<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DevOps Updates &#8211; Best DevOps</title>
	<atom:link href="https://www.bestdevops.com/category/devops-updates/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.bestdevops.com</link>
	<description>Lets Learn, Do it &#38; Share! Thats a Best DevOps!!!</description>
	<lastBuildDate>Thu, 05 Feb 2026 05:35:42 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.1</generator>
	<item>
		<title>How do we become DevOps certified professionals (DCP)?</title>
		<link>https://www.bestdevops.com/how-to-become-a-devops-certified-professionals-dcp/</link>
		
		<dc:creator><![CDATA[rahulkr]]></dc:creator>
		<pubDate>Fri, 13 Aug 2021 13:09:45 +0000</pubDate>
				<category><![CDATA[Continuous Delivery]]></category>
		<category><![CDATA[Continuous Deployment]]></category>
		<category><![CDATA[Continuous Inspection]]></category>
		<category><![CDATA[Continuous Integration]]></category>
		<category><![CDATA[DevOps]]></category>
		<category><![CDATA[DevOps Best Practices]]></category>
		<category><![CDATA[DevOps Process]]></category>
		<category><![CDATA[DevOps Tools]]></category>
		<category><![CDATA[DevOps Updates]]></category>
		<category><![CDATA[Benefits]]></category>
		<category><![CDATA[certifications]]></category>
		<category><![CDATA[DevOps Course]]></category>
		<category><![CDATA[DevOps development]]></category>
		<category><![CDATA[DevOps Training]]></category>
		<guid isPermaLink="false">https://www.bestdevops.com/?p=19059</guid>

					<description><![CDATA[What is DevOps? To knowing DevOps. First, you have to understand DevOps. But today we are not going to put [&#8230;]]]></description>
										<content:encoded><![CDATA[
<h1 class="wp-block-heading"><strong>What is DevOps?</strong></h1>



<div class="wp-block-image"><figure class="aligncenter size-full is-resized"><img fetchpriority="high" decoding="async" src="https://www.bestdevops.com/wp-content/uploads/2021/12/360_F_282378637_7DL904AvZkZovk3RqLdLwNe21RNcjpzg.jpg" alt="" class="wp-image-22575" width="841" height="362" srcset="https://www.bestdevops.com/wp-content/uploads/2021/12/360_F_282378637_7DL904AvZkZovk3RqLdLwNe21RNcjpzg.jpg 836w, https://www.bestdevops.com/wp-content/uploads/2021/12/360_F_282378637_7DL904AvZkZovk3RqLdLwNe21RNcjpzg-300x129.jpg 300w, https://www.bestdevops.com/wp-content/uploads/2021/12/360_F_282378637_7DL904AvZkZovk3RqLdLwNe21RNcjpzg-768x331.jpg 768w" sizes="(max-width: 841px) 100vw, 841px" /></figure></div>



<p class="wp-block-paragraph">To knowing DevOps. First, you have to understand DevOps. But today we are not going to put some definitions. Now we are willing to understand the whole concept of DevOps professionals. We are going to discuss every aspect of DevOps professionals. We have to understand the old days of <a href="https://www.devopsschool.com/">software</a> delivery. How you were consuming the software in old days. Actually, you were using multiple software in the back years like the 19th century includes 95, 97, and 98. Now, we are seeing many sorts of applications concerning delivering performance in new days. We have seen so many times of using applications by users through downloading and installation process.</p>



<p class="wp-block-paragraph">Now, come to the point, we are talking about DevOps. The meaning of DevOps is development and operations collaboration which is done by software teams. By development of software. How it can redefine the whole automation of the software industry? It enhances your mindset for software development. There are many assumptions along with software operations. By the development of software. We take the following steps like manipulating software through engineers from one phase to another and by checking the functions of applications that are out to date and up to date.</p>



<h1 class="wp-block-heading"><strong>What are the benefits of DevOps professionals?</strong></h1>



<p class="wp-block-paragraph">After looking at the term ‘DevOps’. DevOps is a very popular trend in the software industry. &nbsp;Now, we are going to talk about the privileges or benefits of DevOps professionals. There are many sorts of benefits along with the DevOps software industry. Some of the main benefits associated as:</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.bestdevops.com/wp-content/uploads/2021/08/large.jpg" alt="" class="wp-image-19061" width="609" height="380" srcset="https://www.bestdevops.com/wp-content/uploads/2021/08/large.jpg 960w, https://www.bestdevops.com/wp-content/uploads/2021/08/large-300x188.jpg 300w, https://www.bestdevops.com/wp-content/uploads/2021/08/large-768x480.jpg 768w" sizes="(max-width: 609px) 100vw, 609px" /></figure>



<ul class="wp-block-list"><li><strong>Release velocity</strong>: It helps in increasing the release velocity. We can release code for more production and with confidence.</li><li><strong>Development cycle</strong>: Through it, the complete development cycle from initial design to production deployment becomes shorter.</li><li><strong>Deployment rollback:</strong> In this field, we plan for any failure in deployment rollback due to an error in code or issue in production. This gives confidence in feature release without worry about the rollback in spare time.</li><li><strong>Defect detection</strong>: With DevOps associate, we can catch defects much faster than releasing them to production. It simplifies the software quality.</li><li><strong>Recovery from failure</strong>: In case of collapse, we can recover very fast with this process.</li><li><strong>Collaboration:</strong> Through it, a collaboration between development and operations professionals increase.</li><li><strong>Performance-oriented:</strong> Through it, entity follows performance-oriented culture in which teams become more productive and more innovative.</li></ul>



<h1 class="wp-block-heading"><strong>Why we should learn DevOps?</strong></h1>



<p class="wp-block-paragraph">After learning the benefits of it. We are going to discuss the reasons why we learn DevOps? There are certainly reasons to learn about DevOps. It covers continuous software delivery, less complexity to manage, and faster resolution to problems in technical areas. In cultural areas, it handles the teams are more productive and happier, the employees are more engaging, and greater professional development opportunities. In business areas, it manages faster delivery time, improved communication and collaboration and more time to innovate, and greater customer experiences. With its exposure to trending technologies and advanced tools by DevOps certifications, you can increase your professional credibility.</p>



<div class="wp-block-image"><figure class="alignright size-full is-resized"><img decoding="async" src="https://www.bestdevops.com/wp-content/uploads/2021/08/images.jpg" alt="" class="wp-image-19063" width="598" height="368" /></figure></div>



<h1 class="wp-block-heading"><strong>How our DevOps course/ training would help?</strong></h1>



<p class="wp-block-paragraph">Now, after getting the learning process. I will explain to you how DevOps courses/ training helps you to make a software developer or software developer engineer from beginner to advanced level? it gives you knowledge- based on training or courses which will help you in the field of software development. DevOps gives you lots of popularity around the world. It skills huge demand and DevOps professionals are one of the highest-paid in the IT industry. If you become a DevOps engineer/ developer then it makes huge impacts on the sectors of IT. This is the recent situation in which you can get jobs as a DevOps engineer. Through this tutorial, I do assume that you will get all your answers to questions. &nbsp;</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy"  id="_ytid_11544"  width="675" height="379"  data-origwidth="675" data-origheight="379" src="https://www.youtube.com/embed/LB9D-HDdAFg?enablejsapi=1&#038;autoplay=0&#038;cc_load_policy=0&#038;cc_lang_pref=&#038;iv_load_policy=1&#038;loop=0&#038;rel=1&#038;fs=1&#038;playsinline=0&#038;autohide=2&#038;theme=dark&#038;color=red&#038;controls=1&#038;disablekb=0&#038;" class="__youtube_prefs__  epyt-is-override  no-lazyload" title="YouTube player"  allow="fullscreen; accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen data-no-lazy="1" data-skipgform_ajax_framebjll=""></iframe>
</div></figure>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Transitioning from DevOps to DevSecOps</title>
		<link>https://www.bestdevops.com/transitioning-from-devops-to-devsecops/</link>
					<comments>https://www.bestdevops.com/transitioning-from-devops-to-devsecops/#respond</comments>
		
		<dc:creator><![CDATA[anil]]></dc:creator>
		<pubDate>Tue, 24 Sep 2019 05:46:29 +0000</pubDate>
				<category><![CDATA[DevOps]]></category>
		<category><![CDATA[DevOps Updates]]></category>
		<category><![CDATA[Advance-security]]></category>
		<category><![CDATA[Deployment technology]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[IT operations]]></category>
		<guid isPermaLink="false">http://www.bestdevops.com/?p=8012</guid>

					<description><![CDATA[Source:- securityboulevard.com Introduction DevOps is essentially the combination of software development and IT operations, and it is found in many [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Source:- securityboulevard.com<br></p>



<h2 class="wp-block-heading">Introduction</h2>



<p class="wp-block-paragraph">DevOps is essentially the combination of software development and IT operations, and it is found in many enterprise environments. DevOps initially started as a process that fostered an agile type of relationship between developers and IT operations teams. This led to much more rapid development and deployment times and facilitated better communication between different departments within the organization.</p>



<p class="wp-block-paragraph">DevOps helped developers to better understand the operational requirements of the organization while letting the operations side see how the development process would affect the daily functioning of the systems within the organization. The deployment technologies could be built into the software which meant that the finished products could be shipped in record time.</p>



<p class="wp-block-paragraph">DevOps merges many different disciplines together and has a large focus on automation. As the name suggests, software development frameworks and concepts become a fused team that works towards the same goal.</p>



<p class="wp-block-paragraph">Because DevOps treats much of the operational work with the same processes that software development does, it’s possible to roll out large-scale deployments with very little human intervention while still maintaining high visibility within the environment that it is operating in. Automation makes deployments much easier and faster to accomplish.</p>



<p class="wp-block-paragraph">Many DevOps professionals are finding that the increased focus of security requirements is changing the way that applications are developed, and this means changing the way that products are created. We are going to find out how you can transition into DevSecOps and how you can leverage your skills and apply them to this important role.<br></p>



<h2 class="wp-block-heading">What is DevSecOps?</h2>



<p class="wp-block-paragraph">On the surface, DevSecOps is very similar to DevOps, but it has enhanced protections built into the process. This is because many security best practices are now integrated into the products that are being developed. DevSecOps relies on collaborations and teamwork to create more secure applications while continuing to provide non-stop improvements to the code. DevSecOps builds security into the foundations of the application from the very beginning, creating enhanced protections that make the application more difficult to compromise.</p>



<p class="wp-block-paragraph">DevSecOps breaks away from traditional developer environments. This is because the compartmentalized nature of legacy development structures has to be drastically altered in a DevSecOps environment. There is a general shift from siloed departments, and DevSecOps encourages lots of collaborative efforts and teamwork.</p>



<p class="wp-block-paragraph">Historically, it has always been the job of the developer to create an application or system, while the operations team’s role was to use, administer and maintain it and the SOC team had to try and build security around the application. What we see in DevSecOps is a combined team effort between all three of those pillars of the organization, which results in much more secure applications and products.</p>



<h2 class="wp-block-heading">Where does a DevSecOps professional get started?</h2>



<p class="wp-block-paragraph">The natural pathway for many DevSecOps pros is traditionally through a DevOps role, but this doesn’t tell us very much. DevOps has many potential roles, from programmers to network engineers, security analysts, auditors and systems architects. From an information security perspective, there are also many different roles that you could perform.</p>



<p class="wp-block-paragraph">The main difference between DevOps and DevSecOps is the time at which the security team starts to contribute. In the early days of software development, security was often seen as an afterthought. Many security features were tacked onto the application after the main components had been built, which led to many weaknesses in application security and some overlooked security bugs that would only be discovered and addressed after the product had been launched. DevSecOps applies security from the very beginning and is involved in every step of the planning and development process.</p>



<p class="wp-block-paragraph">Programmers and developers are most concerned with completing the product and having it function correctly, while security analysts are willing to implement more controls to harden the application. This can lead to extra work, but the benefits of having a secure application far outweigh a potential security hole in an insecure release.</p>



<p class="wp-block-paragraph">The organization that you are working at has to be fully behind the idea of a DevSecOps approach in their development strategy, as it requires a shift away from traditional development methodologies.</p>



<p class="wp-block-paragraph">Another vital aspect that is often overlooked is the increased popularity of cloud-based services in recent years. Finding a candidate with the prerequisite knowledge to perform all of these functions is tough. Last but not least, you need to have a background or a working knowledge of information security. In order to make recommendations about secure code and potential security issues, you need to be able to understand the concepts behind security.</p>



<h2 class="wp-block-heading">Why DevSecOps?</h2>



<p class="wp-block-paragraph">Automation has always been at the heart of the DevOps approach, so it should come as no surprise that DevSecOps is able to automate security audits. It uses a combination of automated scripts and tools that test the security of the application, the containers that elements reside in and the pipe itself. Security is built into the applications from the very beginning and auditing tests all of the potential weaknesses in the implementation as the product is built.</p>



<p class="wp-block-paragraph">Early detection of security loopholes happens much faster in a DevSecOps environment. This is because of the continuous iterations of secure code that are fed into the pipe, allowing for automated testing to occur daily.</p>



<p class="wp-block-paragraph">Broken tests mean that the pipe is working correctly and that security issues are being picked up before a deployment happens. Not all failures are negative, and a broken build often means that the testing environment is picking up issues before they are released to clients.</p>



<p class="wp-block-paragraph">Audit trails are often built into this process, which means extensive logging needs to occur at each step of the DevSecOps process. If code ever gets audited, then there needs to be a trustworthy and accurate history of development. This is sometimes known as a “trust, but verify” approach, especially when a postmortem of a failed test is conducted.</p>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">The transition from DevOps to DevSecOps requires full commitment from everyone involved in the process. Silos and separation of departments need to be replaced with open and honest communication. Constant feedback and code assessments need to be carried out at every step of the process if DevSecOps is going to succeed. The same is true of code audits, as they need to be carried out on a daily basis with each new commit and update.</p>



<p class="wp-block-paragraph">All of this needs to happen without slowing down the actual development. Failure isn’t a bad thing, and any issues need to be dealt with and rectified as soon as they appear.</p>



<p class="wp-block-paragraph">Documentation and written processes must also be maintained so that future development teams are able to look back and read accurate explanations and decently commented code. But these practices do not form overnight. There is a real need for cultural shifts within the organization, allowing the developers and security teams to work together and help one another. If teams compete with each other and assign blame then the end product will suffer, along with the company’s paying customers.</p>



<p class="wp-block-paragraph">Security needs to be encouraged and developed within the teams if securely developed applications are to be released with increased frequency and efficacy.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.bestdevops.com/transitioning-from-devops-to-devsecops/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>This monster 86-hour bundle will kickstart a DevOps career</title>
		<link>https://www.bestdevops.com/this-monster-86-hour-bundle-will-kickstart-a-devops-career/</link>
					<comments>https://www.bestdevops.com/this-monster-86-hour-bundle-will-kickstart-a-devops-career/#respond</comments>
		
		<dc:creator><![CDATA[anil]]></dc:creator>
		<pubDate>Sat, 13 Jul 2019 06:03:44 +0000</pubDate>
				<category><![CDATA[DevOps Tools]]></category>
		<category><![CDATA[DevOps Updates]]></category>
		<category><![CDATA[Ansible Automation For Beginners]]></category>
		<category><![CDATA[DevOps career]]></category>
		<category><![CDATA[Elasticsearch & the Elastic Stack]]></category>
		<category><![CDATA[Kubernetes Using Docker]]></category>
		<guid isPermaLink="false">http://www.bestdevops.com/?p=6158</guid>

					<description><![CDATA[Source:-androidguys.com Jump on the hot new trend that combines IT and operations into one kick-ass team. What do you with [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Source:-androidguys.com</p>
<p>Jump on the hot new trend that combines IT and operations into one kick-ass team.</p>
<p>What do you with your spare time? Are you a couch potato type who binges show after show? Hey, that’s cool. You do you. We don’t judge.</p>
<p>If you’re a driven type of person who likes to stay sharp, learn new things, or challenge yourself, you might like the current deal in the AndroidGuys Deals Store. It’s the perfect way to master new skills on your own schedule. And, best of all, it’s tech-related and could lead to a new career. Oh, and it’s dirt cheap right now!</p>
<p>DevOps is the hot new approach that’s sweeping the tech landscape. It combine IT and operations teams into a single, make for a coordinated and optimized powerhouse. DevOps enables companies and organizations to create products and software with incredible efficiency. In other words, it’s a valuable skill to learn to say the least.</p>
<p>Buying an unlocked phone? Consider these questions<br />
The DevOps Master Class Lifetime Bundle is a 10-course collection of disciplines that take you from idea, to development and testing, up through deployment.</p>
<p>Over 86 hours of education await you, with instruction on:</p>
<p>Ansible Automation For Beginners to Advanced ($99 value)<br />
Introduction to Kubernetes Using Docker ($99 value)<br />
Fundamentals of Unix &amp; Linux System Administration ($99 value)<br />
Become An AWS Certified Solutions Architect – Associate ($99 value)<br />
Projects in Hadoop and Big Data: Learn by Building Apps ($99 value)<br />
AWS Certified Solutions Architect Professional Exam Guide ($99 value)<br />
Docker for Professionals: The Practical Guide ($99 value)<br />
The Python Mega Course: Build 10 Real World Applications ($99 value)<br />
DevOps Tutorial: Complete Beginner Training ($99 value)<br />
Elasticsearch &amp; the Elastic Stack ($99 value)<br />
Altogether, these ten courses would run $1,000 if you were to purchase individually, but this limited-time deal puts them at just $39. That’s less than $4 per course!</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.bestdevops.com/this-monster-86-hour-bundle-will-kickstart-a-devops-career/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Global DevOps Platform Market 2019 – Puppet Labs, Chef, Docker Inc., Red Hat (Ansible), Atlassian</title>
		<link>https://www.bestdevops.com/global-devops-platform-market-2019-puppet-labs-chef-docker-inc-red-hat-ansible-atlassian/</link>
					<comments>https://www.bestdevops.com/global-devops-platform-market-2019-puppet-labs-chef-docker-inc-red-hat-ansible-atlassian/#respond</comments>
		
		<dc:creator><![CDATA[anil]]></dc:creator>
		<pubDate>Wed, 03 Jul 2019 05:37:22 +0000</pubDate>
				<category><![CDATA[DevOps Updates]]></category>
		<category><![CDATA[DevOps security]]></category>
		<category><![CDATA[Docker]]></category>
		<category><![CDATA[Global DevOps]]></category>
		<category><![CDATA[Puppet Labs]]></category>
		<guid isPermaLink="false">http://www.bestdevops.com/?p=5848</guid>

					<description><![CDATA[Source :- exclusivereporter24.com The Global DevOps Platform Market Report 2019-2026 includes a comprehensive analysis of the present DevOps Platform Market. It [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Source :- exclusivereporter24.com</p>
<p>The Global DevOps Platform Market Report 2019-2026 includes a comprehensive analysis of the present DevOps Platform Market. It specifies the DevOps Platform market size and also factors controlling the growth of the market. The report starts with the basic DevOps Platform Market industry overview and then goes into minute details of the Automotive Connected Infotainment System Market.</p>
<p>The DevOps Platform market Report contains in depth information of major drivers, opportunities, challenges, industry trends and their impact on the market. The DevOps Platform Market report also provides data about the company and its operations. This report also provides information on the Pricing Strategy, Brand Strategy, Target Client of the DevOps Platform Market. Also provides Distributors/Traders List offered by the company. This research report also involves key competition, market trends with forecast over the predicted years, anticipated growth rates. The primary factors driving and impacting growth market data and analytics are derived from a combination of primary and secondary sources.</p>
<p>Leading key players of DevOps Platform market are:</p>
<p>Puppet Labs<br />
Chef<br />
Docker Inc.<br />
Red Hat (Ansible)<br />
Atlassian<br />
Saltstack<br />
CA Technologies<br />
Rackspace<br />
XebiaLabs<br />
VersionOne<br />
Cisco<br />
CollabNet<br />
HP<br />
IBM<br />
Microsoft<br />
Spirent Communications plc<br />
Vmware<br />
DBmaestro</p>
<p>Major highlights of the DevOps Platform market report:<br />
DevOps Platform Market Overview, Market shares, and strategies of key players, Sales Market Forecast, Industry Analysis of DevOps Platform Market and its Driving Factor Analysis, Market Competition Status by Major Key Players, Upstream and Downstream Market Analysis of DevOps Platform Market. Also Contains Cost and Gross Margin Analysis of DevOps Platform Market.</p>
<p>The scope of the report:<br />
This report focuses on the DevOps Platform market global as well as the regional market. The report is categorized based on the end user, regions &amp; application. The various key player in the current market is listed in this report. Key players are elaborately discussed in this report along with their revenue in promising regions.</p>
<p>Global DevOps Platform Market segmentation:</p>
<p>Segmentation on the basis of type:</p>
<p>DevOps Ready<br />
DevOps Enabled<br />
DevOps Capable</p>
<p>Segmentation on the basis of Application:</p>
<p>IT<br />
BFSI<br />
Retail<br />
Telecom<br />
Education<br />
Others</p>
<p>Enquiry Before Buying @ https://www.eminentmarket.com/report/global-devops-platform-market-by-product-type-devops-117955/#inquiry</p>
<p>The DevOps Platform market report majorly split into many regions, covering:<br />
• North America (the United States, Canada, and Mexico)<br />
• Europe (Germany, France, UK, Russia, and Italy)<br />
• Asia-Pacific (China, Japan, Korea, India, and Southeast Asia)<br />
• South America (Brazil, Argentina, Colombia, etc.)<br />
• The Middle East and Africa (Saudi Arabia, UAE, Egypt, Nigeria, and South Africa)</p>
<p>Main Features of the Global DevOps Platform Market Research Report:<br />
1. The report offers market values and anticipated growth rate of the global DevOps Platform market for all years till 2023.<br />
2. The report describes the actual drivers of global DevOps Platform market by considering and taking calculated risks, as well as identifying and testing new tactics.<br />
3. The research report conduct separate industry chain analysis that covers upstream raw material suppliers information, the production process of DevOps Platform, manufacturing cost, raw material cost, labor cost, market channels and downstream buyers of the DevOps Platform market.<br />
4. The report gives immense knowledge on the competitive nature of the global DevOps Platform market, and discuss various marketing strategies to stay ahead in the competition.<br />
5. The report analyzes the market segments and provides the relative contribution to the development of global DevOps Platform market.<br />
6. This DevOps Platform report is an essential tool to check the feasibility of a new project, improve the productivity and geographical expansion of the company.</p>
<p>In a word, the DevOps Platform Market report provides major statistics on the state of the DevOps Platform industry with a valuable source of guidance and direction for companies and individuals interested in the market. At the end DevOps Platform Market Report delivers a conclusion which includes Research Findings, Market Size Evaluation, Global Market Share, Consumer Needs along with Customer Preference Change, Data Source. These factors will raise the growth of the business overall.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.bestdevops.com/global-devops-platform-market-2019-puppet-labs-chef-docker-inc-red-hat-ansible-atlassian/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Portable Security Policies: A DevSecOps Primer</title>
		<link>https://www.bestdevops.com/portable-security-policies-a-devsecops-primer/</link>
					<comments>https://www.bestdevops.com/portable-security-policies-a-devsecops-primer/#respond</comments>
		
		<dc:creator><![CDATA[anil]]></dc:creator>
		<pubDate>Tue, 02 Jul 2019 05:44:10 +0000</pubDate>
				<category><![CDATA[DevOps Updates]]></category>
		<category><![CDATA[Continuous Delivery]]></category>
		<category><![CDATA[Deploy]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">http://www.bestdevops.com/?p=5816</guid>

					<description><![CDATA[Source :- devops.com Protecting critical data and applications is a challenge under any circumstances, but it’s especially daunting when resources reside [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Source :- devops.com</p>
<p>Protecting critical data and applications is a challenge under any circumstances, but it’s especially daunting when resources reside in the cloud. Most organizations today operate a significant portion of their workloads in the cloud, which adds to the complexity of the security problem—a security team can’t fully control cloud environments but is responsible for securing workloads and applications running there.</p>
<p>Cybercriminals are exploiting the situation. They’re becoming more aggressive and ingenious in their efforts, taking advantage of the fact that there is confusion about who is responsible for which aspects of security under the Shared Responsibility Model. Adding to the chaos is the differentiation between cloud providers’ security offerings and capabilities. Quite simply, in most cases, cloud providers are responsible for the security of the cloud and consumers are responsible for security in the cloud, meaning that security and networking teams still need to ensure their organizations’ workloads and applications are free from malware or other tampering.</p>
<p>To accomplish this, security and networking teams can’t rely solely on firewalls, threat detection and vulnerability patching to secure vital digital assets. Security tools developed for traditional data centers are not effective at securing workloads in the cloud due to the cloud’s dynamic nature. Security and networking teams must rethink their approach.</p>
<p>Unfortunately, many organizations are still relying on old and ineffective strategies—further hardening the perimeter, investing in additional threat detection and adding new tools and controls that focus on identification rather than prevention. This security approach has its place, but it does nothing to prevent malicious actors from moving laterally across the network once they achieve a foothold, which leaves cloud-hosted apps and workloads extremely vulnerable.</p>
<p>Instead, security teams need to enable zero trust in cloud environments, which treats all internal communications as untrusted by default. With zero trust, only authorized applications and services are allowed to send and receive communications, and only in specific ways governed by the principle of least privilege.</p>
<p>The Second Layer<br />
Traditional tools aren’t effective in enabling zero trust in the cloud because security and ops teams have a very limited ability to manage all layers of the cloud’s open systems interconnection (OSI) model. Specifically, the lack of Layer 2 controls in infrastructure-as-a-service (IaaS) environments makes tools developed for discrete networks all but useless for locking down ports and controlling or scrutinizing IP addresses.</p>
<p>Even if an organization manages to implement these tools in the cloud, it cannot provide the level of granularity required to stop malicious lateral movement. For example, when on-premises tools are repurposed for cloud environments, they usually rely on subnets to define the boundaries of communication. Because cloud subnets are designed to handle elastic workloads, they need to be far larger than those in on-premises environments. As a result, cloud workloads are more exposed than is necessary.</p>
<p>Securely migrating workloads and applications to a cloud environment is a huge and cumbersome job when relying on traditional tooling. The best way to make workloads portable and secure is to decouple workload protection from the underlying infrastructure. In this way, organizations can be certain that any policies applied on-premises can migrate to the untrusted environment of the cloud, without the complexity of mapping changing network addresses, writing policy exceptions or losing fine-grained control during the process.</p>
<p>Decoupling workload protection from the network requires abandoning a network address-based approach in favor of one based on identity. By using the immutable properties of workloads, security teams can create cryptographic identities for applications and services, which then can be used to determine what is allowed to send and receive communications. Not only does this model provide stronger security, but it also works regardless of where applications are located, because these identities are unaffected when network elements change. What’s more, they can be constructed to tolerate upgrades. By building identity-based policies, security teams can create microperimeters around applications that follow workloads wherever they go, and the policies verify communication across boundaries every time an application attempts to communicate.</p>
<p>Implementing network-agnostic policies doesn’t just harden security. Software developers benefit as well. Without the roadblock of translating application-speak to network-speak, developers can build software and applications in any environment favorable to their workflow while defining policies to protect their work. Once the software is built, they can securely deploy the finished product to the production environment—even if it is hosted by a third party.</p>
<p>No organization should have to compromise security to benefit from the efficiencies offered by the cloud and ephemeral auto-scaling containers. Building identity-based policies that enable zero trust and are independent of the underlying network ensures that companies never have to consider making that trade-off.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.bestdevops.com/portable-security-policies-a-devsecops-primer/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How to Seamlessly Evolve DevOps Into DevSecOps</title>
		<link>https://www.bestdevops.com/how-to-seamlessly-evolve-devops-into-devsecops/</link>
					<comments>https://www.bestdevops.com/how-to-seamlessly-evolve-devops-into-devsecops/#respond</comments>
		
		<dc:creator><![CDATA[anil]]></dc:creator>
		<pubDate>Mon, 01 Jul 2019 05:07:13 +0000</pubDate>
				<category><![CDATA[DevOps Updates]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[Docker]]></category>
		<category><![CDATA[Java Spring]]></category>
		<category><![CDATA[Kubernetes Master]]></category>
		<guid isPermaLink="false">http://www.bestdevops.com/?p=5761</guid>

					<description><![CDATA[Source :- infoq.com DevSecOps, by definition, is an evolution of DevOps. The growing philosophy itself is not fully formed and leaves [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Source :- infoq.com</p>
<p>DevSecOps, by definition, is an evolution of DevOps. The growing philosophy itself is not fully formed and leaves a lot to still be defined. For anyone to claim it is anywhere close to a fully-formed set of best practices or rules would be getting ahead of themselves and the philosophy. This should be expected as DevSecOps is relatively new.</p>
<p>This is the nature of DevOps, in general — always improving and never stagnant.</p>
<p>DevOps, as a process, isn’t by any means ancient itself. It has been largely accepted as a means of facilitating cooperation between the various compartments in an IT outfit, compartments that might otherwise remain largely sealed off from one another.</p>
<p>RELATED VENDOR CONTENT<br />
Become a Kubernetes Master – Download the Cheat Sheet<br />
One-click Java Spring PetClinic Web App on Openshift<br />
DevSecOps in Practice – Download the InfoQ eMag<br />
In-Memory Computing Best Practices: Building a Foundation and Roadmap for Digital Transformation<br />
From Docker to Kubernetes: Container Networking 101 (By O’Reilly)<br />
RELATED SPONSOR</p>
<p>NGINX Plus is the complete application delivery platform for the modern web. Start your 30 day free trial.</p>
<p>The development side of IT works directly with the operations side in a fully formed DevOps process. This allows coding and direct software development to work in unison with traditional infrastructural issues like device management, network upkeep, and help desk functions.</p>
<p>DevOps is designed to allow these sides to meet, communicate and more easily improve upon one another’s work in an automatic and streamlined way. One important aspect that has been left by the wayside is security.</p>
<p>Security is an ever-evolving issue that refuses to be solved for any length of time. It is a headache that needed to be included in this DevOps process for lasting impact inside an organization.</p>
<p>There isn’t a better time to address security of a project than throughout the entire project.</p>
<p>Maintain the DevOps Mindset<br />
At its core, DevOps is a business philosophy — a way of structuring and organizing the IT culture at a company. The big selling point behind this philosophy is that it helps create software, test it, and push it to market faster. While this is certainly true, it’s not the whole story.</p>
<p>Creating and releasing software quickly doesn’t mean much if the product produced is not of high quality. To ignore DevOps’ role in quality control would be failing to grasp its true importance and intention. Effective DevOps allows the development and operations arms to harmonize together and create high-level and quality controlled software as quickly as possible.</p>
<p>As DevOps evolved, which it is perpetually doing, it became obvious that these processes, services, and tools needed to include far more than just software development and operations management. With each new story of a massive data breach and its catastrophic consequences, cybersecurity swiftly became recognized as a critical part of any IT ecosystem. This realization led to DevSecOps.</p>
<p>Transition to and Embrace DevSecOps<br />
The goal is to make security part of the development workflow.</p>
<p>As mentioned, DevSecOps is the natural extension of DevOps. The process is meant to do two things: It can either take the benefits that DevOps gives to the development and operations branches of your IT department and extend them to the security team or it can integrate the security processes that need to be done into the DevOps team.</p>
<p>In DevOps, creating and releasing software quickly doesn’t mean much if the product produced is not of high quality. Does it mean much if the product produced isn’t secure?</p>
<p>Security was being ignored in a process where it logically should have been the main component. Companies truly could not afford to ignore this conundrum any longer.</p>
<p>There are three basic ways of breaking down DevSecOps for any organization:</p>
<p>As a series of technological protocols, like multi-factor authentication or zero-trust, that you implement to secure your DevOps processes.<br />
Perpetual verification can get tiring but not allowing anything through without being checked is one of the few ways to stop almost every threat coming from the outside. This process allows threats to almost always be diagnosed from the inside.<br />
As a series of processes dictating when and how to apply security checks to everything that you do in DevOps.<br />
Specific scenarios call for more security checks more than others. Identifying and laying out which process needs more security attention than others allows most security threats to be rooted out.<br />
As a philosophy of cooperation and shared ownership in which members of your development, operations, and security teams collaborate together, each taking responsibility for some things that would normally be outside of their purview.<br />
As the basis of DevOps is cooperation, this is the most important aspect of DevSecOps. Bringing another focal point into the fold will almost certainly be met with resistance from team members but the long term benefits make it worthwhile.<br />
These three ways of looking at DevSecOps ultimately improve cooperation among the disparate IT team departments. In particular, the transition from DevOps to DevSecOps improves the team’s ability to detect and mitigate threats earlier in the development process.</p>
<p>Subscribing to all three options ensures that no stone is left unturned and leads to the best results in terms of maintaining or even improving current development goals while addressing the security issues that need to be addressed. The goal isn’t to tear everything down. The goal is to empower.</p>
<p>Use the DevSecOps Philosophy in Action<br />
DevSecOps isn’t possible by going about normal day-to-day DevOps processes. You can’t tell team members to just be more mindful about security and expect better results. Security team members can’t randomly jump into the development process and expect to make friends with developers.</p>
<p>How, then, does DevSecOps actually work in practice? The philosophy of DevSecOps is one thing, the practice of DevSecOps is another. In essence, there are three major elements to this new iteration of DevOps:</p>
<p>Microservice-Based Infrastructure<br />
Dissecting your entire infrastructure can be a clunky and unwieldy process. Once it is actually accomplished, your whole process — developing software, configuring infrastructure and running security checks — is broken up into tiny parts, each with specific individual functions. This enables your infrastructure to turn into a well-oiled machine.</p>
<p>After everything becomes hyper-specialized, segmented and well-defined, it becomes easier to monitor each step of the process and make necessary upgrades on a gradual level.</p>
<p>This also allows each individual or small team the ability to claim a process as their own. The blame game will not rear its ugly head and team cooperation will reach higher levels. DevSecOps relies on team cooperation to the same degree as DevOps, possibly even more.</p>
<p>Again, the goal is not to tear everything down. Dissecting an entire infrastructure is done on paper. Once dissected, a company can figure out how to specialize and segment in an efficient manner that will cause the least amount of disruption possible in practice.</p>
<p>Continuous Feedback<br />
To start, tearing down the infrastructure requires feedback. Each team and possibly each team member should have a say on the hypothetical dissection of the organization. Starting from ground zero on a feedback-based system is the ideal approach.</p>
<p>In a DevSecOps-tuned environment, developers receive continuous feedback regarding the state of their systems. This constant flow of updated information lets your team know where it stands in relation to security threats. With security blended into the mix, everyone gets the latest information and can efficiently implement necessary security patches and updates.</p>
<p>Without continuous feedback, new processes are daunting to individual members of a team. Continuous feedback is necessary to keep your I.T. team focused and inspired. When a task has been completed the same way for long periods of time, sometimes years, continuous feedback is necessary to achieve efficiency and proficiency.</p>
<p>A key detail that must be kept in mind: feedback does not only originate from management. Feedback should be oozing from every team in the DevSecOps process. If the team is truly segregated in development, security, and operations — each team will have responsibilities to the other teams and should be providing feedback back and forth multiple times a day.</p>
<p>Automation<br />
Artificial intelligence and machine learning both have the potential to streamline almost everything, reduce human error, and dramatically speed things up. The kicker is that it has to be properly applied to your security checks and other processes. Automation is well and good but challenges arise when it is implemented improperly.</p>
<p>Most DevOps processes instill a hefty dose of automation. Teams that are starting from the ground floor should start slow to avoid overwhelm and confusion among the team. Automation does not only mean AI. Implementing the use of the highest quality of basic software — such as a malware scanner, VPN, and two-factor authentication tool — among your team can help shore up security practices immediately.</p>
<p>If developers must go out of their way to initiate scans, there&#8217;s a good chance they will abandon the scanning tool. Two-factor authentication is already adding a small time gain on a task and should be automatic when accessing anything. A good rule is to not annoy the developers.</p>
<p>In an effort not to overthink basic security and think of automation as a complex tool filled with advanced AI, the basics shouldn’t be ignored. Automation does include advanced AI a lot of the time. However, in simple terms, it is taking a task that took time and making it so that task can be accomplished without the time it used to take.</p>
<p>After the basics, the assistance that AI and ML provide in cybersecurity is especially invaluable, as they not only automate basic and essential security protocols, but can actually learn, evolve, and adapt to newly emerging threats.</p>
<p>DevOps tools have been around for a while now. Tools specifically created for DevSecOps exist but come with criticism. Some call DevSecOps tools DevOps lipstick on an old pig. Patience should be urged to the burgeoning DevSecOps community as new tools will come with time.</p>
<p>Train Developers on Secure Coding<br />
The beginnings of DevSecOps aren’t concrete but the origins can be vaguely traced back to the simple phrase of security as code. The issue is that security as code isn’t the first thing learned by most developers.</p>
<p>Retraining an entire development team on secure coding isn’t just a challenge in terms of retraining — it’s expensive. Having the time and money to go through this training is rare. It is necessary to ensure a smooth transition from DevOps to DevSecOps.</p>
<p>The main issue is that developers don’t know or think that there is any issue with their code. Security as code usually isn’t the first thing a development team worries about. This needs to change for the DevSecOps process to take hold.</p>
<p>Avoid Difficulties Transitioning to DevOps or DevSecOps<br />
Though the advantages of effective DevSecOps, both in terms of quality control and increased cooperation and efficiency, are immense, DevSecOps is as much about people as it is anything else.</p>
<p>Even on the best teams, people can sometimes be difficult. Introducing your people to a new way of organizing how they work together — one significantly different from the way they are used to working — can create friction in the following areas:</p>
<p>Learning to accommodate developers set in their ways and resistant to large-scale reorganization. Implementing DevSecOps reduces error in code but this can be met with resistance from the people actually implementing the code. This can be seen as not trusting the development team and met with resentment.</p>
<p>Resolution of these types of issues are done through communication and compromise. Something as simple as choosing a hosting service can be achieved artfully. A developer may want to use a “developer cloud” hosting service, ie one with a developer-friendly product ecosystem, such as Salesforce-owned Heroku or the widely-loved DigitalOcean cloud hosting.</p>
<p>Ensuring each service a developer wants to use is secure gives the security team more work. This may lead security experts down the path of choosing a service that is tried and true. Performing a security audit on a specific developer-centric service and going with said service. is one way to achieve compromise.</p>
<p>Trust issues between the different arms of your IT department leading to less-than-ideal cooperation. Similar to accommodating developers, each column of an organization has opinions of the other teams. Bias can lead to a member of the security team not trusting a developer or a developer not trusting someone dealing with infrastructure processes.</p>
<p>These problems aren’t new to DevOps, and incorporating another team can lead to more. This is where cooperation and team members from different disciplines working side-by-side comes into play. Integrating members from different teams into new crossover teams leads to community.</p>
<p>An over-reliance on AI and automation that allows human diligence to slip. With DevSecOps gaining steam, automation software is running rampant. Listen to any of the big names in DevOps give a presentation and you will be met with warnings of over-reliance of automation. One day, this whole process may be done by machines. Humans are still the movement machination of the DevSecOps process as it stands in the present.</p>
<p>Automation must be done slowly and carefully. If one piece of automation falls apart, the whole system is compromised. Start with the basics and move from there.</p>
<p>These are difficult problems that can be overcome. Lack of trust and poor collaboration between departments is precisely the kind of thing that DevSecOps is meant to overcome. Given enough time and persistence, the requisite trust should emerge naturally. A tried and true strategy to implement new processes is to ease the team into the DevSecOps transition in gradual stages to avoid overwhelm.</p>
<p>Inspecting Vendor Relationships<br />
With security part of DevOps, preventative measures are easier to implement. It’s the difference between upfront inspection and constant vigilance or waiting for chaos to break loose and only then (too late) trying to fix the problem.</p>
<p>In today’s intertwined internet, substantial security risk comes from third-party partners who provide services and share data and resources with your organization. Your company and network is only as strong as the weakest link. A recent example, this one related to hosting service, is the Google Cloud outage that took down large chunks of the internet, and we mean large. Companies like YouTube, Gmail, Snapchat, and Shopify to name a few were heavily affected.</p>
<p>For perspective, let’s consider the effect on Shopify. The outage stopped sales dead for 800,000 stores in 175 countries for seven hours because the entire Shopify network is centralized with one host (Google Cloud) which obviously did not have a good backup plan. Most scary for those entrusted with securing sites is the reality that the outage could have been a hacker attack in which Google’s servers were forcibly taken offline while malware roamed amongst customer data of the affiliate stores scooping up whatever it could find.</p>
<p>Incidents like this put an intense focus on the uptime/downtime of hosting providers as a critical cybersecurity metric. You need to know your provider’s numbers. According to a recent review of web hosting uptimes, anything lower than 99.9% uptime is unacceptable for small businesses, let alone enterprises like Shopify on which hundreds of thousands of SMEs rely.</p>
<p>The preceding example of the danger inherent in a vendor relationship is just that &#8211; a solitary example in a universe of opportunities. Think of every vendor that your website relies on or allows access to. Any of them could be a serious security problem. Are you ready for it?</p>
<p>Understand the DevSecOps Rules<br />
To achieve the highest levels of productivity while using DevSecOps in your organization, try the following:</p>
<p>Integrate best cybersecurity practices for everyone from the beginning, like updating software and hardware regularly, penetration testing, and mandatory employee training on VPN best practices (virtual private networks) any time they connect to the internet.<br />
Prioritize security. Don’t let human error or carelessness be your undoing. The reason DevSecOps exists is that human error happens. The goal is to limit the number of errors and place protocol in place to catch the error after it occurs.<br />
Monitor all software and check code continuously so you can patch security holes and aim to stay one step ahead of hackers. This includes implementing code dependency checks, such as the OWASP Dependency Check, on a regular basis.<br />
Break tasks up into manageable bits. The smaller and simpler each step is in an overall process, the more likely it is to be done correctly.<br />
Set up one-click compliance reporting so that you can have a clear log of every step in the software development process.<br />
Encourage members of the different arms of your IT department to keep in touch and discuss their concerns. Ensuring team leads talk every day can be as drastic as enforcing mandatory meetings between different arms of the process.<br />
Grow With a New Community<br />
DevSecOps going mainstream is what every proponent of the process envisioned. A burgeoning community is placing itself at the forefront of organizational innovation.</p>
<p>DevSecOps Days is described as a global series of one and two-day conferences helping to educate, evolve, and explore concepts around developing security as code. As the movement grows, the ability to learn and improve within a community grows. InfoQ attended a London event and found it to be greatly beneficial for organizations.</p>
<p>As the movement grows, more organizations will sprout up with more events and learning opportunities for entrepreneurs, small businesses, and large organizations alike.</p>
<p>Time to Evolve<br />
Today’s reality is that cybersecurity threats are everywhere. Any organization that intends to survive and thrive online needs to be ready for them. A major part of this readiness is to stay on the front lines of DevOps thinking, which is DevSecOps.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.bestdevops.com/how-to-seamlessly-evolve-devops-into-devsecops/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>AI help desk software frees IT ops to take on SRE skills</title>
		<link>https://www.bestdevops.com/ai-help-desk-software-frees-it-ops-to-take-on-sre-skills/</link>
					<comments>https://www.bestdevops.com/ai-help-desk-software-frees-it-ops-to-take-on-sre-skills/#respond</comments>
		
		<dc:creator><![CDATA[anil]]></dc:creator>
		<pubDate>Sat, 22 Jun 2019 09:17:39 +0000</pubDate>
				<category><![CDATA[DevOps Updates]]></category>
		<category><![CDATA[ChatOps]]></category>
		<category><![CDATA[Deployment]]></category>
		<category><![CDATA[financial]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[platform]]></category>
		<category><![CDATA[Services]]></category>
		<guid isPermaLink="false">http://www.bestdevops.com/?p=5552</guid>

					<description><![CDATA[Source:- searchitoperations.techtarget.com A financial services company will retrain its help desk staff to be app developers and SREs, while AI handles [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Source:- searchitoperations.techtarget.com</p>
<h2 class="main-article-subtitle">A financial services company will retrain its help desk staff to be app developers and SREs, while AI handles the grunt work for the company&#8217;s call center employees.</h2>
<p>Software-based automation of menial tasks will pave the way for more meaningful work among IT ops pros at a financial services company.</p>
<p>Until 2018, IT ops teams at Freedom Financial Network, a 17-year-old financial services company focused on consumer debt reduction, were largely focused on help desk tasks for the company&#8217;s 2,200 call center employees. The company had also made some progress in cloud migration and the adoption of Agile and DevOps practices, but wanted to take a more automated approach to its everyday IT tasks and rethink how it assigned its employees.</p>
<div class="ad-wrapper ad-embedded">
<div id="halfpage" class="ad ad-hp" data-google-query-id="CLCfkr7f_OICFdkYcgodGrsNDQ">
<div id="google_ads_iframe_/3618/sitops/NEWS_3__container__"></div>
</div>
</div>
<p>&#8220;Having people do application support and begin SRE training changes the game versus paying people $22 an hour to answer the phone and open ServiceNow tickets,&#8221; said Mark Tonnesen, CIO at Freedom Financial, headquartered in San Mateo, Calif.</p>
<p>Tonnesen said he briefly considered AI help desk features from ServiceNow and AIOps software from Moogsoft, but heard word-of-mouth recommendations from other CIOs about a stealth startup called Moveworks. The company, officially launched in April 2019, was founded by former Google employees that specialized in natural language processing at the web giant.</p>
<p>The SaaS-based Moveworks AI help desk software integrates with Slack, Microsoft Teams and other ChatOps services, along with email. It interacts with Freedom Financial&#8217;s call center employees through chatbots and email conversations, and processes their help desk requests through an AI-driven probabilistic decision engine.</p>
<p>&#8220;There are a lot of help desk automation tools on the market that do things like password resets,&#8221; Tonnesen said. &#8220;But they usually still require people on the back end.&#8221;</p>
<p>Since it implemented Moveworks in 2018, Freedom Financial has automated between 15% and 20% of its help desk tasks, and hopes to automate 25% to 30% by the end of 2019. At the same time, it will rework its IT ops teams and retrain them.</p>
<section class="section main-article-chapter" data-menu-title="AI help desk only the first step in complex SRE transition">
<h3 class="section-title">AI help desk only the first step in complex SRE transition</h3>
<p>IT pros at Freedom Financial have already begun to dig into SRE work. A small team of three former software engineers and one ops-focused systems engineer are building an automated application deployment platform in Google Cloud Platform with tools such as Chef and Ansible, along with Docker containers. These SREs support application development for the company&#8217;s customer-facing apps, which added SMS and chat support for call center employees and SMS-based payment support for consumers.</p>
<div></div>
<div class="imagecaption alignRight">Mark Tonnesen</div>
<p>Over the next six months, Freedom Financial will retrain 14 more IT service desk staff &#8212; some as SREs, others to support corporate apps such as Salesforce, and the rest as application developers, Tonnesen said. He also plans to use Moveworks data analysis to identify the most common reasons for help desk requests so that SREs can address their causes long-term.</p>
<blockquote class="main-article-pullquote">
<div class="main-article-pullquote-inner"></div>
</blockquote>
<p>But while AI help desk software frees up IT employees who would otherwise spend all their time putting out fires, it can&#8217;t help Freedom Financial with its toughest task &#8212; retraining employees.</p>
<p>&#8220;I wish there was a better mechanism for training,&#8221; Tonnesen said. Freedom Financial puts engineers two at a time through a three-week training program, then embeds them with product teams to learn on the job. Unlike larger companies with thousands of engineers, Freedom can&#8217;t justify a formalized year-round training program.</p>
<p>SREs are particularly difficult to train from the ground up, Tonnesen said.</p>
<p>&#8220;It&#8217;s hard to find people that really understand what it means,&#8221; he said. &#8220;And we can&#8217;t afford to have an IBM-style three-year internship rotation.&#8221;</p>
<p>Meanwhile, Freedom Financial also plans to roll out Moveworks software in its call center environment for call center employees to use to service customers. Eventually, Tonnesen wants to use AI software to automate back-end business functions such as HR and facility services.</p>
<p>&#8220;We&#8217;d like Moveworks to evolve to support more channels of communications, such as reports and payments systems,&#8221; he said.</p>
<p>In the wider market, IT pros have many choices for AI help desk tools, and that number is only growing. Aside from ServiceNow&#8217;s native help desk automation and AIOps products from Moogsoft, BigPanda, ManageEngine and others, vendors such as Spoke, IPsoft, Zendesk and Freshdesk also offer Moveworks alternatives.</p>
</section>
<p>&nbsp;</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.bestdevops.com/ai-help-desk-software-frees-it-ops-to-take-on-sre-skills/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Docker Database Hacked, 190,000 Users Affected</title>
		<link>https://www.bestdevops.com/docker-database-hacked-190000-users-affected/</link>
					<comments>https://www.bestdevops.com/docker-database-hacked-190000-users-affected/#respond</comments>
		
		<dc:creator><![CDATA[anil]]></dc:creator>
		<pubDate>Fri, 03 May 2019 12:56:45 +0000</pubDate>
				<category><![CDATA[Containerization]]></category>
		<category><![CDATA[DevOps Updates]]></category>
		<category><![CDATA[containerization]]></category>
		<category><![CDATA[DevOps]]></category>
		<category><![CDATA[Docker]]></category>
		<category><![CDATA[Docker Security]]></category>
		<category><![CDATA[Hacked]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Updates]]></category>
		<guid isPermaLink="false">http://www.bestdevops.com/?p=5069</guid>

					<description><![CDATA[Source:- tomshardware.com Docker, a development platform that allows companies to &#8220;build, manage and secure all their applications&#8221; and &#8220;deploy them anywhere,&#8221; [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Source:- tomshardware.com</p>
<p>Docker, a development platform that allows companies to &#8220;build, manage and secure all their applications&#8221; and &#8220;deploy them anywhere,&#8221; announced last week that it discovered a database hack that exposed the information of 190,000 users. The hackers collected usernames, hashed passwords and in some cases GitHub and Bitbucket access tokens used to access repositories on the popular Git platforms many developers use for version control.</p>
<p>Those whose usernames and hashed passwords were hacked got off relatively easy. Usually, it&#8217;s not particularly hard to guess at someone&#8217;s username&#8211;especially if it&#8217;s simply their real name&#8211;and if Docker properly hashed the passwords they should be difficult to access. (As opposed to some other companies, which leave passwords in plain text readable by literally everyone with a computer.) That&#8217;s also a relatively small number of users compared to other hacks.</p>
<p>The people with a real problem are the ones whose GitHub and Bitbucket access tokens were compromised. Those tokens are used to automatically build images of code stored in Git repositories. Bleeping Computer reported that depending on the permissions granted by the token, whoever hacked Docker could use these access tokens to modify the corresponding code repositories. That could enable additional hacks of users of those services. However, Docker said it revoked the stolen access tokens, so those attacks shouldn&#8217;t be possible.</p>
<p>The company is asking users to change their passwords&#8211;on its site as well as other sites using the same password&#8211;and told people whose access tokens were compromised to reconnect their accounts to GitHub or Bitbucket. It also said it&#8217;s &#8220;enhancing our overall security processes and reviewing our policies&#8221; and that &#8220;additional monitoring tools are now in place.&#8221;</p>
<p>The hack came at an inopportune time. The company announced on April 24 a partnership with Arm to make it easier for developers to deploy &#8220;applications for cloud, edge and IoT environments&#8221; to systems with processors based on the Arm architecture. It&#8217;s also hosting DockerCon, a container industry conference, from April 29 to May 2. But it seems Docker doesn&#8217;t want this to detract from those events, as its social media accounts, blog and the news section of its website have all glossed over the database hack.</p>
<p>Instead, Docker disclosed the attack on its Success Center and directly to users who might have been affected. That way, it can let people know what it believes happened while also keeping the focus on its more flattering announcements.</p>
<p>DevOpsSchool.com started one Docker security training program named <strong>&#8220;<a href="https://www.devopsschool.com/courses/docker/docker-security-training-advance.html" target="_blank" rel="noopener">Deep Dive into Docker Security</a>&#8221; </strong>which will be really helpful if you want to be safe in security breaches.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.bestdevops.com/docker-database-hacked-190000-users-affected/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>What venture capitalists need to know about DevOps</title>
		<link>https://www.bestdevops.com/what-venture-capitalists-need-to-know-about-devops/</link>
					<comments>https://www.bestdevops.com/what-venture-capitalists-need-to-know-about-devops/#respond</comments>
		
		<dc:creator><![CDATA[anil]]></dc:creator>
		<pubDate>Sat, 06 Apr 2019 05:31:01 +0000</pubDate>
				<category><![CDATA[DevOps]]></category>
		<category><![CDATA[DevOps Best Practices]]></category>
		<category><![CDATA[DevOps News]]></category>
		<category><![CDATA[DevOps Updates]]></category>
		<category><![CDATA[capital]]></category>
		<category><![CDATA[DevOps Engineers]]></category>
		<category><![CDATA[DevOps transformation]]></category>
		<category><![CDATA[IT professionals]]></category>
		<category><![CDATA[venture]]></category>
		<guid isPermaLink="false">http://www.bestdevops.com/?p=4997</guid>

					<description><![CDATA[Source &#8211; itproportal.com Venture capital (VC) investment into DevOps continues to rise. Already populated by some huge worldwide brands like Google, [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Source &#8211; <strong>itproportal.com<img loading="lazy" decoding="async" class="size-medium wp-image-4998 alignleft" src="http://www.bestdevops.com/wp-content/uploads/2019/04/devops-300x200.jpg" alt="" width="300" height="200" /></strong></p>
<p>Venture capital (VC) investment into DevOps continues to rise. Already populated by some huge worldwide brands like Google, Microsoft and Amazon and estimated to be a $50 billion market, DevOps has graduated beyond a niche software sector for unicorns, and has made it to the mainstream. The amount of interest in this space from the VC community since the middle of 2018 is just one of many signals from investors that “now is a great time to jump in and grab a piece of the next big thing.”</p>
<h4 id="the-market-opportunity">The market opportunity</h4>
<p>According to Crunchbase, there are hundreds of vendors from all over the world providing solutions and services within the DevOps marketplace. DevOps is now a category of investment just like Media or Healthcare, and we regularly see VC partners being brought onboard just to build a DevOps portfolio for their firm.</p>
<p>Because DevOps is now viewed as a mature investment thesis, built on a flourishing technology and cultural movement, the stage is set for it to impact the bottom line of a broad spectrum of businesses – not just software startups or even traditional software vendors. DevOps is the common denominator for how large swaths of the economy are going to become more productive and competitive moving forward.  Whether all companies realise it or not, their ability to prosper (or survive) relies on their software capabilities.</p>
<p>If you look closely, you can see new layers of value being built on top of the foundational investments that create today’s investment opportunity. For instance, early success with the Internet and Cloud Computing has given rise to more powerful cloud native, Microservices, Containers and Serverless architectures. But at the enterprise level, it&#8217;s not just about “DevOps-ing with the new stuff,” a lot opportunity also exists in “DevOps-ing the old.” Most companies are onboarding new generations of technology, but they can’t just get rid of the technology they already have – mainframe, for example. DevOps is a superset of all of the foundational layers that have been set previously.  Done right, DevOps ensures that software gets released on business demand regardless of the underlying technologies.   Today’s cloud will become tomorrow’s mainframe replaced by something else that’s disruptive.  By adopting DevOps companies insulate themselves from these technological shocks, enabling them to easily leverage new disruptions on their terms.</p>
<h4 id="breaking-it-down-what-to-look-for">Breaking it down: What to look for</h4>
<p>So what does an investor need to keep an eye on for the next big opportunity? Or, better yet, what should an investor keep in mind before potentially making the next big investment? As a holder of multiple a senior leadership positions at a number of public and private tech companies, and now CEO of a leading vendor in the DevOps space, there are some tips and considerations for venture capitalists that are important to share.</p>
<p><strong>1) Look For Companies that “Walk the Talk”</strong></p>
<p>Continuous Improvement is a cornerstone of DevOps. When doing due diligence and research into a potential DevOps investment, one question VCs should ask is whether or not the company practices the principles and methods that it preaches. Is the company on its own DevOps transformation path to continue to be as competitive as possible? When teams adopt a DevOps mindset, they think holistically and collaborate more with their peers towards the goal of learning from their experiences, and applying that learning to more efficiently shipping great products. If a company is not building a learning organisation, they are losing to one that is.</p>
<p><strong>2) Invest in ALL Three Pillars of DevOps</strong></p>
<p>DevOps is a trinity of process, tools and people. A lot of vendors are focused on helping teams get their arms around the process piece or operating model, and even more vendors are providing tooling and technology. So, it’s clear that there are many investment opportunities in the process and tooling side of DevOps.</p>
<p>But what about people? Even with killer automation and a rock-solid operating model, the “humans of DevOps” matter.  These folks need to be armed and equipped with the skills they need to help companies adopt DevOps principles and tools – and they are not easy skills to master! Last year, LinkedIn announced that “DevOps Engineers” were one of the most heavily recruited job titles. I believe we will start to see money, as well as a lot of activity and focus, geared towards the people pillar [of DevOps]. Getting people up to speed alongside the process and toolchain developments is a critically important part of DevOps success.</p>
<p>Investment opportunities that address all three pillars should generate outsized returns.</p>
<p><strong>3) Go To Where the Puck is Heading</strong></p>
<p>As DevOps continues its growth path, the market will demand more from its core DevOps solution providers. DevOps has borrowed many of its concepts from the manufacturing world. The have a common thirst for metrics data and lots of it.   Leading vendors are finding novel ways to introduce AI and machine learning as ways to advance the industry. By successfully uniting Development and Operations, DevOps has paved the way to unite more siloed functions. Why not DevSecOps or BizDevSecOps? There is a strong desire to integrate more and more principals into the value stream.</p>
<p>These new paradigms incent the creation of next-generation solutions for companies to leverage in this growing marketplace. Do your research to identify which companies are investing in these new opportunities, and what novel approaches they offer to help customers adapt and become more competitive.</p>
<p><strong>4) To Win Big, Invest More Than Just Cash</strong></p>
<p>The DevOps market is full of solutions and services to cover the entire software delivery lifecycle – from development all the way to production. Each step along the way are subcategories of DevOps where vendors specialise and focus their efforts.</p>
<p>So, should VC firms just find a space and invest money with the category leader? Maybe &#8211; but it&#8217;s not just about money &#8211; it&#8217;s about synergies, goal alignment, and the VC value-add. The VC firms that are most successful become so by investing in companies that are helping to build its industry’s community, best practices and ecosystems. What can a VC do to accelerate the growth of the company it is investing in for the long haul? Help the company build and nurture high performance through its own culture, systems and resiliency, which in turn will help the firm realise a solid return on the investment.</p>
<h5 id="one-final-thought">One final thought</h5>
<p>You won’t find a DevOps transformation that doesn&#8217;t focus on delivering higher velocity, better quality, improved utilisation, etc. To be successful, some (or all) of those metrics should improve – and this measurable improvement equates to real value being created. Be confident in the lasting value of DevOps, it’s not a passing fad.  As previously mentioned the DevOps movement is a very data-driven, metrics-driven approach, which means that this value can be verified and validated – which helps to minimise the risk of a “DevOps bubble.”</p>
<p>If DevOps teaches anything, it’s that fast can move faster, smart can get smarter and competition can get more competitive. It is a truly inspiring movement to be a part of, and an exciting time to work in technology. As the DevOps movement aims to improve the lives of more than 2 million IT professionals around the world, VC firms and investors have a unique opportunity to do their part in making the world a better place.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.bestdevops.com/what-venture-capitalists-need-to-know-about-devops/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Puppet Delivers 2018 State of DevOps Report with Five Stage Plan for DevOps Success</title>
		<link>https://www.bestdevops.com/puppet-delivers-2018-state-of-devops-report-with-five-stage-plan-for-devops-success/</link>
					<comments>https://www.bestdevops.com/puppet-delivers-2018-state-of-devops-report-with-five-stage-plan-for-devops-success/#respond</comments>
		
		<dc:creator><![CDATA[anil]]></dc:creator>
		<pubDate>Sat, 15 Sep 2018 05:37:50 +0000</pubDate>
				<category><![CDATA[DevOps]]></category>
		<category><![CDATA[DevOps News]]></category>
		<category><![CDATA[DevOps Updates]]></category>
		<category><![CDATA[Automation]]></category>
		<category><![CDATA[DevOps Report]]></category>
		<category><![CDATA[DevOps success]]></category>
		<category><![CDATA[Puppet]]></category>
		<category><![CDATA[Technology]]></category>
		<guid isPermaLink="false">http://www.bestdevops.com/?p=4390</guid>

					<description><![CDATA[Source- bdaily.co.uk DevOps in 2018 is a big deal. Most, if not all, enterprises have some sort of DevOps initiatives, [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Source- <a href="http://bdaily.co.uk" target="_blank" rel="noopener">bdaily.co.uk</a></p>
<p>DevOps in 2018 is a big deal. Most, if not all, enterprises have some sort of DevOps initiatives, and many have become non-stop software and data factories, operating 24&#215;7. However, succeeding with DevOps has proved challenging and results vary wildly between companies.</p>
<p>In an effort to solve this problem, Puppet has released its State of DevOps Report this week. According to Puppet, one of the main goals of this report was to understand the DevOps journey and how organisations evolve their practices over time. It used analysis of the responses to create an overarching methodology that could help businesses succeed with DevOps:</p>
<p><strong>Stage 0: Build the foundation</strong></p>
<p>When development and operations teams are just starting to grasp the importance of collaboration and sharing, they rapidly implement technologies and processes to facilitate sharing of ideas, metrics, knowledge, processes, and technologies. This foundational stage is critical to the DevOps evolution, and the health of a successful DevOps organisation rests on the base that gets built during this initial stage.</p>
<p><strong>Stage 1: Normalise the technology stack</strong></p>
<p>At this stage, you may see the dev teams making a coordinated move to more agile development methods or a few teams organically adopting new methods for specific products or workflows. Development teams have adopted version control, which is the first step on the path to continuous integration and continuous delivery. They’re also beginning to normalise their tech stacks by eliminating redundant systems, perhaps refactoring applications to work on a smaller set of operating systems.</p>
<p><strong>Stage 2: Standardise and reduce variability</strong></p>
<p>This stage is where both dev and ops teams concentrate on reducing variance, continuing to standardise the tech stack by further reducing the number of operating systems to a single OS or OS family, and building on a standard set of technologies: databases, key value stores, message queues, identity stores and more. This standardisation phase reduces the overall complexity of the system, enabling teams to scale their expertise. For a business, the benefits are great: You can deploy new applications and services faster, and reduce errors that arise from inconsistency. Best of all, as the shared patterns evolve and improve, the quality of all services improve.</p>
<p><strong>Stage 3: Expand DevOps practices</strong></p>
<p>Now that the important foundational elements are in place, and the system is well understood, organisations can begin to address other pain points. Successful teams at this stage now reuse deployment patterns for building applications and services, and infrastructure changes are tested before deploying to production. Both these practices provide predictability and reliability, building trust in the new methods and practices. With this new level of trust in the system, important cultural shifts can take place in the organisation.</p>
<p><strong>Stage 4: Automate infrastructure delivery</strong></p>
<p>This stage in the DevOps journey is defined by the automation of systems configuration and provisioning, which many people consider to be a high-priority outcome of a DevOps initiative. Self-service for multiple departments ultimately leads to greater efficiency and satisfaction throughout the organisation.</p>
<p><strong>Stage 5: Provide self-service capabilities</strong></p>
<p>By the time an organisation gets to Stage 5, you can see the cumulative effects of achieving high levels of automation and trust. At this stage, resources are available via self-service, and incident response is automated. IT teams don’t automate just for the sake of automating; they do it to make the entire organisation run with greater efficiency and precision.</p>
<p>Nigel Kersten, VP of Ecosystem Engineering at Puppet commented: “While DevOps practices have become far more well known across our industry, organisations continue to struggle to scale pockets of DevOps success more broadly across multiple teams and departments.</p>
<p>“This year’s report explores the foundational practices that need to be in place in order to scale DevOps success, and proves that success can only scale when teams are enabled to work across functional boundaries.”</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.bestdevops.com/puppet-delivers-2018-state-of-devops-report-with-five-stage-plan-for-devops-success/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>6 DevOps culture mistakes holding you back</title>
		<link>https://www.bestdevops.com/6-devops-culture-mistakes-holding-you-back/</link>
					<comments>https://www.bestdevops.com/6-devops-culture-mistakes-holding-you-back/#respond</comments>
		
		<dc:creator><![CDATA[anil]]></dc:creator>
		<pubDate>Tue, 11 Sep 2018 06:18:50 +0000</pubDate>
				<category><![CDATA[DevOps]]></category>
		<category><![CDATA[DevOps Events]]></category>
		<category><![CDATA[DevOps Process]]></category>
		<category><![CDATA[DevOps Updates]]></category>
		<category><![CDATA[business impact]]></category>
		<category><![CDATA[DevOps culture]]></category>
		<category><![CDATA[DevOps engineer]]></category>
		<category><![CDATA[DevOps Mistakes]]></category>
		<category><![CDATA[DevOps professionals]]></category>
		<guid isPermaLink="false">http://www.bestdevops.com/?p=4369</guid>

					<description><![CDATA[Source- enterprisersproject.com Having a strong DevOps culture is like having good taste. Everyone wants it – but is everyone equipped with the [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Source- <a href="http://enterprisersproject.com" target="_blank" rel="noopener">enterprisersproject.com</a></p>
<p>Having a strong DevOps culture is like having good taste. Everyone wants it – but is everyone equipped with the skills, instincts, and sheer luck needed to actually have it?</p>
<p>The reality is, building a great DevOps culture is easier said than done. Here are the major challenges facing strong DevOps cultures and how to overcome them.</p>
<h3><strong>1. Inability to give and listen to feedback</strong></h3>
<p>Teams must learn how to give and receive feedback if they are to improve and take each other forward in the process. Engineers and operators are smart cookies with high IQs, but many need to improve their EQs to collaborate more effectively as a team. Teams with high EQ will always destroy those with low EQ because they can learn and achieve more.   Feedback is about sharing what is working and what can be improved every single day. It’s important that teams don’t just focus on the good or the bad, but rather keep a sharp focus on feedback and bias.</p>
<h3><strong>2. The revolving door problem </strong></h3>
<p>Part of the challenge facing DevOps culture is the short tenure of DevOps professionals themselves. The average tenure of a DevOps engineer is less than three years. Engineers often find themselves lured away for the promise of better compensation, better equity, or the “next hot startup company.”</p>
<p>This doesn’t do any favors to the ongoing battle to achieve true alignment between Dev and Ops teams: How they can play together when team members are constantly jumping ship, leaving behind unfinished projects, and forcing new people to join and ramp up quickly? If there were more stability in engineering teams, it might be easier to build the foundations of a stable and durable DevOps culture.</p>
<h3><strong>3. Well-meaning but time-wasting acts of heroism</strong></h3>
<p>Often you’ll be at a developer conference and an enthusiastic, well-meaning presenter is gushing about the unbelievably complex, bespoke platform that her team has built – one that has nothing to do with their core competency. She demonstrates how they spent six months and $300,000 to create it and the whole room bursts into applause.</p>
<p>The “build it not buy It” mentality is one that truly holds back top-performing engineering teams. In 2018, the platform you need has likely been built – and built extremely well – by a third party. Save your engineering heroics for what your customer actually requires; the rest is a needless waste of time and resources. Be an expert in your business, not the tools business.</p>
<h3><strong>4. The term &#8220;DevOps&#8221; is a problem</strong></h3>
<p>If you ask many high-performing engineering teams about DevOps, the response you’ll often get is an eye roll – even if those teams are uncommonly good at DevOps. The word has been beaten down, over-publicized, and over-discussed. (I know, this article doesn’t help that situation.)</p>
<p>If DevOps refers to the cultural alignment of development and operations so that both teams are responsible for the success of production environments, then the term has enormous value. But if the word has been drained of all meaning by a tsunami of think pieces and keynote presentations, then it’s difficult to have a meaningful discussion about it.</p>
<p>Try to remember that the concept has value, even if it’s been beaten down by so many analyses, conversations, and misunderstandings.</p>
<h3><strong>5. The right culture isn’t modeled from above</strong></h3>
<p>You all know the truth of this statement: There’s no culture unless it’s shown by example, set by the teams above. It takes a superhuman effort for a team to enact its own unique culture within an organization that doesn’t itself value culture or take it seriously.</p>
<p>If you have an organization where the executive and management team isn’t truly facilitating team alignment, including between the developer and operations teams, how can a DevOps team survive and thrive? Culture comes from the top.</p>
<h3><strong>6. DevOps goals aren’t aligned to business goals</strong></h3>
<p>99.9 percent of companies using DevOps are wielding it as a catalyst to drive business outcomes faster, and a strong DevOps culture is one that truly understands the levers of its business. DevOps is not about having a team of “rock stars” that improves technical KPIs; in fact, measuring availability is pointless unless you can measure and report the real business impact.   Technical metrics are great, but goals drive behavior – and goals that focus on the needs of the business constitute the foundation of a solid DevOps culture.</p>
<h3>How to beat the DevOps barriers</h3>
<p>I’ve spent a lot of time describing the barriers that keep DevOps teams from reaching their full potential. But the reality is, there are plenty of positive forces helping DevOps teams build strong cultures. For one, the will to do so is stronger than ever: Companies want strong DevOps organizations to help them achieve business goals. For another, technology is better than ever and can help teams focus on the same shared metrics and set of goals.</p>
<p>Wherever you find the twin enablers of genuine will and solid technology, a strong DevOps culture can’t be too far behind. In addition to will and technology, companies seeking to build that culture must:</p>
<ul>
<li>Focus as much on EQ as IQ, making sure engineers and operators really listen to each other while building a DevOps culture from the ground up. This will also help maintain collaboration and stability on Dev and Ops teams, making constant turnover less of a cultural and business problem. (See our related story: 10 things leaders with emotional intelligence never do.)</li>
<li>Stay in the business you’re in: Allow engineers to focus on what your company was created for, rather than distracting them.</li>
<li>Have open discussions on what DevOps really means, and what it means to your teams, independent of the hype that the word has taken on in recent years.</li>
<li>Ensure leadership is taking DevOps seriously by showing, not telling, how to build a collaborative culture – and by linking DevOps goals directly to business goals.</li>
</ul>
]]></content:encoded>
					
					<wfw:commentRss>https://www.bestdevops.com/6-devops-culture-mistakes-holding-you-back/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Driving innovation and accelerating digital transformation with low-code</title>
		<link>https://www.bestdevops.com/driving-innovation-and-accelerating-digital-transformation-with-low-code/</link>
					<comments>https://www.bestdevops.com/driving-innovation-and-accelerating-digital-transformation-with-low-code/#respond</comments>
		
		<dc:creator><![CDATA[anil]]></dc:creator>
		<pubDate>Mon, 10 Sep 2018 07:27:07 +0000</pubDate>
				<category><![CDATA[Continuous Delivery]]></category>
		<category><![CDATA[DevOps]]></category>
		<category><![CDATA[DevOps News]]></category>
		<category><![CDATA[DevOps Updates]]></category>
		<category><![CDATA[Digital Transformation]]></category>
		<category><![CDATA[digital user experiences]]></category>
		<category><![CDATA[future-proof]]></category>
		<category><![CDATA[innovation]]></category>
		<category><![CDATA[Technology]]></category>
		<guid isPermaLink="false">http://www.bestdevops.com/?p=4365</guid>

					<description><![CDATA[Source- networksasia.net According to IDC, technology and services that enable digital transformation across the Asia-Pacific region are expected to grow [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Source- <a href="http://networksasia.net" target="_blank" rel="noopener">networksasia.net</a></p>
<p>According to IDC, technology and services that enable digital transformation across the Asia-Pacific region are expected to grow by 15.3 percent annually to more than $386 billion (U.S. dollars) in 2018. With the demand for applications and platforms currently at an all-time high, CIOs know their enterprises need to deliver technology and product innovation faster while responding rapidly to new market opportunities and threats.</p>
<p>In a world that is changing at breakneck speed, it comes as no surprise that many enterprises are falling behind their more digitally-savvy competitors in the digital transformation race. With the exploding demand for new web, mobile, and enterprise apps, 43 percent of IT teams in the Asia Pacific already anticipate delivering 10 or more applications in 2018, according to the OutSystems report, <em>The State of Application Development 2018</em>. However, beyond ensuring fast delivery, IT teams are also expected to create applications that provide brilliant and consistent digital user experiences on multiple platforms and devices. In addition, the sheer number of coding languages and continually evolving development frameworks further increase the complexity of building modern, future-proof applications.</p>
<p>While many CIOs would like more applications to be created to streamline internal and external processes, a common concern is the capability of IT departments to deliver them on time and whether or not the IT teams are overstretched. Unfortunately, challenges such as the scarcity of IT talent, massive backlogs, and the high cost of maintaining legacy systems plague the digital transformation journeys of many enterprises.</p>
<p><strong>Gaps that need to be plugged</strong></p>
<p>According to <em>The State of Application Development 2018, </em>14 percent of IT teams in Asia still have a backlog of more than 10 applications. With the rising demand for apps in the region, significantly speeding up the web or mobile application delivery process, which, on average, takes 47 percent of IT teams at least five months to complete, is imperative. However, the shortage of IT talent keeps many IT organizations from addressing the lags in the application development process. Whether organizations focus on retraining or recruiting IT talent, the fact remains that remedying the skills drought is time- consuming and expensive. Even when they do find developers with a strong grasp of the ever-changing array of technology required for digital and mobile development, it is difficult to retain them.</p>
<p>Additionally, when you combine the shortage of developers with inflexible, hard-to-integrate back-office systems, keeping the lights on becomes the main IT focus and not innovation. With an “all hands on deck” approach to addressing legacy issues, integration challenges, and deficient application programming interfaces (APIs), there are further complications and delays in the delivery of new web or mobile apps.</p>
<p>Companies need to change course quickly if they want to seize opportunities in the burgeoning digital economy. Now more than ever, speed-to-market and speed-of-change are the factors that separate successful companies from the underdogs. This is perhaps one reason why organizations are shifting towards continuous delivery—which is a far cry from typical application updates that used to happen only about once a year. However, continuous delivery demands hard work and significant investments in technology and personnel. Such complexity also risks becoming a further drain on IT resources that could be more focused on delivering customer value.</p>
<p><strong>Enabling innovation through low-code development platforms</strong></p>
<p>Given the pressure to advance digital transformation, CIOs need to adapt their technology and processes by using modern, rapid development approaches that can enable more innovation, continuous delivery, and better talent resource management.</p>
<p>One way is to bet on low-code development platforms, which streamline the software design and development process with minimal hand-coding, enabling skilled people to deliver value more quickly and more reliably.</p>
<p>With low-code application development platforms, IT teams can definitely get more experiments off the ground. As development becomes up to 10 times faster than hand-coding, not only do IT teams get on top of the development queue, but they are also able to realize fundamental changes in the risk-to-reward ratio for custom development. Additionally, low-code development platforms are fast enough to enable visual mock-ups that elicit high-quality requirements and feedback, thereby stimulating design thinking.</p>
<p>How does low-code development work? Fast, visual modeling of responsive web user interfaces and mobile apps put the user experience at the heart of the development process. Built-in user feedback ensures that rapid, collaborative design iteration doesn’t depend on developers and users sitting side by side. The best low-code development platforms also enable prototypes and user interface mockups to scale into fully integrated enterprise applications, making this process part of mainstream development instead of a disposable luxury.</p>
<p><strong>A healthy appetite for change</strong></p>
<p>Innovation necessitates an undeniable need for greater speed and experimentation. And while investing in new skills such as design thinking, lean startup, and customer journey mapping is a step in the right direction, much of this investment can go to waste if organizations don’t change their risk appetites. With scarce developer resources and slow hand-coding challenging the promotion of an innovation- oriented culture, experimentation can get lost in bureaucratic requirement gathering and risk-averse prioritization practices.</p>
<p>Low-code development platforms can ease these pains and deliver value because they support the key digital transformation priorities of CIOs. Most importantly, they drive innovation with minimal upfront investment in setup, training, and deployment.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.bestdevops.com/driving-innovation-and-accelerating-digital-transformation-with-low-code/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>DevOps &#038; machine learning improves app performance!</title>
		<link>https://www.bestdevops.com/devops-machine-learning-improves-app-performance/</link>
					<comments>https://www.bestdevops.com/devops-machine-learning-improves-app-performance/#respond</comments>
		
		<dc:creator><![CDATA[anil]]></dc:creator>
		<pubDate>Tue, 04 Sep 2018 08:59:00 +0000</pubDate>
				<category><![CDATA[DevOps]]></category>
		<category><![CDATA[DevOps Best Practices]]></category>
		<category><![CDATA[DevOps Updates]]></category>
		<category><![CDATA[App Development]]></category>
		<category><![CDATA[Big data]]></category>
		<category><![CDATA[Cloud Services]]></category>
		<category><![CDATA[Machine Learning]]></category>
		<category><![CDATA[Microservices]]></category>
		<guid isPermaLink="false">http://www.bestdevops.com/?p=4332</guid>

					<description><![CDATA[Source &#8211; devopsonline.co.uk Machine learning has been hyped (and in some cases overhyped). However, one successful DevOps use case for machine [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Source &#8211; devopsonline.co.uk</p>
<p class="cf-tweet-this cf-tt-target cf-tt-enabled cf-tt-out-of-bounds cf-tt-out-of-bounds-top cf-tt-element-attached-top cf-tt-element-attached-center cf-tt-target-attached-bottom cf-tt-target-attached-center">Machine learning has been hyped (and in some cases overhyped). However, one successful DevOps use case for machine learning is application performance management. Why? Simply put, machine learning is needed to analyse the volume, velocity, and variety of big data generated by today’s dynamic application environments. By applying machine learning to identify patterns and anomalies, DevOps teams can better troubleshoot intermittent and complex problems, understand usage patterns, reduce bug rates, and improve the customer experience.</p>
<h4>What’s changed?</h4>
<p class="cf-tweet-this cf-tt-target cf-tt-abutted cf-tt-abutted-top cf-tt-element-attached-bottom cf-tt-element-attached-center cf-tt-target-attached-top cf-tt-target-attached-center">Modern applications based on containers, microservices, cloud services, and ever-smaller slices of computing and storage functions create a complex mesh of dependencies that are constantly changing. Performance issues can surface at the user or server end, with the root causes hiding somewhere downstream among thousands of objects, methods, and transactions per second. Is the problem with the company’s code, the network, the infrastructure, or the end user’s device? The best approach is the combination of big data and machine learning, collecting data on the full breadth and depth of individual transactions and unleashing the powers of machine learning to identify and classify critical anomalies and bottlenecks.</p>
<h4 class="cf-tweet-this cf-tt-target cf-tt-element-attached-center cf-tt-target-attached-center cf-tt-abutted cf-tt-abutted-top cf-tt-element-attached-bottom cf-tt-target-attached-top">Machine learning needs big data</h4>
<p>When trying to understand and optimise application performance, more data is better. Whether testing an upcoming release or troubleshooting a reported problem, teams and tools often use data samples and averages to create a baseline of normal behaviour and isolate the outliers. However, data samples at one-minute or five-minute intervals in a sub-second world not only miss many of the outliers, they often misrepresent them. <a href="https://www.riverbed.com/document/fpo/Solutions/why-big-data-is-critical-white-paper.pdf">Big data</a>, collecting system and resource data every second from all apps, all devices, all transactions, is essential for training machine learning algorithms. Otherwise, they are learning the simulation, not the real world.</p>
<h4>Machines must be taught, again and again</h4>
<p class="cf-tweet-this cf-tt-target cf-tt-enabled cf-tt-out-of-bounds cf-tt-out-of-bounds-top cf-tt-element-attached-top cf-tt-element-attached-center cf-tt-target-attached-bottom cf-tt-target-attached-center">In machine learning, the analytic engine builds its models by analysing massive amounts of data in order to isolate patterns, clusters, and correlations. One approach is to start with common scenarios, teaching the computer to pick out signatures that are indicative of typical application performance problems. Since there are many possible scenarios to be learned, APM tools use a variety of anonymised real-world data sets from a broad group of organisations in different industries for the initial training. Subject-matter experts then review the results and tell the computer what the correct classifications are for each cluster or pattern. Then the computer explores on its own and the experts identify whether a cluster it found is a problem or not.</p>
<p>Teaching is an <strong>iterative process</strong>, isolating sets of transactions, isolating commonalities, removing transactions with that characteristic, and evaluating the remainder to see if the issue is still present. This enables the tool to catch unanticipated issues which are incorporated into the list of automatic insights. The bigger the data and the more metadata and richness in it, the more accurately the system can pinpoint patterns and causes.</p>
<h4>APM big data and machine learning example</h4>
<p>For example, the chart below is a plot of detailed response-time data points collected from 10,000 individual transactions. Humans see a mostly ‘normal’ distribution curve, with a sizeable collection of outliers. Trying to sort these into logical sets would take the DevOps or QA team weeks or months, long after the related issues have impacted the business.</p>
<p>Machine learning can quickly group the outliers into sets, excluding transactions that have no exceptions and identifying areas for further investigation, such as web service timeouts, database timeouts, authorisation timeouts, and initialisation failures. Exploring further, machine learning iteratively groups and regroups sets, looking at all interdependencies, isolating commonalities, and providing details of methods, database calls, servers, or other characteristics that are consistently associated with underperforming transactions. Performing these tasks much faster than humans, the computer learns the most likely characteristics to isolate based on statistical results instead of guesses and anecdotes.</p>
<h4>Help for DevOps teams</h4>
<p>With a big data foundation, machine learning systems can synchronise multiple data sources based on their metadata, linking server statistics, log file entries, and transactions. Armed with this info, DevOps teams can quickly identify and prioritise the users, transactions, and application components with the biggest impact on the business. Historical data enables rapid comparisons of performance before and after releases, providing insight on the impact of development changes and the effectiveness of testing coverage. Machine learning techniques can also turn complex interdependencies into graphical visualizations that humans find much faster and easier to process than reams of tabular data.</p>
<p>For example, when a series of anomalous transactions are identified, detailed data enables the machine to compare key metrics and examine individual users, transactions with similar errors, or transactions running through a specific geography. Linking logs to transaction data synchronise the data, enabling DevOps to quickly drill into the offending method, server, or network.</p>
<p>In the chart above, machine learning separates consistent and inconsistent characteristics, isolating Method C as the single biggest cause of slowdowns. An important truism is that all slow transactions may be slow for different reasons, and machine learning automates the early stages of data analysis and discovery, enabling the team to focus their resources on resolving the most impactful issues.</p>
<h4>Machine learning: making sense of APM big data</h4>
<p>This is just the beginning of the machine-learning era for APM. However, existing machine learning techniques are already delivering significant value to DevOps teams by analysing APM big data and surfacing the probable causes of performance issues. This rapid identification of issues improves performance reliability, reduces bug rates when used in development environments, and increases user satisfaction with their online experiences.</p>
<p>Data quality matters. Because big data is the foundation of machine learning, it is important to collect all relevant metrics as well as the associated metadata before applying machine learning, and not rely on sampling algorithms that may miss issues in dynamic application environments.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.bestdevops.com/devops-machine-learning-improves-app-performance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>DevSecOps: How to conquer 3 big culture challenges</title>
		<link>https://www.bestdevops.com/devsecops-how-to-conquer-3-big-culture-challenges/</link>
					<comments>https://www.bestdevops.com/devsecops-how-to-conquer-3-big-culture-challenges/#respond</comments>
		
		<dc:creator><![CDATA[anil]]></dc:creator>
		<pubDate>Fri, 17 Aug 2018 05:27:43 +0000</pubDate>
				<category><![CDATA[DevOps]]></category>
		<category><![CDATA[DevOps Best Practices]]></category>
		<category><![CDATA[DevOps Updates]]></category>
		<category><![CDATA[Application security]]></category>
		<category><![CDATA[DevOps security]]></category>
		<category><![CDATA[DevSecOps]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Software Development]]></category>
		<guid isPermaLink="false">http://www.bestdevops.com/?p=4240</guid>

					<description><![CDATA[Source &#8211; enterprisersproject.com Just about any DevOps shop will hit speed bumps on the path toward continuous learning and improvement. “Organizations are increasingly [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Source &#8211; enterprisersproject.com</p>
<p>Just about any DevOps shop will hit speed bumps on the path toward continuous learning and improvement.</p>
<p>“Organizations are increasingly adopting DevOps environments in hopes of achieving transformative velocity and innovation,” says Elizabeth Lawler, VP of DevOps security at CyberArk. “But like any new business initiative, this comes with challenges – and in the case of DevOps, it’s often around culture and areas of responsibility.”</p>
<p>Even issues that seem technical in nature are often rooted in people. Take security: It’s as much a matter of culture and areas of responsibility as it is a technology problem, Lawler says. And even high-functioning DevOps teams are encountering challenges making security – and security teams – integral to development.</p>
<p>“One of the biggest areas of friction remains bringing together security and development operations,” Lawler notes.</p>
<p>This friction is driving interest in the DevSecOps approach – and, almost paradoxically, fueling resistance to DevSecOps practice. IT teams face several significant, common cultural challenges with DevSecOps, and while they might manifest in different ways, they’re closely related – often doing their damage in unison.</p>
<p>We’ll identify a trio of these cultural roadblocks below. Then we’ll share strategies from IT leaders and security experts for proactively breaking down these challenges, as a necessary step toward DevSecOps success.</p>
<h3>Culture challenge #1: An entrenched view of security as something that happens “later”</h3>
<p>“The biggest change in mindset necessary to [create] a mature DevSecOps practice is to understand that security cannot be done as an afterthought,” says Premand Chandrasekaran, VP of software engineering at Barclaycard, a division of the global bank Barclays. “Rather, it requires the attitude that it is built into the continuous delivery pipeline.”</p>
<p>It’s a major – and necessary – change, due to the reality of how systems get built and operated today. Tim Jefferson, VP of public cloud at Barracuda Networks, points out that environments can be spun up and down so quickly these days that their lifespan might be a matter of hours. Security as a final step or afterthought is a non-starter.</p>
<p>“With the traditional model, the infrastructure was built, and the security audit was a post-mortem process,” Jefferson says. “Today, DevSecOps professionals are tasked with baking security into architecture as they build, and into the system as it’s deployed.”</p>
<h3>Culture challenge #2: An “us-versus-them” mindset</h3>
<p>Some of the friction isn’t new: Developers and security pros have often been at loggerheads with one another in the past, notes Meera Rao, senior principal consultant at Synopsys Software Integrity Group.</p>
<p>“The primary cause for this friction is that each team often has its own roadmap, responsibilities, and priorities – and completely different incentives,” Rao says.</p>
<p>Most devs and security practitioners reading this are probably nodding their heads.</p>
<p>“Security teams have long thought that developers were not interested in security,” says Franklin Mosely, senior application security engineer at PagerDuty. “Along those same lines, security teams also thought developers believed that security wasn’t their responsibility.”</p>
<p>Neither is necessarily true, Mosely points out. But the divide can remain evident even in relatively mature DevOps shops – if security remains as a separate entity, it’s effectively siloed, reinforcing an us-versus-them mindset.</p>
<h3>Culture challenge #3: The belief that security hinders innovation</h3>
<p>This belief has helped fuel the traditional conflict between dev and security teams, but it also speaks to a broader antipathy toward IT security, bred from treating security as an afterthought in the software pipeline. (See? We told you these issues often wreak havoc in unison.) As the demand for faster, more frequent delivery continues to grow, there remains a deep-seated view of security as something that slows everything down – the bane of a modern, transformative IT shop.</p>
<p>“We are all very used to this romantic image of the resourceful developer who codes swiftly and slickly – but not necessarily securely, because security has been viewed as the antithesis of function,” says Robert Hawk, privacy and security lead at <a href="https://www.xmatters.com/" target="_blank" rel="noopener">xMatters</a>. “Thus, a big cultural challenge for DevSecOps is to instill order in the face of a legacy of chaos, and somehow accomplish this without hindering innovation.”</p>
<p>This is again both a driving force behind DevSecOps – part of its <em>raison d’etre</em> –  and a fundamental cultural challenge.</p>
<p>“Speed, velocity, and resiliency do not need to be sacrificed in order to be secure and have more stakeholders at the table,” Lawler says.</p>
<h2>Five routes to success</h2>
<p>The solutions to these cultural problems require equal importance in two areas: Tweaking technical strategy and enabling better collaboration and organizational alignment. Let’s delve into five strategies for doing just that:</p>
<h3>1. Have people walk in each other’s shoes</h3>
<p>Ignorance is hardly bliss: When it comes to security, ignorance greatly increases risk. It also breeds misunderstandings and resentment, and that’s what you’re trying to eliminate. Create opportunities for people in different roles to better understand each other’s jobs; many DevOps shops already have experience doing this to create better empathy and alignment between devs and ops. A recurring example is requiring developers to be in the on-call rotation. The same principle applies to security.</p>
<p>“To make security a priority, both security and development teams must learn from each other,” says PagerDuty’s Mosely. “The security professional needs to walk in the developer’s shoes and learn how software is made and the issues that are faced. It’s best to work with developers to come up with solutions that allow them to do the right thing when it comes to security.”</p>
<p>Developers and DevOps pros similarly have a responsibility to work more closely with their security colleagues toward understanding best practices and tools for securing modern infrastructure and software.</p>
<p>“Developers should embrace that security teams have something important to offer in terms of best practices and know-how,” Lawler says. “And security teams should embrace new ways of working and sometimes learn a new lingo to work in the fast flow of modern software engineering. Security needs to be built into development processes early on, and that can only happen when security and development teams collaborate.”</p>
<p>Lawler notes that simply asking people to “do more” on this front is likely just throwing gas on a smoldering fire. So&#8230;</p>
<h3>2. Give people real opportunities to learn and train</h3>
<p>Many of the cultural challenges that can hinder DevSecOps – or any other name you want to give to building a more secure organization – can be attributed to a lack of know-how.</p>
<p>A dev who has never had to be directly responsible for the security of their code in the past, for example, probably hasn’t had much opportunity or incentive to learn best practices for secure application development. Similarly, a siloed security team might have little to no idea how the software they’re charged with securing actually gets built. Change that.</p>
<p>“Most developers aren’t trained in secure coding best practices,” Mosely says. “This creates a situation where engineers are not implementing security thinking and awareness into design, coding, and testing.”</p>
<p>Robust training and learning opportunities are key. Mosely shares two training programs from used at PagerDuty as examples.</p>
<p>“Training can be very effective in creating a mindset where security is more top of mind for our engineers, rather than an afterthought,” he says.</p>
<p>Training and learning can take many forms. Chandrasekaran of Barclaycard says regularly scheduled and unannounced security audits can create good opportunities for learning. He also recommends “hack days” or similar programs, such as a <a href="https://trailofbits.github.io/ctf/" target="_blank" rel="noopener">capture-the-flag event</a> where cross-functional teams are encouraged to actively find and exploit vulnerabilities.</p>
<h3>3. Consider embedding security pros on development or DevOps teams</h3>
<p>If you want to double down on the first two strategies, consider embedding security pros on your development or DevOps teams. Virtually every expert included here spoke of the necessity of breaking down the silo between security and the rest of the team; literally giving security pros a seat at the table can do the job faster.</p>
<p>“IT leaders should create avenues for security experts to be involved in designing, developing and testing code,” says Kiran Chitturi, CTO architect at Sungard Availability Services. “One way is to embed security team members directly into development teams.</p>
<p>Mosely says they’ve used this approach to great effect at PagerDuty, having previously embedded a security engineer on a development team.</p>
<p>“During that time he learned their tools and processes, and the development team gained insight into some security best practices,” Mosely says. “With this knowledge, the security team is better able to assess how they can add value and minimize risk to the business without inhibiting the development processes. At the same time, the product team has a better understanding of things to consider to ensure that they are protecting customer data.”</p>
<h3>4. Explore a “security champion” program</h3>
<p>The embedded approach has a close relative: The security champion. This person need not actually be a security pro, but rather someone who can help drive healthier security habits that spread throughout the organization. (Of course, there should be some incentive or reward for a person who embraces this role, too.)</p>
<p>&#8220;Establishing a training and security champions program allows members of development teams to learn and volunteer to build software security skills and awareness through mentoring, training, and working closely with the application security teams,” Rao of Synopsys says. “These security champions form the front line when it comes to guiding development teams on application security and bridge the gap that exists between DevOps and security teams.”</p>
<h3>5. Embrace automation – and win over skeptics</h3>
<p>Sometimes cultural challenges can, in fact, be overcome with technology. In the case of DevSecOps, most experts agree that automation has myriad benefits.</p>
<p>From the standpoint of cultural resistance, increasing automation is crucial to enabling security to indeed “shift left” in the software pipeline without hindering speed or innovation – while also getting rid of the perception of security as a final step or afterthought.</p>
<p>Let’s address an issue that sometimes gets brushed under the rug: One reason cultural resistance to a change like DevSecOps exists is that at first blush, people see it as translating into net-new work that they don’t necessarily want to do. Asking developers, for example, to simply to “do more,” as Lawler noted above, could be perceived, often rightfully so, as simply adding tasks to their already overloaded plate.</p>
<p>Automation cuts down on the manual toil.</p>
<p>“A lot of verification needs to be automated through the use of a combination of static, runtime and chaos engineering tools to reduce the amount of grunt effort involved,” Chandrasekaran says.</p>
<p>Chitturi of Sungard AS likewise says that “bringing in an automation mindset to teams by introducing tools, techniques, and frameworks that aid in automatic code scanning for security-related checks and dynamic scanning and policing” has been a key strategy in his first-hand experience with overcoming cultural roadblocks to DevSecOps.</p>
<p>Automation also soothes individual fears that you’re going to have to learn all the aspects of security that may occur throughout the DevOps cycle – a daunting thought even for security pros.</p>
<p>Instead, IT leaders should think about how to derive and define security policies from the organization’s governance model, and then choose security experts with the relevant expertise to take responsibility for baking those policies into the various processes in the project or product lifecycle.</p>
<p>“It’s all about automation,” Mike Bursell, chief security architect at Red Hat, recently noted. “The developer, the tester, the designer, the operations person – [all] need to be able to have responsibility for following security-relevant processes, not defining them. Once you have the processes in place, you can manage by exception: Instead of trying to check that people do the right thing all of the time, spot when they do the wrong thing and sort it out from there.”</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.bestdevops.com/devsecops-how-to-conquer-3-big-culture-challenges/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>A proactive flavor of DevOps grows at Google</title>
		<link>https://www.bestdevops.com/a-proactive-flavor-of-devops-grows-at-google-2/</link>
					<comments>https://www.bestdevops.com/a-proactive-flavor-of-devops-grows-at-google-2/#respond</comments>
		
		<dc:creator><![CDATA[anil]]></dc:creator>
		<pubDate>Mon, 13 Aug 2018 06:10:10 +0000</pubDate>
				<category><![CDATA[DevOps]]></category>
		<category><![CDATA[DevOps Updates]]></category>
		<category><![CDATA[Computer Science]]></category>
		<category><![CDATA[Data centers]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[innovation]]></category>
		<category><![CDATA[Software Development]]></category>
		<guid isPermaLink="false">http://www.bestdevops.com/?p=4221</guid>

					<description><![CDATA[Source &#8211; zdnet.com Everyone wants to do DevOps these days, but what does a well-humming DevOps environment really look like? [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Source &#8211; zdnet.com</p>
<p>Everyone wants to do DevOps these days, but what does a well-humming DevOps environment really look like? What is the vision to strive for?</p>
<p>To date, DevOps has been popping up as a hodgepodge of activities and initiatives across companies, perhaps in the name of doing it because it&#8217;s the thing to do. As a result, companies really aren&#8217;t seeing the full potential of DevOps. Consistency in DevOps approaches is a rare thing indeed, relates Kurt Marko, citing a recent survey from Computer Economics. The survey finds &#8220;that although about a third of organizations dabble in DevOps, almost none do so formally and consistently across the organization or show any semblance of mastering of DevOps practices.&#8221;</p>
<p>That&#8217;s because DevOps is more than demanding that everyone get together and throwing some new tools into the mix. As Marko puts it: &#8220;DevOps is like dieting: it requires changes in values, attitudes, processes and habits. Such changes are hard and must be practiced, not bought. They require education and discipline, not a purchase order.&#8221;</p>
<p>The folks at Google/Alphabet, being the trailblazers they always are, are sharing their vision and experience with what they call &#8220;site reliability engineering&#8221; (SRE), providing some examples of how well-tuned teams of developers and ops people can work together to make things happen. Rest assured, it is baked deeply into the Google culture.</p>
<p>To clarify, SRE is somewhat different from DevOps, but joined at the hip. &#8220;Interestingly, the SRE movement emerged separately from the DevOps movement&#8211;although there is little doubt that they are part of the same IT spectrum with similar customer value-driven goals,&#8221; Jayne Groll observes in DevOps.com. &#8220;DevOps focuses on engineering continuous delivery to the point of deployment; SRE focuses on engineering continuous operations at the point of customer consumption. Both domains rely on sharing, culture, metrics and automation. Both require human and automated resources to ensure a seamless value stream and exceptional customer experience.&#8221;</p>
<p>A great illustration is provided by Patrick Hill, site reliability engineer with Atlassian:</p>
<blockquote><p>&#8220;Dev teams want to release awesome new features to the masses, and see them take off in a big way. Ops teams want to make sure those features don&#8217;t break things. Historically, that&#8217;s caused a big power struggle, with Ops trying to put the brakes on as many releases as possible, and Dev looking for clever new ways to sneak around the processes that hold them back. SRE removes the conjecture and debate over what can be launched and when. It introduces a mathematical formula for green- or red-lighting launches, and dedicates a team of people with Ops skills (appropriately called Service Reliability Engineers, or SRE&#8217;s) to continuously oversee the reliability of the product.&#8221;</p></blockquote>
<p>In their latest book and videos on the topic, Betsy Beyer, Chris Jones, Jennifer Petoff and Niall Murphy, all with Google, unveil what they have been doing and provide lessons from which every non-Google enterprise can learn. &#8220;For sizes between a startup and a multinational, there probably already is someone in your organization who is doing SRE work, without it necessarily being called that name, or recognized as such,&#8221; they point out.</p>
<section class="sharethrough-top" data-component="medusaContentRecommendation" data-medusa-content-recommendation-options="{&quot;promo&quot;:&quot;promo_ZD_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}"></section>
<p>SRE &#8220;represents a significant break from existing industry best practices for managing large, complicated services,&#8221; Beyer and her associates write, noting this is the best way for a software engineer to invest time to accomplish a set of repetitive tasks. At the same time, &#8220;it has become much more: a set of principles, a set of practices, a set of incentives, and a field of endeavor within the larger software engineering discipline.&#8221;</p>
<p>The Google team explains that they &#8220;apply the principles of computer science and engineering to the design and development of computing systems: generally, large distributed ones.&#8221; Their tasks range from &#8220;writing the software for those systems alongside our product development counterparts;&#8221; to building pieces such as &#8220;backups or load balancing,&#8221; or simply &#8220;figuring out how to apply existing solutions to new problems.&#8221;</p>
<p>SREs have three missions: reliability, features and operating services.</p>
<ul>
<li><strong>Reliability:</strong> Reliability is the top priority for SREs. The Google team cites the words of Google&#8217;s Ben Treynor Sloss, originator of the term SRE: &#8220;Reliability is the most fundamental feature of any product: a system isn&#8217;t very useful if nobody can use it.&#8221;</li>
<li><strong>Features:</strong> Once suitable levels of reliability are attained, SREs are charged with features and products.</li>
<li><strong>Operating services:</strong> &#8220;Finally, SREs are focused on operating services built atop our distributed computing systems, whether those services are planet-scale storage, email for hundreds of millions of users, or where Google began, web search.&#8221;</li>
</ul>
]]></content:encoded>
					
					<wfw:commentRss>https://www.bestdevops.com/a-proactive-flavor-of-devops-grows-at-google-2/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Why you should apply change management in DevOps failures</title>
		<link>https://www.bestdevops.com/why-you-should-apply-change-management-in-devops-failures-2/</link>
					<comments>https://www.bestdevops.com/why-you-should-apply-change-management-in-devops-failures-2/#respond</comments>
		
		<dc:creator><![CDATA[anil]]></dc:creator>
		<pubDate>Mon, 13 Aug 2018 06:06:58 +0000</pubDate>
				<category><![CDATA[DevOps]]></category>
		<category><![CDATA[DevOps Best Practices]]></category>
		<category><![CDATA[DevOps Updates]]></category>
		<category><![CDATA[applications development]]></category>
		<category><![CDATA[Continuous Delivery]]></category>
		<category><![CDATA[Continuous Integration]]></category>
		<category><![CDATA[DevOps Failures]]></category>
		<category><![CDATA[Software Delivery]]></category>
		<guid isPermaLink="false">http://www.bestdevops.com/?p=4218</guid>

					<description><![CDATA[Source &#8211; techtarget.com In a digital world, every company depends on software to continuously improve its products and business. This need [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Source &#8211; techtarget.com</p>
<p>In a digital world, every company depends on software to continuously improve its products and business. This need for continuous speed has led to the explosion of DevOps initiatives.</p>
<p>Well-executed change management in DevOps shortens software release cycles while improving quality. These conditions, in turn, make continuous integration, regular deployment and continuous delivery possible. For many organizations, however, DevOps remains a distant mirage rather than a reality.</p>
<section class="section main-article-chapter" data-menu-title="So why do some DevOps initiatives fail?">
<h3 class="section-title">So why do some DevOps initiatives fail?</h3>
<p>DevOps success depends on tools, processes and people. The vast majority of problems, though, are rooted in failures on the people side rather than the technology. Organizations need to stop looking for a new tool to throw at the problem. Instead, they should focus their efforts on how to use change management in DevOps to break down silos and create collaborative, cross-functional teams. Your team may have the latest and greatest automation tools and technologies, but if you can&#8217;t align the stakeholders &#8212; from line-of-business to operations &#8212; your DevOps project is destined to fail.</p>
<h3 class="section-title">Potential pitfalls</h3>
<section class="section main-article-chapter" data-menu-title="Potential pitfalls">Many DevOps projects actually start off on the right track. Over time, however, teams retreat to their comfort zones and normal routines and hide behind their old processes and service-level agreements. The initial promise of cross-team collaboration fades. To keep the momentum of change management in DevOps rolling, project meetings need to include representatives from every cross-functional team, and the meeting must focus on people as well as tools and infrastructure.</p>
<p>When a DevOps initiative starts to fail, many organizations will repeat the same approach with the same people and hope the outcome will change. The key to a successful DevOps project is change. Don&#8217;t hope your DevOps project will have a better outcome with the same inputs. This may require changing the people, process or technology &#8212; or all of the above.</p>
</section>
<section class="section main-article-chapter" data-menu-title="Change management in DevOps">
<h3 class="section-title">Change management in DevOps</h3>
<p>It&#8217;s important to note that many projects veer off track at some point. Rather than burying your head in the sand, you need to be able to course correct and remain focused on the goal. This requires clear objectives for your DevOps project and a strong, people-focused leader who can foster collaboration across teams.</p>
<p>Think about DevOps as change management and as a collaborative partnership to find the best practices to achieve your goals of continuous integration and delivery. It&#8217;s important to remember that the initial teething pains with DevOps are well worth the end result: to deliver applications and software at a high velocity.</p>
</section>
</section>
]]></content:encoded>
					
					<wfw:commentRss>https://www.bestdevops.com/why-you-should-apply-change-management-in-devops-failures-2/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>DevOps 101: Adopt Continuous Innovation</title>
		<link>https://www.bestdevops.com/devops-101-adopt-continuous-innovation/</link>
					<comments>https://www.bestdevops.com/devops-101-adopt-continuous-innovation/#respond</comments>
		
		<dc:creator><![CDATA[anil]]></dc:creator>
		<pubDate>Fri, 10 Aug 2018 05:17:58 +0000</pubDate>
				<category><![CDATA[DevOps]]></category>
		<category><![CDATA[DevOps Best Practices]]></category>
		<category><![CDATA[DevOps Updates]]></category>
		<category><![CDATA[Application Development]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[Big data]]></category>
		<category><![CDATA[Continuous Innovation]]></category>
		<category><![CDATA[Machine Learning]]></category>
		<guid isPermaLink="false">http://www.bestdevops.com/?p=4200</guid>

					<description><![CDATA[Source &#8211; informationweek.com DevOps requires some hard work and tough choices, but in the end can keep a business competitive and [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Source &#8211; informationweek.com</p>
<p><span class="strong black">DevOps requires some hard work and tough choices, but in the end can keep a business competitive and innovative.</span></p>
<p class="">I’ve spent a good portion of my career interacting with DevOps, but from an infrastructure and data center perspective. In that role, my goal was to eliminate legacy components from infrastructure so that the entire process could then impact both DevOps and the business overall. Today, my focus has shifted into the world of cloud, DevOps, and advanced technology solutions like artificial intelligence, machine learning, big data, and even natural language processing.</p>
<p>Today, we focus on DevOps. And this next part is really important:DevOps is NOT just for developers.</p>
<p>Too often &#8212; and I was guilty of it in the past &#8212; a person not directly involved with DevOps thinks that this is a bunch of coders doing some kind of development operation; without understanding what that means.</p>
<p>When it comes to DevOps, there is so much more to the story and the process. In fact, business leaders and even &#8220;traditional&#8221; IT people need to know what DevOps is and what it can do for a company. I&#8217;m seeing more custom application development and even integration with advanced software development kits (SDKs) and APIs.</p>
<p>Before we go on, I need to touch on the concept of legacy. At a high level, this is any process or operation that requires quite a bit of manual intervention and a lot of complex reactive support. This can be code, business or IT processes, and even IT infrastructure. Gartner recently pointed out that legacy infrastructure and operations practices are not sufficient to meet the demands of the digital business. As we all evolve into a data-driven society, digital transformation will require agility and velocity that outstrips classical architectures and practices.</p>
<p>Gartner mentioned that in 2018, IT will be increasingly tasked with supporting complex, distributed applications using new technologies that are spread across systems in multiple locations, including on-premises data centers, the public cloud and hosting providers.</p>
<p>Now, let’s understand DevOps.</p>
<p>First of all, DevOps isn’t just two words combined together. DevOps is all of the following:</p>
<ul>
<li>A <strong>cultural shift</strong> in how processes, code, and technology are delivered.</li>
<li>A <strong>philosophy</strong> around continuous development and integration with users, business, and even market dynamics.</li>
<li>A <strong>practice</strong> that continuously evolves.</li>
<li>A <strong>tool</strong> to help deliver services and applications and market-ready speeds.</li>
<li>A <strong>process</strong> to help companies innovate at a much faster pace than what traditional (or legacy) software tools and infrastructure could offer.</li>
</ul>
<p>While it often is referred to as &#8220;agile operations&#8221;, Jez Humble, co-author of The DevOps Handbook, defines DevOps as “a cross-disciplinary community of practice dedicated to the study of building, evolving, and operating rapidly-changing resilient systems at scale.”</p>
<p>I think you get the point. DevOps in today’s world is a technological and cultural shift to allow for continuous integration, continuous development, and continuous innovation.</p>
<p>I’ve had the chance to work with global enterprises and those in the mid-market. I’ve seen each of them develop customized applications and millions of lines of code that they now struggle to manage. Now, each of them is trying to understand how to get to &#8220;a state of DevOps&#8221; and how to get rid of legacy development practices. In that experience, many of my conversations boil down to the following five points.</p>
<p><strong>You need to have a &#8220;coming to terms&#8221; moment and realize that your development process is not capable of scaling or adapting to market needs. </strong>Like a chef in their own kitchen, you truly believe that your soup is already perfect. However, you need to understand your development processes and where there are holes. Maybe you’re leveraging too many custom systems, maybe you’re still coding into applications that should be retired. Or, maybe your competition is starting to outpace you. In organizations that I’ve worked with this was the realization that they came to. Their development processes simply couldn’t support the pace of the market. An evaluation of your ecosystem could give you a lot of answers. Where are there faults? Where does the process work? Where can there be improvements? These are challenging questions but they’re a key start to the process.</p>
<p><strong>You need to dedicate time to understanding your systems, dependencies, and how you’ve been delivering applications and services today.</strong> We live in a data-driven world. Not just about the data we generate; but also the code we’ve create. Applications are complex systems. Data and applications are some of the hardest parts of the environment to work with, especially when there’s a migration in the discussion. To get to a state of DevOps, you’ll need to go on a journey. This one will revolve around a deep-dive around your applications, your code, the libraries that code requires, the process in compiling that code, where data repositories sit, what APIs you use, and more.</p>
<p><strong>You will need to create a &#8220;future-state&#8221; to work towards. </strong>A key part of the DevOps process is the need to design for the future. This means planning around cloud adoption, system migration, future removal of legacy infrastructure, and even future application requirements. Every DevOps planning session I’ve been a part of includes this process. It helps business leaders better understand where continuous development, integration, and innovation can benefit their organization and competitive stance.</p>
<p><strong>You will need to include infrastructure <em>and</em> cloud teams in the planning process. </strong>Don’t lock your server and data center team members out of the DevOps conversation. Right now, I’m helping a customer migrate a massively heterogenous architecture into a hyper-converged platform to allow them to be way more agile. Make sure you include your cloud architects as well; there are so many amazing DevOps tools and functions that the cloud can offer. Remember, DevOps is a cultural shift as well as philosophy. This shift has to happen at multiple levels for the entire process to be successful.</p>
<p><strong>You should work with a partner who can help you create a solid DevOps practice. </strong>Although DevOps is designed to make your life easier. Getting there isn’t simple, it can be discouraging if you have a really complex environment to begin with. Working with a good partner can simply begin the conversation and help you understand where you need to evolve your own ecosystem. Working with a partner who can get you to a state of DevOps is great for your business, your developers, and your process overall.</p>
<p>The ultimate goal is to get to a process where you’re not releasing updates on some weekly schedule. Rather, this process is done continuously. Oftentimes, application release updates can be done several times a day. And so, the DevOps cycle is:  Plan, Create, Verify, Package, Release, Configure, and Monitor.</p>
<p>Once you adopt this model, integrating new processes, systems, tools, and even business units becomes much easier. Continuous integration and development lets you stay truly agile in a dynamic market. Get started on this process right now. Otherwise, you’ll just keep writing code and that legacy challenge will only get worse. When your own DevOps strategy becomes a reality, you create an engine around innovation that’ll help you stay competitive and better support your customers.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.bestdevops.com/devops-101-adopt-continuous-innovation/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How to turn DevOps fakers into believers</title>
		<link>https://www.bestdevops.com/how-to-turn-devops-fakers-into-believers/</link>
					<comments>https://www.bestdevops.com/how-to-turn-devops-fakers-into-believers/#respond</comments>
		
		<dc:creator><![CDATA[anil]]></dc:creator>
		<pubDate>Thu, 09 Aug 2018 06:32:01 +0000</pubDate>
				<category><![CDATA[DevOps]]></category>
		<category><![CDATA[DevOps Best Practices]]></category>
		<category><![CDATA[DevOps News]]></category>
		<category><![CDATA[DevOps Updates]]></category>
		<category><![CDATA[DevOps fakers]]></category>
		<category><![CDATA[DevOps transformation]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Software Development]]></category>
		<guid isPermaLink="false">http://www.bestdevops.com/?p=4194</guid>

					<description><![CDATA[Source &#8211; enterprisersproject.com We recently shared some strategies for sniffing out DevOps fakers in your recruiting and hiring. By DevOps fakers, we mean candidates whose [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Source &#8211; enterprisersproject.com</p>
<p>We recently shared some strategies for sniffing out DevOps fakers in your recruiting and hiring. By DevOps fakers, we mean candidates whose qualifications for a DevOps role might be more hype than substance.</p>
<p>But what if the “faker” is already on your team? Moreover, what if they’re faking not their technical skills or other qualifications – you hired them, after all – but their commitment to your organization’s ongoing DevOps transformation? They’re talking the talk but not walking the walk, perhaps. Or maybe they even balk at the talk.</p>
<p>A healthy DevOps culture depends on team members’ commitment. If you have too many people who are quietly hanging on to their monolithic ways – siloed thinking that produces conflicts and blame; waterfall development practices that slow the delivery pipeline to a trickle; fear and loathing of automation, and so on – then your DevOps culture is at risk.</p>
<p>That healthy DevOps culture is fundamentally about continuous improvement throughout the team. Everyone has room for improvement; some people might need a bit more help than others, and it’s your job as an IT leader to help them get it. We asked several DevOps leaders and practitioners for advice on doing just that. Consider these five practical strategies for converting your DevOps fakers into true believers:</p>
<h4>1. Tailor strategy to the person’s level or role</h4>
<p>For Anders Wallgren, CTO and co-founder at Electric Cloud, coaching a DevOps laggard starts similarly to any other scenario that requires your active leadership. First, you need to take into account the person’s specific role and level in the organization.</p>
<p>“A VP of engineering who can’t break out of the waterfall mentality is a very different problem than an individual contributor a few years out of school who needs coaching on how to write testable code,” Wallgren says.</p>
<p>The former scenario is a more urgent issue that you’ll have to address on a case-by-case (and hopefully limited) basis. The latter scenario is more likely to surface, and it’s also not usually a fire-alarm situation.</p>
<p>Rather, it’s a matter of helping people learn and understand what they don’t know, especially if they’re less experienced or if they’re transitioning from a legacy organization into a DevOps team. A strong DevOps leader makes DevOps processes, tools, and culture a part of someone’s ongoing professional development and goals.</p>
<p>“In my organization, we try to get every dev up to speed on DevOps as they progress up the career ladder,” says Nate Berent-Spillson, senior delivery director at Nexient.</p>
<p>It could be that an early career developer, for example, isn’t “faking it” but simply has significant blind spots in their knowledge of how software gets operated. Berent-Spillson says a dev might literally not know how their code gets deployed or runs in production, for example, or they might not know networking basics like DNS, TCP/IP, or load balancing.</p>
<p>“There’s a lot that I sometimes take for granted on the infrastructure side that many developers don’t know,” he says.</p>
<h4>2. Make DevOps changes more digestible</h4>
<p>Someone who appears resistant to your DevOps transformation might actually just be overwhelmed by the scope and pace of change. Break the issues down into smaller parts – think of it like a microservices architecture for DevOps culture – to help them get on board.</p>
<p>“You have to meet them where they’re at, and give them good solid working examples,” Berent-Spillson says. “Breaking down the problem space into individual slices, and having them solve each one and incrementally to build a more complex pipeline. How do you read and troubleshoot logs? How do you reproduce a failure locally first?”</p>
<p>This might be an especially important strategy in organizations that are shifting to DevOps from a legacy model; these teams have to keep the lights on while they navigate this significant change.</p>
<p>“In most IT and dev shops, individuals and teams are barely treading water with current initiatives and addressing existing technical debt,” says Chris Ciborowksi, CEO at Nebulaworks. “Finding time to pick up new something new, be it tools or processes, and get them integrated with a high degree of success is unlikely and they know this. As such, barriers go up.”</p>
<p>One tactic for addressing this challenging scenario, according to Ciborowski: Identify some existing piece of the team’s workload that isn’t tied to an immediately critical business goal or outcome, rip it out, and replace it with a minimum viable product (MVP) approach.</p>
<p>It should be viewed not as a “final-state” project, but a first attempt that can then be optimized, iterated, and –  perhaps most importantly – learned from, as part of the team’s DevOps transformation, Ciborowski notes. This can lead to the kinds of early wins that build teamwork and traction that breaks down barriers and converts people into DevOps believers over time.</p>
<h3>3. Align and optimize incentives among teams</h3>
<p>Too often, siloed IT teams have some common goals but conflicting incentives to achieve those goals. If those are still in play, they’re likely root causes of people faking their DevOps enthusiasm while remaining stuck in old conflicts.</p>
<p>A common example of this kind of conflict is when developers are too narrowly focused on their time to delivery, while operations pros are solely concerned with systems stability and uptime.</p>
<p>“If these cross-functional teams and their management are using more business value delivery-focused ways of measuring their performance, like feature lead time, mean time to recovery, and deployment frequency, they’ll have a common definition of success,” says Justin Rodenbostel, VP, open source application development at SPR. “When that common definition exists, teams will start to experience success together, which helps remove barriers to adoption and gets the team moving in the same direction.”</p>
<p>Rodenbostel also notes the importance of IT leadership’s unwavering support during this transformative phase: If people are getting mixed messages from you, they’re less likely to believe in the long-term vision.</p>
<h4>4. Give people more input and ownership</h4>
<p>If you’re struggling to get some people to buy into DevOps, you might need to give them more power to buy-in: As in, more ownership and authority over their roles and responsibilities.</p>
<p>“Incentives can be good motivators, but without getting buy-in and creating a sense of ownership within the team for related goals, they can fall short,” Rodenbostel says. He offers a few tips for creating this greater sense of ownership:</p>
<ul>
<li>Let team members help define their performance goals and incentives together.</li>
<li>Make sure early progress is attainable. (See the “make it manageable” section above.)</li>
<li>Make sure that progress is measurable and avoid “success theater.”</li>
</ul>
<h4>5. Play the DevOps long game</h4>
<p>We mentioned at the outset Wallgren’s perspective that converting your DevOps skeptics into believers isn’t all that different from other situations that require your leadership and guidance.</p>
<p>“It’s no different than coaching or mentoring in any other scenario,” Wallgren explains. “Focus on outcomes, learning, communication, openness.”</p>
<p>Indeed, while someone might indeed be “faking” their commitment to DevOps, it’s important to consider the role you play in that. Are you really offering the kind of unwavering support that Rodenbostel advises above? Are you giving people ownership and making things manageable for them?</p>
<p>DevOps doesn’t really have a finish line; some organizations might have a more robust or mature DevOps culture than others, but they’re never “done.” They’re always learning and getting better, and that’s the most powerful tool there is for building and renewing a successful DevOps shop.</p>
<p>“Fostering a culture of continuous improvement is extremely important for long-term success in adopting DevOps,” Rodenbostel says. “Part of that is creating an environment where individuals and teams can learn from each other and grow together. Organizational leaders must ensure that there are opportunities for this to happen and continue to support this type of collaboration.”</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.bestdevops.com/how-to-turn-devops-fakers-into-believers/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>A Right DevOps Approach: Assess Organizational Readiness</title>
		<link>https://www.bestdevops.com/a-right-devops-approach-assess-organizational-readiness/</link>
					<comments>https://www.bestdevops.com/a-right-devops-approach-assess-organizational-readiness/#respond</comments>
		
		<dc:creator><![CDATA[anil]]></dc:creator>
		<pubDate>Wed, 08 Aug 2018 06:05:00 +0000</pubDate>
				<category><![CDATA[DevOps]]></category>
		<category><![CDATA[DevOps Tools]]></category>
		<category><![CDATA[DevOps Updates]]></category>
		<category><![CDATA[DevOps automation]]></category>
		<category><![CDATA[DevOps Readiness]]></category>
		<category><![CDATA[Software Development]]></category>
		<guid isPermaLink="false">http://www.bestdevops.com/?p=4185</guid>

					<description><![CDATA[Source &#8211; devops.com Driving business in this fast-paced world is maddening as owners have to remember customer preferences, beat market competition [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Source &#8211; devops.com</p>
<p>Driving business in this fast-paced world is maddening as owners have to remember customer preferences, beat market competition and similarly cater to different things within the organization’s radius.</p>
<p>How a business owner manages all this defines the business success, which is gauged through outcomes in the form of smart products, point-on services and almost-immediate feedback. Bank applications, the best smartphones and interactive technology are all proof of this.</p>
<p>But what is it that stands at the heart of it all?</p>
<h4>The Right DevOps Approach</h4>
<p>When enough is done and businesses still find that there’s a missing piece that will complete “the successful business picture,” they go back to figuring out what and how they can fix the problem. They never come to realize that they will have to consider revamping their organizational structure to meet the growing demands of their influential business.</p>
<p>How, then, do you assess your approach to DevOps?</p>
<p>While most believe that it’s a technological approach that they should incorporate in their business, it’s more of a cultural approach. To implement DevOps into your existing organizational structure, you first must look at its current state of readiness.</p>
<p>Doing this is important, as it helps decision-makers understand how they can embed the smart collaboration after a thorough consideration of the challenges that stand in the way of DevOps implementation. Once the initial assessment is done, business owners need to ask themselves three questions before assessing DevOps readiness:</p>
<p>&nbsp;</p>
<ol>
<li><strong>Is there a Management-Employee Agreement? </strong>A successful DevOps process not only relies on collaboration between Development and Operations, but also needs a top-down (management-employee) agreement. Once that’s in place, the company is already halfway through the success road.</li>
<li><strong>Is there a Plan in Place? </strong>Many firms just barge into technology like it’s all they need to reach their finish line. Stop! Wait! Think! Owners need to have a detailed strategy, equipped with process tools and goals clearly outlined and best practices chalked out. Once this is done, the culturally different teams need to collaborate and work ways to learn and equip themselves with the technologies and practices of each other’s processes. With all this in place, organizations will be ready to take the DevOps jump.</li>
<li><strong>Is the Organization Ready to Tread the Ocean? </strong>Now that the plan is in place, what’s next? Organizations, as mentioned earlier, are in hot pursuit to experiment with what they’ve learnt new. Anything new is fancy, but humbleness is the key! Starting small will set the new cultural shift to completely settle in its new mold. To run the boat in big waters, you first need to test it in small water. Similarly, to test the success of DevOps for a big business project, you first want to test its adaptability to a smaller one. Once you’ve cut off from the harbor, you are all set to wade the ocean.</li>
</ol>
<h4><strong>Conclusion</strong></h4>
<p>Most business players underestimate the ability of DevOps with whatever industry rumors they hear and some of their own pre-conceived notions. Some other think that they know it all, but what matters is having a strategic approach to first considering DevOps and its tools<u>,</u> and then adapting it accordingly.</p>
<p>Once the DevOps automation is in place, organizations will be busy reaping the benefits of its successful implementation.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.bestdevops.com/a-right-devops-approach-assess-organizational-readiness/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How Can DevOps Enable Your Software Testing efforts?</title>
		<link>https://www.bestdevops.com/how-can-devops-enable-your-software-testing-efforts/</link>
					<comments>https://www.bestdevops.com/how-can-devops-enable-your-software-testing-efforts/#respond</comments>
		
		<dc:creator><![CDATA[anil]]></dc:creator>
		<pubDate>Sat, 04 Aug 2018 05:49:32 +0000</pubDate>
				<category><![CDATA[DevOps]]></category>
		<category><![CDATA[DevOps Best Practices]]></category>
		<category><![CDATA[DevOps Updates]]></category>
		<category><![CDATA[automation software]]></category>
		<category><![CDATA[DevOps software testing]]></category>
		<category><![CDATA[Digital Transformation]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Software Testing]]></category>
		<guid isPermaLink="false">http://www.bestdevops.com/?p=4163</guid>

					<description><![CDATA[Source &#8211; devops.com Digital transformation is not an easy task for business enterprises. There are myriad issues to conquer, such as [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Source &#8211; <strong>devops.com</strong></p>
<p>Digital transformation is not an easy task for business enterprises. There are myriad issues to conquer, such as department silos, legacy systems and a well-entrenched work culture that often refuses to align with the business goals. Needless to say, the imperatives of reaching out to the market quickly and with quality products often are not achieved because of these issues. To eliminate the bottlenecks that end up blighting business enterprises, a growing number of organizations are adopting DevOps, which involves an end-to-end automation of processes, be it for development, testing or deployment.</p>
<p>DevOps takes the Agile methodology a step further by involving all the stakeholders of an enterprise. The DevOps testing strategy encompasses continuous improvement of software products to address the changing customer preferences.</p>
<p>In DevOps software testing, the aim is to detect and eliminate glitches proactively to reduce the cost and time to fix issues that can lead to a poor user experience. In the highly competitive digital market, a poor user experience can stymie a business’s market readiness.</p>
<p>However, businesses should realize that the DevOps software testing approach is a journey and should be leveraged to enhance the user experience on a continuous basis.</p>
<h4><strong>What’s the Key Value Expected from DevOps?</strong></h4>
<p>Considering that the development and operations teams of an enterprise each have different work cultures, systems, goals, tools and approaches, the quality and delivery schedule of applications can be thrown off. Hence, the significance of DevOps testing strategy comes into play to bring synergy between the teams and to enhance the quality and delivery of applications consistently.</p>
<p>DevOps calls for the integration of development and operations teams, wherein QA is made everyone’s responsibility. The synergy helps in breaking the departmental silos and posits the role of QA as an enabler of value addition and to achieve customer delight. This not only ensures quality, but also enables faster turnaround on application development process. Ultimately, enterprises are better equipped for the changing market dynamics and challenges with their business applications.</p>
<h4><strong>Key Drivers to Adopt DevOps</strong></h4>
<p>George Spafford, research director at Gartner, said:</p>
<blockquote><p>“A DevOps initiative must focus on business requirements and not on ‘doing DevOps for the sake of DevOps,’ wherein the methods and tools become more important than what customers need. Organizations must avoid the all-too-common mistake of launching a DevOps initiative before establishing that a business reason exists to do so. For example, instead of focusing on release rates and doing things faster, start with the business value by asking what that will enable.&#8221;</p></blockquote>
<p>Hence, it’s important to work with a DevOps strategy that resonates with the business objectives. These are some key drivers for considering DevOps.<strong><br />
</strong></p>
<ul>
<li>Quick deployment of quality applications across devices, platforms, operating systems and networks.</li>
<li>Increasing competition necessitating the faster release of apps.</li>
<li>Emerging technological platforms whetting the appetite of customers for better products.</li>
<li>The emergence of complex applications with footprints in the physical and virtual world.</li>
</ul>
<h4><strong>How Does DevOps Enable Effective Quality Assurance?</strong></h4>
<ul>
<li>It makes QA a collective responsibility rather than being assigned to a single department or organization.</li>
<li>It enables better collaboration between teams through a shift of culture.</li>
<li>It ensures faster identification and elimination of glitches.</li>
<li>It is responsible for accelerating the time to market and keeps a tab on the software quality through customer feedback.</li>
<li>It provides continuous improvement of software through timely releases.</li>
<li>It reduces cost due to the absence of rework.</li>
<li>It optimizes the utilization of resources and prevents waste.</li>
<li>It helps to cut down the software development life cycle (SDLC) by adopting quick sprints.</li>
<li>It ensures continuous development, testing, integration, deployment, monitoring and innovation of applications.</li>
</ul>
<h4><strong>The Need to Measure DevOps</strong></h4>
<p>Digital transformation has necessitated the need for rapid innovation, development, testing and deployment of applications. Post deployment, appropriate customer feedback should be considered and absorbed into the product to improve its performance further. The success of DevOps QA depends on the level of automation, not to speak of the degree of collaboration among various stakeholders.</p>
<p>In fact, enterprises should use a robust automation software to execute quality assurance across platforms and devices. The automation software should be able to test the code as part of the development sprint on a variety of devices and test environments. The DevOps QA approach should be measurable based on certain metrics to ensure its effectiveness. The measurement platform can include the following:</p>
<ul>
<ul>
<li>The QA team dealing with continuous integration should be able to work with all the tools to find out glitches.</li>
<li>The entire setup should be simple to facilitate quicker learning, adoption and execution.</li>
<li>The test data including dependencies should be easy to access.</li>
<li>The entire build, deploy, release, verify and rework processes should be streamlined.</li>
</ul>
</ul>
<p>&nbsp;</p>
<h4>Conclusion</h4>
<p>In the fast-changing digital landscape, the objective of reaching out to the customers quickly and with better quality of products is paramount. This is where the DevOps specialists turn things around with continuous improvement, innovation and deployment.</p>
<p>As Gartner’s Spafford rightly stated, “DevOps challenges conventional IT thinking with its lack of a standard definition and approach, its constant evolution, and its requirement for acceptance and management of risk.”</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.bestdevops.com/how-can-devops-enable-your-software-testing-efforts/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
