ITOM Visibility & Governance Webinar Series: How to Accelerate Cloud Provisioning with CSC
right so I guess we can get started good morning good afternoon or good evening everyone and welcome to another session of live on service now webinar specifically the item visibility and governance webinar Series today I'm back to my place back to hosting these sessions after Steve stepped up temporarily last time I hope for everyone to joined last session uh you guys enjoyed it I had a look at the feedback it was great so today we have another a very very important I would say a Hot Topic to talk about which is cloud provisioning and specifically our new product there's going to be cloud services catalog now before um talking about exactly these topics I wanted just to remind you that again this webinar is part of a live on servicenow webinar series which is a very interesting set of serious of events dedicated to speed up the deployment of our products or the adoption and in general I achieve value faster with them you can see here the QR code that you can scan in order to um to join and to subscribe to this session to this series otherwise we will post our link on the chat afterwards so a few housekeeping items for us for today so please make sure that everyone is muted and please use the Q a feature to ask questions throughout the session and especially whenever you're asking questions we'll really like to know who you are so uh please uh feel free to introduce yourself and we're gonna also have a couple of polls for today as we typically do have in the session so please keep being engaged as you did so far um also this session is being recorded and you will find it in the same page where in the community the dedicated page to this event where you can enroll yourself so for any references you will find not only be recording but also the deck of what we're gonna present today also a very very important thing after this session ends you will be prompted to a short service so please do fill it out it's very important for us to get your feedback and so let's get started with this now for those of you that don't know me my name is John marital Luigi I'm part of the outbound product management team for item and I Do cover specifically item visibility and item governance even if we're going to see later uh we're gonna shortly change the name of autumn governance and together with me today we have the Superstar guest which is RAM and RAM you can introduce yourself very glad to be presenting once again on the cloud provisioning cloud governance story um between me and John and Steve here we are highly excited frankly with the introduction and the Workwear that is coming up as part of the broader play here called Cloud accelerate which you'll hear more of as we go into these additional sessions in the future but today the focus will be on cloud services catalog and I'm happy to demonstrate it after Jan finishes the initial introduction that's great thanks a lot Ramen thanks for mentioning again Steve Emerson is also attending this webinar he will be helping us out to answer all of your questions so please don't be shy and you have great support for today so before we proceed with the slide just a safe harbor noise for you in order to give you the full picture of what's coming with CSC IGA and you want to understand a little bit why I'm talking about a CSC IGA and we'll have to make some forward-looking statements and talk about the vision that we have in terms of cloud provisioning Journey so please don't make any purchasing decisions just based on what we'll talk about today now let's start with a few slides to give you a bit of context so why are we talking about cloud provisioning in general so we all know that the cloud digital transformation is happening and as part of the cloud adoption Journey there are several digital imperatives that companies have to adhere to specifically we individuated three main pillars and these three main pillars are the scale one which refers to offering a frictionless self solvers experience to the actual users of these cloud services and resources then we have the shift left which is really concerning about the security that is then embedded in the cloud services workflows and then the automated so in general during this journey it's very important to simplify the different operations regarding all the different transitions into cloud or the cloud adoption journey in general and today we're going to focus on the very first pillar that we sell there so on how to scale the club processes with the servicenow item Cloud accelerate and this is the first formal looking statements and let's say they were menstruating today because item governance and or you may have heard of item optimization this is the plan that we have to transform everything and have a unique skill which is going to be Cloud accelerate which will cover the whole journey that we see here so the cloud adoption Journey as we mentioned before conference with different stages but specifically when we're trying to scale the cloud processes we can integrate three main we can say days or stages of this journey the first stage is the configuration stage where we actually have to decide on which applications they actually migrate to the cloud or not and also to create the different Cloud accounts or the different policies Associated to those accounts and manage those Cloud accounts in whatever Cloud providers that we want to choose then after that we have the deployment part so the actual creation of the cloud offerings catalog that then can be used from the requesters but also manage those requests so we'll have the actual requests that are submitted and the resources they will need to be deployed based on those requests then the third part which is the day two and we call it manage is the part where we make sure to configure the security and governance checks and to apply them to all the provision resources and also perform the day-to-day operations on top of those resources well we have a view our servicenow clearly has a view of covering this journey and for each of those stages we are including with a cloud accelerate as we mentioned before either we are including right now or in the future specific um products or specific features that are going to help you address each of these challenges for each one of these days of course each of these products that you see here are gonna cover it potentially not only one but multiple of the steps that we see in this specific slide but for today um it's very important to understand that the view is to cover this whole journey and of course beneath that we have always the support of the servicenow platform which allows to discover all these resources and to manage them and to populate the team to be in a very centralized and cohesive way Focus for today's webinar is as we said before the cloud services catalog which is already available in Innovation Labs actually with two different releases in May and August so you can try it out in your non-production instances and will BGA soon so but what is cloud services catalog well it's the perfect tool in order to first of all automate the cloud services requests process so whenever we have the cloud services request and the related processes cloud services catalog allows to manage the the whole journey that is behind it specifically it allows to reduce the collaboration in time which is typically a big very big pain point in many different organizations and it does that thanks to out-of-the-box content and also automated policy checks to make sure that all the provisioned resources or even the requests that are arriving about provision resources are complying with the company internal policies then we have the part of managing all the different requests and the different provision Resources with a very simplified UI because all the different existing tools are a very important part of the requested tools let's say that we receive from our customers is to really have a simplified UI and in a centralized manner then we have also the advantage to create different catalog offerings in a very fast way in a very quick way and then this is done for the automation needs as an example for infrastructure as the code repositories but we'll see the details later what I really wanted to understand make you understand here and I see a raised hand so please make sure that all the questions are asked via the Q a features um so it's very important to see that even for the end point perspective if so if we're thinking about how to address all these requests inside the company for cloud Resources with servicenow we can even make sure and this is something that comes up often with customers that the only requesters are the ones that actually went through the proper training in order to be skilled and actually have all the knowledge related to the specific resources that are actually provisioned so we'll get to that in a second as a matter of fact we wanted to introduce you to the overall Vision that we have for cloud services catalog so the different stages for cloud provisioning are starting from the left side of this Slide the actual creation of the different Cloud offerings right now as I said we not only have out of the box and as of innovation lab release for some of the major Cloud providers such as AWS and Azure so you don't even need to configure them necessarily um out of from scratch but they are already there but also will introduce the capability of leveraging the existing templates so the cloud resources templates from the actual Cloud providers and bring them in in the centralized cloud services catalog then there will be there is already the possibility of Performing infrastructure is code Discovery through the repositories we're talking about GitHub and gitlab primarily in order to then create the catalogs from what has been discovered in terms of IEC codes then we have the cloud provisioning part which can be done in different ways so if you have the if you're leveraging the automation tools there is and there will be support for leveraging terraform or ansible in order to provision resources from the major Cloud providers we're talking about not only as your Google cloud in AWS but also VMware and also Oracle cloud and then if you prefer instead to leverage devops Pipelines as of il-2 we have support for Azure devops but also support for Jenkins will be introduced and then if you rather prefer to leverage Cloud native templates we offer apis that connect to um these Cloud native templates that can be used in order to provision uh Cloud resources directly in the cloud that you want to choose primarily you can see here you can leverage as an example AWS cloud formation or other types of templates so now that we talked about the different provisioning flows and different provisioning approaches uh that are also since we're again as they said before we have the full support of the overall servicenow platform we can perform Cloud discovery on top of what has been uh just provisioned and then we can go ahead with multiple use cases we can monitor the events and logs and traces or in the future will be able to monitor the cloud costs that are related to those resources and at the same time we always have the possibility to create uh policies that are applied either before or after the provisioning itself so before the provisioning is to automate as much as possible the approvals and after the provisioning we have all the policy checks in order to make sure that we are compliant with the internal policies that have been established inside our company with all this we can perform day two actions and remediations and many many many other things simply um again from the same portal and uh really having this cohesive flow that starts from the very beginning of the creation of cloud offerings until the management of the provisioned ones so this was a generic introduction to our vision and before we transition to the actual demo of what we offer I wanted to start with the first Poll for today so which Cloud automation approaches are you currently using in your company you can select all the different ones that you have and in case you are using different Cloud automation approaches please make sure to include them using the Q a function we uh it's very important for us to have indication if we have um if you're using other automation approaches and we'll definitely consider them for feature references I see a lot of views are inputting different many interesting answers so please keep filling out this poll and I'm going to give an another few seconds here so we can have most of use participating to the poll and after 10 seconds and we're gonna see the results so five four three two one I'm gonna end the poll now and we're gonna see the results before our demo so it looks like the majority of views using CI CD release pipelines such as Azure devops and we're talking about sixty percent followed by 53 percent when it's using ansible forty percent are used using terraforming 25 that is using Cloud native templates this is very interesting so thanks a lot for participating in the first poll I'm gonna stop sharing the results and I'm gonna hand it over to you ram thanks again John um great introduction uh really appreciate all the questions that have been posed I tried to get a hand at a few of the um questions already uh we'll keep filling in our replies on your questions so keep bringing them in I really appreciate the interactive audience that we have today let me go ahead and share my screen and start with a few things that we want to demonstrate today uh so as as John mentioned um you know we have multiple ways of provisioning what is the intent here over and above everything we want to enable you as servicenow user servicenow it teams um to let me say centralize automation centralized and govern uh Cloud automation right and and of course when I say cloud I I refer you know in a broad sense I'm not necessarily referring only to the public Cloud VMware on-prem is also you know very much in the play here very much supported um so let me start by going over a very basic um uh you know workflow uh approach or a catalog item out of the several out of the box catalog items here so what you see in front of here and I hope everybody is able to uh you know see the see the see my share here um we are actually providing several out of the box huh catalog items categorized under uh infrastructure as a service platform as a service there's things around functions there's things around uh databases and stuff like that dynamodb and all that so AWS Azure is what we started with now does that mean that we don't support other clouds No that's not right we do support other clouds because the underlying workflows the underlying Integrations that we have allow you to work with the Google Cloud uh Oracle cloud and also the VMware we started with database and Azure being the leaders in the market obviously right so from that standpoint uh you know that's that's where it's coming where is what is what is this new UI this requested portal is the go forward requester portal um from a servicenow standpoint the service portal which you all have been using or are familiar with is being replaced and uh we move towards the new portal called the employee Center and employee Center will be a place where you know your HR your risk and your planning and everything can kind of fit in together under these these areas this this area which is called as the mega menu and in the mega menu we added cloud services here so that as you as you as your employees and your organization come to raise their typical tickets and requests for Hardware software and all that for office use for their development and other users they may go into service categories under cloud services or specifically request for database they may specifically request for uh you know something around devops and integration and all that stuff right the intent behind the demos today is to give you a better perspective on on each of these and and and with this new UI we're also giving away um you know your need to hold on to the old C PPG cloud is a portal UI in a way this also is the movement away from that Old UI we also introduce new pages into this my stacks and my resources we'll talk about in a minute here right let me start with the deployment of you know a while we have a lot of stuff here I want to quickly show you uh what we added in the August release the beta 2 as we call it uh The Innovation lab and in The Innovation lab we added support for Azure cloud we added support for Azure devops integration also which I'll show right after this um and that whole story is a very interesting story of uh how we are tying in the devops cicd pipeline with this but more about that later the the catalog item again is meant to be more of a template or an example for all the other catalog items here I see joby's hand is up for a long time maybe you can pause your uh question in the Q a and we'll try to help you there I'm trying to rush through a little bit of the demo uh so folks um back to back to you know uh you know this Azure Linux VM deployment here again we have gone with the basic vanilla catalog item uh in terms of all the options that need to be derived here when you take this to your employee base and you want to show them uh like how to go and order something from um you know the servicenow catalog you may want to consider how to improve that experience so that only very less fields are actually posed to them right I kept this the way it is we have kept this in the product out of the box with all the options there so that you get a sense of you know the art of the possible here and I'll lead you through that in a minute here to start with um you know you can order the Linux virtual machine we put in some controls to say that um basically you want to put the agent if it's a production instance so obviously we went with our own agent call as biased whatever but we will go for our agent right so ACC is compulsory for the production instances again out of the possible think about how you could replace this by pushing uh whatever monitoring agent you're using or some other Asset Management agent that you might be using there again we would love for you all to be part of ACC then your out-of-the-box flow is also ready here and as we go further we'll also add more content to support other other tools and all that but yeah bottom line is ACC is compulsory VM sizes other than standard A1 V2 and standard A2 V2 require approval and we'll see how that pans out if I order something else here I'll be cheeky and actually order something different here and we'll also run a cloud config scan at right at the end here okay so I'm going to go through and as a as an engineer I'm going to say um yeah I choose East us here I I choose the application that I'm working for here pet store whatever something like that and then I choose the cost center no questions here engineering so no faking or anything so let me just put it on some business service here and and then I choose the the user group uh to which the stack should be assigned to so that in case I'm not available somebody in my group can also handle that stack and it also benefits from the quotas that are actually put in there some very interesting things that are present here in terms of uh the environment I can Market is Dev test and prod right but if a market is prod the install ACC is is mandatory like I mentioned about that's just the control that you put in place there but if a market development it's it's optional I can choose not to deploy the ACC there let me just go ahead and and add that in right and uh the the lease end date is a great example of a policy that we use to terminate certain VMS that have been uh set up for a particular period of time the lease basically right so by default we said the policy that the lease should uh well hold valid for all Stacks uh uh for all these deployment Stacks right as 90 days from the date of deployment so that's why you find that the lease end date is exactly uh you know uh you know 922 uh from a Los Angeles time zone perspective uh right 922 on the 18th of December then 90 days from now so uh we can extend this and uh if we don't extend this after 90 days the the stack which is the set of objects that are deployed as part of this request they're held together by a stack which is a CSC servicenow construct and that stack uh when it gets deep commissioned deep provisioned completely right the resources are already taken off the billing and all that which is a cool cool thing if you look at it but sometimes you want to extend it so you'll be sent a reminder a week before on that and you can actually extend that as a as a stack owner you can you can ask for an extension there then we have uh certain uh Linux distributions we go for the latest release of these distributions in all cases as per this uh the way this catalog write them as a instrumented and then let me choose you know to provision in a new Resource Group and when I choose the provision and a new Resource Group instead of an existing discovered Resource Group that's in cmdb we actually give it a name and that's the stack name followed by hyphen RG here that way it's all it's all correctly tied up there and I'm going to choose something again interesting where I am going to choose a standard A3 size remember A1 V2 and A2 V2 are the only ones that are pre-approved A3 requires approval so we'll see that experience of how that how that works out here uh let me go ahead and choose certain networks here ideally and we worked with this uh with a couple of our recent customers with whom we've been doing uh very detailed uh pocs and all that ideally what should happen is when when somebody when the engineer comes and chooses the application name uh for which the development is requested and let's say they choose the environment right the application name combined with the environment is a very good indication of which network to use right so that can automatically be set up there again it's a small um sort of uh scripting that needs to be put in place uh client rule if you may uh and and that client will will take care of ensuring that uh the engineer is not put through the sort of uh you know a lot of effort to find the right networks and all that it'll be automatically chosen for them that way again you're restricting them to the right uh you know security limits and all that stuff I prefer to choose the authentication method using uh using a standard password and all that I'm going to give my choice password Here uh yeah I think we're good ACC uh for the credential Alias for the mid to deploy the ACC and and and the last one is the is the is the interesting set of things that you can do with the policies to scan this if you remember the image that uh John presented earlier we are talking about an end-to-end provisioning the the pristine Immaculate Enterprise deployment if I put it that way the the that takes care of uh bringing in the security checking Hardware checking conflict checking it's bringing in so many other controls here like Lee's and stack naming and all that stuff right everything is brought in here so uh here what I'm trying to do is I'm going to do a hardware type check to see whether it's a it's a valid Hardware first thing I'm choosing a non-approved hardware uh so I need to go through approval and once I choose the approval it'll also run an additional Hardware type check to ensure that it's all fine there right so let's just go ahead and order it and uh you know we can uh we can wait for the deployment to to to get started there right um but some couple of interesting things will will potentially happen here as you can see a task comes up here um uh we'll see what the task is actually saying the task is actually saying uh an approval of the request is needed um now normally I would be placing the request as an engineer and then my manager or the admin will be given the approval request here in this case I happen to play both roles uh here so right I'll just go ahead and uh I'll I'll obviously I'll have everything in front of me I can as a approver I can go ahead and take a look and say okay everything looks fine it's valid image valid size and all that okay let's go ahead and approve it and once that gets approved then I come back as my original Self was a requester engineer and let me go in and take a look as to what's what's happening here yeah there you go it just starts and the the provisioning is happening here now what's happening in the background here is pretty interesting right this catalog item is out of the box catalog item with a backing terraform template right we decided to go with terraform it gives us the flexibility to work with multiple clouds and uh you know it's also just based on our experience here it's been the most popular of all the templating sort of Blueprinting kind of uh infrastructures code approaches right so we chose to go with terraform and what's happening in the background here is the inputs that I passed in the form they're getting assigned and passed in as payload along with the terraform call itself right so I'm interacting with terraform open source in the back end here we support also the commercial versions of terraform both the Enterprise and the cloud but uh we're we just go with open source here as simple starting uh starting point Here and Now what's happening is the interface operation calling an execute command is actually calling terraform in the in the back end here and that's um just just simply going through there in the meantime I can go in and I can actually took a take a look at the stack view I I mentioned to you a little earlier about uh two additional views that we've added into the employee Center the portal view where we are talking about my stacks and my resources uh my stacks is where your deployed Stacks which you're deploying from servicenow are are going to appear here so while while we wait for this to proceed I'll take a minute here to show you the mystax view wherein I can see all my previously deployed Stacks not just owned by me but owned by groups and anyone uh primarily because again as I'm admin here but if I have a non-admin regular user I just see the stacks I own or the stacks worst case the from the groups I own here but uh again as admin I am super user so obviously I get some advantages of that the the the again I'm waiting for this the stack State still shows processing here if you notice uh it's it's a short while back I just deployed it if I go to my resources here this is actually quite interesting because my resources allows you to work on discovered resources it need not have been deployed from servicenow um between my stacks which you call as the Greenfield operation and the my resources which I call as Brownfield operations right you your cover basically you can pretty much take any resources that have been discovered and brought into cmdb and by the way the VM is also got deployed now I just see it now so uh basically I can I can go into the VM though it was deployed from from our end you can you can basically see a lot of interesting uh activities and actions that can be performed performed on it okay so it's it's just coming let me go back to my stacks here it's a little bit slow to load I apologize for slowness in my instance here sometimes the instances we use internally for testing purposes can be a little bit slow they sometimes run on very uh you know especially when it comes to reads and writes they can be a little bit because they are running on Docker containers and stuff like that obviously servicenow will not will not give us very beefy instances we have several thousands of instances running inside there um we can take a moment and pass to see if there's any questions here uh while I'll load the page there any questions that need answers that we can discuss live thanks Ram we had actually a few questions that were very interesting so I am trying to answer most of them um specifically um someone was curious about why cloud services was not included as part of the I.T the menu in the employee Center you want to clarify for everyone's attention distinction sorry I didn't get the exact question there yeah if the question uh was related to how we structured within the employee Center portal the cloud services in particular the top left of the page so why is it did we create a dedicated menu for this we created a dedicated menu that is right the reason for that primarily being that there's so many categories that we can look into so if I if I if I bring it up in a minute here right so if I go here there's uh infrastructure as a service where our Linux VM Windows VM you know all these capabilities all these catalog items are there the pass is basically a platform as a service kind of a capability wherein we fit and typically uh databases applications uh web apps scale sets and things like that that's the platform as a service it's one layer about pure infrastructure right your infrastructure could be your network and VMS and stuff like that whereas the pass is more of the application platform uh you know kind of an idea there or even the middleware platform as an idea there uh and then other categories for Less Linux and windows and the devops and the Integrations basically lead you towards uh you know our Integrations that we are building towards uh Azure devops and other things so that's the way this has been structured here it's a taxonomy it's subject to your your changes in fact you can build your own taxonomy uh in in conjunction with this or even expand this further totally up to you here okay so that's one question sorry go ahead just yeah so we have if you can clarify how uh because we have questions around csdm as an example how are stocks represented in the cstm model the stacks basically I'll show you in a minute what a stack is it will become more clear the stack is used to hold basically the resources that have been deployed here it'll become more clear when I go into that so I'll hold that for now um any other um okay I think there's a couple of other questions about csdm and all that let's go through this and and we'll take a look at it real quick here so yeah let me let me start this by create it on top in the most recent one and I I see right away uh the deployment that we did just now so when you look at it the deployment is completed okay we've been through a few steps here an interesting set of steps here first is the execute command which was going on for a while that's the terraform call that that goes out there and as soon as that completes it actually uh runs several Discovery steps again going back to the image that John presented earlier we take into account that we want the resources to be immediately added into into service now there so as soon as and when the resource deployment completes if I go into view dependency you can actually see the actual cmdb resources here right I'm going to answer the stack question in the nunity when the dependency view comes up the stack for all practical purposes it's not part of the it's not part of the csdm right it's it's part of uh it's not a CMD BCI it's actually more of a we call it as sncmp stack right and that sncmp stack record is used to hold these resources together so what you find is actually contains a relationship between the stack and the virtual machine the Nick the storage volume and the IP address here that's basically it the stack is basically used here for running actions at a stack level you can group the stack items together and you can run a stamp uh you know a stop start deprovision modify these all these operations are available at the stack level the stacks name is tagged to these resources so if I go into the view form for the for the for the VM CI here you'll find that this tags here and the tags indicate uh the the the stack name also among other things Business Service cost center application there by the way this is great because you can actually directly create a tag based service map right out of the bat hey your tags are already in place there so whatever is part of the pet store application not just in one stack they may be across multiple Stacks also as long as you select the right application multiple Stacks resources can come together and you can create a tag based service map real quick out of it right so super cool uh user interface and super cool uh usability in that sense coming in here right and additionally of course you also see several other resources here like the East US data center to which this Associated the account to which this is associated the availability zones to which this connects and all that stuff very importantly I want to spend a minute to say we talked about the Simplicity and the operations richness that we provide here I want to talk about a little about the virtual servers related operations here right so first thing I can in this view I can see all of my virtual service related properties I can copy it all as a Json and I can use it in in some other place for some testing purpose and all that stuff uh now the actions for the virtual machine very different from the stack level operations as you can see right you have uh ways to execute a script execute a ansible job template uh execute a resize start stop deprivation and all that stuff and by the way any any API operations that are available that can be run as a interface operation here so that you can perform additional operations on that in fact uh service provider home we worked with closely that created about 60 or 80 different operations and offered it as additional value add for their end customers so this is mbid names can go it and we are making it simpler by providing as part of the future roadmap we plan to provide Gene AI generative AI based um code text to workflow kind of a use case where wherein you can basically say what actions you want for the VM maybe you want to encrypt the disk or something and then encrypt the disk might be the action call passed through the chat interface here and then it will it will go ahead and create the workflow in the back end get it approved from itsite and then push through it that's the Future Vision uh from the jnai perspective but anyway uh we are we're working on that that area there so overall you can see that you know again several actions here uh well formed and very very clear uh kind of uh you know deployment has happened here but it it says something interesting here saying follow-up is required we need to find out what follow-up is required and for that you need to go into the view activities uh and and the view activities usually the follow-up is a task right if you go to the task listing here you'll find that there's a task that's been raised here right let's go and take a look at the task the task is then assigned to the user the task is assigned to the operator group because they typically do the follow-up here the operator group uh again that's customizable inside the workflow anybody who knows servers now will understand that what has been called out is there's been an audit violation here this is the config scan that we talked about so if you're going to audit violation you can actually find that the virtual machine resource uh has the following violation which is basically the hardware type is standard A3 uh while the while the VMS is running there right so it's been set up through the Azure VM Hardware type ccg policy which is part of the other app as part of the same Cloud accelerate portfolio and uh this this can basically be corrected now operator will work on it normally what should happen is the operator will go and fix that and choose the right Hardware type and rerun the deployment and then they can basically resize to the right hardware and they can go about it um but uh you know sorry wrong for interrupting you we have a very interesting question before we go ahead so the question is do these operations go through the change process absolutely absolutely a very good question I'll show you in a minute how these operations will go through the change process here so what I'm doing as an operator right again I'm playing a third role third different role here um I I I'm I'm actually gonna be jumping in as the operator now normally what I should be doing as operator is I should fix the hardware type and move it to the right approved hardware type but just for Simplicity I'm going to close the task and when I close the task let's assume I've fixed the hardware type right it's a prude Hardware type and when I close the task what will happen here is this follow-up required will will go off and it will it'll basically be you know uh become become green in a minute here there was an interesting question about the change operations here let's take one of the operations uh here right and if I go into um you know the change requests for instance there's nothing right now right I can go ahead and um maybe stop the the VM here right when I stop the VM It'll ask me are you sure yeah I'm sure I'm going to change I'm going to stop the VM and when that app happens it'll actually go through a workflow and that workflow well among other things of course bring it down it will set the state and all those things and you can also set up such workflows for approval and all that stuff right but very importantly it'll also create the change request in the back end here as you can see it creates a change so that way you can actually okay so yeah sorry Iran for interrupting you uh just also another very important questions do we need to have ccg entire domain enabled actually for the policy to work this is again Gotham this is a art of the possible sample catalog item the CSC is going to be available as part of a product capability called Cloud accelerate where the ccg cloud config governance is also part of the story there so no additional entitlements needed there if you're on CSC so no issues there thus every catalog item need to go through a scan doesn't have to right you may choose to not scan anything in fact if you remember in the form right if I go back to the form real quick um in the form you choose the AWS form in this case you can you can leave the scans blank so you don't have to run a scan in that sense then right so from that standpoint it's not compulsory but again from a controls perspective that is the big benefit of doing servicenow right anybody can use a CLI and deploy stuff to the cloud but where's the tag where's the application connectivity where's the business service connectivity where's the change the question please where's the audit Trail nothing of that has been put in place where's the scanning where's the pre-provision post-provision step you can just put all of that into the single workflow here with a simple Plug and Play kind of an approach here right so by the way the policy sets the ccg scan I can leave it empty here and I when I press order now it won't run any scan if I leave it empty so again not compulsory there okay so let me stop here with this part of the demo uh suffice it to say that everything else mimics and looks very much the same whether you're ordering an S3 bucket or a storage account or a scale set or a dynamodb whatever it be it and you can add your own catalog items also everything is like making the same kind of an approach here right I want to jump over and quickly turn around and and show you our integration to Azure devops here because uh you know I I I feel it's very important to go over that yeah just let me log in here so the idea behind using Azure devops as a automation think about think think about think about it this way just going back to the picture John was presenting and I I keep going back to that because it's an excellent view of the vision of our deployment automation capabilities you have IAC repositories terraform cloud formation everything sitting in gate and other places and we read those templates uh whatever terraform cloud formation arm template and all that and we converted into catalog items so if you scroll down here you might actually find some additional catalog items that have been created uh here from some of those templates they're not out of the box they look at them as custom custom stuff custom catalog items and all that stuff now along with with uh you know reading the infrastructures code templates and converting and creating as catalog items we also worked with several customers who are saying uh uh but I'm most of my release pipeline operations are being run and I also saw 60 of the answers which said Ado is being used there so which is great right so what we have done here is we integrated with Ado we go in as part of the config set up the for the CSC itself we'll discover all the pipelines that you have okay so what is happening here is we we kind of merged in the concept of the stack and this resource deployment and our workflow and all the stabilities along with an automation or an orchestration that connects into your devops pipelines here right in in very simple terms we'll initiate the devops pipeline we'll let the pipeline do whatever it does what is happening inside the pipeline is a black box right we don't interfere in the pipeline there because that is entirely driven by an application team or a other pipeline owners whatever it might be right but we'll initiate the pipeline and we'll take over once the pipeline completes and I'll tell you what that means in a minute here so stack name will pass in the change request that we are connecting this deployment to the release pipeline to this is the configuration provider which is the Azure devops project that I that I I'm I'm going to connect to and when I choose that you see that the projects are listed here several projects in that in that Pro in that Azure devops uh you know environment is connected here and and and also when for that project a number of pipelines are also discovered and presented here by the way these are all previously discovered as part of our config management Discovery process much like we discovered the infrastructure as code templates and all that we'll discover these and we'll bring it in so we switch to a different uh project here the pipelines in that project now become visible there and not only that the the when I choose the pipeline the variables that are part of the pipeline itself are displayed here I can set the variables I I can I can I can create um you know as many number of different ones here so if I choose this this pipeline would change and different variables would come in here so just some for the testing purposes I've kept some here so let me go ahead and come back to this right and then uh I can I can leave it pretty much empty here my my it's a simple pipeline story that's actually coming in here this is the interesting bit where we are going to specify which is the account to connect into for running a Discovery at the end and they and we'll also mention which is the region we are connected to for running the Discovery at the end why is Discovery needed now the pipeline the the once the request is passed let me go ahead and order it in the meantime once the request is passed and the transfer of control happens into the pipeline the pipeline is responsible for that the expectation that we have from the pipeline owners is we'll pass in our deployment ID we'll pass in a subscription ID we'll pass an application name Business Service name right we are expecting that the pipeline owners will take those values that we provide as part of the flow and and and they will tag it right and if they tag it it becomes very easy for us to check on those tagged resources discover them and bring it back which is what you find actually happening here right so the CAC run Azure devops pipeline interface operation is basically processing now and in the back end it's actually calling out to um Azure devops right now I'll just go there and I can show you in a minute right so let me come back here sorry yeah it just it is going through and um in the meantime yeah let me Connect into azure devops uh to the particular radio environment that I was that I run this on if you remember uh the project was called this and the pipeline was called this and you actually see that it's it's just triggered and it's been running now 43 seconds back right it's going on and uh once that completes right these steps are going to happen there and once that completes we'll discover all the resources and uh we'll we'll bring it back and much in the same manner as we deployed from a regular template we'd actually be picking up the resources here which could be driven in a pipeline in multiple step process in a pipeline you know you don't know so many things could be happening there you clean up stuff you create stuff you you you test stuff you you run a bunch of things there steps in the pipeline but all we want at the end is the set of tag resources if they're attacked we just pick up the tagged resources and we bring back and and and we we show it as as regular stack resources so that it can be deployed there further so I'll just let this run in the meantime and uh of course it takes a minute here um yeah so let's take a look if there's any other questions that we can answer um so Gotham yeah valid question the user portal is already moved to employee center with the ga of the CSC frankly you wouldn't need to use the user portal at all uh once you start using the employee Center portal the admin folder will will be rolling thunder will be working on it slowly over the next releases but user portal definitely uh already you can move to the new portal and there's been very well received by customers there and voila your your deployment is done right and we actually have the deployed resources from the pipeline actually appearing here which is actually if you ask me pretty cool because this would have been a you know a real bottle like otherwise where you know you you might either be able to initiate a pipeline through approval and all that from servicenow but then you don't know what's coming there then you have to work with the pipeline owner to ensure that those are done or you have to run a full Discovery but this is running a very specific targeted Discovery as you can see and it's brought out the CMP the the VM the the Nic and the storage volume that is deployed through maybe some template that was sitting in the pipeline there and yeah you'll see the dependency you can you can you can obviously operate on the virtual server uh in the same manner you can run several operations on that so the developer can come in here and they can kind of group up some things together and they can they can work on it all together I have to add one shot here they can be operating on a pipeline not one shot here so that's that's that's the story around uh the Azure devops integration um if you have questions just feel free to um push it out in the Q a uh make sure to answer those um also thanks to John and anybody else who's been helping to answer questions there which brings me to and the last part of the demo again since you've already seen the Azure devops you already have a sense of it I was very curious at the poll results that we ran initially where ansible was also called up the big problem with ansible as we all know is the fact that it's not very self-service driven and for the first time here we are bringing ansible into the into the fold here by the way ansible automation catalog integration uh this integration catalog well not be available in the beta2 if which which you might which you get on the store today now it was released in August so you'll get it on the store it's coming with the ga in November right again timeline subject to uh all the Safe Harbor notices there but the ga um in the next in the in the coming quarter uh will have the ansible automation here so what we're showing you is a little bit of a preview into into what's coming there and again very similar manner right we work with an ansible uh Tower uh or a ansible AWS as the case may be so we can pick the ones we want Associated change request with that uh previously created change request right and we we pick an ansible application profile wherein you can see again a bunch of stuff here uh again it could be working with any Cloud frankly for that matter no issues there you could be deploying simply easier ec2 or Azure multiple VMS or stuff like that and and again as as has been the case all the variables from that ansible job template are picked up here and you can modify any of the variables you can you can push it to a different Resource Group you can push it to a different public IP you can push it with a different IP name or application name and all that stuff and then uh of course at the end you have to choose the specific um account and specific uh location uh for AWS uh you push it out to whatever something like that right but the idea is here's your opportunity to actually tell your users to say just don't be doing things outside in a different system let's get it all into a workflow and and let's kind of converge on the story there okay again I'm not going to run this but we you've already seen enough examples here uh hopefully this gives a perspective we're adding uh all these capabilities and together and look forward to hearing your feedback on that um there seems to be a couple of questions um the first question the second question that I see here would you need integration hub no you don't need integration app to use the new ansible feature ansible is natively supported from CSC uh through uh what we call as our Cappy operations so we directly integrate with uh you don't need the ansible spoke for instance there's another question can we use tagging functionality of cloud resources While submitting catalog by capturing some more variables and those tags will then be discovered yes absolutely that's the way it's supposed to work you can add as many tags as you like and you can deploy uh you can you can you can you can set up the tags inside your template you can set up the tags inside your pipeline right and we'll discover those and we'll bring it back no issues there can we discover Alibaba cloud like gcp that's more of a discovery question we are talking about the provisioning here but yeah discovery of Alibaba cloud is something that we have in the roadmap please do reach out with more details we are very happy to support it if it's uh important uh for you which is waiting for the right numbers there and also we're looking at um our current commitments before we jump into that how hard is it to customize these catalog items to suit our needs um Sandeep I'll tell you one thing if you take there are other Integrations that are available today from hashicorp themselves there's a terraform app and all that the they are you know there's a lot of manual work like for instance let's take the example of one catalog item if you had to create you have to know every terraform variable you have to create a catalog variable for that and then our story is very simple you can ingest a template terraform or cloud formation or gdm or arm template or whatever it is and whatever else will support in the future as well as these Integrations that we've shown today with our ad1 ansible and all that stuff it's very simple we just take that and we convert it into a full-blown catalog item I'll be happy to share a video we we don't have enough time to show that actual template the catalog item creation today which is a simple one-step process the vanilla catalog item with the workflow attached with the integration to the specific cloud or the technology there cloud formation or terraform or whatever that's just happens in minutes there so very simple to create your own catalog items there and the idea one of the ideas behind giving this out of the box stuff here is basically to ensure that you know you you have ready-made references in fact it's been working very well with some of the povs that we've been doing with some customers even during beta because they've taken these reference uh catalog items that we provide and actually they've created their own catalog items for free at other clouds like Google Google cloud and all that stuff on their own right so it's it's been working out very well in very short time that do that okay so hopefully uh you know that that can yeah I'm handing it back to John sorry for the access time taken no worries at all thank you so much from I'm gonna share my screen now and uh we have poll number two so uh thanks again for your amazing uh demonstration of how cloud services catalog works and for answering so many questions thanks to everyone for actually uh submitting those many questions this is great engagement and we really appreciate it so the very last part of this webinar is around really for us to understand what are your plans in terms of implementation of a cloud services catalog in the future you can see different options here are you considering to implement it within the next six months or a year's time or it could be that you already have one otherwise you're just exploring you don't necessarily have timelines for it and in in case uh if you want to be more detailed or if you're interested knowing more about cloud services catalog let us know in the final survey that you will be prompted out right after this session I'm gonna go ahead very few seconds so please everyone submit your answers I see many of you sir submitting the answers here so after a few seconds and I'm gonna end the poll here so we can finish on time now the results are very interesting so 63 percent of use is just exploring and has no plans yet uh about CSC and then we see that uh 15 of you is interested in in implementing one in the next year it's all present of you have one already so please let us know in the uh either a q a function or a final survey which ones do you have and how do you have it and ten percent of views has uh is interested in adopting one in the next six months so great engagement and uh I we really thank you for your great questions I guess we covered already the questions uh these are some resources please visit the store and you will find the Innovation lab releases of cloud services catalog and the content pack store apps and there is also a YouTube video and we will make sure to attach these resources in the final deck tables here in the same page submit your ideas in case you have new ideas around CSC or around anything really you can think of we have the idea portal it's really important for you to um really put all of your ideas in this portals so they can get attention whenever you have 10 of the same ideas they will be directly prompted to the product management team and they will be considered for the roadmap and as we said before just make sure you enroll to the library servicenow webinar series and that's it for today so if you have further questions just feel free to ask in uh to put them in the final survey we prompted ad right now and that's it again for today thanks for your amazing engagements well make sure we'll answer your questions uh if you'll send them off uh after this webinar and we really look forward to see you in the next episode thanks Ram thanks everybody and we'll see you soon
https://www.youtube.com/watch?v=rlX1LJUjNsY