Captain Take 5 – Nuno do Carmo

Captain Take 5 – Nuno do Carmo

Docker Captains are select members of the community that are both experts in their field and are passionate about sharing their Docker knowledge with others. “Docker Captains Take 5” is a regular blog series where we get a closer look at our Captains and ask them the same broad set of questions ranging from what their best Docker tip is to whether they prefer cats or dogs (personally, we like whales and turtles over here). Today, we’re interviewing Nuno do Carmo who has been a Docker Captain since 2019. He is a Sr System Analyst for a pharmaceutical company based in Switzerland and he is based in Montreux.

How/when did you first discover Docker?

Back in 2015, I was hanging with friends and we would meet once a week to check on technologies and we found out a training on Pluralsight, given by a certain Nigel Poulton, and we decided to “temporarily” download it, **cough**.

Both the training method from Nigel and the technology of Docker were an instant hit for us. We started to learn as hobbyists and fast forward, I guess I took it more at heart than my friends, haha.

What is your favorite Docker command?

`docker run`, everything starts with a `docker run`. That first time that we launch “something”, we don’t know exactly what, it’s not VM and yet an instance with another OS is running.

Also, the power of simplicity from `docker run`, if the container image, network or volume do not exist, it creates it for us. We can start small from a `docker run -it alpine` to a way more complex command with ports, secrets, privileges.

Special mention to `docker app` and the whole CNAB community as it was the first time I contributed back to a project which used Docker (read below)

What is your top tip you think other people don’t know for working with Docker?

For the ones who know me, I’m a huge fan(boy) of Windows Subsystem for Linux (WSL) and while I do use Docker Desktop for Windows, I keep on reminding people who ask for help, that Docker on WSL2 can be installed like we would do in a native Linux OS.

Therefore we can have Docker Desktop running, let’s say with Windows Containers, and the Docker WSL2 running in parallel.

And special mention (yes, again) to `docker context` that makes it even easier to manage the whole setup.

What’s the coolest Docker demo you have done/seen?

Done, without hesitation, is the Docker to WSL2 distribution, which since then I have remixed a lot of times.

The demo consists in running a Docker container with almost any Linux based OS, export it as a compressed file and re-import it into WSL2 as a new distro.

I could automate it with a CNAB tool, called Porter.sh, and the community was so surprised (as it was not a use case initially intended for), that I got my first KubeCon invite to showcase it during a Day0 CNAB event led by another amazing Captain, Scott Coulton.

A massive thank you to the CNAB team and especially Carolyn Van Slyck, Ralf Squillace and Jeremy Rickard.

Seen, again without hesitation, it’s the demo from Jessie Frazelle called “Willy Wonka of Containers” (https://youtu.be/GsLZz8cZCzc).

This demo had such a huge impact on me and since then, 6 years later, I finally will be able to “mimic” it 100% in WSL2. That’s how much “in the future”, this demo was and Jessie is just incredible.

What have you worked on in the past six months that you’re particularly proud of?

Being a hobbyist (read: I do not work with Docker in my daily job), I can definitively say that I’m proud to have helped community members as a Captain and overall fan.

As for the technical part, I’m hard at work bringing rootless containers to WSL2 where, once again, I adapt the existing work of the great Akihiro Suda.

What do you anticipate will be Docker’s biggest announcement this year?

Docker Desktop for Linux, what else?

What do you think is going to be Docker’s biggest challenge this year?

These past years, Docker Inc (the company), needed to find its place in a Cloud Native world led by Kubernetes and associated projects.

I really think Scott Johnston has a very good vision, refocusing on what Docker does and speaks to best: the Developers.

Still, the road is not an easy one and this year I think Docker will be cementing its “new” position within the Cloud Native ecosystem.

What are some personal goals for the next year with respect to the Docker community?

Being a “new generation” of Captain, it’s always hard for me to believe I am in the same group as Legends that motivate me, still to this day, to use and enjoy Docker.

Being the “WSL Corsair”, I found my niche, and I simply would love to see more adoption of Docker Desktop for Windows with WSL2 backend.

Another point is to keep helping the Docker Windows containers side too. It’s there and my own impression is that it lacks some momentum right now. So bringing back the fire with the help of the community will be lots of fun.

What talk would you most love to see at DockerCon 2021?

Docker Desktop for Linux, what else? (bis)

But also, a lot of community members coming together and having fun, and maybe, why not, someone doing a crazy demo and motivating at least 1 person to become a Captain too in the future.

Looking to the distant future, what is the technology that you’re most excited about and that you think holds a lot of promise?

WSL2, and that’s not just the fanboy talking right now. Having the possibility to have a mix of two worlds, not colliding but merging, it’s just mind blowing.

In terms of hardware, even if ARM devices have existed for a long time, the Apple M1 really shook the world and the speed at which Software makers are porting their applications really opens a new ecosystem.

Rapid fire questions…

What new skill have you mastered during the pandemic?

Cooking new recipes

Cats or Dogs?

4 cats at home…

Salty, sour or sweet?

Salty

Beach or mountains?

I’m Portuguese living in Switzerland: both

Your most often used emoji?

  and

DockerCon Live 2021

Join us for DockerCon LIVE 2021 on Thursday, May 27. DockerCon Live is a free, one day virtual event that is a unique experience for developers and development teams who are building the next generation of modern applications. If you want to learn about how to go from code to cloud fast and how to solve your development challenges, DockerCon 2021 offers engaging live content to help you build, share and run your applications. Register today at https://dockr.ly/2PSJ7vn
The post Captain Take 5 – Nuno do Carmo appeared first on Docker Blog.
Quelle: https://blog.docker.com/feed/

These Microsoft SQL Server on RHEL 8 benchmark results might surprise you

When it comes right down to it, a database is only useful if you can use it to get access to the information you need, when you need it. That’s why performance is so important whether you are running on bare metal, in virtual machines or containers. Regardless of whether you’re running on-premises or in the public or private cloud. One of the key factors influencing performance is traditionally the choice of an underlying operating system. 
Quelle: CloudForms

Broadcom improves customer threat protection with flexible data management

Editor’s note: Today we’re hearing from Padmanabh Dabke, Senior Director of Data Analytics and Zander Lichstein, Technical Director and Architect for GCP Migration at Broadcom. They share how Google Cloud helped them modernize their data analytics infrastructure to simplify their operations, lower support and infrastructure costs and greatly improve the robustness of their data analytics ecosystem. Broadcom Inc. is best known as a global technology leader that designs and manufactures semiconductor and infrastructure software solutions. With the acquisition of Symantec in 2019, Broadcom expanded their footprint of mission critical infrastructure software. Symantec, as a division of Broadcom, has security products that protect millions of customers around the world through software installed on desktops, mobile devices, email servers, network devices, and cloud workloads. All of this activity generates billions and billions of interesting events per day.  We have dozens of teams and hundreds of systems which, together, provide protection, detection, exoneration, and intelligence, all of which requires handling a massive amount of data in our data lake.   Broadcom’s Security Technology and Response (STAR) team leverages this data lake to provide threat protection and analytics applications. The team needed a more flexible way to manage data systems while eliminating resource contention and enabling cost accountability between teams.Our data lake has served us well but as our business has grown so have our technology requirements. We needed to modernize the legacy implementation of the data lake and analytics applications built on top. Its monolithic architecture made it difficult to operate and severely limited the choices available to individual application developers. We chose Google Cloud to speed up this transformation. In spite of the complexity and scale of our systems, the move to Google Cloud took less than a year and was completely seamless for our customers. Our architectural optimizations, coupled with Google Cloud’s platform capabilities simplified our operational model, lowered support and infrastructure costs, and greatly improved the robustness of our data analytics ecosystem. We’ve reduced the number of issues being reported on the data lake, translating to a reduction of 25% in monthly support calls from internal Symantec researchers related to resource allocation and noisy neighbor issues.Where does our data come from and how do we use it?Providing threat protection requires a giant feedback loop. As we detect and block cyber attacks in the field, those systems send us telemetry and samples: the type of threats, where they came from, and the damage they tried to cause. We sift through the telemetry to decide what’s bad, what’s good, what needs to be blocked, which websites are safe or unsafe, and convert those opinions into new protection which is then pushed back out to our customers. And the cycle repeats.In the early days, this was all done by people—experts mailing floppy disks around. But these days the number of threats and the amount of data are so overwhelming that we must use machine learning (ML) and automation to handle the vast majority of the analysis. This allows our people to focus on handling the newest and most dangerous threats. These new technologies are then introduced into the field to continue the cycle.Shortcomings of the legacy data platformOur legacy data platform had evolved from an on-prem solution, and was built as a single, massive, relatively inflexible multi-tenant system. It worked well when there was a big infrastructure team that maintained it but failed to take advantage of many capabilities built into Google Cloud. The design also introduced a number of obvious limitations, and even encouraged bad habits from our application teams. Accountability was challenging, changes and upgrades were painful, and performance ultimately suffered. We’d built the ecosystem on top of a specific vendor’s Apache Hadoop stack. We were always limited by their point of view, and had to coordinate all of our upgrade cycles across our user base. Our data platform needed a transformation. We wanted to move away from a centralized platform to a cloud-based data lake that was decentralized, easy to operate, and cost-effective. We also wanted to implement a number of architectural transformations like Infrastructure as Code (IaC) and containerization. “Divide and Conquer” with ephemeral clustersWhen we built our data platform on Google Cloud, we went from a big, centrally managed, multi-tenant Hadoop cluster to running most of our applications on smaller, ephemeral Dataproc clusters. We realized that most of our applications follow the same execution pattern. They wake up periodically, operate on the most recent telemetry for a certain time window, and they generate analytical results that are either consumed by other applications or pushed directly to our security engines in the field. The new design obviated the need to centrally plan the collective capacity of a common cluster by guessing individual application requirements. It also meant that the application developers were free to choose their compute, storage, and software stack within the platform as they seemed fit, clearly a win-win for both sides. After the migration, we also switched to using Google Cloud and open-source solutions in our stack. The decentralized cloud-based architecture of our data lake provides users with access to shared data in Cloud Storage, metadata services via a shared Hive Metastore, job orchestration services via Cloud Composer, and authorization via IAM and Apache Ranger. We have a few use cases where we employ Cloud SQL and Bigtable. We had a few critical systems based on HBase which we were able to easily migrate to Bigtable. Performance has improved, and it’s obviously much easier to maintain. For containerized workloads we use Google Kubernetes Engine (GKE), and to store our secrets we use Secret Manager. Some of our team members also use Cloud Scheduler and Cloud Functions. Teaming up for speedSTAR has a large footprint on Google Cloud with a diverse set of applications and over 200 data analytics team members. We needed a partner with in-depth understanding of the technology stack and our security requirements. Google Cloud’s support accelerated what would otherwise have been a slow migration. Right from the start of our migration project, their professional services organization (PSO) team worked like an extension of our core team, participating in our daily stand-ups and providing the necessary support. The Google Cloud PSO team also helped us quickly and securely set up IaC (infrastructure as code). Some of our bleeding edge requirements even made their way to Google Cloud’s own roadmap, so it was a true partnership. Previously, it took almost an entire year to coordinate just a single major-version upgrade of our data lake.  With this Google Cloud transformation we can do much more in the same time, it only took about a year to not only move and re-architect the data lake and its applications, but also to migrate and optimize dozens of other similarly complex and mission-critical backend systems. It was a massive effort, but overall, it went smoothly, and the Google Cloud team was there to work with us on any specific obstacles. A cloud data lake for smoother sailingMoving the data lake from this monolithic implementation to Google Cloud allowed the team to deliver a platform focused entirely on enabling app teams to do their jobs. This gives our engineers more flexibility in how they develop their systems while providing cost accountability, allowing app-specific performance optimization, and completely eliminating resource contention between teams.Having distributed control allows teams to do more, make their own decisions, and has proven to be much more cost-effective. Because users run their own persistent or ephemeral clusters, their compute resources are decoupled from the core data platform compute resources and users can scale on their own. The same applies to user-specific storage needs.We now also have portability across cloud providers to avoid vendor lock-in, and we like the flexibility and availability of Google Cloud-specific operators in Composer, which allow us to submit and run jobs across Dataproc or on an external GKE cluster.We’re at a great place after our migration. Processes are stable and our data lake customers are happy. Application owners can self-manage their systems. All issues around scale have been removed. On top of these benefits, we’re now taking a post-migration pass at our processes to optimize some of our costs. With our new data lake built on Google Cloud, we’re excited about the opportunities that have opened up for us. Now we don’t need to spend a lot of time on managing our data and can devote more of our resources to innovation. Learn more about Broadcom. Or check out our recent blog exploring how to migrate Apache Hadoop to Dataproc.
Quelle: Google Cloud Platform