
D2DO314: Backups SaaS – Safety as a Service
Get every episode summarized
Each time The Everything Feed - All Packet Pushers Pods publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
About this episode
“The Gartner IT Infrastructure Operations and Cloud Strategies Conference December 8th through the 10th in Las Vegas brings together heads of infrastructure, cloud ops pros, platform engineers and security leaders.”From the transcript
Get every episode summarized
Each time The Everything Feed - All Packet Pushers Pods publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
424 searchable segments. Every word is indexed and playable.
Full transcript
The Everything Feed - All Packet Pushers Pods — D2DO314: Backups SaaS – Safety as a Service. Machine-transcribed; use the interactive transcript above to jump the player to any line.
Today's podcast is sponsored by Gartner. The Gartner IT Infrastructure Operations and Cloud Strategies Conference December 8th through the 10th in Las Vegas brings together heads of infrastructure, cloud ops pros, platform engineers and security leaders. Learn more at Gartner.com slash IO. The dirtiest secret to data protection in the age of AI is it's the same story that we've been telling since data began. Welcome to day two DevOps where the dev whoops is in the details. I'm Ned Belvets and I'm joined by my indefatigable co-host Kyler Middleton. Hi Ned. Today we're discussing backups in the age of hybrid, cloud and AI. We had to send AI in there somewhere, right? All these platforms and tools help you and your adversaries move at lightning speed. Do you know if your backups are valid? That's a good question guiding us through
the need for cyber resilience and an AI world is our guest, Jim Jones. Let's get into it. Well Jim Jones, welcome to day two DevOps. We're very excited that you're here. It's been a while since we chatted. Before we get into the topic at hand, why don't you tell the good folks out there a little bit about yourself and what you do. Hi everybody. My name is Jim Jones. I am a product architect for a little company called 1111 Systems that you may not have heard of. But we are the hyper-scaler VMware service provider these days, but with a very big focus on data protection and ensuring that your path to the hybrid cloud is one that is not as fraught with danger as can't happen from time to time. So I focus in our product team on the data protection products and that can be anything from I need to back up a VM to I need this really crazy restore scenario for my entire enterprise
in case everything goes down all at once. That's me. I am continually surprised at how popular hybrid cloud is. I really thought if you'd asked me 10 years ago, I would have been like everybody will just move to the cloud. No one will have on prem stuff anymore except for that poor file and print server that sits in the corner and lets you know Lucy print her TPS reports at the end of every day. Everything else is going to be in the cloud. And I was like clearly wrong. What's driving hybrid cloud from your perspective? Well, so from my perspective, I think that hybrid cloud is probably the long-term solution. Especially during the pandemic, I was very much sure right there with you that we were going to go from everything is four hosts in the cloud of dust of the hypervisor to we're going to lift and shift everything that is custom and then everything that is it we're going to put it into sass. I think what we've realized and especially as we
get into the modern kind of world where ransomware went up right as long as everybody else's cloud and sass aspirations went up is that there's some things that you just frankly have to guard more and keep the control of that resource. Then you do, then you're willing to say, okay, I'm just going to remove myself for responsibility and making sure this application is uptime or that the security of this application is up because the share responsibility model is a thing and as you get into that second contract for a lot of companies, you know, everybody you buy into a vision, you buy into a dream and it's three years at a time and you've done it for three years and then you've probably had that oopsie. And once that oopsie hit, you know, now you react and you start to draw some things back and that's where I think the long term will be some variant of the hybrid cloud. You know what I mean? I remember the before times and the times after this particular event
for our team when we had this realization and our CIO realized this that we could have someone delete our entire technical infrastructure in the cloud in a matter of minutes, which is an automation script and one misconfigured I am role. And after we realized that, I mean, first of all, it just sends a chill up you like in the olden days, you know, in the on Prem days, you need a database engineer credentials to touch the database and a network engineer credential and all the tooling is so different that the languages are different and it's just difficult to own all those verticals and cripple everyone entirely. But thankfully in the cloud era, you can cripple someone entirely, really quickly, really simply with very standard APIs thank goodness. So yeah, for sure, it is it's a different world now. The the your cloud world is sure different and more accessible in good and really terrible ways. That's what I'm thinking about as you're presenting this. Yeah, I mean, it's definitely it's a, you know, I was I was a siss admin for 20 years and then I
kind of transitioned into the service provider world mostly living in the product situation. And when I did that, you know, backup was kind of my jam. And so that's why I did it. But even as a siss admin, you know, the story we had to tell back then was even a bigger cell because I had to internally sell. I really want to de our site where I want to have something because of something happens that I need to be able to do it. Back then, it was always what I called fire foot and blood, you know, is the building burning down? What am I going to do? You know, is is everything we've been floated away? Now it's it's all it's all a security conversation. And you know, and for better or for worse, we have cyber risk insurance sitting over here saying, hi, you're now fully vetted and involved with us. And we need to protect things and you need to do it right this time. But to your point with with DevOps, what we're what we're finding out is not only can we
do more faster in a good way, we can do more faster in a bad way. And you know, it was fire foot and blood, you know, I have a cyber risk. And that cyber risk, if you look at the paper is Hacker mains in his black hoodie sitting in a van down my corner more than likely it's somebody hitting oopsie, you know, and put it extra lot or didn't calm down it, calm in out of line and an Ansible playbook is far more likely. And that's what we have to be mindful of as we think about that. And then now we have a which is effectively Ansible or Terraformer insert DevOps capability here on steroids. You know, and so what we were doing fast before we're now doing fast with the computer actually doing the thinking of what is what we need to do in the first place. You brought up AI and it's unavoidable at this point. I think there's a sort of we need to clarify what we're talking about when we mention AI because there's different use cases for it.
There's the AI that you've added to your enterprise applications to serve a particular function within that application. Maybe it's doing a warm validation or document processing or something along those lines. Then there's AI that's helping you operate. So think like an SRE agent or something that is performing tasks that involve actually evaluating or deploying things. And then there's just like agents that you run locally that help you with your software development. I'm sure you're talking to lots of clients. Which one is most prevalent and which one are people most worried about? Well, so that's what's funny is the those are two separate things. The one that everybody's worried about is the hacker that's got an access to say a quad code with MIFOs underneath of it where I guess now officially Fable 5 and you're out how to get around the guard rails. That's the part that everybody's worried about. I think you know if we think about
data protection as a holistic thing. We not only have to worry about data going away. We also have to worry about the security and the who can get access to what component of that as well. And that's where we start to see the realistic. Okay, we really need to worry about this as the enterprise search component or the automation component. Where you know because really as we as we look at what AI is today. It's not X machina, you know, I'm not going to have to have a turning test with a robot that walks past me. What I am going to have to deal with is I've gone and I've bought a perplexity, a clawed, a glean, a whatever. And now the race is on to see what all systems, inner processes, I can tie that into whether it be SharePoint, whether it be Confluence, Bitbucket, GitHub, you name it. And we luckily had a world where for a lot of those SaaS-based data,
management platforms before there was a certain amount of security through obscurity that you kind of get away with. And because if you didn't know it was there, you didn't know to go looking for it. Well, now you've unleashed an automated beast. The very first thing that it does is go through and crawl everything you can possibly find that you give it access to. And then try to apply, it's like having a sysadmin that's a toddler. Okay, so it's like underbed, but it's like having a sysadmin who naively believes that as long as this person has rights to this thing, then they absolutely should have rights to it. And we're just going to give them anything that they want up to including reason context. Okay, so you know, the very first thing that I always, you know, it's not talked to a few small businesses on the side here locally.
The first thing I always tell them is that before you even think about letting anybody else have access to this, think of the worst questions that you would ever want any of your employees, any of your competitors or anyone in the community to ask of you, tie your systems in, and then go ask those questions. And then find a small group and have them do the same thing because we all want to say that our permission structure for SharePoint is great. We all absolutely also know that our permission structure and SharePoint is not great. And until you start to find that, you know, I can, you won't unleash, you know, a clawed to a SharePoint repo, and I can, I can measure in seconds probably the amount of time before somebody's going to say, how much does X person make? You know, because it's, you know, we are human beings and there's always going to be that other thing. So that's the, you know, that's that's part of the threat. And it's,
you know, it's, it's, I am, I'm going to end that's the, the campy, funny version, you know, yeah, it's to be painful internally. But that can just as well be what are my, what's my intellectual property? And what have I now unintentionally or my security? What have I now unintentionally leaked potentially possibly to, you know, let's say co-pilot that does use generic, genericized data to broad spectrum, allow context to a thing. And now that thing that was your intellectual property has now become a kind of glossed over or sheeted over concept that it now treats as, okay, this is a reality. Does that make sense? Yeah. You've seen a string of cyber attacks that really target the agents people have running locally on their machines. So whether that's buried in like an NPM package or something along those lines, it's serotonously prompting the agent to,
so X-filtrade data or something along those lines. I know, Kyler, this has been a thing for you deciding what level of access you're going to give the AI agents you have at your work. What level of access it's going to get to these external systems? Like where do you draw those lines? Where do you draw those lines? It's hard. It's a hard problem, right? It's, of course, you want to enable your employees to move fast. So of course, you would give your robots like access to GitHub and access to SharePoint. And do you want them to log in every time, not really? So maybe you'll just grant like a service account, read permissions to everything. But if you grant read permissions to everything, you might grant read permissions to all of your data. And all of your ssh keys and all of your dynamo tables that store secrets and your secrets manage are content. And it's so easy to say like, oh, read only safe because you can't change. Well, read only is all of your secrets. Like it's literally everything. Read only to your SharePoint
is reading all of the, the compensation data like you talked about. It's very easy to misunderstand and mis-scope the permissions that robots should have. But it's also very hard to do it correctly, even with a lot of forethought. If you only give it access to the data that you know can't be misused, you have limited your ability, your employee's ability to like do useful stuff with it. So this is the, the fine edge of a sword. It's really hard to scope this stuff correctly. Yeah. I mean, the, the first place to really consider, you know, I said, go through and do a permissions audit. You know, it's usually the very first thing that I always recommend. The second thing that I recommend is take a look at, I guess there's gates to your corporate data. You know, so think of, so if you look at like an ad lasian, you look at a SharePoint, you look at anything you're going to interface to through an MCP server. Okay. There's API, the tokens you've got from the APIs on the other side, buy and large for their SaaS services. They hit the easy button
of, oh, I just want to do a quick, quick wizard version of creating a token that just is not granular. And you need to be more aware of those things. Yeah. You're, what you're starting to see is a whole lot of growing up on the SaaS world right now because they were all doing the quick and easy version. And now they're having to become more granular because it might even be an unintended consequence of I do want to allow AI access to this thing with my trusted AI platform that I as a business owner have said, this is what I'm going to use. So, you know, that could be saying Glean. But then they take that same thing and, you know, since admin over here wanting to do more go faster, goes and buys himself a cloud subscription and is able to tie it into that same MCP server. And now you've got a data leak situation. Or he or it does a cloud init on their home
directory or one of your developers does. And now all of a sudden, every secret that's stored in an in V file or in a dot file has now been exposed. Right. And so that's now when we have to take that next step in the journey of data protection in the age of AI and start looking at some of these DSPM or data security posture management platforms that are starting to pop up like octaves to where effectively, you know, these are the things that you know. And this is the system that you're using. And you're starting to watch those things for, you know, identifiable string types, you know, reject for what does a token look like? What does one of my account IDs look like? What is a credit card look like? And get a good identification of what that is in the context of here the AI queries that are going through my back claim, you know, for example, if you're using my bedrock, you can have it start watching cloud watch and see the actual queries that are coming through and
the responses. And you're not going to read all that because nobody got time for that. But if the machine can start to watch that for you, okay, now you're at least on a better footing and you can be a reactionary to it. The DSPM acronym is one that I'm not familiar with. So I'm glad you expanded it because I kind of get a better idea of what a data protection. What was it? It is security posture management. So it is security. Yes, PM. Okay. That's a mouthful. I understand why they shortened it. Yeah, it's a little cottage industry right now. A lot of them are being affiliated. So what the, you know, it's effectively it's the evolution of what we've seen for years. I don't know if you guys remember this, but there used to be a company called Data Gravity that did personally identify, file, mobile information, scanning, instant your document, you know, do I see something that looks like credit card? Here's the files where I see all that stuff at.
Yeah. This is that kind of illness steroids, but for the AI generation and what we're finding is one, it's really hard core to do it live as you're doing the thing. So what you're, they're, they're very quickly aligning themselves for being purchased by a lot of the backup and resolve, cyber resiliency vendors that are out there with the idea that as they get integrated with it, I can scan backups way better than I can scan production data because when opening a word document comes slow, that becomes everybody's problem. But if you're just seeing its backups, it's a little easier conversation. So is that where primarily these the PPSM? Yes, PN. Yes, PN. Thank you. Is that primarily where these products sit is in your backup and cyber resiliency? Or do they also sometimes sit in line as sort of a proxy that's scanning prompts? Because I would
want to catch a prompt before it goes out the door. Yeah, it's a both. And like I said, it's a industry that's new enough right now in terms of the vendor landscape that there's, it's kind of a wild west summer being done in one way, summer being done in another. The other thing you're seeing get triggered is how that data protection policy then gets applied. So it goes through its scanning actual documents. So you might be able to attach it to your sharepoint repository, your sharepoint account. It goes through, identifies everything, identifies permissions everywhere, ensures you've got that permission set actually set up correctly. Or identifies who you want it doesn't. But also if we think about, you know, do I see this thing that has super sensitive data? Hey, here's this file that has the entire companies, salaries in it. Let's automatically tag that and put that into a different
both backup as well as access control policy. So it's the automation of some of the zero trust things that we've been talking about for years, which we all have great, great aspirations of zero trust. And let's then, you know, all the way there, implementations of zero trust. Yeah. I, the irony for me here is you know, it's really good at looking at documents and identifying patterns and content is AI. So in order to fight data loss, you almost need to get a product that has AI baked in so it can do the identification and prevent that data loss. Yep. Now I've gone cross-eyed. Yeah, there's a whole lot of the AI watching the AI, you know, out there right now. You know, it's, you know, what we all have heard, you know, vendor demos or keynotes and all that kind of stuff. And that is, that is very much so the
the game right now, you know, he said for, you know, myself professionally, we are, he said, we're a cloud search product that does data protection, but we leverage best in class vendors as an upstream and then do some magic in the middle and then present that to you as a customer and make that an accessible thing. Definitely all the vendors that we talk to on a daily basis, that's, that's their stick right now. We've got the AI that can watch your AI. So you can, you don't have to worry about that. And that's, and then exposing it via an API and then they've got their own AI that goes into it. And what we do, and it's, you know, it's a whole different conversation. Is there a, is there a big push from enterprises? Like if I'm going to buy one of those tools to have the model and everything running locally, but I don't have to worry about my data leaking out to one of these other AI protection services. As an IT leader, your job is to modernize
your existing processes, deploy applications faster than ever, and keep your entire organization abreast with the AI revolution all at the same time. Kyler, it's enough to make your head explode. It is, but you're not in this alone. Gardner's infrastructure operations and cloud strategies conference helps you and other IT leaders and senior engineers connect with experts and the community you need to keep your head intact. We know that the last year has been a decade compressed into 365 days, and it shows no sign of stopping. You need to develop a strategy to keep up. Slow is fast, fast is slow, right? I remember story about a rabbit and a turtle. Exactly. You need to chart your course before you venture into tumultuous AI-infested waters. Khan learned how to captain your boat and command other metaphors too at Gardner's I.O. conference on December 8th in Las Vegas. Learn more at Gardner.com slash I.O.
And you can use our handy coupon code of DevOps to get 450 de bloons. I mean the dollars off the ticket price. It on over to Gardner.com slash I.O. and check it out. That's Gardner.com slash I.O. and code DevOps. See you there, me hearties. So I think that's another one of those when we hit the refresh cycle. I think that's where we're going to start to see that happen. I think the local models, if you're major enterprise, absolutely. Or if you're in a well protected industry like finance, healthcare, etc. I think that's very much so a part of the conversation for your general run of the mill, everything from an SMB up to the middle size enterprise that's just trying to build a thing and do the business. You know, they all just in the last year or so have signed up for whatever that first contract is with whoever the AI vendor of choices. And so that may be a year,
that may be a two year, maybe a three year year. Unfortunately, we're going to have that Wild West time frame of we got to trust the SaaS platform because we sure don't have the smarts in house to build this ourselves. And we maybe don't want to pay to hire the smarts right now because the you know, the economies in a will they won't they kind of situation. And so you know, your bridge of the gap, you've got to do the AI thing. You know, one of the things that I've been calling out a lot here lately, there is a lot of pressure. These aren't trivial contracts that companies are signing up for to go into the AI space. You have a CEO of Nvidia, say, and of developers aren't spending 750K, you know, on do it themselves on tokens, then they're not doing their job. Oh, you know, they're wanting to go big and go home. A bit of it's from that in video. Yeah, yeah, yeah, yeah. Because I never would try to choose because we win.
Well, there's a there's a story of efficiency that's being told right now that AI, you know, the way I put it when I had when I talked to mentees or people, you know, I work with a local community college, one of some things. And when I talk to them is my my standard place to go to is AI is not going to replace you, but the employee who's willing to be AI enabled probably will because at the top level of most of the companies that we talk to, you know, that are just rank and file companies. There's a lot of pressure to be more efficient, do more with less, et cetera, et cetera, et cetera. And so yeah, it's they've now signed up for this contract and it's very expensive. They've got to get something out of it that's tangible that they can then say, okay, here's what I did. Here's what we got out of it. Please, you know, look at me and I'm happy and be happy with me, you know, that kind of stuff. So it's, you know, a little bit of a snorkeby way to look
at it, but, you know, all of us live in a world where, you know, as as technical professionals, there's just as much a career management as a keep up with tech and especially in this age of AI, those two things are very deeply intertwined. Yeah, I mean, so, some of this reminds me a little bit of when we were doing cloud migrations, like 10 years ago, one of the most popular things from the cloud side was to give you these total cost of ownership calculations. That would somehow always magically come out that it's cheaper for you to move everything to the cloud. And actually realizing those efficiency gains was incredibly hard. It required a lot more than lifting and shifting your VMs. There was a lot of upscaling that needed to happen. You actually had to close the data centers that you were replacing. I feel like the proposed efficiency gains from AI are real,
but the degree to which they're real and the degree to which enterprises can take advantage of them, that's there's a gap there between the TCO calculator and the reality on the ground. Yeah, I agree. I think there's there's an aspect, you know, like said, we just talked, we talked a little bit ago about that, you know, what's the hybrid cloud and how is it we're settling into this hybrid cloud space? You know, we're in the cloud portion of the over corrections stage right now with a where, you know, oh, I've got this team of 500 people in my company. I can just add AI and take half those people out and everything's going to be wonderful and rosy. And that's one that assumes that yeah, you're going to get your roll out all entirely to, you know, we as technical technological people all know that that's not really, you know, the the best case scenario is very rarely what happens without an exceptional amount of both
planning protection planning protection, you know, you a user acceptance testing, you know, things all on those lines. And so what we're going to come back to is what's called hybrid AI, where we, you know, there's there's people that we're cutting, we're going to start to bring some of those people back in and that's already starting to happen. And we're going to have okay, so we're now going to have, you know, maybe less total people than we ever did, which is a reoccurring theme in industry, you know, we've automated all kinds of things and every time we've done it, we've had less people in the workforce, but we're going to have more than what we thought we could and we'll come to a happy world now. I said what we have to kind of focus on is knowing that the long term, it's not going to be just this one thing or just this one thing that we've got protection and we've got the capability to ensure that those situations, those systems work across the board.
So yeah. So you've mentioned, you know, recovery and protection several times. And like, I know what data protection looks like for a typical system. I have no idea what data protection looks like when it comes to AI being added and integrated into things. Is that something that you have been dealing with with the clients you're working with? So we've definitely been telling the story quite a bit and we're starting to deal with it with actual customers. So we've already talked about the first part of that, which is, you know, really kind of look at what you've got and ensure you've got kind of the permission fixed. And the next part of the journey that always say you kind of have to go for is, um, assume, you know, this is where you really need to make that zero trust initiative come to be reality. And the first step to that is actually, if you haven't done it yet, find some
smart people in your company and sit down and write what you would call your AI policy. Of here is how we're going to have AI work within our company. Here's what we're going to let it do. Here is as explicitly as we can get away with say, here's what we're not going to let it do. And here are the parameters of the versions of, you know, hand-wavy AI that we're going to let do those things, you know, it might be we're going to do a partnership with vendor X. And vendor X is going to be allowed to do these things. Huge M Jones are not going to be empowered to go yolo your way through our code base with with your $20 pod code account. And explicitly kind of state that. And then that becomes your, your northern, you know, your North Star, if you will. This is, we've state our place in the ground and here's where we go. The, the dirty, the dirtiest secret to data protection in the age of AI is it's the same story that we've
been telling since data began, you know, which is effectively, you know, the, or the version of AI that we are in right now is an automation driven artificial intelligence, you know, effectively what it does is yes, it does do some reasoning, but it manifests itself on data as a, as an automation capability. Okay. So, you know, we're a, we're a DevOps focused podcast at this point. We're all familiar with using, you know, Terraform or Ansible to do these other things. When you thought about what is data protection look when I had, when I started introducing Ansible into my environment to do patching, to do deployments, to do upgrade, to do configuration management, what kind of things did you build into that? The same kind of things that we're wanting to, we talked about then, we're also talking about now. We need to lean into say, what are insert platform here tagging
as being a first class citizen, you know, let's say we're, we're using cloud to do deployments, you know, put in your call MD. Okay, as things get built, as things get used, I want anything to be tagged as this. I want, or anything that's, that's, you know, a sensitive data, I want to tag it with this. If it's a secret, they have to be in a secret manager. And if you find a secret anywhere, I want you to tell me. And so that I know that that thing is there. Or, or flag it into your SIM, your security incident. Oh my goodness. Event manager. This is what I get for being in an industry full of acronyms. But, you know, you want to be able to track those things, watch what's going on. And then, you know, at least that always, we've had tagging capability, tagging support for backup replication and recovery systems for over a decade now. Almost all of them know,
okay, if I see a tag that says backup seven days, then put it into the policy that's for backups, and I'm going to protect for seven days, things along those lines. But we've never used it, because it was also just virtual machines before. You know, I'm going to go grab a virtual machine, and here's all my VMs, or here's my cluster, backing up call it a day. We also have to be aware and make use of immutability. This has been coming for a long time. But the pandemic really brought a exponential rise in ransomware activity that happened. We've seen the number of ransomware based events jump year every year every year. And for those that aren't all that deep into it, ransomware used to be, oh, I've hacked into your system. Now I'm going to encrypt all your systems and ask you to pay a ransom. That's actually morphing now. Now we need to really be aware of the fact
that ransomware that was just encryption before. Now before they encrypted, they want to exfiltrate that data. And that exfill is the thing that comes that is the thing of, okay, you aren't going to pay me to unencrypt your back, your systems, because you made good backups. Well, that's great. I'm now going to leak all of your data. So everything must be encrypted, everything must be having mutable backups on it that can't be touched by the AI systems. Just in my own personal playing here, I ran into this myself. I was deploying a Vault Word and Secret Manager here at the house to handle a lot of my home lab integrations. And I was having Terraform deploy it. It got all the way through up to the point where I had it moving secrets from one Secret Manager into it and something hiccuped during that part.
And it said, oh, I was a successful. What does Terraform do when it finds that it's not successful at something? It issued a Terraform destroy and destroyed everything else that had already happened. Oh. And so you have to start building that data protection in your pipeline. So in my situation now, I've got it set up into like any of my cloud code setups of, okay, for anything that we build, before we move data into it, we're going to take a backup at each step that we go and we're going to manipulate data. We're going to take a backup where you know, and just kind of be hyperaggressive of those things. That's my sense. Yeah. 100%. And what's interesting is you say, tell cloud to take a backup. And the first thing I would think to reach for is like an MCP that is capable of invoking backup software. But the thing that we've actually seen more people doing is having a call bash and like a CLI command to perform the backup because that's less tokens
and somewhat like more reliable from a tool usage standpoint. Is that what you're doing to backup the data or you have something more complicated than mine? It's not complicated even at all. So like my, I cover lots of different backup and replication vendors today, but my first love, if you will, was Vee. And Vee has got a noise power shell module that does all the things that I wanted to do. And so I just have it go run. I've got, you know, I've got a couple power shells scripts that are sitting locally. And I just call those repeatedly of go out, scan all of my backups, find the virtual machine that you're working on, identify what job it's in and say go run. And don't, don't do anything else until it comes back and says success. So, but, you know, you can insert vendor here for pretty much that workflow across the board. If it's actually like creating code, yeah, it's a, it's a bash script. That's the, pretty much anything that's text-based
or markdown now. I've got a Synology across the room that as part of the workflow, it goes through and copies my city and notebook over before it ever touches a file. Just to make sure I'm not, you know, going to blow away my, you know, quote unquote digital brain. As I have it, start manipulating files. So, yeah, it's, it's, you are not the first person to bring up Obsidian in relation to AI and leveraging it as sort of like a brain or a memory or yeah, are you using like a structured skill for that or is that just something you've cobbled together? So, yeah, I said, I think, you know, we're all kind of on this journey at some point. And so, I am literally as we speak right on that cusp of, well, you know, the, the hotness the Twitter told me to do for it. I'm going to do AI things as to use Obsidian because the nice thing about is it's natively markdown. And it's an open, you know, it's a fully open system with lots of community supports so you can find a plugin for literally anything you want to conceive of. Now I'm going
through and doing the whole, I'm going to, I'm creating what I'm referring to as my agentic ideation framework of I get this random idea in the middle of the night, which happens all the time and usually manifests of, he holds the button on my phone and say, hey Siri and say remind me at 9 o'clock in the morning to do this thing. So now it's hey Siri, drop a note that says do this and then I've got a script that's going to go pull it and pull it in Obsidian and then a bunch of different layers of skills, depending on what it is. We'll see how that actually, how that manifests in reality where it's a, it's, it's, it's an idea at this point, you've got to get turned it into something. I love the little automations that people are building with AI and the little tool helper tools that everybody's sort of building on their own. And I think that sort of like it reminds me of way back in like the 1980s when we had computer clubs. I mean, I'm too not
that old, but like, yeah, I'm just that by a little bit, but you know, computer enthusiasts clubs before there were like desktops that you could go and buy and people were just tinkering and trying out new things and in this big discovery phase. And then all the things that we discovered all became distilled down to what became the modern desktop and the modern operating system. I feel like we're at that point where everybody's just like, whoa, what could we do with this? Brains exploding and then it's going to send them or down and it's going to turn into things that are actually useful at a business level. Yeah, yes. I mean, like I said, the, the thing that the modern version of gender, or the current version of gender, triv AI really has going for it is that it's just common language. You know, if you look at the iterations of how did we go to automation? How did we go to DevOps and things like that? You had to know in some form or fashion kind of how code works.
You know, you may not, you know, you may be a PowerShell script kitty like me to be real blunt honest, but you had to have some idea of how effectively the structure worked. And at this point, we're hitting that inflection point for just about anybody of the democratization to where it's not that hard to teach somebody to go from I need to tell somebody or a a co-worker how to do a thing. And here's the general framework of how I do that thing and transition that into something that looks more like what we refer to as prompt engineering. And so that approach to that automation is becoming very much more democratized. You know, I'm working a product organ and that's the meme at the moment. What who needs devs, what I've got product managers. You know, and it's totally not a thing. You, it's still, there's still inherent value to being a
subject matter expert. We are very much showing that computer club mindset. Like you said, what will be interesting is where we start to see the little bit of the snapback of, okay, yeah, here's what the product manager who is who can go through and say, I'd like this thing to do ABCD and E and then X Y and Z. And then put that same concept in the hands of something that says, okay, when you get to step A, I want you to build the thing, but I want you to do it with data structure acts and with, you know, code base this, you know, make sure your repositories have this, make sure your, you know, your data protection policies in place and be able to well in relieve those things. That's, that's really the trick that we're going to make in that, that next progression at the the truly democratized version of AI bush, you know what I mean? And there's not.
We're at that point of we have channel one side and we have people that are literally writing JSON based feature documents on the other somewhere in the middle, those things are going to come together and that's going to be an interesting time to watch. Well, we do live in interesting times, don't we Jim? That we do. Well, if people want to hear more of your thoughts on the topic of AI and all kinds of other things, where's a good place to find you? Yep. So my website is coolay.info, just like to drink. If you've got a dark sense of humor, that plus me being Jim Jones will make a lot of sense. And anywhere on social media, I'm cool at IT with zeros because I'm that lead hacker that I'm not. But that's how you find. Awesome. We'll include links to that in the show notes. Yeah, and thank you so much for being a guest today on Day 2 DevOps. Yes, thank you, but for having me. Thank you to Jim Jones for appearing on Day 2 DevOps and virtual high five to you,
dear listener, for tuning in. If you have suggestions for future shows, we would love to hear about them. Hit us up on either LinkedIn or send some feedback via packetpushers.net slash follow up. You can find me, Ned Bellavans at Ned in the cloud.com and my amazing co-host, Kyler Middleton blogging over at Let's Do DevOps.com and we're both terminally active on LinkedIn. Stop by. Say hello. If you've got a way cool cloud product, you want to share with our audience of IT professionals, become a day to DevOps sponsor. You'll reach several thousand listeners, all of whom have problems to solve. Maybe your product fixes their problem, but they'll never know about it unless you come on our podcast and talk about your amazing solution. Find out more at packetpushers.net slash sponsorship. Until next time, just remember that doing DevOps is awesome and so are you.
More episodes
More from The Everything Feed - All Packet Pushers Pods

TNO074: Lean Teams, Big Demands: Managing K-12 Complexity with AIOps (Sponsored)
The Everything Feed - All Packet Pushers Pods

HN843: From Network Engineer to Network Architect with Kevin Nanns
The Everything Feed - All Packet Pushers Pods

LIU023: Wendell Odom – The Man Who Wrote THE Book
The Everything Feed - All Packet Pushers Pods

HW089: Spectrum Analysis and Vibe Coding
The Everything Feed - All Packet Pushers Pods