Techstrong TV September 29, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
AI agents and Mondays never get me down. You're watching Textron Gang. Hey, everyone.
Happy Monday. Wow. Another weekend, actually, last weekend in September.
We're rolling into October this week. Wow. Time.
It just, it, it, we're in an accelerated, I feel like we're in warp speed or something. In a wormhole. I don't know.
Maybe it's the AI doing it. Um, I'm Alan Shimel. Welcome to Text Strung Gang.
We've got a lot of agentic AI to talk to you about today. And a little piece, I don't know if it's world peace, but it's peace in our lifetime. Um, we've lot to go over.
We've got, we've got the Colorado contingent in today. Let me quickly introduce you to our three is the right word. Coloradoans or Coloradan, I don't know.
But we've got Andy Mann, who sounds funny for a Colorado guy, Kimberly Bates and Mitch Ashley joining us. And of course, everyone's favorite Yankee fan, Mike Ard. And I'm Alan Shimel.
Welcome to Textron Gang. Gang. Welcome.
We've got, uh, a lot to go over today, but I, I, we were talking off camera. It has already snowed in the mountains up there, so all you guys are smiling, getting all your, your ski gear ready and your warm weather stuff. And I've never seen people who love the snow as much as my friends in Colorado.
Yeah, we do. Yeah, we Do. Swish Swish.
Yes, exactly. And just A bit of a, a geography lesson. Andy is actually from the southern hemisphere of Boulder, so that's why he has That makes sense.
So That's the Boulder Republic, right? Yeah. Republic of Boulder.
Yes. The Republic of Boulder. Maybe We have our own international, um, policies.
Yeah. Just so You know, I don't blame you. Um, but anyway, let's not go there.
Let's jump into our agenda stuff. Mike, why don't you take us out? What are we, what are we talking about today?
Well, let's get started with HashiCorp. 'cause they've been core to DevOps for as long as anybody can remember. And they have the whole Terraform project that they helped start and now are trying to commercialize pretty aggressively.
But it was interesting to watch them talk about this at a conference they held late last week. And what they're really poking at is that they're gonna start a AI project, and this is gonna start with MCP servers and it's gonna expose Terraform and the code to AI agents. And the idea here is that, um, eventually AI is gonna, I guess I don't want to say paper over, but integrate this so-called day one versus day two, IT operations mindset where things like Ansible will become more integrated with Terraform because they'll all be in using the same core baseline of AI agents.
Which kind of changes the way you think about it. It could be, you know, maybe we don't need as many specialists, but Kimberly, I know you've been looking at this space for a while. What's your thought about?
Well, just how is it gonna evolve in the age of AI agents? Well, if they can solve this problem day one, day zero, day one, and day two, that is gonna be absolutely fabulous. I think this natural progression of what we're seeing, I mean, with the announcement of, you know, what MCP stood for in terms of coming out of an, um, coming out of Anthropic, what it's supposed to do in terms of some of the unifying capabilities that it has.
And then we're seeing, you know, an ongoing pattern of announcements of people adopting that kind of architecture within their systems in order to integrate the different pieces of it. And, um, we've needed this for a long time. I mean, if you think about what happens with acquiring of the technologies by these companies, and it takes so much work to have them work together.
I mean, when I read this, I was like, you know, I remember this time in our lab when a company that will go unnamed to three, you know, one in three letter companies, it was asking us to do a test with these three to show a solution with these, these products that they could use for data protection. And the screaming and yelling that was coming out of the lab because they had like four, you know, books open, if you will, virtual books or, uh, on their desk trying to figure out how these things work together. And yet the marketing people had said, this works together, you know, but it really didn't.
And so I think what we're talking about, and maybe I'm way too far out on the ledge on, on what, you know, Hashi Corp is doing here, but it's, we're trying to make sure that, that all the pieces that come into the company, um, work together and having an AI agent or an agent AI go out there and look at all these pieces that's going to find some things that maybe us humans don't detect as long as we have somebody that's overseeing the kind of work to be able to start to unify this, these pieces together. And I think that's got some, you know, real possibilities. Um, you know, you guys are better DevOps people than I am, but, you know, that's kind of my, my looking at, you know, what this does.
And it's got great opportunity and it's got some risks to it, but we'll see how it happens. Maybe I could take those three Runbooks and figure it out for you, Kimberly, but Yes, totally. No, it was RU that was trying to do this, and it was loud.
It was ugly. No, RU was struggling with it, man. It, yeah.
Oh, complex. Well, you know, it, it's interesting because we'll see, I think we'll see a lot more of this of IBM, red Hat HashiCorp coming together more in their product strategy, um, but not just in a communications way of getting the products to work together. I mean, you think about it, what more of a natural fit than using not only Terraform and Ansible, but using AI to help automate those things together and start, start to cross those boundaries.
So who knew that, you know, AI would create the kumbaya moment to help Kumbaya moment to help us kind of get these things working together. But I think we'll see a lot more out of this. And, and, and if you think of where we're heading, yes, terraforms been the automation platform for infrastructure as code.
Now you can do even more of that with, you know, automation through AI and through GI and make it much more declarative along with other tools at the same time. So it doesn't have to be just Terraform that you're automating. Um, HashiCorp released what they call the, I think it was GA of their, uh, HashiCorp stack, um, Terraform Stack, excuse me.
And that, and that, and that represents something that's not just within one environment, but across multiple environments, multiple clouds, et cetera. So it's, it's a, I think a succession of things that we're gonna see from HashiCorp, but also most likely IBM and, and, uh, red Hat in the near future. Yeah.
Look, I think it's really interesting to see the integration happening. It was always gonna happen this way. Uh, IBM is a master at acquisition and integration, right?
Uh, and so getting, uh, HashiCorp alongside, uh, Ansible some time ago, this was v obviously going to happen with the very important for IBM to integrate these products, provide that sort of combined offer. I do wonder a little bit if it's, uh, very customer driven, you know, Ansible look, great product, great solution has been around for a long time, but a little bit of a fading star. So it's interesting to see whether IBM can sort of relight that star by injecting this ai.
But I, I'm, I'm totally with you on, on the logic of the AI injection here. Actually, uh, Mitch, the config is a knowable outcome, right? So when you're thinking about provisioning and configuration, um, I hate the word best practices, the known good practices in configuration and provisioning are known notes.
So we've been talking, but yeah, we've talked about this quite a lot. The idea that this is the sort of thing that AI works really well with. Mm-hmm.
Um, and I'm super excited actually seeing them release, uh, stacks. I saw them announce that last year, and I'm like, oh, it's pre-announcement. Is it gonna be what it needs to be?
It really is. And that, again, is very logical for the integration of all those piece parts and components and all on the sort of open source side of the house, right? Red Hat OpenShift, uh, uh, Ansible HashiCorp, this is a really good play for IBM, uh, bringing in a lot of opportunity for customers to provide the, you know, this end-to-end automation, the end-to-end platform engineering across, as you said, Mitch, multiple different estates.
So look, this is gonna keep going. We're gonna see more and more of this. This is great for IBM and great for its sales reps.
Uh, we'll see if the customers actually pick it up though. Um, very excited for Hashi Corp. A little bit less excited for the Ansible stuff personally, But it's also, I believe if I'm looking at this and understanding correctly, they're looking be, it's not just Terraform and Ansible.
It's, it's looking well beyond that in turn to the other disciplines that are going on and the other environments. They're, It's not just I, IBM m either they Talk about Amazon, you know, Microsoft, and, and, and kind of what I was looking at as well, is this, this bigger trend of what they want to, you know, what you're gonna be doing and what we should expect to see this replicate into some other companies doing similar kind of things to make life simpler, if that's possible. So let me play cynic here a little bit.
I'm glad to see that there's anyone left at HashiCorp who worked on this. 'cause I, I thought, I thought the brain drain was pretty severe when, you know, from the acquisition and the, and the whole open source wars. Andy, to your point, HashiCorp, you know, part of the reason that they're part of A IBM is, you know, they, they, they, they had a little run in with the open source community when they changed their licensing.
And, you know, had they not, I don't know if they'd be part of IBM today, to be fair. You know, you, you mentioned IBM is the masters of, of, uh, integration of acquired companies and skill sets and products, you know, but their philosophy's always been that you gotta break a few eggs to make an omelet. Mm-hmm.
And, and some things do get broken. I, I think there's almost like a, a natural progression to assimilation by the Borg. Um, I, I think first you go through this brain drain phrase phase, you know, the people from the acquiring acquiring companies have cashed out their stock options and they're moving on.
Then there's the IBM, let's not just let 'em be for six months before we come in with our drones. Then there's the assimilation phase where it seems like, oh my God, they're gonna break this thing. And then eventually it comes out the other end where, you know, they kept 60 to 70% of what the company used to have, and they've integrated into the IBM portfolio, and we'll keep it there until we send, sell it to some Indian company where software goes to die or something.
Right. That, that's the life cycle of an IBM acquisition. Um, I, maybe it'll be different.
I, I do think there's an affinity between Hashi and Red Hat in general, not just the Ansible, right? They do share open source roots, though. They both change their licensing to a certain degree.
Uh, they both play in that DevOps space developer space. And it'll be interesting to see how they come together. But today's red hat isn't the red hat that we all knew as the darling of the open source industry either.
But there is a trend Later. It's also what, it's 10 years later with the Red Hat. Yeah.
And I mean, they didn't, it didn't start changing until a few years ago. Really? Yeah.
No, it Red, red Hat retained, its, its Raleigh attitude. Mm-hmm. Right?
For, for five, six years, I think. Yeah. Mike, I'm sorry, go ahead.
I think it's pretty obvious. And a lot of these companies just simply don't care all that much about the great unwashed open source masses. They're after corporate enterprise customers and the people who pay for stuff and all the rest of that community stuff is, you know, will salute it as we drive by.
You know what? But that's the same people who say DevOps isn't about culture. DevOps isn't about people, then it's all about tools.
And there are people who do say that and do, and companies that act that way. But sooner or later they find out that it is about the culture, and it is about the people. So It thinks very much a financial interest meets business objectives.
So let's change our model, right? So we can demonstrate more direct value from this open source that we've created. And that's what happened in Red Hat happened with Hashi Corp.
And, and we will continue to see that over time. I, I think one of the things that we, we haven't talked about yet is, what's interesting about this is ai, particularly generative AI, has an affinity for structure. And that's why it's so good at code.
It's why it's so good at ingesting JSON structures. And you put prompts and things like that, and you, it's less likely, and I don't have data to prove this, but it's less likely to hallucinate when it's doing those things because it's operating in a much more structured semantic world. When you think about infrastructure, whether it's terraform, whether it's automation with Ansible, or pick your favorite tool, those environments, I think we're gonna see a real revolution in how AI will help us not only manage, but construct infrastructure across product, across environments.
As that gets better and better, um, maybe we'll have some more flexibility. Maybe we'll have a little bit less technical debt. I'll be optimistic.
I'll play your, the optimist to your cynic. Um, maybe we'll have a little bit less technical debt, or at least technical debt that can be solved, uh, in a reasonable timeframe. But I'm, I'm curious to see where this will go, because I think there's a lot more possibility here because we're talking about code and not writing text for your document.
IT management is code it MAC. Mm-hmm. Okay.
I think it's, IT management is code for everybody. I think the part of this that I'm excited about is that you, you may not necessarily always have to be a DevOps specialist to automate stuff using code. Yeah.
I think that's gonna be pretty cool. Love it. Well, if it works, what's that?
There's always that Andy will remind us. Oh, yeah. And who's gonna operate all this stuff now?
It's always the question, isn't it? Right. And look, I'll be, I, I, I'm actually energized by the idea that we're, we're seeing some really interesting, uh, innovations from what our fundamentally ops companies though, right?
Um, Ansible, HashiCorp, uh, even Red Hat, uh, we've seen so much great AI innovation in the dev sector. We've talked about Claude and code and five coding and all this sort of stuff. But, you know, a lot of, a lot, not all, a lot of the IT ops environment is knowable, you know, good known practices around integrations, around, uh, uh, provision, around configuration, around security scanning, you know, these sorts of things.
There's a lot of goodness there. And if we can take that, uh, mundane routine work of figuring out configs out of human hands, then we free up IT ops to do more interesting things around architectures and development and stuff, um, and DevOps. So yeah, look, I, I, I will always stand up for my ops peeps.
Uh, they are the ones who s who who, who bear the brunt of so much of this. But in this case, they're actually the beneficiaries. And that makes me happy.
All right? If Andy's happy, we're happy. Let's take a break here on the gang.
We'll come back to our B block, which is also around agentic ai, but a little different, uh, this is for, uh, AI agent management, which is the race has been on a long time, but you're watching Textron Gang, You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders. Lives depend on your decisions.
Your home life included that work. You are protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity. Your digital front door is wide open.
And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk.
Black Club, digital executive protection, defending the new attack surface your personal life. Hey, folks, we're banking, as Alan alluded to. Yeah.
There is a fight now on as to who's gonna be the dominant soul or platform for managing all these AI agents. Salesforce just came out with a version of MuleSoft that orchestrates and manages all these AI agents. But then there's a little company called Glean that took it up a little bit further and said, here's this entire AI work platform, and we'll manage all your AI agents for that.
And by the way, and users won't even have to know anything about prompts or all this other stuff, because the graphs are gonna be super smart. But, you know, as you kinda look at all this stuff, let's start with Andy, what's your take on what's going on here? Because to Alan's point, these are just one of maybe two to three dozen entrants that are gonna be in this space.
So is this the new, the new big fight in it? This is innovation disruption. This, I'm, I, I live for this.
This is so awesome to watch. You know, uh, Salesforce has got good property there for with MuleSoft, you know? Great.
We're talking about integrating and managing AI and AI agents across the estate. Uh, as we get more and more AI agents, of course, they're gonna talk to each other. This is the API economy.
We're now talking about the AI agent economy. Uh, and it's, it's essentially a similar kind of thing. So this is why MuleSoft is in a really good position to stake a claim on winning this space.
Uh, they've got great integrations across a broad s swathe of it. Good integration. This is a really strong opportunity because ultimately we do need to manage these IT agents.
They're just like people, right? Where we've, I think we've talked about this, the idea that I get my agent to do some work, and then it talks to another agent that do some work. These are sort of like managing people.
You need to understand what the connections are between them, whether they're performing well, whether they're making mistakes. You need to be able to get them together to work well together in groups and teams. And so, bringing in together multiple agents, and every time we do this sort of thing, we face complexity.
So two agents talking to each other, pretty straightforward, just like two APIs. But we get a bunch of different APIs, or in this case, AI agents talking together. And now we've got death star architectures again.
So we definitely need to have this management layer. And Salesforce is gonna try and stomp the terror, but then this is a disruptive moment. There's no reason why Salesforce and MuleSoft should be the dominant approach when you've got smaller companies like Glean using newer and more interesting, uh, approaches.
You know, looking at MCP servers, defining, uh, your environments, having the agent reiterate itself so that it creates better prompts so that it does its job. Better agents working on continuous improvement themselves. So these already interesting opportunities for disruptive tech.
Yeah, look, Salesforce has got a huge customer base. It's got a dominant place in the market. MuleSoft is good technology, which seems to apply really well to this space.
But this is a new space. And so every time we have a new space, we have this disruptive innovation. And I'm excited to see it.
Well, in the second Star Wars movie, during the Agentic Wars, there was a phase where the AI control planes were battling it out. And that's actually what we're living out today, is, is we're entering this phase of who runs the control plane for agents who runs the observability plane for agents. And I think what we're gonna, we'll see a lot of introduction of technologies to do that.
The question is, will enterprises adopt one a couple? Will they go with a, a known player that they've been working with, you know, ServiceNow introduced their own AI control plane. Maybe it's a Splunk, who knows where this is gonna go?
But to your point, Andy, this is a, this is a period of peak innovation where it's, it's, we're seeing a lot of things come out that yes, there's a need for it. And it's not MCP standard that everybody says yes. That's the answer.
It's everybody has an answer. Which one's gonna win the end going to, to be the ones that survive? So, Mitch, you are wrong about the second Star Wars movie, it was actually Empire Strikes Back, and that's what this is.
I meant in Chronological, you meant in chronological water. But in terms of release, it was the Empire Strikes Back, and they're knocking out the Rebel Scum. Yes, sensei.
I, I Agree, like glean and stuff like that. But seriously, this is, and, but that's a very good analogy of what's going on in this market right now. Let me explain to you why I say that.
I'm watching to see, is AI a big boys game, right? When you go to a VC and you pitch, and we've all, I think most of us here have pitched to VCs, right? What do the VCs look for?
Is it a big enough market? That's the first thing they want to know, right? Is it a big enough market where we can make a lot of money?
Well, agentic AI managing agentic, uh, AI is a big market. Secondly, what's the barrier to entry? Is there some proprietary IP patents that you have?
Or, you know, can anybody come along and do this? Is somebody with more resources just gonna come along and do it? Are you gonna be the missionary who hacks the path in the jungle and someone else just walks through easily to this point?
AI has been a big boy game, certainly in the us right? That was, I think, part of the big thing with deep seek. The Chinese did it on a shoe string.
You didn't have to have billions and billions of dollars, just millions. I think when it comes to managing agents, and we all realize what a golden opportunity, what a pot of gold this is at the end of the rainbow. 'cause we're all gonna have agents upon agents, oodles, and oodles of agents, and they've gotta be managed, right?
Someone's gotta do this. Now, most enterprises, I don't think are going to, and I, and I don't mean this in a bad way, but they're not gonna trust some company named Glean to manage all their agents. They're gonna go to the big boys that they, to the empire, right?
To the Darth Vader and, and Admiral Thrones of the world. And those are Salesforce and ServiceNow and IBM and names that, you know, like that. Now, historically, what happens in the tech space is that the innovation doesn't reside with those people.
The innovation does reside with the gleans of the world. But what happens is when the gleans get too good, one of those empires buys them up, they take over the planet, right? And, and that, you know, big fish, eat the medium fish, the medium fee fish, eat the small fish.
That's the way of it. And the way of tech. And I think that's what we're gonna see here.
I, you know, you might, you might get one company that's kind of a new name that'll break into this as an AI manage, as an agent management platform. The rest of them will get bit bought off by the big guys, because the barrier to entry on this is going to be very, very high, is very, very high. So, Yeah, to your point, to your point about that, I think the issue is who has access to the data and the legacy apps.
'cause that's what the AI agents need. And if you're a startup, you don't have that. You gotta go build all those different connectors and go try to install that.
And I think whether it's, uh, MuleSoft or a Boomie or any of those integration platforms, they have an advantage there. But that's just my take. Is there a barrier to entry with the quality of the work that you're doing with semantics in terms of integrating those pieces?
Because when you look in technologically, you know, what you're saying is that I don't want, a company's not gonna adopt it unless it's a big company, because it's such a big control plane, right? Mm-hmm. So that's, that's one barrier.
But on the other side, the quality of the data piece of it, which is the semantic analysis of looking at all these pieces, that is really tough technology. Yeah. Um, and so a company like Lean or, or others that are coming up that have unique innovation in terms of how they do that, that becomes, I think is the core of the, the barrier.
And, and that's why someone, someone will pay a couple billion dollars for them, but it's chump change. It's not chump change to glean or their employees, right? Or the VCs who are looking at a 10 X are on it.
But, but to an open AI or A IBM or, or a Salesforce, it's chump change. I wouldn't mind a bit of chump change Me either or a little less. But that's, but it, so again, I, I've been in tech 30 years.
Yeah. For the most, 90% of us live off the, the breadcrumbs that fall to the edge of the table from these companies. That's the way it's always been.
You know, Alan, I think your, your analysis of how this will unfold is I would've given the same story, right? So the innovation happens here. Somebody will pick somebody up, and the question is, does does one of these kind of catch fire enough to capture intention and that gets acquired?
Or is everybody say, I need one of these, and they gobble up early before it's Really, well, they, you know what Brad Feld though, he says, right, you gotta be in the top three, because those are the ones that'll get gobbled up early and get the lion's share of the, of the pie. Now. But at every, here's another thing I've learned in 30 plus years of doing this.
At every technological rung like this, there's always one, maybe two companies that achieve escape velocity. Mm-hmm. And they become the next big guys in the next round.
So in the whole generative AI thing, right? Think about all the companies that were trying to do models and doing everything open. AI clearly is a, a, you know, going on in the next round.
Congratulations to Hunger Games of Tech. So open ai, you know, may this, what, what's the, what's the term from Hunger Games? May something smile apart, maybe the odds be in your favor, right?
Open AI made it through Anthropic. Yeah. I wouldn't be surprised if one day they're just part of Amazon, you know, call it as they see it.
Mm-hmm. Um, but this is, this is the way of the world. This is, you know, this is the Way, so the competition then go ahead.
The competition then becomes between, which as you started out with Salesforce, ServiceNow, potentially Amazon, The big guys. Those are the big, so, so that, but that still is a big decision for Yeah. A it organization to decide which one of those big companies I am going to stand Up.
Isn't that the turf four that we, they fight every day. Yeah. Is in IBM always fighting Microsoft?
Isn't Microsoft always fighting? Google is in AWS. Right?
And then, and then sitting on top of them, you have the Accentures and the, and you know, the big integrators who they line up with, though, we all know, they'll line up with whatever makes sense and where, where they're gonna make the most money. Um, you know, the old boss, same as the new boss or the new boss, same as the old boss. There's another new boss though.
And you mentioned that. And that is, does open AI by one of these companies to help propel them? Absolutely.
Accelerate them to that escape velocity become one of the big behemoths to be able to do this. I, I think they're well on their way. You know, I, I saw a video the other day of Sam Altman, Sam Altman in Abilene, Texas.
And my, my son used to be a TV sportscaster in Abilene, Texas. I've been to Abilene, Texas, you know, and he's sitting back there and they're building this Monmouth AI factory. And it's, and it's Sam and, and uh, uh, SoftBank and Oracle, I think are the three partners in that particular one.
And they're building a power center. And they're, they're talking about using a gas powered, power centered, you know, to keep all those cowboys happy. But if you've ever been to Abilene, you know what you see for miles and miles?
Windmills. Windmills, because it's really windy there. Mm-hmm.
And, and that's what's gonna really power those AI factories out there. But clearly Sam, Sam is gonna be, uh, Steve Jobs, bill Gates, you know, surg in Larry or whatever you want to, you know, whoever it is, they are moving on to the next round. You see all those windmills.
'cause there's nothing, it's all flat. There's nothing to stop the wind. So, well, No, there's some hills out near Abilene.
I think there hard, but it's pretty much, yeah, I don't wanna miss, sorry, Andy. I'm So Set. You know what?
That's the Colorado in you guys. Yeah. You guys in your hills, Right?
Size. Some of us say size doesn't matter. I, yeah.
No, no, no. So I'll let Andy talked for, um, but I gotta say this. I don't wanna overlook what, what you said, Kimberly.
And that is, I think another big play here is the, the semantic graph, the, the, um, database side of this. Um, so we talked about a Neo four J or maybe a Clean, or some one of these other companies to really accelerate adding that con contextual information that you need. Mm-hmm.
It's gonna be a super play in this. So I'm gonna play Alan for a minute. Andy, what do you think about this?
What would you like to Say? Oh, yeah. Look, I, I, I just think that it, I, I'm not sure that I necessarily agree with Alan in this case because, uh, this is such a radical revolution.
This is virtualization or the internet or cloud, right? And in some of those cases, the first mover had the big advantage and some didn't. In this case, I actually think that the first mover has advantage because, um, someone like a Salesforce is able to lean into all its existing work on integrations.
And so, look, MC P's gonna make a huge difference in terms of agents working with each other. So maybe Glen gets a handle on it, but they're gonna go down one direction. A smaller company that can only focus on one direction.
They can't spread their peanut butter too thinly. Salesforce is gonna spread their peanut butter all over the place, and they're gonna go with what works and what wins. So look, it may, I, I, I thought it was interesting, you maybe Boomie, it could be a couple of other integration plays mm-hmm.
Like a step logic or something like that, right? The integration players have that leg up. And so I think in this case, first mover advantage makes a difference.
Um, and not just because of that large enterprise play on the trust factor and the relationship. You're right, Alan, you know, a a a huge enterprise is not gonna go with GLE for its entire estate, but you know what one or two teams are. And if that happens to be on the right path, then that could pop.
But I don't, you're telling me it's a new paradigm. Things are different this time. You know what I'm gonna tell you the checks in the mail Fair.
So I, so I wanna know on this Star Wars, I wanna know on this Star War or the, on this analogy you guys are using here around the empire straight back. So exactly who is Emper Palin in this, uh, little Emper drama? This one?
I, I would think it's Mark Benioff, Not Sam Al. Sam Altman's leaving the Rebel Alliance. Is that what it is?
So why Sam, Sam Salesforce is, is the big dude. Yeah. I mean, because there's so many more application environments.
I mean, Salesforce is only one major, granted, it's a major piece of the application environment for a company, but it's, Has I I agree. And they were first Into this. You're not rrp lemme tell you, they're not ERP.
No, they're not hr. Mm-hmm. Nope, They're Not.
But Salesforce is a big dude in it. It's a big Dude, I think. I think.
And so I think about, okay, so I am, as I, I'm responsible and maybe I'm looking at, you know, the, the 10,000 employee kind of place, right? Where I've got a unique group here, I'm gonna be doing my development. I've totally, I don't talk to the other guys.
I have nothing to do with, well, I had occasionally I, I'll have to work with them, but, so I'm gonna implement mine. And then the other guys, you know, and then somewhere along the line it starts bubbling up that they've, they've advanced on this kind of technology. One person talks to another person.
Uh, I'm not, I can hear where you're saying, you know, v VMware kind of virtualization of this, but we're talking application space, and they tend to be unique and they tend to be somewhat separate. Here. Here's, I think a point to make about that camera Lee, is we're talking about the control plane, which is an operational security right?
Aspect of this. Does that, you know, you come, may come with your application environment. Yeah.
Like a Salesforce or ServiceNow. Eventually that rolls down into an ops role. The, the world say, wait a minute, that's all you guys.
Oh, it's self fun and games. But it's, it's real here. Let's talk about what tool we're gonna use.
I wonder if we're gonna enter that kind of a phase where we No, but you could see a place for an SAP or an Oracle. You know, I do Glo I think, I think Larry Ellison and I think Larry Ellison and Oracle is gonna be a bigger emper than Mark Benoff ever dream to. I mean, Mitchell though, Sam Altman clearly has all the potential to be a young, uh, Anakin Skywalker.
Yeah. Yeah. And, and wind up a sth.
Lord, I am your father. All right. Hey, let's take a break here on the gang.
We're gonna come back for our C block. We're gonna get off the agent AI for, I hope this one and talk about, uh, politics makes Strange Red Fellows, and there's cult for World peace. I don't know.
You're watching Textron Gang. Discover Textron Group, the Epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Alright, we're back with the C Block.
And as Alan suggested, we are not gonna talk about AI agents. Everybody got that? No AI agents for this section.
If anyone mentions AI agents shots. Go ahead, Mike. So, um, it turns out that Docker and the folks over at the Cloud Native Computing Foundation have had a little, I guess the signing of a Peace Accord is about all I can kind of describe it.
And they're gonna work together and kind of try to make things, uh, better for most end users. I feel like this has been overdue maybe a long time in coming. I seem to remember back in the day, Docker Khan was the biggest show in town, and then CubeCon came along, and it looked like Docker never got over the fact that they got usurped by CubeCon.
And there was just bad blood in the system for a long time. But Mitch, is there more to it than this? Is it just politics?
Or is there some technical aspect of this thing that leaps out you? Well, I'm not gonna say the, you know, a word that we banned from this segment, but, um, I think Linux Foundation, CNCF, is the senate of this analogy where things kind of come together and happen together. And that, that's essentially what Docker has done, is, is aligned with CNCF to say, what can we do to solve some of these problems with, at the very introduction of creating open source projects, bringing libraries, um, whether it's an MPM kind of issues that we've seen happen, and GitHub aligning to do those to help solve some of those problems.
We're seeing the technology providers aligning with open source organizations to say, how do we move further into the earlier into the cycle? So you aren't pulling stuff out of repost that's already has issues in it. You aren't using, uh, container images that have issues inside of them.
Uh, we have, we have now methods to be able to, uh, use these policies, use these principles, let's align that at the project level, scan code, do all these things that we know are good, useful things. So I think we're gonna see a lot more of these alignments with the Senates of the world, with the CNCS, with the Linux Foundations to say, here, we're gonna help have our technology help what you do at the open source creation phase. And hope that that kind of helps them accelerate their, uh, access into other development organizations, enterprises, doing software development using those same technologies.
Because we used it here. Let's use it Here. So I think somewhere in the many alternate universes of the multiverse, there is a universe where Docker Swarm is the standard orchestrator Oh.
For all cloud native container based applications. And Docker is, has a market cap larger than Salesforce, and they build a big building in the Embarcadero, uh, in, in San Francisco. And, and the CNCF is just another one of the 40 some odd organizations that the Lennox Foundation manages.
Oh, that, that's dark. That's really dark there. Well, no, there's, you know, and as Carl Sagan would say, in a universe of billions and billions of stars, right?
Anything could happen. But the fact of the matter is in the universe that we occupy, and Docker, Docker had this in the palm of their hand. And Mike, to your point, I remember being a docker con in, in, uh, in Austin, Texas, and we were thinking about launching a site around containers, and I wanted the site to have the word docker in the domain name, but Docker, of course, owned the ip.
I couldn't. So we decided to make a, a site around with the word container in there. And I went down to Austin, Texas, and I came back.
I said, you know, there's something, this other thing called Cuba, something that the Google people had that is now open source. And everyone's talking about the, but I don't think it'll catch on. It's way too hard.
And of course, I'm still here. And in that alternate universe I'd be sitting with, uh, who, who was the founder of Docker. Uh, he was their CTO, don't remember, I don't remember his name off the top of my head right now.
He has another company. Anyway, Yeah. I, I, look, I'm, I'm gonna take a marginally, uh, uh, negative view on this one.
Look, uh, I feel like I'm in Cino Man or something at this point. I'm waking up and I'm like, what century is this? Docker?
We're talking about Docker. Look, don't get me wrong, we're still using Docker and Area State. Uh, it's good.
But they blew the opportunity of a lifetime. You are, look, you're absolutely yes. In, in that alternative universe of yours.
Uh, and by the way, I'd love to live there. That sounds like a fantastic place. Uh, in that alternative universe.
Uh, yes, DACA could have been everything to all people. It was such a good technology, and they blew it in a way that someone like an AWS or a VMware or Kubernetes did not. And so we're, I feel like this is a lagging indicator of Dockers trajectory, the idea that we're now getting into bed with, uh, what is ostensibly competitor.
So this is not innovation. This is chasing a tail. Mm-hmm.
So look, I, I think it's possibly good. I don't think it solves a lot of problems for a lot of people, but it really makes me wonder, it makes me sad for what Docker could have been. Yeah.
No, it doesn't. Just, I remember going to the, I, I remember going to the Docker offices right? By the Embarcadero for Pratt's briefings, Solomon hikes, by the way.
And Mitch, I didn't, I don't have a, a computer here to look stuff up. It just, I, I, I, it hit me, um, for you, Solomon was the founder of Docker. I remember going there to interview him.
And you know, they were a little arrogant, to tell you the truth. Andy, if you remember right. They, they really, they had the tiger by the tail, and they thought they knew it.
But, but we're not talking about that Docker, that docker got broken up. They sold half their crap to Mirantis. They open source the container, which is, I think part, you know, is just open source.
I think CNCF might even be managing the container, uh, images. What Docker is today is a repo. Mm-hmm.
It's a repo of what's supposed to be, what is supposed to be secure container images. Right. You download, no, Mike's giving me this.
I don't know, Mike, what do, what do you got then? I think, I think there's, there's a small sliver of those images that are certified and validated to be secure On the rest. Oh, you're, you're taking exception with security.
I, okay. I I, yeah. I'll Give it to you.
The rest of them are just basically, you know, Garbage, not garbage. They're just what people put up there like in every repo, They're, they're, they're a take your chances kind of thing. Yeah.
But every repo is like that. You know, part of the issue is we, we live in the wild, wild west of repos, But isn, I, I think that's What they're trying to change With this alignment. Well, that, and that's what this is about.
Yeah. Yeah. Seems, I'm sorry, Kimberly.
Well, this seems to, what it's doing is giving breathing air into Docker and those people invested in Docker, which is pretty, seems to be pretty extensive. And it gives life to those environments to continue to extend. Or am I missing something here?
No, No. It, I, I think it does, but I, I think really what this comes down to is supply chain security. I think, I think the biggest, and I know I, I wasn't on earlier this week, you guys did that open source, uh, thing.
I think it was yesterday, Mike, or last week, right? Last Thursday or Friday last week. Um, I think the biggest issue facing open source development security DevSecOps, is supply chain security.
SBOs don't solve the whole problem. I think the, the, the biggest single issue in supply chain security is that 80% of the software, 85% of the code in our apps is be, are being downloaded from repos. Whether it's a docker repo of a container image.
So I can quickly build a, a cloud native, uh, app or, or, or an artifact from Jfr Artifactory or something from Maven Central or JavaScript or whatever, bad code malware. We, we saw it with the, uh, the shy haud, the worm last week or the week before. That's how bad stuff's getting injected into our software from software.
I'll Give you an alternate reality though. Think about this for a Minute. I you give this one, but go ahead.
You give us, it's the all convinced you can have your own reality give, I I, I'll give you a whole other possibility. So GitHub is getting sucked up into Microsofts, and now the open source community rallies around the repository from Docker instead as an alternative. And they build out their own little ecosystem.
And by the way, they make it a little more secure than what GitHub has been historically. So maybe there is another future for Docker. Yeah.
And Docker as the repo for Cloud Native is perfect. 'cause it's containers where the other stuff is snippets, artifacts, you know, what have you. Yeah.
But critical mass and GitHub is gonna be extremely hard to overcome, I think. Oh, I'm not saying GitHub's going away, But to overtake it, I think is pretty big challenge. But, you know, maybe, you know, maybe Thanos could do it, but I don't know if anybody else could.
There you go. I'm Iron Man at The projects, or did, Um, but we'll, we'll see. But you know what, good for Docker, because A, as I said, the, you know, Microsoft isn't the Microsoft of the nineties when you talk to them, it's not Steve Balmer's, Microsoft and Docker isn't Solomon, he's Docker either.
Not at all. Yeah. And, um, I, I, you know, if if it, if it's good for the community in, in terms of a more secure supply chain.
Yeah. But I see here's here, I, here's where I don't know that it really does serve the community or serve customers particularly well. It's a step in the right direction in some cases.
But look, if my team just downloaded anything from Docker hub and put it in prod, I'd have their guts for guards, right? And so it's like the V store, remember V apps, we were gonna solve the software supply chain issue with v apps a hundred years ago. And again, it fell into the same problem.
If we don't have maintainers, if we don't have, uh, you know, people who are, are tasked with authority to maintain these images and certify them in some way, then again, it is the wild West. So I just like VAPs, there was no control over that. Anyone could load a V app.
There's a big difference between that and say the iStore or whatever it is. Um, or, or the Android marketplace where these things are tested and verified and there's a governing body which says, yes, this is okay, this is safe. Even then stuff gets through, right?
Um, but when we've got the wild West of yeah, a GitHub repository, a docker hub or whatever it is, if there's not some mechanism, some authoritative mechanism for developers to know this has been tested. I don't need to test that. And oh my God, I just hate the, the idea that my developers would say that phrase ever.
Um, but that's, that's where it's gonna be beneficial. And I don't see them doing that. I just see them providing more, I won't use the word slop 'cause they provide attaches to a different conversation we're not allowed to have.
Uh, but it, it, I don't see that this really does serve the community that well, because you're still gonna have to go through testing and compliance and governance checks and all the stuff on someone else's repo that is unintelligible for you in a lot of ways. So, I don't know. It's, yeah.
For, if it's a good repo that you can use that has the right things in it, that you are prepared to check and validate, great. But I don't know that this does that. I think, I think though, the, the thing we have to remember is this happens at one point, and that's the developers.
The developers are the ones who submit these things, right? The code to the repo images, to Docker, et cetera. And maybe we're seeing a little bit of a shift, um, GitHub announced their, uh, trusted publishing.
They're implementing some of those standards as part of putting things into GitHub, more of an aggressive force enforcement. Maybe it's a lightly aggressive enforcement. Where we see the, the, the dockers and the, and the open source projects and GitHubs, if they start to enforcing some of these things, I think we're we'll likely to see better security implemented because of it.
It's still gonna take developers' effort to be able to do that. 'cause at some point, if it's a bigger hassle than it is worth their time, they'll find another way around it. And that's when your alternative universe happens.
You know? But, but Mitch, we, we are seeing it too. I mean, Seuss Seuss announced their own container image, you know, certified containers of secure, like the most popular stuff you're going to use.
Mm-hmm. And I've seen others do it. I don't remember who, if it was Muntu or, or one of the Chain chaining Guard is probably the biggest player in That space.
Yeah, right. Where they're giving you, they are, you know, use our repo, basically. 'cause we're, we're saying it is.
Um, but look, let, let's see how this plays out. We'll, we'll be a cube con in, uh, I guess it's November, um, in Atlanta. And, uh, it'll be interesting to see how the community is, is, uh, adopting to this.
But guys, we're about outta time here. It was, I just wanna, I just wanna say there's gonna be baseball in October in New York, so we're happy. Ooh, that's right, Mike.
And they, you know, so are they in first place now, or they're tied. And if it's a tie, the Blue Jays are the Well, this is Monday and through the magic of the internet, we won't really know because it's Friday. All right.
We'll know, we'll know soon enough. Anyway, my Coloradan, thank you for, uh, coming on here. Let's pray for snow.
Yes, Mike, I pray for Yankee Winds. I, there's a lot of things I pray for World Peace sanity in this world and everything Else. Oh, we got World peace cnf.
C-C-N-C-F and Docker. Yeah. D well, CNCF.
And Docker can make peace. There's world peace. Peace.
There's hope. There's hope. Um, we'll be back tomorrow though, God willing, Tuesday for, for more Textron Gang.
Until then, as a reminder, as always, we have Textron TV immediately following this. So stay tuned for that. If you're not watching this as part of the Daily Stream, whether you're watching our Textron tv or our Textron tv, uh, YouTube channel or our Textron tv, OTT channel, apple, uh, apple, Google, Amazon Fire Stick, Roku, or Apple tv, check it out there.
But for now, there's Alan Hummel. We're out. Hey everyone.
Welcome back here to Techstrong tv. I wanna introduce you to a first time guest. I love doing first time guests on here.
His name is Dominic Richter. And Dominic is the, uh, CPO Chief Product Officer and a co-founder at a company called Mondu. Dominic, welcome to Text Drug tv.
It's great to have you on here. It's less to be here. Good.
So, co-founder, chief product Officer. You, you didn't wake up in a cold sweat one night and say, I know just what I want to do. I'm gonna go found a company and, and, uh, you know, put myself through this for a couple of years and hope, you know, we hope against hope.
I'm one of the, we're one of the ones that make it. What, what, how did you wind up co-founding Mondu? What have, what's your journey been like?
You know, I've been in security pretty much all my life, uh, studying, you know, from hacking school networks to university, and then finding my job in security. But the thing with security has been that I've been sitting on the attacking side for a very long time. And then one day decided, Hey, I've gotta switch sides.
I gotta see why is this so hard to secure? And in trying to defend it, um, I created a first startup in 2015 that did policy as code, actually mm-hmm. On the first frameworks to market, um, and brought security and the defensive side, IE the platform teams closer together.
And ultimately all of that led me to mondu today. Excellent. Excellent.
So you're co-founder. Who else founded the company with you? So we have a few others.
Um, we've got Christopher Hartman. Um, I, him and I have been working together since the Telco days. Um mm-hmm.
We've got Sue Choi, um, who has been in the, in the scene, especially with OpenStack and Chef software previously. And then we have Patrick Minch, um, another one of my, uh, co security, uh, hackers, um, who has been a co-founder of this as well. Very cool.
Um, so let's talk Mandu. What, what, what, you know, what's it about? What does it do?
What's the mission? So our mission is to reduce the attack surface of the world, essentially. Um, we decided that what we really want to do is not just add more findings to your list, but we actually want to help you to get better and help the world in having fewer security issues.
We know it's not an easy, uh, thing to do out there, but, um, we've wanted to make it easier for people to remediate and fix the issues that will ultimately get them hacked. Um, we've just recently looked at the list of companies again that get hacked like in an average month. And it is my personal data, by the way.
It is your personal data. My data got stolen last year, um, pretty badly. So yeah, Probably several times, several times, A few times.
I gotta tell you, I started collecting, you know, you get those letters in the mail that says you might, you might, like, they don't know you really were, you might have been the subject or involved in a data breach here where you're personally identifiable information, including your social security number, date of birth and everything. And so we're giving you a year's free. Uh, at this point, I have a lifetime of free credit monitoring across all of the different ones from all of the times my data's been breached at this point.
And, and that doesn't even have, you know, help anymore. Like, I came back from It's truth list. I, I use the letters.
I just, I just like to see the stack grow because like you, I've been in security 25, 30 years. Right. And, you know, I remember when they first came out when PCI first came out, and the whole idea of providing credit monitoring first came out, but in the last year or two, it's out of control.
I get, I get almost like once a week, My, my personal data has been stolen to the degree where people took over my, uh, the credit agencies, basically. They're there to monitor my stuff. Yeah.
So they had fake accounts on them because that's how far they got, especially last year. I, I've been through that too. And so, And addresses, tax returns sent and, and we're security people.
Could you imagine civilians, right? How, how are they dealing? It's nuts, man.
If this happened to my grandma, I don't think what she would've done. No, no. I was able to react very quickly, but, um, I don't think they would've, so, no.
And that's what we're trying to change. Like, I'd rather, uh, people have fewer security issues, um, on their table that they can effectively solve. Especially now in the age of ai, you've got these attacks rolling out more autonomously, more automatically than ever before.
Like, we can't afford just sitting back and, and watching critical results fly through anymore. The attackers are just way faster. So, yeah.
Agreed. Agreed. So how, how are you doing it?
Let, let's hear. All right. So what we are doing is we are using a combination of policy code and, um, vulnerability assessment in our environments to figure out what is the most pressing thing that is actually going to hurt you?
Not just the surface level symptoms, but what is wrong at the core? Um, back when I used her attack systems, I could usually see these very easy things that were being done wrong. Like, it's not even the hard stuff that people get wrong.
It is usually the easy stuff that gets broken into and taken advantage of the most. And so for the vulnerability analysis as well as for the policy analysis, we are then usually looking at the entire context. So what is the system?
Is this really something that exposes you? How do you fix it? Um, what is the best way to approach it?
And that ultimately needs to be accessible to the people on the other side. That may be a entire team that you have. Those may be platform engineers.
They may use automation or they may not. We have a lot of customers who have like a bunch of Windows admins trying to fix their Linux machines. And so whenever that happens, you know, my fixes still need to be very actionable, um, for them so that they can go and fix the issues.
I love it. Um, I, I want to talk OPA and stuff, but before we do, I want to just tie some bows around Mondu. Um, how does Mondo use Mondu use OPA?
How, what's the connection there? So we, Or, or not, is it a replacement? You know, I, I don't mean to you go.
Yeah. So we've been looking, uh, policy as code for a long time. Uh, like I mentioned, we did a previous startup where we started with Paul CS Code.
Um, we actually came from the infrastructure automation side. So we built it around, uh, things like chef software, which were used to automate operating systems. And then we went into the cloud direction.
But we realized with Paul CS code that we needed something that was accessible to a security professional, something that they could use and understand, and it needed to unify these different types of technologies that are happening and expose the context of them. OPA came up at tail end, um, after we had left there, um, I was with Google during that time. IOPA had risen to prominence, and it had risen to prominence in the infrastructure, uh, security space to help write policies there.
Um, we had taken a look at it in the early days, right when we started mondu, but, um, similar to other frameworks we had then ultimately decided against it. We knew it was not going to be the right solution for us. Got it.
And, and so you, you guys basically developed sort of an alternative? We did. So we came up with something that we dubbed MQL.
Um, it is a query language that is, um, very much leaning towards GraphQL plus, uh, scripting for assertion. And the reason why we did this is because we realized, you know, a lot of these security problems that we're trying to analyze, they are actually dealing with relationships and context. So, um, we came up with a framework that a needed to be really, really good at expressing those relationship and that context.
So let's say for example, you've got an open process listening on one of your systems that can be attacked. Great. That process is usually reachable, um, because of some kind of cloud configuration, because of some kind of network configuration.
It may be rolled out through a package to all of your systems. You need to understand where it's coming from, uh, what are the permissions it is running with, and so on and so on. These are all relationships.
And so we decided that we needed to have a stack that was going to be good at expressing relationships. So, for example, is this a process that is running as root? Is this a process that is exposed through my gateways?
Can it be reached through that? And so on. All of this became one of the requirements why we initially looked at GraphQL, because as a stack, it is the graph alternative to talking to an API, essentially, the only thing that it didn't have was a strong way to express assertions or to man data and transform it.
And so we added those layers on top. We basically made it easy to, um, transform that data and to say, you know, much as to say, give me all of the users that this process has access to, but to say, none of the users should include your administrators, or none of the users should include root. And so that ultimately became the framework that we used for policy as code.
Um, and we tested it with security professionals because our aspiration there was that it can be easily understood and can actually be used by the people that understand security the best and not just by developers. Got it. I, I want to pivot to this, uh, OPA and Tyro angle, but before we do, for people who want to go look up mondu now and grab information, what's the website?
com. Um, it has all the information about the company, but it is also connected to the open source projects that we have, CRO C and Spec. Um, if you wanna take a look at the open source there as well, CPEC is a great project that actually, um, exposes all these things that I mentioned about policy as code resources and how to do security this way.
Um, you'll find it through the website or through GitHub or Google Search. And mind you, by the way, is M-O-N-D-O-O People probably see it in the bottom with your name, but I'm just throwing it out there. All right, Dominic, let me, let me set the stage for this next part.
So look, I'm familiar with OPA, I'm familiar with the founders of, of the Styre company and the OPA, and they founded the OPA project. My friend Bill Mon used to be this, the, uh, CEO at Styre, though he left a while ago. And then, you know, apple did a very Apple-like thing.
They were big users. They still are big users of opa, of OPA, but instead of buying styre, they did it. They bought the people at Styre, including all the co-founders, all of the technical talent, and left the company as sort of a, a husk, an empty husk, an empty shell.
And basically Tyr wrote to their customers and said, Hey, your, uh, enterprise level sup pr pri, your enterprise level product is end ending of life, end life. We're not supporting it. And for all intents and purposes, there is no styro.
And the good news is we've taken those enterprise level products that are built on top of OPA and given them to the OPA project, which is a ward of the CNCF. So they're not dying, but there's no one, you know, there's no throat to choke there, there's no company no longer a commercial company providing it. And, and the community will decide what to do going forward to continue it, not continue it, change it, not change it, what have you.
Good luck and good night. You know, um, this happens, this happens, right? It, it, it's, it does, yeah.
Real life. So as you could imagine, a lot of enterprise customers of sty a as well as just ranka file OPA users are saying, Ooh, this, this sounds like it could, you know, what could go wrong, right? Um, and, and so they're looking, they're casting about for options.
They're looking for help. Mm-hmm. They're, you know, they want some reassurances.
How is this affecting mondu and how, how are you guys responding? Yep. So, um, let me jump into the OPA angle first, because really if you look at it from the ground up, um, it was built for one thing really, really well, and that is authorization.
Even when we started out, we started to look at the specific security problem that we're tackling. We're still building up a product underneath. And I use languages and frameworks like anyone else.
So, you know, we use Golang and things like React and other frameworks. And so, um, rego actually came up, um, for the authorization bit as well. Um, we had evolved over the years out of it, but, you know, it is actually, um, purpose built for this and is doing a good job at that part.
However, the problem is when you're starting to use it for tasks that it is not really originally designed to do well, and this is where the infrastructure, infrastructure security bits really come in, right? So I always compare it to like a spoon that I use. It's great for eating your cereal in the morning, but once I start to dig a hole to build a house, uh, the spoon might not be the best tool to use.
And so, um, as the star news has come in, a lot of users have, um, met that shocking day. First of all, the lack of clarity. What exactly does that mean?
But after a while, once it dawns that this product isn't really, um, having like its leadership anymore to lead us into the future, um, they feel that the problems that they had raised, especially around the infrastructure security use cases, are not getting addressed. And to be quite frank, they haven't been getting addressed well in the last couple of years either. Um, a lot of us were looking at Sty a and OPA because we saw that it had this widespread use in the Kubernetes community, and that it's going to be fixed eventually.
Like all these problems that we're having, and we're waking up to the reality that that's not the case. And so for us, this meant actually, um, new users who are coming in, who are asking us how we tackle the problem for po um, infrastructure security, cloud security, and other use cases with policy as code, and what we can do with it. So as the first couple of users have been diving in, because you know, now it's worthwhile looking at the alternatives, they're actually starting to realize how many shortcomings the original approach with OPA has had in the use cases that they were trying to solve.
Yeah. This is akin to sort of the, uh, the Broadcom VMware kind of thing where they, you know, they tripled the, the licensing fees, and all of a sudden it became a, a reason for everyone to say, wait a second, there's alternatives, right? Yeah.
We could go to the cloud, we could use what the cloud provider has. There's, there's other alternatives that are cheaper that are maybe better. Um, so that that's what's going on here.
Now, there are some people who've made big investments in OPA. Yep. And to rip that out, you know, no one likes to rip out if something's working right.
Don't fix what's not broke. Yeah. How's Mondo helping those people?
So, um, what we are starting to realize is, first of all, um, in the infrastructure security use cases, you might have the investment, but really double check, is it working for me? The more we have talked to companies that have this use case that are using OPA there, the more we're finding that they're getting stuck with it. It is very hard to spread.
It is very hard to grow. I mentioned it before, right? It isn't, it hasn't been built for this use case from the ground up.
Um, so teams are often getting stuck. You will find, uh, teams of developers that are trying to, um, use this for security use cases, and the security professionals on the other hand, also not being able to use it as effectively as they should. Um, and so our experience is really take a look at that investment and take a look at what it does today.
The majority of the companies that we are finding, um, they just want their standardized policies to be used, um, for cloud or for operating systems, and for the other systems that they're using for that. Actually, mondu comes with most of these policies out of the box. So you can just plug and play.
It is not, um, really hard to replace for that use case. If you have written a lot of custom policies, well, we're finding ourselves in the age of Gen ai, and it is actually making things a lot easier to move things from one stack to the other, or to use Gen AI for writing policies. We have actually been growing our own policy teams this way over the course of the last year.
Um, we've written the, uh, context that the AI needs to write good policies for you and to express them both with MQL as well as with our YAML based policies that we have. And so we have a lot of this tooling that makes it easy to convert the policies into something like MQL. So you aren't stuck with OP and Regal.
Um, it is not like you can't move off of it. It is actually something that is more feasible today than it would've been like two years ago. And moreover, what we are finding, especially with our larger customers, is that the difficulty for them comes in managing this across their organization and being able to handle things like exceptions.
Well, and this is really where OP and Rigo have had the, the least capabilities. Um, the more we're engaging on these use cases, the more people are realizing that they can already do a lot more with MONDU and MQL today than they ever could have with OP and Rigo. And so it suddenly doesn't just become a, you know, let me replace this, but actually, let me do this better.
I love it. Dominic, we're about outta time, but I think people got the gist of what you're saying here, right? I want to just tell 'em one more time, where do they go to get more information on mondu?
It's M-O-N-D-O-O dot Yep. Com. Com That's right.
Mon Com. Come drop us a message on the website or say hi. Um, feel free to reach out.
And then also on the open source, if you're interested in that, if you're coming from Opa rego from the open source site, you're interested in infrastructure security, cloud security, any of that with policy asco, feel free to reach out. We've got a great project there. Excellent.
Will you guys be at CubeCon? Um, we might. Um, we are looking at that right now.
Um, for now, we are going to Hashi Con, um, if you wanna see us in a couple Weeks notes say, so we will be there Tech strong. Uh, I won't because they're, they're too close to each other, and I can't be in two places at once anymore. I used until Quantum Computing comes out, then I will be.
Um, but for now, shredding Ours on. Right. Um, anyway, thanks for coming here on Tech Drunk tv.
Don't be a stranger. Come back and keep us posted. Okay.
Will do. It's been great talking to you. Alright, Dominic Richter, chief Product Officer, co-founder at mondu here on Tech Drunk tv.
We'll be back in a moment. Hello and welcome to the latest edition of the Text Strong AI Leadership Insight series. Today we're with James Horne, who's CTO for KA ai.
And we're having a chat about, well, what's it gonna take to orchestrate all these AI agents and other things that are floating around out there. James, welcome to the show. Thanks very much, Mike.
Appreciate being here. So I think we can all see this coming, right? There's gonna be thousands, who knows, maybe even millions of AI agents eventually, and they're all gonna be doing various tasks, and they're gonna be floating in and out of our workflows.
So how do we manage this and how do we orchestrate all this stuff? Because I got a feeling we're gonna be quickly overwhelmed. Yeah, I think, you know, this is one of the, the key things that I, I think a lot about is, um, you know, there's a number of things out there to help you like kind of build and, uh, an agent and maybe help you deploy that agent somewhere tied into a workflow.
But how do you do that at an enterprise scale? Um, is a really fundamental question when you have to your point, thousands of agents, tens of thousands of agents running within your organization. And the key thing is, especially we don't know what the a the final architecture is going to be.
There's no sort of winning architecture for running these agents at scale yet. So how are you gonna be able to adapt to, um, the differences of different ways of running, say swarm environments where you have, um, you just have masses of agents that are given sort of a common outcome that they're trying to approach or hive environments where you have a central sort of coordinator who's starting and stopping other agents to fulfill a task over time. Um, or even workflow, you know, the based ones, the ones that are most common today, where you've got a, you've got a fixed workflow, you've got an engine of some sort, um, and you have agents that are doing different tasks in that workflow.
The key thing is, is we, we, we know some things about the fact, like AI agents are likely to be very ephemeral. They'll, you'll, you'll start one when you need it. You'll, you'll, you won't keep it running all the time.
Um, they, they may be created on the fly by other AI agents so that the actual definition of the agent kind of pops up as it's the need is discovered and goes away if it doesn't work out, or, or if it once it completes this task. So you start to ask questions, well, what, what do we need to survive in that environment? And one thing that we need is we need to make sure that we have access to data that's necessary to complete the task that these agents are doing, regardless of where they're running.
So we need, and we want, ideally, access to the systems of record rather than having to replicate and duplicate data all over the place. Um, a second thing that we need is we need the ability for our prompts to maybe go and use, um, you know, a model, uh, in one location tied to one data source to answer one part of a question and, and have a different part of that inference running in a different place to answer a different part of the question and be able to bring that back as a common response. So one prompt running on ultimately many models and coming back, uh, to into play.
Um, we need our agents to be able to sort of just ask a question and know that ultimately it's gonna get the, that proper response. We need agents to be able to communicate with each other, and we need then, um, we need a, a good mechanism to make sure that that's secure. Um, all of this, by the way, has a security factor to it, access control, um, the, you know, the appropriate, uh, network protections and so on.
So those are some of the things that we think about, um, a lot in terms of orchestration, is how can we provide that substrate that makes all of those things there and available so that as you build an experiment with the agents and try to figure out what are the ultimate architectures that make sense, you know, that you always have that access, you always have, uh, that coordination and, um, that knowledge of, uh, of location awareness as well, which is another big point in this, um, that, you know, that things are gonna run where they need to and data's not gonna leave the boundaries that it shouldn't leave. Right. To your point, I think people are talking about this with things like, you know, the agent to agent protocol, but that's just a protocol.
It sounds like we actually need something that feels like a platform that's gonna execute those protocols in a way that provides the governance, the security, and the understanding of what's happening between these agents. Is that a fair assessment? Yeah, I think, I think every one of those, uh, protocols have been defined in a way that, um, uh, implementations have some freedom in terms of how they implement the protocol.
So, for instance, data a is a good example. They don't require any form of queuing, um, in order for you to have that communication between agents. But of course, if you're gonna do that at scale, you almost certainly need some form of queuing to make sure that you avoid, uh, race conditions or overwhelming systems, um, incorrectly.
So, um, yes, there's a need for, uh, for a platform, um, to deliver sort of, and I use the term capacity, and it's, it's, it made a lot of sense when we're just talking about compute network and storage. But now the capacity an AA agent needs is the capacity to, to get knowledge and the capacity to communicate more. So, I mean, underlying is still compute, network and storage, but, but it's the way that the a you design an agent and think about an agent, you're thinking less about, um, how the computing works.
And you're thinking more about, if I tell a model to do X, is it gonna be able to figure out and go find the things that needs to do to complete that task? And that's really kind of the fundamental difference, is you still need to deploy things. You still need to make sure that you're consuming the right resources underneath, but the developer or the agent should not have to be thinking about, how am I gonna get to A-A-V-P-U that has enough power on it for me to process this video?
Right? That, that, that should not be what that agent designer should have to worry about. Mm-hmm.
You know, when I talk to some folks, um, we're all obsessed about how we get the agent to actually go do something, but, um, it turns out that convincing the agent to stop doing something might not so be easy either. So we need to have a framework or something that just says, you know, when you reach a certain level of parameters, you know, stop, otherwise you're just creating useless data for the sake of data. Right.
Data. Yeah. I think that, um, there's still an agent design component that, um, that a, a platform like ours isn't necessarily going to take care of, but there, the ability to observe what's happening with the agent and to understand and react to the behavior of the system as a whole and of individual agents is really important.
Um, one of the things that we're doing here by creating all these things that are smart and adapt and learn and whatever, um, and having them come in and out of existence, is we're creating almost the very definition of a complex adaptive system as, as that, that area of science knows it. And that means there are going to be emergent behaviors that come from unexpectedly from the way different agents end up working together that we didn't plan for. So that's one of the things that we very much take serious, is how do we help you understand the emergent behaviors, uh, that are happening in, in, in your agent environment, uh, and help communicate with the other parts of your systems that are maybe handling, uh, you know, different specific aspects like workflow engines and things like that.
Mm-hmm. Does that include negotiations between the AI agents? 'cause I'm asking the question.
'cause it seems to me there will be instances where AI agents will be giving, uh, conflicting missions and just like humans have where, you know, I may be in the marketing department and you may be in the sales department, and we may have a conflicting mission that we need to negotiate some middle ground on. Is that something that AI agents are gonna be able to do? Or is that where the humans come in?
Well, I, so I, I just actually, uh, I haven't published anything yet, but I, I actually did just write a blog post recently for myself, um, on this very topic, right? So the politics and the economics of these systems are gonna be real as well. Um, do we do anything explicitly today on that?
Um, uh, we don't, I'm not aware of any system out there that really does, um, a, a a, you know, phenomenal job, uh, at scale of doing those kinds of things. But there certainly are people experimenting to find, um, figure out how to do that. AI will be involved in doing that.
So there's checks and balances systems that are already in existence in large scale, uh, age agent environments. Those checks and balances systems ought to be, um, you know, very, uh, just kind of very normal and very easy to have out there. Um, uh, but it's also something, uh, it's one of the reasons why I say, you know, the jevons paradox of the AI age is everybody talks about how all the developers are gonna go away and how those jobs go away.
But I don't believe that, I think the nature of engineering changes, I think it goes less from code writing and goes more to how do you curate these complex environments and the way that these things work together and handle the politics and handle the economic clashes and, and, uh, make tweaks as you need to, to help make sure that the system provides an ultimate outcome that's important to the business. But those things will exist. And, uh, and we are, you know, in for a decade of learning a lot about what that looks like and how we can manage it.
Mm-hmm. Another thing I don't see people talking a lot about, but I think will be needed is audit trails for what, who, what agent did what to whom when, and there'll probably be some sort of, uh, regulatory body that wants to know that information, but right now it feels like everything's kind of a black box. But is that where we need to get to?
Yeah, I think, uh, you know, at the very least what we do is, uh, we log the heck outta everything. Um, you know, we keep track of, like with the inference engine, as we, as we, um, do distribute, um, portions of inferencing out, we keep track of what, what decisions were made by ai, uh, to do that and what the responses were. Um, we, we keep track of, uh, you know, of, of interactions, um, between, uh, between agents and, and the Kaza platform underneath for, uh, for data access and other things.
And also, um, you know, we can help keep track of communication between agents, um, that are, are trying to complete tasks together. Um, it, it is absolutely true that there is no way for humans to manage systems like this unless they can see what the system is doing and see it at some detail and catch, um, catch what's going on. That may be important behaviors, uh, you know, bad feedback loops or good feedback loops.
Um, and so, um, so the, yes, this is part of what, uh, a genetic orchestration environment needs to do is very much provide, uh, documentation of what the, or the agents are doing in the orchestration environment mm-hmm. And know one level of scale is always gonna happen. And I'm also asking this question because we seem to talk about using AI agents internally to manage workflows, but eventually they'll be expanding multiple organizations and multiple companies, and will that create another level of complexity on top of all this?
Yeah. Um, yeah, I wrote a book for a rally in 2021 called, uh, flow Architectures, uh, the Future of Streaming and Event Driven Integration. And, and the, the thesis of that book was as we come up with standards for moving near realtime data, um, between, across, basically across organization boundaries, across domain boundaries, that's going to, uh, uh, just create a flood of demand for those kinds of connections.
And, uh, I believe that AI is proving to be the killer app to drive that forward. And you see it with MCP usage, um, already, um, you see some, um, some examples of companies attempting to use agents to automate their, their interactions with other companies on a b, b basis. Um, it's very early, yet it's not a standard thing that everybody is doing, but, um, but I believe that, you know, the reason MCP and A to a and some of the other standards are so important at this early stages, they're beginning to find the way that we are gonna communicate not only within our organizations, uh, among a agents, but also across organization boundaries.
And that brings questions about, um, security and monetization and, um, and, uh, you know, and auditing the, the origins of, uh, where data comes from and all those kinds of questions. Um, so, uh, we do see that, um, uh, we do see that there's an interest in that. We, most of what we see today in development with agents though, is sort of within organization boundaries for now.
Um, but I, I definitely see experimentation happening with, with beginning to cross those boundaries Also as one wag one's put it, um, it's one thing to be wrong, it's another thing to be wrong at scale, but how do we roll things back if they're happening in near instant real time? And, um, and, and what is the implications for being able to do that? Yeah, I mean, there's lessons learned from past architectures that we can, uh, we can take advantage of, right?
So we want to have, uh, uh, we, we want to have a strong understanding of where we need to log things in the sense of, um, of, uh, of something that we can roll back step by step, um, or recreate actions that were taken. Um, so things like what, what people have done with eventing and Kafka, um, you know, those, those kinds of patterns will also work in this environment where you can begin to, uh, to put some transactional logic around different types of interactions. Um, remember that a lot of what agents are doing is actually interacting with tools that exist already today.
So there's already mechanisms in those tools to help, um, with things. But those checks and balances things that, that I was talking about earlier is a very important part of this picture. We need agents that, in part, are verifying that the outcomes we want to have happen are actually happening.
And that can trigger, um, a, a known action in response to something not working out the way we want it to, not, uh, not validating correctly. Um, so, you know, it, it becomes almost like a, um, you know, I, I, uh, I don't know exactly what that pattern's gonna look like at scale. Um, but I believe that it, um, if you look at some of the people that are experimenting with swarms and, and other of those kind of large scale environments, they are explicitly defining prompts as a part of the definition of those things that say there must be, uh, agents that are verifying and validating that the following things are true.
Mm-hmm. So the agents will essentially police, the agents will, yeah. I, I, I believe that's the only thing that's fast enough to actually police them.
I, I think humans will police outcomes at sort of large growing scale. You know, are you getting the outcomes you want from your system, is a, fundamentally a human question. But, um, and then I believe that some of the, the sort of training and psychology and, and, and all the things that in terms of, of helping move agents in the right direction to get the outcomes you want is gonna be human involvement.
But in terms of reacting in the minute to a transaction that's happening, I think, um, you know, agents or possibly other types of software services, um, are gonna have to play that role. But I, you know, it, it seems like agents are the logical way to go about it. So what's your best advice to folks?
'cause at the end of the day, I kind of feel like the agents are being built first, and then someday we're gonna s slap something that looks like an orchestration framework on top of them after the fact, but maybe the cart's before the horse, which way should we go? Yeah. You know, it's a chicken and egg problem to a certain extent.
Um, absolutely validate that. Here's the way that I put it, is if you, or there's a lot of organizations that know, that have done enough experimentation that they know that, um, they're looking for the agentic environment that's gonna cha that that's going to positively affect their business. They already know that they've gotta figure out how to put the pieces and parts together, and they're, they're running experiments today.
I would say if you're gonna start running experiments at large scale, that's the first sign that you probably need some sort of orchestration engine to make, uh, to lower the cost of that experimentation, to make sure the data access and, um, and inferencing and and communication are, um, are straightforward for all your developers across the organization, across organization boundaries were necessary. Um, and then I would say, you know, um, there are some organizations, uh, out there as well that are beginning to, um, uh, to implement, uh, small experiments at larger scale. And I would say as soon as you get to a point where you're really running, you know, hundreds of agents at any given time, maybe thousands of agents at any given time, um, there's a lot that an agent orchestration system can do to remove the toil of managing all of those agents.
So to make it, um, uh, less effort and less risk for your organization from security perspective, from a performance perspective and so on. And so, at that point in time, if you're like, we're, we're beginning to scale up what we're doing here to a point where a, you know, one human or a few humans can't manage it very well, um, it's time to look at, uh, an orchestration environment for the same reasons that when you were doing containers, you eventually looked at Kubernetes because you, you had gotten to a scale where managing all those containers became very, very difficult. All right, well, folks, you heard it here.
Hey, it's quite literally just like going to the orchestra, right? I mean, there's musicians, they all know the music, but they still need a conductor. That's gonna be you.
Hey James, thanks for being on the show. Thanks very much, Mike. Really appreciate it.
All right. And thank you all for watching the latest episode of the Textron AI Leadership Insights series. You can find this episode and others on our website.
We might should check all those out. Until then, we'll see you next time. Hey everyone, it's Alan Shimel and we are live.
That's right. Live, uh, it at Swamp Up. Swamp Up is back in Napa.
After I think two or three years it's been since they were in Napa Should End, I'm thinking it might have been since before COVID that we were in Napa last. But we're really thrilled to be here. It's beautiful here.
It's a beautiful resort. But more importantly, there is so much going on at Swamp Up, you know, like everything else in the tech world, it's kind of the year of AI more than the year. It's the era of a, the dawning of the era of ai.
Still, I like to tell people we're still at the beginning of the beginning, not even the end of the beginning on ai. Let me introduce you to my first two guests of our Techstrong TV coverage here at Swamp. Up to my far left.
He's the guy in the, in the, in the, uh, shift happens Frog shirt, Yuval. Let me make sure I get it right. Excuse me.
Yuval Fern back. Yuval, welcome back. It's good to see you again.
Thank you. Good to see you as well. You know what, before we get to our next guest, Yuval, give to touch, share with the audience your title and role at J.
Sure. So, hi everyone. I am, uh, yba, I'm VP and CTO of MOFs here in Jfr.
Um, actually joined Jfr, uh, a year ago as part of an acquisition of a company called Quack. Um, and nowadays, of course, part of jfr ML and the new product that we launched today that of course we'll talk about in a second. Thank you, Yuval, to my immediate left, not in the frog shirt.
Is is Al Alek. You got that right? You got that.
Perfect. You got that on the money. All righty, Al is with, uh, Nvidia and introduce yourself.
Well, thank you for having me. Yeah, it's great to be at Napa. I was joking around earlier telling folks that, uh, you know, I'm glad we're doing this 'cause now my family really believe that I'm here for work fruit.
So got the proof right. I got the proof now. So, uh, my name's Al.
I'm a senior director of product, uh, at Nvidia. And my job is to, um, take the software that our, uh, awesome core tech team creates, um, a harden those make them production grade for enterprises and help our ecosystem build, um, agents, right, that are fra frankly transformative in everything that we do. Something we were just talking about.
Absolutely. And, and that's a great segue. I i little something extra for giving us that segue.
We were at the keynotes this morning, right? Yuval led off came on. Yuval, you, you, uh, introduced a new product for Jfr called the jfr AI Catalog.
Explain to our audience a little bit, what, what is it? Yeah, so, um, as I shared, I joined J four a year ago, and as part of that, I've seen and got a lot of responses from J four customers about the challenges they have with adopting ai, the challenges that they have with actually trusting AI and the amount of new models that are being launched daily, right? Um, everyone's speaking about ai, but actually using that in production require more than just, you know, testing the new and shiny model.
It requires the ability to trust that, the ability to trust where that model is coming from, um, who's the owner of that model, and even who is actually going to use that model. And as part of that, and as part of all that feedback that we received in the last year, we decided to launch the J 4K catalog. And that's basically a solution that allow organizations, allow our customers to manage the entire life cycle of AI usage, I'll call it, from discovering which models actually exist, um, to deciding who should have permissions to which models, and eventually then serve those models, uh, track the, uh, usage metrics of the models and understand which application uses models and how.
So the goal is eventually to allow organizations to understand where those models are being used by whom, and make sure that they trust those processes that are, you know, shifting in, in such a magnitude and such a, a, a pace of innovation that we haven't seen before. Absolutely. We're gonna come back to that.
'cause I, I have some thoughts and questions, but not open. Explain to me the Nvidia Yeah. I mean, connection, there's a reason for this awesome partnership, right?
Right. And so, uh, we're a full stack acceleration company. What that means is, right, uh, we're not just about producing processors or, or systems.
We actually build out AI factories, but we go all the, all the way up, right? For optimizing runtimes for not just models that NVIDIA publishes, but also the ecosystem models as well. We call that nim nim inference microservices.
And so, uh, what we do, you can think of a nim as, as a, a model with it runtime package as a single microservice, we spend a lot of time tuning that runtime to make sure it runs it efficiently as performantly as possible, uh, on the NVIDIA stack. Um, but equally, right, we contribute a lot to the open source domain. We're very, uh, we're huge participants in the open source community because going back to Eva's point of having that, that trust, having that transparency, it isn't just that we provide the NEMO tron open weights, which are fantastic by the way, and Excel really good at reasoning.
But we, we also open source our, our training data sets. We open source our recipes so enterprise can then take those models further to them for their agenda, uh, capabilities. And so being the ones that provide the secure runtime and the open source of the models and the weights and partnering with Jfr, what drives the services for having all that lineage was just an amazing partnership.
Absolutely. I, I want to dive a little deeper on this, right? So I was at Swamp Up last year in Austin where they announced the, uh, J Frog Nvidia partnership now ale over the course of the 12 months.
How have, you know, what, have you seen how this partner, well, look, AI has been on a hockey stick trajectory for these 12 months, right? But how has that affected, what's the, the, the net that our audience could take about this partnership? What does it mean to them?
I mean, look, you know, Yuva kind of set the scene, right? There's so much happening and it's happening so fast. I joke around and tell people that at one point I think my kids thought I was a vet, 'cause I was talking about new animals every week from llamas to Mambas to, you know, you name it, right?
But, but it's awesome innovation that's happening in the ecosystem, right? So a couple things that are, that I think critical number one is all this innovation that happens, right? Yes, you wanna be experimenting a lot, et cetera, but when you have all this innovation that's happening, right?
And you have all this open source, the potential for exploits growth significantly as well, right? And that's something we talked about earlier when, you know, we were on stage. And so, uh, being, having that transparency, understanding essentially what's part of your run times where malicious code can be potentially like implemented is, is super critical.
So, so you wanna be experimenting, but you also wanna be careful and prudent when you're experimenting. And so that's why having a single source of truth, right, for your system of records, for all your artifacts is critical. And that's why that relationship's been awesome.
And sorry. Yeah. No, no, go ahead.
And I think the second point is, right, um, one of the first use cases we started using agent AI was in actually defining the contextual, um, analysis. Doing the contextual analysis to understand whether vulnerability can be exploited or not, right? And I think, uh, I, I really appreciate the partnership that we have with the JAR platform, because that's something that take very seriously as well, just 'cause the CVE says, you know, it's got a high CVE score, doesn't mean it's exploitable.
There's a lot that goes in to be able to exploit that. And so, you know, we see eye to eye in terms of how we go about really going deep and understanding the potential for exploits and protecting our, our, our customer base. Absolutely.
By the way, this, this partnership didn't start because, you know, us and Vidia thought that we should work together. It started because the J four customers approached us, told us that they need to trust the source of their models. And, you know, the only models for market face, by the way, I think the target face is an amazing hub for models, but it's not enough in many cases.
And customers approached us and told us that they want to have a trusted source of models, and NVIDIA is one of those trusted sources. So a year ago, we, we partnered to make sure that the J four customers can actually get the Nvidia need models directly for multifactor and trust the region of those models. Um, and from there, of course, we progressed with that partnership with the security solutions.
So the contextual analysis, the ability to actually understand how those, uh, artifacts, how those models are vulnerable, and how we can make sure that in the production environment there will be no vulnerability. So eventually it's part of the same goal of making sure that the J four customers, and of course the NVIDIA customers can actually trust the model, trust the origin of the models, and trust that there are no security. And then that will arise because of those new artifacts that they not need to manage and of course have to manage to actually make their product progress over time.
Excellent. Ada, I wanna come back to you 'cause you said something right in the beginning that I want our audience to understand. And that is a lot of people here, Nvidia, and they're thinking G-P-U-G-P-U-G-P-U, not that you make a bad GPU, don't get me wrong, but the real key to NVIDIA's position is the software, is the community, is the ecosystem around Cuda and, and, you know, uh, um, NIMS and, and so forth.
Talk to us about that a little bit and why you are, we're on live tv Paul, uh, cameraman. I'm gonna ask you to grab outta my bag, my AI catalog paper. We'll bring it up.
We're gonna talk more about it, but I'll talk about, yeah. What the secret sauce at Nvidia? Uh, Well, we're a full stack acceleration company, right?
I mean, um, yes. We, we start at, at the silicon, but we go all the way up the stack, right? And so we have AI factories, we have our, our software portfolio that goes all the way up to the, um, you know, what what we call blueprints, right?
Reference workflows for how you'd go implement a specific use case for, for agents. And you get the full benefits of Nvidia when you take the full stack, right? Because we're able to optimize all the way down to stack, but by no means you have to take the full stack, right?
And we leave it up to our audience, our ecosystem, to meet us where they think is best. Some just wanna run on our infrastructure. We love them, some want to utilize right?
Wanna go higher up in the stack and take advantage of the optimizations that we drive through software to enable that. I think one key to Nvidia is, um, you know, call it success or, or secret sauce, is just how, how ingrained we are with the ecosystem. We, we go to market through our ecosystem.
Our partners such as J Fog are super critical to our success at the marketplace. And so you're spot on. We're not just a chip company, we're a full stack company.
Um, right. You can take us, you know, you can go with us up all the way, you know, all throughout, or you can just choose to meet us where you think is best for your, for your, for your domain. I love it.
Thank you. So Yuval talking about the jfr AI catalog, you know, I've written a lot recently about what I call shadow. I, uh, shadow ai, right?
And we've seen shadow, look, I've been in, I've been in the tech business probably longer than both of you. Okay. Um, I've seen Shadow, before I saw shadow open source, there was a time where enterprise's official policy was no open source allowed.
It was, it was a danger, right? I've seen shadow wifi. I remember being at a US Army base and the, uh, army Information Assurance officer telling me we don't have a wifi security problem 'cause we don't allow wifi.
And as I'm walking with them, I see people unplugging laps and throwing them under their desk. As soon as he walks by, they plug him back in. And wifi, we saw it with the cloud developers whipping out their credit cards and opening instances.
It's no different, no different with, it's probably even easier with ai. Yeah. 'cause you have take your pick, right?
Whatever one you want to use. So we call this a prop, right? They gave this out at the, at the keynote today for your talk, your joint talk.
Talk to us about the different models and how we're going to control shadow AI at the enterprise level. Yeah, Yeah. So, so first of all, yes, it is a prop because, you know, this, this booklet have six models in it.
Um, I believe that the current number in I phase of models is around 2 million. And you know, on top of that there are, um, external like model providers like OpenAI and others. So that's another couple hundreds of models.
So, you know, the numbers are way more than that. And of course, no book can actually, you know, manage and track the amount of models that are being launched. Um, and models are now they used for, you know, so many different tasks.
So actually Shadow, uh, um, Aline is in his talk talk about different type of models like reasoning models and, and, you know, voice models and models are being used for different tasks and not just for language models. Like there are many models around computer vision and many models that are still used for structured data. And that's still a valid use case and still something that customers, you know, use as part of their use cases.
Eventually, the goal of the AI catalog is for organization to have the visibility about those models, about where those models are being used and how, and on top of that, as part of our launch, we actually launched a new product that will be available in a couple of months, um, called Shadow ai. Now, the, the issue of shadow ai, the problem with shadow AI is that in many cases, you don't even know that the model is actually adding one of your packages. It's possible that you downloaded the third party doer image.
Uh, that doer image that you use actually uses ai. Um, and it's not something that you can just, you know, not know about. Because nowadays, even the regulators in many places, for example, in the EU, actually force you to show that part of your product uses ai.
It's something that you need to have visibility on. It's something that you need to be transparent on. So the goal of the shadow AI product, but of course, is connected to the J four AI catalog, is to just not, not just allow you with AI catalog to choose which models should be used, but also to see, to have the visibility about where model is being used, what you are not really aware of.
And if those models are being used, for example, malicious or those models that are being used are actually not approved in your organization, you'll be able to actually block those from being used or, you know, go through the pro through the process and approve those specific models. Um, so the goal is about visibility and the ability to discover Where AI is actually being used in your organization. You know, again, my experience is you don't wanna stop people from using ai.
Yeah. And quite frankly, stopping people from using AI is like trying to grab sand in your hand. The, the tighter you make it, the more it slips out between your fingers.
What you wanna do is just, okay, you're using ai, let's let us document it. Let's make sure it's safe, let's make sure it's secure. Right?
And that, because otherwise you're fighting a losing battle. Nvidia has to see that as well. Ale.
No, I, I mean, right. We're not, we're not, we're not definitely fighting ai. Right.
To your point, right? It's, it's, I mean, there's plenty of productivity gains new markets that it opens up, as I said, right? Uh, the, the only reason we're able to publish and maintain so many of these NIMS is because we're using AgTech ai.
Right? Absolutely. But to your point, you do have to be cautious, especially with all this open source that's happening, all this innovation, et cetera.
You wanna create an environment that allows your developers to experiment. That is for sure, right? You wanna, you wanna continue creating that, that experimentation, right?
Uh, that you wanna enable as well. But then when you're going into, into production, yes, you want to have the safeguards that are in place. Um, you want to be able to have the observability, the tooling that is in place, right?
I, I go back to, you know, the, the nitron models that we provide, right? Just being open source in terms of not just the model weights, but the data sets of what it was actually trained on, the recipes of how we got there. Just to give the enterprises and the ecosystem that level of comfort, right?
To know exactly what's going on, right. Such that you always have that lineage that's super critical. Yeah.
I don't think you can, you know, uh, on the contrary, right? Like we're just on the, I think you call the be era beginning. The beginning of the beginning, Right?
And just imagine when physical AI comes into, comes into this world, right? Today we're talking about digital workforce, but very soon, right? We're, we have these world foundation models where you're simulating and generating data to train these robots and these autonomous vehicles.
Man, it's, it's about to get exciting. It it already is. It already is.
Um, but you know, that brings, both of you mentioned this, but you kind of aid at the edges. You didn't eat the middle, which is something else that they spoke about in the keynote saying, I'm trying to remember the exact name. Was it AI gov or ai gov ops?
Something? It was, uh, dev gov Ops. Dev gov.
Ops, excuse me. Dev gov. 'cause there's always something in the middle between dev and ops, whether it's saco or dev gov ops.
I learned a couple new ones today. Yeah, sorry. Yeah.
Yeah. So, but that's really what we're talking about here. We want, we need governance, not, we're not here deporting AI models, right?
We're here talking about you wanna use ai, use the ai, but let's have some governance around it. Let's have some guardrail, some knowledge, right? And that's, to me, that's the enlightened way of doing this, right?
We're not discouraging use ai. I know. So textron's, part of futur, and we, we have a policy now where we're encouraging all of our people, the cameramen, the editors, the writers, the marketing, the decoders, use AI to your heart's content experiment.
We expect you to make some mistakes. That's okay. Make the mis I'd rather you make mistakes trying something new than digging in your heels and saying, I I don't want to use ai.
Because if you don't use, I tell young people this, who ask me all the time, you're not gonna lose your job to ai. You're gonna lose your job to someone who uses AI better than you. That's right.
That's right. All, look, this is something we think about as well, right? And kind of now you're, you're going above and beyond just serving a given model or talking about managing the lifecycle of, of agents, if I may do that, right?
Yep. And, and that pipeline, right? We use, we, we have something called the NEMO platform for managing lifecycles of ages.
Mm-hmm. And that starts from data curation, uh, creating additional data that is, um, doesn't have the potential PII, that you know, you're not just collecting people's prompts, right? To then, uh, taking a model and adapting it for a specific domain.
Then once you have that right, and, and putting it as part of a, of an agent, make sure you have the guardrails that are in place, right? Such that it doesn't go re make sure you have the traceabilities, you can backtrack across the way. We have, uh, something called the NEMO Agent toolkit that allows us to drive all that traceability, all that observability, all that ping profiling around.
It's almost like, it's almost like onboarding a new employee. You have to teach them about your cultures and your norms at the company. You have to tell them the dos and don't dos, kind of like, you know, I'm doing in this interview.
Right? They're, yeah. Right.
And so, so it's exactly like onboarding a new employee and putting all those kind of, you know, managing it throughout this life cycle. And to your point, it it first, organizationally you have to, I love what you just said, right? Everybody's gotta be experimenting, but then making sure that your enterprise is leveraging the likes of the NEMO microservices to Right.
To manage that entire lifecycle. I love it. Yuval, I'm gonna give you the last word and then we're gonna wrap up.
No. So actually going back to this, uh, dev gov ops term and And again, we talked about it today. And, and this is in a way, the theme of this swamper because, you know, automation is already around.
We're seeing that as part of the development lifecycle. We're seeing that now as part of the DevSecOps lifecycle and also around, you know, ML and AI adoption. The challenge is not, or is becoming not out to automate those processes and how to actually, um, um, use new technology.
It's how to make that in a governed way, right? How to protect the way that we use the new technology and make sure that while we are researching new technologies, while we are actually adopting ourself to this new future, we do have the visibility and the governance on top of that to make sure that we're not doing anything wrong and that eventually our customers of, of our product can actually get benefit from those new technologies that we actually use in our products. I love it.
Yuval del. Thank you Del. No, you got it.
You got it. Alan, Thank you so much for coming on here, kicking off our coverage of Swamp Up 2025. We've got a lot more coming at you.
Unfortunately, not all of it's live, but we're recording it all. And over the next days and weeks, you'll be able to see everyone we spoke to here. I encourage you.
com or Techstrong It Techstrong, AI digital, CXO Cloud native now even Security Boulevard. 'cause we'll probably do something about dev gov ops on there to, for our full coverage at Swamp Up. But we're gonna take a break here.
Stay tuned. We'll be back with more from Swamp Up This Tech Drunk tv. Hey everyone, we're back here at Jfr Swamp up in beautiful Napa Valley at the Meritage.
We've had a great day of talking to some really great people and we're ending it with a really smart lady. I'm gonna introduce you two here in a second. Her name is Jung Lu and Jung is with Wiz.
And beyond that Jung, I'm gonna leave it to you to talk to our audience. Yeah. Tell them a little about yourself.
Sure. Thank you so much, Alan, for having me. Um, so Wiz, a little bit about Wiz.
We do cloud security and our goal is really to help organizations adopt cloud as well as AI as fast as possible. And I'm the VP of product marketing, so I'm responsible for product go to market strategy as well as execution at Wiz. Love it.
Um, our audience is very familiar with Wiz, obviously we've been following them for a long time. Um, I wanted to ask about you though, because people are saying, wow, great, she's, you know, she's got a great job over there. But give people a little bit of sense of your journey in, in the, uh, industry.
Yeah. So I will say I grew up in Silicon Valley. Both of my parents were engineers and, um, I fully rebelled.
They expected me to go and be an engineer as well. I started going down the computer science path, realized I hated it. Uh, and so I fully rebelled into finance.
Okay. Um, and did that for a bit before I saw the error of my ways and realized I need to come back to technology. What's core to me is building cool stuff, right?
That actually makes an impact rather than necessarily helping rich people stay rich or get richer. Oh. Um, and so that, uh, ultimately ended up taking me back into technology, back to Silicon Valley.
I was incredibly fortunate to land at Okta. And so really saw actually for the first time how it became an enabler of the business, right? Because this was the wave where we had SaaS, right?
And it could really enable that. And this was also the time when organizations were really thinking about how authentication, um, can be actually an enabler again, of the applications that they are building for their customers. When you think about identity being so central to the journey that you wanna take a customer on.
So that was a phenomenal journey. Uh, ended up seeing Okta grow from about 400 people to 6,000 people. Very large company at that point decided it was time to get back to that builder route.
Um, and was was just by far and away crushing it, such an incredible vision that they had as well. Absolutely. Absolutely.
Um, you know, I always said identity, IAM was the killer security app for the clout, right? So I, I grew up in the security before the clout and, you know, and for us it was the Moton Castle era, right? And cloud changed all that, but IAM became kind of paramount until the Wiz came along.
Well, cloud, cloud, Well, cloud, well, cloud made I, Or cloud development, right? Yeah, exactly. But Wiz came and, and we started looking at cloud security, container security mm-hmm.
Cloud native security in, in a different light. Um, you are here, we're at Jfr, obviously you presented today. If you wouldn't mind share with the audience a little bit about what you presented on.
Yeah, so I think one of the key challenges that we see is there's actually been multiple generations of cloud at this point, right? Yeah. We've had cloud for 20, some, 25, 30 years.
20, yeah. About five or four. And I think really in the early days, it was a lot more of the lift and shift, right?
We could take our on-prem approaches, we could take our workloads, move them into virtual machines. And really a lot of that has, um, dramatically changed, right? It's changed with cloud native development where every team, every organization is trying to move faster and faster and faster.
We have developers that are writing application code, we have infrastructure folks, writing infrastructure as code, and all of that is being shipped every single day. So development is incredibly agile and continuous, but the challenge that we have long had in security is our org structures, our workflows, even the tools that we have, right? They're still very vertical and siloed.
So application security teams, they run code scanners that look for vulnerabilities just in code, right? And then we have Dev SecOps teams now that run scanners and pipeline that just look for issues in the pipeline, evolved out of infrastructure as code scanning in cloud. We have organizations using tools like Wiz that evolved outta CSPM tools that are primarily used by cloud security teams, but increasingly developers.
And then in SecOps we have like a whole other completely different Yeah. Landscape of tools for the runtime. And so all of this is very disjointed, right?
It's very fragmented. How do I actually understand a vulnerability here in code that my SAST tool found actually is deployed into production and is running on a privileged container in my environment? It's actually very difficult to understand.
And I think, you know, when we look at CISOs, when we look at business leaders, even, they ask these horizontal questions like, where are the container images? Where am I exposing sensitive data of my customer facing applications? What, where, where's my risk?
Where's my exposure? And it's very difficult for security to answer those questions today because it is so silent. So really what I was presenting on is how do we flip that model, right?
How does security become horizontal so that we can move at the pace that our development teams and DevOps teams expect for us? And really the key to do that is in our view, context, right? Understand what's running in the cloud, give you the context for the code that created it, as well as the owner that is responsible, and then give you runtime context, right?
What's actually in use, what's loaded into memory that we should prioritize. I love it. You know, what you just said in a lot of words was why we have 7,600 venture back public security companies because it is so fragmented and so siloed and so specialized.
Everybody's a specialist. And you know, when the average, not even big enterprise, when the average, like SME enterprise, I forgot what the number was, 18, 17 different security vendors in a relatively small company. This is, you just hit it on the head, right?
You, you imagine, you know, you're a CISO and you're responsible for 17 different security vendors and you gotta make those all work together, right? It's, it's enough to drive you to drink is what it is. But, and, and we, we, we try to, we're trying to consolidate, but at the same time, the pressure to keep up with the pace of innovation, with the pace of, of ai, with the pace of how much code we're churning out right now, it's like, you know, it was mission impossible before.
This is mission impossible squared. Um, But what I would answer, well, but what I would argue is I think we overly focus on tool consolidation, right? Tool consolidation is an outcome.
But I would say the issue is we have a lot of data mm-hmm. But we don't know how to turn it into something that we can action, right? Every organization, you go to them, they've got their expel Excel spreadsheet of millions of vulnerabilities, right?
It's not that we have a problem with finding vulnerabilities. We have a problem with prioritizing and then getting someone to actually fix it. So I, context for us is how do we really get the insight out of all of this pool of data that we have on what's most critical?
And then let's break the silos between our teams so we can actually work together to fix them. Music to my ears, I mean, I'm thinking back, so I, I started a company called Still Secure in 2001. In 2003.
We came out of the vulnerability scanner long time ago. And that, that what you just described was exactly the state of the art. In 2003, people scanned about once a year, they printed out a telephone book and it was like job security, right?
Because you, it took you a year to go through that book and just in time for the next scan for the new book. Um, we've, we've tried to got getting better. You, you're right.
com primarily because I thought it was a better shot at security. Like we could correct some, you know, original sins built into security, really push for the whole DevSecOps thing. Like at RSA conference, we did the first DevSecOps conferences there and everything.
We've come a long way. But one of the lessons we learned is that developers are not security people. They wanna develop quality code.
Like I've never met a developer who says, I want to develop insecure code. Yes. Right?
They all want do, but I think one of the mistakes that we've made as an industry is thinking that if I only could make them a security person, they develop better code. They're never, they could be a security champion, they have pride in their product, but you still need security people at some level doing the security and helping them. Yes, I agree with that.
But I think, again, for developers, it's not like there was a lack of data. Like no, you know, we tell them all the time, look at all these vulnerabilities. Um, but the issue is what should I prioritize?
Yes. Right? Again, it's what is the insight?
What's the needle in the haystack out of this very long list that you've given to me, security team? And how do we start giving them that prioritization actually, again, through context. Yeah.
Right? Instead of saying, Hey, developer, did you know you have hundreds, maybe thousands of exposed secrets or secrets that have to be rotated? Um, instead of saying that, we can say, actually of all of these, this is the one secret that I need you to focus on, because I actually know that it leads to an admin in our cloud environment that has access to sensitive data, right?
We give that developer that information, they're really, they get it, right? So how do we get the, is that information derived using AI or some sort of automated means? Or does that take the security pro saying that's the one?
So I think it's two things, right? One is you have to correlate the signals together, right? So your secret scanner has to talk to what, uh, the entitlements and the identities that you have in the cloud, right?
So your Kim solution, and they have, you have to be able to correlate that together. So a tool can do that. Security teams can also help you to do that as well.
And they can provide the signal of this is what's most important for you to go fix. Then we can actually use AI to accelerate that path to remediation, right? Because there's actually a number of ways to resolve that particular issue.
You could delete the key might be a little aggressive, you could rotate the key, right? Kind of shooting the patient to save them, but, okay. Yeah, no, sometimes Uhhuh.
Um, but we can offer all of the different paths to remedi remediation. Absolutely. And the developer, again, they know what is best for their applications for the, um, repositories that they are working on.
So you can give them that and AI can help them actually take, okay, I think this is the best path to then actually getting to a fix. So I've spoken to a lot of security companies recently who are saying Nirvana is, we automate this, we automate prioritization and remediation. Now look, from my time on the other side of the camera, selling automated remediation was not an easy sell.
People are scared to death of that, right? But have we come or are we coming to maybe a point where we can convince a developer or an ops team that hey, it, for, you know, 80% of the garden variety stuff we see automated remediation is the way to go. I think that is a nirvana.
Maybe it's not that far off, but from what we've seen, organizations want to automate everything around a decision point and an action that still requires a human in the loop. Um, especially because we started in cloud, right? Automated re mediation in cloud is a very aggressive Right.
If we, It's, it's aggressive everywhere. Believe me, it's true. I I, I, that's why I'm still doing this and I'm not retired, but yeah.
Uh, it, people just don't want, you know, they're afraid that you're gonna break something. Rightfully So. Yeah.
Though, like you could be taking down production workloads, you can, taking down production customer applications. It is, it, it requires you to, to feel that like, impact. And so that's why we think there is a human in the loop still, but as much of everything around it that we can automate as possible, we should.
And I think that does allow us to really start getting out of the continuous patching game and really start burning down these backlogs that we've had forever. Absolutely. Pat patching is, is unfortunately a losing prop.
That's again, something that we've been remediating since 2000 and or trying to do since 2003 and has never gone on. Let me pivot a little bit. We're here at Jfr Swamp Up.
You did present, as I mentioned, and we've been talking about that. What's the connection with Jfr? Let's talk about that.
Yeah, so I'd say overall we share very similar visions, right? When we think about how do we secure development that is happening faster and faster every day, it requires security to move faster, and it requires every team within security to also work together as well. So at Wiz, um, from actually the pretty early days, we have scanned Jfr Artifactory to bring in their understanding of container images and artifacts into Wiz to give that complete understanding of the cloud environment.
Now, what is coming next is we're deepening our integrations because we both believe in that open security ecosystem in order to share context that empowers all of our teams. And so from a Wiz perspective, we have a lot of understanding about the risks associated with cloud. We understand runtime context, the code context as well.
And so we're bringing that prioritization, bringing the risks, and all of that back to Jfr. And similarly, JFR has very deep understandings of packages, right? And so we can take their reachability analysis that, um, acceptability as well, and we can layer that into Wiz and use that context to also further enrich our prioritization as well as the, uh, the move to actually getting to a fix.
I love it. Last question, or last area I want to talk on you. You know, you can't take two steps without tripping over AI here.
What's the AI angle behind all this? Yeah, well, so when we look at ai, there are really two sides of the coin. One is how do we actually secure the AI infrastructure?
And a lot of it is being built on top of cloud. And so for us, it is actually a very natural extension of what we know about cloud environments, right? We need to understand the configuration, the control plan.
We need to understand identities that are associated with it, or non-human identities. In this case, we need to understand the workload layer or the data layer that's being used to train the models and do a complete assessment of the risks that are there. And from there, we can enable now AI teams bring them into the fold, break the walls and silos with them so that they can actually take ownership and help us to secure those elements of their environment.
The other side is around how AI can actually empower all of our defenders, um, to be much smarter to do, to secure things, to take action with less resources. And so we're actually seeing such incredible results there. Um, as an example, we released a new product today called W os.
It's all about hardened container images. So you can start secure. And what we're seeing is we can actually use AI to immediately point out to teams.
These are the most impactful places for you to start deploying this so that you really start getting value right off the bat. And by the way, here's a migration plan, right? Here's everything automated, delivered into the hands of that DevOps team or DevSecOps team so that they can get going on that journey.
Let's talk about that. I'm, I'm sorry, I know I said the last thing, but I got some questions here. So how many, how big is the library, if you will, of these mm-hmm.
Ardent container images, if we can call it that? Yeah, so for us, we are starting with the set that our customers primarily require. So it's all of the major languages.
We've got Ruby, Python, right? We also have FIPs compliant images as well. Wow.
We expect to, um, grow the catalog as we continue seeing customer adoption. But the question that we get from customers, or what we've found through our product development is it's not the number of images, right? Again, it's like the impactfulness, right?
Help me cover the most important components of my containerized environment and then help me actually adopt it. Because that's been one of the key challenges. There are so many container images in an organization.
Security oftentimes is very little visibility even into where are all of my container images, which ones are validated in runtime, right? Which is probably where we should start to focus first. So we're layering on this element of the product with the overall end-to-end container security approach to help organizations again, prioritize, and then actually then swap in where you will have the biggest impact in reducing the number of CVEs.
And this was released today, which, so this is not live. People will be watching this ah, in the next couple days. Yes.
But as of September 9th, correct? It's, it's out Right now. It, it is out in public preview, which means every single one of our customers has access to it and can start adopting it today.
I Love it. Wiz os. Wiz s You heard it here on Text Trunk.
Oh. Um, well, John, thank you so much. I thank you.
I know it's kind of the end of the day, and you were nice enough to come in. I, oh, No, thank, thank you for having me. But keep up the great work, man.
Wiz is doing exciting things in this cloud security and security space in general, so it's great to have you on. Come back. We do this all the time remotely in person.
We'd love to have you back. Thank you. I appreciate that.
Thank You. Jung Lu, uh, with Wiz here at Jfr Swamp Up, that's gonna wrap up our day one coverage here at Jfr. We'll be back tomorrow.
We've got a full day starting, I think at 11 or something, so stay tuned then. But until then, this is Alan Shimel for Techstrong tv. Thanks everyone.
Hi everyone, it's Alan Shimo. Welcome to another episode of Control Alt Deploy. This is a, uh, control Alt Deploy is a podcast we try to do every two weeks or so here at Techstrong.
And we talk about, well, it's, it's really DevOps, but it's DevSecOps, which is kind of, you can't have DevOps these days without DevSecOps. It's about security. It's about how we're, how we're writing in and deploying and running software these days.
It's, it's one of my favorite shows of all the things we do on Techstrong. It is, uh, sponsored by our friends at OpenText. So many thanks to them.
But, um, it's, it's our show. It, it's a tech strong event, a production as we say. And, uh, have a lot of our Textron friends on this particular episode.
I'm looking forward to it. Today's episode is titled Shift Left or Shield right, the Evolution of DevSecOps. And, and that's a loaded question we're gonna have a lot of fun with.
Let me introduce you to our panel members for today. If you watch Textron Gang, you've probably seen a lot of these folks on, on the gang. So they may not be strangers.
Gee, I'm gonna start with our, our friend Kate Scar, and welcome Kate, if you could give people a little bit about you. Sure. I've been, uh, part of, um, I've been doing technology since 1998, started with IBM and again, you know, cybersecurity with us, started with network security, AV and dare I say Tivoli identity and access management, so, Ooh, yeah, no, that, Hey, Tivoli was gonna rule the world.
Thanks, Kate. Um, joining next is our good friend, Tracy Reagan from Deploy Hub. Hey, Ellen.
Hey, you know, Tivoli used to have some pretty righteous parties in Austin. All I have to say about that, and yes, I am Tracy with Deploy Hub. Um, I do get to enjoy being on the gang, uh, on Mondays, which is a lot of fun.
I'm part of the Linux Foundation's open source security foundation, um, board governing board, as well as a continuous delivery foundation's board. And I'm really into open source and I'm really into fixing post-deployment vulnerabilities. Excellent.
Welcome, Chay. It's great as always to have you on. Next up, we have an analyst, gang member, tech field, uh, delegate.
Our good friend Jack, Jack Poller. Hey, Jack. Hey, Alan.
Great to be here. Uh, I am the founder and principal analyst for Paradigm Technica. I have a long history in technology, a few more gray hairs than Kate in a few more years.
Uh, I started as an engineer, turned into a marketing person, and then an industry analyst focusing on cybersecurity. Excellent. Thank you, Jack, and welcome.
It's always, it's always great to have you on. Next up, I wanna introduce you to Garima ba Baal. Uh, well, I'll let Garima introduce herself.
Garima, go ahead. I'm, I am based AWA Canada. I'm the founder for the DevOps Committee of Practice here in Canada, just several chapters.
I'm also the chair for the ambassador program at Condense Delivery Foundation, written several books. And, uh, my latest book, which is coming out, is mastering Security at Scale. So hopefully I can value add to the spam.
Oh, I'm sure you will. Gimi you always bring value to every, every panel, every show we do. So thank you for all you do.
Last but not least, he's, he's the newcomer to our group here today, but we're gonna not hold that against him. Trey Island. Trey, welcome.
Introduce yourself. Uh, thank you very much. Yeah.
Um, I'm based out of Denver, Colorado. I'm a security consultant. Um, so that means I am the technical hands-on demo guy, uh, when it comes to, Hey, how do you integrate application security into your organization?
Are you ready to move to the cloud? Or do you have CICD implementation? So I kind of help with all of that.
Uh, integration with our tools for scanning the source code mobile applications, uh, open source and dynamic scanning. So guys, let's dive into it. com because of what became DevSecOps.
I thought DevOps was gonna give us a chance to do security better, to correct a lot of mistakes that I had seen, you know, in my years in security, we didn't call it DevSecOps. Truthfully, it was rugged DevOps. I remember the fights I had with people in security and the people in DevOps because there is no, there's just one DevOps, you don't need a second there.
You don't need biz in there, you don't need anything. The security people said, ah, you know, it, it should be SEC DevOps, because isn't security first always. Um, and then we, you know, this whole idea of shift left, and I was, I was so gung ho for sh shift left.
I believed in shift left from the bottom of my heart. And it, and it, you know what, over the years caught on DevSecOps became a real thing. Most of the DevOps companies considered themselves DevSecOps companies.
We shifted left and we shifted, left some more, and we even went a little further left, and some began to question, did we go too far left? Is it really working? Maybe we should shift right?
Shift up, shift down, shift everywhere. We still need better security. Kate, if you don't mind, I'm gonna ask you to kick us off here.
Yeah. Did we shift too far? Left?
What shift left the right move? You know, one of the problems that I, I, I feel like we continue to have is that it, I think originally it was a good idea to shift left because the people who were coming out of, um, school, they, we just weren't, it wasn't being taught. So we had to start somewhere in this and shifting left and trying to add security because we were being hit.
I mean, I still remember, you know, the SQL injection attacks in, you know, 2003, 2004. I mean, it, it was, it, it was taken us by surprise, right? And I think at the end of the day though, we still, you know, we became cybersecurity people became these roadblocks and to business and to the dev people.
And, and we were really putting a lot on application teams when they weren't security people at the end of the day. So I, I think we did go too far, um, to the left. And I, and I think that we didn't work together.
We put a burden on them, but we didn't lift a burden and we didn't share that burden going forward. So I think it's better that we are starting to look and, and create this culture of, let's really take a look at this because we all want, um, we all wanna do it safely. I mean, at the end of the day, you know, it, it's, we have to be better at working as a team.
Yes. The team Thing, Greer, go ahead. The team thing, both.
Yeah. Yeah. That, that team thing is so important because, you know, it's, you know, I, I was doing software configuration management in the late nineties all through the early two thousands.
And I never even talked about security. I never even heard about it. I just thought security was something was done behind the other, the, the curtain oz was back there dealing with security, and we didn't have a discussion about it.
There wa there really wasn't any, any tooling to add to anything that we were doing that would improve security. So shifting left was, uh, a, a shock when suddenly we were told, oh, the development team and your, um, your, your SCM at the time needs to have more security in it. We were like, well, what kind, what do we need to do?
And in fact, that was the first time we started looking at, uh, what they call software de bloating now, um, to shrink what libraries we were pulling in, in a shared library environment to try to minimize the amount of libraries that we were bringing in so that we could do better security on the, on the binaries that we had. So it didn't have so many executable, uh, functions in it. So, you know, it's interesting that you say the team part.
'cause I think that's where we got caught up in the beginning and suddenly it was securities got oz, but then you're gonna have to shift it over to the, to the, the munchkins to get the work done. And we didn't know what to do. Yeah, yeah.
It really wasn't being taught. No, not at all. It was security was not taught to developers.
That's for sure. You have computer science emer, you know, the voice of DevOps here. Shift left was such an important piece of it for me.
What about you? It is still an important piece, but what I feel in today's AI era, it is shifting, uh, from a personality perspective, which is basically having more, uh, and new components of, you know, how to integrate security when you are looking at the development stack, because a lot of developers are using AI and AI native tools to kind of in, you know, build code and, you know, also develop and review and test and deploy code, right? So there are new types of security, uh, you know, is required and new, new type of security vulnerabilities are introduced in the code itself.
So shift left is changing, and uh, obviously, uh, there is a lot of upskilling required in that dimension. And why runtime security is important. I'll put some facts on the table so that, uh, you know, we understand the urgency of it.
Uh, there was a report from Checkpoint, which says that, uh, every prompt, which we do, uh, one out of 80 prompts are posing higher risk of, uh, sensitive data leakage. A hundred compromised AI models were deployed into hugging face platform, which is basically ACTO for a lot of people who are using it. And there is dark LLM, you know, the malicious modification of AI models, for example, is happening as we speak.
So if you think about this shifting left had reduced the vulnerability problem by 70%, right? 30% was still runtime security gaps, which we were finding. But now with the injection reduction of AI into various, uh, SDLC lifecycle phases, it becomes more urgent to ensure now we don't look at only runtime security, but also looking at shifting left and seeing what kind of new vulnerabilities are getting added through a AI injection.
I can talk a little bit more about it, but I think from a community point of view, we are seeing a lot of these things which are, which needs upskilling. And, uh, I mean, this is a bad news that, you know, uh, we don't have enough talent. We don't have, uh, enough education and awareness in this dimension.
And where there, where the communities like this, uh, what we drive come handy and we foster that Collaboration. Excellent. Gima, excellent.
Jack, Trey thoughts? Well, I, I may, I don't know if I'll be call it controversial, but I have a slightly different opinion, which is really embrace the power of, and rather than, or which is, I think we need both shift left and shift, right? Which, you know, defense in depth, right?
We are having different types of controls at different points in the process and in the life cycle of the application to solve different problems. Shift left is really, you know, Kate talked about it not teaching cybersecurity to, you know, early engineers, but even senior engineers who know about cybersecurity don't address cybersecurity because functionality, feature functionality and schedule is the most important things to the company, not security. And so we, that's how we measure our developers and our development life cycle, right?
So shift left is a way to introduce cybersecurity into that conversation, to bring it level of importance up so it gets addressed as quickly as possible. That doesn't necessarily make it sufficient to protect our applications. We also need security shifted, right?
To do more at runtime, to catch things that can't be caught at the early stages of the development lifecycle. Fair Tre, you're talking to real life customers, users. What, what's your view on this Shift?
Left is very important. I think the problem, the problem resides when security then offloads their responsibilities onto the developers. And the developers then decide what security tools they want to use because of ease of use.
Not necessarily this tool is better than the other. I've seen a lot of that issues where developers then have a lot of power to dictate what security tools will be used, but they don't really have metrics of why other than, oh, this, this works really good in my ID as far as ease ability, but what security checks are in place. I see a lot of that.
Um, now with these AI tools, it's gonna be up to security to continue to research and understand these vulnerabilities. I think it, for me, my background was, I was a developer before I became a security analyst, before I became a security consultant. So I'm kind of able to have a conversation at a lower level rather than just, Hey, go fix this because the report says, so that I think is a lot where there is contention between developers and security analyst.
'cause the first thing a developer will say, okay, can you tell me why? Or do you, my, my application works like this. Why is this a vulnerability?
You can't just say, it's only in the report, go fix it. You have to go on that other level. Um, so that's where security is gonna have to continue to do their work, their research, their efforts.
And I see AI as a complimentary tool. Um, the problem I see on the development side, if it continues to go down this path, is this whole thing with open source, right? You have something in your code that you did not create.
You don't have a good understanding of it. And if you're just going to use these AI tools to generate an application, you're not gonna have a good understanding and you're probably have a lot of loaded code for functionality you didn't even need to utilize. So that's where organization's gonna have to lock down what tools that they allow.
Forget talks code, you have Insecure code. But go ahead, chase. Go.
I'm sorry. Let's Talk about, let's talk about tools for a minute. So I just spent the last week we have the, at the CD foundation.
Kate and I are on a, a special interest group called the CICD cybersecurity. I'm sick. And we have a deliverable.
So I, I gave up this last week to start working on looking at tools and how they fit within the secure software development framework. And I'm not gonna say AI's out there, and it's gonna probably change the way we do things, but there are so many tools today. I am, I was shocked by the number of open source tools that have been delivered to the industry that I know we're not, we're not using yet.
Not everybody's using them, we're taking them serious. It it just look at the problem with generating SBOs. Not everybody generates an sbo, one of the core components of your secure pipeline.
So we have to remember that while we have this shift left discussion, and many of these tools are on the left side of the house, there's also many that the platform engineering teams are gonna start using that are sort of squished to the middle. Yeah. And, and many of those ones in the middle are, are actually starting to monitor what's happening in production.
So maybe we've come to a place where we're shifting, um, we're shifting a, a lot of tooling into the middle that catches things as it's coming through the pipeline, if they're adding it and it's starting to monitor what's happening in production. I really was surprised by the number of open source tools and the, and the security features that these tools offer that can fit today without any ai, without any new, new tooling to solve some of these problems. Um, and I, you know, I hope when this document gets out that people can use it as a research tool because it is shocking.
I mean, I, I was thinking I'd have five or six tools per category, and I'm looking at 25, 30 tools per category. Wow. All of them doing something a little different and solving the problem in a different way.
But they do relate specifically to the challenges that have been brought up in this, in the secure software development framework. And it's a really good guideline to use that framework because it gives you a real, a clear indication of what your goals are, but it doesn't tell you how to solve them. So what we were trying to do is say, here are the tools that will solve these.
And I were shocked. I was really shocked. It's taken me all week to get just a few of these pages done because there's so many tools and sorting out what they do to fit that has been a challenge.
So I'm hoping this helps. I really do, because we don't need to wait for AI to solve the problem. There are tools out there that can do it today.
Yeah, yeah. And, and true. I love it.
I think you used a key word, um, platform engineering this idea about that, right? It does come to that middle. It, it, it really, um, I think it's a perfect word to that encompasses, um, everything that we're talking about from the shifting left to the, you know, runtime application protection.
It, it, it gives this whole more of a holistic view and I think where organizations are, are moving and it's better. Um, I do wanna address quickly, if you don't mind, uh, with Jack this defense in depth. You know, it's something from a strategy point of view that I have seen that really isn't working.
And the reason being is that it almost creates more of this whack-a-mole type of strategy where you get a, a vulnerability and you get a tool and you hit it. I think in what we are trying to work on, um, with, with Tracy, um, is more of this holistic type of picture and a strategy that is more proactive instead of like a proactive offense, more so than a strategic, um, defense, which is different when you think about it. You know, you still need to have an offense strategy.
It doesn't mean that we are going to attack. It just means that we're setting ourselves up in a position that we understand, hey, a heavy hitter is coming to, um, to hit, are we gonna be all in the infield or are we gonna go to the, you know, off field and get ready because we understand that it's coming. We know the threats, we understand the attacks.
There really isn't anything new even with I ai, they're still the same attacks. We know this. And, and so, um, with the tools that are out there, some phenomenal tools like Tracy is saying, it's, it's, it's, it's such a beautiful time to be a part of cybersecurity.
I, I, I'll, I'll tell you, I don't disagree with you at all. I highlight defense in depth more to highlight that a single tool is not a silver bullet, right? That we are not that simply doing shift left and doing static code analysis or dynamic code analysis, whatever your shift left or combination of shift left tools is gonna give you isn't going to solve or, or provide you perfect security.
Right? And I think you mentioned in the word holistic, which is right, is that we want to think about the entire gamut of everything from the very start of the project architecting security into the design, through the coding phase, through the test phase, through the deployment phase, through runtime. And then even how do you end of life the product and how do you secure, right?
And what do you do with the data at the end? It's an entire picture and there's an entire set of problems. And one tool or one small set of tools shifting left is not going to solve our problems.
So I'd like people to think about it as, and, and I, I appreciate the, the, the, the analogy of whack-a-mole we do in cybersecurity, spend a huge amount of time doing whack-a-mole, which is, I believe the wrong way to do it. And I think the right way to do it is say that we have seen these problems in a slightly different domain. AI is a brand new domain, but it is still a data leak problem, right?
And how do we treat data leak problems and can we, uh, uh, repurpose tools or apply the same tools as Tracy said, where you said there's hundreds and hundreds of tools. How do we use these tools to solve that problem without saying, oh, we have to wait for ai. Yeah, I I would also like to shift this discussion to runtime security.
And you know, of, of course, there's a majority of work which is needed to be done in terms of, you know, securing the legacy or securing the as is or status quo situation. For a lot of organizations, you know, there's a maturity curve. So a lot of organizations are already behind, right?
So the 70% of vulnerabilities, which can be found through injecting security through shift left is not already happening. So that addresses or caters to that. But if you think about runtime security and why it is becoming more and more important, and, uh, the CXOs have a shorter runway of 36 months to prove this because AI is coming, and I'll highlight three points.
LLMs, you know, you, like it or not, developers have started to use LLMs in many shapes and forms. So the LLMs are creating code, right? The second part is prompts.
So we all use prompts, right? And if you think about what tasks software engineers are accomplishing through prompts, there are many, right? So test case generation, for example, has a high kind of volume where, you know, people are generating, uh, test cases through prompt engineering, right?
So, uh, the third aspect is AI agents, you know, if you like it or not, the AI agents are coming in the operation stack as well, and they're using LLMs. So for these three special components, which AI is bringing, we need a special, uh, security mindset. We need to have, you know, specialized components and security guardrails to not to inject malicious code, for example, uh, data poisoning through prompt injections.
Even AI agents, they are playing a, uh, a bigger role because a lot of autonomy and decision making is happening through AI agents. So it is more and more important that, uh, people start to invest in runtime security. I, I don't disagree at all.
I, you know what, I, I like the term shift everywhere. I, and I, it's not my term, actually, I first heard it from my friend Jeff Williams from Contrast Security, right? But certainly we've got a shift left, but we can't expect our developers to become security Pros, right?
As re said, they're going to, they're going to lowest common denominate, a least path of least resistance, whatever one's easier for them, whether it's good security or not, it's something, but we do need to have runtime controls. We need to remember that security doesn't end at the Deploy button, or we don't actually press a button for Deploy anymore, do we? But it doesn't end at the deploy it, that that mission continues as well.
And, and so I would like to see a holistic security view of, you know, throughout that the lifecycle, not just of software development, but of software operations, right? Observability and security is, is something we haven't talked on here, but that needs to be part of this as well. Um, I, you know, we, security's important and no matter who you talk to, I think no one says, ah, security's not really important.
We all say it's important, but we can't just focus on the security over here or the security over there, or at this stage or that stage. Every stage needs security. And I, I think the, one of the problems with security left is we took our eye off the ball of right.
And runtime and, and these other, these other places, um, Uh, you know, being a, you know, I wanna, I wanna, I wanna disagree with that statement just for a minute. Go ahead. Because, you know, if you look at what the open SSF has done, which I work with quite often, and they talk about security all the time, there has been a quite a bit of work done on trying to create that holistic view.
That's why I'm gonna push again, if you have not read the SSDF, this is a, this is like a, a reminder to do that because the goal was to create that holistic view, and there has been a ton of work on creating that holistic view. So read the SSDF because it's, that's what that is. I I will and I should.
And, and Tracy and Kate, when you guys do finish this deliverable here from the, uh, CDF, I'd love to have it either on some one of our tech strong properties. Let's get you both on and, and, you know, shine a light on it because it sounds interesting. Trey, I feel like we haven't heard enough from you on this.
What are you, what are you making of this discussion? No, absolutely. With runtime, right?
You have no, you have an idea of how your application should run when it's under a load, when users are actually actively using your application. But there's always that use case, and sometimes it only takes one to break your application or have data leak. That's why it is important.
It's not important. It's important to have these tools, right? But it's also, why do we have these tools, observability, what are we doing with that data?
Who's managing that data? If a tool is fading, failing, what is the corrective action, right? It's all these things you just can't throw.
And like, uh, Tracy was saying, there's so many tools out there. How do we actually, um, identify the ones that are correct for our use case? There could be a tool that's gonna be great for one company, does not mean it's gonna be great for our company or our application.
So that's where a lot of that research does have to come into play. Um, and having information on the log injection, how is the host running? All of that is important, of course, after the development phase.
But if we can do that in every phase development static, well, static analysis, dynamic analysis, how is it running that is gonna give the holistic view, but sometimes I see is there's so much on dev teams to do almost all of that. And they're great at developing code now you're working them to put another hat on, another hat on. And in my role in the past, because I'm a jack of all trades, I enjoy learning things, but I'm not ne I necessarily did not have teammates that had that same, uh, go get it mindset.
And then you feel like you're my last name. Like you're on an island all by yourself. Um, Yeah.
And, and there is that, that we need I'm sorry, go chase. I have one, one, I it based on what Trey just said, something came to mind what companies can do to start understanding their gaps in their shift everywhere approach is they, like we, we did in chaos engineering, we need to start doing game days where a, a fictional, uh, you know, software supply chain, CVE, that's critical or high risk is floating out there in your live environments. Watch to see how long it takes your team to re respond to it.
What is your meantime to remediation? Those are the kinds of things that organizations should start looking at. Uh, because I'm, right now it's over a hundred days.
We've gotta get it down to less than 15, less than 10 would be good, because it only takes 10 to exploit. But we ha we are over a hundred days folks, and that doesn't work. So game days would be a really important, um, exercise for your team to start practicing because it means every single person in the organization from developers who have to recreate the, the new POM files all the way out to the deployments have to, that that whole, that whole cycle has to be hit when there's one vulnerability that has to be fixed.
Great. Hey, Jack, I'm sorry. Go ahead, Kate.
Oh, I, I was just gonna say, I'll come, you'll come back to Jack Go. So, um, so quickly, the only thing that I'll, I'll add is that, you know, it's not as bad as it was meaning, um, you know, when we used to go talk to application teams, there used to be like, you know, what are we talking about? Like, you have no, I like, and there was such a pushback.
You don't see that today. Today. You actually have people who are interested and, um, who are concerned and still feeling overwhelmed by, by all the different tools that are out there.
And I, and I think, um, and, and I believe the way that Tracy, you know, broke things down very easily, um, within this deliverable, I, I believe that it will help. But making it simple, I think will, will go a long way into making SAC important in DevSecOps. Go ahead, Jack.
I'm sorry, I I don't disagree. Jack, when you talk to consultative clients, right? Analyst service, do they take this?
Do they ask, do they want a holistic approach that shift everywhere? Or do they focus in on a particular stop along the SDLC? I think they, right now, vendors are primarily focused on a particular stop along the SDLC because they perceive that as a way to market and sell.
Not that that's what's really needed. And something that Kate sort of said resonated with me. Part of what I see and what I bring back to vendors is when I talk to practitioners, they complain that the security tools are built for security people, not for developers, right?
When, when I was a, early on in my engineering career, I started out as a software engineer, and then I went and started developing chips. And one of my mentors in the chip development space said, well, all the code you wrote for the chip will work, but you write it like a software guy, not like a hardware guy would. And it took me a long time to figure out what that meant.
And it's really you, the way people do things and operate in DevOps is a different mindset comes out. You start with different assumptions, different perceptions than you do with when you start out as a security person. And think about it as a security person, I think the security tool developers need to put themselves in the position of the practitioners and have people like Trey with them who can represent the practitioner point of view and say, this is how we really use that type of tool in our environment.
Build it for us, not build it for you. And I think that will really help Build it for us, not for you. I think that's a great place where we call pull the plug on this, Jack.
It's a good, good way to end it. Build it for them, not for you. Kate, Tracy Reemer, Jack, Trey, thank you all so much for joining us.
We, we try to keep these to a half hour. We're a little over, but we're close. Many thanks to OpenText for their sponsorship of this and all they contribute, so we appreciate it.
Many thanks for you to you guys for watching. We'll be back in another two weeks with another Control Alt Deploy, and we might be doing some more live round tables where you can take part in them as well. So stay tuned for that.
Until then, for Control, alt Deploy and Techstrong Ms. Allen Hummel, we're out Running enterprise Applications in production is a lot different from the AI experiments many of us have been involved with so far. This episode of the Tech Field Day podcast recorded prior to NetApp Insight 2025 features Ingo Fuchs from NetApp, along with Gina Rosenthal and Glen Decker, and myself, Steven FoST, talking about how enterprises are bringing AI applications to production.
Welcome To the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about key concepts in the industry. This podcast features a variety of perspectives from members of the Tech Field Day community, including delegates and presenters. And this episode is recorded in association with our attendance at NetApp Insight 2025, which is on October 14th.
Tech Field Day is part of the Futurum Group, and this podcast is also published by our sister company Techstrong tv. In this episode, we look ahead to NetApp Insight and are discussing the many ways that companies are moving enterprise AI applications from experiments to production. But before we start that conversation, let's meet who's on the panel today.
Hi Steven and team, very nice to be, uh, here with you today as we're getting ready for the amazing insight event. My name is Ingo Fuchs and I'm the Chief technologist for AI at NetApp. And I'm Glenn Decker.
I am a global principal technologist at Equinix. Uh, I kind of oversee pre-sales, uh, strategy for our, uh, enterprise storage and, uh, data strategy, uh, for our, our customers. Um, and, uh, look forward to the conversation.
Hey there, I'm Gina Rosenthal and I'm a fractional product marketing, um, expert. And I work with lots of B2B companies that are doing AI for their customers. And I am Steven Foskett, the organizer of Tech Field Day, and I am thrilled to be attending NetApp Insight once again with all of the folks on this panel.
And, uh, also of course, this is a topic that's near and dear to me. Uh, we recently launched our utilizing tech, uh, season nine, which is focused on AI applications. Uh, we've been talking about this on the, uh, tech Field Day podcast, and of course on the rundown in the Textron gang as well.
And I think that the topic of today's conversation is something that we've all been talking around quite a lot, and that is that as we move from playing around and experimenting with AI to actual AI powered applications, we are opening up a whole new world of requirements in terms of data protection, uh, data classification, making sure that things are really production ready. Ingo, I wanna start with you because I know that you work with your clients on this exact topic on a regular basis. What are the real production enterprise requirements for AI applications?
Yeah, I think I, I always like to start by talking about data, right? Because data fuels AI very obviously, right? So you need electricity and you need data.
Um, so to drive your AI data pipelines and, and build your AI factories. And so when it comes to data, there are really five questions that I always like to ask, um, when, when we're having these conversations. One is, do you know where your data is that you want to use for AI workflows?
That's where it all starts, right? And that could be on premises in many different locations. That can be in the cloud, that can be hosted clouds, that can be sovereign clouds, that can be new clouds, which are these new GPU clouds.
So data can be all over the place, including shadow ai, right? So a lot of customers that start their AI experiments, they built a little silo over on the side. They put like a singular workflow on there.
They have a data scientist work on it, maybe a data engineer or two, but it's relatively small in scale. And things that work in the silo may not work the same once you go global. So where is your data's kind of the first question.
The second question that I always like to ask is, what is in your data? So do you actually know what you have in that data? Can you classify that data?
Is there personally identifiable information in there? Is there credit card data in there? You some critical data that you absolutely cannot let move through the data pipeline to an agent or to a chat bot.
'cause if you don't let the customer credit data, credit card information even get to the agent, then you don't have to worry about restricting the agent from giving that information out. So if you stop that data from getting into the pipeline, that's the right time when you want to stop that data that you don't want to get out. So where is your data?
What is your data? There's a lot of conversation about structured versus unstructured data because in ai, most of the data that flows into AI workloads is unstructured data. So now you would need to put a structure over that data, which is really what vectorization and embeddings are about.
And then you end up with this vector database load. You might need 10 x the capacity of your original data just to build the structure just to do your embedding some vectorization. So that's critical.
That's number three. Number four is your data current. A lot of customers have data all over the place.
And to find out whether or not this data has been updated is a complex and costly project. And you may only wanna do this once a day, once a week, once a month, once a quarter, depending on the complexity of your environment and how much compute and networking and other capabilities you have. But now, if you have, let's say, a customer service chat bot that's operating on data that's a month old, it's not gonna be very useful.
And then finally, and maybe most importantly, is the data appropriate and ethical for your workflows. So it may be legal, but it is, is it ethical? Is it in line with how you want your organization to be seen by your clients and by your customers?
So you have, you may have a lot of really deep insights into your customers, but if you start make, making pricing decisions or other decisions based on that, is that gonna cause some negative perception in your customer base? So it may be completely legal to use certain data, but is it ethical? Is it appropriate?
Is it in line with the kind of morals that you wanna put out there about your organization? So those are kind of the five questions that always start the conversation with, which has nothing to do with infrastructure, but infrastructure helps tremendously in solving some of these challenges. Yeah, I, I would look at these five questions and you know, I I, I, after digesting them, um, none of them have easy answers, right?
And, uh, and of course, infrastructure doesn't solve any of those questions directly, right? It th there, these are things that must be dealt with by AI centers of, of excellences in, in the enterprise and, and executives. And not just data, the scientists, but lines of business and, and of course lines of businesses where are aware all of the, uh, AI workloads seem to be starting these days.
But, uh, you know, for instance, like where is that data? Uh, that data could be, uh, you know, all spread out through your global organization. A lot of it could be in SaaS platforms that aren't even within your perimeter, right?
And you have to somehow get that all in. Um, and you know, what we're finding is that, uh, many times once customers try to start AI and, you know, endeavors, they'll go and do it in the cloud. 'cause it's easier to start doing something with synthetic data or small data sets that aren't represented of the full production workload.
And then, uh, when they go and bring it to try to get it to pilot even or to production, all of a sudden, whoops. Can't, can't do it that easily. I gotta go pull in all those data sources.
I gotta do curation, I gotta do duplication, I gotta do all these things. So, uh, so, but what we're finding is that, um, you do need to, to, to deal with that data very, very early on as you've first determined your use cases and you're doing data discovery, which is in and of itself is a huge project. Uh, but there is value in consolidating at least one copy of that data, um, I'll call it, on equipment you control and locations you can access, right?
So that from a compliance perspective, which goes to your fifth question, I think you, you also have to add in governance and compliance to, to, uh, appropriateness and ethicality, right? 'cause that's honestly the way the world works in the diff you know, with GDPR Cloud Act, all these different things going on, the AI act there, there's a lot of constraints on what you can do with this data. So, um, bringing at least one copy of that data onto stuff that's totally under your control, which you then can now move to clouds and neo clouds, as you're talking about that data mobility, that ability to, to take that data that you've got and do what you want with it, when you want with it, it's gonna be key because you have no idea what your future AI life is going to look like.
So if that's the case, then you must build in this ability to change, right? And so the ability to have data sets move from one platform to another in a common management framework, right? In a common way of accessing, controlling, and governing, right?
Um, I, I, I happen to know of about a company that does that. By the way, ngo, you, you may know them pretty well, but, uh, that facility coming first before you are even thinking about the broader impli implications of infrastructure, GPUs, right? Um, liquid cooling, all those kind of things.
The data is absolutely first, you're right. But you've gotta bring that data to, uh, in, in a first place. You need to build that kind of core where that data can sit, um, in, in that governed way where that's where your curation, your data duplication, and you can deal with all the five of the questions, at least the, the remaining four, what's in it structured versus unstructured, right?
Is it current, right? And then dealing with the, with the governance and the compliance of that data. Those are the other four questions.
So to answer, for an organization to answer question number one, it's in their best interest to discover, consolidate onto something physical and then get that data back out where you want to experiment with it. Yeah. And I would, I would expand on that a little bit.
Uh, is that, so this really leads to this idea of unified data model where all of your data is seen in a singular model, and then you can apply your applications against that. Similar to what you described Glen. And, and part of that is because a lot of times there might be this new groundbreaking model or a new groundbreaking application, or you choose a vendor to, um, apply their chat bots against your data instead of building them your own.
We see a lot of statistics that using off the shelves, AI applications, typically majority of cases, cases today, leads to better production outcomes than trying to do it all yourself. It's, so it often is kind of a mixture of things. But let's say you have a public cloud provider that comes out with this new application that you want to apply to your data, and some of the data might sit in that same cloud, might sit in different cloud, might sit on premises.
How can you build a peering model or a caching model or data transfer model that gives you the most efficient way to apply these applications against the data that you have, regardless of where it is? So for me, that's all a question about this unified data model that spans all of your different deployment locations and infrastructures and sites and models to say, listen, you might have 80% of this data on premises, but 20% is in a cloud. And can you then peer to that cloud?
Or can you c to that cloud just the amount of data that you want? And then also not leave another copy behind. I think that is one of the biggest problems that we are seeing right now is that there are so many copies and nobody wants to throw anything away.
A lot of companies have very strict rules about how long to keep things, but not very good policies about when to get rid of things. Nobody wants to be at fault for having permanently removed data, and then suddenly somebody changes their mind. And so this unified data model can really help with that problem of just having this full view, like you described, about what data you have, where it is, um, and then where the applications are that should be looking at this data and using this data.
I think it's really interesting, everything y'all have said so far is just data center hygiene. It's not even data center hygiene, it is application hygiene. So I think everybody has raced to, to juice their ideas and to put those ideas, um, to work and find a way to make them work with different, um, architectures and models and different, um, ways of doing things.
But now all of a sudden it's like, hey, yeah, how do we, like you were saying in the beginning, how do we make this, uh, enterprise ready? How do we make this production ready? And I think that's where, just from clients that I've been working with, people find out, oh, we really don't have the data the right way, or we don't, we have everything, every place.
Or we went and we purchased a bunch of infrastructure and it's not going to suit the purpose of this application. What do we do? So I think one thing I'm really looking forward to hearing about at NetApp is to hear these customers like be able to talk to customers and hear more about, uh, the transition plans that they have, or kind of the gotcha moments they, they hear, because this, we repeat this every cycle.
We do something new. We were talking about that earlier, whether it's cloud computing, I can remember a lot of this 'cause I was a cisman going from, from whatever to when Linux, well, from Solaris to Linux. Like all of those applications had to be rewritten and why, you know, so it's kind of like the same kind of kind of thing as before, but it always goes back to let's be computer scientists and let's remember what are we building and why are we building, and then what is the correct application for it?
And we have so many new things that we can do. Like, so having a, a unified namespace or unified area where you can see all of the data where it is and maybe be able to use that at one time for one, um, purpose is, is really kind of mind blowing when you think back across 30 years of, of computing that that's even possible to do. It's pretty amazing.
So I'm, I'm looking forward to seeing how your customers are doing that and how you guys are actually supporting them. It's gonna be kind of cool. Yeah, I think that the also, you know, when you, when you have that, the, the enterprise data that's been, that, that, that runs throughout an organization and, um, you've, you've now created this, this, this factory and, and the first kind of station in the AI factory is of course the data pipeline, right?
Um, that, and things are changing so fast in this field that the needs of data and from a performance, from a, uh, uh, just a retention perspective are, are changing, um, so fast. And, and companies don't know what AI is gonna look like in, in another year or two. Uh, it's most of the time.
And, and we've seen up till now. And, and, and, you know, some of the things you've said imply this, right? That, you know, enterprises are gonna try to pull down existing models, um, or, you know, use commercial models, uh, perhaps and, and just try to use rag against them with vector databases.
And that was kind of, I'll, I'll say that was the first or second wave of the ai, you know, folks that are coming out, we're already seeing that. Um, you know, not all rag is vector databases, right? There's a lot of, especially as you now to bring agentic, right?
Ag agentic is the next wave. And agentic really implies things talking to things in an automated way, everywhere, uh, data, I mean the, the, the amount of compliance and governance, uh, uh, and security concerns that, that, that arise from just the, the explosion of this, uh, it's kind of mind boggling. Um, companies don't know if they're gonna be maybe dabbling into some fine tuning smaller models, expert models, right?
That all, all cont uh, are contingent upon the data being ready for all of these possible different use cases that you have no idea if you're gonna need to go use it next year, two years, three years. And, and so keeping data in, in any tier, whether it's, you know, in, in checkpoints, I mean, even now with the reasoning models, making things even worse because now, um, we see, uh, KV cache being stored as a state, an intermediate state that can be sent to the edge and used in real time for high performance inference at the edge, um, that also requires high speed storage. It also requires data motion capabilities, consistent data motion capabilities.
It's just like all of these things have come out in the last 18 months and no one has had time to digest all this stuff. The rate of change is only accelerating, ironically, being accelerated by AI itself, right? And, and our use of it.
So it's like, uh, the thing you need first is to make sure the data platform that hosts all this stuff is gonna be able to accommodate this rate of change with you as you go and figure out this new stuff. Because as you get to production, um, you need something that's gonna grow with you and be able to scale on a specific use case that you may not even know you're gonna do for another two years. See, I'm hoping the next wave is people are actually gonna take a breath and take a beat and figure out how to do this in the appropriate way so they can move from, um, science experiments to production.
Oh, I, I hope with you, I'm not, I'm not so sure it's gonna happen, but I think it has to happen. And that's the thing, I think that that is interesting about going to something like NetApp Insight, where you have like real enterprise people trying to do real enterprise things as opposed to a lot of this breathless AI hype stuff that we get exposed to on a daily basis. Like the people that go to Insight and the people that are NetApp customers, they're not interested in hype, they're interested in building a Yeah.
Supportable, profitable, you know, productive enterprise application. And so for me, when I go to an event like that, it's talking to people who are really doing this stuff and learning from them. Like, what were the challenges?
And I think that that's the most interesting thing that Ingo, uh, brought up, is that, um, it, it doesn't start with GPUs and models. It starts with data, right? Yeah.
It, it really does. And I think, um, all of your points are really, really valid. And, uh, I wish we had like six hours on this podcast to go into how we are going to move from file and block protocols to semantic understanding of data and how you just talk in conversationally with your storage system in the future and, and how all of that is changing.
But, um, Steven, to your points, I think a lot of the conversations that I have had with customers over the, the last, you know, year or two were really focused on, oh, ransomware attacks are now powered by ai, how I'm going to protect from that, you know, oh, now I need AI powered ransomware protection to protect me from that. Now I have AI workloads and, and pipelines that are sharing the same infrastructure as my, all of my other Oracle sql, all of my other workloads that I have in my enterprise today. So suddenly this old conversation about secure multi-tenancy is a core conversation.
Again, how and quality of service, if somebody were to introduce a rogue agent into my shared infrastructure, can this rogue agent take down my other production application that I rely on that are actually producing things in a physical factory? Can my AI factory take down my physical factory, right? So there's just, you know, how do you peaceful coexist with the infrastructure that your business rely on today while you're building applications for your next competitive advantage that ultimately run on the same infrastructure unless you do wanna build a separate data center.
Gina and I talked about exactly this two episodes ago on the Tech Field Day podcast, and we are a hundred percent in agreement in alignment with you on this. Definitely. Absolutely.
And so it's, I just find, um, there is a little bit of a translation layer, and I've seen it with cloud, I've seen it with DevOps and containers the same, uh, thing. And I think, Gina, you talked about Linux, how Linux became an enterprise class operating system, and, uh, production applications running on it is starting with web service, right? Which is really kind of important, you know, aspect of an enterprise environment.
And so, um, we need to, I think all of us in this industry need to do a better job at translating the language of what AI practitioners are looking for and, and map that to the things that IT practitioners understand the value of snapshots, the values of efficient mirroring the values of data deduplication, and, uh, protecting from copy sprawl, uh, efficient data protection, peering into the cloud, caching into the cloud, and back from the cloud. All things that people have really figured out over decades. But we are all using our language.
And then AI practitioners usually use a different language, and we almost need a little bit of that translation layer to say like, this is not a brand new thing that you have to build. This is something that companies have figured out in the past. We can apply these experiences, especially for production.
And what that will help us achieve is that we go away from this, you know, making decisions based on milliseconds and iops and, you know, how many agent requests can I transact per second into, oh, my data scientist can be productive three weeks faster, right? If I have a data scientist sit around for three weeks, not doing anything, waiting for infrastructure to actually deliver data to the application, that is very, very bad, right? From a productivity perspective, if I can cut days or weeks out of these waiting periods, um, that is really ultimately making a huge difference.
So I, I love that analogy so much. And, um, I think you are absolutely spot on with, you know, our job has always been as operations people to support the business. And that this point in time, it's like, how do we support folks doing ai?
How do we support the data scientists? How do we support everyone on that end? Um, and that translations needed.
I remember I started doing the translations for SaaS. I could show you some of my presentations I did when everybody laughed at me, when me, when I did them at operations, different type of operations shows. So I think, um, I'm, I'm looking forward to seeing how y'all are gonna do that translation when we get to Insight and, um, hopefully there's gonna be a lot of hands-on labs and stuff, so we can actually get our hands dirty and do that too.
Absolutely. Yes, for sure. And, uh, we are building like, some really great experiences.
Uh, it's specifically targeted at giving people with a strong storage background and, and, you know, the opportunity to expose themselves to, oh, this is what a data engineer is asking for, and this is how I can help. This is what a data scientist is looking for, the end of the data data scientists wants to see URI to point an application at. They don't wanna know what all the infrastructure is, where the data is coming from.
They typically don't, don't care. The data engineer cares, right? And so we wanna create some transparency there and expose the very storage focused audiences at insight to this is what a data engineer is asking for and why, and how you can help.
And this is what a data scientist is asking for, and how your knowledge will help the data scientists and it'll make it practitioners just that much more relevant and important, uh, and it will make all of our customers that much more impactful and, and quicker, uh, to getting their AI factories up and running and be productive. Yeah, I think, I think know, we, we've all probably seen the MIT study that was talking about how, so, you know, such a large percentage of of AI projects today are not producing the value that was anticipated, right? And so, um, the, I think, and, and their finding really was just that you're, you're going after the wrong things.
And so the good news is that, and, and the folks usually see it inside of the kind of folks we're gonna be solving the back office, the, the productivity problems, not just the, the content marketing stuff that we've been, you know, that we've been enjoying over the past couple of years now. But now that I think organizations are gonna be focused on really producing true business outcomes that are gonna be visible on the bottom lines, right? I think you're gonna see a lot more folks in IT get a lot more knowledgeable on AI and, you know, all the constructs on, on what a neural network is, what is back propagation, right?
What, how does all this work? You know, what, what's an attention mechanism? They're gonna know you're gonna need to know this stuff.
And, um, then those same people are gonna be able to apply that knowledge back to their IT architecture, um, you know, their kind of schema that they kind of know because they're gonna, they're gonna be the ones who are gonna have to build the data fabrics of the future, right? They're the ones who are gonna have to build this distributed, whether it's in cloud, and it's gonna be, by the way, an and not an OR in the, in the multi-cloud, in the, you know, on on-prem, multiple regions, right? Uh, out to the edge.
Um, and so that data platform is gonna be that, that, that thing that drives the success and, and all the repetitive outcomes out of AI that are gonna be, need to be generated. This isn't gonna be like, you're going have to two tr two things, take the win and go home. This is gonna be a repetitive, and, and every business is gonna be looking for more and more and more value out of ai.
And every, every time you do that, they're gonna be getting better. And that data platform is gonna be become more and more important because now it's driving everything in the business that drives all the AI outcomes, all the models, all the tuning and rag, all that stuff starts with that data platform. So that's why it's just so imperative that people figure this out.
I, I absolutely agree, uh, with you. And, and there is absolutely a lot of educational opportunity there, um, that, that we need to, you know, see through and offer. And in fact, we even offer NVIDIA certifications this year.
So if for folks that are attending inside or have attended inside in the past, you know, you can all get all kinds of, you know, like NetApp certifications, et cetera. You can even get certified on NVIDIA certifications, uh, at our conference. And it's reflecting exactly what you said is you can't just ignore ai.
I mean, you can, but, you know, if you would like to stay employed and be effective and have an impact, uh, in your organization, it's probably a good idea to get up to speed on all these CI topics and how you as an IT specialist, a storage specialist, how you can make a really meaningful impact, uh, to your organization. Yeah. I, I was actually gonna ask you about some of the recommendations, Ingo, that you have for insight, um, if people are attending, and also for people joining remotely, uh, I know that there's going to be some, uh, sessions including, by the way, I should point out Tech Field Day videos.
We will be posting some Tech Field Day videos, uh, maybe featuring from some familiar spaces from this, uh, this here recording, um, after the, uh, shortly, shortly after NetApp Insight. Um, what else? Uh, you know, is it too late for people to get involved?
Uh, how can they come and join us, and are there opportunities to connect online? Yeah, absolutely. I mean, uh, the, uh, the registrations are open for insight.
Uh, we're still, uh, taking, uh, registrations, it's getting tight, so, uh, sign up now. Um, but obviously for those of you that can't make it, uh, we have the, uh, we have the streams, especially for the main stage sessions, which I think will be very, very interesting. And I, I cannot tell you about some of the amazing speakers we're going to have.
Um, but certainly AI will be a very, very big topic, uh, at inside this year. And then yet, tech Fieldy will be able to really sit down and, and have some very in-depth and detailed conversations. Um, you know, Stephen, between your representatives and some key people here at NetApp, including, I believe we will have our chief data scientist, uh, there involved in one of the sessions.
And we have some really great engineering, uh, folks that will really provide a lot of the behind the curtain kind of details of how we have achieved the things that we have achieved, why we have made certain choices, and how this is really changing fundamentally how customers should think about infrastructure in the context of AI in production. And on that note, um, you know, I think that there's, there's definitely a lot coming from this. Uh, Gina Glenn, you're both attending with me.
I already said that my favorite part of events, like Insight is talking to the customers that are there, uh, who have incredible experience. Another thing that I always look forward to is, uh, getting a chance to meet some of the incredible, um, sort of luminaries that companies bring in for these events, whether they're on stage or contributing. Uh, Gina, what do you look forward to at NetApp Insight, and what are you hoping to take away from it?
Uh, both are the things you said. I definitely wanna talk to customers. I really wanna see who's going to be on the show floor, the other vendors, and talk to them about how they're working with NetApp.
I have a lot of friends that work at NetApp, so I'm, I'm very excited to catch up with people. Um, sounds like I'm gonna be doing some hands-on labs and seeing some of these things that Ingo was talking about. Um, what I wanna take away from is I wanna see where customers are, number one.
Like, where really are they? 'cause I'm, I'm hearing from, you know, other, what some of my clients, hearing from them about what their customers are saying and what the problems are, and how we're gonna, you know, from a marketing perspective, how do we work on that? And I'm also interested in hearing about talking to my friends who are on the marketing teams.
Like how are you guys positioning things and how are you con positioning, um, working with your partners and things like that. So, Uh, so, so Insight. Um, I've been going for quite a few years now, and, um, net NetApp kind of set the standard at Insight for technical content that they delivered in the sessions.
Um, they, they, they tried to stay away from being too, uh, too salesy and, and, and try to show you how things worked and got pretty down and dirty with stuff. So the sessions, uh, you know, I'll try to consume as many of them as I can, uh, in, in especially those sessions that are demonstrating how NetApp is solving for outcomes and ai, right? How you're, how am I getting this data ready to be consumed by either, you know, inference through rag or for, you know, getting it ready and, and, uh, and getting it, um, you know, you know, curated and groomed for, uh, for training and tuning and things like that.
So, uh, and, and also moving it around, uh, in that case, how, how is NetApp using its core strengths in data motion and consistency, um, to meet the needs of, of customers in a distributed AI world. And so that, that, uh, has particular meaning to me in my role, but, uh, showing how that works. Insight's always been really good at, at getting to that how, right?
Instead of just the what. So that's what I'm looking forward to. Well, I'm glad that y'all are coming.
I can't wait to see y'all there. Um, those of you watching, again, watch the Tech Field Day Channel. Watch the Techstrong TV app.
You'll see a lot of great content there. Uh, before we go, uh, Ingo, Gina, Glenn, where can we connect with you and continue this conversation other than Las Vegas at Insight? Yeah, well, insight and ideally at the bar, uh, would be preferred, but, uh, LinkedIn, I'm there.
So LinkedIn is, is definitely a good way to get, get in touch with me. Um, I'm also presenting at a lot of conferences. I was just in Berlin last week presenting at the EI and Quantum, uh, summit there and exploring some topics like, uh, uh, post quantum graphy and how to get ready for the upcoming quantum thread, but that's a different conversation.
Um, so that's, uh, certainly another way. But yeah, LinkedIn is a, is a good way to get in touch. And I do, I try to post.
Um, but, uh, frankly, it's, uh, I'm not posting anywhere near as often as I should. You Can find me on LinkedIn. That's the best place.
Um, you can find me on LinkedIn. Uh, that's a great, I do respond to messages there. com.
And at the end of October, you can, uh, I'll be presenting at the, uh, Nvidia GTC DC conference for Public Sector. So catch me there. And, uh, NetApp, NetApp will be at gtc DC as well be able to see who they're, Yeah, our boots aren't that far away from each other.
com/insight. There's a lot more information there, uh, to come in person or to connect online. So thank you all for joining us, and thank you for listening to this episode of The Tech Field, a podcast.
If you enjoyed this discussion, please do give us a subscription on YouTube, um, or in your favorite podcast application so you don't miss an episode. And do consider giving us a rating or a review. This podcast is brought to you by NetApp, as well as Tech Field Day, home of IT experts from across the enterprise, uh, part of the Futurum Group for upcoming episodes and, uh, more upcoming events.
com/podcast, or you can view these videos on Techstrong tv. Thank you so much for listening, and we'll see you next week. AI agents and Mondays, never get me down.
You're watching Textron Gang. Hey, everyone. Happy Monday.
Wow. Another weekend, actually, last weekend in September. We're rolling into October this week.
Wow. Time. It just, it, it, we're in an accelerated, I feel like we're in warp speed or something.
In a wormhole. I don't know. Maybe it's the AI doing it.
Um, I'm Alan Shimel. Welcome to Text Strung Gang. We've got a lot of agentic AI to talk to you about today.
And a little piece, I don't know if it's world peace, but it's peace in our lifetime. Um, we've lot to go over. We've got, we've got the Colorado contingent in today.
Let me quickly introduce you to our three is the right word. Coloradoans or Coloradan, I don't know. But we've got Andy Mann, who sounds funny for a Colorado guy, Kimberly Bates and Mitch Ashley joining us.
And of course, everyone's favorite Yankee fan, Mike Ard. And I'm Alan Shimel. Welcome to Textron Gang Gang.
Welcome. We've got, uh, a lot to go over today, but I, I, we were talking off camera, it has already snowed in the mountains up there, so all you guys are smiling, getting all your, your ski gear ready and your warm weather stuff. And I've never seen people who love the snow as much as my friends in Colorado.
Yeah, we do. Yeah, we do. Swish Swish, yes, exactly.
And just A bit of a, a geography lesson. Andy is actually from the southern hemisphere of Boulder, so that's why he has that. Yeah, makes sense.
So That's the Boulder Republic, right? Republic of Boulder, yes. The Republic of Boulder.
Yeah. Maybe We have our own international, um, policies. Yeah.
Just So you know, I don't blame you. Um, but anyway, let's not go there. Let's jump into our agenda stuff.
Mike, why don't you take us out? What are we, what are we talking about today? Well, let's get started with HashiCorp.
'cause they've been core to DevOps for as long as anybody can remember. And they have the whole Terraform project that they helped start and now are trying to commercialize pretty aggressively. But it was interesting to watch them talk about this at a conference they held late last week.
And what they're really poking at is that they're gonna start a AI project, and this is gonna start with MCP servers, and it's gonna expose Terraform and the code to AI agents. And the idea here is that, um, eventually AI is gonna, I guess I don't want to say paper over, but integrate this so-called day one versus day two, IT operations mindset where things like Ansible will become more integrated with Terraform because they'll all be in using the same core baseline of AI agents. Which kind of changes the way you think about it.
It could be, you know, maybe we don't need as many specialists, but Kimberly, I know you've been looking at this space for a while. What's your thought about? Well, just how is it gonna evolve in the age of AI agents?
Well, if they can solve this problem day one, day zero, day one, and day two, that is gonna be absolutely fabulous. I think of this natural progression of what we're seeing. I mean, with the announcement of, you know, what MCP stood for in terms of coming out of an, um, coming out of Anthropic, what it's supposed to do in terms of some of the unifying capabilities that it has.
And then we're seeing, you know, an ongoing pattern of announcements of people adopting that kind of architecture within their systems in order to integrate the different pieces of it. And, um, we've needed this for a long time. I mean, if you think about what happens with acquiring of the technologies by these companies, and it takes so much work to have them work together.
I mean, when I read this, I, it is like, you know, I remember this time in our lab when a company that will go unnamed to three, you know, one in three letter companies, it was asking us to do a test with these three to show a solution with these, these products that they could use for data protection. And the screaming and yelling that was coming out of the lab because they had like four, you know, books open, if you will, virtual books or Uhuh on their desk trying to figure out how these things work together. And yet the marketing people had said, this works together, you know, but it really didn't.
And so I think what we're talking about, and maybe I'm way too far out on the ledge on, on what, you know, Hashi Corp is doing here, but it's, we're trying to make sure that, that all the pieces that come into the company, um, work together and having an AI agent or an agent AI go out there and look at all these pieces that's going to find some things that maybe us humans don't detect, as long as we have somebody that's overseeing the kind of work to be able to start to unify this, these pieces together. And I think that's got some, you know, real possibilities. Um, you know, you guys are better DevOps people than I am, but, you know, that's kind of my, my looking at, you know, what this does.
And it's got great opportunity and it's got some risk to it, but we'll see how it happens. Maybe AI could take those three runbook and figure it out for you, Kimberly, but yes, totally. No, it was Russ that was trying to do this, and it was loud.
It was ugly. No, Rus was struggling with it, man. It, yeah.
Oh, complex. Well, you, it, it's, it interesting because we'll see, I think we'll see a lot more of this of IBM, red Hat HashiCorp coming together more in their product strategy, um, but not just in a communications way of getting the products to work together. I mean, you think about it, what more of a natural fit than using not only Terraform and Ansible, but using AI to help automate those things together and start, start to cross those boundaries.
So who knew that, you know, AI would create the kumbaya moment to help Kumbaya moment to help us kinda get these things working together. But I think we'll see a lot more out of this. And, and, and if you think of where we're heading, yes, terraforms been the automation platform for infrastructures code.
Now, you can do even more of that with, you know, automation through AI and through get, and make it much more declarative along with other tools at the same time. So it doesn't have to be just Terraform that you're automating. Um, HashiCorp released what they call the, I think it was GA of their, uh, HashiCorp Stack, um, Terraform Stack, excuse me.
And that, and that, and that represents something that's not just within one environment, but across multiple environments, multiple clouds, et cetera. So it, uh, it's, it's a, I think a succession of things that we're gonna see from HashiCorp, but also most likely IBM and, and, uh, red Hat in the near future. Yeah, look, I think it's really interesting to see the integration happening.
It was always gonna happen this way. Uh, IBM is a master at acquisition and integration, right? Uh, and so getting, uh, HashiCorp alongside, uh, Ansible some time ago, this was very obviously going to happen with the very important for IBM to integrate these products, provide that sort of combined offer.
I do wonder a little bit if it's, uh, very customer driven, you know, Ansible look, great product, great solution has been around for a long time, but a little bit of a fading star. So it's interesting to see whether IBM can sort of relight that star by injecting this ai. But I, I'm, I'm totally with you on, on the logic of the AI injection here.
Uh, Mitch, the config is a knowable outcome, right? So when you're thinking about provisioning and configuration, um, I hate the word best practices, the known good practices in configuration and provisioning are no notes. So we've been talking, but we, yeah, we've talked about this quite a lot.
The idea that this is the sort of thing that AI works really well with. Mm-hmm. Um, and I'm super excited actually seeing them release, uh, stacks.
I saw them announce that last year, and I'm like, oh, it's pre-announcement. Is it gonna be what it needs to be? It really is.
And that, again, is very logical for the integration of all those piece parts and components and all on the sort of open source side of the house, right? Red Hat OpenShift, uh, uh, Ansible HashiCorp, this is a really good play for IBM, uh, bringing in a lot of opportunity for customers to provide the, you know, this end-to-end automation, the end-to-end platform engineering across, as you said, Mitch, multiple different estates. So look, this is gonna keep going.
We're gonna see more and more of this. This is great for IBM and great for its sales reps. Uh, we'll see if the customers actually pick it up though.
Um, very excited for Hashi Corp. A little bit less excited for the Ansible stuff personally, But it's also, I believe if I'm looking at this and understanding correctly, they're looking be, it is not just Terraform in Ansible. It's, it's looking well beyond that in terms to the other disciplines that are going on and the other environments.
They're, It's not just I, IBM m either they talk About Amazon, you know, Microsoft and, and, and kind of what I was looking at as well, is this, this bigger trend of what they want to, you know, what you're gonna be doing and what we should expect to see this replicate into some other companies doing similar kind of things to make life simpler, if that's possible. So let me play cynic here a little bit. I'm glad to see that there's anyone left at HashiCorp who worked on this.
'cause I, I thought, I thought the brain drain was pretty severe when, you know, from the acquisition and the, and the whole open source wars. Andy, to your point, HashiCorp, you know, part of the reason that they're part of the IBM is, you know, they, they, they, they had a little run in with the open source community when they changed their licensing. And, you know, had they not, I don't know if they'd be part of IBM today, to be fair.
You know, you, you mentioned IBM is the masters of, of, uh, integration of acquired companies and skill sets and products, you know, but their philosophy's always been that you gotta break a few eggs to make an omelet. Mm-hmm. And, and some things do get broken.
I, I think there's almost like a, a natural progression to assimilation by the Borg. Um, I, I think first you go through this brain drain phrase phase, you know, the people from the acquiring, acquiring companies have cashed out their stock options and they're moving on. Then there's the IBM, let's not just let 'em be for six months before we come in with our drones.
Then there's the assimilation phase where it seems like, oh my God, they're gonna break this thing. And then eventually it comes out the other end where, you know, they kept 60 to 70% of what the company used to have, and they've integrated into the IBM portfolio, and we'll keep it there until we send, sell it to some Indian company where software goes to die or something. Right.
That, that's the life cycle of an IBM acquisition. Um, maybe it'll be different. I, I, I do think there's an affinity between Hashi and Red Hat in general, not just the Ansible, right?
They do share open source roots, though they both changed their licensing to a certain degree. Uh, they both play in that DevOps space developer space. And it'll be interesting to see how they come together.
But today's red hat isn't the red hat that we all knew is the darling of the open source industry either. But there is a trend years Later. It's also what, it's 10 years later with the Red Hat.
Yeah. And I mean, they didn't, it didn't start changing until a few years ago. Really?
Yeah. No, it Red, red Hat retained. Its, its Raleigh attitude, right?
For, for five, six years, I think. Yeah. Mike, I'm sorry, go ahead.
I think it's pretty obvious. And a lot of these companies just simply don't care all that much about the great unwashed open source masses. They're after corporate enterprise customers and the people who pay for stuff and all the rest of that community stuff is, you know, we'll saute it as we drive by.
You know what? But that's the same people who say DevOps isn't about culture. DevOps isn't about people that, it's all about tools.
And there are people who do say that and do, and companies that act that way, but sooner or later they find out that it is about the culture and it is about the people. Well, it's very much a financial interest meets business objectives. So let's change our model, right?
So we can demonstrate more direct value from this open source that we've created. And that's what happened in Red Hat happened with HashiCorp. And, and we will continue to see that over time.
I, I think one of the things that we, we haven't talked about yet is, what's interesting about this is ai, particularly generative AI, has an affinity for structure. And that's why it's so good at code. It's why it's so good at ingesting JSON structures and you put prompts and things like that, and you, it's less likely I don't have data to prove this, but it's less likely to hallucinate when it's doing those things because it's operating in a much more structured semantic world.
When you think about infrastructure, whether it's share form, whether it's automation with Ansible, or pick your favorite tool, those environments, I think we're gonna see a real revolution in how AI will help us not only manage, but construct infrastructure across product, across environments. As that gets better and better, um, maybe we'll have some more flexibility. Maybe we'll have a little bit less technical debt.
I'll be optimistic. I'll play your, the optimist to your cynic. Um, maybe we'll have a little bit less technical debt or at least technical debt that can be solved, uh, in a reasonable timeframe.
But I'm, I'm curious to see where this will go, because I think there's a lot more possibility here because we're talking about code and not writing text for your document. IT management is code it, manage it. M Mm-hmm.
Okay. I think it's, IT management is code for everybody. I think the part of this that I'm excited about is that you, you may not necessarily always have to be a DevOps specialist to automate stuff using code.
Yeah. I, I think that's gonna be pretty cool. Love It.
Well, if it works, How's that? There's always that Andy will remind us. Oh, yeah.
And who's gonna operate all this stuff Now? It's always the question, isn't it? Right?
And look will be, I I I'm actually energized by the idea that we're, we're seeing some really interesting, uh, innovations from what are fundamentally ops companies though, right? Um, Ansible, HashiCorp, uh, even Red Hat, uh, we've seen so much great AI innovation in the dev sector. We've talked about Claude and code and five coding and all this sort of stuff.
But, you know, a lot of, a lot, not all, a lot of the IT ops environment is knowable, you know, good known practices around integrations, around, uh, uh, provision, around configuration, around security scanning, you know, these sorts of things. There's a lot of goodness there. And if we can take that, uh, mundane routine work of figuring out configs out of human hands, then we free up IT ops to do more interesting things around architectures and development and stuff, um, and DevOps.
So yeah, look, I, I, I will always stand up for my ops peeps. Uh, they're the ones who, who, who, who bear the brunt of so much of this, but in this case, they're actually the beneficiaries. And that makes me happy.
Alright, if Andy's happy, we're happy. Let's take a break here on the gang. We'll come back to our B block, which is also around agentic ai, but a little different, uh, this is for, uh, AI agent management, which is the race has been on a long time, but you're watching text on game.
You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders. Lives depend on your decisions, your home life included, that work your protected physically and digitally.
Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity.
Your digital front door is wide open. And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall.
It's convincing you that your personal life isn't at risk. Black clerk, digital executive protection, defending the new attack surface your personal life. Hey folks, we're banking, as Alan alluded to.
Yeah, there is a fight now on as to who's gonna be the dominant soul or platform for managing all these AI agents. Salesforce just came out with the version of MuleSoft that orchestrates and manages all these AI agents. But then there's a little company called Glean that took it up a little bit further and said, here's this entire AI work platform, and we'll manage all your AI agents for that.
And by the way, and users won't even have to know anything about prompts or all this other stuff because the graphs are gonna be super smart. But, you know, as you kinda look at all this stuff, let's start with Andy, what's your take on what's going on here? Because to Alan's point, these are just one of maybe two to three dozen entrants that are gonna be in this space.
So is this the new, the new big fight in it? This is innovation disruption. This I'm, I, I live for this.
This is so awesome to watch. You know, uh, Salesforce has got good property there for with MuleSoft, you know, great. We're talking about integrating and managing AI and AI agents across the estate.
Uh, as we get more and more AI agents, of course they're gonna talk to each other. This is the API economy. We're now talking about the AI agent economy.
Uh, and it's, it's essentially a similar kind of thing. So this is why MuleSoft is in a really good position to stake a claim on winning this base. Uh, they've got great integrations across a broad s swathe of it, good integration.
This is a really strong opportunity because ultimately we do need to manage these IT agents. They're just like people, right? Where we've, I think we've talked about this, the idea that I get my agent to do some work, and then it talks to another agent that do some work.
These are sort of like managing people. You need to understand what the connections are between them, whether they're performing well, whether they're making mistakes. You need to be able to get them together to work well together in groups and teams.
And so bringing in together multiple agents, and every time we do this sort of thing, we face complexity. So two agents talking to each other, pretty straightforward, just like two APIs. But we get a bunch of different APIs, or in this case AI agents talking together.
And now we've got death star architectures again. So we definitely need to have this management layer, and Salesforce is gonna try and stomp the terror, but then this is a disruptive moment. There's no reason why Salesforce and MuleSoft should be the dominant approach when you've got smaller companies like Glean using newer and in more interesting, uh, approaches, you know, looking at MCP servers, defining, uh, your environments, having the agent reiterate itself so that it creates better prompts so that it does its job.
Better agents working on continuous improvement themselves. So these already interesting opportunities for disruptive tech. Yeah, look, Salesforce has got a huge customer base.
It's got a dominant place in the market. MuleSoft is good technology, which seems to apply really well to this space. But this is a new space.
And so every time we have a new space, we have this disruptive innovation. And I'm excited to see it. Well, in the second Star Wars movie, during the Agentic Wars, there was a phase where the AI control planes were battling it out.
And that's actually what we're living out today, is, is we're entering this phase of who runs the control plane for agents who runs the observability plane for agents. And I think what we're gonna, we'll see a lot of introduction of technologies to do that. The question is, will enterprises adopt one a couple, will they go with a, a known player that they've been working with, you know, ServiceNow introduced their own AI control plane.
Maybe it's a Splunk, who knows where this is gonna go? But to your point, Andy, this is a, this is a period of peak innovation where it's, it's, we're seeing a lot of things come out that yes, there's a need for it. And it's not MCP standard that everybody says yes, that's the answer.
It's everybody has an answer. Which one's gonna win the end going to, to be the ones that survive? So Mitch, you are wrong about the second Star Wars movie, it was actually Empire Strikes Back, and that's what this is.
I meant in chronological, You meant in chronological order, but in terms of release, it was the Empire Strikes back and they're knocking out the Rebel Scum. Yes, sensei. I, I Agree, like glean and stuff like that.
But seriously, this is, and, but that's a very good analogy of what's going on in this market right now. Let me explain to you why I say that. I'm watching to see, is AI a big boys game, right?
When you go to a VC and you pitch, and we've all, I think most of us here have pitched to VCs, right? What do the VCs look for? Is it a big enough market?
That's the first thing they want to know, right? Is it a big enough market where we can make a lot of money? Well, agentic AI managing agentic AI is a big market.
Secondly, what's the barrier to entry? Is there some proprietary IP patents that you have? Or, you know, can anybody come along and do this?
Is somebody with more resources just gonna come along and do it? Are you gonna be the missionary who hacks the path in the jungle and someone else just walks through easily to this point? AI has been a big boy game, certainly in the us, right?
That was, I think, part of the big thing with deep seek. The Chinese did it on a shoe string. You didn't have to have billions and billions of dollars, just millions.
I think when it comes to managing agents, and we all realize what a golden opportunity, what a pot of gold this is at the end of the rainbow. 'cause we're all gonna have agents upon agents, oodles and oodles of agents, and they've gotta be managed, right? Someone's gotta do this.
Now, most enterprises, I don't think are going to, and I, and I don't mean this in a bad way, but they're not gonna trust some company named Glean to manage all their agents. They're gonna go to the big boys that they, to the empire, right? To the Darth Vader and, and Admiral Thrones of the world.
And those are Salesforce and ServiceNow and IBM and names that, you know, like that. Now, historically, what happens in the tech space is that the innovation doesn't reside with those people. The innovation does reside with the gleans of the world.
But what happens is when the gleans get too good, one of those empires buys them up, they take over the planet, right? And, and that, you know, big fish, eat the medium fish, the medium fee of fish, eat the small fish. That's the way of it and the way of tech, and I think that's what we're gonna see here.
I, you know, you might, you might get one company that's kind of a new name that'll break into this as an AI manage, as an agent management platform. The rest of them will get bit bought off by the big guys because the barrier to entry on this is going to be very, very high. Is very, very high high.
So yeah, to your point, to your point about that, I think the issue is who has access to the data and the legacy apps. 'cause that's what the AI agents need. And if you're a startup, you don't have that.
You gotta go build all those different connectors and go try to install that. And I think whether it's, uh, MuleSoft or a Boomie or any of those integration platforms, they have an advantage there. But that's just my take.
Is there a barrier to entry with the quality of the work that you're doing with semantics in terms of integrating those pieces? Because when you look in technologically, you know, what you're saying is that I don't want, a company's not gonna adopt it unless it's a big company because it's such a big control plane, right? Mm-hmm.
So that's, that's one barrier. But on the other side, the quality of the data piece of it, which is the semantic analysis of looking at all these pieces, that is really tough technology. Yeah.
Um, and so a company like Lean or, or others that are coming up that have unique innovation in terms of how they do that, that becomes, I think is the core of the, the barrier. And, and that's why someone, someone will pay a couple billion dollars for them, but it's chump change. It's not chump change to glean or their employees.
Right. Or the VCs who are looking at a 10 X are on it. But, but to an open AI or A IBM or, or a Salesforce, it's chump change.
I wouldn't mind a bit of chump change Me either or a little less. But that's, but it, so again, I, I've been in tech 30 years. Yeah.
For the most, 90% of us live off the, the breadcrumbs that fall to the edge of the table from these companies. That's the way it's always been. You know, Alan, I think your, your analysis of how this will unfold is I would've given the same story.
Right? So the innovation happens here. Somebody will pick somebody up, and the question is, does does one of these kind of catch fire enough to capture intention and that gets acquired?
Or does everybody say, I need one of these, and they gobble up early before it's really, Well, they, you know what Brad Feld, he says, right, you gotta be in the top three, because those are the ones that'll get gobbled up early and get the lion's share of the, of the pie. Now. But at every, here's another thing I've learned in 30 plus years of doing this.
At every technological rung like this, there's always one, maybe two companies that achieve escape velocity. Mm-hmm. And they become the next big guys in the next round.
So in the whole generative AI thing, right? Think about all the companies that were trying to do models and doing everything open. AI clearly is a, a, you know, going on to the next round.
Congratulations. The Hunger Games of Tech. So, open ai, you know, may this, what, what's the, what's the term from Hunger Games?
May something smile apart, maybe the odds be in your favor, right? Open AI made it through Anthropic. Yeah.
I wouldn't be surprised if one day they're just part of Amazon, you know, call it as they see it. Mm-hmm. Um, but this is, this is the way of the world.
This is, you know, this is The way, so competition then Go ahead. The competition then becomes between, which as you started out with Salesforce, ServiceNow, potentially Amazon, They're big guys. Those are the big, so, so that, but that still is a big decision for Oh, yeah.
A it organization to decide which one of those big companies I am going to stand. But isn't that the turf four that we, they fight every day is in IBM always fighting Microsoft? Is it Microsoft always fighting Google?
Is it AWS? Right. And then, and then sitting on top of them, you have the Accentures and the, and you know, the big integrators who they line up with, though, we all know, they'll line up with whatever makes sense and where, where they're gonna make the most money, um, you know, meet the old boss, same as the new boss or the new boss.
Same as the old boss. There's another new boss though, and you mentioned that. And that is, does open AI by one of these companies to help propel them?
Absolutely. Accelerate them to that escape velocity become one of the big behemoths to be able to do this. I, I think they're well on their way.
You know, I, I saw a video the other day of Sam Altman, Sam Altman in Abilene, Texas. And my, my son used to be a TV sportscaster in Abilene, Texas. I've been to Abilene, Texas, you know, and he's sitting back there in, they're building this Monmouth AI factory.
And it's, and it's Sam and, and uh, uh, SoftBank and Oracle, I think are the three partners in that particular one. And they're building a power center. And they're, they're talking about using a gas powered power center, you know, to keep all those cowboys happy.
But if you've ever been to Abilene, you know what you see for miles and miles? Windmills. Windmills, because it's really windy there.
Mm-hmm. And, and that's what's gonna really power those AI factories out there. But clearly Sam, Sam is gonna be, uh, Steve Jobs, bill Gates, you know, urg surg in Larry or whatever you want to, you know, whoever it is, they are moving on to the next round.
You see all those windmills. 'cause there's nothing, it's all flat. There's nothing to stop the wind.
So, well, No, there's some hills out near Abilene. I think there hard, but it's pretty much, I don't wanna miss, sorry, Andy. I, so You know what?
That's the Colorado in you guys. Yeah. You guys in your hill Size.
Some of us say size doesn't matter. I, yeah. No, no, no.
So I'll let Andy talk for, um, but I gotta say this. I don't wanna overlook what, what you said, Kimberly. And that is, I think another big play here is the, the Symantec graph, the, the, um, database side of this.
Yeah. Um, so we've talked about a Neo four J or maybe a Clean, or some one of these other companies to really accelerate adding that con contextual information that you need. Mm-hmm.
It's gonna be a super play in this. So I'm gonna play Alan for a a minute. Andy, what do you think about this?
What would you like to say? Oh, yeah. Look, I, I, I just think that I, I'm not sure that I necessarily agree with Alan in this case because, uh, this is such a radical revolution.
This is virtualization or the internet or cloud, right? And in some of those cases, the first mover had the big advantage and some didn't. In this case, I actually think that the first mover has advantage because, um, someone like a Salesforce is able to lean into all its existing work on integrations.
And so, look, MC P's gonna make a huge difference in terms of agents working with each other. So maybe G Glen gets a handle on it, but they're gonna go down one direction. A smaller company, they can only focus on one direction.
They can't spread their peanut butter too thinly. Salesforce is gonna spread their peanut butter all over the place, and they're gonna go with what works and what wins. So look, it may, I, I, I thought it was interesting, you maybe Boomie, it could be a couple of other integration plays, like a Step Logic or something like that, right?
The integration players have that leg up. And so I think in this case, first mover Advantage makes a difference. Um, and not just because of that large enterprise play on the trust factor and the relationship.
You're right, Alan, you know, a a a huge enterprise is not gonna go with Glean for its entire is state, but you know what one or two teams are. And if that happens to be on the right path, then that could pop. But I, so you're telling me we, it's a new paradigm.
Things are different this time. You know what, I'm gonna tell you the checks in the mail. So I, so I wanna know on this Star Wars, I wanna know on this Star War, on the, on this analogy you guys are using here around the empire straight back.
So exactly who is Emperor Palin in this, uh, little Em in this one? I, I would think it's Mark Benioff, Not Sam Al. Sam Altman's leaving the Rebel Alliance.
Is that what it is? So why Sam, Sam Salesforce is, is the big dude. Yeah.
I mean, because there's so many more application environments. I mean, Salesforce is only one major, granted, it's a major piece of the application environment for a company, but It's, has I I agree. And they were first Into this.
You're not rrp lemme tell you, they're not ERP. No, they're not hr. Mm-hmm.
Nope, they're not. But Salesforce is a big dude in it. It's a big Dude, I Think.
I think. And so I think about, okay, so I am, as I, I'm responsible and maybe I'm looking at, you know, the, the 10,000 employee kind of place, right? Where I've got a unique group here, I'm gonna be doing my development.
I've totally, I don't talk to the other guys. I have nothing to do with, well, I had, occasionally I'll have to work with them, but, so I'm gonna implement mine. And then the other guys, you know, and then somewhere along the line, it starts bubbling up that they've, they've advanced on this kind of technology.
One person talks to another person. I, I'm not, I can hear where you're saying, you know, v VMware kind of virtualization of this, but we're talking application space. And they tend to be unique and they tend to be somewhat separate Here.
Here's, I think a point to make about that camera Lee, is we're talking about the control plane, which is an operational security right? Aspect of this. Does that, you know, you may come with your application environment Yeah.
Like a Salesforce or ServiceNow. Eventually that rolls down into an ops role. The Andy world say, wait a minute, that's all you got.
Oh, it's self fun and games. But it's, it's real here. Let's talk about what tool we're gonna use.
I wonder if we're gonna enter that kind of a phase where we're not. But you could a place for an SAP or an Oracle. You know, I think, I think Larry Ellison and I think Larry Ellison and Oracle is gonna be a bigger ER than Mark Benioff ever dreamt.
The, I mean, Mitchell though, Sam Altman clearly has all the potential to be a young, uh, Anakin Skywalker. Yeah. Yeah.
And, and wind up a sth. Lord, I am your father. All right.
Hey, let's take a break here on the gang. We're gonna come back for our C block. We're gonna get off the agent AI for, I hope this one, and talk about, uh, politics makes Strange Red Fellows, and there's hope for world peace.
I don't know. You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. All right, we're back with the C block.
And as Alan suggested, we are not gonna talk about AI agents. Everybody got that? No AI agents for this section.
If anyone mentions AI agents shots. Go ahead, Mike. So, um, it turns out that Docker and the folks over at the Cloud Native Computing Foundation have had a little, I guess the signing of a Peace Accord is about all I can kind of describe it.
And they're gonna work together and kind of try to make things, uh, better for most end users. I feel like this has been overdue maybe a long time in coming. I seem to remember back in the day, Docker Con was the biggest show in town, and then CubeCon came along, and it looked like Docker never got over the fact that they got usurped by CubeCon, and there was just bad blood in the system for a long time.
But, Mitch, is there more to it than this? Is it just politics? Or is there some technical aspect of this thing that leaps outta you?
Well, I'm not gonna say the, you know, a word that we banned from the segment, but, um, I think Linux Foundation, CNCF, is the senate of this analogy where things kind of come together and happen together. And that, that's essentially what Docker has done, is, is align with CNCF to say, what can we do to solve some of these problems with, at the very introduction of creating open source projects, bringing libraries, um, whether it's an MPM kind of issues that we've seen happen, and GitHub aligning to do those to help solve some of those problems. We're seeing the technology providers aligning with open source organizations to say, how do we move further into the earlier into the cycle?
So you aren't pulling stuff out of repost that's already has issues in it. You aren't using, uh, container images that have issues inside of them. Uh, we have, we have now methods to be able to, uh, use these policies, use these principles, let's align that into, at the project level scan code, do all these things that we know are good, useful things.
So I think we're gonna see a lot more of these alignments with the senates of the world, with the CNCS, with the Linux Foundations to say, here, we're gonna help have our technology help what you do at the open source creation phase. And hope that that kinda helps them accelerate their, uh, access into other development organizations, enterprises, doing software development using those, those same technologies. Because we used it here.
Let's use it here. So I think somewhere in the many alternate universes of the multiverse, there is a universe where Docker Swarm is the standard orchestrator Oh. For all cloud native container based applications.
And Docker is, has a market cap larger than Salesforce, and they build a big building in the Embarcadero, uh, in, in San Francisco. And, and the CNCF is just another one of the 40 some odd organizations that the Lennox Foundation manages. Oh, that, that's dark.
That's really dark there. Well, no, there's, you know, and as Carl Sagan would say, in the universe of billions and billions of stars, right? Anything could happen.
But the fact of the matter is in the universe that we occupy in Docker, Docker had this in the palm of their hand. And Mike, to your point, I remember being a docker con in, in, uh, in Austin, Texas, and we were thinking about launching a site around containers, and I wanted the site to have the word docker in the domain name, but Docker, of course, owned the ip. I couldn't.
So we decided to make a, a site around with the word container in there. And I went down to Austin, Texas, and I came back. I said, you know, there's something, this other thing called Cuba, something that the Google people had that is now open source.
And everyone's talking about that, but I don't think it'll catch on. It's way too hard. And of course, I'm still here.
And in that alternate universe I'd be sitting with, uh, who, who was the founder at Docker? Uh, he was their CTOI don't remember. I don't remember his name off the top of my head right now.
He has another company. Anyway, Yeah. I, I, look, I'm, I'm gonna take a marginally, uh, uh, negative view on this one.
Look, uh, I feel like I'm in Cino Man or something at this point. I'm waking up and I'm like, what century is this? Docker?
We're talking about Docker. Look, don't get me wrong, we're still using Docker in our state. Uh, it's good.
But they blew the opportunity of a lifetime. You are, look, you're absolute right? Yes.
In in that alternative universe of yours. Uh, and by the way, I'd love to live there. That sounds like a fantastic place, uh, in that alternative universe.
Uh, yes, Docker could have been everything to all people. It was such a good technology, and they blew it in a way that someone like an AWS or a VMware or Kubernetes did not. And so we're, I feel like this is a lagging indicator of Docker's trajectory, the idea that we're now getting into bed with, uh, what is ostensibly competitor.
So we, this is not innovation. This is chasing a tail. Mm-hmm.
So, look, I, I think it's possibly good. I don't think it solves a lot of problems for a lot of people, but it really makes me wonder, it makes me sad for what Docker could have been. Yeah.
No, it doesn't. I remember going to the, I, I remember going to the Docker offices right? By the Embarcadero for Pratt's briefings, Solomon hikes, by the way.
And Mitch, I didn't, I don't have a, a computer here to look stuff up. It just, I, I, I, it hit me. I for you, Solomon was the founder of daca.
I remember going there to interview him. And, you know, they were a little arrogant, to tell you the truth. Andy, if you remember right.
They, they really, they had the tiger by the tail, and they thought they knew it. But, but we're not talking about that Docker, that docker got broken up. They sold half their crap to Mirantis.
They open source the container, which is, I think part, you know, is just open source. I think CNCF might even be managing the container, uh, images. What Docker is today is a repo.
Mm-hmm. It's a repo of what's supposed to be, what is supposed to be secure container images. Right.
You download, no, Mike's given me this. I don't know, Mike, what do, what do you got then? I think, I think there's, there's a small sliver of those images that are certified and validated to be Secure and the rest Oh, you're, you're not taking exception with security.
I, okay. I I, yeah. I'll give it to you.
The rest of them are just basically, you know, Garbage, not garbage. They're just what people put up there, like in every repo, They're, they're, they're a take your chances kind of Thing. Yeah.
But every repo is like that. They, you know, part of the issue is we, we live in the wild, wild west of repos, But isn't, I think that what They're trying to change with This alignment, well, that, and that's what this is about. Yeah.
Yeah. I'm sorry, Kimberly. Well, this seems to, what it's doing is giving breathing air into Docker and those people invested in Docker, which is pretty, seems to be pretty extensive.
And it gives life to those environments to continue to extend. Or am I missing something here? No, no.
It, I, I think it does, but I, I think really what this comes down to is supply chain security. I think, I think the biggest, and I know, I, I wasn't on earlier this week, you guys did that open source, uh, thing. I think it was yesterday, Mike, or last week, right?
Last Thursday or Friday last week. Um, I think the biggest issue facing open source development security DevSecOps, is supply chain security. SBOs don't solve the whole problem.
I think the, the, the biggest single issue in supply chain security is that 80% of the software, 85% of the code in our apps is be, are being downloaded from repos. Whether it's a docker repo of a container image. So I can quickly build a, a cloud native, uh, app or, or, or an artifact from Jfr Artifactory or something from Maven Central or JavaScript or whatever, bad code malware.
We, we saw it with the, uh, the shy haud, the worm last week or the week before. That's how bad stuff's getting injected into our software from software. I'll Give you an alternate reality though.
Think about this for A minute. I you give this one, but go ahead. You give us, it's the alternate convinced you can have your own reality give, I I, I'll give you a whole other possibility.
So GitHub is getting sucked up into Microsoft. So now the open source community rallies around the repository from Docker instead as an alternative. And they build out their own little ecosystem.
And by the way, they make it a little more secure than what GitHub has been historically. So maybe there is another future for Docker. Yeah.
And Docker as the repo for Cloud Native is perfect. 'cause it's containers where the other stuff is snippets, artifacts, you know, what have you. Yeah.
But critical mass in GitHub is gonna be extremely hard to overcome, I think. Oh, I'm not saying GitHub's going away, But to overtake it, I think is pretty big challenge. But maybe, you know, maybe Thanos could do it, but I don't know if anybody else could.
There you go. I'm Iron Man. Half the projects are good.
Um, but we'll, we'll see. But you know what, good for Docker, because A, as I said, the, you know, Microsoft isn't the Microsoft of the nineties when you talk to them, it's not Steve Balmer's, Microsoft and Docker isn't Solomon Hike's Docker either. Not at all.
Yeah. And, um, I, I, you know, if if it, if it's good for the community in, in terms of a more secure supply chain. Yeah.
But I see, here's here a I, here's where I don't know that it really does serve the community or serve customers particularly well. It's a step in the right direction in some cases. But look, if my team just downloaded anything from Docker hub and put it in prod, I'd have their guts for guards, right?
And so it's like the V store, remember V apps, we were gonna solve the software supply chain issue with v apps a hundred years ago. And again, it fell into the same problem. If we don't have maintainers, if we don't have, uh, you know, people who are, uh, tasked with authority to maintain these images and certify them in some way, then again, it is the Wild West.
So I just like VAPs, there was no control over that. Anyone could load a V app. There's a big difference between that and say the iStore or whatever it is.
Um, or, or the Android marketplace where these things are tested and verified, and there's a governing body which says, yes, this is okay, this is safe. Even then stuff gets through, right? Um, but when we've got the Wild West of, yeah, a GitHub repository, a docker harbor, whatever it is, if there's not some mechanism, some authoritative mechanism for developers to know, this has been tested.
I don't need to test that. And oh my God, I just hate the, the idea that my developers would say that phrase ever. Um, but that's, that's where it's gonna be beneficial.
And I don't see them doing that. I just see them providing more, I won't use the word slop 'cause that provide attaches to a different conversation we're not allowed to have. Uh, but it, it, I don't see that this really does serve the community that well, because you're still gonna have to go through testing and compliance and governance checks and all the stuff on someone else's repo that is unintelligible for you in a lot of ways.
So, I don't know. It's, yeah. For, if it's a good repo that you can use that has the right things in it, that you are prepared to check and validate, great.
But I don't know that this does that. I think, I think though, the point, the thing we have to remember is this happens at one point, and that's the developers. The developers are the ones who submit these things, right?
The code to the repo images, to Docker, et cetera. And maybe we're seeing a little bit of a shift, um, GitHub announced their, uh, trusted publishing. They're implementing some of those standards as part of putting things into GitHub, more of an aggressive enforce enforcement.
Maybe it's a lightly aggressive enforcement where we see the, the, the dockers and the, and the open source projects and GitHub's, if they start to enforcing some of these things, I think we're, we're likely to see better security implemented because of it. It's still gonna take developer's effort to be able to do that. 'cause at some point, if it's a bigger hassle than it is worth their time, they'll find another way around it.
And that's when your alternative universe happens. You know? But, but Mitch, we, we are seeing it too.
I mean, Seuss Seuss announced their own container image, you know, certified containers Yeah. Of secure, like, the most popular stuff you're going to use. Mm-hmm.
And I've seen others do it. I don't remember who, if it was Muntu or, or one of the Chain, chain guard is probably the biggest player in That space. Yeah, right.
Where they're giving you, they are, you know, use our repo, basically. 'cause we're, we're saying it is. Um, but look, let, let's see how this plays out.
We'll, we'll be at Cube Con in, uh, I guess it's November, um, in Atlanta. And, uh, it'll be interesting to see how the community is, is, uh, adopting to this. But guys, we're about outta time here.
It was, I just wanna, I just wanna say there's gonna be baseball in October in New York, so we're happy. Ooh, That's right, Mike. And they, you know, so are they in first place now?
Or they're tied. And if it's a tide, the blue Jays are the Well, this is Monday. And through the magic of the internet, we won't really know because it's Friday.
All right. We'll know, we'll know soon enough. Anyway, my Coloradan, thank you for, uh, coming on here.
Let's pray for snow. Yes, Mike, I pray for Yankee wins. I, there's a lot of things I pray for World Peace sanity in this world and everything else.
We got World peace. CNFC. CNCF and Docker.
Yeah. D-C-N-C-F. And Docker can make peace.
There's peace. There's hope. There's hope.
Um, we'll be back tomorrow though, God willing, Tuesday for, for more Textron Gang. Until then, as a reminder, as always, we have Textron TV immediately following this. So stay tuned for that.
If you're not watching this as part of the Daily Stream, whether you're watching on Textron TV or our Textron tv, uh, YouTube channel, or our text Drunk tv, OTT channel, apple, uh, apple, Google, Amazon Fire Stick, Roku, or Apple tv. Check it out there. But for now, there's Alan Hummel.
We're out. Hey, everyone. Welcome back here to Techstrong tv.
I wanna introduce you to a first time guest. I love doing first time guest on here. His name is Dominic Richter.
And Dominic is the, uh, CPO Chief Product Officer and a co-founder at a company called Mondu. Dominic, welcome to Text Drug tv. It's great to have you on here.
It's nice to be here. Good. So, co-founder, chief Product Officer.
You didn't wake up in a cold sweat one night and say, I know just what I want to do. I'm gonna go found a company and, and, uh, you know, put myself through this for a couple of years and hope, you know, we hope against hope. I'm one of the, we're one of the ones that make it.
What, what, how did you wind up co-founding Mondu? What have, what's your journey been like? You know, I've been in security pretty much all my life, uh, studying, you know, from hacking school networks to university, and then finding my job in security.
But the thing with security has been that I've been sitting on the attacking side for a very long time. And then one day decided, Hey, I gotta switch sites. I gotta see why is this so hard to secure?
And in trying to defend it, um, I created a first startup in 2015 that did policy as code, actually mm-hmm. On the first frameworks to market, um, and brought security and the defensive side, IE the platform teams closer together. And ultimately all of that led me to mondu today.
Excellent. Excellent. So your co-founder, who else founded the company with you?
So, we have a few others. Um, we've got Christopher Hartman. Um, I, him and I have been working together since the Telco days.
Mm-hmm. Um, we've got Sue Choi, um, who has been in the, in the scene, especially with OpenStack and Chef software previously. And then we have Patrick Minch, um, another one of my, uh, co security, uh, hackers, um, who has been a co-founder of this as well.
Very cool. Um, so let's talk Mondu. What, what, what, you know, what's it about?
What does it do? What's the mission? So our mission is to reduce the attack surface of the world, essentially.
Um, we decided that what we really want to do is not just add more findings to your list, but we actually want to help you to get better and help the world in having fewer security issues. We know it's not an easy, uh, thing to do out there, but, um, we've wanted to make it easier for people to remediate and fix the issues that will ultimately get them hacked. Um, we've just recently looked at the list of companies again, that get hacked like in an average month.
And it is my personal data, by the way. It is your personal data. My data got stolen last year, um, pretty badly.
So yeah, probably several times, several times, A few times. I gotta tell you, I started collecting, you know, you get those letters in the mail that says you might, you might, like, they don't know you really were, you might have been the subject or involved in a data breach here where you're personally identifiable information, including your social security number, date of birth and everything. And so we're giving you a year's free.
Uh, at this point, I have a lifetime of free credit monitoring across all of the different ones from all of the times my data's been breached at this Point. And that doesn't even have, you know, help anymore. Like, I came back From it's true twist.
I, I use the letters. I just, I just like to see the stack grow because like you, I've been in security 25, 30 years. Right.
And, you know, I remember when they first came out when PCI first came out, and the whole idea of providing credit monitoring first came out, but in the last year or two, it's out of control. I get, I get almost like once a week, My, my personal data has been stolen to the degree where people took over my, uh, the credit agencies, basically. They're there to monitor my stuff.
Yeah. So they had fake accounts on them because that's how far they got, especially last year. I, I've been through that too.
And so yeah. Addresses, tax returns sent and, and we're security people. Could you imagine?
Yeah. Civilians, right? How, how are they dealing?
It's nuts, man. If this happened to my grandma, I don't think what she would've done. No, no.
I was able to react very quickly, but, um, I don't think they would've, so, no. And that's what we're trying to change. Like, I'd rather, uh, people have fewer security issues, um, on their table that they can effectively solve.
Especially now in the age of ai, you've got these attacks rolling out more autonomously, more automatically than ever before. Like, we can't afford just sitting back and, and watching critical results fly through anymore. The attackers are just way faster.
So, yeah. Agreed. Agreed.
So how, how are you doing it? Let, let's hear. All right.
So what we are doing is we are using a combination of policy as code and, um, vulnerability assessment in our environments to figure out what is the most pressing thing that is actually going to hurt you. Not just the surface level symptoms, but what is wrong at the core. Um, back when I used to attack systems, I could usually see these very easy things that were being done wrong.
Like, it's not even the hard stuff that people get wrong. It is usually the easy stuff that gets you broken into and taken advantage of the most. And so for the vulnerability analysis as well as for the policy analysis, we are then usually looking at the entire context.
So what is the system? Is this really something that exposes you? How do you fix it?
Um, what is the best way to approach it? And that ultimately needs to be accessible to the people on the other side. That may be a entire team that you have.
Those may be platform engineers. They may use automation or they may not. We have a lot of customers who have like a bunch of Windows admins trying to fix their Linux machines.
And so whenever that happens, you know, my fixes still need to be very actionable, um, for them so that they can go and fix the issues. I love it. Um, I, I want to talk OPA and stuff, but before we do, I want to just tie some bows around Mondu.
Um, how does Mondo use mondu use OPA? How, what's the connection there? So we, Or or not, is it a replacement?
You know, I, I don't mean to, I you go. Yeah. So we've been looking at policy as code for a long time.
Uh, like I mentioned, we did a previous startup where we started with policy as code. Um, we actually came from the infrastructure automation side. So we built it around, uh, things like shaft software, which were used to automate operating systems.
And now we went into the cloud direction, but we realized with policy as code that we needed something that was accessible to a security professional, something that they could use and understand. And it needed to unify these different types of technologies that are happening and expose the context of them. OPA came up at tail end, um, after we had left there, um, I was with Google during that time.
Um, OPA had risen to prominence, and it had risen to prominence in the infrastructure, uh, security space to help write policies there. Um, we had taken a look at it in the early days, right when we started mondu, but, um, similar to other frameworks we had then ultimately decided against it. We knew it was not going to be the right solution for us.
Got it. And, and so you, you guys basically developed sort of an alternative? We did.
So we came up with something that we dubbed MQL. Um, it is a query language that is, um, very much leaning towards GraphQL plus, uh, scripting for assertion. And the reason why we did this is because we realized, you know, a lot of these security problems that we're trying to analyze, they are actually dealing with relationships and context.
So, um, we came up with a framework that a needed to be really, really good at expressing those relationship and that context. So let's say for example, you've got an open process listening on one of your systems that can be attacked. Great.
That process is usually reachable, um, because of some kind of cloud configuration, because of some kind of network configuration. It may be rolled out through a package to all of your systems. So you need to understand where it's coming from, uh, what are the permissions it is running with, and so on and so on.
These are all relationships. And so we decided that we needed to have a stack that was going to be good at expressing relationships. So, for example, is this a process that is running as root?
Is this a process that is exposed through my gateways? Can it be read through that? And so on.
All of this became one of the requirements why we initially looked at GraphQL, because as a stack, it is the graph alternative to talking to an API, essentially, the only thing that it didn't have was a strong way to express assertions or to mangle data and transform it. And so we added those layers on top. We basically made it easy to, um, transform that data and to say, you know, not just to say, give me all of the users that this process has access to, but to say none of the users should include your administrators, or none of the users should include to root.
And so that ultimately became the framework that we used for policy as code. Um, and we tested it with security professionals because our aspiration there was that it can be easily understood and can actually be used by the people that understand security the best and not just by developers. Got it.
I, I want to pivot to this, uh, OP and TY angle, but before we do, for people who want to go look up mondu now and grab information, what's the website? com. Um, it has all the information about the company, but it is also connected to the open source projects that we have pec.
Um, if you want take a look at the open source there as well. CPEC is a great project that actually, um, exposes all these things that I mentioned about policy as code resources and how to do security this way. Um, you'll find it through the website or through GitHub or Google Search.
And mind you, by the way, is M-O-N-D-O-O. People probably see it in the bottom third with your name, but I'm just throwing it out there. All right, Dominic, let me, let me set the stage for this next part.
So look, I'm familiar with OPA, I'm familiar with the founders of, of the Sty a company and the OPA, and they founded the OPA project. My friend Bill Mon used to be this, the, uh, CEO at Styre, though he left a while ago. And then, you know, apple did a very Apple-like thing.
They were big users. They still are big users of opa, of OPA, but instead of buying styre, they did it. They bought the people at Styre, including all the co-founders, all of the technical talent, and left the company as sort of a, a husk, an empty husk, an empty shell.
And basically Syra wrote to their customers and said, Hey, your, uh, enterprise level sup pr, your enterprise level product is end ending of life, end life. We're not supporting it. And for all intents and purposes, there is no styro.
And the good news is we've taken those enterprise level products that are built on top of OPA and giving them to the OPA project, which is a ward of the CNCF. So they're not dying, but there's no one, you know, there's no throat to choke there, there's no company no longer a commercial company providing it. And, and the community will decide what to do going forward to continue it, not continue it, change it, not change it, what have you.
Good luck and good night. You know, um, this happens. This happens, right?
It, it, it's, it's real life. So as you could imagine, a lot of enterprise customers of sty a as well as just rank a file, OPA users are saying, Ooh, this, this sounds like it could, you know, what could go wrong, right? Um, and, and so they're looking, they're casting about for options.
They're looking for help. Mm-hmm. They're, you know, they want some reassurances.
How was this affecting mandu and how, how are you guys responding? Yep. So, um, let me jump into the OPA angle first, because really if you look at it from the ground up, um, it was built for one thing really, really well.
And that is authorization. Even when we started out, we started to look at the specific security problem that we were tackling. We're still building up a product underneath.
And I use languages and frameworks like anyone else. So, you know, we use golan and things like React and other frameworks. And so, um, Rigo actually came up, um, for the authorization bit as well.
Um, we had evolved over the years out of it, but, you know, it is actually, um, purpose built for this and is doing a good job at that part. However, the problem is when you're starting to use it for tasks that it is not really originally designed to do well, and this is where the infrastructure, infrastructure security bits really come in, right? So I always compare it to like a spoon that I use.
It's great for eating your cereal in the morning, but once I start to dig a hole to build a house, uh, the spoon might not be the best tool to use. And so, um, as the star news has come in, a lot of users have, um, met that shocking day. First of all, the lack of clarity.
What is actually does that mean? But after a while, once it dawns that this product isn't really, um, having like its leadership anymore to lead us into the future, and they feel that the problems that they had raised, especially around the infrastructure security use cases, are not getting addressed. And to be quite frank, they haven't been getting addressed well in the last couple of years either.
Um, a lot of us were looking at Sty a and OPA because we saw that it had this widespread use in the Kubernetes community, and that it's going to be fixed eventually. Like all these problems that we're having, and we're waking up to the reality that that's not the case. And so for us, this meant actually, um, new users who are coming in, who are asking us how we tackle the problem for po um, infrastructure security, cloud security, and other use cases with policy as code and what we can do with it.
And so, as the first couple of users have been diving in, because you know, now it's worthwhile looking at the alternatives, they're actually starting to realize how many shortcomings the original approach with OPA has had in the use cases that they were trying to solve. Yeah. This is akin to sort of the, uh, the Broadcom VMware kind of thing where they, you know, they tripled the, the licensing fees and all of a sudden it became a, a reason for everyone to say, wait a second, there's alternatives, right?
Yeah. We could go to the cloud, we could use what the cloud provider has. There's, there's other alternatives that are cheaper that are maybe better.
Um, so that that's what's going on here. Now, there are some people who've made big investments in OPA. Yep.
And to rip that out, you know, no one likes to rip out if something's working right. Don't fix what's not broke. Yeah.
How's Mondo helping those people? So, um, what we are starting to realize is, first of all, um, in the infrastructure security use cases, you might have the investment, but really double check, is it working for me? The more we have talked to companies that have this use case that are using OPA there, the more we're finding that they're getting stuck with it.
It is very hard to spread. It is very hard to grow. I mentioned it before, right?
It isn't, it hasn't been built for this use case from the ground up. Um, so teams are often getting stuck. You will find, uh, teams of developers that are trying to, um, use this for security use cases and the security professionals on the other hand, also not being able to use it as effectively as they should.
Um, and so our experience is really take a look at that investment and take a look at what it does today. A majority of the companies that we are finding, um, they just want their standardized policies to be used, um, for cloud or for operating systems and for the other systems that they're using for that. Actually, mondu comes with most of these policies out of the box.
So you can just plug and play. It is not, um, really hard to replace for that use case. If you have written a lot of custom policies, well, we're finding ourselves in the age of gen ai, and it is actually making things a lot easier to move things from one stack to the other, or to use Gen AI for writing policies.
We have actually been growing our own policy teams this way over the course of the last year. Um, we've written the, uh, context that the AI needs to write good policies for you and to express them both with MQL as well as with our YAML based policies that we have. And so we have a lot of this tooling that makes it easy to convert the policies into something like MQL.
So you aren't stuck with OPN Regal. Um, it is not like you can't move off of it. It is actually something that is more feasible today than it would've been like two years ago.
Moreover, what we are finding, especially with our larger customers, is that the difficulty for them comes in managing this across their organization and being able to handle things like exceptions. Well, and this is really where OPI and Rigo have had the, the least capabilities. Um, the more we're engaging on these use cases, the more people are realizing that they can already do a lot more with MONDU and MQL today than they ever could have with OP and Rigo.
And so it suddenly doesn't just become a, you know, let me replace this, but actually let me do this better. I love it, Dominic, we're about outta time, but I think people got the gist of what you're saying here, right? I want to just tell 'em one more time, where do they go to get more information on mondu?
It's M-O-N-D-O-O dot yep. Com. That's right.
Mondu com Com. Come drop us a message on the website or say hi. Um, feel free to reach out.
And then also on the open source, if you're interested in that, if you're coming from OPA rego from the open source side and you're interested in infrastructure security, cloud security, any of that with policy sco, feel free to reach out. We've got a great project there. Excellent.
Will you guys be at CubeCon? Um, we might. Um, we are looking at that right now.
Um, for now, we are going to Hashi Con, um, if you wanna see us in a couple of Weeks. Yes. Notes the same thing.
So we will be there. Textron, uh, I won't because they're, they're too close to each other and I can't be in two places at once anymore. I used till Quantum Computing comes out, then I will be.
Um, but for now, Shredding her on. Right. Um, anyway, thanks for coming here on Text Drunk tv, don't be a stranger.
Come back and keep us posted. Okay. Will do.
It's been great talking to you. Alright, Dominic Richter, chief Product Officer, co-founder at mondu here on Text Drunk tv. We'll be back in a moment.
Hello and welcome to the latest edition of the Techstrong AI Leadership Insight series. Today we're with James ICU Horne, who's CTO for KA ai. And we're having a chat about, well, what's it gonna take to orchestrate all these AI agents and other things that are floating around out there.
James, welcome to the show. Thanks very much, Mike. Appreciate being here.
So I think we can all see this coming, right? There's gonna be thousands, who knows, maybe even millions of AI agents eventually, and they're all gonna be doing various tasks and they're gonna be floating in and out of our workflows. So how do we manage this and how do we orchestrate all this stuff?
Because I got a feeling we're gonna be quickly overwhelmed. Yeah, I think, you know, this is one of the, the key things that I, I think a lot about is, um, you know, there's a number of things out there to help you like kind of build an, uh, an agent and maybe help you deploy that agent somewhere tied into a workflow. But how do you do that at an enterprise scale?
Um, is a really fundamental question when you have to your point, thousands of agents, tens of thousands of agents running within your organization. And the key thing is, especially we don't know what the a the final architecture is going to be. There's no sort of winning architecture for running these agents at scale yet.
So how are you gonna be able to adapt to, um, the differences of different ways of running, say swarm environments where you have, um, you just have masses of agents that are given sort of a common outcome that they're trying to approach or hive environments where you have a central sort of coordinator who's starting and stopping other agents to fulfill a task over time. Um, or even workflow. You know, the base ones, the ones that are most common today where you've got a, you've got a fixed workflow, you've got an engine of some sort, um, and you have agents that are doing different tasks in that workflow.
The key thing is, is we, we, we know some things about the fact, like AI agents are likely to be very ephemeral. They'll, you'll start one when you need it. You'll, you, you won't keep it running all the time.
Um, they, they may be crated on the fly by other AI agents so that the actual definition of the agent kind of pops up as it's the need is discovered and goes away if it doesn't work out, or, or if it once it completes its task. So you start to ask questions, well, what, what do we need to survive in that environment? And one thing that we need is we need to make sure that we have access to data that's necessary to complete the task that these agents are doing, regardless of where they're running.
So we need, and we want, ideally, access to the systems of record rather than having to replicate and duplicate data all over the place. Um, a second thing that we need is we need the ability for our prompts to maybe go and use, um, you know, a model, uh, in one location tied to one data source to answer one part of a question and, and have a different part of that inference running in a different place to answer a different part of the question and be able to bring that back as a common response. So one prompt running on ultimately many models and coming back, uh, to into play.
Um, we need our agents to be able to sort of just ask a question and know that ultimately it's gonna get the, that proper response. We need agents to be able to communicate with each other and we need them. Um, we need a, a good mechanism to make sure that that's secure.
Um, all of this, by the way, has a security factor to it, access control, um, the, you know, the appropriate, uh, network protections and so on. So those are some of the things that we think about, um, a lot in terms of orchestration, is how can we provide that substrate that makes all of those things there and available so that as you build an experiment with IT agents and try to figure out what are the ultimate architectures that make sense, you know, that you always have that access, you always have, uh, that coordination and um, that knowledge of, uh, of location awareness as well, which is another big point in this, um, that you know, that things are gonna run where they need to and data's not gonna leave the boundaries that it shouldn't leave. Alright.
To your point, I think people are talking about this with things like, you know, the agent to agent protocol, but that's just a protocol. It sounds like we actually need something that feels like a platform that's gonna execute those protocols in a way that provides the governance, the security, and the understanding of what's happening between these agents. Is that a fair assessment?
Yeah, I think, I think every one of those, uh, protocols have been defined in a way that, um, uh, implementations have some freedom in terms of how they implement the protocol. So, for instance, data a is a good example. They don't require any form of queuing, um, in order for you to have that communication between agents.
But of course, if you're gonna do that at scale, you almost certainly need some form of queuing to make sure that you avoid, uh, race conditions or overwhelming systems, um, incorrectly. So, um, yes, there's a need for, uh, for a platform, um, to deliver sort of, and I use the term capacity and it's, it's, it made a lot of sense where we're just talking about compute, network and storage, but now the capacity than AA agent needs is the capacity to, to get knowledge and the capacity to communicate more. So, I mean, underlying is still compute, network and storage, but, but it's the way that the a you design an agent and think about an agent, you're thinking less about, um, how the computing works.
And you're thinking more about, if I tell a model to do X, is it gonna be able to figure out and go find the things that needs to do to complete that task? And that's really kind of the fundamental difference, is you still need to deploy things, you still need to make sure that you're consuming the right resources underneath, but the developer or the agent should not have to be thinking about, how am I gonna get to A-A-V-P-U that has enough power on it for me to process this video, right? That, that, that should not be what that agent designer should have to worry about.
Mm-hmm. You know, when I talk to some folks, um, we're all obsessed about how we get the agent to actually go do something, but, um, it turns out that convincing the agent to stop doing something might not so be easy either. So we need to have a framework or something that just says, you know, when you reach a certain level of parameters, you know, stop, otherwise you're just creating useless data for the sake of data.
Right? Yeah. I think that, um, there's still an agent design component that, um, that a, a platform like ours isn't necessarily going to take care of, but there, the ability to observe what's happening with the agent and to understand and react to the behavior of the system as a whole and of individual agents is really important.
Um, one of the things that we're doing here by creating all these things that are smart and adapt and learn and whatever, um, and having them come in and out of existence is we're creating almost the very definition of a complex adaptive system as, as that that area of science knows it. And that means there are going to be emergent behaviors that come from unexpectedly from the way different agents end up working together that we didn't plan for. So that's one of the things that we very much take serious, is how do we help you understand the emergent behaviors, uh, that are happening in, in, in your agent environment, uh, and help communicate with the other parts of your systems that are maybe handling, uh, you know, different specific aspects like workflow engines and things like that.
Mm-hmm. Does that include negotiations between the AI agents? 'cause I'm asking the question 'cause it seems to me there will be instances where AI agents will be giving, uh, conflicting missions and just like humans have where, you know, I may be in the marketing department and you may be in the sales department and we may have a conflicting mission that we need to negotiate some middle ground on.
Is that something that AI agents are gonna be able to do? Or is that where the humans come in? Well, I, so I, I just actually, uh, I haven't published anything yet, but I, I actually did just write a blog post recently for myself, um, on this very topic, right?
So the politics and the economics of these systems are gonna be real as well. Um, do we do anything explicitly today on that? Um, uh, we don't, I'm not aware of any system out there that really does, um, a, a a, you know, phenomenal job, uh, at scale of doing those kinds of things.
But there certainly are people experimenting to find, um, figure out how to do that. AI will be involved in doing that. So there's checks and balances systems that are already in existence in large scale, uh, agent environments.
Those checks and balances systems ought to be, um, you know, very, uh, just kind of very normal and very easy to have out there. Um, uh, but it's also something, uh, it's one of the reasons why I say, you know, the jevons paradox of the AI age is everybody talks about how all the developers are gonna go away and how those jobs go away. But I don't believe that, I think the nature of engineering changes.
I think it goes less from code writing and goes more to how do you curate these complex environments and the way that these things work together and handle the politics and handle the economic clashes and, and, uh, make tweaks as you need to, to help make sure that the system provides an ultimate outcome that's important to the business. But those things will exist. And, uh, and we are, you know, in for a decade of learning a lot about what that looks like and how we can manage it.
Mm-hmm. Another thing I don't see people talking a lot about, but I think we'll be needed is audit trails for what, who, what agent did what to whom when, and there'll probably be some sort of, uh, regulatory body that wants to know that information, but right now it feels like everything's kind of a black box. But is that where we need to get to?
Yeah, I think, uh, you know, at the very least what we do is, uh, we log the heck outta everything. Um, you know, we keep track of, like with the inference engine, as we, as we, um, do distribute, um, portions of inferencing out, we keep track of what, what decisions were made by ai, uh, to do that and what the responses were. Um, we, we keep track of, uh, you know, of, of interactions, um, between, uh, between agents and, and the Kaza platform underneath for, uh, for data access and other things.
And also, um, you know, we can help keep track of communication between agents, um, that are, are trying to complete tasks together. Um, it, it is absolutely true that there is no way for humans to manage systems like this unless they can see what the system is doing and see it at some detail and catch, um, catch what's going on. That may be important behaviors, uh, you know, bad feedback loops or good feedback loops.
Um, and so, um, so yes, this is part of what a, a genetic orchestration environment needs to do, is very much provide, uh, documentation of what the or the agents are doing in the orchestration environment. And one level of scale is always gonna happen. And I'm also asking this question because we seem to talk about using AI agents internally to manage workflows, but eventually they'll be expanding multiple organizations and multiple companies, and will that create another level of complexity on top of all this?
Yeah. Um, yeah. I wrote a book for a rally in 2021 called, uh, flow Architectures, uh, the Future of Streaming and Event Driven Integration.
And, and the, the thesis of that book was as we come up with standards for moving near real time data, um, between, across, basically across organization boundaries, across domain boundaries, that's going to, uh, uh, just create a flood of demand for those kinds of connections. And, uh, I believe that AI is proving to be the killer app to drive that forward. And you see it with MCP usage, um, already, um, you see some, um, some examples of companies attempting to use agents to automate their, their interactions with other companies on a b, b basis.
Um, it's very early, yet it's not a standard thing that everybody is doing, but, um, but I believe that, you know, the reason MCP and A to a and some of the other standards are so important at this early stages, they're beginning to find the way that we are gonna communicate not only within our organizations, uh, among a agents, but also across organization boundaries. And that brings questions about, um, security and monetization and, um, and, uh, you know, and auditing the, the origins of, uh, where data comes from and all those kinds of questions. Um, so, uh, we do see that, um, uh, we do see that there's an interest in that.
We, most of what we see today in development with agents though, is sort of within organization boundaries for now. Um, but I, I definitely see experimentation happening with, with beginning to cross those boundaries. Hmm.
Also, as one wag one's put it, um, it's one thing to be wrong, it's another thing to be wrong at scale, but how do we roll things back if they're happening in near instant real time? And, um, and, and what is the implications for being able to do that? Yeah, I mean, there's lessons learned from past architectures that we can, uh, we can take advantage of, right?
So we want to have, uh, uh, we, we want to have a strong understanding of where we need to log things in the sense of, um, uh, of, uh, of something that we can roll back step by step, um, or recreate, uh, actions that were taken. Um, so things like what, what people have done with eventing and Kafka, um, you know, those, those kinds of patterns will also work in this environment where you can begin to, uh, to put some transactional logic around different types of interactions. Um, remember that a lot of what agents are doing is actually interacting with tools that exist already today.
So there's already mechanisms and those tools to help, um, with things, but those checks and balances things that, that I was talking about earlier is a very important part of this picture. We need agents that, in part, are verifying that the outcomes we want to happen happen are actually happening. And that can trigger, um, a, a, a known action in response to something not working out the way we want it to, not, uh, not validating correctly.
Um, so, you know, it, it becomes almost like a, um, you know, I, I, uh, I don't know exactly what that pattern's gonna look like at scale. Um, but I believe that it, um, if you look at some of the people that are experimenting with swarms and, and other of those kind of large scale environments, they are explicitly defining prompts as a part of the definition of those things that say there must be, uh, agents that are verifying and validating that the following things are true. Mm-hmm.
So the agents will essentially police, the agents will, yeah. I, I, I believe that's the only thing that's fast enough to actually police them. I, I think humans will police outcomes at sort of large growing scale.
You know, are you getting the outcomes you want from your system, is fundamentally a human question. But, um, and then I believe that some of the, the sort of training and psychology and, and, and all the things that in terms of, of how move agents in the right direction to get the outcomes you want is gonna be human involvement. But in terms of reacting in the minute to a transaction that's happening, I think, um, you know, agents or possibly other types of software services, um, are gonna have to play that role.
But I, you know, it, it seems like agents are the logical way to go about it. So what's your best advice to folks? 'cause at the end of the day, I kind of feel like the agents are being built first, and then someday we're gonna s slap something that looks like an orchestration framework on top of them after the fact, but maybe the carts before the horse, which way should we go?
Yeah. You know, it's a chicken and egg problem to a certain extent. Um, absolutely validate that.
Here's the way that I put it is if you, or there's a lot of organizations that know, that have done enough experimentation that they know that, um, they're looking for the agentic environment that's gonna cha that it's going to positively affect their business. They already know that they've got figure out how to put the pieces and parts together, and they're, they're running experiments today. I would say if you're gonna start running experiments at large scale, that's the first sign that you probably need some sort of orchestration engine to make, uh, to lower the cost of that experimentation, to make sure the data access and, um, and inferencing and and communication are, um, are straightforward for all your developers across the organization, across organization boundaries were necessary.
Um, and then I would say, you know, um, there are some organizations, uh, out there as well that are beginning to, um, uh, to implement, uh, small experiments at larger scale. And I would say as soon as you get to a point where you're really running, you know, hundreds of agents at any given time, maybe thousands of agents at any given time, um, there's a lot that an agentic orchestration system can do to remove the toil of managing all of those agents to, to make it, um, uh, less effort and less risk for your organization from security perspective, from a performance perspective and so on. And so, at that point in time, if you're like, we're, we're beginning to scale up what we're doing here to a point where a, you know, one human or a few humans can't manage it very well, um, it's time to look at, uh, an orchestration environment for the same reasons that when you were doing containers, you eventually looked at Kubernetes because you, you had gotten to a scale where managing all those containers became very, very difficult.
All right, well, folks, you heard it here. Hey, it's quite literally just like going to the orchestra, right? I mean, there's musicians, they all know the music, but they still need a conductor.
That's gonna be you. Hey James, thanks for being on the show. Thanks very much, mark.
Really appreciate it. All right. And thank you you all for watching the latest episode of the Techstrong AI Leadership Insights series.
You can find this episode and others on our website. We invite, should check all those out. Until then, we'll see you next time.
Hey everyone, it's Alan Shimmel and we are live. That's right. Live, uh, it at Swamp Up.
Swamp Up is back in Napa after I think two or three years it's been since they were in Napa Should End, I'm thinking it might have been since before COVID that we were in Napa last. But we're really thrilled to be here. It's beautiful here.
It's a beautiful resort, but more importantly, there is so much going on at Swamp Up, you know, like everything else in the tech world, it's kind of the year of AI more than the year. It's the era of a, the dawning of the era of ai. Still, I like to tell people we're still at the beginning of the beginning, not even the end of the beginning on ai.
Let me introduce you to my first two guests of our Techstrong TV coverage here at Swamp. Up to my far left. He's the guy in the, in the, in the, uh, shift happens Frog shirt, Yuval.
Let me make sure I get it right. Excuse me. Yuval Fern back.
Yuval, welcome back. It's good to see you again. Thank you.
Good To see you as well. You know what, before we get to our next guest, Yuval give to share with the audience your title and role at jfr. Sure.
So, hi everyone. I am, uh, Yerba, I'm VP and CTO of MOFs here in Jfr. Um, actually joined Jfr, uh, a year ago is part of an acquisition of a company called Quack.
Um, and nowadays, of course, part of jfr ML and the new product that we launched today that of course we'll talk about in a second. Thank you, Yuval, to my immediate left not in the Frog shirt. Is is Al Alek.
You got that right? You got that? Perfect.
You got that on the money. Alrighty. Ale is with, uh, Nvidia and Del introduce yourself.
Well, thank you for having me. Yeah, it's great to be at Napa. I was joking around earlier telling folks that, uh, you know, I'm glad we're doing this 'cause now my family really believe that I'm here for work proof.
So got the proof right. I got the proof now. So, uh, my name's Del.
I'm a senior, a director of product, uh, at Nvidia. And my job is to, um, take the software that our, uh, awesome core tech team creates, um, uh, harden those, make them production grade for enterprises and help our ecosystem build, um, agents, right, that are fra frankly transformative in everything that we do. Something we were just talking about.
Absolutely. And, and that's a great segue. I, uh, little something extra for giving us that segue.
We were at the keynotes this morning, right? Yuval led off, Al came on. Yuval, you, you, uh, introduced a new product for Jfr called the J Rog AI catalog.
Explain to our audience a little bit, what, what is it? Yeah, so, um, as I shared, I joined jfr a year ago, and as part of that, I've seen and got a lot of responses from Jfr customers about the challenges they have with adopting ai, the challenges that they have with actually trusting AI and the amount of new models that are being launched daily, right? Um, everyone's speaking about ai, but actually using that in production require more than just, you know, testing the new and shiny model.
It requires the ability to trust that, the ability to trust where that model is coming from, um, who's the owner of that model, and even who is actually going to use that model. And as part of that, and it's part of all that feedback that we received in the last year, we decided to launch the J 4K catalog. And that's basically a solution that allow organizations, allow our customers to manage the entire lifecycle of AI usage, I'll call it, from discovering which models actually exist, um, to deciding who should have permissions to which models, and eventually then serve those models, uh, track the, uh, usage methods of the models and understand which application uses models and how.
So the goal is eventually to allow organizations to understand where those models are being used by whom, and make sure that they trust those processes that are, you know, shifting in, in such a magnitude and such a, a, a, a pace of innovation that we haven't seen before. Absolutely. We're gonna come back to that.
'cause I, I have some thoughts and questions, but not open. Explain to me the Nvidia Yeah. I mean, connection, there's a reason for this awesome partnership, right?
Right. And so, uh, we're a full stack acceleration company. What that means is, right, uh, we're not just about producing processors or, or systems.
We actually build out AI factories, but we go the all the way up, right? For optimizing runtimes for not just models that Nvidia publishes, but also the ecosystem models as well. We call that nim nim inference and microservices.
And so, uh, what we do, you can think of a nim as, as a, a model with a runtime package as a single microservice, we spend a lot of time tuning that runtime to make sure it runs it efficiently as perform as possible, uh, on the NVIDIA stack. Um, but equally, right, we contribute a lot to the open source domain. We're very, uh, we're huge participants in the open source community because going back to Val's point of having that, that trust, having that transparency, it isn't just that we provide the NEMO tron open weights, which are fantastic by the way, and Excel really good at reasoning.
But we, we also open source our, our training data sets. We open source our recipes so enterprise can then take those models further into them for their agenda, uh, capabilities. And so being the ones that provide the secure runtime and the open source of the models and the weights and partnering with Jfr, what drives the services for having all that lineage was just an amazing partnership.
Absolutely. I, I want to dive a little deeper on this, right? So I was at Swamp Up last year in Austin where they announced the, uh, J Frog Nvidia partnership.
Now over the course of the 12 months, how have, you know, what, have you seen how this partner, well, look, AI has been on a hockey stick trajectory for these 12 months, right? But how has that affected, what's the, the, the net that our audience could take about this partnership? What does it mean to them?
I mean, look, you know, you've all kind of set the scene, right? There's so much happening and it's happening so fast. I joke around and tell people that at one point I think my kids thought I was a vet 'cause I was talking about new animals every week from llamas to Mambas to, you know, you name it, right?
But, but it's awesome innovation that's happening in the ecosystem, right? So a couple things that are, that I think critical number one is all this innovation that happens, yes, you wanna be experimenting a lot, et cetera, but when you have all this innovation that's happening, right? And you have all this open source, the potential for exploits growth significantly as well, right?
And that's something we talked about earlier when, you know, we were on stage. And so, uh, being, having that transparency, understanding essentially what's part of your run times where malicious code can be potentially like implemented is, is super critical. So you wanna be experimenting, but you also wanna be careful and prudent when you're experimenting.
And so that's why having a single source of truth right, for your system of records, for all your artifacts is critical. And that's why that relationship's been awesome. And Sorry.
Yeah, go ahead. No, no, go. And I think the second point is right, um, one of the first use cases we started using agent AI was in actually defining the contextual, um, analysis.
Doing the contextual analysis to understand whether vulnerability can be exploited or not, right? And I think, uh, I really appreciate the partnership that we have with the JAR platform because that's something they take very seriously as well. Just 'cause A CVE says, you know, it's got a high CVE score, doesn't mean it's exploitable.
There's a lot that goes in to be able to exploit that. And so, you know, we see eye to eye in terms of how we go about really going deep and understanding the potential for exploits and protecting our, our, our customer base. Absolutely.
And by the way, this, this partnership didn't start because, you know, us and Vidia thought that we should work together. It started because the J four customers approached us, told us that they need to trust the source of the models. And, you know, the only models for market face, by the way, I think the target phase is an amazing hub for models, but it's not enough in many cases.
And customers approached us and told us that they want to have a trusted source of models, and NVIDIA is one of those trusted sources. So a year ago, we, we partnered to make sure that the J four customers can actually get the Nvidia e models, the re for multi factory and trust the origin of those models. Um, and from there, of course, we progressed with that partnership with the security solutions.
So the contextual analysis, that ability to actually understand how those, uh, artifacts, how those models are vulnerable. And now we can make sure that in the production environment there will be no vulnerability. So eventually it's part of the same goal of making sure that the J four customers, and of course the NVIDIA customers can actually trust the models, trust the region of the models, and trust that there are no security.
And then that will arise because of those new artifacts that they not need to manage and of course have to manage to actually make their product progress over time. Excellent. Ada, I wanna come back to you 'cause you said something right in the beginning that I want our audience to understand.
And that is, so a lot of people hear Nvidia and they're thinking G-P-U-G-P-U-G-P-U, not that you make a bad GPU, don't get me wrong, but the real key to NVIDIA's position is the software, is the community, is the ecosystem around Cuda and, and, you know, uh, um, NIMS and, and so forth. Talk to us about that a little bit and why you are, we're on live tv Paul, uh, cameraman. I'm gonna ask you to grab outta my bag, my AI catalog paper.
We'll bring it up. We're gonna talk more about it. But al talk about yeah, what the secret sauce at Nvidia?
Uh, Well, we're a full stack acceleration company, right? I mean, um, yes. We, we start at, at the silicon, but we go all the way up the stack, right?
And so we have AI factories, we have our, our software portfolio that goes all the way up to the, um, you know, what what we call blueprints, right? Reference workflows for how you'd go implement a specific use case for, for agents. And you get the full benefits of Nvidia when you take the full stack, right?
Because we're able to optimize all the way down to stack. But by no means you have to take the full stack, right? And we leave it up to our audience or ecosystem to meet us where they think is best.
Some just wanna run on our infrastructure. We love them, some want to utilize right? Wanna go higher up in the stack and take advantage of the optimizations that we drive through software to enable that.
I think one key to Nvidia is, um, you know, call it success or, or secret sauce is just how, how ingrained we are with the ecosystem. We, we go to market through our ecosystem. Our partners such as J Fog are super critical to our success at the marketplace.
And so you're spot on. We're not just a chip company, we're a full stack company. Um, right.
You can take us, you know, you can go with us up all the way, you know, all throughout, or you can just choose to meet us where you think is best for your, for your, for your domain. I love it. Thank you.
So Yuval talking about the jfr AI catalog, you know, I've written a lot recently about what I call shadow I, uh, shadow ai, right? And we've seen shadow, look, I've been in, I've been in the tech business probably longer than both of you. Okay.
Um, I've seen Shadow, before I saw shadow open source, there was a time where enterprise's official policy was no open source fill out. It was, it was a danger, right? I've seen shadow wifi.
I remember being at a US Army base and the, uh, army Information Assurance officer telling me we don't have a wifi security problem 'cause we don't allow wifi. And as I'm walking with them, I see people unplugging laps and throwing them under their desk. As soon as he walks by, they plug them back in.
And wifi, we saw it with the cloud developers whipping out their credit cards and opening instances. It's no different, no different with, it's probably even easier with ai. Yeah.
'cause you have take your pick, right? Whatever one you want to use. So we call this a prop, right?
They gave this out at the, at the keynote today for your talk, your joint talk. Talk to us about the different models and how we're gonna control shadow AI at the enterprise level. Yeah, yeah.
So, so first of all, yes, it is a prop because, you know, this, this booklet have six models in it. Um, I believe that the current number in phase of models is around 2 million. And you know, on top of that there are, um, external like model providers like OpenAI and others.
So that's another couple hundreds of models. So, you know, the numbers are way more than that. And of course, no book can actually, you know, manage and track the amount of models that are being launched.
Um, and models are now, they used for, you know, so many different tasks. So actually Shadow, um, a is in stock, talk about different type of models like reasoning models and, and, you know, voice models and models are being used for different tasks and not just for language models. Like, there are many models around computer vision and many models that are still used for structured data.
And that's still a valid use case and still something that customers, you know, use as part of their use cases. Eventually, the goal of the AI catalog is for organization to have the visibility about those models, about where those models are being used and how, and on top of that, as part of our launch, we actually launched a new product that will be available in a couple of months, um, called Shadow ai. Now, the, the issue of shadow ai, the problem with shadow AI is that in many cases, you don't even know that the model is actually adding one of your packages.
It's possible that you downloaded the third party doer image. Uh, that doer image that you use actually uses ai. Um, and it's not something that you can just, you know, not know about.
Because nowadays, even the regulators in many places, for example, in the EU, actually force you to show that part of your product uses ai. It's something that you need to have visibility on. It's something that you need to be transparent on.
So the goal of the Shadow AI product, but of course, is connected to the J four AI catalog. It's to just not, not just allow you with Air catalog to choose which models should be used, but also to see, to have the visibility about where model is being used, but you are not really aware of. And if those models are being used, for example, malicious or those models that are being used are actually not approved in your organization, you'll be able to actually block those from being used or, you know, go through the pro through the process and approve those specific models.
Um, so the goal is about visibility and the ability to discover where AI is actually being used in your organization. You know, again, my experience is you don't wanna stop people from using ai. Yeah.
And quite frankly, stopping people from using AI is like trying to grab sand in your hand. The, the tighter you make it, the more it slips out between your fingers. What you wanna do is just, okay, you're using ai, let's let us document it.
Let's make sure it's safe, let's make sure it's secure. Right? And that, because otherwise you're fighting a losing battle.
Nvidia has to see that as well. Al No, I, I'm, I mean, right. We're not, we're not, we're not definitely fighting ai.
Right. To your point, right? It's, it's, I mean, there's plenty of productivity gains new markets that it opens up, as I said, right?
Uh, the, the only reason we're able to publish and maintain so many of these NIMS is because we're using Agentic ai. Right? Absolutely.
But to your point, you do have to be cautious, especially with all this open source that's happening, all this innovation, et cetera. You wanna create an environment that allows your developers to experiment. That is for sure, right?
You wanna, you wanna continue creating that, that experimentation, right? Uh, that you want to enable as well. But then when you're going into, into production, yes, you want to have the safeguards that are in place.
Um, you want to be able to have the observability, the tooling that is in place, right? I, I go back to, you know, the, the nitron models that we provide, right? Just being open source in terms of not just the model weights, but the data sets of what it was actually trained on, the recipes of how we got there.
Just to give the enterprises and the ecosystem that level of comfort, right? To know exactly what's going on, right. Such that you always have that lineage that's super critical.
Yeah. I don't think you can, you know, uh, on the contrary, right? Like, we're just on the, I think you called the beginning.
The beginning of the beginning, Right? And just imagine when physical AI comes into, comes into this world, right? Today we're talking about digital workforces, but very soon, right?
We're, we have these world foundation models where you're simulating and generating data to train these robots and these autonomous vehicles. Man, it's, it's about to get exciting. It, it already is.
It already is. Um, but you know, that bring, both of you mentioned this, but you kind of ate at the edges. You didn't eat the middle, which is something else that they spoke about in the keynote saying, I'm trying to remember the exact name.
Was it AI gov or ai gov ops? Something? It was, uh, dev gov ops.
Dev gov. Ops, excuse me. Dev gov.
'cause there's always something in the middle between dev and ops, whether it's psycho dev gov ops. I learned a couple new ones today. Yeah.
Sorry. Yeah. Yeah.
So, but that's really what we're talking about here. We want, we need governance. Not, we're not here deporting AI models, right?
We're here talking about you wanna use ai, use the ai, but let's have some governance around it. Let's have some guardrail, some knowledge, right? And that's, to me, that's the enlightened way of doing this, right?
We're not discouraging use ai. I know. So textron's, part of Futur, and we, we have a policy now where we're encouraging all of our people, the cameramen, the editors, the writers, the marketing, the decoders, use AI to your hearts content experiment.
We expect you to make some mistakes. That's okay. Make the mis I'd rather you make mistakes trying something new than digging in your heels and saying, I, I don't want to use ai.
'cause if you don't use, I tell young people this, who ask me all the time, you're not gonna lose your job to ai. You're gonna lose your job to someone who uses AI better than you. That's right.
Look, this is something we think about as well, right? And kind of now you're, you're going above and beyond just serving a given model or talking about managing the lifecycle of, of agents, if I may do that, right? Yep.
And, and that pipeline, right? We use, we, we have something called the NEMO platform for managing life cycles of ages. Mm-hmm.
And that starts from data curation, uh, creating additional data that is, um, doesn't have the potential PII, that you know, you're not just collecting people's prompts, right? To then, uh, taking a model and adapting it for a specific domain. Then once you have that right, and, and putting it as part of a, of an agent, make sure you have the guardrails that are in place, right?
Such that it doesn't go re make sure you have the traceability. You can backtrack across the way. We have, uh, something called the NEMO Agent toolkit that allows us to drive all that traceability, all that observability, all that pri profiling around.
It's almost like, it's almost like onboarding a new employee. You have to teach them about your cultures and your norms at the company. You have to tell them the dos and don't dos, kind of like, you know, I'm doing in this interview.
Right? They, yeah. Right.
And so, so it's exactly like onboarding a new employee and putting all those kind of, you know, managing it throughout this lifecycle. And to your point, it, it first, organizationally you have to, I love what you just said, right? Everybody's gotta be experimenting, but then making sure that your enterprise is leveraging the likes of the NEMO microservices to Right.
To manage that entire lifecycle. I love it. Yuval, I'm gonna give you the last word and then we're gonna wrap up.
No. So actually going back to this, uh, dev gov ops term, and, and again, we talked about it today. And, and this is in a way the theme of this one because, you know, automation is already around.
We're seeing that as part of the development lifecycle. We're seeing that now as part of the DevSecOps lifecycle and also around, you know, ML and AI adoption. The challenge is not, or is becoming not how to automate those processes and how to actually, um, um, use new technology.
It's how to make that in a governed way, right? How to protect the way that we use the new technology and make sure that while we are researching new technologies, while we are actually adopting ourself to this new future, we do have the visibility and the governance on top of that to make sure that we're not doing anything wrong. And that eventually our customers of, of our product can actually get benefit from those new technologies that we actually use in our products.
I love it. Yuval del. Thank you.
A del No, you got it. You got it. What, Alan, thank you so much for coming on here, kicking off our coverage of Swamp Up 2025.
We've got a lot more coming at you. Unfortunately, not all of it's live, but we're recording it all. And over the next days and weeks, you'll be able to see everyone we spoke to here.
I encourage you. com or Techstrong It, tech Strong, AI digital, CXO Cloud native, now, even Security Boulevard. 'cause we'll probably do something about dev gov ops on there to, for our full coverage at Swamp Up.
But we're gonna take a break here. Stay tuned. We'll be back with more from Swamp Up This Tech Drunk tv.
Hey everyone, we're back here at Jfr Swamp up in beautiful Napa Valley at the Meritage. We've had a great day of talking to some really great people, and we're ending it with a really smart lady. I'm gonna introduce you to here in a second.
Her name is Jung Lu, and Jung is with Wiz. And beyond that, Jung, I'm gonna leave it to you. So talk to our audience, tell them a little about yourself.
Sure. Thank you so much, Alan, for having me. Um, so Wiz a little bit about Wizz.
We do cloud security, and our goal is really to help organizations adopt cloud as well as AI as fast as possible. And I'm the VP of product marketing, so I'm responsible for product go to market strategy, as well as execution at Wizz. Love it.
Um, our audience is very familiar with Wiz. Obviously we've been following them for a long time. Um, I wanted to ask about you though, because people are saying, wow, great, she's, you know, she's got a great job over there.
But give people a little bit of sense of your journey in, in the, uh, industry. Yeah. So I will say I grew up in Silicon Valley.
Both of my parents were engineers and, um, I fully rebelled. They expected me to go and be an engineer as well. I started going down the computer science path, realized I hated it.
Uh, and so I fully rebelled into finance. Okay. Um, and did that for a bit before I saw the error of my ways and realized I need to come back to technology.
What's core to me is building cool stuff, right? That actually makes an impact rather than necessarily helping rich people stay rich or get richer. Oh.
Um, and so that, uh, ultimately ended up taking me back into technology, back to Silicon Valley. I was incredibly fortunate to land at Okta. And so really saw actually for the first time how it became an enabler of the business, right?
Because this was the wave where we had sas, right? And it could really enable that. And this was also the time when organizations were really thinking about how authentication, um, can be actually an enabler again, of the applications that they are building for their customers.
When you think about identity being so central to the journey that you wanna take a customer on. So that was a phenomenal journey. Uh, ended up seeing Okta grow from about 400 people to 6,000 people.
Very large company at that point decided it was time to get back to that builder route. Um, and was was just by far and away crushing it, such an incredible vision that they had as well. Absolutely.
Absolutely. Um, you know, I always said identity, IAM was the killer security app for the clout, right? So I, I grew up in the security before the clout and, you know, and for us it was the Molten Castle era, right?
And cloud changed all that, but IAM became kind of paramount until the Wiz came along. Well, cloud, cloud, Well, cloud, well, cloud made I a Cloud development, right? Yeah, exactly.
But Wiz came and, and we started looking at cloud security, container security mm-hmm. Cloud native security in, in a different light. Um, you are here, we're at Jfr, obviously you presented today.
If you wouldn't mind share with the audience a little bit about what you presented on. Yeah, So I think one of the key challenges that we see is there's actually been multiple generations of cloud at this point, right? Yeah.
We've had cloud for 20, some, 25 years, years, yeah. About two, five or four. And I think really in the early days, it was a lot more of the lift and shift, right?
We could take our on-prem approaches, we could take our workloads, move them into virtual machines. And really a lot of that has, um, dramatically changed, right? It's changed with cloud native development where every team, every organization is trying to move faster and faster and faster.
We have developers that are writing application code, we have infrastructure folks writing infrastructures code, and all of that is being shipped every single day. So development is incredibly agile and continuous, but the challenge that we have long had in security is our org structures, our workflows, even the tools that we have, right? They're still very vertical and siloed.
So application security teams, they run code scanners that look for vulnerabilities just in code, right? And then we have DevSecOps teams now that run scanners and pipeline that just look for issues in the pipeline of all that, of infrastructure as code scanning in cloud, we have organizations using tools like Wiz that evolved data CSPM tools that are primarily used by cloud security teams, but increasingly developers. And then in SecOps we have like a whole other completely different Yeah.
Landscape of tools for the runtime. And so all of this is very disjointed, right? It's very fragmented.
How do I actually understand a vulnerability here in code that my SaaS tool found actually is deployed into production and is running on a privileged container in my environment? It's actually very difficult to understand. And I think, you know, when we look at CISOs, when we look at business leaders, even, they ask these horizontal questions like, where are the container images?
Where am I exposing sensitive data of my customer facing applications? What, where, where's my risk? Where's my exposure?
And it's very difficult for security to answer those questions today because it is so silent. So really what I was presenting on is how do we flip that model, right? How does security become horizontal so that we can move at the pace that our development teams and DevOps teams expect for us?
And really the key to do that is in our view, context, right? Understand what's running in the cloud, give you the context for the code that created it, as well as the owner that is responsible, and then give you runtime context, right? What's actually in use, what's loaded into memory that we should prioritize?
I love it. You know, what you just said in a lot of words was why we have 7,600 venture back public security companies because it is so fragmented and so siloed and so specialized. Everybody's a specialist.
And you know, when the average, not even big enterprise, when the average, like SME enterprise, I forgot what the number was, 18, 17 different security vendors in a relatively small company. This is, you just hit it on the head, right? You, you imagine, you know, you're a CISO and you're responsible for 17 different security vendors and you gotta make those all work together, right?
It's, it's enough to drive you to drink is what it is. But, and, and we, we, we try to, we're trying to consolidate, but at the same time, the pressure to keep up with the pace of innovation, with the pace of, of ai, with the pace of how much code we're churning out right now, it's like, you know, it was mission impossible before. This is mission impossible squared.
Um, But what I would, yes, sir. Well, but what I would argue is I think we overly focus on tool consolidation, right? Tool consolidation is an outcome, but I would say the issue is we have a lot of data mm-hmm.
But we don't know how to turn it into something that we can action, right? Every organization, you go to them, they've got their expel Excel spreadsheet of millions of vulnerabilities, right? It's not that we have a problem with finding vulnerabilities.
We have a problem with prioritizing and then getting someone to actually fix it. So I, context for us is how do we really get the insight out of all of this pool of data that we have on what's most critical? And then let's break the silos between our teams so we can actually work together to fix them.
Music to my ears, I mean, I'm thinking back, so I, I started a company called Still Secure in 2001. In 2003. We came out of the vulnerability scanner long time ago.
And that, that what you just described was exactly the state of the art. In 2003, people scanned about once a year they printed out a telephone book and it was like job security, right? Because you, it took you a year to go through that book and just in time for the next scan for the new book.
Um, we've, we've tried to got getting better. You, you're right. com primarily because I thought it was a better shot at security.
Like we could correct some, you know, original sins built into security, really pushed for the whole DevSecOps thing. Like at RSA conference, we did the verse DevSecOps conferences there and everything. We've come a long way.
But one of the lessons we learned is that developers are not security people. They wanna develop quality code. Like I've never met a developer who says, I want to develop insecure code.
Yes. Right? They all want to do, but I think one of the mistakes that we've made as an industry is thinking that if I only could make them a security person, they develop better code.
They're never, they could be a security champion, they have pride in their product, but you still need security people at some level doing the security and helping them. Yes, I agree with that. But I think, again, for developers, it's not like there was a lack of data.
Like no, you know, we tell them all the time, look at all these vulnerabilities. Um, but the issue is what should I prioritize? Yes.
Right? Again, it's what is the insight? What's the needle in the haystack out of this very long list that you've given to me, security team?
And how do we start giving them that prioritization actually, again, through context. Yeah. Right?
Instead of saying, Hey, developer, did you know you have hundreds, maybe thousands of exposed secrets or secrets that have to be rotated? Um, instead of saying that, we can say, actually of all of these, this is the one secret that I need you to focus on, because I actually know that it leads to an admin in our cloud environment that has access to sensitive data, right? We give that developer that information, they're really, they get it, right?
So how do we get the, is that information derived using AI or some sort of automated means? Or does that take the security pro saying that's the one? So I think it's two things, right?
One is you have to correlate the signals together, right? So your secret scanner has to talk to what, uh, the entitlements and the identities that you have in the cloud, right? So your Kim solution, and they have, you have to be able to correlate that together.
So a tool can do that. Security teams can also help you to do that as well. And they can provide the signal of this is what's most important for you to go fix.
Then we can actually use AI to accelerate that path to remediation, right? Because there's actually a number of ways to resolve that particular issue. You could delete the key might be a little aggressive, you could rotate the key, right?
It's kind of shooting the patient to save them, but, okay. Yeah, no, sometimes, uh, uhhuh. Um, but we can offer all of the different paths to remedi remediation.
Absolutely. And the developer, again, they know what is best for their applications for the, um, repositories that they are working on. So you can give them that and AI can help them actually take, okay, I think this is the best path to then actually getting to a fix.
So I've spoken to a lot of security companies recently who are saying Nirvana is, we automate this, we automate prioritization and remediation. Now look, from my time on the other side of the camera, selling automated remediation was not an easy sell. People are scared to death of that, right?
But have we come or are we coming to maybe a point where we can convince a developer or an ops team that hey, it, for, you know, 80% of the garden variety stuff, we see what automated remediation is the way to go? I think that is a nirvana, maybe it's not that far off, but from what we've seen, organizations want to automate everything around a decision point and an action that still requires a human in the loop. Um, especially because we started in cloud, right?
Automated mediation and cloud is a very aggressive, right. If we, it's, It's aggressive everywhere. Believe me, it's true.
I I, I, that's why I'm still doing this and I'm not retired, but yeah, uh, it, people just don't want, you know, they're afraid that you're gonna break something. Rightfully So. Yeah, though, like you could be taking down production workloads, you can, taking down production customer applications, it is, it, it requires you to, to feel that like impact.
And so that's why we think there is a human in the loop still, but as much of everything around it that we can automate as possible, we should. And I think that does allow us to really start getting out of the continuous patching game and really start burning down these backlogs that we've had forever. Absolutely.
Pat patching is, is unfortunately a losing prop. That's again, something that we've been remediating since 2000 and or trying to do since 2003 and has never gone on. Let me pivot a little bit.
We're here at Jfr Swamp Up. You did present, as I mentioned, and we've been talking about that. What's the connection?
Where is Jfr? Let's talk about that. Yeah, so I'd say overall we share very similar visions, right?
When we think about how do we secure development that is happening faster and faster every day, it requires security to move faster, and it requires every team within security to also work together as well. So at Wiz, um, from actually the pretty early days, we have scanned Jfr Artifactory to bring in their understanding of container images and artifacts into Wiz to give that complete understanding of the cloud environment. Now, what is coming next is we're deepening our integrations because we both believe in that open security ecosystem in order to share context that empowers all of our teams.
And so from a Wiz perspective, we have a lot of understanding about the risks associated with cloud. We understand runtime context, the code context as well. And so we're bringing that prioritization, bringing the risks, and all of that back to Jfr.
And similarly, JFR, OOG has very deep understandings of packages, right? And so we can take their reachability analysis that, um, acceptability as well, and we can layer that into Wiz and use that context to also further enrich our prioritization as well as the, uh, the move to actually getting to a fix. I love it.
Last question, or last area I want to talk on, you know, you can't take two steps without tripping over AI here. What's the AI angle behind all this? Yeah, Well, so when we look at ai, there are really two sides of the coin.
One is how do we actually secure the AI infrastructure? And a lot of it is being built on top of cloud. And so for us, it is actually a very natural extension of what we know about cloud environments, right?
We need to understand the configuration, the control plan. We need to understand identities that are associated with it, or non-human identities. In this case, we need to understand the workload layer or the data layer that's being used to train the models and do a complete assessment of the risks that are there.
And from there, we can enable now AI teams bring them into the fold, break the walls and silos with them so that they can actually take ownership and help us to secure those elements of their environment. The other side is around how AI can actually empower all of our defenders, um, to be much smarter to do, to secure things, to take action with less resources. And so we're actually seeing such incredible results there.
Um, as an example, we released a new product today called Wiz Os. It's all about hardened container images. So you can start secure.
And what we're seeing is we can actually use AI to immediately point out to teams. These are the most impactful places for you to start deploying this so that you really start getting value right off the bat. And by the way, here's a migration plan, right?
Here's everything automated delivered into the hands of that DevOps team or DevSecOps team so that they can get going on that journey. Let's talk about that. I'm, I'm sorry, I know I said the last thing, but I got some questions here.
So how, ma how big is the library, if you will, of these ardent container images, if we can call it that? Yeah, so for us, we are starting with the set that our customers primarily require. So it's all of the major languages.
We've got Ruby, Python, right? We also have FIPs compliant images as well. Oh, we expect to, um, grow the catalog as we continue seeing customer adoption.
But the question that we get from customers, or what we've found through our product development is it's not the number of images, right? Again, it's like the impactfulness, right? Help me cover the most important components of my containerized environment and then help me actually adopt it, because that's been one of the key challenges.
There are so many container images in an organization. Security oftentimes is very little visibility even into where are all of my container images? Which ones are validated in runtime, right?
Mm-hmm. Which is probably where we should start to focus first. So we're layering on this element of the product with the overall end-to-end container security approach to help organizations again, prioritize and then actually then swap in where you will have the biggest impact in reducing the number of CBEs.
And this was released today, which, so this is not live. People will be watching this ah, in the next couple days. Yes.
But as of September 9th, correct? It's, it's out right Now. It, it is out in public preview, which means every single one of our customers has access to it and can start adopting it today.
I love it. Wiz os W os You heard it here on Text Trunk. Oh.
Um, well, John, thank you so much. I thank you. I know it's kind of the end of the day and you were nice enough to come in.
I, oh, No, thank, thank you for having me, but Keep up the great work then. Wiz is doing exciting things in this cloud security and security space in general, so it's great to have you on come back. We do this all the time remotely in person.
We'd love to have you back. Thank you. I appreciate That.
Thank you. Jang Lu, uh, with Wiz here at Jfr Swamp Up. That's gonna wrap up our day one coverage here at Jfr.
We'll be back tomorrow. We've got a full day starting, I think at 11 or something, so stay tuned then. But until then, this is Alan Shimo for Techstrong tv.
Thanks everyone. Hi everyone, it's Alan Shimo. Welcome to another episode of Control Alt Deploy.
This is a, uh, control Alt Deploy is a podcast we try to do every two weeks or so here at Techstrong. And we talk about, well, it's, it's really DevOps, but it's DevSecOps, which is kind of, you can't have DevOps these days without DevSecOps. It's about security.
It's about how we're, how we're writing and deploying and running software these days. It's, it's one of my favorite shows of all the things we do on Techstrong. It is, uh, sponsored by our friends at OpenText.
So many thanks to them. But, um, it's, it's our show. It, it's a tech strong event, a production as we say, and, uh, have a lot of our tech strong friends on this particular episode.
I'm looking forward to it. Today's episode is titled Shift Left or Shield right, the Evolution of DevSecOps. And, and that's a loaded question we're gonna have a lot of fun with.
Let me introduce you to our panel members for today. If you watch Textron Gang, you've probably seen a lot of these folks on, on the gang. So they may not be strangers.
Gee, I'm gonna start with our, our friend Kate Scar and welcome Kate, if you could give people a little bit about you. Sure. I've been a part of, um, I've been doing technology since 1998, started with IBM and again, you know, cybersecurity with us, started with network security, AV and dare I say Tivoli identity and access management, so, Ooh, yeah, no, that, hey, was gonna rule the world.
Thanks Kate. Um, joining next is our good friend, Tracy Reagan from Deploy Hub. Hey Ellen.
Hey, you know, Tivoli used to have some pretty righteous parties in Austin. All I have to say about that, and yes, I am Tracy with the Deploy Hub. Um, I do get to enjoy being on the gang, uh, on Mondays, which is a lot of fun.
I'm part of the Linux Foundation's open source security foundation, um, board governing board, as well as a continuous delivery foundation's board. And I'm really into open source and I'm really into fixing post-deployment vulnerabilities. Excellent.
Welcome, Chay. It's great as always to have you on. Next up, we have an analyst, gang member tech day, uh, delegate.
Our good friend Jack, Jack Poller. Hey, Jack. Hey, Alan.
Great to be here. Uh, I am the founder and principal analyst for Paradigm Technica. I have a long history in technology, a few more gray hairs than Kate in a few more years.
Uh, I started as an engineer, turned into a marketing person, and then an industry analyst focusing on cybersecurity. Excellent. Thank you Jack, and welcome.
It's always, it's always great to have you on. Next up, I wanna introduce you to Garima ba, Baal. Uh, well, I'll let Garima introduce herself.
Garima, go ahead. I'm re I am, I am based AWA Canada. I'm the founder for the DevOps Committee of Practice here in Canada, just several chapters.
I'm also the chair for the ambassador program at Condense Delivery Foundation, written several books, and, uh, my latest book, which is coming out, is mastering Security at Scale. So hopefully I can value add to the spam. Oh, I'm sure you will.
Garima you always bring value to every, every panel, every show we do. So thank you for all you do. Last but not least, he's, he's the newcomer to our group here today, but we're gonna not hold that against him.
Trey Island. Trey, welcome. Introduce yourself.
Uh, thank you very much. Yeah. Um, I'm based out of Denver, Colorado.
I'm a security consultant. Um, so that means I am the technical hands-on demo guy. Uh, when it comes to, Hey, how do you integrate application security into your organization?
Are you ready to move to the cloud or do you have CICD implementation? So I kind of help with all of that, uh, integration with our tools for scanning the source code mobile applications, uh, open source and dynamic scanning. So guys, let's dive into it.
com because of what became DevSecOps. I thought DevOps was gonna give us a chance to do security better, to correct a lot of mistakes that I had seen, you know, in my years in security. Uh, we didn't call it DevSecOps.
Truthfully, it was rugged DevOps. I remember the fights I had with people in security and the people in DevOps because there is no, there's just one DevOps, you don't need a second there. You don't need biz in there.
You don't need anything. The security people said, ah, you know, yeah, it, it should be SEC DevOps, because isn't security first always. Um, and then we, you know, this whole idea of shift left, and I was, I was so gung ho for sh shift left.
I believed in shift left from the bottom of my heart. And it, and it, you know what? Over the years caught on DevSecOps became a real thing.
Most of the DevOps companies considered themselves DevSecOps companies. We shifted left and we shifted, left some more, and we even went a little further left, and some began to question, did we go too far left? Is it really working?
Maybe we should shift right? Shift up, shift down, shift everywhere. We still need better security.
Kate, if you don't mind, I'm gonna ask you to kick us off here. Yeah. Did we shift too far?
Left? What shift left the right move? You know, one of the problems that I, I, I feel like we continue to have is that it, I think originally it was a good idea to shift left because the people who were coming out of, um, school, they, we just weren't, it wasn't being taught.
So we had to start somewhere in this and shifting left and trying to add security because we were being hit. I mean, I still remember, you know, the SQL injection attacks in, you know, 2003, 2004. I mean, it, it was, it, it was taken us by surprise, right?
And I think at the end of the day though, we still, you know, we became cybersecurity people became these roadblocks and to business and to the dev people. And, and we were really putting a lot on application teams when they weren't security people at the end of the day. So I, I think we did go too far, um, to the left.
And I, and I think that we didn't work together. We put a burden on them, but we didn't lift a burden and we didn't share that burden going forward. So I think it's better that we are starting to look and, and create this culture of, let's really take a look at this because we all want, um, we all wanna do it safely.
I mean, at the end of the day, you know, it, it's, we have to be better at working as a team. Yes. The team Thing are Greer Go ahead.
The team thing. Yeah. Yeah.
That, that team thing is so important because, you know, it's, you know, I, I was doing software configuration management in the late nineties all through the early two thousands. And I never even talked about security. I never even heard about it.
I just thought security was something was done behind the other, the, the curtain oz was back there dealing with security, and we didn't have a discussion about it. There was, there really wasn't any, any tooling to add to anything that we were doing that would improve security. So shifting left was, uh, a, a shock when suddenly we were told, oh, the development team and your, um, your, your SCM at the time needs to have more security in it.
We were like, well, what kind, what do we need to do? Yeah. And in fact, that was the first time we started looking at, uh, what they call software de bloating now, um, to shrink what libraries we were pulling in it in a shared library environment to try to minimize the amount of libraries that we were bringing in so that we could do better security on the, on the binaries that we had.
So it didn't have so many executable, uh, functions in it. So, you know, it's interesting that you say the team part. 'cause I think that's where we got caught up in the beginning and suddenly it was securities got oz, but then you're gonna have to shift it over to the, to the, the munchkins to get the work done.
And we didn't know what to do. Yeah, yeah. It really wasn't being taught.
No, not at all. It was security was not taught to developers. That's for sure.
You have computer site reemer, you know, the voice of DevOps here. Shift left was such an important piece of it for me. What about you?
It is still an important piece, but what I feel in today's AI era, it is shifting, uh, from a personality perspective, which is basically having more, uh, and new components of, you know, how to integrate security when you are looking at the development stack, because a lot of developers are using AI and AI native tools to kind of in, you know, build code and, you know, also develop and review and test and deploy code, right? So there are new types of security, uh, you know, is required and new, new type of security vulnerabilities are introduced in the code itself. So shift left is changing, and, uh, obviously, uh, there is a lot of upskilling required in that dimension.
And why runtime security is important. I'll put some facts on the table so that, uh, you know, we understand the urgency of it. Uh, there was a report from Checkpoint, which says that, uh, every prompt, which we do, uh, one out of 80 prompts are posing higher risk of, uh, sensitive data leakage, a hundred compromised AI models.
Uh, were deployed into hugging face platform, which is basically for a lot of people who are using it. And there is dark LLM, you know, the malicious modification of AI models, for example, is happening as we speak. So if you think about this shifting left had reduced the vulnerability problem by 70%, right?
30% was still runtime security gaps, which we were finding. But now with the injection reduction of AI into various, uh, SDLC lifecycle phases, it becomes more urgent to ensure not, we don't look at only runtime security, but also looking at shifting left and seeing what kind of new vulnerabilities are getting added through a AI injection. I can talk a little bit more about it, but I think from a community point of view, we are seeing a lot of these things which are, which needs upscaling.
And, uh, I mean, this is a bad news that, you know, uh, we don't have enough talent. We don't have, uh, enough education and awareness in this dimension. And where there, where the communities like this, uh, what we drive come handy and we foster that collaboration.
Excellent. Gima, excellent Jack Trait thoughts? Well, I, I may, I don't know if I'll be call it controversial, but I have a slightly different opinion, which is really embrace the power of, and rather than, or which is, I think we need both shift left and shift, right?
Which, you know, defense in depth, right? We are having different types of controls at different points in the process and in the life cycle of the application to solve different problems. Shift left is really, you know, Kate talked about it not teaching cybersecurity to, you know, early engineers, but even senior engineers who know about cybersecurity don't address cybersecurity because functionality, feature functionality and schedule is the most important things to the company, not security.
And so we, that's how we measure our developers and our development lifecycle, right? So Shift left is a way to introduce cybersecurity into that conversation, to bring it level of importance up so it gets addressed as quickly as possible. That doesn't necessarily make it sufficient to protect our applications.
We also need security shifted, right? To do more at runtime, to catch things that can't be caught at the early stages of development lifecycle Fair. Trey, you're talking to real life customers, users.
What, what's your view on this Shift? Left is very important. I think the problem, the problem resides when security then offloads their responsibilities onto the developers.
And the developers then decide what security tools they want to use because of ease of use. Not necessarily this tool is better than the other. I've seen a lot of that issues where developers then have a lot of power to dictate what security tools will be used, but they don't really have metrics of why other than, oh, this, this works really good in my IDE as far as easibility, but what security checks are in place.
I see a lot of that. Um, now with these AI tools, it's gonna be up to security to continue to research and understand these vulnerabilities. I think it, for me, my background was, I was a developer before I became a security analyst, before I became a security consultant.
So I'm kind of able to have a conversation at a lower level rather than just, Hey, go fix this because the report says, so that I think is a lot where there is contention between developers and security analysts. 'cause the first thing a developer will say, okay, can you tell me why? Or do you, my, my application works like this.
Why is this a vulnerability? You can't just say, it's only in the report, go fix it. You have to go on that other level.
Um, so that's where security is gonna have to continue to do their work, their research, their efforts. And I see AI as a complimentary tool. Um, the problem I see on the development side, if it continues to go down this path, is this whole thing with open source, right?
You have something in your code that you did not create. You don't have a good understanding of it. And if you're just going to use these AI tools to generate an application, you're not gonna have a good understanding.
And you're probably have a lot of loaded code for functionality you didn't even need to utilize. So that's where organization's gonna have to lock down what tools that they allow Code. Let's about, you have Insecure code.
Go ahead, chase. Go. I'm sorry.
Let's Talk about, let's talk about tools for a minute. So I just spent the last week we have the, at the CD foundation. Kate and I are on a, a special interest group called the CICD cybersecurity, um, sig.
And we have a deliverable, so I, I gave up this last week to start working on looking at tools and how they fit within the secure software development framework. And I'm not gonna say AI's out there, and it's gonna probably change the way we do things, but there are so many tools today. I am, I was shocked by the number of open source tools that have been delivered to the industry that I know we're not, we're not using yet.
Not everybody's using 'em or taking them serious. It it just look at the problem with generating SBOs. Not everybody generates an sbo, one of the core components of your secure pipeline.
So we have to remember that while we have this shift left discussion, and many of these tools are on the left side of the house, there's also many that the platform engineering teams are gonna start using that are sort of squished to the middle. Yeah. And the, and many of those ones in the middle are, are actually starting to monitor what's happening in production.
So maybe we've come to a place where we're shifting, um, we're shifting a, a lot of tooling into the middle that catches things as it's coming through the pipeline, if they're adding it, and it's starting to monitor what's happening in production. I really was surprised by the number of open source tools and the, and the security features that these tools offer that can fit today without any ai, without any new, new tooling to solve some of these problems. Um, and I, you know, I hope when this document gets out that people can use it as a research tool because it is shocking.
I mean, I, I was thinking I'd have five or six tools per category, and I'm looking at 25, 30 tools per category. Wow. All of 'em doing something a little different and solving the problem in a different way.
But they do relate specifically to the challenges that have been brought up in this, in the secure software development framework. And it's a really good guideline to use that framework because it gives you a real, a clear indication of what your goals are, but it doesn't tell you how to solve them. So what we were trying to do is say, here are the tools that will solve these.
And I were shocked. I was really shocked. It's taken me all week to get just a few of these pages done, because there's so many tools and sorting out what they do to fit that has been a challenge.
So I'm hoping this helps. I really do, because we don't need to wait for AI to solve the problem. There are tools out there that can do it today.
Yeah. Yeah. And, and true.
I love it. I think you used a key word, um, platform engineering this idea about that, right? It does come to that middle.
It, it, it really, um, I think it's a perfect word to that encompasses, um, everything that we're talking about from the shifting left to the, you know, runtime application protection. It, it, it gives this whole more of a holistic view. And I think where organizations are, are moving and it's better.
Um, I do wanna address quickly, if you don't mind, uh, with Jack this defense in depth. You know, it's something from a strategy point of view that I have seen that really isn't working. And the reason being is that it almost creates more of this whack-a-mole type of strategy where you get a, a vulnerability and you get a tool and you hit it.
I think in what we are trying to work on, um, with, with Tracy, um, is more of this holistic type of picture and a strategy that is more proactive instead of like a proactive offense, more so than a strategic, um, defense, which is different when you think about it. You know, you still need to have an offense strategy. It doesn't mean that we are going to attack.
It just means that we're setting ourselves up in a position that we understand, hey, a heavy hitter is coming to, um, to hit, are we gonna be all in the infield or are we gonna go to the, you know, off field and get ready? Because we understand that it's coming. We know the threats, we understand the attacks.
There really isn't anything new, even with I ai, there's still the same attacks. We know this. And, and so, um, with the tools that are out there, some phenomenal tools like Tracy is saying, it's, it's, it's, it's such a beautiful time to be a part of cybersecurity.
I, I, I'll, I'll tell you, I don't disagree with you at all. I highlight defense in depth more to highlight that a single tool is not a silver bullet, right? That we are not that simply doing shift left and doing static code analysis or dynamic code analysis or whatever your shift left or combination of shift left tools is gonna give you, isn't going to solve or, or provide you perfect security.
Right? And I think you mentioned in the word word holistic, which is right, is that we want to think about the entire gamut of everything from the very start of the project architecting security into the design, through the coding phase, through the test phase, through the deployment phase, through runtime, and then even how do you end of life the product and how do you secure, right? Yeah.
And what do you do with the data at the end? It's an entire picture and there's an entire set of problems. And one tool or one small set of tools shifting left is not going to solve our problems.
So I'd like to people to think about it as, and, and I, I appreciate the, the, the, the analogy of whack-a-mole we do in cybersecurity, spend a huge amount of time doing whack-a-mole, which is, I believe the wrong way to do it. And I think the right way to do it is say that we have seen these problems in a slightly different domain. AI is a brand new domain, but it is still a data leak problem, right?
And how do we treat daily problems and can we, uh, uh, repurpose tools or apply the same tools as Tracy said, where you said there's hundreds and hundreds of tools. How do we use these tools to solve that problem without saying, oh, we have to wait for ai. Yeah.
I I would also like to shift this discussion to around time security. And you know, of, of course, there's a majority of work which is needed to be done in terms of, you know, securing the legacy or securing the as is or status quo situation. For a lot of organizations, you know, there's a maturity curve.
So a lot of organizations are already behind, right? So the 70% of vulnerabilities, which can be found through injecting security through shift left is not already happening. So that addresses or caters to that.
But if you think about runtime security and why it is becoming more and more important, and the CXOs have a shorter runway of 36 months to prove this, because AI is coming, and I'll highlight three points. LLMs, you know, you, like it or not, developers have started to use LLMs in many shapes and forms. So the LLMs are creating code, right?
The second part is prompts. So we all use prompts, right? And if you think about what tasks software engineers are accomplishing through prompts, there are many, right?
So test case generation, for example, uh, has a high kind of volume where, you know, people are generating, uh, test cases through prompt engineering, right? So, uh, the third aspect is AI agents, you know, if you like it or not, the AI agents are coming in the operation stack as well, and they're using LLMs. So for these three special components, which AI is bringing, we need a special, uh, security mindset.
We need to have, you know, specialized components and security guardrails to not to inject malicious code, for example, uh, data poisoning through prompt injections. Even AI agents, they are playing a, uh, a bigger role because a lot of autonomy and decision making is happening through AI agents. So it is more and more important that, uh, people start to invest in runtime security.
Uh, I don't disagree at all. I, you know what, I, I like the term shift everywhere. I, and I, it's not my term, actually.
I first heard it from my friend Jeff Williams from Contrast Security, right? But certainly we've gotta shift left, but we can't expect our developers to become security pros, right? As Rey said, they're going to, they're going to lowest common denominate a least path of least resistance, whatever one's easier for them, whether it's good security or not, it's something, but we do need to have runtime controls.
We need to remember that security doesn't end at the deploy button, or we don't actually press a button for Deploy anymore, do we? But it doesn't end at the deploy that, that mission continues as well. And, and so it, I would like to see a holistic security view of, you know, throughout that, the life cycle, not just of software development, but of software operations, right?
Observability and security is, is something we haven't talked on here, but that needs to be part of this as well. Um, I, you know, we, security's important, and no matter who you talk to, I think no one says, ah, security's not really important. We all say it's important, but we can't just focus on the security over here, or the security over there, or at this stage or that stage.
Every stage needs security. And I, I think the, one of the problems with security left is we took our eye off the ball of right. And runtime and, and these other, these other places, um, Uh, you know, being a, you know, I wanna, I wanna, I wanna disagree with that statement just for a minute.
Go ahead. Because, you know, if you look at what the open SSF has done, which I work with quite often, and they talk about security all the time, there has been a quite a bit of work done on trying to create that holistic view. That's why I'm gonna push again, if you have not read the SSDF, this is a, this is a, a reminder to do that because the goal was to create that holistic view, and there has been a ton of work on creating that holistic view.
So read the SSDF because it's, that's what that is. I I will and I should. And, and Tracy and Kate, when you guys do finish this deliverable here from the, uh, CDF, I'd love to have it either on one of our tech strong properties.
Let's get you both on, and, and, you know, shine a light on it because it sounds interesting. October, I actually, we have in October. October, alright, I'm marking it down.
Trey, I feel like we haven't heard enough from you on this. What are you, what are you making of this discussion? No, absolutely.
With runtime, right? You have no, you have an idea of how your application should run when it's under a load, when users are actually actively using your application. But there's always that use case, and sometimes it only takes one to break your application or have data leak.
That's why it is important. It's not important. It's important to have these tools, right?
But it's also, why do we have these tools, observability, what are we doing with that data? Who's managing that data? If a tool is fading, failing, what is the corrective action, right?
It's all these things you just can't throw. And like, uh, Tracy was saying, there's so many tools out there. How do we actually, um, identify the ones that are correct for our use case?
There could be a tool that's gonna be great for one company, does not mean it's gonna be great for our company or our application. So that's where a lot of that research does have to come into play. Um, and having information on the log injection, how is the host running?
All of that is important, of course, after the development phase. But if we can do that in every phase development static, well, static analysis, dynamic analysis, how is it running that is gonna give the holistic view, but sometimes I see is there's so much on dev teams to do almost all of that. And they're great at developing code now you're forcing them to put another hat on, another hat on.
And in my role in the past, because I'm a jack of all trades, I enjoy learning things, but I'm not ne I necessarily did not have teammates that had that same, uh, go get it mindset. And then you feel like you're ha my last name. Like you're on an island all by yourself.
Um, Yeah. And, and there is that, that we need I'm sorry, go chase. I have one, one, I it based on what Trey just said, something came to mind what companies can do to start understanding their gaps in their shift everywhere approach is they, like we, we did in chaos engineering, we need to start doing game days where a, a fictional, you know, software supply chain, CVE, that's critical or high risk is floating out there in your live environments.
Watch to see how long it takes your team to respond to it. What is your meantime to remediation? Those are the kinds of things that organizations should start looking at.
Uh, because I'm, right now it's over a hundred days. We've gotta get it down to less than 15, less than 10 would be good because it only takes 10 to exploit. But we ha we are over a hundred days folks, and that doesn't work.
So game days would be a really important, um, exercise for your team to start practicing because it means every single person in the organization from developers who have to recreate the, the new palm files all the way out to the deployments have to, that that whole, that whole cycle has, has to be hit when there's one vulnerability that has to be fixed. Agreed. Hey, Jack, I'm sorry.
Go ahead, Kate. Oh, I, I was just gonna say, I'll, I'll back to Jack. Go.
So, um, so quickly, the only thing that I'll, I'll add is that, you know, it's not as bad as it was meaning, um, you know, when we used to go talk to application teams, there used to be like, you know, what are we talking about? Like, you have no, I like, and there was such a pushback. You don't see that today.
Today. You actually have people who are interested and, um, who are concerned and still feeling overwhelmed by, by all the different tools that are out there. And I, and I think, um, and, and I believe the way that Tracy, you know, broke things down very easily, um, within this deliverable, I, I believe that it will help.
But making it simple, I think will, will go a long way into making SAC important in DevSecOps. Go ahead, Jack. I'm sorry, I I don't disagree.
Jack, when you talk to consultative clients, right? Analyst service, do they take this? Do they ask, do they want a holistic approach that shift everywhere?
Or do they focus in on a particular stop along the SDLC? I think they, right now, vendors are primarily focused on a particular stop along the SDLC because they perceive that as a way to market and sell. Not that that's what's really needed.
And something that Kate sort of said resonated with me. Part of what I see and what I bring back to vendors is when I talk to practitioners, they complain that the security tools are built for security people, not for developers, right? When, when I was a, early on in my engineering career, I started out as a software engineer, and then I went and started developing chips.
And one of my mentors in the chip development space said, well, all the code you wrote for the chip will work, but you write it like a software guy, not like a hardware guy would. And it took me a long time to figure out what that meant. And it's really you, the way people do things and operate in DevOps is a different mindset comes out.
You start with different assumptions, different perceptions than you do with when you start out as a security person. And think about it as a security person, I think the security tool developers need to put themselves in the position of the practitioners and have people like Trey with them who can represent the practitioner point of view and say, this is how we really use that type of tool in our environment. Build it for us, not build it for you.
And I think that will really help Build it for us, not for you. I think that's a great place where we call pull the plug on this, Jack. It's a good, good way to end it.
Build it for them, not for you. Kate, Tracy Reem, or Jack Trey, thank you all so much for joining us. We, we try to keep these to a half hour.
We're a little over, but we're close. Many thanks to OpenText for their sponsorship of this and all they contribute, so we appreciate it. Many thanks for you to you guys for watching.
We'll be back in another two weeks with another Control alt Deploy, and we might be doing some more live round tables where you can take part in them as well. So stay tuned for that, that until then, for Control, alt Deploy and techstrong, Ms. Allen Semmel, we're out Running enterprise applications in production is a lot different from the AI experiments many of us have been involved with so far.
This episode of the Tech Field Day podcast recorded prior to NetApp Insight 2025 features Ingo Fuchs from NetApp, along with Gina Rosenthal and Glenn Decker, and myself, Steven FoST, talking about how enterprises are bringing AI applications to production. Welcome to the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about key concepts in the industry. This podcast features a variety of perspectives from members of the Tech Field Day community, including delegates and presenters.
And this episode is recorded in association with our attendance at NetApp Insight 2025, which is on October 14th. Tech Field Day is part of the Futurum Group, and this podcast is also published by our sister company Techstrong tv. In this episode, we look ahead to NetApp Insight and are discussing the many ways that companies are moving enterprise AI applications from experiments to production.
But before we start that conversation, let's meet who's on the panel today. Hi Steven and team, very nice to be, uh, here with you today as we're getting ready for the amazing insight event. My name is Ingo Fuchs and I'm the Chief technologist for AI at NetApp.
And I'm Glen Decker. I am a global principal technologist at Equinix. Uh, I kind of oversee pre-sales, uh, strategy for our, uh, enterprise storage and, uh, data strategy, uh, for our, our customers.
Um, and, uh, look forward to the conversation. Hey there, I'm Gina Rosenthal and I'm a fractional product marketing, um, expert. And I work with lots of B2B companies that are doing AI for their customers.
And I am Steven Foskett, the organizer of Tech Field Day, and I am thrilled to be attending NetApp Insight once again with all of the folks on this panel. And, uh, also of course, this is a topic that's near and dear to me. Uh, we recently launched our utilizing tech, uh, season nine, which is focused on agentic AI applications.
Uh, we've been talking about this on the, uh, tech Field Day podcast, and of course on the rundown in the Textron gang as well. And I think that the topic of today's conversation is something that we've all been talking around quite a lot, and that is that as we move from playing around and experimenting with AI to actual AI powered applications, we're opening up a whole new world of requirements in terms of data protection, uh, data classification, making sure that things are really production ready. Ingo, I wanna start with you because I know that you work with your clients on this exact topic on a regular basis.
What are the real production enterprise requirements for AI applications? Yeah, I think I, I always like to start by talking about data, right? Because data fuels AI very obviously, right?
So you need electricity and you need data. Um, so to drive your AI data pipelines and, and build your AI factories. And so when it comes to data, there are really five questions that I always like to ask, um, when, when we're having these conversations.
One is, do you know where your data is that you want to use for AI workflows? That's where it all starts, right? And that could be on premises in many different locations.
That can be in the cloud, that can be hosted clouds, that can be sovereign clouds, that can be neo clouds, which are these new GPU clouds. So data can be all over the place, including shadow ai, right? So a lot of customers that start their AI experiments, they built a little silo over on the side.
They put like a singular workflow on there. They have a data scientist work on it, maybe data engineer or two, but it's relatively small in scale. And things that work in the silo may not work the same once you go global.
So where is your data is kind of the first question. The second question that I always like to ask is, what is in your data? So do you actually know what you have in that data?
Can you classify that data? Is there personally identifiable information in there? Is there credit card data in there?
You know, some critical data that you absolutely cannot let move through the data pipeline to an agent or to a chat bot. 'cause if you don't let the customer credit data, credit card information even get to the agent, then you don't have to worry about restricting the agent from giving that information out. So you, if you stop that data from getting into the pipeline, that's the right time when you want to stop that data that you don't want to get out.
So where is your data? What is your data? There's a lot of conversation about structured versus unstructured data because in ai, most of the data that flows into AI workloads, it's unstructured data.
So now you would need to put a structure over that data, which is really what vectorization and embeddings are about. And then you end up with this vector database load, you might need 10 x the capacity of your original data just to build the structure just to do your embedding some vectorization. So that's critical.
That's number three. Number four is your data current. A lot of customers have data all over the place.
And to find out whether or not this data has been updated is a complex and costly project. And you may only wanna do this once a day, once a week, once a month, once a quarter, depending on the complexity of your environment and how much compute and networking and other capabilities you have. But now, if you have, let's say a customer service chat bot that's operating on data that's a month old, it's not gonna be very useful.
And then finally, and maybe most importantly, is the data appropriate and ethical for your workflows. So it may be legal, but it is, is it ethical? Is it in line with how you want your organization to be seen by your clients and by your customers?
So you have, you may have a lot of really deep insights into your customers, but if you start make, making pricing decisions or other decisions based on that, is that gonna cause some negative perception in your customer base? So it may be completely legal to use certain data, but is it ethical? Is it appropriate?
Is it in line with the kind of morals that you wanna put out there about your organization? So those are kind of the five questions that always start the conversation with, which has nothing to do with infrastructure, but infrastructure helps tremendously in solving some of these challenges. Yeah, I, I would look at these five questions and you know, I I, I, after digesting them, um, none of them have easy answers, right?
And, uh, and of course, infrastructure doesn't solve any of those questions directly, right? The, there, these are things that must be dealt with by AI centers of, of excellences in, in the enterprise and, and executives, and not just data scientists, but lines of business and, and of course lines of business is where are, where all of the, uh, AI workloads seem to be starting these days. But, uh, you know, for instance, like where is that data?
Uh, that data could be, uh, you know, all spread out through your global organization. A lot of it could be in SaaS platforms that aren't even within your perimeter, right? And you have to somehow get that all in.
Um, and you know, what we're finding is that, uh, many times once customers try to start AI and, you know, endeavors, they'll go and do it in the cloud. 'cause it's easier to start doing something with synthetic data or small data sets that aren't represented of the full production workload. And then, uh, when they go and bring it to try to get it to pilot even or to production, all of a sudden, whoops, can't, can't do it that easily.
I gotta go pull in all those data sources. I gotta do curation, I gotta do duplication, gotta do all these things. So, uh, so, but what we're finding is that, um, you do need to, to, to deal with that data very, very early on as you've first determined your use cases and you're doing data discovery, which is in and of itself is a huge project, huge project, uh, project.
But there is value in consolidating at least one copy of that data, um, I'll call it, on equipment you control and locations you can access, right? So that from a compliance perspective, which goes to your fifth question, I think you, you also have to add in governance and compliance to, to, uh, appropriateness and ethicality, right? 'cause that's honestly the way the world works.
And the diff, you know, with GDPR Cloud Act, all these different things going on, the AI act there, there's a lot of constraints on what you can do with this data. So, um, bringing at least one copy of that data onto stuff that's totally under your control, which you then can now move to clouds and neo clouds, as you're talking about that data mobility, that ability to, to take that data that you've got and do what you want with it, when you want with it, it's gonna be key because you have no idea what your future AI life is going to look like. So if that's the case, then you must build in this ability to change, right?
And so the ability to have data sets move from one platform to another in a common management framework in a common way of accessing, controlling, and governing, right? Um, I, I, I happen to know of about a company that does that, by the way, ing you may know them pretty well, but that facility coming first before you are even thinking about the broader impli implications of infrastructure, GPUs, right? Um, liquid cooling, all those kind of things.
The data is absolutely first, you're right. But you've gotta bring that data to, uh, in, in the first place. You need to build that kind of core where that data can sit, um, in, in a governed way where that's where your curation, your data duplication, and you can deal with all the five of the questions, at least the, the remaining four, what's in it structured versus unstructured, right?
Is it current, right? And then deal with the, with the governance and the compliance of that data. Those are the other four questions.
So to answer, for an organization to answer question number one, it's in their best interest to discover, consolidate onto something physical and then get that data back out where you want to experiment with it. Yeah. And I would, I would expand on that a little bit.
Uh, is that, so this really leads to this idea of unified data model where all of your data is seen in a singular model, and then you can apply your applications against that. Similar to what you described Glen. And, and part of that is because a lot of times there might be this new groundbreaking model or a new groundbreaking application, or you choose a vendor to, um, apply their chat bots against your data instead of building them your own.
We see a lot of statistics that using off the shelves, AI applications, typically majority of cases, cases today, leads to better production outcomes than trying to do it all yourself. It's, so it often is kind of a mixture of things. But let's say you have a public cloud provider that comes out with this new application that you want to apply to your data, and some of the data might sit in that same cloud, might sit in different cloud, might sit on premises.
How can you build a peering model or a caching model or data transfer model that gives you the most efficient way to apply these applications against the data that you have, regardless of where it is? So for me, that's all a question about this unified data model that spans all of your different deployment locations and infrastructures and sites and models to say, listen, you might have 80% of this data on premises, but 20% is in a cloud. And can you then peer to that cloud, or can you cache to that cloud just the amount of data that you want?
And then also not leave another copy behind. I think that is one of the biggest problems that we are seeing right now is that there are so many copies and nobody wants to throw anything away. A lot of companies have very strict rules about how long to keep things, but not very good policies about when to get rid of things.
Nobody wants to be at fault for having permanently removed data, and then suddenly somebody changes their mind. And so this unified data model can really help with that problem of just having this full view, like you described, about what data you have, where it is, um, and then where the applications are that should be looking at this data and using this data. I think it's really interesting, everything y'all have said so far is just data center hygiene.
It's not even data center hygiene, it is application hygiene. So I think everybody has raced to, to juice their ideas and to put those ideas, um, to work and find a way to make them work with different, um, architectures and models and different, um, ways of doing things. But now all of a sudden it's like, hey, yeah, how do we, like you were saying in the beginning, how do we make this, uh, enterprise ready?
How do we make this production ready? And I think that's where, just from clients that I've been working with, people find out, oh, we really don't have the data the right way, or we don't, we have everything, every place. Or we went and we purchased a bunch of infrastructure and it's not going to suit the purpose of this application.
What do we do? So I think one thing I'm really looking forward to hearing about at NetApp is to hear these CU customers, like be able to talk to customers and hear more about, uh, the transition plans that they have, or kind of the gotcha moments they, they hear, because this, we repeat this every cycle. We do something new.
We were talking about that earlier, whether it's cloud computing, I can remember a lot of this 'cause I was a cisman going from, from whatever to when Linux, well, from Solaris to Linux. Like all of those applications had to be rewritten and why, you know, so it's kind of like the same kind of, it kind of thing is before, but it always goes back to let's be computer scientist and let's remember what are we building and why are we building, and then what is the correct application for it? And we have so many new things that we can do.
Like, so having a unified namespace or unified area where you can see all of the data where it is and maybe be able to use that at one time for one, um, purpose is, is really kind of mind blowing when you think back across 30 years of, of computing that that's even possible to do. It's pretty amazing. So I'm, I'm looking forward to seeing how your customers are doing that and how you guys are actually supporting them.
It's gonna be kind of cool. Yeah, I think that the also, you know, when you, when you have that, the, the enterprise data that's been, that, that, that runs throughout an organization and, um, you've, you've now created this, this, this factory and, and the first kind of station in the AI factory is of course the data pipeline, right? Um, that and things just changing so fast in this field that the needs of data and from a performance, from a, uh, uh, just a retention perspective are, are changing, um, so fast.
And, and companies don't know what AI is gonna look like in in another year or two. Uh, it's most of the time. And, and we've seen up till now.
And, and, and you know, some of the things you've said imply this, right? That, you know, enterprises are gonna try to pull down existing models, um, or, you know, use commercial models, uh, perhaps and, and just try to use rag against them with vector databases. And that was kind of, I'll, I'll say that was the first or second wave of the ai, you know, folks that are coming out, we're already seeing that.
Um, you know, not all rag is vector databases, right? There's a lot of, especially as you now to bring ag agentic, right? Ag agentic is the next wave.
And AG agentic really implies things talking to things in an automated way, everywhere, uh, data, I mean the, the amount of compliance and governance, uh, uh, and security concerns that, that, that arise from just the, the explosion of this, uh, it's kind of mind boggling. Um, companies don't know if they're gonna be maybe dabbling into some fine tuning smaller models, expert models, right? That all, all cont uh, are contingent upon the data being ready for all of these possible different use cases that you have no idea if you're gonna need to go use it next year, two years, three years.
And, and so keeping data in, in any tier, whether it's, you know, in, in checkpoints, I mean, even now with the reasoning models, making things even worse because now, um, we see, uh, KV cache being stored as a state, an intermediate state that can be sent to the edge and used in real time for high performance inference at the edge, um, that also requires high speed storage. It also requires data motion capabilities, consistent data motion capabilities. It's just like all of these things have come out in the last 18 months and no one has had time to digest all this stuff.
The rate of change is only accelerating, ironically, being accelerated by AI itself, right? And, and our use of it. So it's like, uh, the thing you need first is to make sure the data platform that hosts all this stuff is gonna be able to accommodate this rate of change with you as you go and figure out this new stuff.
Because as you get to production, um, you need something that's gonna grow with you and be able to scale on a specific use case that you may not even know you're gonna do for another two years. See, I'm hoping the next wave is people are actually gonna take a breath and take a beat and figure out how to do this in the appropriate way so they can move from, um, science experiments to production. Oh, I, I hope with you, I'm not, I'm not so sure it's gonna happen, but I think it has to happen.
And that's the thing, I think that that is interesting about going to something like NetApp Insight where you have like real enterprise people trying to do real enterprise things as opposed to a lot of this breathless AI hype stuff that we get exposed to on a daily basis. Like the people that go to Insight and the people that are NetApp customers, they're not interested in hype, they're interested in building a Yeah. Supportable, profitable, you know, productive enterprise application.
And so for me, when I go to an event like that, it's talking to people who are really doing this stuff and learning from them. Like, what were the challenges? And I think that that's the most interesting thing that Ingo, uh, brought up is that, um, it, it doesn't start with GPUs and models.
It starts with data, right? Yeah. It, it really does.
And I think, um, all of your points are really, really valid. And, uh, I wish we had like six hours on this podcast to go into how we're going to move from file and block protocols to semantic understanding of data and how you just talk in conversationally with your storage system in the future and, and how all of that is changing. But, um, Steven, to your points, I think a lot of the conversations that I have had with customers over the, the last, you know, year or two we're really focused on, oh, ransomware attacks are now powered by ai, how I'm going to protect from that, you know, oh, now I need AI powered ransomware protection to protect me from that.
Now I have AI workloads and, and pipelines that are sharing the same infrastructure as my, all of my other Oracle sql, all of my other workloads that I have in my enterprise today. So suddenly this old conversation about secure multi-tenancy is a core conversation. Again, how and quality of service, if somebody were to introduce a rogue agent into my shared infrastructure, can this rogue agent take down my other production application that I rely on that are actually producing things in a physical factory?
Can my AI factory take down my physical factory, right? So there's just, you know, how do you peaceful coexist with the infrastructure that your business rely on today while you're building applications for your next competitive advantage that ultimately run on the same infrastructure unless you do wanna build a separate data center. Gina and I talked about exactly this two episodes ago on the Tech Field day podcast, and we are a hundred percent in agreement in alignment with you on this.
Definitely. Absolutely. And so it's, I just find, um, there's a little bit of a translation layer, and I've seen it with cloud, I've seen it with DevOps and containers the same, uh, thing.
And I think, Gina, you talked about Linux, how Linux became an enterprise class operating system, and, uh, production applications running on it is starting with web service, right? Which is really kind of important, you know, aspect of an enterprise environment. And so, um, we need to, I think all of us in this industry need to do a better job at translating the language of what AI practitioners are looking for and, and map that to the things that IT practitioners understand the value of snapshots, the values of efficient mirroring the values of data deduplication, and, uh, protecting from copy sprawl, uh, efficient data protection, peering into the cloud, caching into the cloud, and back from the cloud.
All things that people have really figured out over decades. But we are all using our language. And then AI practitioners usually use a different language, and we almost need a little bit of that translation layer to say like, this is not a brand new thing that you have to build.
This is something that companies have figured out in the past. We can apply these experiences, especially for production. And what that will help us achieve is that we go away from this, you know, making decisions based on milliseconds and iops and, you know, how many agent requests can I transact per second into, oh, my data scientists can be productive three weeks faster, right?
If I have a data scientist sit around for three weeks, not doing anything, waiting for infrastructure to actually deliver data to the application, that is very, very bad, right? From a productivity perspective, if I can cut days or weeks out of these waiting periods, um, that is really ultimately making a huge difference. So I, I love that analogy so much.
And, um, I think you are absolutely spot on with, you know, our job has always been as operations people to support the business, and that this point in time, it's like, how do we support folks doing ai? How do we support the data scientists? How do we support everyone on that end?
Um, and that translations needed, I remember I started doing the translations for SaaS. I could show you some of my presentations I did when everybody laughed at me when I did them at operations, different type of operations shows. So I think, um, I'm, I'm looking forward to seeing how y'all are gonna do that translation when we get to Insight and, um, hopefully there's gonna be a lot of hands-on labs and stuff so we can actually get our hands dirty and do that too.
Absolutely. Yes, for sure. And, uh, we are building like some really great experiences.
Uh, it's specifically targeted at giving people with a strong storage background and, and, you know, the opportunity to expose themselves to, oh, this is what a data engineer is asking for and this is how I can help. This is what a data scientist is looking for at the end of the data. Data scientist wants to see your I to point an application at.
They don't wanna know what all the infrastructure is, where the data is coming from. They typically don't, don't care. The data engineer cares, right?
And so we wanna create some transparency there and expose the very storage focused audiences at insight to this is what a data engineer is asking for and why, and how you can help. And this is what a data scientist is asking for, and how your knowledge will help the data scientists and it'll make it practitioners just that much more relevant and important, uh, and it will make all of our customers that much more impactful and, and quicker, uh, to getting their AI factories up and running and be productive. Yeah, I think, I think though, we, we've all probably seen the MIT study that was talking about how, so ma you know, such a large percentage of of AI projects today are not producing the value that was anticipated, right?
And so, um, the, I think, and, and they're finding really was just that you're, you're going after the wrong things. And so the good news is that, and, and the folks usually see it inside of the kind of folks who are gonna be solving the back office, the, the productivity problems, not just the, the content marketing stuff that we've been, you know, that we've been enjoying over the past couple of years now, but now that I think organizations are gonna be focused on really producing true business outcomes that are gonna be visible on the bottom lines, right? I think you're gonna see a lot more folks in IT get a lot more knowledgeable on AI and, you know, all the constructs on, on what a neural network is, what is back propagation, right?
What, how does all this work? You know, what, what's an attention mechanism? They're gonna know you're gonna need to know this stuff.
And, um, then those same people are gonna be able to apply that knowledge back to their IT architecture, um, you know, their kind of schema that they kind of know because they're gonna, they're gonna be the ones who are gonna have to build the data fabrics of the future, right? They're the ones who are gonna have to build this distributed, whether it's in cloud, and it's gonna be, by the way, an end, not an OR in the, in the multi-cloud, in the, you know, on on-prem, multiple regions, right? Uh, out to the edge.
Um, and so that data platform is gonna be that, that, that thing that drives the success and, and all the repetitive outcomes out of AI that are gonna be, need to be generated. This isn't gonna be like you're going after two tr two things, take the win and go home. This is gonna be a repetitive, and, and every business is gonna be looking for more and more and more value out of ai.
And every, every time you do that, they're gonna be getting better. And that data platform is gonna become more and more important because now it's driving everything in the business that drives all the AI outcomes, all the models, all the tuning and rag, all that stuff starts with that data platform. So that's why it's just so imperative that people figure this out.
I, I absolutely agree, uh, with you and, and there is absolutely a lot of educational opportunity there, um, that, that we need to, you know, see through and offer. And in fact, we even offer NVIDIA certifications this year. So if for folks that are attending inside or have attended inside in the past, you know, you can all get all kinds of, you know, like NetApp certifications, et cetera.
You can even get certified on NVIDIA certifications, uh, at our conference. And it's reflecting exactly what you said is you can't just ignore ai. I mean, you can, but you know, if you would like to stay employed and be effective and have an impact, uh, in your organization, it's probably good idea to get up to speed on all these CI topics and how you as an IT specialist, a storage specialist, how you can make a really meaningful impact, uh, to your organization.
Yeah, I, I was actually gonna ask you about some of the recommendations, Ingo, that you have for Insight, um, if people are attending, and also for people joining remotely. Uh, I know that there's going to be some, uh, sessions including, by the way, I should point out Tech Field Day videos. We will be posting some Tech Field Day videos, uh, maybe featuring from some familiar spaces from this, uh, this here recording, um, after the, uh, shortly, shortly after NetApp Insight.
Um, what else? Uh, you know, is it too late for people to get involved? Uh, how can they come and join us, and are there opportunities to connect online?
Yeah, absolutely. I mean, uh, the, uh, the registrations are open for insight. Uh, we're still, uh, taking, uh, registrations.
It's getting tight, so, uh, sign up now. Um, but obviously for those of you that can't make it, uh, we have the, uh, we have the streams, especially for the main stage sessions, which I think will be very, very interesting. And I, I cannot tell you about some of the amazing speakers we're going to have.
Um, but certainly AI will be a very, very big topic, uh, at inside this year. And then yet, tech FTE will be able to really sit down and, and have some very in-depth and detailed conversations. Um, you know, Stephen, between your representatives and some key people here at NetApp, including, I believe we will have our chief data scientist, uh, there involved in one of the sessions.
And we have some really great engineering, uh, folks that will really provide a lot of the behind the curtain kind of details of how we have achieved the things that we have achieved, why we have made certain choices, and how this is really changing fundamentally how customers should think about infrastructure in the context of AI in production. And on that note, um, you know, I think that there's, there's definitely a lot coming from this. Uh, Gina Glenn, you're both attending with me.
I already said that my favorite part of events like Insight is talking to the customers that are there, uh, who have incredible experience. Another thing that I always look forward to is, uh, getting a chance to meet some of the incredible, um, sort of luminaries that companies bring in for these events, whether they're on stage or contributing. Uh, Gina, what do you look forward to at NetApp Insight, and what are you hoping to take away from it?
Uh, both of the things you said, I definitely wanna talk to customers. I really wanna see who's going to be on the show floor, the other vendors, and talk to them about how they're working with NetApp. I have a lot of friends that work at NetApp, so I'm, I'm very excited to catch up with people.
Um, sounds like I'm gonna be doing some hands-on labs and seeing some of these things that Ingo is talking about. Um, what I wanna take away from is I wanna see where customers are, number one. Like, where really are they?
Because I'm, I'm hearing from, you know, other, what some of my clients, hearing from them about what their customers are saying and what the problems are and how we're gonna, you know, from a marketing perspective, how do we work on that? And I'm also interested in hearing about, to talking to my friends who are on the marketing teams. Like what, how are you guys positioning things and how are you positioning, um, working with your partners and things like that.
So, Um, so, so Insight. Um, I've been going for quite a few years now, and, um, net NetApp kind of set the standard at Insight for technical content that they delivered in the sessions. Um, they, they, they tried to stay away from being too, uh, too salesy and, and, and tried to show you how things worked and got pretty down and dirty with stuff.
So the sessions, uh, you know, I'll try to consume as many of them as I can, uh, in, in especially those sessions that are demonstrating how NetApp is solving for outcomes in ai, right? How you're, how am I getting this data ready to be consumed by either, you know, inference through rag or for, you know, getting it ready and, and, uh, and, and getting it, um, you know, you know, curated and groomed for, uh, for training and tuning and things like that. So, uh, and, and also moving it around, uh, in that case, how, how is NetApp using its core strengths in data motion and consistency, um, to meet the needs of, of customers in a distributed AI world.
And so that, that, uh, has particular meaning to me in my role, but, uh, showing how that works. Insight's always been really good at, at getting to that how, right? Instead of just the what.
So that's what I'm looking forward to. Well, I'm glad that y'all are coming. I can't wait to see y'all there.
Um, those of you watching, again, watch the Tech Field Day Channel, watch the Techstrong TV app. You'll see a lot of great content there. Uh, before we go, uh, Ingo, Gina, Glenn, where can we connect with you and continue this conversation other than Las Vegas at Insight?
Mm-hmm. Yeah, well, insight and ideally at the bar, uh, would be preferred, but, uh, LinkedIn is, I'm on there. So LinkedIn is, is definitely a good way to get, get in touch with me.
Um, I'm also presenting at a lot of conferences. I was just in Berlin last week presenting at the EI and Quantum, uh, summit there and exploring some topics like, uh, uh, post quantum cryptography and how to get ready for the upcoming quantum threat, but that's a different conversation. Um, so that's, uh, certainly another way.
But yeah, LinkedIn is a, is a good way to get in touch. And I do, I try to post. Um, but, uh, frankly, it's, uh, I'm not posting anywhere near as often as I should.
You can find me on LinkedIn. That's the best place. Um, you can find me on LinkedIn.
Uh, that's a great, I do respond to messages there. com. And at the end of October, you can, uh, I'll be presenting at the, uh, Nvidia GTC DC Conference for Public Sector.
So catch me there. And, uh, NetApp, NetApp will be at GTC DC as well be able, will see who they're, Yeah, our boots aren't that far away from each other. com/insight.
There's a lot more information there, uh, to come in person or to connect online. So thank you all for joining us, and thank you for listening to this episode of The Tech Field, a podcast. If you enjoyed this discussion, please do give us a subscription on YouTube, um, or in your favorite podcast application so you don't miss an episode.
And do consider giving us a rating or a review. This podcast is brought to you by NetApp, as well as Tech Field Day, home of IT experts from across the enterprise, uh, part of the Futurum Group for upcoming episodes and, uh, more upcoming events. com/podcast, or you can view these videos on Techstrong tv.
Thank you so much for listening, and we'll see you next week.