The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Marketing/Application Modernization
Application Modernization artwork

How Shadow-Soft is Helping its Customers Solve Technology Challenges

Application Modernization · 2023-03-29 · 27 min

0:00--:--

Key moments - from our scoring

Substance score

26 / 100

Five dimensions, 20 points each

Insight Density5 / 20
Originality4 / 20
Guest Caliber6 / 20
Specificity & Evidence6 / 20
Conversational Craft5 / 20

Shadow-Soft, founded in 2008, has evolved from evangelizing open source software to specializing in Kubernetes platform strategy and container orchestration for enterprise customers. Nick explains that the company takes a three-legged stool approach: combining the right tools (like OpenShift, Rancher, or Dynatrace), people with relevant expertise, and proven processes and frameworks. The core customer problems Shadow-Soft addresses include knowledge gaps left when key technical staff depart, uncertainty about Kubernetes best practices, and the struggle to move from pilot deployments to mission-critical production workloads. A critical insight emerging in the Kubernetes maturity curve is that organizations have spent the past five years experimenting with small-scale deployments and are now ready to scale platforms with security and stability built in from the beginning. Shadow-Soft invests heavily in education through its training academy and in evaluating emerging CNCF ecosystem projects to help customers navigate tool selection decisions without getting caught in vendor-specific messaging around buzzwords like DevOps, containerization, or cloud-native.

Key takeaways

  • →Shadow-Soft uses outcome-focused assessment rather than vendor lock-in, helping customers identify business problems first and then applying appropriate technology solutions to address them.
  • →Engaging security teams early in Kubernetes adoption - rather than treating it as a final checklist item - can compress compliance and ATO timelines from 12+ months to just 3 months.
  • →The three-legged stool model (tools, people/expertise, processes/frameworks) is essential for successful platform adoption; vendors alone cannot deliver complete solutions without integration partners.
  • →Kubernetes has forced adjacent technology vendors like APM and observability tools to completely redesign licensing and measurement models to handle ephemeral, cloud-native workloads.
  • →Most organizations lack security awareness around Kubernetes-specific attack vectors and will need to invest in new tools and practices fundamentally different from traditional infrastructure security approaches.

Guests

Nick

Topics in this episode

KubernetesRed HatOpenShiftCloud-native architecturePortworxDynatraceShadow-SoftCNCF ecosystemRancherAnsible

Questions this episode answers

What are the main reasons customers call Shadow-Soft for help with Kubernetes?

The most common scenario (75% of inbound) is when a key technical expert who built or maintains a Kubernetes deployment leaves the organization, leaving behind undocumented knowledge and risk. Other drivers include uncertainty about Kubernetes best practices and whether current deployments align with industry standards.

How can organizations reduce their Kubernetes security and ATO approval timeline?

By involving security teams from the beginning of platform design rather than treating security as a final compliance step, organizations can compress authority-to-operate approval from 12+ months to roughly 3 months, as demonstrated in Shadow-Soft's government customer case study.

What is the three-legged stool framework Shadow-Soft uses with customers?

The framework combines three equally important elements: the right tools and products (like OpenShift or Rancher), the people and expertise to architect and implement them together, and proven processes and frameworks that establish best practices for adoption and scaling.

How has Kubernetes changed requirements for APM and observability tools?

Kubernetes forced APM vendors to completely redesign their licensing models and measurement approaches because traditional per-JVM or per-instance licensing doesn't work when containers spin up and down in seconds; tools had to become container and cluster-aware rather than infrastructure-bound.

What investment areas is Shadow-Soft focusing on for the next 12-24 months?

Shadow-Soft is investing in Kubernetes as the core focus, expanding its training academy with health assessment and framework courses, and continuously evaluating emerging CNCF ecosystem projects to make informed recommendations as companies mature from pilot deployments to production scale.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

5 / 20

The episode is padded with generic observations about open source growth, Kubernetes adoption maturity, and outcome-oriented selling - none of which are novel to any B2B operator already in the tech space. The only semi-actionable idea (engage security early to shorten ATO timelines) is buried in one anecdote and is acknowledged as 'common sense' by the guest himself.

we're still going to be very focused on kubernetes
what customers want to do is they want to reliably reach their customers

Originality

4 / 20

Every take here circulates freely in the industry: security is an afterthought until a breach, customers want outcomes not products, open source has gone mainstream, Kubernetes is the convergence layer. Nothing is contrarian or first-principles; the guest himself labels the headline advice 'common sense.'

security is an afterthought until there's a breach and all of a sudden there's you know millions of dollars in liability
at its core, that was a pretty important change in the way we did technology operations and development

Guest Caliber

6 / 20

Nick is an early Shadowsoft employee (joined 2010) with real practitioner experience in open source and Kubernetes, but this is effectively a two-person internal marketing conversation - both participants work for Shadowsoft - rather than an interview with an independent external expert whose track record can be independently assessed.

I got involved in 2010 and having worked with both of our co-founders previously
I made the phone call to my family and said, hey, guess what? I'm going to go sell free software to all these organizations in North America

Specificity & Evidence

6 / 20

A handful of rough figures appear (75% of inbound customers are stuck after an SME leaves, 30 security professionals in a room with only 2-3 knowing Kubernetes, ATO timelines cut from 'a year or two' to 'months'), but no named customer, no revenue figures, no specific metrics, and the estimates are presented as impressionistic rather than data-backed.

75% of the people that come through the door figuratively, you know, to shat us off and ask for some help
i sat in a room with you know 30 security professionals late last year and i was just asking them what they knew about kubernetes and And there was probably two or three people that did

Conversational Craft

5 / 20

The host serves primarily as a validation machine, completing the guest's thoughts and offering his own talking points rather than probing. The one moment of sharpness is the guest's sarcastic deflection of the host's advice, which inadvertently highlights how thin the insights are. No genuine pushback or follow-up drilling occurs.

That seems reasonable, Ross. I mean, wow, what a great piece of advice. Somebody should throw that up on Instagram and Twitter is like Ross Beard said, engage security early
Right, right. I love that.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

customers24kubernetes24customer18security15help12applications11technology11today9shadowsoft9tools9build8platform8trying8open7source7sense7

Episode notes

What's your biggest and hairiest technology challenge? Listen to this Fireside Chat, where Nick Marcarelli and Ross Beard discuss some of the top challenges faced by enterprise organizations. Learn how Shadow-Soft solves these challenges for customers, including specific examples and key insights. Discover more about what Shadow-Soft invests in to support its customers on their Kubernetes Maturity Journey. Learn more about Shadow-Soft and download the free framework at shadow-soft.com

Full transcript

27 min

Transcribed and scored by The B2B Podcast Index.

You are listening to Application Modernization, a show that spotlights the forward-thinking leaders of high-growth software companies. From scaling applications and accelerating time to market to avoiding expensive licensing costs, we discuss how you can innovate with new technology and forward-thinking processes and save some cash in the process. Let's get into it. G'day, Nick.

Thanks for joining me. on the podcast how we doing today doing great ross happy to be here it's a beautiful beautiful day outside only a little bit wet a little bit gray spring is almost here well at least all the pollen was washed away that was pretty wild out there on the parking lot the other day yes there's you know pools of water with pollen floating on top going down to the sewer where it longs so big win for everybody yeah yeah i think uh that's the only time i'm happy to see it raining is after there's been a lot of pollen in the air yeah absolutely that uh we could use a little bit of relief for our allergies and things like that i've been i've been good so far my day is coming Nice, nice.

Well, today I wanted to speak with you a little bit about Shadowsoft and how we are creating value for customers, some of the problems we're helping them solve, and then sort of, you know, what are the solutions that we're bringing to the market to ultimately enable and help customers. so to kick us off just maybe give us a quick intro and a little bit about Shattersoft. Yeah absolutely so you know Shattersoft we're not a new company we've been doing this a while we started in 2008 and our focus was really on open source software which was not a mainstream thing oddly enough red hat had you know really just kind of emerged as you know the leader in that and the most viable um so one of our co-founders actually worked at jboss which was acquired by red hat and um you know our our two co-founders got together and decided to build a business around the open source development model um which seemed kind of crazy so you know i got involved in 2010 and having worked with both of our co-founders previously.

And, you know, I made the phone call to my family and said, hey, guess what? I'm going to go sell free software to all these organizations in North America. And, you know, their first question was, well, how do you make money selling free software? And I was like, don't know.

I'll let you know in a couple of weeks. So, you know, it's kind of funny because, you know, open source was definitely emerging and growing, but it wasn't prevalent in standard kind of IT practices. So when you fast forward to today, open source is actually forming the technical strategy and tooling for most organizations in every way, shape and form. all of the cool things that we get to use as consumers every day are built on open source technologies so that you've seen that difference from you know 2010 to 2023 pretty unique so shadowsoft you know kind of you know stumbled into you know a huge growing segment of the it landscape um you know mostly on purpose but i i think we were we were surprised about the the amount of opportunity there would be and how it would shape it we always thought it would but i'm not sure we could have predicted how fast so today you know we mostly help customers around that open source strategy specific to platforms and applications uh kubernetes being at the core of that um long long legacy of it automation uh tools from you know infrastructure automation to pipelines and deployments um those those types of toolings that focus around efficiency and speed reliability so but a lot of that is really converging at the kubernetes platform which is predominantly what we're helping customers with today and that all matters because of how it touches applications the types of applications we write the type of applications we want to re-platform for customers, all that becomes very, very relevant.

So for us, it's very easy to go. Experts in Kubernetes, that's how people should know us because all those things converge into that platform. Right, right, yeah. You know, we're seeing strong demand for Kubernetes.

We had a cracker year last year with year-over-year sort of growth in our professional services. I'm curious, sort of, what are some of the key problems that we're helping customers solve? I know for me, what really sort of comes to mind is this idea of we're helping customers enable innovation, right? We're helping them build out some of these platforms, which then enables them to migrate the application so they can make some sort of updates to the features and functionality quicker, which helps them ward off the competition and continue to innovate and serve customer needs.

For you, what are you seeing? and I'm curious your thoughts. Yeah, so I think one of the bigger challenges in the technology market is that we have all these phrases and terms that we try to impress upon customers to think differently. And so it'll start with DevOps was the one eight, nine years ago, right?

And we spent years trying to educate and evangelize what DevOps is. And at its core, that was a pretty important change in the way we did technology operations and development. But it also was a great use case in the lack of clarity around the message and like what we're actually trying to get done, you know, as technologists. So that hasn't stopped, right?

So we're, you know, platform of the future platforms, this application modernization by modal IT I trying to think of some others you know Hey Docker containerization and microservice like there all these terms and they all mean things But at the end of the day, what customers want to do is they want to reliably reach their customers, their customers with whatever services they're providing. So if they're manufacturing things, great, our manufacturing plant is building things and we're able to analyze and assess the efficiency of that how do those things get out the door where do they ship if they're a logistics company we pick things up we get them where they go is that done on time do our customers have visibility into where their things are if you're you know financially focused can we do transactions everywhere and when we do are they reliable do they happen do they report back correctly we have all these interconnected things so in this world where everything's connected, that actually creates a significant amount of challenges.

So I think what we really try to focus on is if a customer can identify, we have a problem here, there are technology decisions and changes that can be made to apply to that use case. So for us, we're very interested in what is the outcome the customer's looking like that, and then we'll use the appropriate amount of technology to drive them towards that outcome. And a lot of times it's just around lack of knowledge or, you know, workforce, um, on staff to be able to do that.

They just need some guidance, some help, someone to take them along, train them. And, um, you know, that's where we spend a lot of time, you know, making technology changes to help the outcome of whatever the customer's business objective is. And if we're just doing, if we're just doing things to do things, we're not helping the customer. We're probably creating technical debt.

Right, right. I love that. You know, thinking about that, that desired outcome, because I often feel like, you know, sometimes the vendors get a little caught up in just selling their individual product or tool, which, you know, does X, Y and Z. But really what the customer is looking for is a desired outcome around sort of innovating quickly or migrating some applications.

So I really like to think about this with like a three legged stool, right? You've got the tool or you've got the product, like an OpenShift or a Rancher or a Dynatrace or a Portworx. But you've also got two other legs to that stool. You've got the people.

So you need the experts that understand how to build these architectures, bring the different tools together, rally the folks inside the organization to adopt it. And then you've also got the processes, you know, the best practices. And, you know, one of the key insights we had at Shadowsoft when we went and spoke to customers in 2022 is that they told us they wanted a proven path. Right.

They wanted to they wanted help sort of getting those processes in place. And that's why at Shadowsoft, we've got some Shadowsoft frameworks that really we work with customers on to help sort of that leg of the store. So, you know, oftentimes when we talk to customers and they're just working with a vendor, you know, I always sort of encourage them to think, OK, you know, what about those other two legs of the stool? Yeah, absolutely.

And I think, you know, one of the. You know, there's there's advantages and disadvantages on both sides of the house. Right. So if you're a representative of a manufacturer, your job is to go out there and evangelize your solution.

and a lot of times that's all you got so if you want to you know talk to a customer about automation and you work for red hat for example you're obviously going to lead that conversation around ansible ansible is an amazing tool it does lots of things but there's also lots of other integrated tools that could make that life cycle make a lot of sense for a customer and that's pretty hard to do when you sell one thing. So one, you know, what I found is the best representatives at these ISVs have a strong opinion around how partners facilitate those projects.

So Ansible may be the core of what you're trying to do from a automation perspective, but there's probably some other things that need to happen in that life cycle of delivering software. And they're not all provided by Red Hat. But a partner can help integrate those things and set that project up to best practices. So, you know, the same vein where when I walk into a customer conversation, I'm not super interested in talking about brands and flavors until I understand what they're trying to accomplish, because then I can make a recommendation based off what I've seen, be successful and what what our engineering staff would say this is the right way to approach it's not about positioning a certain flavor all the time we have preferences you know just like anybody but ultimately we need to get the right solution into the customer's hands and that that requires great partnership between isv's and integration partners like shadowsoft and others you know across the country and the world to drive that success with a customer.

Yeah, I agree. So when speaking to customers, what are one or two examples or scenarios or compelling events where they may reach out to Shuttersoft for some help? Yeah, great question. So a lot of times it's around, unfortunately it's around hey we've made this investment and you know let's call it uh x technology and um we're stuck we've spent a bunch of money um we've built out this thing our primary application is leveraging this technology and the guy or gal that was the expert the sme within the organization has left and nobody knows what to do that happens more than than I can count, I would say that's probably, you know, 75% of the people that come through the door figuratively, you know, to shat us off and ask for some help.

And that's a huge concern as a customer. You know, you need to build reliability within your staff and your knowledge base and your ability to deliver you know those KPIs for your business And when you don have the people to do that or you not aware of what standing there and what could fall over that pretty terrifying So we see that a lot And then sometimes it just we built out this you know think about Kubernetes We have a large deployment of Kubernetes. We've done okay. It's fine, but we're not sure what's next.

or if we're doing this to best practice or are we heading down a road where we're going to be firefighting more than we'd prefer um so we we really see those those couple of things and you know at the end of the day like you know business is it's a people business so you have someone come in with their opinion on how they do something and they they they build a bunch of stuff and you know if they leave then someone else comes in and they need to build their own destiny within an organization.

You know, that happens a lot too. So, you know, for us, we try to stay focused on like what's best for the customer instead of what's our preference around a certain set of tools or technologies. And that will really benefit, I think, those people in the long run, because most people don't stay at the same place for a long time. I want to build relationships with individuals where we've helped them through a journey because when they get to the next place, they'll call us again.

And that's super important. So the reputation of the work that we do really matters. Right, right. We want to help them overcome some of those challenges.

So what's in store for Shadowsoft over the next 12, 24 months? Where's Shadowsoft investing? um you know we're i know kubernetes is the focus and we've got some frameworks that we've been developing and working with customers on um you know just what's in store for shadowsoft yeah it's a great question um you know we're still going to be very focused on kubernetes um most of what we make investments around will be around that we've you know launched our our training academy which is live and available to anyone at this point with a number of courses around education related to what is kubernetes and what are some of the use cases and how do you do a health assessment um some some of those framework idea you know concepts that you were talking about um but additionally you know the ecosystem like for cncf is insane and growing and huge and you know lots of these projects are starting to make the you know crossing the chasm to companies which means there's going to be viable options for customers to make decisions on what tools should we be investing in in our journey and i just i don't see that slowing down um i think we're probably you know this is you know this is my guess right my estimation but i think the next three to five years will be about lots of great ideas becoming projects evolving into companies And then there's a discussion around the roadmap for Kubernetes on what are investable companies to make a purchase around to implement into your process as a customer.

It's pretty mind-numbing. So our team is focused on evaluating these technologies, being able to make recommendations, trying to peek around the corner, right? I mean, I think that's the most important part in technology is to go, this is what we're doing here. you know in a year will the landscape look different and listen we're all people we're we're making estimations but you know I think that's a huge advantage for customers when you have organizations like ours that are going let us do the work around the architecture of the tools and make some recommendations based on our experience that saves them a lot of time Yeah, yeah, I'm really excited by the progress of Kubernetes adoption, you know, with our customers in the market, you know, as we sort of think about the Kubernetes maturity journey.

You know, I think, you know, we've been fortunate to be in this space for sort of five plus years. And we spent, you know, a lot of those years evangelizing the benefits of Kubernetes and trying to help educate the market on, you know, why customers should embrace it. I think we're now at a point where most folks have built out some sort of platform as a little bit of a pilot or they've got a couple, you know, maybe five, 10, 20 applications. And they're now ready to take that next step.

And they need to really get that platform to a point where it's stable and it can scale with the business with security in mind. So that's what excites me is that people have spent the last few years that are getting getting their hands dirty. And now it's prime time and they're ready to bring these mission critical applications and then be able to take advantage and really benefit from all of the opportunities that Kubernetes can can bring the organization. Yeah, absolutely.

It's an exciting time. And, you know, I think what's interesting, you didn't ask, but I'm going to share, that Kubernetes has, I think, really driven the rest of the technology market to think differently. So you look at, you look at, like, you know, take a look at the APM space or the observability spaces. Everybody likes to rename it now.

Now, those tools have had to go through significant design and utilization changes to accommodate a world that's cloud native, whether that's public cloud services or specifically Kubernetes, whether that's in the public cloud or on-prem. Because applications were not - like these tools weren't licensed to do that five, six years ago. Right. So it made them very expensive or even impossible to entitle to customers.

How do you entitle - if you're entitling an APM around like JVMs, for example, like it's been done in the past, how do you entitle something that's here one second and gone the other? That's pretty complicated. You know, so a lot of these kind of adjacent technology companies that are household names that maybe we've worked with for years and years, they've had to go through a tremendous amount of transformation to be able to cover the use case of what Kubernetes has brought.

And that not a small task You know I really applaud anyone who figured it out because that is um that a lot of hard work you know trying to observe something that alive and dead in you know seconds is pretty insane. So, you know, that, and that rolls down to all types of parts of the stack, whether it's, uh, storage, uh, security. I mean, you know, we're seeing a big boom around security around how do we secure kubernetes most organizations have not thought through this and because it's so new and it's kind of abstracted away it might not even be on the radar right of security professionals and you know we've seen that in talking to you know groups of people you know i sat in a room with you know 30 security professionals late last year and i was just asking them what they knew about kubernetes and And there was probably two or three people that did.

That's a scary attack vector. So that's one thing we're spending a lot of time on right now is like, how do we secure Kubernetes in a way that's going to help a customer? Right, right. So, yeah, it's often the last item on the checklist.

So curious, how does Shuttersoft sort of try and bring those conversations up And where does sort of security or the security teams inside our customer accounts sort of really engage in, you know, the process of adopting a Kubernetes platform? Well, I think, unfortunately, the security awareness is still kind of a last mile approach in a lot of organizations. And that I don't think that bodes well. there's there there's some organizations that are going hey we need to be doing things with security in mind i had a great uh government customer you know government's into security right but there's still a bit of a practice around being able to take a lot of that compliance and actually make it actionable um so i had a specific customer that you know did a great job they built out a stack and and amazon um you know it's like net new kind of greenfield thing but they did it was security involved from the beginning.

So when they went to go ask for their ATO or authority to operate, um, it was a simple quick process, which sometimes can take a year or two, you know, previously they were able to get an ATO and months, you know, while they were building the stack. And then they, they built a framework that allowed them that when they added something on top of the stack um they didn't have to recertify the entire stack because it's already been certified so they were able to build out very very quickly which allowed them to serve their customers which tended to be the other the state agencies that they supported um in a way that was revolutionary for the government and there's there's you know stories and pockets of this and the federal government all over the place but not everybody's doing this well and I'm not picking on the government because commercial companies don't do this well either you know like security is an afterthought until there's a breach and all of a sudden there's you know millions of dollars in liability that's on the line so it's it's a difficult challenge but like you know security is a big part of anything you do especially in Kubernetes so we try to make sure that we're challenging customers to be thinking about that in ways that make sense securing information and applications in kubernetes is different than in traditional infrastructure so the tools you have probably aren't going to cover what you're doing today which means you need to be up to speed on what's available to you and you may have to make some investments around those things too yeah yeah i i think that's interesting and it sounds like you know as a if you're a leader inside an organization that's responsible for the you know rollout of the the new platform, you know, think through, you know, how long does it typically take security to, you know, sign off on these types of things.

And if it is typically, you know, a 12 month process, then you're probably wise to engage them early. And then, you know, you might be able to reduce that, reduce that down to three months. That that seems reasonable, Ross. I mean, wow, what a great piece of advice.

Somebody should throw that up on Instagram and Twitter is like Ross Beard said, engage security early. You know, maybe you'll take 12 months to three months. It's common sense, right? Like it's common sense to you, but that's not how we operate in IT, unfortunately.

So we have to apply some common sense to what we're doing day to day, which is, I think, your point. That's it, that's it. So it's been good catching up today, Nick. Is there anything else that we haven't covered today that you think the audience would like to hear?

Well, you know, I've always got something to talk about. I talk for a living, so that helps. But I think we covered a lot of useful concepts for the listeners. And I think we'll probably do more of these, maybe.

It's like Fireside Chats with Ross and Nick. It's becoming my favorite part of the week. so we could just you know continue doing this and share some of those kind of week-to-week insights that we see but uh probably did enough for now how about this common sense insights i like that i like that that's uh that's good we could all use a bit more common sense i think today in this age so all righty well thanks for joining us on the podcast nick until next time all right thanks ross application modernization is sponsored by red hat the world's leading provider of enterprise open source solutions including hybrid performing linux cloud container and kubernetes technologies thank you for listening to application modernization a podcast for high growth software companies don't forget to subscribe to the show on your favorite podcast player so you never have to miss an episode.

And if you use Apple Podcasts, please do us a favor and leave us a quick rating by tapping the stars. Join us on the next episode to learn more about modernizing your infrastructure and applications for growth. Until next time.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Ep. 313: A Method for the Madness - What Transformation Actually Looks Like Phase by PhaseWorkCookie · features Nick83 / 100
  • Avoiding Scams: Coffee Break Episode 22Almost Productive: A podcast mostly about marketing · features Nick49 / 100
  • Where Do I Begin? Dipping Your Toes in AI for Your BusinessDave Learns AI: A Taptico Solutions Production · features Nick40 / 100
  • From Compliance Theater to GRC Infrastructure: Why AI Breaks Traditional GRC ft Jasmine Kaur, Principal of Security & Assurance Engineering @ CoreWeaveSecurity & GRC Decoded · on Kubernetes96 / 100
  • Ship It Conversations: Jake Warner on Cycle.io, Bare Metal’s Comeback, and Why Private Cloud Is Getting Interesting AgainShip It Weekly · on Kubernetes91 / 100
  • Kubernetes and retiring at the top with Kelsey HightowerThe Pragmatic Engineer · on Kubernetes90 / 100

More from Application Modernization

All episodes →
  • Solving the Kubernetes Talent Shortage
  • Inheriting Kubernetes Day 1
  • Feature Flags and Toggle Management Reduce Developer Stress and Increase Productivity
  • Monolithic to Microservices
  • Innovation Series Part 3 - Viability
Explore the best B2B Marketing podcasts →
All Application Modernization episodes →