JBoss Application Platform Q&A

Yesterday we started a series of Web Casts covering JBoss Application Platforms (Recording, Slides). We didn’t manage to cover all the questions in the Q&A so as promised here they are :

Q: When using your Apache & Tomcat bundled software, do you provide any additional security patches above and beyond what the Apache & Tomcat communities provide ?

A: Red Hat has a dedicated Security Response Team who’s role is to track alerts and security vulnerabilities in the community which may affect users of Red Hat products and services. They work with Open Source communities to identify, classify, diagnose and coordinate fixes. If Red Hat discovered a vulnerability in any Open Source project we would work with the community to coordinate a fix, we wouldn’t keep it secret.Where we might differ from the upstream project is in how we communicate the presence of vulnerabilities and deliver fixes to our customers.


Q: can you guys point out to any benchmarks on jboss as in comparison to the other j2ee containers available (ideally updated every once in a while) online for the people who look into jboss AS evaluation to come and compare it easily with the other AS and

We don’t currently have any public benchmarks comparing JBoss to other vendors. All proprietary vendors have specific restrictions in their EULA forbidding use in benchmarks, so the only viable way to provide a comparison is by comparing vendors submissions for some thing like SPECjAppServer2004. JBoss has long argued that SPECjAppServer2004 does not represent contemporary use of modern app. servers (a position that IBM now agree with) as such we’ve never paid much attention to SPECjAppServer2004 and we’ve never made a public submission. JBoss has been working with SPEC on a new benchmark which we think does better represent modern application server usage and we will, in time, provide our own public submissions.

Meanwhile, many customers who have moved large deployments from our proprietary competitors to JBoss typically cite overall cost saving as the main reason. Performance and overall cost are tightly linked.


Q: what is the official release date of EWP ?

A: Right now the best date I can give you is that it will be released sometime in this Calendar Quarter.


Q: why isn’t seam part of the web toolkit ?

A. That’s the long-term goal. ie. to separate the frameworks from the run-tmes as they typically evolve at different rates. We also want all the frameworks to be certified on all the run-times. This is a form of Pace Layering and I think it provides the greatest flexibility / agility.


Q: What is the level of support you give spring as part of the web toolkit ?

A. With the first version of the Web Framework Kit – Spring is a Technical Preview and not recommended for production use. The intention is to promote Spring to fully supported in the next minor release.


Q: why do you think glassfish managed to have jee5 server so soon ?

A. Because Sun is the spec. lead for Java EE – they have to deliver the Spec., the Reference Implementation and the TCK. It’s impractical for anyone to deliver an implementation before Sun. Just as it is impractical for anyone to deliver an implementation of Java CDI before Red Hat (the spec. lead).


Q: Are these versions (EWS, EWP, EAP) available in the community version, or only the enterprise version ?

A : The community version for EWS is Tomcat, mod_jk and Apache HTTP – you can see the exact versions included in EWS here. JBoss EWP only exists as a ‘profile’ in AS 5.1. You can see the exact component versions for the platforms on their respective web pages, eg. component page for JBoss EAP.


Q: When will EAP 5.0 be Java EE 6 certified ?

A. There is no plan to certify EAP 5.0 with the EE 6 TCK. EAP 5.0 supports Java EE 5, though it does include some features of Java EE 6 – specifically JAX-RS (RestEasy) and the Web Profile. If you want to see ho were progressing with Java EE 6 then take a look at JBoss AS 6.


Q: I would like easier upgrade path in RH Jboss vs jboss.org when you have your customized apps.. or is this a no problem ?

A : As long as you’re using the same base versions – portability should not be a problem. You can use this page to see what version level of components are included in EAP.


Q: What type of improvements are you looking at in order to support Cloud environments ?

A. Here are some of my thoughts :

  • Larger managed domains, possibly shared across BUs, requiring delegated administration and isolation.
  • More automated – everything needs to be easily automated or autonomous by design
  • Automation is just as likely driven by pre-defined policy as by a human sys. admin.
  • Better support for virtualized environments
  • Lower resource utilization
  • More dynamic – eg. to deal with elasticity – grow and shrink environments depending on pre-defined policies

Bob McWhirter and Marek Goldmann have been experimenting and prototyping some of these areas as part of the StormGrind project – take a look.


Q: Would web application developed in Jboss work on tomcat ?

A: JBoss EWP / EAP is a superset of Tomcat – as long as you limit your app. to use just the Web Container (ie. Servlet, JSP) – your app. will be portable. The web-container in JBoss EWP / EAP is based on Tomcat 6.0.18 so obviously supports the same versions of the Servlet (2.5) and JSP (2.1) specs. Tomcat 6.0.18 is also what we include in JBoss EWS.


Q: are there any limitations in the number or requests handled by using mod_jk ?

A. Good one – let me find out. Check this space for an update.
A. I checked with Jean-Frederic Clere, his response is :
“Apart from the OS limitations and httpd limitations (configuration in
httpd.conf, MaxClients for example) there aren’t any limits in the
number of requests mod_jk could handle.”


Q. where can I get the slides ?A. At some point they’ll appear along with the recorded sessions here.

5 Reasons to submit a paper for JBoss World 2010

Screen shot 2010-01-13 at 3.56.35 PM.png

There are only 9 days left to submit your talks for JBoss World 2010, in case you need them, here are some good reasons :

  1. It’s in Boston, In June. It’s a great city and the snow and ice will probably be mostly gone by June.
  2. You get a free conference pass, good for all Red Hat Summit / JBoss World sessions, keynotes, events, meals and parties
  3. You get one free night accommodation (in a hotel)
  4. It’s very likely IMHO that there won’t be a Java One this year – if you are looking for an opportunity to talk about what you’re doing with JBoss technology then this is *the* best place to do it.
  5. If you want to get into the weeds with highly technical content – then there’s a new track for that.

Call for Papers end in just 9 days !

Red Hat Summit :: JBoss World :: Boston :: 2010

Screen shot 2009-11-17 at 12.15.43 PM.png

Red Hat Summit :: JBoss World :: Boston :: June 22-25, 2010

I think I’ve just about recovered from the last JBoss World. Chicago is a fun place and I’m glad I finally got to spend some time there; next year it’s in one of my favorite cities – Boston. From the email :

A comprehensive agenda allows you the unique opportunity to move between both conferences, and learn about open source advancements through:

  • technical and business seminars
  • hands-on labs and demos
  • customer case studies
  • networking opportunities
  • partner displays
  • visionary keynotes
  • direct collaboration with Red Hat engineers

Sign up for special discounts and 2010 Red Hat Summit and JBoss World updates

Interested in presenting at the 2010 Red Hat Summit and JBoss World? Call for papers will open soon! Make sure to sign up for our “Call for Papers Alert List” on the 2010 Red Hat Summit and JBoss World website.

We’re looking forward to seeing you at the 2010 Summit and JBoss World in Boston, June 22 – 25, 2010.

Follow us on Twitter.
Watch the 2010 Red Hat Summit and JBoss World video.

JBoss : Vision and Execution

Another nice score card from Gartner puts JBoss Enterprise App. Platform in the leader’s quadrant of the Gartner Magic Quadrant for Enterprise Application Servers. That’s the fourth year in a row, in case you were wondering. Unscientific as it is – comparing with last year I’d say the leaders are widening the gap (cumulative advantage ?) and JBoss specifically has inched up on the Ability to Execute axis.

Interestingly, Salesforce.com were joined by a couple of other PaaS vendors in the MQ this year – it will be interesting to see if there really is a new wave of infrastructure bearing down on the established platforms. The contemporary PaaS offerings I see today under-achieve as general purpose developer platforms and that leaves them competing with IAAS based on more traditional / established technology (Java, .NET) on cost and convenience terms. It will be good to see “Cloud” get beyond the current over-hyped phase so we can see how this will play out.

More Red Hat commentary here.

JBoss EAP 4.3 Achieves Security Certification

cc-logo

A few weeks back JBoss Enterprise App. Platform 4.3 achieved Common Criteria Certification at Evaluation Assurance Level (EAL) 2+ – here’s the press release and here’s the evaluators updated page.

Common Criteria Evaluation is an internationally recognized standard that defines a  framework for computer systems users to specify security requirements; for vendors to implement them and for third-party evaluators to test them. The Evaluation process ensures that this is all carried out in a consistent, formalized and standard way.

The Evaluation Assurance Level (EAL) describes the “depth and rigour” of the evaluation not necessarily the security hardness. Though products certified at Level 7 (the highest) are likely to be deployed more demanding and secure environments than a product certified at Level 1 (the lowest). EAL 2+ means the products have been evaluated in collaboration with the vendor (eg. to provide development, design and test documentation).

What this means is that customers who care about security (who doesn’t ?) can be assured that JBoss Enterprise App. Platform 4.3 will meet commonly accepted, best practice security requirements. Even outside military and government use, who use Common Criteria as a benchmark, this evaluation should demonstrate Red Hat’s commitment to security. It’s a long and fairly involved process and the costs aren’t insignificant.

This is the first successful evaluation for a JBoss product but the JBoss Data Services Platform is currently in process and we’re already planning for a more stringent evaluation (higher EAL) for JBoss EAP 5.x.

JBoss Open Choice, Part 1 – JBoss Enterprise Web Server

It’s July 4th and we have an extended weekend in the US which is a good enough excuse to catch up on some blogging; at least until the Strawberry Margaritas start flowing. At Java One this year we announced an initiative called Open Choice which I blogged about previously. Fundamentally Open Choice is about broadening our footprint and giving customers what they want and moves us closer to supporting the whole applications infrastructure tier rather than just parts.

Open Choice isn’t some big, far-into-the-future vision thing it’s something we’re doing now. This year. Product-wise it consists of four offerings (where previously there was only one) and as we release them I’ll give you my perspective on why they’re important. Unfortunately I’m already a little behind – we’ve already delivered two products out of four and the third is in Alpha moving quickly towards Beta.

So let me use this post to talk about JBoss EWS 1.0 (Enterprise Web Server). EWS is basically a packaged, certified and tested bundle of Tomcat and Apache HTTP – the industry’s dominant Java web-container and Web Server respectively. We round out the bundle with mod_jk, APR and most importantly a management agent for JBoss ON. We currently support and certify on Red Hat Enterprise Linux and Solaris with Windows coming next.

Providing JBoss ON management support is pretty important – it gives customer the ability to manage the application and web stacks easily and consistently using the same toolset. If you want to learn more – there is a free Webinar on July 14th at 2pm Eastern – more here.

The rationale for supporting Tomcat is that it is absolutely the dominant Java web-container and has become an important part of the corporate IT fabric. Tomcat has been popular for years but in the last two or three  I’ve seen it evolve into a much more strategic platform for IT. Many customer I speak with have defined two distinct tiers of functionality – essentially a full Java EE stack and a lighter-weight Tomcat platform. By supporting both the dominant Java EE implementation (JBoss EAP) and Tomcat, combined with the ability to manage from a single tool – I think we can do a much better job of satisfying a much broader customer base than our competition. Here’s an (albeit unscientific) chart from a recent survey that demonstrates this well :

Most often use Java EE containers

It’s also interesting to note that from this survey JBoss’ deployment share is more than Websphere and Weblogic combined.

OK, so JBoss EWS 1.0 is out and we have customers deployed or deploying some pretty large, strategic apps. but I’m already thinking about the next version (code named Cavalier). Some initial ideas for Cavalier are :

  • increasing platform support to include AIX, HP-UX and maybe other Linux flavours;
  • alternative Connection Pool implementations for Tomcat;
  • looking at a more recent version of Apache HTTPD;
  • possibly supporting mod_cluster.
  • soft-appliances to better support virtualized hosts.

Any other thoughts are always welcome – leave a comment or get in touch directly.

JBoss + eXo = Open Source advantage

jboss-exo

This week, we announced a partnership with eXo – creator of the Open Source eXo platform. This strategic agreement allows us to integrate and distribute each others’ technology thus providing a mutual competitive advantage. This is no doubt good for both company’s products but I think the important point is that JBoss is 1. willing to do this and; 2. able to do this.

Taking the first point – “we’re willing to do this”. I think it shows a level of maturity in our organization that stands us apart from some of our Open Source competitors. The realization that not everything needs to be invented here; that there are smart people outside JBoss as well. There’s a tendency – call it NIH Syndrome, Professional Pride – to want to own and control everything; that’s true for every engineering and product company I’ve ever worked for. When taken too far – that can be at add odds with Open Source and diminishes some of its advantage.

Taking the second point further -  “we’re able to do this”. Our business model is still pretty unique – we put less value on the bits and more on the whole experience. Control of the technology is less of a competitive advantage than some of our competitors because we have more to offer than the bits.

While proprietary software has some advantages – they’re all based on the premise that your technology is better than your competitors and keeping it hidden maintains some kind of advantage. This can only really be true half the time.

Red Hat has the knowledge and experience that allows us to collaborate, allows us to integrate and support technology that we don’t outright control. We’re also confident in ourselves, our brand and our business strategy – and that allows us to see the act of ‘enriching’ other technology (like Apache, OpenJDK, GWT, eXo, etc.) as a way to grow our footprint, capabilities and potential rather than as a competitive faux-pas.

Update :

Some more info on the agreement from eXo : About The eXo Partnership

JBoss Open Choice

Earlier this week we announced a couple of things. First, a change in our platform strategy, second some new products to implement that strategy. We felt we had to give that strategy a name and “Open Choice”, while unoriginal, best illustrated what we’re doing. And what we’re doing is expanding our support to include Open Source technologies  beyond what we’ve typically supported and beyond the JBoss constellation.

This is a reaction to a) customer demand; and b) the realization that not all the cool stuff is created by JBoss. What we’re also doing is reacting to market demand. Java EE, while hugely successful is not the only game in town any more.

j2ee-spring1

We want to ensure that our customers get to choose whatever frameworks, languages, development models they want without causing major disruption for the operations people who have to manage the applications for the other 90% of the application lifecyle (ie. outside development). We also want to remove the risk of deploying new developer oriented tech. by providing a stable, consistent operational footprint (JBoss) to run the resulting apps.

Note – I normally don’t use Job Trends data in isolation to make serious decisions, but it’s convenient and lazy way to find what keywords are trending.

So yes, this is a reactive move; we’re reacting to customer demand and market pressure – we’re really not reacting to anything that Spring Source is doing. I’ll post another blog explaining what we’re including in our Web Framework Kit and why; but Spring Framework is included for much the same reason as struts – they’re mature technologies and both are very widely deployed :

spring-struts

It’s no secret that a big chunk of our business comes from our much larger but less nimble competitors and we have to ensure that migration is a simple and low risk proposition.

spring

As the chart shows (if you have any faith in the data) – Spring Framework usage is fairly evenly distributed across the Java container landscape. By making JBoss a better place to run Spring (among other things) – I believe that we can change this landscape dramatically.

This really isn’t about Spring Source – in fact we don’t even compete with Spring Source. Our sights are set much higher.

New – JBoss MASS – Migration Analysis Tool

jbossmass_logo_450px

It’s been just over 3 months since we created the JBoss MASS project and today we’re announcing the first major code contribution – The Migration Analysis Tool (MAT) was created by Mitch Mocle and team at Middleware Connections. The tool is used as a starting point for estimating the effort required to migrate a group of J2EE applications  from an Oracle/BEA WebLogic environment to a JBoss AS / JBoss EAP environment.

The tool produces detailed HTML reports covering Server Configuration, Deployed Applications and Class Dependencies. Read More on the MAT sub-project page.

This is an important first step. The goal of JBoss MASS is to provide a common place to develop tools for migrating to JBoss – if you have or are thinking of developing such a tool and think that Open Source collaboration might be a good way to enhance and maintain the technology – get in touch.