Copyright @ 2019 JFrog - All rights reserved.
DevOps as a
Competitive Advantage
Ido Green
@greenido
Learnings from 5000 customers
IDO
GREEN
VP Technology
“Every company is now a
software DevOps company.”
SOFTWARE DEVELOPERS
IN THE WORLD
* GitHub self-reports
~40 million
22% YOY DEVOPS
BUDGET GROWTH
Through 2022
DEVOPS IS STILL GROWING
“...projections underestimate DevOps’ extended impact on IT.”
*DevOps: The New Heart of IT. Oppenheimer. 2018.
THE DEVOPS
ARENA
Red Hat
GKE
Amazon EKS
DigitalOcean
Azure AKS
Pivotal
Container
Service
CONTINUOUS
DELIVERY
MY FAVORITE PART OF BEING IN JFROG
BEING IN THE
FLIGHT DECK
OF DEVOPS
WHAT
DOES
THIS
MEAN?
A HYBRID VIEW
ON THE MARKET
TRENDS:
DEVOPS POWER
USERS & BIG-BOX
ANALYSTS
TOP PRIORITIES
Increase velocity of
code to production
Security
Increase cloud adoption
88
71
47
29
29
41
Revenue
Acceleration
Improved Agility
Cost Reduction
Better
Management of
Regulatory &
Compliance Risks
Increased Customer
Satisfaction
Other
WHERE IS THE FOCUS?
▪ Scaling / change management
▪ Legacy processes/apps
▪ Growing number of
microservices
▪ Build high quality
vs
Ship new features
28
27
20
19
6
Agility and Time to
Market
Quality of Services
Cost Efficiency
Security and Risk
Reduction
Other
CIO’S MAIN CONCERNS
Cost / Speed Cloud
(Native, Hybrid / Multi-Cloud)
Velocity
vs
Security
CIO’S MAIN CONCERNS
Cost / Speed Cloud
(Native, Hybrid / Multi-Cloud)
Velocity
vs
Security
WHY COST?
DOWNTIME IS EXPENSIVE
Downtime costs companies an
average of $336,000 an hour.
In (bigger) companies -->
$540,000 an hour.
- Gartner
WHY SPEED?
“In a world where everything
is moving so rapidly, simply
being fast isn't enough; you
have to be faster than all
your competitors”
RELEASE
FAST
OR DIE
CIO’S MAIN CONCERNS
Cost / Speed Cloud
(Native, Hybrid / Multi-Cloud)
Velocity
vs
Security
Cloud
(Native, Hybrid / Multi-Cloud)
Cloud
(Native, Hybrid / Multi-Cloud)
Cloud
(Native, Hybrid / Multi-Cloud)
REALITY:
50%
OF DEVOPS IS CLOUD NATIVE
“The future will be containerized and those containers
will run on serverless infrastructure.”
- Brendan Burns
95%
BY 2022
REALLY?
“Cloud Native is
something that
everyone defaults to
now.”
POWER USERS DEMO THAT CLOUD-NATIVE IS HERE
REALITY:
50%
HYBRID DEVOPS TODAY
STRATEGICALLY
78%
BY NEXT YEAR
REALLY?
POWER USERS: HYBRID IS ON PURPOSE
“Hybrid is a
stepping stone to
pure cloud.”
CONSENSUS: HYBRID IS AN INTENTIONAL DESTINATION
▪ 20% of enterprises with more than 1,000
employees plan to more than double their
public cloud spending.
▪ 71% of enterprises will increase their public
cloud spending by more than 20%
Workloads Distribution
in 2019 vs in 2022
26
25
49
25
23
52
% of Workloads
REALITY:
<30%
using K8s today
~85%
In 3 years
KUBERNETES IS STILL GROWING UP
“Everyone is using
Kubernetes.”
REALLY?
CIO’S MAIN CONCERNS
Cost / Speed Cloud
(Native, Hybrid / Multi-Cloud)
Velocity
vs
Security
TOP SECURITY CONCERNS
▪ 1st and 3rd party
Vulnerabilities
▪ Data Security
*JFrog survey
SECURITY VS VELOCITY:
WHERE ARE THE BOTTLENECKS?
Automate
pipeline
Deployment
automation
Test platform
management
SECURITY VS VELOCITY – TESTING?
“44% say that they
are only testing
about 0-30% of
their codebase.”
REALITY:
60%
NOT INTEGRATED INTO DEVOPS
PIPELINE
29%
FOCUSED ON THIRD-PARTY
VULNERABILITIES
“Security is
something we apply
after
development.”
REALLY?
SECURITY IS COMING INTO THE PIPELINE
Top Aspects - OSS LIBRARY GOVERNANCE
1. Quality
2. Activity on Source
Repository
3. Vulnerabilities
4. License
What do you take into consideration when deciding which OSS libraries to use?
- JFrog survey
SECURITY TOOL CRITERIA
1. Universal - Support
of many technologies
2. Integration with
other DevOps tools
3. Quality of Data
What were the top 3 decision-making factors that you considered when
selecting your software composition security analysis tool?
- JFrog survey
CIO’S MAIN CONCERNS
Cost / Speed Cloud
(Native, Hybrid / Multi-Cloud)
Velocity
vs
Security
DEVOPS FLOW
ARTIFACT MANAGEMENT
DevSecOps
INDUSTRY-LEADING CUSTOMERS CI/CD
DEPLOYMENT
SOURCE
On Premises
Multicloud
On Premises &
Multicloud
“Every company is now a
software DevOps company.”
HAVE A PRODUCTIVE DAY!
Thank You
Ido Green
@greenido

DevOps as a competitive advantage

  • 1.
    Copyright @ 2019JFrog - All rights reserved. DevOps as a Competitive Advantage Ido Green @greenido Learnings from 5000 customers
  • 2.
  • 3.
    “Every company isnow a software DevOps company.”
  • 4.
    SOFTWARE DEVELOPERS IN THEWORLD * GitHub self-reports ~40 million
  • 5.
    22% YOY DEVOPS BUDGETGROWTH Through 2022 DEVOPS IS STILL GROWING “...projections underestimate DevOps’ extended impact on IT.” *DevOps: The New Heart of IT. Oppenheimer. 2018.
  • 6.
    THE DEVOPS ARENA Red Hat GKE AmazonEKS DigitalOcean Azure AKS Pivotal Container Service
  • 7.
  • 8.
    MY FAVORITE PARTOF BEING IN JFROG BEING IN THE FLIGHT DECK OF DEVOPS
  • 9.
    WHAT DOES THIS MEAN? A HYBRID VIEW ONTHE MARKET TRENDS: DEVOPS POWER USERS & BIG-BOX ANALYSTS
  • 10.
    TOP PRIORITIES Increase velocityof code to production Security Increase cloud adoption 88 71 47 29 29 41 Revenue Acceleration Improved Agility Cost Reduction Better Management of Regulatory & Compliance Risks Increased Customer Satisfaction Other
  • 11.
    WHERE IS THEFOCUS? ▪ Scaling / change management ▪ Legacy processes/apps ▪ Growing number of microservices ▪ Build high quality vs Ship new features 28 27 20 19 6 Agility and Time to Market Quality of Services Cost Efficiency Security and Risk Reduction Other
  • 12.
    CIO’S MAIN CONCERNS Cost/ Speed Cloud (Native, Hybrid / Multi-Cloud) Velocity vs Security
  • 13.
    CIO’S MAIN CONCERNS Cost/ Speed Cloud (Native, Hybrid / Multi-Cloud) Velocity vs Security
  • 14.
    WHY COST? DOWNTIME ISEXPENSIVE Downtime costs companies an average of $336,000 an hour. In (bigger) companies --> $540,000 an hour. - Gartner
  • 15.
    WHY SPEED? “In aworld where everything is moving so rapidly, simply being fast isn't enough; you have to be faster than all your competitors” RELEASE FAST OR DIE
  • 16.
    CIO’S MAIN CONCERNS Cost/ Speed Cloud (Native, Hybrid / Multi-Cloud) Velocity vs Security Cloud (Native, Hybrid / Multi-Cloud) Cloud (Native, Hybrid / Multi-Cloud) Cloud (Native, Hybrid / Multi-Cloud)
  • 17.
    REALITY: 50% OF DEVOPS ISCLOUD NATIVE “The future will be containerized and those containers will run on serverless infrastructure.” - Brendan Burns 95% BY 2022 REALLY? “Cloud Native is something that everyone defaults to now.” POWER USERS DEMO THAT CLOUD-NATIVE IS HERE
  • 18.
    REALITY: 50% HYBRID DEVOPS TODAY STRATEGICALLY 78% BYNEXT YEAR REALLY? POWER USERS: HYBRID IS ON PURPOSE “Hybrid is a stepping stone to pure cloud.”
  • 19.
    CONSENSUS: HYBRID ISAN INTENTIONAL DESTINATION ▪ 20% of enterprises with more than 1,000 employees plan to more than double their public cloud spending. ▪ 71% of enterprises will increase their public cloud spending by more than 20% Workloads Distribution in 2019 vs in 2022 26 25 49 25 23 52 % of Workloads
  • 20.
    REALITY: <30% using K8s today ~85% In3 years KUBERNETES IS STILL GROWING UP “Everyone is using Kubernetes.” REALLY?
  • 21.
    CIO’S MAIN CONCERNS Cost/ Speed Cloud (Native, Hybrid / Multi-Cloud) Velocity vs Security
  • 22.
    TOP SECURITY CONCERNS ▪1st and 3rd party Vulnerabilities ▪ Data Security *JFrog survey
  • 23.
    SECURITY VS VELOCITY: WHEREARE THE BOTTLENECKS? Automate pipeline Deployment automation Test platform management
  • 24.
    SECURITY VS VELOCITY– TESTING? “44% say that they are only testing about 0-30% of their codebase.”
  • 25.
    REALITY: 60% NOT INTEGRATED INTODEVOPS PIPELINE 29% FOCUSED ON THIRD-PARTY VULNERABILITIES “Security is something we apply after development.” REALLY? SECURITY IS COMING INTO THE PIPELINE
  • 26.
    Top Aspects -OSS LIBRARY GOVERNANCE 1. Quality 2. Activity on Source Repository 3. Vulnerabilities 4. License What do you take into consideration when deciding which OSS libraries to use? - JFrog survey
  • 27.
    SECURITY TOOL CRITERIA 1.Universal - Support of many technologies 2. Integration with other DevOps tools 3. Quality of Data What were the top 3 decision-making factors that you considered when selecting your software composition security analysis tool? - JFrog survey
  • 28.
    CIO’S MAIN CONCERNS Cost/ Speed Cloud (Native, Hybrid / Multi-Cloud) Velocity vs Security
  • 29.
    DEVOPS FLOW ARTIFACT MANAGEMENT DevSecOps INDUSTRY-LEADINGCUSTOMERS CI/CD DEPLOYMENT SOURCE On Premises Multicloud On Premises & Multicloud
  • 30.
    “Every company isnow a software DevOps company.”
  • 31.
    HAVE A PRODUCTIVEDAY! Thank You Ido Green @greenido