9 ms·
I'm the product lead on cloud.gov... Thanks for noticing us! There are other Cloud Foundry deployments, but what makes cloud.gov special is the focus on ensurin
by bmogilefsky 10y ago
I'm the product lead on cloud.gov... Thanks for noticing us! There are other Cloud Foundry deployments, but what makes cloud.gov special is the focus on ensuring federal agencies are actually able to use it. Federal compliance for a cloud service provider is a tough bar to clear, and without it most agencies are simply unable to take advantage of capabilities the rest of the world now takes for granted. That in turn impedes improvements in the many services the government has to offer. We've just reached the "FedRAMP Ready" status, which is a signifier of confidence that cloud.gov will make it through the exhaustive auditing process to come. Best of all, everything were doing is open source, including all the compliance work, so others will be able to follow in our footsteps. AMA!
- mcritz 10y agoAny plans to standardize agencies tech stacks? Is that even a good idea?
- bmogilefsky 10y agoWe can't control the decisions they make, and wouldn't want to... Each agency has their own CIO, and needs to be able to make decisions about stacks based their needs. Compliance requirements for running a service in public are so huge that agencies have conservatively stuck to ancient options, or farmed it all out to vendors. Our goal is to make the operations, deployment, and compliance aspects of service delivery trivial so they can put more of their resources (and those of the vendors they pay) into the improvement of the services they provide rather than sinking a huge portion of their budgets into redundantly addressing compliance and deployment concerns. And of course, use modern tech.
- BinaryIdiot 10y agoGood luck with that. I was only a government contractor and the amount of blue badges that argue how the other agency is doing it wrong / stupid and they would never use their stack is insane.
- wslack 10y agoYeah, I've certainly seen some of that. Hopefully, though, we can share and spread ideas, if not exact policies.
- bmogilefsky 10y agoYou're right, everyone is on the hook for their own agency, and with such strict regulations they are very conservative about using each other's stuff, which is effectively delegating decisions and responsibility to others that may get them in trouble. This is a major reason for cloud.gov going after the FedRAMP JAB P-ATO recognition. "JAB" is the Joint Authorization Board comprised of the CIOs of the Department of Defense, Department of Homeland Security, and the General Services Administration. Having a triple-sign-off from three CIOs under a consistently applied set of standards is the highest social proof you can get in government that will convince other agency CIOs that it is OK to use your stuff at their agency. Normally it's vendors that go through this program... We're among the few to do it for a government-developed-and-operated service, and the first to do it for something as generally useful as a PaaS. The other aspect is making sure everything we do to deploy and document the platform's compliance is open source and subject to scrutiny, so they can check for themselves... and ideally contribute in areas they think it could be better, of course!
- BinaryIdiot 10y agoYou're fighting the good fight and seems you have a good path. Curious how far you guys make it (it almost seems like everyone is against using "the other guy's" stuff but the vast majority of the time it would save millions). Good luck!
- empath75 10y agoWhat sorts of jobs are available there and what's the salary like? I currently do devops at a large Internet content company near Dulles and I've got federal government experience from many years ago.
- verst 10y agoSee: https://pages.18f.gov/joining-18f/ https://pages.18f.gov/joining-18f/ I'll let @bmogilefsky describe the jobs. @18F as a whole hires engineers, designers, product managers, content writers, journalists, folks with non-traditional cross-functional backgrounds, etc. Salary depends on job grade. See [1] for an explanation of the grades within 18F. Then see the GS pay scale [2] to figure out the pay for your grade in your region. [1]: https://pages.18f.gov/joining-18f/pay-grades/ https://pages.18f.gov/joining-18f/pay-grades/ [2]: https://www.opm.gov/policy-data-oversight/pay-leave/salaries-wages/2016/general-schedule/ https://www.opm.gov/policy-data-oversight/pay-leave/salaries...
- brianwawok 10y agoNothing says "we employ the best" like "fixed salary based on tenure and job function"
- wslack 10y ago18F and other groups in government offer a great potential for impact, but we don't have the same flexibility in compensation policy because of universal federal rules. Speaking personally, I think there's a lot of room for policy folks to dig into how gov't can better hire and retain skilled talent, but that's not 18F's function.
- brianwawok 10y agoFor sure, I don't blame 18f, it is just super annoying to see things like this.
- aidanfeldman 10y ago
- booop 10y agoWouldn't deploying cloudfoundry to AWS GovCloud accomplish the same thing? (Sorry, if the question seems too ignorant)
- aidanfeldman 10y agoWe're in the process of moving to GovCloud, but that's a relatively small part of the overall compliance...fun...that goes into getting a service FedRAMP-approved.
- VonGuard 10y agoYou forgot to mention your slack: chat.cloud.gov, where people can come ask questions, right?
- aidanfeldman 10y agohttps://chat.18f.gov/?channel=devops-public https://chat.18f.gov/?channel=devops-public, actually. EDIT: Gaaah, sorry, down right now for reasons. Will post here again when it's back up. Sorry!
- apahwa 10y agothat link is broken
- verst 10y agohttps://github.com/18F/chat https://github.com/18F/chat Seems like the Slack invite app is not deployed to cloud.gov right now.
- deftnerd 10y agoI think that Slack being down is related to this: Watchdog: 18F's Slack security exposed GSA data https://fcw.com/articles/2016/05/13/slack-security-18f.aspx https://fcw.com/articles/2016/05/13/slack-security-18f.aspx It was enough of a problem that the reaction was to probably take it down and take a hard look at everything before being it back up. Maybe a hosted rocket.chat will be the replacement to allow them more granular control over security.
- jksmith 10y agoYep, I just got Azure Gov FedRamped on my project and it was some serious gnashing and pulling of teeth. Writing all those CMS and IRS procedure docs was a great, but arduous experience. There's a larger story here though involving application outside the US, which is what I'd like to pursue after my current project. It definitely will not include Azure unless that becomes a more cost effective platform. Would love to chat with you guys about some ideas.
- akshatpradhan 10y ago>I just got Azure Gov FedRamped on my project and it was some serious gnashing and pulling of teeth. Writing all those CMS and IRS procedure docs was a great, but arduous experience. If you're pulling teeth in regards to FEDRAMP, you can join ##GRC on irc.freenode.org with fellow teeth grinders. Its a chat channel with 20+ Security Auditors and System Administrators dedicated to discussing enforcement, regulations, and systems administration for FEDRAMP and other compliance frameworks. There's also the brand new subreddit called /r/FEDRAMP that started a few days ago. https://www.reddit.com/r/FEDRAMP https://www.reddit.com/r/FEDRAMP. Check the sidebar for other compliance frameworks too like /r/SOC2, /r/HIPAA, /r/ISO27001, and /r/PCICompliance. https://www.reddit.com/r/HIPAA https://www.reddit.com/r/HIPAA https://www.reddit.com/r/PCICompliance https://www.reddit.com/r/PCICompliance https://www.reddit.com/r/ISO27001 https://www.reddit.com/r/ISO27001 https://www.reddit.com/r/SOC2 https://www.reddit.com/r/SOC2
- fudged71 10y agoThe "Contact us" section is actually a "Subscribe to our newsletter", I would look into changing the copy there and/or providing actual contact details.
- chias 10y agoThis is totally a minor thing, but I feel like the icons halfway down the page are off-by-one: http://i.imgur.com/bXTZqOZ.png http://i.imgur.com/bXTZqOZ.png That is, the arrowbox thingie for scalability, the lock for security, etc?
- bmogilefsky 10y agoGood eyes, will see if we can fix that.
- Shengbo 10y agoAnother very minor thing is that when I click anywhere inside the section below the header, a light-grey border shows up. http://imgur.com/qaqvozK http://imgur.com/qaqvozK
- wslack 10y agoReplicated and logged! https://github.com/18F/cg-landing/issues/67 https://github.com/18F/cg-landing/issues/67
- jeremiak 10y agoThanks for reporting! I opened this issue to make sure we fix it: https://github.com/18F/cg-landing/issues/70 https://github.com/18F/cg-landing/issues/70
- homero 10y agoPlease let the public use it
- kordless 10y agoFor the love all that is holy, no.
- afarrell 10y ago> are simply unable to take advantage of capabilities the rest of the world takes for granted A major argument in favor of PACER is its high-availability. Hopefully this makes it easier to build a better system with the same high-availability but a much better UX.
- kordless 10y agoHow do you see innovations in software able to reconcile bureaucratic processes while not remaining susceptible to scalability and trust issues? I could easily see how the government's business process could be at conflict with the commercial sector's business process. Colluding the two in even a single Open Source project would seem to be illogical.