Keynote: What We Learned Dissecting the World’s Most Popular Containers - Ayse Kaya
Transcript source: automatic speech recognition on Vidleaf (unedited, may contain errors). Paragraph breaks and timestamps added by Vidleaf.
[0:00] Have you ever felt infinitely small. in front of something, vast and complicated. Like... the midnight sky. Ever since I was a little girl, I've been fascinated by complexity. especially how complexity emerges from simple, humble beginnings. from elemental particles to galaxies. And as a researcher at MIT focusing on emerging technologies, I was fascinated.
[0:34] captivated by research like Stephen Wolfram and John Conway's Game of Life. Tying. The computer systems fit biological world. with life itself. After all, what could be more complex? then biological systems. Right? Except maybe Kubernetes. If Kubernetes is the organism, then containers are the cells. And maybe that takes the analogy a little too far, but we know that containers are being used all the time, everywhere.
[1:17] In nearly every software development project, across all verticals. See? I'm not a DevOps engineer. I'm a data scientist. working for a startup called Slim.ai. At Slim, we are obsessed with container optimization and security. And we scan hundreds of thousands of containers regularly. This year alone, we have scanned more than 900,000 containers.
[1:50] And as a data scientist, Working with this data, I would like to provide you a window into The world of containers. As developers experience it, often for the first time. I would like us to expand our senses about this world. I would like us to look at some perspective shifting data about this world. Take, for example, The 60%.
[2:23] That's. the percentage of top publicly available containers that have more vulnerabilities in them today than they did a year ago. 60%. And this is after a year of intense focus on social air supply chain security. in the aftermath of multiple security incidents. Thank you. The rest of the containers haven't improved that much, and we'll be talking about that in a moment.
[2:56] But before, let's couple this insight with this other statistic here. This one. is from a global randomized study that we designed. asking questions to developers and DevOps engineers. 70% said Their customers are asking, demanding their containers to have Zero vulnerability. On top of that, 88% of the developers said It is getting more challenging to remove the vulnerabilities from their containers.
[3:34] The number one contributing factor being the complexity. numerous components with dependencies. them. So as you can see, there's a story that's unfolding before our eyes. Containers are becoming more vulnerable. Customers are demanding perfection more than ever. and developers are feeling the pressure. And although developers are in the heat of the battle, There is an undeniable rising tide.
[4:08] When it comes to Developer interests. in Kubernetes and containers. and container adoption across companies large and small. In fact, Developers are beginning to look at a technology like Docker as native to their workflows like a tool like Git or an IDE. According to Stack Overflow's 2022 Developer Survey, "Dakar" is the number one technology developers Love?
[4:42] and want to learn. And you can see this in the usage stats as well. The all-time pools on Docker Hub has tripled in just a year. But while there are lots of tutorials out there, to learn about shipping and building containers. There is precious little understanding around what's in them. Like self. Containers are being seen as these Atomic units. building blocks of living organisms.
[5:15] where requests go in. Data comes out. It's just that simple. But then... Something like log4shell happens. And before we know it, 2022, becomes the year of software supply chain security. And we are all more invested in understanding not only the principal components of our software systems, but also their second order effects.
[5:48] their dependency trees. So how did this renewed sense of awareness change the container landscape. My research team. It's Slim.ai. have been deconstructing, analyzing, observing containers in an effort to understand What makes these containers developer friendly, and production ready. Last year, around this time, We've put a magnifying lens onto the top publicly available containers on Docker Hub.
[6:23] and publish the report with analytical insights. We had some shocking findings in that report, and I'm not going to list them all. But I'm going to tell you this. As container enthusiasts, We were expecting to see some outliers. Certain containers, certain container categories, having a large number of vulnerabilities, packages, libraries, licenses, special permissions, what have you. But even the averages were surprisingly high.
[6:57] And one thing to note about these containers is that, yes, there are 10 million images on Docker Hub, with more than 318 billion pools. But this top 165 containers account for more than 30% of all use, so it's a very special cluster. So today, be published A sequel to that report. This time, focusing on the delta between last year and this year.
[7:31] So let's go ahead and look into the data and some of our learnings findings. The first finding is that we have more high and critical vulnerabilities than ever across all categories. Now, I already mentioned that 60% of the containers have more vulnerabilities today. than they did a year ago. And yes, we did remediate certain vulnerability, certain incidents. But we are detecting new incidents four times faster.
[8:03] than our remediation rate. And the new ones, the new incidents that we detect, are mostly high and critical. vulnerabilities, but the high severity vulnerabilities have increased by 50%. this year. So today, The average container has almost 300 vulnerabilities, 30% of Fitch is high or critical. up from 20% last year.
[8:35] And V thought, 20% was too high. Let's move on to the next finding. Component complexity has also increased significantly. The average container today has 400 packages. And if you think about it, "This number is supposed to be The tip of the iceberg. Every package might have thousands, sometimes hundreds of thousands of dependencies as shown by multiple studies.
[9:06] But it turns out that even the tip of the iceberg is a nice work. And it is not just the packages. The licenses have increased by 2.5x, the containers have more layers, they are larger, the scanning of these containers takes longer times and even the metadata. They're S-bombs. have increased by 40%. Now, don't get me wrong.
[9:38] These tools, these packages are necessary for experimentation. It helps developers to debug and test and build and have fun. but they also represent a type surface. and imply the need to have an automated process to remove this so that that attack suffers surface never makes it production. Data is data. But what's the impact on our people?
[10:10] How does this more complex and more vulnerable. landscape impact our DevOps engineers and developers. I mentioned that 88% said they find it more challenging to remove the vulnerabilities. Only one. in four developers. said they fully understand how container slimming and hardening works. And interestingly, There seems to be a mismatch, a disconnect between executives and the frontline engineers.
[10:47] 49% of the executives said they are slimming and hardening containers in their companies. but the people who do the actual work. are reporting significantly lower numbers. Governments and companies may be demanding a world with zero vulnerabilities But that land, feels out of reach.
[11:18] given our tools and techniques. The sobering bottom line is that we are no more secure today than we were back in 2021. The silver lining, however, is that we have woken up. And we are more aware of these challenges than ever before. For us at Slim, we believe you should know what's inside your container. and you should ship only what's needed to production. We're seeking to solve this challenge for all of the world's containers through automation and intelligent optimization.
[11:54] And look. I do not think complexity is the enemy here. Ignorances. There are times where we need to take a step back and enjoy the poetic beauty of the complex systems around us. There are other times where we need to step in fearlessly and deconstruct and redesign. I know.
[12:26] that we have to resolve the decision intelligence. the willpower to solve these issues. And most of the decision makers are in front of me. In this room. My friends say I'm an incurable optimist. But that's not why I think the future is bright. I know there are relentless Brilliant! competent teams around the world who are losing their sleep thinking about these problems.
[12:58] So many teams. that I couldn't even fit. the names that we leveraged for this project alone in my thank you card here. And as humans, when we gather, like we did at this fabulous location When we put our hearts and minds together, We can make even ridiculously tough beats Lupeze. And that's why I know when I'm on this stage next time, I will be bringing.
[13:30] Better news. Thank you. ♪ ♪
Open in the Vidleaf workbench
Search the transcript, select lines, copy quotes with timestamps, translate.
Attribution
"Keynote: What We Learned Dissecting the World’s Most Popular Containers - Ayse Kaya" by CNCF [Cloud Native Computing Foundation] (https://www.youtube.com/@cncf), licensed under CC BY 3.0 (https://creativecommons.org/licenses/by/3.0/). Source video: https://www.youtube.com/watch?v=f2-nk5qIur8. This page is a text transcript of the video with paragraph breaks and timestamps added; the creator is not affiliated with and does not endorse Vidleaf.
Are you the creator or a rights holder? Request a correction or removal: copyright@vidleaf.app (see About these pages).
Last updated