Techstrong TV – April 4, 2024
Watch our live stream on Monday, Tuesday and Thursday weekly, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to DevOps, cybersecurity, cloud native, containers and deep-dives into specific technologies and best practices.
Transcript
Hey everyone, it's Alan Shimel for Techstrong Gang. We've got a great day. We've got what's going on with Intel, same old, new stuff.
Is AI really sustainable? Our LL M's commodities, we've got that more as well as a special guest on Textron Gang. Hey everyone.
Welcome back here. Happy Thursday to you. We've got a great text on gang today.
We've got three blocks we want to discuss. One is regarding a lot of information coming out on Intel. Some of it's good, some of it's bad.
We've got a very special guest who's gonna bring the intelligence on Intel to you today. We also have a, a great block on sustainable ai, sustainable by design with our own Echo Insights editor, Bonnie Schneider. And then we're gonna talk about in maybe the, the fastest instance of internet time, have LLMs already become commodities.
We're gonna discuss that more. Let's kick it over to our, uh, chief Content Officer, Mike Ard, who will jump in on this. Hey guys, always happy to be here.
We're gonna talk to Daniel about this next topic right away, but Intel's got a $7 billion operating loss and it's chip making unit. They're reorganizing the company. 5 billion from the government to go build some factories somewhere.
5 billion ahead here. I don't know. But Daniel, what's going on with Intel?
I know you follow him closely. Hey, wait. But before we do that, Mike, not everyone here knows Daniel.
Mm-Hmm. What Did You introduced Daniel? No, I just said we had a special Intel intelligence guest, but this gentleman right here, Daniel Newman.
Daniel is the CEO founder of futurum. com is the website, isn't it? Yes, sir.
Daniel, welcome to Textron Gang. Man, it's a pleasure to have you on here. Yeah, it's great to be here.
A number of the analysts of the Futurum Group have joined, uh, Techron over the years and over some different events. And, uh, it's, it's fun to be in the studio with you all. Um, yeah, I mean, look, Intel, uh, first of all, chip making, uh, the chip industry is cool.
Again, I just wanna point that out. There was a period of time where it was all about cyber DevOps and ai. Well, thanks to what happened a few years ago, the shortages, people couldn't get vehicles, they couldn't get laptops, they couldn't get their phones.
All of a sudden, chip making became the most important thing in the world. And I think you mentioned Mike, uh, when you talked, you said eight and a half billion dollars of grants. They also got $11 billion of loans.
They're building a super fab in Ohio that hopefully will bring the US back on parody, um, at least back to some level of parody on, in terms of what Taiwan is able to do. We don't make any leading edge chips here. We make none.
And that's a really important detail here for everybody out there in the audience, is that Intel has this kind of bifurcated role. First of all, they are a really important, uh, company in the United States. Uh, Gina Raimondo, the, the, the treasurer, uh, I'm sorry, the Commerce secretary ca came out and said, basically, they are a treasurer.
But here's why it's important is ai, and we're gonna talk about AI probably all the time on this show, right? Y'all talk about it quite a bit. Well, you can't run any of these software.
You can't do any of these developer apps. You can't, you know, build security applications without chips. In fact, silicon will lead the world.
I made a prediction three or four years ago, okay? I'm running a muck here. But the point about Intel is, yes, they reconfigured, they resegmented their business yesterday.
So you talked about a $7 billion operating loss. What we we're talking about there is they've now split to a products and a foundry model. So everybody thinks about these fabulous companies like a MD and Nvidia.
Great business models make a ton of money. Well, Intel is actually a fully integrated, uh, design manufacturer of chips. They make the whole thing from, they design them, they manufacture them, they sell them.
They were presenting their business as an integrated model. And the market wasn't fully understanding it because now they're coming out and saying, Hey, we're a foundry. We're a foundry as well.
So if they're gonna be a foundry, that means they're gonna make chips for Qualcomm. They're gonna make chips for Nvidia. They're gonna make chips for a MD By the way, they're gonna make potentially chips on arm, not just X 86, which crazy, which everyone knows them for.
So yesterday, they came out and said, basically, our foundry business, it is not making any money, but we went back and we're actually gonna show you what our business would look like if we were running a fli and we were running a foundry. Their foundry losing a lot of money. The fabs part of their business, though, is actually making a lot of money.
So Pat Gelsinger and their CFO, David Isner came out and basically said, we're gonna show everybody how this works. Now, why this is really important in the end is one intel as a fabulous, does very well, makes a lot of money. Two, they've executed what they call their five nodes in four years.
And this was a really important thing because the company needed to get back in some shape of design, uh, leadership, their technology leadership. Mm-Hmm. And let's face it, they fell behind.
Nvidia obviously jumped way ahead in, in ai. They's still way A-M-D-A-M-D across X 86 took market share, both in the data center and on pc. Um, and now we basically need to understand is Kim Patak Inger, right?
The ship, what he wants people to understand is he has help, right? The ship, but the foundry business, let's face it, if a US and the West cannot manufacture leading, leading edge, five nanometer, three nanometer, two 18 angstrom future nodes, we will fall behind on a, on a global scale. And that yesterday is important.
But on my last thought, I talk a lot, I'm sorry, my last thought is basically, when does this foundry become profitable? We're gonna invest 8 billion in grants, or eight and a half billion grants, 11 billion in loans. They're building all these fabs.
Everybody. It's gonna take three or four years just to get to a return on invested capital. It could be before.
You think it'll be that soon? I thought it. Well, they're talking three, four years.
2030 is when they're really talking about being able to start. Well, I'm just talking about the whole foundry business. Okay?
Yes. Those foundries themselves, they definitely take time to recoup cash. They came out, they were very honest about it.
They were forthright investors, probably didn't love it. But now they've done this great reset Mm-Hmm. And we now know what Intel's plans are and how they look as both a foundry and as a fabulous, I'm a little more cynical, um, and always am so Really, Pat Gelsinger, is he not now the new modern Lee acoa and Chrysler.
And this is a bailout from the United States government courtesy and the taxpayer, which is okay, but let's just say what it is. Well, they're not the only company getting grant money. So you, you know, every one of these fabulous and design companies, whether it's global foundries, whether it's Intel, they're all looking to get capital soer.
Companies like Nvidia, a MD Qual, they're all looking because there's innovation dollars, there's, there's foundry and development dollars. Um, look, when the, when the government's handing out dollars to push innovation, every company's gonna be looking to participate. Having said that, the reason Intel is so important, Mike, and, and by the way, I'm, I'm, I'm, I can be cynical about this too.
Um, the reason it's so important though, is that we don't have another option. We cannot completely outsource and offshore all of our leading edge development. And right now, the only companies that are developing and building fabs in the US are not US-based companies.
So you have TSMC building in the us, you have Samsung building us, and these are good partners. These are good allies. But at some point, you have to understand geopolitical situations change.
And if the US was ever required to be self-dependent, to be able to make its own leading its chips, so we can have these phones and these laptops on everything, next generation, vehicles and cars, you know, the lagging stuff we do, we do. Okay. You know?
Mm-Hmm. No one likes, when I call it lagging, by the way, Alan. Um, but the leading stuff, like, we wanna win ai.
And by the way, China, I don't care whether they get EEUV, whether A SML is shipping to them or not. This is all technical stuff, but, um, I Understand it. China will not stop because of the controls that we're putting into place.
They're figuring out their own ways. You saw iPhones down 33% last month. That's because they've backed Huawei.
They're pushing Xiaomi harmony, and they're making it easier. And Chinese more desirable for people to buy Chinese made products. And yes, the their, their economy has its own challenges As well.
No, no. But yes, it does have their own challenges. But iPhone, the iPhone market in China was like apple's, I, I wanna say third, second or third largest market.
Second I believe. And it's tanking because the Chinese are very good. The government, they're saying, Hey, national one, buy the local one.
Um, and, but I wanna be clear to take in your cynicism, in your point, when we talk about 8 billion and 11 billion, some people say, yeah, but they're building factories. It's gonna create all these jobs. Well, no, a lot of these foundries and stuff, and fabs, they, it's all robotic.
It's not a heck of a lot of jobs. But to your point, it is a strategic initiative on the, based on this country's need of high, you know, cutting edge chips. We can't afford that.
If there's a war in the Taiwan straits that we don't have chips or an earthquake, or an earthquake is yesterday, right. Or the day before. Um, so, so it's important.
Here's my cynicism though. I, I commend the loyalty to Intel. They're a national treasure.
They've been a national treasure for as long as I've been in technology. 30 something years. Are we, are we, are we putting too much money into a, an older horse here?
And is, is there some other ones that, you know, are we, are we kind of funding innovation by doing it primarily with Intel? Or should we be spreading those dollars around to some new growth? Yeah, Well, they put about 53 billion into this with almost five times that in terms of loans and, and, and other investments and innovation.
No one else has raised their hands. There's no other company that's willing to build a 'cause. It's hard, it's really, really hard.
I mean, TSMC has built a very, very robust, very important business on a global scale. But there's no other company that's saying we're willing to take on the manufacturing, the, the, the building, the plants, hiring the people, and building these leading edge chips. And the expertise is complicated.
You know, we, what we've seen over the years has been a lot of distribution of, of, of capabilities. You've got these adas companies like Cadence and Synopsis with IP arm, Mm-Hmm. That have made companies like Nvidia able to develop, build and, and offshore their chip making in a very streamlined way.
They don't necessarily have the, the Foundry expertise. So someone has to take that on. Having said that too, I kind of find these, like, I actually put a tweet out this week.
I said, we're gonna need chips act too. $8 billion is nothing. We're, we're adding a trillion dollars to the deficit every 90 days in the United States.
$8 billion on investment in the most important foundational technological advancements that are gonna happen in the world over the next couple of years. I'm not joking. Like in the next two decades, AI will rule the economy.
The companies that are able to participate and play will be the winner. So it's not just about Intel, it's about can Microsoft continue to succeed? Can Google continue?
They need the silicon to do it. And by the way, they need a partner to manufacture. 'cause they're not all gonna run it on Nvidia.
And that's a whole nother topic for another day. But Google's making chips, Microsoft's making chips, Amazon's making chips. And by the way, they're gonna be able to do it because of Foundry.
They need capacity. They need to not be 100% dependent on having it done in Taiwan. Just the microaggressions and geopolitical tensions between China and Taiwan is enough of a reason that the US has to get this right.
50 billion is nothing. And I hate to say that. 'cause I'd take, I'd take 1 billion of it.
I can make a good life of it, probably. Yeah. But we need to spend a heck of a lot more if we're actually gonna win this.
It's Strategic. Will, will this play out as we hope? Or is it gonna be a situation where we're telling everybody to buy made in America, quote unquote, but then they're still gonna buy stuff that's ARM-based, made elsewhere.
So what's the back end Of this thing? They, they could build arm right? In these, so what we're really seeing here is the decoupling.
This is an Apple player. Remember you open your iPhone, it says designed in California. It's not built in California.
They're built over there. This is the decoupling of the chip business. Intel will still design killer chips, but they're gonna become a contract manufacturer.
You wanna build an arm, I got it for you. You wanna build a new A GPU for, for ai? We'll build it for you.
They're, they're gonna become a contract manufacturer. It lots Of places to build those chips around the world. We need to build them here.
Yeah. I think, I think the point is, there's gonna be some distribution here. We're at zero right now On these advanced chips.
Yeah. We need this. You know, Pat's been reasonable.
Of course, he would love to see us get to 50 50, but I mean, look, being at 90 10 would be a, an incredible, Incredible progress for us. That's 10, that's improvement. And and we need to have some level of self dependence here.
And, and if you're not worried about that, we literally do not have a single industry that can function without silicon. Do you think That there's more awareness about this? You mentioned, because we just went through the pandemic and we saw how dependent we were on China for we couldn't get a face masks.
Yeah. Couldn't face masks. Or then we were like, what about Advil, Tylenol things, everything that we depend on, um, supply chain.
So how do they balance what, what Intel needs to do and the time allotted, um, while they're not making money doing, you know, presenting profits with the need to be independence. Yeah. That, that seems like that's gonna be a tough balance in the years ahead.
Yeah, that's a great question. First of all, the, the, the company is very profitable on, its the, the fabulous part now, the way they're calling it products. Mm-Hmm.
They make a lot of money on products. They've carved out all that expense from the manufacturing side now, and they're putting reasonable arms length business relationship. So they're charging reasonable way for, you know, cost back to the products business.
But they're treating it more like if Nvidia is buying from TSMC now, that's how products is buying from boundary. So you can see how that actually works. So they make the money here, but over here, again, they're getting the grants, they're getting the loans.
They have a smart capital, which is another way they've raised, and I think it's somewhere around 50 billion of total access that they've been able to get. Um, there's no, there's no option to not get this right now. In the end, I, I will actually say I've gone on the record and I said, there is a, a better, it would be a better outcome.
Now there's, it's not a good outcome. Gonna be very clear about this. If Intel products fail, if the Foundry succeeds, I know it's crazy as that sounds, but in this current era with, with the eds, with the arm and the IP companies, you know, there are a lot that can now design chips.
We can design CPUs. You know, you got arm, you got risk. Absolutely.
You got different ways to make phones. You got different ways to make laptops. You got different ways to make cars.
Um, you know, the silicon for cars. But we cannot get the Foundry thing wrong because like I said, we're one, you know, tactical missile away from having no access to leading edge chips. And you know, we sometimes say that with est like, oh, well if China, you know, look, China believes it has a right to Taiwan.
It believes this. And no matter what we say, if at some point they decide that they want to no longer play nice, which we could argue whether they do today or not, um, it would put us in a situation we should never allow ourself to be in. So this, this has to get, this has to happen.
This Has to be done, right. No, this is too strategic. I, I, I don't disagree at all.
I want to give a shout out. I have a friend of mine down in Houston, my friend Misha Misha Stein. Misha was the founder of, uh, alert Logic.
But he, he left there, he founded another company called, I think it's Macro Fab. Five years ago. He told me this.
He said, Alan, we're going to a world where we need to build our chips either in, he, I think he was doing stuff in Mexico, in the US and, and we're just gonna be a contract manufacturer for chips. And I laughed at him back then. I, I didn't, you know, I said, how are you gonna compete with Intel?
How are you going compete with a MD? See, there's gonna be a lot of people who want chip designs and, and he was dead on. So if you are watching this Micha, good, good on you, man.
Anyway, I think that's gonna wrap up. Lock one here on Textron Gang. We're gonna be back.
I think we've got Mitchell Ashley waiting in the wings, and we're gonna talk about sustainability and ai. Something near and dear to Bonnie, we're at Tech Drunk Gang. We'll be right back.
Hi everyone. Welcome back to the Techstrong Gang. Well, we are talking about sustainability because in the wake of the high demand for everything, AI, sustainability has to come into the conversation.
And recently Microsoft has been addressing that, especially with their ambitious goals of reducing carbon, um, emissions by 2030. If you wanna build lots of AI products and you wanted, at the same time, you have to address it. So some of the, uh, Microsoft points that were brought up were water usage.
Maybe we should be using air rather than water for cooling, perhaps turning to sustainable materials. There's a lot of different solutions that can be done as we see the momentum build for ai, um, when it comes to sustainability. So I think this is gonna be a growing part of the conversation as we, as most companies are looking to reach these goals by 2030, you know, you, it, it's sort of like wanting to have your cake and eat, eat it too.
You have to do it in a sustainable way in order for it to, to last and, and to not tap into the resources of the earth that as everyone's doing this at the same time, clearly there'll be an impact. Yeah, I think this particular blog article was almost like a position paper saying, here's what we think this is what we're gonna do and how we might do it. And there are also kind of secondary and tertiary uses of the byproducts of what, like, for example, air, like the heat coming out of a data center, uh, also using that to heat homes.
I think I said like one data center could heat 6,000 homes. So they're, they're thinking, they're sharing ideas about not just within their immediate ecosystem, but kind of broadly within their partners and then the community. Yeah, I agree with that.
And especially when it comes to even building data centers using green construction materials, for example. That's something on Ecotech Insights. I've been interviewing a lot of people looking to do that from top to bottom.
Make it a sustainable effort. You know, an interesting thing, Mitchell and I have a friend, Terry Swack. Mm-Hmm.
And, uh, she's the CEO founder of a company. Is it clean Mines green. Mines sustainable.
Mines sustainable mines. Yeah. It's actually Terry's birthday.
Happy birthday, Terry. It's Happy birthday, Terry. Um, But you know, I was with Terry, but months ago we had a few drinks and, um, but she gave me an interesting fact.
25% or more of greenhouse gases are tied into building Mm-Hmm. Whether it's the manufacturer, the manufacturer of materials that we build with or in the act of building itself of construction, tremendous amounts. Data centers are at, you know, kind of at the top of that list, right?
That's why they, you know, for a while we were building data centers in the Arctic. Mm-Hmm. Because you could cool it there, or they build the data center next to our hydroelectric dam to get access to it.
AI is exasperating this, but here's the golden lining for me. Let's use AI to figure out how to build better, more sustainable facilities for ai. I think this is a case where, you know, you, you can have your cake and eat it too.
To your point, And that's where, I'm sorry, go ahead. Go ahead. Okay.
I think this is a watershed moment comes the day that Microsoft spends this amount of time and energy to create a blog that looks like a position paper. It means that people are screaming in their ears about this and that they're hearing that this is a serious issue. And they're basically running a PR game here to say, you know, we're doing something about this while we continue to consume massive amounts of energy.
So I kind of feel like, yes, it's great that we're talking about it, but I've, you know, been around this block with these guys a few dozen times and I know how they operate. And when they start writing at this level, it means that, you know, they're trying to lobby somebody and they're trying to prevent some legislation from being crafted or something's up. So I think there's more here than what it looks like.
You know, if, if, if AI is the engine, data is the fuel. Mm-Hmm. That's the other half to the coin you're talking about.
Yeah. Which is, think about the vast amounts of data. And Terry's company is one example who, who has a lot of data about the impact of the manufacturing materials and all of that.
Think about all the data that we have now about products that we're creating and, and now that we're paying attention to it, gathering the right kind of data to be able to make the best decisions about reducing impact, about operating it more efficiently or building it more effectively, or reusing all those, all the byproducts of, of those activities. So it's ai, but AI powered by a lot of really great valuable data. And you know, one of the things with AI when it comes to fighting climate change is we're seeing a surge of companies that are creating twofold.
One, monitoring, measuring carbon emissions within software and different companies. But the other side is what kind of what Alan was talking about, the innovation and technology to reduce emissions, build more sustainably, um, track different areas where we're, we're not monitoring emissions, like, let's say through drones. I interviewed someone from a company that does that.
So I think that, um, the Microsoft blog does point to a bigger picture of like what Mike was saying, of what we're, um, what they're, what they're looking for going forward. But underneath it all are these innovations that are happening around the world right now to track monitor carbon solutions and also create solutions just to mitigate the, the, the, if we're gonna use this much ai, we know we are. Okay, well then how are we gonna manage not tapping into water, which is limited already.
So, um, I think it's all happening at the same time. Can I ask you a question? Do you, do you think Microsoft's blog post is something that will be like to the watershed moment others will use as a, a pattern or a baseline to start doing now that's us put our, our position paper kind of validating or extending what that, is it that big of an impact?
It, I mean it depends on, on who's looking towards Microsoft a hundred percent for leadership. But across the board, if you go to different websites of different companies, it is prominently display displayed now. And something that I find that, um, people wanna push forward more in their messaging of how they're doing, um, their own ESG goals and their sustainability.
But a leader like Microsoft definitely could set off a chain reaction that validates it. Yeah. Yeah.
I think there's a guy somewhere, a gal in Europe working for the eu, has their pencil out and is calculating right now what the carbon AI tax is gonna be for the impact that these things are having on the environment and what they're gonna come back to folks and say, Hey, this is what, this is a real cost that you're gonna have to bear. And I think that, you know, a lot of this stuff is pre-positioning to kind of get in front of that stuff. It's, it's possible Shades of Al Gore Who reinvented the internet.
Right. Um, alright. Anything else on sustainable ai?
Well, it's, we'll see what the ripple effect of this is and the Outcomes might be, right? Yeah. We'll and I just think it's something, a topic to keep your eye on because it's gonna just keep coming up more and more.
Vote, absolutely. Vote for more efficient LLMs. That would be the way to go, is just to reduce the amount of carbon being generated in the first Place.
Well, we're gonna talk about LLMs next, but first here's a break we're you're watching Textron Gang. Hey guys, this is JJ man with Mitch Ashley co-host of CSO Talk where we have engaging bite-sized conversations for current and next Gen CISOs. You know, we have some of the best conversations on CISO talk with some of the greatest talent in security people like Andy Ellis who talked to us about optimizing security strategies and how to navigate the boardroom.
Lisa Bradley came on and talked about vulnerability management bug bounty programs and Y SBOs aren't the solution to all your software security problems. Steve Reynolds was also another great guest and he talked to us about what not to do when a security incident happens, What not to dos are great, but we also had Eve Mailer and Steve bitten on talking about security, uh, and third party software, SaaS applications, and weaponizing ai. So go ahead and join us for the latest episode of CISO Talk.
You can find us by going to Techstrong TV slash CISO talk. All right folks, we're back. And as promised, we're talking about LLMs.
Tab nine is basically put out an announcement saying you can bring your own LLM to their tool that lets you write code or test code that will be automatically generated by their LLM, but now they're turning around and saying, Hey, you know what, you can bring open AI or whatever LLM you feel like. And it seems like to me, we just went from, wow, this is the most amazing innovation in the world to maybe an expensive commodity that I can just call through an API and I'll swap 'em out as I see fit. It's internet time baby, You know?
Well, it's interesting. Time Crunch tab nine went through their own transition 'cause they own had their own proprietary non A LLM Gen AI based product and they transitioned to a gen ai. Now they're transitioning to well, and you can add your own, because a lot of the concern is just about, I don't want to code, I don't want put my code into a third party LLM that I'm gonna lose the data.
I lose control over that. I mean, even, you know, I hear people talking about podcasts. So use LM Studio to just do your own lll take, take it from hugging face and work on it in your own environment.
So it seems like that almost, um, you know, kind of the hotel of your own LLM and tools will be a trend to be able to protect it. I'm trying to figure out if people are gonna orchestrate LLMs across different tasks. So I'll have an LLM that's optimized for a specific function, and then I'll use another LLM for a different thing and then I'll have these agents stitched together.
And as that become a workflow, I think it's early yet, but it feels like that's where it's going. That's kind of what the Oracle announcement was about, right? Yeah.
They announced their, I called a broker to decide which LLM or gene AI system will answer what part of the prompt Look, I think we're moving to a modular future. We saw this when we were at reinvent guys, right? When we were doing our interviews.
The, the way of the future is sort of what, what's the sales one called? Einstein? Yeah.
Mm-Hmm. Where it, it's a front end and it can plug into multiple LLMs, it can plug into multiple ais. You're not in a walled garden.
Choice will be the rule of the day until one of these becomes dominant or something like that. But I don't, I I think the market is already spoken fairly quickly and early that they want choice when it comes to LLMs and they want choice when it comes to which ai, they don't want to be locked into open AI or, or Googles or, or anyones for that matter. They also want specialized or don't domain specific LLMs.
They want small SMSs, SLMs, right? Mm-Hmm. To, to be out to the efficiency point, right?
Instead of throwing open ai, gen AI at it chat GPT, let's do something that just does code for these kind of environments. In that Example. I agree.
I think it does sound like it's a more efficient option. Um, but is it more taxing on energy overall if you're using, if, if the LMS are getting larger themselves? That's more of a question, I guess.
I I, to to the other point we were talking about using ai, I think you'll be monitoring like, well I can run six of 'em, but this one, these two do the most efficient. I can save a lot of money just by sending more as long as I'm getting the data from it. I think that'll be one of the factors of who wins.
Yeah. And there's a subtle difference between the training of the LLM requires massive amounts of data and energy. The inference engine that creates, it's only like in terabytes and you can kind of drop that at the edge.
Not so much energy being consumed on the, on the inference engine side of the equation, but we saw, um, open AI and Microsoft were talking about building a hundred billion dollars data center somewhere to drive some massive LLM. And you gotta wonder, do we really need a general purpose LLM to that size to do what for us? Because it seems like the smaller l LMS are more efficient.
Maybe It'll be a bunch of small ones and they're just calling it one thing, you know, who knows? You know, I, I think that's gonna be an interesting, uh, evolution. We need to watch on that.
I I, you know, as an industry we always tend to go big or go home, right? So let's build the super duper computer, LLM. But I, I think the fact of the matter is early and it's still early, so who the heck knows?
But the early indications are that smaller, more focused give you better results than trying to boil the ocean. Think About it. Do you want chat GBT to organize your calendar and prioritize things?
Do you want a SLM that's really specialized at Mm-Hmm. Time management calendar, Whatever. I, I, I think that, you know, but it'll be interesting how it plays out.
But I, I look LLMs are going to be commodities. How quickly they're commodities. They Are hugging face is Proving that, right?
Yeah. I mean, and that's, that's just the Way of this. And I think it becomes easier to swap because I may just be invoking the LLM output through an API.
And if that's the case, then, you know, I'll just move between cloud service providers as I need and then I'll just take the inference engine and deploy that wherever I need and everything becomes disposable. Swappable, Maybe you put the prompt to four LLMs and three of 'em agree. That's the right answer.
Or you know, the arbitrize mutable immutable. Yeah. Excellent.
Interesting times. Yes, it is. We and then you always live in interesting times.
We're ending this on an Irish Uh, I thought that was a Chinese proverb. A Chinese proverb. No, I thought it was an Irish.
We're Already getting yelled at by the Chinese for today. Alright. Alright.
Let's keep the Irish out of it. Anyway, that's gonna wrap it for Textron Gang today. Many thanks to Daniel Newman from, uh, futur for joining us on the Intel piece.
Thank you Bonnie Mitchell. Mike, we will be back on Monday, so not Friday. We'll do our best of, we'll be back on Monday with Fresh Techron gang.
Enjoy the rest of uh, techron TV today. We're out. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
Security boulevard com. Home of Security Bloggers Network Tv. Hey everyone, welcome back here to Tech Drunk tv.
I've got, uh, a first time guest here. I always like having a first time person on. We get to know 'em a little bit and know their company.
They've got some exciting news and we're gonna talk about it. Let me introduce you to Sal Sza. Sal is the CEO and Co-founder of Ninja One, and he's here with us today.
Hey Sal, nice to meet you man. Thank you for being on Strong TV with us. Nice to meet you as well, Alan.
Thanks for having me on. I really appreciate it. Absolutely.
So, um, look, I wanna make sure our audience finds out all about Ninja One, but before we even get to that, let's tell them all about you, Sal. If you, if you're not embarrassed and then we didn't, you know, give us your story. I'll Do my best.
Yeah, I'm, uh, born and raised in New York. Um, started out my journey working in Manhattan many, many years ago. Wound up living all over the country and I've been doing startups for 25 years.
So ninja's, my sixth or seventh startup, depending on how you think about it. Sounds real familiar. I also grew up in New York and did startups all over the country for about 25, 30 years.
And, uh, I also also have probably done five or six. Yeah. So it's crazy times.
It's, it's an interesting, it makes for an interesting life though, doesn't it? Yes, it's, uh, it's high stress, but a lot of fun. I actually was a software engineer 17 of those years, so they didn't really let be good for you behind the keyboard that much.
But, uh, now here I am talking to you, Alan. Fantastic. And are you based in New York now or where are you based?
No, I'm based in Austin, Texas. I, I lived in New York, DC, Connecticut, Phoenix, uh, Austin, Texas, the Bay Area now back to Austin. So It's a great place.
I was with some friends in Austin out in Paris at CubeCon a couple weeks ago and talking about, I mean, it's just rocking the town. Um, so that's interesting. So give us kind of the ninja, you know, you're one of the co-founders.
Give us the ninja one story. You know, ninja was the fourth startup that I built selling to managed ser service providers and, and IT departments. Mm-Hmm.
And, uh, over the years I learned that customer pain really well, how they wanna grow their business, how they manage their customers, and also familiar, very familiar with internal IT departments, having worked across software in Dell and SonicWall in prior lives. And I felt that there was an opportunity to build a platform that was cloud first. And that, and that vision sort of came fruition in 2013, 2014 we started building products.
And the way I kind of looked at it is during that time period there was a consumerization of IT products, meaning IT products got, the user experiences got a lot better. And I felt in the IT market there were still an opportunity to be a disruptor, to build something that was super easy to use, powerful, scalable, with, you know, with high security. And that's the vision by which we started the company.
And it's been, it's been an amazing growth journey over the last eight years that we've been, we've been selling, when we shipped product we had 60 beta customers at the end of 2015. And today we have over 17,000 customers in 80 countries. That's fantastic, man.
What a great story. Good stuff. Stout.
So are MSPs still at the heart of your, like target with Ninja One or you've kind of gone beyond that? Uh, we'll never go beyond MSPs. We actually services both.
So we have thousands and thousands of internal IT departments and we also have thousands and thousands of managed service providers. We find that their needs of both of those buying personas can be solved in, in, in similar ways. They both want exceptional product, ease of use and phenomenal support, which is sort of the backbone of the whole company, how we think about things.
And I'm, I'm actually not a sales centric c like I said, I was a software engineer for 17 years and I actually still run product development today development. Do you? Alright, that's cool.
So interesting. You know, one of one of the companies I started was a security company and we were selling, you know, direct and I, after about five or six years, I, I came to the realization security was just too hard for most organizations. And that MSSP managed security service provider was a great model for most organizations to get the most.
I mean, they had limited dollars for security and they had to have a minimum amount of decent security, right? And, and so we really started targeting that market and then eventually we actually bought an MSSP and started delivering security via that kind of channel, that method. I, I just think it worked a lot better for, for many organizations.
Um, I guess in your case you kind of came to that realization as a result of previous companies you had done about, you know, the, the efficacy of the, uh, MSP model. Yeah, yeah. I mean, 'cause I, I had, I had originally had a DNA in the MSP market, so I knew the market incredibly well.
But what we found is internal IT departments both big and small. We have some internal IT customers with over 70,000 endpoints Wow. That we're using Ninja today.
And we also have managed service providers over a hundred thousand endpoints using Ninja from a single customer. I want to dive into what Ninja does exactly and how and everything, but before we do, I got two quick things for you, Sal, please, number one for people right now who say, okay, I've heard enough, I want to go see, read about them myself. What's the website?
com Easy. com. And then secondly, the big news though is you guys just recently also closed a lodge, uh, series C Round.
Wanna tell us about that? Yeah, I mean we, um, we have an existing institutional investors Summit partners who's been amazing for us. They actually introduced us to our two board members, you know, GERD Watt, Wasinger and N Near, who are both, uh, operational board members.
One has tremendous c c-Suite experience and one, um, tremendous go to market experience. And, um, we were looking to raise cash to scale out our, continue to scale out our product engineering effort and, and maintain the exceptional support that we have. And we're looking for a partner that, um, that could add new value to Ninja.
So Icon's been a tremendous partner so far, um, in terms of introduction, advisory and just, you know, and, and in the ninja way, they're, uh, pragmatic and, and a great culture fit for how we do business and, and how we treat our employees. So they're a perfect partner for us and we're using the cash that we raised to basically just accelerate product development, maintain support, and we're also looking for opportunities to build new products and we'll, we'll talk about that, but n Ninja's on a journey for tool consolidation and sort of minimize the tool sprawl that's happening in IT departments today. So let, so first of all, summit Partners was the existing investor.
Iconic is is kind of the lead, the new lead, Uh, yeah, it's a new institutional round, basically. Yeah. Right Lead and this was a, and this was a 231 and a half million dollars series C, which in today's market, you know, back during c we were throwing numbers around like that left and right.
But in today's market that's an extraordinary amount of money. We, we've been really lucky. Um, our, our growth has been exceptional at small numbers and through pre covid and post Covid.
So I think, I think investors generally are excited about two things. That's been an amazing growth journey and we've shown resilience, you know, both in economic downturns and also, you know, during the pandemic. You know, and our investors point out that, you know, ultimately someday, you know, if Ninja goes IPO years from now, people will look back to that time and and show that, you know, ninja's growth was strong, you know, throughout the entire journey, you know, of our company history.
Fantastic. Great stuff. And you mentioned this money's gonna be used kind of across the board from product to scaling, I imagine scaling, marketing, sales and everything else as well.
Well, yeah, I had a, I had to wait to have an interview there, Alan, 'cause I didn't have a comms department five, five months ago. com and ask me directly. Yeah, I underst but um, I'm sorry you had to wait man.
You well, but it hopefully it was worth the wait for you and, and this turns out well, um, Sal what do you, I mean, tremendous success and congratulations to you and the whole team. What do you think the secret sauce is? You know, I think there's, I think there's a few things you could point to towards the ninja secret sauce.
And we actually talked about this sort of talking more about how Ninja does things. Number one is our culture. We're incredibly organizationally flat.
We truly believe like servant style leadership, it's not about egos, it's about getting the right answer. And I think my employees operate with fear. I mean, we'll have any person, any level of organization, we'll raise their hand and, and say what's wrong with the product or give us unpleasant feedback that we don't want to hear, which ultimately allows us to make the product better over time.
I always laugh that my employees yell at me more than I would yell at, yell at anybody in my life. But the more they yell, I know the more that they care. So I think that's one superpower.
I think, um, transformational support experiences, you know, our CSAT scores are approaching 99%. Like if you pick up the phone and call, we pick up and that's, you know, I'm going to sort of date myself here. Going back to the days of Rackspace with fanatical support.
Like I was, I was their customer and, and would pay for products just to have their support. So, you know, that's the way I kind of think about, you know, kind of a outta respect to, to companies in the past, like they did it, right? So we measure everything.
Like if you fi fill a format, want to talk to us, whether it's support sales or you're having a problem that we could be assistance of, we always pick up the phone. So I think transformational support experience is another superpower. Um, humbly, I think having a product centric CO is a superpower because, you know, often the marketing team will say, Hey, when is this product launching?
And the answer is when it's ready. You know, we built a wonderful reputation of building products that scale well and are easy to use and, and just generally work well. And as we build new products, we've had the discipline to weight, um, and make sure that they're rock solid before we ship them.
So we're, we don't want to chase, we don't wanna chase dollars and hurt our reputation. So I think that's another sort of superpower. And, um, there's a lot of interesting things happening in the market right now.
The endpoints, there's endpoint sprawl all over the place, much more so than even five or six years ago. You know, in a remote hybrid workforce, you have employees working home employees in the office, they have mobile phones, there's IOT devices, there's just devices, everyone. And with that, you know, um, presents tremendous risk.
So I think for Ninja, the tool consolidation where Ninja might replace like 1, 2, 3, 4 tools to simplify the IT or the managed service provider's job, I think is a superpower. And it's working. And, and we've been also really disciplined about, until this, you know, time not purchasing any other companies, everything is built by Ninja from the ground up single stack.
So you don't have sort of the SSO glue gun out, you know, integrated 10 different products and you, it's kind of a consolidated for end. It's all in the product, right? So if you have a problem, you could fi you could diagnose the problem and solve the problem all in one console, which is, which is really power powerful.
I mean, I know years ago everyone said single pane of glass, but it, we actually think we're getting there. So you mentioned this though, and let me, because as I said in the outset, I've had similar experiences in doing startups and stuff. Um, you know, and I'm sure your VCs, your investors will tell you this, organic growth is great, but sometimes you really want to, you know, put a little fuel in the rocket.
And growth via acquisition can really help because it could be strategic, it's not just growth in terms of revenue, but it's, it's growth in terms of maybe new markets, new products, new people, right? New talent. Um, with this kind of funding round, you, you have now, you know, even if you're not paying cash, you know, but you could start using your, your, your equity as a currency because assuming you raised the round based upon that kind of valuation, um, is that something that may change now at Ninja One?
You think that, you know, you might have some inorganic strategic kind of growth like that? Yeah, I mean, I think, I think the way our product strategy has been, the products that we're taking to market this year were already being built two or three years ago. And there's another tra of products that's mid-flight that's a year in development that's gonna pop in the next couple years.
So we have a healthy pipeline of cross sell products and products that could help our customers, you know, extract more value out of the platform. However, we would be foolish not to keep our eyes open and look for, um, exceptional engineering orgs and products that add value to Ninja. So it's not a, it's not a priority, but we are always on the market looking for folks that have the ninja DNA people that believe in the vision and ninja, right?
So they'd be willing to take a lot of stock in our vision, a tremendous engineering team, um, and, and, and a and an excitement about working on something larger. So, you know, I've been on the receiving and sold lots companies myself, and I wanna make sure that if we did that we keep the breast and brightest minds of that, those engineering orgs for years to come. So the, if we found that sort of persona, then yeah, we, we would be open to acquisitions.
Got it. Um, I guess I gotta ask this 'cause you gotta ask it today. What about ai?
How's ai gen ai, is that already starting to influence your product decisions or plans and stuff like that? Yeah, I mean, um, AI is a huge discussion internally. You know, we are, um, we're being super thoughtful about how we build ai.
We're spinning up a large team and we think on the long it's going to be, you know, it's gonna be part of our core platform in a large way. Right now, the tools are young, they're getting better every day. I like to say ninja's not a, a super early adopter of technology.
We're a mid, you know, if you, uh, if you think about it, like the tools are gonna get so much better than 18 months and the people that are absolute earliest, there's gonna be a graveyard of AI startups that fail or there's something destructive happens. So we wanna be careful. So right now our sort of approach to ai, and we have some stuff coming out this year is advisory only, you know, advisory with human eyes.
So, you know, sentiment analysis of, you know, we have lots of great data that we can help our customers draw conclusions and make educated decisions about scripts that they might upload or patches that might be a risk. But, uh, full autonomous control of AI of, uh, of an endpoint, uh, a cloud-based endpoint management product that has control of millions of machines. We think that's, uh, we think that's a long way out.
So we, you know, we're excited about ai, we think it's an integral part of our future, but we don't want to jump too early and, and we're often serving and, and, and checking in with our customers. And I think there's a lot of consensus around that that leverage AI on the early where you could be helpful side caddy to a human, but punt on full autonomous, uh, down the line as, as the technology can continues to develop. And that's kind of our perspective.
Yeah, no, I, I think that's probably mainstream. I, I think just the real contention becomes is where is that horizon? Is it 18 months, 24 months, 48 months or what have you?
And with the pace of, of, of, of the evolution of this year, who the heck knows, quite frankly, right? I mean, we'll have to wait and see where that comes out. Um, what about, you know, 17,000 customers?
Is that worldwide? Is it more US North America? What, what's the kind of distribution there?
What is your focus? Have? Uh, 17,000 worldwide.
Actually emea, we have a phenomenal organization, amia, so about 30% of our customers are actually in amea. We have based operations out of Berlin. Um, mm-Hmm.
And we do have, we sell, you know, like we do sell globally. We sell in apac, we sell in Canada, south America, Africa, pretty much every major continent, uh, with a heavy concentration in North America. Um, and our customers are getting bigger every day, like we talked about earlier.
So, you know, we started off more in the upper part of the SMB, we're sort of, you know, small to mid-size managed service providers, but now we're starting to close, move up into the upper mid market, uh, with lots of product unlocks to sort of support that value to those customers. So we really sell, we truly sell downstream to the SMB and now into the upper mid market. So it's a broad range.
Got it. Got it. So you look at your entire product suite, what do you think is the, the locomotive, if you will, what do you think is the kind of, must have killers that are, are really kind of driving a lot of growth here?
Yeah, I mean, our core product from a day one, you could say endpoint management or RMM, remote monitoring and management, where we have software on all all devices, devices from Raspberry PIs, Linux, windows, Mac, and mobile phones, uh, doing true endpoint management. Traditional endpoint management is our sort of bread and butter, but we also do patch management and compliance software deployment monitoring, alerting, scripting, automation, remote support and backup. So, and, and we actually have many more products in the pipeline.
So I think the thing is, once you have a strong platform that's easy to use and re remove all the friction for customers to consume additional products to help try value and make their job easier, it's a winning recipe. Absolutely. It, it's interesting, you know, I, uh, we got RSA coming up, right?
Uh, may and you look at trends and what people are talking about and, and there was a time where everybody just wanted to talk about cloud, cloud, cloud, you know, this and that. We now we're, there's a little bit of a pendulum swing, if you will, right? Where people are talking about returning to data centers, endpoint stuff, and you know, and, and the work, do anything from anywhere kind of environment that many organizations exist in today.
You know, it's more important than ever that you, you, you have some endpoint insight into your endpoints managing of them, not only for security, but I mean, but yes, for security too. Um, I would imagine that during Covid though, this really had to be a big, I mean, this was, it was, I mean, it had to help the, and I don't mean this in a bad way. Covid doesn't help anyone, right?
No one wants to get sick, goodnight. But during Covid, I would imagine this had to be a, a, a huge kind of growth area for you guys, right? As as people want to become more dispersed.
Like that. Decentralized. Yeah.
You know, I think when Covid started, we were much smaller. So we were 160 employees, now we're like 1200. So if you, if you imagine revenue and that sort of thing.
So at that time, we were growing in triple digits prior to Covid. So we're growing incredibly well. And I, I do think Covid opened up more interesting use cases with hybrid work environments.
You know, ninja very early on was a hybrid work environment. We had lots of people working at home distributed workforces. We have, we have a big office in Clearwater, near Tampa and San Francisco.
So you have salespeople collaborating cross coast and, and even now, like a lot of our employees do work at home and we have hundreds of people in the office. So I think, I think Covid and just hi. I think instead of Covid, I would just say hybrid workforce is here to stay.
It's never gonna change because everyone realized it works. Everyone, you know, the commercial real estate is way down. People you know, from an OPEX standpoint and enterprises can save cash.
Um, so I think it's, you know, I think it's, it's sort of, um, made the pain point higher we were already solving. So I do think, I do think, yeah, I mean, definitely was, it definitely helped a little bit. But I would say unlike, if you think about remote, dedicated remote screen share products were, which were trading at a significant premium like Zoom and others in the market, if you look at the post Covid stats, right, everything kind of settled after.
Yeah, no, they more than settled, they'd come back down to Earth. Right? I mean, uh Right, right, right.
So That was a little crazy. Yeah, I was gonna say as terms of Ninja, we've been able to maintain that growth several years after everyone's kind of getting back to work and, and things are return to normal, which I think is a nod to beyond hybrid work. It just, managing endpoints is hard.
A lot of people don't even know the endpoints they have in their state. And now with the distributor workforce that's highlighting those deficiencies, which is ultimately helping us grow even faster. Very cool.
Hey, Sal, we're about outta time. First of all, again, congratulations not just on this money raise, but certainly congratulations on that. But congratulations on building a company like Ninja, right?
It's eight years you mentioned, and you know, ha, having been in those, in that chair, I know what it takes eight years, day in and day out to breathe life into, uh, an organization and everything. We're we're just 10 years here in, in Textron. March was 10 years.
So, um, I know, I know where you're coming from, man. Congratulations. Keep up the great work whether you have comms or not.
Always reach out to us if you want to come talk. Okay? Thanks, Alan.
I appreciate it. I'll see you down there next time down in Florida. For sure.
For sure. I'm, I'm gonna hold you to that all. All right, sir.
Go check them out. com. That's https colon slash slash dub doub ninja one.
com. Uh, we're gonna take a break here on Techstrong tv. We'll be right back.
This is techron tv. Hey, everyone, I hope you've been enjoying our coverage here. Live at Techstrong, uh, at Techstrong at CubeCon.
We are tech strong, but it's, it's, it's a little crazy. I mean, Scott, I don't, you've been to other CubeCon? Yeah, I have.
I have. And this one is off the charts. You're right.
Absolutely. I, I was with, uh, on Neil Gupta, who's the chairman of CNCF. Sure, sure.
And he told me last night, this is the biggest cube con bigger than San Diego. Yeah. If you remember San Diego before Yeah, COVID before Covid, yeah, yeah.
Was the biggest S one. This is now Eclipse. That, so pretty cool stuff.
Uh, you heard me say Scott, let me introduce you to Scott Johnston. Scott is the CEO of Docker and has been now for, how long has it been? Eight Years.
Just over, just over four years. Four years. Been at Docker.
10 years. So I think I remember when you joined Docker, believe it or not, February, 2014. Docker is 11 years old tomorrow.
Really? So Solomon walked on the stage at Picon Picon 20 13, 11 years ago tomorrow. Okay.
And brought Docker to the world. So here we go. Very Cool.
Very cool. I mean, this didn't exist. This didn't exist 10 years ago, right?
No, it didn't. No, this certainly didn't. com, I started in March of 2014.
Okay. So it was all ascending at Time. It was 10 years.
Yeah. Wow. Crazy.
Crazy. Hard to believe. But there's been a lot of changes since then, right?
Yes, yes. You know, back then Docker was all about the container. Mm-Hmm mm-Hmm.
Of course. A lot of water under that container. Um, as they said, A lot of water under the container.
That's good. Yep. That's good.
And, uh, Docker has grown more, stretch, pulled, changed, come out the other side. Yeah. With a, a very different business.
Right? A lineup that's right. Than Than containers.
That's right. Let's start there, if you don't mind, Scott, at all. Share with the audience.
So, so our journey up to 2019 was really focused on the production use case. Yep. Helping operators run containers at scale in the data center in the cloud across multiple nodes.
And so of course, that involved orchestration. And back in the day, we had an orchestrator, Kubernetes then came on the scene. We eventually embraced Kubernetes, so on and so forth.
In 2019, we realized that there was another opportunity for the company, and that was the developer market. Yes. And so we did a massive pivot in 2019.
Basically shed the operator business, shed the orchestration business to focus just on the needs of developer, and specifically, how can we help developers rapidly as a team develop more secure higher quality software. And that's the journey we've been on the last four years. And you know what, it it, as you said, it was a pretty radical pivot.
Big shift. But in hindsight, genius. Right?
I'd rather be lucky than smart, as they say. It's good to be both. It's Rather be lucky and smart, But that's the story of My life.
But, but developer experience is now Key. A key piece of it. Let's think ab Absolutely.
Absolutely. So the, you know, we're going to get into some of this now though, but I wanted to, now you guys made some announcements recently. We did, We Did.
Uh, well, let's go there if you don't mind. Sure, Sure. So in this focus on developer experience, it's specifically on what we call the inner loop.
And that is what the developer's doing locally when they edit the code, build the code, test the code, verify the code, debug the code, and they go around and around that loop before they do the get commit. Right? So it's all, which is then the outer loop.
Okay. So how do you help 'em go fast in that inner loop? And one of the realizations we came to is seeing the data coming back, is that there's some points of that inner loop that are not efficient, that are not optimized where the developer is waiting.
So, for example, the developer can wait in aggregate sometimes up to an hour a day for their builds to complete locally. They, they type docker build, and they go get a cup of coffee or they go to lunch. And we came to the realization of like, well, wait a minute, we can bring the power of cloud to that local build experience so they have the same developer experience, but offload the build to the public cloud.
We're seeing 39 times speedups. Which to put that in context, that an hour becomes a minute and a half. That's free time.
Absolutely. That's time back in the developer's day To do other things. You know, I've seen, you've probably seen them too, a lot of these surveys that say developers only spend about 30% of their time developing Actually writing code.
Writing code. Right. 'cause a lot of it is waiting for sh Stuff.
Waiting for stuff Yeah. To render. Right.
Right. That's right. And, um, so give 'em more time back in their day to stay in the flow state, be creative, write Code, because what do developers like to do?
Write code. They Like to write code. They're creative, they want to build.
Right. I agree with you, man. That's where it's at.
Um, so working on that inter loop, what else do we got going on? That's a big, so similar to the inner loop, uh, sorry. Similar to build, another big activity in the inter loop is test.
Right? Okay. So now I'm gonna, I built my container, now I want to test it locally, but if that container, or if that, uh, application has like 20 different services that can weigh down the laptop, or if they're developing on an M1 arm, but their production is X 86, now they have an architecture difference.
Yep. Right. So we bought a company in December called test containers, which allows you to have the same test experience locally as you have in the cloud cloud on these same principles of like, burst out to the cloud to do what the cloud does best.
And so we announced this week a partnership with Red Hat Beautiful. Where developer can develop locally, but if they wanna burst out to their Red Hat OpenShift cluster to run the test there, seamless one command deploy. Done.
So lucky and smart, I'll say, I'll take, I'll take lucky, I'll take lucky. Why didn't someone think of this earlier? I mean, OpenShift and our big customers and big banks, it is what platform engineers use to deploy to.
Yeah. They wanna bring, uh, works on my, they wanna avoid works on my machine. So they wanna make, they wanna make the, the test environment as close as possible to the production environment.
And we're like, fantastic. Let's burst from the local test environment to the OpenShift environment. I mean, call it good.
So I'm, I'm not as technical as you probably, right. But look, one of the first big uses not a tech on when I was at my last company, when the cloud first came on the scene was what a difference. Game changer for testing.
Yes. Testing was a expensive time consuming Yep. Pain in the butt.
A hundred percent. Now all of a sudden I had infinite, not infinite, but near infinite scale for my unit test. That's right.
And my, all my, you know, load testing and all of that, we already, so testers already knew that the cloud was your path to buying, uh, you know, a hundred thousand different flavors of laptop and everything. Right. Right.
Why, why did it take so long? You think to do this with containers? You know, I think, I think at the time, back in the day, right, you had a dedicated test team, right?
Remember this, and it was, it was very much waterfall. So like, write the code, someone else built it, someone else tested it, and like waterfall down the way. And in those days, okay, you deploy once a month, you deploy once a Once a quarter, twice a year.
Once A year. Yeah. Yeah, exactly.
But now we're in this world where like, value shipped is the premium. So how quickly can you ship value to production? Yep.
And so that combined with automation, combined with, again, humbly the ease with which the containers become that unit of work Yep. Is pulling more and more that into the developer environment. So how do you make it easy and automated for the developer to, to do testing as quickly as possible then versus throw it over the wall to someone downstream.
So I think that's the dynamic now. And is that like, hey, the faster we can solve issues, the better that quality, better quality software that's gonna be developer can take action and then move on. I mean, I like not only that You have a, you have a better test coverage.
Yes, Yes. Exactly. The, I I liken it to a manufacturing example, which the, the Japanese manufacturers brought, which is they have this notion of the Andon cord on the line, right?
So if a worker sees a problem, they pull that Andon cord because they know fixing it on the line costs a dollar. You fix an inventory costs a $10 Recall costs you a thousand fix Recall, it costs you a million bucks, right? Yeah.
And so, very much what we can do from manufacturing, we can bring to software. Absolutely. Like help the developer solve it Right Then.
Not in ci, not in production, not Oh my God. When the customer sees it. Yep.
Right? And so that's what we're doing. We're helping developers.
It's a Shift left. Problems of solving the problems. That's what's, that's What you're doing.
Solve problems As soon as possible. Good stuff. Both of these are available now or now or just announced Variable now.
Variable now. Very cool. So the one other thing we're doing this week, and you're gonna hear a common theme here, which is again, the hybrid, local and cloud.
So of course the meme of the moment, gen ai, right? So gen ai, uh, works fantastic on laptops that have A GPU, but those, those laptops have a fixed capacity of GPUs, fixed speed of GPUs. So what we're also highlighting this week is the ability to burst that LOM out to a cloud to cloud and run it on a cloud node with a big beefy GPUA Real Nvidia deal Or, or, or tens of Nvidia GPUs in the cloud, right?
So again, how do you speed up that iteration, take advantage of the cloud for what cloud is good for? Right? I mean, look under, it's that same mindset as as moving your testing off, right?
That's Right. Or your builds Up. And this is a great use for the cloud, right?
Because it is so many people, I wanna host my app in the cloud, I wanna, I need good identity, you know, security in the cloud, but the cloud works best for I think little jobs like this very Specific Yeah. Surgical boom Boom in out burst of all that's right. You know, I need what I need and I'm done.
I'll use it again next time. Versus the sprawling infrastructures that, that we spin up. I mean, production has found ways where spiky workloads work well in the cloud, like retail, retail, you know, Christmas season or Black Friday.
Like, okay, great. But we also realize that like there's so much power there that developer is not able to harness. 'cause it can be difficult to set up and provision and secure.
So we, our brand is simplifying, right? Right. So if we could simplify all that, actually we take it completely off the developer's plate.
Developers just use the same commands behind the scenes burst out to The cloud. And that, that's, look, like I said, sometimes I sit around and say, why didn't I think because Well, There you go. There you go.
Exactly. Hey, I wanna bring up another topic. Yeah.
com, we're cloud native now, and all these other That's right. Well, they can't see it online, but over here is our real background with all of our sites. At the heart of a lot of this is that whole CICD pipeline process.
Mm-Hmm. And it's, you know, we're doing this big research project right now called DevOps next, right? Where we're, we're looking at, we don't, we're moving away from cobbling together point solutions, right.
And it's, it's a natural evolution, right? Sure. To more of a platform, more of a, you know, it, it it organic if you will play, we're not just cobbling.
Right? Right. And the heart of that is that, that CICD process, we've come a long way, but there's a long way yet to go.
That's right. That can be done's. That's right.
A lot of these little things point kind of things that you're talking about fit into a larger picture of how do we speed up CICD. That's right. That's right.
And, And so what's the docker view there? And, and look, CICD plays a really critical role for, uh, particularly that intersection between dev and ops of like, what are the, what are the final checks that this app has to go through, particularly for regulated industries? Oh, yeah.
Mission critical workloads. And there's a set of tests and certifications and checks that absolutely have to be done before that workload goes into production. But we hear from customers that sometimes it can take them 5, 6, 7 times looping through CI before they actually go to C Get, Get, get.
Yeah. C, c Get, well, it gets bounce before it Gets to diversion. Right.
And that, that means latency, that means time, that means the dev, the dev is waiting for stuff to come back. That's 30% number. Right?
That's right. That's, that's exactly right. 'cause they're waiting for something else to finish before they can like, take action.
And so we see that and we see what we've been bringing to market of like, okay, if we can actually help the devs solve it earlier, maybe instead of five, six, or seven times through ci, maybe they go once or twice through ci. And so everyone benefits faster delivery of value. The dev is solving problems right then and there, not 30 minutes later, not 60 minutes later when it comes back from ci.
And the CI team is known for a high velocity enabler. So everyone, everyone kind of wins and bringing absolutely these best of both worlds. Best of inner loop to the best of outer loop, as we call it.
Docker's not done with this stuff. We're not Done 11 years going, we're just getting going. We're just entering our second decade.
All of us, all of us here. Second decade, you're A hundred percent cur, you're dead on on that. Right.
And I, again, I think about Wow. Wow. Just, wow.
Do you envision a time where instead of helping these companies with CICD kind of accelerators or catalysts people go to DACA for CICD? It's an interesting question and it it, it's into company evolution question as well, right? Um, I mean, we have found a lot of success the last four years, as you referenced, staying focused on the needs of developers.
And I think what that could mean with automation and where a lot of the technology is going is, does, does it still look like traditional dev CICD production five years from now, six years from now? I don't think so. It could, it could radically change.
And and it's not only the result of automation, of new technologies, but it's also now we're injecting, um, gen AI and data into the equation as well, which now has to be part that Area. Not just gen ai, but I I'll say ML lops All up. You're right.
Yeah. All up. And, and that's fascinating too, right?
'cause now you're shipping not just code, you're shipping models and the data with that model, and you're having to go through iterations that today we go through with code, that you're gonna be iterating with models, iterating with data That they're gonna Right. They're gonna iterate themselves almost. So, Yeah.
I mean, you have to automate it, otherwise everything's gonna slow down again. Right? And, and now you have this new persona, the data scientist who is upstream helping tune the model, but then it's the devs that is taking that and incorporating it.
So, so we're gonna evolve. We're gonna evolve. Sorry.
We as an industry are gonna evolve. Yes. And Docker's gonna be there.
It's gonna evolve right along with it. Docker's gonna be there to serve that development team and help them take advantage of all these great technologies and the data and the, and the models to make great apps. I love it, Scott.
All of the things we're taught, well, what we just spoke about's not available today, but everything else we spoke about is Yep. com. com.
That's Right. All right. Hey man, thank you so much.
Always Good to talk, Alan. Alright. Scott Johnston, CEO at Docker.
Lots of stuff going on there. This ain't containers anymore. Check it out.
We're live in Paris. We'll be back in a moment. I think we have tenable up next.
Stay tuned. Hello and welcome to the digital CXO podcast. I'm excited to be here again this week with you all and with Mike Ard.
How are you doing today? I'm doing great, but um, I'm more interested in how you're doing. You've been traveling, you're out in Las Vegas last week for the, uh, Adobe conference, and it seems like that was a lot of AI chatter, but AI equals digital transformation in a lot of regards.
So what was your sense of what was going on out there? Oh yeah, absolutely. AI seems to be one of the biggest tools that everyone's focusing on in the digital transformation efforts.
So yes, there was a lot around, um, bringing in some generative AI into the Adobe tools. And so I, you know, I wrote some notes down 'cause there was so much information from that event, but the biggest one is they wanna, um, hit every aspect of the content supply chain. Um, that being from creation and production, workflow and planning data, real-time, data reporting, um, all of it reporting and insights.
So with that, they, um, they had some generative a announcements within their firefly. They had some generative a announcements, um, within their, um, Adobe Experience Cloud. And that brings up another one, which was a big partnership with Microsoft.
Um, as far as the Adobe Experience Cloud goes, um, it's gonna share their workflows and data to the Microsoft co-pilot. And they wanted to continue and expand on all these partnerships with them and IBM and Google and, um, continue to innovate, uh, in these areas, uh, to provide wonderful services to all of their clients and consumers. Um, but what fascinated me was some of the use case examples.
So they brought in, um, Pfizer and, um, they talked about how the Super Bowl ad took them only three weeks to create an entire Super Bowl ad and brought them outstanding results. Millions of people came to their beat cancer, um, campaign site within that week of, of that Super Bowl ad playing. And to me that was mind blowing because thinking about what used to be, um, you know, the process to create a Super Bowl ad months and to dwindle that down to three weeks was really impressive.
Um, they also showed how it could create entire ad um, uh, marketing campaigns for all media platforms within minutes. Uh, so mind-boggling the use cases around the generative ai, which we've, uh, been speaking about for quite some time. But seeing those in play was really cool.
Um, and, uh, so that's, that's just a small part of it. Um, I had a, uh, interestingly enough, the, uh, I did speak with Fred Faulkner who was, uh, strategic marketing for Bounties and you know, some of the other vendors I like to go around talking to all the vendors too and, um, the partners. And he was surprised they didn't talk about commerce, and it's like the only area they didn't hit on was the commerce area.
Maybe that's strategic as well, but, um, it's kind of the one area where they, they didn't touch on at this summit. Mm-Hmm. Something seems to be afoot here where we've moved from being amazed by the fact that an LLM can, uh, generate content to now trying to figure out how to orchestrate tasks using these LLMs.
And that requires a fair amount of automation, but it, the reasoning engine in the LLM is getting smarter, and as it gets smarter, it's able to take on more of these tasks and process them in, in the right order that we want something to happen. So when we can say, please create a marketing campaign for me that I can then tweak or create the entire website for that matter. It's still early days, but, um, is it your sense that it might soon become less expensive and frankly simpler just to launch a digital transformation initiative?
Well, I, I mean, just from seeing the use case examples at this summit and, and from talking to some of the, the company leaders a across the summit, I would say Yes, absolutely. I mean, the more, the more this is integrated, um, you know, and the faster everything gets and the less people are needed. Yes.
All right. So what was your sense of what are we gonna be doing with all those people that quote unquote or may not be as needed? Or can we up uplevel our game entirely?
You know, at this point, uh, you know, a lot of business leaders are saying, look, there are some jobs, um, that are not gonna be needed. Or not that they're not needed, it's just there's gonna be less people needed for the exact jobs, uh, since they'll have the tools assisting them. But there's also gonna be a lot of new job creation that's gonna be required.
Um, and so some will shift, but the general consensus is everybody needs to be able to, um, upskill and adapt into potentially different positions and be willing and able to do that, uh, or, um, be at a point, you know, if, if they don't, where they're ready to step out. Yeah. Well also there's a lot of smaller companies that never had these kinds of capabilities and they might be able to compete more effectively.
I think there's a running joke somewhere in, uh, venture capital land about when will the first single employee billion dollar valuation company emerged because of ai, because it was, you know, you can do everything yourself kind of thing. And so maybe we'll all just gonna evolve into many conglomerates and a small number of us will be able to do an amazing thing. Yeah, I mean, it'll be interesting to see how the future unfolds.
It's, it's certainly an exciting and fast moving time at the moment. Um, elsewhere, I saw that, uh, Elon Musk has things to say about AI as they pertain to digital transformation. And I guess one of the things I took away from this grok comment was that, well, he's arguing we need a more human centered approach to ai and therefore this, um, chat agent that he's advocating as a platform, um, is that approach.
I don't, can't tell if that's just, you know, him thumb in his nose at open AI or not, but what is your sense of how, uh, human are all these bots that we're about to create? Well, um, you know, the chat bots still have some work, um, that's needed, but they are getting more and more personal. I mean, that's the goal of, of most businesses trying to incorporate these chat bots is to really personalize them and help get that one-on-one help, um, that that's beneficial and can reduce some of the hours that humans have to put toward that.
But I mean, there's still a lot of glitches and, and things that they simply can't answer, and then it has to go to a human for help. But that is the goal. So ultimately, um, are we all gonna get our own little digital buddies and kind of have somebody to help us with our tasks and then our, my digital buddy will talk to your digital buddy to get something done or, and, you know, once they come to some point where they can't resolve it, they'll call us and hopefully we're both on a beach somewhere when that call comes in.
I, I see that being the way of the future. I really do. Uh, I think it'd be cool.
I'd love to have my own little personal chat, chat bot assistant helping me with everything I could find, you know, the value to that. So it's not there yet though. All right.
We got a ways to go, um, elsewhere on the site, I was reading this article about the role ERP plays in our digital transformation initiatives. And it kind of pointed out a longstanding issue is that a lot of organizations become overly dependent upon these ERP platforms, whether they're from SAP or Oracle to run huge swats of their processes. And that in itself is not a bad thing because, well, we didn't have another approach before and we needed to automate theoretically at least a set of best practices.
But these things are fairly rigid, and I guess we're starting to see SAP and Oracle and j some gen AI capabilities into these platforms, and maybe they'll become less rigid. But do you think we're kinda on the cusp of some sort of decomposing of these big monolithic ERP applications into more smaller discreet processes that are easier to manage maybe and kind of stitch together and combine as needed? I mean, will the ERP as we once knew it kind of devolve into something else?
Yeah, so that was the topic of, of this article, and it was saying that as more business leaders are looking to digitally transform and be more innovative, that they're finding, they don't wanna be tied down into one vendor controlling everything, um, across the entire process. So there might be certain softwares that they would like to use to solve certain problems, um, and their budgets, you know, maybe can't afford these vendors that they're working with. And they would like to kind of, uh, put together a puzzle of various, um, softwares or companies they're working with, uh, for the whole picture instead of just one controlling everything.
This has been going on for as long as I can remember, and a lot of organizations feel their entire IT strategy is wrapped around these platforms and they can't even consider any new technologies or new innovations until they manifest themselves in these platforms. And, and the problem has been the providers of these platforms don't really innovate all that quickly. They're getting better at it.
I'll give 'em points for that in terms of they move things to the cloud, but part of their approach has been, well, we're gonna move things to the cloud, but um, we're gonna make things, yeah, all the software rewrite you can't touch, and then here's a separate application server for you to go write your own code if you feel like you should customize something, but then continue to insist that, uh, there's no need to customize these platforms and yet 90% of the customers continue to customize these platforms. So somebody's quite clearly not on the same page, and I might argue, and customer's always, right. So clearly there's something afoot here, but, um, what's, you know, you've been talking to SAPI know not too long ago.
What's your sense of the tension in this in the, in the ecosystem? Yeah, I think there, there definitely is some tension because at the end of the day, you're right, the customer is demanding more and expecting more, and sometimes it can't be done with certain, um, software or, or vendors that they're working with. So there has to be some collaboration.
I mean, you know, let's just talk about what we were just speaking about at the Adobe Summit. There's tons of collaboration between Adobe and many other companies to provide all these different services and features. Um, well, we should think about that in, in, um, this way too.
Uh, when companies are looking, they should be able to piece together different ones and they should all be able to interact and work together. Yeah, and to your point, it feels like the Adobes and the Microsofts in the world are trying to fill in the white space around these ERP platforms. They're essentially the systems of record.
And so if I'm just, you know, recording transactions and things and events that occurred in those systems, I think that's fine. But the systems of engagement wrap around those platforms and may not necessarily be from an SAP or from Oracle or whoever. And it's a, it's a little bit of a delicate dance, but I think, um, it leads to better innovation maybe if we have that approach.
Of course, you know, you can't have too many vendors 'cause then you might have chaos together, but, um, are we trying to find some sort of digital balance? Yeah, and I mean, I guess that is where, like you said, if you have too many, then you're dealing with this huge sprawl that you're having to keep track of, um, for everything. So that can be, uh, another problem in itself.
But I do feel like there's certain, um, compromises that have to be made in the name of innovation and digital transformation All. Um, I can't help but wonder though, I mean, we talk about monolithic apps versus microservices in the land of DevOps all the time, and this plays out as a set of discreet processes, hopefully within a, an environment. So if we want this world to be the way it is, I think we need to better align what exactly is a quote unquote microservice as a, as a discreet unit as it relates to what a business process is.
And we've been having this conversation about the lack of, uh, alignment between business and IT for three or four decades now. But I wonder if we're at some tipping point now where we have to really think about managing the software in, in exactly the way it's aligned with the various tasks that we're trying to accomplish. Yeah, I think that's where it comes down to, to better communication among all the departments.
And, and again, something we talk about regularly that still seems to be an issue, which is removing those silos to figure out what do all these different departments need? What are they looking for? And then combine that into effective solutions.
All right. And then let's just jump over to our last story here. But, um, you mentioned silos, so it looks like we're creating another one.
People are trying to create these, uh, chief sustainability officer titles. What's your sense, uh, how real is this? Well, I I think that it, it's a very good argument, um, being made that it is a big focus and maybe not, not enough focus is being put to it.
So they are trying to, um, essentially make a position for this or department, um, to focus on it. But I would hope that it doesn't become another silo. So the issue is anytime any new position or any new new department is formed, it, it has this risk of becoming a silo, which is what companies shouldn't be doing it.
No, no team should become a silo. We should all be collaborating and communicating well. Um, so, but as far as the position, I think it would help with, um, innovation, it would help with risk management, it would help with, um, environmental, you know, the environmental footprint these companies are making.
Uh, and, and there is a lot of, um, concern about the environmental footprint and maybe not enough focus being put to it. Yeah, I just wonder what the level of authority's gonna be, because everybody who can actually affect the outcome of the process is a c-level owned something, right? It's either the CIO or it's the head of manufacturing or whatever it is.
So, um, is the chief sustainability officer just gonna be, you know, filling out reports and sending memos to people and maybe not having enough authority? So whoever, if they do create these positions, I, I think there are some that have created these positions, and I think it's, uh, all about, um, they will need to be good at managing and, uh, and communicating, uh, because they need to do a little bit more than just, uh, paperwork and things like that. They, they need to be the ones effectively communicating change across each department and ensuring that it's getting done and it, that they all work together.
I wonder, I mean, if I look at the regs that are required outside of Europe, they're still kind of shaky. Um, so is, is this getting enough traction globally or is it pretty much limited to a particular region where we're gonna see more of this effort than others? 'cause frankly, I, it is not clear to me that, you know, companies in the US are banging this drum as hard as they are in Europe and other places.
That's a good question. Well, we know Europe tends to, to get ahead of these things a little bit more, uh, and, uh, are first in line for a lot of those types of issues. But, um, I think here in America we're focusing more and more on it.
It it's just a matter of focus versus action. So, you know, and you know, which is where this whole conversation comes into play is acting. And, you know, as far as other countries, some are and some aren't.
So, you know, if you look across the globe, um, I'm sure there's a percentage that really aren't focused on it at all. So do you think AI might save us from ourselves here, or is AI part of the problem? Because we're consuming more energy than ever to drive all these large language models?
It's a quandary because it can both help and harm. And I think in, in a, uh, a podcast a few weeks ago, we were talking about how well maybe we could use the AI to eradicate the waste or use it in some other way. Um, so it, it's a quandary.
I do know, um, some people are looking at AI to, um, instead of having all this technological waste, um, basically rewinding legacy stuff to pull as much information as they can from it and, and utilize it with ai. So that'll be interesting to see how that plays out. All right.
Any other final thoughts from your trips and adventures from the last week? Oh my goodness. I'm just trying to recover from a whirlwind week with lots of information, but, um, stay tuned because there'll be more posted.
You can see a little bit of it on our, uh, text drawing, ai, LinkedIn site. All right, cool. Thank you all for listening to our latest podcast, and we'll see you next time.
Thank you. And, uh, stay tuned for more information. Thanks, Mike.
com is the number one online destination for DevOps education and community building. com covers all aspects of DevOps, including DevOps, best practices and tools, DevOps culture, DevSecOps, business impact, continuous testing, continuous delivery, and more. com has the largest collection of original DevOps content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com where the world meets DevOps. This is Techstrong tv.
We have the great pleasure of being joined by Andrew Pinkus, who is a co-founder with re Red Reactive welcome. Couldn't be talking with you Andrew. Yeah, thanks Mitch.
Appreciate it. You Bett. You bet.
Um, you know, we've talked before, but that was at, uh, another, uh, part of your career, uh, a a prior step, I think when you were Atlassian, but great to be having you on here with, uh, redact. Tell us a little bit about the company, uh, why you started it, the problem space that you're going after. I'd love to hear a little bit more about that.
Yeah, absolutely. So, so at Redacted, we're kind the only developer folk, uh, platform focused on accessing, um, live permissioned data for generative AI applications. We fundamentally feel like it's that missing part of the, um, like that LOM application stack, which is a lot of people are focused on that kind of governance aspect around that infrastructure layer, looking at lms.
But one of the biggest blockers to kind of AI or gen AI application adoption or fundamentally building them and getting into production is how do you access permissioned data that's live from sources like Confluence, slack Notion, OneDrive, um, and other kind of custom databases that might be governed by, um, identity access management systems. We see so much kind of in market right now is risk around bleeding information internally. When you bring in generative ai and we're kinda that one stop fix there in order to make sure that integrating RHD K into your product ensures that you can really seamlessly connect, um, to those data sources and then leverage them in real time if you're building AI agents, uh, chat bots, workflow applications, et cetera, any of this kind of next gen style of, uh, gen AI application.
And the reason why we, we jumped into it is my co-founder, Alex and I, uh, we previously used to work at Atlassian and we saw that kind of trend there around challenges around enterprise adoption of, of kind of capabilities. And that, um, it took a long time in order to move customers from kind of server environments and the data center environments and data center environments into cloud. And there were so many permissioning data access, data sovereignty challenges there that need to be solved.
And, and not just in the Atlassian case, fundamentally across the industry around cloud adoption that we saw a very similar trend probably starting to emerge in the generative AI space as well, is that, um, there's so many cool open source projects that they're attempting to stand up, small proof of concepts, um, for interesting use cases, be it agents, chat bots, et cetera. But we really felt like, hey, this really complex and very clear part information security review requirements inside of enterprise environments such that these proof of concepts that leverage gen AI are probably not gonna get into enterprise environments anytime soon. So we wanted to become that kind of that key arm block in order for large groups of internal employees or even their customers to be able to gen to, to leverage generative AI capabilities.
One thing I'm curious about with generative AI is, you know, it's relatively new, it's been around since 2017 or so, but most of us till the last year or two kind of burst on the scene. Are, are those, are the models LLMs, the, the smaller, uh, LLMs are, is there a security model very mature? Is that one of the things we're looking for generative AI kinda come along with to what an enterprise would need for a security model?
So you can't fully depend on what's in an LLM. Yeah, it's a great point here and it's kind of like if you look at the, the last few even kind of quarters of kind of generated AI kind of, um, changes and trends in market, it's the kind of last year obviously gen, um, general, and I get very interested from like a productivity use case point of view with chat GPT and then organizations looked at, well, how do we bring this internally inside the barrier organization? So then they looked at open source models and fine tuning, which obviously comes a great cost and removes a lot of that permission layer of data access.
That's actually the information that you wanna pull on. And there's two kind of core components there, which are kind of security risks. Um, when you look at kind of just fine tuning or training, an end model is that the information that you want AI to leverage, um, needs to come from an end tool.
So you think about confluence like notion one drive, if you're gonna fine tune it, you're actually gonna strip that information away from its source of truth and now start kind of mixing in the concrete, um, into the model that you want to use, which means that that information at any point in time is fundamentally becoming stale. Um, which means that, right, your strategy now is how do you continue to fine tune over time and bear that cost on the organization. The second component is from a security point of view, which is not only are you leveraging stale data now in order to leverage an LLM, but you've fundamentally stripped away the permissions or that fine grain access control from those documents.
So there's kind of two layers there in the fact that not only have you removed that core access of an end user to a tool like Slack or Notion, but then also think about the pages that you can see. And some of your coworkers can't. You might have some locked documents, they might be some things that might be one-on-ones with your manager or HR information or finance information that the, that department's dealing with all of those fine growing controls inside of those tools have now been stripped away when you start putting them into a, into a train in a trainable model.
So we've really lost that, that ability to control, um, data access and create the more kind of risk vectors inside of an organization. We leverage the RAG framework as a core component of how adaptive enables applications to leverage generated AI securely. And what we do is that we fundamentally pass through those security, um, kind of access control layers through to the end application.
So when you leverage redacted, you're passing through no longer the prompt, but also the access token or the token of that end user such to where only pulling on the information that that right user has access to. And you don't have tokens embedded in applications, you have your applications all using the same security model for accessing that data, not 25 different ways. I can imagine there's a lot of benefits to standardizing that process plus the maturity of it.
Are there, are there certain things about LLMs generative AI that present unique challenges to enterprises that are adopting them when it comes to access control and security? Yeah, absolutely. And I think number one is that sense that in so many CTOs and sizers that we speak to is that there's a real kind of interest in starting internally with their core use cases.
So they're looking at it from a, from a use case perspective. Number one is if they're trying to, uh, provide permissions aware q and a across multiple different tools, if you connect up your HR application and into your, um, confluence environment, you can actually pull commission data and more general information across the business for the right user as long as you respect their downstream commissions. And then you point in time.
And then the second component is like, you know, um, like kind of that enterprise knowledge based q and as really where people wanna start on their generally AI journey in enterprise environments. But very quickly, once they get comfort there, they're looking at how can they augment their customer service agents, um, and really deal with high touch customer service, the human in the loop style customer service environments. And that's pulling permission data that's maybe very sensitive about the customer, especially in, uh, financial, in, uh, financial services industries.
So thinking about banks or insurers we might be dealing with customers claim or finances information, you wanna ensure that that customer service agent can speak appropriately about the business and their product information or, or kind of their policies, but then also speak very specifically about what is that individual's end challenge or their situation. Um, and really right now, customer service applications can't do that in the generative AI space because they are making these, um, kind of, uh, these gaps around permission access. It's kind of all or nothing.
Here's your token, now you can, you know, you have access, right? Absolutely. Yeah.
For better or for worse. And it seems like there's a number of use cases, use cases that come to mind. You've talked about the chat bot and, and customer service.
There's also automating workflows, you know, more behind the scenes backend kind of functions, um, you know, automated forms, things like that. I can imagine a number of places where you want to hook in, you know, gender AI may not be the main application, but it's part of the ecosystem of data, data sources that you're using that you wanna be able to hook into those processes and applications. Absolutely, and I think this is really where, it's really interesting to look at the application developer market that's emerging around generating ai, trying to build these native AI applications.
We are working with some right now who are building AI agents, and one of their big challenges is that, you know, they're looking at customer service roles, researcher roles, they're looking at, uh, ITSM desk help desk environments or even kind of risk like automated risk reporting as being these kind of core use cases, um, inside of businesses. But the big challenge that even these kind of AI agent builders have is how do they access these live commission data sources as well? You can access, you know, kind of traditional data lakes and, and, and kind of more stale data in order to start to personalize how, how an all, how a agent might act, but really where you do your work every day is probably where an agent should do their work as well.
Um, and those are in those collaboration tools environments where data is changing consistently, where permissions are being, um, on an almost hourly basis being applied and removed and is where the most recent source of information that you would want an agent to respond to, especially in a risk reporting case. Um, so unlocking that component with RSDK, something that we've been helping some of those AI agents actually do in market right now as well, such that they've got more data coverage to power their in these cases, Are there things you have to do differently for various LLMs, you know, there's something from an open ai, AI versus something you get off of hugging face. Um, are they all different and you have to kind of, you have to adapt them to what you're doing?
Or is it you providing more of a one way to access all of 'em? Yeah, no, it's a great question. So, so we at redacted our SDK now, uh, underlying platforms, fundamentally large language model agnostic, uh, we can allow, we allow you to plug into any model, be it some of those big ones in the space or if you, you're rolling your own.
Um, there's many different use cases there. So we really encourage our customers, especially in the enterprise environment, that that they have been fine tuning a model, uh, and they wanna start there. They can benchmark its performance whilst additionally providing live context through from via model.
Um, are ways for them to kind of leverage what they might have already built or models that they feel comfortable about from, um, like AWS or GCP looking at Gemini and bedrock models, um, in order to feel really comfortable about the security constraints of other parts of their stack, whilst also using redacted to solve that, that fine grain access control challenge. It could also be helpful too then for, not saying it's a small deal to do, but if you want to change out LMS that you're using, right? You may be using one today and now you've, you know, tuned or trained a different one or you're using a different source.
I know some, some people are actually kinda acting as a front end to multiple LLMs and then depending upon the prompt will feed parts of it or, or all of it to a different LLM to get the best response from that particular model. So like you have a lot more flexibility and less direct ties to un unhooking, you know, your connections into a specific LLM to talk to another one. A a Absolutely, and I think one of the, the things that, you know, we go am miss not to mention here as well, is that when you start having a lot of flexibility around different models, especially if you're an enterprise environment, you want a lot of transparency around that data pipeline.
Um, such that we, we are redacted when you're kind of moving information through in this live retrieval environment, um, and pulling relevant business context from Slack Notion OneDrive, for example, for generated ai, we allow you to put in any kind of DLP provider of your choice. So data loss prevention are obviously really large standards things that go through large procurement cycles for enterprises. So they get really attached to their underlying DLP provider, and we allow you to basically pass through any of the context alongside the prompt through a DLP provider before then hitting that large language model of your choice as well for that additional layer of kind of egress security.
Um, if detected your, your VP C environ, What's, what's the onboarding look like? What, how, what does it take, you know, developers always looking for, you know, make my job easier, don't make it more difficult than it already is enough challenges. Um, what does that onboarding onboarding model look like and how, how much time or effort does that take?
Yeah, look, we, we've tried to redacted, really simplify that down, um, to the fact that you can do it within about a day. Um, we have a SDK download off our website, contact us to get access. Um, you select the data sources that you'd like access to for your end users, and then, um, you fundamentally just, um, insert a a a connect button into your application usually during your onboarding flow.
Um, and if you've already got system administrator access and a trusted app inside the enterprise environment that Connect is, is as simple as like an SSO screen that you would see on Google. Let's get that one encounter with Redact in your entire journey, and then you're fundamentally connected securely and managing the, and being able to pull from downstream app applications with its various levels of permission aligned to, to your level of access. Um, what's really great as well is like sort, it's really simple onboard side of enterprise environments in that regard.
With application developers, it's exactly the same as well, which is, you know, there's so many challenges around building those chunking, embedding Vector Store and live fetch pipelines that are taking away time from your engineers solving problems for your customers and your end use cases such as the exact same experience, jump to a platform, download the SDK, embed it into your application, and then passing through prompts plus token allows you to pull live business context from those end data sources. I think the last thing I as well to this is that for our enterprise customers as well, is that we're actually providing a lot of, um, kind of template use cases as well, um, to, to enterprises to really just starting their generative ai, um, adoption journey. So whilst the redacted developer platform is really powerful to support any use case, we're building out those kind of permissions away q and a and high touch customer service kind of template applications such that they can know in that front end.
It's something we intend to open source in time and allows them to get really jumped into their general AI journey with their, with their internal and customers within the, or sorry, internal employees within about two weeks, if not less. Great. I, I would think your experience too, working with enterprises, you, you understand the process you have to go through to get provisioned through the security teams, and the easier you can make that, the quicker it's gonna happen For sure.
A hundred percent. And, and one of the, the, the great points where, where Redacted comes into its own is, um, we've often found, uh, business buyers internally or someone who's in charge of generative AI and taken on that helm inside of the business and might have built a really small rag application. They've got a vector store, which is stripped away the permissions that they're pointing to.
Um, they've got maybe 10 internal users leveraging it, and then they hit information security review. They get really excited about the idea of scaling it up to their customers and they're, and that information security review, that security team fundamentally rejects that solution up architecture. Mm-Hmm.
Um, because they say, why does your, your generative AI application be allowed to have a different permission system, different identity structure compared to, um, what we've invested in in a long time, how all of the rest of our applications work, you're introducing new risks, we're blocking your application here. So they really start to feel that pain internally around that like that, that permission kind of management journey. And that, that challenge there about how to solve that part of the stack.
Um, that once we kind of come in and say, Hey, this is what redacted does, they go, great, how can we integrate you tomorrow? Because we need to unblock, um, our pathway through information security review. So we very quickly become kind of a trusted friend or kind of champion of, of the security, um, team as well, um, which has made it really simple to kind of then make that progress into production environments with our customers Where the hurdles the better o one of the hurdles that can happen in those reviews is, uh, retention of data.
Is there any data that's passing through some of the third party service? Is it getting left behind? So now we go down the road of the II and other, you know, sensitive kind of information.
Is that at all an issue for you? Yeah, well it is actually something that we're, we're kind of actively solving around. Again, kind of going to the origin story of redacted, looking at like what are the enterprise requirements of production grade application kind of, um, adoption and then reversing it back.
We knew that how redacted managers or potentially stores customer data is gonna be incredibly critical to our adoption as a developer platform ourselves. So in those environments, what we've done is that we've really rolled this back to the idea that the big challenge is likely around how indexes of information are managed, which is a lot of applications or in the traditional enterprise search space, um, would be t trawling, different, different systems, pulling all that information into a, into a new vector database or just a fundamental new database before, um, large language models were really popular. Um, and they would store kind of chunks of information about potential customers, the company, et cetera.
Um, redacted doesn't store chunks, and this is part of our unique solution architecture in order to do live retrieval, which is that we only ever storing beddings of information, which is obfuscated versions of the action line documents such that you can never reverse them back out into being a, a record of, of any kind of customer, et cetera. Um, we leverage that plus a pointer system, so we identify where relevant context exists across the business, and then we always go to the source to do the app, um, app query time permissions, check that end user to make sure that live permissions are applied, and then also pull the, the live version of the document in. And what's really great about this is that because we act that pass through layer there and we are not storing any kind of version of the end document ourselves or information on customers, it reduces that third or fourth party risk, which security and information security teams really look at as being that kind of additional kind of vendor risk that that third party risk aspect.
Excellent. Excellent. Sounds exciting.
It sounds like you're attacking a, a very valuable space to go after. It's hard for apps to do much without really good data and secure access to it, whether it's, you know, generative or, or traditional applications. Um, what's the best way for folks to get ahold of you and start to look at, uh, redacted?
Yeah, We we're, we're active with, with many customers across Australia and the US at this point in time, across application developers trying to build, you know, Silicon Valley style startups and, and accessing commission data. I wanna kind of really remove that pain around, um, those kind of, that new data engineering skillset, um, and how to kind of, um, get customer trust, uh, by leveraging personalized information in their environments. Um, and on the other side as well is that enterprises looking at how do they manage their generative AI journey?
How do they build a platform that can, they feel comfortable in building multiple applications on top of, in the chain AI space? Um, and for both of them, I say contact us, our website, um, has a Calendly link on it. You can get in touch with us directly, um, and we've got a full team to go through assessing your use cases, how you can leverage the red reactive platform and then get you up and running within the day or leveraging our template applications to be ready and going with internal use cases within two x.
Very good. ai, correct? That's correct.
Yeah. Awesome. Makes sense.
It wouldn't be that. Yes, it's been great talking with you and, uh, again, I think this is a really fascinating area and certainly something every enterprise, every business has to address around secure access to data now with, uh, generative ai, it's interesting. I'm just doing a panel here earlier today and we were talking about testing and access to data and all kinds of, the myriad of issues that come up with that when you start introducing generative ai.
So wish you the best and, uh, keep us, keep us in touch as things progress, and, uh, love to hear more. Yeah, definitely be speaking to you soon, Mitch. Really appreciate it.
ai. I'm Bonnie Schneider, sustainability contributor to the Techstrong Group. I'm excited to introduce you to a groundbreaking new initiative from Techstrong Research, the sustainability pulse meter.
The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry. Position your company as a leader in the industry and differentiate from your competitors with a sustainability pulse meter offered exclusively from Techstrong Research. This is Textron tv.
Hey everybody, I had a great pleasure of being joined by Aaron West. Aaron is sales engineer with sios. How you doing Aaron?
Hi there. I'm doing very well. Thank you.
And, and thanks for having me here today. Of course. Absolutely.
Um, tell us a little bit about sios. I mean, you all have been around for a while, so there's a lot of folks who do know you about you in case, uh, folks don't then, then we're gonna get into an announcement that you just made recently, but start with a little bit about the company. Sure.
So, um, we're a company that specializes in high availability, um, specifically around application availability. Uh, we also, um, we also have products around storage availability and block replication. We've been doing this for a very, very long time.
Um, so, you know, we've been around for ages, as you say, over 20 years in the industry. And, um, our solutions cover both Linux and Windows. Very good.
A lot of both out there in the world for sure, and always looking for more help with it. Uh, talk about the, the exciting announcement that just occurred. Absolutely.
So, um, I'm, I'm glad to announce that we've, uh, released our latest, um, version, which is 9 8 1. And as part of that release, we've really taken things forward by releasing our new web management console. Um, now this is just for Linux in this release, although there will be a, um, a web management console in the future for our, our Windows product as well.
I don't have a release date for that yet, but it's something to look forward to. But those, using Linux can, can take advantage of this now and, um, and see where we're moving with this. Fantastic.
So tell us, tell us some of the benefits or, or some of the things that we can do now that you have sort of web management console, if you will, in, in one place. You know, where you have a lot, I'm sure there's a lot of information that it's vital to know about, but it's hard to pull it all together. Yeah, absolutely.
So, uh, I think the key, one of the key things is, is moving to a, a web management console rather than the, uh, Java based administration application that we've always used at cis. Um, it basically means that it's a lot easier to, to develop and to build upon that as a platform. So for this release, it's really been about making something that's easy to look at, provides all the features that you would currently expect from our existing management, um, platform, and, uh, also puts that across in a very simplified, easy to use way.
What, what would be some kind of example, use cases where someone is, it is something you're gonna hang in the operation center? Is it something someone's gonna sit in front of to go diagnose or understand events that are occurring? Absolutely.
So, um, the obvious thing is the initial configuration of your clusters. It can all be done through the web management console in a very simple stepwise fashion. It'll take you through the steps, you know, 1, 2, 3, 4, 5.
If you stop partway through, you can walk away, come back, pick up from where you left off. So, um, you're not stuck in a situation of having to, uh, understand everything about deploying a cluster straight away. Um, in addition to that, once you've got your clusters configured, management is made very, very simple.
You know, it's a web management console, so you can simply log in from a, your desktop, your tablet, even your phone. Um, it looks good and great on on all of those platforms. Um, from there you'll be able to handle things like failover and also see the state of the system.
So as part of that, we've included a traffic light system. So things are shown as green when they're healthy and operational, and things will be shown as red when there's some, uh, issue at play and you need to investigate a bit further. Um, I think the other thing that I really like about the platform is it's covered tool tips everywhere.
So it explains what these, uh, these features are, what, what different, you know, uh, statuses are. And you can very easily, uh, click around on the tool tips and understand what you're looking at, You know, um, I don't think anybody's ever said Linux and is simple and it's, that hasn't changed. Um, but particularly when you get into cluster cluster management, bail over high availability, um, all of those kind of issues, you know, that takes some pretty specialized skills, but we're adding new people to workforce all the time.
So it sounds like the ability not only to see what's happening, but, you know, help me understand what it means is really Yeah, absolutely. I mean, the burden on your typical day-to-day, IT admin these days is, is growing. Um, and I feel sorry for a lot of these guys.
You know, back in the old days, systems were quite simple. You know, you provide the, the basic IT infrastructure and, you know, businesses small to medium, were typically running on things like spreadsheets and things like this. Whereas now a small to medium business is moving towards having, you know, SAP in their environment.
And as they have these more critical applications deployed and the bus business begins to rely upon them, they then need to become highly available. And also they need to think about disaster recovery. 'cause no longer can you, you know, withstand downtime.
So the burden on the i on the average IT guy in a company is definitely growing, that they're expected to know a lot more about different systems and have a, a wider skillset. A web management console like we provide hopefully takes some of the burden away from them, both simplifying the whole thing and meaning you don't actually have to be a clustering expert in order to, uh, you know, manage and look after a system. Very good.
Um, I'm curious too, um, one of the things about managing Linux clusters is that, you know, you're always having challenges with capacity, uh, workloads kind of applications that you're deploying on those, uh, different environments. 'cause those things don't stay static, right? It's not like set it up, configure it, just kind of let it hang out there and people will use it.
You, you have a lot of variability going on that you've gotta really understand when something's happening. What are the conditions around it? Um, how, how does the web console help with something like that?
Well, I think it takes you away from the traditional way of understanding these things, which is looking at log files, right? Um, you know, many a Linux admin will be sat at a terminal, um, you know, grepping a log file looking for statuses and, and trying to understand what's going on. I mentioned earlier that we've got the, uh, the traffic light system.
And I think that that's a, a really nice way of getting that across. You can now look at your cluster in a visual fashion, um, so you can see it on screen and you can pick up those statuses, uh, from, from the actual management console itself. It'll show you if something's working, it'll highlight if there's a problem, and hopefully it'll highlight, you know, something that enables you to sort of solve a problem before it becomes too serious.
Right? So if you can see that there's latency, say between the two nodes, and you can pick up upon that before it causes a, a false failover or something along those lines, then you can investigate what's the cause of that, um, and solve the problem before it actually becomes a problem. It seems like also having the mobile, the i, the tablet, the mobile other interfaces are, you know, problems never happen when you're at work, right?
It's always in the middle of the movie at the movie theater or somewhere. Absolutely. It seems, you know, every system administrator or operations personal, uh, person certainly understands that, but being able to get access to that information very quickly and easily, so, you know, if you need to respond, would be a vital importance.
Yeah, I mean, I, I don't imagine that lots of administrators will be sat there entirely administering their cluster from their phone. I mean, absolutely you could do that if you wanted to. Um, but the status and being able to view what's going on from anywhere I think is exceptionally important because, um, obviously they can take an action from their phone, it's fully functional, but even just to know what's going on.
So, you know, you have to, you know, jump onto the VPN or return to the office to get a, uh, you know, a problem resolved, um, is also extremely important. And then how you handle those statuses, you know, we can set up potentially alerts or, um, have it monitored in, in other systems within your, your organization. Very good.
Now, now this can work for both on-prem as well as in the cloud. Is that correct? Yeah, I mean that's a, a really good feature, I think, uh, of, of what we provide.
So our high availability solution covers, you know, Linux and Windows as we mentioned earlier, but also it's suitable for on-prem cloud deployments as well. Uh, and it looks the same wherever you deploy it, which is a really nice way of, uh, of, of having a solution because all too often these days, you're an Amazon expert or you are a Azure expert, um, and understanding how things work across different platforms can be, you know, again, it's one of those burdens that's on the average it, it administrator, right? Um, but our solution allows you a common HA solution that looks the same wherever you deploy it works the same wherever you deploy it.
Uh, and I think that's one of the real benefits. If you're looking at sort of, you know, having stuff stretched between on-prem and the cloud or maybe even multi clouds, It seems like too, the benefit of being able to look at all of that, right? Not just at a single part of it element of a time.
'cause of oftentimes, you know, a distributed cloud application might be talking to a database or an application located in your data center, or it's distributed in multi-cloud fashion. So it, uh, could be a hindrance just if you can get the window into one of those environments. But by being able to see all of it now you can trace down what's going on.
Yeah. And we are also integrated into those environments. So, you know, when, when we're working with Amazon, we are working with things that you used to route 53 EIP PS routing tables to get client access traffic to, you know, the active node.
And the same with when we are working in Azure or other, um, hyperscaler cloud environments, we tie in using our application recovery kits to those environments, you know, directly. Good. Um, now is this delivered as a SaaS, as a, as a cloud-based application?
Is this something people can install in their own data center or both? No, it's, it's absolutely something you install. So it, it will typically be running on the same nodes that, uh, uh, uh, form the cluster itself.
So, you know, typically you'll have, say, two node cluster for something like, uh, a SQL server. Um, and both of those nodes will host and run the web management console along with the actual clustering software itself. However, the software can connect to other nodes.
So, you know, the idea is that as we go forward, it becomes more of a single pane of glass. You'll be able to view your entire infrastructure through, through just connecting to one of your active nodes. Uh, interesting.
Just kinda using any, any node, at least in the future. Any no. Is an entree way into all of it.
Correct. That's it. Very interesting.
So you mentioned, um, the configuration of it, of the web console, uh, web management feature, uh, earlier it sounds like just, uh, does it come with pre-configured with any monitoring or any, uh, um, kind of red and green lights? Or do you start out kind of with a canvas that you build what you want? Yeah, I mean, the basics of of monitoring is all there.
So once you, once you deploy a cluster and actually create that, that cluster, that's gonna show up in the web management console and, uh, you know, different recovery kits that are being used. So these are our, our specific, uh, way of interacting with different applications or platforms. We have our, our arcs, our application recovery kits.
Those kits will each have their own, um, their own warnings and statuses that are then shown. And, uh, you know, that's what I'm talking about having the traffic light system, whether it's green or red. So if you, for example, you've got, um, you know, uh, an an IP address that's, uh, you know, being moved between instances, you could check the status of that IP address.
If it's a, um, if it's a storage volume that's, uh, replicated between instances, you could check the status of the storage and see if it's healthy and working as it should be. Very good. So folks wanna get their hands on this.
Maybe you get a demo or, or do a free trial. How do they do that? Well, all of our, all of our documentation and information is available on our website and, and you know, it's not behind paywalls and, uh, complicated login.
So you can go and check that out. Um, you could also book a demo right there on our website. So please do.
We'd love to talk to you and, uh, introduce you to our, um, simplified HA solution. Very good. com?
Correct. com. Okay, very good.
com/demo-request and, or free dash trial and get you straight to it, or you can get there just from the main page. Very good. Um, anything else that you wanna add, Aaron?
Just to say that this version isn't just about our web management consult, it also comes with more platform support. So, um, you know, the actual product has moved forward, not just the addition of the web management console. So you'll see newer versions of, uh, of Linux are now supported.
So check that out too. Okay. Part of a broader kind of up upgrade too.
That's right. Very nice. Well, thanks.
It's been a pleasure talking with you and appreciate all the helpful information. Congratulations on the, uh, launch and, uh, look forward to the Windows version sometime down the road. Thanks for joining us.
Hope we get to talk again soon. Thank you. You bet.
Take care. Aaron Cloud Native now is the web's leading resource for the growing cloud native ecosystem. com is your destination for news, thought leadership, features and webinars on cloud native architecture, Kubernetes, serverless, cloud native application development, microservices, service mesh, cloud native security, and more.
Stay on the cutting edge of modern application development at Cloud Native. Now, This is Textron tv. All right, guys, we're back at CubeCon plus Cloud Native Con here in lovely Paris.
And we're talking to Cole Kennedy, who's CEO for testify sec. And we're gonna be talking about, well, the failure to communicate in the land of DevOps. Cole, welcome to the show.
Hey, thanks for having me. We have all these tools, they generate all this data, and I've talked to developers about this issue a million times. 'cause they, they hate this, right?
They're like, somebody comes along and says, can you update this? Or whether it's a project management app or whatever it is. And they go, why do I have to update all this stuff is in this thing already.
I have this tool here. Why can't you just collect it? And they get frustrated.
'cause they don't want to sit down with somebody and say, you know, here's the update. Or they don't wanna have to come out of their thing and say, you know, let me send you a message about a thing I just did, so then we can have this asynchronous conversation. Yeah.
That is all a waste of time. So how do we kinda uplift this whole thing? Well, I think, you know, we can look at, you know, the recent past and when we started working with DevOps, right?
It was all about how do we communicate, how do we communicate more effectively, right? Uh, you know, before we had these DevOps methodologies, it might have been that email that you sent to your production team saying, Hey, here's a binary, let's go deploy this thing, right? But over time, we started developing APIs to help us out with this, right?
Um, Kubernetes, Ansible, Terraform, these are all APIs that allow us to communicate much, much more effectively. Um, the problem is, is that, you know, we don't have these APIs, really, or these APIs are very new when it comes to communicating about security, which is I think a lot of these tools that you're talking about, right? I see folks they like, use even Discord servers now to kind of communicate about a project.
Feels like we've done a lot of unnatural things to figure this out. So, um, how automated can automated get as we go forward? Because you guys got the framework now, but what comes next?
Right? So, well, the framework, first of all, I'll do a little plug, it's in the, in total A is the API that allows this, a lot of this to happen. It allows you to create signed metadata about the different events in your software delivery life cycle, right?
So when we have this trusted telemetry to communicate these events, we can evaluate this in an automated way, right? So pushing all these events into an API, whether that's a security scan, a two party code review, um, you know, or, or some other sort of a sign off or other tool that you use once you put all this data into an API, uh, that that data can actually be used and be auto automated or be evaluated in an automated way. Um, so, so that's really, you know, where, where the industry should move to if they wanna fix some of these issues around communication with DevSecOps and speed up these manual processes.
We've had this issue for years is, and we're now at a CubeCon event. Yep. Is there something about cloud native and microservices that kind of forces this conversation?
Or do we get to a level of complexity where people go, I can't deal with this anymore? Yeah, and I think that's what you're seeing is that we're moving much, much faster because we have these APIs around DevOps, but we're still slow when it comes to security because we haven't efficiently, we haven't been able to, uh, um, make that communication more efficient. And so when we have microservices, right?
That's even more applications that are moving even faster into production. So security can become a really big roadblock unless you have a really good methodology to understand the status and the risk of your artifact. And when you have more artifacts because you're using microservices and you're using DevOps, you have more releases, right?
It only compounds the issue. And, and so this is why you're seeing a lot of the scissors, a lot of security engineers are, are, are very over overworked in, in this problem becomes un trackable unless you kind of change your methodology and how you're doing things. So in, in a way, we're kind of creating this immutable workflow that we can understand and we can verify that this took place with this time with this component.
Mm-hmm. Who, um, who wakes up in the morning and says, we gotta go solve this issue. Is it the security side?
Is it the DevOps team? A-C-I-O-C-T-O? Yes.
Well, I mean, you know, it's up to the says, oh, the CI CEO of the company to understand where their risk is. And we've seen a lot of organizations have failed to understand how much risk is exists in their software. Um, so it starts from the top up, right?
And then, you know, know, as an engineer, we have the responsibility to put out secure software that protects our users. So that's from the bottom up too, right? And so it really has to be a whole organizational effort, which again, comes to the problem of communicating, right?
Sometimes it's very difficult to have that cross organizational communication, especially when it's a, a manual form of communication. It seems like there's a lot more regulations talking about securing the software supply chain. We had the Biden administration and issue an executive order for the federal agencies anyway.
Um, do you think we're gonna see more of that type of regulation that's gonna require companies to go address this issue a little bit more? Because right now I feel like it's still a, you know, it's a vitamin in the sense you should do this, but it's gonna become a headache real soon. Yeah, I think we're starting to see it change from should to shall, um, you know, the, the this, uh, just released that self attestation, um, PDF, that now if you're a CEO of a company, you, you need to sign that thing or have a designee that's authorized to sign that, sign that thing.
And, and that form, you know, puts down on paper that you comply with, uh, secure software development, um, practices when you're pushing out software. So if you're selling to the US government, like these, these are, these are shall now you must do these things in order to do business with the government. Um, so I think we're gonna start seeing this filter down to other organizations such as, uh, large banks and, uh, other industries working with high compliance, right?
Because, you know, a big part of, uh, of their threat is that software coming in from their vendors and, and they really wanna be able to control that. Um, and, and right now it, it's very difficult for them to do that because we get back to that communication, right? It's tough for them to communicate what the status of, um, or what the vulnerabilities of the software that's coming into their system.
They just don't have a system set up to do that. I don't think everybody knows who you are, but, um, you know, how did you get into this? Where did you come from?
I mean, not everybody wakes up in the morning and goes, I know I'm gonna go solve this security software management issue. Yeah. So my co-founder and I, uh, Mikel, we were working, uh, for joint Special Operations command, um, developing applications to help the war fighter down range.
And I actually got sent overseas week before Christmas to go deploy this application. Um, and I got there and because it was on a different network, this was a NATO network versus a US network, the compliance rules were completely different. So we weren't able to deploy that 'cause of software because we didn't check all the boxes.
Um, so I ended up spending Christmas away from my wife and my one, my 1-year-old daughter, and we completely failed the mission. The war fighter didn't get the software they needed all because of this compliance issue. So, so this really gave my co-founder and I the impetus we needed to say, Hey, what do we, what do we do to solve this problem?
Right? Um, and, and it ended up being a lot more complex than we thought it was. Um, so, so, you know, five years later, um, you know, we were working with the DOD platform, one for a consultancy called Fox Code, and we ran into some of these similar issues, but this was for a nuclear weapons program.
They, they had these requirements that, that code it needed to get checked, right? But, but this didn't fit into the paradigm that Platform one had created. Um, so we reached for this open source project called in Toto and, and started implementing there at DLG platform one.
And it worked great, but it was a, it was a very academic project. Um, so Mikhail and I, we started working that, working with that project, adding the features needed to work with enterprises. Um, and that's when the company we're working for actually got, got sold to IBM.
So we're like, Hey, you know, we think we have an idea here. We think we know how to solve this problem. And, and it's a problem that does need to be solved.
So, so we started, uh, testify Stack, uh, with, with the, uh, you know, the purpose of, um, providing everyone with secure software. So, first of all, let me ask you, is your wife still talking to you? Because most people, you know, are the 1-year-old and you're overseas and it's Christmas, you would probably be getting a lot of dirty looks for a long time.
Yeah. Yeah. She, well, now that I'm bringing her to Cube Con in Paris, she, she's much more happy with me.
Um, but yeah, it was, uh, you know, solving these problems does take a lot of support, um, from your family, especially when you're getting deployed. Um, it was a, you know, that was a, it was a difficult job. Um, but, you know, it's something that, you know, had a profound impact on myself and profound impact on my co-founder.
Well, besides, you know, what happened on your family side, but with the work, do we underappreciate the amount of stress that we create because we don't have the right kind of handoffs and the right ability to verify that this was created? 'cause it seems like there's a lot of, you know, I don't know what I got, or I get there and suddenly I'm missing a component in your case. But, um, you know, have we become our own worst enemy sometimes?
Yeah. And that's all goes back to the inability to communicate. If a CISO could communicate with a developer and says, this is exactly what you need the software to do in order to be compliant and, and do that in a way that the developer understood where a lot of these problems would go away, right?
But what we see is, okay, the software's ready to go in production, but now we're missing step seven, eight, and nine, uh, because we have all these regulations because this is going into a bank, or this is going into a weapons system, or this is, this is going into some other high compliance areas and we just can't, we just, we gotta do the right thing, right? We, we gotta be compliant. Right?
The Army has, uh, an acronym called snafu, right? Um, have we accepted that too much in software? 'cause it feels like sometimes, uh, our teams are willing to put up with a lot of things that maybe they shouldn't.
Yeah. It, you know, as a software engineer, we're taught to move very fast, right? Getting shipping things is the most important thing.
Um, and, and with that methodology, right? We forgot about, you know, basic engineering, right? We should, when we create something, we should test it to make sure it works, right?
And, uh, I I think now we're starting to see all that come full circle, uh, with that, with, with DevOps now we're turning into DevSecOps making that security in. Uh, so I think things are changing. Um, um, but yeah, there's a lot of work to do, right?
We, we need a lot, we need that verification, that formal verification of our software in the processes our software goes under in order to understand the risk associated with it. Yeah. So what's your best advice to folks?
'cause you've been here, you've lived it, and you know, these teams. So, you know, when you go visit a customer, what's that kind of thing that comes to mind when you go, folks? Man, if you just thought about this one little thing, it would make a world of difference.
Yeah. It's all about observability and, um, the software delivery lifecycle is missing that component. And this is one of the things that we worked on with the CNCF software Supply chain Best practices paper, as well as the CNCF secure software factory reference architecture is we found that this, this, this observability component just missing from all these different CI systems.
Um, so can, can I tell you an analogy kind? Sure. So, I mean, if, if you had a daughter and she was getting married and she wanted this perfect cake for, for her wedding, right?
You would bring that set of instructions to the baker, and then a couple weeks later that Baker would drop that cake off at the wedding. Well, what you've done is you've established a trust relationship with that baker. If that, uh, that kitchen, they, they baked it in was dirty, or the, the, they didn't wash their hands or they used the wrong ingredients, you really don't have any way of knowing that until you eat that cake and get sick from it, or don't get sick to it.
Um, so if you didn't want your wedding to be ruined, I would recommend that you hire an observer, um, to watch how that cake's being made, right? Every time that baker washes their hand, they write that down on a piece of paper and they sign it, right? Every, they, they, they look at what is the oven set to write that down on a piece of paper and sign it.
They, what are ingredients go into it, right? Write that down on a paper and sign it. So now when that cake is delivered, you can deliver those, that envelope with all those steps in it.
And as long as you trust that signature on that envelope, you know how that cake was made, right? You don't have to trust that baker. Now you can trust that observer to know that, hey, this wedding is not, not gonna get, uh, get ruined.
And we need to do the same thing with our software, right? We need an observer to watch the process of our software being made. And then when we do that, right, we can look at those observations and as long as we trust them, right now, we can run that software with, with a good sense of assurance that, hey, it was built the way that our regulators tell us we need to, to build it.
Or the way our CISO tells us we need to build our software. Right now we know it is because we trust that observer. So what are the components to make that happen?
'cause if it's observability, right, I need some ability to collect it and some ability to obs analyze it. So what are those things, right? So, uh, we, we are, we maintain two open source projects at Testify SEC one is witness and the other is IV Vista.
So Witness is our observability tool. Um, this collects information around the CI process. You can either embed it directly into, uh, your CI process or, you know, we do have some integrations with GitLab and GitHub that make it a lot easier to do, but then you need somewhere to put this information.
So that's why we create IV vista. So IV Vista is a storage database that stores these in total attestations and allows you to query them. Um, so with these two components, you're effectively able to observe the entire supply chain, have a great place to store that information and query it.
And then witness also has a policy engine that allows you to evaluate all this evidence to determine whether an artifact is compliant or not. Um, most of the time this process takes days, right? 'cause you're exchanging emails back and forth.
We can reduce that time with those tooling to, you know, you know, under a second, you can't walk down the street without somebody talking about ai. Is this a foundation for right now? I'm gonna go query something to find something, but at one point, will it start to just tell me that there are certain things that are a higher risk proactively in a kind of a danger will Robinson kind of way, but let me know that there are issues in there that I'm not even aware of.
Yeah, I I think AI definitely had to place a play in, in the area of security, but exactly what you said, right? To bubble up information that you might not normally see. Where I don't see AI playing a role in security is where we need to make deterministic decisions about, um, the risk of a software artifact, right?
So it, it, it, a decision made by an AI engine is, isn't necessarily, at least not today, is not gonna pass the muster for, for most, uh, compliance officers, right? So we need some way to do that deterministically. So that's really what we're focused here on set testify SEC is, is not using AI to, to evaluate these attestations.
However, uh, we use a deterministic model to do that. And then we'll use AI to help the user sift through the information and find out, you know, that, uh, you know, some of that, uh, stuff you're talking about, those events, probabilistic is a fancy word for gambling, right? Yeah, yeah, yeah.
Right. It is. And regulators don't like that, right?
Exactly. Buddy, thanks for coming on by. Hey, thanks for having me.
All right. This is Textron tv. Hey guys, thanks.
The throw, we're here with Perma Ban, who is general manager for tansu, for the new Broadcom that's been created as a result of the acquisition of VMware. And we're gonna be talking about, well, everything from where is Kubernetes being used today, what are some of the issues that we're encountering? And for that matter, is AI gonna drive further adoption of Kubernetes?
And we'll get into it from there. But Pima, welcome to the show. Thank you, Mike.
Great to be on the show and good to connect with you again. I feel like, you know, I've been following Kubernetes for longer than I care to emit. No, I feel like sometimes there's us old timers and then there's a lot of newbies and nothing much in between.
But, um, one of the things that seems to be happening is, I would argue Kubernetes is maybe becoming a victim of its own success. It's finally getting enough adoption and enough traction in the enterprise and production environments. But as it does so too, does the course of complaints about the application development experience and the data scientists are now involved and they're saying, this stuff is hard.
So where are we on this journey and where do we need to get to? Yeah. It's interesting that you bring this up because, um, uh, I was at Europe just last week in Paris, and you are a hundred percent right.
The frenzy of innovation around Kubernetes is just crazy. The energy was amazing. And I would say every time I turn my head around a new little project solving a problem that is specific to Kubernetes.
So what I saw, as you said, is all the newbies and all the DIY yourselves, you know, DIYers, who were connecting dots and building a lot of stuff, a lot of open source contribution. But the interesting thing was, I also met some enterprises that are saying now I have slowly grown my Kubernetes platform team from, you know, I was experimenting with five people and now I have 75 people. Uh, and ultimately still my developers don't have a simple interface to deploy and manage their applications, to build their applications.
They are, we are trying to teach them yaml. We are trying to teach them configurations. We are trying to teach them how to handle Kubernetes itself.
And so the thing that I ca take came away is no doubt, the innovation in Kubernetes is amazing. We have been early, uh, we early to lean in into that, and we'll continue to lean heavily into that. But I think the bringing that promise of Kubernetes to developers is where we see a gap.
So the container platform to the app platform, and that is where we wanna strictly position tonsil, right? And that's where we have positioned tonsil to say, how do you take the power of the innovation that is happening and put it at the fingertips of developers without having them to learn 25 different projects and 35 different configurations, right? That's the, um, that's a promise.
So it was very interesting on the ES side. Yeah. Do you think there's a correlation between Kubernetes and this platform engineering movement that we hear a lot about, which is heavily focused on increasing developer productivity?
And does this all kind of tie neatly together with some higher level of abstraction that we're looking for? My goodness. Uh, absolutely.
You see the, it's not as if platform engineering as a discipline has not been there before. You know, of course, you, you know, from tan Zu platform, we also have the Cloud Foundry around time, and there's a very strong platform engineering discipline that was built around that. But that same demand, or it's like a drumbeat is coming up now for the modern app based on Kubernetes work to say we need a platform engineering discipline.
And the discipline is not just about products and platforms, it's also about fundamentally how do you think about the relationship between developers and platform engineers? How do you think about the cultural transformation? How do you think about the processes and what we have, uh, now an industry term called define golden paths to production, that is all part of platform engineering.
And if you want to do platform engineering, right? We know you cannot expose the guts of the platform to the developer. Why does a developer care?
And so imagine if you could just give that abstraction to a developer to say, Hey, you have written your code. You want to build it, you want to bind external services, you want to deploy it, you wanna update it, you wanna scale it and secure it. That's it.
You don't need to know how to configure a cluster. How to configure is your service mesh to connect to each other? How to configure a particular load balancer to talk to that environment.
And that is where I see the next generation of evolution happening. Mm-Hmm. In the market, and at least the, whether it's happening or not, it's really the demand is coming up now, right?
And, and more so as you start talking about AI ml, I can't help but wonder though if some of the complaints are tied back to, well, we just didn't think through the application we were building and whether it was fit for this particular purpose or not on Kubernetes, because there's a lot of people talking about, well, we should do everything in microservices. And then there's other people who say, me, you shouldn't avoid microservices at all costs unless you absolutely have to. And then there's other folks who are somewhere in between.
But do we need to get smarter about what kinds of applications we're deploying on Kubernetes? 'cause maybe a little bit is people are just like, well, it's the cool new thing. I should build an app for it.
Yeah, I think that's a very interesting thing, which is, is it the tail wagging the dog thing, which you start. And our, um, philosophy and premise, and this is what Tansu has championed for a long time, is it has to start from app down. Ultimately, that drives the business need and technology choices.
You don't a technology and say, okay, I'm now unfortunately is happening a little bit, but if when you start app down, then you say, what is the right architecture? Then you say, what is the, you even say, what is the right language I'm building? Right?
It starts from there. So that you want to reduce the toil as much as possible. Let us say I'm building a new modern app.
Maybe I will start with spring. It's already given me all the connectivities. It gives me the framework, it gives me this beautiful place in id, I start building my business logic.
That is where the biggest power comes, right? In developers building the business logic for your environments. And so you build that business logic and then you say, okay, let me make a call.
Where do I want to have this run? Do I want to run it on a Kubernetes based platform, or do I want to run it on maybe virtual machines or do I just go for pass services from, uh, certain types of things? I don't even, uh, need to build something, you know, build and package something there.
And so that decision comes next. And then the decision is a which environment do I deploy? Maybe if I have a lot of proximity to data and I don't wanna ship it around, I do it on a private cloud.
If I have very little, you know, if I, if network traffic is not gonna kill me, maybe I do it on public clouds, or if I need a lot of geolocation and proximity to end users, I get the power of a public cloud. So you have to pick based on the application judgment call. And that is where I feel the transf, uh, power of platform engineering comes in.
Platform engineering should make these choices as intent for the developers. So imagine I build my business logic, then I say, Hey, look, I don't want to, uh, curate my own database. Give me an external database to bind into it, for example, or external data source to bind into it.
And with AI ml, now people are saying external model that I can start using, because I'm not always, everybody doesn't build models. Most people use models, right? And, and so that could all just be intent of what you want, the language bindings and the environment that you want.
Another intent could be, Hey, I want high availability. Give me across multiple clusters and failover. Give me low latency.
Give me access to data. All these things, rather than it be defined by the developer at a Kubernetes level, for a Kubernetes sake, you define intent at this level. And ideally, the platform, the platform solution product, as well as the platform engineering team should then drive the translation of that.
And, um, and, and then ultimately the deployment of the applications and management of applications. That is the ultimate state where we have to be. By the way, this is not new.
This is a pattern we've seen before. If you remember, uh, I, I, I, I say I was in cloud before cloud. I was with a company called LoudCloud, uh, mark and recent and Ben Horowitz's company in, and, you know, 98, 2000, and we were building a cloud.
And at that time, I know customers used to come and say, Hey, I wanna see my server. And we said, you, you don't get to see your server. It's virtual.
You know, we have virtualized it. And uh, you, you are, it's a shared pool. I think it's the same thing.
You don't need to own your Kubernetes clusters and Kubernetes environments and know your service meh architecture that has to get abstracted at the app level. So this narrative of container platform getting elevated to app platform is key. We talked about the platform engineering team, and a lot of those folks are basically trying to manage DevOps at scale.
But there's been this ongoing conversation about, uh, do I deploy Kubernetes on the virtual machine? Do I encapsulate the virtual machine so it runs in a container on Kubernetes, or do I put everything on a bare metal server? It seems like we're still all over the place.
So what drives people one way or another? Um, sometimes it's logical decisions and sometimes it is religion, right? You know that.
And so, but if at least our philosophy, and when I think about tan zu and I think about B, C, F and VMware is just like with virtualization, we just gave a runtime that just works. Do you ever think about ESXI? No, it just works.
You ask for a vm, you get a vm, and we are doing the same thing with Kubernetes in the, so rather than thinking, so we are separating the runtime in that platform. So we're saying the runtime just needs to be a fundamental dial tone that needs to be part of the infrastructure. And so with our VMware cloud foundation that I talked about, we are saying just like you can go and ask for a VM and you can ask for it to be highly available.
You can move it around. You can do all this dynamic workload balancing. Imagine you can just go and ask for a Kubernetes cluster, a Kubernetes environment that is just simple namespace.
These things are, um, something that an infrastructure admin just sets up as a stable stakes, and you don't really start think worrying about. And, and what we have done in internally is of course made it highly performant on top of, um, the BSPHERE and ESXI infrastructure. So whether it is bare metal or not becomes a material, it just easy and the dial tone is there, and then the question becomes, okay, how do you start using that, that that is Kubernetes?
So I feel like at this point, the Kubernetes dial tone is a moot point. It's like you either get it as part of your private cloud infrastructure with vSphere, or you go and get E-K-S-A-K-S-G-K, these offerings have matured a lot. They're pretty good and they are continuously innovating.
So for somebody to be sitting and thinking about Kubernetes style tone and trying to spend an an inordinate amount of effort on that is a waste. And then the question becomes, what do you do after that? How do you now connect the dots between the container on time and start putting services on it so that it becomes usable?
Right? I should not be, again, asking ever for clusters, right? I should be saying, Hey, this is my app and this is my intent.
So how do you define networking? How do you do mesh type of characteristics so that you can connect all these clusters? How do you define regions and availability?
That's where platform engineering power comes. We am starting to see some new folks hanging around the proverbial Kubernetes cooler, and it looks like AI workloads are becoming a killer app for Kubernetes, but we have all these folks who are, uh, data scientists and they're using ML ops to build these models. And then somehow or other we want that to get handed off to the DevOps slash platform engineering team and throw in some data engineers and a few security specialists on top of that.
How do we structure this so that it, it, it, yeah, it kind of works. Again, this is a philosophy that we have and it's changing, right? Where, uh, we all are learning as we go.
Mm-Hmm. But I think we need to separate model development from model use in. And, um, I think if you start doing that, that becomes a lot.
First of all, you have to think, you know, hey, how many people are actually building net models from scratch? How many people are versus how many people are fine tuning with their context and then incorporating it into their business apps, right? We have got all kinds of very powerful models being innovated.
There is a, and, and, and there are all these cloud services that are offering, um, AI ML services. So when you do that, then you say, okay, of course, Kubernetes as a place to run AI ML workloads has become very popular, uh, at CubeCon. In fact, the keynote was AI ml, everything was about AI ml and AI ML workloads.
Now, if you separate and whether it runs on Kubernetes or not, once you separate those two, then you say, okay, what things can you do to help the model developer's life easier, right? How do you do the data cleansing? How do you do the, you know, data engineering?
How do you do the, um, fine tuning of parameters? How do you do the closed loop cycle to get the model right? And then the second part is, hey, how do I let us say I have a model that is developed for a particular industry vertical, and it has got all the right data, everything.
How do I start using it within my apps, right? 'cause model by itself does nothing. You still have to put it in context of the business apps or the business services that you're trying to deliver to their end customer in terms of the interfaces that you're giving to the customers and so on.
And so, um, that is where I was talking earlier, we have done some amazing innovation in spring, uh, called spring ai, and now it is part of the Zu platform with and MLS and the idea, the power of these models that are being developed in Python, but to a Java developer, most of these enterprise apps, 50% of the enterprise apps are in spring and even more are in Java. And ultimately the data sits here, the context sits here, et cetera. So how do you bring that power?
So which bring ai, we have created these Java APIs that allow a Java developer to then access these Python models or other types of models that may be connected to public cloud models, bedrock or OpenAI, any so on. So you are getting, making it easier from a usage perspective. And that of course, naturally fits within the platform engineering piece.
It fits within your, um, build and deploy infrastructure very easily. Do you think we might soon apply AI to the management of Kubernetes itself because, um, it's still fairly difficult and requires a certain amount of expertise. It's getting easier, but I can't help but wonder if, uh, maybe we can use AI to cure what ails us.
Um, absolutely. And we have already done that. So not just specifically Kubernetes, but uh, we launched something called as part of this tansu portfolio, right?
We have really bought the tansu platform together, right? The, the one that I've talked about it, and it's anchored by something called Tan Zu Hub. Tan Zu Hub essentially takes the data associated with your operational environment, your performance, your metrics, your logs, your information about your architecture, your dependencies of Kubernetes clusters to the, um, you know, virtual machines, if it's running on that or your networking dependencies.
And then we have a gen AI based interface on top of it where you, rather than saying, looking at red, blue, green blinky lights in a dashboard and then saying, clicking and saying What went wrong? How do I solve? Often management is less about initial deployment.
Initial deployment happens somehow, but then the minute the next, you start deploying apps and, and now your latency goes through the roof, your logs are not getting collected properly. How do you debug all of that, right? That's where the problems start.
And so this AI ML interface, and we'll be happy to show you, actually send you a video of it, allows you to just ask questions, Hey, which application is having trouble? Show me where the trouble is. And then it takes you to the right screens and walks you through the process, and then also gives you answers on what you can do.
So while it is not a just purely a single button button magic, but the AI ML is a very powerful way to help humans interact with operational data. Operational data is fundamentally complex. And you shouldn't have to sift through operation data or write massive queries to understand operational data.
You should be able to talk to it. And that's what we have done with Council Hub. So ultimately, what's your best advice to folks?
Or, um, since you've been around the block a few times, what do you see folks doing in the land of Kubernetes today that just makes you shake your head and go, folks, we need to be a little bit smarter than that. I think, uh, you hit it when you asked the first question, please go and understand what is the goal and outcome you're trying to drive. Kubernetes is not an outcome.
Kubernetes is a method to get to the outcome. And as long as we keep that sanity, you know, anytime a technology becomes popular, everybody wants to adopt it. They just want, it's great on your resume, it's great on your skillsets, but even on your resume, if you can say, not just that I know Kubernetes, but I have managed to use Kubernetes to drive this outcome.
Just even if you're thinking about your resume, do it that way. So the whole industry as a whole, and many, many do that by the way, but as a whole, as we, if we start looking at these projects and start making them outcome driven, right, that you're doing within your organization, that will actually drive a lot of value to you as an individual, but also to the company. Alright, folks, you heard it here, Kubernetes, it's a means to an end.
So start with the end and work backwards. Hey, Pima, thanks for being on the show. Thank you, Mike, And thank you.
And back to you guys in the studio. Hey everyone, it's Alan Shimel for Techron Gang. We've got a great day.
We've got what's going on with Intel, same old, new stuff. Is AI really sustainable? Our L LLMs commodities, we've got that more as well as a special guest on Textron Gang.
Hey everyone, welcome back here. Happy Thursday to you. We've got a great text on gang today.
We've got three blocks we want to discuss. One is regarding a lot of information coming out on Intel. Some of it's good, some of it's bad.
We've got a very special guest who's gonna bring the intelligence on Intel to you today. We also have a, a great block on sustainable ai, sustainable by design with our own Echo Insights editor, Bonnie Schneider. And then we're gonna talk about in maybe the, the fastest instance of internet time, have LLMs already become commodities.
We're gonna discuss that more. Let's kick it over to our, uh, chief Content Officer, Mike Ard, who will jump in on this. Hey guys, always happy to be here.
We're gonna talk to Daniel about this next topic right away, but Intel's got a $7 billion operating loss and it's chip making unit. They're reorganizing the company. 5 billion from the government to go build some factories somewhere.
5 billion ahead here. I don't know. But Daniel, what's going on with Intel?
I know you follow 'em closely. Hey, wait, but before we do that, Mike, not everyone here knows Daniel. Mm-Hmm.
Really? Why did you introduce Daniel? No, I just said we had a special Intel intelligence guest, but this gentleman right here, Daniel Newman.
Daniel is the CEO founder of Futur. com is the website, isn't it? Yes, sir.
Daniel, welcome to Techron Gang. Man, it's a pleasure to have you on here. Yeah, it's great to be here.
A number of the analysts of the Future Group have joined, uh, Techron over the years and over some different events. And, uh, it's, it's fun to be in the studio with you all. Um, yeah, I mean, look, Intel, uh, first of all, chip making, uh, the chip industry is cool.
Again, I just wanna point that out. There was a period of time where it was all about cyber DevOps and ai. Well, thanks to what happened a few years ago, the shortages, people couldn't get vehicles, they couldn't get laptops, they couldn't get their phones.
All of a sudden, chip making became the most important thing in the world. And I think you mentioned Mike, uh, when you talked, you said eight and a half billion dollars of grants. They also got $11 billion of loans.
They're building a super fab in Ohio that hopefully will bring the US back on parody, um, at least back to some level of parody on, in terms of what Taiwan is able to do. We don't make any leading edge chips here. We make none.
And that's a really important detail here for everybody out there in the audience, is that Intel has this kind of bifurcated role. First of all, they are a really important, uh, company in the United States. Uh, Gina Raimondo, the, the, the treasurer, uh, I'm sorry, the Commerce Secretary came out and said basically they are a treasurer.
But here's why it's important is ai, and we're gonna talk about AI probably all the time on this show, right? Y'all talk about it quite a bit. Well, you can't run any of these software.
You can't do any of these developer apps. You can't, you know, build security applications without chips. In fact, silicon will lead the world.
I made a prediction three or four years ago, okay? I'm running a muck here. But the point about Intel is, yes, they reconfigured, they resegmented their business yesterday.
So you talked about a $7 billion operating loss, but we were talking about there is, they've now split to a products and a foundry model. So everybody thinks about these fabulous companies like a MD and Nvidia. Great business models make a ton of money.
Well, Intel is actually a fully integrated, uh, design manufacturer of chips. They make the whole thing from, they design them, they manufacture them, they sell them. They were presenting their business as an integrated model.
And the market wasn't fully understanding it because now they're coming out and saying, Hey, we're a foundry. We're a foundry as well. So if they're gonna be be a foundry, that means they're gonna make chips for Qualcomm.
They're gonna make trips for Nvidia, they're gonna make chips for a MD by the way, they're gonna make potentially chips on arm, not just X 86, which crazy, which everyone knows them for. So yesterday they came out and said, basically our foundry business, it is not making any money, but we went back and we're actually gonna show you what our business would look like if we were running a FLI and we were running a foundry. Their foundry losing a lot of money.
The fabs part of their business though, is actually making a lot of money. So Pat Gelsinger and their CFO, David Isner came out and basically said, we're gonna show everybody how this works. Now, why this is really important in the end is one Intel is a fli, does very well, makes a lot of money.
Two, they've executed what they call their five nodes in four years. And this was a really important thing because the company needed to get back in some shape of design, uh, leadership, their technology leadership. Mm-Hmm.
And let's face it, they fell behind. Nvidia obviously jumped way ahead on in ai. They're still ai.
So A-M-D-A-M-D, uh, across X 86 took market share, both in the data center and on pc. Um, and now we basically need to understand is Ken Pat Gelsinger right? The ship, what he wants people to understand is he has helped right?
The ship, but the foundry business, let's face it, if a US and the West cannot manufacture leading, leading edge, five nanometer, three nanometer, two 18 angstrom future nodes, we will fall behind on a, on a global scale. And that yesterday is important. But, um, my last thought, I'm not gonna talk a lot.
I'm sorry. My last thought is basically, when does this foundry become profitable? We're gonna invest 8 billion in grants, or eight and a half billion grants, 11 billion in loans.
They're building all these fabs. Everybody. It's gonna take three or four years just to get to a return on invested capital.
It could be before. You think it'll be that soon? I thought it was.
They're talking three, four years. 2030 is when they're really talking about being able to start. Well, I'm just talking about the whole foundry business.
Okay? Yes. Those foundries themselves, they definitely take time to recoup cash.
They came out, they were very honest about it. They were forthright investors, probably didn't love it. But now they've done this great reset Mm-Hmm.
And we now know what Intel's plans are and how they look as both a foundry and as a fabulous, I'm a little more cynical, um, and always am so really Pat Gelsinger, is he not now the new modern Lee Koka and Chrysler. And this is a bailout from the United States government courtesy of the taxpayer, which is okay, but let's just say what it is. Well, they're not the only company getting grant money.
So you, you know, every one of these fabulous and design companies, whether it's global foundries, whether it's Intel, they're all looking to get capital soer. Companies like Nvidia, a MD Qual, they're all looking because there's innovation dollars. Mm-Hmm.
There's, there's foundry and development dollars. Um, look, when the, when the government's handing out dollars to push innovation, every company's gonna be looking to participate. Having said that, the reason Intel is so important, Mike, and, and by the way, I'm, I'm, I'm, I can be cynical about this too.
Um, the reason it's so important though, is that we don't have another option. We cannot completely outsource and offshore all of our leading edge development. And right now, the only companies that are developing and building fabs in the US are not US-based companies.
So you have TSMC building in the us, you have Samsung building us, and these are good partners. These are good allies. But at some point, you have to understand geopolitical situations change.
And if the US was ever required to be self-dependent, to be able to make its own leading edge chips, so we can have these phones and these laptops on everything, next generation, vehicles and cars, you know, the lagging stuff we do, we do. Okay. You know?
Mm-Hmm. No one likes, when I call it lagging, by the way, Alan. Um, but the leading stuff, like, we wanna win ai.
And by the way, China, I don't care whether they get EEUV, whether A SML is shipping to them or not, this technical stuff. But, um, I Understand it. China will not stop because of the controls that we're putting into place.
They're figuring out their own ways. You saw iPhones down 33% last month. That's because they backed Huawei.
They're pushing Xiaomi harmony and they're making it easier. Chinese desirable for people to buy Chinese made products. And yes, the their, their economy has its own challenges As well.
No, no. But yes, it does have their own challenges. But iPhone, the iPhone market in China was like apple's, I I wanna say third, second or third largest market.
Second I believe. And it's tanking because the Chinese are very good. The government saying, Hey, SWE one, buy the local one.
Um, and, but I wanna be clear to take in your cynicism and your point, when we talk about 8 billion and 11 billion, some people say, yeah, but they're building factories. It's gonna create all these jobs. Well, no, a lot of these foundries and stuff, and fabs, they, it's all robotic.
It's not a heck of a lot of jobs. But to your point, it is a strategic initiative on the, based on this country's need of high, you know, cutting edge chips. We can't afford that.
If there's a war in the Taiwan straits that we don't have chips or an earthquake, or an earthquake is yesterday. Right. Or the day before.
Um, so, so it's important. Here's my cynicism though. I, I commend the loyalty to Intel.
They're national treasure. They've been a national treasure for as long as I've been in technology. 30 something years.
Are we, are we, are we putting too much money into a, an older horse here? And is, is there some other ones that, you know, are we, are we kind of funding innovation by doing it primarily with Intel? Or should we be spreading those dollars around to some new growth?
Yeah, well, they put about 53 billion into this with almost five times that in terms of loans and, and, and other investments in innovation. No one else has raised their hands. There's no other company that's willing to build a 'cause.
It's hard, it's really, really hard. I mean, TSMC has built a very, very robust, very important business on a global scale. But there's no other company that's saying we're willing to take on the manufacturing, the, the, the building, the plants, hiring the people, and building these leading edge chips.
And the expertise is complicated. You know, we, what we've seen over the years has been a lot of distribution of, of, of capabilities. You got these adas companies like Cadence and Synopsis with IP arm, Mm-Hmm.
That have made companies like Nvidia able to develop, build and, and offshore their chip making in a very streamlined way. They don't necessarily have the, the Foundry expertise. So someone has to take that on.
Having said that too, I kind of find these, like, I actually put a tweet out this week. I said, we're gonna need chips act too. $8 billion is nothing.
We're, we're adding a trillion dollars to the deficit every 90 days in the United States. $8 billion on investment in the most important foundational technological advancements that are gonna happen in the world over the next couple of years. Absolutely.
I'm not joking. Like in the next two decades, AI will rule the economy. The companies that are able to participate and play will be the winner.
So it's not just about Intel, it's about can Microsoft continue to succeed? Can Google continue? They need the silicon to do it.
And by the way, they need a partner to manufacture. 'cause they're not all gonna run it on Nvidia. And that's a whole nother topic for another day.
But Google's making chips, Microsoft's making chips, Amazon's making chips. And by the way, they're gonna be able to do it because of Foundry. They need capacity.
They need to not be 100% dependent on having it done in Taiwan. Just the microaggressions and geopolitical tensions between China and Taiwan is enough of a reason that the US has to get this right. 50 billion is nothing.
And I hate to say that, 'cause I'd take, I'd take 1 billion of it and I can make a good life of it, probably. Yeah. But we need to spend a heck of a lot more if we're actually gonna win this.
It's strategic. Will this play out as we hope? Or is it gonna be a situation where we're telling everybody to buy made in America, quote unquote, but then they're still gonna buy stuff that's ARM-based, made elsewhere.
So what's the back End of this thing? They, they could build arm right in these, so what we're really seeing here is the decoupling. This is an Apple player.
Remember you open your iPhone, it says designed in California. It's not built in California. They're built over there.
This is the decoupling of the chip business. Intel will still design killer chips, but they're gonna become a contract manufacturer. You wanna build an arm?
I got it for you. You wanna build a new A GPU for, for ai? We'll build it for you.
They're, they're gonna become a contract manufacturer. Lots of places to build those chips around the world. We need to build them Here.
Yeah. I think, I think the point is, there's gonna be some distribution here. We're at zero right now.
Yeah. We need on These advanced chips, we Need this. You know, Pat's been reasonable.
Of course you would love to see us get to 50 50, but I mean, look, being at 90 10 would be a, an incredible, Incredible progress process. Us 10, that's 10, that's improvement. And and we need to have some level of self dependence here.
And, and if you're not worried about that, we literally do not have a single industry that could function without silicon. Do you think that there's more awareness about this? You mentioned, because we just went through the pandemic and we saw how dependent we were on China birth.
We couldn't even get face masks. Yeah. Couldn't face masks.
Or then we were like, what about Advil, Tylenol things, everything that we depend on, um, supply chain. So how do they balance what, what Intel needs to do and the time allotted, um, while they're not making money doing, you know, presenting profits with the need to be independence. Yeah.
That, that seems like that's gonna be a tough balance in the years ahead. Yeah, that's a great question. First of all, the, the, the company is very profitable on, its the, the fabulous part now, the way they're calling it products.
Mm-Hmm. They make a lot of money on products. They've carved out all that expense from the manufacturing side now, and they're putting reasonable arms length business relationship.
So they're charging reasonable way for, you know, costs back to the products business. But they're treating it more like if Nvidia is buying from TSMC now, that's how products is buying from boundary. So you can see how that actually works.
So they make the money here, but over here, again, they're getting the grants, they're getting the loans. They have a smart capital, which is another way they've raised, and I think it's somewhere around 50 billion of total access that they've been able to get. Um, there's no, there's no option to not get this right now.
In the end, I, I will actually say I've gone on the record and I said, there is a, a better, it would be a better outcome. Now there's, it's not a good outcome. I'm gonna be very clear about this.
If Intel products fail, if the Foundry succeeds, I know it's crazy as that sounds, but in this current era with, with the adas, with the arm and the IP companies, you know, there are a lot that can now design chips. We can design CPUs. You know, you got arm, you got risk.
Absolutely. You got different ways to make phones. You got different ways to make laptops.
You got different ways to make cars. Um, you know, the silicon for cars. But we cannot get the Foundry thing wrong because like I said, we're one, you know, tactical missile away from having no access to leading edge chips.
And you know, we sometimes say that with in jest, like, oh, well if China, you know, look, China believes it has a right to Taiwan. It believes this. And no matter what we say, if at some point they decide that they want to no longer play nice, which we could argue whether they do today or not, um, it would put us in a situation we should never allow ourself to be in.
So this has to get, this has to happen. This has to be Done. Right.
No, this is too strategic. I, I, I don't disagree at all. I want to give a shout out.
I have a friend of mine down in Houston, my friend Misha Misha Stein. Misha was the founder of, uh, alert Logic. But he, he left there, he founded another company called, I think it's Macro Fab.
Five years ago. He told me this. He said, Alan, we're going to a world where we need to build our chips either in he, I think he was doing stuff in Mexico and the US and, and we're just gonna be a contract manufacturer for chips.
And I laughed at him back then. I, I didn't, you know, I said, how you gonna compete with Intel? How are you gonna compete with a MD?
Say, there's gonna be a lot of people who want chip designs and, and he was dead on. So if you are watching this Michi, good, good on you, man. Anyway, I think that's gonna wrap up.
Lock one here on Textron gang. We're gonna be back. I think we've got Mitchell Ashley waiting in the wings, and we're gonna talk about sustainability and ai.
Something near and dear to Bonnie. We're a text drunk gang. We'll be right back.
Hi everyone. Welcome back to the Techstrong gang. Well, we are talking about sustainability because in the wake of the high demand for everything, AI sustainability has to come into the conversation.
And recently Microsoft has been addressing that, especially with their ambitious goals of reducing carbon, um, emissions by 2030. If you wanna build lots of AI products and you wanted, at the same time, you have to address it. So some of the, uh, Microsoft points that were brought up were water usage.
Maybe we should be using air rather than water for cooling, perhaps turning to sustainable materials. There's a lot of different solutions that can be done as we see the momentum build for ai, um, when it comes to sustainability. So I think this is gonna be a growing part of the conversation as we, as most companies are looking to reach these goals by 2030, you know, you, it, it's sort of like wanting to have your cake and eat it too.
You have to do it in a sustainable way in order for it to, to last and, and to not tap into the resources of the earth as everyone's doing this at the same time, clearly there'll be an impact. Yeah, I think this particular blog article was almost like a position paper saying, here's what we think this is what we're gonna do and how we might do it. And there are also kind of secondary and tertiary uses of the byproducts of what, like, for example, air, like the heat coming out of a data center, uh, also using that to heat homes.
I think they said like one data center could heat 6,000 homes. So they're, they're thinking, they're sharing ideas about not just within their immediate ecosystem, but kind of broadly within their partners and then the community. Yeah, I agree with that.
And especially when it comes to even building data centers using green construction materials, for example. That's something on Ecotech insights. I've been interviewing a lot of people looking to do that from top to bottom.
Make it a sustainable effort. You know, an interesting thing, Mitchell and I have a friend, Terry Swack. Mm-Hmm.
And, uh, she's the CEO founder of a company. Is it clean Mines green. Mines sustainable.
Mines sustainable mines. Yeah. It's actually Terry's birthday.
Happy birthday, Terry. It's Happy birthday Terry. Um, But you know, I was with Terry a couple months ago.
We had a few drinks and, um, but she gave me an interesting fact. 25% or more of greenhouse gases are tied into building Mm-Hmm. Whether it's the manufacturer, the manufacturer of materials that we build with or in the act of building itself of construction, tremendous amounts.
Data centers are at, you know, kind of at the top of that list. Right? That's why they, you know, for a while we were building data centers in the Arctic.
Mm-Hmm. Because you can get cool it there, or they build a data center next to a hydroelectric dam to get access to it. AI is exasperating this, but here's the golden lining for me.
Let's use AI to figure out how to build better, more sustainable facilities for ai. I think this is a case where, you know, you, you can have your cake and eat it too. To your point, And that's where, I'm sorry, go ahead.
Go ahead. Okay. I think this is a watershed moment comes the day that Microsoft spends this amount of time and energy to create a blog that looks like a position paper.
It means that people are screaming in their ears about this and that they're hearing that this is a serious issue. And they're basically running a PR game here to say, you know, we're doing something about this while we continue to consume massive amounts of energy. So I kind of feel like, yes, it's great that we're talking about it, but I've, you know, been around this block with these guys a few dozen times and I know how they operate.
And when they start writing at this level, it means that, you know, they're trying to lobby somebody and they're trying to prevent some legislation from being crafted or something's up. So I think there's more here than what it looks like. You know, if, if, if AI is the engine, data is the fuel, that's the other half to the coin you're talking about.
Yeah. Um, which is, think about the vast amounts of data. And Terry's company is one example who, who has a lot of data about the impact of the manufacturing materials and all of that.
Think about all the data that we have now about products that we're creating and, and now that we're paying attention to it, gathering the right kind of data to be able to make the best decisions about reducing impact, about operating it more efficiently or building it more effectively, or reusing all those, all the byproducts of, of those activities. So it's ai, but AI powered by a lot of really great valuable data. And you know, one of the things with AI when it comes to fighting climate change is we're seeing a, a, a surgence of companies that are creating twofold.
One, monitoring, measuring carbon emissions within software and different companies. But the other side is what kind of, when Alan was talking about the innovation and technology to reduce emissions, build more sustainably, um, track different areas where we're, we're not monitoring emissions, like, let's say through drones. I interviewed someone from a company that does that.
So I think that, um, the Microsoft blog does point to a bigger picture of like what Mike was saying, of what we're, um, what they're, what they're looking for going forward. But underneath it all are these innovations that are happening around the world right now to track monitor carbon solutions and also create solutions just to mitigate the, the, the, if we're gonna use this much ai, we know we are. Okay, well then how are we gonna manage not tapping into water, which is limited already.
So, um, I think it's all happening at the same time. Can I ask you a question? Do you, do you think Microsoft's blog post is something that will be like to the watershed moment others will use as a, a pattern or a baseline to start doing now that's us put our, our position paper kind of validating or extending what that, is it that big of an impact?
It, I mean it depends on, on who's looking towards Microsoft a hundred percent for leadership. But across the board, if you go to different websites of different companies, it is prominently display displayed now. And something that I find that, um, people wanna push forward more in their messaging of how they're doing, um, their own ESG goals and their sustainability.
But a leader like Microsoft definitely could set off a chain reaction that validates it. Yeah. I think there's a guy somewhere or gal in Europe working for the eu, has their pencil out and is calculating right now what the carbon AI tax is gonna be for the impact that these things are having on the environment and what they're gonna come back to folks and say, Hey, this is what, this is a real cost that you're gonna have to bear.
And I think that, you know, a lot of this stuff is pre-positioning to kind of get in front of that stuff. It's, it's Possible shades of Al Gore Who reinvented the internet, right? Yes.
Um, alright. Anything else on sustainable ai? Well, it's, we'll see what the ripple effect of this is and yeah, I'll Outcomes might be right and I just think it's something, a topic to keep your eye on because it's gonna just keep coming up more and more Vote.
Absolutely. I vote for more efficient LLMs. That would be the way to go is just to reduce the amount of carbon being generated in the first Place.
Well, we're gonna talk about LLMs next, but first here's a break we're you're watching Techron Yank. Hey guys, this is JJ Manila with Mitch Ashley co-host of CISO talk where we have engaging bite-sized conversations for current and NextGen CISOs. You know, we have some of the best conversations on CISO talk with some of the greatest talent in security people like Andy Ellis who talked to us about optimizing security strategies and how to navigate the boardroom.
Lisa Bradley came on and talked about vulnerability management bug bounty programs and why SBOs aren't the solution to all your software security problems. Steve Reynolds was also another great guest and he talked to us about what not to do when a security incident happens. The what not to dos are great, but we also had Eve Mailer and Steve bitten on talking about security, uh, and third party software, SaaS applications, and weaponizing ai.
So go ahead and join us for the latest episode of CISO Talk. You can find us by going to Techstrong TV slash CISO talk. All right folks, we're back.
And as promised, we're talking about LLMs. Tab nine is basically put out an announcement saying you can bring your own LLM to their tool that lets you write code or test code that will be automatically generated by their LLM, but now they're turning around and saying, Hey, you know what, you can bring open AI or whatever LLM you feel like. And it seems like to me, we just went from, wow, this is the most amazing innovation in the world to maybe an expensive commodity that I can just call through an API and I'll swap 'em out as I see fit.
It's internet time baby, you Know. Well it's interesting. Time Crunch tab nine went through their own transition 'cause they own had their own proprietary non A LLM Gen AI based product and they transition to Gen ai.
Now they're transitioning to well, and you can add your own, because a lot of the concern is just about I don't wanna code, I don't wanna put my code into a third party LLM that I'm gonna lose the data. I lose control over that. I mean even, you know, I hear people talking about podcasts of use LM Studio to just do your own ll take, take it from hugging face and work on it in your own environment.
So it seems like that almost, um, you know, kind of the hoteling of your own LLM and tools will be a trend to be able to protect it. I'm trying to figure out if people are gonna orchestrate LMS across different tasks. So I'll have an l LM that's optimized for a specific function and then I'll use another LLM for a different thing and then I'll have these agents stitched together.
And as that become a workflow, I think it's early yet, but it feels like that's where it's going. That's Kinda what the Oracle announcement was about, right? Yeah.
They announced their, I called a broker to decide which LLM or Gen AI system will answer what part of the prompt Look, I think we're moving to a modular future. We saw this when we were at reinvent guys, right? When we were doing our interviews.
The, the way of the future is sort of what, what's the sales one called? Einstein? Yeah.
Mm-Hmm. Where it, it's a front end and it can plug into multiple LLMs, it can plug into multiple ais. You're not in a walled garden.
Choice will be the rule of the day until one of these becomes dominant or something like that. But I don't, I I think the market is already spoken fairly quickly and early that they want choice when it comes to LLMs and they want choice when it comes to which ai, they don't want to be locked into open AI or, or Googles or, or anyones for that matter. They also want specialized or don't domain specific LLMs.
They want small SMS Sls, right? Mm-Hmm. To, to be out to the efficiency point, right?
Instead of throwing, you know, open ai, gen AI at it chat GPT, let's do something that just does code for these kind of environments In that example. I agree. I think it does sound like it's a more efficient option.
Um, but is it more taxing on energy overall if you're using, if, if the LMS are getting larger themselves? That's more of a question I guess. I I, to to the other point we were talking about using ai, I think you'll be monitoring like, well I can run six of 'em, but this one, these two do the most efficient.
I can save a lot of money just by sending more as long as I'm getting the data from it. I think that'll be one of the factors of who wins. Yeah.
And there's a subtle difference between the training of the LLM requires massive amounts of data and energy, the inference engine that creates, and it's only like in terabytes and you can kind of drop that at the edge. Not so much energy being consumed on the, on the inference engine side of the equation, but we saw, um, OpenAI and Microsoft were talking about building a hundred billion dollars data center somewhere to drive some massive LLM. And you gotta wonder, do we really need a general purpose LLM to that size to do what for us?
Because it seems like the smaller LMS are more efficient. Maybe It'll be a bunch of small ones and they're just calling it one thing, you know, who knows? Mm-Hmm.
You know, I, I think that's gonna be an interesting, uh, evolution. We need to watch on that. I I, you know, as an industry we always tend to go big or go home, right?
So let's build the super duper computer LLM. But I, I think the fact of the matter is early at least, and it's still early, so who the heck knows? But the early indications are that smaller more focus give you better results than trying to boil the ocean.
Think about it. Do you want chat GPT to organize your calendar and prioritize things? Do you want an SLM that's really specialized at Mm-Hmm.
Time management calendar, Whatever. I, I, I think that, you know, but it'll be interesting how it plays out. But I, I look LMS are going to be commodities.
How quickly they're commodities. They Are hugging face is proving That, right? Yeah.
I mean, and that's, that's just the way Of this. And I think it becomes easier to swap because I may just be invoking the LLM output through an API. And if that's the case, then you know, I'll just move between cloud service providers as I need and then I'll just take the inference engine and deploy that wherever I need and everything becomes disposable.
Swappable, Maybe you put the prompt to four LLMs and three of 'em agree. That's the right answer. You knowable immutable, excellent, interesting times.
Yes, it is. We I mean you always live in interesting times. We're ending this on an Irish uh, I thought that was a Chinese proverb.
A Chinese proverb. No, I thought it was an Irish. We're already getting yelled at by the Chinese for today.
Alright. Alright, let's keep the Irish out of it. Anyway, that's gonna wrap it for Techron Gang today.
Many thanks to Daniel Newman from, uh, futur for joining us on the Intel piece. Thank you Bonnie Mitchell. Mike, we will be back on Monday, so not Friday.
We'll do our best of, we'll be back on Monday with Fresh Techron gang. Enjoy the rest of uh, techron TV today. We're out.
com is the leading resource for news analysis and education on challenges facing the cybersecurity industry. com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com. Home of Security Bloggers Network Tv.
Hey everyone, welcome back here to Tech Drunk tv. I've got, uh, a first time guest here. I always like having a first time person on.
We get to know 'em a little bit and know their company. They've got some exciting news and we're gonna talk about it. Let me introduce you to Sal Sza.
Sal is the CEO and Co-founder of Ninja One and he's here with us today. Hey Sal, nice to meet you man. I thank you for being on Tech Drunk TV with us.
Nice to meet you as well, Alan. Thanks for having me on. I really appreciate it.
Absolutely. So, um, look, I wanna make sure our audience finds out all about Ninja One, but before we even get to that, let's tell them all about you, Sal. If you, if you're not embarrassed and then we didn't, you know, give us your story.
I'll do my best. Yeah, I'm, uh, born and raised in New York. Um, started out my journey working in Manhattan many, many years ago.
Wound up living all over the country and I've been doing star for 25 years. So ninja's my sixth or seventh startup, depending on how you think about it. Sounds real familiar.
I also grew up in New York and did startups all over the country for about 25, 30 years. And, uh, I also also have probably done five or six. So yeah's crazy times.
It's, it's an interesting, it makes for an interesting life though, doesn't it? Yes, it's, uh, it's high stress for a lot of fun. I actually was a software engineer 17 of those years, so they didn't really let me be good.
You behind the keyboard that much. But, uh, now here I am talking to you, Alan. Fantastic.
And are you based in New York now or where are you based? No, I'm based in Austin, Texas. I I lived in New York, DC, Connecticut, Phoenix, uh, Austin, Texas, the Bay Area now back to Austin.
So That's a great place. I was with some friends in Austin out in Paris at CubeCon a couple weeks ago and talking about, I mean, it's just rocking the town. Um, so that's interesting.
So give us kind of the ninja, you know, you're one of the co-founders. Give us the ninja one story. You know, ninja was the fourth startup that I built selling to managed ser service providers and, and IT departments.
Mm-Hmm. And, uh, over the years I learned that customer pain really well, how they wanna grow their business, how they manage their customers, and also familiar, very familiar with internal IT departments having worked across software and Dell and SonicWall and prior lives. And I felt that there was an opportunity to build a platform that was cloud first.
And that, and that vision sort of came to fruition in 2013, 2014. We started building products. And the way I kind of looked at it as during that time period, there was a consumerization of IT products, meaning IT products got, the user experiences got a lot better.
And I felt in the IT market there was still an opportunity to be a disruptor, to build something that was super easy to use, powerful, scalable with, you know, with high security. And that's the vision by which we started the company. And it's been, it's been an amazing growth journey over the last eight years that we've been, we've been selling, when we shipped product we had 60 beta customers at the end of 2015.
And today we have over 17,000 customers in 80 countries. That's fantastic, man. What a great story.
Good stuff. So, so are MSP still at the heart of your like target with Ninja One or you've kind of gone beyond that? Uh, we'll never go beyond MSPs.
We actually services both. So we have thousands and thousands of internal IT departments and we also have thousands and thousands of managed service providers. We find that their needs of both of those buying personas can be solved in, in, in similar ways.
They both want exceptional product, ease of use and phenomenal support, which is sort of the backbone of the whole company, how we think about things. And I'm, I'm actually not a sales centric c like I said, I was a software engineer for 17 years and I actually still run product development today. Do you?
Alright, that's cool. So interesting. You know, one of one of the companies I started was a security company and we were selling, you know, direct and I, after about five or six years, I, I came to the realization security was just too hard for most organizations.
And that MSSP managed security service provider was a great model for most organizations to get the most. I mean, they had limited dollars for security and they had to have a minimum amount of decent security, right? And, and so we really started targeting that market and then eventually we actually bought an MSSP and started delivering security via that kind of channel, that method.
I, I just think it worked a lot better for, for many organizations. Um, I guess in your case you kind of came to that realization as a result of previous companies you had done about, you know, the, the efficacy of the, uh, MSP model. Yeah, yeah.
I mean, 'cause 'cause I, I had, I had originally had a DNA in the MSP market, so I knew the market incredibly well. But what we found is internal IT departments both big and small. We have some internal IT customers with over 70,000 endpoints Wow.
That are using today. And we also have managed service providers over a hundred thousand endpoints using Ninja from a single customer. I want to dive into what Ninja does exactly and how and everything.
But before we do, I got two quick things for you, Sal, please, number one for people right now who say, okay, I've heard enough, I want to go see from read about them myself. What's the website? com Easy.
com. And then secondly, the big news though is you guys just recently also closed a lodge, uh, series C Round. I wanna tell us about that.
Yeah, I mean we, um, we have an existing institutional investors Summit partners who's been amazing for us. They actually introduced us to our two board members, you know, GERD, wa, Wasinger and n who are both, uh, operational board members. One has tremendous c c-Suite experience and one, um, tremendous go to market experience.
And, um, we were looking to raise cash to scale out our, continue to scale out our product engineering effort and, and maintain the exceptional support that we have. And we're looking for a partner that, um, that could add new value to Ninja. So Icon's been a tremendous partner so far, um, in terms of introduction, advisory and just, you know, and, and in the ninja way they're, uh, pragmatic and, and a great culture fit for how we do business and, and how we treat our employees.
So they're a perfect partner for us and we're using the cash that we raised to basically just accelerate product development, maintain support, and we're also looking for opportunities to build new products and we'll, we'll talk about that, but n Ninja's on a journey for tool consolidation and sort of minimize the tool sprawl that's happening in IT departments today. So Let, so first of all, summit Partners was the existing investor. Iconic is is kind of the lead, the new lead.
Oh yeah. It's a new institutional round, basically. Yeah.
Right. The lead for the, and this was a, and this was a 231 and a half million dollars series C, which in today's market, you know, back during Covid we were throwing numbers around like that left and right. But in today's market that's an extraordinary amount of money.
We, we've been really lucky. Um, our, our growth has been exceptional at small numbers and through pre covid and post Covid. So I think, I think investors generally are excited about two things.
That's been an amazing growth journey and we've shown re resilience, you know, both in economic downturns and also, you know, during the pandemic. You know, and our investors point out that, you know, ultimately someday, you know, if Ninja goes IPO years from now, people will look back to that time and and show that, you know, ninja's growth was strong, you know, throughout the entire journey, you know, of our company history. Fantastic.
Great stuff. And you mentioned this money's gonna be used kind of across the board from product to scaling, I imagine scaling, marketing, sales and everything else as well. Well, yeah, I had a, I had to wait to have an interview with you, Alan, 'cause I didn't have a comms department five, five months ago.
com and that's me directly. Yeah, understand. But, um, I'm sorry you had to wait man.
You well, but it hopefully it was worth the wait for you and, and this turns out well. Um, Sal what do you, I mean, tremendous success and congratulations to you and the whole team. What do you think the secret sauce is?
You know, I think there's, I think there's a few things you could point to towards the ninja secret sauce. And we actually talked about this sort of talking more about how Ninja does things. Number one is our culture.
We're incredibly organizationally flat. We truly believe like servant style leadership, it's not about egos, it's about getting the right answer. And I think my employees operate with fear.
I mean, we'll have any person, any level of organization will raise their hand and, and say what's wrong with the product or give us unpleasant feedback that we don't want to hear, which ultimately allows us to make the product better over time. I always laugh that my employees yell at me more than I would yell at, yell at anybody in my life. But the more they yell, I know the more that they care.
So I think that's one superpower. I think, um, transformational support experiences, you know, our CSAT scores are approaching 99%. Like if you pick up the phone and call, we pick up and that's, you know, I'm going to sort of date myself here.
Going back to the days of Rackspace with fanatical support. Like I was, I was their customer and, and would pay for products me too, just to have their support. So, you know, that's what I kind of think about, you know, kind of a outta respect to, to companies in the past, like they did it, right?
So we measure everything. Like if you fi fill a format, want to talk to us, whether it's support sales or you're having a problem that we could be assistance of, we always pick up the phone. So I think transformational support experience is another superpower.
Um, humbly, I think having a product centric CO is a superpower because, you know, often the marketing team will say, Hey, when is this product launching? And the answer is when it's ready. You know, we built a wonderful reputation of building products that scale well and are easy to use and, and just generally work well.
And as we build new products, we've had the discipline to weight, um, and make sure that they're rock solid before we ship them. So we're, we don't want to chase, we don't wanna chase dollars and hurt our reputation. So I think that's another sort of superpower.
And, um, there's a lot of interesting things happening in the market right now. The endpoints, there's endpoint sprawl all over the place, much more so than even five or six years ago. You know, in a remote hybrid workforce, you have employees working home employees in the office, they have mobile phones, there's IOT devices, there's just devices, everyone.
And with that, you know, um, presents tremendous risk. So I think for Ninja, the tool consolidation where Ninja might replace like 1, 2, 3, 4 tools to simplify the IT or the managed service provider's job, I think is a superpower. And it's working.
And, and we've been also really disciplined about, uh, until this, you know, time not purchasing any other companies, everything is built by Ninja from the ground up single stack. So you don't have sort of the SSO glue gun out, you know, integrate 10 different products, right? And then you kind of a consolidate front end.
It's all in the product, right? So if you have a problem, you could fi you could diagnose the problem and solve the problem all in one consult, which is, which is really power powerful. I mean, I know years ago everyone said single pane of glass, but we actually think we're getting there.
So you mentioned this though, and let me, because as I said in the outset, I've had similar experiences in doing startups and stuff. Um, you know, and I'm sure your VCs, your investors will tell you this, organic growth is great, but sometimes you really want to, you know, put a little fuel in the rocket. And growth via acquisition can really help because it could be strategic.
It's not just growth in terms of revenue, but it's, it's growth in terms of maybe new markets, new products, new people, right? New talent. Um, with this kind of funding round, you, you have now, you know, even if you're not paying cash, you know, but you could start using your, your, your equity is a currency because assuming you raised the round based upon that kind of valuation, um, is that something that may change now at Ninja One?
You think that, you know, you might have some more inorganic strategic kind of growth like that? Yeah, I mean, I think, I think the way our product strategy has been, the products that we're taking to market this year were already being built two or three years ago. And there's another tra of products that's mid-flight, that's a yearend development that's gonna pop in the next couple years.
So we have a healthy pipeline of cross-sell products and products that could help our customers, you know, extract more value outta the platform. However, we would be foolish not to keep our eyes open and look for, um, exceptional engineering orgs and products that add value to Ninja. So it's not a, it's not a priority, but we are always on the market looking for folks that have the ninja DNA people that believe in the vision and ninja, right?
So they'd be willing to take a lot of stock in our vision, a tremendous engineering team, um, and, and, and a and an excitement about working on something larger. So, you know, I've been on the receiving and sold lots companies myself, and I wanna make sure that if we did that we keep the breasts and brightest minds of that, those engineering orgs for years to come. So the, if we found that sort of persona, then yeah, we, we would be open to acquisitions.
Got it. Um, I guess I gotta ask this 'cause you gotta ask it today. What about ai?
How's ai gen ai, is that already starting to influence your product decisions or plans and stuff like that? Yeah, I mean, um, AI is a huge discussion internally. You know, we are, um, we're being super thoughtful about how we build ai.
We're spinning up a large team and we think on the long it's going to be, you know, it's gonna be part of our core platform in a large way. Right now, the tools are young, they're getting better every day. I like to say ninja's not a, a super early adopter of technology.
We're a mid, you know, if you, uh, if you think about it, like the tools are gonna get so much better than 18 months and the people that are absolute earliest, there's gonna be a graveyard of AI startups that fail or there's something destructive happens. So we wanna be careful. So right now our sort of approach to ai, and we have some stuff coming out this year is advisory only, you know, advisory with human eyes.
So, you know, sentiment analysis of, you know, we have lots of great data that we can help our customers draw conclusions and make educated decisions about scripts that they might upload or patches that might be a risk. But, uh, full autonomous control of AI of, uh, of an endpoint, uh, a cloud-based endpoint management product that has control of millions of machines. We think that's, uh, we think that's a long way out.
So we, you know, we're excited about ai, we think it's an integral part of our future, but we don't want to jump too early and, and we're often serving and, and, and checking in with our customers. And I think there's a lot of consensus around that that leverage AI on early where you could be helpful side caddy to a human, but punt on full autonomous, uh, down the line as, as the technology can continues to develop. And that's kind of our perspective.
Yeah, I I think that's probably mainstream. I, I think just the real contention becomes is where is that horizon? Is it 18 months, 24 months, 48 months or what have you?
And with the pace of, of, of, of the evolution of this here, who the heck knows, quite frankly, right? I mean, we'll have to wait and see where that comes out. Um, what about, you know, 17,000 customers?
Is that worldwide? Is it more US North America? What, what's the kind of distribution there?
We have, what's your focus? Have 17,000 worldwide. Actually emea, we have a phenomenal organization, amea, so about 30% of our customers are actually in amea.
We have based operations out of Berlin. Mm-Hmm. Do have, we sell, you know, like we do sell globally.
We sell in apac, we sell in Canada, south America, Africa, pretty much every major continent, uh, with a heavy concentration in North America. Um, and our customers are getting bigger every day, like we talked about earlier. So, you know, we started off more in the upper part of the SMB, we're sort of, you know, small to midsize managed service providers, but now we're starting to close, move up into the upper mid market, uh, with lots of product unlocks to sort of support that value to those customers.
So we really sell, we truly sell downstream to the SMB and now into the upper mid market. So it's a broad range. Got it.
Got it. So you look at your entire product suite, what do you think is the, the locomotive, if you will, what do you think is the kind of, must have killers that are, are really kind of driving a lot of growth here? Yeah, I mean, our core product from a day one, you could say endpoint management or RMM, remote monitoring and management, where we have software on all all device devices from Raspberry PIs, Linux, windows, Mac, and mobile phones, uh, doing true endpoint management.
Traditional endpoint management is our sort of bread and butter, but we also do patch management and compliance software deployment monitoring, alerting, scripting, automation, remote support and backup. So, and, and we actually have many more products in the pipeline. So I think the thing is, once you have a strong platform that's easy to use and re remove all the friction for customers to consume additional products to help try value and make their job easier, it's a winning recipe.
Absolutely. It, it's interesting, you know, I, uh, we got RSA coming up right in, uh, may and you look at trends and what people are talking about and, and there was a time where everybody just wanted to talk about cloud, cloud, cloud, you know, this and that. We now we're, there's a little bit of a pendulum swing, if you will, right?
Where people are talking about returning to data centers, endpoint stuff, and you know, and, and the work, do anything from anywhere kind of environment that many organizations exist in today. You know, it's more important than ever that you, you, you have some endpoint insight into your endpoints managing of them, not only for security, but I mean, but yes, for security too. Um, I would imagine that during Covid though, this really had to be a big, I mean, this was, it was, I mean, it had to help the, and I don't mean this in a bad way.
Covid doesn't help anyone, right? No one wants to get sick, goodnight. But during Covid, I would imagine this had to be a, a, a huge kind of growth area for you guys, right?
As as people want to become more dispersed like that. Decentralized. Yeah.
You know, I think when Covid started, we were much smaller. So we were 160 employees, now we're like 1200. So if you, if you imagine Rev and that sort of thing.
So at that time we were growing in triple digits prior to Covid. So we're growing incredibly well. And I, I do think Covid opened up more interesting use cases with hybrid work environments.
You know, ninja very early on was a hybrid work environment. We had lots of people working at home distributed workforces. We have, we have a big office in Clear Border near Tampa and San Francisco.
So you have salespeople collaborating cross coast and, and even now, like a lot of our employees do work at home, and we have hundreds of people in the office. So I think, I think Covid and just, hi. I think instead of Covid, I would just say hybrid workforce is here to stay.
It's never gonna change because everyone realize it works. Everyone, you know, the commercial real estate is weighed down, people, you know, from an OPEX standpoint and enterprises can save cash. Um, so I think it's, you know, I think it's, it's sort of, um, made the pain point higher what we were already solving.
So I do think, I do think, yeah, I mean, definitely was, it definitely helped a little bit. But I would say unlike, if you think about remote, dedicated remote screen share products where, which were trading at a significant premium like Zoom and others in the market, if you look at the post Covid stats, right, everything kind of settled After. Yeah, no, they've more than settled.
They'd come back down to Earth, right? I mean Oh, right, right, right. So That was a little crazy.
Yeah, I was gonna say, in terms of Ninja, we've been able to maintain that growth several years after everyone's kind of getting back to work and, and things are return to normal, which I think is a nod to beyond hybrid work. It just, managing endpoints is hard. A lot of people don't even know the endpoints they have in their estate.
And now with the distributed workforce that's highlighting those deficiencies, which is ultimately helping us grow even faster. Very cool. Hey, Sal, we're about outta time.
First of all, again, congratulations not just on this money raise, but certainly congratulations on that. But congratulations on building a company like Ninja, right? It's eight years you mentioned.
And, you know, having been in those, in that chair, I know what it takes eight years, day in and day out to breathe life into, uh, an organization and everything. We're we're just 10 years here in, in Techron. March was 10 years.
So, um, I know, I know where you're coming from, man. Congratulations. Keep up the great work whether you have comms or not.
Always reach out to us if you want to come talk. Okay? Thanks, Alan.
I appreciate it. I'll see you down there next time down in Florida. For sure.
For sure. I'm, I'm gonna hold you to that all. All right, sir.
Go check them out. com. Uh, we're gonna take a break here on Text Trunk tv.
We'll be right back. This is Textron tv. Hey, everyone, I hope you've been enjoying our coverage here.
Live at Techstrong, uh, at Techstrong, uh, cube Co. We are tech strong, but it's, it's, it's a little crazy. I mean, Scott, I don't You've been to other Cube con's yet?
I have. I have. And this one is off the charts.
You're Right. Absolutely. Way.
I was with, uh, o Neil Gupta, who's the chairman of CNCF. Sure, sure. And he told me last night, this is the biggest cube con bigger than San Diego.
Yeah. If you remember San Diego before Covid. Yeah, COVID before Covid, yeah, yeah.
Was the biggest one. This is now Eclipse that, so pretty cool stuff. Uh, you heard me say Scott, let me introduce you to Scott Johnston.
Scott is the CEO of Docker and has been now for, how long has it been? Eight years. Just over four years.
Four years. Been at Docker 10 years. So I think I remember when you joined Docker, believe it or not, February, 2014.
Docker is 11 years old tomorrow. Really? So Solomon walked on the stage at Picon Picon 20 13, 11 years ago tomorrow.
Okay. And brought Docker to the world. So here we go.
Very cool. Very cool. I mean, this didn't exist.
This didn't exist 10 years ago, right? No, it didn't. No, this certainly didn't.
com, I started in March of 2014. Okay. So it was all ascending The time.
It's 10 years. Yeah. Wow.
Crazy, crazy. Hard to believe. But there's been a lot of changes since then, right?
Yes, yes. You know, back then Docker was all about the container. Mm-Hmm mm-Hmm.
Of course. A lot of water under that container. Um, as they say, A lot of water under the container.
That's good. Yep. That's good.
And, um, Docker has grown, morphed, stretch, pulled, changed, come out the other side. Yeah. With a, a very different business.
A lineup That's Right. Than than containers. That's right.
Let's start there, if you don't mind, Scott. Tell share with the audience. So, so our journey up to 2019 was really focused on the production use case.
Yep. Helping operators run containers at scale in the data center in the cloud across multiple nodes. And so of course, that involved orchestration.
And back in the day we had an orchestrator, Kubernetes then came on the scene, we eventually embraced Kubernetes, so on so forth. In 2019, we realized that there was another opportunity for the company, and that was the developer market. Yes.
And so we did a massive pivot in 2019. Basically shed the operator business, shed the orchestration business to focus just on the needs of developer and specifically, how can we help developers rapidly as a team develop more secure higher quality software. And that's the journey we've been on the last four years.
And you know what, it it, as you said, it was a pretty radical pivot. Big shift. But in hindsight, genius.
Right. I'd rather be lucky than smart, as they say. Right.
It's good to be both. It's Rather be lucky than smart, but That's the story of My life. But, but developer experiences now A key piece of it.
Ab Absolutely. Absolutely. So the, you know, we're going to get into some of this now though, but I wanted to, now you guys made some announcements recently.
We did, We Did. Uh, well, let's go there if you don't mind. Sure, sure.
So in this focus on developer experience, it's specifically on what we call the inner loop. And that is what the developer's doing locally when they edit the code, build the code, test the code, verify the code, debug the code, and they go around and around that loop before they do the get commit. Right?
So it's all, which is then the outer loop. Okay. Right.
So how do you help 'em go fast in that inner loop? And one of the realizations we came to is seeing the data coming back, is that there's some points of that inner loop that are not efficient, that are not optimized where the developer is waiting. So, for example, the developer can wait in aggregate sometimes up to an hour a day for their builds to complete locally.
They, they type docker build and they go get a cup of coffee or they go to lunch. And we came to the realization of like, well, wait a minute, we can bring the power of cloud to that local build experience so they have the same developer experience, but offload the build to the public cloud. We're seeing 39 times speedups.
Which to put that in context, that an hour becomes a minute and a half. That's free time. Absolutely.
That's Time back in the developer's day to Do other things. You know, I've seen, you've probably seen them too, a lot of these surveys that say developers only spend about 30% of their time developing Actually writing code. Writing code.
Right. 'cause a lot of it is waiting for Stuff, Waiting for stuff to render. Right.
Right. That's right. And, um, so give 'em more time back in their day to stay in the flow state, be creative, write code, Because what do developers like to do?
Write code. They like to write code. They're creative, they wanna build.
Right. I agree with you, man. That's where it's at.
Um, so working on that inner loop, what else do we got going on? That's a, So similar to the inner loop, uh, sorry. Similar to build, another big activity in the inner loop is test.
Right? Okay. So now I'm gonna, I built my container, now I want to test it locally, but if that container, or if that, uh, application has like 20 different services that can weigh down the laptop, or if they're developing on an M1 arm, but their production is X 86, now they have an architecture difference.
Yep. Right. So we bought a company in December called test containers, which allows you to have the same test experience locally as you have in the cloud cloud on these same principles of like, burst out to the cloud to do what the cloud does best.
And so we announced this week a partnership with Red Hat Beautiful. Where developer can develop locally, but if they wanna burst out to their Red Hat OpenShift cluster to run the test there, seamless one command deploy. Done.
So lucky and smart, I'll say, I'll take, I'll take lucky, I'll take lucky. Why did someone think of this earlier? I mean, OpenShift and our big customers and big banks, it is what platform engineers use to deploy to.
Yeah. They wanna bring, uh, works on my, they wanna avoid works on my machines. They wanna make, they wanna make the, the test environment as close as possible to the production environment.
And we're like, fantastic. Let's burst from the local test environment to the OpenShift environment. I mean, call it good.
So I'm, I'm not as technical as you probably, right. But look, one of the first big uses, not a tech strong, when I was at my last company, when the cloud first came on the scene was what a difference. Game changer for testing.
Yes. Testing was a expensive time consuming Yep. Pain in the butt.
A hundred percent. Now all of a sudden I had infinite, not infinite, but near infinite scale for my unit test. That's right.
And my, all my, you know, load testing and all of that, we already, so testers already knew that the cloud was your path to buying, uh, you know, a hundred thousand different flavors of laptop and everything. Right. Right.
Why, why did it take so long? You think to do this with containers? You know, I think, I think at the time, back in the day, right, you had a dedicated test team, right?
Remember this and it was, it was very much waterfall. So like, write the code, someone else built it, someone else tested it, and like waterfall down the way. And in those days, okay, you deploy once a month, you deploy once a Once a quarter, a once a year.
Yeah. Yeah, exactly. But now we're in this world where like value shift is the premium.
Yeah. So how quickly can you ship value to production? Yep.
And so that combined with automation, combined with, again, humbly the ease with which the containers become that unit of work Yep. Is pulling more and more that into the developer environment. So how do you make it easy and automated for the developer to do testing as quickly as possible then versus throw it over the wall to someone downstream.
So I think that's the dynamic now. And is that like, hey, the faster we can solve issues, the better that quality, better quality software that's gonna be developer can take action and then move on. I mean, I like not only That you have a, you have a better test coverage.
Yes, Yes. Exactly. The, I, I like it to a manufacturing example, which the, the Japanese manufacturers brought, which is they have this notion of the Andon court on the line, right?
So if a worker sees a problem, they pull that Andon court because they know fixing on the line costs a dollar. You fix an inventory costs of $10 Recall costs you a thousand fix Recall, it costs you a million bucks, right? Yeah.
And so, very much what we can do from manufacturing, we can bring to software. Absolutely. Like help the developer solve it Right Then.
Not in ci, not in production, not Oh my God. When the customer sees it. Yep.
Right? And so that's what we're doing. We're helping developers.
It's A shift left. Solve problems of solving the problem. That's what it's, is what You're doing solve problems as soon as Possible.
Good stuff. Both of these are available now or now or just announced Variable now. Variable now.
Very cool. So the one other thing we're doing this week, and you're gonna hear a common theme here, which is again, the hybrid, local and cloud. So of, of course, the meme of the moment, genai, right?
So Genai, uh, works fantastic on laptops that have A GPU, but those, those laptops have a fixed capacity of GPUs, fixed speed of GPUs. So what we're also highlighting this week is the ability to burst that LOM out to a cloud to cloud and run it on a cloud node with a big beefy GPUA real Nvidia deal Or, or, or tens of Nvidia GPUs in the cloud, right? So again, how do you speed up that iteration, take advantage of the cloud for what cloud is good for?
Right? I mean, look under, it's that same mindset as as moving your testing off, right? That's right.
Or your build Up. And this is a great use for the cloud, right? Because it is so many people, I wanna host my app in the cloud.
I wanna, I need good identity, you know, security in the cloud. But the cloud works best for I think little jobs like this Very specific Yeah. Surgical boom Boom.
In out burst of bolt. That's right. You know, I need what I need and I'm done.
I'll use it again next time. Versus these sprawling infrastructures that, that we spin up. I Mean, production has found ways where spiky workloads work well in the cloud.
Retail, retail, you know, Christmas season or Black Friday, like, okay, great. But we also realize that like there's so much power there that developer is not able to harness. 'cause it can be difficult to set up and provision and secure.
So we, our brand is simplifying, right? Right. So if we could simplify all that, actually we take it completely off the developer's plate.
Developers just use the same commands behind the scenes first after the Cloud. And that, that's, look, like I said, sometimes I sit around and say, why didn't I think because Well, There you go. There you go.
Exactly. Hey, I wanna bring up another topic. Yeah.
com, we're cloud native now, and all these other That's right. Well, they can't see it online, but that's over here is our real background with all of our sites. At the heart of a lot of this is that whole CICD pipeline process.
Mm-Hmm. And it's, you know, we're doing this big research project right now called DevOps Next, right? Where we're, we're looking at, we, we don't, we're moving away from cobbling together point solutions, right?
And it's, it's a natural evolution, right? Sure. To more of a platform, more of a, you know, it, it, it organic if you will play.
We're not just cobbling, right? And the heart of that is at that CICD process. We've come a long way, but there's a long way yet to go.
That's right. That can be done. That's Right.
A lot of these little things point kind of things that you're talking about fit into a larger picture of how do we speed up CICD. That's right. That's right.
And, And so what's the docker view there? And, and look, CICD plays a really critical role for, uh, particularly that dev and ops of like, what are the, what are the final checks that this app has to go through, particularly for regulated industries? Oh yeah.
Mission critical workloads. And there's a set of tests and certifications and checks that absolutely have to be done before that workload goes into production. But we hear from customers that sometimes it can take them 5, 6, 7 times looping through CI before they actually go to C Get, Get.
Yeah. C, c well Get, well, he gets bounced Before it gets to, into production. Right.
And that, that means latency, that means time, that means the dev, the dev is waiting for stuff to come back, back That 30% number. Right? It's, that's exactly right.
'cause they're waiting for something else to finish before they can like, take action. And so we see that and we see what we've been bringing to market of like, okay, if we can actually help the dev solve it earlier, maybe instead of five, six, or seven times through ci, maybe they go once or twice through ci. And so everyone benefits faster delivery of value.
The dev is solving problems right then and there, not 30 minutes later, not 60 minutes later when it comes back from ci. And the CI team is known for a high velocity enabler. So everything, everyone kind of wins and bringing absolutely these best of both worlds.
Best of inner loop to the best of outer loop, as we call it. Docker's not done with this stuff. We're not done 11 years going, we're just getting going.
Right? We're just entering our second decade. All of us, all of us here.
Right. Second decade, you're A hundred percent cur, you're dead on on that. Right.
And I, again, I think about Wow. Wow. Just, wow.
Do you envision a time where instead of helping these companies with CICD kind of accelerators or catalysts people go to DACA for CICD? It's an interesting question, and it it gets into company evolution question as well, right? Um, I mean, we have found a lot of success the last four years, as you referenced, staying focused on the needs of developers.
And I think what that could mean with automation and where a lot of the technology is going is, does, does it still look like traditional dev CICD production five years from now, six years from now? I know. Think so.
It could, it could radically change. And and it's not only the result of automation, of new technologies, but it's also now we're injecting, um, gen AI and data into the equation as well, which now has to be part that area. Not just gen ai, but I'll say ML lops All up.
You're right. Yeah. All up.
And, and that's fascinating too, right? 'cause now you're shipping not just code, you're shipping models and the data with that model, and you're having to go through iterations that today we go through with code, that you're gonna be iterating with models, iterating with data That they're gonna Right. They're gonna iterate themselves almost.
So, yeah. I mean, you have to automate it, otherwise everything's gonna slow down again. Right?
And, and now you have this new persona, the data scientist who is upstream helping tune the model, but then it's the devs that is taking that and incorporating it. So, so we're gonna evolve. We're gonna evolve.
Sorry. We as an industry are gonna evolve. Yes.
And Dockers gonna be there. Docker's gonna be there. It's gonna evolve right along with it.
Docker's gonna be there to serve that development team and help them take advantage of all these great technologies and the data and the, and the models to make great apps. I love it, Scott. All of the things we're taught, well, what we just spoke about's not available today, but everything else we spoke about is Yep.
com. com. That's Right.
All right. Hey man, thank you so much. Always Good to talk, Alan.
All right. Scott Johnston, CEO at Docker. Lots of stuff going on there.
This ain't containers anymore. Check it out. We're live in Paris.
We'll be back in a moment. I think we have tenable up next. Stay tuned.
Hello and welcome to the digital CXO podcast. I'm excited to be here again this week with you all and with Mike Vard. How are you doing today?
I'm doing great, but um, I'm more interested in how you're doing. You've been traveling, you're out in Las Vegas last week for the, uh, Adobe conference. And it seems like that was a lot of AI chatter, but AI equals digital transformation in a lot of regards.
So what was your sense of what was going on out there? Oh, yeah, absolutely. AI seems to be one of the biggest tools that everyone's focusing on in the digital transformation efforts.
So yes, there was a lot around, um, bringing in some generative AI into the Adobe tools. And so I, you know, I wrote some notes down 'cause there was so much information from that event, but the biggest one is they wanna, um, hit every aspect of the content supply chain. Um, that being from creation and production, workflow and planning data, real-time, data reporting, um, all of it reporting and insights.
So with that, they, um, they had some generative a announcements within their firefly. They had some generative a announcements, um, within their, um, Adobe Experience Cloud. And that brings up another one, which was a big partnership with Microsoft.
Um, as far as the Adobe Experience Cloud goes, um, it's gonna share their workflows and data to the Microsoft copilot. And they wanted to continue and expand on all these partnerships with them and IBM and Google and, um, continue to innovate, uh, in these areas, uh, to provide wonderful services to all of their clients and consumers. Um, but what fascinated me was some of the use case examples.
So they brought in, um, Pfizer and, um, they talked about how the Super Bowl ad took them only three weeks to create an entire Super Bowl ad and brought them outstanding results. Millions of people came to their beat cancer, um, campaign site within that week of, of that Super Bowl ad playing. And to me that was mind blowing because thinking about what used to be, um, you know, the process to create a Super Bowl ad months and to dwindle that down to three weeks was really impressive.
Um, they also showed how it could create entire ad um, uh, marketing campaigns for all media platforms within minutes. Uh, so mind-boggling the use cases around the generative ai, which we've, uh, been speaking about for quite some time. But seeing those in play was really cool.
Um, and, uh, so that's, that's just a small part of it. Um, I had a, uh, interestingly enough, the, uh, I did speak with Fred Faulkner, who was, uh, strategic marketing for Bounties and, you know, some of the other vendors I like to go around talking to all the vendors too, and, um, the partners. And he was surprised they didn't talk about commerce, and it's like the only area they didn't hit on was the commerce area.
Maybe that's strategic as well, but, um, it's kind of the one area where they, they didn't touch on at this summit. Mm-Hmm. Something seems to be afoot here, where we've moved from being amazed by the fact that an LLM can, uh, generate content to now trying to figure out how to orchestrate tasks using these LLMs.
And that requires a fair amount of automation, but it, the reasoning engine in the LLM is getting smarter, and as it gets smarter, it's able to take on more of these tasks and process them in, in the right order that we want something to happen. So when we can say, please create a marketing campaign for me, that I can then tweak or create the entire website for that matter. It's still early days, but, um, is it your sense that it might soon become less expensive and frankly simpler just to launch a digital transformation initiative?
Well, I, I mean, just from seeing the use case examples at this summit and, and from talking to some of the, the company leaders a across the summit, I would say Yes, absolutely. I mean, the more, the more this is integrated, um, you know, and the faster everything gets and the less people are needed. Yes.
All right. So what was your sense of what are we gonna be doing with all those people that quote unquote may not be as needed? Or can we uplevel our game entirely?
You know, at this point, uh, you know, a lot of business leaders are saying, look, there are, um, that are not gonna be needed. Or not that they're not needed, it's just there's gonna be less people needed for the exact jobs, uh, since they'll have the tools assisting them. But there's also gonna be a lot of new job creation that's gonna be required.
Um, and so some will shift, but the general consensus is everybody needs to be able to, um, upskill and adapt into potentially different positions and be willing and able to do that, uh, or, um, be at a point, you know, if, if they don't, where they're ready to step out. Yeah. Well also there's a lot of smaller companies that never had these kinds of capabilities and they might be able to compete more effectively.
I think there's a running joke somewhere in, uh, venture capital land about when will the first single employee billion dollar valuation company emerge because of ai? Because it was, you know, you can do everything yourself kind of thing. And so maybe we'll all just kinda evolve into many conglomerates and a small number of us will be able to do an amazing thing.
Yeah, I mean, it'll be interesting to see how the future unfolds. It's, it's certainly an exciting and fast moving time at the moment. Um, elsewhere, I saw that, um, LAN Musk has, has things to say about AI as they pertain to digital transformation.
And I guess one of the things I took away from this grok comment was that, well, he's arguing we need a more human centered approach to ai and therefore this, um, chat agent that he's advocating as a platform, um, is that approach. I don't, can't tell if that's just, you know, him thumbing his nose at open AI or not, but what is your sense of how, uh, human are all these bots that we're about to create? Well, um, you know, the chat bots still have some work, um, that's needed, but they are getting more and more personal.
I mean, that's the goal of, of most businesses trying to incorporate these chat bots is to really personalize them and help get that one-on-one help, um, that that's beneficial and can reduce some of the hours that humans have to put toward that. But I mean, there's still a lot of glitches and, and things that they simply can't answer, and then it has to go to a human for help. But that is the goal.
So ultimately, um, are we all gonna get our own little digital buddies and kind of have somebody to help us with our tasks, and then our, my digital buddy will talk to your digital buddy to get something done or, and, you know, once they come to some point where they can't resolve it, they'll call us. And hopefully we're both on a beach somewhere when that call comes in. I, I see that being the way of the future.
I really do. Uh, I think it'd be cool. I'd love to have my own little personal chat, chat bot assistant helping me with everything I could find, you know, the value to that.
So it's not there, so it's not there yet, though. All right. We got a ways to go, um, elsewhere on the site, I was reading this article about the role ERP plays in our digital transformation initiatives.
And it kind of pointed a long standing issue, is that a lot of organizations become overly dependent upon these ERP platforms, whether they're from SAP or Oracle to run huge swaths of their processes. And that in itself is not a bad thing because, well, we didn't have another approach before and we needed to automate theoretically at least a set of best practices. But these things are fairly rigid, and I guess we're starting to see SAP and Oracle and j some gen AI capabilities into these platforms, and maybe they'll become less rigid.
But do you think we're kinda on the cusp of some sort of decomposing of these big monolithic ERP applications into more smaller discreet processes that are easier to manage maybe and kind of stitched together and combine as needed? I mean, will the ERP as we once knew it kind of devolve into something else? Yeah, so that was the topic of this article, and it was saying that as more business leaders are looking to digitally transform and be more innovative, that they're finding, they don't wanna be tied down into one vendor controlling everything, um, across the entire process.
So there might be certain softwares that they would like to use to solve certain problems, um, and their budgets, you know, maybe can't afford these vendors that they're working with. And they would like to kind of, uh, put together a puzzle of various, um, softwares or companies they're working with, uh, for the whole picture instead of just one controlling everything. This has been going on for as long as I can remember, and a lot of organizations feel their entire IT strategy is wrapped around these platforms and they can't even consider any new technologies or new innovations until they manifest themselves in these platforms.
And, and the problem has been the providers of these platforms don't really innovate all that quickly. They're getting better at it. I'll give 'em points for that in terms of they move things to the cloud, but part of their approach has been, well, we're gonna move things to the cloud, but um, we're gonna make things, yeah, all the software rewrite you can touch, and then here's a separate application server for you to go write your own code if you feel like you should customize something, but then continue to insist that, uh, there's no need to customize these platforms and yet 90% of the customers continue to customize these platforms.
So somebody's quite clearly not on the same page, and I might argue, and customer's always, right, so clearly there's something afoot here, but, but, um, what's, you know, you've been talking to SAPI know not too long ago. What's your sense of the tension in this in the, in the ecosystem? Yeah, I think there, there definitely is some tension because at the end of the day, you're right, the customer is demanding more and expecting more, and sometimes it can't be done with certain, um, software or, or vendors that they're working with.
So there has to be some collaboration. I mean, you know, let's just talk about what we were just speaking about at the Adobe Summit. There's tons of collaboration between Adobe and many other companies to provide all these different services and features.
Um, well, we should think about that in, in, um, this way too. Uh, when companies are looking, they should be able to piece together different ones and they should all be able to interact and work together. Yeah, and to your point, it feels like the Adobes and the Microsofts in the world are trying to fill in the white space around these ERP platforms.
They're essentially the systems of record. And so if I'm just, you know, recording transactions and things and events that occurred in those systems, I think that's fine. But the systems of engagement wrap around those platforms and may not necessarily be from an SAP or from Oracle or whoever.
And it's a, it's a little bit of a delicate dance, but I think, um, it leads to better innovation maybe if we have that approach. Of course, you know, you can't have too many vendors 'cause then you might have chaos altogether, but, um, are we trying to find some sort of digital balance? Yeah, and I mean, I guess that is where, like you said, if you have too many, then you're dealing with this huge sprawl that you're having to keep track of, um, for everything.
So that can be, uh, another problem in itself. But I do feel like there's certain, um, compromises that have to be made in the name of innovation and digital transformation. Alright.
Um, I can't help but wonder though, I mean, we talk about monolithic apps versus microservices in the land of DevOps all the time, and this plays out as a set of discrete processes, hopefully within a, an environment. So if we want this world to be the way it is, I think we need to better align what exactly is a quote unquote microservice as a, as a discreet unit as it relates to what a business process is. And we've been having this conversation about the lack of, uh, alignment between business and IT for three or four decades now.
But I wonder if we're at some tipping point now where we have to really think about managing the software in, in exactly the way it's aligned with the various tasks that we're trying to accomplish. Yeah, I think that's where it comes down to, to better communication among all the departments. And, and again, something we talk about regularly that still seems to be an issue, which is removing those silos to figure out what do all these different departments for, and then combine that into effective solutions.
All right. And then let's just jump over to our last story here. But, um, you mentioned silos, so it looks like we're creating another one.
People are trying to create these, uh, chief sustainability officer titles. What's your sense, uh, how real is this? Well, I I think that it, it's a very good argument, um, being made that it is a big focus and maybe a not, not enough focus is being put to it.
So they are trying to, um, essentially make a position for this or department, um, to focus on it. But I would hope that it doesn't become another silo. So the issue is anytime any new position or any new new department is formed, it, it has this risk of becoming a silo, which is what companies shouldn't be doing it.
No, no team should become a silo. We should all be collaborating and communicating well. Um, so, but as far as the position, I think it would help with, um, innovation, it would help with risk management, it would help with, um, environmental, you know, the environmental footprint these companies are making.
Uh, and, and there is a lot of, um, concern about the environmental footprint and maybe not enough focus being put to it. Yeah, I just wonder what the level of authority's gonna be because everybody who can actually affect the outcome of the process is a c-level own something, right? It's either the CIO or it's the head of manufacturing or wherever it is.
So, um, is the chief sustainability officer just gonna be, you know, filling out reports and sending memos to people and maybe not having enough authority? So whoever, if, if they do create these positions, I, I think there are some that have created these positions and I think it's, uh, all about, um, they will need to be good at managing and, uh, and communicating, uh, because they need to do a little bit more than just, uh, paperwork and things like that. They, they need to be the ones effectively communicating change across each department and ensuring that it's getting done and it, that they all work together.
I wonder, I mean, if I look at the regs that are required outside of Europe, they're still kind of shaky. Um, so is, is this getting enough traction globally or is it pretty much limited to a particular region where we're gonna see more of this effort than others? 'cause frankly, I, it's not clear to me that, you know, companies in the US are banging this drum as hard as they are in Europe and other places.
That's a good question. Well, we know Europe tends to, to get ahead of these things a little bit more, uh, and, uh, are first in line for a lot of those types of issues. But, um, I think here in America we're focusing more and more on it.
It it's just a matter of focus versus action. So, you know, and you know, which is where this whole know, which is where this whole conversation comes into play is acting. And, you know, as far as other countries, some are and some aren't.
So, you know, if you look across the globe, um, I'm sure there's a percentage that really aren't focused on it at all. So do you think AI might save us from ourselves here, or is AI part of the problem? Because we're consuming more energy than ever to drive all these large language models?
It's a quandary because it can both help and harm. And I think in, in a, uh, a podcast a few weeks ago, we were talking about how well maybe we could use the AI to eradicate the waste or use it in some other way. Um, so it, it's a quandary.
I do know, um, some people are looking at AI to, um, instead of having all this technological waste, um, basically rewinding legacy stuff to pull as much information as they can from it and, and utilize it with ai. So that'll be interesting to see how that plays out. All right.
Any other final thoughts from your trips and adventures from the last week? Oh my goodness. I'm just trying to recover from a whirlwind week with lots of information, but, um, stay tuned because there'll be more posted.
You can see a little bit of it on our, uh, tech strong AI LinkedIn site. All right, cool. Thank you all for listening to our latest podcast, and we'll see you next time.
Thank you. And, uh, stay tuned for more information. Thanks, Mike.
com is the number one online destination for DevOps education and community building. com covers all aspects of DevOps, including DevOps, best practices and tools, DevOps culture, DevSecOps, business impact, continuous testing, continuous delivery, and more. com has the largest collection of original DevOps content featuring breaking news, blog posts, podcasts, and more.
com to learn more. com where the world meets DevOps. This is techron tv.
We have the great pleasure of being joined by Andrew Pinkus, who is a co-founder with re Red Reactive welcome. Couldn't be talking with you Andrew. Yeah, thanks Mitch.
Appreciate It. You bet. You bet.
Um, you know, we've talked before, but that was at, uh, another, uh, part of your career, uh, a prior step, I think, when you were Atlassian, but great to be having you on here with, uh, red Reactive. Tell us a little bit about the company, uh, why you started it, the problem space that you're going after. I'd love to hear a little bit more about that, about Yeah, absolutely.
So, so at Redacted, we're kind the only developer folk, uh, platform focused on accessing, um, a live permissioned data for generative AI applications. We fundamentally feel like it's that missing part of the, um, like that kinda LOM application stack, which a lot of people are focused on that kind of governance aspect around that infrastructure layer looking at LLMs. But one of the biggest blockers to kind of AI or gen AI application adoption or fundamentally building them and getting into production is how do you access permission data that's live from sources like Confluence, slack Notion, OneDrive, uh, another kind of custom databases that might be governed by, um, identity access management systems.
We see so much kind of in market right now, this risk around bleeding information internally when you bring in generative ai and we're kind that one stop fix there in order to make sure that integrating RX VK into your product ensures that you can really seamlessly connect, um, to those data sources and then leverage them in real time if you're building AI agents, uh, chat bots, workflow applications, et cetera, any of this kind of next gen style of, uh, gen AI application. And the reason why we, we jumped into it is my co-founder, Alex and I, uh, we previously used to work at Atlassian, and we saw that kind of trend there around challenges around enterprise adoption of, of kind of capabilities. And that, um, it took a long time in order to move customers from kind of server environments and data center environments and data center environments in the cloud.
And there were so many permissioning data access, data sovereignty challenges there that need to be solved. And, and not just in Atlassian's case, fundamentally across the industry around cloud adoption that we saw a very similar trend probably starting to emerge in the January of AI space as well, is that, um, there's so many core open source projects that they're attempting to stand up, small proof of concepts, um, for interesting use cases, be it agents, chat bots, et cetera. But we really felt like, hey, this really complex and very clear part information security review requirements inside of enterprise environments such, so these proof of concepts that leverage gen AI are probably not gonna get into enterprise environments anytime soon.
So we wanted to become that kind of that key arm block in order for large groups of internal employees or even their customers to be able to gen to, to leverage generative AI capabilities. One thing I'm curious about with generative AI is, you know, it's relatively new, it's been around since 2017 or so, but most of us till the last year or two kind of burst on the scene. Are, are those, are the models LLMs, the, the smaller, uh, LLMs are, is there security model very mature?
Is that one of the things we're looking for generative AI to kind of come along with to what an enterprise would need for a security model? So you can't fully depend on what's in an LLM. Yeah, and it's kind of like if you look at the, the last few even kind of quarters of kind of generated AI kind of, um, changes and trends in market, it's the kind of last year obviously Gen, um, generated AI get very interested from like a productivity use case point of view with chat GPT and then organizations looked at, well, how do we bring this internal inside of our organization?
So then they looked at open source models and fine tuning, which obviously comes at great cost and removes a lot of that permission layer of data access. That's actually the information that you wanna pull on. And there's two kind of core components there, which are kind of security risks.
Um, when you look at kind of just fine tuning or training and model is that the information that you want AI to leverage, um, needs to come from an end tool. So you think about Confluence like notion one drive, you're gonna fine tune it. You're actually gonna strip that information away from its source of truth and now start kind of mixing in the concrete, um, into the model that you want to use, which means that that information at any point in time is fundamentally becoming stale.
Um, which means that, right, your strategy now is how do you continue to fine tune over time and bear that cost on the organization. The second component is from a security point of view, which is not only are you leveraging stale data now in order to leverage an LLM, but you've fundamentally stripped away the permissions or that fine grain access control from those documents. So there's kind of two layers there in the fact that not only have you removed that core access of an end user to a tool like Slack or Notion, but then also think about the pages that you can see and some of your coworkers can't.
You might have some locked documents. There might be some things that might be one-on-ones with your manager or HR information or finance information that that that department's dealing with. All of those fine-grain controls inside of those tools have now been stripped away when you start putting them into a, into a train in a trainable model.
So we've really lost that, that ability to control, um, data access and create that more kind of risk vectors inside of an organization. We leverage the RAG framework as a core component of how adaptive enables applications to leverage generated AI securely. And what we do is that we fundamentally pass through those security, um, kind of access control layers through to the end application.
So when you leverage reductive, you're passing through no longer prompt, but also the access token or the Old Walls token to that end user such that we're only pulling on the information that that right user has access to. You don't have tokens embedded in applications, you have your applications all using the same security model for accessing that data, not 25 different ways. I could imagine there's a lot of benefits to standardizing that process plus the maturity of it.
Are there, are there certain things about LLMs generative AI that present unique challenges to enterprises that are adopting them when it are adopting them when it comes to access control and security? Yeah, absolutely. And I think number one is that sense that in so many CTOs and sizers that we speak to is that there's a real kind of interest in starting internally with their core use cases.
So they're looking at from a, from a use case perspective, number one is if they're trying to, uh, provide permissions aware q and a across multiple different tools. So if you connect up your HR application and into your, um, confluence environment, you can actually pull permission data and more general information across the business for the right user as long as you respect their downstream commissions at any point in time. And then the second component is like, you know, um, like kind of that enterprise knowledge base q and a is really where people wanna start on their generally AI journey and enterprise environments.
But very quickly, once they get comfort there, they're looking at how can they augment their customer service agents, um, and really deal with high touch customer service, like human in the loop style customer service environments. And that's pulling permission data that's maybe very sensitive about the customer, especially in, uh, financial, in, uh, financial services industries. So thinking about banks or insurers we might be dealing with customers claim or finances information, you wanna ensure that that customer service agent can speak appropriately about the business and their product information or, or kind of their policies, but then also speak very specifically about what is that individual's end challenge or their situation.
Um, and really right now, customer service applications can't do that in the generally AI space because they are making these, um, other kind of, uh, these gaps around permission access. It's kind of all or nothing. Here's your token, now you can, you know, we have access, right?
Absolutely. Yeah. For better or for worse, you, and it seems like there's a number of use cases, use cases that come to mind.
You've talked about the chat bot and, and customer service. There's also automating workflows, you know, more behind the scenes backend kind of functions, um, you know, automated forms, things like that. I can imagine a number of places where you want to hook in, you know, gender A AI may not be the main application, but it's part of the ecosystem of data, data sources that you're using that you wanna be able to hook into those processes and applications.
Absolutely, and I think this is really where, it's really interesting to look at the application developer market that's emerging around generating ai, trying to build these native AI applications. We are working with some right now who are building AI agents, and one of their big challenges is that, you know, they're looking at customer service roles, researcher roles, they're looking at, uh, ITSM desk help desk environments, or even kind of risk like automated risk reporting as being this kind of core use cases, um, inside of businesses. But the big challenge that even these kind of AI agent builders have is how do they access these live commission data sources as well?
You can access, you know, kind of traditional data lakes and, and, and kind of more stale data in order to start to personalize how, how it all, how a agent might act, but really where you do your work every day is probably where an agent should do their work as well. Um, and those are in those collaboration tools environments where data is changing consistently, where permissions are being, um, on an almost hourly basis being applied and removed and is where the most recent source of information that you would want an agent to respond to, especially in a risk reporting case. Um, so unlocking that component with RSDK, something that we've been helping some of those AI agents actually do in market right now as well, such that they've got more data coverage to power their in these cases, Are there things you have to do differently for various LLMs, you know, there's something from an open ai, AI versus something you get off of hugging face.
Um, are they all different and you have to kind of, you have to adapt 'em to what you're doing? Or is it you providing more of a one way to access all of 'em? Yeah, no, it's a great question.
So, so we redacted RSDK now, uh, underlying platforms, fundamentally a large language model agnostic. Uh, we can allow, we allow you to plug into any model, be it some of those big ones in the space or if you are rolling your own, um, there's many different use cases there. So we really encourage our customers, especially in the enterprise environment, that if they have been fine tuning a model, uh, and they wanna start there, they can benchmark its performance whilst additionally providing live context through via model, um, are ways for them to kind of leverage what they might have already built or models that they feel comfortable about from, um, like AWS or GCP looking at Gemini and bedrock models, um, in order to feel really comfortable about the security constraints of other parts of their stack, whilst also using redacted to solve that, that fine-grained access control challenge.
That could also be helpful too then for, not saying it's a small deal to do, but if you want to change out LLMs that you're using, right? You may be using one today and now you've, you know, tuned or trained a different one or you're using a different source. I know some, some people are actually kinda acting as a front end to multiple LLMs and then depending upon the prompt will feed parts of it or, or all of it to a different LLM to get the best response from that particular model.
So like you have a lot more flexibility and less direct ties to un unhooking, you know, your connections into a specific LLM to talk to another one. A a Absolutely, and I think one of the, the things that, you know, we'd go am miss not to mention here as well, is that when you start having a lot of flexibility around different models, especially if you're an enterprise environment, you want a lot of transparency around that data pipeline. We, we are redacted when you're kind of moving information through in this live retrieval environment, um, and pulling relevant business context from, so like Slack Notion OneDrive, for example, for generated ai, we allow you to put in any kind of DLP provided your choice.
So double loss prevention are obviously really large standards things that go through large procurement cycles for enterprises. So they get really attached to their underlying DLP provider, and we allow you to basically pass through any of the context alongside the prompt through A DLP provider before then hitting that large language model of your choice as well. So that additional layer of kind of egress security, um, if protect within your, your VP C environment, What's, what's the onboarding look like?
What, how, what does it take, you know, developers always looking for, you know, make my job easier, don't make it more difficult than it already is enough challenges. Um, what does that onboarding onboarding model look like and how, how much time or effort does that take? Yeah, look, we, we've tried to at redacted really simplify that down, um, to the fact that you can do it within about a day.
Um, we have a SDK download off our website, contact us to get access. Um, you select the data sources that you'd like access to for your end users, and then, um, you fundamentally just put, um, insert a a a connect button into your application usually during your onboarding flow. Um, and if you've already got system administrator access and a trusted app inside the enterprise environment that Connect is, is as simple as like an SSO screen that you would see on Google.
Let's get that one encounter with redacted in your entire journey, and then you're fundamentally connected securely and managing the, and being able to pull from downstream app applications with its various levels of permission aligned to, to your level of access. Um, what's really great as well is like sort, it's really simple on onboard side of enterprise environments in that regard. With application developers, it's exactly the same as well, which is there's so many challenges around building those chunking and embedding Vector Store and live fetch pipelines that are taking away time from your engineers solving problems for your customers.
In your end use cases such as the exact same experience, jump to a platform, download the SDK, embed it into your application, and then passing through prompts plus token allows you to pull live business context from those end data sources. I think the last thing I here as well to this is that for our enterprise customers as well, is that we're actually providing a lot of, um, kind of template use cases as well, um, to, to enterprises to really just starting their generative ai, um, adoption journey. So whilst the redacted developer platform is really powerful to support any use case, we're building out those kind of permissions aware q and a and high touch customer service kind of template applications such that they can know in that front end.
It's something we intend to open, something we intend to open source in time and allows them to get really jumped into their generated AI journey with their, with their internal and customers within the, or sorry, internal employees within about two weeks, if not less. Right. I, I would think your experience too, working with enterprises, you, you understand the process you have to go through to get provisioned through the security teams, and the easier you can make that, the quicker it's gonna happen For sure.
A hundred percent. And, and one of the, the, one of the great points where, where Redacted comes into its own is, um, we've often found, uh, business buyers internally or someone who's in charge of generative AI and taken on that helm inside of the business, they might have built a really small rag application. They've got a vector store, which is stripped away the permissions that they're pointing to.
Um, they've got maybe 10 internal users leveraging it, and then they hit information security review. They get really excited about the idea of scaling it out to their customers and their, and that information security review, that security team fundamentally rejects that solution architecture. Mm-Hmm.
Um, because they say, why does your, your generative AI application be allowed to have a different permission system, different identity structure compared to, um, what we've invested in in a long time, how all the rest of our applications work, you're introducing new risks, we're blocking your application here. So they really start to feel that pain internally around that like that, that permission kind of management journey and that, that challenge there about how to solve that part of the stack. Um, but once we kind of come in and say, Hey, this is what Redacted does, they go, great, how can we integrate you tomorrow?
Because we need to unblock, um, our pathway through information security review. So we very quickly become kind of the trusted friend or kind of champion of, of the security, um, team as well, um, which has made it really simple to kind of then make that progress into production environments with our customers. Where are the hurdles the better O one of the hurdles that can happen in those reviews is, uh, retention of data.
Is there any data that's passing through some of the third party service? Is it getting left behind? So now we go down the road of the II and other, you know, sensitive kind of information.
Is that at all an issue for you? Yeah, well, it is actually something that we're, we're kind actively solving around. Again, kind of going to the origin story of redacted, looking at like what are the enterprise requirements, that production grade application kind of, um, adoption and then reversing it back, we knew that how redacted managers or potentially stores customer data is gonna be incredibly critical to our adoption as a developer platform ourselves.
So in those environments, what we've done is that we've really rolled this back to the idea that the big challenge is likely around how indexes of information are managed, which is a lot of applications or in the traditional enterprise search space, um, would be t trawling different different systems, pulling all that information into a, into a new vector database or just a fundamental new database before, um, large language models were really popular. Um, and they would store kind of chunks of information about potential customers, the company, et cetera. Um, redacted doesn't store chunks, and this is part of our unique solution architecture in order to do live retrieval, which is that we only ever storing embeddings of information, which is obfuscated versions of the actual line documents such that you can never reverse them back out into being a, a record of, of any kind of customer, et cetera.
Um, we leverage that plus a pointer system, so we identify where relevant context exists across the business, and then we always go to the source to do the app, um, app query time permissions, check that end user to make sure that live permissions are applied, and then also pull the, the live version of the document in. And what's really great about this is that because we act that pass through layer there and we're not storing any kind of version of the end document ourselves or information on customers, it reduces that third or fourth party risk, which security and information security team to really look at as being that kind of additional kind of vendor risk that that third party risk aspect. Excellent.
Excellent. Sounds exciting. It sounds like you're attacking a, a very valuable space to go after.
It's hard, hard for apps to do much without really good data Yeah. And secure access to it, whether it's, you know, generative or, or traditional applications. Um, what's the best way for folks to get ahold of you and start to look at, uh, red reactive?
Yeah, look, we're, we're, we're active w with, with many customers across Australia and the US at this point in time, across application developers trying to build, you know, Silicon Valley style startups and, and accessing commission data and wanna kind of really remove that pain around, um, those kind of, that new data engineering skillset. Um, and how to kind of, um, get customer trust, uh, by leveraging personalized information in their environments. Um, and on the other side as well is that enterprise is looking at how do they manage their generative AI journey?
How do they build a platform that can they feel comfortable in building multiple applications on top of, in the machine AI space? Um, and for both of them, I say contact us, our website, um, has a Calendly link on it. You can get in touch with us directly, um, and we've got a full team to go through assessing your use cases, how you can leverage the red reactive platform and then get you up and running either within the day or leveraging our template applications to be ready and going with internal use cases within two x.
Very good. And the website is redacted ai, correct? That's correct, yeah.
Awesome. Makes sense. It wouldn't be that.
Yes. It's been great talking with you and, uh, again, fascinating area and certainly something every enterprise, every business has to address around secure access to data. Now with, uh, generative ai, it's interesting.
I was just doing a panel here earlier today and we were talking about testing and access to data and all kinds of, the myriad of issues that come up with that when you start introducing generative ai. So wish you the best and, uh, keep us, keep us in touch as things progress, and, uh, love to hear more. Yeah, definitely be speaking to you soon, Mitch.
Really appreciate it. Thanks for the time today. ai.
I am Bonnie Schneider, sustainability contributor to the Techron Group. I'm excited to introduce you to a groundbreaking new initiative from Techron Research, the sustainability pulse meter. The pulse meter offers valuable insights into how environmental responsibility factors into tech purchasing decisions for key players in the industry.
Position your company as a leader in the industry and differentiate from your competitors with the sustainability Pulse meter offered exclusively from Techstrong Research. This Is Techstrong tv Everybody. I had a great pleasure of being joined by Aaron West.
Aaron is sales engineer with sios. How are you doing, Aaron? Hi there.
I'm doing very well. Thank you. And, and thanks for having me here today.
Of course. Absolutely. Um, tell us a little bit about sios.
I mean, you all been around for a while, so there's a lot of folks who do know you about you in case, uh, folks don't, then, then we're gonna get into an announcement that you just made recently, but start with a little bit about the company. Sure. So, um, we're a company that specializes in high availability, um, specifically around application availability.
Uh, we also, um, we also have products around storage availability and block replication. We've been doing this for a very, very long time. Um, so, you know, we've been around for ages, as you say, over 20 years in the industry.
And, um, our solutions cover both Linux and Windows. Very good. A lot of both out there in the world for sure, and always looking for more help with it.
Uh, talk about the, the exciting announcement that just occurred. Absolutely. So, um, I'm, I'm glad to announce that we've, uh, released our latest, um, version, which is 9 8 1.
And as part of that release, we've really taken things forward by releasing our new web management console. Um, now this is just for Linux in this release, although there will be a, um, a web management console in the future for our, our Windows product as well. I don't have a release date for that yet, but it's something to look forward to.
But those, using Linux can, can take advantage, can can take advantage of this now and, um, and see where we're moving with this. Fantastic. So tell us, tell us some of the benefits or, or some of the things that we can do now that you have sort of web management console, if you will, in, in one place.
You know, where you have a lot, I'm sure there's a lot of information that it's vital to know about, but it's hard to pull it all together. Yeah, absolutely. So, uh, I think the key, one of the key things is, is moving to a, a web management console rather than the, uh, Java based administration application that we've always used at sios.
Um, it basically means that it's a lot easier to, to develop and to build upon that as a platform. So for this release, it's really been about making something that's easy to look at, provides all the features that you would currently expected from our existing management, um, platform, and, uh, also puts that across in a very simplified, easy to use way. What, what would be some kind of example, use cases where someone is, it is something you're gonna hang in the operation center?
Is it something someone's gonna sit in front of to go diagnose or understand events that are occurring? Absolutely. So, um, the obvious thing is the initial configuration of your clusters.
It can all be done through the web management console in a very simple stepwise fashion. It will take you through the steps, you know, 1, 2, 3, 4, 5. If you stop partway through, you can walk away, come back, pick up from where you left off.
So, um, you're not stuck in a situation of having to, uh, understand everything about deploying a cluster straight away. Um, in addition to that, once you've got your clusters configured, management is made very, very simple. You know, it's a web management console, so you can simply log in from a, your desktop, your tablet, even your phone.
Um, it looks good and great on on all of those platforms. Um, from there you'll be able to handle things like failover and also see the state of the system. So as part of that, we've included a traffic light system.
So things are shown as green when they're healthy and operational, and things will be shown as red when there's some, uh, issue at play and you need to investigate a bit further. Um, I think the other thing that I really like about the platform is it's covered in tool tips everywhere. So it explains what these, uh, these features are, what, what different, you know, uh, statuses are.
And you can very easily, uh, click around on the tool tips and understand what you're looking at, You know, um, I don't think anybody's ever said Lennox and is simple and it's, that hasn't changed. Um, but particularly when you get into cluster cluster management, bail over high availability, um, all of those kind of issues, you know, that takes some pretty specialized skills, but we're adding new people to workforce all the time. So it sounds like the ability not only to see what's happening, but, you know, help me understand what it means is really Important.
Yeah, absolutely. I mean, the burden on your typical day-to-day, IT admin these days is, is growing. Um, and I feel sorry for a lot of these guys.
You know, back in the old days, systems were quite simple. You know, you provide the, the basic IT infrastructure and, you know, businesses small to medium, were typically running on things like spreadsheets and things like this. Whereas now a small to medium business is moving towards having, you know, SAP in their environment.
And as they have these more critical applications deployed and the bus business begins to rely upon them, they then need to become highly available. And also they need to think about disaster recovery. 'cause no longer can you, you know, withstand downtime.
So the burden on the i on the average IT guy in a company is definitely growing, that they're expected to know a lot more about different systems and have a, a wider skillset. A web management console like we provide hopefully takes some of the burden away from them by simplifying the whole thing. And meaning you don't actually have to be a clustering expert in order to, uh, you know, manage and look after a system.
Very good. Um, I'm curious to, um, one of the things about managing Linux clusters is that, you know, you're always having challenges with capacity, uh, workloads, the kind of applications that you're deploying on those, uh, different environments. 'cause those things don't stay static, right?
It's not like set it up, configure it, just kinda let it hang out there and people will use it. You, you have a lot of variability going on that you've gotta really understand when something's happening. What are the conditions around it?
Um, how, how does the web console help with something like that? Well, I think it takes you away from the traditional way of understanding these things, which is looking at log files, right? Um, you know, many a Linux admin will be sat at a terminal, um, you know, grepping a log file looking for statuses and, and trying to understand what's going on.
I mentioned earlier that we've got the, uh, the traffic light system. And I think that that's a, a really nice way of getting that across. You can now look at your cluster in a visual fashion, um, so you can see it on screen and you can pick up those statuses, uh, from, from the actual management console itself.
It'll show you if something's working, it'll highlight if there's a problem, and hopefully it'll highlight, you know, something that enables you to sort of solve a problem before it becomes too serious. Right? So if you can see that there's latency, say between the two nodes, and you can pick up upon that before it causes a, a false failover or something along those lines, then you can investigate what's the cause of that, um, and solve the problem before it actually becomes a problem.
It seems like also having the mobile, the i, the tablet, the mobile other interfaces are, you know, problems never happen when you're at work, right? It's always in the middle of the movie at the movie theater or somewhere. Absolutely.
It seems, you know, every system administrator or operations personal, uh, person certainly understands that, but being able to get access to that information very quickly and easily, so, you know, if you need to respond, would be a vital importance. Yeah, I mean, I, I don't imagine that lots of administrators would be sat there entirely administering their cluster from their phone. I mean, absolutely you could do that if you wanted to.
Um, but the status and being able to view what's going on from anywhere I think is exceptionally important because, um, obviously they can take an action from their phone, it's fully functional, but even just to know what's going on. So, you know, you have to, you know, jump onto the VPN or return to the office to get a, uh, you know, a problem resolved, um, is also extremely important. And then how you handle those statuses, you know, we can set up potentially alerts or, um, have it monitored in, in other systems within your, your organization.
Very good. Now, now this can work for both on-prem as well as in the cloud. Is that correct?
Yeah, I mean that's a, a really good feature, I think, uh, of, of what we provide. So our high availability solution covers, you know, Linux and Windows as we mentioned earlier, but also it's suitable for on-prem cloud deployments as well. Uh, and it looks the same wherever you deploy it, which is a really nice way of, uh, of, of having a solution.
Because all too often these days, you're an Amazon expert or you are a Azure expert, um, and understanding how things work across different platforms can be, you know, again, it's one of those burdens that's on the average it, it administrator, right? Um, but our solution allows you a common HA solution that looks the same wherever you deploy it works the same wherever you deploy it. Uh, and I think that's one of the real benefits.
If you're looking at sort of, you know, having stuff stretched between on-prem and the cloud or maybe even multi clouds, It seems like too, the benefit of being able to look at all of that, right? Not just at a single part of an element of a time. 'cause of oftentimes, you know, a distributed cloud application might be talking to a database or an application located in your data center, or it's distributed in multi-cloud fashion.
So it, uh, could be a hindrance just if you can get the window into one of those environments. But by being able to see all of it now you can trace down what's going on. Yeah.
And we are also integrated into those environments. So, you know, when, when we're working with Amazon, we are working with things that you used to route 53 EIP PS routing tables to get client access traffic to, you know, the active node. And the same with when we are working in Azure or other, um, hyperscaler cloud environments, we tie in using our application recovery kits to those environments, you know, directly.
Good. Um, now is this delivered as a SaaS, as a, as a cloud-based application? Is this something people can install in their own data center or both?
No, it's, it's absolutely something you install. So it, it will typically be running on the same nodes that, uh, uh, uh, form the cluster itself. So, you know, typically you'll have, say, two node cluster for something like, uh, a SQL server.
Um, and both of those nodes will host and run the web management console along with the actual clustering software itself. However, the software can connect to other nodes. So, you know, the idea is that as we go forward, it becomes more of a single pane of glass.
You'll be able to view your entire infrastructure through, through just connecting to one of your active nodes. Uh, interesting. Just kinda using any, any node, at least in the future, any node is an know, is an entree way into all of it.
That's it. Very interesting. So you mentioned, um, the configuration of it, of the web console, uh, web web management feature, uh, earlier it sounds like just, uh, does it come with pre-configured with any monitoring or any, uh, um, kind of red and green lights?
Or do you start out kind of with a canvas that you build what you want? Yeah, I mean, the basics of of monitoring is all there. So once you, once you deploy a cluster and actually create that, that cluster, that's gonna show up in the web management console and, uh, you know, different recovery kits that are being used.
So these are our, our specific, uh, way of interacting with different applications or platforms. We have our, our arcs, our application recovery kits. Those kits will each have their own, um, their own warnings and statuses that are then shown.
And, uh, you know, that's what I'm talking about having the traffic light system, whether it's green or red. So if you, for example, you've got, um, you know, uh, an an IP address that's, uh, you know, being moved between instances, you could check the status of that IP address. If it's a, um, if it's a storage volume that's, uh, replicated between instances, you could check the status of the storage and see if it's healthy and working as it should be.
Very good. So folks wanna get their hands on this. Maybe you get a demo or, or do a free trial.
How do they do that? Well, all of our, all of our documentation and information is available on our website and, and, you know, it's not behind paywalls and, uh, complicated login. So you can go and check that out.
Um, you can also book a demo right there on our website. So please do, we'd love to talk to you and, uh, introduce you to our, um, simplified HA solution. Very good.
com? Correct. com.
Okay, very good. com/demo-request and or free dash trial and get you straight to it, or you can get there just from the main page. Very good.
Um, anything else that you wanna add, Aaron? Just To say that this version isn't just about our web management console, it also comes with more platform support. So, um, you know, the actual product has moved forward, not just the addition of the web management console.
So you'll see newer versions of, uh, of Linux are now supported. So check that out too. Okay.
Part of a broader kind of up upgrade too. That's Right. Very nice.
Well, thanks. It's been a pleasure talking with you and I appreciate all the helpful information. Congratulations on the, uh, launch and, uh, look forward to the Windows version sometime down the road.
Thanks for joining us. Hope we get to talk again soon. Thank you.
You bet. Take care. Aaron Cloud Native now is the web's leading resource for the growing cloud native ecosystem.
com is your destination for news, thought leadership, features and webinars on cloud native architecture, Kubernetes, serverless, cloud native application development, microservices, service mesh, cloud native security, and more. Stay on the cutting edge of modern application development at Cloud Native. Now, This is Textron tv.
All right, guys, we're back at CubeCon plus Cloud Native Con here in lovely Paris. And we're talking to Cole Kennedy, who's CEO for testify sec. And we're gonna be talking about, well, the failure to communicate in the land of DevOps.
Cole, welcome to the show. Hey, thanks for having me. We have all these tools, they generate all this data, and I've talked to developers about this issue a million times.
'cause they, they hate this, right? They're like, somebody comes along and says, can you update this? Whether it's a project management app or whatever it is.
And they go, why do I have to update all this stuff is in this thing already. I have this tool here. Why can't you just collect it?
And they get frustrated. 'cause they don't wanna sit down with somebody and say, you know, here's the update. Or they don't wanna have to come out of their thing and say, you know, let me send you a message about a thing I just did, so then we can have this asynchronous conversation.
Yeah. That is all a waste of time. So how do we kinda uplift this whole thing?
Well, I think, you know, we can look at, you know, the recent past and when we started working with DevOps, right? It was all about how do we communicate, how do we communicate more effectively, right? Uh, you know, before we had these DevOps methodologies, there might have been that email that you sent to your production team saying, Hey, here's a binary, let's go deploy this thing, right?
But over time, we started developing APIs to help us out with this, right? Um, Kubernetes, Ansible, Terraform, these are all APIs that allow us to communicate much, much more effectively. Um, the problem is, is that, you know, we don't have these APIs, really, or these APIs are very new when it comes to communicating about security, which is I think a lot of these tools that you're talking about, right?
I see folks they like, use even Discord servers now to kind of communicate about a project. Feels like we've done a lot of unnatural things to figure this out. So, um, how automated can automated get as we go forward?
Because you guys got the framework now, but what comes next? Right? So, well, the framework, first of all, I'll do a little plug, it's in the, in total A is the API that allows us a lot of this to happen.
It allows you to create signed metadata about the different events in your software delivery life cycle, right? So when we have this trusted telemetry to communicate these events, we can evaluate this in an automated way, right? So pushing all these events into an API, whether that's a security scan, a two party code review, um, you know, or, or some other sort of a sign off or other tool that you use once you put all this data into an API, uh, that, that data can auto automated or be evaluated in an automated way.
Um, so, so that's really, you know, where, where the industry should move to if they wanna fix some of these issues around communication with DevSecOps and speed up these manual processes. We've had this issue for years is, and we're now at a CubeCon event. Yep.
Is there something about cloud native and microservices that kind of forces this conversation? Do we get to a level of complexity where people go, I can't deal with this anymore? Yeah, and I think that's what you're seeing is that we're moving much, much faster because we have these APIs around DevOps, but we're still slow when it comes to security because we haven't efficiently, we haven't been able to, uh, um, make that communication more efficient.
And so when we have microservices, right? That's even more applications that are moving even faster into production. So security can become a really big roadblock unless you have a really good methodology to understand the status and the risk of your artifact.
And when you have more artifacts because you're using microservices and you're using DevOps, you have more releases, right? It only compounds issue. And, and so this is why you're seeing a lot of the sids, a lot of security engineers are, are very over overworked and, and this problem because un tractable, unless you kind of change your methodology and how you're doing things.
So in, in a way, we're kind of creating this immutable workflow that we can understand and we can verify that this took place with this time with this component. Mm-hmm. Who, um, who wakes up in the morning and says, we gotta go solve this issue.
Is it the security side? Is it the DevOps team? A-C-I-O-C-T-O?
Yes. Well, I mean, you know, it's up to the ci o the CCEO of the company to understand where their risk is. And we've seen a lot of organizations have failed to understand how much risk is this in their software.
Um, so it starts from the top up, right? And then, you know, as an engineer, we have the responsibility to put out secure software that protects our users. So that's from the bottom up too, right?
So it really has to be a whole organizational effort, which again, comes to the problem of communicating, right? Sometimes it's very difficult to have that cross organizational communication, especially when it's a, a manual form of communication. It seems like there's a lot more regulations talking about securing the software supply chain.
We had the Biden administration and issue an executive order for the federal agencies anyway. Um, do you think we're gonna see more of that type of regulation that's gonna require companies to go address this issue a little bit more? Because right now I feel like it's still a, you know, it's a vitamin in the sense you should do this, but it's gonna become a headache real soon.
Yeah, I think we're starting to see it change from should to shall, um, you know, the, the, this just released that self attestation, um, PDF, that now if you're a CEO of a company, you, you need to sign that thing or have a designee that's authorized to sign, that's authorized to sign that, sign that thing. And, and that form, you know, puts down on paper that you comply with, uh, secure software development, um, practices when you're pushing out software. So if you're selling to the US government, like these, these are, these are shall now you must do these things in order to do business with the government.
Um, so I think we're gonna start seeing this filter down to other organizations such as, uh, large banks and, uh, other industries working with high compliance, right? Because, you know, a big part of, uh, of their threat is that software coming in from their vendors and they really wanna be able to control that. Um, and, and right now it, it's very difficult for them to do that because we get back to that communication, right?
It's tough for them to communicate what the status of, um, or what the vulnerabilities of the software that's coming into their system. They just don't have a system set up to do that. I don't think everybody knows who you are, but, um, you know, how did you get into this?
Where did you come from? I mean, not everybody wakes up in the morning and goes, I know I'm gonna go solve this security software management issue. Yeah.
So my co-founder and I, uh, Mikel, we were working, uh, for joint Special Operations command, um, developing applications to help the war fighter down range. And I actually got sent overseas week before Christmas to go deploy this application. Um, and I got there and because it was on a different network, this was a NATO network versus a US network, the compliance rules were completely different.
So we weren't able to deploy that 'cause of software because we didn't check all the boxes. Um, so I ended up spending Christmas away from my wife and my one, my 1-year-old daughter, and we completely failed the mission. The war fighter didn't get the software they needed all because of this compliance issue.
So, so this really gave my co-founder and I the impetus we needed to say, Hey, what do we, what do we do to solve this problem? Right? Um, and, and it ended up being a lot more complex than we thought it was.
Um, so, so, you know, five years later, um, you know, we were working with the DOD platform one for, uh, consultancy called Fox Code, and we ran into some of these similar issues, but this was for a nuclear weapons program. They, they had these requirements that, that code it needed to get checked, right? But, but this didn't fit into the paradigm that Platform one had created.
Um, so we reached for this open source project called in Toto and, and started implementing their DLG platform one. And it worked great, but it was a, it was a very academic project. Um, so Mikhail and I, we started working that, working with that project, adding the features needed to work with enterprises.
Um, and that's when the company we're working for actually got, got sold to IBM. So we're like, Hey, you know, we think we have an idea here. We think we know how to solve this problem, and it's a problem that does need to be solved.
So, so we started, uh, testify Stack, uh, with, with the, uh, you know, the purpose of, um, providing everyone with secure software. So, first of all, let me ask you, is your wife still talking to you? Because most people, you know, are the 1-year-old and you're overseas and it's Christmas, you would probably be getting a lot of dirty looks for a long time.
Yeah. Yeah. She, well, now that I'm bringing her to Cube Con in Paris, she, she's much more happy with me.
Um, but yeah, it was, uh, you know, solving these problems does take a lot of support, um, from your family, especially when you're getting deployed. Um, it was a, you know, that was a, it was a difficult job. Um, but, you know, it's something that, you know, had a profound impact on myself and profound impact on my co-founder.
Well, besides, you know, what happened on your family side, but with the work, do we underappreciate the amount of stress that we create because we don't have the right kind of handoffs and the right ability to verify that this was created? 'cause it seems like there's a lot of, you know, I don't know what I got, or I get there and suddenly I'm missing a component in your case. But, um, you know, have we become our own worst enemy sometimes?
Yeah. And that's all goes back to the inability to communicate. If a ci o could communicate with a developer and says, this is exactly what you need the software to do in order to be compliant and do that in a way that the developer understood, right?
A lot of these problems would go away, right? But what we see is, okay, the software's ready to go in production, but now we're missing step seven, eight, and nine, uh, because we have all these regulations because this is going into a bank, or this is going into a weapon system, or this is, this is going into some other high compliance areas and we just can't, we just, we gotta do the right thing, right? We, we gotta be compliant.
Right? The Army has, uh, an acronym called snafu, right? Um, have we accepted that too much in software?
'cause it feels like sometimes, uh, our teams are willing to put up with a lot of things that maybe they shouldn't. Yeah. It, you know, as a software engineer, we're taught to move very fast, right?
Getting shipping things is the most important thing. Um, and, and with that methodology, right? We forgot about, you know, basic engineering, right?
We should, when we create something, we should test it to make sure it works, right? And, uh, I I think now we're starting to see all that come full circle, uh, with that, with, with DevOps now turning in DevSecOps, making that security in. Uh, so I think things are changing.
Um, um, but yeah, there's a lot of work to do, right? We, we need a lot, we need that verification, that formal verification of our software and the processes our software goes under in order to understand the risk associated with it. Yeah.
So what's your best advice to folks? 'cause you've been here, you've lived it, and you know, these teams. So, you know, when you go visit a customer, what's that kind of thing that comes to mind when you go, folks?
Man, if you just thought about this one little thing, it would make a world of difference. Yeah. It's all about observability and, um, the software delivery lifecycle is missing that component.
And this is one of the things that we worked on with the CNCF software Supply chain best practices paper, as well as the software factory reference architectures. We found that this, this, this observability component just missing from all these different CI systems. Um, so can, can I tell you an analogy kinda?
Sure. So, I mean, if, if you had a daughter and she was getting married and she wanted this perfect cake for, for her wedding, right? You would bring that set of instructions to the baker and then a couple weeks later that Baker would drop that cake off at the wedding.
Well, what you've done is you've established a trust relationship with that baker. If that, uh, that kitchen, they, they baked it in was dirty, or the, the, they didn't wash your hands or they use the wrong ingredients, you really don't have any way of knowing that until you eat that cake and get sick from it, or don't get sick to it. Um, so if you didn't want your wedding to be ruined, I would recommend that you hire an observer, um, to watch how that cake's being made, right?
Every time that baker washes their hand, they write that down on a piece of paper and they sign it, right? Every, they, they, they look at what is the oven set to write that down on a piece of paper and sign it. They, what are ingredients go into it, right?
Write that down on a paper and sign it. So now when that cake is delivered, you can deliver those, that envelope with all those steps in it. And as long as you trust that signature on that envelope, you know how that cake was made, right?
You don't have to trust that baker. Now you can trust that observer to know that, hey, this wedding is not, not gonna get, uh, get ruined. And we need to do the same thing with our software, right?
We need an observer to watch the process of our software being made. And then when we do that, right, we can look at those observations and as long as we trust them right now, we can run that software with a good sense of assurance that, hey, it was built the way that our regulators tell us we need to, to build it. Or the way our cis o tells us we need to build our software.
Right now we know it is because we trust that observer. So one of the components to make that happen. 'cause if it's observability, right, I need some ability to collect it and some ability to ob analyze it.
So what are those things, right? So, uh, we, we are, we maintain two open source projects at Testify SEC one is witness and the other is ArcHa Vista. So witness is our observability tool.
Um, this collects information around the CI process. You can either embed it directly into, uh, your CI process or, you know, we do have some integrations with GitLab and GitHub that make it a lot easier to do, but then you need somewhere to put this information. So that's why we create IV Vista.
Uh, so IV Vista is a storage database that stores these in total attestations and allows you to query them. Um, so with these two components, you're effectively able to observe the entire supply chain, have a great place to store that information and query it. And then witness also has a policy engine that allows you to evaluate all this evidence to determine whether an artifact is compliant or not.
Um, most of the time this process takes days, right? 'cause you're exchanging emails back and forth. We can reduce that time with us tooling to, you know, you know, under a second, you can't walk down the street without somebody talking about ai.
Is this a found date? Is this a foundation for right now? I'm gonna go query something to find something, but at one point, will it start to just tell me that there are certain things that are a high risk proactively in a kind of a danger will Robinson kinda way, but let me know that there are issues in there that I'm not even aware of.
Yeah, I I think AI definitely had to place a play in, in the area of security, but exactly what you said, right? To bubble up information that you might not normally see. Where I don't see AI playing a role in security is where we need to make deterministic decisions about, um, the risk of a software artifact, right?
So it, it, it, a decision made by an AI engine is, isn't necessarily, at least not today, is not gonna pass the muster for, for most, uh, compliance officers, right? So we need some way to do that deterministically. So that's really what we're focused here on Testify SEC is, is not using AI to, to evaluate these attestations.
However, uh, we use a deterministic model to do that. And then we'll use AI to help the user sift through the information and find out, you know, that, uh, you know, some of the, uh, stuff you're talking about, those events, probabilistic is a fancy word for gambling, right? Yeah, yeah, yeah.
Right. It is. And regulators don't like that, right?
Exactly. Funny, thanks for coming on by. Hey, thanks for having me.
All right. This is Textron tv. Hey guys, thanks.
The throw, we're here with Perma Paraba, who is general manager for tansu, for the new Broadcom that's been created as a result of the acquisition of VMware. And we're gonna be talking about, well, everything from where is Kubernetes being used today, what are some of the issues that we're encountering? And for that matter, is AI gonna drive further adoption of Kubernetes?
And we'll get into it from there. But Pima, welcome to the show. Thank you, Mike.
Great to be on the show and good to connect with you again. I feel like, you know, I've been following Kubernetes for longer than I care to admit. Know.
I feel like sometimes there's us old timers and then there's a lot of newbies and nothing much in between. But, um, one of the things that seems to be happening is, I would argue Kubernetes is maybe becoming a victim of its own success. It's finally getting enough adoption and enough traction in the enterprise and production environments.
But as it does so too, does the course of complaints about the application development experience and the data scientists are now involved and they're saying, this stuff is hard. So where are we on this journey and where do we need to get to? Yeah.
It's interesting that you bring this up because, um, uh, I was at Europe just last week in Paris, and you are hundred percent right? The frenzy of innovation around Kubernetes is just crazy. The energy was amazing.
And I would say every time I turn my head around, there's a new little project solving a problem that is specific to Kubernetes. So what I saw, as you said, is all the newbies and all the d iy ourselves, you know, DIYers who are connecting dots and building a lot of stuff, a lot of open source contribution. But the interesting thing was, I also met some enterprises that were saying now I have slowly grown my Kubernetes platform team from, you know, I was experimenting with five people and now I have 75 people.
Uh, and ultimately still my developers don't have a simple interface to deploy and manage their applications, to build their applications. They are, we are trying to teach them yaml, we are trying to teach them configurations. We are trying to teach them how to handle Kubernetes itself.
And so the thing that I ca take came away is no doubt, the innovation in Kubernetes is amazing. We have been early, uh, we early to lean in into that, and we'll continue to lean heavily into that. But I think the bringing that promise of Kubernetes to developers is where we see a gap.
So the container platform to the app platform, and that is where we wanna strictly position tonsil, right? And that's where you have positioned tonsil to say, how do you take the power of the innovation that is happening and put it at the fingertips of developers without having them to learn 25 different projects and 35 different configurations, right? That's the, um, that's the promise.
So it was very interesting on the Kubernetes side. Yeah. Do you think there's a correlation between adoption of Kubernetes and this platform engineering movement that we hear a lot about, which is heavily focused on increasing developer productivity?
And does this all kinda tie neatly together with some higher level of abstraction that we're looking for? My goodness. Uh, absolutely.
You see the, it's not as if platform engineering as a discipline has not been there before. You know, of course, you, you know, from tan Zu platform, we also have the Cloud Foundry around time, and there's a very strong platform engineering discipline that was built around that. But that same demand, or it's like a drumbeat is coming up now for the modern app based on Kubernetes work to say we need a platform engineering discipline.
And the discipline is not just about products and platforms, it's also about fundamentally how do you think about the relationship between developers and platform engineers? How do you think about the cultural transformation? How do you think about the processes and what we have, uh, now an industry term called define golden paths to production, all part of platform engineering.
And if you want to do platform engineering, right? We know you cannot expose the guts of the platform to the developer. Why does a developer care?
And so imagine if you could just give that abstraction to a developer to say, Hey, you have written your code, you want to build it, you want to bind external services, you want to deploy it, you wanna update it, you wanna scale it and secure it. That's it. You don't need to know how to configure a cluster.
How to configure is to service mesh, to connect to each other, how to configure a particular load balancer to talk to that environment. And that is where I see the next generation of evolution happening. Mm-Hmm.
In the market, and at least the, whether it's happening or not, it's really the demand is coming up now, right? And, and more so as you start talking about AI ml, I Can't help but wonder though if some of the complaints are tied back to, well, we just didn't think through the application we were building and whether it was fit for this particular purpose or not on Kubernetes, because there's a lot of people talking about, well, we should do everything in microservices. And then there's other people who say, me and you shouldn't avoid microservices at all costs unless you absolutely have to.
And then there's other folks who are somewhere in between. But do we need to get smarter about what kinds of applications we're deploying on Kubernetes? Because maybe a little bit is people are just like, well, it's the cool new thing I should build an app for.
Yeah, I think that's a very interesting thing, which is, is it the tail wagging the dog thing? Which start? And our, um, philosophy and premise, and this is what Tan Zu has championed for a long time, is it has to start from app down.
Ultimately, that drives the business need and technology choices. You don't pick a technology and say, okay, I'm gonna build an app for that, which now unfortunately is happening a little bit. But if, when you start app down, then you say, what is the right architecture?
Then you say, what is the, you even say, what is the right language I'm building, right? It starts from there. So that you want to reduce the toil as much as possible.
Let us say I'm building a new modern app. Maybe I will start with spring. It's already given me all the connectivities.
It gives me the framework, it gives me this beautiful place in id, I start building my business logic. That is where the biggest power comes, right? In developers building the business logic for your environments.
And so you build that business logic and then you say, okay, let me make a call. Where do I want to have this run? Do I want to run it on a Kubernetes based platform, or do I want to run it on maybe virtual machines or do I just go for pass services from, uh, certain types of things?
I don't even, uh, need to build something, you know, build and package something there. And so that decision comes next. And then the decision is a which environment do I deploy?
Maybe if I have a lot of proximity to data and I don't wanna ship it around, I do it on a private cloud cloud. If I have very little, you know, if I, if network traffic is not gonna kill me, maybe I do it on public clouds, or if I need a lot of geolocation and proximity to end users, I get the power of a public cloud. So you have to pick based on the application judgment call.
And that is where I feel the transformative, uh, power of platform engineering comes in. Platform engineering should make these choices as intent for the developers. So imagine I build my business logic, then I say, Hey, look, I don't want to, uh, curate my own database.
Give me an external database to bind into it, for example, or external data source to bind into it. And with AI ml, now people are saying external model that I can start using, because I'm not always, everybody doesn't build models. Most people use models, right?
And, and so that could all just be intent of what you want, the language bindings and the environment that you want. Another intent could be, Hey, I want high availability. Give me across multiple clusters and failover.
Give me low latency. Give me access to data. All these things, rather than it be defined by the developer at a Kubernetes level, for a Kubernetes sake, you define intent at this level.
And ideally, the platform, the platform solution product as well as the platform engineering team should then drive the translation of that and, um, and, and improve then ultimately the deployment of the applications and management of applications. That is the ultimate state where we have to be. By the way, this is not new.
This is a pattern we've seen before. If you remember, uh, I, I, I, I say I was in cloud before cloud. I was with a company called LoudCloud, uh, mark and recent and Ben Horowitz's company in, uh, you know, 98, 2000, and we were building a cloud.
And at that time, I know customers used to come and say, Hey, I want to see my server. And we said, you, you don't get to see our server. It's virtualized.
You know, we have virtualized it. And uh, you, you are, it's a shared pool. I think it's the same thing.
You don't need to own your Kubernetes clusters and Kubernetes environments and know your service mesh architecture that has to get abstracted at the app level. So this narrative of container platform getting elevated to app platform is key. We talked about the platform engineering team, and a lot of those folks are basically trying to manage DevOps at scale.
But there's been this ongoing conversation about, uh, do I deploy Kubernetes on the virtual machine? Do I encapsulate the virtual machine so it runs in a container on Kubernetes, or do I put everything on a bare metal server? It seems like we're still all over the place.
So what drives people one way or another? Um, sometimes it's logical decisions and sometimes it is religion, right? You know that.
And so, but if at least our philosophy, and when I think about tan zu and I think about B, C, F and VMware is just like with virtualization, we just gave a runtime that just works. Do you ever think about ESXI? No, it just works.
You ask for a bm you get a bm and we are doing the same thing with Kubernetes in the, so rather than thinking, so we are separating the runtime and that platform. So we're saying the runtime just needs to be a fundamental dial tone that needs to be part of the infrastructure. And so with our VMware cloud foundation that I talked about, we are saying just like you can go and ask for a VM and you can ask for it to be highly available, you can move it around.
You can do all this dynamic workload balancing. Imagine you can just go and ask for a Kubernetes cluster, a Kubernetes environment that is just simple namespace. These things are, um, something that an infrastructure admin just sets up as, uh, table stakes and you don't really start think worrying about.
And, and what we have done in internally is of course made it highly performant on top of, um, the BSPHERE and ESXI infrastructure. So whether it is bare metal or not becomes a material, it's just easy and the dial tone is there, and then the question becomes, okay, how do you start using that? That is Kubernetes.
So I feel like at this point, the Kubernetes dial tone is a moot point. It's like you either get it as part of your private cloud infrastructure with vSphere, or you go and get E-K-S-A-K sgk, these offerings have matured a lot. They're pretty good and they are continuously innovating.
So for somebody to be sitting and thinking about kuber style tone and trying to spend an inordinate amount of effort on that is a waste. And then the question becomes, what do you do after that? How do you now connect the dots between the container on time and start putting services on it so that it becomes us, right?
I should not be, again, asking ever for clusters, right? I should be saying, Hey, this is my app and this is my intent. So how do you define networking?
How do you do mesh type of characteristics so that you can connect all these clusters? How do you define regions and availability? That's where platform engineering power comes Wem certain to see some new folks hanging around the proverbial Kubernetes cooler, and it looks like AI workloads are becoming a killer app for Kubernetes, but we have all these folks who are, uh, data scientists and they're using ML ops to build these models.
And then somehow or other we want that to get handed off to the DevOps slash platform engineering team and throw in some data engineers and a few security specialists on top of that. How do we structure this so that it, it, it kind of works. Again, this is a philosophy that we have and it's changing, right?
What, uh, we all are learning as we go, but I think we need to separate model development from. And, um, I think if you start doing that, that becomes a lot. First of all, you have to think, you know, hey, how many people are actually building net models from scratch?
How many people are versus how many people are fine tuning with their context and then incorporating it into their business apps, right? We have got all kinds of very powerful models being innovated. There is a, and, and, and there are all these cloud services that are offering, um, AI ML services.
So when you do that, then you say, okay, of course, Kubernetes as a place to run AI ML workloads has become very popular, uh, at CubeCon. In fact, the keynote was AI m everything was about ai ML and AI workloads. Now, if you separate and whether it runs on Kubernetes or not, once you separate those two, then you say, okay, what things can you do to help the model developers life easier, right?
How do you do the data cleansing? How do you do the, you know, data engineering? How do you do the, um, fine tuning of parameters?
How do you do the closed loop cycle to get the model right? And then the second part is, hey, how do I let us say I have a model that is developed for a particular industry vertical and it has got all the right data, everything. How do I start using it within my apps, right?
'cause model by itself does nothing. You still have to put it in context of the business apps or the business services that you are trying to deliver to their customer in terms of the interfaces that you're giving to the customers and so on. And so, um, that is where I was talking earlier, we have done some amazing innovation in spring, uh, called spring ai, and now it is part of the Zu platform with the spring accelerators and AI ML accelerators and tiles.
And the idea is how do you bring the power, power of these models that are being developed in Python, but to a Java developer, most of these enterprise apps, 50% of the enterprise apps are in spring and even more are in Java. And ultimately the data sits here, the context sits here, et cetera. So how do you bring that power?
So which bring ai, we have created these Java APIs that allow a Java developer to then access these Python models or other types of models that may be connecting to public cloud models, bedrock or open ai, any so on. So you are getting, making it easier from a usage perspective. And that of course, naturally fits within the platform engineering piece.
It fits within your, um, build and deploy infrastructure very easily. Do you think we might soon apply AI to the management of Kubernetes itself because, um, it's still fairly difficult and requires a certain amount of expertise. It's getting easier, but I can't help but wonder if, uh, maybe we can use AI to cure what ails us.
Um, absolutely. And we are already, and we have already done that. So not just specifically Kubernetes, but uh, we launched something called as part of this tan zu portfolio, right?
We have really bought the tan zu platform together, right? The, the one that I've talked about it, and it's anchored by something called Tan Zu Hub. Tan Zu Hub essentially takes the data associated with your operational environment, your performance, your metrics, your logs, your information about your architecture, your dependencies of Kubernetes clusters to the, um, you know, virtual machines, if it's running on that or your networking dependencies.
And then we have a gen AI based interface on top of it where you, rather than saying, looking at red, blue, green blinky lights in a dashboard and then saying, clicking and saying What went wrong? How do I solve? Often management is less about initial deployment.
Initial deployment happens somehow, but then the minute the next, you start deploying apps and, and now your latency goes through the roof, your logs are not getting collected properly. How do you debug all of that, right? That's where the problems start.
And so this AI ML interface, and we'll be happy to show you actually, or send you a video of it, allows you to just ask questions, Hey, which application is having trouble? Show me where the trouble is. And then it takes you to the right screens and walks you through the process and then also gives you answers on what you can do.
So while it is not a, just purely a single but button magic, but the AI ML is a very powerful way to help humans interact with operational data. Operational data is fundamentally complex. And you shouldn't have to sift through operation data or write massive queries to understand operational data.
You should be able to talk to it. And that's what we have done with Council Hub. So ultimately, what's your best advice to folks or, um, since you've been around the block a few times.
What do you see folks doing in the land of Kubernetes today that just makes you shake your head and go, folks, we need to be a little bit smarter than that. I think, uh, you hit it when you asked the first question. Please go and understand what is the goal and outcome you're trying to drive.
Kubernetes is not an outcome. Kubernetes is a method to get to the outcome. And as long as we keep that sanity, you know, anytime a technology becomes popular, everybody wants to adopt it.
They just want, it's great on your resume, it's great on your skillsets, but even on your resume, if you can say, not just that I know Kubernetes, but I have managed to use Kubernetes to drive this outcome. Just even if you're thinking about your resume, do it that way. So the whole industry as a whole, and many, many do that by the way, but as a whole, as we, if we start looking at these projects and start making them outcome driven, right, that you're doing within your organization, that will actually drive a lot of value to you as an individual, but also to the company.
Alright folks, you heard it here, Kubernetes, it's a means to an end. So start with the end and work backwards. Hey Pima, thanks for being on the show.
Thank you, Mike, and thank you. And back to you guys in the.