does16 london - gareth rushgrove - communication between tribes: a story of silos, devops and...

83
(without introducing more risk) Communication between Tribes Puppet Gareth Rushgrove A story of silos, Devops and Government

Upload: gene-kim

Post on 14-Jan-2017

231 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

(without introducing more risk)

Communication between Tribes

PuppetGareth Rushgrove

A story of silos, Devops and Government

Page 2: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

(without introducing more risk)

@garethr

Page 3: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

(without introducing more risk)

Gareth Rushgrove

Page 4: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

(without introducing more risk)Backstory

The very abridged version

Page 5: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Gareth Rushgrove

Page 6: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

GDSGovernment Digital Service

Gareth Rushgrove

Page 7: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Gareth Rushgrove

Gareth RushgroveTechnical ArchitectGovernment Digital Service@garethr

Page 8: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

I’m no longer a civil servant.Thank you to everyone who is.

Gareth Rushgrove

Page 9: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

I learned the importance of communication first hand;from successes, failuresand relentless observation

Gareth Rushgrove

Page 10: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

- Stories from Government- The importance of language- The power of stereotypes- A few

Gareth Rushgrove

Tips

Page 11: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

(without introducing more risk)

Different Languages

One for each silo

Page 12: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Gareth Rushgrove

Appreciating you’re a silo

Page 13: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Agile, lean, scrum, containers, iteration, stack, hypervisor, nosql, serverless, cloud, velocity…

Gareth Rushgrove

Page 14: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Agile, lean, scrum, containers, iteration, stack, hypervisor, nosql, serverless, cloud, velocity…

Gareth Rushgrove

Developer silo

Page 15: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Incident, event, problem, COBIT, configuration management, capacity management, CAB…

Gareth Rushgrove

Page 16: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Incident, event, problem, COBIT, configuration management, capacity management, CAB…

Gareth Rushgrove

IT silo

Page 17: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

APT, threat model, risk, cyber,mitigation, control, kill chain,threat intelligence, opsec

Gareth Rushgrove

Page 18: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

APT, assume compromise, threat model, risk, mitigation, control

Gareth Rushgrove

Security silo

Page 19: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

SPAD, MCO, GPG, CESG,CERT, GDS, IDP, DTO, 18F, USDS, IL3, OCTO, EUD

Gareth Rushgrove

Page 20: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

SPAD, MCO, GPG, CESG, CERT, GDS, IDP, DTO, 18F, USDS

Gareth Rushgrove

Government silo

Page 21: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

the language and speech, especially the jargon, slang or argot, of a particular field, groupor individual

Gareth Rushgrove

lingonounplural noun: lingoes

Page 22: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Language acts as a barrier to entry to different communities

Gareth Rushgrove

Page 23: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Language differences reinforce organisational silos

Gareth Rushgrove

Page 24: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Gareth Rushgrove

Identify words in your organisation that are only in use in certain groups or teams

Tip

Page 25: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

(without introducing more risk)

The New Service Management

Talking ITIL and agile

Page 26: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

At GDS we talked a lot about Design, User Research, Agile and Open Source because they were fairly new to Government

Gareth Rushgrove

Page 27: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Gareth Rushgrove

We talked a lot about discovery and alpha because people started there

Page 28: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Gareth Rushgrove

We hired a lot of software developers becauseGovernment had very few

Page 29: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Gareth Rushgrove

We didn’t talk enough about operations

Page 30: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

We didn’t talk enough about operations (to begin with because we weren’t running anything)

Gareth Rushgrove

Page 31: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Gareth Rushgrove

Don’t take things for granted, communicate about everything you care about

Tip

Page 32: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Gareth Rushgrove

Words often carry the weight of past experiences and other organisations

Tip

Page 33: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Will the release really work?

Gareth Rushgrove

Paraphrasing one of my colleagues from 2012”

Page 34: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Yes. We’ve done it more than1000 times. I’m confident itworks now

Gareth Rushgrove

Paraphrasing me

Page 35: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Early members of GDS were mainly from media, startup and technology backgrounds

Gareth Rushgrove

Page 36: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

The formal language ofService Management* wasunfamiliar to most

Gareth Rushgrove

*Ironically, ITIL was a creation of CCTA, a UK Government agency

Page 37: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

But practices like automation,developers on-call, configuration management, continuous deployment, and automatedtesting were second nature

Gareth Rushgrove

Page 38: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Gareth Rushgrove

Transformation often meansnew types of people. They will bring their own languageand assumptions

Tip

Page 39: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

We cancelled one configuration management effort because we couldn’t keep the spreadsheetup to date

Gareth Rushgrove

Remembering one conversation with an Government department”

Page 40: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

The recommendation was to move from quarterly releases to one release every 6 months

Gareth Rushgrove

Remembering one conversation with an Government department”

Page 41: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Oh, we use an open source configuration management tool which reports state every30 minutes for every device

Gareth Rushgrove

Remembering one conversation with an Government department”

Page 42: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Overlapping words from different tribes are often a great place to start collaborating

Gareth Rushgrove

Tip

Page 43: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

(without introducing more risk)Stereotypes

Understanding what people think of you

Page 44: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

A lack of personal relationships, sometimes caused by theinability to communicate,leads to stereotypes

Gareth Rushgrove

Page 45: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

a widely held but fixed and oversimplified image or idea of a particular type of person or thing.

Gareth Rushgrove

stereotypenounplural noun: stereotypes

Page 46: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

No

Gareth Rushgrove

Shiny new technology!

We need bimodal IT

What grade are you?

Page 47: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

No

Gareth Rushgrove

Shiny new technology!

We need bimodal IT

What grade are you?

Developer

Page 48: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

No

Gareth Rushgrove

Shiny new technology!

We need bimodal IT

What grade are you?

Government

Page 49: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

No

Gareth Rushgrove

Shiny new technology!

We need bimodal IT

What grade are you?

IT

Page 50: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

No

Gareth Rushgrove

Shiny new technology!

We need bimodal IT

What grade are you?

Security

Page 51: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Some silos are organisational

Gareth Rushgrove

Page 52: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Many silos are personal

Gareth Rushgrove

Page 53: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

a fictional rogue systems administrator who takes out his anger on users and others who pester him with computer problems

Gareth Rushgrove

BOFHBastard Operator from Hell

Page 54: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Subverting stereotypes as a wayto build relationships

Gareth Rushgrove

Tip

Page 55: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

(without introducing more risk)Security Says No?Experts, intermediaries and end users

Page 56: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Gareth Rushgrove

Page 57: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Scaling finite expertise is often done with stacks of paper policy

Gareth Rushgrove

Page 58: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Making use of stacks of paper policy often involves middlemen

Gareth Rushgrove

Page 59: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Having direct access to real domain experts* is awesome

Gareth Rushgrove

*Unfairly in my case that mean

Page 60: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

I think you’ll find you can’t do that because of my interpretation of this wording in GPG13

Gareth Rushgrove

Unfairly paraphrasing countless conversations with intermediaries”

Page 61: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Let’s just ring Richard fromGCHQ and see what he thinks

Gareth Rushgrove

”“

Unfairly paraphrasing countless conversations with intermediaries

Page 62: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

…!

Gareth Rushgrove

Paraphrasing countless conversations with intermediaries

”“

Page 63: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Don’t let scarcity of expertise leadto unapproachable stereotypes

Gareth Rushgrove

Tip

Page 64: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

(without introducing more risk)

Code as a Communication Medium

Bridging policy and practice

Page 65: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

The dreaded incident severity conversation

Gareth Rushgrove

Page 66: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Critical, Major, Minor, P1, Sev2

Gareth Rushgrove

Page 67: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Stage 1Everyone thinkseverything is critical

Gareth Rushgrove

Page 68: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Stage 2Everyone thinks all incidents for there own service are critical

Gareth Rushgrove

Page 69: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

(without introducing more risk)

Feature: Search

@high Scenario: check search results on unified search Given I am testing through the full stack And I force a varnish cache miss When I search for "tax" using unified search Then I should see some search results

@normal Scenario: check organisation filtering on unified search Given I am testing through the full stack And I force a varnish cache miss When I search for "policy" using unified search Then I should see organisations in the unified organisation filter

@normal Scenario: check sitemap Given I am testing through the full stack And I force a varnish cache miss When I get the sitemap index Then It should contain a link to at least one sitemap file And I should be able to get all the referenced sitemap files

GOV.UK Smoke Tests

Page 70: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

(without introducing more risk)

Feature: Search

@high Scenario: check search results on unified search Given I am testing through the full stack And I force a varnish cache miss When I search for "tax" using unified search Then I should see some search results

Page 71: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

The ambiguous nature of thewritten word

Gareth Rushgrove

Page 72: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Lots of opportunities forpolicy as code

Gareth Rushgrove

Page 73: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

(without introducing more risk)

// Should cache responses for the period defined in a `Cache-Control:// max-age=n` response header.func TestCacheCacheControlMaxAge(t *testing.T) {

ResetBackends(backendsByPriority)

const cacheDuration = time.Duration(5 * time.Second)headerValue := fmt.Sprintf("max-age=%.0f", cacheDuration.Seconds())

handler := func(w http.ResponseWriter) {w.Header().Set("Cache-Control", headerValue)

}

req := NewUniqueEdgeGET(t)testRequestsCachedDuration(t, req, handler, cacheDuration)

}

CDN Acceptance Tests

Page 74: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

(without introducing more risk)

Scenario: The application should not contain SQL injection vulnerabilitiesMeta: @id scan_sql_injection @cwe-89Given a scanner with all policies disabledAnd the SQL-Injection policy is enabledAnd the attack strength is set to HighAnd the alert threshold is set to LowWhen the scanner is runAnd the XML report is written to the file sql_injection.xmlThen no Medium or higher risk vulnerabilities should be present

BDD Security

Page 75: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

(without introducing more risk)package { 'openssh': ensure => latest}

Puppet

Page 76: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Where possible combine policy with implementation

Gareth Rushgrove

Tip

Page 77: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

(without introducing more risk)ConclusionsIf all you remember is…

Page 78: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Share language as muchas possible

Gareth Rushgrove

Page 79: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

Because sharing language makes shared tooling and process easier

Gareth Rushgrove

Page 80: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

And learning the language ofanother tribe is a fantastic wayof breaking down silos

Gareth Rushgrove

Page 81: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

(without introducing more risk)

What I Don’t Know How to DoDevops Enterprise Ask

Page 82: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

What macro organisational structures limit theemergence of silos?

Gareth Rushgrove

Page 83: DOES16 London - Gareth Rushgrove - Communication Between Tribes: A Story of Silos, Devops and Government

(without introducing more risk)Thanks

Ask me questions later