Hariharan Ragothaman – Architecting a Unified Deployment Pipeline for Speed, Security, and Compliance | swampUP 2025
Hariharan explores approaches for architecting a ‘Unified Deployment Pipeline’ that accelerates developer velocity and productivity while enforcing robust security governance across the SDLC with integrated logging, tracing, and metrics. Additionally, by automating SBOM generation, our strategy delivers an organization-wide impact—enhancing transparency, compliance, and overall risk mitigation. This architecture also provides central observability of progress and aggregates metrics to monitor the health and maturity of deployments.
Transcript
Let me introduce you to our next guest. His name is Harry Hara Ram Ragman. Ragman.
Thank you. We're Gonna call him Harry? Yes.
Harry. Okay. Harry.
Harry's a technologist. He's here, you know, as he's not a frog, he's not part of Jfr, but he's here as a, a technologist with a keen interest in things. And I, I wanted to introduce him to you and give him a chance to talk a little bit about what he's really finding interesting here and, you know, kinds of things he wanted to mention, uh, that he here at Swamp Up.
So first of all, Harry, welcome. Thank You so much for having me. Yeah, it's my pleasure.
Yeah. Talk to us about what you're doing here at Swamp Up. So, uh, my first warmup experience was in 2023 when it was hosted back in San Jose.
I remember we were there. Yes. I think it was a complete pleasure.
I really enjoyed it, and I had the opportunity to, uh, work with, uh, and interact with a lot of jfr, uh, employees and, and to know more deep about Jfr products. And I always asked by to, you know, speak at Jfr. So this year actually, I spoke with Jfr on one of the frameworks that I had developed.
Um, it was about, uh, optimizing, uh, infrastructure deployments and bringing in both, uh, uh, accessibility, security and speed to them, um, such that, uh, you know, it, the overall time it takes to bring a service to production is rapidly reduced. Oh, yeah. Yes.
So, so you actually took the Jfr platform Yes. And developed sort of your own framework. That is correct.
That is improving security, quality and Accessibility. Accessibility, yes. And you did that at your, we're not here talking about where you work or anything like that, but you did that at the place you were working and Yeah.
Uh, and, and like what I'm trying to say is you did it in a, a commercial setting. It wasn't just a science experiment. Yeah.
So I think, uh, in one of the previous places I had worked at, uh, it start, we were trying to solve a problem where, uh, we were trying to sell, uh, unify different pipelines, uh, software pipelines, because in general what happens is when very large organizations, pipelines can get really fragmented. So unifying pipelines, uh, is very essential both for traceability and also cost. But at the same time, um, uh, you should also ensure that security is not an afterthought, right?
So we wanted to ensure that like if you take a typical software infrastructure pipeline, you have the curation process, create creation process, the build, deploy, and then the run. So when that happens, we wanted to sort of impregnate each of those boxes and ensure that security is embedded in each of, each of each of those layers, uh, while unifying the various pipelines. And, uh, that was done in a very commercial setup, and then I decided to take it forward by also.
And that was a time when, you know, open, uh, you know, all the ai, It was just coming up A all the AI stuff was just coming up. And so I decided to, uh, integrate NLP based frameworks into that architecture. So very cool.
By using, uh, JFR x-Ray and, uh, uh, JFR Artifactory, uh, that helped in optimizing the overall time it took to deploy infrastructure. So I realized that by, uh, uh, inculcating a frameworks within into your DevSecOps pipelines, you not only make, uh, AI the whole pipeline safe and secure, but you also make it more accessible to not just engineers, but also people from, uh, other forms of interest. Because, uh, when you have an NLP framework, uh, up in front onto your service, uh, all the requests can be in plain simple English.
So that, that's, that, that probably sums it up and paints a picture. Yeah, No, that, that, you know, and look, and, you know, the beautiful thing is we saw here this year's swamp up. Yeah.
Every day we're seeing more and more AI innovation, more and more AI capability. True. So, you know, though, you've, so in essence, the framework is never done.
Correct. I think, uh, that's a, that's a great question. I think, uh, it, it's definitely an evolving architecture.
In fact, the future directions that we want to take that framework is, um, for example, the, the current framework currently just focuses on ensuring that you, uh, uh, you know, export and software build of materials and unify the various pipelines to put it in very simple terms. Uh, software develop materials is more about like, you know, imagine like a cake. A cake can have different layers.
Mm-hmm. Each, each layer can have, uh, different ingredients and each of those ingredients can be sourced from different places. So the, once we unified the pipelines and we were able to generate a software bill of materials, we kinda knew what our software contains.
But then, uh, we, we can extend it to like, potentially like SALSA frameworks that can tell you like what it's made of. And, uh, we could also take it forward by, you know, ensuring that zero trust is embedded into this framework. I mean, zero, when I say zero trust, I mean the five pillars of zero trust being, um, identity transport, authorization, uh, gateway and visibility.
So one way, one way of possibly extending the, uh, framework would be to integrate zero trust in a much more closer fashion. Because when you look at security as a first class citizen, you're looking at it, you can look at it from both, uh, top down and bottom up. Top down is more about ensuring that you use all the latest tools, AI, and ensure that, you know, your software will super secure and does not have any vulnerabilities.
But when you do take a bottom up approach, you take, you put in a lot of attention to ensure that the APIs you develop are secure by design. So yeah. I love it.
If I had to ask you to look into your crystal ball and say, all right, swamp up 2026. Yes. And I don't know if you saw, but they announced New York, I think for next year, That that is true.
Yes. Yes. They had a, they had a, they had a raffle that, that helps us to select which location, but then I think it was New York.
Yes. Yeah. Yes.
Um, where do you see your framework being a year from now? Uh, yeah, that's a pretty deep question. I think, um, one, we do want to embed zero trust much more closely, as I just mentioned.
Yes. Two, we also want to, uh, we had, we had benchmarked our, uh, uh, our framework and architecture with the then available open source AI models. We would probably do, uh, another round of benchmarking to see which it works well with three.
Um, we would also do a lot of like, domain specific tuning to it, because I've realized lately that, uh, there's a lot of power to small language models, uh, as well, because they have a lot more context. And I, I think we're gonna see more sml Yes. Over the next year as people realize LLMs are good.
But yes, you need the SMLs for some very specific domain expertise. Yes. So that's where I see the architects are evolving into.
Yes. Good. You know what we didn't mention?
Yes. If someone wants to go see this framework for themselves, how did they do that? Oh, uh, so it's actually, uh, we did have the opportunity to publish this framework, uh, in a conference in an IP conference that happened in Indonesia.
So the work actually is public, so, uh, Where can they go? So, I mean, if you follow me on LinkedIn, uh, it's our, like Google Scholar. It's fairly, uh, easy to find.
Is It on GitHub or anything? No, Uh, it's not on GitHub. It's on the I explore page.
Uh, okay. That people can, could go and reference. Yes.
Well, now you mention your LinkedIn page. How do people follow you on LinkedIn? Just, is it under Harry or, that's Correct.
Yeah. Yeah. Just my first name and last name.
It's Ma. Easy to find. Yeah.
Alright. There you go. Thank You Harry.
Thank you for covering on Text Drug tv. This wasn't so hard. Thank you so much.
It was a complete pleasure. Yeah, Absolutely. Hey, we're gonna continue our coverage here at, uh, JFR Swamp Up.
Stay tuned. You're watching Textron tv. Thank you.