Evolution of CI/CD and Open Source Engagement with Dadisi Sanyika and Mark Waite at OSS Seattle 2024
Apple’s Dadisi Sanyika, CD Foundation governing board chair, and Mark Waite, CD foundation treasurer and governing board member, delve into the state of continuous integration and continuous delivery (CI/CD) in 2024, emphasizing the importance of addressing gaps in DevOps tooling and processes. They underscore the need for education and mentorship, particularly for new developers, and highlight the critical role of business involvement in sustaining open source initiatives. They conclude with a call to action for individuals to engage with open source, leverage resources like the Continuous Delivery Foundation’s reports, and contribute to the community’s growth and resilience.
Transcript
This is Textron tv. Hey everybody, thanks for joining us. We have a great conversation, very special conversation happening right now because we're talking with some of the people who really have been part of, uh, open source for a long time.
Matter of fact, leading the charge in many respects. So I'm happy to introduce d dc c the dc And Mark, um, the DC who was just recently elected chairman of, uh, the Continuous Delivery Foundation. Correct?
Yes. Wow. We've really, uh, we've really upscaled, you know, they talk about marrying up, though this is interviewing up.
Oh, no. Okay, awesome. When you're already, you know, up there in the, in the elite status of interviews on text, tv, mark, so I mark's from Cloud B.
So would you introduce yourself? Sure. Um, my name is Dice Ika and I am the, uh, board tour of the continuous delivery Ation still new.
So it's like Harry didn't, Haven't quite gotten that to roll out. Exactly. Yeah.
Uh, I'm on the Spinnaker, TOC as well, the Technical Oversight Committee. Uh, and I'm employed at Apple. Fantastic.
Fantastic. And we've talked to you many times before. I think last time we talked was at the, uh, CloudBees conference or the DevOps World conference, I should say, right in, uh, Santa cla, which is a lot of fun.
Tell, tell folks what you Do. Yeah, so I'm the community manager for CloudBees community. Means, in this case that I worry about the health of the Jenkins project as an open source project and how people interact with it and what happens in it, and how it releases and how it benefits et mm-Hmm.
Well, I imagine you're real interested, maybe even kind of participated in this new report survey that we just released, right? Just came out I think today 'cause we're recording, um, around continuous delivery. And of course inside of that is a lot of good DevOps and other things.
Tell us, tell us a little bit about what, what did we learn right? What came out in the new news? So it's the, uh, state of continuous integration and continuous delivery report of 2024.
And it's a survey of, um, about 10,000 developer professionals. And it's looking into like how they use devout tools, um, what tools are effective, what processes are effective, and what we learn from that is, you know, where the strengths are and weaknesses in the community and how we can begin to, as creators, open source community. Like what tools do we need to fill the gaps, right?
Mm-Hmm. And so if you see that there's a section where people aren't engaging with, um, particular CI tools or in the space in particularly, you think about like, how do I lower that area right? To those CI tools.
If you find that new people meet developers are engaging the tools, it's the same kind of process. How do you build the education strategy? You know, what kind of certifications can you put in place so that you can take advantage of that?
And so that information we get year to year, uh, from, uh, uh, oh, I'm gonna data slash Data slash data, Data slash data. And, uh, I see the data logo. So yeah, You had me at data.
Yeah, there you Go. For slash data. And, um, it's very useful in that context.
Yeah. So that was one of the things that came outta the report when I saw some highlights about it was kind of a trending down of adoption from new folks coming into the software industry. You know, I think overall still adoption is high and a lot of people using it.
Why, why do you think that is folks coming in? You, you're just talking about having some certification training. Is it, is it awareness thing or is it, you know, that's that's your, uh, that's somebody else's Cadillac, not mine.
You're Well, well, so okay. I'm, I'm gonna offer a theory. Okay.
The, the report is very wise in that it doesn't say a lot of why. It says a lot of what Sure. Yeah.
So, but, but one of the, one of the aha moments for me in reading the report was one in three, one in three. So let's think one third Mm-Hmm. Of the developer said, I use continuous integration to run my tests, b***h.
Okay? It was 20 years ago that Kent Beck started this thing called Extreme programming, where you run all your tests all the time. I remember, but we are still, two thirds of the community is not saying, oh, I do that.
And for me, that's, that's, That's kinda shocking to me. 'cause Right, I was, I remember, you know, extreme programming, fair programming, all that stuff, right? It's like, right, hey, just automate this, this run that every time we check in And build Friday, that's when we're gonna kick it.
That Was, that was how, how it was done and, and yet today. So, so there is, there is a very real risk that organizations have not yet adopted what to most of us seem like fundamental practices. Right?
It's What do you mean you don't run your tests every time you commit? Of course you should. Yeah.
But, but there are things that we can help and, and education programs, promotional programs, insight programs, ways to suggest you should consider this are all good things. Mm-Hmm. Right.
Because there is an entire group of people who have joined the software industry recently, right? And recently could be three years, five years, 10 years, whatever. And they can all benefit from hearing repeatedly the message.
You should in fact write tests, you should run tests, you should deploy frequently. The Dora metrics are reminders of that, right? There are all sorts of hints that those fundamental software practices are still really good practices.
Yeah. And just to add to that and the point that you made about educating people about the fundamental practices, meaning that's good practice overall, right? You wanna be sure that you're reinforcing that behavior, that you're giving people the opportunity to engage and learn.
And one of the things that I've been doing since I've taken over, uh, as as chair of the CDF is talking to, uh, universities, is getting a better understanding of how are we preparing our youth as we move Into, Uh, professional, uh, software development. Because what I want to ensure is that they understand the tools that are available for continuous deliver Mm-Hmm. And how this foundation can impact that, collecting that information and just getting the oversight that this is something to be in engaged with.
Not necessarily saying that this is a cause or this is a thing, but there is a set of data that says, okay, this might be a risk prompted the conversations, you know, outside Yeah. Of the CDF to say, Hey, how can we engage with community? Okay.
And so that's, that's the portion of it that I take away from the report, is that it's, it's still 10,000 developers that we've talked to. It's not the, you know, the grand universe, but it is a Great job. That's a lot of developers.
Yes, It is. It's a lot of developers just To get developers to fill out a survey, you know, it's like Exactly. While I'm doing my security work that I'm supposed to be shifting left, I'll fill the survey out.
Yep. So let, let me at, at the risk of being burnt at the stake, which I may be setting myself up to do, I think the door metrics have been fantastic. Help us to give us a benchmark.
'cause a lot of organizations I just need to weigh and say, are we doing things effectively? How do I compare myself to others? Um, I, I've come to the conclusion of my own kinda running development teams that sometimes putting internal benchmarks while helpful, you kind of forget about the external part of delivering it.
So is it how many builds that we deliver that's important? Or is it how fast effectively are we releasing code? Is it maybe there's a quality aspect to the frequency of, of delivering as well as running?
So it isn't about testing it every time. It's actually by raising the quality and security, that's what you're really after, right? Well, and ultimately there's a grand, I might even take it, take it one step further.
Okay. But Don't light any fires that matter. No, no, No, no.
I think, I think There's real Okay. Real, real merit to us reminding ourselves regularly that the thing we're trying to do is deliver value to users. You Got it.
Yeah. And, and tests and security checks are all good, healthy things. But our real destination is value to users.
And it, it's easy, it's easy for me to get distracted. I happen to love automated tests. I love test coverage, and I tend to get fixated or distracted on those.
You're the guy. Okay. Yeah.
And, and those kind of people are, are dangerous. Right? So the problem, Problem, don't put him on video, by the way.
I'm kidding. The problem with that kind of fixation is you can lose track of the intent to de deliver real value to people that matter. And that may be people who pay you.
Mm-Hmm. It may be people you're trying to keep out it all sorts of who's who should we be giving, giving the value to? And delivery is the thing, right?
If I've never delivered the software, nobody got the value. Yeah. Think about the value that something like Jenkins has created.
I mean, frankly, that's what a lot of the DevOps industry has been built upon. It's still heavy in use. That's what I use first.
Well, Hudson, then Jenkins, and you know, that progression, um, one of the first DevOps tools, when you think about that underlying technology is still supporting both innovation, new things that have come along, as well as things that have been operational for a long time. Yeah. That's an impact.
That's a positive impact. And It's, and it's good that we're reminded that mature things are not a negative, right? Mm-Hmm.
The fact that the Linux kernel is a nice mature piece of code is a very good benefit. Good point. Right?
The fact that the Berkeley kernel is a, is a valid, solid thing is a good thing. And, and so we like, we like stable, we like mature, we also like to evolve, we like to keep growing. Absolutely.
You know, with, with that maturity sometimes comes, um, it's like mass, right? There's this momentum that's either hard to stop and shift or, uh, just to change and improve. And that can be a, an advantage.
It can also be something you've gotta figure out a way to, I don't need to stop it. I just need to help nudge this a certain way. Is there any, my technical term, any nudging we need to think about for continuous delivery?
Continuous integration. What's that? What's that next Kind of gentle.
Let's, let's guide it this Way. Well, uh, Okay. Everybody in the pay attention here, we come with it.
We have an announcement today. No, I'm just kidding. So that's a great question.
I, I personally, um, as someone who is a task driven development enthusiast, um, and a Jenkins, another, I be able to get that on the record. Um, I, as I walk around and talk to people here, now I'm asking those same kind of questions. And what I find as I'm also talking to people about the continuous delivery foundation, but we going, what we're trying to make, um, the question becomes interoperability, right?
Mm-Hmm. You, you have this push, especially last year where so many IDPs introduced and there's a lot of concern, right? About supply chain security.
And again, this is the information that's in that same report, right? Like how we are engaging in this particular, uh, use case. It needs to be addressed, but making those adjustments impacts your door metrics, right?
Yeah. And so, getting to a point where we can be interoperable, we can start to talk about a common language for, uh, city, the sea tools that will give us this flexibility to be able to bring in new tools and try 'em out very easily. You know, reduce the amount of costs that are around integration.
'cause there's so much scaffolding that you have to put around integration as you Probably get. And so we need a better plan for interoperability, um, now. Yeah.
And that's what we're working on. I mean, that's what's important in the CDF right now. Um, if there is one reason to take a look at both the report and what we do, it is our using this information to bid towards interoperability and the neutralize it.
How do we use it to better ourselves, our own work? Yeah. Meaning use work, et cetera.
Yeah. I think maybe you and I had a conversation about like plugin architectures and re maybe revamping those things over time to, because you learn a lot, right? Especially as you scale things up, that's when you find new problems and issues with any technical solution and ways to do things better.
So I want, we were having a conversation before we started, and that is people's involvement in open source. And the, as you're talking and Mo took folks around the conference here and you're kind of getting a sense of what's happening and there's a lot of different motivations people have. Uh, ultimately there's gotta be something that's fulfilling about doing right.
Kind of a self-motivation. 'cause I wanna learn, I wanna contribute. What are you nearing something that's community?
I mean, you're very involved too, so what are you nearing? Yeah. So for, for me, I think the, the best long-term motivation is that my business will benefit because I'm involved.
Mm-Hmm. Now that's a terrible thing to say. I didn't say anything altruistic there at all.
Right. I was a, I was totally capitalistic in what I just said because It's an altruistic business of course. Oh, of course it is.
It is. No, absolutely. It's, We're here for the betterment, capitalism, mankind, Man, and people kind, except in this case where I, I'm a total capitalist.
And, and so the, for me, the, the crucial thing is when we detect those places where my business will benefit because I got involved mm-Hmm. Then all of a sudden my manager and my manager's manager really actually want me for the benefit of the business to be involved in that thing. And open source is a place to help others help me.
Mm-Hmm. And, and we rise together. So, so for me, I think the game there is, yes, it's great to have, oh, I wanna benefit mankind.
That's really wonderful. And I think that's a, that's a high powerful motivation. But the reality is business motivation has done a lot more for the open source world than all of the high powered motivation might have.
Right. The people, I was just listening to a talk from Sony group. They talked about the business impacts of their, their open source contributions.
They've been doing open source contributions for 20, excuse me, 20 plus years. Yeah. And with That much time, they've got Experience seeing how things work in, in open source communities.
So business is really cool. Now we love the the loan developer as well. Right.
There's nothing wrong with that. A six gun shooter. Exactly.
It's really cool. But practically Speaking, companies that choose to invest in open source do better. E Well, I, I echo a lot of that statement.
One thing I'd like to add though is, um, what I've noticed and what I've learned then in this role is that there are, I'm an engineering manager and an engineer. And so when I think about open source contributions, I, I think about the actual sitting down at Mm-Hmm. But there are so many people who are bringing so many other aspects to what the community needs and community involvement and discovering on product news.
And, and they are doing those things for business reasons and personal reasons. Because being able to advance your career because you, you know, you've positively and affected these commun communities is a real goal. I mean, and it should be an accept goal.
And I wanna help people do that because if you can do that and you can help the continuous delivery foundation, you know, get the word out, bring back the information we need to bring, build better tools, you know, that that interaction alone was really, really important to, we use. And a lot of people wanna do is just that Mm-Hmm. Okay.
There is a giving back sense. There's also a self betterment. Yep.
And let's say that was, face it, there's a resume builder to it. I mean, how many people I've talked to that I was, I was contributed to these three open source projects. I'm like, yeah, I used all of those.
Thank you. You know, I appreciate what we did there. You've been contributing for a long, long time and obviously you, you as well.
Um, how do we continue to, to recruit folks to be involved? Is it sort of a self thing that happens or are the things that we have to do work should do that help keep that the pipeline and people to work on projects? Because you know what, the number of projects aren't getting smaller.
Right? They're all, they're growing not years to either year. I think that's, there's two problems.
And you, you've mentioned both of them. And so I'll, I'll take those in turn. One, there's a lot of project or, and we are, the number of projects is not getting smaller.
So I do think there are a lot of people engaging and coming in and finding the to do that. Um, I think that, you know, how they learn about taking their idea into the community is to start a project. Mm.
And maybe, possibly, again, this is not me in any way dictating that this is what should be done, but perhaps if there was a way to kind of educate people about when they're in college or when they're in school and they're young about the different projects that are in line with their ideas Mm. And how to contribute into those projects. We get two things.
We get the experience in working in an old prob base, which makes you very attractive to, and then, you know, an engineering manager who's, who's developing it. If there is a young person who is out of college and they have a ton of spinner crew experience, I'm like, oh, you've been, you can work at old code. I can work with you.
Yeah, yeah. I, I can definitely work with you. But that's, that's one side of the problem is that education.
And then the other side is, you know, what problems are we solving and what's the next step in Those problems that we're solving? Maybe there's some form of kind of internship in college, an open source internship, I, whether it's documentation or testing or contributing some code or, you Know, Should we start a program? Like What there is actually, there is.
Okay. Right. Every idea is already been thought of.
I just think they're new and really good. 'cause I thought And They are, they are good. And, and that's the right thing.
So we are, we're seeing in, in, at least in the Jenkins project, we regularly see an uptick in contributions as the beginning of Google Summer of code starts. Yes. Oh, Interesting.
And it is, and, and what happens is the universities around, and particularly universities in in Asia and in China and in India are are known for letting their students know, Hey, Google summer of code is starting. You need to get involved with an open source project. So we'll see this bump in open source contributions from these students in schools.
Obviously someone has told them, you need to get involved to do this. And some portion of them choose the project I'm on. And they start asking questions.
They start raising, raising poll requests. They start, and, and many times they look like a first time contributor, meaning very inexperienced, didn't do this, didn't do that. And their learning process has thus begun.
Mm-Hmm. And that learning process. Now if they'd waited until they entered their professional career to do that, we would've lost several years of them seeing what open source was.
Oh wow. Okay. And they then can arrive at these new employers with an idea, oh, you know what?
It's not just proprietary software that I have to use. It's not just there is an entire world out there ready for me to consume and to contribute both. Mm-Hmm.
There is, it's amazing how much open source, I mean, you can, you could build a business on open source if you wanted. Oh, we have done that. A lot of companies have.
Um, was there anything else from the report that kind of jumped out that you want to highlight? I, we, I think we covered it. Beer.
Okay. I think you covered most Of it. I Oh, did I?
Okay. Okay. Alright.
I did, you know, one thought about, um, the folks kind of entering their career, to your point, um, how does entering your career as mentorship, right, not formal programs of mentors hanging with people who are doing the kind of work you wanna do. Who are you kind of seeing start to respect? Oh, that, 'cause you also learned your areas of interest, right?
I might be interested in open source, but I really love working with data. So I me go down one of these paths or I like the underlying in architecture of the tools, the CICV or whatever, IIV and Jenkins is my own. How did that, my professor in college said, there's two things you're here for, to find out what you're interested in, to find a way to go do that work, essentially learn how to learn.
And there's a lot of value to, to thinking about it that way. So. Well, and and you just noted that there are a number of layers of, of potential interest, right?
You could be, oh, I want to talk to hardware. No, I want the, the abstraction of the web browser. No, I want something in between there.
I want to talk about data and, and there is plenty of places for individuals to exercise their own interest and contribute at the same side. Mm-Hmm. Very good.
You know. Any, any thoughts? Uh, what's in the news these days?
One of the things on open source is this whole business source model and different companies or have shifted to that model. Not everybody obviously, I mean, with tons of open source that isn't that way. Any thoughts on that?
And maybe why that's happening or, but don't worry they'll be back or, you know, that kind of a shift. Are we seeing a real kind of momentum and change here of doing a mix of open source and business, uh, software licensing? Or not?
Not enough down that path though. No. Yeah.
I would have to say from, from my perspective, it's, it's not enough yet to, well, um, I I think seeing it, you know, you, you can't really predict or understand what was going on in that business to, to make those choices or why they made those choices. Um, but there is plenty of open source and we open source communities have a way of shifting, um, to realign themselves when something challenging happens. And you know, I think if we give them time and give them their space and also support them.
'cause that's the other side of this, right? The, you have to financially support these open social, that's, that's an, um, a big deal. If you're using a software and it's free Or You know, if it's, if it's free, how do you collect the thing coming, right?
Mm-Hmm. Um, and so there is that side, and I want to acknowledge that wholeheartedly. Uh, so that's why you go to work.
That's why you, you contribute to it. That's why, like you were just saying, the, you have, uh, was it the Sunny Creek? Mm-Hmm.
Um, that was contributing for years and years and years. It's seeing benefit in that because they, they are a part of the cme, right? They do understand what's going on.
And so, um, yeah, but you're still left with, you have to make a business model too. I mean, that, that shouldn't Change. Greg.
I I think that's really important. And sorry to interrupt. Um, but if I, to me, when I looked at, okay, so when somebody, if they make a shift like that, there's a why.
I mean, there's a reason for that. It isn't necessarily a philosophical difference. It oftentimes it's financial pressures looking to be sold, you know, packaging the company up, make it attractive in a different way.
Maybe the people we're trying to, to, uh, acquire us don't see open source as, as a positive in the business model or don't understand it. There can be many reasons why people do that. Exactly.
It's not, it's not a, uh, judgment on open source and that approach. I think it's what fits for what that business needs at that point in time. That, that's my read on it.
I know. So open source sustainability is certainly a hot topic right now because sustainability has to involve financial sustainability, right? Yeah.
We, we have to eat, um, phrase from a friend long ago as programmers gotta eat. Mm-Hmm. Right?
And, and it's the reality. We, we are still looking for what are the models that will make source, will make software sustainable and transit license transitions is, is at least one thing that's being explored and it obviously is, right? Well, It's been a constant big, we've Got a lot of organizations.
Yeah. Well, and, and even as, even historically, right? You think about the at and t and Berkeley conflict many, many, many years ago, again, was about, about a, an open source versus proprietary thing.
And, and so it's not that this is, this is somehow new, but it is, it is very much an explorations. What's what's it gonna take to keep this to be sustainable? And, and I'm the wrong person to critique any one of them.
I like a particular working model myself, and I'm grateful to be viable right now in that working mark. Mm-Hmm. So I wanna run, run an idea by you another, you might burn me at the state for, but that's okay.
I'll risk you. First one went. Okay.
Um, you know, I, I spent some time in the security world and the software person who's been networking in security is all software. And the evolution of the networking world was heavy, heavy on defense, right? Building defenses to keep people out and from breaking in or once they got in, moving around and getting access to things.
And then I think enough, enough attacks and successful break-ins occurred, people started realizing we're gonna get broken into eventually a priority. Have. So rather than pushing off the inevitable, let's invest in response as well as defense.
In a way, I think about DevSecOps kind of the same way. We put a lot into the left. Let's, uh, code scan, let's build more secure software.
And I think that's fantastic. Kinda like quality, delivering code faster is actually a good defense because it's gonna happen, right? It's, you know, your ability to respond to delivering a patch in hours and minutes as opposed to weeks and months, right?
Because we don't have that capacity. See, that's another reason why you want to be able to deliver frequently why you want automated testing to be happening. Because in those times where you don't have a choice, you've gotta, you have to have a short interval.
Or if you don't, there's a lot of point things associated with it. So should we gather, gather some tender wood and bundle and start the fire yet? Or am I on onto something Here?
Okay, so, so, so I I, I like how you phrase it. It might be sometimes people act like change is their enemy and, and therefore keep things as stable as possible, right? Oh, we wanna keep things as stable as possible, but that means, for example, don't update my dependencies, don't and delay those things because then I'll do them all in a big lump at the end house.
We know and the problem, right? The problem with that choice of acting like change is my enemy is that then when change comes, change really is my enemy then because I have to do all sorts of things. Okay?
Most recent security vulnerability in library things, I need to update it. But before I could do that, I must update all these other things and they bring a risk that I didn't want right. In that moment of crisis.
Good point. So, so shifting from change is my enemy to change is very real and I need to embrace it and make it happen as smoothly and as cleanly as I can. Is is a seismic shift.
And, and the report highlights that there are plenty of places where people have not realized that yet. Mm. Right?
And, and we know there are places where change really has to be done carefully. Life critical. I don't want firmware updates on my pacemaker, thank you very much.
I'd like it to like Hold that phone up to my pacemaker. Right. Whatever I have.
Exactly Right. So, so it's The modem put to my Pacemaker, right? But, but shifting towards change is real.
We need to embrace it and keep doing it, and by doing it often we actually can reduce the amount each change makes. Mm-Hmm. So, so I think it, it's a, it's a valid point there.
There's a cost to choosing to accept change as a frequent thing, but the alternative cost tends to be so highest to be frightening. Yeah. It's how do you make changes strength.
I'd get really good at it. Right, Right. And, and do it often.
But that means you're doing it often, Matt, What to be really good at serving the tennis. But I probably need to be able to volley that back after I You Guys heard of the continuous delivery foundation? What, what's that?
What do you think they might help you in some way? This is all a big setup For you DC Hey, and as a spinnaker person, I'm just saying you guys are just saying all the right things right now, it's, it's thing. Um, and, and I agree.
I just want to, you know, and not to take anything away from the point that you were making about DevSecOps, but being able to be flexible to react to an environment to change people is super important with Darla. Yeah. Um, and it should be easy and it should be kind of seamless, right?
And you should be able to put things in place that can monitor what's going on, the heat from releases to let you understand, oh, there's a problem. And that problem might come to hour four, hour six, hour 16, you know, and you still need to be able to make the change over our lab, you know? And so spot on that isn't just about DevSecOps, that's what this report is all about.
A report is, this is what continuous integration, continuous delivery, and deployment is all about. This is where you are in it, but you need these things if you're going to be effective in business strategies that will fall around the deploying software regardless of what you're deploying it to. Fantastic.
I I'll sign up for that. I agree with you for sure. Where can folks get the reports?
I think you have it probably on both websites or Yes, it is on our, uh, it's on the CD do foundation website. Uh slash cd, uh, reports. I've got, I forgot the, the link I filled.
Bad Better. If you Google it, it'll take it right? Just, just go to cd Do foundation.
Yeah. And you open up CD Do foundation. It'll the frame, you'll find a pointer towards that, that page and it'll take you there.
If not, look at look in my Twitter because I've a Flash Characters slash it's on my LinkedIn. I don't Know which way I go. There are lots, there are lots of places you can find that.
So I'm visit my league too. Very good. All right.
Well, did you see, congrats on, uh, your, to see your role as chairman. Um, that's fantastic. Look forward to, uh, your leadership and great things continue to happen.
I Am very excited about the opportunity. Um, I, I think we have a wonderful community. We just onboarded a new set of ambassador forwards, uh, that I'm very, very excited to work with.
Um, the staff is wonderful and, um, everybody is wonderful. Mark has been a mentor and a friend to me since I've joined the community, um, and has made sure that I keep myself out of trouble. I think I've been very, very glad that he was next to me, Was a very handy guy to have talk to you again.
Great conversation. Um, get involved in Oppi Source, you know, we all love to use it and there's many, many ways you can participate, so we hope they'll do that. Thanks again.
Thanks to everybody that's contributing and to help get us to where we are today with continuous delivery. We'll be back with more great conversations like this one.