3 ms·
Platform teams could be highly toxic especially in small startups during initial secops/audit era. You really need like hundreds of product engineers to gain ve
by bvrmn 2y ago
Platform teams could be highly toxic especially in small startups during initial secops/audit era. You really need like hundreds of product engineers to gain velocity/value from platform teams.
- tuananh 2y agothat's when they dont see internal teams are customers. because if they do, they will do everything to make the internal teams life easier. enabling, not gatekeeping.
- SerCe 2y agoIn my mind, platform teams wouldn't necessarily be toxic in a small-ish companies, it's just very unlikely they'd qualify to be a platform team. In the absence of cross-cutting logic to take care of, it sounds like they'd effectively be a product team focusing on the infra things?
- master_crab 2y agoThat’s generally how they start. Most companies don’t really start with a “platform” team. It’s usually a guy who manages the infrastructure, or is the go-to for your IaC questions.
- SerCe 2y agoThat's true, but they don't always have to evolve to follow the platform team model. They could evolve into more of an SRE-style team and/or traditional ops team.
- bvrmn 2y agoLet me elaborate. The idea of "we have multiple product teams and they do similar stuff, let's optimize it" visits CTO/CEO brain on quite early stages. And "platform" team could evolve according to: 1) devops/sre start to provide some guides on top of some cloud, nowdays it's k8s. Like default service templates. 2) service templates transforms into custom DSL with side configuration and k8s abstraction things. 3) Abstraction/libraries on top of secrets management. 4) Service configuration per enviroment. At with point it's all good. But startup grows, and needs a secops team to get some internal audit. Or it could be a platform team initiative. 5) Audit shows critical issues with permissions and platform team starts to think about how to restrict access. Mismatch with "old freedom" could be quite high for unprepared product teams. Platform becomes "inconvenient". It takes huge amount of resources to make it actually usable.
- SerCe 2y agoI see, thank you for clarifying. That's an interesting observation, I feel like there is a story behind it. :) I definitely agree that as any small start-up grows, the security controls become very painful, especially for those folks who felt "the freedom" before the controls were established. That said, would the picture look better without platform teams? The security controls would need to be there anyway, and I'd personally prefer to use some self-serve, platform-ish solution built by a team of software engineers that would do call auditing, verification, etc., rather than raising a JIRA ticket with some ops folks who'd do the security-sensitive thing for you.
- bvrmn 2y ago> I feel like there is a story behind it. :) Ahah. 100%. Honestly I am in a great conflict right now. My current role is in a platform team (first time here, previously it was only product positions). And I'm responsible for implementing unified company wide authorization including client libraries and integration with all web frameworks in use. I feel vast empathy for product engineers having to migrate and integrate the new system. It has artificial intended bumps I have to enforce and doesn't like personally.