Optimizing the DevOps Workflow with Clean Code – Peter McKee, Sonar
The number of developers globally is expected to hit 28.7 million by 2024. That amounts to millions of lines of code being written each day. As developers and lines of code continue to multiply, and pressure to deliver with speed increases, quality often gets sacrificed. Plus, with generative AI added to the mix, we’ll likely have more code with less oversight. All of this is unfolding in a cloud-centric operational environment that’s vastly distributed and highly dynamic. That’s why it’s mission-critical to optimize the DevOps workflow. A new ecosystem of tools and practices embedded in the DevOps workflow that leverage automation and machine learning, and that can interoperate at a much deeper level, is direly needed to overcome bad code and create software that has lasting value. The good news is that this innovation is ramping up — one pivotal example can be seen in the advances being made with Clean Code best practices.
Transcript
This is Textron tv. Hey everyone. Welcome back here to Textron tv.
I'm happy to be joined by my friend Peter McKee. Peter is the head of developer relations and Community at Sonar. We were talking off camera, I think the last time I saw Peter was actually in person at, uh, in Austin at the open source, uh, summit from Linux Foundation.
So it's been about a year, maybe more. Peter, welcome it. I hope it's not another year until we talk to you again.
Yeah. But, uh, great to have you on. Before we jump into today's topic of discussion, Peter, let's talk a little bit about Peter, and then, you know what, not everyone in the audience is gonna be, uh, familiar with Sonar as well, so we we should probably spend some time getting them to know who Sonar is.
Yeah, sounds good. Yeah. Um, Peter McKee, I'm the head of developer relations, like you said, and community at Sonar.
Um, sonar really focuses on, uh, developer tools, uh, clean code, helping, uh, devs write better, cleaner code, maintainable code, reliable code, those type of things. Um, and we, we go from all the way from the developer's desktop all the way through the C I C D pipeline, your DevOps, all the way into production with, uh, static code analysis. Um, we have our own analyzers, our linter, and all those good things.
Bunch of PhDs at, uh, the company writing rules and really focusing on static analysis. But, um, but yeah, I've been, uh, an engineer for 30 years. Uh, I found out I'm one of those, uh, smiley, happy, uh, talkative engineers.
No, most engineers are happy too. I shouldn't say that, but, uh, yeah, I found I was one of those talkative engineers and got in the community in Devereux, but, um, I do miss coding though a lot. I do miss it.
Yeah. Well, you know, what's holding you back? Well, I tell you what's on you back a job?
You gotta go full-time with these things. You know, Peter, I will tell you, I'm not a coder. Right.
And I've been in tech probably as long as you have 30 something years, you know, playing with generative AI and watching, you know, you feed a a script into there and ask it to explain it to you. It can make me a coder. I mean, it it amazing stuff.
And, and you know, I think it's certainly, uh, this whole AI thing kinda leads the way, but again, as we were talking about off offline, we are, we're 10, 12 years into this DevOps, I don't wanna call it a revolution. DevOps, evolution, DevOps era. And, um, when we talk about DevOps today, it doesn't seem it's come a long way since 2012.
Yeah, for sure. Right? com, the tools we use, the way we think about it, it's acceptance in within the enterprise and, and market in general.
And, and then the external macro factors, right? Cloud has continued to, you know, be dominant digital transformation of which DevOps is a big enabler. Um, and of course, generative ai, these are all things Yeah.
That are, uh, weighing in on various ways in, in DevOps. But to me, the, I, I think the biggest thing, and maybe it's because of my own mindset, is the rise of DevSecOps. Yeah.
Right? When I first started DevOps, there was a lot of pushback from security people about DevOps, and there was a lot of pushback from DevOps people about, we don't need the know people in here. We don't need the, but that's come together too.
And, and the whole idea, you know, I know clean code is a big thing, right? With sonar. Yeah.
But the whole idea of clean code of quality in code and testing it and making it everyone's responsibility Yeah. Is is widely accepted. It's not novel.
It that is DevOps today. So I gave you my Yeah. Take on it.
Let's hear your take. Yeah, I, yeah, I agree. The, the landscape.
I know one thing as an engineer, right? Um, the abstraction layer is gonna get higher and higher and higher, right? It doesn't mean your job's gonna go away.
I, I, I think, uh, in the early days of DevOps, right? You know, a lot of ops people were concerned, okay, well, you know, you get a little fear, uncertainty, a doubt about your job. Well, is this gonna take away my job?
And no, it's just a different way to look at. And, and I think AI is gonna do the same, right? We're producing specifically with code, right?
We're producing so much code already. Companies, um, you know, are shifting to realize that they're a software engineering company, a software company just as much as a manufacturing company, right? And that's producing massive, massive, massive amounts of code.
And, uh, I do a little mentorship on the side, and I help folks go from, you know, other jobs in the software engineering and, um, we're just dying, dying for engineers, you know, autogenerated code, even frameworks that we used to write produced code. And now with ai, generative ai, it's even gonna compound it even more. And so, you know, it begs the question on how do we, how do we write good quote code?
How do we make sure it's, uh, good quality, high standards maintainable, right? These, these are things that, you know, sonars focused on. Uh, and it's a great problem to have, right?
I think sometimes, you know, sometimes it's engineers, right? Especially as old, old ones, right? We, uh, you know, change comes and we get a little excited about it, or we, you know, say, well, that's, you know, it's, it's not that great.
It's, you know, terrible. But this is the first iteration, right? They've been working on it for a while.
But you, you and I might talk hopefully not in a year from now, but you know, a year, a year or two from now, we'll talk and AI would be totally different. Totally different in the code space, I think. Yeah.
Things I, I agree with you. Yeah. No, I look, you know, so we actually did a hackathon here about two weeks ago in tech strong offices, and we had some of the founders of the DevOps space here.
I had John Willis here, Damon Edwards, um, Patrick Dubois. org. Yeah.
Chase Bannon was with her. And man, we had a, we had a, a really good group of people. Gene Kim sent a few people down who he considers kind of AI, DevOps, and, you know, they were working, it was a hackathon where they were actually coding.
You would've loved it, Peter. Yeah. I mean, it would've got you back in it.
They were coding and let's call it operationalizing ai Yeah. Right. For it people, for the ops people, for the DevOps people.
And what was interesting is they were showing stuff they did three months ago, four months ago, which has already been superseded by new stuff. Yeah. And there's so much code out there, and so many, I don't wanna say frameworks, but, so there's so much information out there that allows you to kind of kickstart what you're doing.
And it's, it's like internet crunch time. We are, you know, it's doubling every 12 days, it seems. Yeah.
Yeah. So I can't imagine a year or two from now where we are. Yeah, yeah.
Me either. And, and, um, you know, it'll just keep shifting left and then into the, into the, into the, uh, the business functions. Right?
You know, it's, you, you look at spreadsheets, you can do amazing things with spreadsheets, generative AI coming along right. Is even gonna help even more with that. Well, They're building it.
Microsoft built it now into Excel. Yeah. Yeah.
It's crazy. It's crazy. And we look at it as a great opportunity for us, right?
Uh, more code that's out there, more code that needs to be cleaned. So, So let me ask you a question. How does Sonar harness AI to help clean code better, faster?
Yeah, we're doing a lot of research into it, right? It's a little early in, in, uh, you know, like I said, it's early, but moving fast, right? You know, it's kind of, it's the auto bond.
You jump in and you're, you're already a hundred, you know, a thousand miles an hour already. But, um, yeah, we're taking a deep look at it. Um, you know, I think it's very, very useful.
Uh, I can't, um, you know, talk a little bit behind the scenes of what we're thinking about, but it's definitely a big player, uh, as we're moving forward on our roadmap right now. We think that, um, it's not there yet. You know, the code that's ai, you know, the code that's being put in is, is what you get out, right?
And it's, it's a, it's a very good predictive engine. Um, you know, but if an engineer looks at some code, you know, 70, 80% there, which is, which is great, right? I mean, it, it's a big leak.
But I think, I think there still needs to be some work there. So, uh, we're investigating that. We're, we're looking at how do we use that to create rules?
How do we validate our rules? You know, how do we look at, um, not just at the, like the tactical code level, but can you use AI for architecture? Right?
Uh, these more abstract concepts, um, and help guidance with architecture, microservices, those type of things. It's a big ask. It's a big leap, but it's very exciting to me.
Yeah, for sure. Oh, I, I, I agree with you. It is, you know, putting AI to the side for a second though, too.
I, I think, you know, again, when we look at the future of DevOps, some of the other things that we've seen in here is my mind. DevOps has enabled the rise of, let's say, SREs, you know, the whole SS r e thing, right? For sure.
And even platform engineering now where these aren't replacing DevOps, I think they're, they're all part of a continuum, if you will, right? Of, of how the S L D C plays out. Yes.
Um, or S D L C, excuse me. Um, you know, and, and so when we look at, you know, we're doing, in October 16th, we have this DevOps experience of virtual events. I think the sixth or seventh year we're doing it.
And it's, and this year's theme is achieving balance in DevOps. 'cause I think we do, you've gotta balance out Yeah. Right?
From pre-development, you know, platform engineering kind of stuff through the development and, and configurate, uh, C I C D pipelines, SS r e, post-development, observability, feedback loops, iterations, testing, I mean, all of these things. But, but here's what I like, a lesson I've learned that's gotten through my head, Peter, is don't believe when anyone says all this automation, and even now, AI is gonna cost people their jobs. Yeah.
There's always more to do, and it always creates more jobs. Yeah. I not less, yeah, a hundred percent.
A hundred percent. Your perspective might change, you know, your job, how you do your job might change a little bit what tools you use, right? Yeah.
I, I, Alan, I think ai, to me is a simple, simple idea around, you know, if, if I was building a, a deck and I had a hammer, and, you know, my guys came to me and said, Hey, we need a, we need a, you know, an air powered hammer, right? Saying, that's not how I did it back in my day. Right.
We used, we, you know, you gotta use the manual. Of course. I'm, you know, so if AI helps, I think it's gonna help, but Yeah.
And, and I think it'll shift. It'll shift, right? And, and to your point, I don't think we have, we've made all these advancements and they're great, but we, we advance so fast, holistic approaches, right?
Since we're such a soft, um, engineering practice, meaning we're not, you know, physically building buildings, you know, things change so fast, right? So fast. And, you know, you think you have it, and then something shifts, right?
And, um, but makes it exciting. And like I, It does, but the key to it is you gotta recognize no matter what you do, they're gonna make a better hammer. Exactly.
And you gotta be able to say, look, if it's a better hammer, I'm going to use the better hammer. Right? And, and that's the therein lies the issue.
Yeah. Yeah. Well, you know, uh, you know, I think it's maybe part of, uh, uh, moving along in life.
You know, you look back and, and you know, I remember my parents were looked at the TV and the radio, you know, my grandfather used used to say, the TV's gonna ruin the world. Right. You know, and they said that about the radio, right?
And the car and the horse and buggy, same thing. I think we look at it and just, you know, it's a little bit of a fear, right? Of, uh, un uncertainty what's coming in the future.
But like I mentioned before, like abstractions and progress is, is gonna keep continuing, right? We're not gonna stop it. So you just gotta stay up to date with it.
Say, uh, and how does it integrate it into everything? And how do you take a metered approach, right? Like, you just can't keep throwing new things at, at stuff all the time, right?
It's that balance for sure. Yeah. I agreed.
Agreed. Matt, let's talk a little bit about more, a little more about sonar though, Peter, I feel like we haven't really given people enough Yeah. Information why they should engage with you and how they should engage.
Yeah. So I think, you know, we're, we're really bold on code, right? We, you know, um, the book, you know, uh, um, software engineers are the new, uh, king Makers, right?
Came out by Red Monk 10, 12 years ago, right? And, and it's coming true. And I think it's, you know, uh, you know, just moving, moving more in that direction as we talked about code, right?
So Sona really focuses on code. You know, we, we dabble in other areas, we dabble on SaaS and those type of things and in security, but we, we really think it starts with code, right? If you have clean, maintainable, reliable code, everything downhill starts to, starts to look better, right?
And so we have tools that help the developer, uh, you know, our custom lins and analyzers that sit in your I d e, they're all open source, freely downloadable, plug them in. You can run 'em side by side between all your other linters and you can see what you like. One of the really, really good features we have in, in sonar lint is our rules.
Um, so all of our engineers run our write our rules. They write descriptions, the remediation. Um, so it's a tool for developers written by developers.
Um, you know, I go in there and, you know, I've been coding for a while and there's things that I've learned by just seeing the rule and why, how they describe why it should be, you know, this way, right? And of course, there's always debate, but, so I think es lint and, and linters are awesome. I think our analyzers are a little bit better, a little bit deeper, but please, you know, folks should, should take a look at it theirselves.
But the real power of our products come in with sonar, um, cloud and, uh, cube, which is our server side and analysts analyzing engine, right? So it sits right in the C I C D workflow as you push in a PR or a branch, right? You can analyze your application.
Well, in the, in the id, we only look at one file at a time just because of processor, uh, consumption on the servers. We look across your projects. So we do things like taint analysis.
So we'll follow data as it comes into your application, as it goes through your code and into functions, across files. And we're looking for, you know, you might, uh, bring in some user data and an a p I endpoint, and you clean the data there and you look for, uh, bad data. But as it gets passed down, another function might pull something off a disk or out of a database and just concatenate right away, right?
And now you've tainted that for function calls later. And so that's where the, a lot of the power comes in on the server. And then we also do duper deeper SaaS, not duper, but deeper SaaS, um, where that's looking inside of open source modules, right?
We actually scan that code. We follow your code down into open source modules. Um, you know, it's kind of like ska, but with ska, you, you're doing a lookup, you know what version is, and you're looking up CVEs.
Um, we do that too, but we also get dive deep into your code and actually see where the, uh, the issues occurring with inside open source tools. So that's, that's a huge feature that we have. So, um, you know, plugging sonar cube or cloud into your C I C D, so you get your, your quality gates are there, and unless they turn green, you shouldn't go to production, right?
And you get that feed boat back loop with ES lint, uh, I'm sorry, es lin with, with our sonar lint our tools, right? You get the ni nice connections, so you see all the issues from the server, right? In your I d e trying to shift left to, to fix those errors and bugs quicker.
Um, and then it also helps just in code reviews, right? Uh, a lot of code reviews are manual. Um, we're human.
We can't keep all these, you know, we have over thought 5,000 rules in our engine. You know, you just can't, you know, uh, reason about them all at one time. Um, and a lot of times code reviews, uh, are, are a little bit set up to be advantageous, right?
Um, our industry, right? That's a bunch of smart people and they wanna look smart. So sometimes when you do code reviews, you, uh, it's an opportunity to show how smart you are when really that's not the point, right?
And so with the automatic analysis, you kind of get these lower end things that could be debatable. You set your standard, you know, um, and then, and then you rely on that. So, and then, and then you can focus on the higher level abstractions, right?
And not so much in the details. So we, we think it helps out there a lot. And then you, and we also have a, sorry, I'm, I'm rattling on.
Stop me, Alan, if No, no, good. Hey man, it's your interview. Yeah.
And, and so we have a method methodology called, uh, clean as you code also. So it takes in these clean code principles and practices and puts it in a methodology, right? Alan, you know, as soon as you open a project, right?
No one really starts from scratch anymore. It's really, really hard. So you, you, you know, you throw a static analyzer on and you're gonna get, you're gonna get thousands of, of, you know, issues and you know, as a good engineer, what do you do?
You turn that back off and you go, go about your day, right? No. Um, but you look at all those issues and where do you start?
And so we have a, a, um, a process called Clean as you CLO code, and you set up a quality profile, and that's all the issues and bugs and defects that you wanna look at. And there's severity. Then you set up a quality gate that says, Hey, I'm gonna look at high severity security issues and bug issues.
And, and if we have any of these that are not passing, then code does not pass into production and you focus only on new or modified code. Um, and what we found is that if you focus only on new and modified code and clean that as you go, uh, over about five years, you get to about 60% code coverage. You start out first year, about 22nd year, about 35, and by the fifth year you get to about 50, 60% code coverage.
And so, you know, begs the question, what's that last 40%? What do we do with that? Just let it leave it, leave it alone, right?
It hasn't been touched in five years. It might not be that maintainable, but it's reliable. It's running, it's working.
It's bug free. There's A lot of that until it isn't Peter. Until it isn't.
Until It isn't. Right? Right.
But You, that stuff happens. Yep. And you, but you, and it keeps the developer happy, right?
Mm-hmm. You don't have to go off on this big refactoring, right? It's fun at the beginning, and then it's very painful and you never get to feature parody.
It's very, very difficult. Or, you know, we all wanna do right click start over. It's the worst thing you can do in software engineering.
I know, I know we want to do it. I love doing, I want it to be my code, but you know, it's not the way it works, right? You have to work within the code you have.
And so we think Clean as You Code is a great way to approach that, starting with your, uh, new code or code you modified and, and making sure that's clean and stable, and then that, that has a, uh, you know, a downward effect on the rest of the code. But yeah, so that's Sonar really focused on clean code, good software engineering patterns and practices, and our, our tools really try and help you do that. Yep.
Peter, I don't know, did we mention the website? I don't, I didn't catch it. Yeah.
No, I don't think so. com. com.
Go check it out. Excellent, man. Download our stuff.
Uh, jump into our community. com. I have two great community, man.
If you have any questions, we'll get you an answer right away. Peter, it's great having you on. Let's not wait a year.
Let's not. Until Next time, huh? Yeah, likewise.
And you gotta come to Austin again. I, I was just talking to someone. I was a guy from Google who's moving to Austin.
I told him I'm coming. Yeah, I'll let you know when I can get down there. Definitely.
Alright, until then though. com. Check it out.
We're gonna take a break here on Techstrong. We'll be back in a minute.