Welcome!

@DevOpsSummit Authors: Jason Bloomberg, Stackify Blog, Aruna Ravichandran, Otto Berkes, Ayman Sayed

Related Topics: @DevOpsSummit, Microservices Expo, Linux Containers, Containers Expo Blog

@DevOpsSummit: Article

Rugged DevOps | @DevOpsSummit #DevOps #Agile #Microservices

An interview with James Wickett and Ernest Mueller from theagileadmin.com on Rugged DevOps, silos, and W. Edwards Demings

You might already know them from theagileadmin.com, but let me introduce you to two of the leading minds in the Rugged DevOps movement: James Wickett and Ernest Mueller. Both James and Ernest are active leaders in the DevOps space, in addition to helping organize events such as DevOpsDays Austinand LASCON. Our conversation covered a lot of bases from the founding of Rugged DevOps to aligning organizational silos to lessons learned from W. Edwards Demings.

Wickett: Hi, I'm James Wickett. I work over at Signal Sciences. I've been doing stuff in the DevOps space for quite a while and am interested in security as well.

Mueller: Hello, I'm Ernest Mueller. I work at AlienVault. I've also been in the DevOps world for a long time. James and I have worked together a lot in the past, and we blog together at the agile admin.com.

Weeks: There is a lot of conversation going on around Rugged DevOps. Is this the end of traditional security as we know it, or is there a place for what security has been doing all along to coexist with some new ways?

Mueller: Certainly. Every field has to continue to innovate to survive. And InfoSec is no exception. IT operations is no exception. The reason that we attend the  and that there is a DevOps track is because IT infrastructure operations and systems professionals have the same issues. Right? The long lead times, bottlenecks, not being well-aligned with your customers. And we managed to find a way out of that using leading principles, using agile principles, to where we could improve the state of things.

Can the old coexist with the new? It certainly can for a time. I think, though, there is an extent to which the new modes of thinking in the end have to be adopted or you die out, right. You're still doing your core thing. You are providing IT operations or you are providing security, but the way you do that has to change and keep pace with business demands.

Every field has to continue to innovate to survive. And InfoSec is no exception. IT operations is no exception.

Wickett: We talk about this in our presentation on lean security here at the conference. It is not so much of a question of "replacement" or "is traditional security going to be around longer?" It is just going to look a lot different.

The really cool thing (and what Ernest mentioned as well) is we both worked together in operations shops in the past. That was five or eight years ago when operations was then where security is now. Operations today looks dramatically different than it did 10 years ago. I think the same thing is going be true about security. (See slides from Ernest and James.)

Weeks: When I talk to a security audience about how they interact with development, they are like, "Ah, we have no access to development." When I speak to development communities about security they are like, "Ah, don't let those guys in the room."

Part of the Rugged DevOps conversations is not only how do you bring security into development, but how do you bring it in early enough into the development life cycles. How have you been able to bring security in and bring it in early?

Operations today looks dramatically different than it did 10 years ago. I think the same thing is going be true about security.

Mueller: Again, this is one of the core problems that DevOps faced at its initiation, where that exact same dialog occurred between developers and operations.

There are a number of techniques you can use. But what you have to understand is that you are looking at an underlying culture change. There is no silver bullet for that, and so it can take years. But aligning both the people that are trying to do the work and the management that is trying to organize it to understand-that sort of close collaboration throughout the entire pipeline is what's important.

And there are some times where you have to power through it. I remember early on in our DevOps implementation at National Instruments. We had started having design reviews with developers and operations personnel that were in the same room. The application architect approached me and said, "These guys keep asking us questions that we don't really even understand or know the answers to about capacity or about reliability. Maybe we should just have separate reviews." I said to him, "Well, you have two options. We can continue to do them separately, and we can continue to not understand each other. Or, we can do it together and power through it. And it really shouldn't take all that long before we do start to understand each other because we all have the same goal, which is to ship these products."

I said to him, "Well you have two options. We can continue to do them separately, and we can continue to not understand each other. Or, we can do it together and power through it."

So we powered through it, and it really didn't take that long for everybody to finally get to a good point where they could understand and collaborate with each other. But it took determination to get there.

Wickett: I think that was really, really well said. We are having that conversation where we're saying we do need to shift left. We are saying we do need to make it earlier. We've kind of seen the writing on the wall. How do we get there?

I think there are some practical approaches. We are just taking small steps. I have seen people do this at different organizations. There have been a lot of talks on this. But when putting security into your continuous integration in your delivery chain, I think there is a huge gap.

I work at Signal Sciences so it is one of the things we do. But there is a huge gap in the operations knowing whether we are under attack, why are they attacking and what are they trying to do. Right? And I am not saying you need to buy our product to get that done but there is ...

Image title

Lean Security from SeniorStoryteller

Weeks: I'll say it. You do need to buy his product.

Wickett: Good, please, say that.

But it's amazed me how often shops have no idea what's actually going on. They don't really know what parts are being attacked. They don't know what's happening on their site. They don't have any sort of security operational telemetry coming back to developers or to management.

As we've seen in lean, those are the invisible things. You've got to make them visible. I don't know what that's going to mean for people's organizations. I could make a bunch of random recommendations, but take the principle of making those invisible things visible and start trying to apply it.

Take the principle of making those invisible things visible and start trying to apply it.

Weeks: Building on that: Part of the whole discussion around DevOps is rapid feedback loops. How do you get information from people as quickly as possible so that they can be informed and take action on that?

Mueller: Absolutely. Well, I think we've seen a lot of fledgling successes in that area. James is the core contributor to an open source product called Gauntlet that introduces security testing into continuous integration processes. We've seen presentations at other conferences, from Twitter and from Etsy, where they've built these security warning systems very, very early on that notify the people that are actually creating the flaw as they are creating it.

W. Edwards Deming said that we can't ensure quality by mass inspection after the fact. We have to build integrity into the product as we create it. Unfortunately, a lot of security thinking today is built around mass inspection after all of the mistakes have already been made and then trying to go back and get somebody to do rework of a product that has already shipped, that's already making money, that's already out there in customer deployments, whatever. That's always inherently going to be a much more difficult route at ensuring actual security.

We can't ensure quality by mass inspection after the fact. We have to build integrity into the product as we create it.

Wickett: In some ways, we've built this problem ourselves. We do compliance on an annual basis. Compliance is built around the waterfall mechanism, and security is a function of compliance or something that they try to accomplish. It's very antithetical to fast feedback loops. It's very antithetical to rapid cycles. So we need to find ways to break that down into more discrete chunks that can happen on a daily or weekly or hourly or per-code-commit basis.

Weeks: How did the rugged DevOps movement originate?

Wickett: Rewind to 2009 or so, and there are the first signs of DevOps kind of coming through. There is the agile operations thing. People were talking about velocity that year. The first DevOpsDays by Patrick Dubois happened. Flickr says that we're doing 10 deploys a day. And just everybody loses it.

At the same time, Josh Corman came out with the Rugged Software Manifesto in 2010. I read that. And Ernest and I were both latching onto DevOps at that time, and we were trying to do some cloud-based implementations but really focused on the DevOps-centric vision around that.

We told ourselves, "We can't just stop at Dev and Ops. We have got to have security." And this is while we were taking a lot of telemetry data from Internet of Things (IoT) types of devices and thinking that's going to need to be secure if we ever wanted to get a customer on that. So we really started to try to put that together.

We can't just stop at Dev and Ops. We have got to have security.

We stumbled across the rugged stuff, and at the same time, we just really felt like rugged and DevOps were two things that were moving in different tribes. They were both trying to accomplish very similar-type missions. In Austin, we run the DevOpsDays event there. We have a lot of security folks in the Austin area. It's the capital of Texas, so there are a lot of folks related to that.

It seems like the DevOpsDays we've had there have a very security-focused push every year, and the rugged language really struck more of a cord than security. To me, that's a rough brief history of how that's come about.

Weeks: James, you also run LASCON in Austin, which is a great security conference. It has a DevOps track where security and development or DevOps come together.

You are both thought leaders yourselves. But who else do you listen to? If you could tell someone reading this, "Here is someone that you should see at a conference or look for their video on YouTube," who would you recommend?

Mueller: Obviously, the list of presenters here at the Rugged DevOps Summit is a litany of many of the best-in-class people to hear speak, whether it's Josh CormanJohn Willis or Damon Edwards. I could list the entire set. People that aren't here, like Pete Cheslock, have done a lot in merging both DevOps and security.

Wickett: Throw in Nick Galbreath who I work with now. I really kind of saw him doing some of the same stuff, and I really dig that. Gene Kim, of course, would be a good fit.

I love learning from Patrick Dubois. When he speaks on anything, I am really interested in what it is. He is doing more mobile stuff these days but always good stuff there. Anybody else?

Zane Lackey, too. I also work with Zane.

Weeks: That's a great list. Thanks!

Hey, DevOps Austin is coming up in the beginning of May. Is the call for papers still open?

Mueller: That's right, the 2nd and 3rd of May this year.

The DevOpsDays Austin call for papers is open, call for sponsors is open, and tickets are being sold, although early birds are sold out already, so I recommend that people move quickly.

We're in our fifth year. The last couple of years, we have been filling up our venue at 500 people. We have actually moved venues to the University of Texas Darrell K. Royal-Texas Memorial Stadium this year, so we have a little bit more space, and we're riding on more tracks. We're riding on a hack-a-thon actually.

It's interesting. One of the things you have to be careful about in this whole thing is not losing the developers.

One of the things you have to be careful about in this whole thing is not losing the developers.

People that were very involved in OWASP for a long time saw that started off as a developers and security sort of thing. And over time, unfortunately, that relationship was lost a little bit, and they've had challenges as a result.

Now we are like, "How do we get the developers back collaborating with security?" We're trying to make really sure that there is a lot of interest in DevOps out of the operations space, and so that can sometimes start to push out the content the developers find compelling.

We've added a content tract and a hack-a-thon to try to make it super compelling to developers this year.

Weeks: Excellent. James, I think you guys just secured a Series A. Is that right? Should we tell people you are hiring at Signal Sciences? Is AlienVault hiring too?

Wickett: Yes, I think Signal Sciences is hiring both in the L.A. area and across a lot of remote positions. The engineering team has a number of remote members.

Mueller: Absolutely, we are hiring too. We have teams in Austin, out here on the West Coast and in Ireland. Our original office was in Madrid, Spain. So we have a lot of folks there if we have any international readers on the blog.

Weeks: Excellent. Perfect. I appreciate you guys spending time with me. Absolutely enjoy the conference, and we'll point people to the recording of your session as well.

Wickett: Cool.

Mueller: Super.

Wickett: Thanks, Derek.

Weeks: Thank you very much.

If you loved this interview and are looking for more great stuff on Rugged DevOps, I invite you to download this awesome research paper from Amy DeMartine at Forrester, "The Seven Habits of Rugged DevOps."

Image title

As Amy notes, "DevOps practices can only increase speed and quality up to a point without security and risk (S&R) pros' expertise. Old application security practices hinder speedy releases, and security vulnerabilities represent defects that can leave a company open to cyberattacks. But DevOps practitioners can leap forward with both increased speed and quality by including S&R pros in DevOps feedback loops and including security practices in the automated life cycle. These new practices are called Rugged DevOps.

More Stories By Derek Weeks

In 2015, Derek Weeks led the largest and most comprehensive analysis of software supply chain practices to date across 160,000 development organizations. He is a huge advocate of applying proven supply chain management principles into DevOps practices to improve efficiencies, reduce costs, and sustain long-lasting competitive advantages.

As a 20+ year veteran of the software industry, he has advised leading businesses on IT performance improvement practices covering continuous delivery, business process management, systems and network operations, service management, capacity planning and storage management. As the VP and DevOps Advocate for Sonatype, he is passionate about changing the way people think about software supply chains and improving public safety through improved software integrity. Follow him here @weekstweets, find me here www.linkedin.com/in/derekeweeks, and read me here http://blog.sonatype.com/author/weeks/.

@DevOpsSummit Stories
DX World EXPO, LLC, a Lighthouse Point, Florida-based startup trade show producer and the creator of "DXWorldEXPO® - Digital Transformation Conference & Expo" has announced its executive management team. The team is headed by Levent Selamoglu, who has been named CEO. "Now is the time for a truly global DX event, to bring together the leading minds from the technology world in a conversation about Digital Transformation," he said in making the announcement.
SYS-CON Events announced today that Conference Guru has been named “Media Sponsor” of the 22nd International Cloud Expo, which will take place on June 5-7, 2018, at the Javits Center in New York, NY. A valuable conference experience generates new contacts, sales leads, potential strategic partners and potential investors; helps gather competitive intelligence and even provides inspiration for new products and services. Conference Guru works with conference organizers to pass great deals to great conferences, helping you discover new conferences and increase your return on investment.
DevOps is under attack because developers don’t want to mess with infrastructure. They will happily own their code into production, but want to use platforms instead of raw automation. That’s changing the landscape that we understand as DevOps with both architecture concepts (CloudNative) and process redefinition (SRE). Rob Hirschfeld’s recent work in Kubernetes operations has led to the conclusion that containers and related platforms have changed the way we should be thinking about DevOps and controlling infrastructure. The rise of Site Reliability Engineering (SRE) is part of that redefinition of operations vs development roles in organizations.
In his Opening Keynote at 21st Cloud Expo, John Considine, General Manager of IBM Cloud Infrastructure, led attendees through the exciting evolution of the cloud. He looked at this major disruption from the perspective of technology, business models, and what this means for enterprises of all sizes. John Considine is General Manager of Cloud Infrastructure Services at IBM. In that role he is responsible for leading IBM’s public cloud infrastructure including strategy, development, and offering management. To date, IBM has launched more than 50 cloud data centers that span the globe. He has been building advanced technology, delivering “as a service” solutions, and managing infrastructure services for the past 20 years.
The next XaaS is CICDaaS. Why? Because CICD saves developers a huge amount of time. CD is an especially great option for projects that require multiple and frequent contributions to be integrated. But… securing CICD best practices is an emerging, essential, yet little understood practice for DevOps teams and their Cloud Service Providers. The only way to get CICD to work in a highly secure environment takes collaboration, patience and persistence. Building CICD in the cloud requires rigorous architectural and coordination work to minimize the volatility of the cloud environment and leverage the security features of the cloud to the benefit of the CICD pipeline.
"ZeroStack is a startup in Silicon Valley. We're solving a very interesting problem around bringing public cloud convenience with private cloud control for enterprises and mid-size companies," explained Kamesh Pemmaraju, VP of Product Management at ZeroStack, in this SYS-CON.tv interview at 21st Cloud Expo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.
Enterprises are adopting Kubernetes to accelerate the development and the delivery of cloud-native applications. However, sharing a Kubernetes cluster between members of the same team can be challenging. And, sharing clusters across multiple teams is even harder. Kubernetes offers several constructs to help implement segmentation and isolation. However, these primitives can be complex to understand and apply. As a result, it’s becoming common for enterprises to end up with several clusters. This leads to a waste of cloud resources and increased operational overhead.
"Infoblox does DNS, DHCP and IP address management for not only enterprise networks but cloud networks as well. Customers are looking for a single platform that can extend not only in their private enterprise environment but private cloud, public cloud, tracking all the IP space and everything that is going on in that environment," explained Steve Salo, Principal Systems Engineer at Infoblox, in this SYS-CON.tv interview at 21st Cloud Expo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.
22nd International Cloud Expo, taking place June 5-7, 2018, at the Javits Center in New York City, NY, and co-located with the 1st DXWorld Expo will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy. Meanwhile, 94% of enterprises are using some form of XaaS – software, platform, and infrastructure as a service.
"CA has been doing a lot of things in the area of DevOps. Now we have a complete set of tool sets in order to enable customers to go all the way from planning to development to testing down to release into the operations," explained Aruna Ravichandran, Vice President of Global Marketing and Strategy at CA Technologies, in this SYS-CON.tv interview at DevOps Summit at 21st Cloud Expo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.
Vulnerability management is vital for large companies that need to secure containers across thousands of hosts, but many struggle to understand how exposed they are when they discover a new high security vulnerability. In his session at 21st Cloud Expo, John Morello, CTO of Twistlock, addressed this pressing concern by introducing the concept of the “Vulnerability Risk Tree API,” which brings all the data together in a simple REST endpoint, allowing companies to easily grasp the severity of the vulnerability. He provided attendees with actionable advice related to understanding and acting on exposure due to new high severity vulnerabilities.
While some developers care passionately about how data centers and clouds are architected, for most, it is only the end result that matters. To the majority of companies, technology exists to solve a business problem, and only delivers value when it is solving that problem. 2017 brings the mainstream adoption of containers for production workloads. In his session at 21st Cloud Expo, Ben McCormack, VP of Operations at Evernote, discussed how data centers of the future will be managed, how the public cloud best suits your organization, and what the future holds for operations and infrastructure engineers in a post-container world. Is a serverless world inevitable?
SYS-CON Events announced today that CrowdReviews.com has been named “Media Sponsor” of SYS-CON's 22nd International Cloud Expo, which will take place on June 5–7, 2018, at the Javits Center in New York City, NY. CrowdReviews.com is a transparent online platform for determining which products and services are the best based on the opinion of the crowd. The crowd consists of Internet users that have experienced products and services first-hand and have an interest in letting other potential buyers learn their thoughts on their experience.
SYS-CON Events announced today that Telecom Reseller has been named “Media Sponsor” of SYS-CON's 22nd International Cloud Expo, which will take place on June 5-7, 2018, at the Javits Center in New York, NY. Telecom Reseller reports on Unified Communications, UCaaS, BPaaS for enterprise and SMBs. They report extensively on both customer premises based solutions such as IP-PBX as well as cloud based and hosted platforms.
A strange thing is happening along the way to the Internet of Things, namely far too many devices to work with and manage. It has become clear that we'll need much higher efficiency user experiences that can allow us to more easily and scalably work with the thousands of devices that will soon be in each of our lives. Enter the conversational interface revolution, combining bots we can literally talk with, gesture to, and even direct with our thoughts, with embedded artificial intelligence, which can process our conversational commands and orchestrate the outcomes we request across our personal and professional realm of connected devices.
DevOps promotes continuous improvement through a culture of collaboration. But in real terms, how do you: Integrate activities across diverse teams and services? Make objective decisions with system-wide visibility? Use feedback loops to enable learning and improvement? With technology insights and real-world examples, in his general session at @DevOpsSummit, at 21st Cloud Expo, Andi Mann, Chief Technology Advocate at Splunk, explored how leading organizations use data-driven DevOps to close their feedback loops to drive continuous improvement.
SYS-CON Events announced today that Evatronix will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Evatronix SA offers comprehensive solutions in the design and implementation of electronic systems, in CAD / CAM deployment, and also is a designer and manufacturer of advanced 3D scanners for professional applications.
Sanjeev Sharma Joins June 5-7, 2018 @DevOpsSummit at @Cloud Expo New York Faculty. Sanjeev Sharma is an internationally known DevOps and Cloud Transformation thought leader, technology executive, and author. Sanjeev's industry experience includes tenures as CTO, Technical Sales leader, and Cloud Architect leader. As an IBM Distinguished Engineer, Sanjeev is recognized at the highest levels of IBM's core of technical leaders.
We all know that end users experience the Internet primarily with mobile devices. From an app development perspective, we know that successfully responding to the needs of mobile customers depends on rapid DevOps – failing fast, in short, until the right solution evolves in your customers' relationship to your business. Whether you’re decomposing an SOA monolith, or developing a new application cloud natively, it’s not a question of using microservices – not doing so will be a path to eventual business failure.
"Cloud4U builds software services that help people build DevOps platforms for cloud-based software and using our platform people can draw a picture of the system, network, software," explained Kihyeon Kim, CEO and Head of R&D at Cloud4U, in this SYS-CON.tv interview at 21st Cloud Expo, held Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA.
Is advanced scheduling in Kubernetes achievable?Yes, however, how do you properly accommodate every real-life scenario that a Kubernetes user might encounter? How do you leverage advanced scheduling techniques to shape and describe each scenario in easy-to-use rules and configurations? In his session at @DevOpsSummit at 21st Cloud Expo, Oleg Chunikhin, CTO at Kublr, answered these questions and demonstrated techniques for implementing advanced scheduling. For example, using spot instances and cost-effective resources on AWS, coupled with the ability to deliver a minimum set of functionalities that cover the majority of needs – without configuration complexity.
As DevOps methodologies expand their reach across the enterprise, organizations face the daunting challenge of adapting related cloud strategies to ensure optimal alignment, from managing complexity to ensuring proper governance. How can culture, automation, legacy apps and even budget be reexamined to enable this ongoing shift within the modern software factory? In her Day 2 Keynote at @DevOpsSummit at 21st Cloud Expo, Aruna Ravichandran, VP, DevOps Solutions Marketing, CA Technologies, was joined by a panel of industry experts and real-world practitioners who shared their insight into an emerging set of best practices that lie at the heart of today's digital transformation.
SYS-CON Events announced today that Synametrics Technologies will exhibit at SYS-CON's 22nd International Cloud Expo®, which will take place on June 5-7, 2018, at the Javits Center in New York, NY. Synametrics Technologies is a privately held company based in Plainsboro, New Jersey that has been providing solutions for the developer community since 1997. Based on the success of its initial product offerings such as WinSQL, Xeams, SynaMan and Syncrify, Synametrics continues to create and hone innovative products that help customers get more from their computer applications, databases and infrastructure. To date, over one million users around the world have chosen Synametrics solutions to help power their accelerated business and personal computing needs.
As many know, the first generation of Cloud Management Platform (CMP) solutions were designed for managing virtual infrastructure (IaaS) and traditional applications. But that's no longer enough to satisfy evolving and complex business requirements. In his session at 21st Cloud Expo, Scott Davis, Embotics CTO, explored how next-generation CMPs ensure organizations can manage cloud-native and microservice-based application architectures, while also facilitating agile DevOps methodology. He explained how automation, orchestration and governance are fundamental to managing today's hybrid cloud environments and are critical for digital businesses to deliver services faster, with better user experience and higher quality, all while saving money.
SYS-CON Events announced today that Google Cloud has been named “Keynote Sponsor” of SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Companies come to Google Cloud to transform their businesses. Google Cloud’s comprehensive portfolio – from infrastructure to apps to devices – helps enterprises innovate faster, scale smarter, stay secure, and do more with data than ever before.