Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Agenda - DevOps Mutualization SIG Meeting - Thursday 17 June 2021 #30

Closed
9 of 11 tasks
mcleo-d opened this issue Jun 14, 2021 · 10 comments
Closed
9 of 11 tasks

Agenda - DevOps Mutualization SIG Meeting - Thursday 17 June 2021 #30

mcleo-d opened this issue Jun 14, 2021 · 10 comments
Assignees
Labels
approved Approved meeting minutes indexed meeting GitHub action meeting label

Comments

@mcleo-d
Copy link
Member

mcleo-d commented Jun 14, 2021

Date

Thursday 17 June 2021 - 12pm Noon EST / 5pm UK

Untracked attendees

Name Firm Comment

Meeting notices

  • FINOS Project leads are responsible for observing the FINOS guidelines for running project meetings. Project maintainers can find additional resources in the FINOS Maintainers Cheatsheet.

  • All participants in FINOS project meetings are subject to the LF Antitrust Policy, the FINOS Community Code of Conduct and all other FINOS policies.

  • FINOS meetings involve participation by industry competitors, and it is the intention of FINOS and the Linux Foundation to conduct all of its activities in accordance with applicable antitrust and competition laws. It is therefore extremely important that attendees adhere to meeting agendas, and be aware of, and not participate in, any activities that are prohibited under applicable US state, federal or foreign antitrust and competition laws. Please contact legal@finos.org with any questions.

  • FINOS project meetings may be recorded for use solely by the FINOS team for administration purposes. In very limited instances, and with explicit approval, recordings may be made more widely available.

Agenda

Minutes

  • Roll Call
  • Eddie Knight CitiGroup?
  • Paul Groves - CitiGroup
  • Ashok Singh - JPMC
  • Brian Hanafee - WF
  • Dov Katz - MS
  • Richard Wagner - CodeThink
  • Tistran Maat - CodeThink
  • Anders Wallgren - CloudBees
  • James MacLeod - FINOS
  • Amol Shukla - MS
  • Tim Johnson - CloudBees
  • Jamie Jones - GitHub
  • John Mark - FM?
  • Meeting notices, antitrust policy
  • Minutes from May 20, 2021 approved by silent consensus
  • Self-service tooling for DevOps
  • Dov - "Adopting Tech and Tools in a Regulated Enterprise"
  • Want to build consensus on tools that can make us all more productive
  • Figure out how to cope with the fact that our world isn't always supported OOB by tools
  • If we're all building wrapper tools to address this, can we open-source and leverage?
  • Objectives: Guiding principles, challenges, patterns, examples
  • Guiding principles & best practices: Manage access to technology (who can do what); Keep track of assets (know what we have); Security and architecture best practices (keep things safe and reliable, follow the rules)
  • Common challenges; unsophisticated access controls; difficulty managing public cloud entities without corresponding tracking in-house; need guardrails
  • Things that take "hours at home" take "several weeks in the office"
  • Typical pattern: lock down access, require manual action by small group of support staff, unsustainable/unscalable
  • Strategic preferred option: lock down admin access, create clis/apis/pipelines with admin privileges for applying changes to the system
  • Examples: Serverized liquibase, "unimatrix" creation of namespaces in k8s, devops self-service tools to provide admin access to, e.g. SCM, JIRA
  • Questions and next steps: does this ring true, are you building similar "wrappers?" Can we open-source this stuff, would you use it if that existed?
  • Brian: we have a lot of wrappers internally, too; "it's a losing game"; other tools that access tooling APIs make this difficult; answer has to be that this gets accessed at the API level
  • Ashok - similar situation for us, happy to share
  • Amol - can we share more details on a future call?
  • James: Paul, is there an appetite to respond to this?
  • Paul: Yeah, can reach out to people to find out
  • Anders: We've worked a lot on self-service & access control aimed specifically at this problem set, so this all rings very true to ue
  • Brian: Feedback for CloudBees: Jenkins doesn't help here; actions are tagged to individuals, need to take into account the role/duty on whose behalf this is being done
  • Anders: noted
  • Paul Groves: described upstreaming tool for git/git proxy
  • "JMW" - good to hear, sounds like the right direction. It's in all our interest if we can view the totality of the software lifecycle that we depend on. Bi-directionality has been missing here, looking forward to checking this out.
  • Jamie: github connect is our pathway for this to happen, git proxy is the best solution for right now, happy to talk further requirements
  • JMW: scanning vendors don't really consider this issue, which is annoying. would like to see more partnerships working on this problem
  • AOB
  • James: Please add people to firm CCLAs for GitHub Team Discussions to facilitate more robust participation
  • James: DevOps Mutualization panel accepted, who would like to join the panel?
  • Richard: Build Meetup 2021 next week

Decisions Made

  • ...

Action Items

  • ...

WebEx info

Webex:
https://finos.webex.com/finos/j.php?MTID=md62056638ba05fbea86b9582df94f807

Dial-in

  • US +1-415-655-0003 US Toll
  • UK +44-20319-88141 UK Toll
  • Access code: 127 662 6070

Github Repo: https://github.com/finos/devops-mutualization/

Mailing List: Email devops-mutualization+subscribe@finos.org to subscribe to our mailing list

@mcleo-d mcleo-d added meeting GitHub action meeting label pending-approval Meeting minutes pending approval labels Jun 14, 2021
@mcleo-d mcleo-d pinned this issue Jun 15, 2021
@mcleo-d
Copy link
Member Author

mcleo-d commented Jun 16, 2021

DevOps Mutualization Panel Discussion @ DevOps World 2021

screencapture-mail-google-mail-u-0-2021-06-16-13_04_32

@awallgren
Copy link

Hi everyone

@ashukla13
Copy link
Contributor

hi

@mcleo-d
Copy link
Member Author

mcleo-d commented Jun 17, 2021

Hello 👋🏻

@RichardWagener365
Copy link

Hi everyone, Richard Wagener - Codethink

@tcraigjohnson
Copy link

Good morning!

@TLATER
Copy link

TLATER commented Jun 17, 2021

o/

@jbjonesjr
Copy link
Member

👋 Happy DevOps Mutualization day everyone

@RichardWagener365
Copy link

AOB Agenda Item: BuildMeetup - 24-25 June 2021

This is a two day virtual event on the 24-25 June, with a mix of talks, lightning sessions, and panel sessions. The event has been scheduled to be as timezone friendly as possible. And if there are talks that you are not able to make, all talks will be recorded and will be freely available to all.

Also, there are also 3 talks from Codethink!

  • Tristan Van Berkom: BuildStream and the REAPI
  • Tom Coldrick bb-remote-asset: A Remote Asset API Server Implementation
  • Edmund Sutcliffe/(and me): The Cargo Cults of build

Full Schedule below:
https://meetup.build/schedule.html

If you are interested in attending and want to register, you can do so at: https://meetup.build/

@awallgren
Copy link

Minutes added, feel free to correct/update.

@mcleo-d mcleo-d closed this as completed Jun 24, 2021
@mcleo-d mcleo-d unpinned this issue Jun 24, 2021
DovOps added a commit to DovOps/devops-mutualization that referenced this issue Jul 8, 2021
ashukla13 added a commit that referenced this issue Jul 21, 2021
Added presentation made 17 June SIG meeting (  #30 )
@mcleo-d mcleo-d added approved Approved meeting minutes and removed pending-approval Meeting minutes pending approval labels Jul 22, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Approved meeting minutes indexed meeting GitHub action meeting label
Projects
None yet
Development

No branches or pull requests

7 participants