Self-Hosted Remote Development with Rob Whiteley of Coder | AWS re:Invent 2023
At AWS re:Invent 2023, Rob Whiteley talks about Coder, a self-hosted remote development platform. It allows you to upgrade workspace specs with a few lines of code and roll out critical security updates to thousands of workspaces in minutes.
Transcript
This is Textron tv. My name is Shera Rubinoff, I'm the Chief Cybersecurity Officer with the Textron Group, and I'm here with Rob Whiteley, CEO of coder. Rob, it's a pleasure to be with you here today.
Yes. Thank you so much for hosting me. This was great.
So Rob, We've had some great conversations and I'd love you to share with the audience who is coder, what is your story, please explain who you are, how you came about, and, uh, let's go from there. Yeah. I hope you have about two hours.
No, I'm just kidding. I'll give you the short version. Sure.
So, so coder is, uh, a cloud development environment solution, or CDE is, is sort of the industry terminology. What that basically means is we're trying to solve the problem of helping enterprises shift their development from local laptops Mm-Hmm. To more of a cloud native where you're asking developers to access the cloud and develop there.
Sure. And the idea is developing locally on laptops is expensive. It's error prone, and you often end up with the, well, it worked fine on my machine, but then when I ship the code it doesn't work.
So we try to solve that. Mm-Hmm. Um, we've been around for about seven years, uh, and we actually started life as an open source project called Code Server.
Mm-Hmm. Uh, which is an IDE. And we've since grown to have a more complete solution in this CDE space.
Well, that's wonderful and certainly very needed. And let's dive into the security benefits of this. Yes.
Because there are many and much are needed. And I'd love to, for your audience to understand that. Yeah, Yeah.
No, I'm, I'm super excited to be here. 'cause I think it's an underappreciated element. Right.
So, to me, if I step back, the reason why companies are investing in cloud development is for developer productivity. Mm-hmm. Right.
Only about a third of a developer's time is actually spent coding. Sure. Uh, the remaining two thirds is doing operational stuff.
Administrative. So by going to the cloud, you get productivity gains. Great.
That's why I came, why I stay is usually a security benefit. True. And what I mean by that is, so many of our customers have told us that, uh, well, a developer left his laptop in a cab, or, uh, she did not have access when she was on the road.
And so by putting things in the cloud, it allows you to connect from any device. Mm-Hmm. And it gets source code off of laptops.
And so that's now a major source of intellectual property for most companies. The applications run your business. And so to get source code off laptops is a huge benefit.
Uh, and that's just the beginning. That's usually what triggers. Um, so for example, one of our large banks, it was actually the CISO that brought us in solely to solve that problem of getting lap, uh, source code off laptops.
Oh, that's A huge problem. It it is. And I think that alone is worth it.
But once you're in the cloud, I have better access controls. I can do role-based access, I can, uh, be more thoughtful about encryption and how I secure it and whether I enforce certain forms of SSH. So there's a lot of benefits and I don't think customers realize that until they're underway.
And so part of what we are hoping to do is front end that conversation a bit more. Security is actually a major driver on shifting to the cloud. It's not just the productivity gains.
Certainly. And let's talk about the no extra steps that we were discussing earlier. Yes.
You know, the human factors piece of security is a massive piece that organizations and technology companies and all types of security, and certainly with coding that all different, there's many different steps to do in order to get to what you wanna do. And when there's extra steps and people are in a rush, they don't wanna do that. Yeah.
They wanna circumvent it, they wanna break it, they wanna leave it open so they don't have to think about it, leave passwords around all sorts of things. Yes. So please tell me what coder does and why.
Yeah. No, that's, it's great. In fact, um, coders, co-founder Amar has a phrase that, uh, developers are inherently lazy.
Yeah. Uh, and he doesn't mean any disrespect by that, it's just they're, well, It's everybody. Right.
The multitasking, you know, I wouldn't just call the code. I would like say that coders are fabulous, But I think in part of the coding ethos is do things as elegantly and simply as possible. That's what makes good code.
And so if you shift the security burden to the developer Mm-Hmm. Like we in the industry love this concept of shift left. Okay.
Which basically means shift things earlier in the development life cycle. Yes. What that really means is you're asking the developer to do more, to take on more steps to build security into, uh, his or her workflow.
But that is against that ethos of being lazy and trying to do things efficiently. And so I think one of the things that we've noticed is, let's flip that on its head a little bit. Let's shift the developer.
Right. What if we could make the developer more productive and just make security seamless Exactly. Built into it.
They're not having to worry about it. And how does that work? Well, if I'm logging into a cloud to do my development, I'm inheriting the entire security infrastructure I've already put in place for my cloud, my firewalling, my access controls, my encryption, my backups, everything that keeps that environment, um, that I'm probably already put in production.
Mm-Hmm. I now automatically shift those security controls to my development environment, which again, used to be laptops and I was depending, uh, I was very dependent on making sure my antivirus or my mobile device management kept that device secure. And my developer had to battle that they had to toilet, they had to update things, they had to make sure.
So we reduce that toil, but more importantly, we take the security off the plate, off the mind. If you access the cloud, it is more secure. Period.
Full stop. Sorry. And so that's what makes I think this work better as opposed to having to send developers through more security training and Right.
Yeah. You gotta write clean code and have fewer bugs, but that is what the developer should be focused on, not complying with your security policies, which is too much toil. Certainly my background is heavy in security.
And I will tell you the best technologies out there have the security built in and have the no extra steps. You want something that's better, stronger, faster, without the onus being on the user, which is the developer or somebody who has to be responsible for it. You wanna make sure they're doing their job great and they're doing their job well without having to burden them.
Yeah. With thinking about those extra pieces. Yes.
Just think about our daily lives. Right. Moving a million miles an hour.
And certainly the developers, that's something they have to keep on top of mind. They have to be answering everything, running around and traveling, everything they're doing. The last thing you want them to think about is, wait a second, did I do all these steps?
Yeah. Because most of the time they haven't. Yes.
So that's, that's an excellent thing that you's certainly built in. And in terms of, you know, the competitors out there Hmm. And, um, that you see or you, you come face when you are, you're at the marketplace, what would you say your main differentiators are in the marketplace?
Yeah, sure. So I, I think for us, there's two primary ways these solutions get deployed. Mm-Hmm.
Um, they're self-hosted, which means you download the software that's coder. So we start as open source and you can upgrade to the commercial if you want. Um, but you own the software, you deploy it.
Okay. Uh, or you can consume it as SaaS. The problem with this space in particular when deployed as sas, uh, which is pretty much all of our competitors, is I now have a lot of very sensitive metadata about my developers.
What environments are they using? What tools are they using? How often are they in those?
What languages, what versions? That's all could be used to exploit the application. So that metadata is now flowing out to some third party cloud, which by the way, I had to poke a hole in the firewall just to do Right.
Uh, only for them to poke a hole right back into my environment in order to provision the developer, uh, workstation. So for us, keeping it all hosted inside your cloud, whether it's on premise or public, we don't care. Sure.
Um, is what has been the biggest inherent differentiation. Um, I love SaaS. SaaS is the future, but in an early adopter market like this, there's a clear leaning towards self-hosted.
Most of these organizations can run software as well as a cloud provider anyway. Mm-Hmm. And so they would rather just do it themselves.
Right. So that's difference one. The second one I would just say is the majority of solutions in this market, and again, I'll I'll call this the CDE or cloud development environments.
Mm-Hmm. Is their design with the operator in mind. Okay.
The backend DevOps team that has to own the infrastructure. We've tried to approach it from the developer, what's gonna create the best developer experience because, uh, one of the things that you hinted at is if you make things difficult, it will not get adopted. Correct.
We don't live in a world where we can force developers anymore. They pretty much have to opt in. Right.
And so if it's not a good experience, they just won't adopt that structure. Well, that's the mindset of developers and it's very good that you're honed in on that. Yes.
And a lot of people are like, well, this is what we do for everybody else. I like the fact that you're really honed in to what do the developers do? How do they like to work?
And work along the path of that. And when they talk about security in general or how operating anything really works is think about your user base work the way they work and build the security around that. Exactly.
Exactly. Don't try to force them into something. So that's key.
Yeah, Exactly. So our mindset's simple. If you make the developer experience clean and you take security friction out of it Yeah.
They will adopt it. Great. And then you finally benefit from all those advantages we talked about.
Wonderful. Uh, the worst thing I think you could have is you deploy the solution and they just continue to work on their laptop as if nothing's changed because they found the new thing too difficult. Right.
True. And I know you had some really interesting announcement coming out in that came out in September. I'd love you to reiterate that and tell our audience a little bit about that.
Yeah. And also hint about some new things coming down the pike. If you could give us a little bit of a sneak peek here.
Yeah. So I think, so back in September we announced, uh, something called the coder registry. Mm-Hmm.
And so think of that as a marketplace for coder plugins. And and the reason why that's important is because, um, we believe in developer choice. Developers should choose the tools that make them most productive.
Um, and so what we've done is we've created this registry so that anybody in the developer tooling ecosystem can write a plug into coder. Okay. So if you want to be able to provision your tool to a developer, 'cause we sort of own that developer eyeball, if you will.
Right. We are the thing they log into to do their work. Right.
Uh, and so we can merchandise different tooling, right? So if you want to use a code, uh, gen AI tool for assistance, we can make that. So by doing these plugins, we'll create a much more, I think, robust ecosystem where, uh, it is not on the developer to do that integration.
Mm-Hmm. We're just a, a tile they can click on now to say I want that tool. Uh, but we still get the platform team the chance to curate that.
So if they don't want to introduce that tool, then they can just kind of, uh, exclude that from the developer's pick list. So that registry is what we announced we're, we're building more and more, um, third party, uh, support for that. And so that's sort of the big thing.
So that was big announcement. Um, what I can say for next year that I think is gonna be, uh, most exciting is we're really trying to focus on how do we make these platform teams that are responsible for making developers productive, for helping secure source code, um, and really equip them with a much more advanced set of insights. So one of the things that coder does is we collect a lot of that metadata Mm-Hmm.
And like I said, we don't beacon it to the cloud. It stays local to your environment. That's important.
Well, that's a rich data set for sure. There's a lot we could do with that data set to help make operators' lives easier. Okay.
And so one of the things we'll be looking at next year early is how do we expose that in a way where maybe you can figure out, okay, if I, if I increased the amount of, uh, compute, what would that correlate to for an outcome? Right. And so by, by kind of frontend that we can make it a lot easier for operators.
Again, if we can remove friction from the developer experience, they will adopt it. So that's part of what we're looking at. Well, that's very exciting.
Yeah. So everyone stay tuned for that announcement coming up. And Kevin, anything else you want to add for our audience?
Anything that they should take note of or any helpful hints around anything around, uh, the AWS conference or your company itself that you'd like to share with us? Yeah, I think the biggest thing would be, um, so the cloud development environment is new. Yeah.
It's an emerging market. Uh, I think a lot of companies are not necessarily investigating it because they think it's not right for them. Mm-Hmm.
Or they don't want to force developers to change behavior. Mm-Hmm. I think what we've experienced is every customer that does it has, uh, quickly expanded.
And so to me, my biggest call to action is just go look at it. I mean, it's free, it's open. You can get started.
I'm not even asking you to, to, to purchase anything. But I think just shifting the behavior from local to cloud Mm-Hmm. Getting those security benefits and demonstrating that win back to the business Yep.
Is the first step in. I think what'll be a sea change in arguably the last mile the cloud has not effectively touched yet, which is developers. Yes.
Production environments have been in the cloud for a while now. Development environments are next. Yep.
So I think now's the time to get started. Well, that's wonderful. Thank you so much for sharing your insights with our audience.
Yeah. Thanks.





