Compliance & Code Security in DevOps: Navigate Regulations and Supply Chain Risk with AI | CTRL+ALT+DEPLOY Ep 2
Transcript
Hey everyone, welcome to Control Alt Deploy. This is episode two, and we're glad you've joined us. I'm Alan Shimmel of Techstrong Control.
Alt Deploy is a video show we do with our good friends at OpenText, where we talk about cutting edge, leading edge stuff, topics around DevOps of all things. Um, we're really glad you're joining us. We have a great panel.
How often does this happen? I'm the only guy on the panel. I have three amazing women to introduce you to who, who are on our panel today.
Let me introduce you to them right off the bat. First of all, joining us, uh, from New Mexico. She's the CEO of Deploy hub, open source CBF Board members, uh, on several boards, our friend Tracy Reagan.
Hey, Tracy. How are you? I'm doing great.
I was gonna mention this. I think that this is the first time I've been in an all female panel. It's very cool.
I love it. Not that I don't like the, the dudes on the panel as I'm not saying that. It's just is extraordinary.
It's all women. Yeah, no, you know, we didn't plan it this way to tell you the truth, but hey, more power to you. Good for you guys.
And it's, it's, I, I feel flattered to be here joining us from Canada. She runs the, uh, one of the leaders of the Canadian DevOps community, but really a worldwide, uh, person in the DevOps world, as well as top contributor at the CDF. We've just been informed, my good friend, Garima Boal.
Hi, Garima, how are you? I'm good. How about you?
Excellent. I'm glad to have you here. And then last but not least, he's from OpenText, Hillary Johnson.
Hillary, welcome to Control Alt Deploy. It's great to have you on. Um, I give a little bit of background.
Um, I'm sure I Was gonna say I'm the new person. Tell us. Yeah, I'm The new person.
I'm the senior industry strategist here at OpenText for manufacturing. I've been in manufacturing for 14 years now. Um, and so I've got a vast background from really small job shops to really large enterprise like me, medical devices.
So been in this for a hot minute. Got it. I appreciate you being on.
So, so panel, today's, uh, title is, uh, compliance and code security and DevOps navigate regulations and supply chain risk with ai. Well, everything's with AI today, but really as we get into it, it's a how can, how can our DevOps teams and, and let's not just confine IT to DevOps team could be platform engineering teams, developer teams. How can we stay audit ready and secure the software supply chain, you know, leveraging things like AIS and SBOs and of course automation.
And, you know, this was a hot topic before AI was hot. Of course, we weren't talking about using ai, but securing supply chain has been a problem. Certainly, you know, it first burst on the scene, I guess, with the SolarWinds breach back during COVID, right, where there was a, the malicious code inserted into shipping product.
Um, Tracy, I know you spend a lot of your time focused on this, where, you know, has AI changed the game here for us? Where, where do you see, pretend, where do you see progress? Where do you see we still need to make a lot more progress?
Um, well, um, before last week, I would be far more optimistic. Um, uh, I was at CD Con and we did a, a, a focus group around CICD cybersecurity. And I discovered that many of the DevOps engineers are not interested in adding security to their pipelines.
In fact, they're flat against it. They don't want to do it. Um, and that's because I, I don't think that there's maybe I, I don't know what the reason is.
I don't think they wanna be disrupted. Again, I don't think they wanna touch their workflows. Uh, so we have some work to do in DevOps around the understanding of why security is important.
You know, I, I keep my foot in two different worlds. I'm on the board of the open source security foundation, so I understand and hear what they're working on. I know about their new tooling, like proto bomb, and then I have the other foot in the, in the C station, and I'm on their technology oversight committee.
And I see that there is a very, very large gap. I'm practically doing the split here, folks between the two worlds, because there is such a wide gap. Um, at our focus group, one of the most concerning things that I heard, but I heard many of them, the, the first one was, they don't believe that SBOs are important to incorporate into DevOps pipelines because they're not always accurate.
They're just a checkbox. And without consuming the data, it's useless. Which I agree, that's why Artelia is around.
We're consuming that data and making as actionable. But the point is that they don't see a strong need for securing the code base through the CICD pipeline that somehow is an engineer's job, a software engineer's job, and not something to be automated. And I, you know, this, this concerns me because if we're not looking at disrupting ourselves, we will be disrupted.
There will be younger people come along and do things differently, and AI will be part of that solution. There's just no way to stop it. It's a freight train.
Get off the tracks. Yeah. Karima, I'm, I got to tell you the truth.
I'm, I'm shocked. How about you? I'm not that shocked.
I think that, you know, I understand where Tracy's coming from. I am also associated with the Cortes Delivery Foundation. We have a lot of ambassadors who are trying to steer the needle in the right direction.
And I also see that Tracy is heavily invested in, uh, open source security. But I understand, uh, the community kind of sentiment and, you know, not overlooking the recent past. Right?
You mentioned about SolarWind. We have seen log four js and we have seen x uh, Z back doors, you know, so the regulatory pressure is intensifying on us, whether we see it or not, right? Regulations like EU Cyber Resiliency Act, or even the NIST two in Europe, or executive order in, you know, us.
I think they are all reflective of the fact that we have to take security seriously. And sbo, OM is comprising of one of the biggest pieces of the puzzle when it comes to contest monitoring, the vulnerability scanning, and maintaining that transparency in the system. So I would like to have more discussion on this topic and raise awareness and see what we can do from a practitioner's point of view or community point of view to ensure that we, Uh, Move the needle in the right direction.
Hillary, help us Labor shift going on right now, right? You've got old labor kind of coming towards the end of their career, younger labor, who doesn't quite understand some of the, the trades or some of the manufacturing world. Um, and they're looking for new tools.
So I think it's gonna be, at least from what I can tell, is there needs to be a shift in thinking from upper management and from owners, and even SMBs. You know, nobody likes change, but it's inevitable. Kind of like what cybersecurity was when you were breached and, and manufacture, I know from a manufacturing point of view, they didn't think it was gonna happen to them.
Um, and so they, their, their guard was down. So eventually, maybe it's, you know, um, where they need to see it, that it's happening to somebody else, or, you know, okay, I, it hasn't happened to me yet, so maybe it won't happen to me and I can focus on getting some other things done with my business. And so there's, there's gonna need to be a shift with the different kinds of people who are coming into the business full stop.
Um, and whether or not you like it is one thing, um, that's, I mean, my 2 cents, but it kind of, it needs to be a shift in mentality. Well, we that, and as part of the problem, we've been shifting. We've been shifting left, shifting left, shifting left, shifting left to the point that DevOps engineers are not shift, they're not left, they're not software developers.
So we've been pushing it all to the software developers and the DevOps engineers are like, that's not our job. We shifted all that to the, the, the developers. They're the ones that should be protecting their software supply chain.
But that's exactly the point. It's not the software dev software developers want to develop quality code, but they're not security experts either. It's the security people or the security experts.
But that's one of, you know, I was at while you were at the Open Source summit last week, I was in New York at the platform engineering Con. And, and that's, you know, what a, what a dynamic community with lots of buzz and lots of, a lot of young people, to your point, Hillary, right? A lot of young people coming in here.
Even though, you know what was funny? I interviewed a lot of folks that were closer to my age, and they said, I've been managing platforms for two, three decades. Managing platforms is not a new discipline.
Calling a platform engineering maybe is newer, but managing platforms is what we've been doing. And I think one of the reasons that platform engineering has struck an chord and, and gotten as popular is it has, is that part of their, not manifesto, but part of their reason for doing it is you can't just keep shifting left and saying it's the developer's job to do. Developers want to develop, right?
Developers want to develop code. They're not security people. They're not DevOps engineers, nor are they platform engineers telling developers that you're responsible for security.
Oh, and by the way, you're also responsible for building the platform that you develop on because we're shifting everything left. Well, that's not, that doesn't scale when, when you get, when you get to enterprise levels, that doesn't scale. However, I am surprised to hear that DevOps engineers would wanna sort of abdicate their responsibility in terms of, because it, in terms of secure code, because it's not just the software engineer who makes sure it's secure code.
What about testing, right? That to code, code needs to be tested. Whether it's, it's whether the code's written by AI or people or both, it needs to be tested, right?
We, there should be a pride in what we are in what we are doing at our jobs where, no, I'm not gonna release shoddy code, I'm not gonna release insecure code, I'm not gonna release code that doesn't comply with regulations and compliance. Right? I think what we're hearing is more what Hillary said is it there is sort of an old guard that wants to stick their head out the window and say, I'm fed up and I'm not gonna take it anymore, right out of a movie.
And there's also a lot of people in, in the workplace who, you know, this is their fifth disruption in the last three years, and, and they're shellshocked, right? They just want to dig their heels and, and honestly, I'm fed up, I'm not gonna take it anymore. But progress waits for no person, man or woman or what have you, right?
No person. And so they can, they can protest all they want. That doesn't mean that SBOs aren't gonna be required.
That doesn't mean that AI is going to stop writing more code and having as big a, a bigger impact. Wait, wait till the agents come in, right? We, we spoke about that earlier in our episode, one of Control tlo, and I apologize, Tracy, Hilary, you weren't on that episode, but Garima was on with me.
And, and, um, you know, we spoke about what agent AI is going to mean for DevOps engineers, right? So sticking your head in the sand and your head and your, and your heels in the sand, I don't think that's a, I don't think that's gonna work here. Yeah.
So I think what I, what I, what I saw what in that meeting, uh, was a lack of curiosity. Um, because I am one of the most curious people. I know, me and Brian Dawson were kind of OCD about things, and we'll get on something and we really will research it and have fun playing with it and trying to understand it.
And I, I saw a lack of that curiosity in that group. Um, and I understand that they probably have a lot of work on their plate to keep those brittle workflows up and running. And the thought of trying to create something new, maybe an overwhelming task.
But what one person said, struck with me, stuck with me, is he said, PE people will start generating SBOs when their bottom line depends on it. And he was a company servicing the, the, the public sector. Uh, he said, we don't have a choice.
We have to, but we still feel it's like a checkbox. And I could submit the same SBO m over and over and over and nobody would know the difference, which is a true fact. Totally True.
So that, that is true, right? Yeah. To me, the SBOs always seemed like the tag on my pillow, that if I tear it off, it's a federal offense, but whoever reads what's on that tag, right?
And I'm always eager to te tear it off just so I can Break the law. So that's, that's the kind of person you are. Exactly.
Who else here, Hillary, do you pull the tag off? What do, do you read the tag? No, I don't want the tag in my ear if it pops out of my pillowcase.
Um, uh, I think, I think the thing is that is so true. People are learning AI out of necessity. I learned AI out of necessity.
'cause I was doing the job of four people. So as we're, as all of these comps companies are still running lean, they're gonna have to figure out that, that to dig their, their heels in and start testing it. I think the other thing about AI is it's not a hundred percent accurate.
Um, right. You know, so you've got that, that cautious behavior behind it. Like, well, what if it isn't?
I can't trust it fully. Yeah. You still need a person to verify some of this stuff.
And so how do you, how do you start progressing, um, still knowing that there's, you gotta have somebody who, who's checking all of this. So, um, just 2 cents. I, I agree.
See, so Tracy, I'm more like you. I started using AI purely outta curiosity. Now I find it an indispensable tool.
Me too. To your point. Yeah.
To your point though, you were doing the job, you had to do the job of four people, so you had to use AI as a force multiplier. So I was reading an article, I think I mentioned in the earlier episode, uh, mark Benioff from Salesforce claims that maybe up to 50% of the work being done at Salesforce now is being done by AI and agents and stuff. I don't know if I believe that to tell you the truth, but that seems, you know, is, is this where we're heading?
Are we, let's say it's not 50%, is it 25% Garima? You talk to people in DevOps all over the world, there's more than anyone. What do you, are we, are we already using AI that much?
As I said, uh, in the first episode, I will stick to that. I think we are in the experimental phase for ai, right? I mean, we are using AI for experimenting around a lot of productivity and efficiency gaps, which we have, right?
And then we are also thinking about using it in different dimensions when it comes to like, um, exponential scaling. But we are not yet there. And I, as I pointed out earlier in the episode as well, that, you know, when we look at things around, you know, we are building things with ai, like what type of code are we referring to?
What kind of enterprise we are, like comparing it to? Because if it's a large enterprise, we have a lot of legacy, uh, systems, right? So it's not easy to refactor, rebuild, you know, repurpose code, um, even for humans.
So, I mean, AI is, uh, something which we should have a secondary thought on. If you are an AI native company, you are building an AI native platform, I would believe that there is a substantial amount of, you know, excitement, enthusiasm, as well as potential what we can do with ai. But again, you know, uh, we haven't substantiated this.
Nobody has product defined it in, in a larger scale. So we don't know how much technical depth we have built around this, right? So there's a lot of questions around, you know, how AI is enhancing the productivity for DevOps pro professionals.
This is yet to be seen. Hillary, what about your experience at OpenText? And don't say anything that's gonna get us all in trouble, but, you know, is, is AI doing that much of the work around there?
That's what part of the company you're in. Um, you know, from, from a marketing standpoint, probably more so. Really?
Um, yeah, very much so. I mean, it does all the research for me. It, it, it writes a lot of stuff.
It gets me started. I'm not a writer. So, you know, there's plenty of times where I need someone to get, um, my thought process going.
Um, you know, in a manufacturing, uh, in a manufacturing perspective. I know of friends who have smaller manufacturing business. Let's take this from the size of the business.
You were saying. Enterprise has a harder time. 'cause they have legacy systems, they've got disjointed, you know, Salesforce, half the time, one's in Europe, one's in the us and one, you know, they're all over the place.
Um, smaller companies are really starting to explore this more. 'cause they have the bandwidth to do it. They don't have as many legacy systems.
So I would say almost reach out to those smaller innovation businesses and see how they're handling it. Maybe let them be the Guinea pigs, create some friends, create some networks, right? And figure out how they're using it because it's gonna need to scale.
Enterprise is is incredibly disjointed. And it, there's so many processes. I think small, I think the smaller to medium sized companies are actually gonna kind of pave the way on this.
And this is just my prediction if I get my crystal ball out that, you know, they're gonna be the ones helping this. Yeah. You know, we saw this in DevOps, right?
When DevOps first burst on the scene, there was this whole argument, is DevOps better for small medium companies where they have to do it by necessity? Or is it better in enterprises where you can do it at kind of great scale? And, you know, counterintuitively, I I think it was both, right?
It worked, it worked at both. Now, if you talk to the platform engineering people, they'll tell you, it's when you really start scaling up that DevOps runs into scale issues. And that's why you, you can help with platform.
But let me, let me put something else in front of you, the three of you, and see what you think about this. If you are gonna believe that SBOs and, and like a lot of security, it's what we call checkbox security, right? Compliance is the least common denominator type of security.
It's doing the minimum you gotta do to comply with whatever your regulations are. But if, if SBOs are part of that least common denominator security that we need, isn't automating that with ai, the easiest thing to do then, because if, if it really is not that important, but we still gotta comply. Wouldn't I wanna just automate it and get it out of the way?
Tracy, I'll throw it to you first. Generating an SBO is easy. We don't, there's many tools out there that will generate an sbo.
M it's a very simple, uh, command line to add to your workflow, by the way, folks, very simple as about as simple as they get, it's probably four words. So generating SBO m is not necessarily the issue. I think what the issue is, is touching the scripts and dealing with, um, any modifications to the workflows themselves.
That's the, that's the real issue. Unless it has real benefit. And that is the problem with SBOs.
Yes, everybody should be doing 'em because it's the first step down the road, right? But then there should be a second step. Evidence stores are important.
Let's start gathering that information. Let's start watching for changes in the sbo m What is different between this, this build and the last build? Are we bringing in new package versions that we were, um, that the, the developers have have updated now we need to make sure that the testers go through that.
Make sure that it's properly tested. How can we make the data actionable? If we do that, then DevOps engineers will be more motivated to use an SOM because it has a purpose.
Right now it's just a government regulation that says you have to have one. So why, if I'm a not, if I'm not delivering code to the US government, and I don't have customers who are demanding an SOM, why would I bother? I, I totally understand the sentiment.
I understand why I would bother, because I, I wanna know what, uh, I, I really do wanna know how compliant those packages are that I'm consuming because I'm delivering code to customers. So I need to protect myself. And the way to do that is to know, again, I'm curious.
I'm a curious person, so I wanna know what's happening. I wanna know what's coming through the pipeline, but not everybody is. And you know what's really gonna change DevOps?
It's when DevOps engineers are gonna start having to manage AI agents and LLMs, that means that they're going to have to change the way they, you know, our, our DevOps pipelines are pretty traditional still. The two, the two pieces that we do is we run a build, right? We take code and we turn it into binaries, create a container, and then we call a deployment tool.
We, you know, DevOps pipelines themselves don't do deployments and they don't do builds. They call scripts that do that work, or they call external tools. So we're doing builds and we're doing deploys, and we're happy.
And that deployment go out, may go out to testing, or it may go out to production. We don't even have to worry about that because the deployment tool deals with that. And most of the time we're consuming something that's a home chart for that.
Or we are, we have GI ops. It's, it's supporting the de the, the deployment. So we really don't have a lot in the pipeline anymore.
We just have a ton of pipelines. Thousands of them. Thousands and thousands of pipelines.
So when we start asking for things like what version of the LLM was used in this build, that's when they're gonna say, well, I don't have an AI bomb to tell you that. And that's when we're gonna start seeing changes in the pipeline. In the pipeline itself.
It has to be driven by a serious need that's going to motivate a DevOps engineer to dig into thousands of workflow files and start updating them. Or guess what they might do. They might use AI to do that.
So they will. And and if it, if it checks the box, they will. Right?
If it's, yeah. If it's just a check box. Yeah.
And so, you know, maybe compliance isn't the right driver, is what I'm hearing you say. I don't think compliance is, is something that they really are focused on. The compliance is being forced at the dev, uh, at the shift left side, there's quite a bit of work that developers are doing.
They're taking classes. They're trying to learn to write better code, make sure that they don't have stack overflow issues, for example. They're working at that.
But the DevOps pipeline, there is tooling that can be added to it that's not necessarily being added at the CD foundation's at our focus group, I asked if anybody knew what proto bomb was, which is a big tool that the CI that open SSF has been working on. Nobody understood what it was. They had no idea.
That's a big, there's a big disconnect between the two. And I wanna p point out that these tools are coming out on a very fierce, there, there, there's new ones all the time for security that can be added to the DevOps pipeline. At the CD foundation, we're working on something called the CICD cybersecurity sig.
We're putting up a website that will have defined for achieving, um, the software, the secure software development framework. For example, NIST 800, whatever it is. Uh, we're gonna, we ha we are working on every single task and we're finding what open source tool could be added to the pipeline in order to achieve that NIST task.
Because dev develop DevOps engineers don't have time to go hunt down tools and understand exactly every single task that you have to comply with, which is numerous and what tools you have to add for that. So we're trying very hard to understand what the DevOps teams are looking for. And what they're looking for is just gimme the information.
What do you want me to add to the pipeline? I don't wanna go sort out security. I manage the pipeline.
What do you want me to add to it? And how will it benefit you? So that's where we need to get to.
Fair. You know, I remember being a little boy in school, school and some sixth grade philosopher told me, all spaghetti is macaroni, but not all macaroni is spaghetti. Okay?
Bear with me. AI helps us with automation, but not all automation is ai, right? And automation is something we've been trying to do in DevOps from day one.
'cause the very idea of automation seems to at least, you know, the idea behind it is, oh, we could go faster because it's automated. We get humans out of the way. We, we could go fast.
It just runs as fast as it can. It's automated. And that's very much like AI is part, is a, you know, automation is a big part of one of the, the, uh, you know, the things that attract us to AI is it can automate stuff, take humans outta the equation and just do it.
And we've spoken in episode one, the difference between automation and autonomous, right? Is autonomous ai, AI does more than automation, right? AI could bring autonomy, AI can do, it replaces humans in, in so many in some ways.
Um, what about non-AI automation and DevOps helping to navigate compliance and regulation and, and supply chain risk? Is it all AI is, is that, has all all automation now become ai? Hmm.
No. Reem or I see you wanna talk or thinking? Yeah, I, I think, um, and, uh, you are right that automation is different from what we are seeing now.
Because if you think about SBO management, for example, we can automate a lot of SBO management stuff, uh, in the CICD pipeline itself, right? Versioning of SBOs, for example, vulnerability management scanning tools. There is also SBO M platform management.
If you're a fan of PLA platform engineering, you could appreciate that. But when we talk about ai, it is, uh, I would say there are four aspects which we have to consider, which is different. First of all, timing of when and how we are putting automation into the stream, right?
So that is very important because when we consider secure by design with respect to ai, it makes a lot of difference. You know, throughout the lifecycle, we are considering ai. And that, uh, also kind of helps us understand that why timing of security is important.
Our approach is also another factor because, you know, automation is often reactive. Um, uh, from AI perspective, we are more proactive, right? They anticipate and mitigate threats before they occur, right?
Integration, for example, is another, uh, aspect, which is also different because we are not only considering code, we are also considering data processes and all other aspects of like, modern model training, deployment, as Gracie mentioned, you know, what version of LLM you have used in the pipeline. So all those kind of things also become important. And lastly, I would say adaptability.
Adaptability becomes, uh, more critical. Because, you know, when you're talking about AI in the mix, it's more real time, you know, self-learning loops, you know, they, they can kind of enhance itself. So it's a lot of other factors which you have to think about.
And again, that's the reason why I was thinking that, uh, you know, the AI integration and the, the, the journey of AI integration and SOM in security management is still at an experimental stage. So I think gima used a very important word in that. And that's adaptability.
So right now, we have, we have job schedulers. Let's just, CICD is all driven by job schedulers. Jen Jenkins, a job scheduler, harnesses job scheduler, they're job schedulers, and you pass things to them for them to execute and order.
That is what we call workflow automation, right? That is what we do. The problem is adaptability.
Because of the fact that we use scripts to build that automation, it makes us less agile. Even though we preach agility all the time, we ourselves are not very agile because we can't adapt easily, which is why we can't add a lot of security steps to the pipeline. So that takes me to why l uh, the potential for AI to manage our workflow instead of having a job scheduler.
When we start moving into AI and having an LLM actually manage the workflow like a, like a cloud Opus four, then we can be more agile, we can be more adaptable. We can ask it to change faster. So right now, humans are struggling with the, with being adaptable and changing what AI has an could offer to DevOps in the future, or platform engineering, whoever takes it on first is a more adaptable way of managing the automation.
That's where we're stuck. Fair? Fair.
As I'm listening, um, I'm thinking about machine, uh, monitoring and lin learning, and then what is, what can come from that? So, you know, when you have a lot of information coming in machine monitoring, it's just putting the data out, and then you have a human who's, who's reading that information, the next step then is to take that information and have, um, your AI then analyze that information and say, oh, I'm seeing a forecast here, or I'm noticing a, a trend here. And then you can align it with things that are going on in, in the natural world.
I, I'm wondering if it's just a lack of like, curiosity, like we're saying, and they don't even know that there's this capability out there. As I've talked to people about ai, one of the biggest things, I, I talked, I talked to the president of an old company I worked for, I was 3D metal printing. He's fantastic.
But I, he asked me, he said, Hey, how can I use ai? And I was like, you were one of the smartest, you're, I mean, really, really smart gentleman. But we had a lunch meeting and I said, this is how you can use it, personal and professional.
It goes a whole, I didn't even know. And the amount of platforms out there. So I wonder if it's more or less like opening it up and saying, here's what the actual capabilities are, versus just saying who's gonna take it first?
Maybe you point out both your PO particular position can do it this way, and here's an example. I just think it's lack of understanding a lot of it, um, and not actually knowing what the different capabilities are because they haven't had the time to jump in. Everybody's working lean.
Um, so sorry, 2 cents there. It's almost, it's a progression one, right? You get, you get in all this data, but what are you gonna do with all that data?
Right? We got data everywhere. Everywhere, right?
But I think a lot of it is maybe they just don't know what the capabilities are and they need someone to show them. Well, and, but also their attitude. You gotta be open to learning about the capabilities.
I'm sorry, go ahead, Tracy. We, we don't keep data in DevOps. That is a big problem.
We, uh, so the data that we keep in DevOps is stored in log files. Okay? Um, sometime they're checked in, but generally they're probably left on the, in the directory where the, the deployment was, uh, executed or the build was executed.
Uh, we don't even create, uh, historical records of how, what a, a workflow look like when it executed. That's not stuff that's a DevOps pipeline, uh, gathers. So we have a problem with actually implementing AI around DevOps with a lack of, of data.
So we can't, so let's say we, we take a large company, I don't know, standard oil, whoever we wanna think about and watch their DevOps pipelines over the course of time and store that information in an evidence store, we could absolutely start watching a model and, and having that model make predictions, but without the data, we struggle. Um, so these pipelines don't have that kind of information. Now, what we do have is we have workflow files that are checked into gi.
We have, um, build files that are checked into gi, we have palm files that are checked into gi and we have, uh, helm charts that are checked into GI and that they, the existing models can go look at those to regenerate things for us, right? But we don't have historical data to do predictive work because we are, the data is fragmented in log files everywhere. Every tool has a different log file.
They just get stuck in the director that they executed. And we're not doing anything with them, kind of like an bum, exactly like an bum. So without that, we as DevOps engineers are going to struggle with having the ability to do anything more than generates a, a new helm chart or a new, uh, workflow file from ai, which you can already do today.
You know, God helps those who help themselves. And I think people, I think there are so many things that AI can do for us, not take our jobs or replace us, but augment us and extend us and make our lives easier, better that, you know, there's gonna be, there's gonna be people who work because of ai, and then there's gonna be people who don't work because they just don't want to recognize the ai, if you will. So I would, uh, also add something here, because we have been talking about this for a long time, that, you know, there's a lot lack of awareness at every level that you know, how AI is adding value to our ecosystem as a software developer, I did a talk, uh, at, uh, DevOps con, uh, in Berlin, and I started with this, that in 20, 35 years down the line, do you think that your software development, uh, would look the same?
Is the job the same, you know, five years down the line, what could change and what will be the challenges and risks? And when you start thinking about it, there is like a change in how practitioners would see, you know, software development and what skills are needed, how teams will be structured. Because there will be, if you like it or not, there will be a lot of AI assisted software development in the ecosystem.
There will be teams where you'll have like five code assistants as well as, you know, four senior devs in the same team. So how do you cope up with that? And then from an enterprise perspective, do you think that all the big bank changes which are happening, they're not human led anymore.
They are AI led micro changes which are happening in the ecosystem. You know, if you open your eyes, you see you, you're using copilot, you are using, you know, all these tools and time has come, you know, people have to realize that their job is changing. So now you have to think about your left hand side and right hand side of the brain, like what needs to be getting added to your left hand side of the brain, which is like creativity, you know, like your co-creation with AI tools and capabilities and right hand side of the brain, like what?
Computational logic, statics stakes and LLM models and all those kind of things, which needs to be up, uh, you know, upgraded to your skillset. So this is like, you know, this is a self re reation, you know, you have to think about what, how the industry is changing and what is in, for me as an individual, as a team, as an enterprise, right, as a leader. Agreed.
On. Hold on. You agreed too, Hillary.
All right. Hey, you know what, though? We're at, we're about outta time here.
This has been a great conversation. Look, I, I think every day the way how fast this AI stuff is moving and, and compliance will need to catch up towards doable with AI too, right? Compliance is, is in, in and of itself will become a moving target.
So this is gonna be something we're gonna be watching going forward. But for now, Garima, Tracy Hillary, thank you for joining us on Control Alt Deploy. Thank you to our friends at OpenText sponsoring.
This is Alan Hummel. I hope you've enjoyed this episode. Stay tuned for more.