Click here to close now.

Welcome!

@DevOpsSummit Authors: Elizabeth White, Liz McMillan, Tech Spot, Louis Evans, XebiaLabs Blog

Blog Feed Post

Interview: Peter Coffee on Leveraging the Web’s Transformation

Noel Wurst: Hello, this is Noel Wurst with Skytap and I am speaking today with Peter Coffee. Peter is the VP for Strategic Resource at salesforce.com and he's also going to be taking part in the SDLC Acceleration Summit on May 13th in San Francisco, California. Peter how are you doing today?

Peter Coffee: It's great to with you Noel. I'm fine, thank you.

Noel Wurst: Great, awesome. Well, I was going to say that I had the privilege of reading your bio online. I recommend listeners go online and check it out for themselves. It's such a varied background, you've done a little bit of everything. I saw everything from aerospace, the defense sector, alternative fuel research, video game development, and I was curious as to what you're working on now with Salesforce or outside of there. What's piquing your interest these days?

Peter Coffee: May job was created seven years ago at salesforce.com, three years after I had a breakfast conversation with Marc Benioff about what it would take to let people build things on the web; We didn't call it the cloud seven years ago. as readily as some of the tools like Hypercard or Visual Basic or letting them build things on desktops and get rid of idea that you had to build the app with all of the same complexity and difficulties and then have addition compounded difficulties putting it up online. But instead, be able to get to something that allowed you to build it as readily as if you were just going to run it on your PC, and then make it securely and reliably available to people anywhere. That was the vision for what the next generation platform needed to be. And if you think about it, the web went from being a medium where you can publish stuff for other people to read, to posting stuff on which other people could comment, to now where it really is a medium for taking what you know and packaging it in a way that makes it available for other people to use.

There was a peer research report that just came out recently that said, you've got to stop thinking of the World Wide Web as the world's library and start to think of it as the world's supercomputer.

Peter Coffee: That's really what has fascinated me in all of the areas where I've been fortunate to have the opportunity to work, is that we have tremendous facilities available to us now. Not to look at one or two isolated blank ideas about what might work and then pick the one that works the least badly. But really to start mapping and entire spaces of solutions that are available to problems and really being to hunt for something close to optimality on how we get stuff done. I think that's what's really exciting in every field today, is the opportunity to pursue optimality instead of settling for incremental improvement.

Noel Wurst: It's definitely an exciting time to be in that field with all the different capabilities that are popping up day by day and month by month. I noticed that the session you’re giving at the SDLC Acceleration Summit—the session or panel that you're going to speaking on is titled, “Faster In What Direction?

Peter Coffee: Yes.

Noel Wurst: The abstract warns specifically against “accelerating a legacy model or mistaking it for progress.” 

Peter Coffee: Yes.

Noel Wurst: And, like you were just saying, with everything changing so much and changing so quickly, I was wondering if maybe there is an enterprise or a company that is changing quickly—what are maybe some of the warning signs that should maybe alert themselves that maybe they’re not moving in the right direction? Or maybe they are changing quickly, but maybe it's not for the best.

Peter Coffee: The interesting thing about the place that's loosely called “Pod Computing” is that it's very much like a supermarket in which you can walk in, and if you know what you're there to buy—it's there. If you go to the rice and beans aisle you'll find sacks of ingredients at an attractive price. And you'll take them home and you'll have to do a lot of work before you can put the food on the table. But if it occurs to you to look in another direction, well over there's the deli counter where there's some very interesting things that you might not even attempt to create yourself, that are ready for you to consume pretty much as soon as you get them home and pop them in the microwave.

That's really where the cloud marketplace is today. You've got the infrastructure cloud of virtual servers that you can spin up by the minute or the hour and do traditional skills intensive, error prone, complex and innovation limited IT at an attractive cost. 

Then you've got the platform as a service and software as a service markets where you can find tremendously innovative best practices solutions available for you to use immediately and modify and tailor to become uniquely yours. I think that's the biggest caveat that I have to offer people who are attracted by the obvious economies and accelerations that virtualizing legacy IT can provide, and who think that that constitutes victory when they aren't realizing that the next logical step is to move beyond wiring up their virtual machines the way they wired up their physical ones. Instead say, “well what if I were thinking about what I do? What if I was thinking about application construction as composition and orchestration of services and the linkage at the API level, instead of composition of hardware and linkage at the binary data transfer level?”

Noel Wurst: That's a really great analogy, the “rice and beans aisle” that you said before. That's exactly what the situation is. There's all these options out there for people to change for the better, and to be able to accelerate their entire business, or the SDLC. But at the same time, it's still really difficult for people to change. Even if they see the success that other companies have had by changing and by reinventing their processes. 

But I was kind of curious as to ... I know why it's hard for people to change. But what are some of the things, the reasons that those who are still maybe embracing somewhat outdated technologies. What are some of the reasons that they shouldn't fear that change? Besides just, “it'll get better” or “it's going to be great in the end.” The ones where that's not enough to convince someone to make that kind of investment or make that kind of change. What are some reasons to not fear that path or completely different direction for their business?

Peter Coffee: It's perfectly logical for people who've invested years or decades in mastering a set of skills to seek reasons to believe that those skills are going to continue to be the definition of their value and the source of their livelihood to the rest of what they hope will be a healthy and lucrative career. It’s completely logical for them to look for that validation. We know from any number of different research fields, that people will find confirming evidence for what they want to believe, and will be remarkably successful, even if unconsciously ignoring disconfirming evidence. So I completely get this and I don't attribute bad motives to anybody.

Noel Wurst: Right.

Peter Coffee: What I do find is that there are some organizations that are starting to look at this as much more of an opportunity to have greater leverage and to catalyze dramatic improvements. For example, I was just at the headquarters at one of our customers, USAA, which is a massive insurance company that primarily sell their services to military and ex-military. You've seen their advertising.

Their annual technology forum, their in-house event, has 3,000 people attending it. It’s the size of one of our larger metropolitan events. They asked me to come and do a seminar on how the IT department could best serve, what they call, “the citizen developer”—which I believe might be a phrase that Forrester might have been the first to popularize. If you think about the way that the spreadsheet allowed people to model and experiment with a process, instead of having to go hat in hand to the business analyst, and beg for some COBOL to do that work. 

It's the next logical step to go beyond the spreadsheet on a network share with an email thread wrapped around it to something like a Force.com app that runs in the cloud, has proper security, auditability, governability, back-up built in as a service, and the IT department can tremendously increase its value to the business by providing what we might call adult supervision to the citizen developer. 

To provide guidance on compliance, process integrity, data dictionary discipline and so on. And the IT departments that are starting to say, “You know, tugging the old workload and keeping that to ourselves is a poor strategy for increasing our value to the organization compared to being vigorous and creative in providing support to the business units.” In taking advantage of the lower barriers to entry and the considerably higher productivity they can have by building what will be a much more disciplined application.

Everyone talks about Shadow IT today. It's this dark matter of the IT universe that doesn't shine with its own light and it's very hard to find it. But we all know it's out there stretching from desktop databases and other things that are not visible, not governed, not recalled, not auditable, and not really contributing to a store of knowledge that turns the company into a learning organization. The IT departments that I think are doing very well, and there are existing groups of these, they’re saying, “Our best contribution is to take things that a very difficult to learn and very easy to do wrong and still have an enduring value like basic disciplines of process integrity and find a way to sprinkle those on top of the old coffee of the legacy infrastructure and turn it into something that's much more exciting.”

Noel Wurst: That’s so great. It reminds me, I also had the chance to interview Theresa Lanowitz, who's also going to speaking at The SDLC Acceleration Summit, and we were talking specifically about the “extreme automation” that comes from utilizing some of these new technologies and it's like you were just saying as far as the way things were done in the past. 

The definition she had of extreme automation, I asked her to define it, was “solving classic problems with new technology and tooling.” Essentially saying people who are maybe of skeptical of automation, or are very quick to say, “Well automation doesn't solve everything,” basically she was saying automation doesn't solve everything, but at the same time, it's not solving anything new that you haven't seen before. It's solving a problem that may have existed in your organization for years. It may have been problems that is kind of just always laid around because there wasn't extreme automation there to help solve those.

I was curious if you would maybe define extreme automation the same way or basically see the same value that it solves the problems that are well-known, well documented and widespread across multiple enterprises.

Peter Coffee: Well, I don't know if you remember, there was a minor sub-plot in the book of Jurassic Park that I think they decided was too complicated to bring forward into the movie, about how the eye of the frog doesn't even bother to tell the brain about things that aren't moving. Because the brain wants to focus on things that are moving and therefore might be targets for eating. The eye doesn't even bother to tell them about the stationary things. I think a lot of us are really good at ignoring stationary problems that have been with us for so long that we stop even to think of them even as problems and just think of them as part of the environment.

I like the phrase of “extreme automation” because it invites us to go and, pardon the expression, rip the scabs off some of those old wounds and say, “Can we afford intellectually and financially to reexamine some of our assumptions about things that we're just going to have to tolerate. Because maybe we don't have to tolerate them anymore.” That can require some creativity and it can also require taking some risk. Because you're going to be bringing these ideas to senior managers who may have built their careers on the existence of these “problems” and of the construction of elaborate and complicated work arounds to these problems. And you're essentially coming in and saying, “Yeah but, what if we stopped calling that problem something that we have to tolerate at all?  What if we just destroy it? What if we just cut the Gordian knot, to use another old metaphor. Instead of spending tons of effort, time, and money untangling something—we just cut it in half. That's a career risk and an intellectual challenge and a skills and technology challenge.

But there is always something going on at any given time that forces that kind of disruption. Back in the 1960s everybody was worried about the space race. So we had projects Apollo, which did some things at the time that were considered frankly impossible  until people felt that they had to find a way to do them. Then they discovered ways to do it. I think our next project Apollo is the aging of the baby boomers who are going to need adaptive and assistive technology. To make it possible for them to age gracefully at home instead of going into nursing homes which we simply won't be able to afford to build at that kind of scale.

So things like a Nest thermostat are really just kind of the tip of that spear in terms of saying, “You know, we need to rethink automation from something that lets people program things to do stuff into devices and algorithms and systems that are aware of an environment, learn what's normal, call attention to that which is abnormal and therefore perhaps requires someone to do something—and that's really where we need to go with business IT as well. It’s to get beyond the idea of the bigger and bigger dashboard with more and more performance indicators and get to much smarter systems that notice when things that have been behaving in a coordinated way suddenly don't seem to be coordinating. That suggests an anomaly that detects for data science disciplines what I might call “pre-failure signatures” and are able to say, “I don't know why this is happening. But I know that when it does happen, a week later something much much worse usually happens. So then you'd want to take a look at this now.”

This is a very interesting time for developing new categories of algorithms that don't just capture the byproduct of business activity, but inspect those patterns and look for interesting high leverage points that allow people to take an inexpensive action at the right time instead of a much more costly disaster recovery or damage control action later on.

Noel Wurst: That's all so great. And then lastly, it's all kind of come to this. It's interesting, all of this technology we've been discussing of course involves the cloud. But I watched a video on YouTube recently of a presentation you did at PhillyForce last year that was titled “Connecting Above the Cloud.”

It's funny, I'm writing an article this week about the same thing, and I'm going to use a piece of your your presentation in the article. You talked about the cloud metaphor and how the industry didn't choose that term. You said that “connected” and “social” work a lot better than just saying “the cloud.” To quote you from that presentation, you said, “The cloud is only interesting because of the connections that it enables.”

That's really interesting, because I think we've only said the word cloud two times in this whole interview. Back in the day, “cloud” was in every other sentence. I feel like even though cloud adoption of course is going up, and all kinds of news came out this week about how it’s ramping up quickly—yet, we're saying the word “cloud” less and less. I really like the way that successful enterprises have been able to enable these connections between their customers.

But I also like how much the cloud, to go ahead and say it again, has enabled developers, testers, IT, DevOps, and all this connectivity that goes on kind of behind the curtain, not just among the people who are kind of using these apps. I was kind of wondering if you might maybe expand on how this technology is helping enterprises themselves, but not just not just the consumers who use these apps.

Peter Coffee:Sure. Well, you know it's almost an accident of history that Intel had a commercial imperative to develop the integrated circuit and the microprocessor before it became practical to have a global standard spaced wired and wireless network. Because we had a period of several years, a little over a decade really, when we went from the 4004 microprocessor, which was barely enough to run a four-function calculator, to things like 32bit computers on a chip. 

During that time connectivity was expensive, slow, and intermittent. I compared it the other day to being colonist on Mars with our little bubbles of air and having to put on a spacesuit to go from one to another. Inside that bubble which was in the IT world, inside your data center or inside your local area network, you could be reasonably comfortable. But as soon as you wanted to do something that involved going from one bubble to another, well this was a perilous exercise. You had to use your dial-up modem or it was like putting on your spacesuit for a brief moment of interconnection with another bubble somewhere else.

During this time, we've essentially been terraforming planet computing. We've got an atmosphere now that you can breathe without putting on a spacesuit and if there's still people walking around with air tanks on their banks, that they call their “private cloud.” Okay, and it doesn't make any more sense in the world of IT then it would make sense in a world of a terraformed Mars. To ignore the fact that the environment now is different. The environment is now of ubiquitous connectivity with what was comparable with what we used to find more than sufficient in an office building. You can see this in the behavior of people. They are saying, “Now wait a minute, why would I buy a laptop computer, which is essentially a spacesuit? It's its own hard drive, display, battery, keyboard all this stuff and all. All I really need is a little magic piece of black glass which might be the size of a phone or it might be the size of a tablet. All I need is that thing which is a window into this world of available information, computational capability, connection with other experts, connection with algorithms and supercomputing facilities.” 

There's an awful lot of stuff that used to sort of make sense to build more and more powerful desktop machines to do. But people are now saying, “But wait a minute. I don't actually want to do that on my desktop at all. I don't want to video editing on my desktop, I want to upload the clip from my smartphone to YouTube and let YouTube worry about things like compression algorithms and making it run on different devices and things like that.” This is a hard challenge. It's to get beyond thinking of the cloud as a product and start thinking of the cloud as just an enabler for things that are much more interesting products.

Because if I can drag one more metaphor in, I once said, a gourmet chef does not talk about the miracle of clean water being available from a faucet whenever he needs it. He assumes that's going to be there because you can't really talk about doing cooking without it. But once you've got it, you don't really think about it very much. You don't think about the miracle of electricity when you're building your home theater. That's invisible. That's assumed and you're thinking instead about what's the amazing experience I can that create given the assumption of that pervasive reliable cost-effective resource.

It's really important to get beyond cloud and start thinking about, “Wait a minute, what do I have to do to step up my game? To be a value creator by using this medium of connection, by using processing power and algorithms of discovery and analysis, to create a kind of customer experience, or the kind of government first-response in a disaster, or the kind of life-long delivery of education that were never really feasible to discuss until we had this remarkable atmosphere in which we breathe data and breathe computational power whenever we need it.”

Noel Wurst: Well, that is all I have for you today. I am really looking forward to attending your presentation at The Summit as well as the other ones that are going on there. Again, everyone, this is Peter Coffee, the VP for Strategic Research at salesforce.com. Peter speaks all over the world, and he’s going to be at the SDLC Acceleration Summit in San Francisco, California on May 13th. Thank you so much for speaking with me today.

Peter Coffee: Thank you very much. I always tell people I never know what I think until I have to answer questions. So, these conversations always tell me things that I didn't realize I was thinking about until I have them. Thank you for the time.

Noel Wurst: Awesome, thank you. 

Read the original blog entry...

More Stories By Skytap Blog

Author: Noel Wurst is the managing content editor at Skytap. Skytap provides SaaS-based dev/test environments to the enterprise. Skytap solution removes the inefficiencies and constraints that companies have within their software development lifecycle. As a result, customers release better software faster. In this blog, we publish engaging, thought provoking stories that revolve around agile enterprise applications and cloud-based development and testing.

@DevOpsSummit Stories
With major technology companies and startups seriously embracing IoT strategies, now is the perfect time to attend @ThingsExpo in Silicon Valley. Learn what is going on, contribute to the discussions, and ensure that your enterprise is as "IoT-Ready" as it can be! Internet of @ThingsExpo, taking place Nov 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with 17th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. The Internet of Things (IoT) is the most profound change in personal an...
SYS-CON Events announced today that EnterpriseDB (EDB), the leading worldwide provider of enterprise-class Postgres products and database compatibility solutions, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. EDB is the largest provider of Postgres software and services that provides enterprise-class performance and scalability and the open source freedom to divert budget from more costly traditional solutions to more strategic data-driven initiatives. EDB’s Postgres Plus Cloud Database provides t...
T-Mobile has been transforming the wireless industry with its “Uncarrier” initiatives. Today as T-Mobile’s IT organization works to transform itself in a like manner, technical foundations built over the last couple of years are now key to their drive for more Agile delivery practices. In his session at DevOps Summit, Martin Krienke, Sr Development Manager at T-Mobile, will discuss where they started their Continuous Delivery journey, where they are today, and where they are going in an effort to constantly bring new offerings to market.
In a recent research, analyst firm IDC found that the average cost of a critical application failure is $500,000 to $1 million per hour and the average total cost of unplanned application downtime is $1.25 billion to $2.5 billion per year for Fortune 1000 companies. In addition to the findings on the cost of the downtime, the research also highlighted best practices for development, testing, application support, infrastructure, and operations teams.
SYS-CON Events announced today that the "First Containers & Microservices Conference" will take place June 9-11, 2015, at the Javits Center in New York City. The “Second Containers & Microservices Conference” will take place November 3-5, 2015, at Santa Clara Convention Center, Santa Clara, CA. Containers and microservices have become topics of intense interest throughout the cloud developer and enterprise IT communities.
Buzzword alert: Microservices and IoT at a DevOps conference? What could possibly go wrong? In this Power Panel at DevOps Summit, moderated by Jason Bloomberg, the leading expert on architecting agility for the enterprise and president of Intellyx, panelists will peel away the buzz and discuss the important architectural principles behind implementing IoT solutions for the enterprise. As remote IoT devices and sensors become increasingly intelligent, they become part of our distributed cloud environment, and we must architect and code accordingly. At the very least, you'll have no problem fil...
Enterprises are fast realizing the importance of integrating SaaS/Cloud applications, API and on-premises data and processes, to unleash hidden value. This webinar explores how managers can use a Microservice-centric approach to aggressively tackle the unexpected new integration challenges posed by proliferation of cloud, mobile, social and big data projects. Industry analyst and SOA expert Jason Bloomberg will strip away the hype from microservices, and clearly identify their advantages and disadvantages. He will then discuss the role microservices play in cloud-enabled enterprise integrati...
SYS-CON Media named Andi Mann editor of DevOps Journal. DevOps Journal is focused on this critical enterprise IT topic in the world of cloud computing. DevOps Journal brings valuable information to DevOps professionals who are transforming the way enterprise IT is done. Andi Mann, Vice President, Strategic Solutions, at CA Technologies, is an accomplished digital business executive with extensive global expertise as a strategist, technologist, innovator, marketer, communicator, and thought leader. For over 25 years and across five continents, he has built success with Fortune 500 corporation...
Announced separately, New Relic is joining the Cloud Foundry Foundation to continue the support of customers and partners investing in this leading PaaS. As a member, New Relic is contributing the New Relic tile, service broker and build pack with the goal of easing the development of applications on Cloud Foundry and enabling the success of these applications without dedicated monitoring infrastructure. Supporting Quotes "The proliferation of microservices and new technologies like Docker has transformed how modern software is built and managed today," said Patrick Lightbody, vice presiden...
You often hear the two titles of "DevOps" and "Immutable Infrastructure" used independently. In his session at DevOps Summit, John Willis, Technical Evangelist for Docker, will cover the union between the two topics and why this is important. He will cover an overview of Immutable Infrastructure then show how an Immutable Continuous Delivery pipeline can be applied as a best practice for "DevOps." He will end the session with some interesting case study examples.
For customers that want to build their own custom apps, Kony’s Enterprise Mobility Platform meets the development needs across the full mobile app development and operations (DevOps) lifecycle. This full DevOps solution encompasses unique app UI design tools (Kony Visualizer) and the leading multi-channel app dev tools (Kony Studio), empowered by Kony’s Mobile Backend as a Service (MBaaS) offering (Kony MobileFabric), as well as testing and analytics. It extends fully to the end user through the addition of Kony Apps, which allow customers to get to market faster.
The 5th International DevOps Summit, co-located with 17th International Cloud Expo – being held November 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA – announces that its Call for Papers is open. Born out of proven success in agile development, cloud computing, and process automation, DevOps is a macro trend you cannot afford to miss. From showcase success stories from early adopters and web-scale businesses, DevOps is expanding to organizations of all sizes, including the world's largest enterprises – and delivering real results. Among the proven benefits, DevOps is cor...
Actifio, the copy data virtualization company, today announced a series of new features and functional enhancements to better support the growing number of customers leveraging its virtual data pipeline technology in support of DevOps use cases. While infrastructure is increasingly seen as a commodity inside large enterprises, applications – where the technology touches the business – are becoming more strategic. Managing the flow of data that powers those applications presents a range of challenges at every stage of their lifecycle.
The 17th International Cloud Expo has announced that its Call for Papers is open. 17th International Cloud Expo, to be held November 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA, brings together Cloud Computing, APM, APIs, Microservices, Security, Big Data, Internet of Things, DevOps and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding business opportunity. Submit your speaking proposal today!
DevOps Summit, taking place Nov 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA, is co-located with 17th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long development cycles that produce software that is obsolete at launch. DevOps may be disruptive, but it is essen...
The recent trends like cloud computing, social, mobile and Internet of Things are forcing enterprises to modernize in order to compete in the competitive globalized markets. However, enterprises are approaching newer technologies with a more silo-ed way, gaining only sub optimal benefits. The Modern Enterprise model is presented as a newer way to think of enterprise IT, which takes a more holistic approach to embracing modern technologies.
Security can create serious friction for DevOps processes. We've come up with an approach to alleviate the friction and provide security value to DevOps teams. In her session at DevOps Summit, Shannon Lietz, Senior Manager of DevSecOps at Intuit, will discuss how DevSecOps got started and how it has evolved. Shannon Lietz has over two decades of experience pursuing next generation security solutions. She is currently the DevSecOps Leader for Intuit where she is responsible for setting and driving the company’s cloud security strategy, roadmap and implementation in support of corporate innova...
Software-driven innovation is becoming a primary approach to how businesses create and deliver new value to customers. A survey of 400 business and IT executives by the IBM Institute for Business Value showed businesses that are more effective at software delivery are also more profitable than their peers nearly 70 percent of the time (1). DevOps provides a way for businesses to remain competitive, applying lean and agile principles to software development to speed the delivery of software that meets new market requirements. IBM's new DevOps Innovation Services help address the challenge of s...
“Oh, dev is dev and ops is ops, and never the twain shall meet.” With apoloies to Rudyard Kipling and all of his fans, this describes the early state of the two sides of DevOps. Yet the DevOps approach is demanded by cloud computing, as the speed, flexibility, and scalability in today's so-called “Third Platform” must not be hindered by the traditional limitations of software development and deployment. A recent report by Gartner, for example, says that 25% of Global 2000 companies will be DevOps shops by next year! “As we see more IT shops running like software companies, we’ll see mor...
JFrog on Thursday announced that it has added Docker support to Bintray, its distribution-as-a-service (DaaS) platform. When combined with JFrog’s Artifactory binary repository management system, organizations can now manage Docker images with an end-to-end solution that supports all technologies. The new version of Bintray allows organizations to create an unlimited number of private Docker repositories, and through the use of fast Akamai content delivery networks (CDNs), it decreases the download time of large Docker repositories, speeding DevOps work significantly. Bintray’s highly availa...
More organizations are embracing DevOps to realize compelling business benefits such as more frequent feature releases, increased application stability, and more productive resource utilization. However, security and compliance monitoring tools have not kept up and often represent the single largest remaining hurdle to continuous delivery. In their session at DevOps Summit, Justin Criswell, Senior Sales Engineer at Alert Logic, Ricardo Lupo, a Solution Architect with Chef, will discuss how to successfully integrate security controls in your DevOps program.
17th Cloud Expo, taking place Nov 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy. Meanwhile, 94% of enterprises are using some form of XaaS – software, platform, and infrastructure as a service.
Thanks to Docker, it becomes very easy to leverage containers to build, ship, and run any Linux application on any kind of infrastructure. Docker is particularly helpful for microservice architectures because their successful implementation relies on a fast, efficient deployment mechanism – which is precisely one of the features of Docker. Microservice architectures are therefore becoming more popular, and are increasingly seen as an interesting option even for smaller projects, instead of being reserved to the largest, most complex application stacks.
The speed of product development has increased massively in the past 10 years. At the same time our formal secure development and SDL methodologies have fallen behind. This forces product developers to choose between rapid release times and security. In his session at DevOps Summit, Michael Murray, Director of Cyber Security Consulting and Assessment at GE Healthcare, examined the problems and presented some solutions for moving security into the DevOps lifecycle to ensure that we get fast AND secure.
In his session at DevOps Summit, Tapabrata Pal, Director of Enterprise Architecture at Capital One, will tell a story about how Capital One has embraced Agile and DevOps Security practices across the Enterprise – driven by Enterprise Architecture; bringing in Development, Operations and Information Security organizations together. Capital Ones DevOpsSec practice is based upon three "pillars" – Shift-Left, Automate Everything, Dashboard Everything. Within about three years, from 100% waterfall, Capital One now has 500+ Agile Teams delivering quality software via Agile and DevOps practices.