AI and the Evolution of DevTools with DeployHub’s Brian Dawson at OSS Seattle 2024
Brian Dawson, with a diverse background spanning engineering at Sony PlayStation and blockchain ventures with Ripple, has returned to the DevOps space with DeployHub. Reflecting on his journey, he highlights significant shifts in developer tooling, including the rise of cloud-based development environments and the emergence of low-code and no-code solutions. Additionally, he notes the transformative impact of AI on the development process, particularly in aiding code generation and error detection, foreseeing a future where technology continues to democratize software development.
Transcript
This is Textron tv. Hi, everybody. We're gonna have a little bit of a different conversation here at the Open Source Summit.
You know what a great, what a great thing about these kind of conferences is, especially in this community that's very connected, is you get to reconnect with people. Sometimes you get to form new relationships. And Brian Dawson, who is with Deploy Hub, um, I've known through a couple different roles that you've played in the industry.
So I thought that it'd be good to, um, well, first of all, we'll get, get some background, let folks know your background and get a perspective on now you're stepping back in, in a big way, right? With what's that role, you know, what are you seeing happen? But let's first introduce yourself for the two people that didn't see you on some Techstrong event a few years ago or so.
Awesome. Great. No, Mitch, first, thanks for having me.
And, uh, you know, I always like being on with you. I'm just trying to, uh, have some of you rub off on me. Be Careful what you ask.
Okay. Okay. Um, but no, yeah, we've, over the years from being on site at, uh, the Jenkins conference or DevOps world to doing remote talks, we've had a lot of great conversations over the years.
We have, which I've sort of missed for the past year and a half or two years. Um, to your point, starting with background, you know, real quick, I, I started my career as an engineer, um, um, interestingly enough, 'cause it relates, um, I started, uh, in the first group of r and d and, and developer relations for Sony PlayStation. Oh, interesting.
So that was really my first introduction. That sounds fun. Opens.
It was an awesome, uh, a job. And I look back and reminisce on that all the time. Um, when I picture what a young, what, what impact a young engineer at a burgeoning company can now have on this b behemoth that is, uh, PlayStation.
Right. And, uh, I do like to think on a tangent. I was just having this conversation with someone else.
Look, a lot of us joined software engineering as engineers because we want to create, we want to innovate, and then we wanna sort of have, um, a contribution and a lasting impact. So, uh, that start to my career, I think, really underscored that. I started working with g New Free Software Foundation Tools.
That was our compiler set. Another thing I and many, many, many other people have used That. And, um, and that was my introduction to Nicks.
net, with CollabNet and Subversion, where in various roles I was heavily focused on, um, using open source to, uh, create tools that empower developers to, uh, better deliver. Um, and, um, where I think that really came to fruition, I think where we spent the most time together was, uh, in the number of years that I spent at, um, when we started, again, was another small company called CloudBees, which many people maybe know as the leading, uh, corporate sponsor of Jenkins, we're the creators of Jenkins. Uh, we're on our executive staff.
net. And, uh, we realized that to really, uh, deliver true impact with this set of tools and subversion, um, we needed to create a continuous integration and continuous delivery service continuum, cruise control, uh, were there, but they had just been supplanted by Jenkins. Mm-Hmm.
Um, so we built out that practice. Uh, and then I joined CloudBees just about the time that we saw the introduction of this word DevOps. And, uh, and spent a number of years there working with the internal teams, um, as well as externally evangelizing and, um, sort of informing people on DevOps best practices.
I feel like this is kind of a Rorschach test, or you're, you're trying to see if you could trigger me between Subversion and PlayStation Source Forge. Right. Isn't that always the case?
I'm always trying to take, Okay, what was, what was that like, turtle? What was that thing you installed versus Right, right, right. Okay.
Whatever. Right, right. But, um, yeah, so, um, so yeah, and then I guess to wrap it up, so I don't, so, um, fantastic time at CloudBees and then, uh, I landed a fantastic opportunity to come work at the Lennox Foundation.
Mm-Hmm. Um, where I got a chance to work with a fantastic group of people. Um, the people that put on this event, um, Chris EK was CNCF, watching the growth there.
And then, uh, sort of, uh, participate as we launched, uh, the open source software security foundation. Mm-Hmm mm-Hmm. Um, and we'll get back, I'll pause in a minute, but there's a story there that has led to me being back here today having the conversation.
Okay. So sometimes in your career, like, we have a path and we may like, oh, I'm gonna go try this for a while, or I'm gonna do this. And maybe not directly in the trajectory we were on.
Um, you went into, um, not Bitcoin, but Blockchain. Blockchain, that's what it was. Yes.
Okay. Why blockchain? What, what, what enticed you to say, you know what, this is kinda interesting.
I mean, obviously it's a lot of buzz about blockchain at the time That Yeah. Did that. Um, I, I, I, well, there's a fundamental thing I think we, we talked about a bit offline or, or maybe I just mentioned, is, um, I've always sort of, um, lived on, um, maybe not the bleeding edge, but the leading edge part of, uh, one of the reasons I started coding in the first place is I wanted to innovate.
I wanted to create Clearly all the things you've worked on. Right. I wanted to do, Had a lot of sustained impact.
Um, and I have a look, I left gaming to go to DevOps. 'cause I kind of felt like, um, uh, I was running the tools and technology team. I had grown up in the console game industry, and I'm a bit masochistic, maybe.
I decided, okay, let me see if I'm good at something else. So I jumped out. And so I think the move to blockchain was, it was this amazing leading edge, bleeding edge technology that really had the ability to change things.
I stayed out of it for years. I read the Satoshi White papers in 2011. I'm like, this is amazing.
The way I would describe it as, imagine that you have a globally shared, secure, immutable database, just this database that wraps around the world that anybody can access. What could be more open source and community oriented, Distributed, no one central point of control. Yes.
And, uh, but the downside of it is for me is kind of, um, the crypto culture that kind of took over the technology, right? Mm-Hmm. So I saw a great opportunity to try something new, go innovate, take a chance, um, with a respectable company called Ripple.
Um, and you know what? It was a fast, fantastic experience. In fact, one of the things we were able to do is connect to a project of which I'm on the governing board of the Ortel project.
And we are able to work with Ripple to create an implementation where we could store open source SBOs on the blockchain so that they would live there for perpetuity or perpetually. And at any given time, someone can take a hash from the package they have, go to the blockchain, and, uh, reliably, um, look at the SBO or the package manifest on that. So.
Brilliant. Um, so yeah, it was, it was A lot of connectedness what you've done, even though you went down the path of blockchain. Yeah.
I think I finally, you know, uh, I still have friends that go, Brian, what do you do? Um, so from the outside, it probably doesn't look, that's My mom asked me, is that what you do? No, that's not what, Well, at least your mom asked you.
My mom doesn't even ask. She stuck. But yeah.
So, um, so, uh, the time that we hadn't really been connecting, I stepped away from the DevOps space and the software delivery space. Um, I was spending about two years doing, uh, something similar in the Web3 and blockchain space. Mm-Hmm Mm-Hmm.
So was it TIUs and the being part of that, that kind of brought you back into this community? Or what was it that, that pulled you in said, Hmm, lemme go back. This maybe even come home a little bit to some of your roots first.
Uh, yeah. Generally, yes. But I'd say it starts with me being a masochist.
Oh, Back to the, uh, I, I should go try this again. I'm like, you know what, um, my salary's okay. The kids have graduated.
Things are pretty well, why don't I quit my job and have no money? I haven't, I haven't rolled the dice on that one, but, okay. I understand.
Um, it goes back to the, so, um, after the experience at Ripple, which it was great, I really, um, I spent a lot of time with a lot of startups, right. Helping small teams build everything from their business to their go-to market process. And I said, you know what?
I want to, um, go, uh, do that. Um, I had been on the Orillia board for about a year. Um, but then that also gave me an opportunity, uh, to join Deploy Hub as a co-founder Mm-Hmm.
And really take, again, combine someone of, I learned to get back into the DevOps space and go, bill, I will also say exhilarating, but unsettling to go into a space where I know absolutely nothing after about 15 or 20 years in, in this space, Uh, true. This, that does challenge a person. Yeah.
It is. It is. Uh, So let, let's take if, if you're okay.
I think one of the great things to be, to share with folks is while you aren't brand new to the community by any stretch, you've had a little bit of, of gap separation, if you will Mm-Hmm. Where you stepped away and things were in a certain state when you were heavily involved. Yeah.
Go work on some other stuff, decide to come back and reengage in this. Yeah. Wouldn't, what do you see happening?
What's the different, this thing? Is it, you know, same movie, same ending, or are we, we things have really kind of progressed in some areas you thought was really fascinating or maybe not. Yeah, I, it's all, it's a mix of all of the above.
Um, um, excited, surprised, disappointed, and I still think, um, I still have more to see. But, you know, right now it's think slicing across a couple of things. And I'd say I talk about, um, developer tooling, developer experiences, languages, et cetera.
Um, CI/CD and DevOps as a practice, um, AI are probably the primary three things where I see some changes. Mm-Hmm. Um, and then maybe if we get there, there's also a difference in kind of funding what's being funded and, you know, what businesses are getting a chance.
Um, I, I, I feel start starting with developer experience. I will tell you, um, even in just the past two years, and I would credit, uh, frankly, a lot of the GitHubs and GitLab of the world for really driving home and we know we have Cloud nine, et cetera. Um, um, accessible, easy to use cloud-based SaaS-based development environments, um, 'cause I'm looking at 'em now, um, uh, you know, going into my latter years and I'm seeing a lot of young developers, including my son and daughter that are computer science majors, and I'm watching how fast they're able to engage, pick things up, and start to actually generate product.
I saw that with the startups that I saw Web3, and I'm, I'm just trying to figure out, am I just dense? I mean, which the answer is maybe Yeah. What didn't I get back then that I seen happen?
Right. But what I'm seeing is, is that, um, the tool set and the tool suite available to these people that get going right away, um, creating code, um, executing logic, putting together stacks and delivering applications is unlike what, what we had Oh. When, when we were started The very much, to make an analogy, the rector set the, the Lego blocks.
We were doing a lot of assembling Yeah. Right. Of technology.
Yeah. You, you could even say using the GitLab, the GitHub cloud nine more of a platform approach, right? Yes.
That it isn't a closed system, but it does tie things together. Yes. In a very significant way.
You're not spending time doing integrations of tools and incompatibility issues and Yes. Oh, this library dependency, fun things. Dependency conflicts.
Yeah. And I always, I joke, 'cause I was going through this the other night with something and I go, oh my God, I remember, um, you know, why haven't coded in a while as things get busier. Like it's the environment set up.
I'm like, I actually just want to start to write code. I don't Want, how do we get busy now? Right.
Be busy that I can't get to what I want to Do now in that experience. The other thing that was really neat, which will go to one of my classic things that when asked to predict I mis predicted, um, is we're low code and no code solutions. Okay.
Got same. More. Yeah.
Uh, uh, flutter flow is something I'm working with now. Bubble, um, coming across people time and time again, and now using one to build a project myself, um, where you're beyond rapidly prototyping, you literally can sit down and, um, you know, if you have enough Celsius or caffeine in a day, you can deliver a full stack app with payment processing. I can, it's insane.
It's insane. I'm jealous Without developing. Well, yeah.
Yeah. My, my, uh, my younger brother and I are working on a project. He's been a lifelong product manager, um, has never been a coder, never took a coding class.
Um, he has built an entire application that we're getting ready to launch, uh, next week. Mm-Hmm. So it's impressive.
So that's you Essentially, a comment about that is my prediction. My sense is, uh, the next generation of low code, and especially no code is really AI generated code. Think about that.
That's Yes. Kind of the next handle. Now, it won't look like the platforms and the environments we're doing no code today.
It probably will look different. Yeah. May, maybe there'll be some simulators, I don't know.
But that seems to be our next No code. Think So. And actually you set up a good segue.
I hadn't thought All righty. Didn't plan that, But No, it was, um, yeah. Be, I, I I 'cause that again, it was my experience using code.
Uh, I'll try to hit this real quickly. I'll go along. Um, I had always been a procedural C guide.
Right. Um, the reason why with c plus plus is I loved some of the protection, some of, uh, the convenience of object oriented programming. But the catch was, um, with the inheritance, um, to truly understand what you were building, there were a deeply nested set of classes methods that you needed to understand.
Right. Um, so you, so I had a point in my career where I was spending 60% of my time in documentation, 40% coding. Wow.
Um, hay ai, which is probably one of the biggest changes, largely good bad that I've seen is, uh, one of the biggest, uh, changes in this space. Before we get to DevOps or DevSecOps, it's just as a developer, having your pair programming assistant, frankly, even if it's not generating code for you, the way that it could cut down your discovery and learning Mm-Hmm. Your, your error detection and diagnosis.
Um, your optimization. I mean, I think it's just an amazing tool for a developer. And what I have experienced is, um, you do really get what I wouldn't have expected.
And I don't think many of us expected to come now coding through natural language process. I mean things. It's really what it Is.
Yeah. Yeah. Very good point.
You know, it's, it's interesting. One of our folks sent me some code, this has been some months back, and said, I'm trying to debug this stuff as some Java script. I'm like, okay, I haven't read Java script for a while.
Let me think about this. So I just, I just put it in the chat, GPT that at the time I didn't have my ID up and said, what, what's wrong with this code? Basically, what error do you see?
It said, switch these things around. But basically you've got 98% of it's structured this way. Right.
By the way, if you wanna add a bunch of air handling and other stuff, there's another version sent it back. And, and the gentleman's like, that's amazing. How did you do that?
I said, you just put it in just foot to your IDE. Ouch. Attach the teeth.
You know, it's not the magical elixir for everything, but it is healthy with kind of get unstuck. Yeah. Learn.
I don't know what this code does, you know, show me ways I might solve this problem, whether I choose to use it or not. Or someday, maybe it's generating all that code for you. Well, I also, I mean, it's interesting if you talk, you think about, um, about, think about, uh, you know, we're in a world of polyglots, right?
Where you have to darts now taking on rust go, um, uh, it's no longer kind of assembly CC plus plus for trend, right? Mm-Hmm. Um, and, and you know, if you think about some of the knights or any of us sort of think about some of the knights that we might have had, you know, blurring over looking at lines of code, trying to figure out why this thing will compile or even worse, why it compiles.
Um, but something happens at one time, man. The ability to just go, Hey, tell me what's wrong with this. That is impressive.
Yeah. I will tell you where I'm disappointed with AI as I come back. Okay.
Um, is, uh, let's say about the time that I kind of focused elsewhere, not completely, but the time we're marking was when, um, MLOps or AI ops were really starting to become a conversation. A lot of people were exploring, um, how can we, um, uh, optimize the creation of CI/CD and DevOps workflows or pipelines? Um, how can we use, um, AI to ensure that even small teams, organizations that didn't have platforms, op teams, developers can get, um, robust CI/CD pipeline stood up so that they can focus on development Mm-Hmm.
Especi more quickly. Right? Yeah.
Yeah. And I really, while there's been an, I mean, it's amazing. It is exciting.
I'm, I'm a cynic, you may know me a little bit. I do hate the fact that we are in a world where all investing needs to be ai. I hate the, the, um, the, uh, the filler AI implementations, but I'm excited by, by the real useful applications of ai.
The thing I am missing is, um, I think just as we've helped the individual develop with code generation, uh, I think we could do better at applying AI to optimize software, um, deliverable mm-Hmm. From, um, uh, our build scripts, from our dependency management onto our pipeline workflows. And then I start to say more importantly, in, uh, remediation, not only remediation of defects, but uh, remediation of potential security issues.
I think, and you know what a big problem is? I think you've probably heard, I already agree, is it's, we still have to build up the data, the amount of data that it takes to do Mm-Hmm. Well, and the data in its unstructured data, right?
Right. Sort of folks have heard me say this, I think already it's the, there's a pony in there somewhere in all that data Yeah. Of my security issues, my what happened in the whole build process and trying to re recreate from all those kind of bits of data.
Yeah. This is having some, I dunno if it's a structured way, but an observable way. Right.
Of what happened to that. I, I have a question for you around CI/CD. Yes, sure.
So, involved in Jenkins community and your work at CloudBees. Um, they, they just, CDF just issued their state of CI/CD report. I think a number is 83, 80 4% of respondents outta 10,000 develop always process.
It's a big number. Um, said that they're, they're doing CI/CD, they're doing devox. Right.
Okay. Great. That, that's a great sign.
Right now, there are other data in there interesting about what they're, where they're having challenges and successes. Uh, what's your, what's your view on the state of CI/CD today? Uh, I, um, I think, uh, it, it is, it's always mixed.
I write, I think it's, it's, it's, it's both great to see that, say from, um, corporate, a commercial perspective, um, it's hard to find an entity that hasn't at least identified the terminology and tried to embrace, um, improvement of software development and delivery practices. Many with that being attached to kind of value, realizing how valuable their developers are and having a real focus on developer experience. Mm-Hmm.
Um, others interested in, in, um, in overall productivity, uh, delivering a new features, et cetera. But I do feel like, um, we moved, uh, fast, and this is sort of playing the cynic a bit. I think, um, at some point when CI/CD transformed to DevOps, and DevOps actually became a target of investible capital, um, I think so yeah, you, You, you started to see, um, the community, I don't wanna necessarily say companies, but it ultimately companies move on.
And then the community move through CI/CD before, frankly, I'll tell you every survey I've done, 80, 90%, yes. We do it. I then ask qualifying questions and, um, for a period of probably five to six years after those qualifying questions I'd arrive at, yeah.
About 30% of you that said you're doing CI/CD or doing anything, right? Mm-Hmm. There was confusion around the terminology.
Um, so an example would be DevOps, right? DevSecOps, rightfully why we would debate, you'd always say DevOps includes security, but we need the term DevSecOps. So that is explicitly understood that you don't develop your DevOps process, then go talk to the security.
You don't add airbags to your car after it's rolled off the factory line. Exactly. Kind of a bad idea.
Exactly. Same for security and Software. So one of the things I'm seeing now, and I'm talking to people, I'm sort of validating.
What I've seen is, this is an example of, um, we flew right past kind of ensuring that everybody was fortifying DevOps with security to kind of going, security's important, security's investible. I think what we've ended up with is a lot of people went under this DevSecOps tent just to create standalone kind of CSO side, right. Side security tooling that doesn't actually shift left into the developer environment.
So I think Interesting, yeah. When we talk about what we see in terms of continuous, um, vulnerability detection and security intelligence in the application development lifecycle, it is surprisingly lower under, Well, it is intriguing. You talk about DevSecOps, it's a place where I spend a lot of time.
Right? Right. And I've developed some kind of thinking in my own about it.
And one of it is, you know, is DevOps DevSecOps? Is it shift left? No.
Yes. But no, it's not the developer's job, all that kind of thing. Um, but the rise of software, supply chain security.
Yeah. I've come to think of, I hope you start thinking of DevSecOps is the entire workflow, the entire process of how we create a software, whether it's suggested from a third party source or written by a developer or whatever that is to the deployment environments, that it goes into that. So that's the horizontal path, right?
And then there's the vertical path, which is I create software, but I also do that on a bed of soft load. Right? So there's Yes.
The security of that whole tool chain, and I also, and Within it also on, on a, on topology, which is created from another bed of software, but yes. So it's not shipped left or right, it's 360, or, you know, you wanna look at it in a three dimension, if you will. Not to get over it complicated, but to me, that's, you've gotta address all of that, or any one of those are an attack vector.
Yes. And the, the other side of it is, sorry for folks that may have watched this, me already talking about this. You know, I spend a lot of time just in security world before kind of coming back in with software and cloud and security learned the lesson of, it's not just about defense or prevention.
It's the response actually. Yes. Because you will get attacked.
You will get compromised. We're at that stage where it's not, if it's when and how many times, what's next. Absolutely.
So you better be really good at response. Kinda the same thing in software, right? We're working on defense, whether it's code scanning or, you know, in production doing these things or testing for these things to security, all valid, helpful ways of doing things.
Right? Um, our velocity of software delivery, whether we're able to take five deploys a day, right. For, you know, that's just beyond the possibility of my team.
I want to have a hundred mile fastball when I need it. I mean, when I deploy that yes, fix right. In hours, minutes, whatever it might be Yes.
When I need to. Right? I don't need to deploy five times a day if, if, unless I really want to do that, or that's important to the business.
So think about it as response is also part of DevSecOps. Yes. Man.
You have a, uh, you're gonna get me in trouble 'cause you have a lot there I want to dig into. Okay. The one I'll, Well, you're feel free to pick it apart and, you know, tell me I'm not thinking about it.
I, I'm as, as usual, uh, you know, nine times outta 10, maybe we're aligned, right? We've talked about some of these things and I'm, I'm with you there. The first thing I wanted to say is just to underscore, um, uh, yes.
As, uh, we frequently heard and frequently say it's not about, um, do I deploy every 10 minutes, right? Um, it's about, um, having the capability to, to respond rapidly. And that can either be to market threats, customer needs.
Yeah. Or it could be to security threats. Mm-Hmm.
Right. Or a number of other things. But it's having the capability.
And I always like to say, I think, um, you know, many of us have come up in a world where you used to have an SDLC and then you had a ECR r an emergency change request process. Mm-Hmm. That kind of said, here's how we can Wait.
You are triggering me now. Okay. All right.
Right. Okay. Right.
So PTSD here, but, okay. And I was always, well, and I have it too, as I would go out and help people design and build their pipelines and, and, um, within certain environments, I'd always say, yes, you should at least have a fast lane. But, but what we're talking about is let's not have your emergency change request process be a separate lane that bypasses everything else that you deemed value.
Mm-Hmm. Let's figure out how to do everything we deem valuable fast enough to, to, um, equate to an emergency change. It's Benefited by all those things we put in place to help us get there, not only securely, but with quality, et cetera, and the right, the right changes at the right time.
And I think you'd hit a free here thing for me. Um, I, um, one of the things I'm really proud of that I had done before is to help initial people get a grasp of what DevOps is. I, um, I created something called the four quadrants of DevOps maturity.
Mm-Hmm. Right. And it was very simple, uh, reductive, you could maybe say, but the key thing was to say that, um, was to drive home this idea that you had to connect the left and right, not necessarily shift left.
Mm-Hmm. And in an organizational context, doing at a team level or in a modern dup microservices, decou with architecture, doing it at a team level is not enough. You have to look at an organization level.
So this is a different view of like what you said, it's not only left. Right, right. In multiple other census, it's top down.
So we'll call it 360. Now, the catches that I found this psychological was with, in dealing with companies, that's where the challenge comes in. Yeah.
Right. Um, uh, the hard work is getting everybody to understand their shared stay, their shared pains, and come together to do the work, to come up with a process tolling and a fix that enables everybody to work together. That's really the ascent as essence of DevOps and collaborative.
This is where some people, I don't know where you stand, may argue with chef luck. There's things about it that I didn't like 'cause Jeff left kind of turned into this thing I complain about in my, as I get into, I get off the lawn age Is in your lawn chair, you're running Porch, get off my lawn, your porch full Stack your get the hose out. Full Stack engineer.
Go back that here. School. Right.
But it is, um, and I really respect, right? But while I understand people have different definitions of full stack, but there was a lot of, um, taking on chef left means, you know what, we just build this automated process. We don't actually need experienced QA professionals.
We don't need security. That's back to the whole original, all we need is developers is just kind of a, a, a point of DevOps that might, might have been valid in some respects, right? Because we can automate a lot of things.
But it wasn't about eliminating people. No. It's actually about bringing people together, Together.
And it wasn't a, you gotta think there's a lot of domain expertise. Like if you really want to truly be your best, what it is is about getting, um, the people in different and stakeholders in the software delivery process to work together effectively and efficiently. But moreover, to, to, I'd argue, to say, to codify the application of each other's domain expertise to be able to deliver that best output and best outcome efficiently, effectively, and safely.
Yeah. You've clearly said this before. I many times The, the equivalent, I heal it.
I haven't said exactly those words. So let me run something by you here. I actually think we're at a similar stage with ai when you talk about scaling beyond a team Mm-Hmm.
To an organization with DevOps. I think we're there with maybe even a step before with ai, which is, we're in the co-pilot, which is kinda low hanging fruit for delivering. Yeah.
Which co-pilot do you mean? Yes. Okay.
And that, that's the point is how many co-pilots do I need? Right? How many freaking copilots can I even Yeah.
Afford more or less use, whether it's in my browser or my word processing tool, my collaboration tool, my IDE, my, you know, fill in the blank. Everything I use Yeah. Whether it's design, you know, art graphics or whatever.
It all has copilots, right? So we're, we're, we need to evolve past that. But I think that the next true stage of how AI makes a difference is it's gotta move past an individual's work.
It has to move to teams work. How do we six people work together on delivering software and AI is a part of helping all of that happen. Not just my ai, his ai, her ai, et cetera, et cetera.
Where does it help us as a, as an organization, as a team to really fuel or power what we can do together? Yeah. So there's a couple First, that's a, uh, uh, a really good question.
You have some gears turning, so it's, I'm not ready with the Response. I know, I know how to, I know how to push your buttons too. Um, no, you have a couple of really interesting things there.
Um, um, one is this does talk a bit about what I said earlier about, um, um, application of ai. Um, to, uh, one implementation of that would be to take aggregate, what I'd say dedicated streams of data. Mm-Hmm.
That may matter to one individual person, aggregate, analyze, and provide insights on that, that are shared insights by the, for the entire team. And that speaks a bit to, uh, using AI to analyze your security posture using AI to look at, um, sort of your target delivery KPIs and your historical performance. And then start to give people an understanding another, you know, how we would always say, um, you know, we look at the Dora metrics or we say, if you can't measure it, you can't manage it.
Um, is that a Peter Thiel quote? I believe. Um, but you also know what really happens anywhere where there's data and there's a human in between.
Um, is, uh, our delivery metrics have always been hype. Um, um, um, hyper interpretive, right? Mm-Hmm.
So we can't trust it. Oh Yeah. I mean, you're like, because there's, uh, wise, damn wise and statistics, right?
Um, so that's a good application for, um, for AI there. I do think there's a component of that, uh, that I don't have a thought for. It is gonna be a challenge, right?
How do we use AI continuously together? Um, like in the way we say a coder would use, um, so that we are developing a shared understanding and shared intelligence. Um, but you do hit another market thing that we've all seen over our crew that's gonna be interesting.
Um, someone's probably delivering this now is innovation. Um, a bunch of startups seed up. 'cause everybody's racing to be the first to market their slight variances idea.
And then we know markets always go into consolidation or centralization, then they decentralize, then they recentralize. And I think what's gonna happen is after we shake out all of the CRT of, um, first, what is a useful use case of ai and then what is a effective implementation of that use case of ai look for, to go in the trial of disillusionment where some of that stuff shakes off Mm-Hmm. Then you're gonna be left with a set of tools that people use day to day, but are gonna be siloed into individual offerings or solutions have you outlined.
And then there's gonna be room for, um, a control pane or a single plane of gas integration, um, for people, um, to, uh, deploy that AI within work, outside of work where I think your true copilot becomes an aggregate of multiple special purpose. Yeah. Purpose, large language.
I Agree with that. Is that makes Sense. Did I pass the test on that?
You were already passed that long time. Oh, so you're, you're all good. So I have another theory, and now the idea, this is what all about our conversations.
'cause we can exchange even the craziest ideas just to see if there's a, you know, but of, you know, something good there. One of my thoughts is that with AI somewhere down the road, maybe long after I've stopped doing all of this, but you know, we, we, we think about security of software and think about a KNR code base, our environment, the infrastructures code, all the factors that we operate in, those can all be represented in software Yeah. In an expert system or model.
Yeah. Whatever it might be. And we can build simulations of that software using the software itself.
Wow. Okay. Okay.
I'm, I'm pushing Yeah. Pushing. Do you watch three Body Problem On Yes.
On Yes. Netflix, this is the gold headgear game, right? You're level three.
Right? So, so, um, and, and think about security. Now we can do tabletop exercise in a simulated environment.
I mean, in the network world we do this, right? Right. We've gone through this evolution where we can simulate networks.
Why not do that with software? It's got its own key complexity, right? Maybe it's, the feasibility is a little more to, I, I don't know, but it seems like that would be a, can you imagine sitting down with your security team and say, so what are all the attack backdrops we haven't talked about?
Or what are the new ones we need to be thinking about that just occurred? Let's run tabletop exercise in a simulator. Yeah.
With our current code base in production or what we're planning to release. How's it gonna react? Yeah.
I, you know, and you're triggering a lot of things, so I'll try to control myself and be disciplined. Um, That's my goal here. You're right.
You lose control. Brian, I'm gonna, When he explodes then, you know, you have a scans moment. You, we've reached, uh, let's Call, let's gee out for a bit.
'cause you know, um, by the way Yeah. Like three body problem. I'm trying to think of a, you know, those are, uh, those are, those are my, those are my jam, right?
I like those, uh, type of what if, um, futuristic scenarios. Um, first I talk about, you know, in this pseudo, um, sentient that we have lying underneath, um, the current iteration of large language models and the like, um, is to really, and I'm sure there's work there that I just haven't seen. But I also think about that.
Look, look, it's one thing to go through tabletop exercises to um, to uh, uh, uh, take a chaos monkey approach to have somebody play the red tomb or the black hacker, right? All of those are still fairly scripted and programmatic and, and, and um, you know, your red team or your black hat is probably the closest that you get to trying to get into the emotional motivation and mind of somebody that's trying to get to your data in the system. So you're thinking like, how do we fuzz testing in our, it's how do we do chaos?
How do we do the unexpected? It's, and We dunno what it's right. And that's, so I don't whether it's, you know, uh, and we'll just use like fuzz and chaos I think is, are good, uh, examples.
But there's this, um, human layer here that when it comes to when somebody decides they're gonna approach a system and tack it, that when you were going through, um, there's a limit to which you can bring a team together and you could structure or script out an exercise to evaluate that. I like the idea that there's this layer in ai. Yep.
Um, even though I don't believe we really understand very well what's happening there. Mm-Hmm. But we clearly see that with some of the better models and better, um, um, prepping and prompting that, um, you can replicate, um, a human's view on why, where, and how you would attack a system.
Um, that we just can't script. I think, um, I think there's the other thing, and it just has to do with order of the magnitudes of massive scale. So now you have the ability to say, I'm really about to geek out now.
Right. To kind of prompt and model sort of, um, different personas, right? You can even prompt and model different groups of attackers, hostile states and bad actors.
Mm-Hmm. Um, I had a lot of color attribute and nuance to how they would approach the thing. And now at scale you have this ability, won't get me started on quantum computing.
'cause then it's gonna get right is the rate at which once you let a machine do this that you can use for rista and, um, astonishingly deeply nested, um, uh, scenarios to explore. Every possibility isn't, it's mind boggling. Right?
Yeah. That's one. I don't know if I even thought about it, if I could figure really understand the consequences of that, but you, you, so they're, yeah, they're giving me the hook.
I figured they were gonna kick me outta here. So No, These guys are just so hard to get 'em all. They're always like, You guys are so loosened up by o Thank God for playing.
No, I love Paul and Bris team. Um, just real, real quick, I'll ask you the impossible question to answer in a few few minutes. What, what is something you'd really like to accomplish stepping back into open source DevOps, this community, This is gonna be loosely re related, um, but off topic.
Um, so the first one, and then I'll get, give another but someone off topic, um, is, um, uh, protect and increase the humanity of what we do. You maybe heard me say before that I think what gets lost a lot that relates to a lot of the conversation that we had is I don't care what you are developing, I don't care if you're using AI to develop, it's all generative code, it's low code, no code. You've automated half of it.
The end point of everything we do in this space at one end or the other is a human. And um, I think where, and especially as AI starts to roll, roll out, we, you know, we start to lean into quantum computing. Uh, one of the things that becomes imperative is, um, that uh, we do focus on ethical technology and often sometimes we allow the evaluation of the social impact and the human impact to become before blitz scale and delivery of the idea.
Right now we're inversed. Yeah. Right.
Agree with That. And so if I could do one thing, it would be to, um, just represent and ensure that we're protecting and increasing the humanity of this, um, not just space wear and the craft that we're in. Right.
You know, what's interesting is, I don't know if you intended it or not, but you brought us back the three body problem Yeah. Is about saving the people, right? Yeah.
It's not about predicting when we have stability and chaos. So let's press pause right Here. I know we have to.
You're gonna get me restarted up or You know, I might lose an arm or something here if I'm not careful. So we will, we'll leave it at that. You know, obviously, you know, Brian has been a contributor in so many ways in our industry and done a lot of interesting things and, you know, very thoughtful about, um, how he thinks about problems and he thinks to solve.
So thanks for joining us and sharing with that, I look forward you to do some more panels and discussions together. Likewise. Hey Mitch.
Um, thank you for having me here. There's never been a time that is not an enjoyable discussion with you. Glad to be back having this again.
And then I really want to thank the tech strong team. I want to thank, uh, Paul, Brian, Allen, Jody and the rest of the team. This brought this together.
I really appreciate you guys and you guys are part of representing that human element of what we Do. Thank you so much, sir. Alright.
Talk again, sir. All right, great. Thanks everybody.
Don't, don't run off too far. You've got that microphone tied to how far Yeah, you might, you might lose an ear. No, you won't.
Yeah. And I didn't do the still portion of the cutout. That's right.
Thanks everybody for joining us for this conversation. We've got some more great interviews coming up soon.