Exploring GitLab’s Innovations at KubeCon With David DeSanto | KubeCon SLC 2024
KubeCon in Salt Lake City showcases GitLab’s DevSecOps platform, led by Chief Product Officer David DeSanto. The platform integrates AI to boost software delivery speed and security, emphasizing visibility and compliance. GitLab Duo, an AI-powered suite, enhances developer efficiency and collaboration between security and development teams. The discussion also covers trends in AI and model ops, along with future enhancements for Duo Workflow.
Transcript
This is Textron tv. Hey, everyone. We're back here live at, uh, CubeCon in Salt Lake City.
Cold Salt Lake City, I might add, but Salt Lake City. Nevertheless, it's a great show. We've got a busy, busy floor.
You'll probably see stuff going by. Those are not props. They're real coming by our, our booth here on the floor.
I'm really happy to introduce you to our next guest. If you, if you watch Text Drunk tv, you've seen him over the years. Unfortunately, I only get to see you at shows lately.
Yeah. But he's my friend, David Desto. David is, uh, chief Product Officer at GitLab.
Correct. And has been for a number of years now. And beyond that, though, David's one of the genuinely nice guys in this industry.
We, I love catching up with him, and he's never shy to give his opinion or tell us what's going on. David, welcome. It's great to have you, man.
Thanks for having me. It's good to have you back here. The beard looks a little shorter.
It's a little shorter. I went to the bar on Saturday before he flew out. It was like way too long.
All right. I did, I look nice for our, uh, our time together. Absolutely.
Well, you kind of look at this shirt, David's wearing, he wore it because I usually wear the loud flower shirts. Yeah. And I went, I went preppy today and, and he went wild.
So yeah, If everyone, like, I actually packed this for this. I wanted to be somewhere in there in Alan's Galaxy. Of course.
Yeah. I had, I known. But anyway, David, it's great to have you on.
First of all, look, our audience knows GitLab, but let's talk about what's new with GitLab and maybe focus in, then we can focus in on some of the projects that are kind of near and dear to you. Sounds great. Yeah.
So for those who are not familiar, GitLab is a comprehensive DevSecOps platform. Means that we support everything from planning to coding, to building, deploying, securing, all the way out to monitoring the applications deployed, using GitLab. And for GitLab, we've been very much focused in a couple of areas as we continue to grow the platform.
Obviously AI is one of those, and we can talk about that a little bit, but we wanna embed AI into that to help people deliver software more quickly, more securely and so forth. We're focused on visibility as well right now, helping customers better understand their usage of GitLab, how uh, the applications services they're deploy with GitLab are being used and helping them close that loop with real data and of course, security and compliance. Big thing for us, uh, I joined GitLab in 2019, as you're aware, let everyone know to add Secur and compliance to GitLab.
And that's now Ultimate and it's the fastest growing part of GitLab. Well, it's, it's probably the fastest growing part of DevOps. It is.
Um, and you know, I just a quick plug. com. Oh, I'll have to check that out.
Yeah, we just launched today. There's, there's stuff there. We took some stuff from DevOps as well.
Um, but security is equally as important there as, as you know, um, David, the last time we spoke, I think it was probably RSA was RSA after Paris. Did I talk to you in Paris or We, We, Giev was not in Paris, right? That's right.
So it was RSA. Yeah. It was weird.
It was the first Cube con, but we actually had our first company all in person event since the pandemic company was 300 people. Last time we did it, it was 2200. Wow.
And so we were all together for a week. Good for you guys. But it overlapped with Cube Con first time.
Yeah. Okay. It's always another Q con.
And we're, and we're here for this one. Exactly. But, uh, at RSA we spoke about Duo We did, which at the time was kind of really, you know, catches stride.
First of all, assume people don't know duo, maybe. Yeah. Let explain to them and then tell us where we are on that.
Yeah. So, uh, GitLab Duo is our suite of AI powered features and workflows within GitLab. It's why we've now repositioned the company as an AI powered DevSecOps platform.
We truly have embedded AI into the foundations of the product. And so what that means for those who are not familiar with DUO or trying to understand what DUO does, uh, it does everything from helping you with planning to coding, to troubleshooting your CICD pipelines and helping you resolve security vulnerabilities. And so, uh, last time we got together, duo Pro had just come out that's been focused on developer efficiency.
So it has the code suggestions, code completion, code generation in the ID chat, helping you understand the code, refactor the code, fix the code, generate test cases for it. And of course, GitLab has been known as a security company for the last several years. It comes with, uh, control.
So you can govern how AI is being used by your team. Uh, since then, we actually launched DUO Enterprise. This is now focused on operational efficiency for the entire company.
And so that includes helping you summarize conversations and planning, generate descriptions of what you wanna work on, helping you get code review, uh, through it a lot more effectively with summarizing the code review, helping you fix issues as part of code review. And then the two that I am the most excited about and we've seen a lot of adoption on are our root cause analysis, helping you troubleshoot failed. CICD pipelines.
An example of that Power a customer shared that, uh, with DUO Enterprise, they had a failed pipeline over a weekend. They had a big push that was going out on Monday, but the maintainers were not available. It was very late in the day.
And developers had a failure in their pipeline. Duo helped them resolve it and get back on track. And they were able to ship the code on Monday as planned.
The other one is vulnerability resolution. This allows developers to be able to click a button and have duo resolve a vulnerability that's introduced. The reason why I'm so, uh, passionate about this, not always my background, security, security, but I truly believe developers don't wake up in the morning and say, I wanna write zero day vulnerability in my application today.
Right? No. They wanna write really good code.
And so if you can help them do that, they learn from it. And so during their merger request of our security scanners, find a vulnerability, Joeo can resolve that for them, explain to them what it did and why it was vulnerability. And they learn to not do that again.
And now they've resolved the vulnerability at the time of commit and it doesn't hit the security team later on in the process. Absolutely. So very, very, very powerful.
And that again, is, uh, a customer in financial services told us, uh, that feature loan, and this is actually a really cool statement, has gotten their security teams and developer teams working closer together and not pointing at each other. You know, we run an annual ecop survey and it's always been, you know, 60, 70% say it's the other team's fault. The vulnerability is there and that's going down.
It's because Joe is helping bridge that connection. The teams are working better together. I love it.
You know, David, I I've seen some, uh, studies actually I think was a GitLab study. Yeah. We had our eighth annual over 5,000 respondents.
Again, You know, how much time did developers spend developing Yeah. A minuscule amount of time. So I think it's important to take, adopt this approach that duo's taken, which is, it's not enough just to tell the developer, Hey, there's a bug here or a vulnerability here.
This coat's no good. That great. That's a fine beginning, as they say in Las Vegas, right?
But if you're not gonna fix it, automate the fixing of it. You're making them more work, less time developing, more time doing this. And, and quite frankly, in today's day and age with magenta AI and Generat AI and everything else, if you can't automate that, you really aren't helping the situation as much as you think.
No, absolutely. I, uh, one stat that came outta that survey, which I think is what you're referring to, is there's a drop in developer responses on how much time they spend coding. So last year was 25%.
This year it dropped to 21%. Yes. And that tells you a couple things.
One's related to CubeCon, we're putting more and more on the development team. So they're now spending more time maintaining CICD, maintaining deployments and monitoring of those. And that's something that pulls away.
I started my career as a developer. I know it's hard to believe, Alan, that I'm not like 25, but many years ago when I started developing 25, to me, I'll take, I'll, I'll take it out, I'll take it. Uh, I started my career as a developer.
If I was spending 21% of my time as a developer, I'd be frustrated too, right? Yeah. And so where DUO comes in is it's helping shift that paradigm.
We talked about platform engineering right at the beginning. Platform engineering teams are usually like one platform engineer to like a hundred developers, right? Security is similar.
And you're right. The best way to get the developers out of those other things and working on the most strategic work, which is their development work, you've gotta empower the teams around them. Also with ai, that's why DUO is not just for developers, it's for everyone in the company.
So everyone gets more efficient because you made your developers a hundred times more efficient, things around them are gonna break, right? And so that's what we've been focused on. Now you mentioned AG Agentic workflows, and one thing we announced at our GitLab 17 event.
So for those who've not seen it, uh, you can go and stream it, it's available online. Uh, we talked about where we're going over the next year, and one thing we announced at the end, it was kind of our end. One more thing, uh, was that we talked about the next phase of duo.
So AI today is very reactive. You gotta go in, ask it a question and check click a button. And that works great for some use cases, but we don't see that as the future of ai.
We see it as ag agentic, or we've been calling it AI agents. Yep. And that's where they can become more proactive and take decisions, make decisions on your behalf proactively.
And a great example of this is you have a production incident and you know what line of code it is that caused it. Why couldn't an agent just quickly fix that line of code versus you having to go all the way back through the process into planning and pull it all the way back through? Uh, so we announced to do workflow as part of it.
Uh, today it's still in a proof of concept stage. We only have have it out with a handful of customers. But our goal is to get it to beta early next year and to GA by the middle of the year.
And we're focused on initially helping with planning and software creation. And so, uh, what dual workflow is doing in its proof of concept is helping organize your backlog based off the most urgent things based off what's having for the business. It's helping get through code review, serving as the code reviewer for the human, so that way you can actually have code review at any time of the day and get feedback based off company standards as well as be able to fix the things in your code base or deliver new features that are the more low hanging fruit, we'll call it, operational improvements.
And that developer spent a lot of time on instead of working on the strategic functionality. So dual overflow today has helped do, as an example, grab an item in the backlog that is a new feature, but lower hanging fruit, uh, be able to create that feature because DUO Workflow understands your entire code base. And GitLab as a platform also understands your CICD, your production, your planning, all the things around it can create that feature based off the description and be able to submit that for code review.
And so we actually did this with a recent feature. Uh, we wanted to improve how DUO is perceived for performance by the customer. What that means is, is it actually connected to the cloud infrastructure?
Is the streaming working for chat and co-generation? Is it able to connect to our backend security services, develop your resolved vulnerabilities? And so we created a new widget in the product.
Well Duo grabbed that, wrote the code, including not just the software, but the docs update for the doc site, uh, manuals that we create. So developers come in, understand what the code's doing, and sooner that as a merge request that a human then reviewed and then merged and sent out to production, that would've been something Wow. We would've had a developer spend time on.
But it's more important that they're building the more strategic things like helping re reduce false positives in security, helping you get through planning more effectively. And so that's what we see as the future of ai. And I Mean, but just think, look, we're sitting here talking about this.
Yeah. 15 years ago, 20 years ago, if you would've told someone they're gonna have an agent that does that for them, they would've thought you were on drugs. Honestly.
Yeah. Well, I I'm gonna say just a couple of years ago I was being kind. Yeah.
So the way I look at it is like two years ago at CubeCon, I was asked the question like, what is the next step? And I talked about DUO Enterprise and like DUO Enterprise has become a, a thing. But the idea that large language models will be far enough along that they can have larger context, not just larger context.
In the case of US Duo is using multiple models and, and DUO Workflow is actually using about five models to do what it's doing. But it can do that because there's enough knowledge now that we can actually share the information that needs to know about your organization. And so what I would say is, uh, our goals have duo workflow be part of your team.
Just another team member there helping out A digital, a digital team member. Yeah. We've been referring to it as your AI team member.
And so we're really excited to bring that to beta, open it up to the broader GitLab community, and then bring it to general availability next year. Uh, but that's one of the things we're working on next, Like right after January or later next year, Mid-year next year is what we're targeting for it. Uh, maybe earlier next year.
But we're on track. We announced the plan at that GitLab 17 event. Right.
Which was beta by the end of our fiscal year. For those who are not aware, I dunno why you would be, but our fiscal year ends in January. So we're shooting to make it available to brought our customers then and then beta shortly after that in GA at the midyear point.
So maybe next year at this event, I'll be telling you about what it's doing as a GA product, but very excited about it. I'm thinking RSA is the end of April. Beginning of May.
Yeah. That'd be a good time to talk about the lunch. Yeah.
So I can tell you about some exciting stuff leading into that. 'cause you're wanting to know Go ahead. So GitLab, even though we talk about AI a lot, 'cause it's what everyone talks about, CubeCon feels like an AI event now.
They All do. Um, but we're still focused on security and compliance. Uh, we shared at RSA that we had some acquisitions coming.
We actually acquired xi Yes. Leading solution for SaaS. mm-hmm.
And Ilian who led software bill and materials and SEA very cool. And so I'm very excited to share with everyone that the oxide technology is fully integrated into GitLab. Now.
We launched our advanced SaaS capabilities. So now we're able to validate whether it's a false positive Yep. Trace the code flow.
So both the data control of it, but also the actual data flow of it. And that allows us to then also predict vulnerabilities that could be in the runtime. And so very powerful.
And now we're working on that resilient technology. And so by RSA, we expect to have both those things fully integrated in and talking about what we're doing next around application security risk posturing and so forth. Uh, but very exciting acquisitions and available today.
Absolutely. And finished ahead of time. Yeah.
Uh, we weren't gonna have oxide integrated till about RSA. We finished several months early. It's very exciting.
It's six Months since RSA. Yeah. I'll just quick, quick plug.
We'll be doing the 10th annual our DevSecOps event at RSA this year at Moscone Center. And the, the theme is, um, DevSecOps and AI in an AppSec Yeah. Context.
So in line, as you would expect, and we'll be announcing call for speakers and sponsors and stuff, you'll be able to not register for it at RSA, I forget what they call it. Put your intents down. Yeah.
If an RSA attendee to attend it. So yeah, looking forward RSA is gonna be here about five months. It's crazy.
It's crazy, isn't it? Like I actually, as I was leaving for Q Con, I realized, uh, the end of the year is only six, seven weeks away. It's kind of, You got reinvent.
Are you doing Reinvent or you not? Uh, we'll be at reinvent, but you're not, you. I will not be there.
Good for you. Uh, but our CMO will be there about half of my leadership team, uh, the leader that leads the ICD will be there and SaaS platforms, well They'll be there. So, We'll they have an analytics and We'll talk to the powers that be about adding some GitLab folks over.
Yeah, I uh, you should definitely do that because we will have some announcements there as uh, related to reinvent then You're into the first of the year and then Yeah, we're Off then. It's our say running man. But yeah, the last thing I wanna touch on that we're working on that I think will be exciting for everyone, CI IC is still the core of GitLab.
So again, we talk about ai, we talk about security and compliance. And so we've actually now rolled out our CI ICD catalog. It's a capability in the product that is great for developers and for platform engineers where you can define CI components and then share them in the organization.
So now if you're a platform engineering team, you can have good templates that you want people to apply in their CI so that way they can scale their environment. 'cause your team is usually not as big as the development organization. What I'm excited about is that it's not just been companies adopting it, customers adopting it in their own organization.
We open it to the broader GitLab community. com that everyone can pull from. And this involves not just GitLab contributing, not just customers, but our partners like Google Cloud and AWS are contributing components that you can then easily adopt and deploy your software out into those hyperscalers where you run your code.
Sure. Uh, and then also has now been, uh, broader community con contributions as well. We've seen, uh, community groups, uh, like Lennox Foundation also contributing to that.
And so now we have hundreds of components that, you know, if you adopt, will work exactly as you want them to work. And that's just allowing people to scale their CI faster than they've been able to do before. And we're seeing people talk about where if they start a new project, it was months to get up and running and get stuff shipping.
It then turned into weeks with things like cloud native and what's talked about at Kubernetes and CubeCon here. And now customers are talking about it being, uh, minutes or days from their idea to starting the project, to building the CI and pushing the code out. And so, uh, a customer ally spoke at their actual event a couple weeks ago and they shared that with things like CI ICD catalog, our remote development capabilities where you can just one click and have your developer environment, they're having developers contribute, uh, net new to a project, never seen the project, uh, within minutes having their first commit to the project.
Like that's incredible. Yeah. And that's the power of GitLab as a platform, so.
Love it. Yeah. And lunch is open for everyone.
So youre here Lunch time here. Go To lunch. Lunch.
If you see David, say hello. Yeah. Uh, David, thanks so much man.
So a Pleasure to seeing you. And I'll say, check out our predictions. They're gonna be out soon.
Oh, we Didn't hit that. Go ahead. So just quickly for everyone, 'cause I know we're, we're at No, no, we're on overtime.
Go ahead Man. Uh, for me, I'm seeing a couple of trends I thought would be interesting. Uh, model ops being able to, uh, version AI models and ship them production.
I see that becoming a core part of DevSecOps next year. Really. It's still a separate environment.
You can do it both in GitLab, but all companies have to be an AI company now. Right. So I expect to see that next year we'll be talking about how AI and model ops is just a part of DevSecOps and not a separate market.
Uh, the other is the agentic workflows. Gotcha. I expect to see, uh, lots of agents.
A Lot of agents. A lot of agents. Right.
And that's gonna have its own headaches, I think. Yeah. And then the last one is just the trend of what happens in Cloud native.
A lot of customers still today talk about their cloud native or their cloud focus, but they're still running some in data centers or running virtual machines. And the idea of development and production will truly be blurred the way that we've talked about Q Con for years. And so I'd watch out for those trends and many more, but got a couple more that'll be out here shortly.
And of course our CMO, my leadership team will be as well. But check those out. And yeah, I wanted to share them because I think they're very topical.
You're the best. David. Yeah.
David DeSanto, chief Product Officer at GitLab here at CubeCon. As he said, I think there's gonna serve lunch. I'm not.
Yeah. And check out our booth. It's here as well.
Absolutely. com. Yeah, we're live at CubeCon.
We'll be back. Stay tuned.