Techstrong Gang – October 7, 2024
Alan, Mike, Mitch and special guests Chris Blask and Tracy Ragan dive into a Techstrong Research report that suggests more DevSecOps progress is being made than is generally appreciated.
Then, the gang discusses the rate of DevOps progress being made in mainframe environments before deliberating whether generative artificial intelligence (AI) is driving up the cost of cloud computing.
Transcript
Hey, everyone. Happy Monday. You know, are we finally making progress in DevSecOps?
I've been hoping and waiting for this for about 10 years. Um, but we are using DevOps on the mainframe, and generative AI is driving, spending on the cloud and everything else. We've got that and more.
You're watching Textron Gang. Hey everyone. Alan Shimel here from Techstrong.
Welcome to our Monday show. You know, it's October 7th. And just before we start, I just wanna mention this is the anniversary of, uh, last year's attack by Hamas terrorist attack against Israel.
And we all know what has ensued in the year since then. And as we approach this one year anniversary, unfortunately, I, I don't think we're done quite yet with peace breaking out all over the Middle East, but we do, we do pray for that and we'll see where the future goes. Um, beyond that, though, we're here on TechOne Gang.
We're not gonna be discussing that today, I think. But we do have some interesting stuff to discuss as it teased in the opening. We have a, a slice of a, of our DevOps next report.
And as it applies to Dev SecOps to go over, we're gonna talk about DevOps and mainframes as well as, uh, cloud spending being driven by generative ai. We've got a great lineup of people to discuss it with. Let me introduce you to our gang for this lovely Monday.
First of all, uh, joining us from Canada. Still though, he, I hope he's making his way down here soon. He's our nautical, cybersecurity and other things expert.
Chris Blaske. Good to see Alan. Hey, Chris.
Good to see you, man. Hope it's good. Um, joining us, joining Chris and I today up in the Rocky Mountains, our CTO in Fu, CTA, Mitch Ashley.
Hey, Mitchell, how are you? Flying high, thank you very much. Flying high.
Looking good. Looking good. Uh, speaking of flying high, you know, he's, he's, he's looking for a subway series between the Mets and the Yankees.
Our c uh, chief Content Officer, CCO, Mike Ard. Hey, Mike, how are you? Fingers and toes are crossed.
We'll see what happens. Uh, you know, I went to the last Subway series. Me too.
I was, I was at the game where Roger Clemens broke Piazza's bat, and Piazza threw the broken bad Adam. I was at the game where I sat down Derek Jeter in a home run, and then nothing happened for nine innings. That was the end of the game.
That's a good way to, that's a, a good Yankee game right there, baby. Um, all right, moving along. From baseball to the mountains of New Mexico, she is a open source expert, as well as the CEO founder of Deploy Hub, Tracy Reagan.
Hey, Tracy. How are you? I'm doing great, Alan.
Again, thank you for having me. I always enjoy our, our Mondays together. Well, you don't have to thank me.
It's us who thank you for coming here, Tracy, you bring a lot more to this that we, you know, can, can ever hope for. So thank you for joining us every Monday. You're the best for those who may not.
Well, if you watch every Monday, Tracy has a different, a different angle today. She seemed to have turned the monitor around, and she doesn't have that angelic glow anymore, but At least not yet. The sun is coming over.
Yeah. But The day is young. Anyway, guys, let's jump into it.
Mitch, you know, you were the primary author behind the DevOps next report. com that really kind of zeroed in on DevSecOps progress. And this is a, this is something that's frankly near and dear to me, right?
I, I've been a big DevSecOps proponent since people were throwing stuff at me for saying so. And, um, but it's good, it's good to Bevin, you know, vindicated. But are we being vindicated?
Tell us, rich, what's the deal there? Well, you know, you don't see much data very often about this, so it's really great that that was something, uh, we looked at in this, uh, DevOps next analysis. The study that we did.
Excuse me. Uh, just to give you kind of some numbers, 47% of respondents, uh, said that they're regularly employing DevSecOps SecOps practices. Now, what is that?
That's things like code scanning over half, or said that they're doing regular, uh, vulnerability scanning. Um, others are making investments in API security application, security investments. Um, some even at the high level, you know, at, uh, a quarter, 20 to 25% of them in that range, depending on what you're talking about.
So it's, it's gone from let's shift left and kind of have the developers do code scanning and fixing problems to, let's really start talking about the application security, the APIs. How do we secure that as well? And also, um, working with other organizations like platform engineering.
It isn't just a developer issue, right? It's, uh, leveraging teams like that to help create secure configurations and platform people are using, uh, to make sure that, uh, security guardrails and, and, uh, policies are being applied and base images and, and platforms that are being set up for them. So it, it's, it's vindication in the sense that we've gone from talking about it and telling developers they should do something about it, to, it really is happening.
Um, and it was a good, good percentage of our respondents. Now, security people are gonna say, well, if 1% aren't doing it, then it's not good enough. Well, we're happy for progress, right?
We'll, we'll get there, we'll get there over time. It's, it's a, a nice change to see that, uh, is in motion. I think if you look at the numbers, you can decide whether the glass is half full or half empty.
'cause I think it's a 47% are doing it, which in my mind means 53 or not. But it was also interesting when I looked at some of those numbers where there was more people said they were scanning code vulnerabilities, then said they were actually doing DevSecOps. So Mitch, do you think people are making a distinction between, you know, just scanning code isn't enough?
Well, it's, it's a good point. Scanning code tends to be a starting point for DevSecOps. Going, going further, you know, it's evolved as a definition too.
It's like DevOps, there is no official, here's the manifesto for, well, I guess there is a DevOp DevSecOps page. I'm not sure that we all follow Shannon LE's exact, uh, definition of it. I, I think it's more of we're doing security and application software, whatever that is.
Um, but since we ask things about API security and platform engineering and other areas that helped us kind of tease out, so what else besides, besides code scanning, that that's a basic, that should be a fundamental. I mean, that number should be 80, 90 plus percent. Um, but, you know, we're getting there.
You know, part of the problem is, is that we're, we're, we're, we're just catching some of these. I think if you look at the survey, I would guess that most of those companies are just starting to catch up. Um, code scanning is, and, and, and checking for vulnerabilities at the point of the build is a ch is a check mark, right?
Is, I don't know how useful, how, how useful it is, is good at that moment, but then there's tomorrow, right when the new vulnerabilities are found. So these, uh, these very static practices are still behind the eight ball. They're still not where we need to be.
So while it's good that we have, um, more companies adopting what I would call, uh, secure software frameworks, um, it's just not enough. We've had companies who have adopted, uh, you know, a secure software framework and they're still being impacted by bad vulnerabilities. So it's not solving the problem.
And what I'm, what I'm seeing is we're not, we're not doing enough innovation in the space. We're not doing enough. We're not doing enough to, uh, to really address the bigger, broader problem, which is real time checking of vulnerabilities all the time.
Not, not just when you do a build. And, you know, in, in terms of the, um, discussion around APIs, I think a couple of, uh, I think it may have been, uh, last week or maybe a week before we talked about, uh, AI security and the API, the API security is probably a super important one. Why anybody is running without an API gateway.
I don't know, right? So we're getting caught up, but we're not doing enough to get ahead of the a the get ahead of the, the bad players. So, or I would say it is, we still have a long ways to go.
There's a lot of progress to be made as well as what We have. We've made a lot as well, right? You know, because this is, you know, with my continuous obsession with, you know, the past and the, and the future.
In the past, we could, you know, it was classic to say, why aren't we writing better code? And the the short short answer was, alright, since nobody else is doing it, you know, where's the budget for this extra time? And people to do that to make my software slower or more expensive than my competitors.
And it's obvious at some point in the future, yes, you know, we're gonna have secure code written and secure by design and, and, uh, cyber informed engineering and everything we're talking about, here are where we are right now. And these points along the way. And I love this one because the software bill of materials world that I'm all wrapped up in these days is I thought a couple years ago would, would help with this, with one of these issues.
And it really has. We, we see this, you know, in my day job with side beats where DevSecOps is getting along better with other teams when you can say, here's why. You see what's inside of, right?
So all the comments everybody's making are, are very accurate and timely. And you can see from here, you know, we start putting a couple more pieces together. I think this next year is a lot about integration of all these things like scanning.
You know, Tracy does, uh, uh, nailed it. Perfect one, scanning vulnerabilities when you're doing a build is lovely. Now where are the other parts, you know, what about in runtime and, and so forth.
But we're getting there. So my name's Alan Shimmel, and I'm here to tell you the good news. Okay?
I feel like I rang your doorbell on a Sunday, right? But, so here, here's the deal, guys. Half full or half empty is still a hell of a lot better than there wasn't even a glass 10 years ago.
Okay? That's number one. Number two, I remember watch, I might have been a sonar type state of software security survey 6, 7, 8 years ago, less six, five years ago, that said they were touting, they were so happy.
75% of code was now being scanned for vulnerabilities before it was deployed, before it was deployed. And I looked at that and said, what are these other 25% of people thinking? What were they thinking?
But then I think back to when Mitchell and I started still secure 2001, we came out with a vulnerability manager, scanner van in I think 2003. And back then it was a chore trying to get people to scan, not code pre-deployment, but code in production code out there to get them to scan it at least once a year. Once a year.
They were like once a year. Do you know, it creates so many vulnerabilities. We don't, we only scan when they tell us we had to right?
Once a year. So think back, think back to where we were and where we've come. Well, you said you, you said it with that 75% thing.
So on this Monday on, uh, the CSA SBO m weekly meeting, uh, the UK NCSE, the National Cybersecurity Center gave a presentation and one of those key points that I was looking for that, you know, not having an SBO is a red flag now. Yeah. Now, 2, 3, 4 years ago, you know, nobody had an software bill of material.
Now it, it asks the same sort of question if, if, if 75% over there and you're not, you know, you know, in any of these security issues at that time, then it becomes a why would I buy your stuff at all? Right? Because it's a critical mess.
You've got critical mass behind you now, But, but lemme just put it out there. Okay. S bombs so far so good.
So what, right, right. Uh, if you're not consuming the data, the developers, and you're not, you know, analyzing it and chewing it up and spitting it back so that it's useful information, the developers are checking in their SBO into get, it's in a big fat text file and nobody's doing anything with it, really. We are getting it done, we're adding it.
But for most part, people can't even add SBOs to their GCAS pipelines. It's a, it's a major, uh, stumbling block. So we have to figure out a way to make it easy for new tooling to be added to the DevOps pipeline.
So new, new security tooling and be added. And like you said before this next year, I hope, because it would be good for deploy hub, if that's the truth. Consolidating and federating the data is what is needed.
And being able to continue to scan for vulnerabilities based on the SBOs, on the versions of the o objects that are running in production all day long and reporting them all day long, is where we need to be. So once you have SBOs, this is like when we move from vulnerability management to neck, once you have SBOs, you don't necessarily need to scan for vulnerabilities. You just scan your sbo, uh, you know, uh, manifest, manifest or whatever you want to call it.
And you know where your vulnerable pieces are, right? So when we did n we stopped actually scanning the computer, or that was secondary, that was an, a secondary scan. At first, what we did is we just looked in the Windows Reg, for instance.
And so what version of antivirus did you have and what version of Windows, and what version of this and that, and make sure you didn't have a known vulnerable version in there. And you can do that with SBOs. But let me, again, I'm gonna focus on the good news.
The whole concept of supply software, supply chain security, born out of a, out of a terrible security incident. Granted, but the whole industry ecosystem that's popped up around software supply chain security, including SBUs, and has, has been, you know, given a lot of love and attention by CISA and the present and the present administration by the Linux Foundation and open SSF, and, and a bunch of the foundations there by industry in general, has brought DevSecOps and software security, uh, software supply chain security to the top of everyone's list. And At expense Of DevOps tell a problem.
ofop What? At the expense of DevOps? Yes, they did.
So at the expense of DevOps, DevOps has become DevSecOps. Oh, and that's what it should have been. It should have be, it shouldn't be.
You know, you have a, you know, like at the Linux Foundation, which I'm very involved, you have the lit, you have the, the continuous Delivery Foundation, then you have the open SSF, and they don't work together. They don't talk to each other. They're not trying to collaborate between the, no, That's politics.
It's politics. That happens. This is just a reflection of the culture in every, uh, enterprise.
Every organization has their security team's got the stuff that they're doing. And then the platform engineers, as we're calling them now, um, they're trying to keep, you know, uh, the new tooling in, in the system and do the best that they can, but they're not talking necessarily to the security teams. So on that topic, what we have to be able to do is start defining what compliance actually means.
We don't have good discussion around what compliance looks like for security and software. And it's true, and SBO m is important, but what's important out of the SBO m are the packages, where are packages running, and being able to understand the vulnerabilities for all those packages based on their version and what endpoint they're running on. And this is why security and DevOps have to be together because it, they can't live in silos.
You can have an sbo om, but if you don't know where, where the binary is, that's, that, that, that s om was, um, that represents it's a u it's not useful. The information has to get federated. It has to, and it has to be a DevSecOps solution, not a open source security solution or a, or a supply chain issue.
And then there are, over here is people, they're doing their Jenkins workflows. We don't even, you know, the, the Jenkins community expressed to me that they don't even really have people asking them how to add SBOs to Jenkins, which I think is a problem. So at the risk of, uh, telling the fellow with the good news to get off my launch, um, most of the developers that I talk to basically, you know, hate scanning and it's generally false positives that they ignore.
And they think the scanning tools aren't frankly, all that good or helpful. And meanwhile, the folks who are running the SBOs will tell you that, you know, a fair number of the SBOs are simply outta date because we're updating the software so fast that we didn't run the SBO again after. That's The, that is the point.
That's why it's gotta be added to the pipeline. A developer shouldn't have to stand their code. It shouldn't be a developer's job.
Me jump in, because I think, I think getting too tied up around SBOs is sort of taking one issue and taking it too far. Yeah. A lot of stuff needs to happen with SBOs.
I agree with you. Um, so I'm gonna join, um, I'm gonna join Alan on the porch in my white shirt and black tie and talk a little bit about what some of the vendors are doing. So, um, Hello, my name is, and, uh, I mean, so take GitHub for example.
Like, it isn't just a buying a tool, plugging something in, right? It, it's building security into the pipeline, into the, into the tool chain, right? And DevOps.
So if you take GitHub for example, they've come out with some new capabilities. They're advanced security features, things like code scanning. When things are check in, there's a code ql, uh, CLI for, for invoking scanning both locally and remote.
They're secrets scanning in your code. You know, again, these are, there's also auto trigger rules, things you can do to invoke security processes and look at dependencies across this. And what's interesting about it, I gave a, I gave a talk last week at, uh, naidoc, uh, DevOps, uh, local user group in Denver.
And we're talking about DevOps and AI. And, uh, sort of a, a ideation session broke out about talking of, well, what if we took some security principles, like what we did back in the, uh, intrusion prevention days, Alan, of, of examining traffic and what's happening going in and outside of networks? What if we did that to our repositories, especially on large amounts of repositories where we might say, Hey, there's a lot of AI we could apply to this.
Like, suddenly we're seeing a lot of commits to this code repository that has been touched by a number of years. Okay, not big deal, but it's from people we've never seen before, and we're seeing other activities here. So all of a sudden we see un unusual anomalies in activities, might not be anything, but might be a pattern that we can recognize or seeing code that was checked in there, showing up in other repositories.
So people were thinking about, oh, how could I do some security things? These are developers, DevOps people, not, not, uh, vendors. So it's just, I think it's, I think there's good things happening and it's frustrating that it's not happening enough.
And I, and I get that, that's my, If you'd like to, especially like pin bot innovate, those are so easy. Hold on, Tracy, I'm gonna give you the last word. Go ahead.
I, I mean, to what Mitch said, uh, when you have tools like depend abot or renovate that you can add in a GitHub action so easily, why are you not doing it? Yeah, I agree. That has to be automated.
It shouldn't be on the developer. Yes. Anyway, Hey, we, we've gone overtime on this block.
We need to take a break here on Techstrong gang. We're gonna come back and talk about DevOps in the mainframe world. Stay tuned.
In a world where every line of code powers the future, every keystroke can introduce new threats. A software evolves so must security, it's time to rethink how we protect our digital world. Join the leaders in DevSecOps and AI at the OpenText DevSecOps Virtual Summit on September 24th.
Discover how innovation is transforming software delivery faster, more secure and smarter from AI driven security to the truth behind cloud security. Get the insights that will keep you ahead of the curve. Don't just watch the future unfold.
Be part of it. Register now and secure your place, tomorrow's world. All right, folks, we're back.
And we're talking about a new report from BMC that shows that, well, there's progress being made in terms of adoption of DevOps in mainframes environments. And that's a long time incoming. Wait, hold on a minute.
I hear a knock at the door. More good news. I've got my little magazine.
Um, so again, I've got great good news. Here's the good news on this one, though. This is not new.
Well, let me, let me just preface this by saying BMC is a mainframe, uh, software tools provider. Uh, they bought Compuware, which was also a mainframe, but they were both sort of leading lights in the DevOps on the mainframe platform and have been. But, but here's, here's a dirty little secret.
DevOps has been, or the mainframe community has been a friend of DevOps since DevOps first popped up because the DevOps, the mainframe community saw DevOps as a way to modernize mainframes. And that's a big push in the mainframe world, right? Speaking of Linux Foundation, I worked still with the Open Mainframe project there, the people behind Zoe, which is a huge DevOps on the mainframe, uh, force of nature.
Uh, they just came out with a new version. I think we're doing some show on its suit, but the, the fact of the matter is, first of all, the mainframe's not going anywhere. For those of you who are, you know, prematurely calling the mainframe is dead, you're outta your minds.
No one's ripping those puppies out. There's too many trillions of dollars behind them. Uh, secondly, from a security stability, operability, they're still penny for Penny, probably the most efficient, most secure platform we have.
Third, BMC, Broadcom, IBM Rocket, and a few others have done an amazing job of modernizing what we can run on DevOps there. I mean, on mainframes using DevOps frameworks and so forth. There's, from a language support, app support, they already really had containers before CNCF was born, right there, there it is a modern development platform.
And why wouldn it when, you know, when our DevOps next survey says, what, 77% of organizations are using DevOps, why wouldn't you use it on the mainframe? Why not? I mean, it, it, it's, it works well together.
It goes like chocolate and peanut butter. So if you wouldn't make mind making a small donation, Mike, Well, here's what I would ask in a very, uh, let's keep this religious theme going. It seems to me that a lot of these shops are running both DevOps and Waterfall, and some of them are melded, DevOps and Waterfall together in some unique way of their own and have their own little offshoot of the various religions that are out there.
Is that blasphemy? I mean, I, I'm, I'm asking you, you know, is, Is what, is DevOp in that kind of, am I, am I, how much leeway do people have? Because, you know, I may just say that, you know, I ran a, you know, a CI routine.
I'm doing DevOps baby, And maybe you are. Andrew Clay, say, can have a bill that takes three days, the DevOps you deserve. Okay.
Alright. Wait a second. Just, let's just back up for a minute.
Let's just back up for one stinking minute. In Endeavor was the very first DevOps tool I ever touched. It stands for environment for developers and operations.
And we were doing incremental deployments in, when I first started in software, literally, I never had to write my own compile JCLI never had to guess what my configuration looked like. 'cause Endeavor took care of automated configuration management. I could make one code change and check it and basically check it in, and it if, if approved, if there was a quorum and it got approved, that one code change could go out.
Everything I learned came from the mainframe. And it, while we think about the mainframe being kind of waterfall, because it's got a lifecycle, I suppose there really isn't any difference. And everything we have learned in software, everything has come from the mainframe, including DevOps, and in fact, they continue to do a better job in DevOps than we do to this day.
Now, when it comes to cross platform singing, that's a diff Go ahead. When it comes to cross platform, it's a different story because we've always struggled when we have objects that are on the mainframe. And this is, this is a problem in banking.
Uh, a lot of the, the FinTech, you have objects running on the mainframe that connect to things that are running on a distributed platform. How do you make sure they march across the lifecycle together? Those are different, those are different problems.
And over time, we've seen new languages on the mainframe like Java that has brought a different culture into this, into the space, and they may not be using Endeavor to manage that. So when we're talking about DevOps on the mainframe now, it's really a new group of mainframe developers who are not using a tool like Endeavor, and they're trying to look at other, other ways to manage the process so that they can do more incremental releases and not do these monolithic deployments. So I just wanna say that the mainframe has, was the, was the, you know, Virginia, it was the example, and it should be the example to all of us.
I was at a, uh, at, at, um, during the, uh, Obama administration, I got invited to look at what we, the problems were with all the electronic, um, transfers that they were having across all these different platforms. And I had two meetings. One was with the distributed side and one was with the mainframe side.
The mainframe side was really easy. There was two people that came in. We looked through everything we were, they were doing, we talked about things that they could change.
And it was done 30 minutes. And we were, I was done, I was happy. The afternoon session, there was 45 people in the room to manage the same process on the distributed platform.
And we could not see heads or tails. And that's why I say that, you know, the mainframe has always taught us the way, and we can, we should still look at that as the example. So Mike, you've just heard from St.
Tracy, the patron seed, so dialing of devox, okay? And on the second day, God created the mainframe. I was gonna say, um, all, all, all, all I heard was distributed systems are broken.
Well, no, but, but a new apostle. But, but hear me out on this. I think the action Tracy's dead odd where the action has been in mainframe DevOps over the last seven or eight years has been on the bifurcation.
I love when I use big words like this has been on the bifurcation of the systems of record versus the systems of engagement, right? Systems of records being the mainframe are still here. And many times your systems of engagement are distributed systems or some may call it in the cloud, right?
And, and having those work together in sync is, has given rise to a lot of new tools, right? The, uh, the, uh, Compuware Topaz, which is now part of BMC, I think is a prime example of this, but there's more the whole, you know, as I I I mentioned the Z Zoe project from Open Mainframe Project at Lennox Foundation deals a lot with this running Java and Rust and other modern languages, our mainframes, you know, it's all part of bringing together these systems of record system engagement on a bifurcated platforms where you have mainframe working with cloud or other distributed systems. And, and you know, what companies are doing this.
It, it's not the same as just being on a monolithic mainframe, but companies are doing it and they're doing it well. The other thing is, I will just say for as long as I've learned about DevOps and studied and listened to people about DevOps, no one ever said Waterfall is dead long lived. DevOps.
I've always heard from real DevOps people that you'd use the right methodology and the right tools for the job. And there are some things that lend themselves well to a waterfall or a fast waterfall. And there are some things that don't, don't, don't, don't take your square peg and make it round.
If you've got a round peg that works well for that. And, and so there's nothing a matter with saying, yeah, I basically do waterfall, but I do a little CI with it or, or whatever Is that DevOps again, the DevOps you get is the DevOps you deserve. And if it works for you, it works for you.
I, you know, we don't need any orthodoxies here, Michael, that that's what this, these extremist things is what Marine's involved so's, But we do use security and your DevOps. Yeah, I just really had, I think the Tesla and Tracy, you know, gives us hope, right? I had a couple years working with Unisys and Maine, you know, to much to my surprise, as you said, Alan mainframes are still out there.
You know, Citibank buys mainframes from Unisys based on Dell hardware, and that's specifically how I ended up on my supply chain path. But they do it with high reliability. They do a lot of things that in the rest of the world we talk about, and you should and had a, but this much of it has, has been working.
That's why, you know, the global financial system exists because it is possible to, to, to hit some of these bars. Yes, in the great wild internet world, we haven't got there yet, but it's not because it's impossible. Agreed.
All right, let's take a break. We're gonna come back and we're gonna talk about is is, is Gen AI driving cloud spending? It's, it's, well, it's driving investment, that's for sure.
But you are watching Textron Gang Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement and top quality leads with us will access editorial websites, streaming videos, virtual events, custom content analyst research, and more.
Join our satisfied clients, let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. All right, folks, we're back.
And yes, we're gonna be talking about how Gen AI is driving cloud spending, but we're more interested actually in what that means for IT organizations. 'cause obviously the people making GPUs and the folks providing the cloud services are just getting richer. But Tracy, um, are we reaching a point where we are not gonna have enough capacity and all of a sudden things are gonna get held up, prices might go up.
I mean, as you look at this survey, what do you see for 2025? Well, um, chargebacks have been a problem, um, for quite some time. Uh, when we add AI to IT and Gen ai, which requires a lot of resources, and you have everybody doing something around Gen ai, uh, it, it's always, you know, we could, anybody could have predicted that this was gonna happen.
I think, um, we'd haven't gotten our hands around managing chargebacks in general, right? Companies are still, and have tons of, there's all kinds of reasons why chargebacks are a problem. And, you know, we have organizational silos and, you know, nobody really knows who's using, um, who's costing the, the, the company so much money because you can't see who's actually creating the, the chargebacks, you know, cost allocation across multiple cloud providers.
How do we, how do we track that? So this is, was really kind of, um, in the works when AI started up and we started generating, or we started using more resources in our cloud environments without the ability to really see where the expenditures are. We, we, as a small company, struggle with this all the time.
It's like, how did that get spun up? We need to bring it down because it's costing us and it's been out there for a month and nobody's using it. This happens all the time.
So now with Gen AI and so many teams that are, that are experimenting with it, I can imagine that that 30% year over year cost, uh, increase that was noted in this article is probably gonna get to 50% in no time. So, like many of the tasks that we do in software development, we're not ready for AI yet. While we have the tools that obviously we can, we can build the, the software, we're not ready, ready to manage the software, we're not managed to ready to manage the cost.
So we've gotta figure out how to manage chargebacks. That is the, that's the basic problem. And that's not been solved.
And I've always wondered, you know, we, and the vendors have to be the ones who are providing the, the more, the clear chargeback information, and maybe they don't want to, maybe having that, you know, having it obfuscated is part of their we business model happen. Not that I wanna say they're bad, I'm just saying they're there to make money. So how do we manage chargebacks is really the question that this article has here, and I don't know how to do, how to answer that question.
All Right, well, I'll keep it going. Um, Mitch, um, is it a cry for help? Basically we need fit ops for Gen ai or something that feels kinda like, how are we gonna manage all this stuff?
Because, uh, right now it just seems like there's a bunch of drunken AI data scientists spin enough GPUs at will and nobody's paying attention What's changed? Yeah, That's what I'm saying. It's exactly the same.
It's just now AI is there, it's a charge back issue. Well, You know, we have another thing happening too here. All right, Another thing happening here, and that's the, the FOMO problem with ai, which is, and organizations are investing and reserving, uh, GPUs, whether it's in the cloud or in the data centers of their own.
And in, in the anticipation of not wanting to miss out on the benefits of ai, but not knowing yet what they're gonna use it for, we're in that experimentation phase that you're talking about. So we are also driving up cost of reserving resources for something we're anticipating that we're gonna need. It isn't like we're suddenly maxing out the capacity of all the stuff that we're buying or reserving.
There's a bit of a, uh, let, let's make sure, you know, it's like the baseball card, you know, peak, let's make sure we all get whatever the popular baseball cards are and then the market crashes. I hope that doesn't happen here, but we, we do have kind of a run going on of, of trying to acquire these resources for AI applications. Are are, are you saying that there's GPU hoarding going on?
Is that what I'm hearing? Purpose? There's a show coming purpose out on a and e, the GPU hoard.
Well, and again, this is just another indication of, of where, how, when you're early in a cycle, right? Because you thinking through this one. Yeah, That's exactly it.
Bill, Bill, Chris, Where I am Chris, yeah. As mi as Mitchell just saying, right? Did We have on here?
No, It's possible, But you Know, yeah, yeah. On the s bottom topic, Tracy and I can go all day long, but that's really early, right? Maybe a little, you know, later down the pipe than, than ai.
But we're at the point with AI where Mitch's explanation makes perfect sense. I hadn't thought of it that way, but Oh yeah, no, what does that, right? So we haven't even thought through the actual implications of using this stuff yet.
No, but, but it's just not, it's just not AI though. And in fact, in the article it pointed out that 93% of the people responded, said that they wanna be able to see what the expenses that distributed across their departments and business units, because they can't see that to understand who they need to go to, to say you're overspending in this area. So it's kind of free.
So I think we're really talking about two separate things though. com and Cloud native. And we've done some virtual events.
Yes. The only thing worse than your cloud bill is your cell bill, though I will tell you the, uh, the cell phone providers have gotten better. Uh, the cloud bill is just a mess and it's done so on purpose to, to not let you really see what you're doing.
However, not to paraphrase someone, but why do we need to listen to the experts when we could use some common sense? And common sense tells me, Mitch is finally, he knows who I'm talking about. Common sense tells me that if everybody wants to use GPUs and there's only so many GPUs, and most people aren't capable of running a GPU environment system in their own data center, they gotta get it from some cloud provider.
This is the time for the cloud providers to make hay, right? So common sense economics tells us that they're gonna raise prices here in GA and, and, and make money while they can. I'm not gonna use the price gouging term, but this is, that's the, that's the reality of where we are right now.
I I was talking earlier, a friend of mine just took over, took over CMOs a company, basically it's GPU as a service, right? You could turn 'em on and off and without going through the whole cloud provider thing. And they have access to high, high-end, high-end Nvidia GPUs.
So, you know, what's the answer here? I think the answer here is what Chris and Tracy alluded to, which is we're still early as this thing sort of normalizes the, uh, you know, cloud spun cloud spending specifically for gen AI will, will, um, equal out. I don't think it's gonna go down.
I think gen AI is a driver for more cloud spending. Will we? Do you think A d will make a difference here?
I'm sorry, what? Mike? I said, do you think a MD will make a difference here?
'cause part of the issue is we're overly dependent upon Nvidia, but they're both dependent upon the same manufacturing line in, uh, Taiwan somewhere. You know, that's like saying if we, if we, if we pump more oil, will gas prices go down? We, we've already seen that the amount of oil we pump really is not very related to the price of gas.
There's so many other factors along the supply chain of it, and it just doesn't seem to have any rhyme or reason to how much oil we're pumping out of the ground or fracking outta rock or whatever. However, we're getting our oil. I think it's the same thing.
Uh, gen AI is hot. GP user are hot. FOMO plays a role in it, as Mitchell said, and the cloud providers are gonna charge a premium for it.
'cause if I have the g, which, Which may mean some, some organizations might be saying maybe we should have pri our own private clouds and we're gonna get off the paying the cloud provider and, And it could happen and run and run GPUs. Okay? But that's gonna be a, that's gonna be a specialization skillset that they're gonna have to pay for.
And that's expensive too. That's not any cheaper. I mean, you're talking about big dollars.
Yep. I don't know. I think I'll call up the president and see if we can get some cloud price control legislation go.
You are the last president I saw do price controls was Richard Nixon. How'd that go? I'm not a crook.
Um, anyway, it it, it Led to a bunch of whip inflation now buttons from Yes, it did. Mike, you're showing your age. You're showing your age, Mike.
I don't, I don't know anything about that, but yeah. Bright In the late seventies. Yikes.
I, you know, I, I think the market, this is the rad in the snake and it has to play itself out, is, is my kind of take on it. Anyway, um, guys, we, we've had a 50 minutes of rollicking fun here. Let me just say, we have nothing against anybody's religion, and I don't care what you do or who you believe or who you pray to.
Um, so please don't hold it against me or any of us here. Uh, we're just having some fun. But that's going to take a, a, a, uh, a wrap on this version of the text on gang.
We will be back tomorrow with even more fun, I hope. Um, it'll be Tuesday and I'll actually be on that one, I think. Well, no, I'll still be here.
I'll still be here in Boca. Um, Mike, we hope to see you then. Mitchell, you're heading to Barcelona next week, right?
I am, I am. I'm gonna be doing some reports from the Atlassian team 24 conference in, uh, Barcelona. They're Well, enjoy box Barcelona.
Have some tapas for us. Tracy, what's anything in store for you? Not a thing.
I'm staying home. Good for you. Chris, how about you just staying here and hacking robots.
Beautiful. All right. This Allen Shimmel for Techstrong.
You've just watched Text Strong Gang. I'm Bonnie Schneider, sustainability contributor to the Techron Group. I'm excited to introduce you to a groundbreaking new initiative from Techron Research, the sustainability pulse meter.
The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry. Position your company as a leader in the industry and differentiate from your competitors with a sustainability pulse meter offered exclusively from Techstrong research.

