WEBVTT
00:00:00.150 --> 00:00:28.887
We all understand that it's really important to have a flexible and adaptable technology stack, but that is underpinned by knowing where everything is so I'm really pleased to welcome Akhil Bhaskar to share some of his experiences with managing that stack and how it really enables the uh innovation and adaptability of companies.
00:00:28.887 --> 00:00:30.445
So welcome, Akhil.
00:00:30.445 --> 00:00:31.750
Thanks Jon, nice to be here.
00:00:31.750 --> 00:00:34.231
So Akhil, we've known each other for a little while.
00:00:34.231 --> 00:00:43.893
Currently you're at AWS, but you've also had a number of other roles in different countries, in the US, Australia, Singapore.
00:00:43.893 --> 00:00:50.036
One of the things that I think is very top of mind is there is a lot of excitement about digitalization.
00:00:50.036 --> 00:00:55.810
And of course, since the pandemic, every company has had to have a digital presence.
00:00:55.810 --> 00:01:14.274
Not every company has everything in order and it digitized very quickly perhaps and is still resolving some of those challenges and some of those played out in well-known outages, security vulnerabilities, cyber hacking.
00:01:14.274 --> 00:01:27.460
Can you perhaps share some of your experiences with what it actually takes to manage your stack well so that you can have that adaptability and flexibility that you need.
00:01:27.460 --> 00:01:29.981
Yeah, first of all, thank you for having me.
00:01:29.981 --> 00:01:35.006
It's always nice to see you and for once we're in the same city, which is always great as well.
00:01:35.006 --> 00:01:44.257
I think before I jump into a couple of examples of what I've done and where I've done it and where I think I've done it well with my teams is a bit of my background as well.
00:01:44.257 --> 00:01:58.825
So yes, we've worked, I've worked across multiple countries in various industries, but I think the thing that makes me who I am is that I've moved from m Currently I'm in a vendor land, if you will, but I've been in customer land.
00:01:58.825 --> 00:02:06.311
I've been in consulting previously, supporting customers across the world, understand what does digital transformation mean.
00:02:06.311 --> 00:02:22.884
And it's not just "Here's the latest and greatest cool technology", although we love that because we are all techies at heart, but it is about how do you apply to the problems that are real and how do you come up with solutions that are not just short-term wins, but sustainable long-term success.
00:02:22.884 --> 00:02:28.409
So underpinning everything I do is really just mental models and frameworks.
00:02:28.409 --> 00:02:40.739
And that I think is the crux of what you're talking about here as well, which is how do you think about systems and how do you think about understanding what do I have, where do I have it, who's doing what with it and so forth.
00:02:40.739 --> 00:02:42.781
Look I'll give you a clear example.
00:02:42.781 --> 00:02:46.711
when was it, it was like 2019, 2020, somewhere thereabouts.
00:02:46.711 --> 00:02:52.122
There was a big log4j supply chain vulnerability that came through.
00:02:52.122 --> 00:02:59.734
And log4j for those that are Java users, it's a fundamental piece of technology, right?
00:02:59.734 --> 00:03:06.836
It's one of those libraries that everyone uses and has been using for 20 plus years, maybe even longer.
00:03:06.836 --> 00:03:09.387
I've been using it for 20 plus years.
00:03:09.387 --> 00:03:13.252
And so every single java application has log4j in it.
00:03:13.252 --> 00:03:21.705
Now this is where supply chain issues come into play where suddenly this log4j, a certain set of versions were affected.
00:03:21.705 --> 00:03:27.349
And unfortunately, we were using one of those versions that was affected as well.
00:03:27.349 --> 00:03:44.825
Now, cue, know, everyone's screaming around, you know, the sky is falling situation, but luckily, we had a weapon at our disposal that we had not even planned for, you know, coming to our aid at this point.
00:03:44.825 --> 00:03:46.234
This is the software catalog.
00:03:46.234 --> 00:03:48.104
This is the software catalog.
00:03:48.104 --> 00:03:52.538
We were using a technology called Backstage, which I think you're quite familiar with as well.
00:03:52.538 --> 00:04:01.424
And using Backstage, all I wanted to do was to understand, y'know, what were we building, where were we building it, and how could we make things go faster, right?
00:04:01.424 --> 00:04:09.438
So it was a, for those that don't know Backstage, it's a way to understand your entire software catalog, but it also gives you things like templates and golden paths.
00:04:09.438 --> 00:04:21.096
So you can go in very quickly and say, I want to build a new microservice, or a micro front end or whatever it might be, click a button, it starts up a scaffold and then you build on top of it.
00:04:21.096 --> 00:04:32.396
But the scaffold gives you a lot of the goodness that you need, but also it gives me as a manager, as an engineering leader, a lot of goodness that developers usually don't think about, right?
00:04:32.396 --> 00:04:39.935
Tag, explainable documentation, understanding, you know, who the authors are, what libraries are being used and so forth.
00:04:39.935 --> 00:04:42.627
So this is really two things though.
00:04:42.627 --> 00:04:57.798
The software catalog is a way of helping you to manage the assets and I guess I'm impressed that not only you had a software catalog of your own assets but also the dependencies on external software, the software supply chain.
00:04:57.798 --> 00:05:17.612
But the other part of what you mentioned with the scaffolding templates is it helps to encourage the use of the organo- organizations style guide and patterns rather than developers coming along using what they used at their last company or looked at on the web and thought that's really nice.
00:05:17.612 --> 00:05:28.531
Which creates not necessarily bad practices but if it's not a common practice within your organization then it's very confusing for other people who need to work on that application.
00:05:28.531 --> 00:05:33.055
So AWS has this thing where we talk about undifferentiated heavy lifting.
00:05:33.055 --> 00:05:40.119
And I didn't know that term until I joined a few years ago, but I think everyone kind of understands a bit of that term, right?
00:05:40.119 --> 00:05:45.922
So it's what are the things that I don't need to worry about in order to do the things that I do need to worry about, right?
00:05:45.922 --> 00:05:47.184
The things I get paid to do.
00:05:47.184 --> 00:05:56.028
Now in this company, we had a core group of full-time staff, developers, but we also had augmented ourselves with a ton of contractors.
00:05:56.028 --> 00:06:17.233
Now in order to make the contractors whose time is valuable and where we're paying pretty decent rates in order to make sure that their time is being utilized as efficiently as possible or at least in my realm, we put in a lot of these patterns to use your word but just opinionated aspects of how should you do certain things, right?
00:06:17.233 --> 00:06:25.557
So we had chosen the language, we'd chosen certain libraries, we'd chosen a style guide, we'd chosen the GitOps path and so forth.
00:06:25.557 --> 00:06:27.702
So everything's kind of built in.
00:06:27.702 --> 00:06:30.761
All they have to do is build the logic that sits inside of it.
00:06:30.761 --> 00:06:33.483
Now, I talked about the libraries.
00:06:33.483 --> 00:06:35.175
Honestly, that was a...
00:06:35.175 --> 00:06:58.949
a little bit of we just wanted the information but also we kind of got lucky to be honest because in that set of libraries and again this was just pulled from we were using Maven at this point right so Maven has a list of libraries so we just kind of pull it and just write it down somewhere and that somewhere then feeds into Backstage right it's a configuration file that leads into Backstage.
00:06:58.949 --> 00:07:13.781
Now when the log4j issue happened and we knew that a certain library version was affected, all I had to do was go to my catalog and just search for anywhere where that log4j version existed.
00:07:13.781 --> 00:07:23.211
So where, remember I said cue everything's, you know, "We don't know what to do and we have to now spend..." Management asking how are we exposed?
00:07:23.211 --> 00:07:28.545
In fact, our CIO did come and say, you know, "How bad is it?" Right?
00:07:28.545 --> 00:07:32.276
And honestly, it took us two hours, right?
00:07:32.276 --> 00:07:33.766
We did an entire review.
00:07:33.766 --> 00:07:39.949
We validated that the information was correct, because again, I didn't want to just trust, you know, one configuration file.
00:07:39.949 --> 00:07:45.081
So we went back in, just made sure our catalog was showing the right information.
00:07:45.081 --> 00:07:54.380
And we took that to the CIO and said there are 10 components that were affected, two that were already being fixed, and eight that were on the to-do list.
00:07:54.380 --> 00:08:04.346
And effectively, I told our CIO, "Give us a day, everything will be patched, we'll be up and running through all the testing, everything else." We were done in about four hours, honestly.
00:08:04.346 --> 00:08:20.387
So a thing that could have blown up to be something quite complicated, something quite bad, turned into a situation where having had the rigor and the hygiene of maintaining, you know, what do we have, where do we have it, how do we have it, came in extremely handy for us.
00:08:20.387 --> 00:08:31.110
The word hygiene I think is very apt there because when you think about cleaning and keeping your house in order, that's a key part of Absolutely is.
00:08:31.110 --> 00:08:33.323
Yeah, I'm a big fan of it right again.
00:08:33.323 --> 00:08:41.399
from my consulting days, we usually got brought in when things were going pear-shaped or when we had to build something very large.
00:08:41.399 --> 00:08:49.383
And because we were consultants, we had to showcase every week, you know, here's what we've done, here's the progress and so forth.
00:08:49.383 --> 00:08:53.044
I think that's kind of just, it's just inbuilt in me at this point, right?
00:08:53.044 --> 00:08:54.905
The habit of hygiene.
00:08:54.905 --> 00:09:00.451
I fundamentally think that is the thing that sets me, know, up for success in these scenarios.
00:09:00.451 --> 00:09:25.875
So from doing the housekeeping and making sure that you understand your supply chain Those sorts of incidents, whether it's a security vulnerability or an outage, whether it was caused by on your estate or one of your providers, it's important to understand what your options are, where your vulnerabilities are and prioritize action.
00:09:25.875 --> 00:09:27.246
the next...
00:09:27.246 --> 00:09:46.916
everybody's talking about what AI can do for people but what I'm conscious of apart from the business applications is how do you make sure that you're still in control of the key aspects of your business and that you innovate.
00:09:46.916 --> 00:09:52.249
but you do so in a way that you know that you can sustain over time.
00:09:52.249 --> 00:09:54.755
So what are you seeing now?
00:09:54.755 --> 00:09:56.330
That's a big topic, right?
00:09:56.330 --> 00:09:59.009
And of course everyone talks about AI at this point.
00:09:59.009 --> 00:10:11.469
We talk about probably the biases, governance and things like that, but from a technology estate standpoint, where do you see the need for firms to...
00:10:11.469 --> 00:10:13.038
how do you amplify that?
00:10:13.038 --> 00:10:17.572
Do you take Backstage and extend it or what else do you need to do?
00:10:17.572 --> 00:10:19.048
So I'm actually...
00:10:19.048 --> 00:10:19.840
big fan of it.
00:10:19.840 --> 00:10:26.273
In fact, we're what a small team and I are actually building on Backstage but for agentic AI.
00:10:26.273 --> 00:10:39.202
Now before we go into agentic AI, just generative AI has created this incredible wave of excitement and optimism and yeah like even my mother is a big gen AI user and so forth.
00:10:39.202 --> 00:10:45.187
it's just been this really interesting and really quite a step change.
00:10:45.187 --> 00:10:46.830
in how we think about tech, right?
00:10:46.830 --> 00:10:54.083
But generative AI, the part that makes it really cool is the hallucinations, right, or the generative part.
00:10:54.083 --> 00:10:54.971
But that's the same.
00:10:54.971 --> 00:10:56.274
The creative part of it.
00:10:56.274 --> 00:10:57.644
It's very creative.
00:10:57.644 --> 00:11:01.076
when I write something with it, it's, wow, that's amazing, right?
00:11:01.076 --> 00:11:10.620
But it's that same generative or hallucinative or creative part that creates problems for businesses because businesses want predictability.
00:11:10.620 --> 00:11:13.461
Businesses want confidence and control.
00:11:13.461 --> 00:11:20.467
And when I asked this question, I want some sort of deterministic answer, not a probabilistic answer.
00:11:20.467 --> 00:11:24.250
And the entire point of generative AI is it's probabilistic, right?
00:11:24.250 --> 00:11:29.010
Now if you shift that over to agentic AI, this is where it gets really interesting, right?
00:11:29.010 --> 00:11:31.673
Because agentic AI...
00:11:31.673 --> 00:11:36.951
in a very rudimentary way you can think of it as microservices plus plus, right?
00:11:36.951 --> 00:11:48.163
Because it is about modular programming, it is about domain orientation, it is about how do you carve out certain parts of your workflow and you assign it to various different agents.
00:11:48.163 --> 00:12:09.577
Now agentic has been around since the 1950s i think it has been but what's changed now is instead of having to code everything you know explicitly or to put some sort of neural engine in it or to have a business rules engine in it, I can now give it a three line English language statement and it goes and figures it all out.
00:12:09.577 --> 00:12:11.299
That's the cool part of what's changed.
00:12:11.299 --> 00:12:22.350
But you still need to understand as part of the agency that an agent has, as part of the autonomy that the agent has, what is it doing and where is it going and is it allowed to go there?
00:12:22.350 --> 00:12:24.839
Is it allowed to check out this information?
00:12:24.839 --> 00:12:26.423
What are the boundaries?
00:12:27.089 --> 00:12:36.221
Boundaries are incredibly important and it's just there's a knowledge boundary, a resource boundary, a tool boundary that there's a number of different boundaries to think about.
00:12:36.221 --> 00:12:50.565
And not only do you need guardrails, but you also need, especially for regulated environments like banks and telcos and governments, you need to be able to show what did the agent do, why did it do it, and what was the result out of it.
00:12:50.565 --> 00:13:01.706
So the explainability comes back into play, but ultimately all of that goes back to I need a software catalog, I need to know what the agents are, I need to know the boundaries of them.
00:13:01.706 --> 00:13:07.802
So you get back to this idea of give me list of things that I have and have access to.
00:13:07.802 --> 00:13:11.264
And that list can change dynamically, that's okay.
00:13:11.264 --> 00:13:17.578
But every time I add a new agent that I'm going to a marketplace and picking up, I add it to my list, right?
00:13:17.578 --> 00:13:25.931
So that's the part I think we haven't quite nailed down yet as a industry, but we need to because that comes back to hygiene.
00:13:25.931 --> 00:13:35.998
One of the things that's documentation and the compiling of all this information a real challenge is it has been a lot of manual work.
00:13:35.998 --> 00:13:47.200
Now tools like Backstage to feed the software catalog improved things a little bit because you can tap into the GitLab or GitHub organization.
00:13:47.200 --> 00:13:54.907
And when changes are made there, it can feed through, there's a feed through to the software catalog.
00:13:54.907 --> 00:14:01.594
What do you see that change process happening in the agentic world?
00:14:02.735 --> 00:14:08.836
Because you can spend, if documentation is an afterthought, then it will always be behind.
00:14:08.836 --> 00:14:18.716
The advantage of that git-based repository for software is that that's the active working space.
00:14:18.716 --> 00:14:24.488
So how do we maintain that in the AI?
00:14:24.488 --> 00:14:29.850
I think a fundamental shift here is we've gone from programmatic work, right?
00:14:29.850 --> 00:14:37.517
So I need to build these if-then loops and whatever the logic is, to what I'm calling intent-based development, right?
00:14:37.517 --> 00:14:42.299
So I give an agent an intent and it then has to go figure out what it's doing.
00:14:42.299 --> 00:14:50.784
The moment you go to intent-based development, and you could do this in a way in traditional programming as well, right?
00:14:50.784 --> 00:15:00.171
I have an intention to build an app that I can sell on a marketplace or it's a module that I put into an API library or whatever the case might be.
00:15:00.171 --> 00:15:12.239
What we didn't do before because it was kind of annoying, right, and I've worked my way into understanding why documentation is important but that doesn't mean I like it, right?
00:15:12.239 --> 00:15:14.879
But the moment you have an intent...
00:15:15.061 --> 00:15:23.076
AI, whether it's a foundation model or some other type of system, can actually go through and figure out, you know, what is the system doing?
00:15:23.076 --> 00:15:24.485
What does it need to do?
00:15:24.485 --> 00:15:27.548
What inputs and outputs and parameters does it need?
00:15:27.548 --> 00:15:35.932
And I think now it can go and write a lot of the documentation for you that does not absolve the human from forgetting about it.
00:15:35.932 --> 00:15:39.686
The human still has to go check it, make sure it's correct, right?
00:15:39.686 --> 00:15:47.004
The same way they would check the output and go is two by two coming out to be four or "Woah, that's fundamentally wrong", right?
00:15:47.004 --> 00:15:55.922
So it's the same way the human still has a responsibility but a lot of the undifferentiated heavy lifting can now be outsourced to these agents.
00:15:55.922 --> 00:15:59.673
In terms of skills, raises a challenge.
00:15:59.673 --> 00:16:04.297
Obviously there's a new skill to learn, is how to manage the agent.
00:16:04.297 --> 00:16:14.985
also there have been some other changes like we don't necessarily need to use all the tools we used to use, but we still need to retain some knowledge of some things.
00:16:14.985 --> 00:16:17.667
So for example, my father was an accountant.
00:16:17.667 --> 00:16:20.087
He knew how to use a slide rule.
00:16:20.087 --> 00:16:20.798
I've never used it.
00:16:20.798 --> 00:16:21.447
slide rule.
00:16:21.447 --> 00:16:37.416
Never needed to because we had calculators when I was in school but the reason in primary school we still teach children the times table is because you need to be able to do that mental check at least an order of magnitude check.
00:16:37.416 --> 00:16:41.548
that you're plugging in the right numbers to the calculator.
00:16:41.548 --> 00:16:50.836
What are the skills, how do you see skills evolving in this world where not everybody's necessarily going to learn some of the foundational...
00:16:50.856 --> 00:16:56.942
And I think that would be a very unfortunate situation if that is the case.
00:16:56.942 --> 00:17:00.063
You're right in that we still teach the times table, right?
00:17:00.063 --> 00:17:01.195
Is there a need for it?
00:17:01.195 --> 00:17:07.608
No, like we just whip out our phones now and calculator app, know, previously it was the actual calculator and so forth.
00:17:07.608 --> 00:17:16.384
But I think fundamentally moving forward, and I talk to my teams about this all the time and they tell me about this as well, which is, I think there are two skills that are critical.
00:17:16.384 --> 00:17:18.386
Storytelling and critical thinking.
00:17:18.386 --> 00:17:23.951
I'll give you a reason, even though they sound nothing like technology or software oriented.
00:17:23.951 --> 00:17:27.794
Storytelling is really important because that's how you communicate.
00:17:27.794 --> 00:17:34.419
And communication becomes super important when it's an intent-driven programming-based model.
00:17:34.419 --> 00:17:37.561
If you just say, go build me an app.
00:17:37.561 --> 00:17:40.203
I mean, the thing's gonna spit out an app.
00:17:40.203 --> 00:17:41.244
Is it the app you want?
00:17:41.244 --> 00:17:41.924
Not at all.
00:17:41.924 --> 00:18:01.494
But if you say, hey, I want to build a calculator app where I give it two entries and here are the four types of calculations you can do to it and when I come up with that, like if you don't know the answer, if you don't feel confident, go build a Python compiler and run it there and then come back with an answer.
00:18:01.494 --> 00:18:04.833
Now obviously that's a very simple example.
00:18:04.833 --> 00:18:10.173
When you said storytelling, I was thinking, yes, as people, we need to tell stories to each other.
00:18:10.173 --> 00:18:17.403
But you're talking about telling a story to the agent who's going to build something for you.
00:18:17.403 --> 00:18:20.727
But I think human to human storytelling, that's a whole different topic.
00:18:20.727 --> 00:18:25.309
I love that topic and maybe we can talk about that again at a later point.
00:18:25.309 --> 00:18:29.551
In the context of programming, I think storytelling is still critical, right?
00:18:29.551 --> 00:18:39.257
Because you have to communicate often in an English language or if you're using a model that can take in a different language, you need to be crisp and clear, right?
00:18:39.257 --> 00:18:51.563
Now, if you think about the history of software programming, how often have you been there before, like how often do you get requirements that you're like, oh I understand exactly what I need to do, right?
00:18:51.563 --> 00:18:53.743
We've not been good at this.
00:18:53.743 --> 00:19:02.138
And in fact, if we go into agentic AI, we need to fundamentally get better at telling the system what is it we want to do.
00:19:02.138 --> 00:19:08.362
Now we won't necessarily get it right the first time also because we might just not know what it is that we want the first time.
00:19:08.362 --> 00:19:11.564
This is where the second part comes in which is critical thinking.
00:19:11.564 --> 00:19:18.627
And again human beings need to develop and continue to develop critical thinking and there's an entirely different human side of it.
00:19:18.627 --> 00:19:23.010
In the programming side of it, it comes back to feedback loops and iterations, right?
00:19:23.010 --> 00:19:24.559
I see a thing.
00:19:24.559 --> 00:19:28.093
I need to know what is what was my original intent.
00:19:28.093 --> 00:19:29.834
What does good look like?
00:19:29.834 --> 00:19:34.155
Because The machine is going to be very happy to give you 50,000 iterations.
00:19:34.155 --> 00:19:42.527
You as a human, as the owner of that outcome, you have to decide which one of those is correct and when you are happy with it, right?
00:19:42.527 --> 00:19:53.460
And when do you go, that's good, let me now, you know, push this change into my Git repo and have my GitOps process take over to do CD effectively, right?
00:19:53.460 --> 00:19:57.990
So those two skills for me are the fundamental skills.
00:19:57.990 --> 00:20:00.762
uh Beyond knowing base programming.
00:20:00.762 --> 00:20:07.960
I think you still need to know a little bit of that and just logic but Look, I was building something in Rust the other day.
00:20:07.960 --> 00:20:23.366
No understanding of Rust at all, right, but I had my my Go script and I said I want to convert this to Rust right and we have a thing called Kiro here and I just put it into Kiro and I said help me convert this to Rust and it took me through it.
00:20:23.366 --> 00:20:24.403
Was it the best?
00:20:24.403 --> 00:20:25.483
Maybe, maybe not.
00:20:25.483 --> 00:20:32.787
I don't know enough to know about it, but I built a working app in Rust that I could put in my POC environment.
00:20:32.787 --> 00:20:44.353
Wouldn't trust to put it into production yet, but I think those skills are still useful, but for me it comes back to can you tell the system what it is you want in a clear, succinct way?
00:20:44.353 --> 00:20:50.855
And then when it gives you something back, can you verify that this is the thing that you wanted out of it?
00:20:50.855 --> 00:20:53.207
And if it's not, rinse and repeat, right?
00:20:53.207 --> 00:20:53.869
Loops.
00:20:53.869 --> 00:20:57.215
Akhil, I think you've summed this up extremely well.
00:20:57.215 --> 00:20:58.939
Always a pleasure talking with you.
00:20:58.939 --> 00:20:59.660
is always.
00:20:59.660 --> 00:21:02.083
Thanks very much for sharing that.
00:21:02.083 --> 00:21:02.646
absolutely.
00:21:02.646 --> 00:21:03.282
Thanks, Jon.
00:21:03.282 --> 00:21:04.048
Cheers.
00:00:00.150 --> 00:00:28.887
We all understand that it's really important to have a flexible and adaptable technology stack, but that is underpinned by knowing where everything is so I'm really pleased to welcome Akhil Bhaskar to share some of his experiences with managing that stack and how it really enables the uh innovation and adaptability of companies.
00:00:28.887 --> 00:00:30.445
So welcome, Akhil.
00:00:30.445 --> 00:00:31.750
Thanks Jon, nice to be here.
00:00:31.750 --> 00:00:34.231
So Akhil, we've known each other for a little while.
00:00:34.231 --> 00:00:43.893
Currently you're at AWS, but you've also had a number of other roles in different countries, in the US, Australia, Singapore.
00:00:43.893 --> 00:00:50.036
One of the things that I think is very top of mind is there is a lot of excitement about digitalization.
00:00:50.036 --> 00:00:55.810
And of course, since the pandemic, every company has had to have a digital presence.
00:00:55.810 --> 00:01:14.274
Not every company has everything in order and it digitized very quickly perhaps and is still resolving some of those challenges and some of those played out in well-known outages, security vulnerabilities, cyber hacking.
00:01:14.274 --> 00:01:27.460
Can you perhaps share some of your experiences with what it actually takes to manage your stack well so that you can have that adaptability and flexibility that you need.
00:01:27.460 --> 00:01:29.981
Yeah, first of all, thank you for having me.
00:01:29.981 --> 00:01:35.006
It's always nice to see you and for once we're in the same city, which is always great as well.
00:01:35.006 --> 00:01:44.257
I think before I jump into a couple of examples of what I've done and where I've done it and where I think I've done it well with my teams is a bit of my background as well.
00:01:44.257 --> 00:01:58.825
So yes, we've worked, I've worked across multiple countries in various industries, but I think the thing that makes me who I am is that I've moved from m Currently I'm in a vendor land, if you will, but I've been in customer land.
00:01:58.825 --> 00:02:06.311
I've been in consulting previously, supporting customers across the world, understand what does digital transformation mean.
00:02:06.311 --> 00:02:22.884
And it's not just "Here's the latest and greatest cool technology", although we love that because we are all techies at heart, but it is about how do you apply to the problems that are real and how do you come up with solutions that are not just short-term wins, but sustainable long-term success.
00:02:22.884 --> 00:02:28.409
So underpinning everything I do is really just mental models and frameworks.
00:02:28.409 --> 00:02:40.739
And that I think is the crux of what you're talking about here as well, which is how do you think about systems and how do you think about understanding what do I have, where do I have it, who's doing what with it and so forth.
00:02:40.739 --> 00:02:42.781
Look I'll give you a clear example.
00:02:42.781 --> 00:02:46.711
when was it, it was like 2019, 2020, somewhere thereabouts.
00:02:46.711 --> 00:02:52.122
There was a big log4j supply chain vulnerability that came through.
00:02:52.122 --> 00:02:59.734
And log4j for those that are Java users, it's a fundamental piece of technology, right?
00:02:59.734 --> 00:03:06.836
It's one of those libraries that everyone uses and has been using for 20 plus years, maybe even longer.
00:03:06.836 --> 00:03:09.387
I've been using it for 20 plus years.
00:03:09.387 --> 00:03:13.252
And so every single java application has log4j in it.
00:03:13.252 --> 00:03:21.705
Now this is where supply chain issues come into play where suddenly this log4j, a certain set of versions were affected.
00:03:21.705 --> 00:03:27.349
And unfortunately, we were using one of those versions that was affected as well.
00:03:27.349 --> 00:03:44.825
Now, cue, know, everyone's screaming around, you know, the sky is falling situation, but luckily, we had a weapon at our disposal that we had not even planned for, you know, coming to our aid at this point.
00:03:44.825 --> 00:03:46.234
This is the software catalog.
00:03:46.234 --> 00:03:48.104
This is the software catalog.
00:03:48.104 --> 00:03:52.538
We were using a technology called Backstage, which I think you're quite familiar with as well.
00:03:52.538 --> 00:04:01.424
And using Backstage, all I wanted to do was to understand, y'know, what were we building, where were we building it, and how could we make things go faster, right?
00:04:01.424 --> 00:04:09.438
So it was a, for those that don't know Backstage, it's a way to understand your entire software catalog, but it also gives you things like templates and golden paths.
00:04:09.438 --> 00:04:21.096
So you can go in very quickly and say, I want to build a new microservice, or a micro front end or whatever it might be, click a button, it starts up a scaffold and then you build on top of it.
00:04:21.096 --> 00:04:32.396
But the scaffold gives you a lot of the goodness that you need, but also it gives me as a manager, as an engineering leader, a lot of goodness that developers usually don't think about, right?
00:04:32.396 --> 00:04:39.935
Tag, explainable documentation, understanding, you know, who the authors are, what libraries are being used and so forth.
00:04:39.935 --> 00:04:42.627
So this is really two things though.
00:04:42.627 --> 00:04:57.798
The software catalog is a way of helping you to manage the assets and I guess I'm impressed that not only you had a software catalog of your own assets but also the dependencies on external software, the software supply chain.
00:04:57.798 --> 00:05:17.612
But the other part of what you mentioned with the scaffolding templates is it helps to encourage the use of the organo- organizations style guide and patterns rather than developers coming along using what they used at their last company or looked at on the web and thought that's really nice.
00:05:17.612 --> 00:05:28.531
Which creates not necessarily bad practices but if it's not a common practice within your organization then it's very confusing for other people who need to work on that application.
00:05:28.531 --> 00:05:33.055
So AWS has this thing where we talk about undifferentiated heavy lifting.
00:05:33.055 --> 00:05:40.119
And I didn't know that term until I joined a few years ago, but I think everyone kind of understands a bit of that term, right?
00:05:40.119 --> 00:05:45.922
So it's what are the things that I don't need to worry about in order to do the things that I do need to worry about, right?
00:05:45.922 --> 00:05:47.184
The things I get paid to do.
00:05:47.184 --> 00:05:56.028
Now in this company, we had a core group of full-time staff, developers, but we also had augmented ourselves with a ton of contractors.
00:05:56.028 --> 00:06:17.233
Now in order to make the contractors whose time is valuable and where we're paying pretty decent rates in order to make sure that their time is being utilized as efficiently as possible or at least in my realm, we put in a lot of these patterns to use your word but just opinionated aspects of how should you do certain things, right?
00:06:17.233 --> 00:06:25.557
So we had chosen the language, we'd chosen certain libraries, we'd chosen a style guide, we'd chosen the GitOps path and so forth.
00:06:25.557 --> 00:06:27.702
So everything's kind of built in.
00:06:27.702 --> 00:06:30.761
All they have to do is build the logic that sits inside of it.
00:06:30.761 --> 00:06:33.483
Now, I talked about the libraries.
00:06:33.483 --> 00:06:35.175
Honestly, that was a...
00:06:35.175 --> 00:06:58.949
a little bit of we just wanted the information but also we kind of got lucky to be honest because in that set of libraries and again this was just pulled from we were using Maven at this point right so Maven has a list of libraries so we just kind of pull it and just write it down somewhere and that somewhere then feeds into Backstage right it's a configuration file that leads into Backstage.
00:06:58.949 --> 00:07:13.781
Now when the log4j issue happened and we knew that a certain library version was affected, all I had to do was go to my catalog and just search for anywhere where that log4j version existed.
00:07:13.781 --> 00:07:23.211
So where, remember I said cue everything's, you know, "We don't know what to do and we have to now spend..." Management asking how are we exposed?
00:07:23.211 --> 00:07:28.545
In fact, our CIO did come and say, you know, "How bad is it?" Right?
00:07:28.545 --> 00:07:32.276
And honestly, it took us two hours, right?
00:07:32.276 --> 00:07:33.766
We did an entire review.
00:07:33.766 --> 00:07:39.949
We validated that the information was correct, because again, I didn't want to just trust, you know, one configuration file.
00:07:39.949 --> 00:07:45.081
So we went back in, just made sure our catalog was showing the right information.
00:07:45.081 --> 00:07:54.380
And we took that to the CIO and said there are 10 components that were affected, two that were already being fixed, and eight that were on the to-do list.
00:07:54.380 --> 00:08:04.346
And effectively, I told our CIO, "Give us a day, everything will be patched, we'll be up and running through all the testing, everything else." We were done in about four hours, honestly.
00:08:04.346 --> 00:08:20.387
So a thing that could have blown up to be something quite complicated, something quite bad, turned into a situation where having had the rigor and the hygiene of maintaining, you know, what do we have, where do we have it, how do we have it, came in extremely handy for us.
00:08:20.387 --> 00:08:31.110
The word hygiene I think is very apt there because when you think about cleaning and keeping your house in order, that's a key part of Absolutely is.
00:08:31.110 --> 00:08:33.323
Yeah, I'm a big fan of it right again.
00:08:33.323 --> 00:08:41.399
from my consulting days, we usually got brought in when things were going pear-shaped or when we had to build something very large.
00:08:41.399 --> 00:08:49.383
And because we were consultants, we had to showcase every week, you know, here's what we've done, here's the progress and so forth.
00:08:49.383 --> 00:08:53.044
I think that's kind of just, it's just inbuilt in me at this point, right?
00:08:53.044 --> 00:08:54.905
The habit of hygiene.
00:08:54.905 --> 00:09:00.451
I fundamentally think that is the thing that sets me, know, up for success in these scenarios.
00:09:00.451 --> 00:09:25.875
So from doing the housekeeping and making sure that you understand your supply chain Those sorts of incidents, whether it's a security vulnerability or an outage, whether it was caused by on your estate or one of your providers, it's important to understand what your options are, where your vulnerabilities are and prioritize action.
00:09:25.875 --> 00:09:27.246
the next...
00:09:27.246 --> 00:09:46.916
everybody's talking about what AI can do for people but what I'm conscious of apart from the business applications is how do you make sure that you're still in control of the key aspects of your business and that you innovate.
00:09:46.916 --> 00:09:52.249
but you do so in a way that you know that you can sustain over time.
00:09:52.249 --> 00:09:54.755
So what are you seeing now?
00:09:54.755 --> 00:09:56.330
That's a big topic, right?
00:09:56.330 --> 00:09:59.009
And of course everyone talks about AI at this point.
00:09:59.009 --> 00:10:11.469
We talk about probably the biases, governance and things like that, but from a technology estate standpoint, where do you see the need for firms to...
00:10:11.469 --> 00:10:13.038
how do you amplify that?
00:10:13.038 --> 00:10:17.572
Do you take Backstage and extend it or what else do you need to do?
00:10:17.572 --> 00:10:19.048
So I'm actually...
00:10:19.048 --> 00:10:19.840
big fan of it.
00:10:19.840 --> 00:10:26.273
In fact, we're what a small team and I are actually building on Backstage but for agentic AI.
00:10:26.273 --> 00:10:39.202
Now before we go into agentic AI, just generative AI has created this incredible wave of excitement and optimism and yeah like even my mother is a big gen AI user and so forth.
00:10:39.202 --> 00:10:45.187
it's just been this really interesting and really quite a step change.
00:10:45.187 --> 00:10:46.830
in how we think about tech, right?
00:10:46.830 --> 00:10:54.083
But generative AI, the part that makes it really cool is the hallucinations, right, or the generative part.
00:10:54.083 --> 00:10:54.971
But that's the same.
00:10:54.971 --> 00:10:56.274
The creative part of it.
00:10:56.274 --> 00:10:57.644
It's very creative.
00:10:57.644 --> 00:11:01.076
when I write something with it, it's, wow, that's amazing, right?
00:11:01.076 --> 00:11:10.620
But it's that same generative or hallucinative or creative part that creates problems for businesses because businesses want predictability.
00:11:10.620 --> 00:11:13.461
Businesses want confidence and control.
00:11:13.461 --> 00:11:20.467
And when I asked this question, I want some sort of deterministic answer, not a probabilistic answer.
00:11:20.467 --> 00:11:24.250
And the entire point of generative AI is it's probabilistic, right?
00:11:24.250 --> 00:11:29.010
Now if you shift that over to agentic AI, this is where it gets really interesting, right?
00:11:29.010 --> 00:11:31.673
Because agentic AI...
00:11:31.673 --> 00:11:36.951
in a very rudimentary way you can think of it as microservices plus plus, right?
00:11:36.951 --> 00:11:48.163
Because it is about modular programming, it is about domain orientation, it is about how do you carve out certain parts of your workflow and you assign it to various different agents.
00:11:48.163 --> 00:12:09.577
Now agentic has been around since the 1950s i think it has been but what's changed now is instead of having to code everything you know explicitly or to put some sort of neural engine in it or to have a business rules engine in it, I can now give it a three line English language statement and it goes and figures it all out.
00:12:09.577 --> 00:12:11.299
That's the cool part of what's changed.
00:12:11.299 --> 00:12:22.350
But you still need to understand as part of the agency that an agent has, as part of the autonomy that the agent has, what is it doing and where is it going and is it allowed to go there?
00:12:22.350 --> 00:12:24.839
Is it allowed to check out this information?
00:12:24.839 --> 00:12:26.423
What are the boundaries?
00:12:27.089 --> 00:12:36.221
Boundaries are incredibly important and it's just there's a knowledge boundary, a resource boundary, a tool boundary that there's a number of different boundaries to think about.
00:12:36.221 --> 00:12:50.565
And not only do you need guardrails, but you also need, especially for regulated environments like banks and telcos and governments, you need to be able to show what did the agent do, why did it do it, and what was the result out of it.
00:12:50.565 --> 00:13:01.706
So the explainability comes back into play, but ultimately all of that goes back to I need a software catalog, I need to know what the agents are, I need to know the boundaries of them.
00:13:01.706 --> 00:13:07.802
So you get back to this idea of give me list of things that I have and have access to.
00:13:07.802 --> 00:13:11.264
And that list can change dynamically, that's okay.
00:13:11.264 --> 00:13:17.578
But every time I add a new agent that I'm going to a marketplace and picking up, I add it to my list, right?
00:13:17.578 --> 00:13:25.931
So that's the part I think we haven't quite nailed down yet as a industry, but we need to because that comes back to hygiene.
00:13:25.931 --> 00:13:35.998
One of the things that's documentation and the compiling of all this information a real challenge is it has been a lot of manual work.
00:13:35.998 --> 00:13:47.200
Now tools like Backstage to feed the software catalog improved things a little bit because you can tap into the GitLab or GitHub organization.
00:13:47.200 --> 00:13:54.907
And when changes are made there, it can feed through, there's a feed through to the software catalog.
00:13:54.907 --> 00:14:01.594
What do you see that change process happening in the agentic world?
00:14:02.735 --> 00:14:08.836
Because you can spend, if documentation is an afterthought, then it will always be behind.
00:14:08.836 --> 00:14:18.716
The advantage of that git-based repository for software is that that's the active working space.
00:14:18.716 --> 00:14:24.488
So how do we maintain that in the AI?
00:14:24.488 --> 00:14:29.850
I think a fundamental shift here is we've gone from programmatic work, right?
00:14:29.850 --> 00:14:37.517
So I need to build these if-then loops and whatever the logic is, to what I'm calling intent-based development, right?
00:14:37.517 --> 00:14:42.299
So I give an agent an intent and it then has to go figure out what it's doing.
00:14:42.299 --> 00:14:50.784
The moment you go to intent-based development, and you could do this in a way in traditional programming as well, right?
00:14:50.784 --> 00:15:00.171
I have an intention to build an app that I can sell on a marketplace or it's a module that I put into an API library or whatever the case might be.
00:15:00.171 --> 00:15:12.239
What we didn't do before because it was kind of annoying, right, and I've worked my way into understanding why documentation is important but that doesn't mean I like it, right?
00:15:12.239 --> 00:15:14.879
But the moment you have an intent...
00:15:15.061 --> 00:15:23.076
AI, whether it's a foundation model or some other type of system, can actually go through and figure out, you know, what is the system doing?
00:15:23.076 --> 00:15:24.485
What does it need to do?
00:15:24.485 --> 00:15:27.548
What inputs and outputs and parameters does it need?
00:15:27.548 --> 00:15:35.932
And I think now it can go and write a lot of the documentation for you that does not absolve the human from forgetting about it.
00:15:35.932 --> 00:15:39.686
The human still has to go check it, make sure it's correct, right?
00:15:39.686 --> 00:15:47.004
The same way they would check the output and go is two by two coming out to be four or "Woah, that's fundamentally wrong", right?
00:15:47.004 --> 00:15:55.922
So it's the same way the human still has a responsibility but a lot of the undifferentiated heavy lifting can now be outsourced to these agents.
00:15:55.922 --> 00:15:59.673
In terms of skills, raises a challenge.
00:15:59.673 --> 00:16:04.297
Obviously there's a new skill to learn, is how to manage the agent.
00:16:04.297 --> 00:16:14.985
also there have been some other changes like we don't necessarily need to use all the tools we used to use, but we still need to retain some knowledge of some things.
00:16:14.985 --> 00:16:17.667
So for example, my father was an accountant.
00:16:17.667 --> 00:16:20.087
He knew how to use a slide rule.
00:16:20.087 --> 00:16:20.798
I've never used it.
00:16:20.798 --> 00:16:21.447
slide rule.
00:16:21.447 --> 00:16:37.416
Never needed to because we had calculators when I was in school but the reason in primary school we still teach children the times table is because you need to be able to do that mental check at least an order of magnitude check.
00:16:37.416 --> 00:16:41.548
that you're plugging in the right numbers to the calculator.
00:16:41.548 --> 00:16:50.836
What are the skills, how do you see skills evolving in this world where not everybody's necessarily going to learn some of the foundational...
00:16:50.856 --> 00:16:56.942
And I think that would be a very unfortunate situation if that is the case.
00:16:56.942 --> 00:17:00.063
You're right in that we still teach the times table, right?
00:17:00.063 --> 00:17:01.195
Is there a need for it?
00:17:01.195 --> 00:17:07.608
No, like we just whip out our phones now and calculator app, know, previously it was the actual calculator and so forth.
00:17:07.608 --> 00:17:16.384
But I think fundamentally moving forward, and I talk to my teams about this all the time and they tell me about this as well, which is, I think there are two skills that are critical.
00:17:16.384 --> 00:17:18.386
Storytelling and critical thinking.
00:17:18.386 --> 00:17:23.951
I'll give you a reason, even though they sound nothing like technology or software oriented.
00:17:23.951 --> 00:17:27.794
Storytelling is really important because that's how you communicate.
00:17:27.794 --> 00:17:34.419
And communication becomes super important when it's an intent-driven programming-based model.
00:17:34.419 --> 00:17:37.561
If you just say, go build me an app.
00:17:37.561 --> 00:17:40.203
I mean, the thing's gonna spit out an app.
00:17:40.203 --> 00:17:41.244
Is it the app you want?
00:17:41.244 --> 00:17:41.924
Not at all.
00:17:41.924 --> 00:18:01.494
But if you say, hey, I want to build a calculator app where I give it two entries and here are the four types of calculations you can do to it and when I come up with that, like if you don't know the answer, if you don't feel confident, go build a Python compiler and run it there and then come back with an answer.
00:18:01.494 --> 00:18:04.833
Now obviously that's a very simple example.
00:18:04.833 --> 00:18:10.173
When you said storytelling, I was thinking, yes, as people, we need to tell stories to each other.
00:18:10.173 --> 00:18:17.403
But you're talking about telling a story to the agent who's going to build something for you.
00:18:17.403 --> 00:18:20.727
But I think human to human storytelling, that's a whole different topic.
00:18:20.727 --> 00:18:25.309
I love that topic and maybe we can talk about that again at a later point.
00:18:25.309 --> 00:18:29.551
In the context of programming, I think storytelling is still critical, right?
00:18:29.551 --> 00:18:39.257
Because you have to communicate often in an English language or if you're using a model that can take in a different language, you need to be crisp and clear, right?
00:18:39.257 --> 00:18:51.563
Now, if you think about the history of software programming, how often have you been there before, like how often do you get requirements that you're like, oh I understand exactly what I need to do, right?
00:18:51.563 --> 00:18:53.743
We've not been good at this.
00:18:53.743 --> 00:19:02.138
And in fact, if we go into agentic AI, we need to fundamentally get better at telling the system what is it we want to do.
00:19:02.138 --> 00:19:08.362
Now we won't necessarily get it right the first time also because we might just not know what it is that we want the first time.
00:19:08.362 --> 00:19:11.564
This is where the second part comes in which is critical thinking.
00:19:11.564 --> 00:19:18.627
And again human beings need to develop and continue to develop critical thinking and there's an entirely different human side of it.
00:19:18.627 --> 00:19:23.010
In the programming side of it, it comes back to feedback loops and iterations, right?
00:19:23.010 --> 00:19:24.559
I see a thing.
00:19:24.559 --> 00:19:28.093
I need to know what is what was my original intent.
00:19:28.093 --> 00:19:29.834
What does good look like?
00:19:29.834 --> 00:19:34.155
Because The machine is going to be very happy to give you 50,000 iterations.
00:19:34.155 --> 00:19:42.527
You as a human, as the owner of that outcome, you have to decide which one of those is correct and when you are happy with it, right?
00:19:42.527 --> 00:19:53.460
And when do you go, that's good, let me now, you know, push this change into my Git repo and have my GitOps process take over to do CD effectively, right?
00:19:53.460 --> 00:19:57.990
So those two skills for me are the fundamental skills.
00:19:57.990 --> 00:20:00.762
uh Beyond knowing base programming.
00:20:00.762 --> 00:20:07.960
I think you still need to know a little bit of that and just logic but Look, I was building something in Rust the other day.
00:20:07.960 --> 00:20:23.366
No understanding of Rust at all, right, but I had my my Go script and I said I want to convert this to Rust right and we have a thing called Kiro here and I just put it into Kiro and I said help me convert this to Rust and it took me through it.
00:20:23.366 --> 00:20:24.403
Was it the best?
00:20:24.403 --> 00:20:25.483
Maybe, maybe not.
00:20:25.483 --> 00:20:32.787
I don't know enough to know about it, but I built a working app in Rust that I could put in my POC environment.
00:20:32.787 --> 00:20:44.353
Wouldn't trust to put it into production yet, but I think those skills are still useful, but for me it comes back to can you tell the system what it is you want in a clear, succinct way?
00:20:44.353 --> 00:20:50.855
And then when it gives you something back, can you verify that this is the thing that you wanted out of it?
00:20:50.855 --> 00:20:53.207
And if it's not, rinse and repeat, right?
00:20:53.207 --> 00:20:53.869
Loops.
00:20:53.869 --> 00:20:57.215
Akhil, I think you've summed this up extremely well.
00:20:57.215 --> 00:20:58.939
Always a pleasure talking with you.
00:20:58.939 --> 00:20:59.660
is always.
00:20:59.660 --> 00:21:02.083
Thanks very much for sharing that.
00:21:02.083 --> 00:21:02.646
absolutely.
00:21:02.646 --> 00:21:03.282
Thanks, Jon.
00:21:03.282 --> 00:21:04.048
Cheers.