FOSDEM 2018 in review
I had the privilege to attend FOSDEM in Brussels for the third consecutive year. While maybe the magic of the event has slightly vanished for me, I still do maintain the view that it still provides something that many other conferences can not. Not burdened by commercial drivers (as many vendor-led events like re:Invent, Red Hat Summit etc.), FOSDEM is able to provide very high quality content without any marketing fluff thrown into the soup. For a company such as Ambientia, which uses a lot of free and open source software in most, if not all of our projects, FOSDEM offers a unique view to see the most recent developments in these tools and technologies. It allows us to be more prepared for the future.
FOSDEM is a huge event with well over 20 concurrent sessions taking place both days, so to be able to really for the event in any meaningful extent having more than one person to attend is very important. As FOSDEM is completely run by volunteers (and in part funded by sponsors such as Red Hat, Google and AWS) it is also free to attend, i.e. there are no participation fees or such. All you have to do is to show up.
Over the past couple of years, FOSDEM has also gotten a bit bigger attendance-wise. This in turn has put more burden on the facilities of the university campus FOSDEM is held at. At this point, the most popular devrooms (the rooms the sessions are held in) are very crowded and you might even have to wait in line to attend some of the most popular ones. This is an unfortunate side-effect of growing popularity.
My weekend at FOSDEM was mostly spent around Identity and Access Management, Free Java and Containers. All topics offered very interesting sessions. Some highlights are listed below. Unfortunately, the Security devroom that has been arranged in the previous years was not there this year. I don’t have a clear understanding why. This year, security-related matters were mostly embedded in other devrooms (e.g. Kubernetes Security Best Practices in the container devroom) and in the main track, and of course to some extent covered in the IAM devroom.
FOSDEM PgDay
Before FOSDEM, there is an annual PostgreSQL day organized by the good people at PostgreSQL Europe. The day offered a nice overview of more recent developments in PostgreSQL land. These days, PostgreSQL is highly versatile swiss-army knife style RDBMS that can be bent to lots of things you wouldn’t expect a relational database to be able to do. At least a couple of talks highlighted Postgres’s capabilities to handle JSON has a native data type, which makes Postgres a viable alternative to e.g. MongoDB in some use cases. The last talk for the day covered ways in which Postgres can be used as a time series database, instead of using purpose-built systems like InfluxDB or OpenTSDB.
Red Hat IdM in a large Linux environment
y first session at this year’s FOSDEM was Dustin Minnich’s talk on migrating Red Hat’s own internal identity management over to Red Hat IdM. Currently Red Hat uses a hodgepodge system made up of MIT Kerberos, Dog Tag certificate system, 389 Directory Server and BIND DNS server. Currently, they are planning to migrate the old system over to mostly Red Hat IdM -based solution, which in turn is based on a open source project called FreeIPA.
The talk was very interesting as our own identity management infrastructure is fairly dated and in need of a upgrade. FreeIPA -based solutions have been considered as an upgrade path, so the talk provided interesting insights into limitations of FreeIPA/Red Hat IdM and possible ways to overcome these challenges.
All in all, it was also reassuring to witness that even large tech giants like Red Hat with significant IT budget and dedicated IAM team have issues doing these kinds of migrations.
https://fosdem.org/2018/schedule/event/opensource_idm_in_enterprise/
FreeIPA and Samba 4
There were few more talks about FreeIPA and Samba 4, which mostly revolved around project updates and things of similar nature. There have been long standing issues with bringing Samba 4 -style AD functionality to Fedora/RHEL, mostly due to RHEL being shipped with MIT Kerberos instead of Heimdal Kerberos and with MIT Kerberos being incompatible with other Kerberos implementations than Heimdal.
Anyway, going forward, we need to carefully assess our own upgrade path. Samba 4 is currently not a good option as the Active Directory functionality is not available for RHEL. FreeIPA in turn does not integrate too well with Windows and OS X workstations.
Java for containers
The Free Java devroom had a few interesting talks about specific techniques in the JVM/JDK level to improve suitability of Java for containerized workloads. The main challenges with JVM and containers have been mostly in the fact that JVM is best optimized for long-running processes, whereas containers might have significantly shorter lifecycles (e.g. due to autoscaling). This creates issues as JVM is relatively slow to start (e.g. compared to native code) and it’s traditional code execution optimization mechanisms rely to some extent on dynamic observation of hode code paths. The JVM with full class library has also fairly significant footprint memory-wise. All of these issues are being tackled by techniques like class data sharing, ahead of time compilation and jlink -provided optimizations.
A couple of suggested talks:
- https://fosdem.org/2018/schedule/event/jvm_startup/
- https://fosdem.org/2018/schedule/event/java_world_containers/
Containers devroon impressions
This year the containers devroom (where I spent most of my Sunday) did not suffer from such massive Kubernetes hype as it did last year. There were a lot of Canonical employees present (although also a lot Red Hat/CoreOS people), which in turn led to lot of talks that discussed features of LXD, which is another type of container runtime.
Compared to OpenShift, LXD is positioned to run whole operating systems as containers, in a very similar fashion as virtual machines are run. The main difference to VMs being that you cannot run arbitrary operating systems as containers (e.g. you cannot run Windows container on a Linux host), as containers share the kernel with the host.
While not particularly interesting to us as a technology, it is at times of course good to observe what the competitors of our technology partners are doing.
The closing keynote
The FOSDEM closing keynote was presented this year by Mr. Jon Masters, a Computer Architect at Red Hat. He has been working on mitigating the widely publicized Meltdown and Spectre bugs and held a very insightful presentation into modern processor architectures and the foundations to why bugs like Meltdown and Spectre are possible. For anyone interested in the low level details of how computers actually manage to get any computation done, it is highly recommended.