Pyrsia and Ortelius – Tracy Ragan and Steve Taylor, DeployHub
Tracy Ragan, CEO & Co-founder of DeployHub and Steve Taylor, CTO & Co-Founder of DeployHub speak with Alan about their involvement with Pyrsia, an open-source software community initiative that utilizes blockchain technology to secure software packages from vulnerabilities and malicious code and Ortelius, a unified microservices catalog designed to track and version your microservice software supply chain along with all consuming ‘logical’ applications.
Transcript
This is texturing TV. Hey everyone, welcome back to text John TV. I am happy to be joined by a good friend of ours here at Tech Strunk TV, and and actually a First Time guest on text on TV.
Let me introduce you first of all the Steve Taylor and Secondly to Tracy Reagan. Hey Tracy. Hey Steve.
How are you? Or good. Don't good.
Great Steve. You're the first time we're here. So we're gonna make you go first.
Why don't you introduce yourself to our audience and give them a little bit of your background? Alrighty. So my name is Steve Taylor.
I am the CTO of deploy Hub and one of the lead contributors to the artillas open source project. That's under the CD Foundation been in the devops world forever and you know, pretty much Keep a pulse on everything that's happening and in new technology this coming out. Love it.
Thank you. And thanks for joining us Tracy you you've been here once or twice before but for people maybe aren't familiar. Give them your background.
I am the CEO of deploy Hub Steve Steve and I co-founded deploy Hub a couple years back to take on the challenge of consolidating all the devops intelligence into a governance catalog a hub of deployment data. So to speak I am also on the I served on I have a history of Open Source. I actually was a helped create the eclipse Foundation way back in the day.
I also started help start the continuous delivery Foundation. I was on the board of that for a few years and now on the opens open ssf board because security and S bombs is all all that we ever talk about and Steve is being humble. He's a main driver of the Persia project, which is also the open source project any search on the technology oversight committee for the city the CD Foundation as well as myself, so we're very busy very much.
I was actually out in Israel at yala devops, but two or three weeks ago. We had a good interview on Persia. So Stephen chin wasn't there, but we had a chance to meet with.
Fred Fred Yeah, and there was another person one of the folks from the company. They acquired they're part of Jay frog excuse me. Was it suhendra?
No, no, it was a gentleman. Anyway, whatever. We spoke a lot about Prince here and how that all fits in there and it's an exciting project.
But for today, I want to focus in first of all. With all the open source stuff and all of the the foundational work you guys are involved and I don't want people to lose sighted deploy how by there so you know what? I don't care if it's state Steve or Tracy.
Why don't you give our audience a little bit? What's the play about to the India these days and what it's about? So deployup is what we would call a governance catalog governance around the supply chain that you consume and all of its parts and pieces and how all those parts and pieces relate.
We all know. What a service catalog is pretty much a service catalog. You know, if you are Enterprises you service Town long to say, oh we're using this version of Oracle.
We're using you know, this version of all these Enterprise tools now if you break that down into microservices you have you have a microwave service. Yeah or a governance catalog that tracks the microservices. They're usage their Providence.
They are dependencies. They're as Farms their CVS and a lot of other what I like to call devil intelligence that we need to start using in order to build more intelligence systems more intelligent devops systems and starting to add AI machine learning into it without At Central catalog you don't have a central place to start cooking the data and that's what we're that's what we're all about. very cool and then the other thing that you guys are really kind of driving is the and I'm gonna miss pronounce it but really it's not a really yes particularly for tilius or really it's something else but the artillery is Project assume our audience doesn't know anything about it.
Steve tell him what it is. Yeah. So Abraham or tilius who we name the project after was one of the first people to create a world atlas and he did it by pulling together.
Little maps from all these other guitar cartographers across the world. So he was actually like the first open source guy back in I think was 1870 15 70 16 70 15 70. I'll get the date.
Oh, so he was able to pull it all together and that's kind of the the basis of ortelius. The open source project is to pull together all this data that's out there around your software, you know, we have especially in the microservices world. You have your Docker container, for example, then that doctor container contains other packages those packages contain other packages and we get this huge web of information that has to be sorted through to make sense out of it.
And that's where we within the artist project are pulling together everything to leverage that data. A and make it useful to people, you know, we've been we've been generating in in creating and using S bombs forever, you know the software Bill materials, but it would only come into play when an auditor marched down to your desk and said where does this come from and what we're doing with artillious and deploy Hub is bringing that into the everyday world. So every day you can you can understand where you stand with your with your software and how it's being affected as you developers Drive change.
I love it. Excellent. Excellent.
All right. Have we set the foundation here? We clear.
I think I should we should mention that artillias is incubating at the continuous delivery Foundation. It is okay project. So to CBF, right?
Yeah manage product in the incubation stage, which our audience is familiar that sandbox information graduation sector. um Glad we got this out of the way. Let's now talk about the news Tracy.
You want to share with us? So we started working again going back to the open source security Foundation. We started working with some of the challenges that they are currently having, you know, and I noticed I probably can't be heard that well, this is my microphones over there.
So we started looking at the challenges and one of the challenges around s bombs is s-bomb security itself. S bombs right now are not immutable. They're basically a text file and when you talk about s bombs and open source and building applications.
Everybody uses tons and tons of Open Source, right? every time one of those underlying components an open source component gets updated. You have a new version of your application and you have a new s-bomb and you have a new set of CVS.
Now those s-bombs are in text files and they said there any pretty much the devops pipeline NSD pointed out. Somebody might say did you generate an s bomb for this? Well now s bombs are more important.
The bind Administration has said hey, if you're turning software over to the government, you better be able to generate an ass bomb. How do you do that in a microservices world? But that's consuming all these lower level pieces.
You don't have the concept of an application anymore. So what we we thought about was how do you create an immutable s-bomb audit Trail? That can track versions and changes and aggregate that up to the applicological application Level and we started thinking about you know, what this is a really really good project a use case for a ledger.
How do we if we can build That Into The Ledger then, you know, then we might have a centralized place for for Enterprises for open source consumers to be able to start tracking changes in their open source, supply chain along with the S bombs and the cve's so we applied for a small Grant to do a proof of concept with the with xrp the xrp Ledger that's hosted by Ripple and we're very excited to say we've got a word of the the grant to do that POC. It's a small group. Okay, but we'll be looking at how to build out that immutable s bomb audit Trail so that we can have S bombs everywhere.
For example, I mean, I'm sure there's some Used to this question, but I I want to know what the s-bomb for the new lawn for Jay. Looks like I also want to know as a company who which applications that I have pushed out to my my production environment are consuming that version of blog per day. And what is the cve report?
And what is the s-bomb look like for that that at an app at a microservice application Level that is a hard question to answer but we can do it. We have the technology now. We're going to build that out through a blockchain.
I love that you're using blockchain with the two to make it. It's great use of the technology. So let me let me be clear here too, right having been in the security world for a long time.
There is some things. That cross over from security to compliance pix pii personally identifiable information. It was always a security.
Target, if you will, right and we want to protect pii But when it was codified. Into various security regulations it became a checkbox. in the compliance world and people when it when that transition takes place people start checking the Box just for the sake of checking the Box.
And they lose sight of why we check that box because that Pi is important it could. Really damaging or really, you know used in bad ways. I'm up.
I I am hoping that esperms. Don't become the next checkbox. That hey, I've got this great project that you know automatically using blockchain.
generates my ass bomb check Biden Administration once that's bombs. Cisa Since we need that pumps. check But what we don't do is look at the S farm and say, oh, geez, we got to update the package or we've updated the package.
So now we have the latest package, but have we run? Any test to make sure that that package has an impacted something else we're doing. Or you know like taking two drugs that kind of offset each other.
Does that package conflict with something, right? I'm afraid that we're just gonna take a check compliant. and and we lose sight of How all of this fits in whose job is it is it the developer?
Is it the devops engineer? Is it the security folk? Is it the SRE?
Right who who's responsible beyond the checkbox? Well, first of all, I want to tell you that somebody recently. I don't remember who said it was one of the still up hours one of the do I still up hours and they said security is not a checkbox.
So that is a really good point because yeah, I would I guess it's not in anybody in security would tell you that but I will also tell you that we went through a period in security five years ago. I call it the compliance Sarah where it became very checkboxy it is and if you look at a an F bomb. it's it's not pretty.
And there's you have it out there. And yes, I generated it. So what do you want me to do with it?
I did it. I have it. It's out there if you want to look at it, it's there.
What do you want me to do with it and that I think that's the issue and it's and it it being able to consume the information you generated it. But what are we doing with it consuming it doing something with the data and that's what we are focused on at deploy Hub and artillas is consuming we're consumers at best bombs and we want to pull that data in so we can start presenting it in and easily consumable ways. We're lazy at heart.
I mean we want things served to us and s bomb is definitely not served to us. It's something you have to generate. It's in the text file.
You have to try to read through it to determine if there's any problems at best what you should be using it for is to parse it and then generate a cve report to see what your package of vulnerabilities are. Consumption and Adoption of the s bomb process has to do with the difficulty of it being in a simple text file and it being very very ugly. You quite honest.
We want to be pretty and at the end consumable. So that I don't think there's an opportunity. To ingest as farms and create not work.
It's because no one wants to have more work tickets. It's created or anything but create follow-ups create workflow out of that that's bombing and I am just throwing it out. I know two people who might be interested in that over into play up and and stuff but it's an idea.
So one of the things that because artillious and deploy have our gathering all this data in when we talk about s bombs, there's nested as bombs, you know, so it gets really complex. And what we are doing is when we talk about The xrpl Ledger, we're persisting that snapshot of all those S bombs onto the blockchain which allow us to then look at your application historically, so If I want to be able to search and search all my applications and my Enterprise to see if any of them are using the log for J. That's a simple query that we're able to return that information.
It's not marching off and telling all the developers go tell me if you're doing this stuff. It's it's literally a couple clicks and you got your answer and then because it's in a ledger we can see when that is fixed so we can see that it was introduced at this point and then it was resolved, you know, two months later. It was that vulnerability was resolved so that that history and they search capability are very important for soft developers.
Now, the next thing that allows us to do when we have all this data is to add in open policy agents so each Company can decide what they trust what is their version of trust? So that's where you can do Opa against the information that deployhub has and in your pipeline decide. Is this a risk?
I'm worth willing to take or is it something I need to stop? so that's where we're kind of headed with the xrpl, and we're very excited about how it's going to really help us back the versioning of the The Logical application for Developers Love it guys. We're running low on time people who want to get more information about the project about deploy Hub.
Can you give us some urls? com is the easiest one or tilius is o r t e l i u s dot IO I just on the CD Foundation as well. So CD dot Foundation go to projects and you'll find artillery stairs.
Well. Fantastic. Hey Steve, you've made it through your first text drug TV appearance.
Congratulations. Now now we're going to expect you back more often though. So I'd love to be back.
All right. I hope to look forward to seeing you Tracy. It's always good to see you.
Of course. I don't know if you're gonna be in Dublin for this Linux Foundation ossf thing. No, they were not I won't but Tech strong my but if not Detroit for kubecon We're likely find Detroit in November thinking about its November October now.
I know it's just gonna be cold there. Yes, it will be you know how much I love the cold living down here, but hopefully we'll we'll see you somewhere. I'll be in Orlando devops world.
We're not gonna be there Sorry, but we'll catch up. It's like yeah, we'll get there. Hey, you can drive down from Orlando, but we'll talk.
Okay for now. We're gonna take a break here on Tech strong TV. We'll be back.
Thank you.