What's Holding DevOps Back? - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

IoT
IoT
DevOps
Commentary
11/27/2020
08:00 AM
Lisa Morgan
Lisa Morgan
Commentary
Connect Directly
Twitter
RSS
50%
50%

What's Holding DevOps Back?

DevOps teams are at different stages of maturity. However, there are some common challenges they face along the way.

Image: lesslemon - stock.adobe.com
Image: lesslemon - stock.adobe.com

Some DevOps teams are well-oiled machines, but it's taken time to get there. Perhaps they didn't have the right culture or processes in place to start. Maybe they lacked some tooling that could help facilitate more efficient processes.

"There isn't one way to do DevOps," said Jared Murrell, director of DevOps, engineering & communities of practice at Github. "It's not simple to quickly and perfectly 'do DevOps.' DevOps is defined by the people building software and how they work together. Naturally, there are some hurdles to overcome."

Ownership

DevOps team members need to understand something about what the others do so they can all work together as a cohesive cross-functional team. That doesn't just happen because later stage functions have been responsible for identifying flaws in code, which is a different mindset than working as a team to continuously improve the speed at which code is delivered, it's quality and internal processes.

"You won't have successful DevOps unless the whole team embraces responsibility and contributes to the larger goal," said Murrell. "Instilling this responsibility allows teams to move forward together and makes each team member feel they have a stake in the overall success of the team."

Collaboration

DevOps began with the idea of getting Dev and Ops working closer together, but the concept doesn't end there as evidenced by the emergence of modified terms such as "DevTestOps" and "DevSecOps." However, DevOps teams also need to work with other functions such as cybersecurity and governance.

James Bores, Bores Security Consultancy
James Bores, Bores Security Consultancy

"For DevOps work, you need strong communication and integration between teams so a DevOps team can take ownership of their own governance and risk [without] putting the organization at risk or running into a brick wall from another function in the company," said James Bores, principal at Bores Security Consultancy.

These days, DevOps teams also need to concern themselves with data. Brian Platz, co-CEO and cofounder of blockchain-based graph database platform Fluree, said DevOps can contribute to an enterprise data bottleneck if it lacks the proper data infrastructure.

"DevOps will need to create and likewise demand access to high quality, rich and real-time data, but if data rules and standards aren't created and enforced as a strategic priority, the acceleration of products and services under DevOps will simultaneously accelerate data silos and leave behind a wasteland of duplicated and partial information," said Platz. "DevOps decision makers must collaborate with data professionals in their organization to define the key data stakeholders and derived data standards to integrate into their toolset and process."

Brian Platz, Fluree
Brian Platz, Fluree

Automation

DevOps requires automation to meet its goal of faster value delivery. As DevOps teams move toward CI/CD, more of the pipeline must become automated.

"Automation is a huge part of successful DevOps, but teams need to determine what is beneficial to automate, and where to start," said Github's Murrell.

Denis Leclair, VP of engineering at sponsored ad campaign creation and management platform provider Trellis, said in his experience, the two most frequently cited challenges in deploying DevOps in organizations include the upfront investments needed in tools and analytics to enable the successful automation of workflows across the range of value streams and reskilling the workforce to be effective in the new model. One example is software quality assurance (SQA).

"For the benefits of DevOps to be recognized as scale, testing and feedback must be automated," said Leclair. "Developers need to embrace a testing mindset (e.g., TDD). On the other hand, SQA engineers need to become proficient in designing and developing large [and] complex test automation code systems -- that is to say, they need to become more skilled as software developers."

Denis Leclair, Trellis
Denis Leclair, Trellis

Security

DevOps teams tend to morph into DevSecOps teams because DevOps and a separate security function isn't working well enough. DevOps teams are under constant pressure to reduce application development and delivery cycles, which can and often does impact product quality including security. Shifting security testing left helps, but it doesn't produce the same results on its own as including security expertise on the team so security is top of mind for everyone.

"Developers understand how to write code. What they're missing is the perspective [of] what attackers do and how they do it," said Kevin Breen, director of cyber threat research at cyber security skills platform provider Immersive Labs.

Breen advocates security champions who understand software development and cybersecurity because they can explain cybersecurity within the context of the code the developer is building. In addition, teams should have automated application vulnerability scanners that are part of the pipeline, although QA should also be taught how to use some security testing tools so they can run SQL injection tests, for example.

Kevin Breen, Immersive Labs
Kevin Breen, Immersive Labs

"It's about empowering developers, QA and operations to use the right tools at the right place and not be afraid to go to the security team," said Breen.

Roey Eliyahu, CEO and co-founder of Salt Security, said his customers achieve the most success when they prioritize both pre-production and post-production security.

"Despite customers' best efforts, applications frequently roll out with bugs and vulnerabilities," said Eliyahu. "Modern mobile and web applications that rely on multiple APIs create a complex web of logic and are especially susceptible to such challenges. With API-based applications, many gaps do not surface until they're in production."

Roey Eliyahu, Salt Security
Roey Eliyahu, Salt Security

Cloud spend

Managing cloud spend isn't just a DevOps issue, but there are some nasty cost-related surprises that DevOps teams can run into according to Jeff Valentine, CTO at cloud management platform CloudCheckr.

One is relying on AWS Pricing Calculator results and presenting them to the business as-is when the tool can't factor in what the business is trying to achieve, how the team will run the software or what mistakes the DevOps team may make. Another "gotcha" is failing to consider the cost of bandwidth, which can account for 5% or 10% of a bill. A third pitfall is believing that shutting off an EC2 instance will stop costs from accruing when the EBS volume was never deallocated.

"There are all these weird analogues that were never 'a thing' on premise so they didn't realize they had to ask about it," said Valentine. "Also, they tend not taking advantage of cost savings plans because they just don't want to spend the time learning."

Jeff Valentine, CloudCheckr
Jeff Valentine, CloudCheckr

Bottom line

DevOps is a journey that requires patience and dedication on everyone's part. While strong leadership is needed to succeed, there are technology, process and people elements, all of which need to be addressed.

DevOps is a mindset and a practice that focuses on continuous improvement on several levels including building and releasing better quality code faster, improving intra and inter-team communication and collaboration, and overcoming other common barriers such as automation and using cloud spend wisely.

 

For more on DevOps, follow up with these stories:

AIOps, DevSecOps, and Beyond: Exploring New Facets of DevOps

Making Developers More DevSecOps Aware

The Growing Security Priority for DevOps and Cloud Migration

How AI and Machine Learning are Evolving DevOps

What AIOps Could Mean for the Future of Remote Work

 

Lisa Morgan is a freelance writer who covers big data and BI for InformationWeek. She has contributed articles, reports, and other types of content to various publications and sites ranging from SD Times to the Economist Intelligent Unit. Frequent areas of coverage include ... View Full Bio
We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
Comment  | 
Print  | 
More Insights
InformationWeek Is Getting an Upgrade!

Find out more about our plans to improve the look, functionality, and performance of the InformationWeek site in the coming months.

Slideshows
10 Things Your Artificial Intelligence Initiative Needs to Succeed
Lisa Morgan, Freelance Writer,  4/20/2021
News
Tech Spending Climbs as Digital Business Initiatives Grow
Jessica Davis, Senior Editor, Enterprise Apps,  4/22/2021
Commentary
Optimizing the CIO and CFO Relationship
Mary E. Shacklett, Technology commentator and President of Transworld Data,  4/13/2021
White Papers
Register for InformationWeek Newsletters
2021 State of ITOps and SecOps Report
2021 State of ITOps and SecOps Report
This new report from InformationWeek explores what we've learned over the past year, critical trends around ITOps and SecOps, and where leaders are focusing their time and efforts to support a growing digital economy. Download it today!
Video
Current Issue
Planning Your Digital Transformation Roadmap
Download this report to learn about the latest technologies and best practices or ensuring a successful transition from outdated business transformation tactics.
Slideshows
Flash Poll