The Evolution of Harness with Martin Reynolds | AWS re:Invent 2023
Martin Reynolds, field CTO from Harness, discusses the evolution of Harness as a modern software delivery platform and a leader in the CI/CD space. Reynolds highlights the broadened scope of Harness beyond traditional CI/CD, emphasizing its role in helping developers deliver software securely across the entire development process. He shares insights from his experience as a former customer and now part of the Harness team, emphasizing the importance of focusing on the right information at the right time rather than simply shifting work left.
Transcript
This is Textron tv. Hey everyone, welcome back. We're here live in Las Vegas for AWS Reinvent at our, uh, studio here up in the Wynn Hotel, our tower studio.
And I'm happy to be joined by our next guest. He's Martin Reynolds Martin's with our good friends at Harness, one of the leaders in the CD space, and a big AWS partner we might add as well. That's Great.
Um, Martin, thank you for joining us. Before we jump into it though, uh, I, I just jumped in, like everyone here knows who we we are, but it's Alan Shimmel over at, uh, tech Drunk tv, and I'm joined by Mitchell Ashley, our CTO and GM of our Tech Drunk Research Division. Um, Martin, first of all, welcome and thanks for joining us.
Most of our audience knows who harnesses. They're not a stranger. com site or our cloud native Now cloud native site.
Every, you know, harness is pretty well known, but there are a few people out here maybe who don't maybe just get started or Yeah. Maybe just get started or not familiar. It happens.
Why don't you, we start here. Why don't we tell 'em a little bit about Harness Martin? Sure, sure.
I, I mean, it, it's really interesting. I will state I'd like, I've, I've been at Harness for a month. Okay, sir.
A long timer. A long Timer, but I, I previously was a customer for four and a half, five years really? So we were a very early adopter.
So I know the products really well. Uhhuh, so Harness is a, it's a modern software delivery platform. Yeah.
And it, it started in that core of cd that was where the core of it began, but it's kind of stretched out from there because, you know, as the product's matured, it's actually just become more of a, well, how do we help developers deliver software securely? Well, A as across the whole piece well itself, quite frankly has matured, right? Yeah.
It, it used to be, so there used to be, I used to call it the continuum of CI ICD. Yeah. You never said ci cd.
And, and so that was that continuum of, but now CD represents, I think, whether it's GI Ops or it represents, you know, from planning Code architect, architecting through the IDE through the integration. It's not just that point of deployment anymore. No, Right.
It's, it that's exactly right. And it's all the checks and balances that you need to make along the way so that by the time your software gets to production Exactly. Gets in front of your customer.
That's it. It's, it's almost a non-event, right. It used to be that the, the act of pushing the button to deploy the software was the culmination, right?
Yeah. Management, but now it's sort of an management. Yeah.
It's an anti-climax. Climax now, right. Because everything's, It should Be well if it's done right.
And, and quite frankly, harness has been one of the leaders in bringing that sort of, uh, mindset to how we develop and deliver software to, to the market. You know, I always find it a, a tremendous endorsement of a product when you've got an X customer who, who comes aboard to especially four and a half years using that. Yeah.
So yeah, you definitely know the product. Yeah. Love the product.
Well, not only that, I gotta assume you love the product. Yes, absolutely. Otherwise you wouldn't go work in the company.
No, no, that's absolutely it. Love the product. I mean, helps deliver software better.
So What was your role when you were using it? Or what roles have you had while you were using? Uh, essentially I was, uh, DevOps director and then DevOps and IAS director.
So I was essentially responsible for the tool chain, getting all those things out there. So the software was deployed, um, that company had a hundred plus products, so with multiple tech stacks. So it was, it was a fairly broad, wide environment.
We were trying to make that, uh, in fact, probably the most common conversation I had is that like, deployments aren't releases. Deployments should happen all the time. And you're right.
Should be a non-event. You know, a release is a go-to market, right? It's a, Hey, there's this new thing that you want to see, but it probably should have been in production for weeks or months and had beta testers and be behind feature flags.
And that should just be all part of the process. Agreed. One of things I imagine was a challenge you could tell us is all those different environments, all those tech stacks Yeah.
And, uh, I'm sure they're all uniform and very similar. No, absolutely. Yeah.
Not, and, uh, tell us a little bit about, about that and some of the challenges of what a harness does in those kind of situations. So those multiple tech stacks, um, there was consolidation around it and essentially, you know, where Harness really helped was being able to build templates and, and then actually have some governance over the top of them to say, Hey, it might be Tech Stack A or Tech Stack B, or Tech Stack C, but actually it still had all the right security testing and it's had the performance testing done, and it's compliant with everything we need for that particular environment. And then it's okay to deploy and it should be a, shouldn't be a, like a fight.
It should be this is the policy and you either meet the policy and deploy or you don't meet the policy and you fix whatever it is that you need to do. Sure. Mm-Hmm.
You know, and, and then it's really about getting the right information to the right person at the right time. You know, it's that kind of, uh, I, I always think that shift left was done a little bit skew if, 'cause a lot of companies just shifted all the work left. Yeah.
And that is not the way to solve that problem. Didn't work very well. You need to shift the information left and it needs to be the right information at the right time in the right context.
So you, I and I, I'm not gonna take credit for this. I heard it on a webinar that we did someone else, and I don't think it was someone from Harness, but someone said, we need to shift everywhere. 'cause I think when we use the word shift, we are focused, like substitute the word focus for Shift uhhuh.
Right. We started putting our focus left. Yes.
We need to, but we need to focus right. Sometimes. Yeah.
And we need to focus right in the middle sometimes. And so we need to shift everywhere, right. Because we need focus.
And, and that focus, like looking at a picture, you know, it changes. Sometimes you gotta focus here, sometimes you gotta focus there. And I think that again is some of the, the difference between pure CICD DevSecOps versus modern software delivery software supply chain as some call it.
Yeah. Right. Um, is that, that that focus is a shifting focus?
It is. It is. And it, it, it actually plays into that whole thing.
You know, that whole thing of having like a bill of materials is great. Mm-Hmm. I've gotta build of materials.
I know what's in my software. But actually knowing all the things that happened, you know, that kind of The dependencies and everything else. Yeah.
All the dependencies. Who wrote the code when it went into which environment, the prominence of all that. Yeah.
All the CE of it. What the tests were that were run, you know, whether all those security things were done and what were the outputs and being able to see them in context at the right time. 'cause I think that is, I think focus is a great way of saying it because it is, you know, I need to know at the right time in the right place.
And having that information where the focus needs to be is, is the right way to do it. Absolutely. Rather than just saying, no, I'm just gonna make all this stuff go over.
Yeah, No it doesn't and I'm just gonna keep shoving it left onto the developer's plate. Mm-Hmm. That's not necessarily the answer either.
No, I, no. In fact, I, I feel pretty strongly about that because honestly, you know, if you work for a product company, and harness is a product company too, you know, what you really want your developers to be doing is building the features that make the customers really happy. Yeah.
And what you don't want them doing is all the toil and the, you know, stuff that isn't making No, no. Let me, let me explain. Let me put it to you this way.
If I told you I have a business model, I have my highest paid employees right here Mm-Hmm. Who are, you know, time constrained to finish their, in this case coding, but finish their task. Yeah.
And then I have a bunch of lower paid employees who do tasks that are sort of ancillary to that highest paid employee. And I got this great idea where I'm gonna take stuff off of the lower paid employees, lower paid employees plate, and put it on the higher paid employee. It's a great idea.
No, because, because after all, he is the higher, or they are the highest paid employee, let's just give them more. And this way we'll give these lower paid folks less. Doesn't that sound logical?
No, it doesn't sound logical. Absolutely not. And let's just keep putting more and more security.
Give it to him too. Yeah. Testing, give it to her as well.
Right? Yeah. The security of the testing.
Don't worry about that. Keep putting it over here until one day that whole thing chokes. Right.
And that developer goes to another job. Yeah. And you gotta go hire a new developer and it's, it, it, it, at some level, I, you know, and, and I, I'll confess I was guilty.
I, I kept, I was all about shift left for a long time. uhhuh, um, it, yeah. We need to shift everywhere.
It's not about shifting the work. I think that whether it's shipped everywhere or shift well, what we did, but that's what we did. Right.
Right. We said like, developers are gonna do ops, they'll do, uh, security too. Yeah.
Anything else we need them to do? Testing. Testing, do the testing, testing.
Yeah. Let's have them do Yeah, no, those tests. So that is an issue here.
I'd like to turn, we are here at AWS re event. Absolutely. Um, what's Harness doing here?
Uh, well, Mostly good question. It's No, uh, mostly we, you know, we want to show people our platform Mm-Hmm. You know, and we want to show how we work with, you know, work with the cloud vendors, to be honest.
Yeah. You know, and AWS are doing some exciting things, you know, and, and we're a big consumer of AWS in fact, you know, it's, it's, it's where some of our platform lives and, you know, and it will be going forward. So it's, you know, it's a, it's a great place to be and it's a great place to show how we can help teams deploy into those environments.
You know? I mean, it's one of the original tenants that was making, you know, CDs easy. Yeah.
You know, without having to write lots of scripts, without having to, you know, easy to do the right thing and difficult to do the wrong thing. That's what you kind of want to get to. And so, you know, we are here, we wanna show people that, and we wanna show how we can do it with AWS cloud and how we partner with them to do that.
What do, what do you, what does it take to stand out in a big event like this? 'cause there's so many people, so many great companies. A lot of noise and, and a lot of noise.
A lot of distractions. You know, that shiny objects for those that like shiny objects. Yeah.
So it, it's, I I honestly think you just have to show your quality. Like genuinely you have to show how you do it better than everybody else. Yeah.
It's not a case of just, you know, I I think shouting the loudest doesn't necessarily make you win. No. Uh, showing that you can do it and showing that you've done it and that it's repeatable and you know that you end up with that kind of final output that is gonna work that makes your developers' lives easier, that they have a great experience, that you've got a full supply chain that you are going through when you are delivering your software, that you can, you know, pick out where that problem happens, when it happened, why it happened, where it's deployed, and how you can then just push it out and fix it And do it in a short window.
Yeah. I mean, you might have 20 minute conversation, but you might have 30 seconds in most cases. Right.
To kind of get, get that attention. Yeah. And honestly, I, I, the, I I personally find the easiest way to engage is, is, is ask them where their pain is.
Like, you know, what's your pain? What, what makes your life difficult? And let me show you how we can make it easier for you.
Hmm. I think that as soon as you get to actually talk to a live person, one of the things that it fascinates me about this show, I spoke to Mitchell about it last night, is the amount of money and effort that vendors are putting into having video billboard, billboards on the sides of buildings on the top of cabs. The globe inside the cabs.
Yeah. Yeah. I mean the U2, not the U2, the, the sphere Yeah.
Right outside of, of Venetian here, where this thing's being held. It's kind of been taken over, but I don't know if you noticed by Google Cloud. I, I did not that I know.
It was brilliant for a second. I Actually filmed It. A lot of people were saying, come to the new cloud.
And I get it. This isn't, you know, this is Counterprogramming for Google, right? Yeah.
So I'm gonna give them a pass. And I think it is a beautiful, a brilliant piece of counter programming, but the amount of vendors who, we speak to vendors all the time, we all know what the economic situation is in the tech world right now. Yeah.
The amount of money being spent to shout loud, look at me, look at me, look at me. Versus investing the time into having conversations about where is your pain? Yeah.
How can I help? Yeah. Is amazing to me, I think it's, it's akin to buy, it's akin to cash off startups buying Super Bowl ads for $7 million for 30 seconds.
Right. Versus developing better product, developing better customer. Honestly, it's the relationships that, that make it work out.
Of course it is. And, you know, if we can solve somebody's pain, make their jobs easier, and actually, you know, that's how you build Customers. Yeah, absolutely.
And that's how you get customers to one day leave their place and come work for you. Absolutely. Right.
You didn't come to your harness because you saw their ad on the side of one of these casinos. Oh no, absolutely not. Yeah.
And I, I think that is, that's an interesting phenomenon here. And I've spoken to vendors, I said, are you getting Lead store? Right?
They said, we don't know. So it's, it's a really, So why are you spending the money? Well, a lot of people see it.
A lot of people see it. Yeah. That's one thing.
But I honestly, it's, it's a, it's a really interesting thing. 'cause one of the things that actually made me want to come work for Harness is, and I've actually seen a video of like multiple people where they've like customers where they're talking about working with HARs. One of the big things was the, every single one of them said, no, no, they're not a vendor, they're a partner.
They're not. And that's what I used to say too. Right.
They're not a vendor, they're a partner. They work with us all the time's. Like, how Can we solve the Problem Together?
That's, that's the kind of vendor slash partner you want to work with. Not someone who spends their money on Super Bowl ads. And so that's kind of, I, I'm gonna leave it at that.
I'll get down off my soapbox now. But Martin, what else can you want to share with our audience about what you, what you guys got going on here? I mean, We've actually had a lot of growth in the platform.
It, it's been like quite an exciting year. I, like, I still remember, you know, harness cd, and then Harness was CICD and Feature Flags. And you know, now they have some fabulous tools that they've added into the platform.
They've added in internal developer platform, which, you know, is honestly the number of people who have that desire to have that Sure. You know, make developers' lives easier, make things automated. And then they try and host the open source things themselves, and they're like, ah, it's actually quite hard.
And it takes a lot of toil. Mm-Hmm. You know?
Yeah. So, you know, harnesses is based on backstage, so it gets all the same thing. So Yeah.
Which A lot of those are as well. Yeah. Which is quite exciting.
But also I think some of the, some of the other things that have come in is the way, the way they've been building AI and ML into the, you know, into the processes. And I always find it interesting, right? Because I always feel like AI should be easy to use.
And so I know it's a disruptive technology in terms of the industry, but it shouldn't be disruptive to the people who are consuming it. It should absolutely be part of their process. It should make their lives easier, make their lives better.
You know, and I know Harness have been doing it since the really early days, right? They have their continuous verification tool, right? Yes.
Uses a, you know, ML and a little bit of AI to kind of say, Hey, you've deployed this, you, you might want to roll forward or, or roll back, right? Mm-Hmm. And it's been in there, but that's just kind of extended out now.
Yeah. And it, and they're extending that out across the tool chain and includes the, the new ADA tool, which doesn't matter whether you've got one or all the modules, you get the benefit of that. And, and they're using it to make things easier.
So, you know, we talk about a lot about policy as code, and, you know, making it easy to do the right thing, hard to do the wrong thing. I know I'm repeating myself with that, but that is a, you know, we want that to be the way, um, and, you know, generating those policies, getting AI to generate them for you, that's a massive time saver. Sure is.
And, and look, did I gotta be honest with you, this isn't the first time we've discussed AI in the last three days. Our interviews I come up, I'm not surprised it's come up once or twice, but three minutes into every conversation. Yeah.
But I mean, I, I think what you are really hitting at is sort of an issue that we have discussed these interviews, which is what's real and what's, yeah. What does rubber meet the road here versus what might be could be, should be, will be. Yeah.
Um, and I think, you know, if we were to fast forward and look at not just your interview here, but all of the interviews we did during this show and in three to five years, look back on them and see what AI is in three to five years Mm-Hmm. We'll probably laugh. Yeah.
Right. Because we didn't get it right. Right.
I mean, some things happened a lot how far off we may have. We've really been Right. Yeah.
Right. Some things happened a lot faster, some things will happen a lot slower and some things will never happen and some things we haven't anticipated will happen. Absolutely.
Um, It's just, and it's gonna be an interesting ride these next couple years as we see that play out. Yeah. But right now, I think we're starting to see at least, especially in IT development and, and you know, uh, in it in general that I call an AI for ops.
Right? Yeah. We're starting to see some real tangible ways that Yeah.
This does, I mean, Mitchell has put a ton to time in working around this with a group of folks we've been working with, and we're, there's real stuff going on. There's real stuff there. Yeah.
There's real's, real stuff going on. We'll See it, it's interesting though, right? Because like, if you look at that and think, okay, you know, this is what we do when we, when a person writes some code Mm-Hmm.
So the person writes some code and we, you know, we make sure it does all the right testing and everything. I, I, I think if you don't have that in place, adopting things that generate code, you know, automatically, like I feel like you can't start with that if you haven't got all the other stuff In my class. Well, don't have a foundation.
And so you, you're always building on a house of cards or on Luke brick sand. Yeah. And so that bigger issue, that's one of the things that scares me about ai right?
Is that I think for the next generation of developers, the next generation of students, the next generation of, of interviewers, if they're just trained on let the a AI do it, but don't understand the underlying Yeah. Yeah. Well, I, I think what it misses is writing software's not writing code.
It's, it's performing that function in a context of an architecture, of a set of, of a technology stack as a set of tools, as a set of processes and guidelines. Compliance, you know, you rarely start out with a blank sheet of paper without any of that. You, you might to prototype stuff, but it really software you, you've got all that other stuff you're building it within Right.
This context until we've got that context. Yeah. And that's one of the things that generative AI can do, maybe will do help us within some, at least to some degree.
But yeah, I mean, when I hear people say, yeah, I'm just gonna have it write my code. Like you can have it write code, but it's not gonna be software that you're going to use in most cases agrees, at least today. I, I, and, and that's, I'm not poo-pooing generative ai.
It's just that's where we are today. Yeah. I think it's, i I, my personal experience is it's, it's a, it's, it's a helper, but it's not a replacement.
That's, No, that's, it's, I think that's another thing that people have to realize. It's not putting the developers or the testers or anyone else necessarily out of a job. There might be some changes, right?
Yeah. There might be some jobs that you lose here that you make up here, but I think it's a helper that can 10 x people, right? Yeah.
Right. And that should be the goal. How do I 10 x this developer?
Who is that highest paid person on the totem pole in my, my development chain? How do I 10 x them? Yeah, absolutely.
And that's, And still I have faith in the, In the product, the output In the product and the output. Right. And the next, the people doing deployment, right.
Or doing testing or, I think it's anywhere in that chain, Right? It is. It's, it's the whole chain.
And I think as long as you, you are starting with that good foundation, you've got all the governance in place, then you can trust that code that comes through that's generated by something rather than someone Yeah. Mm-Hmm. Well, I think we're still getting that govern, that that's another, that's a whole nother interview.
You know, how are we gonna trust and, and put the governance in place from a security point of view of the, of this. But you can't make wine before it's time. Right.
It, this will come as well. Yeah. And, and it's gonna be an interesting ride as, as we get there.
Hey, we we're gonna wrap up for people who want more information about Harness though, and about a couple of these things we're talking about. com. Harness Dot ia Io io.
Excuse me. It's harness dot ia. And actually I, I also know that we have coming up, um, we're starting to do some like hands-on, uh, webinars for people so they can come on, build a pipeline.
Oh, that's very cool. Uh, they'll, they'll be available from, from the harness io site as well. You can sign up for those On demand.
And, and live as well. Live, Yeah. Live.
Very cool. io. We're gonna take a break here on our day three.
Uh, uh, AWS reinvent coverage. Stay tuned. We'll be right back.





