In short
The Changelog Podcast Episode Notes
Podcast Information
- Title: The Changelog: Software Development, Open Source
- Description: Software's best weekly news brief, deep technical interviews & talk show.
Episode Details
- Title: Setting Docker Hardened Images Free (Interview)
- Release Date: January 28, 2025
- Guest: Tushar Jain, EVP of Engineering at Docker
- Overview: This episode discusses Docker's launch of Hardened Images in May 2025 and their subsequent decision to make these images freely available and open source.
---
Key Topics Discussed
- Introduction to Docker Hardened Images (DHI)
- Launch Date: May 2025
- Function: A production-ready set of secure, minimal images designed to enhance supply chain security.
- Open Source Release: Made freely available in December 2025.
- Significance of Supply Chain Security
- Current Threats: Supply chain attacks have skyrocketed, causing $60 billion in damages in 2025, triple from 2021.
- Docker's Response: Decision to provide hardened images for free to enhance security for all developers.
- Understanding Docker Hardened Images
- Definition: Images that are minimal, low-to-no CVEs, and backed by an SLA.
- Benefits:
- Reduced vulnerabilities
- Faster patches
- Accessibility for all developers
- Core Components of Hardened Images
- S-BOM (Software Bill of Materials): A complete inventory of all components in a package.
- S-LSAs (Supply Chain Levels for Software Artifacts): Framework to ensure build integrity and security.
- VEX (Vulnerability Exploitability eXchange): Communicates the relevance of reported vulnerabilities to specific components.
- Security Features of DHI
- Build Pipeline: Moved away from traditional Dockerfiles to a more secure YAML syntax for building images.
- Transparency in Vulnerability Reporting: Docker’s approach to openly disclose vulnerabilities and their impact.
- Migration and Adoption
- Migration Process: Developers need to balance usability with security when switching to hardened images.
- Adoption Rates: Strong initial traction among developers and open-source projects, with ongoing interest.
- Future Directions
- Expansion Plans: Introducing new packages, enhancing security features, and looking into language-specific packages.
- Focus on AI and Agent Development: Developing secure environments for coding agents and simplifying the developer experience.
- Community and Ecosystem Involvement
- Partnerships: Collaborations with various tech companies and security firms to enhance Docker's capabilities.
- Open Source Philosophy: Aim to foster a community-oriented approach to security and software development.
---
Key Takeaways
- Security is Paramount: The transition to Docker Hardened Images represents a significant step towards making security foundational in software development.
- Developer Experience: Docker aims to facilitate a seamless transition for developers migrating to more secure environments.
- Long-term Vision: Docker's commitment to security and transparency is not just an operational strategy but a core ethos driving future developments.
Closing Thoughts Docker is reshaping its approach to security and software delivery with hardened images, establishing a new standard for developers. As the landscape evolves with the integration of AI, Docker's focus will be on ensuring trust and security across all stages of the software development lifecycle.
---
*These notes encapsulate the essential discussions from the podcast episode, highlighting the importance of security in software development and the proactive steps Docker is taking to safeguard developers and their projects.*
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOUnderstanding Docker Hardened Images
0:51 to 3:49
Discussion on the importance and implications of Docker's move to make Hardened Images free.
“This is the year we almost break the database.”
The Importance of Security in Software Development
3:49 to 8:02
Tushar Jan discusses supply chain attacks and the necessity for Docker Hardened Images.
“Every language, every ecosystem, every build stuff, they're a target because who does not use Docker?”
Building Secure Images: Concepts and Features
8:02 to 11:25
Explanation of SBOM, Salsa, and VEX, and their significance in security.
“If there's a CISO who cares about a bunch of stuff, that stuff is in the feature.”
Gains and Trade-offs of Using Docker Hardened Images
11:25 to 14:01
Insights on the benefits and potential challenges of switching to Docker Hardened Images.
“There's S-BOMS, there's Salsa, and there's VEX.”
Understanding Docker Hardened Images
14:01 to 16:44
Learn about the trade-offs between usability and security in Docker images.
“In production, in development, you want stuff.”
Customer Adoption Insights
16:44 to 19:20
Discover customer reception and adoption rates of Docker's hardened images.
“The barrier for them to go adopt and try it out and see the benefit is low.”
Timing of Product Announcements
19:20 to 21:44
Understand the implications of the timing of product announcements in tech.
“I mean, it must have been a head of engineering undertaking.”
The Ripple Effect of Security Changes
21:44 to 25:40
Explore the broader impact of security changes in the software industry.
“but something bothers me about GitHub Actions.”
The Journey to Docker Hardened Images
27:00 to 28:00
Get insights into the development timeline and transparency in Docker's offerings.
“And then, then it's like, is there a big enough business here?”
Understanding Supply Chain Responsibility
28:00 to 28:39
Discussing the importance of securing the software supply chain and its implications.
“And then on the speed, we built a bunch of stuff, but we get to leverage a lot of Docker underpinnings, right?”
Show all 32 chapters
Transparency in Vulnerability Reporting
28:40 to 30:30
Exploring the concept of VEX and how to communicate vulnerabilities transparently.
“Can you go deeper into this vex you've said a couple of times, vulnerability, exploitability, exchange?”
Docker's Approach to Supply Chain Security
30:31 to 32:58
Examining how Docker addresses supply chain security and its implications for the industry.
“It was just like never, as I can tell, like broadly adopted yet because like with scan as we're working through, some had it, some didn't.”
Long-Term Vision for Docker Hardened Images
32:59 to 34:53
Discussing the long-term strategy behind Docker Hardened Images and its benefits.
“that was needed here for us to go drive this and go do this.”
Expanding Security Measures in Docker
34:54 to 37:00
Future plans for expanding the security features of Docker images and packages.
“Like I got a home lab, I'm launching Docker on a daily.”
Detailed Features of Docker Hardened Images
37:01 to 39:28
Exploring the features and benefits of the newly released Docker Hardened Images.
“we've not addressed all of them but this is why this is not a one and done, we've got docker images that's good, no this is a pillar it's a pillar and now we're going to work on the pillar.”
Understanding Security Vulnerabilities
39:29 to 41:45
Analyzing the nature of vulnerabilities in Docker images and their implications.
“and then help you move towards that and manage that so I've been cruising your hardened images directory or catalog as you do and I've been looking at a few of these and it's very cool.”
Introduction to Scout Health Score
41:46 to 42:00
A discussion on the Scout Health Score and its role in assessing image security.
Introducing Docker Hardening with DHI
42:00 to 43:51
Learn about the health scoring system for Docker images and its security implications.
“Scout is our own scanner that we've had.”
The Importance of Containers in Software Development
43:51 to 45:00
Understand why containers are becoming the standard for application deployment.
“To not do it this way seems like that's just not right.”
Partner Ecosystem and Security Integration
45:00 to 47:36
Explore the collaborations with various tech partners and their role in enhancing security.
“At the end of the day, containers are a great way to bundle up software package it well, understand it, deploy it across systems.”
Partnership Dynamics and Collaboration
47:36 to 49:07
Discover how Docker collaborates with partners to enhance product offerings and security.
“Like you can't do broad impact without working with partners.”
Extracting Security Principles for Broader Applications
49:07 to 51:22
Learn about the principles and frameworks for securing software beyond Docker.
“And so it varies a lot where we are and what's needed as we work through it.”
The Vision for Secure Registries
51:22 to 53:14
Insight into the potential for a unified security standard across registries.
“But if I step back and think like, okay, how do you secure non-contained registries, et cetera?”
Future Directions for Docker's Security Initiatives
55:29 to 56:00
Explore the next steps in advancing Docker's security and package offerings.
“Let's talk about forward-looking things.”
Future Impact of Docker Hardened Images
56:00 to 57:28
Learn about the vision for Docker hardened images as a default standard.
“both leading your team but also just altruistic thinking about Docker and its trust level, what do you want to come from all this work?”
Creating a Movement Around Security
57:28 to 58:38
Explore the concept of creating a cultural shift in software security practices.
“The next popular open source package starts with just DHI because why wouldn't it?”
Adapting Docker for AI and Agents
58:38 to 1:02:13
Understand how Docker is evolving to support AI and the next generation of applications.
“I think it was the show Billions or something like that on NBC.”
Building Secure Runtime Environments
1:02:13 to 1:04:50
Delve into the creation of secure runtime environments for coding agents and untrusted workloads.
“and run isolated environments with containers.”
Integrating Security into the Development Cycle
1:04:50 to 1:10:00
Learn how Docker aims to integrate security throughout the software development life cycle.
“And I think like sort of, you know, what should the next, well, I want to say what should the next five years of the doc look like, but I'm talking AI.”
The Importance of Hardened Images in Security
1:10:00 to 1:12:09
Discover the role of hardened images in enhancing software security and deployment.
“And then we're just going to start doing stuff across the rest of the STLC too.”
Future of Software Development and Coding Agents
1:12:10 to 1:13:33
Explore the anticipated shift towards coding agents and their implications for engineering.
“If it's successful, and I'm confident it will be, then everyone who's, one, I think the entire engineering world, every engine's going to move to using coding agents.”
Navigating Change in the Software Landscape
1:13:34 to 1:15:06
Understand the rapid changes in software development and the opportunities they present.
“And it's, it's clear that everything from the bottom up is changing about how we develop software, how we deploy software, how we have to secure it, et cetera.”
Transcript
Automatic transcript. May contain errors.0:08Welcome, everyone. I'm Jared, and you are listening to The Change Log Log. where each week we interview the hackers, the leaders, and the innovators of the software world. In May of 2025, Docker launched Hardened Images, a secure, minimal, production-ready set of images. And in December, they made DHI freely available and open source to everyone who builds software. On this episode, we're joined by Tushar Jan, EVP of Engineering at Docker, to learn all about it. But first, a big thank you to our partners at Fly.io, the platform for devs who just want to ship, build fast, run any code fearlessly at Fly.io.
0:50Okay, Docker hardened images for all on the changelog. Let's do it.
1:02This is the year we almost break the database. Let me explain. Where do agents actually store their stuff? They've got vectors, relational data, conversational history, embeddings, and they're hammering the database at speeds that humans just never have done before. And most teams are duct taping together a Postgres instance, a vector database, maybe Elasticsearch for search. It's a mess. Our friends at Tiger Data looked at this and said, what if the database just understood agents? That's agentic Postgres. It's Postgres built specifically for AI agents, and it combines three things that usually require three separate systems.
1:45Native, model context protocol servers, MCP, hybrid search, and zero copy forks. The MCP integration is the clever bit. Your agents can actually talk directly to the database. They can query data, introspect schemas, execute SQL without you writing fragile glue code. the database essentially becomes a tool your agent can wield safely. Then there's hybrid search. TaggerData merges vector similarity search with good old keyword search into a SQL query. No separate vector database, no elastic search cluster, semantic and keyword search in one transaction. One engine. Okay, my favorite feature, the forks.
2:26Agents can spawn sub-second zero copy database clones for isolated testing. This is not a database they can destroy. It's a fork. It's a copy off of your main production database, if you so choose. We're talking a one terabyte database, fort, in under one second. Your agent can run destructive experiments in a sandbox without touching production, and you only pay for the data that actually changes. That's how Copy on Write works. All your agent data, vectors, relational tables, time series metrics, conversational history, lives in one querible engine. It's the elegant simplification that makes you wonder why we've been doing it the hard way for so long.
3:09So if you're building with AI agents and you're tired of managing a zoo of data systems, check out our friends at TigerData at TigerData.com. They've got a free trial and a CLI with an MCP server you can download to start experimenting right now. Again, TigerData.com.
3:48so friends we have supply chain attacks caused 60 billion dollars in damages in 2025 triple what they caused in 2021. Every language, every ecosystem, every build stuff, they're a target because who does not use Docker? And Docker's response was to make hardened container images free for everyone. We have head of engineering, Tushar, here today to dive deep into that and all the things that come from it. So welcome to the show, Tushar. Thank you. Excited to be here. And excited to talk about all that. Where do we begin in such a deep topic? I mean, You got vendors out there that had products around this.
4:26You got the desire to secure the supply chain. You have a brand to protect. You got developers to protect. You got bills to protect. You got a lot of responsibility. I mean, it's a big job you have, but where do we begin to unpack the reasoning and decision-making behind this choice? Yeah, maybe I can, let me just talk about how we think of supply chain, supply chain security and our current role in it, and then how that evolved to talk around images. and then eventually why we made it free and how we see that. What exactly is Docker-hardened images? We can explain that too. Perfect. So let's start at the beginning, before even that.
5:00I'm going to see everyone knows Docker and Docker Hub. Everyone builds containers, you use images. Docker Hub is effectively upstream for open source container images. We get billions and billions of polls per month. Everyone pulls from us. And these are the repositories or images of usable open source software. And not just upstream base images, but like, you know, I want MySQL on Debian. You get that from us, that works. Great, we've been doing this for a decade. But we basically keep up with upstream. As a result, images do have CVs. They've lost to CVs caused by multiple reasons. One, bloated stuff, bloated packages that are built for usability first.
5:40As a result, have many packages in them. Or just, you know, not patching fast enough. Hard-in images, and this is a concept that has started in the industry even before we launched a product, which is let's first minimize this problem. What people started doing was we left scanners in production. They'll see when there's a CV. We'll go alert some teams. They'll have to go update and patch. And this is sort of the world I lived in. Instead, why do we need all these images? Can we first minimize them? Let's get minimal packages that are only what we need. Second, can we have someone patch these faster?
6:13And then we drive that. So we'll release the burden on engineering teams. This is sort of the movement that started. it's very natural for Docker to do this. And so we launched Docker images as a paid product early last year. It's a hard-earned images, base images, app images that are minimal, low-to-no CVs, backed by an SLA by us. When we launched, we had a limited catalog and we've been aggressively growing that. Our vision was always, like Docker is like broad adoption, get tooling and content out to everyone. So vision was always, we need to make this accessible to everyone. And then for enterprises, we provide things enterprises care about, compliance, and we can cover what is an enterprise package.
6:53But for everyone out there, they should be able to get a great starting point and a secure starting point. So that was a vision always. We just had to build up to that. So that's what we got to last year and launched that out there. So this is a paid product for a bit there. And this is a big deal because you're letting revenue go by making this choice. Yes and no. So it was a paid product. What we did is basically launch a large catalog of, we've made our entire content, entire catalog available for free, nearly most of it. What's paid is stuff that enterprises would care about still. So what's free is like any developer, any project, like open source projects have been adopting this at scale.
7:30In fact, like NETAN is probably the largest open source project that's moved to this, which is what we want. We want everyone to have a secure starting point. But now if you want an SLA, like any place where there's a CISO, they want things. I want an SLA commitment behind the patching. I want FIPS images and stakes images. I want support and patching on images that are old, like outside LTS images. That kind of stuff is in our paid product. I want deeper, more scalable customizations. Those are in our paid product. So we still have a paid tier. And that's basically the add to it. If there's a CISO who cares about a bunch of stuff, that stuff is in the feature.
8:09Feature is for every developer, every company out there. Gotcha. So table stakes, it seems, is S-bombs, S-L-S-A. I didn't know there was an S-L-S-A out there, but there is. S-L-S-A, S-L-S-A, build level provenance. Yeah. And cryptographic signing. You're making those three things. Those things. Table stakes. Everyone gets an S-bomb, our build pipeline salsa is. Salsa. That's how you say it? Salsa? Salsa. That's how you say salsa. It's fun. There you go. I'm not going to trip over my acronym ability then and just do salsa. And so that is how we build these. So we have a salsa level three build pipeline.
8:44We actually open sourced our builder for this. What's been interesting is to do this, we had to change how we build images. It's still using like Docker build underneath the covers, but we moved away from Docker files to our own semantic layer, to our new which build these well. I can explain that. And then our build system. It's been interesting as we've done this, you know, supply chain security is a broad topic and secure content is one part of that. Securing your build system is another part of that. That's key. So it's been interesting we've done this now. Lots of companies are interested in our build pipeline.
9:16So that's the next thing we're looking at is exposing that as technology to everyone for so everyone can have secure build pipelines. And we'll keep going down this route of like how to basically see the supply chain is just critical. Not just for traditional container stuff, but we'll also see this with AI when we talk about that. You said you moved away from Dockerfile? Is that right? Concretely, I mean, it's still using the same technology on the covers, but just we built our own, we open-sourced this too. We built our own YAML syntax here just to make builds more repeatable. Like in Dockerfiles, you can shell out, you can do stuff, remove that.
9:50So in this syntax, it's very repeatable, it's reproducible. So you can actually do these in a way where you meet salsa requirements. it's still a build kit underneath the covers can you unpack briefly SBOM what that means why it's important and Salsa which is obviously how you say it Adam I mean come on I knew that the whole time did you know that the whole time Jared? no I did not I had no idea I also don't know the first time it was good to learn this is like a different version of an SLS at some point let's hope let's learn on the air here which we've been doing it for years so we're not easily embarrassed Go ahead.
10:27Let us know what it means now. So S-POM is simply software build materials. All it means is to be in a container package, there's a bit of many layers. How do you know what's in it? And then second, you want to know not just what's in it, but how is it built? Everything about how everything was built and signed. If you look at S-POM packages, you can say like, okay, here's not just a top layer image that's there and all the packages. Here's everything else that's in it. And we also, we sign it. we can capture aspects of the built environment, where it was built, various aspects of the node, et cetera.
11:00So there's a bunch of detail that's there. That's typically important for, or that's important for one provenance, you know where the thing came from. Two, later with this compromise, you can trace what's all impacted and you can manage that. So SBOMs are critical. And then with containers, they're complicated just because of all the layering that can happen. And so we manage all the transit dependency that will be full SBOM. And then many tools, you know, all the scanners can pull from that. and understand what's happening there. Gotcha. There's three things to explain here. There's S-BOMS, there's Salsa, and there's VEX.
11:31I'll cover VEX then second, actually. VEX then is, I'm going to get what it stands for wrong. I'm going to make it up and assume he's correct. Someone can correct me in the comments if I'm wrong. But it's like vulnerability exceptions, I think, which are, a lot of times you have CVEs that are reported, but if you look through it, the maintainers, where you're like, these don't actually apply. And so you can produce VEX statements. And that is also, you know, we stand behind that or upstream maintainer has it behind it. And then scanners can understand that and know like, okay, these things don't matter.
12:05So it reduces scanner noise. And what's good to do it this way, a lot of times what other people can do is like, in the S-BOM, they might obfuscate, or they have a CV fee that says, here are the CVs. Instead we say, here's everything, go pull it from anywhere else, and then we'll tell you which things we think don't matter and we're standing behind that. It's just much more open and transparent. And then Salsa stands for, it's an open standard, it stands for how you build a thing and you build an environment. And there's various levels. And Salsa 3 just means it's reproducible, it is not being tampered with, the build environment itself doesn't have access.
12:45It's a way to secure your build pipeline that we're standing behind. So you know, like, okay, nothing's being tampered with on the build pipeline itself. Gotcha. And so that's all a bunch of just maybe that's like, you know, to give an example, all the machinery that goes into doing this stuff. So stuff we're putting in the free, you know, we say we're giving revenue. I think of it as actually, no, like, look, our business model is very much, there's both the business model and ethos here. Ethos is very much get this out, the communication runner up with standards. And business model is sure we'll drive that stop funnel to a paid product.
13:17but as we do put a lot of effort and value that we give out into free, right? Docker Hub is free and we're giving the free tier for Docker on images. There's lots that just goes into that. Let's just say I'm a working developer with a couple of servers out there in the wild and they're all Dockerized. Maybe I got a Postgres server and my base image is like Debian or Alpine or something basic and then I apt-get install Postgres and my Docker file does all the things or whatever. what do I gain by switching to a Docker hardened image and what do I potentially lose? Or what might I hit up against when I try to do that?
13:55Yeah, so in terms of what you gain, so like two ways, we generally have two flavors of hard images, like a development image and a production image. In production, in development, you want stuff. Like you need a package manager, you need shell, you need debug, you know, all these things, right? You need the VZ debug. Cool, we'll give that to you, still minimal. Really, with them, we recommend a multi-stage build for your production images. You don't need that stuff necessarily, so minimize that. There are trade-offs here, primarily to do with usability and how you manage that. So first, the images you get from us, maybe you need a few more packages.
14:30We've customized build for that. You run that through a build pipeline, we'll add those in. Those are still hardened packages we're putting in, and you still get all of S-BOM, Salsa, VX, all that carries forward. But if you've just built a project and doing it, a lot of times, a lot of people, migration is really easy. Sometimes you've done stuff where I have to figure out what's my trade-off between usability and security and what am I managing there. And if I've built my system in a way where I can't put this up well or I really depend on shell access in production, then those are trade-offs I'm making.
15:07And so those are typically the challenges that a number of projects can run into. for the most part from a lot of our customers, we hear like the vast majority of their projects are able to migrate easily to this. We are also looking at building like an agent here to help do this. We've got initial versions of running internally. We use it internally and then we'll start building that up. How much can we help people with complex migrations here? Yeah, that'd be super useful. So what did adoption look like back in May? And then what's it look like since then? Is this something that everyone's just like, it's a no-brainer?
15:43Obviously, you might have some headaches, but they're worth it? Or are people more tentative? What's been the reception? Yeah, maybe just as I did first, we did a webinar, I want to say, a couple of weeks ago, something, I forget when, that was pretty broadly attended. I think my favorite question from that was, so is there any reason I shouldn't use Docker art images? Right. There really is like no one, like, no, you shouldn't. There's really no reason why you wouldn't want to just have a hardened image, you know? There's really no reason, right? This is part of the reason for opening this up, like you should go do this.
16:13So early on, we had lots of good traction with customers and working with all the enterprise deals. Since we've open sourced this, also to be fair, we open sourced it right before the break, like I think December 16th or something is when our, not open source, but the free tier, that's when our launch was. But even then we saw immediate interest and pickup. And so we're tracking open source packages, adopting this dramatically. Like I mentioned, it's gone to it. And then with customers, it's resonated. So like CISOs like it, head of platform like it, in part because, you know, we're seeing play out what we hoped, which is, okay, now someone on the team, typically someone has a mandate of like, oh, I should go.
16:52And people care about this problem. The barrier for them to go adopt and try it out and see the benefit is low. It's basically zero. They can just do it. And then they're like, okay, now I want all these, you know, additional security guarantees. Great. Now we can have a conversation about the paid tier. So we've seen an uptake for sure in this motion playing out where like, open source adoption, top of funnel with companies, and then we start working through this. You know, this is still one of those things I think people have to, it takes time to work through because like people have adopted, they have to care about security, they drive it, but starting to see this grow quite a bit.
17:33You mentioned releasing this announcement right before the break. Adam, didn't you have some feedback on that timing of this announcement. I think it was like, I think anybody would have feedback on that timing. I mean, come on now. Yes, the worst time ever. So I'll say something. It's the worst timing ever. Just because right before the break, I don't know. I feel like holidays actually now, like when all AI products get released, it's like the moment to release all the things anyway. Right. Everyone's at home tinkering. They're like, we got to get our product out there for people to tinker it with it.
18:05Yeah. Yeah. I didn't know it was December. That's for sure. Right. Yeah. I was like, I don't care what month it is. I'm here and I'm innovating. You better follow me or be left behind. I suppose there's no really bad time. It's just that whenever you want to get good fanfare, now you're playing a month-long launch plan versus a single day with a great precipice and a lot of attraction. Now it's just, I think you just made it hard on yourself, basically. Yeah, it's fair enough. We'll take that. I want to say part of it was just like, let's just do it and get it out versus come back and let's just go right that being said though i mean there's no good time like secure today you know like security i would i would rather use secure today than tomorrow yeah in every case because don't delay security i think uh you know just timing is is not the best because we couldn't do the show in december we were we were away we were taking our breaks are we talking about it now but here we are to some or december january 28th talking about it Super important, though.
19:06I mean, I think, you know, the one thing that I'm reading here is obviously that, you know, when you make a change, when Docker makes a change, when you change the default, it's a ripple effect throughout the industry. Yes. And I think about, one, the effect of that ripple, and then two, creating that ripple. My gosh, behind the scenes, what kind of thinking, what kind of specifications, what kind of planning, how do you architect this new vision, this new build pipeline from build kit to all the free artifacts that are given away for free, and then re-changing how you productize it to create revenue as a company?
19:42I mean, it must have been a head of engineering undertaking. You know what I mean? It's a whole company effort. Honestly, my job is the easiest in all of this. I mostly say, hey, we should do this. We should do this. Let me know when it's finished, guys. And then, you know, look, Docker's got great talent. And so people rally and do stuff. In this case, like this is always part of the thing we wanted to go do and drive it. But then, yes, there's lots of stuff to go figure out. starting first and foremost with don't put stuff out there. It's true for everything, but if you're going to make a big product we have the quality, the underpinnings of this technical security have to be stellar.
20:24We simply cannot do it if you don't do that. In part because not from a brand damage on the color side, like that too, but first, we are the source of supply chain. People will take what we put out there and yes, we'll get if you do something bad, so we'll find out, we'll figure it out. But really, it's a responsibility of whatever we're doing is going out there. So we have to deeply, deeply care about that. And so that comes from just the team that's on this and the experts we have on this and going deep here. We've got decades in these areas, and they've got a bunch of strong people here working on it.
21:00And then there is a product and strategy and all that we work through, like, okay, how do I actually get this out? Manage community, manage customers through this. and work through all of that. So yeah, this is definitely a whole company effort for us to go take on. And it's the start of what we're doing. This is just a start, right? Like the vision is secure your entire supply chain. For those Java, it's like void main down. Like we want to address everything. Make it to packages, get your build pipeline, secure your entire supply chain as we can. Get policies out, because we sit everywhere in SDLC, from laptop to CI, production to registries, content rest.
21:39Let's try to get the point where we can secure all of it. Well, friends, I don't know about you, but something bothers me about GitHub Actions. I love the fact that it's there. I love the fact that it's so ubiquitous. I love the fact that agents that do my coding for me believe that my CI, CD workflow begins with drafting TOML files for GitHub Actions. That's great. It's all great. Until, yes, until your builds start moving like molasses. GitHub Actions is slow. It's just the way it is. That's how it works. I'm sorry, but I'm not sorry because our friends at namespace, they fix that. Yes, we use namespace.so to do all of our builds so much faster.
22:22Namespace is like GitHub actions, but faster. I mean like way faster. It caches everything smartly. It caches your dependencies, your Docker layers, your build artifacts. So your CI can run super fast. You get shorter feedback loops, happy developers because we love our time, and you get fewer, I'll be back after this coffee and my build finishes. So that's not cool. The best part is it's drop-in. It works right alongside your existing GitHub actions with almost zero config. It's a one-line change. So you can speed up your builds, you can delight your team, and you can finally stop pretending that build time is focus time.
23:02It's not. Learn more, go to namespace.so that's namespace.so just like it sounds like it said go there check them out we use them we love them and you should too namespace.so can you estimate the time to shipping from the point where the phrase docker hardened images was like a wipe on a whiteboard somewhere or in a product roadmap, like we're going to do this someday to the deciding we're going to do it now. And then from that point till either December 16th or May, when you actually shipped the original. Let's see, I'll, I'll try to, I'll jog my memory. So I think what I'll say is, um, uh, so when you see a joint, uh, Don, Don, and I would say, uh, I think Feb of last year, that's when the site is rolling around and before seems like, yep, we're going to do this.
23:58We're going to launch it. so I think from that point people with skill set but formed a team at that point early Feb, mid Feb, something like that and we got it out into limited release in I want to say three months within the next three months so that got us to summer then we kept growing, growing, growing and then I think the real, we knew we wanted to make it free, we weren't sure when but I think the real thing was like, oh, we should work towards free December, I want to say it was like honestly, it was like maybe early November, mid-November was like, okay, we're doing this or like right around, yeah, it was close to Thanksgiving is what it was called, somewhere around there.
24:48And so from then till there was like a probably like a four week sprint. That's all pretty good. It's all pretty impressive. You said you have a good team there. I mean, I was expecting longer. So I guess congrats to you and the team for really a pretty quick turnaround. Yeah, well, I think in this day and age, you don't have time. Everything. You don't have time. Yeah, you better get it done yesterday. You better get everything done yesterday. Because also, there's so many containers, but this mode of working is critical for us, for everything we're doing. And when we cover AI, we'll talk about that.
Read the full transcript
25:22It's in that space in particular. The timeline I just said in the air world has to shrink 10x. So this muscle is in general as an agency organization critical for us. This part of the conversation talks about the time. Eight months is what I roughly kind of captured there to go from Docker hardened images to GA to let's make it free. Let's release it and it's released. But the tension behind it has to go back beyond that. Because one thing that was mentioned in the announcement post was, I'm going to quote this, it says, and while some vendors suppress CVEs in their feed to maintain a green scanner, Docker is always transparent.
26:02So there's this, it seems like if I'm reading this correctly, you got Docker, which is, you know, the supply chain essentially of images, Docker Hub and the trust factor. and you've got vendors out there who have been doing versions of this seemingly not being fully transparent making their builds green when they're actually not green can you speak to not just the cycle to get here but the tension that rose to say we've got to take this on we've got to make this a the way this this default standard that you've made it can you speak to attention and what it took to sort of, uh, own the responsibility.
26:44Yeah, absolutely. So, you know, this, these ideas go way back, right? Can go to when like Google digital started. Right. And so like, most of the ideas go back. And so discussion has been there, like, what else should we do here? What to build or how to manage this? I think there's been lots of like in the past, uh, discussion of how, how should we do this? And then, then it's like, is there a big enough business here? Should we go after this? How do we think about this versus what else we're doing across the company, et cetera? So this discussion has definitely been there for some time. And what's the best way to do it?
27:19I think a few things came together for us in Feb. One, we should change clarity of, yeah, we're doing this stuff, we're going to do it. Second, I'd say on the technical side, clear clarity on how we should do this. The serpents were like, we're going to do this differently, and here's how. Even concretely, VEX statements are a thing the industry is adopting now, and we're helping driving that. We've broken all the scanners of like, this is why you should adopt it. It's a standard, but there's no universal adoption of here. And we're driving that forward and making that happen. So I'd say the tension is definitely there.
27:49But before that, I've been a year and a half. I'd say even before my time, it's been there. It's one of those topics that's been in the industry for a while. And then the real thing was like, no, we should do this. And that was both business clarity and second, I'd say, technical clarity on how to do this. And then on the speed, we built a bunch of stuff, but we get to leverage a lot of Docker underpinnings, right? We've got Pilkit here, we've got Docker Engine here, we've got Hub here. We get to leverage all of that for how we get to go drive this and make it happen. Yeah, I think the core part is just realizing this will come from like, we are a core part of the supply chain.
28:27And so we have to start not just the kind of stuff we do, but take on the broad responsibility of how to secure the supply chain. that's both a business opportunity, but it's also almost like a responsibility, right? Given our position where we are. Can you go deeper into this vex you've said a couple of times, vulnerability, exploitability, exchange? It seems like, and I'm not steep deep in this. I'm learning. I'm pulling back the Google results on this stuff. Yes, I still Google here and there because it's just easier sometimes. It seems like this is a way to be transparent, a software supplier to be transparent about particular areas where you're still vulnerable, but you're able to do so, it seems like, in a community mindset where, hey, we've got this thing, we're delivering it, it's not fully green.
29:13And these are the areas where it's not green. Can you speak to the behind the scenes of what that exchange actually is? Yeah, so the way I actually use it is, you can have packages. So typically, if you're a distro, you have packages, and then you have your own CV field. like, hey, we will tell you what are the CVEs here. And that's when we need to control it. You have this root issue of like, well, there are CVEs, but like, you know, there's CVEs in the national database, but they're not actually an exploitable CVE. We don't think it's actually exploitable in our code base or the way this works.
29:49So if you publish your own CVE feed, you can just not publish it. And that's when we do it. We take a different approach where we publish fully transparent SPOM. Scanners can take that and they pull the central CVE feed and they see the CVs. Then we publish the VEX feed that says, okay, here's the ones that we don't think matter. In the other approach, you're missing that transparency and that logic of like, oh, here's everything, here's what we think doesn't matter, and here's why. And which is a better approach, because then we can talk about it, right? And we can see whether you agree or don't agree with us.
30:22Also, for CISOs on the right, for anyone else, it's very clear what's happening. So that's the sort of thing we're doing, the approach we're taking here. Now, this has been a standard for some time. It was just like never, as I can tell, like broadly adopted yet because like with scan as we're working through, some had it, some didn't. And now we're working with all of them and they're all getting it in there. And what it seems like is it's a focus on what is exploitable versus the things that are not. So you still have, let's just say security concerns, but these are the ones that we should pay attention to.
30:52These are the ones that are actually worth paying attention to and actually cause real harm or damage. It's both. we put everything in there it's just a way to annotate stuff so we put everything in there like here's the ones that we think aren't and what's coming but then also explicitly which ones are not exploitable we put that in there too so we cover all of that in there. What about this tension? Can you go maybe one layer deeper in terms of who has been the supplier so you got Docker then you got third parties not so much by name necessarily but like what are their roles in the supply chain and why has this moved to a free tier with these kind of table stakes requirements been a great move compared to the prior you know the prior way sure so maybe we think uh maybe the way i'll talk about this is so yes i think like you know Docker Hub has been, I'd say, easily the biggest main registry for open-source container images.
31:55There have been other companies that have come up that are selling hardened container images, right? So that's been a model. There are other business models that companies have come up and started doing. So then the question for us was like, well, one is very natural for us to do that, so we should look at doing that. And it's a thing we've discussed and not done explicitly. So that's a very natural thing for us to go do. I think the tension talking more just like Docker Hub could have remained just the open source usability first place, or really it's like, no, Docker should take on supply chain security all up.
32:36And I think that was the sort of change in our product and business thinking. is if you look at our product strategy pillars, supply chain security should be a core part of it because we are a core part of supply chain, not just for images, but also where our Docker engine is. It runs everywhere. And so we should take those two things and drive supply chain security everywhere. And so that was, I think, the sort of mental framing change that was needed here for us to go drive this and go do this. And now the other thing for us from making this phrase is two parts. One, it's a general approach of broad-conference adoption and then drive, use that as a funnel.
33:15But maybe second is like, you know, we have a holistic platform and supply chain security and secure content is one part of that. So that's why for us, maybe there's some amount of, you know, revenue impacted, but I don't actually think so because for anyone who needs compliance guarantees, there's a paid tier for everyone else's broad adoption. but this is a, this is one pillar of our business, not the entire business, right? So that lets us go do things where we get broad adoption for the community. Seems like very much a long-term play. Like this is not a short game play. This is a long game play.
33:48And, you know, Jerry, we just, we're about to release this episode. I think it might be out. I don't know if it's out or not. I don't know. About securing NPM. This reminds me a lot like that. I'm wondering to start a few, if while you were in this tension period with the ecosystem and realized the responsibility, and then in this announcement back in February internally, hey, let's do Docker hardened images. Let's actually put the effort here. Let's do all the research. Let's figure out what we have to tie together. And let's make a concerted plan to execute. How did you look at the rest of the world in developer land to say, where are the supply chain attacks happening?
34:24And what are their issues? Because there seems like a responsibility you've taken on. and just put it bluntly, GitHub is not with NPM, at least based on our current examination of the situation, you've taken the responsibility and made a concerted effort and launched it in eight months. And you've done it regardless of maybe here in this conversation, regardless of potential revenue loss. I think it's a long-term play and you're adding trust to the layer and security to the layer, which is good for your brand long-term and good for Docker and me. Like I got a home lab, I'm launching Docker on a daily.
34:57You know, I want that to be trusted and secured. How did you look at the rest of the world when it comes to supply chain attacks or supply chain security? Was NPM one of the examination targets for you? Yeah. So a number of software to unpack there. Absolutely. One thing before I do that, just a revenue topic first. I actually think of this as a revenue accelerant for us, to be very clear, right? Like, I actually think this is a revenue accelerant. We're having this conversation because we launched Docker Arms for free. All the listeners listen to it. Hopefully, many people can go use it. And within companies, they'll want the stuff the CISOs want, and that should hopefully lead to them calling us.
35:33So the reach, basically, our reach should expand here. So I view this as a revenue excellent for us, and we're starting to see that play out. Just in the revenue front. On the other part, you're absolutely right. Look, I can't tell if supply chain security attacks have actually gone up or we just talk about them more. But there is definitely a marked increase here, right? The NPM stuff, but the Shai Haloo attack that just happened. side note, I love that name. I just watched the show and then I was like, ah, now I know. So we absolutely saw that and see this happening broadly. And when we look at that, this is what I was saying, this is the start.
36:10We have right now with Docker and images, we've started securing a critical part of your supply chain. There's a lot more to do. There's a lot more that's in your supply chain. There's packages, there's runtime. And so our ambition is to get through all of it and start looking at it all. Mostly because it's just the tax increasing and supply chain attacks are the ones that have massive impact, right? They just ripple out. And so you see as a critical a business need and a need needed for like software across the world. And then it's also just critical foundation needed. I think if you're going to live in a world where AI agents are writing more software, like if you don't have secure foundations, that life's just going to get way, way worse.
36:51and so as we look at our AI play too we think secure contents and supply chain security is a critical pillar for that too so that was absolutely all of these things and to be clear we've not addressed all of them but this is why this is not a one and done, we've got docker images that's good, no this is a pillar it's a pillar and now we're going to work on the pillar. So one thing we didn't cover was the breadth of the announcement of what was happening here so if I understand correctly and correctly might be wrong is over 1 ,000 hardened images and Helm charts are now available. That's a lot.
37:24You're building on Alpine and Debian. These are familiar. These are trusted foundations people are building on. And it's obviously being announced as open source under the Apache 2 license. So DHI is now free under Apache 2. That's the current state of affairs. Where do we go from here? Like what is in that 1 ,000 hardened images in those Helm charts? What is not there currently? What needs to be there? If now is the flag moment, where else are you going to go from milestones? Yeah, so a number of things. One, we're going to roll out hard and system packages. Also, today, a lot of system packages that you want come from upstream repos.
38:05We're going to start offering our own hard and system packages. But from source, we'll patch ahead where and when needed. So we started doing that, and that'll come out. We're also going to look at language packages. We'll attack that language by language. We'll go into that and get those out. On the enterprise side, we'll look at long-term support. Typically, packages have LTS. After two years, you stop getting patches from upstream or three years, you can buy long-term support from us. So we can continue patching. And typically, enterprises, for various reasons, they move slower. And so that's important there.
38:43So we expand the way to think about this is like expand the breadth and coverage of all the things, of all the content you care about. Let's get that out. The next thing after that for us, I think, is a secure build pipeline. This is not another thing we're trying to look at. Duke is seeing all the interest here. And so we have to figure out how exactly we'll do that. We want to get this out so anyone who's building software should run on us and get the benefits of a SaaS-3 build pipeline and work on getting that out from there. and then I'd say last thing and this is like a part of this we started is I really want to get some agents out here that help you with either migration or help you with understanding your state of affairs and get you how to get them secure basically everything we can do to have the foundation to make it secure and then help you move towards that and manage that so I've been cruising your hardened images directory or catalog as you do and I've been looking at a few of these and it's very cool.
39:43I have some questions around like the security summary. So I'm looking at the PHP image based on Debian 13, 92 packages. So that's pretty slim. Seven tools included if you're in on the PHP image. And it has one medium severity vulnerability, 10 low severity vulnerabilities, six unspecified severity vulnerabilities. I assume those are upstream vulnerabilities that you know about because you're not doing hard in packages. Like those things are just like you're patched up as far as you can go, but there's just known vulnerabilities. Is that what those mean? Good question. So the lows and unknowns, this is my step, but the medium one, I'd be very curious.
40:25I'm going to go look at it afterwards. Typically those will, if there's any high, we work with upstream or we'd go ahead and do it. Medium should fall in that category too. I think for us where like it should be something we go after soon. And so I'll look at that one afterwards, but generally high critical, of course, and even mediums, we try to get ahead and drive quickly. So when you have like, say there's this medium here and we don't know what it is. I can't seem to find if it lists what that is somewhere. I think that'd be a pretty cool addition. It should be. If it isn't yet, it'd be a good addition.
40:56Yeah, that'd be a sweet addition. I do see a full security details and it still shows the vulnerabilities list, but I can't seem to find it at the moment. Anyways, is that then, is that a known CVE against a package, against one of these 92 things that have been installed? But that doesn't necessarily mean that there is a patch, or is there a patch that just hasn't been applied? If there was a patch, we apply it really fast, like ours. Likely there's not a patch, or in an unlikely case, yeah, like there's not a patch. But even then, we typically try to go work at it and get a patch in place. that's what we do for high so the medium it depends a lot where we are on that yeah i mean yeah lots of packages yeah lots of images it's probably a uh an ever a never-ending task is just to continuously be yeah so there's behind this there's there's a machine running right uh of totally software and people so then the other question i have about is this scout health score which maybe it's not it's new to me is that new in general or just new to me scout should be something we've had for some time.
42:02Scout is our own scanner that we've had. And it's our own scanner that scans everything. And now we've just put it in here. So you can see the health score that's there. We've given it, you know, in Hub, package owners can see the health score for their packages that they're publishing. And now here we've done it. So anyone can see the health score of packages we're publishing here with the DHI. Yeah, that's super cool. So this one has an A score and it has all the reasons, like no high profile vulnerability, no fixable critical or high vulnerabilities, signed supply chain attestations, no embedded secrets, no embedded malware, like on and on and on.
42:38And I assume there's a score for every image you all have on here. There should be a score for every image and there should not be any score that's lower than an A. And if there is, I will follow up on that. Well, if we have a, let's see, filter my scout score and just say, show me the ones that are B's or lower and then, you know, get to work. You mentioned, actually, you mentioned one thing there, which is like no unbearable secrets, et cetera. So that's another thing where it's not just about reducing the package playing CVs. We go through actually like, you know, a list of stuff like what makes the thing secure and ensure that it's there.
43:10Like there's no credentials in there, none of this stuff. And keep in mind, we're getting lots of patches from upstream all the time. And we scan every single one of them. So there's a mixture of AI running here and people to make sure what's happening here is secure. It's cool stuff. It seems like a good step forward for everybody. it's honestly like for me it's been um i'm inside the house so it's you know biasing to say but like seeing the team here just run this and define this and have very strong opinions of how to approach this one and do it it's been um uh it's been really fascinating privilege to do that right as i've come in here and see everyone who works at this space and do it uh because there's a lot of depth in here as you've done this uh so i'm excited now and a patient to like do all the stuff this part of a vision in this space and build this out uh and i'm hoping if anyone listening you should go try dhi there's no reason yeah it's too easy not to or too easy to i guess yeah too easy to and no reason not to i like this is a better way to say it there you go so this makes me feel like uh containers are the way even more so now they've already been the way for so long and this has been the docker story arc since you know solomon to now essentially is that it took the world by storm uh we now have the containerized way to do things deploying applications become easier than ever and you know if there was any scrutiny on how that plays out well now that you've made this security mindset a first-class citizen in the way you deliver which seems like the obvious way to do things.
44:46To not do it this way seems like that's just not right. Containers are the way. Would you agree with that? I think containers are the way. In general, I don't think containers are going anywhere even as application paradigms are changing. At the end of the day, containers are a great way to bundle up software package it well, understand it, deploy it across systems. 1 ,000%. Can you speak to the ecosystem and the partners? So external, Google, Mongo, the CNCF, Sneak, Jfrog, a lot of the players in this space, CircleCI, Socket even. We have friends at Socket. Can you speak to partner level involvement in orchestrating all the things, I guess?
45:31Yeah, there's a ton of partner involvement, right? And like various kinds. So there's scanners. So like Wiz is, for example, we work with them to do great stuff here. all the various scanners. So there's a bunch of scanners that have to integrate with us, so drive that. There are CSPs where they pull images from us and understand that, so working with them. There's also interesting things we can do with them over time and figure out various, you know, they have trust centers, so have them integrate with us too, right? So all of their, effectively their own scanners and their own registry caches have them integrate with this, so we do that.
46:06Then there are other players in the sort of, I would say, a supply chain or a security space, right? So Socket is interesting. We actually have a partnership with Socket that I think we announced where you can get images from us and we'll integrate Socket. And so you can get Socket firewall and get their benefit over, I believe it's PyPy or NPM. I forget which one they're on now. I think NPM. And so there's a number of, like the ecosystem, like Docker is in general, All the DevTools has lots of players in it, and the Docker is just like such a core part of the Nexus. So we have lots of players who integrate players to do this.
46:46So when we do this, we have a key arm that goes around drives various partnerships. We have strong relationships with many people here. With Microsoft, actually, when we did LA, the limited release, I was at MS Build last year when you were there, too. That's where we announced it, and we had early integration with Microsoft for this, where they would take Docker images, but if you'll deploy them and keep up with updates and get those deployed to their pipeline and to their scanners. And so there's a number of these kinds of integration we're doing everywhere. And the way maybe to think about this is if you want to go drive broad change and impact, us launching is critical, but we have to go do it through all the various, the key sort of, you know, systems and players in this space.
47:36Like you can't do broad impact without working with partners. What is that like? Do you have to, if I'm one of these partners, do I get early access to documentation? Do I get early access to maybe an embedded engineer that's, you know, works for Docker, but actually works for me because they're inside my organization, helping me better understand and organize the way we work around securing Docker or working in orchestration, orchestration as a partner. How does that play out when it's actually boots on the ground, people getting commingled? How does that work? It varies based on the state of the partner state of where we are.
48:11So for example, when we started early with Microsoft, we were just getting started. In that case, we had PMs and engineers connected. Generally, everyone would end up on a joint Slack channel or something. And then we're deeply connected. And in that case, we were doing some co-build and it's very early. So they're getting early access from us and we're working together. When you're at a later stage, then you just have connections with partnerships and product people generally, and then you drive that forward, right? So depending on where we are, we do this. But maybe the approach and the philosophy here very much is succeeding in partnerships is not the job of a partnership department.
48:49It's a job of our company with everyone, right? So we figure out what's needed and drive that. That's the general approach for everything, right? These aren't, yes, our departments are focused and stuff, but we have to operate as one. And so depending on what's needed, we'll have engineers plugged in, we'll have essays plugged in, whatever's needed to manage this and do this as we work with everyone around it. And so it varies a lot where we are and what's needed as we work through it. But it ends up becoming a cross-functional team effort by default. Is there a framework or a specification or a substrate that can be borrowed or extracted from all the work you've done, your team has done for the last eight or nine months accomplishing this mission?
49:36I'm just thinking like if we want NPM or any other registry out there to have similar characteristics or similar concerns around security, is there a substrate here that can be extracted that says this is the way we secure registries across the board? Because we look down the line, you've got the idea that you've mentioned hardened MCP servers, for example. This is a versioning thing around AI. How can we secure AI? Then you've got things like maybe hardened libraries or system package. I'm thinking like apt or anytime you install anything, like, is there an extractable thing here from this effort that, uh, that you can lead or provide a spec to?
50:17That's a, that's a good question. So again, the first thing that comes to my mind is actually, I think the first thing is like at least extracting like the principles and the like, uh, end goals, right? Being very clear about that. Like we have some core principles that we applied. and I say that because the hows might differ depending on the domain of what's needed. Yeah, for sure. And so then the second one, what can you extract at a technical level to that? I am not sure. I'm sure there's stuff here, but especially if I think about stuff outside container images land, then it's interesting and a little different, but the principles definitely do and the approach does in terms of common things that you can pull out there.
50:56I think there are things here, For example, the way we're building, yes, we made it for images and containers, but I suspect that if you sit down and look at it, core parts of that stuff, we can pull out and make it work for non-container stuff too, maybe. I'm winging it a bit here when I say that. But there's core parts of how do you do a build pipeline that should apply, I think, a little more generally too, as an example. There are parts of maybe some of the AI agents we're running that can apply more broadly than just for, because they run at the code level to verify security of all the thousands of upstream PRs, patches we're getting, right?
51:37So there might be stuff like that. But if I step back and think like, okay, how do you secure non-contained registries, et cetera? First thing that comes to mind very much is like, let's extract the code principles and then we can see what components are acceptable. Yeah. Do you have that in like a manifesto? and if not can you can you give it to me yeah as i was saying this i'm like i think i teed up the next question yeah i really i really want that i mean i really do i think yeah because i even think about like i want i want your your what and your why and i kind of want a little bit of your how but not all of your how because my how is going to be a little bit different based exactly my context right i want to know your what and your why and how you think about the problem because I want, that's the, that's the intellect.
52:23That's the intelligence. My how is going to be different if I run, you know, a different kind of registry that is not at all images or container images or around the things you care about. It's going to be a way different thing. So don't tell me the how, give me the what and why. Yeah, yeah, yeah, yeah. Yeah, absolutely. That's actually great. And then also, you know, riffing a bit here, even though the how's different, you can imagine if you do that, you still produce maybe like this, maybe another opportunity. It's good to give me some ideas here. Maybe the opportunity to work with CNC for someone of producing a spec of like, once you've done it, like, you know, what's an S-bomb?
52:56It's a signed artifact saying, hey, here's what I've done. Here's what's there that someone can take and understand and then be like, OK, cool, this passes the bar. So, you know, if you can agree in the Watson house and cool, someone else do that and produce a result, an artifact that captures all of that. and then just depending on what you're doing, you can still like have a central, a central like, you know, reviewer or grader or something across stuff. So it's not limited to just containers, but like expand more broadly. There's something interesting here. You can also do this for like runtime security, for example, I think.
53:32Cool. All right, Adam, I think you gave me, you gave me an action item here. All right. Go right down. I'm trying to do that. What's a podcast? I mean, I want it seriously. So the moment you release it, email me personally, if you don't mind, because I'm going to read it right away. Done.
53:53So here's the thing about network security for enterprise. It's usually a six month project involving hardware, consultants, and at least one person whose entire job is managing the VPN. NorLair looked at that solution and said, what if we could do that in 10 minutes? What is NorLair? It's a toggle-ready network security platform built for businesses, VPN, access control, threat protection, all this stuff, all in one place. No hardware requirements. It's built on zero-trust principles, which means only the right people access, the right resources, verified every time. And it's powered by NordLynx, their VPN protocol that's built on WireGuard, so it's actually fast.
54:32For IT admins, this is good stuff. grandly control over who accesses what, from where, on which device, built-in threat detection, scan provisioning for automated onboarding and offboarding, deploy minutes, and scale in clicks. They've also partnered with CrowdStrike to bring Falcon endpoint protection to small and mid-sized businesses so you get enterprise-grade, multi-layered security without needing an enterprise-sized IT team to run it. Here's an exclusive offer for you, friends, up to 22 % off NordLayer yearly plans, plus 10 % on top of the coupon code changelog-10-NordLayer. Try it risk-free for a 14-day money-back guarantee at nordlayer.com slash the changelog.
55:14Once again, nordlayer.com slash the changelog and use the coupon code changelog-10-NordLayer for the 22 % off NordLayer yearly plans, plus 10 % on top if you use that code. Enjoy.
55:32Let's talk about forward-looking things. We're here in January, just the tail end of January, going into February. You've done all this work. It's released. It's out there. We've got table stakes, hardened security out there for Docker images. What is next? You've got great partners in place. You talked about how you integrate with them, how you work with them, how you involve them. and you have hopes for new trusts to be built on in the community. What is, in your mind, as head of engineering, both leading your team but also just altruistic thinking about Docker and its trust level, what do you want to come from all this work?
56:07There's a lot here. So in terms of what's next and how to think about the impact, that would be great to get here. So first, on the current stuff, like I said, we should do a lot more, right? We've got to keep adding packages, expand the ecosystem of stuff we cover a lot more, get into system packages, get into language packages, build stuff for the enterprise layer. We need to get our secure policies, like the ability to define policy and enforce it across your entire tool chain. So we're working on that, trying to get secure builds. There's a deeper map here for us to go work on and drive. But maybe to your point, what's the impact we want here?
56:46One, I'd love to see this be the default starting point. Right. Like what is needed to get in the place when I'm building something new? Why not start with Docker hard images and what all is needed to achieve that? And I expect it's a mixture of technical and non-technical things that are needed there. Like one, it's like, you know, for someone who is starting, like where do they learn how to start? How do we make this be the default easy path? For a lot of people, it's like, I'll just, I'll copy what someone else did. Or I'll just do whatever ChatChapD tells me to do. So how do we go influence all these places and let this be the starting point for everyone?
57:23Because that should be a key thing if I jump forward in years in the future. Great. The next popular open source package starts with just DHI because why wouldn't it? That's the thing you do. And so if you go achieve that. And the reason that matters to us, apart from the electric goal or just the real goal of make software secure, on the business side, that then very clearly leads to enterprises They get to buy enterprise level security from us. Yeah, just worry a little less. One less worry for a CISO or one less worry for a head of engineering to think, gosh, our supply chain needs to be secured.
58:01Somebody should do something about that. Let's just trash the engineers, right? Shift left more, okay? Just put more on developers. Right. Even more. That's one way you could go. Yeah. Yeah. Well, it's very much, you know, just start, start green, start green, stay green. Oh, I like that. Start green, stay green. Yeah. There you go. You should tagline that. You should put that on the website or something. If you haven't done it yet, t-shirt that, okay? There you go. That's how you create defaults, right? You create a movement. Yeah. Do you see that kind of a tangent? I don't know. I'm going to riff a little bit.
58:39Do you see that? I think it was the show Billions or something like that on NBC. I don't even know. I didn't watch the show but i saw the clip where he was talking about lemons do you see this clip ever i don't i've seen the show i don't recall this clip well there's a known term out there you you know when life gives you lemons you make lemonade he's like no no that's not what you do and i'm gonna just paraphrase because i forget but he went into this massive just like deep dive now you don't make lemonade you make lemons scarce and he went through this whole story arc of how you make lemons the default and you you make it a tagline that's uh that's not cool that's lemong you know you kind of give it this cachet of sorts, you know, I think if you do something like that, you create a movement, you create a change.
59:21That's how you create a, you start green, you stay green and you make that the, the maneuver. And it's essentially you make it not cool. Yeah. It's the ultimate nerd snipe. It's the inevitable. Like this is the way and the longer you take to get there, the further behind you are. Yeah. 1000%. Yeah. And so if you go do that and then also, I don't know. I do a video of figure out to make this be the thing that like is the default thing that like every agent recommends and starts because that's just how I was writing the code now anyway. So. Yeah. Agent recommends is still a black box, I guess, in a way, right?
59:58Yes. And you can rag it, but that's just from the side. It's not from the bottom. It's not from the bottom up. Figuring that out. What's left? I know we covered a lot. I know you have a big role there. I know that there's a lot happening around Docker in general. I mean, this is a big announcement. there's AI things happening. What is your stance on things in that area around the Docker world? That's, you know, so we've done all this but like the AI stuff is clearly a big focus for us and it sort of comes together in my mind. Maybe we'll talk about how we think about it. It's like, you know, how I think about this a bit.
1:00:32So look, Docker, you know, everyone uses it. It's a core part of the CLC. We help code go from laptop to production and we kind of solve for like, you know, the big growth of apps that happened over the last decade, cloud-native apps. Everyone moved to the cloud, everyone built services, containers are a way to do that and drive that. We solve all that with our packaging, with the content distribution, with the engine for building and running. Well, there's two big shifts happening now. Everyone is, the entire SDLC is changing. You're developing coding agents, but literally the entire SDLC, how you build, test, publish, run code, is going to change and become AI first.
1:01:10And second, the kinds of applications you're writing are going to be agents now, the next growth of apps are agents. So I kind of see a very natural thing for us is like, you know, I think of Docker as our job is to help engineers and engineering team securely build and deliver software. And so we've done that over the last decade for the way things have worked. And now we're adapting that for AI. A core thing for us that we've had with Docker and docker images and even security trust we talked about, but even more important with AI and agents, I think is trust. The thing is, if you're going to trust across this layer here for agents, that'll help people trust agents more.
1:01:49Basically, today everyone's writing 10x the code, but no one's shipping 10x the code. In large part, because there's not code trust yet. Even when I've used an agent, how to let it run unfettered. Do I trust all this output? How to test all of this? How to get this out? How to know what it's building with? So that's sort of a framework we have. and we're starting with the runtime environment. So we've got Docker, Docker Engine. This is how you build and package and run isolated environments with containers. Well, now we've got a slightly different thing with agents. So with coding agents, we think, I frankly think it's crazy.
1:02:24Everyone runs coding agents, flatten the machines, and then just like NPX installs MCP servers and runs them in the machine. Like talk about supply chain risk. And so great. But to be clear, the productivity benefits here are crazy. What I want to do is I want to use an agent and let it run. I don't want to run a YOLO mode by default, go do everything, but just give me some security. So we're going to adapt our engine, build a new engine. The way I think it was, we're building a new runtime engine for untrusted workloads. It should be a place where you can go put in a coding agent. It needs a computer.
1:02:59It should be able to go run to everything it can do with security guardrails. so by default we'll have micro VMs here so if you go look we have our initial start of this should have just come out if you look at Docker Sandboxes you can do Docker Sandbox run Cloud spins up Cloud in a micro VM around that we have network proxies that are outside the VM so when it tries to go outside of the network we run through proxy layer, we have a credential layer here where you don't have to give it your credentials but if it starts to GitHub, we inject credentials outside so the agent doesn't need to know your secure content or data.
1:03:38You control files it has access to, control where it goes, but let it run. Then for MCP, this is where we're adding our MCP security. We have a trusted registry of MCP servers. These are MCP servers that we've vetted. We run through security hardening here. We're also building DHI versions of these and a gateway that's plugged in. and the gateway is where we can start injecting a lot more security rules too. And so the vision is built towards a secure runtime for untrusted workloads, you know, folks and coding agents. And we'll make this work both locally and remotely and give you the same thing so you can be working locally, but we'll have a cloud that'll be coming out soon.
1:04:19And we actually have some early partners who are working on this already. But as a developer, I should just start in our Docker sandbox. I get all the property benefits. I run my agent unfettered. I get all the security benefits. I'll get cloud. And for enterprise, they can manage governance around all of this stuff. And then we tie supply chain security in here. As we're doing this, create by default, build on the secure content we've talked about, get that in here, et cetera, et cetera. Let me pause. This is like a big, big push for us. And I think like sort of, you know, what should the next, well, I want to say what should the next five years of the doc look like, but I'm talking AI.
1:04:56so let's just sit the next year for a minute yeah we'll see what happens after that right well it does make sense because i i'm a i'm kind of a uh a dash dash dangerously skip permissions kind of guy you know um so when i run claw that's where i go i'm just tired of like saying yes you know what i'm saying so i just i just in a way yolo i'm not yoloing on production stuff but on like little tinker things uh but that's dangerous obviously it's it's got the word in the in the flag for a reason. And so what you're saying is in this future world where we may be going to in this next year around AI, I can do that in a way that is less dangerous because it's containerized.
1:05:39It's compartmentalized. It's in its own, you know, micro VM or a sandbox. And so the danger is really just micro VM danger, not Adam's MacBook Pro danger, where I can, I've seen this where there was a Hacker News article out on this. I believe something like deleted their, the agent deleted their entire machine. You know, that's a possibility when you live dangerously. Yeah, there's a ton here. So just to, you know, play in the picture a bit. So there's the VM isolation and we can do that and that protect your home directory, your directories a bit, but it's more than that, right? So we can talk about just file for a minute.
1:06:17Well, you want to protect stuff, but now, well, what if you do actually need it to read some folder? How do you manage that? So this is, it's different from like containers because containers you think of like package and you static and then scale them out. Here we're talking like a runtime that actually needs to be dynamic. That's the nature of the thing. But I still want security statements to be true about it. So by default, limited access. When I want to go out, we can decide what we approve, what we don't, let it run. And when it does, like control writes to sensitive areas. When it wants to write out to the network, it's not just, they have to put a gate there to anything he wants to do outside this box, we put a gate, great, we have a network proxy.
1:06:55That can control not just where it goes, but over time we'll add in deeper rules here that is it doing something dangerous. And we can work at various levels of the stack as we do that. Credentials, don't give this thing credentials. You want to pull from GitHub, let's not put that in the agent, put that outside. And agent can just try to talk to GitHub and we'll inject the credentials. There's a ton of stuff you have to do, and I don't know if you followed the CloudBot stuff. I feel like I started, did that start on Saturday? or something. And then it's been like, yeah, so I've been using it and then it's just like insane to follow the speed.
1:07:27And then I think yesterday there was, I forget the name of the person who wrote like a deep security article of how he used Skillhub to get everyone to install the skill and like escalate it. His white hat showed how he could. It just goes to show like what's happening here is like the potential is tremendous. We all want to use it. But the security concerns are very, very real. this is sort of the core of what I think our job is, like, enable devs to be deeply productive and add security. And just, this is now a space where, like, this has always been true, but it's even more true, it's more clear now, because the productive benefits and security threats are just like, you know, 100x what they used to be.
1:08:09Right. Everything's faster, more pervasive. Yes. We're just flying by the seat of our pants and the stakes are high. And I think it's like a perfect moment for Docker, because when you think about isolating isolated secure workloads i feel like you know is docker if not docker who else star green stay green just trying to say it you know a couple more times here yeah and so that's what we'll do local and cloud also and i think cloud's critical for us because as you start doing this stuff i don't know i was doing a bunch ago recently i've gotten to the point now where like i don't know cloud can run for like a couple hours for me and produce good quality code with tests and everything, I want that to run off somewhere else.
1:08:50So I can close my laptop and go do something else. And I run like six of these at a time. And so, but I also want easy, I want security as the cloud, and I want easy DX between local and cloud because I want to dig into it. And so that's the other part of the engine we're building now, where the engine will run locally and remotely, and we can get security and seamless local remote experience for you. we're going to have to get the IDE back into play, but I'm not talking about the actual IDE. I'm talking about the AIDE, AI development environment. That's what we need. Yes. I mean, you had that for the cloud development environment, CDE, right?
1:09:26Yes. Let me take your machine away from you. Let me put it in the cloud. Let me attach your IDE and or VIM or whatever you want to rock because that's just how it works. Yep. You know, we need an AI DE out there where you can just develop in the AI and close your laptop and move along and let it just keep churning. That's your journey, right? And then be able to pull it back when you need. You know, you have the security layer there when you need it. And so yeah, this is like, yeah, so it's like adapting Docker to be the engine across the entire STLC for CloudSuite. And so that's on the development side.
1:10:00And then we're just going to start doing stuff across the rest of the STLC too. We've got to build security agents as we go in, Docker building, CI left, working on all these problems here. the goal is really help you securely actually help developers securely 10x code writing use agents and then help realize that and actually get that shipped out and know that it's safe and secure as you do that I definitely think this maneuver you've made with hardened images I wouldn't say it cements it necessarily it certainly puts the cement down and is hardening to just go back to the play on words here because I mean I can't imagine deploying software to production in a cloud that isn't in a container.
1:10:42I can't imagine. It just doesn't compute for me that way. Now, I am a system D kind of guy, so I do YOLO here in my home lab. So I don't really do a lot of Docker stuff in my home lab. Sometimes, especially if I'm putting somebody else's application in because they've already done the work. They've containerized it for me. But if I'm doing my own thing here, I'm usually system D-ing it, and I'm usually just running it bare metal because it's a VM. It's in Proxmox. It's my home lab. It's not high stakes. and it just gives you one less layer between me and the actual machine itself. I've already got hypervisor, virtual machine, then Docker, then Apple.
1:11:17It's like, come on, I don't need all those layers. That being said, I think that your intuition is right. I think what you're doing in this maneuver has strengthened your position, has strengthened your trust for me. And I think it just solidifies the fact that Docker is here to stay and containers are the way. Yeah, maybe like, you know, another pithy statement maybe, like, you know, it's like build once runs anywhere, sort of like Docker, build once runs anywhere, trust always or something. Like, trust across the board. And that's true for AI, and then you're right, like DHI, like the same ethos, right, coming through of like trust, security is critical, just critical across your entire software lifecycle.
1:11:58Well, Tushar, you are the head of engineering over there. Anything left to say about what you do, what you're doing, what you're going to do before we close things out? No, maybe I'll just wrap up, which is the thing where we're headed, what are we doing? If it's successful, and I'm confident it will be, then everyone who's, one, I think the entire engineering world, every engine's going to move to using coding agents. It's just what's going to happen. I think all that should run in a new secure runtime for agents using the secure supply chain base that we have. So you use the runtime, basically adapting our engine and our content for the AI world.
1:12:39And I think that is, I think, what everyone needs. And I think we're in a position to do that. And already there. So I think that's the core focus for us is believe in, you know, solve for the world of people using coding agents. But as we do that, I think we're also building the platform that people need for running any agent. so that'll be the next phase once you get through this that any agent that's running of any kind should run on this layer here that's what we're focused on doing honestly it's like a super you know it's really fun, I feel lucky to have this gig it's a fun gig to be in the middle of all the change in the software world and to be at a place like Docker that's doing this right it's so critical and so core it's a really fun time to be a developer because there's so much change it's also quite scary this change you know there's a lot of there is some uncertainty while there's so much potential there's also so much uncertainty and so much pause but also so much not pause yeah i mean it's such a such a conundrum really to think about the state of things but like everything is literally changing we didn't expect this to be where it's at a year from year ago like a year ago the conversation was this direction, but not where it's at currently.
1:13:56And it's, it's clear that everything from the bottom up is changing about how we develop software, how we deploy software, how we have to secure it, et cetera. It's a fun time because we get to rebuild it all. So if you're an old hat, you're like, uh, okay, that sucks. I don't want to have to like learn new stuff. But if you're a new hat, you're like, sweet, let's build some cool stuff. But it is a wild ride we're on right now. I mean, everything is changing. It is a wild ride. Also, at least for me, like, you know, look, I struggled to answer that, like, hey, where will engineering be in, like, where will software development be in two years?
1:14:32I don't know. I can estimate and I can guess a bit. But right now, what's really fun is, like, fundamentally, I think people become engineers to, like, build stuff, like, solve problems and innovate. And, like, coding has been a key way to do that. We just get to, like, do that at, like, 10x, 100x the throughput now. It's just fun. I can have an idea and go. And that's just fun. Couldn't say it by myself. Tushar, thank you so much for sharing your time with us, doing this hard work, leading the charge, and being cool. Thank you. Thank you all. It was a lot of fun. Great talking to you.
1:15:12All right. That is your changelog interview for this week. We hope you enjoyed it. And we have a members-only bonus segment for our ChangeLog++ people. You get an extra 10 minutes of us talking Ralph, talking OpenClaw, and talking role changes. It's sort of the skills of, like, deck leads and deck managers and PMs, right? PMs, great communicators. Absolutely. We are the PMs now. We are the PMs now. We've always been the PMs. Join today at changelog.com slash plus plus. It's better. thanks again to our partners at fly.io to our bfreaking residents breakmaster cylinder and to you for listening we appreciate you hanging out with us each week that's all for now but we'll be back on friday with amel hussein talking career renaissance aerospace my return to the blogosphere and more looking forward to it talk to you then
1:16:24Thank you.
1:16:45Game on!
From the publisher
In May of 2025, Docker launched Hardened Images, a secure, minimal, production-ready set of images. In December, they made DHI freely available and open source to everyone who builds software. On this episode, we're joined by Tushar Jain, EVP of Engineering at Docker to learn all about it.
