Behind the Code: Jenkins Upgrades, Challenges and Evolution – The CD Pipeline EP15
In this episode, Alan Shimel and Lori Lorusso sit down with key maintainers of the Jenkins open-source project to explore their experiences with major upgrades and significant improvements to Jenkins. Join Mark Waite, Basil Crow, Damien Duportal and Kris Stern as they dive into the challenges of managing a project with a large user base, a long history, and how evolving trends in software development have shaped the platform.
Transcript
Hey everyone. I'm Alan Shimel of Techstrong and you're watching CD Pipeline. CD Pipeline.
A case you've never heard of it before is a joint venture between our good friends at the CD Foundation and Continuous Delivery Foundation, part of the UX Foundation, and us here at techron. com and Cloud native Now, security Boulevard among others. And of course, tech Strong tv, which hopefully you're watching this on.
Um, we get together about once a month for, uh, the CD pipeline show, and we, and we explore various areas that are in germane, you know, to, to continuous delivery in the CD foundation. The CD Foundation is the caretaker manager of some of the greatest software in the world, bar none, whether we're talking cd, open source commercial or not. We've got projects like Spinnaker and Jenkins and so many others.
Lori Lorusso, my cohost is gonna tell us about them when I introduce her. But today's show we're really gonna focus in on Jenkins and, and look, Jenkins is died, I think it's 12 to 15 years old now. I don't remember exactly, but it still represents 40 plus percent of all the CI users organizations out there are still using Jenkins.
So by far the biggest single ci uh, product in use. But this isn't your grandpa's Jenkins. A lot's come under a lot of water under that bridge since it forked from Hudson all those years ago.
It's gonna be a great discussion. Let me introduce you to an all star panel for this. First of all, he's a veteran of our panels.
Every time we have a Jenkins, he's always kind enough to volunteer his time and he volunteers a lot more of his time than he does just here on our shows. He is a board member and has been for a long time, my friend Mark Waite. Hey, mark, welcome.
Thank you, Alan. Thanks so much. Give us a little bit of your background.
Mark, I I mentioned you're a Jenkins board member, but there's a lot more there, a lot of meat on that boat. So I've, I've actually served in the past as Jenkins documentation officer, so I care about writing. I've served as a Jenkins core maintainer and as a maintainer of the get plugin and a few other plugins.
So I cared deeply about keeping Jenkins relevant, current, and valuable to our users. And that matters a lot to me. Now.
I, I came from a commercial software background, so open source was kind of a different transition for me, and that transition has been a lot of fun. I've learned a bunch by being part of it, and I'm really thrilled actually to be able to welcome other people to help with projects that are open source and have something to offer to the world at whole as a whole. Fantastic, mark, thanks for jumping on.
My next guest, and I'm gonna do my best on his name is Damien Duportal. Yeah, thanks. Hello.
Yes, hi, Damien, how are you? Damian, how are you? Damien is well, why don't you introduce yourself?
I, you can do a better job than I can. No problem. So, my name is Damien Duportal.
I'm the currently elected, uh, infrastructure officer for the Jenkins project. So I have a background on the infrastructure side. Uh, on the past I worked for French public state, uh, infrastructure project for public websites.
And also I have a background in training engineers and teaching in engineering school, uh, teaching CI/CD, uh, some architectural design on infrastructure side and a bit of development on go along language and Java languages. Fantastic. David, here we are.
Sorry, go ahead. No, no, go ahead. No, Brad, you are.
I'm, I'm done. Oh, okay. David, thank you so much for joining us.
I appreciate it. My next guest who I have to give special, special kudos to, 'cause she's joining us in the middle of her evening, in the middle of her night, forget the evening. Um, she's from in Hong Kong today.
It's Chris third who's the Jenkins organization administrator for Google Summer of Code. Chris, thank you so much for joining us. Tell us a little bit about yourself, but if you wouldn't mind a little bit about Google Summer of code as well.
Yeah, sure. So, um, I got into software engineering, the gza or Google Summer of code, uh, as we call it as well. So, um, I started, I think, I think the first time I contributed was in 2019 with open astronomy, but that was like before I was acting in Jenkins.
And, um, I first started like, uh, when I was doing the PhD in thesis, uh, that's when I did most of my software development in Python. So, um, I did, I think I did twice with op astronomy, uh, in JSO. So I was in, uh, 2019, was in 2020, and then, uh, I, and then, and then I graduated in 2021.
And, and, um, that's when I started contributing to the Jenkins. So first I start off, um, as a contributor and then moved on to, uh, become, um, a GO org admin at GO Mentor. And then I think I started to become a maintainer, like in, um, maybe it was around, uh, 2021 as well, mark to remember that.
So I'm not very sure. But, uh, and, and then I, I, I picked up like so far four plugins also, I have become like a copy editor for Jenkins IO website as well. And, um, I think, I think I've been contributing for, for in Jenkins since, for, uh, for a few years.
Fantastic. And, and for those folks who don't know, Jenkins was a summer of code, uh, designated project. And, and Chris, if you wanna lead the discussion on that, but the rest of you can join in, right?
One, what Google selects you for summer of code. I mean, it's just, I mean, it's worth its weight in gold kind of in terms of the, the, the exposure, the resources that are made available, the, you know, the, the, the audience. I mean, just, there's so many good things that being A-G-S-O-C designated project helps with, right?
And it, and it also, it also represents kind of the creme de la creme, if you will, the top of the deep in many ways of, of an, of a project, of an open source project. Because being selected a designee from GSO, you know, there's a very formal process that you have to go through. And being selected is no easy feat.
It, it's quite a, it's quite a accomplishment. So Chris, thank you for all you do in helping to maintain the project as well as being the administrator for GS o and kind of the bridge there, if you will. Yeah.
Um, so, and then thank, you know, thank you for being on today. Let us go next now though to Basil Crow. We have quite a lineup today.
I'm very impressed. Basel, why don't you introduce yourself? Sure.
Uh, I'm a Jenkins Governance board member and a core maintainer. Uh, I've been using Jenkins since 2012. So actually the one constant in my career is that every single day of my career I've been looking at Jenkins console logs.
So, um, you know, I started contributing to Jenkins in 2014 and maintaining some plugins in 2018. And fast forward a few years, and I'm working in CloudBees as a principal engineer on Jenkins day in and day out. Um, I have a background in OS and networking, uh, from Brown University.
And I previously worked on file systems and databases at Delphix. Uh, so I bring this kind of os systems background to what I do on Jenkins. I love it.
Um, da, I got a silly question for you. You're much younger than me, but do you envision that you'll be working on Jenkins for the entirety of your career? Well, I had a, I had a previous manager who said that no one is gonna retire at Delphix.
And I think that's an interesting, you know, perspective because, you know, technologies do change and people's careers change, but I found a lot of, uh, joy and comfort in working on Jenkins over the years. You know, I really love the community, I love the technology, so, you know, for me it's something that I would like to be involved in, uh, for quite a while. Um, but of course the world around us is always changing, so we can never make these predictions with certainty.
I got it. Well, welcome and thanks for being here, man. I appreciate it.
Last but not least, she's my friend, is returning. She's missed the last couple episodes as she's pursued her career goals and ambitions, but we nailed her down for today, and I'm really happy to in introduce you to my friend Lori Lorusso. Hey, Lori, welcome.
Tell people a little bit about you and what you're doing these days. Hey Alan, you have been missed by me as well. Uh, so I am the head of community at Ruano, which is great.
So working in open source databases, which is just a lot of fun. Um, I, I think the first episode that we did, Alan was on Jenkins, so this is kind of like, it was like a year ago or so, so this is kind of a nice coming back to, I think it might have been two years, two, Okay, now we're aging ourselves. Don't, uh, you know, uh, but, so this is fun.
And, um, so yeah, so CDF ambassador, really happy to be back with the, the whole CDF crew here today. Um, we wouldn't be around if it wasn't for Jenkins. So to have all these different perspectives, yours included in terms of like, the history of what's going on in the future, it is gonna be a really good show.
Fantastic. Thanks Lori. I appreciate you.
Alright. So look, as I said in the outset, this ain't your Grandpa's Jenkins. Well, it is, it's still Jenkins.
It still does CI and CD still has a whole bunch of plugins that work with it, right? But it's not, it's not the St. Jenkins.
com. Let's talk big things, big picture. What have been some of the biggest improvements, developments, changes in how we use Jenkins versus how we did then?
And maybe we could talk about how we think we'll use Jenkins going forward. If it's okay, I'd like to ask Dan Demian or Basel. 'cause you guys, you, you've got Jenkins dirt under your fingernails, right?
What, what, how do you answer that question? Either one of you? Uh, ba if you may, because on my case, I haven't changed my usage of Jenkins since, since a few years.
Uh, but it was already, uh, unusual, unusual back in time. Uh, it was used for de up to deployment. Uh, and it still is.
The thing is, uh, with the, the arrival of new players, uh, free players that are hosted, we start to show a discrepancy between people who want CI CD system managed by someone else we paid or managed by themselves. Um, what I've seen though in the past years is that we have more and more specialized computing when you use the dedicated hardware like, uh, automotive industry, for instance, where they use, uh, testing hardware and very specific hardware, uh, on these cases. It used to be manual.
Um, a tool like Jenkins, uh, has been used widely for them. And that's a very big change, at least in Europe, where I can see them, uh, because I don't know exactly why I have ideas, but generally they tend to avoid using cloud players. They prefer doing things themselves.
And that's where the power of Jenkins is, because it has been a workhorse for years. And that's its current, uh, relief, very big value for me and big change in the past year. So sir, so to add, add to what, uh, Damien said, I mean, um, when, when Jenkins started, it was developers running it under their desks in their offices.
And, um, you know, everything was static agents. Um, there was a lot of flakiness. Nowadays, Jenkins environments or CI environments in general are all run on ephemeral agents typically, uh, containers or virtual machines on some kind of cloud or even, uh, on a private cloud.
But that has been sort of the biggest, uh, transition I've seen in terms of stability. And that is also sort of changed the culture around Jenkins because now instead of developers kind of starting Jenkins controllers on their own, they're, uh, maintained by dedicated DevOps teams who have all sorts of security requirements and budgetary constraints and things like that. So that to me has been one of the biggest transitions that I've seen.
But to, to Damien's point, the fact that Jenkins is open source is a huge benefit because you can debug any problem that you have. You never have to be reliant on another company or another provider. Uh, you could truly have full control and ownership of your builds, which matters to a lot of Jenkins users.
And, um, yeah, and, and finally, the, the, uh, existence of competing free services, uh, I don't think that can continue forever, economically. Um, I mean, there might be, uh, proprietary alternatives that are offering free services for the time being, but I think eventually they will have to start turning the screws on customers and start charging money for those services. And at that point, the strength of Jenkins will be that it is and remains always open source.
Nothing is truly free. Go ahead, Lori. No.
Yeah. So one of the things that you brought up was security, and I did there, there's a talk that I give, and it's called securing your software supply chain. Um, no, securing your, well, anyway, so securing your supply chain, one open source project at a time, blah, blah, blah, blah.
But one of the things I love to highlight is Jenkins security plugins, like, or your plugins, your help check, right? So when you talk about the ecosystem continuing to grow and evolve, people can go to the plugins and get the health check to see if their plugin that they're gonna use is being maintained. If there's any like potential breaches, like how active it is.
And I think that's one of the benefits when you talk about the ecosystem continuing to grow, keeping it open source, is that you see what Jenkins is doing within itself to make sure that you are always using the right things or have, uh, the ability to, the freedom of choice. To your point, Alan, nothing is free, but the freedom of choice to say, okay, this one has got maybe an 87 health check and this one has a 99, let me use that plugin instead. I think that that's super cool.
And Mark, I know that's your project, right? Plugin, Plugin, plugin health score is a thing. You're right, that I, I like the, the transition that Basel described from desktops to clouds, right?
From sitting under somebody's desk, because it resonates from my, my journey that that was what happened to me is I started with it, that I needed it locally. I installed it myself, I cared for it, I watched over it, and eventually other people wanted it too. And it just got bigger and bigger.
And that, that evolution from small and simple to big and widely deployed is, has been a really good thing. Absolutely. I mean, look, I, I agree.
I, you know, looking back over the years, big, big picture things that have really helped shape OJ and the community, I think has been the advent of cloud native technologies, right? Moving to the cloud and cloud native and everything that goes with that. I think the other big thing has been that, you know, when Jenkins first started, it was all about ci, which is very much a dev, a developer kind of thing.
But you, you don't say CI without saying CD today, which is an ops thing. And, and that's DevOps. That's what's happened.
DevOps, right? CI/CD, um, now the, there's been other things though. I think the, the continued advancement of plugins, you know, Steve Jobs, when the, i, when they first did, did the iPhone, look, I had a Windows phone.
It did a lot of what the iPhone did when it first launched, believe it or not, right? But they said they asked Steve Jobs, what was the key to the iPhone? It was the AppSec, it was the app store, and there weren't a lot of AppSec when they first launched maybe a hundred, 150, but division of 10,000 AppSec and forget it, we probably have closer to a million AppSec, right?
The vision of those AppSec and how those AppSec keep the platform moving, the underlying phone stuff moving. Same thing happens here with Jenkins. It's the AppSec dummy, right?
It's all about the AppSec, because those AppSec give us the functionality no matter what new comes down the pike. That's how we plug it in. It's the plugins.
And, and so Laurie mentioned security. Yeah, security's done a current, but there's been so many more. Great.
And there still are, I don't know, mark, you probably know. I mean, at one time I know there were at least 1500 plugins, but I'm, I don't keep up on it. Yeah, We've, we've crossed 2000 now, 2000 plugins, and, and They, they keep arriving.
And I thought, I thought that eventually the, the thing would just stop because haven't we solved all the interesting problems? But the answer is apparently we have not solved all the interesting problems yet, and people keep bringing new and interesting things that help solve problems. Well, on that note, let's talk about new and interesting things, right?
We didn't think about AI in 2012, right? And what's, what, how's AI gonna affect how we use Jenkins and why people use Jenkins? And how, um, we didn't talk about multi-cloud environments and digital transformation right, in 2012, but that's certainly something that can continues to evolve here.
Um, I think it was Damon brought up that today a lot of people like to get their Jenkins hosted, whether it's paid for or free. I'm not going to get into the economics of it, but certainly when we have SAS ified or Sassy Jenkins or whatever you want to call it, right? How does that kind of continue to evolve and change here?
Um, security Lori brought up continues to, um, you know, evolve and become important here. Chris, you know, as with your experience with GSO and, and some of the other projects you've been involved in. I mean, this is a dynamic, it's a huge community, bigger than your average open source community, but it's so dynamic and it's so ever changing.
How do you know we're from where you sit in the middle of the night in c**k from where you sit, how do you, how do you see this and, and how does it play out? Um, I think with GSO, which is a program we run every, every year, if, uh, since we, um, we've been, um, gang selected, um, by, by Google to, uh, participate for, I think it passed, um, I don't remember when we started, but for at least since I was here, since 2021, we've been accepted every single year, uh, without like, uh, without fail. And I think there, there are like many, we have like many people expressed interest in, uh, wanting to participate and to contribute to Jenkins.
The, so, so, um, I, I would, I would put a number of, um, maybe hundreds per year, uh, as like, um, the number for how many people, um, would put in application, um, for like doing g with us. Uh, and, um, and also like, um, I think for, in terms of the numbers of mentors participating for, for Jenkins, it's, um, it numbers between 10 to 20 every year, I guess. So if I'm wrong, please correct me, mark.
And, um, so that's quite like, um, that, that's not a small number at all. Like in terms of, um, uh, G mentor oic, and, uh, because like comparing to the other oic I was, um, I was involved with, um, I think we, we have like, um, more people expressing interest and, um, but um, the, the problem we have, like for with, with JSO every year is to recruit mentors. Um, but we've been lucky to, uh, to have like, um, to have sufficient number, uh, people mentor our projects.
And, um, but um, I think, yeah, in terms of scale, we, we do have, um, a, like a, a sizable, uh, project to one every year, every summer. Yeah. Love it.
And look, it's a sizable project all around. It's, you know, in terms of the community, and I wanna dive into that in a moment. Well, first I wanna come back to like, you know, what's, what's in front of Jen, what's, you know, new developments, new things that we're, we're dealing with.
I mentioned ai, look where I sit here, it tech strong. It sucks the oxygen out of every conversation, right? You, you can't talk about anything tech without saying, okay, how are we using agent ai, generative ai, MLOps or ml, you know, machine learning, some people, you know, as a form of ai.
Um, how, how, and Mark I'll ask you because you kind of have that visionary role there, right? How do you see AI in all of its flavors? Well, so we, we did a, a generative AI project actually in Google summer of code that, that was experimenting with how can we use generative AI in, in a Jenkins kind of environment?
And I suspect we'll see that sort of assistive thing where it's trying to help intelligent human beings as they do their jobs more effectively. I'm, I'm not seeing a pattern that says, oh, we're going to replace intelligent human beings, but there's certainly a pattern of help, encouragement, suggestions, ideas that, that seem to be moving us forward. Now, will, do I ever expect Jenkins itself to suddenly be magically AI something or other?
I'm not sure I do, but I do see lots of opportunity for AI to help the people who use Jenkins in interesting ways. Anyone else on the panel with thoughts around Jenkins and ai? Sure.
I mean, I, I often, you know, do dependency upgrades. One of my main focuses in Jenkins is upgrading libraries and things like that. And there's so often that you'll see an upgrade of some library and things will start failing.
You know, builds will fail, tests will fail. You've gotta go fix compatibility. And there's so much data there that an AI could train itself on.
I mean, uh, just correlating things like an error message with a commit that fixes that problem. And that data all lives in a combination of your source control system and your CI system. So for example, the uh, pull request comes in from, let's say, depend a bot or whatever, and you know, you get your Jenkins build failure or your CI build failure from whatever CI system, and then you write the commit that fixes it.
That's all intensely valuable data to train a, a large language model. So I think we're gonna see people taking advantage of that in the future. Excellent.
Yeah, makes sense. Makes sense. Anyone else on that one?
Um, on the infrastructure and cost side as well, I see some things that could help, uh, when you have your build fading as basically explained, sometimes it's hard to immediately tell, is it an infrastructure issue? Is there currently an outage on A-W-S-U-S test one, like last Friday? Or is, is it problem due to the change being in being added by the user because we are doing CI continuously testing?
Is it an unexpected behavior or network issue? It's really hard to tell, but when you are a developer and you have a feedback, the, the root of the CI says, Hey, you want a quick feedback loop? If you see an error, something failed, is it because of your change or is it unrelated?
Then you are going to get a coffee and come back later. And in that area, we have a lot of data and it looks like that we see some determinism and I'm, I'm absolutely sure that in the future, people will build small thing on that area to help. Is it to an infrastructure problem to help, uh, during the phase one analysis to direct to the right operator?
Is it an infrastructure developer code issue? And in the same area, the cost management and ECI system is really hard to track on billing. You can see the billing at the end of the month and say, oh, it's a lot, I want to decrease it.
Right? But each build you are running has a cost, a direct cost, but also has a high value or not in order to tell should I run that, that build, that's the real question. Will it be valuable for my business or for my goals?
That kind of element is really hard between the Lori Lorusso and the infrastructure that have different pricing models. If you run it in-house, if it's AWS if it's a minor layer like digital c or eh or others, that's really hard to track. If you had abstract layers such as agents ephemeral or not, new CPUs changing often.
And also auditing a, the machine that, uh, costed un harm three months ago is now cheap as hell because there is a new CPU in the data center. All of these element are, are a stream in constant change using LLM here. I'm sure people will be able to give good indicators in the spirit of what Mark said, Hey, should I run that build?
Will it cost me so much and is it still the same cost as it was three months? If it's different, then I will change the hypothesis and I will change the behavior. I am really convinced that, uh, all the hay high system will have a huge added value for helping human on that matter, not replacing them here.
Got it. Makes sense. Guys, I wanna talk a little bit, um, oh wait, Lori, you have a question?
Yeah, sorry. Uh, no, No, it's okay. Uh, so yeah, so I think like every, so what you're talking about is like the future, but like, so then the question becomes, and I think GS o is a great example of this, is how does Jenkin, which is, you know, such a, a graduated project, continue to attract new contributors.
Like how do you continue to look new and fresh in the eyes of a developer? Because, you know, I would think people would wanna be small, you know, big fish in a small pond, but Jenkins is by no means a small pond. So like how do you keep attracting the new fish?
Yeah, so, so, so Google summer of code is certainly a major attraction. It really is. Alright, why is it a major attraction?
Well, the Jenkins project runs from four to six GSO projects every year, and the students, or the contributors that are selected for that are awarded 6,000 US dollars for their work. So they get a summer being paid to work. That's a strong incentive.
So we get a great collection of applicants for that. As prep for that. We've seen that Hack Tober Fest sponsored by Digital Ocean gives us another place where people say, oh, I want to test drive this.
They'll join Hack Tober Fest, they'll try their hand, they'll get ready. And between Hack Tober Fest and Google Summer of Code, those are the, the sort of starters get people involved kind of experience. Now, the retain people, the top contributors people usually are those who have a reason of their own why they are contributing to Jenkins.
Maybe they work for large company X that uses Jenkins in many places, and large company X needs them to be sure that Jenkins is in good control. Maybe they work for a small consultancy and they continue visiting consulting co companies. They need to be sure they know Jenkins.
So in each of those cases help these self-interest keeps them involved in the project. So that's, those are sort of at the core. Did did that answer your question, Lori?
Maybe. And maybe others have better suggestions in mind. Anybody else?
Yeah, I do want to add like, um, four Gza in particular. We do try to diversify the, like, the types of projects we have, so to attract more, like more people with different backgrounds. Um, like, because like for most of the participants of GSO, they are new open source contributors because like one, the criteria for, uh, acceptances, they have to be like, they have to have, um, not non-sufficient, not, not like, not a long term engagement in open source software development, except if they, like, if, if they're running for it, like if they applied for a second time.
So, um, it's like their skills can be quite like, um, the skills varies and, um, most of them are university students. So, um, I would say like, um, how we keep them, uh, like, um, attracted to a program is, um, to give them options and also like giving, giving them support. I think those two other keys.
Yeah, I I would add to that, this Lori, the answer to your question, I'm reminded of, you know, if you ever go house shopping, right? And you're looking to buy a house, there's a term you hear called this house has good bones. Maybe an older house may not have the latest appliances or the cool color paint chop, but it has bones.
There's a structure there that you can build on and make it cool, make it what you want it to be. Make it great. You can attract new people.
You can't, you'll get some, right, but you can't do it continuously. That's a good word to use, right? Continuously.
You can't do it continuously. You can't keep doing it if you don't have that structure, those good bones in place. And one of the things that I think separates Jenkins from your average, you know, your average open source project is that it has this long standing structure.
It has good bones. Mark, we've got out, look out of the more people plus mean here, right? 1, 2, 3 outta the five people plus me, excuse me, outta does the five people plus me here.
Four of you are intimately associated with the community, with the project on the community level, fulfilling roles, right? You all have jobs and, and let's call it out. CloudBees has been, as I said in the beginning of the show, a great benefactor and a great supporter of Jenkins and you know, they're Mark, you work for CloudBees still?
I do, yeah, I do. Mark and I, I know Basil do. Um, but nevertheless, there's others besides CloudBees who've supported Jenkins, Right?
Absolutely. Talk a little bit about the community structure, if you don't mind. Sure.
Yeah. So we've got a, we've got a governance board. Uh, five people intentionally not allowed to be dominated by any one company.
So two of those people at most can be from any single company of the five member board. Uh, then we have officers, again, those officers are elected at an annual annual election process. Then the distributed nature of the project.
We have core maintainers who worry about Jenkins Corps itself and then plugin maintainers that care for the plugins. And that gives us this broad swath of people who can support, maintain, and care for the thing with some ability to make transitions, uh, that those transitions are crucially important. Back to the story of what makes it interesting, well, Jenkins, guess what?
Support has supported Java eight, supported Java 11 now supports Java 17, supports Java 21 has all sorts of interesting transitions through which it passes on its journey of remaining as an interesting, useful, and valuable piece of software. Absolutely. You can't maintain that larger base, that larger community without these kinds of, without this kind of infrastructure in place.
And I, I think that's a big part of it. I wanted to mention one other thing. We only got a little time left, but Gloria, you spoke security before this whole software supply chain security and SBOs and the, and, and calling into question the very nature of open source vis-a-vis security, right?
Because there was a period of time where we thought open source was more secure than commercial software, then it, you know, that pendulum swings back and forth, but certainly over the last few years, software composition analysis, the supply chain, our software, uh, supply chain security has taken center stage, and I gotta imagine that's had a major effect on Jenkins as well. Laurie, you mentioned some new plugins and stuff like that that help it. Chris, I'm wondering, or, or Basel or, or Damien, any of you, what are, how are you seeing this manifest itself?
I, Well, I've seen a lot more interest in keeping third party dependencies up to date in Jenkins itself. Um, you know, it, we used to, we used to have a very old tool chain, and nowadays, um, we regularly update all dependencies. Um, we, our customers really put Jenkins in some of the most sensitive environments.
Um, people who are building and deploying software install their Jenkins controllers in a, in a trusted position in their supply chain. So they care a lot about making sure that we are keeping up with all sorts of operating system updates and library updates. And so that's been a major focus of mine in the past few years.
Fair, very nice. Um, Chris Damon, anything on your end? Um, Yes.
One of the, the things that, uh, bother me early in my career and now is kind of something that I see positive is that one of the way to achieve a real life security additionally to what Basil say, updating and keeping, let's say when you cook, you like to clean your, your kitchen on the go. Otherwise, at the moment you have piles, piles of, uh, things everywhere in the same idea. Keeping things simple sometimes as engineers will like and will love having fancy things, fancy new things, and sometimes, um, pondering that willingness to have new things, to keep things simple helps us to build for sustainability.
Virtual machines are still, or even physical servers are still really useful because you can control way more element of the stacks. It's not always easy because you don't have all the background and skills, but security is way more efficient when you build for sustainability in a project like Jenkins. By keeping things slow and simple, that means not choosing fancy or trying it just for the fun of it and say, okay, declare it, that's fun.
That was cool, but we won't use it even if we won't. Because keeping things simple helps people to have a better view. You don't overload cognitively people, and when you have a better overview of all the pieces altogether, you, you understand the system so you can keep it secure or make it evolve.
And I think that's one of the key concept here that made Jenkins a walk horse, again, unsafe. WI can't say it's fully safe and we will never suffer a supply chain attack. We don't know what the future will, will do.
However, I have a great confidence in the fact that every contributor or maintainer here has a clear view of the system or they can ask for and get, uh, talked about this. And I think that's a key success element for the security part more than tooling for me, the world as bumping is really useful. Uh, we are a bit late on that area, but it's not the key concept, it's just one step.
It's, it's just a one, uh, part of the chain. And the world chain is built on sustainability going slowly, but building for a long time. Absolutely.
Guys, we're about outta time. Well, what a great discussion. This has been of a great project.
Before we go, I wanna mention or give people some places they should be going to and monitoring to keep up on what's going on with the Jenkins project and CDF Mark. And Lori, if you don't mind, I'm gonna ask Lori, if you could talk about the CDF mark, if you could specifically talk about Jenkins project, where, where, where to go, how to stay on, how to get involved, right, where to stay up to date. Mark, why don't you go first?
Sure. io is the place to go to learn about Jenkins. The documentation is there, the, the blog posts are there, the latest releases are described there.
If you'd like to get involved. The top level page offers 8, 10, 12 different areas where you could be involved, either helping maintain code, helping write documentation, help do testing, all sorts of ways that people can be involved in ways both small and large to help the project as it moves forward. Come join us.
Love it. Thank you, mark. Hey Lori, what about you?
Tell us, give us some CBF info. Well, as Mark alluded to in Tacto Fest, and so CD Foundation is participating, Jenkins is one of our projects. Uh, I'd love for you to go to CD Foundation to find out more about the projects that we have, uh, what's going on with them.
We have quite a few events coming up, um, but there's always some new stuff going on under our blogs and our featured, um, maintainers and our featured projects. I'm at the airport, so I don't know if you can hear, there's an alarm going on behind me. It's very, we don't hear it.
Oh gosh, you're so lucky. Um, I wish I didn't as well. Uh, so yeah, so go to CD Foundation and if you wanna have a conversation and you're not sure where to start, definitely check out the Slack channel.
Um, you can always ask a question there. There's tons of people there that are happy to jump in and to help you out. And I think that the Jenkins team here we've had on the call today is a prime example of the type of open source stewardship that you'll receive when you reach out and talk to us.
So please go to CD Foundation, go to our Slack channel, check out hack Tober, f check out all the cool stuff that, um, Jenkins is doing with GS o And yeah, again, Alan, we are so happy to have this partnership with you. Uh, we couldn't do it without you. You really helped us spread the word about what's going on in our CD space.
Thank you, Laurie. I look forward to seeing you in person soon. Um, so Chris, Damian, basil, mark, and Laurie, of course, thank you for joining us on this episode of the CCP Pipeline.
On behalf of the CD Foundation n Techron, thank you for watching this. We hope you enjoyed it, you found it useful. Until next time, this is Alan Shimel for Techron.
We're out.

