Copyright © SUSE 2021
So, you think you know
SUSE? Jurriën Bloemen
Solution Architect @ SUSE
jurrien.bloemen@suse.com
Copyright © SUSE
2021
Powering Innovation With Leadership in Linux & Kubernetes
Hybrid
Cloud
Infrastructure
Dev Datacenter Branch
Cloud Edge
Support
&
Services
Catalog
Security
Storage
Governance
The platform for managing all Kubernetes distributions
Datacenter Edge Block Storage
Linux SLE Desktop / POS
SLE Server
SLES for SAP Applications
SLES for HPC
SLE Micro
SLE Extensions
SUSE Manager
SUSE Linux Enterprise
Compliance
Security
Availability
Management
The most adaptable Linux operating system Other Linux
Copyright © SUSE
2021
SUSE Linux Enterprise
Copyright © SUSE
2021
The Most Adaptable Linux OS
SUSE Rancher / Virtualization / Platform-as-a-Service / Bare Metal Apps
Desktop /POS Datacenter Branch
Cloud Edge
SLE
Product
Family
Availability
Management
Compliance & Security
Copyright © SUSE 2020
AMD64 / Intel 64 Arm 64
IBM Power IBM Z & LinuxONE
Products & Solutions
SLE High Performance
Computing
SLE Real Time
SUSE Linux Enterprise
Server
SLES for SAP Applications
SLE Micro
SLE Desktop / POS
Management &
Automation
SUSE Manager
Global Services
Support
Subscriptions
Consulting &
Training
Select Services
Architecture
Extensions
High Availability &
Geo Clustering
Workstation
SLE Live Patching
Hybrid Cloud
Infrastructure
Supports SLES &
Other Linux
Copyright © SUSE 2021
SUSE provides life cycle options to customers​
depending on the customer specific needs​
SLE 11 – in LTSS, no further active development
SLE 12 – general support, selected enablement
SLE 15 – general support, active development
 13 years total lifecycle, 7 Service Packs (SP)
 Service Pack Overlap Support: 6 months
 Long Term Service Pack Support (LTSS): up to 3 years after end of general support
 Specific products can have longer overlapping support (e.g. SLES for SAP)
 See https://www.suse.com/lifecycle
5
SUSE Linux Enterprise Life Cycle
GA = First release of code stream
GE = End of general support
LTSS = Long Term Service
Pack support
EOL = End of life
SLE
15
2018 2019 2020 2021 2024 2025
2022 2023
SLE
12
Next major
codestream
SLE
11
2026
GA
SP0
SP1
SP2
SP3
SP4
SP5
2030
2018 2020 2026 2028
2022 2024
SLES lifecycle, other products may have
longer overlapping support
Contains forward looking statements. Subject to change.
GE EOL
GE
GA SP1 SP2
SP5
SP4
SP4 SP5
SP2
SP3 SP6 SP7
SP6
SP7
Copyright © SUSE 2021
SLE Micro
Copyright © SUSE 2021 7
Immutable Operating System
Immutable design ensures OS is not altered during runtime and runs reliably every single
time.
Prepared to support very long product lifecycles
Peace of mind for all – developers, administrators and enterprises.
Near-zero Downtime
Apply security updates without rebooting kernel.
Update application workloads when needed.
Mission-Critical by Design
Copyright © SUSE 2021
Secure OS Platform
Built-in Security Framework for OS and Containers
Deploy secure systems with United States Department of Defense-style
mandatory access controls using SELinux.
Secure Device Onboarding
Securely onboard remote appliances/devices.
Ready for Certifications & Compliance
Leverages certifications and compliance from SLE, such as FIPS 140-2, DISA SRG/STIG.
8
Kernel Live Patching
Reduce risk of cyber attack, apply security updates to Linux kernel as soon as available
without waiting for a maintenance window.
Minimal Attack Surface
Immutable design, minimal attack vectors.
Copyright © SUSE 2021
Perfect for Containers & Kubernetes
*SLE Micro supports K3s, RKE2 or 3rd party Kubernetes distributions 9
Built from ground up to support containers
and microservices.
Workloads are isolated from the core
filesystem to guard against malicious
applications compromising the system.
Easily combine SLE Micro with K3s, the
world’s most popular Kubernetes*
distribution for use in low resource,
distributed edge locations.
Copyright © SUSE
2021
22 APRIL 2021
SUSE Manager
Copyright © SUSE
2021
Open-Source infrastructure management solution designed
to help your enterprise DevOps and IT Operations teams to:
•Optimize operations while reducing costs
•Reduce complexity and regain control of IT assets
•Ensure compliance with internal security policies and
external regulations
11
SUSE Manager
SUSE MANAGER 4
Copyright © SUSE
2021
12
Multi OS support
L
Linux 2
Copyright © SUSE
2021
Rancher Desktop
Running Kubernetes on your Laptop/Desktop
Copyright © SUSE
2021
14
Copyright © SUSE
2021
15
Copyright © SUSE
2021
16
Copyright © SUSE
2021
17
Copyright © SUSE
2021
18
You can start using it today!
https://rancherdesktop.io/
Copyright © SUSE
2021
SUSE Rancher
Copyright © SUSE
2021
20
SUSE Rancher - the industry’s leading platform to manage
all Kubernetes distributions
Containerized App 1 Containerized App 3
Containerized App 2
Security & Authentication Policy Enforcement & Governance
Simplified Cluster Operations & Infrastructure Management (Run & Manage)
Platform Services (Build & Run)
SUSE Linux Enterprise / RHEL / Ubuntu / Oracle Linux / Amazon Linux
Amazon
EKS
Azure
AKS
Google
GKE
Cloud
Datacenter Edge
Branch
Dev
K8s Version Management
GitOps Continuous
Delivery
Cluster Templates &
Config Enforcement
Node Pool Management
Cluster Provisioning &
Lifecycle Management
Centralized Audit
Monitoring &
Logging
CIS Benchmarking
RBAC, OPA, Pod
& Network Policies
Rancher
Catalog
Monitoring &
Alerts
Dashboards &
Observability
Service
Mesh
Longhorn
Storage
Copyright © SUSE
2021
Innovate Everywhere
Rancher Overview
Rancher provides a consistent interface for
managing and interacting with the cluster.
Providing a gateway to Kubernetes native
apps through the catalog.
One Dashboard
Rancher can be installed on
any CNCF certified cluster.
Installs Everywhere
Rancher provides a graphical interface for
managing smaller environments. The built in
GitOps engine allows deployments to scale
up to thousands of clusters.
Scaled Management
Rancher Multi-cluster Manager unifies
clusters to ensure consistent operations,
workload management, and enterprise-
grade security
Multi-cluster Management
Leveraging the agility and software
delivery from the Datacenter is making its
way to branch offices, cell towers and
satellites.
Edge
Rancher provides a consistent
experience for Kubernetes clusters on the
desktop, edge , or datacenter.
Single Cluster
Available Vision
Copyright © SUSE
2021
SUSE Edge
Copyright © SUSE
2021
Innovate Everywhere
SUSE Edge Overview
Rancher provides a consistent interface for
managing and interacting with edge clusters.
Rancher
Rancher’s Continuous Delivery feature is
based on Fleet. Fleet provides a built in
GitOps engine which allows deployments to
scale up to tens of thousands of clusters.
Continuous Delivery (Fleet)
SUSE’s container optimized, ultra-reliable,
lightweight operating system for the cloud-
native edge.
SLE Micro for Rancher
SUSE Edge aims to address the
“management at scale” challenge by
removing the complexity of cluster and
OS management.
Full Edge Stack Management
Multi-architecture support is native in the
SUSE Edge solution. Both the Kubernetes
offering, with k3s and the operating system
offering with SLE Micro support both ARM
and x86 hardware.
Multi-architecture
Security at the edge builds on SLE Micro
as an enterprise grade operating system.
Security
Copyright © SUSE
2021
High Level Architecture
System Registration Service
System Attestation Service
Management: Policy, App, Infra
Management: Visibility, RBAC, Rollout
System Onboarding Service
System Update Controller (v2)
SLE based OS
RKE2 / k3s
Management
Agent
HW
app
app
app
Today
Tomorrow
SUSE
Rancher Edge
Stack
Copyright © SUSE
2021
Onboarding and OS Management Components
The Node Onboarding and OS Management capabilities are provided by a handful
of components.
Onboarding
o NewRanchercomponents:
 MachineRegistrationservice
 TPM HashGeneration
o IncludeElementalin generationof
OSimmutableonboardingimages
Cluster Management
o StandardClusterCreation
 Nodescan beassignmentfromthenew
MachineInventory
o Standardclusterlifecyclemanagement
OS Management
o NewRanchercomponents:
 OSImageManagement
o Enhanced systemupdatecontrollermanagesOS
updates
Copyright © SUSE
2021
26
Onboarding Flow
This is an example of one possible provisioning flow. The components
in the onboarding and OS management suite provide tremendous
flexibility.
Install
Rancher'
s new
onboardi
ng
services
Build and
deploy an
onboardin
g image
Remote
machines
boot the
onboardi
ng image
Machines
register
into the
inventor
y based
on the
TPM hash
Assign
machines
(with
roles)
to a
cluster
Cluster
is
created
Cluster
is ready
Copyright © SUSE
2021
27
OS Management Flow
OS lifecycle management is also handled by Rancher using a combination
of Fleet and the downstream system-update-controller.
New OS
image is
built and
pushed to
a
registry
OS Image
spec is
updated
for the
target
cluster
Fleet and
the
system-
update-
controlle
r effect
a rolling
update
Alternate
partition
s on the
nodes are
updated
with the
new image
The node
reboots
The
Kubernete
s cluster
state is
preserved
on the
Persisted
partition
Cluster
is ready
Copyright © SUSE
2021
1. Rancher Server prep
2. Custom onboarding ISO
build
3. Installing first image
and shipping boxes
4. Boxes call home
Rancher
5. Rancher Server
assigns clusters & roles
6. All the OS updates
done from Rancher
7.Further k8s deployments
8. Applications deployed
SUSE deployment on the edge
Highlights:
- Rancher becomes a control center
- Hardware registerswith
Rancher at deployment time
Copyright © SUSE
2021
Longhorn
Copyright © SUSE
2021
“Everything should be made as
simple as possible…“
Ease of use
Longhorn is built with security in
mind
Security
Longhorn is 100% open source and owned
by a non profit foundation (CNCF)
Open Source
Enable Persistent Workloads
Free-up time spent on
managing complex storage
solutions
Manage complexity
Support cloud, on prem and
edge with ARM64 support and
low resource support
Deploy Anywhere
Support databases, analytics
tools, AI/ML workloads that
require persistent storage
Longhorn 10k View
Longhorn
Information is forward looking and subject to change at any time.
Copyright © SUSE
2021
Copyright © SUSE
2021
Harvester
Copyright © SUSE
2021
— ‘Open, Interoperable Hyperconverged Infrastructure Solution’
– 100% Open-Source
– No Licensing & Hardware Fees
— Modern solution built on cloud-native technology
– Kubernetes, Longhorn, KubeVirt
— Production-ready, turn-key conventional HCI experience
— Implements HCI on bare metal services
— Lightweight, software-driven
– Doesn’t require any additional hardware, external SANs
– Reliable at the Edge
— Native Integration with Rancher for containerized workloads
33
What is Harvester?
Copyright © SUSE
2021
34
Harvester combines key cloud-native technologies into a
single API
Orchestration
Virtualization Platform
VM Management
Persistent Storage
Meta CNI
Virtual IP
Copyright © SUSE
2021
Harvester Architecture
Node
Harvester
KubeVirt
VM
Longhorn
Node
Harvester
KubeVirt
VM VM VM VM VM VM
Management network
VLAN 1
VLAN 2
VM
Longhorn
Copyright © SUSE
2021
36
Major Features
— Installation via ISO or PXE
– Air gap environment support
– Proxy support
— VM lifecycle management
– Cloud Config
– SSH key injection
– Graphic console to VNC and serial port
– Template
– Live migration
– Export images from existing VMs
– Terraform support
— Built-in monitoring dashboard
— Storage
– High performance and efficient block
storage
– Built-in highly-available image
repository
– VM backup/restore to NFS/S3
– Hot plug disk
— Network
– Virtual IP for the cluster
– Multi-network support
– VLAN support
– Custom SSL certificate
Copyright © SUSE
2021
37
Copyright © SUSE
2021
38
Copyright © SUSE
2021
NeuVector
NEUVECTOR
THE CHALLENGE
40
Container environments
are rapidly becoming more
prevalent
Traditional Security tools
don’t work in these
environments
Kubernetes abstracts the
complexity of container
networking for the trade-off
of network visibility
NEUVECTOR
LAYERED SECURITY: DEFENSE IN DEPTH
Supply Chain
Security
Runtime
Security
Vulnerability Scanning
Compliance Scanning
Admission Control
Runtime Scanning
Threat Based Controls
Zero-Trust Controls
NEUVECTOR
VULNERABILITY & COMPLIANCE MANAGEMENT
DEVELOPER
CI/CD
PIPELINE
PRIV/PUB
REGISTRY
RUN-TIME
Commits
Code
Pass
Build
Admission
Control
NEUVECTOR
NeuVector is Unique
• Fast & Accurate
• Scalable to 100s of 1,000s of images
• Support for Air-Gapped Environments
• Easy to deploy – K8s native
NEUVECTOR
RUN TIME SECURITY: DEFENSE IN DEPTH
44
CVEs
DLP
Network Attacks
OWASP Top 10
Admission Control
Automated Learning
Network
Process
File Access
Security as Code
Threat Based
Controls
Zero-Trust
Controls
NEUVECTOR
Alerts to any anomalous application behavior
Alerts & Denies on any anomalous application behavior
ZERO-TRUST FOR CONTAINERS
Identifies application behavior at Layer 7 Network, Process & File Access
Automated behavior-based learning
Zero-Trust Segmentation
Security Policy as Code
Replicate security policies & zero-trust segmentation automatically to other clusters
NEUVECTOR
NeuVector is Unique
• Automate Security Policies
• Network Visibility in Production
• Zero Trust Protections - network, process and file access
• Data Loss Prevention for Compliance
NEUVECTOR
DEVOPS PIPELINE TO PRODUCTION SECURITY
SDLC
Security
Compliance Reporting
Threat
Defenses
Zero-Trust
Defenses
NEUVECTOR
Pod Pod Pod
Node Node Node
Pod
Node
Pod
Node
Virtual Switch Virtual Switch Virtual Switch Virtual Switch Virtual Switch
Pod Pod Pod Pod
Pod Pod Pod Pod Pod
Controller Controller Controller
Enforcer Enforcer Enforcer Enforcer Enforcer
Web UI
Scanner Scanner
Manage Policies
REST API
Enforce Security Policies
Inspect Network Traffic
Deploy as Daemonset
WebUI
CLI Console
Parallel scanning
FAST
Scales for large repositories
NEUVECTOR ARCHITECTURE / DEPLOYMENT
Copyright © SUSE
2021
© 2020 SUSE LLC. All Rights Reserved. SUSE
and the SUSE logo are registered trademarks of
SUSE LLC in the United States and other
countries. All third-party trademarks are the
property of their respective owners.
For more information, contact SUSE at:
+1 800 796 3700 (U.S./Canada)
+49 (0)911-740 53-0 (Worldwide)
Maxfeldstrasse 5
90409 Nuremberg
www.suse.com
Thank you
49
SLES – SLE Micro – Trento – SUSE Manager – Rancher Desktop
Rancher – Edge – Longhorn – Harvester - NeuVector
Jurriën Bloemen
Solution Architect @ SUSE
jurrien.bloemen@suse.com

More Related Content

PDF
Kubernetes in The Enterprise
PDF
Cloud-Native Operations with Kubernetes and CI/CD
PPTX
VMworld 2015: Build and Run Cloud Native Apps in your Software Defined Data C...
PPTX
Pivotal Container Service Overview
PDF
NGINX Controller: faster deployments, fewer headaches
PDF
Four considerations when monitoring microservices
PPTX
Achieving DevSecOps Outcomes with Tanzu Advanced- May 25, 2021
PDF
Red Hat multi-cluster management & what's new in OpenShift
Kubernetes in The Enterprise
Cloud-Native Operations with Kubernetes and CI/CD
VMworld 2015: Build and Run Cloud Native Apps in your Software Defined Data C...
Pivotal Container Service Overview
NGINX Controller: faster deployments, fewer headaches
Four considerations when monitoring microservices
Achieving DevSecOps Outcomes with Tanzu Advanced- May 25, 2021
Red Hat multi-cluster management & what's new in OpenShift

What's hot (20)

PPTX
Application Security in the Cloud - Best Practices
PDF
Deploying Kafka on vSphere with Kubernetes Using the Confluent Operator (Just...
PPTX
Achieving DevSecOps Outcomes with Tanzu Advanced- March 22, 2021
PPTX
Making Microservices Smarter with Istio, Envoy and Pivotal Ingress Router
PDF
Pivotal Developer-Ready Infrastructure Slides
PDF
PKS: The What and How of Enterprise-Grade Kubernetes
PDF
Concourse, Spinnaker, Cloud Foundry, Oh My! Creating Sophisticated Deployment...
PDF
Enterprise Application Migration
PDF
Red Hat Enterprise Linux 8
PDF
Cloud-Native Patterns and the Benefits of MySQL as a Platform Managed Service
PDF
Enterprise Java on Azure: From Java EE to Spring, we have you covered
PPTX
DevSecOps: Security at the Speed of DevOp
PDF
Introduction to Spring Cloud Kubernetes
PDF
Virtual Desktop Infrastructure with Novell Endpoint Management Solutions
PDF
Pivotal Platform: A First Look at the October Release
PPTX
DockerCon EU 2017 - General Session Day 1
PPTX
Continuous Everything in a Multi-cloud and Multi-platform Environment
PDF
Tanzu Standard
PDF
VMware - Snapshot sessions - Deploy and manage tomorrow's applications today
PDF
How to Overcome Data Challenges When Refactoring Monoliths to Microservices
Application Security in the Cloud - Best Practices
Deploying Kafka on vSphere with Kubernetes Using the Confluent Operator (Just...
Achieving DevSecOps Outcomes with Tanzu Advanced- March 22, 2021
Making Microservices Smarter with Istio, Envoy and Pivotal Ingress Router
Pivotal Developer-Ready Infrastructure Slides
PKS: The What and How of Enterprise-Grade Kubernetes
Concourse, Spinnaker, Cloud Foundry, Oh My! Creating Sophisticated Deployment...
Enterprise Application Migration
Red Hat Enterprise Linux 8
Cloud-Native Patterns and the Benefits of MySQL as a Platform Managed Service
Enterprise Java on Azure: From Java EE to Spring, we have you covered
DevSecOps: Security at the Speed of DevOp
Introduction to Spring Cloud Kubernetes
Virtual Desktop Infrastructure with Novell Endpoint Management Solutions
Pivotal Platform: A First Look at the October Release
DockerCon EU 2017 - General Session Day 1
Continuous Everything in a Multi-cloud and Multi-platform Environment
Tanzu Standard
VMware - Snapshot sessions - Deploy and manage tomorrow's applications today
How to Overcome Data Challenges When Refactoring Monoliths to Microservices
Ad

Similar to So you think you know SUSE? (20)

PDF
Rancher Rodeo
PDF
Rancher Rodéo France
PDF
Rancher Rodeo 13 mai 2022
PDF
Innovate everywhere - SUSE edge
PDF
apidays LIVE Hong Kong 2021 - Building a solid interoperable foundation for y...
PDF
DevOps: Arquitectura, Estrategia y Modelo
PDF
Code Factory avec GitLab CI et Rancher
PDF
Code Factory avec GitLab CI et Rancher
PDF
Lancement Harvester
PDF
SUSE y Big Data
PDF
SUSE: Infraestructura definida por software para BigData
PDF
apidays LIVE Australia 2021 - Building an agile foundation for your Enterpris...
PDF
Rancher Labs - Your own PaaS in action
PDF
Rancher Labs - Your own PaaS in action
PDF
SUSE, Hadoop and Big Data Update. Stephen Mogg, SUSE UK
PDF
SUSE OpenStack Cloud
PDF
2013 linux days final
PDF
An Open, Open source way to enable your Cloud Native Journey
PDF
Productos de SUSE basados en CaaSP
PDF
High Performance Computing with SUSE — We adapt. You succeed!
Rancher Rodeo
Rancher Rodéo France
Rancher Rodeo 13 mai 2022
Innovate everywhere - SUSE edge
apidays LIVE Hong Kong 2021 - Building a solid interoperable foundation for y...
DevOps: Arquitectura, Estrategia y Modelo
Code Factory avec GitLab CI et Rancher
Code Factory avec GitLab CI et Rancher
Lancement Harvester
SUSE y Big Data
SUSE: Infraestructura definida por software para BigData
apidays LIVE Australia 2021 - Building an agile foundation for your Enterpris...
Rancher Labs - Your own PaaS in action
Rancher Labs - Your own PaaS in action
SUSE, Hadoop and Big Data Update. Stephen Mogg, SUSE UK
SUSE OpenStack Cloud
2013 linux days final
An Open, Open source way to enable your Cloud Native Journey
Productos de SUSE basados en CaaSP
High Performance Computing with SUSE — We adapt. You succeed!
Ad

More from Kangaroot (20)

PDF
Live demo: Protect your Data
PDF
RootStack - Devfactory
PDF
Welcome at OPEN'22
PDF
EDB Postgres in Public Sector
PDF
Deploying NGINX in Cloud Native Kubernetes
PDF
Cloud demystified, what remains after the fog has lifted.
PDF
Zimbra at Kangaroot / OPEN{virtual}
PDF
Kangaroot EDB Webinar Best Practices in Security with PostgreSQL
PDF
Do you want to start with OpenShift but don’t have the manpower, knowledge, e...
PDF
There is no such thing as “Vanilla Kubernetes”
PDF
Elastic SIEM (Endpoint Security)
PDF
Hashicorp Vault - OPEN Public Sector
PDF
Kangaroot - Bechtle kadercontracten
PDF
Kangaroot open shift best practices - straight from the battlefield
PDF
Kubecontrol - managed Kubernetes by Kangaroot
PDF
OpenShift 4, the smarter Kubernetes platform
PDF
10 - MongoDB
PDF
9 - Making Sense of Containers in the Microsoft Cloud
PDF
8 - OpenShift - A look at a container platform: what's in the box
PDF
7 - Monitoring Kubernetes with Elastic
Live demo: Protect your Data
RootStack - Devfactory
Welcome at OPEN'22
EDB Postgres in Public Sector
Deploying NGINX in Cloud Native Kubernetes
Cloud demystified, what remains after the fog has lifted.
Zimbra at Kangaroot / OPEN{virtual}
Kangaroot EDB Webinar Best Practices in Security with PostgreSQL
Do you want to start with OpenShift but don’t have the manpower, knowledge, e...
There is no such thing as “Vanilla Kubernetes”
Elastic SIEM (Endpoint Security)
Hashicorp Vault - OPEN Public Sector
Kangaroot - Bechtle kadercontracten
Kangaroot open shift best practices - straight from the battlefield
Kubecontrol - managed Kubernetes by Kangaroot
OpenShift 4, the smarter Kubernetes platform
10 - MongoDB
9 - Making Sense of Containers in the Microsoft Cloud
8 - OpenShift - A look at a container platform: what's in the box
7 - Monitoring Kubernetes with Elastic

Recently uploaded (20)

PPTX
DevOpsDays Halifax 2025 - Building 10x Organizations Using Modern Productivit...
PPTX
Plex Media Server 1.28.2.6151 With Crac5 2022 Free .
PPTX
Chapter_05_System Modeling for software engineering
PDF
Practical Indispensable Project Management Tips for Delivering Successful Exp...
PDF
MiniTool Power Data Recovery 12.6 Crack + Portable (Latest Version 2025)
PPTX
Folder Lock 10.1.9 Crack With Serial Key
PDF
Top 10 Project Management Software for Small Teams in 2025.pdf
PPTX
string python Python Strings: Literals, Slicing, Methods, Formatting, and Pra...
PDF
IDM Crack 6.42 Build 42 Patch Serial Key 2025 Free New Version
PPTX
Odoo ERP for Injection Molding Industry – Optimize Production & Reduce Scrap
PPTX
Human-Computer Interaction for Lecture 2
PDF
Sanket Mhaiskar Resume - Senior Software Engineer (Backend, AI)
PDF
What Makes a Great Data Visualization Consulting Service.pdf
PPTX
Human Computer Interaction lecture Chapter 2.pptx
PDF
PDF-XChange Editor Plus 10.7.0.398.0 Crack Free Download Latest 2025
PPTX
ERP Manufacturing Modules & Consulting Solutions : Contetra Pvt Ltd
PDF
Understanding the Need for Systemic Change in Open Source Through Intersectio...
PDF
Building an Inclusive Web Accessibility Made Simple with Accessibility Analyzer
PDF
Lumion Pro Crack New latest version Download 2025
PPTX
Lesson-3-Operation-System-Support.pptx-I
DevOpsDays Halifax 2025 - Building 10x Organizations Using Modern Productivit...
Plex Media Server 1.28.2.6151 With Crac5 2022 Free .
Chapter_05_System Modeling for software engineering
Practical Indispensable Project Management Tips for Delivering Successful Exp...
MiniTool Power Data Recovery 12.6 Crack + Portable (Latest Version 2025)
Folder Lock 10.1.9 Crack With Serial Key
Top 10 Project Management Software for Small Teams in 2025.pdf
string python Python Strings: Literals, Slicing, Methods, Formatting, and Pra...
IDM Crack 6.42 Build 42 Patch Serial Key 2025 Free New Version
Odoo ERP for Injection Molding Industry – Optimize Production & Reduce Scrap
Human-Computer Interaction for Lecture 2
Sanket Mhaiskar Resume - Senior Software Engineer (Backend, AI)
What Makes a Great Data Visualization Consulting Service.pdf
Human Computer Interaction lecture Chapter 2.pptx
PDF-XChange Editor Plus 10.7.0.398.0 Crack Free Download Latest 2025
ERP Manufacturing Modules & Consulting Solutions : Contetra Pvt Ltd
Understanding the Need for Systemic Change in Open Source Through Intersectio...
Building an Inclusive Web Accessibility Made Simple with Accessibility Analyzer
Lumion Pro Crack New latest version Download 2025
Lesson-3-Operation-System-Support.pptx-I

So you think you know SUSE?

  • 1. Copyright © SUSE 2021 So, you think you know SUSE? Jurriën Bloemen Solution Architect @ SUSE [email protected]
  • 2. Copyright © SUSE 2021 Powering Innovation With Leadership in Linux & Kubernetes Hybrid Cloud Infrastructure Dev Datacenter Branch Cloud Edge Support & Services Catalog Security Storage Governance The platform for managing all Kubernetes distributions Datacenter Edge Block Storage Linux SLE Desktop / POS SLE Server SLES for SAP Applications SLES for HPC SLE Micro SLE Extensions SUSE Manager SUSE Linux Enterprise Compliance Security Availability Management The most adaptable Linux operating system Other Linux
  • 3. Copyright © SUSE 2021 SUSE Linux Enterprise
  • 4. Copyright © SUSE 2021 The Most Adaptable Linux OS SUSE Rancher / Virtualization / Platform-as-a-Service / Bare Metal Apps Desktop /POS Datacenter Branch Cloud Edge SLE Product Family Availability Management Compliance & Security Copyright © SUSE 2020 AMD64 / Intel 64 Arm 64 IBM Power IBM Z & LinuxONE Products & Solutions SLE High Performance Computing SLE Real Time SUSE Linux Enterprise Server SLES for SAP Applications SLE Micro SLE Desktop / POS Management & Automation SUSE Manager Global Services Support Subscriptions Consulting & Training Select Services Architecture Extensions High Availability & Geo Clustering Workstation SLE Live Patching Hybrid Cloud Infrastructure Supports SLES & Other Linux
  • 5. Copyright © SUSE 2021 SUSE provides life cycle options to customers​ depending on the customer specific needs​ SLE 11 – in LTSS, no further active development SLE 12 – general support, selected enablement SLE 15 – general support, active development  13 years total lifecycle, 7 Service Packs (SP)  Service Pack Overlap Support: 6 months  Long Term Service Pack Support (LTSS): up to 3 years after end of general support  Specific products can have longer overlapping support (e.g. SLES for SAP)  See https://www.suse.com/lifecycle 5 SUSE Linux Enterprise Life Cycle GA = First release of code stream GE = End of general support LTSS = Long Term Service Pack support EOL = End of life SLE 15 2018 2019 2020 2021 2024 2025 2022 2023 SLE 12 Next major codestream SLE 11 2026 GA SP0 SP1 SP2 SP3 SP4 SP5 2030 2018 2020 2026 2028 2022 2024 SLES lifecycle, other products may have longer overlapping support Contains forward looking statements. Subject to change. GE EOL GE GA SP1 SP2 SP5 SP4 SP4 SP5 SP2 SP3 SP6 SP7 SP6 SP7
  • 6. Copyright © SUSE 2021 SLE Micro
  • 7. Copyright © SUSE 2021 7 Immutable Operating System Immutable design ensures OS is not altered during runtime and runs reliably every single time. Prepared to support very long product lifecycles Peace of mind for all – developers, administrators and enterprises. Near-zero Downtime Apply security updates without rebooting kernel. Update application workloads when needed. Mission-Critical by Design
  • 8. Copyright © SUSE 2021 Secure OS Platform Built-in Security Framework for OS and Containers Deploy secure systems with United States Department of Defense-style mandatory access controls using SELinux. Secure Device Onboarding Securely onboard remote appliances/devices. Ready for Certifications & Compliance Leverages certifications and compliance from SLE, such as FIPS 140-2, DISA SRG/STIG. 8 Kernel Live Patching Reduce risk of cyber attack, apply security updates to Linux kernel as soon as available without waiting for a maintenance window. Minimal Attack Surface Immutable design, minimal attack vectors.
  • 9. Copyright © SUSE 2021 Perfect for Containers & Kubernetes *SLE Micro supports K3s, RKE2 or 3rd party Kubernetes distributions 9 Built from ground up to support containers and microservices. Workloads are isolated from the core filesystem to guard against malicious applications compromising the system. Easily combine SLE Micro with K3s, the world’s most popular Kubernetes* distribution for use in low resource, distributed edge locations.
  • 10. Copyright © SUSE 2021 22 APRIL 2021 SUSE Manager
  • 11. Copyright © SUSE 2021 Open-Source infrastructure management solution designed to help your enterprise DevOps and IT Operations teams to: •Optimize operations while reducing costs •Reduce complexity and regain control of IT assets •Ensure compliance with internal security policies and external regulations 11 SUSE Manager SUSE MANAGER 4
  • 12. Copyright © SUSE 2021 12 Multi OS support L Linux 2
  • 13. Copyright © SUSE 2021 Rancher Desktop Running Kubernetes on your Laptop/Desktop
  • 18. Copyright © SUSE 2021 18 You can start using it today! https://rancherdesktop.io/
  • 20. Copyright © SUSE 2021 20 SUSE Rancher - the industry’s leading platform to manage all Kubernetes distributions Containerized App 1 Containerized App 3 Containerized App 2 Security & Authentication Policy Enforcement & Governance Simplified Cluster Operations & Infrastructure Management (Run & Manage) Platform Services (Build & Run) SUSE Linux Enterprise / RHEL / Ubuntu / Oracle Linux / Amazon Linux Amazon EKS Azure AKS Google GKE Cloud Datacenter Edge Branch Dev K8s Version Management GitOps Continuous Delivery Cluster Templates & Config Enforcement Node Pool Management Cluster Provisioning & Lifecycle Management Centralized Audit Monitoring & Logging CIS Benchmarking RBAC, OPA, Pod & Network Policies Rancher Catalog Monitoring & Alerts Dashboards & Observability Service Mesh Longhorn Storage
  • 21. Copyright © SUSE 2021 Innovate Everywhere Rancher Overview Rancher provides a consistent interface for managing and interacting with the cluster. Providing a gateway to Kubernetes native apps through the catalog. One Dashboard Rancher can be installed on any CNCF certified cluster. Installs Everywhere Rancher provides a graphical interface for managing smaller environments. The built in GitOps engine allows deployments to scale up to thousands of clusters. Scaled Management Rancher Multi-cluster Manager unifies clusters to ensure consistent operations, workload management, and enterprise- grade security Multi-cluster Management Leveraging the agility and software delivery from the Datacenter is making its way to branch offices, cell towers and satellites. Edge Rancher provides a consistent experience for Kubernetes clusters on the desktop, edge , or datacenter. Single Cluster Available Vision
  • 23. Copyright © SUSE 2021 Innovate Everywhere SUSE Edge Overview Rancher provides a consistent interface for managing and interacting with edge clusters. Rancher Rancher’s Continuous Delivery feature is based on Fleet. Fleet provides a built in GitOps engine which allows deployments to scale up to tens of thousands of clusters. Continuous Delivery (Fleet) SUSE’s container optimized, ultra-reliable, lightweight operating system for the cloud- native edge. SLE Micro for Rancher SUSE Edge aims to address the “management at scale” challenge by removing the complexity of cluster and OS management. Full Edge Stack Management Multi-architecture support is native in the SUSE Edge solution. Both the Kubernetes offering, with k3s and the operating system offering with SLE Micro support both ARM and x86 hardware. Multi-architecture Security at the edge builds on SLE Micro as an enterprise grade operating system. Security
  • 24. Copyright © SUSE 2021 High Level Architecture System Registration Service System Attestation Service Management: Policy, App, Infra Management: Visibility, RBAC, Rollout System Onboarding Service System Update Controller (v2) SLE based OS RKE2 / k3s Management Agent HW app app app Today Tomorrow SUSE Rancher Edge Stack
  • 25. Copyright © SUSE 2021 Onboarding and OS Management Components The Node Onboarding and OS Management capabilities are provided by a handful of components. Onboarding o NewRanchercomponents:  MachineRegistrationservice  TPM HashGeneration o IncludeElementalin generationof OSimmutableonboardingimages Cluster Management o StandardClusterCreation  Nodescan beassignmentfromthenew MachineInventory o Standardclusterlifecyclemanagement OS Management o NewRanchercomponents:  OSImageManagement o Enhanced systemupdatecontrollermanagesOS updates
  • 26. Copyright © SUSE 2021 26 Onboarding Flow This is an example of one possible provisioning flow. The components in the onboarding and OS management suite provide tremendous flexibility. Install Rancher' s new onboardi ng services Build and deploy an onboardin g image Remote machines boot the onboardi ng image Machines register into the inventor y based on the TPM hash Assign machines (with roles) to a cluster Cluster is created Cluster is ready
  • 27. Copyright © SUSE 2021 27 OS Management Flow OS lifecycle management is also handled by Rancher using a combination of Fleet and the downstream system-update-controller. New OS image is built and pushed to a registry OS Image spec is updated for the target cluster Fleet and the system- update- controlle r effect a rolling update Alternate partition s on the nodes are updated with the new image The node reboots The Kubernete s cluster state is preserved on the Persisted partition Cluster is ready
  • 28. Copyright © SUSE 2021 1. Rancher Server prep 2. Custom onboarding ISO build 3. Installing first image and shipping boxes 4. Boxes call home Rancher 5. Rancher Server assigns clusters & roles 6. All the OS updates done from Rancher 7.Further k8s deployments 8. Applications deployed SUSE deployment on the edge Highlights: - Rancher becomes a control center - Hardware registerswith Rancher at deployment time
  • 30. Copyright © SUSE 2021 “Everything should be made as simple as possible…“ Ease of use Longhorn is built with security in mind Security Longhorn is 100% open source and owned by a non profit foundation (CNCF) Open Source Enable Persistent Workloads Free-up time spent on managing complex storage solutions Manage complexity Support cloud, on prem and edge with ARM64 support and low resource support Deploy Anywhere Support databases, analytics tools, AI/ML workloads that require persistent storage Longhorn 10k View Longhorn Information is forward looking and subject to change at any time.
  • 33. Copyright © SUSE 2021 — ‘Open, Interoperable Hyperconverged Infrastructure Solution’ – 100% Open-Source – No Licensing & Hardware Fees — Modern solution built on cloud-native technology – Kubernetes, Longhorn, KubeVirt — Production-ready, turn-key conventional HCI experience — Implements HCI on bare metal services — Lightweight, software-driven – Doesn’t require any additional hardware, external SANs – Reliable at the Edge — Native Integration with Rancher for containerized workloads 33 What is Harvester?
  • 34. Copyright © SUSE 2021 34 Harvester combines key cloud-native technologies into a single API Orchestration Virtualization Platform VM Management Persistent Storage Meta CNI Virtual IP
  • 35. Copyright © SUSE 2021 Harvester Architecture Node Harvester KubeVirt VM Longhorn Node Harvester KubeVirt VM VM VM VM VM VM Management network VLAN 1 VLAN 2 VM Longhorn
  • 36. Copyright © SUSE 2021 36 Major Features — Installation via ISO or PXE – Air gap environment support – Proxy support — VM lifecycle management – Cloud Config – SSH key injection – Graphic console to VNC and serial port – Template – Live migration – Export images from existing VMs – Terraform support — Built-in monitoring dashboard — Storage – High performance and efficient block storage – Built-in highly-available image repository – VM backup/restore to NFS/S3 – Hot plug disk — Network – Virtual IP for the cluster – Multi-network support – VLAN support – Custom SSL certificate
  • 40. NEUVECTOR THE CHALLENGE 40 Container environments are rapidly becoming more prevalent Traditional Security tools don’t work in these environments Kubernetes abstracts the complexity of container networking for the trade-off of network visibility
  • 41. NEUVECTOR LAYERED SECURITY: DEFENSE IN DEPTH Supply Chain Security Runtime Security Vulnerability Scanning Compliance Scanning Admission Control Runtime Scanning Threat Based Controls Zero-Trust Controls
  • 42. NEUVECTOR VULNERABILITY & COMPLIANCE MANAGEMENT DEVELOPER CI/CD PIPELINE PRIV/PUB REGISTRY RUN-TIME Commits Code Pass Build Admission Control
  • 43. NEUVECTOR NeuVector is Unique • Fast & Accurate • Scalable to 100s of 1,000s of images • Support for Air-Gapped Environments • Easy to deploy – K8s native
  • 44. NEUVECTOR RUN TIME SECURITY: DEFENSE IN DEPTH 44 CVEs DLP Network Attacks OWASP Top 10 Admission Control Automated Learning Network Process File Access Security as Code Threat Based Controls Zero-Trust Controls
  • 45. NEUVECTOR Alerts to any anomalous application behavior Alerts & Denies on any anomalous application behavior ZERO-TRUST FOR CONTAINERS Identifies application behavior at Layer 7 Network, Process & File Access Automated behavior-based learning Zero-Trust Segmentation Security Policy as Code Replicate security policies & zero-trust segmentation automatically to other clusters
  • 46. NEUVECTOR NeuVector is Unique • Automate Security Policies • Network Visibility in Production • Zero Trust Protections - network, process and file access • Data Loss Prevention for Compliance
  • 47. NEUVECTOR DEVOPS PIPELINE TO PRODUCTION SECURITY SDLC Security Compliance Reporting Threat Defenses Zero-Trust Defenses
  • 48. NEUVECTOR Pod Pod Pod Node Node Node Pod Node Pod Node Virtual Switch Virtual Switch Virtual Switch Virtual Switch Virtual Switch Pod Pod Pod Pod Pod Pod Pod Pod Pod Controller Controller Controller Enforcer Enforcer Enforcer Enforcer Enforcer Web UI Scanner Scanner Manage Policies REST API Enforce Security Policies Inspect Network Traffic Deploy as Daemonset WebUI CLI Console Parallel scanning FAST Scales for large repositories NEUVECTOR ARCHITECTURE / DEPLOYMENT
  • 49. Copyright © SUSE 2021 © 2020 SUSE LLC. All Rights Reserved. SUSE and the SUSE logo are registered trademarks of SUSE LLC in the United States and other countries. All third-party trademarks are the property of their respective owners. For more information, contact SUSE at: +1 800 796 3700 (U.S./Canada) +49 (0)911-740 53-0 (Worldwide) Maxfeldstrasse 5 90409 Nuremberg www.suse.com Thank you 49 SLES – SLE Micro – Trento – SUSE Manager – Rancher Desktop Rancher – Edge – Longhorn – Harvester - NeuVector Jurriën Bloemen Solution Architect @ SUSE [email protected]

Editor's Notes

  • #3: Story After the video in the beginning I’m sure all of you will be keen to hear more about Edge Computing. Nevertheless I want to give you a glance overview about SUSE, to understand how well we are positioned to support you to “Innovate Everywhere”. At the heart of our strategy is our leadership in the two most important technologies powering digital transformation: Linux and Kubernetes. What powers all of our solutions is our unique open, interoperable solution stack. Not only is SUSE a leader in Enterprise Linux and Kubernetes, but also offering an open, complementary approach, allowing you to choose what fits you best. That gives you back control over your IT architecture and does not enforce decisions by tech dependencies. As you can see on the lower layer we address with our Linux and Kubernetes offerings several areas from Development over Data Center, Cloud Computing, Branches to the Edge. This is the reason why you will find in the middle bar so many flavours of Linux offerings. With our most adaptable Enterprise Linux in the industry, we are able to deliver use case purpose build solutions. Beside we offer systems management with SUSE Manager, that also supports all major Linux distributions from other vendors and communities. Let’s go to the upper, blue layer: With the recent acquisition of Rancher Labs we are now also able to offer with SUSE Rancher the industries only container platform management that supports all Cloud Native Computing Foundation (CNCF) certified Kubernetes distributions. While it is common not to run just one Kubernetes cluster in a business environment, SUSE Rancher allows managing Catalog, Security, Storage and Governance in a consistent way across all your Kubernetes clusters from a central point. Of course our offerings are accompanied by Support and Services. Speaker Background Information n/a Backup Data / Comments / Questions SUSE Manager supports with current version 4.2 SUSE, openSUSE, Red Hat, CentOS, Oracle Linux, Ubuntu, Debian, Amazon Linux!
  • #5: TALKING POINTS SUSE Linux Enterprise is an adaptable and easy-to-manage platform that allows developers and administrators to deploy business-critical workloads on-premises, in the cloud and at the edge. All SUSE Linux Enterprise products are optimized for performance, security and reliability in specific environments or use cases. This approach enables you to: Simplify your IT environment The SUSE Linux Enterprise “common code base” platform bridges traditional and software-defined infrastructure. Simplify workload migration, protect your traditional infrastructure, and ease the adoption of containers. Modernize your IT infrastructure Modernize your IT infrastructure with SUSE Linux Enterprise Server’s multimodal architecture. With its cloud-agnostic design, SLES can easily transition to public cloud—Alibaba, Azure, AWS, Google, IBM, Oracle. Accelerate innovation Connect to our developer community at SUSE Package Hub. Once you are ready to move to from development to production you can seamlessly transition from our community Linux distribution - openSUSE Leap - to SUSE Linux Enterprise with just a few clicks. FAQs What does ‘Adaptability’ mean in the context of SLE? SLE products include APIs and services that make it possible to write applications that can work with the widest range of architectures, servers, storage and network options available. This approach allows SLE products like SLES to adapt to any operating environment and enables smooth workload migrations between them. What about security and compliance? Why is SLE different? SUSE engineers promptly react to security incidents, and deliver premium quality security updates. The configuration, auditing and automation features of SUSE Manager make it easy to ensure compliance with internal security policies and external regulations. What about business continuity? Why should I trust SUSE over competitive products? SUSE Linux Enterprise High Availability Extension, geo-clustering, and SUSE Linux Enterprise Live Patching improves business continuity and saves costs by reducing downtime, increasing service availability and enhancing security and compliance. What about virtualization? Each SUSE Linux Enterprise subscription includes support for the leading hypervisor technologies like Vmware and cloud platforms such as AWS, Azure and Google Cloud. We maximize your flexibility and lower costs without sacrificing performance, security or reliability.
  • #6: SLE lifecycle details Please note that the info covers primarily SLES, other products might differ so always consult suse.com/lifecycle for the specifics
  • #9: Container runtime (podman) supports auto-generation of SELinux policies for container workloads. Secure updates - Updates are always security signed and verified. Each update is atomic and uses transactional update technology. SLE Micro leverages SLE common code base, to provide FIPS 140-2, DISA SRG/STIG, integration with CIS and Common Criteria certified configurations. Packages and repositories are security signed – Intruder cannot exchange good, new packages with old or insecure packages. Using integrated “Secure Device Onboarding (SDO)” client, MSPs (Managed Service Providers) or IHVs/ISVs can ship an appliance directly to end customer, and subsequently, while operating the device remotely, onboard it securely.
  • #10: Run container workloads with performance & security SLE Micro is built from ground up to support containers and microservices. All applications/workloads are run as containers and separated into dedicated containers. So, new installation of workloads can be done without reboot, atomic updates are easier to support, and it is easy to rollback when an update goes wrong. Workloads are isolated from the core filesystem to guard against malicious applications compromising the system. Container runtime (podman) is adjusted to support auto generation of SELinux policies for container workloads.
  • #12: SUSE Manager is an Open Source Infrastructure Management solution. While reducing costs and complexity it will ensure that your environment is compliance with your internal security policies. One of the big differences between Satellite 5 and SUSE Manager is that we also focus on the cloud. We understand that you have to manage on-premise but also workloads in to cloud. That’s also a reason why it is possible that SUSE Manager can run in the cloud so that you don’t need local hardware to run SUSE Manager.
  • #21: TALKING POINTS There are two key pillar of a successful ‘Kubernetes Everywhere’ strategy Certified Kubernetes Distributions To enable compute everywhere, you need to deploy certified Kubernetes distributions everywhere you need compute – in the datacenter, in the cloud, across desktop, branch, and edge locations Centralized Management You need to deploy a centralized management control plane, that delivers three key capabilities Consistent cluster operations – enabling ITOps teams to manage all of your certified Kubernetes distribution with a consistent interface, regardless of who developed the distribution or where it runs Security, Policy, and User Management – enabling ITOps teams to automate processes and applying a consistent set of user access and security policies for all of your clusters no matter where they are running. Shared Tools & Services – any Kubernetes management platform need to provide seamless access to DevOps tools and services including app packaging, CI/CD, logging, monitoring, and service mesh
  • #27: Would like to have “builds” that show the technical details happening at each step.
  • #28: Would like to have “builds” that show the technical details happening at each step.
  • #34: Harvester is an open-source hyper converged infrastructure software. Built and designed with cloud-native environments in mind. Virtualizes the entire stack: the compute, the storage, and the network. 100% Open-Source, same as Rancher. No additional capabilities from subscription. Subscription entitles to support. Main HCI players (VMWare, Nutanix) are proprietary. Production ready turn-key experience. Higher level of completeness over niche open source HCI solutions (Portworx, KubeVirt). Different components very well integrated. Easy to use. Same experience as enterprise grade conventional HCI experience. Designed to run on bare-metal servers. - On-premise, Edge. On cloud: On-demand bare metal servers (e.g. Equinix Metal). No nested virtualization. Not supported in production. Performance penalty. Not intended for Main Public Cloud Providers. Already HCI. Edge: - Small clusters with relatively powerful servers with decent specifications. Remote branch locations. Restaurants. Factories. Remote branch offices. Not for Raspberry Pis. Harvester is: Lightweight: Lowest resource consumption of any HCI in market. Software-driven. Hardware agnostic. No specialized Hardware (e.g. external SANs). Unify and consolidate heterogeneous hardware. Integrates very well with Rancher. Rancher single pane of glass. Kubernetes use cases. HCI concerns. Unify management of VMs and containers from a single console. Role-based access control. Enterprise authentication. Observability tools. CI/CD tools.
  • #35: Unique approach: Built on a foundation of cloud native technologies. Single unified API to deploy VMs. Great user experience. Kubernetes: Mature and stable orchestration layer. RKE2. Bootstrapped with RancherD. Single binary. Kubernetes cluster bundled with Rancher. KVM - Virtualization platform. KubeVirt: Virtualization management layer. Orchestrates running VMs inside of pods.   Longhorn - Distributed and highly available persistent storage. Multus: Meta-CNI. Allows for multiple software defined networks. KubeVIP: - Provides virtual IP support. - For bare-metal Harvester cluster (installation, accessing UI, node registration). - For Kubernetes clusters provisioned through Rancher. - Provides Load balancing functionality. Proven, powerful technologies for today’s infrastructure needs. SUSE Linux: Derivative of OpenSUSE 15.3. Name TBD (Elemmental for Open SUSE, RancherOS v2, …). Backed by SUSE. Binary-compatible with SLES. (not yet available) In 2022, transition to SLES for users with Harvester subscription.
  • #36: Harvester is a cluster of nodes, Each of which is running: SUSE Linux, RKE2 (Secure and stable base). Longhorn (Storage) and KubeVirt (Virtualization). Not swappable for other storage or virtualization solutions. Tight integration. Key elements of the entire HCI solution. Tied to certain functionalities (e.g. Hot Plug). Harvester seen as a single entity rather than pick and choose. Run VMs on top of Harvester. Networking: Each VM connects into management network (Kubernetes overlay network). Management network accesses any VM in the cluster. Can create multiple VLANs. Only VLANs. Support for other network types, e.g. VXLAN, in roadmap priority. VM can connect to multiple networks at the same time (Isolate traffic across VMs).  Provided by Multus and Harvester's network CNI plugin (allows VM to connect to multiple network interfaces).  Clustering multiple Harvester hosts together. Create a shared compute platform across them.  Manage all these servers as one pool of resource. Allocated to VMs. Kubernetes on top of VMs. When add more nodes to the cluster Harvester reconfigures itself (Kubernetes cluster).   Heterogenous machines are supported. Good networking is very important. Additional considerations: RKE2 and KubeVirt don’t currently support Arm, so Harvester does not support Arm. Can’t upgrade from Harvester v0.3 to v1.0 (work in progress).
  • #37: (Only for the ones with additional info) Can create similar VMs based on templates. Live migration with storage is powered by Longhorn. Similar to vMotion in the VMWare world. It allows to migrate VM from one node to another without downtime. Possible within the same Harvester cluster. Can not move guest VMs between different clusters. Exporting images from existing VMs. Can use a VM, modify it and then export it. The exported VM can be used for future deployments. Harvester supports Terraform and is a Terraform provider. Monitoring Dashboard. Situation and resource consumption at: Cluster level. VM level (similar to node status in Rancher) . Storage. Only block storage, no object storage. High performance: In tests, Longhorn is the fastest software defined storage solution on SSD/NVMe. Faster than Ceph and Portworx for raw disk operations. A critical part of the storage involves storing the Virtual Machine Base Images, It needs to be high performant. Efficiency: Longhorn is able to store the base image used to spin many virtual machines. These images are shared and reused across the virtual machines. Longhorn also stores the deltas for whatever each VM is using. You don’t need to duplicate the base image on disk for each VM. It is a very efficient way to store the data for all VMs. VM backup and restore to NFS and S3. Currently limited to the same Harvester cluster. In future, allow to backup Harvester VMs and restore on another location (For Failover and Disaster Recovery). Hot plug disk support. Harvester contributed the enhancements to the upstream KubeVirt project. Hot plug disk is used if you have a Kubernetes cluster spin up from a Harvester VM to obtain a better performance for the disk. When the CSI driver in the guest cluster asks for a hot volume, it is actually a real hot plug disk to the VM. Network: Virtual IP support: One virtual IP for the cluster. One virtual IP for any Kubernetes cluster provisioned through Rancher. Kube-vip can also get a load balancer service. Can bond NICs. Custom SSL certificate. - Can bring SSL certificates for a specific domain into Harvester.
  • #41: The use of containers and Kubernetes is exploding because of the scalability and efficiency that they help with. Unfortunately, traditional security tools don’t work inside of these environments. To make matters worse, K8s deliberately obfuscates the network traffic as a trade-off for that efficiency. This is what our founders found a way to solve, to operate in these ephemeral environments the same way traditional security tools do.
  • #43: For our vulnerability management, we are full lifecycle, we start when a developer builds an image We have plugins for Jenkins, CircleCI and others We can pass/fail builds as part of the pipeline, and we can scan registries as you might expect, and we do plug into admission control so you can create pod security policies in our product for deploying containers. we want to make sure we’re continuously scanning in production to find new CVEs as they’re published. Important to mention here that we built our scanner in house, so no use of existing open-source technologies. We’ve been told by our customers that it is the fastest, most flexible and accurate scanner on the market. And, since we’re cloud native, it can scale quickly and easily to large repositories (we have a customer who has 100s of thousands of images that get scanned regularly without issue).