Techstrong TV September 10, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey, everyone, do we have trouble with triples, I mean, tariffs? You're watching Text Drunk Gang. Hey everyone, welcome to another text, drunk gang.
Happy Wednesday to you. Uh, I'm Alan Shimmel and I'm coming to you today from out in Napa Valley at the Jfr Swamp Up event where we're talking about DevOps, a lot of DevOps software supply chain, and more. We're gonna get into that, but we've got a great show lined up today.
We've got a great panel to talk about it with you all. Let me introduce you to our panel today. Uh, we've got our friend Chris Blak, Garima Bal, Jeff Rich, John Willis, and of course John Schwartz, who's out here in Napa with me.
Of course he would be. He is our Silicon Valley person panel. Welcome.
Thanks for joining us here on Textron Gang. Um, so we're gonna lead things off today, riffing off an article that John has up, um, regarding tariffs. I mean, to say the least, it seems like our tariff policy is unstable, um, geared towards, you know, who whoever bends the knee, uh, on, again, off again.
But it, it's hard, it's hard to figure out what the heck's going on, John. Yeah, yeah. I, I, I wish, I wish I could explain it to you as well, because what I'm doing is like a timeline, and the timeline shows a consistent thread of threats from the Trump administration, especially after he has his closed door meetings with the tech executives.
I think, uh, our excellent producer, Taylor, put it really well. He goes, haven't we talked about this before? And I was like, yes.
This is like deja vu all over again. It's, uh, I'll just give you a little, uh, a quick summary of what just happened in the last couple of months, and I'll make it really quick. 5 billion for over its ad exchange business.
A day before that, the Trump administration threatened to slap tariffs on, on semiconductor imports from companies not shifting production to the us, which is a major theme of this America first strategy. Last month, Trump vowed in a social media post to levy substantial terrorists on countries that regulate or tax us tech, tech companies, specifically. He's talking about Europe, but he is also talking about Asia.
And then July, he proposed a ban, which was, I think, crazy on US tech companies that, that are outsourcing jobs to India. And I think my, my takeaway, and I will pass this on to our esteem gang, is that, you know, in a sense he's made tariffs a key tenet of his foreign economic policy, uh, to exert pressure not just on people overseas, but companies that are, that are here and in a sense, in a way to kind of strong arm or force them into building data centers or investing money in manufacturing here. Now we'll see where, how that goes, but I'm very dubious of it because I think what's happening is that these tech executives are whispering to him all these promises and throwing out all these numbers that they have absolutely no intention of ever following through on.
There's just trying to appease him in the, in the short term. So this is what we have is you have like basically favoritism based on threats and on, based on, um, his agenda to bring manufacturing back. It's, it's a crazy world, and it's gonna keep changing day by day.
Okay. Anybody want to jump in here? I, I'm sorry, I had to editorialize a bit because I find this stuff head spinning.
It's completely inconsistent, but I, I, I see what the ultimate goal is, is basically like, and for everything else he does this intimidation and frustration and confusion. I mean, I, I think it's just, I I, you know, I don't have much to say about this. I'm very interested in the chips, you know, like TSMC and what, you know, where, where they wind up in the big picture versus China.
But to watch Tim Cook grovel to, uh, to Trump, it, it was, I know Trump is antithetical to everything he believes in. Um, you know, it, but it, it makes me think, John, what you're saying is they're just playing this game with him. Yeah, right.
They're saying, I think I think you billion. Absolutely. You, you got it.
No worries. You know, so anyway. Yeah.
Yeah. I'm glad you mentioned Tim Cook, and I'm just, I'll, I'll, I'll stop talking, but I'm John, you're right, totally right about Tim Cook. I mean, he, in a sense, I think he knows how to play Trump pretty well, but at the same time, to me it's rather sad, empathetic for what, uh, apple stands for or used to stand for versus what they are now.
Well, well, yeah. So, so we're, we're logical tactical people by definition. That's, that's, you know, this is actually tech strong.
You know, we think through things and things make sense regardless of what they are, and they can sometimes make stupid sense, but they make sense, right? And, you know, as, as you, you folks know, but we do a lot of semantic breakdowns. We look at the logic of words and systems and so forth and see how you, you know, 'cause you can logically describe what's, what's going on in this case is a perfect example.
And the Hyundai right is a, is a great one. And we did a, you know, we did a Casco breakdown in that one. And if you just logic and walk through it, the, the story that makes sense in English words is that, you know, the, the, the, you know, investment, you know, the billion, the dollars was invested in the states and Georgia, that wasn't important.
And the immigration, uh, part wasn't important either. So what is I important? The only thing left is concentrating authority, right?
To demonstrate, specifically have a spectacle where you say, if you thought doing this would work, and if you thought doing this would work, you're wrong. There's only one thing that can work. And that's a, that's a well worn story, you know, that is played out in history in the world over and over and over again.
So for us to stand here and say it doesn't make sense, and it's crazy, is is it a good emotional, it's an honest reaction. But like any, you know, I've dealt with threat actors of all sorts all, all my life, you know, including all of the, you know, all of them, you know, terrorists and bad rogue states and so forth. And you always break it down.
And there is a logic there, and it's important to understand what it's, so I think this is, this is a, a relatively simple semantic puzzle, and we just walk through it and you can see what the reasons are, and you can predict and adjust and, and combat, if you will. You know, those structures once you understand them. Chris, I, I gotta go with you real, real briefly.
Um, because a lot of our members at I, at IDA are outside of the US and I have conversations with them and they asked me questions like, how can you justify what's going on? Like, I'm not the person to ask, first of all, but it, to me, simply put, tariffs are our cule and Chris, well, you said the objective's gonna be there. It may not, may or may not be actually related to trade, but there is a cule available and it's used.
I, I got a few thoughts on this. So, Chris, to your point about historical, you know, use of monarchs and despot, despots, you know, there's been a few documents in the history of humanity to, to deal with this kind of rubbish, you know, hammurabi's rule of, uh, rule of law going back a couple thousand years beyond, you know, before Christ, the Magna Carter, the Declaration of Independence, the US Constitution, you know, little, little things that define the relationship between a ruler or a government and its citizens. And when those kinds of things get trampled, you wind up with things like Nazi Germany, Mussolini, Italy, Franco, Spain, Stalins, right?
Stalins, Soviet Union. You know, the, and, and, and, uh, and I'm not here trying to, you know, doom say all of this because I, I, I do think we're, we're coming to a point where the people in this country, or at least a majority of the people, a clear majority, are saying, you know, this, this is, this is just nonsense. There are the 30, 35%, whatever.
I don't know what kind of drugs they're on, but, you know, they're, they're gonna go along and, and believe, and maybe it's because they have their own their own views on it. But the fact of the matter is, look, we have a case before the Supreme Court right now, or it's going before the Supreme Court. We're an appellate division in a very well reasoned decision, said, these tariffs, these tariffs are wrong.
They're illegal. He has no power to do that without the it's Congress. So Jeff, to your point about a cudgel, you know, I, I, I posted a couple weeks ago on my Facebook feed, actually, 'cause I don't try to do politics stuff on LinkedIn, a a video of Ronald Reagan, that libtard Ronald Reagan, right?
Where he talked about why tariffs don't work. Why that at first it may seem to work 'cause you're getting the money, but what you're doing is you're, you're, you're not cuddling, you're coddling the companies that you are protecting and, and make them, it's like being an overprotective parent and you make an emotionally damaged child, you make a, a non-competitive company because they can't compete on the world stage without your protective tariffs keeping. And sometimes that's okay to do for short term if you're looking to build your industry or whatever, but using it as the weapon that he's using it here is, is not healthy.
It's not even healthy for the companies you're purporting to protect that. That's the bottom. Yeah.
You know, it's in, you said that, it made me think about, I mean, just the intel and the relationship between the government and intel now. Like, I think we're, we are gonna see other types of those deals. I'm not sure who with, but this kind of overprotective kind of almost symbiotic relationship between the government and tech company, which is completely an athema.
It's just, it's, you're gonna see more of it. And I, I wanna mention one other thing, the nonsense story about, well, it's the foreign companies that are paying these tariffs. It's not the American people.
You know, I have a good friend of mine, Jeff, you probably remember Stephen Northcut. Steven, of course I do. Yeah.
Yeah. And Steven's also not want to be a bleeding heart liberal, right? Steve Stephens, free conservative, Steven's one of the founders of Sands, he's retired now.
He put a post up just today, I saw it that him and his wife ordered some goods. I think they were from England or, or somewhere, some kind of China, you know, uh, ceramics. And that, uh, the UPS people called him and said, well, look, in order for us, we've got your goods here, but in order for us to deliver them the tariffs on these, uh, the goods, were about $300.
The tariffs on these are $61. So you, we need you to pay the $61 now before we'll deliver them. Well, that's not a tax on the manufacturer or the company sending it.
That's a tax on you, right? That's $61 added to the cost here. Well, you know, Alan, I wanna just tell you a quick story, which is just, and no defense here, but I sent a book to Mark Burgess, my, my book, right?
'cause I wanted to ship it really fast because he, he wrote the forward for it, right? And, uh, so I sent it like two days to, um, to where he lives in, in, um, not Norway, uh, now I forgetting where it's, but our country. So it got stuck in, in, um, in, in, you know, tax whatever evaluation.
And turns out he had to pay like $60 for a free book that I sent. Um, anyway, so it's sort of like, you know, like, again, no defense, but just, it made me think of that story, which a book, well, Well, what happens is, is you get reciprocal tariffs. Yeah, yeah, yeah.
But I mean, yeah, yeah, yeah. And, and, and that's what Ronald Reagan said in that video, one of, so he mentioned three or four things. One was, you know, companies become non-competitive.
The second thing was that you get reciprocal tariffs. And what happens is basic global trade breaks down. And, and Ronald Reagan, like, like the Republican party we, most of us grew up with, was a big believer in free trade and go globalism.
And, and you know, it's a big markets out there. And, and so, you know, this is what happens as a result of this. The other thing, John, you John Schwartz, you brought it up, and I just wanna emphasize that is the, the uncertainty of all of this today, it's on tomorrow, it's off.
Kiss my ass today and it's okay. Do something that upsets me and it's not okay. This sort of chaos, chaos that we're all being subjected to is ultimately that even if he was doing something right, it's wrong.
Right? The, the chaos business doesn't thrive in chaos. That, That, but, but that is of course, the point, right?
And there was a, there's a song from a, a one man play about Billy Bishop, a World War I, uh, uh, ace that I always think about in conflict. And it's, it's after he had, uh, become famous, going back to England, getting trotted around, getting full of himself, and someone over and wiser gave him some advice. And it goes like this.
It says, when you fight, stay as calm as the ocean and watch what's going on behind your shoulder. Remember, war's not the place for deep emotion, and you might get to be a little older, right? And I've carried that through my entire career because it can get really exciting.
And usually we're the ones on the outside. It's not us being attacked. We're helping people be attacked, you know, who are being attacked.
We're helping build defenses. And, and, and, you know, you know, I love and respect all my peers, all of us, you know, here and so forth. But, you know, we're inside this loop and we're talking about, you know, the, the room when the reality is, you know, to your point, Alan, the rest of the world has moved on, and there's plenty of articles about this that I can tell you the next FDA or next, you know, n regulation comes out, it will not have the effect of any of the previous ones because nobody in the world cares.
We're not gonna adopt, you know, in Australia or, you know, anywhere, you know, the next FDA re regulation because it's RFK running it. So, you know, the game being played, uh, against the, uh, uh, population is to keep it in chaos and keep uncertainty. And, but, you know, from a cold conflict, you know, professional perspective, it's pretty simple.
What we actually do about it. Know, I have my opinions, but they're what they're, I think we, we've talked about this before where we talked not, it's not so much about America first, but America alone. And I think, Chris, you nailed the, nailed it with this idea that the rest of the world kind of moved on, is moving on, and we're the last suffering, you know, internally killing ourselves.
And it's just, um, it's just the state of things right now. It is, it is. You know what?
I don't want to beat this dead horse. Yes. Let's take a break.
Let's come back and talk about something excitingly. DevOps, you're watching Text Game, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. No access. Editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients. Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Techron Group.
Hey, everyone, we're back here on Textron Gang on Wednesday. You know, my friend John Willis hasn't been on in a little bit, or I haven't been on with him anyway, so it's always great to have him, but, uh, it reminds me of, when I think of John, I, I think of DevOps. No, no, no offense John.
I think of a lot of things, but DevOps is one of them. Um, and you know, lately, you know, we spend a lot of time on the gang talking about ai, too much time talking about AI and, and what goes on in our government and everything else. But I, I wanted to spend a little bit of time as long as we've got John and Garima two really big DevOps pillars here, talking about kind of the state of DevOps Garima, why don't you kick it off and we'll let John jump from there.
Yeah, thank you Ellen. And it's a privilege to speak, uh, on this topic in front of John, our North Star. So I'll start with my view from a community perspective.
Uh, I had written an article called DevOps Plus, uh, in the beginning of this year, which talked about the next era of DevOps and the capabilities which are into play and why it is important, uh, to adopt, uh, in the emerging technology era. DevOps, uh, for ai, DevOps with quantum. These are key themes of those, uh, that article.
But I also believe that there is a wide range of capability which are needed as a foundation to integrate these emerging technologies. And we must talk about AI native software integration, for example, why DevOps plays an important role, AI native technology stack, for example, how it is impacting and, uh, you know, influencing the DevOps platforms, how DevOps platforms are integrating, uh, AI agents, for example, or tool based integration points. Open source also is offsetting a lot of these, these challenges by bringing data sets, repositories and models.
And, uh, some of the examples I can talk about is me and John, uh, last year I think we met at a conference and we discussed a lot of things. And I was intrigued by what he was talking, uh, in conferences. I think, uh, I heard him talking in DevOps days, really, uh, for the first time about shadow AI and shadow AI in making, and that intrigued my curiosity of, you know, what we as DevOps practitioners could do about it, right?
So that was very timely that we had that conversation, John, last year. And we said, uh, to ourselves, you know, as practitioners and committee leaders, we gotta do something about it. And that's where the DevOps for gen AI hackathon originated from.
And now we have done it in, you know, a couple of cities. We are going to Toronto in November, but I mean, giving you a reflection of, uh, what, uh, we could expect from DevOps and the challenges which we are facing in the AI native software. If you think about like, uh, communities like CNCF and CDF, we have also been exploring the potential of observative, for example, CICD, uh, stack for AI native software.
Those are kind of, uh, really good questions to kind of, uh, dwell into. And, um, I think, uh, at the hackathon, uh, which we did in awa, we had a, a suite of applications which came out for, for observability team or observability space. So these are the changes or the, these are the trigger points, which you can see from a community perspective.
And I think I would also like to, um, uh, share this platform with John and get his reflections on, you know, our findings together. And maybe John, you can also highlight your views on, you know, the conversation we had in London. I still remember, it's fresh in my mind and, uh, how the hackathon experience went and, you know, how do you see the state of DevOps taking, uh, you know, uh, the next steps?
Well, lemme say everybody needs a garima. 'cause I just, I just mentioned the idea of a, a je I hack DevOps Jedi hackathon, and man, she just went off to the races. So, um, you, you're a pretty amazing in what you helped put together.
And, and I, I think I've started the idea and now we've got another one coming up at the end of this year. Um, yeah, I've got a lot of thoughts. I, I was saying this beforehand, I was talking to Andrew Clay Schafer, right?
And he's one of my dear friends, uh, also, you know, sort of a giant in the DevOps community. Um, you know, he told me a story, um, of how, um, CMU all the stuff they've been doing on security and stuff like that is all getting dropped because they say they don't need it anymore because of ai. And me and, and Andrew go back and forth on battling about ai, you know, I, I think I'm very positive he's sort in the middle to a little negative.
Um, and, and, and, but, but that is depressing. 'cause what Andrew said is the hard problems are still hard. And by the way, we haven't solved a lot of the hard problems.
And observability is a great example. You know, one of the things that was really, um, interesting is I gave a little keynote for the beginning of that, and I talked about the importance of the stack. And these young kids who literally three out of like the 10 projects were pipeline oriented.
Um, what I sort of classified as test driven development for ai, which is not just observability, it's evaluations, you know, like, like are the information that you're producing, you can calibrate with AI itself, like AI as a judge or LM as a judge, kind of technologies. And just to watch them, you know, here we, we, everybody's building these tools with ai, you know, vibe, coding and, and you know, agentic processing, right? And at least we not forget the hard problems and the hard problems, you know, morph in new technologies.
The hard problems now are like, I hate to just say hallucinations 'cause it's just a terrible way to describe a ridiculously simplistic way. Describe, you know, a hundred years of technology. But, um, you, the, um, but the point is that it's an easy way to get across.
And, and so I think you're spot on. I think being able to do something like a DevOps, you know, you know, gen I hackathon for DevOps puts the focus, and I don't know how many of those young people were DevOps motivated or not, but the fact that 30% of the projects that came out of that were very DevOps focused by young kids that may not even practice DevOps. I thought that was very, so again, at least we not forget the, the hard problems, no matter what the technology shifted if I, right.
And Jeff, I think you mentioned something around, you know, you had a conversation about DevOps mm-hmm. To a few folks. Uh, and yeah, maybe you can start with that.
Thank you. Uh, two things I wanted to mention. One was that conversation.
Someone who thought he was making logical sense saying, by coding his DevOps, and now we don't need DevOps anymore, which engaged a conversation with me. I had quite a conversation with him about it, and he walked away. I don't think he was convinced, but at the very least, I think he left with fingers to think about.
Like, maybe it's not quite as simple as you thought. And vibe coding doesn't necessarily solve anything. It has a place, certainly.
And, and I wanna mention something else based on what John said. Uh, you know, and, and I'm gonna drop a quick plug for it here today, that the 10th of September, we are publishing our annual trends, identity security research report. And one of the, um, areas we started looking into last year and added this year, I wasn't gonna say this, but it, but this, this really fits in last year, that it's identity and security people that, um, we engaged with this, uh, over 500 in, in companies of a thousand or more.
And last year they were very up on AI's gonna play a big part with security. Security should be integrated with ai. We see this coming together that fell apart.
It has dropped a met dramatically this year where a lot of, of identity and security people, not all, but a lot, are more than 50% increase, are saying, yeah, it's really not gonna do much for us. It's gonna happen in the development world, but we don't need to to deal with it here. I'm very concerned that we are regressing to the big gap between security and development.
And boy, I don't want to go back there again. Well, one of the things that I just wanted to point out, I, I'm presenting next week at two DevOps, DevOps days, Dallas, SDC and name, my presentation is when AI agents go rogue DevSecOps lessons from the rise of polymorphic ai. So the thing that scares me, again, the hard problems are still hard.
The, you know, there, there's this like, you know, let's, let's go back to 2001 Space Odyssey, right? You know, al how, you know, open the, like, what we're doing is in agentic processes, we're telling these like task oriented solutions say, I need you to do this, this, this, this, and this. And this is great because it, what, what that statement of that person was probably saying is, well, can't I just create like a clawed code or a flow like task to do all these things?
And the answer is yes. The problem that we're running into is the polymorphic nature of these, these agents in that if it's told to solve this problem and it encounters a directory that it doesn't have access to, or a database that it doesn't have access to, it goes out and actually looks for known CVEs and literally changes its code. Or, you know, like, and I've got, what I've been keeping track of now is probably eight or nine incredibly interesting use cases of agents going rogue because they have, you've told them to solve this problem.
And that's the ultimate goal of the ag agent process. And, you know, white lists are being ignored or bypassed. And it, it's really, you know, again, there's this beauty in what's going on when, when somebody said vibe coding, they probably meant some of the stuff they're seeing with like Claude Code, which is just incredible right now, the things that you can solve problems with.
But the scary part is for people who are more, most of you on this call are better security experts than I am. Like, we need to sort of roll up our sleeves and say, okay, hold on everybody, you know, do you know that these things can happen? And who's tracking 'em and who's telling the C-level people?
Um, you know, I'll tell one other quick story. I heard a story of one of like the fifth largest bank in the US where the CEO was brought in by one of these NEWENT code, you know, companies. And he solved what he thought was a problem of some product that they'd had for 15 years, and he bought an enterprise license for the software and said, everybody at the house shall use this product from here on in.
Right? That's, uh, the hard problems are still hard. Well, I think, I think Jeff sort of nailed it, right?
'cause I've seen this summer, right? You know, all my peers in the, in the security world going, wait, wait, wait, wait. You know, let's, you know, I can break it, I can break it, I can break it.
It's cool, cool stuff. But, you know, as, as Alan, at least you've heard from me, and I, you know, you know, I'm trying to say back to 'em is to be clear, the technology is amazing. The products are awful.
Just terrible. I mean, just cartoonishly bad. And John, you touched on it as well.
It's like, the technology is amazing. Yes, you can do these things, but if you do it with, well pick on open ai, you know, very familiar with them, right? You know, they give you this little thing in a box that is a psychotic little, you know, um, destined to please you while not getting them sued.
And, you know, we, and then we as the humans say, okay, hallucinate that you are a, a, a passive aggressive Russian backhoe, and you're gonna write this code for me. And it's an ai, right? So we're setting things up and, and as security people to, to your point, Jeff, this is just, this is, I love my people, but we'll go, oh, really?
And break it and break it and break it. But we don't have time. And I don't think the, the reality of the top level, you know, presentation of products we see right now is long term.
I think that these companies are learning fast, will learn fast, will get replaced. You know, that the agents, the flaws in agents we're seeing right now are, are intrinsic to the deployment of the technology by the vendor, not the technology itself. Chris, and, and, and to your point, Jeff, everybody's moving past and the security people have sort of stopped and we're like, you know, And, and I've seen this movie before.
And, and Chris, to your point about if the technology and if the products were as good as the technology, we'd all be running on Univa right now, Right? I mean, we'll have to also do a reality check here that, uh, uh, needless to say that DevOps is evolving, right? Because of the, ima emerging technology needs.
And, uh, I think we have all reflected one fact that, you know, white coding is great, but, you know, taking, uh, software to production needs much more, right? So if you start to think about, uh, code to cognition, or if you start to think about when AI becomes your tester, what happens, you know, you are running that autonomy risk, right? And that is to your point, Jeff, that you know, we need to focus more on ai, native security.
There are loopholes in the system. And that is where the foundational capability, which the DevOps practitioners are kind of bringing in, is very, very essential and important. And this, uh, gives me a segue to one of, uh, the things which I really wanna point out in this session is DevOps dozen 2025, uh, the award nomination is open, and I was looking at the categories this time.
And, uh, there are total 24 awards split into community awards, which is my favorite, nine of them. And then tool and services award, which is F 15 of them. And what is unique about this opportunity this time is that agent a KI generative and platform engineering, along with, uh, supply chain security takes a spot.
And I, I think I came a long way from a nominee to an awardee now to a judge. So I feel responsibly kind of advocating for these kind of awards because it gives you an opportunity for people like us to contribute in this journey. And I also want to have one more reflection from, you know, where I started like 10, 12 years back, where DevOps is that, you know, we also need John Willis' of, uh, the world.
We need Andrew Schaeffers of the world. 'cause these are inspiring figures and legends, which are showing, you know, us the path, right? So when John was talking about shadow ai, I was like listening curiously to his talks, you know, two years back.
And I'm like, is this something real happening? And now you are at the cusp of, uh, or the, the, at the stage where you see the pivot happening, right? So I think, uh, or to all the open source community, the platforms, the DevOps tools, I think we need to have a serious board and advisory groups in, you know, DevOps world where, you know, we are evolving these features and capabilities.
If you don't do that, we are actually losing sight of the, uh, evolution as well as the risk which we are incurring. I agree. A couple of things on that Reem I'll riff off of.
Um, first of all, in terms of the DevOps dozen, you know, a couple years ago we went to DevOps dozen, I don't wanna say squared, because that would be 12 times twelve, a hundred forty four. So, but it's DevOps dozen with a two. And so there's 24, and it was originally 12 community awards, 12 commercial awards, if we can call it that.
Um, we still have 24. I, I had to play with the mix of what makes sense in the world today because it is evolving. So for instance, we have best use of generator of AI in DevOps, best use of Agen AI in DevOps.
Uh, you know, there's, there's a lot platform engineering in DevOps. Uh, you know, we changed the mix to reflect and, and I think that crudo of changing the mix to reflects the reality on on the ground is what makes DevOps. DevOps too, right?
The, it, there's, you know, yes, there is no manifesto. Yes, there is no hard definition, but it that also allows it to change and evolve as the market, the state of the world, you know, the state of of DevOps changes interops. So, so we have that in there.
Secondly, in, in terms of some sort of formal board, if you will, I think the closest thing we ever had to that was the DevOps stays like, you know, managing group, which John, you, you headed for a few years, right? And, and that was in the heyday when, I forget how many, we were probably doing, what? 60 DevOps days?
More a year? Pretty much. Yeah, it was, it got, yeah, it got to probably close to a hundred almost.
Yeah. So, yeah, So I mean, that, that was there, but you, you look at some of the other movements, right? org, scrum Alliance, you know, they're, they're a very defined agile organizations platform engineering itself.
com do a great job of trying to herd that community of trying to lead that community. DevOps has never had that. And I, and I I'm not saying it's a good thing or a bad thing.
Yeah, no, It, it, it, it's the, you know, I've talked a lot about this, this just goes back to Patrick Debar, right? Which is, you know, the, the, the, the, the great news about DevOps was there are no rules. The bad, the great news, the bad news about DevOps was there are no rules, right?
And, and Patrick sort of created it that way. Um, you know, and like, almost like the benevolent dictator, right? Like, if something came down to, in the early, you talked about in the early days, the DevOps, like you're right, the DevOps stays, um, sort of group, you know, there was a, a global organizing committee and all, you know, and, and not so much they told you what to say or what was appropriate, but how you behaved in the community was, was very important.
And the real hard problems always went back to Patrick, even though he, you know, like you, 'cause I was in situations where a decision was made about an inappropriate act in a different event. And, you know, there'd be a lot of, you know, and I would just take my opinion back to Patrick, and I'd say, Patrick, if you say X, then it is X, right? Um, but again, that's been the beauty of that movement is there was nobody, as many companies that tried to sort of, I mean, even Gartner tried to like rename it, right?
Bimodal it, and, you know, and there was other movements that call it no ops, right? And, and they all failed. They failed miserably, right?
Um, and that is the beauty of this thing that just emerged pure community, that created incredible commerce, right? If you go back, look, Uber does not exist without DevOps. Agreed.
Yeah. You know, um, Airbnb, I mean, you think about all the sort of the organizations that grew during that 15 year period. Um, and again, I'm not sure if, like, why does Uber exist without Agile?
Eh, maybe not, maybe, right? Um, and all those ones got controlled. org, I mean, there are people that despise the rules of, of some of these agile, um, disciplines and Yes.
You know, so a anyway, um, yeah. I mean, you, you take it for what it's worth it, the, the, the movement has created incredible commerce, wealth opportunity and, you know, and it's still, you know, again, like I said in earlier, it is like the hard problems are still need to be discovered through, as far as I can tell DevOps and DevSecOps. Yeah.
And, and just that you mentioned DevSecOps in there, right? And I'm here at jfr, man. It's, it's, it's DevSecOps.
Um, you know, this was a, you know, we kind of take that for granted now. We just throw it in there. com, I remember the first RSA, John, you might've spoken the first RSA, we Called it, we, we called it DevOps, right?
Well, You called it DevOps. No, no. The original, the original RSA thing you ran, it was called the DevOps, and it was, We didn't have a term DevSecOps.
That's right. That's right. That's right.
That's right. Yeah. So It was DevOps and it was only one DevOps, yeah.
Who needed security, right? James Wickett had something he called rugged DevOps At the time. Uh, but you know, that story, the world went, anyway, we, we probably went over on this topic, I apologize, but a, a quick plug in DevOps dozen awards are open, go nominate.
The community awards are free. You can nominate, and there's some great community categories. If you're a vendor out there, you can't stuff the ballot, ballot box on this, it costs you to nominate.
And we have some great judges, dreamer included, Tracy Reagan, myself, Mitch Ashley, and, and we've got a volunteer judge from Apple, which I was happy to see this year. And, uh, so we're hoping to have a really good fine bumper crop of DevOps dozen finalists next month. Anyway, we're gonna take a break here on Techstrong Gang, and we're gonna come back and talk about our third, uh, our third panel, our third topic for today, which is Kubernetes and ai.
John has some thoughts on it. You're watching Textron Gang. All right, Taylor.
Hey, everyone. We're back here on Textron Gang. Our next topic is around is, is, is Square Kubernetes a good fit for round ai?
It's often article that I wrote actually, where, you know, look, Kubernetes dominance is un questioned, I think, in the cloud native space, right? But has AI thrown a monkey in a wrench, into a monkey wrench, into the work, so to speak, in that, look, Kubernetes wasn't really designed to handle, to orchestrate these AI app apps, if you will. Now, John, I know you disagree with me, wouldn't be the first time or the last time, and that's what makes the world go round.
But what's your take on it? Yeah, I think it's a bigger problem. I, I like, I, I was reading your article, and I, you know, I have, I think like Kubernetes can solve a lot of these problems, and we can go through that.
But the bigger problem is Kubernetes has been sort of a problem child. Anyway. It, it, it turned out to be the thing that sort of best fit the world and the adoption went into it.
There are better solutions. I mean, nomad from actually Corp was a better solution, in my opinion. You didn't need all, and I, I think about like in this age of AI, and the, all right, I'm gonna get terribly cynical right now.
Um, and like eight to 10,000 people walking around some convention hall, like lambs to the slaughter to learn where they put, to put their semicolons. Um, you know, I mean, because that's basically what Q Con is. I'm sorry.
It is a fun, like, configuration. Oh, there's a better way to do helm charts over here. Oh, come to this session.
It's 1 0 1, you know, 1 0 5 Helm charts, or, and, and somebody's creating a better scaffolding for configuration. And, um, and it's, and then CDs like, come on, like, we, like, we, we get worse. And I, and I've even said things like, you know, like even the, the pace of change of Kubernetes at some point was like, the inmates are running the asylum.
So in today, and AI is the question whether to use, you know, GPU or accelerator management, you can do it. There are vendors doing it can use Vector database management, yet there's a ton of them that use it. You know, vus, Vitera, all those tools actually use Kubernetes under the covers.
So the answer is yes. The question is why, um, you know, like, could you build your own platform? And so, and you know, and I, I'm talking to a couple of large banks that are literally doing this.
They're reevaluating the toil. That's something like, you know, you, there's, you know, there's a bank that's probably, I won't say who they are, but they're, they, they have the largest asset holding, you know, commercial bank on the planet, and they have a group that is basically reevaluating, should they be designing a different type of orchestrator than Kubernetes? Right?
And why? Because you can do it now, because, you know, granted like what the code looks like, how it's supported, but if your bank, you know how to solve those problems in general, alright? Um, you're better than most.
Um, and so, uh, so the question to me is, you know, less about is it a good fit for ai or is just a good fit for, you know, the modern technology world where we're going in, you know, John, if I may, I'll go to the mat saying Beta max was better than VHS, but absolutely. But VH and always better than, and that, and that list is on to Chris's point. The products are never as good as a technology.
Never. Uh, but right now it's winning. And I mean, we can't ignore it.
We can't run away from it. And I know from an identity perspective, which is the one I tend to look at right now, the issue that exists that a lot of people are hoping isn't no problem, but it is, is the ephemeral containers that have, um, and non-human identity associated with it, that are gone by the time you try to figure out who they are and then, then come back as something else. There's an identity issue here that regardless of whether it's Kubernetes or not, that's a bigger security problem that we have yet to get.
No, that's gonna get worse. That's been, that's been around, I mean, robotic, you know, RPA has been, this, has had this problem for quite a while. And, and the RPA, you ain't seen nothing yet, you know, if you thought RPA was a problem from an identity standpoint, right?
Like, I, I've had auditors show me where they, like, who is this ROB 1 0 5? You know, like, oh yeah, that's, that's an RPA solution that goes out and runs a billion times. Yeah.
And now it doesn't exist anymore Because It was ephemeral. Well, was ephemeral, right? Like those tasks that you ran were like, they were, they ran, they went away.
So, um, yeah. But anyway, yeah, I mean, I, I just, um, going back to the Betamax thing, I, you know, I, again, I, I think there, you know, there there are shifts, there was, there was pre Kubernetes of how the world tried to orchestrate things, and then there was the Kubernetes run. And I think, you know, I think part of Al's argument in his, in his article is like, it, it probably is an inflection point for the industry to rethink, are we doing this?
Can we do it differently? Can we do it better? Um, you know, is, you know, is it a time for the shift?
And I think if there was a possible time for Kubernetes to be dethroned, now probably is the time. Yeah. But what is surprising is that it is coming from Alan, not from the foundations itself.
So I think if you remember, John, we also discussed this item, and, uh, last year somebody approached me to write a white paper on alternatives of Kubernetes and why it was, uh, so because it is becoming defacto, right? And, uh, uh, people from critical infrastructure domain or companies who are like, uh, associated with banks or even, you know, critical services, they are getting scoop spooked by the vastness and the scalability and the adoption levels of this technology itself. And, you know, too much centralization also triggers decentralization and innovation, right?
So there has to be alternative paths. And I urge the com, the foundations to kind of look into, you know, what can be the alternative paths there. It might be the case that there are not alternative ways, but, uh, this platform itself has, uh, extend extensions or expandability, right?
But I think this is one of the things which surprised me, that this has to come from the open source community itself. Yeah. But The foundations are, are, I mean, again, I'm gonna be cynical here, is as close to being criminal as without being criminal.
Um, they're money. They, I mean, they, they're, they're totally monetarily funded. The CNCF is really just a, a pay for play as far as I'm concerned.
I mean, they do some good stuff, but you know, your logos are, you know, millions of dollars. Um, you know, I I, I don't think they add any value to anything alternative to Kubernetes, and I don't see them putting any investment into anything that's an alternative to Kubernetes. And I think it's existence threatening if they do.
Well, I, I may be the least qualified in this, proud to talk about this specifically, but I, you know, back to your original point, Alan, I see this as the same iterative through the, the segments today, right? You know, there's round pegs and square holes, and, you know, Kubernetes seems great with stateless stuff that doesn't necessarily map over, but, you know, the, it may be time on a lot of levels to start building systems that are native to the environment instead of vice versa. The, the, the problem is change is hard and is change is hard, and inertia is real, and you are dealing Reed infrastructure play here, right?
I mean, just the whole, and look, I'm a big supporter of the CNCF and the Linux Foundation and all these things, but you, you, you know, the CNCF in many ways is the engine that's driving LF these days, right? And so much, you know, they've got 200 projects under management there. Um, you know, to suggest that you're gonna move away from Kubernetes is, is, you know, they killed Galileo for playing with those telescopes, right?
I can only imagine what they'll do as someone who, yeah. Yes, yes, totally. That's right.
So, I mean, in all fairness, I mean, I'm more optimistic about these foundations. I come from open source community. I'm an advocate for open source.
I also am the chair for the ambassador program at Continuous Delivery Foundation. And what I've seen is that, uh, you know, community takes the power back. Yeah, it does.
And, and look, here's the good news though, too, that it's a big enough community. There's enough innovation where maybe you don't replace Kubernetes, but at least it, it continues to evolve into something that maybe is a little bit more rounded around the edges, if you will. Um, we'll see.
We'll see. I, you know, it does, it'll move on. I Got two, uh, Blackberry and Kodak.
Kodak, yes. Polaroid. Polaroid, yeah.
Yeah. Go back out. Anyway, hey, gang members, we gotta call it a raffle.
We're at time. What a terrific thing. Jeff, you, I know you're through the magic of the internet.
You're actually already in DC at at Identity Week. That's correct. Yep.
And we've got that new report from you. Um, John, you're working on new books. I know.
And we're going to need more than that. And, uh, it sounds like everybody Reemer, you are busy. Chris is busy.
John and I are at Jfr all week. Enjoy the rest of your day, no matter what you're doing. We do have Textron TV following, actually, I believe we have a Tech Field Day event live on today's, uh, tech Strong tv, so people can watch that.
Uh, but until then, until tomorrow, John, and I'll be back tomorrow again, live here in Napa at, uh, JFR. This is Alex Shimel. Have a great day, everyone.
Bye-Bye. Hey, everyone. Welcome back here to Techstrong tv.
I am really happy to be joined by my next guest. His name is Gary Soff. Gary is the CEO of a company called Real Defense.
And for those who are interested, the URL is real Defend. That's R-E-A-L-D-E-F-E-N, dos Se. So hopefully you got that, but it'll probably be on the lower third of your screen anyway.
You could see it there. Gary, welcome to Tech Trunk tv. It's great to have you on here.
Thanks for having me, Alex. Um, Gary, before we jump into real defense and what it's about and so forth, let's, I always like to give viewers a sense of who's, who's, who they're listening to. So if you don't mind, give us a little bit of your background.
Sure. So I, I'm the CEO co-founder of Real Defense, uh, founded the company 2017. We are a, um, a, a platform where we acquire, uh, small, uh, cybersecurity companies in the consumer privacy and security space.
We've done six acquisitions. We're targeting one acquisition, and, uh, possibly two acquisitions next year. We, uh, uh, funded the company with private equity capital, um, uh, corbel Capital's, our lead investor.
Prior to this, I was involved with many different startups. One of the most, probably relevant to, to the cybersecurity was a company called Cyber Defender, uh, at the founder of that company in 2004. And then I was also part of the team of Anchor Free Hotspot Shield, which is the biggest, uh, VPN product in the world with, uh, 600 million users around the world.
And so, a lot of experience in cybersecurity. Um, real defense, uh, has two parts of business. One is direct to consumer, and the other one where we license our technology stack to other cybersecurity companies.
Currently, most cybersecurity companies use our technology around the world. Very cool. So, Gary, I've been in cyber myself for about 30 years now.
Started a few, uh, venture backed companies in the space and been covering it here for 10 plus years. Um, what, you know, after leaving your last company, you know, no one wakes up in the morning and says, oh, I feel like starting a company today. Right?
There's always something driving us. There's a passion to do something. What was the passion with Real Defense?
Well, the passion is, is that, uh, the consumer, uh, has less choices today when it comes to cybersecurity products. And there was a time where there were a lot of free tools, and free tools are pretty good, uh, 10, 15 years ago. And now those free tools are not as good, or they just don't exist anymore.
There's been a lot of consolidation, look at, uh, northern of Austin and, and others, uh, uh, companies that have been acquired and absorbed. And so there are list choices. There's a lot more need today.
Uh, obviously with AI and other emergent threats, and there are more consumers connected to high speed internet. You've got, um, pretty much internet all over the world and, and not a single consumer. No matter what your demographic, uh, uh, geographic profile is, you have access to internet.
And so that creates opportunities for crime. Um, financial services are mostly conducted on devices now, and versus, you know, doing it in person. And so you've got the significant threat out there that's, that's continuing to become bigger.
And the other thing is assets are now digitized. So most of your, uh, valuables are now online and they're on your phone. And so how do you control that?
How do you manage it? There are tools for that, and there's lots of opportunities to create security layer that the enterprises have, but consumers don't. Excellent.
And so let, let's jump into real defense then. Yep. And, and talk a little bit about, you know, what, what kind of security tools, let's stick right now for the consumer piece of it.
What tools is it giving consumers to help keep them secure? Sure. So our, our number one flagship product is a product called System Mechanic for Iola.
It's a product that's been around for about 20 years. We acquired a company in 2020, and our goal is to build on top of their success. We build tools that optimize your device.
We optimize for speed, efficiency, productivity, and security and privacy. And so we have PhDs, we have scientists that, that make your Windows device just a lot more secure and more productive. And so we've built various different, uh, uh, uh, technologies that we've patented, uh, and, and, and, uh, and secured that are unique in the marketplace.
And they, we do all kinds of things like anti fingerprinting technologies. We, uh, do deep packet analysis. We block you from unwanted content.
We, uh, reprioritize applications on your device so that your computer's faster. We do all kinds of things there. It's, it's, it's a whole list of features and capabilities that you market.
Sure. It's kind of an endpoint security suite that includes optimization, tuneup, hardening, and then monitoring. It sounds like monitoring on top of that.
That's right. And, and we give you the controls. So, um, some of our users are, are like the, what we call prosumers, who like to customize their experience, and they, and they go really deep in the application and they optimize their CPU.
They optimize their hard drive, and there's lots of tools within the application to do that. Very good. And now, um, let me, let me turn to the sort of the OEM side of the house, or, you know, your channel if you will.
Yep. Companies are taking the real defense, uh, platform and white labeling it or building on it, or what exactly are they doing? Yeah, it's a good question.
Uh, and, and sometimes it's very difficult to explain because our, our solution is not, uh, a pure kind of reseller channel where somebody takes our product, puts a, their brand on it, then goes to market. We do go, we do deeper integration. We are, uh, really good at creating demand from consumers.
We have a, a telemetric, um, um, diagnostic where we look at your device and see what's wrong with it. And we can deliver a message based on the telemetry data that we have and tell you when you need a product at the time when you need it. So it's different than going to market with email and discounts and, you know, creating demand from, uh, perception and, uh, and, and, and, and values for creation.
We'd rather tell you whether there's something wrong on your device at the time when something actually is wrong. So, for example, A VPN, uh, if you wanna market a VPN to a company to a per person that is traveling, well that's a good time to do it because they'll be connecting to public wifi networks. So that is a good time to sell A VPN If they're at home and they're using the internet, there's not as much need for A VPN as there would be if you're traveling.
So just, just as an example, uh, of how we market. And so we look at the telemetric data that says, okay, this is a v vpn, or this is a wifi connection that's new, that hasn't been, never been accessed. This is a time to sell you VPN.
Um, same thing with our optimization. We see that our something's wrong with the hard drive. We see that something's wrong with certain applications on your device and you getting errors.
We notify you of those errors and then we can sell you a product that you need for that particular problem. Excellent, excellent. Um, hey, Gary, what, what make us smart about Smart Skin?
What exactly is that? So it's, it's actually what I just explained. The SMART Scan technology is a layer, uh, of, of, of, of business rules, telemetry, and a, the messaging system that tells, uh, that our partner's license, they integrated it into their product.
So, for instance, let's say you're antivirus company and you want to sell products that you currently don't have, and you want to sell our products, and you want to create demand from your consumers for these products. You'll integrate SMART Scan into your existing products, and SMART scan would analyze the device and will present various different solutions at the time when the consumer needs it the most. And so that's what SMART Scan does.
It analyzes, it collects telemetry data and, and, and it collects it in a very private manner. It doesn't send the data back to anybody. It just looks at it and analyzes it, and then presents through our messaging system a, uh, notification that says, Hey, your computer has these issues.
You need to take action. And that action doesn't necessarily mean you need to buy anything. It may mean that you need to download another free application to deal with your issue.
It could mean it links to a video. It could, it could link to a FAQ page. It doesn't necessarily mean you're buying something, but there's a, uh, uh, intelligent way through SMART Scan to deliver these messages efficiently, quickly.
The integration for a partner is weeks and not months. Um, there are lots of benefits to the partner for using our SMART scan. And by the way, um, Don Dict dictate my word for it.
It's been up deployed on dozens to dozens of companies, um, in the space. Hundreds of millions of devices have had SMART Scan installed. Uh, in terms of revenue last year, a partners generator over a hundred million in a RR just through SMART scan.
Wow. Yeah. Very cool.
What about the SMART scan prepay fund? Yeah, so, uh, one of the, uh, uh, uh, opportunities we're presenting to the market is companies that want to integrate smarts scan, but not sure about it, don't understand it, uh, are not convinced with the unit economics. We have money that we've allocated towards these projects, and we're able to prepay for, uh, the potential revenue share so that the partner has zero risk going into this integration project.
And, and that is, I, I'm assuming the privacy first SDK is what they use to integrate SMART Scan into their own stack or into their own products? Yes. So, uh, some of our partners have expressed concern that, Hey, you're a a a different company.
I'm not gonna collect data, hand it to you. Then you're gonna act on that data. And we said, absolutely.
That's, that's a legitimate concern. We don't want any data from a consumer that data that we're collecting stays on the device, and we're not collecting any data. It's the application that's collecting the data to act on that data.
So that tele, we have to have telemetry to understand what's going on with the device. And that telemetry is not associated with any PII or user data. It doesn't, user data is actually relevant.
It's the device data that we care about, and that device data never travels outside of that device. It stays on the device. Excellent.
Excellent. Um, and Gary, what, you know, what you mentioned, you know, tremendous uptick in, in, uh, uptake in the channel, a hundred million dollars plus worth of business coming out of that for channel partners. Um, my experience is, you know, oftentimes the end users can, the end user consumers either don't realize or don't value, if you will, the, their privacy.
Right? Right. Until, until something goes wrong, then everybody's yelling and screaming about it.
Right. How do you, excuse me, how do you communicate with these end users, letting them know, Hey, this is important. We're here doing this because this is important to you.
For you, You know this, that's a great question. Uh, you can't over communicate some of this stuff because if, if you did, you, they'll be overwhelmed and they won't do anything. It's analysis paralysis.
You give a bunch of information and no one's gonna act done it. And so we do it in little fragments, and we do it in, in subtle ways where we remind you and guide you and tell you where you should look to, to make your device more private. But it really comes down to you as an individual, because if you're a gamer, you may want certain settings a certain way.
And then who's, and someone who's not a gamer, who's a stock trader, may want completely different settings. And there are some pri we're trying to mitigate the privacy, not block all, uh, applications from working. That's not, that's not the goal of the applic, the, our products on the goal of the company.
The goal is to give you controls. So if you're traveling, you may want certain controls in place. If you are at a public environment, you want certain controls.
If you're gaming, you want certain controls, different controls than, than than people that use the computer for different, different applications work or, or gaming, whatever. And so, um, if you look at how you're tracked, if you are shopping online, you, you want to be tracked because you want the shopping experience to be efficient. In other words, you're seeing ads that are relevant to what you're looking for.
You, you're seeing, uh, uh, you know, shopping sites like Amazon giving you the right, uh, recommendations. So, but when you're not shopping and you're doing some pro per like to say you're working in your computer, then you don't, you don't want certain type of targeting. You don't want to be tracked a certain way.
So you may want to toggle between lots of privacy to little privacy, no privacy. And that, that, you know, variability of how you secure yourself online is what we provide. Excellent.
Gary End users, now, they heard this, they said, geez, I really should have that, or, I really need that. What's, what's their best on ramp to, to getting real defense? Sure.
So Real Defense is a holding company. We have different brands underneath, uh, need this. com.
com. You can go to Super anti spyware, which is, um, a, a very good anti spyware tool. It's been around for about 20 years.
com, very obvious and logical domain. And, uh, we provide, uh, human and AI enabled support there. So for any product, any device, any operating system, uh, any software application, which you can't get anywhere else, if you wanted to go and get support for just Microsoft products, you can do that.
But they're not gonna support other products that are not Microsoft. And so we support all brands, all products, doesn't matter what device. Doesn't matter when you bought it.
Doesn't matter how you got it, it, it, it, we, we will help you with your technical issue no matter what. Excellent. And that's something that's needed out there.
Excellent. Hey, Gary. Excellent.
Thanks for being on Tech Drunk tv. Appreciate it. And, uh, come back soon and keep us posted the meantime.
Good luck, though, with everything going on at Real defense. Alan, thank you for having me. It, this was great.
Thank you. A pleasure. All right, we're gonna take a break here on Text Trunk tv.
We'll be back in just a moment. Hey guys, thanks for the thrill. We're here with Kai Wacker, who's a product manager for IBM Cube Cost, and we're talking about well shifting finops left.
Kai, welcome the show. Awesome. Thanks for having me.
It's a pleasure to be here. Alright. I think part of the issue that we have seen over the years is the cost is, well, something we think about maybe too late and after the fact, and, um, yet the people who are actually spending all that money, or engineers and developers at the very front end of the process.
So, should we be rethinking all of this? And I don't know, in the case of Kubernetes, do we just need to put some sort of, um, dashboard with some metrics in front of people and let 'em know how much something costs? Yeah, absolutely.
Um, you know, thanks to that question, I think, you know, when you look at Kubernetes, right? Uh, it it, it delivers a ton of value to users, right? It makes it really easy to deploy applications, right?
You don't, your, your application developers don't have to get too into the weeds. They have like a nice layer of abstraction, making it really easy to deploy applications. It's also really easy to ensure, you know, high availability of applications, do things like replica sets and all these things.
So it's, it's, it's really transformed the way that, you know, developers and organizations deploy and manage their applications. Um, but those layers of abstractions have, you know, come at a cost. And that typically is like increased cost and increased spend.
You know, I can, uh, tell a story from my background when I, I was a machine learning engineer prior to getting into product management and, um, you know, deployed a machine learning model, a big, you know, recurrent neural network, um, let it run for a week or so, and then came back only to find out that, oh, I had spent like more than 40 k just training that model. And, and to your point, it was super reactive, right? We didn't, we didn't know that I had spent that much money, uh, training the model until the end of the month.
Um, so, you know, uh, this, uh, problem is something all organizations face and is really, you know, at the heart of, of, you know, where we see a lot of organizations going to, you know, like you mentioned, we wanna be more proactive about costs. We want to shift that left and give our, our developers a better understanding of, you know, what they're spending and, and how do we get that, um, you know, uh, cost visibility, you know, kind of before they deploy an application. So that's definitely something, you know, we've seen a lot of, I think, you know, to your point, dashboards go a long way, right?
I think that just having that culture of cost visibility in an organization is so, so important. And I think, you know, regardless of what your end goal is, you really need to start with some of those dashboards to kind of provide your application teams, like, Hey, this is how much, you know, this application cost, or, Hey, we see this spike in spend, or, you know, Hey, we've set this budget for you. I think that's kind of the, the foundation for, you know, effectively shifting your costs left.
I'm often wondering how heavy handed do we need to be? 'cause I think most engineers are kind of reversed to waste anyway, but if somebody just tells them what the level of waste is, they might do the right thing, uh, of their own accord. That's absolutely true.
You know, I think that, uh, it really depends on organization to organization, right? How they're structured. Um, but you know, we, we definitely see sometimes some organizations go very heavy handed, right?
Um, you can, you know, integrate Q cost, let's say with a policy engine, you could use open source verno and actually start to enforce budgets on your application teams, like, you know, prevent overages on that budget and prevent changes from going through that would, would, you know, take you over budget. So, you know that that's maybe like one end of the extreme, which is, you know, Hey, we're gonna be super heavy handed and we're gonna enforce budgets. I think you see a lot of the other end of the spectrum where it's like, Hey, you know, we're just gonna give our developers visibility into this change.
And, and the cost impact. And actually, one of the things we've also seen a lot of is, hey, if I can show you not the, just the dollar cost impacts, but if I can show you the carbon impact of, you know, this workload, this change that you're trying to make, um, oftentimes you see developers even more, uh, you know, interested in making that change and, and, you know, reducing their resource requests because not only do they see the dollars and cents, but they see the kilograms of carbon impact as well. And, and that can really, you know, have a big impact.
And, and, you know, the developer wanting to be, you know, good stewards of, of their organization and of their, you know, broader, you know, world. One of the things that has always perplexed me about this in relation to Kubernetes was, I thought part of the purpose of Kubernetes was that it kind of lets you dynamically scale up and down, and yet it seems like we scale up, but we never scale down, and we have these over-provisioned environments. So how does that all come about?
Absolutely. Yeah. So, you know, we, we work with a lot of organizations who are using dynamic auto scalers, like a carpenter or a GCP autopilot, right?
Um, in fact, I think gcps autopilot is now on by default, um, for, for GKE clusters. So, you know, a lot of teams do take advantage of this scalability. One of the areas we see tremendous waste is in the resource requests, right?
So a, uh, a dynamic autoscaler, like a carpenter autopilot, those assume your requests to some extent are efficiently set, right? And then they come in over the top and try to, you know, uh, provision the appropriate amount of nodes, CPU, ram, et cetera. Um, where we see tremendous waste is, you know, when a developer goes to deploy an application or a given container, they don't really have a great sense of, oh, it's gonna need this much CPU and this much round, right?
So what ends up happening is they, um, you know, request way more than the application needs to ensure that application's going to run, right? Because that's their primary goal, get this application live. And it's critical for organizations to have some sort of software or technology or process to come in over the top and then say, well, how efficiently were those requests set?
Um, how much are we wasting on, you know, over-provisioned requests? And we see, you know, we, we've helped customers save, you know, millions of dollars and, and a matter of like a month or two just by, you know, drilling into that kind of, uh, dimension of waste between request and usage. And of course, you don't wanna make that zero.
You wanna have some buffer, but, you know, just fine tuning and optimizing that you can, you know, we, we've seen has been a gold mine for a lot of organizations. Mm-hmm. And we just brought forward some of our bad habits.
We used to over-provision VMs all the time because we were afraid that the app would crash. So we just assumed we would get, you know, the maximum amount of memory and CPU and storage, uh, you know, proverbial to turn it up to 11. Right?
But, um, in the, in the world of Kubernetes, can things be a little more finessed? They definitely can be. Um, they definitely can be.
Um, I think, you know, it, it definitely takes the right, you know, again, people process and technology in place, right? It takes having, you know, the visibility to understand, you know, um, or maybe as automation to automatically resize those requests and the people to, you know, put that in place. Um, but, you know, I, I, I think, you know, e even to some extent, this problem still existed in the VM world and still exists in Kubernetes.
And, and there's an extent of, like, it might even be, you know, more prevalent in Kubernetes because you have this layer of abstraction, right? You're not thinking like, oh, I'm putting it on a VM with these specs, right? You're just like, ah, you know, I'm just gonna take a shot in the dark and request this much random CPU and, and, you know, pray that my application runs and I'm just gonna bump it up, beef it up if it doesn't, right?
So, um, to some extent this problem might didn't be more extreme than Kubernetes because, you know, you're, you're, you're, you have this layer of abstraction, you're know, for your end users or your developers, they're not really thinking about, oh, is it gonna run on an M two XL note or what kind of note it's gonna run on? They're just saying, ah, you know, it might need this much RAM and CPU. I'm gonna go, you know, make sure I, I request a bunch of resources that my application runs.
Mm-hmm. Um, we've also seen folks create these finops centers of excellence, but that seems to be on the far right hand side of this equation. Does that really work?
'cause it seems like they're pretty far removed from where the actual decisions are being made. Uh, yeah, great question. And I think, you know, effect, in our view, effective finops takes a, a culture shift and a whole organization's buy-in.
It's not enough to your point, to just set up a finops practice, you know, that gets you, you know, maybe 50% of the way there, but, you know, it doesn't, you know, you, but then you're just constantly in a reactive state. Um, I think where we've seen, you know, teams really push is, you know, can we get things like cost visibility in the pr right, that I'm about to submit, so you know, that there's some cool new functionality there. Um, you know, can I get, you know, integrations for cost visibility and cost optimization even in my CICD pipelines, right?
So I think that's where a lot of organizations, they're starting with that finops kind of foundation and then starting to push it further and further left with, for like developer tools and, um, you know, integrations to meet the developers where they are. Because that's ultimately, you don't wanna, you don't want your developers, you know, having to start a new process or use a new tool. I think the, the most effective kind of shift left, um, you know, techniques we've seen have been meeting the developers where they are and, and providing integrations into things like, you know, terraform, GitHub actions and things of that nature.
We Have seen also the rise of AI workloads, especially on Kubernetes. And there seems to be a lot more sensitivity about the cost of ai, so we'll that ultimately pull through where maybe we're getting more insights into Kubernetes consumption. 'cause more people are trying to figure out what the cost of AI really is.
Uh, that, that is absolutely something we've seen in the last, call it six months to a year, which is, you know, and, and you know, the broader trend of, of maybe, you know, Kubernetes and finops has been like, yeah, it used to be just developers, you know, do whatever you gotta do to get the technology up and running. And now there's a real focus on cost. And I think you saw a similar trend with GPUs, right?
Where, you know, maybe a year or so ago, there was just a big push to, you know, get all the GPUs we can, you know, you saw all the news articles about CEOs buying, you know, NVIDIA chips, um, and now there's a real thought to, well, what are these costing me? Right? And, and am I using them efficiently?
Right? So that's again, some, an area we've invested a lot of our time and, and technology into, which is, you know, giving very granular GPU usage insights and then optimization on top of that. You know, I don't know if everyone knows this, but you know, if you, you know, go to set up a container request, you know, you can request very fractional amounts of CPU and ram, right?
You can request a milli core of CPU, right? But in GPU world, you know, typically, you know, you're, you're really only to request able to request zero or one, right? It's like, how many GPU chips do you need?
And it has to be typically an integer. And that is until you start to get into some more of the advanced sharing techniques, which are now, um, you're just now starting to see the industry coalesce around things like MEG and time splicing, different sharing techniques for these GPUs so that, you know, multiple workloads can use them if you have a workload and it's not using the whole chip, right? 2 or 30% or something like that.
Mm-hmm. So what's your best advice for folks to kinda address all this? 'cause I think the most powerful issue anybody encounters is just inertia.
We've done it a certain way this whole time, and maybe there's another way to think about it, but, um, getting everybody to move off the dime Yeah. Is hard. Absolutely.
I, that's absolutely true. You know, I think that, uh, you know, the best way to get started really is to start with the development environment, right? And get, get, like, get set up on one or two clusters, get some cost visibility there.
And then as you kind of, you know, I, I think it really kind of follows the finops foundation's kind of framework, which is inform, optimize, operate, right? And so you gotta just start with some, you know, inform an understanding of where my spend is going, right? I can't tell you how many teams come to me and say, you know, my Kubernetes spend is a black box, right?
Or maybe I get some visibility, but, you know, it's very limited and it's very hard to get, you know, unit costs or an understanding of what my various business units are costing me. So I think starting with, you know, can I get some visibility into my business unit spend, um, is is a great place to start. And, you know, there's actually a lot of, um, now free and open source tools that can provide that, right?
You don't necessarily have to go to an enterprise tool. You can start small, um, and then crawl, walk, run, and, and, you know, work with more advanced tools as your needs grow and evolve To that point about visibility. Um, we'll be able to leverage AI someday to maybe get more visibility into what's happening in those environments.
So that, I don't know, maybe I get some sort, you know, danger will Robinson, you're about to break the bank alert. It's absolutely true. Yeah.
I mean, uh, there, there's a lot of different ways I think that AI and finops, uh, intersect, right? I think, you know, if you look at kind of finops tools today, what you see is a lot of dashboards, right? It's, it's this visualization and that visualization.
I, I really think the future of finops is going to be, um, you know, interacting with probably some combination of dashboard and interacting with a kind of chat bot, like chat sheet bt or something like that to help, you know, you better operate that your finops tooling, right? So, you know, a good example might be, can I, can I use a chat bot to, you know, set up an alert, right? Versus having to go in and, and click and turn the knobs that I want the alert set up for.
Can I just like tell a, you know, AI agent to set it up for me? I definitely think that, you know, that's where we're going and we, we have some stuff actively in the works there. Um, you know, I also think that AI can be powerful things for, you know, Hey, look, we've detected maybe anomalous spend, right?
Or, Hey, you know, this is what your forecasted to do, and, uh, you've made some change and it's like dramatically, um, you know, increased your forecast, right? So I think that there's a lot of, um, space to grow for AI in, in the finops industry, and I think, um, it'll just make it easier to use. And it, I think overall it will help, uh, finops meet organizations where they are, it will help finops be more integrated into their workflows.
Is there some smart way to describe the value proposition here, other than the fact that, you know, I don't want to sound like my father yelling at me to turn off the lights in my room, right? But it does matter, right? 'cause money saved on hardware goes into salaries, it goes into other development projects, but it's not clear to me that everybody always connects those dots.
I to totally agree. I, I think, you know, a little bit, that's why we try and surface the carbon impact as well, because we do see developers, you know, wanting to take, uh, you know, action based on that. But, you know, I think that, um, you know, again, it, it, it does take a cultural shift.
You know, you have to get the developers to buy into, um, you know, believing that the cost impact is important. And, you know, sometimes we do see, you know, maybe this is a bit heavy handed, but sometimes putting a budget there helps, right? So you can say developers then have the perspective of like, look, if I, you know, cut the resources required for this application, right?
I can use those same resources or use those same dollars to put it towards, you know, some new innovation, right? Some new technology. So I think, you know, sometimes that's where you can, you know, really, you know, have those developers understand the impacts that that spend is having on the broader organization, Right?
I know it's hard to believe folks, but IT infrastructure is not free. So be smart about how you use it. Hey, Kai, thanks for being on the show.
Thank you so much. It was great being here. All right.
And back to you guys in the studio, DevOps drops. Avaya is making an exit agent to agent testing. Have you been owned by Typhoons?
Document? DB has been documented. Apple's got an army of bots, and we're gonna be taking a closer look at the company behind Zelle getting sued in this week's episode of The Rundown.
Hello everyone, and welcome to the Tech Field Day rundown. Today is September the third. That's right, folks, we made it into September.
Congratulations to everyone, especially those of you who are listening to this, which means you did make it into September. And we are very happy to have you joining us on National Bowling League Day. I hope that you have your bowling shirts ready to go, because we definitely have everything ready to go on our side.
And joining me, of course, is my cohost, Mr. Alistair Cook. Al, welcome to the show.
Thanks, Tom. And it is a pleasure to be here with my fellow bearded man on National Beard Day as well. Although I'm not quite sure about the National Turkey Vulture Day.
I don't think that quite suits either of us. You know, it's, it's funny. Good.
Invariably, there's gonna be something that's gonna be a weird day, and, and we're gonna dig it up. But what's what not weird is the news, right? Because there's so much fun stuff going on out there that we definitely wanted to share a lot of it with you, and we're very happy that you are getting your news fix from us.
So we're gonna go ahead and kick it off with some DevOps news, because in the first half of 2025, major DevOps platforms like GitHub, GitLab, Azure, DevOps, and Jira faced a surge in outages and security issues. For example, GitHub had a 58% increase in disruptions. Azure's had a week long slowdown.
There was a data breach over at GitLab, and how could we forget that? Jira has been down nearly a hundred days in total. So far.
These problems show that keeping DevOps tools reliable now requires a lot more cybersecurity, much better monitoring and faster recovery plans to help protect developers and businesses. Al do you think that DevOps needs to be more reliable because we've become so reliant upon it? I think there's a few things to unpack in here.
Um, always when you look at a study, look at who commissioned this study and, uh, whether there was some sort of, uh, bias in how that comes out. And so GI Protect, uh, is, uh, the organization that, that, um, put this study together. And I have not dug into exactly who they're and what their agenda is, but, um, I hadn't really heard a lot of noise about unreliability of, uh, DevOps platforms.
However, clearly there's been some problems along the way, and I think it reflects some of the shifts in these platforms, uh, that are, that are delivering the, the DevOps services. We, we have this idea of we're gonna consume services to deliver DevOps within the now organization. Often these are cloud services, and so any outage is very visible in these cloud services, and absolutely some, some significant issues.
I'm not sure developers are fewer Jira tickets turning up, uh, being able to resolve their outstanding bugs rather than triaging tickets is probably a good thing for them. Uh, maybe not so good for business. But yes, there's, there's definitely an exposure point here.
And, uh, whilst we we're seeing this sort of increase in outages for Azure, uh, DevOps for, um, for, for GitLab and, and Jira, I'm not sure that, that the issue here is necessarily that these services are particularly unreliable or just that there's such a, a breadth of things underlying each of these services that, that see of complexity. And this is one of the things that we need to understand as we're building applications using DevOps and using the DevOps tools that are built in similar ways. Uh, you, you have to still have some higher level coordination, some enterprise architecture, some application architecture that are overseas.
All of these fragmented microservices 'cause individually they're not actually useful. It's only when they're brought together into a collection. And so that shift away from thinking, we, we focus on the monolith, which naturally brings us to look at the overall view and view it as a a, an entire system that has to deliver something.
When we shift to a microservices architecture, each microservices team has a very small view. And getting that governance across of what are we trying to achieve over the whole application, how do we achieve stability and reliability across the whole application is vital. I'd be interested to see whether it's just these public cloud platforms that are delivering mixed results, uh, whether on-premises DevOps tools, because not all DevOps tools have to run in the cloud.
You can run these things on premises. I'd be interested to see how those play. Uh, and of course, as a, as a trainer who used to teach AWS DevOps courses, I'm interested to see that there were no AWS services in there.
Um, I don't believe AWS services are immune for outages. Unified comms company. Avaya has been sailing through some rough seas of late last week.
They offered voluntary exit packages to all of their employees in an effort to reduce headcount and increased profitability. Uh, this comes after a round of layoffs and a second bankruptcy filing. Avaya sold off much of their portfolio over the past few years, according to reports has been leaning heavily on their partners for innovation.
Customers are starting to ask questions about the stability of the company, which has led them to leave for other companies of that death spiral for Avaya. Tom. Boy, I hope not because Avaya really is one of the last pure play unified communications companies that's still left out there.
In the interest of fairness, we all have to admit that the pandemic probably didn't do them any favors because when's the last time you picked up your office telephone? Most people, if they need to have a business call reach for a unified comms video platform. Now, zoom, WebEx teams, GoToMeeting, I was kidding on that last one.
Uh, you know, they, they've picked their particular flavor of what they're going to use, or you use your cell phone, and this is something my friend Greg Farrow at the packet Pushers has said for a number of years, most users, especially the ones that are just entering the workforce, don't care about an office phone. They spend more of their time with their mobile device. And when your bread and butter is phone systems, integration of phone systems, software to integrate phone systems that move away from those platforms can cause huge problems for you and your team.
And that was reflected in the fact that not only did they have a round of layoffs, which our heart goes out to those people who are affected, but they offered a voluntary separation package to I think pretty much all of the employees there. That should be the handwriting on the wall. We want you to step away, take what you can now and move along.
They know they're not going to lose everyone. That's just the way these things work. Not everybody can step away from this with, you know, a three month off ramp or what have you.
Their hope is that they can get enough people to take it where they can get their, their labor cost down, because that has become the name of the game in Silicon Valley. Now is I need to reduce my labor cost as much as possible because mythically out there somewhere, AI will eventually be able to do all of this. I think maybe, but I think more importantly, the question we should be asking is, how much longer can Avaya stay in this game before somebody decides to buy what's left of their assets in the unified comm space and do some kind of an integration?
Honestly, I could see a company really coming in and saying, we're going to buy you, we're gonna integrate you with the, the systems that you have with some kind of video conferencing platform, and that's a done deal. And then Avaya ceases to be a company and just becomes a brand under somebody else's flag. I I hope that that's a good exit for them because I really don't see any other thing that doesn't involve a lot of teeth gnashing and a lot of pink slips at this point.
Lambda Test has launched a private beta of their agent agent testing, and it's the first platform that is built to test and validate AI agents. Traditional testing struggles with AI agent unpredictable behavior. But Lambda Test uses multiple AI agents to simulate real world scenarios, check the conversations that are having for tone, reasoning, and biases, and then generate tests from the text, audio, images and video, uh, involved with everything integrated with its hyper execute cloud.
The platform speeds up testing by up to 70%, increases coverage five to 10 fold, and reduces manual QA work, which everybody loves, right? This allows organizations to deploy ai, AI agents more reliably, more efficiently, and most importantly, a lot more safely. Al do you think getting AI to test Our AI agents is a level of recursion that we're ready for?
Well, there's always room for another layer of obstruction and another level of recursion in any system, but my concern is, yes, we're using AI to test ai, and it depends then on the quality of the testing AI to identify the quality of the AI we're building, bearing in mind that the AI agent we're building may well have been built with an AI agent that's helping us to write code, huh? Um, yeah, where's the, where's the human creative in all of this? Well, hopefully that's the thing that we're getting most value out of the actual creative use of the, uh, the engineers, the developers who are building the, this, um, software underneath.
Now Lambda Test has a whole suite of different tools for software testing, and this is just another aspect of their software testing. My expectation is that this is driven by their customers, giving them feedback that testing their AI agents is difficult because if AI agents, anything that uses a generative AI tool is non-deterministic in its output. And so you feed it the same data into build one of your AI agent and build five of your AI agent, it's gonna give you a different answer.
This is just the nature of ai, uh, of generative ai. And so you need some tool that can look at these two answers and say, even though they're not the same text, are they really the same result? And in fact, have we improved the result?
Which is the, the vital question, have we improved the result between version one and version five of our new AI agent? Uh, that's, that's a, a tough kind of question to be asking humans to do at scale. And so we definitely wanna have some automation, and it does look like, uh, some sort of generative AI tool is going to be the most productive way of doing that assessment.
Has that non-deterministic result gotten to something that has improved? It's the challenge, of course, will be in training that generative AI agent that is doing the test of the result of your agent. Yeah, the, all these layers of recursion is starting to hurt my head.
I think the general answer is yes, we are seeing more generative AI tools being built through development, um, platforms, and we should expect to see this continue. We've covered on the rundown some interesting test results of how productive developers are using these AI tools. The short answer was less than they thought they were.
So we'll see whether it be why, um, enlightenment of agents talking to agents and agents, testing agents over time. We've been talking about the salt typhoon intrusion for a while now, and it's the gift that keeps on taking according to the FBI. It's almost certain that your diet has been stolen by the state hacked, uh, state hacked according to the FBI.
It's almost certain that your data been stolen by this state. Salt typhoon's been operating since at least 2019 and has compromised at least 200 American companies and organizations. Salt typhoon's also been able to locate mobile devices and monitor internet usage, as well as recording phone calls from high value targets.
This is pretty sophisticated stuff. The connection to the state, uh, Chinese state was also highlighted because entities associated with various typhoon groups have provided information to the Ministry of State Security and the People's Liberation Army, uh, assault typhoon seems to be something you could spend all of your time on. Tom, have you spent a lot of time looking at this week?
No, but they've spent a lot of time looking at my stuff. Evidently, uh, this was a bombshell report from the FBI basically saying assume that you've been hacked at this point. And, and I can see why, and this is one of the things that I was worried about when we first started covering this story.
Salt typhoon got embedded in telco providers, and that is kind of like the worst case scenario because as we've seen recently with other news of people with Grande Vos or VO Grande, depending on how you look at it, once you have physical access or effective physical access to a device, you have owned that device completely. And that's the ultimate goal for a co a group like Salt Typhoon, is to get some kind of embedded persistent access to these devices that require, uh, you know, that have a lot of data that flow through them. Um, and, and that require a massive amount of effort to get rid of the software that's on it.
I mean, yes, the, the big thing that was dropped last year of how they potentially recorded conversations from, uh, political candidates and things like that, yeah, that was big for an election year here in the us, but the fact that they now have pretty much everything else that they could possibly want or have access to, that's the bigger problem. If they can do phone geolocation, then they can pretty much nail down a group of specific targets to a location and track things. If you don't think that that's important, remember that, uh, there have been generals in other countries that have been assassinated for uploading workout maps to Strava.
Um, you know, the fact that, uh, people who have uploaded their Fitbits to, uh, certain cloud-based services have bulls-eye, uh, secret military bases that we weren't supposed to know about, because they, they track how many steps they take around a thing in the middle of nowhere on a daily basis. You see why this metadata could be important and why a company that has basically unfettered access can, can do that. 01 Bitcoin to make this go away.
Well, now imagine if it was a state sponsored activity that, um, they uploaded and just basically decided to put somebody on blast. What if they wanted to ruin the career of a potential political candidate or, or any one of these things, right? Like that's the ultimate thing that you have to be thinking about here.
I don't know what we're ever going to see come out of the salt typhoon thing. The, the, the biggest hope is that we can get them out of these networks block whatever access they were using to get in and hope that whatever they stole was not sensitive enough to come back to bite us in the future. But I think the reality of things is, is that we will never know how much they got or how critical it is until they decide to deploy it at the dramatically appropriate moment.
And that could cause some magic of issues down the road. So good luck to everybody out there, because, you know, now it sounds super scary. The Lennox Foundation has added document db, which is a PostgreSQL open source document database to its projects under an MIT license, which is aiming to create a standardized NoSQL platform.
This is backed by major companies like AWS Google and Microsoft document. DB combines MongoDB compatibility with Postgres reliability, offering more flexibility in reducing vendor lock-in while full MongoDB compatibility is still a work in progress. The project focuses on portability, developer choice and supporting, you guessed it, AI arrow workloads.
Uh, what do you think about this, Al? Is this just another database that I have to choose from in the magical wheel of databases, or is there some real progress being made here? I think there's, there's a big chunk of confusion on the name document DB here, and I want to address that part first, because AWS has a service called DocumentDB with MongoDB compatibility.
This DocumentDB ain't that, even though AWS is part of the, the group of companies that are doing this document db, this one is, uh, more coming from a little bit of the Microsoft side for some of the, the development in here, but it's a set of extensions to Postgres that make it a no non relational or no sql, uh, querying standard. And the point here is to have something that is in the Linux Foundation that is not tied to a, uh, interesting licensing change. And, and the background on that one is MongoDB changed their licensing to prevent AWS and other cloud companies from building a product using the MongoDB code.
Um, my understanding is the AWS document DB uses the MongoDB code from before that licensing change. And so it was not based on Postgres. Uh, this new one is based on Postgres is in the Linux Foundation, supported by a bunch of other companies as well.
So it's not just one company pushing it out. AWS Google, Microsoft Cockroach Labs, um, and amongst others are involved in this effort to have a standardized, uh, document database tool available. Uh, it's a good thing, it is gonna be beneficial if we see a standard kind of database that you can use across multiple different platforms.
Uh, they're talking about this as being as, as standardized as using sql. So writing a SQL application where your application code only needs to be able to talk sql, and then there's a layer between that, a SQL driver layer between that and whichever database vendor you're using. That's the kind of approach they're looking for here, although it is actually the database engine that's being released in here rather than a, an abstraction layer.
Uh, I think this is a pretty cool thing. I think we will see more development of this, and it will be interesting to see what AWS calls their open document DB service that isn't their current document DB service. Uh, if you follow Cory Quinn's, uh, last week in AWS you'll know that, uh, naming of products at AWS is an interesting challenge all unto itself and, uh, doesn't necessarily follow any sense.
Uh, there's some really interesting elements in this document DB version, uh, particularly support for acid consistency, which is not something we'd normally see in a NoSQL database. That's a, a very important thing, particularly for enterprise organizations, where all of your application developers come from a background of having SQL and acid consistency, and we start talking to them about eventual consistency and they get terrified. Uh, large goal, yeah, full compatibility with MongoDB further down the track.
There's some tendencies for, um, Mongo themselves to take you to court when you get too close to compatibility with newer features in MongoDB. So there'll be some challenges there, but I think the expectation is that this will be a, a product will use rather than MongoDB since that more restrictive licensing. Mongo Apple's preparing a big AI hardware push tabletop robot with Smarter Siri coming in 2027, a smarter speaker, uh, full screen on your smart speaker, then make it a different kind of device, uh, and a new home security cameras.
These devices will run a new operating system just as they've unifying their other operating systems and tie into Apple's ecosystem credits. Warn that the products are kind of late and may not have any unique features, uh, may struggle to complete unless Apple can deliver something truly new. And I think, Tom, you'd love to have something truly new in your Apple hardware state.
Oh yeah, absolutely. I say this as I type this on an Apple keyboard connected to a MacBook Pro right next to my iPad and my iPhone's charging here in the corner and can't help but think to myself how Apple was late to the phone game late to the tablet game. Oh, wait, no, no, they created that one, um, laptop game.
Uh, they, they kind of really pioneered that system too. Um, quick show of hands for everybody out there in the audience, how many of you went out and bought the iPhone 16 because it ran Apple Intelligence? Leave a comment, just leave your hand raised.
Um, now quick question for all of you who are leaving. The other kind of comment before you finish typing, how many of you went and bought the new Galaxy phone because of its AI features? Same number, more, less.
I mean, yes, friend of the show, Stephen Dickens definitely went out and bought the new Samsung Galaxy phone or the Nexus phone. I forget which one it was because it had all these enhanced AI features. How about the rest of you?
Was, was that the break point for you? Like the the choice between these two new handsets was all of the AI features that one did or didn't have, or was it that you just wanted to get a new phone and this one had a a new button on it and they'll figure out the software in a little bit? Nobody buys these devices for the promise of what they're going to have, right?
We know what Apple's ecosystem is gonna look like in the fall based on what they announce in June at ww DC. The hardware to support the software that they're developing is what's usually announced. And yeah, we know what we're gonna expect.
A slightly faster horse that eats a little less hay, or in this case, a slightly faster chip that consumes a little less power, possibly a slightly thinner device. If we get a home pod that has a screen on it, great. But does it need to run ai?
I think that this is where we're starting to get into a little bit of a, uh, a catch 22 is they're claiming that the hardware needs to be powerful enough to run all these new AI features, but they can't tell us what AI needs to do. It needs to be different. It needs to be unique.
It needs to be transformative. When has that ever happened in a Apple's ecosystem? Yeah, it has happened.
The iPhone transformed the way that phones work. The iPad transformed the way that people do compute, but they were not revolutionary and groundbreaking when they were released. In fact, I can still specifically remember when the iPad came out and people are like, this is the dumbest thing I've ever seen it, it doesn't have a keyboard.
Well, who would ever use this? Like, it, it, there's no reason for me to ever, oh wait, now I get it. Because it didn't transform the way that people use their laptops.
It gave people access to a, a form factor of a system that was between a phone and a laptop. 'cause we didn't have that at the time. And I can tell you that because I just got done watching the very first Mission Impossible movie, you know, the one from 30 years ago, and it was quaint to see those Mac or the Apple Power books and all of the stuff that was going on, and then go watch the new one, go watch Final Reckoning and never take out a laptop.
Everything is done on tablets or something else. You know, that future tech that you are so crazy about in these new shows. Everything revolves around these ideas of what these these devices are gonna be doing, whether or not they're running ai, I promise you something, we are as recording of this.
We're a week away from seeing whatever the new iPhone looks like. I don't think Apple Intelligence is going to move the needle on that phone much at all because the people who bought into the ecosystem for Apple Intelligence last year are still bought into it for whatever Apple Intelligence is gonna look like this year. But the people who are just buying a slightly newer phone are not gonna care one way or the other.
So to all the critics out there that say that this is Apple's micro break moment, and if they don't have good AI features and do things, then I need you to write down the five AI features you need an iPhone to do before you'll switch to one. And I'm sure I'll be waiting next year to get that full list. Right.
Al, we had a closer look story that we wanted to take a glance at because it could involve a big massive cybersecurity incident in the making. Now we all probably know the name of New New York Attorney General Leticia James, but she's filed a lawsuit against Zell's Parent Company, which is known as Early Warning Services. That doesn't sound ominous at all There.
She's accusing it of failing to protect customers from widespread fraud that costs victims over a billion dollars, B billion with a B between 2017 and 2023, the suit claims that early warning systems ignored known vulnerabilities and failed to enforce anti-fraud rules on its partner Banks. Experts say that the case rages raises major questions about the responsibilities of real-time payment platforms as well as highlighting the need for stronger security identity verification, and frankly, consumer education. A victory for New York could result in everyone's favorite fines and possibly some mandated reforms.
But the bigger question is whether or not consumers will see meaningful change or restitution from all of this fraud. Now, Al, I don't know if Zelle is a huge payment platform down under, but is d I'm sure you guys have payment processors that you like to use down there in this instant back and forth. Are you seeing a lot of fraud or potential problems with that?
So payment fraud, fraud for particularly instant payments is absolutely a thing. We, we have regular television ads here from a couple of our major banks talking about being aware of fraudulent, uh, activity, people trying to do social engineering because these, these attacks are generally social engineering attacks to get you to give them enough information that they can then institute a transfer out of your account. Absolutely, that is a routine piece of education.
Uh, the banking industry in New Zealand works a little bit differently to the United States. Uh, we're for a start a much smaller country, and so it's much easier for us to have a central clearing place, and we've had that for a while in a way that the US doesn't seem to have. So Zelle, uh, seems to be very widely used in the US to transfer money between individuals or between individuals and, and organizations.
And, uh, clearly a, a place that is ripe as a tire for fraud. Uh, in the same way any other instant payment platform is. We, we saw fraud going back, uh, PayPal fraud coming back 10, 15 years.
Uh, and so this is nothing new that the fraud is going on. The the challenge, of course, is that we have more of those mobile devices that can be engineered on more of the capabilities to be constantly connected and therefore constantly at risk and also increased use of these instant payments because people just don't send checks on the posts the way that they did back when I had here on the top. Uh, times have changed.
And yeah, this is gonna be an interesting test case for who has what level of responsibility in the path through these payments, whether there is a requirement for due diligence on the part of Zelle and, and their partners to make sure that this isn't a fraudulent transaction rather than leaving the penalty entirely on the, the consumer at the end. Uh, I know there's, there tends to be legislation around this. I know there is in New Zealand around, uh, if, if they, uh, if the individual customer has behaved in good faith and, and sensibly, they usually, uh, found to be the ones who should carry the loss rather than the, uh, transfer company.
But if the transfer company has not acted in good faith with due diligence, then they should have some responsibility. Tom, do you use a lot of transfer systems in your, your life? Do you have multiple of these things set up on your phone?
I, I have them set up because I kind of have to for certain things, but I actually don't use them very much at all. Like, I, I went to buy something the other day that the, the person selling it was like, oh, well you can just cash app me the money and I actually had to dig out my password 'cause I never log into Cash App. Um, people are like, oh, well why don't you Venmo me this?
Or Why don't you do that? You notice that these are all brands, right? Cash App, Venmo, PayPal, money, apple Pay, whatever, you know, who wasn't getting a bite out of that Apple?
The banks, and that's why Zelle exists, folks. Zelle is the bank industry trying to get in on the micropayment peer-to-peer payment system because like you said, nobody sends checks anymore. Um, you know, the, the, the holy grail is to be able to tap your phone together and transfer that money back and forth.
There's, there's very little like physical money transfer happening. Like I just finished, uh, working, uh, a football game here in Norman, Oklahoma, and the entire stadium is cashless. They, they will not take cash if you show up with it.
Like if you have cash in your pocket, you have to go to a machine and transfer that cash into like a debit card or you know, some kind of payment card and then use it. So why was Zelle so particularly egregious here? One of the things that makes people pick one payment processor over the other is friction.
Lower friction means a little more likely to pick that one. PayPal for the longest time was the lowest friction option because everybody had a PayPal account and then Zelle came along, I'm sorry, not Zelle. Venmo came along and Venmo reduced friction as well.
My wife takes, uh, payments for her tutoring through Venmo and they, Venmo sent her a debit card. It's like, you don't even have to transfer money back and forth, just pay directly with your card and drove. It's driving the, the banks nuts because not only do they not get any of that money, they can't, it's not stored in their bank system, which means they can't loan it out in, can't earn an industry on, but they don't get the transaction fees because it's, the other part of it is all those transaction fees are avoiding the banking system.
So they created Zelle and they made it as low friction as possible. How low friction, basically you had a Zelle account, whether you realized it or not, if you were working from one of the major partners of Zelle, they had already pre-provisioned you a Zelle account or enabled it. So all you had to do was call in and do that.
And this is the fraud that Letitia James is talking about because it did not take any verification system or, or minimal verification at all for me to call a bank with an account number and some kind of identifying information and set up a Zelle account and then it goes to the app and then I redirect that to a different account somewhere. And then I start using your legitimate bank account, Zelle information, transfer money all over the place. And not only is it invisible, you may not even know you have a Zelle account, but then nobody can trace it.
And so when the fraud comes back, it comes back to my bank account. 'cause that's where it was attached to. And now I'm fighting charges that I didn't even know I had.
And that's the problem. If you create a low friction environment with no checks and balances, then what ultimately ends up happening is that people are going to defraud it. Because I don't know if you know this or not about human beings, Alistair, but they're always looking for a shortcut, especially if it means I can get rich from it.
And so that's the problem that people are dealing with, is they found the get rich quick scheme and they're gonna ride the sucker into the sunset. And so what ends up happening is, is that people like me are left out in the cold. And by the way, I did check, I had no intention of using Zelle ever, but I still check to make sure that my bank account had a Zelle whatever, so that I could set it up, set up my passwords and everything, and then shut it off.
It didn't because my bank is a credit union and it wasn't participating in Zelle, which made me feel a little bit better. But I can also tell you that scammers are looking for Zelle. They prefer to use Zelle because the same kinds of, uh, transaction protections that places like PayPal and Venmo use don't exist in Zelle because it's effectively almost like a wire transfer.
Once it's gone, it's gone. And so at least with Venmo or PayPal, if they, they detect that it's a fraudulent transaction, they can claw that money back. Zelle really can't.
And so I hope that this at least as a win for the the New York Attorney General, because one of the things that we found over the years is that when things happen in New York, because so much business goes through New York, they almost invariably have to change the way that they do things in order to make sure that they're able to do business in the state of New York. And then we just get all the benefits of that. Well, on that note, there is one thing that I know that you can absolutely bank on electronic or otherwise, and that is the lineup of field day events that we have coming up.
And we're really close to the next one. I believe Al that's on you. It is.
I have an amazing week next week where I'll be up in Santa Clara for AI infrastructure field day. We'll be live streaming on the 10th and 11th. That's Wednesday and Thursday next week.
And we have a patch schedule. We have, um, Morant and Broadcom, we have SAT and Refa, uh, we have Hammer Space and HPE as well as having an amazing panel of delegates who are gonna be in the room representing you as the viewers and asking the really interesting and challenging questions of our presenters. As always happens at Tech Field Day events, you get a a week's break off from, uh, tech field data, catch up on everything that you missed for AI Infrastructure Field day, and then it's back to Silicon Valley for Tom.
And you've got Security Field Day. I do, I've got a great lineup of security Field day companies. com for the list and also check out the delegates while you're there.
I will be asking them if they've set up Zelle or others payment processors. And then I'll also be asking 'em for their secret questions to see if they're paying attention. Then I'm gonna take a week off, but I'm coming right back with a special virtual event.
We're gonna be doing Tech Field Day exclusive with Microsoft Security. They have some big announcements coming up at Microsoft Secure on September the 30th and the next week we are gonna be diving right into those. We're gonna be getting a firsthand account of all the cool stuff that they're working on with Microsoft Sentinel.
com to see the lineup and get more information about that. And then Al I believe you're back with more. Indeed, I am, I'm returning October 22nd and 23rd for Cloud Field Day.
Uh, that should be another awesome event. We've got a HPE and uh, we've got oxide returning. They're an amazing company.
So we have that nice little lineup starting for Cloud Field Day and we'll be building that out as we get closer and closer to the event. And then Steven FoST finishes our October with AI Field Day October 29th and 30th and he'll have another great panel of delegates and a great selection of presenting companies. So check out the Tech Field Day com site.
You'll find details of all of our events, past, present, future events will all be there. And you can see all of the interesting things that we've talked about and make sure you tune in for the presentations you really care about. Of course, another presentation you really care about is us right here with the tech field data rundown, where with you every Wednesday with new episodes, you can see them on your favorite podcast application or you can catch us on YouTube as well.
Of course, if you would rather watch on your streaming device. We are featured in the Textron TV app on all of your favorite streaming platforms and you can often catch us on the Textron Gang or other RUM group programs. We'll be back next Wednesday with all of the IT news that's fit to print or fit to make sarcastic comments about.
Until then, for myself and for Tom Hollingsworth as well as for all of us here at the Tick Field Day team, we're wishing you and yours a great week and we'll see you on Wednesday. Welcome everybody. My name is Jared Burns, I'm one of the solution architects within the VMware Cloud Foundation Division for Broadcom.
0. 0 depending on where you're coming from. All right, to go over a couple of things.
So most people are aware of how VMware Cloud Foundation was in the older versions, which is you had what was called a VMware Cloud Foundation instance, and that instance was SDC manager, your Storage vs. Center, NSX. And you ran on the, the, as an instance, and each instance was separated.
It was all by itself and you could have multiple instances and they can all be independent of each other. What we've done on VCF nine is we've introduced a new concept called the VCF Cloud Foundation Fleet. A fleet now consists of one instance, but it also consists of operations and automation as a whole.
And what I mean by that is you get one single operations, one single automation that runs across a fleet, and then you can have multiple VCF instance talking to that fleet. And then we also came back introduced the VMware Cloud Foundation and private cloud. But what that means is that is just pretty much a group of VCF Cloud Foundation fleets, and that's really the only big difference.
Now with the way that, um, private cloud works for us. Couple considerations that we always take into account when we do a VMware Cloud Foundation deployment. We always wanna look at centralized management.
What we mean by that is, is where is my operations gonna live? Where is it gonna be placed and where is it gonna be best for performance across my fleet? Second one is my initial deployment.
I'll always follow what we call a VMware Cloud Foundation Fleet Deployment basic. Um, and I'll talk more about that as we go along, but it's pretty much the first design you start off with. It is what you deploy out of the box.
So it will be SDC manager, operations automation and vCenter with SDC manager over the top. And this does support multiple, um, foundation agencies depending on how you wanna deploy. And then flexibility, we're allowing for multiple clusters, single domain, um, inside of a VCF fleet.
Now we've cut down on the need to, you know, have so many restrictions around how you deploy the VCF instance. We're supporting more storage, we're supporting more options when it comes to the architecture of A VCF. Here are the four designs that we're gonna talk about today.
Um, the first one is VMware cloud, uh, is VMware Cloud Foundation Fleet Deployment Basic Design. This is the one that we just talked about early on. Then there's one that's called the site high availability, which is across multiple availability zones.
The third is disaster recovery across regions. And the fourth one is a in, it's a mix between the site high availability and disaster recovery, where you give both the best worlds. Hey, Jared, quick question.
I don't wanna get too deep in the weeds, but you have to choose one of these four deployment types, you know, in design prior to deployment and, and stick with it, uh, until you redeploy. Or is there opportunity to go from one design to another as you mature as an organization? And maybe you wanted basic to start out, but you need one of the more complex designs, uh, with more capabilities later on.
Yes, that's correct. Yeah, so basic you start out with, right. So basic is where we get everything.
The rest of these you can go about. So majority of our customers, you know, most customers out of the gate aren't going to be able to, um, know the exactly that they want, say high availability day one, or they want disaster recovery. So what we do is we base it off the first basic design and then you can just grow into the rest of the designs.
The only difference is, is that you'll have a second availability zone or you'll go into DR and you'll just need to come up with a way of how you wanna do Dr. Now as in, you know, prior releases, we've really recommended SRM or VLR, we still do recommend VLR, um, but we also allow for more different solutions when it comes to dr. Um, you know, your other software that's out there that can do the same kind of replication between two sites.
Gotcha. Thank you. That's a great question.
Thank you for bringing that up. All right, so let's go in the first design. So this is the first basic deployment design.
And as you can see here, you have VMware Cloud Foundation Automation, VMware Cloud Managed Operations, your STC manager, storage, vCenter, NSX. 0 we are allowing for, um, a difference. So we allow for vsan still, but we also support Fiber channel and NFS out of the box.
So when you go to a green field deployment, you don't have to just do VS a for management domain. You can now do fiber channel or NFS for your management domain. The key to this basic design is that this is where you start, it's your foundation for everything, but it doesn't establish high availability of fault tolerance between, um, racks or between sites.
Now what you won't see here is we don't talk about rack design, we don't talk about your network design. We're, we're kind of hoping the customer has an idea of what they're they do today and we don't wanna change it. So we're just saying, okay, customer, you know, if you wanna set, go across multiple racks with your hardware.
If you have redundant UPSs, redundant networking, as long as you're good there, we're good to put our software on top of that. Alright, quick que quick question here. Uh, do you still, uh, support consolidated, um, uh, like to consolidate the management domain and workload domain together?
Yes, we do. Um, mm-hmm. Okay.
We just don't use the term consolidated and standard anymore. Mm-hmm. Because everything is considered, everything is pretty much a consolidated out of the box.
You, you choose if you wanna build workload domains, so you could have multiple VCF instances where you just have a management domain with multiple clusters across a fleet. We don't met, we don't recommend, we don't have to recommend a workload domain. We can, you can choose that workload domain depends on your needs.
But yes, we do still support, um, the old consolidated model. We just don't call it consolidating where we just call it domain. Alright, thank you.
Thank you very much. No Problem. And, and you mentioned you don't dictate to customers like what their design is gonna be for high availability or anything, those like that, but there were capabilities in the product particular with vsan if they choose to use it like stretch clusters and fault domains.
Are all those features still available? Well, customer designs, Yeah, they're still available. Um, the difference is, is we are now allowing for metro clustering.
So let's say you are a customer that has Metro clustering set up between your two, your two availability zones. Our manager domain now supports that solution. Now will SDC manager, it's still not in the workflow for SDC manager.
So it would be still where the customer would build, you know, four hosts to one site, four hosts to another, connect it to the storage and then create all the, the workflow to do that. But yeah, we do support vsan stretch cluster still, it's just we're not forcing a customer to have vsan in their management domain. We're trying to give a lot more options around that.
The second one is high availability, as you can see here. Um, the key to this one is having portability between your IPS addresses between availability zones. You can do it with NSX or you can do it with your underlying nor um, networking structure.
Um, there's no requirement to have NSX to stretching between the two availability zones. If you have layer two stretching with your, you know, underlay, then that's supported. Um, we also allow for the differences now that the VMware cloud automation operations are not deployed by default anymore on AVMs, we, um, have gotten rid of that terminology.
It's now it's up to the customer to deploy If they wanna deploy on V AAG networks or in aex segments, it's up to them during the deploy. Okay. And then the next one is disaster recovery between zones, which you'll see here is you'll see operations being replicated over automation is a little different.
Um, it's using, um, we call VMSP, but it's a Kubernetes backend. So we are still working through like how that recovery would happen for automation, but it doesn't do the same replication as it does today. So it's a little different when it comes to that.
And then the last one is pretty much, you know, stretch clustering and replication. And what you'll see here is that you have two availability zones of region one and region two, um, and you're, you're actually replicating operations to region two. Now, one of the new features that I did not have a picture of, and I should have had a picture of was when you deploy this, you can have one region, one region two and you can have a fleet sitting in region one that's will maintain and be able to, um, support a VCF instance of region two.
So you don't req, there is no requirement to have, you know, operations of both regions. You can have operations in one region that'll support multiple instances across the globe. The only key difference there is that you always wanna keep in mind that it's 500 milliseconds round trip time between the ops collector and the operations cluster and a hundred milliseconds between workload domain and the v the vCenter or, um, host that it's supporting.
So you always wanna keep in mind that based on your VCF instance, you don't wanna go more than a hundred milliseconds between your host and your vCenter and you don't wanna ever go over 500 milliseconds between your operations and your operations collector. So Jared, just just to be clear, that's, that's like an operational requirement, like the delay can be no more between those components for the a hundred, a hundred millisecond 500 millisecond requirement? That's correct, yes.
It's round trip now. A hundred millisecond has been tested internally to us. That's the highest we could get with a workload domain.
500 milliseconds has been out there for a while with operations, so that shouldn't be a change to most customers. But it is a change because what you have to take into account now is that ops collector does more, it used to just do, you know, metrics and um, object collection and sent to the operations. Now it has the ability to do log forwarding, so where you can actually grab the logs from that local site and send it through the log collector or the operations collector back to operations and logs to get the information.
It also supports, um, data be held locally for a temporary amount of time for the operation collector. So if the operations note is down, it will keep those metrics local to that collector for a certain amount of time. Uh, and Jared, I have another question kind of about the architecture.
Uh, and I think you covered this and I'm just not familiar with the new terminology. Like I assume I see multiple management domains and VCF that used to be, um, federation back when you had multiple SCDC management instances, but now VCF operations is the single point of management for multiple VCF deployments with multiple management domains managing the single console. So that's kinda like the new federation, is that correct?
Yes, That's correct. Yeah. So operations is now the new, the new federation.
So the way operations works now is that we deploy out a appliance called VVCF Operations Fleet Manager is a replacement for the Aria Lifecycle Manager. You've seen in the past with the ARIA products and what it is, it connects directly into operations and it does its fleet lifecycle management, password rotation, certificates all in one place. So that operations itself is able to ly single manage every VCF instance that's connected to that operations instance.
Um, so single pane of glass multiple places, you know, one place to go in now it's not like where you can click on one button and upgrade everything in one VCF instance or inside of a a full fleet. But what it does do is give you a single pane of glass where you can click on different VCF instances and do upgrades and pass a rotation certificate management at any given time. But it is the, it is like the old federation of SDC manager I see different just moving into operations and there's some futuristic stuff coming down roadmap wise where we're gonna do more with operations and that type of stuff.
So stay tuned for that. Gotcha. Alright, so we're gonna go through some green field deci decision factors.
Um, one of the first one is what we call local fault domain or fault protection, protection costs. Well availability zones or protection disaster. This is one of the key things that we want customers to think about when they go about doing the planning of their fleet.
They want to, we wanna be able to say, okay, do you only need, you know, vSphere high availability to protect your workloads or do you really want to have protection across multiple availability zones or are you not really wanting to have two sites for high availability but you do want disaster recovery. So these are kind of the things you wanna think of out of the box, but you don't, it's not like you have to do this right away. Like I said before, you can use the basic deployment, deploy the VCF fleet with the instance and then it can, and then you can just add on over a period of time.
It's not something you have to think right away. There's only a couple gotchas that you would want to keep in mind is you wanna make sure if you are gonna do a high availability, you do stretch your network and your storage. If you do dr, you wanna make sure you know your IP portability story upfront so that you know when you lay out those tools, operations automation logs, you know how you would be able to move those if required.
And then a couple of things around operations placement scale, what we're, what we're bringing up here is that you wanna make sure you have enough scale for, you know, compute memory storage resources for the operation appliances. Um, in the, there's 2D deployment models you can look at. The first one's called Simple.
And what that is is that deploys one operations primary node, one fleet manager and one collector. When you do high availability, you're deploying the normal, which is, you know, primary replica data and then you have the option to deploy in um, multiple collectors, but you can do after the fact, but you do do a fleet and collector and then the last option and when you can't deploy it right out the box, but it's something to think about would be operations, continuous availability. But that one has some, um, regular like restriction around you gotta be within 10 milliseconds of each of the nodes talking to each other.
So you have to always keep that in mind when you do the design. And how easy is it to scale out or back in from those various deployment types. Um, for ca it's a flip.
You have to flip it from CA to HA and then you would delete the no you didn't need anymore HA from simple is pretty simple. Um, you just use the new VCF operations fleet manager to do that scale out. So you would just go into the fleet manager say, I wanna deploy replica in a data node.
Um, and then you would scale it out. Now it will ask you where you wanna place those. It usually places them in the original management domain they created.
Um, I'm still testing if it's ability to do it across multiple, um, data centers. But then you're talking about CA and you got start talking about latency. So it's best just to keep all the HA nodes together.
Um, so yeah, there, there is, it's pre, it's it's about the same as it was with are you a lifecycle manager, suite lifecycle manager? Um, just a little different when it comes to the interface you use, you don't log into a separate interface anymore. You log into operations, you go into Fleet and then you do the scale off in the organization separation.
Where this one becomes key is, um, if you have customers that are running PCI environments or something where you can't have it, see operation, see all the environments it's running, I have a couple customers that they have separated environments where they cannot deploy operations as a whole. So then you would wanna look at, okay, can I deploy it with how do I wanna deploy my fleet for these type of solutions? Do I want operations run certain types or do I want to type, type of workflows or do I want to be able to be across the board?
So you wanna look at your organizational separation because we don't have the, the tendency in operations, we do an automation, but we don't have that as of yet in operations and it could come down in future, but we just don't know when that would be. Uh, and can I have a question here? This organizational separation thing, it's uh, some kind of, uh, transferring the vCloud director and functionality to VCF or this is completely new approach and it's not gonna be connected to that, uh, let's say name as this product or many customers.
So That, that is something that's coming in our, with the automate VCF automation future releases. I don't have a lot of details on how that's gonna look, but that is something we are looking at with VCD into the automation platform and how they do tenancy within VCD. Yeah, so that is something mm-hmm.
Here we're just talking about like if you want to deploy multiple fleets with different operations and automations to manage those fleets, but So it's basically completely dedicated infrastructure Yes. For some organizational part or customers of of of the IT department. Yeah, that's But the infrastructure needs to be different though.
They are not share the same infrastructure. You're not sharing your operations, you're automated instances across multiple VCF instances or clusters. That's correct.
Alright, thanks. Alright. In the mi we talked a little bit about it earlier, but another big design decision that you would wanna think about upfront when you do a greenfield deployment is, where do I wanna place my operations and automation nos out of the box?
Um, there are two ways we, there's one we call the preferred way, which is you would deploy it with the VCF installer, which is the new terminology for the cloud builder. So it's a replacement of the cloud builder in the older VCF deployments. And what it does is it allows you to put all of the components on one network, which would either be ESXI or VM Management Network.
And based on that, then you'd make the choices to say, okay, now that's where it's gonna live. It, it goes through the installer. The installer does the full bullet belt out in one step.
Now there are options, and this is something maybe you would consider around DR or high avail, high availability when you site availability is deploying as a second day operations. And what that means is that you would skip operations and automations day zero and you would run a different API call into the solution to deploy on a separate VLAN or NSX segment for operations automation. Um, and why we that's offering is there is that there's some recommendations around if you use an SX segment, if you wanted to do federation for dr, you'd want to be able to put that on a segment.
And there are, you know, concerns around if you wanted to stretch a VAM between two sites, it might not be best to stretch the VM management network between those two sites because that has the V center NSX living on it. So that is kind of something to think about and it's something I would consider day one because you're not gonna be able to switch those networks or ips after the deployment. So it's something up front I would be, I would consider out of the box.
All righty. So couple more design decisions. I know there's a lot of design decisions, I do apologize, but want to give you guys as much information front.
So we still have the 25 vCenter per VMware Cloud Foundation instance limitation. Um, as part of that limitation, just keep in mind that once you hit the, the 25, you just build another VCF instance. The second one is, and this is a big change from the five x days, is we went from 1200 hosts per VCF instance to 2,500 hosts per VCF instance.
So about 1300 and we still support a maximum of 25 x managers per VCF Cloud Foundation instance. And, uh, what is the minimum, for example, host amount for set up the VCF cluster For a management, the VCF foundation, it's three or four. So three is for simple, four for for high availability.
So we, you can deploy in three to do a simple deployment, which would be one. No, when I say simple and I, I don't talk about it in the slide deck, but what simple deployment means is I deploy one operations primary node, one automation one in SX one V center, and SDC. That's a simple deployment, right?
And I do have a collector, but those will be simple. One appliance for everything, for each component. When I go to ha's, when I would have, you know, three of sxs, three operations in the analytic cluster and three automation, um, notes based on that, you need four.
But you can start with three hosts if you wanna come, um, out of the box, Is it still a requirement that if you want to stretch virtual domain, you also need to stretch management domain? It's not required if you're using, if you're not using vsan, if you're using vsan, SDC manager does still require it, but if you were using non vsan like a metro cluster, you could stretch workload without stretching management. And, and is there any maximum number of VCF instances that Cloud Foundation fleet can manage?
Not at the moment. It's based on the operations objects and metrics limits. And I think If we hit those limits, that could be a Potential model.
6 million for a large or extra large operations node to hit that number for, I think metrics and objects, I have to get the numbers for you, but if you hit those is when you would need to deploy a fleet and it, you guys know what, like what a object is and what a, um, metric dig. So like, as long as you're not hitting those numbers, yeah, you won't need multiple fleets. But again, you, you would wanna look at, you know, what is, where do I place my fleet and is it best for me to have a fleet in, you know, New York City supporting, you know, something maybe in, you know, London or you know, Singapore or to Tokyo.
You'd have to think about what's, what's best for you. Um, and running a fleet two fleets set by, you know, next to each other is not that big. It just means more hardware for management, but outside that it's, it's not as bad as it used to be.
Um, but it is still, uh, operations undertaking to do. 0. Um, when it comes to IP requirements, so this is what we're talking about, simple and high available.
So you need at least four nodes, um, ips, I, I, I think I messed that slide up. It should be three, not four, sorry about that. And four, four high available.
And then you'll see the ips across the board of what's required. We need to deploy it. Um, VMware identity broker I haven't talked about yet, but that is used for the replacement of VMware Identity Manager.
Um, it's the new V-C-F-S-S-O and then it shows the rest of the ips. Any questions so far? Okay.
And then we'll go to the DNS entries. Same thing. DNS entries.
It would be three for simple, four for high availability. I, I, I for some reason did a copy and paste there on that one. But these are all the DNS Ries and what you'll notice here is OP automation shares 1D NS entry pretty much.
So you would have two entries altogether, but it, it, it shares DNS entry and the IPS on automation. I'll slip back to this real quick. It says two and the reason why there's two there is one is always for upgrades.
So like for simple, you'd get two because the first node would be using the ip and the second node would be the second IP would be free. And when you do the upgrade, it would build the second node with the new i, the second IP and then release the first ip. And same thing for, um, ha you need four IP addresses, but only three are in use and it's an embedded low balancer.
So the in low balancer is not external. Um, and in for operations the same thing. 0.
We give you the option, but we, but you're not required to put anything there. All right. And here's all the steps that go along with greenfield deployment.
You prepare your, prepare your es os you download U VMware Cloud Foundation installer. Now the, the big difference there is that cloud builder used to have all the bits. So when you download a cloud builder, it was about a 30 gig file, um, ISO or OVA that had all the bids.
So it had NSX vCenter, um, all built into it with the new vvc, the VMware Cloud Foundation installer, you just deploy the installer and then you reach out to either a online depot or offline depot to download the binaries for the installer itself. So we no longer store 'em inside of the OVA for the installer. And then you complete the UI wizard either by going through the steps or uploading A-J-S-O-N, it does a validation of deployment specs, they'll do a deployment, it'll deploy automation operations, SDC, vCenter and NSX out of the box.
And then, um, you will go in and configure your licensing. Um, there's new licensing as you guys probably are aware, where we are no longer using keys for our licensing. And we go to a keyless solution, which is a file that you download from our webpage, and then you import that into operations.
And operations then has licenses required. And then you deploy, you know, the cloud foundation identity broker. The, the broker is the V-C-F-S-S-O.
So we went to a one single place to do all of our authentication and that does integrate with third party like, um, ping and uh, Microsoft Auth authentication. And then you deploy operations logs and networks. So, uh, all this nine steps can be done in dark site, uh, setup.
So without internal active Turner Connection, right? That's correct, yes. So what you would do there is on the third step, you'd either import those binaries into the VCF installer or just set up an offline depot if you can, that has internet access and then transfer 'em in.
If not, then yes, you can still do the bring in the bits offline for a dark site. And Where does that Cloud foundation installer deploy to or run from? Is it one of those ZSXI hosts you prepared?
Is it somebody's laptop? Do you have options? What?
You have options. So you have options. So the, the key to the, the, the installer is that if you can deploy it on the host, you're getting ready to bring up to be VCF.
Now if you do do that, what it does, it turns that installer into the SDC manager where if you deploy on a separate ES six I host it then will leave the installer alone and build a brand new SDDC instance or appliance. And why that's critical is you're probably asking is that if it turns in the SEC manager, then you can't reuse it. So let's say you wanted to deploy more VCF instances, you can't reuse that appliance to deploy more instances because it turns off that functionality where if you deploy it on a separate host that's not a part of VCF today, it allows for that functionality to stay because that install is pretty much the SDC manager is what it is.
It's the appliance for SDC manager just with the functionality of the installer. Yep. 0.
What we're gonna do is we're gonna go through some customer environment. So what we call this is a self-managed V center. What we mean by that is, is that the V center itself is actually living in one of the clusters within that V center.
There is no separate management V center over the top. And so what you'll see is, is as we progress through this, if you're using a self-management vCenter and you're moving to VMware Cloud Foundation nine, you're doing an upgrade, it would then install that vCenter. That is a management vCenter in, it turns in one of those vCenters into a management vCenter by installing operations automation.
If it's not there, if it's there, you would just upgraded place. But what we're trying to show here is that we're not, we can do this either with self-managed V centers or Management V centers themselves. So here you'll see self-managed V center with ELM.
0 when you do a upgraded place, you cannot have enhanced click mode intact. We do request you to break that connection. Um, and you would break it on the VS center as going to management first and then you would break any workload domain vs.
Center. You wanna bring in separately. Now there are two ways to do it.
0, which is you run the utility and it breaks out the fir only V center by itself and then you just recreate all the permissions. The second one way is you would upgrade all your V centers to nine that you're planning on putting in nine and then you would break 'em after the fact. 0.
So you don't lose any of the permissions that are on the vCenter. So that's something to consider also as part of when your design decisions as part of the vCenter ELM. So then the next one is that, um, we're gonna talk about here is is again, ELM.
This just kinda shows what happens to the management domain. Okay? And then this would be the managed vCenter with multiple V centers.
So this is a V center that manages multiple V centers. And all we wanna do is here is just kind of show what happens. So your vSphere stay there, but it's now a management domain.
All right, so then this shows up as your vSphere deployment with VMware Cloud Foundation. Um, what you're seeing here is these are all the steps for just a vSphere customer. This does not account for operations.
Um, so what I mean by that is, is that this would deploy a brand new operations automation solution. So this would be a customer that just has vSphere and nothing else. Um, so this will show you, okay, what does a customer have to do to get to VCF nine with just vSphere generic by itself.
This is with vsan or external storage, whichever way you want to go. But as you can see, there's, there's one through nine steps. It's kinda like the greenfield.
The only difference here is there's some more pre or extra to follow. Um, one of those is lifecycle. 0.
So you would migrate your workload domains to VLCM and then you would up, you would do the rest of the status. You create vCenter, you upgrade ESXI or ESX and then you deploy the cloud built installer. Wherever you can de deploy on that clusters, you're importing or upgrading or you can deploy on a separate cluster.
If again, if you deploy on the cluster you're bringing into VCF, it will turn that into the SDC manager automatically. If not, then you would get a new SDC manager appliance And then you configure the depot and binaries again for the installer. And then you would do the actual upgrade to VMware Cloud Foundation and you deploy op operations automation as part of that.
And then you configure your licensing and then you would have the option to import any workload domain B centers. Any questions on this one? Okay, our customers supposed to be able to do this by themselves or Yes, customers should be able to do this by themselves.
Um, we have some, um, upgrade guides that walk a customer through all the steps and all the pre-reqs required to do this work. Um, it does take a lot of steps. I'm, I'm not gonna lie, it's, it is a lot of steps.
Um, but the key is it's not as hard as it used to be where you, when you did the actual conversion to vCenter or VCF where you used a script inside of STC manager to do the actual conversion, it all does it through the installer now. So what you do in the installer is you select what your existing components are. So if you had vCenter and operations, you click those two boxes, it then pulls in the names of those two boxes based on you entering them and then it does the conversion so you don't run a scripting longer.
So it, we have made it easier to do it it, but it is still a lot of steps to follow. Yeah, all All experience from upgrading from five to 5 0 1 or to 5 0 2 says that a lot of issues will normally show up that you need some help for. So solving, Yeah.
And so we'll talk through the vSphere VCF to VCF upgrades. But yeah, the um, yeah, we've tried to shore up a lot of those issues we've faced in the past, um, around how to do upgrades and how to get a customer there and be successful. And one of the keys is design planning and then the perform all prereqs.
Those two steps are very key for successful of being doing an upgrade. Um, and the reason for that is because, you know, we talk about ELM in there and how ELM will affect you, how vem affects you, uh, how like vCenter ha, so vCenter high availability would affect you. So if you're using the appliance based vCenter high availability, how that affects you, how you can turn that off and then turn it back on.
We talk about NSX Federation if you did run NSX Federation during the upgrade for some reason in your environment, we talk about all those kind of things. So the real key to these upgrades is getting into the design planning and seeing the differences and then what the pre you need to perform to get to where you need to be. Um, can you onboard as well through this procedure infrastructure that you have at some hyper scholar, uh, based on your license that you can bring VCF nice license to the I know Google or, or I assume Azure, I think, uh, Azure VMware platform.
We have, I think it's called like that. I'm sorry, VMware Azure. Azure, yeah.
They called the, it's a service engines now. I can't think of all of 'em off the top of my head, but yeah, there are mm-hmm. Engines around it.
I have not got into how you would do those, how you would upgrade those into VCF and we haven't, I haven't done a lot of detail on how to get nine on those engines at this point. Okay, thanks. Alright.
Did that, And here's some of this is where I show you the changes between, you know, what you're going from. So you're going from individual product license, key based endowments to keyless subscriptions. You know, your V three HA stays the same.
If you're running V center high availability, you disable VCHA, you perform the upgrade to reconfigure it, you know, your V three cluster stay. The same enhanced link mode we replacing with VMware Cloud Foundation operations and VMware Identity broker. Um, we do support, you know, standard switches and VDS switches.
The only caveat to that is, is that every host has to have at least one connection to one VDS. So the VDS has to be connected to one. Um, we do import workload domains within SX existing today.
1 or higher NSX and then you can import as is. There is no requirement to upgrade 'em outside of VCF. You can have eight in NSX four, bring 'em into VCF and then use the VCF fleet components to do the upgrades.
And then we go through vsan and vendor non VMware. So we still support that. Um, if you deploy, if you don't have operations deployed, we'll deploy it.
If you have don't have automation deployed, we'll deploy it. Um, we now support Kubernetes containers through automation itself. We do not support VxRail today on upgrades and we do not support high heterogeneous clusters on support today.
And we do enable FIS by default on the vCenter itself. Okay. It's your FIPs your FIP certification.
Is that now at one 40 dash three or is that referring to something else? I think it is, but I would have to get back to you on that. I'm not really sure of that one.
Okay. That's just the, the latest, the latest iteration, you know, beyond one 40 dash two? Yeah, I think it is 1 43.
I think I saw a paper on it, but don't quote me on that. I'm not really sure if they've, what they've done on that. Actually, I just know that when you replace the vCenter now from eight to nine, it deploys the brand new of vCenter.
It does automatically turnips on through the API and then it's automatically set up. Okay. Um, then we're gonna go through some the design considerations in whole.
So you can see all the design considerations here we just talked about. And then we talk about ip. So in a vSphere environment where you only just have vSphere, if this is everything you're gonna get deployed on top of it.
So you're gonna have S-D-C-N-S-X, VMware Cloud Foundation operations, the fleet manager collectors automation, and then how many ips based on which model you slu. Um, you choose on that selection of what would be required. 0 update one or greater to perform an upgrade to nine.
Um, that's also for import or management upgrade. The license has changed. 0 scale.
You wanna make sure your existing environment can support. 0 resources. We do increase our CPM memory on at least automation side of the house, but we, and some of the other stuff is increased a little bit, but you'd wanna take into account NSX and some of these other new appliances getting deployed.
Vsan. Um, we do SS support a n stretch during the upgrade process. So you would upgrade the witness or replace the witness, then you would do the upgrade, um, and then actually perform the VCF convert to um, VCF nine.
0 or later you do need a temporary IP address for vCenter. And then you would also want IP addresses for the DNS records. For additional components.
Um, all clusters that need to be upgraded are part of the new management vCenter need to be on vSphere Lifecycle Manager. So if you're on V we ask you to convert that to VLC cm. And then if you do have e lm, we do ask you to remove that VLM from that vsan we're getting ready to convert to management.
Do you still support VS a n also? Yes. Yes.
Okay. Thank you. Yes, we support VS A-N-O-S-A and vsan ESA.
0. And then we kind of repeat some of this stuff about like what you're gonna do. You wanna make sure you configure the mapping offline depot, that type of stuff.
Um, you wanna make sure the VM is, you know, the installer, you wanna make sure you put it somewhere where either you wanna, if you wanna reuse it, you put it outside the management cluster. If you want to just turn to SDC manager, just put it inside the cluster, you're getting ready to move to VCF And then this has kind of pops you through all the steps. And this is for the import of workload domains.
We don't support management right now with NSX attached to it, but we do support workload domains, vCenters that are gonna have, uh, that do have an NSX. 0 that has no NSX and and you wanna bring it in. If you put it on nine before bringing it in, it actually gives you the ability to only deploy one NSX manager if you require it instead of three.
But if you're on eight, it'll ask you to do the standard three appliances. And we do not support NSX Federation as part of vSphere. Now VCF, we do support NSX Federation to be in place, but we don't sp um, support N SX Federation.
If you are a non vSphere CUS V CF customer today and you're just taking a vSphere and importing it into VCF and then here's all the imports orders that are N-F-S-V-D-S cross cluster imports, icas, the V vault H CM mesh import, two host VSAN cluster import vsan stress clusters import one no cluster or a standalone cluster. Um, what we did there is all Standal standalone hosts are importable now within a vCenter. So if you do import a vCenter that has a standalone host, all we would ask you to do is connect it into a cluster.
So moving into a single cluster and connect to A VDS and then we can import it and then we can support single p Nick host. And then we talk about configuring the offline. 0.
You would, um, configure SDC Managers Depot and then you configure the VCF operations Fleet Manager Depot. Both can be offline, both can be online and both can be manually where you upload the packages, the pack, um, bundles separately independent, but there are two different managers. You can use the same offline depot for both if you choose to.
And then the next steps are configuring automation after deployment. 0 and you get the same experience you have today. And then the other option is to deploy Identity broker for single U-C-F-S-S-O.
So this just GA back in June, correct? June 17th I think was the date. And so what are you hearing from the community?
Like you've, obviously you've gone through and you've tested all sorts of migration options. Um, what are, what are the gotchas, what are some lessons learned from field, um, installations and upgrades that that supplement what you've, uh, talked through so far? So we have been talked through with all of our customers and we're not getting customers just doing upgrades.
They're doing either Greenfield or they're doing up, they're doing greenfield and upgrades, they're doing all greenfield or I haven't ran to many customers say I'm gonna upgrade everything. Um, some of the gotchas that we've, we've kind of gotten in is that a lot of our customers have thought, well I have to have VCN for management, so I gotta go buy buy brand new hardware. And so that's been a big challenge because when you go and have that conversation with the customer base, they're like, okay, I need VCN for management.
Uh, and we're like, well no, you don't anymore. And that seems to have opened the doors a little bit more to VCF in the sense that customers now have that opportunity just to go with whatever hardware they have as long as it's on the HCL and whatever storage outside of, they still need a new fiber channel NFS for management, but then it's a little bit more open for the workload domain side of the house. So really that's the big gotchas.
Um, the other gotchas are ELMA lot of conversations about ELM and what we can do and how we, you know, make sure the services are the same and there's no changes. Um, but those are really the big ones we've learned so far off of. 0 are looking at, they're gonna do a greenfield and then they're gonna do some upgrades or imports of work order domains at a later date.
Um, I I have one follow up question when it comes to like, it's probably more relevant for Greenfield, but could be for upgrades as well, is how are people sizing whatever hardware the management domain is gonna run on to, to make way for all the appliances? Is there good guidance out there for after they decided what kind of design they're gonna use? You need this much CPU, this much ram and this much, much storage for those appliances to, to ensure that they're future-proofed, I guess you could say?
Yeah, we're working on a sizing calculator guide to be a little bit more, um, clear on what you're required. Um, used to, you know, to get out of the gate you would want at least 32 CPUs in a box because the automation appliances now do 24 virtual CPUs and they won't power on if you don't have more than 24. So we're seeing a lot of customers having to look at their CPU accounts and say, okay, do, can I run the new automation appliances at, you know, 24 virtual CPUs?
Um, so that's a big one. Storage wise, we're about the same around the storage per se. The Aria Lifecycle Suite Lifecycle Manager is the same size as the fleet operations, uh, manager.
So they're the same size, so it's just a replacement. Now the key that you have to keep in mind there is, is that we're not deleting the old. So like if you're running a lifecycle manager from Aria still, it'll stay around until you're ready to delete it and you might not be ready for a while to delete it because it still might have logs, logs in it.
It still might have the IDM in it. It can still have automation in it that you choose not to go to nine with. So you have to keep that in mind and account for another appliance for that.
And then you just need to account for the S-S-O-V-C-F SSOs. But auto operation sizes, we stayed the same When it comes to sizing of operations, those did not change size wise or CPU memory wise. Um, we just increased the numbers of objects and metrics.
And then the collectors themselves, they're a little bigger than they used to be. I think I looked at it as four by 16 now for a standard, um, size, and that is the other one I count for. You only get one of those out the box when you install from Greenfield.
So if you wanna have more than one, then you would wanna count for that as part of your hardware adjustments. And I know you said you're working on a calculator in the meantime, I assume all those figures are in the docs somewhere on, on the Broadcom site and we're, you would have to pull em out individually from multiple articles like, operations need this and the sex managers need that and, and, and do the math myself. Well, we're, we're working on it.
So I think you guys have probably seen the old planning and prep doc that was originally for five. Hopefully you guys have seen that, that has some of the numbers in it. Um, and accounts for some of the numbers.
What we're trying to do for future releases roadmap is build that into the product itself so you don't have to go somewhere else. But right now, I think it's in a couple places, but it is something I've taken offline with my leadership that says we need a couple, one place to put all these sizes so people have one place to look when they want to go find out what they're gonna have to deploy. Yeah.
So it is on my list to do. Yeah. So, so it's still like this, you need to spend a lot of time in, uh, an Excel sheet before you start doing anything.
We we're trying to also take that spreadsheet in future releases and getting it back into the product. So the goal is that as we get further down the road, you won't have to have external resources to do any of this. We'll have our sizing in the, in, in the installer or in a location.
We'll have our IP requirements somewhere. We'll have it all within the product. So you just log into the product, the product tells you everything that is the goal, but we're just not there yet.
So we still have the PMP if you want to use the P mp, but it's a lot less. It used to be like, I think 26 tabs. I think now it's down to like five tabs.
So they, they've changed it a lot. So hopefully this was helpful and useful.