Showing posts with label Tanzu. Show all posts
Showing posts with label Tanzu. Show all posts

Tuesday, December 10, 2024

Announcing General Availability of Bitnami Premium

Today the Bitnami team, part of VMware Tanzu, is thrilled to make two announcements. The first is that Bitnami Premium, a new commercial upgrade to the Bitnami Application Catalog containers and Helm charts, is now Generally Available. Second, we are kicking off a new endeavor with Arrow Electronics to facilitate a streamlined Bitnami Premium purchase and support experience.

A new commercial version of Bitnami open source containers and Helm charts

Enterprises that love Bitnami can now purchase a Bitnami Premium subscription from Arrow Electronics and consume the containers and Helm charts right in Docker Hub. Bitnami Premium users will get access to private Docker Hub repositories with the same containers and Helm charts they are used to, plus new commercial features including:
  • Enterprise support for all 500+ Bitnami Premium packages
  • All LTS branches of all Bitnami application packages maintained up-to-date
  • Unlimited pulls of all Bitnami Premium containers and Helm charts from Docker Hub
  • Secure software supply chain metadata including Software Bills of Material (SBOMs), SLSA 3 pipeline validation with in-toto attestations, Notation and Cosign signatures, Build-time CVE and anti-virus scan reports, and more.

Alongside the launch of Bitnami Premium, we are making some changes to how we deliver the Bitnami Application Catalog:

  • Unlimited pulls from Docker Hub will no longer be available. Free Bitnami Application Catalog containers and charts will be subject to the same limits as any other Docker Hub repos starting December 16th, 2024 January 6th, 2025. Pulls of Bitnami Premium containers and Helm charts will not count towards your  Docker Hub pull limits or overages.
    UPDATE: We’ve received a lot of feedback from the community on the impact of this update. We have decided to shift to a gradual implementation, starting with a 3-hour test December 16th, followed by a 12-hour test on December 19th. The permanent change is now scheduled for January 6th, 2025.
  • Long-term-support (LTS) branches of the software we package will no longer be maintained in the free Bitnami Application Catalog. To continue receiving updates for LTS branches of packages, you will have to upgrade to Bitnami Premium.
  • We are improving Bitnami Application Catalog users’ supply chain security through additional integrity checks in our Helm chart installation process. These checks enable users to be aware when they are using containers that were not created and tested by Bitnami.
These changes enable us to deliver a premium Bitnami experience to our enterprise users who will benefit from support and security metadata, but who do not need the extensive customization that is core to our other commercial offering called Tanzu Application Catalog (TAC). We are committed to continue delivering free Bitnami Application Catalog content to our community of developers and other open source project maintainers over the long term. 

Read on to learn more about Bitnami Premium and the coming changes to the free Bitnami Application Catalog content.

New goodness in Bitnami Premium

Bitnami Premium is a new version of the content packaged by Bitnami that is sold through Arrow Electronics. You can connect to an Arrow salesperson if you have any questions or want to purchase access. Once you buy Bitnami Premium, you will be given access to the Bitnami Premium registries in Docker Hub. You can then return to Docker Hub where you will have access to the Bitnami Premium containers, Helm charts, and software supply chain metadata from the new /bitnamiprem and /bitnamichartsprem orgs. These private repos are what enable you to pull without limits or caps. You will also see containers for all LTS branches continuously maintained up-to-date: for example, you will see PostgreSQL containers for versions 12, 13, 14, 15, 16, and 17; while in the free Bitnami catalog, you will only find version 17.

A middle ground between free Bitnami Application Catalog and Tanzu Application Catalog customized packages.

In Bitnami Premium, all of the applications are built on Debian just as they are in the free Bitnami library. You get the entire library of containers and Helm charts kept up-to-date with the latest changes anywhere in each app from the OS to the application code itself. You can consume the content through Docker Hub where you’ve already been pulling it to date. However, in the Bitnami Premium registries, you will also find important software supply chain security metadata delivered as OCI artifacts alongside the containers and Helm charts. This metadata is useful for enterprises that need third-party open source software to be compliant with policies around auditability, supply chain integrity, and time to remediation of vulnerabilities.
  • Supply chain security and integrity: Bitnami Premium containers and Helm charts are built on an SLSA 3 pipeline, with attestations and signatures serving as proof that the software you’re deploying in your clusters is what you expect and has not been tampered with. 
  • Software bills of material (SBOMs): At both the Helm chart and container levels, SBOMs give you fine-grained insight into the contents of every package. This will make it far easier to continuously validate the integrity of software supply chains and to track and triage vulnerabilities as they are discovered and patched.
  • Build time CVE scans, anti-virus scans, and more: also included with Bitnami Premium content are Trivy CVE scan results and ClamAV scan results that satisfy requirements for, among other things, doing business with the US Federal government. You will also find the results of Bitnami’s automated functional tests that run as part of every artifact update, trigger information that specifies why the latest update was released, and more. 
Bitnami Premium differs from Tanzu Application Catalog in that, just like our free Bitnami content, it is a one-size-fits-all library of containers and Helm charts all built on Debian. Tanzu Application Catalog gives you the ability to customize your artifacts along many different dimensions. Some of the key differences include:
  • Private delivery: TAC containers and Helm charts are delivered directly to your private registries, or are hosted in a private registry maintained by us that you can pull from. 
  • Choose a Linux distro or use your own “golden image”: TAC gives you the ability to choose among four supported Linux distros: Debian, Ubuntu, RedHat UBI, or VMware’s own PhotonOS. All of the software packages on these distributions are maintained up-to-date and are tested to work in multiple Kubernetes environments as part of the release process. You can also use your own golden image: we’ll build and maintain the artifacts on top of it. For customers that need it, PhotonOS includes FIPS OpenSSL, is STIG-compliant, and includes zero/minimal CVES with VEX statements to triage any remaining ones.
  • App-specific customization: With TAC, you can inject your own customizations such as user settings, certificates, or plugins into our SLSA 3 pipeline, so the artifacts you receive are truly promotable to production environments.
  • Software knowledge graph: This keeps track of all your software dependencies at the individual package level. It continuously scans them for vulnerabilities, and organizes them into a searchable graph database so you can see in real-time which versions of which apps are affected and patched. It also includes useful information such as open source licenses, package management ecosystem data, and more.
  • UI and API: TAC includes access to a user interface where you can add and remove applications from your catalog, and interact with the software knowledge graph to see at-a-glance details about your software. The TAC API enables you to build information from the software knowledge graph into your pipelines to ensure you are keeping your applications up-to-date with the latest patched applications.
For a side-by-side comparison between Bitnami Application Catalog, Bitnami Premium, and Tanzu Application Catalog, check out this feature matrix.

Continuing our long tradition of partnerships

Since Bitnami’s beginning over a decade ago, our many partnerships have propelled us to be a leading publisher of open source software. Bitnami cloud images drive billions of compute hours annually for our hyperscale cloud partners, for example, and our containers and Helm charts are pulled hundreds of millions of times per month from our partners at Docker Hub.

We now begin our newest endeavor with Arrow Electronics. Arrow is a global leader in IT distribution. Arrow is known for its ability to help businesses navigate the complexities of modern IT landscapes, providing the tools, technology, and expertise needed to drive digital transformation and operational efficiency.

Arrow will sell Bitnami Premium access through its website. Bitnami users interested in purchasing Bitnami Premium will find a streamlined process to pay, share their Docker Hub user identification, and gain access to the private Bitnami Premium repos in Docker Hub. Bitnami Premium customers can add and remove users through Arrow's support team, as well as submit tickets for enterprise support jointly delivered by the software packaging experts at Arrow and Bitnami.



What changes are coming for the free Bitnami library?


Pull limits for free Bitnami content


Beginning December 16th, 2024, the Bitnami Application Catalog will use standard Docker Hub pull rate limits for Bitnami apps. Enterprise customers will be able to access the full Bitnami library in Bitnami Premium, purchased through the Arrow and consumed right in Docker Hub, with no rate limits or restrictions. Note that we are not changing any licenses for our packages, meaning that projects can continue to bundle our Helm charts and containers in their own application packages.


Long Term Support version updates


Many open source projects we publish packages for have multiple LTS versions supported by their communities. Currently, Bitnami maintains all of these LTS versions up-to-date. Starting December 10th, 2024, we will only continue updating the latest version available for apps in the free Bitnami Application Catalog. This will enable OSS projects and individual/small businesses to continue using the latest versions of Bitnami applications. Bitnami Premium customers who need to continue pulling up-to-date versions of LTS branches can access them in the Bitnami Premium repo in Docker Hub.


Supply chain integrity check in Bitnami Helm charts


Bitnami has invested hundreds of thousands of developer hours in constructing a world-leading pipeline to build, monitor, update, and test open source software in multiple Kubernetes environments. For these Helm charts to perform as intended and to leverage the many built-in security features, they need to deploy the Bitnami containers they were designed to work with. Therefore, we are adding new checks in the deployment process to ensure that the containers they were designed to deploy are the ones being deployed. 

Keep an eye out for more updates

We are excited to deliver an enhanced experience for Bitnami Premium users, but this is just the beginning. We will continue to build on the value that all of our Bitnami community members, both free and paid, realize through our many years of experience publishing high-quality open source software packages for the world’s developers.

Keep abreast of our blog for new updates and features, and be sure to check to follow us on X (formerly Twitter) and LinkedIn.

Tuesday, August 31, 2021

Kubeapps 2.3.4 - Easier Deployment in VMware Tanzu™ Kubernetes Grid Clusters

A new Kubeapps release is out, and it is even easier to run in TKG clusters! The last version of Kubeapps necessitated a manual update of the current Pinniped version to the latest – this step is no longer required.  Cluster administrators can now configure Kubeapps to simply use the built-in Pinniped instance to authenticate through the same OIDC provider as they have already installed in their VMware Tanzu™ Kubernetes Grid (TKG) clusters. 

Keep reading to learn more about how to benefit from installing the Kubeapps 2.3.4 version.  

Advanced Features for Tanzu Users 

Kubeapps enables users to consume and manage open-source trusted and validated solutions through an intuitive web-based interface. 

With the previous release, Tanzu users gained the possibility of deploying Kubeapps directly to TKG workload clusters. This integration allows users to operate Kubernetes deployments through a web-based dashboard both on-premises in vSphere, and even in the public cloud on Amazon EC2 or Microsoft Azure. 

Kubeapps provides a wide catalog of ready-to-run-on Kubernetes solutions. In addition to the default Kubeapps catalog, Tanzu users have the flexibility to configure either VMware Tanzu™ Application Catalog (TAC) as a private chart repository or any of VMware Marketplace™ Catalog or the Bitnami Application Catalog as public chart repositories. This extends the number of available solutions and sources for development teams to work with. Refer to this blog post to learn more about Kubeapps key features for Tanzu users.  

How to Use Kubeapps in TKG 

However, once Kubeapps is enabled in a cluster, some concerns may arise for cluster administrators when users need to access the tool:  

  • How to ensure secure authentication for users to Kubeapps? 
  • How to manage the different application catalogs? 
  • Is possible to customize the layout of Kubeapps to align it with my corporate branding policies? 

This new release of Kubeapps comes to address all these questions. When you install Kubeapps in a TKG cluster, you at once get:  

1) An in-built authentication system in TKG via Pinniped using the same version as the cluster runs

Authorization is delegated to the Kubernetes RBAC, which means that the same policies and roles configured for your cluster will be used when users want to enter and use Kubeapps.  

That way, the authentication to Kubeapps is completely safe since it will use the same OIDC provider as the TKG cluster uses.  

Follow these steps to configure an OIDC provider in your cluster to use for Kubeapps authentication: 

2) An easy way to deploy applications from the Tanzu Application Catalog and the Bitnami Application Catalog from the VMware Marketplace through Kubeapps

With Kubeapps, you can either deploy custom applications from a private repository or access the different catalogs from both public and private repositories that VMware provides. To configure application catalogs in Kubeapps once it is running on your TKG cluster, use the following instructions depending on which solutions you want to add:   

Once Kubeapps has been configured with one or more application repositories, you can start to use it to deploy, upgrade, roll back, or delete applications on your TKG clusters through its dashboard. Check out this documentation to learn how. 

3) A custom user interface

To provide a rich user experience, Kubeapps supplies a set of parameters to use for configuring a custom user interface. Learn how to configure the user interface to follow your company branding guidelines.  

Support and resources 

Since Kubeapps is an OSS project, support for this version of Kubeapps will be provided on a best-effort basis. For solving the problems you may have (including deployment support, operational support, and bug fixes), please open an issue in the Kubeapps GitHub repository. A markdown template is provided by default to open new issues with the information requested to prioritize and respond to them as soon as possible. Also, if you want to contribute to the project, feel free to send us a pull request, and the team will check it and guide you in the process for a successful merge. 

In addition, you can reach out to Kubeapps developers at #kubeapps on Kubernetes Slack (click here to sign up). 

For more information about the topics discussed in this blog post, refer to the following links: 


The Kubeapps team continues to work on the revamp of the Kubeapps backend. It will support multiple package formats really soon. Stay tuned!

Wednesday, July 28, 2021

VMware Joins Docker Verified Publisher Program with its Bitnami, Tanzu and Spring Cloud Products

“VMware is pleased to join the Docker Verified Publisher’s program. This provides developers unrestricted access to our artifacts and allows them to safely adopt the popular open-source technologies we’ve made available. We are excited that VMware Tanzu customers, in particular, will benefit from a wider range of complementary services they can leverage as they quickly get apps to market.” - Ashok Aletty, VP Engineering, VMware

In May 2021, Docker, IncTM announced the launch of its Docker Verified Publisher Program which helps developers recognize trusted publisher software. For development teams, this is huge, since this program simplifies the consumption of secure and verified components for them, as they build their applications.  

What is the Docker Verified Publisher Program? 

When building container-based applications or deployment templates such as Helm charts, it is a frequent practice to grab pre-built building blocks to quickly create application images. A common concern among developers is to make sure that the pieces being used to build their applications are secure, reliable, maintained and up to date. Nobody wants to spend time fixing security issues or exposing their software supply chain to malicious content.  

To make it easier to select robust, trusted, and reliable software when navigating through Docker Hub, Docker has launched the Docker Verified Publisher Program. With more than 200 ISVs and thousands of individual contributors delivering software through Docker Hub, the creation of a “Verified Publisher” badge enables development teams to quickly recognize trustworthy containerized images. Docker’s differentiated and trusted content can be used as reliable building blocks for quickly building, sharing, and running applications with complete confidence.  

In addition, developers will benefit from being exempt from rates limiting. This means that regardless of the Docker Hub subscription they opted for, they will have unlimited container image requests for Bitnami, Tanzu, and Spring cloud repositories.  



How can I find VMware Images Labelled “Verified Publisher”? 

VMware with its Bitnami, Tanzu, and Spring Cloud products has joined the Docker Verified Publisher program to enable developers to find trusted content for use in their application delivery pipeline.  

This will allow developers to have unlimited access to VMware’s robust and secure components.

From now on, all users, especially VMware Tanzu customers, will be able to accelerate time to market for their applications by accessing an extended offering of complementary services.  

As a part of VMware’s open-source offerings, Bitnami delivers more than 250 images labelled as “Verified Publisher” in Docker Hub. To discover them, navigate to Docker Hub and enable the “Verified Publisher” filter. You will see the “Verified Publisher” badge in the upper right corner of each image.  

Support and Resources 


Both the Tanzu Developer Center and the Bitnami Documentation Tutorials site are full of handy resources that will enable you to benefit from using VMware’s Docker Verified Publisher images when building your applications.  

Also, check out the VMware and Bitnami GitHub official repositories to contribute to these projects and to solve the problems you may have by opening an issue. Our support teams will be happy to help you there! 



Monday, June 7, 2021

Kubeapps Meets Tanzu Kubernetes Grid: a New Release is Out

The latest version of Kubeapps (v.2.3.2) is now available for deployment on VMware Tanzu™ Kubernetes Grid™ (TKG) workload clustersVMware Tanzu users already benefit from deploying Kubeapps in several environments andnow with a little configuration Kubeapps can be integrated with your TKG workload cluster. In addition to this capability,  Kubeapps also features full compatibility with the latest versions of Pinniped which means that it can be used with any OIDC provider for your TKG clusters and even in managed clusters such as Azure Kubernetes Service (AKS) and Google Kubernetes Engine (GKE). 


Want to know more? Keep reading to discover the latest capabilities of Kubeapps that will enable developers and admin clusters to deploy and manage trusted open-source content in TKG clusters. 


A bit of history: What is Kubeapps? 


Kubeapps is an in-cluster web-based application that enables users with a one-time installation to deploy, manage, and upgrade applications on a Kubernetes cluster.  

This past year, the Kubeapps team has added key new features to support different use cases and scenarios. Firstlywe added support for private Helm and Docker registries and later, in Kubeapps version 2.0we built support to run Kubeapps on various VMware Tanzu™ platforms such as Tanzu™ Mission Control, vSphere, and Tanzu™ Kubernetes Grid.  

With Kubeapps you can:  

  • customize deployments through an intuitive, form-based user interface 

  • inspect, upgrade and delete applications installed in the cluster  

  • browse and deploy from public or private chart repositories including VMware Marketplace™ and Bitnami Application Catalog 

  • secure authentication to Kubeapps using an OAuth2/OIDC provider such as the VMware Cloud Service Portal 

  • secure authorization based on Kubernetes role-based access control 

Key Features of Kubeapps 2.3.2


In this Kubeapps release, we have focused on delivering key user experience features including the capability to enable Tanzu users to deploy Kubeapps directly as a Helm chart in TKG workload clusters. This version is tested and validated on the latest version of TKG (v1.3.1) 

Once Kubeapps is up and running, cluster admins will benefit from having: 

  • SSO for Authentication with TKG using Pinniped by configuring an OIDC provider;

  • the ability to configure VMware Tanzu™ Application Catalog (TAC) as a private Chart repository; 

  • the capability to configure VMware Marketplace Catalog and the Bitnami Application Catalog as public chart repositories;

  • customized user interface adapted to the Tanzu look and feel. 



Kubeapps support for SSO Authentication 


All these new capabilities are designed to offer a seamless experience between Kubeapps and Tanzu Kubernetes Grid clusters. 

 

How can I configure Kubeapps to run in my TKG clusters? 

 

Tanzu users can execute these simple steps to gain the maximum advantage with this new version of Kubeapps: 

  • Configure your cluster to enable SSO for Authentication with TKG using Pinniped and integrate Kubeapps with the identity management provider

  • Adjust the Kubeapps user interface to get a customized look and feel 

  • Configure role-based access control in Kubeapps (RBAC) to manage roles and permissions among the teams in your organization 

  • Deploy Kubeapps in the cluster  

  • Add public and private repositories to Kubeapps: the public VMware Marketplace™ repository and your private VMware Tanzu Application Catalog for Tanzu Advanced repository 

At this point your development team can start deploying, listing, removing and managing applications in your TKG clusters from the Kubeapps user interface with total confidence! Refer to the Kubeapps documentation to learn how to deploy and configure Kubeapps on VMware Tanzu Kubernetes Grid. 


Watch the following live demo to learn how to get Kubeapps up and running in your TKG clusters:






Support and Resources 

 

Since Kubeapps is an OSS project, support for this version of Kubeapps will be provided on a best-effort basis. For solving the problems you may have (including deployment support, operational support and bug fixes), please open an issue in the Kubeapps GitHub repository. A markdown template is provided by default to open new issues with the information requested to prioritize and respond to them as soon as possible. Also, if you want to contribute to the project, feel free to send us a pull request, and the team will check it and guide you in the process for a successful merge.  

The Kubeapps documentation section is full of useful resources to help you get the best of the chart.  

Check out the step-by-step guide for deploying and configuring Kubeapps on VMware Tanzu™ Kubernetes Grid™ and the Bitnami documentation tutorials site for improving your Kubernetes skills.  


Also, for more information about VMware Tanzu Kubernetes Grid, refer to its documentation page where you will find handy information on managing your Kubernetes clusters.