About this talk
This talk focuses on GitOps and Continuous Delivery (CD) events as methods to achieve compliance in software delivery pipelines. The speaker, Manuel Scher, discusses his extensive experience in DevOps and outlines the evolution from monolithic applications to a microservices-based approach, emphasizing the necessity for frequent releases. He highlights how automated pipelines can enhance security and compliance through standardized practices, with a specific focus on CD events as part of the Continuous Delivery Foundation. By utilizing GitOps, organizations can implement a single source of truth for all compliance metrics and automate their delivery processes. The session addresses the challenges faced in large organizations related to visibility and the importance of a clear audit trail to prove compliance, while also discussing the return on investment for implementing these systems. Overall, the talk provides valuable insights into aligning development and operations for improved efficiency and compliance.
Full transcript
[Music] uh hello hello good morning uh we are continue with next Topic in this truck uh let me welcome Manuel Scher to this stage who is going to talk about kops and continuous delivery events uh Manuel is a senior devops evangelist with a huge experience and Def and Ops Solutions ambassador of the wops Institute and so on and so on uh but I personally like this uh
how Manuel cols he self like the wsif fire and theologist yeah I like these these names sounds funny uh so Manel now now we have some uh time for your talk and uh audience can ask their questions in the chat and in the end we will have like five minutes to for you to answer these questions okay you're welcome good okay so let's uh let's start thank
you very much much for the uh the introduction uh as you mentioned we will talk today about uh gitops and CD events especially uh seen to achieve compliance uh in uh uh software delivery pipeline which is I mean this is the topic uh the main topic pure devops of the track today we will go through a very quick introduction uh I can hear some of you my
God this guy is still using the software is eating the world uh picture I do that because I had a chance to work with Mark andreen who is the guy who said that in back in 2011 um if I remember correctly so as you mentioned I have a a huge experience which means a long career um within uh several vendors several companies doing both Dev and Ops
and devops and Dev secops uh and we will talk uh today about that gitops and CD events solution that we have uh created uh with uh with several teams that allow to uh make sure that every software that goes to production uh is compliant we will see what it means to what it is compliant and that we can prove the compliance with uh a couple of Clicks
in the solution we have created so before going into the solution I like uh always to uh talk a little bit about history uh we are in the software world the software world is quite young at the end of the day uh but has a a an interesting history so over the last 25 years especially in the financial services but not only uh we um that history
uh for applications for infrastructure we used to work with monolithic application we've gone through client server and here application now we are more microservices focused the infrastructure at the very beginning was uh the main frame uh open systems then we are uh today in the more container Centric uh thanks to the cloud so things that have evolved a lot the main Evolution though is the following we
had big applications so few releases of these big applications we were talking about big bang for new versions new releases of and uh we are now with more modular applications uh which means many releases because we are able to release very small pieces of application that independent so it's completely different and we've gone through some um I would say some waves okay some waves of the software
development these waves from uh roughly when when I was born until until now has gone through uh some levels of maturity okay devops today or devops is currently the the highest level of maturity we are uh going through New Path uh like AI for example but applied to what we know today so if we want to uh summarize we've gone through languages Bo we applied some methods
we've been talking about product and process and and now today is really what we call devops this is characterized the uh the transition to devops with the deployment frequency remember my uh many uh few small application with a lot of releases it means a lot of deployments towards the target uh platforms towards what we will be interested in today towards the uh the production platform if we
go a little bit more in details very quickly how that devops tooling has matured if we start from the beginning we had very simple things job based you remember my my main frame or my uh early open systems uh a lot of scripting which is difficult to scale difficult to manage expensive uh because people were were quite often uh changing jobs uh so maintenance was a nightmare
with done that first step through maturity to something called p line based with some reusability with uh the notion of uh different stages in the pipeline to handle what we have to do the tools very simple version control the first one uh everybody could remember uh of my age could remember Unix in the the early' 70s uh which embedded the first version control system CCS uh to
manage the sources so scripting and moving to uh environment to stages to Transitions between these stages uh to model the pipeline the best practice were I WRA the script to orchestrate into a already um even with the pro knowledge at least the scripts were working so I could uh use this scripts and I could do a basic level of security transition the second to the third generation
since I have the pipeline I can add several things like uh QA like uh testing like security so basically from stages and environment I am moving through adding uh peripheral activities uh to my uh to my pipeline in terms of best practices I can ensure that I better manage the environments and what is in the environments I can have repeated activities I can have the a better
knowledge of what I'm doing what I'm releasing where it is released it will be by the way we will see that in a couple of slides the the the the first step towards the bill of material knowing how my software is made and where it will be uh deployed and operated but in terms of Steel of best practices I can add from here other activities the change
management for example I can add the requirement management so build a complete chain to make sure that I uh I do the requirements of my software I Implement my software and what I will release can be managed and controlled with change management against some uh initial requirements obviously security is always around so I can add more security and make sure for example that I can move to
the next stage only if my QA tests are correct uh which is something that we all know today but only if my code scan are correct only if my security scans are correct and so on so last step from prescriptive to configurable this is what we have today a complete release automation release orchestration that does the link with uh basically from a code commit in GitHub until
the release in production of my new uh application that kind of solution usually is modelbased so I have a model of how the software should be released and I will apply that model to my many versions so from iding QA and test and CI and so on I have a proper devops platforms that will cover all the aspects of my um software delivery supply chain which includes
and this is where uh I want to uh to go the audit Trail since I have uh everything automated in my platform I can prove I can easily out the evidence of everything I'm doing through the approval process uh through the uh the security and uh compliance I can have the reporting on that very simple and I can also uh be maybe more user Focus developer focus
and have a Self Service uh capability to on board the application but also to um verify the audit and compliance uh through that Self Service uh portal platform so I I reach a level of that goes through the different uh Generations a level of that normally could allow me to have uh the control of the releases the control of the deployments and the the easiness of compliance
and audit but in the facts okay in the facts I have some challenges the common challenges in uh Financial Services or maybe some other things the one so there are many challenges uh the one I decided to uh focus on today is the security and compliance this is the one we are talking about this is the one we address with that solution based on GTH ups and
CD events so why do we have these challenges by the way um I just put that slide because on the on the uh right corner here bottom corner I have a very basic drawing you you will you will see why do I put that very basic drawing because that drawing I think I I first used it I don't want to lie but it was 303 uh years
ago the wall of confusion between development and operation and this is still the case today okay this is what Dev pops uh addresses or tries to address but we still have some difference of Visions between development and operation we are um moving towards the resolution of that but think about big companies big companies have some organizational structures that are moving also because big companies acquire some other
companies around the world this is the case for big banks for example they concentrate and they bring on board some new organizations some new groups some new tool chains that have to be included in that notion of global solutions that work for every software that is released whatever the technology so stack of Hardware whatever the the release team and the usage that they have whatever the software
licenses whatever the processes that are applied so that challenge that challenge these challenges because there are many uh this is typical of of an boring slide okay so I will obviously not go into everything but we are spending a lot we don't have enough visibility and we are losing uh people and business which is are the three most important things that we are trying to solve uh
in terms of devops processes and simple processes in my software delivery chain it translates into uh figures it translates into money un necessary spending I'm losing some money I'm I'm spending too much money visibility and control I'm losing time hence money to uh have a better visibility and to ensure that I have the control and uh I'm losing people in business so it's directly for both of
them money because people is not happy to work or I'm losing also business because customers are not happy of uh the way my software is available or or my software is B less so everything translate in money and I have to change that into a approach where I will have better compliance audit better quality of release uh better smile in my uh teams and I will have
less money spent in duplicated Hardware where the cloud is is part of the solution um over time so I will reduce that that over time and I want to do that uh introducing flexibility visibility control scalability reliability so uh my impacts okay that prediction in uh everything that I was talking about efficiency savings risk mitigation which are interesting things but the money is still there so return
on investment how much shall I spend to get a working solution and what is the return on investment how much can I expect to save and to earn after that so if we look at a typical return on investment of that kind of solution the return investment is very very fast okay around this is an average um well average slash best case I have my return on
investment in less than half a year here I have five month of return on investment so after that my communative investment are in red my benefits are in blue I have only benefits of my working solution so solution what are we talking about about um the title was using giops and CD events some of you may not be familiar with this notion so what is CD Evans
it's a project of the continuous Foundation um as we we uh said in the introduction I'm an ambassador for the foundation and I'm working a lot for and with CD events it's quite simple it's about adopting continuous delivery uh and incorporate whatever tooling best suits for the specific requirement so it's not linked to a tool but it's the common specification for continuous deliv events for the interoperability
of what happens in the software delivery supply chain so what I can do with CD events I can have flexx pipelines easy to scale I can have synchronizations between workflow and we will see that in details um I can have a simple way to enhance some modify my workflows and very important standardized notification for compliance and metrix collections so I can collect information and I can have
the automated compliance with the help of CD EV if you go to the website uh the CD website you will find those uh schemas basically things happen on my system a on the top things happen on my system B on the top I will synchronize the events so that at the end of the day when I deploy I have a full product made of system a and
system Bay that work together another way of seeing things still very simple in the middle here I have some kind of broker things happen on the top here on that drawing on that schema SCM uh testing QA building uh generating artifact uh doing Security checks deploy and everything will be sent to broker and from the user point of view I can view I can store I can
notify I can generate metrics uh based on what happened on the top so you see the idea I made some information available and my broker will make will me use that information for whatever I want so whatever I want in my case will be uh make sure that my software is compliant and make sure that I've done the right things whatever it means we will go a
little bit more for uh releasing my software the second uh principle in the title was gitops gitops probably most of you are more familiar this is the definition you find on the gitops uh Wikipedia page I believe operational framework that takes develop spe practices used for application development and the them to infrastructure automation so gitops is much much about automation you remember my um uh history of
the devops tooling if you go to the gitops web page you find exactly that this is roughly the same okay and I discovered I swear I discovered that uh gitops uh history okay the infrastructure automation versus the cloud operating maturity model maturity I discovered that after uh I built that part of history of uh of that presentation this is roughly the same okay from programmatic automation until
the complete uh automation of the uh the platform aspect gitops uh still on the website you have several schema I uh took two of them because we have the the two principles that we've been using the first one is to have a single source of Truth this is very important not only sorry for the source code but also for all the results of the different checks I
will do to make sure my software is compliant the second thing is automation gitops is able to trigger a pipeline everything uh every time something is committed to get so based on these two principles we have defined the solution so what okay so so what happens um in my software delivery supply chain basically I have a lot of stages because a lot of teams are doing a
lot of activities but roughly I have three main steps I have several uncontrolled stages uncontrolled mean that I can have an environment that is built on the Fly um I can have some data that are not yet um equivalent to the ones I will manipulate in production I'm doing some testing can be security testing it can be quality testing it can be against requirements sit uh uat
all all that kind of testings until I reach a stage which is um I will go to pre-production to prepare to switch to production okay so knowing these three pieces the three parts of my uh supply chain this is what I have uh created so an execution phase for the checks and a validation phase for the checks this is in the validation phase that I will make
sure that I have compliance whatever it means we will see that uh the compliance before sending to production so how does it work giops will trigger a pipeline since the pipeline is uh a generic one a generic mechanism generic process I have to know what is for example the technology I will uh deploy to what is the uh the type of uh software I will deploy is
it microservices is it the Mainframe program is it client server stuff uh shall I deploy to Cloud uh infrastructure shall I deploy to uh my data center because still some uh companies especially some banks have some data center is some countries that are very uh touchy um so I have a parameter file that tells me this is what uh I want to um bring to production so
some of the security controls will apply some of the um the checks or compliance check will apply or not everything is in my my parameter file since I want to be user oriented for that parameter F I also provide templates this is the typical parameters you have to use if you uh are working with microservices this is the parameters you have to use uh if you use
do files uh if you are working on Mainframe if whatever okay after that according to what the parameter files defines um the uh software will go through a number of checks okay checks for the security for Force for s for dust for whatever all the scans that you can imagine but also other checks okay in my example in the company where we we've been working uh there
are 17 17 chapters of uh controls to evaluate the compliance 17 security is one of them so you can imagine data management uh architecture and so on and so on so documentation is also a very important one so it will go through a check of everything once I have done the check I have stored some values these values typical this is where I'm thinking you remember my
single source of Truth in um in the kops uh principles uh these St values I will try to put them in uh uh that single source of Truth in one place this is still something we are working on so far we have in several places we have only one information of one type but some of them are stored in the itsm system some of them are stored
in the policy engine some of them are stored in the software build of material according to the use uh I want to do of that information but the idea is I have one information in one place which will allow me to validate the controls I do a very simple example um in my S scan I have to make sure that I don't have any critical violation okay
if I have one critical viation at least then the control uh static scan will not be validated and the application will not be allowed to go into production and we will do the same with all the different controls able to produce an audit report so that the person in charge of analyzing the results will know why the application did go to production or why the application did
not go to production okay so basically this is the U uh the Global idea the global process that we've been um creating how does it translate so we'll go through a number of uh screenshots uh that show some of the of uh the pipelines and the processes so you've seen the title my Security checks my generic security pipeline what what does it answer to it answers to
the following I want to do cicd I want to be compliant I want to build a a bomb uh because you may remember 3 years ago 2021 uh Biden has uh issued an executive order for applying the software bill of material to any software it has been then relay with the Cyber resilience act Europe um but but not the project application business focus development although we are
all talking about Shi left uh development is not necessarily a security specialist it's not made of security specialist they are very very skilled in security but how to Def a compliance scheme a compliance engine for the security it's not exactly their main focus the main job so The Specialist Team Define for me the security the compliance through a number of steps I have to go through for
implementing security what happens in terms of security in development in integration in delivery and so on and so on this is what the pipeline can look like visualized like a Canan like uh activities and if I focus on one stage for example before entering the stage and after for exiting the stage I have rules uh to comply to did the user go through the training so we
can understand the result of the S and what are the result of the S did did go through the threshold for in my example those tools on I Cube check marks IQ server you understand here that I am my my process is independent from the tools I've been using those tools in my examples because they are some kind of uh markets they are very uh familiar on
the on the market it can be any other the tool that I can Implement over there same thing for uh preproduction I can go I can exit preproduction and go to production if I have some um rules that will allow me to um go into production so my uh green check uh going into production so this was for security but but the application itself so my main
frame or uh client server or microservice application what other question I still want to do cicd to be compliant and to build the softare build of material but I want to do that using the security checks provided by the pipeline I've been describing building my Bild of material and making sure that uh each stage achieves all the control my controls because I want to testing but also
the generic controls the one I described in the security pipeline but you can imagine I mentioned 17 chapters of controls so whatever the control I want to be able to use these controls so how does it work you remember my CD events before a way to synchronize this is exactly what I've been doing my security pipeline at the bottom my main release pipeline at the top and
I will synchronize using CD events I've done everything in integration then I give the information to my main pipeline which is at that moment in QA I've done everything every check for the delivery in terms of security then I give the information between sit uat for my main pipeline so I synchronize using CD events those pipelines in that way the the beauty of that so ahead of
the pipeline which is made of my test okay Dev test dit test a QA test this is my my test it's not the security ones that are defined by the security teams but but in my development stage look at that I have the same conditions to enter I have to be aware of what I'm doing so I'm a registered traine of the processes but to exit the
stage I also have to do the same stuff uh going to check if the thresholds for my uh sonar Cube check marks and iq7 the same uh tools that I had before because it's been done by the other pipelines but through CD events I got the results check the same results to move my pipeline along uh to go to the delivery application so uh I hope this
is quite clear you can imagine the uh the the combined pipelines of my 17 chapters I have a lot of events that go and feed my pipeline while I'm doing that uh let's do a a quick focus on my bill of material um I was talking about the uh the US executive order that was issued in May exactly 3 2021 um the typical use case for the
uh the bill of material we use uh bill of material for automation for compliance for security for understanding the complexity of an application at the end of the day it's um it's another artifact that contains the description of all the artifacts uh I can use I need for qualifying my application so for those another reference to uh to Unix uh for those who who were familiar with
that uh tool on Unix in 75 my God yet another compiler compiler Yak the bomb is a little bit of yet another artifact artifact this an artifact that describes artifact it's also the single source of software delivery truth so it contains everything that is used to build the software but also everything that is used to release the software including all the results of my uh scans for
example of the result of my tests just because I can do a scan today and uh the same scan tomorrow and have different results so the result can change over time because I've discovered for example new um vulnerabilities in an open source Library so what while the the um the change then my software build of material have to trace uh everything and this is the reason why
it's typically ESR uh just like you do at at your notary you give the notary some important documents so that uh the notary can have the custody of these documents and we'll make sure that they are never uh changed this is another subject there are many things I'm doing also uh in other channels presentation on sbom uh so if you want to uh to explore that uh
that is Bomb just uh look on Google and you will find some very interesting things um the production stage by the way of my uh security pipeline I made sure that I I have a bill of material of my software entity typically my microservice uh to make sure that before deploying to production I have the bomb uh I have information in my cmdb if I have cmdb
I have the immutability of my bit of material notorized esro and I have created an SKU okay these are the uh the companies uh specifics but I make sure that I have my I can verify that I have my bomb before production so basically uh this is pretty much uh on on the description of the of the solution what I wanted to um to finish with is
a couple of Lessons Learned um it looks very very simple I will add one of them on top of that but um so very simple ones uh Implement devop processes uh security controls automated build of material just do it okay it's it's easy to do you remember my history uh even if you have a minimal set of tools of scripts you can wrap them and automate them
it's very important uh because and it's the second one uh if you don't do it the competitors will do and the competitors doing that will get some benefits and will uh get more market shares than you have so do follow the State ofthe art uh it's a an investment but it's important to be on the State ofthe art because state of the art uh will ensure that
you have uh the best level of devops def secops implementation to be on top of uh your Market the third the third one yes um quite interesting because we've seen that um automated and self-embedded controls it is easy that the culture and practices will be part of uh the day-to-day life of the organization and will get disseminated within the organization the first time a control is implemented
it's some kind of okay I have something new something more to do if it's done uh seamlessly with the process that um I've described you then it's easier because uh it's painless for developers and operation then it it gets as I said on the day to-day life and then it gets disseminated within the organization it becomes a normal stuff to do and if it's not done people
will be shocked because oh we didn't do that we we have to because it's so simple and it brings so much benefits okay and the uh on top of that uh which is quite related to the last one adoption and preparing the adoption is crucial for that kind of solution so uh communicate a lot and uh involving people in very early stages so that they can in
those very early stages measure the benefits and see that their is becoming better because of so uh we we're ending on that so thank you very much for following the talk um I do not know if there are some questions already on thank you for the talk we have only two minutes left and we have one question uh okay what should be the first step to implement
such an approach question um I would say I mean it's not an an easy uh an easy question because there's so much to do I would um do the link with one of the last thing I've said um we have to implement a compliance solution we have to make sure because uh the company has to prove the compliance and to automate in my case the compliance of
uh the the the software release every releas is compliance I know that if it's gone in production it is compliance um so one of the first thing to do is to in my opinion uh is involve the people you remember adoption work on involving people at early stages um involving the people in um the definition of the the benefits of the solution what do I expect from
that solution okay I've been told because my huge company wants to achieve that compliance automation stuff but for you uh development teams operation teams security teams what does it mean on a day-to-day basis okay is it is it is there what is the the benefits that you will have in your life I would start with that okay involving people in early stage and showing the benefits talking
about the benefits so that we can work together and you will help me uh as an implementation team to get these benefits and I will help you to uh maybe change a little bit your way of working to achieve those benefits ahead of the technical aspects which are at the end of the day it's I would say it's only technical stuff okay so I hope it answers
the uh the the
More from this event
See all 58 talks →
Halil Ibrahim Kalkan: Building a Kubernetes Integrated Local Development Environment
45:20
Paco Orozco: Growing at the Edge: Doubling Traffic While Changing the API Gateway
45:03
Viktor Vedmich: Ideal Blueprint Versus Reality for CI/CD Pipelines
46:03
Koray Oksay: Continuous Deployment: The GitOps, The Pipelines, and The Ugly
43:03