CI/CD Infrastructure with Amit Mishra at JFrog swampUP 2024
Amit Mishra, an engineering manager at Credit Karma, discusses his role overseeing CI/CD infrastructure, which heavily relies on JFrog’s Artifactory for managing and securing software dependencies. He emphasizes the importance of centralized dependency management, security integration, and how JFrog’s evolving features, like its support for various packages and security advisory during events like the Log4j vulnerability, have been crucial for Credit Karma’s engineering processes.
Transcript
This is Textron tv. Hey everyone, Alan Shival back here at Swamp Up in Austin. Our next guest is Amit Misra.
Amit is with Credit Karma. And Amit, welcome. I, it's a little loud out here.
Thank God we got good mics. So people will hear you, but there's a lot going on. It's in the afternoon here and, and there's a lot of people talking and milling about Ahman.
I mentioned you're with Credit Karma. What do you do at Credit Karma? So, Uh, I'm an engineering manager at Trade Karma, and my key responsibilities include, um, heading and owning the CI ICD, uh, infrastructure.
Uh, it includes Jfr products, it includes GitHub, silicon ci, uh, data analyst infrastructure, a bunch of infrastructure that drives the CI ICD pipeline. Absolutely. And you know what, Amit, maybe there are people out here who aren't familiar with credit, they didn't see the commercials or anything, but how would you explain Credit Karma to people?
Okay, so Credit Karma, I would say is one stop shop for, uh, making sure that you take control of your financial, uh, wellbeing. Uh, we are a fully free service. We are owned by Intuit, and we just don't give you free credit scores, but much above and beyond that, uh, we approve you on our website or on the app for the credit cards, which are applicable to you based on your credit score.
And, uh, more than that, like home loans, autos, uh, all that thing that anybody needs for their financial wealth, uh, we provide that. And again, I'm gonna read it. It's all free.
Okay. And, you know, the website and the applications that do all this are primarily, I mean, they're internally developed by Credit Karma. Yes.
That is proprietary stuff. And you're here as a J Rog customer, right? You've been a J Rog customer for some time.
Yeah. Yes. So, uh, there's a fun factor around J Rog, uh, introduction to Credit Karma.
Uh, it was one of the first initial product, uh, that I was going to do a POC at ck. And I think J Frog's, uh, lifespan at Credit Therma is the same lifespan as my lifespan at ck. So we both, So as long as they're doing good, you are good.
Yes, exactly. As long as you are doing good, They're good. Yeah.
Doing good. Yeah, that is correct. Absolutely.
Good for you. Yes. So, you know, we set the stage a little bit.
Let's talk about how do you use J Rog at Credit Karma? So, J Rog basically, uh, Artifactory product of J Rog, uh, we are actively using that and it basically helps, uh, all engineering, uh, to manage, share, and download the dependencies. And it is heavily used in our, uh, CICD build pipelines.
If I explain it like, uh, as part of any service that is deployed in production, JFR plays a very, very critical role to make sure that the, uh, dependencies are managed in the most effective, secure, and scalable way. Absolutely. And, you know, I would imagine over the years of using jfr, you know, it's evolved from just the Artifactory to security, DevSecOps, ML ops, you know, so much runtime security announced today.
If you wouldn't mind, and again, without getting you in trouble or giving out trade secrets, how, like, how are you using not just you, but how is you and your team using, uh, J far in Credit Karma today beyond just, you know, base artifactory? Yeah, So I think, uh, as I said, uh, our jfr is, um, being used as a critical dependency management system. Okay.
We do not, uh, uh, we do not encourage our developers to fetch artifacts or any dependencies from the internet because, uh, there are certain security concerns. Uh, and I had a previous talk that I was speaking around, uh, there was a lot of security insights that I covered. Uh, it becomes very critical when, uh, working in a company like Credit Karma, uh, security kind of stands out as a one of the most critical aspect on whatever we do.
Uh, we wanna make sure that when we are serving, uh, any dependencies to our engineering, it is coming through a trusted source. And that trusted source is what Jfr Artifacty platform provide us with, in a nutshell. Got it.
I've got some questions that we're going through, if it's okay. So what were the main challenges that you and your team were facing when, you know, when you, that made you kind of turn to a solution like jfr? So, yeah, as I told you, like, uh, uh, JR has been, um, working and running at Credit Karma since almost nine plus years now.
And, uh, when I joined, the dependency management was basically fetching stuff from maybe, you know, third party, which were not coming from a trusted source. Uh, I think what Jfr has done is it has provided us with one stop shop, uh, when it comes to dependency management. Uh, and I love the way the security features are inbuilt into Jfr.
Yeah. You can tie a dependency back to a homegrown dependency, back to its build information. Uh, and it gives a lot of visibility into what kind of a dependency is being, uh, consumed at which part of the lifecycle for the service that is being deployed in production got.
So, uh, plays a very critical role, and it is helping us to centralize, uh, our dependency management system. Got it. And I, I can't imagine, uh, our CIC rebuild pipelines, um, without Jfr being in the picture at this point.
I, I don't disagree. So let, let's talk, you know, but today everybody answers to their boards were around KPIs. Yes.
How do I know I'm getting my money's worth? How do we know this is working? What are the KPIs that matter most to you and, and your use of jfr?
Uh, yeah, that's a good one. So key pro, uh, key performance indicators in our case, uh, when it comes to JF Rog have different aspects, right? Uh, they could be velocity driven, they could be security driven, right?
In our case, uh, some of the key performance we get is around security would be, uh, what percentage of our dependencies are still being fetched from non artifactory sources when it comes to say, uh, bill Titan, right? Uh, and we want to keep that numbers down. Uh, ideally, ideally you want your KPS to be high.
In this case, we want to keep it down because we don't want, um, any outside dependencies to fast, which are not coming from artifact. Uh, other critical KPIs, I would say are, which we want to make sure that, uh, optimized build times, uh, faster way to replicate stuff, uh, from source to the destination. Uh, so those kind of KPIs are like, how are we, uh, facilitating our developers with a faster built time, faster shareable time, faster download time, faster, upload times of these artifacts, and, uh, we monitor all that stuff.
We do. Yes, we do. Uh, these are some critical metrics that we, uh, these are some other, our critical SLAs and SLOs, and we are monitoring them, uh, in different tools, I would say, uh, at Credit Karma.
And you're happy with the KPIs? No one's ever happy. We always wanted do better.
We always, yes. Uh, you already answered that partially. Uh, it's a continuous improvement.
I would say That's Starbucks. The numbers will, uh, always fluctuate. Uh, but being a leader of an or which kind of owns Artifactory, uh, it is my duty to make sure that we have our eyes and ears open to any alarming, uh, metrics, uh, which could impact, uh, our end users, which is our developers directly or indirectly in universe.
Very good. Next, I wanted to ask you a little bit, so you mentioned you're using Artifactory, but you're using some of the security tools and some of the other tools specifically, are you using it, I think you said X-Ray. We are not using x X-Ray, not using no advanced security curation.
So we are using, uh, uh, I would, uh, we are using GitHub Advanced Security. Okay. As far as the security tooling around, uh, JFR goes the current offering, we are actually looking into doing a POC on X-Ray.
That would be our first step. But other than that, uh, we have a lot of security protocols, scanners, uh, that, uh, I cannot, uh, disclose here, which are running on our infrastructure, uh, which go above and beyond, uh, Artifactory scope and are making sure that there is a secure product delivery. Uh, when we say, uh, when we are delivering it to credit firm, One thing about security is there's no lack of scanners tonight.
Yes. Yes. There's some really good ones out there.
Yes. Yeah. Alright, let, let's move along.
Um, so as a Jfr customer, where would you say you and your team have seen the greatest impact and value from using jfr? So I feel, um, the biggest impact is the centralized dependency management system. I am a big fan of, uh, artifactory releasing support for different type of packages, uh, on a, on a periodic basis with all the releases.
Um, you know, this could be Swiss packages, this could be like Maven, other, other packages. So the functionality that j Frock keeps on improving, uh, helps us to improvise, uh, our end users, which is a development team and being part of the platform, I think it's, uh, always on top of our, uh, mind to be in a state where a developer should not worry about the underlying in, uh, platform. Their job should be just to come commit and dependency management should be left to us, because that's where platform comes into picture.
And I feel that, uh, uh, Artifactory playing a very, very critical role in that aspect. Absolutely. Um, is this your fir this is not your first swamp up?
Uh, actually it is really in like nine years. This is my first swamp up. Um, unfortunately there was couple of swamp up that I missed because of pre covid, covid phase, pre Covid.
Uh, and I think, um, yeah, my account rep was making fun of me, like, first form up, you come and you are speaking in the conference. So yeah, That's a good thing. Yeah, That's a good, yes.
com, you know, one of our text Trump sites, and I think they are probably one of the most unique infrastructures or unique cultures culture. Excuse me. What's your favorite part about being a jfr customer?
So, um, I feel to start with, I'm really impressed with Swamp Up to start with. Uh, I love this conference. I'm actually regretting why this nine years?
This, yeah, nine years. Uh, sometimes the work commitments, so you get busy. Uh, I think, uh, the way the knowledge sharing is going on, I'm really excited, uh, to hear from other people, their stories.
Uh, and I was very impressed with the keynotes, uh, specifically Me too, the, uh, with the GitHub and, uh, JFR integration. The integration, yes. And we are a GitHub shop as well, so I am really looking forward for, uh, the, all that integration.
So I think, uh, the list goes on and on, but I feel, um, uh, the way, the rapid, uh, approach that they have around turning things, uh, I, I can tell you like when we started, we were running Jfr, uh, art is a Docker container, and now here we are supporting, uh, Kubernetes. Uh, I, I love how they're evolving with the industry, uh, specifically when it comes to integrating security. Uh, and again, again, I'm gonna say reiterate, uh, security, security, security, because I, I belong to Credit Karma Security is embedded in our heart and minds of what we do.
Uh, so very impressed with the unified security platform. Uh, I have heard some good things around, uh, integrating GitHub Advanced Security. Yeah.
With J Pro Security, uh, really looking forward to it. So, uh, yes, the, the rapid growth, uh, the way the functionalities are released. Uh, and if there are any issues specific to me with the CDs, uh, I'm a big fan of J Pro's, uh, security Advisory.
Uh, they're very much on top of it when yeah, they're their Team, their research team. Yeah. Log four J was one of the scenarios where, uh, we were immediately held and, uh, we were, I think Jfr was one of the tools that, uh, the mitigation happened at the very first, uh, one of the first four on.
No, they were on top of it. Yes. They've done a good job.
Ahmed, thank you so much for coming out and talking to us today. Thank you. Keep up the great work at Credit Karma.
Thank you. Thank you for having me. And it is a great pleasure to be part of Swamp Up.
Thank you. Thank you. Thank you.
You've heard it here. Credit Karma speaking at Swamp Up. We're gonna take a break.
We're back. We've got a lot, a lot more coverage from day one. It's swamp up.
Stay tuned.