Prashanth Nanjundappa – DevSecOps in the Cloud – An Essential Approach for Growing Organizations
Cloud-native technologies are evolving very quickly, and this architecture depends on a shared responsibility model – especially when it comes to security. While cloud providers play their part in securing infrastructure, it’s important for organizations to plug this gap; that’s where DevSecOps comes in. In this session, you will learn some of the most common challenges and ways to work though them to help build secure cloud-native software without having to compromise on time-to-market.
Transcript
Hey everyone. I'm Prashant. I'm jeopath.
I'm VP product management at progress and my responsibility here is product management and marketing for Chef product line progress acquired Chef a couple of years ago. And I'm respond. I'm really enjoying the journey now understanding the devops that take off space and I'm excited to talk to all of you about why is the safe Ops important especially in the cloud Journey right with that?
Let me quickly jump and talk a little bit about what to expect in the next few minutes and a mission introduction about progress and Chef and then let's jump right into what is more Ops. What is that setups and why is it important in the cloud context? I have this is this is the you know through this discussion.
I am assuming that most of you are familiar with devops, but I'll touch briefly on what is devops, but the main focus is themself hops because Think that's the challenge which is which is faced by large Enterprises how who are growing? And of course some are we have budgeted sometimes the Q&A as well? So they will take any questions that comes as they come along or we can do it towards the end as well with that.
Let me switch over to giving you an overview of where progress is an organization and progresses or 40 year old organization and we have been listed in NASDAQ more than 30 years and progress has a host of product Suites The Common Thread among all of that is we are building software for developers to help build Enterprise class applications, and we have a lot of organizations using soft broker software to build Enterprise class applications and Run mission critical systems on it. Right the one of the and progress has grown through m&a and one of the latest addition to the progress portfolio has been chef and Chef has been around for more than 12 years and if Said the devops motion where it started its Journey with infrastructure automation or infrastructure's code and even till date we are helping organizations accelerate their devops journey, and we are designing products to have faster time to value and make it easy to use and of course help address different aspects of their organizations. They have options.
That's a cops Journey switching to why we all are here, right? So all of us are interested in building our software building of building an idea and making it available through our you know end users through software or Hardware choice, but the because of the competitive and bad man the time from which you I have the idea the time in which you want to ship needs to be compressed. But this is easier said than done there are three And that we need to optimize on one is speed you'd be obviously want to do as fast as possible.
But at the same time we want to balance the efficiency meaning we need we don't want failures. We don't want bugs. We don't want you know, if you find bugs we need to resolve that if there is a production issue we need to resolve that faster and last which is very very important which is typically an active thought which is this it mean is it compliant have we patched All the known security issues and have you opened any welder abilities?
Are we running the right certified software so that we we don't allow expose our data and our customers data into Bad actors so that they can hack into it and exploit it right. This is the this is the conundrum. This is the difficulty.
It's all of us. Help face, and we need to reduce this right and now more than ever. We need to accelerate because you know in the last two years or last two months alone, like, you know, when this when the covid hit there was such a big wave of digital transformation which involved Utilization of cloud Technologies, and this is not this is just the beginning and this is set a trend so that for people to move from on-prem or who are not even digital completely to about take up the digital transformation and in the heart of the digital transformation.
Is cloud right? So this is a survey result from flexora where they hold a large Enterprises and of course, we know any startup or a new company who are starting in they start with Cloud, right? They start utilizing Cloud native Technologies.
They go to one of the large Cloud providers, maybe AWS Google or Azure or many others and they start using native Services. I think that's that's something that we all understand but I wanted to spend a little time saying that that's not the trend only in startups, but it is also very evident Trend even in large Enterprises. So here also we see most of our most of the Enterprise according to this survey use height meaning they use private data something I'm private club as well as a public cloud and they also use multi-public cloud So This Cloud adoption is not just in A small organizations are startups, but it is also a very evident Trend in large Enterprises.
Also when you start adopting Cloud there is there are some threats right? There are some risks and there are some concerns and this is not not to say that these concerns are only in Cloud but this is more and more evident in cloud. And one of the biggest one is security and compliance.
This is one of the top concern and actually another one is cost and governance and third is human skill getting the right kind of skill, but I want to talk a little bit about security and compliance because this is this is where that's a cops can help before we dive into why it is a concern or well, you know how to solve the concern. Let's talk a little bit on why it is a concept and because the traditional approach towards security is very method in sequential. Right when devops wave hit the development and operations can came together but still Securities and after part as you can see here, you know first development is done.
So in QA, they do functional testing non-functional testing of load testing all of those things and then it goes to Security review and it comes to a heart This is this is because of the mindset and this is also because of the practices. And this kind of gets exasperated when we go to Cloud because in the previous if we go back to this slide here this in this methodology in traditional it this has been solved by putting governance early on itself, right? Whatever security points that had to be made they move many of those things before the dev by certifying the required hardware software that organizations can procure and utilize but when it comes to Cloud there is a lot of democratization on many dimensions starting with the tech choice is no more with it, right and developers, um have click access to any software they can procure and start using so security teams don't even know what software is being used.
So Going back they get to see only when it comes to Security review. So what happens stop? Right and similarly Technologies evolving at a Breakneck speed.
So if you are using let's say a fully managed service that version keeps changing. They add new versions they bring in new services. So this this is a continuous change and it is a very very fast change.
It is very hard for development teams to keep track of it and cloud while cloud service providers say they have security built in it's a shared responsibility model me as organization have equal responsibility. If not more to ensure that it is configured properly. The right policies are put in place so that we had using the service that cloud provider provides safety S3, or maybe Cosmos DB or anything like that is utilized in the right manner.
For example S3 is a great service right example to bring up this point. Where is three they provide both encryption on encryption. It is our responsibility as business unit to set the encryption on right this might sound very simple.
But this is this can be very very I know this can lead to very bad outcome if you don't do it and that's that's one example of shared responsibility model and last the scale becomes. So big automation is innovatable. You can't you can't expect your developers or even your Ops you to go do things manually you got to do automation.
And you know top performance use, you know, whoever is successful. They have definitely used devsecops. They have you they have seen, you know, advantage of bringing security early on are seeing, you know, speeding security up has given them outcome.
These are some of the examples where you can see the results of adopting of security first or security early Security in a mindset. Which will lead to faster business outcomes. And and difficult is the one which will help us in in that Journey.
So before I you know, and again I want to call out that there's a cops is is not a silver bullet. It doesn't solve everything and also it is not one single tool. So before we talk about that, let's let's spend a minute on now the definitions itself, right many of us are familiar with devops and devops is a combination of cultural physics philosophies as well as practices.
It's not a tool. It's a methodology which which brings which brings developers and operations are together so that they can cut down the time required to bring the product the production right and it has helped in faster time to Market. It has helped in Faster reliability and many other advantages right whereas difficult brings in security angle into that and helps bring security also into software development life cycle ensuring we shift left the security practices breaking.
The methodology that we saw here where security was an afterthought and bringing it into the stlc cycle itself so that we can we can have faster time to Market. And I want to call out one thing here that you know, before we embark on depths of cops from our observations as we have spoken to more than 100 hundred and fifty customers who have started adopting or even not upgrade in, you know, very Advanced stages security deposit me. They have their Ops methodology and methodologies in place.
This is foundational and so we can accomplish some of the things of devops but having devops and jail methodologies in place will give you that advantage and more chances of being successful in your website cops adoption. So looking at devsecops, there are few. There are few fundamental aspects that help make, you know, help help you think about how can I bring in or how can I be successful in devsecops Journey?
So these are some of the pillars that we believe are essential intensive cops first is secure configuration and that is making sure that you are infrastructure is configured properly and second. It is delivered securely and there is enough Automation and we would like to say automation not just the sake of automation but auditable automation. So if you have done automation, it should be Version Control.
You should be able to check who has intervened. Ideally, there should be a human free zone and human intervention Zone which should be segregated and any changes in human Freedom should be auditable. and then one of the very very important aspect which is not spoken enough, but I can't stress more the importance of it is people and skills and let's talk a little bit about each of these things.
And of course, yeah, you know, you got to measure in order to improve so measure monitor report and audit is all so equally important. But if at all there is one area, I think which we which I would ask all of you are I know attention if you want to be successful in that's me is people on skill because that is the least trust and that is the most top common area where organizations fail adopting this Like now let's look at look at about some of the challenges that are there in implementing or going after these pillars, right? So let's take secure configuration and delivery.
So for configuration and delivery, there are multiple teams involved, right? So collaboration is key. But it is it it's seldom really happens.
It multiple teams work in their own silos developers and operations of you know, that's if it's a mature organization then they are in once. I know if not, they have an Ops are also separates and before deployment they are in in block and that's where infrastructure as code or is he has helped but similarly if you want to once it is developed. It is deployed then compliance automation compliance and security also becomes a concern and these are different silos that exist and there are plenty of blockers if you want to proceed.
The answer to that again, which is most commonly used and where we have seen the highest success is adopting as a code paradigm. So if you take code as a parent a code as a Common Language across these teams, then you can not just bring them under stlc process. So what are those things if code is that if it is code you can test it.
You can increment it you can roll back and you can Version Control it and so assume that you have a security policy. Where going back to the S3 example, you need to have every bucket every data in address each to be encrypted. If that is the policy if you can codify that identifying all the data storage and making sure that it is encrypted.
then you have a security policy similarly in your development if you want to make sure that You know my application needs to be deployed on 256 MB RAM, maybe. Yeah, I know or 8GB storage or something like that. If you have some specification if you can codify that then your deployment is also available as code and you can deploy it if it doesn't work, then you you fail that and you have next version where instead of 8GB you upgraded to 16GB instead of eight.
Yeah or from 256 MB you go to one GB right? So you have this variations you Version Control. Then this is pieces of code, which is common and it can be integrated into your cicd pipelines or any any mechanism or any automation mechanism that you have and that has also kind of become fairly standardized or there is a there is a common pattern that is evolving in that and that's where policy at school comes in.
Right? So we have we have seen we are helping our customers accelerate their devopsychops journey through policy as code where they can have compliance policies where they can have security and governance policies are deployment and application policies. And of course infrastructure configuration policies, all of these policies can be codified and then go through the regular stlc process and then go to production, right?
This helps in far better collaboration. And enable scalability and most importantly shift left that risk, right? So the security blocker which was in the last page kind of moves into earlier part of your development.
So every developer when they submit a piece of code, it gets checked against all the policies not just you know, the development policy but also security compliance and any other policies that you're organization has and you get continuous visibility into every changes that happen. So some of the key benefits that is your, you know, your policy is documented and codified and secondly you have faster time to Value because you you crack or you identify issues faster in the cycle and third it becomes you you get fewer false positive. So there is less work for your teams and you are delivery Cycles improve and it is secure and last but not least.
And again this is going back to our people aspect you have single workflow and you have a common skill set that you are organization needs and this is one, you know getting into little bit of how Chef solves this we help Define business policies through a Common Language and they are you know, they're typically in various aspects various, you know PDF word dogs sometimes, you know, written physical documents which we help organize and code it. And we also provide a host of Premium content, which is pre-populated policies for your Hardware of for your operating system for your databases and even lot of cloud services as well. And then our tool change helps you to collaborate and even create and extend these policies and wherever there is there, wherever there is violation, we help even create favor staff and by definition or from from beginning we have been we have adopted a test driven methodology, but everything that goes through the pipeline so you get advantage of testing everything up early in the cycle so that you you have higher confidence of things that are getting delivered and last but not least did the single tool you get advantage of single artifact and all so single team can manage various aspects of here are development life cycle.
Switching gets a bit. Right? I want to talk a little bit about automation, which is another pillar.
Okay automation. I think is is something that is spoken a lot. So I don't want to spend time telling what importance of automation is or why automation is required, but I want to call out a specific attribute of moving from just automation to auditable Automation and we got to create a human-free Zone where humans are not allowed to there are no exit holes.
There are no hatch exit hatch where people are allowed to go monkey patch things, right? So, of course some in really really circumstances you might want to do it, but that is exception that rule. By Design, you have to have systems like this where once your code is.
Developed it could be your application code. It could be your security policy. It could be your compliance policy.
It could be your infrastructure policy. Right? All of them are cool remember and that gives you this Advantage.
So once the code is done you review it and you commit And then the software lifecycle kicks in which is you know, you you put it for testing and if it is infrastructure, you deploy the infrastructure if it is policy you test the policy. And once it is done graduated to test environment subsequently to staging environment. And then to production environment.
anytime things fail it goes back to changing the code which again version controls. And now you have already double controls over every automation that you have made up. Of course, there are different ways of achieving audit, but if you take as a code approach, this is one of the one of the successful way or away in which developers understand our common way in which you can apply security infrastructure as well as compliance policies in the same methodology for all of them.
So I want to I want to take a moment and switch over to talking a little bit about Chef cspm Cloud security posture of post poster management framework, which we have designed to help address some of the challenges that organizations are faces when they migrate over to cloud or when they start adopting Cloud if you're using infrastructure of service infrastructure as a service and Cloud, then you have to manage your operating system databases everything on the virtual machines that you get from the provider. But if you start using managed Services, then you use the platformer service the manage services that cloud service providers provide and then currently there is a huge update and Adoption of deploying applications using containers on a container container orchestration services, like kubernetes. So these are four different now tears where you will have challenges and we have Because of our feedback from our customers we have gone and assessed and provided the premium content that I was referring back in the policy has called code section for each of these sections.
So that organizations can start codifying their policies not just for in terms of you know, help manage their hybrid cloud of operations and have a multi-cloud governance and also bring in a cloud native cacd governments, but also, Move Beyond compliance and into the security area where you can you can ensure you follow a coded approach towards security and not just that you configuration a you know, is he is key and you you make sure that all of your configurations are in a secure Manner and last but not least you give a multi into and support for your multi-cloud adoption. So if you're using assured gcp and Cloud which are going back to our survey we saw that most of the Enterprises are using hybrid Cloud automatic load. If you want one software to bridge that still gap or to have one solution that works on all of the cloud this can well, you know, it's just cstm is get towards that Of any of that and let's look at one of the other challenge that we have, you know, you are going to face when you go on this devsecopes or option as I was talking the human skill is one of the most important aspect which is which is most commonly forgotten in this journey.
And as per this as per the report we see that the bridge the gap is building and it is extremely difficult for organizations to hire as you can see more than 60% of the respondent said it is very difficult for them to it was a very difficult experience for them to hire and it is the demand for this has also not help it's in it's good that evolves their sake of practitioners are now in demand and they are getting paid more than ever but it also brings the challenge of how to hire them. And and in our approach in our experience, we have seen looking at three prong approach for skill and also augmenting that with tools and processes is the way to bridge that Gap and when we look at the skill itself, there are some Niche skills that organizations need to have experts in which you cannot choose to upskill or train individuals because not not just because it is not it is difficult technology, but it is it also needs a Minds if my mindset change architect who is experience in database management or on-prem server infrastructure optimization needs a severe shift in mindset to go start utilizing Cloud native services to the best potential right? I'm not saying that they cannot but it is a big shift right wherever.
It is such shift. It is important to recognize that and higher. Higher laterally and wherever you have but that's not always a choice.
And also that's the most expensive and choice as well and risky as well. So you get someone who you don't know or you you don't know what you want. So it's a risky choice, but you have to make that you don't want to do that everywhere.
Right? And the other places is upskilling and reskilling so your developers your office teams. I think they have especially who are the individual contributors.
I think upskilling is the way to look at them and there is another way to another option which is reskilling right. So there are smes who are who have been in SRS right there have developers who have been focused on building applications. So bring them together.
Let's let these let them let them work in us one single team as a devops team or a scrum team where they can help each other three skin, and now we are sorry can do a little bit of coding and you are Developer can also understand some of the office responsibility. So you have self-sufficient team and also you have crossed the team members as well and needless to say with this you have to also choose the right tools processes and methodologies like policy escort. So again, all of us are here to ensure to learn and understand, how can I bring the idea that I have in my mind to Market or to my customers in the fastest possible way without compromising on speed efficiency or risk?
Right? Hopefully this was useful to all just to summarize some of the key takeaways from from this session for you. All please devops is devops or option is foundational.
It's not that without that you can't succeed you can't succeed. But with that the chances of success is higher acknowledge the skill Gap. This is really really important.
I can't just importance of this and have a very clear plan of reaching that same skill. Yeah. And auditable automation, why are right process and tools is essential not just automation, but auditable Automation and code is a Common Language plus devops breaks silos and policy as code is the key part which will you know, if you have adopted code code as a Common Language then policy as the code methodology you will help you be successful in devsecoption.
With that I'll pause and see if there have any questions. Otherwise, thanks for having a chance to talk to you all.





