Techstrong TV – September 25, 2024
Watch our live stream on Monday, Tuesday and Thursday weekly, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hi, everyone. Happy Wednesday, a Fire Sale at Intel. Who would've thought, what's the future of software engineering jobs in this AI era?
Speaking of ai, will AI force the platform engineering issue? Finally, you are watching Text Drunk Gang. Hi everyone, it's Alan Shival here at Techstrong.
Welcome to another edition of Techstrong Gang, our daily show where we talk about, well, quite frankly, whatever we find interesting. Um, and we've got a few interesting topics to talk about today. We've got a great bunch of folks here for our assembled gang.
Let me, uh, introduce our gang members for today. First of all, joining us from Charlotte. She is a, uh, literal Swiss Army knife for developers and ops and DevOps, and everything in between Cloud.
It's our friend Hope Lynch. Hey, hope Welcome. Hi, Alan.
Thank you for having me here today. You know, I am, uh, very interested in our topics that we have along Oh, you, and you always have good stuff to say about 'em, so thank you. Thank you.
Speaking Of good stuff to say, say about them. We're happy to be joined by our resident Futurum DevOps app Dev Analyst. I don't know if I got that right exactly, but nevertheless, it's Paul Nadi.
Paul, why don't you set it straight with, did I, did I have that right, Alan? Great to be here. Great to be here with the team.
Uh, yeah. No, I'm practice, lead, um, practice, uh, lead for the, uh, app dev practice at future. Yep.
Perfect. Joining Hope. And Paul at my side here in Boca Raton, at least for a few more days until the playoffs begin in the Yankees are on their way to theirs.
29th World Championship going and only Mike Ard. Hey, Mike, how are you looking Forward to Being? I hope I didn't jinx us.
I'm looking forward to being in El, in El Bronx. In, in the Bronx. In the Bronx.
All right. Um, so guys, I I, I let it off all kinds of stories flying around with Intel for sale. I don't know if they're for sale, if it's solicited unsolicited, but you know, when there's smoke, there's fire.
But is it a fire sale? Um, you know, uh, first there was a lot of stories out there about Qualcomm, which, you know, you could see that kind of makes sense, right? I guess.
Um, but now the big thing is, you know, the PE vultures and sharks are a circle, and, and there's money being banged, you know, tossed around 5 billion, 6 billion. Look, that's not gonna buy Intel. But Mike, what do you think?
I think there's a lot of drama here. I haven't seen this kinda show since, you know, barbarians at the gate for HBO, it starts. Yeah, remember that?
Be like that. Pretty cool. Yeah.
I think it's just gonna be this, like this for months to come. And I don't think Apollo, uh, the management company is gonna necessarily buy Intel for 6 billion, to your point. But they did chip in to build a manufacturing plant in Ireland with Intel for the next wave.
It almost seems to me. And then I thought also the biggest thing that happened was that Intel talked about co-designing an AI chip with Amazon. I think that ultimately that's what they're gonna become, is more of a designer shop, and what they're moving towards is the manufacturing side of that is gonna be outsourced to a lot of different companies that may have been former parts of Intel.
And we're gonna see this be a trend. We already see it in, most of the chips are designed by somebody else in manufactured in Taiwan. So I think they're moving to more of that arm model, and they just got caught on the back end of it, a little bit too slow.
The number that troubled me most was 2 billion in cash flow for a bus business that needs 10 billion to run minimum. So, you know, there was some concern here about how sustainable intel is, and that's where that fire sale conversation is coming from. So designed in California by Apple is, that's their model.
Yeah. So I, I, I agree. I, you know, the, the story is that they're gonna spin the fab business out as a separate unit.
I don't know if it's gonna be a totally independent entity, but it's certainly a separate unit. And then, so you'll have a design and then a, a fab, you know, businesses under the umbrella. Um, I, you know, Paul, hope, let me let you guys weigh in here before I weigh in with my thoughts on it.
Sure, absolutely. Um, you know, I think when we look at Intel, there's a lot of concern and challenges that are happening within the, the market. Um, you know, and I think Intel has kind of fallen short on, on expectations.
Um, there is a lot of, you know, desire to kind of, you know, regain that market share that they had, right? And this influx of money is driving kind of towards that goal. Of course, we're seeing that as an opportunity to, to help drive Intel's value up.
Um, but I'll speak, um, Mike, what you were talking about, uh, you know, with regards to where the company is pivoting, um, in, in my world, I'm less about the infrastructure in that, in the chip set, but more about the software side of the business. And, um, when I, when I think about, um, you know, Intel's software business, right? I think about the, you know, the, the, the products that they have to offer, which, you know, whether it's the Open Vno toolkit or the open source projects, or the, or the one API runtime, you know, I, I think about what they're, what they're, uh, trying to achieve, right?
And when, when I look at my research and I see that 20% of respondents and our latest app dev research indicate that application portability is critical to their organizations across infrastructures, across environments, across, uh, you know, locations and such. And 67% of respondents indicated that's very important to them. I think that the, um, the one API strategy that Intel is driving towards is really going to help accelerate what Mike was going after, right?
Which is build faster, accelerate that API kind of delivery across different environments. And the, you know, when we look at Intel one, API, the, the DPC plus plus and C plus plus compiler, it really does provide the developers with the ability to be more portable as well as, you know, rely on their existing and future gpu, uh, seek BU and, and AI accelerators to kind of help drive towards that unified approach. Um, you know, we, we see that 48% of developers are, are developing in a heterogeneous environment across CPUs, GPUs, and, and, and like for ai um, applications.
This is an area where a unified architecture is really helping to drive that, that, you know, a, a approach. I think that's where Intel is going to help grow. And even if it, um, kind of spins this part of the business off to the side and kind of runs it as an independent business, it's really gonna help drive that, uh, that AI adoption more of a software front.
I think Intel has always kind of missed that software boat. Um, and they do it again, right? You see Nvidia pushing cuda, and that kinda locks everybody into their GPU stack.
Um, Intel has that one API, but they never really came around and said, there's a couple of open source alternatives to Cuda, and the Intel doesn't seem to be driving that very hard. And, uh, it's almost like they become too reactionary and they're always on their heels. Very, very much so.
And the point that you just raised that I think is, is applying the pressure and also probably nudging the interest of, of companies like Qualcomm and the Apollo group, right? They're seeing what's happening with Nvidia, and can we get any, any of that, even if it's third place or fourth place, right? Um, maybe a little bit of a turnaround story because, uh, Intel, um, you know, they fall on hard times a bit.
They are also having some financial challenges, uh, as you said, uh, they're still competing with Samsung and TSMC, uh, for chip manufacturing. So they, they, they need something, something has to take hold, whether it is an investment or a buyout, um, yeah, they, they need a savior. So let me give you the shimmy take on this, okay?
First of all, as it relates to the Intel software stack. Very nice. Paul, I appreciate the metrics you, you cited there, but I don't think literally the proverbial flea on the elephant or pimple on the elephant in, in terms of the Intel business.
Let's be clear, we're all of an age here. Well, Paul, hope, Paul, hope you're the youngest here, but, of course, but you know, Mike and I are of an age where Intel is chips, Intel, you know, it was the Wintel empire growing up for me, or not growing up. But, you know, in my, in my career, it's always been the Wintel Empire.
And now, of course, Apple's in there. But Intel is an American institution. It's a strategic asset of the United States of America.
And yes, we are all GPU crazed right now. And so if you don't have a GPU story, you know, it's, it's kind of like with the data center business went in when cloud exploded. If you don't have a cloud story, who the heck's gonna need a data center?
You know, so that you came up with a private cloud and all that, and it's taken almost 20 years for the data centers now to become what, you know, invaluable. They get right at a premium. I, I don't think Intel is ready to be, have their bones picked over yet.
And I think the folks at Barron's are smart, and that's why they're making this deal, right? Because the Wheel of Karma goes round and round, and it's a b***h and g this current GPU craze and one company having, you know, 98% market share on GPUs isn't gonna last forever. So do you think quality is quality?
Do you think They have time? That's the question. Yes.
I, 'cause I think, I think between the money they get from CHIPS Act, and will they get bought, perhaps, will they take in equity stakes from outside people? Yes. I'm surprised I don't see Warren Buffet at their door right here, because it is a typical buffet, right?
Buy low, buy low, sell high. That's what Apollo's doing. They're already partnered with them.
Let them take another 6 billion stake for very favorable terms, because when that wheel goes round, they're gonna be sitting in the catbird seed with it, and that investment's gonna pay off handsomely. Alan, I would, I would, uh, I would echo, you know, just to, just to be clear on my statements, I agree with you a thousand percent. I mean, the software business at Intel is a small little, you know, yeah.
Almost se to their business, right? Uh, but, but with that said, there's enough effort there, there's enough initiative there to either spin that off its own initiative, uh, you know, maybe even create a sub-business out of it, uh, that would, you know, that would kind of help drive that unification across, uh, heterogeneous environments. Uh, until no doubt it's a ship company.
It is a, it is a, uh, company that's built on hardware, and that's where their heritage is, and that's where they're going to be moving forward. Uh, the question is, is are they going to evolve with the times? And, and that's a, that's a big, big question right Now.
I think that the difference too, is what N NVIDIA's up to is they understand that GPUs may not last forever. So they're building a software stack that is a credible part of their business. I think when Wintel was coming along, Intel was overly dependent upon Microsoft.
And Microsoft woke up one day and said, oh, by the way, we can use all these other processors to run Windows. And Intel's been kinda like trying to figure out what their next great thing is ever since, in my opinion. I I don't disagree with that.
They missed, they certainly missed the arm, the arm race. Mm-Hmm. Uh, that being said, look, this recent deal with Amazon to design, uh, uh, AI chips, these kinds of things, being, no matter what happens in this election coming up, I think the, the path is clear.
We want manufacturing here in the us. We don't wanna wake up one day and our beepers are blowing up, and our walkie-talkies and Intel stands to be the biggest beneficiary of the CHIPS Act, and of the billions of dollars that have been set aside to, to kickstart technology manufacturing here. So do you think Pat Gelsinger over at Intel should get out the Lee a Coca playbook and start saying, you know, I need a bailout from the US to, I, I think in essence, that's what the CHIP act may wind up being for Intel.
But they need, you know, a, you need a KOA lead follow, get out of the way person for this. But number two, you need something you had to hang your hat on. The AI chip with Amazon could be something, the separate fabrication where, you know, we're, we're manufacturing chips for Qualcomm and whoever else, Qualcomm, stop having your chips manufactured in China.
Have them done here by Intel. Um, I, I think the US government can force the issue of devices here in the US need to be manufactured here in the us. So, and, and I'm a free trade kind of person, but I think that's where we're headed.
Couple Of weeks ago, the head of the Department of Commerce, United States government sent that very message to folks and said, you know, we would appreciate it, suggestion if you would use the Intel fabs, but I don't know if anybody else got the memo. I, I think there's gotta be a stick behind that. But I, I do think, look, we spoke about it, uh, in Monday's show, I, I guess was when we discussed the Lebanon situation.
This is a, a, a clarion call to supply chains throughout the world. If you don't have complete control of your supply chain, and if your supply chain is a, is a, uh, critical infrastructure of your national interest, you're making a big mistake and you're looking for trouble. And I think that is what's coming out of what we spoke about Monday, and that's what can save Intel.
You heard it here first. Are we, are we betting that Intel gets acquired, or do we think Intel continues as a standalone company? That's a good, good question.
Hope, what do you think? I, I just feel acquisition is, it just feels farfetched to me, right? Um, if I were coming in with a bag of money, and especially if this is not a business I've been in before, right?
I, I want to prop them up, support them, make sure I get my investment back by some multiple, right? But if I go in and now I'm taking it over and I'm making all of it my problem, that is a completely different proposition. All right.
My next question, who's making the movie Netflix or HBO Barbarian's at the gate? Two? Yeah, I, you know, in today's world, it could be any number, it could be Paramount, assuming they're still in business, they don't get bought or, uh, or Prime Amazon.
Who, who that? Well, I, I don't think Amazon can do it or Apple. 'cause they're gonna be in the movie.
So that could, yeah, This is a third shoe, Paul, but I, I, I, Paul, you think standalone or acquisition? I think it's gonna re Intel. I have to reinvent itself.
I mean, there's definitely, uh, change and changes are coming. Uh, I have no question. I think the investors for, you know, to, to hope's point, I mean, if there's investment in the company and an influx of money, it's gonna reinvent itself to a way that we probably don't, won't recognize Intel in the next five, 10 years.
I think if PAC comes in and changes it to more of a, uh, uh, adapting towards the market needs and the market growth that's happening, and the change in AI that's happening, look, we're seeing across the board in this, in the software development side, that new tech stacks are being put in place like such, for example, web assembly, that's harmonizing the underlying architecture. Doesn't matter if it's a MD intel arm, doesn't matter. You're running it on a, a, a web assembly, a web application in 2022.
I would've thought that was an Intel. I look at it and go, not an issue in 2023 when they started incorporating, you know, multithreaded ness and, and, and, uh, dot net applications in, um, in, in web assembly changes the dynamic. And it's, I think that type of technology is going to make the infrastructure invisible.
And the, the, the chip sets are not going to matter moving forward as long as they can produce the results they need to support the, the business logic above. I, you know, I, I don't disagree, but it, but, but hardware does matter. I think that's the last end of the last year or two.
Look at Nvidia and, and I'll give you another dark horse with Intel Dell Maybe. Anyway, I, I'm gonna vote for investment. I'm voting, you're voting investment too.
'cause creating another monopoly is a bad idea. Absolutely. And we need strong US based companies here.
I like to see Dell invest. Let Michael write a check. Uh, August note though, I, I've gotta tell you, um, I'm, I'm trying to line up Daniel, Daniel Newman at fu who obviously covers the, uh, chip market is always on CNBC.
And those, hopefully we'll have something maybe tomorrow from Daniel and his take on it. But for now, let's take a break. That's enough on Intel.
We're gonna come back and talk about a small thing like the future of software engineering jobs. You're watching Text Day In a world where every line of code powers the future, every keystroke can introduce new thread. A software evolves so must security, it's time to rethink how we protect our digital world.
Join the leaders in DevSecOps and AI at the OpenText DevSecOps Virtual Summit on September 24th. Discover how innovation is transforming software delivery faster, more secure and smarter from AI driven security to the truth behind cloud security. Get the insights that will keep you ahead of the curve.
Don't just watch the future unfold. Be part of it. Register now and secure your place in tomorrow's world.
All right, folks, we're back, and the folks over at the Wall Street Journal wrote an article saying that, well, the number of software engineering jobs are down significantly, at least in terms of listings. And that's not a surprise given the current state of the economy, but what it is to be a software engineer is changing. And that's a big question.
And it's not clear to us whether or not it's the economy or whether or not people are trying to figure out what a software engineer is before they go higher, the next wave because of the, in the introduction of AI into all these workflows. Um, hope, I know you're close to this whole subject, let's start with you. But, um, what do you think is going on here in this job market, and what are you hearing from folks in terms of, well, what are they looking for for software engineers?
Yeah, there's definitely some recalibration happening. Uh, partly because everyone is looking for an AI skillset. So if you are an engineer with an AI skillset, you know, ML ops, AI ops, uh, maybe you have some DA data engineering skills, um, that can go along with it, you probably are still somewhat in demand.
But for other engineers, other software engineers, especially those that are very, very entry level, um, they are being automated and AIed, uh, to the side because automation is taking care of a lot of the repetitive things. Um, those tasks that don't require as much creative thought and deep thinking. AI is coming along and, and, and scooping those away as well.
So, um, I, I think though, I think there will be somewhat of a comeback, however, because we are still at such an early stage of what organizations are realizing they can do with ai, and I am saying beyond generative ai, I think it's, it's awakened people's imagination and helped them start to investigate AI more. And the things that the engineers will do, some of those things have been there for years, uh, possibly even for decades. But they've, uh, enterprises just have not shown that deep of an interest, but now it's, it's a little easier to approach.
I think they're gonna shift more roles in that direction. Paul. Yeah, you know, look, I mean, I, I, I agree with a lot of what hope said, but let me add a different perspective.
Um, I think that this article and the media in general, this is just another case of the media over emphasizing looking for click vapor. Hey, you gotta jump on, read my article, right? I mean, look, this is, this is throughout my entire career and all of our careers, we've had a natural herding of the, you know, culling of the herd.
Uh, you know, that happens within organizations to kind of restructure retool re refocus on things. But I'll throw some data out there just because I, I, it kind of aligns to what hope was saying, also aligns to where the market's going. There's definitely an interest for, you know, uh, uh, re software engineers that understand AI tool sets.
No question. But what we're seeing in our research is, uh, 67% of organizations are looking to hire it gen, uh, it generalists over specialists moving forward. And the reason behind that is because they, one, that the skill gap issue is a real thing.
They can't find people that know how to do the, the job. S uh, second, what they're doing is they're pushing the level of complexity back to vendors. They're saying, vendors, you need to solve this problem, and our generalists can do the deployments.
So the role of the software engineer is not going away. The role of the software engineer is, is, you know, is is going to continue to go move forward. The generalist approach is from our data is really where organizations are hiring.
Um, they're looking at that because one, they're available, and two, they're pushing that complexity back on the vendors to fix it. Now, hope brought up a good point. The, this tool set of tech stack has been available for a long time.
Automation has been, it's not new, right? This is something that's been available for a long time and organizations haven't been able to capitalize on it. Now, there's an incredible push right now to, uh, incorporate automation into those, uh, call a tedious or redundant tasks to focus more on innovation than focus on maintenance.
In fact, I'm, I run a trending study every year, and not surprisingly, over the last five years, we've seen a third of software developers spend their time on innovation. And 66% of their time is spent on maintenance. Organizations need to move away from that, especially those organizations that heavily rely on their software to generate revenue for their business.
They need to continuously innovate, right? And so utilizing automation and AI tech stacks in order to get you there, that's how you're gonna, uh, move to more towards that, uh, innovation versus, uh, maintenance mode. But that's where I think it's going.
I mean, this is not, again, I, I don't, I never, well, I don't look at the media as a, a source of truth at all because it's just about, you know, let me click on my article and read it. It's, it's the top headline to catch it. But other than that, it's, uh, it's really about what natural attrition that's happening within, within organizations.
I think that they needed to look a little deeper into this, right? So are the number of software engineering jobs down yes. Or are the most of those jobs that are down probably from tech companies?
Absolutely. Um, we put together every Monday, uh, list called the five great DevOps Job Opportunities. And we put this together every weekend, and we look at this thing, and what you see in there, if you kind of pok in the data a little bit, and the listings, is that the number of jobs for traditional enterprises for software engineers, they're still looking hard and heavy for those folks.
And they would happily take, um, some of the folks who have worked for tech companies, but those jobs are not in San Francisco and the Bay Area. They're in places like New York and North Carolina and Texas, and even here in Florida. So I think people who are software engineers may have to look beyond their current regional areas.
And I think that's a big part of what's going on in this whole analysis. Um, and also if you look at it, um, one of the things that is apparent is the number of people applying for jobs on LinkedIn for software engineers is up. So you might have seen back in a couple of months ago, maybe, you know, the listing would say, 25 people have applied for this.
Now it's like, well, a hundred people have applied for that. So there's definitely more people applying for those jobs, but I'm not seeing, um, the num the demand for software engineering decline outside of the core tech sector. Yeah, and one of, one of the other points that I, I think is, is valid here as well, um, over the course of my career in technology, I, I have seen, you know, salaries start out somewhat normalized, and then, you know, they really inflated.
And now a lot of those salaries seem to be settling back down to earth, uh, a bit. So when you have software engineers who were, uh, at FANG or in, in that rarefied air somewhat, and now there are layoffs and they are looking for roles, most of those people are going to go toward the same roles that have those higher salary requirements. So there are organizations who are struggling to find software developers because the salaries that they will pay, maybe they're in middle America, maybe they are somewhere in rural North Carolina, um, are not going to be, uh, the salaries of those tech centers.
So that has to play out somehow, uh, as well. Yeah, we're, well, we're okay. I, I agree with both what, what you said and what Mike was talking about, but you know, I take companies like, and I'm just gonna throw a company out there not, um, endorsing or not or saying anything.
I take a company like Oracle, right? Oracle in the Northeast and the New York, Connecticut area had six different offices pre covid. They have zero offices now in the Northeast, right?
And all of the employees in the northeast. That doesn't mean the employees are not in the northeast, they just work from home, right? So we are, we have to get rid of this mindset of all the, all the innovation and software engineering are, is, is out of California or out of a specific region.
It is a global effort now. And you know, if we're, if we're around the, you know, the, this just call it domestically around the states, those jobs are available. Those skills are available regardless if you're in rural North Carolina or you're in the valley, those jobs are there, and you can get them done remotely.
Because look at companies like Oracle that are doing this, right? Um, and most companies are, I'm, I'm a believer. I am, believe me, I am absolutely a believer.
Um, I am, I am one of those people's, no borders, let anyone work where they want. But, uh, whether it's a small sample size or a large, there are still people who say, I looked at this remote role, but I must live in a certain state. Um, even in that state, maybe I can only live in certain cities.
Then I will go to ler comment about normalization or harmonization of salaries. Yes. If, if some, if a position, if somebody was blessed to have a job that was paying an ex, you know, a huge salary and that job then went away, they have to have realistic expectations of what that role was being.
True. Very true. That's hard.
It's hard. So I have some thoughts on this one too, just a few. Just a few.
First of all, in my entire career, there's never been a technology innovation that didn't end up creating net, net plus new jobs. And I think the same is gonna be true for this AI thing. Let's not make it the AI boogeyman that's killing all the jobs.
Number two, I think as much as, you know, those, those Oracle jobs, Paul, those were salespeople. 'cause it was e it was great being an Oracle sales guy in New York. You made a million bucks a year.
And, and now not having to go to the office and do it from home and, you know, take, go into Wall Street once a week or into Manhattan. It's a great day. There weren't, there weren't people sweat shopping in Oracle software development hubs on Madison Avenue or something, you know, those were sales jobs.
Um, I do think we are seeing a great rebound of companies saying, Hey, you gotta come into the office. Amazon's done it. Dell has said you could stay home, you'll just never get a promotion, right?
But otherwise, come in the office, people are coming back to offices. I will tell you, as a CEO, I think people working from home, unless they're a very responsible person in the exception, rather than the rule, your organization is much more efficient working in the office together. The, the communication, there's a lot of reasons, but it's much better.
That being said, I think the future is this, we probably have 27, 30 million developers in the world today heading to 40 million or so in 10 years. I think in 15 years though, with the advent of ai, we're gonna have 500 million developers. I think everybody's gonna be, every software engineer will be a developer because it takes nothing, it'll, it will take very low.
There's a very low barrier bar to entry to develop software when AI can write it for you. Excuse me. But that's gonna create other opportunities.
Some of them are obvious and some of them are not so obvious for a lot of jobs around software engineering. And that's why I like that. We call it software engineering.
And not just development, whether it's ops or something else, there is necessity is the mother of invention. And there's gonna be a ton of opportunities here. So don't, you know, don't throw away your computer science degrees just yet and go take pharmacy or something.
Um, there's, you know, there's gonna be a lot of opportunity. And a thing I've always learned, and I was told this as a, as a young man, smart people find opportunity in every nook and cranny. And, and there will be opportunities here.
So don't discourage, don't despair, but I don't know if I'd live in rural North Carolina. Good. I think I, that was a good way to end that.
Yeah. And you know, who knows there might be software engineering hubs in the Bronx now because, well, we can do, There probably is. There probably is.
I've heard we Will see Uhhuh. All right, we're gonna take a break here on Textron Gang, and we're coming back with our last block, which is will AI force the platform engineering issue? I feel a disturbance in the force.
Mike, you're watching Textron gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. All right, folks, well, coming off that last conversation, we aren't gonna talk a little bit about, well, what impact will AI have on software engineering? We've heard about the rise of platform engineering and trouble with platform engineering is you asked 12 people what it means, and you'll get 15 explanations.
So, um, one of the issues though that's pretty clear is that it's getting more complex to develop software in the sense that there are lots of AI models that people are using and there's different kinds of them, and you have to manage which one to use at what particular point. It's not just gen ai, there's causal ai, there's predictive ai, and all these things go into software development now. So hope, I love to get your insight here, but is, on the one hand, it's easier to build software, but managing the whole process seems like it might get more complex as I have all these different AI agents that I'm using for different tasks.
Agreed. Um, platform engineering to the rescue. So, uh, platform engineering definitely can help by using a lot of the same tools that platform engineering already uses.
Um, bringing in some standardization, uh, having a standardized framework to manage the operational complexity that comes along with AI systems, how to integrate the development and operations to AI in a way that is scalable and also sustainable. Because AI does not live by itself, uh, on an island. It has to be part of, um, the SDLC has to be part of the workflow, has to be part of the way this is and work gets done.
So platform engineering definitely will be a critical enabler for this. And making sure that organizations aren't just overwhelmed and overrun, overrun by the complexity that's going to be part of it. Paul, you wanna weigh in here a little bit.
What are you seeing in terms of what does the software engineer of the future need to be? And, um, there was an article, somebody was interviewing Kelsey Hightower, who, you know, came to fame as a result of his work in Google and Kubernetes, and he was just saying, ignore Gen AI for now until we see what it becomes and what we become. Yeah, well I, you know, I mean, I think I'll echo a lot of what folk was talking about.
When we look at the, at the, uh, the CICD pipeline and across, say, zero day one to day two, build, release and operations, anything that touches with the SDLC, uh, it needs to be optimized and have, uh, operational efficiencies in order to get the code out the door. I mean, business KPIs are trying to push bus push code out the door very rapidly. And in fact, we see in our research that 24% of organizations wanna push code out the door on an hourly basis, yet only 8% are able to do so.
And part of the reason they they do that is because they don't have these operational efficiencies within their CICD pipeline. The other fact is we see that there's an incredible boost of applications being created, far more applications, 50 to a hundred percent more applications being created now than just three years ago with the same or fewer resources. So in order to continue to grow and continue to build this momentum of what businesses business KPIs are driving for these software developers to create these applications, they're going to need to use the appropriate tech stacks in order to do so.
Gen a, gen ai and natural language and, and ways to, uh, you know, drive and build your code is a tool, it's a tool to make it faster. I mean, you can use a hand screwdriver and screw the screw into the wall, you can use a drill, right? Um, I think gen AI is the drill, right?
And if you have to release code faster, if you have to create those applications faster with fewer resources, you need to be more optimized to do so. And I think that's where the AI trend is going to kind of help push this out. You know, if you look at the article that we're, they're in our notes for this block.
It's about, you know, you've got 150 different models. How, how do you, how do you herd those cats? And then you mentioned you ask people what, uh, platform engineering is, you get a bunch of answers, here's what it is.
And, and you can diverge where you'd like, but at the end of the day, it's setting up a platform with guardrails so that we could go faster in development. Much like if you've ever driven a, a, a, been on like a Mag L train or a high speed train, well, not here in the US but in China, right? There's guardrails, this thing goes on, and it, and those guardrails, you know, help guide the chain and allow it to achieve, you know, 200 mile an hour speeds.
To me, that's what platform engineering does here. And there's no reason why we can't use AI to help us with those platform engineering guardrails. But once those guardrails are in place, and it may mean cutting back from the 150 different models in production and standardization on certain models, but once they're in place, we, you know, we should be high speed bullet trains in terms of, uh, development and, and software engineering.
It should allow us to go faster with less friction. And I, I think that's always been the goal before a, before AI during AI and, you know, anything that comes in the future. And again, smart platform engineers, just like smart people everywhere will harness AI to make that better and doable.
Well Hope. Do you think the platforms that we have in place today are gonna be extensible enough to manage all these models? Or do we need to kind of go back into the whole stack and say, we gotta modernize this thing?
'cause we have, you know, to your point about guardrails, I was just reading this article about EVs are so heavy that they're blowing right through the guardrails we have. And we might have to replace every guardrail that's on the highway because we have all these EV vehicles now. Mm-hmm.
Is DevOps gonna have the same kind of experience where the CICD platform that was built and deployed 5, 6, 7, 8 years ago wasn't designed for this? Oh, I definitely see innovation coming. Um, two things I think that are going to really force, force this issue even more.
Um, one security and compliance, uh, massive amounts of sensitive data potentially being run through, uh, some of the models, maybe now prime targets for some security vulnera vulnerabilities, challenges with compliance. Uh, this is going to be so complex. Different models handling different data sources, um, that have varying levels of sensitivity, all maybe converging to a single application.
So platform engineering will have to figure out, uh, how are we going to offer the built in security protocols and the automation? We're we need to manage identity, we need to manage access control, we need to manage data governance across all of these. And hopefully most of this is automated.
That is not something that can be managed team by team and ensure that your enterprise is, is meeting the standard, but also, uh, monitoring and observability for AI models. AI models. I think that is going to be so crucial.
And we already know a lot about monitoring and observability, but now what do we need to monitor and look for in production environments, uh, for these, uh, now are we also looking at, uh, drift bias degradation over time? Uh, platform engineering will have to take another look at the toolkit and, and see what has to be done. Yeah.
Hope, the, the interesting, I, I'm glad you brought up the monitoring and observability piece. One of the things that kind of comes to mind very quickly is in our research we see that, um, 75% of respondents indicate that they use six to 15 different observability tools to understand what's going on within their environment, yet they're only monitoring and observing 54% of their high valued application. So they're not even looking at their entire environment, right?
So they're using this complex environment with all these tools and it, it doesn't make it easy, right? Not to mention that they have to put the underlying tech stack in place in order to run what they're trying to build. So there's definitely an evolution coming.
There's definitely a, a kind of a, I would call it a unification of the management side of it as well as a unification of the tech stack to get it to, to get it done. Yeah, I think there's gonna be, in the average enterprise, three years out, thousands of these AI models running around, they're getting smaller and more domain specific, and that's awesome. They're gonna be better and smarter, but the management and the orchestration and the degradation of these platforms is gonna be a huge headache.
I, I think that's why you gotta set up guardrails. But I smell opportunity. I'm the optimist.
I'm that little boy who looks in that room and says there's a pony there somewhere. I could smell it. Um, anyway, I think this is a good time to call a wrap on this version of Textron Gang.
I hope you at home have enjoyed, uh, today's, uh, today's show. I had a lot of fun. I hope Mike and Paul and hope you guys did too.
It was, and you know, these are gonna be themes I think in stories we're gonna be coming back to. But for now, I'll point you, we have a tech field day live going on today, I think following this that people will be able to join in on as well as our whole tech trunk TV lineup. So stay tuned for that and we'll be back here tomorrow with another great tech drunk gag.
But until then, is Alan Shimmel for Techstrong. And we're out. This is Textron tv.
Hi everyone. Alan Shival here for Techron tv. I've got a first time person on Textron with me today.
His name is Francis Cordone. Francis is the chief customer Officer for a company named Causley. I don't believe we featured them before either.
So let's welcome him and, and find out more about, uh, Francis and Causley. Hi Francis, how are you? Hi.
I am good Alan. Thank you for having me. How are you today?
Very well, thank you. So Francis, let's start with you. Tell us a little bit about you.
Excellent, thank you. So, yes, um, it started in the nineties really with the pioneers of application performance management, dating myself here a little bit, but I think that's within a small company called me Interactive that ended up creating a lot of the concepts we use today. And it was bought many years later by hp.
By Hp. Yes, I remember I was, that's when I started in the, I was an engineer by, by training. And then that's when I started working in the performance management and monitoring space and then moved to United States with, I am originally from Spain.
Mm-Hmm. Moved to United States with a company called Compuware. And then I moved to Dynatrace where it was very, very small that was there about seven years building this company that today is so well known.
And then I did something that changed everything in my career after so many years being a vendor, thinking I understood customers, I became a customer. I went on to run application reliability for the Bank of New York Mellon as centralized team for 12 lines of business. And Alan, that was incredible.
O opened my mind first week two, our outage, 200 million penalty. Talk about PagerDuty and the cost of outages. I think we're talking about a timeless problem that only keeps getting worse because of the complexity of these dependencies.
And then I went on to become a vendor again because I had a passion in my heart to do it well, to take a lot those learnings that I had doing it in high stakes environment. So constantly is, is from the ground up built to do this. And I couldn't be happier to be in an environment that allows me to use both my vendor and my customer experience to bring that to the table.
Excellent. Let's talk about cosley then. Give us, give us the, uh, scoop there.
Yeah, very good. So if you think about the history, I love to go, I don't know, Alan, maybe with age it happens, but it starts like everything is related to history. I like explaining things by their history.
Okay. And if you think about the phase we went through in the world of obligation, performance management and then observability, it, it was for so many years about further levels of visibility. Give me more data, give me more data.
Oh, we don't have the ability to instrument Java. Give me Java. We don't have the ability to instrument that net.
Gimme the net. And of course network and server. And now containers constantly takes a step back and says, alright, with so much data, the problem we're having now is the fatigue with so much data, too many dashboards.
But who is telling you when something happens and you have 300 things going on, who is telling you which one is the root cause and which are symptoms? And if you think about it, the model, even with sophisticated solutions and as the uh, owner of resiliency and reliability at the Bank of New York, I had to spend millions in vendors. And they were good, they did their work, but they didn't do this single thing.
Differentiate root causes from symptoms, the cause and effect relationship wasn't there. So costly bills from the ground up to use data that more often than not is already there. And let's give that to the software to tell you root cause analysis and hopefully later we'll talk about that's not only reactive, that can also be proactive.
It has about three levels of maturity, but essentially that's costly and built from the ground up to do this with what we call our causal reasoning platform. Alright, I love that. Now, so let, let's dive in a, you know, let's dive in a little deeper there, Francis.
First of all, when we talk about the rising cost of incident response, there's really two pieces of it. Number one is the cost of incidents period. As you mentioned when you were back New York, me, $200 million, it's a fair amount of money, right?
It's A lot of For outages. So incidents, downtime, cost, businesses, money. So minimizing downtime is a huge priority.
But the second piece of it is a lot of companies say, okay, we need incident response software that allows us to minimize this. But it's not just buying software or signing up for a SaaS service. It's truly the implementation of that, of of using it, adopting it, living it, breathing with it that you then find out can cost a lot of money and not necessarily solve your problem.
Exactly right. So when we talk about causally helping with the rising cost of incident response, well we're almost causal reasoning software, you know, as defined by causley solving the rising cost of incident response. What costs are we talking about?
Excellent. I love how you framed that. So if you don't mind, I'll tackle maybe two or three key things you've mentioned there and develop them a little bit in the context of costly and how it can help the cost.
As the PagerDuty article refers to the cost, and to be honest, the, they mentioned, uh, a number of like 175 minutes on average. We actually, in conversations know in many cases is a lot more than that, uh, and with multiple people involved. But the cost is something that even organizations struggle with because more often than not that cost is the operational expense of the people that will be involved.
But there is a lot more cost in the part that's difficult to calculate. What about the customers right there, right then that we're having a poor experience and they may jump out of your platform and go somewhere else. That causes a lot more serious the, the the damage to the brand.
Uh, and then what we are missing in this too is engineers that now get involved systematically to do this because of the decentralization of the reliability practice and the complexity. So engineers jump on these are also not doing their innovation work creating and that's ultimately what puts a company ahead of the competitors that they're innovating faster. Especially in this time.
The cost is a lot more than the number of hours or minutes, but what's going on with that? This is also why a costly, I like to partner with customers to establish the language of value, which is a lot related to what you mentioned of how is it implemented, right? How do we talk about these things and how do we integrate in the processes?
At the end of the day, what we're trying to do is let people do their work, innovate, create faster cycles of releases that put a company, you can put a company ahead of the competition. That's the most important. Not to mention attrition of employees.
The engineers are called to be engineers 'cause they like to create not troubleshoot. And that's a whole shift. However, the model today remains give data to experts to do troubleshooting and maybe instead of three hours, they take an hour and a half.
But why do we have to give it to experts that could be doing, doing creativity or innovation? So that's your first point. But then here's something very important to, to your second point, even innovation.
'cause if you read the PagerDuty, it's almost the impact of not having automation. They keep referring to the cost of manual troubleshooting, manual, manual. But I can see people reading that and jumping too soon to oh yeah, we need innovation.
But my question I ask almost as a challenge for everyone out there to think about, to learn from a best practices standpoint, how can you automate when you don't know, which is a root cause versus a symptom? In other words, in any complex environment today, you're going to have hundreds of symptoms when something serious happens because of the ripple effect, the services dependency, the components and innovation, which is also something that has to be done for the standpoint of integrating with systems, systems, et cetera, is actually not what we're looking for until we know which of these created the problem. Because if not, we're looking at like taking an aspirate when I have a headache without understanding if I have a headache every day, maybe there's a bigger reason and I should see a doctor about it.
It may be a simple example, but when I was at the bank, this was a daily life like just restarted. We were so panicky about that because we couldn't determine without that tremendous spend of money and time what was the root cost. So yes to the cost of manual, but to do it well, what we need first is to think costly, to understand what's the root cause.
And everyone today they can open an LLM on their phone. We have access to these incredible technologies. They're very good at correlation.
They're not that good at causality. This is something technologies barely now starting to do. Well, we are so good at having petabytes of data, but at best to establish correlation between them.
And so I love the PagerDuty article because it, it gives a visibility into I must if I am running a, uh, IT operations and organization, I know I must automate instead of relying on manual troubleshooting. But to do that, well you have to have causality because that's what's going to tell you when you automate this, then it goes ahead and prevents those issues and fixes the problem. And you talk about implementation.
If I can throw one more then my, my passion is to work with organizations to say, when you've done done that, which is already ahead of the curve, who is doing causality in their current environment for current fires, to eliminate them at the root cause. And then you put aish, but let's take it further Now if you can see that, or if you have a system like costly that can tell you that relationship of root concept and effect, even for issues that haven't happened yet, then couldn't you start building resiliently and that's the implementation you're referring to. After we work a little on those fires, let's move it left, let's integrate into the workflows, into the processes, and let's start building things that don't break to begin with.
So we don't accept that broken model in it. Operations of things have to break and hopefully we're in a race to not take too long to fix them. That wouldn't work with my car.
I don't wanna accept a model which the, the KPI is that they, the mechanics take little time in fixing it. I don't want the car to break. And that's the journey we're on with costly and a partnership with our customers.
And I would argue an organization out there that's thinking about this maturely, let's learn to build resiliently so things don't break to begin with. And of course it's complex in in the current environment. So, and, and I don't, let me run this by and you tell me, you know, today we're all looking at how could ai, right, how can AI help us go faster, cheaper, better?
Um, and AI is very good at correlation, right? Whether we're talking about an ML ops, AI ops kind of thing, or even generator of AI and LLMs, it's, it's very good at correlation by taking, you know, big data sets and boiling that down is partial reasoning beyond today's ai. Yeah, excellent question.
It is a different take definitely because LLMs or gen AI isn't really, uh, it's forte isn't really thinking cause in, in a, in a cause and effect RELAT cost. No. So I'll tell you a little bit about it and in general, and then also as it relate, relates to what approach costly had.
But also with ai, I have the feeling that we're leaving this explosion of methodologies that in truth will be many, many, many, many, many tools. AI is almost like many years ago, say agile, it's just an umbrella of many practices. But at the end of the day, people care about the getting the job done and what technology we use only now because it's such a, a novelty.
But in reality what we need is to get it done, get the job done effectively. And for that we made to combine multiple tools. So thinking costly.
And there is a scientific, uh, branch called, uh, causal ai. And it applies to medicine, it applies to it, it it has and it thinks a little different than LLMs or gene ai. What it is, is causal models and it has to capture knowledge that has existed.
If you think about message brokers, if you think about, uh, HDP calls, RPC calls, Java obligations, all Kubernetes, all not these things have a footprint. These things have a way of behaving in relationship to each other and it gets beyond human scale because of the dependencies. But this can be expressed in SAL language and when we put that together, we call that a SAL model.
And when we instantiate that with the topology of an organization and maintain it in real time, which is obviously very difficult to do, and that's the approach we take, then we have effectively a model that's constantly applying causality to your environment as it's alive. And that would not work with LLM, but LLM would be really good to help you as a side, um, assistant in other things. For example, summarize for me what happened in the incident yesterday that would be perfect.
Learn from my logs how many times that would per but not to tell you causality when it's happening and preventively for that. We need a different technology in the greater sense of the world way of doing things. And that's what we do with our al reasoning is causal models and environments that are instantiated and maintained.
Excellent. You know, we're almost outta time Francis. I didn't even ask you for people who wanna find out more about Coly.
What's the website? Yes, the website is costly io and uh, we have there, That's hold on, that's C-A-U-S-E-L-Y io Io. Very good, very good.
And yes, I encourage people to go there. We're actually really transparent there. People can see the description of essentially how we operate this description of our sal models and causal reasoning.
And also people can there see the platform in action through videos and a sound guided tour, and then contact us to learn more. So I encourage people to go there and check it out. Excellent.
Francis, thanks for coming on and, and, uh, educating us here a little bit. Success. Wishing you a good success with Causley and keep us posted.
Alan, I'm such a big fan of your work, so I was so honored to be here. Thank you so very much for having It's My pleasure. Francis Gordon, chief Customer Officer at Causley here on Techstrong tv.
That's causley io. We're gonna take a break. We have a lot more here on Textron TV today.
Stay tuned. This is Textron tv. Hi everyone, it's Alan Shimmel and we're back.
Day one Swamp up in Austin. Uh, our next guest is Ms. Shing Chu.
And I think I got that right. Perfect. Perfect.
Shing is with a company called CommScope. She's speaking here today. We're gonna talk about what she's speaking about and a few other things.
But before we get to that sh Yes. Share with our audience a little bit of your own personal story. What's your role at CommScope?
How'd you get there? And maybe not everyone here knows CommScope. What, what's CommScope about?
CommScope is a device manufacturer. Uh, we making different, uh, electronic devices, full service providers and make people to connect to the infrastructure and getting their services. So for that kind of equipment security is, is the very important part.
Otherwise, you are not only mess up your consumer side, you're also mess up your network side. So my role and my background, so my background is in security. I've been in security field for more than 25 years.
Me too. Oh great. Yeah, We didn't, we didn't call it Cyber Z in Five sec.
So what I talking about here then you understand. So, um, my, um, I, with start a background, I've been doing security for 25 years and I'm leading a product marketing and a product security solutions within CommScope. So my team is developed security, uh, services platform for our product team also.
They are customers and our customers. So you are responsible for internal security as well as External Security, external for customer security Because they're buying our equipment, they're putting the equipment in the network. So any problem they are, problem is our problem.
It's your problem too. And you know, I mean, talk about, you know, a hot topic in security these days, supply chain security. Absolutely.
A lot of people talk about software, supply chain security, but hardware, supply chain security is a whole nother problem. So there are two security supply chain here. So one is a software supply chain.
You are absolutely correct. The other one, manufacturing supply chain. So both are so critical in a way, you know, because it's manufacturing supply chain is more like a high volume environment.
The hackers will focus on those high volume environment because with a single attack they can breach the, the all other devices. Devices. So that's one thing that's important.
Software supply chain is also important because the hardware become commodity and the software become differentiated today. So a lot of people putting a lot of functionality inside the software, how do you protect those? Become very important aspect of the ecosystem.
Got it. Yeah. Got it, got it.
So one thing before we jump into what you're talking about. Yes. For people who want to get more information about CommScope Yes.
It's COMM Two, M's. S-C-O-P-E do com. Com.
Absolutely. So CommScope com com if you're interested. Yes.
Alright, Shing, let's move over. Now you are actually a JFR partner slash customer, Correct? You are speaking here at swapa.
Uh, yes. The people, you know, the people watching this are not here. Yes, yes.
So give them an idea. What are you, what are you presenting on? Okay, So for everybody who was in, um, you know, in this field, probably they know what we're talking about, but a lot of people, they're not in this field and maybe like audience, like today they, uh, they being in the morning keynote section and, uh, you hear so many things about the security, you wanna talk about productivity, you talk about the accountability.
So what I'm going to talk about the tomorrow is the trustworthiness. How do we bring the trustworthiness to a next level, to a higher level to enhance the level in the software supply chain? And I'm going to review our collaborative work with, uh, uh, J Frock, how do we are talking, you know, to, uh, bring this amazing platform to next level to facing the most aggressive attacks we see every day now.
So I hope everybody will be coming to my session. I'm going to show you how do you bring that in? Software integrity to a different level against the most aggressive attacks.
Love it. I love that. Yeah.
Alright, I've got a few questions for you Absolutely. From our friends at jfr. Yes.
I wanted to Yes. Go over a bit. Um, so let's talk specifically, how do you and your team interact with the jfr platform?
Okay. CommScope is a bigger company. We have many different product solutions.
They're using different platform manage the software. For my team, we are focused on the security side. Our collaboration with the jfr is how do we provide a solution that the easy to plug into the jfr, uh, platform, make that seamless, uh, workflow with, enhance the security.
That's what my group does. So we are going to demo what we have this, you know, proof of concept tomorrow. And then two, like not only our internal team who will using the Jfr platform, all your customers, JFR customers today and the future, they will be taking advantage of our capability.
Got it. Um, so when you first adopted jfr Yes. What were some of the, like, what were the drivers, what were the problems that you were facing that said we need to use Jfr?
Well, I have to say, you know, JFR today, even though I had an even deeper understanding through the today's keynote, I think it's a promise. A promise of different capabilities and consolidated in this one platform. A lot of organizations, you may not have all the expertise you have, even for mostly elite companies, but there are so many different product teams.
They're living in their silos. You know, we talk about the silos in the keynotes. They're living in their silos.
They will not have all the skills they have, so they don't have a consistency in terms of deal with the software supply chain. So I think even this platform, especially for some medium size or small size company, they don't have the expertise. We're talking about it here.
You can kind of consolidate the most, you know, the latest technology and the machine learning in the security into, you know, uh, a lot of core technologies, you know, a, a company cannot afford to have. So I think that's the thing values I see that can bring people to next level. Got it.
Yes. Let me, uh, let me ask you, in your use of the Jfr platform Yeah. What KPI, how do you know it's working, right?
What are the KPIs you point to, to say, oh, we're seeing value here? Yeah, I would see why is productivity, you know, the other one you have to, you know, we, what we see the is the visibility every step of way. You have the evidence now with the government mandates and some in mostly, you know, industries, uh, initiatives that become very important.
And you have to have a visibility. You have to be able to provide the evidence. You have to show how you do security and to do it right.
To not just go through the flow. Right. So I think that that's important aspect though.
KPI I'm looking for. I I agree with you. And look, we're seeing more and more come out here in the US with like Seaside Yeah.
And stuff like that. Yeah. But in the EU as well.
Yeah. Around the world. Yeah.
Around the world. Yeah. Where do you think j the Jfr platform has delivered the, the biggest bang for the buck?
The biggest impact, The biggest, the impact pack. I have to say the collection of the capability is the overall, um, capability. Also the forward thinking.
You know, JFR already in the latest, the technology, right. The, for the, uh, generative ai. So you need to count on somebody, be able to keep you up to the, the, the, the most front end of the technology.
So I think today, especially with all the keynotes I learned, and for the future things to come, I think that this is the company with a lot of features. Agreed. I agree with you.
Is this your first swamp up? It's my first, uh, uh, swamp up is my staff. It's the second swamp up.
Are they come you? I haven't but this time it's Only day one. But what have your impression been so far?
It's a lot of energy here. A lot of energy. A lot of energy.
I have to say. It's a lot of cool stuff here. And I hear a lot of people talking about the latest, the technology.
Yeah. So, which make people excited. Yes.
Gets your passion going. Yes. Right?
Yes. Yes. Shane, thank you so much for coming on.
I tell you, thank you. A this goes very quickly. Well, Thank you so much.
Good luck. Good luck with your presentation. Thank you.
Chu here at Swamp Up. That's gonna wrap up our day one coverage. Stay tuned.
com and cloud native now, security Boulevard, text Drunk ai, text drunk itsm, and of course here on Text Drunk tv. But for now, I'm Alan Shimmel and we're out. Hello and welcome to the Leadership Insights podcast.
I'm Amanda Ani. I'm excited to be here today with Kevin Kramer. He's the founder and CEO of Sapio Sciences.
How are you doing today? I'm great, Amanda. It's a pleasure to be here.
Thanks for having me. Happy to have you on our show. Can you first share a little bit about SIO Sciences and what services do you provide?
SIO is, um, a lab informatics, uh, software provider. So we, we currently offer solutions around, um, what are called limbs, laboratory information management systems, and also electronic lab notebooks, also known as ELNs. Um, we also offer Jarvis, which is a, uh, uh, scientific data management, uh, in the cloud, uh, system.
Wonderful. Well, that leads us to our topic of the day, which is AI and machine learning in life sciences and drug discovery. And SIO sciences recently announced the general availability of the world's first AI power lab assistant.
So can you share a little bit more about that? Sure. Um, actually SIO got started as a machine learning company.
Actually, a lot of people don't know that. All the way back in 2004, uh, we were using, uh, machine learning to analyze genetic data. And back then we were using what we called genetic algorithms.
And, uh, you know, we were way too ahead of the game at that point to, you know, get any real traction. 'cause the market just wasn't ready for it, I think. Um, but we're, we're in a new era now, very exciting era, uh, you see have been paying attention.
There's some pretty significant breakthroughs that have happened with, uh, these large language models from chat GPT and anthropic and Meta, et cetera. So it makes sense to leverage these to fulfill our mission. Our as our mission is really to accelerate drug discovery and to support this.
And we do that by supporting the science and the scientists. So how, how are you gonna support the science and the scientists? Well, uh, usually when people think about AI and life sciences, they're thinking about, or I say pretty grandiose things where the, the AI is designing drugs, you know, and doing everything.
And I think someday we'll get there, but we're not there yet. But what can we do in the meanwhile to help the scientists do their job better? So, um, the AI models are actually quite good at understanding natural language.
So English, right, or whatever language you're speaking in, they're quite good at understanding your intent and what you're asking. So what we wanted to do was several things. One is to bridge natural language into our product.
So, and there's several ways we do that. One is, um, we already had a really powerful way to search for data in the system. So people were putting a lot of data in the system organized, uh, usually in hierarchy of data, and they wanna find things.
And we have the ability to build out a search, um, inside our product. And I think we have the best in class search. But we thought, well, why not make it even easier?
And let them just use natural language. So you can say, show me all the DNA samples I created this year. And you can ask like that and it'll build a search for you behind the scenes and run it and you get back to your data.
So this is a, you know, something that helps the scientists find data where rapidly that they wanna work with in the system. Also, we, you know, in our electronic lab notebook, Amanda, we, we, um, build out experiments and scientists will build out experiments. This could be kind of a clicky, you know, process where they're adding entries in, into a notebook.
It's basically, if you're familiar with the ELN in the old days, in fact, some labs still do this. They use paper notebooks. They actually are writing in, I did this, I did this, I'm experimenting with this.
This is my objective, et cetera. So this is an electronic representation of that. And again, in order to make it less tedious for them, we put a natural language front end on that.
So they can give a protocol to a lane for some experiment, and it will actually build out the experiment for them. And this is pretty amazing if you think about it. It's quite, these experiments can be quite varied, complicated, have many different elements in them.
So the fact that we can do any, any portion of this is pretty amazing. So the, that we can take protocol and just say, build experiment, um, even complicated plates, I don't know if you know what plates are, but these are things they use in the lab. Um, and they can be set up in a kind of complicated way.
It'll just handle that and all through natural language. So you don't have to know the details of how to set things up. The system will just take care of it for you based on your natural language request.
Um, other things we're getting into that I think will be even move the needle more is, um, uh, I'll call it age agentic ai, where you're are, um, a scientist is asking a scientific question. And the, the language models often don't know the answer to those things. But there's many tools out there that do have the answer.
So you can connect these tools to the AI to our system, such that when the scientist asks a question about like a molecule or a large, a large or small molecule, it figures out if there's a tool that can help answer the question, it calls the tool directly and then gets an answer back and gives that to the scientist. So this is pretty exciting, the idea that we can do these, um, agentic, uh, where you're calling it agent, essentially, which is an external tool, but making the, uh, interface for the scientists natural language. So they just ask in a, what's very natural to us, as you and I are speaking right now in natural language and we understand each other and these language files are very good understanding language to take that, uh, ask a scientific question, have this thing go do the work for you and just give you the results back.
Um, we have that as well in Elaine. And then we have other things in terms of, uh, answering questions about how to do things in the product. That's all backed by a lane as well.
So it's, it's, uh, pretty exciting. And I think there'll be bigger developments coming down the road, but these are things we're doing right now at, These are very interesting use cases. So you're speeding up processes, you're simplifying them, making them more organized, efficient, all very impactful.
Do you have any particular company, Jo Journeys, that you'd be able to share with us that, um, they've achieved something through this technology? Well, we just came out of beta only, uh, recently. So it's been, uh, experimenting with people using it up till now.
So we'll look forward to having some hard metrics on it. Um, but it's not hard to see how, you know, if you don't have to click or type a lot or, uh, you know, be navigating around the product or not even knowing how to do things. Um, if, if you could just use natural language as the interface, and I think this is a big thing.
I'll think a lot of things will become natural language interface in the future, including your phone. I think a big advance would be mobile phones would just be, you have all your apps on there, but you won't actually interact with the app directly in the future. I think you'll just ask your phone something, it'll figure out what app to use.
This is kind of an agentic type of process as I just described, inside of our system. Um, and by the way, we also support, I should say, with ai, uh, voice. So you can actually talk to the system.
So you can talk, you don't even have to type. You talk. It types it out for you.
You say it looks good, say go. And it'll take, take the action for you. So this is a major productivity booster and also gets people to do things in the product they might not do otherwise.
'cause they may find it too tedious to try to figure out how to search the data or what have you. It, it, it, uh, opens up a lot of capabilities for them that, uh, in our product just by making it easy for them working in a, a paradigm we're all used to, which is natural language. So I imagine you have some big plans with this technology.
Looking toward the future, say a year from now, how do you think this will impact the enterprise? Well, I think that, uh, the, the big thing we wanna do now looking forward is build out these, uh, agents and have a lot of pre-wired agents in the product. So things that are particular to life scientists, uh, around small, large molecules, so that there's a lot of tools that are already connected into a link.
So you just, again, work at natural language and we have a bunch of these baked in to the product. So it, it can just call and do basically think of it like a scientific assistant. I think this is where we need to head.
So we're not gonna replace the scientists, but increase their productivity substantially. We see this internally, whether it's from marketing to support to our delivery team, ai, uh, to our coders. Um, AI has been a significant performance boost, uh, because it just accelerates things that you, that used to be tedious and hard.
Now it's making 'em fast and easy and often higher quality, uh, as well. So I think not just in life sciences, but in all domains, AI is a significant accelerant of, of a productivity and discovery. There's big things that are happening too, like around protein design and, uh, things that are more nitty gritty science.
And we incorporate these into our products when they become available so that scientists can leverage those as well through natural language. With all the advancements in this technology. And, and with your product you're putting out, we talk about what you mentioned at the beginning, these, uh, big drug discoveries and, and, uh, solutions.
Do you think that eventually we'll see cures to some of the, the bigger diseases, uh, much more quickly than we would've imagined? Wow, this is the thing, Amanda, that gets me up seven days a week and sitting in this office, um, is the, is to, to do that. I think that we are at an inflection point, not just with ai, but just in technology in general.
We have CRISPR gene editing now. We have cell and gene therapy. We have, uh, antibody drug discovery pipelines that are quite robust.
There's a lot of amazing stuff that's happened on the lab science side, um, on biology and chemistry fronts that give a lot of potential therapeutics now. Um, and I think AI will help us understand them better and get to them quicker. When we talk to the employees of PO and we talk about the importance of the work that our customers are doing and how we're supporting them, you know, we know that the, to get a drug to market, it's basically a 10 year process, roughly starting from ground zero.
That's crazy, right? It's very long. But even if we, let's say through our technology, we say three months, it, it think of how many lives and how it's suffering.
You can reduce in three months. Um, if someone has cancer and you're getting a cure three months sooner or six months sooner, or a year sooner, of course, we, I think there'll be much bigger chunks taken out of these timelines actually, um, this decade. Um, but we think in increments right now, being able to save months can save lives, reduce suffering, you know, there's a financial benefit for the companies as well.
I like to focus on the human benefit or animal benefit or environmental benefits, um, that are important. And, and of course, people need to have, make money and pay their employees on, I get it. But really the whole idea of a PO is trying to support these, these, uh, technologies to accelerate getting 'em to market faster.
So the world's just a better place for all of us to live in and healthier and happier. Uh, anything we can do to help, that is what we're gonna do. Absolutely.
And that would be amazing. So if there's one key takeaway you could leave with our audience today, what would that be? I think people should be thinking big, um, and thinking outside the box.
I think we do that here. I, uh, at our SIO Khan conference, uh, earlier this year, we're gonna have one again in, in Fort Lauderdale in, uh, February. I said that sio, we lead and we follow.
So we, we lead in the sense that we are doing things that no one thought of with ai. No one thought of the things we're doing, they always were thinking of something different. Um, but I think the things we're thinking about are probably years, years away yet.
Um, but what can we do today? So we were leading on that front, but at the same time, we follow, we listen to our customers and say, how can we use technology to help you do your job better, faster, smarter? And I think people should think big now, um, about what's possible.
Because I think the new technologies that we have in the lab and in silico in software are really game changing. When I started coming in 2004, we were doing machine learning. Those things were cool and interesting, but now we've got amazing, incredible technology, and it's not slowing down.
It's going much faster. So I think that people are Still thinking in linear terms. They think of progression as a linear line.
Um, and they're, with the technology we're at now, it's more of a, it's an exponential. So things are accelerating, so it goes up much faster. It's not linear anymore.
It's gonna go up much faster. So the capabilities are gonna go, um, ex become exponentially better. So if you already have a technology like we do that's using large languish models, when the new models come out and they're said 10 times better than once today, we automatically already benefit.
We don't have to do anything more. We've already done the hard work to work with the models and use them in the right way. So when they get smarter and better, then uh, we benefit immediately right away.
You just drop in the new model and automatically you get smart, you're smarter. So I think that people should be already putting in place, um, the foundations to use these models, particularly around data. We see a big problem that pharma with data, they don't have a handle on their data.
Their data spread around a hundred different systems. And these models need data. They need data to train, to learn, to learn how to do things.
And their data is a massive asset that they have that's underutilized. So we're helping on that front too, to pre-wire things to get the data together and then feed it into models to make them smarter for them to do their chemistry or biology work, um, to, to get drugs to the market faster. So I think people should be getting a handle on their data now in preparation for working with models, uh, in the new now and in the near future.
All right. Well, thank you for sharing your insights with us today. It Was my pleasure.
Thank you for, uh, taking the time to have me. All right. And thank you to our audience.
Stay tuned. There's more. This is Textron tv.
Hey guys, thanks for the throw. We're here with NAHAD Kasami, who's director of engineering for Amazon Q for developer, and we're talking about a, the latest edition of it, and b, some new code transformation capabilities that they've been adding as well. Neha, welcome to the show.
Great, thank you. Happy to be here, Mike, and thanks for the opportunity. Um, I, as you said, I am the director of engineering for Amazon Q developer, and, um, I'll be talking about, uh, some of the new agent capabilities that we recently launched.
So yeah, go ahead, level, Set us a little bit for those who haven't been following everything, but, um, the original agents just came out not too long ago and they've been out there. What's been the reception like so far before we jump into the latest version? Yeah, we've, uh, seen a lot of excitement over all, uh, q develop or just around the overall q developer product, which includes the agent as well.
Um, specifically for Q developer are coding, uh, acceptance rates are the highest, uh, recorded in the industry. And we've seen, uh, as high as 50% acceptance rate from some of our customers, which has been great, uh, very delightful for us to see, uh, on the agents part, uh, specifically on the Q code transformation agent, uh, internally, we have seen some pretty dramatic success. Uh, and d Jassy recently posted about it, um, that by using Amazon q uh, code transformation agent, we have been able to upgrade our internal pipelines from Java eight or 11 to Java 17, uh, which just saved us like 4,500 years in terms of just development years.
That, that's a pretty big statistic. And that, that's been a huge success story for us internally. And, um, on the queue agent for software development, which I will talk about in a lot more detail, uh, we were already at the top of, uh, the SWE bench, uh, leaderboard.
And with all the things that we've been, um, iterating on with that agent, there's a bunch of new improvements that have come to that one. So all in all, uh, just very positive feedback on overall queue developer and also just the agent bit. We've seen some real results, right?
So what's the latest and greatest, what have you added in this release? This release? Yeah, so we launched the first iteration of this agent, um, you know, with our GA product.
And in May we, uh, had a blog post about it. At that time, we were top of the leaderboard for SWE Bench. SWE Bench has dataset, which basically has a Python code for a lot of just, uh, common coding problems, uh, that, uh, people solve for.
Uh, this particular version of the agent has a lot of advancements, uh, compared to the previous ones. Uh, notable ones being, first of all, like a much more powerful model behind it. Uh, the world of models is moving really quickly, so just four months, uh, it, a lot of advancement has happened there.
Uh, but it's not just about using, uh, the best model available. It's, there's a lot of intelligence and, uh, tooling that's built around the model that this agent has. And that's where we have invested a lot of our time.
Uh, to be more specific, um, we have the, this particular agent is able to explore a lot more coding parts. So he tries and explores multiple parts, sees what is working, what is not working. It is even able to backtrack and take a different path.
And that sort of intelligence is something that we worked on through a series of experiments in the last four months. Um, I think the approach we took with this one was just to see if you are a senior developer and you're trying to learn a new language and you are in a new code base, how would you approach the problem? So a lot of the agent is mimicking that particular workflow.
So the agent takes a goal, you can talk to it in natural language and give it a prompt to say, Hey, I want to implement, let's say, a shopping card, uh, for an e-commerce website. So it will take that prompt. The more specific the prompt is, the better it is, uh, the better guidance it receives, or the better results you will get.
But what it does is, just like the engineer would do it scans the code base, it looks for, Hey, which files do I need to modify within those files? What methods do I need to touch? And it will generate the updated code for that as a human, as the engineer who's using the agent, you get to see the, uh, diffs within, within your IDE, and you can, uh, accept those if they look fine, but at, at that point, you can also give the feedback to the agent.
So that, that was the second piece of what we, um, developed in the agent, is the ability to take feedback. Previous version did that too, but this one, I think we just made a lot more advancement in how that feedback is incorporated and then used for the next step. So it takes that feedback, it will generate a strategy, again, as I said, explore multiple parts and pick the one that it thinks is the best and shows the results back to the developer.
Um, I think, um, a few other things I would say, which power this agent, we actually came up with a text representation of the code, which I thought was a very interesting way in which where, uh, team members work is like, if you're a human, uh, engineer who's looking at code, I think a lot of it is, uh, visually you look at the code, different repositories files and those repositories, and your brain is processing those lines. What we did here for the agents to actually take the code we in, we came up with a format, which is, uh, text code. And, uh, as the name says, it basically takes the code and, uh, explains it as text to the agent.
So it, it's an intermediate, uh, layer that we developed, but that's how we communicate the code to the agent, and it takes that and then determines which parts to take. Uh, so that's been, uh, one pretty big breakthrough that we achieved in this version. And some of the other things we developed.
Um, we make sure the agent doesn't get stuck. That's, that's one thing, um, that we were experiencing is you can get stuck in analysis paralysis, even as a developer. So again, taking the same analogy, how do we make sure the agent doesn't get stuck?
So there's some very specific checks and guardrails put in place to make sure it's not getting stuck. And, um, there is a concept, uh, of, uh, agents using tools that is becoming, uh, a lot more popular and mainstream. So this agent, our software development agent, has these tools at is disposal, uh, which make the code that is generating a lot more accurate.
And these tools are, uh, simple tools, like it has the ability to open files, select files, uh, close files, even like, uh, run some basic checks, uh, tests. So I think in our future versions, you'll say expansion of these tools, but in this version from, based on just where we were the previous iteration, there's just lot more tools that the agent has now in its tune kit that it is using to just get better results. So overall, some of the behind the scenes things going on, but the net result is, uh, just 51% more tasks.
It is completing on the, again, the SWE bench dataset, um, the verified one, and on the full one it's, uh, 43% more. Do you think as we go along that more organizations are gonna stay current on their code base? Because let's take Java for example.
There's people running on Java eight, still 12 and all kinds of versions, and they don't upgrade it because, well, it's just heavy lifting and they got other things to do, but then we discover that, you know, that older code has more vulnerabilities in it, and then we're surprised when bad things happen. So can we, um, get everybody to stay on the latest and greatest version of something? Yes, I think that's, uh, where a lot of the advancement in AI will really help the developer workflow.
Like any, any team of developers, I feel like it'll be much easier for them to stay current, uh, because a lot of the work can now be done with these agents. Like I was talking about the core transformation agent that is part of QI mean, these are some real results that we achieved that basically you, we have a pretty big repository here internally, and we, uh, had the agent run on like 30,000 pipelines internally and take the old Java e Java 11 code and upgraded it, uh, to the new version. And I think that's just, um, going to become part of, uh, you know, the maintenance or the upgrades, the part of, uh, the team that performs the various functions.
I feel like, uh, a lot of these agents is going to be very helpful for that team. Are we also gonna convert applications in one language to another language? We have a lot of application modernization projects out there.
People are running everything from COBOL to whatever it may be. Um, is it worth actually converting to a different language, or are we just gonna stay within our language lanes as it were? Uh, no, I, I do believe agents are going to expand and, uh, the language translation, which are very natural next step to just the, uh, version upgrades.
The other thing that comes to mind is, we hear a lot about agent AI these days, and there are these agents. I think we're gonna have multiple agents that are trained on specific tasks and domains. But, um, how do we orchestrate all those different agents that are doing those tasks?
Is there some sort of central command and control for all the agents? How does that work? Yeah, I think at very interesting times, uh, in the top, in just the Asia architecture.
Uh, I don't think the agent architecture itself is brand new. I mean, we've had agents in the AI world for a while, but I think what has happened is with the, uh, what the LLMs have done and the tooling around that, it's just become a little, uh, easier for us to have way more advanced. So yes, I think individual agents will become experts in a certain domain, and you will need like a system, uh, an orchestration system, which is really all the job of that orchestration system is to make these agents run in the most efficient way and the most effective way.
So the orchestrator is essentially deciding when to pick which agent to run, uh, how do the agents talk to each other? So I think those kind of workflows are becoming easier to build, and the power of each of these agents is just only going to increase. Um, I was talking about the tools.
Uh, a big part of agent workflows are the tools that these agents are able to use. So how to use these tools to make their output better. I, I think we will see a lot more advancement there.
I feel like we're still in the first innings of all this. And one of the things that people are talking about is we're using these tools to generate more lines of code, but it's not necessarily resulting in better and more applications being developed because, well, we don't quite have the workflows as fully automated as we might. Um, what is your sense of where are we on this journey?
I think the developers are thrilled, but the people will hire, the developers are scratching their heads going, well, how come we're not getting more software out faster? Uh, I think that that's an interesting question. Uh, we do have some real, uh, data from our customers that, that who have said their developers are like up to 50% more productive.
That's how they have measured the developer productivity as a result of these, um, AI advancements, uh, that we've seen. Um, I think it is only going to get better. We are just starting in this journey.
Uh, today I think it's available with these coding assistant and agents are available in certain, um, ides today. The next step I see is integration with workflows that teams have built over time. And as soon as that integration starts, I think the power of these agents just becomes more real.
So I think in the next two years, we are going to see a pretty dramatic, uh, change in the landscape as far as SDLC is concerned. Mm-Hmm. And part of that, it seems that the LLMs themselves, the reasoning engines are getting smarter and that may manifest itself in time and, um, better, um, a series of tasks can be completed by an agent in a, in a, in a more natural fashion.
Is that a fair assessment? Uh, I would say yes and no. I, I think the reasoning model getting more powerful is going to allow the agent to do, um, tasks a broad set of tasks really well.
But I think more intelligent agents will likely be using, like, you, you'll have to do more work on top of the model to make it specialized. And when you talk about the quality of work improving, it has, it will be a lot more than just the model itself. Hmm.
Um, as you kind of think through this whole thing, um, what does the future of an application development team look like? It's starting to feel like, to me it's a mix of humans and agents that are kinda working hand in glove or hand in machine glove or whatever you might wanna say. But, um, you know, how should we be thinking about what is the role of the developer?
What does the machine do? And, and how does all this come together? Yeah, I think it's an exciting time in the life of a developer at this.
Uh, I would see that. And, uh, I, I think a lot of the, uh, undifferentiated work that developers have to do today, uh, like think to upgrade cases, the classic example, or modernizing the code base. I, I think agents and AI are going to be very helpful for the developers for that kind of, uh, undifferentiated work.
So I think developers are going to really spend their time on higher value tasks, and I think they will become the guide for some of these agents. So they, they still have a very important role to play, which is to teach these agents. Uh, they become teachers and guides to say, this makes sense, this doesn't make sense.
Uh, but I think it, it's pretty, uh, it pretty exciting that they, this is where they will be spending a lot more of their time. Um, I think just the developers who are at entry level coming out of college are more used to these assistance, um, than the previous batch that came. And, um, I think they, they wrap up, I expect would increase, uh, and be productive much faster.
And I think they'll be able to just do much higher value tasks sooner. Mm-Hmm. Um, they say that we might be producing more software in the next few years than we have in the last decade, and the whole rate of development is gonna dramatically accelerate.
And I wonder, are we approaching a point where maybe we're creating software faster than the business could absorb? I think we'll be surprised. I think businesses win catch up.
And, uh, I, I think to me it's like the past. We produce the software, the past, we will enable the business to run, and it's just, uh, going to be a flywheel that, that's my prediction. All right, folks.
You heard it here. It's gonna be a lot more fun to build software, that's for sure. And remember, the whole purpose of building software is to solve problems.
So let's go solve more problems. Hey Mia, thanks for being on the show. Thank you for having me, Mike.
All right. And back to you guys in the studio. I am Bonnie Schneider, sustainability contributor to the Techstrong Group.
I'm excited to introduce you to a groundbreaking new initiative from Techstrong Research, the sustainability pulse meter. The Pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry. Position your company as a leader in the industry and differentiate from your competitors with a sustainability pulse meter offered exclusively from Techstrong Research.
Hi everyone, and welcome to the first ever episode of our new series, uh, from The Source, I am your presenter, uh, I, Turner Field, CTO, uh, here at Sonotype, and our other presenter. Hi, I am Brian Fox, co-founder, CTO at, at Sonotype. So, uh, from The Source is intended to be a biweekly, uh, show where we'll, uh, focus on our, uh, special domain, uh, software, the area of software, supply chain management, and all the intricacies, uh, intricacies of that.
In each episode, what we're going to do is dive into key topics. That includes the latest regulatory updates, best practices for maintaining, uh, open source compliance, as well as emerging threats, outpost, my malware, and anything really that kind of affects, uh, the life of developers, organizations, DevSecOps professionals, uh, when it comes to our, uh, software supply chain management, uh, overall. So, uh, Brian, I'm super excited.
Yeah, likewise. I think, um, there's, there's, there's a lot to learn in this space. So you've had some examples of some recent, uh, malicious types of attacks that, uh, that, uh, happened this summer.
Do you want to just give the high level on that? Yeah, absolutely. Um, so what's been happening, uh, happening over on the, uh, JavaScript ecosystem, MPN is that over the summer we've observed huge amount of, uh, spam entering that ecosystem.
And what's behind that Skip spam is actually really, really interesting. So, so these are essentially packages, uh, that are being designed to look like real open source. Um, they're downloaded by each other.
They're, they're sort of bot networks that also stimulate the downloads. And when you crack open the lid and you start looking at these packages, they're kind of nonsensical names. They're kind of, uh, kind of, uh, you know, published in an automated and sort of, uh, flood like fashion.
You know, thousands of them pop up every single day. Um, what ends up, uh, ends up actually being behind it, is that, uh, is that, um, uh, somewhere along the, uh, year, there was a new pro crypto protocol that was announced called t uh, XYZ, uh, to be precise. And it's called some pretty legitimate backers behind it.
Actually, one of the people that invented Home Brew, uh, if you're a Mac user, um, you know, many of us, uh, have used that, uh, baggage management system. And, um, what they did was, uh, they published a protocol that aims to reward open source contributors. They aim to aim to, essentially, every time you publish an open source package, you introduce a little token in it.
And, um, and now that token is monitored by sort of the crypto network. And, you know, the intention was that if your package becomes really popular, then you get rewarded with a little bit of cryptocurrency. The idea is, hey, you know, we should compensate our open source maintainers better now, of course, this being the realm of software, we can't have nice things.
So pretty soon after that, uh, was, uh, published, um, you know, bad actors basically overtook that, uh, logic and started just publishing outright spam and then manipulating the targets, uh, manipulating the, uh, downloads of those packages altogether. So basically they, they, uh, download them from the internet, uh, kind of overinflate the numbers, and that obviously stimulates paybacks, uh, for the developers. So, over the summer, I think, you know, Brian gave me honest here, we've seen, uh, you know, hundreds of thousands of these sort of appear.
And I think I read from somewhere that actually most of the newly published practices over the summer in NPM were basically just spam, you know, that was related to this sort of, uh, the Cook Concentrated campaign. Yeah. So I think the, the, the, the fact that this is happening highlights a, a, a major flaw in the, the supply chain.
Like you said, the motivation in this particular case was for somebody to, to game the system and get some more payout, to make a bunch of pretend packages look like they're really popular, more popular than real things, and therefore basically steal effectively some of these donations. But I think in order to really understand how we got here, I think we have to take a, a, a bunch of steps of that. Um, you know, so if, if we, if we think about how software is developed these days, right?
It, you know, when I started, uh, a long time ago, you know, we sat down and see, um, and, uh, and, and, you know, started at void, main void and you know, wrote all of our code from there, um, open source came along and, and early days, a lot of the open source pieces, especially if you were looking to include capabilities into software, you're developing, not not open source in like Firefox or Apache, HCBD, where you just wanted to use the software, but like you actually needed a class file or some functionality Yeah. Like curses to, uh, highlight your terminal or something. Yeah, exactly.
And so in those days, you basically had to like, go get the, the source code and you like, would copy and paste it into your software and then massage it and make it work, right? So you were like literally taking a paragraph from a book and putting it into your book. That's how Open Source largely started in terms of like leveraging the capabilities.
Fast forward a little bit, you know, we got to the point where you had whole reusable modules, um, in Java, these would be the jars, right? In, in Windows C world, they were lib files, shared objects, DLLs. And so these were whole compiled pieces of units.
So sticking with the book metaphor, it's like taking a whole chapter and including it wholesale into, into your software, right? And so this made it a lot easier. You didn't have to just cut and paste code.
And also, um, it was easier as those libraries matured and fixed bugs. You just picked up that whole thing and included it. You didn't have to rework the custom code.
Um, and then package managers came along, you know, CPAN for Pearl was a very early one, but then also Maven, uh, one that I've been involved in for, what, 21 years. Wow. It's a lot weird to say that.
Um, um, Apache Maven is a, a, a very popular build system in Java that really modernized some of this dependency management, um, uh, s space, basically. And so what happened there was we were able to publish these open source components into a repository on the internet, along with the metadata that included information about the component, but also that component has dependencies too, right? Yeah.
So these are transit of dependencies. And so these repositories in, in the Maven land, this is what we call Maven Central or the central repository. Turns out Sonatype runs this repository, but other ecosystems followed suit.
You have, um, the pi pi, you have the new get gallery, you have NPM js, um, Ruby, and you know, Docker, Iist, and you know, yeah, right? D Noland and all, all of these other places. Yeah, That's right.
These are, these are the public registries where people can put and share these components. Now, the thing to understand is that most of the interaction with these, these tools, um, you know, you, you add the dependency to your build file somewhere, and the, the tool goes off and it fetches this automatically from the repository. And then in, in many of these cases, it reads the metadata and says, oh, I, I have that thing.
I have to get these 15 other things. Um, and it will do this automatically. Some of those ecosystems, um, that process is actually executing code that's been fetched because they need to be quote unquote installed.
You know, RPM is a very well understood thing. It's a very similar thing to RPM where it's actually installing the software. Yeah.
And in, in security terms, that's, uh, by definition a remote code execution, right? So I think you can start to see where this, this challenge comes from that, you know, did, did you wanna add anything that Ilka? Yeah, I mean, I mean, that's exactly it, isn't it?
It's, um, it's, you know, by design, every single modern software build manager, which is in every single programming language has a, is builtin remote code execution floor. And by design, I really mean, yeah, in most cases, you need to compile, you know, the library to the right environment. You might need to fed some extra components.
You might need to do some massaging, especially, you know, in these sort of AI projects, you often see the libraries are very sensitive to the target environment. You need to have certain drivers and, and things like this. So it all, uh, all kind of works together.
And that in on itself is pretty dangerous because there is usually no developer interaction. There is no, hey, developer, here's the lines of things that are executing. Even if that was printed out, you know, you could certainly put a minus X or something like that on the com command line that makes it sort of, uh, very verbose.
But the issue really is, uh, there's fairly little, you know, that you can do. Once the package installation starts, it will compete, and we assume that the package does legitimate things. Now, sort of another fundamental weakness, uh, to add on to that, that exists sort of within the software supply chain when we talk about dependency management is in the upstream, in these registries.
Um, maybe since was a bit of an exception, we kind of take a slightly different philosophy. Uh, I'm, I'm, I'm sure you know, the, um, uh, people, uh, people, uh, who like to, uh, comment about that will, will forever have a different opinion. But, um, in, um, places like NPM and Python, you know, in many open because there's sort of philosophy of, uh, you know, we have open access, anyone's free to register.
It's done on a fairly, you know, good intended philosophical background. It, it, it promotes, uh, contribution back makes it easy, lowers the barrier of energy. So anyone that's kind of, kind of, uh, can publish a package is very easy to do so.
But the flip side is, in many places, there is no enforcement or control over the namespace of those packages. So that leaves us open to this sort of field of, uh, uh, this sort of one, uh, uh, risk landscape of people, for example, finding a very popular package and then registering a, a sort of typos code at version of it, like changing one letter in the package name. Uh, so instead of requests, which is relat relatively popular, uh, Python package, there's a legitimate malware campaign, uh, that was called, uh, using the package name called request.
So publish a couple versions that make it, you know, fake the read me. It looks perfectly legitimate. And sort of that's combined with the fact that the way that developers actually install these packages in 99% of the cases is they have to type the name out.
It's like typing a name, an ad address onto a postcard, right? So you do MPM install requests or PIP install or, or, or, or whatever, uh, or MBN install. And, and so when a infinite amount, you know, there's tens of millions of developers across the world, they do this sort of, uh, activity on a daily, uh, basis, multiple times a day as well.
Eventually, they are going to make a typo. Uh, and that's really what these two methods of attacks, uh, rely on, you know, in many cases when they, when they're using phishing tactics. So in some ways it's not very different to phishing.
We were kind of talking about this in the pre-show, but, um, you know, sort of all the same gamut, uh, types of vectors, uh, appear, right? People can do targeted phishing. They can do spear phishing against a single person or a single company, or they can go broad base and use it, use it to, um, to, uh, distribute malware.
And they really realized that it's quite an effective method of, uh, releasing malware. So, so, uh, Brian, we actually kind of keep track of, uh, what we're kind of seeing. So o over the last few years, I mean, there's been pretty phenomenal growth in these, uh, types of, uh, attacks as we've seen them.
Yeah, some of the first ones that I, I picked up on and started, you know, on the conference circuit talking about this problem was way back in 2017. Um, and, and you could very quickly see the evolution of the attack vectors as each subsequent, uh, attack kind of built on the things of the, the ones before it. But, um, you know, last year we were at 250,000 known malicious components.
This year it's over 700,000, so it continues to double or more every year. We haven't hit that law of large numbers where the percent of growth tapers off yet. And, and, you know, I take this as evidence that this is working.
You know, it, it's, um, it's working. That's why the attackers keep doing it. Um, some of these attacks are quite significant.
I think we're gonna get into some of the, the different types of attack in a minute. But, you know, it, it, um, the reason why, again, that this is happening is that the industry at large does not have good enough defenses against this. And, you know, we, I've been exploring different metaphors.
You know, if you think about food at a picnic that's left out too long, that gets maybe a little bit bad, you could think of that like a vulnerability. It might be okay, it might hurt some people who are immunocompromised, but most people are okay, that's like your typical vulnerability. But poisoned food is very different, right?
And I think these intentionally malicious components are more like poisoned food. And so the, the challenge is that organizations try to rationalize this away. They try to handle, uh, all of the dependency management problem the same.
And they have this mental model of how we deal with vulnerabilities. We prioritize them. We try to fix the most important ones, and, and we'll, we'll ship the release.
And, you know, it's a big pile. We can't fix them all right? These are all va very valid, um, rationalizations in the, the, uh, vulnerability world.
But when you're dealing with intentionally poisoned food, the fix is not go put it back in the fridge. The fixes not eat around the mold. Um, you know, and, and I think that's the part that's missing is that so many of these attacks are, are perpetrated and they execute as soon as the developer downloads 'em.
So by the time you put it in your list and you think about prioritizing the vulnerability, you might have had tens or hundreds or thousands of machines actually, you know, having the payload execute. And we've seen this happen with, with large, um, you know, financial institutions that turned this on and started looking for these things and found that they were already, um, you know, baked into applications and deployed all over their, their, their portfolio. Um, and so this is a very real problem that not enough people are thinking about.
And so, okay, you gave some examples early on. You know, these were, they were, they were sort of not super scary from a, from an end user perspective 'cause they were trying to really just steal the crypto game, that popularity system. But let's talk about some of the other types, uh, of very real attacks that we've seen.
Yeah, I mean, um, I mean, uh, there's been sort of a huge evolution of, uh, the types of ware that we're, we're, we're seeing, right? Um, and, you know, it kind of follows through, um, almost mirrors the popularity of open source itself. You know, as, as it's become more adopted, more ingrained, it's kind of given motivation.
And so, you know, kind of worse and worse types of, uh, creepy crawlies have started to appear. So to your point, like very initially onwards, uh, initially in the beginning, the types of malware that you'd see distributed tended to be things like discord sessions dealer. So it was, it was, uh, sort of people that were just trying to steal an identity often.
Uh, we started seeing crypto miners. Those were sort of the early, uh, supply chain attacks that you, you start, we started observing where, for example, you know, you sell, you sell people distributing, just, you know, uh, making a, the package look like it's legitimate, adding crypto miner in it, uh, developer machines and highly privileged, uh, uh, hardware, uh, usually run hard on Ram and CPU. So, uh, nobody's usually none the wiser if you're getting into a CI pipeline.
There was at least one heist that we, we saw that, uh, uh, used, uh, a, uh, uh, vulnerability, a vulnerability to poison, um, uh, shrinkage machines. And then, you know, mine, crypto essentially on those builds, uh, build agents. So, so, um, you know, initially it was that sort of thing, you know, dangerous, yes.
Criminal, absolutely, but not necessarily sort of, uh, dangerous from us or resilience and security, you know, organizational security perspective. Over time though, it started evolving and we started seeing sort of the more serious, uh, gangs appear. You know, somewhere around, I'm, I'm gonna say 20 18, 20 19, we saw the first orchestrated targeted crypto heist that used poisoned, uh, packages pretending to be open source.
And what they did was, uh, well, actually this was a takeover attack. They, they took over an open source project, and, uh, they knew that that open source project was adopted by a specific crypto wallet. So they poisoned that project, and then when it was run in that crypto wallet, they actually stole the funds.
And I think that group made with, made a way with like millions that, Yeah, and just to put a fine point, I believe this was event stream and it was 2018, I think, and copay was the target. But the important point here is not so much that it was crypto, I mean, it was important for them. This attack was targeted and delivered a patch file that patched custom code inside of the copay website, right?
Yeah. So that could be anybody's application. If you imagine that these, these components can apply a patch to your custom code, well then it's game on, right?
And, and that's the real takeaway, I think, from that event stream one. Um, and, and again, this was 2018 when, when this happened, and, and, you know, we were out there talking about it, that was a long time ago. Yeah.
Um, but we've seen them all, we've seen it, you know, stealing AWS keys from machines and databases. Um, you know, we've seen some attacks that got in that, you know, got into, um, you know, camera, uh, streams and things like that at hospitals and police departments and, and things like this, right? All of these through these, these dependency, um, types of attacks And, and probably pro.
And so you might be thinking, Hey, nothing new under the sun. This all malware that we deal with, uh, through all the other ecosystems. Well, what makes these things particularly dangerous, A, is that they're running on privileged hardware that usually have privileged access.
Uh, and b, it can affect your own code, which means that you, you know, they're often used as a starting point for more serious multi-phase, or what we like to call and sophisticated operations, you know, when you, when you see the press releases, right? Um, yeah. And so probably the most serious ones that we've seen are legitimate, uh, legitimate pieces of malware.
For example, COBAL Strike. We found some packages distributing COBOL strike a couple of years ago, which I think was sort of an initial warning bell, uh, that, you know, sort of the big serious groups have moved into this territory. And more recently we caught, uh, some packages actually distributing lama, which is a known malware strain.
Uh, you know, it's, it's thought to originate from sort of Russian nation state, uh, originating hackers. Of course, these tools, once they spread out, they, they get used by other, uh, groups as well. But, you know, that's what we associated with mentally.
Um, and kind of interestingly, uh, Lama the malware family was amongst the families implicated by Mandiant when they investigated the recent Snowflake breach. So if it is actually a really interesting read, we'll, we'll add that to the show notes here, but, um, the Mandiant, uh, Mandiant report on the Snowflake breach kind of talks about how they, uh, use the, uh, uh, how they kind of got, uh, hold of snowflakes authentication tokens, and then use those to hack their customers or kind of hack into the instances and then, you know, do what they did. And it was found that the, the heist started by them distributing info steering malware, and one of those strains was laa.
We've seen that same strain happening, uh, being distributed in the supply chain. It kind of makes sense, right? You know, it's, it's something that, you know, developers would have a hold of, uh, a hold of as well.
So un uh, unfortunately, this type of more serious, well funded and well motivated thing, uh, has moved, uh, for good, uh, into sort of the threat landscape that now faces us as developers and unfortunately, fairly on targeted. I think a lot of these are sort of cast out net types attacks where they do try to type us what something that's very popular and then distribute the malware. Uh, and, you know, the beauty of it is, uh, for the hackers is, you know, if it hits the developer machine, it is executed.
It's almost guaranteed. Yeah. And one, one thing, like, while some of those examples you gave are, I, I, would I struggle to define this classic malware that might be picked up by your typical, you know, uh, endpoint systems and malware defense systems, things like that.
Many of them aren't, many of them are custom code that is designed to run in the context of the build. So it's not like there's a known back door or root kit that your virus tool or whatever tool is gonna pick up and see. That will happen in some cases, but what we're seeing is most of these actually don't look like that.
They look like open source custom code that's doing something very fishy. Um, and, and, um, and so traditional malware defense systems are not catching up to this type of problem. And, and as evidenced by the explosion of them, we're not solving it, right?
And so this is something of course, you know, I was out on the conference track in 2017 highlighting this problem. Of course, we've been working on, on solutions to this, right? And, and this is why we're raising the awareness.
'cause we see how many of these, these packages are, we've, we've gotten really good at identifying them. We have ways of blocking them, um, at the package registry. Now, when your developers are actually downloading these components, and, and that's really the only way to stop it, you have to stop it before it executes, and again, it's executing as soon as they download it.
So scanning before you release the software completely misses the whole, whole war, right? Yeah. I think that's, that's a really important call out actually in the context of malware, right?
Um, if it hits the developer machine or any tool, uh, that tries to run an automated build, it's game over. The prevention is the only cure. So, you know, in terms of, uh, in terms of, uh, and when you add on to that, that you are certain when regular, uh, endpoint security tools just aren't enough, they don't have this sort of data.
It's often custom code, it's deployed once it lives for a couple of days, then it's removed, uh, from the world. They just, uh, can't keep up with that sort of volume. So what's pretty interesting is we've kind of inadvertently, um, you know, become one of the sort of leading authorities, uh, in helping our customers prevent this.
And we do it by the means of, for example, auditing of their open source package, uh, traffic as it comes in, and then looking for sort of signs of compromise, uh, as well as known, uh, malicious and poison packages. And I think, um, at this stage, we're like discovering them, you know, within 10 minutes of them being published. But, you know, sort of technically speaking, if you're thinking about ways of defending this, I think like the couple of takeaways that, uh, folks ought to take out of this is a, it's a real hole, and it's already there.
It's being very actively exploited. And two, prevention is the only cure. Normally people try to, especially in the context of vulnerability and DevSecOps, we try to avoid building breaking, build as much as possible.
Everybody's sick of gates, but this is the only place where legitimately stopping a download from completing and breaking a build sometimes in a fairly violent fa fashion, is the only way to prevent the payload actually from executing. Unfortunately, these payloads are, you know, so, so numerous. We've actually collected a timeline of all of these packages that we've seen sort of, that kind of highlights.
We'll make sure to put that on the show notes, but it is a very long laundry list, and unfortunately, it's getting worse. Yeah. The, the numbers are getting so big, it's hard to even talk about all of them anymore, which is why we have to move to broad classes of, of problems now.
Well, uh, that's, that's the evolution. So, uh, we're, we're, we're, uh, about to run out of time, uh, for, uh, this first episode. Uh, but, uh, Brian, um, it's been an absolute joy, uh, to, uh, deep dive into this topic.
Any sort of takeaways, uh, takeaways that people ought to take, uh, aside from everything we've spoken about, All the things, um, importantly, you can't, you, you, you can't treat these malicious components like you are your vulnerabilities. There basically are, um, very few ways of solving this. Most organizations have none, right?
And so if you think you have a solution for this, I, I bet you do not. Um, and, and I see this time and time again, and so people are willingly leaving their, you know, their front doors open, um, with the bad guys, you know, trying to come in, um, thinking that they have defense. And, and that's the real problem.
That's why we're trying to educate people that this is a different problem, requires a different solution that you probably don't already have. Well, uh, on that depressing bombshell, Brian, I think we're gonna, uh, gonna call it here, uh, this time. Uh, thanks very much for joining us.
Uh, tune in, uh, in a couple of weeks time, uh, for the next episode, uh, of, uh, from the source. com Is the number one online destination for DevOps education and community building. com covers all aspects of DevOps, including DevOps, best practices and tools, DevOps culture, DevSecOps, business impact, continuous testing, continuous delivery, and more.
com has the largest collection of original DevOps content featuring breaking news, blog posts, podcasts, and more. com to learn more. com where the world meets DevOps.
Hello and welcome everyone to the 5G Factor. I'm Ron Westfall, research director here at the Futu and Group, and today I am focusing on the major 5G ecosystem developments that have caught my eye. And this includes T-Mobile energizing 5G ecosystem interests in AI ran technology.
Also, a snapshot of the AI ran market segment, including NVIDIA's competitive position and closely related what's going on with Open ran and can open ran, prove its green credentials. So with that, there is a lot on, uh, tap, and let's dive right in. Well, first of all, I believe T-Mobile shrewdly leveraged its Capital Market Day event on September 18th to unveil its new AI RAN Alliance initiatives with Nvidia, Ericsson and Nokia.
Now, the initiative is definitely tied as AI ran is poised to substantially enhance customer real world network experience, meet the overgrowing demand for higher speeds, reduce latency naturally, and increase reliability essential for the latest gaming video, social media, and augmented reality applications. That's right, AR and I'm glad that AR is called out because in my conversations I'm seeing uptick in 5G supporting AR capabilities. And so the question is, what's the use case?
What's the context? What we're seeing is that, uh, construction sites and in any environment that requires, uh, drawings or the ability to provide a 3D viewpoint of an existing environment, well, there it is, AR is, uh, critical, and that includes, uh, many settings where only 5G can provide a real time connectivity, uh, capability. And so this is, I think, something that we'll see more of because AR initially was touted as a huge application that 5G would be supporting it kind of, uh, dialed back in terms of, you know, the actual, uh, use cases and capabilities.
But now I'm seeing that AR is going to be integral to why 5G connectivity will become more, uh, not only widely, uh, implemented, but also monetized quite simply. And so this is something I think that T-Mobile with its, uh, announcements at the capital, uh, at its, uh, capital Day event will, I think definitely raise, uh, the interest in profile. And so to step back, what are the key aspects here about AI ran and why would T-Mobile along with Nvidia Eric Sinopia pick this time to discuss, you know, what is going on?
Well, first of all, I believe AI ran technology can achieve the hardest thing of billions of data points to create algorithms that optimize network adjustments for peak performance and predict realtime capacity needs where customers require it most. Now, there's been progress in this area, but it hasn't really been a true realtime dynamic capability. And so what is the technology?
It has to enable automation quite clearly. And AI is clearly the underlying technology, I believe, along with its, uh, cause of machine learning that can provide this, you know, ability to adjust, you know, uh, the network requirements according to real world and real time requirements without compromising security, without trade offs and performance and say other parts of the network and so forth. That's really, I think, a, a dramatic breakthrough that we're on the, uh, the, uh, precipice of c.
And so in addition to that, I anticipate that AI can enhance RAN performance and automate operations, as well as quite simply elevate mobile network infrastructure performance, enabling it to run third party AI application workloads at the network edge, well, simultaneously. And so this is a lot, it's a lot being packed in, but that's, I think, how AI can make a significant difference that we haven't seen yet in terms of 5G network capabilities, let alone overall mobile and wireless networking capabilities. And this is also gonna be important for, uh, related technology such as, you know, wifi, I think you'll see many environments where, uh, there's a preference to use wifi, say at a central site, but we definitely need to use a 5G implementation or a private 5G implementation to address, you know, wide area network environments.
And so that means there's be more blending of the private 5G 5G and, uh, wifi worlds and what's going to be, you know, the technology that could underline, you know, how this can come together best. Well, AI, I think is the answer, at least AI is gonna play a central role in this. Now also, AI ran specifically is being developed alongside other advanced to 5G features in collaboration with T-Mobile and its partners.
Now, uh, the new, uh, alliance, I guess you can call it, is prioritizing that AI ran concepts will be developed in an open and containerized fashion along the same principles as Open ran. And so there's some skepticism like, okay, is T-Mobile, you know, tossing a SAT into the open ran ring? I believe, uh, because, you know, they've been not using open ran, I believe, uh, this is something that, uh, needs a, uh, level set understanding.
We saw that at and t when it announced that it was using Ericsson as its prime lead integrator for open ran implementation. That's basically how almost any top tier operator is going to unfold its open ran implementation when they believe it's ready for that. And what that means is that an EID or a Nokia will probably play the lead integrator role and then bring on other partners as required.
That would certainly include, you know, selecting the chip set of vendors that they deem most well suited for, you know, the specific unique needs of the operator, but also bringing in, you know, an alternative radio supplier like Fujitsu. And when it came to the at and t and Ericsson, uh, collaboration and as, as well as, you know, other third parties such as, you know, and os when it comes to, you know, some of the BSS or OSS capabilities. So it's really gonna be a case by case basis where the, uh, operator is going to select a lead integrator and working together, they'll decide who is best suited for the initial deployment of open ran.
And then, you know, after you know, it's been battle tested, then we'll see more diversification of suppliers and so forth. So it really is an exercise in patients. This is not unique to Open Rand.
We've seen this with other technologies, but I think it's really good news overall that AI ran can actually, at the end of the day, be a good friend to open Rand. And as a result, uh, really invigorate the open RAN implementations out there. There are still less than 10% of the overall RAN implementations out there.
So that is, I think, going its trend toward the advantage of Open ran. The fact that AI ran will now become more, I think, uh, prioritized in the planning of, you know, the major operators. And certainly T-Mobile is proving that.
And to reiterate, I think AI RAN stands out as a breakout technology because it can significantly enhance the existing open RAN architecture, but also it's allowing the collaboration that needed, uh, to demonstrate that AI ran could not only fulfill the potential VPA ran, but also quite simply surpass its expectations. And so this is exciting. I I think this is, uh, a collaboration that will not only earmark how a RAN technology can be truly innovative, but also impact the other parts of the network that includes, you know, 5G core capabilities, 5G advanced implementations, and ultimately six G itself, which I still think it's a little premature to talk about in terms of its practical implementation.
But let's first of all get 5G standalone more widely deployed, see how 5G advanced innovations make an impact. And then I think a year or two from now, we can talk more pragmatically about okay, six G. But yes, on the RD side, six G is certainly has to be a part of the planning there.
Now, what T-Mobile's doing with Nvidia Ericsson and OIA is taking advantage of increased mobile ecosystem interests in AI ran itself, the debuted basically at Mobile World Congress in Barcelona at the beginning of the year, and has since I think, garnered a lot of interest because we've seen fundamentally a stalling, if you will, of, you know, 5G deployments overall. A lot of it's associated with the RAN and the fact that open ran has really taken off. It's really in the eye.
They beholder as we saw with the at and t uh, Ericsson, uh, partnership. But I think that is going to, uh, basically recede in terms of, you know, perception. It's like, okay, open ran will increasingly become just that, uh, integral to the planning of the operators.
And that there's a lot of quite simply ecosystem support behind it, not just from the operators who are getting past, okay, we want to support open RAN in principle, but how can we implement it in reality? That I think is, you know, the challenge that's ongoing right now. We also have national governments and, you know, other, uh, you know, imperatives as to why open ran will become more important.
There's less reliance on, you know, supply chain surprises, or less risk, I should say, of supply chain surprises, you know, coming out specifically, uh, from the Asia Pacific region. And that's something that Open ran, uh, can play a role in. We see players like Avenir, for example, being able to step up and show that open RAN can come from an independent supplier.
Also, I think what's important here is that we have wider deployment of 5G sensors, which means that the mobile network operators will have to improve their RAN and overall mobile network efficiencies, as I touched on, as well as augment overall network edge intelligence. So it's not just about, okay, a better experience for consumers, but then also certainly businesses. But the IOT component, IEI think iot is going to play a major role in how mobile operators can sell 5G, you know, diversify the revenue streams and so forth.
And that includes 5G sensors for the AI or the AR applications I touched on, but also things, uh, such as intelligent video monitoring, uh, as well as advanced gaming capabilities. We've heard about that actually making it happen. Moreover, I see that the suppliers across the mobile ecosystem, uh, chain will increasingly integrate AI enabled RAN platforms to basically keep an eye on decreasing ran power consumption.
I'm gonna touch on this more as well as costs, and that can also boost what are, uh, increasingly important digital twin outcomes. And that's part of the AR piece, but digital twins are also important for many environments that is having a simulation of a real world environment that can allow the decision makers to make better, uh, uh, decisions quite simply about Yeah, what is going on? And I think a good analogy, and I've uh, invoked it before is what we do with, uh, Google Maps as well as GPS is giving a, a real world simulation of what's going on with the traffic out there and how you can get from one destination to the other in an optimized fashion.
Well, the same thing, uh, with, you know, construction sites, the same thing, uh, basically if any r and d environment that would like, you know, an accelerated output of how can we better design, say, you know, the mobile network itself, but also, you know, smart buildings, uh, smart cities, you know, there's just a whole host of use case scenarios where 5G can play an integral role using AI as a difference maker. Also, I think that it's important to note that the AI ran cloud-based multipurpose network has the potential support, not just the traditional Telco workloads, but also core RAN and also AI workloads together, and that it can be, uh, better enabled through what is, uh, being labeled as AI as a service. So AI as a service, you know, there's a long line of, as a service capabilities out there, I think will, uh, quite simply have more prominence and bumps, you know, the as a service capabilities out there, such as infrastructure as a service, software as a service platform, as a service.
And so this is good news, this is good news, you know, for mobile network operators, but certainly also for businesses and as well as, you know, increasing competition across the entire mobile ecosystem. Now, the next steps, let's say, you know, we're seeing enhanced capacity, better energy efficiency and improved resiliency. That means that new GI AI applications along with the traditional, uh, workloads such as voice, video and data, have the capability to make better contextual decisions about how to best utilize network, uh, performance, uh, parameters.
And also, uh, again, it's about cost savings. And so when these capabilities are firing in all cylinders, that just quite simply improves the total cost of ownership, I think, uh, metrics for the mobile network operators and thus spur more investment in terms of how can we best use AI to improve ran network performance, but from there across the entire mobile network. And so moving on to the next theme, the second major theme, it's again about AI ran, but let's drill down more into what are these AI ran capabilities, specifically when it's related to Nvidia ai aerial technology, which, uh, was certainly featured in the announcements, uh, by T-Mobile related to AI ran.
Now what we're seeing is that telecommunication providers are evolving beyond, you know, their traditional services. They certainly, it's a strategic aim by using AI computing capabilities. Now, this means how can that be translated into these improved outcomes that we talked about?
Well, this transformation, uh, requires the optimization of wireless networks to meet demands of generative AI across mobile devices, as well as, you know, basically any device out there that requires it, robots, uh, autonomous vehicles, smart technologies, and so forth. And so I think it's important to note, what are the capabilities that the Nvidia AI aerial platform is, uh, supporting? Well, first of all, uh, Nvidia aerial coda accelerate includes a software libraries that enable partners, uh, to develop and deploy high performance virtualized ran workloads on NVIDIA accelerated compute platforms.
Okay? That's, you know, uh, pretty, I would say self-evident. But what's also important are the following two out in second Nvidia AI aerial radio framework includes PyTorch, I tensor, flow based software libraries develop and train models for improving spectral efficiency and adding new capabilities to 5G and ultimately six G radio signal processing.
And this includes Nvidia cyana, a link level simulator that provides development and training of neural network-based 5G and six G radio algorithms. So this is ambitious. This is really Nvidia stepping up and saying, all right, there are all alternatives to how virtual ran and open ran implementations are being done today.
And that is naturally a direct challenge to Intel, and it's X 86 CPU approach. Now, that's, doesn't, not by any means mean game over. What it means is that, okay, there are some competitive alternatives out there, uh, that could spurt intel to really step up.
Its X 86 game, for example, and come up with ways to show that, okay, this is an approach that will be of, if not a key part, but one that can answer, you know, some of the things that NVIDIA is bringing to the table. And third, Nvidia, Ariel Omniverse, digital twin, digital twin twins, again, or A ODT is a system level network, digital twin development platform that can enable, uh, uh, the physically accurate simulation of wireless systems. I already pointed out this, and that actually to provide more to detail that comes from a single base station to a comprehensive network with a larger number of base stations covering an entire city.
So, in other words, the networks can be smarter. We can simulate not just, you know, the, uh, base station level, but entire, you know, cities, uh, for example, which would be crucial for a mobile network operator, and then ultimately perhaps the end-to-end network itself. And so it's doing this by incorporating software defined ran, uh, could accelerated, uh, capabilities along with the user equipment simulators and realistic terrain and object properties of the physical world.
So this is moving along and this is coming closer to network to you. Now, I think what's also important to note here is that Nvidia ai Aerial is a suite of accelerated computing software and hardware that's designed to really accelerate the simulation training deployment of AI ran technologies. So that's, you know, to reiterate what is the objective here and what, what, pivoting off of that.
The platform can become a critical foundation to allow network optimization at scale to serve the, the demands of a host of new application services capabilities. And this could ultimately provide savings and TCO, but also open tele telecom operators to revenue opportunities across, uh, the enterprise space complimenting existing consumer services. And I think it's also important to note that, uh, it's fulfilling really both the general purpose and virtualization boxes.
And while NVIDIA thinks AI itself can help to reduce energy consumption, GPUs, as we've seen, and you know, data centers that are using GPU clusters to do heavy lifting, uh, AI training, quite simply require a lot of energy, and as a result, they're power hungry. And that includes in comparison to CPUs and other accelerators. And that is going back to, okay, NVIDIA versus Intel when it comes to the future of open ran the future of virtual ran.
And this could be a decisive factor actually for Intel if it can show, okay, energy efficiency can, uh, actually be better attained through A-A-C-P-U centric approach. However, let's, you know, let the competition commits. Uh, as we've seen with Edge computing, which involves, you know, hosting applications closer to mobile sites rather than, you know, those large data centers, there's, uh, been a topic of discussion as to how this can be applied, uh, to virtual ran.
And while progress has been, I would say limited, it's, I think indicative that when you're seeing more neutral host, uh, implementations as well as other implementations at the edge, that both Nvidia Intel are stepping up to demonstrate this is something that, uh, the mobile ecosystem can take advantage. Uh, and so I think it's all important to note that when it comes to the virtual ran, uh, market, there has been a lack of an ARM or X 86 based alternative to Intel. But I think we're gonna see, uh, more alternatives coming to the forefront.
And that includes an, uh, AI centric, uh, or GPU centric approach by Nvidia. Now, I think it's also important to note that, uh, when it comes to, uh, the Nvidia aerial omniverse digital twin applications, we're already seeing, I, I would say partnership support Key psych, for example, is using the technology for its testing and simulation systems while we're seeing partners such as Deeps, Northeastern University and Samsung collaborating on six G research using Nvidia aerial AI radio framework. So this is, uh, showing that that vital ecosystem support is becoming, you know, more real.
Also, I am seeing that the cloud stack software providers such as Arna Networks, canonical Red Hat and Wind River, and as well as network stack, uh, providers such as acus are providing, you know, that the support for network and server, uh, capabilities to enhance capabilities that are being offered by Dell, HPE as well as supermicro. And these are all key partners for Nvidia in this segment, at least using Nvidia ai, aerial technology solutions. And it doesn't stop there.
There's also Vapor IO and system integrators like Worldwide Technology also exploring how can we use the AI proving ground of nvidia, but also ultimately the T-Mobile Testing center to figure out how we can make AI work better for RAN implementations. And as a result, the overall mobile network. And I, I think it's also important rounding out here to talk about the energy efficiency and sustainability aspects.
Now, the hope is, is that GPU energy efficiency using AI can be improved at the edge, and it's different again, from data center environments. And that includes, uh, CPU technology, whether it's X 86, uh, based or, you know, using arm based implementations. The bottom line is the energy efficiency has to be there in order for the mobile network operators to, you know, offer a more compelling service, but also for them to meet their own in-house sustainability goals.
And I don't think that's all at the table at all. It's definitely something that the, uh, mobile network operators are keeping a CLO close eye on as they're looking at ways to innovate their, uh, overall mobile network implementations. And with that in mind, I thought it was interesting that Orange Group is confident that O ran compliant radio units can achieve energy efficiencies comparable to two traditional reus.
And so this is important. This has been, uh, a bit of a debating point. You know, can open ran actually at least match or exceed, you know, the energy efficiencies that we're seeing with ongoing ru uh, implementations.
And this could be, you know, a real, uh, you know, game, uh, decision breaker that is, if open ran cannot improve on traditional RS in this regard, then it could als it quite simply continue spinning its wheels in terms of, you know, market presence. So what we're seeing is that when it comes to cloud ran ecosystem, which you know, basically is, I would say a subset of the overall open ran realm, it's important that it can support virtualized base band units as well as distributed units and as well as centralized units and operating on commercial off the shelf hardware with accelerators that deliver again, those energy efficiency gain gains. Now, so why is Orange confident about this?
Well, it's really taking advantage of these new chip sets that are coming down, and that cloud ran specifically can match from 2002 25 onwards. That is the energy efficiency performance of those traditional rans and high capacity urban scenarios. So this is not gonna be an overnight sensation, but a again, when it comes to those dense urban settings, we can see open ran, uh, again, exceeding what traditional RAN could do in this particular area.
And what else is, uh, you know, contributing to this? Well, using massive MIMO technology, running again on those, uh, generic hardware, uh, platforms combined again with those purpose-built accelerators. Now, I believe there's been progress not only with the chip sets and accelerators, but I think Orange brings out a very important point.
It's also with the dimensioning part, and this is again, where AI is helping play a role. And with the newer chip sets that are coming out or have come out, it should, uh, as a result be able to provide highest capacity scenarios with a mix of FDD bands and TT DD bands and massive mime up and a single server. So that's bringing a lot of, you know, factors together, but I think that's going to be the bottom line.
Can an operator like Orange use a single server to combine these, you know, well-established bands on the FDD and TDD side, uh, using massive MIMO to attain these energy efficiency objectives? And that sure is looking like it. Orange would not be talking about it, if not otherwise.
Also, I think it's interesting to note that chip set developments from various suppliers and also noting ran advances, uh, made by again, uh, Nvidia, uh, that orange is expecting performance crossover, uh, between dedicated and generic hardware will happen sometime next year, or at least no later than 2026. So that's really putting a lot on the line. It's saying we're putting our money where our mouth is are just saying, okay, we believe that the Nvidia uh, proposition is going to help drive this.
And that's tied back again to why the T-Mobile announcement on the AI ran side itself is so momentous. And also, you know, spotlighting that Nvidia, Ericsson and Nokia are all on board. And this is just exciting.
This is just gonna be, I think, great news we're making, you know, the RAN market segment itself more interesting, that is, you know, a more open ran, uh, implementations or at least accelerating them and also just intensifying the competition. And with that, I would like to say thank you all for joining the 5G Factor. Again, please bookmark the 5G Factor.
It's on the Futureum Group, uh, website. And always appreciate folks taking time to listen to my thoughts on what is going on. That is so exciting and I'm looking forward to, you know, providing an episode next week as well.
And with that, thank you everyone. Have a great 5G and AI ran day. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of Security Bloggers Network. Hey everyone, good to see you.
Welcome back to Marketing, art and Science, the webcast podcast, where I, Lisa Martin sit down with CMOs regularly and we talk about the artistry, the science of marketing, and how these CMOs are pulling those levers or flexing those muscles to convert prospects to loyal customers. I'm so pleased to welcome today's guest, my longtime friend and colleague, Ivana Karens the EMEA, CMO of UiPath. Ivana, it's so great to see you.
It's so good to be here. Thanks for having me. My pleasure.
And I'm excited for the audience to learn from you. Let's go ahead and kick off with your background. You and I go way back 10 plus years or so to our TIBCO marketing days.
Talk to the audience about your ascent to the level of CMO for amea, for UiPath. Yeah, um, I mean, I started my career in journalism, funnily enough, so kind of an unusual ally. Yeah, an unusual entry into marketing.
Love, my gosh. Yeah. Yeah.
So I, I worked in radio on TV for a number of years, um, and I entered marketing kind of through public relations. So I, I had studied PR as part of my journalism masters, and I moved into marketing that way, uh, worked in comms for a number of years and then started to broaden my remit a bit, moved into field marketing, then account-based marketing was added on, and then digital marketing, and then a little bit of product marketing. And then I moved into BDR management as well.
Um, and so kind of throughout the career, I suppose my career now spans 20 years. Makes me feel old to say that I Know right? Throughout A career, I've kind of touched on all aspects of marketing.
Um, so yeah, it was kind of an unusual route to marketing, but an enjoyable one on the best. I love that. Well, it gives you such fresh perspective, especially from a communication standpoint.
You know, what the mainstream media is looking for. And that's always a hard one because we're so used to talking with audiences and taking very technical information and distilling it down to digestible components. And when you're doing TV and radio, it's gotta be even more.
So get the audience a little bit of over with. Anyone's not familiar with UiPath. I know that you guys are delivering AI for the real world enterprise, and we can't go a day without talking about ai.
Tell us about UiPath and how does it deliver on that? Yeah, so we kind of grew up in what's called the era of Robotic process automation, which is RPA. And that really was all about automating backend mundane processes.
And, you know, we still build on that every day. It's still our foundation. Um, you know, we're now moving into, you know, more intelligent ai, if you will, uh, looking at things like Egen ai, which is kind of the next big thing, uh, that's on the horizon.
But primarily, I mean, if I was to put it really simply, we help organizations to be more efficient, to enable their people to be more efficient and focus on the more strategic, more creative tasks, rather than having to be bowed down by, you know, documents. And, you know, extracting information from documents or, you know, invoicing in the realm of finance is a, is a very complex thing and very time consuming, but very mundane for the most part. So it's taken the mundane out of work and allowing humans to flourish and focus on what's more important.
I love that. And everyone wants that. No one wants to be bogged down with the mundane task that you're checking out checklists.
They really wanna be able to get creative and strategic for the most part. Love that. Right.
Let's dig in now to the MarTech stack. So I always love talking with CMOs like you about MarTech in action and how it's taking someone from a prospect who's out there doing their own research on UiPath and automation Mm-Hmm. To a loyal advocate customer.
So give us a little kind of a high level overview of the Mark marketing technology stack at UiPath and, and what it's doing to convert those prospects to advocates. Yeah, I mean, I would probably say our tech stack is a little bit too comprehensive. You know, we probably could look at streamlining a little bit bit, but we do definitely have a tool for almost everything.
And, you know, some of those tools are better than others, but I would say a lot of our tools are focused on, you know, primarily the top of the funnel initially. How do we get those prospects engaged? Those people who are doing their own research, who haven't really reached out to UiPath as yet.
I mean, we call that the dark funnel. Like how do you get UiPath in front of people who are just educating themselves early on in their buying cycle? How do you engage them with a po uh, to a point where they will want to learn more later on when they are ready to buy?
And there's so many tools out there that can help you to do that in a really good way. I mean, there's one tool that I love, which is Six Sense, which really helps to increase that level of engagement. It helps us to really target different buying groups, you know, and really get to the peak the decision makers within those buying groups and ensuring that they're aware throughout their buying cycle.
And I think, you know, a lot of the tech out there today is really helping us to be much more intelligent around the type of content that we place in front of prospective buyers right, throughout their journey. You know, 'cause the type of content you want to position, you know, very early on. And the journey is very different from the type of content you want to position in the middle or the bottom of the funnel.
So, you know, getting the right content in front of the right audience at the right time I think is hugely important. That's what it's all about. And so figuring out what tools can help us to do that, I think we've, you know, it's really helped us to refine our demand generation activities to become a whole lot more personalized in how we're reaching out to people so that we're putting messages out there that are resonating, uh, with the right audiences.
And, you know, it's always necessary to, to do that at the right time. And, you know, I think that there's so many tools. Like, I mean, obviously all the data analytics tools, you know, mark Marketo is our marketing automation tool.
You know, we've got tools for AB testing, SEO, social, you know, all of those tools. I think it's about how you use them, you know, to make sure that you are positioning your message in the right way to the right audience. And, you know, that's a difficult thing to do.
But I think marketing has become so different now with ai, uh, infused into it that we've, we're becoming, I think, a little bit more, you know, focused on our buyer and on a little bit more customer centric, which we need to be really getting to understand our customers. You know, this spray and pray effect is gone long gone. I mean, thank God long gone.
I sure right? You, yes, you Have to get targeted to a particular type of persona. Um, and that's the kind of marketing I love.
That's the marketing that excites me because there's an art and a craft to that, if you will. You know, you, you mentioned, you know, that the science behind it, there is a huge amount of science now behind how you do marketing effectively. I think it's hugely exciting.
And while that it's one of my favorite things as a former life sciences person back in the day before I got into tech, and we've seen marketing evolve so much the last 10 years into being so scientific and being, and, and that's why we created this show at a really understand how those two are coming together and how it changes. 'cause you, you talked about a great deal about the personalization element. Yeah.
The right content, the right message, the right time, the right person. We all expect that in our consumer lives. Mm-Hmm.
Which blend into our business lives, right? We just expect we're going to get delivered the right content that I'm looking for this right now. Don't show me something similar that I bought yesterday or last year.
I want you to know me in a non-creepy way and deliver messages, content offers, product services that are relevant to what I'm looking for right now. And I love how you talked about really pulling the, the leverage. You mentioned Six Sense, a lot of my CMOs on the show talk about Six Sense and how great it is for doing just that, but it's so incredibly important to be able to flex those, those AI muscles.
We'll talk about that in a little bit too, as, as well as the artistry. So how do you blend the two or pull those levers of the science piece and the art piece, and like, what does each one mean to you and to UiPath? Yeah, you know, I, I think this is a really interesting one because, you know, it's almost about getting the fusion of the art and the science, right?
And, you know, I always think of that left brain right brain analogy. You know, if you just have all creative marketers, you're gonna have great content, but you won't know who to target, and you definitely won't know how to get to them in a very personalized way, you know? And and similarly, if you just have those analytic type marketers, you know, you won't have any content that's gonna resonate, but you surely know who to go after.
But with what, so, you know, getting that mix of the art and the science right, is critical in marketing now. And, you know, building teams, you have to think about that. You have to think about the creative folks as well as those analytical folks, and then how you bring the two together.
And, you know, it, it can be difficult because if you are leaning too heavy on one side versus the other, you know, your marketing is not going to be as effective as you want it to be. But when you get it right, that's when the real magic happens. You know?
And I just love sometimes when you do see the, the, the fusion, you know, come together in the right way. You know, the, the, the creativity and the results that you can get from that. I mean, it really is like watching magic happen, you know, when you see, you know, the campaigns going out and the impact that they're having ultimately on pipeline of revenue, because, you know, that's the ultimate success of marketing.
But you know, when it does happen in the right way, it really is phenomenal to watch. It is magic, isn't it? It's so fun to see all those levers being ticked in the right direction.
Talk a little bit about the impact because you, you talked, you just said it, it's all about, at the end of the day, from a marketing perspective to influence pipeline and impact revenue. How are you guys at UiPath doing that, leveraging the technology that art in the science? Yeah, I mean, I think for me it's about mapping out the buyer journey, um, and then figuring out where the tech can help you, right?
So, you know, and I think it's also understanding who you wanna go after, right? Who are your target audiences, you know? And that may be different for different product lines that you have, um, you know, within your, your, your platform.
Um, but really understanding that at the outset I think is most important. And then, you know, as I said, figuring out where the tech is really going to help you to do more. You know, it, it, the tech should compliment your overall strategy.
It isn't the strategy in itself, you know, and I think some marketers become a little bit too reliant on the tech, but I think if you can get the tech right and understand what the tech can do for you throughout that buyer journey, I think that's when you'll start to see impact. You know, and I think we, we thought long and hard about, you know, I I mentioned sense as as a tool, you know, but again, we were very clear on who we were going after. You know, we know our buying groups very, very clearly.
And what we really wanted to do was to track that level of engagement across those buying groups and then watch how we improve that over time. You know, or, uh, if it's dis improving, obviously we need to take, um, you know, action to, uh, to fix that. But, you know, I think it's been quite interesting that, you know, we, when we, when you integrate advanced tools like such as marketing automation, you're obviously the CRM and data analytic platforms.
And you know, I think it really helps to streamline your de demand generation efforts and your nurturing efforts so that you become much more targeted and then you can, you know, you can achieve higher quality leads that you're passing over to your business development team than to qualify. And then you see greater efficiency through the follow, you know, your pipeline is greater, you know, the pipeline is created a little bit faster. You know, you're improving win rates, you're improving the time to value, and these are all the things that we're using our marketing tools to measure, you know, what are we doing to improve overall pipe creation, pipe acceleration, you know, how are we helping to improve those win rates, you know, reduce the, uh, the buying cycle, et cetera.
These are things that we are measuring and, you know, there's fantastic data automation, uh, tools to help us to do that. And, you know, I think when that all comes together, you know, you really can show the value that marketing brings to a business and the impact that it has, you know, ultimately on revenue, uh, over time. But I think once you can measure that and demonstrate that to the business, I think that's when you really begin to see, you know, the return on investment of, you know, not only the tools that you're using, but you know, the, the whole marketing organization, um, of a company Really elevating it up to c-suite to be, this is a, a critical business partner for us across sales, finance, operations, you name it.
Marketing is a, is a really integral cog in the, in this well oiled machine that is absolutely UiPath. And you've done a great job of articulating how you do that and why it's so important. Hmm.
Absolutely. You know, I think, I think you, you, you know, there's always a bit of conflict between, you know, sales and marketing sometimes, you know, who's generating the pipeline, where is the pipeline coming from? But I think, you know, if you have the right tools in your, in your tech stack, and you can align, you know, from the top down in an organization about how you're going to measure that, you know, and how you're gonna report on that on a regular basis, I think that's when you can really start to build that partnership that you just spoke about.
And that's when marketing really gets the seat at the table, right? Yeah. You know, because, you know, that is, is is so merited because, you know, we bring in a significant portion of pipeline, we influence a significant por portion of pipeline that, you know, obviously results in a significant portion of revenue.
And so really, you know, understanding the art and the science of marketing is only going to make us more effective and, you know, hopefully contribute to more pipeline and more revenue in the future And better partners with sales. How, how has the MarTech stack that you've implemented that you've talked about, it sounds like you've got great alignment with sales. How has it influenced and maybe helped improve that sales relationship?
Because they probably now have visibility into data and their customers, prospects and customers that they didn't have before, which is huge that, And that's the bottom line, you know, a salesperson really thinks about how can marketing help me? You know, and you know, when, when you're using certain tools that help them to understand how an account is engaging, you know, who's engaging, what they're looking at, getting some sense of their intent to buy. I mean, this type of data is gold for a salesperson.
Yeah. You know, that automatically brings marketing closer to sales, you know, and then I think helping them to understand the way we measure success in marketing, you know, and, and then being very transparent about that, you know, and, you know, there has to be transparency in the numbers, you know, but once you start to, you know, cloud over or, you know, you start to, you know, um, increase the marketing contribution beyond what it actually is, you're just doing a major disservice to marketing. You know, you're killing relationship between sales and marketing and you're, you're losing credibility.
So the transparency, the alignment, you know, all of that has to be there and the trust has to be there as well. And, you know, I think that's when marketing truly becomes a partner rather than just a service. You know, that helps, uh, salespeople do their job.
They become a true partner for sales, you know, and that's when they get that seat at the table that I referred to earlier. And you, when you mentioned trust, I was thinking that the whole last few minutes, that is currency these days. Yes.
Trust between a brand and prospects a brand, and its existing customers, sales, marketing, key functions. It is absolutely table stakes for selling relationships and ultimately the impact on the UiPath brand that marketing wants to deliver. So how, how does the tech stack, the relationships that you put in place within marketing and within other key partners in the organization, how has it influenced UI Path's brand?
Oh, I, I think it's influenced the brand quite a bit. And you know, I think you touched on a really important point, and I think it's a, it's a, it's kind of a new development in marketing, you know, this, this whole notion of truth, you know, I mean, always people have this picture of marketing as, you know, it's, it's a version of the truth, you know, it's a verbose, it's, you know, exaggerate it. I mean, I think we have to get back to the truth, you know, and really reinforcing, you know, the true, you know, differentiation of a product.
You know, if you, because you know, all you're going to lead to in the long run is a disappointed customer, you know, so you have to think of long run the impact it's gonna have on your business, on your customers, on their satisfaction levels. If you, if you oversell, you know, what the, the company does. So, you know, I think a level of truth, and getting back to honesty in marketing, I think is a, a really important kind of movement, if you will, within marketing.
And I think, I think it's only a good thing, you know, there's so much fake news out there, there's so much, you know, oh my gosh, That you have to just, you know, say it as it is, obviously in a very engaging way, you know, over multiple different channels. But, you know, ultimately for me, it's about the personalization of the message, the truth, you know, um, and reinforcing the truth and knowing your customer, you know, knowing what they want. And then, you know, giving them what they want when they most need it.
That's when, you know, marketing really shines. That's when you know, you know, you're, you're, you're, you're having an impact, a real impact on the business. That truth is, is absolutely essential.
And it's a great way to differentiate a brand as well. You mentioned the fake news, and it's out there and it proliferates faster than we can even comprehend faster than we can identify and stop it. And so for brands to be truthful with their customers is just no longer a nice to have.
It's something that every brand needs to implement. Let's move into kind of our third topic, and let's look at, we talked about AI briefly, emerging technologies. Some help us understand some of the practical applications of AI at UiPath in marketing within the technologies that you're selling as well.
Yeah. Yeah. I mean, we, we actually use our own technology in marketing.
It's, uh, really quite amazing. You know, we have, uh, uh, products called Document Understanding and Comms Mining, you know, um, really what Document Understanding does is it reads large amounts of documents and pulls out, you know, important information so that you don't have to go through all of that detail. So, you know, again, it's a, it's the kind of prompts that you give it, you know, what is it that you want from that document?
But it saves my team so much time in using these types of tools. You know, comms, mining, you know, helps to go through emails looking for certain things. You know, it can summarize, you know, um, a number of emails after a holiday and highlight, you know, what are the key things you need to focus on?
Where do you need to prioritize, you know, those 350 emails that you missed while you were on vacation. So, you know, we are using our own technology, um, a great deal in marketing, and it is making our lives a whole lot easier. But I think, you know, that the future and where we can go, even where our product is going now, um, you know, with, with this whole notion of agentic AI and using agents, you know, that work together with robots and humans, you know, I think they, the possibilities are endless.
And I think, you know, what that will do for marketing in the future, I think is it's, it's exciting and scary, honestly. Yeah. All at the same time.
Yeah. But, you know, anything that takes away mundane work for me, uh, I'll take it all day long. I, yeah, I hear you.
Exactly. And I love, I love stories that drinking your own champagne. Yeah.
Um, people always ask me why I say that, because you know how much I love dogs. You've known me a long time eating your own dog, but I'm like, champagne just has like, pinky out kind of flare. Sounds not fair.
So I like that. When you, and kind of, if we, if we peel back kind of the layers of marketing, what are some of the areas in which AI, gen AI is really helping you guys move that efficiency meter? And I think of like customer data analysis, customer journey orchestration, personalized content creation.
What are some those key areas and use cases that you are really seeing great results? Yeah, I think, I think one of the areas that I love, it's, you know, if we create video content, 'cause, you know, everybody talks about text, you know, text-based content and what you can do, AI can do with text. But I think the, you know, the, the opportunities in, in the world of video and dynamic content, I think is really exciting.
Um, you know, the ability to actually create a video and then, you know, the video might be 20 minutes long. And then to, you know, put an input to the tool to say, okay, now give me a 32nd video that's good for LinkedIn and give me, you know, a two minute, or that's good for, you know, YouTube or, you know, and it will literally spit back out what you want with very little work on anyone's side. And, you know, there's, there's time saving in that there's massive cost savings Word, you know?
Yes. Yeah. Where you work with agencies to create each version of that video, you know, and the time it creates for them to write the script and then create it intuitives and all this sort of stuff.
I mean, you can actually get multiple outputs from one piece of content. And you know, what I think is really fantastic is that if you have one hero piece of content, it might be a white paper, for example, from that you can bring to life any amount of content, you know, from emails that you'll send to your customers, short videos that, uh, scripts that you'll create. And you could even use certain tools to create the video.
You know, that'll, uh, create an avatar of you using your own voice. You know, it's, it's, it's phenomenal the possibilities, you know, and I think for marketing, it's only going to make things obviously move a whole lot faster. You know, I think it'll make marketing very, very exciting, but also I think very impactful, even more impactful than it is today, because you will, you know, the, the ability to know what your customer wants before they almost know it themselves.
I think that's the sort of scary part, but also the exciting part because the level of personalization there is, you know, through the roof. So, you know, I, I, I think there's just endless possibilities with ai. It is a little bit scary, you know, you need to have those guardrails, the governance, the ethics, all of has to be in place.
But I think, you know, the possibilities, you know, they, they are really exciting for me when I think about it, you know? And, and I hope I'm around to see, and I'm still working in marketing to see it come to fruition because I think it's beyond our wildest dreams. It really is.
There's so much we don't, there's what, what fascinates me is there's questions we don't even know we have yet that it Yeah. Probably can already answer is so the whole crystal ball element of it is, is fascinating. And also working on the personalization piece, because we, I I mentioned in our consumer lives, we just expect that yeah, we expect that brands will know us, um, yep.
Anticipate if I bought a tent, anticipate what I might want next so it show me more tents. Exactly. Show me and chairs able show me coolers Yes.
Relevant content you can do In the business world. I mean, you know, the possibilities are phenomenal, you know? Yeah.
To say, well, you know, you bought this product, but, you know, instead of having to a salesperson to think about, well, now, you know, they've used this product for this amount of time, they might be ready for this, you know, technology will do all that for us, you know, and they will preempt and predict what it is that we want to do next. And, you know, I mean, it's, it's kind of scary what that means, uh, for, for, for marketing in the future, but, but also very exciting, as I said. Absolutely.
I share your enthusiasm and your excitement for, I I, I don't know about you. I always feel like being a, in technology, especially as a marketer, we have an opportunity to help the masses understand better all of the positive applications of AI that are already x in that they might not be aware of because the mass media is so focused on the fake news and, and, and harm. And we see those stories get elevated more so than the positive stories.
Yes. Do you feel kind of like a sense of responsibility there in terms of let's help spread the word on all the good AI is already doing? Absolutely.
You know, there's a lot of scare mongering, I think, around ai. Yeah. And, you know, AI is gonna replace humans and what will humans do, and all of this, you know, I, I don't think there's a point in the, in the near future where, you know, AI will fully replace humans.
You know, I think it'll free humans up to do so much more, you know, and to really focus on things that need human focus and, you know, put all that other stuff to, to a robot or an agent or, or, or whatever. But, you know, I, I, I think, you know, we need to really be careful about, you know, putting guardrails around things. You know, I think the, you know, the, the governance around AI is something that we, you know, have to figure out, you know, not only as UI path, but right across the world.
It affects everybody. Yeah. You know, and I, and I think the governance and the ethics piece, you know, I think there, there are pieces that we, we really need to get on top of.
But, you know, honestly, I think, you know, the excitement for me surpasses any negatives. You know, I, I think it's going to be a, a really fun world, you know, when, when AI and, and agentic AI and all these, you know, future iterations of AI kick into place, I think it's just going to be, you know, very, very fast moving. But, but very fun indeed.
Yes. I think so too. I share your, your excitement about that and, and, and I see a lot of positive aspects.
You know, when I, when I talk to the mainstream media like Schwab network, there's like, you know, there's so much investment going on in ai. We talk about the Nvidia and the Magnificent seven and, and, and investors are like, where is the ROI in this? But, but monetizing AI is challenging.
Do you, are we not there yet? 'cause a lot of what we're seeing when I talk to marketers, um, is efficiency gains, which to your point earlier, that can contribute to cost savings. But do you feel there some pressure to start monetizing the investment in ai?
Oh, Yeah. I mean, companies are investing so much in ai then the, the obvious next thing is, okay, show me the ROI before we keep investing at this rate. Yeah.
So I think there's a massive pressure coming, but, you know, I think when we speak to a lot of our customers, we tend to assume they're much further along on their AI journey than they are. You know, we tend to assume they've got it figured out, but the, they, the issue is, is they don't, you know, many are trying to figure out what their AI strategy for the future should be. And many of these companies are turning to us to say, you know, well, what should I be thinking of?
You know, is there something I'm missing here? Am I behind the curve? And everybody's assuming everybody else is way further ahead than they are, you know?
But the truth of the matter is, a lot of companies are really only starting their AI journey, you know? Yes. And, and they're onboarding, you know, into ai, you know, quite slowly and surely.
But they have to, to your point, be able to show ROI for the level of investments that they're making. And that's where, you know, it, it becomes a boardroom issue. You know, how much we investing in ai, what's the return, et cetera.
But, you know, I think we're very early stage in adoption of AI across companies. And that real ROI is still yet to be shown, to be frank in a lot of cases. Absolutely.
Well, so many companies are still on the pilot phases. And you bring up a great point about, of everyone, you go to any tech event, which you and I go to all the time, and AI is part of the, of the theme. It's infused in the keynote, it's infused into every conversation that we have on our show.
Yeah. Um, and, and, and the, and the kind of the, the scare tactic there is from, from senior leaders, if you're not investing in ai, you are already behind. And so there's that, oh my gosh, what are we doing?
What, right? What are we not doing? Mm-Hmm.
But what, what we see, what you get to see, and I get to see as well, is what's the reality right now? Right. Is it hard for the horse in terms of monetization?
I think so. I think so. But I think we have to keep moving forward and getting these quick wins, these efficiency gains, which can then companies can then, whether it's through the voice of the customer or whatnot, showing the value it's delivering back to the business.
I do believe we'll get there, but I think it's a little early innings if we were to use an American baseball reference. Yeah. I completely agree with you.
We're really only at the starting phase, even though people think we're much further ahead, we aren't, not, not in, in different, you know, in enterprise adoption of ai, I think it's still early days, Still early days. It is Formula One, lap one. I'll, I'll give you a, a better AMEA reference there.
Last question for you. Uh, we love to, to wrap the show, Ivana with our failed to fab segment, which is just really, I always say failure is not a bad F word. All, all the, the viewers, those tuning in goes, she says that every show.
It's true, but it is true. It's a learning opportunity. Talk to us about, uh, uh, whether it was a marketing initiative or a business initiative that wasn't going according to plan that you stepped in marketing, stepped in, and really converted that to a favorable Yeah.
Yeah. I mean, I, I remember once being at a previous company, it was not UiPath. Um, but we had a significant kind of setback in an, a highly anticipated product launch.
Um, you know, there were unexpected technical issues, uh, I to put it mildly. Um, and that, you know, resulted in really negative customer feedback. You know, so this had the potential to, you know, uh, affect our brand reputation, but instead of sort of succumbing to the failure, um, we decided to sort of use a blend of technology and strategic marketing to try and turn it around.
And, and, and that's exactly what we did. So we used actually social listening to kind of closely monitor what the customers were saying about the, you know, the glitches and, and the product itself. And we fed those pain points back to the tech team, you know, in real time.
And then we used, uh, social media and email to keep our customers up to date on how we were fixing this in short, in a short timeframe. Um, and then, you know, we, uh, we then actually targeted, um, yeah, we used actually data analytics to segment our customer base, um, to really identify the most loyal customers who would, had been affected by this. And then we reached out to them to give them early access to the revamped product.
You know, we gave them discounts, et cetera. You know, we got their feedback real time, which really kind of helped to Mm-Hmm. You know, make sure that we weren't sort of in alienating them, that we were helping to regain their trust.
And the other thing we did was we used, um, Marketo, uh, to nurture those that had shown initial interest, um, in, in the new product, but hadn't converted because of the technical glitches. Um, you know, and we actually using, you know, case studies and positive, you know, customer feedback over time, we were actually able to convert quite a few of those. So I think what actually, you know, turned out to be a, a ridiculous nightmare, you know, a a a failure turned into a kind of fab and favorable, you know, marketing initiative over time because it demonstrated the ability to leverage technology together with street strategic marketing, um, you know, to enable, you know, to turn it around.
And then actually, you know, in the long run, they became more loyal customers because they liked the openness, the open way in which we dealt with what was, you know, turning out to be a failure at the beginning. But, you know, we, we salvaged it in the end. Thank goodness, Transparency.
That's a beautiful example of the blend of art and science coming together to convert something that, that had sudden hiccups that customers were really upset about into something that was very favorable and fabulous. Ivana, thank you so much for joining me on the podcast. It's always great to talk to you, but I, I love how much you leaned into the theme of the show.
I think the audience is going to learn a ton from what you shared and your examples. We thank you so much for your time. Oh, my pleasure.
We wanna thank you for watching this latest episode of Marketing, art, and Science. I'm Samo Advisor Lisa Art, and for Ivan Karens, we'll see you the next show. Cloud Native now is the web's leading resource for the growing cloud native ecosystem.
com is your destination for news, thought leadership, features and webinars on cloud native architecture, Kubernetes, serverless, cloud native application development, microservices, service mesh, cloud native security, and more. Stay on the cutting edge of modern application development at Cloud Native now. Hey everybody, and welcome back to Techron Unplugged.
I'm your host, Atan Solomon in this episode 24 of our series. In this episode, we're taking you to ucon 2024 at ucon. Our co-host, Cassandra Chin met up with Daniel Fury, a developer experience engineer at WE eight, and he shares how his love for music intersects with his work in technology.
He also discusses the creative process behind his music, the accessibility of AI, and the unique projects he's built that showcase the potential of modern technology. Without further ado, let's head over to Vu Con 2024. Welcome back to Textual Unplugged.
I'm Cassandra Chin, and today we're here with Daniel. Thank you. Cassandra, Can you introduce yourself?
Sure. Uh, my name is Daniel Piri. I'm a develop experience engineer at a company called Aviate.
Um, and I like to make music in my free time. You say you like music. Like what kind of music do you like making or enjoying?
I, that's a great question. I enjoy all types of music, specifically creating music. I really like ambient music 'cause it helps me connect with, uh, nature.
I go on a lot of hikes also, and so I make recordings of my hikes and I put those in my music creation software and make, make ambient music. I think it's really interesting that you like ambient music. Yeah.
Because it's not like the first thing that comes to mind when I think of genres. No, not at all. It's, uh, it's more of like an appeal to relax and like connect with myself and connect with nature.
And I feel like ambient music is way less objective in what you want to create. It's more of you work with what you get, and then you make something that you find beautiful and very personal to yourself. So, um, that's why it stands out for me.
I would recommend. So you said you actually create the music yourself? I do, yes.
Um, and it's a very manual process of listening to, to the recordings that I make and adding a bunch of instruments over that. Uh, yeah, it's, it's super fun. And I, I think I got into this mostly because I'm, I grew up using computers and I've liked electronic music, and I think just like music software has made creating and expressing yourself in that way, way more accessible, which I absolutely love.
Can you kind of describe like, the entire process of creating a song start to finish? Oof. Yes.
Um, there's always this joke with artists, right? Like, a song is never finished. You just stop telling yourself this stuff to work on.
And so usually you start with an idea or an emotion, like specifically for me. And I, I try and connect that to what I want to express. And with ambient music, that's usually like slow and the music sort of unfurls.
And then I add some, some drums. I try and add some resistance. I work with space.
And so basically you get your sample, put that in the software, right? Um, just like look for happy accidents. There's no set process, I guess.
And something, something works out at some point. And once you have an idea of all the elements that you want to work with, you start to arrange them in the way that you want the music to come out. So it's a lot, like, it's a lot like a puzzle.
You have all these pieces, you get the pieces, and then you start to, to put them in this, in this shape. But it's a puzzle that you choose. Never thought that making music could be like a puzzle.
It's not something that like jumps out when you think about making music. But, um, yeah, like I, I really enjoy problem solving. And when I think about what, what would make me want to make music, it makes it much easier to do when I think of it as like a problem that I want to solve.
And you have a start and some sort of end, you know, I dunno if that makes sense. Has your interest in music helped you want to get into technology? I, I wouldn't say so, no.
Um, so I've always been a fan of like electronic music in general. Um, I think as I answer your question, I think about it. I'm like, probably yes, because a lot of people who make electronic music are extremely nerdy.
Like they build the software that they use to make the music right. Um, and so I think exploring that helped me discover a lot of different, different softwares. Um, I don't think I'm that in depth yet where I'm like making my own plugins, for example.
Um, but yeah, I think there's definitely an aspect of music that made me interested in pursuing a software related career. I think it's interesting you didn't realize it yourself, that like, your hobbies can actually help your work a little bit. You know, it's, there's like stuff that you never realize until you think about it.
So yeah, I find it interesting also, but now I learned something about myself, so thank you. So like, how did you get started into technology? So this I can track down.
Um, my, my parents always had computers around, and I was always like, I was always the kid who would work on people's phones or like fix their settings. And so I grew up in Zambia, um, in the early two thousands. And around that time the internet was only just developing.
And so, like, we didn't have YouTube when I was, when I was a child. Um, we had these like phones and we'd browse the internet on like these Java browsers. And one of my neighbors gave me a, an old laptop from the nineties.
Um, like it used floppy disks. I don't know if you've, you've used something with like floppy disks Before. I've heard of them, but I think they're a little beyond my time.
They're, They're very old. Um, they're old for me also, like, it, it was like an old laptop that they just gave to me. It ran Windows 95, um, which I don't think is supported anymore.
Like a lot of people use it now for like these retro themes. I think you might know, like the retro boxy windows. Um, but yeah, my actual laptop had that and I started playing a lot of minesweeper.
Um, have you played that? Yeah, I've played it online before. It's a great game.
Yeah. I didn't realize it dated back that far. It, It's, it's probably one of the first games that was on a Windows machine that, and, um, pinball is like a very classic pinball game.
Um, anyway, uh, that's a tangent. So that, that laptop really opened up a lot. Um, and one of my uncles who's always done like marketing, um, he used to work at Coca-Cola.
He introduced something called Jula to me, which was a competitor to WordPress. So you would use that to make websites. And it was just like, in passing, I was like, this looks boring.
Um, I didn't really pay attention. And then one of my friends made a website and I was like, this is so sick, let me do that. Um, and so I was like, I was hooked.
I got into like computer science class in high school and we would create websites with like HDML and CSS and I was like, okay, I really enjoy this process of building stuff, right? Like, I would have an idea in my head, I would go in my laptop and I would translate that to something real, and it was like, it was a good feeling. And so I kept looking for that.
I think that's really cool. Yeah. Do you still tinker with websites Quite a lot?
Yes. Um, I think that's one of my favorite things. I, I like to think of myself as like a, an artistic person.
And so, well there's like, I like to think of myself as an artistic person, but also I have like way too many ideas that I'm just like, let's get this from the head and let's do this. And that's my favorite thing about the web. It's so quick in terms of how fast you can get something from, Hey, let me get a website and let me, like, let me put my image on a screen right.
And ship this. And yeah, I do a lot of tinkering. I build just like funky applications.
I do like timers. If it's a friend's birthday, I would build like a custom timer with like these funky stickers and then put it on the internet, send it to them, and then it's just like my way of expressing myself. And that gets really cool.
You can build something quickly and just, you know, it's really personal. Yeah, that too. Yeah, it's, uh, it also comes with time.
Like, I think when I started it wasn't as quick, but I was really, I didn't think about it as a challenge. I thought about it as, I wanna do this really fun thing for my friend or my, my mom or, um, my neighbor. And that really pushed me to get better.
Is this still more of a hobby or do you do it in your job? A bit of both. Um, it's very different types of things that I build for my job and things that I build for myself.
An example of that is I have this website, um, called Lusaka, my Laos, which is basically a visual journey on a website that goes through poems that I write and pictures that I took. So Your custom Website, my own custom website, yeah. Um, and so like my job doesn't need me to do that.
Um, but for my job, I do build a lot of these applications to showcase how different technology works. And today I'm speaking and I will be demoing something that I built. Like if you use an iPhone and you have your gallery, right, you have the ability to search through your images, right?
If you have a bunch of images of your cat that you took five years ago and you wanna find them, you could just type cat and then your iPhone shows them, right? Ideally. And so I built a demo like that in VJS.
And so it's uh, Um, how does it actually like find cats? Is it AI related? It is AI related, yeah.
It's, uh, so the technology behind it is something called, uh, vector search. And so we use these machine learning models to sort of get an idea of what images are. And so you put your images in a store and you store them somewhere, and you create these representations of those images called embeddings.
And what you do is you search through those embeddings and it understands what's in an image in a language that computers understand. And once you have that, you can search through images, like really, really easy. Yeah.
It's really cool how it can do that now. It's so impressive. Um, that's the really nice thing about technology also.
It's, it's always changing and new stuff is getting more accessible for everyone. You said that technology works for iPhone. Have you considered like Android or other kinds of devices?
Uh, yeah. So the demo i I made is a website actually, so it would work anywhere. Um, the example of iPhone is just like, it's something that was traditionally only on iPhones, right?
Very close. No one else could do that. But now with ai it's way more accessible.
So now you could use it literally anywhere. So now you're showing that really anyone can do it. Anyone can, yeah, it's way more accessible and approachable.
Also, I think AI was very closed off previously where like you people had to, I think a lot of people thought you had to go to like the best schools or, uh, study for 20 years to understand how to do these things. But now it's just, you can spend time on YouTube, you can read up a couple papers and you could build incredible stuff. When did you start getting into ai?
Great question. So I studied, uh, computer science in university, and my, my last year I did a paper on, uh, these very specific AI models that work with, uh, images, so they understand images called, uh, convolutional neur networks. And so that was six years ago.
Yeah, so it's been like six years. So you've actually been engaging for, with AI for quite a while. I, I took a pause after my undergraduate, um, and then over the past year, I, I got back to it.
So you could say it's like a year. Do you enjoy your work with ai? Does it feel new?
It feels, it's a good balance of new and familiar because I spend a lot of time doing it. Um, and it's, it's always a challenge just because like I said, it's like people always pushing these boundaries and figuring out new ways of doing things. Um, and for me, a lot of my job is taking these very seemingly complicated things and making them way more accessible for everyone else to use.
'cause I think there's a big fear with people using ai, uh, that it's this really complicated thing and I, I would like people to believe that it's not. When you say people, do you mean like other developers or kind of like consumers, Other developers? Yeah.
So like a lot of AI is done in Python and it's, it's a very, um, research heavy field. And so a lot of people who don't do research feel like this isn't something they can do. And so other developers who want to utilize AI and aren't researchers think, oh, this isn't for me.
But I don't believe that. I think anyone can do it if they want to. So, Um, I think we've had a really good chat today.
Yeah. Yeah. Thank you.
Thank you for Having me. A lot of interesting stories and I really like your touch on music. Yeah, Happy to talk to anyone for a long time about music.
And yeah, you could catch me anytime if you wanna continue. Thank you, Daniel. Thank you, Cassandra.
Thank you very much everyone for watching this session. My name is Bob Walker. I'm a field CTO at Octopus Deploy, and I'm really excited to be here today to talk to you about common problems with Kubernetes continuous delivery at scale, in terms of, of agenda for this particular video.
First we're gonna start off with a common Kubernetes deployment pipeline, just so everyone's kind of on the same page, you know what we're talking about, and we'll, I'd start identifying some of those challenges. Then we're gonna move on to some deployment scalability problems once you move beyond that. And then finally, we're gonna wrap it up with how Octopus Deploy can help you solve some of those challenges and problems.
So let's first start off with a common Kubernetes deployment pipeline, and we're gonna start at the very end of the pipeline, which is we want to get the latest version of our code up to Kubernetes. Now to do that, we're gonna be updating our manifest files, or it could be a helm chart or a customized file, whatever you prefer. And this actually highlights one of the very first challenges of a common deployment pipeline, which is what's gonna be the utility that runs QCTL apply that runs helm upgrade or Helm install whichever tool you prefer.
And so we kind of end up in this situation even at the beginning of what's responsible for this, but let's proceed along with our pipeline. It's important to note that all we're doing is we're just telling Kubernetes the version of the code that we want to run. Kubernetes still needs to go out to our container registry and download that version of the container and start running it.
But then when we need to update to a new version of a container, this is where our build server comes in. And this is like any other build server that you're used to using. It could be running Jenkins, GitHub, actions, team City, Azure, DevOps, whatever the case may be.
It's modern in your source code. If it detects a new change, then it's gonna go ahead and build it, create the image, perform the tests, any analysis, all that other good stuff that happens with your verification. 1.
This highlights the second challenge that many people encounter with their Kubernetes deployment pipeline, which is what is gonna be responsible for updating the manifest file to then give to Kubernetes. Now, typically, we see companies approach this from a variety of different angles. We've seen all requests, GitHub actions, Jenkins jobs, anything in between.
But really the ultimate goal is to get that version down to the manifest files so we can then send it to Kubernetes. So really we have two big questions to answer. Now, one of the things that you might be thinking about is, well, isn't this what GitHubs is designed to solve?
Well, yes and no. When we look at GI ops and we look at the four common principles of GI Ops, we can see that it's really more focused on how do we get a file into source control? And then once it's in source control, how can we get that to our desired system?
And then how can we make sure that that desired system matches what we have in source control? Ultimately, what this is designed to do is if we keep an eye on the bottom left hand part of the screen, we're changing this problem from a push where we're trying to push our changes from Kubernetes, uh, from Git to Kubernetes, to moving it to Argo, where a tool like Argo can then monitor our GI repositories and pull any appropriate changes in. But we're still not solving the core problems.
So let's start talking about some deployment scalability problems, because as folks start solving some of these challenges, they're gonna start seeing these problems, but not really until you get to the point where you have dozens, if not hundreds of applications. First up, let's address the elephant in the room, which is GI Ops does solve a problem, but it's really focused on solving, getting the update and manifest files to Kubernetes. Something still needs to update the manifest files and push them up to Kubernetes.
On top of that, chances are you're not gonna have a situation where you are gonna make a change to your source code and then immediately push it up to production. Most likely, you're gonna have some sort of a series of environments like a dev test, staging and production. And so we need to progress those changes through there.
But GI Ops and conversely, Argo, they're monitoring just a single file. Once that file changes, then we automatically apply it to say, our Kubernetes cluster. So what this will look like is we have our manifest files.
We'll have a say a configuration file for our first environment, and then we'll have additional configuration files for our remaining environments. In this particular case, I'm using customized with overlays. Then if we're using, say, a tool like Argo, or even if we're using Jenkins or GitHub actions, it's monitoring for that development config to change, and then it automatically will sync that to Kubernetes, and we'll repeat the same for each of the environments that we have.
Then when we want to have a new version, what we have to do is we have to figure out, okay, we still need to update that development config file. And then once that's done and it's saved into version control, then the applications will start and I'll say, oh, I see a new version. I'm gonna go ahead and sync that to Kubernetes.
And then we'd have to re repeat that by updating our test config file. And this could be done in a completely different way. Maybe development is updated by a build server, whereas test that's more of a manual process, or it's pull request, same course problem where not really problem, but it's more along the lines of we just apply that change to Kubernetes, and then we repeat that for each of our environments.
But then when we start digging a little bit deeper into this, some problems start to manifest themselves. First up, if you have the capability to approve them, pull request, and for a production config file, that means you can make changes directly into production. That's pretty scary.
How can you ensure that everyone has the appropriate controls in place and that all the approval pipelines have been followed? When you start changing up how you make these changes to your manifest files, that's scary as well. Having your build server update, your development config file, but then having a completely different process for tests and then staging in the production.
In addition to that, how do we handle anything along the lines of, say, environmental differences and secrets? Now, for some differences, we can store them directly in, say, our customized files or our manifest files or our helm charts, but there's still those secret values that we have to be concerned with. And then finally, what about the different versions?
How do we know what version is, is in what environment and is ready to test? These are all the different challenges that start manifesting themselves with a pipeline like this. Once we start adding in environmental progression, the concern that we have is that when we start solving these problems, oftentimes it's the responsibility of the application team, and they'll come up with different solutions, and it's not so bad for one or two applications, but then imagine trying to solve this problem for 30 applications or even hundreds of applications on top of that, it's common for HA to have multiple different hosts for each of your components.
So your application itself, it might run in Kubernetes, but you might have a database backend that's run on Azure SQL or A-W-S-R-D-S, or you might be leveraging file storage and you're using an Azure file storage or AWS S3 or anything in between. On top of that, how do we debug these applications now that they're running in Kubernetes, especially if we're moving off of, say, a traditional Windows or Linux application host where we're used to SSHN or RDPN into the application. So we start compounding additional problems.
What's gonna be responsible for doing those deployments to Azure sql, and how do we debug our applications? So let's talk a little bit about how Octopus Deploy can help solve these challenges and these problems. So when we take all of the different challenges and we start applying them to our pipeline, we've added environments.
We've now, we have additional cloud infrastructure where maybe we're hosting our database on RRDS. We have our backend system and files stored on S3, and then we're using Route 53 for any of our DNS configurations. So you can see all of these different challenges that are just compounding themselves on top of one another.
So we're Octopus Deploy fits into this equation is we, we will sit between your Git repository and your container registry, and we are aware of all the different clusters that you want to deploy to, along with any additional infrastructure. We also have concepts such as dev test and prod concepts of environments. 1 to Dev, what we would do is we would create a release, and this would pull the manifest files, the Terraform files, as well as the version from our container registry, and we would create this artifact that we could then deploy to dev.
We can also have that artifact also be used to deploy to our cloud infrastructure. But then when it comes time to promote it up to test, we can go ahead and push the button to promote that change, exact same processes before. And then when it comes time to deploy to production, then we can start leveraging additional things like our Rback controls where we can ensure that the person who's deploying up to production has permissions to do that.
Not only that, we can ensure that your policies are being followed by integrating with say, ServiceNow and creating a change request that then has to go through its own approval pipeline. We also have features such as our runbooks, which allow for common day two operations. So let's take a brief teaser look at what this looks like with Octopus Deploy.
So this is my application dashboard, and I can see what versions have gone out to my development environment. But you can see that these can't be promoted to test staging or production because these are changes that haven't been approved yet, but changes that have been approved and that are in Maine that can go to test staging. And then production, I have a change ready to go to staging, so I'm gonna go ahead and click on the Deploy button, and I have the option to deploy now or later.
I'm gonna pick now because this has to be pretty fast demo. And so then what what's gonna happen is now we're gonna get a list of all of the steps that are gonna run for this particular deployment. It's more than just deploying to Kubernetes steps seven and step eight.
That's what's doing the deployments to Kubernetes. But we also have additional steps where we're gonna verify the deployment, perhaps update a load balancer, as well as perform any sort of notification. We're deploying into our database changes by building out our Delta report.
We're also gonna pause the database, the deployment, excuse me, pause the deployment and notify our DBAs and allow them to review the migration scripts before they go out to our staging environment. On top of that, we can look at the history and we can see who did what, when, where, and why. You can see I was the one who triggered this, and we can also see the date in which this was triggered.
Now we're able to do all of this by looking at our deployment process, and what we can see here is that we have a single deployment process that's defined for all of our environments, but what we can do is we can turn on and off steps based on the environment that we're going to. So for example, steps four and five, we're only gonna run that inside of staging, but we get a lot of the same benefits of what we do with, say, a GI ops based tool, because we are pulling our manifest files directly from Git. So we're following a lot of the same principles of GI Ops.
We're storing our manifest files inside of Git, and we're automatically pulling, pulling those, and we're applying that to the system. One of the reasons we're able to get away with having a single deployment process for all of our different environments is by leveraging what we call project variables, where we can scope different values to different environments. In addition to that, we can have sensitive variables, which will only be decrypted when we are performing an actual deployment itself.
So if we go back to our deployment and we can see now, it should be in a paused state, and it's waiting for me to approve it. We can see the database change. I can go ahead and download the file, and I can see, oh, this particular change is pretty innocuous.
If there was something in there that looked to be damaging, I could go ahead and abort the change. But in this particular case, I'm gonna go ahead and proceed, and then it's gonna do my database deployment, and then it's gonna do my Kubernetes deployments. And we're able to deploy to Kubernetes because we've installed what's known as a agent on the Kubernetes cluster.
That's how we're communicating back and forth with the Kubernetes cluster. And then finally, we can actually see the status of our Kubernetes deployment in near real time as it's performing that. So if we wait a couple seconds, we can actually see that occur, jump back to the task log and see where we're at.
We can see where we're at. The Deploy database changes, and now we are creating the connection string secret. So now we can take a look at the Kubernetes object status, and we can see that it is finished, that up and everything looks good.
And then it can move on to step eight. We can see all of the different work that the Kubernetes cluster is performing. So that was a very brief demo into what Octopus Deploy can do.
You might be asking, what about if you're using Argo cd? Well, the good news is, is that we recently acquired codefresh, and codefresh brings a lot of the same core concepts, such as environmental progression and environments, and having Arba RAC based controls to Argo cd. And so you get a choice.
You if you wanna use Argo cd, you can use Codefresh. If you wanna use Octopus Deploy, you can use Octopus Deploy to deploy directly to Kubernetes. Finally, if you'd like to know even more, we have a white paper that you can download for free that talks about a lot of these same common problems, as well as goes into uh, deeper dives into some other topics.
com. Thank you very much.