Taking DevOps to the Next Level | Predict 2023
At Predict 2023, Techstrong CEO Alan Shimel and Techstrong CTO Mitch Ashley along with DevOps leaders John Willis and Damon Edwards, will discuss how organizations can make real, measurable impacts to the business, emerging organizational models to ensure collaboration and, most importantly, how to communicate those wins.
Transcript
Welcome everybody. I'm Damon Edwards from pagerduty. com.
So we're live in Boca Raton for to Tech strong. And this is predict. Yeah.
So Damon, we've been sort of doing having these conversations for many years. Imagine my crystal ball right now. Yeah.
There you go. So give us your sort of outlook on what what are we looking at? Like well we might do a devops cafe episode.
That's yeah. Yeah inside joke for that. I used to watch our podcast but it's not dead yet.
Yes. No, so yeah devops predict. I mean, I think Alan wants to talk about you know, how we've seen the future of devops evolving and I think you know my theme for everything for for 2023.
I think it's My mind go somewhere between a hangover and a like Boa Constructor. Yeah, right and The Hangover beating that, you know, we had this tremendous party, you know in the economy the better economy business things skyrocketing and then you know, the party's over right and we got this got a process everything that happened and and deal with it. And now same I think the same in the technology side of the world, you know, we had just tremendous Go-Go, you know time wherething is defined by how do you go faster?
How do you do more? How do you do use these new, you know ephemeral Cloud native Technologies. How do you you know transform dude, you know digital transformation DeVos Transformations SRE Transformations and you know like that book and structure.
It's a lot to process right and I think and what we're seeing evolving in 2023 is organizations have to figure out how do we actually operationalize all this stuff right, you know for We had these kind of side projects right there was the the devops transformation over here the srev transformation over there and kind of at the fringes right and these new Cloud native technologies that we all, you know consumed and but those were kind of different Stacks somewhere else, right and now it's how do we bring all that together to sort of I would call it like Mainline operations and you know do the things that we know we need to do to have a you know, predictable low risk steady growth, you know high quality operations. And so yes, I call this either the I guess the hangover year or the the boa constrictor has to that's the process that giant thing that you know, it's funny, you know, you've been this, you know me being around us having conversations podcasts and all this is something that you've been bringing up for many years, you know, like we'd always sitting around talking about like software deployment and oh my good and you'd be like, hey everybody what happens after it hits. So this has been a thing for you for many years, you know, maybe now we gotten to the inflection point Of like in that today didn't listen to you because you spent a lot of time with SRE and like you it's been your gig about operations and I think we came we're looking at I think we're looking at the devops side of the world from an operations perspective.
Like it's yes, it's Dev a lot of devops conversation was Dev towards office. How do we launch this new thing? How do we get to kubernetes?
How do we launch this new digital? How do we you know, whatever it is. It's like how do we do the new and how do we do it faster and you know versus looking from the other side, which is how do we operate this?
Right? If you think about you know operations, it's the the history of success, right? It's yeah everything you've accumulated along the way as you've been the business has been the legacy of success the legacy of success.
Exactly. And and so now it's like, okay. Well, you know, everything has to work at once you can't have this idea where it's like, oh, we're gonna do the new let's just cleave this and just start a new team block everything else out and go make it happen.
This is like, but we can't do that because everything is still in this, you know, this this world that we operational world that we live in so, you know, I think you know that Is kind of a major a major theme that we're you know, that that I've been seeing and I think is going to is going to accelerate because there's always there people were being responsible but it was sort of a secondary concern to the Go-Go right now. It's wait a minute. Like, you know, we have to operate efficiently, right?
We have to conserve let's get the most out of our cash right? But what is interesting is they're saying we have to operate a fish in League at the most out of our cash. We have to finally bring the Auditors in can't hold them off anymore.
Right? We have to yeah, the regulatory issues the the control issues security issues. Like we have to clean all that up, right?
We can't say well, you know, that's that's that's in the future. But at the same time We see companies doubling down on their digital Transformations. Right one of those like you invest in the down times, right?
You know, they say unfortunes are made in the down times and collected in the up times. Yeah, and I think that message is is pretty strong where they're saying. Hey, we got to cut head count.
We got to control the cost because a lot of people were hiring two years ahead. Right? Yeah.
So now it's like we got to continue we got to get that back under control but it's not a batten down the hatches, you know going to hibernation mode. We see it as like companies saying we still need to go fast, right actually invest more right in the future now, but I think we're also hitting that limit where investing more in the future requires operational excellence operational. We optimize now, we're going to Optimum if you like like to cliche a history of devops.
Yeah, maybe we really are in the optimized phase now, I think so. Yeah. I think I think it's less about inventing a new future right and more about making the new future fulfill that we've already kind of built, right?
Yeah. It's not evenly it's not The whole idea of the future is is here. It's not just not evenly distributed.
Yeah now it's actually we got to actually distribute it evenly and I think you know on the operational side what's basting is we've had this extreme this rapid rising in true complexity right that you know complicated like an engine of a motor you can model it. You know, what you're gonna do if you change things and our system just to be a little more like that and now with the digital transformation World, we've pushed everything together and we're dealing with somebody else's infrastructure everywhere these, you know different cloud and SAS Services. We use we have, you know, we're encouraging people to remix and use API.
So now our user traffic is one for being mostly unpredictable to often wildly unpredictable. So, you know, we've arrived at assembling truly complex systems and that just means There's going to be more unplanned work because more unpredictable right predictable. Yeah.
Yeah, and at the same time we've sold I think ourselves this idea that we have to go faster. Right and we've raised the so raise the expectations within the business of how fast things should move and that's the normal now, that's normal. Right exactly.
That's the expectation. And also what I think to double down on that we've raised the expectation from users like everything should be always on always available. You know faster and Fast Response right that that from a business like the people you do business with should feel like they're very responsive to your needs.
I don't mean just website response. I mean like new features and you know, and and you know changes in things definitely things are broken, right so she feel very responsive and fast. So now we've got more complex systems and we've got a greater speed demands.
Yeah, which is means a whole lot of unplanned work just things pop up even in Project work. It's like we didn't expect that. We need to do this now.
So it's more complex. You've raised the sort of You know the bar of what can expect and it's like the elevator thing right? Like, you know, think about somebody going in the future and somebody complaining about going 25 floors and it took so long to get there.
Yeah, you know like right. Yeah, that's a funny point. So yeah, so that's and that's what so in really this and if you think about work unplanned work, right is the killer in most organizations it is that you know, it's the not recognizing and planning for the unplanned.
Right? Like it's like like the Dominic degrandis stuff like like it's the thieves the time thieves. Yeah.
That's right. Yeah, it's the not sort of recognizing that it's something that you need to try to get your hand like assuming it doesn't. Yeah just danger point.
You know what it is. It's funny. It's kind of like every time you come out with a new sort of Technology, you know.
Trend or whatever it is, right, like nobody thinks about the operation side of it. Yeah, because they're like, oh it's gonna fix that chef and puppet. We're gonna fix right we're gonna fix we just needed a source repository and a polyglot, you know operations developer person and then make a million servers dance.
It's and if there was a problem they check in the fix. No, it's in a million service. It's the antics of complexity right which is this deterministic view.
That was my biggest problem with chef and puppet not to go too far after reservation about Mark Burgess had tried to do it save engine which was his play was that chef and puppet and I think devops in general is deterministic view if we do all these things. Yeah, and we're so quick at repeating the throat is over the sixth floor idea like it like yeah, there's a danger in that because you you're thinking deterministic. Like it'll be like to your point which is the flag you've been running for you which is what happens which is always the difference between so development.
You know, it's a great point. I mean actually J. Paul Reed does a great job of a whole presentation about this idea, but when you're in the development side of the house, you know, it's writing code.
Does it compile does it not does it run? It doesn't know right? And if it doesn't you can find out why right?
So it's a very deterministic. Mindset that you're in I deliver, you know, I check it in it builds or runs or it doesn't and I can debug. Why don't run right whereas operations inside.
The house is completely, you know stochastic right? It's completely and you so you have to deal with the unexpected. I Love Actually quote somebody else charity Majors had this great.
I love it, which is like she's like operating complex systems or something is paraphrasing that part basically or you know complex online, you know Services, is it never-ending stream of seemingly impossible failure failure scenario. So I got like stuff you would never plan for yeah, you haven't and and going back to 40 to that going back to what they're talking about folks like and he's talking about Netflix. They've invested, you know, probably billions of dollars at this point and the idea of reliability, right?
He's like they don't have He worked there. They don't have fewer errors. They have weirder area.
Yeah, right. So so it's like just yeah that that the more complex our systems get the more unpredictable. They are which means human beings have to get involved in operating those those systems and our old method of we got these functional silos.
We'll open up tickets and Route them between them or just hit a button and we'll make it so well, yeah, so I don't make it so is is not reality. Yeah, right. We haven't been able to do that ever.
Yeah any other any other high consequence domain outside of technology and billions and billions of dollars, you know thousands of millions, maybe man years right a person years and haven't fixed that problem. Now, we're saying in technology World We're not gonna happen. So we're not gonna fix that problem just smarter than everybody else.
Right? We need humans to operate these things, but our humans are now completely overrun with this unplanned unplanned work and things grind to a halt take too long. And then it just it's effectively, you know, it's like the proper eyes and Sorry world is toil.
Right? We've created all this toil for everybody and now we're back to nothing can get done. Right?
And so I think you know part of big thing. I'm in working on this this year is pulling these different kind of threads together to say Hey, how do we actually go and attack the unplanned work? Because the classic Enterprise model of we open up tickets and then we've got this kind of pmo layer that's going to help route and prioritize things and remind you and push you on it.
Like that is too slow. It's way too expensive. It's even makes sense when you say yeah, I mean in the world we're in today, it was miserable and barely hung together.
That's right in the Legacy world, like barely was hanging on but in this new, you know X the new again the complexity of our systems we built and the expectations of speed around change and speed around customer responsiveness to customers, you know, those who can kind of process and handle that unplanned work the best we'll have a serious speed advantage over those who those who who can't right and Companies double down and want to really accelerate these digital Transformations. You know, that's going to be the rate limiting fact, right? 99 necessarily always unplanned, but you can think of us toil It's that or the lean sense.
It's the waste the Buddha that you're you're gonna crowd out all of the value adding transformation work that you want to that you want to do. I love in the Phoenix project. There's a whole thing where Somebody is trying to question.
It might be bill or Eric. I can't remember but the characters but it's like saying why is it going to take you 72 hours to do this? Yeah.
And is this like brilliantly Simple queuing Theory answer but it's not it's in sort of a Mom and Pop answer which is okay. Imagine this imagine that you have. Your 90% busy.
Yeah, and you got seven, you know, or you know what I'm my math. It's gonna be terrible in this but like you've got like seven different dependencies, right? And so each dependency is going to be in a queue of a 90% Yeah, and like it just adds up to the hours and that's the vision.
That's what Dominican did really good. It's about your point about playing Words. It's not just that it's unplanned work.
Yeah. It's and and it's the complexity with the unplanned work. Yeah, and then it's complexity of the dependency tree.
So I would do anything I would I would go into is interview. These companies and and I'd say how long does it take? You know, what do you do about that is how long does it take to do that?
Like 15 minutes? So like 15 minutes really right the real cycle time. I said, well, how do you get like authorization or file?
You know, it's like oh, well, I got to send that off and in the end, they didn't count that time. Yeah, so it actually took them 72 hours, right? But in their mind was 15 minutes and the way they reported it from a pmo or whatever.
It was 15 minutes. So you like this dark work. it you know, I think what's a what's yeah, and I think so.
It's really there's two there's two problems right one is our tooth solution they can say well, you know what two things need to address one is around the automation side of things right and it's not just automation for people think of automation like to deploy to go do something right but really, you know, I see one of the most important automation around Context right, how do I diagnose something? How do I get the health checks? And how do I how do I understand?
How do I how do I use tools to improve the context that is coming through to the human because we still have this sort of hubris of like, oh, well, I just need root access and yeah, you know some monitoring and some log access and like I can figure it out right? But literally you see, you know, when not just incidents any any sort of, you know, critical, you know work you need to respond either a either failure to man like an insan or value to man like a customer needs something right on opportunity sure having that understand that context is where most people spend their spend their time right from the signal some has to get done to the I'm trying to figure it out. You're trying to figure it out.
I think you check this. You think I check that turns out we check that something else, you know, we go around and around and turns out no we had to call Alan right? That's right, right.
So having so automating the ability to collect and Process that that context is a huge part of it. So it also you know, we see a lot of automation efforts. Focus on like kind of these little Atomic things at the edges.
So you need self-service, right? You need self-service to keep a lot of this stuff off of people's plates. But a lot of times you see around the edges what they're automating like, oh, I need a new laptop or oh, I need a new VM or some of these little kind of atomic Atomic actions.
Right? And I think you know, the next step is creating that self-service to do things but in a collaborative way when it's like, oh we knew we need to collaborate much these different these different folks, right? So actually truly collaborative work and the goal of that is to reduce that those coordination costs, right and that's people talking about whatever.
Yeah the academic side right looking at, you know, what does it take for multiple people to joint joint activity to accomplish some, you know, some common some common goal and you know, there's not a lot of there hasn't been a lot of attention paid to that people think about automation sort of like, how do I automate this process? Yeah, right or how to automate this person's something for this person to do their job. Faster not how do we use automation to make decisions and take action in a coordinated way because on a complex system with all these different parts.
It's you know, rarely one person can solve the problem never. Yeah, right. It's always like, you know, I got to bring in three or four large, you know top five Bank a major outage.
It's a war room for like sometimes a day and a half that right but these days least then you can say Hey, you know, that was a major right all hands on that. Right? But what happens when you log into the you know, the simple you go to the zoom call for the or the slack room for the you know, the P2 or P3 or P4 bug and there's 30 people in there.
Yeah, right. Like that's where it gets extremely corrosive. Yeah 30 people on a P4 call.
You've got too many. Yeah, too you're paying you how many employees that's all right, and because in half of them are just it's getting it's that everyone's in this sort of unplanned. You know, we're you know, it's okay mode.
It's okay. We like to think of our scientists and we are I mean not to go too far the Rother or even Deming but like we don't actually act like we don't apply scientific method. We we literally have these chaos interactions, you know anything that's going to mention is I think the best illustration of that complexity and again, it's large scale outages, but it's to your point it happens on P4 is even right but is John alspar's Capstone his master's degree.
Yeah took it took a couple outages at Etsy and just showed. Like all the stuff that interact. I mean he tried to create heuristics around it.
But the point was just reading that paper. I was like major outages at what the slack channel looked like what the responses were all those things. It's a real great illustration of Academia and a real world Etsy like what you're talking about like this is the complexity that we deal with and so yeah, if we can't right, I think we're just that's right.
You know, I think but yeah, I mean, that's a big so yeah, so when it comes down to what you're saying, hey, what do we have to operationalize like what you know, and by the way, it's not a boa constrictor. It's a python that swallows. Yeah.
I was wondering but yeah, the flow zoology is not our thing or whatever whatever they're that term is. Yeah. So yeah, so it's that idea that you know, so what you have to what do we have to do?
Right and and you know part of it is there's just plowing forward with the cloud migrations plowing forward with these new kind of Technology making these making the making the the new Stacks right that we were that we were building the default stack organizations. But in order to get that done that even get what it gets in the way of that is not having the operating model, right the old operating model of Highly ticket driven functional silos kind of adding sort of human, you know, kind of pmo pushing around it. Lots of all hands on deck, you know, yeah blast escalations that He's gonna do that needs to change right and you know, it's funny as you're saying this I'm thinking about like even Cloud native right Cloud native has put a stake in the ground, but it really is more about delivery.
And I mean, I'm sure that people are go hey, haven't you seen what's going on in these little Cloud native but like the truth about is most of the conversation about clanita were like how to deliver how to program how to use apis. It's like there is I don't know there is a definitive line of sand for operational the version the the pure operational version of what cloud native has done. Yeah, I think SRE to yeah.
All right, good point well as touched on that but I feel like it's a broader conversation. I'm not sure SRE like like the devops like yeah when devops started right? It was very it was you know, is it Chef or puppet or see if engine right that was original conversation, right, you know because it was like we all thought it was a deployment problem.
Right? Right, and then it was like no no, wait a minute. It's not an appointment problem.
That's just right Canary in the coal mine for this much bigger bigger. But I think SRE is sort of a it's definitely attempt. Yeah, just before I forget this is that I think you've seen this too is to the point you made earlier.
We're living in a world that has slam merged this new stuff with the old stuff. Yeah. So the biggest problem I find with SRE Is it's not pragmatic for a large bank that still has mainframes still has 30 old job applications.
It's still what running, you know, you know sort of Webster like well, here's and so yeah anyway, so and you come in and say okay. Well, we're gonna do air budget. We're gonna do this and they're like, yeah, I don't know that's gonna well, I think it's kind of like the problem.
It's gonna I'm going back the problem that the devops would have in the beginning was that we didn't really understand like the underlying recipe for it. So you just look at sort of the results. Yeah, and you go do this right and then it caused chaos because it was cargo culting sort of a little bit a little piece of or what just and I think a lot of the organizations that that had early success with the SR with with SRE or Divine SRE.
Don't really they haven't fully documented the conditions. Yeah. Well Google's not about in which Google's not a bank.
Well, that's the first thing I'd say to a back and there's also a lot of organizational principles and management principles as a business. Yeah, the way the way the way it's it's kind of like reminded of like, you know people like to talk about the Netflix technology side of things, right, but guess what the freedom responsibility deck. It's about the business.
Yeah, the business operates that yeah. So the the technology organization is just a reflection how the business where the funding where the people management where everything, you know, that's how the business runs. So, of course the technology organization is going to look like right but if you don't run your business that way but you try to run your technology organization that way we see this all the time.
It's just massive conflict, right because you're not actually looking at holistic system and I feel like a lot of the SRE today a lot of the SRE conversation is around looking at that that one piece of it. Yeah almost Like, you know, two up close. Yeah and not looking at those organizations saying what are they doing?
Holistically as a business? No, I agree that allow that and and guess what if Google was a bank right? They would organize themselves differently.
They would have been different. Yeah, but it they've still the same might have the same result. Yeah, right.
It's just you someone could say hey what we built a bank today and we built it along the same management organizational of things of you know, Netflix. Yeah, it wouldn't look exactly because business but it would probably get up probably clear. I'm not saying you can't do that.
Sorry bank. It's just like to your point. So let's bleed into the my you know, like yes.
Yes. All right. So we're talking and that's actually a funny point that we both didn't realize this but that we were just talking a few minutes before we got on air here and about like what are we going to talk about?
And it's it's you know, I think the yeah Wayne told people about automated governance and sort of yeah, you're working on because I feel like it's the same it's the same python idea, right? Like, how do we how do we consume all of this new stuff? Yeah, but match the actual needs of the businesses around that you know, so about for about five years now a little longer whatever I I sort of got interested in, you know, sort of what's more interesting than just devops and even operations and devops and and devsecops got what is interesting right like but there was like, I'm always looking at like what are the things that nobody else is looking at right at least from mice based world and I can't running these companies where I noticed audit was a mess internal audit external audit also but internal audit And and I propose a paper.
So I started throwing Topo Powell who is a Capital One and I proposed a paper that we would do for the Forum. You know, the Forum papers that mean you've been doing for many years and part of Gene Kim's dad. Yeah it revolutions.
I do Revolution. Yes Summit. Yeah.
So I proposed that we do this concept of a devops automated governance and you know in Topo was part of it and it was really the the prime objective of that that first paper in 2019 was to be clear. These are in Industry guidance papers that yes, I too Revolution gets bunch of Executives and people together and we've got this like, right 70 80 of now. Yeah, they're great, you know, so but the we have a tablecloth dysfunction.
Hey, Innovative people but so the goal of that was like at the highest level was could we increase the efficacy of tall of audit and reduced the toil? Right? And we created a paper that was a referenceable architecture of like this micro service and a container that went into kubernetes admin controller and it left all these bread crumbs of evidence, you know, like it's like and and it was designed to be sort of digitally signed immutable.
And and then I start that's where the conversation really started for me. I'm Krishna backing up even that had you decided to do that. Right because I think this is one of these areas where No one likes to talk about audit.
Yeah, but yet if you go inside an organization of any scale or any any kind of any any High consequence, you know domain it's like it's a hugely destructive. You know time-destructive. Oh, yeah.
No, it's okay. Can you yeah, no that might help people talk about that help. Why is this problem not talked about more and why is it such a big problem to solve Damon?
I'm glad you know so top Bennett, you know. Like an incredible mentor to me right? Like stopo lives it, you know, like it Capital One.
He was the guy I spent a day with him one day and it was always like teleport going to Milling that 30 people called Topo. What do we do? You know and it was brilliant.
But so I started as I'd go around and interview people I'd hear these things like the thing. I heard more often. It's like, oh we don't tell Auditors about that.
You know, we're not gonna tell him about kubernetes till next year because why and they're like because it's gonna increase all day like yeah, we spend 34 days a year on audit like and it's terrible, you know, they it waste all the time. We got to go back and forth an emails. We got to give us a kept hearing that so I kept paying Topo like what is this?
You know, give me the reality check of this like this world that I guess I'm hearing over and over and repeatable just like that one line. We don't tell order there's things they don't already know like that just seems dysfunctional for a top five bank right through the operating that way and then I dug a little deeper. So that's really where that started.
It's like. Let's sit down. Let's have a conversation about like, what is that problem and it's in in the core of that first paper.
Also was that we wanted to change what we call subjective at the station or subjective evidence because that Toil and low efficacy comes from the fact that the evidence that we produce is subjective. It's a service now record of I've gonna do this and if it's raining on Tuesday this might happen and then if all else fails go look at the sneak log or you know stick wasn't that popular but like go look here and I was like that just as an outsider that just seems like you know, Buddy who likes to build Automation and think about like the like our journey of like being early in on devops. Like this just doesn't make sense.
Yeah, so that's what really became the Genesis of let's write a paper where we create a model or prove out a model because remember was on that paper was taupe Topo was Courtney kisser. It was Sam guggenheimer from Microsoft. It was like this old John restitaski.
It was an All-Star. I mean I was sitting there. When they were on the Whiteboard, I was getting chills, you know, same green.
I was like, well Microsoft we do this and Dwayne Holmes who were in 60 billion dollars worth the Marriott Revenue through kubernetes and he started like inversion 07, you know Docker and they're all at the board. I'm just sitting back like I got a Wonderful Life folks, you know and and listening to him talk about attestations that we need this kind of, you know, in evidence, right? We need this kind of evidence at Microsoft.
Well at Marriott we have to have this evidence and it became a document of about 75 like a kitchen sink and one company would do all these. Yeah, and it was really well documented. We put it in a format.
We we control we we Define the gate if you will we Define the attestation how it should be stored. And so that's what brought us to that. So where how we got to that paper it started with me like questioning Topo about like could this be real?
Yeah, I'm saying absolutely. Let's start talking about it. Let me call John rosatasky it he's See, let's talk to Courtney over at Nike and like yeah, no, we're all seeing this and like let's make this this year's foreign paper because every year to Forum, we sort of get the opportunity to kind of come up with a new problem challenge as a paper.
Yeah, and that's when the after that came out my you know that sort of level of my conversation. Increased in the place. I went to pretty quick after that and he stood whole set of presentations about the Blurred and broken lines of Defense.
So I started so the thing I would hear this is like I go in a site and it's John come in like check out our devs secops that you've been doing this for years people coming to him and come look at our devops reference and you'd be like, okay, that's good. I do this. Well, I started getting calls the people started seeing me as the devs SEC Ops person, right?
And it's a John come in look at I that's cool. There's a lot of banks that are not doing that like, oh, he's you doing enrichment with Sony cue that's really cool. But then the thing that at the end we have this conversation, they'd say no.
No, we follow the three lines of the fence. And so the three lines of Defense if you don't know it's by sort of it's an ordered or you know, sort of framework. It's almost every bank and mostly highly regulated organizations work.
Yeah, or some model is that you have first line, which is basically the owner It's usually the tech the second line is somebody who is responsible for that risk. Your first line is the risk implementer, right? Like they're the ones that yeah, and then the second line is the responsible and in some ways, although not express this way.
My insight out view of it was they were the sort of The Interpreter between first line and in third line in general but is called different names but sometimes really nasty names but but is internal audit. Yeah, and so that this model of like we're doing devsecops and we're doing all this stuff, you know, and a lot of times my presentations I say like if there's one thing you take away from this presentation, which is it SEC is not it risk, right and we say that to somebody who's in like it risk. They're like, oh my God, thank you, you know because like solving the deaf Secaucus problem as it's sort of the Zeitgeist if you will of how we think it is today is not solving the risk, which is the second line and third line.
Yeah, and one last thing I said to see a day in my opinion, that's the most important missing piece. We solve the devops, right? You know again in general, right?
We saw or at least we've got the memos out about the devs. We saw the dev and the Ops to build the features in infrastructure, right? I'm not that we want right but we kind of weird talking about is I mean, it's similar to the self-service, you know for operations that we talk about is important to cut down that toil so you have enough time to do the things that you want to invest in and do I feel like you know, this is the one of these it's funny.
It's one of these things where The toil of audit the toil of you know, the evidence collection the toil of the remediations you got to do at the 11th and the efficacy right? We're not really say do it. We say we the amount of the amount of toil really that's pushed into the systems onto people by not kind of Shifting left or building that self-service.
I don't mean so, you know, well self-star like somebody like self audit to say Hey, you know, you know continuous compliance. Basically, that's right that story here. Yes, and that's interesting because it kind of feel like it's all you know, it's the same convergent theme that we're talking about earlier, which is you know, how do you free up the time?
Yeah, the people we have to get more. Yeah, I mean get more done and they're constantly being I mean toilet is a fancy new word for leans waste, right? And yeah, and I think that the point that I sort of clarity I had which was actually John rosatos at PNC really help me understand it's good.
John is great because he'll call me up like John, you know, how do I work with my Architects which is a whole another conversation Enterprise and I'm like or call me and like, you know, I I can't work with risk or you know, something like that, right and John is sort of like other people do this too. And but and then I realize you know what I think we're missing the point. In sort of devouts their secops is that we think we solve the security problem.
but in almost every organization since I sort of had this You know sort of ability to see this problem a little more clearly that we got the dev. We got the Ops. We got the devops secops.
Yeah, but we still are pre devops. The prehistoric with second line and third line so they don't like today in a major bank and I've now started to interview in second line people like yeah. I know John like there's no communication.
We don't know how to talk to each other. And here's the key point is and I got this sort of not on this particular subject, but I got this on another discussion had what Courtney kisser about one of the oldest Top Line initiatives is protect the brand Right and first line, you know second line is the translator the third line and third line protects the organizational business and if we're broken as bad as we were pre devops like if Devin hops are broken, we're broken we are broken that's and and going to my point earlier about the complexity of the speed. Right?
So it it barely hung together before when it was slow disconnected. Yeah. Yeah, right did you know more disconnected systems that tended more towards complicated than than complex right speak right speed was yeah this be expectations were slow the customer expectations responsiveness were extremely right?
Right. So the fact that it barely hung together then and cause a lot of a lot of chafing and a lot right and a lot of yeah and a lot and a lot of cost right? I think you know, it's that same trend of like why now, why is it why is why is why 23?
Well time to solve the unplanned work time to solve the you know, the the governance risk the GRC. You know right over the governance all the same. I mean, it's all the same issue right?
It's it's the the light on the Python's got us what got to swallow that. Yeah, and if not, then we're just stuck. Well, I think you're gonna see the biggest bifurcation of companies who were able to get this done and to operate in this way and and to you know be this responsive as fast as they can be at the lower right at the lowest price point possible versus companies who can't I think it's gonna be this is truly gonna become a competitive different.
I did want to finish the sort of initiative which is where we got to no problem. But is I mean what we went we got back in 2021. Yeah, and we tried the right new paper.
It turned in a book. It's called Investments unlimited. Yeah, and it is a story about a real bank that's fictionalized that basically is a bank that's about the fell in order in the banking world.
It's called MRI, but it's basically failed artery from the OCC who regulates Banks and how they have to go through this journey. Of changing that subjective. Yeah to objective and how they sort of create this very much what we did in 2019 as a reference Archer.
We tell a story of Phoenix project like story about a bank that sort of learns how to take what like sort of like subjective explanation of what they did for every delivery. Yeah, and turn that into digitally signed immutable evidence. A non tamperable to say like and and with the ultimate goal of zero day instead of 40 30 40 Days for an audit zero days.
And so now that book has become the thing that you can give to the book so you can scream to the boss all day like the Phoenix project. You say do we plus we got to do demos we have then you give them the Phoenix project and they're like, oh I get it. Well Investments on limit now has become sort of that book.
Now, you can sort of say hey we need to do a better job with internal audit and in you know, so second line third line even in the book, there's a point where we say. They that's a sort of the character the Jonah, you know, the the classic gold rating. Yeah model where they this guy Bill he tells, you know, he talks about like, hey three lines and fence can be solve this we can still have the three lines of Defense model.
We just need to do it a different way. And so that like where we stand right now is I think the door has been open. For people to better understand how to look what we did in 2019 very few people really understood what we were trying to say.
Right right you had to be and by the way most devops people are not security people. So it was hard selling them. Right but like the second attempt which is the investment book has put it in a storytelling way.
Which just go right? I always said that's the best way to teach anyway now you can basically tell you can see a story of what we try to do. There's a 19 what's is a very boring Road reference architecture of a narrative of a bank like hey, that's me.
That's I and I see I can so I mean that's you know, like where I think is to me we're at right now and hopefully that book opens up the door and there's nine authors. I'm not plugging it because I think we're gonna make money off it. I'm not any money off it but but I hope it's the book that sort of like gives a better attempt at letting the world see that there's a better way to deal with this whole sort of complexity and like, you know, yeah, So yeah, how much time we have left here folks?
Five minutes. Okay, it's good. So I think what other what do you think?
In 2023. What do you think, you know? Is the world comes out of covid right things changing, where do you see the devops movement kind of you know going, you know, are you still going to devops day or no?
It's Enterprise Summit. Like what's in here? What's on you're gonna be devout on GPT folks?
Yeah. I don't know. I mean there's a convergence of like like getting Quantum still a little ways off.
So wait till 25 or but but I think there are like a couple of like really interesting things molding. I think AI language, you know language models these yeah language was like gp3 gp35, which we're seeing that I think there's a couple of overlays that of interesting new. Convergences III, you know people think I'm crazy once we get past it that nfts and cat pictures, then we'll get to the real stuff.
So I think those two are going to be part of our our career or what we're doing. Yeah. So anyway, that's a short with a couple minutes left.
Yeah. Yeah. No, but you yourself you go into devops day.
Oh, I'm sorry Enterprise Summit. Yeah. I'm here.
We're back out here. And I'm going RSA. In fact, I'll be part of the tech strong RC.
I'll be speaking there and I think April and then we will have hopefully oh Jean said, there's not gonna be a London devops days devops Enterprise Summit, but we'll definitely be back in Vegas together and maybe we'll be that kind of stage together. Yeah, that would be yeah, so that's you know devops days. I'm hitting it hard and then we'll send a price Summit RSA Dev The Devout, you know text wrong version of sex up stays and yeah, how about you pretty much same thing.
I mean, I think that's, you know, trying to get some devops days this year devops Enterprise Summit the devops con. You're up to a great. Oh, yeah, and I miss those trash and remind me that I still tell him.
Hey John, so John still here then yeah looking forward to a whole, you know text wrong slate of sure. Yeah slate of content that we've got for the tech Stone folk run a good show. Yeah for the year.
It's good. It's good stuff and we've got some thumbs up from yeah our in studio audience. Yeah, and yeah, hope everybody enjoys the The tech strong conference predict conference and predict 2023.
I'm actually excited to hear people's predicting we've been so. Fixated on this. You know, how do we offer operationalize?
You know, how do we cure The Hangover of all of all of the Moon Go-Go time that we've had the last you know the last few years. You know, I think as we see that there'll be interested to see what other people's predictions are. Yeah as well.
So yeah, thanks a lot. Again. I'm Damon Edwards John Willis and enjoy the rest of the event.




