Adoption of cloud-native technologies like service mesh, serverless computing, function-as-a-service (FaaS), and service proxies rose dramatically this year, according to the Cloud Native Computing Foundation (CNCF) "2022 Annual Cloud Native Survey."

The CNCF's previous annual surveys asked if cloud-native technologies were used in production, but this year's survey differentiated between production use for most applications and more limited usage. CNCF CTO Chris Aniszcyzk told SDxCentral that "partly as a consequence and partly because these technologies are growing in popularity, we saw a large bump in the usage of service mesh, serverless, and service proxies."

Service proxies have seen a significant jump in production use within the CNCF community with 71% claiming adoption in 2022, compared with usage by 37% of those surveyed in 2020. Service mesh adoption increased from 27% of those surveyed in 2020, to 47% that said they have adopted service mesh in 2022, and serverless architecture/FaaS adoption rose from 30% in 2020, to 53% in 2022.

The survey also found containers are mainstream, with 44% of respondents noting they use containers for nearly all applications and business segments. Another 35% said containers are used in a few production applications.

However, Aniszcyzk explained that container adoption is outpacing the maturity of cloud-native technologies more broadly. Only 30% of respondents have adopted cloud-native approached for nearly all development and deployment activities at their organization. And 62% of organizations don't use cloud-native technologies regularly, but they use containers for pilot projects or limited productions use cases.

Cloud-Native Training, Security Gaps Inhibit Container Adoption

The main challenge in container use and deployment is a lack of training and security, according to the CNCF. "In fact, lack of training is the most significant barrier inhibiting adoption," especially for 44% of respondents that have yet to deploy containers in production, and for 41% that use containers on a limited basis, Aniszcyzk said.

Insufficient training has "consistently been a barrier to adoption," he noted. In an effort to bridge that gap, the CNCF and the Linux Foundation have developed pre-professional certifications and training for those just starting with cloud native or with an interest in cloud-native security.

In addition, Aniszcyzk cited cloud-native integrated development environments (IDEs) and developer portals as emerging tools that improve the developer experience and help cloud-native adoption go smoother for organizations. Cloud-native IDEs give developers "ephemeral workspaces" that automate setup, simplify processes, and ultimately save developers time.

Developer portal Backstage, for example, uses service catalogs, software templates, documentation, and workflows to limit the complexity of cloud-native adoption while letting devs "discover and use" various services, regardless of environment. "Backstage is one of the few CNCF projects I’ve seen deployed in traditional enterprises first, even before Kubernetes," Aniszcyck added.

SBOMs, eBPF Drive Kubernetes Security

Aniszcyzk noted software bill of materials (SBOMs) are coming up in the cloud-native world as a popular security tool. According to the CNCF survey, 44% of respondents have fully implemented or are beginning to implement SBOM content to address compliance and security issues. Following the White House's 2021 Executive Order and the U.S. Securing Open Source Software Act, SBOMs will likely maintain their status as "an essential part of software supply chain security," he explained.

The Kubernetes project has adopted SBOMs and produces them within project builds and releases, with many other CNCF projects sure to follow. Aniszcyzk also highlighted the Open Source Security Foundation's (OpenSSF) mobilization plan focused on open source security challenges.

"I also expect a lot of new innovation in this space that will work to aggregate a lot of this security information," he said, citing projects on his radar like GUAC, Scorecards, Sigstore, and Witness.

"eBPF is another technology that is becoming pervasive in the cloud-native space," Aniszcyzk said. For example, the Cilium project uses eBPF – which runs sandboxed programs in a Linux kernel without changing its source code – to increase container workload visibility. And Falco uses the technology to monitor behavioral activity and find anomalous activity in container runtimes.