Gopal Dommety and David Greene, OpsMx | KubeCon + CloudNativeCon North America 2023
Gopal Dommety and David Greene discuss how to enable application security at speed and scale for growing Kubernetes environments. It is common to focus on security in development or in production, but not the gap between the two. With OpsMx secure software delivery solutions, you can use the delivery and deployment process to understand application security posture, enforce security policies, automate compliance, and manage vulnerabilities. OpsMx builds on the CI/CD and DevOps tools that you are already using, aggregating data silos into a unified application context.
Transcript
This is Textron tv. Hi everybody. We are back here in Chicago at the Great Conference, C**n.
It's a lot of great fun, great people we're talking to. The showroom is bl buzzing. I mean, it's on a days of old here, so it's great to see things are back and big and a lot of fun.
So, a great conversation we're having here with some friends from Ops mx. We're, talk a little bit about what Ops MX does and dig into some new announcements. David Green, uh, CRO and go.
Paul, what is your last name? Go Paul DTI Paul. And great, well, why don't, why don't you start out by talking about what Ops IMEX is?
Yeah. So, uh, Mitch, uh, we started Ops imx with the vision to fully automate and secure software delivery. That's our vision.
Um, there are developers there is sort of production, and so we, as people are going into Kubernetes and microservices, we realize that automating the delivery and the deployments is a lot of manual task. And we said we should bring intelligence to secure that delivery and deployment aspect. Now with the executive mandate software supply chain, that's kind of become very, very important.
A lot of focus on that. Yeah. And so, uh, we provide like a deployment firewall.
That's what we provide. Most of our customers are like large enterprises. Uh, we obviously, we have some that are small and medium.
Um, they tend to have large deployments. Uh, fortune 10 kind of customers. That's what, what optimize And mostly deployment into the cloud or, or can be private data center too or, Um, deployment into, yeah.
Both cloud and private data centers. Okay. Uh, we, we have in large Kubernetes environments, we, we deploy into OpenShift.
And that's, And you mentioned of course, supply chain security. I mean, there are security requirements, standards, et cetera, but every organization kind of has their own thing, right? You've gotta adapt.
It's, It's a huge focus right now. Right? I mean, and if you look at the work around the supply chain, there's generally been two areas of focus.
There's been a lot of focus on the production environment when stuff's already running in the real world or in the developers. But there hasn't been any work to connect those two. And that's really what we're focused on showing here today at CubeCon, is this idea of how do we start to get really an end-to-end view of the application life cycle from when the developer starts the code, when that code lens into production.
Right. Um, we're, we're showing our booth go, Gopaul mentioned the deployment firewall. That's a new capability we just announced a couple weeks ago.
Uh, that's designed to do automated compliance and policy enforcement as part of software delivery process, right? So as the, as the, as the release is running through its various approvals and stages and reviews to be able to do that, that check before it goes into the environment to make sure that you've got your security checks, you understand your security posture, you've got the approvals you need, the environment's ready for it, all those other things you wanna make sure are done before you actually put that coat out in the Wild. Yeah.
Usually is that last gate, right. Gate you've gotta Go through gate, The last gate. We've done everything you're Supposed to do.
Yeah. Yeah. Got the results we need to see.
Yeah. Yeah. Right.
Somebody pushes the button or whatever they Do and now it's live right out. Exactly. It's a last comprehensive gate that makes sure the code, the process, the people, the delivery, and the deployment.
All five of them have kind of happened and we are tested. And you mentioned working with enterprises. Some of those deployments I can imagine are pretty complex, right?
Yes. You know, you're with this cloud, that cloud Kubernetes here and something Else. One of everything.
Yes. Yeah. Everything.
I, I can only imagine some of the issues you might deal with as you work with customers to kind of figure out how to adapt to that. What are some things you've learned about what they need that you've put into the product? Yes.
So, uh, you're right, there are lots of deployment targets. Like, you know, some of our customers have 20, 30 and hundreds of target Kubernetes clusters scale. Some of our customers have 24 to nine, one of our customers has 90,000 pipelines.
Wow. Right. And million deployments.
And we have people who have nine pipelines too. I think when you have that scale and speed, uh, any security check, any approval that you need to do from a security point of view just becomes hugely ones for from a time sort of people point of view. So we are built in ability to fully automate gates based on that, uh, application security graph that we have, the end-to-end security graph, which if you think about it at scale and speed at that scale and speed is super hard to keep it, uh, you know, fresh.
Right? Uh, so we build the ability to gate. You also, uh, audit is a big, big sort of issue.
Um, especially when you need to audit at that scale. We build that in policy enforcement, like you said, that last gate needs a lot of checks. Uh, and sometimes you will be surprised.
Even large enterprises have, uh, very, uh, not so security enriched processes like just changing a certain artifact can push you to production. We built in sort of the deployment firewall actually has come into being actually, actually working with our customer that scale. And of course, those nine pipelines or whatever number, they all do things the same way and follow all The rules.
They're exactly the same. That's what I remember working in an enterprise. Nine is one, but 90,000 is another.
Yeah, I was gonna say more or less getting 90,000. I think. I think that's the key about the scale, right?
You have to the, the, the whole shift left movements that let everybody do things their way, which is great from a productivity standpoint. They don't first time, right? Yeah.
But at the end of the day, you've gotta have some way of making sure that some minimum set of standards was enforced, right? And so that's where the automation comes in. And I think the other thing which we're showing here at the booth is how we can start to add intelligence to that automation, right?
So, you know, let let us actually do a evaluation of a new release, compare it to an existing release, and give you a score that says, you know, from a quality or a performance or security standpoint, this release looks like it's ready to go, this one doesn't. Right? Then we can automate policies on that.
Um, you know, start to be able to generate your own rule set that you might need to enforce with that, right? So, you know, the automation plus the intelligence allows you to scale from the nine to the 90,000 in a, in a environment that's very unique. So I would imagine, you know, I I used to describe when I was running development teams, it's like when we get ready for a release, it's like going on a trip.
Yeah. We don't want to get in the RV and find out we left stuff, we gotta go turn around and go back. Right?
So it's, and that takes preparation, you know, not just if they, we think we're ready to release, it's do the final check. It's all those stages before. Yeah.
What, what kind of things do you do to help customers? So when they get to that point, right, it's ready, it's ready to go. Not we have 25, 2500, right?
Whatever the number is, things we gotta go back and do. Well, one of the things we've built into the deploy of firewall is the ability to do a, to do a preview, do a simulation check, right? So that a developer who's worked on release can say, great, I'm going, my release is gonna go to this target environment.
Let me run a check today and see how it lines up against the rules for that environment. Right? And so we're not deploying anything, we're just say, if you order to deploy, this is where you'd be in good shape and this is where you'd be out, out of compliance, right?
So we're, we're, we don't want the call. We don't want the call at 1:00 AM when you're in the deployment cycle to say you forgot something, right? Yeah.
Turn around on that vacation. Exactly. So we're trying to give that visibility early in the process, right?
Um, and, and with that comes reporting, right? Because if you, if you, if you make it more, if you make it easier to make it visible, people can make decisions. One of the problems is for a developer, you got 20 different tools that each have a different data silo, and you're supposed to check all of 'em, right?
We're aggregating all that data into one view as part of getting this end-to-end perspective. So you could just go one place. If I tell you there's an issue, then you go one place to see what that issue is, then make a decision on how to act.
Yeah. It seems like too, you know, we often talk about security and automation and processes, which all fantastic. We might think of it as, as a byproduct, but actually think some of the essential things is all the data we create in that process is what we can use for, you know, for our audits and for compliance, whether it be security or our own internal processes.
So you're not writing documentation at the end, right? I've got the data I can present. So I would imagine that that is one of the things you've got to do is not just a screen that says, we're ready to go, but here you go.
Here's all the information that we need to provide to whoever for our policies and procedures and compliance. Absolutely. The visibility and the checks is one thing, but the auditability from a compliance point of view is another incident response.
When you have, uh, an incident, uh, uh, you know, to be able to trace back to exactly, like, for example, you can go into a pod and say, if this failed, which exact PR went into this pod? And how did it get here? Yeah.
And we are also looking at enriching the security. Like you have all the security vendors with CS ESPNs and so enrich their security graph with this data so that they can do better, uh, security response. That that's, you're absolutely right.
I think Very good. And you learn from those things too, right? Yes.
Yes. Yeah. That can make improvements in the flow.
Yeah. AIML has been a big part of, uh, our original thesis of starting the company. And I did want to ask you about that too, because it's one of the topics for all this, it's all of this, it's atory for pre interview, right?
So it's, I'm required to bring it up at at least check 42 seconds into the conversation. Um, you know, it's putting AI and ML into our applications and systems and the things that we do. Yeah.
The things we produce. But there's also AI and ML and generative AI that we use on the process Mm-Hmm. Of how we create and deliver software.
Um, I think one of the particular tricky things about AI ml, especially generative ai, is like, you have to feed data into this. This is not just deploying software and data's generated by someone interacting with it, right? We're constantly data streams that are going into from multiple sources to feed into these.
And so delivering a release isn't just, yes, it's code, but it's also the dataset, the content, the data streams that are going into it. How, how do you account for those kinds of, oh, you've been doing some research on that. Odd things that are a little different.
Yeah. Yeah. So I think the AI ML is, uh, in the delivery process used in many different flavors, right?
Uh, one flavor could be, which we do, is when you do deployment, uh, during the deployment, we use AI ML to understand the behavioral characteristics of an application and understand if there are any security risks that are being sort of generated during the deployment. That's, that's one area. The other area is, uh, you know, we have this data and we want to be able to predict the policies that you need to have to have and also generate the, the rego or the, the, the specification for the policy.
And a human can literally say the intent, and that generates the, the, the policy, because these policies are very application specific, right? And, uh, sort of the third area we, we see a lot of emphasis is that especially now that you have these vulnerabilities or policy violations or alerts, uh, the, the root causing of them is being done with a lot of ai now, especially with, with the generative ai, with, with the, you know, open AI APIs, right? They're sort of, so I see it cannot turning our world into a much more efficient world and much more personalized world.
I mean, that's how I see, I dunno if I asked, answered your question, but Well, There's also the piece, I think you're talking little bit about grandpapa, about, you know, the, the deployment process itself, that the process of deploying machine learning models, it's fundamentally a deployment process, right? Even though there's, there's now data with the code, it's still fundamentally a delivery and deployment process, something into product. It's just as a bigger object, right?
And so that, that's, that's one of the new areas we're working on right now in the process. How do we do That? So, Mitch, maybe I missed the question, but I think, think Yes, I like Your answer anyway.
That's not a question, but that's okay. Yeah. Yeah.
So, so I think, uh, you know, if you take, uh, I gave you the example of this customer who has this 24,000 pipelines, right? 12,000 of their pipelines are actually AI ML models, right? That's interesting.
Yeah. And so when you do AI ML models, AML models follow the same delivery process, but they have model, they have model training and also the model deviation in production. Yeah.
Right? And so there they Aren't static things, Right? They're dynamic, They're static things.
They're not static, right? So, so I think the sole security layer that we have is now we are, we are, we are optimizing it for the ml sort of ops or ML model delivery. And so very interesting sort of challenges that come even in security, because once you're in production, uh, the behavior of the model could, could potentially give you a secure data, which was never the case in the, in an is truly in an application, right?
Uh, so that's an area that we are being sort of forced, I guess, by customers. Yeah. Because I, we didn't realize half the pipelines were, were machine learning models, and so we apply the security layer to, to that deployment.
Well, that's, that's kind of our industry, right? We don't necessarily know what We're gonna be doing. Exactly.
Exactly. We Have to figure out ways how to do it. Right.
Ready for it. Yeah. Yeah.
It's very interesting. It's a good point about we don't typically deliver a lot of data in our, in our deployment pipelines, right? There's databases in production that we've passed against, and otherwise in these cases, they are, they're vector databases and, but it's, it's learning models that we've Adjusted.
And the complexity of these graphs are very interesting because, you know, you all these models are cascaded, uh, if this model works, this data comes in, the next model works. I mean, it's actually very fascinating for us to be able to apply. It's almost too complex to do it manually.
You, you can't do it manually, right? You can't do it manually. You just can't do it.
I mean, I think across the board here, right, the challenge is the, the, the reflux often is if we're not sure we'll have a person do it. But the challenge is that people are so overwhelmed they lack context, right? And so that's where you've gotta rely on some kind of automation intelligent system to offload the people.
And then, then you bring the people in on an exception basis when you're really stuck and they had take the time to really dig in and understand what's happening, right? That, that's, that's the complimentary model. You, you're absolutely right.
That's a new dimension of delivery that has kinda in the last two years has really taken off. And you said securing, automating software delivery, that's the new dimension. Yep.
The models and Yeah. And the data associated Models, they didn't think of, we didn't have that in mind when we started doing CICV. Exactly.
Exactly. Exactly. Absolutely.
That's okay. It's adaptable. Yeah.
So deployment, any, anything as you kinda look forward, you know, you're thinking about where you might go or where the industry might go in your domain in the next six or 12 months, or what, what's kind of top of mind of here's the next set of challenges we might look at? I think, uh, the, the one is driven by, the first challenge is driven by, as an industry, a lot of scale of Kubernetes. The scale of Kubernetes is kind of taking off, right?
Mm-Hmm. And so, uh, as the scale of Kubernetes, uh, uh, takes off people underestimate the, the complexity of deployments and securing deployments. Uh, and so, uh, today, in fact, somebody came to a booth and he said, he asked the exact question and I asked him like, how do you know?
He said, well, rest of the guys are going see it six to nine months from now. So I think scale will drive the need for automating security. I think that's one.
I think the second is that the lot of, as in the software delivery, a lot of these tools, security tools that need to be inserted, like, you know, this scan, this scan, so on and so forth. I think that we are also seeing a little bit of a consolidation to say, Hey, I want the delivery bill materials for the entire delivery, uh, to be understood. Uh, I think that's another sort of trend that is just starting.
And I think that's the tip of the iceberg. Once we have that delivery biller materials and this application graph, you can do lots of interesting things, uh, including some generative AI way to understand, you know, how things happen. I mean, it's a, it's I think, a new frontier that we can hit.
But both these will, we are hoping will, will make the need for what ops provides deployment firewall and the delivery bill of materials, et cetera, ubiquitous, right? I mean, hoping that's kind of the, that's how we think of from first principles as to how, uh, you know, the industry and us can probably help. Interesting.
Well, where can folks find out more, go kick the tires or whatever They do? We've got a couple of, obviously if you're here at CubeCon, we're in Booth P 14, we've got demos and giveaways happening here. com has got more information for people who want to try out those solution.
We've got demo environments, trial environments they can go to kind of exceed for themselves how this sort of compliance and sandbox might work for themselves at deployment Farmers. That's one of those things you kinda have to see it, where You see it, where they test drive it, right? Yeah.
That's the way I am. So that kinetic learning I want, I wanna See it beside you. Absolutely.
And feedback for us is most important. We need customers to kinda Yeah, exactly. You know, kick the tires and make us work hard.
Great. Well, David, go Paul, thank you so much. Great Appreci for sure.
And check out the, uh, ops MX website and all the great content. If you're here, check out their booth as well. Thank you for joining us for this in, uh, discussion.
We'll be back in a few minutes with another great interview. So hang tight.





