Maximizing Hybrid Cloud Efficiency with Amazon EKS and Rocky Linux 9
In CIQ's final webinar of 2024, Rose Stein and Zane Hamilton host Curtis Rissi and Dean Bryda from AWS, along with the head of CIQ's cloud programs, to walk through Amazon EKS Hybrid Nodes. Launched at re:Invent 2024, the feature lets the EKS control plane in AWS schedule workloads onto node groups running on customer-managed infrastructure, including Rocky Linux 9 hosts on premises or at the edge.
The AWS guests explain where Hybrid Nodes sits between cloud EKS and the air-gapped EKS Anywhere, the shared responsibility model, the networking prerequisites (remote node and pod CIDR ranges, VPN or Direct Connect), and the use cases they see in financial services, healthcare, manufacturing and retail. They also cover mixed-mode clusters, IAM Roles Anywhere, observability tooling, and why networking is the hardest part of setup.
The session closes with a look at Rocky Linux 8 and 9 images on the AWS Marketplace (x86 now, Arm coming), LTS images for older minor versions, Rocky Linux in Amazon WorkSpaces and AppStream 2.0, and a short primer on Warewulf as a stateless provisioning tool for compute nodes ahead of a January webinar on managing GPU clusters. Platform and infrastructure teams running Kubernetes across cloud and on-prem environments get a practical view of what the feature does and how to start.
Key takeaways
- EKS Hybrid Nodes, launched at re:Invent 2024, lets the AWS-managed EKS control plane schedule workloads onto on-premises node groups you bring yourself.
- Rocky Linux 9 is validated as a host OS for Hybrid Nodes, and CIQ was one of 19 launch partners for the feature.
- Networking is the hardest part of setup: remote node and pod CIDR ranges must be known at cluster creation and cannot change later.
- Hybrid Nodes is for new clusters only at launch; converting an existing EKS cluster is a destructive change that requires spinning up a new one.
- Mixed-mode clusters can combine node groups in AWS and in multiple on-prem environments under one cluster with shared IAM policies and namespaces.
- Rocky Linux 8 and 9 images are on the AWS Marketplace for x86 with Arm images following, plus LTS images for older minor versions.
Questions this video answers
What are Amazon EKS Hybrid Nodes and how do they differ from EKS Anywhere?
EKS Hybrid Nodes keep the Kubernetes control plane in AWS while you bring your own on-premises or edge servers as node groups, connected over VPN or Direct Connect. EKS Anywhere is aimed at self-managed, air-gapped deployments with an on-prem control plane, so Hybrid Nodes fills the middle ground for connected hybrid workloads.
Can I run Rocky Linux 9 with EKS Hybrid Nodes?
Yes. Rocky Linux 9 is validated for use with EKS Hybrid Nodes, and CIQ was one of the launch partners. You install the operating system on VMs or bare metal, run the nodeadm CLI to install the Kubernetes components and register the node, and CIQ can support the OS layer while AWS supports the managed control plane.
What networking do EKS Hybrid Nodes require?
You need connectivity between AWS and your on-prem environment through a site-to-site VPN or Direct Connect, and you must supply the remote node CIDR and remote pod CIDR ranges when creating the cluster. Routes must be configured in the VPC and on the on-prem gateway. Low latency is not strictly required; one presenter runs GPU workloads over a 70 millisecond home connection.
About this video
Recorded on December 20, 2024. The session covers:
- A comprehensive overview of Amazon EKS Hybrid Nodes, now validated for use with Rocky Linux 9.
- The key benefits for Rocky Linux customers, including seamless OS integration across cloud, on-prem, and edge container hosts, and the added CIQ enterprise benefits for cost and efficiency.
- Insights on Rocky Linux on the AWS Marketplace.
This video is part of the RLC+ playlist. Browse every CIQ video by product and topic.
Transcript
good morning good afternoon and good evening wherever you are thank you for joining at ciq we're focused on powering the next generation of software infrastructure leveraging the capabilities of cloud hyperscale and HPC from research to the Enterprise our customers rely on us for the ultimate Rocky Linux Warewulf and Apptainer support escalation we provide deep development capabilities and solutions all delivered in the collaborative Spirit of Open Source can you guys welcome thanks so much for being here I can't believe zann Hamilton this is our last webinar of the year last webinar of 2024 it's gone fast too fast so fast Okay so we've got some amazing
guests here with us today so you guys already know who I am Ros Stein I work at ciq do a sales and admin and all kinds of wonderful things glad to be here zanen why don't you to introduce yourself s Hamilton I lead sales here at CQ you sure do and you are a great Boss by the way thank you for being such a great boss this whole year you don't mean it but I appreciate it anyway just say thank you man yeah thank you thank you thank you oh no you're welcome there you go I said thank you you say you're welcome there you
go you're welcome easy Brea whichever all right wonderful glad to be here and Mr JW hey folks I'm JW I'm the head of Ci's Cloud programs over here pleasure to be uh on the show with you today roseen Zan welcome and also so I I'm just in the Gratitude mood is the season JW thank you for taking on that role you have had a few roles here at ciq and you've done really well at all of them so thank you for everything that you do for us my pleasure let's keep it up in 2025 absolutely oh my gosh I can't believe it's 2025 already it's
so weird all right and Mr Dean you are a new face to me so introduce yourself who are you well first of all Rose thank you for having me on the show today uh my name is Dean brida I'm part of aws's uh partner strategy I do go to market strategy for application monitorization with our partners yes welcome Dean yeah welcome Dean it's awesome I know that we have a a great relationship I'm not really in in that space there but it's really nice to put a face to all the wonderful things I've been hearing about our relationship and our partnership with AWS so thank
View full transcriptHide full transcript
you yeah absolutely okay last but not least Mr Curtis hi and thanks thanks for letting us be a part of the last webinar of the year like that's actually a great honor and like we really appreciate it um and for those listening my name is Curtis reesi and I work with Dean um I've had the honor of working with Dean for the last couple years now um and my focus is on modernization partners and my principal essay focused on that been with AWS for about a decade now I think going on nine years uh this year um and so I'm very happy to be a
part of this containers and and Linux operating systems have kind of been you know lock step in my career here and very excited to see what we can do with you and your customers together into 2025 yeah yes and speaking of customers I mean we both have lots of customers and some of them are the same so thank you to everyone who watches everyone that is in all of the communities that we are a part of and just thank you for for being here and making this life a fun one absolutely we're here for that's what we're here for okay so who's going to do
the overview a little overview of the Amazon eks hybrid nodes so I can I can get started on that and then Dean and I can just basically tag team the conversation as we go through so um we definitely want this to be an interactive conversation so all of you can just kind of chime in as we go um let me go ahead and share my screen so that we can get this started yeah and while that's pulling up there I'll uh I'll te the stage up a little bit this is a uh a super cool launch we've been working on for the last few months
and this actually just got launched at reinvent 2024 uh which is always a uh a fantastic party there that was uh just occurring last week first week of December uh if you haven't been uh that is a fantastic event to check out um it is by far the largest one of these Tech conferences I've ever been to and I gotta say probably had the most vibrant uh Expo as well it was just everyone was packed in there learning having a great time I got to meet our friends uh uh from AWS over during that show as well and uh you know it's not just a
little window on the screen there JW I feel like you told me when we were there I think they were anticipating about 65 to 67,000 and there were over 880,000 oh my gosh that's a lot of people in one one place it's a lot of people and it wasn't just one place though it was like what five hotels and all the conference facilities around it it seemed like going from one place to the other was at least a mile mile and a half walk each Direction hopefully you wore good shoes right yeah good time to buy a new pair of sneakers yeah it's definitely time
like like oh I've got I've got a I've got I've got a a session to go to it's just a couple hotels over how long can it be EXA you know an hour and a half later I'm rolling up all sweaty here I tell you 12 and half miles on Tuesday 12 and a half miles in one day exactly it's like that's that's the size of a small town in fact I think that's bigger than my town like I I think my town is only 65,000 people so it's trying to walk around that all day is is a is a process which is awesome so
thanks for everybody that that went through that and I hope you got everything out of reinvent that that you went there for if not we've got great sessions like this where hopefully we can continue that conversation Beyond reinvent yeah so tell us a little bit about uh the brand new feature uh which is the subject of our discussion today eks hybrid nodes yeah we you're here to talk about this and it's an expansion uh on on top of the the suite that is eks that we we've got going today um I think most people are familiar with eks in the cloud and some of you
may be familiar with eks anywhere which is really more towards you know running completely air gapped on Prem but there's a lot of customers these days and Dean can probably comment on this that are trying to run hybrid like maybe they have data on Prem that they need access to and they need a run workloads next to but they don't want to set up a specific cluster just for that and self manage it I like Dean do you want to do you want to kind of add on yeah I would say it's probably the probably the first piece of feedback we received from our customer
in our partner bases hey we have eks and we have anywhere but wouldn't it be great if we could have a an experience that actually included both of them and not just have an air gap solution and so you know that piece of feedback has been in the mind of AWS for a period of time and you know it's fantastic we're able to launch something like that now where we can have a a manage experience for on cloud and on Prem workloads yeah and like the idea here is that we we work backwards from customers at AWS and you know we've been hearing specifically from
customers that trying to manage your own on- premise infrastructure as well as managing infrastructure in the cloud oftentimes there's two different processes you have to put in place and that that's operational overhead that basically most people don't actually need and what we really want to focus on especially in this gen kind of evolving and and escalating Evolution um kind of state like the ability to get the undifferentiated heavy lifting off your plate so that you can focus on the Innovation that's really kind of the key driver for a lot of these businesses and so we're trying to find ways to to simplify that management consolidate
some of that technical sprawl and allow you to to basically make use of the on- premise resources using the same kind of management layer um and scale that you get in the cloud and so um you know when we look at that that's that's kind of what we were trying to drive with with um eks hybrid nodes and like I said at kind of the start of this we have a couple different options here depending upon the use case that you're looking at so um we have Cloud connected use cases um such as eks on on AWS Outpost which has that connectivity to AWS um
on the right side of this in the green we've had things like um eks anywhere which is really set up to be self-managed and put in an on- premise environment of an air gapped State you know the example that we type typically use is things like cruise ships where you know there's a ton of compute on top of these cruise ships that most customers never have to see and they're kind of in the background but they help the cruise ship function when that cruise ship leave port leaves Port there's no connectivity so I don't if any of you have been on a cruise before like
there's no cell phone access and maybe you're on edge which is like 15 years ago kind of connectivity Wi-Fi for $10 a minute uh over the satellite you know exactly maybe spacex's new feature will help fix that with cell satellite or satellite cell phones um but the idea is there's a middle ground here that that customers need and that's where eks hybrid noes really kind of comes in where you can take advantage of what's going on in AWS from the control plane and you can deploy workloads to to node groups that you br you manage and bring up on your own operating system so in
this case say rocky lenux um so you're going to bring up those nodes have that connectivity and be able to schedule workloads from one location using the same process um and so you're going to get that managed kubernetes kind of experience that's akin to to running ecast I mean Zane I know you've uh heard our customers complaining about the hassle of running their own kubernetes clusters uh this is not a new struggle in the industry here no and having to build a cluster on Prem to do I mean kind of what Curtis said earlier that or maybe was de that having to build a cluster
on Prem for a specific use case it just becomes more overhead more burdened and they're looking for this I mean truly this becomes an easy button I don't have to worry about having a completely differentiated environment differentiated thing this is very powerful to me consistent standardized yep yep absolutely on I think he hit the the nail and the head there Zane with that that easy button kind of mentality I don't for any of you that have implemented eks anywhere I don't want to say it's difficult but it is there is a specific set of steps that you have to follow and there are certain Hardware
requirements um and if that meets your use case then they're they're perfect for that but in this scenario with eks hybrid nodes you can bring your own infrastructure you can bring you know if you have racks sitting there that are just being unused or you want better utilization out of them it's a simple process of installing uh the the control plane on or the not the control plane but the the node ADM the CLI on it to connect it up to the cloud and the most challenging part of that is honestly the networking and so it's it makes it a much easier process for getting
up and running and being able to to to amortize the the value of those existing you know infrastructure components and get more more cost savings and benefit out of them um which is fantastic and so um yeah that's kind of where we've been headed for this and hopefully um it works well with the customers and a lot of to workload sorry C I mean speed to workload getting things up and running because everybody's got kubernetes people but at some level there is a basic knowledge of setting up kubernetes versus the actual deep understanding and this kind of makes it where you don't have to have
that deep of skill set you can kind of Leverage what exists the complicated part's been done you're just kind of connecting into it well and honestly that's that's one of the things that we hear from customers all the time especially when we're talking with Partners like Consulting Partners I would say maybe 50 to 60% of an engagement is honestly spent on just setting up that plumbing before they've even touched the workload and so the idea here is if you can find a simplified way of dealing with that you can use automation tools you can use uh terraform you can use the things that that that
customers are already using today to simplify that story and immediately get up and running focusing on the workload and that's like I think we forget that like a lot of us are technologists that are working in the kubernetes space and we love the Niles we love the knobs we want all of the the thirdparty solutions that we're adding in but we also really need to understand that the whole point of that is to help the business get something out to customers quickly and efficiently and safely so kind of on that topic like what are those workloads that we're seeing today and that we think are
great use cases for hybrid notes and it's spans kind of the gamut of what we're seeing today and I don't know Dean if you want to cover some of these like what we're seeing from like a sales side um I'm more of the tech junkie on this side yeah so a couple of big ones right so um there's two ways to look at this one is hybrid nodes brings the advantage of leveraging uh sweated assets you already have on premise you know things that you've already paid for that you're depreciating over time that you want to Leverage The that infrastructure because it's sitting there there
uh the other side of the coin too is though what if you have specialized Hardware that you want to leverage in with workloads but you really can't do it incloud in on Prem at the same time that that brings in that use case of things like round machine learning and some of the uh Enterprise modernization which is hey I have an application I have a workload that's on Prem today but I want to connect it to Cloud Technologies I want to I want to connect to some of the managed Services AWS has so we're not saying that you you can't do both what we're saying
now is is you can have something on Prem and still talk to the cloud and still use our manage services so it really brings that Enterprise application uh landscape together where bits and pieces and parts of can be can be in different places so that's really cool um Financial Services healthc care manufacturing of course manufacturer I think probably brings to mind very quickly about Edge devices things sitting on the on the floor things like that which makes it really nice special purpose Edge devices financial services and Healthcare um a lot of the modeling that they do they may not want to do it in the
cloud they may want to do it on Prem and that could be for regulatory compliancy type in issues um you think about drug and research development maybe that shouldn't be in certain parts of the cloud Financial Services maybe there's some compliancy they need to worry about so that brings that opens up that use case for those different types of workloads yeah and I think there's some opportunities that that we can see within this like retail is another one that we don't have on here but when you think about it the whole point of this is finding ways to be able to manage what could be
potentially hundreds if not thousands of clusters from as much of a centralized place as possible so if you're running a retail shop or a manufacturing solution where you could potentially have dozens if not more of these being able to manage them centrally is kind of a core thing and being able to keep track of that to to Dean's point of like if there's Regulatory Compliance or data residency compliance you can still have the control in the cloud while maintaining the data dat a residency and meeting those requirements without having to have something completely separate and bespoke um and so that's like it's helping accelerate there
and then when you think about the financial services sector they spent a lot of time hardening their operating systems they spend a lot of time hardening like their infrastructure and being able to leverage that strength so say they're hardening Rocky Linux and putting everything on top of that like being able to immediately connect that to the cloud in a consistent way taking advantage of some of the cloud benefits of of security and processing governance here and aligning that to what what they're doing on Prem it makes it a much easier process for them to be successful um especially if they're doing things like Payment Processing
data streaming you know companies like NASDAQ you can imagine they're running apis on top of these types of solutions being able to do that in a performant way that fits into their current processes it's great that's really what we want to see and that kind of leads into what does this actually look like you know we're talking about there's a control plane in the cloud and then there's these you know servers on Prem like what does that actually mean and the idea here is that we've got essentially cluster operators or automation that's happening kind of on the left side of this and so in the
cloud you have somebody that's spinning up your infrastructure hopefully using something like cdk or terraform or cloud formation to automate the infrastructure piece you have somebody that's doing that typically on Prem you know whether they're using something like terraform on Prem or you know one of the the old uh configuration Management Solutions that are out there um they're basically trying to provision these things and they can follow the same kind of process and so what we have up in the cloud is we have an API that you're going to use that can spin up a cluster that can do updates to that particular cluster um
and then what that'll what'll happen is these clusters can spin up you can have one that can speak to multiple regions you can have individual clusters and individual regions you can have a mix of them these can even be hybrid clusters where there's some workloads that have node groups in the cloud and some node groups that are down uh in the on- premise environments and you can schedule workloads based on affinities labels whatever um and so if you have something that you know your deployment team pushes out and the deployment Target is an on- Prem environment it can automatically schedule that based on the resources
available um and what that looks like on Prem is you need to Simply spin up um either VMS or bare metal and install the operating system put the the hybrid node CLI on top of it and then from there you manage that with the specific apis on top of that for install and it upgrade and uninstall um and so the fun thing that that really ties this together is you know you've got the the U VPN or the direct connect so the ne the network connectivity is kind of the key between those two locations and then you have governance and IM along with that so
you can use things like systems manager and IM IM rules anywhere to have consistent permissions across that so you can still have one centralized way to control and you get that benefit on Prem any questions on that like does that make sense to to all of you here I realize that we're going kind of deeper in the Weeds on the tech side but um no absolutely that's fantastic and I I again just looking at this diagram it is required that you have side to side VPN or yeah like when you I think with the next slide we we talk about um the the shared responsibility
model and like when you look at the way this works you're going to there's three components so you've got the the components in the cloud which is really the the the cluster themselves the control plane you have the network connectivity that brings it down in fact I think that's on the next slide I'll jump ahead a little bit I lost it oh well um w w um so basically the idea here is you've got what's up in the cloud you've got the network connection which can be direct connector VPN down to the the on- premise environments and then you have the on- premise environment and
as long as you have those three things set up you're good to go and you can automate the configuration of basically each of those components like so using something like cdk you can spin up the the vpcs in AWS you can spin up the Clusters you can even spin up and provision the the the VPN connections if you're using a VPN I think there's a little bit more to it with the direct connect side but you can still automate the good portion of that and then on Prem you can use something like terraform to provision the the the individual nodes themselves and install the certificates
in the CLI to make that connection and in a fully automated sense that that makes a lot of sense and in that structure there's certain things that we will do for you and there's certain things that we want to the customers to understand that they need to be responsible for so at the top of this diagram that you're seeing here it's the AWS managed resources this is all the stuff that's up in the cloud like eks itself um the VPN connections guard Duty the security and observability pieces the cluster and the control plane all of that is essentially the managed services that are you're going
to turn on with the click of a button and maybe provide some light configuration but we're going to handle the management upkeep and security of those um as you go down that stack into the on premise environment this is where you're going to have the actual node groups so the physical infrastructure the virtualization the on premise networking things like that the operating system that's really where the customer is going to have to manage that and where we come in kind of in a hybrid scenario or is a vend diagram overlap is really the the eks hybrid nodes CLI and the node group management on top
of that so things like managing the cube proxy core DNS any of the kubernetes add-ons that are a part of eks we're going to offer support for that and then the same with node ADM itself like how we manage the on premise nodes so they can have that connectivity to the cloud will support that as well so you have fully managed up an AWS that you can have a support contract to get support there you have on premise where you're going to manage your own infrastructure and maybe you have somebody that helps you with support for that and at the operating system to application layer
there's a combination of support and I imagine ciq offers support for all the rocky lenux users out there that if you're using that it's your your base you can have like a fully supported uh implementation across the stack whether through AWS or through ciq absolutely we do okay the uh the shared responsibility model is uh well known uh around here for for sure and uh we're ready to help any customers who are running Rocky Linux anywhere you can boot up a rocky Linux machine and honestly that's that's the value that I hope more customers take advantage of like we said earlier it's this is ability
to go from idea to implementation as quickly as possible like some people yes you need to manage things yourself but if you have Partners like ciq and like um AWS to help you with that process you take advantage of it where wherever possible I realize not everybody can afford you know support contracts but we all work our best to make those affordable and meaningful um and then we have partners that help along the way um and this was the diagram I was actually looking for the four components that you you need to have are the network connectivity the on- premise infrastructure um the operating system
itself um and I apologize Rocky lenux isn't on this slide but we're working to get it on this slide like it it belongs here as far as I'm concerned um and so we want to make sure that that's on this slide as well so my apologies there um and then you have their credential providers which is the the the security side of it so you've got systems manager and I am roles anywhere um which your consistency with the cloud so those are the four components any questions on this anything we need to add this is the boring slide are there any latency requirements from the
on- prim connection back to to AWS I mean it's not like uh video game latency where you need the lowest ping to be successful um I think the latency requirement is more for the specific workloads um and it's going to vary based on the workload itself as long as it can report in at at specific occasions like the reality is if that connectivity drops it just simply means that the cluster state is going to remain the same unless something happens on that on those node groups like if if you have that disconnect and and you know something goes down it's not going to restart and
so it's it's you just want to make sure that like that meets your um your risk appetite for that that workload um and so that's why if you have a scenario honestly that is um has a looser connection or a connection that's going to drop with frequency that's where I would look more towards something like um an air gap solution something like eeks anywhere um and consider that so that you can have that on premise control plane um but if you don't have that requirement or you have you know somewhat consistent connectivity um even if it's a slower connection like just being able to connect
to that control plane to schedule nodes would be good I mean lower lower the lower it is the better um but I'm like literally I've got a server sitting right here running a number of these instances and I've got on my home connection which I hope a business connection is faster than that I've got a home connection here and it's 70 milliseconds um and it's pumping out workloads just fine and this has a GPU and I'm scheduling you know GPU related tasks on it so it's it seems to be doing just fine oh very cool yeah it's fun fun idea here um and this is
kind of the the fun diagram of how it all works and basically there's there's three Focus areas so when you set up uh the cluster there's things that you have to kind of know in advance and that's going to be you know everything is the the Crux of this all is networking you know the the tripping point and the challenge that everybody runs into is the networking piece and you need to know these things up in in advance because when you create the cluster you're going to have to know the remote node Network side arranges and the remote pod Network side side arranges and the
Pod Network side range really only needs to be known if you're going to be running things that have web hooks um because the way that web hooks work in this scenario is the control playe needs to be able to know the IP address for those um so that it can actually um like since they're running in the cluster itself their pods it's going to have to be able to route down and it goes directly to the actual IP um of the the Pod Network so generally we want you to expose that with like bgp but at the end of the day you have to know
those upfront so that you can feed that into the cluster configuration so that when it Provisions that cluster it knows how to communicate those workloads down and connect to them so if you're going to have multiple node groups or multiple networks these are the kind of things that you have to have that kind of theory for or understanding of upfront so that you can get it right it's not something today you know it is a feature request for the future but something today that you can't you can change on the Fly it's a destructive change and so I just want you to be clear on
that um within that you also have the the VPC routing so you're going to provision the VPC and then you're going to set up specific routes through your direct connect or through your VPN using those cider ranges and so you need to have that set up and so whether you have one five however many subnets you want you just need to make sure that routing is set up so that it's actually transporting those um Communications through the the right Network channels um and then you're going to configure on your on premise environment that Network routing so make sure that it's coming through and then the
Gateway in your router on premises understand how to route that to the specific cluster and then also down to the the specific node groups in there and then once you in that it's like once you're in the node group it's just standard kubernetes like you can use the cnis that you typically want to use you just can't use the VPC cni because on premise that that's that's an AWS perspective uh uh specific thing um but you can use things like psyllium um or Calico on premise you can set up your Ingress controllers the same way you normally would the metal lb is supported note or
engine X is supported and then basically it's just standard kubernetes from there the thing that you just have to be aware of is when you're deploying workloads how are you getting storage connected to it how is the operating system being secured and separating between you know the the workloads that are on it and making sure that you've got all that kind of stuff in place um for the on- premise environment like that's that's basically all there is to it it's essentially a networking component in you know provisioning tool on the the on-prem which simplifies it honestly absolutely it does massively yeah and that's that's the
hope and then for those of you that want to see what this looks like within the console it's it's not just a c implementation when you go to create your cluster there's going to be an option for you to specify a remote Network um and it's just going to ask you for this so your node cider and your pods siter um and that's basically all it comes down to um on premises the way you're going to provision this you know if anybody was familiar with eks anywhere we have a whole solution that goes through and Provisions the bare metal it speaks to to ipmi and
will basically provision turn on the the bare metal install everything configure the control plane configure the node groups this is a much more simplified scenario like you're going to have the node ADM CLI which goes through and sets up um the the cluster software on it installs kubernetes it will provision all the you can set up the certificates to to allow for that connection um it's going to register those nodes and basically set everything up that needs to be running on top of it um and then basically that's that's it and so from there you're just in the the the typical life cycle management of
those nodes you make it sound so simple Kurt well I don't want to like I I run the risk of making it sound overly simple it's it's as simple as as we we can make it right now we are open to feedback um we are looking for ways to improve that process especially in the automation face of things if you can you we want to make it as simple and seamless as possible for customers but at the end of the day it's still software that you have to install you're still provisioning the hardware and you uh you as the customer need to be you know
have a process for that um and you know there's there's ways to automate that wherever possible so yeah yeah if you have sorry JW if you have an existing eks cluster can you turn it into a hybrid cluster would it be building a new one I know that affects the networking in the back end a little bit so yeah so long term long term we want to be able to get to that so if you have something you can configure it but based on the networking implementation today at launch it's something that is it's a destructive change like you're going to have to spin up
a new cluster fortunately this is the same process everybody runs today like you want to spin up a new new version you can do an inplace upgrade but a lot of customers will just spin up another cluster make sure everything's working and then redeploy the workloads you just update your cicd processes and it over it's a it's kind of the same model there it's just you've got that additional step of setting up the the network connectivity but honestly once that's set up it's the same process it's all a matter of routes the VPC and the the actual VPN connection or direct connection can stay the
same it's just where you're deploying those clusters and so it's just a matter of make Shing the networking can connect those those routes makes sense thank you yeah no worries the documentation on this is actually pretty clear too we uh we were Kurt you and I were involved in the uh uh pre-release testing for this feature and you know the the networking was the hardest part by far but that's uh pretty Standard Plumbing for uh for anything you're doing in this genre I think that's kind of funny too because like everybody understood the kubernetes part and I think most customers really understand that kubernetes and
the provisioning process we have we've been doing this for years but I think a lot of people don't actually Venture into the networking side and I I don't know from my own history I used to work at a at a mapping soft company and the networking team they were seen as gods they were off like another room and like you you made requests of them and you begged and pleaded to get ports open it's like just that whole structure was was essentially seen as magic uh to Magic consumer yeah black magic it is um and you can kind of see that throughout the launch like
as everybody's trying to get through this um the networking was the The Stumbling point and honestly the networking isn't that hard and so that I see as a good sign if that's where we're stumbling it's just that connectivity and the rest of it is pretty straightforward that's a win like I think that's that that's the important piece um so for those of you listening don't let that seem like it's a barrier this is actually a really easy process and we're working to find ways to give you examples on how to actually automate the provisioning of those in context so that we're offering say blueprints that
can actually provision and spin these things up so that you don't have to they'll give you an output that's your your connection Keys they'll give you an output that's the the VPN security implementation um and the the CTS and and that that that implementation you need to take to your network team to build that and connect it like we're trying to find ways to simplify that and we're going to continue to evolve this over the next year um to make it even easier for customers to get set up so and the good news is you go through the pain once and once you get through
that small bit of pain of getting connected then you have that unified um run operations where everything's put together on a single console so everything actually looks the same yeah and it looking the same is kind of the key what's what's on the slide here right now is the way these nodes are going to show up in the console in AWS is the exact same way that the nodes show up today for the the nodes in AWS um you're just going to get an additional item down here under compute I think you can see my Mouse um that just denotes whether that node is AWS
or if it's hybrid and then you're also going to get visibility into the actual metrics on those nodes themselves and so that's the beauty of it actually running a traditional node in your clusters you get the same visibility um as you would with anything uh any other cluster so it's it's really that simplification and then you're going to have the same access to things like eks add-ons that you would now if it's an eks add-on that's specific to just AWS and what's in the cloud maybe that that's not going to work for you like the the the VPC cni that's just not it's not applicable
in that scenario um but everything else should work and we had I think 19 launch Partners including ciq at launch for this that includes various isv Solutions as well as uh Consulting solutions that can help um and so there's um we're going to continue to grow that but at the end of the day this is just standard kubernetes so if you're using it today chances are it's going to work just like it normally does and then some of the features that we're looking at um at launch it's available essentially in all AWS commercial regions um it's specifically to your point Zane it's for new new
clusters today um it is a feature request we are going to try and get that in so that we can modify existing clusters but that's not available today um it uses the same versions of kubernetes that we support in the cloud so the the latest Standard Version as well as the extended kubernetes kubernetes versions and we typically support uh two to three versions back um I'm GNA get shot for that one because I can't remember whether it was just two or three and I should know that so I'm sure I'm going to get a slack message later it's two um try to stay current that's
that's the real answer just try to stay current just try try to stay current both of these like the node ADM and uh the CI and AWS offer support for upgrades um so make sure you're running the latest and if you're not set up a process with your offs teams to make sure that that's something that happens um as these are coming out you can set up parallel like I say I say this my wife would yell at me like like there are costs with setting up secondary clusters and ab environments but if you are using this with a purpose and you you make sure
that that testing a setup you can save on cost there but the idea is at regular intervals be testing your your software against the latest versions and making it making use of your cicd pipelines to get those tested and validated and automated so that you can release them as quickly as possible um unforunately the conversation we have around here far too often Curtis we we run across customers who are running operating systems that are literally 20 years old so dude I came from Problem the reason I'm in modernization is I came from a company where we were running cold fusion 7 for 400 applications during
a time when cold fusion 12 was out and just saying we were running cold fusion just makes me it's like there's some stigma there but it's that that reality of like it's it's real people get locked into these Legacy applications and that's where companies like you and I are we're really here to help people get onto these latest versions stay secure like get the right operating systems in place as a foundation to build their applications on top of and like by partnering with you and this like we can help get those workloads moved over so if you as a customer have these Legacy workloads on
Prem uh work with CQ work with AWS let's get these types of things provision in kubernetes let's containerize them and like hopefully Breathe new life into them so you're not just like it's not Pandora's Box where you occasionally open it and go like oh my God it's okay we gotta close the Box abut these workloads can actually be uh modernized and keep your business going getting back to this it's the same um console and uh CIS that you're used to today um and so everything should work the same as you would expect um mix mode we do support mix mode clusters I think this is
an interesting one for a lot of customers you can have node groups in AWS as well as on Prem and multiple on Prem environments um you know under one cluster and that you know no two workloads are the same um and oftentimes the workloads that we do have are complex like especially if you're looking at gen workloads some things are going to be serving functions some of these things are going to be batch process some of these are going to be streaming functions and capabilities and are going to be long-term inferencing you can find the right node group and provision the right infrastructure in Silicon
to meet the needs of that application but still have it all within the same cluster in context to each other so you can minimize the networking Hops and and increase that performance those workloads may need and so we offer that same kind of flexibility and this is something that's really interesting and I think is a key differentiator for this solution because typically you have to manage these things separately and maybe you've got an API that's connecting across these clusters but they're completely independent here you can have them all be a part of the same workload and you can take advantage of the same policies and
permissions internally to keep the workflows kind of segregated you can have the same name spacing across these and you can get that proximity um so it's it's kind of an important thing to to to keep in mind you can truly build a multi-tier application stack across on Prim and on cloud it's pretty cool absolutely I think that's that's the it's something that more customers should probably take advantage of or consider um and then on Prem like we continue to have the same thing so you can use core DNS as an add-on for auto scaling and C the the Q proxy add-on as well so in
AWS you can take advantage of eks auto mode potentially and then on premise you can have um Auto scaling that's handling the scaling of your your on premise environment um again I've said this a couple times but I really want to hit this one home you can take advantage of the same am policies and roles on Prem as you do in AWS using the the PO identity and I am roles um for or IM rolls anywhere I always mix up I want to call it Ursa like ursa's here um you get Ursa within the cluster and then you get IM am rolls for the cluster
itself which is nice um and then the same kind of observability is is there like most customers these days are using Prometheus and grafana we've got otel that's on top of that connecting it all together um you could take advantage of running these in the cluster you can take advantage of manage manage services like U managed Prometheus and graphon and AWS if you want um and then the same observability like Cloud watch is there as well so you can pump that out through otel into cloudwatch and then guard duty to manage an the the auditing and governance of the cluster like some of this is
the boring Plumbing but these are important features I'm sure there's a a security admin or an operations person that's like that's that's there and it works um so for you I applaud you and I LW you thank you for being you um and then for the rest of us that are looking at just the workload there's everything you need in here to to make you successful so there's a little bit of it for everybody on this and and honestly that's all I had for the the presentation it really isn't too much more to it so we got the thank you slide now um and we
do have an email address so if any of the customers here have questions or need help or support on this um you can email AWS hybrid um with questions feature requests are great through here if you have a support contract I recommend not using this for support contact your your support Representatives your Tam and go through them for support this is more of you know feature requests and Communications to the Mark teenss um so yeah and with that I will stop sharing my screen direct to your inbox there Kurt direct yeah it's just all an alias to to to siry and for any for anybody
who's looking to implement this themselves as I mentioned earlier there's fantastic service documentation available from AWS about this as well ciq we've also prepared uh a full-on um technical blog walking through the process um of installing this you know from inception through validation um of the cluster to to know that it's working and showing a a quick little little app a little game that we uh we threw on as a validation test that's going to be up on the CQ website so if you want to see exactly how the sausage is made in a specific scenario you can go take a look at that as
well yeah and I'm I'm planning on using some of that internally at AWS to share with the the essays here that can take them out to customers as well um I think that's the key differentiator here like there is the documentation which walks you through everything like you get full details of all the considerations that you you you should be be making with with setting this up what I love about your blog post and what I think customers are going to get the most value of when it launches is it's very prescriptive like instead of the theory it's the actual practical application because a lot
of times when people are setting something up for the first time they just want to see it like what does it actually look like and then if they have specific requirements yeah the docs are there to support that so definitely combine the two take a look at at at the the team's blog when it comes out because it it does tell you okay do this now like here's the consideration now do this like um so it'll get you up and running very quickly um and then as you want to go beyond that definitely reach out to to the rest of us to help helping you
in that Journey yeah taking it one step further we will be analizing a lot of this because we have our anable products so we want to make it as easy as possible exactly yeah and that's that's something that I think we can even uh continue to support with you um to try and get that out to customers um we've got the options of cdk and terraform in the cloud but if customers today are using anable with with ciq like let's do it let's get that set up to make it a just a turnkey solution for customers you get up and running um secure the operating
system you know make sure everything's performant in tune the way you need for your governments and governance and requirements um yeah perfect we'll certainly be we'll certainly be uh hitting up about that one here in 2025 Kurt absolutely and I look forward to it and I don't know Dean is there anything else that that I missed or you think we should add I think you covered it pretty well thank you I think uh yeah I think we're good yeah I love these more interactive conversations versus than just reading a slide deck like it's it's much more valuable agreed thank you for doing that appreciate it
anytime thanks for letting us interact and ask questions been for me so are you guys going to be sticking around as we talk about Rocky and Warewulf or are you heading out I have time to stick around I'm kind of interested in hearing more about this to be honest so I don't know if I need to stay on camera or yeah around yeah stick around now you get to ask questions sounds good exactly so I think this is actually uh JW's time to shine right now talking about Rocky Linux on a WS Marketplace uh you can run Rocky Linux uh all over the place
including in AWS we've got uh Marketplace listings for you ready to go these are of course our our standard uh offerings it's it's our latest version of Rocky 8 latest version of Rocky 9 which has just come out as 9.5 uh so we're we're talking about keeping your environments current uh folks it is time to upgrade you'll find those in in the AWS Marketplace we've got them for x86 right now arm will be coming very shortly um our uh our Engineers are turning the crank in the back end to put that all together um and uh it will be very shortly behind that uh we
also have some LTS images there if you happen to be running a little bit older of a version because you've got some apps that maybe are bound by very specific uh compliance requirements or their you're running an isv application that is certified only on one specific older version you know Rose how often do we see that uh a lot David we can help you with the ongoing security and compliance for those uh for the previous handful of minor versions of eight and nine uh you know obviously you don't necessarily get the latest and greatest performance and security features if you're running a little bit back
there but that's the reality of the world sometimes and so we offer that for you as well um and a quick plug for another AWS Service uh if you are running virtual desktops through Amazon workspaces or appstream 2.0 you can also find Rocky Linux over there uh and it's a a drop in replacement you know for your rail environments you fire it up right from the console and you go so you can run Rocky across your entire fleet your whole infrastructure ructure all the way from the edge all the way up through the cloud and uh into some managed virtual desktop services for you you're
really making it easy for customers to adopt aren't you let's talk about let's talk about arm support as you just mentioned when's that gonna come out because we love Arm support with graviton yeah absolutely and we love it too we're um we're actually just refreshing those images um you know as we speak really and I would expect that if if it's not up by the time you're seen this webinar when this uh the bits flow through the pipe and get uploaded there um it wouldn't be more than a few weeks beyond that um this is this is a very very fast follow thing we just
do them one at a time uh uh as we have the bandwidth on our uh Solutions delivery team there fantastic we have a pretty large embedded base of graviton customers we love to hear that you're supporting graviton yeah it's really exciting especially going through the marketplace like simplifying that that procurement process for a lot of customers just being able to make it more of a turnkey solution handle billing and stuff that's fantastic so thanks for going through that I really do appreciate it it's our pleasure and we're happy to you know if you've got customers who need a need a site license or anything of
that nature do some Enterprise support uh you know it's not just U metered listings off the rack you know we're we're happy to talk to you about a private offer if you've got something that's not covered by uh the version you just grab and walk to the checkout with there so come and talk to us we got Zane we got Rose we got all all our CQ team we're here for you that's right and thanks to the team that's working on arm I know that's a big Skip's a big fan I know Skip puts a lot of time into it so I know there's a
team of people but skip appreciate your work on our yeah thanks skip shout out to skip absolutely it's an important thing especially as we we have more and more customers looking for geni workloads they're trying to find ways to get that performance um as well as the cost savings because some of these workloads are very expensive and so being able to make use of arm processors wherever possible um yeah like we should all be hitting up AMD and some of the the Intel like see if we can get them to accelerate development of more arm processors for arm premise environments too sure cool um so
I know sorry there's so many other directions you can go in with cloud and with Rocky Linux and I was like you know I don't know should we like read Focus back into the next thing I think so I think probably we will we will let Rocky just lay right there as beautiful as it is um so they're actually is another open source project that we help uh maintain and support and do training uh with that is really taking a front seat uh and a lot of our conversations and places that we are going I mean all of our stuff is very very exciting but
Warewulf is making a comeback man it's got a bright future keep saying it I keep saying it good marketing man good I like it I like it a lot so um yes we just want to make a little bit of a plug for Warewulf right now and using Warewulf to manage your GPU clusters we're actually having a webinar with that exact title on January 11th at 11:00 a.m.
you actually have to register for this one so it isn't one that we're just going to be live we kind of want it to be a little bit more personalized a little bit more Hands-On not not um I mean live in there but not live to the you know what I mean like Live on YouTube you gotta register and get the link gotta register thank you be a full moon too right yeah that's is it that would be so how cool that somebody should check the calendar double check that no no I'm thinking oh that would be amazing yeah so January 9th and we're going
to put the registration link uh right at in in the comments right there for you so it'll be super easy um and I guess Jess do we have do we is there any questions any any other questions we got I don't think so yeah I think it's an important thing that we should like most customers should be considering like AWS we don't offer a multicluster management solution um and so having something a solution like Warewulf that can handle cluster provisioning um for customers and simplifying that process that's something that's actually really important and most customers should be evaluating um trying to manage these things yourself
um doesn't make a whole lot of sense and so it's really exciting to see products like this coming out now I have a question for you because I'm just the peanut gallery here now um is there a reason for the name Warewulf like is there a meaning behind that that yes you know it Zane I'm I'm blanking for some reason I've heard the story from Greg probably 20 times for reason the wear is actually right and wolf is from B wolf model like the bolf clusterf cluster that's totally cool the the OG of clusters back in the day there trivia night now I'm gonna stump
everybody next Friday yeah that's right if we if we did trivia night together I think we would win I think we would all win here especially with that question so Curtis actually that brings up a question for you like how familiar are you with Warewulf I am unfortunately not very familiar so like just understanding of just like at the very high level what it is and what it does yes but deep in the weeds of the power and the the the value it's providing for customers I'm actually kind of green to so like are you willing to dive in a little bit on what that
is and do we have time for that or is is sure yeah you can do that yeah so I mean it's really an HPC tool it would started off as a a very easy way to deploy a large amount of nodes compute nodes as a version 4 it's actually a stateless provisioner so all of the actual compute nodes it Provisions stateless so it makes it a very easy very fast way to provision out a lot of nodes and the way that it was designed the way that it's built now it's very easy it's command line tool that you can just start deploying out the the
images are an oci compliant container image it's not what it actually it's not pushing a container to a machine it actually puts a a version of Linux running in memory but it's very easy to Define what those look like because it's just an oci compliant container definition so makes it really easy to Define what you want your Compu noes to look like it's very easy to change them switch them out add things to them with overlays so it it's a really powerful tool that's fantastic I'm gonna dive into that this weekend because I want to learn a little bit more about that that's that's very
cool awesome okay guys well we actually could probably just keep on talking for a long time because there's so many different aspects and so many exciting things in Tech world and at AWS the amazing things that you guys are bringing to the Forefront and for the community and for your customers uh it's really exciting we are so pleased to be one of your partners one of your many but one of your partners uh AWS so yes thank you for all the work that we're doing together I appreciate it yeah we really do appreciate the partnership and I'll speak for Dean and he may want to
comment but we're definitely looking forward to to continuing the partnership into 2025 and I'm looking forward to seeing more ways that we can find Integrations and drive more value to your customers yeah yeah exactly likewise curtain Dean absolutely appreciate it appreciate okay well happy holidays you guys and happy New Year and thank you so much for being here we'll see you in 2025 you than everyone thanks everybody
Built for scale. Chosen by the world’s best.
2.75M+
Rocky Linux instances
Being used world wide
90%
Of fortune 100 companies
Use CIQ supported technologies
250k
Avg. monthly downloads
Rocky Linux
9
Enterprise products
Spanning the kernel to the orchestrator
Have questions about your infrastructure?
Talk to a CIQ engineer about Rocky Linux, HPC, and AI infrastructure.
