DevOps Pro Europe 2025

Peter Parsons: Policy-as-code for Any Cloud to Any Edge Automation

43:12 · 20 May 2025 – 23 May 2025 · YouTube

About this talk

In this talk, Peter Parsons discusses the concept of policy as code, focusing on its application across different cloud environments. He draws on his extensive experience in infrastructure management to emphasize that DevOps transcends traditional application development, advocating for a broader scope of applying automation principles. Parsons explains that the evolution of data management necessitates a shift from manual configurations to automated solutions like Chef, enabling organizations to achieve scalable, repeatable, and compliant infrastructure setups. He also highlights the importance of integrating security into the development process through DevSecOps practices. By expressing policies as code, businesses can ensure compliance and operational efficiency while navigating the complexities of modern data environments.

Full transcript

[Music] ladies and Gentlemen please welcome our next speaker Peter Parsons presenting the topic policy is code for any Cloud to any AG automation good morning um and uh welcome to devops Pro Europe thank you for all the uh taking the time oh good grief more coming in um strange environment slightly different to the the one I was in yesterday um I do like watching standup comedy just

to go off on a tangent and I do this so just just be warned um and the standup comedians are going say always tell me how bad it is with the lights shining in their eyes and you can only see the first two rows and I think right now I understand just how they feel so um those you the back I've got no chance of seeing what

you're doing back there so um so anyway on to the talk thank you um good morning uh so Peter Parsons I'm based in the UK um but um work for the the the chef uh business uh within progress software as a technical pre-sales engineer supporting um customers all across Europe including um some here in uh in in Lithuania so delighted to be back I was last here

about uh 6 weeks ago um enjoy visiting uh vus and the and the region so um one thing as well I think it's worth getting clear before we start one thing I'm not um is I'm actually not a developer um I haven't seriously cut any code for a long long time um since the 1990s and back then I was a fairly serious SE hacker writing compilers and

stuff like that um but that was a another lifetime ago um um uh what I am what I do have is a is a background in in the infrastructure side of the industry um infrastructure software Hardware networking virtualization container platforms and all of that side of it um so while I appreciate this is a a devops conference um one thing I learned many years ago from one

of my university lecturers is that um is not to constrain yourself in terms of what you can do in in software or Hardware uh because you can do the same things in both and also think about you know how how you can apply that um because devops isn't just about application development and hopefully um I'll be able to to show so quick summary uh what I'm going

to cover um a little bit of a overview of the the state of the market some of the things that we're seeing as a an infrastructure vendor rather than a a pure play devops uh provider and then talk a little bit about um how those ideas and principles and theories can be applied Beyond The Realm uh of application development because they absolutely can uh and they should

so um the market today whole bunch of stats there I'm not going to go through all of them uh suffice it to say this industry uh constantly changes um back when I started out uh clouds were things that you saw in the sky and and were responsible for the rain um you know if I wanted to go and check my bank balance I had to go into

the middle of the town where I lived between 9:30 and 3:30 Monday to Friday walk into a building and go talk to a person it wasn't 5 seconds and a couple of clicks on uh on one of these things um the world is evolving and by the time I hit retirement age and certainly looking at my audience here by the time most of you hit retirement age

I have no idea what the world's going to look like anymore in the the the tech industry suffice it to say the one thing I can guarantee is it's going to be different from from from where we are today um back when I started uh things were pretty Central calized the traditional data center approach uh connecting via terminals um was was how a lot of computing was

done um if you went into that bank branch I talked about uh then you know they would have 80x 24 character terminals green screens or orange screens for those of you who may remember those things pretty simple interface you know keyboard couldn't do much with them a mouse wasn't a thing um it was just a a standard basic querty keyboard the world has moved on uh so

in uh in in the decade since and one of the big shifts and the big changes has been the amount and the volume of data uh that is now generated um you know I probably have more data sitting on that than some of those data centers had back in the uh back in the late ' 80s and early 90s when I was uh starting out in the

industry and increasingly we're you know we're generating more of that data and that data itself is living out there on those devices um you know think about an autonomous self-driving car how much data does that need to do what it needs to do and to do and to do it safely uh it certainly wouldn't work if it had to try and connect back over a network to

a central data center at every time it needed to make an instant decision um whereas the first car I had probably the only digital device in there was the radio you know everything else was mechanical literally so D you know this the state of how we compute the state of where we compute is very much changing um data out in the wild outside that traditional safety net

of the uh Enterprise firewall um is at more risk and in the modern social media world uh the chances of that data one leaking and two putting the CIO the CEO the ceso all over the Press uh is is much greater as well again back then that wasn't wasn't really a thing CU let's be honest nobody had the technology at home to go and try and break

into that bank and uh get any of that data or steal any of their money uh as happens today so the world has changed very very much and with it there's been a change on how we do things now I did start over here way back when doing things by hand on a terminal window if I needed to do something to half a dozen systems that meant

logging into half a dozen terminal windows and typing the same thing six times and I was great at typing things things six times cuz we all know we can we can repeat and we can do it perfectly so I'd log in and i' type in the same thing six times and I'd done a perfect job and I ended up with four systems that were exactly the same

and two that were different in two different ways even though I typed exactly the same thing six times right CU we can't we can't do that it doesn't it doesn't work and that's only for the small networks that I used to look after back in the 1990s um uh let say back in a another lifetime so where uh Solutions like chef and there are others out there

and um I've say I've been in this industry a fair amount of time uh and even though I work for a vendor I'm very happy to have open conversations about the state of the industry and the swings and roundabouts and I've worked with other Solutions as well um and especially just double-checking none of my sales colleagues are here so I can say what I um the the

industry is evolved and started off um you know with Chef if anyone's familiar with with with with chef and its history it's about 15 years old or or so now as a as a company and as a product and as a solution and it was there uh to enable consistent and repeatable and scalable configuration management of at the time virtual machines physical service um delivering giving you

the ability to to actually um Define the state of your environment in a coded way in a repeatable way um so that rather than you having to go on and work manually you just Express how you want your systems to look and Chef would um basically build them for you uh to your requirements uh moving on from that um as a solution um we uh added about

five or six years ago a compliance and testing solution uh in there to enhance that give you some uh repeatability uh not just in in how you build but how you prove that what you built is what it should be and for those of you who working in regulated Industries you know I've worked a lot with you know being UK based uh work with a lot of

financial services organizations over the years and still do banking is heavily regulated uh so are other sectors like like Healthcare on and off I've done a lot of work with the online gaming industry uh that has some very interesting regulations that you have to work with um so it's not just about building to a standard it's about being able to prove that you've built to a standard

so being able to show that you're not just where you need to be but you can you can demonstrate that compliance is is key and all of that feeds into um where we are and and are looking to go which is to have everything in your environment uh all your policies expressed as code in some way so there's there's there's nothing manual within your environment so what

do this journey look like uh where have we come from where were we trying to get to so infrastructure is code the start point and I said back in the '90s when I was configuring the infrastructure manually on the servers figuring the network to involve getting real cables and plugging them into real sockets uh on real switches rather than again configuring everything in software um kind of

worked as long as you didn't make any mistakes but yeah as it says up there let's press the right button error prone because I'm a human being I'm error prone I make um and it's not a particularly scalable approach I'm not a 24/7 resource I do occasionally need a bit of time off and some sleep and coffee definitely need coffee so the idea behind the infrastructur as

code piece here is essentially you know your infrastructure can have developers in the same way that applications have developers and those developers Define the state of an environment the state state of a network the state of a server the state of an application to be deployed using a language and a framework in exactly the same way that you build end us or applications or busino business applications

uh using exactly all the same uh tooling here um so you have a a code repo for your infrastructure probably the same code repo you're using for your applications be sensible go through the same pipelining process go through the same test h potentially using that compliance testing as a as as a way of proving it and then can be pushed out and deployed wherever you want to

run so that's the the the the basic principle uh behind what Chef does what Chef was originally designed to do uh and where it's looking to go so the benefits of yeah uh there are the are a number um sure most of not all of you are familiar with the term shift left um again industry term we we love as an industry inventing terms and coming up

with ways of saying something but in a way that's unique to us so we kind of can can keep the rest of the world out for it a little bit shift left yeah very simple um if you have a problem fix it when fix it early when it's a small problem that's that's all all we're the earlier you fix something uh the easier it is the cheaper

it is and the less of a problem uh it it can well down the line it can become a bigger problem and when you really don't want to run into those bigger problems because they they they are more challenging so the idea behind infrastructure is code is you can develop and test your infrastructure deploy your infrastructure and guarantee the state of your infrastructure in exactly the same

way uh as the applications that are running on top of it and it's provable in the same way uh from a compliance or regulation or validation perspective as uh the it so how do we do that um and how do we do that validation um the compliances code piece here is about taking us away from this approach where security didn't come in until you had an application

to review or or or a system uh to review um you've gone through uh and I'm old enough to remember when waterfall was the way all software development was was was done um and here each of these steps here um was a Handover um we did a as as a company organized somebody to to look at a study and look at information transfer and information loss in

that model so every time you make one of those handovers how much of what's here actually ends up here in terms of information and the study found the answer was about 50% uh at may sound not great it's also not that surprising cuz whenever we do something so much of the understanding of what we do and how we've done it and why we've done it is in

here it's probably not documented um that's that's again we're not not the greatest so we know why we did that that way rather than that way we know the little detail behind why something's been set up in in a particular way um that it is but that doesn't always get communicated and sometimes it's so obvious to us we think it might be obvious or should be obvious

to everybody else and often it's not um and that detail gets lost in those communication so imagine here we lose 50% how much in production by the time we've got that 50% loss every time how much of the information we started with and the knowledge has actually ended up over there they it's less than 10% it's not not not great so um not the um not the

ideal way uh to go about things so the with um the compliances code um and we talk a lot uh in Chef not just about devops but about Dev secops and Dev SEC Ops is all about making security and equ partner in the whole process uh and making sure that the team uh are involved right here at the start um so we don't end up running back

into that challenge where by the time we this uh we realize we've done a whole load of work with something that's not going to pass here we have to go back to square one and down again now we have a big problem that's an expensive problem to fix we've wasted a lot of people's um and it's not a a great situation to be in so by integrating

security into the processes and if we go back to that first chart I had with the the state of the industry a lot of organizations are already doing that um if you are great if you're not please think about it you know it's a great way um to you know to improve things further and make sure that when you hit that end stage um one um you're

going to get there quicker you're not going to have to go back around the loop uh and secondly because everybody's been involved all the way through uh the whole process there uh that information and knowledge loss from from stage to Stage uh is going to be reduced or or or minimized I mean ideally we want it eliminated doesn't always happen um but that's where we want to

go increasingly these days um most organizations not all of them are making use of of of public Cloud as well there are very good reasons why uh public cloud is a real asset to the industry um you know going back 10 15 20 um organizations you know had large data centers when that data center got full the marginal cost of adding one server was crazy because you

needed a new building you needed new power supplies you needed I live in the UK you needed lots of planning permission and regulations to go through that one more server the server itself may have been only a few th000 but the actual cost cost of bringing that server into your environment was in the millions or even the tens of millions sometimes if you've ever been to the

east side of London um it's full of lots of data centers they have a power problem there isn't enough power uh when we were as a country building all the infrastructure uh for the London 2012 Olympics uh as was um that actually had an impact on the IT industry because the amount of power they needed for the building work for the infrastructure for the Olympics took power

away from from the rest of the grid the data centers were limited actually even the London Underground slowed down because there wasn't enough electricity to run the trains at full speed you know so these things these things do impact on us um so you know real benefits of of cloud the agility the flexibility um the ability to comply with some of those regulations I talked about earlier

um you know anything to do with financial transactions anything to do as I said I did some I've done work in the past with the the gaming industry in terms of where gaming transactions happened where where their customers live there's lots of regulations around that a lot of them are non-technical regulations as well um so if you have anything to do with the US in the gaming

industry that's done on a state-by-state basis so if if you've got a customer in North Dakota that means certain things must physically happen in North Dakota there isn't an awful lot of data center space in North Dakota it gets quite interesting with with some of these uh some of these environments and and some of these challenges but um increasingly there is um so organizations are making use

of you know Cloud multi clouds for Geographic reasons for for regulatory reasons and just more than anything else just to give themselves Choice one of the reasons to go with more than one provider is to avoid being tied into any single provider uh now I work for a software vendor um and I've worked for a number of vendors in my my career if you look at my

profile on LinkedIn you'll see it's a history of various hardware and software vendors um over the years and one of the things I got told very on very early on in the industry um useful snippet and I always happily share this with organizations I'm talk I talk to is is that my job as a vendor is to make it as easy as possible for you to adopt

the stuff that I'm talking to you about okay I want you to buy my Hardware I want you to use my software my job is to make it easy for you to do that as an organization who's buying software your job is to make it as easy as possible for you to go somewhere else when you've decided you don't like my anymore okay so if you if

you're in the in the business of choosing software uh or involved in the process or looking at the process make sure you always factor that in I'm using this stuff now but if next year I want to go somewhere else how easy is it for me to go somewhere else I want to make sure I can go somewhere else El you should always be looking to do

that that's the best thing for for for your organization to do don't be tied in uh to any one organization stuff and that's why a lot of organizations multicloud because they can you know play the pricing off against each other they can play the technical features off against each other and it just gives them that that flexibility the challenge or one of the challenges with Cloud though

is it's out there it's outside the data center how do we manage all the challenges associated with giving people access to something that's outside our data center what do we do about our data sitting somewhere that's outside our center and one of the things the clouds are very good at is making it very easy for you to get your data into them and maybe not quite so

easy to get it out again if you look at if you look at the small print on the pricing um always something to to be aware of you know what what are my users doing here what rights do they have um have I have I given them rights to do the right thing um they're spending my company's money uh am I have I got control over that

um CFO will certainly be interested in in that one you know how's my storage configured you know um publicly accessible S3 buckets seem to be a pretty common thing in terms of data breaches and and leaks should be something that's fairly simple to avoid yet seems to to happen on a fairly regular basis so how do we you know avoid all this stuff and make sure that

somebody in our organization doesn't put our organization at risk uh by making one of these usually simple configuration errors it's usually a mistake not always but most of the time it's a it's a mistake that when these things might exist across the world um you know if you look at some of the global organizations and and one organization I I've worked with uh in my time working

with Chef was doing this across uh clouds spread all across the world geographically and looking at objects running into the millions you know how do you prove the the compliance of that many objects which are then supporting their customers um and do so that you can be sure that you're not exposing your organization and your customers uh to potential risk it's it's a real Challenge and that

data is increasingly sitting in interesting and uh unusual places um yeah so you know the uh the size of the um you know the the wording here is kind of related to various studies showing where some of this data to actually sits um if we look at it you know retail days um again my first job uh school job part-time job when I was at school was

working in Supermarket across the road from from the school where I attended the tools were mechanical every pretty much everything was done as a cash transaction if it doesn't it involved writing a check um credit card machines certainly were were not a thing um you know contactless payment no that's that was that was decades into the into the future um these days you walk into a modern

Supermarket when I go into the supermarket the first thing I do is I pick up a device I scan the device against my loyalty card card um I then get special offers in the shop based on scanning the loyalty card so they're now analyzing me and going what can we persuade him to buy this time that he didn't last time let's give him a deal let's get

him trying to get buy a little bit more um you go around the shop you're scanning all the barcodes again back then barcodes weren't a thing I had a manual pricing gun and I'd put an individual label on everything after I'd manually set the hopefully set the price correctly with my thumb if I got that wrong I was in real trouble um but uh you know these

days there's none of that because it's all done using the it systems in there you go to the till again the Till's an electronic thing beep beep as we scan everything's stored in there that feeds the stock control system in the store the stock control system can then get contact the warehouse and said we're we're selling a lot of ketchup or whatever it is this week please

send us some more we're running low it's you know the world's Advanced so much in so many ways with with all of data you know we have you know one of our big users in the US is a is a restaurant chain um again they uh interesting challenge how do you how do you manage um organizations where you know some of these places are in the middle

of nowhere in in the US so 20 mi down a dirt track road with a a network connection that's not much better than dialup um you know yeah we we have pretty good connectivity here in in Europe you know 5G 4G pretty much everywhere on our phones you know fairly ubiquitous Wi-Fi a lot of the world isn't like that um but this data is still out there

and being generated because they have to give the same user experience in that store 20 miles uh the shop the restaurant 20 miles from from from from anywhere as You' get in the in the middle of middle of a big city um so the data requirement is is fairly much the same um so yeah lots of lots of Aviation as I I flew in yesterday you know

the pilots were probably doing their uh pre-flight checks on a tablet um the passenger list will be on a probably on an iPad that the uh the chief flight attendant has or whatever and they can look at it and go you know where are our frequent flyers who do we need to give special attention to does anyone have any special meal requirements all of that's done now

you know electronically rather than uh the oldfashioned way of a a big paper print out uh for those who remember big paper printouts and dot matrix printers again don't know how many other people other than me in the room are of that sort of a that sort of an ilk so how do do we tie all of this together to make all of this modern complexity uh

simpler um well the the the approach that we take at at chef and that we that we Advocate is bundling it all into what we call policy as code the idea being doesn't matter what element of your environment you're talking about your application your infrastructure uh your compliance checks express it in a coded way use exactly the same process and approach that you do for your application

development you know use the same uh source code repositories use the same version controlling use the same pipelining you know you can use the same sorts of test harnesses as long as you can write the test for it and Oh wrong button and you can bring everything to everyone together no matter what part of the business business they're in not just not just the apps but the

the C the office of the ceso you know your your Chief regulatory officer and your uh your infrastructure team to build it all and bring it through um to deploy fully consistently into production and not just in your individual data centers but out there on all those interesting places that exist outside the uh the corporate data center as so what does that bring um well in our

view and and our experience these sorts of approaches do bring a lot of benefits to to an um you know efficiency scalability are are key um you know pretty much every organization is in a in a situation where you know as as a phrase I've heard many times over the years do more with less how how do you do more with less there's there's only two ways

well there's only two ways to do more one is to work harder the other is to work smarter one of those is a much more appealing uh approach to it than the other and that's that's to work smarter because working harder just means more hours longer hours evenings weekends all of that sort of stuff and to be honest we all want to do stuff uh not just

work so by coding everything um you've got audit Trails you've got provability repeatability um you can automate the testing uh you can automate the deployment of everything and for those people who in the in the business need to go out and prove it to an external body you know living in the UK organization like the financial conduct Authority uh The Regulators we've got a lot of them

the office of something or other ofcom is the the office of communications they regulate telecoms um off gen you know they regulate the en energy industry all of those bodies require the organizations that they regulate to be able to prove their compliance with the standards and and all the other things with them and this approach gives you tooling and the information to be able to do that

so uh just to wrap up um uh we'll take questions so yeah if you're not already taking uh the approach that you're using to build your applications and looking at how you can apply that to other um other areas of your organization uh I recommend uh that's worth doing and um at that point uh I'll uh I'll I'll stop talking um and we've got microphones down the

front here um don't know if anyone's played anything with slido but just to to finish off for any questions any discussion points like I say none of my sales colleagues are here I can I can I can be an open as honest as I like it's great um so do we we can check like SL but I see uh okay I said no questions but now we

have one question okay yeah here maybe I can read it could you please provide a specific example of policy as code okay it's a bit hard to understand from abstraction how does it uh Sher it be different typo snd next to each other on the keyboard somebody has borrowed my fingers when typing um because my my typing is terrible and the more people are watching me me

type the worse I get um so policy is code so it's um it's it's really about what it is your you're covering so um the the infrastructure code piece um that the traditional Chef configuration management and there are other tools out there like I say no sales colleagues here I can be be honest at that we cover things like you know this is the version of the

operating system that needs to be installed um and then I'm going to configure things about my operating system so what ports am I going to open in the firewall on the server which packages do I need to be installed what version of those packages what are the config files for those packages look like you know if if it's a web server do I have a standard homepage

that gets deposited in there or do I have other content related to to that if it's an application server how's that configured you know what does it relate to you know if I'm going to deploy a database how's my database setup what's my defaults on on the database and that side of it um so that's your infrastructure piece um and then you've deployed an application to go

on top of that now while that's running um how do we check the state of that how do we how do we prove that what we we how we think the server or the instance of the application should be is actually the case so we can we we want to be able to run tests against that deployment outside of the deployment itself so we don't ever want

to Mark our own homework if we can avoid it so if we have a second framework and uh and jef does this and there again there are other Solutions out there in the market that do the same thing that can come in and look at that deployment and go run a test so you know is this particular kernel module disabled for example um you know how's my

user access and user management configured in there do I have appropriate password standards that are compliant with my corporate password so it's the is the minimum length what it should be you know is the rotation policy what it should be is the complexity policy what it should be is the history length policy what it should be um you know what ports do I have open within there

um and and and what protocols are they supporting so policy is policy is code is is is a broader encompassing than than just your infrastructure it's about running that security and compliance testing uh alongside it um and then being able to report back on that so that your uh uh so that your your business owners can go to you know the cxos who need it and they

can go to the external bodies to need it and go yes we've done this and there how we've done the deployment but more importantly here's the proof because what the external bodies care about is they don't believe you they want you to prove it that's that's my experience so that's what it is policy is code is a more broader all-encompassing uh view of and um covers more

than it I see there's another one come up what stack do I recommend um so if my salespeople were here there's only one answer to that question um the honest um is you know there are multiple Solutions out there in the market um so one um you know the whole stack includes everything um not just the the the sort the aspects that that we do as chef

and and our competitors do so many of you you know probably our biggest competitor on the configuration management side is is anable and I know anable as well I spent nearly a decade working at at Red Hat uh so familiar with that as a solution um so from a stack perspective um is you know again also look at what you already have so if you've got a

lot of devops processes in place for your application start from there no point in Reinventing the wheel um definitely not so you know if you've got a if you've got a source code repo you've got version controlling you've got all of those processes already in place just you know the same Tech works for application code code for infrastructure code for compliance code no problem at all you

got a pipeline existing pipeline you know maybe you know using Jenkins you're using Maven whatever you're using you know no reason to look to move away those same tools and Technologies can be used again extending from just your application code to your infrastructure code to your compliance code um you need to write some different testing harnesses potentially or typically um uh to go through that piece but

you know start with what you've got would be my my my honest recommendation if you've got something that works for for you now for the application side look to extend its use improve its value um and then um yeah look to way you you might have the the gaps and then how you how you might want to do the configuration management how you might want to do

the compliance piece and there are many aspects to to compliance it's a whole another subject in terms of what you want to check um so from our point of view we uh build and provide things like uh the standard CIS profile so standard D6 um out of the box we what we don't do is is vulnerability scanning that's a whole another area as well so you may

need some tooling for that and automate that process as well um so yeah the answer is you know find start with what you've got see where you're get are and then evaluate the tools that will will help plug those gaps so bringing into external body with uh yes that's part of absolutely um you know I you know in the in the UK we have some quite heavy

regulation in certain industries doesn't always work very well news uh from the UK newspapers and see the state of some of our our rivers and things like that at the moment you go uh maybe some of that's not doing well that's that's not it regulation that that that's other regulation um but yeah a lot of uh what external bodies want they they don't want to know that

you they they want to know you're doing it but they want you to be able to prove it to them you know they want that you to get to be able to give you the rubber stamp to go yes you've said you're compliant with our whatever our standard is uh you've shown me I'm happy you can carry on being a bank you can carry on being a

health care provider or or whatever it is uh because if a bank loses its banking license it has a bit of a problem um something similar uh and I think I'm probably about to get the the the wrap-up or the hook or whatever the the the thing is yeah um so thank you very much for for being here thank you for your time thank you for uh

the questions uh and enjoy the rest of the conference yeah please guys give a warm welcome and Applause like to Peter yeah thank you very much uh that's yeah