43 ms·
"This is what DevOps is about: running Ops like you're Developing an app, not letting your devs run your ops." This is a very common attitude of sysadmins who
by spajus 10y ago
"This is what DevOps is about: running Ops like you're Developing an app, not letting your devs run your ops."
This is a very common attitude of sysadmins who think that configuration management is the only thing they need to do to "become DevOps". Sadly, years after DevOps movement has started, the majority of people who are "doing DevOps" are those sysadmins who just added Puppet or Chef to their toolbox.
Security is a very difficult subject when it comes to DevOps practices, but the approach given in this presentation is definitely something I would not want to be part of. Unless what they are securing is a nuclear reactor control center.
- Annatar 10y agoOn the other hand, I have yet to work with, or even meet a developer who thinks that DevOps isn't dumping .tar files or Docker images directly into production. The developers love it because it gives them carte blache to just hack production any way they see fit. For instance, I had some Java developer attempt to argue with me that .tar files are the same as .rpm's, and that was just one of many incidents. The worst part is, the developers actively spread that propaganda, along with OS packaging requiring root privileges to deploy payload as being unsuitable for continuous delivery.
- spajus 10y agoI think this is solvable by educating devs, not just by enforcing policies. And path to production should be a well defined process, that has to evolve from collaboration between devs and ops, so nobody should be able to just "hack production" on their own, and ops could also be doing dev code reviews to see what exactly they are doing.
- acdha 10y agoEducation is critical, along with ownership. A lot of the bad practices on either side happen when someone can just fob a mess off onto the other group rather than trying to fix it. Once they have that responsibility it's easier to get someone to care about e.g. how a tarball doesn't address dependency management.