Techstrong TV September 16, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices. http://techstrong.tv/
Transcript
Hey everyone, it's Alan Shival and we're back here on Tech Drunk TV in beautiful Napa Valley at the Jfr Swamp Up event. Continuing our Day two coverage. There's a little bit of a break going on, you can't see, but out there people are eating ice cream and peanuts and potato chips.
It's a little mid-afternoon break, but we're still here 'cause we've got a lot more to bring you. Let me introduce you to our next guest. If you've been watching Tech Junk TV over the years and any of our coverage of Jfr, you already know him, but I'm gonna pronounce his name right for the first time.
'cause it seems my pronunciation is a little old fashioned. So let me introduce you to Yoav. Laman.
Perfect. Nice to Meet you, Yoav. It's good to see you.
Yoav, of course, is a co-founder, one of the co-founders in CTO here at jfr. You have a pleasure. How are you?
Likewise Busy. Lots of announcements. This warm up.
Probably The most, we're A few warm up that we have had, uh, lots of good, good feedback from customers and, uh, also some suggestions. So, uh, And that feedback's, that's, That's the goal actually. You know, what they say, the feedback from this year's Swamp Up will be in the products for the next, Hopefully even Well before with ai.
We have to. So, y we were talking, you know, before we got on, we have had a lot of people give us a piecemeal, a piece here, a piece there, a piece there. I'm gonna ask you, pull it all together for us, right?
Give us the a go overview of all of these great announcements, all this great innovation mm-hmm. That was announced here at Swamp Up. Okay.
So I'll try to give the full umbrella of announcements that we made. So we started with Jeff O Fly and Fly is, uh, uh, our own disruption of the platform for, uh, a new agent, uh, repository based on Artifactory. And that's, uh, that comes with, uh, a new user experience for managing software releases.
Uh, so that was our first announcement. Then we went over to, uh, UPT Trusts. And UPT Trusts is, uh, the way to control your software supply chain based on three, uh, major concepts.
First one is application that gives you ownership assignment for every release, every artifact, uh, in the JO platform. The second one is, uh, signed evidence. And we announced, uh, partnership, uh, with many leading industry vendors, uh, such as GitHub, such as sonar, such as ServiceNow, uh, to, uh, uh, integrate their evidence, uh, into, uh, into the JO platform to accompany the, the releases.
And, uh, finally, uh, it's, uh, policies that, uh, allow you to use the information, uh, within the Jet O platform, use evidence in order to assign rules for the progression of your artifacts, uh, of your releases, uh, all the way towards, uh, production. Uh, so this is aplu. It's a, it's a unified package that includes all these, uh, three main features, uh, ownership evidence and uh, uh, policies.
Um, so that was, uh, uh, another announcement. We also had a deep dive to our integration around evidence with, um, with GitHub to take the salsa provenance of GitHub, uh, workflow build and put them alongside artifacts in the JO platform, uh, as evidence, which is, when you come to think about it, it's the logical thing because, uh, you, it makes sure that, um, that the evidence itself is bound to the artifact and you can never get out of think. And it's also the fact that Artifactory is the entity that is exposed through your production.
So that's, uh, one thing that where we did a deep dive of Atrust. And the, uh, other thing is we announced on stage and integration with ServiceNow, uh, around Atrust as a, as a full, as a, as a whole. Uh, and we show the, uh, synergy between applications that many of our customers are already managing in ServiceNow, and how change requests in ServiceNow are going to be, uh, reflected as evidence in, in, uh, in JO uh, and vice versa, how you, how you can move between the platforms.
So that was, uh, also, uh, part of the big announcement of apta. Yes. Then, so it's a mouthful.
Then, uh, we move to a new announcement, which is around machine learning and ai. This is AI catalog. Yes.
And AI catalogs allows you to have governance over, uh, models that are packages, but also models that are, uh, uh, SaaS like, uh, anthropic and open AI and so on. Uh, under a single platform, you have a catalog where you can find the latest versions of the models and the metadata about them, like, uh, the security status, the, the licensing and, and, um, other metrics that have to do with, uh, model health. And then, uh, similar to what we have, uh, uh, in curation, uh, we elevated the same features for machine learning.
So you can allow different teams to use different type of models. Um, for instance, you may allow a research team to use deep seek, but you never want to see that, uh, in a production facing, uh, uh, release. And part of that when it comes to, uh, to SaaS models, is, uh, also being a gateway between you and the SaaS models.
So if you, for instance, if you're using open ai, uh, you will use it through the GO platform, and that allows you to have governance also over these type of models. Uh, so, so this is, uh, this is the gist about, uh, AI catalog. Mm-hmm.
And then we went into a bunch of security related, uh, announcement. I think I, I can mention two, uh, highlights there. The first one is the support for ID extensions.
Yes. Uh, and, uh, basically it's a combination of artifactory acting as a proxy for your, uh, vs code extensions. So we start with VS code, we will extend it to other ideas and, uh, curation allowing you, uh, to, uh, to, to control the, the, the, the, the extensions that your developers are able to install on their endpoints.
And this is one of the most dangerous and overlooked, uh, risk that developers are, uh, currently facing because you basically install a software on your, on from the internet that everyone knows that it's wrong, but, uh, for some reason with the ID plugins, it's assumed to be safe. It's not. And we demonstrated a social engineering hack that's a tempted developer.
We read about 'em, we hear about it every other week, whether it's a docker container or from a repo component. It, it, Yeah. So, so now you can apply this protection by, uh, pointing at, uh, Jeff oga, your, uh, single source of record for, uh, for your ID plugins too.
And another security related announcements that we made is around the Genal mediation and, uh, what we've done there. So, uh, we do with modesty, we, we have one of the best, uh, research teams, uh, uh, in the world at Jeff o mm-hmm. The security research team and our security advisories are very accurate to a degree that you can, if you find a, um, a, a a zero day in when you scan the code, the advisory that Jeff o gives you is, is one that if you take this advisor as a junior developer, it really tells you what the problem is.
It gives you an example of how to fix it, and it goes into details of, uh, what exactly need to be changed in your code. And what we figured is that we can just give it to the LLM and we can prompt the LLM with the research data of JO and the LLM will remediate the, the vulnerability or, or the zero that, that the jfo scanners found. We started with the integration with the, uh, co-pilot with the GitHub copilot, um, as part of the VS code integration.
But we will extend it. And the, the user experience is you write your code, Jeff Fog is, uh, scanning your code continuously, it finds issues, and it's taking the research data of the JO team to prompt the LLM and apply immediate, uh, uh, suggestions of how to fix that. And you just have to accept it and, uh, and merge the changes.
So, uh, that's the, the, uh, I think that's the last, uh, uh, big amount. No, I don't think we did, did we do fly? We, yeah.
Yeah. Started Fly, Fly With Fly. Right.
Okay. I got a little confused. An ambitious, an ambitious lineup.
Yeah. For one Swamp up. Yeah.
Very Ambitious. And the it, uh, team that talks relentlessly on the, I mean, that breaking trust to, to our users. The theme around all of it though, yo, Yoav, excuse me.
You're okay. Yoav, the theme around all of this is really the, the transcendence of ai, and you know, how we're seeing this just totally upend the normal flow of, of, of progress, of, of it, of software development, of the software development, life cycle insecurity in DevOps, in platform engineering, in, in everything. It's, if you're not adopting this to as, as OMI said on the stage, if you're not adopting this, get out of the room.
Get out of the room. Another important kind of theme here though, was no one company can do this alone. Right?
Even J F's a great company. You got a great research team, you got great developers, but the, we're talking about just upending entire Yeah. Ecosystems in, in of blink of an eye almost.
And so you need a partners like a ServiceNow and an Nvidia and Sonar and some of the other ones that we've spoken about. Definitely. How is it working?
'cause now you're not just working as one team, you've gotta work at the pace and in coordination with other engineering team. Yeah. How does that affect the pace of what you, you are doing at Jfr?
So, first of all, like you said, we are in an ecosystem, but, um, I think we are in an ecosystem of, of platforms today. Yes, there may be a few platforms in, in each domain, but still it's an ecosystem of lots of platforms that also makes the integration points. Once you figure out the integration points, uh, it, they, they are becoming very natural.
So what we find out, first of all, we have great, great partners with us. You mentioned ServiceNow and GitHub and Sono, but once you found out the logical integration points, it's very easy to get the teams together and, uh, create sort of a v team that works together and, uh, and creates the inter the, the first level of the integration and then carries on to, uh, uh, to polish it. Uh, so it's actually surprisingly, maybe, but works exceptionally well once, uh, ev once you have the clearance of, uh, how things are working together.
Now, another thing that you mentioned is the, the impact of, uh, of ai. So AI already made a huge change in how we code. Yes.
It's completely different now. Nobody even is surprised by that. Maybe the next surprising thing, but this is also, uh, a reality today, is that you have coding agents leaving, uh, alongside the, the, the human developers.
But I think that the main gap is around. So, so coding is kind of solved. It'll change a a lot, I assume also, but, um, it's already, it's already happened.
But I think where we still free, uh, see friction is around software delivery. Because what's happening is that releases are being created in a much faster pace than ever. So it's a really a nonstop release train that is happening.
And you cannot stop to, uh, think about irrelevant problems such as how do I version my release? And what is the compatibility meaning compared to the, to the previous release? It's just an ongoing flow of, uh, of releases.
With frameworks like UPT trusts, you will get the quality of the release so that you can trust. It doesn't matter if, uh, it was an AI agent that created the release or, or, or a human, or a combination of both. You have the gating, you, you have the governance to make sure that your release is, is ready for to be, to be deployed in, uh, in production, uh, and to be promoted, uh, across the different, um, um, policy gates.
Uh, but at the end of the day, you need a new way to identify your releases. Yeah. You need a new way to pinpoint them and, and, uh, and scale them up and roll them, roll back and identify issues with existing releases.
And this is, uh, part of what, part of the change that we introduced with Fly with the Gen release as well. I, I think between Fly and with, with AI catalog, that's one of the sort of unwritten or underlying thing things, is that versioning is going to change. Versioning.
Yeah. You will need a version, because at the end of the day, you need to the down. Yeah.
But it doesn't need to be something that you, uh, take note of or remember. Uh, and it cannot be, and I think the trust is still not there to walk in a full semantic way with the releases, but it'll get, it'll Take, I'm sure it could get, because trust, trust is a trailing indicator, never a leading indicator. You know what I mean?
You gotta earn it. Trust, You gotta earn it. Yeah.
But I think it'll also play out like that because of, uh, of agent to agent communication. Yeah. So the negotiation of what kind of capabilities you have, it cannot be bound to a, to a specific version.
It doesn't make sense anymore. No. It'll be negotiated based on semantic, uh, between agents.
And speaking of that, we actually had a, uh, Janni, Janan on, uh, about the PC server. He, he did a lot of great work on that. Yeah.
Made sure to tell us. So very proud of him. Yeah.
Yan started the MCP server of Jeff Fog as a local MCP server. As a, as a almost a, as a pet project. Yep.
Uh, and then we, um, kind of, uh, upped the game and, and did a fully remote server. Yes. Which is more, more difficult to do.
But, uh, as a company, it allows you, uh, to have better control over security. And also, um, you don't have to request clients to update the, uh, the MCP installation on the local machine. But it's a, it's a, uh, what's the word?
A reference. It's an indication. Uh, a reflection.
That's the word I'm looking for. It's a reflection of our times that before January, no one knew we didn't have MPC service. Here we are, September, MPC, here we are in September.
And it is the standard. You must have it, you can't do without it. Yeah.
I think it's a kind of a co common thing that we're seeing today. That, uh, thing is our changing on a, on a Right. You know, Today.
Today it's radically new. Tomorrow it's old hat. Yeah.
Well, MCP has a lot ahead of it. Like, there a lot of proposal of, uh, improving the standard and adding, yeah. Um, so, um, stronger authentication and, um, and the iden stronger identity and, and so on.
Well, I think there's also the A two A thing, and There's the A two A thing, which are we, we can argue whether these standards are Complementary. Well, that the thing about A two A is now that's part of Linux, I believe. Foundation.
Yeah. That's some big names. Yeah.
And, uh, we'll see, I mean, this is all gonna play out that the, the issue is for people like you and I who've seen this, you know, we've seen these games. We've seen these plays before, never at this velocity. That that's the key thing.
The velocity here, the, the time crunch. Yeah. It's, uh, incredible.
The warp. Yeah. Yeah, Yeah.
No doubt. What could we look? So next year in New York?
Yeah. God willing, I'll be there. It's my home.
September 1st, We will be there. What do we, what You want to give us an early preview or too early? I think it's too early.
Especially we just, uh, uh, wrapped up saying that, uh, things are changing so quickly actually. Yeah. So betting on, even betting on next year, uh, is hard.
I think you will see, uh, first of all, you will see there are some things that I can say that, uh, uh, you will definitely see like, uh, a lot of improvements on what we are bringing to market. Uh, today with APTAs, we have, uh, uh, a few more things, uh, at our sleeve. And also, uh, with Fly, uh, I think we will see a more, um, a more intention based way to do DevOps.
Yeah. Almost, uh, um, vibe ops thing if you want. Yeah.
Vibe ops. Okay. Well, dev vibe ops.
'cause you gotta have the dev in the ops with something in the middle. No, But in, in, seriously, it's going to be much more intention. Yeah.
Based, uh, with, uh, a higher degree of trust. So I think that this Is this, you know, I remember when HTML came out, all of a sudden I was a coder. I was never a coder.
But HT ML I could do then. Yeah. HTML 2 0 3, 0 4 oh CSS JS script, you know, all these things came on.
All of a sudden I wasn't a coder no more. I think we're gonna see a similar kind of thing. You'll have, everyone could be a, a developer with vibe coding.
Everyone will with AI will develop something if they need, but there will be the tools that the pros use, right? That vibe coating, refined vibe, coating squared, or whatever you want to call it, where it'll be for professional developers. And, and that's, you know, developers aren't going away.
They're not gonna be replaced. They're just gonna be empowered with This. I, I, I agree with you.
I think we will have humans mainly for, uh, just expressing intention and providing, uh, feedback loops. Uh, there's that. I, I'll tell you what else, and I've written about this.
Uhhuh for, You'll Need Humans for the Creative Spark. AI is very good. It's, uh, when you say, I wanna do this, I want you to do this for me, I want you to create that for me.
But it doesn't create the ideas. Of course, The human brain still creates the idea. It's that spark of humanity that I think will always be the Human is the guide.
The Human is the guide. Yeah. Uh, yeah.
But I'm, but the reason I asked you about next year is because I didn't think you would know what's gonna be next year, otherwise why you should retire if you already know what's gonna be next year, retire. But I would like to have you back on in July, maybe next year. We will talk about Swamp Up September 1st With Pleasure.
Alright. Yoav, Yoav Laman, CTO Co-founder helping wrap up our day two coverage. But we're not done.
We still have a few more. So stay tuned. This is Alan Shimmel for Tech Drunk tv.
We'll be right back. Thank. Hey everyone, it's Alan Shimmel and we are Live.
That's right. Live, uh, it at Swamp Up. Swamp Up is back in Napa.
After I think two or three years it's been since they were in Napa Should End, I'm thinking it might have been since before COVID that we were in Napa last. But we're really thrilled to be here. It's beautiful here.
It's a beautiful resort. But more importantly, there is so much going on at Swamp Up, you know, like everything else in the tech world. It's kind of the year of AI more than the year.
It's the era of a, the dawning of the era of ai. Still, I like to tell people we're still at the beginning of the beginning, not even the end of the beginning on ai. Let me introduce you to my first two guests of our Techstrong TV coverage here at Swamp.
Up to my far left. He's the guy in the, in the, in the, uh, shift happens. Frog shirt, Yuval.
Let me make sure I get it right. Excuse me. Yuval Fern back.
Yuval, welcome back. It's good to see you again. You Good to see you as well.
You know what, before we get to our next guest, Yuval Give to share with the audience your title and role at J Frock. Sure. So everyone, I am, uh, yba, I'm VP and CTO of MOFs here in Jfr.
Um, actually joined Jfr a year ago as part of an acquisition of a company called Quack. Um, and nowadays, of course, part of jfr ML and the new product that we launched today that of course we'll talk about in a second. Thank you, Yuval, to my immediate left not in the Frog shirt.
Is is Del Alek. You got that right? You got that.
Perfect. You got that on the money. All righty.
Ale is with, uh, Nvidia and Ale. Introduce yourself. Well, Thank you for having me.
Yeah. It's great to be in Napa. I was joking around earlier telling folks that, uh, you know, I'm glad we're doing this 'cause now my family really believe that I'm here for work fruit.
So, got the proof right. I got the proof now. So, uh, my name's Al.
I'm a senior, uh, director of product, uh, at Nvidia. And my job is to, um, take the software that our, uh, awesome core tech team creates, um, a hardened those, make them production grade for enterprises and help our ecosystem build, um, agents, right, that are fra frankly transformative in everything that we do. Something we were just talking about.
Absolutely. And, and that's a great segue. I I little something extra for giving us that segue.
We were at the keynotes this morning, right? You all led off Ale came on. Yuval you, you, uh, introduced a new product for Jfr called the jfr AI Catalog.
Explain to our audience a little bit, what, what is it? Yeah. So, um, as I shared, I joined J Fog a year ago, and as part of that, I've seen and got a lot of responses from jfo customers about the challenges they have with adopting ai, the challenges that they have with actually trusting AI and the amount of new models that are being launched daily, right?
Um, everyone's speaking about ai, but actually using that in production require more than just, you know, testing the new and shiny model. It requires the ability to trust that, the ability to trust where that model is coming from, um, who's the owner of that model, and even who is actually going to use that model. And as part of that, and as part of all that feedback that we received in the last year, we decided to launch the J 4K catalog.
And that's basically a solution that allow organizations, allow our customers to manage the entire life cycle of AI usage. I'll call it, from discovering which models actually exist, um, to deciding who should have permissions to which models, and eventually then serve those models, uh, track the, uh, usage metrics of the models and understand which application uses models and how. So the goal is eventually to allow organizations to understand where those models are being used by whom, and make sure that they trust those processes that are, you know, shifting in, in such a magnitude and such a, a, a, a pace of innovation that we haven't seen before.
Absolutely. We're gonna come back to that. 'cause I, I have some thoughts and questions, but not open.
Explain to me the Nvidia Yeah. I mean, connection, there's a reason for this awesome partnership, right? Right.
And so, uh, we're a full stack acceleration company. What that means is, right, uh, we're not just about producing processors or, or systems. We actually build out AI factories, but we go all the, all the way up, right?
For optimizing runtimes for not just models that Nvidia publishes, but also the ecosystem models as well. We call that nim nim inference microservices. And so, uh, what we do, you can think of a nim as, as a, a model with a runtime package as a single microservice, we spend a lot of time tuning that runtime to make sure it runs it efficiently as performing as possible, uh, on the NVIDIA stack.
Um, but equally, right, we contribute a lot to the open source domain. We're very, uh, we're huge participants in the open source community because going back to Eva's point of having that, that trust, having that transparency, it isn't just that we provide the NEMO tron open weights, which are fantastic by the way, and Excel really good at reasoning. But we, we also open source our, our training data sets.
We open source our recipes so enterprise can then take those models, further tune them for their agenda, uh, capabilities. And so being the ones that provide the secure runtime and the open source of the models and the weights and partnering with Jfr, what drives the services for having all that lineage was just an amazing partnership. Absolutely.
I, I want to dive a little deeper on this, right? So I was at Swamp Up last year in Austin where they announced the, uh, JFR Nvidia partnership now ale over the course of the 12 months. How have, you know, what, have you seen how this partner, well, look, AI has been on a hockey stick trajectory for these 12 months, right?
But how has that affected, what's the, the, the net that our audience could take about this partnership? What does it mean to them? I mean, look, you know, YVO kind of set the scene, right?
There's so much happening and it's happening so fast. I joke around and tell people that at one point, I think my kids thought I was a vet. 'cause I was talking about new animals every week from llamas to Mambas to, you know, you name it, right?
But, but it's awesome innovation that's happening in the ecosystem, right? So a couple things that are, that I think critical number one is all this innovation that happens, right? Yes, you wanna be experimenting a lot, et cetera, but when you have all this innovation that's happening, right?
And you have all this open source, the potential for exploits growth significantly as well, right? And that's something we talked about earlier when, you know, we were on stage. And so, uh, being, having that transparency, understanding essentially what's part of your runtimes where malicious code can be potentially like implemented is, is super critical.
So you wanna be experimenting, but you also wanna be careful and prudent when you're experimenting. And so that's why having a single source of truth, right, for your system of records, for all your artifacts is critical. And that's why that relationship's been awesome.
And, sorry. Yeah, go ahead. No, no, go ahead.
And I think the second point is, right, um, one of the first use cases we started using agent AI was, and actually defining the contextual, um, analysis. Doing the contextual analysis to understand whether vulnerability can be exploited or not, right? And I think, uh, I, I really appreciate the partnership that we have with the JAR platform, because that's something that take very seriously as well.
Just 'cause the CVE says, you know, it's got a high CVE score, doesn't mean it's exploitable. There's a lot that goes in to be able to exploit that. And so, you know, we see eye to eye in terms of how we go about really going deep and understanding the potential for exploits and protecting our, our, our customer base.
Absolutely. By the way, this, this partnership didn't start because, you know, us and Vidia thought that we should work together. It started because the J four customers approached us, told us that they need to trust the source of their models.
And, you know, the only models for market face, by the way, I think the target face is an amazing hub for models, but it's not enough in many cases. And customers approached us and told us that they want to have a trusted source of models. And NVIDIA is one of those trusted sources.
So a year ago, we, we partnered to make sure that the J four customers can actually get the Nvidia need models directly from multifactor and trust the region of those models. Um, and from there, of course, we, with that partnership with the security solution, so the contextual analysis, the ability to actually understand how those, uh, artifacts, how those models are vulnerable, and how we can make sure that in the production environment there will be no vulnerability. So eventually it's part of the same goal of making sure that the J four customers, and of course the NVIDIA customers can actually trust the model, trust the origin of the models, and trust that there are no security incident that will arise because of those new artifacts that they not need to manage.
And of course have to manage to actually make their product progress over time. Excellent. Ada, I wanna come back to you 'cause you said something right in the beginning that I want our audience to understand.
And that is, so a lot of people here Nvidia, and they're thinking G-P-U-G-P-U-G-P-U, not that you make a bad GPU, don't get me wrong, but the real key to NVIDIA's position is the software, is the community, is the ecosystem around cuda and, and, you know, uh, um, NIMS and, and so forth. Talk to us about that a little bit and why you are, we're on live tv Paul, uh, cameraman. I'm gonna ask you to grab outta my bag, my AI catalog paper.
We'll bring it up. We're gonna talk more about it, but I'll talk about, yeah. What the secret sauce at Nvidia?
Uh, Well, we're a full stack acceleration company, right? I mean, um, yes. We, we start at, at the silicon, but we go all the way up the stack, right?
And so we have AI factories, we have our, our software portfolio that goes all the way up to the, um, you know, what what we call blueprints, right? Reference workflows for how you go implement a specific use case for, for agents. And you get the full benefits of Nvidia when you take the full stack, right?
Because we're able to optimize all the way down to stack, but by no means you have to take the full stack, right? And we leave it up to our audience, our ecosystem, to meet us where they think is best. Some just wanna run on our infrastructure.
We love them. Some want to utilize right? Wanna go higher up in the stack and take advantage of the optimizations that we drive through software to enable that.
I think one key to Nvidia is, um, you know, call it success or, or or secret sauce is just how, how ingrained we are with the ecosystem. We, we go to market through our ecosystem. Our partners such as J Fog are super critical to our success at the marketplace.
And so you're spot on. We're not just a chip company, we're a full stack company. Um, right.
You can take us, you know, you can go with us up all the way, you know, all throughout, or you can just choose to meet us where you think is best for your, for your, for your domain. I love it. Thank you.
So Yuval talking about the jfr AI catalog, you know, I've written a lot recently about what I call shadow. I, uh, shadow ai, right? And we've seen shadow, look, I've been in, I've been in the tech business probably longer than both of you.
Okay. Um, I've seen Shadow, before I saw shadow open source, there was a time where enterprise's official policy was no open source allowed. Yeah.
It was a, it was a danger, right? I've seen shadow wifi. I remember being at a US Army base and the, uh, army Information Assurance officer telling me we don't have a wifi security problem 'cause we don't allow wifi.
And as I'm walking with him, I see people unplugging laps and throwing them under their desk. As soon as he walks by, they plug him back in. And wifi, we saw it with the cloud developers whipping out their credit cards and opening instances.
It's no different, no different with, it's probably even easier with ai. Yeah. 'cause you have take your pick, right?
Whatever one you want to use. So we call this a prop, right? They gave this out at the, at the keynote today for your talk, your joint talk.
Talk to us about the different models and how we're going to control shadow AI at the enterprise level. Yeah, Yeah. So, so first of all, yes, it is a prop because, you know, this, this booklet have six models in it.
Um, I believe that the current number in I phase of models is around 2 million. And, you know, on top of that there are, um, external like model providers like OpenAI and others. So that's another couple hundreds of models.
So, you know, the numbers are way more than that. And of course, no book can actually, you know, manage and track the amount of models that are being launched. Um, and models are nowadays used for, you know, so many different tasks.
So actually Shadow ALINE is in his talk, talk about different type of models like reasoning models and, and you voice models and models are being used for different tasks and not just for language models. Like, there are many models around computer vision and many models that are still used for structured data. And that's still a valid use case and still something that customers, you know, use as part of their use cases.
Eventually, the goal of the AI catalog is for organization to have the visibility about those models, about where those models are being used and how, and on top of that, as part of our launch, we actually launched a new product that will be available in a couple of months, um, called Shadow ai. Now, the, the issue of shadow ai, the problem of shadow AI is that in many cases, you don't even know that the model is actually adding one of your packages. It's possible that you downloaded the third party doer image.
Uh, that doer image that you use actually uses ai. Um, and it's not something that you can just, you know, not know about. Because nowadays, even the regulators in many places, for example, in the EU, actually force you to show that part of your product uses ai.
It's something that you need to have visibility on. It's something that you need to be transparent on. So the goal of the shadow AI product, of course, is connected to the J four GA catalog, is to just not just allow you with AI catalog to choose which models should be used, but also to see, to have the visibility about where model is being used, what you are not really aware of.
And if those models are being used, for example, are malicious, or those models that are being used are actually not approved in your organization, you'll be able to actually block those from being used or, you know, go through the pro through the process and approve those specific models. Um, so the goal is about visibility and the ability to discover where AI is actually being used in the organization. You know, again, my experience is you don't wanna stop people from using ai.
Yeah. And quite frankly, stopping people from using AI is like trying to grab sand in your hand. The, the tighter you make it, the more it slips out between your fingers.
What you wanna do is just, okay, you're using ai, let's let us document it. Let's make sure it's safe, let's make sure it's secure. Right.
And that, because otherwise you're fighting a losing battle. Nvidia has to see that as well. Al No, I, I'm, I mean, right.
We're not, we're not, we're not definitely fighting ai. Right. To your point.
Right? It's, it's, I mean, there's plenty of productivity gains new markets that it opens up, as I said, right? Uh, the, the only reason we're able to publish and maintain so many of these NIMS is because we're using a Gentech ai.
Right? Absolutely. But to your point, you do have to be cautious, especially with all this open source that's happening, all this innovation, et cetera.
You wanna create an environment that allows your developers to experiment. That is for sure, right? You wanna, you wanna continue creating that, that experimentation, right?
Uh, that you wanna enable as well. But then when you're going into, into production, yes, you want to have the safeguards that are in place. Um, you want to be able to have the observability, the tooling that is in place, right?
I, I go back to, you know, the, the nitron models that we provide, right? Just being open source in terms of not just the model weights, but the data sets of what it was actually trained on, the recipes of how we got there. Just to give the enterprises and the ecosystem that level of comfort, right.
To know exactly what's going on, right. Such that you always have that lineage that's super critical. Yeah.
I don't think you can, you know, on the contrary, right? Like, we're just on the, I think you called the be era, right? Beginning.
The beginning of the beginning, Right? And just imagine when physical AI comes into, comes into this world, right? Today we're talking about digital workforces, but very soon, right?
We're, we have these world foundation models where you're simulating and generating data to train these robots and these a autonomous vehicles, man, it's, it's about to get exciting. It, it already is. It already is.
Um, but you know, that brings, both of you mentioned this, but you kind of aid at the edges. You didn't eat the middle, which is something else that they spoke about in the keynote saying, I'm trying to remember the exact name. Was it AI gov or ai gov ops?
Something? It Was, uh, dev Gov ops. Dev gov.
Ops, excuse me. Dev gov. 'cause there's always something in the middle between dev and ops, whether it's saco or dev gov Ops.
I learned a couple new ones today. Yeah, sorry. Yeah.
Yeah. So, but that's really what we're talking about here. We want, we need governance.
Not, we're not here deporting AI models, right? We're here talking about you want to use ai, use the ai, but let's have some governance around it. Let's have some guardrail, some knowledge, right?
And that's, to me, that's the enlightened way of doing this, right? We're not discouraging use ai. I know.
So text trunk's part of Futur, we, we have a policy now where we're encouraging all of our people, the cameramen, the editors, the writers, the marketing, the decoders use AI to your heart's content experiment. We expect you to make some mistakes. That's okay.
Make the mis I'd rather you make mistakes trying something new than digging in your heels and saying, I, I don't want to use ai. 'cause if you don't use, I tell young people this who ask me all the time, you're not gonna lose your job to ai. You're gonna lose your job to someone who uses AI better than you.
That's right. All right. Look, this is something we think about as well, right?
And kind of now you're, you're going above and beyond just serving a given model. You're talking about managing the lifecycle of, of agents, if I may do that, right? Yep.
And, and that pipeline, right? We use, we, we have something called the NEMO platform for managing lifecycles of ages. Mm-hmm.
And that starts from data curation, uh, creating additional data that is, um, doesn't have the potential PII, that you know, you're not just collecting people's prompts, right? To then, uh, taking a model and adapting it for a specific domain. Then once you have that right, and, and putting it as part of a, of an agent, make sure you have the guardrails that are in place, right?
Such that it doesn't go, Ari, make sure you have the traceabilities. You can backtrack across the way. We have, uh, something called the NEMO Agent toolkit that allows us to drive all that traceability, all that observability, all that ping profiling around.
It's almost like, it's almost like onboarding a new employee. You have to teach them about your cultures and your norms at the company. You have to tell them the dos and don't dos, kind of like, you know, I'm doing in this interview.
Right? They're, yeah. Right.
And so, so it's exactly like onboarding a new employee and putting all those kind of, you know, managing it throughout this life cycle. And to your point, it it first, organizationally you have to, I love what you just said, right? Everybody's gotta be experimenting, but then making sure that your enterprise is leveraging the likes of the NEMO microservices to right.
To manage that entire lifecycle. I love it. Yuval, I'm gonna give you the last word and then we're gonna wrap up.
No. So actually going back to this, uh, dev golf ops term, and, and again, we talked about it today and, and this is in a way the theme of this swamper because, you know, automation is already around. We're seeing that as part of the development lifecycle.
We're seeing that now as part of the DevSecOps lifecycle and also around, you know, ML and AI adoption. The challenge is not, or is becoming not out to automate those processes and how to actually, um, um, use new technology. It's how to make that in a governed way, right?
How to protect the way that we use the new technology and make sure that while we are researching new technologies, while we are actually adopting ourself to this new future, we do have the visibility and the governance on top of that to make sure that we're not doing anything wrong. And that eventually our customers of, of our product can actually get benefit from those new technologies that we're Actually use in our products. I love it.
Yuval del, thank you Del. No, you got it. You got it.
Alan, thank you so much for coming on here, kicking off our coverage of Swamp Up 2025. We've got a lot more coming at you. Unfortunately, not all of it's live, but we're recording it all.
And over the next days and weeks, you'll be able to see everyone we spoke to here. I encourage you. com or Techstrong it, tech strong, AI digital, CXO Cloud native, now even Security Boulevard.
'cause we'll probably do something about dev gov ops on there to, for our full coverage at Swamp Up. But we're gonna take a break here. Stay tuned.
We'll be back with more from Swamp Up this text Drunk tv. Hey guys, thanks Withrow. We're here with Haw Ol, who's CEO of one io, and we're talking about how integration needs to evolve, especially in the age of AI because, well, it's getting a little complex out there.
Haw, welcome the show. Thank you. So one of the issues that we seem to see out there is, well, it's getting a lot more complex as we noted, but historically we had a bunch of APIs and then we got a bunch of connectors built on top of those, and we managed them through some sort of centralized platform if we were lucky.
But chances are we just kind of managed them in some sort of bespoke way that was not very efficient. You are. How does the way we think about integration need to change as we start to deploy all these AI agents out there?
It seems to be coming together at a level of scale that is mind-boggling at the moment. Yeah, well, I, it first thing the old all saying that goes in it, that if you build it, you have to run it. So I think that's the first principle which leads into this, um, more like a holistic thinking of managing innovations as more like a products rather than just ad hoc project that somebody, some hero puts together.
And then we hope, fingers crossed that they work, work. Um, so that's, that's the fundamentally fundamentals not kind of a mindset change that we need As part of that. Therefore, do we need to kind of build the integration platform first and figure out how to manage it before we go build all the connectors?
Well, of course, integration use cases are like various, there are different kind of indications that you, the simple, simple, simple from simple, um, um, innovations that can be kind of connector driven. Let's say that you need to hook up your active directory and stuff like that, which is really like simple all the way to this, uh, cross platform workflow automation that involves several parties. So of course you have to weigh, uh, the requirements are against the investment investments that you do.
But overall, the innovation platform is a kind of a good starting point, but it's only set of tools. So you really need to have some operations model. You have, you need to have governance, all those things on top so that technology is not, um, enough.
Mm-hmm. We have had integration platforms for years and they're usually managed by some internal IT team. Um, but it seems to me at least that it's not like we're integrating things every day.
We do integrate a lot of things, but is this really, you know, a capability that the internal IT team should have? Or should it just be something that feels more like a service that I just in vogue as needed? Mm-hmm.
Of course. Depends what is your business? If you feel like that innovations are your core business, then of course you invest into your own capabilities.
Um, um, at the end of the day, there's no, no sort of a way of outsourcing responsibility. So regardless of internal IT team doing them these things themselves or, uh, getting them as a service or something in between, there should be somebody with responsible of this. So, um, that said, um, majority of the companies and the prices, they have their internal team to support their business.
So things that are not directly creating, um, business value should be somehow put aside or buy both not to invest in too. Yeah. Um, will this whole equation get a little more complicated?
We talked about early on in the intro with the rise of AI agents, but are these not gonna be, I don't know, hundreds of thousands of endpoints that need to be integrated, not just with legacy systems, but each other? And how is that gonna all play out in your mind? Yeah.
Well, um, I, I would, I guess that the ai, um, helps us to build faster, first of all. And then AI agents are as, as, as we see them at the moment, they are mimicking human beings. So it means that they, they still need, um, real time, reliable correct data in order to operate.
That means that you need the integrations more than ever. And then the demand is becoming so, so, so much higher because of the AI agents will be deployed, systems will be, uh, and they require more and more data. So you need to build more and more integrations, which means that you have to find ways to scale, which means that, uh, the manual way of, uh, an approach based approach that you bring in bunch of people and start building from the stretch on top of the platform is not suitable anymore.
Will we also maybe, I don't know, create AI agents for the integration platforms themselves to help integrate AI agents with legacy applications? And the AI agent will talk to one other AI agent, which will then manage the process for them? Is that possible?
Well, they need something in between. And uh, like what you just described is it's sort of, uh, considered as a kind of API driven approach that you have APIs and interfaces. Putting AI on top of the APIs might make them little bit more, uh, you know, intelligent.
But the problem is that how, what is the communication? What, where's the communication happening then and how do you, the translations and mappings and all these things with different data models and how do you run the business logic on the integration? So point to point, yes, that I can see that happening, but then you need to have this, um, multi-point integration use cases.
Um, it's unlikely that ai, um, agents can replace it. They can, they can be super efficient when they get the data and can process it and send it over, but how they send it over there needs to be something in between mm-hmm. Some kind of fabric.
Right. And to your point, how that gets accomplished matters, especially from a governance and security and compliance perspective. So I can't help but wonder if the cart's before the horse a little bit and we're all excited about AI agents without thinking through exactly how these things are gonna get managed.
Yeah. Well I think we, thankfully we have one, one really good example in the, in the sort of past of it, which is DevOps, I think same fundamentals can be applied, uh, when it comes to managing integrations, taking the DevOps s culture, taking the automation, taking the monitoring, having the lifecycle approach, and that leads into better governance, clear responsibilities, accountability, um, SLAs, SLOs, all these things that are making integrations look like more at the products that have some, some, you know, clear reason to exist and they're not, add some, some ad hoc stuff. So I think that DevOps principle would nicely limit it into this picture When it comes to integration.
What's that one thing you currently see organizations doing that just makes you shake your head a little bit and go, folks, we should be a little bit smarter than that? Well, we, we still try to fix, fix this scalability issue with the sort of the old way of doing things, which is, uh, today I think was today Gartner has to released the latest magic quadrant for IPAs. And you'll see the same folks there year after year, integration platform as a service.
That's considered as a kind of a, some kind of a silver bullet for this. And nobody's talking about the actual requirements for this integration. So we are taking, um, we are enhancing the tools for developers to develop integrations.
Uh, but you still need the developers. So I, what you said mentioned about the AI being on the, on the IPAs platform and helping, helping them to develop faster, make more integrations without any management model. And we all remember what happens happened when the shadow it was introduced back in the day, like suddenly you have different things outside within the organization because it's so easy.
But at the end of the day, security, governance, all those things that are super important nowadays, um, they, you need, you just need a model for the operational model that covers them, the whole team. From your perspective, um, how will the current platforms need to evolve? Therefore, I mean, a lot of people will say, I already have an integration platform.
So what becomes the impetus for them to change that out or swap that out and, and, and what's the ROI on that? Well, I don't think it, it goes down to not only on the platform, what technologies it comes down to the understanding that innovations are, are, are sort of important part of the whole IT delivery as they, uh, are in the supply chain is a good example. Supply chain management innovation have been, have been fundamental for, for that kind of, uh, uh, concept for, for decades.
And now within it, we have to wake up that we should have a similar principles, even regardless of the technology we need to invest into competencies, the model, how we run it, uh, the whole approach of, uh, really investing into important things and consider integrations of products. So it takes a, also, I think there's a kind of a skill, skill gap in that sense that companies are not really getting there. And it's not about ai, it's about really having the competencies and understanding what it really takes to run integrations as a, as a part of a, um, organic part of your it, IT ecosystem.
Mm-hmm. So as you look forward to this new AI slash API driven world, you know, how many APIs will organizations be managing, do you think? And then, you know, are we gonna see some level of scale here that people aren't quite prepared for?
Well, I think it was some what it MuleSoft or Salesforce, um, study about this app, number of applications that we add, uh, every year in the larger enterprise, it's hundreds of new applications will be kind of added, especially like terms of ai. So there will be a lot of interfaces, APIs, and now the question is that how do you make sure that they are, uh, they match into your security requirements, all these things. So it, it's, the scale will be, will be just like we, I think we just, we, we have just scratched the surface when it comes to a number of APIs and interfaces.
And that being said, you need a governance model. You need operational model, otherwise you're gonna be like, you're, you're sailing your ship without knowing if all the, all the hatches are electric, are closed. Drew that.
So what's your best advice ultimately for IT folks out there as they kind of think this through and they start to, I guess, recognize the level of scale, what should they be thinking about? Mm. Quite often we see when we discuss with the customers, the biggest pain is that they, they say that they have technology, they have integration capabilities when it comes to team, uh, competencies and, and things like that.
But they still have a backlog of six months to getting there, which means, of course, simple answers you have to prioritize. But how do you prioritize if you don't really know what is the most business critical, um, uh, for instance, for what, what is the most bus business critical innovation for you? How do you do it?
So, um, my advice is that you really step back from technology perspective and start thinking that how do we actually deliver integration in integration at scale, which means that the operational model, how do we, how do we ensure that we are credible deli in delivery on time? All these things that are like basic stuff to any, any IT operation, but integration are integrations. Integrations are not open considered as as a product.
So people don't think them like that. So I would start with that type kind of a thinking that should be turn our thinking into more productized, standardized approach and what, what kind of investments we are willing to, to take in order to get there, which means then you have to prioritize. All right, folks, while you heard it here, Hank, when it comes to integration, we're gonna be looking at things at a level of scale that might be mind boggling, but at the end of the day, it all comes down to the fundamentals.
But if you don't start with integration, you're gonna treat it as an afterthought. It's probably gonna go wrong. Yuha, thanks for being on the chair.
Thank you. All right. And back to you guys in the studio.
Hey, I'm Bob Planker and I am talking about security and compliance, security and trust. Actually. Uh, you know, compliance is one thing, security is another thing.
0. So I like to start with sort of our approach to security and our, our approach to all of this stuff. And in fact, our approach when, uh, we talk about security and compliance, our approach is security first, security, you do good.
Security. Security is an always sort of thing, always on compliance. You're getting audited once a year, something like that.
If that's all you're doing security wise, you're probably in trouble at that point, but, uh, uh, you know, good security is explainable to your auditors or it should be at least. And so that's actually one of our goals. But, you know, we really want our customers to be able to be secure faster.
Security itself is not something that advances an organization. It's not the prime thing for most organizations. Some organizations actually do security and they care deeply about that, but most it's just a means to an end.
They want to deliver services, run workloads, that sort of thing. And so where we can turn things on, we like doing that, uh, where security's always a trade-off in some ways. So we don't turn certain things on because of those trade-offs, but we want it to remain flexible.
Not everyone is the same. Not everyone has the same requirements, many workloads, there's always something, right? So I really try to stay flexible there.
Recovering quickly. All manner of stuff can happen in an environment, and being able to, to be resilient to that is really important. Uh, resilience has really been the primary feature since, uh, of VMware infrastructure software since, uh, 2005 or so, when vMotion was invented, and we kind of stopped talking about it, but we shouldn't have.
And actually, the EU Digital Operational Resilience Act, uh, where banks in the eu were really doing a lot of work with that, uh, late last year, mid last year, uh, really highlighted all of the resilience features that we have. And then we've got a ton of stuff and, you know, just tactical stuff, uh, from failed application upgrades or de-risking just day-to-day stuff or, you know, strategic stuff, what happens if I get run over by a hurricane and that sort of thing. And so very important there.
And then last one on my list, really what we're after in VCF and the, the real differentiator is trust, inherent trust in the stack. Well, we talk about zero trust a lot. The industry talks about zero trust, but I see zero trust implementations.
They end up being lots more trust. So zero trust should be less trust, not more trust. And it's maybe just my opinion, but, uh, you know, that's, you know, fewer things to secure.
The easiest thing to secure is the thing that you don't have, you know, and so reducing the amount of trust, reducing the population of people that can have access, all of that stuff, very important for security. And then being able to replace trust with continuous verification. I mean, there's the old eighties cold war thing.
Uh, trust but verify. That's exactly right. You know, like you can, if you've got data from the last hour that your hosts are all up to date and are running the right level of firmware, all of this stuff, that's really powerful.
And so the ability to trust that your platform, your data is where you think it is. You know, data sovereignty is really important. There's a lot of regulations nowadays about data having to remain in certain places, uh, that you know who's got access, you know, what has access, not just who, but what other systems that the system is verifiably secure that, uh, it's being monitored, it's continuously monitored, and you can verify that the security state of it, uh, problems.
When that changes should be highlighted rapidly, it should, uh, come to people's attention. You know, somebody that can do something about it, dear human, dear human maintainer of mine, I am VCF and you should fix me. You know, that sort of thing.
And maybe it's, maybe it's innocuous, maybe it's an actual breach, but a lot of times it's just innocuous. Somebody changed something. I used to change security controls to debug and to debug things, to fix things, and then I'd forget to put 'em back, you know, and then I'd find out about it during an audit.
And then resolving things, uh, resolutions to problems should be quick, non-disruptive. If, if they can be, you know, vMotion is a great example of that, again, where we can patch infrastructure without taking the workloads down. And so that's, uh, kind of the core of how we think about security moving forward.
And, and really, again, not about security, but about trust. Can you trust your platform? Do you trust your platform and why?
So I'd like to talk a little bit about lifecycle patching. Some of the highlights, hit some of the highlights from, uh, uh, the security world. Things that are pertinent.
There's a lot to be said about lifecycle, being able to, to update, upgrade patch when there's a patch available. And we've gone through some changes over the last few major versions, update manager's gone, we miss you Update manager. But lifecycle Manager's really cool.
It cares deeply about the way a system is configured. It's doing the continuous monitoring as well. Hey, a system has extra pieces of software on it.
Well, that's not good. You know, like, we should check that out. That sort of thing.
And so we've taken a lot of feedback around that. How do we make that easier to use? How do we make it more valuable?
Multi-vendor cluster images. Uh, you know, in a perfect world, we all get a dump truck full of money backed up to us every couple of years, and we buy a whole new homogenous cluster. That's not how the real world works.
Not at my real world at least. And so, uh, um, yeah, uh, making that easier to deal with, taking out some of the friction, uh, ha the high availability and NSX components were add-ons and installed separately, and they get into dependency loops. We're one big family now, and VCF, it all just ships as part of it, so that's gone.
But also things like GPUs, all this ai, newfangled AI stuff is neat, but we've spent 10 years making GPU usage just part of just one of the gang as far as our workload is concerned. Being able to move it around, you know, AI researchers and data scientists can feel important on their own, you know, but from an infrastructure perspective, it's just all the same. And that's really nice, especially in nine.
We've really done a lot of work with the vMotion stuff. Live patching and custom EVC profiles. Talk a little bit about those here.
So live patching is something we announced in eight, vSphere eight, but its scope was so limited, we actually haven't had an opportunity to use it yet, you know, and that's gonna continue into the near future too. But, uh, in nine, our, our vision for it is that about 80% of anything that a host needs to be patched for should be covered by live patching, you know, and that's really nice. The, the ability to not move workloads.
Most workloads can move just fine, but there's big ones. There's, uh, workload administrators that are jumpy about it. And so we want to, uh, uh, where we can leave them where they're at.
We enter partial maintenance mode and then partial maintenance mode just stabilizes the machine. Nothing going in, nothing coming out as far as workloads. And then it does what it needs to if it needs to repair, uh, and patch the virtual machine monitor.
And we'll talk a lot more about the virtual machine monitor in a few minutes here. Uh, then we do what's known as a Fast Suspend resume. It's basically a process to process vMotion is what it amounts to.
It's milliseconds, nanoseconds, I dunno, I I used to say that it's measured and it could be measured in CPU cycles, but any, anything can be measured in CPU cycles. Caveat here is, uh, DPU and TPM enabled hosts are not yet compatible. Dpu u's got the ESX running on the DPU itself.
So there's considerations there, and tpms, the extra security. So what we're doing with Live Patch is replacing part of the operating system, you know, and we don't want to ta we turn on extra security to prevent attackers from being able to do that. So we need a way to authenticate ourselves to the system so that attackers can't do this maliciously, but we can.
So it's in pro in process. It's number one question. Hey, Have a quick question there.
Yeah. The, the TPM enabled hosts, we know that Microsoft has made a big deal about future versions of Windows needing a TPM to be enabled. Uh, is this something you feel is gonna impact the ability to virtualize, like at, at this point, workstation endpoints, or do you feel like this is something that's gonna be easily overcome very soon, like you are working on figuring out how to make this TPM compatibility thing work?
Uh, so this is at the host level. This is ESX itself. So ESX is the, the hardware trusted platform module belongs to ESX and no workloads touch it.
Um, there's no workload data stored there whatsoever. Uh, for workloads, we've got the virtual TPM, which is completely separate. It's rooted in VM encryption, so it keeps it secret safe that, that direction, and it's not impacted by this at all.
So, okay. Thank you. If that makes sense.
I have, since, uh, Tom broke in, now we can ask questions. I'll go, um, How does patching work in the context of B-S-X-I-I being part of the whole product of VCF? Can I just use this feature to pack, just patch, just so when something critical happens, or does it have to come apart, come to, to me, as part of a huge VCF upgrade or patch, uh, itself?
It, it Can be both. Uh, so we've got a new versioning scheme as well. Uh, some logic has been applied to our versioning.
0 U three Q-Z-S-S-P whatever anymore. Uh, nobody knows what those are. Uh, everyone knows what Arabic numerals are and, uh, that, you know, the versions go up and we have newer stuff.
So really trying to do that. 0. 2 as an example.
1 is a VCF bundle, and you, you'll get things as that as well. 1 is a tactical patch, basically. And, uh, so we're gonna apply that.
1 is released, that'll be something you'll apply like this. But you can get these patches in both directions, uh, if it's big enough or, um, and there's a, there are timeframes associated with these things as well, you know, monthly, quarterly. 1, for example, would be a quarterly patch, that sort of thing.
So, you know, trying to make some sense out of it. But yeah, to your question, you'll, you'll be able to see the, uh, ESX updates in all of those sorts of ways. And, And Bob, this is, uh, Jack Poller from Paradigm Technica.
Uh, another question on patching, which I know is, is sort, not really security, but still security is, are, are patches going to be inclusive or admins gonna have to be responsible for saying, I need to build up a stack and a chain of patches in order to get my machines? Oh, that sounds like a nightmare, Jack. The, uh, um, no, they're always inclusive.
Uh, and with very few exceptions over my experience with VMware, basically, we, we, they're always cumulative. So if you apply the latest stuff, the latest version, you go out and support portal, download the latest thing, you'll have all of the patches up until that point. So, cool, no good questions.
Uh, EVC. So making patching easy also, you know, uh, if you've got mixed, mixed clusters, clusters that, uh, so you get different, um, generations of CPUs, you can't vMotion back and forth between them. EVC, it enhanced vMotion compatibility, basically smooths out the differences between them.
But it's been incredibly hard to use because you had to, you had to remember to turn it on when the cluster was absolutely empty, right when you built it, and nobody remembered that. And then, or you gotta wait for a power outage or, or some other catastrophe and then make an unscheduled change, that sort of thing. And so, a couple with that, the, uh, uh, CPU generation CPUs have kind of gone nuts, and there's a whole bunch of different types and varieties, and there's all this edge stuff now that uses all that stuff.
We've got the ability to just capture what you're using. And in fact, uh, uses link mode if you've, you've got your host in link mode, uh, clusters are all linked to, to each other. It'll look at the whole thing and say, here's the baseline for all of this stuff, and then you can just turn it on right where you're at.
And so hopefully that will make things a lot easier moving forward for, uh, uh, again, just patching, being able to deal with it. The, some of the friction here deep inside the hypervisor itself, doing a lot of work as far as security and the layers of security in here. Uh, first couple of things, code signing, we've been talking about that for a long time.
Our ecosystems got a lot of inertia to it. We still have partners, vendors out there that are telling people to shut security off because they're not signing their code. You can do that, you can still do that.
We're on our way to making that not possible. But, um, if you do that, now, you get an indispensable warning that you've got a security problem, which you do. Uh, secure boot, 40% of the world uses secure boot.
It's been around for 15 years. It's a great way to prevent malware. Trying to make that easy as well.
You can enforce it via, uh, configuration profiles. Now you can actually just turn it on, switch over to it, and ESX will boot just fine using, uh, using that now. So shouldn't be any barriers there anymore, except, uh, in people's minds, hopefully.
So let's talk about the user level, monitor sandboxing, and then confidential computing a little bit too. Uh, so inside of ESX, we've got all these different layers of, I often compare it to an onion, you know, you peel it a little bit, you cry a little bit, it's all good. And, but you've got these different layers there.
The guest operating system, unless you're running Windows three one or dos or something, which still run, by the way, you've probably got inpro process protections there. You've got a, a roll based access control model, something like that around that. You've got the VM runtime container runtimes as well, just a workload runtime, and that's a security boundary.
And then around that, in seven, vSphere seven, we introduced a sandbox. Basically, it watches what the runtime does, and if it didn't try something funny, it kills it and sends a alerts, you know, and it's not perfect, but it's a heck of a lot better than it used to be. And these protections are available on all of the workloads running on E-S-X-E-S-X itself is a security boundary.
You know, there's, uh, you can, uh, sequester certain types of workloads and certain, uh, security, you know, keep the same security levels together, that sort of thing. Then underneath CPU in memory, which about eight years ago, we discovered that the promises made by CPUs and memory controllers and IO controllers, and that aren't necessarily what actually gets implemented. And so, and there's more of those.
I mean, recently in the last couple of weeks, there's even been announcements about new versions of Specter and Meltdown esque vulnerabilities from a MD and and such. So nobody, nobody's, nobody gets out of this one without a little bit of blame. But what do we do about it?
So we've got the, the two main types of vulnerabilities here, hardware vulnerabilities, where your guest operating system, an attacker that's got access to a guest operating system, can coerce the hardware into giving a data it shouldn't have access to. And then you've got the VM escapes, you know, the, uh, um, where you can, an attacker breaks into the guest operating system and then can get out into ESX, and you don't want them there either. So, as far as hardware vulnerabilities, we'll talk about a little bit about that.
Confidential computing, for example, we've had A-M-D-S-E-V-E-S and Intel's, SGX technologies built in since seven. You know, there's follow ons, those are kind of hard to use, and they kept secrets from the hypervisors. And so the hypervisor basically takes its ball and goes home, says, I'm not gonna help you with vMotion, I'm not gonna help you with all this other stuff.
And so, a MD and Intel came up with, uh, new versions of these that help with, with a lot of that stuff. And so S-E-V-S-M-P-T-D-X, the follows, uh, follow-ons to these, those technologies. And so, uh, a MD in particular, they, uh, uh, they implement their versions of the security, the confidential computing, uh, uh, technology.
They've got a security processor. It's an arm chip that's actually integrated into their epic CPUs, which is cooled by itself. And a guest operating system that wants to participate can request an encryption key.
And, uh, uh, it gets encryption key. Its data is encrypted in memory and in the CPU registers as well. And so that's really nice.
And so it's not an all or nothing thing. You can turn certain guest operating systems can enable it. If you've got a guest operating system, if you are running Windows three, one, you don't have to enable it, whatever, it can be just it's own little operation going on there.
And then if there is a security vulnerability, uh, and a guest operating system can get access to something, it shouldn't have access to the, uh, um, all it gets back is cipher text. It doesn't have the encryption keys there. So that's a nice powerful protection.
It's actually kinda interesting that CPU manufacturers are basically admitting that they are probably gonna have more problems like this. And so, but it's a way to protect yourself. And it's really important in shared environments, especially public cloud.
It's been very popular in public cloud because you don't know who your neighbors are. You know, it's a little bit of different security profile when you, when you're your own neighbor, you own the whole box, the whole box belongs to you, that sort of thing. And so, but, uh, uh, building that in, we've got a lot of customers that are running in shared environments and that do want to take advantage of this.
So we've got the initial steps here, uh, to enable these particular technologies. Does require host hardware support, as would seem obvious. Uh, right now it's delivered via RPQ.
We actually want to ask you a couple of questions. If you want to turn this on. It's not very onerous.
Uh, so just, um, yeah, uh, reach out. If, if people want to turn it on, uh, it will be, yeah, it'll be in, in the future. It'll be fully, it's tech preview, essentially.
But, um, yeah, more to come. So, Bob, yeah, what's up? Uh, I understand the use case here for confidential computing.
Makes sense. You wanna protect from lateral movement. Uh, any kind of idea, what kind of overhead, if any, that could introduce, uh, on the host itself?
That's a good question. And actually it, well, and it's gonna get the, you know, if it had a motto, it would be, it depends, you know, the workload, it depends on IO and that, there's actually a complicating factor here too, and I'll get to that in just a second. Uh, the user level monitor, we implemented this with a change in the virtual machine monitor.
So performance testing is actually ongoing right now. Uh, it's, yeah, it's less, you get, it's less performant than the, the old style. But, uh, um, yeah, we're working on it right now.
I don't have a specific number. You know, everyone wants a number. Is it 5%?
Is it 35%? I don't have a number for you, But there, there is a number out there, and it could vary based on the customer, but there's prob likely to be some kind of impact that you need to account for. Oh, yeah, there is a number for sure.
We don't know what it is right now. Okay. And we don't, we haven't properly, we haven't characterized the workloads enough.
So the virtual machine monitor that we've been dealing with is 20 years old. You know, like, and we've got good characterization of workloads on it. The, uh, um, yeah, the new one is not that old.
And so, uh, our performance in the office that the Broadcom office I'm part of, uh, there's a guy that sits down the hall for me. And he, that's exactly what what we're talking about right here is exactly what he's been doing the last few weeks. So, yep.
And he was unwilling to give me answers about it as well. I asked exact same questions. So the, uh, uh, moving forward, let's talk a little bit about that.
So, uh, CPUs basically have two modes in which they can operate. The, uh, um, one mode is VM kernel or the kernel mode where anything running runs really fast, has no permissions. 'cause that's why it runs really fast.
And, uh, can, has a run of the box user mode is a little different. The, uh, user mode is, uh, um, doesn't have run of the box. It's got permissions.
It's, it doesn't have permission to do anything really. But for performance reasons, all hypervisors run things in kernel mode. And, uh, oh, it makes sense.
But that means when you've got a a VM escape, you're root, you're administrator, you're, you can do whatever you want there. And so that's not good. So what we're, what we're doing is part of this, and you'll see it in nine.
It's in nine, but it's not the default yet for a lot of these same reasons, Ken, that we were just talking about, that we're kind of conservative when it comes to this stuff. So, uh, it's the default, if you turn on memory tiering, it's the default if you turn on confidential computing, but it's not the default. There's some, uh, advanced parameters you can set if you want to, uh, uh, to make it the default or make it a certain percentage of the workloads that you start.
But, uh, um, yeah, it de privileges it. So somebody gets out, does a VM escape, gets out out of the sandbox even, well, what are they gonna do? They don't, they have no rights to anything.
And then beyond that, we've taken those sandboxes, you know, the idea of, Hey, we've got these sandboxes around the workloads themselves, but what about all these other processes? Well, we applied them to the other processes. So these are just four different examples.
I didn't want, there's a lot more little boxes I could draw, but they've got a sandbox around them as well. They've got a permission model, and if they try to do something funky, again, killed alarms. Thanks for playing.
So, uh, uh, yeah, just trying to sandbox as much as possible. Contain the blast radius there. They're basically doing a change through with a vm, like you're doing process, uh, Services.
Yeah, exactly. Yep. So, uh, you know, the old school, uh, vulnerabilities, like the service location protocol, which has gone in nine, by the way.
Uh, that open source project was unmaintained for a number of years and had vulnerabilities, and we had to issue advisories about it and stuff like that. You know, uh, the problems there could have been contained. Certainly we want to get it fixed, but you know, the idea is to buy time so that you can do the stuff that's not in a panic.
And, uh, so, and that's nice. So workloads, people wanna run workloads on their platforms, and I don't blame 'em. Uh, most people don't just run VCF for the sake of running VCF like I do.
Um, number of sort of tactical, uh, incremental improvements to workloads. Uh, the really interesting things here, secure Boot, there's a lot of people wanting to sign their own, do their own secure boot stuff. And that's, uh, cool.
We support that now, support that officially now, there was a backdoor way to do it before. And, uh, so we, that's been promoted, uh, hardened virtual USB, we had some advisories about that. And anytime we have an advisory or two about the same subsystem, we'll take a look at it and harden it.
So, virtual machine hardware 22, you'll see that, uh, Microsoft's Black Lotus vulnerabilities where they lost control of their signing keys for Secure Boot, uh, that was not good. Uh, they've been slowly, quietly replacing the, uh, uh, and revoking UEFI certificates over the last few years as part of Windows update. Uh, so if you are running nine and running the latest versions of, uh, virtual hardware, you'll need the latest versions of the Microsoft ISOs.
0, we bumped the revision on there. There were some feature changes, but forensic snapshots, this is another interesting thing, because again, we're kind of conservative when it comes to operations. And any snapshot that we, we take, we want to be runnable again, and convincing engineering that forensic snapshots don't need to be runnable.
Actually, that was easier than than we thought, but, uh, uh, forensic snapshots don't need to be runnable. They need to be scannable by a tool, but that's it. So we've got support for that now too.
And so that's really nice. I think the biggest thing for me, for workloads, we get a lot of resilience features in the platform for workloads, but the VPCs, the virtual private clouds, eh, I, yeah, the, uh, um, are really interesting. The, the idea that you can dynamically create network segments for workloads to isolate them, apply security controls to them, all of that stuff.
And you can do it globally, all kinds of, there's all kinds of neat stuff there. I think that's a really interesting thing moving forward. And as NSX becomes tightly integrated, well just becomes part of ESX, it's, uh, um, yeah, that integration is getting a lot less complicated to do too, and a lot easier to set up.
Cryptography. People are deeply interested in keeping their secrets and cryptographic methods or how that works. 3 is the default all the way around.
Uh, we can fall back by default. 2. Again, we're a little conservative for backwards compatibility, but, uh, you can set that, I'll show that to you in a second.
And you can choose your cipher suites as well. Um, one, I've got slides for all of these things, so I'll just skip into it. Key wrapping.
So one of the ways in which you can do encryption is to keep your keys externally in a key management system. And that's great. People, uh, people do that, but we never delete a key.
We actually can't tell if you're still using the key or not. And so people get really angry for a bunch of different reasons. One, they get all these keys in there and they don't know what's in use and what isn't.
2 million bucks in keys every year, you know? And that's a lot, you know, like, I, I think that's a lot. And so people asked, and three, they wanna rotate their keys.
And so that kind of plays into which keys are actually in use. And so we've got a wrapping key now. Uh, and so it's not just the two keys, the data encryption key and the key encryption key anymore.
You can, we can wrap the key encryption key. You know, all problems are solvable with another layer of abstraction, right? You know, and so we, uh, um, we can wrap that key.
We can rotate that key. We can give it a name that your KMS provider, uh, admin or your KMS admins can find. So in that case, You are wrapping a relatively static key with the dynamic key store in the KMS that people would rotate.
Can we do a, can we do a force and say, Hey, we're, we're not sure of the, the, the validity or that, that the, the key we've wrapped is compromise. Can we force rotation of that one as well? Yes.
Yep. You can, uh, you can also create, uh, so one thing I didn't mention here, and I'm sorry, should have actually, because, yeah, uh, so there's this idea of rekeying. There's a deep rekey where you, uh, have to power the VM off and you rekey all the whole stack, you know, from scratch.
But there's these shallow rekey where you're changing the intermediate keys, and you can do that while everything's online. And so that's how you would do that. You would rotate it through a shallow rekey process.
Uh, you can either create a, another key provider to do that, or you can just do a, a, a shallow, uh, rekey here, however you want to do it. There's mechanisms for for that. It's, it's very flexible.
Good question. Uh, ciphers, I was talking about this. Uh, we've hit a NIST 2024 TLS one three only, which will be a popular option.
3, only the two ciphers that pass, that pass all scanners globally. You'll have to find other things to talk about with your GRC folks. So sports, weather, international regulatory compliance, whatever.
Uh, speaking of international regulatory compliance, the ca browser form the standards body for, uh, browser certificate validity and all that stuff has over the next two years are lowering certificate li legal lifespans to 47 days, which sounds like an absolute nightmare to me. Uh, I long for the days where I could get a 10 year certificate and be done with it, but, uh, I get why, you know. But the, uh, um, yeah, so VCF has got interfaces for managing these things, being able to see the STA status of it, uh, renewing them automatically, and we've got things on our roadmap for better, uh, support for external ACME protocol, that sort of thing.
So, yeah, uh, a lot of good stuff there. A lot of, a lot of good stuff. Pa, centralized password management, centralized security operations, auditing, all the stuff that was in Aria operations prior, has become VCF operations and really doubling down on the auditing and monitoring for security, being able to dive into, uh, you know, you get an alert that a security control has changed, you know, who did it?
Being able to go into the VCF operations for logs, formerly re operations for logs, uh, log site, whatever we wanna call it. Um, it's all becoming VCF operations, so I'm happy about that. But the, uh, um, being able to dive into that stuff, being able to see who did it, uh, maybe not tell why it was done, but, you know, get to the, the bottom of things more quickly so you can figure out is it an actual breach or just, yeah, junior admin doing something, you know, or senior admin doing something and forgetting, you know, as I said earlier.
So a lot of good stuff going on here too. And also for compliance, trying to get ahead of your compliance so when the auditor shows up, you're ready to go, you know, you don't have any surprises. But also keep it flexible too.
So if you're, if you've made a business decision to not do a security control, you can shut that off. So it's not always bo bothering you. Getting towards the end here.
Access control. Access control is a big way in which organizations are breached, frankly, you know, identity systems. And so being flexible with this, we're also really trying to get out of the business of being an identity provider, because there's so much better stuff going on with real identity providers out there, you know, and if you need an on-premises one, the Symantec VIP stuff works great, otherwise we support Okta.
We support Ping Azure ad or Intra id, but also generic PRI providers as well, saml, uh, OAuth providers, all of those, uh, you can set up your own as well. And so that's, that's been something that's been asked for. And so there it is.
Uh, we've got a site-wide VCF wide unified configuration. You set SSO up once and it'll configure it on all of the different, uh, interfaces. You've also got multiple deployment options.
It's the old VIDM stuff, except it's been changed to be a broker. It's the VMware identity broker, and it's been embedded in all of eight. It was embedded in vCenter, uh, as a broker.
It doesn't have its own identity man identity provider stuff in there anymore, like VIDM did. But it can broker connections to other things. And so you can use the embedded one in vCenter.
You can have an external, uh, you can have an appliance deployed as part of VCF or you can have an appliance cluster. So three, three different appliances deployed, however you want to do that. 0, and some of that is actually programmatic access to the role-based access control systems, which has long been asked for, long been needed so that people can write stuff to automate these things.
Uh, you don't have to do weird, uh, weird stuff in the back end. There's standardized interfaces for it. So that's what I've got for you guys.
Uh, we publish all of our, well, we publish as much as we can. Anytime I run across a, uh, something that could be public, I've been putting it out on our GitHub repository. Um, and whether you believe in QR codes and their security or not, well, here's a QR code, and it's doubly bad if you, uh, swing that way because it goes to a redirector, which then goes to my GitHub, URL.
But, uh, um, yeah, you can take it out on me and explore some sometime when we see each other. And that is my, my deal. Thank you folks, and security and trust.
Thanks, Bob. Hopefully you and I can catch up again sometime soon for a, uh, drink. And, uh, and Emil, um, Bob was one of the delegates at my very first Tech Field day event, so we kind of miss him from being on the delegate side.
Awesome to hear about that fairly consistent story, right? Keep things up to date. Thank you very much for joining us.
This has been an awesome series of presentations around VMware Cloud Foundation nine. If you missed any of the presentations, you'll be able to catch up with them very shortly on the Tech Field Day YouTube channel. And of course, continue asking your questions in the comments in there, as well as interacting with everybody across the social media platform.
So thank you very much for joining us. Have an awesome rest of your day. Okay, just in the demonstration, um, we're gonna show full support of a modern mainframe CICD pipeline.
Uh, we're using IBM, um, an open source based DevOps stack. Uh, we will show how quickly it is to stand up and shut down a popup, uh, virtual mainframe in minutes. Um, we're gonna showcase the fast track and snapshot and reset an instance to, to show you how quickly you can recover and repeat your testing.
And, um, we're also gonna show, um, bit of Ansible and, and that's all about, um, improving automation and empowering the teams with self-service operations. And just quickly, the, the demo application is, is the similar ones we showed last year. Well, same name, NextGen Bank, and that's a web-based ui.
It's using ZOS connect, uh, to the backend, and it's got a mixture of our old friends cold kicks and DB two. Um, just, just so you understand, the, the backend for the next gen bank is running on a popup in dev test. And a real world example that would be, it would be production on a mainframe for.
So you get, you get the idea of what we're trying to show there, so into, uh, the demonstration. And so before we start, first thing thing we need to do is stand up a virtual mainframe environment to use. So we're gonna invoke an instance of the popup mainframe or popup as we call it.
And you can see, um, we are actually standing the exhibition up in the Azure cloud. As I said, we've got the two types of popup, as you saw on both sleeves. Um, one is for the X 86 hardware and the cloud, and the other is runs on Linux one.
And Linux said, uh, for the reasons that we've discussed. So they both provide the same ability to provide a virtual ZOS on demand. And for Azure, it takes around nine minutes to install.
So now we're, we, are I ping logging onto familiar TSO and we're getting into ISPF in a safe, happy space. So, um, now standing up a popup Z edition, um, this is actually a lot easier and quicker to install. Um, apart from us having to sign the license key, we like to protect our ip, but it's literally running a couple of commands.
And then again, um, you can just log straight into TSO, um, and, uh, you see there, and again, exactly the same ISPF. So now, uh, now we've actually stood the environment up. Um, we are gonna, um, show you how we're gonna make a change.
So, uh, you could then install your applications by migrating that data and config. Or if you've already done that and you've in and you put it into Git, then you would just check it out and build it from Git. But here, um, we're showing, um, we're showing our next gen bank system, um, and, and, uh, we've built this, this sample application.
Um, and we're gonna show the trans customer transaction history here on the UI in ascend order on oldest first. So we're gonna show, um, there's a new request in from a user who wants to see that changed around, which means the transaction history needs to be sorted in descending order. But before we make the change, we are gonna show you, um, how we can take, um, a snapshot of the entire Z os environment so we can return to any snapshot with the self-service capability.
And so this means you don't need to worry about potentially breaking the environment, um, to do this. So this is just us literally, um, checkpoint's done it literally, it literally takes a couple of seconds. Can you give to run the checkpoint?
Sorry, you can give the snapshot an arbitrary name. Yes, You can. So I thought I saw that's what's happening up there.
Yeah, yeah. So you can give it a name and then you can, that goes into a database. So you can then choose which one you wanna go back to and just label them in a, in a sensible fashion.
Yeah, Me, I like to label them just a random string of, of time code numbers down the millisecond precision. 'cause that really is useful. Later on, You need to get out more.
Yeah. Can you name it, Steven? It is Next, next time, next demo would work For with a PA anyway.
So here's our zero OS delivery pipeline. Um, indeed, any player pan line pipe pipeline, excuse me, you're planning to adopt will run on a popup mainframe. In our example, we're using a standard IDE to do the development.
And then, um, we're doing a series of build and unit test steps before deploying the code and running system tests. Um, of course there could be other phases in your pipeline. Um, there could be, um, there could be security verification.
But here now we're gonna show the code change, and the first time we do, it's gonna be in VS code. So the developer checks out the code from the GitHub repository, and then they're gonna modify the query to retrieve the rose in descending order, then commits and pushes the code back to the GitHub repository. And then by checking it in the CICD pipeline is automatically triggered by the, by the code checkin.
This pipeline uses GitHub actions, which in this example, builds the code using the I-B-M-D-B-B facility. And then it's conducts, uh, a series of unit tests using the open source tool, cobble check. And you can see the results of the unit tests here, which have all been successful.
And then it's gonna push the compiled binaries into an artifact repository. Artifactory. Um, these binaries are then deployed onto a different ZOS instance using IBM deployment facility wie deploy, where we are gonna run integration tests using the Glasser open source testing framework.
And unfortunately, you can see the glass of test packs have reported an error. Um, and you can see the failure there. And looking in, in our original ui, we can now see that the balances are now blank.
As it turns out, the developer has overlooked some logic, which was there for testing purposes. In situations like these, it's very used to really go back in time to a previous state, and we start from there. So again, we're gonna use a fast track, and very simply, the developer just can run a command, um, to rewind the entire zero OS system.
And we're now back to the previous state, and we can see the transaction history as it originally was in a sending order. Um, so now we want to go and fix the logic error, and this time we're gonna use IDZ to do the, um, development. So they can choose their own development tool, or it could either be an ISPF, if you wanted it to be, and you could trigger the pipeline manually, it doesn't really matter.
Um, so now the code has been fixed correctly, and we're gonna commit the changes back into GitHub, uh, which triggers, uh, the pipeline again, and the pipeline's gonna run again. And this time, uh, magically, uh, and for the developers benefit, they've all, all the steps have passed. And now if we go into our ui, we can see the order of the transaction history has been changed to support the user request, and it's been successfully developed and tested, and the valid data is now in descending order.
So then what would happen, right, because this is still in, so is, is there a way to automate, I don't even, Correct. Yeah, so that pipeline, so that pipeline was just handed in the beginning part of, uh, the developed unit test process. So in a typical DevOps, after that, you could then use exactly the same pipeline, uh, to promote, say, into a system integration test that could be on a physical mainframe using the same exact same pipeline as software using db DB deploy.
So we help organizations do their end to end, uh, route to live DevOps. So you can use this where you're doing, where you're repeating frequently, and you are recompiling and rebinding. It's much better to be doing it on a virtual popup than using, uh, vital, um, you know, missus on the physical mainframe.
That's a really great point. So it's, so you really, if by using this, using this technology only the, the last compile would need to be on a real physical system, because again, that's one of the license stipulations. You, you must, um, only run code that you've compiled on a physical mainframe, not on a popup, but the previous 20 compiles would be on a popup at no cost.
Yeah, because you're getting, in terms of your msu and then Things like user acceptance testing and performance testing presumably goes on the final LPAR as well. Performance testing, correct. Um, would definitely be, because otherwise your hardware emulation, it would perform differently.
Um, so you would be comparing apples and pairs, but you could use popups for doing, say, SQL performance and seeing how queries are running. And you can see it going faster and faster by, by doing it again and again. So there is some performance tuning you can do, but, um, just understanding what performance work that is.
Um, but yeah, we've, uh, you could have, uh, you know, you could, that you could go straight through to live and it could be a final approval before it's promoted live using the same DevOps tool chain. Yeah. So you can, you can do that.
Um, so you, you, you saw how we deployed a mainframe code change using automation, and now we're just gonna show you how you can streamline operations, um, and simplify management using Ansible playbooks. 1 release. And so we've done a lot of work here with popup, uh, to help clients, uh, simplify the management of them.
Um, and you can, you can use an existing Ansible orchestration node, or you could actually run it on the popup if you're completely new to Ansible. So we, we've got the, the node, um, on the popup, and these come with a se popup comes with a series of Ansible playbooks, um, that a ship ship with a popup. And we also make them available in a GitHub repository we give to our clients.
So we're developing all of the time, and they can just take new versions or take new playbooks. Um, so in this one, uh, so, uh, you don't need to have any rack f skills or, um, knowledge to better use this. You could just use a file to put in the username and the playbook would, um, do the rest.
So here we're defining a, a new user, um, a new starter called, uh, Trump D and, uh, they're just logging onto TSO. Um, we've also, same as creating, we can remove users. And this is someone that's decided to, uh, leave us and join someone else.
And we run the similar, um, playbook. Um, Biden Joe is leaving, found pastors new why and Joe ever a running application. So it's, And so there we go.
So just, that was just a very quick example, how we can put, put the, the operations into the hands of developers and that using Ansible playbooks, those can be joined up in other DevOps automation pipelines. So your creation and remove user could be joined up from your ServiceNow and whatever and be through end to end and just to find operations. Um, shutting down popup, um, is, uh, is really straightforward and easy as well.
Um, so it's a bit like, um, wanting to tell your children to switch the lights off when they leave the house. Again, users can shut down, uh, the popup in a very straightforward way. Um, and that is great for, um, not leaving environments idle and, um, just, uh, help meeting your sustainability objectives.
Alright, so just, just to recap, um, what you've seen, uh, I'm gonna return to the pipeline diagram once more. So what you saw is a, is a fairly commonplace and simplified application development process. Um, and this has all been running on the popup mainframe environment.
You can also use the pipelines to install full applications on demand from Git. And we work with our clients to do that, to put their, their application. So if they just need to, um, uh, create an environment on demand, they can pull the application out and maybe the batch also from installing the GI and Artifactory and produce that into an environment.
And you can also use the pipelines, um, to perform DBA kicks and IMS like admin tasks. Um, so whereas before you need to page out to other members of the, of the mainframe team to do specific work, you can have the pipeline do that, um, do that work. So that really empowers the developer community and gives them the freedom to get, get on and deliver.
Um, and this, and within project teams, if you can reduce the project team size down to one or two, that's massive. We're gonna reduce the costs of, uh, development projects. You saw how quickly we installed a popup and how straightforward it's to bring a brand new technology stack, um, up and running and the opportunity to completely modernize the way you work.
Um, and that wouldn't disrupt any other users in the organization using existing dev test LPAs 'cause that that can be a challenge to actually install new software and do new things in a, in a, where resources are really, um, at a premium and you just can't also find resources to install software. Um, we also saw how easy it was to checkpoint and roll back. And this provides a powerful, resilient way to test out changes without the effort of delay of environment setup work.
And we showed you, we, we pretty much showed you app dev reimagine. As with a popup, it's easy to begin your DevOps journey from a standing start 'cause you get all that software in away in the, uh, the immediate install. So I mean, that was from an app dev perspective, but I think popups and we've worked with a number of clients to remove technical debt and either doing code refactoring and batch refactoring, um, because it's very straightforward, um, to just keep on Undertaking tasks and if they're not working and just re rewind that out and start again.
Um, and, and quite often it's very difficult for organizations to decommission old software and con config. But if you know, you need, uh, to get output of 20, uh, 30 results, um, you can keep on taking away until you still get that same, that same result and just reducing down your environment. Another, another key, uh, advantage of pop-up is by using the modern tools and ides you make the mainframe accessible to non-green screen users.
Um, and that's, that's really, that's really helpful because there's so much other knowledge in the enterprise, um, that don't have mainframe skills. They could be understanding test automation and you can use those skills now to by using the the Glasser testing framework and bring that other knowledge into mainframe without actually having to hire mainframe specific test automation experts. So it really, it really opens up, um, the, the mainframe to, to other users within the organization.
And that's gonna further drive down costs if you could use those, uh, those other commodity skills. So there's, there's, there's been significant movement in far as I understand in, uh, among main framers towards DevOps. Mm-hmm.
Longstanding, well, I think it's appropriately methodical and cautious as opposed to what I might call the Silicon Valley approach of let's dive in and find out later if it's problematic. But my point is, um, that that's still within, let's say the mainframe paradigm. This is a breakout from that.
It's a, maybe a safe one, maybe it's not a breakout depending on how you define where the line is. 'cause you're emulating, you're, you're, you, you're, you're, I feel like you're really holding the, the, the frontier tight. That said though, um, aren't you encountering this sort of cultural issue as you, as you address this real problem, which is, you know, that that all sounds, I mean IIII understand that you're allowing non-cloud, you know, on-prem, you know, uh, IFL and, and LinuxONE implementations.
But nonetheless, this is now, like a lot of these examples are really exciting to me. Yeah. 'cause I work a lot in the cloud native and, and you know, DevOps spaces, but I could see it being rather alarming.
Um, and among a lot of your clients, and I'm just asking about the cultural clash And with anything modernization, DevOps, there's always that challenge. So what is great about this is that you can put it in and then one or two people from existing forward thinking application team can go and do something really new and groundbreaking. And then it's all about playing that back to other, other teams, showing them what they can do.
And you know, I think deep down people always wanna work smarter and better. So if they could see making their job easy and taking out a lot of repetition, they will want to do it. But as, but as you say, you know, there's always, we often come across lots of naysayers.
You can't do this and it's hardware emulation, it, it's not the same. Well it looks and feels exactly the same. You're running the same code base, go and show some progress.
And once you've shown it and played it back, everyone wants it. And so teams are bending over each other backwards to get hold of it. 'cause their jobs become, you know, there's so much, a lot of mundane mundanity about running bits of scripts and tests and all these sorts of things.
If that can all be done by the technology, you can do deliver so much more change. So I think it is, so, you know, you do, it does have to be sponsored. It does, it does have to, anything with DevOps has to be sponsored from the top.
So funding does have to be available. That's what I was, and it does need to be change managed. It needs to be change managed.
Like anything that doesn't go away. But I think if you can show real tangible results, um, and then that's, that's the breakthrough when other technical people go, whoa, I want some of that. And then you're there.
It's, it's, I'm with you on most of that. It's that, yeah, it's, it's passing over that threshold. 'cause I, I, I can see you pitching to management dev, uh, app managers and so forth, and they're just eating it up and then there's that part of the process that is not necessarily visible to you, but they're going back to the team and they're saying, I, here's something.
And then what I call the gum snappers, which are the, which are these technical folks are sitting there just going, oh, well yeah, but here's the five things that I need to do every single day that obviously this is not gonna be able to do as you're gonna do poorly. Like the, the naysayers that you don't necessarily get direct access to if you are, if it is being like change management and if it's being pushed through organizationally, then I hear you that you're starting to show examples and these gum snappers, compatriots are sitting there doing, look at all these things I'm doing and there's jealousy and there's, there's that, there's that acceleration. But I, I feel this, I sense this potential resistance in your initial pitch, in your initial value.
I think that can be helped by having younger members of the team that have always worked in this way. So introducing these more distributed type skills into the mainframe younger, you know, sorry, uh, Gary in their twenties, you're talking that As a feature pick stuff Up, which now very Quickly to all this innovation and stuff Yeah. The gum snappers, that's like, that's, that is a problem.
That's not a feature that's a problem. That to some, to some, to some of, um, older members. It could be.
But as we all know in the mainframe world, um, there is addressing that skill shortage. Shortage is imperative. And yeah.
You know, I think, um, You think if you'd, if you'd launched this product five years ago that had been that problem, if I've been coming to share for years, you, you see this environment, the age profile. Oh yeah. I dunno what the demographic data is.
Share have probably got it. But the demographics of this environment are changing. And I think what the more experienced professionals, let's call them that are, are seeing, and we've talked, I've talked about it in a couple of sessions so far this week, they're having to be less resistive to change.
Yes. Because the demographics, you know, whereas it was 10 old guys who could all just gang together and not do anything, can be very resistant to changes a block. Now there's probably seven of them that, but the three that have been cycled in over the last five years, they're younger and they're looking over their screen going, oh, what are they doing?
That's cool. And they're getting dragged along. So I think that demographic's changing.
But, but I think that there's, there's two points to come back to, to your question. There'll be different teams. So you get to the, the development team, they'll be all over this.
The managers will be all over this. The systems programmers will be all over this going, this is great. We don't have to do this anymore.
They can look after themselves. The security folks are gonna have kittens. 'cause they see, they see in their mind their mainframe data going off the platform.
Mm-hmm. Keeping it on the IFL. That's a, that's a big positive win.
Big game changing. Okay. But Sunday I sat in an IBM closed door session and they're talking about simplification.
How do we make this platform easier to manage? And you got these, all these old trust guys going, no, no, no, we are not doing this. I was sat at the back of the room and I just wanted to stand up and say, it is not for you.
You've just got to help make it simpler so the folks coming in behind you can do it. This is not for the old trusty folks. Yeah.
This is for the next wave of mainframe. As a mainframe of developers. And this will make a huge difference.
And it's so funny you said that, mark. I was thinking exactly the same thing. I was thinking the great thing about if they were to use a popup, then it doesn't matter if they, they stuff up IDMS or do something horrible because just rewind it back out.
It doesn't matter. So fortune really follows the brave with this technology. And you don't, and there's no, there's, you know, you sort of remove the risk.
Self-sufficient. And that's the thing that's, they don't have to go and ask. Yeah.
Steven, who's the head of mainframe? Can I have an lpar? They don't have to go to Jeff.
Who's the data storage. Right. Can you restore all those databases for me?
Think press button, Don. This is the conversations we had with VMware 25 years ago when it first came out. The exact same conversations of, you know, you can train people to do open systems, you can do all of these things and, and, and stop having to run inlines on a symmetrics.
You know, so this was, this was the same absolute problem we had with mainframes, but it went away because there was so much value to being able to virtualize this and being able to, to, to make a difference in the organization. It Must been too slow for too long because it cannot, it's not allowed to move fast and break things because it's too important. Import.
Yeah. Well now we can, but this, you break it as much as you like. 'cause you can just restore afterwards.
This this allows 'em to just break it. I mean, we, we've got youngsters in the business and we say we give them their own little l pass, but we back them up ourselves. We haven't got all this technology, but we say to them, yeah, if you break it, you fix it.
And by the way, if you want to restore it, that's how you restore it. Yeah. You've just made it really easy for them.
'cause I mean, I know this is a DevOps play, but for me, this is a great systems program, a training tool and technique, techie playground for it. You, you also have the other end. You, you talk about the old crusties and, and what happens?
You, because I'm assuming you can back this up on a daily base, do a backup on a daily basis, a snapshot on a daily basis if you wanted To. Well, you can, you can, yeah. You can stock it up in multiple Ways.
Yes. What happens if, uh, if all of a sudden the main database is gone? Cattywampus, you could bring that back from there.
Maybe even a ransomware attack comes in. Like all of a sudden you're bringing that back, using that snapshot, and you're back up and running within, uh, half, one, fifth at a time. Then if you had to deal with The ransomware.
Mm-hmm. That is a future use case I've been thinking about on how you can, um, where you can, um, uh, you can back up, flash back up all of the, all of the volumes and then you can create copies onto pop-up from the flash and use that to, to restore. And particularly for production fix.
'cause you can keep on replaying scenarios that way. So I've been thinking about that. Um, anyway, let me, let me wrap up.
Um, we focused on the technical tasks in this, um, with the demo. Um, and, uh, but we can see the potential benefits of using this. And we've proven with clients that there's been a 400% improvement in time to market using this technology by doing this early testing.
Um, and, uh, it's great for CIOs, um, sustain sustainability initiatives. We shut down these environments and one of our clients on, uh, running the environments in Azure just by having them down two hours, hours a day, save the license bill as well. So it has a sustainability and a cost saving if you're running in Azure.
But again, switching off, switching these environments off anywhere is pretty new concept for mainframe. Um, so, uh, yeah, we truly believe that pop-up mainframe revolutionized mainframe delivery by providing teams with a immediately available fully functioning mainframe environment. Um, and just reproducing more of them.
And to meet your use cases becomes really straightforward. And as I said, I think it's a, with what we've done with Fast Track is, uh, definitely a game changer for environmental environment management and environmental management as well with through sustainability. But thank you very much.
Hey, everyone, is AI safety an oxymoron? You're watching Textron Gang. All right.
Moving on A block in three, two. Hi everyone. Happy Tuesday.
Wow. I hope your week got off to a great start yesterday. We are, of course, back at it now as we get into the meat of the week.
And it promises to be another interesting week with lots of news and the tech world and, and the greater world around it that affects the tech world. Or maybe it's the tech world that affects the greater world around it. Either way, we've got some good stuff to talk about and some great people to talk about it with.
Let me introduce you to our gang for this fine Tuesday morning. First of all, joining us, uh, JP Morgenthal, jp uh, relatively new gang member, Chaya au Chaya, welcome. Hi.
And of course, two old Reliables, Steven Foskett and Mitch Ashley. Hey, gentlemen, how are ya? And Lee, not, Not so happy being called Old Man.
Well, who's old and who's reliable? Was he taught? Was that too different or were we both what?
Or I'm not sure what you meant there. We'll, we'll discuss it off camera. Here we go.
Everybody's a comedian on it. Tuesday. Keep your Day.
Um, So, so guys, let, let's jump right into it 'cause we've got some meaty stuff to talk about today. I wanted to first, uh, talk about AI safety, which is what it kind of teased out in the beginning. You know, we've come a long way from the, the letter signed by the hundred people that we should stop all AI activity until we figure out how to make it safe, including some of the people who are pouring money into it and going after it.
But, you know, AI safety still is a thing. There's a, uh, another pass out coming outta California legislature, um, talking, you know, some of the providers are talking about putting guardrails in how well they'll work. I don't know, but Chaya, why don't you kick us off on this.
What, what are we dealing with? Sure. So first of all, the bill is a step in the right direction.
We do need cartwheels around it, so it's definitely much needed. But if we go into the detail side of it, it's like essentially saying that the companies who have a valuation less than 500 million or 50 million has to regulate themselves and expose themselves in terms of what is their source of information. And they call it as a frontier model or frontend model.
So that is something needs to be explored on. Uh, it's, it, it's looking like, like we are trying, so the bigger players are trying to control the smaller players. That's what I can think about it.
And it requires more due diligence when the policies goes in life. Um, when I say I like the step, I'm also concerned with, it shouldn't slow down the pace at which AI is developing, right? So when there's so much of guardrails comes in place, it slows down the momentum of it.
And we are in a changing era. So that's something we have to be careful about. Agreed.
Yeah, I, I would agree with Chaya there that, um, this, uh, some of the unintended consequences of these bills can be, as she said, um, having the larger players cement their lead and locking out smaller players. Uh, that certainly is something to be concerned about, for example, with the anthropic financial settlement, uh, that we talked about last week on, on the gang, as well as, uh, you know, bills like this one at, at the same time, of course, there's a huge political dimension here where you've got, uh, essentially two Democratic, uh, presidential hopefuls, uh, or at least political hopefuls, uh, going head to head over this, where one is trying to prove his, uh, progressive, uh, bonafide days by saying, you know, I, we need AI safety. And the other is trying to, uh, basically, uh, prove himself to the Silicon Valley establishment and say, wait, wait, wait, maybe we don't.
And I think that unfortunately, the, the world we live in, it, it often is more about politics than about, uh, the intended consequences of actions like this one. Yeah, considering I don't, so many, so much of the donor money is coming, of course, from the, the same companies. There, there is a comparison between the last time, last year when they took a shot at this.
This has got some of the teeth removed in it. You don't have to have a governor that you can shut it off automatically. You just have to disclose whether you have one.
Um, and there are less strict reporting requirements. There's still some of the same safety requirements. So it's, it's a little bit lessened, not quite as sharp teeth, and we'll see if that's more palpable to Newman.
I, I, I view this equivalent to the SEC, right? Where, you know, there was an option either you police yourself or we will institute, uh, it will codify the policing actions out of the government. I don't think politics is the right place to attempt to police, uh, emerging technology.
Um, but what they're saying is they're not seeing the industry police itself enough, which indicates that maybe what we need is a third option here. We need an organization that is supported by these, by the, the big tech companies that they're willing to delegate and, and submit to, uh, in order that, that's equivalent to the SCC that's going to, uh, ensure the openness, uh, and the, and the, and the safety of what these companies produce. Uh, and I haven't seen that emerge, and I'm surprised that that hasn't been an option put forth and accepted it.
It's something they could drive very quickly. If you could get, you know, Microsoft meta, Google Anthropic, uh, open AI to, you know, accept and adopt an a, a particular organization, um, to act in this role for them. Well, I, I've got some views on this, not surprisingly.
First of all, everything's political, right? You're not the amount of money at stake here, right? Let's be real clear, the amount of money at stake here is, is literally the pot of gold at the end of the rainbow, right?
And so with that amount of money, there's gonna be a lot of, a lot of players, right? Political, nonpolitical, corporate, individual, what have you, uh, social justice warriors and everything else. So to to, you know, it's naive to think that we could somehow keep politics out of this.
We're not. Um, what's interesting is, as in so many other things around technology, policing, environment, environment policing, et cetera, we lack the will it seems, or the consensus on a federal level to get something done for the us right? The eu, they passed something almost a year ago, right?
It was when they started their AI safety bill. Um, so in the absence of a national political will, certain states take the initiative and take the lead. California has been a state that's been doing that for years.
California privacy laws, the California laws on, on fossil fuels and car, uh, mileage and so forth. You know, they, so California has a history of, of being out frontier, right? They, they have the will to do it.
What we don't often see is, is I think as Stephen pointed out, the two facts, and California, for all intents and vers is kind of a one state, state, a one party state, right? But you have two powerful players there. And, and, and it's playing out.
It plays out on the background though, of the tech bros, right? And, and what do they want to do? And of course, they probably don't want formal government regulation, they prefer self-regulation, but they can't even get their act together to do that, right?
They're all busy suing each other and everything else. So don't look to them. Now, income's the white knight here.
If there is such a thing, and it's AWS they're saying, hold on, hold on. We could put some guardrails in here and, and make it safe for everyone. I don't know.
Is that, is that putting the fox in charge of the hen house? Maybe E everybody has guardrails though. I mean, they all have guardrails.
The the question is a do they really, or do they just say they do? No, they, there are guardrails. I mean, there, the, the challenge, and this is why I think a third party organization is required, that it's, you know, how, like anything else in software engineering, you have to test it, and you have to be willing to break your own code, so to speak.
Um, biggest problem in software engineering is QA and, and unit test engineers at unit test don't know how to ba break their own code or aren't willing to break their own code. So no, no, But, but jp, when you put out bad code and your app is bad, there are consequences, right? You're, no one wants to use your app.
You've got, you get sued for security problems, et cetera, et cetera. Who, where is the teeth of a th how is a third party gonna enforce AI safety? What it would, how do they enforce that?
Again, it would have, yeah, so it's what I said earlier, right? They have to be the SEC of this industry. They have to be accepted and contracted that Those, so, but let's, the SEC is a quasi-governmental Yes.
It's chartered agency. And that's What's you, the federal government isn't chartering an AI commission. I don't see it happening under this administration, that's for sure.
Yeah, it's required, but yeah. To Steven's point, not happening. Well, yeah, just like it should happen doesn't mean that it will happen.
If you look at what Amazon announced with bedrock guardrails, those, that's at a much, much finer grain grainer of, of guardrail. It's things like, uh, the example they gave in their block blog was, here's the document policy document that you use to say whether someone can get a mortgage loan or not, right? That, that's, so it's like no knowns of, of safety, if you will.
This is really policy enforcement guardrails more than safety, safety guardrails for you to create something in bedrock using that facility. I'm guessing that's probably not a comprehensive enough abil capability, or you'd have to cover so much, so many areas. It's really the model creators that have to put in the, the guardrails into the safety, into the model, as opposed to every third party they can check it, but making it safe, that's a tough, tough nut to Crack.
Well, oh, Mitch, you raised a great point. And actually, this is a question I had in my head before we even started this segment. Let's define safety here, right?
To me, I think with regard to this technology, the most important safety, uh, mechanism I want checked here is can the LLM be used to hack? Can it be used for cyber crime? Can it be used for nefarious purposes?
And I, I think that is one important thing, but I think, believe it or not, jp, there are more important things. We discussed it on a show last week about the mother who wrote the essay in the Times about their daughter who killed herself, SU su committed suicide. And, and I, you know, I put that, I wrote an article on that with Bill Brenner, a good friend of mine who's big in, uh, mental health and tech.
And we got a tremendous, you know, response from the community. This evidently happens a lot, and there's a lot of lawsuits pending right now, because people are starting to rely on AI for therapy companionship, right? You know, this is on a personal level, we're talking, I'm not just talking hacking, I'm talking life and death.
Yeah. But isn't that just gonna be re resolved by a disclaimer that pops up on the, on the chat, on the gp, on the chat interface? That's is, hey, anything, anything you learn here is just the purpose of the entertainment, blah, blah, blah, blah, blah, you know?
And that, that's it. Now I'm Moved on. I, I, I, no, because they're actually creating AI therapists and AI companions, and, you know, and, and, but you bring up an excellent point, jp, I, you know, looking at it from a legal angle, right?
There's two ways that we get kind of clarity on, on, on the legalese here. One is by statute, you know, by regulation, by, by some sort of governmental action that clearly defines what the liability is and what the penalties are, right? What's allowed, what's not allowed?
And, and what, what are the repercussions In the absence of that, we fall back, or at least here in the US except for Louisiana, we fall back to common law. And it's, it's basically tort law, right? With, uh, uh, you know, reasonable mis test.
So is it reasonable, jp, if I clicked on the click that, you know, that stupid thing that we clicked on every site, letting us know that cookies are involved and they have their own policy without reading it. And then, you know, some AI therapist tells my kid it's okay to off yourself or whatever. Yeah.
Is, is that enough to, is that reasonable? Well, also, I think it's important to recognize that a lot of these guardrails are themselves AI models. Yeah.
It's turtles all the way down. And so if you have an ai, like I, I applaud Amazon's bedrock guardrails on a, on a technical level, because essentially you can say, look, if it gives me some information, verify that information, you know, if it gives me a fact, verify that fact, I like that idea. The problem is then we need a guardrail for the guardrails, and then we need a guardrail for the guardrail guardrail so that we can make sure that, you know, 'cause that that one's not hallucinating in the next one.
But I actually want to, you know, kind of circle back this whole conversation to Chaya's first point, which is, does this lock out innovation, whether it's guardrails or an SEC for AI, or, or whatever it is, i, is that going to make sure that no company can compete with the magnificent six who have built large language models, Right? So what I can add to that is if you say, why do we even need guard rails? We need guard rails because as users, I want to know the information that the model is giving.
What is the source of it? And is that source legit? Is that source valid enough to certify that here is information before AI error?
You can go to the a website and see where you are reading from, and you know, if it's Wikipedia, is it something else? Now, we don't know. So we definitely need guardrails.
And here Bedrock is saying that there is an agent world where you can automate lot of things, but there are knowledge bases and policy documents, which we need to have a manual interaction to set up those rules. And that rule, that is where the critical piece comes in, that companies are allowed, the users are allowed to say, here is what the source of information that I can trust on. Here is what my model is going to read on, and here is the information.
But like Stefan said, that we need to make sure this shouldn't slow down the pace of development, because again, we are adding a human angle here. You know, I think e essentially, aren't we making a decision? Are we going to, basically, to your point, Alan, about tort lies.
This is gonna be solved in the courts. And, and all the model makers will put every, you know, liability disclaimer that they will into their policies, of course, if possible. And when harm happens, it gets resolved in the court.
Or there's some things, so potentially egregious with ai, which I think some of us think that's true, like gaining power, physical safety, things like that, um, that might benefit from some either oversight, maybe regulation. So I think you start with oversight, like what are the kind of things that are happening? Or does it warrant that we need some regulation?
Maybe it's a light touch, maybe it's a little heavier hand. But if you put a big heavy hand regulation out there from the beginning, that's potentially going to, uh, you know, impact the innovation and the speed of the market. I, I, I agree with you, Mitch.
I, I think in the absence of regulation, in the absence of industry, uh, oversight, you know, taking care of their own, so to speak, in the absence of all of that, the court fills the vacuum plain and simple. And, um, that's, that's just the way of it. It's not an AI specific thing.
I think that's kinda how our society functions, right? The absence of everything else, the court becomes the arbiter of, of reasonable, of allowed or not allowed. Um, it'll be interesting.
And, and, and of course this does, as Steven pointed out in the beginning, I want to come back to that. This plays plays off against the backdrop of people jockeying for the next presidential election. And, you know, depending who wins and what policies are jp, we may very well have an A-I-S-E-C, right?
We could hope. But, um, it remains to be seen. It remains to be seen.
Let's take a break. We're gonna come back and talk a little bit about AI infrastructure. And Steven recently had AI Infrastructure Field Day.
We'll get a report on that and some more of what's going on around super intelligence. You're watching techron Bank, Discover Techron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide.
Our secret impactful content that sparks awareness, engagement, and top quality leads with us. You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients.
Let's revolutionize your tech journey. Contact us today and tell your story to the world in the most powerful way with Textron Group. Welcome back to Textron Gang.
Uh, I'm Steven FoST and I run the Tech Field Day business unit, uh, sort of sister company for Techstrong. Uh, you, if you were watching last week on Techstrong tv, and really, if you weren't, why weren't you? Uh, you might have caught some of the presentations from our AI infrastructure Field Day event that was live streamed here.
Um, I, I wanted to bring some of the takeaways from that event to the, the gang this morning. Now, first off, I, I should point out, um, you know, we had, uh, six companies present, uh, Broadcom Hammer Space, refe, Mirantis, Satter, and HPE. Now, I don't want to necessarily focus on those companies specifically.
What I'd love to do is try to pull together some of the threads from the conversations that we saw last week. So let me put a couple of things to the panel here. So, three things first, um, one of the unifying messages throughout those presentations was the difficulty of moving generative AI applications from experiments into production, and specifically how to physically infrastructurally, you know, nuts and bolts, make these things run in a way that enterprises want to be able to make these things run.
This is especially critical because all enterprises are investing in AI and trying to figure out how AI transforms their industry, and yet we don't really have a consensus on what that infrastructure is going to look like. And that leads us to the second point, which is build versus buy. Do you have the resources?
Do you have the time? Do you have the interest in building your own AI infrastructure? Or does it make more sense to just use a service to run it in the cloud or to find some sort of SaaS that can run it for you?
Uh, and, and also, what are the implications of doing that? If you do decide to run it as a service, uh, does that sacrifice some of your ability to control access to your data and so on. Which leads us to the third point, data management.
Now, we all know that it's garbage in, garbage out when it comes to AI models. And, uh, this is especially true when you're looking at smaller AI models, because most enterprises aren't going to build their own chatbot. Instead, they're going to leverage a foundational model with their own data and sort of a rag situation, or they're going to build a special model.
I actually wrote about that on LinkedIn last week after talking to another company, uh, called Articulate, um, which hopefully we'll see at the next field day. Uh, and if they build a specialized model that makes the data even more important, because that is going to be a very limited data set for, for a model. So lemme throw this out to the panel here.
Um, uh, jp uh, you know, you're somebody who I very much respect on this AI topic. What do you think about the challenge of enterprises trying to put generative AI models into production? I I think it's a spectrum.
I actually have written about this too. Uh, it's, uh, probably, I think it's a LinkedIn post I have out there, right? I, I think it's a spectrum.
I think there, what I, the way I like to think about it is that you, your organization and, and businesses are gonna learn this very soon. Your organization is so unique in certain areas that to get to the quality outcome you want from a model you are going to have to use, you train it on your data, right? It, it's not, I mean, while there is some amount of training you could do on the larger ones, your data's still getting lost in the corpus.
That is the universe of data that is, you know, used by those models. So if you have stuff that is very specific to your domain, then it makes sense that you would want to build and, and host that model for yourself. You can host it in something like Azure, uh, or AWS, right?
In a, in a safe, private, you know, compartmentalized way. Um, so you don't have to go out and get the infrastructure to necessarily build that out per se. Uh, you know, obviously for some organizations operating at the edge is important.
Getting small models operating at the edge is an architecture. It's required in certain manufacturing and other areas where they're starting to introduce ai. But let's just for now say that you go to the, um, that the cloud is suitable.
You, you, so your domain specific model, but then there makes, uh, there's a point at which you want to add in the universe of data, right? And that's where it's almost, it's almost analogous to being able to burst out, like we've always talked about in cloud computing. I have my local resources and you know, VMware, and then I want to be able to burst out when I need it to the cloud resources, right?
And it's similar kind of architecture. I have my domain specific stuff local to my business, and then when I need the corpus, uh, that is the world. Like, okay, but why is this pattern happening?
Well, it could be geo, uh, you know, socioeconomic, it could be something in the news that happened. I don't have that data in my model. I need to go to the larger corpus to go get it right.
And that to me is what I see as a complete intelligence model that needs to be understood and built by companies. You know, jp, I think that's both you and, and Steve are direction and correct. Uh, my sense is that for most organizations, building models is at least, uh, LLMs is, uh, you know, out of their reach, right?
The cost and the effort and the skills to do that. Probably the next step down or step to that is, of course, we all are familiar with the rag, and that is a way to provide information to the model that it, it you ingest into the model and to have it analyzed. I think we've entered a new era where MCP servers are the new rag, because I mean, you can, anybody can create an MMCP server.
Matter of fact, there are online services that will built on for you. And that's a way, if you start to put in filtering and sort of guard rail rails or logic of how to use that MMCP servers to your information, your data, et cetera, so you can curate what it has access to, it really gives you the access to anything. Now, you don't have to move data into some rag location, and you can maybe use a combination of both to get access to your data and then use the general reasoning or processing capabilities of the model.
The thing that I wanna add on the infrastructure side is there are a shift in the technical skillset that is needed to maintain this infrastructure, right? The typical skillset of a DevOps and SRE team, which been managing the infrastructure versus managing the AI infrastructure needs some additional skillset, which gives us people an opportunity in terms of directions of career opportunities to explore, right? There are a lot of, um, thought around the industry that AI is going to take away job, but here, there is this direction where every company needs their own infrastructure or maybe some sort of, if they go to a cloud provider.
So this gives them an opportunity to see if new skills can be leveraged to maintain this, um, infrastructure. There are two aspects of this. One is where, um, the model is getting learned, and the other aspect is where the user experience of it, how slow or how fast your internal tools work versus the outside world enterprise level solutions, right?
So that is something I wanted to add on, because the thing is, um, we built services on CPS and rags, but this field has been changing. Now I just read this, something came out as fast MCP last week. So we really need to make sure the skillset that we are hiring is up, up to the mark in terms of the things needed to manage this infrastructure.
So, so I have two points. One is you chaa around, uh, skills management. I, I, I, I think you're onto something really interesting there, uh, because I think that's part of, uh, the cost differential be in, in using these resources and getting these resources as in an outsource model like the cloud, right?
It's, uh, if you were a compare, uh, general virtual machine that you might take from Amazon, um, a against what it costs for the same amount of time for a GPU based machine, it's significantly higher on the GPU machine. And I think part of that is both the hardware is expensive to, to maintain, and that there is additional skills and labor that are required in order to build and maintain and operate that cloud. Now, Mitch, as to your MCP point, I, I, I, I don't necessarily agree MCP is your data.
Think of it as just a, a, a way to tap into other data sources, but that data just gets pulled into the context window. And what I've learned working with these things is that, um, you know, right now there is a, a huge problem with context windows as they get larger. I have found that stuff later in the window is obviously, uh, paid heavier attention to than stuff earlier in the context window.
So pulling in additional data doesn't necessarily get you to, um, where you want, if you were to have, if you have a domain specific requirement, um, a a better solution would be take an existing small model and then, you know, and then retrain that using, you know, uh, techniques like Laura, uh, which allow you to change the weightings. It's not as expensive as building your own LLM, you're basically just ta, you know, affecting the weights of an existing model, much more effective, much equally effective, and much less cost, uh, to, to be able to, to do that. But then you, that LLM is specific, or we call them sometimes s SLMs, small language models are very specific to your task and your domain, whereas I, I, again, MCP is gonna allow you to reach out to a world of data, but a, you have to know what that data is, and you have to know how it it fits into you.
You're basically providing it as a tool, and you're saying, and, and the LLM might use the right tool, it might not use the right tool. Sometimes you can force it to use your tool by saying, use this tool to do this. But then you are basically just, I mean, all it's doing is an a, a, a natural language app program that you're writing, right?
It's just basically, uh, use this integration component to go get me data and then do something with the data and, you know, and then, and you end up with the same result as if you had put that data in a CSV and uploaded it or attached it to your message. So I think, I think the viewpoint I'm trying to express JP is, is it's a matter of degrees, right? Maybe the largest organizations could, could, you know, modify the weights and have the sophistication enough to know that what they're doing and changing the model in that way more or less go through the much more expensive process.
What I, what I'm saying is I think the market is going to innovate and create ways for us to not have to train models specifically on our data. So, for example, um, I mentioned MCP, it isn't, isn't just giving a model access to, uh, services that are tools that are available through an MCP server. It can be a, it can be a specific agent that's built, that's trained that is, uh, directed on a specific kind of task and how to use the data that's coming from an MCP server versus a general model.
I, that's one of the resources or tools I can decide to use. And whatever's in that, in, I can do whatever I want with it. Mm-hmm.
So I think there's ways to direct how those resources are used, whether it's MTP or through a RAG or some other option. I think we'll see more innovation in this space. So maybe there's a, an advance CCP server that's got more, uh, direction and guidance to it of, of how you, and the ways that you want that information, uh, to be used, right?
And or some other way like that. Right? And just to add to that, your point j jp, when you said that GPU versus your own machine can have performance issues, I do want to add with the SLM, the small models you can even develop on your own machine, even to get started for A POC with the tools like MCP.
So there is a fast pace coming in in terms of, do I really want this? You don't need to first buy expensive GPUs, then experiment around the infrastructure, then build your servers. It's, it's can go in the other direction as well, whether you first figure out, this is what we want to build as an organization, these are the tools, MCP versus RAG versus any foundational model.
Let's see if this is what we wanted. And then go and evaluate the cloud providers where you want to get a GPU based infrastructure. You know, listen, listening to the three of you talk, I, I have one thought, what an opportunity, what an, what an opportunity to go, this is what people want, but they're not gonna be able to do the full Monty.
Let's figure out something that gets them that easier, cheaper, and I'll go start a company around it. And isn't that what makes tech go round and round? You got it.
Absolutely. And that's, It's plenty of opportunity, Steven, That that's the most interesting part of this, is that, you know, whether it's a conventional infrastructure company like HPE or a more DevOps focused company like Mortis or a new startup like Ray Fay, um, they're all trying to figure that out. And I love to see that kind of innovation coming from these companies.
And, you know, that's the excitement of this space. So, um, as we wrap up here, I'll just point out that we are doing another, uh, AI Field Day event. Uh, we'll actually be back, um, with our full on AI field day in, um, October, the end of October, the 29th and 30th.
So, uh, keep an eye on this space. Uh, obviously we'll be talking about it here on Techron Gang, but we'll also be live streaming more, uh, tech Field Day focused on AI in the, uh, next month. So thanks, uh, thanks so much, uh, uh, y'all for this, uh, really interesting conversation.
Absolutely. All right, with that, let's take a break and we'll come back and talk about, we're going to get local, local, and, you know, all politics is local, right in Steven's backyard, or maybe not in my in Steven's backyard. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com, home of security bloggers network.
So the Columbus NIMBYs are pushing back about data centers near them, what, why, you know, they could bring jobs. Maybe it glows at night with the gigawatts of energy that these, uh, centers used, perhaps. But what else?
Steven, you know, because we're talking about Columbus, you are our resident, what's the word? Ohioan? Ohioan.
Ohioan, yeah, sure. Okay. You are our resident Ohioan.
Why, why, what's the matter with the good people of Columbus? They've had data centers there forever. Yeah.
And they got a lot more now. Um, yeah, so first, just a little geography lesson. So, uh, Jerome Township is the one that has voted on this, uh, that is, uh, right, uh, basically it's the township outside of a town called Dublin, Ohio, which is one of the richest and most, uh, prosperous suburbs of Columbus, the capital.
And so it is really no surprise that this is where the nimbyism would start. Um, but I, I don't really blame them. I don't, I, you know, NIMBY always sounds so negative.
Uh, the truth is, they're building data centers like crazy in Ohio, um, in, uh, around Columbus especially. There's, uh, you know, the intel fab that we've talked about a lot to the east, but then there's also, uh, just a whole belt of data centers, especially north of town, which is where this is. And those data centers are really causing some havoc.
Now, we talked last week about the fact that it's driving up energy prices, not because it is, uh, necessarily outstripping the ability of utilities to provide energy on a regular basis, but because of the extremes, essentially, they, that last watt, when it's, uh, extremely hot or extremely cold, the data centers, uh, are bidding up the cost of that tremendously, which raises everybody's utility bills. Uh, Ohio is a, is a state that has a lot of, uh, a lot of water and a lot of land, and a lot of people, and a lot of electricity. But, uh, all those things are being tapped out by these data centers.
And the, uh, the voters are reasonably starting to say, wait a second. Um, is this really gonna bring the economic benefits? Because again, these are data centers that are often subsidized in the form of, uh, tax reductions, uh, subsidized in terms of allowing companies to come in here with, uh, lesser regulations and, and in hopes that somehow they will contribute to the local economy.
But people are starting to realize that in many cases, there just aren't that many jobs in these data centers. Um, at least not that many, uh, you know, good jobs that are gonna be taken by locals. So the question is, uh, why are we building all these things, especially in, uh, leafy suburbs, uh, outside of town?
So, uh, you know, this is not just an Ohio problem. I think this is coming everywhere. It is.
We we're seeing this across the nation for the most part. I haven't heard a lot of pushback in West Texas yet, but, um, it's, you know why? I mean, why you, one is, Stephen, you're right.
The, the economic benefits, maybe you're not, or they, that we were sold, right? There's not a lot of jobs being created. These, these data centers are largely on autopilot, and they can be managed remotely.
The jobs don't even have to be local. Secondly, it, it, it puts a tremendous burden on our energy infrastructure, our water cooling in, they don't really use water as much, but our cooling infrastructures and, you know, just all of our infrastructure, um, that, you know, depending, again, you know, I don't wanna get into a red state, blue state thing, but, but depending on your political persuasion means drill more, import more shale oil, or heaven forbid, use more solar and wind power, or, you know, renewable sources. And, and this is, you know, this is, uh, state by state, county by county, we're gonna need to make decisions there, you know, and, and, and it thrusts the utilities into it too, right?
The electric utilities become key players here. Because if I'm selling you all of my bandwidth, in essence to run your data center, do I have enough to keep people's houses lit up? And that, that's, that's when stuff gets real, right?
If you're telling me I gotta do a brownout, because that data center down there is sucking up all my power consumption, well, I could tell you where I want that data center. Yeah. Well, I, I should point out too, that Ohio's, uh, electrical utility is notoriously corrupt.
Uh, if you wanna look up first energy, you'll see some h hilariously brazen bribery schemes and attempts to influence elections and things like that. Uh, they're the ones providing the energy. What could go wrong?
What could go wrong, You know? And I think what I want to add here is, think about it, data centers is the source for startups around the ecosystem to be built. There is a reason why there are startups in places like Bay Area or in Seattle, because the accessibility to the data centers and the performance that they get relatively better.
So, uh, this, this location such as Ohio gives the opportunity to build that ecosystem. And also, it may not require a large number of technically scaled workers. It still needs specialized knowledge visit.
So the tech knowledge get diversified across the country to manage the infrastructure. It gives essential point for the startup because it's harder to build companies around in states like California or others, which are expensive in terms of taxes, in terms of other compensation or the minimum wages companies has to do, versus states like Ohio. And others would give that benefit in terms of performance on the technical side, and also the, uh, the technical resources they would need.
Uh, Ohio has, uh, couple of number of good companies. You say GM is there, aviation is there. So there is a good amount of technical talent which hasn't explored themself around those basic companies.
Yeah, this is probably a very naive statement, so I'll admit that upfront. But it seems like some good zoning laws might help with this, right? If you're building your data center next to my neighborhood, that's, that's a problem.
If you're building it in the, in, in the industrial area, you've created an industrial strip wherever, where you have the target distribution center in the Costco, whatever, and the, you know, Amazon Center, et cetera, and you're putting data centers in those areas, then I think's gonna be more acceptable to people. Now, you may have that flexibility either 'cause of cost or availability of land, et cetera, but maybe that's not the right place to build anyway. Is this in sensible zoning gonna help with this?
Well, the problem is that our zoning rules are all local. Uh, in the United States, there is no such thing as even statewide zoning, uh, let, let alone national. Uh, and so that leads us to some really strange situations.
For example, Houston, where I used to live famously has no zoning. So you can build anything anywhere. Um, places like Dublin, Ohio have incredibly strict zoning.
Well, the little town that I live in, you know, regulates what color you can paint your house, let alone where you could put a data center that's Boulder, Colorado. Yeah, we have one of those too. So yeah, it really matters, um, on a lo on a locality by locality basis.
And I honestly, I feel like this is one of those things where, you know, America, America is famous for, um, devolving decisions to local authorities. And that seems to be one of the things that the, uh, uh, the Republican party has long espoused as well, that all decisions should be local. The problem is there's an awful lot of localities, and all you have to do is find the one that's gonna allow it in order to, uh, really kind of change the whole map.
Well, not only that, you know, you can go local, local, local as, as we, we are doing in this country, and then you wind up with this patchwork of inconsistency. Mm-hmm. Right?
And it's also, I will point out getting back to First Energy, very easy and cheap to bribe local government officials. Um, yes, they were convicted of that. We'll leave it at that guys.
We are right on the, uh, mark here to wrap up today. This is a great discussion. My, my purpose, I'm gonna end it with this.
My personal opinion is progress. No man can stop progress and no local township can either. Data centers will be built where they make sense, I guess.
But, um, Steven, Mitch, JP Chaya, thank you so much for joining today. Thank you for watching. As Steven mentioned that, uh, tech Field Day, ai, tech Field Day, it is available on the, uh, tech Field Day YouTube site.
It's available on Tech Trunk tv, as well as the tech strong TV OTT channel. So you can get it on Apple, Amazon, Roku, uh, iOS or, or Google. So check it out there.
As usual, we have a full text from TV lineup immediately following today's show, so stay tuned for that. We'll be back tomorrow with more great talk and more great gang members. Until then, this is Alan Hummel, we're out.
Hey everyone, it's Alan Shival and we're back here on Tech Drunk TV in beautiful Napa Valley at the Jfr Swamp Up event, continuing our Day two coverage. There's a little bit of a break going on, you can't see, but out there people are eating ice cream and peanuts and potato chips. It's a little mid-afternoon break, but we're still here 'cause we've got a lot more to bring you.
Let me introduce you to our next guest. If you've been watching Text Drunk TV over the years and any of our coverage of Jay Frog, you already know him, but I'm gonna pronounce his name right for the first time. 'cause it seems my pronunciation is a little old fashioned.
So let me introduce you to Yoav Laman. Perfect. Hey, nice To meet you, Yoav.
It's good to see you. Yoav, of course, is a co-founder, one of the co-founders and CTO here at j Frog. Yoav a pleasure.
How are you? Likewise Busy. Lots of announcements.
This warm up. Probably most we're a few warm up that we have had, uh, lots of good, good feedback from customers and, uh, also some suggestions. So, uh, And that's feedback.
That's the goal, actually. You know, what they say, the feedback from this year's Swamp Up will be in the products for The next, hopefully even well Before with ai. We have to.
So, y we were talking, you know, before we got on, we have had a lot of people give us a piecemeal, a piece here, a piece there, a piece I'm gonna ask you. Pull it all together for us, right? Give us the a go overview of all of these great announcements, all this great innovation mm-hmm.
That was Announced here at Swamp Up. Okay. So I'll try to give the full umbrella of announcements that we made.
So we started with Jeff O Fly and Fly is, uh, uh, our own disruption of the platform for, uh, a new agent, uh, repository based on olfactory. And that's, uh, that comes with, uh, a new user experience for managing software releases. Uh, so that was our first announcement, then we went over to, uh, AmTrust.
And AmTrust is, uh, the way to control your software supply chain based on three, uh, major concepts. First one is application that gives you ownership assignment for every release, every artifact, uh, in the JO platform. The second one is, uh, signed evidence.
And we announced, uh, partnership, uh, with many leading industry vendors, uh, such as GitHub, such as, so now, such as ServiceNow, uh, to, uh, uh, integrate their evidence, uh, into, uh, into the JO platform to accompany the, the releases. And, uh, finally, uh, it's, uh, policies that, uh, allow you to use the information, uh, within the JO platform, use evidence in order to assign rules for the progression of your artifacts, uh, of your lysis, uh, all the way towards, uh, production. Uh, so this is aplu.
It's a, it's a unified package that includes all these, uh, three main features, uh, ownership evidence and uh, uh, policies. Um, so that was, uh, another announcement. We also had a deep dive to our integration around evidence with, uh, with GitHub to take the salsa provenance of GitHub, uh, workflow bills and put them alongside artifacts in the JO platform, uh, as evidence, which is, when you come to think about it, it's the logical thing because, uh, you, it makes sure that, um, that the evidence itself is bound to the artifact and you can never get out of think.
And it's also the fact that Artifactory is the entity that is exposed through your production. So that's, uh, one thing that where we did a deep dive of UPT trusts. And the, uh, other thing is we announced on stage an integration with ServiceNow, uh, around abrus as a, as a full, as a, as a whole.
Uh, and we show the, uh, synergy between applications that many of our customers are already managing in ServiceNow, and how change requests in ServiceNow are going to be, uh, reflected as evidence in, in, uh, in JO, uh, and vice versa, how you, how you can move between the platforms. So that was, uh, also, uh, part of the big announcement of apta. Yes.
Then, so it's a mouthful. Then, uh, we moved to, uh, uh, a new announcement, which is, uh, around machine learning and ai. This is AI catalog.
Yes. And AI catalogs, uh, allows you to have governance over, uh, models that are packages, but also models that are, uh, uh, SaaS like, uh, an and open AI and so on. Uh, under a single platform, you have a catalog where you can find the latest versions of the models and the metadata about them, like, uh, the security status, the, the licensing and, and, um, other metrics that have to do with the model health.
And then, uh, similar to what we have, uh, uh, in curation, uh, we elevated the same features for machine learning. So you can allow different teams to use different type of models. Um, for instance, you may allow a research team to use deepy, but you never want to see that, uh, in a production facing, uh, uh, release.
And part of that when it comes to, uh, to SaaS models, is, uh, also being a gateway between you and the SaaS model. So if you, for instance, if you're using open ai, uh, you will use it through the GO platform, and that allows you to have governance also over these type of models. Uh, so, so this is, uh, this is the gist about the AI catalog.
Mm-hmm. And then we went into a bunch of security related, uh, announcement. I think I, I can mention two, uh, highlights there.
The first one is the support for, uh, ID extensions. Yes. Uh, and, um, basically it's a combination of artifactory acting as a proxy for your, uh, vs code extensions.
So we start with VS code, we will extend it to other ideas and, uh, curation allowing you, uh, to, uh, to, to control the, the, the, the, the extensions that your developers are able to install on the endpoints. And this is one of the most dangerous and overlooked, uh, risk that developers are, uh, currently facing because you basically install a software on your own from the internet that everyone knows that it's wrong, but, uh, for some reason with the ID plugins, it's assumed to be safe. It's not.
And we demonstrated, uh, uh, a social engineering hack that, uh, tempted, uh, developers, We read about him, we hear about it every other week, whether it's a docker container or from a repo component. Yeah. So, so now we can apply this protection by, uh, pointing at, uh, Jeff Fog, the old, uh, Jeff Oga, your, uh, single source of record for, uh, for your ID plugins too.
And another security related announcements that we made is around the gen remediation and, uh, what we've done there. So, uh, we do with modesty, we, we have one of the best, uh, research teams, uh, uh, in the world at Jeff o mm-hmm. The security research team and our security advisories are very accurate to a degree that you can, if you find a, um, a, a zero day in when you scan the code, the advisory that Jeff o gives you is, is one that if you take this advisor as a junior developer, it really tells you what the problem is.
It gives you an example of how to fix it, and it goes into details of, uh, what exactly need to be changed in your code. And what we figured is that we can just give it to the LLM and we can prompt the LLM with the research data of jfo, and the LLM will remediate the, the vulnerability or, or the zero that, that, uh, the jfo scanners found. We started with the integration with the, uh, co-pilot with the GitHub copilot, um, as part of the VS code integration.
But we will extend it. And the, the user experience is you write your code, jfo is, uh, scanning your code continuously, it finds issues, and it's taking the research data of the JFO team to prompt the LLM and apply immediate, uh, uh, suggestions of how to fix that. And you just have to accept it and, uh, and merge the changes.
So, uh, that's the, the, uh, I think that's the last, uh, uh, big announce. No, I don't think we did. Did we do fly?
We, yeah. Yeah. Started slide Fly With Fly.
Right. Okay. I got a little confused.
An ambitious, an ambitious lineup. Yeah. For one swamp up.
Yeah. Very ambitious. And the, A team that works relentlessly on the, I mean, the breaking trust to, to our users.
The theme around all of it though, Yoav, excuse me. You're okay. Yoav.
The theme around all of this is really the, the transcendence of ai, and you know, how we're seeing this just totally upend the normal flow of, of, of progress, of, of it, of software development, of the software development, life cycle insecurity in DevOps, in platform engineering, in, in everything. It's, if you're not adopting this to as, as Shami said on the stage, if you're not adopting this, get out of the room. Get outta the room.
Another important kind of theme here though, was no one company can do this alone. Right? You j F's, great company.
You got a great research team, you got great developers. But the, we're talking about just upending entire Yeah. Ecosystems in, in a blink of an eye almost.
And so you need a partners like a ServiceNow and an Nvidia and Sonar and some of the other ones that we've spoken about. Definitely. How is it working?
'cause now you're not just working as one team, you've gotta work at the pace and in coordination with other engineering teams. Yeah. How does that affect the pace of what you, you are doing at Jfr?
So, first of all, like you said, we are in an ecosystem, but, um, I think we are in an ecosystem of, of platforms today. Yes, there may be a few platforms in, in each domain, but still it's an ecosystem of lots of platforms that also makes the integration points. Once you figure out the integration points, uh, it, they, they are becoming very natural.
So what we find out, first of all, we have great, great partners with us. You mentioned ServiceNow and GitHub and Sono, but once you found out the logical integration points, it's very easy to get the teams together and, uh, create sort of a v team that works together and, uh, and creates the inter, the, the first level of the integration and then carries on to, uh, uh, to polish it. Uh, so it's actually surprisingly, maybe, but works exceptionally well once, uh, ev once you have the clearance of, uh, how things are working together.
Now, another thing that you mentioned is the, the impact of, uh, of ai. So AI already made a huge change in how we code. Yeah.
It's completely different now. Nobody even is surprised by that. Maybe the next surprising thing, but this is also, uh, a reality today, is that you have coding agents living, uh, alongside the, the, the human developers.
But I think that's the main gap is around. So, so coding is kind of solved. It'll change a a lot, I assume also, but, um, it's already, it's already happened.
But I think where we still free, uh, see friction is around software delivery. Because what's happening is that releases are being created in a much faster pace than ever. So it's a really, a nonstop release strain that is happening.
And you cannot stop to, uh, think about irrelevant problems such as how do I version my release? And what is the compatibility meaning compared to the, to the previous release? It's just an ongoing flow of, uh, of releases.
With frameworks like UPT trusts, you will gate the quality of the release so that you can trust. It doesn't matter if, uh, it was an AI agent that created, uh, the release or, or, or a human, or a combination of both. You have the gating, you, you have the governance to make sure that your release is, is ready for to de to be deployed in, uh, in production, uh, and to be promoted, uh, across the different, um, um, policy gates.
Uh, but at the end of the day, you need a new way to identify your releases. Yeah. You need a new way to pinpoint them and, and, uh, and scale them up and roll them, roll back and identify issues with existing releases.
And this is, uh, part of what's part of the change that we introduced with Fly, with the Gentech release as well. I, I think between Fly and with, with AI catalog, that's one of the sort of unwritten or underlying thing things, is that versioning is gonna to change Versioning. Yeah.
You will need a version, because at the end of the day, you need to the down. Yeah. But it doesn't need to be something that you, uh, take note of or remember.
Uh, and it cannot be anything. The trust is still not there to walk in a full semantic way with the releases, but it'll gather. It'll Time.
I'm sure it'll get because trust, trust is a trailing indicator, never a leading indicator. You know what I mean? You gotta earn it.
Trust, you Gotta earn it. Yeah. But I think it'll also play out like that because of, uh, of agent to agent communication.
Yeah. So the negotiation of what kind of capabilities you have, it cannot be bound to a, to a specific version. It doesn't make sense anymore.
It will be negotiated based on semantic, uh, between agents. And speaking of that, we actually had a, uh, Yanet, Janin on, uh, but the FPC server, he, he did a lot of great work on that. Yeah.
Made sure to tell us. So very proud of him. Yeah.
Jonatan started the MCP server of Jeff Fog as a local MCP server. As a, as a almost a, as as a pet project. Yep.
Uh, and then we, um, kind of, uh, upped the game and, and did a fully remote server. Yes. Which is more, more difficult to do.
But, uh, as a company, it allows you, uh, to have better control over security. And also, um, you don't have to request clients to update the, uh, the MCP installation on the local machine. But it's a, it's a, uh, what's the word?
A reference. It's an indication, uh, a reflection. That's the word I'm looking for.
It's a reflection of our times that before January, no one knew we didn't have MPC service. Here we are, September MPC, like, here we are in September. And it is the standard.
You must have it. You can't do without it. Yeah.
I think it's, um, kind of a co common thing that we're seeing today that, uh, things are changing on a, on a, You know, today it's s radically new tomorrow it's old hat. Well, MCP is a lot ahead of it. Like a lot of proposal of, uh, improving the standout and adding, um, so, um, stronger authentication and, um, and the ident stronger identity and, and so on.
Well, I think there's also the A two A thing, and There's the A two A thing, which are we, we can argue whether the standards are Complement. Well, that the thing about A two A now that's part of Linux, I believe. Foundation.
Yeah. That's some big names. And, uh, we'll see.
I mean, this is all gonna play out that the, the issue is for people like you and I who've seen this, you know, we've seen these games. We've seen these plays before, never at this velocity. That that's the key thing.
The velocity here. That the time crunch. Yeah.
It's, uh, incredible. The warp. Yeah.
Yeah, yeah. No doubt. What could we look?
So next year in New York? Yeah. God willing, I'll be there.
It's my home. September 1st, We will be there. What do we, what?
You want to give us an early preview or too early? I think it's too early. Especially we just, uh, uh, wrapped up saying that, uh, things are changing so quickly actually.
Yeah. So betting on, even betting on next year, uh, is hard. I think you will see, uh, first of all, you, you will see there, there are some things that I can say that, uh, uh, you will definitely see like, uh, a lot of improvements on what we are bringing to market.
Uh, today with APTAs, we have, uh, uh, a few more things, uh, at our sleeve. And also, uh, with fly, uh, I think we will see a more, um, a more intention based way to do DevOps. Yeah.
Almost, uh, VI ops thing if you want. Yeah. Vibe ops.
Okay. Well, what it dev vibe ops. 'cause you gotta have the dev in the ops with something in the Middle.
No, but in, in, seriously, it's going to be much more intention Yeah. Faced, uh, with the, a higher degree of trust. So I think that, but This is, yeah, I remember when HTML came out, all of a sudden I was a coder.
I was never a coder, but H-T-M-L-I could do then. Yeah. HTML 2 0 3, 0 4 oh CSS JS script, you know, all these things came on.
All of a sudden I wasn't a coder. No war. I think we're gonna see a similar kind of thing.
You'll have, everyone could be a, a developer with vibe coating. Everyone will with AI will develop something if they need, but there will be the tools that the pros use, right? That vibe coating, refined vibe, coating squared, or whatever you want to call it, where it'll be for professional developers.
And, and that's, you know, developers aren't going away. They're not gonna be replaced. They're just gonna be empowered With this.
I, I, I agree with you. I think we will have humans mainly for, uh, just expressing intention and providing, uh, feedback loop. Uh, there's that.
I, I'll tell you what else, and I've written about this. Uhhuh For, You'll Need Humans for the Creative Spark. AI is very good at when you say, I wanna do this, I want you to do this for me, I want you to create that for me.
But it doesn't create the ideas. Of course, The human brain still creates the ideas. It's that spark of humanity that I think will always be The human is the guide.
The human is the guide. Yeah. Uh, yeah.
But I, but the reason I asked you about next year is because I didn't think you would know what's gonna be next year, otherwise why you should retire. If you already know what's gonna be next year, retire. But I would like to have you back on in July, maybe next year.
We will talk about Swamp Up September 1st With Pleasure. Alright. Yoav, Yoav Laman, CTO Co-founder helping wrap up our day two coverage.
But we're not done. We still have a few more. So stay tuned.
This is Alan Shimel for Text Drunk tv. We'll be right back. Hey everyone, it's Alan Shimmel and we are Live.
That's right. Live, uh, it at Swamp Up. Swamp Up is back in Napa.
After I think two or three years it's been since they were in Napa Should End, I'm thinking it might have been since before COVID that we were in Napa last. But we're really thrilled to be here. It's beautiful here.
It's a beautiful resort. But more importantly, there is so much going on at Swamp Up, you know, like everything else in the tech world. It's kind of the year of AI more than the year.
It's the era of a, the dawning of the era of ai. Still, I like to tell people we're still at the beginning of the beginning, not even the end of the beginning on ai. Let me introduce you to my first two guests of our Techron TV coverage here at Swamp.
Up to my far left. He's the guy in the, in the, in the, uh, shift happens. Frog shirt, Yuval.
Let me make sure I get it right. Excuse me. Yuval Fern back.
Yuval, welcome back. It's good to see you again. Thank you.
Good To see you as well. You know what, before we get to our next guest, Yuval give share with the audience your title and role at jfr. Sure.
So, hi everyone. I'm, uh, Yuval Fern back. I'm VP and CTO of MOFs here in Jfr.
Um, actually joined Jfr, uh, a year ago as part of an acquisition of a company called Quack. Um, and nowadays, of course, part of jfr ML and the new product that we launched today that of course we'll talk about in a second. Thank you.
Yuva to my immediate left not in the frog shirt. Is is Del Elick. You Got that right?
You got that. Perfect. You got that on The money.
All right. Al is with, uh, Nvidia and Del introduce yourself. Well, Thank you for having me.
Yeah, it's great to be at Napa. I was joking around earlier telling folks that, uh, you know, I'm glad we're doing this. 'cause now my family really believe that I'm here for work proof.
So, got the proof right. I got the proof now. So, uh, my name's Al.
I'm a senior director of product, uh, at Nvidia. And my job is to, um, take the software that our, uh, awesome core tech team creates, um, uh, harden those, make them production grade for enterprises and help our ecosystem build, um, agents, right, that are fra frankly, transformative in everything that we do. Something we were just talking about.
Absolutely. And, and that's a great segue. I i little something extra giving us that segue.
We were at the keynotes this morning, right? You all led off, came on Yuval you, you, uh, introduced a new product for jfr called the jfr AI Catalog. Explain to our audience a little bit what it, what is it?
Yeah. So, um, as I shared, I joined JFO a year ago, and as part of that, I've seen and got a lot of responses from jfo customers about the challenges they have with adopting ai, the challenges that they have with actually trusting AI and the amount of new models that are being launched daily, right? Um, everyone speaking about ai, but actually using that in production require more than just, you know, testing the new and shiny model.
It requires the ability to trust that, the ability to trust where that model is coming from, um, who's the owner of that model, and even who is actually going to use that model. And as part of that, and as part of all that feedback that we received in the last year, we decided to launch the J 4G catalog. And that's basically a solution that allow organizations, allow our customers to manage the entire life cycle of AI usage.
I'll call it, from discovering which models actually exist, um, to deciding who should that permissions to which models, and eventually then serve those models, uh, track the, uh, usage metrics of the models and understand which application uses models and how. So the goal is eventually to allow organizations to understand where those models are being used by whom, and make sure that they trust those processes that are, you know, shifting in, in such a magnitude and such a, a, a pace of innovation that we haven't seen before. Absolutely.
We're gonna come back to that. 'cause I, I have some thoughts and questions, but I'll explain to me the Nvidia Yeah. I mean, connection, there's a reason for this awesome partnership, right?
Right. And so, uh, we're a full stack acceleration company. What that means is, right, uh, we're not just about producing processors or, or systems.
We actually build out AI factories, but we go all the, all the way up, right? For optimizing runtimes for not just models that Nvidia publishes, but also the ecosystem models as well. We call that nim nim inference and microservices.
And so, uh, what we do, you can think of a nim as, as a, a model with a runtime package as a single microservice, we spend a lot of time tuning that runtime to make, make sure it runs it efficiently as perform as possible, uh, on the Nvidia stack. Um, but equally, right, we contribute a lot to the open source domain. We're very, uh, we're huge participants in the open source community because going back to Val's point of having that, that trust, having that transparency, it isn't just that we provide the Nemo tron open weights, which are fantastic by the way, and Excel really good at reasoning.
But we, we also open source our, our training data sets. We open source our recipes so enterprise can then take those models further into them for their agenda, uh, capabilities. And so being the ones that provide the secure runtime and the open source of the models and the weights, and partnering with Jfr, what drives the services for having all that lineage was just an amazing partnership.
Absolutely. I, I want to dive a little deeper on this, right? So I was at Swamp Up last year in Austin where they announced the, uh, J Fry Nvidia partnership now ale over the course of the 12 months.
How have, you know, what, have you seen how this partner, well, look, AI has been on a hockey stick trajectory for these 12 months, right? But how has that affected, what's the, the, the net that our audience could take about this partnership? What does it mean to them?
I mean, look, you know, Yuva kind of set the scene, right? There's so much happening and it's happening so fast. I joke around and tell people that at one point, I think my kids thought I was a vet.
'cause I was talking about new animals every week from llamas to Mambas, you know, you name it, right? But, but it's awesome innovation that's happening in the ecosystem, right? So, a couple things that are, that I think critical number one is all this innovation that happens, right?
Yes, you wanna be experimenting a lot, et cetera, but when you have all this innovation that's happening, right? And you have all this open source, the potential for exploits grow significantly as well. Right?
And that's something we talked about earlier when, you know, we were on stage. And so, uh, being, having that transparency, understanding essentially what's part of your runtimes where malicious code can be potentially like implemented is, is super critical. So you wanna be experimenting, but you also wanna be careful and prudent when you're experimenting.
And so that's why having a single source of truth, right, for your system of records, for all your artifacts is critical. And that's why that relationship's been awesome. And, sorry.
Yeah, go ahead. No, no, go ahead. And I think the second point is, right, um, one of the first use cases we started using agent AI was, and actually defining the contextual, um, analysis.
Do the contextual analysis to understand whether vulnerability can be exploited or not, right? And I think, uh, I, I really appreciate the partnership that we have with the JFAR platform, because that's something they take very seriously as well. Just 'cause the CVE says, you know, it's got a high CVE score, doesn't mean it's exploitable.
There's a lot that goes into be able to exploit that. And so, you know, we see eye to eye in terms of how we go about really going deep and understanding the potential for exploits and protecting our, our, our customer base. Absolutely.
And by the way, this, This partnership didn't start because, you know, us and Vidia thought that we should work together. It started because the J four customers approached us, told us that they need to trust the source of the models. And, you know, the only models for market face, by the way, I think the target face is an amazing hub for models, but it's not enough in many cases.
And customers approached us and told us that they want to have a trusted source of models. And NVIDIA is one of those trusted sources. So a year ago, we, we partnered to make sure that the J four customers can actually get the Nvidia e models, the directly for multifactor and trust the region of those models.
Um, and from there, of course, we progressed with that partnership with the security solutions. So the contextual analysis, the ability to actually understand how those, uh, artifacts, how those models are vulnerable, and how we can make sure that in the production environment there will be no vulnerability. So eventually it's part of the same goal of making sure that the J four customers, and of course, the NVIDIA customers can actually trust the models, trust the origin of the models, and trust that there are no security incident that will arise because of those new artifacts that they not need to manage.
And, of course, have to manage to actually make their product progress over time. Excellent. Ada, I wanna come back to you 'cause you said something right in the beginning that I want our audience to understand.
And that is a lot of people here, Nvidia, and they're thinking G-P-U-G-P-U-G-P-U, not that you make a bad GPU, don't get me wrong, but the real key to NVIDIA's position is the software, is the community, is the ecosystem around Cuda and, and, you know, uh, um, NIMS and, and so forth. Talk to us about that a little bit and why you are, we're on live tv Paul, uh, cameraman. I'm gonna ask you to grab outta my bag, my AI catalog paper.
We'll bring it up. We're gonna talk more about it. But Al talk about Yeah, what the secret sauce at Nvidia?
Uh, well, We're a full stock acceleration company, right? I mean, um, yes. We, we start at, at the silicon, but we go all the way up the stack, right?
And so we have AI factories, we have our, our software portfolio that goes all the way up to the, um, you know, what we, what we call blueprints, right? Reference workflows for how you'd go implement a specific use case for, for agents. And you get the full benefits of Nvidia when you take the full stack, right?
Because we're able to optimize all the way down to stack. But by no means you have to take the full stack, right? And we leave it up to our audience, our ecosystem, to meet us where they think is best.
Some just wanna run on our infrastructure. We love them. Some want to utilize right?
Wanna go higher up in the stack and take advantage of the optimizations that we drive through software to enable that. I think one key to NVIDIA's, um, you know, call it success or, or or secret sauce, is just how, how ingrained we are with the ecosystem, right? We, we go to market through our ecosystem.
Our partners such as J Fog are super critical to our success at the marketplace. And so you're spot on. We're not just a chip company, we're a full stack company.
Um, right. You can take us, you know, you can go with us up all the way, you know, all throughout, or you can just choose to meet us where you think is best for your, for your, for your domain. I love it.
Thank you. So Yuval talking about the jfr AI catalog, you know, I've written a lot recently about what I call shadow. I, uh, shadow ai, right?
And we've seen shadow, look, I've been in, I've been in the tech business probably longer than both of you. Okay. Um, I've seen Shadow, before I saw Shadow open source, there was a time where enterprise's official policy was no open source allowed.
It was a, it was a danger, right? I've seen shadow wifi. I remember being at a US Army base and the, uh, army Information Assurance officer telling me we don't have a wifi security problem 'cause we don't allow wifi.
And as I'm walking with them, I see people unplugging laps and throwing them under their desk. As soon as he walks by, they plug 'em back in. And wifi, we saw it with the cloud developers whipping out their credit cards and opening instances.
It's no different, no different with, it's probably even easier with ai. Yeah. 'cause you have pick your pick, right?
Whatever one you want to use. So we call this a prop, right? They gave this out at the, at the keynote today for your talk, your joint talk.
Talk to us about the different models and how we're going to control shadow AI at the enterprise level. Yeah, yeah. So, so first of all, yes, it is a prop because, you know, this, this booklet have six models in it.
Um, I believe that the current number in a phase of models is around 2 million. And, you know, on top of that, there are, um, external like model providers like OpenAI and others. So that's another couple of hundreds of models.
So, you know, the numbers are way more than that. And of course, no book can actually, you know, manage and track the amount of models that are being launched. Um, and models are now, they used for, you know, so many different tasks.
So, actually Shadow, um, Aline in his talk talk about different type of models like reasoning models and, and, you know, voice models and models are being used for different tasks and not just for language models. Like, there are many models around computer vision and many models that are still used for structured data. And that's still a valid use case and still something that customers, you know, use as part of their use cases.
Eventually, the goal of the AI catalog is for organization to have the visibility about those models, about where those models are being used and how, and on top of that, as part of our launch, we actually launched a new product that will be available in a couple of months, um, called Shadow ai. Now, the, the issue of shadow ai, the problem with shadow AI is that in many cases, you don't even know that the model is actually adding one of your packages. It's possible that you downloaded the third party Docker image.
Uh, that doer image that you use actually uses ai. Um, and it's not something that you can just, you know, not know about. Because nowadays, even the regulators in many places, for example, in the EU, actually force you to show that part of your product uses ai.
It's something that you need to have visibility on. It's something that you need to be transparent on. So the goal of the Shadow AI product, but of course, is connected to the J four AI catalog, is to just not, not just allow you with Air catalog to choose which models should be used, but also to see, to have the visibility about where model is being used, what you are not really aware of.
And if those models are being used, for example, are malicious, or those models are being used actually not approved in your organization, you'll be able to actually block those from being used or, you know, go through the pro through the process and approve those specific models. Um, so the goal is about visibility and the ability to discover Where AI is actually being used in the organization. You know, again, my experience is you don't wanna stop people from using ai.
Yeah. And quite frankly, stopping people from using AI is like trying to grab sand in your head. The, the tighter you make it, the more it slips out between your fingers.
What you wanna do is just, okay, you're using ai, let's let us document it. Let's make sure it's safe. Let's make sure it's secure.
Right? And that, because otherwise you're fighting a losing battle. Nvidia has to see that as well.
Al No, I, I, I mean, right. We're not, we're not, we're not definitely fighting ai. Right.
To your point, right? It's, it's, I mean, there's plenty of productivity gains new markets that it opens up, as I said, right? Uh, the, the only reason we're able to publish and maintain so many of these NIMS is because we're using AgTech ai.
Right? Absolutely. But to your point, you do have to be cautious, especially with all this open source that's happening, all this innovation, et cetera.
You wanna create an environment that allows your developers to experiment. That is for sure, right? You wanna, you wanna continue creating that, that experimentation, right?
Uh, that you wanna enable as well. But then when you're going into, into production, yes, you want to have the safeguards that are in place. Um, you want be able to have the observability, the tooling that is in place, right?
I go back to, you know, the, the Nemo tron models that we provide, right? Just being open source in terms of not just the model weights, but the data sets of what it was actually trained on, the recipes of how we got there. Just to give the enterprises and the ecosystem that level of comfort, right?
To know exactly what's going on, right? Such that you always have that lineage that's super critical. I don't think you can, you know, uh, on the contrary, right?
Like we're just on the, I think you called it deep be era, right? The beginning of the beginning, Right? And just imagine when physical AI comes into, comes into this world, right?
Today we're talking about digital workforces, but very soon, right? We're, we have these world foundation models where you're simulating and generating data to train these robots and these a autonomous vehicles, man, it's, it's about to get exciting. It, it already is.
It already is. Um, but you know, that bring, both of you mentioned this, but you kind of ate at the edges. You didn't eat the middle, which is something else that they spoke about in the keynote saying, I'm trying to remember the exact name.
Was it AI gov or ai gov ops? Something? It Was, uh, dev gov Ops.
Dev gov. Ops, excuse me. Dev gov.
'cause there's always something in the middle between dev and ops, whether it's SCO or dev gov, gov ops. I learned a couple new ones today. Yeah, sorry.
Yeah. Yeah. So, but that's really what we're talking about here.
We want, we need governance. Not, we're not here deporting AI models, right? We're here talking about you wanna use ai, use the ai, but let's have some governance around it.
Let's have some guardrail, some knowledge, right? And that's, to me, that's the enlightened way of doing this, right? We're not discouraging use ai.
I know. So textron's, part of Futur, and we, we have a policy now where we're encouraging all of our people, the cameramen, the editors, the writers, the marketing, the decoders, use AI to your heart's content experiment. We expect you to make some mistakes.
That's okay. Make the mis I'd rather you make mistakes. Trying something new than digging in your heels and saying, I, I don't want to use ai.
'cause if you don't use, I tell young people this, who ask me all the time, you're not gonna lose your job to ai. You're gonna lose your job to someone who uses AI better this way. That's right.
Alright. Look, this is something we think about as well, right? And kind of now you're, you're going above and beyond just serving a given model.
You're talking about managing the life cycle of, of agents, if I may do that, right? Yep. And, and that pipeline, right?
We use, we, we have something called the NEMO platform for managing life cycles of agents. Mm-hmm. And that starts from data curation, uh, creating additional data that is, um, doesn't have the potential PII, that you know, you're not just collecting people's prompts, right?
To then, uh, taking a model and adapting it for a specific domain. Then once you have that right, and, and putting it as part of a, of, of an agent, make sure you have the guardrails that are in place, right? Such that it doesn't go, Ari, make sure you have the traceabilities.
You can backtrack across the way. We have, uh, something called the NEMO Agent toolkit that allows us to drive all that traceability, all that observability, all that pri profiling around. It's almost like, it's almost like onboarding a new employee.
You have to teach them about your cultures and your norms at the company. You have to tell them the dos and don't dos, kind of like, you know, I'm doing in this interview. Right?
They're, yeah. Right. And so, so it's exactly like onboarding a new employee and putting all those kind of, you know, managing it throughout this life cycle.
And to your point, it, it first, organizationally you have to, I love what you just said, right? Everybody's gotta be experimenting, but then making sure that your enterprise is leveraging the likes of the NEMO microservices to right. To manage that entire lifecycle.
I love it. Yuval, I'm gonna give you the last word and then we're gonna wrap up. No.
So actually going back to this, uh, dev gov ops term, and, and again, we talked about it today. And, and this is in a way the theme of this swamper because, you know, automation is already around. We're seeing that as part of the development lifecycle.
We're seeing that now as part of the DevSecOps lifecycle and also around, you know, ML and AI adoption. The challenge is not, or is becoming not how to automate those processes and how to actually, um, um, use new technology. It's how to make that in a governed way, right?
How to protect the way that we use the new technology and make sure that while we are researching new technologies, while we are actually adopting ourself to this new future, we do have the visibility and the governance on top of that to make sure that we're not doing anything wrong. And that eventually our customers of our product can actually get benefit from those new technologies that we actually use in our products. I love it.
Yuval Ado, thank. No, You got it. You got it.
One. Alan, Thank you so much for coming on here, kicking off our coverage of Swamp Up 2025. We've got a lot more coming at you.
Unfortunately, not all of it's live, but we're recording it all. And over the next days and weeks, you'll be able to see everyone we spoke to here. I encourage you.
com or Techstrong it Tech strong, AI digital, CXO, cloud native, now even Security Boulevard. 'cause we'll probably do something about dev gov ops on there to, for our full coverage at Swamp Up. But we're gonna take a break here.
Stay tuned. We'll be back with more from Swamp Up This Techstrong tv. Hey guys, thanks with Row, we're here with Haw Bergal, who's CEO of one io, and we're talking about how integration needs to evolve, especially in the age of AI, because, well, it's getting a little complex out there.
Haw. Welcome to show. Thank you.
So one of the issues that we seem to see out there is, well, it's getting a lot more complex as we noted, but historically we had a bunch of APIs and then we got a bunch of connectors built on top of those, and we managed them through some sort of centralized platform if we were lucky. But chances are we just kind of managed them in some sort of bespoke way that was not very efficient. You, how does the way we think about integration need to change as we start to deploy all these AI agents out there?
It seems to be coming together at a level of scale that is mind-boggling at the moment. Yeah, well, I think first thing, the old, old saying that goes in it, that if you build it, you have to run it. So I think that's the first principle which leads into this, um, more like a holistic thinking of managing innovations as more like a product rather than just ad hoc project that somebody, some hero puts together.
And then we hope, fingers crossed that they work. Um, so that's, that's the fundamentally fundamental kind of a mindset change that we need As part of that. Therefore, do we need to kind of build the integration platform first and figure out how to manage it before we go build all the connectors?
Well, of course, integration use cases are like various, there are different kind of indications that you, the simple, simple, simple from simple, um, um, innovations that can be kind of connector driven. Let's say that you need to copy your active directory and stuff like that, which is really like simple all the way to this, uh, cross platform workflow automation that involves several parties. So of course you have to weigh, uh, the requirements against the investment investments that you do.
But overall, the innovation platform is a kind of a good starting point, but it's only set of tools. So you really need to have some operations model. You have, you need to have governance, all those things on top so that technology is not, um, enough.
Mm-hmm. We have had integration platforms for years and they're usually managed by some internal IT team. Um, but it seems to me at least that it's not like we're integrating things every day.
We do integrate a lot of things, but is this really, you know, a capability that the internal IT team should have? Or should it just be something that feels more like a service that I just in vogue as needed? Mm-hmm.
Of course, it depends. What is your business. If you feel like that innovations are your core business, then of course you invest into your own capabilities.
Um, at the end of the day, there's no, no sort of a way of outsourcing responsibility. So regardless of internal IT team doing them these things themselves or, uh, getting them as a service or something in between, there should be somebody who's responsible of this. So, um, that said, um, majority of the companies, enterprises, they have their internal team to support their business.
So things that are not directly creating, um, business value should be somehow put aside or buy both, not the investing too. Yeah. Um, will this whole equation get a little more complicated?
We talked about early on in the intro with the rise of AI agents, but are these not gonna be, I don't know, hundreds of thousands of endpoints that need to be integrated, not just with legacy systems, but each other? And how is that gonna all play out in your mind? Yeah.
Well, um, I, I would, I guess that the ai, um, helps us to build faster, first of all. And then AI agents are as, as, as we see them at the moment, they are mimicking human beings. So it means that they, they still need, um, real time, reliable correct data in order to operate.
That means that you need the integrations more than ever. And then the demand is becoming so, so, so much higher because of the AI agents will be deployed, systems will be, uh, and they require more and more data. So you need to build more and more integrations, which means that you have to find ways to scale, which means that, uh, the manual way of, uh, and approach based approach that you bring in bunch of people and start building from the stretch on top of the platform is not suitable anymore.
Will we also maybe, I don't know, create AI agents for the integration platforms themselves to help integrate AI agents with legacy applications? And the AI agent will talk to one other AI agent, which will then manage the process for them? Is that possible?
Yeah, well, they need something in between. And uh, like what you just described is it's sort of considered as a kind of API driven approach that you have APIs and interfaces. Putting AI on top of the APIs might make them a little bit more, uh, you know, intelligent.
But the problem is that how, what is the communication? What, where is the communication happening then and how do you, the translations and mappings and all these things with different data models and how do you run the business logic on the integration? So point to point, yes, that I can see that happening, but then you need to have this, um, multi-point integration use cases.
Um, it's unlikely that ai, um, agents can replace it. They can, they can be super efficient when they get the data and can process it and send it over, but how they send it over there needs to be something in between mm-hmm. Some kind of fabric, Right?
And to your point, how that gets accomplished matters, especially from a governance and security and compliance perspective. So I can't help but wonder if the cards before the horse a little bit, and we're all excited about AI agents without thinking through exactly how these things are gonna get managed. Yeah.
Well, I think we, thankfully we have one, one really good example in the, in the sort of past of it, which is DevOps. I think same fundamentals can be applied, uh, when it comes to managing innovations, taking the DevOps culture, taking the automation, taking the monitoring, having the lifecycle approach, and that leads into better governance, clear responsibilities, accountability, um, SLAs, SLOs, all these things that are making integrations look like more at the products that have some, some, you know, clear reason to exist and they're not at some, some ad hoc stuff. So I think that DevOps principle would nicely limit it into this picture When it comes to integration.
What's that one thing you currently see organizations doing that just makes you shake your head a little bit and go, folks, we should be a little bit smarter than that? Well, we, we still try to fix, fix this scalability issue with the sort of the old way of doing things, which is, uh, today, I think just today, garner has released the latest magic quadrants for Pass, and you'll see the same folks there year after year, integration platform as a service. That's considered as a kind of a, some kind of a silver bullet for this.
And nobody's talking about the actual requirements for these integrations. So we are taking, um, we are enhancing the tools for developers to develop integrations. Uh, but you still need the developer.
So I, what you said mentioned about the AI being on the, on the IPAs platform and helping, helping them to develop faster, make more integrations without any management model. And we all remember what happened happened when the startup, it was introduced back in the day, like suddenly you have different things outside within the organization because it's so easy. But at the end of the day, security, governance, all those things that are super important nowadays, um, they, you need, you just need a model for them, operational model that covers them, the whole thing.
From your perspective, um, how will the current platforms need to evolve? Therefore, I mean, a lot of people will say, I already have an integration platform. So what becomes the impetus for them to change that out or swap that out and, and, and what's the ROI on that?
Well, I don't think it, it goes down to not only on the platform, what technologies it comes down to the understanding that innovations are, are, are sort of important part of the whole IT delivery as they, uh, are in the supply chain is a good example. Supply chain management innovation have been, have been fundamental for, for that kind of, uh, uh, concept for, for decades. And now within it, we have to wake up that we should have a similar principles, even regardless of the technology we need to invest into competencies, the model, how we run it, uh, the whole approach of, uh, really investing into important things and consider integrations as a product.
So it takes a, also, I think there is a kind of a skill, skill gap in that sense that companies are not really getting there. And it's not about ai. It's about really having the competencies and understanding what it really takes to run integrations as a, as a kind of a, um, organic part of your it, IT ecosystem.
Mm-hmm. So as you look forward to this new AI slash API driven world, you know, how many APIs will organizations be managing, do you think? And then, you know, are we gonna see some level of scale here that people aren't quite prepared for?
Well, I think it was some what it, MuleSoft or Salesforce, um, study about this app, number of applications that we add, uh, every year in the larger enterprise, it's hundreds of new applications will be kind of added, especially like terms of ai. So there will be a lot of interfaces, APIs, and now the question is that how do you make sure that they are, uh, they match into your security requirements, all these things. So it, it's, the scale will be, will be just like we, I think we just, we, we have just scratched the surface when it comes to a number of APIs and interfaces.
And that being said, you need a governance model. You need operational model, otherwise you're gonna be like, you are, you're sailing your ship without knowing if all the, all the hatches are latches are closed. True that.
So what's your best advice ultimately for IT folks out there as they kind of think this through and they start to, I guess, recognize the level of scale? What should they be thinking about? Mm.
Quite often we see when we discuss with the customers, the biggest pain is that they, they say that they have technology, they have integration capabilities when it comes to team, uh, competencies and, and things like that. But they still have, uh, backlog of six months to getting there. Which means, of course, simple answers is you have to prioritize.
But how do you prioritize if you don't really know what is the most business critical? Um, uh, for instance, for what, what is the most bus business critical innovation for you? How do you do it?
So, um, my advice is that you really step back from technology perspective and start thinking that how do we actually deliver integration in integration at scale, which means that the operational model, how do we, how do we ensure that we are credible deli in delivery on time? All these things that are like basic stuff to any, any IT operation, but integration are integrations. Integrations are not often considered as, as a product.
So people don't think them like that. So I would start with that type kind of a thinking that should be turn our thinking, the more productized, standardized approach, and what, what kind of investments we are willing to, to take in order to get there, which means then you have to prioritize. All right, folks, while you're heard it here, hey, when it comes to integration, we're gonna be looking at things at a level of scale that might be mind boggling, but at the end of the day, it all comes down to the fundamentals.
But if you don't start with integration, you're gonna treat it as an afterthought. It's probably gonna go wrong. You, uh, thanks.
Being on the chair. Thank you. All right.
And back to you guys in the studio. Hey, I'm Bob Planker and I am talking about security and compliance, security and trust, actually. Uh, you know, compliance is one thing, security is another thing.
And trust all works up to the idea of trust. 0. So I like to start with sort of our approach to security and our, our approach to all of this stuff.
And in fact, our approach when, uh, we talk about security and compliance, our approach is security first, security, you do good. Security. Security is an always sort of thing, always on compliance.
You're getting audited once a year, something like that. If that's all you're doing security wise, you're probably in trouble at that point, but, uh, uh, you know, good security is explainable to your auditors, or it should be at least. And so that's actually one of our goals.
But, you know, we really want our customers to be able to be secure faster. Security itself is not something that advances an organization. It's not the prime thing for most organizations.
Some organizations actually do security and they care deeply about that, but most it's just a means to an end. They want to deliver services, run workloads, that sort of thing. And so where we can turn things on, we like doing that, uh, where security's always a trade off in some ways.
So we don't turn certain things on because of those trade-offs, but we want it to remain flexible. Not everyone is the same. Not everyone has the same requirements, many workloads, there's always something, right?
So I'd really try to stay flexible there. Recovering quickly, all manner of stuff can happen in an environment, and being able to, to be resilient to that is really important. Uh, resilience has really been the primary feature since v uh, uh, VMware infrastructure software since, uh, 2005 or so, when vMotion was invented, and we kind of stopped talking about it, but we should have, and actually the EU Digital Operational Resilience Act, uh, where banks in the EU were really doing a lot of work with that, uh, late last year, mid last year, uh, really highlighted all of the resilience features that we have.
And we've got a ton of stuff. And, you know, just tactical stuff, uh, from failed application upgrades or de-risking just day-to-day stuff or, you know, strategic stuff, what happens if I get run over by a hurricane and that sort of thing. And so very important there.
And then last on my list, really what we're after in VCF and the, the real differentiator is trust, inherent trust in the stack. Well, we talk about zero trust a lot. The industry talks about zero trust, but I see zero trust implementations there end up being lots more trust.
So zero trust should be less trust, not more trust. And it's maybe just my opinion, but you know, that's, you know, fewer things to secure. The easiest thing to secure is the thing that you don't have, you know, and so reducing the amount of trust, reducing the population of people that can have access, all of that stuff, very important for security.
And then being able to replace trust with continuous verification. I mean, there's the old eighties cold war thing. Uh, trust but verify.
That's exactly right. You know, like you can, if you've got data from the last hour that your hosts are all up to date and are running the right level of firmware, all of this stuff, that's really powerful. And so the ability to trust that your platform, your data is where you think it is.
You know, data sovereignty is really important. There's a lot of regulations nowadays about data having to remain in certain places, uh, that you know who's got access, you know, what has access, not just who, but what other systems that the system is verifiably secure that, uh, it's being monitored, it's continuously monitored, and you can verify that the security state of it, uh, problems. When that changes should be highlighted rapidly, it should, uh, come to people's attention.
You know, somebody that can do something about it, dear human, dear human maintainer of mine, I am VCF and you should fix me. You know, that sort of thing. And maybe it's, maybe it's innocuous, maybe it's an actual breach, but a lot of times it's just innocuous.
Somebody changed something. I used to change security controls to debug and to debug things, to fix things, and then I'd forget to put 'em back, you know, and then I'd find out about it during an audit. And then resolving things, uh, resolutions to problems should be quick, non-disruptive.
If, if they can be, you know, vMotion is a great example of that, again, where we can patch infrastructure without taking the workloads down. And so that's, uh, kind of the core of how we think about security moving forward. And, and really, again, not about security, but about trust.
Can you trust your platform? Do you trust your platform and why? So I'd like to talk a little bit about lifecycle patching.
Some of the highlights, hit some of the highlights from, uh, uh, the security world. Things that are pertinent. There's a lot to be said about lifecycle, being able to, to update, upgrade patch when there's a patch available.
And we've gone through some changes over the last few major versions, update manager's gone, we miss you Update manager. But lifecycle Manager's really cool. It cares deeply about the way a system is configured.
It's doing the continuous monitoring as well. Hey, a system has extra pieces of software on it. Well that's not good.
You know, like, we should check that out. That sort of thing. And so we've taken a lot of feedback around that.
How do we make that easier to use? How do we make it more valuable? Multi-vendor cluster images?
Uh, you know, in a perfect world, we all get a dump truck full of money backed up to us every couple of years, and we buy a whole new homogenous cluster. That's not how the real world works. Not at my real world at least.
And so, uh, um, yeah, uh, making that easier to deal with, taking out some of the friction, uh, ha the high availability and NSX components were add-ons and installed separately, and they get into dependency loops. We're one big family now, and VCF, it all just ships as part of it, so that's gone. But also things like GPUs, all this ai, newfangled AI stuff is neat, but we've spent 10 years making GPU usage just part of just one of the gang as far as our workload is concerned.
Being able to move it around, you know, AI researchers and data scientists can feel important on their own, you know, but from an infrastructure perspective, it's just all the same. And that's really nice, especially in nine. We've really done a lot of work with the vMotion stuff.
Live patching and custom EVC profiles. Talk a little bit about those here. So live patching is something we announced in eight, vSphere eight, but its scope was so limited, we actually haven't had an opportunity to use it yet, you know, and that's gonna continue in the near future too.
But, uh, in nine, our, our vision for it is that about 80% of anything that a host needs to be patched for should be covered by live patching, you know, and that's really nice. The, the ability to not move workloads, most workloads can move just fine, but there's big ones. There's, uh, workload administrators that are jumpy about it.
And so we want to, uh, uh, where we can leave them where they're at. We enter partial maintenance mode and then partial maintenance mode just stabilizes the machine. Nothing going in, nothing coming out as far as workloads.
And then it does what it needs to if it needs to repair, uh, and patch the virtual machine monitor. And we'll talk a lot more about the virtual machine monitor in a few minutes here. Uh, then we do what's known as a Fast Suspend resume.
It's basically a process to process vMotion is what it amounts to. It's milliseconds, nanoseconds, I dunno, I I used to say that it's measured in, it could be measured in CPU cycles, but any, anything can be measured in CPU cycles. Caveat here is, uh, DPU and TPM enabled hosts are not yet compatible.
D p's got the ESX running on the DPU itself, so there's considerations there, and tpms, the extra security. So what we're doing with Live Patch is replacing part of the operating system, you know, and we don't want to ta we turn on extra security to prevent attackers from being able to do that. So we need a way to authenticate ourselves to the system so that attackers can't do this maliciously, but we can.
So it's in pro in process. It's number one question. Hey, I got a quick question there.
Yeah. The, the TPM enabled hosts, we know that Microsoft has made a big deal about future versions of Windows needing a TPM to be enabled. Uh, is this something you feel is gonna impact the ability to virtualize, like at this point, workstation endpoints, or do you feel like this is something that's gonna be easily overcome very soon, like you are working on figuring out how to make this TPM compatibility thing work?
Uh, so this is at the host level. This is ESX itself. So ESX is the, the hardware trusted platform module belongs to ESX and no workloads touch it.
Um, there's no workload data stored there whatsoever. Uh, for workloads, we've got the virtual TPM, which is completely separate. It's rooted in VM encryption, so it keeps it secret safe that, that direction, and it's not impacted by this at all.
So, okay. Thank you. If that Makes sense.
I, since, uh, Tom Broken, now we can ask questions. I'll go. Um, how does patching work in the context of V-S-X-I-I being part of the whole product of VCF?
Can I just use this feature to pack, just patch, just so when something critical happens, or does it have to come apart, come to, to me, as part of a huge VCF upgrade or patch, uh, itself? It, it Can be both. Uh, so we've got a new versioning scheme as well.
Uh, some logic has been applied to our versioning. 0 U three Q-Z-S-S-P, whatever anymore. Uh, nobody knows what those are.
Uh, everyone knows what Arabic numerals are and that, you know, the versions go up and we have newer stuff. So really trying to do that. 0.
2 as an example. 1 is a VCF bundle, and you, you'll get things as that as well. 1 is a tactical patch, basically.
And, uh, so we're gonna apply that. 1 is released, that'll be something you'll apply like this. But you can get these patches in both directions, uh, if it's big enough or, um, and there's a, there are timeframes associated with these things as well, you know, monthly, quarterly.
1, for example, would be a quarterly patch, that sort of thing. So, you know, trying to make some sense out of it. But yeah, to your question, you'll, you'll be able to see the, uh, ESX updates in all of those sorts of ways.
And, And Bob, this is, uh, Jack Poller from Paradigm Technica. Uh, another question on patching, which I know is, is sort of not really security, but still security is, are, are patches going to be inclusive or are admin's gonna have to be responsible for saying, I need to build up a stack and a chain of patches in order to get my machines? Oh, that sounds like a nightmare, Jack.
The, uh, um, no, they're always inclusive. Uh, and with very few exceptions over my experience with VMware, basically, we all, we, they're always cumulative. So if you apply the latest stuff, the latest version, you go out into the support portal, download the latest thing, you'll have all of the patches up until that point.
So, cool, no good questions. Uh, EVC. So making patching easy also, you know, uh, if you've got mixed, mixed clusters, clusters that, uh, so you get different, um, generations of CPUs, you can't vMotion back and forth between them.
EVC, it enhanced vMotion compatibility, basically smooths out the differences between them. But it's been incredibly hard to use because you had to, you had to remember to turn it on when the cluster was absolutely empty, right when you built it, and nobody remembered that. And then, or you gotta wait for a power outage or some other catastrophe and then make an unscheduled change, that sort of thing.
And so, a couple with that, the, uh, uh, CPU generation CPUs have kind of gone nuts, and there's a whole bunch of different types and varieties, and there's all this edge stuff now that uses all that stuff. We've got the ability to just capture what you're using. And in fact, uh, uses link mode if you've, you've got your host in link mode, uh, clusters are all linked to, to each other.
It'll look at the whole thing and say, here's the baseline for all of this stuff, and then you can just turn it on right where you're at. And so hopefully that will make things a lot easier moving forward for, uh, uh, again, just patching, being able to deal with it. The, some of the friction here deep inside the hypervisor itself, doing a lot of work as far as security and the layers of security in here.
Uh, first couple of things, code signing, we've been talking about that for a long time. Our ecosystem's got a lot of inertia to it. We still have partners, vendors out there that are telling people to shut security off because they're not signing their code.
You can do that, you can still do that. We're on our way to making that not possible. But, um, if you do that, now you get an INDISPENSIBLE warning that you've got a security problem, which you do.
Uh, secure boot, 40% of the world uses secure boot. It's been around for 15 years. It's a great way to prevent malware.
Trying to make that easy as well. You can enforce it via, uh, configuration profiles. Now you can actually just turn it on, switch over to it, and ESX will boot just fine using, uh, using that now.
So shouldn't be any barriers there anymore except, uh, uh, in people's minds, hopefully. So, let's talk about the user level, monitor sandboxing, and then confidential computing a little bit too. Uh, so inside of ESX, we've got all these different layers of, I often compare it to an onion, you know, you peel it a little bit, you cry a little bit, it's all good.
And, uh, but you've got these different layers there. The guest operating system, unless you're running Windows three one or dos or something, which still run by the way, uh, you've probably got inpro process protections there. You've got a, a, a role-based access control model, something like that around that.
You've got the VM runtime, container runtimes as well, just a workload runtime, and that's a security boundary. And then around that, in seven, vSphere seven, we introduced a sandbox. Basically, it watches what the runtime does, and if it didn't try something funny, it kills it and sends alerts, you know, and it's not perfect, but it's a heck of a lot better than it used to be.
And these protections are available on all of the workloads. Running on E-S-X-E-S-X itself is a security boundary. You know, there's, uh, you can, uh, sequester certain types of workloads and certain, uh, security, you know, keep the same security levels together, that sort of thing.
Then underneath CPU and memory, which about eight years ago, we discovered that the promises made by CPUs and memory controllers and IO controllers, and that aren't necessarily what actually gets implemented. And so, and there's more of those. I mean, recently in the last couple of weeks, there's even been announcements about new versions of Specter and Meltdown esque vulnerabilities from a MD and and such.
So nobody, nobody's, nobody gets out of this one without a little bit of blame. But what do we do about it? So we've got the, the two main types of vulnerabilities here, hardware vulnerabilities, where your guest operating system, an attacker that's got access to a guest operating system, can coerce the hardware into giving it data it shouldn't have access to.
And then you've got the VM escapes, you know, the, uh, um, where you can, uh, attacker breaks into the guest operating system and then can get out into ESX, and you don't want them there either. So, as far as hardware vulnerabilities, we'll talk about a little bit about that. Confidential computing, for example, we've had A-M-D-S-E-V-E-S and Intel's SGX technologies built in since seven.
You know, there's follow ons, those are kind of hard to use, and they kept secrets from the hypervisors. And so the hypervisor basically takes its ball and goes home, says, I'm not gonna help you with vMotion, I'm not gonna help you with all this other stuff. And so, a MD and Intel came up with, uh, new versions of these that help with, with a lot of that stuff.
And so S-E-V-S-M-P-T-D-X, the follows, uh, follow-ons to these, those technologies. And so, uh, a MD in particular, they, uh, uh, they implement their versions of the security, the confidential computing, uh, uh, technology. They've got a security processor.
It's an arm chip that's actually integrated into their epic CPUs, which is cooled by itself. And a guest operating system that wants to participate can request an encryption key. And, uh, uh, it gets the encryption key.
Its data is encrypted in memory and in the CPU registers as well. And so that's really nice. And so it's not an all or nothing thing.
You can turn certain guest operating systems can enable it. If you've got a guest operating system, if you are running Windows three, one, you don't have to enable it, whatever, it can be just its own little operation going on there. And then if there is a security vulnerability, uh, and a guest operating system can get access to something, it shouldn't have access to the, uh, um, all it gets back is cipher text.
It doesn't have the encryption keys there. So that's a nice powerful protection. It's actually kinda interesting that CPU manufacturers are basically admitting that they are probably gonna have more problems like this.
And so, but it's a way to protect yourself. And it's really important in shared environments, especially public cloud. It's been very popular in public cloud because you don't know who your neighbors are.
You know, it's a little bit of different security profile when you, when you're your own neighbor, you own the whole box, the whole box belongs to you, that sort of thing. And so, but, uh, uh, building that in, we've got a lot of customers that are running in shared environments and that do want to take advantage of this. So we've got the initial steps here, uh, to enable these particular technologies.
Does require host hardware support, as would seem obvious. Uh, right now it's delivered via RPQ. We actually want to ask you a couple of questions.
If you want to turn this on. It's not very onerous. Uh, so just, um, yeah, uh, reach out.
If, if people want to turn it on, uh, it will be, yeah, it'll be a in in the future. It'll be fully, it's tech preview, essentially, but, um, yeah, more to come. So, Bob, yeah, what's up?
Uh, I understand the use case here for confidential computing. Makes sense. You wanna protect from lateral movement.
Uh, any kind of idea, what kind of overhead, if any, that could introduce, uh, on the host itself? That's a good question. And actually it, well, and it's gonna get the, you know, if it had a motto, it would be, it depends, you know, the workload, it depends on IO and that, there's actually a complicating factor here too, and I'll get to that in just a second.
Uh, the user level monitor, we implemented this with a change in the virtual machine monitor. So performance testing is actually ongoing right now. Uh, it's, yeah, it's less, you get, it's less performant than the, the old style.
But, um, yeah, we're working on it right now. I don't have a specific number. You know, everyone wants a number.
Is it 5%? Is it 35%? I don't have a number for you, But there, there is a number out there.
And it could vary based on the customer, but there's prob likely to be some kind of impact that you need to account for. Oh, yeah, there is a number for sure. We don't know what it is right now.
Okay. And we don't, we haven't properly, we haven't characterized the workloads enough. So the virtual machine monitor that we've been dealing with is 20 years old.
You know, like, and we've got good characterization of workloads on it. The, uh, um, yeah, the new one is not that old. And so, uh, our performance in the office that the Broadcom office I'm part of, uh, there's a guy that sits down the hall for me.
And he, that's exactly what what we're talking about right here is exactly what he is been doing the last few weeks. So, yep. And he was unwilling to give me answers about it as well.
I asked the exact same questions. So the, uh, uh, moving forward, let's talk a little bit about that. So, uh, CPUs basically have two modes in which they can operate.
The, uh, um, one mode is VM kernel or the kernel mode where anything running runs really fast, has no permissions. 'cause that's why it runs really fast. And, uh, can, has a run of the box user mode is a little different.
The, uh, user mode is, um, doesn't have a run of the box. It's got permissions. It's, it doesn't have permission to do anything really.
But for performance reasons, all hypervisors run things in kernel mode. And, uh, oh, it makes sense. But that means when you've got a a VM escape, you're root, you're administrator, you're, you can do whatever you want there.
And so that's not good. So what we're, what we're doing is part of this, and you'll see it in nine. It's in nine, but it's not the default yet for a lot of these same reasons, Ken, that we were just talking about, that we're kind of conservative when it comes to this stuff.
So, uh, it's the default, if you turn on memory tiering, it's the default if you turn on confidential computing, but it's not the default. There's some, uh, uh, advanced parameters you can set if you want to, uh, uh, to make it the default or make it a certain percentage of the workloads that you start. But, uh, um, yeah, it de privileges it.
So somebody gets out, does a VM escape, gets out out of the sandbox even, well, what are they gonna do? They don't, they have no rights to anything. And then beyond that, we've taken those sandboxes, you know, the idea of, Hey, we've got these sandboxes around the workloads themselves, but what about all these other processes?
Well, we applied them to the other processes. So these are just four different examples. I didn't want, there's a lot more little boxes I could draw, but they've got a sandbox around them as well.
They've got a permission model, and if they try to do something funky, again, killed alarms. Thanks for playing. So, uh, uh, yeah, just trying to sandbox as much as possible.
Contain the blast radius there. We're basically doing a change through with the vm, like you're doing process, uh, Services. Yeah, exactly.
Yep. So, you know, the old school, uh, vulnerabilities, like the service location protocol, which is gone in nine, by the way. Uh, that open source project was unmaintained for a number of years and had vulnerabilities, and we had to issue advisories about it and stuff like that.
You know, uh, the problems there could have been contained. Certainly we want to get it fixed, but you know, the idea is to buy time so that you can do the stuff that's not in a panic. And, uh, so, and that's nice.
So workloads, people wanna run workloads on their platforms, and I don't blame 'em. Uh, most people don't just run VCF for the sake of running VCF like I do. Um, number of sort of tactical, uh, incremental improvements to workloads.
Uh, the really interesting things here, secure boot pe, there's a lot of people wanting to sign their own, do their own secure boot stuff. And that's, uh, cool. We support that now, support that officially now, there was a backdoor way to do it before.
And, uh, so we, that's been promoted, uh, hardened virtual USB, we had some advisories about that. And anytime we have an advisory or two about the same subsystem, we'll take a look at it and harden it. So, virtual machine hardware 22, you'll see that, uh, Microsoft's Black Lotus vulnerabilities where they lost control of their signing keys for Secure boot, uh, that was not good.
Uh, they've been slowly, quietly replacing the, uh, and revoking UEFI certificates over the last few years as part of Windows update. Uh, so if you are running nine and running the latest versions of, uh, virtual hardware, you'll need the latest versions of the Microsoft ISOs. 0, we bumped the revision on there.
There are some feature changes, but forensic snapshots, this is another interesting thing, because again, we're kind of conservative when it comes to operations. And any snapshot that we, we take, we want to be runable again, and convincing engineering that forensic snapshots don't need to be runnable. Actually, that was easier than than we thought, but, uh, uh, forensic snapshots don't need to be runnable.
They need to be scannable by a tool, but that's it. So we've got support for that now too. And so that's really nice.
I think the biggest thing for me, for workloads, we get a lot of resilience features in the platform for workloads, but the VPCs, the virtual private clouds, yeah, I, yeah, the, uh, um, are really interesting. The, the idea that you can dynamically create network segments for workloads to isolate them, apply security controls to them, all of that stuff. And you can do it globally, all kinds of, there's all kinds of neat stuff there.
I think that's a really interesting thing moving forward. And as NSX becomes tightly integrated, well just becomes part of ESX, it's, uh, um, yeah, that integration is getting a lot less complicated to do too, and a lot easier to set up. Cryptography.
People are deeply interested in keeping their secrets and cryptographic methods or how that works. 3 is the default all the way around. Uh, we can fall back by default.
2. Again, we're a little conservative for backwards compatibility, but, uh, you can set that, I'll show that to you in a second. And you can choose your cipher suites as well.
Um, one, I've got slides for all of these things, so I'll just skip into it. Key wrapping. So one of the ways in which you can do encryption is to keep your keys externally in a key management system.
And that's great. People, uh, people do that, but we never delete a key. We actually can't tell if you're still using the key or not.
And so people get really angry for a bunch of different reasons. One, they get all these keys in there and they don't know what's in use and what isn't. 2 million bucks in keys every year, you know?
And that's a lot, you know, like, I, I think that's a lot. And so people asked, and three, they wanna rotate their keys. And so that kind of plays into which keys are actually in use.
And so we've got a wrapping key now. Uh, and so it's not just the two keys, the data encryption key and the key encryption key anymore. You can, we can wrap the key encryption key.
You know, all problems are solvable with another layer of abstraction, right? You know, and so we, uh, um, we can wrap that key. We can rotate that key.
We can give it a name that your KMS provider, uh, admin or your KMS admins can find. So In that case, you are wrapping a relatively static key with the dynamic key store in the KMS that people would rotate. Can we do a, can we do a force and say, Hey, we're, we're not sure of the, the, the validity or that, that the, the key we've wrapped is compromised.
Can we force rotation on that one as well? Yes. Yep.
You can, uh, you can also create, uh, so one thing I didn't mention here, and I'm sorry, should have actually, because, yeah, uh, so there's this idea of rekeying. There's a deep rekey where you, uh, have to power the VM off and you rekey all the whole stack, you know, from scratch. But there's these shallow rekey where you're changing the intermediate keys, and you can do that while everything's online.
And so that's how you would do that. You would rotate it through a shallow rekey process. Uh, you can either create a, another key provider to do that, or you can just do a, uh, a, a shallow, uh, rekey here, however you want to do it.
There's mechanisms for for that. It's, it's very flexible. Good question.
Uh, ciphers, I was talking about this. Uh, we've had a NIST 2024 TLS one three only, which will be a popular option. 3, only the two ciphers that pass, that pass all scanners globally.
You'll have to find other things to talk about with your GRC folks. So sports, weather, international regulatory compliance, whatever. Uh, speaking of international regulatory compliance, the ca browser form the standards body for, uh, browser certificate validity and all that stuff has over the next two years are lowering certificate li legal lifespans to 47 days, which sounds like an absolute nightmare to me.
Uh, I long for the days where I could get a 10 year certificate and be done with it, but, uh, I get why, you know, but to the, uh, um, yeah, so VCF has got interfaces for managing these things, being able to see the state, uh, status of it, uh, renewing them automatically, and we've got things on our roadmap for better, uh, support for external ACME protocol, that sort of thing. So, yeah, uh, a lot of good stuff there. A lot of, a lot of good stuff.
Pa, centralized password management, centralized security operations, auditing, all the stuff that was in Aria operations prior, has become VCF operations and really doubling down on the auditing and monitoring for security, being able to dive into, uh, you know, uh, you get an alert that a security control has changed, you know, who did it? Being able to go into the VCF operations for logs, formerly re operations for logs, uh, log insight, whatever we wanna call it. Um, it's all becoming VCF operations, so I'm happy about that.
But the, uh, um, being able to dive into that stuff, being able to see who did it, uh, maybe not tell why it was done, but, you know, get to the, the bottom of things more quickly so you can figure out is it an actual breach or just, yeah, junior admin doing something, you know, or senior admin doing something and forgetting, you know, as I said earlier. So a lot of good stuff going on here too. And also for compliance, trying to get ahead of your compliance so when the auditor shows up, you're ready to go, you know, you don't have any surprises.
But also keep it flexible too. So if you're, if you've made a business decision to not do a security control, you can shut that off. So it's not always bo bothering you.
Getting towards the end here. Access control. Access control is a big way in which organizations are breached, frankly, you know, identity systems.
And so being flexible with this, we're also really trying to get out of the business of being an identity provider, because there's so much better stuff going on with real identity providers out there, you know, and if you need an on-premises one, the Symantec VIP stuff works great, otherwise we support Okta. We support Ping Azure ad or Intra id, but also generic providers as well, saml, uh, OAuth providers, all of those, uh, you can set up your own as well. And so that's, that's been something that's been asked for.
And so there it is. Uh, we've got a sitewide VCF wide unified configuration. You set SSO up once and it'll configure it on all of the different, uh, interfaces.
You've also got multiple deployment options. It's the old VIDM stuff, except it's been changed to be a broker. It's the VMware identity broker, and it's been embedded in all of eight.
It was embedded in vCenter, uh, as a broker. It doesn't have its own identity man identity provider stuff in there anymore, like VIDM did. But it can broker connections to other things.
And so you can use the embedded one in vCenter. You can have an external, uh, you can have an appliance deployed as part of VCF or you can have an appliance cluster. So three, three different appliances deployed, however you want to do that.
0, and some of that is actually programmatic access to the role-based access control systems, which has long been asked for, long been needed so that people can write stuff to automate these things. Uh, you don't have to do weird, uh, weird stuff in the back end. There's standardized interfaces for it.
So that's what I've got for you guys. Uh, we publish all of our, well, we publish as much as we can. Anytime I run across a, uh, something that could be public, I've been putting it out in our GitHub repository.
Um, and whether you believe in QR codes and their security or not, well, here's a QR code, and it's doubly bad if you, uh, swing that way because it goes to a redirector, which then goes to my GitHub, URL. But, uh, um, yeah, you can take it out on me and explore some sometime when we see each other. And that is my, my deal.
Thank you folks, and security and trust. Thanks, Bob. Hopefully you and I can catch up again sometime soon for a, uh, drink.
And, uh, and Emil Bob was one of the delegates at my very first Tech Field day event, so we kind of miss him from being on the delegate side. Awesome to hear about that fairly consistent story, right? Keep things up to date.
Thank you very much for joining us. This has been an awesome series of presentations around VMware Cloud Foundation nine. If you missed any of the presentations, you'll be able to catch up with them very shortly on the Tech Field Day YouTube channel.
And of course, continue asking your questions in the comments in there, as well as interacting with everybody across the social media platform. So thank you very much for joining us. Have an awesome rest of your day.
Okay, just in the demonstration, um, we're gonna show full support of a modern mainframe CICD pipeline. Uh, we're using IBM, um, an open source based DevOps stack. Uh, we will show how quickly it is to stand up and shut down a pop-up, uh, virtual mainframe in minutes.
Um, we're gonna showcase the fast track and snapshot and reset an instance to, to show you how quickly you can recover and repeat your testing. And, um, we're also gonna show, um, bit of Ansible and it's, and that's all about, um, improving automation and empowering the teams with self-service operations. And just quickly, the, the demo application is, is the similar ones we showed last year.
Well, same name Next Gen Bank, and that's a web-based ui. It's using zero s connect, uh, to the backend, and it's got a mixture of our old friends cold kicks and DB two. Um, just, just so you understand, the, the backend for the next gen bank is running on a popup in dev test.
In a real world example, that would be, it would be production on a mainframe for, so you get, you get the idea of what we're to show there, so into, uh, the demonstration. Um, so before we start, the first thing thing we need to do is stand up a virtual mainframe environment to use. So we're gonna invoke an instance of the popup mainframe or pop up as we call it.
And you can see, um, we're actually standing the exhibition up in the Azure cloud. As I said, we've got the two types of pop-up, as you saw on both sleeves. Um, one is for the X 86 hardware and the cloud, and the other is runs on Linux one.
And Linux said, uh, for the reasons that we've discussed. So they both provide the same ability to provide a virtual ZOS on demand. And for Azure, it takes around nine minutes to install.
So now we're, we're I ping logging onto a famili familiar TSO, and we're getting into ISPF in a safe, happy space. So, um, now standing up a popup Z edition, um, this is actually a lot easier and quicker to install. Um, apart from us having to sign the license key, do we like to protect our ip, but it's literally running a couple of commands.
And then again, um, you can just log straight into TSO, um, and, uh, you see there, and again, exactly the same ISPF. So now, uh, now we've actually stood the environment up. Um, we are gonna, um, show you how we're gonna make a change.
So, uh, you could then install your applications by migrating that data and config, or if you've already done that and you've, and you put it into Git, then you would just check it out and build it from Git. But here, um, we're showing, um, we're showing our next gen bank system, um, and, and, uh, we've built this sample, this sample application. Um, and we're gonna show the trans customer transaction history here on the UI in the sending order, um, oldest first.
So we're gonna show, um, there's a new request in from a user who wants to see that changed around, which means the transaction history needs to be sorted in descending order. But before we make the change, we are gonna show you, um, how we can take, um, a snapshot of the entire Z os environment so we can return to any snapshot with the self-service capability. And so this means you don't need to worry about potentially breaking the environment, um, to do this.
So this is just us literally, um, checkpoint's done it lit. It literally takes a couple of seconds. Can you give it an arbitrary name to run the checkpoint?
Sorry. You can give the snapshot an arbitrary name. Yes, You can.
So I thought I saw That's what's happening in that there. Yeah, Yeah. So you can give it a name and then you can, that goes into a database.
So you can then choose which one you wanna go back to and just label them in a, in a sensible fashion. Yeah, Me, I like to label them just a random string of, of time code numbers down the millisecond precision. 'cause that really is useful.
Later on, You need to get out more. Yeah. Can you name it, Steven?
It Is Next, next time, next demo would work for With a PA Anyways. So here's our ZOS delivery pipeline. Um, indeed, any player pan line pipe pipeline, excuse me, you're planning to adopt will run on a popup mainframe.
In our example, we're using a standard IDE to do the development. And then, um, we're doing a series of build and unit test steps before deploying the code and running system tests. Um, of course, there could be other phases in your pipeline.
Um, there could be, um, there could be the security verification, but here and now we're gonna show the code chains, and the first time we do, it's gonna be in VS code. So the developer checks out the code from the GitHub repository, and then they're gonna modify the query to retrieve the rows in descending order, then commits and pushes the code back to the GitHub repository. And then by checking it in the CICD pipeline is automatically triggered by the, by the code check-in.
This pipeline uses GitHub actions, which in this example, builds the code using the I-B-M-D-B-B facility. And then it's conducts, uh, a series of unit tests using the open source tool, cobble check. And you can see the results of the unit tests here, which have all been successful.
And then it's gonna push the compiled binaries into an artifact repository. Artifactory. Um, these binaries are then deployed onto a different ZOS instance using IBM deployment facility wie deploy, where we're gonna run integration tests using the Glasser open source testing framework.
And unfortunately, you can see the Glasser test packs have reported an error. Um, and you can see the failure there. And looking in, in our original ui, we can now see that the balances are now blank.
As it turns out, the developer has overlooked some logic, which was there for testing purposes. In situations like these, it's very used to where, go back in time to a previous state, and we start from there. So again, we're gonna use them fast track and very simply, the developer just can run a command, um, to rewind the entire ZOS system.
And we're now back to the previous state, and we can see the transaction history as it originally was in ascending order. Um, so now we want to go and fix the logic error, and this time we're gonna use IDZ to do the, um, development. So they can choose their own development tool, or it could either be an RSPF if you wanted it to be, and you could trigger the pipeline manually.
It doesn't really matter. Um, so now the code has been fixed correctly, and we're gonna commit the changes back into GitHub, uh, which triggers, uh, the pipeline again, and the pipeline's gonna run again. And this time, uh, magically, uh, and for the developer's benefit, they've all, they, all the steps have passed.
And now if we go into our ui, we can see the order of the transaction history has been changed to support the user request, and it's been successfully developed and tested, and the valid data is now in descending order. So then what would happen, right, because this is still in, so is, is there a way to automate, I don't Even, correct. Yeah, so that pipeline, so that pipeline was just handed in the beginning part of, uh, the developed unit test process.
So in a typical DevOps, after that, you could then use exactly the same pipeline, uh, to promote, say, into a system integration test that could be in a physical mainframe using the same exact same pipeline as software using db d deploy. So we help organizations do their end to end, uh, route to live DevOps. So you can use this where you're doing, where you're repeating frequently, and you are recompiling and rebinding.
It's much better to be doing it on a virtual popup than using, uh, vital, um, you know, MS U on the physical mainframe. That's a really great point. So it's, so really if by using this, using this technology, you only the the last compile would need to be on a real physical system, because again, that's one of the license stipulations.
You, you must, um, only run code that you've compiled on a physical mainframe, not on a popup, but the previous 20 compiles would be on a popup at no cost. Yeah, you're getting in terms of your msu And Then things like user acceptance testing and performance testing presumably goes on the final l par as Well. Performance testing, correct.
Um, would definitely be, because otherwise your hardware emulation, it would perform differently. Um, so you'll be comparing apples and pairs, but you could use popups for doing, say, SQL performance and seeing how queries are running. And you could see it going faster and faster by, by doing it again and again.
So there is some performance tuning you can do, but, um, just understanding what performance work that is. Um, but yeah, we've, uh, you could have, uh, you know, you could, that you could go straight through to live and it could be a final approval before it's promoted live using the same DevOps tool chain. Yeah.
So you can, you can do that. Um, so you, you, you saw how we deployed a mainframe code change using automation, and now we're just gonna show you how you can streamline operations, um, and simplify management using Ansible playbooks. 1 release.
And so we've done a lot of work here with popup, um, to help clients, uh, simplify the management of them. Um, and you can, you can use an existing Ansible orchestration node, or you could actually run it on the popup if you're completely new to Ansible. So we, we've got the, the node, um, on the popup, and these come with a se popup comes with a series of Ansible playbooks, um, that are ship, ship with a popup.
And we also make them available in a GitHub repository we give to our clients. So we're developing all of the time, and they can just take new versions or take new playbooks. Um, so in this one, so, uh, you don't need to have any raef skills or, um, knowledge to better use this.
You could just use a file to put in the user name and the playbook would, um, do the rest. So here we're defining a, a new user, um, a new starter called, uh, Trump D and, uh, they're just logging onto TSO. Um, we've also, same as creating, we can remove users.
And this is someone that's decided to, uh, leave us and join someone else. And we run the similar, um, playbook. Um, Biden Joe is leaving, found pastors new why and Joe ever A running application.
So it's, And so there we go. So just, that was just a very quick example, how we can put, put the, the operations into the hands of developers and that using Ansible playbooks, those can be joined up in other DevOps automation pipelines. So your creation and remove user could be joined up from your ServiceNow, whatever and be through end to end just to find operations.
Um, shutting down popup, um, is, uh, is really straightforward and easy as well. Um, so it's a bit like, um, wanting to tell your children to switch the lights off when they leave the house. Again, users can shut down, uh, the popup in a very straightforward way.
Um, and that is great for, um, not leaving environments idle and, um, just, uh, help meeting your sustainability objectives. Alright, so just, just to recap, um, what you've seen, uh, I'm gonna return to the pipeline diagram once more. So what you saw is a, is a fairly commonplace and simplified application development process.
Um, and this has all been running on the popup mainframe environment. You can also use the pipelines to install full applications on demand from Git. And we work with our clients to do that, to put their, their applications.
So if they just need to, um, uh, create an environment on demand, they can pull the application out and maybe the batch also from installing GI and Artifactory and produce that into an environment. And you can also use the pipelines, um, to perform DBA kicks and IMS like admin tasks. Um, so whereas before you need to page out to other members of the, of the mainframe team to do specific work, you can have the pipeline do that, um, do that work.
So that really empowers the developer community and gives them the freedom to get, get on and deliver. Um, and this, and within project teams, if you can reduce the project team size down to one or two, that's massive. We're gonna reduce the costs of, uh, development projects.
You saw how quickly we installed a popup and how straightforward it was to bring a brand new technology stack, um, up and running and the opportunity to completely modernize the way you work. Um, and that wouldn't disrupt any other users in the organization using existing dev test LPAs 'cause that that can be a challenge to actually install new software and do new things in a, in a, where resources are really, um, at a premium and you just can't also find resources to install software. Um, we also saw how easy it was to checkpoint and roll back.
And this provides a powerful, resilient way to test out changes without the effort of delay of environment set up work. And we showed you, we, we pretty much showed you app dev reimagine. As with a popup, it's easy to begin your DevOps journey from a standing start 'cause you get all that software in straight away in the, uh, the immediate install.
So, and then that was from an app dev perspective, but I think popups and we worked with a number of clients to remove technical debt and either doing code refactoring and batch refactoring. Um, because it's very straightforward, um, to just keep on undertaking tasks. And if they're not working, you just re rewind that out and start again.
Um, and, and quite often it's very difficult for organizations to decommission old software and con config. But if you know you need, uh, to get output of 20, uh, 30 results, um, you can keep on taking away until you still get that same, that same result and just reducing down your environment. Another, another key, uh, advantage of popup is by using the modern tools and IDs you make the mainframe accessible to non-green screen users.
Um, and that's, that's really, that's really helpful because there's so much other knowledge in the enterprise, um, that don't have mainframe skills. They could be understanding test automation and you can use those skills now to by using the, the glass of testing framework and bring that other knowledge into mainframe without actually having to hire mainframe specific test automation experts. So it really, it really opens up, um, the, the mainframe to, to other users within the organization.
And that's gonna further drive down costs if you could use those, uh, those other commodity skills. So There's, there's, there's bit significant movement in, as far as I understand, in, uh, among main framers towards DevOps. Mm-hmm.
Longstanding, I think it's appropriately methodical and cautious as opposed to what I might call the Silicon Valley approach of let's dive in and find out later if it's problematic. But my point is, um, that that's still within, let's say the mainframe paradigm. This is a breakout from that.
It's a, maybe a safe one, maybe it's not a breakout depending on how you define where the line is. 'cause you're emulating, you're, you're, you, you're, you're, I feel like you're really holding the, the, the frontier tight. That said though, um, aren't you encountering this sort of cultural issue as you, as you address this real problem, which is, you know, that that all sounds, I mean IIII understand that you're allowing non-cloud, you know, on-prem, you know, uh, IFL and, and LinuxONE implementations.
But nonetheless, this is now, like a lot of these examples are really exciting to me. Yeah. 'cause I work a lot in the cloud native and, and you know, DevOps spaces, but I could see it being rather alarming.
Um, and among a lot of your clients, and I'm just asking about the cultural clash And with anything modernization, DevOps, there's always that challenge. So what is great about this is that you can put it in and then one or two people from existing forward thinking application team can go and do something really new and groundbreaking. And then it's all about playing that back to other, other teams, showing them what they can do.
And you know, I think deep down people always wanna work smarter and better. So if they can see making their job easier and taking out a lot of repetition, they will want to do it. But as, but as you say, you know, there's always, we often come across lots of naysayers.
You can't do this and it's hardware emulation. It, it is not the same. Well it looks and feels exactly the same.
You're running the same code base, go and show some progress. And once you've shown it and played it back, everyone wants it. And so teams are bending over each other backwards to get hold of it.
'cause their jobs become, you know, there's so much, a lot of mundanity about running bits of scripts and tests and all these sorts of things. If that can all be done by the technology, you can do deliver so much more change. So I think it is, so, you know, you do, it does have to be sponsored.
It does, it does have to, anything with DevOps has to be sponsored from the top. So funding does have to be available. That's what I was saying.
And it does need to be change managed. It needs to be change managed. Like anything that doesn't go away.
But I think if you can show real tangible results, um, and then that's, that's the breakthrough when other technical people go, whoa, I want some of that. And then you're there. It's, it's, I'm with you on most of that.
It's that. Yeah, it's, it's passing over that threshold. 'cause I I, I can see you pitching to management dev, uh, app managers and so forth and they're just eating it up and then there's that part of the process that is not necessarily visible to you, but they're going back to the team and they're saying, I hear something and then what I call the gum snappers, which are the, which are these technical folks are sitting there just going, oh, well yeah, but here's the five things that I need to do every single day that obviously this is not gonna be able to do, is gonna do poorly.
Like the, the naysayers that you don't necessarily get direct access to if you are, if it is being like change management and if it's being pushed through organizationally, then I hear you that you're starting to show examples and these gum snappers, compatriots are sitting there doing, look at all these things I'm doing and there's jealousy and there's, there's that, there's that acceleration. But I, I feel this, I sense this potential resistance in your initial pitch, in your initial value. I think that can be helped by having younger members of the team that have always worked in this way.
So introducing these more distributed type skills into the mainframe younger, you know, so, uh, Gary was in their twenties talking About as a feature pick stuff Up very quickly, which is now quickly To all this innovation and stuff. Yeah. The gum snappers.
That's like, that's, that is a problem. That's not a feature that's a problem. That to some, to some, to some of, um, older members.
It could be. But as we all know in the mainframe world, um, there is addressing that skill shortage. Shortage is imperative.
And yeah. You know, I think, um, You think if you'd, if you'd launched this product five years ago, there'd have been that problem. If I've been coming to share for years, you, you see this environment, the age profile.
Oh yeah. I dunno what the demographic data is. Share have probably got it.
But the demographics of this environment are changing. And I think what the more experienced professionals, let's call them that are, are seeing, and we've talked, I've talked about it in a couple of sessions so far this week, they're having to be less resistive to change. Yes.
Because the demographics, you know, whereas it was 10 old guys who could all just gang together and not do anything, can be very resistant to changes a block. Now there's probably seven of them that, but the three that have been cycled in over the last five years, they're younger and they're looking over their screen going, oh, what are they doing? That's cool.
And they're getting dragged along. So I think that demographic's changing, right? But I think that there's, there's two points to come back to, to your question.
There'll be different teams. So you get to the, the development team, they'll be all over this. The managers will be all over this.
The systems programmers will be all over this going, this is great. We don't have to do this anymore. They can look after themselves.
The security folks are gonna have kittens. 'cause they see, they see in their mind their mainframe data going off the platform. Mm-hmm.
Keeping it on the IFL. That's a, that's a big positive win. Big Game changing.
Okay. But Sunday I sat in an IBM closed door session and they're talking about simplification. How do we make this platform easier to manage?
And you've got these, all these old crusty guys going, no, no, no, we are not doing this. I was sat at the back of the room and I just wanted to stand up and say, it is not for you. You've just got to help make it simpler.
So the folks coming in beyond you can do it. This is not for the old trusty folks. Yeah.
This is for the next wave of main framers and mainframer developers. And this will make a huge Difference. And it's so funny you said that, mark, I was thinking exactly the same thing.
I was thinking the great thing about if they were to use a popup, then it doesn't matter if they, they stuff up Id MS or do something horrible, you just rewind it back out. It doesn't matter. So fortune really follows the brave with this technology and you don't need, and there's no, there's, you know, you sort of remove the risk.
It's Self-sufficient. And that's the thing that's, they don't have to go and ask. Yeah.
Steven, who's the head of mine from, can I have an lpa? They don't have to go to Jeff. Who's the data storage.
Right? Can you restore all those databases for me? Think press button, Don.
This is the conversations we had with VMware 25 years ago when it first came out. The exact same conversations. Uh, you know, you can train people to do open systems.
You can do all of these things and, and, and stop having to run inlines on a symmetric, you know, so this was, this was the same absolute problem we had with mainframes, but it went away because there was so much value to being able to virtualize this in being able to, to, to make a difference in the organization. It must Been too slow for too long because it cannot, it's not allowed to move fast and break things because it's too important. Important.
Yeah. Well now we can, but this, break it as much as you like, 'cause you can just restore afterwards. This this allows 'em to just break it.
I mean we, we've got youngsters in the business and we say we give them their own little l pass, but we back them up ourselves. We haven't got all this technology, but we say to them, yeah, if you break it, you fix it. And by the way, if you want to restore it, that's how you restore it.
Yeah. You've just made it really easy for them. 'cause I mean, I know this is a DevOps play, but for me, this is a great systems programmer training tool and technique, techie playground for it.
You, you also have the other end. You, you talk about the old crusties and, and what happens you, because I'm assuming you can back this up on a daily basis. Do a backup on a daily basis, a snapshot on a daily basis if you wanted To.
Well, you can, you can, yeah. You can back it up in multiple Ways. Yes.
What happens if, uh, if all of a sudden the main database is gone catty, wpa, you could bring that back from there. Maybe even a ransomware attack comes into play, all of a sudden you're bringing that back using that snapshot and you're back up and running within, uh, half, one fifth at a time. Then if you had to deal with the ransomware.
Mm-hmm. That is a future use case I've been thinking about on how you can, um, where you can, um, uh, you can back up, flash back up all of the, all of the volumes and then you can create copies onto popup from the flash and use that to, to restore. And particularly for production fix.
'cause you can keep on replaying scenarios that way. So I've been thinking about that. Um, anyway, let me, let me wrap up.
Um, we focused on the technical tasks in this, um, with the demo. Um, and, uh, but we can see the potential benefits of using this. And we've proven with clients that there's been a 400% improvement in time to market using this technology by doing this early testing.
Um, and uh, it's great for CIOs, um, sustain sustainability initiatives. We can shut down these environments and one of our clients on, uh, running the environments in Azure just by having them down 12 hours, hours a day, save the license bill as well. So it has a sustainability and a cost saving if you're running in Azure.
But again, switching off, switching these environments off anywhere is pretty new concept for mainframe. Um, so, uh, yeah, we truly believe that popup mainframe revolutionized mainframe delivery by providing teams with a immediately available fully functioning mainframe environment. Um, and just reproducing more of them and to meet your use cases becomes really straightforward.
And as I said, I think it's a, with what we've done with Fast Track is uh, definitely a game changer for environmental environment management and environmental management as well with through sustainability. But you very much.