The Lab with Brendan O’Leary EP 17
Senior developer evangelist Brendan O’Leary tells us about this month’s GitLab release.
Transcript
Hello friends and welcome to the lab a monthly show where we look at the latest and greatest developments in software developments development devops and the cloud I'm your host Brendan O'Leary coming today from a sunny Annapolis Maryland on the east coast of the United States. For those who don't know me, I'm a developer evangelist at gitlab which means I get to talk to amazing folks throughout the software engineering space about what it means to really get code shipped into production. And we have a great episode for you today.
3 including some new exciting get Ops features and task management capabilities. But not only that we're also going to be looking into gitlabs sixth annual devsecop survey. And to help me sift through all those findings here today.
I have with me two, very special gitlab guests one from gitlabs product team. We have Hillary Benson director of product management. and from gitlab's public sector team Bob Stevens vice president of public sector get and they'll join us later in the episode to discuss some of gitlab's brand new survey findings and you know what they really mean for the state of devsecops today, but first, let's dive into the gitlab updates.
3. I'm really excited for a lot of the changes here. First is something I've been looking forward to honestly for a long time and I'm really excited.
It's finally here and this is creating tasks within an issues. So, you know tasks allow you to take what might be, you know, a larger issue and break it into smaller discrete work units that can then be worked on and before and gitlab. You could have, you know, things like markdown checklists or or sections in your description to help with that but they're not, you know, a rangeable easily.
You can't label them or manage outside of manage them anywhere outside of just that, you know description markdown. but now you've got these tasks within issues in the child items widget and you can open a task directly within the issue update the title of that task set of wait for the task or at a description and those tasks will help you break down the work within projects for gitlabs free tier and can also be used to Create another level of planning hierarchy for premium customers who are using, you know Epix issues and now tasks. In the next aeration of tasks, you'll be able to add labels milestones and iterations to any task to help you organize where those tasks should fall and that represents our first step in the next evolution of issues epics incidents requirements management test case management all of these different work items.
And so there's be a lot more to come here as we as we continue to iterate. 3 is something we announced a while back, but it's finally here and that is that the get-ops features of gitlab are now available in our free tier. So when you use gitops to update a kubernetes cluster, it can also be called maybe a pull-based deployment right where you have an agent that sits in the kubernetes cluster and pulls what the known State should be from a source code a place where you manage that infrastructure as code, right?
And so with that you can kind of have a lot of improvements around security and scalability and stability as the cluster can kind of contain itself and you don't have to have you know, an external agent working on the cluster but instead have an agent inside the cluster that's pulling updates to you. And the gitlab agent for kubernetes has supported these workflows for a while now since it's an initial release, but up until now the functionality was only available with premium or ultimate. So but now if you have free free subscription to get lab you also get the pull-based deployment support and these features that are available in gitlab free help, you know small high trust teams or you know, maybe suitable to test the agent against what you want to be able to do with kubernetes and get lab until you upgrade to a higher tier for some of the more the features.
In the future in premium. We're hoping to add multi-tenant support and this would be similar to impersonation featured that's already available for our ci/cd workflow to help you decide, you know kind of role-based access to multi-tenancy. 3 include adding approval roles for all protected branches, so You can now have Mr.
Approval rules that apply only to the protective branches in your product project that helps you, you know, selectively apply these compliance controls so that you don't have to worry about you know, Mrs. That are happening kind of Upstream of the main or the protective branches of of your project. Can also submit merge requests reviews with summary content I love this feature.
So if you don't know what a merge request review is, you know, this is the ability to comment and multiple places along a merger class without you know, sending the merge request owner a bunch of emails for each comment. You can package them all up in a review and have all of your comments come at once but now you can also summarize your your request at the end, right? So in addition to specific comments on specific lines, you might want to have you know, The summary of your review or how you're approving it or if it looks good to you and these are just minor changes when you submit the review.
Now, you can add that summary comment along with you know, all the quick actions. You expect like, you know, hitting slash approved to approve the merge request in addition. It's also a new UI for custom HTTP editors the headers for streaming audit events.
So you can add or remove HTTP headers headers for those streaming audio audit events directly within the gitlab user interface which makes it easy to interface with other systems that might expect, you know, specific header values to be present. And this was previously available through the API, but now is available in the gitlab you online. And then two other features I wanted to point out one is maintaining sample group links with the API.
So up until now Samuel group links had to be configured within the UI, but now you can also manage those Samuel group links programmatically using the gitlab API. So that way you can automate all of your sample group management through through that API. And lastly you can Define password complexity the complexity requirements.
So you can now have additional requirements in addition to the minimal password length for instance should contain numbers uppercase letters lowercase letters and symbols and since complex passwords are less likely to be compromised the ability to figure this configure this and force those complex that complexity requirements will help administrators enforce their password policies across their organization. 3. 3 you'll be taken right to the blog post about it.
0 and we're really excited to for what's coming next. So stay tuned to the gitlab blog for the full list of updates. Now I'm excited this year not only to announce gitlab's sixth annual Global devops survey, but also to dive into all the findings we had.
This year we were able to serve you over five thousand devops professionals and the finance highlight, you know where we are with sliver cybersecurity with global devops adoption and with new trends and technology. Is that are taking industry by storm. Hillary thanks so much for joining us today.
So has one of our security thought leaders here at gitlab. What did you see as you know the key takeaways from this year's survey. Yeah, thanks for having me Brendan.
I appreciate it. So I think there's a lot really to take away from from this year's survey. I've had to pick out just a few things that are particularly relevant from a security perspective.
There's three main things. I think I'd highlight the first one being that regardless can kind of globally regardless of whether you're in a development security or operations role folks agree that their top area of investment in 2022 is in security, which I think is pretty significant. It's not entirely surprising that everyone's says that a high level that security is important, but when you're actually talking to folks who are in non-security roles highlighting security as a top priority, I think that's sort of is indicative of you know, the rubber meeting the road and security really actually being a top priority in practice and not just in philosophy, right?
So that's a pretty important takeaway. I think the survey also revealed that Security Professionals are starting to really see their roles change in relation to the whole shift left Paradigm. So 57% of security team members said that their orgs have either shifted security left or planning to do that this year.
Which I think is pretty significant. And I think that developers are starting to see kind of the day-to-day Hands-On activities with developer developer team sort of changing and becoming more concrete. And then the last thing that I'd highlight is probably just the broader concept that devsecopson General is becoming more of a daily practice unless of just a philosophy that people are aligned around it's becoming more and more real.
and there's a few things in this survey that I think point to that actually but for instance just over three quarters of Ops teams agree that at some level developers are able to you know receive and then also address security issues during the development process and that's not you know, that's just one thing that you need to be able to do if you're implementing a desktops program, but that's a pretty significant number. So those are the main things that I think I'd pick out and point to Yeah, no, that makes sense. And like you said it's maybe not surprising entirely.
That's that security is top of mind. But to hear it being put into practice is again, maybe not surprising, but but good to hear. So what did surprise you in the survey?
Like what what did you not expect or what was kind of surprising to you? Yeah, I think there's a couple things here. The extent I think the extent to which the developers are taking on not only security type responsibilities, but also infrastructure Ops related type responsibilities and it was fairly surprising.
So we've seen a lot of focus on shifting security left, but the survey seem to indicate that developers will really sort of Shifting in a lot of directions and they're taking on more traditional Ops responsibilities. So for instance, there's over a third of the developer respondents say that they're instrumenting their code for production monitoring. They're creating their own infrastructure monitoring their own infrastructure.
They're on call for for when those those apps are running in production. And those are all things that typically used to be pretty exclusively held for operations professionals. And so I think that the fact that that's shifted a lot was something that I thought was surprising.
Surprising in terms of how much it's happening. If that makes sense, and then I think the the other big thing is is just how big of a problem tool chain sprawl has become so we obviously know that maintaining tool chains is time-consuming. That's not that's not newer surprising but I think the extent to which that this is become an issue is what is surprising and so there's nearly nearly 40% of folks said that they're spending between a quarter and a half of their time managing their tool chain, which is just that's just massive.
And I think that's that's more than double the 2021 percentage. And so it's always been an issue but how significant diet increases and the amount of time that's being spent is pretty surprising. and then again, it may not be surprising for folks that they stop and think you know, if you're devops professional you stop and count the number of tools that you that you use it may not you'll quickly reach six or ten.
So it's not it's not surprising but in in the in the results 41% of devops teams used between six and ten tools. And so when you when you actually think through you're like, oh, yeah that that makes sense. I do use that many tools but to see it actually outlined is maintaining 10 different tools and spending potentially up to a half up to half your time maintaining them is it's pretty that's pretty significant.
So anyway, I think those those to take a statistics really demonstrate that there's still a lot of work to be done in uniting the tool chain for devops. And and really I think it points out that if you if you want to have a productive team and you want to have better security posture and you want to maintain your budget you gotta really pay attention to what's happening with your dual Jane. Yeah interesting again.
I think I think you put it really well that It's it's not surprising. But also it's like one of those things that isn't surprising but it's maybe shocking right to hear the numbers. Yeah be be so significant and that significant period of time is you know is critical as we're all trying to get product to Market faster.
But Bob I also wanted to get some of your insights, you know from a public sector perspective. What's the state of devops adoption there? And you know, what does devsecops look like in you know, government and education and defense industry.
What did you say there? Good. Thanks Brandon.
So overall we're seeing that the adoption of a platform a demos platform is often both the private and the public sector space. I think that almost 75% of our respondents have either implemented or intend to implement, you know, a devops platform in the near future and quite frankly. It's required in order to meet the compliance security and the tool chain consolidation that they they are attempting to to achieve and and also, you know to be able to deliver software Factory software faster.
Sorry, I was thinking about software factories because like, you know in the case of the Air Force they built several software factories with you know, with a platform and as a result of that they've been able to save hundreds of man hours of development time in order to get applications out in a much much faster way, but having said that there's still a lot of folks in the government that that haven't develop Or I haven't built, you know a deficit house platform. I think that about 50% of our government respondents said that they they have developed some sort of platform and that may sound like a lot half 50% but that's 50% of the respondents not 50% of the government that's actually done it. So I think there's still a long way to go in the government.
And you know, I think we all know that they tend to move a little bit slower because of their budget cycle and also because they're they're more risk adverse, but when it comes to US security they tend to move a little bit faster, which is why I think that they're going to accelerate the adoption of the death secops platform and you know, because security is going to be you know critical for them to implement. If you look at the focus that you know, the White House has and Homeland Security and Office of Management and budget everything that they're putting out all the guidance. They're putting out is in regard to security.
So they're gonna have to increase or accelerate the you know, the speed at which they develop software in the in the future. I also know that I think a lot of our respondents I think maybe fit as many as 59% said that they they feel like they're developed their development Cycles. Remain the same or are actually even slowed down a little bit and I think that again is because they really haven't, you know, fully adopted the platform devops platform, which is something that they they need to do in order to to increase those those speed emission rates that they currently have or required to hit.
You know that that makes a lot of sense and so, you know, you know based on that and based on, you know, this tension of speed emission to you know, ensuring security and Assurance that's attention. That's maybe magnified in the public sector, you know, I think it's attention everyone experiences, but is maybe magnified in the public sector? Based on that and and what you saw in the survey, do you have expectations about how you know, what devops looks like in the future for the public sector?
So I'm gonna say that um devops it is or will become devsecops. In fact, I can tell you that, you know, if we're going to see a government customer today, if if we aren't there to talk devsecops then you know, they're less likely to be interested in speaking to us. That's how important the security aspect of it has to become and as Hillary said, you know shifting left which is what you know, a Dev psychops platform allows you to do can really really help eliminate some of the conflict that occurs between the security group and the and the developers today, you know, the developers want to go fast security people want to go slow because they want to make sure that it's secure and and it's free of all it's free as they can make it a vulnerabilities as possible.
But by shifting it left and incorporating it into the development process. I think that we can satisfy both which will accomplish the goal of speed to Mission, which is you know, what everyone in the government wants to do. That makes sense.
Yeah, I know. I think that's really critical. And and you know, I think that's why we see platforms, you know growing in adoption as folks are trying to make this a cohesive cohesive.
You know, you said software Factory earlier right to be able to to make sure that we're getting software out faster and more securely I want to change gears a little bit. We also asked questions in the survey about the state of automation of artificial intelligence machine learning and how those apply in software development Hillary. Maybe you could talk a little bit about this.
So in in the devsecop survey, you know, I saw automations becoming extremely common. You know, what else did you see around that? Yeah, I think honestly the main headline for me in relation to this was just how much more important automation seems to be this year than it was last year.
It seems like this is really you know automation is frequently spoken about as being an important and important aspect but in the survey results, we had a number of you know measurements metrics that were doubled, you know year over year or close to doubled so first it's the percentage of development teams that report that they're testing is fully automated has nearly doubled since last year that jump from 25% to 47% and it's not including the additional 21% who plan to roll out test automation at some point this year. That's definitely a very big thing and beyond that developers want more automation about a third said that they're looking to add more automated testing and resolve testing bottlenecks. And you know, it's not just about developers either almost a quarter of Ops teams report that they're fully automated or at 44% that are mostly automated both of Numbers are big jumps from from 2021 as well and setting across the board automation has become something that's very very Central to increasing productivity and efficiency within teams.
And any more broadly artificial intelligence and machine learning are already a part of a lot of devops teams processes today about half of survey takers so that they use artificial intelligence or machine learning to check their code in some form. And almost 40% of teams said that they use Bots to test their code, which that's up from 15% So from 15 to 40 percent, that's just a massive increase this year as well. And about a third of teams were using some form of artificial intelligence or machine learning for for code review that's almost double from last year as well.
And so I think you know just across the board. This is really become an additional a much more important priority for folks to the extent that there's only five percent of teams who said that they have no plans to incorporate any form of AR ml into their devops practices. So this is something that's become very top of mind for both I think.
And that's interesting and something we'll have to take a look at and yeah, that would be hard to see that trying to continue but maybe you know the continues growing up to the right like that and we're all going to be looking at it very shortly. So yeah. Thanks for sharing.
So Hillary and Bob thank you so much for joining us today. It was really excited to talk to you about get Labs 2022 devsecop survey. If you want to learn more about the sixth annual survey.
Be sure to check out the full report. com. Slash developer Dash survey and it's free to view and download take a look a lot of really interesting findings in there.
And of course as always, thank you very much for watching today. You can find me on the internet as at O'Leary crew most places and Twitter is where I spend most of my time. So if you have an idea for a future episode or wanted to discuss anything from today's episode, you can reach me there my DMs are wide open or you can just tweet at me and let me know.
Let me know what you think. Again, the lab is produced monthly and so we'll see you next month in the lab. Stay safe.





