Chapter 15. Retrospectives and Futures
When I first started with PaC, almost eight years ago, I was looking for a way to remove the tight coupling between control definition and control implementation. I knew that writing imperative code to implement all the cloud controls we needed was not a sustainable model. That led me to adopt Cloud Custodian in 2016 as part of our AWS cloud migration.
Along the way, I tried Chef InSpec and Puppet. While both are viable solutions for what they do, I wasn’t satisfied with their approach or syntax for my use cases. I am in no way knocking these solutions. In fact, I used Chef to counter drift in several use cases. I just didn’t think they were the best solutions for my need to interrogate our cloud resources and build detective and preventive controls for real-time, near-real-time, or even periodic reactions. And c7n’s declarative syntax was very appealing to me.
Two years later, I was searching for a similar solution for building Kubernetes controls; c7n wasn’t an option at that time. Instead, I chose OPA and started my Rego adoption. After learning Rego, I found myself writing helper libraries to perform common tasks in Rego Kubernetes policies, like getting Pods, containers, and their respective metadata and settings. I then moved on to more declarative solutions, like Gatekeeper and eventually Kyverno.
Considering the PaC solutions I covered in this book, I think there are a few trends that have led to improved adoption. In this chapter, ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access