Techstrong TV November 25, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey everyone, those DDoSs just keep getting bigger. You are watching Textron Gang. Hi everyone.
Happy Tuesday. It's gonna be a short week here on the Gang. It's the US holiday of Thanksgiving, so a lot of us might be heading out to visit family or heading home to have family visit us, but we probably, I think Wednesday will be, uh, our show and then we'll do one for Friday.
Um, but be that, whether you are taking off for the Thanksgiving holiday or not, we're glad you're watching and joining us today on Textron Gang. As we kick off our Tuesday coverage, let me introduce you to our fantastic gang that we have for today. We have, uh, our friend Steven FoST, also our friend jp.
They're all our friends. They're all gang members here, JP Morganthal, hope Lynch and Y Genni, and give Genni. I always mess up your last name, but it's Caram.
And then of course, the dean, Mike Ard gang. Welcome. We've got a lot to go over today, so let's dive right into things.
You know, over the years, I, I don't know, maybe it's this, that spectator in me, I love to see how many, how big a DDoS attack can get, right? They've grown over the years because, you know, we have, we have organizations like Akamai and CloudFlare, these big CRNs that can diffuse these, you know, often terabits of, of, of, uh, of traffic that these DDoS storms create. But it looks like maybe we got all, we, we hit another new, I don't know if it's an all time high, but eugeni a major attack against Microsoft, uh, by a particular, you know, and, and these, it's botnets that really, you know, create these storms.
Evgeni, what can you tell us, or Mike, do you wanna kick us off and we'll go to Yu Afghani? Yeah, Yeah, just the facts of the case are, um, at least Microsoft is reporting that, uh, I think more than 500,000, basically a half a million IP addresses were involved in this attack. And these things have been steadily increasing all year long.
I mean, it seems like there's now a leapfrog to kind of make the next biggest DDoS attack, and it seems to be happening at a rate of almost, you know, a new record every two to three months or so, Afghani, is that what we're seeing? But is all this eventually gonna build to the point where, well, maybe we will take down the internet? I don't know, but what's your concern?
There's a couple of things that's a very, very interesting, if it go 10, 15 years ago, we had did this attacks there as well, but the difference that we used to implement a DDoS devices on-prem, now it's not gonna be possible because the device on-prem, it's still very, very related to the amount of traffic and the throughput of the internet you have. So you have to have a gido protection in the cloud, whereas the pipe of the provider will be much bigger than the pipe of the end user there. So companies like Akamai, company like CloudFlare or Roger, and many others have five as well, have a cloud approach because we need a bigger pipe to be able to clean.
And this has become very interesting because we basically switch the way we protect users. Also with DDoS, we can do protections that on demand or protection all the time, depending on the cost as well. And if you look on Microsoft, guess what, they're not using somebody else, at least as far as we know, they have their own protection.
Same with AWS, same with GCP. And it's a quite a big shift that some of the bigger companies decided to build their own protections like the clouds, the Azures, the, uh, the is instead of using somebody else. So this is definitely a shift because they need to provide and protect their customers and protect themselves as well about the size and the scale.
We not always like to talk about ai, but the majority of the previous attacks, the bigger ones that Mira Botnets were not controlled by ai as far as we know they were controlled by humans. Right Now, guess what, we may have a human that control some kind of an AI system that can now much better understand where to attack and how to shift that attack as well. And I think this, what we're gonna be seeing, we are gonna be seeing DDoS attacks that are managed by some kind of AI entity to make them smarter and able to shift them and maybe avoid the defenses of the, the target.
Interesting. You know, I, I think one of the problem, not problems, it's not a problem, but I think one of the issues we have when we talk about how do we wanna defend against DDoS attacks is the fact of the matter is most DDoS attacks do not bring down sites anymore, right? It used to be, you know, Microsoft weren't dark for a couple hours or Google was brought down or what have you.
What happens is it is, for most of us, DDoS has become a sort of minor annoyance. I mean, even here at Tech Trunk, right? We operate Security Boulevard, its security site, cyber site, and it's pretty well known.
It gets a lot of views. And so it's a frequent target of the bad guys because we're always publishing cyber stuff. And you know, I'll get notified from our providers once every two, three weeks, Hey, we, we blocked a DDoS attack against the Boulevard today, right?
And here's, here's the, you know, the metrics and so forth and where it came from and, and we, you know, and they put it into their normal, you know, uh, crime fighting kind of, uh, system there to try to figure out who did it and what's going on. But, you know, and I may see the slights a little sluggish sometimes. Sometimes we don't even see the slight being sluggish.
So it, it's kind of the, I I I analogize it to, you know, credit card fraud. Most of us never are victim of credit card fraud in terms of it really cost us money. It's just a pain in the butt.
We gotta file a claim with the credit card company or the bank, and they credit us back on our account, but it really doesn't cost us anything out of our pocket. It's just an annoyance, Deducts, interesting analogy, but it's, don't think about that. It's because we shift from on-prem protection.
You're no longer protecting your website here, it's down somebody else mm-hmm. Upstream. Yeah.
Right. And that's exactly it. We've, we've put the burden on someone else and let them worry about it.
And I think for a lot of us, that's what DDoS has become too. But I also, I also wonder in, in listening and thinking about this, um, yes, years ago you probably had an appliance on your network, but now it's up to the hyperscalers. But I think also part of it is them offloading risk, right?
So if I want to be safe, maybe I think, oh, I migrate to cloud instead of, you know, being part of the open and be centralized, uh, seemingly more fragile internet while the one that's controlled by the hyperscalers is more resilient. And also, um, there are a lot of companies that if they were still having appliances on-prem, it would be older legacy hardware, forget about regulation updates and all of those things, they probably would still be more vulnerable. Um, so I think a Lot are just offloading the risk to The hyper.
Yeah, I mean, it makes sense. But let me, let me tell you a another side and a victim of this, right? Because how do you, how do you block DDoS attacks?
Basically, you, you filter out the ips that are attacking you, right? So we're getting, whether it's a ping or, you know, whatever kind of traffic you're sending me, I say, okay, this ip, you know, Steven's IP is sending me a lot of garbage and I'm gonna filter it out. I'm just gonna filter out Steven's ip.
But Steven's not sending that on purpose. Steven's Steven's machine was zombie, right? And so, unbeknownst to Steven, his machine has been added to this botnet, and it's, and it's, you know, flooding my, my pipe.
And so I block Steven because he's flooding my pipe, you know? And Steven deserved. Now, Steven didn't deserve it.
What did he know? So, but, but, but now the problem is, is when do I turn Steven back on? And how does it impact Steven being blocked as a, uh, uh, one of the bots of this podcast?
That, that's that, yeah, that's a really interesting point. And I, you know, I I, I've thought about this before, and as you started speaking about it, I started to think about if you specify any time period, then the, the attackers are just gonna learn what that time period is and start re and turn back that node back on with it after that time period. So it's, now you need an a, a process to go through to get validated again, to get cleaned.
But I mean, sorry, it's like an STD, you should have to go to the doctor and get cleared before you get to back. I, I didn't have that on my bingo card, jp. I gotta be honest with you, Steven, was this, what did they say, Stephen?
He was, in fact, I'm sorry. It, it's a, it's, it's an appropriate level comparison because his machine was infected. I, I gotta say, I was enjoying this conversation until that jp um, you know, I, I swear it wasn't me.
Um, mm-hmm. But it, it's, you know, it is, it is funny 'cause the, um, the fact that most of these botnets are now using consumer IOT devices. You know, one of the things we pointed out in the article, for example, is that the, the rise of fiber to the home, uh, has made these all the more potent, because even a low powered, you know, device, an IOT camera, a thermostat, DVR, you know, router could, um, participate in a ddo s to a much greater extent than it could back in the old DSL days or something, you know?
But I agree that I, I've always felt like some things belong in the, in the network, and some things belong on-prem. You know, email is an application that belongs in the network. Uh, web servers belong in the network.
Why? Because, because they're accessed that way. Whereas, you know, other services belong on-prem.
DDoS mitigation strikes me as something that belongs in the network, and it, it, it should be something that companies like Akamai and CloudFlare and yes, Microsoft are working to mitigate rather than something that we individuals have to fight off. Because it's, it's really an internet problem. It's, uh, you know, like your, uh, uh, distasteful analogy, you know, there's a point at which a, um, a, a disease goes from a personal problem to a social problem.
And I think DDoS is a social problem. So we have to have companies like CloudFlare, for example, mitigating this. But that being said, think about last week's news about Cloudflare's outage.
One of the reasons that it impacted so much of the internet, including all of my sites, including all of our sites, is because we rely on cloud or CloudFlare for DDoS protection. And so by doing that, we're essentially putting all our eggs in this very one big, very capable basket. But that does open us up to other issues.
And, and I could see a situation where one of these botnets successfully DDoSs, you know, a, a CloudFlare or Microsoft or Google, and that would be really damaging. So at what point though, am I, am Danny, work me through this, William, because it seems to me like I'm at half a million IP addresses. I'm probably this time next year gonna be seeing attacks involving a million IP addresses, and can I block a million IP addresses and figure out when they should be turned back on?
And remember, there are multiple DDoS attacks out there. So, um, at what point is this just gonna become unmanageable? So somebody need to run and manage this vidos attack.
I believe we already have some kind of an AI operated or half AI operated system that help me to run this attack to be more manageable on the bad guys. This is gonna become the part on our side, on the good guy side as well, to use some kind of intelligence, artificial intelligence to help us understand what to run. Now, when we say block these ips, we are blocking them to access our sites.
It doesn't mean we're blocking them to access other sites. We're potentially making them this IP higher on a blacklist, and then maybe we're gonna block in from SAPs, or the reputation will go down because they have reputations list everywhere else as well. So there may be potentially gonna be blocked somewhere else.
For example, if I'm a small business and from my ip, a DDoS launch, my IP reputation now goes higher or better, whatever you wanna say this now, potentially my email maybe blocked or other connections from me, maybe block somewhere else. But to answer your question, we'll need a more sophisticated system to understand how this attack evolve and to block it as well. So we'll need to find a way.
And majority of the vendors right now use AI in one way or another. Not many people talk right now about AI-based DDoS protections. We have firewalls that are more AI aware right now, DDoS and ai, I didn't hear yet, but I'm sure all the providers have something that helps them evolve.
That makes sense. I, I know someone who you can call to help you. I, in, in, uh, doing a little research for this.
So IU, who they say are responsible for it, one of the prime people, he's based in Brazil, not only is he part of the attackers, but he runs a DDoS mitigation service. So, So he's playing both sides. The He knows how he attacks and he knows how to defend.
Well, those are the best guys. Those are the best. Isn't that Like, just morally wrong?
I'm sorry. Let's clarify. He's setting the house on fire and putting out the fire.
So Yeah, it's good. But, but you know, it does bring up the issue though, that these botnet networks are oftentimes run by, um, pseudo, uh, state, you know, country, state actors, or at least supported by, uh, state actors. And, you know, now we, we have seen in the past, uh, police activity, law enforcement activity against some of these botnet operators where it made sense and they've taken them down.
Microsoft, there's always a good job with that. There's always one to pop back up on this Thing. Yeah, well, that's the problem.
It's a bit of a whack-a-mole game. And now, and now all these hacktivists are renting those services to bombard anybody that you happen to Disagree. Well, yes, you can rent, you could rent a DDoS storm.
What JP said about me earlier, I think I might rent a DDoS. Jp, what's your address? Uh, I think you're taking this a little too personal.
Well, No, but Steven, the, the key is though, after you ddo them, then you come in and offer to, to, uh, Oh, so the, to defend So the old mafioso Yeah, exactly. I break, I have a kid break your window, and then I, You shame of something happened, right? Yeah.
Um, but, but you know, to Steven's point earlier about IOT devices, you know, you have Amazon, you have Google, right? They're, they're hosting the network services for a lot of these devices. I, I, hopefully they're smart enough and, you know, their equipment is becoming enabled, uh, with, you know, enough compute power and, and os that it could be compromised.
So I hope, I mean, I hope they're smart enough that when these devices are coming online and connecting back home, that they're doing so through a VPN level connection, I, we don't know because we don't own those devices. We can't see how they're connecting. But think about, and I don't mean to pick on them, I don't know anything about them, but Honeywell, my, my, my, uh, thermostats connect back to Honeywell.
I haven't seen Honeywell in the news talk out and stepping up about their advanced capabilities for security and DDoS protection. They're now, maybe they're delegated through a Microsoft and partnership or Google partnership protect themselves, but Honeywell's now the risk is on them. They're the ones who are capable of now opening up, uh, potential for IOT devices on their network to be compromised.
Yeah. Well, and to that point, I think a lot of these companies with IOT devices are finding out that this is a challenge. Um, I'm pretty mad at BMW because they shut off third party integration with their connected drive experience, uh, last month.
The reason they did that is because it was, uh, realized that there was almost no security on it, and anyone could find out the status of anyone's car. And, uh, actually, right, uh, settings including unlock to anyone's car, uh, that's not great. And so they shut it off immediately.
And I think that, you know, there's a lot of abandoned wear out there. There's a lot of just, just garbage out. There you go.
You go buy an iot, you know, an off-brand IOT switch or thermostat or something. You don't know how well that's protected. It's probably not.
And it's certainly not gonna get any kind of security updates. That's the world we live in. And I think a lot of respectable and responsible companies, like I said, like BMW, I'm kind of mad that they shut it off, but I'm glad that they did too, because I'd rather not have my car unlock by somebody over the internet.
So, wait, is there an opportunity here for somebody to, I don't know, sell a managed botnet? Let's not use jps metaphor. Let's go with an extermination service so that I get rid of all my infected devices and, you know, I'm just gonna pay extra for the privilege.
Or is this something that just, you know, I'm the cdm, Nobody gonna pay for this. I think about that. Well, somebody need to pay for this government who, you know, JI government, And we don't own the devices, right?
So I, I don't have access to my Amazon doc. I can't get inside it. I can't d you know, uh, exterminate anything that's in it.
I can't, it's not on me, Right? And, and so this, and we don't have time cuts, we're way over time on this, but if you look at the, it was DigiCert and a bunch of people put together an industry consortium for these connected devices. And it, it starts with, it starts with each connected device having its own unique MAC address and its own unique certificates, PKI certificates, and so that you can reach in and control individual iot devices, but only if they've been built to do so.
And, and there are several industry consortiums around that. I, I've actually done some work in there over the years, but, um, at the end of the day, they're all still connected. And the bad guys always seem to find a way.
But we gotta take a break. There's a great conversation, great topic, but we're gonna come back and we're gonna talk about the Tennessee Titans. No, not those titans.
Different data center titans. You're watching text, drug gun, You've earned it. The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included that work.
You are protected physically and digitally. Nothing gets through your team without a fight. But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm.
And now home your sanctuary attackers see an opportunity. Your digital front door is wide open. And what compromises your home can breach your border.
Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk. Black clerk, digital executive protection, defending the new attack surface your personal life.
Hey, folks, we're back in. Yeah, we're talking about Tennessee home of the TVA, and turns out there's a report that says that the state of Tennessee, followed by Texas, is now number two for AI data center deployments. And of course, you know, California and Virginia are probably number one and two overall.
But it's interesting to see that there's been a shift in terms of where these AI workloads are showing up. Jp, did any of this surprise you in here? And are we using, you know, government funded electricity to drive these data centers in Tennessee?
It, it Wasn't, it was a little surprising only because, uh, geographically, my experience was at North Carolina was on the rise. Uh, back when I was, uh, at EMC, um, there were a number of data centers that were being built in North Carolina, all very modern, the access to the cooler temperatures, uh, fresh water, uh, and electricity, you know, made them a optimal site for building out data centers. Now, it seems that people have found, uh, that Tennessee also meets the same requirements.
You know, it's like, um, a little bit like, you know, the old Star Trek or, uh, sci-fi shows where they're out there looking for a planet that meets your, you know, needs for life and support. You know, if, if we find the place that, you know, they're gonna settle it, and, you know, to the matrix point, right? They become power sites and start to overpower and destroy the environment.
Uh, and that's what the report kind of is saying. It's like, all right, you know, these, uh, these, these beasts that are, uh, in need of massive compute power, especially around ai, are identifying, you know, environmentally good places to put a data center, uh, that supports their needs, but they're destroying the environment that is around it. And, uh, and these are, uh, uh, areas that are impacted by climate and other events that are going on.
And the recommendation was, you know, for, you know, start looking at places that aren't so environmentally impacted, like the Midwest. Uh, and of course, you know, the Midwest has its own issues for why it hasn't, you know, risen up with regard to becoming a, uh, titan of, you know, support for building out these facilities. And, but the reasons are, I I, I to the, and I agree with their report on this is, is because, you know, it's easy.
I, it, it, you know, I have everything I need to run my data center in these areas, so it makes sense for me to do it. It's more work to do it, and obviously a little costlier in the Midwest, but I, I do less damage to the surrounding environments. And, uh, I think you're going to, and it would take regulation to force these companies to start to, or, or incentive.
I mean, the states that one of their, uh, one of the, um, uh, suggestions was the state should be incenting the businesses to come there. And by helping 'em and partnering with them, I think they should. I, I do think it's that, you know, these other areas are being inundated and it's over.
It's starting to overwhelm the environment. Well, Before we go any further though, I just gotta say this, Mike, the New deal called they want their TVA back boomer, I don't know how many people out here actually know the TVA or how big a, a player it is in, in the energy, uh, energy space, you know, creating electricity. But Steven, I thought Ohio was the new data center capital.
What's going on? Hey, I ain't the governor of Ohio. What Do I know?
Lucky For you. No, I, and for us, Yeah, I think I'm gonna miss out on that election too. Um, but I, I would point out that, uh, there's actually a very specific thing happening in Tennessee, and that is that in Memphis, xai is building the world's largest GPU powered supercomputer, the Colossus.
2 million, uh, GPU chips being, you know, that have been deployed in Tennessee. Well, um, publicly, 200,000 of those, or, you know, are, um, part of a single, uh, AI supercomputer run by Xai. And so that is, you know, a significant proportion of that entire footprint.
Now, obviously, there are others as well, and we're seeing build outs and data centers everywhere. But I think that the fact that Xai has, um, focused on Memphis specifically, they've got at least two data center locations there, they have at least two, um, colossal AI supercomputers deployed there. Uh, that alone, that single investment could skew the results and skew the conversation we're having.
You know, maybe apart from that, it's Indiana, Ohio, North Carolina, whatever. It's certainly wouldn't be part of the equation if it hadn't been for XAI. And I should also point out that that's been very controversial because, um, despite the fact that on their own homepage, they have a community and environmental responsibility page, uh, the community seems to disagree with the level of community responsibility and environmental responsibility they've shown there, uh, using, uh, things like portable gas powered turbines to power their data center rather than, you know, because they can't get enough grid power in there, things like that.
And, um, I, I, I would say, you know, there certainly is a conversation to be had, but, um, it's an example of what happens when companies are allowed to essentially shop jurisdictions for these data centers. They can go around and they can say, you know, who wants it? Who wants this kind of investment?
Uh, Memphis raised their hands. And so, you know, here we go, XAI ported in there, and suddenly Tennessee's on the map next time, you know, maybe Des Moines will raise their hands, or, you know, Albuquerque. And then what?
Well, then we'll have somebody else on the map. And, you know, I think it shows, frankly, a, a, a weakness overall of, uh, governmental planning and, um, environmental planning, uh, site planning, power planning, that these things are just being built sort of wherever they can build them, and that, that shifts the landscape so deeply. So is it safe to say we're walking down to Memphis?
Sure. See, I was gonna do a whole oh, brother, where art out, they're building the dam. They're lighting up the whole valley.
It's gonna be a new South, You know, Uhhuh. So, so, so, wait, can we, so there's an economic cost here, right? I mean, if I understand this correctly, the value of the real estate around the data center drops, and then of course, the data center, people buy it even cheaper, and more people are mo gonna move to places where there are not data centers.
So the value of real estate will go up in places where there is no data center, because more people who used to live next to a data center are trying to move in there is this, wouldn't get it. I, I, I don't think that that's really what happens. I think that basically the underprivileged people who live where these things are built can't move and don't have any, uh, you know, real mobility opportunity.
And so they just get stuck with breathing bad air and, uh, listening to loud noise and paying more for electricity. It's the love can now say job, but I mean, but l let's be fair though, you can't blame Memphis. You can't blame Ohio or North Carolina, or, or Abilene, Texas, or any of these places that are, you know, bending over backwards to welcome in these data centers because, you know, they're being, they're being, uh, romanced and corded by millions, tens of millions, if not billions of dollars of investment locally, the promise of major jobs.
Even though we know that these AI data centers are not very labor intensive in terms of job creation, uh, you know, the, the federal government is patting them on the back saying, go for it. Go for it, go for it. And they're in competition.
Memphis doesn't wanna lose to Nashville. Nashville doesn't wanna lose to Charlotte. Charlotte doesn't wanna lose to Raleigh, Texas doesn't wanna lose to California, and none of us wanna lose to Mexico.
And so, you know what, what's the right answer here? I don't know if there's a right answer. I have a question that I would love to get your opinion on.
Um, so right now, AI data, data centers are being called critical national security infrastructure, right? 0, but the Pentagons, a lot of the cloud capabilities you've seen the contracts that, um, Microsoft and AWS have inked with the US government, but you've got, um, military national security running on commercial infrastructure. So they are depending on the same data center, maybe that, you know, is, is is giving me Netflix, right?
But now we have the power consumption concerns. And for years they've talked about fragility of the power infrastructure in the United States. They are projecting that the data centers are really going to overwhelm, um, Northern Virginia, they are saying by 2030, instead of just two or three hours of, uh, power interruptions per year, it could go up to more than 400 hours of power and interruptions per year.
So now, if you loop that back, now, you know, what kind of national security issues are we running up against if we do not have a reliable backbone? I mean, clearly, uh, power is the bottleneck for AI factories. And whether we talk about building thorium, small reactors, or these nuclear reactors that go in like a container or, I, I don't mean a docker container, I mean like a shipping container, um, or, you know, some other, you know, because hope that the, the, the Idiocracy of the whole thing is at the same time we're saying, wait a second, let's stop investing in in solar and, and wind and renewable clean energies, even though they hands down are the biggest driver.
Steven's an expert on this, he could tell us, right? Steven, like 90% of the power coming on was, was coming from renewables. An awful lot of it was, yes, sir, there's a lot of gas turbines, but there ain't no nuclear despite the, the, the, the legend and rumor, there ain't no, uh, new oil and coal and so on.
For the most part, it's, uh, it's been solar and wind, but that's all changing now. And, um, in here, in the United States, at least in other countries, uh, you know, I mean, China has built out, uh, in Mongolia, uh, enough power to basically replace the everything in the United States. And they're using that to power their data centers.
And, uh, along with their industrial expansion, um, it would've been good if the US had, uh, made similar investments. So, Alan, will this become a political issue to the point, whereas Tip O'Neill once pointed out all politics being local, that the people in these local communities are gonna start voting out the quote unquote bums who made these deals, and maybe they're gonna be a little bit of a rebellion in the process. So it already is a political issue right?
Now. Look, my my son recently left Abilene, Texas where he was based for a year and a half. I could tell you it was a tremendous feather in the cap of ABIs or whatever they call people from Abilene, uh, that they were building out these huge data factories, these huge AI factories there.
It may be a case where all of a sudden, oh, they didn't tell me they were putting a coal plant in too, right? And, and that, and, you know, grandpa has black lung now. And, um, you know, then all of a sudden it's a different tune.
But right now, I think cities are vying to, you know, in this lottery of who's going to get these giant mega, uh, factories, AI factories, but that, that may change. But anyway, we, we we're over time already on this one. We've been just pontificating a bit.
Let's come back though. We talk. Let's hear about company.
I always thought as a leader in the AI space, Nokia, you're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT, leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, folks, we're back. And yes, we're talking about Nokia that pledged $4 billion to accelerate AI networking specifically and here in the United States.
And, um, of course, the issue, I think in a lot of people's minds, or maybe most folks don't realize that Nokia owns Bell Labs, which is one of the predominant research facilities here in the us and I think they're trying to maybe make sure that nobody in Washington comes after them for being a, uh, com a company that's fundamentally based over in Scandinavia. Steven, what's your take on what's going on here and will other networking companies kind of step up? Because, well, we haven't heard a lot from networking companies in this whole AI investment space.
Yeah, I think that Nokia is really, um, taking, uh, well, you know, they're kind of stepping outta the shadows here. Uh, they have new management. Um, it's been very aggressive, uh, a new American born CEO who's very interested in putting Nokia on the forefront of networking technology.
And they have done some really remarkable things to, uh, to, to move that forward. Uh, key among those is hiring a bunch of incredible people, as you said, uh, you know, making incredible investments as well, um, but also focusing really on, you know, practical technologies. Uh, you know, they're thing doing things, uh, using things like SR.
Linux, um, their IXR, which we saw at Networking Field, A 39. Uh, all of these things are really key to putting Nokia on the map as generally a networking company, but of course, it's 2025. So if you're a networking company, you know, you're looking at selling into the AI space, and of course that is a very, very tasty market.
Um, you know, you look out at what's happening in the market, there's a lot of OEM stuff using, um, Broadcom especially, uh, silicon. Uh, there's a lot of investment happening from companies like Cisco, uh, like HPE, uh, trying to push into that market as well. Um, obviously, you know, if you're a company like Net Nokia that has really solid, uh, interconnecting technologies, switches and, and so on, you're gonna be looking at that market too.
So I would say, you know, kind of stepping away from the sort of political aspect of making promises to invest in America, I think there's sort of a, a nuts and bolts business aspect that's happening here, and that Nokia is trying to establish itself, it found the right market for its products, and it's stepping up if you do wanna learn more about that. By the way, we did post the, uh, networking field day presentations from Nokia on the Techstrong tv. Uh, you can also find those at the Tech Field Day YouTube channel.
And, uh, to the point of this story, we're actually gonna hear a lot more about this at our AI infrastructure field day coming up where Nokia is gonna be presenting basically the technology that's, uh, underlying this announcement. Jp, are the workloads gonna become more distributed? I kind of feel like when I look at these data centers today for ai, they're kind of like, you know, a replay of these massive mainframes, but are the workloads gonna get more distributed across networks, not only within the data center, but between the data centers?
Uh, I think there's an issue that I, I'm seeing, or, or that I read about as well, that the, that raises question to that, which is, uh, do we want to put the responsibility and, and, and our capabilities in the hands of a few number of companies that are owning all this infrastructure? And right now, in fact, the article I read was about that there is concern and some professors somewhere has come out and stated that this is breaking, uh, anti monopolistic practices and, and laws of the United States For years. Hold on.
Am I, am I in a dystopian time warp? The whole g*****n economy's run by eight or nine companies. Forget just the data centers, that's the, the, the story of our existence right now, 80% of the gain in the s and p 500 is, is on seven companies.
Half of the US GDP growth is on AI stuff. Now you're worried about a concentration in too few hands. Well, maybe I always worry, Don, Don't close the I'm down point.
I found Passion. Something you're passionate about, Al Not your passion. Maybe I think this is A, maybe, maybe a disaster.
Maybe. Maybe the way to resolve that particular issue is to distribute more of the workloads, though other places besides those eight companies, jp, That's not what happens though. People, people don't want to, it's always the same old problem vendor.
Lockin still happens. People, you know, the more that companies do to try to avoid vendor lockin, the more expensive it gets. Um, vendor lockin, you know, that, that, for the, that's the ongoing rage I'm gonna avoid.
I'm gonna go outta my way and cripple and hurt, you know, and cause extra pain to myself, because I don't wanna commit to any one of these vendors because I might wanna move and look, We've All been trained by the mobile companies on this problem. Yeah. A few people in it have suffered small pains of this over years.
But the world as a whole has learned this lesson from the mobile companies, right? Think about how hard it is to change your mobile phone provider, okay? They, they've tried to make it easier, right?
You know, we'll switch your phones, but it's the most painful thing in the world. My phones are different. I have to swap out all my phones because my phones only work on their network.
And, you know, it's painful. And the same thing occurs with these systems, right? And just commit, you know, deal with it, right?
It, it, we now have AI coding throw away what you got rebuild the tomorrow with Claude. So at the risk of sounding jaded, Us jaded, that wasn't jaded. Actually.
No, no, No, no. I'm, I, I, I'm, you know, I'm gonna say something. At the risk of sounding jaded, what's a measly 4 billion bucks today?
Well, two and a half weeks of, of, uh, profit. Yeah. Think, think about it this way.
Um, these things are not, you know, storage and networking, you know, the entire industry. I could fit into a, um, a sidebar or footnote at the, uh, annual reports of these massive AI companies, simply because they're spending so much money, a $4 billion investment, though, I mean, step away from it. I, I'm sorry to do this, but let's have, let's focus back on the topic here, which was Nokia making an investment, right?
Um, a $4 billion investment would be a massive investment for a company of the scale of Nokia. Absolutely. And would really move the needle in terms of the network infrastructure, you know, AI hardware, AI connectivity, AIOps, um, yes, it's not huge in comparison to the amount of money that's being spent on these AI data centers, but it is huge in comparison to the size of the enterprise and HPC networking market.
But another No, You add the value though. Can, can they really do it? I mean, you know, do they have the, uh, you know, the resources and the staff to really make a difference here?
And from a, from a, you know, research perspective? Well, they're, that's what this investment is going for. They're gonna be spending a huge amount of money, uh, trying, but they're Not only spending, they are going to get, uh, federal broadband subsidies, right?
So there is $42 billion in federal broadband subsidies available. It's called the, uh, the bead program, broadband equity access and deployment, right? Nokia, they, I think it was last year, they became the first technology vendor to self-certify that all of their fiber products are built in America.
Um, what is it called? BABI, BABA compliant makes me think of compliant, right? And they, right now, um, may be the only one.
So if anybody is looking at complying with that and getting part of that $42 billion pot, which I'm sure Nokia has a great head start on, they're probably gonna go to Nokia because Nokia is already certified. And that is a very good point. I think that hope is really the crux of what Nokia is promising here.
They're saying we are the American supplier, which is ironic considering that they, you know, were a European country or company, but now they're, they're saying like, look, we are the bi American, uh, supplier, and that could move the needle. Good For them. Just wanna, that's like going IKEA for the 4th of July, is that what you're saying?
Yes. That's very American. Now, you know, I love Ikea.
I love the meatball. Well, good for Nokia though, guys. I hate to do this here, but we're about outta time for today's episode.
I wish we could go on more about it, uh, just having some fun. But we'll be back tomorrow and we could talk about it some more, talk about stuff some more. But for now, hope, jp, Steven, Mike, thanks for joining us.
Thank you for joining us. We hope you enjoyed this. Um, as usual, we have a full tech, strong TV lineup immediately following the gang today with some great stuff, I think, including some of our most recent CubeCon coverage.
And I think we might, well, Stephen, any the short week I know, but not much Tech Field Day on this week. Well, we don't have, um, new Tech Field day presentations, but of course, we've got the brand new, uh, security Boulevard podcast and the new utilizing AI podcast both this week on, uh, tech Strong AI and Security Boulevard. Excellent.
So stay tuned for that. And you can get those podcasts, by the way, on whatever your favorite podcast platform of choice is. But, and In America, it's Thanksgiving this week, Thursday is Thanksgiving, but we'll be here, we'll be here, uh, tomorrow.
Hey, I wanna, I wanna point out that Techstrong Gang and Techstrong TV is made in America. You're willing to certify that. How do I know where Steven is today?
Today, I Literally, I let fell off my chair. Hope. Is there Anything, I'm actually coming to you from my, my secret layer beneath a volcano in St.
Lucia. So you can do whatever you want, but hope is does that, can we qualify for any kind of government billion dollar handouts for that? You Know what?
I, I, I bet there is some way to work that out. I tell you. Let's, let's, let's ask Claude.
All righty, Let's go back to the beginning, to the AI story. I think, look, we've descended. We're gonna pull the plug right here.
Everyone, have a great day. We'll see you tomorrow. This Alan Shimel.
We're out. Hey, everyone, welcome back here to our day two coverage, my wrap up of, uh, day two here on Techstrong tv. You think it's a wrap up?
You see this guy sitting next to me, you're saying, oh, Shimmy's doing Techstrong gang. But no, you come to an event like this, you never know who you're gonna meet. I look up from my chair where I've been bolted in all day, and who's walking over here, but none other than my friend Sanjeev Sharmer, of course, if you guys follow Text Drunk Gang, you know, Sanji is a, a gang member, frequent guest.
But I, I'll tell you the truth, you know, I, I started Techstrong in 20 13, 20 14. com, and, you know, one of the first people who contributed and, and was part of it was this gentleman right here at the time, Sanjeev was the, uh, field CTO of DevOps worldwide for IBM. And, and we struck up a relationship.
I, we, as we did the, uh, I think we were called not DevOps days, Jenkins Days Cloud these days. And we had DevOps connect Yep. With the different in-person events we were doing.
Sanjeev was always there to do a keynote for us, give us the latest research and findings and feelings of IBM on it. Like, all good things that came to an end. Sanjeev moved on from IBI feel like we're doing, this is your life.
I know Shava, I know. Seriously. Sanjeev moved off from IBM and he went to work at, uh, truist.
No, before that I went to Delphix. I, that's right. He went to work at Delphix.
Yeah. A, a, a DevOps startup, and did some amazing things there as part of the executive team. Then went to Truist where, and Iist did the merger, The merger and integration of two large banks.
Then went on to Dell, where you have a senior position in the cloud. Well, I was the senior vice president of platform engineering for Platform, had the developer platform for all, you know, 15,000 plus developers at Dell. Absolutely.
And, and then recently, I, you know, I thought Sanjeev retired to be a, a venture capitalist. No, he didn't. I knew he wasn't being a venture capitalist, but he's been on, uh, on Textron gang with us, and always happy to give his opinion on the state of tech, but lo and behold, he's here because he's got another job.
He's got a new gig. We're happy for him and happy to hear about it. So you don't have to introduce yourself.
I introduce You. I know. Crazy, man.
I mean, listen, we've known each other for a long time. Yep. Doing, we've been watching this industry evolve for a long time.
So it was time for me to go be a part of a fast-paced AI startup, which is focused on solving the problem we've actually been trying to solve for over a decade. So that's where, that's how I ended up at Stack Gen. I, my, my official title is VP of Platform and Customer Success, you know, beautiful.
Uh, I own the, you know, I, I'm responsible essentially as, you know, acting field, CTO kind of role. Okay. Uh, working with customers, which is what I love to do.
Absolutely. com started, a couple of articles I wrote were about the impotence mismatch, the speed mismatch Yes. Between developer velocity and infrastructure, or Yes.
Platform velocity. Today, a decade later, it has not been solved still, right? Yeah.
I think we had reached an equilibrium where developers were somewhat happy with infrastructure speed and infrastructure was somewhat happy with, you know, all the pressure from development. But then Gen AI happened, and now what are we seeing? Developer velocity is accelerating even faster and not it's time for platform to keep up.
And that's what Stack Gen is solving. We are solving that platform velocity issue by, you know, if AI writes your code, AI should run your platform, is our thesis. Yeah.
And we have, uh, agents which can maintain and manage and govern your platform for you. And I'm like, man, this is the place for me. This was like designed for me.
So here I am. It really Is good for you. I'm really happy for you too.
Thank you. Thank you. A, You know, taking a page outta my own VC book, I was never a VC either, but I, I've been around enough VCs and I did stay in a number of Holiday Inn expresses.
One of the things VCs look for when they go make an investment is team, what's the team done? Is this a team that's going to execute? Is this a team that could get us where we want it to be?
And I think that's one of the strongest parts of the Stack Gen story, right? You're joining a team here, the CEO, I think it's his sixth or seventh startup. I know I followed him on the last three or four.
Um, and it's not just him, the, the core group, CTOs, VP engineering, sales, been there, done that, been there, done that. Because you know what, you've worked at the biggest companies, Dell and IBM and big banks, worldwide banks, you've worked at startups, but this is a startup juggernaut, right? Their, their, their MO is, they come in and within 3, 4, 5 years at most, but three or four years, they've got people knocking on their door to buy the business.
Yeah. I mean, we, uh, as far as customers are concerned, we already have customers knocking on our door. Yes.
Right. And you know, the rest will follow. Absolutely.
And they know the day. Our goal is, are we, the question to ask is, are we solving the customer's problems? Yeah.
Right. And you know, I've, I've actually known the company for, for some time now. I've been following them other than I've known Sachin for the founder for several years.
Yep. But what I wanted to see was, is it a product still trying to figure out where is place in the market, right. So no market fit.
Exactly. Uh, or is it a product where the customers are coming to us and saying, these are my problems and your, your product can, can solve it. And, uh, we are, we are doing that.
It's an early stage startup, so we've got a long way to go. The product still has to develop and evolve, but we have, uh, you know, marquee brand name, you know, fortune 500 type customers. Yes.
Uh, who are already using the product. And, uh, one of my roles as you know, VP of customer success is to be that bridge between what customers are seeing, how customers want to use the product, and then back with product management and engineering to make sure our roadmap aligns with what's happening in the market. So it's very much a two-way, It's definitely a two-way, two-way street.
That's how I've always seen a field CTO slash customer success team. It's not like, you know, take a square peg and put it in the customer's round hole. Right.
It is like, figure out what kind of hole And then go back The feed of the customer is what's missing, missing in the customer. Right. Right.
And then figure out what out of those can be used in the broader market. Right. Because there'll be customers who come with very unique and novel needs, which only fit them for the right customer corner cases.
Exactly. There'll be edge cases always. Uh, obviously we want to serve a large set of customers.
So that was one of the hardest lessons I had to learn in startups in my startup career, is that you can't build for edge cases. Yeah. You gotta build for the market, not the edge.
And I don't mean the edge, like Yeah. Oh, that edge. Yeah.
He like, he liked that edge. Yeah. But, um, and then I made that mistake.
You know, I'm watching Mitch, Ashley's out in front of us there. Mitch and I built a platform. We, we took our vulnerability management tool and turned it on its head for a company for a very unique case work, you know, case.
And we spent an, like, two whole product cycles. This is when we used to do, you know, a product cycle every six months. So we spent almost a year, and we finally made that product exactly what this edge case needed.
That company's name was Lehman Brothers. And at the year, at the year, I think was 2007, and they went out of business, took us a year to, to, took us a year to build the product for them, for their Lehman Live portal. I'll never forget this.
And then before we could collect the money. Wait, isn't Leman live where you go find out what the prices of the CDOs are? Yeah, Exactly.
Yeah, I know what that is. Uh, uh, classic story. Classic.
But, but seriously, that's where I learned that you can't, you can't build for the edge cases. You've gotta build for the meat of the market. Yeah.
And, And it requires somebody, somebody, people who have experience in the market Yeah. Actually look at an edge case and say, are they just ahead of the curve and everybody else will come here? Or are they truly an outlier?
Right. I, and there's a judgment call there, because you might, you, you might not know, but this, They might, this is why I say team is important. Absolutely.
One person cannot know everything. Absolute. The team is important.
And we as a team then need to decide, okay. Really analyze and say, step back and say, okay, let's double click on this. Are others going to do the same thing?
And you can query other customers. Customers want to help you also, you know, one of the things I've found out having worked for large vendors, right? I've always been, except for my Truist and Dell days, I've always been in client facing roles, even at IBM.
Right. The customers also want the startup to succeed, right? Yeah.
When I was at Dell or at Truist, and we would acquire a product from a startup, we wanted them to succeed. We were betting on because their success. Success.
Exactly. Nobody wanted to buy a product and then the company is gone. Yeah.
Right. Uh, you know, like, uh, we, we, you know, and, and, and no companies don't survive. And then what do you do?
Yeah. And that happens. We can't control that.
But, uh, it's always a partnership. And I think that is a, that needs to be fostered properly. And that's why, you know, uh, the team, uh, wanted to bring somebody like Neon who has actually done that, who's got the battle scars to say, Hey, I ran, I run platform engineering teams both in a regulated environment, in a highly scaled, global environment that, uh, that brings that experience.
And, uh, hopefully I can help, uh, truly add value as we go forward. I love it. Sanjeev, we gotta wrap up here.
Absolutely. I want to congratulate you and wish you thank you and wish you a lot of success with Stack Gen. As I said, I, I've, I've followed this company since before they announced, came out of stealth as well.
And I, and you know, I think that there's a high probability of success there, and I think you improved that probability, and I'm sure this won't be the last time we have you on talk. Absolutely not. You're not kicking me out of the gang.
No. Well, I got ideas. We're thinking about getting gang jackets, motorcycles, jackets with.
I like that. I like that. Maybe we should, we should make a album like a rock album cover or something.
Get together. Something. No, I was like a TV show, like Sons of Anarchy or something.
Nice. I love it. That's What we need.
Yeah. Sanjeev, thank you. Sanjeev Farmer Stack Gen here on Tech Drunk tv.
Hey, that's gonna wrap up day two. We'll be back tomorrow though. We've got a, well, it's not a full day.
I think things ended two here tomorrow, but we'll be back in the morning giving it to you live, and we'll be doing wrap ups. Count on us for your cube con information. But for now, this is Alan Shimel.
Thanks for watching. We're out. Hey guys, thanks.
The throw, we're here with Y and Hal Chow, who's the CEO for Testrite, and we're having to chat about how AI may be finally breaking up some of those DevOps bottlenecks that have been plaguing us all these years. Y and Hal, welcome to the show. Thank you, Mike.
Yeah, nice to meet you. Yeah. So walk us through your thinking here.
I mean, we all know that AI agents are coming, or in some places they've already arrived, but we have all these bottlenecks and DevOps that we've been struggling with for all these years. Can we finally break them using AI agents? Uh, yes, for sure.
Um, so, but I, I will say it's still kinda like a progress, um, at this moment. So, and everything actually is, is changing so rapidly in the past couple years, as we know. Um, agents like Cursor coding, agent like Cursor, GitHub, copilot, uh, tray, and all those, uh, coding ai help developers actually write code very fast, and they can sometimes write thousands lines of code within just, um, minutes.
Uh, but this also create actually new problems. Sometimes we'll find bugs or flying everywhere. Sometimes we'll also find ai, probably just writing too fast so that you cannot really keep this pace with it.
Review all those content manually by yourself. Uh, when it generate tens of thousand lines of code, million lines of code, it's almost impossible to automat to review by human beings. That's new.
Kinda like a bottlenecks, or what do we call new issues or problems raised by those new agents. And test Bri actually was created to solve those new bottlenecks and to make programming smooth or easy again, for developers, uh, we are trying to use our agent, uh, AI testing AI to help to automatically validate software or code autogenerated by those AI coding agent like Cursor or GitHub copilots. We can be directly installed into programmer's, IDE, so they can install our MCP directly into their IDE with just one click within minutes.
And then they can just use natural language prompts in their cursor chat bot or maybe AI coding IDs, check bot to run test Bryan, and something like, Hey, can you test this software or project using test Bryan MCP? And then it's all done. So our AI will automatically run all those steps, including analyzing their code base and learn from their software, read their existing, um, product requirement documentation, generate a test plan, generate test the code, run test cases, do test result analysis, and share the final results with customers.
So all these, So, so I, so I get that we have new bottlenecks that are emerging in the age of ai. I guess, you know what I was curious about? And can we use AI to replace or fix the legacy bottlenecks that we've been struggling with?
Or are we just gonna start piling more code through those bottlenecks and essentially hit the wall faster? Got it. Got it.
So, um, it's actually, um, so I will say it's actually a interesting progress that AI agents is like, actually lots of AI agents is actually already fixing legacy bottlenecks in the past, I believe, five years, especially for programmers. I, I used to work in Amazon for more than five years. The biggest bottleneck when I was a programmer probably is the coding efficiency like this, how whether we can write code that fast, whether we can actually ship things, um, way faster.
And meanwhile keeping the quality, because purposely, if it's a human being, you can probably only write 200 lines of code, 300 lines of code in a day. So at that time, the main bottleneck is how fast you can understand a problem, how fast you can propose a solution, implement it, how fast you can end to end test it, make sure it's really good running successfully, and then deliver it. So at that time, everything's probably about speed.
And, and right now I think, yes, existing agents and, and all those, um, like AI data solved that problem. The pace is great. Everything was solved within minutes.
They can generate hundred thousands of lines, like we mentioned before, within just 10 minutes. So speed is really fast today. This bottleneck in the past of three, five years is successfully solved by agent.
But meanwhile, when they're solving ex legacy problem or bottlenecks, they're creating new ones. For example, uh, the code quality, for example, those hallucinations introduced by found foundational models, because I, I know open AI cloud code, they are doing fantastic jobs. They're releasing like models almost every year, GPT-4, GPT five, cloud three, cloud four.
But, uh, those models do, are actually making some hallucination issues or arrows. Uh, if you look at their performance on SWE benchmark, you will notice that their accuracy is only about 60%, which meaning that 40%, they make mistakes. Uh, and that is already the state of art perf like, like the best model among all those existing AI models.
So 40% basically, meaning usually if you have like, um, 10 features that you want AI to implement, probably six got successfully implemented, but a four maybe partially still have some issues or didn't fully meet your requirements. And that is the new bottleneck created by these agents. So especially for startup like us, what do we do or what do we focus do is solving the new bottlenecks probably doesn't exist before five years ago.
So this is actually a quite interesting change which is happening in the industry. You know, a certain perspective, it seems like the bottlenecks are just shifting and we can write code faster, but the problem is if I get to the back end of the workflow and then a lot of that code gets rejected because it's too verbose, there's too many vulnerabilities, and the overall amount of technical debt starts to increase, doesn't that defeat the purpose of kinda having these AI coding tools in the first place? Because now I got all this code that I'm just sending back to have redone anyway, probably by human.
You are right, you are right. Um, be, this is actually what's happening right now in the industry. Um, because we work with, um, almost 50,000, uh, enterprise customers in the past one year, and we observe that lots of things are happening to them, uh, especially when they're adopting the, these kind of like AI coding agent.
At first, they were surprised by their speed. Uh, they found that one ai to some degree, their speed can replace maybe 10 engineers when it's generating code. So they were, they were surprised.
They would say, wow, it changed everything. So they purchased lots of AI tools. They start to use all those tools, uh, to write a code, and programmers actually have more time to, to drink coffee or, you know, just, uh, free their hands, but probably focus on designing, uh, customer facing problems, which is good.
But later they find out, seems like they cannot fully count on ai. I'm not saying AI is not good, so that we, we, we cannot use it at all, just the degree, the balance. So you can for sure let cursor, let GitHub co-pilot and all these tools or cloud code to help you to create the first draft version.
But that version definitely cannot be directly released to a customer if it's enterprise level feature or enterprise level software. Because as you can see, 40% chances they will, they will probably create some hidden issues, unseen bugs or hallucinations somewhere. So right now, existing programmers job is on how to identify those issues, how to manually fix those issues.
So I would say statist, uh, speaking, their job efficiency right now indeed got increased. So whatever takes them, like for example, a week before to ship to finish today with the help of cursor, GitHub, copilot, all these popular coding tools, they probably would get it done for two, three days. So half of their time and half of their efforts probably is already saved today, although they're still fighting with those ai solving those hallucination issues, solving those bugs.
But indeed, it saved them some time. Uh, due to the efficiency of the ai, our tool is basically helping them to say, can we save them some extra time? Help them to even be better to faster ship the confident, ship the software with more confidence, make it even like what used to take seven days, five years ago, and right now only take half a day so that they can be even 10 times faster with the same quality than before.
Yeah, that's kinda like, um, what I'm trying to, to share. Yeah. So yes, basically, uh, in short we can say, um, AI is indeed helping people already.
If you look at how much time, how much effort, how easy it is right now compared with five years ago, but just like it's still not perfect, uh, still not probably what people thought, uh, it is today. Yeah. So I understand that we can clearly write more code in a day than we did before.
And, um, but we have to be smart about this, I think, because I cannot ask the AI that created the code to review that code, and I need a different model to kinda look at that, and then I need some sort of ability to reason across it and judge it. But so do we need an an an entirely new way of thinking about our DevOps workflows because there's gonna be multiple AI agents that need to play off each other? Yes.
This is actually, uh, uh, this is actually something I really want to share. Yes, we are actually, uh, sharing with actually developers worldwide, lots of startups, enterprises that the DevOps and also the whole development happen is probably changing today. So especially on the testing side, we are encouraging something called left shifting, left shifting, uh, if we wanted to easily understand it, I probably wanted to share something about my background when I was working at Amazon, uh, five years ago.
Even those big tech companies, the typical, um, DevOps kinda like, uh, cycle is you write the code first and as the programmer, you do some unit test to make sure that you don't make mistakes among the code. So all the logic is fine, and then you create a new PR code review, submit to your team to do some code review so that other team members help you to quickly review it, making sure that your design, your logic, your implementation on the human review also makes sense and doesn't make too many obvious mistakes. And then you merge the code to, um, your dev endpoint, to your, uh, kinda like beta endpoint, and then let the QA team, the testing team to do some manual testing.
They'll play with the feature mouse clicking around record the whole scenario and trying to tell you whether this code under the more kinda like production endpoint is working correctly or not. So they will let basically bunch of manual resources to use your feature, um, mimic the customer's real behavior, trying to tell whether everything's all fine. This is what we call integration testing or end-to-end testing.
And that including sometimes ui, front-end UI testing, sometimes backend, API testing and all these kind of testing. So we do have different kinds of testing even when we talk about software testing. And today, when we talk about left shifting, actually this is even, um, uh, recommending from injury, uh, from deep learning, uh, deep mind and left shifting, basically meaning we don't have to wait for the development to be fully finished and then do testing.
We can even do testing while we are doing development. And to some degree we can even do test driven development, basically, meaning you can first design those test cases ahead. Uh, something like if I want to create a feature a, then basically I need to have these five test cases for feature A.
And if the AI correctly implemented the feature a meaning the AI has to at least pass all those test cases, otherwise it doesn't mean it successfully did the job or finished my requirement. So basically they have a high level design doc, and then they immediately design some testing associated with those features, and then they do implementation. The implementation will be fully finished or marketed as finished only when all those tested cases are green or passed.
So that at that time, human beings and also ais both have confidence, I did great job, this software at least satisfy all these requirements and it can be probably moved to the next stage or maybe for beta users to give a try or something like that. Yeah. So this is what we call after shifting do testing earlier that, for example, when you generate the sum code using Cursor, using GitHub copilot, you can already give it a test wrong to see because we know they are making mistakes somewhere, we just don't know where.
So we can make a testing wrong or execution at that time. And when we notice, okay, so it, so 70% are right, but here, there this place we have some issues and then we let a cursor iterate again, fix all those issue, and then we run test again, and then we find remaining issues and that keep in the loop until everything is great. This is exactly what test bride MCP is doing right now.
So we don't engage like traditional QA tools at the end of the day when everything from the developer side is finished, because that basically meaning developer has already fixed all those, um, cursor issues. Uh, they manually spotted them and fixed already using prompts, but we wanted to engage earlier when they're coding. So every time when they use Cursor to generate something, they can immediately run test Bri to spot or to validate whether there are issues and they can keep running it, keep those two AI agents working together onto all test green and then maybe create a PR for other team team members to review or maybe deploy it to their dev end point, uh, for some beta users or internal members to give a try.
Things like that. I feel like though there's something wrong with our little human condition in all of this, and people will see that they can write more code and then they'll just continue to write more code and they won't think about spending more of the time they freed up on testing and improving the quality of that code. Yeah.
Yeah. So, uh, if it's, uh, actually a junior level of engineer, or sometimes if, if you, if your first time using, uh, tools, uh, you will, you'll feel that way for sure. Uh, but with your software become more complex, with more of your customer complaining, Hey, I have this issue.
Oh, I encountered that issue, they will immediately realize that the quality of the software is not enterprise level and they cannot afford to maintain that kind of software to their customers because they will, they will lose customer. Interesting thing is today with the rising of tools like Cursor, GitHub, copay, and all these coding agents, the barrier to to, to create, uh, software is very low. So almost everybody, when they have an idea, uh, this is why we call it a vibe code.
So when you have a vibe, when you have an idea, you can already create something, um, by yourself or with a very LinkedIn small team. So the resources needed to create a software is is not that big, big or huge. Everybody can almost create a software when they have, uh, I idea that means people with same idea probably a lot, and there are probably a lot of similar products in the market because you, you, there are definitely lots of people with similar idea, like you, they'll also create a software, they will also release it.
These, all these changes also lead to the fierce competition. Right now in the AI sector, lots of, um, industries, lots of, um, like different attracts, we can all see d similar products right now in the market because of, because creating a software is so easy today. So the main, I would say the main factor for you to win a competition among your competitors is naturally right now becoming whose quality is better, whose AI is more accurate, whose software is more user friendly, who whose AI is faster and, and more, maybe more affordable.
So everything is about the, the, the software is user experience and quality. If you can become the best software among your competitor, you naturally just wing it because idea, vibe is cheap right now. So every, everybody with an idea can, can somehow generate something.
So people will immediately realize that. And what we can see is people already realizing that and they're trying to pay more attention as well as money, uh, into the software testing world. Uh, this is more driven by their revenue, I think by the competition, by their customer's, feedback by the market is, um, current situation.
So I believe in the future, people will just pay more attention, more and more attention in the future due to the natural. Um, uh, I, I would say the, the competition, uh, in the market so different, it doesn't matter what what the industry is, doesn't matter what things they're building, as long as they want to win the competition in the future, they definitely want to focus on quality. And, and, and, and right now, the only way to do that for sure is, um, is do more testing, making sure your, your, your software is robust and, and your platform is stable, reliable, under all kinds of conditions for any of your customers.
Yeah, Folks, you heard it here, the choice is clear. We can either write more bad software faster or we can take some time and focus on writing better quality software that people actually use and enjoy. Hey, YHA, thanks being on the show.
Thank you so much, Mike. Alright, and back to you guys in the studio. Hey everyone, welcome back here to Techstrong tv.
I'm happy to introduce you to my next guest. It's his first time on, so let's uh, hear what he has to say. His name is Philip Peku.
Uh, Philip Phil. Phil. We're gonna call him Phil.
Phil is the global practice head of developer experience at a company called Valis, and he's gonna tell us all about that as well. But first, let's welcome Phil to the show. Phil, nice to have you on here.
Thanks so much. Thanks for having me, Alan. Appreciate it.
So Phil, you know, we're gonna talk about ti we're gonna talk about Fest and break, but before we do that, let's let's hear Phil's story a little bit. Sure. My name's Phil Haku.
Uh, I, uh, I went to school for mechanical engineering and then I spent 10 years in robotics. So I tinkered with, uh, all kinds of tools to avoid talking to other people. After that, I moved into software engineering and then realized that helping people is actually a lot more interesting.
Um, after that kind of progressed over to kind of more of an agile role, uh, worked through the Atlassian ecosystem first on the product side, then onto the consulting side. I've been there for the last couple of years. So that's been kind of the short version of my history.
Very cool, very cool. Um, and Phil, you know, I, I'm, I'm, I think I'm speaking, I'm, I'm not gonna say anything you don't necessarily don't know, but a lot of folks in our audience may not be familiar with Valis. How, how would you describe that to 'em?
So, I think Valis is a, um, I think we've, we've long been a big fish in a small pond, so we are one of the platinum solution partners in the Atlassian space. Mm-hmm. Uh, we span the globe, but obviously once you look at it from a global perspective, we're, we're really more of a boutique consulting firm in that sense.
So we focus a lot on the tooling and process around the Atlassian stack. So a lot of it is software development. Uh, a lot of it is, um, service management now, obviously over the last couple of years.
So we do a lot of work in that particular space. Uh, outside of that, you know, you can think of us as a value added reseller or GSI, maybe not so much G as si, right? So we're a services integrator, value added reseller via Atlassian stack.
And then everything from a process perspective that comes around that, I think of it as like layers of the onion starts with the Atlassian tools. What do you wanna do with it? Setting it up, and then obviously optimizing and going fast with them.
Excellent, excellent. You know, uh, I'm trying to think. I think, uh, some of us were, not me personally, but some of my crew are over in Barcelona just a few weeks ago for the Atlassian, uh, user conference there.
Lot going. I was there. You were also there.
Yeah. We could've done this in person with you there. Uh, next time, Absolutely.
Make sure we're gonna hold you to that Phil, though, I don't know where the next one is off the top of my head right now, but they, they usually reach out and we send, uh, a crew over and some of our writers and content folks. Um, so, you know, the Atlassian channel, of course is one of the great success stories, I think of the, in the DevOps and space. And I mean, it, it's, it's almost legendary, if you will, right?
When you, I mean, you know, you look at Atlassian versus let's say, uh, like A-W-S-A-W-S is a hyperscaler, it's an 8,000 pound gorilla. But from a channel point of view, Atlassian from, from day one has always done a great job of integrating their partners and allowing their partners to have some meat on the bone, if you know what I mean. Do, right?
There's, there, there's things that you need an Atlassian partner to do it, Atlassian themselves doesn't do it. And so it, it, it's a great thing. Um, Phil, before we jump into our topic of discussion, maybe people who want to get more information on valis and how to, you know, how to engage, what, what would you suggest?
I think there's, there's probably two common channels that people can reach out to us. com. Um, there's a good amount of content and there's a contact form there, obviously.
Um, if people want to dive into any of the conversations that we bring up today, um, I'm pretty active on LinkedIn, so if they can figure out how to spell my last name, I'm probably the only one that has it that way. So they could always reach out that way and have a slightly more informal conversation if that's what they wanna do. Absolutely.
And, and Phil, you don't know this while we're recording it, but in the finished version, actually, your name and ti and your title will be, uh, underneath the, on the lower third of the video. So people, you can see it right there. It's H-E-I-J-K-O-O-P.
The I and the J make the y, so it's Hey, Kup. That's right. But, uh, people will see it there, Phil, if it's all right.
Let's transition now into what our topic of discussion here is. You know, uh, a mantra in Silicon Valley for a very long time has been move fast and break things. But, you know, it's not, it's not that we're bulls in China shops or something like that.
The idea is that we know in moving fast things that aren't enterprise ready, things that aren't scalable are gonna break. And if they're gonna break, let's find out that they break and, and fix 'em and make them more scalable and more resilient and, and not breakable. Right?
It, so the idea is, you know, kind of go fast as you can and, and we just keep rebuilding stuff this way and rebuilding. It's kind of, it's part of that DevOps agile culture, I think, too, which is iterate and reiterate feedback, loop iterate, feedback, feedback, iterate. Yep.
That's true. I, yep. So, but now, you know, look, AI has changed a lot of things, obviously.
Has it changed the move fast and break things mantra? I, at least at the enterprise level, I, it may have helped it. I think it was already changing.
I think there's two parts to consider. There's the, the learn fast aspect, which was the original, uh, impetus to moving, uh, move quickly, break things right as you want to fail quickly, learn what didn't work as part of that, that kind of feedback loop. Um, I think that is probably more the case now than it was before, right?
We wanna learn quickly, market test, get it validated and all that stuff. What I think has, um, often been overlooked and it's easier to overlook and get away with when you're a smaller company, is not regressing to a point where things become unusable, right? So a good example would be AWS's recent outage from a couple weeks ago.
Like, you don't want to get to a point where you are effectively publicly embarrassed for a little while because you've moved fast and broke something. And so I think there's a balance that needs to be found when it comes to trying new things. You can absolutely still get away with going quickly, trying new things, seeing if it works and pulling back.
But your core value prop should always still be accessible. And I think that that's where a lot of the, um, the literalism sometimes bites it when it comes to this particular philosophy. It's a move fast, try new things, absolutely.
But don't break the old things like, don't break what got us here. Don't break the core platform and above all else, don't break customer trust. Because I think when it comes to moving fast and trying new things, if the functionality that you said, and it's got a big banner that says this functionality's in beta, people have their expectations managed.
If people can't reach their bank accounts because you're trying something new, you have a whole different level of problem. And so I think that that's where enterprise in particular, have to have a different trade off because their core value proposition, the legacy frameworks and everything they like that is effectively a commitment to their customers that that will be available and they'll get better at it, but they cannot, like, their floor of behavior and delivery has to be maintained at all costs. And you could think about it in the DevOps and agile space as like, you need to have regression testing and everything else in place place because you can never get worse as you try new things.
And I think that that's the philosophy that needs to find a balance with, with customers. Fair, fair enough. Um, so how, how's this kinda manifesting itself, like at your, at the Valley Valley Anis level where, you know, how are you seeing this kind of play out?
I think there's, there's two main things we see a lot. A lot of people want the shiny new toy. Uh, they wanna vibe code their way to new functionality.
They wanna get through their backlog, they want to try all the cool new things. They also have to add AI on top of and into their tool. Um, a lot of people are still bolting it on as opposed to making a core value prop.
Um, and so there's a lot of demand for help us do these things, help us accelerate what we're doing. And we're seeing that in most places. They don't have the foundation in place to go faster because they're just not doing the basics right.
Um, I, I think I've turned into a bit of a curmudgeon at this point, but if you don't have a lot of the basics, right, in terms of having security in place and you have QA systems and you're monitoring everything, like none of the AI tools are really gonna be helping you because you're just building a taller tower that is going to fall over. Um, the other side, would The James Good game, right? Oh, absolutely.
There's just a lot more holes than I think people are cognizant of because they just mm-hmm. Again, not a lot of tools, also not a lot of monitoring, so you don't even know how bad things are sometimes. Um, the other side that we see a lot of this coming in is obviously just we are being mandated to do this stuff.
So it's a less of a, I want, and it's a lot of it I must, and then we're trying to figure out how can they balance this out? Because in most cases, there's the technical, tactical implementation that people are, are stuck with. You must start using ai.
You need, you need to increase your throughput, your volume, et cetera, et cetera. But it doesn't always correlate correctly to business value. So in most cases, we're trying to help them understand that bridge before they do anything.
Like, if I'm gonna do this, it's gonna generate 10,000 lines of code, potentially. Why? What is the business value?
What is the purpose is? And that helps them make better decisions ahead of time, because you want to actually go in and still have that experimentation mindset, but have a bit of a credible hypothesis in terms of like, well, if I do this, these are the trade-offs that I'm explicitly making. There might be a couple I'm not aware of, that's okay, but it is all in service to this end.
And if I can't make that chain of thought, I'm just experimenting for the sake of experimenting, that's also great. But that's what sandboxes are for, right? Like, if you're doing this in production, you have to have that credibility towards a, I'm doing this in the service of this business value that I want to achieve over here.
Excellent. Very cool. Um, you know, Phil, I, I, this isn't, is this an enterprise specific thing you think?
Or does it apply to SMEs as well? I think it applies to both in different ways, though. Um, one of the things that you see just company dynamics are different at different sizes.
Um, there's a lot of uncertainty, frankly, in, in enterprise, especially with that layer of middle management where they're starting to look at the Salesforce and AWS and, and meta layers in terms of like basically shoving out whole layers of management because they don't think they need them anymore. Um, and you can see people saying, like, looking at that anxiously and saying, is that the future? Do I need to prepare for that?
Um, SMBs don't really have that problem in the same way. They have a slightly tighter line of sight between leadership decisions, obviously in the tactical, uh, individual contributors. Um, but a lot of this is still a question of if we can't, like, of that uncertainty from a do this to get to this business value, I think is the core of, of what this goes on.
And it just becomes more complex at enterprise levels because there's a lot more dependencies between software systems. You have to collaborate between more different teams. You have a lot more legacy, um, not just code, but also commitments to customers and services that need to be maintained.
So it just becomes a slightly more complex version of the same challenge. Agreed. Agreed.
I I, I don't disagree there at all. Um, let, let's look specifically with ai, Phil ai, sure. Right?
Does this Take it away with it these days, right? Don't even get me started. Um, but, but, but seriously, you know, and, and, and I'm talking specifically like with digital twinning and the ability to do this sort of in a, in an AI environment, if you will.
Does it give us a way out here, like having our cake and eating it too? We can build systems that last by going fast and breaking things, but in a virtual environment with AI simulation or what have you. And, you know, I think it is very Likely.
And this on a cheery note. Yeah, yeah, yeah. No, I, I would say yes, that is the very likely end state.
I don't think most companies are there yet, uh, oh, no. From a process perspective, but I think that that is absolutely the, the next step. We, we've seen a lot of conversations in AI around that early build plan, like make the thing, a lot of the conversations, I think have started to move towards the next stage of that, like the traditional waterfall element, right?
Like, you need to check your requirements, you need to make security, uh, priority, you need to make sure QA works and everything else in production obviously is stable. Um, I think it's inevitable that you get to that particular stage. I think that you can absolutely go faster and prototype things.
I think the table stakes, obviously, that have been pretty high before are obviously just gonna get higher when it comes to enterprise software, which will be great because users want better user experience and user interface and things like that. I think, however, and this is a challenge we've seen a lot, this only works when you're doing it with people who understand both the problem domain and the craft that they're working on, right? Uh, we see this in every element.
If you don't understand the question that you're asking from ai, you cannot correct it as well as you can. That's one of the challenges I see in vibe coding is senior engineers experience people getting tremendous value out of it. Juniors aren't because they don't have the experience.
And that kind of understanding intuitively of like, oh, I skipped a step here. And that's where the veneer is, is often the challenge, right? Like, you'll get the working piece of software, but a working piece of software on my computer is not the same as an enterprise level working grade of software.
So once we have the rest of the process infrastructure and guardrails in place, I think we absolutely get there, but I don't think we're quite there yet. That's, that's basically what we do day in, day out, is help build that particular state that we're working towards. Agreed.
I love it. Phil. We're about added time.
com. Check it out. Phil, thanks for coming up on here.
I appreciate it. Um, I, I, thanks for having me. You could reach, thank you.
com website. But, um, look, you know what, sometimes you can't teach old dogs new tricks and maybe, maybe, uh, we are moving past move fast and break things to build systems that last you're watching text on tv. We'll be back in a moment.
Hey folks, we're at Atlassian Europe and we're talking with Tiffany Tow, who's executive vice president for platforms and Enterprise, and we're having a little chat about cloud and ai. Tiffany, welcome to show. Thanks so much for having me, Mike.
My pleasure. Um, you guys have announced that you're gonna end the life Atlassian data center, which probably doesn't come as much as a surprise to folks because you've been pushing folks towards the cloud for a while. But, um, why now?
What's the transition that you're trying to achieve and well, how far are people making that migration anyway? 'cause you've been at it for a few years. Great question, Mike.
And you're exactly right. It did not come as a surprise to any of our customers. We've been investing so much in our cloud platform the last seven years.
Um, and as folks hopefully saw in the keynote so many new things in terms of AI and all the collections and the system of work deliver all this new business value for customers. Um, but why now? A big part of it is, as we talk to our customers, many of them have been migrating to cloud.
Uh, 99% of our customers have some bit of footprint already in cloud. But what we hear from some of them is that sometimes there can be inertia in their organizations, right? Many of them have had data center for 10, 15 years.
And so being able to make a clear timeline for them that says, this is when March, 2029, it's time to be off of data center and into the cloud platform, enables these teams to start planning right backward from that timeline within their companies and start to build a business case. Because quite frankly, they're not migrating from, uh, JIRA data center to Jira Cloud. They're moving from kind of traditional behind the firewall, siloed, uh, products that work very well and have scaled, but into a cloud platform.
And that's what it's all about when it comes to ai, right? Every customer that I talk to is so excited about bringing AI to all of their workflows, but to do that, it's gonna be leveraging cloud technologies. It's gonna be leveling how these systems are built out on the cloud.
And so for many of these customers having that balance of new value by real rebuilding their workflows with AI in the cloud, and then also having new deployment models in the cloud to support even the most regulated industry customers. Um, we've announced that we have support not just for, uh, high levels of security with Atlassian Guard on top of our commercial cloud, but we now have our gov cloud for our US government customers that has FedRAMP certifications soon to be IL five as well. Uh, but we announced isolated Cloud earlier this year.
And so isolated cloud gives you, um, a dedicated tenant. You have isolated, um, uh, compute storage and networking. And so that's a great environment for some of our regulated industry customers, and we'll support that, not just in the US but all of our data residency regents.
So mm-hmm. So in effect, I get a private data center is just on somebody else's infrastructure. Correct.
Um, what's been their reception to that concept among folks who do have those requirements for compliance stuff? Are they willing to do that? Because a lot of them seem to, sometimes they wanna hug their servers and they're like, I own my infrastructure, but, you know, psychologically speaking, that may not as be as, uh, compelling as an issue if I have a private cloud, right?
Mm-hmm. No, you're right. And I think that's also another reason why it's been great to actually put this announcement for a send out because we can start to have these conversations with these customers.
Um, what we're hearing has been really positive. I think initially we had a, a very small set of customers in the US that we thought were gonna be going on to isolated cloud, but once the announcement came out, we've been hearing a lot more demand for it, and not just here in the us but you know, obviously we're here in Barcelona at the Team AMIA conference. Um, we've had a lot of impromptu meetings these this week from customers here that are excited about looking at an isolated cloud environment for them.
So yes, there's gonna be a, you know, change management is, is always hard as, as you alluded to. Um, but I think the signal we're getting from customers is that the excitement to rebuild all this with AI in the cloud and a clear timeline enables them to start putting plans together. So that point, does AI not force the issue?
Because ultimately I have all these models, I need to expose them to data, and the more data I expose to them, the smarter the models get, that all lends itself to the cloud. Because if all my data's sitting in some isolated data center somewhere, I'm really not gonna be able to do that as efficiently. You're exactly right, Mike.
Um, for, uh, customers, a lot of what we discussed with them is, look, everyone is using, uh, AI on the consumer side, and that's all one uniform data set, right? It's everything on the web is the data set that feeds Chad G Boutique. But when you think about harnessing the power of AI for your company, how are you gonna expose all of that data?
And oftentimes that data doesn't come from one vendor. You know, they have products from Atlassian, they have products from Microsoft, maybe they have products from ServiceNow, Salesforce. And so being able to provide that rich context to customers is gonna require a lot of interoperability between these platforms.
And that's gonna be done best in the cloud, right? And you, you see that right now with, um, a lot of the conversations around MCP model, context protocol, how the agents are gonna access this data, how the agents are gonna work together. So you're spot on.
Any customer that wants to bring AI agents into their workforce is going to have to be able to build some sort of platform strategy that connects this data together. Um, and that's why we've built the teamwork graph. Um, hopefully you've heard a little bit about that.
The teamwork graph, as I understand it, is the, the thing that maintains the context and discovery and the relationships between all the various components that are in the cloud or in the SaaS applications, but not just your applications, third party applications as well. So, um, a lot of folks probably don't know what a graph is, but explain, yeah. Um, a graph is really important because it's about the relationships between the data, right?
You can have all of the data sitting there in buckets, but if you don't have, uh, an understanding of how that data is related to each other, what kind of insights can you draw? What kind of insights can an agent draw? What kind of context can you give it?
And so the teamwork graph was born from, um, kind of pre all this AI stuff, but at Atlassian, customers were asking us to help them get more insights from the data that was coming into the system. And like you said, not just from, you know, Atlassian's products, JIRA, confluence, JIRA service management, but they often are using a pretty rich set of developer tools, right? And other functions, Salesforce, et cetera, bringing in data.
Mm-hmm. And so as we started to look at the relationships between that data, we saw that we could be quite opinionated about it because the way teams work, uh, is usually modeled in a specific way. Development teams have certain objects that they're using, whether it's, you know, repos, right, code, et cetera.
Uh, teams work around goals that they're setting for themselves. They're managing projects in Jira. So all these data objects have relationships together and context.
And so we started to invest in making that bigger and bigger. And you, you saw in the keynote, we've got now billions of relationships now between all those objects. And so what that means is think of it as a very unique fingerprint of your company.
And so what that means is when you log into our systems and you make a search query, or you initiate some task, it knows Mike, it knows what projects you've been working on, it knows what team you're on, it knows what your team is working on. And so it doesn't just look at the structured data to answer these questions, it's actually using the teamwork graph to provide context for the query. Um, and now it has memory, as you probably saw in the keynote, right?
So it makes your agents smarter and smarter about the way you work, but also the way you work with others in the company. And that's the really hard bit, right? It's like there's personal productivity and there's team productivity, and those are at very different levels.
And I think the teamwork graph, um, is really exciting because we're starting to see not just, obviously our own teams build experiences on top of it, but we announced, um, today that we're opening it up. And so that means people can extend and add their own custom objects into it. They can pull from the graph and build their own applications off of it.
So we really see it being kind of an, an exciting piece of, uh, making AI really valuable, um, for customers. And That goes back to what you were talking about with context and my personal preferences, and everybody has a slightly different way of working this is the AI agent in that context become, um, my primary engagement partner? Mm-hmm.
Or am I managing a hundred agents that all have different kinds of memory and different kinds of experience? How do I kind of marshal this small army of AI agents? What's that gonna look like?
That's a great question. And I feel like, uh, the whole agent strategy and what that workflow is gonna look like has been evolving so fast the last six months, right? I think initially it was, Ooh, everyone's gonna have an agent.
You know, Mike's gonna have his personal agent. And then it became, well, no, he's gonna have hundreds of agents and they're all gonna do lots of stuff. And then it became, okay, well every company's gonna have thousands of agents.
How are we gonna manage this? Right? What we've been hearing from customers is they want simplification.
You don't, you want to not have to think about managing a whole set of agents. So we're trying to provide a good amount of flexibility right now because we recognize customers are gonna try lots of different things. And across the wide range of use cases we're seeing, there's probably not a one size fits all.
Um, but we believe what's really important is the skills that you're endowing those agents with. So part of what we announced today is, um, a really large library of several hundred skills that an agent can have. So you could choose to build one Uber agent for Mike that has all the skills.
It can do a bunch of admin tasks for you. It could do your core work, it could do personal work, it could do all sorts of things. Or maybe you don't like that and you'd prefer to have very separate siloed agents.
So we wanna give you that flexibility to be able to do, um, the model that you'd like. So I think there's gonna be a lot that shapes up over the next, um, six months year. But what's exciting for us is we're seeing customers customize, uh, tens of thousands of agents and give those agents the ability to, uh, go and actually initiate workflows in our system.
We're seeing millions of workflow automations being triggered by agents already. So, uh, we believe that probably Atlassian right now is probably one of the largest AI workflow, um, generated platforms. Mm-hmm.
To bring this full circle, a lot of folks who have their own data centers will be concerned that their data doesn't wind up training an AI model. So how does Atlassian kind of protect everybody's data or isolate that data from all the other AI models and agents that customers might be using in the cloud? That's a really important question.
I get a lot from our customers. So the models that we use right now today, we work with OpenAI, we also work with Meta and have their models. We do not share any customer data with those model providers.
So the teamwork craft data that we're using to provide that structured context, it's only used when you're querying. And so it's providing that grounding so that you can get the right response back. But we're not sharing any of that data directly, um, with the model providers.
And it's also isolated, uh, per customer, right? So each teamwork graph instance, right, that we're training is for that particular customer. So, um, it's a really important question that I know customers and if they wanna see the architecture diagram, we've got a lot on the website as well that kind of goes through exactly what, um, the lifecycle of that data goes through.
So, uh, All right. Hey folks, you heard it here. You're going to the cloud and there's gonna be a lot more functionality and a lot more features and things you never imagined you could do.
So better do it sooner than later. Tiffany, thanks for being on the Show. Thanks so much, Mike.
All right, we'll be back in a minute. Hi everyone. We're back here live at CubeCon.
It is, uh, day two. Well, it depends how you count. 'cause Cube con's funny 'cause we have like this day zero all of the, uh, satellite conferences, but we don't really, that's a zero.
Yesterday was day one today, therefore it's day two, though. Some of us have been here three days. Yes.
It's fuzzy meth. Anyway, though. We're, we're still live here.
My next two guests are with Intuit, and I know what you're saying. Intuit Cloud Native Computing Foundation. What are they doing here?
Well, I'm gonna let them explain it, but there's a really good story behind it. Let me introduce you to them. We have Lisa, Lisa Marie, not Presley, Lisa Marie, Nancy, who, if you've watched our previous, uh, Textron cover, uh, CubeCon Coverages, it's not her first time here.
And then we have Mr. Patel, and I'm blanking your first name. Jamil Jamil Patel, also from Intuit here.
And, and guys, welcome. Thank you so much. It's great to be back.
It's always good to see You act. Always good to see you as well. So I, I, I kind of opened the door with the question, Intuit, what are you doing here?
Yeah. Well, that first day of the conversation, you talk about nothing, zero about it. We, uh, we actually started, uh, one of the colos, it's the Argo Con.
Yep. 'cause as you know, Intuit is the creator of the Argo Project and donated it to the CNCF started that conference, um, with the, with tons of help from, um, the Acuity and Codefresh and Red Hat folks. Uh, and now it's one of the most popular co-located events.
Octopus deploy. Octopus Deploy now. Yes.
Yeah. Uh, that's true. That's true.
Um, so yeah. And, and those, we are all still incredibly active in, in the Argo community. And Argo Khan is one of the most popular co-located events.
It was packed on the first day. Well, Argo CD, I believe is now the number three, uh, project in CNCF, right behind Cube K itself, and then, uh, and hotel over here. Yeah, yeah, Yeah.
And those are sta at Argo Khan, uh, two thirds of all Kubernetes low, uh, users have Argo CD installed. Really? Yeah.
They just republished actually, as of yesterday. Dan just talked about it. 97% is are using Argo.
It was a crazy stat, which almost says that more people are using Argo than Kubernetes. So that math we need to sort out, but people are using Argo. People love Argo, particularly Argo cd.
Yeah. Um, so yeah, no, it's great. It was very popular.
Uh, but, but to your question, open source is we're, we're on the platform team. Yes. And open source is pretty core to a lot of the work we're doing.
And we don't just, you know, consume open source. We also do build and contribute back things like the Argo project, the pne Prj, um, which is our Kubernetes native event stream platform. And all of this stuff we use, we consume, I would say more than what, a hundred open source projects mm-hmm.
Or contribute to. So, you know, we've, we've built a little open source program office. We'd show up at events like this.
And I just had a conversation with someone who walks through a booth about the hundredth conversation I've had when they're like, you know, what is Intuit doing here? I've, I didn't think of Intuit as a technology co company, and I definitely didn't understand how important you were to open source and vice versa. And we've won End User of the Year award twice from the ECF here at Cape Con twice.
Very cool. Um, so yeah, we're very proud of the work we do in open source. So I of course, knew this before we started the conversation today.
Um, but when you think about it, you know, one of the things that makes the CNCF successful is the mix. It's not all technology vendors, it's not all, and I don't mean this in a bad way, geeky, you know, uh, dev or ops or, you know, A lot of end users Verticals. But it's also end user organizations that quite frankly have the resources to, to dedicate people and time and money to open source projects.
And instead of kind of keeping it for its themselves, which is kind of the old way of doing it, become good community members here because they're vital to the mix. Right? At the end of the day, you are not here to sell your, your open source software.
You contribute it. You're, you know, 'cause there are other, for instance, I, I was interviewing the, the folks at Broadcom, VMware earlier today, you know, they're the third largest contributor to code to Kubernetes. And a lot of people don't think that, 'cause they think Kubernetes hypervisor, they're separate, but no, they're the third largest contributor to code there now.
And I commend them for that. But let's face it, they're feathering their own nest. Right.
You know what I mean? And, and one can say, even if they're not doing it for that being the only reason, one can still say, well, but they're, they're selling software. Right?
Right. And two it different thing, you are doing it. 'cause it's, it's, it's making what you guys do better, but you want everyone else to be able to have access to that as well, because you're not selling.
And to be able Contribute To it, it helps Make it better. Helps. Yeah.
Well, it's like paying it forward, right? Mm-hmm. When you contributed to the community, hopefully others follow and, and it's all that karma wheel that goes round in mountain, Right?
And paying it forward also has its dividends. Like for Argo project, uh, red Hat is now contributing as well. And they've created cool features.
There's an MCP server introduced, and now we are also leveraging from the community. So like, if we were to do all this ourselves, it's all our resources. Uh, versus now we are getting back from the community.
So the dividends come in, it just takes some time. Absolutely. Yeah, it does.
And that's karma, right? It goes round and round, but it, it, it does pay off. Yeah.
If you don't mind though, I, I want to shift, I'm shifting. Um, no, no, but ai, yeah. Right?
Yeah. Everyone, well, not just this time for the last two, three years, you know, we all lead with ai and I, I think just as Kubernetes itself is maturing a little bit, we're, I'm not saying AI's mature, we still have a long way to go. But we are starting to see definitive patterns in how we use ai, where we use ai, who we is using ai.
Let's talk a little bit about Intuit ai. Absolutely. Jamil, yeah.
The last, yeah. One of the things like our, you know, mission. In our mission statement, we have three statements.
We have, uh, less work or no work, more money and high confidence. Like we have these three statements, and as we think about ai, like it helps you make more money, it helps you do less work, and it gives you more confidence. And it's very critical to our consumer products that they have AI in them.
And that lets our consumers, uh, get all of these things. Now, when it translates to like an engineering organizations, there's like, you know, we think about it in three areas since we are all like in the platform engineering space, there's one is like, how can AI make platform engineers more productive and make infrastructure awesome? The second area is how can it help general application developers be faster?
So how do developers go faster with all the coding tools and the tools they have? And the third one, uh, is more around like, how, how are we using ai, uh, where we are giving developers ways to build AI applications for customers? Because there are new tools for building AI.
And, you know, our developers need to know how to use these tools and how to get faster from an app that did not have AI to now having AI in that app. So for all these three areas, we are investing heavily. And maybe I can give you some examples for each of there.
Yeah, I was gonna ask you too. Yeah, go ahead. So for the platform engineering side, uh, this is where like, Kubernetes is hard.
That's something, that's why platform engineers are paid so much. Uh, now with AI coming into the space, they're actually gonna get more and more productive. Uh, for Argo CD for example, we added Argo CD assist.
And that is when, you know, people used to ping, uh, our platform engineers and say like, what is wrong with my deployment? Now AI can just build a summary first, and if the summary doesn't work for them, they can still ping them. Exactly.
Uh, there is build failure analysis where every time a build fails for a developer who doesn't know what's going on behind the scenes, they get a summary of like, what is failing. And sometimes, uh, there's also remediation, uh, where it tries to remediate the fact, and developers don't even know what is happening. We call that done for you experiences where things are done for you and you don't even have to worry about things.
Uh, so that's on the, like how AI is helping platform engineers. Let, let me stop you right there on this platform engineering thing. So, you know, we, we started a new site since last year when I interviewed you.
Hopefully it's on there. com, see on the edge, right. com.
Because platform engineering, I think has emerged as its own discipline. Mm-hmm. Yes.
It's closely tied in a DevOps. Yes. It's closely tied into, uh, cloud native but it's its own thing.
Um, when we look at platform engineering, though, I think two years ago, three years ago, if I asked someone who claimed to be a platform engineer, what are you doing? Kubernetes is hard. And we're gonna make Kubernetes easy.
Not easy. I don't think it ever gets easy, but manageable. Yeah.
But I think if you ask most platform engineers today what the mission is, they'll tell you IDP internal development platform. Right? Because that seems to be where the action is in platform engineering and also a lot of where the AI is going.
I'm wondering what you're seeing as a real life platform guided into it. Yeah. Uh, so Intuit got lucky.
We invested in an IDP way early before Backstage came out. Every third person I talked to at CubeCon, they're like backstage, backstage, backstage, uh, because the IDP serve as a, as a web layer to all their abstractions. So making Kubernetes easy is through abstractions and where do you put them?
You can't put them on Kubernetes itself. 'cause then you gonna learn that. So instead they have an abstraction on top of that, which is IDPs.
Most IDPs are going to have an AI assistant moving forward, and that's going to be your platform. Engineering team's first line of defense. And if that AI is not able to answer or do things for your, uh, general developer, that's when you go to the platform engineers.
Versus today we live in a world where like the first choice might be platform engineers. So then I think, you know, IDP and AI together, like in one platform is going to be our first line of platform engineering defense. And you'll see more and more vendors come out.
You'll see the Kubernetes ecosystem getting well integrated into it right now, it has all the popular projects, but you'll see a lot more projects going into it. Because once you have an IDP, you have to integrate Jira, you have to integrate GitHub, you wanna integrate Argo, and the list never ends. No, no.
So it's a integration. But I, I think we learned something from like APIs, right? Which is, you don't wanna do a one off for every single one of these projects or every single one of these products that you wanna plug into your IDP.
You know, I, I think with Agentic ai, we have the ability with, let's say an MCP server to, to not repeat the mistakes of and sins of the past. Right? We, we could do that very quickly.
Is that something Intuit is looking at? Yeah. And that's where like if you look, I would say five years ahead, uh, I would also say like, you know, the I-D-E-I-D-P experience might also shift left.
We are thinking about shifting left. And a lot of these experiences are happening within the IDE itself. So when you're developing, you also have a chat agent, a chat window with CPS enabled.
So why wait until deploy? And then asking the questions like, you are coding, you're asking the questions in the side, like, why will this bill pass? And your MCP, like your IDE, then call the AI MCP, try to run it in your cluster or tell you information about your clusters.
And before you even push the code out, you will know like what's, you know, what's wrong with your code. So, you know, there's a shift left happening where you want to alert the developers before they push it to a stage where they need support. Like things need to be fixed right when they're working on it.
And I'm hoping that our tool chains also support that. So you have that chat window that provides you alerts and errors early on, then you deploy, then your IDP has a chat window that you have alerts and whatnot. And then you have all your operations dashboards and those things.
Those also have those. So like you will have a, and you know, a lot of the companies are, their jobs are to unify these assistants. 'cause there's like almost too many these days and they don't talk to each other.
So you have to ask the same question here, here, and here, and choose the best answer based on which one's the most mature. So, you know, that's kind of what I've seen happening as well. I get it, I get It.
I was gonna make some joke about like, okay, everybody stop building Dev Dov portals and just, you know, focus on IDPs and, but I bet you next year when we're having this conversation, that will probably be a reality or much closer to We'll see. Yeah. You know what?
This, this, you've said it now it's out in the universe. Exactly. Don't even get money.
So we'll, we'll come back and, and get it. Um, so that's AI in developer platforms. Mm-hmm.
But there were two other AI use cases for Intuit here. Yeah. So the other one, uh, which, you know, in the last three to four years, we have seen a 12 or five years actually we have seen a 12 x increase in developer velocity.
Uh, and the reason being all of the, like the AI coding tools, there's a boom of that. Uh, right now the market's changing so rapidly. Every three months there is a vendor, there's cursor, augment code, Gemini Codex, you know, more, more to come.
Uh, and, uh, what we adopted early on as a strategy is not to choose one option, but to give developers flexibility. But in addition to the tool, we are providing Intuit, uh, code as context to all of these capabilities. So when developers ask like, how do I write a web plugin?
It doesn't tell you just a how to write a generic web plugin. It will tell you how to write an Intuit web plugin. And that has been like very crucial to our journey where when our developers ask for help, it is, it has all theisms baked into it, uh, to begin with.
Um, so from a, you know, code gen code generation perspective, like I think at advice, everyone on the same journey to like not focus on the tools. 'cause the tool market is going to change. Acquisitions are going to happen.
Chad, GPT and the other vendors will release our open AI will release new, new tools. And your developers are always gonna say, this is the coolest or that is the coolest. And you can't, in a real world support all of them.
So I, I'd see this market will evolve and ultimately you'll see clear winners. Uh, but right now you can focus on making your AI such that it doesn't give generic answers, but it gives like your company specific answers as much as possible. Excellent.
Yeah. Let's talk about something really important. Customers.
Mm-hmm. How's AI helping you with customers? So, uh, in the customer landscape, like there is, you know, there's immense opportunities.
So on the QuickBooks land, like we have certain agents that help people get, get paid five days faster. And that's like very much aligned to our, our mission of more money. Uh, who, who doesn't wanna get paid faster like I do.
Like, you know, so there are things that would reconcile your transactions on QuickBooks faster, and that enables business owners to also like run their accounting faster. Um, so that could mean vendors are getting paid faster, employees are getting paid faster. Um, so that's on the business side.
On the TurboTax side, like if you filed taxes with TurboTax last year, it will do Gen I summary. And it will kind of make you feel more confident that, uh, because TurboTax is a tool and you file your taxes yourself, you put the documentation. So sometimes you are doubting yourself, like, did I put everything in the right way?
But now AI is gonna say, Hey, you, you put this document but you didn't support it with this other document, that's usually the case. So maybe you are missing to upload your gains on the stock sale or whatever. Yeah.
And then that's gonna make you more confident in terms of being able to confidently say, I file my taxes. Right? Or I did my accounting.
Right. Or with MailChimp, it's like email marketing. You know, everyone wants help from AI to write emails.
It's in there. Now. It also tells you what is the best time that this person's likely gonna open this email.
And that is intelligence. Where before it was like, send an email at 9:00 AM that was the the norm. Right now it's like, send an email to the people when they want it and when they're most likely to open and read this email.
And that is a game changer in Sure. Is. And, and in, in, and that kind of capability in the hands of a small business owner.
Like if you're a big company, yes, you have those capabilities, but a small business owner being able to personalize up to that extent is magical. Absolutely. To stay on top of all the regulations and all the rules.
And you know, imagine if somebody suggested, Hey Alan, like you're leaving money on the table 'cause you didn't write off all these things, but you can write those off. That's legal. Yeah.
And you'd be like, Ooh, let's do that. Then more money for you. Oh, I love paying more taxes.
Especially unnecessarily. Uh, Yeah. Uh, excellent stuff.
So, you know, it's funny, I was talking to people earlier last year, we were talking a lot about AI this year. I haven't heard as much though. It, it's kind of built in now.
And um, but we're still just scratching the surface, right? Mm-hmm. There's so much more it's gonna happen here.
It'll be interesting to see how that plays out. And I'm also interested to see how it plays out from an open source perspective, how much of this winds up on that side by the project pavilions mm-hmm. Right.
Versus inside of commercial products only. So it'll be interesting. It'll be interesting.
Yeah. And the C NCF is, is working hard. We, as you know, I'm a CNF ambassador and have been for many years, um, over 10 now.
I guess I just saw my picture on a slide saying something about 10 years of contributions. So, wow. But that's, we do talk to them a lot and we just had a meeting with them a couple weeks ago, you know, really asking that question, like, what's your plan with ai?
And, you know, we had a bunch of projects that we think would be great to be in the C ncf F and then they told us about some stuff we didn't even know about. So the conversations are happening, they are talking to the end users, um, and, and they're also trying to get, you know, the ossis get publishing more, more and more standards all the time, which is really good and really helpful. Agen is a very big conversation in Kubernetes right now.
Uh, so that's a hot topic. Yes. Um, so we're excited, we're excited to see where it's going.
Yeah. It's, and this morning they announced the AI Big Bricks project. Uh, they're working on Cajun the Envoy, uh, like AI gateway with Tetra and Solo.
Uh, those are all like, exciting projects. Uh, and you know, I don't think, uh, like, you know, AI and Kubernetes are like so separate today. 'cause people are already running a lot of AI workloads on Kubernetes.
There's a lot of libraries out there now. It's just like, it is the same way where the coding agents are like, which ones are gonna hear like, we gonna be here to stay and which ones are gonna be just like noise in the space. So we should find out.
And you know, this is a great place to know and feel from all the audiences here. Agreed. Yeah.
Agreed. Well, listen, we're, we're probably over time to tell you the truth. I want to thank you both for coming here on Tech Trunk tv.
You have an invitation in next year, but let's not wait till next year Exactly to catch up. Thank you. You always love being here.
You okay? Alright. Thank you for having us.
Yeah. All right. Thank you so Much.
Intuit. Open source dynamos here at Cube Con. We're gonna take a break.
We'll be back in a minute. All right, everybody, good morning, good afternoon, good evening, wherever you are in the world. My name is Shauna Med.
I'm the CPO of CloudBees and, uh, running r and d here at CloudBees. Glad you could join us, uh, and, uh, and spend some time together. Listen, the thing is modern DevOps, uh, there's probably a question worth asking ourselves, which is, how did we actually get here?
Um, if we look historically, DevOps, uh, really started as a cultural shift, uh, decades ago. And, and the idea at the heart of it was that, you know, developers and operators would come together. And the idea would be that if they were moving and, and, and they were working together much more closely in the software development lifecycle, they would move faster.
They'd break down some silos. And, uh, core technologies and, and concepts used in order to do that was to deploy pipelines. Uh, deploy as much automation as you can containerized and essentially kind of get to an accelerated velocity, uh, beyond what you were doing manually.
Um, the end goal kind of being, Hey, let's, let's deploy 10 times a day versus, you know, once a quarter. Uh, and every one of these leaps that you're seeing on the chart here, it brought new tools into the equation. Uh, CICD tools brought new, uh, new different types of tools into the equation.
Containerization did, Kubernetes did a whole galaxy of new tools. If you think about it. Uh, security shift left into the pipeline itself brought yet another set of types of scanners and tools into the pipelines that weren't there before.
And, and, and, and the way that we build applications, uh, changed as well. We went cloud native building, microservices, and today we've got AI writing code for us. The truth is, every time that you have within your organization probably has their own stack.
So DevOps in itself, if you summarize all that and think back, is about speed. It was about agility. It was about breaking silos.
Now, the interesting thing that happened is there was a reaction to that over the years. And, and, and, and the enterprise reaction to that is kind of looking at it and going, wow, this is really messy. Right?
Um, that's a lot of tools and you're integrating them all to work with each other. Let's go ahead and consolidate. We need less tools, not more tools.
And this idea that somehow fewer tools means less complexity. And if I think about it on the surface, that seems like a logical thing to think about. But the question I often ask myself and to, uh, the companies that I work with is, is tool count really the problem that you have within your organization?
Actually, because tools for, if you think about that chart, is not really a mistake, is it? It's, it's really more or less Conway's law in action. Uh, because the way I think organizations are structured inevitably shapes the systems and pools that they use.
So sprawl often reflects organizational reality. It's not just poor governance. Um, you know, sprawl is an inevitable outcome of innovation in my opinion.
And I think teams actually will adopt what solves real problems from them. And I, and I don't think anybody wakes up in the morning and says, you know, let me niche 80 platforms if you could. So I don't think tools are paired by accident.
I think they each solved a very real problem for the, the, the teams that implemented them. And so it, it, it shouldn't be thought of as a problem, but rather it's a feature. It's not a bug of the system itself.
So then comes the platform vendors in, right? And then comes the idea that there is a platform. And this platform often will be the silver bullet, you know, and, and the idea is, hey, if you just put one platform in place, it'll rule the ball.
It'll give you this single pane of glass, uh, across your entire landscape. Uh, there's gonna be no integration headaches anymore because you're using all the modules that are inside this platform, and everything's gonna be neat. It's gonna be unified, it's gonna be unified workflows.
And I think, okay, that would've made sense. That's the traditional platform approach. That was a very natural response, I think in some ways to the growing complexity in the SDLC and for a whole host of companies that made sense too.
For a lot of teams that made sense too. Greenfield was, was one great area where being able to get into a platform like that where nothing else existed from before, there was no legacy code, maybe there was no tech debt that you have to deal with, it's purely all cloud native, small, tight-knit teams. And they all looked at speed as the number one sort of vector that they wanted to focus on over complexity.
And for startup, that is a very reasonable approach. But it wasn't really for the enterprise, was it? It's kind of different in the enterprise.
And we all have worked in very large scale organizations with very large teams. And many teams know that there's always decades of code that you are managing, that you've built that you need to build and maintain and release. There's multiple frameworks across the board that have to work.
You know, you got hybrid infrastructure from on-prem that is historically there or maybe still there that you're managing and running. You've got your cloud and you got off a multi-cloud depending on how you're set up. And then there's always these mystery servers out there somewhere, and nobody knows exactly what's on it.
So when you think about it, you also have distributed teams. You got teams working differently, which means they got different cultures and ways of working. And automatically compliance isn't just gonna happen.
There's heavy compliance needs that need to be followed. So I think the answer in the enterprise to the question is everything homogenous. The answer is no.
Complexity and heterogeneity is really inevitable in the enterprise. There's nothing you can do about it. And it doesn't feel like it ever felt like a platform was built to solve this reality.
I think in many ways it's a fantasy against the reality that enterprises are actually facing. The, the promise that, you know, the platform vendors will give you is, Hey, it's simple. It's, uh, simplicity over anything else.
It's speed, it's cost saving. But the reality for the enterprises is that they've got boltons downtime lock-ins, that's type of things is not they want, they don't want those types of things. They, they don't want rigid workflows that force them to work in one way across their entire enterprise.
And then unfortunately, what o often will happen is developers will just bypass the platform anyway. So while it's true, simplicity on paper seems really appealing, it's actually equivalent to rigidity in practice. That's how I think about it.
So we could step back for a little bit and say, okay, well what is it that the enterprise is really trying to do? Where do they want to get to? What's most important to them?
And I think it is one, one thing that's always the most important thing is try to always avoid the single point of failure. You, you want to be resilient at any scale at that you are operating at, um, security and compliance. You want to be able to put that in place, but you don't want it to be a bottleneck.
You want to be able to have hybrid integration between your tools and so on. You wanna be able to go across environments. You want teams to be autonomous and operate in an autonomous way, but provide some sort of common guardrails that feels like are the top priorities that always every enterprise company will talk about.
And the real goal then becomes a little bit more clear. That means the answer isn't, we need fewer tools. What we do need is freedom with some control.
We want simplicity to occur through orchestrating them, but not through consolidating them. And what we really want is we want developer joy, a lot of it. So if I think about the stack, that diversity in your stack, that's an advantage that you want to unlock, not one that you wanna take away.
So what can that path forward be that you can take? And how do you focus in on some of the things that are most important? I typically have four very practical sort of principle for how to tackle complexity The way I think about it, first and foremost, I always say, you've got to be flexible.
You gotta be able to have flexibility as your top priority y because you wanna build for change. Change is absolutely inevitable. And don't build forever.
Platforms that lock you in. You know, give the tool choice and power teams to pick the best tool for the context they're operating in the work that they're doing. And don't mandate things.
I think guardrails will always eat mandates for lunch. So that's one thing. Be flexible.
Number two, always think about composability and what you're building over trying to consolidate everything. Think API first think interoperability between the tools. What kind of ways can you bring the stuff that you already have within your software development lifecycle together to be used in a way where you don't have to script everything, control planes, use them for visibility, get governance across it and try to use policy as code as much as you can across your environments so that everything is composable reusable instead of consolidating into a locked platform.
I think about modernization as an incremental step that you take, not a big bang approach. Those, those big bang migrations are almost always super expensive. They take forever to do and are, are, are, are often going to fail and run over costs.
So modernize, but do it at piece by piece. Take one thing by one thing big some build some quick wins, uh, and then get momentum from that. As you think about what to modernize, when to modernize it, don't go big bang.
And the other thing is think about how do I provide governance into the organization without it becoming an actual bottleneck for those it governs, it's like a guardrail. Try to automate security and compliance, but do it outside of the pipeline. Find a way to put compliance and security as guardrail around the organization as opposed to making it the developer's responsibility alone.
Balance that shift left, uh, with the productivity that you want developers to be able to have so that they can really feel joy in what they're doing every single day. So if that's sort of the practical principles, there's one very clear sort of tactical thing that you can do and how can you achieve this complexity without chaos stake that I'm talking about? And I always say, Hey, look, there's two things you gotta split.
It's much better for you to centralize the control plane. Do that for visibility, orchestration, governance, compliance. Make sure you centralize that control plane, but absolutely decentralize the execution plane to give teams autonomy, speed, and innovation.
And I think that when you sort of, in a very practical manner, split these two, it actually gives you an opportunity to really unlock speed, but do it safely and go faster in this world of AI first and, and, and, and, and how much innovation it is that we are required to bring to the market to stay competitive. So here's the success factors for every enterprise. No doubt if you take that approach, always think ecosystem, but don't go, you know, an empire.
We're not building platforms to build large empires where everything sits in there. The ecosystem always wins. And there's so many examples in the market of that where those who didn't build empires but built ecosystem actually win.
Um, and don't think about diversity in your stack as a bug. It's, it's really a feature and it's really about unlocking that diversity by control, planning it together. And then second, measure your outcomes.
Please don't measure your tool counts. That's never a great way of building success in my humble opinion. So stop chasing, stop chasing that fantasy where you're gonna have a whole bunch of fewer tools.
Embrace it, be flexible. Think about composability, modernizing incrementally and governed without bottleneck. And I'll leave you with this quote that I always think about as, um, you know, sort of the one opening line or ending line of one of my presentation.
And that is, listen, enterprises don't win by locking into one platform. That's never been the case. They win by building delivery systems that truly can adapt to a changing landscape and tools just the same way that the business does.
You do that, and I think you're gonna have great success in terms of being able to operate, give developers the joy they need and be able to innovate faster, but do so safely. And with that, I thank you for your time and have a great, great rest of the seminar. Bye Agents for cloud migration.
Commvault Unity has arrived hero for Code Arista and Palo Alto are gonna team up. We're gonna be talking more about Microsoft and Anthropic. There's some AI driven espionage out there.
And, uh, wait a minute, we're gonna see if clad flares back online in the closer look in this episode of the Tech Field Day rundown. Hello everyone. Welcome to the tech Field Day rundown for November the 19th.
Uh, today is a day that I absolutely cannot endorse it's national play monopoly day. You're probably thinking to yourself, oh yeah, my family's gotten into some fights before I once played Monopoly with lawyers and they made me sign contracts. So never again.
Thankfully I've pivoted that business into talking all about the tech news that's been going on this week. And, uh, joining me is my somewhat sleepy co-host Mr. Alistair Cook.
Al it was great to see you last week in person, but I think that jet lags starting to catch up with you. You know, it's one of the amazing things is, uh, being in the states after working with the team, I gotta go to Ohio with the team and, uh, be in person with people, but I also gotta experience it's Sunday in the, in the US while it's Monday in New Zealand. And I'm usually on the other side of that.
It was a fun experience, but yeah, it's a long way home. It's a long way home. But thankfully a lot happened in the time that you were gone on that plane.
And we're gonna be talking all about it because Yeah, well, you know, how often do you break the internet? We're gonna start off with a story about the last people that broke the internet, and that's our friends over at Amazon Web Services. Because AWS introduced a new AI powered agent that dramatically accelerates cloud migration projects by automating tasks that used to take us weeks.
The professional services delivery agent can generate proposals from diagrams or notes, deploy sub-agents for coding and testing and leverage AWS transform to modernize legacy systems. It's all backed by insights from thousands of prior migration. These tools position AWS alongside other heavyweights like Google and Microsoft, and using AI to streamline large scale cloud modernization.
Al, can Amazon finally turn the corner and make it easy to move things onto AWS? I hope so because historically we've picked up what we had on premises shoved into, into AWS or another cloud platform and been terrified at the costs that we got after a little while. So going through a good consulting process to do that migration to, to get the most value out of getting our applications onto the public clouds, that's a really vital part of cloud adoption.
And the aim with this particular component, the AWS professional Services delivery agent, is to shorten the cycle for that instead of taking six months to a year to go through that planning and discovery and specification to have some AI agents deal with the huge volumes of data that you get as you're going through that, that process and to make sense of things through here. So, doing some of the, the design and iteration ar around what does my infrastructure look like on AWS that's different from how it looks on premises. What things should I rewrite in order to use new platforms?
You know, how many Rs are we up to 7, 8, 9 of migration that's, uh, that we get with AWS. Having some of those guidance and decisions is, is absolutely vital. And I've seen this previously that it looks very simple to move to a cloud platform.
You just take what you got and you shift it across. But there's so many interdependencies and discovering and analyzing those interdependencies, working out your cycles to to move. That's absolutely really hard work.
And it does seem like it's a combinations of choices, uh, process that really does suit an AI agent. Will this lead to more successful and and faster migrations from on-premises to AWS remains to be seen. And it's a, it's a complex kind of process to go through.
And one of my concerns is that as you go through that process, you need to build knowledge within your organization about how to, how to actually enact the transition from on-premises up to AWS and the differences. My concern is that these agents might prevent some of that knowledge gain, that, um, internal awareness that's a vital to speed up a, a normal migration. Of course, it may remove the need for that because the AI agents might be that smart Convault, our good friends at Convault have just launched Cloud Unity and AI powered platform that unifies data protection, recovery, and identity security across cloud and hybrid environments, tackles AI driven data sprawl and rising identity based attacks, uh, with integrated governance tools and all of the nice advanced threat detection and recovery testing.
Early access is available now, but full releases coming early next year. Tom, have you had access to the earliest? I have not had early access, but I was in the audience for last week's keynote when Sanjay Merchant came out and kind of start talking about what Unity entails.
Uh, we're gonna be, uh, following along with the live stream that's actually happening today on the 19th. com for more details on that. Here were some of my big takeaways from what I got during the Commvault Shift keynote.
The first thing is res ops. I hope you're ready for a new ops, uh, designation. Uh, in this case.
You know, with Commvault, it's resilience ops, right? It is not enough to be available. You have to be resilient, you have to make sure your data never goes down.
Uh, that is part and parcel of what Commvault has always been about. We know that for a fact because we've seen that over the years. Commvault's kinda the gold standard for backup and recovery, but that's not the market that we're in anymore.
We are in the data protection market. And one of the things that they announced that, it took me a minute to kind of understand the totality of it, is something called synthetic restores. And you're probably thinking to yourself, well, how hard is it to restore data?
But I want you to think about this because this is the way that the market has been going. So it used to be that if something blew up, we had to restore it, right? Well, we had to go back and figure out where we had good data from.
And in the case of a security incident, we have to make sure that the data is still clean, and that means restoring back to, uh, a certain point in time, right? But how do we know that the point in time is far enough back that we're getting the right data to restore? And what happened to all the data that's been created since that restore point?
Can't all be bad, right? So what Convault is proposing with this synthetic restorer capability is that they're gonna take a look at the backup. So we're not just going to last yesterday or last week or last month.
We're gonna take all of the backups and we're gonna look for the critical files that are infected, and we're gonna roll those back to the point where they were not infected. But for everything else that's not destroyed, we are going to roll it back to the last known good of that file. So if that last known good file was yesterday, then we could restore part of the system to a month ago and another part to last night.
That means minimal data loss, that means resilience all over the place. And that is huge for people who are uncomfortable with this idea of like, you know, we gotta start taking big full backups and full snapshots all the time because you never know when we're gonna miss something and we're gonna have to roll back. The other thing that I thought was big deal was the fact that Convault is integrating identity protection into their platform.
'cause one of the things I think that a lot of people are missing out on is that you can get infected and you can clean up all of the servers, but if the attackers penetrated into active directory, they've got a foothold, they can just keep coming back. Like, what if they changed the password on backup operators and added themselves as a unknown user, or worse yet at one that looks like a system account, they can just keep coding back in and doing everything they want to do, and you're just gonna have to keep rolling back. Only now they're watching you roll back in real time and they're combating all of those rollback points.
So eventually you're either gonna be forced to pay or you're going to be extorted for whatever else and have your data dumped. So I like where Commvault's headed with this. Uh, the, the name change of course is important because we're unifying resilience into the platform.
And, and I'll admit some of the commercials in the keynote we're kind of cute. I kinda liked it. Uh, so make sure you stay tuned for more of that.
And also we've got some great content coming out from the people that attended, not my just myself, but Jack Poller and, uh, Jay Coutre and More Great Field Day delegates. So make sure you're tuned in for that. We're going back to AWS because they also have something else they came out with.
It's their Kero AI coding tool that has new features aimed at producing more reliable, secure, and testable code, including everybody's favorite, A CLI version. It also has proprietary based testing to validate behavior against specifications and the ability to rewind to earlier checkpoints. The update also enables Kero to work across multiple project roots and support custom AI agents while qualifying startups can get a free year of Kero Plus Pro Kero.
Pro plus AWS engineers say that these enhancements promote a more disciplined, specification driven workflow that reduces debugging stress and scales AI powered development with quality rather than speed. Al I kind of like the vibes on this one. Is kiro gonna turn the corner from letting AI just kind of write whatever looks good?
Well, I think that's fundamentally what Kiro ISS all about is not having those vibes, um, moving to a, a position where you write the specification of how your application should work and the AI implements what's written in that spec. Uh, I haven't gone hands on with this. The preview was, was launched in July and, uh, has has got a bit of buzz around.
I've, I've heard a little of people using it and I say, I really like the idea that there is a more declarative way of working here. This is define at the beginning how the software should work and then validate that it does work. Uh, in some ways it's, it follows a little bit of, of what I liked in the test driven design methodology where you first test for the functionality that you're going to build and make sure it fails 'cause you haven't yet built the functionality and then you build functionality until you, uh, pass the test.
Uh, that is one of the ways of going around. Let's design how things should work and, and make sure they do work that way. Uh, I definitely, this, this testing by properties is a really good functionality in here as well.
This is the ability to say this particular function should have this, this result. Now build a set of tests that, uh, somebody walks into a bar and orders a beer, orders 99 beers, orders minus one beer, uh, orders a car. Uh, does the software do what it's supposed to do?
That, that kind of building those use cases, uh, those tests. So unlike test, different development where you build those first, the property test approach builds those from your specification of how things should work. I like that whole declarative behavior.
Uh, and then the ability to work with larger projects, integrating Kero into your pipelines by using that CLI rather than having to do everything through a, uh, a, a click ops. Absolutely. This, this kind of stuff is where we're gonna see value in actually building real applications that are supportable and maintainable in the long term.
Yet don't require the vast number of developers hacking on little bits of code and particularly repeated bits of code over time, uh, remains to be seen how the pricing works versus value on this. And whether a WS can continue to deliver this, uh, ai, almost ai, um, for, for the long term. Uh, there's, there's a lot still to be written about the cost of delivering these things versus what you can charge people for them.
So we'll keep an eye on it. Over time, Arista and Palo Alto networks are expanding their partnership to address the rising hybrid data center complexity. And of course, AI driven cyber threats.
Uh, integrating Arista's, uh, collection of product di Ava MSS with Palo Alto's own Next Gen Firewall and, uh, Prisma Airs. Uh, they offer a unified zero trust, uh, security and realtime threat. Quarantining centralized policy management, always my favorite.
And DevOps friendly automation, delivering scalable, consistent protection across multiple data center and multi-cloud platform, uh, environments. Uh, this sounds like there's a partnership between uneasy friends and that hopefully this is gonna be magically wonderful for customers. It should be wonderful for customers because when you look at what people are doing, especially in the cloud environment, they're leveraging a lot of Arista switches.
That's where Arista has made a lot of their money over the last few years. But one of the things that Arista's having trouble getting off the ground is a security practice. They've purchased a number of security firms over the last few years.
I don't necessarily know that they've really taken off as much as we might like. And so what do you do when you can't really build it? Well, you gotta buy something.
And in this case, the buying is involved in a partnership, but they picked the best one on the block, right? Palo Alto Networks is one of the, if not the premier security firms in the business, right? They have next gen firewall.
They have a lot of cloud security offerings. What they don't have is an inroad into those clouds through the networking team. Because as more and more people are starting to recognize the fact that networking security are two sides of the same coin, how do you displace existing installations?
Well, in a lot of cases you have to partner up with a company who's displacing other things out of the network. Arista made their money displacing Cisco. So how do you get into that network now that Arista has displaced them?
Well, you partner up with Arista and Arista says, well, our stuff works really well with Palo Alto. If you've got a refresh coming up, now's an opportunity to take a look at it. I will say though, that when this announcement was made, there were a lot of eyebrows that got raised because historically these kinds of partnerships lead to more engagement down the road.
I'm not going to say the a word because that would be speculative at this point, but if there was a transaction to be had, this would not be a bad place for it to occur because both of these companies are very well known in their individual spaces, and I think wrapping them up would be a very unique opportunity for some people. I don't think that that's gonna happen anytime soon though, because while Palo Alto is sitting on a lot of money, a wrist is worth a lot. And I don't think that this is an acquisition that they could really swallow in whole yet, but it would be very complimentary.
And, uh, quite honestly, I, I'd I'd love to see, uh, someone like Akin do to doing some Palo Alto presentations. 'cause that could be real fun. Microsoft announced yet another major new AI partnership with Anthropic and Nvidia, but this is signaling a move beyond the once exclusive ties that it had to open ai.
Andro will buy $30 billion in Azure compute while invest Nvidia invests up to $10 billion and Microsoft up to $5 billion to help scale Anthropics clawed AI models. This deal gives anthropic massive Nvidia powered capacity and strengthens Microsoft's AI infrastructure strategy as its relationship with open AI involves at Microsoft Ignite, which is happening this week, they also introduced a new IQ lineup of AI tools, work iq, fabric IQ, and Foundry iq, as well as Microsoft Agent 365, designed to automatically support business workflows as companies prepare for future of billions of AI agents. Al I think it's interesting that we've always heard so much about the partnership that Microsoft has with open ai and now they're going out and seeking out anthropic.
Do you think Microsoft's playing the long game by betting on different horses or is there something else going on here? I think this is definitely a, a hedging strategy. So we covered previously on the rundown that OpenAI pre had had an exclusive deal with Microsoft that OpenAI would run on Azure and that Microsoft would use OpenAI as its standard AI powers, things like co-pilot.
We covered that. This tight deal had come to an end and there was a much lucid deal where OpenAI could use other vendors and we're contracting to use other vendors to provide that infrastructure and that Microsoft is free to work with other vendors. So Microsoft has always been the king of partnerships partner with everybody.
Uh, I see this relationship with, uh, anthropic as being part of that. They recognizing that there is no longer an exclusive relationship. They need to have a real, real relationship with a competitor to open ai in this case anthropic, and it's all part of the same partner with everybody and make sure that nobody can hold you to ransom.
So OpenAI can't say to Microsoft, well the, this is the only feature set you get because this is what we're, we're doing. Uh, Microsoft has then no leverage to say, well, we want this other feature we need for co-pilot as they make a commitment into Anthropic. Yeah, it absolutely gives them some more choices in there, uh, naturally enough, this is the AI money go round, and so Nvidia is in here as well.
And Nvidia investment in anthropic means that Anthropic will hand back some of that money to buy Nvidia hardware. So when we talk about this as a money go round, it really is money changing hands back and forth in some of these places. Uh, Microsoft continues to, uh, put money into this, uh, $5 billion, uh, invested here.
So it's not a trivial amount, but it's not the $30 billion, $60 billion we've seen in in other deals along the way. Um, and Microsoft has $13 billion in open AI investment. Uh, it really is, I think, a, a protection against, uh, open AI choosing their own path.
We've seen some interesting challenges with open AI as they wanna change their, their governance and structure around there. Uh, if that represents a risk to Microsoft, connecting up with Anthropic seems like a great way to mitigate that risk. Uh, we'll see just over time as, uh, whether this continues to grow, we see more and more money being put into, uh, anthropic and maybe a, a dial off on OpenAI.
I don't think so. I think this is really a protection of the relationship with OpenAI. Newly uncovered cyber attack shows the first large scale espionage campaign carried out mostly by ai.
A apparently Chinese state backed group used AI agents to handle up to 90% of the operation, so including scouting potential, uh, victims and exploiting vulnerabilities in stealing data. Uh, the incident highlights the rapid escalation of AI driven threats and the need for strongest safeguards around these AI attacks, better detection and also industry wide cooperation in as near real time as possible to protect against these attacks. Tom, uh, this is another arms race, isn't it?
It's AI for attack and AI for for defense, Yeah. And that's exactly what we talked about on this week's episode of Security Boulevard because it really did feel like this is kind of turning the weapons back on the creators a little bit. I also thought it was a really fascinating way that they were able to kind of slice this attack up so that multiple Claude agents were not actually knowing what was going on.
It was almost like a operating in a compartmentalized cell structure so that each of the agents were returning work that was then being tied together by other agents to do the actual exploiting so that it evaded all of the models jailbreak capabilities of saying, oh yeah, we're not gonna do bad things. You know, theoretically it'd be like, you know, the difference of me asking how do I rob a bank versus describe what good bank security looks like. Uh, one of those things would probably set off a trigger while the other one when used improperly would probably get me the answers that I need to know how to avoid security cameras and guards and things like that.
Uh, also, uh, the, the press release from Claude, uh, I'm sorry, from philanthropic about Claude was rather interesting in the fact that they said, well, we detected it and we stopped almost all of it, but almost all of it ain't all of it. And it, some of the attacks did go out, and of course now they're probably going behind the scenes to try to figure out exactly what was used to bypass the filters and the protections and how they're going to evade it in the future. And, uh, I I think that we're just, we're starting to see the tip of the iceberg here because this is probably not the first one that we've seen, but it is definitely the first one that somebody is reporting about.
So, bravo to philanthropic for at least admitting that this was going on. But I think one of the things that we're gonna see as this goes on more and more is that people are gonna refine their prompt engineering. They're gonna be able to break these tasks down into finer and finer detail so that it really is going to become impossible or worse, yet they're gonna take the outputs from one group of AI and feed it to a separate set to actually leverage the attack.
So that attribution is gonna be very difficult to trace down. And I, I don't know if there's a clear cut answer here, because the real thing that people are saying we need to do is lock it all down so that it can't be used for attack. That's like saying, oh, well, we should get rid of all BCRs because they're only ever used to record, you know, copyrighted programs when that's actually not the case.
Uh, we just, we have to find a better way to figure out how to use them. All right, we wanted to take a closer look at a story today. Uh, it took us a little bit while to write it, of course, because there were some internet issues.
Everyone's favorite web infrastructure provider, CloudFlare had a massive global disruption that caused error 500 messages and took down major platforms including X Twitter and chat GPT along with most other AI platforms. The outage, uh, triggered by a sudden spike in unusual networking traffic impacted thousands of websites early on Tuesday morning and highlighted the fragility of internet architecture. 20% of global web traffic flows directly through CloudFlare.
The firm is actively investigating the root cause and working to restore full service while underscoring the need for greater resilience and digital infrastructure. And I think it's kind of funny that we've run into this problem, uh, recently al where DNS updated an AWS took down one half of the internet and CloudFlare getting knocked offline by a massive traffic spike, uh, took out part of the rest of it this week. Uh, you know, they, they're still attributing what exactly went on.
We know that CloudFlare is gonna give us a great postmortem when they figure out exactly what happened, but I want to turn it over to you and maybe ask, are we putting too many eggs in one basket by relying on CloudFlare to protect us? Because when CloudFlare goes down, we can't get anywhere. So here's the thing, CloudFlare is very popular because it does a great job of a very specific task of delivering applications globally, uh, to your users in a way that gives them really good performance anywhere in the world.
CloudFlare has built an amazing network to do this and let's this in context central everything on cloud Cloud. We certainly don't often see CloudFlare outages of this scale. So yeah, the outage is extremely visible the same way any of these centralization outages are extremely visible, but they're very rare.
And so when you look at what is the impact on the total uptime of whatever system you're using, you'll still find that even with the, this particular failure or this type of failure, uh, you're still getting higher availability and better performance for your users across the, the last year than you would've if you ran this yourself or you tried to do some equivalent of this. So yeah, centralization means it's very visible when things go wrong, but centralization means you can spend a lot of engineering on making sure they don't go wrong often. One of the things I've read on this, and, and it came across Reuters, is that the, the sort of triggering event here is an automatically generated config file that got too large and then caused a service to crash.
Um, this feels a little bit like what we saw with CrowdStrike where a config file was deployed out and that caused the massive outage for, for, um, CrowdStrike. Uh, it seems like these config file changes need to run through A-C-I-C-D pipeline to validate they're not gonna cause problems, yet we need to deploy them out fast. You're the eternal optimist, al, and that's what I love about you because I, I took a, a slightly different, uh, tack from this and it come courtesy of our friends at down detector, you know, the website that everybody goes to, to figure out when you're having problems with stuff.
Oh, wait, I couldn't check that one either. 'cause it turns out it runs on CloudFlare. Yes.
I, the world is better off because CloudFlare is frontend sites and preventing massive DDoS attacks, and their engineering has done a really great job of helping us extend and expand the way that that web works. And, and a lot of other things too. They're effectively the Internet's proxy layer at this point.
1 from the trash heap of history, uh, because of bad configuration stuff. All that being said, you cannot put all of your eggs in one basket. And, and we've learned that from a lot of things.
I mean, all you gotta do is just look up the infographic from the XKCD of, you know, the entire modern internet. And then there's a little thing down there, a little Jenga piece, and it's insert name there, AWS CloudFlare, uh, n engine X, whatever. What we're starting to see is that when these outages do happen, they happen at a a, a level that is difficult to contain.
And you mentioned CrowdStrike, we've talked about AWS before. Um, there are a lot of challenges that happen when we've built something that is effectively too big to fail and more than any other company, I think CloudFlare is pretty strict in the way that they deploy things, in the way that they, uh, leverage stuff. I can't fault them for this.
How can you figure out, oh, the config file got too big. When do we test for that? How do we understand that the problem is not the outage itself, it's the rolling effects from that outage.
If, you know, it went down for 10 minutes, everything that checks on CloudFlare kept pinging, it kept going offline. You know, little things that you didn't think were reliant on that. I was having a meeting first thing this morning and went to go check the calendar on somebody's website.
It's offline, it's hosted on CloudFlare. Like, oh, well that's fascinating. And so you've got to figure out how to prevent this from happening.
Yeah, in some cases, you, you probably do need to have your, your load balanced infrastructure running on it, but I don't know, maybe put your status page somewhere else, host it somewhere that nobody goes like Oracle Cloud. So you're, you're suggesting to avoid the, the problem that a WS had with outages when they had the big S3 outage and the, uh, the website at AWS that reports on the status of a WS services is dependent on the S3 service. Uh, yes, circular dependencies like that are really problematic, but, uh, yeah, I I still view using a, a well engineered system that is designed to continue to operate at large scale Absolutely as is way better than any of the other solutions for this.
So yeah, I, I'm still comfortable with putting our websites through CloudFlare, having even trivial things go, go through CloudFlare. But yeah, the tool that tells me whether things are working or not can't tell me if they're not working, if it's dependent on the thing that's not working. Yeah, mi mindful of circular dependencies.
The other thing that that strikes me on this is that there's, there do seem to be a lot of circular dependencies that go through cloud flap because what we didn't see is when the, the issue was resolved, everything miraculously started working again straight away. It took a little while for it to filter through the various layers that are dependent on CloudFlare before all of the layers caught up with one another. You know, this eventually consistent, uh, systems that we usually see at internet scales, uh, would be interesting to see if you had centralized everything into a single place, rather than having these eventually consistent distributed systems, whether the time to get back into operation would've been longer or shorter, because of course, in a centralized place, you have to replay everything in a single stream.
Whereas when you're doing eventually consistent, you're replaying in different locations and your total timeout might be lower. Something that's not gonna be affected, I hope by any cloud outages, any security outages. Um, now I'm gonna have to make some sacrifices To all of the good luck Gods, something that I expect not to be affected is AI infrastructure field day four.
That will be my next return to the United States January 28th and 29th. The event is already filling up. We already have, uh, four companies confirmed to be there and we're expecting a few more to roll in as well.
Uh, really looking forward to kicking off 2026 for Tech Field Day with AI infrastructure field day. Uh, and then of course, Tom, you're going a long way afield as well. That's right.
We're looking at the possibility of heading over to Cisco live in Maya, which is gonna be in Amsterdam once again this year. You know, I can't get enough of those little teeny tiny pancakes. com is gonna be, uh, your home for that.
So when Al flies halfway across the world, I fly the other halfway across the world. But then Al you're you're coming back in March? Absolutely.
I can't stay away. Uh, I'll be back for Cloud Field day 25 in, uh, the middle of March. Uh, and those tiny, uh, pancakes, the puffs, uh, my Dutch, uh, sister-in-laws, uh, gave, gifted us the pan to make them.
So maybe come down, visit me and we'll make you some tiny pancakes. Uh, what isn't tiny, of course, is the tech field Day rundown. Do join us, uh, continue to join us for the Tick Field Day rundown.
You can catch new episodes every Wednesday, either as a YouTube video or in your favorite podcast application. Rundown streamed on Tick Strong tv. Of course, that's part of the Futurum Group, and you can find us on both Techstrong and Rum Group, uh, locations.
We'll be back next Wednesday to talk about all of the ITT News for the week. That was, and until then, for myself and for Tom Hollingsworth, and for Corey and all of us here at the Tech Field Day team, we're wishing you and yours a great day, great week, and we will see you on Wednesday. Hey, everyone, those DDoSs just keep getting bigger.
You are watching Textron Gang. Hi, everyone. Happy Tuesday.
It's gonna be a short week here on the Gang. It's the US holiday of Thanksgiving. So a lot of us might be heading out to visit family or heading home to have family visit us, but we probably, I think Wednesday will be, uh, our show, and then we'll do one for Friday.
Um, but be that, whether you are taking off of the Thanksgiving holiday or not, we're glad you're watching and joining us today on Textron Gang. As we kick off our Tuesday coverage, let me introduce you to our fantastic gang that we have for today. We have, uh, our friend Steven FoST, also our friend, jp.
They're all our friends. They're all gang members here, JP Morganthal, hope Lynch and Y Genni, and give Genni. I always mess up your last name, but it's Caram.
And then of course, the dean, Mike Ard gang. Welcome. We've got a lot to go over today, so let's dive right into things.
You know, over the years, I, I don't know, maybe it's this, that spectator in me. I love to see how many, how big a DDoS attack can get, right? They've grown over the years because, you know, we have, we have organizations like Akamai and CloudFlare, these big CRNs that can diffuse these, you know, often terabits of, of, of, uh, of traffic that these DDoS storms create.
But it looks like maybe we got all, we, we hit another new, I don't know if it's an all time high, but evgeni a major attack against Microsoft, uh, by a particular, you know, and, and these, it's botnets that really, you know, create these storms. Evgeni, what can you tell us, or Mike, do you wanna kick us off and we'll go to Evgeni? Yeah, yeah.
Just the facts of the case are, um, at least Microsoft is reporting that, uh, I think more than 500,000, basically a half a million IP addresses were involved in this attack. And these things have been steadily increasing all year long. I mean, it seems like there's now a leapfrog to kind of make the next biggest DDoS attack, and it seems to be happening at a rate of almost, you know, a new record every two to three months or so, Afghani, is that what we're seeing?
But is all this eventually gonna build to the point where, we'll, maybe we will take down the internet? I don't know. But what's your concern?
There's a couple of things that's very, very interesting. If it go 10, 15 years ago, we Adidas attacks there as well, but the difference that we used to implement a DDoS devices on-prem, now it's not gonna be possible because the device on-prem, it's still very, very related to the amount of traffic and the throughput of the internet you have. So you have to have a DDoS protection in the cloud, whereas the pipe of the provider will be much bigger than the pipe of the end user there.
So companies like Akamai, company like CloudFlare, or Rod and many others, F five as well, have a cloud approach because we need a bigger pipe to be able to clean. And this become very interesting because we basically switch the way we protect users. Also with DDoS, we can do protections that on demand or protection all the time, depending on the cost as well.
And if you look on Microsoft, guess what, they're not using somebody else, at least as far as we know, they have their own protection. Same with AWS, same with GCP. And it's a quite a big shift that some of the bigger companies decided to build their own protections like the clouds, the Azures, the, uh, the is instead of using somebody else.
So this is definitely a shift because they need to provide and protect their customers and protect themselves as well about the size and the scale. We not always like to talk about ai, but the majority of the previous attacks, the bigger ones that Mira Botnets were not controlled by ai. As far as we know, you are controlled by humans right now.
Guess what? We may have a human that control some kind of an AI system that can now much better understand where to attack and how to shift that attack as well. And I think this was, we're gonna be seeing, we are gonna be seeing DDoS attacks that are managed by some kind of AI entity to make them smarter and able to shift them and maybe avoid the defenses of the, the target.
Interesting. You know, I, I think one of the problem, not problems, it's not a problem, but I think one of the issues we have when we talk about how do we wanna defend against DDoS attacks is the fact of the matter is most DDoS attacks do not bring down sites anymore, right? It used to be, you know, Microsoft went dark for a couple hours, or Google was brought down or what have you.
What happens is it is, for most of us, DDoS has become a sort of minor annoyance. I mean, even here at Tech Trunk, right? We operate Security Boulevard, it's security site, cyber site, and it's pretty well known against a lot of views.
And so it's a frequent target of the bad guys because we're always publishing cyber stuff. And, you know, I'll get notified from our providers once every two, three weeks, Hey, we, we blocked a DDoS attack against the Boulevard today, right? And here's, here's the, you know, the metrics and so forth and where it came from and, and we, you know, and they put it into their normal, you know, uh, crime fighting kind of, uh, system there to try to figure out who did it and what's going on.
But, you know, and I may see the slights a little sluggish sometimes. Sometimes we don't even see the slight being sluggish. So it, it's kind of the, I I I analogize it to, you know, credit card fraud.
Most of us never are victims of credit card fraud in terms of it really cost us money. It's just a pain in the butt. We gotta file a claim with the credit card company or the bank, and they credit us back on our account, but it really doesn't cost us anything out of our pocket.
It's just an annoyance d Interesting analogy, but don't think about that. It's because we shift from on-prem protection. You're no longer protecting your website here.
It's down somebody else mm-hmm. Upstream. Yeah.
Right. And that's exactly it. We've, we've put the burden on someone else and let them worry about it.
And I think for a lot of us, that's what DDoS has become too. But I also, I also wonder in, in listening and thinking about this, um, yes, years ago you probably had an appliance on your network, but now it's up to the hyperscalers. But I think also part of it is them offloading risk, right?
So if I want to be safe, maybe I think, oh, I migrate to cloud instead of, you know, being part of the open and decentralized, uh, seemingly more fragile internet while the one that's controlled by the hyperscalers is more resilient. And also, um, there are a lot of companies that if they were still having appliances on-prem, it would be older legacy hardware, forget about regulation updates and all of those things, they probably would still be more vulnerable. Um, so I think a lot are just offloading the risk to the hyper.
Yeah, I mean, it makes sense. But let me, let me tell you a another side and a victim of this, right? Because how do you, how do you block DDoS attacks?
Basically, you, you filter out the ips that are attacking you, right? So we're getting, whether it's a ping or, you know, whatever kind of traffic you're sending me, I say, okay, this ip, you know, Steven's IP is sending me a lot of garbage and I'm gonna filter it out. I'm just gonna filter out Steven's ip.
But Steven's not sending that on purpose. Steven's Steven's machine was zombie, right? And so, unbeknownst to Steven, his machine has been added to this botnet, and it's, and it's, you know, flooding my, my pipe.
And so I blocked Steven because he's flooding my pipe, you know? And Steven deserved. Now, Steven didn't deserve it.
What did he know? So, but, but, but now the problem is, is when do I turn Steven back on? And how does it impact Steven being blocked as a, uh, uh, one of the bots of this bot?
That that's that, yeah, that's a really interesting point. And I, you know, I I, I've thought about this before, and as you started speaking about it, I started to think about if you specify any time period, then the, the attackers are just gonna learn what that time period is and start re and turn back that node back on with it after that time period. So it's, now you need an a, a process to go through to get validated again, to get cleaned.
But I mean, sorry, it's like an STD, you should have to go to the doctor and get cleared before you get Back on. I, I didn't have that on my bingo card, jp. I gotta be honest with you, Steven, is this, what did they say, Steven?
He was, in fact, I'm sorry. It, it's a, it's, it's an appropriate level comparison because his machine was infected. I, I gotta say, I was enjoying this conversation until that jp um, you know, I, I swear it wasn't me.
Um, mm-hmm. But it, it's, you know, it is, it is funny 'cause the, um, the fact that most of these botnets are now using consumer IOT devices. You know, one of the things we pointed out in the article, for example, is that the, the rise of fiber to the home, uh, has made these all the more potent, because even a low powered, you know, device, an IOT camera, a thermostat, DVR, you know, router could, um, participate in a DDoS to a much greater extent than it could back in the old DSL days or something, you know, but I agree that I, I've always felt like some things belong in the, in the network, and some things belong on-prem.
You know, email is an application that belongs in the network. Uh, web servers belong in the network. Why?
Because, because they're accessed that way. Whereas, you know, other services belong on Preem DDoS mitigation strikes me as something that belongs in the network, and it, it, it should be something that companies like Akamai and CloudFlare and yes, Microsoft are working to mitigate rather than something that we individuals have to fight off because it's, it's really an internet problem. It's, uh, you know, like your, uh, uh, distasteful analogy, you know, there's a point at which a, um, a, a disease goes from a personal problem to a social problem.
And I think DDoS is a social problem. So we have to have companies like CloudFlare, for example, mitigating this. But that being said, think about last week's news about Cloudflare's outage.
One of the reasons that it impacted so much of the internet, including all of my sites, including all of our sites, is because we rely on cloud or CloudFlare for DDoS protection. And so by doing that, we're essentially putting all our eggs in this very one big, very capable basket. But that does open us up to other issues.
And, and I could see a situation where one of these botnets successfully DDoS is, you know, a, a CloudFlare, Microsoft, or Google, and that would be really damaging. So at what point though, am I, am Danny, work me through this, William, because it seems to me like I'm at half a million IP addresses. I'm probably this time next year gonna be seeing attacks involving a million IP addresses, and can I block a million IP addresses and figure out when they should be turned back on?
And remember, there are multiple DDoS attacks out there. So, um, at what point is this just gonna become unmanageable? So somebody need to run and manage this vidos attack.
I believe we already have some kind of an AI operated or half AI operated system that help me to run this attack to be more manageable on the bad guys. This is gonna become the part on our side, on the good guy side as well, to use some kind of intelligence, artificial intelligence to help us understand what to run. Now, when we say block these ips, we are blocking them to access our sites.
It doesn't mean we're blocking them to access other sites. We're potentially making them this IP higher on a blacklist, and then maybe we're gonna block in for SAPs, or the reputation will go down because you have reputations leased everywhere else as well. So there may be potentially gonna be blocked somewhere else.
For example, if I'm a small business and from my ip, a DDoS launch, my IP reputation now goes higher or better, whatever you wanna say this now, potentially my email maybe blocked or other connections from me, maybe blocked somewhere else. But to answer your question, we'll need a more sophisticated system to understand how this attack evolve and to block it as well. So we will need to find a way, and majority of the vendors right now use AI in one way or another.
Not many people talk right now about AI-based DDoS protections. We have firewalls that are more AI aware right now. DDoS and ai, I didn't hear yet, but I'm sure all the providers have something that helps them evolve.
That makes sense. I, I know someone who you can call to help you. I, in, in, uh, doing a little research for this.
So I, who they say are responsible for it, one of the prime people, he's based in Brazil, not only is he part of the attackers, but he runs a DDoS mitigation service. So, So he's playing both sides. The united, You knows how he attacks and he knows how to defend.
Well, those are the best guy. Those are the best. Isn't That like, just morally wrong?
I'm sorry. Let's clarify. He's setting the house on fire and putting out fire.
So Yeah, it's good. But, but you know, it does bring up the issue though, that these botnet networks are oftentimes run by, um, pseudo, uh, state, you know, country, state actors, or at least supported by, uh, state actors. And, you know, now we, we have seen in the past, uh, police activity, law enforcement activity against some of these botnet operators where it made sense and they've taken them down.
Microsoft's done a good job with that. There's always one to pop back up on this. Yeah, well, that's the problem.
It's a bit of a whack-a-mole game. And That, and now all these hacktivists are renting those services to bombard anybody that you happen To disagree with. Well, yes, you can rent, you could rent a DDoS storm.
What JP said About me earlier, I think I might rent a DDoS. Jp, what's Your address? Uhhuh, I think you're taking this a little too personal.
Well, no, but Steven, the, the key is though, after you DDoS him, then you come in and offer to, to, uh, Oh, so the, to defend So the old mafioso. Yeah, exactly. I break, I have a kid break your window and then I Up.
Right? You shame of something happened, right? Yeah.
Uh, but, but you know, to Steven's point earlier about IOT devices, you know, you have Amazon, you have Google, right? They're, they're hosting the network services for a lot of these devices. I, I, hopefully they're smart enough and, you know, their equipment is becoming enabled, uh, with, you know, enough compute power and, and os that it could be compromised.
So I hope, I mean, I hope they're smart enough that when these devices are coming online and connecting back home, that they're doing so through a VPN level connection, I, we don't know because we don't own those devices. We can't see how they're connecting. But think about, and I don't mean to pick on them, I don't know anything about them, but Honeywell, my, my, my, uh, thermostats connect back to Honeywell.
I haven't seen Honeywell in the news talk out and stepping up about their advanced capabilities for security and DDoS protection. They're now, maybe they're delegated through a Microsoft and partnership or Google partnership to protect themselves. But Honeywell's now the risk is on them.
They're the ones who are capable of now opening up, uh, potential for IOT devices on their network to be compromised. Yeah. Well, and to that point, I think a lot of these companies with IOT devices are finding out that this is a challenge.
Um, I'm pretty mad at BMW because they shut off third party integration with their connected drive experience, uh, last month. The reason they did that is because it was, uh, realized that there was almost no security on it, and anyone could find out the status of anyone's car and, uh, actually write, uh, settings including unlock to anyone's car. Uh, that's not great.
And so they shut it off immediately. And I think that, you know, there's a lot of abandoned wear out there. There's a lot of just, just garbage out.
There you go. You go buy an iot, you know, an off-brand IOT switch or thermostat or something. You don't know how well that's protected.
It's probably not. And it's certainly not gonna get any kind of security updates. Uh, that's the world we live in.
And I think a lot of respectable and responsible companies, like I said, like BMW, I'm kind of mad that they shut it off, but I'm glad that they did too, because I'd rather not have my car unlock by somebody over the internet. So, wait, is there an opportunity here for somebody to, I don't know, sell a managed botnet? Let's not use jps metaphor.
Let's go with extermination service so that I get rid of all my infected devices and, you know, I'm just gonna pay extra for the privilege. Or is this something that just, you know, I'm the cdm, Nobody gonna pay for this. Like, think about that.
Well, somebody need to pay for this government who, you know, which government, We don't own the devices, right? So, uh, I, I don't have access to my Amazon doc. I can't get inside it.
I can't, you know, uh, exterminate anything that's in it. I can't, it's not on me, Right? And, and so this, and we don't have time 'cause we're way over time on this, but if you look at the, it was DigiCert and a bunch of people put together an industry consortium for these connected devices.
And it, it starts with, it starts with each connected device having its own unique MAC address and its own unique certificates, PKI certificates, and so that you can reach in and control individual IO OT devices, but only if they've been built to do so. And, and there are several industry consortiums around that. I, I've actually done some work in there over the years, but, um, at the end of the day, they're all still connected.
And the bad guys always seem to find a way. But we gotta take a break. This is a great conversation, great topic, but we're gonna come back and we're gonna talk about the Tennessee Titans.
No, not those titans. Different data center titans. You're watching text, drug gun, You've earned it.
The spotlight, the responsibility, the weight of teams, companies, and entire industries fall on your shoulders, lives depend on your decisions, your home life included that work. You are protected physically and digitally. Nothing gets through your team without a fight.
But in a globally connected world, everyone sees you, including those who mean to cause you and your organization harm. And now home your sanctuary attackers see an opportunity. Your digital front door is wide open.
And what compromises your home can breach your boardroom. Because the devil's greatest trick isn't targeting your workplace firewall. It's convincing you that your personal life isn't at risk.
Black cloak, digital executive protection, defending the new attack surface your personal life. Hey folks, we're back in. Yeah, we're talking about Tennessee home of the TVA, and turns out there's a report that says that the state of Tennessee, followed by Texas, is now number two for AI data center deployments.
And of course, you know, California and Virginia are probably number one and two overall. But it's interesting to see that there's been a shift in terms of where these AI workloads are showing up. Jp, did any of this surprise you in here?
And are we using, you know, government funded electricity to drive these data centers in Tennessee? It, it wasn't, it was a little surprising only because, uh, geographically, my experience was that North Carolina was on the rise. Uh, back when I was, uh, at EMC, um, there were a number of data centers that were being built in North Carolina, all very modern, the access to the cooler temperatures, uh, fresh water, uh, and electricity, you know, made them a optimal site for building out data centers.
Now, it seems that people have found, uh, that Tennessee also meets the same requirements. You know, it's like, um, a little bit like, you know, the old Star Trek or, uh, sci-fi shows where they're out there looking for a planet that meets your, you know, needs for life and support. You know, if we find the place that, you know, they're gonna settle it, and, you know, to the matrix point, right?
They become parasites and start to overpower and destroy the environment. Uh, and that's what the report kind of is saying. It's like, all right, you know, these, uh, these, these beasts that are, uh, in need of massive compute power, especially around ai or identifying, you know, environmentally good places to put a data center, uh, that supports their needs, but they're destroying the environment that is around it.
And, uh, and these are, uh, uh, areas that are impacted by climate and other events that are going on. And the recommendation was, you know, for, you know, start looking at places that aren't so environmentally impacted like the Midwest. Uh, and of course, you know, the Midwest has its own issues for why it hasn't, you know, risen up with regard to becoming a, uh, titan of, you know, support for building out these facilities.
And, but the reasons are, I I, I to the, and I agree with their report on this is, is because, you know, it's easy. It, it, it, you know, I have everything I need to run my data center in these areas, so it makes sense for me to do it. It's more work to do it.
And obviously a little costlier in the Midwest, but I, I do less damage to the surrounding environments. And, uh, I think you're going to, and it would take regulation to force these companies to start to, or, or incentive. I mean, the states that one of their, uh, one of the, um, uh, suggestions was the states should be incenting the businesses to come there.
And by helping 'em and partnering with them, I think they should. I, I do think it's that, you know, these other areas are being inundated and it's over. It's starting to overwhelm the environment.
Well, Before we go any further though, I just gotta say this, Mike, the New deal called they want their TVA back boomer, I don't know how many people out here actually know the TVA or how big a, a player it is in, in the energy, uh, energy space, you know, creating electricity. But Stephen, I thought Ohio was the new data center capital. What's going on?
I ain't the governor of Ohio. What Do I know? Lucky For you.
No, I, and for us, Yeah, I think I'm gonna miss out on that election too. Um, but I, I would point out that, uh, there's actually a very specific thing happening in Tennessee, and that is that in Memphis X AI is building the world's largest GPU powered supercomputer, the Colossus. 2 million, uh, GPU chips being, you know, that have been deployed in Tennessee.
Well, um, publicly, 200,000 of those or, you know, are, um, part of a single, uh, AI supercomputer run by Xai. And so that is, you know, a significant proportion of that entire footprint. Now, obviously, there are others as well, and we're seeing build outs and data centers everywhere.
But I think that the fact that X AI has, um, focused on Memphis specifically, they've got at least two data center locations there, they have at least two, um, colossal AI supercomputers deployed there. Uh, that alone, that single investment could skew the results and skew the conversation we're having. You know, maybe apart from that, it's Indiana, Ohio, North Carolina, whatever.
It certainly wouldn't be part of the equation if it hadn't been for X ai. And I should also point out that that's been very controversial because, um, despite the fact that on their own homepage, they have a community and environmental responsibility page, uh, the community seems to disagree with the level of community responsibility and environmental responsibility they've shown there, uh, using, uh, things like portable gas powered turbines to power their data center rather than, you know, because they can't get enough grid power in there, things like that. And, um, I, I, I would say, you know, there certainly is a conversation to be had, but, um, it's an example of what happens when companies are allowed to essentially shop jurisdictions for these data centers.
They can go around and they can say, you know, who wants it? Who wants this kind of investment? Uh, Memphis raised their hands.
And so, you know, here we go, Xa, I poured it in there, and suddenly Tennessee's on the map next time, you know, maybe Des Moines will raise their hands, or, you know, Albuquerque. And then what? Well, then we'll have somebody else on the map.
And, you know, I think it shows frankly, a, a, a weakness overall of, uh, governmental planning and, um, environmental planning, uh, site planning, power planning, that these things are just being built sort of wherever they can build them, and that, that shifts the landscape so deeply. So is it safe to say we're walking down to Memphis? Sure.
See, I was gonna do a whole, oh, brother, where Art thou, they're building the dam. They're lighting up the whole valley. It's gonna be a new South, You know, uh, so, So, so wait, can we, so there's an economic cost here, right?
I mean, if I understand this correctly, the value of the real estate around the data center drops, and then of course, the data center, people buy it even cheaper, and more people are mo gonna move to places where there are not data centers. So the value of real estate will go up in places where there is no data center, because more people who used to live next to a data center are trying to move in there is this wouldn't get with. So I, I don't think that that's really what happens.
I think that basically the underprivileged people who live where these things are built can't move and don't have any, uh, you know, real mobility opportunity. And so they just get stuck with breathing bad air and, uh, listening to loud noise and paying more for electricity. It's the love canal, say job.
But, I mean, but le let's be fair though, you can't blame Memphis. You can't blame Ohio or North Carolina, or, or Abilene, Texas, or any of these places that are, you know, bending over backwards to welcome in these data centers because, you know, they're being, they're being, uh, romanced and courted by millions, tens of millions, if not billions of dollars of investment locally, the promise of major jobs. Even though we know that these AI data centers are not very labor intensive in terms of job creation, uh, you know, the, the federal government is patting them on the back saying, go for it.
Go for it, go for it. And they're in competition. Memphis doesn't wanna lose to Nashville.
Nashville doesn't wanna lose to Charlotte. Charlotte doesn't wanna lose to Raleigh, Texas doesn't wanna lose to California, and none of us wanna lose to Mexico. And so, you know what, what's the right answer here?
I don't know if there's a right answer. I have a question that I would love to get your opinion on. Um, so right now, AI data data centers are being called critical national security infrastructure, right?
0, but the Pentagons, a lot of the cloud capabilities you've seen the contracts that, um, Microsoft and AWS have inked with the US government, but you've got, um, military national security running on commercial infrastructure. So they are depending on the same data center, maybe that, you know, is, is is giving me Netflix, right? But now we have the power consumption concerns.
And for years they've talked about fragility of the power infrastructure in the United States. They are projecting that the data centers are really going to overwhelm, um, Northern Virginia, they are saying by 2030, instead of just two or three hours of, uh, power interruptions per year, it could go up to more than 400 hours of power and interruptions per year. So now, if you loop that back, now, you know, what kind of national security issues are we running up against if we do not have a reliable backbone?
I mean, clearly, uh, power is the bottleneck for AI factories. And whether we talk about building thorium, small reactors, or these nuclear reactors that go in like a container or, I, I don't mean a docker container, I mean like a shipping container, um, or, you know, some other, you know, because hope that the, the, the Idiocracy of the whole thing is at the same time we're saying, wait a second, let's stop investing in in solar and, and wind and renewable clean energies, even though they hands down are the biggest driver. Steven's an expert on this, he could tell us, right?
Steven isn't like 90% of the power coming on was, was coming from renewables. An awful lot of it was, yes, sir, there's a lot of gas turbines, but there ain't no nuclear despite the, the, the, the legend and rumor, there ain't no, uh, new oil and coal and so on. For the most part, it's, uh, it's been solar and wind, but that's all changing now.
And, um, in here, in the United States, at least in other countries, uh, you know, I mean, China has built out, uh, in Mongolia, uh, enough power to basically replace the everything in the United States. And they're using that to power their data centers. And, uh, along with their industrial expansion, um, it would've been good if the US had, uh, made similar investments.
So, Alan, will this become a political issue to the point, whereas Tip O'Neill once pointed out all politics being local, that the people in these local communities are gonna start voting out the quote unquote bums who made these deals, and maybe they're gonna be a little bit of a rebellion in the process. So it already is a political issue right? Now.
Look, my my son recently left Abilene, Texas where he was based for a year and a half. I could tell you it was a tremendous feather in the cap of ABIs or whatever they call people from Abilene, uh, that they were building out these huge data factories, these huge AI factories there. It may be a case where all of a sudden, oh, they didn't tell me they were putting a coal plant in too, right?
And, and that, and, you know, grandpa has black lung now, and, um, you know, then all of a sudden it's a different tune. But right now, I think cities are vying to, you know, in this lottery of who's going to get these giant mega, uh, factories, AI factories, but that, that may change. But anyway, we, we we're over time already on this one.
We've been just pontificating a bit. Let's come back though. We talk.
Let's hear about company. I always thought as a leader in the AI space, Nokia, you're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Hey, folks, we're back.
And yes, we're talking about Nokia that pledged $4 billion to accelerate AI networking specifically and here in the United States. And, um, of course, the issue, I think in a lot of people's minds, or maybe most folks don't realize that Nokia owns Bell Labs, which is one of the predominant research facilities here in the us and I think they're trying to maybe make sure that nobody in Washington comes after them for being a, uh, com a company that's fundamentally based over in Scandinavia. Steven, what's your take on what's going on here and will other networking companies kind of step up?
Because, well, we haven't heard a lot from networking companies in this whole AI investment space. Yeah, I think that Nokia is really, um, taking, uh, well, you know, they're kind of stepping outta the shadows here. Uh, they have new management.
Um, it's been very aggressive, uh, a new American born CEO who's very interested in putting Nokia on the forefront of networking technology. And they have done some really remarkable things to, uh, to, to move that forward. Uh, key among those is hiring a bunch of incredible people, as you said, uh, you know, making incredible investments as well, um, but also focusing really on, you know, practical technologies.
Uh, you know, they're thing doing things, uh, using things like SR. Linux, um, their IXR, which we saw at Networking Field, A 39. Uh, all of these things are really key to putting Nokia on the map as generally a networking company, but of course, it's 2025.
So if you're a networking company, you know, you're looking at selling into the AI space, and of course that is a very, very tasty market. Um, you know, you look out at what's happening in the market, there's a lot of OM stuff using, um, Broadcom especially, uh, silicon. Uh, there's a lot of investment happening from companies like Cisco, uh, like HPE, uh, trying to push into that market as well.
Um, obviously, you know, if you're a company like Net Nokia that has really solid, uh, interconnecting technologies, switches and, and so on, you're gonna be looking at that market too. So I would say, you know, kind of stepping away from the sort of political aspect of making promises to invest in America, I think there's sort of a, a nuts and bolts business aspect that's happening here, and that Nokia is trying to establish itself, it found the right market for its products, and it's stepping up if you do wanna learn more about that. By the way, we did post the, uh, networking field day presentations from Nokia on the techron tv.
Uh, you can also find those at the Tech Field Day YouTube channel. And, uh, to the point of this story, we're actually gonna hear a lot more about this at our AI infrastructure field day coming up where Nokia is gonna be presenting basically the technology that's, uh, underlying this announcement. Jp, are the workloads gonna become more distributed?
I kind of feel like when I look at these data centers today for ai, they're kinda like, you know, a replay of these massive mainframes, but are the workloads gonna get more distributed across networks, not only within the data center, but between the data centers? Uh, I think there's an issue that I, I'm seeing, or, or that I read about as well, that the, that raises question to that, which is, uh, do we want to put the responsibility in, in our capabilities in the hands of a few number of companies that are owning all this infrastructure? And right now, in fact, the article I read was about that there is concern and some professors somewhere has come out and stated that this is breaking, uh, anti monopolistic practices and, and laws of the United States for Years.
Hold on. Am I, am I in a dystopian time warp? The whole god damn economy's run by eight or nine companies, forget just the data centers, that's the, the, the story of our existence right now, 80% of the gain in the s and p 500 is, is on seven companies.
Half of the U-S-G-D-P growth is on AI stuff. Now you're worried about a concentration in too few hands. Well, maybe I always Worry.
Don't, Don't close. I'm Something you're passionate about. Al maybe My, your passion, maybe I think this is A, maybe a disaster.
Maybe. Maybe the way to resolve that particular issue is to distribute more of the workloads, though other places besides those eight companies. Jp, That's not what happens though.
People, people don't want to, it's always the same old problem vendor. Lockin still happens. People, you know, the more that companies do to try to avoid vendor lockin, the more expensive it gets.
Um, vendor lockin, you know, that, that, for the, that's the ongoing rage I'm gonna avoid. I'm gonna go outta my way and cripple and hurt, you know, and cause extra pain to myself because I don't wanna commit to any one of these vendors because I might wanna move and look, we've all been trained by the mobile companies on this problem. Yeah.
A few people in it have suffered small pains of this over years. But the world as a whole has learned this lesson from the mobile companies, right? Think about how hard it is to change your mobile phone provider, okay?
They, they've tried to make it easier, right? You know, we'll switch your phones, but it's the most painful thing in the world. My phone's a different, I have to swap out all my phones because my phones only work on their network.
And, you know, it's painful. And the same thing occurs with these systems, right? And just commit, you know, deal with it, right?
It, it, we now have AI coding throw away what you got rebuild the tomorrow with Claude. So at the risk of sounding jaded, Us jaded, that wasn't jaded. Actually.
No, No, no, no. I'm, I, I, I'm, you know, I'm gonna say something at the risk of sounding jaded, what's a measly 4 billion bucks today? Well, two and a half weeks of, of, uh, profit.
Yeah. Think, think about it this way. Um, these things are not, you know, storage and networking.
You know, the entire industry could fit into a, um, a sidebar or footnote at the, uh, annual reports of these massive AI companies, simply because they're spending so much money, a $4 billion investment, though, I mean, step away from it. I, I'm sorry to do this, but let's have, let's focus back on the topic here, which was Nokia making an investment, right? Um, a $4 billion investment would be a massive investment for a company of the scale of Nokia.
Absolutely. And would really move the needle in terms of the network infrastructure, you know, AI hardware, AI connectivity, AI ops, um, yes, it's not huge in comparison to the amount of money that's being spent on these AI data centers, but it is huge in comparison to the size of the enterprise and HPC networking market. But another, you Know, you add the value though.
Can, can they really do it? I mean, you know, do they have the, uh, you know, the resources and the staff to really make a difference here? And from a, from a, you know, research perspective?
Well, they're, that's what this investment is going for. They're gonna be spending a huge amount of money, uh, trying to, but they're Not only spending, they are going to get, uh, federal broadband subsidies, right? So there is $42 billion in federal broadband subsidies available.
It's called the, uh, the bead program, broadband equity access and deployment, right? Nokia, they, I think it was last year, they became the first technology vendor to self-certify that all of their fiber products are built in America. Um, what is it called?
BABI, BABA compliant makes me think of Baba Yaga. So I have to pause when I say it, but BABA compliant, right? And they right now, um, may be the only one.
So if anybody is looking at complying with that and getting part of that $42 billion pot, which I am sure Nokia has a great head start on, they're probably gonna go to Nokia because Nokia is already certified. And that is a very good point. I think that hope is really the crux of what Nokia is promising here.
They're saying we are the American supplier, which is ironic considering that they, you know, were a European country, uh, company, but now they're, they're saying like, look, we are the bio American, uh, supplier, and that could move the needle Good for them. Like, that's like going IKEA for the 4th of July, is that what you're saying? Yes.
That's very American. Now, you know, I love Ikea. I love the meatball.
Well, good for Nokia though, guys, I hate to do this to you, but we're about outta time for today's episode. I wish we could go on more about it, uh, just having some fun. But we'll be back tomorrow and we can talk about it some more, talk about stuff some more.
But for now, hope, jp, Steven, Mike, thanks for joining us. Thank you for joining us. We hope you enjoyed this.
Um, as usual, we have a full text Drunk TV line up immediately following the gang today with some great stuff, I think, including some of our most recent CubeCon coverage. And I think we might, well, Steven, any the short week I know, but not much Tech Field Day on this week. Well, we don't have, um, new Tech Field Day presentations, but of course, we've got the brand new, uh, security Boulevard podcast and the new utilizing AI podcast both this week on, uh, Textron AI and Security Boulevard.
Excellent. So stay tuned for that. And you can get those podcasts, by the way, on whatever your favorite podcast platform of choice is.
But, and in America, it's Thanksgiving this week. Thursday is Thanksgiving, but we'll be here, we'll be here, uh, tomorrow. Hey, I wanna, I wanna point out that Techstrong Gang and Techstrong TV is made in America.
You're willing to certify that. How do I know where Steven is today? I literally Almost fell off my chair.
Hope. Is there Anything, I'm actually coming to you from my, my secret layer beneath the volcano in St. Lucia.
Yeah, Exactly. So, so you can Do Whatever you want, but hope is does that, can we qualify for any kind of government billion dollar handouts for that? You Know what?
I, I, I bet there is some way to work that out. I tell you. Let's, let's, let's ask Claude.
All righty, Let's go back to the beginning, to the AI story. I think, look, we've descended. We're gonna pull the plug right here, everyone, have a great day.
We'll see you tomorrow. This Alan Shimel. We're out.
Hey, everyone, welcome back here to our day two coverage, my wrap up of, uh, day two here on Techstrong tv. You think it's a wrap up? You see this guy sitting next to me, you're saying, oh, Shimmy's doing tech strong gang.
But no, you come to an event like this, you never know who you're gonna meet. I look up from my chair where I've been bolted in all day, and who's walking over here, but none other than my friend Sanjeev Sharmer, of course, if you guys follow a text drug gang, you know, Sanjeev is a, a gang member, frequent guest. But I, I'll tell you the truth, you know, I, I started Techstrong in 20 13, 20 14.
com, and you know, one of the first people who contributed and, and was part of it was this gentleman right here at the time, Sanjeev was the, uh, field CTO of DevOps worldwide for IBM. And, and we struck up a relationship. I, we, as we did the, uh, I think we were called, not DevOps days.
Jenkins days. CloudBees days, and we had DevOps connect Yep. With the different in-person events we were doing.
Sanjeev was always there to do a keynote for us, give us the latest research and findings and feelings of IBM on it. Like all good things that came to an end. Sanjeev moved on from ib.
I feel like we're doing, this is Your life. I know Chief s Shava. I know.
Seriously. Sanjeev moved off from IBM and he went to work at, uh, truist. Now, before that I went to Delphix.
That's right. He went to work at Delphix. Yeah.
A, a, a DevOps startup, and did some amazing things there as part of the executive team. Then went to Truist, where went The merger. The Merger and integration of two large banks.
Then went on to Dell where you have a senior position in the cloud. Well, I was the senior vice president of platform engineering for Platform, had the developer platform for all, you know, 15,000 plus developers at Dell. Absolutely.
And, and then recently, I, you know, I thought Sanjeev retired to be a, a venture capitalist. No, he didn't. I knew he wasn't being a venture capitalist, but he's been on, uh, on Textron gang with us, and always happy to give his opinion on the state of tech, but lo and behold, he's here because he's got another job.
He's got a new gig. We're happy for and happy to hear about it. So you don't have to introduce yourself.
I introduce you. I know. Crazy man.
I mean, listen, we've known each other for a long time. We've doing, we've been watching this industry evolve for a long time. Yes.
So it was time for me to go be a part of a fast paced AI startup, which is focused on solving the problem we've actually been trying to solve for over a decade. So that's where, that's how I ended up at Stack Gen. I, my, my official title is VP of Platform and Customer Success, you know, beautiful.
Uh, I own the Yeah. Know, I, I'm responsible essentially as, you know, acting field, CTO kind of role. Okay.
Uh, working with customers, which is what I love to do. Absolutely. com started, a couple of articles I wrote were about the IMPOTUS mismatch, the speed mismatch Yes.
Between developer velocity and infrastructure or platform velocity. Today, a decade later, it has not been solved still, right? Yeah.
I think we had reached an equilibrium where developers were somewhat happy with infrastructure speed and infrastructure was somewhat happy with, you know, all the pressure from development. But then Gen AI happened, and now what are we seeing? Developer velocity is accelerating even faster and not it's time for platform to keep up.
And that's what Stack Gen is solving. We are solving that platform velocity issue by, you know, if AI writes your code, AI should run your platform, is our thesis. Yeah.
And we have, uh, agents which can maintain and manage and govern your platform for you. And I'm like, man, this is the place for me. This was like designed for me.
So here I am. It Really is good for you. I'm really happy for you too.
Thank you. Thank you all. You know, taking a page outta my own VC book, I was never a VC either, but I, I've been around enough VCs and I did stay in a number of Holiday Inn expresses.
One of the things VCs look for when they go make an investment is team, what's the team done? Is this a team that's going to execute? Is this a team that could get us where we want it to be?
And I think that's one of the strongest parts of the Stack Gen story, right? You're joining a team here, the CEO, I think it's his sixth or seventh startup. I know I followed him on the last three or four.
Um, and it's not just him, the, the core group, CTOs, VP engineering, sales, been there, done that, been there, done that. Because you know what, you've worked at the biggest companies, Dell and IBM and big banks, worldwide banks, you've worked at startups, but this is a startup juggernaut, right? They're, they're their MO is, they come in and within 3, 4, 5 years at most, but three or four years, they've got people knocking on their door to buy the business.
Yeah. I mean, we, uh, as far as customers are concerned, we already have customers knocking on our door. Yes.
Right. And you know, the rest will follow. Absolute.
Absolutely. And they know the day. Our goal is, are we, the question to ask is, are we solving the customer's problems?
Yeah. Right. And you know, I've, I've actually known the company for, for some time now.
I've been following them other than I've known Satin for the founder for several years. Yeah. But what I wanted to see was, is it a product still trying to figure out what is place in the market?
Right. So no market fit. Exactly.
Uh, or is it a product where the customers are coming to us and saying, these are my problems and your, your product can, can solve it. And, uh, we are, we are doing that. It's an early stage startup, so we've got a long way to go.
The product still has to develop and evolve, but we have, uh, you know, marquee brand name, you know, fortune 500 type customers. Yes. Uh, who are already using the product.
And, uh, one of my roles as you know, VP of customer success is to be that bridge between what customers are seeing, how customers want to use the product, and then back with product management and engineering to make sure our roadmap aligns with what's happening in the market. So it's very much a two-way, It's definitely a two-way, two-way street. That's how I've always seen a field CTO slash customer success team.
It's not like, you know, take a square peg and put it in the customer's round hole. Right. It is like, figure out what kind of hole And then go back The feed of the customer is what's missing, missing in the customer.
Right. Right. And then figure out what out of those can be used in the broader market.
Right. Because there'll be customers who come with very unique and novel needs, which only fit them for the right customer corner cases. Exactly.
There'll be edge cases always. Uh, obviously we want to serve a large set of customers. So that was one of the hardest lessons I had to learn in startups in my startup career, is that you can't build for edge cases.
You gotta build for the market, not the edge. And I don't mean the edge. Like Edge, yeah.
Not that edge. Yeah. He liked, he liked that edge.
Yeah. But, um, and I made that mistake. You know, I'm watching Mitch, Ashley's out in front of us there.
Mitch and I built a platform. We, we took our vulnerability management tool and turned it on its head for a company beneath for a very unique case work, you know, case. And we spent an, like two whole product cycles.
This is when we used to do, you know, a product cycle Sure. Every six months. So we spent almost a year and we finally made that product exactly what this edge case needed.
That company's name was Lehman Brothers. And the year that, the year I think was 2007, and they went out of business, took us a year to, took us a year to build the product for them, for their Lehman Life portal. I'll never forget this.
And then before we could collect the money, Wait, isn't even live where you go find out what the prices of the CDOs are. Yeah, Exactly. Yeah, I know what that is.
Uhhuh, um, classic story. Classic. But, but seriously, that's where I learned that you can't, you can't build for the edge cases.
You've gotta build for the meat of the market. Yeah. And, And it requires somebody, people who have experience in the market Yeah.
Actually look at an edge case and say, are they just ahead of the curve and everybody else will come here? Or are they truly an outlier? Right.
And there's a judgment call there, because you might, you, you might not know, but Might be is why I say team is important. Absolutely. One person cannot know everything.
Absolute. The team is important. And we as a team then need to decide, okay.
Really analyze and say, step back and say, okay, let's double click on this. Are others going to do the same thing? And you can query other customers.
Customers want to help you also. You know, one of the things I've found out having worked for large vendors, right? I've always been, except for my truist and de days, I've always been in client facing Yes.
Roles, even at IBM. Right. The customers also want the startup to succeed, right?
Yeah. When I was at Dell or at Truist, and we would acquire a product from a startup, we wanted them to succeed. We were betting on because their success is success.
Exactly. Nobody wanted to buy a product and then the company is gone. Yeah.
Right. Uh, you know, like, uh, we, we, you know, and, and no companies don't survive. And then what do you do?
Yeah. And that happens. We can't control that.
But, uh, it's always a partnership. And I think that is a, that needs to be fostered properly. And that's why, you know, uh, the team, uh, wanted to bring somebody like Neon who has actually done that, who's got the battle scars to say, Hey, I ran, I run platform engineering teams both in a regulated environment, in a highly scaled, global environment that, uh, that brings that experience.
And, uh, hopefully I can help, uh, truly add value as we go forward. I love it. Sanjeev, we gotta wrap up here.
Absolutely. I want to congratulate you and wish you thank you and wish you a lot of success with Stack Gen. As I said, I, I've, I've followed this company since before they announced, came outta stealth as well.
And I, and you know, I think that there's a high probability of success there, and I think you improved that probability. And I'm sure this won't be the last time we have you on talk. Absolutely not.
You're not kicking me out of the gang. No. Well, I got ideas.
We're thinking about getting gang jackets, motorcycle jackets with. I like that. I like that.
Maybe we should, we should make a album like a rock album cover or something. No, I was Together. Something like a TV show, like Sons of Anarchy or something.
Nice. I love it. That's what we need.
Yeah. Sanjeev, thank you. Sanjeev Farmer Stack Gen here on Tech Drunk tv.
Hey, that's gonna wrap up day two. We'll be back tomorrow though. We've got a, well, it's not a full day.
I think things ended two here tomorrow, but we'll be back in the morning giving it to you live, and we'll be doing wrap up count on us for your cube con information. But for now, this is Alan Shimmel. Thanks for watching.
We're out. Hey guys. Thanks.
To throw. We're here with y How chow, who's the CEO for Testrite. And we're having to chat about how AI may be finally breaking up some of those DevOps bottlenecks that have been plaguing us all these years.
You and Hal, welcome to the show. Thank you, Mike. Yeah, nice to meet you.
Yeah. So walk us through your thinking here. I mean, we all know that AI agents are coming, or in some places they've already arrived, but we have all these bottlenecks and DevOps that we've been struggling with for all these years.
Can we finally break them using AI agents? Uh, yes, for sure. Um, so, but I, I will say it's too kinda like a progress, um, at this moment.
So, and everything actually is, is changing so rapidly in the past couple years, as we know. Um, agents like Cursor coding, agent like Cursor, GitHub, co-pilot, uh, tray, and all those, uh, coding AI help developers actually write code very fast, and they can sometimes write thousands lines of code within just, um, minutes. Uh, but this also create actually new problems.
Sometimes we'll find bugs or flying everywhere. Sometimes we'll also find ai, probably just writing too fast so that you cannot really keep this pace with it, review all those content manually by yourself. Uh, when you generate tens of the lines of code, million lines of code, it's almost impossible to automate, to review by human beings.
That's new, kinda like a bottlenecks or what do we call new issues or problems raised by those new agents. And test Bri actually was created to solve those new bottlenecks and to make programming smooth or, or easy, again, for developers, uh, we are trying to use our agent, uh, AI testing AI to help to automatically validate software or code autogenerated by those AI coding agent like Cursor or GitHub copilots. We can be directly installed into programmers, IDE, so they can install our MCP directly into their IDE with just a one click within minutes.
And then they can just use natural language prompts in their cursor chat bot or maybe AI coding IDs chat bot to run test bri, and something like, Hey, can you test this software or project using test BRI MCP? And then it's all done. So our AI will automatically run all those steps, including analyzing their code base and learn from their software, read their existing, um, product requirement documentation, generate a test plan, generate test the code round test cases, do test result analysis, and share the final results with customers.
So all these, So, so I, so I get that we have new bottlenecks that are emerging in the age of ai. I guess, you know what I was curious about and can we use AI to replace or fix the legacy bottlenecks that we've been struggling with? Or are we just gonna start piling more code through those bottlenecks and essentially hit the wall faster?
Got it. Got it. So, um, it's actually, um, so I will say it's actually a interesting progress that AI agents is like, actually lots of AI agents is actually already fixing legacy bottlenecks in the past, I believe, five years, especially for programmers.
I, I used to work in Amazon for more than five years. The biggest bottleneck when I was a programmer probably is the coding efficiency like this, how whether we can write code that fast, whether we can actually ship things, um, way faster, and meanwhile keeping the quality, because purposely, if it's a human being, you can probably only write 200 lines of code, 300 lines of code in a day. So at that time, the main bottleneck is how fast you can understand a problem, how fast you can propose a solution implemented, how fast you can end-to-end test it, make sure it's really good running successfully, and then deliver it.
So at that time, everything's probably about speed. And, and right now I think, yes, existing agents and, and all those, um, like AI indeed solved that problem. The pace is great.
Everything was solved within minutes. They can generate hundreds, thousands of lines, like we mentioned before, within just 10 minutes. So speed is really fast today.
This bottleneck in the past of three, five years is successfully solved by agent. But meanwhile, when they're solving ex legacy problem or bottlenecks, they're creating new ones. For example, uh, the code quality, for example, those hallucinations introduced by found foundational models, because I, I know open AI cloud code, they are doing fantastic jobs.
They're releasing like models almost every year, GPT-4, GPT five, cloud three, cloud four. But, uh, those models do, are actually making some hallucination issues or errors. Uh, if you look at their performance on SWE benchmark, you will notice that their accuracy is only about 60%, which meaning that 40%, they make mistakes.
Uh, and that is already the state of art perf like, like the best model among all those existing AI models. So 40% basically meaning you if you have like, um, 10 features that you want AI to implement, probably six got successful implementing, but a four maybe partially still have some issues or didn't fully meet your requirements. And that is the new bottleneck created by these agents.
So especially for startup like us, what we do or what we focus to do is solving the new bottlenecks probably doesn't exist before five years ago. So this is actually a quite interesting change which is happening in the industry. You know, a certain perspective, it seems like the bottlenecks are just shifting and we can write code faster, but the problem is if I get to the back end of the workflow and then a lot of that code gets rejected because it's too verbose, there's too many vulnerabilities, and the overall amount of technical debt starts to increase, doesn't that defeat the purpose of kinda having these AI coding tools in the first place?
Because now I got all this code that I'm just sending back to have redone anyway, probably by human. You are right, you are right. Um, be, this is actually what's happening right now in the industry.
Um, because we work with, um, almost 50,000, uh, enterprise customers in the past one year, and we observe that lots of things are happening to them, uh, especially when they're adopting the, these kind of like AI coding agent. At first, they were surprised by their speed. Uh, they find that one AI to some degree, their speed can replace maybe 10 engineers when it's generating code.
So they were, they were surprised. They would say, wow, it changed everything. So they purchased lots of AI tools.
They start to use all those tools, uh, to write a code, and programmers actually have more time to, to drink coffee or, you know, just, uh, free their hands, but probably focus on designing, uh, customer facing problems, which is good. But later they find out, seems like they cannot fully count on ai. I'm not saying AI is not good, so that we, we, we cannot use it at all, just the degree, the balance.
So you can for sure let cursor, let GitHub copilot and all these tools or cloud code to help you to create the first draft version. But that version definitely cannot be directly released to a customer if it's enterprise level feature or enterprise level software. Because as you can see, 40% chances they will, they will probably create some hidden issues, unseen bugs or hallucinations somewhere.
So right now, existing programmers job is on how to identify those issues, how to manually fix those issues. So I would say statist, uh, speaking, their job efficiency right now indeed got increased. So whatever takes them, kinda like, for example, a week before to ship to finish today with the help of cursor, GitHub, copilot, all these popular coding tools, they probably would get it done for two, three days.
So half of their time and half of their efforts probably is already saved today, although they're still fighting with those ai solving those hallucination issues, solving those bugs. But indeed, it saved them some time. Uh, due to the efficiency of the ai, our tool is basically helping them to say, can we save them some extra time?
Help them to even be better to faster shift the confident, shift the software with more confidence, make it even like what used to take seven days, five years ago, and right now only take half a day so that they can be even 10 times faster with the same quality than before. Yeah, that's kind of like, um, what I'm trying to, to share. Yeah.
So yes, basically, uh, in short we can say, um, AI is indeed helping people already. If you look at how much time, how much effort, how easy it is right now compared with five years ago, but just like it's still not perfect, uh, still not probably what people thought, uh, it is today. Yeah.
So I understand that we can clearly write more code in a day than we did before. And, um, but we have to be smart about this, I think, because I cannot ask the AI that created the code to review that code, and I need a different model to kinda look at that, and then I need some sort of ability to reason across it and judge it. But so do we need an an an entirely new way of thinking about our DevOps workflows because there's gonna be multiple AI agents that need to play off each other?
Yes. This is actually, uh, uh, this is actually something I really want to share. Yes, we are actually, uh, sharing with actually developers worldwide, lots of startups, enterprises that the DevOps and also the whole development happen is probably changing today.
So especially on the testing side, we are encouraging something called left shifting, left the shifting. Uh, if we wanted to easily understand it, I probably wanted to share something about my background when I was working at Amazon, uh, five years ago. Even those big tech companies, the typical, um, DevOps kinda like, uh, cycle is you write the code first and as the programmer, you do some unit test to making sure that you don't make mistakes among the code.
So all the logic is fine, and then you create a new PR code review, submit to your team to do some code review so that other team members help you to quickly review it, making sure that your design, your logic, your implementation on the human review also makes sense and doesn't make too many obvious mistakes. And then you merge the code to, um, your dev endpoint, to your, uh, kinda like beta endpoint, and then let the QA team, the testing team to do some manual testing. They'll play with the feature mouse clicking around, record the whole scenario and try to tell you whether this code under the more kinda like production endpoint is working correctly or not.
So they will let basically bunch of manual resources to use your feature, um, mimic the customer's real behavior, trying to tell whether everything's all fine. This is what we call integration testing or end-to-end testing. And that including sometimes ui, front-end UI testing, sometimes backend, API testing and all these kind of testing.
So we do have different kinds of testing even when we talk about software testing. And today, when we talk about left shifting, actually this is even, um, uh, recommending from injury, uh, from deep learning, uh, deep mind and left shifting, basically meaning we don't have to wait for the development to be fully finished and then do testing. We can even do testing while we are doing development.
And to some degree we can even do test driven development, basically, meaning you can first design those test cases ahead. Uh, something like if I want to create a feature a, then basically I need to have these five test cases for feature A. And if the AI correctly implemented the feature a meaning the AI has to at least pass all those test cases, otherwise it doesn't mean it successfully did the job or finished my requirement.
So basically they have a high level design doc, and then they immediately design some testing associated with those features, and then they do implementation. The implementation will be fully finished or marked as finished only when all those tested cases are green or passed. So that at that time, human beings and also ais both have confidence.
I did great job. The software at least satisfy all these requirements and it can be probably moved to the next stage or maybe for beta users to give a try or something like that. Yeah.
So this is what we call after shifting do testing earlier that, for example, when you generate the some code using cursor, using GitHub copilot, you can already give it a test wrong to see, because we know they are making mistakes somewhere, we just don't know where. So we can make a testing wrong or execution at that time. And when we notice, okay, so it, and so 70% a right, but here, there this place we have some issues and then we let a cursor iterate again, fix all those issue, and then we run test again, and then we find remaining issues and that keep in the loop until everything is great.
This is exactly what test Bright MCP is doing right now. So we don't engage like traditional QA tools at the end of the day when everything from the developer side is finished, because that basically meaning developer has already fixed all those, um, cursor issues. Uh, they manually spotted them and fixed already using prompts, but we wanted to engage earlier when they're coding.
So every time when they use Cursor to generate something, they can immediately run test Bri to spot or to validate whether there are issues and they can keep running it, keep those two AI agent working together until all test the grain and then maybe create a PR for other team, team members to review or maybe deploy it to their dev end point, uh, for some beta users or internal members to give a try. Things like that. I feel like though there's something wrong with our little human condition in all of this, and people will see that they can write more code and then they'll just continue to write more code and they won't think about spending more of the time they freed up on testing and improving the quality of that code.
Yeah. Yeah. So, uh, if it's, uh, actually a junior level of engineer, or sometimes if, if you, if your first time using, uh, tools, uh, you will, you'll feel that way for sure.
Uh, but with your software become more complex, with more of your customer complaining, Hey, I have this issue. Oh, I encountered that issue, they will immediately realize that the quality of the software is not enterprise level and they cannot afford to maintain that kind of software to their customers because they will, they will lose customer. Interesting thing is today with the rising of tools like Cursor, GitHub, copay and all these coding agents, the barrier to to, to create a software is very low.
So almost everybody, when they have an idea, uh, this is why we call it a vibe code. So when you have a vibe, when you have an idea, you can already create something, um, by yourself or with a very LinkedIn small team. So the resources needed to create a software, it's, it's not that big, big or huge.
Everybody can almost create a software when they have, uh, I idea that means people with same idea probably a lot, and there are probably a lot of similar products in the market because you, you, there are definitely lots of people with similar idea like you, they will also create a software, they will also release it. These, all these changes also lead to the fierce competition. Right now in the AI sector, lots of, um, industries, lots of, um, like different tracks, we can all see the similar products right now in the market because of, because creating a software is so easy today.
So the main, I would say the main factor for you to win a competition among your competitors is naturally right now becoming whose quality is better, whose AI is more accurate, whose software is more user friendly, who whose AI is faster a and more, maybe more affordable. So everything is about the, the, the software is user experience and the quality. If you can become the best software among your competitor, you naturally just wing it because idea, vibe is cheap right now.
So every, everybody with an idea can, can somehow generate something. So people will immediately realize that. And what we can see is people already realizing that and they're trying to pay more attention as well as money, uh, into the software testing world.
Uh, this is more driven by their revenue, I think by the competition, by their customer's, feedback by the market is, um, current situation. So I believe in the future, people will just pay more attention, more and more attention in the future due to the natural. Um, uh, I, I would say the, the competition, uh, in the market so different, doesn't matter what what the industry is, doesn't matter what things they're building, as long as they want to win the competition in the future, they definitely want to focus on quality A, a, a And right now, the only way to do that for sure is, um, is do more testing, making sure your, your, your software is robust and, and, and your platform is stable, reliable, under all kinds of conditions for any of your customers.
Yeah, Folks, you heard it here, the choice is clear. We can either write more bad software faster or we can take some time and focus on writing better quality software that people actually use and enjoy. Hey, YHA, thanks for being on the show.
Thank you so much, Mike. Alright, and back to you guys in the studio. Hey everyone, welcome back here to Techstrong tv.
I'm happy to introduce you to my next guest. It's his first time on, so let's uh, hear what he has to say. His name is Philip Peku.
Uh, Philip Phil. Phil. We're gonna call him Phil.
Phil is the global practice head of developer experience at a company called Valis, and he's gonna tell us all about that as well. But first, let's welcome Phil to the show. Phil, nice to have you on here.
Thanks so much. Thanks for having me, Alan. Appreciate it.
So Phil, you know, we're gonna talk about Valis, we're gonna talk about Move Fest and break, but before we do that, let's let's hear Phil's story a little bit. Sure. My name's Phil Haku.
Uh, I, uh, I went to school for mechanical engineering and then I spent 10 years in robotics. So I tinkered with, uh, all kinds of tools to avoid talking to other people. After that, I moved into software engineering and then realized that helping people is actually a lot more interesting.
Um, after that kind of progressed over to kind of more of an agile role, uh, worked through the Atlassian ecosystem first on the product side, then onto the consulting side. I've been there for the last couple of years. So that's been kind of the short version of my history.
Very cool, very cool. Um, and Phil, you know, I, I'm, I'm, I think I'm speaking, I'm, I'm not gonna say anything you don't necessarily don't know, but a lot of folks in our audience may not be familiar with Valis. How, how would you describe that to him?
So, I think Valis is a, um, I think we've, we've long been a big fish in a small pond, so we are one of the platinum solution partners in the Atlassian space. Mm-hmm. Uh, we span the globe, but obviously once you look at it from a global perspective, we're, we're really more of a boutique consulting firm in that sense.
So we focus a lot on the tooling and process around the Atlassian stack. So a lot of it is software development. Uh, a lot of it is, um, service management now, obviously over the last couple of years.
So we do a lot of work in that particular space. Uh, outside of that, you know, you can think of us as a value added reseller or GSI, maybe not so much G as si, right? So we're a services integrator, value added reseller of the Atlassian stack.
And then everything from a process perspective that comes around that, I think of it as like layers of the onion starts with the Atlassian tools. What do you wanna do with it? Setting it up, and then obviously optimizing and going fast with them.
Excellent, excellent. You know, uh, I'm trying to think. I think, uh, some of us were over, not me personally, but some of my crew are over in Barcelona just a few weeks ago for the Atlassian, uh, user conference there.
Lot going on. I was there too. You were also there.
Yeah. We could have done this in person with you there, uh, Next time. Absolutely.
Make sure we're gonna hold you to that Phil, though, I don't know where the next one is off the top of my head right now, but they, they usually reach out and we send, uh, a crew over and some of our writers and content folks. Um, so, you know, the Atlassian channel, of course is one of the great success stories, I think of the, in the DevOps and space. And I mean, it, it's, it's almost legendary, if you will, right?
When you, I mean, you know, you look at Atlassian versus let's say, uh, like A-W-S-A-W-S is a hyperscaler, it's an 8,000 pound gorilla. But from a channel point of view, Atlassian from, from day one has always done a great job of integrating their partners and allowing their partners to have some meat on the bone, if you know what I mean. Do, right?
There's, there, there's things that you need an Atlassian partner to do. Atlassian themselves doesn't do it, and so it, it, it's a great thing. Um, Phil, before we jump into our topic of discussion, maybe people who want to get more information on valis and how to, you know, how to engage, what, what would you suggest?
I think there's, there's probably two common channels that people can reach out to us. com. Um, there's a good amount of content and there's a contact form there, obviously.
Um, if people want to dive into any of the conversations that we bring up today, um, I'm pretty active on LinkedIn, so if they can figure out how to spell my last name, I'm probably the only one that has it that way. So they could always reach out that way and have a slightly more informal conversation if that's what they wanna do. Absolutely.
And, and Phil, you don't know this while we're recording it, but in the finished version actually, your name and Valis and your title will be, uh, underneath you on the lower third of the video. So people, you can see it right there. It's H-E-I-J-K-O-O-P.
The I and the J make the y, so it's Hey, Kup. That's right. But, uh, people will see it there, Phil, if it's all right.
Let's transition now into what our topic of discussion here is. You know, uh, a mantra in Silicon Valley for a very long time has been move fast and break things. But, you know, it's not, it's not that we're bulls in China shops or something like that.
The idea is that we know in moving fast things that aren't enterprise ready, things that aren't scalable are gonna break. And if they're gonna break, let's find out that they break and, and fix 'em and make them more scalable and more resilient and, and not breakable, right? So the idea is, you know, kind of go fast as you can and, and we just keep rebuilding stuff this way and rebuilding.
It's kind of, it's part of that DevOps agile culture, I think, too, which is iterate and reiterate feedback, loop iterate, feedback, feedback, iterate. Yep. That's True.
I, yep. So, but now, you know, look, AI has changed a lot of things, obviously. Has it changed the move fast and break things mantra?
I, at least at the enterprise level, I, it may have helped it. I think it was already changing. I think there's two parts to consider.
There's the, the learn fast aspect, which was the original, uh, impetus to moving fast, uh, move quickly, break things right as you want to fail quickly, learn what didn't work as part of that, that kind of feedback loop. Um, I think that is probably more the case now than it was before, right? We wanna learn quickly, market test, get it validated and all that stuff.
What I think has, um, often been overlooked and it's easier to overlook and get away with when you're a smaller company, is not regressing to a point where things become unusable, right? So a good example would be AWS's recent outage from a couple weeks ago. Like, you don't want to get to a point where you are effectively publicly embarrassed for a little while because you've moved fast and broke something.
And so I think there's a balance that needs to be found when it comes to trying new things. You can absolutely still get away with going quickly, trying new things, seeing if it works and pulling back. But your core value prop should always still be accessible.
And I think that that's where a lot of the, um, the literalism sometimes bites it when it comes to this particular philosophy. It's a move fast, try new things, absolutely. But don't break the old things like, don't break what got us here.
Don't break the core platform and above all else, don't break customer trust. Because I think when it comes to moving fast and trying new things, if the functionality that you said, and it's got a big banner that says this functionality is in beta, people have their expectations managed. If people can't reach their bank accounts because you're trying something new, you have a whole different level of problem.
And so I think that that's where enterprise in particular, have to have a different trade off because their core value proposition, the legacy framework and everything they like that is effectively a commitment to their customers that that will be available and they'll get better at it, but they cannot, like, their floor of behavior and delivery has to be maintained at all costs. And you could think about it in the DevOps and agile space as like, you need to have regression testing and everything else in place because you can never get worse as you try new things. And I think that that's the philosophy that needs to find a balance with, with customers.
Fair, fair enough. Um, so how, how's this kinda manifesting itself, like at your, at the Valley Valis level where, you know, how are you seeing this kind of play out? I think there's, there's two main things we see a lot.
A lot of people want the shiny new toy. Uh, they wanna vibe code their way to new functionality. They wanna get through their backlog, they want to try all the cool new things.
They also have to add AI on top of and into their tool. Um, a lot of people are still bolting it on as opposed to making a core value prop. Um, and so there's a lot of demand for help us do these things, help us accelerate what we're doing.
And we're seeing that in most places. They don't have the foundation in place to go faster because they're just not doing the basics, right. Um, I, I think I've turned into a bit of a curmudgeon at this point, but if you don't have a lot of the basics, right, in terms of having security in place and you have QA systems and you're monitoring everything, like none of the AI tools are really gonna be helping you because you're just building a taller tower that is going to fall over.
Um, the other side, The Jane Good game, right? Oh, absolutely. There's just a lot more holes than I think people are cognizant of because they just mm-hmm.
Again, not a lot of tools, also not a lot of monitoring, so you don't even know how bad things are sometimes. Um, the other side that we see a lot of this coming in is obviously just we are being mandated to do this stuff. So it's a less of a, I want, and it's a lot of it I must, and then we're trying to figure out how can they balance this out?
Because in most cases, there's the technical, tactical implementation that people are, are stuck with. You must start using ai. You need, you need to increase your throughput, your volume, et cetera, et cetera.
But it doesn't always correlate correctly to business value. So in most cases, we're trying to help 'em understand that bridge before they do anything. Like, if I'm gonna do this, it's gonna generate 10,000 lines of code, potentially.
Why? What is the business value? What is the purpose is?
And that helps them make better decisions ahead of time, because you want to actually go in and still have that experimentation mindset, but have a bit of a credible hypothesis in terms of like, well, if I do this, these are the trade-offs that I'm explicitly making. There might be a couple I'm not aware of, that's okay, but it is all in service to this end. And if I can't make that chain of thought, I'm just experimenting for the sake of experimenting, that's also great.
But that's what sandboxes are for, right? Like, if you're doing this in production, you have to have that credibility towards a, I'm doing this in the service of this business value that I want to achieve over here. Excellent.
Very cool. Um, you know, Phil, I, I, this isn't, is this an enterprise specific thing you think? Or does it apply to SMEs as well?
I think it applies to both in different ways, though. Um, one of the things that you see just company dynamics are different at different sizes. Um, there's a lot of uncertainty, frankly, in, in enterprise, especially with that layer of middle management where they're starting to look at the Salesforce and AWS and, and meta lays in terms of like basically shoving out whole layers of management because they don't think they need need them anymore.
Um, and you can see people saying, like, looking at that anxiously and saying, is that the future? Do I need to prepare for that? Um, SMBs don't really have that problem in the same way.
They have a slightly tighter line of sight between leadership decisions, obviously, and the tactical, uh, individual contributors. Um, but a lot of this is still a question of if we can't, like, of that uncertainty from a do this to get to this business value, I think is the core of, of what this goes on. And it just becomes more complex at enterprise levels because there's a lot more dependencies between software systems.
You have to collaborate between more different teams. You have a lot more legacy, um, not just code, but also commitments to customers and services that need to be maintained. So it just becomes a slightly more complex version of the same challenge.
Agreed. Agreed. I I, I don't disagree there at all.
Um, let, let's look specifically with AI, Phil. Sure. Right?
Does it Take it away with it these days, right? Don't even get me started. Um, but, but, but seriously, you know, and, and, and I'm talking specifically like with digital twinning and the ability to do this sort of in a, in an AI and environment, if you will.
Does it give us a way out here, like having our cake and eating it too? We can build systems that last by going fast and breaking things, but in a virtual environment with AI simulation or what have you. And, you know, I think it is very Likely.
And this on a cheery note. Yeah, yeah, yeah. No, I, I would say yes, that is the very likely end state.
I don't think most companies are there yet, uh, oh, no. From a process perspective, but I think that that is absolutely the, the next step. We, we've seen a lot of conversations in AI around that early build plan, like make the thing, a lot of the conversations, I think have started to move towards the next stage of that, like the traditional waterfall element, right?
Like you need to check your requirements, you need to make security a priority, you need to make sure QA works and everything else in production obviously is stable. Um, I think it's inevitable that you get to that particular stage. I think that you can absolutely go faster and prototype things.
I think the table stakes, obviously, that have been pretty high before, obviously just gonna get higher when it comes to enterprise software, which will be great because users want better user experience and user interface and things like that. I think, however, and this is a challenge we've seen a lot, this only works when you're doing it with people who understand both the problem domain and the craft that they're working on, right? Uh, we see this in every element.
If you don't understand the question that you're asking from ai, you cannot correct it as well as you can. That's one of the challenges I see in five coding is senior engineers experience people getting tremendous value out of it. Juniors aren't because they don't have the experience.
And that kind of understanding intuitively of like, oh, I skipped a step here. And that's where the veneer is, is often the challenge, right? Like, you'll get the working piece of software, but a working piece of software on my computer is not the same as an enterprise level working grade of software.
So once we have the rest of the process infrastructure and guardrails in place, I think we absolutely get there, but I don't think we're quite there yet. That's, that's basically what we do day in, day out, is help build that particular state that we're working towards. Agreed.
I love it. Phil. We're about added time.
com. Check it out. Phil, thanks for coming up on here.
I appreciate it. Um, I, I, thanks for having me. You could reach, thank you.
com website. But, um, look, you know what, sometimes you can't teach old dogs new tricks and maybe, maybe, uh, we are moving past move fast and break things to build systems that last you're watching text on tv. We'll be back in a moment.
Hey folks, we're at Atlassian Europe and we're talking with Tiffany Tow, who's executive vice president for platforms and Enterprise, and we're having a little chat about cloud and ai. Tiffany, welcome to the show. Thanks so much for having me, Mike.
My pleasure. Um, you guys have announced that you're gonna end the life Atlassian data center, which probably doesn't come as much as a surprise to folks because you've been pushing folks towards the cloud for a while. But, um, why now?
What's the transition that you're trying to achieve and well, how far are people making that migration anyway? 'cause you've been at it for a few years. Great question, Mike.
And you're exactly right. It did not come as a surprise to any of our customers. We've been investing so much in our cloud platform the last seven years.
Um, and as folks hopefully saw in the keynote so many new things in terms of AI and all the collections and the system of work deliver all this new business value for customers. Um, but why now? A big part of it is, as we talk to our customers, many of them have been migrating to cloud.
Uh, 99% of our customers have some bit of footprint already in cloud. But what we hear from some of them is that sometimes there can be inertia in their organizations, right? Many of them have had data center for 10, 15 years.
And so being able to make a clear timeline for them that says, this is when March, 2029, it's time to be off of data center and into the cloud platform, enables these teams to start planning right backward from that timeline within their companies and start to build a business case. Because quite frankly, they're not migrating from, uh, JIRA data center to Jira Cloud. They're moving from kind of traditional behind the firewall, siloed, uh, products that work very well and have scaled, but into a cloud platform.
And that's what it's all about when it comes to ai, right? Every customer that I talk to is so excited about bringing AI to all of their workflows, but to do that, it's gonna be leveraging cloud technologies. It's gonna be leveling how these systems are built out on the cloud.
And so for many of these customers having that balance of new value by really rebuilding their workflows with AI in the cloud, and then also having new deployment models in the cloud to support even the most regulated industry customers. Um, we've announced that we have support not just for, uh, high levels of security with Atlassian Guard on top of our commercial cloud, but we now have our gov cloud for our US government customers that has FedRAMP certifications soon to be IL five as well. Uh, but we announced isolated cloud earlier this year.
And so isolated cloud gives you, um, a dedicated tenant. You have isolated, um, uh, compute storage and networking. And so that's a great environment for some of our regulated industry customers, and we'll support that, not just in the US but all of our data residency regions.
So mm-hmm. So in effect, I get a private data center is just on somebody else's infrastructure. Correct.
What's been their reception to that concept among folks who do have those requirements for compliance stuff? Are they willing to do that? Because a lot of them seem to, sometimes they wanna hug their servers and they're like, I own my infrastructure, but, you know, psychologically speaking, that may not as be as, uh, compelling as an issue if I have a private cloud, right?
Mm-hmm. No, you're right. And, and I think that's also another reason why it's been great to actually put this announcement for a send out because we can start to have these conversations with these customers.
Um, what we're hearing has been really positive. I think initially we had a, a very small set of customers in the US that we thought were gonna be going on to isolated cloud, but once the announcement came out, we've been hearing a lot more demand for it, and not just here in the us but you know, obviously we're here in Barcelona at the Team AMEA conference. Um, we've had a lot of impromptu meetings these this week from customers here that are excited about looking at an isolated cloud environment for them.
So yes, there's gonna be a, you know, change management is, is always hard as, as you alluded to. Um, but I think the signal we're getting from customers is that the excitement to rebuild all this with AI in the cloud and a clear timeline enables them to start putting plans together. See that point, does AI not force the issue?
Because ultimately I have all these models, I need to expose them to data, and the more data I expose to them, the smarter the models get, that all lends itself to the cloud. Because if all my data's sitting in some isolated data center somewhere, I'm really not gonna be able to do that as efficiently. You're Exactly right, Mike.
Um, for, uh, customers, a lot of what we discussed with them is, look, everyone is using, uh, AI on the consumer side, and that's all one uniform data set, right? It's everything on the web is the data set that feeds Chad GPT. But when you think about harnessing the power of AI for your company, how are you gonna expose all of that data?
And oftentimes that data doesn't come from one vendor. You know, they have products from Atlassian, they have products from Microsoft, maybe they have products from ServiceNow, Salesforce. And so being able to provide that rich context to customers is gonna require a lot of interoperability between these platforms.
And that's gonna be done best in the cloud, right? And you, you see that right now with, um, a lot of the conversations around MCP model, context protocol, how the agents are gonna access this data, how the agents are gonna work together. So you're spot on.
Any customer that wants to bring AI agents into their workforce is going to have to be able to build some sort of platform strategy that connects this data together. Um, and that's why we've built the teamwork graph. Um, hopefully you've heard a little bit about that.
The teamwork graph, as I understand it, is the, the thing that maintains the context and discovery and the relationships between all the various components that are in the cloud or in the SaaS applications, but not just your applications, third party applications as well. So, um, a lot of folks probably don't know what a graph is, but explain, yeah. Um, a graph is really important because it's about the relationships between the data, right?
You can have all of the data sitting there in buckets, but if you don't have, uh, an understanding of how that data is related to each other, what kind of insights can you draw? What kind of insights can an agent draw? What kind of context can you give it?
And so the teamwork graph was born from, um, kind of pre all this AI stuff, but at Atlassian, customers were asking us to help them get more insights from the data that was coming into the system. And like you said, not just from, you know, Atlassian's products, JIRA, confluence, JIRA service management, but they often are using a pretty rich set of developer tools, right? And other functions, Salesforce, et cetera, bringing in data.
Mm-hmm. And so as we started to look at the relationships between that data, we saw that we could be quite opinionated about it because the way teams work, uh, is usually modeled in a specific way. Development teams have certain objects that they're using, whether it's, you know, repos, right, code, et cetera.
Uh, teams work around goals that they're setting for themselves. They're managing projects in Jira. So all these data objects have relationships together and context.
And so we started to invest in making that bigger and bigger. And you, you saw on the keynote, we've got now billions of relationships now between all those objects. And so what that means is think of it as a very unique fingerprint of your company.
And so what that means is when you log into our systems and you make a search query, or you initiate some tasks, it knows Mike, it knows what projects you've been working on, it knows what team you're on, it knows what your team is working on. And so it doesn't just look at the structured data to answer these questions, it's actually using the teamwork graph to provide context for the query. Um, and now it has memory, as you probably saw in the keynote, right?
And so it makes your agents smarter and smarter about the way you work, but also the way you work with others in the company. And that's the really hard bit, right? It's like there's personal productivity and there's team productivity, and those are at very different levels.
And I think the teamwork graph, um, is really exciting because we're starting to see not just, obviously our own teams build experiences on top of it, but we announced, um, today that we're opening it up. And so that means people can extend and add their own custom objects into it. They can pull from the graph and build their own applications off of it.
So we really see it being kind of an, an exciting piece of, uh, making AI really valuable, um, for customers. And that goes back to what you were talking about with context and my personal preferences, and everybody has a slightly different way of working. Does the AI agent in that context become, um, my primary engagement partner?
Or am I managing a hundred agents that all have different kinds of memory and different kinds of experience? How do I kind of marshal this small army of AI agents? What's that gonna look like?
That's a great question. And I feel like, uh, the whole agent strategy and what that workflow is gonna look like has been evolving so fast the last six months, right? I think initially it was, Ooh, everyone's gonna have an agent.
You know, Mike's gonna have his personal agent. And then it became, well, no, he's gonna have hundreds of agents and they're all gonna do lots of stuff. And then it became, okay, well every company's gonna have thousands of agents.
How are we gonna manage this? Right? What we've been hearing from customers is they want simplification.
You don't, you want to not have to think about managing a whole set of agents. So we're trying to provide a good amount of flexibility right now because we recognize customers are gonna try lots of different things. And across the wide range of use cases we're seeing, there's probably not a one size fits all.
Um, but we believe what's really important is the skills that you're endowing those agents with. So part of what we announced today is, um, a really large library of several hundred skills that an agent can have. So you could choose to build one Uber agent for Mike that has all the skills.
It can do a bunch of admin tasks for you. It could do your core work, it could do personal work, it could do all sorts of things, or maybe you don't like that and you'd prefer to have very separate siloed agents. So we wanna give you that flexibility to be able to do, um, the model that you'd like.
So I think there's gonna be a lot that shapes up over the next, um, six months year. But what's exciting for us is we're seeing customers customize, uh, tens of thousands of agents and give those agents the ability to, uh, go and actually initiate workflows in our system. We're seeing millions of workflow automations being triggered by agents already.
So, uh, we believe that probably Atlassian right now is probably one of the largest AI workflow, um, generated platforms. Mm-hmm. To bring this full circle, a lot of folks who have their own data centers will be concerned that their data doesn't wind up training an AI model.
So how does Atlassian kind of protect everybody's data or isolate that data from all the other AI models and agents that customers might be using in the cloud? That's a really important question. I get a lot from our customers.
So the models that we use right now today, we work with OpenAI, we also work with Meta and have their models. We do not share any customer data with those model providers. So the Team Warcraft data that we're using to provide that structured context, it's only used when you're querying.
And so it's providing that grounding so that you can get the right response back. But we're not sharing any of that data directly, um, with the model providers. And it's also isolated, uh, per customer, right?
So each teamwork graph instance, right, that we're training is for that particular customer. So, um, it's a really important question that I know customers and if they wanna see the architecture diagram, we've got a lot on the website as well that kind of goes through exactly what, um, the lifecycle of that data goes through. So, uh, All right.
Hey folks, you heard it here. You're going to the cloud and there's gonna be a lot more functionality and a lot more features and things you never imagined you could do. So better do it sooner than later.
Tiffany, thanks for being on the Show. Thanks so much, Mike. All right, we'll be back in a minute.
Hi everyone. We're back here live at CubeCon. It is, uh, day two.
Well, it depends how you count. 'cause Cube con's funny 'cause we have like this day zero all of the, uh, satellite conferences, but we don't really, that's a zero. Yesterday was day one today, therefore's day two, though?
Some of us have been here three days. Yes. It's fuzzy meth.
Anyway, though. We're, we're still live here. My next two guests are with Intuit, and I know what you're saying.
Intuit Cloud Native Computing Foundation. What are they doing here? Well, I'm gonna let them explain it, but there's a really good story behind it.
Let me introduce you to them. We have Lisa, Lisa Marie, not Presley, Lisa Marie, Nancy, who, if you've watched our previous, uh, Textron cover, uh, CubeCon Coverages, it's not her first time here. And then we have Mr.
Patel, and I'm blanking your first name. Jamil Jamil Patel, also from Intuit here. And, and guys, welcome.
Thank you so much. It's great to be back. It's always good to see You act.
Always good to see you as well. So I, I, I kind of opened the door with the question, Intuit, what are you doing here? Yeah.
Well, that first day of the conversation, you talk about nothing, zero about it. We, uh, we actually started, uh, one of the colos, it's the Argo Con. Yep.
'cause as you know, Intuit is the creator of the Argo Project and donated it to the CNCF started that conference, um, with the, with tons of help from, um, the Acuity and Codefresh and Red Hat folks. Uh, and now it's one of the most popular co-located events. Octopus deploy.
Octopus Deploy now. Yes. Yeah.
Uh, that's true. That's true. Um, so yeah.
And, and those, we are all still incredibly active in, in the Argo community. And Argo Khan is one of the most popular co-located events. It was packed on the first time.
Well, Argo CD, I believe is now the number three, uh, project in CNCF, right behind Cube KU itself, and then, uh, and Telemetry hotel over here. Yeah, yeah. Yeah.
And those are stat at Argo k uh, two thirds of all Kubernetes low, uh, users have Argo CD installed. Really? Yeah.
They just republished actually, as of yesterday. Dan just talked about it. 97% is are using Argo.
It was a crazy stat, which almost says that more people are using Argo than Kubernetes. So that math we need to sort out, but people are using Argo. People love Argo, particularly Argo cd.
Yeah. Um, so yeah, no, it's great. It was very popular.
Uh, but, but to your question, open source is we're, we're on the platform team. Yes. And open source is pretty core to a lot of the work we're doing.
And we don't just, you know, consume open source. We also do build and contribute back things like the Argo project, the pra, um, which is our Kubernetes native event stream platform. And all of this stuff we use, we consume, I would say more than what, a hundred open source projects mm-hmm.
Or contribute to. So, you know, we've, we've built a little open source program office. We'd show up at events like this.
And I just had a conversation with someone who walks through our booth about the hundredth conversation I've had, but they're like, you know, what is Intuit doing here? I I didn't think of Intuit as a technology company, and I definitely didn't understand how important you were to open source and vice versa. And we've won End User of the Year award twice from the DCF here at Cape Con twice.
Very cool. Um, so yeah, we're very proud of the work we do in open source. So I of course, knew this before we started the conversation today.
Um, but when you think about it, you know, one of the things that makes the CNCF successful is the mix. It's not all technology vendors, it's not all, and I don't mean this in a bad way, geeky, you know, uh, dev or ops or, you know, A lot of end users Verticals, but it's also end user organizations that quite frankly have the resources to, to dedicate people and time and money to open source projects. And instead of kind of keeping it for its themselves, which is kind of the old way of doing it, become good community members here because they're vital to the mix.
Right? At the end of the day, you are not here to sell your, your open source software. You contribute it.
You're, you know, 'cause there are other, for instance, I, I was interviewing the, the folks at Broadcom, VMware earlier today, you know, they're the third largest contributor to code to Kubernetes. And a lot of people don't think that, 'cause they think Kubernetes hypervisor, they're separate, but no, they're the third largest contributor to code there now. And I commend them for that.
But let's face it, they're feathering their own nest. Right. You know what I mean?
And, and one can say that even if they're not doing it for that being the only reason, one can still say, well, but they're, they're selling software. Right? Right.
And two it different thing, you are doing it. 'cause it's, it's, it's making what you guys do better, but you want everyone else to be able to have access to that as well, because you're not selling. And to be able To contribute To it, it, and helps Make it better.
Helps. Yeah. Well, it's like paying it forward, right?
Mm-hmm. When you contribute it to the community, hopefully others follow and, and it's all that karma wheel that goes round in mountain, right? And paying it forward also has its dividends.
Like for Argo project, uh, red Hat is now contributing as well. And they've created cool features. There's an MCP server introduced, and now we are also leveraging from the community.
So like, if we were to do all this ourselves, it's all our resources. Uh, versus now we are getting back from the community. So the dividends come in, it just takes some time.
Absolutely. Yeah, it does. And that's karma, right?
It goes round and round, but it, it, it does pay off. Yeah. If you don't mind though, I, I want to shift, I'm shifting.
Um, no, no, but ai, yeah, right? Yeah. Everyone, well, not just this time for the last two, three years, you know, we all lead with ai and I, I think just as Kubernetes itself is maturing a little bit, we're, I'm not saying AI's mature, we still have a long way to go.
But we are starting to see definitive patterns in how we use ai, where we use ai, who we is using ai. Let's talk a little bit about Intuit ai. Absolutely.
Jamil. Yeah. So, yeah, one of the things like our, you know, mission.
In our mission statement, we have three statements. We have, uh, less work or no work, more money and high confidence. Like we have these three statements.
And as we think about ai, like it helps you make more money, it helps you do less work, and it gives you more confidence. And it's very critical to our consumer products that they have AI in them. And that lets our consumers, uh, get all of these things.
Now, when it translates to like an engineering organizations, there's like, you know, we think about it in three areas. Since we are all like in the platform engineering space, there's one is like, how can AI make platform engineers more productive and make infrastructure awesome? The second area is how can it help general application developers be faster?
So how do developers go faster with all the coding tools and the tools they have? And the third one, uh, is more around like, how, how are we using ai, uh, where we are giving developers ways to build AI applications for customers? Because there are new tools for building AI.
And you know, our developers need to know how to use these tools and how to get faster from an app that did not have AI to now having AI in that app. So for all these three areas, we are investing heavily. And maybe I can give you some examples for each of the area.
I was gonna ask you to, yeah, so go ahead. So for the platform engineering side, uh, this is where like, Kubernetes is hard. That's something, that's why platform engineers are paid so much.
Uh, now with AI coming into the space, they're actually gonna get more and more productive. Uh, for Argo CD for example, we added Argo CD assist. And that is when, you know, people used to ping, uh, our platform engineers and say like, what is wrong with my deployment?
Now AI can just build a summary first, and if the summary doesn't work for them, they can still ping them. Exactly. Uh, there is build failure analysis where every time a build fails for a developer who doesn't know what's going on behind the scenes, they get a summary of like, what is failing.
And sometimes, uh, there's also remediation, uh, where it tries to remediate the fact. And developers don't even know what is happening. We call that done for you experiences, where things are done for you and you don't even have to worry about things.
Uh, so that's on the, like how AI is helping platform Engineers. Lemme, let me stop you right there on the, this platform engineering thing. So, you know, we, we started a new site since last year when I interviewed you.
Mm-hmm. Hopefully it's on there. com, see on the edge, right.
com. Because platform engineering, I think has emerged as its own discipline. Mm-hmm.
Yes. It's closely tied into DevOps. Yes.
It's closely tied into, uh, cloud native, but it's its own thing. Um, when we look at platform engineering, though, I think two years ago, three years ago, if I asked someone who claimed to be a platform engineer, what are you doing? Kubernetes is hard.
And we're gonna make Kubernetes easy. Not easy. I don't think it ever gets easy, but manageable.
Yeah. But I think if you ask most platform engineers today what the mission is, they'll tell you IDP internal development platform. Right.
Because that seems to be where the action is in platform engineering and also a lot of where the AI is going. I'm wondering what you're seeing as a real life platform guided into it. Yeah.
Uh, so Intuit got lucky. We invested in an IDP way early before Backstage came out. Every third person I talked to at CubeCon, they're like backstage, backstage, backstage, uh, because the IDP serve as a, as a web layer to all their abstractions.
So making Kubernetes easy is through abstractions and where do you put them? You can't put them on Kubernetes itself. 'cause then you have learned that.
So instead they have an abstraction on top of that, which is IDPs. Most IDPs are going to have an AI assistant moving forward, and that's going to be your platform. Engineering team's first line of defense.
And if that AI is not able to answer or do things for your, uh, general developer, that's when you go to the platform engineers. Versus today we live in a world where like the first choice might be platform engineers. So then I think, you know, IDP and AI together, like in one platform is going to be your first line of platform engineering defense.
And you'll see more and more vendors come out. You'll see the Kubernetes ecosystem getting well integrated into it right now, it has all the popular projects, but you'll see a lot more projects going into it. Because once you have an IDP, you have to integrate Jira, you have to integrate GitHub, you wanna integrate Argo, and the list never ends.
No, no. So it's a integration. But I, I think we learned something from like APIs, right?
Which is, you don't wanna do a one-off for every single one of these projects or every single one of these products that you wanna plug into your IDP. You know, I, I think with Agentic ai, we have the ability with let's say an MCP server to, to not repeat the mistakes of and sins of the past. Right?
We, we could do that very quickly. Is that something Intuit is looking at? Yeah.
And that's where like if you look, I would say five years ahead, uh, I would also say like, you know, the I-D-E-I-D-P experience might also shift left. We are thinking about shifting left. And a lot of these experiences are happening within the IDE itself.
So when you're developing, you also have a chat agent, a chat window with CPS enabled. So why wait until deploy? And then asking the questions like, you are coding, you're asking the questions in the side, like, why will this bill pass and your m mc like your IDE, then call the AI MCP, try to run it in your cluster or tell you information about your clusters.
And before you even push the code out, you will know like what's, you know, what's wrong with your code. So, you know, there's a shift left happening where you want to alert the developers before they push it to a stage where they need support. Like things need to be fixed right when they're working on it.
And I'm hoping that our tool chains also support that. So you have that chat window that provides you alerts and errors early on, then you deploy, then your IDP has a chat window that you have alerts and whatnot. And then you have your operations dashboard and those things.
Those also have those. So like you will have a, and you know, a lot of the companies are, their jobs are to unify these assistants. 'cause there's like almost too many these days and they don't talk to each other.
So you have to ask the same question here, here, and here, and choose the best answer based on which one's the most mature. So, you know, that's kind of what I've seen happening as well. I get it, I Get it.
I was gonna make some joke about like, okay, everybody stop building dev, do portals and just, you know, focus on IDPs and, but I bet you next year when we're having this conversation, that will probably be a reality or much closer, too much. We'll see. Yeah.
You know what? This, this, you've said it now it's out in the universe. Exactly.
Don't even Get money. So we'll come back and, and get it. Um, so that's AI and developer platforms.
Mm-hmm. But there were two other AI use cases for Intuit here. Yeah.
So the other one, uh, which, you know, in the last three to four years, we have seen a 12 or five years actually we have seen a 12 x increase in developer velocity. Uh, and the reason being all of the, like the AI coding tools, there's a boom of that. Uh, right now the market's changing so rapidly.
Every three months there is a vendor, there's cursor, augment code, Gemini Codex, you know, more, more to come. Uh, and, uh, what we adopted early on as a strategy is not to choose one option, but to give developers flexibility. But in addition to the tool, we are providing Intuit, uh, code as context to all of these capabilities.
So when developers ask like, how do I write a web plugin? It doesn't tell you just a how to write a generic web plugin. It will tell you how to write an Intuit web plugin.
And that has been like very crucial to our journey where when our developers ask for help, it is, it has all theisms baked into it, uh, to begin with. Um, so from a, you know, code gen, code generation perspective, like I think I'd advise everyone on the same journey to like not focus on the tools. 'cause the tool market is going to change.
Acquisitions are going to happen. Chad, GPT and the other vendors will release our open AI will release new, new tools. And your developers are always gonna say, this is the coolest or that is the coolest.
And you can't, in a real world support all of them. So I, I'd see this market will evolve and ultimately you'll see clear winners. Uh, but right now you can focus on making your AI such that it doesn't give generic answers, but it gives like your company specific answers as much as possible.
Excellent. Yeah. Let's talk about something really important.
Customers. Mm-hmm. How's AI helping you with customers?
So, uh, in the customer landscape, like there is, you know, there's immense opportunities. So on the QuickBooks land, like we have certain agents that help people get, get paid five days faster. And that's like very much aligned to our, our mission of more money.
Uh, who, who doesn't wanna get paid faster like I do. Like, you know, so there are things that would reconcile your transactions on QuickBooks faster. And that enables business owners to also like run their accounting faster.
Um, so that could mean vendors are getting paid faster, employees are getting paid faster. Um, so that's on the business side. On the TurboTax side, like if you filed taxes with TurboTax last year, it will do gen AI summary and it will kind of make you feel more confident that, uh, because TurboTax is a tool and you file your taxes yourself, you put the documentation.
So sometimes you're doubting yourself like, did I put everything in the right way? But now AI is gonna say, Hey, you, you put this document but you didn't support it with this other document, that's usually the case. So maybe you are missing to upload your gains on the stock sale or whatever.
Yeah. And then that's gonna make you more confident in terms of being able to confidently say, I file my taxes. Right.
Or I did my accounting. Right. Or with MailChimp, it's like email marketing who, you know, everyone wants help from AI to write emails.
It's in there. Now. It also tells you what is the best time that this person's likely gonna open this email.
And that is intelligence. Where before it was like, send an email at 9:00 AM that was the the norm. Right now it's like, send an email to the people when they want it and when they're most likely to open and read this email.
And that is a game changer in Sure. Is. And, and in, in, and that kind of capability in the hands of a small business owner.
Like if you're a big company, yes, you have those capabilities, but a small business owner being able to personalize up to that extent is magical. Absolutely. To stay on top of all the regulations and all the rules.
And you know, imagine if somebody suggested, Hey Alan, like you're leaving money on the table 'cause you didn't write off all these things, but you can write those off. That's legal. Yeah.
And you'd be like, Ooh, let's do that. Then more money for you. Oh, I love paying more taxes.
Especially unnecessarily. Uh, yeah. Uh, excellent stuff.
So, you know, it's funny, I was talking to people earlier last year, we were talking a lot about AI this year. I haven't heard as much though. It, it's kind of built in now.
And, um, but we're still just scratching the surface. There's so much more it's gonna happen here. It'll be interesting to see how that plays out.
And I'm also interested to see how it plays out from an open source perspective, how much of this winds up on that side by the project pavilions mm-hmm. Right. Versus inside of commercial products only.
So it'll be interesting. It'll be interesting. Yeah.
And the C NCF is, is working hard. We, as you know, I'm a CNF ambassador and have been for many years, um, over 10 now. I guess I just saw my picture on a slide saying something about 10 years of contributions.
Uh, so Wow. But that's, we do talk to them a lot and we just had a meeting with them a couple weeks ago, you know, really asking that question, like, what's your plan with ai? And you know, we had a bunch of projects that we think would be great to be in the CNCF and then they told us about some stuff we didn't even know about.
So the conversations are happening, they are talking to the end users. Um, and, and they're also trying to get, you know, the ois get publishing more, more and more standards all the time, which is really good and really helpful. A agentic is a very big conversation in Kubernetes right now.
Uh, so that's a hot topic. Yes. Um, so we're excited, we're excited to see where it's going.
Yeah. This morning they announced the AI Big Bricks project. Uh, they're working on Cajun the Envoy, uh, like AI gateway with Tetra and Solo.
Uh, those are all like, exciting projects. Uh, and you know, I don't think, uh, like, you know, AI and Kubernetes are like so separate today 'cause people are already running a lot of AI workloads on Kubernetes. Uh, there's a lot of libraries out there now.
It's just like, you know, it's the same way where the coding agents are like, which ones are gonna hear like, we gonna be here to stay and which ones are gonna be just like noise in the space. So we should find out. And you know, this is a great place to know and feel from all the audiences here.
Agreed. Yeah. Agreed.
Well, listen, we're, we're probably overtime, to tell you the truth, I want to thank you both for coming here on Tech Junk tv. You have an invitation in next year, but let's not wait till next year Exactly to catch up. Thank you.
You always love being here. You okay? Alright.
Thank you for having us. Yeah. All right.
Thank you so much. Intuit. Open source dynamos here at Q Con.
We're gonna take a break. We'll be back in a minute. All right, everybody, good morning, good afternoon, good evening, wherever you are in the world.
My name is Shana Med. I'm the CPO of CloudBees and, uh, running r and d here at CloudBees. Glad you could join us, uh, and, uh, and spend some time together.
Listen, the thing is modern DevOps, uh, there's probably a question worth asking ourselves, which is, how did we actually get here? Um, if we look historically DevOps, uh, it really started as a cultural shift, uh, decades ago. And, and the idea at the heart of it was that, you know, developers and operators would come together.
And the idea would be that if they were moving and, and, and they were working together much more closely in the software development lifecycle, they would move faster. They'd break down some silos. And, uh, core technologies and, and concepts used in order to do that was to deploy pipelines.
Uh, deploy as much automation as you can containerized and essentially kind of get to an accelerated velocity, uh, beyond what you were doing manually. Um, the end goal kind of being, Hey, let's, let's deploy 10 times a day versus, you know, once a quarter. Uh, and every one of these leaps that you see on the chart here brought new tools into the equation.
Uh, CICD tools brought new, uh, new different types of tools into the equation. Containerization did, Kubernetes did a whole galaxy of new tools. If you think about it.
Uh, security shift left into the pipeline itself brought yet another set of types of scanners and tools into the pipelines that weren't there before. And, and, and, and the way that we build applications, uh, changed as well. We went cloud native building, microservices, and today we've got AI writing code for us.
The truth is, every time that you have within your organization probably has their own stacks. So DevOps in itself, if you summarize all that and think back, is about speed. It was about agility.
It was about breaking silos. Now, the interesting thing that happened is there was a reaction to that over the years. And, and, and, and the enterprise reaction to that is kind of looking at and going, wow, this is really messy.
Right? Um, that's a lot of tools and you're integrating them all to work with each other. Let's go ahead and consolidate.
We need less tools, not more tools. And this idea that somehow fewer tools means less complexity. And if I think about it on the surface, that seems like a logical thing to think about.
But the question I often ask myself and to, uh, the companies that I work with is, is tool count really the problem that you have within your organization? Actually, because pools fra, if you think about that chart is not really a mistake, is it? It's, it's really more or less Conway's law in action.
Uh, because the way I think organizations are structured inevitably shapes the systems and pools that they use. So sprawl often reflects organizational reality. It's not just poor governance.
Um, you know, sprawl is an inevitable outcome of innovation in my opinion. And I think teams actually will adopt what solves real problems for them. And I, and I don't think anybody wakes up in the morning and says, you know, let me niche 80 platforms if you could.
So I don't think tools are paired by accident. I think they each solved a very real problem for the, the, the teams that implemented them. And so it, it shouldn't be thought of as a problem, but rather it's a feature.
It's not a bug of the system itself. So then comes the platform vendors in, right? And then comes the idea that there is a platform.
And this platform often will be the silver bullet, you know, and, and the idea is, hey, if you just put one platform in place, it'll rule the ball. It'll give you this single pane of glass, uh, across your entire landscape. Uh, there's gonna be no integration headaches anymore because you're using all the modules that are inside this platform, and everything's gonna be neat.
It's gonna be unified, it's gonna be unified workflows. And I think, okay, that would've made sense. That's the traditional platform approach.
That was a very natural response, I think in some ways to the growing complexity in the SDLC and for a whole host of companies that made sense too. For a lot of teams that made sense too. Greenfield was, was one great area where being able to get into a platform like that where nothing else existed from before, there was no legacy code, maybe there was no tech debt that you had to deal with.
It's purely all cloud native, small, tight-knit teams. And they all looked at speed as the number one sort of vector that they wanted to focus on over complexity. And for startup, that is a very reasonable approach.
But it wasn't really for the enterprise, was it? It's kind of different in the enterprise. And we all who have worked in very large scale organizations with very large teams, and many teams know that there's always decades of code that you are managing, that you've built that you need to build and maintain and release.
There's multiple frameworks across the board that have to work. You know, you got hybrid infrastructure from on-prem that is historically there or maybe still there that you're managing and running. You've got your cloud and you got off a multi-cloud depending on how you're set up.
And then there's always these mystery servers out there somewhere, and nobody knows exactly what's on it. So when you think about it, you also have distributed teams. You got teams working differently, which means they got different cultures and ways of working.
And automatically compliance isn't just gonna happen. There's heavy compliance needs that need to be followed. So I think the answer in the enterprise to the question is everything homogenous.
The answer is no. Complexity and heterogeneity is really inevitable in the enterprise. There's nothing you can do about it.
And it doesn't feel like an ever felt like a platform was built to solve this reality. I think in many ways it's a fantasy against the reality that enterprises are actually facing. The, the promise that, you know, the platform vendors will give you is, Hey, it's simple.
It's, uh, simplicity over anything else. It's speed, it's cost saving. But the reality for the enterprises is that they've got boltons downtime lock-ins, that's type of things is not they want, they don't want those types of things.
They, they don't want rigid workflows that force them to work in one way across their entire enterprise. And then unfortunately, what o often will happen is developers will just bypass the platform anyway. So while it's true simplicity on paper seems really appealing, it's actually equivalent to rigidity in practice.
That's how I think about it. So we could step back for a little bit and say, okay, well what is it that the enterprise is really trying to do? Where do they want to get to?
What's most important to them? And I think it is one, one thing that's always the most important thing is try to always avoid the single point of failure. You, you want to be resilient at any scale at that you are operating at, um, security and compliance.
You want to be able to put that in place, but you don't want it to be a bottleneck. You want to be able to have hybrid integration between your tools and so on. You wanna be able to go across environments.
You want teams to be autonomous and operate in an autonomous way, but provide some sort of common guardrails that feels like are the top priorities that always every enterprise company will talk about. And the real goal then becomes a little bit more clear. That means the answer isn't, we need fewer tools.
What we do need is freedom with some control. We want simplicity or to occur through orchestrating them, but not through consolidating them. And what we really want is we want developer joy, a lot of it.
So if I think about the stack, that diversity in your stack, that's an advantage that you want to unlock, not one that you wanna take away. So what can that path forward be that you can take? And how do you focus in on some of the things that are most important?
I typically have four very practical sort of principle for how to tackle complexity The way I think about it, first and foremost, I always say, you've got to be flexible. You gotta be able to have flexibility as your top priority y because you wanna build for change. Change is absolutely inevitable.
And don't build forever. Platforms that lock you in. You know, give the tool choice and power teams to pick the best tool for the context they're operating in the work that they're doing.
And don't mandate things. I think guardrails will always eat mandates for lunch. So that's one thing.
Be flexible. Number two, always think about composability and what you're building over trying to consolidate everything. Think API first think interoperability between the tools.
What kind of ways can you bring the stuff that you already have within your software development lifecycle together to be used in a way where you don't have to script everything, control planes, use them for visibility, get governance across it and try to use policy as code as much as you can across your environments so that everything is composable reusable instead of consolidating into a locked platform. I think about modernization as an incremental step that you take not a big bang approach. Those, those big bang migrations are almost always super expensive.
They take forever to do and are, are, are, are often going to fail and run over costs. So modernize, but do it at piece by piece. Take one thing by one thing big some build some quick wins, uh, and then get momentum from that.
As you think about what to modernize, when to modernize it, don't go big bang. And the other thing is think about how do I provide governance into the organization without it becoming an actual bottleneck For those it governs, it's like a guide rail. Try to automate security and compliance, but do it outside of the pipeline.
Find a way to put compliance and security as guardrail around the organization as opposed to making it the developer's responsibility alone. Balance that shift left, uh, with the productivity that you want developers to be able to have so that they can really feel joy in what they're doing every single day. So if that's sort of the practical principles, there's one very clear sort of tactical thing that you can do and how can you achieve this complexity without chaos stake that I'm talking about?
And I always say, Hey, look, there's two things you gotta split. It's much better for you to centralize the control plane. Do that for visibility, orchestration, governance, compliance.
Make sure you centralize that control plane, but absolutely decentralize the execution plane to give teams autonomy, speed, and innovation. And I think that when you sort of, in a very practical manner, split these two, it actually gives you an opportunity to really unlock speed, but do it safely and go faster in this world of AI first and, and, and, and, and how much innovation it is that we are required to bring to the market to stay competitive. So here's the success factors for every enterprise.
No doubt if you take that approach, always think ecosystem, but don't go, you know, an empire. We're not building platforms to build large empires where everything sits in there. The ecosystem always wins.
And there's so many examples in the market of that where those who didn't build empires but built ecosystem actually win. Um, and don't think about diversity in your stack as a bug. It's, it's really a feature and it's really about unlocking that diversity by control, planning it together.
And then second, measure your outcomes. Please don't measure your tool counts. That's never a great way of building success in my humble opinion.
So stop chasing, stop chasing that fantasy where you're gonna have a whole bunch of fewer tools. Embrace it, be flexible. Think about composability, modernize incrementally and govern without bottleneck.
And I'll leave you with this quote that I always think about as, um, you know, sort of the one opening line or ending line of one of my presentation. And that is, listen, enterprises don't win by locking into one platform. That's never been the case.
They win by building delivery systems that truly can adapt to a changing landscape and tools just the same way that the business does. You do that and I think you're gonna have great success in terms of being able to operate, give developers the joy they need and be able to innovate faster, but do so safely. And with that, I thank you for your time and have a great, great rest of the seminar.
Bye Agents for cloud migration. Commvault Unity has arrived hero for Code. Arista and Palo Alto are gonna team up.
We're gonna be talking more about Microsoft and Anthropic. There's some AI driven espionage out there. And, uh, wait a minute, we're gonna see if cloud flares back online in the closer look in this episode of the tech field.
A rundown. Hello everyone. Welcome to the tech field, a rundown for November the 19th.
Uh, today is a day that I absolutely cannot endorse it's national play monopoly day. You're probably thinking to yourself, oh yeah, my family's gotten into some fights before I once played Monopoly with lawyers and they made me sign contracts. So never again.
Thankfully I've pivoted that business into talking all about the tech news that's been going on this week. And, uh, joining me is my somewhat sleepy co-host Mr. Alistair Cook.
Al it was great to see you last week in person, but I think that Jet lags starting to catch up with you With, you know, it's one of the amazing things is, uh, being in the states after working with the team, I got to go to Ohio with the team and, uh, be in person with people, but I also got to experience it's Sunday in the, in the US while it's Monday in New Zealand. And I'm usually on the other side of that. It was a fun experience, but yeah, it's a long way home.
It is a long way home. But thankfully a lot happened in the time that you were gone on that plane. And we're gonna be talking all about it because Yeah, well, you know, how often do you break the internet?
We're gonna start off with a story about the last people that broke the internet, and that's our friends over at Amazon Web Services. Because AWS introduced a new AI powered agent that dramatically accelerates cloud migration projects by automating tasks that used to take us weeks. The professional services delivery agent can generate proposals from diagrams or notes, deploy sub-agents for coding and testing and leverage AWS transform to modernize legacy systems.
It's all backed by insights from thousands of prior migration. These tools position AWS alongside other heavyweights like Google and Microsoft, and using AI to streamline large scale cloud modernization. Al, can Amazon finally turn the corner and make it easy to move things onto AWS?
I hope so because historically we've picked up what we had on premises shoved into, into AWS or another cloud platform and been terrified at the costs that we got after a little while. So going through a good consulting process to do that migration to, to get the most value out of getting your applications onto the public cloud, that's, that's a really vital part of cloud adoption. And the aim with this particular component, the AWS professional Services delivery agent, is to shorten the cycle for that instead of taking six months to a year to go through that planning and discovery and specification to have some AI agents deal with the huge volumes of data that you get as you're going through that, that process and to make sense of things through here.
So, doing some of the, the design and iteration ar around what does my infrastructure look like on AWS that's different from how it looks on premises. What things should I rewrite in order to use new platforms? You know, the, how many Rs are we up to 7, 8, 9 Rs of migration that's, uh, that we get with AWS.
Having some of those guidance and decisions is, is absolutely vital. And I've seen this previously that it looks very simple to move to a cloud platform. You just take what you got and you shift it across.
But there's so many interdependencies and discovering and analyzing those interdependencies, working out your cycles to, to move. That's absolutely really hard work. And it does seem like it's a combinations of choices, uh, process that really does suit AI agent will this lead to more successful and and faster migrations from on-premises to AWS remains to be seen.
And it's a, it's a complex kind of process to go through. And one of my concerns is that as you go through that process, you need to build knowledge within your organization about how to, how to actually enact the transition from on-premises up to AWS and the differences. My concern is that these agents might prevent some of that knowledge gain, that, um, internal awareness that's a vital to speed up a, a normal migration.
Of course, it may remove the need for that because the AI agents might be that smart. Commvault, our good friends at Commvault have just launched Cloud Unity and AI powered platform that unifies data protection, recovery, and identity security across cloud and hybrid environments, tackles AI driven data sprawl and rising identity-based attacks, uh, with integrated governance tools and all of the nice advanced threat detection and recovery testing. Got access is available now, but for releases coming early next year.
Tom, have you had access to the earlys? I have not had early access, but I was in the audience for last week's keynote when Sanjay Meti came out and kind of start talking about what Unity entails. Uh, we're gonna be, uh, following along with the live stream that's actually happening today on the 19th.
com for more details on that. Here were some of my big takeaways from what I got during the Commvault Shift keynote. The first thing is res ops.
I hope you're ready for a new ops, uh, designation. Uh, in this case. You know, with Commvault, it's resilience ops, right?
It is not enough to be available. You have to be resilient, you have to make sure your data never goes down. Uh, that is part and parcel of what Commvault has always been about.
We know that for a fact because we've seen that over the years. Commvault's kinda the gold standard for backup and recovery, but that's not the market that we're in anymore. We are in the data protection market.
And one of the things that they announced that, it took me a minute to kind of understand the totality of it, is something called synthetic restores. And you're probably thinking to yourself, well, how hard is it to restore data? But I want you to think about this because this is the way that the market has been going.
So it used to be that if something blew up, we had to restore it, right? Well, we had to go back and figure out where we had good data from. And in the case of a security incident, we have to make sure that the data is still clean and that means restoring back to, uh, a certain point in time, right?
But how do we know that the point in time as far enough back that we're getting the right data to restore and what happened to all the data that's been created since that restore point Can't all be bad, right? So what Convault is proposing with the Synthetic Restore capability is that they're gonna take a look at the backup. So we're not just going to last yesterday or last week or last month.
We're gonna take all of the backups and we're gonna look for the critical files that are infected, and we're gonna roll those back to the point where they were not infected. But for everything else that's not destroyed, we are going to roll it back to the last known good of that file. So if that last known good file was yesterday, then we could restore part of the system to a month ago and another part to last night.
That means minimal data loss, that means resilience all over the place. And that is huge for people who are uncomfortable with this idea of like, you know, we gotta start taking big full backups and full snapshots all the time because you never know when we're gonna miss something and we're gonna have to roll back. The other thing that I thought was big deal was the fact that Convault is integrating identity protection into their platform.
'cause one of the things I think that a lot of people are missing out on is that you can get infected and you can clean up all of the servers, but if the attackers penetrated into active directory, they've got a foothold, they can just keep coming back. Like, what if they changed the password on backup operators and added themselves as a unknown user, or worse yet at one that looks like a system account, they can just keep coding back in and doing everything they want to do, and you're just gonna have to keep rolling back. Only now they're watching you roll back in real time and they're combating all of those rollback points.
So eventually you're either gonna be forced to pay or you're going to be extorted for whatever else and have your data dumped. So I like where Convault is headed with this. Uh, the, the name change of course is important because we're unifying resilience into the platform.
And, and I'll admit some of the commercials in the keynote we're kind of cute. I kinda liked it. Uh, so make sure you stay tuned for more of that.
And also we've got some great content coming out from the people that attended, not my just myself, but Jack Poller and, uh, Jay Coutre and More Great Field Day delegates. So make sure you're tuned in for that. We're going back to AWS because they also have something else that came out with.
It's their Kero AI coding tool that has new features aimed at producing more reliable, secure, and testable code, including everybody's favorite, A CLI version. It also has proprietary based testing to validate behavior against specifications and the ability to rewind to earlier checkpoints. The update also enables Kero to work across multiple project route and support custom AI agents while qualifying startups can get a free year of Qro Plus Pro Qro.
Pro plus AWS engineers say that these enhancements promote a more disciplined, specification driven workflow that reduces debugging stress and scales AI power development with quality rather than speed. Al I kind of like the vibes on this one. Is kiro gonna turn the corner from letting AI just kind of write whatever looks good?
Well, I think that's fundamentally what Kiro ISS all about is not having those vibes, um, moving to a, a position where you write the specification of how your application should work and the AI implements what's written in that spec. Uh, I haven't gone hands on with this. The preview was, was launched in July and, uh, has has got a bit of buzz around.
I've, I've heard a little of people using it and I say, I really like the idea that there is a more declarative way of working here. This is define at the beginning how the software should work and then validate that it does work. Uh, in some ways it's, it follows a little bit of, of what I liked in the test driven design methodology where you first test for the functionality that you're going to build and make sure it fails 'cause you haven't yet built the functionality and then you build functionality until you, uh, pass the test.
Uh, that is one of the ways of going around. Let's design how things should work and, and make sure they do work that way. Uh, I definitely, this, this testing by properties is a really good functionality in here as well.
This is the ability to say this particular function should have this, this result. Now build a set of tests that, uh, somebody walks into a bar and orders a beer, orders 99 beers, orders minus one beer, uh, orders a car. Uh, does the software do what it's supposed to do?
That that kind of building those use cases, uh, those tests. So unlike test, different development where you build those first, the property based test approach builds those from your specification of how things should work. I like that whole declarative behavior.
Uh, and then the ability to work with larger projects, integrating Kero into your pipelines by using that CLI rather than having to do everything through a, uh, a, a click ops. Absolutely. This, this kind of stuff is where we're gonna see value in actually building real applications that are supportable and maintainable in the long term.
Yet don't require the vast number of developers hacking on little bits of code and particularly repeated bits of code over time, uh, remains to be seen how the pricing works versus value on this. And whether AWS can continue to deliver this, uh, ag agent ai, almost ag Agent ai. Um, for, for the long term.
Uh, there's, there's a lot still to be written about the cost of delivering these things versus what you can charge people for them. So we'll keep an eye on over. Arista and Palo Alto network are expanding partnership to address the rising hybrid data center complexity.
And of course, AI driven cyber threats. Uh, integrating Arista's, uh, collection of product di Ava MSS with Palo Alto's own Next Gen Firewall and, uh, Prisma Airs. Uh, they offer a unified zero trust, uh, security and real-time threat.
Quarantining centralized policy management, always my favorite. And DevOps friendly automation, delivering scalable, consistent protection across multiple data center and multi-cloud platform, uh, environments. Uh, this sounds like there's a partnership between uneasy friends and that hopefully this is gonna be magically wonderful for customers.
It should be wonderful for customers because when you look at what people are doing, especially in the cloud environment, they're leveraging a lot of Arista switches. That's where Arista has made a lot of their money over the last few years. But one of the things that Arista's having trouble getting off the ground is a security practice.
They've purchased a number of security firms over the last few years. I don't necessarily know that they've really taken off as much as we might like. And so what do you do when you can't really build it?
Well, you gotta buy something. And in this case, the buying is involved in a partnership, but they picked the best one on the block, right? Palo Alto Networks is one of the, if not the premier security firms in the business, right?
They have next gen firewall. They have a lot of cloud security offerings. What they don't have is an inroad into those clouds through the networking team.
Because as more and more people are starting to recognize the fact that networking security are two sides of the same coin, how do you displace existing installations? Well, in a lot of cases you have to partner up with a company who's displacing other things out of the network. Arista made their money displacing Cisco.
So how do you get into that network now that Arista has displaced them? Well, you partner up with Arista and Arista says, well, our stuff works really well with Palo Alto. If you've got a refresh coming up, now's an opportunity to take a look at it.
I will say though, that when this announcement was made, there were a lot of eyebrows that got raised because historically these kinds of partnerships lead to more engagement down the road. I'm not going to say the a word because that would be speculative at this point, but if there was a transaction to be had, this would not be a bad place for it to occur because both of these companies are very well known in their individual spaces. And I think wrapping them up would be a very unique opportunity for some people.
I don't think that that's gonna happen anytime soon though, because while Palo Alto is sitting on a lot of money, a wrist is worth a lot. And I don't think that this is an acquisition that they could really swallow in whole yet, but it would be very complimentary. And, and, uh, quite honestly, I, I'd I'd love to see, uh, someone like a Ken do to doing some Palo Alto presentations.
'cause that could be real fun. Microsoft announced yet another major new AI partnership with Anthropic and Nvidia, but this is signaling a move beyond the once exclusive ties that had to open ai. Andro will buy $30 billion in Azure compute while invest Nvidia invests up to $10 billion and Microsoft up to $5 billion to help Scalero's claw AI models.
This deal gives anthropic massive Nvidia powered capacity and strengthens Microsoft's AI infrastructure strategy as its relationship with OpenAI involves at Microsoft Ignite, which is happening this week, they also introduced a new IQ lineup of AI tools, work iq, fabric IQ, and Foundry iq, as well as Microsoft Agent 365, designed to automatically support business workflows as companies prepare for future of billions of AI agents. Al I think it's interesting that we've always heard so much about the partnership that Microsoft has with open ai and now they're going out and seeking out anthropic. Do you think Microsoft's playing the long game by betting on different horses or is there something else going on here?
I think this is definitely a, a hedging strategy. So we covered previously on the rundown that OpenAI pre head head an exclusive deal with Microsoft that OpenAI would run on Azure and that Microsoft would use OpenAI as its standard AI powers, things like copilot. We covered that this type deal had come to an end and there was a much lucid deal where OpenAI could use other vendors and we're contracting to use other vendors to provide that infrastructure and that Microsoft is free to work with other vendors.
So Microsoft has always been the king of partnerships partner with everybody. Uh, I see this relationship with, uh, anthropic as being part of that. They recognizing that there is no longer an exclusive relationship.
They need to have a re real relationship with a competitor to open ai in this case anthropic. And it's all part of the same partner with everybody and make sure that nobody can hold you to ransom. So OpenAI can't say to Microsoft, well the, this is the only feature set you get because this is what we're, we're doing.
Uh, Microsoft has then no leverage to say, well, we want this other feature we need for copilot as they make a commitment into Anthropic. Yeah, it absolutely gives them some more choices in there, uh, naturally enough, this is the AI money go round, and so Nvidia is in here as well. And Nvidia investment in anthropic means that Anthropic will hand back some of that money to buy Nvidia hardware.
So when we talk about this as a money go round, that really is money changing hands back and forth in some of these places. Uh, Microsoft continues to, uh, put money into this, uh, $5 billion, uh, invested here. So it's not a trivial amount, but it's not the $30 billion, $60 billion we've seen in in other deals along the way.
Um, and Microsoft has $13 billion in open AI investment. Uh, it really is, I think, a, a protection against, uh, open AI choosing their own path. We've seen some interesting challenges with open AI as they wanna change their, their governance and structure around there.
Uh, if that represents a risk to Microsoft, connecting up with Anthropic seems like a great way to mitigate that risk. Uh, we'll see just over time as, uh, whether this continues to grow, we see more and more money being put into, uh, anthropic and maybe a, a dial off on OpenAI. I don't think so.
I think this is really a protection of the relationship with OpenAI. Newly uncovered cyber attack shows the first large scale espionage campaign carried out mostly by ai. A apparently Chinese state backed group used AI agents to handle up to 90% of the operation, so including scouting potential, uh, victims and exploiting vulnerabilities in stealing data.
Uh, the incident highlights the rapid escalation of AI driven threats and the need for strongest safeguards around these AI attacks, better detection and also industry wide cooperation in as near real time as possible to protect against these attacks. Tom, uh, this is another arms race, isn't it? It's AI for attack and AI for for defense, Yeah.
And that's exactly what we talked about on this week's episode of Security Boulevard because it really did feel like this is kind of turning the weapons back on the creators a little bit. I also thought it was a really fascinating way that they were able to kind of slice this attack up so that multiple Claude agents were not actually knowing what was going on. It was almost like a operating in a compartmentalized cell structure so that each of the agents were returning work that was then being tied together by other agents to do the actual exploiting so that it evaded all of the models jailbreak capabilities of saying, oh yeah, we're not gonna do bad things.
You know, theoretically it'd be like, you know, the difference of me asking how do I rob a bank versus describe what good bank security looks like. Uh, one of those things would probably set off a trigger while the other one when used improperly would probably get me the answers that I need to know how to avoid security cameras and guards and things like that. Uh, also, uh, the, the press release from Claude, uh, I'm sorry, from philanthropic about Claude was rather interesting in the fact that they said, well, we detected it and we stopped almost all of it, but almost all of it ain't all of it.
And it, some of the attacks did go out, and of course now they're probably going behind the scenes to try to figure out exactly what was used to bypass the filters and the protections and how they're going to evade it in the future. And, uh, I I think that we're just, we're starting to see the tip of the iceberg here because this is probably not the first one that we've seen, but it is definitely the first one that somebody's reporting about. So, bravo to anthropic for at least admitting that this was going on.
But I think one of the things that we're gonna see as this goes on more and more is that people are gonna refine their prompt engineering. They're gonna be able to break these tasks down into finer and finer detail so that it really is going to become impossible or worse, yet they're gonna take the outputs from one group of AI and feed it to a separate set to actually leverage the attack. So that attribution is gonna be very difficult to trace down.
And, and I, I don't know if there's a clear cut answer here, because the real thing that people are saying we need to do is lock it all down so that it can't be used for attack. That's like saying, oh, well, we should get rid of all BCRs because they're only ever used to record, you know, copyrighted programs when that's actually not the case. Uh, we just, we have to find a better way to figure out to use them.
All right, we wanted to take a closer look at a story today. Uh, it took us a little bit while to write it, of course, because there were some internet issues. Everyone's favorite web infrastructure provider, CloudFlare had a massive global disruption that caused error 500 messages and took down major platforms including X Twitter and chat GPT along with most other AI platforms.
The outage, uh, triggered by a sudden spike in unusual networking traffic impacted thousands of websites early on Tuesday morning and highlighted the fragility of internet architecture. 20% of global web traffic flows directly through CloudFlare. The firm is actively investigating the root cause and working to restore full service while underscoring the need for greater resilience and digital infrastructure.
And I think it's kind of funny that we've run into this problem, uh, recently al where DNS update and AWS took down one half of the internet and CloudFlare getting knocked offline by a massive traffic spike, uh, took out part of the rest of it this week. Uh, you know, they, they're still attributing what exactly went on. We know that Cloudflare's gonna give us a great postmortem when they figure out exactly what happened, but I want to turn it over to you and maybe ask, are we putting too many eggs in one basket by relying on CloudFlare to protect us?
Because when CloudFlare goes down, we can't get anywhere. So here's the thing, CloudFlare is very popular because it does a great job of a very specific task of delivering applications globally, uh, to your users in a way that gives them really good performance anywhere in the world. CloudFlare has built an amazing network to do this.
And then let's, let's put this in context. Although we've centralized everything on CloudFlare, we don't often see CloudFlare outages. We certainly don't often see CloudFlare outages of this scale.
So yeah, the outages extremely visible the same way any of these centralization outages are extremely visible, but they're very rare. And so when you look at what is the impact on whatever system you're using, you'll still find that even with the, this particular failure or this type of failure, uh, you're still getting higher availability and better performance for your users across the, the last year than you would've if you ran this yourself or you tried to do some equivalent of this. So yeah, centralization means it's very visible when things go wrong, but centralization means you can spend a lot of engineering on making sure they don't go wrong often.
One of the things I've read on this, and, and it came across Reuters, is that the, the sort of triggering event here is an automatically generated config file that got too large and then caused a service to crash. Um, this feels a little bit like what we saw with CrowdStrike where a config file was deployed out and that caused the massive outage for, for, um, CrowdStrike. Um, it seems like these config file changes need to run through A-C-I-C-D pipeline to validate they're not gonna cause problems, yet we need to deploy them out fast.
You're the eternal optimist, al, and that's what I love about you because I, I took a, a slightly different, uh, tack from this and it come courtesy of our friends at down detector, you know, the website that everybody goes to, to figure out when you're having problems with stuff. Oh, wait, I couldn't check that one either. 'cause it turns out it runs on CloudFlare.
Yes. I, the world is better off because CloudFlare is front-end sites and preventing massive DDoS attacks. And their engineering has done a really great job of helping us extend and expand the way that that web works.
And, and a lot of other things too. They're effectively the Internet's proxy layer at this point. 1 from the trash heap of history, uh, because of bad configuration stuff.
All that being said, you cannot put all of your eggs in one basket. And, and we've learned that from a lot of things. I mean, all you gotta do is just look up the infographic from the XKCD of, you know, the entire modern internet.
And then there's a little thing down there, a little Jenga piece, and it's insert name there, AWS CloudFlare, uh, NGINX, whatever. What we're starting to see is that when these outages do happen, they happen at a a, a level that is difficult to contain. And you mentioned CrowdStrike, we've talked about AWS before.
Um, there are a lot of challenges that happen when we've built something that is effectively too big to fail and more than any other company, I think CloudFlare is pretty strict in the way that they deploy things, in the way that they, uh, leverage stuff. I can't fault them for this. How can you figure out, oh, the config file got too big.
When do we test for that? How do we understand that the problem is not the outage itself, it's the rolling effects from that outage. If, you know, it went down for 10 minutes, everything that checks on CloudFlare kept pinging, it kept going offline.
You know, little things that you didn't think were reliant on that. I was having a meeting first thing this morning and went to go check the calendar on somebody's website. It's offline, it's hosted on CloudFlare.
Like, oh, well that's fascinating. And so you've got to figure out how to prevent this from happening. Yeah, in some cases, you, you probably do need to have your, your load balanced infrastructure running on it, but I don't know, maybe put your status page somewhere else, host it somewhere that nobody goes like Oracle Cloud.
So you're, you're suggesting to avoid the, the problem that AWS had with outages when they had the big S3 outage and the, uh, the website at a WS that reports on the status of a WS services is dependent on the S3 service. Uh, yes, circular dependencies like that are really problematic, but, uh, yeah, I, I still view using a, a well-engineered system that is designed to continue to operate at large scale absolutely is, is way better than any of the other solutions for this. So yeah, I, I'm still comfortable with putting our websites through CloudFlare, having even trivial things go, go through CloudFlare.
But yeah, the tool that tells me whether things are working or not can't tell me if they're not working, if it's dependent on the thing that's not working. Yeah, might mindful of circular dependencies. The other thing that that strikes me on this is that there's, there do seem to be a lot of circular dependencies that go through CloudFlare because what we didn't see is when the re the issue was resolved, everything miraculously started working again straight away.
It took a little while for it to filter through the various layers that are dependent on CloudFlare before all of the layers caught up with one another. You know, this eventually consistent, uh, systems that we usually see at internet scales, uh, would be interesting to see if you had centralized everything into a single place, rather than having these eventually consistent distributed systems, whether they time to get back into operation would've been longer or shorter, because of course, in a centralized place, you have to replay everything in a single stream. Whereas when you're doing eventually consistent, you're replaying in different locations and your total time out might be lower.
Something that's not going to be affected, I hope by any cloud outages, any security outages. Um, now I'm gonna have to make some sacrifices to all of the good luck Gods, something that I expect not to be, uh, affected is AI infrastructure field day four. That will be my next return to the United States January 28th and 29th.
The event is already filling up. We already have, uh, four companies confirmed to be there, and we're expecting a few more to roll in as well. Uh, really looking forward to kicking off 2026 for Tech Field Day with AI infrastructure Field Day.
Uh, and then of course, Tom, you're going a long way of field as well. That's right. We're looking at the possibility of heading over to Cisco Live and Maya, which is gonna be in Amsterdam once again this year.
You know, I can't get enough of those little teeny tiny pancakes. com is gonna be, uh, your home for that. So when Al flies halfway across the world, I fly the other halfway across the world.
But then Al, you're, you're coming back in March? Absolutely. I can't stay away.
Uh, I'll be back for Cloud Field day 25 in, uh, the middle of March. Uh, and those tiny, uh, pancakes, the puffs, uh, my Dutch, uh, sister-in-law has, uh, gave gifted us the pan to make them. So maybe come down, visit me and we'll make you some tiny pancakes.
Uh, what isn't tiny, of course, is the tech Field Day rundown. Do join us, uh, continue to join us for the Tech Field Day Rundown. You can catch new episodes every Wednesday, either as a YouTube video or in your favorite podcast application.
Rundown streamed on Tick Strong tv. Of course, that's part of the Futurum Group, and you can find us on both Techstrong and RUM Group, uh, locations. We'll be back next Wednesday to talk about all of the IT news for the week.
That was, and until then, for myself and for Tom Hollingsworth, and for Corey and all of us here at the Tick Field Day team, we're wishing you and yours a great day. Great week, and we'll see you on Wednesday.