Techstrong TV March 5, 2026
Guarding the “Wild West” of Agent-Driven Code: Endor Labs CEO Varun Badhwar warns that while AI coding assistants generate mostly functional code, security lags far behind—positioning Endor Labs as a real-time security intelligence layer to vet open-source models and neutralize AI-driven vulnerabilities at scale.
The Agentic Shift in ITSM: Xurrent CPO Phil Christianson explains how AI is transforming IT service management from reactive ticketing to predictive insights, automated remediation and intelligent service orchestration aligned to business outcomes.
AI Agents & the Open Source Supply Chain: Eclipse Foundation CMO Thabang Mashologu highlights a 20x surge in agent-driven activity across registries like Open VSX—forcing a rethink of funding, governance and scalability for AI-native open-source ecosystems.
Platform Engineering as the AI Superhighway | Ep. 12: Luca Galante joins to argue that internal developer platforms must evolve into automated, guardrail-driven “golden paths” to withstand the exponential pressure from citizen developers and autonomous AI agents.
Agents of Dev Podcast Ep. 12: A deep dive into how development teams are adapting architecture, tooling and governance to manage non-deterministic AI systems in production.
RSAC Cybersecurity Predictions 2026–2027: A preview of RSA Conference community research and Atlas insights—analyzing Innovation Sandbox trends, speaking data and the technologies poised to shape the next wave of cybersecurity.
Transcript
Hey everyone. Welcome back to Techstrong tv. You know, man, there's just so much going on every day.
I'm really happy to have this next gentleman I'm gonna introduce you to. His name is Varun Badis. Varun is the founder and CEO of Indoor Labs Company you may have heard of, but if you haven't, don't worry.
We're going to get you up to speed there. But first, let's welcome Varun Varun, welcome to Text Trunk tv. It's great to have you on here.
Great to be back here, Alan. Good to see you. Absolutely.
It's been a while. It's been a while, and I, you know, it must, I'm, I'm thinking it's, it's our RSA time. All my security folks are coming outta the woodwork.
Right. But, uh, it's good to have you here, Varun. We're gonna talk about indoor labs.
I want to talk a little bit about AI generated software and what we can do there. But let's first talk about you a little bit. People not familiar with your story.
As I mentioned, you're the founder and CEO at Indoor Labs. How did you know, how did, where did life take you from two to wind up here? Yeah, great question, Alan.
So, I've been building cybersecurity companies for the last 16 years. Uh, it's always been at this intersection of large shifts in technology. So my first company in 2010 was a company called CipherCloud in securing SaaS applications in the enterprise.
Right? People were freaking out, my data's gonna be with somebody else outside of my network, outside of my VPN. How's that gonna work?
And so we solved that problem. That whole category was called CASB, then came known today as kinda sassy and, you know, yeah, more, uh, kinda the zero trust architectures. And then in 2015, I saw a bigger wave coming, which was around, um, you know, moving from data centers to Cloud infra us.
So started a company called Ru Lock, uh, in, which was the defining company for cloud security Posture Management, uh, that got acquired by Palo Alto Networks in 2018. Uh, and we rebranded to Prisma Cloud. So I think a lot of your viewers would've heard of Prisma Cloud by Palo Alto Networks, uh, which is kind of the, the, the Palo Alto Wiz equivalent product in the synapse space.
We defined it with how executed us, but, you know, kudos to them. And then, you know, swallowing the spirit of the large tectonic shifts in technology. While I was working in Palo Alto Networks, I had 400 engineers reporting into me.
The summer of 2021, SolarWinds happened, and everybody started talking about software supply chain security. Sure. And for me, the biggest, uh, eye-opening moment was the fact that, um, you know, 80% of our code wasn't even written by our developers.
And it came from the wild to wild west of open source and everywhere else. And so we kind of said, how do you actually build software supply chain security for this modern ecosystem where your developers are mega assemblers of anything and everything available in the ecosystem? We made a bet.
We went really deep in understanding the risks around open source software. And lo and long behold, AI coding agents came along two years ago that were all trained on open source, and now they're replicating more and more coding patterns that they have learned from code on GitHub and everywhere else. And while it's become the hottest, most talked about subject in AI today is just AI software development agent software development.
You know, the thing that's really hard is engineers want to continue to innovate and move fast. And every security control and application security typically tries to slow them down, right? So there's always this trade off of security or speed.
And we said, look, there's gotta be a way to do security and speed in the software development lifecycle. And that kind of brought me to indoor labs. And today, the world's most prolific software companies, technology companies, financial services organizations use indoor labs.
You know, whether it's Cursor, whether it's Atlassian, snowflake, Dropbox, um, we're just incredibly proud to support the future of software. I love it. You know, Varun, what you just described was a lot of the reasons why I first, you know, got into DevOps.
I I really thought that DevOps gave us the opportunity, you know, it was like that old song by the singer, meatloaf two outta three ain't bad, right? You Well, it was like you couldn't have quality speed security. You couldn't have all three, though.
Some one can argue quality and security are similar or the same, but you know, you, you just, you, you couldn't have it all. If you got two of them, you were really happy. And I felt like with DevOps and modern, you know, agile to DevOps shift left software supply chains, we could have it all, right?
Yes. And they call me selfish and, you know, and all everything else, but I want it all right. I want secure software that we're going really fast.
So, you know, it, it's very, I I think it's a wor it was a worthy goal, and I think indoors made a hell of a lot of progress in, in helping us get there. Of course, the world has kind of changed. It's changing on it.
These last three weeks have been like watershed weeks. I think as we look back, we're gonna say, Hey, you know, after the first of the year, things just really went bonkers. But how is ai, I mean, AI's having a profound impact here.
How's it impacting your world? Look, it's an incredibly exciting time for us because there's more lines of code being produced faster than ever in every company. And frankly, a company in middle America that never even considered themselves to be have a technology advantage, I speak to them.
And today they feel like they do today. They feel like they can compete with the mega Silicon Valley companies. 'cause they have the tools where there's 70 developers in South Carolina can actually go build market leading technology that will help them drive their revenue as a company.
And so every company is certainly becoming more and more of a software company today than ever before. Yet, Alan, the thing that's always happened time and time again, is these shifts bring more ways for people to develop and innovate faster. But that also means if done unguarded, you're gonna have a lot of security risks that emerge into these new applications and architectures.
Guess what happens? It's no longer just your trained software developers writing code. It's people in my marketing team and my sales team writing code and pushing prs, right?
So the whole vibe coding thing is happening at the speed at which you're moving. No human, not even the most trained professional software developer has the time to review all of the verbose outputs of the AI coding agents. And so, you know, we said, look, let's tell you this, the models are getting significantly better and will continue to get better at providing functionally correct code.
In fact, Columbia University and Carnegie Mellon just did a study in December with Claude four sonnet, and it was impressive. 61% of the code produced is functionally correct. You wanna guess how much of that is secure?
5%, as I say. 20. Yeah.
Uh, so, so, you know, the, the thing is, these models are all trained in open source software. They've learned the good practices, but they've certainly learned all the vulnerable patterns of writing code. And they don't have an easy way.
It's not easy to filter and unlearn the stuff that's not great that you don't want them to replicate. And so, as an enterprise that is promoting fast software development, I now need to put the harnesses to watch out for all of this code, review it, make sure we can rewrite it without vulnerabilities, make sure it doesn't introduce new business logic flaws. Like turn off session time out in your application because you told it to go build a new API endpoint.
And so you need the guardrails, you need AI to combat that ai. And the last piece is context of your applications, right? It's great if you wanna produce some new lines of code, but in a typical organization, you're maintaining historical applications and architectures, and then you're building on it.
How do I give my AI agents context about my existing applications, my coding practices, my security practices and requirements, my compliance obligations? And so you need this security intelligence layer that's really missing as it comes to secure agent software development that the models don't have themselves. And so Endor is now becoming very quickly that security intelligence layout layer in the agent software development, which essentially helps customers do three things code really, really fast, but free of vulnerabilities, be able to automate review and security reviews and threat modeling and design reviews of all the code that's produced.
And the third thing is fix vulnerabilities that are disclosed genetically really rapidly. So you're no longer pushing a million tickets a year to your development team in their backlog, but rather working with them to be generate this flywheel to triage and fix vulnerabilities that can affect you rapidly. Because Alan, the, the problem is the adversaries have access to AI tools as well.
Just because you take six months to fix something doesn't mean they're gonna wait on you for six months to go attack you and exploit a new vulnerability. It would be nice if they did, but neither world don't work like that. And, and that, and that exactly is it.
You know, VU and I like you, I speak to a lot of people, speak to a lot of different organizations, and, and you're right, the feeling out there today is, my God, I could build anything. I could build anything, right? I have friends, executives, founders, past founders, serial entrepreneurs who have encoded in 30 years, 20 years who are saying, if I start a company today, I could build the whole thing right?
In a couple of days it seems like, and have an MVP up there and I don't need to hire a couple of dozen people. It's game changing. But at the same time, you know, we saw it with the, uh, the open cloth thing.
Are we, are we thinking the right way about security? Are we building it in? Or are we gonna say, okay, we'll we'll catch up to that, right?
Um, and, and sooner or later it comes back to bite you, right? We've learned this lesson how many times in our careers, if you don't do it in the beginning, it you pay the price. And, and you know, the interesting thing, Alan, is we've always tried to train the humans to do it the right way, and we've failed at it, but now we have an opportunity to get the agents to do it, and they're pretty darn good at doing stuff if you give them the prescriptive guidance of which you want them to get done for you.
And so for us, that is why I feel like it's security in the shift left arena, when you were talking about DevOps stuff like ops, you know, it started with CICD pipelines and scanning the pipelines, then we said, no, let's get into the PR workflow and let's scan the pull requests. Now, fundamentally to me today, it's how are you creating security experts that are pairing with your code generation agents in the agent software development workflow, well before it even becomes a pull request. And so the way, for example, and or surfaces the tooling for customers is you're in cursor, you're in clawed.
Use your favorite tool. Those tools know that they need to be reviewing all the code they're producing with indoor. We give them continuous feedback.
You can literally see it in the spec. They're rewriting the code based on our feedback. When they say done, you know that there's gonna be vulnerability free software because Indoor has helped Cursor or Claude or CLO or copilot just produce the code right from the onset.
And so now I don't have a backlog I have to deal with, or if a new vulnerability comes out in, in three weeks, I don't have to put it on the human to fix. I'm gonna tell the agent where the vulnerability is, how to go upgrade that without breaking your application, and then let it go, execute that action really fast and test your application. I love it.
I love it. So Varun, uh, I gotta ask hard question, right? We're all talking about ai, we're all telling, telling each other what a great world is gonna be, but rubber, at some point, rubber has to meet the road.
Mm-hmm. As we sit here today with Endor, where, where is your AI security, if you will, how real is it? How built in?
Is it, how widely used? Is it right? Is Yeah.
Is it here? Is it still something we're talking About? Well, as I mentioned earlier, you know, some of the world's most prolific software companies, the biggest AI company on the planet, all the way to the biggest, a coding agent company like Cursor on the Planet to Atlassian, snowflake, MongoDB, uh, they're all customers.
They're actively every single day building and shipping a software that is secured by and or labs. So it's here, it's working, it's scaling. Um, for us, there's two parts to this, right?
There's, how are we using AI internally to solve decade old cybersecurity problems? Mm-hmm. I'll give you a real example.
You know, when you run all of these code scanning tools, you get like 50 to 80% false positives. Alan, like the stuff that they find may theoretically be a problem. But when a developer looks at the entirety of the application architecture may find, well, yeah, I'm not doing any validation of input here, but I have a framework here that handles it for me, two repos or two files away.
That's the rate reality of modern software security tools. Never were able to understand them indoors. AI SaaS actually is actively for our customers today, automating that entire triage and investigation process and reducing the backlog by 70, 80, 90%.
Saying like, look, you're safe. Sure there might be a theoretical problem here, but we see it in the entirety of your application flow. It's no problem.
So we're using AI to deliver better security outcomes. So that's one. The second, Alan, is we're helping our customers adopt AI more safely and with confidence.
An example being if you're trying to pull one of the 2 million models of hugging face and deploy it as part of your application indoors, doing all the scanning for supply chain risks, malware, you know, malicious pickle files, all of that, as you're going and grabbing open source models from the internet, or you want to use PyTorch, making sure you're getting a secure version of that from pi pi. All of that analysis for malicious actions. Because look, the attackers know this open source ethos is a wild, wild west, right?
We saw Shai Ude as a, uh, large attack campaign, a target open source. And you know, we're seeing more and more of that, which is where we are able to protect the AI supply chain for our customers. So they can adopt AI faster or they can use Cursor to write code faster.
And so yeah, both facets of, uh, addressing decade old security problems with ai, as well as empowering you to use the latest AI tooling is something that's front and center here available now to use Arun. We're about outta time. You know, we didn't mention indoors website though.
Can you just give us a know, you know, what's the website? com. Check out, um, you know, our recent announcement of our new agent software development security platform called ori.
com. I love it. Varun, will you be at RSA?
I'll be at RSA. And I look forward to meeting you and, uh, anybody else interested in catching up on this, uh, on this topic I'm extremely passionate about. As you could tell, I know you are.
I'll be a broadcast ally all week. Stop by and say hello. Will do.
Thanks so much. All right. Varun Badis, founder and CEO of labs.
Hey, you know, doing what a good CEO and company needs to do today using AI to secure software BREW will be in touch. Thank you very much. We're gonna take a break here on Tech Trunk tv.
We'll be back. Hey guys, thanks for the throw. We're here with Phil Christensen's, chief Product Officer for Zurich, and we're having a chat about, well, how AI is actually being applied within IT operations.
Phil, welcome the show. Thank You, Mike. Happy to be here.
So we see a massive amount of hype around AI these days, and it's supposed to do everything from, I don't know, curing cancer to sending us to the moon and back. But, um, it does seem like there were some basic fundamental things and IT operations where it's making a difference. And so are you starting to see that and do IT folks, or do they have faith in AI these days?
'cause I think initially there was a lot of skepticism. Yeah. Well, thanks, thanks for the opportunity to chat.
I look forward to talking about ai. Certainly a topic of of interest at the moment. Um, if, if you wouldn't mind, just to give a little background on, just so there's some context for the types of the answers that, uh, give on, on who I am and what we do.
And I won't, not gonna go into a marketing pit, just just for some background. It SM platform, so service management as well as an incident management platform. So we allow for our customers to basically run a service desk.
So the traditional kind of broken laptop, someone calls in with a problem, uh, as well as the broader IT operations issue of a machine breaks, a, a router goes down, a server crashes. These things break in the middle of the night on a Sunday, and they aren't gonna call a help desk. They're gonna send in an alert through an observability tool.
We integrate with those tools and we bring that data into our incident management system, and we help our customers to, um, establish war rooms, contact the right people, um, establish escalation trees as well as run playbooks and, and actually execute remediation steps to resolve the problems that are occurring. And then retrospect on, on what's occurred. And, you know, everything I just described are, these are workflows that organizations have been doing for a long time.
Neither of these concepts are, are new by any means. But what we've seen from an AI standpoint inside this space is really an ability to bring better tooling, more efficiency, help all our customers do more faster, uh, with less. And, you know, if you dial back when this all started, I guess in 2024 ish, somewhere in there when LLMs really took off, you know, we started with a lot of sort of your standard LLM based tools, things like summarization capabilities, uh, reading from a, uh, uh, historical tickets to figure out how to route something, sentiment and tone analysis, you know, Grammarly style, uh, improvements.
And all of these things were help people to be better. And I think they helped you to do your job faster. I think as, as 2025 sort of on, uh, took off, you started to see more, we started building things like chat bots and, and actually constructing multi-step interactions where not only do you summarize something, you also, you know, look for a specific answer.
You maybe first you look for a knowledge base, and then you look for a similar request from the past. And then you create a ticket, you start to piece together multiple steps. And, and now I think we're seeing 2026 is this year of ag agentic.
And, and ag agentic really gives this idea of not only bringing tools to, uh, our customers, but actually taking action. AG agentic is like that, that grand leap into, uh, not just, uh, tooling, but remediation and actually going out and having an AI agent go do something, add scale to a server, restart a, a, a, uh, a router, like truly taking action. And I think that's where things start to get a little bit more radical, but, uh, that seems to be coming.
And are people crafting these workflows around AI agents, or are they still experimenting with them? Or how far down the path are we? Well, I think that the idea of a workflow in a, in a, in a, in a automation tool like ours is not new.
Like we, for, for many years, ITSM tools and, and incident management tools have had workflow capabilities where you say, you know, when this type of event occurs, execute these four steps. And those steps could be web hooks out to third party systems. They could be, you know, waiting for approval from a manager to take, to execute a task That's not new.
I think what's new is that you now have, um, these AI agents who can more intelligently figure out when to do these things, and you can actually determine based upon what's occurring in a customer's environment, which one of these tasks should be executed. So I think executing workflows, constructing workflows is not necessarily new. I think it's more about helping our customers to understand when execute those workflows and, and, um, maybe doing them faster.
Also, it seems to me though, that the creation of the workflows are becoming more accessible because I do have a natural language interface. And I think historically I had, I have a lot of expertise to create that automation, and maybe I don't need as much of that anymore. Yeah, no, I think there's some truth in that.
Uh, for sure. It's, it's getting easier to build these types of automations, but I still think that you still, you still see, um, especially in this world of, of infrastructure and IT and IT operations, you still see many companies, I'll give you ours as an example. Um, the founder of our company is still still a member of our engineering team and, and a very important member of the engineering team.
And when I joined two years ago, he'd been, he'd been found the company eight, eight years prior to that. He was still operating as the SRE, basically, he was still the guy with the keys to the kingdom to AM to our Amazon account. And the one who had control over who could get it, like be, it's such a critical part of who we are.
And with that information, so much can be done. You could, you could take down our system, right, with that information that, that he has. And I think that the, I the last thing he gave up as he sort of became a, a founder moved into a more of a strategic role as he moved outta this operational role.
The last thing he gave up was those keys to the kingdom. And I think that's very common at, at small companies that the, this, this thing that you're seeing get automated in IT operations space, or at least claim to be automated, is sometimes the most critical part of your entire company. So I still think there's not skepticism, but a, a desire to make sure that's done safely.
Um, many, many companies, I'll give you one last example. I was talking to a, a customer who was evaluating our software, and we were talking about the idea of these virtual SREs or virtual IT operations members. And this guy was like, why would I, uh, hand that over to an an AI agent?
Those are the most critical jobs in my company. They're the most high pay, high paying jobs in my company, and they're the hardest to recruit for because they're so important. That's the last thing I'm gonna hand to an AI agent.
So, I don't know, I think there's, in this space of IT operations, we've chosen some of the most critical functions to, uh, theoretically hand over to ai. I think it's gonna take some time, uh, before companies start doing that, Are people rethinking what their ITSM platform's gonna be? Because a lot of them are looking at their existing platforms they've had for many years, and they can see that there are AI capabilities being added to them.
So what kind of creates that moment in time where somebody wakes up one morning and says, Hey, we need to just rethink this from the platform all the way down to the, the Yeah. The studs as it were. I mean, I, I don't know that that's changed much.
I don't, I mean, as it relates to ai, I think that people are constantly evaluating their SaaS products, say, uh, in, in, in any enterprise. And you wake up one day after using the tool for, uh, three or four years, and you realize that you're paying a lot of money for it, you're using 20% of it, and you've got a bunch of data that you didn't spend enough time making sure was well organized, and it's a mess. And, you know, suddenly like, well, I could clean all this up, or I could just go find a better tool.
And, uh, that's where we come in and we, we do a lot of replacements in that, in that area. But I, I think that's a, that's not uncommon. I think that, I mean, that's not being driven by ai.
I think that's just the nature of enterprise software. Yeah. And, and a lot of the reasons that there's, there's so much turnover.
You know, ITSM is a billion dollar turnover market every year. Um, because of that, You hear a lot these things about how people are going to deploy their own AI agents, build their own workflows, and there's a lot of noise on Wall Street about the impact that all this will have on SaaS applications. But I mean, what's realistic here and what do I wanna do versus even if I can do it doesn't mean I should do it.
Yeah. I, I think at the end of the day, if you think about platform vendors in particular, um, I think they like ourselves. I think this is the area where to some extent, you, you're still, you're going to need platforms.
If you think about in our, in our space, there's over a million requests logged across our customers, a million and a half requests logged across all of our customers every month. That data from those requests is not in any LLM is not accessible by Claude or anybody else. It's in, it's behind our, our walls.
And if we, if, if we, the only people that can access it are us. And I think that's not uncommon for ERP systems, CRM systems, there's a core data element that platforms have that you're, you're, you're, you're not gonna be able to, um, sort of vibe code your way into. Um, frankly, I, so I think that, you know, you look at this world of, of vibe coding and, and Claude Code and like, it, it very much focuses on sort of that top layer, the UI layer, um, there, there, when, when you start dealing with larger enterprise applications, you're dealing with a lot more than that.
Um, and I think we're actually well positioned as a SaaS company to take advantage of these tools and, and to use this amazing knowledge base we have of how our customers have been using our ITSM for the last decade to bring better and better tools, um, to our customers. How smart will these platforms get? And I'm asking the question because at some point, will I, as the IT manager just kind of roll in the work in the morning and there'll be a message saying, here are the three most important things you should fix because, you know, these are the ones that are most likely to get me fired.
Or, you know, yeah. Is it gonna, We do that today? We've done that, we've done that a lot before.
That's, that's why people buy our software. Uh, no, that's, you know, I, I don't think that's, I, I, I think bringing the right problems to the right people is what our tools have been doing from the beginning. And, um, we want to be able to do that better.
We wanna be able to give our, our customers tools to, um, remediate those issues when they do occur. But I don't think it changes this fundamental need to have orchestrating tools and, and, and systems of record. Um, you know, I, you think about if you've ever been through like an ISO certification or, uh, any of these compliance certs that companies get, if you think about the rigor that goes into those, this is why companies use enterprise software, is because there's actually rules that govern how you need to operate as a company.
And, and that requires having systems of records and, and process and audit, as boring as those things sometimes sound, that that is what keeps your data safe. And when you sign up for, uh, you know, when you, when you buy something, when you go to the hos, the doctor's office, like these things are not just done because people, you know, for fun, they're, they're done for, for real reasons. And I think that that doesn't change just because there's ready access to, um, to, you know, workflow capabilities in vibe coding.
There is some expectation out there, at least in some quarters, that eventually these AI agents will reduce the number of IT people that we need. Do you subscribe to that theory, or is it gonna be more about, well, maybe we'll just get more value outta the folks we do have, in fact, maybe we will see more organizations hiring professional IT folks because, well, there'll be more of them available, but we still need 'em. Yeah, I, I, I mean, I think it's, it's the latter.
Every job I've ever had, personally, the first thing I do when I get into seed is start to look for things I can automate and look for things I can do faster and more efficiently. I think any strong professional it, uh, person does that. And, you know, the idea that there are teams of junior IT guys and gals that are just doing mundane password resets all day, like, I just don't think that exists today.
Anyway, uh, I, I, I think that these things have all largely been automated, and you already are in a situation where you are constantly pushing your employees to, to do more and think about things differently and come up with more efficient ways to do their own jobs like that. That's how you rise up through corporations and through, uh, the professional world. And, uh, if you're good at that, you're gonna be even better at it with, uh, the types of tools that that AI will bring.
It seems to me too that maybe our expectations for AI are a little, uh, off the charts, shall we say, and won't it just kind of become the new table stakes and everybody's gonna have the same basic set of capabilities. So, um, you know, what is the ROI per se when, you know, it's not really gonna be necessarily a competitive advantage as much as it is just something everybody does. Yeah, I mean, majoring ROI has always been the name of the game and enterprise software for any feature we've ever built.
And that's how, that's, that's how I, as a product manager my whole career, that's how I've always thought about everything from, from a, from AI or before I think about how many of our, my customers are gonna use this, what's the impact that's gonna have at, at, at their operation? And, um, and is it something we should build? And I don't think that, um, fundamentally changes.
I think there's just better tools available that can have a larger outsize impact as, as we deliver them. And, you know, it's, we will certainly see a change in how those tools are created. I think we'll be able to make more tools faster.
We're already seeing, our engineers are all using cloud code now, um, as you know, what do they say? Like 10% of all public code written is coming through cloud code now, or some insane number like that. Uh, it, it, we're going to be able to produce more code more rapidly, but all of that code is going to remain aimed at, uh, I improving the return on value for our customers as they use our software.
And, you know, we're, we're embracing that. We're embracing the idea that, um, hey, maybe, uh, a year ago you needed a hundred people to do this job, and now you, you need 80. That's great.
We love that here at Zurich, and we'll figure out a way to, to, to be okay if, even if that means a reduction in the amount of licenses you need to buy from us, we, we'd rather we brought efficiency gains to our customers, Right? But those other 20 might go work for organizations that previously would never have had an ITSM platform or something of your ilk because they couldn't afford, or were just basically trying to get by with some, you know, non platform oriented tools, right? Yeah, yeah, I suppose so.
But, you know, I think that they'll take with them the knowledge of the, the, the tooling that they learned, uh, at their previous job. So, you know, we have a very vibrant word of mouth, uh, uh, network of, of, uh, of users in, in, in the zu in, in the exert world. So, So what are you seeing people do in terms of the way they manage it today that just makes you shake your head a little bit and go, folks, maybe we should be a little bit smarter than that.
Interesting. Um, you know, I, I do think that, um, there's an interesting divide between IT and DevOps. I, I've sort of lived between both my career as, as sort of a, a creator of software and then also a member of IT departments and know the, the DevOps world is one in which they embrace a little bit more of a, uh, people over process type of mentality where they empower people to define, uh, uh, how they want to operate it.
It, by its nature is a little more rigid, you know, it's a little more here, you know, you look at the ITIL standards, it's these 32 different ways of doing things, and you do them this way and statuses flow this way. And I think there's a, there's some amount of rigidity in, in some IT organizations that could be, uh, loosened up a little. I think I, I think that there's, there, the, the strict, strict adherence to, uh, process is important.
It allows you to scale an operation, uh, which you ultimately is a good thing. But I think it can drive people, it can, it can make jobs feel more mundane. It can remove some creativity from, um, everyday life.
And I think that that is something you don't want to do. You know, an example, we, we released an AI feature in which we, we de we, um, attempt to assess the sentiment of a conversation. So you're, you're in, you have a ticket open, the ticket has gone back and forth.
You got someone really frustrated, they're not getting the service they expect, and they're angry. We'll put a little frowny face and we'll give a little description of, of, you know, or maybe even like, you know, steam coming outta the ears. And we used emojis to do this in our application.
And, and you know, there was an, it was an incredibly polarizing feature. Uh, we had a lot of IT professionals that were like, how dare you put an emoji in my ITSM? That is not the place for them.
You know, this is not an ITIL process. Get it out. And others that were like, okay, maybe my tone is a little bit, uh, too techno speak in nature, and I could lighten up a little when I, when I have these conversations.
So I dunno, I think a little bit of lightning in, in it, a little bit more of the people over process is not a, not a bad thing. Hang. Do you think therefore that maybe AI will be the vehicle where maybe we do introduce a little more empathy across these workflows?
'cause Well, that's a big phrase in the land of DevOps, but to your point about idle, you know, it's all about thou shal, so there's a middle ground here. Yeah, Yeah. And maybe, you know, I think that, um, there's certainly the, the pace and speed of innovation that AI is enabling is going to allow ITSM companies to just do a lot more, a lot faster in the coming months, frankly.
And I think being open-minded to change and open-minded to doing things differently, uh, is, is important. And I, there seems, there does seem to be a moment here with the what's happening and what's available that, uh, you know, if you, some of these thought pieces that have come out that perhaps have even moved the market related to, you know, the, the future of something big is happening. And some of these big articles that are out there, they talk about, you know, you know, put your ego aside no matter how senior you are, you are, and, and make sure you take a look at these things.
And I, I think that, that, that seems to be happening. All right, folks, who knows? Maybe those lions and lambs will be lying down together.
After all that was right. Thanks for being on the show. Absolutely.
Thank you, Mike. Appreciate your time. All right.
Back to you guys in the, Hi, everyone. Welcome back here to TechOne tv. I'm happy to have Ang Maia logo.
I hope I got it right. You Nailed it. Ang is, yeah, we did it.
Great. Ang is now the chief marketing officer, CMO at Eclipse, the Eclipse Foundation. So first of all, Tobar, since the last time you hear of promotion, congratulations.
And they got a good man for the job. Good for you. Good for them.
I hope so. Yeah. I, I think so.
Toba people say, how, how do you qualify to be the CMO and a place like the Eclipse? Give them a little sense of your journey. Great question.
So, um, I am an engineer by training and trade initially on in my career. Um, I've had a variety of roles in r and d and product management and marketing over the last, over 20 years now. So I'm, I'm dating myself here, Alan, uh, mm-hmm.
But the, the last decade or so I've been in the open source world, and it's been quite a ride. And, uh, no day is, is the same as the, uh, the last and at the Hoops Foundation, uh, what, uh, we do, uh, our mandate is three things. We want to, uh, uh, ensure that we're empowering developers, we are enabling collaboration, and we are ensuring user freedoms.
So the role of my team, the, the great folks that I get to work with around the world, is doing that from the perspective of marketing and events and product management, which, uh, we're gonna talk about a a bit later on. Excellent. Um, you know what, as we were talking off, off camera, I think a lot of our audiences heard the name, the Eclipse Foundation.
It's, it's a, it's bedrock in tech, right? It's, it's a known entity. But I bet if I asked everyone who raised their hand, if they heard the Eclipse Foundation, and then I went around and asked them, well, tell me about the Eclipse Foundation.
What does it do? You know, what's some of the software or the projects? They have a tough time.
So look, you're the chief marketing officer now, man, right? This is your job. You gotta change that.
You gotta change the equation to Mark, tell, tell us, you know, give us the, I mean, we don't have all day, but tell us the Eclipse Foundation story, The, the elevator elevator pitch, if you will. Um, so we are one of the world's largest open source foundations, and our mandate is to essentially provide stewardship, so governance and, and a process framework around, uh, over 400 different open source projects, uh, ranging from the automotive software defined vehicle space to developer tooling to AI and, and edge computing. So we have a pretty broad portfolio in terms of the different types of technology that are, um, hosted and honed at the Eclipse Foundation.
And we are proud of the fact that we are the largest open source foundation that's actually based in Europe. So that's something that, um, uh, you know, if you look at our contributor base and committers, uh, it's a global C community, but we are based in Europe and, uh, and proud of those roots. Look, in this day and age of digital sovereignty and national sovereignty and personal sovereignty and AI sovereignty, and all of the sovereignties, all of them, it's an important, yeah, it's important.
It's an important distinction. And I, I thank you for bringing that up. You know, Toba, I really think when we look back over this next, over the last, let's say three, four months, and over the next few months, when we look back through the lens of history, these are the months where I think the AI disruption that we've all been told about is starting to really gain traction.
We're seeing it in open source software. We're seeing it in open source models, we're seeing it in security, the amount of vulnerabilities and bugs being found by AI scanners. Um, and a lot of people are saying, oh, it, it's the death nail for open source software.
Well, there's a lot of people who kind of, you know, the algorithms rule them a little too tightly and they get a little too wound up, but to say that it's not having any effect is naive and, and not true either. So talk to us about how, in this day and age registries, let's say like open VSX, right? What is the future, near term, long term look like for them in this age of ai?
You know, how does it stay current? How does it incorporate this and, and, you know, stay as useful as it is? Yeah, that's a great question.
I, I don't think it's a, an exaggeration to say that AI is changing every facet of our lives. And that includes the digital realm and ecosystem that, that, uh, we are part of as the Eclipse Foundation and, and, uh, the various open source projects that, that we host, uh, under our Aegis, um, the, the way in which it's, uh, altering that landscape and the work that we do is something that, uh, we are still trying to wrap our heads around. I think you're absolutely right.
Uh, you, you, you didn't necessarily say this, but what I heard is that, uh, we're at an inflection point, uh, both in terms of how it's impacting consumption and usage of the different products, if you will. The, the, the software that comes out of the open source collaborative model, but also up and down the value chain or supply chain, you're seeing, um, AI having a profound impact, impact, rather. And you mentioned open VSX.
So open VSX is the world's largest vendor neutral marketplace for vs code compatible extensions. Uh, what does that mean in, in practical terms? Well, think of it as an app store for, for any extensions that work with vs code compatible, um, uh, uh, technologies.
So as a result, what we are seeing through that extension registry, and this is something that, uh, in speaking with our friends at other package registries and, and repositories, uh, it it's something that's industry-wide, is that you're seeing the extensions being consumed in a way that is different than Alan and Tang using, uh, using the software as we would've through, uh, an integrated development environment, uh, an IDE or a platform. Uh, these AI agents, um, have a mind of their own, uh, I'll put it that way. And, and the, the nature of that, uh, often in terms of bandwidth and downloads is ex, uh, exponentially higher than, than what you would've seen from individual developers, right?
So we've got some platforms that are using open VSX as a default registry that when they fire up, these AI agents essentially go and install and update extensions at 20 times the rate that a developer would. So at, at, at that level of, uh, of scale, uh, in terms of, uh, the multiples. So we are all having to cope, uh, and, and as an open source project, open VSX is an open source project, and it's also a public registry that, that we host, uh, on our infrastructure.
Uh, we are seeing our various costs, our bills go up in terms of the, uh, the bandwidth and storage and, and, uh, and and compute that's related to operating open VSX. So what that has caused us to do is, is really have to, um, make some good and hard decisions around the future of open VSX and ensuring that it's always available and, and freely accessible to the developers that rely on it, as well as the companies that are commercializing and building all of these great innovative AI native tools, uh, on top of it. So it's, it's the best of times and the best of times, uh, in the sense that we are, uh, we we're, we're seeing a lot of goodness, but, but, uh, also commensurate challenges, uh, associated with that.
So it's, it's goodness squared, if you will. Yeah, yeah. No doubt.
You know, I was, as I told you before we got on camera, I did a whole bunch of videos today, but in, in talking to some of the folks that I've been interviewing and talking with, I think what we're seeing now with AI is problems of scale. Yes. Using ai, we are running into scale like we've never seen, right?
Finding 600 vulnerabilities in open source projects a few days after you release a new version of an AI model, we're really not equipped to, to go do, you know, to go deal with that in a timely manner. We've gotta, we've gotta build up the muscle memory and, and, and responses for that kind of thing. When we look at the amount of code, I, I saw some charts today, the amount of code in 2025 beyond hockey stick, it's almost vertical.
Yep. Right? The amount of open source, uh, uh, code contributed, all of these things are ho not hockey stick.
They're vertical lines. Yes. Yeah.
They're vertical lines. Like you said, you need the infrastructure to support that. We, we weren't, if we weren't counting, you know, on doubling or tripling our storage or our bandwidth or our instances or our compute power, um, yeah.
Not to mention what using AI itself takes in terms of compute and, and infrastructure. Absolutely. Absolutely.
So these are all things, and, and you know, in a lot of ways, at least in the tech industry, tba, I, I feel like we're a new kid with a toy on Christmas Day, right? And, and we're, we're using AI because we can, not necessarily, because we should not, that we shouldn't use AI for, you know, we are using it for things that I think over time we're gonna realize, yeah, no, that's not probably the best use of it economically, or, you know, for whatever reason we're learning all this, right? This is a, this is a literally, you know, an 800 pound gorilla that we don't really understand the, its best usage, its best way of, of, of leveraging.
Uh, unfortunately it falls to organizations like the Eclipse Foundation, right? Because you're on the front line of this. So I get what you're doing, I get what I'm hearing from you.
I guess my final wrap up to you is how are you coping? Yeah. It, as, as I think you're spot on.
Um, and as we were saying before, it's an embarrassment of riches and, and learnings and coping is, is absolutely the right word. So, just to put what you're describing into, uh, into perspective, when we first launched the Open VSX registry, so this is again, the, the publicly hosted version of Open VSX, the project. We were thinking of it as a best effort, background service that would help satisfy the needs of our community and a few, uh, stakeholders in the, in the industry.
Um, we just recently surpassed 300 million downloads per month. Um, so that's about six times what we saw in the initial year. So a six x to your point around scale.
Uh, and, and by the way, I, I, I bought a sweet spot in my heart for hockey analogies because I'm a hockey dad, hockey parent twice over. So I spent a lot of my time in, in hockey arenas. And by the way, it is, as you said, it is very much this, uh, this, uh, exponential growth that we're seeing, both in terms of the, the downstream consumption, uh, and but also the publishing where we're up to 7,000 unique publishers with 10,000 extensions.
Every time we update our, uh, our, our, our, uh, dashboard, it, it's immediately out of date because that, that growth vector and that velocity is, is as strong as it has been. And the primary driver for that, uh, or at least one of, uh, the, the primary drivers to your, uh, earlier question is AI made of tooling and, and what we're seeing in terms of the cloud IDs. So you can go through essentially a, a who's who, A vs code compatible, uh, platforms and tools that are backstopped by, uh, open VSX, so have backend integrations into open VSX.
You've got your Amazon kiro, your Google Anti-gravity cursor, windsurf, all of these use open VSX. And, and what that's translated to for us in terms of coping is making sure that, um, we, we have the funding and, and, uh, and the operating model that keeps pace with that. So some of the announcements that we've made recently are around implementing rate limits.
Uh, and again, that's not to punish anyone, it's really to enable us all to thrive, uh, both individuals. So the, the developers and open source projects out there for whom we're giving, um, really generous rate limits as well as the commercial platform vendors, the folks that need to have, uh, the, uh, the downloads and the bits flowing at a much faster rate in order to satisfy their millions of use, uh, of users. Uh, there was a recent analysis that that, um, estimated there are approximately between eight and 10 million developers that rely on open VSX.
They may not know it. And in fact, in many of our conversations, we ask people, Hey, do you know anything about Open VSX? Have you used it?
And they say, no, but when you ask, uh, Hey, do you use, uh, antigravity from Google or, or, uh, any of those other platforms that I mentioned, it turns out that they are indirectly using Open via sites. So, uh, rate limiting to ensure stability and scalability. And then, um, we are actively working with, uh, some organizations such as as Kiro as Amazon rather, uh, and, uh, and Cursor who have really stepped up their support and, and we're tremendously grateful for them, uh, uh, kicking in financial contributions as well.
Um, so it's, it's all of those things. We're looking at it from a technology perspective, from an operational, and also financial in terms of working with those key stakeholders, those heaviest users, to ensure that the sa the, the, the service is secure. It's, it's stable, it's scalable, and, and freely available for, for the ecosystem.
Love it. Deba, I, I realize it's probably a little later in the day by you. I appreciate you coming on here.
Best of luck. Well, first of all, and congratulations on be being CMO now. Thank you.
And, uh, best of luck to you and the Eclipse Foundation. Come back on and keep us posted because these are, these are really interesting times, right? We're gonna see how this unfolds all of us.
Absolutely. Yep. Well, thank you so much.
All right, My friend. It's good seeing you. Congratulations and be well.
Thank you. We're gonna take a break here on text Trump tv. We be, we'll be back in a moment.
Hey everyone, welcome to Platform Engineering podcast. The platform engineering podcast. You know, we, we haven't been on in a while, but we've got a really good excuse.
My friend Luca here is now a papa. He had a baby, and the little knower is over a month. Yeah, over a month older Eddie.
Right? Over Six weeks I think. Yeah.
Six Weeks. And, but it was as it always is, you, you know, you could tell people, but until you live it, you don't understand it. Uh, it was, it was more than you bargained for, but better than expected.
Yeah, right. LUKA percent. It's been, it's been a bliss and, um, and a rollercoaster in the last six weeks.
Uh, but it's, it's, it's been awesome. But yeah, not too much time to record podcasts, unfortunately. No, no.
But hey, let, let's, we'll jump right into it. Um, you know, so what's been going on while you've been busy a lot, right? I really, yeah.
I really feel like when we look back five years from now, these last, let's say three months, November, December, January, February, four months are going to go down as sort of the pivotal months where the a ai, it hasn't caught up to the hype. I don't think it'll ever catch up to the hype, but AI got real, right? I, I think the releases of, of philanthropic Claude and, and, uh, AI codes Codex in November and December were watershed releases where it stopped being a toy and became, oh my God.
Yeah. Production Tool, Right? Yeah.
This thing works. Yep. It's a production tool.
And, and I think what we've seen since then too is like with the release of Claude Opus and, and some of the security tools and using it to find vulnerabilities. I know in the security world, my friends are full. I, I don't mean to be cr but they're crapping themselves.
I would, right? There are so many, we're finding so many vulnerabilities. How the heck are we going to keep up with this?
Because if, if we could find them, the bad guys can find them too. And it's so, it, it's really changing the game we're seeing. You know, and I'm not here to doom and gloom it, but if you work in front of a screen and you are not leveraging AI in your job, someone else is, and they may take your job, you may not lose your job to ai, but someone else is using it and they may replace you, Luca, in, in terms of platform engineering, that doesn't exist in a vacuum either, right?
Platform engineers are being tasked with, Hey, we gotta build this new vulnerability scanning right into the platform, right? We need to scan code as we're writing it, as we're putting it in the pipeline. We need to fix code, we need to understand our, we need to instrument our platforms better.
We need to AI our platforms. And do we need a separate platform for ai, a new platform for ai? What does that mean?
Do we need two platforms? Do, do we make one new platform? org in the community.
What are you hearing? What are you seeing? Yeah, Yeah, like you said, I think it's a super, super interesting time.
I think I was reading like a couple of, uh, tweets or ex posts, whatever, um, uh, on this like kind of like, Hey, Q1, 2026, you'll be looked back on as sort like this, like text singularity type of thing. Um, which, who knows? It might at the same time, it's like we keep saying this, you know, because it keeps accelerating.
So, you know, probably Q2 is gonna be even phaser. Uh, but what I think it is crazy, crazy now is like obviously the, you know, AI's coming first for light, you know, coding and software and you know, then it's like, you know, if you look at, um, the, the releases of, of Anthropic, I think it's really interesting. And, and like, and this is actually, I dunno, if you listened to this podcast with Elon on, on the, you know, the three hours conversation, uh, with the, with the PayPal guy, no, sorry, the Stripe guy.
Um, and um, right, you know, they're talking about all sorts of like crazy stuff and rockets and so on. But like one interesting, I felt like there are like a couple of interesting things around, like how is he planning to monetize xai and how are they seeing also, like people like philanthropic, you know? And it's like, well, yeah, like you could look at this and like, okay, well their CapEx is through the roof.
They're spending crazy amounts of money. Um, how are they gonna ever make it up in like licensing? You know?
And they're like, well, we don't have to make it up in licensing. We can just go disrupt like, you know, trillion dollar industries and just like, take that revenue essentially. Like, 'cause 'cause once to your point, right?
Like if you're, I think if your job is sitting in front of screen today, like any of those, like white collar jobs and just like desktop jobs, like none of those are safe, essentially. Um, they can, they can, they're gonna go after, you know, each, each one of them 1, 1 1 after the other. And I think Elon made an interesting point that was like, you know, I don't even need to go and do crazy stuff.
I don't need to go and like replace their, like rocket scientists. I can go replace like, um, you know, the 1% of the global population that does, um, uh, support in call centers. You know, like that's like half a trillion industry that you can com.
You know, you can just take like, you know, a, a fraction of that and that already pays for the entire CapEx of, of like data centers and so on. So I thought that was interesting. And I think if you look at like what philanthropic has been doing the last few weeks seems that it's like that kind of playbook.
And I don't know if like Dario is, like shorting is like making money on like shorting companies, like right before he announces stuff, but he could, because it's like, you know, like the, the, like, you know, if you look at like Palo Alto networks, like, you know, all the, all the security, uh, tickers that we are familiar with, it's like, it's crazy. Like every time they release something they crater like 10, 15%. Um, you know, and, and they, yeah.
Look, IBM with thing, IBM was down 13% this week because cobol Yeah. So that's crazy. So that's, so that's happening and that's there.
I think, you know, going back to your question like the, the platform eng, you know, we've been saying for like six months that, you know, AI really has overshadowed, I think a lot of the trends that we've talked about in IT enterprise for the last 18 months, two, three years, whatever, it's probably just turbocharged platform engineering. Um, and I think we're seeing that still. Um, and in fact, I think it's, it's accelerated.
Like I think what you're seeing with AI is either it's killing stuff faster and faster, or it's accelerating the need for other things faster and faster. Um, and I think well designed platforms and well thought out, uh, golden paths and, you know, and all sort of like the best practices and principles of platform engineering that we've been talking about, you and I on this podcast for the last year, plus all of those things apply a hundred percent. You know, and in fact they're, they're, they're, you know, they're more needed than ever because you're going from application developers being the end users of your internal developer platform to now you have this concept of citizen developers, IE anybody in the, in the enterprise can be essentially developers.
So you number of platform users is 1,000 xing, and then you put ages on top of that and it's like, you know, getting another two or three orders of magnitudes, right? So, so all of a sudden now you, you, you, the need for, you know, a well streamlined set of workflows and processes and, you know, they're all sitting under this platform thing is, is increasingly, um, you know, enhanced. And, and, and, and, and you see this also in the data.
We, we keep serving platform engineering teams and you see the explosion of the responsibility of running and supporting AI workflows, AI workflows, AgTech stuff is gone from like five, 10% a year ago to like 30, 40% when we released data apart from engineering report in November, December, and it's already broke instead, right? So I, I think clearly you're seeing this trend of offering teams, um, owning more and more the responsibility ultimately for the stack. And to your point, you know, is this like an AI platform?
Is this an AI set of workloads on top of the existing platform engineering, uh, stack? Um, I think it's both, honestly. Um, I think it's like what we are seeing is enterprises that had their, you know, their housing order with, uh, with platform engineering, uh, initiatives already rolled out or rolling out can take advantage of AI much faster at scale.
They can move from, um, you know, this like impressive day one demos to like actually day 100 operations at scale very, very easily. Because their mindset is there. Some of the setup is there, obviously you need to tweak things, but more importantly, I think the mindset is there, right?
Of like, Hey, we need to have like a solid backend and then, you know, plugging on top all these different things and you can, you know, basically roll over the same permissions to agents or, um, you know, if I'm a user and I, and I want to u and i, I want, and I have a set of like LLMs that are doing stuff for me, those LLMs can inherit my permissions. You know, and, and so there's, there's a set of stuff that can happen that can accelerate you as an enterprise if you already have platform engineering in place. But I think it's also then a matter of like, how do you sell this ideas internally as usual right.
To the enterprise. And I think, you know, what I'm seeing, and you know, also just working directly with a lot of enterprise teams is you can go two rats. One is, hey, you wanna do ai?
Great. You first need to do platform engineering. Um, and then, you know, and then you can do AI and that works.
And I think, again, it works, especially if you already had some notion of what platform engineering was and you're already doing it. If you're kind of like you want to go AI native type of type of thing, then I think it's just a matter of like how us like people from the industry repackage the same principles into more AI native language. It, you know, at the end of the day, it doesn't dramatically change the same way that platform engineering also hasn't invented anything specifically new, right?
It's kind of like was, was, was mm-hmm. You know, sitting on, on the shoulders of giants before it. And so here I think it's just a matter of like, it's yet another adoration and it's just really, you just need to adapt your lingo, uh, depending on the context and who you're talking to.
So to me, Luca, the biggest thing is, you know, I've always believed platform engineering serves an internal audience, right? Developers, DevOps ops, and, you know, SREs, I think that the biggest change that we've brought here is your new audience are agents. They're not human.
They're agents, right? And, and as much as we try to give them human characteristics, they're not, they're agents and you don't have to say thank you to them, but you've gotta have guardrails for them, right? And you and you, and, and we have to, it's almost like, I don't know if you've been following the MT book.
Yeah, yeah. You know, the MT book stuff or the open club. So the way they talk to each other when humans aren't around right?
Is almost like a different mm-hmm. Language, a different way of communicating. I think that is true.
And we need to build that into our platforms. And it, and this is hard when you think about it, right? How do you design golden path for agents to interact in a language and manner that's kind of alien to us, right?
That we may not even understand, right? But they do. But we need to design the, the environment they're gonna do that in with guardrails that are not gonna, you know, let us, you know, go off the edge here, go off the cliff.
It's, it's almost like, do we need agents to build, do we need AI and agents to build this next iteration of our platforms that are optimized? 'cause we may have 10 XA hundred x agents for every person in the organization that we're servicing. Yeah.
Yeah, Exactly. Like I, to your point, I don't think you even need to necessarily like, you know, speak their language, right? It's really just about like, what are the, what are the guardrails, what are the golden paths?
Like, I think there's, you know, um, Gregor Hoka has this helpful, um, analogy that I think is becoming increasing more helpful now with, with, you know, in this agentic world, which was this, this idea of the like, you know, kinda like the paved road that we talked about. Um, but really where it's kind of like, hey, you can think of like an initial kind of like, uh, pretty sort of like rusty brownfield enterprise setups at this kind of just like dirt road with, you know, that's like really bumpy with a bunch of like, you know, holes in it and stuff like that. Um, you know, potholes and so on.
Um, and then, you know, basically you go and, and, and really what you do with platform engineering is you put like, asphalt on top and then like all of a sudden you can actually drive your car instead of like, you know, 40 miles an hour. You can, you can, you can drive like a hundred miles an hour, right? And you can have more cars.
And I think like, that's helpful, fun thinking, like, you know, about agents is really just about like taking that road and making it into like an eight lane, like, you know, like highway super highway of like, you know, that's, that's now the type of like volume that needs to run through that thing. Like it's, it's the same thing, right? Uh, conceptually it's the same thing.
You want have the same type of permissions. You want to have the same type of like security and governance built in and enforced by design across the platform and the different workflows and the different teams and the different new types of users. You just have a lot more of them, you know, and, and so, and, and, and so you just need to like, expand that thing.
And, and the asphalt needs to be perfect 'cause they're gonna go way faster than a hundred miles an hour, right? Um, but I think conceptually nothing is different really, which is again, why I go back to the fact that this really can be a golden era opportunity. I think for platform engineers and platform engineering organizations, or generally like IT organizations there are following platform engineering best practices.
Because, um, if you have that, that's, I think that's really the competitive advantage. You know, like, like the, the ai the AI space is moving so fast, like we were saying at the beginning, right? Like it's, it's, it's crazy like week over week, it's hard to keep up.
Um, but we know that enterprises don't move at that speed. And so what can you do as an enterprise? You know, like I think, like I've, I've talked to, I'm talking to like a lot of, uh, enterprise leaders who like, um, are to your point, right?
Like they're freaking out. They're like, okay, you know, I get, I get bombarded, but all this stuff, like, okay, like, you know, developers are doing all these crazy things, agents that now do this stuff. 001% of teams like philanthropic itself, right?
They're dogfooding all the stuff, of course. So they're way ahead of the curve, which is why they can like ship stuff every week, essentially. But, you know, you have to benchmark yourself, I think, as an enterprise to other enterprise around you.
And they're not doing it like they're as stack as you, they're like, as, you know, frozen as you. Um, and I think the, the, the key difference there is like, okay, how do I actually, you know, start executing on a plan that's not just like ai, ai, ai for the sake of ai, but it's actually deconstructing and reverse engineering, okay, what do I need to, to deploy AI at scale? Okay, it's a well designed platform.
Okay, how do I do that? And, and like start making progress that way. Um, you know, as opposed to, okay, like what's the latest, coolest new thing that I can try and play around with?
Because that's just like a, a cool demo, but it's not gonna scale. And, you know, again, in a sense, we've already seen this, right? We've actually already seen this.
Like one of the main anti-patterns and struggles that we've talked about here, uh, of, of platform engineering teams is actually sort of this like, tragedy of the commons of like, you know, you might have a good target reference architecture for your internal developer platform, and you might have like a good roadmap to get there, but then, you know, some of your platform teams and some of your platform engineers might get distracted by the shiny new tech that like, comes around the corner and is like, ah, but I wanna play around with that. It's a lot more interesting. Maybe it's better for my cv, right.
Looks better on my LinkedIn or whatever. And that's, and that's kind of the strategy of the commons, where like, well, from an organizational perspective, it would be better to just follow the roadmap and like, you know, build and just like, you know, leverage this compounding effects, um, but from the selfish, you know, point of view of an individual contributor, you know, they might wanna play with something specific, right? And I think we gotta be really careful, uh, because this dichotomy just went like a hundred x with ai, right?
Because like every week you have a new excuse to like, go and play with the next thing. Yeah. That, and that is, so we're running along on time.
I wanted on something else, but we'll, we're gonna pick this up in our next episode. And that is, I think one of the biggest challenges we're seeing with all this AI is a question of scale, a hundred Percent, right? And security and The scale is just, well, it's the, it that's the challenge in security Yeah.
Is the scale of it, right? The, it's the challenge all around, and the amount of code that's being generated, the amount of apps, the amount of infrastructure, the it scale. Um, but I, I want to end today's note with some platform continu news.
Yes, We, So what's happening? There's A lot happening and there's a lot in the, in the pipeline that's gonna be announced soon. Um, but we are, um, so we have obviously the main event, um, this is end of June, uh, this year, um, last week of June, we're gonna do, uh, you know, the usual full week of platform engineering.
This is the number one celebration I think around the world for platform engineers. We're expecting 50 to 60,000 people to connect virtually. com, um, and you can sign up for all the virtual stuff.
Um, I think what was especially interesting last year from the virtual standpoint was the virtual, uh, workshop program. We had, um, I think 30, 40 virtual workshops, two to three hours long each, uh, and each one of those had around 250 registrations. Um, you know, 50, 60 plus people actually getting hands-on voting, doing stuff.
Um, so I think that's super interesting. Um, and, and again, that's open for everybody. Um, and otherwise we meet in person across two live days.
One in London on the 23rd, um, and one in New York on the 25th of June. Um, and So you're giving yourself time to get in this, So we're not doing the back to back thing this time. We're actually having one thing between, um, which I think is gonna be really helpful also, because actually a lot of our partners, a lot of our sponsors are also doing both.
Um, so my goal is if we can grow Platform Con in 27 to a place where we can actually get a, like, we can actually charter a jet for everybody to fly between one and the next, that would be really cool. Um, but so That's, that would be, that's, That's, that's, um, our main event platform con, and then we're very excited about what's, um, you know, basically going to New Horizons, new Frontiers with PFR Con, um, we're bringing it to, um, new continents. Um, and so stay tuned for that.
Uh, we're, we're hoping to announce, uh, at least two new locations, um, between, you know, this and next week. But certainly by the time we record the next episode, um, I think we can announce them. Um, and, um, and so there's at least two more live days coming, obviously.
Um, I think the community's already familiar with Paris. We did Paris, uh, last year in October. Uh, it's coming back on the 24th of September.
Um, so again, uh, in Q3 at the end of Q3 this year. Um, and so that's, that's already a fixed department. Um, stay tuned for more.
We're very excited. Um, but I think, you know, 26 is the year the Platform Con is going global, so it's, uh, it's exciting. Very cool.
com. Yes. Right.
You can check it all the out there. Luca, congratulations you again on Noah. Uh, I don't know if it's time for a feeding there, but hopefully we'll be back in the next, our next show in two weeks.
We'll continue the conversation. Who knows what'll happen with AI back there. Yeah.
Excited to be talking more. All Righty, absolutely. Luca Gallente.
Thanks, Alan here on the Platform engineering show. It's good to have my partner here back. We'll be back in two weeks with more, but until then, this is Alan Shimmel.
Thanks for watching. Bye-Bye. Control.
This is agent Dev. I'm in position. Copy that.
Dev. Stand by for go Standing by. Hi everybody.
You are joining us for another episode of Agents of Dev. Welcome, glad to have you here. Hey, hello there.
From the great white north of 2026. Storm, The blizzard of 26, or Trevor, I guess, uh, is what we're calling it. Um, yeah, glad to be here actually and be able to be here.
It is, uh, you know, in New England, we know how to do snow, Mitch, but, uh, sometimes we forget. And I think yesterday was one of those days in in which you look out and you think, you know, I, I think that I made a film about this in you where people got snowed in, in New York City and couldn't escape, uh Oh, yeah. Escape from New York.
Oh, no, that's a different one. It was very similar to that with Snow Escape from New York with Snow, A different movie. Yeah.
You, you guys are definitely prepared for some cold weather. The wind is always what gets me swings around the buildings. That was a problem.
Oh, man. Whew. That can be better.
Yeah, we have like 60 mile an hour winds with the snow, and so lots of, you know, swirling and looked pretty, you know, sand dunes in snow factor form factor. But, uh, yeah. Glad, I'm glad that we're, today is sunny and, uh, it's a whole new day.
Well, good. Glad you know, that wind is like a pesky memory leak that you just can't find, you know, and it just drives you crazy. Anyway, uh, so introduce our first segment here, Brad.
Yeah. So, um, this, you know, we, we actually, if you guys recall, uh, those of you who, uh, perhaps have been with us before, uh, and, and thank you, uh, if you do recall, we introduced a new segment called The Call Outs, uh, two words. And, um, what, what that's meant to do, or sorry, one word, uh, to, to call out in text, um, to talk about some of the vendor moves that, uh, we have found interesting, uh, this, uh, last few days.
And as you know, we, we don't publish the day we record. So this, this is live now. Um, what, what I'm gonna talk about for my callout, and that is, uh, do you remember Pure storage, uh, the lovely orange and the Hexagon shape and, uh, they're now called EverPure.
Hmm. Uh, very huge name. I, I remember Informatica changing its logo to the origami bird and everyone flipping out about that, if you recall, um, you know, five or six years ago, this is, I think I missed that one, but okay.
It was, it was a big deal, Mitch. Okay. The, it was a different orange shape, color shade.
So, uh, yeah. Anyway, um, they, they've really changed, um, their branding to reflect what we're seeing in the market right now, which is the, the death of dumb storage, the, the, the demise of storage that, you know, doesn't, um, function as an intelligence layer. Uh, and that is what pure EverPure and its, its colleagues in, in, uh, you know, the storage marketplace.
So Dell, hp, et cetera, are, are all striving for, is to elevate the role of data, um, beyond just sticking it in file blocks and objects, and then managing that with backups and such. It's becoming a very different play for them, and one that brings those vendors into kind of direct competition with, you know, the, what I, what I would call the, you know, traditionalists, uh, the, the cloud first traditionalists of Snowflake, Databricks, and then all the hyperscalers. So interesting times are, are, uh, right with us now.
So you're saying, uh, said another way a data makeover is what we're, we're doing. Like how do we get them, get our data in place and, and better prepared? Well, it's for ai, for, for other things too.
Well, it's, it's really for ai. Okay, Yes. Let's just face facts that, right, right now, you know, every investment is centered around how do I bring AI to data or data to ai, um mm-hmm.
And, uh, what does that mean for traditional data, uh, storage and analytics, uh, practices. So it's, um, you know, top of mind as top as it can get. Great.
Great. Well, my call out is, and, and I also have a report published about this reports titled, uh, IBM versus Anthropic, A Tale of the COBOL Modernization Tape. So the big controversy, right?
When and when, uh, anthropic announced, uh, and then a blog post of, oh yeah, we, we we can solve this, uh, cobal modernization problem. No, no problem cloud's already. My goodness.
So did, did you think about AWS, um, in, in that mix? Because I, I saw that they were trying to do the same thing and, and when I saw those, uh, I thought, why are we going from one legacy language to another? Yeah.
Let's move it to Java and then we'll move it to, you know, uh, you know, what should we put in there? Is it just like stepping stones? Is it just to, to get used to getting more modern?
Why not just jump to rust? Is the question Yeah. Is exactly.
Or, or just kind of don't care. Um, so, so here you, you can tell I've been around for a while and COBOL was actually second language that I learned. I started an Apple base on an Apple two E and a lot from that point forward, there's always been, oh, we should replace this.
This is, we have, we like this database vendor better 'cause we're gonna standardize on it, or we wanna rewrite this in a different language, or we just wanna rewrite it to, you know, kind of bring it up to date. You know, the road is littered with failed modernization projects. Promise, promise you, if you haven't been long around long enough to live through that now, you know, if, if you're starting greenfield and you wanna refactor code, okay, that's a different problem than you've got a whole enterprise, especially in the mainframe world where you're running ATM, you know, how many millions of ATM transactions through, uh, through your code is, you know, they're kind of the iron workhorse.
Uh, most of those applications that are in cobol, yes, some of 'em are, you know, been around and maybe get run once in a while. But, so anyway, and my report is all about sort of wrong question of what tool do we use? The right question is how do you put together the best team, you know, the best boxing coach, the best gym workout coach, the best nutritionist?
How do you get the right things together to, to be successful at this? So when you do the modernization, and by the way, I think AI is actually will be more helpful, if not equal, probably more helpful in the architecture, in the data transformation, in the, um, yeah. Planning and execution of this performance testing.
Hey, you know, you're writing rewriting code doesn't mean you're gonna handle millions of ATM transactions, right? How do you scale and do all those things? I think that's where AI will actually have again and again and again, impacts on how we modernize projects or platforms or applications.
Yeah. And I think, I think what gen AI can also do is help us to prioritize what we modernize, because not every line of cobalt code needs to be rewritten. Oh, I'm, I'm offended that still.
I thought it was all really good, but okay. You know. No, I'm saying some, some cobalt code should never be touched.
Um, that, that it is sacrosanct that, that, uh, we, we shouldn't mess with it for a couple of reasons. One might be that we don't ever use it, which might be a good reason. Mm-hmm.
And just knowing that is an important part of modernization because you know, typically you, you can't r up with AI and say, just make everything Java, let's go. You gotta Know it's not a syntax change. We're not changing, you know?
No man, no. Right. Yeah.
So you gotta know what the code is doing, and understanding code is something that generative AI is pretty good at. Yeah. It's a lot of the institutional knowledge that we lose in people retiring, passing away, et cetera, that wrote programs in the sixties, seventies, eighties, nineties, you know, all through to today.
Um, some of that knowledge is institutional institutionalized and other people know it, or it's in documentation, but a lot of it is just in code and, and in people's heads. Yeah. So, you know, it's, well, do we get rid of this code?
We don't know what it does with the people that wrote it aren't here. We, they, you know, we'll analyze it and try to determine to our best understanding functionally what it does, but why is it here is the harder question. So Yeah.
So snarky comments, yeah, don't count. They don't count. So I ended the piece with, by the way, the, you know, it may not be IBM versus Claude or Anthropic, it might be IBM plus Andro is the best answer.
So keep that in mind. You know, as the markets crash around IBM stock or do whatever crazy things the stupid market does on the tiniest, you just turn away from the markets blog post. It's insane.
And think about The tech That we'll react to. So that's my call out. Um, hey, uh, you wanted to talk about vast, vast forward, so let's dive into that talk.
Talk to me about what's Going on. Yeah. That, that is, has had, have happened, uh, by the time this, all of those, this goes live and, uh, they, they do their, their annual show fast forward, and this one's in Salt Lake City.
And I, I was actually geared up to go, but then we had a snowstorm and tested gravity out and found that gravity always wins and, and, uh, so no travel. Uh, but that story aside, um, you know, vast is an interesting player. Uh, and I'm mentioning them partly because we, we talked about EverPure, um, previously, and, and both vendors, obviously competitors with one another, and one does it from hardware up and another does it from software down, if you'll and, uh, both of them, you know, focusing on how do you get data to meet AI where AI lives and to do so in a performant manner.
And it was interesting to see Vast and, and, you know, its competitors talking about, um, just vectorize everything, just embed everything and we'll do it at scale. This, this was maybe eight, 10 months ago. Okay.
And that has changed, uh, a little bit, partly because the reality of the market is that you should not vectorize everything. It's just, you know, not, not tenable. There, there are use cases where you need to be able to, you know, push down, um, indexing for instance, into the storage tier, to to gain performance when you have a lot of indexing updates that need to happen as.