logo

NJP

How JFrog and ServiceNow are Bridging The Gap Between DevOps and IT Operations

Import · Dec 08, 2022 · video

uh without further Ado thank you for coming today and I'll turn you over to our hosts Isaac bill hey there how you doing I'm Bill Manning um I am a solution architect here and also solution engineer and manager for the Americas at jfrog uh Hey servicenow guys thank you so much I'm so excited to actually present with Isaac Isaac hey everybody Isaac Parts um the devops product manager for servicenow I've been here uh five years going on five years now so I'm based out of Northwest Arkansas I used to be a developer many years ago but many of the concepts still stayed the same so it was a natural progression for me to get into devops and this jfog partnership is has been really exciting so we look forward to showing you what the solution looks like today absolutely we couldn't be more excited on this end also I think uh especially we're seeing who some of the people we had in the polls that are here um I think you'll be very excited to see all the integration points and the various aspects behind it we'll be talking about the jfrog platform and how it integrates into servicenow and so let's kick it off take it away Isaac all right so what is devops this is where uh typically two major teams two primary teams are are joining together we need to connect those worlds the solution you're going to see today it shares information from your CI CD tools of choice from any of your coding pipeline orchestration tools and servicenow is is agnostic in that sense so if you're using a different combination of these tools that's completely fine we're focusing on jfrog today and you'll see through the solution how everyone doing their normal tasks whether that's the development team or whether that's the change management team it's it's creating Automation and we're reducing as much administrative overhead as possible so is it possible to do this you'll you'll see yes it is possible to bring these two teams together this is a representation of maybe the current state Your devops solution is in a lot of Developers do not like having to wait and unfortunately that's what a lot of a lot of them are doing and over the course of a year service now has gathered data from our customers to see to see that when you want to have a production commit or a production change put out into your application whether it's your website a mobile application internal external the development team is waiting sometimes three weeks to just have that proved and to get their code committed to a production instance this is something that's a challenge for all teams involved we can move forward past this so right now maybe things are a little contentious development they they have work to do they have maybe uh some some code that is going out for a new product or there's maintenance or bug fixes they need to go they don't they're not focusing on well is there an operating system update going on one of my servers is there a virtual machine that's expiring are there certificates that are expiring they are they're not focused on the cmdb aspect and this is where some some challenges can arise because I.T also has their job to do current state many organizations they're competing for resources a lot of times development needs to go it might be putting you know pumping the brakes and saying wait hold on a second we can't just uh we're not ready for this in some way shape or form but these two teams can't exist without each other they really need to be viewed as two halves of a whole and to make sure that development can go forward and be interrupted as little as possible whereas I.T can focus on security compliance and making sure that nothing's going to get broken if you want to go into warp speed so to speak so well it's funny you say that right I mean that's the thing is is that you and I have been in this game for a long time you know we go back to the days of you know even when it was more monolithic for you know releases that were happening quarterly you know you have J you know massive meetings and now with the increased Speed and Agility of most organizations trying to get out there with smaller features faster you know how do you ensure a lot of those pieces and components are safe secure you know approval processes you know like you said moving at warp speed as opposed to you know running you know running at the current speed that like most spaceships are right now right getting to that next phase absolutely so here's a representation of individual challenges that these these respective teams are dealing with we've already talked about development and change management just to recap they're they don't want to spend time on administrative tasks we want to make sure that we're focused on what they're doing and also a lot of times these administrative tasks can have errors in them if you're copy pasting things along those lines there's a human element to that as well the change management side are they able to keep up with the volume of changes it's so interesting as Bill and I talk to customers it doesn't matter what industry they're in everybody has software that's the customer expectation that's the business to business expectation so there's just an increasing volume of changes that are coming down to it that need to be kept up with and support the development tasks as as the company expands their business over on the governance side right how how is compliance being registered are you able to check to make sure that we're not putting clear text passwords in your configuration files are we making sure that all of the proper security scans and code scans are being performed it's not just about coding this is where jfrog comes in making sure that that oversight is there for the governance operations again needs visibility into what they're expected to manage all the way up to your executive level do you really have a grasp on the the time and resources it's taking to build and support your applications so from the from the Inception from the idea and that demand are you as an organization able to track any potential bottlenecks where are things being held up are the developers going too fast or are they going too slow is it able to keep up with all of the changes are they providing the right instances and environments and a stable Network so the application Level getting into the the VP of development here is just an example being able to track all of these systems these CI CD tools but also separate teams is something that's a challenge and the servicenow jfrog solution aims to address that from the servicenow side there is an adoption Journey first and foremost we have to connect the tools so connecting to tools like jfrog Jenkins jira any other type of planning tool coding tool orchestration tool what's what's your favorite flavor picket uh Azure devops right so getting the tools connected is first and foremost from there that devops data we're able to organize it group it accordingly by pipeline or by project and then add add that development cicd information into change requests so if you're used to using the servicenow change request process this is simply piggybacking on top of change processes that you already have in place it just has now much more context from there the adoption Journey gets them to change registration so as your development team is automatically pushing out their commits typically on a daily basis we want to collect those and automatically create the change request avoid any manual errors and making sure that the context is properly inside of servicenow for any auditing approvals and rejections that need to be done and finally change automation that's the the run of the crawl walk run change automation is where you're allowing systems like servicenow and jfrog to make decisions to automatically approve certain parameters or if they're not met to reject certain parameters and this reduces the overhead for your it team greatly if you can start automating those change requests that's where you really start to see a lot of speed added to this solution and this is where we kind of cut over to the other side of this right so you know the administration task that you can perform uh utilizing things you know utilizing service now as that infrastructure for approval processes depending on your role within your software development organization of course you have the software development side and the corresponding software and I love the fact that Isaac brought up the idea you know we always say you know every software company every company is a software company and it's true and the thing is is that you know at jfrog you know we have uh the broad range of insane amounts of customers of you know although you know we've been doing this for a long time since 2008. you know we have almost 7 000 Global customers uh in every potential field uh out there you know we have like almost 100 of the Fortune 100 you know top 10 awning manufacturers top 10 Banks all you utilize us for their software development needs even now to the military you always hear from you know developer to device code to cloud of course but there's multiple layers in the organization the handle software development so on this side we're going to talk about right now is of course the operation side we know the software development the deployment development the release management right the accountability behind it the security aspects behind software development and the thing is though is what we see over time is you know that the speed and delivery uh you know has increased over time and you want tools that will be able to match that right that will actually be able to keep up with the Speed and Agility of organizations while at the same time having that Administration functions to have accountability behind it and today we're excited to show the integration between these two awesome products right the administration side the accountability side and on the other side of it too the other portion of the accountability which is actually the development aspects of it too now we have here you know of course the accelerated change and I'm going to talk about part of this and and so is Isaac but you know these are some of the things that you know that are brought to the table uh from servicenow in terms of things like backlogs and your you know orchestration and testing and the operational side and actually jfrog and our platform really fits symbiotically into the entire ecosystem that was designated and you know as part of servicenow devops and the integration into our system allows you to really expedite and Excel as an organization you know there's a reason why so many organizations have trust through our platform and also trusted servicenow and now the symbiosis between the two allows you to have that in a more you know a more concise manner uh between them I said would you like to make any uh additional comments on this slide here too yeah thanks Bill so this is essentially a high level architectural overview of what servicenow and jfrogs means when they say devops so having those systems of record on the left hand side performing their tasks developers performing their tasks getting into now the orchestration and testing a very natural part of your pipeline process then there's the release stage typically that's where a pause is inserted when we have an orchestration tool like like Jenkins you're going to see Jenkins today get to the final stage of a pipeline that's where a change request is typically created from the orchestration tool it's put on pause the change request over in service now takes over as the approval or rejection of the is this going to continue you see a lot of information coming over and wrapped around that change request and it's coming in from all different sources and this is truly the The Core Power of a solution for us to bring in data from your cmdb in Orange you see the incidents and outages for us to bring in your existing change processes and your existing change Windows you see things like the blackout schedule there in sort of a pink color jfrog bringing in your releases your artifacts your test results your scan results and then finally the code commit itself making sure that we're we're tracking back to the developer and this specific bit of work they did that's landed in this change request the the stories as well tracking your budget making sure that development is is tracking the right amount of hours and is is working on the right items that match your your agile processes so this change request it's not just a change request at this point this is an extremely powerful grouping of data from there the Change Control once it's a hopefully approved sends that back to the orchestration tool it proceeds then to finish compiling that Pipeline and going through the rest of its stages so all of that information wrapped around that change request it allows systems like servicenow and jfrog to help make those decisions and sometimes maybe there is a bucket for manual review what we want is to make sure that your your major pipelines with your kind of standard steps let's take out that high volume of change requests and talk about automating it talk about automating those approvals and of course there's always going to be time for manual review as well and we'll talk about both of that so what's nice is is that you know all that corresponds into one of the key factors one of the core values that we have as jfrog we call it the liquid software Vision which is simplify streamline the power right you know software updates of the world right the idea here is you know if I asked you on your phone you know what version of Twitter maybe that's a bad way to talk now but anyway or what version of an application you have on there it's hard to tell right you'd have to actually do a little digging and and the thing is is that software over time has become more seamless right the releases have become faster you know users expect to have the things that they need and the thing is is that you know we talk you know All Those portions in those processes you know that were described by Isaac that you know is handled by Services now the way to kind of think about what we do is we're the flow behind you know underneath it whether it's a you know continuous stream of software development that goes by so it's excited with the liquid software Vision or to actually say it's more akin to something like a conveyor belts you know your publishing or you're building software there's many very phases for checkpoints and whatnot and the thing is is that artifactory which is the core component of our platform and the platform itself has a massive amount of metadata around that software development and you can actually have that data actually correspond back in the service now and it's we actually also to have that same methodology like servicenow too we are truly Universal we integrate you know we have many different packages over 32 package type Technologies everything from Conan for CNC plus plus you know we have an amazing DACA registry uh you know all the standard coding languages including things like cargo rust and and Swift support even now to things like orchestration tools like Helm and also infrastructure as code uh like terraform some Chef puppet ansible right we have all those we also integrate into everything right whether it's either through plugins that have been developed using our CLI or even just direct API integration and the thing is is that you can use this anywhere we have a managed solution that we have as a company you can install it in your own you can have a combination of both we're truly flexible in our approach to actually have our platform actually be deployed where you need it now we'll retell you but where you need it we give you the freedom that ability to do that and when you say that that really comes down out to you you know the ideas of simple things like managing your software supply chain you know we hear this a lot these days and the reason why I decided to kick this off here is to relay the context of some of the key features that we'll be integrating in today because the thing is is that when we talk about software supply chain remember your software 85 to 90 percent of the things you produce are someone else's right these are you know coders are artists they're you know in my opinion I'm a decoder Isaac's been a software developer you know our palette that we use to create the things that we create is those libraries you know we need a you know we have the ability to like parse a string or create a hash table or or whatever and we rely on this and the thing is is that you know the big question is is that where does it come from right false components so the free and open source this is one of my favorite quotes to kind of exemplify uh the reason why we're discussing this as part of a servicenow jfrog integration every time you do a pip install go get Maven Finch or something that's you know to that you know it's the equivalent of just finding a thumb drive on the street and plugging it into your production server right you don't know where it comes from and that's actually a lot of the problems that we see today under supply chain attacks because there was a 650 percent increase in supply chain attacks last year alone and the thing is the reason why is it's super easy to get into it usually lies on the radar because usually it's not a direct dependency that you're doing it's usually some sort of indirect dependency now this isn't just libraries you might use for python or npm or CNC plus plus these are also base level Docker images that you use every day you know something you compose you're like oh I'll just use a a base level in Ubuntu image maybe already has Java and python installed and I'll go and install my application and I'm good to go well we'll sure we'll talk about some of that today because in a lot of cases they're not as safe and secure as you think they are so understanding the jfrog platform it truly is an end-to-end devsecups platform and the idea here is very simple in the center we have jfog artifactory that's the way to maintain and manage those third-party transitive dependencies that you use every day to build your software or even like base level container images or even base level even things like uh terraform templates but it's also a way to manage your build one of the key factors that we showed in one of the earlier slides for servicenow is of course the sdlc the software development life cycle and the many aspects behind that you know the thing is is that that's one of the tie-ins that you can have between servicenow and and actual jfrog especially with artifactory is is that when you produce a build you know you might have like I said Dev QA staging production and we have a promotion API that allows you to promote those bills through the cycle if you follow things like 12 Factor app method or multi-tier the atomic unit the things that you actually produce in Dev and the things that you release into production should be identical medical variants of that are are problematic and this allows you with artifactory to keep that consistency and then use servicenow to create things like approval processes or automated approval processes where you could even go ahead and use a product like our jfrog x-ray product which actually goes ahead and make sure that those transitive dependencies that you're utilizing those base level images are compliant from a legal perspective right so licensing make sure there's nothing malicious or nefarious uh inside of those actual binders that you're using just to give you an idea everybody knows about solarwinds that was a fifth level Transit of dependency so it's not even a direct dependency that caused it so this actually makes sure that those components are safe and secure based on rule sets that you actually apply in addition to that you can also make sure that things are operationally uh risk-averse the thing is is how old are the actual components you're using how healthy is the open source project that's supplying it we can tell you that and you can place rules and of actions based on those rules everything from the developer level at shift left which we'll talk about in a minute all the way up to its release and it's an end-to-end accountability in terms of security you can also integrate into your CI and one of the things we'll talk about is how to get that data back into servicenow so that you can review that data to make sure that if you are promoting a bill say to production or even to the next phase of the sdlc maybe you want to make sure that you're not actually introducing something potentially threatening we also have at the top top left over here jfrog pipelines it's our CI CD and CI orchestration tool it's actually a straight CI environment built for scale it can be used as a distribution mechanism too if you already have your investments in your own CI but also too a lot of companies these days have multiple CI systems and multiple builds so you can actually use our pipelines product as a way to orchestrate them and on top of that we have accountability built in where we actually have signed pipelines where you can go in and have a blockchain style ledger to show that you actually have that accountability strain and you can publish that information if you like to the far right we have distribution where we cover you in terms of Distributing your software whether you're Distributing I'll say a web service or you're pushing say a home chart and Docker containers or maybe you want to have your customers download an SDK or you want to update things in the field uh you know it could be a way for you to like you know even share your stuff with other companies that you work with we have distribution and the thing is our x-ray Product 2 also extends all the way down to the distribution side on the bottom part we have our jfrog connect product this is our iot platform it's the device manager it's a remote updater it's a process monitor it's a wrote Diagnostics and also remote accessibility so that's another thing we offer and then on top of that we have mission control and insight it's a way to get actual metadata out of the system and you can plug that into other tools that you might use so you know for that kind of uh you know velocity information or security coverage information uh it's all based in standard open metric format so you can pull it into any tool you want to get that kind of designation but just to kind of show you is is that what we do is we provide that end to end from the curation aspect at the developer level we even have things like our ID plug-in uh to make sure your developers can address it where it matters most where the ROI is greatest if you try doing it in production by the way it's 100 times more expensive to actually fix than it is at the developer level we also provide levels of remediation we are a CNA so we are a cve number Authority so by providing you with remediation information it allows you to attack it quicker and we can provide this information up into servicenow on actionable change requests so you can actually go ahead and say I want to review any potential security threats that might be part of this and make it actionable on top of that we also have the ability to extract the software bill of materials from every build that you produce so this way you have accountability if that's part of the industry and it starts off with the government and it's worked its way up into other Industries such as medical uh fintech Aeronautics and Aviation and multitude others it's becoming a standard and the thing is that we built this compliance mechanism end to end in the system now we I told you before how we can maintain and manage the binaries that you're looking at and make sure they're secure and compliant and not operationally at risk but we also just recently introduced new features one of them is infrastructure as code scanning which you can actually publish that information to say maybe you're using something like terraform to configure your servers and maybe there's an issue with the version of the template you're using to deploy it we could also detect are you accidentally exposing any secrets are there any secrets inside such as keys and others that might be you know something you don't want to have on these production servers just in case we also could tell you there's any application or Services exposures you know maybe there's a service that's running in the background that actually something you don't want to run will let you know that there's something there so you maybe you want to turn it down so you can get some better performance operationally maybe in an operating system or maybe there's a service that's just sitting there with a port open waiting for a connection for no reason and you're just inviting an attack now the thing is is that we can tell you where those issues are and how they are but also too when it comes to things like cves where there are malicious components you know with artifactory what's nice is an x-ray is that we can tell you yes you're being affected number one number two we could say oh by the way it's in this bill number three here's the blast radius of every bill that it's affected if that component is used in multiple now we have contextual analysis and contextual analysis Narrows the focus on the issue at hands and tells you is this CV applicable or is it not this saves you time and Remediation because now instead of having a broad scope and having to research where it is you can actually now dive into the specific component in which you actually want to enact the change now saying that and having all these components and being able to match your sdlc and manage your binaries from end to end where does the service now integration come in and this is where we're heading so the thing is is that we will provide this in a level of a Spoke integration right so be able to do things such as do user Management Group for management permission management inside the artifact you know the entire jfrog platform you can also go ahead and manipulate uh binaries that are inside of artifactory since this is a universal binary repository manager it's a mouthful but things like one of the key factors is is that everything in the artifactory component you know in our in our actual artifactory product is based on metadata so you can increase metadata properties key value pairs key value arrays you can actually look at items and artifacts you can pull information from it and actually publish information back into artifactory and vice versa some of this stuff is bi-directional and you can also do repo management whether it's it's you know being able to look at a repository get you know what binaries in there its size you know lots of different things behind it but then you get to the X-ray portion of our product so you can get scan results Associated to a build so you know you know Associated to a build so you know what issues might be in there in terms of of you know potential binary threats also too watches and policies and rules which is the way you detect and the actions you take based on the criteria you've defined in terms of your evaluation of those binaries and at the end of it also having things like records and summaries you know we the ability to actually get us a component analysis of the software that you're doing similar to a software bill of materials but also being able to get a build summary so you know everything about it how was it built where was it built were there any environmental system variables that were set during it such as debug Flags don't get me wrong going to get me started on how many people have left debug flags on when they've done this but the whole idea here is is that the tie-ins into this as the base of the actual devops Foundation them you know all these companies use having that Administration layer on top with servicenow now gives you the ability to have that communication that symbiotic relationship between Administration and operations and some of the things we'll be doing going forward as part of this in the use cases we'll be addressing you know once again build promotions being able to build in accountability options here where you can go in and actually you know approve uh promotions from one phase your stlc to the next you know being able to go ahead and manage groups and and that they're you know and permissions at their levels the ability for x-ray tracking right track violations and and see how artifacts are you know the any sort of accountability behind those artifacts in terms of violation nefarious means license compliant operational risk whatever and also to be able to actually create rules and policies eventually so this way you can adjust it based on your corporation's needs and at the end also too giant approval workflows that will be integrating over time such as license compliance security violations user and group management build promotions right uh being able to add and you know maybe Block in a libraries that can't be used and then lastly also we have this concept of projects um which is like an R back style control mechanism inside of our platform and being able to control that too go ahead Isaac all right Aaron go ahead and cue up these uh these next rounds of questions as we as we go ahead before we get started on that just a quick summary a recap of uh how you answer the first questions we have representation across all these different roles which is great so hopefully everybody can take away some from this session and um and from what it sounds like you know if you have even if you have a small number of teams organizing those teams and centralizing that information is going to be important so um yeah just wanted to share that with the folks and we can launch a few other poll questions we'll get the demo queued up all right first off let us know if you're both your customer of both jfrog and servicenow let's be exceptionally relevant to you if that's the case and we'll give it a 30 more seconds here [Music] [Music] all right this will help us um figure out what kind of information we need to send you when uh when we contact you for further support here so thank you for that we'll go to the next one um if you can tell us where you are in your devops journey [Music] foreign [Music] we'll give it about a 15 to 30 more seconds [Music] we should be talking about you know sorry there we go go ahead and share these results so we've got again a heterogeneous environment which is perfect for this kind of solution Isaac bill you have any comments on that yeah this is uh pretty pretty typical uh answers here um it's basically split 50 50. where there's a solution in place versus somewhere in the road map that's that's helpful thank you we can send you out the right kind of information for that and then this last one will also relaunch at the end um you know let us know if uh you'd like to uh have have one or both of of our um uh teams contact you after the event okay so we'll go ahead and um get started with the demonstration but real quick here to give a give an overview what are the outcomes we're looking for as we show this solution think of how this benefits the Developers think of how it takes tasks off of their plate think of how it improves the efficiencies of devops and the change management process especially as there's larger amounts of volume coming in I think of things like governance making sure that there's checks and balances in place between jfrog and servicenow also um there's there's configurations that may not be acceptable right do you have american-based data being housed in a European database how can you set up the devops solution to monitor things like that we're going to show you how we help you with governance operations support all the way up to the VP of app development there's just improved visibility we really hope you see that out of the demonstration today and that's one of the key things man I really think about this idea of the two of us working symbiotically together because some of the biggest complaints we got from our customers is is that you know there is that aspect of disparity between you know the two organizations but the thing is is that you know one of the things we should probably also talk about Isaac is the fact that not only is this an accountability play right between the two and being able to organize it and also expedite and increase the velocity but you know the thing is it could be real time you know the thing is as these you know things happen it's event based so it's like you can actually you know you know you can inform like your release manager that there's a new build available for their approval you know if something fails you can notify AI uh immediately of various aspects there's some notification Tools in our product that also tie into servicenow so that you know the faster you can remediate the faster you can expedite going forward so the thing is is that um you know I think we have the demo after these couple of slides um but I'll let you talk through these and then we'll go in and do the demonstration which I'm excited about yeah absolutely so think about what what pipelines and applications you want to monitor as part of this devops solution customers that we talk to have anywhere from a couple hundred applications to 5 000 applications so are all of those going to be partaking in the devops solution maybe not so start the ones in incremental approach of which pipelines and applications you want to monitor first and of course build out efficiencies from there and also you'll see we we encourage a self-service approach here to doing the implementation it's it's really not an implementation it's kind of a quick start guide and you'll see that in uh in the demonstration today as as I wrap up we'll give you a call to action how can you get started from the servicenow side if you are an itsm Pro customer there's no additional licensing needed if you have itsm Pro everything from the servicenow side that you'll see today you already own so we really do encourage you to get started hopefully that's uh your next step after you see what we show today I can move forward oh you're you're going to see um insights so there's there's definitely reporting that you'll you'll get instantaneously as soon as this as soon as you start your your devops journey and you'll we're also going to get into change creation and showing you how that change can be automatically approved okay that's kind of the call to action but we'll move oh there we go there we go so yeah again we do want you to we do want you at the end of this webinar to uh to get started there is a self-service approach to starting this Implement to starting this devops solution and uh we're going to give you links and some tutorials just as reminders to help you get there and just let you know by the way if you are if you are interested in jfrog just go to you know jfrog actually or just go into Google and type in jfrog uh free tier there is a free tier available or if you'd like to do a full trial of some of our various offerings that we have just go there uh you know you can either choose to have us hostage host to yourself like I said we have a free one where you can play around and practice but there's many different ways to get involved uh with the jfrog in this and we can go forward with it so now here comes the fun exciting bit the demo time so I'm going to let Isaac take the helm hold on okay all right all right Bill are you able to uh to see my Chrome browser I am able to see your Chrome browser I am there we go all right let's give let's give it a go we're gonna go so just just remember um we're agnostic here uh bill and I decided to use Jenkins as the orchestration Tool uh most a lot of our joint customers are used to it but if you're on any other type of coding pipeline orchestration tool what have you just remember that the solution will still look the same we're agnostic in that sense so I have some code as a developer that I've already committed and I want to go ahead and build this pipeline so um it is building now and you can see the status is is kicking off as as it begins its build so now just so you know there is a a Art Factory a jfrog plug-in actually inside of this Jenkins instance because we have one you can either use the actual you know extension that we offer or you can also use our jfrog CLI I have plenty of webinars based on some of the talks I've given around that and in this case by the way remember we're going to manage those third-party transitive dependencies and the builds you produce so you can actually pull the dependencies that you have and then publish your results uh back into artifactory and then have the corresponding data show up in servicenow which we'll talk about in a minute so while this is actually building uh we can actually go into probably bring up jfrog and actually just really quick and just kind of show what the interface looks like right so if you take a look in here we're actually going to go ahead and actually if you go over to the one that says artifactory on the left hand side there expand that and actually go to builds because that's where we're going to actually doing our work today and if you look there's the servicenow jfrog demo so if you click on there you can see the latest version of the actual one that was being implemented to the right of that you can see the CI environment which it can't it comes from and the nice part about this is I actually as you can click on that link it'll actually it'll actually bring you directly back to the actual bill that's produced it and inside of of Jenkins if you look there's actually a a button that says go back to artifactory right so it's a it's a Sim it's actually a bi-directional link if you go back it's jfrog for a second while that's continuing doing its build you can also see that there's a critical status this is letting us know that there's issues that are in there and if we go back and let's see where we stand by the way in the uh Jenkins build let's see what it's doing okay so right now it's doing a quick scan result so it's actually going to go ahead and which build does this one's build number 18 correct 18. excellent so if we actually go back to jfrog while it's finishing you can actually see where we've already detected some critical issues on the X-ray status and if we can go in right now go select build number 18 if that's okay with you you can see that there's actually we've already uploaded the artifacts so if you click on the one that says servicenow jfrog demo under module ID if you look in that that row right there you can actually see if you click on dependencies in this case we actually published a dependency uh sorry the middle line right there and there's the one we did now if you go click on the X-ray data this will be the fun exciting part this is actually a jar that we compiled and what's great is is that we can show you uh like all the violations and you know that are in there or the security threats if you could please click on security for a second and let's go click on that first cve there that's that right there and that will bring up the information where you can see that there's a critical severity in the component that you're doing if you click on the source advisory uh that second tab right there and you expand summary in the description you can see this is your standard actual information you would get from a cve most of the time let's be honest those cves are not that detailed and there's not a lot of information in them but if you click on the one that says jfrog research uh the tab next to it and you expand the summary we give you a little more precise uh consolidated one if you go into the detailed View you can actually see where we've actually given a level of research behind it why like I said we are a CMA and we're constantly providing cves but the next tab down there where it says remediation right below actually details we actually tell you what you need to do to fix it and then right below that where it says reason we actually tell you the justification why we did it now if you click on the impact path we also tell you exactly where this is inside of the jar and we also provide the reference materials um to it if you close that X really quick because the scan should almost be done click on licensing for a second and we can actually show you the licenses that are actually in there expand that one out uh and you can see all the license files that are part of this so from an accountability aspect if you scroll back up please you can also see operational risk this is what I just wanted to show really quick and then we'll go in and see the integration but this is letting you know the health and the and the validity of those open source projects that are actually pulling it down now in this one we don't have it but if you look there's a tab in this build browser portion that says release history and that's actually the corresponding information on where you actually can go use arbitrary data with our API and have every phase of your sdlc spelled out so let's go see if that build's completed I believe it probably did at this point yeah all right there we go and it fails because it had a lot of criticals well let's go take a look at service now right should we go take a look and see what happened let's go ahead and see the pipeline itself so over on the servicenow side we are monitoring that pipeline from Jenkins there we go open this up and at this point notice there is a change control set to True these are a representation of the stages in that pipeline that came from Jenkins so upload download and then X-Ray Scan was the stage where we have told servicenow activate Change Control once the pipeline gets to this particular step so I can go ahead and click on click on that and we see there's an orchestration task let's dive into this particular result here and you see all of that information coming on underneath of your step executions it took two minutes and the state was a failure state let's let's figure out what happened and why this was a failure all right so back on the Jenkins side I'll click on build 18. and the output when I scroll down you see here it created a change request within servicenow this is where that automation that servicenow and jfrog has with these orchestration tools in your piping pipeline encoding tools to be able to essentially pause and grab data pull it into servicenow give you a change request and then all your standard Change Report process is going to flow from there so we're going to open up this change ID inside of servicenow so I'll go ahead and just quick Copy and change oh it's right here so sorry so just to just to verify so this one is three zero zero nine nine and you can see here the change request that was generated is in fact three zero zero nine nine all right so let's go ahead and open up that change request and we'll see what it looks like on on the surface now side okay so as we scroll down we can see here's the artifact versions that were pulled in okay and over here here's the software quality summary we pulled that in from jfrog as well and these apply change policies that were applied to this information because we did allow a decision to be made the approvers is telling us that the devops system made the decision to reject this particular change process why was that so let's open up our change policy and see why this was why this failed when an orchestration tool like like Jenkins creates a change request we've got policy inputs that make up decisions these policy inputs are a combination of data coming in from different sources so we've got number of outages in last seven days that's servicenow data we want to check your cmdb are there any critical Ci's that had a P1 or a P2 incident in the last week right code security Test passing percent systems like jfrog bringing their data in so that we can create more policy inputs not just servicenow's data let's go over to decisions so out of those 13 policies policy inputs we can make three different decisions and my instance it's it's a little a little bit straightforward but we've got an auto reject Auto approve or basically a bucket where it was not reject rejected or approved so let's let's take a look at the auto reject and we had a simple condition in here if jfrog code security had any critical issues immediately is going to be rejected so this right here is a serviceman workflow pulling in that policy input from jfront they Auto approve is a little bit more robust so let's take a look at that what that auto approve would look like so code coverage greater than 70 number of outages zero code commits we don't want to have more than 50 code commits that's you know just a policy we've created as an organization so these are these are the uh policy inputs that would give you an auto approval um so hopefully that that makes sense uh to everybody and and what we've done there one things I'm excited really about is like I love the fact that like I said you know you can follow the path of a build especially the tie-ins where you had some of those you know change requests and change management and you know be able to like approve a build and promote it you know based on its results and all the metadata we could Supply with it's amazing I love it real quick there's an example of more data that we can put into your change requests so here more context is given uh when we're pulling in information from systems like jfrog and we can give you you know the security rating uh we're also pulling in from others uh from jfrog x-ray looking for violations I've also got sonar Cube running on this instance and even your your budget for your planning can be included as part of this change approval process rejecting it or approving it the call to action from the servicenow side we'll send these links out there's um if you're an itsm Pro customer you have this you have these capabilities available to you from the store the e-servicenow store just type in devops do a search and sort of the the parent all encapsulating would be the devops change velocity this includes the data model the Integrations necessary to run the CI CD tool chains and making sure that communication goes back and forth and then once that I'm losing my tabs here once that's available you'll have also something called the devops change workspace this is that guided setup this is the call to action if you have itsm Pro go to the servicenow store install devops change velocity from here this is where you set up the devops system account it walks you through that this is where you connect tools it walks you through that how do you group the applications together so if you've got a different planning tool and a different coding tool in a different pipeline tool we want to make sure that the grouping matches up and servicenow knows what data to track really quickly here connecting to a tool is is a quite a simple process you get a category first once it decides to come up here we go so is it a planning pool is it a coding tool is it an orchestration tool is it an artifact software quality summary so I'll go over here to orchestration um Jenkins is what we use today and so at this point it walks you through do you have a personal access token the necessary credentials and then what pipelines and stages do you want to start monitoring so really definitely go and start the devops change workspace it is meant to be uh self-service and it gives you access to start using uh devops solution right away excellent all right all right then to the bottom of the hour so um if any would like to stay on and ask any questions um our our host will be available for a few more minutes and also um if you'd like to be contacted after the session let me go ahead and relaunch this poll and feel free to respond um in the affirmative either way and uh and someone will reach out to you and give you some more information about where to access these Solutions um you know the the other details on the content will be posted to the webinar link as well but we can always follow up with those personally so um gives you an opportunity to maybe ask a question if you don't want to ask in the session anything like that so foreign thank you for your time everybody and I really appreciate it yeah we'll be sending out links to make sure that you um you see the the self-service um information and documentation that's available and servicenow uh Isaac guys I really appreciate uh you having me here um you know this has been an exciting Journey so far uh behind the scenes working on the stuff looking forward to uh you know helping companies that are out there do their jobs more efficiently uh you know now within Administration side behind it excellent you know this is this is going to change people change the game a lot for a lot of people um but thank you so much have a wonderful day everybody be safe be wonderful be well from our side likewise thanks to the J for our team for helping us put this together uh I think it's been a really great session and I will hope to uh do more white content in the future so really appreciate it everybody so we'll hang for a couple of minutes if you're all done feel free to drop and you'll see it for the next one excellent

View original source

https://www.youtube.com/watch?v=jFZjUfhDspg