Advancing DevSecOps with CloudBees’ Sacha Labourey
Sacha Labourey, chief strategist for CloudBees, explains how the acquisition of Launchable will advance DevSecOps in tandem with quality assurance in the age of artificial intelligence (AI).
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Sasha LeBarre, who is Chief Strategy Officer for CloudBees, and we're talking about this acquisition of Launchable by CloudBees and what that means for the industry.
Sasha, welcome the show. Hey, good to be with you, Mike. In my mind, at least, launchable Hass been interesting because it's kind of been at the intersection of this gen AI meets quality assurance meets DevSecOps, and it seems like that's a primordial soup of something interesting.
But, you know, why are you acquiring these guys and how do you see this all playing out? Yeah, it's exactly for that reason, right? It's, uh, it's interesting if you do, uh, kind of the, the map, uh, of, of all of the things that intersect with, uh, obviously there is, as you said, gene ai.
There is DevSecOps, um, and, uh, and, and QA is, is a, is a, an area where developers tend to spend, uh, a bunch of their time as well. And quite frankly, what's unique about Launchable as well is that, uh, there is, uh, uh, another very important intersection is that, uh, the, the co CEO of Launchable, har and que are, uh, have been a key, key, uh, key key CloudBees, uh, team members, uh, for a very long time. So, one more thing we had in common, How will this evolve?
Because we've been talking about security almost like it's a separate gate within a DevOps workflow, and yet we also all kind of intuitively understand that security is part of a quality assurance conversation. And do we need to kind of meld these two things, or are they separate functions within a workflow? How do you kind of see this all coming together long term?
So I, I think they, they are all related in some fashion, meaning they, they're important things, but they kind of get in the way of the flow, right? And so doing it right is very important. Um, nobody, you know, like everybody, every developer will complain about the time they spend going through security issues, for example.
But at the same time, they very much understand that having secure code code is important. The same is true for any of the QA activity, right? Uh, uh, stability or, or regressions and, and so on.
It's very important to achieve. And so I think it's more in the, in the how, uh, that, uh, a solution need to be found. Not so much as to, uh, whether we have to do it right, is, is the, the answer is in the question there.
Most of the time we've been talking about this in the context of shifting left, and I think everybody kind of agrees with it and concept, but when we push it to the developer, a lot of times they push back and say, the cognitive load is too high. So where does all this need to sit between where the developer is and the DevOps team, and what's the right balance? Yeah, I think, uh, I think it's, it's in the how again, um, because as you said, uh, rightfully so, the, the, the shift that, uh, shift left approach brought a lot of goodness to, to, to, to DevSecOps, right?
It made it possible to, to go and tackle issues, uh, much sooner when they're much cheaper to tackle and, and so on. So all of that is very positive, but what we've observed is, is really this quote unquote tsunami of, of signals going towards developers, and it just makes it hard to focus. It just makes it hard to know what matters, what doesn't matter.
And, and that's why we, we really were interested in, in, um, in launchable, right, the idea that you could do that in a much more efficient fashion, um, uh, that you could get help from AI, that you could, uh, uh, get the faster, uh, cycle time that, you know, all of those things, uh, impact the how. So it's not so much about is shift left good or not good, or should we do security or other type of testing, but it's really the how, and, and we think that launchable is an amazing way to improve that. How, On the, how point where does Gen AI fit in?
Is it gonna help us figure out the, the signal versus the noise and all those alerts in that tsunami you described? Yeah, I think it, it, it's, it's useful in, in, in multiple, uh, area. Uh, first it's not just LLM, right?
There is a lot we can do with, with traditional quote unquote machine learning. Uh, there is so much LLM out there that we sometimes tend to forget that there is, uh, another world outside of, of, uh, LLMs. But yeah, LLMs can, can be, uh, useful to, um, to, uh, deduplicate content to explain what the problem really is.
You know, uh, scanners or, or, or, uh, testing tools can be sometimes, uh, a bit cumbersome in, in their approach to communication. So you receive that stream of information, you have lots of duplicates, and how much is really about the same problem, and how does that really apply to your problem? And is would there be a better way to, to, to, to, to state that, to understand that maybe even in some cases, to, you know, to prioritize those things and, and be able to elevate what really matters versus not.
So yeah, l and m's, uh, as its place and AI as its place, um, in, in at many steps along, uh, along the way, uh, from that journey and, and what we're observing in some ways that the dev DevSecOps flow that we've built are very much human flows, right? Uh, meaning, it, it's really the human being being this big orchestrator that says, okay, I'm receiving this notification, so I'm going to do this and check that, and then I'm gonna look in this terms. Essentially, there is kind of an implicit workflow that's happening where the human being is the orchestrator, and what AI enables is really a way to flatten the situation and, and, and think, what is the work to be done?
What are we trying to achieve? Because maybe there is a better way than just to automate that human flow. Maybe there is a way to, to really redefine completely how that job should be done, uh, by leveraging ai.
So that's one of the promises we we're seeing with, um, with AI as part of, of testing and, and dev DevSecOps in general. What is the future of a DevSecOps team look like? Because in my mind, I can envision a world where there are humans and then there are AI agents, and they're kind of collaboratively working together with some asynchronous workflows, but how should people think about this stuff?
Yeah, I think we, we've been almost overly focused on the coding side of things, meaning a lot of the discussion, if you check out there, are really around, um, uh, is there still a job for developers, right? Will AI replace developers? So on the coding part, um, those are interesting discussion, but I think we're very far from, from, uh, from something like that.
And so what's more interestingly to us is everything else, right? If you talk to a developer, a developer is not gonna tell you, I hate coding. Uh, or, or if that's the case, they, they, they should think about potentially changing job.
But, um, it's, it's about the 80% of their times that they're spending not coding. And that's really where AI and LLMs can have a massive impact. Um, and, and in, in, in improving the life of developers and get them to do what they like, stay in the flow, stay in the flow as much as as possible.
Uh, one of the objective at CloudBees, uh, when it comes to AI is to try to, uh, uh, bring the time spent by a developer on non-coding, non-coding activities to, to zero, right? Uh, obviously it's aspirational, um, but it, it's, it's, it's a good aspiration. I think a lot of the folks I talk to are kind of torn in their minds.
They have, many have invested in DevOps, they have platforms, and they have customized those and extended those out for better or worse in some instances. And, and they're reluctant to give up that. But there's an argument to be said that maybe we reached a point where we need a new platform because the capabilities that we're in need for today and tomorrow, well, you know, we weren't thinking about that stuff five years ago.
So, you know, what's your advice or how do I kind of navigate this if I'm already invested in DevOps and I'm looking at these next generation platforms? I, I, I'm, I'm, I have to say that, uh, I I'm not completely, uh, uh, um, um, I don't know if I, I would say I'm hugely skeptical or, uh, I'm hugely open. Uh, I guess they're all true.
I think what's amazing about DevOps in general is the pace at which we've been reinventing ourselves. We are trying to deliver software better, faster, more secure. That's what we're trying to do.
You can call it platform engineering, you can call it DevOps, DevSecOps, it doesn't really matter. You adapt to the problem at hand. And I think different companies have different DNA, they have different legacy, they have different aspirations, and based on that, um, they should pick the methodology and the solution that fits their needs in the better way.
Um, but I don't think there is one single answer. It also depends on your size, on your ma on your maturity. So I don't think, uh, say, because Spotify did one thing, then, oh, everybody should do it.
Uh, it doesn't mean that because, uh, uh, uh, Spotify did it one way, nobody should do it, right? And, and, and you can see, uh, and we're talking to companies day in, day out about DevOps, and you see that their practice is vastly different from company to companies. They might each call them platform engineering or DevSecOps, depending on who you're talking to.
But when you double click and look at what they're doing, it's always pretty unique. Um, so I, I think what, what we care about is offering flexibility that makes it possible for you to embrace whatever makes the most sense. Um, I'm more skeptical about approaches that are very opinionated, that guide you in a very strict way, because they might work for you, but they might not work for a lot of other companies.
So I, I think keeping an open mind, uh, keeping also a, a, a a strategy and a a, an approach that makes it possible to embrace third party solution is, is extremely important. Right? We were talking about AI a minute ago, as you know, Mike, as a, as a, the innovation in, in DevSecOps has just been amazing in the last decade.
And so being able to leverage those innovation, uh, whenever you feel like it is, is, is a net positive, Right? And of course, what works today might not work tomorrow, right? So you need something that's flexible.
Yeah, exactly. I was, I was reading a, a very nice blog, uh, uh, a few, a few days ago on, on somebody, uh, talking about, uh, uh, the evolution of DevOps and then DevSecOps, and then platform engineering and going through it and listing the pros and cons, and, and you can see it, it's a journey. And reading this, I was thinking that's really their journey, his journey in, in, in that specific situation.
And that person was ending the article saying, actually, I'm, I'm having a lot of, uh, positive experience right now, writing bash scripts and pulling containers. And, um, I was like, you know what? Good for you.
Not sure it's gonna work for all type of companies, but, but again, it it's not wrong or right. It, it, it's what seems to work for them today. So, uh, go and do it.
Mm-Hmm. What's your best advice then in the leaders of DevOps teams that are trying to navigate a couple of things, they want, uh, to write more code faster and to be more competitive, and yet there are these, um, issues around security and also quality for that matter that, uh, there's a sense of, well, do we need to slow down to achieve that, or what's the right balance there? Because again, um, a lot of developers are, they're rewarded more on features than they are on fixing vulnerabilities, but yet fixing those vulnerabilities is a more pressing issue.
Yeah, I, I think there, there is, um, we, we, it, it's a matter of balance. It's a balancing act, and it's very important to invest on both sides. Um, uh, I think it, it, it would be a mistake not to leverage ai, uh, for productivity to go faster, code more, and, and so on.
It, it would equally be a, a mistake to not leverage ai, uh, to make your code, uh, safer, more secure. And, and, um, and, and so yeah, there is a, i, I agree. There is a period of, uh, of a bit of unknown.
We don't know what we don't know. Things change very fast. Uh, problems that you had three months ago, maybe it's not a problem anymore.
Uh, and what you think not is not possible today will likely be possible in three months, or is stick in six months. So I think it's, it's very important at that point in time right now when it comes to AI to keep a very open mind. And, and I, I don't think, uh, organizations should necessarily spend a huge amount of time, uh, uh, toying with a lot of things, right?
Because it's, it's pretty easy as well to, to get stuck in, in, uh, lots of, uh, of, uh, uh, experimentation left and right. They require pretty smart people as well. So I, I, I think a good way to, to do that is, is to look at some of the solutions out there and, and, uh, um, be able to test relatively quickly, uh, uh, is that solving a problem for me today or is it more aspirational if it's aspirational because the output is 20% of it is good, 80% is less good, maybe come back to it in six months.
Um, but there are solutions that will provide you with, with, uh, um, actual, um, benefits right now. And so prioritize based on, on, on, on this, I would say, All right folks, well, we're just coming off the Olympics and acrobatics was center stage, and at the old end of the day, then it's all about balance. Guess acrobatics and DevOps have a lot in common.
Hey, Sasha, thanks for being on the show. Exactly. All Right, you, Mike, Back to you guys in the studio.