DevOps Days Podcast

DevOps Days Podcast

By DevOpsDays.orgTechnology
Download on the App Store

DevOps Days Podcast episodes

  • 2015 - DevOpsDays DC - 24 - Avoiding the "Half-Baked Zone" - The Fallacy of Real-Time Analytics in Performance Monitoring

    Is your performance monitoring using real-time analytics in a way that will produce results or noise and frustration? Real-time analytics can improve the value of performance monitoring by enabling operations teams to pinpoint problems faster and proactively manage applications, but it’s notoriously difficult to harness its value. In this presentation, we will show you how to avoid the pitfalls of partial analytics implementation, and explain the value of a comprehensive monitoring analytics platform.

    0 min
  • 2015 - DevOpsDays DC - 20 - Effective Infrastructure Code Review

    Once infrastructure becomes code it becomes testable as code (testing is generally considered a pretty good idea). It also becomes reviewable as code. Code review is a powerful complement to testing (and might just be the more effective of the two for finding bugs), spreading knowledge, and improving at the craft of programming

    In this talk:

    • Be convinced reviewing code review is also a pretty good idea.
    • Cover pre and post commit workflows and example tooling to make your day better.
    • Lessons from the messy growing pains of growing an organization from virtually no formal code review to reviewing every commit.
    • Best practices for being an effective reviewer and reviewee.
    0 min
  • 2015 - DevOpsDays DC - 28 - Consumer to Collaborator: Re-imaging the US Government's role in Open Source

    Government agencies are often hesitant to use open source tools out of concerns of security and compliance issues. This hesitancy to use open source deprives many government agencies from closely collaborating with others to create software that is finely tuned and widely available to scratch its own itch. The five-year old OpenSCAP community is helping to change that and re-imagining the US Governments role in open source through its NIST-Certified SCAP 1.2 scanning software and growing body of open source licensed SCAP content. By the OpenSCAP suite scanning and configuration management tools, government agencies looking to become high velocity organizations can automate the cumbersome process certifying a server has been properly hardened for production and begin to develop community resources for hardening of other popular open source tools. The OpenSCAP community is actively developing suite of software tools to make continuous monitoring in agile environments easier, especially for developers, who often do not realize they could be scanning their systems more collaboratively with Ops. OpenSCAP is not merely a secure piece of open source software, it is software that helps demonstrate security and compliance. The SCAP-Security-Guide Project is the only source of official configuration management SCAP and hardening content for Linux that is licensed open source and also directly reviewed by official government agencies. Initially started (and still significantly funded) by Red Hat, the OpenSCAP project has recently moved it's repository from the the Fedora Project to GitHub and has seen an increase in the pace of development.

    0 min
  • 2015 - DevOpsDays DC - 30 - DevOops & How I hacked you

    In a quest to move faster, organizations can end up creating security vulnerabilities using the tools and products meant to protect them. Both Chris Gates and Ken Johnson will share their collaborative research into the technology driving DevOps as well as share their stories of what happens when these tools are used insecurely as well as when the tools are just insecure.

    Technologies discussed will encompass AWS Technology, Chef, Puppet, Hudson/Jenkins, Vagrant, Kickstart and much, much more. This talk will most definitely be an entertaining one but a cautionary tale as well, provoking attendees into action. Ultimately, this is research targeted towards awareness for those operating within a DevOps environment.

    0 min
  • 2015 - DevOpsDays DC - 35 - Getting the Message Out in the (Big, Bad, Government) Enterprise

    Or, "Automation is hard and the enterprise is large."

    Fewer steps, decreased time-to-production, faster iteration cycles... Devops practically sells itself - except when it doesn't. You can do all the right things but if you don't make it matter for Mission(tm), nobody will listen. We're very good at the first step toward excellence (doing great things) but we often forget about the follow-up - talk about it. But how? Where? Changing culture isn't easy, especially when you're a single person inside a huge government organization. We'll show a few tips we've learned along our journey toward making government work a little less painful. Speed of government? Red tape? Legions of bureaucrats with nothing better to do than slow you down? We know your pain. We're here to help.

    0 min
  • 2015 - DevOpsDays DC - 36 - DevOps Security and Continuous Failure: Lessons From Heartbleed, Shellshock, and Countless Other Security Flaws

    We pursue increasingly rapid delivery cycles while acheiving previously unimaginable degrees of scalability, reliability, and raw performance. But there is obviously a growing and serious mismatch between our develoment and operations performance in securing our applications compared to our performance in other areas. I work at a company extensively involved in Drupal and other open source projects that concentrate on both DevOps and security, but continue to be plagued by serious security vulnerabilities. Organizations and individuals negatively affected by Heartbleed and other security flaws probably would have readily traded some delay in accessing new features or temporary access problems for better security. So, how can we better focus DevOps culture and practices on the concept of Continous Security to deliver this? Perhaps we need to look at ongoing advances in automated security testing, more rigorous and frequent manual code review, and paired/team programming practices, and work better on more fully integrating these all into DevOps.

    0 min
  • 2015 - DevOpsDays DC - 37 - 3 Ways to get Capacity Utilization Wrong

    Right-sizing your environment is one of the most stressful decisions to make when moving to the cloud. If you under-provision resources, systems are at risk of going down and you lose money. If you over-provision, you’re wasting money that could be used elsewhere. In this presentation, we’ll share with you 3 ways we’ve learned how to get capacity utilization wrong and how we eventually got it right.

    1. CPU measurement alone won’t give you the full view of your infrastructure utilization
    2. You can’t measure the utilization for a metric if you don’t know how high it can go
    3. If you only rely on request count and don’t include queue length, you will miss an early warning
    0 min
  • 2015 - DevOpsDays DC - 39 - Demming's 14 Points

    W. Edwards Deming offered 14 key principles for management to follow for significantly improving the effectiveness of a business or organization. Many of the principles are philosophical. Others are more programmatic. All are transformative in nature. The points were first presented in his book Out of the Crisis.

    0 min

About DevOps Days Podcast

From the publisher's feed

Audio recordings of DevOpsDays conferences (http://devopsdays.org).