A New Milestone: Istio Comes Closer to Cloud-native Ecosystem - Build What's Next
Blog

A New Milestone: Istio Comes Closer to Cloud-native Ecosystem

3454

Of your peers have already read this article.

2:00 Minutes

The most insightful time you'll spend today!

The Istio project is a part of cloud-native infrastructure like Kubernetes and Knative. After adoption by over 100 organizations and 4,000+ developers, Isito has been submitted as an incubating project within Cloud Native Computing Foundation (CNCF).

Today we are excited to announce that Google and the Istio Steering Committee have submitted the Istio project for consideration as an incubating project within the Cloud Native Computing Foundation (CNCF). This is a significant milestone for Istio and its community, and we are thrilled to reach this next step in the evolution of the project.

Google and Istio


Google originated the Istio project, which alongside Kubernetes and Knative, is a critical part of cloud-native infrastructure. The Istio project has found success and maturity in its current model — being adopted by hundreds of organizations and bringing in over 4,000 developers for IstioCon.

For over 20 years, Google has helped shape the future of computing with its open source contributions and has invested deeply to unlock innovation for our customers. Istio extends Kubernetes to establish a programmable, application-aware network using the Envoy service proxy. Istio works with both Kubernetes-based and traditional workloads, and brings standard, universal traffic management, telemetry, and security to complex deployments. Finding a home in the CNCF brings Istio closer to the cloud-native ecosystem and will foster continuing open innovation.

The Istio journey


We started to develop Istio in partnership with teams at IBM and Lyft in 2016 based on patterns that were being used to connect Google production applications. Google’s security focus complemented the traffic management focus of an open-source project published by IBM, and those two teams decided to collaborate on Istio directly. Istio was launched “fully formed” in May 2017, with the v0.1 release featuring sidecar-powered traffic control, observability and policy features — the things that today define a service mesh. Istio has been open source from the beginning, and has a governance structure that promotes continuous contribution and project engagement.

By the release of v0.3 a few months later there were users trusting it in production, seeing immediate benefits from its powerful features. The project reached v1.0 in July 2018, and was being used at scale by eBay and The Weather Company. Google led a major re-architecture with the release of v1.5, unifying the control plane into a single service. This change, based on user feedback, reduced administrative overhead, as was later written about in the IEEE Software journal. We also greatly simplified extensibility of the mesh by building support for WebAssembly plugins into Envoy.

Istio is now offered as a managed or hosted service by over 20 providers, including Anthos Service Mesh, a suite of tools that helps you monitor and manage a reliable service mesh on-premises or on Google Cloud.

The future of Istio as a project in the CNCF


At Google, we believe that using open source comes with a responsibility to contribute, sustain, and improve the ecosystem, and we are committed to improving critical cloud-native projects on behalf of our customers and the community at large. Google has made over half of all contributions to Istio and two-thirds of the commits, as measured by the CNCF DevStats.1 After deciding to adopt Envoy for Istio, Google rose to be Envoy’s number-one contributor.2

Istio is the last major component of organizations’ Kubernetes ecosystem to sit outside of the CNCF, and its APIs are well-aligned to Kubernetes. On the heels of our recent donation of Knative to the CNCF, acceptance of Istio will complete our cloud-native stack under the auspices of the foundation, and bring Istio closer to the Kubernetes project. Joining the CNCF also makes it easier for contributors and customers to demonstrate support and governance in line with the standards of other critical cloud-native projects, and we are excited to help support the growth and adoption of the project as a result.

Istio is key to the future of Google Cloud and if the project is accepted, Google will continue to strategically invest in Istio as a key maintainer and through ongoing investment in engineering for upstream contributions.

1. https://istio.teststats.cncf.io/d/5/companies-table?orgId=1
2. https://envoy.devstats.cncf.io/d/5/companies-table?orgId=1

Blog

Recent Updates on Google Cloud EKM to Meet Customers’ Cloud Data Security

3225

Of your peers have already read this article.

2:00 Minutes

The most insightful time you'll spend today!

Google Cloud's External Key Manager (EKM) safeguards cloud data with encryption keys stored and managed in third-party management system. With ongoing efforts to help firm take encryption into their own hands, Google Cloud released new features.

Google Cloud External Key Manager (Cloud EKM) lets you protect your cloud data with encryption keys that are stored and managed in a third-party key management system outside Google Cloud’s infrastructure. This allows you to achieve full separation between your encryption keys and your data stored in the cloud, making you the ultimate arbiter of access to your data. We are continuously innovating and developing the functionality of Cloud EKM, so let’s explore some recent updates we’ve made.

New functionality


Available today, we have added several much-anticipated features to Cloud EKM to help meet customer requirements:

Cloud EKM over VPC

Many customers want to incorporate an additional layer of security and reliability when connecting their key manager to the cloud. To help meet this need, we are introducing Cloud EKM support for Virtual Private Cloud (VPC) networks. This support allows Cloud EKM to connect via a secured private network, giving customers stricter control over network access to their external key manager. For more information, see Using Cloud EKM with VPC.

Support for asymmetric keys

In addition to symmetric encryption keys, Cloud EKM now recognizes both RSA as well as Elliptic Curve asymmetric keys created in a supported external key manager. With support for asymmetric keys, you can sign approvals granted via Access Approval. Asymmetric keys can add a layer of assurance when granting administrative access to customer data. You can also use the external asymmetric keys to sign data just as you would a cloud native key. For more information, see Asymmetric signing keys.

Protection level organization policy

We’ve made a new organization policy available for Cloud KMS that allows for fine-grained control over what types of keys are used. By using this org policy, you can specify that only specified KMS key types, for example EXTERNAL or EXTERNAL_VPC, may be created. This function can help meet specific requirements for separation of data or data sovereignty, ensuring only externally-managed keys are used with certain workloads. For more information, see Organization policy constraints.

Cloud EKM supports the Google Cloud services which typically store customers’ most sensitive data assets, and we are constantly adding support for more services. For example, we recently added Cloud EKM support for Cloud Storage, allowing customers to leverage Google-scale storage while adhering to local regulations and holding their keys in their own key manager. For a complete list, see our currently supported services, and if you’re interested in using Cloud EKM with a GCP service that is not yet supported, you can make feature suggestions here.

Best practices for Cloud EKM


The newly published Reference architectures for reliable deployment of Cloud EKM services guide provides recommendations for running a highly available and reliable external key manager integrated with Cloud EKM. These recommendations answer some of the most common questions and concerns we’ve heard from customers. The recommendations are aimed at operators of an external key manager, meaning that if a supported partner operates your EKM, you might share some of these responsibilities with a partner, depending on the design of their product and how it integrates with Cloud EKM.

Take encryption into your own hands


Being deliberate about encryption is critical for securing your sensitive data on Google Cloud. We’re always evolving our encryption products to meet your needs and help you achieve your business goals, and we hope that the additional features mentioned in this blog will allow you to make better use of your key management infrastructure. To get started with Cloud EKM, check out our documentation to learn more or try it for yourself in the GCP console.

3721

Of your peers have already watched this video.

1:26 Minutes

The most insightful time you'll spend today!

Case Study

How Sri Lanka’s Largest Ride-hailing Company Fixed its App and Improved Business

PickMe is Sri Lanka’s largest ride-hailing company.

“(Almost) every Sri Lankan is our customer. We have passengers who use us on a daily basis. We have drivers who use the platform to make a living. So obviously, the ecosystem is pretty big,” says Jiffry Zulfe, Founder & CEO, PickMe.

Before the company used Google Cloud, it hosted in a local data center. That strategy caused problems.

The first was the local provider’s ability to keep up.

“We were a company that was growing very fast. So the number of customers, the number of drivers, the volumes, would double every couple of months. And that required computer power, which the local provider struggled to do.”

The company also faced reliability issues. It’s servers would go down sometimes, which would slow down some of the services and affected customer experience.

That’s when they decided to get on the Google Cloud Platform.

“By bringing GCP into our platform, we saw a huge improvement in our latency. And also, we have had great reliability. The customers have gained confidence that when you open that app, it works all the time,” says Mithila Somasiri, Chief Technology Officer at PickMe.

Whitepaper

CFO Watch: A Handy Guide to Financial Governance in the Cloud

DOWNLOAD WHITEPAPER

3958

Of your peers have already downloaded this article

4:30 Minutes

The most insightful time you'll spend today!

With a growing number of enterprises across industries making the move from on-premise infrastructure to on-demand cloud services, there has been a major shift from CapEx to OpEx spending. As a result, budgeting can no longer be a one-time operational process completed annually. Instead, spending must be monitored and controlled on an ongoing basis due to the dynamic nature of cloud use within organizations.

Hence, yesterday’s solutions for control and predictability of infrastructure expenditures don’t work well in this new era of cloud services. No wonder, a recent Google study on cloud financial governance among IT and Finance professionals found that lack of predictability is the single greatest cloud cost management pain point.

What is needed by organizations are cloud financial governance tools — that are easy to use and help uncover opportunities for optimizing costs and usage — to make cloud costs more predictable.

Download this handy guide on financial governance in the cloud to learn how you can get on the path to predictable cloud costs.

6520

Of your peers have already watched this video.

46:30 Minutes

The most insightful time you'll spend today!

Case Study

The Inside Story of How Home Depot Migrated to Google BigQuery From an On-prem DW Solution

In the media, you will often hear story of how born-in-the-cloud companies manage with massive infrastructure.

But it is one thing is to be a startup, and build infrastructure with bespoke requirements. And quite another to have a complex, multinational organization with online, with mobile, with brick-and-mortar presence, and hundreds of thousands of SKUs and professional services, and many, many years of technology, innovation, and really smart engineers.

This is the second story. The story of how The Home Depot, the number-one home improvement retailer in the US pulled of that feat.

The Home Depot has over 2,200 stores, over 4 lakh associates, and 2017 revenues of over a $100 billion.

In this video, Rick Ramaker, technology director, data analytics at The Home Depot, and Kevin Scholz, distinguished engineer, The Home Depot, talk about how the company transformed and modernised its data warehousing, the challenges they faced and the benefits they accrued from the project.

It’s a fascinating watch!

Blog

Canada’s Climate Scientists Use Google Earth Engine to Observe Foliage Density in Near-real Time

3400

Of your peers have already read this article.

1:30 Minutes

The most insightful time you'll spend today!

NRCan's expert talks to Google Cloud's executive on cloud computing and ML tools' role in sustainability and climate resilience initiatives. Read how their LEAF toolbox that builds on EE satellite data creates customizable maps of foliage density!

Climate scientists face a deluge of environmental data to analyze and interpret from real-time sensors and satellites across the globe. The stakes are as high as our planet’s long-term future, but rapidly changing conditions are already impacting communities through extreme events like floods and wildfires as well as management of everyday resources. In this context, detailed environmental maps are key sources for urgent global issues like food security, water quality, and vegetation levels.

Scientists, researchers, and developers rely on state-of-the-art cloud computing tools like Google Earth Engine (EE) to detect changes, map trends, and quantify differences on the Earth’s surface. EE leverages the compute power of Google Cloud to combine a multi-petabyte catalog of satellite imagery and geospatial datasets with planetary-scale analysis capabilities.

To find out more about how climate scientists address these complex research challenges, I spoke to Dr. Richard Fernandes, Research Scientist at Natural Resources Canada (NRCan). Dr. Fernandes is also a 2022-23 member of the Google Research Innovators Program, which provides technical and professional support to a global cohort of leading researchers. I asked him to describe how cloud computing and machine learning (ML) tools can support climate resilience research and drive awareness about climate sustainability.

Dr. Fernandes, can you give me an overview of your research in climate sciences?

My research focuses on mapping the status and trends of vegetation over Canada. Every month we generate maps of vegetation parameters, such as canopy cover at 20m resolution, to support environmental monitoring and assessment. These maps contribute to global datasets that are used to reduce uncertainty in weather and climate forecasts.

Canada has approximately 10 million square kilometers of land and the annual data volume of these maps is equivalent to streaming HD movies for over 750 hours non-stop. And that’s only the tip of the iceberg: the volume of input data we need to generate those maps is typically 100 times more. Unlike movie streaming services, we have to independently process each input pixel to locate it accurately, screen for clouds (and even the shadows of clouds), and then transform it into a vegetation parameter value like canopy cover using ML algorithms.

The volume of high-resolution data and the amount of compute we need are challenging and ever-increasing. Rather than dedicating servers 24/7 for constant monitoring, we rely on cloud computing and ML. Cloud computing allows us to manage all this data in a useful and accessible way. We have also been able to successfully use the Google Artificial Intelligence (AI) Platform to calibrate new ML models for third-party datasets.

How did you start working with Google Cloud?

I started using EE together with open source APIs for integration with Google Drive about four years ago. With the pandemic my research group has transitioned to using EE, Google Cloud, and Google Drive for both our Canada-wide mapping as well as for R&D activities. In January we developed and released the LEAF toolbox, which builds on EE satellite data to create customizable maps of foliage density in near real-time. We do all of the pixel processing in EE and leverage the ability to integrate our own functions using their APIs. We combine EE with Google Cloud to handle and manage output datasets. Fortunately, EE has most of the input data already at hand so we don’t need to deal with that 100x larger volume.

What impact do you expect LEAF will have now–and down the road?

Both the Canadian federal government and provinces already use our data products as inputs to permafrost, crop status, and water resource models. Agriculture Canada had been using a conventional Geographic Information System (GIS) and approached us to ask how we manage our data. They want to use LEAF to assess how crops are progressing, which impacts local economies and the global food supply. We’re in a pilot with them to apply EE to their crop condition assessments.

Also exciting is that the Province of Alberta is integrating the LEAF toolbox within a system for monitoring the reclamation status of oil and gas wells and mines. They want to know how to rehabilitate sites that were developed for mineral and gas deposits. This is another great use case but many others are possible. The technology itself is cool, but that’s not even the point. ML algorithms are constantly evolving and improving. New ML algorithms use active learning that detects mistakes and makes updates on the fly. The technology will be different in five years — or five months! — so our priority is making these tools accessible and useful now.

Comparing tree leaf canopy year over year with LEAF.

Why is state-of-the-art technology for climate research so important?

Scientific research must be validated, transparent, and rigorous to drive the best solutions to our complex and changing ecosystem. Climate action needs greater public awareness, which requires more knowledge, which demands the best data. By democratizing information and decision-making, we can create an ecosystem of openness and public-private partnerships. We can lower the barrier to entry for advanced research and help scientists validate and reproduce their results. Also, scientists don’t want to have to become software engineers for these custom highly specific solutions. They want user-friendly tools that let them focus on their analyses and share their insights with the world. That’s one of the major appeals of the Google Research Innovators Program for me: I want to share LEAF with colleagues and collaborate with other researchers who are using new tools in new ways.

Do you have any parting words about your mission?

We’re so fortunate to have Canadian taxpayers and the Government of Canada funding our work. We have worked with many scientists over the past two decades to develop and validate the algorithms we use, especially Fred Baret and Marie Weiss at INRA France, who have championed the idea of free and open access to algorithms and knowledge, and data.

I really believe in democratic access to information. I like the fact that the terms of service of Google products allows us to offer not only maps but the actual processing system in a free and open manner to everyone. I also like that EE provides a simple-to-use user interface that works on mobile devices. We designed LEAF not just for experts, but for individuals. My mom was able to make maps of a nearby park in real time on her tablet. It is my hope that expanding access to critical environmental information will increase our collective awareness of how our actions impact both near and far places — and make us active in the cause of a sustainable future.

That’s an inspiring note to end on. Thank you for your time!

Thanks for having me!

Click here to learn more about Google’s commitment to renewable energy. Or try the LEAF toolbox for yourself!

More Relevant Stories for Your Company

Blog

Google Cloud Cortex Framework: Innovate on Cloud with Less Risk, Cost and Complexity!

Google Cloud Cortex Framework is a comprehensive approach to cloud innovation that enables users to accelerate value with less risk, complexity and cost! The Cortex Framework includes a comprehensive tools and know-how to build, design and deploy cloud solutions to address business challenges and achieve desired outcomes. Watch the video

Case Study

How Lowe’s SRE Team Decreases Mean-time-to-recovery (MTTR)

Editor’s Note: In a previous blog, we discussed how home improvement retailer Lowe’s was able to increase the number of releases it supports by adopting Google’s Site Reliability Engineering (SRE) framework on Google Cloud. Lowe’s went from one release every two weeks to 20+ releases daily, helping meet its customer needs faster and

How-to

6 Tips for Stress-Free Google Cloud Billing

If you took one look at the title of this blog and thought, “just show me how, because I already know a million reasons why I’m stressed about billing things” then check out the interactive tutorial right here. For everyone else, read on, because we’ll walk through some common sense tips,

Case Study

Vodafone Leverages Google Cloud to Aid COVID-19 Frontline with Anonymized Insights on Population Mobility

Editor’s note: When Europe’s largest mobile communications company, Vodafone, was asked by the European Commission to help understand population movement across the European Union and the UK to help fight COVID-19, it was able to provide anonymized mobile network-based insights to answer the call. Here’s how Vodafone, with the support

SHOW MORE STORIES