logo

NJP

CSDM Use Case Discussion - End to end cloud app creation and management

Import · Apr 21, 2021 · video

[Music] um when i was talking to the architecture team there i could see or whatever i feel like kind of the wheels spinning where they're like oh okay i get how you know all of this begins to come together around you know appropriate tags service mapping apm and then you know conversations you may have had with a number of our accounts around the common source data model like all of this begins to kind of come together a little bit more solidly it felt like we're going to get into a cloud-based application creation sequence is what i'm calling this and and the reason for that is because what that's what they're doing they're they're saying oh we have a cloud provider we're going to develop apps and they're going to be deployed and run in the cloud right that's ultimately what's happening and so the the resources that are typically uh in the data center here are really out there in the cloud somewhere and the question is you know what are they you know uh so if something goes wrong here i have context here you know what i mean so i can say oh this this is the business consumer these are the departments and locations that will have problems and that's that's the problem we're trying to solve on the out on the back end of this whole process right um so to do this this is what we've got from a design point of view and it really starts with the business app that somebody's going to create some sort of app right you're funding a team that that does this work this is what we sell itbm for um you catalog the business application and it provides a human readable id at this point so that's kind of the starting of of the team creation that's the starting of where you need to build something now if they decide to build it on the cloud out here right that's fine this is what we'll support um the second thing we do is once they get far enough along and they say hey you know we're going to start deploying code that we've developed you know and and we're going to start allocating resources from the cloud to that what we're proposing here is you call create the app service which is your dev environment potentially and what you do is you get an application service id and you create the app service in a tag-based approach what that does it tells you if you got development production or qa sort of instances i call these app services instances because from a development point of view you're deploying sort of environments and you're you know you've got something you know for each dev tester or production environment use so with me so far any questions no yep this makes sense so so we have really two ids that's established we have the business application and we have the app service id up until now we may not have any cloud resources yet okay but we know we're going to create them and we're going to create a dev environment so there's three methods in which we can allocate the cloud resources the first is what i call broker direct which is that you basically provide access point in our own catalog that redoes the request for you so it's all hidden from you it's automated that that's one option now when you do that you need the ids you need to insert that business app id as part of that request process so you have to build the request process with that id in mind and this id ideally if you just have this one that's fine the app service id because you can always find the business app that's related to it right if you follow cstm so with me so far yep now when when you that's one option the second option is you can go direct to the cloud provider so whoever is doing the development whoever does the application development up up here can go directly to azure or into aws and start requesting resources now the problem with that is that if they did that without any kind of tags you wouldn't know what they're for so when you set up azure or aws you can set up what we call tag governance here and the tag governance says hey you can't request a resource unless you provide xyz tags and we're saying well again you go back to this tag you use this app service id or the business application id or both to create it as a required tag and you can set those um those those cloud providers up so that they require that you can't really request anything without those tags so with me so far yep yep now the third option and there may be more but these are probably this is good enough i call it an intermediated sort of option which is the developers over here they've got their coding platforms and and as soon as they code something there could be a trigger in their ide that actually requests resources from terraform and terraform is what builds out in interfaces to the cloud provider but again you you basically provide the id you set it up so that the ids flow from from the code or whatever the developer is using over here through terraform and back out to the cloud provider so now everything is tagged right you don't have anything that should that's missing that that id now here's the cool thing so so if you follow this process you should now have ids on everything out there you should that's the goal all right with you so far yep yep and what i've seen is like that blue area as we went into the some of the clients were talking about the dev uh teams or i don't think they're doing that tagging to the level that that it should be i would say so i think there's there's probably educational work that we need to probably do there education and also some automation that can be implemented here and the reason we start with the business app and this app services though so that we can be tied into their ci cd pipeline so the dev tools that automate the the the deployment of their app right so when they start coding they also code in their city pipeline so that the code as it's checked in automatically gets built and deployed and you know eventually you can go to production yep but if they insert these tags as part of that process then there's governance now we have a tie this service now we have this tie and we have this app service tie we sort of know now where that stuff's going to land yeah yeah so that's the upfront stuff it can be automated as part of ci cd pipelines and puppet stuff all those tools can be integrated with tags in mind now now so what that leaves you is is two options of tags right you got the business app and business service app service ids now out there for everything all right so so now now that the tags are applied out here in the cloud provider we have cloud discovery and that cloud discovery will bring in all the resources that happen to get created through any of these means right back into the cmdb and those tags will be associated with those things because we'll bring back the tag as well okay so that's the the next step is step five this is where we've tried to go in to the the cloud ops teams or the engineering teams and say we can we can consume tags but the problem is steps one through four here on your diagram is where clients haven't realized the necessity to do all of this so then when we go inbound to these teams to say hey why don't let's let's turn on you know cloud discovery and we can consume all these tags and then we can knit it back into our those cloud teams are kind of blank i would say because they're not realizing that the importance of all of this yeah well it's putting it on one page so they realize how they impact one another like you said this is the tail end this is after the resource has been created right we bring it back in through this or they're only tagging for maybe chargeback purposes internal chargeback purposes so they're putting maybe rudimentary tagging in like okay we're just going to build this to a certain you know line of business or whatever they're not getting that there's an entire application um service business service um sort of hierarchy or metadata you know framework all around this and how important it is so then when we go talk to other teams you know i think we span multiple organizational teams here in our accounts as well you know architecture like we talked about you have cloud ops teams you have your traditional say sacrum team and then you have your dev teams up in in the top left area that's right that's right and uh we introduced an api so that you can actually create the app service as part of your ci cd pipeline so there's an api that'll return this id when you call it so as as the developers are just you know chugging along implementing things they call out to service now get an id and they can insert that now as part of the process what i was thinking about is with our dev devops application capability like that what i was noodling on was like how do we get the dev team to get excited about this because them inserting the tags that may not have a direct benefit to them but what i was thinking about is i know we can report out on some of the metrics and the change failure rates and the door metrics and things like that on our devops modules so i think the carrot to the business to the to the dev teams could be we could break out your reporting at the application level if they insert the tags because what i was thinking about is if they don't have a benefit themselves for doing the tagging you know will they adopt the tagging strategy themselves if the benefits are in other organizational areas well the benefits is to automatically being able to understand you know your consumers and if these guys are not happy out here right you start getting that feedback through your service management process also billing i mean you you touched on billing here as well when your cloud providers provide a bill they provide the they can provide that tag association so now you can say okay this application has 40 deployments right and maybe 39 are in development and we don't need them we're getting billed for 39 development environments what gives right you can kill maybe 39 development environments and then get your billing under control yeah so so but yeah if you don't do some sort of tagging the other problem with tagging as well as well is that people try to insert a ton of tags like they'll say hey everything you request has 40 tags on it right and they try to capture everything imaginable in the model right including where it's used why it's used and and this is impossible this is really impossible to set up and actually govern because you're asking developers now to insert that information rather than just one or two ids and we can gather the rest if we had that other data yeah so so this is almost the complete you know use case the tags are now there and we associate those through a dynamic query basically for this app service the app service will gather up all things that are tagged for it so we have that traceability up to there and then the really i think the interesting thing is that you were talking about governance and we're like at the business app id this is where you start looking at tco total cost of ownership grc right if you if if the developers decide to add a component here that has sensitive customer data or credit card data it's now going to need to be managed differently it's audited right make sure that you encrypt credit cards so grc kind of taps into the app design and we can kind of capture that up here regardless of where it's deployed right including the cloud and then the app service id tells you that environment right specific use and if you have it a cloud app deployed multiple times right multiple times for different consumers or different locales a lot of folks will do that they'll have some people in one location and then people in another location using a different um a different app service for example a different cloud provider location so that's the common use case as well and the last thing i would say is that anything that's not tagged that is a questionable like what kind of governance stamps how was that created so somebody shouldn't be able to go out there and create a cloud resources that's not tagged because now the billing is going to come in and nobody knows who's attributing that billing right for that resource yep yeah i've seen this like i said i um you know based here in in toronto so uh i've seen this at a couple of banks at the light began to go on because we were dealing more down in the sort of the sacrum the cmdb the governed data governance steward yeah sort of level and then the reality kind of started to hit like that this is you know there's there's we got to bring architecture in and we got to probably involve the dev teams and where it really hit me where we began working with the dev teams and began to see that they're probably the the point where they need to be putting in the tags um and have some sort of framework or structure there that then um ties a lot of this together because i always look upstream right so you're you know you're dealing with the problem down here but you got to go upstream it's like how are these things created and we've identified three different models for how they're created um and there may be more but you know the the first inkling of something being done is really at that business application and then most organizations they need to have a business app to fund something it's like we're getting we're going towards what we call product based it or product centric id and that business app is sort of the the level where you know a business organization or capability requires an application and so you know teams are hired and and then they're kind of established to develop these things so yeah you got to swim upstream to fix the problem you can't fix it from the outflow you know i mean so i get yeah absolutely that really has hit me in the last um in the last few months here that i saw that this was we were we were going at this at the bottom end of it versus trying to get more to that top end here and get in bridge into that development team or at least architecture like i i'm still not 100 sure if it's it it happens even before the development team it's like hey you know the architecture team or the business says we need an application created for doing something i don't know it doesn't matter it could be for managing covid right status but the point is somebody decides we need to fund something then the team is assembled to develop it but that that's the point where you establish the id you describe the app that's going to be built and as it's built out and as it's deployed various places that's where those tags and you know resources are acquired and anyways that's that's kind of the the very first start of the application kind of happens way up there in design and planning yep

View original source

https://www.youtube.com/watch?v=IJ-S6rjN71A