Universal Approach to DevOps – William Collins, Alkira
William Collins, a cloud architect for Alkira, explains why a universal approach to DevOps is required to resolve misconfiguration issues once and for all.
Transcript
This is texturing TV. Hey guys. Thanks for the throw.
We're here with William Collins. There's a cloud at architect around Kira and we're talking about the cloud security and this nasty bit of business call Miss configurations. Hey, William, welcome the show.
Hey, thanks for having me glad to be here. We've been talking about Cloud security forever and a day and I think part of the issue that we don't really get into is what's the root cause of this concern because the cloud platforms themselves are reasonably secure. It just seems that the way we can figure them is a huge problem developers are configuring these things and we don't know precisely what they're doing all the time and a lot of times they're making mistakes.
So, how do we go fix this problem? so just defining this problem in general like more broadly is we're looking at any changes that teams anybody in your technology organization is making Outside of the the technology teams and the the business is peer review. So things are happening changes are getting made and nobody knows what those changes are and Cloud just in general, you know compared to the the data center days is dramatically increased in number of changes in general.
So when you have all these different teams making all these different changes, first of all, you're introducing a lot of complexity because you don't have a standardized approach to what the changes are. You don't have a specific design pattern that's being deployed. And secondly, how do you do compliance?
How do you go through and manage these changes and the simple answer from a high level is you have to have a a designed in an intentional automation strategy to do this and enforce your strategy across all the teams the developers and anybody that needs to consume the infrastructure. How do I make sure that happens when every developer has their own little credit card and feels free to do whatever they want. Yeah, so that's where if so is organizations get bigger.
They Institute larger. Programs into their business maybe they think through like a cloud center of excellence and basically anybody in this company then wants to use cloud. They got to come through an intake process.
They got to come through the cloud center of excellence and go through this whole intake to be able to use infrastructure and as they go through this intake there's there's golden modules. There's golden templates that they have to go through that have this policy that have our business intent and our compliance and all these things built in To these templates in this policy. So is they get that infrastructure spun up?
All those things are built into the automation from the beginning because one thing to keep in mind is once something's out there. It's hard to pull it back in and remove it. You have to you know, get your intent in there before it actually gets deployed super critical.
Does that slow down the rating which applications are being developed and provisioned or is that more or less, you know wives tale that we tell ourselves but in reality it may not have any impact whatsoever. I think initially it can because it's a growing pain. So if you're used to having, you know, say you spin up a Linux server or Windows server and you're used to having root.
You can go through and do whatever is you you please on This Server. Well, that's not good. It's not secure.
It's never good for anybody to have root permissions over, you know, some sort of system like that and same with Cloud so in the beginning a lot of developers and teams are used to having too much access to do too many different things that are well outside of their scope. So as you reel that back in it is a growing pain, but once you get to the point to where you have your roles and responsibilities and your access and your identity stuff hammered out it becomes a lot easier and it's better for these teams because they don't have to worry about all this other stuff that they had to before, you know, their scope is narrowed. Yeah.
Do you think the bad guys are getting better at looking for these misconfigurations? Maybe this problem is going to grow worse before it gets better. The bad guys are always many steps ahead of everybody else constantly going constantly looking constantly scanning and you know, there's good bad guys and there's bad bad guys.
So there's good bad guys that go through and try and find holes and things and then they let businesses know they're like, hey, you've got this problem and you know, we want to let you know about it before a malicious actor comes in and tries to do something with it, you know and organizations nowadays are willing to accept that and you know, a lot of you know startups and even you know, AWS and Cloud providers have these bug Bounty programs to where they are willing to cough up some capital. And you know, so folks can come in and find holes and and let them know about it and you get a reward. So yeah, I mean bad guys are always ahead of the game and finding these things and the more software changes and the faster it changes the harder this problem is gonna get to solve so that's why it's important to try to slow things down and get a hold on on things.
quick do you think cloud service providers should be doing more to help deal with this issue? Because I mean they have a vested interest in kind of making it easier for developers. But at the other end of the day, they also have a responsibility for security.
So what should they be doing? I don't honestly and this is an opinion. This is me William Collins opinion time.
I don't think they should do any more at this point. You know, I think it's on the the Enterprise or whoever's building a platform. Here's the thing if I go and I build a house and I decide to build my house without door locks.
Hey anybody can build a house. There's lots of Builders out there. But you you know, you don't want to build a house without door locks.
Anybody can just walk right in and steal your your intellectual Capital your property. So same thing with building things in the cloud, you know, if you go out and you try to build a house without skills without experience and not even knowing like the outcome that you want to achieve and then you know, something happens and then it all falls down that's on you and same with building things in the cloud. You can't go in there willy nilly and just try to use different things and say, oh I'm gonna not really know about this, but I'm gonna deploy it and then, you know cross my fingers.
That's not a good strategy for anything. What is your sense of our shift to deaf secops? We hear a lot about shifting things left towards developers.
Is that for real in your mind, or is it more about really just putting the guard rails in place and letting those guys do what they need to do, but are we really gonna ask them to become Security Experts? I'm really glad you asked that that's a good question the shift left thing. It's almost kind of a word now that's being overused but it's super important and that's something that you know products like alkira in any sort of born in the cloud product these days have to give you the ability to to have a system to where you can shift it left where you can put your intent in the build pipeline in the automation pipeline before it ever gets deployed into a production environment.
So the new companies that are building on cloud now have to keep that in mind. That although it is an on them to make you shift all of your stuff left. It is on them to provide you the the ability to do so in the product and that's important because when you shift left you can actually like I talked about earlier you can enforce these policies and enforce these things before developers can even commit and a source control.
You can block pull. You can say Hey, you can have a policy set to to trigger to say hey, unless these policies and conditions are met. You can't actually even publish this or deploy it into Source control.
You can't commit it. So those are super important things and that actually helps to developer because it gives them a system in which they can work to where they have to abide by these policies and these outcomes, but if they don't they get a message, they're not allowed to continue forward until they meet those. You know that criteria.
Yeah. What is the role of the cybersecurity team then in this conversation where things are shifting left to what's left for them to do and where would they interact with folks if they needed to? So that's a that's a hard one.
And that's so networking and security just in my experience over the past 10 years of doing this. They've been like the last two pieces of dragging. Things into the cloud everybody else is on board.
Even the compute folks are like, yeah. We're we're automating things with cloud formation and terraform where we're deploying VMS and Cloud, but networking security were really slow to make this transition and now is devsecops and net secops teams are coming in. It's on them to provide, you know, they can't blame Developers for going and deploying stuff if they're environment has given developers enough permissions to do.
So that's on the the SEC part of it the Hat they have to go back and ring those permissions in and they have to build this policy as code and such a way to where the developers can move they can move fast, but they can move fast responsibly and you know, that's where coming up with the you know, thinking through the strategy looking at the identity and access management looking at the infrastructure is code being able to build these things in these pipelines to where it's convenient, you know, because at this point you have to come into the I call it the devops tool chain. So the devops tool chain now is universal. It's gonna cross network security compute all these teens.
They're gonna have to speak the same language to make this successful. how do I get all these people who are not devops Specialists, especially those security folks and to agree because do I just throw them all in room and lock the door until reason prevails or is there some other way of thinking about this? And in the earlier days when I was working with the Enterprise that is precisely what one Enterprise did with a lot of teams, they flew everybody in and we got in this big room and there was this gigantic whiteboard and they're like, this is the future this year.
This is what we're doing. You're in here, you got to figure it out and I'll tell you why that was an interesting few days. It was like nothing I've ever experienced.
But at the end of the day, you know, it's it it's got to come from a high level leadership change and it has to be one of those things to where It can't be a program or a project like this isn't an eight-month project. It's not a program with this budget tied to it. It is a cultural shift.
It's like it's you know, not a New Year's resolution that gets dropped in March, you know, it's a lifestyle change. So this is on leaders VP and above like sea level down to say hey, this is the way we're moving things forward and it's gonna be a slow incremental change it is because the bigger the business the more processes exist the more processes exist. The more red tape, you have all these different things that basically you have to go through manually because some of them, you know as processes get added over time.
Some of them you need you have to keep but there's some that are just we're put there for some reason and they're not even relevant anymore. You have to feed through all this stuff and understand it and as far as like talent and you know modernizing your talent the business has to put in I'm in the effort to up train and to you know, look at bringing in Consultants or you know Partners to come in and maybe give you a little a little steroid injection a little boost to get you going and to help, you know, show some results because you got to have some some quick results, but get the right foundations in place to where your people can come in and evolve like with this system. Do you think a lot of organizations though?
They come down or the senior leaders come down and they give the big speech and there's a bit of a sermon and everybody nods their head and but there's no tools or no plans. So everybody goes back to doing what they were doing before. So how do we kind of like close the gap between the intention which is good but sometimes the execution that is flawed.
It's funny that the more. Especially in the large Enterprise space the more these large Enterprises. I talked to in thinking back to the ones that I worked for over the years.
Every business is different every you know, one one thing that I'm seeing, you know, just specifically to your point is historically Enterprises were very hierarchical with how they're structured. So when a decision had to be made it's like okay goes from technical decision makers to like a manager to an associate director to a director to an associate VP and that's just on the network side or the cloud side and then it has to go down the security side and then all these people have to be in the loop. You have to get you know, 20 people on a phone call and then they have to be agreed before even a single decision can move forward.
So what Enterprises are doing these days are thinking through it's sort of like flattening that structure and giving I don't want to say individuals the autonomy to make these decisions and move forward with things but like breaking that structure into smaller structures. So decisions can actually be made without everybody having to be on the zoom to say yes. All right.
Well, hopefully it's gonna turn into something that feels more like a team sport than the traditional US versus them kind of approach that we have in place but William, thanks for sharing your insights. Absolutely. And back to you guys in the studio.