DevOps Dozen 2025 and the State of the DevOps Community | TSG Ep. 1001
In this special edition of Techstrong Gang, Alan Shimel, Mike Vizard, Mitch Ashley, Chris Blask, and Kate Scarcella examine the state of the DevOps community following the release of the 2025 DevOps Dozen awards. The panel discusses what this year’s selections reveal about how DevOps is evolving, where momentum is building, and what it signals for teams heading into 2026.
Transcript
Hey everyone. Welcome to our Textron Gang Live, which is all about 2026. We're live in 20, 26.
Guys, we've got an interesting show for you today. A little different than our usual. Um, we're calling it DevOps Appreciation Day.
I know Hallmark probably. I'm print a lot of cards for DevOps Appreciation Day, but for all my DevOps people out there know you're appreciated. Let me, uh, introduce you to our gang for DevOps Appreciation Day.
We've got up north Chris Blask, also up north, Kate Scarcella High up north. Anyway, you wanna take that Mitch Ashley, and of course, the dean, Mike Vizard gang. Welcome.
You know, you know what I love about DevOps? Smells like victory in the morning. No, no.
That's an old movie line. What I love about DevOps is it has evolved, shifted, changed, pulled, pushed, stretched, that it encompasses so much today, whether we're talking about DevSecOps and security, or AppSec, whether we're talking about platform engineering, cloud native, GI ops, of course, CI/CD, observability, all of these things are SRE. All of these things are kind of within the DevOps culture, within the DevOps bubble, if you will.
And, um, it, it keeps it interesting, right? There's a, in spite of the, the DevOps, that stuff that we saw a few years ago, it is bigger and better than ever, than the community and the, and the market are vibrant. And, and as proof of that, you know, this year for 2025, we announced on our predict show last week, the winners of the 2025 DevOps dozen awards.
I think it was the ninth maybe. I think it's the ninth year of the DevOps dozen award. You know, Mitch and Mike May know this, and you may not.
We kind of started the DevOps Dozen awards nine years ago, a little bit, not tongue in cheek, but a little audacious to think that there was even a dozen different categories for awards in DevOps, right? We, we, and I'll admit, we made some categories up that weren't really fully baked back then, but it, you know, as I sit here now, nine years later, I'm afraid we don't have enough awards to cover all the different flavors and varieties and places that DevOps touches on. And so we, you know, we, we've had a, we've had a change and evolve, right?
A couple years ago, we went to the DevOps dozen awards squared, which is actually DevOps dozen too. So we had a dozen community awards and a dozen tools and service awards to kind of break out those things that were sort of open source or community based, and those things that were more on the commercial side of the house to help cover the wide range of different things going on in DevOps. We've stuck with that a little bit that we've had a modify that year to year as well.
Look, we've seen things like AI come in here and change things and, you know, we, we've tried to keep the DevOps award, the DevOps dozen awards relevant, and up to, up to the minute, I think we did a great job this year before we even get started again, I gotta give a shout out to Andre Pinot on our team. You know, Andre is a marketer extraordinaire, analyst. We we're Andre's a semi-retired.
We're grateful for any time he gives us, but year in and year out. He really sort of takes the DevOps dozen awards under his wings and, and runs with it. So, shout out to Andre and helping us again make this year's award, award a success.
One last thing. com, register the actual presentations and announcements, as well as all of the finalists where we, uh, announced there. Mitch, Mike, I'm gonna ask you two guys to kick off here because you've been involved with us with the DevOps Dozen awards now for all these years.
What is the DevOps Dozen awards mean to you, Mitch? You know, it, it's, it's a bit of a rallying cry to just to talk about what are we doing in the community? What are we doing as a vendor community?
What are we doing as participants, advocates, people to move the ball along, people that challenge us and say, Hey, we're not doing enough here. We need to step up and well people to say, Hey, let's celebrate things that are happening. So it's great to recognize what people have done in DevOps, and as you said, the the categories, it really kind of expand, not because we're trying to just give everybody participation award.
No, there's so many elements of DevOps these days. DevOps really is the term doesn't mean what DevOps meant. You know, nine years ago when we started all this, and I think I've been a judge for a number of, maybe, maybe most of those years too.
So it's, it's a lot of fun to participate in it, but it's even more enjoyable to see what people are doing and see that they're getting recognition for it across the board. Yep. Mike, to Me, to me, I look at the journey has been rather incredible.
And I look at it and I go back in time and early on, like DevOps was the rebellion against those idle folks who were a little too overly dictorial in their approach to it. And the DevOps guys were basically saying, you know, we needed more freedom to create and drive stuff. com talking about, well, you know, what is the relationship between DevOps and platform engineering?
And to me, that's kind of like us stumbling towards something that feels like a middle ground, where we have some structure where we're not just kind of loosen together all these tools and telling people go for it. But we're also trying to preserve the flexibility and the freedom that goes with DevOps. And so, I don't know, Alan, your article's up there, but what's your take on, where are we on this journey?
You know, it's, it's kind of the never ending journey. And, and I wish I knew exactly where we are. We're here, you know, how's that?
Right now? We're here where we'll be tomorrow. There.
Um, I, I think, you know how people think that the US Constitution is somehow the word of guard, that the founding fathers were modern day prophets that are infallible, and therefore, everything you know is, is, is like, you know, biblical and, and, and one of the beautiful things about DevOps is there is no bible, there is no manifesto, there is no definition, there is no right wrong path. I, I think the best way to describe it is something I heard Andrew Clay Schaeffer say, once the DevOps you get is the DevOps you deserve. I've heard him say it more than once.
Mm-hmm. That's the closest thing you've got to a creed in, in DevOps. So where is it?
Yeah. Platform engineering's here and Platform engineering's great. com, it, it helps DevOps because I think the platform engineering community recognized that for DevOps to truly succeed, it needed that platform.
It needed the guardrails. You know, it's funny, when Platform engineering first came out, it was about Kubernetes. If you can get your Kubernetes platform under management, hey, you've got a great platform there, but no, now it's more about IDPs and setting up CI/CD guardrails, which allow DevOps engineers to do, or DevOps teams to do their things.
And so again, that's the beauty of, of DevOps the way it's set up, it morphs, it embraces, it extends all of these other ancillary technologies and frameworks that come down the pike. Chris, Kate, we haven't got you guys involved. I'm interested you both, you actually both come from a, uh, security background, right?
So I'm gonna imagine your answer is gonna be more security centric maybe than Mike's or even Mitch or I, what is, what does DevOps mean to you today, Kate? Well, you know, one of the things that I find is we're still leaving out security. And at the end of the day, um, and it's concerning when I look at, when I personally look at platform engineering, I understand we're basically putting a structure, um, to DevOps, but we're still, that doesn't mean that we're putting security as a part of it and meaning that, let's say, you know, so we have structure, um, if you're building a house, you have a foundation, but do you want that foundation to crumble as you start to, you know, build your house?
And, and so for me, I still find that security is being bolted on, and I don't understand that, but, and it's concerning, especially as we talk about AI and, and the idea that it's just going to be going so fast that if we don't start building presently SEC with DevSecOps Ops, we're just gonna end up having another platform a couple decades from now, and it's gonna be some brilliant new term and still not give us the actual secure foundation that we need to build what we need to build safely. Chris, You know, I, I came to security early in my career, but really second, my, my first epiphany that set this path was everyone's gonna get on this internet thing. And then it was all, they all need security.
So I spent, you know, all, you know, these decades focusing on that. However, it's not about that. It's about the story.
And we go back to the beginning. In the early nineties, the story was, everyone's gonna get on this global network. And Bill Gates himself went on TV and said, no one will use the internet.
That's a silly academic thing. What they'll all do is they'll pay me for the Microsoft network. And the story back then was you could divide the glo the world into camps that everybody believed one or two things.
Either that the big brother was going to sell us this monitored surveillance system that we'll all submit to, or that the hippies are gonna win, and this internet thing's gonna work. And in, for example, 20, 25, people would be arguing about phrases like DevSecOps that nobody knew back then, but still trying to navigate this space where it's not all just dictated from the top. So you guys, as you say, you, uh, people on this screen have spent way more time in specifically DevOps and DevSecOps and, and Kate, you know, uh, I've been more on the margins of that.
But what I see is our ability to have conversations with technical terms, it never existed. And we're coming up with these terms and all their implications and all the conversations we have here because we keep building succeeding to build a system that is not monolithic and centralized. And it seems to be the only way to do it.
And I think everybody on the screen here, most people watching would we we're concerned. We have some fear that it ends up being centralized. So can we, every day, every week we talk about this, can we solve all these individual granular problems in DevOps and DevSecOps?
And I don't know either, but we continue to do so. And that's, that's what I find comforting, You know, let's, we added a dash of hope to this. And, and I, I come to it from a, uh, like I recently started describing myself as an engineering operator, 'cause building, building products and building software.
And in some points in my career, also operating, run, running those things. Now, being an analyst is, it was about 2014 when Alan, uh, rang me up and said, Hey, Mitch, what do, what do you know about DevOps? I'm like, I think you miss said that.
It must be something else. I never heard of it. To your point, Chris, about new terms.
And that sort of launched down my path of, well, what is this and how and can we use it? And, and today, I think where we are, Kate, to your concern about it, I'm not gonna paint this as, oh, good, it's all rosy. We've figured it out.
But what's changed today is, is we're pursuing at breakneck speed, AI and agents and all this stuff, um, co-generation, all these things that we're all concerned about the security of which I am as well, but also coming along with it, our vendors and the standard open standards to, to a, to a degree, they're a little bit later than that of adding in security guardrails, behavioral guardrails, um, observability, building it into the platform of where we develop agents and we operate agents. That wouldn't happen. That didn't happen when we started on DevOps.
It didn't happen two years ago. Um, so I'm, I'm, I'm hopeful, I'm optimistic that because we've made it part of the conversation security about developing software that we are taking, you know, some steps to help secure more parts of AI that we're building, agents that we're building than we have traditional software before. It's not relying strictly on scanning after the fact somewhere down the pipeline.
Um, and, and it, it's gonna be, it's gonna fall short, I'm sure, and we're gonna have to do some things to really aggressively fix problems that we haven't addressed yet. But I think we're thinking about it more holistically of software at least starting to, and the vendors recognize that their customer base, especially enterprises, can't deploy This AI stuff at scale without addressing security. Um, and that's increasingly part of the conversation.
So I'm hopeful that we're gonna do much better than we've done, and we're gonna figure out where else we've fallen short to that we've gotta do a lot better. Yeah. And Mitch, you brought up, um, two key words that I love as a security person that is, um, behaviors and, um, observability observations, because I always talk about indicators of compromise, indicators of behavior.
If we see in indicators of be of compromise, it's already too late. It's already for us, the right of boom. As we talk about when we talk about behaviors, we're still talking about a left of boom impact.
And that is extremely helpful to me. So thank you for bringing up that word behavior. So I think that's the key going forward.
You're welcome guys. I wanna transition to acknowledge and recognize some of the DevOps dozen award winners this past year. Unfortunately, we don't have the time to really go through every single one of them, but I'm gonna cherry pick ones that I think are important or I want to just acknowledge.
And we're gonna start off with the community section of the awards, which is a little less than half the awards this year, but they're, they're not less than half important. They're very important. And there's some great ones out here.
I'm gonna start off with the best DevOps related video or audio podcast, maybe call it a webcast or whatever, you know, uh, the modern mainframe from BMC one this year. And a lot of people say mainframe DevOps. What do you mean?
Again, that's one of the secret sauces of DevOps. DevOps has done wonders, wonders for the mainframe world. It's really allowed the mainframe to run the latest stuff and whether, you know, and whether you're bifurcating system of record, right?
And all of these things. But there's so much good going on there around DevOps and mainframes. Good to them.
Um, the next one I wanted to pull up is the best DevOps book of the year. And this was a book that comes out of it, revolution, our friend Jean Kim. It's called Progressive Delivery.
Build the Right Thing for the Right People at the right Time. It's by James McGovern, if it's cut off on my teleprompter. But James Governor, James governor, excuse me, James governor from Red Monk, um, Kim Harrison and, and Heidi Waterhouse Waterhouse and Adam Ziman.
Great book. And, and it really captures, you know, we talk about the evolution of DevOps. This book really captures that.
Even that title is exactly what DevOps is today, right? It's built the right thing for the right people at the right time. So shout out to that book.
If you haven't read it, add it to your library. The next one I want to break out, and then I'm gonna ask you all to jump in on this, is Best DevOps community evangelist. DevOps has always been a community of evangelists, right?
We've had from my friend John Willis, Andrew Schafer, I mentioned, there's been so many great evangelists in the DevOps world, whether they were doing Devereux or what have you. This year's winner was Nathan Harvey. Nathan is, is kind of a pied piper of DevOps, right?
He started out at chef, he was the chef guy who was out there preaching in the wilderness early on. He left chef like many did, and went over to Google. And I thought, well, I don't know what he is gonna do about DevOps at Google.
But then of course, Google bought Dora, right? Which was a company started, of course, by Dr. Nicole Forsgren, Jean Kim, and J Humble, and they're the people who came out with the first sort of surveys, maybe not the first, but the biggest DevOps surveys every year that showed how high performing IT teams are performing, you know, u utilizing DevOps or not.
And we call it Dora is DevOps research and Analysis, I believe. Mm-hmm. Google took that, you know, gene, Nicole and and J are not as involved or not involved anymore, but Nathan's kind of taken that over and Nathan won for top DevOps community evangelists this year.
And the 2025 Dora report won for best DevOps survey researcher report. Mitch, Mike, I know we all talk to a lot of companies who will often tell you, and they cite the Dora metrics, right? In terms of, that's the measuring stick they use to how they're doing the DORA metrics.
And Nathan is still out there. He appears on our events, he on and Textron tv, but he's all over spreading the gospel of DevOps. Mike, I know you've met them.
You've, you've met Nathan, interviewed Nathan, what do you think? I was, I like the idea of Dora, and I like the fact that we're tracking some metrics, I guess other folks and myself included there. One criticism people have is the metrics don't always correlate to a business outcome.
So it's wonderful that we are, you know, turning over more code and fixing it faster and generating it more. And that may be what the DevOps engineers can, can control, but I sometimes wonder if we get a little overly obsessed with that particular set of metrics without connecting it back to something where, you know, DevOps teams can go to the business and say, this is the value of the ROI and the return on this whole methodology. And I don't know, Mitch, am I asking for too much here?
Or what do you think? Well, um, just like the, the DevOps you deserve as the DevOps you get, DevOps doesn't stand still. And I think the Dora reports under Nathan's leadership have progressed significantly.
Not that they weren't progressing, but they were very focused on how many, how many, uh, deliveries to production are you doing? And that is, that is a primary, uh, uh, metric that Dora people used to, to measure themselves against, or, and I always criticize that and said, but yet, if it's the wrong delivery, why does it matter? We were, it's, Nathan's really turned the page and said, we need to think forward more of where we're going.
That's why this report was, was talked about, uh, gen generative AI assisted development. And he's really taken on the mantra of let's really look at how we're developing software and how that's fundamentally changing. How, how developers really are becoming the engineers of how software is created, not create, just creating software.
And that process is gonna fundamentally change and transform like it, like it can under DevOps. And I think that's the good news. So to your point, I think DevOps has been, or excuse me, Dora has been sort of the easy metric for all of us to rally behind, but the environment's changing.
And so Nathan's challenge, and I think he's up to that challenge, is to really identify, so in the world of where we can generate software as fast as we want, maybe we can push it to, to, to, uh, production as fast as we want. Yeah. But what are we pushing?
How are we pushing, how are we creating it? And how are we creating value for the business? I've heard him talk more about business value in the last two years than any of us talked about business value in the previous store reports, which is a great sign of, um, evolution and maturity.
Yep. Kudos, kudos to Google and the whole Dora team. And Nathan, of course.
Um, I wanna make a quick mention about the DevOps event of the year. It was DevOps stays for in Zurich. You know, for those not familiar, not from the DevOps world.
com. Um, the first DevOps days was in Gantt, Belgium with Patrick dubois. The first DevOps days in the US was in Silicon Valley with my friend Damon Edwards and John Willis.
And since then, I forget how many like a thousand DevOps days have taken place around the world. What was interesting here is this was the only DevOps days nominated for DevOps event of the year. All the other events of the year where, uh, vendors, user conferences, which are great, there was some great user conferences in here that were made in the finals, including jfr Swamp Up and Grafana and, and some others.
But it was nice to see the vote. People still like that DevOps days format, that unconference that, you know, it's not run by a single vendor. It truly is the community.
So shout out to the folks at Zurich. They are a great example of the best of DevOps days. Also, I wanted to call out best DevOps open source project.
This wasn't the project you were looking for. A lot of people were looking at, you know, traditional open source projects, but our friend Garima Garima, Bo Powell, right? Did, uh, an event.
John Willis was a big help to her with it, um, called DevOps for Gen AI Hackathon. And so it was a series of projects that were spawned out of this hackathon and Garima, you know, Garima's a great community organizer in the mold of, of Obama or something, right? She really does a great job with organizing communities both in Canada.
She single-handedly has built that, but worldwide. And, and this was a a, a great project. All open sourced, open, you know, open everything, not just the code.
It was open and, and kudos to her. I wanna mention, you know, this year more than ever, it, it's amazing. So we have judges, right, for these awards, but then there's also the public voting and you know, the judges are 60%, voting is 40%, but this year, more than ever, last year I saw it too.
Basically there were one or two out of maybe 24 awards where the judges picked did not line up to the voting. I think the community recognizes value and quality. And so I'm happy to say that the over over 99% of these awards represent what the community voted for.
So congratulations to Emer and the whole team there. Next up, I wanted to talk about DevOps industry leader of the year. And I think now we, we moving away from community and into more of the commercial awards.
Um, well, it's still technically community, I guess, but these are more commercial. So DevOps industry leader of the year was Geo Bansal. And you know, you know how in the Oscars guys usually best director is the best picture.
And oftentimes it's the best actor too that we had that we had some of that going on here today. This was a, a year for harness, right? Jodi, of course is the CEO founder of Harness, technically harness ai.
Um, and they had a good year. They had a good year, Chris, and, and, and part of that good year was around security, right? They absorbed, traceable another security company Jodi had founded to give it their, the security, you know, chops in, in harness of Boost AI security.
I don't know, Chris or Kate, if you've had a chance to look at what Har Harness has done this year, Mitch, I know you have, and Mike, I assume you have as well, but to me, I think you take a look at those three awards together. Geo is best DevOps industry leader Harness for best end-to-end DevOps, uh, solution. And then also I believe Harness one for best DevOps platform engineer Award for their harness IDP.
They actually came out with their own IDP. So, you know, first of all, congratulations to Harness, but Yang, um, any thoughts anybody wanna contribute or speak about that? I, I'll jump in just to kinda kick things off, um, what I think is notable about Harness and of course, you know, I followed them for, for a long time before even meeting an analyst is they're very much are a platform company, but they lean to the right.
They're very much after code has been their strength and they continue to do that, including in the age of ai. So they're, they're very much a software delivery platform. And now they're, they pursued an added more agentic automation.
They've really invested in knowledge graph technology to bring contextual information into AI and also some of the other parts of their offerings. Um, really deep DevSecOps integration. Um, they have really continued to innovate and not just stayed where DevOps was or DevSecOps was three years ago.
They're continued to really take in leading, leading stance. Um, I'm very bullish on what they're doing in many areas. Um, they've got some, they've got some places to shore up.
I'm not gonna focus on those things today. But, um, Jody has really done a great job and he's recognized as a, as a, as a great leader in the industry and he's done really well with Harness. And so I think they're gonna continue to do great, do great things.
Yeah. And you folks know more about DevOps side of it, but you know, what I've seen from this is that, that they're making platform engineering, not theoretical, remove removing friction instead of putting gates while doing the, doing the security threat of it. So I've, I, you know, I've liked that, I've seen that along, but I again, don't have the, the depth of understanding and on the DevOps side of that, but that just seems logical and that, that's where we've been going with this.
I think, you know, the one thing they do really well is they strike that balance between I want to choose my tools and I want an integrated platform. Because theoretically you can buy their entire stack. They also let you swap out things more easily and they don't necessarily dictate the platform to you.
So I think there's a natural tendency where DevOps shops don't wanna necessarily buy that fully integrated platform. They kind of want some choice, but they want it to feel like a platform. So it's one of those I want my cake and eat it too.
Kinda scenarios. And the reason why that becomes important is that then you prevent this, um, this hacking, for lack of a better word, that then makes things less secure. So that's why that piecemeal is good.
You know, right around the end of the year, harness announced a major new funding round with like a $5 billion valuation. Yep. com article I did with it.
I also embedded a podcast, a DevOps chat podcast I did when Harness launched, I think eight or so years ago. Um, what's interesting is for those of us who've been around, like when I first started DevOps, right? CloudBees GitLab later on jfr, they were the three big DevOps and to and platforms, and they focused on C-I-C-D-C-I-C-D.
I remember interviewing Jody early on and he said, well, I looked at this the same way I looked at the, uh, application management a PM market when I started AppDynamics. And I said, what's missing here? What doesn't work?
And the problem from Jodi's point of view is all of these CI/CD platforms were CI first and then cd, but Jodi thought that the emphasis should be on cd. And he made harness a cd, a continuous delivery platform more than a CI ICD platform was the first time I saw a CD decoupled from ci, right? In DevOps.
And that was the mantra early on. ai before we, you know, be, this is eight, nine years ago, eight years ago, whatever. Before AI was cool.
He had the vision of maybe he was talking more about machine learning truthfully, but he had the vision then of doing it. Um, and so as we sit here today, you know, when we looked at best end-to-end DevOps platform harness really stood out, they really built that platform, including the platform engineering, the IDP piece of it, including Mitch, the observability piece of it, including Kate, the cyber, the security piece of it. They really got some great security chops in there.
So again, just kudos to the harness, Jody and the whole harness team. Greg, I have One more thing about Sure. On this too, and I think this sets the stage for the broader industry is, um, yeah, they had, I think it was 240 million series E, um, but they've got 250 million in, in a AR a RR at right?
50% I think year overgrowth, if I remember it. So it, it, it's, it's humming, it's moving really well. And I think there's a couple reasons why that have implications for the broader industry is, like you said, they're not just leaning into the cd.
The, they're, they're going down a path that you might call the, uh, kind of the AI control plane for what happens, um, from the delivery point on. And that's a lot of the investment in this, um, delivery knowledge graph, which of course can be used not just in in delivery, but pre pre-delivery as well. So they've invested in technologies and taking an approach that I think set the stage for where we're going, not where we've been in CI/CD.
And at the same time, um, to your point, they recognize like kind of the AI vendors is they can't be everything to everybody and everybody's gonna have 20 different tools and different things they make consolidate, but they're still gonna have four or five of everything, and they've gotta work with the tools that people have. So you have to meet people with where they are, customers with where they are and where they're going. And I think all of those are key elements of any successful strategy looking forward.
Yep. Gotta move along here a little bit, guys. I want to next call out the good folks at Octopus Deploy, right?
They want for best application of gen AI in a DevOps tool or platform Octopus Deploy. You know, I remember first meeting these people. They, they're done in Australia.
I felt terrible. They were up at 12 one in the morning to do their tech drop TV interviews with me. They of course bought, uh, or acquired codefresh, the people really behind, uh, what became Argo, one of the biggest OI think it's the third largest open source project in, uh, the CNCF.
Um, fantastic, right? They've really made their, their mark on the space and they've really kind of taken the lead when it comes to AI using generative AI and, and even agentic now too. So I I, I, you know, I think this is an up and comer.
If I had to pick who's the next harness, it's octopus Interesting perspective, I'm happy to jump on. And then them as well, you know, they have, you know, they're still kind of framed as the CD part of specialist in, in terms of what do, what, uh, octopus is doing. But they've invested not just in MCP, you know, access to, to what they're doing, but they've also created, I believe it's, uh, some kind of, it, it, I think it's the AI recovery agent, if I recall about, and where we can look at where failures are, what's happening, root cause analysis in the pipeline itself, right?
Not just leading into production. Um, so, so you can also recover earlier in the, the deployment cycle as well as once you move into production. And we see a lot of investments right now.
Um, we, companies are making investments in, for example, um, feature flag capabilities that push all the way up into the deployment cycle as well as what gets deployed into production. And tying that to observability, that was a company that Dynatrace acquired. So I think Octopus got a bigger vision for what's happening in the c CD pipeline.
And that's part of why you have that sense, Alan, as of an up and comers, they've got a vision for where this is headed. One of the things I like about what the, that whole community is doing is that they give you an option for cd, right? Not everything has to be programmatically addressed.
You can use a graphical tool to manage CD and that makes the whole thing more accessible to a larger number of people who may not have the programming skills and they're just mere mortal IT administrators that wanna do continuous deployment. This is a good thing. Absolutely.
Hey, let's jump to a security thing, right? Best supply chain security solution, right? And this is something, look, you know, every year at RSA we do the DevSecOps days on Monday, and certainly supply chain security has become the focus of security, you know, pre-deployment.
So best supply chain security solution was our friends at Jfr, the Jfr platform. And Jfr, I think more than any of the other big DevOps platforms who've talked about becoming a security company, has become a security company. They've acquired more than several security startups that they folded in for, uh, for security, DNA and their, their supply chain security solution.
Everything from X-ray to the, they have ai, supply chain AI security, they've really become a security solution. I think it was recognized here as such. Yeah, for me, um, you know, if you can't prove where it came from, you shouldn't trust where it's going.
Yeah, I think that's, that's a fair comment. It's a fair comment. King, I wanna ask you this question though.
'cause we talked about security earlier and you know, you hear the phrase security by design all the time. But I wonder if just like as humans, we're conditioned not to think about security after the fact. I mean, you basically, you build a house, you then you put the windows on, and then you put the doors on, and then you figure out where the locks go.
So, you know, that may not be the best approach for software engineering, but is this just kind of like, have we brought forward something that we are mentally conditioned to do after the fact? Yeah, it's a good question because I believe that, um, my hope is that security gets to the point where, as a consumer, you can walk into your house and turn a lock and voila. And I know, you know, that's, you know, crazy talk.
But you know, my hope is if I'm looking at, um, you know, secure by design, I also think it has to take in, uh, agency, agency of the person. So like, who, you know, just goes back to what I just said, you know, you know, where is this coming from? And, and so maybe the house is not the best example.
Um, although the only thing I would add to that, um, house example is that when we're building, like you're doing cement or whatever, you definitely are putting in elements that make the foundation strong. So it's not just windows and doors that we're thinking about, it's also the components of the house that matter, the foundation. I mean, you know, the foundation, foundation foundation is everything, you know, and it gives you not only hope, but it provides, um, the framework.
And that to me is very much security. Um, is is framework, you know, and that should help us build, um, our security into, um, into DevOps, right? Is the components just like a house.
So I'm gonna go back to the house. I'm sticking with my house, I'm sticking with the foundation, this whole house. Well that's right.
That, Well that because it's all about story over time. Like I can geek out, you know, last six years I've gotten deep into supply chain. I can tell you more about why there are eight fields and SPDX versus like, but what I really care about is that something seems to make sense and it continues to be coherent over time, right?
And I guess I gotta say this out loud, DevOps, for those who don't know it, is the idea that developers and operators should speak to each other, the basic, right? And oh, we should ask the security to be able to DevSecOps. And you know, as we move through time with these things, somebody will say something, it's like, we should have it that way.
Okay, you know, I should be able to walk into my house with a key and then, well, you can't do that because that requires all these things. And as I said at the beginning, we've been competing since the early nineties in, does someone build this thing and tell us what to do? Or do we build it and we continue to go down the storyline of we should do this.
Somebody says that it turns into working group and we come up with a solution, move forward. And that gives me a lot of hope. The specifics of it, you know, failure states and things breaking out, that happens all the time, working out better or worse, that's a big deal.
But we keep going down this path where, no, we don't need a big, we don't need someone to tell us the answer may be impossible, but things like developers and operatives just speaking to each other, the whole industry, You know, Chris, it is so funny that you mentioned that because I feel like, you know, and I've said this before in the show, at some point, those two should actually marry. I feel like it's been like this contentious sort of divorce. And like, are we, you know, we're gonna be separated.
No, no, wait, we're married. No. You know, right now we're friends with benefits.
What are you talking about? All right, on that note, that's the key to move on to the next category here. Yeah.
Hey, I wanna talk about best observability solution. You know, in many ways, 25, 24, if it were not for ai, observability would be the story. 'cause we've made tremendous star strides, observability, post-deployment, observability, pre-deployment observability, moving information, feedback loops from post to pre.
And really the good folks at Grafana Labs and their Grafana Cloud product In a very open source friendly way, right, have led the charge in many ways on observability. Of course, Tel OpenTelemetry is the, you know, the king of the hill when it comes to open source observability, second largest CNCF app. But right behind it you have Prometheus, uh, which Grafana is a big, uh, uh, a promoter of contributor to as well as to hotel.
And then, uh, uh, Loki is actually a Grafana project that's also in there. But they, they, I, I just wanna shout out to them, they really have not single-handedly perhaps, but in a big way help move the needle to make observability as integral as, as it is to the whole DevOps way of doing business. You know, you highlighted the open source, which is, uh, super important.
I, their m and a strategy is really picked up too. They just announced the acquisition of tail curl. Yeah, excuse me.
Tail control. That's what it's, yeah. Tail control in, uh, this month actually.
And, um, that's all about, you know, AI assisted tracing and sampling, um, across their existing, um, they acquired a company, I think it was pyro scope in 2024 or 2023 that they're building upon. I would surprised to see them doing some more m and a across this. So they, they've kind of got, they've got a multi-pronged strategy.
You know, we used to think of Grafana as what dashboards, right Alan? Yep. That was, oh, and, and you tacked on Grafana to whatever open source tool, um, or product for your dashboards.
And they've, you know, really become a much different company today with Grafana Labs. Yep. Guys, we're almost outta time.
I want to speed ahead. One last there, there's some great, I, I should call out Sona type one for best DevSecOps solution for their SCA, uh, tool. So Brian Fox and the Sona type team.
Good for them. Rookie of the year, as I call this one best new DevOps tool. Goba ai.
I met them up at Platform Engineering Con, um, another old security guy, you know him. Chris Ian. Ian Amit, right?
Smart as a whip Oh yeah, security guy, but really using AI to, to help secure code. I, I'd want to give him a shout out over there and gone back. That's G-O-M-B-O-C.
Um, guys, we're outta time doing this live format. We, we we're locked in 'cause we can't edit it later. Um, Mike, I appreciate you coming up with the idea of DevOps Appreciation Day here.
Next year we'll do greeting cards, but it was a great idea to highlight the winners of this year's DevOps Dozen awards. com to get more information there. As I said, you could also go to predict 2026 to see the, uh, presentations as well as the finalist.
Kate. Chris, I know this wasn't exactly a hundred percent in your wheelhouse. I appreciate you coming on though and contributing valuable input into our discussion.
Mitch couldn't have done it without you and Mike, of course. Um, that's it for today's DevOps gang show, though. We'll be back tomorrow back to our regular format.
So stay tuned for that. Uh, we've got tech drunk TV coming up though. Check that out.
I gotta go run to a webinar on what else? DevOps and Security. But until tomorrow is Alan Shimel.
We're out.


