docker federal summit 2017 general session

83
Docker Federal Summit 2017

Upload: docker-inc

Post on 21-Jan-2018

1.031 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Docker Federal Summit 2017 General Session

Docker Federal

Summit 2017

Page 2: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Thank You Sponsors

Platinum

Gold

Silver

Lunch Happy Hour

Page 3: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Thank You to our Federal Agency and Community Speakers

Page 4: Docker Federal Summit 2017 General Session

Thank You Docker Community

• Summit Attendees

• Summit Speakers

• Summit Sponsors

• Meetup Organizers

• Mentors

• Docker Team

• Customers

• Partners

• Docker Captains

• Contributors & Maintainers

Page 5: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Driving Docker Momentum in the Industry

Docker

Hosts

14MGrowth in Docker

job listings

77K%Image pulls

Over 390K%

Growth

12BDocker

apps

900KProject

Contributors

3300

Page 6: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Building a New Industry

Docker Pulls

Page 7: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Communities Helping Communities

Page 8: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Healing heroes one

family at a time

www.bouldercrestretreat.org

Page 9: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Thank you for your

participation today.

Together we are sending

two families to Boulder

Crest for a weekend of

healing.

Visit their table on the 8th

floor to learn more

Docker 2017 - Confidential

Give Back Together

www.bouldercrestretreat.org

Page 10: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Federal Summit Logistics

• All meals and happy hour

• General session

• Platinum sponsor talks

• Sponsor expo

7th Floor

• Coffee Break

• Learning Lab: Hands on Tutorials

• Gold sponsor talks

• Sponsor expo

8th Floor

Page 11: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Iain Gray

SVP Customer Success

Page 12: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Docker In Every Industry

Service

ProviderTec

h

Public

SectorInsurance

Healthcare

& Science

Financial

Services

Page 13: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Being Used for Critical Apps

To keep planes in the air

To keep soldiers away

from landmines

To cure

diseases

To process $ billions in

transactions per day

To keep the largest ecommerce

websites running

To power the largest

financial institutions

To monitor fire

alarms

To keep healthcare systems

running smoothly

Page 14: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Docker in Public Sector

Page 15: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

The Myth of Bi-Modal IT

MICROSERVICES TRADITIONAL APPS

Cloud or New

InfrastructureYou are either here..

Old Infrastructure …or here

Page 16: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

There is only one mode

FAST

Page 17: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Enabling a Journey

…you should be past AND future proof

MICROSERVICESAGILE TRADITIONAL

APPSTRADITIONAL APPS

Cloud or New

Infrastructure

Old

Infrastructure

Page 18: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

The Reality Is Diverse

Virtual

IT Ops

Windows

Cloud

Microservices

Bare Metal

Developers

Traditional

Linux

On Premises

Page 19: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

What is Required for Modern IT

1

2

3

A secure and reliable base platform

Security across the entire supply chain

Leverage an ecosystem that

extends these principles

Page 20: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

The IT Reality is Diverse Apps and Infrastructure

Traditional

Third Party

Microservices

Applications Infrastructure

Page 21: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Start With a Secure Base and Containerize Apps

Traditional

Third Party

Microservices

DEVELOPERS IT OPERATIONS

Page 22: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Standardize and Secure the Supply Chain from Dev

Image RegistrySecurity scan& sign

Traditional

Third Party

Microservices

docker store

DEVELOPERS

Page 23: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Secure the Software Supply Chain to Production

Image RegistrySecurity scan& sign

Traditional

Third Party

Microservices

docker store

DEVELOPERS IT OPERATIONS

Control Plane

Page 24: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Nathan McCauley

Director Security Engineering

Page 25: Docker Federal Summit 2017 General Session

Usable

SecuritySecure defaults with tooling that is native to both dev

and ops

The Key Components of Container Security

2

5

Infrastructure

Independent

Trusted

Delivery

Safer Apps

Everything needed for a full functioning app is delivered

safely and guaranteed to not be tampered with

All of these things in your system are in the app

platform and can move across infrastructure without

disrupting the app

+

+

=

Page 26: Docker Federal Summit 2017 General Session
Page 27: Docker Federal Summit 2017 General Session
Page 28: Docker Federal Summit 2017 General Session

What is Least

Privilege

Infrastructure?

Page 29: Docker Federal Summit 2017 General Session

What is Least

Privilege?

Page 30: Docker Federal Summit 2017 General Session

A process must be able to access

only the information and

resources that are necessary for

its legitimate purpose. Principle of Least Privilege

Page 31: Docker Federal Summit 2017 General Session

Infrastructure that follows the

principle of least privilege in the

strictest manner possible.

Least Privilege Infrastructure

Page 32: Docker Federal Summit 2017 General Session

Why Least Privilege?

Page 33: Docker Federal Summit 2017 General Session

Blast Radius

Reduction

Page 34: Docker Federal Summit 2017 General Session
Page 35: Docker Federal Summit 2017 General Session
Page 36: Docker Federal Summit 2017 General Session
Page 37: Docker Federal Summit 2017 General Session
Page 38: Docker Federal Summit 2017 General Session
Page 39: Docker Federal Summit 2017 General Session

My Apartment

Neighbor’s Apt

Garage

Neighbor’s Car

Page 40: Docker Federal Summit 2017 General Session

My Apartment

Neighbor’s Apt

Garage

Neighbor’s Car

Page 41: Docker Federal Summit 2017 General Session

My Apartment

Neighbor’s Apt

Garage

Neighbor’s Car

Page 42: Docker Federal Summit 2017 General Session

My Apartment

Neighbor’s Apt

Garage

Neighbor’s Car

Page 43: Docker Federal Summit 2017 General Session

My Apartment

Neighbor’s Apt

Garage

Neighbor’s Car

Page 44: Docker Federal Summit 2017 General Session
Page 45: Docker Federal Summit 2017 General Session
Page 46: Docker Federal Summit 2017 General Session
Page 47: Docker Federal Summit 2017 General Session
Page 48: Docker Federal Summit 2017 General Session

How do we achieve

Least Privilege

Infrastructure?

Page 49: Docker Federal Summit 2017 General Session

Reduced Privilege

Page 50: Docker Federal Summit 2017 General Session
Page 51: Docker Federal Summit 2017 General Session

Neighbor’s Car

Page 52: Docker Federal Summit 2017 General Session

Cryptographically

Signed Artifacts

Page 53: Docker Federal Summit 2017 General Session
Page 54: Docker Federal Summit 2017 General Session

Garage

Page 55: Docker Federal Summit 2017 General Session

Segmentation

Page 56: Docker Federal Summit 2017 General Session
Page 57: Docker Federal Summit 2017 General Session

Neighbor’s Apt

Garage

Page 58: Docker Federal Summit 2017 General Session

Minimal

Dependencies

Page 59: Docker Federal Summit 2017 General Session
Page 60: Docker Federal Summit 2017 General Session
Page 61: Docker Federal Summit 2017 General Session

Immutable

Infrastructure

Page 62: Docker Federal Summit 2017 General Session
Page 63: Docker Federal Summit 2017 General Session
Page 64: Docker Federal Summit 2017 General Session

Thank

you

Page 65: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

What is Required for Modern IT

1

2

3

A secure and reliable base platform

Security across the entire supply chain

Leverage an ecosystem that

extends these principles

Page 66: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

A Reliable Platform Available Everywhere

On every Major CloudIn the Datacenter On every Major OS

Page 67: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Certified & Trusted Ecosystem Technology

Docker Enterprise Edition

Page 68: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

A Global Network for Support and Success

Global NetworkProduct & Support

39

47

18

GSI/FSI

Page 69: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Beginning the JourneyGet started by modernizing legacy apps with Docker

Enterprise Edition without changing the the source code

Page 70: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Double click on the apps you already have

Third Party

Microservices

Gartner estimates

that over 90% of an application TCO

is incurred AFTER

it is initially deployed

Traditional

Page 71: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Docker Brings Immediate Value to Existing Apps

Efficient

Secure

Portable Enable workload portability across hybrid cloud

Reduce the attack surface of legacy apps with inherent

container properties

Optimize infrastructure costs and streamline operations

Page 72: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Savings and Speed

Optimize Infrastructure Accelerate Deployments

February 2017: HPE and Docker Reference Configuration for infrastructure optimization using Docker containers on HPE infrastructure

25% savings on VMs

47% savings on bare metal

50% savings on cloud

Provision, deploy and scale

apps up to 75% faster

Page 73: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

How: Modernize traditional apps approach

Existing

Application

Convert to

containerModern

InfrastructureMove to cloud or

refresh HW

Modern

MicroservicesAdd new services

or start peeling off

services from

monolith code base

Modern

MethodologiesIntegrate to CI/CD

and automation

systems

APP

Page 74: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

• Accelerate portability, security and efficiency for existing apps without modifying source code

• Turnkey program includes professional services, Docker Enterprise Edition and hybrid cloud infrastructure

• Available from our partner:

Modernize Traditional Apps Program

Learn More

www.docker.com/boozallen

Page 75: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Banjot Chanana

Senior Director Enterprise Product

Page 76: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Recap: Docker EE Secure Supply Chain

Image RegistrySecurity scan& sign

Traditional

Third Party

Microservices

docker store

DEVELOPERS IT OPERATIONS

Control Plane

Page 77: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Docker Enterprise Edition (EE) Values

Efficient

Secure

PortableApplication composition and configuration portability

across any infrastructure

Safer applications and infrastructure

Optimize infrastructure costs and streamline operations

Page 78: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Key Capabilities of Docker EE

Container App Lifecycle Workflow

Private Image Registry

Image Scanning and

Monitoring

Secure Access and

User Management

Content Trust and

Verification

Application and

Cluster Management

Policy Management

Integrated Lifecycle

Management

Security

Distributed State

Network

Container Runtime

Volumes

Orchestration

Container Engine

Application Composition, Deployment and Reliability

Page 79: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

•Built in orchestration:

clustering and scheduling

•Automatic cluster security

TLS, CA, and rotation

•Container centric networking

•Pluggable platform

Secure and Reliable Base

Security

Distributed State

Network

Container Runtime

Volumes

Orchestration

Page 80: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

•One supply chain for all

applications

•App composition from dev

deploys direct to production

•Secure access with RBAC

and LDAP/AD support

•Integrated content security

End to End Container Lifecycle

Container App Lifecycle Workflow

Private Image Registry

Image Scanning and

Monitoring

Secure Access and

User Management

Content Trust and

Verification

Application and

Cluster Management

Policy Management

Application Composition, Deployment and Reliability

Page 81: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Demo

Page 82: Docker Federal Summit 2017 General Session

Docker 2017 - Confidential

Thank You and Enjoy the Day Next Up

Agency Panel Discussion

by Booz Allen Hamilton

featuring GSA, JIDO, USCIS

Titled “Lessons Learned in Adopting

Containers in Production”

7th Floor

Learning Lab

Featuring Docker Orchestration

Taught by Docker Captains Bret Fisher and Phil Estes

8th Floor

Page 83: Docker Federal Summit 2017 General Session

THANK YOU

Docker 2017 - Confidential