Opens in a new tab
vmblog logo 2024 wht (updated)

Section 2023 Predictions: The Future of Kubernetes – Why Observability, Security and Cost are Key in 2023

Share: 

David Marshall | Published: December 16, 2022
vmblog predictions 2023

 

Industry executives and experts share their predictions for 2023.  Read them in this 15th annual VMblog.com series exclusive.

The Future of Kubernetes: Why Observability, Security and Cost are Key in 2023

By Stewart McGrath, CEO and Co-founder of Section

The cloud native landscape is booming and Kubernetes is clearly the central project around which this growth is coalescing. The need for better automation to deploy, scale and manage containerized applications is apparent. In the same way that Linux has become the default open-source operating system for the management of software and hardware today, Kubernetes has become the equivalent for the orchestration of containers.

Businesses are clamoring for the benefits of a Kubernetes platform to manage their containerized applications so they can deliver their ideas faster and with more control. As they find this flexibility and feature set from managed Kubernetes services, do-it-yourself Kubernetes platforms will become a thing of the past. With the rise of Kubernetes as the standard “operating system” for containers, we see an adjacent rise in concerns over performance, security, availability and observability to manage their production Kubernetes workloads.

This feels remarkably like an interim phase in the Kubernetes evolution. We expect this operating system to continue to be abstracted away from end users. As a result, businesses will begin to differentiate themselves by the quality (and speed) of turning their ideas into software that will run on these Kubernetes platforms. 

As Kubernetes evolves, many organizations will find themselves wholly unprepared to face a few key deployment challenges. From as-a-service platforms or managed services like Rafay and AWS EKS to point solutions for customers to deploy their own managed (or partly managed) services, I predict we’ll see observability, security and cost emerge as the three most important themes businesses will seek to address in the new year.

Observability

The Kubernetes / cloud native market has, arguably, had a stronger historical focus on the developer side of the DevOps paradigm – the plan, code, build and test aspects of application delivery. In a way that makes sense. You first need to develop the tools, techniques, and processes to get containerized applications to market.

That pendulum is now swinging toward the Ops side. As cloud native applications become both more prevalent and more complex, it’s natural to take a hard look at how best to release, deploy, operate and monitor workloads. That last aspect – monitoring and observability – is particularly critical for companies that are looking toward distributed, multi-cluster or clusterless deployments. In simple terms, you can’t manage and optimize what you can’t see.

Monitoring is essential for the effective operation of any modern application. However, monitoring complexity increases significantly when faced with instrumenting distributed systems. There’s a long list of CNCF projects for teams looking to improve observability, like OpenMetrics, OpenTelemetry and Prometheus, or managed telemetry services and point solutions, like Kentik, New Relic and Dynatrace, to name a few. We expect to see heightened interest in the observability and management of distributed applications in the coming year.

Security

The Kubernetes Project includes excellent documentation with respect to managing workload security on a Kubernetes cluster as well as the security of the cluster and API. Implementation and management of the security structure for Kubernetes clusters can, however, be both challenging and time consuming. As such, we anticipate a continuing rise of services to support Kubernetes security management from the “shift left” offerings of those like Snyk to broader services like Sysdig. 

And, while it’s great to see offerings coming from the shift left movement, we can see a world in the very near future where the point security solutions are rolled into managed Kubernetes solutions. I anticipate these solutions will not only contemplate security observability, pod security, API and server bypass security, RBAC, and secrets management but also core elements such as proper DNS and TLS network configuration and DDoS protection Layers 3, 4 and 7 – all at global distribution and with multi-tenancy.

Cost

Which finally brings us to cost. While this is an evergreen concern for IT, the container and cloud native space is experiencing an epiphany that it can quickly become very expensive to run workloads at scale. A recent CNCF survey confirmed this pain, finding significant increases in cloud and Kubernetes-related bills for surveyed organizations, with 68% of respondents reporting increased Kubernetes-managed workload costs. Among those, half saw costs jump more than 20% during the year.

Two factors conspire here: The first is that the time and specialist resources needed to manage (upgrade, optimize and debug) the Kubernetes environment grow over time and can be difficult to satisfy quickly and cost-effectively. The second is that a containerized environment can be complex (and therefore costly) to operate. Efficiency can be elusive, especially with hyperscalers, leading to the dreaded surprise bill.

Managed Kubernetes offerings such as EKS, AKS and GKE all offer some help for teams to avoid being completely tied down by Kubernetes operation issues, reducing the need for specialist Kubernetes resources. However, these highly opinionated systems also come with their own hooks and can lead to serious cloud vendor lock-in.

A variety of services are just starting to emerge to help teams manage the cost of their own Kubernetes environments, like Cast, CloudZero and Apptio, as well as a variety of others that provide some combination of cost visibility / observability or cost reduction suggestions. These services are typically driven by AI engines or, to a much lesser extent, plug-in tools that act within your cloud account to manage cluster costs. I expect we’ll begin to see these services become part of fully managed Kubernetes solutions.

The Kubernetes ecosystem continues to gain wide adoption, and with that growth and evolution inevitably come new challenges. As I look ahead, observability, security and cost are three big themes I expect we’ll see organizations face and seek to address during the next year.

##

ABOUT THE AUTHOR

Stewart-McGrath 

Stewart McGrath is the CEO and Co-founder of Section, a Cloud-Native Platform as a Service (PaaS) that continuously optimizes the orchestration of global infrastructure to run distributed applications at the right place and time, always. With extensive experience leading companies in the technology space, Stewart’s passion for building teams focused on bringing technologies to market drove him to co-found and lead Section. As applications continue to evolve and end-user demands for performance, security, and functionality increase, he envisions a world where developers are unencumbered by infrastructure and a better Internet is powered by app distribution and the Edge.