and having to
86
00:05:25,489 --> 00:05:27,859
reinvent the wheel again and again.
87
00:05:27,939 --> 00:05:32,339
And so had the idea for Control
Plane, left VMware, started
88
00:05:32,349 --> 00:05:34,399
this company, called Dan Wilson.
89
00:05:34,469 --> 00:05:39,749
He was back at SAP and I said, "I want you
to join me as my CTO and really deliver to
90
00:05:39,759 --> 00:05:44,969
the world, what you do as a service." And
I thought it's gonna be a hard battle, but
91
00:05:44,979 --> 00:05:48,979
he jumped ship and he said, "Yeah, I'll
join you." And, that was the origin story.
92
00:05:49,079 --> 00:05:53,559
And then we brought on a few other
brilliant, engineers that have decades
93
00:05:53,569 --> 00:05:59,079
of, practice on, on, cloud native
architectures, and, we built this company
94
00:05:59,179 --> 00:06:00,639
Bret (2): this is pre-AI, right?
95
00:06:00,739 --> 00:06:03,979
So, th- we're gonna get into a
whole bunch of details later on,
96
00:06:03,999 --> 00:06:09,399
agent-driven infrastructure, like
MCP and CLI tooling, agent h- harness
97
00:06:09,399 --> 00:06:12,239
first, whatever we wanna call this
thing, th- this new future we're in.
98
00:06:12,339 --> 00:06:15,249
but what did, what was it like
to to be an infrastructure
99
00:06:15,249 --> 00:06:17,299
company and to see AI coming?
100
00:06:17,399 --> 00:06:20,859
Were, were you sorta like seeing
where this all could take us in
101
00:06:20,859 --> 00:06:23,879
terms of agents helping us in
infrastructure and stuff like that?
102
00:06:23,979 --> 00:06:24,829
Doron: 100%.
103
00:06:24,859 --> 00:06:27,129
we, I think, got more lucky.
104
00:06:27,289 --> 00:06:32,509
We have more luck than brain, because
it found us at a very interesting time.
105
00:06:32,509 --> 00:06:38,179
We, we wanted to reduce the cognitive
load on engineers not having to stitch
106
00:06:38,179 --> 00:06:42,299
together Kubernetes, Istio, Grafana,
Prometheus, Vault, and the things…
107
00:06:42,429 --> 00:06:44,509
all the CNCF, solutions out there.
108
00:06:44,609 --> 00:06:51,986
And we created an API that gives you
unified access to any cloud, any service,
109
00:06:52,086 --> 00:06:56,893
and we find that AI, if you just tell
it, "Create me the infrastructure," it's
110
00:06:56,903 --> 00:07:02,225
gonna duplicate a lot of resources: a
NAT gateway, a load balancer, brain, a
111
00:07:02,225 --> 00:07:07,075
Kubernetes set of nodes, and it's gonna
be expensive, non-deterministic, and
112
00:07:07,075 --> 00:07:09,515
it's gonna be non-secure, non-compliant.
113
00:07:09,615 --> 00:07:13,365
And where is the logging, the metrics,
the tracing, the secrets management,
114
00:07:13,365 --> 00:07:15,455
the service discovery, the TLS, the DNS?
115
00:07:15,455 --> 00:07:17,555
And the list goes on and on.
116
00:07:17,655 --> 00:07:23,067
So what AI needs, just like an engineer
needs, is a reduced cognitive load.
117
00:07:23,087 --> 00:07:27,077
In the era of AI is less
tokens, less context window.
118
00:07:27,177 --> 00:07:30,497
Give it a deterministic API
that says, "Hey, take my
119
00:07:30,497 --> 00:07:32,277
desired state and make it so.
120
00:07:32,377 --> 00:07:36,917
And by the way, make it so on
any cloud." It is a boon for AI.
121
00:07:37,652 --> 00:07:40,041
It makes AI a lot more effective.
122
00:07:40,141 --> 00:07:44,831
we find AI in a perfect, intersection
because we can now make it do
123
00:07:44,881 --> 00:07:49,181
tricks that is otherwise very, very
expensive or even u- unattainable
124
00:07:49,281 --> 00:07:53,371
Bret (2): Yeah, I always struggled
with, automation, pre-AI, in terms
125
00:07:53,371 --> 00:07:56,345
of, there's a point at which you're
trying to automate things and
126
00:07:56,345 --> 00:07:59,745
automate triggers and intelligence
with a deterministic language.
127
00:07:59,845 --> 00:08:03,985
And I always would get to a point where
I want this to be more automated, but
128
00:08:03,985 --> 00:08:08,255
the level of effort to automate that
small thing was way more than it was
129
00:08:08,255 --> 00:08:10,005
worth in terms of the automation.
130
00:08:10,005 --> 00:08:13,375
And, and in DevOps forever, we've been
talking about the toil, and I think
131
00:08:13,375 --> 00:08:16,365
that, I think the first time I heard
that was from Google's SRE paper, was
132
00:08:16,365 --> 00:08:20,325
talking about, the toil of ops, and
I always felt like there was a better
133
00:08:20,325 --> 00:08:23,765
way, a more complete way to automate
things, but every time I would try to
134
00:08:23,765 --> 00:08:27,665
take it to the next level, it, it was
like the management had no tolerance
135
00:08:27,675 --> 00:08:30,405
for me spending all of my time trying
to automate these little things.
136
00:08:30,405 --> 00:08:32,945
I'm like, "Yeah, but they're tiny
paper cuts and they add up over time,"
137
00:08:32,945 --> 00:08:35,695
and I was trying to, defend the,
the case for more automation, but
138
00:08:35,695 --> 00:08:37,045
we would just never quite get there.
139
00:08:37,045 --> 00:08:38,775
And now I feel like the
world is our oyster.
140
00:08:38,775 --> 00:08:42,935
I feel like we're, we're at a place where
you're only limited by your imagination
141
00:08:42,965 --> 00:08:46,415
and your ability to, manage the harness
and manage that agent inside it.
142
00:08:46,445 --> 00:08:48,515
Doron: we, we called it
the cloud is your oyster.
143
00:08:48,615 --> 00:08:55,255
We truly allow you to have a singular
API and leverage BigQuery on Google
144
00:08:55,335 --> 00:09:01,405
and Cosmos DB on Azure and S3 on Amazon
and-- or any one of the services.
145
00:09:01,505 --> 00:09:06,385
You can now write code and run it on your
Raspberry Pi or Dell machine or your EC2
146
00:09:06,405 --> 00:09:09,775
instances or EKS, AKS, GKE, whatever.
147
00:09:09,875 --> 00:09:14,759
And you can, not be
confined by any factor.
148
00:09:14,819 --> 00:09:20,109
So think of all the clouds as They have
merged, and now you can run the compute in
149
00:09:20,109 --> 00:09:26,319
a basement or on a cloud or on a secondary
or neo cloud, but leverage any service of
150
00:09:26,319 --> 00:09:28,773
any cloud, and, and let AI do the work.
151
00:09:28,773 --> 00:09:31,513
Like, I need a Postgres, I
need a Redis, I need a Kafka.
152
00:09:31,613 --> 00:09:36,123
You can conversationally get those
things up and running deterministically
153
00:09:36,223 --> 00:09:39,193
Bret (2): All right, so if we back up a
second, If someone hasn't heard of Control
154
00:09:39,193 --> 00:09:43,873
Plane, how is this different than a cloud
or different than a cloud management
155
00:09:43,873 --> 00:09:48,213
tool that we might all be using, like
Terraform or, any of the dozen, different
156
00:09:48,223 --> 00:09:52,623
opportunities I have to manage my cloud
with a CLI or some sort of service?
157
00:09:52,623 --> 00:09:52,973
Doron: Sure.
158
00:09:53,073 --> 00:09:56,653
So Terraform allows you
to create resources.
159
00:09:56,663 --> 00:10:00,203
We provide the Terraform
provider for control plane.
160
00:10:00,453 --> 00:10:04,923
We provide Pulumi, we provide other
interfaces Control Plane is a virtual
161
00:10:04,933 --> 00:10:09,253
cloud, allowing you to not have a
cloud and be cloudless and still
162
00:10:09,253 --> 00:10:14,243
run on Amazon, Google, Azure, Oracle
without a cloud account and pay by
163
00:10:14,253 --> 00:10:16,519
the millicore and megabyte of compute.
164
00:10:16,519 --> 00:10:20,039
So if you deploy the Bret app,
you can run essentially serverless
165
00:10:20,139 --> 00:10:23,899
on any cloud or multiple clouds
without having a cloud account.
166
00:10:23,909 --> 00:10:26,199
You can bring your own cloud account.
167
00:10:26,299 --> 00:10:30,229
If you're a SaaS and your customers
tell you, "Hey, you must run on Azure,"
168
00:10:30,229 --> 00:10:34,439
or, "You must run on Oracle," or,
"Must run on Hetzner," you now can.
169
00:10:34,459 --> 00:10:38,809
Your code, without any change,
can run anywhere, even on-prem.
170
00:10:38,909 --> 00:10:42,746
We let you have observability
built in We let you, as I
171
00:10:42,746 --> 00:10:44,446
mentioned, run by the millicore.
172
00:10:44,546 --> 00:10:47,566
We let you, communicate across clouds.
173
00:10:47,666 --> 00:10:52,036
If you have data in a VPC, let's say
RDS, Relational Database Service, and
174
00:10:52,036 --> 00:10:56,566
you want to run the workload on-prem,
yet communicate with RDS without
175
00:10:56,576 --> 00:10:59,036
poking holes in the firewall, you can.
176
00:10:59,136 --> 00:11:01,266
You can, run above the cloud.
177
00:11:01,266 --> 00:11:05,016
So today, when you run RDS as
an example, you're paying a
178
00:11:05,016 --> 00:11:07,266
high premium to run a database.
179
00:11:07,306 --> 00:11:08,616
You're not paying for the compute.
180
00:11:08,716 --> 00:11:12,506
Control Plane lets you run any
open source project very easily.
181
00:11:12,506 --> 00:11:15,276
We've certified, lots
and lots of, templates.
182
00:11:15,576 --> 00:11:21,396
You can run Kafka, Postgres, MySQL,
Cassandra, Mongo above the cloud.
183
00:11:21,396 --> 00:11:26,366
So if you wanted to move your
persistent store to Linode or Hetzner
184
00:11:26,526 --> 00:11:29,006
or Oracle or on-prem, you can.
185
00:11:29,106 --> 00:11:33,386
If you need multi-master replication,
we support that for many database types.
186
00:11:33,486 --> 00:11:39,246
we provide, sandboxes, so you
can deploy workloads or, or write
187
00:11:39,286 --> 00:11:42,296
code in a isolated environment.
188
00:11:42,396 --> 00:11:46,866
The difference about our, sandboxes
is that they allow you to communicate
189
00:11:46,876 --> 00:11:51,786
to your databases and other resources
in private data centers or VPCs.
190
00:11:51,886 --> 00:11:56,006
And you can traverse the network
boundary, easily connecting Amazon
191
00:11:56,006 --> 00:12:00,736
US East and Azure US West and Oracle
in, the Middle East, et cetera.
192
00:12:00,836 --> 00:12:06,766
So you can think of all the clouds
have, having merged and, with a hundred
193
00:12:06,816 --> 00:12:11,676
x simplification on how to consume
them, but without any limitation.
194
00:12:11,756 --> 00:12:16,166
So if you need to use the
native SDK for SQS, SNS,
195
00:12:18,549 --> 00:12:23,239
Dynamo, or any other native service,
you can we, we-- think of us as
196
00:12:23,249 --> 00:12:27,109
a virtual cloud, just like what
virtualization did to servers.
197
00:12:27,139 --> 00:12:30,459
You didn't care if it's
Dell or HP, we do to cloud.
198
00:12:30,469 --> 00:12:34,479
We make it so you don't care and the
agent doesn't care if you're running
199
00:12:34,479 --> 00:12:37,243
on Azure or any other, cloud provider.
200
00:12:37,443 --> 00:12:41,853
In fact, you can deliver traffic close
to where the customer is, and if there
201
00:12:41,853 --> 00:12:46,443
is a failure, let's say Amazon US East is
down, you automatically get routed to GCP
202
00:12:46,443 --> 00:12:48,463
or to Amazon US West or somewhere else.
203
00:12:48,473 --> 00:12:51,493
So you deliver low latency
and extreme high availability.
204
00:12:51,493 --> 00:12:55,653
We provide a five-nine guarantee,
translating to five minutes, fifteen
205
00:12:55,653 --> 00:12:58,343
seconds per year of cumulative downtime.
206
00:12:58,443 --> 00:13:04,553
So the reason customers come to us is
for unbreakable compute, for, extreme
207
00:13:04,613 --> 00:13:07,723
ease of use, for, cost optimization.
208
00:13:07,763 --> 00:13:12,203
Many of our customers save about fifty
percent compared to running natively
209
00:13:12,233 --> 00:13:17,083
on Amazon or Google because They can
pay for what they use and not pay for
210
00:13:17,103 --> 00:13:18,823
a cow when you need a glass of milk.
211
00:13:18,853 --> 00:13:22,563
'Cause when you buy a Kubernetes
cluster, you pay for the brain nodes,
212
00:13:22,663 --> 00:13:25,843
the worker nodes, you pay a hundred
percent of their utilization, even
213
00:13:25,843 --> 00:13:27,723
though they may consume twenty percent.
214
00:13:27,773 --> 00:13:30,273
And on control plane, you
pay twenty percent if you're
215
00:13:30,273 --> 00:13:31,403
consuming twenty percent.
216
00:13:31,503 --> 00:13:35,433
Bret (2): so you built this sort of
unified API layer over multiple clouds
217
00:13:35,533 --> 00:13:39,663
and, It sounds like you're adding almost
like your own custom services on top
218
00:13:39,663 --> 00:13:42,763
of that like you mentioned the, the
sandboxing, and obviously someone can,
219
00:13:42,763 --> 00:13:45,983
design their own little, EC2 instance
or whatever, or they can, they can try
220
00:13:45,983 --> 00:13:47,323
to design their own sandboxing solution.
221
00:13:47,323 --> 00:13:49,803
But it sounds like you're, you're
adding these as, specific services
222
00:13:49,803 --> 00:13:52,523
on top of that unified API, This
is actually a long question.
223
00:13:52,733 --> 00:13:53,763
I'm spitballing here.
224
00:13:53,933 --> 00:13:56,823
But, you could implement something
in one of those sandboxes or one of
225
00:13:56,823 --> 00:14:00,943
your other, ideas on top of any of the
clouds, whether or not that cloud has a
226
00:14:00,943 --> 00:14:03,613
particular offering labeled that, right?
227
00:14:03,613 --> 00:14:06,943
'Cause when I think of unified
cloud, I think of, reducing it down
228
00:14:06,943 --> 00:14:10,663
to its core elements and then, only
getting to use those core elements.
229
00:14:10,663 --> 00:14:13,463
But it sounds like you're
enriching on top of that API to
230
00:14:13,473 --> 00:14:14,683
give us higher level services.
231
00:14:14,743 --> 00:14:19,113
Doron: yes, people assume because
we unify the cloud, we give
232
00:14:19,113 --> 00:14:21,223
you, lowest common denominator.
233
00:14:21,323 --> 00:14:23,063
But in fact, we're the opposite.
234
00:14:23,093 --> 00:14:27,353
We give you the union of all clouds,
because now You can write the code
235
00:14:27,353 --> 00:14:33,223
with a native SDK for Google, for
Cloud Spanner, for Amazon, for, SQS,
236
00:14:33,233 --> 00:14:38,416
for, Azure, for cloud, for, let's
say, Entra ID or Cosmos DB or whatever
237
00:14:38,516 --> 00:14:42,246
machine learning service that is on
Azure, and we allow you to consume
238
00:14:42,246 --> 00:14:44,876
those services without credentials.
239
00:14:44,976 --> 00:14:47,326
Why is it important in the era of AI?
240
00:14:47,336 --> 00:14:50,856
You do not want to leak to
the LLM, the credentials.
241
00:14:50,956 --> 00:14:57,176
So neither in design time, meaning coding,
nor at runtime are keys exposed, and
242
00:14:57,176 --> 00:15:01,066
in fact, you don't even have to rotate
the keys because you get ephemeral,
243
00:15:01,236 --> 00:15:03,246
zero trust, least privileged tokens.
244
00:15:03,346 --> 00:15:07,486
and we patented the technology
called Universal Cloud Identity that
245
00:15:07,496 --> 00:15:13,656
basically gives you the identity, the
IAM of all the clouds in a much more,
246
00:15:13,756 --> 00:15:18,406
streamlined manner, and the code is
devoid of credentials completely.
247
00:15:18,706 --> 00:15:22,936
Yet the code can only do the
exact, operations on the exact
248
00:15:22,936 --> 00:15:25,426
resources you granted it access to.
249
00:15:25,526 --> 00:15:27,756
Bret (2): what are you
seeing with adoption?
250
00:15:27,816 --> 00:15:31,386
as a, as someone who's… I've managed
infrastructure for over 30 years
251
00:15:31,386 --> 00:15:35,076
at this point, and, w- we've been
chasing this dream in ops land of,
252
00:15:35,126 --> 00:15:36,706
the unified control plane, right?
253
00:15:36,706 --> 00:15:40,336
we've had for decades now, ever since
really the cloud or before, we've
254
00:15:40,336 --> 00:15:42,356
had all these attempts at unifying.
255
00:15:42,356 --> 00:15:43,776
You know, VMware wanted to do it.
256
00:15:43,786 --> 00:15:45,096
Microsoft tried to do it.
257
00:15:45,196 --> 00:15:49,866
we had just all these different pieces,
and the best we could do was, like, stick
258
00:15:49,866 --> 00:15:53,486
to one OS and then use their, I think
they, system management tools or whatever.
259
00:15:53,586 --> 00:15:56,996
And then I feel like ever since then
I've been chasing this dream, whether
260
00:15:56,996 --> 00:16:01,006
it was Terraform or Chef and Puppet
before that, and then we got Pulumi, and
261
00:16:01,006 --> 00:16:05,876
we've had all these different attempts
at, one control plane essentially that
262
00:16:05,876 --> 00:16:09,786
controls not necessarily my workloads,
but just the infrastructure behind it,
263
00:16:09,886 --> 00:16:12,266
and it's always felt like a compromise.
264
00:16:12,376 --> 00:16:17,166
It always felt like if I'm gonna do
Terraform, that's great, but it's gonna
265
00:16:17,166 --> 00:16:21,776
get much harder as I go multi-cloud, and
I'm gonna be spending my days in TOML
266
00:16:21,786 --> 00:16:25,136
hell just trying to make sure I don't
break things with a, with an update.
267
00:16:25,236 --> 00:16:28,396
So I'm curious of, like, some
customer stories around, onboarding.
268
00:16:28,416 --> 00:16:31,076
How do people get to control
plane from where they are,
269
00:16:31,076 --> 00:16:31,976
and what does that look like?
270
00:16:32,076 --> 00:16:32,376
Doron: Yeah.
271
00:16:32,376 --> 00:16:36,716
So we have, over, eighteen hundred,
now over two thousand customers.
272
00:16:36,786 --> 00:16:40,086
Some of them are very large,
some of them are tiny, doing
273
00:16:40,086 --> 00:16:41,746
vibe, coding type projects.
274
00:16:41,846 --> 00:16:46,576
And most of the larger customers,
the-- none of them are greenfield.
275
00:16:46,616 --> 00:16:51,683
They're all coming from Amazon,
from Google, from Heroku, from, uh,
276
00:16:52,263 --> 00:16:57,045
Azure, and they all have a sprawling,
degree of Helm charts and, Terraform
277
00:16:57,052 --> 00:16:59,852
or Pulumi or Crossplane, artifacts.
278
00:16:59,952 --> 00:17:06,695
And we have, mechanical translation in
the CLI allowing you to take a Kubernetes
279
00:17:06,695 --> 00:17:10,645
YAML and enrich it to the Control
Plane YAML because Kubernetes doesn't
280
00:17:10,655 --> 00:17:17,175
have the concept of the global virtual
cloud, a cloud made up of N clusters.
281
00:17:17,185 --> 00:17:21,345
So in Control Plane, I can take three
clusters or three hundred and turn
282
00:17:21,345 --> 00:17:25,125
them into one global virtual cloud
or actually subdivide them into many
283
00:17:25,165 --> 00:17:30,405
global virtual clouds and deploy an
application to the GVC, which is like
284
00:17:30,405 --> 00:17:36,965
a VPC, but spread across two regions or
a hundred in one cloud or many So our
285
00:17:36,965 --> 00:17:41,565
customers typically have a couple days
up to a couple weeks, depending on how
286
00:17:41,565 --> 00:17:45,795
large the customer is, of migration,
which is, again, that mechanical
287
00:17:45,895 --> 00:17:51,205
translation of their YAML or Helm chart
or other artifacts to Control Plane.
288
00:17:51,305 --> 00:17:54,475
But we integrate very nicely
into their CI/CD pipelines.
289
00:17:54,575 --> 00:17:56,935
We integrate with Flux or Argo CD.
290
00:17:57,035 --> 00:17:58,565
so it's very natural.
291
00:17:58,845 --> 00:18:00,675
The learning curve is very shallow.
292
00:18:00,775 --> 00:18:04,655
Once you learn Control Plane, you
feel, and what I hear from customers,
293
00:18:04,755 --> 00:18:07,155
we run circles around our peers.
294
00:18:07,255 --> 00:18:11,245
And one customer, I think the best
compliment I ever got was after
295
00:18:11,245 --> 00:18:15,085
using Control Plane, moving back
to not using Control Plane is like
296
00:18:15,085 --> 00:18:19,025
going from iPhone seventeen to
Nokia from nineteen ninety-seven.
297
00:18:19,125 --> 00:18:22,865
That's-- And, and now, that was
very rewarding for me to hear, and
298
00:18:22,945 --> 00:18:24,895
I would-- I'm eager to demonstrate.
299
00:18:24,995 --> 00:18:29,785
and my objective is after this,
call, y- are you gonna go back to
300
00:18:29,785 --> 00:18:33,355
the old ways or are you gonna adopt
Control Plane to deploy your code?
301
00:18:33,455 --> 00:18:37,405
I think it's the latter, because,
it's-- we, we truly give you,
302
00:18:37,505 --> 00:18:40,495
Dan Wilson as a service, the one
I, I mentioned, I started with.
303
00:18:40,505 --> 00:18:45,435
He's our CTO, and he really, rather than
you having to spend or the AI having
304
00:18:45,455 --> 00:18:51,005
to spend millions of tokens reinventing
the wheel, focus on what matters, which
305
00:18:51,005 --> 00:18:56,225
is your rocket shipping system or your,
whatever the thing that you're doing
306
00:18:56,325 --> 00:18:59,015
and not be, knee-deep in the toil.
307
00:18:59,295 --> 00:19:00,435
and there is a lot of toil.
308
00:19:00,465 --> 00:19:04,235
It's one thing to have toil,
but why should every company
309
00:19:04,335 --> 00:19:06,605
reinvent the same wheel?
310
00:19:06,645 --> 00:19:11,565
Logging, metrics, tracing, secrets,
m- mutual TLS between services because
311
00:19:11,575 --> 00:19:17,245
you want a service mesh, audit trail,
scaling, scaling strategies, failover
312
00:19:17,345 --> 00:19:19,475
Should every company reinvent that wheel?
313
00:19:19,475 --> 00:19:20,475
Does that make sense?
314
00:19:20,565 --> 00:19:24,715
Should every company have an Exchange
server engineer babysitting email?
315
00:19:24,995 --> 00:19:26,495
That was the case.
316
00:19:26,775 --> 00:19:29,915
It isn't anymore because it
doesn't make sense when you can,
317
00:19:30,015 --> 00:19:33,965
shift left or whatever, delegate
that, mundane responsibility to
318
00:19:33,965 --> 00:19:35,935
somebody who is excelling at it.
319
00:19:36,187 --> 00:19:36,987
And think about it.
320
00:19:36,997 --> 00:19:41,317
If every company reinvents the same
items I just mentioned, it represents
321
00:19:41,357 --> 00:19:46,484
technical debt because now you need to
maintain, fix the CVEs, upgrade Kubernetes
322
00:19:46,504 --> 00:19:50,434
every three months, upgrade Istio,
upgrade Prometheus, upgrade Grafana.
323
00:19:50,534 --> 00:19:54,594
When do you have time to do the
actual work when you're babysitting
324
00:19:54,594 --> 00:19:57,764
an infrastructure that your
peers are doing the same thing?
325
00:19:57,864 --> 00:20:01,214
We say stop with the babysitting
of infrastructure, start
326
00:20:01,254 --> 00:20:03,134
delivering value to customers,
327
00:20:03,234 --> 00:20:05,094
Bret (2): We talked about this
last time when we, we had a
328
00:20:05,114 --> 00:20:06,394
r- a call a couple weeks ago.
329
00:20:06,494 --> 00:20:10,890
The, the assumption that I have about
services like this, like if I'm looking
330
00:20:10,890 --> 00:20:13,590
at your homepage and I've not talked
to you and I don't know anything about
331
00:20:13,590 --> 00:20:17,640
the company, is that, to me, there's
always a compromise, I feel like.
332
00:20:17,650 --> 00:20:23,100
And so when I think about the complexity
of the cloud APIs, just for AWS, the,
333
00:20:23,100 --> 00:20:26,900
"This Week in AWS" podcast with Corey
Quinn, I've been, I've been on his
334
00:20:26,900 --> 00:20:30,950
show, he's been on mine, but I, I always
find his articles about, yet another
335
00:20:30,960 --> 00:20:33,960
AWS service that we don't understand
what it is, and it's redundant.
336
00:20:33,960 --> 00:20:37,370
And, and so he talks about the hundreds
and hundreds of services they have, and
337
00:20:37,630 --> 00:20:41,480
it's, th- there's always a customer for
the things, but it may not be you or me.
338
00:20:41,580 --> 00:20:46,373
And I always find it hilariously
complex that I am so behind on how
339
00:20:46,373 --> 00:20:50,053
many of those products I don't know
about and I've never used, and it just,
340
00:20:50,153 --> 00:20:52,223
Am I even an engineer if I
don't understand half the
341
00:20:52,223 --> 00:20:53,843
things that AWS deploys, right?
342
00:20:53,843 --> 00:20:54,763
Sometimes I question it.
343
00:20:54,763 --> 00:20:59,293
But, I'm curious about, how your API
relates to their product APIs, and how
344
00:20:59,293 --> 00:21:02,923
you guys have been able to innovate
around covering all the bases to make
345
00:21:02,923 --> 00:21:07,073
sure that we're not left with, this
reduced abstraction that's only the
346
00:21:07,173 --> 00:21:10,573
same core fundamentals across every
cloud, but you're allowed to, you're
347
00:21:10,573 --> 00:21:12,233
able to e- enrich it a little bit.
348
00:21:12,233 --> 00:21:13,103
Tell me a little bit about that.
349
00:21:13,123 --> 00:21:13,673
How's that work?
350
00:21:13,773 --> 00:21:15,423
Doron: Yeah, that's a great question.
351
00:21:15,470 --> 00:21:19,153
So I mentioned we're not the
lowest common denominator, but the
352
00:21:19,153 --> 00:21:20,673
union, and what does that mean?
353
00:21:20,773 --> 00:21:25,333
It means if Amazon came up with a
Bret service a microsecond from now,
354
00:21:25,603 --> 00:21:30,273
we would support it because we're
not trying to, abstract the API,
355
00:21:30,283 --> 00:21:32,583
the native API to the Bret service.
356
00:21:32,583 --> 00:21:35,543
We integrate at the identity
and access management layer.
357
00:21:35,617 --> 00:21:41,910
And so we would mechanically be able
to pull permissions from their IAM IAM
358
00:21:41,910 --> 00:21:44,170
system relating to the new Bret service.
359
00:21:44,210 --> 00:21:49,340
The coder, AI or human, would use
the native SDK if there is one to the
360
00:21:49,340 --> 00:21:51,670
Bret service or the C-- or the API.
361
00:21:51,743 --> 00:21:56,913
We just inject the token necessary
for the Bret service to do its work,
362
00:21:57,203 --> 00:22:01,433
and we're able to do it whether you--
the workload is running on-prem,
363
00:22:01,533 --> 00:22:06,587
on Hetzner, on DigitalOcean, , on
Google, on Amazon, on Azure.
364
00:22:06,687 --> 00:22:11,610
So because we integrate at the IAM, the
identity and access management layer
365
00:22:11,710 --> 00:22:12,100
Bret (2): Yeah
366
00:22:12,388 --> 00:22:16,388
Doron: We are supportive of any
new service that Google, Amazon or
367
00:22:16,388 --> 00:22:18,968
anybody else provides instantly.
368
00:22:18,968 --> 00:22:21,188
There is no work that we need to do.
369
00:22:21,288 --> 00:22:27,128
And the likelihood of Amazon or anybody
else changing their identity and access
370
00:22:27,128 --> 00:22:32,741
management APIs that we exploit are
zero, because if they change their APIs,
371
00:22:32,771 --> 00:22:34,631
the cl-- the world would break, right?
372
00:22:34,651 --> 00:22:38,521
Because everybody, millions of
people have, utilized their services.
373
00:22:38,531 --> 00:22:42,411
So if they were to change, they
would give you multi-year head start.
374
00:22:42,511 --> 00:22:48,151
but, because again, we integrate at the
IAM level, when you consume, let's say,
375
00:22:48,221 --> 00:22:54,125
RDS, but you're on, Azure, the, the, the
workload is running on Azure or on-prem,
376
00:22:54,225 --> 00:22:59,845
we obtain the correct token from their
STS, their security token service, and
377
00:22:59,845 --> 00:23:05,845
know how to inject it at runtime from
the SDK to RDS, in our case, And, so in
378
00:23:05,845 --> 00:23:11,418
effect, the workload is liberated and
no longer captive to the subject cloud.
379
00:23:11,418 --> 00:23:13,658
You can now move amongst the clouds.
380
00:23:13,758 --> 00:23:16,818
People spent millions of dollars
moving from Amazon to Google or
381
00:23:16,828 --> 00:23:20,888
Google to Oracle, but on Control
Plane, the cloud is your oyster.
382
00:23:20,888 --> 00:23:24,488
You can move from Amazon to Google,
from Google to on-prem, from on-prem
383
00:23:24,488 --> 00:23:29,958
to whatever with a click of a button,
and you can leverage all of them.
384
00:23:30,258 --> 00:23:34,608
So we flip the script where
the clouds want to-- their
385
00:23:34,638 --> 00:23:36,438
objective is to lock you in.
386
00:23:36,538 --> 00:23:41,988
We flip it on its head and, turn them
in-into just commoditized utilities.
387
00:23:42,088 --> 00:23:46,068
So when you consume electricity,
your TV doesn't care if it's
388
00:23:46,108 --> 00:23:48,061
Edison or somebody else.
389
00:23:48,161 --> 00:23:49,641
It cares about the interface.
390
00:23:49,741 --> 00:23:55,545
With Control Plane, you now have a virtual
cloud operating system that utilizes
391
00:23:55,585 --> 00:23:59,245
the power, the whole power of Amazon,
the whole power of Google, et cet- et
392
00:23:59,245 --> 00:24:01,415
cetera, but without locking you in.
393
00:24:01,435 --> 00:24:01,815
Bret (2): Yeah.
394
00:24:01,915 --> 00:24:05,095
I wanna change the conversation
a little bit to be more specific
395
00:24:05,115 --> 00:24:09,135
on some of the AI, uh, stuff that
we're all managing right now.
396
00:24:09,135 --> 00:24:14,025
So, this whole year for me has been really
focused in understanding other DevOps
397
00:24:14,045 --> 00:24:18,265
teams and, platform engineering teams,
like understanding the way that they're
398
00:24:18,265 --> 00:24:20,305
using agent harnesses to do their job.
399
00:24:20,305 --> 00:24:23,255
I think, if we f- if we rewound a year
ago, maybe even three or four years
400
00:24:23,255 --> 00:24:27,241
ago when Google Copilot was kinda like
the first IDE to throw AI completion
401
00:24:27,241 --> 00:24:30,221
in, and even in those early days,
I think I demoed it when it was in
402
00:24:30,221 --> 00:24:31,641
beta when we were on this channel.
403
00:24:31,641 --> 00:24:33,891
I remember one summer we were, I
think it was 2022 or something.
404
00:24:33,901 --> 00:24:37,131
It was before ChatGPT came out, and we
were, like, looking at the, the early
405
00:24:37,131 --> 00:24:41,851
GPT model that was embedded in, in
GitHub Copilot, and the, VS Code UI.
406
00:24:41,951 --> 00:24:44,891
And we were, we were trying to
see how far we could get with YAML
407
00:24:44,891 --> 00:24:47,391
and TOML by tab completing, right?
408
00:24:47,391 --> 00:24:50,561
Like, we were trying to figure out
how much time can it save me as an,
409
00:24:50,571 --> 00:24:54,501
as a ops engineer, but we were really
just talking about file completion,
410
00:24:54,551 --> 00:24:56,461
completion in a YAML statement.
411
00:24:56,471 --> 00:25:00,891
So, it was saving me keystrokes, and
it maybe, was saving me potentially
412
00:25:00,891 --> 00:25:03,481
some human error that would
hopefully be caught by a linter,
413
00:25:03,581 --> 00:25:05,041
but it wasn't a huge gain, right?
414
00:25:05,041 --> 00:25:07,611
And so you fast-forward a
little bit, and then we're all,
415
00:25:07,651 --> 00:25:08,751
we're doing that with ChatGPT.
416
00:25:08,751 --> 00:25:09,831
People are copying and pasting.
417
00:25:09,831 --> 00:25:13,371
And then last year when we got Claude
Code for the first time and we under- we
418
00:25:13,371 --> 00:25:17,281
started to understand what an agent loop
is, it, it started to shift and I started
419
00:25:17,281 --> 00:25:22,181
to notice that my, my production friends
were all dabbling with letting their, the
420
00:25:22,181 --> 00:25:25,531
first thing they would do is let their
agent have, a read access token to some
421
00:25:25,531 --> 00:25:29,088
part of their infrastructure so that it
could maybe run the kubectl commands for
422
00:25:29,088 --> 00:25:31,978
them or run the AWS CLI commands for them.
423
00:25:32,078 --> 00:25:36,695
And I was doing that same thing
for, like, GitHub CLIs for, for CI.
424
00:25:36,695 --> 00:25:36,705
CI.
425
00:25:36,715 --> 00:25:39,675
Like, I cared about GitHub Actions
and, my build status and stuff
426
00:25:39,675 --> 00:25:42,505
like that, so I was, I was managing
that middle portion, and I was
427
00:25:42,505 --> 00:25:43,875
using agents to, keep track of it.
428
00:25:43,875 --> 00:25:47,205
And now it's like these are all inherent
features that are really built in.
429
00:25:47,215 --> 00:25:49,675
They, they've got the background
workers, the sub-agents, and things
430
00:25:49,675 --> 00:25:51,165
that are making this really possible.
431
00:25:51,165 --> 00:25:53,745
But I'm curious what you're
seeing with your customers.
432
00:25:53,895 --> 00:25:57,205
how, how are they driving
their infrastructure with AI?
433
00:25:57,825 --> 00:26:00,305
Like, I guess maybe if we can get
to some, into some nitty-gritty
434
00:26:00,305 --> 00:26:03,915
details around, are they focused
on only using their agent harness?
435
00:26:03,915 --> 00:26:07,025
Are they using, MCP to, to Control Plane?
436
00:26:07,025 --> 00:26:09,058
Are they using, Control Plane CLIs?
437
00:26:09,098 --> 00:26:11,838
Like, how are they actually doing
this work, and what are some
438
00:26:11,838 --> 00:26:12,668
of the stories you're hearing?
439
00:26:12,768 --> 00:26:17,478
Doron: Yeah, our customers, pretty
much all use our MCP server,
440
00:26:17,578 --> 00:26:24,318
and we always pride ourselves in
providing all the accessibility.
441
00:26:24,418 --> 00:26:29,008
Of course, at the lower end is, is the
API, but everything you can do in the
442
00:26:29,028 --> 00:26:35,131
API, you can do in the CLI, Terraform,
Pulumi, Crossplane, UI, and MCP.
443
00:26:35,231 --> 00:26:37,810
To us, these are symmetric interfaces.
444
00:26:37,910 --> 00:26:42,640
Of course, with MCP, you can now bring
the intelligence to let it discover
445
00:26:42,640 --> 00:26:46,872
what can be done, and now you can
have conversational infrastructure.
446
00:26:46,872 --> 00:26:50,242
You now have the equivalent of
a enterprise architect/platform
447
00:26:50,362 --> 00:26:57,062
engineer/DevOps/SRE bundled into one
that you can have a conversation with.
448
00:26:57,202 --> 00:27:00,302
you can tell me the app you want
to build and the dependencies that
449
00:27:00,302 --> 00:27:04,698
you want to have, and the MCP will
go and negotiate and build those
450
00:27:04,698 --> 00:27:07,138
things that we want to build for us.
451
00:27:07,238 --> 00:27:11,521
And then if we need to troubleshoot
or need to look at observability, the
452
00:27:11,541 --> 00:27:15,981
MCP is able to look at the traces,
the logs, the metrics, a- and add the
453
00:27:15,981 --> 00:27:18,901
intelligence to give you actionable items.
454
00:27:19,201 --> 00:27:25,870
So you feel like you have the best SREs
and platform engineers at Google with you
455
00:27:25,870 --> 00:27:28,120
twenty-four seven, and you don't pay them.
456
00:27:28,220 --> 00:27:32,690
So you can vibe code a very complex
system made up of 20 microservices all
457
00:27:32,700 --> 00:27:37,570
intertwined with databases and queues
and, and caches and say, "Okay, give
458
00:27:37,570 --> 00:27:42,980
it to me codified." And our codified
version is always backwards compatible.
459
00:27:42,990 --> 00:27:46,060
So I'm sure Kubernetes deprecate
stuff every three months.
460
00:27:46,060 --> 00:27:48,170
You have some deprecations and new APIs.
461
00:27:48,270 --> 00:27:50,730
It's a fairly unstable substrate.
462
00:27:50,830 --> 00:27:53,920
So if you wanted to take YAML
from 10 years ago and just run
463
00:27:53,920 --> 00:27:56,040
it, you'll run into issues.
464
00:27:56,140 --> 00:27:57,830
So we made an early choice.
465
00:27:57,930 --> 00:27:59,790
Bret (2): At a minimum
warnings, possibly errors, yeah
466
00:27:59,890 --> 00:28:00,240
Doron: Right.
467
00:28:00,290 --> 00:28:01,800
And we made a decision.
468
00:28:01,880 --> 00:28:06,880
We, we noticed that six years ago and
made the very, I think, good decision of
469
00:28:06,910 --> 00:28:09,470
always having backwards compatibility.
470
00:28:09,570 --> 00:28:14,800
So if you take YAML from six years ago and
apply it today, you'll get the exact same
471
00:28:14,830 --> 00:28:19,880
artifacts on top of any compute substrate,
whether it's on-prem, Azure, etcetera.
472
00:28:19,980 --> 00:28:23,075
Bret (2): we-- Are-- When you s-
when you say that, are we talking
473
00:28:23,075 --> 00:28:27,495
about your customers can continue
to use Terraform or Pulumi?
474
00:28:27,605 --> 00:28:30,395
I'm assuming that that's how they're,
they're interacting with you, right?
475
00:28:30,395 --> 00:28:33,915
Like, they're, they're talking
to your API from these particular
476
00:28:34,015 --> 00:28:35,495
management tools, right?
477
00:28:35,495 --> 00:28:38,492
I'm ass- I'm assuming, um,
OpenTofu is s- is supported.
478
00:28:38,712 --> 00:28:40,432
What else, what are the other ways?
479
00:28:40,462 --> 00:28:43,332
'Cause, o- one of the things I've
started to see with agents is if,
480
00:28:43,342 --> 00:28:46,662
if you're a singular cloud, it might
just be better if your, if your
481
00:28:46,682 --> 00:28:50,952
agent is the complete interface to h-
whatever the description language is.
482
00:28:51,052 --> 00:28:54,612
I've seen some examples of people actually
switching away from Terraform back to
483
00:28:54,612 --> 00:28:59,072
the native, cloud formation or whatever
of their cloud, because they look at
484
00:28:59,072 --> 00:29:03,422
it as there's this agent abstraction
between me and the YAML or the JSON.
485
00:29:03,432 --> 00:29:08,222
I don't have to be the expert in every
single line of that anymore, so I
486
00:29:08,222 --> 00:29:12,012
actually care more about, some of the
inherent functionality of a different,
487
00:29:12,112 --> 00:29:16,442
of, of the language tooling itself rather
than, we always looked at Terraform
488
00:29:16,442 --> 00:29:19,152
as maybe a little bit more to, easier
to understand than cloud formation.
489
00:29:19,352 --> 00:29:22,552
A little bit, a little less comprehensive,
a little, little less verbose.
490
00:29:22,652 --> 00:29:25,082
But if you've got an agent in
the way, that matters less.
491
00:29:25,112 --> 00:29:26,912
Are you seeing anything like that?
492
00:29:26,962 --> 00:29:30,122
Are, are you seeing people,
switch, products now that they're
493
00:29:30,142 --> 00:29:32,192
using agents, as their interface?
494
00:29:32,292 --> 00:29:33,612
Doron: Somewhat, yes.
495
00:29:33,642 --> 00:29:37,152
I've seen people that, that used
certain… I don't want to name names
496
00:29:37,152 --> 00:29:42,132
'cause I don't want to dish on any one
platform, but there are many equivalents.
497
00:29:42,222 --> 00:29:46,122
Like when-- whether you use
Crossplane, Pulumi, CloudFormation,
498
00:29:46,262 --> 00:29:49,092
Terraform, and a few others,
they're functionally equivalent.
499
00:29:49,092 --> 00:29:50,872
They're like French, English, Spanish.
500
00:29:51,142 --> 00:29:53,622
You can express the same
ideas in these languages.
501
00:29:53,622 --> 00:29:57,332
They do things in slightly different
manners, like Pulumi is more,
502
00:29:57,432 --> 00:30:01,682
programmatic than, than, declarative,
and Terraform is more declarative.
503
00:30:01,782 --> 00:30:06,372
But at the end of the day, they
express a desired state, and there is a
504
00:30:06,382 --> 00:30:10,822
translation layer that takes the desired
state, like with DAG on, on the case
505
00:30:10,822 --> 00:30:16,222
of, Terraform, and applies in the right
order, calls the APIs that are affecting
506
00:30:16,222 --> 00:30:18,292
the, the actual resources in the cloud.
507
00:30:18,392 --> 00:30:20,032
It's just a translation, right?
508
00:30:20,032 --> 00:30:23,272
So like you said, if I don't
have to write to that language,
509
00:30:23,302 --> 00:30:27,722
why can't I talk in English and
let it make the calls directly?
510
00:30:27,822 --> 00:30:28,852
But here is the thing.
511
00:30:28,952 --> 00:30:35,472
Terraform, as an example, or OpenTofu,
invested heavily in doing the DAG and
512
00:30:35,472 --> 00:30:39,872
doing the validation and doing stuff that
the agent itself will have to reinvent
513
00:30:39,882 --> 00:30:44,232
what they had done to apply things in the
right order and give you the rigor that
514
00:30:44,232 --> 00:30:46,232
they have already baked into the platform.
515
00:30:46,332 --> 00:30:50,942
It is better, like in the Excel example
I've ga-- I've given, to let the
516
00:30:50,962 --> 00:30:56,462
agent leverage a tool like Terraform
than to learn, the underlying, API.
517
00:30:56,472 --> 00:30:57,542
It's, it's possible.
518
00:30:57,592 --> 00:31:00,422
here it's, it's, it's
not an exact science.
519
00:31:00,432 --> 00:31:03,222
Here is subject to, to, judgment.
520
00:31:03,322 --> 00:31:07,092
It can call the, the direct, it
can call the API, it can call
521
00:31:07,092 --> 00:31:09,372
the CLI of the AWS, let's say.
522
00:31:09,472 --> 00:31:14,542
It can call, a CDK, There are
many, again, equivalent, logically
523
00:31:14,542 --> 00:31:15,992
equivalent, options here.
524
00:31:16,242 --> 00:31:16,562
So
525
00:31:16,662 --> 00:31:16,792
Bret (2): So
526
00:31:16,896 --> 00:31:17,066
Doron: our
527
00:31:17,072 --> 00:31:17,382
Bret (2): you, I
528
00:31:17,482 --> 00:31:21,532
Doron: w- w- we, we just give you the,
the one API, and it's your choice.
529
00:31:21,562 --> 00:31:26,392
You tell the AI, " Use the API, use
Terraform, use YAML, use JSON, JSON,
530
00:31:26,402 --> 00:31:31,072
use, CRD." We give the choice to the
customer or the AI, and the AI would
531
00:31:31,072 --> 00:31:35,862
choose the, the least token-consuming
manner that it can operate in
532
00:31:35,962 --> 00:31:40,322
Bret (2): So when someone's migrating
to your platform, if they're using
533
00:31:40,322 --> 00:31:43,922
CloudFormation, d- I'm assuming you
don't support CloudFormation because
534
00:31:43,932 --> 00:31:45,702
you're sitting in front of the AWS.
535
00:31:45,792 --> 00:31:46,252
Like, you're, you're
536
00:31:46,388 --> 00:31:46,718
Doron: Correct.
537
00:31:46,822 --> 00:31:47,302
Bret (2): different
538
00:31:47,402 --> 00:31:50,232
Doron: we, we don't support cloud
formation for control plane.
539
00:31:50,242 --> 00:31:53,672
We have customers that use cloud
formation to create their S3 buckets
540
00:31:53,672 --> 00:31:57,152
and their RDS and their Dynamo,
then, then they tell control plane,
541
00:31:57,252 --> 00:32:02,242
run a workload that connects to
the S3 bucket to RDS to Dynamo.
542
00:32:02,342 --> 00:32:04,282
They're not, in conflict with each other.
543
00:32:04,322 --> 00:32:05,872
They're just not overlapping.
544
00:32:05,972 --> 00:32:10,502
There is no reason for us to introduce
a cloud formation concept 'cause
545
00:32:10,502 --> 00:32:13,412
it's a proprietary, lingo of AWS.
546
00:32:13,412 --> 00:32:17,052
So we are operating at
the cloud agnostic, layer.
547
00:32:17,112 --> 00:32:18,592
We fly above the cloud.
548
00:32:18,692 --> 00:32:20,772
We don't wanna fly in, in that cloud.
549
00:32:20,782 --> 00:32:21,712
We fly above it
550
00:32:21,812 --> 00:32:23,952
Bret (2): Do you see, do you
think that Terraform is still the
551
00:32:23,962 --> 00:32:26,622
primary way your customers are
managing their infrastructure?
552
00:32:26,642 --> 00:32:27,822
Do you see that as, the majority?
553
00:32:27,922 --> 00:32:29,569
Doron: I would call it 60%.
554
00:32:29,669 --> 00:32:30,059
Bret (2): Okay
555
00:32:30,169 --> 00:32:33,489
Doron: Just because of inertia,
Not because it has a, a, a
556
00:32:33,489 --> 00:32:35,219
specific advantage, like I said.
557
00:32:35,319 --> 00:32:39,899
Whether it's Terraform, Pulumi, or
Crossplane, or something else, All they
558
00:32:39,899 --> 00:32:45,009
are, are syntactic sugar on top of the
API with some DAG, that, that decides
559
00:32:45,029 --> 00:32:49,209
what to create first and what to destroy
first, and maybe save the state and so on.
560
00:32:49,309 --> 00:32:53,739
So to me, those are fairly
commoditized, languages.
561
00:32:53,839 --> 00:32:57,669
So for, for the audience to
understand, we don't compete with
562
00:32:57,669 --> 00:32:59,489
Terraform, not even a little bit.
563
00:32:59,589 --> 00:33:02,239
It's like a car doesn't
compete with, a sandwich.
564
00:33:02,439 --> 00:33:04,449
It's two different animals completely.
565
00:33:04,549 --> 00:33:04,809
Bret (2): yeah.
566
00:33:04,859 --> 00:33:07,144
so we talked about customer
base, and, like, the different
567
00:33:07,144 --> 00:33:08,384
size of customers, right?
568
00:33:08,384 --> 00:33:12,334
And it's hard for, any one cloud to
always, a-adopt all customers, right?
569
00:33:12,384 --> 00:33:16,024
We, we all think of, the digital oceans
and, the Vercels of the world, that
570
00:33:16,024 --> 00:33:19,374
they're all like a very niche cloud,
that they've got a very specific purpose,
571
00:33:19,384 --> 00:33:22,464
and then you have the three hyperscalers
that are just everything for everyone,
572
00:33:22,464 --> 00:33:26,294
but it's also impossible for anyone
to get on board really easily, right?
573
00:33:26,394 --> 00:33:31,324
Do you, do you see, are small teams
of, with n-no developers or very few
574
00:33:31,324 --> 00:33:34,784
operators or anything like that, do
they-- Is Control Plane being used by
575
00:33:34,784 --> 00:33:36,434
those kinds of small little companies?
576
00:33:36,464 --> 00:33:39,924
'Cause I, I have a scenario where
I'm thinking, I have, companies
577
00:33:39,924 --> 00:33:44,554
that are, they, th-they might have
one or two IT staff, but, they
578
00:33:44,554 --> 00:33:45,704
don't have internal developers.
579
00:33:46,004 --> 00:33:49,624
So usually when it, it's hard to figure
out, as a consultant, your heart, it's
580
00:33:49,624 --> 00:33:51,374
hard to figure out, what do I do for them?
581
00:33:51,374 --> 00:33:54,244
Because I either have to put them
on a hyperscaler, and then now they
582
00:33:54,244 --> 00:33:56,104
can't do anything without me, right?
583
00:33:56,104 --> 00:33:59,434
I become a bottleneck, which I, I, me as
a consultant, I don't ever wanna do that.
584
00:33:59,434 --> 00:34:01,394
I wanna be instantly
replaceable re-usually.
585
00:34:01,494 --> 00:34:06,124
Or I have to put them on some sort of
niche cloud that, if it's too niche, it
586
00:34:06,124 --> 00:34:10,084
may not be here in five years, or it might
be somehow limited i-in, in what it can
587
00:34:10,084 --> 00:34:14,394
do, and then I'm li- like a Lovable for
AI or whatever, like these, these little
588
00:34:14,424 --> 00:34:16,104
fly-by-night dashboard companies, right?
589
00:34:16,404 --> 00:34:19,784
Do you… W-what's it look like for the
really small teams on, on Control Plane?
590
00:34:19,884 --> 00:34:24,704
Doron: The good news, you will always
have a substrate to run upon 'cause it can
591
00:34:24,704 --> 00:34:29,394
be, like I said, your on-prem, it can be
Azure, Google, Amazon, Oracle, et cetera.
592
00:34:29,494 --> 00:34:34,194
And we have customers that have, non,
traditional developers, certainly no
593
00:34:34,194 --> 00:34:38,724
dev… We have DevOps engineers that
use Control Plane, platform engineers,
594
00:34:38,824 --> 00:34:43,584
but we have people that are just vibe
coding and not know anything about…
595
00:34:43,604 --> 00:34:46,284
They don't know the if
statement, and they still deploy
596
00:34:46,284 --> 00:34:48,064
successfully on Control Plane.
597
00:34:48,164 --> 00:34:51,174
case in point, my younger
son, wanted to build an app.
598
00:34:51,214 --> 00:34:53,834
He never wrote a code, any
piece of code in his life.
599
00:34:54,084 --> 00:34:57,824
He was able to write a full game,
which was pretty impressive, and
600
00:34:57,824 --> 00:35:00,704
run it on Control Plane, and he
didn't even ask me how to do it.
601
00:35:00,804 --> 00:35:05,244
So he deployed the whole game with
a back end, and, I was shocked.
602
00:35:05,284 --> 00:35:08,574
You know, I, I helped develop the
product, and I was shocked at,
603
00:35:08,624 --> 00:35:12,174
at, at what he was able to do, and
he's never written a line of code
604
00:35:12,194 --> 00:35:14,544
despite me wanting him to, to learn.
605
00:35:14,644 --> 00:35:15,664
But he was able to do it.
606
00:35:15,664 --> 00:35:19,294
So we have many people with
no coding experience that are
607
00:35:19,294 --> 00:35:20,674
able to be very successful.
608
00:35:20,774 --> 00:35:21,124
Bret (2): Yeah.
609
00:35:21,224 --> 00:35:23,844
Do you think that's a-- With AI, I mean,
I, I know my answer to this question,
610
00:35:23,844 --> 00:35:25,114
but, it's like a leading question.
611
00:35:25,114 --> 00:35:28,294
Do you think that with these agents
getting better and better and th-
612
00:35:28,304 --> 00:35:32,384
there's the… Now we got Cowork and,
and Claude Code built into people's
613
00:35:32,484 --> 00:35:35,674
Claude and ChatGPT subscriptions for
people that aren't technical, right?
614
00:35:35,674 --> 00:35:37,454
You don't have to use the TUI anymore.
615
00:35:37,554 --> 00:35:41,634
And so I feel like we're, we're heading to
a, pretty quickly to a place where non-IT
616
00:35:42,040 --> 00:35:45,780
staff are getting more and more power
to be able to potentially do things like
617
00:35:45,780 --> 00:35:48,910
vibe code their own app and deploy it on
the internet, and If they don't have the
618
00:35:51,187 --> 00:35:51,787
IT staff to help them manage it,
they can, they can at least get
619
00:35:51,787 --> 00:35:53,637
by with some, some simpler stuff.
620
00:35:53,687 --> 00:35:55,367
do you see that happening
on Control Plane too?
621
00:35:55,377 --> 00:35:56,807
It sounds like it is, since your, since
622
00:35:56,809 --> 00:35:57,439
Doron: 100%.
623
00:35:57,449 --> 00:36:01,619
We are, we are releasing a,
more consumer-oriented…
624
00:36:01,719 --> 00:36:02,679
I'll come out and say it.
625
00:36:02,699 --> 00:36:05,199
We are, the, shipping very soon.
626
00:36:05,299 --> 00:36:09,009
We're in the tail end of,
Vers- not Vercel, but, Lovable
627
00:36:09,189 --> 00:36:11,379
and Replit, Base44 killer.
628
00:36:11,479 --> 00:36:15,249
And why we're able to do what they
do, but they're not able to do
629
00:36:15,249 --> 00:36:17,989
what we do, is the coding agents.
630
00:36:18,089 --> 00:36:23,309
when you look at Replit, most of the
effort has been put into, Guardrails
631
00:36:23,529 --> 00:36:29,469
and skills that are just, wrappers,
assisting agents for, for the LLM.
632
00:36:29,569 --> 00:36:33,489
and, and those are now in the LLM
itself most of the, of the time.
633
00:36:33,589 --> 00:36:38,019
The heavy lifting is allowing you to
run on any cloud, letting you scale
634
00:36:38,029 --> 00:36:41,129
using a hundred different scaling
strategies, letting you fail over
635
00:36:41,129 --> 00:36:44,749
automatically, leveraging hundreds
of diff- the operational stuff.
636
00:36:44,849 --> 00:36:48,319
So we've been hard at work building
this operating system for six and a
637
00:36:48,319 --> 00:36:51,879
half years, and it's not something
you can vibe code, absolutely not.
638
00:36:51,979 --> 00:36:58,879
And so we built this operating system,
and for us to layer the, consumer-facing
639
00:36:58,979 --> 00:37:04,409
app builder is a lot easier than
for an, an app builder to create an
640
00:37:04,419 --> 00:37:06,499
operating system for running, anywhere.
641
00:37:06,599 --> 00:37:08,919
Replit is I, I played
with it a little bit.
642
00:37:09,019 --> 00:37:10,739
It's a, it's a good tool.
643
00:37:10,859 --> 00:37:14,489
I don't know that it will let
you scale to Netflix grade.
644
00:37:14,589 --> 00:37:18,629
I, I think what happens is, and I wrote
an article that I'm publishing, but many
645
00:37:18,629 --> 00:37:23,219
people, when they start scaling or need
security or need compliance, they get
646
00:37:23,249 --> 00:37:27,219
off of that vibe coding platform, where
Control Plane takes you all the way to
647
00:37:27,239 --> 00:37:29,839
Netflix grade cloud native maturity.
648
00:37:29,939 --> 00:37:35,186
You get the compliance, the security, the
scalability, the, unbreakable compute.
649
00:37:35,286 --> 00:37:37,696
Bret (2): I would just assume that
a lot of those platforms are not
650
00:37:37,706 --> 00:37:39,876
like, SOC 2, PCI, you know, HIPAA,
651
00:37:41,369 --> 00:37:42,419
Doron: HIPAA, right
652
00:37:42,527 --> 00:37:46,040
Bret (2): all the things that like a dec-
any decent sized company is gonna care
653
00:37:46,040 --> 00:37:49,480
about, and there's probably someone in
marketing vibe coding something on Lovable
654
00:37:49,480 --> 00:37:50,960
that's completely not up to standards.
655
00:37:51,040 --> 00:37:55,210
For me, my experience so far has been one
of the biggest challenges in like the vibe
656
00:37:55,220 --> 00:37:59,680
codings products out there, is they don't
really answer the data problem, right?
657
00:37:59,690 --> 00:38:02,870
Like, 'cause usually m- everyone that
I've talked to so far, like creating
658
00:38:02,870 --> 00:38:05,570
a dashboard is cute, and these are,
these are important things for teams.
659
00:38:05,640 --> 00:38:08,720
but th- th- there needs to
be data on that dashboard.
660
00:38:08,900 --> 00:38:12,680
There needs to be data in that app, and
it's usually existing cust- company data
661
00:38:12,890 --> 00:38:17,780
locked up somewhere, usually not behind
like a perfectly designed open portal
662
00:38:17,950 --> 00:38:23,480
with a proper API across every surface
with, with automatic, token delivery
663
00:38:23,490 --> 00:38:27,050
for people that request it to ins- Like,
there's just this whole infrastructure
664
00:38:27,050 --> 00:38:29,364
of cloud native that a lot of companies
665
00:38:29,364 --> 00:38:30,524
they haven't matured to yet.
666
00:38:30,814 --> 00:38:35,204
And that's to me, like building these vibe
coding platforms for companies, which I
667
00:38:35,214 --> 00:38:37,634
think, yeah, again, like we could probably
do a whole separate podcast on, but
668
00:38:37,634 --> 00:38:43,094
like that world is inherently necessary
that you have a very modern mature
669
00:38:43,094 --> 00:38:44,954
infrastructure before you can do that.
670
00:38:45,054 --> 00:38:50,629
' Cause a lot of it is about, automation
and security and encryption and, l-
671
00:38:50,629 --> 00:38:52,214
like you said, auditing and compliance.
672
00:38:52,214 --> 00:38:56,584
That's, that's where I live, and that's
where the vibe coded app, while it may
673
00:38:56,584 --> 00:39:01,154
not be stable or highly redundant, it has
to… It, it… Those things are almost
674
00:39:01,154 --> 00:39:03,254
like optional, maybe someday things.
675
00:39:03,254 --> 00:39:05,834
But what's not usually optional
is for this thing to be useful, I
676
00:39:05,834 --> 00:39:08,684
need to access that SQL database,
and how do I get that, right?
677
00:39:08,694 --> 00:39:10,564
How do I ensure that
that data doesn't leak?
678
00:39:10,564 --> 00:39:12,684
How do I make sure that
this is behind the firewall?
679
00:39:12,684 --> 00:39:15,744
Like, there's all those levels
of complexity that I don't see
680
00:39:15,744 --> 00:39:18,724
the Replitz and the Lovables of
the world ever truly tackling.
681
00:39:18,724 --> 00:39:21,274
So I think you're right that this is
probably… These, these solutions
682
00:39:21,274 --> 00:39:25,064
are probably gonna come more from
infrastructure companies like yourself
683
00:39:25,074 --> 00:39:31,057
rather than a, a startup that's focusing
on AI as a, as a sort of, magic button.
684
00:39:31,157 --> 00:39:33,037
So, I'm, I'm interested to get into that.
685
00:39:33,037 --> 00:39:36,197
So I know you brought some demos,
and we could talk about this product
686
00:39:36,217 --> 00:39:39,487
forever, but I, I feel like we've,
we've covered some of the questions
687
00:39:39,487 --> 00:39:41,077
that I wanted to, to know about.
688
00:39:41,177 --> 00:39:43,077
l- l- what are we gonna, what
are we gonna look at today?
689
00:39:43,177 --> 00:39:47,257
Doron: So I want to show you, I, I want
to do a tour around the platform, and
690
00:39:47,257 --> 00:39:52,577
I'll give a sneak peek at some of the
power you get right out of the box, and
691
00:39:52,677 --> 00:39:57,577
traverse the network boundaries, allow
you to run an app anywhere, even on-prem,
692
00:39:57,677 --> 00:40:01,777
that consumes any service of any cloud,
show you the observability, show you
693
00:40:01,777 --> 00:40:05,947
the audit trail, show you the Terraform,
capabilities and, and stuff like that.
694
00:40:05,947 --> 00:40:09,497
So just give you a general tour
so people know what exists.
695
00:40:09,527 --> 00:40:15,157
And, most people don't know that they
have at their fingertips so much power,
696
00:40:15,257 --> 00:40:17,227
and they keep struggling with Amazon.
697
00:40:17,327 --> 00:40:21,877
And, w-where you can get a hundred
x the productivity by leveraging,
698
00:40:21,917 --> 00:40:23,817
a, a platform like Control Plane.
699
00:40:23,917 --> 00:40:28,327
and not only that, save a bundle
because you're not running full EC2
700
00:40:28,367 --> 00:40:30,597
instances, you're running the millicores.
701
00:40:30,897 --> 00:40:35,077
So you can literally run your Bret
app for six-- five and a half cents a
702
00:40:35,077 --> 00:40:39,817
day, a day meaning twenty-four hours,
literally less than six cents a day.
703
00:40:39,917 --> 00:40:43,787
and yet people are spending money
on NAT gateways, load balancers and,
704
00:40:43,897 --> 00:40:47,247
Kubernetes nodes and pay hundreds
of dollars per month when they can
705
00:40:47,247 --> 00:40:48,857
be paying, cents on the dollar.
706
00:40:48,957 --> 00:40:50,007
And that's what I want to show.
707
00:40:50,107 --> 00:40:51,157
Boom questions?
708
00:40:51,257 --> 00:40:52,487
Bret (2): no, this is, this is a lot.
709
00:40:52,587 --> 00:40:56,077
That's, I'm trying to think of my
workflows and, like, how my workflows
710
00:40:56,087 --> 00:41:00,267
for creating infrastructure and managing
infrastructure need to adapt to this
711
00:41:00,267 --> 00:41:02,667
model, 'cause it's, it's flexible enough.
712
00:41:02,667 --> 00:41:04,057
you have click ops, right?
713
00:41:04,117 --> 00:41:09,827
but it seems so easy to hop back and forth
between the click ops, 'cause it feels
714
00:41:09,827 --> 00:41:14,777
like the click ops is backed because you
have that versioning and the audit trail.
715
00:41:14,877 --> 00:41:18,817
you don't, it doesn't, it looks like
you've removed the risk of the, sort of
716
00:41:18,817 --> 00:41:23,577
the rogue click that now is no longer
compatible or, or can- isn't tracked in
717
00:41:23,577 --> 00:41:25,827
a way that you can update your Terraform.
718
00:41:25,827 --> 00:41:28,707
this is the classic problem of, we're
git- we're trying to do GitOps, and
719
00:41:28,707 --> 00:41:33,017
we're putting all of our infrastructure
in, in Git, and we're storing changes
720
00:41:33,017 --> 00:41:35,767
there, and we've maybe got some
automation for Terraform plans and
721
00:41:35,767 --> 00:41:38,697
applies, or we've got, we've got some
stuff going on there, and that's the
722
00:41:38,697 --> 00:41:39,647
only way we're supposed to do it.
723
00:41:39,647 --> 00:41:43,597
And then we get some person that shows
up and in an emergency or because they
724
00:41:43,597 --> 00:41:48,177
didn't know or whatever, they go into
the AWS console and make a change,
725
00:41:48,457 --> 00:41:54,387
and now I'm bifurcated, and I have
no path to success because AWS isn't
726
00:41:54,387 --> 00:41:58,087
gonna really easily export, it's not
gonna to export Terraform for me.
727
00:41:58,357 --> 00:42:02,787
And so I have to figure out what they
changed before, I risk blowing their
728
00:42:02,787 --> 00:42:05,127
stuff away with my future Terraform apply.
729
00:42:05,227 --> 00:42:07,837
And so we, we've always had this
challenge in infrastructure of,
730
00:42:07,887 --> 00:42:09,347
sometimes we do need the click ops.
731
00:42:09,347 --> 00:42:12,997
Sometimes we ne- do need to be able to go
into a GUI really quick, troub- especially
732
00:42:12,997 --> 00:42:15,377
when you're, like, troubleshooting or
just trying to recover from outage.
733
00:42:15,637 --> 00:42:19,477
You don't wanna stare at a bunch
of l- code in TOML forever.
734
00:42:19,777 --> 00:42:23,357
So you're, you're usually in the, in
the dis- in this GUI app trying to
735
00:42:23,357 --> 00:42:26,447
figure things out, but you also know
that y- it's, you can't touch it.
736
00:42:26,647 --> 00:42:29,247
It has to be read-only because you
need to make your changes somewhere
737
00:42:29,247 --> 00:42:30,357
else, and you're so nervous.
738
00:42:30,357 --> 00:42:32,977
So it feels like you've kinda
thought about that a little bit.
739
00:42:33,177 --> 00:42:35,577
Doron: Yeah, and everything,
like I said, everything you
740
00:42:35,577 --> 00:42:38,587
can get as, YAML or, or JSON.
741
00:42:38,687 --> 00:42:42,547
But here is our app running, and
so we give you a more consumer-y
742
00:42:42,567 --> 00:42:44,057
interface to this thing.
743
00:42:44,157 --> 00:42:47,999
but the bottom line, it's really backed
by the control plane API, and the control
744
00:42:47,999 --> 00:42:54,809
plane API lets you run anywhere, and with,
with determinism, and, and it's the same.
745
00:42:54,809 --> 00:42:57,699
You c-- Again, you can run it on
your Raspberry Pi or Dell machine.
746
00:42:57,799 --> 00:43:01,619
And the cloud wormhole, which I
haven't demonstrated, allows you to
747
00:43:01,619 --> 00:43:07,149
very, very easily connect to an RDS
instance in a VPC or connect from
748
00:43:07,149 --> 00:43:11,439
a, the seven different locations
here to my own Redis on my machine.
749
00:43:11,539 --> 00:43:14,829
And we have a service catalog
where you can run above the cloud.
750
00:43:14,879 --> 00:43:19,379
If you want to run CockroachDB or
Cassandra or really any open source
751
00:43:19,389 --> 00:43:22,669
project, we certify these s-services.
752
00:43:22,769 --> 00:43:27,199
Like let's say I want to run Hermes
Agent or Langfuse or Keycloak or, you
753
00:43:27,249 --> 00:43:32,309
name it, Postgres, Mongo You can run
them at the cost of the infrastructure
754
00:43:32,409 --> 00:43:36,519
instead of paying a premium to RDS.
755
00:43:36,539 --> 00:43:39,719
You pay double what the compute
is, but Control Plane lets you
756
00:43:39,719 --> 00:43:43,689
do backups, lets you do leaders
election, lets you do multi-master
757
00:43:43,689 --> 00:43:45,669
replication with different add-ons.
758
00:43:45,769 --> 00:43:48,839
You can run Ollama, you can
run whatever you want to run.
759
00:43:48,939 --> 00:43:54,571
and you can conversationally say, "Hey,
get me an N8n, run me a Hermes agent,
760
00:43:54,581 --> 00:44:00,248
run me, know, OpenBaO or run me whatever,
Postgres very, very easily." you,
761
00:44:00,288 --> 00:44:02,038
you can do all of, all of that stuff.
762
00:44:02,038 --> 00:44:03,998
And again, you can run anywhere.
763
00:44:04,098 --> 00:44:04,458
Bret (2): Yeah
764
00:44:04,510 --> 00:44:06,700
Doron: w-we're not going to do
an exhaustive demonstration.
765
00:44:06,700 --> 00:44:10,340
one of the things that, that people
care about is security, and you
766
00:44:10,340 --> 00:44:14,940
can set very granular policies of
who is allowed to do exactly what.
767
00:44:14,950 --> 00:44:19,360
You can say, this agent is allowed only
to push image but not delete an image.
768
00:44:19,460 --> 00:44:23,600
This Lisa can only, read a
certain value but not write.
769
00:44:23,700 --> 00:44:26,090
Secrets are only available to X and Y.
770
00:44:26,190 --> 00:44:28,360
So everything is very, very granular.
771
00:44:28,460 --> 00:44:31,170
and th-there is a lot, a lot more.
772
00:44:31,270 --> 00:44:32,850
You can set custom domains.
773
00:44:32,950 --> 00:44:35,960
we have customers with twenty
thousand different domains, and
774
00:44:35,960 --> 00:44:38,300
they run perfectly on Control Plane.
775
00:44:38,400 --> 00:44:44,200
It gives you the confidence to operate
above the clouds without being bogged down
776
00:44:44,300 --> 00:44:46,770
by the complexity of any particular cloud.
777
00:44:46,770 --> 00:44:49,380
And the thing I wanted to show,
because we have this thing called
778
00:44:49,420 --> 00:44:52,273
Capacity AI That is by default on.
779
00:44:52,373 --> 00:44:57,463
If you look at the spend, you're spending
twenty-five millicores 'cause the system
780
00:44:57,463 --> 00:45:01,953
learned over time that Bret video game
only needs twenty-five one-thousandth
781
00:45:01,953 --> 00:45:04,183
of a CPU and thirty-two megs of RAM.
782
00:45:04,283 --> 00:45:08,553
If you go to the control plane pricing
and plug in-- And you can bring your
783
00:45:08,563 --> 00:45:12,523
own compute, or you can use control
plane compute, or you can do both.
784
00:45:12,623 --> 00:45:16,253
So twenty-five millicores and
thirty-two megs of RAM cost you a
785
00:45:16,253 --> 00:45:18,173
dollar seventy-eight per month, period.
786
00:45:18,183 --> 00:45:20,893
You don't pay for load balancers,
you don't pay for nodes,
787
00:45:20,893 --> 00:45:21,893
you don't pay for anything.
788
00:45:21,913 --> 00:45:22,933
That's all you pay.
789
00:45:23,033 --> 00:45:24,353
We charge you by the second.
790
00:45:24,453 --> 00:45:28,243
let's say a full hour would cost
you, No, sorry, a full day would
791
00:45:28,243 --> 00:45:30,503
cost you less than six cents.
792
00:45:30,603 --> 00:45:35,493
So if you ran the Bret app for a
full twenty-four hours in a location,
793
00:45:35,593 --> 00:45:37,363
it would cost you six cents.
794
00:45:37,363 --> 00:45:41,413
That's why I'm saying sometimes running
it in more locations is even cheaper
795
00:45:41,513 --> 00:45:45,003
than running it in a single location,
'cause if you were to stand up a EKS
796
00:45:45,033 --> 00:45:49,003
cluster, you would pay hundreds of
dollars in a month to heat up the planet
797
00:45:49,043 --> 00:45:50,843
Earth or to make Jeff Bezos richer.
798
00:45:50,943 --> 00:45:55,743
We let you pay for what you eat,
not for heating up the planet Earth.
799
00:45:55,843 --> 00:45:57,463
So extremely cost-effective
800
00:45:57,563 --> 00:45:59,713
Bret (2): In that, in the,
the workflows you were showing
801
00:45:59,905 --> 00:46:02,882
as you would, as you were doing this
stuff, I w- guess one of my questions is
802
00:46:02,932 --> 00:46:07,972
Deployment configurations and design can
often be, hard for teams, especially when
803
00:46:07,972 --> 00:46:09,542
they start to adopt Kubernetes, right?
804
00:46:09,542 --> 00:46:13,742
Because then they have to pick Flux
or Argo, and they have to decide on a
805
00:46:13,872 --> 00:46:17,682
particular way to deploy that, and then
they have to configure it all correctly,
806
00:46:17,682 --> 00:46:20,756
and then when they have b- a bunch of
different apps, yeah, so my premise was,
807
00:46:20,816 --> 00:46:25,286
like one of the, one of the challenges
that I, I train people on and is a lar-
808
00:46:25,336 --> 00:46:28,776
a d- decent amount of my consulting
over the last six years has been once
809
00:46:28,786 --> 00:46:32,706
teams adopt Kubernetes, there becomes
this deployment complexity because it's
810
00:46:32,716 --> 00:46:34,376
not enough to just have Kubernetes.
811
00:46:34,376 --> 00:46:38,266
Then, then you need, your code's stored
in a place, GitHub, GitLab, whatever, and
812
00:46:38,266 --> 00:46:39,716
then you gotta connect all that together.
813
00:46:40,006 --> 00:46:44,716
And, in the old days before containers,
a- and even when we first, first
814
00:46:44,716 --> 00:46:48,016
started using containers, it was very
much "I'm gonna write a CI job that
815
00:46:48,016 --> 00:46:51,866
runs kubectl apply," or, "I'm gonna
run a Docker run, and, and it's gonna
816
00:46:51,916 --> 00:46:53,136
connect to the server from my CI."
817
00:46:53,413 --> 00:46:55,623
And then we grew up, and we
realized we maybe need a more
818
00:46:55,693 --> 00:46:59,553
deterministic methodology, and then
we started adopting Argo and Flux.
819
00:46:59,653 --> 00:47:03,553
And, and so for the longest time,
I've been f- I've been advocating
820
00:47:03,553 --> 00:47:04,713
and teaching those technologies.
821
00:47:04,713 --> 00:47:07,823
We call it GitOps, but it doesn't
necessarily have to be labeled that.
822
00:47:07,903 --> 00:47:11,453
and I'm curious how you, how
your platform works with that.
823
00:47:11,463 --> 00:47:14,923
Does that m- It, it… You've got a
lot of, glue there that feels like
824
00:47:14,923 --> 00:47:18,563
it makes a lot of these rough edges
streamlined and it's almost like you're
825
00:47:18,563 --> 00:47:21,683
applying opinionated defaults, which I
love because I'm a, I'm a very much a,
826
00:47:21,953 --> 00:47:23,553
an opinionated defaults kind of guy.
827
00:47:23,653 --> 00:47:28,483
when it comes to like the code in
the repos, and is it as easy as
828
00:47:28,483 --> 00:47:31,973
someone on your platform pointing
to repos, and then it figures out
829
00:47:31,983 --> 00:47:33,543
how to get it into Kubernetes?
830
00:47:33,583 --> 00:47:36,193
do they need to even worry
about Argo at this point?
831
00:47:36,203 --> 00:47:39,293
'Cause you've been saying things like
deploy this app, and it's doing it.
832
00:47:39,323 --> 00:47:40,383
I don't know how it's doing it.
833
00:47:40,383 --> 00:47:41,823
I know it's, I know it's
running on Kubernetes.
834
00:47:42,063 --> 00:47:44,753
But what's that, that deployment
look like for Control Plane?
835
00:47:44,753 --> 00:47:45,613
Is it automating it?
836
00:47:45,633 --> 00:47:47,423
Is it, is it doing Argo for you?
837
00:47:47,523 --> 00:47:49,343
Doron: So it c-- you can use Argo.
838
00:47:49,913 --> 00:47:55,206
So we have, a CRD, a control plane
CRD, so you can have a cluster and,
839
00:47:55,306 --> 00:47:58,196
use Argo or Flux very naturally.
840
00:47:58,296 --> 00:48:02,226
the way it works, so you said, "I'm not
sure how it works," so let me explain.
841
00:48:02,326 --> 00:48:04,466
you get the YAML.
842
00:48:04,496 --> 00:48:05,956
Let me share real quick.
843
00:48:06,056 --> 00:48:07,786
and again, YAML is just one of many.
844
00:48:07,786 --> 00:48:10,636
So if… let's take this
guy for-- as an example.
845
00:48:10,736 --> 00:48:12,646
I can export, this YAML.
846
00:48:12,776 --> 00:48:14,496
So you can see the kind is workload.
847
00:48:14,506 --> 00:48:19,036
It's a new kind that doesn't exist on
Kubernetes, and it has the different,
848
00:48:19,056 --> 00:48:23,586
like what's the memory, what's the
scaling strategy, what GVC does it go on?
849
00:48:23,686 --> 00:48:28,176
And you j-just say CPLN apply
and give it, minus F and give
850
00:48:28,176 --> 00:48:30,013
it the YAML, and it deploys it.
851
00:48:30,113 --> 00:48:33,413
Like I said, we have other ways
to deploy, but at the end of
852
00:48:33,413 --> 00:48:36,133
the day, we have a data service.
853
00:48:36,173 --> 00:48:39,646
We have an-- we have the control
plane API, and you make a call to
854
00:48:39,646 --> 00:48:43,783
the plane itself is, is running
on Amazon, Google, and Azure, and
855
00:48:43,883 --> 00:48:45,643
the-- our data is distributed.
856
00:48:45,743 --> 00:48:51,786
It calls a component we call the which
is a control plane, Go-based application.
857
00:48:51,886 --> 00:48:55,476
It runs on the edge, we
call them edge clusters.
858
00:48:55,486 --> 00:48:59,056
So you can have one cluster, or in
our case, we have one, two, three,
859
00:48:59,056 --> 00:49:01,496
four, five, six, seven clusters.
860
00:49:01,596 --> 00:49:03,320
These are different clusters.
861
00:49:03,420 --> 00:49:05,090
They can have hundreds of nodes.
862
00:49:05,190 --> 00:49:09,850
we provide clusters that are, cloudless,
meaning we provide clusters, or you can
863
00:49:09,850 --> 00:49:13,510
bring your own, you can bring your own
cluster like I did in the Ron office.
864
00:49:13,610 --> 00:49:18,130
I created the Kubernetes brain in the
cloud, but I could have run OpenShift or
865
00:49:18,140 --> 00:49:22,100
EKS or whatever, in the local environment
The-- what you need is a Kubernetes
866
00:49:22,140 --> 00:49:27,070
cluster with the actuator and a few other
components like the, the log, collector,
867
00:49:27,080 --> 00:49:28,550
the metrics collector, and so on.
868
00:49:28,650 --> 00:49:32,450
But we control planify a cluster,
and then it becomes part of
869
00:49:32,450 --> 00:49:33,800
that global virtual cloud.
870
00:49:33,900 --> 00:49:38,500
We use NATs under the covers to have
our, control plane, if you will,
871
00:49:38,660 --> 00:49:44,070
communicate the desired state to all the
clusters, and they all take the desired
872
00:49:44,070 --> 00:49:46,550
state and actuate it in the cluster.
873
00:49:46,650 --> 00:49:51,040
So under the cover, you have, stateful
sets or, deployments or, pods and
874
00:49:51,050 --> 00:49:55,340
all the Kubernetes goodness that is
happening, but it has been abstracted.
875
00:49:55,440 --> 00:49:59,420
And if you want to see the Kubernetes
resources and, and it's a bring your
876
00:49:59,420 --> 00:50:04,650
own Kubernetes like I have here, you
can get the kubeconfig and go edit
877
00:50:04,920 --> 00:50:06,650
or use the dashboard and go edit.
878
00:50:06,750 --> 00:50:10,660
But we… You noticed we didn't
have to issue kubectl apply commands
879
00:50:10,660 --> 00:50:14,940
and all that because there is an
actuator component in this cluster
880
00:50:15,040 --> 00:50:18,680
that went and did the actuation
of the desired state Makes sense.
881
00:50:18,680 --> 00:50:24,390
And also, if we are down, the, the cluster
operates autonomously and serves traffic.
882
00:50:24,640 --> 00:50:29,340
Maybe you can't upgrade the version
of the workload, but A, we're very
883
00:50:29,340 --> 00:50:31,910
highly, redundant and highly available.
884
00:50:32,010 --> 00:50:34,170
so we're very, very unlikely to go down.
885
00:50:34,450 --> 00:50:37,820
But if we were to go down, we are the
control plane, not the data plane.
886
00:50:38,080 --> 00:50:41,780
The data plane is where the data,
flows, and you mentioned that earlier.
887
00:50:41,880 --> 00:50:43,360
so hopefully that gives you kind
888
00:50:43,514 --> 00:50:44,124
Bret (2): the goal, right?
889
00:50:44,124 --> 00:50:47,554
Is like the control plane never,
never takes down the data plane
890
00:50:47,654 --> 00:50:49,034
when it's, when it's unavailable.
891
00:50:49,034 --> 00:50:49,364
Yeah.
892
00:50:49,566 --> 00:50:50,196
Doron: Exactly.
893
00:50:50,246 --> 00:50:53,416
A, we're extremely… Yeah,
and we test everything, like,
894
00:50:53,436 --> 00:50:54,976
like I can't even tell you.
895
00:50:55,076 --> 00:50:59,816
From day one, we created what we call
the Observer Project, and it does
896
00:50:59,826 --> 00:51:04,146
twenty-four seven millions of tests
simulating node failure, multi-node
897
00:51:04,146 --> 00:51:08,726
failure, cluster failure, AZ failure,
region failure, whole cloud failure.
898
00:51:08,826 --> 00:51:10,386
And we do, fuzzing.
899
00:51:10,486 --> 00:51:15,436
We do random failure, introduction of
failure modes with a core objective
900
00:51:15,486 --> 00:51:17,336
of making sure you never go down.
901
00:51:17,436 --> 00:51:20,796
So one of the things you get with
Control Plane is mainframe-grade
902
00:51:20,936 --> 00:51:23,376
availability over commodity infrastructure
903
00:51:23,476 --> 00:51:26,561
Bret (2): All right Yeah, the
fractional CPU, stuff is, is
904
00:51:26,571 --> 00:51:27,931
pretty flexible and pretty awesome.
905
00:51:27,931 --> 00:51:32,101
When you're running small stuff and
you're a small company and every single
906
00:51:32,101 --> 00:51:36,161
workload you add has, this minimum
cost to it, and Even when you try to
907
00:51:36,161 --> 00:51:40,701
run, small instances in an EC2 cluster,
you're limited on how small you can go,
908
00:51:40,721 --> 00:51:46,181
and then you're inherently bottlenecked
there if you ever get any decent traffic
909
00:51:46,201 --> 00:51:48,321
because it, it doesn't know how to…
910
00:51:48,361 --> 00:51:50,541
You, you have to build a lot of
intelligence in in order for it to
911
00:51:50,541 --> 00:51:54,771
auto-scale up and correctly change
the node size, if you need more memory
912
00:51:54,771 --> 00:51:59,171
because, a classic example is, a legacy
app with a PDF export and someone
913
00:51:59,171 --> 00:52:03,481
decides to PDF export a report that isn't
batched properly, so then it consumes
914
00:52:03,481 --> 00:52:06,761
all the memory on the server for one
report, and then the, and then your tiny
915
00:52:06,761 --> 00:52:09,631
little app crashes the whole thing all
because you wanted to print a report.
916
00:52:09,631 --> 00:52:13,101
So there's always, there's always, sizing
challenges because you just want things,
917
00:52:13,111 --> 00:52:17,331
especially when, when it's, a small
business kind of situation where, they,
918
00:52:17,341 --> 00:52:23,531
you tell them, $500 a month for something
that they consider not worth all that is a
919
00:52:23,531 --> 00:52:27,131
hard sell when you're like, "Well, that's
what it takes to be minimum redundant
920
00:52:27,131 --> 00:52:29,041
across regions in this particular cloud."
921
00:52:29,141 --> 00:52:32,531
And the idea that I can say, "Well,
you're, you're only using this
922
00:52:32,531 --> 00:52:35,961
app internally, so we don't even
need a single CPU. We need a half
923
00:52:35,961 --> 00:52:37,131
of one. We need a third of one,"
924
00:52:37,231 --> 00:52:40,951
Doron: Yeah, we need a fif-fiftieth
of one or, one, one-twentieth of one.
925
00:52:41,051 --> 00:52:45,701
Yeah, and that's… And you can now
give people redundant availability for
926
00:52:45,701 --> 00:52:47,361
three dollars, five dollars a month.
927
00:52:47,461 --> 00:52:50,941
you can run an app for five
dollars a month that is-- has the
928
00:52:50,941 --> 00:52:52,951
availability of a real enterprise.
929
00:52:53,261 --> 00:52:54,011
Bret (2): how do people get started?
930
00:52:54,021 --> 00:52:57,151
They go to Control Plane.com
and sign up for an account?
931
00:52:57,251 --> 00:52:57,616
Doron: Yeah.
932
00:52:57,616 --> 00:52:58,971
Yeah, it's very easy.
933
00:52:59,071 --> 00:53:02,901
so they go to Control Plane, they
click sign up, they follow the prompts.
934
00:53:02,941 --> 00:53:06,721
we ask for a credit card, and I
find some people get intimidated.
935
00:53:06,821 --> 00:53:10,331
we're happy to give you,
especially to your listeners,
936
00:53:10,431 --> 00:53:15,751
shoot me an email directly, Doron,
D-O-R-O-N, @ Control Plane.com.
937
00:53:16,101 --> 00:53:19,791
I'll give you, basically a, a
free month to experiment with.
938
00:53:19,791 --> 00:53:23,331
Of course, don't do crypto mining and
don't do crazy stuff, but happy to
939
00:53:23,331 --> 00:53:25,231
let you experiment on the platform.
940
00:53:25,331 --> 00:53:30,741
Even if we were to charge you, you can
run so cost effectively that unless you
941
00:53:30,741 --> 00:53:34,211
reach five dollars in spend, which is a
lot on Control Plane, we don't charge you.
942
00:53:34,211 --> 00:53:37,921
So if you're under five dollars a
month, we don't even charge you 'cause
943
00:53:37,921 --> 00:53:39,531
it's not worth it to send to Stripe.
944
00:53:39,631 --> 00:53:43,411
So many people can run real projects on
Control Plane for less than five bucks.
945
00:53:43,511 --> 00:53:47,331
There is no platform fee, there's no
per seat fee, there's just usage fee,
946
00:53:47,431 --> 00:53:49,051
and it's very, very cost effective.
947
00:53:49,221 --> 00:53:51,001
Bret (2): That's what I used
to use Heroku for, so now m-
948
00:53:51,261 --> 00:53:52,541
now maybe you're my new Heroku
949
00:53:52,641 --> 00:53:54,301
Doron: Think of us as a non-toy Heroku.
950
00:53:54,401 --> 00:53:54,701
Bret (2): Yeah
951
00:53:54,759 --> 00:53:59,479
Doron: the non-toy, replace your, Heroku
with, the, the, the cloud du jour.
952
00:53:59,579 --> 00:54:03,089
But, we give you all the power
of all the clouds, but, with the
953
00:54:03,119 --> 00:54:05,119
ease of use of Heroku or better,
954
00:54:05,219 --> 00:54:06,529
Bret (2): thank you so
much for being here, Doron.
955
00:54:06,629 --> 00:54:07,179
Doron: thank you.
956
00:54:07,189 --> 00:54:08,759
Really enjoyed, the conversation.
957
00:54:08,769 --> 00:54:10,429
You asked great questions.
958
00:54:10,519 --> 00:54:12,029
super happy we connected
959
00:54:12,129 --> 00:54:13,349
Bret (2): And we'll
see you guys next time.
960
00:54:13,449 --> 00:54:13,689
Ciao.