Techstrong TV – May 16, 2024
Watch our live stream on Monday, Tuesday and Thursday weekly, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey, happy Thursday to you. We've got a terrific Textron gang with a new first time guest, a new gang member here. I don't know if he's wearing his colors or not, but we're gonna be talking about big changes at the helm of AWS.
And I don't mean open source str me, uh, strange cloud bedfellows with Oracle and a, and a mystery person, as well as what? Googling, Googling, what's AI next to Google? All that and more on Textron gag.
Hi everyone. Alan Shimel Textron here, uh, on Textron Gang for you. As I mentioned in the opening, we've got a, a eclectic mix of stories to cover as well as a brand new gang member.
We're gonna go right to, and let me introduce you to Steve Dickens. Steven is one of our compadres from the Futurum group. He has, well, Steven, you could tell them about yourself.
Welcome to Textron Gang, and why don't you introduce yourself. I feel part of the Gang, Allen. Thank you for having me join.
So, uh, as, as you said, Steve Dickens, I lead our hybrid cloud infrastructure and ops practice here at the Futu Group. Been with the business, I think I'm employee number four. Daniel tells me.
So I've been around for a while, worked at a whole bunch of companies prior to that in product management and sales roles. So glad to be part of the gang. Is there, is there sort of a special sort of band Down the needle?
Like, yeah, look, you get colors. Hopefully it doesn't wind you up in trouble or anything. Well, well, you're from New York, but, um, but anyway, yes, you are an an official gang member.
Stephen, welcome and thanks for being here, joining Steven and I today. To my immediate left, Bonnie Schneider, our Echo Insights editor and, uh, sustainable it person extraordinaire. Welcome Bonnie.
Thanks, Alan. Great to be here. Thank you.
And then to my far left from Dub Bronx, which down here in Boca. For now, um, our Chief Content Officer, Mike Vizard. Hey, Mike, how are you?
I'm doing great. Always happy to be here. Great.
Go Rangers. Great. Go Rangers.
What about the Knicks? The Knicks? What?
Last time? All right, they're up three, two, but, okay. Hey, enough New York sports.
Let's go over, we've got some great stories to cover today. Mike, what do we got? All right, well, let's get started with the changes of the leadership at AWS Adam Zelensky.
He says Zel Ky, He is saying that, uh, he needs a break. He's gonna go spend some more time with the family. There's a new fellow at the helm there.
His name is Garmin, I think he used to run, uh, sales and marketing. But Steven, let's jump in here. Um, a lot of times people read into these things and say, you know, is there something more to this announcement?
Or is this just kind of a natural changing of the guard? Well, I mean, I think I spent some time looking into this yesterday. I looked at some of the SEC filings for AWS.
They didn't make a stock award to Za Lipski for this year or for last year. So if you're not making stock awards to CEOs, is that indicative? Don't know.
Am I reading too much there? I think the other piece to this is, whilst Amazon's posting good numbers, 17% in their last quarter for growth for AWS, and that business is now in aut at a hundred billion annually, those numbers weren't as big as Google and Microsoft's growth. So if you are Jassy looking at this going, I need to be posting the same numbers to keep share as Microsoft and, and Google.
Maybe there's is, maybe there's something there as well. So I think, I don't know, Garman, I think from everything I hear, he's, he is, he's gonna be focused on driving growth, obviously comes from a sales and marketing background. So growth and execution on top line is gonna be something he's comfortable with.
It's gonna be interesting to see that play out for sure. I think. Absolutely.
Look, I got a couple of thoughts on this surprise. So first of all, in terms of the stock, look, a CEO has a special comp plan, obviously, but the, the AWS way is that when you come on, you basically get four years worth of stock. And they're not options.
They're flat out just grants of stock that, you know, you vest over the four years. So it's not unusual for an average, you know, for an AWS exec not to get new stock every year. So I don't know how much to read into that, but if, if you believe, if you believe what was in the, uh, Andy's blog post and then Adam's blog post, right?
Adam was there at the beginning of AWS in 2005. He stayed on in, I think through 2011 or something like that, and then went off and, and, you know, wanted to do his own thing. And, and he was CEO at other company and has done, you know, several other ventures.
And when, when Jeff Bezos was stepping down and, and, uh, and the c Andy Jassy was moving up, they put on a search for a new CEO. And rather than hiring someone from within, they reached out to Adam, who was still an insider. And, and the story says is that he was brought in to groom the next level, the next generation of AWS leadership.
And he's been there three, three plus years, whatever. I believe Adam's background is also heading up sales at AWS that when he left, uh, the Garmin is the, is the new CEO Garmin kind of stepped into that role. So he was in what Adam was doing before Adam left AWS years ago.
So it could be a natural progression of, of a leadership change there. Look, it's hard for AWS to grow, you know, it's a lot harder when you do. And as, as Steven said, a hundred billion, I think they did 88 billion last year.
It's hard to, you know, grow at 25%. It's a lot easier to grow 25% when you're only doing 10 billion or 20 billion. And, and so I think that though the war of big numbers sort of catches up to 'em.
But make no mistake, AWS is still the 800 pound gorilla, right? They, they rule the roost. I think Garmin was one of the first employees at eight.
He was also there in 2005. Yes. So he's been around.
So there's a fair amount of continuity there. The one big change immediately was, I guess Adam had been personally running sustainability issues for AWS Yeah. That got transferred immediately to some other, Yeah, the same day they made the announcement, um, later, um, Amazon CEO announced that sustainability will move from something that reports directly to the CEO to community impact and global communications.
So that's a big change because Amazon's been a leader in sustainability and with AWS and their sustainability partners. And that's growing as well because you have climate tech and, and energy efficiency all under that umbrella. So Steven AI is all the range.
And of course, part of the problem with AI is that, well, it kind of consumes a lot of resources and generates a lot of carbon. So is there a, uh, a, a correlation here or is this one of these incidents where it's just kind of a happy accident? Well, I mean, I think if you, so we've got obviously a WSA hundred billion, Amazon's a big business outside of AWS and they've got a huge footprint with warehouses and distribution network.
So I think it's fair that the ESG should have its own sort of tier one position in that leadership team. Yes, it's gonna have an impact act into AWS and you're right, there's gonna be a large focus on kind of the AI sort of wave and how hungry those machines are. But Amazon, at a group level's, thinking about ESG beyond the data center, they're thinking about electric vehicles and their partnership with rivian and they're thinking about smart manuf, smart warehouses and how they do things there and supply chain, it's a bigger beast.
I think you do make a good point around AI being concrete. These GPUs and these GPU farms are gonna put huge, huge constraints on data centers. We're already seeing, you know, I saw something come across my desk the other day.
The data center providers are looking to put in nuclear power plants next to their data centers. We're gonna see some weird and wacky stuff over the next four or five years, you know, around hydro, around putting these data centers in cold parts of the world so that they can pull in natural, sort of local environmental to be able to call these things. Yes, that's gonna be a part of the question.
And obviously if AWS is running a hundred billion dollar cloud business, they're gonna have that problem probably more than anybody else. They're all gonna be in strange places. Do you think Amazon is suffering a little bit of AI envy when they look over at OpenAI and Microsoft and some of these Other No, I, I, you know what?
I think they're making their bets like any smart investor does, and they're not, they're not dumb people there, you know, they have a significant, I dunno if it's a significant, but they have quite a stake in philanthropic. They, they're developing their own internal AI resources on top of that. I, if I'm not mistaken, they are the biggest consumer or buyer of the Nvidia GPUs.
Right. But I think they're also developing their own, uh, AI chips. And, and you know, Steven, to your point about data center builds, yes, I, you know, the knee jerk reaction is build, build, you know, drill, baby drill or whatever you want to call it.
But I think, I don't know if that's smart money. I think that's chasing now money. I fully think that as a result of ESG efforts and these kinds of things, we're gonna come up with a better mousetrap to do AI computing that's not as resource intensive.
And before I would go invest in a 12 year plan, 'cause, you know, how long does it take like a nuclear plan, right? To go get licensing from the federal nerc, FERC folks and, and all of these things. And the time you build it and it gets opened and it's running, it's seven to 10 years minimum.
In seven to 10 years, I think you're gonna have much more efficient chips that'll negate the need for that. So I, I think that is, you know, smart business people weighing short-term, long-term. How much do you want to put into that kind of stuff Or heavens, Well, Alan, you make, you make a great point.
You look at, I mean, AWS has been investing in its own custom silicon with in and Traum we're on, I don't know what generations of those, but they've been at them for a while now. You know, it's not something that they've just announced. They're on multiple generations of that.
So I think they firmly believe that training and inference need a better mousetrap to use your words, and they're already investing in that. So I think, yes, they've got a huge strategic relationship with Nvidia and everybody needs to have one of those. But there's also optionality, you know, so not everything needs a H 100 in order to be, um, sort of in the AI space.
There's a lot, lot of stuff you can do on custom silicon, such as infer and train that you don't need to have an Nvidia GPU to achieve. Right? I think you're right about that in the sense that we are only using the GPU because we need parallel processing for training.
But there's gonna be, I think the software guys are gonna actually have a lot to say about this in the months ahead, where they're gonna say, you know what? There's more efficient ways to do this and, and we'll include a mix of processors. But I would just say, don't forget those developers.
I got more money on the software guys than the hardware guys. Well, Look, all of us are urban age, except you bond, uh, we're, don't Throw me into that then. It's not fully Gray yet.
Yeah, I get you. I get you. But it's not fully gray.
But, but the story of our careers has always been that software has displaced hardware eventually, right? First we do things in silicon and then we learn to do it in, in software, basically. Will AI follow that pattern?
Or is this truly the re you know, 'cause in many ways, look, thanks to Nvidia and ai, hardware is back baby. Yeah, right? It's, it's a subtle mix, right?
Some things we drop into the chip because they're common and it's better to run them there and it's more efficient from a speed perspective. But other times we write better software to make better use of the hardware. And I think to your point, it's more often the case that software carries the day than the hardware guys.
'cause it takes them, I mean, I'm just thinking back in time when the virtual machines came out. I mean, how long was it before Intel got around to optimizing instruction sets for virtual machines? I think I set my watch by the, like seven years.
Well, they, they had a reason not to too. I mean, they didn't, they wanted everyone to just keep screwing servers. But, uh, well, I mean that, we're Gonna talk about Google coming up, but Google announced trillion yesterday, which is the sixth generation of their TPU.
I think you're right on that cycle. It's just where we are in that cycle. I think we're seeing, you know, new hardware companies come to market.
We're seeing new processor types. I'm seeing more innovation in silicon than I've ever seen. No doubt.
So I agree that that cycle is gonna happen. I think it's just where we are in it at the moment. We're probably in the hardware part of that cycle.
It's all about Nvidia. It's all about custom silicon. You know, we're seeing companies like Grok grow massively.
I think I agree with you that the software's gonna come and eat that for lunch, but it's just when, right. I think that's probably maybe a couple of Years new when Steven, we, we'd be rich on some island somewhere, maybe making a deal with Oracle Cloud. So Wait one bet on that.
Go ahead. It's hard. We Steven gonna make a difference before or after 2030?
Well, I mean, I think we're in the phase. I mean, just going back to what I was saying, I think we're in the phase of hardware is where the game is at for ai. It's gonna be the next stage of the cycle is where software's gonna be.
One thing I've learned is you can't look more than five years out in technology. Who the heck, nos. Lucky if can go two, three anyway.
Well, 18 months ago, none of us were talking about chat. GPT. Absolutely.
Or chat GPT-4. Oh that came out and it, and it's, I played with it yesterday in my chat. GPT account, OpenAI account.
And uh, it's pretty cool. Now does Google have four oh MV? We, we'll talk about that.
But first we're gonna take a break. We're gonna be back here. We're gonna talk about some strange cloud or the cloud makes for some strange bedfellows.
Stay tuned. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats and more.
com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more. com.
Home of security bloggers network. All right, and as promised, we're back and we're talking about this, uh, expanding bro between Elon Musk and Larry Ellison, where, um, the folks at, uh, Elon's Company have been using Oracle Cloud. And I can't help but wonder if that's just because they can't really use anybody else's 'cause they're, or with everybody else.
But we'll see how that goes. But, um, it's a huge deal. 10 years billions of dollars involved Alan thoughts.
So let me, yeah, let me, let me just frame the deal. And, and by the way, it's not a signed deal. It, it's more of a rumor at this point.
com. The, the storming goes that Elon Musk's new fledgling AI company, which I guess he thinks will do well if he wins his lawsuit against OpenAI for OpenAI being too commercial. But Elon's not gonna be too commercial.
I'm sure he is doing this for the common man, um, is making a deal with Oracle Cloud to use up to 10 billion with a b dollars worth of Oracle Cloud, GPU resources for Elon's non-commercial ai, uh, business that he's generating. Assuming Elon raises the $6 billion in venture capital and we'll see how much of his old check he writes into it raises $6 billion to get this thing off the ground so it can compete with the likes of OpenAI and Microsoft and Google and, and all of the rest. To me, I look at this and I say, look, this is fomo.
This is pure fomo. You got, you got two players who are not big players in the AI space who wanna be Stephen. And so we're putting them together.
Stephen, go ahead. So, So I'll give the flip side of that. So imagine if you had a platform with 4 million vehicles driving around the world, each of them with a cameras on them being able to take real time data around what's happening on streets, pedestrians, road markings, what's going on in the world.
And you were able to bring that back to a Dojo supercomputer where you've built your own chips. Maybe that'd make you think about Tesla in a slightly different way than being a car manufacturer. I wrote about this in Forbes a few, few, uh, months back.
Think everybody's thinking about Tesla as a car manufacturer. They are a million miles away from being a car manufacturer. We look at Google Maps and how those ugly cars that have to drive round and get pictures of Elon's got a fleet of 4 million plus vehicles driving around every day, capturing all this information.
You deep dive into the Tesla, Ts and Cs and I have all of that data from your cameras is going straight back to, um, build full self-driving capabilities and also a huge corpus of data that you can do things with. So I think about Tesla of AI's gonna be about data sets. Who's got the biggest corpus of data?
You know, Google with YouTube, you've got Microsoft with and, and Google with G Suite. You've got Microsoft with what they've got with Outlook and all those big corpus of data. Who's got the biggest corpus of data of driving around the world with vision?
It's Tesla. So you pull that back and you try and think about compute, computer vision type work, use cases, how people navigate around the world, how people walk, how people cross the road, how cars drive that huge corpus of vision data. Tesla's got a lock on it.
So I don't think it's about fomo. I think they've already got that and they've been doing this Dojo suit computer for years anyway and probably got one of the biggest Nvidia GPU forms today. So this isn't, there's no there behind for a specific use case of Rob Robotaxis and us navigating out in the wild.
Tesla's got the best corpus of data out there. And Larry and Elon, they're bo, they're bros, they're friends. I got the opportunity to ask Larry some questions at a recent Oracle event.
He was effusive about false self-driving guaranteeing that Elon's gonna get it done. Which I, he didn't need to make that comment 'cause we were talking about a database launch, but he unprompted to talk about false self-driving. So it doesn't surprise me that those two were in bed together about a cloud project and just maybe I would frame it a little bit different.
That's a vision I care not to see. I wouldn't, I, so, so, so I would argue differently though, right? Yeah, I've got that in my brain now and I'm gonna live with that with that.
So couldn't I just easily replicate that with a Uber plus Amazon plus a couple of car manufacturers and I'm good to go because I'm gonna get the same data. So I, I think you need Economics. You need economics, Mike.
Not only that, that's why you can't need, yeah, you need, there's the same problem we have with the LLMs. No, they're using data that they didn't have permission to use and, and now in the case of Tesla, uh, Steven says people did sign and they didn't notice. They signed it to Ts and Cs.
That basically allows Tesla to suck all that information back up. Um, and look, I never thought of Tesla is a car company either. I think they're a battery and software company wrapped around a car, right?
I I don't think their cars necessarily are particularly well made or, or great. But their battery technology is top of the line and their software is heads and tails above anything that the big three or worldwide car manufacturer south or it was, I think people are catching up, but I don't know if this is truly about Tesla or if this is about Elon Musk ego that he's not part of OpenAI and he wants an OpenAI competitor. 'cause there's more to OpenAI than Google Street View or Way Pro or all of it.
I mean, I mean there's some weird ownership of OpenAI being a not-for-profit and then it transfer into a profits for-profit business. Elon was an original investor in bootstrapped OpenAI when it was a not-for-profit. So I think there's some weirdness there.
And that's probably Elon, just from an ego point of view and from a personal perspective thinking that's just weird. And that shouldn't be the case. I think you've gotta detach that from what Tesla and his business interests are.
Elon's got enough money to throw lawyers at something that he thinks is weird and shouldn't be the case. I think that's the OpenAI piece. I think his business thoughts are, I got a massive corpus of data.
AI's gonna be vital for full self-driving. It's gonna be vital for what he's doing with SpaceX. So I think you've gotta him as a person and his ego is probably prosecuting the OpenAI law lawsuit just 'cause he thinks it's odd and he thinks he was wronged.
You can judge that as you want. His business side of his brain is probably thinking, I've gotta get an AI platform. You know what Oracle's doing?
They launched 23 AI as an open as a database. I got chance to sort of get, um, pre pre briefed on that. They're doing some great stuff.
I think Oracle, OCI the cloud platform's a great platform for data. So, you know, and he's got a relationship, probably a really close relationship with, um, you know, with Larry that he doesn't have with the, with AWS and he doesn't have that with Microsoft. No, I Mean, so I think you've gotta detach the business from the personal, It's hard to do that with that individual.
But let, let's focus on the Oracle piece of it. Look, Larry's sitting out on Lanai, you know, his island out there In Nashville. Yeah.
Then they just, well, Oracle's moving Nashville. Not Larry, Larry, Larry lives on his island. But, um, and this is a huge deal for Oracle.
Oracle. Look, they do have a great cloud, especially for data, right? You, as you would expect from the database company, um, they are well behind AWS and Google and Azure and they don't wanna be that Larry, you know, Larry playing, if you're not the top three, get out and Larry will keep chipping in there, you know, chipping at that rock till he is in the top three.
And you know, this is a $10 billion deal. That's 10 per, well, it's spread out over 10 years. So it's not all at once, but it's still a sizable deal.
It's a marque name. Um, it's, it's a great thing for Oracle Cloud, right? Because too, for too many people, they think of the big three and they, and they leave Oracle out, right?
And look, the fact that we talk about Oracle and not an IBM cloud is probably music to Larry's ears anyway. But, you know, it, it's a, it's a great deal for Oracle Cloud. Assuming they get these GPUs, I'm not Sure that the data they have is as rich as you might think.
'cause most of it is in a structured format and that's like a sliver of the data you need to train AI models, which is all unstructured. And I don't think Oracle has a lot of unstructured data. I think most of what they got is your classic relational database stuff.
And we've seen databases run away from relational databases for the last five years where everybody's, but They AI's on SQL databases at Oracle. Yes. Oracle has A-A-A-A-A fire in every or Folks be market leader in any of those other categories.
Well, They're looking well, they're moved to Nashville. They focused on health and healthcare care is huge. So they're targeting that with data in ai.
There's a lot, obviously they can get that True. So, you know, can we hook up the healthcare data car Look at Yeah. Tri Think Well you look at, you look at Cerner, number one, number two, you know, against Epic from a healthcare perspective, massive corpus of data for one of the most explosive areas that's gonna happen with ai.
Going back to what you were saying, they've, they've got a, my MySQL play. So as unstructured structured, they made that acquisition that came through. So yes, we've got this traditional view of Oracle that they're the database company.
They are still, but AI's gonna revolutionize healthcare. They just bought the largest, you know, one or two, I don't know the market share, but it's certainly number one or two of, um, electronic patient record systems. And that's a huge corpus of data you put in the vision stuff with Tesla and that relationship.
And I think, Alan, the other thing I would say is they're number three by market share. And number four by market share. OCI If you were to define the market slightly differently and say Enterprise and you took out Office 3, 6 5, and G Suite, are they as far behind?
Probably not. Yeah. So if you talk About Enterprise Cloud Yeah.
Rather than consumer cloud, if you will Mm-Hmm. And sort of end user AppSec, you take out G Suite and Office 3 6 5 and they never report those numbers independently. You take them out of the, the cloud numbers, it's probably a different store.
They, they're still probably fourth place, but they're not as far behind AWS S. But you take out 3, 6, 5 and and G Suite from the other two and it's probably a lot faster. I I, I don't disagree there, I don't disagree there.
But I mean, to give Microsoft and Google their due, they built their cloud offerings around us. But those were always meant to be the engines there that, that, that kind of drove it. Right.
Uh, what's interesting is, you know, look, we talk about data and, and healthcare, right? Estimates are that as, as we move fully to electronic healthcare documents, something like 40 to 60% of all the data stored attached to the internet will be healthcare related. Whether it's MRI films or, or you know, other types of medical, uh, uh, data.
It it, you know, it's like early on in the internet, 40% of every bit running through the, the pipes was poured. Now it'll be healthcare. And that pretty much sums up where we are in, in society.
So, but so, so if I have a heart attack while driving Oracle will dispatch an ambulance. There will likely be Al El let them, uh, they'll dispatch A Tesla ambulance become and pick you up. My doctor Not drive ambulance.
Oh Goodness. Yeah. An automated, a full self-driving Tesla ambulance will come and pick you up.
Good stuff. Good stuff. Alright, let's move on from our friends or of Larry.
We'll continue this saga of Larry and Elon, perhaps at another later date here on Text Drug Gang. But let's now we're gonna take a break and we're gonna come back with the great googly Moogle. Google announces a whole raft, a whole new raft of ai, real make believe.
I will discuss it real watching Textron gang, Welcome back. In our final segment we're talking about, well, what's going on with Google? They had their big Google IO conference this week and they announced all kinds of stuff, none of which is actually here and now there's a prototype of, uh, AI assistant that can talk and hear, help you find your glasses and debug code, they say.
And then there's all kinds of new models coming down the pike that may be available later this year, early next. And there's even new hardware. What's going on with Google from your perspective here?
'cause it seems like a lot of this stuff is either, uh, I'm gonna be a player or, you know, as soon as I get off this couch, I'm gonna kick some butt. So Google announces more AI names and offerings. Wait, let me check my list of how many Google AI offerings and names I've seen in the last year.
I, they all start running in, they, I mean, whoever's making the names, UPS got a great job security over there at Google because I'm, I'm losing track. I can't keep track of all the different things and none of them seem to stick. You know, we talk about Folo.
I I don't think it should be lost on anyone out here that at the, you know, the same week that, uh, OpenAI announced OpenAI four oh as, uh, chat GPT-4 Oh as opposed to chat GT four, which does some of the things that you just, you know, Google, is it Oram or Oro Ra something? Um, GT four, oh, I think No, GPT-4 oh is the OpenAI. But I, but that has, you can speak to it and it talks back to you and all of that as well.
Um, I, I think the thing with Google is I think they're shooting themselves in the foot by just announcing too many things, too many things that aren't even available or real yet because they want to be perceived as keeping up with the, you know, the Joneses, meaning OpenAI, Microsoft. And it looks like this unholy alliance now of OpenAI, Microsoft, and potentially Apple, right? Google.
That's Google's worst nightmare. Mm-Hmm. Um, and, and so they gotta show that they're keeping pace.
So they're, you know, they're announcing this stuff. When is it gonna be real? Will it ever be real?
Will it be any good? Who the heck knows? Steven, what do you think?
So, Uh, maybe take the flip side of that Google io as an event's been scheduled for a while. All those announcements have been worked on for the last six, nine months. And maybe you open it chat.
I stole their thunder. I mean, that, that's possible too. So Chat gt comes along.
It wasn't by accident that they'd decided to announce it a couple of days before Google io. Google io has been. So it's, I don't see this as Google reacting to chat.
GPTI see it as chat GPT trying to get ahead of Google. So all of these guys are trying to one up each other. AWS wanted to brief me the Thursday before I went to out to Google Cloud next.
Why did they want to brief me the Thursday before I flew out on the Monday to Google? 'cause they wanted to have AWS's stuff fresh in my mind before I went out to Google. So they're all trying to one up themselves and, uh, one up each other and get their stuff out early.
The Google io sort of train would've been well established. They would've been planning that for six months. I was surprised by how much came out considering Google Cloud next was, what was that a month ago?
Mm-Hmm. You know, the TPU Yeah. Trillium stuff.
I mean, TPUV six is now gonna be called Trillium. I love, I mean, as you say, the person naming this stuff has got a great job right now. What was wrong with TPU?
But, so I've gotta relearn some new words. Trillium, um, I don't think, I don't think I'd read into this that it's Google reacting to chat. GPTI think it's probably chat GPT reacting to Google.
Because Google, I was a, a staple in the car in the Canada and that's been locked in. So maybe I'd see that a little differently. But the difference is chat GPT-4 oh is actually available right now.
You could go on and use it today. Yeah. Yeah.
I've been playing with it. Yeah. It does a bad job of describing Daniel Newman wearing a j an arsenal jersey, by the way.
But I tried that one. I saw that it gave him a, it gave him a full head of hair. Yeah.
Which is obviously wrong. But I mean, I think we're on the, the, the innovation cycle is so fast right now. Everything is kind of a three month turn.
I think Google giving a state probably what is more a statement of direction than a product launch, you know, where these things are gonna come. Uh, I dunno, I don't see that as a bad thing. It's, it's gonna be tough.
How Do you think this is gonna play out? 'cause what Google's really saying is that there's gonna be kinda one master AI assistant that we speak to that will find your glasses and debug your software versus, you know, we've had this conversation on a couple of shows now where everybody's saying, you know, well here's my, here's my copilot. So do I need all these other random copilots?
Or will there be, you know, one or two that are gonna do everything? That's interesting. I don't know, Bonnie.
Well, you look, Go ahead Steven. AWS has got Q as its assistant. Uh, Microsoft's got copilot.
Google's what got what it announced yesterday. Gemini. Gemini.
Gemini. Yeah. Yeah.
And Trillium that you, you mentioned Steven, I Think Google's put an official name on it, the LLM. But they're just showing a prototype. Oh, something thing that they have a project called, it's called Astro or something like that.
That's True Astro. Yeah. And it's, it's, it is, it's interesting watching both announcements because it gets you so excited and then you keep reading and it says, oh, it's actually not available for the next few months.
Um, for some of them. But one of the things I just wanted to mention about Trillium, uh, in their announcements that Google is making and and across some of the other ones is that energy efficiency w was, it mentioned in many of these new announcements that Trium, for example, 67% more energy efficient and other Google AI models are boasting that they're able to be more energy efficient by only using part of the model at one time. They're, they're, they're able to kind of designate areas of resources.
I mean that's, I I don't know that's what they're saying. But That's, but that's the, but that's good. I, I think that's evolution, right?
You, you learn to, uh, build those efficiencies in shut down what you're not using. Right. More efficient.
I think that's the, that's the way of things, if you will. And, and, and it's a good thing. But Mike, to your point, look, the Microsoft copilot was primarily, you know, first sort in GitHub.
Uh, we are gonna see it in those Office 365 or whatever they call 365. Now, um, interestingly, I downloaded Copilot for my iPad. Pretty cool.
I don't know if any of you have played with it. It, it works really nice. It's, it's a good AI thing.
But I, I think what your point is, are we going to have an Uber, no pun intended to the car taxi business, but we gonna have an Uber AI who kinda wipes our nose for us and cooks dinner and does everything else. It's Mama Mm-Hmm. You know, or are we just gonna have a series of very specialized ais that reform very specialized tasks for us?
And we probably all of the above, I think we're gonna have an AI throw down. We're gonna have, the bots are gonna like battle it out. And didn't they Make a movie like that?
Like the guy was, uh, who was it? Uh, Hugh Jackman was the manager of the, of the bot that, the fighting bot that was kind of, yeah. Beat up and stuff.
It, that was a good movie. I think it's gonna be which ecosystem you're gonna be in. You know, Apple's gonna have its AI meta has already started rolling out AI across all of its platforms now.
We've seen that Google's got its ecosystem with YouTube, with G Suite, with, you know, with what they do on the phones with Android, there's gonna be a number, depending on which ecosystem you spend the most time in, you're gonna probably gravitate to that. So if you are an Apple fanboy, you are gonna be in that ecosystem. If you are an Android person, you're gonna be in that ecosystem.
If you live your life in Microsoft teams and Microsoft applications at work, you're gonna use that depending on what, and you're probably gonna have two or three of those. You know, maybe your work persona is working with Microsoft and your personal personas working with Apple, you know, or you're in the Android Google ecosystem, depending on kind of where your work place is, whether you are a G Suite or a Microsoft person. You know, I think there's probably gonna be three or four of these big platforms.
I don't see 20 of those big platforms. 'cause it's a network effect. Yeah.
I think Amazon will be in there too. Don't count those guys out. I think, Yeah.
I mean, what they're doing with Q is fascinating right now. They're, well, I, I'm not even talking AWS I'm talking like Alexa Yeah. And all of that.
Because really, let, let's be clear, your general AI kind of thing you're talking about is what we wanted Siri and Alexa and Google Home and all these things to be, we even wanted Clippy to be that back in the day. Right. Going back.
But, um, and I think they are, they're gonna be much better than what we have. Steven, do you think that we will get the interoperability issues right, because today it's kind of a pain in the butt. My house, they, all the women are on Apple.
All the guys are on Google, uh, and nothing Is it really, really far in your house? Yeah. And, and nothing is interoperable.
So, you know, everything's kind of a pain in the ass to like connect to somebody on video through Apple. Google. Don't know it.
It's in your house. Yeah. So Steven, is it like that in your house?
I can't imagine a scenario where I'd be the green bubble person in a blue bubble world in my House. Oh, that's, oh, I know that something's wrong over there. All all are the king of your castle all here.
All all, all the boys are on Android. Man. You swear by it.
Well, there's only one Boy in my house. And that's Right. And you've gotta go.
If I had A green bubble, forbid you don't to get my feedback down, but, um, we gotta go like, download something like WhatsApp that we can all actually use that, you know, well, well, I Think Mike, that's the point for me. That's the point for me. There's gonna be this bigger ecosystem.
There's gonna be an Apple ecosystem. There's gonna be a Google ecosystem, there's gonna be an Amazon ecosystem, but there's still opportunities for people like WhatsApp to be able to be that connecting layer between those two ecosystems. So there's, whilst I see three or four big players emerging, and this is where the startup ecosystem plays a role.
There's gonna be these firms that pop up that go, you, we need a messaging layer. We need a communications layer. We need a social media layer.
We need a a something layer to, whether it's a home layer or a, you know, there's gonna be like Nest was back in the day. There's gonna be these firms that kind of come together that bring the connection points across these big ecosystems. Uh, absolutely.
I'll give you an example. Slack. They got Salesforce behind them, right?
Broadens ubiquitously on everything. Mm-Hmm. Maybe we'll see that.
Anyway, we're, we're outta time for this gang, uh, episode. We will be back not tomorrow, Friday because we don't do it. As matter of fact.
Well, soon we may be doing Friday shows, but not tomorrow. We'll be back Monday with a, a fresh text Drunk gang, as well as more content. But that's not all for Text Drunk TV today, immediately following this, we have our full text Drunk tv, uh, schedule on you.
If you're on Tech Drunk tv, you'll see the playlist there. Or if you're on any of the tech drunk sites, your playlist is there. You can click to it right now.
You don't have to listen to me Say Goodbye. Um, or you can go to Tech Drunk TV and watch any of our shows and interviews and content on demand on our YouTube channel or however you like Ensuing Text Strong. Um, until then though, Steven, what a smashing debut for a new gang member.
I feel like I need a bandana and I wanna be on The show. Something we gotta get you. I feel like you made your bones.
I need a tech strong T-shirt. That's what I need. If you come on down, I promise you we're not waiting for you.
Uh, thank you. We hope to see you on a actually, you and, and some other, uh, analysts will be with us on Monday show, I believe. Yep.
So looking forward to that. We're gonna do sort of a Laverne and Shirley meet, mark and Mindy, if that doesn't make me too old, a mashup. A mashup as Mike tells me they're called.
Uh, but thank you Bonnie. Thank you as always for being on. Okay, Mike Vizard, welcome and thank you.
Um, and most of all, those of you out there, thank you for watching and hanging out with us today. Stay tuned for the rest of our Tech Trunk TV programming. Until then, I'm Alan Shimel.
We're out. Cloud native now is the Web's leading resource for the growing cloud native ecosystem. com is your destination for news, thought leadership, features and webinars on cloud native architecture, Kubernetes serverless, cloud native application development, microservices, service mesh, cloud native security, and more.
Stay on the cutting edge of modern application development at Cloud Native. Now, This is Textron tv. Hey, everyone, we're back here.
Live in Paris. Day three coverage, I feel like day three DevOps, day two, DevOps. No, but it's day three of CubeCon.
We're in Paris. We're coming to you live on Techstrong TV and all the whole Techstrong network. Let me introduce you to our next guest.
This is a real life DevOps analyst right here. Paul Nati. Paul is with the Futurum Group.
If you were tuning in yesterday, we, we had another Futurum analyst on. We're happy to have Paul on though, because he's their DevOps guy. Well, Paul, I hope I didn't steal your whole story.
No, Not at all. Alan, Please welcome, welcome to Techstrong. Thank you, Alan.
Thank you. It's great to be here. It's great to be here.
You know, I really, I really love the warm intro you just did, uh, love DevOps. It's really my passion. It's where I live.
Uh, app, app dev, app modernization. It's kind of like that space that I'm in. So you're fairly new to rum, but you're not new to DevOps as you mentioned.
Let's hear a little bit of the pulse story. Sure, sure. Yeah, no, thanks for that.
So, uh, definitely a little bit new to futurum. Um, I, I built a practice, uh, an analyst practice about four years ago. I, so in, in the app dev space, app modernization, app development, uh, growth in that space focused on the CI/CD pipeline, uh, really about cloud native, past, present, and future states.
Uh, prior to being an analyst, I was in the vendor world for about 25 years. Both large and small companies took four companies to events. You know, so and so really, uh, understand that kind of startup mentality, but also the, uh, the big company politics as well.
Yep. What kind of, it's very hard to do something for a job if you're not passionate about it. Right?
Where's your passion in DevOps? Oh, wow. You know, so I have a passion.
I mean, I wrote a book on, on rapid application development, so, you know, for dummy's book. So, I mean, I really, really, that's my passion is like, I really love it. So when I look at DevOps, I look at the day zero day one, day two, right?
The build, release and operation side of it. I look at like what it means to take pro, to build those applications, get 'em out the door, what does it mean from a perspective of today's technology versus what, what's happening in current stance, but also what's happening in the future, right? I'm looking at, you know, uh, monolithic applications moving to microservices and containerization, but I'm also looking at like serverless and wasm and web assembly and what that, where that's going.
So it's really kind of an evolving state, really exciting time. It, it has been, well, you know, so March, uh, 14th, yeah. com, publish publishing DevOps.
Very congratulations. Thank you. So we've been, you know, in this DevOps space a while.
And, you know, I've certainly seen changes e evolution over the 10 years. Uh, but you know what I just realized before we get into that, there are people out here who maybe aren't familiar with Futura. Oh, okay.
So, as I mentioned, you're, you're, you're the DevOps guy there, right? I am. But There's more to Futur than DevOps.
If you would, I, I don't want to dis take us off track, but take a minute. Explain to our audience how is Futurum organized? Absolutely.
So Futurum has a broad set of offerings that, um, allow, uh, organizations to really help their, uh, go-to market strategies, understand how they're going to, uh, broadcast who they, uh, who that company is, what their message is, where they're trying to get out to the market. So, uh, whether it's, uh, video assets or written assets or content anywhere from top of funnel, mid funnel to conversion assets, haven't really helping that go to market and drive through. So, but first and foremost, I look at it in the context of being a primary research firm.
Uh, that's what I focus on is a research element. Mm-Hmm. But there's a media element as well, and there's, and there's, uh, intelligence portal.
And, but with the practices, there's 14 practices throughout, uh, future arm, the future arm group, everything from cybersecurity to infrastructure to storage, to networking to all the, all the things you can imagine. Sure. And of course, application development, that's where I, that's where I fit in.
Absolutely. And I, and that's, uh, that's where I, I focus in on. Excellent.
Alright. We got that out of the way. Well, Daniel, you're welcome.
Um, but let's now focus back in on DevOps. 'cause both of our passions lie there. Absolutely.
As I said, 10 years on, I've seen a lot of water under this DevOps bridge. Right. I mentioned to you off camera, we're doing this whole report on what we call DevOps next.
Where, where do you see us on this journey, on this DevOps journey, you know, as an industry, as an ecosystem, as a community. Yeah, absolutely. So, I mean, I'm looking forward to your, to your DevOps next report.
I, I, that also aligns nicely to this observability report I'm putting out as well. So I'm looking forward to collaborating you with you on that. But let's talk about the evolution, right?
Um, you know, it really is still immaturity, right? I mean, there's, uh, there's, there's organizations that are out there that have it in lines of business. Then there's organizations that have it, DevOps in lines of business organizations that have it, DevOps, SREs and lines of business, and then platform engineering.
Of course, that comes into the play as well, right? Right. So when you look at this kind of evolution, it really depends on where the organization is in a maturity cycle.
Yeah. Um, I was talking about here we are live on the show of, of Kku Con. I would, I'll give you a nice shiny quarter.
If you find me somebody that identifies as a, a server or a storage admin, they're not, right. They're, who are they? They're platform engineer, form engineers.
Right. So, and this is, I'm glad you brought this up. 'cause here's my take on platform engineering.
You know, to quote Shakespeare Rose by any other name would not, would still smell is sweet. We've been doing things that are platform engineering, we just didn't call it that. Right.
But the, the kinds of things that platform engineers do are, are the kinds of things that have needed to get done. Sure. I think more than anything, platform engineering as a term has arisen because I was never a fan of the term DevOps engineer.
Right. I I think DevOps is more about multifunction teams. Yeah.
But saying someone's a DevOps engineer, I understood why a lot of engineers, a lot of people who are today calling themselves platform engineers said, no, I, what, what the, what the heck's a DevOps engineer. Right? Right, right.
I I do CI/CD, I do ops, or I do, you know, so I, I get that, but I also think there's a continuum that's even bigger than the ones you spoke about. I think it starts way here to the left with Agile. Yeah.
Right. Agile is 25 years old. Absolutely.
It's pretty well defined where Agile leaves off. So the DevOps picks up and, and when I say DevOps, I mean many flavors including SRE, including platform engineering, including that whole software, uh, uh, s software supply chain and, and SDLC. But then it goes further right?
To ITSF to service management. That's right. This is the world we live in, in the software factory.
Yeah. Right. And, and I think the sooner we realize that, like how you said, how organizations are kind of defining themselves, I think those are artificial silos.
Well, I mean, that eventually gotta come together a bit. Yeah. Alan, I mean, I think it comes down to what are the business KPIs?
What are businesses trying to release? Yeah. So when I look at my recent research and I see of a, of a, just a sub 400 respondent survey, I found that 24% of those organizations that survey that responded to my survey wanna release code on an hourly basis.
But yet only 8% are able to do so. But the 8% that are able to do so touched on what you're talking about. They, they, their commonalities between it was agile software development, they could use DevOps practices.
They use infrastructure as code, and they, and basically they kind of, they push it out that way. Now, the reason why that's important to note is because when you look at the release cycles and you look at pushing code out the door DevOps KPIs or get the code out the door, push it out, right? Yeah.
But they'll also need to worry about things like quality. Quality, right. And when, when QA is going, Hey, I got a problem that's, uh, you know, DevOps, like I need to push it out the door.
Right? Well, what I found in my trending survey is from 2022, I found that only 29% of organizations are doing, doing continuous testing, really only 20 in the CI/CD pipeline. Right.
But in 2023, it jumped up to 66%. That, That's more what I see. Okay.
Right. And, and, and the reason behind that in my mind while I was kind of talking through this, was these organizations were using their, their end user clients as the test bit as The beta Yeah. The beta testers.
Right. Right. And their justification was, well, we use software agile methodologies, we're pushing code on our Scrum use every two weeks.
Right. Not a good model. Right?
No. 'cause you lose the, you stick Well, you're making your customers Guinea pigs. Exactly.
And not a, not a good place to be. Right. So let me, I, I'll interject one thing 'cause we are here at CubeCon.
Yeah. I think one of the reasons for that jump though too, Paul, is the whole GI ops Argo, which is a huge CNCF project here Argo, that allows us to do our CI/CD within a cloud native stack within a cloud native system. And there's a place for testing in there Yeah.
To the left of deployment, right? Yeah. Yeah.
And, and then I I, so one of the things we do at Techstrong right? Is we have this video series called DevOps Unbound sponsored by tricentis. And you know, they're, they're kind of the leaders in continuous testing.
That's their tagline. Um, they've really made so much progress because of this cloud native stack cloud as cloud native has become more dominant, continuous testing is part of your release cycle Yeah. Has become easier, more organic.
And, and I think that's a a, a reason you see that jump too. Yeah, I agree. I mean, I think part of the, uh, continuous testing con, uh, continuum there Yeah.
Um, fits into the, uh, the, the, the adoption of using open source as well. Right. So if you start using open source, we find that in our research that, uh, 87% of organizations who responded, they want to work with vendors that sponsor open source projects.
Yes. But they also don't want to go at IT alone. So they want those vendors to provide enterprise level support.
So, but when I bring up open source and in relation to testing, the reason why these vendors wanna, or I'm sorry, these organizations wanna work with the vendors that it sponsor these projects, is because open source hardens the code. It, it, people can bang on it, make sure it works, and then it comes out the door and says, okay, now it's proven. It works, it's tested in, it works in the ecosystem.
And plus you have community support. So if something goes wrong, you can lift it from there. Well that, you know, that's one of the reasons why this place is so damn crowded and they do so well.
Right. It's this foundational open source model where that rising tide lifts all the boats. Absolutely.
And then vendors get to kind of riff off of that. Right. But, you know, you bring it up.
But now we're, we're, we're starting to see a little bit of a backlash around open source vendors and changing licensing and saying, wait a second, we gotta, supporting this open source project or training for it is not enough for our business model. I can't make a business where converting 4% of my users is my success formula. Right.
Right. I gotta do more, I gotta figure out how to wr out more revenue from that model. Yeah.
And I think we're just entering that kind of phase here. It's gonna have repercussions. Oh, for sure.
Right. Yeah. And, and the way I would see it is, uh, you know, there are many vendors that's that use op, like work with open source models, right.
If you don't have strategic differentiation, and this is something that I work with a lot of my clients with Mm-Hmm. Is like, what are your three to five strategic differentiation points? If you don't have those points and truly understand why those points are differentiators, then it's going to be very difficult to cut through the noise.
There's a lot of noise. Well, no. Take observability, which is what you're working on now.
Right? Right. Look, at the end of the day, how many of 'em are just OpenTelemetry and Prometheus?
Maybe a little Grafana, right. Under the covers. Right.
So where's the table stakes? Right. If, if, if you Have, that's the table stakes, right?
If you've gotta do something more than that, you want my money. That's right. If you have 5, 6, 7 companies doing the same thing using OpenTelemetry, where do the three to five things that make it work?
That, and I think, I think, look, there are gonna be companies that struggle with that, and quite frankly, may not be around. Well, I mean, look, look what's happening in the industry, right? You have the Cisco Splunk acquisition.
Yeah. Right? You have, uh, the merging of, of different companies that are going under pe, you know, and really getting investment from those.
And they're consolidating. They're coming Together. You're gonna see a lot of this.
You're gonna want to see a lot of it. And because of that differentiation. So I would strongly recommend vendors that are looking at these using open source to put their products forward, but validate their differentiation against market data.
That market data is really gonna provide that solid point to say, this is why it matters. And find that little, little spot that makes it work. Yep.
I, and, and by the way, this is not just a problem for the smaller guys. No. I think even some of the companies you mentioned need to figure out what their sauce is, what's their special sauce here?
The, those three to five points? It'll be interesting. I, I think we're, we're, we're certainly in for consolidation.
I think observability in particular Yeah. Is gonna change drastically Consolidation and rapid expansion of the ecosystem. Absolutely.
You know, we we're probably talking, I don't know, I don't know how I forgot. I didn't time it, but we haven't even mentioned AI yet. We gotta talk about it.
Well, we have to talk about ai. I mean, if we didn't, we'd miss it. Yeah.
So, ai, DevOp AI and DevOps, what do you see there? Oh, well, you know, AI and DevOps, I, you know, I just, I did a study around AI impacts to the developers, right? And we, and, and what we find is 18% of, of organizations that using AI in their production code, but 27% of organizations are in consideration that they're thinking about it.
They're trying to understand what's going on with it. So why is that? Well, there's a little bit of uncertainty.
I mean, we saw with, with a recent airline that they put out some stuff that didn't actually help them, right? Because they said they try to blame it on the ai, but it's like, it's their business, right? So if you, but the common use cases, like for DevOps and developers, I mean, you know, rapid code creation, uh, you know, documentation, uh, customer satisfaction, knowledge base, all is the real, like those are the real use cases.
But what I'm finding in our research, excuse me, what I'm finding in our research is, uh, it varies based on geographic locations. The, the adoption is really Yeah. Very much so.
Uh, there's some, some, uh, or, uh, some parts of the world that are much more, uh, uh, willing to adopt faster than other parts. So for example, we're in, which we're in AMEA right now. We're in Paris right now.
Uh, far much more conservative in AMEA than it is in say, apac. What about North America? North America's kinda more in the middle.
Really? Yeah. Somewhere in the middle.
Yeah. I Guess what research, guess what you think about it? That's kind of, I could see the reasoning behind it.
Yeah. We could share those data points. But, but the thing is, is, uh, when you look at it, it really does come down to look at what organizations are doing.
I mentioned earlier about releasing code on an hourly basis, right? Right. Applications are being developed very, very rapidly.
Now, if you're not using some type of AI to take actionable insights and do some automation, you're competitively going to be behind you. There's, there's not a firm and organization out there that can put enough people resources behind creation of applications moving forward. It has to be generated with autonomous ways of doing it.
Because if it's not, um, you're just gonna be falling behind. And then if you're, if, if, again, if you're not using that, uh, uh, um, automation to do it, the impacts of security, the impacts of, of, of bug is the impacts of anything will fall off. And you'll, and your product will be impacted by that.
Look, to me, it's a speed of business issue. Absolutely. If you're not automating you, you, you're, you're, you're in that right lane, and you're gonna have people blowing their horn at you all day, right?
Yeah. Correct. That, that's the bottom line.
Um, you know, sitting here listening to you talk about hourly, you know, that's the goal. Hourly. So you're talking to someone that, in my last venture backed company that I co-founded, you know, we were really proud of ourselves when we went from twice a year to quarterly.
I know. Yeah. We thought, my God, how am I gonna finish all the testing Right.
In a quarter, right? Right. Now we talk about hourly.
Well, waterfall versus agile, right? Well, we were, we were, it wasn't that long ago. We were, we thought we were doing agile.
Right? Maybe what we were really doing was fast waterfall, Fast waterfall. But, um, that being said, that's the world we live in today.
And that's why when we talk about things like automation, and we talk about things like ai, you're not going to hit those KPIs without those. Not at all technologies. Not at all.
It's just not At all. And it's just gonna accelerate. I don't get how big a team you have.
That's right. Because at some level, the more, the more people you add, the more time it's gonna take for people to do, you know, to coordinate. Right.
Um, good stuff, Paul. Where can people get access to some of your reports and stuff? Oh, I appreciate that.
com is where my, my pages, my, my information is, uh, most of my research, uh, from the briefs and such are, they're ungated. So you can go there right now and pull it right off the site. Um, I do have some contact information there.
If you wanna reach out to me directly and talk to me, That would be great. Yeah. Hey, man, thank you for coming on.
Thank You. It's been great. Futurum group.
I don't wanna mess up your last name. Paul Nadi. You get it.
Got it. Paul Nati here on Textron tv. We're coming back to you live from Paris in just another minute.
Stay tuned as we wrap up day three. This Is Textron tv. Hey, everyone.
We're back here live. It's, uh, what is it, about three o'clock? Well, no, it's only one 30 here in, uh, San Francisco at RSA conference.
We're on Tuesday. Seems to, there must be, you could tell when there's a lot of sessions going on, because things quiet down here. Otherwise it's a little bustling.
Um, we're live on Broadcast Alley, which is a Moscone West. I'm joined by my friend David DeSanto. David, if you don't know, is the Chief Product officer at GitLab.
com and we started doing the DevSecOps event, people would say, what's a company like GitLab doing at a security show? Right. Or a cyber show, as they say now.
And I don't think people say that anymore. They don't, not about GitLab, certainly, and not about DevOps in general. Yeah, Right.
Have a really nice booth over in the expo hall too. I I've seen that with a lot of advertisements and everything. And that started, I guess about three years ago.
I think it was Ashley. Yeah. Kramer got on Tech Drug TV with us and said, GitLab is a DevSecOps company, not a DevOps company anymore.
Yeah. A DevSecOps. Yeah.
And that was sort of like the Microsoft trustworthy computing moment. Mm-Hmm. For GitLab.
Yeah. Our, our first conversation was actually at RSA four years ago. That's when you and I first, Right.
Your first question to me was like, why are you here? Yep. Absolutely.
Yeah. Who am I? What have I done?
But now we don't ask that anymore. We know why you're here. Yeah.
GitLab is a DevSecOps company. Dick GitLab, you know, when we look at the entire CI/CD process, the entire software development, life cycle software, supply chain, security and everything else, excuse me. GitLab plays a vital role in that.
So I'm not going to obviously beat that dead horse. We understand it. But you guys have some new stuff going on here.
You made some announcements. You mentioned you're exhibiting here. Is this the first time you're exhibiting?
It's not the first time. I think what, what's happened for GitLab is we've gone from being just that, as you said, DevOps platform. If people think of SCM and CI and over the last several years, and Ashley did a really great job helping rebrand GitLab as a company.
Um, now there's this expectation that GitLab is actually a security company that does dev like DevOps, right. DevOp so and so, yeah. For some of the things we've been talking about.
I think the biggest thing is we just acquired another security company. Uh, What, what do tell Yeah, yeah. So their name is Ox.
I, they're an Israeli based company. Ox Ox, I-O-X-E-Y-E, Uh, ox. I, yeah, I know them.
I've interviewed them several times. Yeah. So they're big, uh, Clement of fame was really two things.
Reachability of vulnerabilities. Yep. And their ability to do what they call code to cloud.
Mm-Hmm. Uh, scanning. And so that acquisition closed last month.
Fine. I, I did, I missed that one. Yeah.
And someone hasn't been calling me over there. Alright, well, we'll, we'll take it up with, uh, my handler when we're done. Yeah, Absolutely.
Dave, you had a word for me there. So, ox I Ox I, yeah, so There no idea. There was two guys, basically the two co-founders.
Why there two co-founders There? There's two Co-founders and there was a team, I think about 16 mm-Hmm. Well, I never got to interview them.
Okay, well we should make you, we should have to talk to them. Absolutely. Uh, both Ron and Dean are fantastic.
Yeah. Security practitioners. But, uh, yeah, so they were a partner initially and we were seeing the value of what we could do together.
And so, uh, GitLab acquired ox I and the team is very excited to be here. They just did what they call a fast boot. They had the GitLab secure and governed team, so that Okay.
Do security scanning and compliance, then GitLab, uh, and the team together in Europe. And they planned out how they're gonna do the integration and so forth. So the first main thing is we're looking at accelerating our SA map, which includes the reachability.
So for those who are unfamiliar, that allows you to validate that the vulnerability is actually exploitable and whether or not it's a false positive. And with that, they're able to automatically detect that and mark them as such and excellent. That's the first part.
The next part's the cloud or code to cloud where they are scanning at runtime that code moving into production. And that's something that GitLab has not traditionally focused on, but we're excited to see where that can go. Well, so here's my crazy thing.
Yeah. I think there are two things missing in our SDLC, you know, lifecycle sort of security thing. One thing I'd like to see, David, is a, uh, I'm gonna call it a, uh, a repo firewall.
Okay. That you cannot download anything from a repo, a repo, an artifact, a component or anything unless it goes through this firewall. And that firewall's gonna check to make sure it's the latest version.
It's no, no, no vulnerabilities. Maybe you run something in a sandbox or whatever. So, 'cause I think just doing that, filtering that stuff out at the source.
Yeah. And I don't know why repos don't do this, but, Well, I got good news for you. You took my idea.
That's not good news. My children need, you know, a living here. But what do You think?
Uh, well, I, what I would say, Al, is I, I need to be able to feed my dogs. Okay. Okay.
We have kids. I, I have an eight month old puppy. I was actually gonna ask you about it.
We talked about it last Time. We'll spoke up. I show you pictures when we're done.
Awesome. Yeah. Yeah.
So, uh, Caleb does have a dependency proxy built into it. Okay. So you can only pull down packages that are authorized.
Really. Yeah. And then where our incubation teams are working on a dependency firewall, which would complement that, That's exactly what I think the world needs.
I mean, I, for instance, we were doing a story the other day, even like docker hub images, they again, right, yeah. With malware And NM usually something, right? Yep.
So I think that's something that's desperately needed. And then the second piece of that is sort of what you're talking about the cloud, right? Yeah.
Adapt, add that upload point, right? That's your other choke point. It is.
And by the way, I, what it does is it compliments some other features we recently released. So, uh, GitLab's always been run as part of the CI pipeline. Mm-Hmm.
So the security scans run at build time. Well, we want to extend beyond that. And now you get real time scanning of your dependency registry and your container registry.
And so Post deployment, Uh, Or at deployment, Well, they're sitting in the registry and if we, uh, publish our, we update our vulnerability database a couple times a week, if we update the database and there's now a new vulnerability that you're vulnerable to, it'll alert you that it's in the registry and that it's in production. And so, GitLab, when I first spoke to you, uh, it would be almost four, a little over four years ago. Four years ago.
I just remember it was right before the pandemic. Right. And we had talked about can you get outta San Francisco?
'cause they were about to dock the cruise ship. It Was 2020. Yeah.
Right. Uh, we were talking about with, uh, SaaS secret detection and das. And we've now expanded that to include container scanning, infrastructure code scanning.
I love it. Fuzz testing API security. Well, the fuzz testing, I think I remember.
Yeah. But you know what you're talking about with registry. Mm-Hmm.
So it's not truly registry scanning, it's registry checking. You know, we were talking with Mitch Ashley, our CTO off camera. So Mitchell and I were at a company that we both helped co-found called Still Secure.
And that was, uh, early two thousands Mm-Hmm. And we kind of pioneered Mac that were access control. Yeah.
And that's exactly, people used to ask, what's the difference between NAC and vulnerability scanning? And that was exactly the difference. I'm not just scanning your infrastructure for vulnerabilities.
I'm actually in our generic product, we would go into the registry Mm-Hmm. Now endpoints and or servers. Yeah.
We'd go into that registry and look at what the registry said you had Mm-Hmm. And if it wasn't on that, call it a gold image or Whatever. Yeah.
Golden image. We would, you know, using 8 0 2 1 x, we prevent you from getting on the network, take you off the network, put you in quarantine, remediation or what have you. It sounds a lot like that.
Yeah. What, how I look at it as is that, you know, software's become even more complex. Yeah.
There was a great paper is probably about five, six years old now, but it was an analysis of the last 20 years of security vulnerabilities. And it talked about how enterprise applications were growing at like 10 x code base. Mm-Hmm.
Vulnerabilities were growing at like a half a percent per year in size. And the risk of what that is. And when you think about someone like GitLab, who's trusted by more than 50% of the Fortune 100 to secure their software, you're in the situation where that could be a lot of microservices, a lot of applications.
We have customers who talk about having tens of thousands of applications. And so the best way to help you secure that is to give you the visibility into what's in your registry, what's running in production. Absolutely.
Yeah. Absolutely. Um, this available now.
Yeah. So the real-time scanning is available now, if you are using GitLab Ultimate, you can go in and enable it. The ox I integration will happen over the next nine months.
The team is focusing first on integrating their SAS scanner in first, replacing our existing, and then we will then start on the reachability and longer term the, the code to cloud. But I love it. It, I'll tell you there, there's always excitement when, when we do an acquisition both internally and the company who's joining GitLab.
There's just a lot of excitement about what this could actually mean for DevSecOps. I, I, look, I love the Occi story. I love, you know, both of those, the two co-founders were two bright young men.
Yep. Um, so that's our canine dogs here. Yeah.
They wanna join the conversation. Yeah. They, they're on next they said David's about out of his 15 minutes, uh, mic 'em up.
Yeah. It's, um, but anyway, yeah. So I ox I was one of the announcements.
What else do you have? Yeah, so we've extended GitLab Duo and what I can do for ai. And, and so for those who don't know, GitLab duos, our suite of AI features across DevSecOps Mm-Hmm.
And, uh, since the last time we spoke and we're showing off in the booth today. So if you're here at RSA, stop by, if not, you can see the demo on the website. We're showing off, uh, duo's ability to auto resolve vulnerabilities.
Love it. And so now for developers, it's not just helping them understand why it's a vulnerability, but now with a single button, they can click and have duo refactor the code and remove the vulnerability. I love that.
And so what we're realizing is that for customers to get the acceleration they need, like we, at our time of our IPO, Sid said he was quoting a Mark Andreessen, like every company will have to become a software company. Yeah. I think everyone now is got to become an AI company to stay competitive.
No doubt. And giving them the power of what GI Lab Doo can do. Not just for creating code, helping 'em with playing, but now helping 'em auto resolve vulnerabilities.
You're starting to empower the entire team and that's where you get your acceleration. I love that. Yeah.
Very cool. Yeah. What else we got David?
Yeah, so I would say the last thing is stay tuned. We've been focused a lot on software supply chain security. We see that as fundamental to how people deliver software.
It is. Uh, we recently, uh, took a, a more prominent role with the open SSFI joined the board a couple months ago and we're really looking forward to how we can help define better software supply chain security standards for the industry. Amen.
Because I mean, I know they've had some reorg and open SSF I'm glad to hear that GitLab is, is actively involved in there now. Yeah. We're a general member and I joined the board.
You Are? Yep. Good for you.
Yeah, I'm excited about it. I, I knew some of the board members there. Um, I don't know if they've stayed or left 'cause they've left some companies, but we'll talk about it.
Yeah, we can talk about it, but I think there's a tremendous opportunity to make it happen there. Yeah. I mean, ultimately, like our goal, so we've been focused initially on shifting security left and helping you see your vulnerabilities on the dev side.
We then started talking about the ops side and Yeah. Leveraging things like our API scanning and so forth on production. And now it's about getting that full, uh, connected environment.
The feature we just announced in our last release was the ability to block secrets before they're even pushed to pre-commit time. Very powerful. Absolutely.
We wanna extend that to now being also, uh, web signing. If you're doing stuff within the ui, being able to give you a full SBO m not just for the software that GitLab is built, but allow you to import other applications. That's right.
You gotta put everything in there. Yeah. And then finally, just continue to extend the visibility you can get today.
Right now you can see if there's a compliance violation that's occurred. We wanna take that further and get you into like the actual, call it the data digital forensics component of that to better understand what happened, why it happened, and how to prevent it. And so if you start to look at the things we've talked about, whether it's oxide, whether it's the pre-commit, secret scanning, and the container scanning both, or the registry scan, both container dependency, and you start to see like where that can go.
Uh, our goal is to really give someone a single pane of glass into their, their full software development life cycle, including the health of their software supply chain. I love it. Yeah.
So you, what you're trying to tell me is you haven't been very busy yet. Yeah. I mean, I'll, I'll, I'll be honest.
I've been lo fake. Yeah. It's actually funny.
I think every, every conversation we have, it's like, when has David been home, right? So this is the end of five weeks of travel. I got to go around the world, meet with a lot of customers.
It's very interesting to see how it re regardless of where you live in the world and who you work for, there's a lot of common themes. Yes. There is.
You know, you are worried about developer productivity, you're worried about security. Security. You're worried about visibility and really about the Guide Rail guardrails and controls.
Yeah. And whether that was visiting customers in Paris, London, and Germany across the us it's really interesting to see how GitLab is making a difference for, for our customers in the industry. Like Walt Disney said, it's a small world after all.
It Is. But yeah, we've gone from first conversation. David, why, why is GitLab at RA to GitLab has put the sac in DevSecOps.
Excellent, man. I love it. Yeah.
David DeSanto GitLab here live at RSA. Excuse me. We're gonna take a break as we're headed into our afternoon coverage of our first election.
Second Dave coverage here at RSA. Stay tuned. We'll be back.
Hey everyone, it's talent Hum. Will here for Text Drunk tv. You know, by now, I hope most of you have heard the news that Techstrong is combining with Futuro Group to bring probably the largest end-to-end offering of advisory services and media to the tech world today.
We're so darn excited to have this because as I, as I mentioned in my discussions with Dan Daniel Newman, CEO of Futurum Group, really the pieces of this puzzle fit together like a good Tetris board in that regard. Let me introduce you to two people I want to bring on today. First of all, I, I mentioned him earlier.
Dan Daniel Newman is the CEO founder of Futurum Group. Um, Daniel, welcome back to Text Drunk tv. It's great to have you on here.
Good to be here. And then joining us for the very first time on Text Drunk tv. He's actually a co-founder, Daniel's partner in Six five Media right.
As well as the CEO and Chief Analyst at More insights and strategy. It's Patrick Morehead. Patrick, welcome to Techstrong TV for your very first but not last time.
Yeah. Thanks For joining us. No, I've been really impressed with what you've built, uh, and I'm super excited to, uh, leverage all the goodness across more insights and strategy.
Uh, the six five and six five media and also, uh, signal 65, our labs testing business. And here's the really great news guys. You're going to be able to see a lot of the six five media right here on Text Trunk tv.
Speaking of premium kind of stuff though, six five Media has their flagship event coming up, right? This is the big thing you guys aim for all year this year seems like it's gonna be bigger than ever. Daniel Pat, tell us about it.
Yes. Maybe I'll kick this off. First of all, it's the, the fifth year running.
And, uh, what Daniel and I really wanted to do is come up with a unique event that really hit, uh, at the thought leadership and strategic nature of, of what was on the minds of CIOs, uh, CEOs, CXOs, and even investors. Shocker, right? This year's event is about ai.
And you know, as Daniel's, I, and I always talk about 2023 was, was the early build out, right? Primarily in the data center. Uh, and, you know, there were some app early application that came out, but this year's event, we're calling AI Unleashed, right?
Which is really how AI is working for enterprises delivering real value. And of course, the continued infrastructure build out in the data center and on the edge. And we couldn't be more excited.
I, no, no pun there, more excited, but all good actually, what I, what I love about the six five Summit format is this isn't a bunch of 22nd sound bites clipped off at some show or something, right? These are in-depth discussions with the two of you and some of the leaders, leaders of the tech world, right? This, this here is Keynote Daniel Klu said, Yeah.
5 really was that the tech media and the business media rarely gave top executives across the tech landscape really the platform to go deeper into the business, into what's making their technologies different, how they're serving their customers. And Patrick and I know that as analysts, that it is the voice of the analyst that really drives market understanding. Pat loves to say we are here to educate, to inform, and we are, but we're also here to drive meaningful conversations this year.
Speaking of meaningful conversations, we have maybe one of the most exciting and prolific CEOs, bill McDermott, the CEO chairman of ServiceNow. And he's gonna be joining an esteemed group of people who have kicked off our event. This includes Pat Gelsinger of Intel, Arvin, Krishna, CEO of IBM, uh, Michael Dell, the CEO of Dell.
Um, and then we had Hock Tan last year from Broadcom. So every year we've brought top top CEOs exclusive in-depth conversations. And of course, on the average, we have 20 plus other CEOs and their direct reports from the world's most exciting companies and startups.
So we have companies like Microsoft and A-W-S-I-B-M, Salesforce, uh, you know, hp, uh, you kind of go down the list, Lenovo, Intel, and it's so many, and in many cases covering 13, 14 different technology adjacencies. So it's everything from chip makers to applications builders to automotive companies, and even regulatory policy and sustainability conversations. Alan.
So we love what we've built and could not be more excited to bring distribution of the six five on the Tech strong network. And of course, sharing what Techstrong's doing across our respective networks. That is how we end up with the Tetris board.
You spoke of the peanut butter and honey, the peas and carrots. You get my drift? Yeah.
I don't know how many people out there do peanut butter and honey and not jelly, or they like peas and carrots just, but it fits together pretty tight. Meaning if You're paying attention, Uh, we're, we're with you. Yeah, I Mean, we, we've got a lot, lot of different, uh, swim lanes as we call them.
I mean, we have of course, right, AI infrastructure, AI enterprise software. We have automotive, right? We have connected intelligent edge, we have cybersecurity semiconductors, uh, of course.
But there really is something for everybody on what you, you know, what the listener wants to hear. And, and we love our sponsors for it. We're super excited.
You can't register. There's no, it's no cost to, you know, view this, it's available, stream, gone those days. It'll also be available on demand.
And as Daniel alluded to this year for the first year, it'll be available, it'll actually be on our tech strong virtual event platform, which is gonna allow for a lot more interactivity. Folks. You'll be able to chat with other attendees as well as maybe some of the speakers and some of the companies represented there.
There'll be additional interactive features of downloadable information, just a whole bunch of stuff. We're gonna, you know, bring that whole text drug treatment to it. And that is really, you know, when I, when I first met Daniel, besides getting the opportunity to meet Patrick, what really got me excited was, man, what we could do with this.
Right? You know? And, and, and this is gonna be a great example of what you can expect in the future from a, a tech strong future, a hookup here where we just, we're just gonna go bring it like you've never seen it before.
So again, that's June 11th to the 13th. Daniel, is there a site we could send them to right now? Or maybe they could register and get more information?
Yeah, absolutely. I would appreciate if you'd throw it in the show notes below. com and of course follow us on at six five Media on all of the socials, and there will be links to register there, but couldn't be more excited about the integration of the platform, the creating a more, uh, interactive experience for all of our viewers and of course sharing this.
And we appreciate Alan, that Techstrong has come to the table and wanting to help share this great moment. The six five and Techstrong are gonna deliver tons of eyeballs engaged viewers, it, dms and the leaders of the tech industry are gonna be checking out our content. June 11th to 13th.
Be there. This is Textron tv. Hi everyone, welcome back to techron tv.
You know, we talked just back from RSA last week. I thought maybe I had enough of security, but how could you ever have enough of security? So in that note, let me, uh, introduce you all or reintroduce you to my friend Nick Durkin.
Nick is Field CTO at Harness a company. I actually participated in a panel we did over at RSA. We're happy to have Nick in the harness team working with us.
Hey, Nick, it's great to see you. I'm sorry I didn't see you in person, but it's great to see you here at Textron tv. Absolutely, Alan, and thank you for having us on.
Genuinely appreciate it. Uh, it's much, it's actually our pleasure to have you on. Hey, Nick, we're gonna jump in and talk about something that no one talks about today, ai.
But before we do that, why don't we talk a little bit about you and give people a little, your background and just in case there are folks out there who are not familiar with Harness, maybe give 'em a little of the hardest story as well. Sure. Yeah, no, look, um, I started my career working in the banks, uh, doing some interesting things.
7 billion valuation and doing some fun stuff here. But ultimately, a lover of tech, um, advocate for the software developers and the operations folks around the globe trying to remove the worst part of people's jobs. And when you think about Harness, I think that's where it comes down to.
We, we built the modern software delivery platform designed to remove the worst part of people's jobs. No one wants to sit there and babysit deployments. Nobody wants to sit there and wait for tests to run, try to figure out which systems need to be running and operating.
So use artificial intelligence, use machine learning to think about things like your best engineers so they don't have to Right. Remove that worst part of the job. And, and, and look, AI is a hype term, uh, currently, but we've been doing it for the last seven years.
We came out as the first continuous delivery platform using artificial intelligence and machine learning to remove that worst part of the job seven years ago. Great. Very cool.
And they really have, I mean, harness almost, not, not redefined, but modernized whole CI/CD now we call it, of course, it's off. You know, the pipeline, the software pipeline, the software factory. And, and, and also let's not minimize software supply chain security.
And the whole issue of dev set ops, you know, within the, the development and delivery and deployment of software, right? And, and that's part of the harness mission today as well was actually on the panel we spoke about at RSA. I had said, uh, you know, your product G four on with us.
And it was about how, you know, DevSecOps is going forward as part of this whole DevOps CI/CD cloud native. You know, it's all rolled in. They're, they're, they're very interconnected today, right?
These are not separate silos anymore that just exist, you know, in a vacuum. The way, the way we think about it was everyone tried to shift left, but unfortunately they shift the workload left. And that was the wrong thing to do.
You know, adding more burden to developers, um, already, you know, they're already having to build their own tools. They're the only engineers on the planet that have to build their own tools, that have to go search for documentation, do other things. So to add more workload to 'em just is insane.
And so what we try to do is shift the information left, make sure that everyone has the right information at the right time. And that's security information that's making sure we know that our, our artifacts are at tested, that they're built appropriately, that they have the appropriate security scans. That's also about cost, right?
Engineers, if they don't, if they don't know the cost, they can't even do anything about it, right? And so bringing the right information at the right time, whether through the build, through the deploy, through the, uh, code scans, again, through the attestations, all of that needs to work in harmony. And the only way you do that is you stop that infighting by empowering everyone, giving them the information when it's valuable.
And I think that's one of the key things why this platform is so successful and so powerful is because it does, it gives people the right information when it's valuable. I love it. Good stuff, Nick.
Um, just real quick before we jump into whatever, wanted to talk to you about people are interested in hardest or getting more information, it's H-A-R-N-E-S-S. com or io? io, yep.
Yeah, the, uh, yep. Dot io. Absolutely.
Cool. All, so, another thing that was on high visibility at uh, RSA of course is ai, right? Everybody's talking about gen AI and ai, and is it gonna replace your job?
Is it gonna make you more effective? Is it gonna make you 10 x more efficient? Um, what, what should, what should we have AI be doing and what shouldn't we have AI be doing?
You have some thoughts on that, Nick, no surprise. I do, I do. It's, uh, it's, it's one that's honestly, you know, for the last seven years I've been preaching it.
And if you're gonna use artificial intelligence, if you're gonna use machine learning, we use automation, right? We should be doing it to remove the worst part of people's jobs. If we're using it to remove the best part, you're going to be fought, right?
You're going to have conflict. You're gonna create, you know, un unnecessary intentions as opposed to if you use it to remove the worst part of someone's job, they'll gladly adopt it. No one wants to babysit deployments.
No one wants to wait for tests to run. No one wants to figure out which system should be turned off and turned on to save cost without impacting customers. All these things, let's use artificial intelligence for, and at that point, you think about the toil when developers are spending only 40% of their time actually writing code, right?
That means 60% of the time is just toil, it's wasted time. And, and the reality is they shouldn't be having a context switch a thousand times over. They should not be writing these tests to do all these pieces.
If we start removing that worst part, now we're doing something beneficial. What's interesting though is that most of the industry is focusing the time on what engineers and what software developers love the most, which is writing code. And so I find it ironic that that's the first place to attack when yet there's so much more workload around what the software developers have to do, what, uh, these engineers have to actually create.
And if we can go remove that toil now we can actually start gaining the benefits. And, and I see it in a few ways. You know, one, you get junior developers become better quicker 'cause they don't have to, you know, move around all the different tooling and work that, but your best engineers become great.
They become amazing. They become the best because now again, you, you give them the freedom to do what they love. I, I agree with you a hundred percent, but you know, and I've been through more than several tech innovations in my career.
I will tell you that I think AI has a potential to be, I mean, on par with the commercialization of the internet in terms of civilization changing. But, but that being said, they all have a similar kind of evolution, which is, you know, at first call it a cheap parlor trick or the, or the magical factor. Like, wow, how did they do that?
Right? Uh, then it's the, okay, early commercialization, let's call it, let's go after the lowest hanging, easiest fruit that we can find. Then it's sort of the optimization sets in.
Let's get more bang for the buck. Let's, you know, not just do what's easy, but what's right and best. But that's a process, right?
And, and so when we, when we look at this evolution of, of AI and how it's, especially as it affects like the IT stack and software development and stuff like that, you know, I can't help but think Nick, we're way, way early in this. I think, I think we are early in the sense of the generative AI portions of it. We've been using, you know, artificial intelligence neural networks to determine things to think about things like your best.
We've been that for a long time. And I think in the generative case, that's where, where, where we're we're, where we're early, and if you look at, you know, we just ran the state of developer experience report, you know, went out to over 500 engineering leaders and practitioners really looking at, you know, what does this look like in our world? How is this going to affect us?
And you think about it, just the burnout factor, I think, what is it over half of the developers attribute leaving their jobs to burnout. Why? It's because of all that excess.
And so we start using it again. If we start, you know, in order to get this adopted in order to your point, to have it not be the early phase to get it adopted, we have to use it to remove the worst part. If we go and attack this and we go attack, you know, how many million developers in the world by saying, here's your job, it's going away.
That that doesn't win for anyone, right? That instills fear, more burnout, all the different parts and pieces. So I think it's about how we actually attack this problem, how we go work together in solving it.
Sure. I absolutely, but I, it's funny, I just got done the recording text on gang for tomorrow, actually. Well, by the time this plays and had one little more already played.
And, and you know, one of the things we, we talked about was developer burnout and developer, you know, uh, with the rides of AI and no code kind of stuff, citizen developer versus professional developer. Do we need a developer for every app? Do we need an app for everything?
Right? That, that was kind of the discussion. And I think right now we're still asking those kinds of questions.
It's this worthy of a developer's time and effort, because you're right, one of the things we've done, and it's not just security shift left, it's the whole shift. Left movement is put more straws on that camel's back. And, and it's funny when you think of it.
So that's the most overworked, highly paid position on the, you know, on the scale here. So let's put a little more work on that one where, you know, with ai, I mean, certainly the promise is, is that we do make it more efficient and we put less work on their, on their, uh, plate. But as I said, I, I think it's a bit of a process to figure out what, what work is less, right?
What, what is this, what is this developer consider to be sort of redundant, boring, low level, crappy crap that they don't want to do, right? And, and it, and it may not be, you know, uniform across every developer either. I think that's why you have different, you know, different categories.
I mean, you have folks that specifically you spend their time and wanna wanna work on DevOps, you have security engineers working specifically on that. And I think to your point, it's about empowering everyone to do the right work, to do the work they love, but do it in a way that's meaningful that doesn't cause infighting. And you know, you look at how many hours people are putting overtime in, I mean about half the days of, of the month people are putting in overtime.
You know, that's what we looked in the survey. And the reason is, is 'cause there's that much work to do. So there's the work.
We know that the work exists. And I think to your point, if we don't shift it left meaningfully, if we don't shift the information left, we don't give people all the right things. That's why we get rework.
That's why we get people, you know, context switching multiple times a day because people are shoving things back at them. And I think if we do this appropriately, if we make it so that we get the information at the right time, we remove that. And we've seen that, and this is, this is those benefits that you gain is that you remove the back and forth.
No other engineer, you know, I posted up on, on on Twitter or on X and I said, Hey, let's, uh, I think I did it on LinkedIn as well, and I said, let's, you know, start treating software engineers like every other engineer in our company, like our electrical engineers, our mechanical engineers, our chemical engineers. And people go, well, in what world? They go software engineer that we have at the best.
We get all the free food, we get the snacks, we get, we get to work from home. All these fun things. They're like, great.
I was like, so you, you know, you have to build your own tools, right? You have to search and hunt and pack for documentation. And 20 times a day you get interrupted for, for changing, you know, the context.
I go in what world is that a good way to operate? And so we start actually treating engineers like the rest for engineers of our companies, like our software engineers, genuinely, I think that's where you start actually seeing the success. You allow them to do what they're phenomenal at.
So couple of, uh, surveys have come out, how much time did developers actually spend developing? How much time do coders actually code? And I've seen it range from like 11% to 30, 31%, no more than that.
And so, you know, and, and let's be clear, coders like to code, right? You'd like to see that number at 66%, I bet, or higher. On the other hand, testers like to test security people like to secure.
Are all of us being so inefficient that the, and I haven't seen surveys on this, how much time, you know, the test to spend testing. I, you know, but I wonder is the whole stack that distracted and really can AI help us up and down here? I think that's the, that's the key.
That's the benefit. That's the area where we can focus. Because today, again, we shifted that workload.
So why do we have this full stack developer that has a list that's longer than anything? Alan, I'm sure you would not hire your electrician to do your plumbing and your plumber to do your electrical. And yet we ask our software developers to manage our cloud, to add security to like literally every part and piece of the stack.
And it doesn't make sense. We've hyper specialized everywhere else in the world, and yet here we, we give freedom, but we don't actually do that. What we do is we shove workload on them.
And I think that's the biggest issue. And so, to your point, if we allow everyone to do what they're meaningful and, and what they're good at and what they love and they're passionate about, have you seen someone do what they're passionate about? They do it with, with, with every bit of energy.
If you force something on that that they hate doing, you watch that. That's what we see the burnout for. And so all this is, is about empowering people to do what they're great at, and again, giving them the information at the right time, not the workload.
Of course, swim, we played devil's advocate here for a second. This isn't Star Trek, right? And we haven't quite done away with the monetary system and it's far from Nirvana and Utopia.
We don't have people with red shirt that disappear on every other episode. But, you know, that being said there, you know, not every job is perfect and there's always going to be things that are toil and, you know, unpleasant, redundant, not interesting. Um, I, I think we do want to try to prevent burnout, obviously across the board as well.
It's burnout. As you know, the World Health Organization has recognized burnout as a real condition. It's not just, you know, some care and moaning at work about how much work they have.
Um, so it, it, you know, this is a real thing. What makes us think AI's the answer though, Nick. So I think this is the way to actually go and start putting things in, in, in buckets and actually allowing people to focus on the areas that they love.
And it's about also making it easy to do the right thing and making it hard to do the wrong thing. And I know that's, it's a basic statement like, oh, sure that, that makes sense. If that was true, the cloud wouldn't have existed, right?
If it was easy to do the right things, people would've spun up VMs easily, but instead they went to the cloud. And so I think by making it easy to do the right things, it's giving people guardrails. It's giving them the ability to have enough freedom to do what they need, but not too much freedom to where it kills them.
And I think that's really the benefit, is that by removing that worst part of the job, by making it easy to do the right thing and, and hard to do the wrong thing, like let's genuinely make it difficult for people to go do the wrong thing and to focus in the wrong times or, or spend their time in the wrong area. Now we can actually start seeing it. And that's where then you can find everything.
You know, one of the things we often talked about is you have to measure things. How do we know what to even go fix? And what you use AI for, for not even measuring it.
And most organizations aren't even measuring what the entire software live life cycle looks at. That's one of the things that we, you know, come in and focus on, which is let's look at that entire engineering life cycle and figure out where should we spend the energy and the effort. Where would AI be great?
'cause it's something nobody loves doing. Testing, right? Writing rego for policies, doing all these things that people hate.
Creating dashboards even, right? Versus where can we actually affect change with maybe it is process, right? Well, okay, we're not gonna maybe fix that with ai, but you have to even start measuring it in the first place.
I think that's where you get to harmonies when we actually know what things look like and half the people don't even, don't even understand their metrics that they're even measuring or trying to fix. I, I don't disagree there at all, my friend. It, it is.
Um, you know, I just, so I do believe we're going to get to a future where AI 10 x is people A hundred percent Right? How soon? I, I can't tell you for sure.
Will we have quantum computing by then? Who the hell? No.
But all that being said, you know, the promises there and, and sometimes you just gotta keep your eye on the prize and fight through, you know, kind of the jungle to get to, to the promise land, right? Um, I, I do think it's gonna be an interesting couple years as we figure this stuff out. I, I just, you know, and there'll be voices like you who are calling, you know, for clarity, Nick, but I, I, I think we're in somewhat of an uncharted territory and we've gotta figure out kinda what makes sense all around here.
If we keep the human at the forefront and the focus, right? And I know it's on my screen. Where's it, Adam?
Remember the human? But if we actually start thinking about people, right? And we're using AI to actually, you know, better people's lives, I think that's a great focus.
That's a, that's a great start. And, and by doing that, and by again we have the people that work way too many hours, we have the people we lean on way too much. If we can remove burden from them, why wouldn't we?
Any intelligent company would do that. And I think that's, if we actually keep the human at the forefront, that's where we win. Absolutely.
Hey, Nick, we're probably over time. I, I have a good time talking with you though. Sorry, I let it run.
But, um, hey, say hello to all our friends at Harness. I know you guys recently had some big corporate news out look for that probably. com.
Absolutely. And, uh, we're working with Harness on our DevOps next event, uh, report as well. So I'm sure we'll be in touch on that.
But until then, Nick Durkin Fields CTO harness here on Tech Drunk tv. We're gonna take a break. We'll be back in a minute with more Tech Drunk tv.
I'm Bonnie Schneider, sustainability contributor to the Techstrong Group. I'm excited to introduce you to a groundbreaking new initiative from Techstrong Research, the sustainability pulse meter. The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry.
Position your company as a leader in the industry and differentiate from your competitors with a sustainability pulse meter offered exclusively from Techstrong Research. This is Textron tv. Well, the great pleasure of talking again with Austin Parker, Austin, who I've talked to many times on panels and shows and, and at shows.
And we just both came back from, uh, KU Con in Paris recently. And, uh, you're director of Open Source, Open Source. Okay.
At, um, honeycomb Welcome. Yes. Yeah.
Um, yeah, it's great. Been there about oh nine months now. Yeah, I remember when you first moved over.
Yeah. That's all fantastic. It is all going well there.
I hope it's great. Yeah, no, it's super, super fun. Super exciting place.
Um, we're doing a lot of really great stuff over at Comb right now. Ah, There's some fantastic people there, including, oh Yeah, love, love the people. Love.
They're really great. Love, Love charity. You love charity and, uh, Liz and Everybody.
Oh, Liz's great. Yeah. No, it's, it's so fun to work with a bunch of people that I've, um, you know, throughout my career, sort of in observability, I've interacted with so many of these people in the community and now just getting to work beside them, um, and really help, you know, continue to innovate in the space is really fun.
It is. It's a very, um, highly respected and highly collaborative group of people. I mean, this, it's really good to see the great things that have come from all your work.
One of which is you recently came out with the new book, and that's what we're gonna talk about. Now, you're not a first time author, you've authored other books, but I think this one has a little bit different approach than you had. Tell us the book title.
Yeah. And tell us about kind of what, what it's about. So the book is called Learning OpenTelemetry.
Um, I wrote it with my friend Ted Young, who's also, uh, who I worked with at LightStep for five years. And we were both, uh, initial contributors, kind of founding members of OP of OpenTelemetry as a project. You know, one thing that people might not know at this point is a long time ago, or maybe not that long ago, but certainly five, six years ago, there was a project called Open Tracing that was part of the CNCF.
And there was a project called Open Census that, uh, Google and Microsoft were backing. And we both, both projects had very similar aims, um, to really help push forward observability. Um, mostly through making distributed tracing more accessible to people, open Census, um, had slightly different ideas about how to do it, but it was causing a lot of confusion that there were these two projects that more or less did the same thing out there in the world.
And one day, you know, we all kind of sat down, it's like, eh, it's silly that there's these two separate things, you know, why not just have one thing? And that's what led to OpenTelemetry. So that was announced back in 2019.
Um, we recently kind of celebrated our five year, you know, anniversary. Wow. Um, and it's come just an amazing, uh, it's honestly staggering, you know, how far this project has come over the past five years.
But with that in mind, you know, as it's gotten more popular, uh, OpenTelemetry has been for three or four years now, you know, the second highest velocity project in the CNCF, um, at the end of 2024 or 2023, sorry, we had something around 2000, you know, almost 2000 contributors, um, over 300 companies contributing to the project, you know, which is a huge number. And as time goes on in any com large complex project, it becomes harder and harder to kind of understand what it's about, right? Like as it expands and grows.
There's just so much knowledge that kind of doesn't get lost, but just sort of gets gets subsumed, it goes below the tide. And we found ourselves kind of answering a lot of the same questions over and over about like, why, why were things in OpenTelemetry a certain way? Mm-Hmm.
And we have a lot of great documentation about it. Um, and people have written other books about OpenTelemetry, right? Good friend of mine, um, Alex Bowen wrote a great book about, you know, using OpenTelemetry of Python.
But the thing that a lot of these books had in common is they're very kind of focused on like a, you know, on one language, right? And how to do this stuff in Python, um, or in Go or in Java or whatever. And nobody really took a step back and said, well, hey, what, what is the point of all of this?
Because when someone comes into OpenTelemetry from, you know, existing sort of monitoring observability background, you know, they know things like Prometheus, they know Elasticsearch or Open Search, they know maybe Zipkin or Yeager, or they know specific commercial tools, you know, they know Datadog, which obviously is a great observability company. Splunk, there's so many things Mm-Hmm. And fundamentally, like, yes, that's valuable knowledge coming in, but OpenTelemetry is trying to do something that is a little different.
It's, and it's kind of a subtle difference sometimes. Um, but we're really trying to push this space forward by talking about how all this telemetry, all of this data from your application is really part of not three pillars, but of a single interconnected braid of data. You know, a stream, a very rich stream of data that has things like inherent correlation, um, hard and soft context between different signals in between different events that happen in your application and your infrastructure.
Um, conventions for how to represent this data so that tools and end users, you know, can understand it more easily. And there wasn't really a great resource for people coming in that didn't have that context, didn't have that background. Mm-Hmm.
And so we sat down and said, you know what? We're gonna, we're gonna fix this. And we went out and wrote, wrote a book on it.
And that is Learning OpenTelemetry. It is, you know, the comprehensive guide, I think on, not necessarily like the API or the SDK or how you do certain specific actions, but we give you all of the knowledge you need to be able to interpret and understand like, what is happening in OpenTelemetry? How does OpenTelemetry function, how do all these parts fit together?
And we give you the knowledge that you need to, to go on and learn more, right? Because there is great documentation. You don't need us to regurgitate the documentation to you in a book.
Um, we have great docs on our website, but you do need to understand what all these different things mean in order to really understand what the documentation is telling you. And so that is what Learning OpenTelemetry does. You know, it, it's really great.
'cause I, I've often struggled with this, the simplicity of logs, alerts, and traces sounds good. But it's a much more complex than that of putting that all together with context and what's happening and, and in systems and multiple systems and, you know, transactions that are flowing and resources that are involved in it. You know, it, it is, it is a, a braid, if you will, of weaving all of that information together as you described, to really understand what's happening.
So just listing those three, um, sort of understates what's really involved, it makes it simple to understand. But, you know, you could put all those in a database and have that, that's not what, you know, this is really about. Right.
Uh, well, well tell us, I I, I, one of the things I, I really appreciate about the book, and it's great that you, you took approach, an approach like this. Uh, let's just set the context of understanding kind of the whole system of you, of a system of tele OpenTelemetry and how that fits into an observability kind of model. And you talk about the difference of telemetry and versus analysis, right?
Mm-Hmm. Those are kind of getting that data and then doing analysis on it, on it are not necessarily in the same tool. And that's where most of us live, right?
It's, that's part of what OpenTelemetry does, is separate that the data gathering, um, from, you know, being tied into individual commercial or open source tools for that matter, um, kind of giving you that one common plane of how do you get all that information together and then access it in a way that you can do analysis across all those systems, on all those kinds of information. Yeah. I think there's one, one thing that I've been sitting down with a lot recently is this idea that, you know, uh, again, to kind of do a quick history lesson.
Let, let's think five years ago before OpenTelemetry, um, when observability was sort of this hot new word. Mm-Hmm. And if you go and you look at, you know, again, you look at these commercial tools like Splunk or Datadog or whatever, these were considered monitoring tools, right?
You didn't have an observability tool. You had a monitoring platform. And that monitoring platform will let you do things like take in metrics and set alerts on them, or search through logs, or do what was called, you know, what we call a PM, right?
Application performance management, real user monitoring. What are all these things, you know, and what do all these things have in common, right? At the end of the day, these are all taking events from your system, um, translating them in a certain way, storing that data in a certain way, and letting you do math over those events, right?
Letting you do things like when this number gets bigger than that number for more than five minutes and be an alert, you know, ping, ping me, um, PagerDuty or something. And very quickly as observability became a word that people kind of cared about, um, all these monitoring tools just, you know, flip the sign around and said, Hey, we're observability tools now. And I don't think that's wrong, right?
Like, I think that some, some people, that happens All the time, every time you come up with a new turt, everybody rushes to become that. Every, Everyone rushes to say they're part of it. And I, but I don't think that's actually necessarily wrong of them to do, because I do think that, you know, most modern analysis tools do let you do observability stuff.
The distinction that I like to draw now is that a lot of people, you know, and this goes back to what I said earlier, if you're coming in from sort of a monitoring background or professional observability background, you're not really, you're, you're thinking of this stuff as still workflows. You're thinking of it as analysis. So you don't think about logging as anything other than the input to sort of a log search system.
You don't think about traces as anything necessarily other than the input to a a PM tool. And now with Modern Tools, yes, you can have some correlation between those, right? You can jump from a log to a trace, or from a, you know, metric exemplar into a trace, or from a real user monitoring, you know, from a web session into specific logs that might correlate with it.
But the dis the difference, and I think OpenTelemetry is trying to get at this, is that the actual data itself is more or less, I relevant to the analysis in the sense that right now, you know, the analysis drives the data, but what should actually happen is the data should, the data itself should drive the data. A trace is a particular, you know, in OpenTelemetry, all of these things are just events, right? When I, when something happens, I'm creating an event and I'm telling OpenTelemetry, okay, I want you to interpret this event as a particular type of instrument or signal.
I want you to say that this is a metric or, um, a counter or a measurement in a histogram or a log statement, or a span or a span event, or all this stuff, right? There's a lot of, you know, varying details here. And one of the things about the book is we break all this stuff down for you and say like, okay, here's the difference between a span event and a metric and a blog.
But ultimately, all of these things are just ways for you as a developer, or you as a library author, or you as some, you know, someone that works with software to make a statement about like, Hey, there are events that happen in my software. How should you as a user interpret those events? And they give you ways to model the behavior of your software and system.
And then the people that are using your software system can take those events with their semantic information about what is going on and what is happening and why it's happening. Put those into analysis tools and use that to understand the emergent behavior of the system in production rather than, I have a bunch of logs, I don't know what these mean. OpenTelemetry gives you the tools you need to actually have a semantic understanding of like, this is what this log means, and this is why, even why this log is a log, right?
It could be anything else. It could be a metric, it could be a trace, but it's a log for a particular reason. And as tools kind of catch up with where OpenTelemetry is, I think we'll see more being done to help end users understand like, oh, all these semantics, all of these, um, these affordances that OpenTelemetry gives you, actually helps you become more efficient at finding problems in your system, right?
Find understanding like why an incident is occurring, and even understanding how the system is really supposed to be put together. I think we talk a little bit about this in the book, um, like you said, the difference between transactions and resources, right? A transaction being something that happens in the system, a resource being something that is consumed by transactions.
And if you're a developer, understanding that is actually super, super critical because you can't affect resources necessarily. You can give, you can put more in, and you can always give more ram to your pod or, um, more hard drive space, but you can't really modify them on the fly. You can only really affect transactions.
And understanding the emergent behavior that comes out of hundreds or thousands or millions of transactions and resources, co-mingling at the same time is where I would say pretty much all interesting problems, performance problems happen. Makes a lot of sense. Yeah.
So, and one of the things that I hear you saying is, in part, this is for end users to kind of understand OpenTelemetry as a system and the elements in it so you know what it's made up of and how it works, so you can better implement it. But it also sounds like, you know, there, there's a great book for prologue of how to, how to develop and using hotel, uh, libraries and such. Um, but it sounds like it's good, good for developers to read this because you also will understand the whole, the system as a whole.
And now, you know, when you're emitting transactions, here's how that interacts with other transactions of different types, that kind of thing. Yeah. Fair to say.
Uh, yeah. One, one thing that, there's a little call later in the book that I really love, and it's that we used, you know, I don't know if I've ever told you this, but like, when I got started in software, I got, I was a software developer and test, right? So I was in qa, and it used to be that we had people whose job it was to understand, you know, how the system fit together and the interactions between different parts of the software.
And we called them qa. mm-Hmm. And so you would write code, you would make sure it builds in your machine, you would make sure it passes, you know, unit test, and then you would throw it over the wall to a QA engineer that would go through and do acceptance testing, right?
They would go through and they would make sure that it works in the way that we think it should work, that there aren't unexpected behaviors, or that when I do something weird, you know, everything keeps happening the way it should. And over the years, you know, QA has been, I mean, I think it's really kind of been a dying breed, right? Like, we don't have, uh, as much manual qa, I feel like as we certainly used to as an industry, but in a lot of ways, telemetry can really help us with this, right?
Because telemetry is a way for you as a developer to actually say, this is what the system is supposed to do. You know, you can define the relationships between things. You can say like, Hey, when I'm writing a, you know, when I'm creating a trace of my system, or I'm creating a span, I'm actually saying what's important, right?
Like, how is, um, what do I, how do I expect this to work kind of in isolation? And then you can record that by taking those spans and sending 'em somewhere. And you can have a nice like copy of like, Hey, this is how things are supposed to work.
It works this way on my machine. I can then take that and compare it to how it's working in production, right? That's a really powerful ability.
And if you start thinking of like, Hey, telemetry is part of, you know, this is kinda like the modern QA process. This is how we're actually making sure that things that we're building work properly. Um, but it's also much more powerful because it's something that runs all the time, right?
Like this telemetry is just there, it's below the surface. You can go look at it when you need to, to validate your assumptions. Um, and then when things do break, because things are always changing in a complex system, you can go and actually understand what's happening to my system in production.
Why are things different than I expect them to be? And again, you have that history, right? You have like, well, it works this way here and now it's working that way there.
Um, and now I have all the data I need to really understand that. And also I can take that data, put it into analysis systems and do things like get alerted on it, right? Or see, you know, track those changes over time, um, through metrics or get that kind of like snapshot of a single end-to-end transaction with traces.
You know, that, that, that kind of explains, at least in part, one of the really interesting things I saw in the book too. Um, you know, 'cause we talked about observability and development and test. Now it's not just an operational, uh, uh, tool, if you will, if that's the right term, but, um, there was a call out in the book that I remember saying, sort of, don't stop at telemetry and analysis, right?
Getting the data and then doing the kinds of math on, on that data to tell you what's happening. This is more like a DevOps kind of adoption, right? It really, it's something that affects the whole organizations.
And as you're talking about how this could help qa, right? Mm-hmm. Up informed QA of what the system is doing, what's happening and it does, is doing the same thing in test Mm-Hmm.
Talk about how that, how observability is something, uh, that an organization adopts, not just a thing we use. io, uh, inspired by some other people writing in the community about, about sort of the thing that I said before, right? Which is how every monitoring company has flipped the, you know, flipped their sign over and said, we're an observability company.
But I think fundamentally like that actually kind of hides a deeper truth, which is we spend a lot of time talking about, you know, we, we've kind of spent so long as people out on the bleeding edge talking about observability, is just better monitoring that we've missed a real opportunity to make it relevant to the rest of the organization, right? Because if you, a really simple example is this, we spend all this money on like these very expensive, you know, observability platforms. Um, but if you think about like a, a business in general, what drives a business?
It's data. Businesses collect so much data every single day, and we have these massive data lakes, data warehousing, you know, we business analytics. Like what is that?
Well, it's just telemetry, isn't it? Right? Like, aren't customer analytics, you know, aren't like tracking clicks in a webpage or how many things someone ordered or a customer profile aren't All these things actually just also telemetry, there's telemetry about a different thing.
Why do, why aren't we kind of taking that next step and saying, well, look, perform, you know, performance telemetry from sort of your engineering is actually so much more related to that business intelligence telemetry than you really think. Because if I'm, if I have an e-commerce site, um, or I have any software that deals with, you know, any kind of software that people interact with, and I generate revenue off of that software in some way, the performance of the software and the actual business performance are incredibly important to correlate. So why don't we, you know, and right now we actually can't really fundamentally ask those questions because we have this, this wall between sort of the engineering side and the, the business side.
But wouldn't it be interesting if you could ask stuff like, okay, show me, you know, I have this conversion funnel of people that are on the site, and I wanna know, um, how many people are falling outta the funnel? Well, I really also would like to correlate that with, you know, performance, right? Like, for people that are falling outta the funnel, what percentage of them had a page load time that was over 500 milliseconds or over one second, right?
What percentage of them were in a different geo? Uh, break it down by device type. Break it down by like any number of factors that are, again, blending analytics, you know, business intelligence, data with performance, uh, telemetry data.
Now, OpenTelemetry is really just about standards for that, you know, performance data, right? It's not trying to be a schema for bi data, but there's no reason that you couldn't extend it or that you can't use the fact that it is a standard to kind of correlate with other standards. I actually had a really interesting chat a couple weeks ago with a, um, someone that works, uh, involved in large injection molding operations for plastic bricks.
Mm-Hmm. I can probably guess who that might be. Oh.
Um, and they're using, and they, so they obviously have, you know, very complex, uh, and very finely detailed standards for, you know, production and a lot of robotics, a lot of automation, a lot of manufacturing stuff. And it's very important to them. They've extended OpenTelemetry to get data about the performance of their injection molding process.
Right? Interesting. And you know, how the robots work and, um, and all of this stuff is obviously, you know, uh, like this is a huge thing for them because this is, this is literally the bottom line, right?
Like, if you're physically making stuff, you wanna make sure that you're not, you know, you want to control waste, right? You wanna control, like, how much do I have to throw away of a given batch because of x, y, and Z reasons? So they're taking up telemetry and they're really extending it into sort of their business operations in a particular, in, in a one specific way.
But it really got me thinking, it's like, oh gosh, like software doesn't do, software really doesn't do this that much, right? Like, you tend to see this, again, this silo of, and even in places that understand this, they're like, well, I would rather, you know, it's like, oh, don't, don't commingle these, right? Like, take the, the customer analytics and use a different SDK and throw those into the, the BI data lakes so that our analysts can look at them.
Mm-Hmm. I'm, I, I feel like that's a missed opportunity for observability as a a practice. And we can extend it even further, right?
We can start bringing in code quality, we can start bringing in team health. We can start associating all sorts of other things with performance and ask interesting questions about like, well, and I mean, I don't wanna like sound like a jerk, but hey, maybe it would be nice to know how many, like, can we identify which team is improving their code the most in prod? Can we see which team is maybe responsible for more?
Um, failed pushes, failed mi, failed migrations, right? And not in the sense that we should punish them, but in the sense that that is useful data for our decision making process. 'cause maybe that tells us that people are getting burned out.
Maybe it tells us we need to invest more in training, right? We can take this data, we can put it in, we can turn it into SLOs into service level objectives about like, how good should our code quality be? How many times should we pushing?
Where do we need to invest and move that up and up and up until it's sitting, you know, until that's what they're looking at in the boardroom. And at that point, I think in a lot of ways, like soft, especially now, you know, the economy is changing. Money isn't free anymore.
The biggest challenge that every single person I talk to, especially executives, is like, we need to show value. We can't just throw money away anymore. We have to, you know, we have to connect everything back to how is this making money for the company?
And I think even in places where software is their job, r and d is seen as a call center, right? It's not seen as something that produce, you know, it's, it's like we have to just keep giving the engineers more and more and more money. And then sometimes they come back and give us something that we make money off of, but we don't really like that.
Right? But it's like, well, why not? You know?
Why can't we change that? And I think there's a lot of reasons why it's actually a much, we, we don't have time to talk about all the details right now, but I think one way that we can start to adjust this is by bridging, you know, this world of performance telemetry and how the application is running and what the system is doing to what the business is doing, right? Like, how is the business operating?
Where are we making our money from? Where, you know, what is important to us? Let's, let's tear down this wall and bring these things together.
0, right? Something that is more than what we have today. Something that is more valuable and more essential.
Um, and I believe OpenTelemetry is a huge part of that. And I think by reading this book, you will kind of come to see like some of this, you know, where, where this starts at on the performance telemetry side is certainly Super fascinating. I can totally see the talk you're putting together, um, probably in your head and in, in a few slides, I would imagine.
So what's what's fascinating too, is that one of the things that really intrigued me about OpenTelemetry initially was that we can start to measure things that, um, like end user experience, we could start to put business metrics in here. And what you're really doing is saying that that's really a wide open area. Um, we could do quality of our products of quality in a manufacturing process, quality improvement efforts, performance, right?
What are we're more efficient lines or, or manufacturing process that might, just to use that example, um, might help our business, uh, perform better or, um, respond to the customer faster, put on, because software's running all that stuff, right? Yeah. So we're already there writing code or using software to operate those things.
Why not collect the telemetry information that can help us measure the value we're creating or how to improve it, or Mm-Hmm. What's working well and what's not that just in our system, but in the things that our software is helping produce. Yeah.
I think that's a, it's a fascinating idea. It's, it's definitely, I think it's where this is all, you know, it's, it's where this is all going, right? I don't even wanna say, I think 'cause like I, I fundamentally know, um, these worlds are getting closer and closer together.
And it's not just because of, you know, I think some of it is definitely the macroeconomic stuff I was talking about, but a lot of it is just every company is a software company, right? Like, you can't escape that fact. Um, and with the rise of things like generative AI with the likelihood that more and more and more of our lives are going to be impacted by software, you know, it's not enough to just have, you know, the, these sort of slow feedback loops in terms of how is stuff performing for the customer, because people have more options than they ever have before for permission, anything imaginable.
And if you're not kind of putting customer, you know, that sort of end user experience and customer focus as the first thing, then someone else that is, is gonna come and take you lunch. Right? Exactly.
So, And it's too late to learn how to do that at that point, right? Right. Like, by the time you see.
But, and that's, I think that's what has been the story of so many industries and so many companies, you know, over the past two decades or so, certainly since the early two thousands. But by the time you realize there's a problem, then you, the moment has passed. You can't be reactive anymore.
And this isn't just, you know, about, like this is your business. Yes. But this is also about your software system by the ti.
If some, if you are hearing about a problem, 'cause the customer is reporting it, then you have already lost like tens of thousands, hundreds of thousands, maybe even millions of dollars because that one person that reported it, you know, people don't have this, you know, people don't give you a break anymore, right? Like, people, if, if something doesn't work, they're just gonna be like, oh, heck with this, and they're gonna move on to the next thing, or they're gonna find another way to do it. Um, this is true for so many things.
You know, if you aren't proactive, if you don't know what's happening in production to your customers, like it's not, oh, we were slow and we caught it late. It's like you have lost people that will probably never come back at that point. Yeah.
You only get, you know, that's just the way of the world these days. It is, it's pretty cutthroat out there. I feel like, um, you people really have to love you to give you a break.
You know, Everything's digital. That means there's a lot of options, right? Yeah.
Because we're working the same and, And with AI and stuff like that, there are, it, it reduces the barrier even more to people coming up with new options. Mm. Um, Good, really good way to think of it.
Well, hey, you know, whether you're wanting just to learn more about OpenTelemetry, I really just wanna understand it better. Maybe I'm new to it, or you, you want to understand it to, well, well enough to do more than just operationalize it. Really leverage OpenTelemetry in some unique and valuable ways.
It sounds like this is a fantastic book to help you set the stage. Yeah, I think it's a great resource move that Way. So Yeah, we have practical guidance on how to, you know, under, you know, we have foundational knowledge.
We have some practical guidance from actual users that we've kind of collected from our, from our Open Symmetry end using end user group. So stories about different trade offs, stories about like how to start using it, how to roll it out, um, deployment scenarios. There's a, there's a lot of like practical stuff in the book and there's a lot of foundational stuff I would strongly recommend.
You know, I said if this is a topic that interests you, if you're interested in observability, OpenTelemetry, um, either because you're adopting it or you're thinking about adopting it, you know, I really do think this is an invaluable resource and we, we tried to write it as something that, you know, is gonna be useful for the next five, 10 years, right? Like Open Symmetry is gonna be here for a while. I think this is probably a book that should be on everyone's bookshelf that is working with systems, software systems.
Sounds like it to me as well. So Learning OpenTelemetry. Um, where would you suggest people go check it out?
com. Um, we have links to Amazon to find a local bookseller or to, uh, where you can read it digitally on, um, O'Reilly Atlas. And we have a couple of, you know, you can find out some of our events.
We're gonna actually have a, uh, book release party this summer in Portland, Oregon. Um, and as we travel and do book signings and stuff like that, um, we'll try to post 'em on there. com.
Well, I hope we'll get another chance to explore this some more. 'cause uh, you brought up about a hundred things that I'd like to ask you more about, but we're obviously can't do that today, but appreciate you, um, well writing the book, you know, seeing the need for this and then, and filling that need, creating value through that. So congrats on the book.
Um, yeah. To you and Ted, you said Ted? Yeah, Ted Young.
Yeah, Ted great. Another great person in the community. Another wonder, Another wonderful human being.
Yeah, he is. Just super appreciate it much. And folks, uh, definitely check it out.
com and, uh, to get your copy in whatever form and through whatever source you choose. Austin, it's been a great pleasure. Always good talking with you and love getting online.
Love seeing you in person too. So I don't know if you'll probably be at some of the same events here again, we'll catch up with you. Yeah, No, definitely.
See, see you around next, next time we pass cross. Okay. Take care.
Thanks again. Bye. Al.
This is Techron tv. Hey everyone. We're here at the Open Source Summit, Seattle 2024, enjoying a great show.
It's really been, uh, a lot of energy, a lot of passion, A lot Of cross-pollinization about different kinds of open source project, which is of course what brings us all together here. A pleasure being joined by Kate Stewart with the Linux Foundation. Yes.
Our first time talking. It's great day talk here. Thank you very much for having me.
Yeah, I know you're, I know you're getting ready to zoom into a panel here. That's right. Yeah.
So, uh, if we can kind of capture a little bit of, um, sure. Knowledge and passion. Tell us about what you do at the Linux Fund.
So, um, my role at the Lenox Foundation is focusing on making sure that embedded open source becomes dependable. And so what I'm working on is how we can improve the transparency of open source, and then especially on the embedded side, how can we actually start to get it so that when people are designing with open source for things that maybe have safety elements or security elements, that we actually can make it easy for people to automate and actually do the right level analysis for being able to trust what you're working with. Can you say a little bit about embedded software for people who may not work in that space?
Sure. What are some of the unique characteristics of it? So, embedded software is usually software defined for a specific purpose.
Uh, things like your car, things like, um, you know, a blood, you know, a a a device like a blood pressure satellite or satellite. Yeah. Okay.
So basically resource constrained usually. Mm-Hmm. Power is a lot more important in those spaces.
You know, power's important in big server farms, don't get me wrong. Is footprint Still a, A big consider Footprint is very much a consideration because, um, Linux doesn't get smaller than about, you know, just 20 meg, you know, 10, 20 meg, something that range right now. And when you're dealing with a little sensor that's just basically looking at the temperature or something, or altimeter or things like that, you're not gonna wanna put that much memory on it.
Mm-Hmm. 'cause that consumes power. Exactly.
And so, you know, ze, one of the projects I work a lot with is called Zephyr. And Zephyr is pretty much been designed for resource constrained devices is too big. And that's in our tagline Where Linux is too big.
Too big. Yep. Where Linux is too big, Where we love Lenox, but weight Is too big.
And I love Linux too, don't get me wrong. I've been very active on a few other Linux related projects as well. Um, and I'll happily talk about those too.
But Zephyr is, you know, 10 K and up. Wow. What a Difference.
And yeah. And so that's, So it's not a even more slim down Linux. It's, it's All in No, it's completely its own new code base, everything else.
And it's been getting a pretty good community building up over, over Simon. It's been quietly building over time. Mm-Hmm.
Um, and it looks very familiar to anyone who's worked with embedded Linux. It's got, like, it's got cake config, it's got, um, the device, it's got device tree, and so you can just put in exactly what you need. And so that is attractive to a lot of developers, especially when the resources are an issue.
And it's being used in things like trackers that have to run for like, you know, tracking animals. Mm-Hmm. Um, it's being used in firmware on things like laptops.
Um, so all of Google Chromebooks right now this year, um, have Zephyr running on the firmware when they're powered off. Oh, Interesting. So that it, because it sips the battery as opposed to Linux, which is, this would be more resources just to keep it not awake.
Um, over in the Zephyr booth, you'll actually see a framework laptop, which is a doit, well, it's a build it yourself tip of laptop, or you can buy built and everything's full in play. And they're using Zephyr too. Um, we're also in Tic Kons hearing aids.
Mm. And it's also in wind turbines. So there's a lot of places people don't, It's a lot of places never think about.
And, you know, this is where people are ranked software and they wanna have good security. Yeah. And in some cases they wanted having safety.
So let's talk talking about both. Yeah. First security.
One of the challenges we've had ages ago, I think we've done some things to help with this, is how do we, how do we continue to update Yeah. Added systems at, At, And so for many, many years, it was sort of the usability life, uh, uh, uhhuh span of a piece of hardware was, was no problem. We, we will obsolete and replace it hard to do in a satellite or some other like that.
And so, um, there's a variety of, um, other projects we collaborate with that do secure boot and updates. And so those technologies are out there and we're certainly working with leveraging them. Um, one of the other things that's important is don't do an update unless you really need to.
Oh, okay. Okay. And so one of the things that we're doing in the Zephyr project is we can automatically on every build, generate out a build desk bomb.
And so if you turn on an option, you config, you gain this build desk bomb. So you're getting this bill dust bonus, so you know exactly which c files made into which a and which a were linked together to make your alpha image. Okay.
Interesting. And so you have that high precision, which eliminates a whole class of false positives on the security side. So, you know, if there, if the file with has a bug, the vulnerability is, isn't present, you don't have to do anything.
And being able to cut that out and just say, okay, yeah, no, we're fine and be authoritative. Mm-Hmm. Is a good thing.
So Zephyr's been embracing all the best security practices it can find. It actually got the gold badge for, um, it's open SSFs badging program. Mm-Hmm.
It got it way back in 2019, I believe. Okay. Um, it's actually one of the few open source projects is a CVE numbering authority with Mitre.
And so, you know, and we have its own piece or team for incident responses and assigning vulnerabilities. So the project is trying to follow best practices as we know them. And it's played off for the project in the sense it's continued to grow.
The, the big challenge right now is going after safety though. Okay. Tell us some more about that.
Okay. Kind of popularized now more people are thinking about it because of ai, but there's more aspects to it than, Yeah. So, so to do safety, you have to look at a system, you have to look at a full system of components.
And that is, part of that is softwares, but it's also what software, what hardware is it running on, what services may be pulling down. And as we start to bring more AI and modeling and things like that in, you know, what are the implications of your data sets and your training methodologies? So with Zephyr, what we're looking at is, um, getting it so that we can take the kernel of it through formal safety certification.
So if we used in 60, like the certification we're going after is 61 5 0 8. Um, we've been working with the certification body already. We're in our phase one assessments, and we'll be working on our code base through this next year.
And we're hoping to get 61 5 0 8 and 26 26 2 A LD, um, next year. And so this is what we're actively working on in the project and trying to figure out a methodology where we can do this in the open. Because right now a lot of the safety stuff happens behind closed doors and under NDAs because of the liability reasons.
But because we don't have any, because we're an open source project Yeah. We're more transparent. We can be more transparent.
We can try to show people how to do it. And so if we can do a bit of it, we are hoping that other people will help, help us build on it, what we do. And so that's, We can get more people to do it once they understand it's Not exactly, or, or understand it and then see the process.
In fact, Zephyr is one of the projects that's actually trying to do this. There are two others I work with that are trying to do this, one of which is a Linux kernel. Okay.
Uh, there's a project called elisa, enabling Linux and Safety Critical Applications. Okay. That's a, that's the acronym Not to be mistaken by the Macintosh Elisa.
No, Preces. Lisa Elisa. Okay.
Okay. Elisa. And so that group is a group of people that have come together to collaborate on how we can, um, surface up requirements, do the analysis of systems.
And so we've got some working groups in automotive and medical devices and, and aerospace that are meeting and trying to look at the problem and then trying to figure out, okay, how do we configure Linux? How do we assemble things together? What are reference systems?
And so they're trying to tackle the, so a lot of competitors are trying to collaborate on making things a lot stronger. Okay. Uh, they all need to solve the safety Problem.
They all need to solve the same problem. They're all working with Linux and they're trying to figure out how do we take Linux into a, you know, in spaces in places we need safety. Mm-Hmm.
And then the third one that's trying to do this beyond is Zen, which is hypervisor. Okay. And so it's been around for 20 years plus.
Yeah. You're familiar. And so the maintainers in that community are keen on doing this.
And so they're working on, you know, updating some of the code base to be aligning with measure coating standards. And then they're also looking at how do they start surfacing out the requirements so that we could have the requirements, the code to the tests, to the evidence to show that the requirements are satisfied. Mm-Hmm.
And then eventually, if all these projects are able to surface their requirements, well then when you create a system, uh, you've got, okay, I've gotta use this sensor. I've got on this operating system, I've got this property I need to satisfy from these things. When we have to plug these open source pieces in, we can hopefully connect our requirements.
So you can start to see, oh, if I use, I use this sensor, et cetera, here are all the tests I need to run. You Kinda have traceability. Right.
Exactly. And that traceability is what the analysis needs for the standards. And so as we work our ways towards that, having that transparency is going to be key.
And one of the other projects I work with is to try to improve that transparency. Okay. Is a project called SPDX or software package data exchange, except it used to be called software.
Now it's called System Package Data exchange. Oh, interesting. Okay.
Because it's more the software, right. We have, we're having to track metadata. It's important to know which hardware your software is running on, because there could be a bug in the hardware.
There could be like, um, do you remember when we had, um, specter and Meltdown? I do. Yes, I do.
And so it was the, it was, the problem was in the prediction side of the chips architecture. Mm-Hmm. And they had to work around it in the kernel and firmware to make sure that it wouldn't, couldn't be exposed.
And so you had to know exactly which firmware you had. You had to know exactly which hardware you have a running on, which, what chips you're running on. And then you also had to know the versions of the kernel to know that you had a safe configuration or secure configuration.
That's, There's a lot of parameters. You don't always don't Normally have to secure cloud applic. And normally right now, cloud application right now, now, right now, they're all scattered in, you know, different things.
Like some of the, we're starting to get the SBO stuff working. Okay. Mm-Hmm.
But, you know, the stuff for the, how the track, how we're tracking the firmware and the hardware together and things like that is still happening very manually inside organizations. And then they're sort of trying to layer the software on. So this is why we need to take it up to the system level so we can actually get all this stuff pulled together in a common way so we can reason about it.
Find it system. Right. Exactly.
It's not an isolated component that strictly operates otherwise it wouldn't do Anything. Yeah. And like, you know, one of the things you find in a supply chain is my product is your component And vice versa.
Me, they're a good point product for me to products and Yeah. And, and so subsystem figuring out, making sure that things are modular and things can come, like, so those who have the expertise can put the right level of metadata in automatically. We'll build trust.
Mm-Hmm. And then if people can build on trusted components and start to assemble their systems, we can do the right level analysis to keep us all safe. And it's a way, but figuring out how we can summarize all these different elements and have a common framework is one of the challenges that the SPDX community has been working on for the last three years.
And so, um, we've been working with, um, people from the, uh, the, the, we've had collaboration between OMG and the CIS group at OMG, along with the SPDX community from the last first release of our spec to try to come up with an internal model so that we can actually go out in multiple formats and quite frankly, be in databases so that everyone can query, like we can eventually query this up. And we've added profiles such that if you care about hardware, these are the additional fields you need. If you care about software, these are the additional fields you need it.
So we're trying to make it more approachable and efficient systems. You what? And, and I'm not an embedded systems person myself, but Okay.
Kind, kind of learning about it and reading about it. One things I remember reading is that, um, for example, with things that go into space Mm-Hmm. We're much more likely to use something that's been around for a long time.
Well proven. We know the failure rate is really low. Like maybe power CPC chips for CPUs, et cetera.
So we have a lot of legacies. Yep. Well proven technology.
Um, and then we also of course have, you know, what about the AI chips and new things that are coming down the pike, and how do we secure those? Do you, how far back are you able to step into existing technology that's been out there for a while? Or do we just pretty much let that be what it is and kind of work on the next generation?
I Think, I think it's, it's working on the next generation, like the European Space Agency has already said they're gonna go with risk five. Okay. Okay.
Some of those legacy things are not there. Five. Okay.
Interesting. Yeah. Right.
You're really making an leap there. And so, you know, um, they're, you know, they, they were in MIPS for a long time and then number moving out to risk five. So they're basically building up on that infrastructure.
And so the question then is, okay, what software are they gonna be running on these things? And then how do we take and prove it? It's gonna be safe for use and things like that.
Because, you know, the more you know the consequences of getting things wrong out there are, you've thrown several million. It's, it's a financial consequence. Usually.
It's really tough to bring it back. It's tough to, well it's tough to update it sometimes too. 'cause it's a rather thin pipe to get all the way up there and very slow point.
But, you know, some of the prototyping work that NASA's doing is like, um, you know, curiosity and the mo the, the Mars rovers, you know? Mm-Hmm. It has been running on the planet bars.
Right. And it's been, you know, in various places in the space, in the space station and so forth. So open source is sort of there, but it's not in the critical spaces right now.
And I think getting it so that we build confidence that it can go in those places is a function of being able to do the analysis that they expect of assist system level. Interesting. Does with embedded systems, now, there may not be millions of satellites that use the same chips, but like in iot kind of the other end of the spectrum, you know, it can be little, it can be millions of devices to have that embedded system in it.
What kind of complexity does that bring to how you think about also security Software? There's delivery. Yeah.
So there, there's, there's businesses and lots of startups forming about managing, you know, um, Goliath, which is one of the members of the, of the Zephyr project. And there's a few other members that are actually quite good about, um, talking about and having solutions here where they basically, you know, rope help you manage from a control point of, and you know, what, what, what versions of things are and which versions of the chips and how you update them and be consistent. So it's a business that's been formed and there's a lot of people that are interested in starting to go out that, you know, you have a whole fleet of trackers, you know, you're tracing, you know, you're tracking through your food supply chains or you're tracking through your vaccines.
You make sure they don't go above the temperature range as they're shipping out, so it doesn't invalidate them. These sorts of trackers are already out there and are being managed. And more and more of those are showing up.
We live in a world of sensors where we googleize it or not. We've got Lots of sensors out there, they're wonderful, uh, you know, but we need to be efficient with them. And, you know, there's ones that are basically powered by solar Mm-Hmm.
Solar powered trackers. And, you know, you see things like, you know, energy converters even see some things. I'm starting to see some things about passive powering because it's tipping that low that they can do the passive powering from vibrations and other things Mm-Hmm.
To actually power things. Interesting. So there's, there's lots of really cool applications in the, the deep embedded space.
Yes. That it's fun. Yeah.
It's cool. What's, What's the next problem you'd like to work on? Oh, I think the problem I've got of trying to get open source to, uh, work with all this, uh, safety critical infrastructure, I think is a good problem.
I think that one's gonna enough. Okay. And, and, you know, I worked with the SPDX community to make sure we can start to talk about hardware more efficiently.
Talked about virtual twins or digital twins more efficiently. Mm-Hmm. Um, and be able to pair up the hardware with the software.
And like, you know, you, and you know, quite frankly, hardware is composed of other hardwares composed of other hardware. Right. And, you know, can we describe a hardware supply chain with, with, uh, a common metadata format such that we can reason from, you know, this piece of software to this chip on this board, on this system and make the connection.
You know, I think being able to, when you need to make that connection, you know, when someone's, you know, the F FDA A is gonna be looking for things like this already we've seen the things and that critical infrastructure, like the energy sector is looking for this sort of stuff. So it's a good challenge. It'll keep me busy.
It's the big challenge. Do we need to redefine SBO m as system bill of materials? Yes.
So we cover any instance, whether it's it's only software, Whatever. No. What we need to basically re-look at the whole problem as a system problem, not just as a software problem.
Now the software bill of materials is shining the light on a, a part of the system that was opaque before. And there's work out there already for hardware build materials. People know how to do that.
The supply chain's been doing that for years. They've doing That a long Time. Yeah.
Right. But let's make sure we can figure a way that there's a common language so they can all talk to each other to know exactly which piece of software is, is deployed on which piece of hardware. And that people are someone, someone like, you know, an organization that's tracking all these devices is keeping in track about all to make sure that, oh, this, this set of the devices has this piece of firmware on it, and oh, and it's gonna need this security update.
And, but oh, these ones here are a more recent ship, therefore they're fine. You know, being able to get to that level of precision will help everyone. Very good.
Well, okay, I know you got a panel to go to, but folks wanna get involved. This is an interesting area. Okay.
How do they get ahold of you? Or get ahold of? Yeah, if at the projects they might wanna Be, um, they might wanna take a look at the ELISA project, if they care about Linux.
Um, they might wanna take a look at the Zephyr project if they're having that resource constrained considerations. And then, um, if they're interested in making sure we represent hardware properly, if they're interested in making sure we re services and some of the operational stuff properly, um, the SPDX project is always welcoming the community to come in and join us. And if you look up SPDX on our GitHub repo, uh, all our meetings are listed, all our mail lists are are there, and you can just basically self sign up.
So we try and make a very low, easy barrier to entry. Very Good. Sounds like you need help.
You're, you're welcome. Help, we always are very much welcoming. Help any of these projects very much welcome.
Help. Very expertise. Oh, it's nice to talk with you, fa good luck with your panel too.
Thank you very much. It's all about, um, we've been pre we've been moving the, um, preempt RT patches into the upstream and this has been work that's been happening for about eight years and it's almost finally done. So we're gonna be talking a little bit about that today.
Some Of those problems stick around for a while. Well, these, the hard problems take a long time to solve properly and we have to solve them properly. Yeah.
Otherwise, the solution doesn't stick well. Why solve 'em multiple times. Right.
That's what was happening. Can't do It. Right.
The first sign. Well, thanks again. Good luck with the panel.
Thank you very much. Enjoyed talking to you With the Linux Foundation. Another great conversation.
You know, it's, to me, it's fascinating, the, the melding of hardware and software and thinking about embedded systems, even though that's not my special thing. So many cool things going on there. So get a ball.
Many, many projects you can contribute to. Thanks Jake. Thank you.
We'll be back with more interviews and, um, Margaret stuff from the open, uh, open Software Summit. Oh yes, there we go. I don't know if I get that right every time, but, And we're also running embedded open source summit here in parallel.
Oh, you are? So there's lots of embedded people Are lots of parallel. Yeah.
Yeah. So you see they're two different T-shirts, even though behind you. Do you ever get the T-shirt with different ones on both sides?
'cause you're playing multiple roles, right? Yeah. Well I do play multiple roles.
I enjoy it. So that's great. Thank you so much.
Thank you again. You Okay? Alright.
com is the number one online destination for DevOps education and community building. com covers all aspects of DevOps, including DevOps, best practices and tools, DevOps culture, DevSecOps, business impact, continuous testing, continuous delivery and more. com has the largest collection of original DevOps content, featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Where the world meets DevOps, This is Textron tv.
Hi, I am, it's Ashley here at Atlassian T 24 talking about one of my most favorite topics around Trello. An a Trello user for, I dunno, close to a decade, maybe even a little bit longer. So it's great to be talking with, is it head of product for Trello?
That's right. Yep. Um, head of product for Trello.
My name. Pronounce Your name. Gura.
Gura. Thank You very much. Uh, very happy to be here.
Thanks for having me here, Mitch. It's Great. So I don't know if we have enough time to talk about all this stuff.
I'd love to talk about. Yeah. Um, how, how long have you been working with Trello or been here?
Uh, I've been on Trello for over three years. Okay. Yeah.
So for fourth year running? Yeah. Yeah.
Trello has been around for almost 13 years. It's an amazing product. Uh, has been around a long time.
Uh, we have had like over a hundred million people create a Trello account. Uh, it's kind of one of the most downloaded AppSec on app store, play store. So very ubiquitous used around the world in 20 languages.
Yeah. The nice thing is it's so easy, it's so approachable to get into. It's got kind of a low friction to start just doing a to-do list with my own workflow or my small team or scaling it up.
Yep. Yep. Absolutely.
And I, I, I think, uh, we all are used to a lot of pieces of software today. I mean, we live in SaaS, world software as a service. Uh, in a typical company, people may be using 50, a hundred different software applications, but typically we, when we are describing a typical company, people using a hundred applications, you're thinking about a worker.
Those, like a typical knowledge worker sitting at a desk sometimes with like two monitors and managing. It has To be the technical, like a tech worker or, or even, uh, like a very professional knowledge worker sitting at, at a desk with multiple screens and, uh, juggling between different AppSec. But we have, uh, users that are out there in the field, like, uh, people use Trello, uh, when they're on the go, like roofers standing on a roof and construction workers, they're using Trello on their phone to manage their workflow.
So it's not only a tool for knowledge workers, it's a tool for all workers in all kinds of workflows. Uh, I mean, I know, Mitch, you mentioned that you, uh, your kind of, uh, company uses Trello and you are all on the field and interviewing people on the go. Maybe you can tell us like how you use Trello in your organization.
Great. Great question. Yeah.
Um, well, everything, everything we do in, in, uh, Textron runs on Trello Mm-Hmm. In terms of workflow, um, used in a lot of different ways, but one of the primary ways is whenever a sales order comes in, Atlassian would like us to come and do this project with them, or be on a webinar or produce a spec, a special event for them, whatever it is. Um, usually when you engage with the customer, there's multiple things we're doing.
So that all breaks out into, um, cards that go onto different functional boards, team boards, and that could be anybody from the person who's planning an orchestrating a virtual event to a content piece that research might need to Yeah. Run. Or a webinar that we're producing or an interview someone signs up to, and to do an interview on Techstrong tv.
And then we all have our workflows inside of our board. Some of them common, some of unique to that Yep. Kind of work custom piece of content.
So it doesn't happen until it's in Trello in many cases for us, That, That, but you don't get there overnight too. You really kind of start with this is the, we're having trouble orchestrating this so many times and it's w repeatable, but it's just too complex to replete it reliably. And so let's figure out a way to automate it.
Yeah. One of the things I want to ask you about is my introduction with to Trello is because it was Paul's Kanban, right? It's a visual workflow.
That's right. Matter of fact, that's why I introduced it to, uh, the Textron. com is one of our biggest sites.
Yep. It's like, well, we're gonna talk about visual workflow, let's do with visual workflow. So worked with Trello.
Is that still true? Is that one of the, you know, one of the appealing factors of why Yeah. You wanna use Trello?
Absolutely. Absolutely. And, uh, I mean, I could say like, we, we are all, each one of us is different in terms of our work style and preferences.
And, and some people are very kind of, let's say linear, methodical, like they like a very structured workflow. And then some people are kind of more kind of right brain creative, or they're more special in terms of thinking about their work. Like, in their mind they're like, okay, there's something I need to do, and that's top left on my Trello board and something that I'm trying to get to by the end of this week.
And that's top left on my board. So they have that spatial organization and spatial memory, uh, and, and Trello is that tool. And, and it's like that, whether you use it on a computer or on your phone or you project it on a tv, it always has that visual spatial element to it.
And it's tactile. Like when you move a Trello card, uh, from one list to another list, you get that sense of spatial orientation. So that has been true for Trello for 13 years.
Uh, and, and we have continued to maintain that. Uh, it's, it's very responsive works, uh, on any device, uh, real time. And when people are collaborating, they're seeing the same thing.
Like, you could have, as you mentioned, a news organization where someone is on the ground in Europe and there's an editor in New York, and you are here doing a piece in Las Vegas, what happens? And everyone is seeing the same fellow board in real time and, and getting that real time update. So it, it, it's a very, very efficient, uh, product, very spatial and, and visual.
Now, since we are talking about visual, let me talk about something new in Trello. Okay, wonderful. And you'd say like, what could you do new in Trello?
How could it get any better? How could you make it better? Uh, well, I mean, people love Trello because it's visual and it's colorful.
So when we talk about color, it's like the Trello boards are colorful because you can upload your own image and colors and, and the whole kind of canvas is very beautiful and colorful. Well, Trello cards, uh, are also colorful because you can create card cover images, you can upload gifs and have motion and, and it's all beautiful. Well, the one thing which wasn't colorful in Trello, we just added color to that, and that's the Trello list or the columns.
So now the board, the card and the columns on the Kanban board are all colorful. And I mean, you would have guessed like Trello has been around for over a decade. Like, we have made it as colorful as we can, but no, there was still one more place.
And that was the columns and the list, uh, that we have added color to recently. And, uh, our users love that. Like, that's what they have been asking for from us, that, uh, the reason they come to Trello.
I mean, there are many to-do list type, uh, applications in the world. Uh, there's no dearth of them, but the reason, uh, everybody comes through Trello is because it's so easy to use. It's visual, spatial, tactile, and we are making it more visual, more colorful.
Uh, so that's, that's been our journey. And, uh, we like it that our users love it, and they tell each other about it. And, and it's been a wonderful journey for Trello.
Interesting. You, you would think, oh, adding color. Yeah, no big deal.
Right? Just add color. Why, why is that an important thing?
And what I would share is even like, gamification of our work, right? Right. So the, uh, the confetti, the confetti visual animation, you move something into the done column.
Yep. I've had more than one person say, oh, that's so cool that I just feel so good about my own. Yep, yep.
And, you know, it's, it's enjoying, yeah. It's not making the next tool, the next drudgery is making this tool not only helpful, but also it's fun to work with. Absolutely.
It's much rather than staring at a white column list spreadsheet Yep. That's, you know, 80 columns wide or Yep, yep. 8,000 columns.
Right. Some of it. Yeah.
Um, but having an environment where you enjoy working. That's Right. That's right.
Yeah. Absolutely. So our journey has been pretty much continue to keep Trello very accessible, user friendly, and we never wanna compromise that, uh, because that's what makes Trello so special and more visual and more colorful.
Um, the other thing which we can talk about is we are in the world of kind of generative AI and kind of making Trello. I Had the timer going, how long before we talk about generative ai? Exactly.
Now you made it under the wire, you're good. Yeah. Now is the time.
So, uh, something that we recently launched in Trello is, uh, uh, generative ai, where if you have a Trello card and you're typing something as a description, the generative AI can assist you with kind of, uh, adding more description to the card or adding more details to the card. Now, that's a use case that almost every application in the world has tried to kind of mimic in a way that, well, if you have to write some text, then can we, can we use generative AI to automatically write that text? Uh, one area where we, we feel like we can push the frontier in Trello, because Trello is very visual, is, uh, not only create like a description in a card, but really understand what is the user trying to accomplish.
So sometimes you get an email and it has a bunch of things for you to do, like, uh, a long email, lots of action items. And oftentimes what we'll do is we'll mark that email, snooze it, or send it to a Trello board, and we are like, okay, I'll come back to it later and, and read it again, and then figure out all the things I need to do. But generative AI can parse that email for all the action items, all the key things that can be done.
So that's one area we are working on where like, if you get an email, you get a Slack message, Microsoft Teams message, like, can Trello automatically parse that and create your workflow in Trello so you can have cards or checklists within the card based on what's the set of things that you need to do? So we, we are, we wanna make sure that generative AI is really helping people manage their workflow in a very, very efficient manner. And, uh, I mean, Trello is where people manage their work.
So If you want, I can send you a long list of Zaps, Zapier Automation, so you can say, Hey, we can do that. Absolutely. Absolutely.
I mean, we have had Trello users, uh, who have used Zapier, uh, for over a decade and created like, very interesting workflows in terms of connecting their calendar with Trello, Calen, uh, connecting their email and Slack and Microsoft team with Trello and, and any, uh, other kind of, uh, application, like if you're a salesperson using Salesforce, if you're an HR person using Workday. So all kinds of integrations can be built. Uh, but with generative ai, now we can do it in a more seamless manner, and we can extract meaning out of a large body of text.
So it's one thing to say like, let's create a Trello card. When you get an email, it's another thing to read that email. Understand that there are 10 subtasks that you need to do that's included in that email, and create a Trello checklist with those 10 subtasks.
So that's where generative AI is actually pushing the frontier of not only automating things by connecting different software tools, but finding meaning in, in every, uh, action item and then breaking it into Subparts. So it's an exciting era. And, uh, we are, I have a Feature request.
Go ahead. Yep. And I'm using Team or Slack or Zoom.
Yep. You know, now you can get recording software that will tell you here's the notes from the meeting, and that's usually it's a set of action items. That's right.
Guess what? We'd love to have that Absolutely. Print those cards for us.
Make That Absolutely, absolutely. Yeah. I mean, we, we get a lot of our action items from these meetings, so certainly, uh, and I mean, Atlassian has, uh, the Loom product that we have acquired, uh, last year.
And, uh, loom Tell folks what Loom is. Yeah. Yeah.
So Loom is an async video communication tool. So oftentimes, uh, and I know you'll be, uh, talking to the Loom team, uh, as well. So, And we use Loom also.
Oh, Excellent. Excellent. So Loom is an async video communication tool where, uh, oftentimes people are sending emails or Slack messages, but it's very hard to explain what exactly you, uh, you want to communicate, uh, only in text format.
So Loom is the video format in which you, you are almost sending a video postcard, uh, to your colleagues, coworkers, your customers partners, to explain your concepts, ideas in a more visual way. So if you have a bug in your product and you want to show what it looks like, you send a Loom video with that. If you want a feature, you show what you're looking for and expecting and send that, uh, to, uh, your team and explain that to them.
And, and Loom is a, is a new way of working. Uh, so we'll be working on more integrations between Loom and other Atlassian products. And, uh, I like your feature requests that if you get, uh, some action items coming out of a video, then uh, we can transcribe it, we can extract meaning out of it and, and then create Trello cards and the checklist in Trello cards based on that.
I have a long list of to-dos that I can send you that Perfect, perfect test data. Yeah. Um, you know, it's interesting, we use Loom for, um, like when we're rolling something new out, Hey, sales team, here's a new thing.
Here's how you do it in HubSpot, or, you know, CRM or whatever it might be. It's a great visual way of just three minute sort of, you know, yeah. YouTube ish kind of video, but built right into your workflow.
Absolutely. It's really great. Yeah.
Well, let's, so, you know, uh, Trello was acquired what, about seven years ago? That's right. Right?
Yep. And of course, when things get acquired, you wonder, is it gonna become Atlassian eyes and what's it gonna, it gonna be able to recognize it in two years? Or is it gonna gonna hold true to what made the product so great that they acquired it?
Yeah. And, and certainly Atlassian has kinda let Trello be Trello if, Right, right. Yep, yep.
But there's also so much more we could probably do if there's some connected more connected tissue between Trello and J or Con, whatever the other Absolutely. So that is a big windup to say, I think you've got some announcements, right? Yeah.
So, uh, like one thing which which you highlighted is that, uh, Trello has been part of Atlassian for seven years, and it has, uh, kind of kept its Trello or its uniqueness in a way, because Atlassian values that aspect of Trello. Uh, a lot of times acquisitions are not successful, products fizzle out, but this has been a successful acquisition for Atlassian. As I mentioned, uh, we have had over a hundred million users that have created a Trello account.
So, uh, Trello has its own unique place in that sense that people use Trello, uh, in a complimentary way to other Atlassian products. Now, one thing which we have been, uh, kind of focusing on is, uh, we want to help companies standardize on a single, uh, way of working. And we want to describe that as an Atlassian system of work.
So there's kind of some basic, uh, platform level capabilities that every company needs. Like they need to be able to create user accounts, secure them, analytics, reporting, uh, so that's an Atlassian level kind of, uh, platform level capability. Then every user in a company, every employee in a company needs to have, uh, a project management tool, knowledge management, I talked about video communication, so loom type capabilities.
Uh, and then there are specialized capabilities, like if you are in customer service, IT service, you have a service solution. If you're in software development, you have, uh, software development capabilities. So we are trying to explain this way of working as the Atlassian system of work.
And Trello kind of nicely fits into the Atlassian system of work, where we want Jira to be the project management tool for the entire company. And we want Trello to be more around individual productivity, personal productivity. So like every user has, uh, lots of work to do and many, many different tools.
Uh, so it's not only about project management because you get emails and slacks and calendar notifications, and you have things in Jira and Salesforce and so on. So Trello can be more of your kind of personal assistant to plan and, uh, plan your work and plan your day. Uh, and Jira can be the project management solution, uh, for your team.
So, uh, as we have announced at this conference, uh, we have made a lot of investment in improving Jira and making it accessible to not just tech, uh, workers and developers, but also, uh, all the creative, uh, people and non-technical people in a company. So we want, uh, JIRA to be that single platform where tech and non-tech teams, so basically the entire company can collaborate together on projects. Uh, and then we have Jira aligned, which can connect the projects to the company level strategy.
Mm-Hmm. So we are trying to standardize on Jira project management, and then Jira for, uh, connecting projects through the company level strategy. And Trello is more for, uh, helping each individual be more productive.
Okay. Yeah. So it sounds like, yeah, Trello, DNA is kind of transferred into Jira, if you will, in some ways.
Absolutely. It's, it's been kind of nice, uh, kind of, uh, uh, helping each product get the best of it and learn from each other. So, uh, Trello has learned a lot, and Jira has learned a lot.
Uh, JIRA has gotten, uh, a lot more visual, uh, as Trello teams and Jira teams have worked together. So if you have used Jira work management, uh, which is now, uh, part of, uh, the Jira experience, and in that we have board backgrounds, uh, we are working on, uh, card cover images, so we, we wanna make sure that project management, uh, uh, brings the best of the visual aspect of Trello. So Jira has gotten a lot more visual, uh, a lot more accessible.
Uh, it's much more mobile friendly. Uh, so, uh, that's been a, a great journey for Atlassian to continue to evolve Jira and make it, uh, useful for all employees in a company and continuing to evolve Trello, uh, for where Trello is uniquely different and complementary to Jira. Okay.
Good. Yeah. Well, how do you, how do you see this, um, kind of the progression path for maybe some customers are only using Trello, not using Jira yet.
Sure. What's that look like? Do they, are some things going away in Trello that now are being, so you need to be in Jira to do that, or kind of do it in me either environment?
How does, how do you think that works? Sure. Uh, so, uh, JIRA is actually used in, in most companies around the world now, there are a few use cases where you could say that, uh, companies were only using Trello, uh, from, uh, freelancer solo entrepreneurs, small businesses, uh, where, uh, uh, they were not using Jira because, uh, traditionally, like they didn't, did not have, uh, a tech type of workflow.
So those use cases are relatively simple. Uh, and I mean, either it's like one person or a team of two or three people, and they're just collaborating. And Trello is, uh, very user friendly for those type of use cases, and that'll remain.
So we will continue to, uh, uh, refine Trello and make Trello useful and accessible, uh, for those use cases. Uh, for typically, uh, a bigger team, a more structured team, uh, Trello is not the tool for project management. And now we know a lot of companies use Trello, uh, try to use Trello for, uh, big project.
Uh, but we believe Jira is a better solution for managing and coordinating a big project. And that's why we are helping our customers move to Jira for managing big, large scale projects. And, and in most cases, they're already using Jira, because Jira has been pretty much, uh, present in all organizations, uh, around the world.
Uh, JIRA has been around for almost 20 years that It has. Yeah, yeah. Yeah.
It's kind of tough to do a critical path Yep. Analysis on Trello. Yep.
Which, you know, is that the right tool to be doing that and adding, right. Yep. Yeah.
Yep. Yeah, no, I, I mean, we believe it's a very complimentary use case where, uh, every person has a project management need, but every person also needs to, uh, plan their own work, organize their own work, and Trello is a way to plan your own work. Uh, and Jira is a way to manage projects and coordinate, uh, dependencies with other teams.
Okay. Yeah. Good.
Yeah. Is, is Trello changing a lot, or is it more Jira changing to be able to take on work in some of the ways that Trello Works? Right, right.
No, I, I mean, we could start by saying that the world is changing a lot. Of course. Yeah.
That's why I'm curious. Hopefully things are always changing, Evolving. Absolutely.
Absolutely. And as the world is changing and evolving, uh, we as software people, uh, that are building this software, we have to keep on evolving the software too. So some aspects of Jira, uh, which make Jira so unique will continue to be there.
Like people, like some sort of, uh, format structure. They wanna standardize workflows in a company, they wanna automate workflows, uh, and Jira is really, really good at that. So we want to preserve that and build other things on top of it.
Uh, on the other hand, Trello was very easy to use. It was very visual, very spatial. We want to preserve that.
So there are aspects of Trello, which we will preserve, but we will also continue to add more things to it. I mean, we just talked about generative ai. So if you're getting an email and you want to track your action items through that, like, that's a very typical Trello use case where you want some sort of, uh, extracting meaning out of your email, extracting meaning out of your, uh, slack message or calendar appointment, or your Salesforce action items, or as you mentioned, a, a Zoom meeting action items.
And those things can easily go on, on your Trello board or on your Trello to do items. Very good. Yeah.
Great. Any other announcements that we're touching on today? Or, or that's enough?
That's all I'm happening. Well, We've covered a lot. Yeah.
I was gonna say, and I'll just kind of close off by saying that, uh, Trello was the most visual and colorful tool, and we have added even more color to Trello, more color. So, uh, yeah, there are beautiful card, uh, covers. There are board backgrounds and board colors, and now we have, uh, list colors.
So you can design your own magical workflow in the visual, colorful way that Trello has been. And it's, it's even more colorful, and you can use it on your phone, Android, iOS, you can use it on, on web. And then some of our customers just project Trello boards on a big screen, uh, on, on a wall.
And that Too. We did that in one of our test labs. Yep.
For that Same kind of thing. Yep. So, AV, it's been, uh, fantastic talking with you.
Congratulations on the announcements and continued evolution of Trello and your Great, thank you. Appreciate you stopping by. Thank you.
Thank you for having us. All right. You haven't checked out Trello yet.
Be sure. And, uh, do that, of course. Along with Jira.
So we will be back with another great interview in just a moment. Absolutely. Thank you.
This is Textron tv. Hey guys, thanks for the throw. We're here with Gary Penolver, who's CTO for Quad Orbis, and we're talking about, um, how to get the budget kind of justified.
There's a lot of pressure these days on cybersecurity costs, and yet the threats keep rising, so we're kind of in a rock and a hard place. So Gary's gonna walk us through how to maybe have those conversations. Gary, welcome to show.
Thanks for having me. And, uh, good to chat. How do security folks kind of have a conversation about ROI?
Because in a lot of cases, we're still trying to improve the proverbial negative, right? So it's, something didn't happen, but we spent money, but how do we know what that costs? And we have to explain that to CIOs and CFOs who are asking these questions about, are we any more or less secure than we were?
But it's hard to quantify. So how do we get there? That's quite a big question, but yeah, it's, um, it's, it is exactly what you said.
It's that, yeah, there's, there's an element of, um, uh, justifying that spent, um, which I think, you know, a lot of organizations really struggle with, um, front, understandably, because if you're doing a good job, then how do you know if it's just by pure luck or, or by, by the volume of what you've spent? Um, I think kind of interestingly, you know, in that setting, what we've seen in the last, um, 18 months or so is, you know, with a slight economic downturn, um, actually, you know, even CFOs being a bit more, um, challenging in terms of, um, you know, some of the spend that, that, that goes on in this area. I mean, you know, sort of pre, pre 18 months ago, I think it would've been a brave CFO that would've challenge the spend on cyber, but actually certainly a lot more, a lot more challenging in that space.
And I think it's, it's kind of a combination of the more savvy, um, um, in terms of, um, uh, uh, challenging, but equally the, the, um, the fact that it, they, they have gotta justify the spend as well. Um, and it, and it, and it is hard to put that number on it. Um, and I think, you know, part of the problem is that CIOs CISO aren't always that great at kinda explaining some of, uh, the reasons why they wanna do certain things.
Um, you know, they kind of very much focus on the technical aspects versus the, you know, the, the tangible business aspects of that thing. So it's, it is a challenge definitely, It feels like to me as well, that, um, we've been spending money on cybersecurity platforms and tools for years now, and spending more doesn't always equate to better. So is part of this exercise to figure out how to maybe rationalize some of the stuff that we have out there to spend less, but be better To recalibrate?
Yeah, no, I, I, I'd agree with that sentiment. I think I, I forget what the stat is, but I think it's something like most, most organiz, most enterprises have got between 20 and 30 security tools, um, something in that kind of region. And that's, that is a lot of spend, right, as you say.
And that is, that isn't necessarily helping in a lot of cases. I think if you look at, if you look at not all, but a lot of large breaches, a lot of the kinda stuff that makes it to the press, um, it's actually not doing the basics properly. Um, so if you look at, you know, good sort of good hygiene, you look at the United Health, um, um, incident that I think affected, I understand a lot of Americans, the majority of Americans in some, some fashion over the last few months, um, that was down to lack of multifactor authentication just on a, on a, on a system.
Um, so it's again, sort of those basics that, that everybody knows what they are, um, aren't always focused on, you know, organizations don't necessarily, um, have the, the visibility and assurance of those basic controls. They're kind of focused on the shiny new tech that claims it can solve, solve everything, I think, I think that is, there is a recalibration that needs to happen in that respect. I'd agree.
Speaking of shiny new tech, we have AI everywhere. Is this gonna force that recalibration? Because there's just a lot of things that will be automated, there'll be things that we couldn't do before.
So is this kind of one of those seminal moments? It's obviously very cool and buzzy, you know, AI at the moment, and, uh, agreed. It's, um, and I think, you know, there's a lot of products that are throwing AI against the problem and hoping some of it sticks, and clearly some of it will, right?
Yeah. Some of it's gonna stick. Um, the trouble is, is that it'll probably, you, you'll probably get some of the lands on both sides of the coin in the sense of, you know, both attackers and defenders can, can leverage some of that ai.
You know, if you, if you look at kind of phishing, for example, um, you know, obviously one of the things that most people are told to look out for in regards to phishing is, um, the tone, the language, you know, spelling mistakes, et cetera, et cetera. Well, you know, just running these, you know, what, what should our attackers do these days? Running them through a, you know, a chat GPT or similar actually results in some pretty decent English sounding and convi more convincing sounding, uh, phishing emails.
So it kind of works, it works in both sides, unfortunately. But yes, it should help sort of that, that kind of speed of response aspect and, um, uh, you know, that kind of, uh, mean time to detect, mean time to, to, to, to, to respond, et cetera. But, but equally it's gonna help the attackers too.
Mm-Hmm. Well, speaking of helping the attackers, it feels like we're trying to have a conversation about being smarter with the budget at a time when the attacks themselves, as you pointed out, are increasing in both sophistication and for that matter volume. So sometimes I feel like we're always kind of evaluating our spending against, you know, yesterday's war instead of tomorrow's war.
Yeah. Yeah, I think so. I think, um, and as you touched upon right at the very beginning, I think sort of a lot of organizations struggle to defend those budgets.
So they, I think, which, you know, what, what probably doesn't help in, in some respects is, um, the lack of really solid information out there for a lot of enterprises to be able to help benchmark themselves in terms of, are we spending too little, too much, you know, for our industry? Um, I think that doesn't help in terms of some of that justification of why, you know, that the, where you started at the very beginning, really the kind of CIO, um, uh, CFO kind of conversations. Um, but you're absolutely right.
You know, so much of the security space is selling on that, that futures that kind of, you know, the, the, the, the, the a PT, the advanced persistent threat, kind of the, the, you know, the, the nation state, well nation states are going to attack lots of organizations clearly. But, um, as I keep coming back to it's, those, doing those basics properly, I think is what, what a lot of organizations struggle to do. Um, um, and if they just focused on those, I think actually they would have a, a much better chance of, of, um, securing themselves against, you know, 90% of the tax act.
We have, uh, been dealing with this shortage of cybersecurity expertise for as long as anybody can remember, and it seems like we're pushing more responsibility for security operations over to the IT team. We're deputizing developers making them more responsible. Um, is that working or is there a new demarcation between who's responsible for certain tasks versus others?
What we're certainly seeing in, in, in our space is, is people adopting more automation. Um, so even quite simple automation in terms of, you know, collecting, um, uh, um, control information. So, you know, if you think of the examples you gave their own security operations teams, et cetera, they're, they're being, they've got responsibilities to ensure that they operate first line controls for things like, um, have we got antivirus on all of our, on all our desktops, you know, quite a key control, for example.
Um, and they, they, they've got to, uh, you know, keep on top of that in first instance, but equally demonstrate that kind of assurance piece to, to the wider organization. And equally, again, that kind of upwards reporting, um, that helps justify why we're spending on certain areas and why we need, you know, some, um, uh, you know, additional drive to try and, you know, increase our coverage, for example, um, of, of security controls. Um, so there's a bigger burden on them to, to deliver those kind of things.
But automation really does help, you know, to kind of get that kind of a visibility in the first place and reduce that manual burden of some of those responsibilities so that those kind of people that you mentioned can actually focus on the more rewarding pe the your work for themselves, actually, the, the real risks that that, that are servicing rather than the, you know, are we covered type questions? How should security people be talking to the CFO and the CIO? Because for years they were talking about, well, we need to have a seat at the C level and the board, and we need to talk to these people.
And now many of them got in there and are surprised to discover that nobody knows what they're talking about. So how do we have that conversation? I think, I think in most cases, there's, it's a combination of, um, education for, for the board, um, and helping them understand the, you know, the macro level, um, aspects of it.
Um, and equally the, the, the CISO and CIOs to be less technical in terms of the way they talk about some of these problems and the, the, you know, the, the challenges they face, the things that need to be the remediated. I think it's the combination of those two things that I think are, that are, um, that needs to be addressed, you know, that need to be worked on In general, do you think that maybe our security spending is still somewhat misaligned? And I'm asking the question because security people will allocate budget to things that they control, and since they have more control over the network edge, you'll see a lot more firewalls.
And yet, application security has always been something of the redheaded stepchild because the security team thought the development team was doing something about it, and then the development team thought the security people were doing something about it, and nobody allocated anything for anything. Um, so are we just kind of fundamentally misaligned? I think there's, there's probably an aspect of that, and obviously movements like DevOps and DevSecOps have tried to address some of those, some of those aspects.
Um, but yeah, I think it's a, it's quite a common problem that, that, um, that the organizations have faced is that, that, as you said, that demarcation, that kind of, who's responsible for which part? Um, and I think the push to the cloud, obviously, you know, that kind of agility, that kind of, you know, that kind of DevOps mentality of re release faster, you know, um, um, and trying to automate those checks and balances along the way, I think, again, starts to address some of those. But that doesn't, doesn't apply to all industries, obviously.
It doesn't apply to all, all scenarios. Do you think we'll ever start talking about security at the front of the conversation instead of chasing after what's ever happened? Because it seems like every morning somebody walks in and the attack surface has expanded yet again because somebody did some cool and interesting new thing without actually thinking through what the security implications are.
Yeah, I mean, it's, it's an interesting one, isn't it, because you got, you've got, um, again, uh, that's probably sound like a broken rack, but again, all those new and cool things that come out, they're quite often similar kind of methods of attack. There's kind of similar kind of things that are happening. And again, if those, you know, basic hygienes being done properly, um, and you get some good visibility of it, I think that really does help to address, you know, address a lot of those, even the new things that come out.
Um, um, you know, um, tools are always, so techniques are always adapting, but the tools and the, the defense mechanisms will always be catching up to, um, I just think the, the math, the, you know, the approaches that people take, you know, they need to focus on that kind of, that, that, you know, the good hygiene piece as I mentioned. What's your best advice then, to security folks? Because, you know, it's always amazed me is given the challenges they faced, they are by and large eternal optimists, they always think that somehow or other there's gonna be a different outcome, and yet contrary to all the evidence, they still believe.
So, um, is that just the nature of the person required for this job, or is there something else at work here Ask, you've, you've obviously spoken to different security people to me than, you know, a lot of 'em are of 'em are definitely pessimists. I think, uh, they're definitely glass half, half empty, but, but, um, it is, I think it is in the nature, isn't it. I think you, you, you know, the, the kind of that kind of constantly playing catch up, trying to, to defend against things is, isn't the nature of the job, unfortunately.
You know, it's, um, and it probably does take a certain type of mentality to do that. You're absolutely right. So, um, there's a lot of burnout in the security space, obviously, in the high levels of turnover.
Is there something to be done about that, or is that just the nature of the beast? I think I, again, there's, there's been some interesting trends. Again, I think in terms of, um, you know, the kind of economic downturn, as I mentioned over the last 18 months, which there's probably, um, de powered a lot of CISO in a lot of ways.
So some of that decision making about the spend and things like that, that were mentioned, it's kind of taken away from them because as I say, the budgets just just cut. Um, and, um, I think that that in itself probably puts quite a large amount of additional pressure than they were already facing on, on top of those, those types of, um, you know, the defendants, the people that are trying to look after the organization. Um, so yeah, I think there is, um, there is, there is a lot of that in the, in the industry.
Um, but, um, in terms of what can be done about it, I think it's, uh, I think it's sort of, um, again, I think it's the nature of the job, I think, isn't it? You know, it's, um, you know, there's obviously certain things that can be done from a, from a wellbeing perspective, but I think unfortunately there is a lot of pressure that goes with defending and, uh, and, and being on the back foot probably a all the time, This is a nascent trend, but it seems like at least I'm seeing a lot more newly appointed CIOs who used to be the ciso. And so are we bringing these two things together?
Yeah, it's interesting, isn't it, how, um, you know, sort of the shift in the, in the kind of, in that kind of exec and, uh, c-suite, um, area. Um, and as I mentioned before, you know, I think the, even the CFO is becoming a lot more savvy and a lot of organizations to, um, some of the spend, um, and the justification that goes with some of these things on, on security tools in particular, and it spend, um, so I think that is, there is a general, um, uh, uplift going on in terms of the education and the kind of the awareness within, within that, well, that space. I haven't seen that many CISO become CIOs personally.
Um, um, but, um, I'm sure it happens. Yeah. So you are now granted one wish for cybersecurity.
You can just magically transform things overnight. What's that one thing that you would do that kind of, would make everybody's life of just that much more tenable? Um, well, selfishly, obviously, I think, yeah, in terms of what, what we, what we do in this space in terms of how people to look at, um, making sure that, that the things they thought they had in place from a controls perspective, and when we say controls, we mean, you know, anything that might be there for, um, uh, compliance, but equally might be there for, um, you know, protecting against ransomware or, or something like this.
Um, some, some sort of key control, making sure that those are in what you think is in place that stays in place and actually, you know, is, is continually performing the way that you want it to be, including those basic hygiene controls that we mentioned. So again, taking, you know, automating as much of that as possible and helping organizations to, to say focus on the more, the more value piece, the more interesting parts, parts of their job, or actually what comes out of all this, what are the risks that we need to actually address? I think that's the, that's, that's the magic wand.
I'd love to, to help people to work on more meaningful stuff, um, and actually have confidence that the basics are being done properly, and when they're not, be alerted to them straight away so they can actually fix them rather than finding out when they've been breached or as such. All right, folks. Well, it doesn't look like things are gonna get any easier anytime soon, but, so maybe just maybe the most important attribute of all is plain old fortitude.
Hey, Gary, thanks for being on the show. Yeah, Well, thanks for your time. All right.
We're speaking And back to you guys in the studio. This is Textron tv. Hey guys, thanks for the throw.
We're here with Glenn Brico as Vice President of Marketing for Harness, and we're talking about the recent raising of an additional $150 million in funding by the company at a time when, while there's more changes going on in the land of DevOps and CI/CD than a recent memory. Hey, Glenn, welcome to the show. Hey, thanks Mike.
Thanks for having me. Normally, of course, you know, the folks on, uh, wall Street and venture capitalists are all watching this space pretty carefully, but if I'm running a DevOps environment or I'm a senior level IT executive, what should I be taken away from this raising of $150 million? What does it means to them, and what are your plans for it?
The landscape is changing quite a bit, actually. Um, going back to about, you know, let's say 10, 12 years ago when, um, uh, the DevOps space really started and took off, uh, to really support the new, uh, modern software delivery, uh, practices, the, uh, landscape has changed quite a bit, right? So the original version of DevOps, uh, that we were promised was, um, um, uh, did not pan out as planned, right?
A lot of the point solutions that we've seen on the market, and we've kind of like seen 'em come and go, uh, required a lot of sort of maintenance and, um, uh, sort of duct tape in and integrating things together. Uh, and, uh, the original intent for a lot of those solutions was to really improve developer productivity. And reality is, when you're spending most of your time integrating and connecting things together, you're actually, uh, losing a lot of the gains that you're hoping to, uh, to achieve.
And so the landscape of changing in a way where, uh, the platform solutions are really the leading story, right? The platform solutions have an advantage of having best in class, um, modules like we do at cars, uh, that are highly interoperable, work really well together, and at the same time integrate with a lot of other solutions that are out there in the ecosystem. And so I think the funding announcement is a clear nod to, uh, our progress as a company, uh, that the sort of like big market that we're going after, the problem that we're trying to solve, and just the company performance overall, uh, since inception of the business.
Do you think that the overall size of what we would call the DevOps marketplace continues to grow? Or is it more we've kind of established within, I don't know, the Fortune 5,000 that these are the folks who are gonna be able to execute on this level of engineering? I mean, are, are we getting to a point where the platforms are simpler and more people can play?
Um, that's a, you know, I'd say that's a fair statement. The reality is, look, harness is going after what we're calling a trillion dollar problem, right? Uh, there are roughly 30 million developers in the world, you know, average, uh, uh, salary for a developer is, you know, give or take a hundred k, uh, per year.
And the reality is roughly 52, 40 to 50% of developer time right now is spent on what we're calling toil, which is essentially mundane repetitive tasks, integration tasks, um, that are not actually producing code. And so if you can achieve, you know, a gain of, you know, 10, 20, 30%, right? Like we've seen in a lot of our customers, you're actually recouping a material amount of developer time, um, uh, back towards actual, um, uh, productive code creating activity.
Um, and then there's also an issue of, uh, developer experience, which is another problem that we're really going after, uh, that prevents developer burnout, attrition, uh, and just overall sort of, uh, satisfaction with their job. And again, the whole point is, um, you know, this isn't just a, uh, a software industry problem. This is a world problem.
Most of the innovation in the world today comes from software. And, um, um, you know, being able to accelerate that, create efficiency, create increased productivity, is really helping the world at large, uh, as opposed to just, you know, uh, uh, uh, helping the company's bottom line, which we're also doing, How easy is it for somebody to switch if they have a legacy platform that they've been kinda stitching together and nursing all these years, and now suddenly there is this modern platform alternative, um, you know, and I are feasibly do that, or how, or is that just too big a heavy lift for some organizations? Probably.
We've actually made it in incre incredibly easy, right? We've created, um, a migration path, automated migration path from most of the, uh, open source solutions, other, uh, point solutions and even other platforms in the market. Uh, so it's actually incredibly easy.
It's a very low lift. Uh, we, a very strong, uh, uh, technical team here, solution architect team that helps, uh, the customers through, you know, let's say like the last, you know, five to 10% of their migration if needed. Uh, and to your earlier point about, you know, large companies adopting platforms like this, we're actually seeing an increasing, um, number of, uh, mid-market size companies, or even early stage startups who want to get it right from the get go so that they're not dealing the pain with the pain, you know, three, four years from now when they're actually lar running on a larger scale.
Are we at some sort of seminal moment here in terms of picking our platforms for DevOps? Because of the rise of ai? We're starting to see all this, uh, developers are using tools to write more code than ever.
The pace at which we may be building applications is starting to increase. I don't feel like the DevOps side of the house has exactly the same level of, uh, AI capability as the developers do. So where are we?
You know, it's interesting you say that. So, you know, I'll, I'll address the two points separately. So in terms of appetite for platforms, uh, a couple weeks ago we released, um, uh, our inaugural state of developer experience report.
And one thing that came where we went out and we surveyed, um, uh, roughly 500 practitioners and, uh, engineering leaders, uh, in, uh, north America. And one of the themes, one of the main themes that came across very clearly is that, um, uh, in increasing numbers, executives in particular, uh, technology executives, engineering executives, are very much leading toward the, uh, platform, uh, path to again, kind of like get ahead and address, uh, get ahead of and address, uh, some of these inefficiencies that they're seeing in, you know, their past established processes. That's kind of part one, uh, on the AI front.
Um, you know, I think that AI sort of like has been the theme of the day, uh, across many industries. Um, you know, engineering and DevOps included. We at Harness took a very practical and pragmatic, um, approach to how we're leveraging ai, uh, in our platform.
You know, there's a stat that's slowed now there, the, like, a very high number of AI projects in a lot of companies and AI initiatives doesn't actually pan out and lead to productivity, right? And so, rather than going after, uh, sort of like some ephemeral AI idea, we've actually practically integrated AI into our platform since day one. So practical features like, uh, code rollbacks identifying about code, um, code creation to sort of, uh, eliminate a lot of the mundane and repetitive tasks, uh, or scripting that the developers have to do.
All of that is innately built into our platform, right? Uh, our cost management solution, for example, has AI that identifies, uh, is powered by AI that identifies, um, uh, sort of an efficiencies, um, um, uh, you know, instances that are sort of like, uh, left out to die high and then, uh, you know, collect spend, uh, and accumulate spend that's costing the company a lot of money. Uh, we're able to identify those, uh, auto stop them, automatically shut 'em down, uh, and, uh, recoup a large number of, uh, budgets that right now is kind of, sort of, uh, going to waste.
And so, yeah, for us, AI is, uh, again, like at the very foundation of our platform. And, um, you know, we're, we're continuing to invest in fact, uh, you know, a a a lot of the funding that we just, uh, uh, uh, uh, secured is actually gonna go into expanding and building on more, uh, AI initiatives. But again, we took a very practical approach and making sure that, um, our customers are getting the most value, uh, out of their investment by virtue of leveraging AI and spending, again, less manual, um, investing less manual effort into, um, uh, making their developer teams productive.
On a separate note, we seem to be experiencing something of, uh, existential crisis in the land of open source. So a lot of folks are trying to figure out how their business models should evolve, and there's consortiums that are leading things. And how does Harness kind of view this whole space?
'cause I know you have an open source platform, but what is the best way to kind of engage everybody and still make some money for somebody? Absolutely. Uh, harness has always been, uh, a huge proponent of the open source space.
Uh, we're involved in a number of, um, uh, open source projects like, uh, Litus chaos, like tofu, uh, uh, just to name a few. Uh, reality is, is that at some point, you know, folks are sort of like, uh, evaluating the dollars and cents, right? Whether it makes sense, um, to continue with their open source, uh, approach, or whether they need specific enterprise level features, large scale features for scalability, um, to, um, uh, you know, to really sort of, uh, take their, um, software delivery life, so cycle to the next level.
Um, and so we're seeing a lot more customers kind of like, to your point, go back and evaluate where they are with their process. And, um, uh, a lot of customers are starting to make the choice to, uh, move over to a platform and again, recoup a lot of the, uh, manual effort and toil that's introduced by having to like stitch different things together. Having said that, our platform is, uh, highly interoperable with, again, point solutions in the market with, um, uh, with a lot of open source solutions in the market, right?
Some companies have a lot of time and effort and invested, and they feel like they have their process dialed in. Uh, we make it very easy to integrate. We make it very easy to adopt not just the entire harness platform, um, but our, you know, customers can get started with very specific modules, all of which are best in class modules, um, to start in their join journey to, uh, efficiency innovation.
We've used the word platform, uh, more than a few times here, and we've seen the rise of platform engineering. How do you think this will play out? Because some folks are like, well, this is the revenge of centralized it, and we created DevOps to get out from underneath that in the first place.
But other folks are saying, to your point, uh, we're inefficient. Things don't scale as well as they should, and there's a lot of duct tape. So how do I get to the middle of this conversation?
You know, a lot of companies today are really leaning in and figuring out, um, what is the best process and what are some of the best practices for their individual teams and lines of business. And that's actually the beauty of our platform, is that we're able to operate in, you know, a highly controlled, uh, centralized level, um, especially in, you know, some of the regulated industries, uh, like financial services, you know, a lot of our customers in the financial services industry. And, uh, um, but at the same time allow enough customization and flexibility, uh, for lines of business and individual, uh, engineering teams to do what's best for their flow and their process, but still, um, be able to deliver the level of, um, uh, governance, security, uh, and, uh, uh, productivity across the board.
And you mentioned security, and again, it seems like there's a debate here about where to shift the responsibility left towards. Is it all the way to the developer or is it somewhere between the developer and the security team? I feel like we're struggling for balance yet again.
Yeah, probably. And so this is where, you know, on our, uh, um, uh, security test and orchestration solution help, uh, comes in and a lot of our customers are starting to adopt it on top of their CI/CD um, uh, pipeline design. Um, because the reality is, you know, again, developers wanna write code, right?
They don't want to go and, uh, have to manually run a bunch of scans and tech, uh, uh, and checks with a bunch of different disparate, um, uh, security, uh, solutions out there. And so the way that we've solved the problem is we automatically integrate with over 40 scanners, security scanners out there, um, that are essentially running across the entire, um, software creation, software testing, software delivery process. And so, again, the, the goal and the mission of our company is to offload as much of this manual toil and, uh, uh, uh, manual task, manual intervention that takes away from what developers love to do, which is to write quality code.
All right, folks, while you're heard in here, there's been multiple phases of DevOps over the years, and unlike this time, we didn't recognize those phases till after they were well started. This one, we seem to be right on time, and we're all on the same page. Hey, Glenn, thanks for being on the show.
Hey, thanks for rallying Mike. All right, and back to you guys in studio.