logo

NJP

Beers With Cloud Engineers - Episode 22 - Cloud Account Management

Import · Mar 04, 2024 · video

absolutely so I'm excited uh to to welcome you all to session 22 of beers with Engineers um uh super glad to have you all here it's it's kind of like uh hanging out with a group of friends once a month you know um it's really nice uh you know will and I always joke about how this is our favorite day of the month um and it's not far off the truth so um good to get together and hang out again and today U we always have to start with the Safe Harbor slide um because some of the things that we're talking about may change as they you know get pushed into GA um and we always want to make sure that we're clear that you know functionality may not exactly land the way we talk about here and overall don't make any stock purchasing decisions based on anything that we discuss here today um so uh well well with same agenda as you guys know we generally like to keep this pretty loose and pretty formal um as always interactivity is you know most fun for everyone involved so at any point you have questions feel free you know drop something in the Q&A um you know or raise your hand um or even come off mute and just jump in with questions right the um the whole point of this is for you guys to have an opportunity to get into some of the Deep dive of what we're working on so let's talk about why we're here and uh um what the whole point of this is right so um will and I actually built this series out because we realized that there's a lot of different service now customers that are moving along this Cloud dat of Journey managing infrastructure in in the cloud you know doing containers doing the you know official like cni Cloud native p pieces and there's not a lot of discussion around how folks are using service now in that journey and there's not a lot of opportunities for customers to kind of talk with each other about that as well so um as you know at the end when we turn the com turn off the recording and open up the floor for conversation the goal of that is for for everyone to talk and discuss and think about how things are going so let's talk about who we are um so uh I actually am an ex-service now employee I have moved over to the customer side of the house and I run the Enterprise applications team for a trading firm out of Chicago called drw um I am an old school tech nerd um been doing it longer than I care to admit and uh I love what I do um I love all things um from a you know it operations standpoint I've been in it for a very long time um I am all about how do we intelligently and effectively use technology in order to solve business problems um I play a lot of board games funny enough my my mom got me a shirt that says board game Legend for for Christmas that I happen to be wearing today um and uh I trained Brazilian jiu-jitsu um which is actually one of the reasons why I am not drinking a beer today I'm I'm sticking to my healthy water because I'm training and preparing for a competition in a couple months and uh I need to lose some of the beer weight so um will over to you thanks Mike hi everybody will halum I'm a advisory itom architect at service now I'm focusing on IP operations management automation um lots of different Cloud native Arenas I've been at service now about three years before that was on the practitioner side for for several decades working kind of in that same realm and really found that I enjoy taking repetitive tasks and automating them and that was kind of how I came into the service now orbit is it's such a great platform for doing those kind of things and in my spare time I like spending time with my family play a little pickup hockey here and there and uh and enjoy video gaming and I am not training for Jiu-Jitsu um so I will be enjoying a Sam Adams Cold Snap which is a delightful white ale I'm just gonna say I'm envious it sounds good um so before we launch into our main topic uh we just wanted to touch Bas it's been we kind of skipped um January because it's a uh I had a lot of travel going on and it's kind of a busy kind of kickoff month for service now and um it kind of collided with our normal uh our normal date that we would have chosen so uh it's been since December since uh we've come together as a group so we just wanted to touch base on a couple things that had happened since then um just to make sure folks were were looped in so the first thing um and we did actually touch on this in December was the release of um release of the new Cloud native operations cn2 also called um Cloud native operations for visibility and um what was announced shortly after was kind of the the road map for the original version of cloud native Ops which had a lot of uh it was it was fundamentally different in a bunch of different ways and so what they've announced is that um that won't work starting with Washington so when an instance gets upgraded or you build an instance on Washington it's only going to work with the V2 of cloud native Ops um if you're staying if if you've got you know Vancouver or older instances you can continue to use the older functionality uh through this year I believe the kind of Drop Dead date is sometime in 2025 but um just from my perspective it's the the new version's so much nicer I definitely encourage anybody um anybody I talk to to take a look at that new generation of CNO the kubernetes Ander and and um consider adopting that as your kubernetes visibility solution so but just wanted to highlight that because that was announced shortly after the um the offering was released not kind of coincident with it my only caveat to like add on that is unless you're using the older capability in cn1 to ingest like metrics for health um or the um the capability to connect up to um some of the service mesh Technologies there's no reason not to upgrade to V2 right V2 is lighter faster uh less resource intensive um and does a phenomenal job and it's actually easier to roll into um your kind of cluster standup processes than V1 was so highly highly recommend to just move over to V2 if you're not already on that path definitely and then just the other thing I wanted to mention was um those of you who've been with the community for a while may recall we did a live event with Mike and myself an actual beer at um knowledge 2023 we are looking into doing something similar for knowledge 24 um it's still kind of early planning stages the primary challenge is just being able to get somebody to you know fund um you know getting the getting the room reserved and and getting the uh getting the beverage Etc so we are working on that just wanted to let folks know that we're going to do our best to make that happen again if you've got any kind of um suggestions for topics or things that you would have um liked to see different if you went to the event last year certainly you know reach out via any of our available channels to help us with that kind of feedback always welcome okay so now on to the the main event for today so I'm going to hand things over to merly who's going to talk to us about a new offering which is it's it's um available from the store and the Innovation Channel today and uh a kind of an early form and the idea is to kind of um seed the conversation and find out from our customers what the Real Pain points are with provisioning cloud accounts and kind of really shape the direct the ultimate direction for this offering so that it matches up against those challenges so I'm going to release my share and merly if you want to grab the screen share and just let me know when you'd like to pop those polls up yeah thank you thank you so can you see my screen now yes yeah so yeah today my topic will be uh cloud account management so just before introduction say I've been with the service now last 3 three plus years now so into technology around 22 plus years now so uh yeah I'm in Passionate in solving many technical problems and say mentoring the team members in uh going from one level to up uh in mentoring with my knowledge and uh gaining other Knowledge from them side that was my passion of uh technology in learning so so this is my third presentation in B for engineers so presented uh service gra connectors for AWS and gcp and this is my third project on cloud account management okay uh so here if you see uh where do we go there are a lot of cloud products in service now where uh uh say you have uh like uh cpg CSC uh there are a lot of other products right where do we stand uh the cloud account management right so we stand at the day Zero where say someone is want to try uh migrate from uh onr to Cloud okay they have a department they have a say where they want to move the application from on to Cloud right so they need an account right so where uh if you see the current process where it takes uh if you have a manual process or a semi automated process where it takes uh few days to few weeks right so here uh we are trying to bridge that cap in doing uh an automation say where someone in the team can go and make a request and then uh there will be approver manager who approves the request and after the request the accounts can be created in matter of few minutes right so that is what uh we are trying to uh solve the problem uh if you see here uh so what are the other features we uh apart from creating an account is say uh we are planning to say introduce Landing zones uh in setting up the landing zones and also uh say do on on a periodic basis of say attesting the account right say today uh person a will be the owner of the account and down the line say person may move out of the company or move of the project and somebody has to uh own that account right so for that a reasonable uh uh say uh audit can be happened for say for government audit purpose right so for that so we have an attestation process where uh will be task will be created where the there will a set of people who will be assigned to the task and they need to verify okay person still is the owner of account one and uh if it is changed they can go and change it so that that the details are up to date in cdb okay so once say uh the account is created uh we also planning to offer offboarding right closing the account where say for example you may created the account for a temporary purpose for a POC or doing some type of say short term right uh or let's say you are you're done with the project you want to decommission the account so we offer are going to offer a where uh an automation process where you can just go and close the account so these are the three main uh flavors of this product we are going to offer so currently uh in uh Innovation lab uh we are focusing on mainly on account Creation in AWS so in future it will be uh expanded to Azure and gcp okay so uh so how do we manage all this application right say uh we want to restrict uh because since it is an account um creation process we don't want to have any user in the service now instance to go and uh access this application because of security reasons for that we defined three different roles right now so one is a requester so who can be a team leader or type of a representative in the team who wants to initiate a code gation process so they will log into the portal and then they make a request once they make a request uh email notification is sent to the approvers where the approval comes into picture where he is a supervisor either from the management team or from the finance team so they will review the request and say where okay is it something within our budget they'll review the request and then they go and approve the request so once approver approves the request so then it uh notification sent to the provisioner saying that okay hey uh company can have say uh more than one uh cloud or right so so they will be the deciding party okay this account request has has to go to ar1 or R2 or R3 so they are the decision makers uh based upon their say historical facts or the guidance from the CC leadership based upon that they go and provision the account in a uh they they assign the request to a particular AR from there the automation kicks off say greeting the account uh from end to end okay so these are the three roles we are going to use it and for uh say demonstration purpose we created some uh test use users with that we are going to go and say demonstrate the users so any questions until this point of time just a a comment um when I first saw this offering get announced it brought me back to my life as a customer because one of the things we were struggling with was a desire on the part of our business users to dynamically provision AWS accounts and WS provided some kind of very low-level basic tools to facilitate that but there was no approval process around that there was no workflow that we could customize so that it followed our business processes so when this came out I it just brought me right back to that particular challenge that I had experienced firsthand and you know wished that this was available back then because we would have been able to really um provide that flexibility to our business users while maintaining all of the you know I I was in a a regulated industry so there were a lot of auditing and approval um and accountability requirements that we so we couldn't just expose the AWS console to all of these business users it had to have some kind of a flow around it and so I I just think this is really great that we're offering this kind of capability thanks well anybody else so uh there's a question in the Q&A uh will cloud account management be used for access management to the resources integrating with Azure IM Etc yeah so the initial offering is say uh okay let me uh step back a little bit here right so uh you can have say if you see the cloud hierarchy structure right uh we are right now not focusing on IM uh in the near future we're focusing on the subscription accounts in each Cloud right so we assume that okay you already have a cloud or uh everything set up because of the security purpose and all building purpose right and uh what we are facilitating is say okay go and create a uh subscription account on the fly in a very fast full manner right in a sec fful manner where with all the approvals in picture right so that is what we are focusing on so right now we're focusing on a member account in AWS the future would be uh aure subscriptions and next would be gcp projects and after that I we'll be stepping into IM uh resources and I would think in the interim because it's all just built on top of standard platform capabilities as well as using terraform on the back end in the interim if somebody did want to add that level of customization all of the hooks are there they could do that it's just it won't do it out of the box until farther down the road map yeah that makes sense so this the technology stack we using it say currently in service no s side we are using say UI Builder uh pad Playbook I don't know how much you aware of it so it's a framework where it's built upon uh say uh the the flow flow designer framework where it gives you a canb type of a view visual visualization where you can arrange the activities in a way you want I will show you shortly where it allows you to do more customization based off your needs so out of the box we say okay we are the we are offering this many steps to create an account so down the line say if at all you want to introduce something uh in the middle you can you're free to go and introduce it so that it will fulfill your custom needs right and uh we are going to use Pace uh where uh it helps you to uh it's a p say uh platform as a code engine where it allows you to execute rules uh in say in between the steps let's say for example uh uh for example here uh in the first release we what you're doing is the steps of manual where let's say once my request has been made uh it has to it will go as a a uh manual approval process where somebody has to come and approve or deny right so the with the introduction of pace what going to happen is say let's say my request is for Dev enironment and my budget is say let's say my Dev budget is say $2,000 my my request budget is $1,000 right so with a certain set of criterias if I'm follow if I'm within the criteria it will automatically allows you to say uh uh make an auto approval without any manual intervention right and also when coming to uh say the second phase say provisioning process right so right now somebody has to go and assign okay request one from business unit one so has to go to uh R three right so that is been done manually in the phase one in the phase two when you induce P fa pce uh what is going to happen is say that can also be automated okay so they do have have a mapping automatically they can go on map automatically so that once you make a reest if it falls under all the limits so the account is created in a matter of 3 to 5 minutes okay all the process automated so instead of taking several days it can take it can take within few minutes that you get the job done right so that's the way uh where the p is coming into piture the other one is say the main integration H we using it say to interact with many apis that's that's the whole uh Tech stack in service no site and in uh terms of uh integrating with Cloud So currently we're using terraform uh where the scripts uh the terraform scripts are there in the GitHub so as soon as you make a request so it pulls a code from the terraform uh GitHub and then executes the terraform code and then it creates resources in the account in the cloud site okay so this is the textt tack of uh our this application so any questions so for I assume that's terraform Enterprise right uh currently yeah so the phe one supports terraform cloud and we're adding support for terraform Enterprise to okay yeah now when if somebody installs this today from Innovation lab where do they get that um those terraform templates that reside in the the G repo yeah we will share that uh we will share that perfect yeah yeah so let me jump into the demo uh so the different topics I want to cover is say the cam config uh uh say is the place where you say initially set up it will be done by the provisioner from the CCO team so he is the person knows all the credentials all those say settings in terraform and also in GitHub so they will come and uh say set up the configuration for each cloud or with that uh say uh a requester will say uh now then once the setup is done then it is open for say request to go and make a request then the approver will say come and approve or deny it and once that is done the Prov will make a provision request say setting the right context for the cloud or and then we will see the how the execution is done and what are the logs we can see all those stuff in the demo so I logged in into the instance uh where I want to share so as I said earlier right so we have three different types of roles so I logged in I will log in as a requester so who is a Beverly Campbell so here you can see a nice dashboard where how many requests has been made how many accounts has been created through uh the scam and then uh what is my the stats of say what is my approvals spending approvals approves approved ones denied ones and uh say once we introduce say what are the different platforms applications they used in the different type of applications right and also nice stats of okay how many accounts has been created in the past couple of months and also what the different types of environments they created so this type of stats you can see as soon as they login and here you see the recent fire request uh which has been made you can they can see with the status okay and with that say if I want to create a new request I'll go here and then I will select the the enir which I want to do right so here out of the box V ship uh three type of environments so if customer uh there is a table called CIS Choice table where the customers can go and introduce their own uh environments like say po uh stage uh test or say uh performance right they can introduce all type of environments so which has been tied to many other say uh itm and itm products the same environment value okay so once they populate those prefix right it so this uh the screen will have all the en listed here so they can go and say make a selection of say uh uh so if they they want to have uh one account created or uh for each enironment or uh they can have uh they can have multiple en created so for each environment we'll create a one one uh request so if you see here uh say we will ask the customer to fill in the say okay so what type of cloud they want uh in future when when introduce Azure at gcp so this is a decide uh account they which Cloud environment they want to create so that's what they mention it and here the temporary uh dates let's say if you are creating the request for a temporary time you can fill those dates and then you can fill in the monthly budget say $1,000 right and then you can pick a select the uh applications so these values are say part of the platform tables using it so we assume that say we are creating those uh pre-populating those values up front so that uh we we can refer to them so the reason why we're doing is say the same cost center values we used in uh cost say there is a product say CCM product and other itm product right so we all refer to the same table same values so that the we are talking to the same uh cost center such way that uh we are uh we are having a meaningful data uh referred in all the places so so we just fill in all the details whatever you want and then uh say we go on it so as a standard mechanism what we do is uh we take all this parameters as a key value and we'll populate as a key value tag in the cloud account and uh if at all let's say you feel you want to had more tags say my tag uh my tag one and then uh say my value one so I can just go and add those values so this will be an additional tag attached to the uh account so that once it comes back to the cbdb you will see as a key value tags in the uh service account table we just fill in all the details and say uh say production I say $5,000 right so so we get this question a lot when we talk to customers about any of our offerings that provide these kind of template basically template you know forms or catalog items um if the customer wants to take that and then autofill some of those fields that's something that they would be able to do is that correct yeah so we are working on that will so uh the the way we are working on it to say uh when you create a service now user in the service now instance so you'll attach that user to a cost Center business unit right so if uh in the next version we are trying to say autop populate all these values say if it is already there if it is there we already automatically populate all these values if it is not there we'll let the user to go and do it so when I have a plans of say the future where you go and create a profile where uh say say let's say I'm creating a account quite often right so we can go and set up this values as a predefined values yeah so that we can repopulate all those stuff yeah so those are the plans are there so this is the vanilla version what we came for site now so I enter all the values I go and review it and then I make a request submitted so now what happens is say uh a notification is sent to the approver group where there can be one or more than uh one approvers so they will get an email uh and then they come to the portal back so once they come to say there will be unique link s to uh for each request they uni L send to that email when the click the L email they they will be ending up and coming to the portal where uh they can see the request one second sorry so once they come in right so they will see what are the requests which have been made here so they can see all the requests uh so we created three request right now so it will be uh they can see the request so they can go into the request and review the details uh I think I took the wrong example it me take the development yeah so you see all the details who raised the request and what are the budget everything okay so once they see that request you should see your okay one second is the manager will listen set up the user yeah so they go to the request for some reason that user has been having some issues so so here once the request has been done so they review the request so they'll either say approve the request or the request so if you're denying the request let's say I'll take one more uh deny the request so they need to say uh denate for for say over budget so what happens is once this step has been done who raise they'll get a notification saying that okay whether the request is approved or denied so once that is done so now email is sent to the provision group saying that hey the new request has been approved now it's time to go and provision it so there uh comes another user called Kyle so once they login they'll see the request which is ready for approved so they come here and then then select uh the appropriate uh Cloud context so the one of the reason here is right even though I make request for AWS say the CC team or the leadership May decided okay all the new accounts has to go to gcp or Azure so where at this point of time you can go and change the context so it is not that say whatever the request is made you'll be assing the same uh Cloud context so here you can go on assign to Azure or gcp instead of AWS it's up to the prer group who decides uh the envirment what they want So based on on that so we will populate uh which cloud or uh we we want to uh create and then uh say click on provision okay so when it comes to provision I'll just uh give a pass here and I will so here so they'll see the this here is where the uh process automation designer comes into picture where uh they can see the uh realtime executions of each task uh each action say basically when you talk to terraform right so you go and create a workspace then add the variables to the workspace then you start triggering the workspace uh where uh it goes into say apply State then it it comes to the final stage of say provision right so those all steps you can see it in real time I'll show you shortly the Canan picture so here uh so so here what happens is once you say uh apply approve the as in the request so it will start executing all the uh terraform work workflows in a sequential Manner and then uh say we also can see uh the executions happening for the each uh request now I noticed you had to acknowledge that kind of instructional record at the beginning for it to proceed is the idea that that would be a place that a customer could inject any kind of um you know procedural requirement before triggering the actual provisioning okay so that inst step say nor what happens is say uh whenever the record is uh the request record is updated right so this pad process will check into the status of okay uh it has reached the deced state so here we looking for a a state called approved State as soon as the state is appr reached so this pad proc automatically gets triggered right so we don't want to do that before assing the proper Cloud context okay so that's why I had a that initial step to say stop uh automatic automatic execution before the cloud content set up so when when you start introducing Pace right so those steps will be done uh before and then uh say you don't need to see you will not see all this stuff okay so what happens is as soon as the prision automatic prisioners say automatic assignment of the cloud context has happen uh the pace automatically gets triggered in the background and it's it is getting completed okay so you see we are going through several stages here see uh there are say one is I'm prepping the environment and then uh creating the workspace now contacting Cloud to go and create the account so these are the different steps as happening and at the end of the step you see uh we capture all the uh terraform attributes and also a new account is created so I can copy this account and then I can go to uh Cloud uh see new account is created just now so uh that's what uh the end processes so once it is completed yeah notification again sent to all the groups say requester approver and provisioner they said that okay this is the account number got created and they'll see the uh say they'll get the email notification so here we just created an account so uh we got an email okay so I'll talk about a little bit about in the end uh what is is email Alas and all so right now this the end to end process uh is happened all in within uh few seconds so any questions until now uh there's a couple in the uh in the Q&A um do we have a target for GA for cloud account management yet it's currently in the Innovation lab uh uh I think it's in Q3 Q3 I'm not perfectly sure but yeah the dates are yet to uh uh reach why do not use employee Center is it possible to use catalog items scam so uh the reason uh we not using employee Center is say uh uh this whole product want to restrict in a secure way we don't want to open it for the the whole world in service now right so that was one of the key requirement from our PM where uh just introduce this columns only for uh few people in the team so that uh because we are going to add a lot many features uh where it involves a lot of auditing right so that's the reason it was restri to set of people in the Enterprise so did you answer your question Jon us I think one thing there is around um the okay good all right cool he says yes there's another one that popped in from Bob automatically create an app service that yeah so the whole thing is right so if you see the initial form uh it will be gred uh for a particular uh app service right so that is the whole by Point here so you can go and select when you make a request I'm creating this account for an app service so you select those app service and this tied to that app service so yeah I can show you here uh the cloud where once you go here you'll see all the uh tags created here which application we are creating it and then in service now did it create an application service with that detail okay I'm coming to that mic oh sorry I me jumping ahead yeah yeah so that's that's my next topic to uh discuss so so uh if you see right uh uh what we do is uh we depend on certain platform tables like say environment cost Center business unit uh Department system user right so we depend on all this tables so we uh request customers to have proper value populated uh before you start using this application okay so the reason is say uh this particular values are being used across multiple application service now and we want to talk in the same language so I don't want to say okay I have an app one has having a name as app AP1 and if it say if somebody is creating a uh different name let say application one it is very difficult to consolidate all those details right since as a platform we referring to all common uh table so we request say users to say go set up all these details up front before using the uh before using the application so as a prequest say we ask customers to say fill all these details let's say let's say you have 100 business units go and pop all those 100 business units and let's say cost does you go and populate all this details right so we uh at the end time we refer all the details and we go and populate all those uh in as a tags in AWS so did I answer you Mike well specific to the application service I I noticed when I was trying this out it required that I select an application service to associate with the cloud account that I was requesting I think I missed that particular uh entry here sorry yeah it includes application service too yeah we need to add it I think I forgot to add this point here so in theory you could have an overarching flow that you know if you're on boarding a new application service and your procedure calls for it to reside in its own AWS account you could use the overall automation capabilities of the platform to generate that app service record and then kick off a cloud account creation that aligned to that app service yeah so yeah so this is all about I was talking about the service now how we handling all those n to end so let me dig deeper uh little bit into the AWS Concepts uh say as you know uh the previous two product which I developed so we asked the customers to have give us the limited permissions uh so that we can can do our job right similarly here also we're asking uh in order for me to go and create an account right so we need to go and create a imem user in the management account so we need to create a role with this permissions so that Mar trip sorry you're you're with me on the water today so we request customers to say go and admins to go and set up a role with all these permissions so that uh the application can do all this say greeting of the new account okay so currently uh there is a caveat here so we don't support STS assume role currently uh so for example we are we ask a customers to go and create a user in the master account right so maybe the the future so we can have a say uh place where you can create a uh IM account in any member account from there we can assume that role in the master account and then we can go and initiate the rgpa calls okay and also uh in future we are also planning to have a credential L uh approach uh where uh say you uh you have a mid mid server in Cloud where we can uh get the temporary St uh uh token with that uh we can go and make an APA call here so there those are all future enhancements we are planning for okay so one of the main thing I forgot to uh mention here is say uh our is a completely the solution is completely mid solution so there is no mid server involved uh only purely service no instance terraform envirment and Cloud so I sorry I forgot to mention it earlier it's completely mid solution maybe when it comes to a credential less solution where uh say let's say I don't want to give you uh the credentials but uh you say let's say you are creating a a VM instance in a cloud where it can uh get the STS token so there we may need a mid server involved other than that there is no mid server requirement as of now it seems like that's a little bit mitigated by virtue of these permissions um which largely seem to be kind of mostly readon um they're not read only they're uh actually creating an account right it's not read only yeah oh yeah I missed create account okay yeah so if the create account API calls coming from the instance what is it using um what is it using terraform for yeah well which so because terraform terraforms I thought terraform was actually creating the account yeah terraform is creating the account but the code is stored in the GU so this yeah so we calling this say API in the Terra the Terra form right so you pass all those values and uh it'll be uh it can be called from terap gotcha okay yeah so the next topic I want to talk about little bit more about uh a root email so as most of you know uh each AWS account requires a unique email ID right so uh let's say in a company where we have thousands of accounts it is very difficult for someone to create a unique email ID every time and with this automation it is hard to uh predetermine all those uh say creating an email on the Fly uh contacting ad server it is very difficult to do it right so what how do we solve this problem is say we are asking customers to say uh create an email allas for example here uh you need to say the aw thatp need to contact uh uh M admin right so where they go and create an allas so here I giv example say AWS I CC at my company.com right so this is the email allas they create it and what we do is say uh they need to uh make sure that okay if I uh suffix any other uh text with that email and say at the email Dynamic email right so they should be able to receive the email into the mailbox which uh to this email box right such a way that we can create thousands of emails unique emails and attached to uh A's requirement of having a unique email ID and whatever the communications goes uh to the email goes to one email ID such a way that I get all the communications for this particular or into one email box such a way that I can uh say get uh all the uh request uh coming to one email box so to show you here uh here we have we created an email account just now right so I got an email to this a uh I awfa the request number is 96 serv.com but my actual email is this one itom aafa service.com right so all the emails created for dynamically comes to these email alas so that I can manage the those accounts from here so if I want to Res the was that by virtue of some uh rule that you had to request within our M365 email system saying hey anything that starts with that yeah that DL with a plus and then a suffix send it to the yeah the base DL okay yeah yeah so that way I can easily manage the account right so uh that helps all for us to also automate the whole stuff y right so yeah so this with this I can have a centralized communication coming to my things and also if at all I want to uh say say um change the password I get the notification to this email ID where I can go and reset it I can do all those uh say management stuff here okay so one other thing I forgot to mention is say in terms of uh configuration so here is what uh yeah so let's say I I'm creating an account for the AR one right so I go and set up all those details here okay so I give the root email alas here and I give the uh the the terraform code where it is residing it and which for which cloud or I'm going to uh refer to this configuration and what is the cloud type everything I give here so what happens is say uh this details is been picked up dynamically in the runtime uh and then it is getting executed so the one other thing I want to show you is on the pad framework he just really quick while he's pulling that up I want to jump back to something that plus email address thing that's actually a little known trick that is supported by all mailboxes it's called a sub address and any that after the plus is basically ignored and it's delivered to the email address without that plus in it there's a whole RFC that documents it funny Sid trick you can actually use that in your personal email addresses if you get an email if you give someone an email with plus blah blah blah then you can quickly filter on that and you can actually know who it came from if you want to like track who's selling your information that kind of stuff it's kind of an interesting trick nice yeah so yeah so so we saw in the the provision we saw that okay when they click the and there are sequence of steps happen right so this is what is that right so what we do is we prepare the uh we prepare the execution flow so where uh this is the place okay my request is AWS I'm requesting for AR one right so what we do is from the configuration we try to refer the record and then send it to the next uh next section where I go and create an execution context uh execution context so what happens is uh say whenever uh uh I created when whenever I run the flow it'll create a new request here uh what happens is say let's say for example I I I given the wrong password or I did some typo right so what happens is every time I don't want to use the customer okay there is some technical issue happened I don't want you to go and create a new request and approve it so we will still use the same request approved request and we can run multiple times so until the issue is resolved okay there can be issue in the terraform configuration there can be issue in the AWS configuration right so issues can happen anywhere right so what happens is uh we create a new context for the same request until it is successfully done uh so they need to just run this uh uh pad framework flow uh every time when they want to rerun the whole flow so we go and make a new request and then this will have the complete logs so we capture all the logs from from the uh terraform and from the cloud say okay we executed uh many steps here right and if you see here there's a counter because uh uh there is a whenever you run the terraform it takes couple of seconds to uh get it done uh from say from initiating to Next Step it takes some time right so what we do is we keep on pulling uh the terraform whether the job is done and then we capture all the stuff so that we do a retry uh from our side so once it is done we go to the next step okay so that is what you see here so whenever there is some error happens I can show you one example here so whenever some error happens we capture those errors and can put it here in the logs so this helps say for example the CC people uh they can see all in one place what went wrong they can go and fix it error and come back and rerun the whole flow and then they can uh do it until they they they s they are successful in creating new account right so this logs helps them into uh where and also this one you see U where this lock came from and which Step so we have a number of steps here so where we can see uh where the issue has happened okay and here is what the beauty of this framework is say uh so as out of the box we given these features right so if at all you want to uh customize it to your needs you can just go and create a new activity and introduce in the middle and you can drag and drop the way you want okay so that way it helps you to more customize to your needs and then you can execute it right that's the beauty of this framework that's awesome hey merley do you want me to pop up those polls real quick yeah sure sure yeah while you're doing that I I really like this process automation designer flow it's really really helpful so um so yeah we're we just pop up a couple quick polls just trying to uh because part of this is kind of back and forth and this this tool is very early in its life cycle and so you have an opportunity based on the real challenges within your environments to kind of shape its direction um merley do you see this question about the ga offering in the Q&A maybe you can respond to that so yeah the initial Target is uh Q3 uh we are targeting AWS first and maybe later uh Azure but it in pipeline we already started working on it yeah um we need to see when we can ship it as a ga uh J okay oh um so when I went to test this and I went to install it from Innovation Labs I noticed that until you gave me the direct link to the the app in the store I couldn't find it via search if that's still the case what should customers do if they're interested and want to try it out but they can't locate it in the store uh I can give you the say I can type the yeah if you can give me that link I can include it in the um because I'm going to at least send out our slides if your slides are available to send out I can send those out as well but between the two slide decks I can include that link uh when I send the wrapup email if that if that works I mean you could you can put it in the chat now if you want but um if it's if you don't have it handy we can just send it out as part of the wrapup emails yeah handy sending it to perfect yeah I hadn't really realized that there's kind of tiered levels of how available something is it could be an innovation labs in searchable but it could also be an innovation lab but you have to work with you know somebody like your account team to actually get the URL to install it just to try and um you know manage the the implementations and make well the evaluations and make sure that um somebody doesn't get themselves in over their head yep cool um I know we're coming right up on time did we want to fire off that other polls yeah yeah here I think um where did my polls window go oh it won't let me okay yeah I'll have to end this one and go back and now I'll launch the second one B skill yeah given the link and also the um point of contact PM Ram dadan so you can reach out to him uh for any further questions and plans you want thank you uh while we got that poll now's a good time to jump in with any questions that you have I have one last side mik oh go for it yeah once they're done with the poll I can go the last slide all right we'll give it another 30 seconds yeah these seem to align with the answers we're getting so far seem to align with my experiences as well okay hlls are closed go go right go right ahead with your final slide yeah yeah so here is what right so we want to listen to the customers right okay uh what are the main things they want to focus on right so right now if you see uh we are focusing on account Creation in the future we planning to say have fature for account suspension and closure process uh which is say nothing but uh uh let's say I want to limit my budget and over spend don't want to over spend right so we are going to offer a feature called suspension where they cannot create a new resource and let's say if they want to gracefully close the account by uh setting all the resources right so we're going to offer those closure process and also we planning to have support for Azure and Global projects in the future right and also we have plans to say have uh plans to do with cacd and creating a landing zones uh credential as access and also integrating with a control tower right so we just want to know uh which are the features you want to go uh as a first choice or second choice right that would be of great uh feedback help so that we can focus uh on those Solutions which you guys want it awesome so um yeah one a great channel for that kind of um feedback is uh the the PM for the product ROM who uh information Merle's put in the chat we'll also include that in the wrapup emails that go out after the session is uh after the session recording is posted so we'll make that available and um as always um you know invite and welcome all kinds of feedback and and participation um there's a question how can I get my colleagues invited to this meeting series um the uh the easiest thing to do is just um when the wrap-up email arrives it'll have the sign up link for the next session and then you can pass that along share that URL with any um with any colleagues or teammates that you think would also be interested in excellent well mle as always it's great to have you on um we love the the Deep detail that you get into in your presentation so thank you very much appreciate it thank you thank you that's exactly what the the folks need to hear right so really really appreciate it um with that um we're looking forward to seeing everybody again next month um I appreciate you guys running a little along with us um and I think unless there's anything else will we can shut down the recording and will and I can stick around and chat any questions that you have for us sounds good

View original source

https://www.youtube.com/watch?v=DW_3QYOYMVY