A New Milestone: Istio Comes Closer to Cloud-native Ecosystem

3458
Of your peers have already read this article.
2:00 Minutes
The most insightful time you'll spend today!
Today we are excited to announce that Google and the Istio Steering Committee have submitted the Istio project for consideration as an incubating project within the Cloud Native Computing Foundation (CNCF). This is a significant milestone for Istio and its community, and we are thrilled to reach this next step in the evolution of the project.
Google and Istio
Google originated the Istio project, which alongside Kubernetes and Knative, is a critical part of cloud-native infrastructure. The Istio project has found success and maturity in its current model — being adopted by hundreds of organizations and bringing in over 4,000 developers for IstioCon.
For over 20 years, Google has helped shape the future of computing with its open source contributions and has invested deeply to unlock innovation for our customers. Istio extends Kubernetes to establish a programmable, application-aware network using the Envoy service proxy. Istio works with both Kubernetes-based and traditional workloads, and brings standard, universal traffic management, telemetry, and security to complex deployments. Finding a home in the CNCF brings Istio closer to the cloud-native ecosystem and will foster continuing open innovation.
The Istio journey
We started to develop Istio in partnership with teams at IBM and Lyft in 2016 based on patterns that were being used to connect Google production applications. Google’s security focus complemented the traffic management focus of an open-source project published by IBM, and those two teams decided to collaborate on Istio directly. Istio was launched “fully formed” in May 2017, with the v0.1 release featuring sidecar-powered traffic control, observability and policy features — the things that today define a service mesh. Istio has been open source from the beginning, and has a governance structure that promotes continuous contribution and project engagement.
By the release of v0.3 a few months later there were users trusting it in production, seeing immediate benefits from its powerful features. The project reached v1.0 in July 2018, and was being used at scale by eBay and The Weather Company. Google led a major re-architecture with the release of v1.5, unifying the control plane into a single service. This change, based on user feedback, reduced administrative overhead, as was later written about in the IEEE Software journal. We also greatly simplified extensibility of the mesh by building support for WebAssembly plugins into Envoy.
Istio is now offered as a managed or hosted service by over 20 providers, including Anthos Service Mesh, a suite of tools that helps you monitor and manage a reliable service mesh on-premises or on Google Cloud.
The future of Istio as a project in the CNCF
At Google, we believe that using open source comes with a responsibility to contribute, sustain, and improve the ecosystem, and we are committed to improving critical cloud-native projects on behalf of our customers and the community at large. Google has made over half of all contributions to Istio and two-thirds of the commits, as measured by the CNCF DevStats.1 After deciding to adopt Envoy for Istio, Google rose to be Envoy’s number-one contributor.2
Istio is the last major component of organizations’ Kubernetes ecosystem to sit outside of the CNCF, and its APIs are well-aligned to Kubernetes. On the heels of our recent donation of Knative to the CNCF, acceptance of Istio will complete our cloud-native stack under the auspices of the foundation, and bring Istio closer to the Kubernetes project. Joining the CNCF also makes it easier for contributors and customers to demonstrate support and governance in line with the standards of other critical cloud-native projects, and we are excited to help support the growth and adoption of the project as a result.
Istio is key to the future of Google Cloud and if the project is accepted, Google will continue to strategically invest in Istio as a key maintainer and through ongoing investment in engineering for upstream contributions.
1. https://istio.teststats.cncf.io/d/5/companies-table?orgId=1
2. https://envoy.devstats.cncf.io/d/5/companies-table?orgId=1
3547
Of your peers have already watched this video.
1:30 Minutes
The most insightful time you'll spend today!
See How Rémy Cointreau Drives Customer Centricity with SAP on Google Cloud
Rémy Cointreau is a French, family-owned business group whose origins date back to 1724. Rémy Cointreau is working to be a more customer centric organization. In order to fulfill this goal and to modernize, they determined they needed to get away from infrastructure management and decided to move their SAP landscape to Google Cloud.
Additionally Rémy Cointreau wanted to become more data centric. Learn how operations that used to take five weeks now take five minutes. Learn how Rémy Cointreau is leveraging live data analysis and is preparing for the future with SAP on Google Cloud.
Three Benefits of VPC Network Peering for SAP Managed Apps

3534
Of your peers have already read this article.
3:00 Minutes
The most insightful time you'll spend today!
Over the past year, RISE with SAP has emerged as a valuable solution for SAP customers seeking a faster, simpler, and more affordable path to the cloud. RISE with SAP is a subscription-based offering that typically includes a number of fully managed cloud application options, including SAP S/4HANA Cloud and elements of the SAP Business Technology Platform. It’s a great way to migrate your business to modern cloud ERP applications, while handing off the implementation and management to SAP and freeing your own IT staff to focus on other projects.
As a strategic partner for RISE with SAP, Google Cloud works closely with SAP to ensure reliable, secure, high-performance connectivity between your SAP managed applications and your other Google Cloud applications and services. Today, we’re focusing on a Google Cloud capability that plays a big part in achieving this goal: VPC network peering. If your company uses Google Cloud to host its RISE with SAP managed applications (or any other SAP-managed offering, such as SAP Enterprise Cloud Services), it’s worth learning more about why VPC network peering is an important capability and how your network admin can implement it.
VPC network peering: The critical link for your SAP managed applications
We recently co-authored a white paper with SAP that goes into technical detail about how VPC network peering works and includes step-by-step configuration instructions. But it is useful to understand, at a higher level, why it matters for RISE with SAP subscribers.
When SAP implements your RISE with SAP managed applications on Google Cloud, it also provisions a virtual private cloud (VPC) — a virtualized network that provides the same functionality, performance, and security benefits as a dedicated physical network — for this SAP environment. In fact, a VPC actually gives you some capabilities that a physical network can’t match, such as the ability to increase IP space without downtime.
Using VPC network peering to connect your SAP managed environment with your Google Cloud applications and services gives you three key benefits:
- Network latency: Traffic that remains inside Google’s network enjoys lower latency than connectivity that uses external addresses.
- Network security: Service owners do not need to have their services exposed to the public internet and deal with its associated risks.
- Network cost: Rather than pay egress bandwidth costs for networks using external IPs to communicate, peered networks can use internal IPs to communicate, saving you money on those egress costs. Regular network pricing still applies to all traffic.
Many customers also appreciate the flexibility they get from VPC network peering: It supports the ability to peer your own VPC networks with other VPC networks that reside in different projects and even in different organizations.
Using VPC network peering to strengthen your SAP security posture
Most Google Cloud customers find VPC network peering most useful to ensure seamless connectivity between their SAP managed applications and the rest of their Google Cloud environment. But some companies also rely on VPC network peering to gain greater control over the security of their cloud environments. This can include:
- Implementing additional network security capabilities, such as advanced firewalls, intrusion detection, and network package inspection, that go above and beyond standard SAP security measures.
- Leveraging Google Cloud Interconnect to link your on-premises and Google Cloud environments, including your RISE with SAP managed applications, without sending traffic across the public internet.
Once your company has configured VPC network peering, things get even more interesting. Google Cloud offers plenty of ways to complement and enhance the value of your SAP applications: using Google BigQuery to consolidate and enrich your SAP application data; relying on Google AI/ML capabilities to sharpen your predictive analytics and real-time decision-making; or leveraging Google Kubernetes Engine to jump-start your own cloud-native application development efforts, among many other examples.
Some of the world’s biggest SAP customers, including The Home Depot, and Cardinal Health, have chosen Google Cloud to migrate their business-critical SAP applications. And we’ve seen how useful VPC network peering can be for SAP customers to unlock the full value and potential of Google Cloud. Be sure to download our white paper so you can get VPC network peering configured for your RISE with SAP managed applications, and discover for yourself just what’s possible when you run SAP applications on Google Cloud.
Airbus: Taking the flight to a brighter future with Google Cloud and Google Workplace

3583
Of your peers have already read this article.
1:30 Minutes
The most insightful time you'll spend today!
“Any device, anytime, anywhere.” A cohort of CIOs within Airbus believed that the cloud, combined with new ways of working, could provide the foundation for this vision. Google Workspace and Google Cloud have played a pivotal role in helping Airbus realize this new path, transforming security, data management, and collaboration along the way.

Adopting a secure-by-design approach
In adopting Google Workspace and Google Cloud Airbus needed to ensure a robust, zero-trust security model that works across the entire organization, even when employees are working outside the office. Google Workspace provides a single login that enables secure access to data, based on device and user information, as well as contextual inputs that inform the security risk of each login and user action. Airbus admins also use Google Workspace to define trust rules that govern what information and files can be shared within and outside the organization, making it easy for employees to comply with best practices from anywhere.
Encryption also plays a central role in keeping information secure and private. By default, Google Workspace uses the latest cryptographic standards to encrypt all data at rest and in transit. Google Workspace also offers client-side encryption, which Airbus uses for their most sensitive projects, giving them authoritative control over their data as the sole owner of their encryption keys.
And to ensure the organization is protected against hackers, Airbus has implemented sharding as a standard practice, thereby splitting data across multiple servers and data centers. Because the company works with incredibly sensitive information—including government and military information—the ability to locate data all within European data centers continues to be a necessity.
Powerful data management
Managing an enormous volume and variety of data, Airbus needs to ensure complete compliance with internal policies, as well as with external standards, like the General Data Protection Regulation (GDPR). Given this context, Airbus requires a solution that has strong built-in governance controls. Airbus also leverages the Drive labels feature, along with manual classification, to ensure that every file added to Google Drive is tagged and labeled correctly. In turn, these labels define the loss-prevention policies assigned to each file.
Staying connected during the pandemic
Before the pandemic, nearly every employee spent their workdays at an Airbus facility. When remote work became mandatory, the company made the pivot to Google Chat and Google Meet as an essential part of supporting real-time and asynchronous collaboration. Gmail also played a significant role in secure, anywhere-anytime communication, with its built-in anti-spam and anti-malware protections. Customizable filters let administrators protect against suspicious attachments, untrustworthy links, and countless other forms of malicious content. While Gmail blocks more than 99.9% of spam and phishing messages from ever reaching users’ inboxes, more advanced security measures like sandboxing can be put in place for specific use cases.
Protecting more than just data
Google Cloud’s sustainability efforts are as equally important to Airbus as data security. Google Cloud has been working to keep its climate footprint and those who use its services as low as possible, with all of Google currently carbon neutral and with a goal to run on carbon-free energy 24/7 at all of our data centers by 2030. And with our smarter, more efficient data centers, we’re already on that path with more than six times the computing power for the same amount of electrical power we used 5 years ago.
Building the future of work
By combining Google Workspace with Google Cloud, Airbus has been able to live up to its vision of “any device, anytime, anywhere.” The new model is a core foundation for its evolving future of work. Not only has Airbus adopted a zero-trust model across the organization, it’s also transformed how data is secured, managed, and accessed by employees working across a broad range of locations. The new flexible approach has also led to changes in how collaboration happens. Google is deeply gratified to have supported Airbus as they implement these changes and we continue to be proud that we’re running the cleanest cloud in the industry.
Want to learn more about how Google Workspace helps businesses like yours do more while keeping your data secure? Read this whitepaper to find out about our zero-trust model and other ways we protect organizations.
Dassana: Choosing Google Workspace and Google Cloud to accelerate growth and reach goals

3042
Of your peers have already read this article.
2:30 Minutes
The most insightful time you'll spend today!
When Dassana co-founders Gaurav Kumar and Parth Shah, formerly founder and founding engineer at RedLock (now Prisma Cloud by Palo Alto Networks), set out on a new startup journey in 2020, they knew exactly where to start: sign up for Google Workspace.
“Every startup I’ve been at, we used Google Workspace,” said Kumar. “We’ve been using it for so long, and we’re all used to it. It’s like drinking water—you don’t think about it.”
“We’re big on user experience,” explained Shah. “Google is one of the few companies out there that is all about building the right kind of user experience that’s easy to follow. The sharing capabilities are amazing and, of course, easy to use. Docs, Sheets, Slides—we use all of it.”
Dassana, which emerged from stealth with $5 million in seed funding earlier this year, is a next-generation security data lake. It provides a holistic picture of security risk across an organization and its business units by ingesting large volumes of structured data in a schema-less fashion. Their success is a great testament to why startups are choosing not only Google Workspace, but a range of Google Cloud products.
Though the Dassana team was comfortable with Workspace from the start, not all their early technology choices were the best fit for the company, and Google Cloud services became more crucial as the startup evolved. For example, the team opted to use Amazon Web Services (AWS) to start their cloud journey, but ultimately started to explore other cloud options when they decided to run their technology platform on Kubernetes.
“We started looking into which cloud platforms provide the best Kubernetes experience,” said Kumar. “Hands-down, Google Kubernetes Engine (GKE) had the best experience. If you look at product velocity and how GKE has evolved over time, from its early days to GKE Autopilot and all the features and other native integrations—nothing even comes close.”
In particular, Kumar noted that the native integration between Google Workspace and GKE was particularly unique and useful. “When I go to Google Workspace and then go to GKE, my identity is already there,” he said. “I don’t have to integrate or manage anything. If I disable an account in Workspace, it’s also disabled on GKE.”
Another advantage is that GKE allows you to set up Google Groups to work with Kubernetes role-based access control (RBAC) for GKE clusters. This lets administrators maintain users and groups outside of GKE and assign RBAC permissions directly to Groups in Workspace without any extra engineering work or overhead management.
“I can actually use my Workspace identity to give granular controls to my GKE workloads. The integration of Google Groups in GKE and Kubernetes is a lifesaver. It’s saved us a lot of hassles,” said Kumar. Kumar also noted that the platform delivers better performance compared to other solutions thanks to the low latency of Google Cloud’s global network.
Like many startups, Dassana has found a powerful combination in Google Workspace and GKE on Google Cloud that lets them connect technologies, easily collaborate with their teams, and rapidly build their product. The team also recognizes the necessity of continued innovation, and is exploring additional Google Cloud products to help them accelerate their momentum. For example, Dassana plans to use the performance and scale of Cloud Storage buckets to store the company’s data. The team is also investigating how to save time by using Pub/Sub to integrate data directly from Google Workspace and other sources for security analytics.
To learn more about why startups like Dassana are choosing Google Workspace and Google Cloud to accelerate their growth and reach their goals, visit our startup solutions pages for Google Workspace and Google Cloud.
How Google Cloud Sped up Nuro’s Data Delivery to Engineers and Automated Storage Transfer

3408
Of your peers have already read this article.
3:00 Minutes
The most insightful time you'll spend today!
Engineers that build last-mile delivery services belong to an elite order, a hallowed subcategory. Delivery customers are incredibly demanding when it comes to speed and convenience, and the services they use must take variables like increased traffic, road conditions, human error, and even driver availability into account every day.
Nuro is a company with a new approach to delivery services. Nuro has a fleet of autonomous vehicles designed to address many of the problems related to last-mile delivery. And every day, these vehicles — and their sensors — generate a lot of data before parking for the night. For Nuro engineers, that data can help them understand the impact of new on-road features, make improvements to their vehicles’ software, and ensure even better deliveries for their customers.
For Nuro, the key challenge is how to move petabytes of data as quickly, securely, and easily as possible from their edge environments, like vehicle depots, to Google’s Cloud Storage. For this delivery effort, Nuro selected Google’s Transfer Appliance with its new online transfer capability, now generally available.
Helping Nuro to speed up data delivery from the edge to the cloud
Like many Google Cloud customers, Nuro collects data from remote environments, like vehicle depots, that have different networking and storage capabilities when compared to a traditional data center. For a transfer solution to be effective moving unstructured data from these environments to the cloud, the solution needs to be easy to deploy and automate, while still providing similar performance as a more complicated alternative.
The Transfer Appliance was built for this use case. It arrives to customers as a physical appliance with a preconfigured version of Google’s Storage Transfer Service software already installed. Customers can move files to the appliance by using SFTP or SCP, or, alternately, can mount the appliance as an NFS share and copy target. Data can be stored locally on the appliance or transferred over the network, and secure encryption — at-rest and in-flight — is enabled by default.

With these new appliances, Nuro will be able to automate much of their storage transfer needs. When their autonomous vehicles return to the depot, they can move data like software logs, LIDAR data, and sensor data — all ideal fits for Google’s Cloud Storage — from parked vehicles to the Transfer Appliance. Online transfers can then be performed throughout the day, ensuring a steady stream of valuable data in the cloud for developers to analyze and use in their nightly builds. All of this will help Nuro’s engineering leaders like Jie Pan to run more productive development teams with less operational overhead.
“Our autonomous vehicles generate a tremendous amount of useful data, and our goal is to get that data to our engineers as soon as possible,” said Jie Pan, Engineering Manager at Nuro. “When vehicles return to the depot, we can move data hourly into Cloud Storage over the network. We also have the flexibility to return the Transfer Appliance back to Google Cloud. Most importantly, this rapid transfer architecture gives a meaningful boost to engineering productivity and development velocity.”
Going the extra mile
Engineering and infrastructure leaders understand the value of delivering the right data to the right teams, as fast as possible. By adding preconfigured, over-the-network transfer into a turnkey Transfer Appliance, Google Cloud customers can more easily automate these data deliveries by scheduling regular migrations of on-premises files, objects, and other unstructured data to our Cloud Storage.
As Nuro continues to grow their manufacturing and testing footprint, they plan to use Transfer Appliances to further scale and simplify their data migration from on-premises to Google Cloud. Cutting the time to migrate their data by more than half will make for happier, more productive developers, and that will help Nuro bring us all the future of delivery a little faster.
If you’d like to learn more about Transfer Appliance and its new online transfer capability, click here or reach out to your Google Cloud account team.
More Relevant Stories for Your Company
Forrester Research: The Total Economic Impact of SAP on Google Cloud
Migrating and running SAP on Google Cloud reduces complexity allowing for easier management, improving performance and security, and allowing organizations to better leverage SAP data to drive business outcomes. Over three years, SAP on Google Cloud reduces costs and improves performance and reliability. Among other benefits, migrating SAP to Google

Strengthening Operational Resilience in Financial Services by Migrating to Google Cloud
Operational resilience continues to be a key focus for financial services firms. Regulators from around the world are refocusing supervisory approaches on operational resilience to support the soundness of financial firms and the stability of the financial ecosystem. Our new white paper discusses the continuing importance of operational resilience to the financial

withVR Uses the Power of VR to Prep People with Speech Disorders for Real-life Speaking Situations
Editor’s note: Meet Gareth Walkom, an entrepreneur dedicated to helping others with speech disorders. Turning life experience into innovation Did you know that 3% of Americans have a speech disorder, while 1% of the world’s population have a stutter? Just getting what they need in everyday interactions can be stressful,

How Cloud Networks Enable CSPs to Deliver 5G
Communication services providers (CSPs) are experiencing a period of disruption. Overall revenue growth is decelerating and is projected to remain below 1 percent per year, following a trend that started even before the pandemic.1 At the same time, driven by the pandemic, data consumption in 2020 increased by 30 percent relative







