Anoop Dawar & Christie Lenneville – GitLab Product Keynote
GitLab is a complete DevOps platform, delivered as a single application. For the last many years, we have focused on helping teams thrive by improving their efficiency and velocity while reducing risks. How exactly are we doing that? In this product keynote, hear from GitLab as they discuss the evolution of the GitLab single application, how the world is moving in our direction, and see some of the most exciting parts that are yet to come.
Transcript
One of the things that makes GitLab different is how we embrace iteration in the speed where we iterate. It's especially amazing how the community is welcome to contribute and makes significant contributions every month. We are shipping a new release every month, have been keeping the scales for well over one hundred consecutive months.
These are not little patches, but releases of typically hundreds of improvements ranging from new features to iterating on existing features. I'm excited about our next topic where we get to learn from more velocity and iteration makes possible. In our next session, we're going to meet two of our product design leaders who will share insights into what we've been doing and working on and where we're headed.
Christie is GitLab's VP of UX. She spent much of her career empowering UX teams to create pragmatic and thoughtful experiences for deeply technical products. Anoop is the Vice President of Product Management.
He leads our diverse team of product managers who are leading the future direction of GitLabs, features and capabilities. He's led product management teams at Facebook, Cisco and others. Good day, everyone.
My name is Anoop Dawar, I'm the Vice President of product management here at GitLab. And I'm Christie Lenneville. I'm the Vice President of User Experience.
And before we get started, Anoop has an obligatory slide to share. Yes, I do. It is a quick housekeeping matter.
We plan ambitiously in our roadmaps are subject to change without notice. Information in this session should not be used for the purposes of any material purchase decisions, not as it is a promise of any sort. OK, but that out of the way.
We are delighted to share a bit about what we have been up to and humbled that you took the time to attend today. We'll talk about four topics. I'll start off with sharing the industry challenges with DevOps adoption, and then I'll share some recent examples of how GitLab's product can help you and your company on your own DevOps journey.
Then I'll talk about where we're going and finally seek your contributions to get there together. As you know, DevOps is changing how companies deliver software, but most haven't realized the full value of DevOps. In fact, last year IDC estimated that 77 percent of companies have adopted DevOps, but only 8 percent use DevOps practices on half or more of their applications.
So natural to ask what's going on? Well, we think the main reason is here. How many tools do you have to string together to form your DevOps toolchain?
When you think about everything needed from planning the project to creating the software, testing it, packaging it, deploying, configuring, monitoring, securing, it's a lot of stuff. Cleaning, chaining these tools together comes at a real cost of complexity. This is the toolchain crisis.
You need people dedicated to design, build, maintain these integrations and these integrations are brittle. They can and they do break. But worst of all, the toolchain reinforces the silos since different people use different tools and breaking down silos was the whole point of DevOps in the first place.
All this leads to tools from multiple data models, impedance mismatch, security and availability, challenges that reduced transparency, add complexity and increased risk to the business. This is not for a lack of investment. We are already spending billions on DevOps, but more than half the time spent doing DevOps is wasted on logistics and repeatable tasks.
And while it's all better than it was, almost 90 percent of organizations that adopted DevOps were disappointed with the results. This has really hit home this last year where almost every enterprise we spoke to has a mandate to cut costs and improve efficiencies at the same time. We, of course, think we can be part of the solution.
We will all GitLab to be a complete platform for the entire DevOps lifecycle, delivered as a single application by utilizing Gitlabs. Teams can now work out of the same application to manage their DevOps practices. And people who were previously managing toolchain integrations can now focus on tasks that add real value to the business.
This enables you to enjoy minimal integration with a single data platform, which is simple and secure and enables continuous collaboration and transparency. It can also help you replace expensive and disjointed tools and replace them with new capabilities that were not possible before because of the single app approach making things like seamless collaboration, real-time feedback and fully integrated security testing a possibility. We took this view a while ago, and we are seeing it resonate very strongly with users this year, we expect this to be a full on phenomenon by next year when we explain this vision to customers.
Oftentimes they'll say, well, that sounds great, but my journey to DevOps maturity is a long one and the product you have is broad. Where do I start? A typical adoption pattern for many of our customers is as follows.
First, bring SMNCI together. These are the areas of GitLab product with the most maturity and depth and tying SMNCI can lead to some of the biggest efficiency gains. So this is a common place for our customers to start.
After that, customers tend to adopt security features next, which helps them shift their security practices left and empower developers to take more control over the security of the app. After that, customers tend to adopt our continuous delivery features, which help bring down barriers between development practices and operational practices, and makes it much easier to move code from dev to staging to production. After that, the journey varies by customer.
We have features to help you manage your project portfolio, plan your releases, store your package artifact, monitor your apps, defend your apps. When you're ready to expand your adoption to those use cases will be ready for you. The main takeaway from this slide is that you can adopt GitLab and speed up your ability to adopt DevOps best practices at the pace and in the order you choose, you're in charge.
Now, I'm going to turn things over to Christie to talk about improvements we made to the GitLab product over the last six months. Take it away, Christie. Our team has worked so hard to deliver value to our customers over the past six months, and I feel privileged to have the opportunity to share some of the most exciting result.
Starting with how we're improving our experience to help you deliver better products faster. First, we've made big improvements to search before wind developers wanted to search across projects for code. They had to clone repositories and search locally, we clearly heard that that process was so time consuming and frustrating.
Now you can use the UI to search across all projects in a group, including advanced searches with fuzzy or exact match boolean operators and more. The results you get from your search are highly relevant and you get them much faster than before. We know that many of our customers use those get Lab A.
And we want to make that experience better for developers who previously had to spend time navigating between those tools to get their job done. 2, you can see a list of issues from your JIRA project in GitLab and you can search and filter to narrow the results so that they're relevant to you. You can also navigate directly from GitLab back to the associated JIRA issue by just clicking the link.
And by popular demand, we've also started work on Dark UI. This is one of our most highly upvoted requests, so we've approached it with two experiments. Your feedback is important for moving this forward.
So please contribute either with feedback an issue or by submitting MRs yourself to improve what's there. 2. And I'd like to share a couple of examples with you.
First, you can now view MR changes in line to make code reviews faster and easier. And you can also make comments across multiple lines more easily so your collaborators know exactly what code you're referring to. This is good progress, but we have more to do.
So look for improvements in upcoming milestones. Unmodern teams, product development and design all work closely together. So we're making that easier with features that can easily access designs in an issue so you can immediately see important context and leave comments as designs evolve.
But we also know the design management involved relevant stakeholders in the conversation on functionality, interaction, UX and much more, because Figma is an industry leading collaborative design tool. We created a plugin. That lets you start productive up conversations in GitLab while keeping Figma connected to make any improvements.
This helps your team collaborate more seamlessly where the action happens. And last but certainly not least, we know that performance is a key element for a good user experience with a laser like focus on performance improvements in the last quarter, we may GitLab 10 percent faster, but we're just getting started. We have multiple initiatives become globally faster with a focus on our primary use cases.
But we're not just focused on faster development, we want to help you make your product more secure too. Our security scanning features blind application vulnerabilities within the development workflow so you can fix them before they become a problem. Developers immediately see the cause and effect of their own specific changes so they can address security flaws alongside code flaws.
Previously, your environment had to have consistent Internet access to run these important scans. But we now support security scans within offline or airgapped network environment. This empowers you to perform automated and continuous assessment of your security risk, no matter where you deploy GitLab.
We've also made security findings, first class objects, so that you can easily manage and triage them, just like you would a regular GitLab issue, but with their own security, relevant workflow. When you confirm that a finding is in fact a vulnerability, you can quickly turn it into an actionable next step, which you can resolve with an associated MR. This effort also included improving our security dashboards as seen here at the project level.
GitLab recently acquired two companies and PeachTech to enable deeper and wider testing than before. We're happy to announce that our first major step coverage guided plus testing is now available for go Anson plus plus letting you find vulnerabilities that are unique to your application. David DeSanto, director of Product for Secure & Defend, and Sam Kerr, Principal Product Manager for Plus Testing, are speaking about the value testing in our Dev SEC abstract.
So please check out their session to learn more. 1 and added support for offline scanning. 3 we will be shipping all GitLab SAST open source scanners to the core open source offering.
As the world continues its transformation to cloud native developers and DevOps teams are building more containers than before. Previously, developers had researched the vulnerabilities container scanning solutions identified, but now GitLab container scanning can automatically remediate vulnerabilities with known solutions. In just two simple ways allowing developers to get back to writing code.
And continuing the theme of cloud native transformation, we believe security is successful when everyone contributes. That's what we're proud to announce the first release of our container security solution, enabling dev sec and ops teams to collaborate on security for Kubernetes deployments. Our initial release includes intrusion prevention, file integrity monitoring and application allow list policies.
Now I want to share how we've iterated to save you time and money through operational efficiency. A year and a half ago, we built Mavin support directly to get lab to provide a standardized way to share packages and have version control across projects. Since then, we've added support for a wide variety of additional languages as part of our stewardship promise.
We're excited to announce that basic functionality for each package manager format is now available in the GitLab Core Edition. You can use GitLab as a public or private package registry with an easy to use UI that allows you to download any relevant files. 3 we made incident management available and GitLab Core so that companies of all sizes can spend more time innovating and building software and less time and money reacting to outages, racing to restore services.
We also added an integration that automatically creates GitLab issue for each pager duty incident so you no longer have to manage incidents in two separate tools. Recently, we also made alert management easier by offering a single interface that aggregates IT alerts that originate from multiple sources with our Slack integration, you can quickly see and access alerts. And if the work requires action with just a few clicks, you can create an issue that includes important details like helpful metrics.
Our new alerts list also lets you sort through alerts to find and triage the most critical problems first. Access to Git repositories is critical to developers and businesses because when an outage occurs, developers can't push code and deployments are blocked. GitLab now supports highly available Git storage without using INNOVEST.
HA configurations, improve the availability of important systems like GitStorage by removing single points of failure, detecting outages and automatically switching to a replica. This means that an individual system component can fail and your end users will never know. As you can see, we've made some amazing progress over the last six months, but we couldn't have done it without feedback, from you the wider community.
That's why I'd like to invite everyone to sign up for our First Look program, where you can participate in user research like interviews and surveys to help build the features you want, the way that you want them. We even offer incentives like gift cards and GitLab swag for your efforts. 2 that makes it easy to add a new epic from an existing epic.
It also lets you add more information to an epic than before, similar to how our issues are structured. Another example that you can see on this slide is how First Look participants influence upcoming changes to mass immigration. Currently, you have to integrate every project individually, but mass integration allows you to integrate once for a whole group or even an instance.
This upcoming change offers massive value for large enterprises because it reduces the work required to integrate with external services by multiple orders of magnitude. That's why we're so grateful for your feedback to help make this feature both useful and easy to use now that we've retrospected on the last six months. Anoop is going to tell you more about exciting things coming up next six months.
Thanks, Christie. Did I mention that we have an ambitious product vision? Well, we need your help to realize that vision.
So let's first see what's in store for the near future. A quick reminder that road maps are subject to change. With that said, let's start with how we want to help you deliver better products faster.
Iteration is one of the key values that GitLab, and we know that it is one of the hardest ones to put into practice. It is at the core reducing cycle time and delivering better products faster. 2.
You are now able to assign issues to iterations with more than one time box in GitLab. This is especially helpful for teams that follows Scrum or XP. Soon we plan to provide reporting and insight.
By a burn up and burn down charts and other progress indicators. In addition, epic swim lanes will provide the ability to group work on your issue bored by EPIC, so you can clearly see how a specific Epic's issues are progressing through our workflow. Many enterprises, customers that run self managed GitLab instances, have requested us to support the ability to run, GitLab on open shift.
I'm excited to share that we are working with RedHat to build an operator that will support running GitLab on OpenShift. We want to build it in a way that we continue to build features into the chart. And then the operator can also handle Day 2 operations such as backups and upgrades.
Creating and editing complex pipelines can be a lot harder than customizing one. So we would like to offer a visual authoring tool to create complex pipelines and a visual editing tool for editing complex pipelines. That's not all.
Enterprise teams often want to provide centrally managed pipelines that can be readily discovered, understood and customized. GitLab CI/CD Library of Recipes is now looking to provide a set of published jobs with descriptions of the job and possibly variables to customize them. With that, let us more focus towards reducing security and compliance risk.
The line between Dev SEC and Ops continues to blur, with applications being updated and production faster than before. Security is no longer an afterthought for developers. But there is a lot to prioritize.
Therefore, we want to enable you to identify what you should fix first to reduce your security risk. We are implementing a risk based model, enabling you to prioritize effectively. This includes expanding the much requested security report to have additional information at your fingertips, as well as improved filtering and multi select options so you can identify the most important findings for your organization or project.
2 we released coverage guide at first testing, allowing you to scan, go and C++ project, our second recent acquisition provides the rest API first testing and we are releasing this in the next couple of months. It will enable you to begin immediately testing REST APIs defined using open API standards for both known and unknown vulnerabilities, including OS top 10. I.
configuration. Now, we believe the auto remediation should be easier than two clicks we offer today or the next several milestones we will be incorporating GitLab bot for automatic remediation of new vulnerabilities. This will let you get back to writing code as it will apply the fix, verify that it works and merge the code back into your branch automatically.
Applications are updated in production faster than ever before, and that means you need to be able to validate your production applications are free of vulnerabilities even as new ones are being identified. Therefore, we are making DAST available for OnDemand scans outside your development workflow, as well as providing new profiles, site and scanner, providing you the visibility across the entire software development lifecycle. Now we want to be able to support your cloud native workflows all within your GitLab experience, we will be launching an alerts dashboard as part of a threat monitoring functionality, allowing you to triage all alerts, giving you a single view of your cloud native security strategy.
We will continue to retreat on alert dashboard and look to provide a Kanban style tracking board line for additional granular tracking while you triage alerts. Now, let's see what the team's been up to to help improve operational efficiency. In user research, we learned that most projects use a 50/50 mix of public versus private packages, and our customers want to rely solely on GitLab as a universal package manager to reduce costs and drive operational efficiencies.
But until recently, GitLab has only supported private hosted package repositories, which meant we were missing a lot of use cases. Now you can use a dependency proxy to create a virtual registry that fetches dependencies from your hosted and remote registries. This lets you publish and install packages with a single URL instead of having to remember which packages are hosted via.
You can also cash container images and packages for faster and more reliable. Today, we shortcode coverage history only in a per project view. However, if I'm a development team lead, I would love to have a single place to go view the code coverage data for all my group's products so I can quickly get the test coverage data.
We are introducing that you can also download data for project at CSFI to use with other tools to integrate with your existing systems. You can today you can set up a lab on a single server or scale it up to serve many users. To help with that, GitLab has built out recommended reference architectures to scale from 1000 users to 50000 users.
These are built by GitLab and verified by GitLab's quality and support teams. Now we are embarking on another step, automatic deployment of reference architectures to help take the complexity and guesswork out of operating GitLab. Today's businesses are always on and expect the same from their software.
This means that when things go wrong, companies need to have a team are often multiple teams that can quickly and effectively respond to service outages. This requires on call calendar management tools that allow these teams to create and modify On-Call schedules according to their specific predictions. We are working on a new incident management system that establishes On-Call schedules, rotations, schedule overrides as well as alert routing.
com/direction/kickoff. We have an ambitious product and we want everybody to contribute. Yeah, that's right.
As we've mentioned throughout this talk, a lot of different roles are involved in software development. And this is the ultimate GitLab vision where everyone involved uses a single application so that they're on the same page with their whole team. So while we're still calling it DevOps, we're really expanding its definition into one where everyone can contribute.
You can see us call out roles like product program and project management, but we're also adding support for other roles like design and quality engineering at our own company. Even teams like Marketing, Finance and People Operations collaborate inside of GitLab. It's our big, hairy, audacious goal to make GitLab, the most popular collaboration tool for knowledge workers in any industry.
So Anoop, how are we doing that? Oh, I thought you'd never ask. Let's see.
GitLab has come a long way since its inception as a source control tool with issues since 2011, we have released over 100 releases on the 22nd of every month. And as you can see, we've grown quite a bit since then. This would not be possible without your feedback and contributions just in the first six months of this year, despite the pandemic and other tumultuous world events, you contributed one thousand four hundred and forty eight merge requests, one thousand four hundred and forty eight.
That is astounding! Thank you to each and every one of you. Each month, we also announce an MVP that has contributed in an outstanding way to make it better for everyone.
I would like to call out the last six MVPs, Jesse, for building batch suggestion feature to group all selector suggestions made to a diff and submit them at once. Jacopo for helping and notifications on pipelines are fixed. Sashi for your contribution to snippets, released tags and webhook events.
Dmitry, for helping with 40 percent memory usage reduction when using Puma as a Web server. Steve for creating a network per build to solve multiple issues with Docker Executor and Roger for helping at S/MIME signature verification. This is special.
Thank you to the entire GitLab community for believing in the vision and helping everyone contribute. With that, I'd like to conclude. Stay safe and have a great day, everyone.