7 ms·
My thoughts not facts. I know that there are more products then I mention. I fail to see in what segment Hashicorp will remain relevant over time. Terraform i
by AtNightWeCode 5y ago
My thoughts not facts. I know that there are more products then I mention.
I fail to see in what segment Hashicorp will remain relevant over time.
Terraform is the tool I mostly see companies pay for. Over time cloud vendors will make Terraform obsolete. In fact it is already a problem to use Terraform since it can not move at the same pace as major cloud vendors.
Vault is an extremely complicated niche tool, most companies should not use.
Consul, the service discovery tool is mostly not needed in cloud environments. Don't think any cloud vendor today have Consul as a service on their agenda even though this has been announced years ago which is a warning sign. Personally I really like Consul and the way you can set up ACL for instance.
Vagrant, use whatever.
Nomad has lost the battle with Kubernetes a long time ago. I never trusted Nomad and I never will but I can see that if you really want to orchestrate a lot of containers Nomad may be the right tool.
When selecting an identity platform you mainly have to go along with the corruption in the industry...
I really wish Hashicorp good luck on this journey though.
- runlevel1 5y agoMulti cloud, hybrid, and on-prem often need solutions that aren't married to a single cloud provider. That's not all companies. It's not even the majority of them. But those companies do tend to be the ones who can afford HashiCorp's premium offerings. Edit: Fix typo.
- vngzs 5y agoA lot of big finance companies use Nomad for all their compute scheduling. Citadel, for instance. They desire the ability to schedule Windows workloads, containers, regular processes, etc. through a common interface. They might not want or need to go all-in on containers. Vault has a similar target market. Big high-paying institutions. It's not the average market of your tech company, and 100-200 person startups generally won't need it. If you're in the fintech space, maybe you do.
- jordanbeiber 5y agoI feel I need to reply with my thoughts. - Vault is not niche - it’s THE way to manage pki and credentials if you’re half serious about security. Which is why you’re now are starting to see managed vault. - Consul - EVERYONE should use service discovery, cloud or not. It’s indispensable for numerous reasons. If you doubt it’s relevance, check out the Kubernetes integration work - there’s a reason for that focus. You need service discovery if you operate at any sort of scale, spanning multiple providers and teams (Azure have a managed consul offering btw). - “Trust” nomad? The team and I have used it since 0.4 and 0.6 in full production at two different companies. K8s as well, but it lacks the unix vibe of “one thing, and do it well”, which is something you get with nomad, consul & vault. Nomad has been rock solid and I’ve so far had no reason to not “trust” it, 100s of thousands of deploys later. - terraform spans many providers. It’s a good tool, not without it’s quirks. But I’d rather have one quirky tool than multiple quirky vendor ones. Also, we use TF for basically everything - even the stuff we host in-house through lxc and postgres for example, and through home grown providers as well. I could write pages on the hashicorp products!
- AtNightWeCode 5y agoAll major clouds have better alternatives to Vault. Vault is mostly for really large companies that want to run things like this by themself. There is no need for service discovery in the cloud in general. I have also used Nomad a lot. Maybe it is because we always needed the cutting edge features in general, but in general not very good quality. Core features always worked though. People should use Kubernetes instead in most cases. There is simply no way Terraform and the HCL2 will survive for cloud environments. For other use cases I do not know.
- jordanbeiber 5y ago“People should use Kubernetes instead” is an interesting take considering your first paragraph. :) You’ve perhaps not had to troubleshooting issues in a more advanced k8s setup - that is something that is not “for most people”. Keeping services discoverable, with service health-checks and configuration data at hand in the k/v is not needed in the “cloud”? I guess a lot comes down to how you opt to manage you services… It’s what etc does, but worse (imo), for k8s. My usual work with larger infrastructure spans more than k8s or a single provider, hence consul is a given. To my knowledge no other secrets solution exists that cover all the things vault does, and at the same lets you stay provider agnostic. It integrates well with the major cloud providers though!
- AtNightWeCode 5y agoWhat I am saying is that Kubernetes has become the mainstream tool to use. You have to put up good reasons or custom needs to use something else. A thing I like about Consul is that you can also use it as a KV. Something I lack in the cloud. The Vault in Azure is the Keyvault which is all around terrible but Keyvault in conjunction with how Azure works in general is sufficient to build secure infrastructure.
- nuker 5y ago> You have to put up good reasons or custom needs to use something else. Its bloody too complex was a good enough reason to move off it to ECS.
- thunderthunder 5y agoI really don´t feel K8S have won this battle. I agree people talk more about K8S but i have seen a trend in people that are disappointed with K8S and move against Nomad instead. I guess K8S is too messy. It´s like taking a 2015 enterprise vsphere datacenter environment and containerizing it. Too many layers.. But of course, there´s no fully managed Hashicorp offer for all products in GCP or AWS, Azure....
- AtNightWeCode 5y agoI do not really understand why people run so many things in containers in the first place. Sure, for sand-boxing and sometimes resource utilization, but the large services I worked on have always been on 10+ dedicated high-end servers with 200GB+ memory each. Absolutely zero need for any additional abstractions. You can also design solutions that use a lot of memory in contrast to containers.
- dilyevsky 5y ago10 machines is not large by any stretch if imagination and hasn’t been for a long time. Try hundreds or thousands
- jen20 5y agoI would suggest that you reevaluate Nomad. It solves basically every one of (many) problem with Kubernetes in an elegant and reasonable way, at a scale Kubernetes is by no means capable of. Further the idea that cloud vendors will make Terraform irrelevant is laughable. None of them have any impetus to provide a consistent workflow across multiple clouds. The shortcomings of CloudFormation in particular are unlikely ever to be overcome.