Techstrong TV November 10, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Platform engineering on the eve of CubeCon. We'll be back in a minute. Hello everybody, and welcome to the latest edition of a Textron gang.
We're got a awesome lineup as usual. We got Gina Rosenthal, Jack Poller, Wiki, Wang, Andy, man, and we're gonna have a conversation about a lot of different things today, all of which are top of mind for folks. But as I mentioned early on, we are at the first day, or at least the pre-first day of CubeCon, there's gonna be a lot of folks hanging out in Atlanta all week long.
And today there is this platform engineering session going on, which apparently is jam packed. 0, which is essentially all about how AI will be applied to platform engineering. But Gina, I know you looked at this article, and I know you've kind of talked about with this in the past, but I'd love to get your take a little bit on how real is platform engineering in your mind?
What is this thing? 'cause it's a little still, shall we say, amorphous? Well, I think platform engineering is a good idea.
And I think this article, there were, uh, there were some very interesting, uh, there's a very interesting section about from scripts to systems. So platform engineering is this idea where everything can be run from code and you can build your, ultimately the hope and dream is your ops and your development teams are gonna work together because they have this platform that the engineers can just, um, say what they want their test system to look like or what they want their development system to look like. And so instead of doing it on their laptops or some system under their desk, it's all being cooled with real world, real world scenarios and the little test beds or being built with, like, it's gonna look in production and they go crazy.
Then they check it into the, to the, um, the CI systems. And then everything just works as it should just by itself. And the, the premise of this idea is that we've gone from scripts back in the old ancient days when I was assistant man and we're gonna now get to this AI native intelligent insight that's gonna be step three.
And I, the, the, the, the problem with this article with me was, it just kind of didn't give a lot of examples of how that works and what's going on. That was the first problem I had. I love the idea of thinking about, you know, automation first, that everything should be turned into code.
And that can, and I think that is a fa fabulous idea. That is not a new idea. That is something we were, I was doing back when I was assistant man for Soliris and Red Hat.
We did kickstart and jumpstart scripts and with some arcane, horribly hard to understand language and you just hoped nothing in the, um, hardware side changed too much that you'd have to go back into that language and, and fill it out. Now you have all of these great ways to develop these scripts. You've got all sorts of great systems.
You've got companies that are doing infrastructure of code and doing the hard work of figuring out the, the hardware intricacies for you so that you can have this continuously, um, updated system. So they think we're at the self-service stage, which is step two and standardization, which that's the hard part. That is the super hard part, especially if you're dealing with bare metal or you're dealing with a cloud that might decide to change something out of the blue on you and, and mess all your systems up.
Part I really had a problem with though was the AI native, what are we calling ai? I mean, this is like an AI thing to me more than a platform engineering thing. What is ai?
Because the things that we need to look for drift in scripts that we need to help, uh, have, have a way to inventory all the servers you have available, or VMs you have available already you're working with. Um, and to see where the problems are. That's, if it's anything, it's what they call narrow ai, which is what we've always called machine learning and deep learning.
So it's not, we're not looking at some brand new thing that's gonna automatically learn and do all the things and put the icing on a cake once that happens. If you've never had to deal with the intricacies of hardware, even on a cloud, the differences between things and software versions, um, then you, how do you learn where's our next gen coming from? How are they gonna ever know how to do things if we don't remember that all this changes?
That's what makes it really hard. And while it would be great to say AI does it, I don't think you, I don't think the author really maybe thought about what ai, I would love to have seen some examples of what she thought that was. So that was my thought.
But I, I love the idea of it because it sucked doing it the old way. So I'm hoping it's getting better for people. You know, Gina, one thing you mentioned was, you know, arcane languages.
And I think the, the premise and promise of LLM integration, whether you call that native or not, is the ability to put a natural language interface on, uh, what we're doing with computer configurations and, you know, the, the infrastructure configuration, the ability for us to be able to say, Hey, I want this server to have this many instances, and to be able to talk to that machine in English language is a very useful, uh, capability. And I think that will help us in the long run. Getting there is the really challenging part, and I think that's your right to, to sort of raise that is how do we do that and what does that really look Like?
Yeah. And is This just an elaborate effort to get rid of scripts? I mean, are we wrapping buzzwords around buzzwords just to kind of kill the Scripts?
Well, yes, because we're in it and we're, we're talking about software and vendors and stuff, so absolutely. Uh, you know, this is what we do. But look, I actually think this, I'm, I I, I do agree with Gina on one point and I disagree on quite a lot.
Uh, but I agree that, look, this is essentially an ML thing. I think this is not really an ai. Are we talking a gentech?
Maybe we're talking a little bit about LLM. Look, I actually worked on this at Splunk like a hundred years ago, right? Uh, we'll partner with Puppet.
Puppet does automated provisioning and configuration management and stuff, uh, typically out of the older world, but, you know, Nova under the cloud regime. And we prototyped this idea of intelligent machine to machine deployments. Um, is that a gen?
I mean, we were using machine learning to understand the known knowns of a configured environment, you know, so going out using Puppet, do I be able to understand what's happening effectively maintaining this idea of a dynamic CMDB? Yes, I said the C word. Um, and using that as an LLM to then plan and automate the deployment, the configuration, the scale up, the scale out, right?
And then the deprovisioning. Um, I actually think this is a super opportunity. A lot of operations, I've talked about this before, is unknown unknowns when problems occur, troubleshooting, that's where you need the smarts to do the hard work and the thinking.
But you know what? Deployment and configuration management, that's where we have a lot of known knowns. We have things like golden images, we have things like LL uh, like uh, CDBs.
We have scripts that define how code, how infrastructure is deployed in our infrastructure as code. Um, so we actually have a bunch of known knowns. I think this is potentially a really positive way to get out of the configuration management business as humans and be able to use these, you know, machine learning on the pipe to understand what is a good configuration, what is running a good, a known good environment with high performance and being able to like, uh, uh, uh, Jack said, you know, talk LNLP.
Hey Siri, uh, fire me up a gold image. So 'cause I wanna run an AI workload, boom, we are there. I dunno.
Yeah, it is a little bit future forward. Um, and yes, we are trying to sell a bag of goods when it comes to this future forward notion of platform engineering. But look, I actually think this one could be real.
No, I totally agree with you. So don't, don't get me wrong, right, because I've worked on, you know, I've worked in the old school, I haven't had the privilege of having to assist admin, a new school kind of thing. But my point is, is, is we've, and this has always been my point, we are a computer scientist and we have had this spectrum of things that hasn't started.
I mean, you're, that was like crazy blow your mind stuff 10 years ago to me. But back when we were doing, just even doing jumpstart and kickstart the beginnings of this, um, that your problem that you solved solves so many problems we had with the developers, right? So like the, the promise of being able to say, developer, I have a developer has a user case, he doesn't know what it's gonna run on, or she doesn't know what it's gonna run on.
If they can declaratively say, Hey, I wanna, like you said, you know, I wanna build an ag, ag agentic, um, platform. They can, that that could be done automatically. I think the problem I have is feeling like the, this is something humans never could have accomplished.
That, excuse me, that we're using AI to do it. One sec. I'll start that over.
So I think the problem is that, um, we're acting like this isn't a continuum from where we've come from. We, we need to recognize that we need to recognize it's not ai. We need to start call, stop calling ML and a and, um, deep learning things.
Ai, there are products that have those, um, capabilities in them already. So my point is, let's, when we talk, start talking about this and hopefully when we get, when, you know, hopefully Atlanta will see this, you know, this week we need to see some examples of how you've built this in already. What does this look like?
Instead of just this, oh, we sure be nice if we had these three. You can't define three stages without giving some proof behind it. That's kind of my point too.
Mm-hmm. Wiki, I'd get your opinion here because the one thing, and I don't hear a lot about when I hear the phrase platform engineering is security, compliance or any of those fun Things. Yeah.
So I think the key cons, uh, insights is, uh, the team can't stand on a single two right? Anymore 'cause it's so complicated. Now they do need a governance and uh, uh, observability layer that can spend different frameworks and plots.
So I think ai, LLM, that ability can make it happen, right? So in this year in RSA or this year, I actually see a lot of different AI tool can make it happen. A lot of company make the AI or LLM elements in their tools to help in this area, which is fascinating.
Yeah. Andy, I can't figure the following out. Is platform engineering something apart and distinct from DevOps?
Is it the evolution of DevOps or is it just kinda really a DevOps mulligan and we're just doing this over again with a different kind of spin on it? Oh, mate, uh, oh, you put me on the spot with that one. Look it, uh, DevOps, as we know, DevOps is fractured into all sorts of commercial opportunities and platform engineering is absolutely one of them.
Look, this kinda actually comes out of the idea of a Spotify model. So not actually DevOps. This is not about collaboration, communication, communication and integration of teams.
This is about having a service department, um, which is okay and I dunno that I love it. Um, the, you know, the idea of platform engineering definitely comes out of DevOps. It comes out of infrastructure as code.
It comes out of the idea that developers aren't actually operations, they don't actually do provisioning configuration management and we shouldn't ask them to. So the, I think it does come out of DevOps in that devs have asked ops to do a job for them, which is build environments that are gonna work and scale and, you know, ideally be predefined to be secure and all these sorts of things. But ultimately, yeah, I dunno, I don't know that I love this.
Um, I think having an expert team to sort of replace the golden image team with a dynamic, uh, on demand provisioning team, I don't think it, it, it breaks down barriers. I don't think it breaks down walls. I really like it from an automation perspective.
And if I was a developer who could just click a button and go, boom, there's my environment, I'd be super happy. Uh, but I think it does take some of the collaboration out and I think it does sort of work against some of those good principles of DevOps that we've worked towards for so long. That idea of collaboration, that everyone's on the same team, that we're all working together to get this software out the door.
Uh, I don't know that it's positive that way. Uh, Gina, do you think that we have an opportunity here to maybe finally bridge the divide between the classic IT admins and the DevOps engineers and maybe we'll all link arms and sing Kumbaya together? What do you say?
Oh, man, why? That's Andy's question. Uh, you know, I hadn't thought about what Andy just said that, um, this, uh, this I idea that a developer could just declaratively state what the environment should be, might not be a good thing because it keeps the developer separated from the ops people.
And it, it does get rid of those that one of those DevOps principles. And I kind of think that's probably true because I think we've got, we, and I think we go in stages with this as, as the hardware matures and the hardware is able to do more things for the software, and I think we're probably in that stage and we're probably gonna be in that stage for another couple of years. Um, where you don't, you as an ops person, the reaction might be too over, not over secure, but to, to keep that away from the developers.
Let them just run fast, give 'em what they need, and this is a way to do that. And so maybe that takes away, so I, I'm not sure, but I, I do think that that's not a good thing on the ops side because it's much better, um, to work with your developers and understand what they're needing and what they're gonna declaratively call. So it's already there.
So not having to deal with each other is probably in the long run, not a good thing. I got that from you, Andy. Thank you.
There you go. Jack, help me out here. So, software engineers will have their own AI agents.
They may have, I don't know, each member of the team will have, let's just say arguably 10 developers will have their own AI agents and they'll probably have 10 of those. And then we'll have a bunch of AI agents that are assigned a particular task on behalf of the A on behalf of the team. And this all sounds wonderful, and of course something will fit in the middle of that to provide some orchestration.
But as I continue to think about it, just the overall complexity of managing that may be beyond the cognitive capabilities of our mere humans. 0? Because once I get past, I don't know, 20 agents, can I really manage that?
Well, we love, uh, specialization in it. And so I think you're now gonna see the rise of, you know, we have this thing we call AI ops, but you're now gonna say, see AI platform engineering whose job it is going to be to maintain, build, and maintain the AI platform that helps the platform engineers build and maintain the platform on which our apps actually run. And at some point, the specialization is gonna be a little bit crazy, right?
Where we're gonna have people whose only job it is is to just, you know, tweak one button so that somebody else can tweak a button so somebody else can tweak a button. So eventually we can run something somewhere. Uh, you know, I think, you know, the counter argument to that of course is that the, you know, as I said before, you know, a AI and LLM gives you the opportunity to use a natural language interface.
Uh, AI in general gives you the, uh, opportunity to abstract away a lot of the drudgery and complexity of the day-to-day things so that we are no longer, I mean, if you think about what is, uh, uh, infrastructure as code, it means it's taking away the need for an infrastructure person, whether they're a developer or an operations person to log into every individual machine and type individual commands to configure that machine, right? Instead, we have a, a a, a level of indirection and a higher level language. We can talk about how we want things to look and let something, let a machine do the complex, you know, minutia of configuring every little bit and bite.
And if we can then abstract that out one level, maybe we can do away with some of the platform engineers and some of the DevOps engineers and some of the AI ops engineers because we've automated enough of this that we, the underlying infrastructure is complex, but the management of it is simplified. I hope. I Hate how right you are about some of this stuff, Jack.
Um, I hate to think that you are right, but I think you are right. We're gonna have agents, running agents and you know, this, this actually does come back to something that Gina pointed out, and that's the skill issue. And the more we have this embedded in platform engineering, this expertise and the more complicated the environment gets and the, the more we seed that knowledge to the LLM or whatever agent or AI it might be, where is the knowledge gonna come from when we need to do something new and different?
You know, the, the golden images or the infrastructure as code definitions we've got today are not gonna get us to where we need to be tomorrow. Who then figures that out. So yeah, I think, I actually think you're right, Jack, and I hate that you're right because we're gonna, you know, to Jean's point just atrophy a lot of knowledge into those systems.
So the thing is too based just, sorry, but based on Jack, what you said about the, the, the agents managing agents, does that mean we'll have to have a specialized section of the CMDB to accept tickets from all these agents and disperse them properly? I think so too. 0 version, right?
Which is where you simply automated what humans do. But the real, the the right way to do all of this is to rethink it and say, how does you know a clean sheet of paper? How does it look if you had a clean sheet of paper?
And what would machine to machine communication look like to, to make these things happen? Take the human out of the loop and do it the right way the first time. Yeah, I just wanna say like, uh, I just talked to somebody, uh, this week talking about how to how they manage the agent identity or like code agent as part of the thing, right?
It, it's kind of interesting like, uh, agent and agent used to talk together, but people still need to be in the loop. Yeah. Make it happen.
Yeah. Well folks, I don't know whether you believe in platform engineering or not, but I will tell you that people who have platform engineering certificates and things like that seem to be making about 20 to 25% more than your average DevOps engineer does. So get yourself a certificate whether you believe in it or not, because well, you get yourself a raise, we'll be back in a minute.
You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included, that work your protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity, your digital front door is wide open. And what compromises your home can breach your boardroom.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black clerk, digital executive protection, defending the new attack surface your personal life.
All right folks, we're back and we're shifting gears a little bit. There's been reports that Apple plans to have some sort of deal with Google to embed Google's AI Gemini models into Siri, which, you know, a lot of folks are talking about. But Wiki, I'd like to get your opinion on this.
And of course I'm a little biased. I I use Google, I have Android phones, and I kind of looked at this and shrugged and said, well, if Apple's going to use Google, why don't I just use my phone in the first place? 'cause it's the same AI model, so why am I gonna get a different phone to go talk to a different model?
I don't know. But what's your take on what's going on here? I actually, I wanna talk from two perspective, right?
First of all, like Google and Apple, they have collaboration for a long time, right? From the search side, Google still need to pay, uh, apple to put their search into the Apple phone. So it's not new.
They have a collaboration. So that, and second thing, I think, uh, apple actually play very, very smart. Um, you know, like all those big hats, they put lot of money into the GPO and try to get all the chips, um, and spend a lot of money, right?
Um, but Apple, they, I feel like they're very calm. They, they, they always waste their pace, right? They, they choose very smart to how they spend their money on the info or other thing.
So, uh, it's not bad if they have some, they leverage what our Google has already and to enhance their LMLL capability, right? So like I, I do talk with somebody, uh, earlier this year in my podcast, uh, when they talk about their LLM, they used to, uh, really wanna have their own model. Uh, but their, their prediction is if they have their own model, their delivery will be in 2027.
But at the time when OpenAI suddenly, uh, said, okay, we have that API and they can quickly plug in and then make their, their, their product happen within two, 2025, right? Which is a huge jump and huge saving from their side. I think Apple is kind of like doing the same thing.
They try to leverage the capability Google model has and spend less money from their side while at the same time they try to deliver the best product. I think it's very smart. This is my opinion.
Yeah. Jack, what's your take here? Because on the one, some folks would say it's a bit of a black eye to Apple because they're leaning on Google for AI after talking up their own Apple initiatives for a while.
But to wiki's point, maybe, you know, these things are compatible with each other and you know, better sooner than later. My understanding is that this is theoretically a, uh, sort of a stop gap measure, I think as Wiki was saying that, that Apple needs something. Now, what I don't understand from Apple's perspective is what is the value of owning your own LLM model?
And, you know, apple likes to control its own destiny, but does having a model that's not Gemini and that's not, uh, open AI's model and somebody else's model, what value does that bring to Apple in the long run? And is it worth the ROI of, I don't know what's cost now for them to do it? 10 billion, $20 billion to build a model, right?
2 trillion parameter model. So it's five times as big almost. And you know, in terms of the amount of knowledge it has and can consume and, and manipulate.
So I just don't understand what Apple gets from having their own model. And I think chasing that is a fool's errand. Uh, 'cause um, people always talk about where's the future direction for the AI or LLM because of the energy resource, uh, strengths, uh, we tend to see like it's more at the age end, right?
Which is like a small language model. I think it's still have a value if Apple can keep their own model, uh, towards, to like a smaller size model, um, specifically to support age technology. So I think this is some PO point I can add.
Yeah, Andy, I gotta tell you, and this is kind of similar to what we just talked about in the previous thing, but I'm a little worried that at some point in the future, my AI agent is gonna be talking to your AI agent and they're gonna negotiate something, then the next thing you know, I'm gonna be meeting you and Timbuktu because our AI agents set up this meeting. How are we gonna manage all this and kind of keep some level of control around? I don't know, mate, if, if my Outlook calendar will only handle time zones perfectly, then I think would be great.
Uh, but no, look, i i, it it is gonna be, uh, an agent to agent. Well, machine to machine is something that I know, uh, colleagues of mine, people like Dennis er at EMA who's retired now, um, the, the, uh, research emeritus, uh, has been talking about machine to machine for a long time. And it, this comes out of older technologies.
You know, everything old is new again, you know, my thesis, it process automation and robotic process automation combined with intelligence and library knowledge becomes, you know, agentic AI in a lot of ways. So yes, this is, this is absolutely gonna be the case, but that think, that's actually part of why this is a good deal for Apple because this is not a case of ag agentic ai. This is not a case of advanced intelligence and becoming a differentiator for their platform.
You know, you think about things like Gemini, Claude or, or Anthropic, and you think about corporate use cases and you know, understanding what is my customer buying patterns and you know, what, what other offers could I make to get someone out of that mode into this mode and stop churn that's not this right on device AI for Apple is like, uh, take a picture of my grandson or delete my ex from this photo. Or, um, um, answer question. Why do cowboys wear chats?
I don't know. Um, this is what on device AI is for Apple. Is it gonna really differentiate them to have their own model with a trillion, uh, of vectors?
Or can they get away with Alaw and anthropic a Gemini? I think that's really smart because it's, yeah, we are gonna get to where you are going agents to agents, machine to machine. This is absolutely gonna be a thing, and that's its own problem.
But this is very much about grandma trying to, uh, uh, get her phone to work properly. And I think Apple intelligence has been missing in action, a total dud. Um, and as WY said, you know, Google and Apple, this is a partnership already.
The enemy of my enemy is my friend, and they both want to see Microsoft not succeed, right? So this idea of being a slow follower with core competency differentiate everywhere else, like Wiki said, on the experience on the device, on the software, on the walled garden. Is AI gonna make the difference for 'em?
I don't think so. So yeah, I think this is actually pretty interesting. I don't know.
I'm a little bit worried about, you know, someday my father-in-law's gonna call me up and he is gonna say, Hey, can you come pick me up? And I'm gonna say, where are you? And he is gonna say, I don't know, but it says in the, in somewhere in the South Bronx, and I'm gonna have to go drive down there and get 'em because the phone sent 'em there.
It's true. I mean, people just, this is true already, right? People just follow their GPS blindly and turn into canals and, and down one way streets and all sorts of things.
Put it this way, uh, just because Apple is getting Gemini is not gonna make humans more intelligent. Well, the oth the other thing about it is that's a little worrisome, is one of the main drawbacks to LLMs is the data that it has been historically trained on. And that is the Internet's wise, wonderful world that is absolutely discriminatory towards women, people of color, people, uh, that are, um, disenfranchised.
So that's kind of the worry thing. 'cause I thought Apple was one of the places you could trust to have trained their model and to kept some of that out. This is just kinda like what I've heard.
I don't use Apple either. I use Google, which is a whole different story that you try to keep up on and it's impossible to, but if, if you know that those models have been trained that way, um, then, then how sure are we that the, that, that, that doesn't creep in to the Apple model, is that same tort types of kind of hidden biases that are in the, in the data, because that's how our, our history has been. So, um, I think that's a concern to think about.
I may, I wonder if that's why they're going so slow to do their own thing. I tell you what I would love to see though, because you know, my household is a split one, right? Half the house is on Apple and the other half is on Android.
Wouldn't it be wonderful if this AI stuff made it easier for us to communicate with each other on our phones across different apps? So then that way I don't have to sit there and get my wife telling me that I should get on, you know, the Apple video conferencing platform so she can call me better or more easily, or we don't have to use WhatsApp as an intermediary. Is that gonna be possible?
What do you say Wiki? I should say everything will is possible, right? You never know.
So something cannot avoidable. So, well, that's it. We, we, we will wait to find out, Jack, last question.
Will people switch from phones based on the AI experience, or are we pretty much having this kind of Coke versus Pepsi thing and everybody's already decided, and it's just a question of what capabilities are gonna come in, but it's not gonna change anybody's mind? Oh, I think people are much more passionate about Apple versus, uh, everybody else than Coke versus Pepsi. And there are, there are people who say, you'll get my Apple device outta my cold dead fingers, right?
They're not switching no matter what. I know people who have actually said they won't join a company because they couldn't have an Apple device. They wanted another, you know, they want their Apple MacBook and their Apple phone, and if the company makes 'em use a Windows box, they're not going there.
So, I mean, we're way past that point. All right. I billions will be spent trying to convince people to switch, but I think most people have already made up their minds, and I don't think we're gonna see a whole lot of people going, oh wait, that AI experience is so much better.
I'm gonna give up my phone and switch everything out because that, I'm just jealous of that ai, I don't see it happening. Yeah, like I I Apple device a lot, right? Like no matter what kind of a large language model they are, they're, they're try to move.
Um, sorry, I don't think that it will change my, uh, habit to use Apple. So, and my Apple fan, sorry. All right, well folks, I'm gonna leave it there, but I'm pretty sure we're gonna enjoy the fight.
Whether you switch or not, we'll be back in a minute. Discover Techron group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in most powerful way with Textron Group. All right, folks, we're back with our final block of the show.
And Jack Poller has an interesting story up on Security Boulevard talking about why in Israel they're sending cars back that remain in China. Jack, is this gonna become a global phenomenon or what's going on here? Uh, well, yes, it actually is.
And I, I thought this was gonna be just, you know, because rightly so, Israel is very paranoid, but it turns out they're not the only paranoid country in the world. And Denmark had the same problem, the same discovery with electronic, sorry, electric buses that they bought from China. So let's first talk about Israel, and we can talk about Denmark in Israel, they, uh, have banned 700 plus cars that were, uh, imported from China, that they were leasing to senior officers in the military.
Their first step a couple of months ago was to ban the cars from going on base on military basis, because the cars are equipped with cameras and microphones and uh, and cellular connections. And they weren't sure what was going on. They, so they started to investigate those cars and they decided that the systems were complex enough that they could not guarantee that sensitive data was not being sent back to China and or that people couldn't hack into the cars to get access to the cameras, microphones and the data.
So from a military perspective, there's a very big operational security. If you know that the cars are associated with senior military officers and you can at the very least track their locations, then you know where the military officers are theoretically, and that's a big, uh, operational security and a big risk. Um, so that's sort of one risk that was identified.
So Israel's response was basically saying, we're taking those cars back from the senior military and we're just not going to allow anybody in the Israeli military to use cars from these companies. But I think it's actually a larger problem in general because if you look at most modern cars now they have a cellular connection and they can do an over the air update. So you can't, even if you inspect a car software that's embedded in it, then it can be updated.
So you have to keep track of all of that. Denmark sort of looked at it and said, well, we have the same problem with Chinese buses now. They're not concerned about the operational espionage portion of it.
They're concerned that somebody, either the Chinese government or a hacker could come in to their electronic vehicles and basically turn 'em off and then they wouldn't be able to use them. And there's, you know, this is, uh, very small countries, but reliant on public transportation. So their first response was to, they pulled, uh, three of their bus models into a cave that was basically essentially like a Faraday cage, so underground so that no radio signals can go in or out.
And they were trying to figure out what the buses were communicating. And based on what they found, they decided their first response was to pull the sim cards to prevent those buses from communicating to the rest of the world. And they said, any updates that come in, they're going to inspect the updates before they get applied to the buses.
So There's a couple of different ways to look at it. It's a cybersecurity risk. It's a, um, it's a potential denial of service risk.
There's a hacker risk. The hackers can come in and, you know, the, the, the big scare where it's here around the thing that it's Chinese. But if you think about it, it's all, it's basically all the modern vehicles.
If you look at a Tesla that comes in, a Tesla has, you know, five, six cameras that are recording 24 by seven, right? And is can, you know, and the Tesla headquarters can get access to that data at any time. So there's a big security risk here of who can get access to that data.
And essentially these things are rolling, motorized spy vehicles is one way to look at it. Andy, will this go the other way? To Jack's point.
So, you know, United States, we sell cars overseas and some countries may decide that we too are injecting things into there and it can become, uh, an issue where everybody just says, I'm only buying cars made in my country. Yeah, absolutely. And I probably should to a large degree, especially with, uh, sensitive environments, not just military, uh, but also infrastructure and other things that might be at risk.
Uh, you know, and again, it doesn't need to be nation states. These could, it could be about nefarious actors taking control. We've seen, for example, various, uh, cars being able to be packed in remote controlled, you know, literally being able to crash you on the freeway.
Um, it doesn't have to be some sort of James Bond secret squirrel thing, planting a secret listening device and all this just to, you know, just to leak some sensitive data. Jack's spot on all of these cars have got this ability, and it's not just over the air updates, it's GPS, it's back based telemetry for things like, you know, diagnostics remote start and stop a remote takeover. Look, Tesla's already bricked cars that have failed on their repayment plan.
Um, do you think if, if our president comes out to Tesla and says, can you tell me where so and so is driving? Yeah. We've seen this also, by the way, with Uber many years ago, using telemetry to, for nefarious purposes in that case, tracking, uh, journalists that were critical of them.
You know, this doesn't have to even be a nation state problem. And yeah. Is if, if, if the US government needs to hack into a Ford or a General Motors car that's made here to find out where someone is, and by the way, we've seen this with things like, uh, GPS devices on watches, soldiers going running off base in Afghanistan.
I think it was, were giving up their location 'cause they had Strava, the running tracking app connected to their GPS watches. This is not an Israel story, this is not a China story. This is just a modern connectivity story.
But I do think you're right, Mike, the, this is gonna be a give, give pause to a lot of nation states who are thinking, well, what if America takes over my buses or cars? You know, this is absolutely not limited to these two or three nation states. Mm-hmm.
Wiki, every morning I get up and it's cold here in New York. So I get out my little mobile app and I get the car turned on and I get, you know, defrost going and the whole thing's. So the car is kind of toasty warm when I get into it.
Is that now gonna have to include a security scan before I get in it? What do you think? Uh, theoretically, right?
From professional perspective, I think from the data perspective, they do need to have some like encryption for your, like driving data to protect where you go, right? And your identity or something. Um, for like, but if you see the, the other interesting facts here, uh, actually in Israel, that company that that Chinese car company, right, is a best seller for September, actually compared to other car company.
So I think I respect their, their innovation and the quality they have there. Um, but I should say like not only for car, right? Other IOTD wise, it's very hard to standardize internationally.
This is very, very true point. 'cause there are, there are so many different, um, protocols or so many different models try to standardize it. So I do respect like a, a different country has like different thinking.
Yeah, that's my Gina. Should I sell the car and call an Uber? Would that be better?
Depends on where you live. I, that's another argument, a whole different thing. Um, but I, I think what's missing too, like, I, I think everybody is talking about the, the holistic ways it could be problems, but even down to the smallest thing, if you have an ex that's trying to track you or wants to do something bad or trap you, if you've got, uh, people go on strike and just, or wanna be on strike, so they disconnect, they log in and disconnect everybody system.
It's incredible. I know they always have a car hacking village at Defcon. How many, um, s systems are actually running electronic systems, communication systems are running within just your normal Ford car, right?
So there's, there's almost like, I'm not sure how much of a responsibility the car crew are taking for those systems, um, to let people know. I know I've never gotten anything from Ford that says, Hey, you should, you know, make sure you don't do this and this, that information is just kind of going off into the ether, I believe. So how do you, there are, it seems like there should be a way to contain your personal data on the car that you paid your money for to your personal vehicle, um, and to be able to be notified if something has gone awry.
But even as I'm saying that, like, who's gonna understand that? I definitely don't wanna teach all my family about that. Like, what is the system since this is a, you know, it it's the nation state thing is a big deal, but the nation states have their own armies and whoever they have working on that, you know, technically.
So they've got very smart professional people, probably the smartest in their nations working on com, you know, protecting that sector. But you know, what happens if there's, you know, worst case scenario, there's a way to hijack a whole city because you can turn the cars against each other or you can, you know, you can shut 'em all down and how can you protect yourself against just the common normal things of your X track and everywhere you go, 'cause he hacked into your tire network. So mm-hmm.
You know, Jack, We talked about foreign governments here, but you know, the, my local government may not always have my best interest at hearts either, right? Because it could be that, um, you know, they wanna track whether I'm gonna go vote on Tuesday, where's my car, and send me a message telling me the polling place is closed. So, uh, Or who you're voting for, right?
Depending on who you think you're, they think you're voting for, they may say, you know, let's disable all the cars of this group of people so they can't get to the polling place. So that way we get more votes of our people, right? There's the, but yes.
And, and I look at this as, as the greater story is that for many, many years we've, we've waved a hand around, uh, we've done a lot of hand waving around it and industrial control, so I, sorry, ot, uh, iot and industrial control system security. And from an enterprise perspective, we basically said, okay, the, the short, quick, easy way to deal with that is we put them on an isolated network. There's a, you know, and they're sort of separated and it's essentially the version microsegmentation of a large scale for IOT devices.
But the reality is that almost everything we have these days is an iot device. If it's got a radio in it, it's you, it's not on a separate network that you can isolate and somehow control. If it's got a cellular network in it, you have no ability to, to understand what it's communicating to whom.
And it's a bidirectional communication. So if somebody, if you can send messages into the device, a bad person can send messages in and take it, you know, and take it over. If you can send data out, you can send data out that you don't want it to send out.
So, you know, I mean, and this is not a new problem. I remember, you know, 25, 30 years ago when camera when, uh, um, cell phone makers started adding cameras in to cell phones and, uh, you would go into a manufacturing facility or a chip fab, the first thing they would do is say, all phones in the bucket here. You can't take a phone that has a camera with it into this facility.
'cause we don't want any pictures here, right? So, I mean, but that, that was easy because we could confiscate the phone. Now you, you know, what do you say, strip naked.
We take every single electronic device off, you know, you have your rings and you know, your, your watches and all the other stuff that we have that, you know, everything's got a radio in it, even Bluetooth, right? So the how do you, you know, we have a big problem that we've sort of, like I said, we've done a lot of hand waving around, and that's sort, I don't know, I guess I'm putting the red flag out there and saying, wake up, pay attention to this a little bit. All right.
I think we're reached that point where to a certain degree, in every country we live in a surveillance. Uh, let, try that again. All right.
I think we reached the point where, to a certain degree in almost every country we live in a surveillance state, whether we like it or not, it's now a question on what we're willing to tolerate or not tolerate. But as everybody just pointed out, maybe it's good to have a healthy dose of paranoia. Hey, I wanna thanks our guests for sharing their knowledge and insights today.
I wanna thank you all for watching today's show. It was great. tv lineup.
It's gonna be equally awesome. And we'll see you all again tomorrow. Hi everyone.
Welcome back here to Techstrong tv. You know, I, I've so much going on in the world lately. I've, I've had the pleasure of talking to the few of the folks at suse and, uh, but here's one of my favorite.
There were words Sus Arians, Sussan. I don't know what the right thing is. I Honestly don't know.
Let me get you Juice. You to my friend Peter SMAs, that snails with an M, not an N, correct. Otherwise we call s With an A.
You go the other way, snails, which is, Hey, sna, With ans with an M. Easy. Peter is the SVP and GM for Enterprise Container Management at suse.
Peter, welcome back. It's great to have you on Techs Drug tv. Thank you.
It is always fun to be here. I love the conversations. So a little bit of wishful thinking with that background.
Or you're on vacation. I wish I was on vacation. I, uh, I won't give too much.
PII, but so I'm, I'm up in Massachusetts, so this is really more wishful thinking. It's a pretty nice fall day, I have to admit. But that's definitely wishful thinking.
Hopefully I'll be in a setting like this, but apparently this is your backyard from what I understand. So for You Well, it is pretty much, yeah, it's, well, so that beach is across the street from me, but Diane, but I will be up in Boston actually in November. My, my son is getting sworn into the Massachusetts bar.
Oh, wow. And we're, yeah, we're coming up, I think the 18th and 19th, something like that. But congrats for that though.
I'll be in Atlanta for CubeCon. I think you will too. Yes, sir.
And, and, uh, that's what I wanted to talk a little bit about today, about sort of a CubeCon preview of what, what we think maybe the big themes, themes that Cube Con are gonna be. And, and you know, what, what Susie, what's Susa doing? And, and we're not here to talk about, I, I know you guys are gonna be releasing news and people are gonna just have to wait for that until CubeCon itself, but that doesn't stop us from talking about kind of the bigger themes.
But before we do that, Peter, I, I wanted to jump into, I, I mentioned your SVP and GM of the Enterprise Container Management, I guess a division or team at, at suse, What you call it, a business unit. Okay. The bu Yeah.
Great. Is that the rancher business? What we used to know is Rancher business more than that.
Let you know part of it. Give us an idea of what that BU is about. Yeah, I, it that's a great, it's, it's a great question.
I think the simplest way to answer it is it, it's technically a business unit, but at the end of the day, we have multiple businesses operating in context, you know, so as you know, we're heavily focused on edge, we're heavily focused in AI specifically. We have a, we have a sister division, you know, around Linux. So I would abstract sort of away from sort of like what we call bus use away from sort of what we ultimately deliver from a market standpoint.
So sort of, sort of back a house versus front of house. Because ultimately mm-hmm. What I'm, what I'm looking after and what I get up and care about every single day is, is ultimately cloud native.
And I have counterparts I work with, there are other folks you talk with, you know, Keith, basil and you know, Avanav and so forth, all the different folks. But at the end of the day, we operate in concert. And so, kind of coming back to your point about next week, like we do have a bunch of news, we will, we'll sort of tease that a little bit now, but thematically the important message for folks to take away, regardless of sort of the, the, the back of house bu stuff.
At the end of the day, SUSE is all about delivering a platform. We are, you know, the market leading open infrastructure platform actually for not only Cloud native, but also Linux. Obviously I'm focused primarily on the cloud native stuff.
So ultimately it is about putting all of our best resources forward to deliver this open infrastructure platform. What is an in open infrastructure platform that is basically a single unified management control plane for developing, deploying, and managing all of your cloud native workloads regardless of where they are. So again, that's where, from a platform, it could be everything from, we'll talk next week more about big focus around VMware modernization.
We are a landing spot. Our open infrastructure platform is a landing spot for organizations that are modernizing away from VMware. Okay.
So we'll talk more about, so we continue to invest in virtualization as a core component of the platform. We have a bunch of exciting stuff we're gonna talk about next week around Prime. Everyone knows Rancher Prime as the primary, you know, the primary platform for enterprise container management, if you will.
And that's sort of the mm-hmm. The central control plane in the brains, if you will, from a, from an infra management standpoint. Bunch of exciting stuff going on there around things like observability, um, infrastructure, resource optimization.
You know, how do you basically make, how do we continue to make prime for its part the best platform for all cloud native workloads? And that means you have to manage all the infrastructure. It means you have to help people optimize the resources of that infrastructure.
It means that you need to make the user experience as simple as possible. And so we're gonna be touching on, you know, uh, you have to give them the insight and visibility to be able to do intelligent things with that platform. So you can imagine next week we're definitely gonna be touching on virtualization.
We're definitely gonna be touching on things around observability. 'cause that's so front and center. Um, we'll certainly be talking about AI and we can kind of double click on that, but you can, Ima the most important message, a again, if people take nothing else away, the most important thing is when you think Susa and you think Cloud native, think Susa as the open infra platform for all of your cloud native workloads inclusive of those folks on ramping from VMware modernization.
Absolutely. You know, we, we've seen a real, or where I sit, right? Seen a real evolution in what we, what cloud native is.
Hmm. Right. For most of us, we call it cube con.
Right? And so if it's Cube Con, it's probably about cube, about Kubernetes, right? K but another name for the show is Cloud Native Con.
Hmm. Right. And that's, I think the official name, or maybe they're both official now.
And I think this is the year that cloud native con becomes real. It's not just CubeCon anymore. Yeah.
You know, when you look at the top five projects at CNCF, I think at least two, if not three of 'em are observability related. Yeah, yeah. Ai AI is pervasive up and down this stack.
Yeah. Service grown up. Yeah.
Well, if you're not doing AI at this point, you know, you gotta ask yourself why and how far behind the curve you are. Yeah. Right.
That, that's kind of where we ares Crazy, but true. Yeah, no, just a, a couple funny things on that front. Number one is that, uh, I technically have sort of two titles because I'm also the general manager of Cloud native.
And that's honestly part of the evolution because what you've said is, is, and, and I wanna say they're both, they're sort of interchangeable is my point. Like, it's not, it's not two separate jobs, but to me, I think you're spot on. And the reason that you're spot on is if you go back, I mean, we've been at this a while, right?
If you go back to the early days of Kob Con, which is around 10 years, right? And the early days it was, how do I use Kubernetes? How does it work?
What do I do? You know, and that's where Rancher, you know, like our, that's where we really cut our teeth. We were the first kids on the block because I'm an extra.
Absolutely. We made Kubernetes easy, we made it simple. And it's why we have, you know, tens of thousands of active users.
It's this enormous community that's rooted in making Kubernetes simple, but where the market and everything is evolved. And why we talk now about being the cloud native platform is it's all ma, it's maturation. I mean, I, I joke about how co it's still K Con, but look at sort of the, the, what's the word I'm looking for?
Sort of the commercialization of Kub Con, kind of the, the, you know, the um, the enter prioritization, the, you know, that look at the, the people coming. You go five years, six years ago, you go to Kub Con, it's all backpacks, you know, and the sessions are super tactical now. You got a lot more suits.
You got a lot more ties. You got a lot more. And this is because a different set.
Look how I'm dressed and I, I didn't wear my jacket today, but to, you know, I used to, no, but I used to go in a t-shirt. You're the people, you're, you gotta, you have to spam the whole spectrum. So you gotta be able to do both.
So you put the blue blazer on the Universal. Yeah. You know, I can do everything.
It's a uniform, but it's, but it's, but your point is valid, which is that it's now, I mean, just the, the, ultimately the strategic value and the strategic nature of Cloud native as a technology for enterprises, you know, small, medium, large enterprises. It's, it's business critical. It's mission critical.
It's no longer about does it work? How does it work? It's about the overall ecosystem.
It's about maturation, it's about security postures. It's about, to your point about observability, accelerating remediation, reducing risk, reducing tc, I mean, it's just the whole thing has become, it's still about tech and innovation and all that kind of stuff, but fundamentally, the nature of the conversations are changing. So it's just the overall landscape is, is evolving.
And it's super fun because from the beginning of time, you know, the thesis has always been, you know, those who can basically, from a, from a, from a go to market or from a business strategy standpoint, like those that can provide, you know, consolidated management, you know, and simple management of a cloud native infrastructure will do well going forward because you're riding the wave of adoption of cloud native within the enterprise. And, you know, the VMware stuff with Broadcom is just one more mega catalyst that is creating motivation and the catalyst for people to say, you know what? I don't want it to replace, like, for like, this is gonna help me accelerate my cloud native modernization journey.
What do I use? Where do I go? And I can only, I can only reflect on that in terms of, just from a suse business standpoint, that's exactly what we're seeing happen.
It's, these are C-suite conversations. These aren't, you know, you go back five, six years ago, it's just purely developers, but completely bottoms up. Now you're talking c it's completely the other way around.
It's, it's actually completely, it's both obviously. And it meets in the middle. Yeah.
'cause there's a middle allowed element to it. But here's an interesting thing. You know, we recently did a whole series of webinars with AWS and some of their partners around, around VMware, around modernization, transformation, moving to cloud, et cetera, as you would imagine with a WSI think the whole Broadcom VMware licensing issue, if we could call it that.
But we all know licensing is just another word for dollars and cents. The price increase it's given people, it, it, it, it's sort of a, a boundary layer where people are now saying, wait a second, I may wind up paying what they want me to pay. I may stay on VMware.
Yeah. But this is an inflection point where I now should take a look at what my options are. Do I want to get rid of virtualization altogether?
Like run, run cobe on bare metal? Yeah. Do I want to still keep a hypervisor, but run a cloud native stack with microservices on top of that, on maybe one of the hyper, you know, hyperscalers virtualization platforms.
Do I want to use a suse and standardize because I'm not moving everything to the cloud today? And Like we never will. Like we never will.
Exactly. And so I want something, I don't want one os there and one os here, and I, I, I want to keep my stack consistent. So I, I need a suer kind of that that bridges that, that's, Yep.
Um, All, all of the above. A little of this, I want to be on multiple clouds. And that, by the way, just to jump in there, it's, it's again to, from a Susa overall value proposition, you, you, you've, thank you.
'cause you've nailed it because it is a bit of all of the above, you know? Yep. It's for us, it's for us, it's not about being like, for like, sort of get from point A to point A in the context of virtualization, but to your point, it's, it's, it's like, um, it is absolutely a catalyst.
It's creating conversations. And the key is you have to be adaptable. You have to be flexible, you have to be composable, you have to be open because it's not, it isn't a one size fits all.
And that's something we're finding from a, just from an overall market landscape and from a susa, you know, value proposition. People really are drawn to the openness and the flexibility. It's not sort of an R way or the highway kind of thing.
We are a bridge, but we're also a retirement home for VMs. Like, it's, there's, it's all about what ultimately the organization our customers are trying to do. And we're well positioned there because of the openness and composability of our platform relative to others are more like, okay, here's your box, here's your big box, which you can put here, there, or everywhere.
So it just sort of speaks to our different approach to the market, I guess is really what I'm saying. Absolutely. Well, and it, you know, it, it, I think it speaks to SUSE being a full spectrum, I guess is a good word.
A full spectrum solution. Peter, you gotta look ai, it, it's, it's on, it's in every conversation now. Everybody has a, a situa, you know, a story.
Everybody's doing things. I know SUSE is mm-hmm. Uh, without, you know, going into the specifics of your announcements next week, how do you see AI playing in these things we're talking about?
Yep. And that's, uh, very easy. Uh, very answer, very easy answer.
Um, sort of two things. I'd say two dynamics. Number one is we want to be, we said we want to be the open infrastructure platform for all workloads.
Okay. That's inclusive of ai. So we will absolutely be talking about the work that we're doing, continuing to do around suse ai.
Okay. And that's about being the best platform for running AI workloads. Okay.
So one is, and there's a lot there, and we can unpack that next week at the show and so forth. But basically, one is about being the platform. So that's vector number one.
And, and no surprise, wait for it. It's about being open, it's about being composable, it's about being flexible. So we'll double click on all that stuff next week.
The other big piece though, is also obviously ai, you know, ag agentic from a user experience standpoint. So no surprise, we will absolutely be talking about our efforts on that front, um, around the use of ag agentic, full ag agentic for enhancing the user experience of the platform. So I'd say those are the two primary vectors.
Um, and both fronts are quite exciting. I know there's, you know, everybody might wanna try and say that I'm, I'm really pleased and excited with the stuff that we're doing, and I think we're gonna blow some minds when people can get into the details and come see it in the booth and play with it, and do all that kind of stuff. So we're excited for next week.
Very cool. Yeah. You mentioned something before about the kind of the, let's call it the changing demographic mm-hmm.
For group conte, for cloud native con attendees. And, you know, I've seen it too, right? We, we, in my mind though, beyond how they dressed, we went from a very developer, heavy, real, developer heavy, almost exclusively developer.
Then we saw the rise of the ops folks, right? What I think we've seen over the last couple years is a combining of DevOps and Cloud Native as well as platform engineering. Yeah.
Right. Platform engineering has a huge audience at, at cloud, native Comic Q Con. And it's a, I think the most po last, the last one, it was the most popular, like zero day mm-hmm.
Uh, event was the platform engineering one. Yeah. I, and actually you triggered a thought.
I'm glad you mentioned that. And again, without, without you have to come tune in next week. But, um, we've always been, uh, you know, super strong on the ops side, you know, and we've made great, you know, we've, we've invested a lot of time and energy and resource and innovation, you know, on the developer side as well.
And that's both from an open source standpoint, clearly just from a community innovation standpoint as well as, you know, from a commercial platform standpoint. And so, uh, I think people are gonna be, uh, suffice it to say we have a, we have, you know, our open source community has a very, very, very, very large developer community. Okay.
The rancher developer community has a very large community. And so there's some really exciting stuff we're doing on that front that is actually gonna sort of, if you will, big shift left. Because to your point about developers, they're still front and center.
So if you look at the maturation of the market, a lot of say, security and security posture and that type of stuff would get taken care of by the ops folks. But where the world continues to shift is, you know, how do you put even more and more, how do you continue to meet developers where they are now, put more of that control into, you know, move it upstream, whether it's security, et cetera, you know, secure supply chain, that kind of stuff. So I'll leave it at that.
But there's some super fun stuff going on. 'cause we stay, we, we absolutely stay near and dear to the developer community. And we got some very cool stuff coming down next week.
I think people are gonna, I think people are also gonna real just net net. I don't know if I can hide my enthusiasm. We're obviously looking forward to next week because we're, we're all in the mail.
We're bringing some exciting stuff. So we can't wait to, to share it with everybody and, and have 'em, you know, come join us in the booth and play with it. I love it.
Peter. You know, I always tell people passion is contagious. Mm.
I love the passion. I agree. Thank you.
I agree. No, I appreciate it. I love these conversations.
Absolutely. Hey, there's going to be a lot of, uh, of news next week on this. We're gonna try to get you or some of the SUSE people over to, we'll be, we'll be broadcasting live all week from the show floor.
Nice. So Tuesday, Wednesday, Thursday. Sweet.
Uh, so we will catch up with you there when we could talk more openly about this. But, you know, I think, as you said, suffice to say, there's a lot of, a lot of stuff to be unpacked. I think it's gonna be a great event.
It's gonna be a great Kon. Atlanta's a great town. Yeah.
Um, And by the way, one thing, I gotta get this in as well 'cause this is all completely public, but remember when we talk about open infrastructure for Susa, let's not forget about Linux. We just made a massive announcement on this last 16 stuff. So again, next week is obviously sort of, you know, focusing on that side.
But again, folks, when you take it away, this is building directly on top of all the very cool stuff we've already done, done This last month. Well, that is the underpinning for all of this, right? Yeah, absolutely.
Look, Just a little plug on my own. I wrote a nice article on this. Go check it out.
It's inside. You did. It's brilliant.
It's brilliant. Yeah. Thank you.
On Techstrong it. So go check that out. You know, I talk about AI and everything else that I think was, is a big story there, Peter.
We'll talk more in Atlanta. Come ready and, uh, I'm already ready. Look forward to seeing you next week.
All right, my friend Peter Smails, SVP and GM Enterprise Container Management at suse, doing, giving you a quick CubeCon preview. We'll see you next week in Atlanta. This is Alan Shimmel for Tech Trunk tv, though.
We're gonna take a break right here. We're gonna be back with more. Stay tuned.
Hey everyone, welcome back here to Text Drunk tv. Let me introduce you to our next guest, David Yek. David is the senior or a senior principal engineer at Amazon Web Services.
David, welcome to Tech Drunk tv. It's great to have you on here. Thanks For having me.
It's wonderful to be here. Thank you. David.
I always like to start off with giving our audience a sense of who it is they're talking to. So, look, this is only a 15, 20 minute interview, so let's not get crazy, but give people a maybe a sense of kind of your journey to how you got here today and you know, what kind your, your story. Certainly.
Well, I'm a, I'm a software engineer who has built A 20 year career at Amazon doing basically a singular purpose with basically one thing in mind. And that is making developers' lives easier. Uh, it's a somewhat selfish motivation because I'm a developer, and so I'm making my own life easier.
Uh, but this has been from, from making it easier to write code, to running it in production. So this is things like I, I found it, uh, distracting to have to spend a lot of time operating databases, uh, when I have a system that depends on the database. And so when I heard we were building a Amazon DynamoDB at AWS, I joined the team.
And, and since then, I've never had to do database operations again. So it's really a, uh, this singular motivation of just making my life easier and making, making ev all, all developers everywhere is life easier coding and running things in production. Absolutely.
Pretty cool stuff, huh? Um, so David, we're going to talk today about Vibe coding and, and specifically, but Vibe, coding, security, um, you know, depending who you talk to, the amount of code that's being generated now either exclusively by AI with the help of AI is phenomenal, right? We, we might be, I've heard stories, we might be generating twice as much code as we have in the past.
I, I think actually I've seen, uh, I've seen, uh, stats where Google and Microsoft admit to 30% of the code they're generating, being AI generated almost a third. Um, I know AWS right? With between Bedrock and, and so many of your AI offerings, you guys gotta be seeing a ton of AI generated code.
Um, is it, is this a well, 'cause you know, the threshold question for me is, is this a fad? Is this the new normal or is it you ain't seen nothing yet? I'd say it's more, uh, the latter.
I'd say it's more, you ain't seen nothing yet. I mean, I, I think we're, we're seeing as, as more and more developers adopt Vibe coding, they're just able to reach deeper into their backlogs, get more done, and have actually a lot of fun while doing it. Uh, I think, uh, the, you can even see the, the acceleration as the practice and the tools improve.
I'd say Vibe coding started as sort of a, a one shot to a, a large language model. You would issue a prompt say, Hey, generate a, a code, a piece of code or class or something that does this. It would return the code, but it was tedious because I would have to run the code myself, compile it, paste, copy the errors that I got from compilation or tests into the LLM and say, Hey, I got these errors.
Can you fix them for me? So that was tedious and slow. And so that was, and, and not all that much fun and successful.
And so what then if you just look at the evolution of the technique and the tools, then agents started getting applied to it. So in a agentic loop where instead of, uh, me having to go back and forth with the errors, you let, you let the agent both call the LLM to say, Hey, the, the user has asked for code that does this, and it will run the code itself and see its own errors and fix them. And so that got that improved things.
Now I can let it go in the background and it finds and fixes its own errors. But then the latest generation, and now this, these approaches I think were initially very good for prototypes, for greenfield projects, smaller projects, because they would have some, they would kind of wander off if you give it too much to work on at once, they might forget what you were trying to get it to do. And so, but the more, the more recent, uh, the, the more recent set of tools around AI coding, I think is why I think that this is here to stay and only accelerating because those more recent, uh, AI generated AI tools for, uh, for coding, um, follow a spec driven development approach.
So instead of letting the agent kind of wander and, and run into obstacles and forget what it's doing, you spend more time with the agent upfront, uh, deciding what it is we're gonna do, you plan, what are the requirements, and you flesh those out, get a better, better idea for what it's gonna do. Uh, then you come up with a design and you agree, you work through the design upfront instead of, uh, thinking like 30 minutes into a session. Uh, and then you, uh, uh, and then you work through the tasks so it can break things down.
So I think that this, this evolution of the tooling of where we go from one shot prompts to loops to now SPECT driven development, um, we don't know what's next, but I, I, I'd say we've now gotten into, we can work on enterprise code bases, large existing code bases and be successful and, and accelerate development. You know, one, one of the things that, that we're seeing here in, in talking to, you know, a lot of different people is the, if you analogize this to low code, no code, right? 'cause originally, I think that's what they were kind of comparing vibe coding to.
Mm-hmm. Right? Everybody could code.
0. Uh, now I could become a developer to using vibe coding, much like a no code, right? And, and we saw this in low code, you had sort of what they called the citizen developer versus the professional developer.
Hmm. But the wrap on the no code stuff is, look, if you're doing simple apps, it's okay. But anything sort of enterprise worthy or, you know, somewhat sophisticated, it's just not up to the task.
I think originally when we first started seeing Vibe code, and, and keep in mind that was probably, what, 10 months ago, 11 months ago it was. So Yeah, the term only came in February as far as I saw. Yeah, Me too.
Shortly before MCOs after, uh, uh, MCO, right? But anyway, the, the idea was, yeah, it's good for simple stuff, script kitty stuff, right? But you're not gonna really use it for a, you know, a full-blown sophisticated application.
But that's changed. Oh, yeah. I think we are using it now for, you know, enterprise worthy applications.
And to me, that is a, that's a sea change, right? It, it, it's, it goes from being, and I don't mean to disparage the low-code, no-code folks, but it goes from almost being a toy to being a pro tool. Yeah.
We've even seen vibe coding within itself turn, turn from only being capable of smaller applications to being capable of building large applications. Um, even so, uh, a WSA small team in AWS built in IDE and agent ID called Kero. And this does this vibe coating, but it brings this spec driven development approach to it.
And we actually built Kero with kero once it got to the point where we could use it, uh, to, to execute specs. Um, the team actually built a feature that I asked for, um, which was on my list of, uh, when you're vibe coding, uh, sometimes, uh, you let the agent go run through a bunch of tasks and maybe you, you put your attention elsewhere, maybe read a document or something. And I found that when I was reading and it was coding in the background, sometimes it would be waiting for me to approve a command or to answer a question or clarify something, and I wouldn't notice.
And so I would be really, uh, sad. I would say, well, oh, shoot, I, I blocked the productivity of this agent for 10 minutes. I wish that my operating system had notified me and said, Hey, you, you were waiting on something, and this was on the Kero team's backlog to implement.
They planned on implementing this feature, but they weren't able to get to it yet. And they said, well, you know, I bet it was, they had scoped it out as a two week task. And instead they said, well, let's, let's use a spec.
Let's have Kero implement itself. Um, it's kind of complicated as a two week task because you have to interface with every operating system has a different way of doing notifications, inter process, calling, uh, different APIs, different whole structure of what the code needs to be. And so they gave this task to Kiro, wrote, they worked with a spec, they worked, said, okay, here's what I needed to do here, the operating systems, here's how it needs to work and plug in, here are the requirements.
And, and it came up with the design. They worked together and they got it done in two days without even actively working. Um, so that was, uh, that was a huge change of enterprise level code, uh, two weeks to two days.
Uh, that's a pretty able to get further into the backlog than we were able ever able to do, because these specs are able to steer the agent better. Excellent. So now we come to the next bottleneck, because, you know, the theory of constraints is as soon as you clear one thing, you hit the next thing, right?
Kinda outta the Phoenix project. And the goal, I've been in security 25 years in all my 25 plus years and all that time, it's a rare occurrence where security is out ahead of innovation like this. And I don't, it looks like vibe coating's no different.
Yeah. Vibe coating could spit out code, but how secure is that code? And what are we doing to keep up with this torrent this flood of more code, you know, that needs to be secured and we, we can't just put it out there.
Um, and I get you, you need AI to fight ai and it's might, you know, do we need Vibe sec? Do we need vibe security to keep up with Vibe coding or something else? What do you think?
Well, at the end of the day, when I have an agent write code for me, that's my code. And so I kind of, I think of it as, well, it is my code. I treat it as that.
And, and it goes through, we need the same kind of focus on automated review, automated security review of things like we, that we have today in, in enterprise environments. Um, and so I think about, um, the other, the other approach I think that we go with is, is the deering, the coating, uh, kind of unpack where can, where can bugs creep in, uh, to the code? And I find those bugs keep creep in when vibe coding, when say the prompts are too vague.
If we start with something that is a, a vague set of requirements, it might decide to, um, you know, go off and, and, uh, make up its own, uh, its own approach or its own requirements. So that's where spec driven development, I think is actually improving our security, uh, be of use of it, because we agree ahead of time how the code can be structured. Um, the other part that can come in from a security standpoint is if it, um, kind of forgets over time what we had agreed on.
So we can say ag agree upfront how the code is gonna be structured from a security standpoint, and then later on with Vibe coding, if, if, if we're not using the tools correctly, they can, uh, go off and forget that kind of high level mission. And then I would've to, I will notice later that it went off and got distracted and removed something that I wanted to be there. But with Spectrum and development, not only do we agree on what's going to happen in the code and how it's gonna be structured, but it also breaks down the implementation into tasks.
And this is important for LLMs because if an LLM tries to make something from scratch all in one shot, it's going to get distracted. It's gonna forget things. It has to manage its memory, its working memory, its context window.
And by breaking things down into smaller tasks, it can keep that higher level objective in mind as it works on a smaller task without getting crowded out with like the, the entire backlog of what it's trying to eventually do. So actually just mindful use of spectrum driven development, I think is the, is the starting point to, to secure vibe coating. Very cool.
Um, what does it mean for the security industry, for the security professionals though, Dave? com 12 years ago, and I did it because I'm a security person. And I thought, like, what be, what we call today, dev SecOps was gonna be finally the holy grail that we were looking for, right?
Shift left, get security stuff fixed earlier, faster, better. And what we found out is developers aren't security people. Security people are security people.
We could, you know, developers want to deliver quality code, but they're not interested in being security people. How do, where does the security pro fit into this whole thing? I think the security pro has a very important and, and continued job in this, uh, in this effort.
Uh, they're one way that I've seen security teams be, uh, effective, by the way, uh, I've been, the entire time I've been, my whole 20 years of coding, I've been doing DevOps. Just like you're saying, like where I am a developer who operates, that's what that means. There's no DevOps role, it's just Dev does the ops and Yep.
Similarly, the security is, uh, the end of the right. Yeah. At the end of the day, we're on the hook for everything.
The, the finished product. Mm-hmm. There's no, there's no frontline team, uh, running this stuff for us.
And that means all the security, all the operations, all needs to be baked in. And so what I really appreciate when security teams, when do this is when they help give me the guidance that I need and the tools that I need. So it just happens the right way from the start.
And so that it catches me when I'm, when I do something that they didn't intend. And so this is the, so what this, what these security teams end up doing for me, um, is go like the, the code review level, like pull request, review level, or along the deployment line, uh, pipeline doing the tests and verification for me. But I think this and that, that stays going forward, um, how to incorporate security best practices into spectrum and development, I think is actually a new, uh, emerging and a very important role for security teams.
If I want to have a security standard around the way that my company does something, or the, the things that I'm looking for to make sure it's incorporated, I can provide these agent IDs with some, um, what we can call them specs. We can call it steering, we can call it context. Um, but ultimately I need to view, give my instructions of how to think about security in different contexts to a coding agent.
And so things like qro offer these, uh, steering files. Uh, so steering is something that's brought in no matter what I'm working on. It's just these, these kind of truths to always keep in mind is it's implementing something.
And so, um, the security team, central teams, these, uh, cloud center of excellence is platform engineering, security organizations. They can provide steering that gets in inserted to all of these projects. So that it's just sort of a, a directory of, Hey, remember these things that'll be consulted, uh, as it as it goes and implements things.
So these security requirements, best practices, um, they're, they can actually shift left all the way into the, as the code is being written by finding the right way to hook into, uh, the agentic IDE that's being used like in, in Qro. This would be steering files, You know, as we're in, we're coming into year two of this kinda revolution. I mentioned, uh, NCOI, we talking about vibe coding, and we said at the outset, kind of, you ain't seen nothing yet.
Give us what you mean by that. What do you think we can expect? You know, AWS reinvent is in like a month maybe, right?
Mm-hmm. Yeah. About a month from now.
Um, what, without, I realize you can't, you know, you can't go into announcement. They'll, they'll make it reinvent, but you know, what, what's it, it's usually reinvent is a good forward view into the year ahead from where you sit. What do you think?
Well, if you look at the, the, the pace of things being released, the pace of innovation, kiro being on a, a weekly or biweekly launch cycle with new features coming that often, um, I think that's sort of the, uh, that's what I mean about the acceleration. When you start to use these tools to build these tools, you get this acceleration effect. It's just more and more happens.
Um, if you look at other, um, recent release releases, you, you were talking about, um, you mentioned, uh, no code, low code. We've actually seen some interesting approaches to that, um, in the, uh, Amazon Quick Business Suite, quick Suite, um, this is actually makes it so that, uh, business users can, uh, can have write kind of workflow applications, things that are, that are, uh, kind of a more standard formulaic, uh, ag agentic application, uh, that ties to their business data, uh, right there. So that actually released in the, in the last, uh, couple weeks or yeah, couple weeks.
So I think in, in the lead up to, to reinvent, you're seeing, uh, a theme of, of more and more good application of ENT technology. And, and so I'm excited about reinvent. I'll be there, hopefully, uh, hopefully other folks are there.
Look me up and we can, we can chat. Uh, it's a good, it's a good learning conference to, to, for everybody to, to network and, and learn new techniques. And I'll tell you, there are a lot of, of new techniques to learn new practices like spectrum and development that we need to, to be always, uh, always just improving ourselves as, as developers and learning new practices, how to incorporate security into these practices like you're talking about.
I think these are all very important topics that, that will, I think people should expect to learn a lot about at Reinvent. Absolutely. We'll be there doing video all week, so I'm excited as well as well, we'll have reporters doing stories and our future analysts, they'll be there doing analysis and fact gathering.
So it is, it's a great, great, great event. Reinvent. David, I want to thank you for coming here on Text Drunk TV and talking vibe coding and vibe security with us a little bit.
You know, if we don't speak at reinvent, you have an invitation. Come on anytime you want. We, we talk about this stuff all day, so happy to continue the conversation forward.
Fantastic. Yeah, you're, you're, you're asking some good questions and, and poking out this in the right way, so thanks for spreading the word about it. Thank you.
David Chu, senior principal engineer, AWS Amazon Web Services here on Tech Trunk tv. We're gonna take a break. We'll be back in a minute.
Hey everyone, it's Alan Shimel. Welcome to another episode of the Platform Engineering Show, hosted by me and my friend Luca Luca Deante of the platform engineering community. Luca, how are you my friend?
I'm good. Hey, A everybody good to be here again? Where are you?
And, and soon in person, my coupon soon in person soon in, yes. In what they call the A TLA. The a TL.
Yeah. Yes. I've been, I've been writing a TL all the time in the, in the last, in the last two weeks.
Never been though. So looking forward, it, it's, it's a nice city Atlanta. It's a, it's, you know, they used to call it the capital of the South.
Mm-hmm. Um, I don't know if they still do, but it, it's a nice city. I think you're gonna enjoy Atlanta.
Hot Atlanta. I just pictured it way more central, you know, in my ignorance. I didn't realize it was east.
No, I mean, there is a downtown area like Peachtree Plaza and where CNN Tower is and all that since downtown, but you know, it's one of these typical American cities where it's all about the suburbs and the experts. Yeah. Greater Atlanta, Metro Atlanta spreads out the airport.
Have you ever Massive airport, the airport there? Yeah. Yeah.
I've been, I've been through the airport. Yeah. Yeah.
Yeah. The airport's huge. And you know, it's, I I will tell you, I've missed more planes Atlanta than, than you caught.
Just, I mean, well, just getting to the airport, the traffic could be bad. Okay, that's good to know. Yeah, because I, I have, I have a pretty tight one on Thursday leaving the event.
I need to go see the, believe it or not not if you can, the best way to go is the metro, the, the train. I do believe it. I mean, London is like that.
Yes. London's like that. So Atlanta doesn't have London's metro, but you know, from the airport it's the best way to get into it works.
Yeah. Um, but Luca, why are we in a T CubeCon? So CubeCon CubeCon and the unofficial opening party of Cucu, which is how's a cube?
Um, it's, um, I don't know if I ever told you, but like this, this like, basically started as a joke, um, with Casper like five years ago when we were at a, a Cuon Valencia, um, which was like a very nice cuon. That was like my first cube. I I loved that cuon.
Yeah. Because you, you know, you would just like walk out. It was sunny, even in though it was like February or March, it was sunny.
You could go have like tapas beach 20 degrees. It was great. Yeah.
Yeah. So I love that. But you know, then you're like, man, we're like around this like nice Spanish city, good vibe.
And then like, a lot of the party was just like this boring corporate stuff, you know? And so we're like, well, what if we just did like, um, 'cause you know, we're like Berlin based, so like, what if we did like the, like the, a techno thing? Um, and so, and that's how it started.
And, and, and it was, it's funny because the next, um, uh, Q con after that was Detroit, which is also famous for techno. Right. And there's this like Berlin Detroit connection.
Um, and so we're like, okay, we'll do it there. And it was like 80 people, and it was basically like a big house party. Um, but fast forward to now, like the, the last one we did in London was like 6,000 registrations and like 1500 people through the door.
So it was a proper rave. Yeah. Like, there was, at some point there were this like, um, like animals that we like spray painted in this like psychedelic colors.
And I just like, I just like turned a corner at like 1:00 AM or something, and they were like, crowd surfing the animals. Really people, people get pretty wild. It's fun.
Yeah. Um, I don't know, I, I'm being, you know, typically the European cube cons have more attendees. Yes.
The North American, but they're close. I, I haven't heard anything from the CNCF in terms of what they're expecting. I think it's low.
Yeah. I can see it now. Because like with, with, uh, with Ha Cube, we essentially capture always as a rule of thumb, like a third to half of the conference, um, in terms of people that sign up and, and, and, and, and the numbers are low.
So I think it's gonna be smaller than Salt Lake City. Really? Hmm.
That's surprising. 'cause if you remember it, it snowed in Salt Lake City, though. It, I heard it's gonna be cold in a TL but new, new Trump administration as well.
Right? Like, I think it's, there's a lot of people that, I think that's in the other thing, it puts a damper on on people flying in international, even from international, from national. You know, it's, it's a hassle getting it in the US now, and it's a shame.
Yeah. I mean, I'm not worried, you know, but I, I've, I've talked to a lot of people that are like, very worried. 'cause they hear this like, horror stores of people being detained, blah, blah.
So, and everything else, which is, if you look at the numbers, it's like, it's like being, you know, striked by lightning anyway. But it's like, but still, you know, people are worried. So I think that also having an effect.
I think it's also people voting with their feet. Mm, yeah. Yeah.
Yeah. You know, we, we just had an election here off year elections, just not too many big races, but I think people voted pretty clearly. They're not real happy.
Yeah. Uh, what's going on? But that, that's a shame to tell you the truth.
'cause Atlanta is a great host city, and it, and the, the, the World Congress Center where they got this, where the event is, is actually a pretty nice, uh, nice. Well, I can't wait. I'm excited.
Absolutely. And there's, there's gonna be some great, um, learning going on, some great sessions. You know, we did our cloud native con virtual event last week as sort of a Q con preview, and we had, I think it's one of the first times he's actually presented the new D from CNCF.
Yeah. Uh, he, he did a nice presentation there and, um, we'll, we'll see. I mean, look, regardless of how many people are there, the generally the enthusiasm and passion for all cloud native and open is, is, is high.
Right? So I fully expect that. And all things platform engineering, I think that's one, one of the still fastest growing narratives within like CNCF and, and, and CubeCon.
Like the, so you and I are gonna be the platform engineering day. Uh, yes. The, I think as a co-located the, the day before it starts.
Yeah. And that's typically one of the biggest, right? Yeah.
Of co-located. Yeah. That Backstage Con is another of the big ones.
Yeah. But it's top three I think at this point. Yeah.
You know, it's funny, I, I was talking to some folks from suse Yeah. That I was just talking to some people at SUSE today. Are you?
Oh, very cool. Yeah, I spoke to, I lied, I speak to SUSE all the time, but I was talking, uh, yesterday to their, uh, general manager for their container business, Uhhuh. And, um, you know, it was interesting to hear and, and, and there's backup.
I also last week, spoke to some folks at IBM. Mm-hmm. Even in suse, it's interesting to hear how these larger companies look at the connection between like cloud native DevOps, platform engineering, right?
It's like almost the, they have like, the personas of these, of those three areas are so tightly interlocked, right? Mm-hmm. And they're, and they're key.
They're key to all, you know, all three of those are key to suse, key to IBM, IBM's making a big push in developers again. Yeah. Um, platform engineering is, is huge to them, as it is to suse.
And of course, the whole cloud native, they view as the, as the new stack. Yeah. Well, absolutely.
I mean, I was talking to, I think a, a shared friend now, pine Cash at, at Broadcom as well about this, right? Mm-hmm. Um, and, and, and, and also like a few folks at Red Hat, right?
Like, 'cause I think, you know, we've talked a lot about this idea of, of Puff for engineering being this multi-stakeholder, you know, a multiplayer game that you need to solve essentially in the enterprise. And, and I think that's where all these, this like big, ultimately, big platform slash ecosystem players are realizing it's like, okay, uh, it's just getting more complex. I can no longer just focus on like a subset of these personas.
I really need to take them all on board. And so with that, to your point, it's like, okay, DevOps the platform engineer, but then also I need to like revamp my, um, developer application. Developer narrative, right?
Um, it's very, very interesting. And, and then, uh, I, I think another trend that, at least that I'm seeing Luca, is, you know, cloud Native Con was called CubeCon. 'cause it was all about the Cube, right?
Yeah. We're, but we're seeing observability, right? We talk about what are the biggest, uh, you know, zero day events.
So, you know, pre events. What are the biggest, what are the biggest projects that CNCF is, is managing these days? Well, certainly coop's still big.
The biggest well Open telemetry is like open right up there with, with Kubernetes. Now Berthe is right up there. Yeah.
You get the Grafana stuff, you know, it, it's that, that whole observability, which now then brings in security with a big way, right? Yes. 'cause a lot of securities, you know, based on that.
Um, so the whole cloud native community, I mean, when we did Valencia, and that wasn't that long ago, right? What was Valencia four, four years ago? Four or five my, that it was still very cube based, right?
It was Cube, very developer based, you know, the ops people, the platform engineers, all of these things are now a big part of Yeah. Of, of the, well, and you could see I think in the crowd as well, right? Like, um, and this is actually an interesting thing 'cause we're just talking about the fact that, you know, like Europe usually is a little bit bigger.
Whoa. I think that's true. Um, at least like, at least I heard that's been like post COVID, like pre COVID apparently like us was bigger.
Pre COVID San Diego, and then yeah, everybody says San Diego. But then I'm also like, of course San Diego was bigger than like Detroit and Chicago. So what?
I gotta be honest, it didn't suck in San Diego, Luca. Yeah. We had a big old, we rented a big old Airbnb and John Willis amazing.
There. We we bought a whole bunch of guitars and, uh, what's his name from, from the DevOps movement as well? Um, uh, Adam Clay, Schafer Uhhuh.
Yeah, yeah, yeah. He came and Brian, that we, we had a jam out party at this Airbnb. That's awesome.
Where we were staying. That's awesome. It, it was, yeah.
That, that didn't suck. But, um, but, but that's what I'm seeing. You know, like I'm seeing this, this, there's also this, this, um, maturity, you know, that's like changing a lot.
And that's, I think, like, while what I wanna say is like, while um, you is bigger, I do think that, um, it's still a little bit behind, uh, slightly in terms of maturity. What I see in the US is like, you now have like maybe fewer people, but it's all like very senior enterprise practitioners that are coming with like very high intent to CubeCon of like, Hey, they know, they know what they're, they're looking for. Yeah.
They know what they're looking for. They know their problems. And I think, you know, to your point, CubeCon is then adapting in terms of like the format and the content offering to be, you know, to mature past just the pure open source plays into like, okay, but how do you actually apply, you know, more observability, more security.
It's just like more enterprise grade essentially. Abso you know, it's funny you say that. I was talking to another person maybe last week, uh, about CubeCon around cloud native con the, the virtual event we did.
And they said, you know, you could tell the maturity by how people address it. Yeah. In past cube cons, the average guy would, you know, the hoodie, the guy was a t-shirt with a backpack.
Right? Right. And then all of a sudden you saw less t-shirts and backpacks and more like buttoned collar shirts.
Now you see people wearing sports jackets, you know? Yeah. And carrying, you know, portfolios and so forth.
And, and, and so that is, I think, an indication of, of who they're aiming at, who's coming to these things, who Yes. Right. Who decision makers are.
Yeah. Yeah, yeah. The industrialization.
Yeah. Yeah. Um, of course, Luca AI is, is on top of everyone's mind with, you know, uh, cloud native, AI native, cloud native ai, and platform engineering.
I know you've been doing some, preparing some new material to take on the road with you and stuff. Give us a little quick Yeah. Talk to us.
Let me actually, we, we never do this, right? But like, I thought we could actually do some screen sharing today. Um, and, um, yeah.
Here, um, and yeah, this is like, this is like one opening that I did. Um, so recently we just talked about, uh, it's funny 'cause we literal just said the word industrialization as well. Um, but, but, but this is like, um, you know, we recently had Platform Con Live Day in Paris, um, and, and on stage, you know, like we said the last time, we talked a lot about, you know, what can, how, you know, a AI is, is sort of, you know, if it wasn't for ai, platform engineering would be the hottest trend in, in, in, in enterprise today.
Uh, and, and I think actually juxtaposing them that way is not the, the full story. The full story is actually how they can, how can they collaborate together, um, to be the, the, the hottest thing in enterprise today, and to make sure that AI can really deliver on its promise in the enterprise. And, and so, and, and I started with this because this is like, um, you know, like if, if a a few people, you know, I heard now at this point of this idea of like, AI is this like steam engine moment, you know?
Um, and so I actually wanted to go back and look at the, at the real industrial revolutions. Um, and, and so like, I did like a little, a little like, uh, uh, history walkthrough, which I'm not gonna cover entirely. But the, but I think the interesting thing is if you see, you know, if you go back, essentially what you see is like, you always have this like technological innovation that then triggers in a sort of a cultural organizational innovation, right?
So people are now like, okay, what do I do with this, um, with this new thing, you know, that is enabling a bunch of new workflows and products and whatever. And, and you could see actually that happened with, with the steam, with the steam engine, you essentially had the, the first, the people, we basically, you had a, a geographic concentration from a bunch of sort of like decentralized, uh, artisanal shops, really, right? Um, into, okay, now everybody's in this big building around this big machine, and then, you know, we're doing things.
0 that actually took another a hundred years or something to, to hit that. You literally had this like big inflection point, you know, of, of, uh, you know, going from like, just some sort of, you know, organizational reaction to this new technology to actually this like balance of social technical, which is this, this, this concept that we've talked a lot about in platform engineering, right? Of this idea of like, you know, balancing the, the technical, uh, elements with the, with the cultural elements.
And that's really when you actually hit mass adoption and global scale with, you know, both in terms of factories, but also in terms of the output of factories. And you're really ushered in like, you know, the modern consumer era essentially. Um, and, and so you can kind of think about it this way, right?
In terms of these two cones of like, you know, you have technological innovations that then influence the organization innovation, but oftentimes they kind of run in parallel. And then when you hit this like, sweet spot, that's really when you, you, you kind of like hit the inflection point in terms of growth. And I would argue you could essentially show the same thing, and I'm gonna skip through the presentation here, um, with, with ai, right?
Um, where essentially you've had this, you know, technological innovations, um, and you could even try here pre ai, right? Where you had like CPUs and clouds and so on. And we as an industry have tried to adapt to that, right?
Like we had Waterfall, we had Agile and so on, but it's really with platform engineering that we kind of hit that balance, and that really enables that industrialization moment of, of the, of, of the entire industry. And, you know, you essentially can layer on top of this, these GPUs. I mean, ultimately GPUs are kind of just like an iteration on CPUs, right?
Um, and, um, you know, but, but really we are, the, the, the interesting thing is that we already have this, this foundation now, and so we can, I think, you know, leveraging everything we've learned with platform engineering today, apply as a foundational framework for AI and really move, you know, avoid the whole like, you know, soul searching and, and really hit like enterprise grade very, very quickly. So it, it, you know, if, if you study this stuff in school, right? The first industrial revolution was the steam engine.
Mm-hmm. And, and it did take, you know, that was a little bit full as Folly or whatever they called it, Fulton's folly. And, um, it, it did, it, it took almost a hundred years for the steam engine to kind of find its place really, really just upend.
It was in a truly a revolutionary, right? Yes. You started with locomotives, with trains and how that opened up stuff, and then the modern factory and steamships and all that.
It took almost a hundred years. Then if you go from the time of the modern factory to let's say Ford's assembly line, that probably got cut down to 70 years, 60 years. Yes.
And, and they call that the second industrial revolution. Yes. Right?
That's what you have there, two. Oh. But it really didn't reach its zenif until like you had on your slide there, I noticed Lean, lean manufacturing.
That's really 1950s already, right? Yeah, yeah, yeah. Deming and Kaan, ka ka katana and stuff like that.
So it took another 40, 50 years for it to kind of fully blossom. Exactly. Then right around the end of the fifties, you had really to, to the early sixties, the third industrial revolution, which is electronics, right.
The digital age. And it has taken us, so figure, let, let's say 65 is, is a number, right? Mm-hmm.
1965. Yeah. It keeps compressing, right?
Right. It only took, I mean, from 65 to the commercialization of the internet is 30 years. Yes.
By 1995, the internet goes commercial. So in 30 years, we were able to, to digest that technological innovation revolution and convert it into a societal civilization kinda shaking revolution. Now, here we are 25 years later, right.
And now you've got AI ready to disrupt, but, but there's more, but wait, there's more. Right? You've got ai, you've got what we're calling physical ai, robotics or robotics.
Exactly. I don't know if you've been seeing some of these things from like figure and Tesla Yeah. And some of the new robots, the next gen, and then you've got Quantum, which is we are right on the cusp of Q Day.
Right. Those three things promise it won't be just a fourth industrial revolution. It may be a fifth and fourth and fifth combined.
Yeah. Within exactly. Years from each other that's gonna blow this thing up.
That's gonna change. You want to talk about platforms, talk about autonomous platforms, talk about, you know, really intelligent platforms. You know what, I, I saw a study from the uk, they think by like, uh, 2030 to 2035, 70%, seven out of every 10 jobs done ai.
Um, you know, what does that mean for, so yeah. Had it not been for AI platform engineering be the hottest thing out there, but the reality is we all have to internalize AI into everything we're doing because Exactly. It's a new, and, and, but, but, but I think the interesting thing is like, you know, while, you know, like we said, right?
Like it always took so long, uh, before we were able to essentially leverage these new technologies in a productive, standardized, industrialized way, right? And I think like the opportunity that we have here, at least on, you know, in our small world of kinda like it and enterprise, it is like, well, look, we already have the foundations to, to take this, you know, and, and the principles, right? To take this and, and, and like skip the soul searching part and just going straight to like industrial scale.
Um, and, and I think that's the tension that I see right now on the field, right? Like you mentioned, um, the last time this, this like, uh, MIT study, right? Where like 95% of like pilots failed.
And I think now there's like other studies saying like different things, right? And there's distention because I think, you know, there are some people that are just doing, you know, wishy-washy AI implementations and like, you know, the demo looks really good. And then how do you go from the demo to day to day two operations, which is where you create the real value.
Who knows? You know, and people that are like, oh, wait, I can actually use the same, you know, best practices and, you know, platform as a pro, you know, the same concepts. Um, and, and that's actually how you go to day to day two and day 100 operations.
And that's actually how you create value. And you mo you move past this like, you know, initial impressive demo that then doesn't really go anywhere. You know, I know ITIL and the whole, you know, it, service management is considered old school, but there's lessons to be learned from itil, which is if everything you're doing is a one-off, that's all you're gonna have is a bunch of one-offs.
Yeah. Right? You, you've, if you don't have process in place, if you don't have platform in place with repeatable processes, with repeatable practices, you, you're destined to live in that MIT study world forever, where 95% of it is, is a failure.
But, but again, that's part of the evolution that sometimes takes a long time, but now it takes even less time, uh, is moving from the one off, from the experiment to, to the, to the assembly line. Right. To the assembly line.
Because every one of these industrial revolutions builds on what came before it, right? Absolutely. And at this point, we, we have the foundation to, to, to build quickly with it.
Look, it, it's going to look at, you're younger than me, you're going to have to deal with this. I, I probably won't. Um, but I, I wondered, what do you hear from, from the community, Luke?
Are they worried about job loss? Are they worried about is AI gonna replace them or is how is AI gonna change their day to day? I think it, it, it, it, what I'm seeing is like this, this, uh, split right between people that are really embracing it and people that are just like, um, um, not acknowledging that it's even happening, you know?
Um, there is some, like, I, I'll send it to you. Uh, somebody forwarded me this like Reddit thread, which was hilarious because it was like somebody asking something and then like, people being like, well, but you're aware. You can basically, you know, do with that.
And, and, and all these, all these people immediately, like downvoting, everything, every comment that was like, bro, like you can solve this with AI either now or very soon. And just like being completely downvoted, uh, which is like, why would you down vote somebody? You know?
It's like, um, and, and, and it's just like, I think it speaks to the fear that a lot of people have, especially, and I think this caught me, I think, to an extent, off guard. And I think a lot of the, the, the white collar industry, um, you know, if you wanna call it that, because I think like the common narrative, right? Like I, I, I, I was listening to a podcast really interesting about this, right?
Because we as humans perceive that, you know, white collar jobs, you know, like software you use, your brain is like harder, you know? And it takes more time to learn than, you know, driving a car or driving a truck, right? But the funny thing is, like, for for LLMs, it's the other way around.
Uh, you know, so it's like, actually it, it's like this, this like knowledge and like bits based stuff, um, which again, like they don't really understand, but they can replicate so well. That is essentially, it's like they, they're doing it. Um, you know, and, and so the funny thing is, I think we've all been told the story of like, you know, oh, the truck drivers are gonna use their job and like, look, maybe the truck drivers, because now you have like Tesla semis and like, you know Right.
You have autonomous driving. You actually do have autonomous driving, but I'm not gonna lose their job. The plumbers, the electricians Exactly.
Carpenters everything that is like moving atoms, you know, is like, is gonna be, uh, rewarded and everything that is like moving bits right. Is basically gonna be replaced. Um, and, but that's, that's the, the paradox here is for the first time service workers Yes.
Are threatened with obsolete being obsolete. Right? Exactly.
And I'm sure there's a lot of plumbers and electricians are, you know, saying, how does it feel? Right? Yeah.
Well, that's the thing. There's not many of them, and the few of them are, are about to make a lot of money. Yeah.
Abso and it, quite frankly, it's the same thing, right? We're gonna spend $3 trillion on data centers in the next couple years, next two, three years. I mean, yeah.
Crazy amount of money. 8 trillion, actually. Yeah.
But these aren't the data centers that I was managing and operating in 1999. There's very few people in these data centers, right? The, the jobs that the data center creates are mostly the construction jobs and building that.
Yes. Yes. Once they're built, yeah.
There's not a lot of people in those data centers. No. Um, so it, it, it is gonna be interesting.
But look, so I, I think anyone who ignores AI and all of this ignores it at their own peril, right? You've gotta embrace it. Mm-hmm.
Because things like platform engineering for things like platforms for developer platforms for software, you know, there's gonna be such possibilities. Things that we're gonna be able to do that we couldn't do three years ago. Yeah.
That, you know, it, I, I still think this is the most exciting time to be alive and in this than ever. Like, I'm a hundred percent, a hundred percent agree. You know, like just new jobs.
Like, like, you know, like 50 years ago nobody had heard about like a content creator. Yeah. You know, and, and the funny thing is, like now we have a lot of content creators that will probably be disrupted.
And so there's not gonna be any content creators anymore in like 10 years. Ah, but it's gonna be something else, you know? So, we'll, we'll see.
Yeah. See where it goes. Luca, we will see you in, uh, in Atlanta.
'cause we a TLA hot Atlanta, a TL. We've got House of Cube on Monday night. How Yes.
Can people still register? Yeah. Yeah.
People can still register. Um, it's free. Um, and it's open bar, uh, grape food, great drinks all night.
Where can they go? com, uh, to sign up, and then you'll get all the info there. Uh, the only thing I would recommend people to come early, um, 'cause we normally have about a thousand people standing outside of the door, so the, the earlier the better.
Very cool. And then, as you said, you'll be kind of monitoring the PE event on Monday as well as the, uh, uh, backstage, what is it? Open Backstage?
What do they call? Backstage Con, uh, backstage Con is there. And then, you know, maybe, yeah, maybe we should check hotel since it's growing, uh, so much and I don't know.
Yeah. We'll, but we'll be around then. You're gonna come by our, our stand over there and we'll do a, we'll do a live stream.
Let's do it from a TL. Let's do it. Let's do it.
Maybe Tuesday, Wednesday. Yeah, we'd love to Alrightyy. Hey, Luca.
Have safe, safe flight over here. Yes. Here.
It's going to be cold in Atlanta, so just won't I know. They just sent me the screen show. I was like, damnit, because this week was great this week.
You still had like ign. Yeah. So Atlanta usually one time a year will get like, ice or, and a little bit of snow, but the littlest bit of snow or ice shuts that town down.
Um, they just can't. They're not, they're not built for that. Right.
But it's not gonna be that cold, you know, at night. It'll, no, no. A colder.
Yeah. Yeah. It's, but it's like, it goes down to like three als so.
Yeah. Pretty cold. Look, if it gets too cold, Luca, I'm only an hour, hour and 20 minute flight from the, Hey, I told you I'm flying directly to Sao Paulo, so you'll be fine.
It's gonna, but it's gonna be like a, like a funny, a funny packing for sure. Absolutely. You're gonna need a little of this.
A little of that. Yeah. All right, my friend.
I will see you in Atlanta. See you next week was posted. Thank you for listening.
We will continue the conversation in Atlanta, but for now, that's this, uh, edition of the Platform Engineering Show. Bye-Bye everyone. Hi.
Welcome everybody. Thanks for joining me for this talk at DevOps experience. My name is Mitch Ashley and I'm with the Turing Group.
I lead the software lifecycle engineering analyst practice and get a great good opportunity to talk to vendors and practitioners about what's happening in the market. Now, let's talk about ai, of course, but how that's affecting us or will affect us, uh, in our work. Of course, the whole attention, really for the last two years around AI has been either chatbots, but when you talk about AI and development, the story's always been about writing code, writing code, faster, right?
Vibe, coding, all kinds of different terms. AI first, AI native, uh, et cetera. And of course, yeah, that's a lot of interest.
Can, can AI write more code better, faster, higher quality, whatever. Sometimes there's some debate about that or, or vulnerabilities in it. But I wanna focus beyond that.
'cause not all of us are vibe coding, or will be vibe coding or writing code with ai. It may be writing code for us to do work, but that's not necessarily what's happening. And we've seen a shift in the market, particularly in the last, let's say, three to six months, especially.
But, you know, as anticipated, I've, I've said for some time, the real value of AI isn't in improving the productivity of one individual. It's improving productivity about how work happens when that usually means it's teams, it's teams of people. And so we've seen a lot of progress just in the last few months around open standards to help vendors work with their interoperability between each other and getting access to information via things like model, model context, protocol server, et cetera.
Uh, but there's also, uh, a lot of things that are happening in the market on the vendor side, where we're seeing AI intro being, being introduced in products across the software development lifecycle. So this talk is about where is that happening and why is it, why is it happening the way it is? And what can we expect to see over the coming months kinda looking forward?
So let's talk a little bit about why the shift. First of all, of course, LLMs are starting to mature and they're adding more constant capabilities. Maybe even tough for some of us to keep track of what the latest LLM does and what it, what work it's good for.
But there tend to be some, you know, things about what, what LLMs are really good for, uh, doing coding. 5. Could be of course, um, O OpenAI, OpenAI, uh, GBT four or five, whatever your preference is.
There are some good models for coding, but what really we're looking for is what kind of work can those L LLMs do for us? And are they model, if you will, can we use different, uh, agents to talk to those LLMs to perform work for us? And do we trust the work that they're gonna be doing for us?
I'm gonna talk about that trust issue a little bit more here. There's also economic pressures, you know, and all the way up to the CCEO in the boardroom. Organizations are making big bets, maybe even big claims around their investment in ai.
And frankly, now is the time to deliver, stand up and deliver as, as the movie title is. Uh, organizations are looking on being able to, looking to be able to demonstrate some real value from their AI investments. Doesn't mean they have to solve the world's problem and doesn't have to raise, uh, you know, drop cost by 10% or raise, uh, revenue by 40%.
We're looking for just some places where we think AI can add value and benefit to the business that is really tangible, and in some cases, monetizable. We also have sort of the developer and ops fatigue that's ongoing. You know, whether it's alert, fatigue and operations, or it's in the development world.
We need more fa more software, you know, quicker, better, faster. Uh, we're expected to deliver more capabilities, but still have it be secure and of high quality. So I, I think the takeaway here is, let's think about AI not as a tool for writing software, but a tool for how far can it help us across the software development lifecycle, and where, where can we use the most help?
And that's actually what I'm hearing a lot from vendors as I talk to different vendors across the software develop lifecycle, what problems they're tackling with ai, which is both an indication of what they hear from customers as well as what they think their they're differentiators might be around, uh, implementing a ai. So there's a couple of themes I wanna go over in terms of what we're seeing today to frame some of the comments about what I'm making. Uh, first of all, we want to deliver lifecycle outcomes, not just speed of coding.
We have to focus on delivery, security and operations. And delivery can be implementation all the way into pushing, uh, applications and software into testing and production environments. Customers also are looking to still, to avoid vendor lock-in.
There's a lot of interest in being able to use the model preference or open source model, whatever might be. But they also don't want to get locked into a vendor's framework, uh, particular vendor environment. Now, there's some things that are a bit unavoidable.
You start developing agents in a particular vendor's, uh, environment, they're probably gonna need to run in those environments. So there is some decisions around what you decide around vendors, but there's also open standards like model context protocol, and, uh, agent to agent that are the two most prominent, get the most attention right now of giving you access to external information from models, as well as starting to do some of the, uh, coordination or communication between agents. And there's a third one actually, agent communication protocol protocol, which is also about that.
Uh, last but not least, is understanding that we have to not only improve productivity or improve output, fix problems, whatever it might be we're using AI for, but we also have to address security and governance. And honestly, this is often a, a place where we forget to address that until we have to. And I don't know that AI will necessarily be different, but if you believe some of the projections around how much software we'll be able to create using ai, I mean, just generating code, I mean producing it through the whole lifecycle, that means a lot of the governance and security will have to be automated.
We don't have enough people on the planet, my view, to fix every vulnerability that might be introduced by an LLM or a human or combination of both. And of course, we need audit trails and humans in the loop to do that. I call it human driving The loop to be able to really direct AI is where we're heading.
So, trend number one, I'm gonna talk about moving from conversational AI to putting AI to work or agents that actually perform work. And we're seeing some of the first generation of tools, um, next gen agents if you want to think of that, that are actually performing work. Now, I'm not claiming they're doing, you know, you know, gobs and gobs of work or taking out huge manual tasks that we can now automate fully with ai.
Certainly we would like to move to more of that direction, but there's some been announcements I think worth pointing out that I think you should follow, certainly that I'm following, to see where there are advancements across the lifecycle. So in the development world, not just generating code, but, um, Microsoft announced their agentic DevOps initiative at build, uh, 25 conference back in May. And it's a built around their, uh, copilot agent mode that's about fixing bugs, reviewing code, modernizing apps, running, you know, pushing things into deployment.
And we're seeing some progress moving towards that. An easy thing to step into for vendors is code review, because they're not only, you know, analyzing code as part of the development cycle. They can also do code assessments, feedback, things like that, but also taking on more tasks that initially developers are performing, but then moving to things that might happen beyond just an individual developer or team.
So I expect we'll see more of that entering into the DevOps cycle. DevOps tools beyond just the coding portions of this. Of course, GitHub copilot agent is part of this as well.
Um, there's been some upgrades, I think as recently as AAU as August around, um, doing pull requests, iterating on code, things like that. A GitLab who is more of a platform approach, you know, across full platform for DevSecOps as they do do a agent platform, which is designed to help refactor code, but also scan for vulnerability, generate tests, optimize processes around CICD pipelines, things like that. Again, these are stage setting for where these technologies are going and some of those capabilities.
com Con conference, Boston, and there are a number of AI announcements around Splunk and Cisco. Uh, but they also have introduced some AI troubleshooting agents, uh, as well as Dynatrace is, has as well, also with their Davis AI agent, AI around investigating alerts, doing better correlation planning around some remediation. Now it isn't automated yet.
Maybe we can invoke some predefined scripts in some cases, but it's not yet quite a gally, uh, doing its own process of resolving issues. Uh, plummy Neo actually just introduced, uh, by Plumy, uh, is their AI platform for engineering platform engineering to execute, do some governance and optimizing around cloud infrastructure. So those are some, so let's call 'em first volleys of moving significantly beyond just the code generation.
Part of what AI does for us and moving is, uh, beyond not, instead of, but beyond doing conversational chat bot or natural language interface to query about what code does or asking an agent to do something or a LLM to do something for us. Second, trend number two, AI embedded in workflows rather than Bolton. I, I've described AI as moving from the phase of, we have chatbot and, and natural language interfaces.
We have kind of bolted on, we've added AI into our products. There's sort of a feature built in, or maybe even behind the scenes. It's, it's, you know, we're benefiting from ai, maybe it's doing more machine learning kinds of activities.
Now we're starting to see AI that's really embedded or part of workflows or processes that technologies from vendors are starting to, to deliberate some, some examples of that. Uh, GitHub announced both AI integration into actions as well as GitHub's multi-model ecosystem for access to multiple LLM models from different providers. The, uh, integration actions is really designed around auto issue, triage, release notes, doing smarter CICD workflows and Microsoft software around Azure AI factory in Okta in September as released.
Some things about, uh, model router and also browser automation, uh, for model selections. We're seeing some more activity around, uh, integrating the models into not just using a model, but deciding what the best model is for a particular task. Atlassian, who's really started with their, um, with their rvo agent technology, uh, introduced earlier this year at the lasting team conference in North America, has also introduced in June, JIRA AI workflow breakdown, which is a process that auto decomposes epics in the, in the, uh, uh, in the process of, uh, analyzing what new requests are for code features, things like that.
And also some sensitive data detection, uh, to help build in governance. So as you're putting things in there in, in the ethics and the design and into Jira, those workflows to make sure you're protecting things like privacy, things like that confidentiality. Uh, interestingly enough for, for some, it was a bit of a head scratcher.
Atlassian also announced, uh, their intent to acquire the browser company, uh, and getting into the browser business, then you might think, why would Atlassian wanna be a browser company? Doesn't Google kind of have that sewn up? Well, there are a number of companies, including Google, who are investing in the next generation of browsers that are really built around to be AI centric, to be built around agents and technologies rather than AI being built into the browser to be able to control what the browser's doing.
And, and this is a bit of a bet, I think a pretty big bet by Atlassian that we don't know what the, uh, what the current browser leaders are gonna do, but they could favor themselves and, and cut out some other people who are building and technology in a bit of a way for Atlassian to control their own destiny. Maybe it ends up they don't have to do that, but it certainly is a, at a minimum, it's a hedge to their bet. I think it's more of a strategic buy as well as a talent acquisition to, to bring that technology into the fold with Atlassian.
So, so the meaning behind this is, you know, at chatbots were really our training wheels and AI is now moving into more of a native automation work surface being more tightly coupled, or at least becoming, starting to become more coupled with CICD use of planning boards and also some operational pipelines. We'll get into some more operational features here next. So let's talk about trend number three, simplifying operations and scaling ai.
Microsoft, as I mentioned, introduced their agent DevOps concept. I'm sure we'll be hearing more about that over time here as they've continued to roll that. But that's also included, you know, Azure, Azure SRE agents during production.
And, uh, and at some point autonomously or, or at least partially respond to incidents that are happening that are detected in that area. Um, ServiceNow, uh, who has made a couple of announcements. Um, one of them is their AI control center, uh, which is a centralized governance point for agents and agent workflows.
So you actually have a control point for what are the agents that are active, what are the security levels that they have within your organization, and what work are they performing, if you will. Now, this is actually a ServiceNow announced the AI control tower as part of their agent, uh, build technology, ServiceNow build agent, which helps create agents as part of the, through natural language, as part of the workflow that ServiceNow currently has in their technology. So they're not kind of throwing the baby out with the bath water, they're adding agent capability.
This task is actually something, instead of building a process in the, in the windowing interface, here's a way where we can actually assign it to an agent and give it extra instructions with natural language control center is the way to, to manage that. Docker also introduced something called Docker offload that shifts GPU Center AI workloads to the, to the cloud, rather than having to build or re-architect an environment locally to run for testing, for development, for production, uh, or new workloads that are incorporating AI into the applications themselves that are GPU intensive, maybe not just for learning things, but also, uh, to do, uh, to more processing kinds of activities, inference level, if you will. BMC, uh, helix AIOps, uh, they introduced this summer, some hand enhancements to that around event clustering.
Um, also automated remediation around alert noise. Again, when I say automated, I'm not saying fully automated, but some automations in these technologies that we're seeing. Dynatrace, Davis and Splunk, as I mentioned, AI troubleshooting agents, uh, also are, it kind of fall into this category again, I, that I mentioned earlier around trying to reduce the manual investigation and, and help work towards more of a more resilient automated type processes.
So the meaning behind all of this trend, or why is this happening, is vendors are looking at where they can attack some of the operational complexity, whether it's alert, fatigue, noise automations, things that require manual response, isn't necessarily that AI is, is being the smartest bot in the room, if you will, about solving the toughest problems. But let's take things off the table that can free up people, um, from processing, dealing with, trying to assess and manage alerts or more manual tasks and start to address also some of the governance or governance of control of this as well. So let's move on to trend number four.
Security found means fixed. And I say that, or as an early sense of not, not that it's all that way, but we wanna, we really wanna move security beyond better information or more concise processed information for you. Yes, we need great information or what's happening, uh, in a security incident and tracking down what the issue was, et cetera.
Uh, but we also need AI to start to do workforce in fixing issues and move from more of a found versus fixed mode. Uh, GitHub security made enhancements in August around scanning AI prompt for secrets. You know, that's just one small thing, but again, uh, helping remove some of those things that, uh, we are embedded.
And now the code that is prompts as well as code that we create, uh, Docker AI vulnerability remediation, uh, is works around hardening docker files at build time to make sure that they're more secure. Splunk also announced their agent sock in early September. Uh, again, Dynatrace as their Davis ai.
Other, other observability systems, of course, are introducing new capabilities around automated the scripted incident response, uh, based on some predefined test cases and conditions. And we'll see more automated over time as trust gets built into these agents. Perforce actually an interesting different kind of announcement, uh, made announcements around their, uh, Delphix AI synthetic data generation in September with the ability to produce, uh, more compliant test data that is compliant for accuracy and regulatory requirements.
It's one thing to generate synthetic data, it's another to make sure that it is not letting any private or confidential information personal, uh, PII information leaking into that synthetic data. So they have an interesting product that they've released. So, again, as we, if we think about security, um, there are automated tasks to help us filter through and manage the quantity information, that's certainly a benefit.
I think the real benefit is as we're able to hand early basic tasks to be handled by ai, bots start to begin to address more complexity as those become more sophisticated and also the trust is built. So let's talk about some strategic guidance for the vendor community. 'cause even the folks that are trying to balance the shift of how do we introduce new AI capabilities in my products?
How do I not introduce AI in a way that becomes a failure or a problem for my customers, while at the same time doing a lot of, uh, a lot of innovation and trying to be a leader in the market as they, as they add AI or build new AI capabilities. So, first of all, think about, you know, AI as a shift from a product strategy to an SDLC strategy. So think about not just features, um, but think about how AI is delivering better outcomes for customers in the software development lifecycle.
Whether that's delivery of software into testing, testing the software, uh, and putting it in production, the security of that, how it's manageable, um, the operations of it versus more than just faster code or creating code faster. 'cause we can't just create and the next technical debt or mountain of code that isn't also secure that we can get into production and operate it. We have to have AI help us with that as well.
I mentioned earlier the avoiding a lock in. Yes, everyone vendor wants stickiness in their products. That needs to be because of the benefits that it has, not because once you're in, it's tough to get out.
They, customers do need to work within a multi-vendor ecosystem, but they also expect to benefit from open standards. I mentioned MCP and H two A earlier. Uh, it, it is a multivendor ecosystem that we work on today.
And I don't see vendors, or excuse me, don't see customers signing up to say, I'm just gonna go all in on one thing and I'll agree to live there and just kinda ride that one vendor to hope that they, um, have my best interest at heart. The third thing is prioritizing built in security and governance. Now's the time to build in the transparency audit trails where human is in the loop where human is, is driving the loop or leading the loop controlling what, uh, agents are doing or AI is doing so we can earn trust.
Which brings me to the last topic that I wanna talk about. Moving at the speed of trust. That's a, that's an old concept from Stephen Covey book, um, wrote, interestingly enough, a, as we're introducing AI into more and more processes, we're looking to automate things with AI, with agents.
Maybe they're single step, maybe they're multi-step, maybe they're more agentic automated, uh, with less supervision. Uh, as we do that, we've got to focus on earning trust, not just by the capability that they provide, but also by the explainability and accountability of what those AI technologies are doing. Frankly, the biggest failure a vendor can have is introducing new a AI capability that suddenly deletes a production database or causes a quality issue in software that now we don't trust.
Whether it's going to be able to deliver better software versus lower quality or less secure software for that matter. You know, there are edge cases that'll know, certainly get the attention in the press and we'll hear about, but customers need to be able to, to trust the AI and what it's doing for us. As I talk to platform engineers, as I talk to security people, as I talked to ai, excuse me, uh, software testers, quality assurance people, it's all about trust.
They're like, this is all interesting. I wanna be on the forefront of knowing how to leverage this technology, but I don't trust it yet. Um, which means it's a process to moving into being able to automate things, but also it's important to decide what you automate using ai.
You know, don't bent the bank on the first couple of AI automations or agents that you create either in your product or what you do with that particular product. Help customers move into a world where they're gonna be able to see what AI is doing with it. And I wanna single out ServiceNow.
I think their AI control center is the act, exactly the kind of thing that I'm talking about. It's not just about what a single, uh, ai, uh, agent or bot is doing for you, but also be able to get a, a bigger horizon, bigger field of view on what's happening with AI across workflow and processes. So I can't emphasize that enough.
It's moving at the speed of trust that trust your customers and have what you're doing with ai. So what should we be watching for in the next, let's say, 90 days or so? I would certainly look to see some early production uses.
Um, some agent pipelines. There's gene, uh, agent processes, people like GitHub, GitLab assure DevOps moving to GA with more AI or agent driven CICD and rollback kind of capabilities. I think we'll see that the first place to enter.
And the reason is because the development side of this, the development software engineer and the DevOps engineer are the places where I think we can demonstrate the earliest benefits of the lowest risk, because they're used to introducing new technology and understanding what, what's acceptable risk and why and what not to take. Second is in the security vendor space, sort of the race to auto fixing where this move from found to fixed. I mean, capabilities such as secret scanning is, is a good for start for patches and configs policy as code remediation, things like that.
I think we'll see more kind of policy as code where policy as AI agent being created to help implement what we need to require today people or manual intervention to step in and do. The third is we'll see more governance type dashboards or accountability dashboards. And actually those will become sta table stakes for vendors as they're introducing ai increasingly across the software development lifecycle.
I've highlighted ServiceNow, their AI control tower. I think the Docker MCP gateway is another example of, uh, giving control not just into ai, but also controlling what AI is doing and knowing what it's doing. So we'll see a lot of advancements.
I'm excited to see what the vendor community continues to do, what customers accept and find value from, and also how that building that trust accelerates not only the, not only the innovation cycles of vendors and customers, but the acceptance of ai. So in closing, thanks for being part of our discussion today. I didn't, uh, no death by slides.
I tried to avoid PowerPoint slides for you. Hopefully that was appreciated. But as we, uh, you know, graduate AI from being coding, coding assistant to being more assistance in the software development lifecycle, AI is starting to be referred to as a team, a teammate or a companion, um, or someone that's a thing that's working with us, working with people.
And the next competitive advantage isn't necessarily faster code. Matter of fact, it's about better, faster software delivery and outcomes that are also secure by design. Don't take people to do or AI after the fact implement security and also operated at scale.
So thank you for watching and, uh, stay tuned. com/mitch-ashley. You can read about it there.
Subscribers can get the, you know, full details analysis of this that have incorporated into an A IR report. So thanks for listening and look forward to talking with you soon. Soon.
You can always reach me at M ashley at fu group com. Happy to talk with you, take care and, uh, have a good experience here at the DevOps experience Experience. Despite widespread skepticism, AI is already widely used in the enterprise, often in the form of so-called shadow applications outside of traditional it.
This episode of the Tech Field Day podcast features a delegates Ryan Booth and Dave Graham discussing the real state of AI adoption in the enterprise. With me, Steven FoST, welcome to the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about a key concept in our industry. This podcast features a variety of perspectives from members of the Tech Field Day delegate and partner community, and is often recorded in association with one of our events.
This episode is actually a preview of the AI Field Day event that is happening this week, but don't worry if you're listening, uh, later on, uh, it's hopefully still gonna be relevant. Tech Field Day is part of the Futurum Group, and this is podcast is also published on our sister companies site, tech Strong tv, as well as their over the top video app. On this episode, as we head into AI field day tomorrow, we're talking about, well, the real world of ai, essentially, shadow AI is here, people are using this technology, people are, uh, experimenting with it.
They're pushing it as far as they can, and the enterprise really needs to catch up or it's gonna be left behind. But before we have that conversation, let's meet who's on the podcast today. Hey there, my name is Dave Graham.
I'm the director of marketing at ML Commons, uh, which is an industry led consortium, uh, focuses on AI for everyone. So I'm really, really glad to be here. I have a long history in building AI stuff, infrastructure, networking, compute, storage, you name it.
I've been around for, for quite some time. Yeah, cool. Hey, thanks for having me, Steven.
Um, my name is Ryan Booth. It's, it's been a while, but it's good to be on again. Um, I'm excited for what we have coming up this week.
Um, I've been in the infrastructure, engineering and operations, mostly in networking, um, industry for about 20 years. Um, moved into software development pretty heavily about 10, 12 years ago. And then within, geez, I easily to pass five years.
I've gotten pretty heavy into ai. And then now that's my primary focus. A lot of it with AI software development and bringing AI solutions into enterprises.
And as I said, I'm Steven Foskett. I am, uh, organizer of the AI Field Day event, but I'm also, uh, you'll, you'll see a lot of from me about AI on our utilizing tech and our new utilizing AI podcast, which actually, uh, sneak peek is gonna be on Thursday afternoon, and then is launching, uh, next Wednesday. And of course on the Textron Gang.
Um, but I go to a lot of these events and I've met a lot of people and, and frankly, this is kind of a cool, um, it's kind of a cool get together here because Ryan, Dave, and I, you know, we've been in this tech community, this tech industry together for, you know, well over a decade, probably going on two decades here. And, um, both of you have really been kind of in the weeds for the last, you know, few, uh, making this stuff, building this stuff. And I think that what is interesting here is, on the one hand, we have all of this, um, public understanding of ai, you know, I mean chat, GPT is on everyone's lips.
It's the most hyped product, certainly of the century. If not, uh, ever, I think Jesus would like a word. But, you know, it's, it's pretty hyped.
Um, you know, it. And yet, and yet I think a lot of people are wondering, how does this, how does this get real? How does this really, you know, matter in the enterprise?
What is this gonna do to hardware and software and the, and the, and the tech industry? And yet, and yet the whole time there's people like you guys and frankly like me, me, who have been looking at this technology and saying, huh, that's cool. Lemme play with that.
Lemme see what I can do with that. And so e essentially whether the enterprise is ready or not, we're going for it. We are, we are going to be deploying AI in various ways.
We're gonna be deploying, you know, some companies, frankly, futurum is one of those companies where the CEO said, Hey, everybody use ai. Go. Other companies I think are very much like, whoa, whoa, whoa.
I don't know, you know? And so let me just kind of put it to you, Ryan, I'm gonna start with you. Um, 'cause you kind of suggested this idea, this topic.
Uh, what is the truth of shadow ai? Um, yeah, everybody out there that's curious about it has been playing with it, you know, and if, if, if you're, if you're seeing what's going on and, and you're, you're seeing how it can, um, chat, GTP can help with your workflows, help you write documents with your emails, all these tools that are coming, people are picking 'em up. And if they're not picking the ones up that came out yesterday, you know, maybe they heard about the, the new open AI browser that came out, you know, the other day, and now they're on top of that, and that guy's doing a hundred percent of your calendar work and your email work.
Um, absolutely it's creeping in from every corner. And then you have software developers who are building it in with co-pilots and assistance with, um, building software network engineers are using it. DevOps engineers are using it to, to help troubleshoot and dig into issues, build scripts to help fix and clean stuff up.
It's coming in everywhere. And, um, it, the, the solutions that are still there, still needing to be a lot, uh, more mature than they are currently. And I think that's a lot of the gap that we're seeing.
Yeah, I mean, the, to echo your point, Ryan, I mean, a lot of, a lot of what we're seeing is the, uh, the adoption curve has been great on a individual basis, right? I can go into perplexity, I can grab my chat GPT stuff, and you're privileged to work for a company that, you know, will buy your license, you know, on a monthly basis or whatever. It's great to get in there and use it.
And what you're finding is the friction that exists between the user and these tools is becoming less and less, right? You can go to lovable, you can, you know, Claude code or whatever, and you can, you can scroll LinkedIn and find everybody building solutions now that, you know, previously required hiring a dev, having a pro, a program or project manager, and doing these things. And so you have this kind of rapid, rapid, uh, implementation curve where previously you did.
Now the trick is, to your point, uh, rapid adoption means that there's less time spent on the necessary fundamentals of how does this integrate into my workflows? How does this, you know, it we're band-aiding, we're patching a, uh, problems that, you know, historically required going through accounting or, you know, purchasing and whatever in order to find this, you know, the vetting, the vetting becomes different, right? The vetting becomes, can I run it locally?
Does it solve my immediate problem with not a lot of longitudinal thought about the, the nets, you know, the end result on this. And that becomes, it's exciting and terrifying all at the same time, right? It's that duality of, uh, what we're kind of running into.
Yeah. It's, it, it's exciting and terrifying. And those of us who've been in it well, like the three of us for a long time, um, I think that we see a lot of parallels to that old, um, you know, pc, uh, revolution when everybody, um, you know, I, I, you know, it, I guess it wasn't really even called it MIS whatever they called it back then.
Um, you know, had this sort of, uh, centralized top-end mentality of computers, and then people in like sales and product and marketing saw what spreadsheets could do and saw what word processors could do, and went out and bought an Apple two, or an IBM, you know, PCXT or whatever, brought it in, set it on the desk and went for it. You know, I mean, my, my first job, you know, when I was still in high school, I worked for a company implementing a DB two database for a marketing group. Uh, and that was literally on a PC that existed in marketing.
And the central IT department knew nothing about it. I mean, we literally saw this, the same exact thing is happening with these AI tools, essentially. People are, you know, and, and we're literally from the moment chat GPT was released, people were putting their credit card in or not.
And, um, and throwing stuff at the chatbot and using it as a way to accelerate and automate their daily jobs. And I think that it's true that some, some companies have embraced that, some companies have not. But embrace it or not, it is getting used and it is everywhere.
Um, I mean, you guys are in, in, in the development side, you know, what do you see there? Well, I mean, as we moved from BYOD to BYO ai, right? It's now what are you bringing in?
Uh, like I have one, I worked with a wonderful gentleman at, at m at ML Commons, right? And so we get on calls and we have our weekly standups and whatever, and he is in it and he's supporting the organization from that standpoint. He's like, oh, I got an agent that can do that.
Like, you know, like this, this would not be the term that I would've used. I mean, we never used this at Dell, right? You know, like going back, it was, you know, we got people for that, you know, and it's, it's that literal shift from like, it's not necessarily people anymore.
It's now this, this tightly coupled or loosely coupled or whatever, you know, thing that we paid for the, to kind of get the, get the job done. So, I mean, it, it, it's a fascinating turn, like you're saying that's, it's no longer this, you know, shadow box that's sitting in a corner. So now a shadow entity that exists beyond the firewall, they're somehow trying to interact with and then pro protect your privacy and your, your, your data when it comes down to it.
So, uh, yeah, I, I draw a lot of correlation, um, to the experiences, um, that I observed and we went through with, um, the shift to cloud and then also the DevOps movement. Um, those two right there for me are, are playing out almost, you know, step by step as in AI as they did in the past, and, and very much so early days clouds, just like what you were saying, I was just thinking back to the day when we had to pull up AWS console and see like 97 instances, all of them named like 1, 4, 7, 2, 3, 6, 9, 8, and it's like, who the hell owns this stuff? And I'm starting to see that in, in these AI workflows, especially stuff that I build.
Um, I could iterate very, very fast through building applications, through building infrastructure, all of that. Um, but then over time, it's, it's getting it all into a cohesive, um, group. And that, I guess that comes with maturity of all this.
Yeah. And I think that just like, you're right, just like cloud, um, totally the same situation. Uh, there's a lot of players here and there's a lot of products here, and I suspect that most organizations have absolutely no idea.
I guess it's like SaaS apps, like, you know, most organizations have absolutely no idea which applications are being used by which departments, in which ways, which things are important, which things are not. Um, you know, not to make it too on point, but like one of the companies that's presenting at AI Field Day Haiku, like their claim to fame is basically finding and protecting like data across like all the different SaaS applications. Mm-hmm.
Somebody who came up with that business model probably is looking at AI the same way and thinking way, oh my gosh, like marketing uses Jasper, like software development, you know, they're using, you know, a Microsoft, you know, co-pilot, uh, you know, the, the, the sales team is using, you know, Salesforce agent force or whatever, you know, maybe they're using Gemini. You know, there's gotta be a moment where somebody in, in, you know, is high up in the company has to stop and say, what are we doing? We're using everything, aren't we?
Yeah. And then I think that's a lot of what they're starting to see right now. Um, these engineering teams that are our organizations across, or that are really embracing this, um, that sticker shock of that bill hitting of the amount of tokens and the, the amount of stuff they've been spending and doing, um, is, is pretty big.
It's significant. Um, and it hits almost every single organization just like it did with cloud. Um, and you gotta, you gotta weigh that in and it's a, um, I'm not exactly sure how we solve that right now.
Um, it's budget, but yeah, being able to balance how many tokens you can generate and use versus what comes out of it, I think will be a key metric very soon. Yeah. I think there's a lot of data, you know, again, not trying to even promote my stuff, but just in general, things are changing.
Uh, unlike Amazon, which you could predict that there would be, or AWS, you predict that there's gonna be a cost adjustment, you know, a couple times a year, right? Cory Quin famously would, would remind you of the fact that there are pricing adjustments that happen. But you, you, you, you hit steady state after a while, right?
The depreciation curve or the am amateurization curve, whatever you wanna call it, you know, it became table stakes, right? We know that we're going into Amazon, we know that this instance pricing is, and that generally doesn't deviate all that much. Still have your backend sales processes where you can go talk to a rep and maybe get a little bit of dollars off the top.
But with ai, you know, the thing that we're noticing right now is that all these providers suddenly understanding that they're in the pinch point between the infrastructure that's being served. So running on Amazon or running on open, you know, opening ai, running on Nvidia or running on Core Weaver, you know, core Four two, any of these CSPs, they're suddenly in the pinch point of we gotta supply our infrastructure, we gotta figure out how to pay for infrastructure with our subscriptions. But simultaneously that bottleneck, which Ryan, you just talked about, that TPOT or TT PT, right?
The time to First Oak and TT ft, sorry, time to first Oak owner, that response period, then drive is the demand in there. You can again, go on LinkedIn or you know, on Reddit, Reddit's famous for this at this point, but you can go in there and say, oh my gosh, my cursor wasn't, you know, giving me the same outputs it was giving me last week. Or, you know, this is not an interfacing, you know, cloud codes pricing model change, and now my efficacy model has just changed.
Well, it's coupled to new model release infrastructure and it's less predictable now. There's no predictability to it at this certain point. We know you're gonna pay a lot, but what does that payment actually look like, again, over a time slip of a year or whatever.
So when you try to budget and try to forecast these things, if you're gonna corporate into, you know, uh, your enterprise or what whatnot, you know, you're only looking at a very, very narrow window of cost that can vary wildly within that. And then you add on all the other enterprise features like KU would, would be willing to offer you, you know, guardrails, you know, uh, idp IDS, right? Trying to understand what's, you know, what's happening where, where things are going and, and trying to provide that in there.
And everything suddenly end up back in the cloud model of everything's an operational expense at this point, right? And there's no predictability. It just becomes expense on expense on expense.
And I, I think that right there, um, enterprises are, are gonna have to face the reality that local models are gonna have to be a must. Um, I don't think everybody needs to run full on infrastructure, inference, infrastructure like the providers do. Enterprises need a handful of models.
Um, but we need a way to be able to host models up for users, and they don't have, they should not care what models being used. They don't, they do their job. Um, but then that also comes with, you know, all of the, the enterprise features that come on top of that are back auditing, data control, you know, all of those things have to come on top.
Well, you need a way to characterize it too. I mean, I think that's the other thing, like choosing the model may be a characterization of, okay, I know that this model can provide these particular features and functionality, right? Um, but also this type of output and this type of return, right?
Again, looking at Ty, the first token or context windows and the things that matter end up, end up mattering. So you need a way to characterize that up front. And ultimately, I think we're probably in this kind of mirrors your point, we're end ending up in that menu style approach to stuff.
What can I provide my enterprise internally? You know, I know what this infrastructure can do because there's a characterization of his infrastructure. HPE is dropping a stack on my site.
I know they can pass this amount of data using, I was gonna say power rich. They're not power rich, that'd be tell. Uh, but you know, they're, you know, using their, you know, their server storage and networking, right?
Um, they, they have a characterization. They've done the benchmark and they've done the characters and provided to me, and I'm buying now based on what I believe to be the case. This is the premise, I think, behind AI factory type concept as well.
And then you look at your models and introduce model velocity. I mean, if you wanna talk about that a little bit, Ryan model velocity is a problem too, because all of a sudden you have a drop again that next week there'll be another iteration of an OSS type model, or there'll be a, you know, coming outta China, another great deep seek model or, you know, choose your poison. So one of the things though that concerns me about all this is, and, and it was the same with PCs and it was the same with SaaS and so on, is, um, the question of, of control.
Essentially, if you are the CIO and you are listening to this discussion, you might be saying, cool, but wait a second. So the corporate data, the corporate code base is being slurped up by like 12 different coding assistance. Um, all of our, you know, product, um, roadmaps and stuff are being slurped in by like three different marketing applications.
You know, chat, GPT sees everything and is coordinating that across every, you know, across their models, whether they say it or not. And of course, these models are famously, um, incapable of shutting up, uh, when it comes to keeping private data private. Um, uh, if I was a CIO, I'd be super worried about that.
Not just because, oh my gosh, people are using the corporate card to pay hundreds of conflicting subscriptions to thousands, you know, or hundreds of different companies, whatever. But, um, but also because, oh my gosh, where, where's my corporate data? So, you know, you guys are enthusiastic about this, but how would you answer, how would you talk to the CEO?
How would you say, uh, wait a second. It's okay because Brian, yeah, and I, I, I, I, I think it's, it comes down to there's options and, and we now know how to control. Um, it's, it's been one of those over the past few years that hallucinations, um, models going out of control.
It, it giving just horrible, horrible responses. While it's not solved, it's way better than it was before. Um, definitely in the software development space, controlling models to build enterprise level software, um, while it is a skillset to build up, it's possible.
Um, and so I, I do think we're, you know, the, the, the we, the tools that we're getting provided, the things that are getting built to hand off to us, those features need to start getting built in. We need, you know, the OAuth control. Um, and I almost, I I, I kind of have, you know, the build versus buy argument kicks around in my head a lot right now.
Um, I can see spitting out software at a very rapid pace right now, um, with not as strong of a skill set as we're used to. So I don't necessarily need to go out of to a vendor that sells a very generic style product. Maybe I can build a very pinpointed one.
But then there's the tech debt with that, and then there's the ownership and the management. Um, but then you don't have to rely on those vendors and those SaaS companies that we have so much money to throw at or we're throwing so much money at, and we could probably invest that into the tokens we'll use to build and invest in the tools we'll build ourselves. Um, I don't think that's an end all beat all for everybody, but what businesses it does work out for, um, and it ma matches up with, I think it's a good strategy.
Yeah, I think there's a, uh, some of the early discussions I was in, I used Cursor and Kiro and Zed and you know, choose, choose your poison, right? And one of the things I determined very, very quickly is, you know, like I suck at product management and program management and any of that stuff. And even today, still not a, not a strong suit of mine, but one thing that it kind of showed me is to, to again, elaborate a little bit on, on your point.
You end up building in debt and interesting in, in, in varied ways. Now, it may not be technical debt, but if you're not conscious of what you're building, if you're not conscious of the processes, but whereby you got to that solution, you end up building yourself into a corner. So for example, I can go out to get, and I can take a look at my repositories, isn't they great?
I mean, they were great little projects that I do now, me picking that up next week means that I have to go back in time. I have to think about what I did, what I built, why I built it, and the pragmatics of both language and syntax. Right?
What have I, what have I done? You start to, and that's just me dealing with me, right? And other people are certainly more attentive to their stuff and they have better documentation plans.
But one of the things I of discovered and where I've seen actually a burgeoning amount of capability being delivered is it this idea of kind of product management for ai, which is AI driven, but it's basically trying to maintain your context in a weird way. It's doing what we expect from infrastructure, which is maintaining a context flow between user and application. And I think that's an area where, uh, i, I don't know if excited is the word that I would use, but it's an opportunistic kind of, kind of place where you kind of sit in the middle where enterprises could adopt this stuff, but as long as they kind of, you know, provide a plan or provide those guardrails and say, Hey, you can, you can do this, you can build this, but here's your documentation.
I need a PRD for everything you do. Yeah. And I, I've worked through a number of tools and I've worked with a couple vendors out there that, that are focused on, um, the, the customer story to PRD creation.
Um, and I've been really digging into that as well, building out workflows that can automate it, um, add to it, and, you know, allow PMs to build full on prototypes for engineering teams to review or proof of value that could easily iterate. Um, and then, yeah, from the software side, if you're not, if you don't have a PRD and you're not doing like, test driven development with ai, it's a crapshoot on what you get. It really is.
And it still kind of is. Um, you don't know what's gonna work, what's not gonna work. Does it do it the right way?
Did it just full on skip stuff and added to-do comments? I, I, I absolutely, I had something running over the weekend building and going, you know, it was like a 1500 page PRD amazing as hell, application, blah, blah, blah. And 90% of the API logic was mocked, and then the test were too.
And so it was like, yeah, I had to start completely over with it. And, but yeah, it's, it's, it's one of those, um, we have to learn with it. And, and I guess one of the bigger points, I'm staying here, I've been doing this for a year and a half, you know, and I still get into situations where I catch sharp edges and get cut.
Yeah. I mean, didn't you just tell chat GT to fix all that stuff? Come on, man.
Um, They always respond. Oh, absolutely. Absolutely.
That's a great idea. You're right, Ryan, you we should do this, then they don't do it. Say they do it.
Well, I, you know, it's, it's interesting. I, I think, um, well, first off, I think there's an opportunity for one of these big companies, and I, I'm sensing that chat, GPT and or that OpenAI sees this and is working on it. Um, and I, and I think, I'm gonna guess that Microsoft, Google and so on can't be far behind.
Um, I think they've gotta be able to look at this and say, wait a second, if every, you know, if, if there's already like 50 different users of this application at this company, then we're already a supplier to that company and we should help that company get their hands around the use of our tool. You know, kind of like what you're describing, Ryan, when you open up the Amazon, you know, you know a console and you see all these different groups using, you know, in your company using this tool, wouldn't it be helpful? Wouldn't it be great if the, the company said, you know, Hey, you know, Mr.
CIO, um, this is what's happening at your company, whether you knew it or not, and we're here to help you get your hands around this situation. Um, you know, fir that first off, uh, second off, um, I think that, you know, it really is gonna be important for these companies, um, to work together on, uh, control of data and not allowing data to be shared beyond where it is. And I know that they talk a lot about that, but I think that they, they need to reassure people about that.
But then mo more importantly, I would say is, um, you know, kind of what comes next, because so far, a lot of the stuff that's happening has just been LLMs, let's just apply. Mm-hmm. Let's throw an LLM at it.
But as we're talking about on the utilizing tech podcast, I know, sorry, spoiler alert, other podcast, um, as we're talking about utilizing tech, you know, a agentic AI is just around the, is just around the corner. And soon we're gonna see chains of AI deployed, just like process automation, um, you know, that, that, that sort of thing. And, and these chained AI agents that are able to select tools and use tools and pass data that is going to create an entirely new, uh, sort of software paradigm where you're gonna have people building and deploying their own stuff.
And, and you combine that with what we've been talking about here for the last 20 minutes about shadow it. Um, you know, it's kinda like, uh, when people started using Zapier and I-F-T-T-T and stuff like that, and, and, and, and, you know, automating processes, um, we're gonna see that happening widely. Uh, and it's gonna be users of Gemini on Google or users of Chat, GPT and OpenAI, you know, they're gonna be building their own kind of chains of agents.
Um, and, and, and there's no stopping that either, right? Yeah. Um, I, right now I wanna say that agents are everywhere.
Um, the adoption thing I think is going in reverse. I think I, I tie it a lot into like how, um, Docker, um, Docker and containerization went. Um, next thing you know, everybody was looking around and containers were everywhere, and they didn't know where they came from.
Um, same thing. Agents are gonna come from everywhere. Everybody's installing 'em, and hell, half the people don't even know they have agents running on whatever device they're using 'em on.
'cause we can't agree on a term for agent. But, um, it is. But I think for most people, you know, the, the fear is, is almost too much.
Or we, we, we lean way too much into it because you think about containers now, they're everywhere, but they're managed fine. Um, they're tucked away. They're not presented to the user is the users don't care about the containers, they don't care about the ai, they care about the result.
And so, as we've learned to pull that back and that why, and that here's what we're delivering to you gets delivered. That's how it'll turn around, I feel. Um, until then, though, we're just like containers.
They're gonna be everywhere, and we're gonna hate 'em all. Yeah. We have swarms.
You know, there's a gentleman I follow on LinkedIn named Ruben Cohen, who's, uh, who's a phenomenal, you know, software engineer up in Toronto area, and he is been building stuff off the back of cloud code for, you know, at least a year. But yeah, he came up with sworn stuff and he gives proof points all the time. Like, Hey, listen, I was able to eliminate this much by running a form of agents that have a central command and control.
I mean, dude, it looks like decenter all over again, right? Like back in the VMware, like command and control, everybody's interconnected, whatever, uh, and anthropomorphize it all. You want to, you know, it's bees and you know, the hide and all that kind of fun stuff.
But, you know, like this, this ends up being, again, to your point, Ryan, just great at making points. Um, it's this sprawl of, it's every, everything everywhere, all at once, right? And you end up in, you know, like the movie, uh, but you end up in this kind of scenario where you, you never know what's completely out there, and you start to get into purpose-built agents that are only solving one little niche problem that might end up solving your parameterization or security problem, right?
Because you don't have to worry about that agent ever exceeding the bounds of this stuff. Again, ripe opportunities, I think to, for industry and enterprise to kind of step in consultants as well. Hey, did you know that you're running this offer 5 99?
I'll give you a report, um, cynically as that may be said, but it gives that kind of perspective on, you know, again, the assumption is now to my point earlier about BYOD, it's now everybody's coming in BYO ai, right? We're all coming in bringing our own ai, our own kits, our own mentality, our own kind of perspective on how we want to accomplish business. And when we enter, enter into a sacred halls of a larger, small, medium business enterprise, you name it, we're all coming in with this kind of set of tools that are in our, in our pocket that now expose us to various, various degrees of risk and responsibility.
So, yeah, I think so. Um, I, I, I think, you know, especially like early days of developers or, you know, um, before the DevOps days, that was developers and engineers you rolled in, you set up your local environment, and that's, that's how you proved your worth was how well you were able to work inside your environment. And I, I do agree that's that'll, you know, with, with AI as well, those that can come in and have a strong environment.
Um, but from an enterprise standpoint, I'm, I'm seeing very few people talk about this one, but I am starting to see some talk is the fact of centralizing what we just talked about into a control center. So similar to like, you would control your VMs through vCenter, um, being able to control your agents, be able to apply, um, rules and policies and context structure across your PRDs and down to all your engineers and all your agents. Um, there's a lot of work to be done there, and there's very few that are, are working at it that I know of right now.
I mean, yeah, I, I think this is, you know, to the, the overarching point in your, you know, how do enterprise get ready for this type of thing? Again, it's, it's embracing the suck as the case may be, all right, it's coming and we're gonna have to deal with it, right? So it's, it's not, it's, it's cautious acceptance though.
It's, it's going out there and actually setting aside time, effort, and energy and money just to say, Hey, listen, what is, what does this actually look like? Pragmatically set up a tiger team, as much as I hate that term, set up a tiger team to go and evaluate these tools. Look at the practical applications of AI within your enterprise or within your business, right?
Can it solve a marketing problem? And always keeping in mind that people are the, are the drivers of this, right? I think we run to the tools quickly and we forget the people, and that leads to things on the news, right?
So keeping a perspective that people are gonna be using these tools, and then people also have to be cross-trained and be able to engage in these things, and they need to be able to engage in these things in a safe and meaningful way, right? That's the other part, is what I experiment with at home is not necessarily what I'm gonna be able to do at, at work, right? So being able to kind of, uh, bring that policy in there.
And also, I think, and, you know, you can bet you're gonna elaborate on this a little bit more, but start to define your data sovereignty, your data security, your data problems, right? If you're in a highly reg regulatory, you know, regulated business, you obviously have a set of rules you gotta comply with, but always think in terms of where could this be if I, you know, if I didn't understand what, what the tool was doing, right? Where could this end up?
And I think those are at least off the top of my head, three things that when I look at enterprise, things that I caution people about or consult with people about. Yeah. Yeah, yeah.
Um, you know, I, I'm right there with you. I agree. Um, you know, geez, your data is your business and, you know, data's a new gold, excel's the new shovel.
Um, so, you know, why not, um, protect it, but geez, it's, it's gonna be a difficult one. Um, there are, there are some cool security solutions out there that I've seen. Um, you know, you, you hinted on it earlier, Steven, that, you know, transformer models might not be the end all be all, and maybe, you know, I, I feel next step is we start discovering more models or the data scientists do not, we, I won't be discovering s**t, but anyways, um, it's, it's, it's getting in there and protecting the data inside the models or obfuscating that data inside the models so you don't have to worry about it there.
Well, and, and you know, I would say one of the things that sort of occurs to me is, is that a good response would be to have a more proactive response and essentially say, Hey, I know y'all are using, you know, chat GPT and Claude and Gemini and co you know, co-pilot and all these, um, we've got a corporate subscription. You know, you're welcome to use this. Uh, it doesn't cost you anything, you know, no more credit card bills, no more worrying about tokens or whatever.
Use this one, this is the corporate one. It's pretty good. It does all the things.
Um, you know, that, that I think is the, is is sort of the way that businesses can kind of help to turn this ship essentially to, you know, embrace, embrace the fact that people are using these tools and then direct them in the direction you'd like them to use to, to, to do. And, and I think that that's a more proactive way than sort of running around with your hands on fire and saying, ah, people are using things. Um, so, uh, thank you guys so much.
This has been an incredible conversation, uh, lot of fun, uh, talking about this, and I'm really looking forward to having this conversation continue at AI Field Day this week. So tomorrow and Thursday we're gonna be live, uh, basically eight to four or eight to five, uh, Pacific time with Tech Field day presentations, discussions, et cetera. And you know, like I said, we're gonna be debuting this new podcast, uh, Thursday afternoon as well.
Check your podcast for utilizing ai, uh, where we're gonna have conversations like this literally every Wednesday going forward. So, uh, before we go though, um, let's talk a little bit quickly. Where can we connect with you?
Where can we continue this conversation, Ryan? Yeah. Um, I spend most of my time in, um, LinkedIn when I'm on social.
Um, I'm not on Twitter very much anymore, but I can still bounce over there from time to time. Um, I do most of my blogging and most of my thoughts come out on my substack. ai, and that kind of has everything I'm working on.
Oh, well, most days. Yeah, LinkedIn, I mean, it's tends to be where we're at. Uh, LinkedIn, I have my own personal blog over at a Quiet Little Rebellion, um, which is on my LinkedIn page as well.
org, I mean, where I'm constantly interfacing with the work groups that we have here would love participation. It's, uh, you know, it's a thing that we're answering or trying to solve some of these problems that are in a more, uh, industry consortium kind of way. So yeah, love to see you there.
And I'm also on Blue Sky, same name. Yeah, absolutely. And ML Commons, I will reiterate that they're always looking for folks to contribute and join these, uh, and I've seen some people that have really do dove in there and, and gotten pretty involved in some of those efforts.
Um, it's not just a, not just a speed benchmark. It's a lot more than that. So it's really cool to see what you all are doing over there.
Um, and as for me, as I said, you'll see me on Textron Gang pretty much every Tuesday, uh, here on the Tech Field Day podcast, uh, occasionally on the, uh, tech field Day rundown, um, more often though, uh, on other podcast, including utilizing tech and utilizing ai. So thanks for listening to this episode of the Tech Field Day podcast. Um, if you enjoyed it, uh, please do subscribe.
You'll find us on YouTube or in your favorite podcast applications. Uh, also maybe give us a review or rating. We would love to hear from you.
This podcast is brought to you by Tech Field Day, home of IT experts from across the enterprise and part of the Futurum Group. com/podcast, or you can find us on Tech tv. Thanks for listening, and we will catch you next week.
OpenAI and Microsoft get more mature. Amazon is discounting a little bit of their opex IBM applies textures, IBM and A MD are gonna get even more. Quantum.
Qualcomm finally squares up to Nvidia, Palo Alto soars with Prisma Air. And we're gonna take a closer look at the US government's sudden interest in quantum computing in this week's episode of the Tech Field Day Rundown. Hello everyone.
Welcome to the Tech Field Day rundown. I hope you have your costumes ready because we are getting so close to Halloween. Uh, but I hope that you're enjoying the crisp fall air on this national oatmeal day.
I, of course, am Tom Hollingsworth, and I'm joined once again by my amazing co-host, Mr. Alistair Cook. Al, welcome to the show.
Always great to be here with you and, uh, enjoying my first cup of coffee of the data right now. Well, I'm glad that you're enjoying some coffee as we take a look at some of these wonderful fun stories going on in the world of enterprise it. And as we discussed in the opening, Microsoft and OpenAI are taking their partnership to yet another level with yet another new agreement.
Microsoft now owns a $135 billion stake in open AI and keeps exclusive rights to its AI models and Azure API all the way through 2032. The deal adds independent. A GI verification allows for joint product development with third parties and lets Microsoft pursue a GI On its own open AI gains more flexibility, including access to US government customers, the ability to release open models, and the freedom to use multiple cloud providers.
The company's aim to keep innovating responsibly and create new opportunities for businesses and users. Al Microsoft now owns $135 billion of open ai, and yet they're allowing them to go off and do other things. Where's the value for Microsoft in this?
Well, bear in mind that that $135 billion is only 27% of OpenAI, or at least the, uh, public benefit co corporation that they're transitioning to. So remember that OpenAI was not originally commercial, and there's all kinds of challenges around that. So, uh, there's some fun pieces in here.
Uh, part of it is around how the original agreement between OpenAI and Microsoft ran and that this, uh, artificial general intelligence declaration is a sort of watershed in that agreement. And so now there has apparently been a, a declaration that is, uh, due to be verified for artificial general intelligence from open ai, uh, and that changes how things all fit out together, but that really tightly bound partnership becomes a little looser on this. So Microsoft can choose to follow more, uh, uh, AI in general, uh, AI without necessarily being bound to open ai, and they probably are still gonna be pretty tightly bound and open.
AI can buy its compute resources from somebody other than Microsoft, although they've already contracted for $250 billion of Azure services, I have to be incredibly successful to need to spend some money anywhere else. So that loosening of the all of these things is basically around how the contracts used to be and how the contracts have been renegotiated. Uh, it's just allowing both sides to be a little more free of what they do.
Personally, I think we'll see them as tightly bound together as they always have been. I don't think this is actually gonna make any material difference to how either organization operates. It just gives them the option that they might choose to.
We often don't take the options that we might choose to. We just have them because maybe we might want them. Amazon, who we covered some of their troubles last week, although much overblown troubles in my opinion.
Uh, Amazon has a new piece of news for us. They're laying off approximately 14,000 employees, about 4% of its corporate workforce as they adopt AI to streamline operations and may cut an additional 30,000 roles, that'd be another 8%, bring it to a whole 12% of their workforce. Uh, over time, the company says AI will enable faster innovation and efficiency and, uh, reduces the need for certain positions while creating new opportunities elsewhere.
That sounds like management speak. Uh, this marks Amazon's largest recent restructuring in the follows, previous layoff layoffs across its divisions, executives emphasize that AI adoption is transformative for the business, uh, even as it raises concerns about job displacement in the wider tech sector. I don't think you and I are at risk of being replaced with ai, but how much more of Amazon can be replaced with ai?
I'd be a little bit worried about what actually has been replaced by AI at Amazon, because we hear about how they want to cut all of these jobs because they overhired during the pandemic. Okay, I I'll buy that. Well, no, actually, what we really meant is, is that a lot of those roles that we hired for during the pandemic, maybe a few more people are actually able to be done by ai.
Okay, weird. So I'm assuming that all of your ai, uh, data centers and infrastructure and all that stuff is running at a hundred percent capacity right now and really providing value. What do you mean it's only running at like 18 to 20%?
That's so weird. It's almost like what you have isn't being utilized to its fullest extent, but yet you're cutting people because the AI is doing better than you thought. Well, if you're only running it at 20%, you're not gonna buy any more this year.
Are you? Surely not. Surely you're not gonna go out and use the money that you save from these layoffs to buy more AI data center components to augment things that are already running at what a fifth of their regular capacity.
That's one of the problems that we're seeing here, is that all of the signs in this story point to the fact that Amazon is not actually laying people off because AI is doing their job. They're laying people off so that they can buy more stuff to make AI bigger. You know what this sounds like, right?
You know, there was that little kerfuffle in the Netherlands about something, something tulips. You don't wanna be the last person not holding the bag until it's time when everybody drops the bag, and you don't want to be the last person holding it. So why would you not preemptively say, we're not going to play this game.
We're gonna use what we've got, and when it finally reaches a point of maturity, then we're going to maybe buy a little bit more, but not a lot more. Well, that's because the market is basically being propped up right now by people buying like crazy, like they're going, uh, out of business. And, and I think what you're gonna see is that, and, and we know this through every bubble, every hype cycle that we've ever lived through, there are things that AI is good at, but AI is not good at everything.
And once you realize that and you stop overspending on ai, you're gonna realize you probably are gonna end up needing to hire a lot of those people back that you laid off because they're the ones that doing the real grunt work underneath the covers. And I think it's funny that a company that started off by saying, oops, we might have overspent on hiring in the pandemic now claims that all of this extra AI stuff they're buying is in no way overspending on any of that, except the difference is, is that hopefully some of these people can go out and find jobs and do something meaningful in the industry. All that AI gear that you're buying, if this doesn't pan out, I don't know what you can use it for.
I dunno, maybe you can sell more books. IBM consulting has acquired texture. It's a company that helps businesses move to and modernize hybrid cloud systems.
Textures. Tools will speed up cloud projects, reduce manual work, improve recommendations and support greener IT strategies With experience in over 100 global projects, texture strengthens IBM's platform from managing cloud transformation from start to finish, helping clients modernize faster and more confidently. Al do you think that IBM's cloud ambitions would benefit from having a tool like texture?
IBM's always had a big consulting practice, and it's a consulting practice built around having processes and templates that can be reused by the IBM branded person in your town. And so having good templates, good processes around that application, migration and modernization and, and, and just general cloud strategy and hopefully probably an AI strategy. And there is vital IBM of course, international business machines, that's an English language thing, and texture is an Austrian company.
It's really vital as you're starting to sort of focus on European growth, that you have local presence and local understanding that is quite different from the US Understanding our operating in Europe is very different. It's, it's a series of much more isolated, smaller enclaves of ways of doing things in regulatory and compliance environments. And so I think this acquisition is around getting the knowledge, the checklists, the processes that fit a European business P practice, uh, in addition to the existing deep knowledge of IBM operating in North American, uh, practices.
I think it's a, a great thing for, uh, IBM to have a broader, uh, platform for their, their, uh, consultants and to have more access to European markets. I think a lot of US companies underestimate just how different the European market is to the US market, thinking that countries in the US are similar to states, uh, states in thinking that countries in Europe are similar to states in the US and, uh, that simply isn't the way things, things work out there. So yeah, good move and helping companies move across to that migration and modernization.
I know we've been talking about migration and modernization for a long time and cloud strategies for a long time, but there are still a lot of organizations that really still haven't made enough of the move or haven't made a move in a way that actually gives them business advantage, ends up being beneficial to them. So, uh, better consultancy, better methodologies around that is always gonna be beneficial. Speaking of IBMI, BM and a MD have made big step in quantum computing by running the error correction algorithms on a MD chips instead of requiring yet more qubits.
This allows the fragile quantum calculations to be stabilized using low cost, widely available non-super cool hardware, uh, making practical quantum quantum systems more achievable. The milestone moves IBM closer to its 2029 goal of fault tolerant quantum computing and shows the potential of combining classical and quantum computers for real world applications. Thomas, this big news, or is this just more quantum is getting better but isn't really here yet?
I think it's big news for this one particular aspect of it, and I do agree that being able to run the error correction algorithms on what I would consider to be standard computing hardware is a big deal. For those of you who did not watch my conversations episode about quantum computing, basically what happens is, is that whenever you're trying to measure those qubits to figure out what the data is that locked in there, you have to have enough error correction to screen out the noise that's created because there's a lot of extraneous data that's produced when you're doing this measurement. Normally that takes a little bit more horsepower to do, as you mentioned, A lot of times it's being run on the same computer that's actually doing the work, and that requires a lot of space, a lot of electricity, a lot of liquid nitrogen.
Yeah, really liquid nitrogen. These things have to be cooled within a few degrees of absolute zero in order to be able to run. So on the one hand, you know, you've got cold fusion, which is we want to be able to run fusion in anything less than the heart of a star.
Now on the other side, you've got warm quantum computing, which means we wanna be able to run it anywhere north of 273 degrees, science degrees below zero. And so the the idea is here that if you can start getting more precision in your calculations on cheap hardware, it allows you to take the investments that you're doing to make the quantum computer itself run better. And this is the, where I've had a little bit of, um, disagreement with some of the news that's come out about quantum computing over the last couple of years is that some companies like Google are racing to produce a computer that has like the massive amount of qubits available to do these calculations, right?
Like you, you hear about, you know, we've got a computer that can do hundreds of qubits or thousands of qubits, and every time I read one of those articles, I didn't see any mention of error correction. And that's for a good reason. Uh, for those of you out there that are audio files, well, what happens if you wanna make the music louder, right?
You, you go over to the speakers and you turn the knob all the way up. What happens when you turn the knob all the way up? You increase the noise of everything in the system, not just that, uh, beautiful, uh, you know, uh, Johnny Lee H****r Blues album that you're listening to, but all of the stuff in the background that was, uh, captured on the recording as well.
That's why we have digital signal processors and all kinds of technologies that allow us to screen out that background noise. We're using it right now on this episode of the rundown to screen out my daughter coming home and slamming doors and walking around in the background. But in order for that to work on a quantum computer, you have to be able to screen a crap load more data, and that is a quantum unit is crap load.
But what you're gonna run into is, is that, that it becomes relatively expensive. So I'm glad that a MD was able to make this work. I I can't wait to see what more applications come out of this.
And if you stay tuned for a closer look, I think you might actually find out that we're not the only ones that are interested in seeing what more can come out. Quantum computing, Qualcomm is entering the AI data center market with two brand new processors. The AI 200 and the AI two 50, the first gonna launch next year in 2026.
And the one is, the other one is gonna launch in 2027. They're designed for AI inference workloads. The chips support major AI frameworks and will be sold as part of integrated rack systems or individually if you wanna pocket them in your local microcenter.
And they're looking to target cost conscious enterprises with that. This move diversifies Qualcomm beyond more than just making chips for mobile phones and positions them to challenge NVIDIA's dominance in the AI infrastructure market. And that is a key market being driven primarily by a generative AI and large language models and the hardware that powers it, most of which comes from Nvidia.
The launch signals a strategic shift that could reshape Qualcomm's growth and industry standing. And we've been waiting a long time for a company to come by that has a credible threat to NVIDIA's dominance in the market. Al, can Qualcomm pull it off?
Well, that's a billion dollar question for Qualcomm really, isn't it? Uh, two chips turning up next year in the following year. Yeah, it's, it's kind of feels a little like this is, um, me too.
We're a little bit late to the party, but we realize that, uh, that this is gonna be a big party. It's not really, because silicon design takes an awful long time. It's not like writing software where you can make a change to code and see that code run a few minutes later.
When you are working in silicon, things take a lot longer to cycle through and make changes. So it's not that they completely missed the boat and are are starting to run very late, it's that the engineering to do this takes a long time and maybe they weren't certain when they could complete that engineering. This announcement means they're pretty sure they're gonna be delivering some, uh, valuable turn in next 12 months.
Um, I think this is really good. We do need to see some credible competition for Nvidia, and I think they're very wise to target inference. Inference is the phase where we're actually running an application that delivers some value.
A lot of the time we're seeing a lot of focus in the AI industry around what do you do for creating foundation models and what do you do for training? And it becomes a second thought that we're actually gonna need to get some business value for all this money we are spending. And that business value comes from inference.
So yeah, seeing Qualcomm focusing on inference and focusing on what I characterize as in as an engineered system. So a rack scale infrastructure full of inference hardware. Uh, I think this is something that we will see more of.
Uh, we last week at, um, at Cloud Fields Oxide computer showed us that same rack scale infrastructure idea. I think, uh, there's wasn't full of Qualcomm chips, but maybe some of the later ones will be. Uh, Qualcomm delivering this as, as rat scale infrastructure for running your AI workloads on.
Seems like a really good move. Others in the market, uh, a MD has made announcements. Intel of course has had, uh, their accelerators in the market for a little while as well.
So it's not that Qualcomm is the only challenger for Nvidia here, it's just that we haven't seen anybody unseat Nvidia from being that primary accelerator for our workloads. Palo Alto Networks is expanding its AI tools with Prisma as two and Cortex Ag Agent X to support AI applications and automate security tasks. So AI for security and security for ai, uh, Prisma two secures AI models and agents throughout their lifecycle where Cortex agent lets teams build and manage AI agents to handle threat detection response and policy enforcement automatically.
These updates help organizations stay ahead of moving cybersecurity challenges as AI uses rapidly increase both by the companies that are targets as well as the bad actors. Who would like to use AI to attack you. Uh, is Palo Alto the best place for all of this?
Is it a necessary place for all of this? I think it is. If you're Palo Alto's investors, because they, they want to see something being done with agentic ai, right?
I mean, LLMs were so last year, or was it the year before? Whatever, it doesn't matter. New, new things, new new stuff, right?
A agents, what are agents? Um, they're stuff that does things for me and stuff, but they need to be secure. 0 comes into play.
Uh, we're gonna secure your models and secure your agents so nobody can do anything with them. And they're not supposed to do, you know, this is, uh, like the scene in the movie where the, the positronic net brain has some kind of a security mechanism and, and it'll keep you from, I don't know, corrupting it or you can just wait for it to do it on its own because we're still kind of at that point where AI likes to make stuff up. Uh, the other thing, agen is all about making and building these agents.
Um, you may remember this from, uh, your early days in, in working in computers. This was called, uh, writing a program. And, and it's weird because that's really what you're doing is you're writing yet another program that runs on your network.
And yeah, it looks for threats, it gives you suggestions for the responses. If there's a policy enforcement violation, it can take care of all those. I want you to go out and do a favor for me.
I want you to survey all of the security analysts and operations people in your organization and ask them how comfortable they are with an AI agent handling threat remediation and policy enforcement for them on their own. Just, just curious, do you get like, um, oh, I think that's a really good idea. Um, I would love to be more efficient in my, my, uh, role or do you get Oh my God, no, not a chance because I know which one you're more likely to get.
I understand that a lot of people are really excited about the, the concept of what an AG agentic AI system can do. And I love that these are the same people that wanted to take a lot of these zero trust, uh, tools and just turn them on and see who screened the loudest to determine what needed to be adjusted. Did you know that the screen test is actually a thing in it where you implement a policy change and you wait for people to screen before you adjust it?
Yeah. Are you as horrified by that idea as I am? 'cause 'cause I, I get it.
Everybody has to have AI in their system, right? And if you're security company, you better be securing the AI that people are wanting to use and you better be coming up with ways to build AI to do stuff for you. And I can't wait to see if Agentic AI can make it into 2026 as the hot new thing, or if we're gonna discard it off to the wayside and move on to some other thing that everybody says we have to have in our product.
Boy, I really hope that we don't get burned on this one, but if we do, there's an agent for that. We had a story that we wanted to take a closer look at, and we've alluded to it because it involves the US federal government and the fact that they're considering taking a stake in several quantum computing startups like Adam Computing, D-Wave Ion Q ti, and Quantum Computing and Exchange for federal funding of at least $10 million each. This program is gonna be managed through the Commerce Department's chips program.
You remember that one. And the plan aims to support us quantum companies provide needed capital for them, and potentially earn returns for taxpayers reflecting the government's growing role in strategic tech investments. Al we've seen the US federal government buying a stake in companies as of late, including Intel and others, but do you think that they're going out on a limb here by trying to invest in quantum startups?
Well, it's not a lot of money they're talking about here. I mean, it does say at least 10 million, but I mean 10 million's, a pretty small amount of money when you're building brand new kinds of infrastructure. Um, just as a, because we were talking about liquid nitrogen cooling before for, um, quantum computing.
I was looking at that, and that's, that's probably one of the costs these companies have and costs about a buck a gallon to make liquid nitrogen. Uh, so, you know, 10 million liters, uh, 10 million gallons of liquid nitrogen, that's quite a lot of liquid nitrogen, but that's just a consumable. That's not the thing that they're actually building here.
So, uh, unless the amounts being invested here are a lot larger, I don't see that it's actually gonna make a, a huge amount of difference to the financials of these companies. The validation that the US government thinks that they're strategically important enough to the, to the country, because fundamentally that's gotta be why you're investing here. Speculative investment is the, the job of the venture capitalists, the government's job is to look after the country as a whole.
And so investing in these companies is really putting a, a little sticker on them saying, uh, tested and approved by the US government more than, I think making a big change to the, the business model in here. Uh, absolutely these companies will be very happy to get that sticker and to be able to show that sticker off to the, uh, venture capitalists who are going to be the ones who front up the billions of dollars it's going to take to commercialize a quantum system. Uh, of course this is all still proposed and maybe, and, and talked about and thought about, uh, and it's partly because these American companies are, are struggling to secure funding.
And so that sticker saying approved by the government has, has gotta be a good thing. How much return are we gonna get to see? I'm not sure that the, the returns are gonna be near, and like a lot of these, uh, early investments, there's gonna be a lot of failure along the way.
So you wanna see a big return from a relatively small number of these investments that you make, just like any other venture capital, uh, does follow that precedent of taking a stake in, uh, Intel recently, uh, that was a much larger investment. It was a nearly 10% stake in Intel, uh, as well as some of the securing of rare earth, um, materials that have been. Um, that's the Pentagon side, making sure that they've got a secure military supply of areas.
It's, it's not quite the same as a, a central government investment. So yeah, there's some, some prior art of these investments, but, uh, I don't know, Tom, is this a good use of your taxpayer money? No, no, it's not.
Uh, I I, I'll go out on a limb here and say, uh, $10 million for a lot of these companies, relatively speaking is a drop in the bucket. It, it covers a lot of operational costs, really. And when you consider that a lot of these companies are already kind of backed by very large organizations anyway, why on earth would the US federal government want to basically kind of toss some change at people?
Well, a lot of these companies are private, which means they don't have to disclose anything about what they're doing, what they're working on, what their direction is. And so if I buy into them a little bit, that gives me a look into the company, including their financials and their projected plans, right? Because if as an investor they have to brief me on it, even if I own a pittance of the actual overall company, now you, you wouldn't think that that would give me the ability to, I don't know, influence the company's direction, right?
Like that would be wrong is if the US federal government stepped in and kind of directed the company to do certain things, to research in certain ways to create opportunity for us, uh, interests to be coming out on top. No, I I, that's a conspiracy theory, right? I'm, I'm sure there's some group of political people out there that believe that the government should keep their hands off of businesses, right?
You, you can go look up which one that one is, and then giggle when you realize who was asking for this. I think that the US government really does need to keep their hands off of this. What they need to do is they need to use the National Science Foundation as the vehicle to move money into these things because it creates a layer of insulation.
Because you said that a lot of these companies are gonna wait for that little sticker that says the US government invested in us and we must be great, right? Then I'm gonna go up to Sand Hill Road and I'm gonna convince all of those people that they wanna invest in me. And what I'm seeing when I see that little sticker on the, the prospectus is so there's an outside actor with more power than me that can step in and basically invalidate my investment.
If they decide, you know what? We don't like the way that this is going. We're gonna create regulations that's gonna allow you to not work on this anymore.
We're gonna pull your government contracts for this thing because we don't like the way that you have, uh, ignored us on this one little thing that we asked for over here. You're probably sitting there saying to yourself, there's no way they could do that. They've done that.
The, the current administration has done that many times recently, and there's nothing stopping a future administration from doing that on either side of the aisle. If you think that I'm trying to, to play a certain kind of role here, anybody could do that. And that little 10%, $10 million investment gives them the foothold that they do because if the government hadn't invested in them, government wouldn't have any idea what to do.
And so I think that this all needs to be run through the National Science Foundation. It needs to be run through outside parties that are not directly involved with the day-to-day operations of the US Federal government. Quite honestly, I think it might be time for the, the federal government to get out of the business of investing in companies hoping to get a payoff.
'cause I will tell you that as a taxpayer, I'm never gonna see that money. In fact, I don't know that the federal government's gonna see that money. I I don't have any visibility into where it goes and I'm a stakeholder in the US Federal government.
You're not. But I am. I do wonder also whether that insight into what they're doing might really be something where the funding should have come from darpa.
That it's actually the, the Defense Department, sorry, ministry of War that, uh, wants to look inside these, these quantum companies and possibly see the, uh, military applications for it. 'cause I think maybe that's the, the interesting insight on that rather than ncf, although of course I'm sure there's some, uh, some spokes who, uh, are part of or at least observing what happens with NSF. Of course, if you'd like to observe what's going on in the future, we highly recommend you check out the AI Field Day that is running October 29th, why that's today and tomorrow October 30th, Stephen is out in the Bay Area with a great lineup of companies and delegates as usual.
And of course, you should probably be watching that live stream as well. Then we've got a little moment of break before you have to travel, Tom. That's right.
I am gonna be out in Silicon Valley on November 5th and sixth with Networking Field Day. We are gonna have a great lineup of companies and they're all gonna be talking about ai. Surprise, surprise.
com and check out the lineup. We've got the schedule posted. Uh, gonna be some great conversations, some wonderful delegates that are joining me for this one.
Uh, it's kind of fun, uh, but it's not the most fun that's gonna be had in the month of November. I think that might belong to you, Al. 'cause what are you doing the week after, The week after I get to spend some time at KubeCon, north America and Atlanta?
So we'll have a day of presentations at Kku Con. We've got, uh, south Works and Traffic Labs and VMware by Broadcom presenting all looking at cloud native Kubernetes stuffs and some of the operations around them. So it'll be on, uh, November the 11th.
I of course am gonna spend some more time at KubeCon learning about all of the interesting innovation and vendors that are there. But that week you're gonna be somewhere as well. Do the people at home get to know where you are spending your November?
Uh, actually I'm gonna be working at the Commvault Shift event that's going on in New York City Now. Steven's hosting it, but I'm actually gonna be a delegate for this one. com before you know it.
Um, but I've got a great group of people that are gonna be joining me there. I get to go to Times Square, um, maybe I go get to visit the whole all guys, who knows. But I also get to learn about data protection and all the cool stuff that Commvault's been working on.
And that market is exploding so fast right now. Uh, like the, the investments that are going on, the acquisitions that are happening, uh, I'll have a lot to say and Steven will have a lot to say as the host of that event. So make sure you check out our website for more details.
We also hope that you will join us in the future for more great episodes of the Tech Field Day rundown. We're here every Wednesday, sometimes with the two of us as co-hosts, and sometimes we invite new people. Uh, there will be somebody co-hosting next week because I'm gonna be out at Networking Field Day.
But no matter what happens, make sure that you catch us when we are streamed on Wednesday. Uh, make sure you subscribe to us in your favorite podcast application, because that's a good way to listen to us when you're mowing the lawn or, um, painting the walls. Just don't pick yellow.
Evidently. It is the slowest color to dry, as I was told by my wonderful producer Corey. Um, but whatever you choose to do, we hope that you leave us a rating and a review so that everybody knows how great we are around here.
But we're only great because you're great because you continue to listen to us and you keep showing us stories that we definitely wanna cover. We'll be back next week with more great information and a little bit of fun. But until then, take care of yourselves.
Have a happy Halloween and we'll see you in November. Platform Engineering on the eve of CubeCon. We'll be back in a minute.
Hello everybody and welcome to the latest edition of a Textron gang. We've got a awesome lineup as usual. We got Gina Rosenthal, Jack Poller, Wiki, Wang, and Andy man.
And we're gonna have a conversation about a lot of different things today, all of which are top of mind for folks. But as I mentioned early on, we are at the first day, or at least the pre-first day of CubeCon, there's gonna be a lot of folks hanging out in Atlanta all week long. And today there is this platform engineering session going on, which apparently is jam packed.
0, which is essentially all about how AI will be applied to platform engineering. But Gina, I know you looked at this article and I know you've kind of talked about with this in the past, but I'd love to get your take a little bit on how real is platform engineering in your mind? What is this thing?
'cause it's a little still, shall we say, amorphous? Well, I think platform engineering is a good idea and I think this article, there were, uh, there were some very interesting, uh, there's a very interesting section about from scripts to systems. So platform engineering is this idea where everything can be run from code and you can build your, ultimately the hope and dream is your ops and your development teams are gonna work together because they have this platform that the engineers can just, um, say what they want their test system to look like or what they want their development system to look like.
And so instead of doing it on their laptops or some system under their desk, it's all being cooled with real world, real world scenarios. And the little test beds are being built with like, it's gonna look in production and they go crazy. Then they check it into the, to the, um, the CI systems and then everything just works as it should just by itself.
And the, the premise of this idea is that we've gone from scripts back in the old ancient days when I was assistant man and we're gonna now get to this AI native intelligent insight that's gonna be step three. And the, the, the, the problem with this article with me was it just kind of didn't give a lot of examples of how that works and what's going on. That was the first problem I had.
I love the idea of thinking about, you know, automation first that everything should be turned into code and that can, and I think that is a fa fabulous idea. That is not a new idea. That is something we were, I was doing back when I was assistant man for Soliris and Red Hat.
We did kickstart and jumpstart scripts and with some arcane, horribly hard to understand language and you just hoped nothing in the, um, hardware side changed too much that you'd have to go back into that language and, and fill it out. Now you have all of these great ways to develop these scripts. You've got all sorts of great systems.
You've got companies that are doing infrastructure of code and doing the hard work of figuring out the, the hardware intricacies for you so that you can have this continuously, um, updated system. So they think we're at the self-service stage, which is step two and standardization, which that's the hard part. That is the super hard part, especially if you're dealing with bare metal or you're dealing with a cloud that might decide to change something out of the blue on you and, and mess all your systems up.
Part I really had a problem with though was the AI native, what are we calling ai? I mean, this is like an AI thing to me more than a platform engineering thing. What is ai?
Because the things that we need to look for drift in scripts that we need to help, uh, have, have a way to inventory all of the servers you have available, or VMs you have available already you're working with. Um, and to see where the problems are. That's, if it's anything, it's what they call narrow ai, which is what we've always called machine learning and deep learning.
So it's not, we're not looking at some brand new thing that's gonna automatically learn and do all the things and put the icing on a cake once that happens. If you've never had to deal with the intricacies of hardware, even on a cloud, the differences between things in software versions, um, then you, how do you learn where's our next gen coming from? How are they gonna ever know how to do things if we don't remember that all this changes?
That's what makes it really hard. And while it would be great to say AI does it, I don't think you, I don't think the author really maybe thought about what ai, I would love to have seen some examples of what she thought that was. So that was my thought.
But I, I love the idea of it because it sucked doing it the old way. So I'm hoping it's getting better for people. You know, Gina, one thing you mentioned was, you know, arcane languages.
And I think the, the premise and promise of LLM integration, whether you call that native or not, is the ability to put a natural language interface on, uh, what we're doing with computer configurations and, you know, the, the infrastructure configuration, the ability for us to be able to say, Hey, I want this server to have this many instances and to be able to talk to that machine in English language is a very useful, uh, capability. And I think that will help us in the long run. Getting there is the really challenging part, and I think that's your right to, to sort of raise that is how do we do that and what does that really look like?
Yeah. And is this just an elaborate effort to get rid of scripts? I mean, are we wrapping buzzwords around buzzwords just to kind of kill the scripts?
Well, yes, because we're in it and we're, we're talking about software and vendors and stuff, so absolutely. Uh, you know, this is what we do. But look, I actually think this I'm, I I, I do agree with Gina on one point and I disagree on quite a lot.
Uh, but I agree that, look, this is essentially an ML thing. I think this is not really an ai. Are we talking a gentech?
Maybe we're talking a little bit about LLM. Look, I actually worked on this at Splunk like a hundred years ago, right? Uh, we were partnered with Puppet, puppet does automated provisioning and configuration management and stuff, uh, typically out of the older world, but, you know, novad under the cloud regime.
And we prototyped this idea of intelligent machine to machine deployments. Um, is that agentic? I mean, we were using machine learning to understand the known knowns of a configured environment, you know, so going out using Puppet, do I be able to understand what's happening effectively maintaining this idea of a dynamic CMDB?
Yes, I said the C word. Um, and using that as an LLM to then plan and automate the deployment the configuration, the scale up, the scale out right. And then the deprovisioning.
Um, I actually think this is a super opportunity. A lot of operations, I've talked about this before, is unknown unknowns when problems occur, troubleshooting, that's where you need the smarts to do the hard work and the thinking. But you know what?
Deployment and configuration management, that's where we have a lot of known knowns. We have things like golden images. We have things like LL uh, like uh, CDBs.
We have scripts that define how code, how infrastructure is deployed in our infrastructure as code. Um, so we actually have a bunch of known knowns. I think this is potentially a really positive way to get out of the configuration management business as humans and be able to use these, you know, machine learning on the pipe to understand what is a good configuration, what is running a good, a known good environment with high performance and being able to like, uh, uh, Jack said, you know, talk LNLP.
Hey Siri, uh, fire me up a gold image. So, 'cause I wanna run an AI workload. Boom, we are there.
I dunno. Yeah. It is a little bit future forward.
Um, and yes, we are trying to sell a bag of goods when it comes to this future forward notion of platform engineering. But look, I actually think this one could be real. No, I totally agree with you.
So don't, don't get me wrong, right, because I've worked on, you know, I've worked in the old school, I haven't had the privilege of having to assist admin, a new school kind of thing. But my point is, is, is we've, and this has always been my point, we are a computer scientist and we have had this spectrum of things that hasn't started. I mean, you're, that was like crazy blow your mind stuff 10 years ago to me.
But back when we were doing, just even doing jumpstart and kickstart the beginnings of this, um, that your problem that you solved solved so many problems we had with the developers, right? So like the, the promise of being able to say, developer, I have a developer, has a user case, he doesn't know what it's gonna run on, or she doesn't know what it's gonna run on. If they can declaratively say, Hey, I wanna, like you said, you know, I wanna build an ag agentic, um, platform.
They can, that that could be done automatically. I think the problem I have is feeling like th this is something humans never could have accomplished. That, excuse me, that we're using AI to do it.
One sec. I'll start that over. So I think the problem is that, um, we're acting like this isn't a continuum from where we've come from.
We, we need to recognize that we need to recognize it's not ai. We need to start call, stop calling ML and a and, um, deep learning things. Ai, there are products that have those, um, capabilities in them already.
So my point is, let's, when we talk, start talking about this and hopefully when we get, when, you know, hopefully Atlanta will see this, you know, this week we need to see some examples of how you've built this in already. What does this look like? Instead of just this, oh, we sure be nice if we had these three.
Can't define three stages without giving some proof behind it. That's kind of my point too. Mm-hmm.
Wiki, I'd get your opinion here because the one thing, and I don't hear a lot about when I hear the phrase platform engineering is security, compliance or any of those fun things. Yeah. So I think the key cons, insights is, uh, the team can't stand on a single tool, right?
Anymore. 'cause it's so complicated. Now they do need a governance and, uh, uh, observability layer that can spend different frameworks and plots.
So I think ai, LLM, that ability can make it happen, right? So in this year, in RSA or this year, I actually see a lot of different AI tool can make it happen. A lot of company make the AI or LLM elements in their tools to help in this area, which is fascinating.
Yeah. Andy, I can't figure the following out. Is platform engineering something apart and distinct from DevOps?
Is it the evolution of DevOps or is it just kind of really a DevOps mulligan and we're just doing this over again with a different kind of spin on it? Oh, mate, uh, oh, you put me on the spot with that one. Look it, uh, DevOps, as we know, DevOps is fractured into all sorts of commercial opportunities and platform engineering is absolutely one of them.
Look, this kinda actually comes out of the idea of a Spotify model. So not actually DevOps. This is not about collaboration, communication, communication and integration of teams.
This is about having a service department, um, which is okay and I dunno that I love it. Um, the, you know, the idea of platform engineering definitely comes out of DevOps. It comes out of infrastructure as code.
It comes out of the idea that developers aren't actually operations, they don't actually do provision provisioning, configuration management. And we shouldn't ask them too. So the, I think it does come out of DevOps in that devs have asked ops to do a job for them, which is build environments that are gonna work and scale and, you know, ideally be predefined to be secure and all these sorts of things.
But ultimately, yeah, I dunno, I don't know that I love this. Um, I think having an expert team to sort of replace the golden image team with a dynamic, uh, on demand provisioning team, I don't think it, it, it breaks down barriers. I don't think it breaks down walls.
I really like it from an automation perspective. And if I was a developer who could just click a button and go, boom, there's my environment, I'd be super happy. Uh, but I think it does take some of the collaboration out and I think it does sort of work against some of those good principles of DevOps that we've worked towards for so long.
That idea of collaboration, that everyone's on the same team, that we're all working together to get this software out the door. Uh, I don't know that it's positive that way. Uh, Gina, do you think that we have an opportunity here to maybe finally bridge the divide between the classic IT admins and the DevOps engineers and maybe we'll all link arms and sing Kumbaya together?
What do you say? Oh, man, why? That's Andy's question.
Uh, you know, I hadn't thought about what Andy just said that, um, this, uh, this I idea that a developer could just declaratively state what the environment should be, might not be a good thing because it keeps the developer separated from the ops people. And it, it does get rid of those that one of those DevOps principles. And I kind of think that's probably true because I think we've got, we, and I think we go in stages with this as, as the hardware matures and the hardware is able to do more things for the software, and I think we're probably in that stage and we're probably gonna be in that stage for another couple of years.
Um, where you, you don't, you as an ops person, the reaction might be to over, not over secure, but to, to keep that away from the developers. Let them just run fast, give 'em what they need. And this is a way to do that.
And so maybe that takes away, so I, I'm not sure, but I, I do think that that's not a good thing on the ops side because it's much better, um, to work with your developers and understand what they're needing and what they're gonna declaratively call. So it's already there. So not having to deal with each other is probably in the long run, not a good thing.
I got that from you, Andy. Thank you. There you go.
Jack, help me out here. So, software engineers will have their own AI agents. They may have, I don't know, each member of the team will have, let's just say arguably 10 developers will have their own AI agents and they'll probably have 10 of those.
And then we'll have a bunch of AI agents that are assigned a particular task on behalf of the A on behalf of the team. And this all sounds wonderful, and of course something will fit in the middle of that to provide some orchestration. But as I continue to think about it, just the overall complexity of managing that may be beyond the cognitive capabilities of our mere humans.
0? Because once I get past, I don't know, 20 agents, can I really manage that? Well, we love, uh, specialization in it.
And so I think you're now gonna see the rise of, you know, we have this thing we call AI ops, but you're now gonna say, see AI platform engineering whose job it is going to be to maintain, build, and maintain the AI platform that helps the platform engineers build and maintain the platform on which our apps actually run. And at some point, the specialization is gonna be a little bit crazy, right? Where we're gonna have people whose only job it is, is to just, you know, tweak one button so that somebody else can tweak a button so that somebody else can tweak a button.
So eventually we can run something somewhere. Uh, you know, I think, you know, the counter argument to that of course is that the, you know, as I said before, you know, a AI and LLM gives you the opportunity to use a natural language interface. Uh, AI in general gives you the, uh, opportunity to abstract away a lot of the drudgery and complexity of the day-to-day things so that we are no longer, I mean, if you think about what is, uh, uh, infrastructure as code, it mean it's taking away the need for an infrastructure person, whether they're a developer or an operations person to log into every individual machine and type individual commands to configure that machine, right?
Instead, we have a, a a, a level of indirection and a higher level language. We can talk about how we want things to look and let something, let a machine do the complex, you know, minutia of configuring every little bit and bite. And if we can then abstract that out one level, maybe we can do away with some of the platform engineers and some of the DevOps engineers and some of the AIOps engineers because we've automated enough of this that the underlying infrastructure is complex, but the management of it is simplified.
I hope, I hate how right you are about some of this stuff, Jack. Um, I hate to think that you are right, but I think you are right. We're gonna have agents, running agents and you know, this, this actually does come back to something that Gina pointed out, and that's the skill issue.
And the more we have this embedded in platform engineering, this expertise and the more complicated the environment gets and the more we seed that knowledge to the LLM or whatever agent, uh, AI it might be, where is the knowledge gonna come from when we need to do something new and different? You know, the, the golden images or the infrastructure as code definitions that we've got today are not gonna get us to where we need to be tomorrow. So who then figures that out?
So yeah, I think, I actually think you're right, Jack, and I hate that you're right. 'cause we're gonna, you know, to Jean's point just atrophy a lot of knowledge into those systems. So the thing is too based just, sorry, but based on Jack, what you said about the, the, the agents managing agents, does that mean we'll have to have a specialized section of the CMDB to accept tickets from all these agents and disperse them properly?
I think so too. 0 version, right? Which is where you simply automated what humans do.
But the real, the the right way to do all of this is to rethink it and say, how does you know a clean sheet of paper? How does it look if you had a clean sheet of paper? And what would machine to machine communication look like to, to make these things happen?
Take the human out of the loop and do it the right way the first time. Yeah. I just wanna say like, uh, I just talked to somebody, uh, this week talking about how to how they manage the agent identity or like code agent as part of the thing, right?
It, it's kind of interesting like, uh, agent and agent used to talk together, but people still need to be in the loop. Yeah. Make it happen.
Yeah. Well folks, I don't know whether you believe in platform engineering or not, but I will tell you that people who have platform engineering certificates and things like that seem to be making about 20 to 25% more than your average DevOps engineer does. So get yourself a certificate whether you believe in it or not, because well, you get yourself a raise, we'll be back in a minute.
You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included, that work your protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity, your digital front door is wide open. And what compromises your home can breach your boardroom.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black clerk, digital executive protection, defending the new attack surface your personal life.
All right folks, we're back and we're shifting gears a little bit. There's been reports that Apple plans to have some sort of deal with Google to embed Google's ai Gemini models into Siri, which, you know, a lot of folks are talking about. But Wiki, I'd like to get your opinion on this.
And of course I'm a little biased. I I use Google, I have Android phones, and I kind of looked at this and shrugged and said, well, if Apple's going to use Google, why don't I just use my phone in the first place? 'cause it's the same AI model, so why am I gonna get a different phone to go talk to a different model?
I don't know. But what's your take on what's going on here? I actually, I wanna talk from two per perspective, right?
First of all, like Google and the Apple, they have collaboration for a long time, right? From the search side, Google still need to pay, uh, apple to put their search into the Apple phone. So it's not new.
They have a collaboration. So that, and second thing, I think, uh, apple actually play, play very, very smart. Um, you know, like all those big hats, they put lot of money into the GPO and try to get all the chips, um, and spend a lot of money, right?
Um, but Apple, they, I feel like they're very calm. They, they, they always waste their pace, right? They, they choose very smart to how they spend their money on the info or other thing.
So, uh, it's not bad if they have some, they leverage what our Google has already and to enhance their LML um, capability, right? So like I, I do talk with somebody, uh, early this year in my podcast, uh, when they talk about their LLM, they used to, uh, really won't have their own model. Uh, but their, their prediction is if they have their own model, their delivery will be in 2027.
But at the time when OpenAI suddenly, uh, said, okay, we have that API and they can quickly plug in and then make their, their, their product happen within two, 2025, right? Which is a huge jump and huge saving from their side. I think Apple is kind of like doing the same thing.
They try to leverage the capability Google model has and spend less money from their side while at the same time they try to deliver the best product. I think it's very smart. This is my opinion.
Yeah. Jack, what's your take here? Because on the one, some folks would say it's a bit of a black eye to Apple because they're leaning on Google for AI after talking up their own Apple initiatives for a while.
But to wiki's point, maybe, you know, these things are compatible with each other and you know, better sooner than later. My understanding is that this is theoretically a, uh, sort of a stop gap measure, I think as Wiki was saying that, that Apple needs something. Now, what I don't understand from Apple's perspective is what is the value of owning your own LLM model?
And, you know, apple likes to control its own destiny, but does having a model that's not Gemini and that's not, uh, open AI's model and somebody else's model, what value does that bring to Apple in the long run? And is it worth the ROI of, I don't know what's cost now for them to do it? 10 billion, $20 billion to build a model, right?
2 trillion parameter model. So it's five times as big almost. And you know, in terms of the amount of knowledge it has and can consume and, and manipulate.
So I just don't understand what Apple gets from having their own model. And I think chasing that is a fool's errand. Uh, 'cause uh, people always talk about where's the future direction for the AI or LLM because of the energy resource, uh, strengths, uh, we tend to see like it's more at the age end, right?
Which is like a small language model. I think it's still have a value if Apple can keep their own model, uh, towards, to like a smaller size model, um, specifically to support age technology. So I think this is some PO point I can add.
Yeah, Andy, I gotta tell you, and this is kind of similar to what we just talked about in the previous thing, but I'm a little worried that at some point in the future, my AI agent is gonna be talking to your AI agent and they're gonna negotiate something. And the next thing you know, I'm gonna be meeting you and Timbuktu because our AI agents set up this meeting. How are we gonna manage all this and kind of keep some level of control around?
I don't know, mate, if, if my Outlook calendar will only handle time zones perfectly, then I think would be great. Uh, but no, look, I I it is gonna be, uh, an agent to agent. Well, machine to machine is something that I know, uh, colleagues of mine, people like Dennis at EMA who's retired now, um, the, the, uh, research emeritus, uh, has been talking about machine to machine for a long time.
And it, this comes out of older technologies. You know, everything older is new again, you know, my thesis, it process automation and robotic process automation combined with intelligence and library knowledge becomes, you know, agentic AI in a lot of ways. So yes, this is, this is absolutely gonna be the case, but I think that's actually part of why this is a good deal for Apple because this is not a case of agen ai.
This is not a case of advanced intelligence and becoming a differentiator for their platform. You know, you think about things like Gemini, Claude or, or Anthropic, and you think about corporate use cases and you know, understanding what is my customer buying patterns and you know, what, what other offers could I make to get someone out of that mode into this mode and stop churn that's not this right on device AI for Apple is like, uh, take a picture of my grandson or delete my ex from this photo. Or, um, um, answer a question.
Why do cowboys wear chats? I don't know. Um, this is what on device AI is for Apple.
Is it gonna really differentiate them to have their own model with a trillion, uh, of vectors? Or can they get away with a claw and anthropic a Gemini? I think that's really smart because it's, yeah, we are gonna get to where you are going agents to agents, machine to machine.
This is absolutely gonna be a thing, and that's its own problem. But this is very much about grandma trying to, uh, uh, get her phone to work properly. And I think Apple intelligence has been missing in action, a total dud.
Um, and as WY said, you know, Google and Apple, this is a partnership already. The enemy of my enemy is my friend, and they both want to see Microsoft not succeed, right? So this idea of being a slow up with core competency differentiate everywhere else, like Wiki said, on the experience on the device, on the software, on the walled garden.
Is AI gonna make the difference for 'em? I don't think so. So yeah, I think this is actually pretty interesting.
I don't know. I'm a little bit worried about, you know, someday my father-in-law's gonna call me up and he is gonna say, Hey, can you come pick me up? And I'm gonna say, where are you?
And he is gonna say, I don't know, but it says in the, in somewhere in the South Bronx, and I'm gonna have to go drive down there and get 'em because the phone sent him there. It's true. I mean, people just, I this is true already, right?
People just follow their GPS blindly and turn to canals and, and down one way streets and all sorts of things. Put it this way, uh, just because Apple is getting Gemini is not gonna make humans more intelligent. Well, the oth the other thing about it is that's a little worrisome, is one of the main drawbacks to LLMs is the data that it has been historically trained on.
And that is the Internet's wise, wonderful world that is absolutely discriminatory towards women, people of color, people of that are, um, disenfranchised. So that's kind of the worry thing. 'cause I thought Apple was one of the places you could trust to have trained their model and to kept some of that out.
This is just kinda like what I've heard. I don't use Apple either. I use Google, which is a whole different story that you try to keep up on and it's impossible to, but if, if you know that those models have been trained that way, um, then, then how sure are we that the, that, that, that doesn't creep in to the Apple model, is that same tort types of kind of hidden biases that are in the, in the data, because that's how our, our history has been.
So, um, I think that's a concern to think about. I may, I wonder if that's why they're going so slow to do their own thing. I tell you what I would love to see though, because you know, my household is a split one, right?
Half the house is on Apple and the other half is on Android. Wouldn't it be wonderful if this AI stuff made it easier for us to communicate with each other on our phones across different apps? So then that way I don't have to sit there and get my wife telling me that I should get on, you know, the Apple video conferencing platform so she can call me better or more easily, or we don't have to use WhatsApp as an intermediary.
Is that gonna be possible? What do you say Wiki? I should say everything will is possible, right?
You never know. So something cannot avoidable. So, well, that's it.
We, we, we, we will wait to find out, Jack, last question. Will people switch from phones based on the AI experience? Or are we pretty much having this kind of Coke versus Pepsi thing and everybody's already decided, and it's just a question of what capabilities are gonna come in, but it's not gonna change anybody's mind.
Oh, I think people are much more passionate about Apple versus, uh, everybody else than Coke versus Pepsi. And there are, there are people who say, you'll get my Apple device outta my cold dead fingers, right? They're not switching no matter what.
I know people who have actually said they won't join a company because they couldn't have an Apple device. They wanted another, you know, they want their Apple MacBook and their Apple phone, and if the company makes 'em use a Windows box, they're not going there. So, I mean, we're way past that point.
All right. I billions will be spent trying to convince people to switch, but I think most people have already made up their minds, and I don't think we're gonna see a whole lot of people going, oh wait, that AI experience is so much better. I'm gonna give up my phone and switch everything out because that, I'm just jealous of that ai, I don't see it happening.
I I I Apple device a lot, right? Like no matter what kind of a large language model they are, they're, they're try to move. Um, sorry, I don't think that it will change my, uh, habit to use Apple.
So, and my Apple fan, sorry. All right, well folks, I'm gonna leave it there, but I'm pretty sure we're gonna enjoy the fight. Whether you switch or not, we'll be back in a minute.
Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. All right, folks, we're back with our final block of the show. And Jack Poller has an interesting story up on Security Boulevard talking about why in Israel they're sending cars back that remain in China.
Jack, is this gonna become a global phenomenon Or what's going on here? Uh, well, yes, it actually is. And I, I thought this was gonna be just, you know, because rightly so, Israel is very paranoid, but it turns out they're not the only paranoid country in the world.
And Denmark had the same problem, the same discovery with electronic, sorry, electric buses that they bought from China. So let's first talk about Israel, and we can talk about Denmark in Israel, they, uh, have banned 700 plus cars that were, uh, imported from China, that they were leasing to senior officers in the military. Their first step a couple of months ago was to ban the cars from going on base on military basis, because the cars are equipped with cameras and microphones and uh, and cellular connections.
And they weren't sure what was going on. They, so they started to investigate those cars and they decided that the systems were complex enough that they could not guarantee that sensitive data was not being sent back to China and or that people couldn't hack into the cars to get access to the cameras, microphones and the data. So from a military perspective, there's a very big operational security.
If you know that the cars are associated with senior military officers and you can at the very least track their locations, then you know where the military officers are theoretically, and that's a big, uh, operational security and a big risk. Um, so that sort of one risk that was identified. So Israel's response was basically saying, we're taking those cars back from the senior military and we're just not going to allow anybody in the Israeli military to use cars from these companies.
But I think it's actually a larger problem in general because if you look at most modern cars now they have a cellular connection and they can do an over the air update. So you can't, even if you inspect a car software that's embedded in it, then it can be updated. So you have to keep track of all of that.
Denmark sort of looked at it and said, well, we have the same problem with Chinese buses now. They're not concerned about the operational espionage portion of it. They're concerned that somebody, either the Chinese government or a hacker could come in to their electronic vehicles and basically turn 'em off and then they wouldn't be able to use them.
And there's, you know, this is, uh, very small countries, but reliant on public transportation. So their first response was to, they pulled, uh, three of their bus models into a cave that was basically essentially like a Faraday cage, so underground so that no radio signals can go in or out. And they were trying to figure out what the buses were communicating.
And based on what they found, they decided their first response was to pull the sim cards to prevent those buses from communicating to the rest of the world. And they said, any updates that come in, they're going to inspect the updates before they get applied to the buses. So there's a couple of different ways to look at it.
It's a cybersecurity risk. It's a, um, it's a potential denial of service risk. There's a hacker risk.
The hackers can come in and, you know, the, the, the big scare where it's here around the thing that it's Chinese. But if you think about it, it's all, it's basically all the modern vehicles. If you look at a Tesla that comes in, a Tesla has, you know, five, six cameras that are recording 24 by seven, right?
And is can, you know, and the Tesla headquarters can get access to that data at any time. So there's a big security risk here of who can get access to that data. And essentially these things are rolling, motorized spy vehicles is one way to look at it.
Andy, will this go the other way? To Jack's point. So, you know, United States, we sell cars overseas and some countries may decide that we too are injecting things into there and it can become, uh, an issue where everybody just says, I'm only buying cars made in my country.
Yeah, absolutely. And I probably should to a large degree, especially with, uh, sensitive environments, not just military, uh, but also infrastructure and other things that might be at risk. Uh, you know, and again, it doesn't need to be nation states.
These could, it could be about nefarious actors taking control. We've seen, for example, various, uh, cars being able to be packed in remote controlled, you know, literally being able to crash you on the freeway. Um, it doesn't have to be some sort of James Bond secret squirrel thing, planting a secret listening device and all this just to, you know, just to leak some sensitive data.
Jack's spot on all of these cars have got this ability, and it's not just over the air updates, it's GPS, it's back based telemetry for things like, you know, diagnostics remote start and stop a remote takeover. Look, Tesla's already bricked cars that have failed on their repayment plan. Um, do you think if, if our president comes out to Tesla and says, can you tell me where so and so is driving?
Yeah. We've seen this also, by the way, with Uber many years ago, using telemetry to, for nefarious purposes in that case, tracking, uh, journalists that were critical of them. You know, this doesn't have to even be a nation state problem.
And yeah. Is if, if, if the US government needs to hack into a Ford or a General Motors car that's made here to find out where someone is, and by the way, we've seen this with things like, uh, GPS devices on watches, soldiers going running off base in Afghanistan. I think it was, were giving up their location 'cause they had Strava, the running tracking app connected to their GPS watches.
This is not an Israel story, this is not a China story. This is just a modern connectivity story. But I do think you're right, Mike, the, this is gonna be a give, give pause to a lot of nation states who are thinking, well, what if America takes over my buses or cars?
You know, this is absolutely not limited to these two or three nation states. Mm-hmm. Wiki, every morning I get up and it's cold here in New York.
So I get out my little mobile app and I get the car turned on and I get, you know, defrost going and the whole thing. So the car is kind of toasty warm, and I get into it. Is that now gonna have to include a security scan before I get in it?
What do you think? Uh, theoretically, right? From professional perspective, I think from the data perspective, they do need to have some like encryption for your, like driving data to protect where you go, right?
And your identity or something. Um, for like, but if you see the, the other interesting facts here, uh, actually in Israel, that company that that Chinese car company right, is the best seller for September, actually compared to other car company. So I think I respect their, their innovation and the quality they have there.
Um, but I should say like not only for car, right? Other iot d wise, it's very hard to standardize internationally. This is very, very true point.
'cause there are, there are so many different, um, protocols or so many different models try to standardize it. So I do respect like a, a different country has like different thinking. Yeah, that's my, Uh, Gina, should I sell the car and call an Uber?
Would that be better? Depends on where you live. That's another argument.
A whole different thing. Um, but I, I think what's missing too, like, I, I think everybody is talking about the, the holistic ways that could be problems. But even down to the smallest thing, if you have an ex that's trying to track you or wants to do something bad or trap you, if you've got, uh, people go on strike and just, or wanna be on strike, so they disconnect, they log in and disconnect everybody system.
It's incredible. I know they always have a car hacking village at Defcon. How many, um, s systems are actually running electronic systems, communication systems are running within just your normal Ford car, right?
So there's, there's almost like, I'm not sure how much of a responsibility the Karma users are taking for those systems, um, to let people know. I know I've never gotten anything from Ford that says, Hey, you should, you know, make sure you don't do this and this, that information is just kind of going off into the ether, I believe. So how do you, there are, it seems like there should be a way to contain your personal data on the car that you paid your money for to your personal vehicle, um, and to be able to be notified if something has gone awry.
But even as I'm saying that, like, who's gonna understand that? I definitely don't wanna teach all my family about that. Like, what is the system since this is a, you know, it it's the nation state thing is a big deal, but the nation states have their own armies and whoever they have working on that, you know, technically.
So they've got very smart professional people, probably the smartest in their nations working on com, you know, protecting that sector. But you know, what happens if there's, you know, worst case scenario, there's a way to hijack a whole city because you can turn the cars against each other or you can, you know, you can shut 'em all down and how can you protect yourself against just the common normal things of your x tracking everywhere you go? 'cause he hacked into your tire network.
So mm-hmm. You know, Jack, We talked about foreign governments here, but you know, the, my local government may not always have my best interest at hearts either, right? Because it could be that, um, you know, they wanna track whether I'm gonna go vote on Tuesday, where's my car, and send me a message telling me the polling place is closed.
So, uh, Or, or who you're voting for, right? Depending on who you think you're, they think you're voting for, they may say, you know, let's disable all the cars of this group of people so they can't get to the polling place. So that way we get more votes of our people, right?
There's the, but yes. And, and I look at this as, as the greater story is that for many, many years we've, we've waved a hand around, uh, we've done a lot of handwaving around it and industrial control, I, sorry, ot, uh, IO OT and industrial control system security. And from an enterprise perspective, we basically said, okay, the, the short, quick, easy way to deal with that is we put them on an isolated network.
There's a, you know, and they're sort of separated and it's essentially the version microsegmentation of a large scale for IOT devices. But the reality is that almost everything we have these days is an IOT device. If it's got a radio in it, it's you, it's not on a separate network that you can isolate and somehow control.
If it's got a cellular network in it, you have no ability to, to understand what it's communicating to whom. And it's a bidirectional communication. So if somebody, if you can send messages into the device, a bad person can send messages in and take it, you know, and take it over.
If you can send data out, you can send data out that you don't want it to send out. So, you know, I mean, and this is not a new problem. I remember, you know, 25, 30 years ago when camera when, uh, um, cell phone makers started adding cameras in to cell phones and, uh, you would go into a manufacturing facility or a chip fab, the first thing they would do is say, all phones in the bucket here.
You can't take a phone that has a camera with it into this facility. 'cause we don't want any pictures here, right? So, I mean, but that, that was easy because we could confiscate the phone.
Now you, you know, what do you say, strip naked? We take every single electronic device off, you know, you have your rings and you know, your, your watches and all the other stuff that we have that, you know, everything's got a radio in it, even Bluetooth, right? So the how do you, you know, we have a big problem that we've sort of, like I said, we've done a lot of hand waving around.
And that's sort of, I don't know, I guess I'm putting the red flag out there and saying, wake up, pay attention to this a little bit. Alright. I think we're reached that point where to a certain degree in every country we live in a surveillance.
Uh, let, try that again. All right. I think we've reached the point where, to a certain degree in almost every country, we live in a surveillance state, whether we like it or not, it's now a question of what we're willing to tolerate or not tolerate.
But as everybody just pointed out, maybe it's good to have a healthy dose of paranoia. Hey, I wanna thanks our guests for sharing their knowledge and insights today. I wanna thank you all for watching today's show.
It was great. And please stay tuned to the rest of the text drawing TV lineup. It's gonna be equally awesome.
And we'll see you all again tomorrow. Hi everyone. Welcome back here to Techstrong tv.
You know, I, I've so much going on in the world lately. I've, I've had the pleasure of talking to the few of the folks at suse and, uh, but here's one of my favorite. There were words, SU arians, seins.
I don't know what the right thing is. I honestly don't know. Let me get you Ntroduce here to my friend Peter Snails.
That snails with an M, not an N, correct. Otherwise we call SNAs with an N, we go the other way. Snails, which is easy.
S with An hey, snails with an M. Easy. Peter is the SVP and GM for Enterprise Container Management at suse.
Peter, welcome back. It's great to have you on Tech Drug tv. Thank you.
It is always fun to be here. I love the conversations. So a little bit of wishful thinking with that background.
Or you're on vacation. I wish I was on vacation. I, uh, I won't give too much.
PII, but so I'm, I'm up in Massachusetts, so this is really more wishful thinking. It's a pretty nice fall day, I have to admit. But that's definitely wishful thinking.
Hopefully I'll be in a setting like this, but apparently this is your backyard from what I understand. So good for You. Well, it is pretty much, yeah, it's, well, so that beach is across the street from me, but I am, but I will be up in Boston actually in November.
My, my son is getting sworn into the Massachusetts bar. Oh, wow. And we're, yeah, we're coming up, I think the 18th and 19th, something like that.
But congrats for that though. I'll be in Atlanta for CubeCon. I think you will too.
Yes, sir. And, and, uh, that's what I wanted to talk a little bit about today, about sort of a CubeCon preview of what, what we think maybe the big themes, themes that CubeCon are gonna be. And, and you know, what, what Susie, what's Susa doing?
And, and we're not here to talk about. I, I know you guys are gonna be releasing news and people are gonna just have to wait for that until CubeCon itself. Yeah.
But that doesn't stop us from talking about kind of the bigger themes. But before we do that, Peter, I, I wanted to jump into, I, I mentioned your SVP and GM of the Enterprise Container Management, I guess a division or team at, at suse. Well, You call it a business unit.
Okay. The bu Yeah. Great.
Is that the rancher business? What we used to know is Rancher business more than that, you know, part of it. Give us an idea of what that BU is about.
Yeah, I, it, that's a great, it's, it's a great question. I think the simplest way to answer it is it, it's technically a business unit, but at the end of the day, we have multiple businesses operating in context, you know, so as you know, we're heavily focused on edge, we're heavily focused in AI specifically. We have a, we have a sister division, you know, around Linux.
So I would abstract sort of away from sort of like what we call bus away from sort of what we ultimately deliver from a market standpoint. So sort of, sort of back a house versus front of house. Because ultimately what I'm, what I'm looking after and what I'd get up and care about every single day is, is ultimately cloud native.
And I have counterparts I work with, there are other folks you talk with, you know, Keith, basil and you know, Avanav. And so for all the different folks, but at the end of the day, we operate in concert. And so, kind of coming back to your point about next week, like we do have a bunch of news, we will, we'll sort of tease that a little bit now.
But thematically the important message for folks to take away, regardless of sort of the, the, the back of house bu stuff. At the end of the day, SUSE is all about delivering a platform. We are, you know, the market leading open infrastructure platform actually for not only Cloud native, but also Linux.
Obviously I'm focused primarily on the cloud native stuff. So ultimately it is about putting all of our best resources forward to deliver this open infrastructure platform. What is an in open infrastructure platform that is basically a single unified management control plane for developing, deploying, and managing all of your cloud native workloads, regardless of where they are.
So again, that's where, from a platform, it could be everything from, we'll talk next week more about big focus around VMware modernization. We are a landing spot. Our open infrastructure platform is a landing spot for organizations that are modernizing away from VMware.
Okay. So we'll talk more about, so we continue to invest in virtualization as a core component of the platform. We have a bunch of exciting stuff we're gonna talk about next week around Prime.
Everyone knows Rancher Prime as the primary, you know, the primary platform for enterprise container management, if you will. And that's sort of the mm-hmm. The, the central control plane in the brains, if you will, from a, from an infra management standpoint.
Bunch of exciting stuff going on there around things like observability, um, infrastructure, resource optimization. You know, how do you basically make, how do we continue to make prime for its part the best platform for all cloud native workloads? And that means you have to manage all the infrastructure.
It means you have to help people optimize the resources of that infrastructure. It means that you need to make the user experience as simple as possible. And so we're gonna be touching on, you know, uh, you have to give them the insight and visibility to be able to do intelligent things with that platform.
So you can imagine next week we're definitely gonna be touching on virtualization. We're definitely gonna be touching on things around observability. 'cause that's so front and center.
Um, we'll certainly be talking about AI and we can kind of double click on that. But you can, Ima the most important message, again, if people take nothing else away, the most important thing is when you think Susa and you think Cloud native, think Susa as the open infra platform for all of your cloud native workloads inclusive of those spokes on ramping from VMware modernization. Absolutely.
You know, we, we've seen a real, or where I sit, right? Seen a real evolution in what we, what cloud native is. Hmm.
Right. For most of us, we call it cube con. Right?
And so if it's Cube Con, it's probably about cube, about Kubernetes, right? K But another name for the show is Cloud Native Con. Right?
And that's, I think the official name, or maybe they're both official now. And I think this is the year that cloud native con becomes real. It's not just CubeCon anymore.
Yeah. You know, when you look at the top five projects at CNCF, I think at least two, if not three of 'em are observability related. Yeah.
Yeah. Ai, AI is pervasive up and down this stack. Yeah.
Service me grown up. Yeah. Well, if you're not doing AI at this point, you know, you gotta ask yourself why and how far behind the curve you are.
Yeah. Right. That's kind of where we are.
It's crazy, but true. Yeah, no, just a, a couple funny things on that front. Number one is that, uh, I technically have sort of two titles because I'm also the general manager of Cloud Native.
And that's honestly part of the evolution because what you've said is, is, and, and I wanna say they're both, they're sort of interchangeable. It's my point. Like it's not, it's not two separate jobs.
But to me, I think you're spot on. And the reason that you're spot on is if you go back, I mean, we've been at this a while, right? If you go back to the early days of Kub Gun, which is around 10 years, right?
And the early days it was, how do I use Kubernetes? How does it work? What do I do?
You know, and that's where rancher, you know, like our, that's where we really cut our teeth. We were the first kids on the block because I'm an absolutely, we made Kubernetes easy, we made it simple. And it's why we have, you know, tens of thousands of active users.
It's this enormous community that's rooted in making Kubernetes simple, but where the market and everything is evolved. And why we talk now about being the cloud native platform is it's all, it's maturation. I mean, I, I joke about how Kub, it's still Kub Con, but look at sort of the, the, what's the word I'm looking for?
Sort of the commercialization of Kub Con, kind of the, the, you know, the, um, the enter prioritization that, you know, that look at the, the people coming. You go five years, six years ago, you go to KB Con, it's all backpacks, you know, and the sessions are super tactical now. You got a lot more suits.
You got a lot more ties. You got a lot more. And this is because a different set.
Look how I'm dressed and I, I didn't wear my jacket today, but used to, you know, I used to No, but I used to go in a t-shirt. You're the people, you're, you gotta, you have to span the whole spectrum. So you gotta be able to do both.
So you put the blue blazer on the universal. Yeah. You know, I can do everything.
It's a uniform, but it's, but it's, but your point is valid, which is that it's now, I mean, just the, the ultimately the strategic value and the strategic nature of cloud native as a technology for enterprises, you know, small, medium, large enterprises, it's, it's business critical. It's mission critical. It's no longer about does it work?
How does it work? It's about the overall ecosystem. It's about maturation, it's about security postures, it's about, to your point about observability, accelerating remediation, reducing risk, reducing tc, I mean, it's just the whole thing has become, it's still about tech and innovation and all that kind of stuff, but fundamentally the nature of the conversations are changing.
So it's just the overall landscape is, is evolving. And it's super fun because from the beginning of time, you know, the thesis has always been, you know, those who can basically, from a, from a, from a go to market or from a business strategy standpoint, like those that can provide, you know, consolidated management, you know, and simple management of a cloud native infrastructure will do well going forward because you're riding the wave of adoption of cloud native within the enterprise. And you know, the VMware stuff with Broadcom, it's just one more mega catalyst that is creating motivation and the catalyst for people to say, you know what?
I don't want it replace, like for like, this is gonna help me accelerate my cloud native modernization journey. What do I use? Where do I go?
And I can only, I can only reflect on that in terms of, just from a suse business standpoint, that's exactly what we're seeing happen. It's, these are C-suite conversations. These aren't, you know, you go back five, six years ago, it's just purely developers bot completely bottoms up.
Now you're talking c it's completely the other way around. It's, it's actually, yeah, no, it's completely, it's both obviously. It, it, and it meets in the middle.
Yeah. 'cause there's a middle allowed element to it. But here's an interesting thing.
You know, we recently did a whole series of webinars with AWS and some of their partners around, around VMware, around modernization, transformation, moving to cloud, et cetera, as you would imagine with a WSI think the whole Broadcom VMware licensing issue, if we could call it that. But we all know licensing is just another word for dollars and cents. The price increase it's given people, it, it, it, it's sort of a, a boundary layer where people are now saying, wait a second, I may wind up paying what they want me to pay.
I may stay on VMware. Yeah. But this is an inflection point where I now should take a look at what my options are.
Do I want to get rid of virtualization all together? Like run, run cobe on bare metal? Yeah.
Do I want to still keep a hypervisor but run a cloud native stack with microservices on top of that, on maybe one of the hyper, you know, hyperscalers virtualization platforms. Do I want to use a SUSE and standardize because I'm not moving everything to the cloud today? And We never will.
Like we never will. Right, Exactly. And so I want something, I don't want one os there and one os here, and I, I, I want to keep my stack consistent.
So I, I need a suer kind of that that bridges that, that's, Yep. Um, All, all of the above. A little of this, I want to be on multiple clouds.
And that, by the way, just to jump in there, it's, it's again to, from a Susa overall value proposition, you, you, you've, thank you. 'cause you've nailed it because it is a bit of all of the above, you know? Yep.
But it's, for us, it's for us, it's not about being like, for like sort of get from point A to point A in the context of virtualization, but to your point, it's, it's, it's like, um, it is absolutely a catalyst. It's creating conversations. And the key is you have to be adaptable.
You have to be flexible, you have to be composable, you have to be open because it's not, it isn't a one size fits all. And that's something we're finding from a, just from an overall market landscape and from a Sosa, you know, value proposition, people really are drawn to the openness and the flexibility. It's not sort of an R way or the highway kind of thing.
We are a bridge, but we're also a retirement home for VMs. Like, it's, there's, it's all about what ultimately the organization our customers are trying to do. And we're well positioned there because of the openness and composability of our platform relative to others are more like, okay, here's your box, here's your big box, which you can put here, there, or everywhere.
So it just sort of speaks to our different approach to the market, I guess is really what I'm saying. Absolutely. Well, and it, you know, it it, I think it speaks to suse being a full spectrum, I guess is a good word, full spectrum solution.
Peter, you gotta look ai, it, it's, it's on, it's in every conversation now. Everybody has a, a situa, you know, a story. Everybody's doing things.
I know SUSE is mm-hmm. Uh, without, you know, going into the specifics of your announcements next week, how do you see AI playing in these things we're talking about? Yep.
And, and that's, uh, very easy, uh, very ans very easy answer. Um, sort of two things. I'd say two dynamics.
Number one is we want to be, we said we want to be the open infrastructure platform for all workloads. Okay. That's inclusive of ai.
So we will absolutely be talking about the work that we're doing continuing to do around suse ai. Okay. And that's about being the best platform for running AI workloads.
Okay. So one is, and there's a lot there, and we can unpack that next week at the show and so forth. But basically one is about being the platform.
So that's vector number one. And, and no surprise, wait for it. It's about being open, it's about being composable, it's about being flexible.
So we'll double click on all that stuff next week. The other big piece though is also obviously ai, you know, ag agentic from a user experience standpoint. So no surprise, we will absolutely be talking about our efforts on that front, um, around the use of ag agentic, full ag agentic for enhancing the user experience of the platform.
So I'd say those are the two primary vectors. Um, and both fronts are quite exciting. I know there's, you know, everybody might wanna try and say that I'm, I'm really pleased and excited with the stuff that we're doing and I think we're gonna blow some minds when people can get into the details and come see it in the booth and play with it and do all that kind of stuff.
So we're excited for next week. Very cool. Yeah.
You mentioned something before about the kind of the, let's call it the changing demographic for Coop Conte for cloud native con attendees. And, you know, I've seen it too, right? We, we, in my mind though, beyond, beyond how they dressed, we went from a very developer, heavy, real, developer, heavy, almost exclusively developer.
Then we saw the rise of the ops folks, right? What I think we've seen over the last couple years is a combining of DevOps and Cloud Native as well. As platform engineering.
Right. Platform engineering has a huge audience at, at cloud, native Comic CubeCon. And it's a, I think the most po last.
The last one, it was the most popular, like zero day mm-hmm. Uh, event was the platform engineering one. Yeah.
I, and actually ing you triggered a thought. I'm glad you mentioned that. And again, without, without you have to come tune in next week.
But, um, we've always been, uh, you know, super strong on the ops side, you know, and we've made great, you know, we've, we've invested a lot of time and energy and resource and innovation, you know, on the developer side as well. And that's both from an open source standpoint, clearly just from a community innovation standpoint as well as, you know, from a commercial platform standpoint. And so, uh, I think people are gonna be, uh, suffice it to say we have a, we have, you know, our open source community has a very, very, very, very large developer community.
Okay. The rancher developer community has a very large community. And so there's some really exciting stuff we're doing on that front that is actually gonna sort of, if you will, big shift left.
Because to your point about developers, they're still front and center. So if you look at the maturation of the market, a lot of say security and security posture and that type of stuff would get taken care of by the ops folks. But where the world continues to shift is, you know, how do you put even more and more, how do you continue to meet developers where they are now, put more of that control into, you know, move it upstream, whether it's security, et cetera, you know, secure supply chain, that kind of stuff.
So I'll leave it at that. But there's some super fun stuff going on. 'cause we stay, we, we absolutely stay near and dear to the developer community and we got some very cool stuff coming down next week.
I think people are gonna, I think people are also gonna real just net net. I don't know if I can hide my enthusiasm. We're obviously looking forward to next week because we're, we're all in the mail.
We're bringing some exciting stuff, so we can't wait to, to share it with everybody and, and have 'em, you know, come join us in the booth and play with it. I love it. Peter.
You know, I always tell people passion is contagious. Mm. I love the passion.
Agree. Thank you. I agree.
No, I appreciate it. I love these conversations. Absolutely.
Hey, there's going to be a lot of, uh, of news next week on this. We're gonna try to get you or some of the Sousa people over to, we'll be, we'll be broadcasting live all week from the show floor. Nice.
So Tuesday, Wednesday, Thursday. Sweet. Uh, so we will catch up with you there when we could talk more openly about this.
But, you know, I think, as you said, suffice to say there's a lot of, a lot of stuff to be unpacked. I think it's gonna be a great event. It's gonna be a great Kon.
Atlanta's a great town. Yeah. Um, And by the way, one thing, I gotta get this in as well 'cause this is all completely public, but remember when we talk about open infrastructure for suse, let's not forget about Linux.
We just made a massive announcement on this last 16 stuff. So again, next week is obviously sort of, you know, focusing on that side. But again, folks, when you take it away, this is building directly on top of all the very cool stuff we've produced that's Done this last month.
Well that is the underpinning for all of this, right? Yeah, absolutely. Look, just a little plug on my own side.
I wrote a nice article on this. Go check it out. It's, you did, it's Brilliant.
It's brilliant. Yeah. Thank you.
On tech Strong it, so go check that out. You know, I talk about AI and everything else that I think was, is a big story there Peter. We'll talk more in Atlanta.
Come ready and, uh, I'm Already ready. Look forward to seeing you next week. All right, my friend Peter Smails, SVP and GM Enterprise Container Management at suse, doing, giving you a quick CubeCon preview.
We'll see you next week in Atlanta. This is Alan Shimmel for Tech Trunk tv though. We're gonna take a break right here.
We're gonna be back with more. Stay tuned.