The Future of DevOps and DevSecOps: Big Stories to Watch in 2025 – Predict 2025
As we look ahead to 2025, the landscape of DevOps and DevSecOps is evolving rapidly, shaped by groundbreaking advancements and emerging challenges. In this dynamic panel, C-level executives from leading DevOps and DevSecOps companies will explore the key trends and big stories set to define the industry in the coming year.
Topics will include the transformative role of AI in automating and optimizing CI/CD pipelines, the growing importance of platform engineering in enabling scalable, developer-friendly environments, and the critical need to fortify software supply chain security against increasingly sophisticated threats. With perspectives from industry visionaries, this session will provide invaluable insights into how organizations can stay ahead of the curve and thrive in a fast-paced, innovation-driven ecosystem. Join us for a forward-looking discussion that will illuminate the future of DevOps and DevSecOps in 2025 and beyond.
Transcript
On, on. Hey everyone, it's Alan Shimel, CEO of Techstrong. Thank you for joining us on our, I think it's eighth or ninth annual Predict conference.
This is where, you know, some of us put our necks out on the line and make some bold predictions about the year to come. And maybe sometime at the end of, next of the end of this year, we will go back, revisit this and see were we crazy or did we know what we were talking about? This is a keynote panel for Predict This year.
We have a whole day worth of predictions coming from, from really smart people. And this panel's no, no different. I've got some really smart people, much smarter than me to talk about what is the future for DevOps and DevSecOps.
What are the big stories to watch in 2025? com 10 plus years ago. DevSecOps burst on the scene and a lot of it's become a real thing, as you're gonna hear from our guests.
But there's also been a lot of changes, a lot of tumult in the last year, year and a half, as things like AI and platform engineering and software supply chain security have all kind of burst on the scene. And it's, it's pushing and pulling DevOps in ways we probably didn't imagine. Our panel today is a great panel to discuss these topics.
Let me jump in and introduce them to you, first of all, joining us, and we recorded this, and he was kind enough to come on late in the evening. His time is my friend Kobe Reiser. Uh, Kobe is the CPO at check marks.
Kobe, welcome. Why don't you give people a little bit of your background, though? Yeah.
Uh, thank you Alan. Uh, really glad, uh, really glad to be here. I'm the Chief Product officer of, uh, of check marks.
I'm leading, uh, within check marks. I'm leading, uh, um, engineering, uh, product management and security research, uh, for the last four and a half, four and a half years. Um, I am actually leading the, the tr the, the building, uh, the development and building of our, uh, chip marks one, uh, platform.
Um, our legacy product is an on-prem product, uh, and we completely shifted to the cloud, and this is what I'm happily doing. Absolutely. Thank you.
Thank you again for joining us, Kobe. Appreciate it. Next up is another friend of mine who's a frequent, uh, visitor on our tech drunk TV show.
He's Nick Durkin Field, CTO Harness. Hey, Nick, why don't you tell, introduce yourself a little bit Very well, and thank you so much for having me on. Genuinely appreciate it.
And, uh, look, uh, join harnesses Employee number nine, almost eight years ago now. And so watch it grow from, you know, a small, uh, startup in its alpha stage to, to now helping the largest customers in the world solve secure software delivery and, and leveraging ai. So glad to be on here helping with this, uh, phenomenal panel.
Fantastic. And thank you for being here. Joining us is a newcomer to our tech strong TV and tech strong event family, but certainly her company is no stranger.
It's GitLab. I wanna introduce you all to Sabrina Farmer, who's the Chief Technology Officer at GitLab. And Sabrina, first of all, welcome.
Thank you for joining us. I hope this won't be the last time you, you, this will be a good experience for you. We'll see you often on Tech Trunk.
Why don't you give people a little bit about your background? Yes. Hi everybody.
I am Sabrina Farmer. Um, as you say, I am the Chief Technology Officer at GitLab. GitLab is the most comprehensive AI powered DevSecOps platform for software innovation.
I have been here for almost a year now. Um, prior to that I spent 19 years at Google doing essentially production engineering and also infrastructure engineering. Um, really happy to be here, excited to talk about what's the future.
Thank you. We're excited to have you here, Sabrina. Thank you.
Last but not least, my friend Paul Davis, who's field CSO at what a collection we've got Field CTO Field cso, chief Technology Officer at CPO. That's, that's impressive. Paul, why don't you tell people a little bit about yourself.
So yeah, really humble to be part of this, uh, this panel. These are brilliant. So there's some real power players here.
Um, so yeah, I am a former Fortune 10 CISO slash soc ir, but also as described myself, I'm a reluctant developer, uh, program and head software houses and built software in 12 different languages. So I'm sort of melding that with business risk and everything to help, you know, push forward the vision of a secure software supply chain using jfr and integrating with many of my colleagues here, as they say, to create that secure software supply chain. So, very much sort of focused in that area.
So thank you. Thank You Paul, and thanks for joining us as always, and thanks to our friends at jfr. So, you know, guys, as I said, off camera or before we started, those who don't learn their lessons from history are doomed to repeat it.
2024 in 20, the last half of 2023 has certainly seen some churn, upheaval, tumbled within the DevOps DevSecOps space. Um, if I had to ask each of you, what were your, what were your big stories or big trends in 2024 that we think we should look ahead to going into 2025? What would you say they were?
Sabrina, you are the newcomer here, so I wanted to give you first, first dibs. What do you think were the big 2024 trends and stories that we need to learn from in order to look ahead? I think, you know, obviously the big topic, what everyone's talking about is ai.
And I think over 20, 24 people we're trying to figure out how to roll it out. What does it mean, what does it change? Everyone thought they needed it, but they didn't really know what to do with it.
And I think there was a lot of experiment, a lot of money spent, um, and a lot of lessons learned. I think what I, I'm excited about mostly is as you come to the close of the year and agents become something that's more of a reality, you really see the opportunity to apply AI to improve how people work, right? And I think that it took us a whole year to get here, um, and to really start to believe that it was possible.
But, you know, we are seeing people look at not just how to develop code, but also how do you operate the systems that you're building. And, you know, having worked in production engineering for so long and, and AI for, you know, even longer, um, I think that to see this reality is really exciting and really trying to get people to really embrace it is, I think what we have to look forward to next year Panel. What do you think?
Wow. I mean, a, I I think myself personally, it's, I'm starting to see glimmers of hope. Um, as a security person.
I'm a pessimist and paranoid. Um, so, you know, there are gaps there that I, that I, I wanna see better AI in the world of the actual supply chain as opposed to just the developer experience. Mm.
But I'm seeing now some of those coding agents helping developers are getting to a point where I can start to trust them. Um, but there's still a long way to go. And I think also from the perspective of regulations, I think we're just starting to see inklings.
Europe is scary because they put teeth under regulations. Uh, I, I'll be blunt, I think we need to do that in the US as well. Um, 'cause there's accountability across the board.
But I, I'll pass it over to Nick Fre. I don't wanna hold the mic, but Nick, for your perspective No, I, I can, you know, I think you're right on the AI side, I think one of the things also we've seen is that we've seen people now unifying on singular platforms and getting away from point solutions. And I think it was one of the things that we actually talked about last year, Alan, yeah.
Uh, was this was gonna happen, that people are actually starting to unify on platforms and they're, they're getting away from, from, from grabbing all these point solutions. And I think that was something we actually saw. And, and to good measure, right?
We saw people actually gaining a lot of value, gaining velocity, adding security into this, because now it is one, one platform versus, you know, having to bolt and spending the time, you know, bolting together and writing the glue code versus actually being part of a platform. And Kobe, that's check marks one, right? Yeah, exactly.
That's check marks one. We, uh, I fully agree, uh, we saw a lot of consolidation, meaning, uh, people are kind of do not want to run point solution, have multiple vendors, uh, get themselves and their, uh, developers and users, uh, and security people, uh, confused with. We, we solve them.
They want to, they want to consolidate. So we saw that we actually, this was one of the, uh, main objectives of check marks. One, have a one-stop shop for, uh, application security testing.
We also connected it with, uh, runtime in order to provide runtime insights. That's actually changing the way security is done on, on the left hand side in, in the pipeline. Because you can give, uh, you can give runtime.
You, you can, you can provide runtime context and then give more actionability and confidence in the results, uh, because, you know, it's, it's running in, in right time. Uh, I also agree with Sabrina, like, yeah, like 20, 24 was the year of, uh, okay, what do we do with ai? And, and, and I think that it's, uh, you know, I think that that, that, you know, a lot of our customers kind of came to us and say, okay, we know that we needed ai.
What, what do we do with it? So we kind of, uh, we kind of, uh, put in place, uh, um, strategy of, uh, protect, um, and we're protecting the code, uh, mainly on, on the developers and side. We have integrations with, yeah, we, we have like integration with, uh, uh, with copilot and, and, and tools like that.
We also have a tool of our own, which, which actually provide best security practices as, as code has been written. Remediation, okay? We're talking about pipelines.
We don't want to run the, uh, we don't want to run the pipelines 10 times until we get the we, until we get it right. So Remedia, AI, remediation advice, and also secure lms, this is more a 2025 thing. Uh, you know, we see people going more and more into open source lms.
I think that this is going to be the next big thing in 2025, and people will like to, to protect that. And a lot of supply chain, by the way, uh, we invested quite a lot of supply chain, uh, especially in malicious, okay. Kind of the SCA part is, is kind of figured out, but the malicious part isn't, uh, isn't meaning let's say if I'm taking, actually, if you use an open source, you're actually taking code from Stranger.
How do I know that this stranger didn't put anything malicious in it? So kinda, we invest a lot of research in that, and, uh, we're trying to bring this value to, uh, um, to, to customers. You know, what's interesting is, at least two of you up here, your companies are open source companies, right?
And so you're not getting code, you know, is it, is it from strangers? Yes. Is it from it, it's not so much from strangers, but perhaps untrusted sources, right?
Especially if you are maintaining a, a, a, a repo like Artifactory or something. But I wanted to return to AI for a second because that is the big, I think when, when people look back five years, 10 years from now, 2024 will be the year AI went big. It, it dominates.
But I think also when we look at 2024, it'll be the year that Gen AI went big gen ai, right? This whole, the idea of the co-pilot, and I think all of you have some sort of co-pilot type of functionality built into your products now or are coming out with them. But I think when we look ahead to 2025, gen AI may not be the big AI story.
I think, Sabrina, you mentioned it, a agentic AI may wind up being the real story, not just for 2025, but going forward. And I totally agree with that. Yeah, I totally that I think that's really the power.
I think, you know, the press likes to talk about the code, the de developing the code, the code aid, right? And I think that's true, right? But ultimately, that's still up to the software engineer, whether they accept it or not.
I think it's really the agents that are gonna unlock the power and really help us find the next opportunity. Free up your people so that they're really thinking about the next innovation that we should have. I have to say, I'm pretty surprised at how quickly AI has gotten into the DNA of not just tech companies, but the average user.
They're very comfortable playing with it. I think that's surprising. I do think with large LLMs really made it accessible.
And so I think we'll see this accelerate a little bit more in, in how people learn how to commercialize it. But really, 2025 is gonna be about the agents and how people put it to use. And I think to Paul's point, like the regulation is coming, right?
Compliance is not getting easier. You can't staff fast enough today because one, this technology's really expensive. Um, and so I really think this is what's going to unlock the power of what AI can do for companies and the users.
If I could Go ahead, Paul, I was just gonna say the, the, I as a geek as a techie, um, agent AI is really, really exciting for me because I've always won. I, I, I have a personal assistant, people know me. I wear little gadget on my shirt.
This is my personal assistant. It's an AI agent, right? But it's, I don't trust it.
But the thing that I get scared about is, um, I think we could see us repeating the same mistakes we did with ai, with Agent ai. The same acceleration path is coming along where people have false expectations around it, have these grandiose ideas, and the reality becomes, oh, actually we need better controls about where can't trust it. I remember in one situation where I was doing automation and one particular customer shut down everything because they managed to do a self-inflicted denial of service.
Mm-hmm. The agent ai, letting it make decisions by itself scares me. Okay.
I'm, it, I'm paranoid, but I, I think I, I, you know, as you said at the beginning, Alan, if we don't learn from history, we're gonna make the same mistakes. I think we need to apply the same disciplines we talked about. Like, um, LLMs being weaponized, I'm marketing weaponizing.
LLM sounds far more exciting, um, malicious. Um, but from the perspective of we are now realizing that the data scientists are developers and are being targeted, and that's the, the, the models, the ML SecOps model needs to align with the sort of the traditional SecOps. We also, and we are learning disciplines and stuff like that.
And so I'm sure everybody in this call is saying, but I think we need to basically make sure we, we apply some discipline. We don't set false expectations. And I don't know whether people agree with that, but I am a little bit concerned that I have high expectations, but I'm cautious.
Others might read that magazine and go, oh, let's do this. And we lose control. I have a, I have a fun take on it a little Bit.
And, and by the way, like this comes from, you know, and Harness came out to the market actually in 2018. It came out as the first software platform using AI to actually remove the worst part of people's jobs. And it wasn't about taking the best part, we didn't go after coding because that's what people loved.
We went out after all of the things they hate doing. So babysitting, deployments, waiting for tests to run, all of those things. And so it's interesting though is, you know, a lot of people talk about agentic AI actually mirroring human behavior.
And I actually think this is, is actually opposite. I think we are actually going to mirror agentic behavior. What we're gonna do is we're gonna empower people to do what they love.
I know that's the weird one, right? But the reality is each one of these agents dives down and does something specific, right? But if we're focused that on what we hate doing, right?
And all the things that, that, that, that, uh, are the things that we put off till tomorrow, let Theis do that, and now spend our time focusing on what we love. When you get someone who's locked in doing what they're passionate about and not having to focus on writing a terraform or a groovy or like working on all the extra pieces, let them do what they're phenomenal at. Now we're actually empowering our people, and it actually brings harmony amongst all this, as opposed to like having to be combatant.
So I think it's, it's a huge future. It's a huge opportunity. Um, and I'm really excited about what we're, what we're seeing in the agent AI space as well.
I think that the main challenge with Agent AI will be to manage all these agents. Yeah. Yep.
You know, you'll, you know, you will have, like, you know, you'll have an LLNI dunno, tens, hundreds of agents. You know, each developer will put in what, what, what each one of them do. And, uh, what, what do we, the, the sequence of of of, of what, of what they're doing.
I think that this is, Uh, well, you, you're just thinking about one developer to many agents, or one, each developer has their own agents. So you have many developers. One times when one developer has 10 different agents, right?
Mark Benioff, uh, spoke, I think it was just yesterday or last earlier this week. Well, by the time people watch, this was a few weeks ago, you know, and he said, we're all gonna have all of these virtual employees he calls them that will, you know, we may have thousands of them that are out there doing tasks for us. Some, some agents will be one trick ponies, right?
They'll do one thing, they'll do it pretty well, but they only do one thing. Other agents will be more general agents that are kind of alter egos for our digital presence. Other agents will be managing agents, you know, agent managers of other, I mean the, And so I, I imagine to yourself, just to troubleshoot an issue that comes from a customer.
Oh, yeah. I navigate between all the, okay, what, what kind of, what, what the hell is going on here? Uh, but I mean, this is, this is, this is the world.
We could be looking at it, and we need to, we need to put some order, some order in here, right? To, to, otherwise it's gonna run amok. I dunno, if any, I think Kobe, oh, sorry, Sabrina, go ahead.
Please talk. Yeah, I think Kobe makes a really good point, right? If you really wanna think about, um, unlocking the power, you should also think about the management of all of these things coordinating together and who's gonna create the controller for this, right?
And to Paul's point, like you still need the oversight, right? Automation has, you know, I've been automating duction systems for a long time, and I can tell you like, you can shoot yourself in the foot just as well as an agent could. That's not, that's not new, really.
I think it's just a new way to look at it. Um, but I think that Kobe's highlighting a really big important thing for people to think about as they start creating these agents and automating them, is you do need to figure out how do you coordinate all these things together. Um, I I, I agree.
I it's gonna be interesting. And I'm not even touching on the security implications of having agents running all over the place. This is why, this why I talked about control, not even secure.
Yeah. It, it, it, it is. But on the other hand, I mean the, the, the things that it opens up the, the possibilities, right?
Are pretty exciting when you, when you really think about it. And then, you know, and Benioff, and, and granted, he's a great marketer, right? Give the man credit where credit's due.
He is one of the best in terms of marketing. But when he refers to these agents, he interchangeably uses the word robot. Is an agent a robot?
And is, is a robot something that does physical task or is it also just a digital robot? Right? And, um, and, and once we start marrying AI to robots, what, what does that mean for our, the way of life, right?
Um, I mean, it's, it it's a brave new world in many ways, right? That, that this, And in some sense, you know, bots are kind of the same concept of agents. Okay.
Kind of. I think that's what he's getting at. Yeah.
We, we did have it, like we did have these software bots, but I, I, I think that, that the kind of the options are, are kind of the, the, the limit is the sky right now because, because, because of the, uh, gen ai which is behind it, uh, Everyone could be, I, I think you're gonna see an actually, an interesting turn. I think you're gonna see people overuse LLMs and overuse agents where they're gonna use these massively expensive things that, that, that do very basic tasks. It's back to the times when like people's, you know, like using this massive amount of ai when in actuality you could just be doing math, right?
So instead of doing creative, uh, AI doing that, We do automation. Wind up is a bunch of wallies just fat, colorful people on chairs. And, you know, the ai, we can't do math without a calculator, right?
I I, yeah, I, I I think people actually have to focus and realize, like, do we automate this? Do we do predictive modeling? Do we use generative modeling?
Like, and actually using the right tool for the job. 'cause I think right now, people are just throwing everything at, at Gen AI right now and, and calling it good. But in reality, that could be two lines of Java or two lines of go instead of a massive LLM.
And I think that's, that's some of the challenges. Well, well, you remind me of, uh, uh, I've met, uh, one of the DevOps leaders a few weeks ago and told me, you know, my job is to watch as much Netflix as I can, meaning the automation of DevOps should, should, should do everything. So, uh, what what you said about the, uh, agent AI reminded me of that.
Absolutely. So, I, I, I think, Nick, you said at the beginning, we should be using it for the, I, I like to say I want people to use to start using their brain, stop doing the boring stuff, right? Yeah.
Um, I think it's really fun that we're all saying the same thing, which is we need control. We need to set our expectations and roll these things out. I remember when I was on a manufacturing plant, there was this one robot, physical robot, and it could make seven different models of car, brands of car without changing anything.
It was so well defined, but it still needed people at the end to just do the tweaks, to do the things like that. That was God, 15 years ago, right? I think we got the same thing with this stuff.
And I think I, I'm kind of reassured that we're all talking the same thing, which is we need to have oversight. We need set our expectations, because otherwise it will run rampant. But the trouble is we will see people that are, um, like, um, setting their expectations the wrong way, you know?
Well, I, I think that's the story. That will be the story in 2025, right? E experimentation in excess in, in experimenting with this stuff.
But you know what? Just like in the real world, AI is sucking up our conversation here. We have do have a couple of other things we need to talk about.
One of them, I wanted a big, you know, I think a big emergence in 2024 was sort of the, the legitimate legitimatizing of the platform engineering space, right? And in many ways, I think platform engineering, first of all, it's not replacing DevOps, right? Yeah.
DevOps isn't going anywhere. But platform engineering is a response to DevOps, I think, where DevOps wanted to bust down the silos and have us all working together. That was kind of the original intent, right?
And what one of the outgrowths of that though, is that we just started shifting everything left. Give it on the developer, put it on the developer, put it on the developer. As I mentioned earlier, things we put on the developer was security.
I think we found out that they care about security, but they're not security people, but they wanna develop secure code. Another thing we put on them is build your own platform. They don't wanna necessarily build their own platform.
You know what, maybe having a silo for platform builders is a good thing, as long as they communicate with all of the other stakeholders, developers, testers, security, SRE right? All the, the traditional disciplines in there. And so we saw this whole platform engineering kinda concept rise.
And I'm glad to see that in speaking to most of you. Your companies are bracing platform engineering. It's no longer, uh, if us or them, it's, we're in it together.
Give, if you wouldn't mind let, well, Sabrina, we started with you last time. I'm gonna start with Nick this time. Let's talk about how do you guys view platform engineering, especially going forward here in 2025?
Sure. I think you, you made a good point. And then the way we actually referenced it, when we talk about shift left, people started shifting, the workload left.
And that actually wasn't good. And what we actually want is we hire really smart people and wanna shift the information left, give them the information, give them those, uh, results. The security scans now, not when it's in production.
And they have to go, you know, get in a backlog, give them cost information now, right? Make sure they understand what that change the infrastructure's gonna do now, not a month later when it gets into production. So it's about bringing that information at the right time.
It's also about making it easy to do the right thing. And it's about making it hard to do the wrong thing. And I know that sounds super basic, but it was easy to do the right thing.
The cloud wouldn't exist 'cause we, we would've made VMs in our company, right? So you make those easy paths to get people to production, make it extremely simple. But you put policies in place to make sure that everything that you're doing actually meets your security, your compliance, your regulatory rules.
And as a platform, the goal here is actually to create harmony amongst all these teams. Like, although the folks on this phone are on the, on this call, we actually integrate with, right? Because again, you have to, and what we do, what we don't wanna do is we don't want to have security being the team of, no, they should be the ones empowering this by writing the policy.
We don't be financed to be the ones of no, and, and cost, you know, coming back with a big stick and carrot, empower them to write that, to make sure that you're, you're meeting your budgets, make sure the DevOps teams can write the pipelines, but we're all doing it in harmony. So now it's an actual platform to bring people together. If you're buying a tool that's a stick to use to beat a different department, it's the wrong tool.
It's not the platform that you need. You need something that brings harmony. That's, I know it might be like a little controversial mm-hmm.
And maybe a little hippie. No, I, that's genuine. I think it goes back to dev, that's DevOps, right?
It's about working together, not necessarily that we all, all of us become DevOps engineers or DevSecOps engineers, but it's about, we all have our thing that we do, but we work together. So I I'm, I'm, I'm with you. Rest of the panel.
What do, what do you guys gals think about, about that? Uh, sorry, did you wanna Go ahead, Kobe? No, no, go ahead.
So the, the thing for me is, is you're right, it is, um, bringing together the teams. We have a lot of siloed, I've heard feedback that the data scientists don't trust infrastructure people to stand up the infrastructure in, in production. Partly because it's a brand new world.
It's, it's in, it's not just standing up a server. We have to have additional tools to see drifting, uh, compromises, new attack forms, et cetera, coming in. So the whole thing, we actually came with a term called every ops, because, you know, there's DevSecOps, DevOps, machine ops, ml ops, it just goes on.
I know Espina, you've got SRE, there's all this stuff and everything, but it rarely, I, I like it because I spend a lot of time working with customers, getting them to overcome those barriers and unify them. So we talked about security. I'm sorry, Nick.
I convert developers into security people, right? Okay. Bad.
In fact, I already disrupted, we were cube gun and this poor guy is sitting there, uh, we're having a drink. And I said, you know, you're a security person. And he went, and by the end of, he says, I hate you.
But you're right, because security is everybody's responsibility, but it's not the no thing. It's not the thing. It's about enabling and understanding the implications.
And we talk about streamlining that ability to create a, a, a, a visible view of everything that's going on, and understand, leveraging each other's expertise to create a pipeline that's streamlined, fast, secure, safe. I know, I'm I ideal, but that's what we want, isn't it? Yeah.
Right. Because that's what protect our big customers businesses. But that model of everything, we gotta stop the silos.
And I think for a lot of the leaders, the CISOs and the, the CTOs, the CIOs, there's gonna be change. Right? Kobe, I saw you get a big smile on your face when Paul Sid, that we've gotta convert them all into Security people.
Yeah. You know, we, we built a platform like in the first place to be kind of, to unite everyone, like security people, developers, uh, developers, et cetera. Um, kind of the, the use cases that we see now that, that kind of customers are interesting in is, uh, how to save DevOps people's time and also developers' time providing them a new experience through the platform.
For example, uh, you know, there was a kind of a discussion if developers are security people or not, kind of, uh, through platform engineering, you can actually reach a situation, kind of that everything is being done automatically, uh, you know, automatically. And the developers is actually, uh, we just show him, uh, a Jira case and tell them, okay, you need to fix this, this, and this. Okay.
This is kind of a, a kind of a platform engineering together with, combined with, with a bit of, of ai. So kind of, it, it saves time. It, it also provide a different experience and it also eliminates mistakes.
So kind of these are the main three use case that, that, that we see now of kind of what kind of our customers and design partners want, want to use, uh, the platform engineering for. I think I agree with what everyone has said. I think I have a little bit of a different take.
So I think platform engineering has always been something that people would argue is a good thing. It was an ideal, but in reality it was an idealistic state, and it was never like a high enough priority to do because people were like, well, I'm gonna choose best in class, and then I'll figure out how to integrate these things together. And, you know, so we'll delay that idealistic viewpoint.
I think maybe what's changed on why platform engineering is such a highlight right now is that there is so much regulation coming. Mm-hmm. And so all of these integration points that we have done for probably the last decade, because we wanted to choose best in class, and that ended up with many, many solutions that we then tried to tie together.
If you have to do something like GDPR, all these integration points are now a risk to your business. And I think as business leaders, that's why platform engineering is such a buzzword right now and why people recognize that. Like you need to have an already existing integrated platform.
So as we meet our requirements for the different regulations and all the compliance that we're being held accountable today, that maybe didn't exist five or 10 years ago, platform engineering helps you unlock that and actually reduces the risk for your business. And I think that's why it's so popular today, this collaboration. It's actually just an added benefit.
Much more so than the driver today. Sabrina would, would you say, so I've had some people say to me, the platform eng, the platform engineering team is actually an oversight team. It's almost like a platform architecture where they've got the full visibility across the whole thing, and they're guiding and being the focal point for getting the groups to work together.
Does that resonate or not with you? I think that's how, um, people defined platform engineering in the past, right? They plug all these things together.
You'd have your SRE team that SRE team would manage all of these different integrations, and then they were the oversights committee. I don't think that is sufficient going forward, right? I think that breaks down very quickly.
Um, I think that's very expensive way to do it. And true platforms reduce your cost of ownership, right? And I don't, I think that's something we didn't pay attention to for a long time.
But in the current market with the current cost of technology, that line item is actually, uh, not as, you know, available today. As the businesses are growing and the market pressure is there, Does that mean that should be part of the office of the CTO or part of Dev, or, I don't know. I'm trying to work out how it fits Where it fits.
Yeah, I mean, I think that varies by company. Yeah. Right, right.
Yeah. Yeah. In today's world where the CTO is often the CPO as well and vice versa, or the CIO is also the CISO, it really does vary.
com, our newest site, and we have a new show out there that actually check marks is sponsoring with us, called the Platform Engineering Show. org, which has two to 200 to 300,000 members involved. So we're gonna be looking hard at platform engineering.
I think the other big story is it's not replacing DevOps, it's part of this whole continuum, right? Platform engineering enables DevOps, it enables DevSecOps, it en, and, and the only way it works is through open lines of communications with developers, with SREs, with DevOps teams, with security tips, right? And I, I think that's the important thing to remember, guys, we've got one more subject and not a lot of time to do it.
And so I want to get it up there. We, we touched a little bit on software supply chain and software supply chain security. So I, I gotta disagree.
We haven't solved the open source security issue. I, I, I think this is just like a, a snake that keeps coming up and biting us. Um, what makes you think 2025 will be any better?
Or will it? Paul, we haven't started with you. Let's start with you on this one.
Well, that's a hot one. So, uh, so I mean, securing the supply chain, I think it's, it's, it's beca it's, it's something that now that the executives are starting to realize is important, that they're accountable for. They, you know, just like, um, a friend of mine was saying about Sarbanes Ox as best to sign off supposed to, so they're as best to sign off on supply chains.
It's gonna happen more and more. But I think, I think we're still getting there. I think it's not, it's, it's, we still got a long way to go, I'm afraid to say, because, um, I'm still, we talked about streamlining, consolidation, getting, you know, that traceability.
Um, and that's a thing for, for us to have a secure supply chain. We've gotta see everything as it traverses through, um, through its lifecycle of getting into production, um, securing that and getting everybody, you know, a platform engineering, uh, and sorry, Sabrina, I think it's critical and I think it does need to be a focal point. 'cause it's gonna be the one place that can push that story together with the security team to get that going through.
But in 2025, I'm hoping that we're gonna see some new tools, which will help with that consistency and that traceability. I think we still have a long way to go because I'm still working with customers and organizations who are still struggling of trying, just, just trying to consolidate their tool sets. I spend a lot of time on streamlining exercises.
So from that perspective, I, I'm hopeful I see progress. I don't see all the answers being ai, I'm afraid. And in fact, in some conferences, I dunno if you've, it's almost like it's a groan.
Oh, somebody's doing a presentation on ai. It's like, not another one. You know what I mean?
But I think, oh, I live it. Yes, yes. But I think standardized processes, maturity, actually tying it to better metrics beyond developer velocity.
Um, I always thought talk about the ripple effect. When something goes right, it has a beautiful effect across the whole organization. When it goes wrong, it has a, a ripple effect that hurts everybody.
It's not just there, it's not social security, it's not just infrastructure ops or whatever. Everybody gets impacted. And I think I'm hoping, and, and I'm gonna be pushing to get different metrics in place.
So people want to understand the impact and the positive nature of supply chain beyond just getting product faster onto end into production. Radical, I'm sorry, Fair Panel. I, I think that in 2025, uh, uh, we're also going to go further down, further down or up in the chain, meaning you go into the source and assess how trustable it is.
Meaning like, is the repo that I am taking something from, how healthy that is the con the contributors that are contributing to, to the open source that I'm trying to fetch how, kind of, how reliable they are. 'cause up until now, we kind of, uh, we mainly focused, okay, I'm taking a piece of, of something, a piece of software. Uh, is that specific piece of software?
Is that, uh, is that, uh, a healthy one or not? I think that we're now going to go kind of one step down in, in the chain and, and, and again, and assess how trustable the source and the contributors to that source, uh, are we, we act never a, I'm not supposed to mark it, but we have a solution that acts like a gateway between the public repos to stop the bad stuff coming in. Um, the real challenge is getting the developers to say, go through this way, go through this way to the, to to get you to your repos opposed to going direct.
Like, don't go at home, install the package and then come back, sort of thing. So there's a lot of, there's a lot of challenges about that enforcement. And try to explain to the developer what you're gonna save them time, uh, save them time and money and let them spend less time fixing bugs and more time To creative.
I mean, there are still people downloading the wrong log. Four j Well, Struts two and Equifax, this is a common, how do you stop them from downloading old vulnerable bug ridden bad components. Sabrina, I saw you shaking your head though.
I wanted to give you a chance. I mean, obviously, you know, we get hundreds of external contributions into GitLab. It's amazing.
People ask me a lot of questions about that. And you know, look, just because all of your contributors are internal does not mean you don't have risk, right? It's just sort of like if you had a firewall versus not having a firewall, if you're behind the firewall, you're safe.
That's not true. That's never been true, right? We've learned the hard way that that's not true.
I actually think sometimes the number of eyes who are on open source, right? And like checking for that and looking out for that is much more powerful than what you might get. Um, if you're all hidden internal, like having worked for a very large tech company for a long time, not all teams are the same.
They don't all make the same assumptions. So even when you're integrating inside your corporate walls, you have the same kind of risks. You need to be on the lookout for that.
You can get malware into your system unknowingly. What you, what you really need to have is like, you need to have policy controls, things that are enforced that are automatically looking for that. So if you employee does do it, it's not like, Hey, you broke the rules.
It's like, Hey, we just stopped what you did. That cannot be integrated into the system we are watching for where this is going. And that's, again, back to the platform.
Like the platform can enable those things for you. Yep. Because it plug, all your system is all plugged in together.
You can look at everything at the same time. And I think that's how you wanna think about it. It's not open source or internal.
The risks are the same for the both. One has consequences, right? Because you, they're your employee, right?
You have, um, you can do something about it, whereas the other person can't do anything about it. But actually it's the same problem in the end. I think, uh, I think this falls in that same thing that I was saying earlier, which is make it hard to do the wrong thing.
And if you put in all that policy in place, like you said specifically, like that's, that's why we built open policy agent into harness. So you can prevent any one of these, right? Make sure that every piece of code is scanned.
Make sure that every piece of code doesn't hold that MIT license. Make sure that it goes through the appropriate measures to block things like a log four J, but also make sure that it has salsa attestation, so it's got a bill of materials. You make sure you're there, but you actually know that it's the actual artifact you're using so you don't fall into like a SolarWinds attack.
Mm-hmm. And so now the actual attack vector has grown from just the artifact, just the code. But now to your point, this is why the platform's so important.
This has to be from source code, from the build, from the deploy through all the systems. And it's not even just about validating it, finding it, checking it. You're going to have that zero day now how to remediate it.
So that platform should know what you deployed on, which infrastructure with which configuration that were secrets to get you back. Or more importantly, as you update those, uh, artifacts or you change those libraries to promote them out to production again. And so getting you remediated quickly so you don't struggle with those.
And I think this is truly where when we start automating all those things, and it gets us back to where we were. Like, if we start taking that burden off of people, uh, and actually focusing them on the areas, now each one of those teams can do what they're great at you. You empower it.
And what's really scary here, you know, the government is actually the first ones who did this. Well, there was an executive order that forced this that said, Hey, you have to have a bill of materials. You have to have an attestation that proves it.
And this is one of the first times we've seen our US government actually leapfrog and actually leave the, the, the public sector behind. And we've been working with those enterprise customers on that specific problem for years now. And what we're seeing this year, and I think, uh, to get it back into predictions in 25, you're seeing now actually all these, you know, public companies catch up to, we need to have this secure.
We need not only for our own software, but to your point, even the people that are our vendors, uh, the people that are co contributing. It actually, it, it builds trust amongst the entire community Agreed to Sabr, to Sabrina's point that, uh, in internal, you know, internal code is also, uh, not, not secure. Like we have a whole concept of what we call price packages.
Not open, not not only open source pack, meaning packages that were actually developed within, within the, uh, within the organization. And we treat, we treat them, we treat the same, They're potentially Malicious open source packages. Yes, absolutely.
Guys, We are outta time. I wish we had, as I said in the beginning, twice as much, three times as much. We could talk about this all day.
What ama an amazing, amazing panel. Thank you all. Nick, Paul, Sabrina, Kobe, I, I honestly from the bottom of my heart, thank you so much.
I hope you guys out here watching this have enjoyed this panel. Um, all four of these companies and these folks are kind of frequent guests on Tech Drunk tv. So watch for them throughout the year.
Um, we have a lot more lined up here for you today on Predict 2025, including the winners of the DevOps Dozen awards we'll be announcing. So for on behalf of everyone and, and here at Techstrong, I'm Alan Shimmel. Thanks for joining us on this great panel.
Stay tuned for a lot more here at Predict.



