10 ms·
Istio moved to CNCF Graduation stage
- aidenn0 3y agoEnough searching around told me what CNCF is, but I still don't know what it means to "graduate"
- gattacamovie 3y agothere are 3 stages of a CNCF project: incubation,sandbox,graduated for each there are conditions, including number of contributors, number of companies oficially backing it, etc.
- GenericDev 3y agoWhy would you want this?
- nickstinemates 3y agoFunding can be attained more readily if you have a project that reaches any of these stages.
- jrockway 3y agoWhat are some major CNCF projects that have gotten investor funding in the last year?
- captn3m0 3y agoA “graduated” project might find it easier to get adoption, contributors, as the guarantees (stability, integrity, security, governance) are some of the criterion that org use while deciding on tooling. It’s basically saying: If you were shying away from using Istio in production, we graduated, take a look now?
- mkl95 3y agoIt's a statement that it's not some personal project and it is backed more or less consistently by a bunch of people.
- cyrnel 3y agoThe graduation criteria I care about is "Have completed an independent and third party security audit". Lots of software in the cloud native world puts security in the back seat sadly!
- akhayam 3y agoYou can read more about incubated and graduates CNCF projects here: https://www.cncf.io/projects/ https://www.cncf.io/projects/
- akhayam 3y agoTldr: you can bring your open source project to CNCF and if there are enough infra/platform developers vouching for it then you can become an incubated project. After that, there is a bunch of boxes (traction, integration, stability) that you need to check before CNCF endorses you as a graduated project.
- aidenn0 3y agoSo it's just a stamp of approval?
- AlexB138 3y agoSort of. It's also a statement of maturity.
- mdekkers 3y ago> Sort of. It's also a statement of maturity. And of funding. Some of the hoops such as a 3rd party audit are _not_ cheap
- eddythompson80 3y agoAlso a lot of projects in sandbox or incubation are “finding themselves” so to speak. It’s what used to happen when a project would release a v1 that’s really mostly a POC, then have some major overhauls/rewrite in v2/v3. At least in theory by “graduation” or v3, you know that this thing has a non-trivial user base, fairly defined in what it does and how it does it. Some independent reviews and established patterns etc. Nothing protecting them from rotting or dying or breaking obviously, but at least you know you won’t be shouting at it alone.
- dpedu 3y ago
- zgluck 3y agoIt's about the modern day J2EE - Kubernetes. Approximately the same cost per "getting something done" ratio. Exactly the same kind of orgs (both on the seller and buyer sides). I hear the money is good though, if you're into that kind of slow work.
- jupp0r 3y agoYou might not know what J2EE or Kubernetes do if you compare them like that.
- zgluck 3y agoI know and understand both technologies in enough detail, thank you. They were/are abused as instruments of complexity by consulting firms. They are both fantastic at this purpose. Of course it's also possible to use this tech to actually get stuff done. But that's not what it's widely used for in this consulting environment. The typical end-customer is you (the tax payer.) You have no influence over what you paid for, though. Also: it's a recurring cost, like Netflix. It doesn't really stop...
- KnobbleMcKnees 3y agoThe problem you're describing is consultancies, not Kubernetes.
- zgluck 3y agoYeah, but like J2EE, Kubernetes will become synonymous with waste [in the public sector] in about 5-10 years from now. I mean, you've got to admit, it's a repeat of history?
- dosint21h 3y ago[flagged]
- AlexB138 3y agoHere's the PR: https://github.com/cncf/toc/pull/1000 https://github.com/cncf/toc/pull/1000
- meepmorp 3y agoIn case anyone wants to read the rendered markdown: https://github.com/cncf/toc/blob/main/proposals/graduation/istio.md https://github.com/cncf/toc/blob/main/proposals/graduation/i...
- akhayam 3y agoFinally… took a while. Now CNCF needs to figure out how to get Istio to work nicely with the networking k8s addons
- dirteater_ 3y agoThe CNCF doesn't really dictate that kind of stuff. If something doesn't play nice try the Istio slack or file an issue on the main repo: https://github.com/istio/istio https://github.com/istio/istio
- AlexB138 3y agoHere's the official CNCF announcement: https://www.cncf.io/announcements/2023/07/12/cloud-native-computing-foundation-reaffirms-istio-maturity-with-project-graduation/ https://www.cncf.io/announcements/2023/07/12/cloud-native-co...
- hsaliak 3y agoAnd yet -- grpc is still "incubating". Do these statuses really mean much?
- phillipcarter 3y agoThey do have meaning, but the meaning is orthogonal from metrics like total use throughout an industry: https://github.com/cncf/toc/blob/main/process/graduation_criteria.md#graduation-stage https://github.com/cncf/toc/blob/main/process/graduation_cri... There is little doubt in my mind that gRPC is a larger and more impactful project than Istio.
- sdesol 3y agoHere's the insights for grpc https://devboard.gitsense.com/grpc/grpc https://devboard.gitsense.com/grpc/grpc They are attracting less people than istio but not by much. Full disclosure: This is my tool
- verst 3y agoThe CNCF has their own tool - a Grafana dashboard for all their projects: https://devstats.cncf.io https://devstats.cncf.io A bit awkward to use but lots of great info there. I use it every now and then (I'm a maintainer of Dapr).
- sdesol 3y agoYeah I was aware of devstats and yes the UI is awkward to use. I'm planning on open sourcing DevBoard, since GitSense is really the differentiating factor, so CNCF is free to use it, if it wants to. I personally think Grafana is great for analyzing time series data but I don't believe it's a very good dashboard system if you need to tell a story, which is what I believe software development insights needs. If you goto to https://devboard.gitsense.com/dapr/dapr?board=gitsense_examples.intro_to_widgets https://devboard.gitsense.com/dapr/dapr?board=gitsense_examp... you can see how my DevBoard widget system is different than Grafanas. Note, the repo that I talk about in the Intro page hasn't been pushed to GitHub yet, but will be soon (hopefully by the end of this week). I'm planning on creating widgets where you can just feed it some numbers and it will generate a graph, but since my widgets can be programmed, you can do much more with the data to tell a story and to help surface insights.
- sdesol 3y agoHere is some community information for istio https://devboard.gitsense.com/istio/istio https://devboard.gitsense.com/istio/istio Not kubernetes level https://devboard.gitsense.com/kubernetes/kubernetes https://devboard.gitsense.com/kubernetes/kubernetes but still very good. Full Disclosure: This is my tool, but I figure the insights would be interesting/useful.
- alanwreath 3y agoI may have missed the announcement where Istio’s ownership was being transfered to a vendor-neutral foundation like the CNCF, or is the Open Usage Commons What can be used in place?
- mikeyouse 3y agoYeah they joined CNCF last September; https://istio.io/latest/blog/2022/istio-accepted-into-cncf/ https://istio.io/latest/blog/2022/istio-accepted-into-cncf/
- SomaticPirate 3y agoI think this just demonstrates the power of vendor-neutral Open Source. I don’t mean that in an inflammatory way. Istio, a collaborative project from Google/IBM that was arguably going to be a slight differentiator for their respective clouds was forced to go vendor-neutral after Linkerd did. Same thing happened to Knative. CNCF definitely has some politics but its been interesting to see large OSS projects be essential dead on arrival now if its not in a vendor neutral holding org. I personally try to favor vendor neutral projects now. Slightly smaller chance of being burned like I was with Grafana switching licenses.
- awestroke 3y agoIf I needed a service mesh, I'd probably use Linkerd. What would I be missing out on?
- crb 3y agoI like to equate the question to "If I needed a container orchestrator, I'd probably use Nomad. What would I be missing out on with Kubernetes?" Ignore the CNCF for a second. Both are open source, so will survive regardless, but the former has a single vendor behind it, and the latter has almost all the cloud industry. There are valid use cases for FreeBSD, but the default choice is Linux.
- ceposta07 3y agoI think it does come down to risk and risk mitigation. As someone who works for an “Istio vendor” we see some of the largest deployments of Istio in the world for mission critical/tier-0 workloads… and all the steps it took to get there including evaluation/POC of other vendors/mesh technologies. Part of these decisions are based on things like “What is the rest of the industry doing?” “How vibrant/diverse is the community?” “How mature is the project _for enterprise adoption_?” “What vendors are available for enterprise support?” “Is it already available in my platform of choice?” etc.etc. The sting of “picking the wrong container orchestrator” is still fresh in a lot of organizations. We see Istio make it through these questions with good answers for a lot of organizations where other/alternative service mesh vendors strike out pretty quickly. This is even before we get to the “feature comparisons” for usecases these large organizations focus on/have.
- 0xEFF 3y agoThis is a good analogy. For more context in the past 5 years working with customers in the Bay Area I’ve not encountered one who mentioned linkerd let alone ran it in production. More than half those companies ran istio in production at large scales.
- williamallthing 3y agoMaybe you're just not talking to the right companies. There are a ton of Linkerd adopters and the list is constantly growing! https://linkerd.io/community/adopters/ https://linkerd.io/community/adopters/
- goalonetwo 3y agoWe are using istio at scale. I have a love-hate relationship with it. It is very complex and builds on 5 other layer of abstraction (K8s, Envoy, Iptables,...). Grasping what is going on requires you to understand all of those layers first. Istio essentially adds one layer of proxy for all your ingress/egress requests and from an engineering/performance/cost perspective that is not amazing. Once it is working and deployed though it provides a solid set of functionalities as part of the infrastructure directly. AuthN/Z, mTLS, security, metrics and logs are all deployed by default without the end-user having to do anything. Eventually I expect Istio will evolve to a model that makes more sense with Ambient/eBPF (For cost/performance reasons) The community behind Istio is especially helpful and one of the main reasons why we went with this project.
- slygon 3y agoWe tried Istio, but our Devops team (8 people) said they don't have the capacity to manage that complexity. We're rolling with Linkerd ever since, still a joy
- datadeft 3y ago> It is very complex and builds on 5 other layer of abstraction Yeah this is a definite no for me.
- Niksko 3y agoBoy do I have bad news for you about all of modern software...
- candiddevmike 3y agoNot all modern software. No one is forcing anyone to use this stack.
- amarshall 3y agoYes, pretty much all modern software. The real difference is whether it’s a leaky abstraction or not. Sounds like istio is leaky.
- crb 3y agoHi everyone, I'm the person who drove the CNCF process for Istio (and made the linked commit). I'm happy to answer any questions.
- ec109685 3y agoCongrats on the graduation. My company has been using it for a long while through all its design iterations. We still haven’t achieved an amazing distributed tracing strategy, we don’t use its MySQL or Redis interfaces, and haven’t rolled out more advanced features like smart retries. It’s hard to get momentum on that versus other must have work. But for mTLS and authn and authz, it works great. Thanks for the hard work.
- deleted 3y ago[deleted]
- throwawa3432 3y agoI think it should be titled Envoy+Istio in the same spirit of GNU+Linux. Jokes aside, Envoy really deserves some spotlight.
- tflinton 3y agoIstio is amazing once you grok how it works and get it running. It has a lot of gotchas (objects in istio-system become global?) and there’s a lot of ways to abuse or misuse it.
- vbezhenar 3y agoWhat's an alternative to istio? I want to have http metrics between our services inside kubernetes. I don't really want all the fancy shmancy mtls, dpi and stuff, they don't bring value to me.
- shitlord 3y agoIf you don't want any of the fancy stuff, then you can just use Envoy without Istio and configure it yourself.
- vbezhenar 3y agoThat's an interesting thought. Even if I would throw it away for istio in the end, the experience for managing Envoy, might be valuable. How do I do that exactly? I need to install some iptables rules inside a pod to redirect pod traffic to envoy?
- shitlord 3y agoEnvoy is the proxy that does the heavy lifting. Istio is just a glorified configuration system. Even if you choose to use Istio you're still using Envoy. You're spot-on about using iptables rules. There is an example here with a yaml configuration and some iptables commands: https://github.com/envoyproxy/envoy/blob/main/configs/original-dst-cluster/README.md https://github.com/envoyproxy/envoy/blob/main/configs/origin... You might be able to re-use some of that. It should be pretty easy to get metrics for outbound/inbound http requests, but I don't remember the exact yaml incantation.
- vbezhenar 3y agoThanks, I'll look into that. Might actually be the simplest solution in the end.
- ceposta07 3y agolol i’m not quite following how manually injecting envoy, “configuring envoy yourself/by hand” in a pod and “copying istio code for iptables re-direction” and then trying to maintain this yourself is easier than just using istio? install istio, turn off mtls if you dont want that (https://istio.io/latest/docs/reference/config/security/peer_authentication/#PeerAuthentication-MutualTLS-Mode https://istio.io/latest/docs/reference/config/security/peer_...) and you have what you’re looking for. doesn’t get simpler than that.