AI and the SDLC: New Ideas and Gotchas | DevOps Experience 2023
The world of AI in software design and delivery is rapidly evolving, with new tools and techniques emerging every day. If you’re looking to stay ahead of the curve, this session is for you. We’ll start with a high-level overview of AI and the software development life cycle (SDLC) and then dive into the exciting and sometimes tricky world of using AI in software development.
From planning and estimation to risk analysis, user story writing, and even simulated pair programming, AI is changing the game in software development. We’ll cover the latest and greatest AI tools and techniques, as well as the benefits and challenges you’ll encounter along the way.
By the end of the session, you’ll have a solid understanding of the benefits and challenges of applying AI to the SDLC. Plus, you’ll walk away with practical knowledge and skills to start putting AI to work in your own projects. This session is ideal for software architects, engineers, developers, project managers, and technical leaders who are eager to learn about the cutting-edge applications of AI in software development.
Key Takeaways:
– Understand Current Landscape and places to apply GAI to the SDLC
– Know the risks and be able to make tradeoff decisions
– Have a call to action to immediately apply to organizations
Transcript
Hi everybody. My name is Trace Bannon. Today we're gonna spend some time talking about how we can apply AI to the SS D L C.
I've got some good ideas for you. There's a lot of stuff happening out in the market in industry, and there are some gotchas that we need to talk about. But first of all, let tell you a little bit about who I am.
So as I said, my name is Tracy Bannon, but I go by trace. I'm a software architect. I'm an engineer.
I work for a firm called Mitre, and we're a federally funded research and development corporation. What does that mean? It means I get paid to give objective advice, to do the leading edge research to make things work for the betterment of our US government, and that helps all of us.
So a lot of things that I get my hands into. I play a lot with DevSecOps, I'm with metrics open source. I'm writing and building software, and I'm applying AI ml and generative AI across the SS D L C.
So I love this graphic. It's based on an illustration that was in the New Yorker, but Nicholas Conrad, but I altered it just a little bit. You'll see that the hand is depositing chat, G p t down into the enterprise.
Where can we apply it? Everywhere? And the question is not if you're going to apply it, it's when are you going to apply it?
And you'll forgive me. I am glancing down because I have multiple monitors today. So let's talk about this.
When as an architect talking to organizations, when I talk about applying ai ml, g a i, Gaia, um, people are always assuming that I'm talking about custom development and I'm not. It's applicable to low-code, no-code as well as to custom development. Remember, these days, we are really knitting together different components, open source libraries, snippets that we get.
We're knitting those together. Sometimes it's vis-a-vis a platform that's provided to us. And it's interesting that I have found that the low-code, no-code ecosystem has been adopting AI for a long time.
It's probably because of the men mentality. These folks really want to build software fast. They want to provide capabilities quickly.
So if there's something that gives them that edge that they adopt it. So I have found that before the G P T surge, before that tidal wave that we're all aware of the low-code, no-code groups were already, uh, getting into, uh, applying AI and ML into their ecosystems doesn't mean that custom dev is not doing the same thing. As a matter of fact, it's going across the entire, uh, value stream.
Let's take a look at what happens with the value stream. So when I talk about the value stream, I'm talking about soup to nuts from the idea from the business concept until there is value being realized, whether it's in government, whether it's in industry, that entire cycle, a little bit bigger, a little bit broader than what we traditionally think of as DevOps or DevSecOps. And look at all the different ways that we can start to apply and analytics.
Are there bottlenecks? When I'm looking across all of my tools, all of my value stream management tools, can I see where the bottlenecks are using descriptive analytics? I can use diagnostic analytics to say what's causing those different types of bottlenecks.
I can use predictive analytics to see where there are things that we could impact with a remediation, and then I have to get after which decision should I make. I'm not going to remediate everything at all times. It's always based on risk and value.
I can use prescriptive analytics to help me with that. All of that getting after continuous optimization. So AI detection of SS D L C bottlenecks across the entire value stream is on the horizon.
You will hear me say frequently today that it's, everything is not ready for prime time. What I'm telling you today is different than what I told folks months ago, six months ago. And it'll be very different than what you hear in six months because it is evolving and changing so quickly.
One thing that you will hear me also repeat again and again, is to take a risk-based approach, pause, and really think about where you're going to get the greatest value and pilot things as you go. But let's take a look at where we can use this across DevSecOps. It's actually pretty amazing.
This is a simple graphic just getting you after the infinity loop that we're all familiar with. Where can AI be used? Well, I'm gonna show you the next slide, and it's gonna be an eye chart.
We are not going to cover it all. There's a lot of additional material that you'll get through this, uh, P D f file that from today's conversation, and you can get down into these details and we can talk offline about it. Today, we're hitting the wave tops, but let me show you all of the different places that it can apply.
Infusing AI across the continuum is massive coding, planning, releasing, deploying AI ops. It's everywhere. But you're not going to do all of these things at once.
For me, uh, I'm probably the most excited about what it means from an architectural perspective because sometimes it's hard for me to really get after all of the code reviews, some of the refactoring help that I need, and those are giving me jumpstarts today. I, there are some challenges that we're gonna talk about when it comes to leveraging, uh, generative AI for coding, but we'll get after that in a moment. The point to this slide is that there's a lot, so many aspects are being improved.
So many aspects are being expanded. This is simply to highlight that there's explosive amount of possibilities in the innovation. Now, I'm gonna continue to hit wave tops as I cover a couple of different areas from that, from the, uh, the DevSecOps principles.
The first I wanna talk about is augmenting your planning. This is so cool. I've been playing with this.
I have not taken a system to production yet that is leveraging this, but we're doing requirements generation. So I can use natural language processing to take a transcript, sit down and have a conversation with the end users, a guided conversation, take the transcript, feed it in, and have it pull out, have the natural language processor, pull out what the functional requirements are, what the strategies are. I can also then take it, take those requirements and have them generated into usable agile user stories and epics.
It's a fantastic jumpstart. There is a new group in industry that's focused on agile AI and how they can apply this to, uh, the agile methodology. Uh, we're gonna see a lot on horizon.
Now, I tell you this, this is a great place for you to start to play. You can do some validation of information that you have. I would not, um, I would not rest on this yet.
However, key considerations, the dataset, integrity and diversity. You need to have a broad set of data that you're feeding into any model because you have to make sure that you have those various perspectives. Otherwise, you are going to miss different user needs throughout, uh, the design process and throughout the requirements generation.
The second is quality, quality assurance. Human oversight is a mandatory part of this right now. For as much as AI is helping us with repetitive tasks.
It also takes a lot of handholding. It takes a lot of babysitting. Right now, it's okay, but we have to be cognizant, go in eyes wide open.
In this case, if I have user stories that are going to be going to a delivery team for them to do design and development against, I still need to have eyes on to validate that they meet the needs of the stakeholders on the horizon. We're probably gonna be able to move away from that, but not yet. Let's move on to another discipline within DevSecOps.
This is the one you hear about. Developers don't fret. You're not gonna lose your job tomorrow.
You are going to need to learn to use AI assisting tools. It's not gonna take your job. It is going to help you, but it's also gonna take extra time.
Code completion and code generation is one of the places getting the most amount of airplay right now. Is it good? It's okay.
I'm going to give you an example on the next slide that'll probably temper you about your immediate adoption of code generation. Another place though is this idea of user personalization. This can be really helpful as well.
Um, generative AI in specific, when you're talking about personalizing user experience, think about using Netflix or Hulu or Spotify platforms. Those have been developed and they're using advanced AI to understand the end user's needs to really customize what they get from that platform that's being developed on their behalf and being presented to them dynamically. Well, what are the key considerations for that?
Well, you need to make sure that your AI is ethically being trained. It's easy to propagate biases. These are not necessarily negative biases.
They could be, uh, a music bias for a particular genre that's getting propagated forward. You have to understand the weighting of the biases that are there and be able to counteract those biases. Otherwise, your user personalization is going to be very skewed.
Same thing again, as on the planning. Gotta be concerned about quality, the quality assurance, rigorous testing, rigorous testing when it comes especially to using generated code. Now, as I step into the next slide, I'm going to go a little bit deeper in this, but realize that right now code completion has been around for a while.
This some people, we used to call this intelligence. We begin, begin to type in a word and it nets out the rest of that word in development and programming languages within an I D E I can begin to type in, it will actually parse out and provide me with an entire sentence or an entire structure of code. It's still code completion at that point.
With code generation, I can actually ask my I D e, I can ask the virtual assistant or pair programmer virtual pair program, and that's working with me to generate code that does something in specific. The problem that we're seeing consistently, uh, are the number of choices and the different type of code that's getting generated because there's no right answer. Remember then when you're using generative code, it is mathematically predicting how likely words are, even if they're computer programming words, language words, how likely those words are to be found together.
Those are called vectors. So when you are doing your language analysis, it is really statistically figuring out how likely words are to go together. Well, that's why you often will get a lot of choices.
Let me take you to the next slide, and this will make a lot of sense. This is specifically using copilot. When you put in that you want to, uh, have a bit of code, this is an actual one that I created.
Um, I just wanted to return the sum of Xs. And when it did, if you notice at the top it says one of three, one of three, what that means is that at least three different samples have been given back to me, and I have to make a choice on which one to accept. Well, I feel pretty comfortable with Trace Bannon making that decision.
New and career are still learning, and so they don't necessarily have what they need in order to be able to select which one of these, um, samples, which one of these generated code options are the best ones. So it can actually take more time and it can inject flaws. It can inject defects.
Right now, actually this is as of May, June timeframe average of only 26%. 26% of the generated code from copilot from GitHub was actually being accepted by the developers. So think about that 75% roughly of what they were getting at that point.
It's not being accepted, it's being trained daily. It's improving daily, but still, you have to start by understanding that you're not going to be able to automatically generate an entire application by just speaking the word. Someday that will happen, not today.
When you are considering doing this, make sure that you start the code yourself and be as explicit as possible. There will be defects, so make sure that you are testing immediately. It's actually a little bit more difficult at times to use test-driven development, which is something that we often promote.
It's more difficult to start out with test-driven development if you're using a generative AI tool. Oftentimes though, in the, with these generative tools, they don't have the broader context of your entire solution. So it may be duplicating or triplicating a function, for example, that you've already created someplace else.
This is getting better. Um, what I will, what I will recommend to you is what GitHub recommends, which is to ensure its suitability. There are words from their website.
You've gotta have rigorous testing. You've got a IP scan. You have to make sure that what you are leveraging has not been copied in a way that is, um, VA invalidating intellectual property rights and make sure that you're checking for security vulnerabilities.
Testing, right? We're gonna work our way around the infinity loop. I've designed the code, I've gathered the requirements.
I've done the first build of it. Let's talk about what you can do with testing. This is probably the most, uh, focus right now in industry is a complete explosion of the different types of testing that can go on.
I like it For test data management, um, for automating test data management. Test data management is often overlooked. We focus so much on the tests and not on the data.
The data has to be matched and versioned to the code base and to what's happening at that point in time. I can leverage, uh, I can leverage my models, I can leverage that to help me to create a better, uh, data test, data management strategy, and also to, to synthesize, um, the data for me. It also help you to create test strategies.
Folks aren't always thinking about this. You can ask, uh, a generative model, for example, if you have a well-crafted prompt to provide you with a test strategy, as long as you give it enough information that it understands which words need to be identified on those mathematical vectors as being relevant, um, it is getting better. But at the, at this point in time, I would say that you still have to be very, very, um, focused on making sure you are adapting to your environment.
So what are some key considerations? Even if you are, uh, creating synthetic data, it's possible that it mimics the real world too much. Who's supplying your model?
It could be that the data that's being created synthesized by the model for you is leveraging something that it learned, um, that could have p i i personally identifiable information or something that would allow me to deduce. So think of this from a medical perspective. If I have trained a model, um, and I wanna use it to create test data for a new algorithm that detects a certain disease, there could be information in there that lets it track back to Trey Bannon, um, and what her blood type is and her height and her weight, and the fact that she's had these vaccinations and has had these diseases and these surgeries across her lifetime.
Even by getting rid of my name, it's poss possible to infer. So it's something to be very aware of that you need to be always protecting sensitive information, even if it's synthetic from a model. The other thing is balance, uh, and adaptability.
Everybody wants to get rid of the humans in the loop. I got news for you peeps. We're not getting rid of humans in the loop.
Not yet. And when we do, their, their role is going to change. For now.
There's still a role for manual testing. It brings that unpredictability, that intuition, that models don't yet bring. You also wanna make sure that your models that are being leveraged for testing can be adapted because your code is going to change.
Therefore, the testing and the generation of any kind of test or test strategy need to be able to balance against that. Alright, this is exciting. Ah, I wanna call your attention to one thing that's on this screen.
Stack overflow. Uh, just did a developer survey and I think that this is an amazing statistic. 55 point 17% of the respondents say they want to use AI for software testing.
Look at the number who have confidence in those tools. 85. So it's not there yet.
It will be there. Be looking at it on the horizon. Cybersecurity.
This is near and dear to my heart. Everything that we're talking about today has a basis in security. Um, I am, uh, very much an advocate of secure by design, secure by in depth, secure by default.
Um, if you are bolting on cybersecurity, you're at risk. But let's talk about ways that we can improve cybersecurity. You can use generative AI models to simulate new types of cyber attacks.
This means that you're gonna be able to detect and prepare counterman measures before an attack actually ever happens. Um, there are, um, there are security protocols. Generative AI can create adaptive new security protocols for you against different types of threats.
Again, you are going to need to understand the ideas that these models are providing you and then be able to do the validation against it. This is not a trust situation where you automatically say the security model is right. You are going to need to validate against it.
There is a, uh, so, uh, threat modeling we've talked about. AI-based vulnerability checking is on the horizon as well. Um, and this is where it can play a crucial role.
Simulating new novel types of vulnerabilities as well. So it can take a look and detect where there are current vulnerabilities, known vulnerabilities, CVEs, uh, it could be from the oasp top 10, um, but it can also start to detect trends, uh, that will lead to the identification of future vulnerabilities. So you gotta make sure though, from a data privacy perspective when it comes to cybersecurity, that you are training on anonymized data.
Like I know that I'm foot stomping data quality. It's a theme, guys. You gotta be cognizant of the data that's being used to train the models.
The size of the model is not what's important. It's the quality of the data that's in the model and the methods being used to train the model. Another piece of this though is that security, uh, improving your cybersecurity with AI means human oversight.
Those critical security decisions, humans need to make those decisions, not a model. Let's see. There is, uh, just something cool I wanna add on here is there's something called, again, a generative adversarial network.
Uh, and it's really cool. There is a way to set up, uh, two neural networks, what's called a generator and a discriminator, and these things will go back and forth against each other. The generator tries to produce data that's indistinguishable from real data, from an attack perspective, and the discriminator is trying to figure out.
So there you can actually play two models against each other, real time, um, attacking, counter attacking, uh, and which is going to be another one of these ways that we see improvement in cybersecurity in the future. We could spend an entire day talking about just applying AI to cybersecurity. I'm gonna hit a couple more wave tops before we end today.
Release management. Uh, I'll always start with your repetitive tasks. So when we're using any kind of AI ml or generative ai, we wanna get rid of the, the, the things that we have to do day in and day out in this, in this case, there are some things on the horizon.
These are not all ready for prime time, but being able to predict the likelihood that a release is successful is something where there's a lot of research being done right now and a lot of initial prototyping being done. I think this is going to be a game changer from a a software delivery perspective. Right now, today, there are are folks that are having their pipelines automatically generated for them.
Well, that's, that's neat. That's novel, that's helpful. But the idea that I could take a look at the entire release structure and have a model evaluated and be able to predict beyond what my experts, my human experts say.
Are there things that, uh, we're not aware of that could cause a failure? And then be able to predict that and be able to mitigate that risk. Um, another is the dynamic environment.
Provi provisioning, um, and deployment optimization. So what does this really mean? It means that when I go to deploy, there are times where my calculations are wrong, my spreadsheets are wrong.
Even the tools that my cloud service provider has given me are not as accurate and adequate as they need to be. As the models get smarter, as our tools get smarter, our environments will be able to be even better when they are, uh, dynamically provisioned and the deployment is optimized for exactly what that needs to be. Obviously, we are using things, uh, in the cloud right now, such as auto-scaling that allows us to, to automatically, we're using infrastructure as code.
This is the next level above that, that is even more intelligent. And it's basing on trends that have already been seen in the usage, changes that are being seen across the I a c, across the infrastructure as code. Um, and there are a couple of things to be concerned about.
Things to keep in mind. Data quality, that's right, data quality, uh, and completeness. If you don't have enough information, if you don't have complete visibility into that production environment to be able to train the release models, you're not going to have that success prediction.
Um, that's going to be adequate for what you need. The second thing is making sure that that deployment strategy aligns with what you're doing. Well, what do I mean by that?
Well, it could be that, uh, the strategy that is defined and provided to you by the AI doesn't match. You may not want, for example, a blue-green deployment, but that may be something that came up. So you need to make sure that what is being suggested aligns to your business goals.
Alright, making our way around this one makes my toes curl. I'm dev married to ops, and so I've been working in and around IT service desk operations and monitoring my entire life. The idea that I can help with the IT service desk, things like deterministic self-healing.
Do I need someone to take a look at something or can the application and can the environment, can the tools that are surrounding a solution be intelligent enough to determine that something is going off the rails? This is more than just simply our, what we used to do to have a A C P U monitor that told us when something pegged at a certain level and then we spun up another server instance. This is bigger and more than that, this can be shutting down ports.
This can be rerouting traffic in different ways. This can be slamming the door shut on certain types of entities can be a, a myriad of different solutions, but this idea that I no longer have to call into the help desk, that the system itself is aware and is able to heal itself is, is amazing. This has been around conceptually for quite a while, but the realization of it is happening now because of the technologies that we have in play.
Um, the other piece that I think is super exciting is deterministic ticketing and support allocation. This means if you have a support organization, it is able to understand as long as you have trained it, the skills of your individuals, uh, what they're currently doing, what the likelihood is for the time to resolve a particular ticket that needs to have human interaction and it routes it to the right person. So this idea of automatically determining what the ticketing information is and then routing it to the right person saves a tremendous amount of time.
It also pre-populates your knowledge base because one of the things that happens with our IT service desk that not all of our folks are entering in manually all the information that they need to capture this improves that capture. Now, key things to be aware of is trustworthiness of the decisions. You have to validate the decisions that are being recommended by the models.
At first, you have to do that again and again. It has to be tested, it has to be a lot of rigor around that. Every model that we're talking about today, every application of ai, ml or generative AI needs to have a lot of testing, needs to have a lot of eyes on.
The second thing that's hyper important if you're going to augment your IT service desk is that you provide a mechanism for feedback from those end users. Not just the, the those who are being served by the service desk, but the humans who are getting those tickets, who are, who are the operations, uh, individuals at the IT service desk. They also need to be able to refine the models accuracy with their inputs.
Supplemented I IT operations is similar to release, uh, in nature to some of the release items that we talked about earlier. Automated resource allocation in particular is when you are using generative AI algorithms to dynamically allocate above and beyond making it even more efficient. Uh, it could be that it goes beyond the I E C that you're used to with your cloud service providers.
Another reason that this is so important is that this does not depend on you being in the cloud. Not everybody is in the cloud. Not everybody will be in the cloud.
That's okay. The second thing is getting after predictive maintenance. If we are watching, if we are careful, if we're looking at what's going on, we wanna take care of problems before they happen.
Uh, as my husband and I often talk about dev and ops, ops has often been reactive where dev has been proactive looking for towards the future, looking at the issues that have already happened. As we're making our way towards SS r e as we're making our way towards having improved operations, we wanna involve predictive maintenance. I wanna fix it before it's broken, so it's an important piece, but I've gotta make sure that I understand the costs.
If you are implementing AI driven solutions, they're generally not free. None of these things that we're talking about today are free. They all come with a cost, but especially when you're talking about operations, your costs can be exorbitant depending on what you are, uh, allowing, uh, to have happen on your behalf.
Um, the scalability as well, you may need to be able to scale, uh, uh, in infinite, have infinite scalability, and I'll put that in air quotes by leveraging the cloud. However, again, not everything is cloud-based, and you also need to be cognizant of that scalability. You wanna have max, um, capacities match max thresholds put on, uh, onto all of your auto scaling.
Downtime is disruptive. It's uh, expensive and it's something that we want to, you know, in certain critical sectors like finance, like healthcare, like the government, you have a unique perspective to be able to step back, uh, and get after a more productive predicted, um, uh, operations environment. I'm gonna add this in for just a moment.
Most folks kind of glaze over when I talk about an enterprise strategy, but I gotta tell you guys, you need to be thinking about what you should be doing overall for your enterprise. Just real quickly, just real quickly, do you have a data strategy in your organization? If you do, great, does it have ai, uh, included in it?
Yes or no? Find that out. If it does, fantastic, make sure that it, that it meets your needs.
These are the things you have to do. If you're going to start to include AI as part of your enterprise. Do a needs assessment.
Doesn't need to be a six month in-depth study. It can be a rapid determination, but at least understand where you could benefit from it. Don't apply ai ml, G I I everywhere.
I'm finding organizations right now that are drowning because they're trying to do too much. Do a pilot. Check it out before you do a full scale implementation.
Run something smaller and evaluate the success. Then you need to figure out, do you have the skills to be able to do what you're thinking about? You may need to hire or, uh, train up your staff around ai.
If you are leveraging AI as a subscription service, you still have to be cognizant and smart about what it is that you're getting, you are going to need to establish some governance. So ethical guidelines, oversight that's responsible for how you're using AI to incorporate that into your strategy. It can be lean strategy, it can be a fast strategy, but at least think about it.
Have the conversation. You need to have monitoring and feedback loop about how you are leveraging generative ai, AI ML in your organization. And take the time to, uh, to consider thought leadership.
How are you going to stay current? How's your organization going to stay current? How are you personally going to stay current?
Right now, it's very easy to be completely overwhelmed. I know many folks who are changing their social media feeds, who are changing their newsletter subscriptions, who are unsubscribing from different emails. 'cause quite frankly, they are overwhelmed.
You need to figure out what community will best reflect what your direction and needs are for your organization and for you personally. So that's great. You've got a number of different areas that you're thinking about.
You're gonna do a needs assessment. You're going to understand strategically where you can leverage any of these ai ml or generative AI techniques. Gosh, what does this mean for the future?
Well, right now, AI is being infused across all of DevOps and the entire value stream. As I said at the beginning, the easiest place to start is looking for those smaller, repetitive things and then expanding. It's being incorporated and experimented with.
Right now, it's not ready for primetime continuous testing, as I said earlier, that's where it's being most impacted today. Talk to me in, in six months, I'll have a different story for you. AIOps is on the rise and it's enhancing observability and conman.
Conman is continuous monitoring. Shifting security left doesn't mean that we're dumping things on developers. It means that we need more humans involved across the entire S D L C and this idea of release anomaly predictions or release success predictions is rapidly improving.
We're not there yet. There are some questions that you need to ask of whoever is providing your ai. Not gonna cover all these in details.
You can get a hold of this. The set of materials, essentially you wanna be asking questions about the where the data is coming from. Is your information as it's being fed in to be evaluated?
Is it secure? Is it in-house? Is it going externally?
If it's going externally, how is that being protected? What's the privacy of the data? That's a big, big piece of this.
If there are updates to models and you're subscribing to it, whether it's you're subscribing to an enterprise service within your organization or subscribing to an industry, how do those model changes affect what you're doing? Think about this. This is immense and amazing.
It's very easy to get bogged down. It's very easy to go underwater with all of these things. Be practical and pragmatic.
Understand the pricing aspect of this. Understand, um, the limitations that can happen with that. Couple other things to keep in mind and we'll close out.
These are just things to keep in mind. Prompt engineering is a new discipline. There's a concept called human machine teaming.
How are humans going to really interact after a while? If their partner is a virtual assistant, what's going to happen with them? What's, how are software teams going to perform over time?
Are people going to begin to trust ai? When are they going to be able to trust it? When shouldn't they trust it?
All of those things we need to be aware of. Uh, as a friend said to me the other day, we can't put the genie back in the bottle, so let's keep talking about it and discussing it. Here's your call to action and we'll close out.
Connect with whoever your providers are and ask them the model and security questions that are here. Talk to them about their AI roadmaps and pulse your organization. It doesn't matter where you sit in the organization.
Understand around you who's using any kind of ai ml. Understand the landscape. Just pulse it and see what's there.
That will help you to figure out what type of research and discovery that you should be using, that you should be doing, and what type of reasonable guidelines. Here's what I need from you. In my role, I'm constantly pulsing the government, pulsing industry, pulsing the communities so that I can bring that goodness together and help to propagate that out.
Please share your stories, share your lessons learned, um, and if you have new use cases or new tools, please reach out as well. Here's my contact information. Thanks guys.
I hope you learned a lot today.





