Can DevOps Cure IT’s Case of Turret Syndrome?

#DevOps

App deployment should be viewed as a comprehensive, end to end process.But we treat it today like each silo is a fork in a project that never merges back together, causing disjointed operations, reporting, measurement and ultimately, failure to meet business priorities of improving time to market, fewer disruptions and lower costs.

Because, silos. Or, as we might call them in the middle ages or the Renaissance, turrets.

it turret syndrom

Which of the four IT silos does this picture describe?

If you guessed (e) all of the above then you're right. And yes, I'm aware I gave you no choices, it wasn't really a quiz, after all, merely a literary device. I do that sometimes.

All four operational silos in IT are burdened by the same baggage. That's why DevOps ultimately applies to all four ops, because all four ops (storage, compute (aka "operations"), network and security) share the same issues caused by the tendency to create silos (or turrets or towers or whatever you want to call them) as organizations grow. The result is painful for the business, for end-users and for everyone who has to scramble to fix a problem or deal with an outage or figure out the current status (and explain why the app isn't available yet).

Processes ossify and become more complex over time, with no real concern for how they impact the big picture: getting an application to market (whether that market is internal or external is not really important as both productivity and profit are increasingly important to business and thus, the CIO).

So while we can certainly focus DevOps on Dev and Ops, eventually (and by eventually I mean almost immediately) we're going to run into the same issues its trying to solve when we toss the app deployment over the next wall, to the network.

image

So tear down those walls. Encourage collaboration and shared metrics. Operationalize all the network things and add some Dev to your (Net) ops.

More in this presentation on operationalization: Operationalize all the Network Things!

read more

Driving Analytics in the Cloud with @SAPInMemory | @CloudExpo [#Cloud]

“SAP had made a big transition into the cloud as we believe it has significant value for our customers, drives innovation and is easy to consume. When you look at the SAP portfolio, SAP HANA is the underlying platform and it powers all of our platforms and all of our analytics,” explained Thorsten Leiduck, VP ISVs & Digital Commerce at SAP, in this SYS-CON.tv interview at 15th Cloud Expo, held Nov 4-6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.

read more

DevOps and the ‘Internet of Things’ By @RachelChalmers | @ThingsExpo [#IoT]

Enthusiasm for the Internet of Things has reached an all-time high. In 2013 alone, venture capitalists spent more than $1 billion dollars investing in the IoT space. With “smart” appliances and devices, IoT covers wearable smart devices, cloud services to hardware companies. Nest, a Google company, detects temperatures inside homes and automatically adjusts it by tracking its user’s habit. These technologies are quickly developing and with it come challenges such as bridging infrastructure gaps, abiding by privacy concerns and making the concept a reality. These challenges can’t be addressed without the kinds of agile software development and infrastructure approaches pioneered by the DevOps movement.

read more

‘Cloud Solutions’ with @DEACdc CEO @AGailitis | @CloudExpo [#Cloud]

“For the past 4 years we have been working mainly to export. For the last 3 or 4 years the main market was Russia. In the past year we have been working to expand our footprint in Europe and the United States,” explained Andris Gailitis, CEO of DEAC, in this SYS-CON.tv interview at Cloud Expo, held Nov 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.

read more

Internet of Things Fabric and the API By @MuleSoft | @ThingsExpo [#IoT #API]

How do APIs and IoT relate? The answer is not as simple as merely adding an API on top of a dumb device, but rather about understanding the architectural patterns for implementing an IoT fabric. There are typically two or three trends:
Exposing the device to a management framework
Exposing that management framework to a business centric logic
Exposing that business layer and data to end users.
This last trend is the IoT stack, which involves a new shift in the separation of what stuff happens, where data lives and where the interface lies. For instance, it’s a mix of architectural styles between cloud, APIs and native hardware/software configurations.

read more

Look closer to home for the biggest cloud security issue, SME execs told

Picture credit: iStockPhoto

The biggest threat to cloud security among IT is the company’s employees unintentionally exposing data, according to the latest research figures from CloudEntr.

The study, which took 438 survey responses from industries including financial and manufacturing, found three quarters (75%) of smaller businesses are most worried about their workforce when it comes to securing data in the cloud. Larger IT firms were more concerned about hackers using employee credentials to get their hands on data.

Not surprisingly, regulated institutions were more concerned about cloud compliance than non-regulated, but 75% also said their biggest tool in becoming more secure was employee education.

It’s not just employee education, but shadow IT which continues to be a problem. 29% of those polled said they had no plans to use the cloud in their organisations, but of that number, nearly half of IT pros said they knew of employees who were using it.

The vast majority (89%) of IT pros questioned said they were concerned with cloud security, and security (63%) was more important than convenience in a cloud solution.

There have been various vulnerabilities and outages in recent days, from Docker’s vulnerability recorded earlier this week, to Microsoft Azure’s downtime from a bug which slipped the testing process. Dejan Lukan, writing for CloudTech earlier this week, noted data breaches and data loss as some of the most serious threats to organisations, as well as a lack of understanding.

“Enterprises are adopting cloud services in everyday operations, but it’s often the case they don’t really understand what they are getting into,” he wrote.

“When moving to the cloud there are different aspects we need to address. If the [cloud service provider] doesn’t provide additional backup of the data, but the customer expects it, who will be responsible when the hard drive fails? The customer will blame the CSP, but in reality it’s the customer’s fault, since they didn’t familiarise themselves enough with the cloud service operations.”

The IT pros surveyed by CloudEntr are making it their prerogative to change this. 89% of respondents who have been impacted by security breaches say they planned primarily to educate their employees in the next year.

What do you make of this data? Are you worried about what your workforce is doing in the cloud?

Docker vulnerability exposed, users urged to upgrade for cloud security

Picture credit: iStockPhoto

Docker, the Linux container for run-anywhere apps, has a major vulnerability in all but the latest version of its software which can enable malicious code to extract hosted files.

The vuln, described as ‘critical’ in severity, was first spotted by Red Hat’s security researcher Florian Weimer and independent researcher Taunis Tiigi, with Docker crediting them in a security advisory.

“The Docker engine, up to and including version 1.3.1, was vulnerable to extracting files to arbitrary paths on the host during ‘Docker pull’ and ‘Docker load’ operations,” it reads. “This was caused by symlink and hardlink traversals present in Docker’s image extraction.

“This vulnerability could be leveraged to perform remote code execution and privilege escalation,” it added.

The advisory document noted there was no cure for this issue, and urged users to upgrade to the latest iteration.

This wasn’t the only bug in the system either. An issue which affects versions 1.3.0 and 1.3.1 allows a malicious image creator to modify the default run profile of containers – yet this has been fixed with the current version.

The problem arises when taking into account the vast majority of major cloud computing providers have partnered up with Docker in order to package sleek, secure applications on its platform. Microsoft announced its deal in October, with Google, Amazon Web Services and Rackspace also on board.

It’s easy to see why these vendors are buddying up; as Docker leverages the host’s operating system, there are no overheads or difficulties in spinning up virtual machines when shipping an application in its container. But like a lot of nascent products that are hitting the zeitgeist, it’s best to not get carried away on an untested system when security scare stories are just around the corner.

Users are urged to upgrade to version 1.3.2 as soon as they can, which they can find here.

‘UP Your OPs Game’ By @DTzar | @DevOpsSummit [#DevOps @MS_ITPro]

Want to enable self-service provisioning of application environments in minutes that mirror production?
Can you automatically provide rich data with code-level detail back to the developers when issues occur in production?
In his session at DevOps Summit, David Tesar, Microsoft Technical Evangelist on Microsoft Azure and DevOps, will discuss how to accomplish this and more utilizing technologies such as Microsoft Azure, Visual Studio online, and Application Insights in this demo-heavy session.

read more

Monetize This! Internet of Things By @MetraTech | @ThingsExpo [#IoT]

The Internet of Things will greatly expand the opportunities for data collection and new business models driven off of that data. In her session at @ThingsExpo, Esmeralda Swartz, CMO of MetraTech, discussed how for this to be effective you not only need to have infrastructure and operational models capable of utilizing this new phenomenon, but increasingly service providers will need to convince a skeptical public to participate.
Get ready to show them the money!

read more

How DevOps can improve reliability when deploying with AWS

Picture credit: iStockPhoto

Reliability, in the cloud technology era, can be defined as the likelihood that a system will provide uninterrupted fault-free services, as it is expected to, within the constraints of the environment in which it operates. According to the Information Technology Laboratories (ITL) bulletin published by the National Institute of Standards and Technology (NIST) on cloud computing, reliability in cloud environments is composed of the following:

  • The hardware and software services offered by the cloud service provider
  • The provider’s and consumers’ personnel
  • The connectivity to the services

In other words, reliability is dependent primarily on connectivity, availability of the services when needed, and the personnel managing and using the system. The focus of this article is about how DevOps can improve reliability when deploying in the cloud, particularly in Amazon Web Services (AWS) environments.

DevOps can, in fact, help improve the reliability of a system or software platform within the AWS cloud environment. When it comes to connectivity, there is the Route 53 domain name system routing service, the Direct Connect service for dedicated connection, and ElasticIP, offered by AWS. For assurance of availability, AWS offers Multi Availability Zone configurations, Elastic Load Balancing, and Secure Backup storage solutions with Amazon S3.

DevOps can be used to configure, deploy and manage these solutions and the personnel issues for reliability are practically non-existent because of the automation that is brought about by AWS DevOps offerings such as OpsWorks.

OpsWorks makes it possible to maintain the relationship between deployed resources persistently, meaning that an IP address that is elastically allocated to a resource (for example, an EC2 instance) is still maintained when it is brought back online, even after a period of inactivity. Not only does OpsWorks allow an organization to configure the instance itself, but it also permits the configuration of the software on-demand at any point in the lifecycle of the software itself, taking advantage of built-in and custom recipes.

Deployment of the application and the infrastructure is seamless with OpsWorks as the applications and infrastructure can be configured and pointed to a repository from which the source is retrieved, automatically built based on the configuration templates, and deployed with minimal to no human interaction.

Additionally, the auto-healing and automatic scaling features of AWS are perhaps what gives AWS deployments the greatest reliability, since when one instance fails, OpsWorks can automatically replace the failed instance with a new one and/or scale up or scale down as demand for the resource fluctuates. This ensures that there is uninterrupted and failure-free availability of services offered to connected consumers.

So, with a DevOps approach to deployment of cloud apps in an AWS environment, it may very well be possible that while the shift to cloud computing may test the reliability of the technology, in reality, it is a not something that one needs to be overly concerned about. Try the DevOps approach to deployment and see for yourself how reliable it can be and is.

The post How DevOps can Improve Reliability When Deploying with AWS appeared first on Cloud Computing News.

The cloud news categorized.