Loading…
Attending this event?
In-person
11-12 December
Learn More and Register to Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for KubeCon + CloudNativeCon India 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in India Standard Time (UTC+5:30)To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date." The schedule is subject to change and session seating is available on a first-come, first-served basis. 
Room 3 clear filter
Wednesday, December 11
 

11:30am IST

Configuring Object Store for Vector Database Applications - Jiffin Tony Thottan, IBM
Wednesday December 11, 2024 11:30am - 12:05pm IST
Vector databases like Milvus and LanceDB are revolutionizing similarity search and AI workloads. However, their performance in cloud-native environments depends heavily on optimized storage configurations. This session will delve into configuring Ceph's RADOS Gateway (RGW) using Rook for this workload. And provide a sample demo of how to run these applications with RGW.
Speakers
avatar for Jiffin Tony Thottan

Jiffin Tony Thottan

Backend Engineer, IBM
Jiffin Tony Thottan is part of the IBM Storage Team working as a Backend Engineer in Ceph. Initially part of the NFS team and contributed to GlusterFS , NFS-Ganesha projects. He has given presentations about his work at various conferences like FOSDEM, Storage Developer Conference... Read More →
Wednesday December 11, 2024 11:30am - 12:05pm IST
Room 3
  Data Processing + Storage

12:20pm IST

Data Protection Considerations for Elastic Cloud-Native Applications - Pankaj Ahire, Veritas Technologies
Wednesday December 11, 2024 12:20pm - 12:55pm IST
In this comprehensive session, we will delve into the intricate details of data protection in the context of cloud-native applications. We will start by examining the automation of application discovery. This includes a special focus on application-consistent backups, particularly crucial for distributed applications utilizing multiple persistent volumes. We will then navigate the considerations for temporary storage and compute needs during backup and restore operations. The discussion will extend to the impact on production applications' compute and I/O performance. As a highlight, the session will explore strategies for detecting and protecting applications from ransomware attacks. The final segment of the presentation will cover application recovery and thereby mobility of applications across different Kubernetes platform distributions. Each aspect is designed to prepare participants for a future where cloud-native data protection is efficient, resilient, and cost-effective.
Speakers
avatar for Pankaj Ahire

Pankaj Ahire

Mr. Pankaj, Veritas Technologies
Pankaj is technical lead and building data protection capabilities for Kubernetes, Hypervisors, OpenStack, File Systems in Veritas NetBackup. He is one of the key members of NetBackup engineering that laid the foundation for Kubernetes protection. He has overall more than two decades... Read More →
Wednesday December 11, 2024 12:20pm - 12:55pm IST
Room 3
  Data Processing + Storage

2:55pm IST

Ensuring Seamless Service Continuity in 5G: Enhancing Kubernetes Disaster Recovery for Telecom - Saurabh Swaraj, Grace Hanusha, Sunil N, Ganesh Chandrasekaran & Karthikeyan Subramaniam, Samsung
Wednesday December 11, 2024 2:55pm - 3:30pm IST
In the telecom industry, service availability is critical, making local and geographic redundancy essential for disaster recovery. While 5G Core Networks emphasize centralized, cloud-native strategies, 5G Access Networks require distributed, low-latency redundancy for edge cloud environments. Current CNCF tools like Velero, Portworx, and Stash offer Backup and Recovery Solutions but lack live synchronization between active and standby clusters, crucial for telecom's KPI needs. This session will explore a K8S-native solution designed to bridge this gap, offering seamless redundancy for telecom workloads, particularly in microservices-based deployments like vRAN/ORAN. This solution supports a 2-way policy-based sync, allowing for fine-grained control on how data is managed during failover. The solution integrates with CNCF projects, including Nephio for intent-based automation and Prometheus for real-time monitoring, aligning with the move towards distributed cloud-native deployments.
Speakers
avatar for Ganesh Chandrasekaran

Ganesh Chandrasekaran

Head of Telco Orchestrator Part, Samsung R&D, Samsung R&D, India, Bangalore (SRIB)
Ganesh is the Head of Telco Orchestrator Part at Samsung Research Institute, Bangalore. He holds a Master's degree in Telecommunications from UCL, London,UK. Ganesh completed his PhD from the 5G Innovation Centre at the University of Surrey, UK. Since 2017, he has worked with Samsung... Read More →
avatar for Grace Hanusha

Grace Hanusha

Cheif Engineer, Samsung R&D
Chief Engineer at Samsung R&D Banglore
avatar for Saurabh Swaraj

Saurabh Swaraj

Lead Engineer, Samsung R&D
I’m Saurabh Swaraj, a Lead Java Engineer with nearly 6 years of experience in developing scalable systems and solving complex problems. At Samsung R&D, I designed a Live Sync system that improved consistency to 99% and reduced delays by 16 minutes. Previously at Digbi Health, I... Read More →
avatar for Sunil N

Sunil N

Chief Engineer, Samsung Research Institute Bangalore, Samsung Research Institute Bangalore
Sunil has good experience in architect, design, implement software applications in telecommunication management domain. He is interested in Cloud, AI/ML domains.
Wednesday December 11, 2024 2:55pm - 3:30pm IST
Room 3
  Data Processing + Storage
  • Content Experience Level Any

3:45pm IST

WebAssembly Profiling with Pprof and Wzprof - Rajiv Ranjan Singh, A.P. Moller - Maersk & Naman Lakhwani, Independent
Wednesday December 11, 2024 3:45pm - 4:20pm IST
Embark on a journey to supercharge your Go applications targeting WebAssembly by harnessing the profiling capabilities of pprof and wzprof. This session unravels the intricacies of optimizing Go-powered web applications for maximum performance. Discover how pprof provides deep insights into CPU and memory usage, forming the foundation of our optimization journey. Complementing pprof, wzprof, tailored for WebAssembly, offers streamlined performance analysis during module execution. Through practical demonstrations, learn how pprof and wzprof work together to resolve performance bottlenecks, optimize computations, and manage memory effectively. This talk equips both seasoned Go developers and WebAssembly newcomers with essential tools and techniques to maximize application efficiency and speed.
Speakers
avatar for Naman Lakhwani

Naman Lakhwani

Independent, -
During his time at VMware, Naman was one of the early members of the VMware Tanzu's long-term support (LTS) team. He is a Kubernetes org member and closely works with the Structured-Logging Working Group in Kubernetes. He started his open-source journey with CNCF in 2021 with the... Read More →
avatar for Rajiv Singh

Rajiv Singh

Rajiv Ranjan Singh, A.P. Moller - Maersk
I am working as a software engineer at A.P. Moller - Maersk. I graduated from JSS Academy of Technical Education, Bengaluru with a Bachelor of Engineering degree in Information Science & Engineering. I am fascinated by the extensive impact computers can have on solving real-world... Read More →
Wednesday December 11, 2024 3:45pm - 4:20pm IST
Room 3
  Emerging + Advanced

4:50pm IST

Reimagining Kubernetes Pods: Nested Containers with CRI-O - Sohan Kunkerkar, Red Hat Inc
Wednesday December 11, 2024 4:50pm - 5:25pm IST
With user namespaces reaching beta in Kubernetes and new developments in CRI-O, we’re closer to making nested containers within pods more flexible and powerful. Traditionally limited by masked /proc and restricted user namespaces, this approach now offers capabilities similar to Podman. In this talk, we will explore how Kubernetes’ security features—privileged mode, rootless containers, and network isolation—can enable running containers inside pods. We’ll examine the support matrix for various configurations and discuss upcoming work to bring VM-like flexibility to Kubernetes pods for more secure and dynamic container orchestration.
Speakers
avatar for Sohan Kunkerkar

Sohan Kunkerkar

Senior Software Engineer, Red Hat Inc
Sohan Kunkerkar is a Senior Software Engineer at Red Hat, bringing expertise in distributed systems, backend engineering, and containers. His active contributions extend to CRI-O, a container runtime engine, and various sub-projects within the Kubernetes Sig-Node community. Sohan... Read More →
Wednesday December 11, 2024 4:50pm - 5:25pm IST
Room 3
  Emerging + Advanced

5:40pm IST

Effortless Clustering: Rethinking ClusterAPI with Systemd-Sysext - Sayan Chowdhury, Microsoft
Wednesday December 11, 2024 5:40pm - 6:15pm IST
Through the years, ClusterAPI has evolved into an indispensable tool, streamlining the lifecycle management of Kubernetes clusters across multiple infrastructure providers. The current approach adds a layer of complexity at the image-building stage, presenting users with a multitude of options. But what if we challenge this conventional approach? This presentation introduces a paradigm shift in ClusterAPI image building, leveraging systemd-sysext and image composability. Join me in this talk as we explore how this innovative approach could help cope with the never-ending matrix of Kubernetes versions and Distro images, significantly enhancing usability for users managing their workloads.
Speakers
avatar for Sayan Chowdhury

Sayan Chowdhury

Senior Software Engineer, Microsoft
Sayan is a Linux Software Engineer at Microsoft and a maintainer of Flatcar Container Linux. As a Release Manager, he works to maintain and build Flatcar. With a strong passion for open source, Sayan has been involved in other communities, namely Python, Fedora and Mozilla. Sayan... Read More →
Wednesday December 11, 2024 5:40pm - 6:15pm IST
Room 3
  Emerging + Advanced
 
Thursday, December 12
 

11:30am IST

A Deep Dive Into the Current Runtime Security Landscape - Ankur Kothiwal, CERN
Thursday December 12, 2024 11:30am - 12:05pm IST
The most widely used runtime enforcement techniques today are prone to attackers. Many of these techniques work on the principle of stopping or killing a process in response to an attack, which relies at the mercy of an exploit writer putting little to no effort into avoiding triggering these detection mechanisms. Our discussion will focus on various aspects of runtime security: how it is currently implemented, its shortcomings, and the performance implications associated with these approaches. We'll explore a various range of cloud-based runtime security implementations. We'll expose the attacker's perspective, demonstrating how they can bypass these common runtime security measures. This will equip you to anticipate and counter their tactics. Finally, we will cover recent popular attacks and how appropriate runtime security measures can prevent them in the future.
Speakers
avatar for Ankur Kothiwal

Ankur Kothiwal

Computing Engineer, CERN
Ankur Kothiwal is a Computing Engineer at CERN. He is actively involved in open source, currently serving as a maintainer and a CNCF Ambassador. In the past, he participated in and mentored various open source outreach programs and has also been a committee member for KubeCon Paris... Read More →
Thursday December 12, 2024 11:30am - 12:05pm IST
Room 3
  Security
  • Content Experience Level Any

12:20pm IST

Enhance Kubernetes Security with the Common Expression Language (CEL) - Hoon Jo, Megazone
Thursday December 12, 2024 12:20pm - 12:55pm IST
Among the 4C (Cloud, Cluster, Container, Code) security in Kubernetes, there are various techniques to enhance the security of the cluster surface. In particular, Admission Control (webhook) is one of the most flexible and powerful methods. As this trend, there is movement to apply it to various forms of Kubernetes(e.g. GKE, Openshift and so on). In my opinion, one of the easiest and most efficient ways to apply it is to improve security through CEL (Common Expression Language). I believe that the Validating Admission Policy becoming `stable` in v1.30 is part of this proof. So I will show you the CEL DEMO provided by Google Cloud to get a quick and easy understanding of how to improve the security of GKE. Through this exercise, you will learn the basic structure of CEL and the freedom of scope that can be applied, and you will be able to apply it to any other platform with minimal effort.
Speakers
avatar for Hoon Jo

Hoon Jo

Cloud Solutions Architect | Cloud Native Engineer, Megazone
Hoon Jo is Cloud Solutions Architect as well as Cloud Native engineer at Megazone. He has many times of speaker experience for cloud native technologies. And spread out Cloud Native Ubiquitous in the world. He has written several books and latest books is 『CONTAINER INFRASTRUCTURE... Read More →
Thursday December 12, 2024 12:20pm - 12:55pm IST
Room 3
  Security

2:55pm IST

Dynamic Management of X509 Certificates Using Kubernetes Certificate Operator - Abhidnya Joshi & Senthil Ponnuswamy, Dell Technologies
Thursday December 12, 2024 2:55pm - 3:30pm IST
Security is non-negotiable area and Kubernetes based environments are no exception! Usage of x509 certificates is the key thing. Be it K8s deployments in private or public cloud, ensuring availability of "right" X509 certificate for a service is very important. If this service is getting connected from external (apps/clients which are outside of K8s cluster) clients, this is even more important! But what is really the "right" x509 certificate and how can we ensure that is always remains "right"? Can we make corrections dynamically? Can we also ensure easy propagation of certificates imported from outside the cluster? Propagation of Certificate revocation lists to ensure services can deny revoked certificates? This talk helps describe the strategy K8s based products can use to dynamically generate, make correction and propagation of X509 certificates within K8s cluster using K8s operator design pattern and makes use of well-known CNCF projects such as cert-manager and trust-manager.
Speakers
avatar for Abhidnya Joshi

Abhidnya Joshi

Software Senior Principal Engineer, Dell Technologies
A technical leader in security and protocols area in Data Domain in Dell Technologies, has 18+ years of experience in the Software industry. Her domain expertise lies in popular file transfer protocols such as SMB, NFS and protocol Security and storage. She has worked with Samba community... Read More →
avatar for Senthil Ponnuswamy

Senthil Ponnuswamy

Distinguished Engineer, DELL Technologies
Senthil Ponnuswamy is a security leader with 16+ years of experience in building security features for storage products. He is the Chief Security Architect for DELL Technologies Data Protection Engineering. Senthil has also 13 security-related patents granted by USPTO.
Thursday December 12, 2024 2:55pm - 3:30pm IST
Room 3
  Security

3:45pm IST

Fuzzing for Stability: Uncovering and Mitigating Helm's CVE - Jakub Ciolek, AlphaSense
Thursday December 12, 2024 3:45pm - 4:20pm IST
Join this talk to uncover the story of a high severity CVE-2024-26147 [CVSS: 7.5] discovered in Helm and understand the role of fuzzing in maintaining the ecosystem’s integrity. Through this demonstration, you'll see firsthand the systematic approach used to identify the vulnerability that caused Helm to panic when faced with missing YAML metadata. The issue enabled crashing Helm SDK-based clients over the network and additionally, bricking local Helm client installations. We'll dive into the specific tools and techniques that were instrumental in detecting the issue, focusing on their applicability to your daily work. This session is designed not just to share a discovery but to foster a community-wide commitment to proactive security practices. Learn how these insights can be applied to strengthen the security and reliability of your Kubernetes deployments, ensuring a safer environment for all users of the ecosystem.
Speakers
avatar for Jakub Ciolek

Jakub Ciolek

Senior Tech Lead - Cloud Platform, AlphaSense
Jakub Ciolek is a seasoned Senior Tech Lead at AlphaSense, focused on Kubernetes and open-source innovation. He has made notable contributions to the Go compiler and identified key vulnerabilities in Helm and Argo CD. He is dedicated to driving forward secure, scalable solutions in... Read More →
Thursday December 12, 2024 3:45pm - 4:20pm IST
Room 3
  Security

4:50pm IST

SPIFFE as a Glue for Large Scale Telco Deployments: A Nephio Perspective - Rahul Jadhav, AccuKnox
Thursday December 12, 2024 4:50pm - 5:25pm IST
Emerging Telco trends such as ORAN, advanced 5G core demands a disaggregated arch for scaling. Kubernetes based deployments are becoming a norm and much of the open CNCF/LF tooling are playing a major role. The aim of this submission is to talk about the challenges that Nephio(www.nephio.org) SIG-Security team faced about streamlining security operations across multi-cluster multi-region, multi-vendor based deployments. The aim is to talk about specific instances/use-cases where the Nephio management cluster needs to securely interact with regional/edge clusters for the control plane needs. Also why/how the Nephio security team envisaged SPIFFE as a foundational layer to bind multi region together. A particular problem statement in the context of ORAN deployments where SMO (Service Mgmt Orchestation) has to securely interact with IMS (Infra Mgmt Service) for secure creation of infrastructure and the role SPIFFE played in the context would be highlighted.
Speakers
avatar for Rahul Jadhav

Rahul Jadhav

Nephio SIG-Security chair, CNCF Ambassador, CTO AccuKnox, AccuKnox
An avid coder, a systems engineer working on solutions involving security and performance of cloud-native tech. Contributed towards several open sources including Linux Kernel and worked closely with IETF Standards (such as ROLL, 6lo, LWIG) and Linux Foundation. Taken several projects... Read More →
Thursday December 12, 2024 4:50pm - 5:25pm IST
Room 3
  Security

5:40pm IST

Expedia Group's GitOps Revolution: Extensive Scalability Testing on ArgoCD for 30K+ Applications - Shivani Mehrotra, Expedia Group & Mohit Kumar, Coforge Limited
Thursday December 12, 2024 5:40pm - 6:15pm IST
Expedia Group's journey to implement GitOps with ArgoCD is a story of innovation, scalability, and overcoming challenges. Our GitOps journey involved migrating from KubeFed to ArgoCD, focusing on extensive scalability testing across hundreds of virtual clusters, set up using open source tool, vcluster. We proactively identified potential challenges and prepared comprehensive test cases tailored to different application flavors. We created three types of applications for testing, with sizes varying between 15-30 resources, including CRDs and jobs, small applications containing 15 resources and large applications containing 30 resources. We experimented with multiple test scenarios, using permutation and combination of applications tested on 300 vclusters, scaling approximately 1,000 applications to 30,000+ across these clusters. We concluded this initiative with determining optimal settings for various tunable parameters in the ArgoCD controllers.
Speakers
avatar for Mohit Kumar

Mohit Kumar

Coforge, Senior DevOps Engineer, Coforge Limited
Mohit, Senior DevOps Engineer at Coforge, specializes in GitOps and DevOps methodologies with a focus on Kubernetes orchestration and cloud infrastructure. His expertise ensures high availability and scalability across global platforms. Committed to the forefront of technology, Mohit... Read More →
avatar for Shivani Mehrotra

Shivani Mehrotra

Shivani Mehrotra, Expedia Group, SDE-II, Expedia Group
Shivani, SDE-II at Expedia Group is a platform engineer, specializing in building robust systems. Passionate about innovation, Shivani thrives on challenges, delivering impactful results in her role. Outside of work, Shivani enjoys exploring new technologies and staying at the forefront... Read More →
Thursday December 12, 2024 5:40pm - 6:15pm IST
Room 3
  Platform Engineering
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Content Experience Level
  • Timezone


Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.