WEBVTT

00:00:00.680 --> 00:00:03.560
Hey, hey, how are you, man? Good. Well,

00:00:03.560 --> 00:00:05.040
I heard I heard you say this is going to

00:00:05.040 --> 00:00:07.320
be a short call. Yeah, actually I just

00:00:07.320 --> 00:00:09.400
realized like I'm I just jumped off one

00:00:09.400 --> 00:00:10.880
call, but then I see that there was

00:00:10.880 --> 00:00:12.760
another one back to back, but like I'm

00:00:12.760 --> 00:00:14.800
going to be I don't know. There's just

00:00:14.800 --> 00:00:16.520
too many calls, you know. Well, you're

00:00:16.520 --> 00:00:19.280
busy busy guy. Well, I'm good for you

00:00:19.280 --> 00:00:21.200
good for you. I guess you're spinning a

00:00:21.200 --> 00:00:24.200
few plates, right? With Specular and

00:00:24.200 --> 00:00:27.480
I didn't want to do a Specular thing.

00:00:27.480 --> 00:00:30.080
Yeah, and like I think it would be cool.

00:00:30.080 --> 00:00:32.599
Uh so for example, I did one 2-hour

00:00:32.599 --> 00:00:35.120
session with a friend who

00:00:35.120 --> 00:00:37.400
came up with a cool idea and then he

00:00:37.400 --> 00:00:40.320
built a little mock-up in V0 with static

00:00:40.320 --> 00:00:41.920
data and I asked him like is there

00:00:41.920 --> 00:00:43.480
anything you want to build and then we

00:00:43.480 --> 00:00:45.440
do a 2-hour session and if if all goes

00:00:45.440 --> 00:00:47.920
well by the end of it I'll you'll have a

00:00:47.920 --> 00:00:49.880
extra little piece of code on top of it

00:00:49.880 --> 00:00:52.440
that works. Uh basically and and you

00:00:52.440 --> 00:00:53.600
understand a little bit more the Spec

00:00:53.600 --> 00:00:54.920
Driven Development approach.

00:00:54.920 --> 00:00:56.440
>> Yeah.

00:00:56.440 --> 00:00:58.160
I'm keen to do that. Like the thing that

00:00:58.160 --> 00:01:00.600
bothers me, I've got real furor around

00:01:00.600 --> 00:01:02.920
that whole like you hear developers who

00:01:02.920 --> 00:01:05.040
say that like yeah, I've got some agents

00:01:05.040 --> 00:01:08.120
going overnight and you know, while I go

00:01:08.120 --> 00:01:10.640
for to the gym, that the the agents are

00:01:10.640 --> 00:01:12.400
running. But

00:01:12.400 --> 00:01:14.360
when I'm using an agent, it's just like,

00:01:14.360 --> 00:01:16.240
you know, I ask it a couple of things

00:01:16.240 --> 00:01:18.040
and then it stops. Have you managed to

00:01:18.040 --> 00:01:20.160
like run the Spec Ledger overnight and

00:01:20.160 --> 00:01:21.920
you come up with and and then in the

00:01:21.920 --> 00:01:23.320
morning there's a

00:01:23.320 --> 00:01:24.520
there's a there's a fresh new

00:01:24.520 --> 00:01:26.680
implementation. Months ago they had this

00:01:26.680 --> 00:01:29.840
like gas town spice must flow this Dune

00:01:29.840 --> 00:01:32.960
references with like the ideas of

00:01:32.960 --> 00:01:35.600
keeping agents in a loop if they stop

00:01:35.600 --> 00:01:38.360
until the task is complete. Even lately

00:01:38.360 --> 00:01:40.800
auto research is going berserk

00:01:40.800 --> 00:01:43.280
everywhere about people like you give it

00:01:43.280 --> 00:01:44.280
a

00:01:44.280 --> 00:01:45.920
some constraints some experiments to run

00:01:45.920 --> 00:01:48.320
and it iterates against those goals and

00:01:48.320 --> 00:01:50.440
overnight you get like I don't know 45

00:01:50.440 --> 00:01:52.600
50 experiments. I'm just making up

00:01:52.600 --> 00:01:53.160
numbers here.

00:01:53.160 --> 00:01:54.520
>> What's what is auto research? Sorry, I

00:01:54.520 --> 00:01:56.040
didn't get that. Uh auto research is

00:01:56.040 --> 00:01:58.920
from that ex-OpenAI guy and that the guy

00:01:58.920 --> 00:02:01.320
who coined the term fine-coding. I am

00:02:01.320 --> 00:02:02.560
afraid to mispronounce his name,

00:02:02.560 --> 00:02:05.600
Karpathy. Andrej Karpathy. Yeah. So, he

00:02:05.600 --> 00:02:08.160
he he released auto research and he said

00:02:08.160 --> 00:02:10.200
like he does a lot of LLM fine-tuning

00:02:10.200 --> 00:02:13.120
manually and finds optimizations based

00:02:13.120 --> 00:02:15.440
on how he understands the algorithms.

00:02:15.440 --> 00:02:17.800
And he basically formalized the process

00:02:17.800 --> 00:02:21.280
and now he has LLM agents executing

00:02:21.280 --> 00:02:23.520
this. And he says he already had a

00:02:23.520 --> 00:02:26.640
highly manually optimized

00:02:26.640 --> 00:02:29.480
stack and the AI found a lot of

00:02:29.480 --> 00:02:31.200
improvements overnight. They talk about

00:02:31.200 --> 00:02:33.400
numbers. I don't remember them like 30%

00:02:33.400 --> 00:02:34.120
improvement.

00:02:34.120 --> 00:02:35.640
>> This is the work where I feel like I'm

00:02:35.640 --> 00:02:37.120
missing it. I mean, do do you do that

00:02:37.120 --> 00:02:38.760
sort of stuff at Spec Ledger? Get the

00:02:38.760 --> 00:02:41.360
agent working all the time or

00:02:41.360 --> 00:02:43.160
I mean, if we continue a little bit

00:02:43.160 --> 00:02:44.520
about auto research, it's very

00:02:44.520 --> 00:02:45.920
interesting because people are taking

00:02:45.920 --> 00:02:48.240
this from fine-tuning models to actually

00:02:48.240 --> 00:02:51.080
building out features as well. And so,

00:02:51.080 --> 00:02:53.200
you see a lot of posts on Reddit and

00:02:53.200 --> 00:02:55.200
LinkedIn and everywhere from people

00:02:55.200 --> 00:02:57.480
saying I took auto research and I made

00:02:57.480 --> 00:03:00.280
it work on this like product feature.

00:03:00.280 --> 00:03:01.200
Like

00:03:01.200 --> 00:03:03.400
I think there was one famous company, I

00:03:03.400 --> 00:03:05.680
don't remember the name, but they had

00:03:05.680 --> 00:03:08.200
manually fine-tuned templates for their

00:03:08.200 --> 00:03:09.959
template engine. I think it was Shopify.

00:03:09.959 --> 00:03:12.040
Might have been Ruby, I'm not sure. And

00:03:12.040 --> 00:03:14.600
they they had auto research

00:03:14.600 --> 00:03:15.959
improve the performance of those

00:03:15.959 --> 00:03:18.080
templates. So, it basically can work on

00:03:18.080 --> 00:03:20.440
on all kinds of like it's it's it's a

00:03:20.440 --> 00:03:22.160
framework. It's a bit like Ralph Ralph

00:03:22.160 --> 00:03:23.880
Wiggum. It's kind of a loop to to get

00:03:23.880 --> 00:03:24.360
that going.

00:03:24.360 --> 00:03:26.200
>> Okay, I feel like I need to try this. I

00:03:26.200 --> 00:03:27.120
mean, you mentioned

00:03:27.120 --> 00:03:28.959
>> terms of your question that you asked

00:03:28.959 --> 00:03:31.640
three times already, which is have you

00:03:31.640 --> 00:03:33.959
set up agents to run overnight with Spec

00:03:33.959 --> 00:03:38.239
Ledger? And I feel like I'm not like

00:03:38.239 --> 00:03:40.600
Oh, man. Don't let me down.

00:03:40.600 --> 00:03:42.519
>> I just told you this before that even if

00:03:42.519 --> 00:03:44.400
I let if I write the specs and somebody

00:03:44.400 --> 00:03:46.800
else builds it, it's not up to my

00:03:46.800 --> 00:03:49.280
expectation. Even last night, I did

00:03:49.280 --> 00:03:52.080
something really fun. There's like I use

00:03:52.080 --> 00:03:55.440
a certain sauce and they have a CLI but

00:03:55.440 --> 00:03:57.680
it doesn't expose some of the UI

00:03:57.680 --> 00:03:59.000
features. You have to go to the web

00:03:59.000 --> 00:04:00.960
interface to click on this then go there

00:04:00.960 --> 00:04:02.720
and it's very annoying because I have to

00:04:02.720 --> 00:04:04.160
click a whole bunch of buttons to just

00:04:04.160 --> 00:04:06.080
see the error message. Plus it's then

00:04:06.080 --> 00:04:07.680
beautified but it doesn't actually give

00:04:07.680 --> 00:04:09.600
me raw data and ultimately I need that

00:04:09.600 --> 00:04:11.280
data back into the shelf to give it back

00:04:11.280 --> 00:04:13.280
to my agent. So to go and click buttons

00:04:13.280 --> 00:04:14.959
and then to copy out data put it in the

00:04:14.959 --> 00:04:18.160
shelf it's annoying. Yeah. So um

00:04:18.160 --> 00:04:20.440
the agent or Claude Code really cleverly

00:04:20.440 --> 00:04:22.880
found a whole bunch of curl endpoints. I

00:04:22.880 --> 00:04:25.600
I think maybe from public API specs and

00:04:25.600 --> 00:04:27.320
it does a lot of like it fetches my

00:04:27.320 --> 00:04:29.720
credentials from the credential file. It

00:04:29.720 --> 00:04:31.360
puts it you know does a curl with

00:04:31.360 --> 00:04:33.880
authorization like bearer token and then

00:04:33.880 --> 00:04:35.320
it finds the details but there are so

00:04:35.320 --> 00:04:36.919
many curls and then sometimes makes

00:04:36.919 --> 00:04:40.040
mistakes that I just decided hey I want

00:04:40.040 --> 00:04:41.600
to capture all those curls and put them

00:04:41.600 --> 00:04:44.400
into a CLI like a go lang CLI. And just

00:04:44.400 --> 00:04:45.919
to come back to the point right? I

00:04:45.919 --> 00:04:48.000
started with first documenting like some

00:04:48.000 --> 00:04:49.680
markdown so that I could point agent to

00:04:49.680 --> 00:04:51.320
it here's how we did this particular

00:04:51.320 --> 00:04:52.680
step. These are the curls you do this

00:04:52.680 --> 00:04:54.120
particular step. These are the curls you

00:04:54.120 --> 00:04:56.240
do. And so I took that doc and I gave it

00:04:56.240 --> 00:04:58.120
to Spec Ledger say write the user

00:04:58.120 --> 00:05:00.680
stories right as an as an engineer or an

00:05:00.680 --> 00:05:02.440
AI agent I need the command line

00:05:02.440 --> 00:05:05.240
interface to you know trigger this

00:05:05.240 --> 00:05:07.200
particular action and to go fetch the

00:05:07.200 --> 00:05:09.120
logs and to get the the error messages

00:05:09.120 --> 00:05:11.240
and things like that. So it's it's not

00:05:11.240 --> 00:05:13.200
like GitHub actions something different

00:05:13.200 --> 00:05:14.640
because GitHub actions CLI does this

00:05:14.640 --> 00:05:17.760
beautifully right? So um so anyway I got

00:05:17.760 --> 00:05:19.880
Spec Ledger to write the user stories.

00:05:19.880 --> 00:05:21.440
Then I went one step further because I

00:05:21.440 --> 00:05:23.640
had like like two weeks almost of me

00:05:23.640 --> 00:05:25.880
doing this. So I went and I told it now

00:05:25.880 --> 00:05:27.120
you have the user stories you have this

00:05:27.120 --> 00:05:29.280
initial thing. Now go through all of my

00:05:29.280 --> 00:05:31.240
Claude Code sessions look for this

00:05:31.240 --> 00:05:33.960
particular API endpoint and find any

00:05:33.960 --> 00:05:36.080
usage scenario where this was where this

00:05:36.080 --> 00:05:38.040
was being used and what was the usage

00:05:38.040 --> 00:05:39.520
what was the use case how was it was it

00:05:39.520 --> 00:05:41.640
being used why was it being used?

00:05:41.640 --> 00:05:43.120
>> That's pretty much what you said.

00:05:43.120 --> 00:05:45.040
>> Look through your cloud sessions but

00:05:45.040 --> 00:05:47.240
carry on. And yeah I mean like I like I

00:05:47.240 --> 00:05:49.040
said I I am not using the automation and

00:05:49.040 --> 00:05:50.640
often I have way too many tokens right

00:05:50.640 --> 00:05:52.680
now. So, I'm like, just go ahead and use

00:05:52.680 --> 00:05:54.000
as many tokens as you want because I'm

00:05:54.000 --> 00:05:55.720
running out like it's the end of the

00:05:55.720 --> 00:05:56.960
hitting the end of the week and I still

00:05:56.960 --> 00:05:58.960
have like used only 40% of my tokens.

00:05:58.960 --> 00:06:01.360
So, just like over 2 hours just go and

00:06:01.360 --> 00:06:04.720
explore. And it found like three or more

00:06:04.720 --> 00:06:06.920
usage scenarios where the AI agent was

00:06:06.920 --> 00:06:08.400
like, yeah, your document talks about

00:06:08.400 --> 00:06:09.960
these things, but there's a couple of

00:06:09.960 --> 00:06:11.520
cases where the agent was trying to do

00:06:11.520 --> 00:06:13.240
this and and it didn't work well with

00:06:13.240 --> 00:06:15.480
the curls. So, it added those in. And

00:06:15.480 --> 00:06:17.360
then ultimately I had a beautiful spec,

00:06:17.360 --> 00:06:18.880
right? I had a wonderful spec. This is

00:06:18.880 --> 00:06:21.760
the CLI. I have my whole design of how I

00:06:21.760 --> 00:06:23.880
want it. I wrote the plan and there was

00:06:23.880 --> 00:06:26.560
just like 40 tasks which like in the

00:06:26.560 --> 00:06:29.120
past I would hit 80 tasks, right? And

00:06:29.120 --> 00:06:31.000
after 80 tasks I would say 80 tasks is

00:06:31.000 --> 00:06:32.520
too much. It will definitely go RE, it

00:06:32.520 --> 00:06:34.720
will not go well. And I included E2E

00:06:34.720 --> 00:06:36.640
like it uses Go lang so it uses VCR

00:06:36.640 --> 00:06:39.200
cassettes to like replay HTTP because it

00:06:39.200 --> 00:06:41.040
I'm I'm I'm working against an API

00:06:41.040 --> 00:06:42.520
server, right? So, I'm running

00:06:42.520 --> 00:06:43.880
end-to-end with

00:06:43.880 --> 00:06:45.320
>> VCR cassettes I've never heard of that.

00:06:45.320 --> 00:06:47.440
I've heard of HTTP test.

00:06:47.440 --> 00:06:49.720
Yeah, I I think it's using like a local

00:06:49.720 --> 00:06:53.120
HTTP test server, but it's replaying

00:06:53.120 --> 00:06:55.600
responses from like cassettes from like

00:06:55.600 --> 00:06:58.520
on on on disk snapshots of what the API

00:06:58.520 --> 00:07:00.400
returns from what it observed in the

00:07:00.400 --> 00:07:03.720
past. So, wonderful, right? 40 tasks,

00:07:03.720 --> 00:07:05.520
VCR cassettes, cassettes, end-to-end

00:07:05.520 --> 00:07:07.760
testing, CLI fully defined. This is

00:07:07.760 --> 00:07:09.440
perfect, you should go to sleep, right?

00:07:09.440 --> 00:07:11.320
And you should just let it let it run.

00:07:11.320 --> 00:07:13.880
But, you know, 40 cloud takes maybe 30

00:07:13.880 --> 00:07:15.400
minutes to implement this stuff, right?

00:07:15.400 --> 00:07:17.640
Very fast. And then it finished the

00:07:17.640 --> 00:07:19.480
first session. I think I did cut off

00:07:19.480 --> 00:07:21.680
after the the spec, but I did keep the

00:07:21.680 --> 00:07:23.200
same session because I'm using 1 million

00:07:23.200 --> 00:07:25.560
tokens and I was only at like 15% so

00:07:25.560 --> 00:07:28.840
that's like 150,000. And if I hit 20%

00:07:28.840 --> 00:07:30.880
that's 200,000 tokens, then I'm already

00:07:30.880 --> 00:07:32.200
at like

00:07:32.200 --> 00:07:35.280
50 over 50% of my 400k even though I'm

00:07:35.280 --> 00:07:37.640
on 1 million tokens, when I hit 20% I

00:07:37.640 --> 00:07:39.800
usually clear it because even if you

00:07:39.800 --> 00:07:41.880
have 1 million, if you go over 20% it

00:07:41.880 --> 00:07:44.440
starts to degrade. Are you using Sonnet

00:07:44.440 --> 00:07:46.880
or uh Opus. I'm on Max, right? So, I'm

00:07:46.880 --> 00:07:49.160
on like on Opus 4.6 with 1 million token

00:07:49.160 --> 00:07:51.000
context window.

00:07:51.000 --> 00:07:53.360
Yeah, I got I got promo because like in

00:07:53.360 --> 00:07:56.880
Copilot like Opus says 3x, so I don't

00:07:56.880 --> 00:07:59.240
click Opus and hence I'm not getting the

00:07:59.240 --> 00:08:00.480
good stuff.

00:08:00.480 --> 00:08:02.240
Yeah, so so what happened then is it

00:08:02.240 --> 00:08:03.680
completed the task very quickly,

00:08:03.680 --> 00:08:06.000
implemented the CLI. I asked it to use

00:08:06.000 --> 00:08:07.840
the CLI and it did great. Like I gave it

00:08:07.840 --> 00:08:10.480
the original curl scenarios and it says

00:08:10.480 --> 00:08:12.880
run these scenarios with the CLI and it

00:08:12.880 --> 00:08:13.880
did everything and it worked

00:08:13.880 --> 00:08:16.120
wonderfully. And then I asked any

00:08:16.120 --> 00:08:18.280
divergence from plan. Oh, yeah. The plan

00:08:18.280 --> 00:08:19.520
said I should put everything under

00:08:19.520 --> 00:08:22.000
package golang directory, but I put it

00:08:22.000 --> 00:08:23.760
all under under internal, which means

00:08:23.760 --> 00:08:25.240
it's an internal module you can't use it

00:08:25.240 --> 00:08:27.320
from other golang library as a library,

00:08:27.320 --> 00:08:28.960
right? I said, "Okay, not a big deal,

00:08:28.960 --> 00:08:30.280
but why did you diverge from plan,

00:08:30.280 --> 00:08:31.840
right?" It says, "Oh, somewhere it said

00:08:31.840 --> 00:08:33.800
something like it didn't put it in where

00:08:33.800 --> 00:08:35.479
I expected it." I guess the agent

00:08:35.479 --> 00:08:37.599
decided this was an internal utility and

00:08:37.599 --> 00:08:38.840
therefore it shouldn't be an external

00:08:38.840 --> 00:08:40.159
contract, therefore it needs to go in

00:08:40.159 --> 00:08:42.159
internal. This is a diversion from plan.

00:08:42.159 --> 00:08:44.280
It pisses me off, right? Cuz I give you

00:08:44.280 --> 00:08:46.440
a very clear plan and for some reason

00:08:46.440 --> 00:08:48.080
you do it differently. Then the second

00:08:48.080 --> 00:08:49.520
thing is, "All right, now run the end to

00:08:49.520 --> 00:08:50.760
ends.

00:08:50.760 --> 00:08:52.480
Run the end to end, right? With a

00:08:52.480 --> 00:08:54.160
clearly told you to build end to end."

00:08:54.160 --> 00:08:56.040
Oh, yeah, "No, no, end to end were

00:08:56.040 --> 00:08:57.480
marked as out of scope." What are you

00:08:57.480 --> 00:08:59.560
talking about? It wasn't out of scope.

00:08:59.560 --> 00:09:01.160
>> So, this seems to be a theme. We've

00:09:01.160 --> 00:09:03.400
talked about this before where the AI

00:09:03.400 --> 00:09:05.680
doesn't quite do what you want it to do.

00:09:05.680 --> 00:09:07.240
So, are you getting Do you think you're

00:09:07.240 --> 00:09:08.520
getting any

00:09:08.520 --> 00:09:11.320
any better at controlling the AI from

00:09:11.320 --> 00:09:12.320
going off piste?

00:09:12.320 --> 00:09:14.280
>> Builds. I haven't built the the Gerkin

00:09:14.280 --> 00:09:15.800
integration yet, right? What we talked

00:09:15.800 --> 00:09:18.200
about BDD. Do you think Gerkin will pull

00:09:18.200 --> 00:09:20.160
it straight? Hopefully, because it

00:09:20.160 --> 00:09:21.680
should write them first, right? It

00:09:21.680 --> 00:09:23.800
should write all the BDDs first and then

00:09:23.800 --> 00:09:25.320
it should not stop until the BDDs pass.

00:09:25.320 --> 00:09:26.839
>> sense. Like you you have your spec and

00:09:26.839 --> 00:09:30.720
then you have have your your test BDD.

00:09:30.720 --> 00:09:33.160
And then that should be the guardrails

00:09:33.160 --> 00:09:35.800
going forward. Yeah, so that's the thing

00:09:35.800 --> 00:09:37.760
that pisses me off and that makes me

00:09:37.760 --> 00:09:41.360
reluctant to let an agent's team run off

00:09:41.360 --> 00:09:42.480
like loose.

00:09:42.480 --> 00:09:44.680
>> I see. I see where your your point is

00:09:44.680 --> 00:09:45.840
that you don't want to make it run

00:09:45.840 --> 00:09:47.200
overnight because you think it's just

00:09:47.200 --> 00:09:49.440
going to go wrong anyway. Yeah.

00:09:49.440 --> 00:09:50.160
Um,

00:09:50.160 --> 00:09:52.240
but to come back to like Claude has made

00:09:52.240 --> 00:09:54.120
a lot of releases that make it much

00:09:54.120 --> 00:09:56.600
easier to leave your machine and then,

00:09:56.600 --> 00:09:58.200
you know, check in and then kick it back

00:09:58.200 --> 00:09:59.160
off.

00:09:59.160 --> 00:10:00.120
Yeah.

00:10:00.120 --> 00:10:02.240
I haven't really activated them yet, but

00:10:02.240 --> 00:10:04.000
like you can /remote and then it

00:10:04.000 --> 00:10:06.400
will it makes your your laptop

00:10:06.400 --> 00:10:08.360
accessible through the app. So, you can

00:10:08.360 --> 00:10:09.840
be on your phone and then you can check

00:10:09.840 --> 00:10:11.480
if the what's the status Yeah, those

00:10:11.480 --> 00:10:12.760
those features sound great. I mean,

00:10:12.760 --> 00:10:14.720
unfortunately, my employer gives me

00:10:14.720 --> 00:10:17.240
Anthropic via like an API key. So, all

00:10:17.240 --> 00:10:19.520
those like quality of life features like

00:10:19.520 --> 00:10:22.040
voice, mobile, all those features are

00:10:22.040 --> 00:10:24.080
actually not enabled in my Claude code.

00:10:24.080 --> 00:10:26.440
Yeah. Do you do you use voice yourself?

00:10:26.440 --> 00:10:28.760
Yeah, um, I did it on the demo, right?

00:10:28.760 --> 00:10:31.400
With my friend and I like it, but I

00:10:31.400 --> 00:10:33.320
rarely use it because

00:10:33.320 --> 00:10:35.360
to me, while I type, I formulate my

00:10:35.360 --> 00:10:37.960
thoughts and when I speak, I will

00:10:37.960 --> 00:10:40.160
misspeak and then I have to go back and

00:10:40.160 --> 00:10:42.960
delete part of the Oh, that's not clever

00:10:42.960 --> 00:10:45.120
cuz like I think some of them are kind

00:10:45.120 --> 00:10:47.360
of clever enough to like

00:10:47.360 --> 00:10:48.760
I think it's a very fine line.

00:10:48.760 --> 00:10:50.600
>> respond or something. It's a fine line

00:10:50.600 --> 00:10:52.720
between being like clever and and like

00:10:52.720 --> 00:10:54.160
shortcutting and clearly seeing where

00:10:54.160 --> 00:10:55.680
the user what said something and they

00:10:55.680 --> 00:10:57.800
meant something cuz sometime it

00:10:57.800 --> 00:10:59.200
misunderstands me because of my

00:10:59.200 --> 00:11:00.880
beautiful accent and then it comes up

00:11:00.880 --> 00:11:03.000
with this weird word and then it tries

00:11:03.000 --> 00:11:04.200
to make sense of it and then it would

00:11:04.200 --> 00:11:05.760
delete half my sentence, not Claude

00:11:05.760 --> 00:11:07.320
code, but I've seen that happen in some

00:11:07.320 --> 00:11:09.440
other tools and I was like, okay, Yeah,

00:11:09.440 --> 00:11:11.320
the dictation is always one of those

00:11:11.320 --> 00:11:13.960
things that never quite works very well.

00:11:13.960 --> 00:11:15.440
I mean, like I was just thinking

00:11:15.440 --> 00:11:18.360
yesterday like my as try as try as I may

00:11:18.360 --> 00:11:20.400
to like optimize my my workflow. Like

00:11:20.400 --> 00:11:22.440
when I when I write my to-do list I'm on

00:11:22.440 --> 00:11:24.200
a piece of paper in the morning that

00:11:24.200 --> 00:11:26.120
that just seems to work the best for me.

00:11:26.120 --> 00:11:28.240
Like I want to dictate some ideas, but

00:11:28.240 --> 00:11:30.280
and then they they sort of get lost in

00:11:30.280 --> 00:11:32.680
voice recorder or they never

00:11:32.680 --> 00:11:34.800
they never comes back out. So does that

00:11:34.800 --> 00:11:36.520
Did I answer your question about

00:11:36.520 --> 00:11:39.000
>> Yeah, I guess you did, but like

00:11:39.000 --> 00:11:40.440
blame

00:11:40.440 --> 00:11:41.920
I need to figure this out myself,

00:11:41.920 --> 00:11:44.040
obviously. Can you hit your table? Hit

00:11:44.040 --> 00:11:45.520
your table.

00:11:45.520 --> 00:11:47.400
I I

00:11:47.400 --> 00:11:48.480
Wow.

00:11:48.480 --> 00:11:50.840
I got it on like a stand now. So I

00:11:50.840 --> 00:11:52.920
listen to the feedback. Thank you,

00:11:52.920 --> 00:11:55.120
whoever gave me feedback.

00:11:55.120 --> 00:11:56.760
Well, it bothered you and honestly, I

00:11:56.760 --> 00:11:58.560
also noticed your camera shaking last

00:11:58.560 --> 00:11:59.160
time. I

00:11:59.160 --> 00:12:01.400
>> Yeah, so I fixed

00:12:01.400 --> 00:12:02.600
And

00:12:02.600 --> 00:12:04.320
are you going to fix your your headset

00:12:04.320 --> 00:12:05.840
or you going to get a road headset or

00:12:05.840 --> 00:12:08.520
something? Like a proper What do you

00:12:08.520 --> 00:12:10.640
mean? Like a proper microphone? Is Yeah,

00:12:10.640 --> 00:12:13.120
like the road stuff is is pretty good

00:12:13.120 --> 00:12:15.760
from Australia.

00:12:15.760 --> 00:12:16.600
Australia?

00:12:16.600 --> 00:12:18.480
>> No.

00:12:18.480 --> 00:12:20.280
Oh, the weather is so bad here. How's

00:12:20.280 --> 00:12:22.080
the weather in Vietnam? Just tell me

00:12:22.080 --> 00:12:22.200
it's

00:12:22.200 --> 00:12:23.480
>> You're the third person who asked me

00:12:23.480 --> 00:12:24.880
this.

00:12:24.880 --> 00:12:26.440
Tell me it's beautiful.

00:12:26.440 --> 00:12:29.160
It's beautiful. Um oh yeah, thanks for

00:12:29.160 --> 00:12:30.680
sharing those Reddit links about the

00:12:30.680 --> 00:12:32.960
trivia thing. I always thought to myself

00:12:32.960 --> 00:12:34.280
that

00:12:34.280 --> 00:12:35.920
that one day someone's going to do a

00:12:35.920 --> 00:12:38.160
sneaky attack with the

00:12:38.160 --> 00:12:40.720
get orphan commits because I even I've

00:12:40.720 --> 00:12:42.520
noticed that myself sometimes that when

00:12:42.520 --> 00:12:44.160
I'm messing around the branches and I

00:12:44.160 --> 00:12:46.000
delete a branch, if you know the commit

00:12:46.000 --> 00:12:48.640
hash, you can you can pull stuff out

00:12:48.640 --> 00:12:49.560
from

00:12:49.560 --> 00:12:51.320
from the nether. Yeah, it's crazy,

00:12:51.320 --> 00:12:53.839
right? It's like even even very early on

00:12:53.839 --> 00:12:55.160
in my career when I pushed my

00:12:55.160 --> 00:12:56.880
credentials to the to get up like

00:12:56.880 --> 00:12:58.600
everyone does.

00:12:58.600 --> 00:13:01.240
Not me. I'm not a fool. Oh, yeah. Well,

00:13:01.240 --> 00:13:03.560
not yet then. So um

00:13:03.560 --> 00:13:05.720
So then you learn very early on that to

00:13:05.720 --> 00:13:07.560
remove credentials from a get commit is

00:13:07.560 --> 00:13:10.480
not sufficient to to just like go and

00:13:10.480 --> 00:13:11.560
rewrite rebase

00:13:11.560 --> 00:13:12.760
>> Actually, I've never done it. So what do

00:13:12.760 --> 00:13:14.240
you What do you have to do? Just delete

00:13:14.240 --> 00:13:16.160
the repo and start again or what did you

00:13:16.160 --> 00:13:18.280
do? You have to rotate your credentials.

00:13:18.280 --> 00:13:20.200
They are gone.

00:13:20.200 --> 00:13:22.720
Even if you go and rebase interactively

00:13:22.720 --> 00:13:24.560
and rewrite history and push that,

00:13:24.560 --> 00:13:26.400
GitHub doesn't garbage collect those

00:13:26.400 --> 00:13:29.680
commits. So there are bots that are

00:13:29.680 --> 00:13:32.560
watching for for events and they will

00:13:32.560 --> 00:13:34.160
find those commits and then they will

00:13:34.160 --> 00:13:36.440
delete the data. GitHub does check for

00:13:36.440 --> 00:13:38.920
credential stuff nowadays, I do believe.

00:13:38.920 --> 00:13:41.320
Yeah, and a lot of yeah, even definitely

00:13:41.320 --> 00:13:43.440
if you push a personal access token,

00:13:43.440 --> 00:13:44.920
right? It will immediately go send you a

00:13:44.920 --> 00:13:46.640
notification like we revoked your PAT.

00:13:46.640 --> 00:13:47.160
>> Yeah.

00:13:47.160 --> 00:13:49.400
Cuz you pushed it. God damn it. That's

00:13:49.400 --> 00:13:50.960
what I I wanted you to share the PAT.

00:13:50.960 --> 00:13:52.000
Well, I'm trying to actually work it

00:13:52.000 --> 00:13:53.360
Have you ever worked with GitHub apps?

00:13:53.360 --> 00:13:54.680
That's the thing I'm supposed to do at

00:13:54.680 --> 00:13:56.520
work, but it's quite confusing and I'm

00:13:56.520 --> 00:13:57.400
just wondering

00:13:57.400 --> 00:13:59.480
>> Yeah, GitHub apps are my favorite

00:13:59.480 --> 00:14:01.200
>> Something weird about it. way to

00:14:01.200 --> 00:14:03.080
interact with the GitHub because so

00:14:03.080 --> 00:14:05.560
there's yeah, I mean GitHub apps are the

00:14:05.560 --> 00:14:07.600
ideal way to manage automation because

00:14:07.600 --> 00:14:09.400
you can create them inside your

00:14:09.400 --> 00:14:11.520
organization as an app, keep them

00:14:11.520 --> 00:14:13.480
internal, and then you can install them

00:14:13.480 --> 00:14:16.240
into repositories, and there's no single

00:14:16.240 --> 00:14:18.280
like if you if you say you use the old

00:14:18.280 --> 00:14:20.040
way, which is create a machine user,

00:14:20.040 --> 00:14:22.400
which create an account into your org.

00:14:22.400 --> 00:14:24.680
>> Well, basically a PAT. What do you mean

00:14:24.680 --> 00:14:26.480
Yeah, you could give your personal PAT,

00:14:26.480 --> 00:14:27.800
but usually you don't do that, right?

00:14:27.800 --> 00:14:29.240
So, you create a dedicated

00:14:29.240 --> 00:14:31.200
>> people create automation accounts for

00:14:31.200 --> 00:14:32.000
it, but yeah, that's

00:14:32.000 --> 00:14:33.480
>> but then you have to buy a license seat

00:14:33.480 --> 00:14:35.120
for it. So, you have to pay for that as

00:14:35.120 --> 00:14:36.000
a license seat.

00:14:36.000 --> 00:14:38.440
>> Yeah. And then you have to like find a

00:14:38.440 --> 00:14:40.240
way to share access to that account. And

00:14:40.240 --> 00:14:42.360
you have to log in to access the PAT and

00:14:42.360 --> 00:14:45.360
control like if you even use this create

00:14:45.360 --> 00:14:47.200
what's it called granular Yeah, and make

00:14:47.200 --> 00:14:48.800
a long you have to make a long-lived

00:14:48.800 --> 00:14:51.600
PAT. It's very very yeah, annoying. And

00:14:51.600 --> 00:14:53.839
then if you use GitHub apps, you

00:14:53.839 --> 00:14:55.600
basically can dedicate app

00:14:55.600 --> 00:14:57.440
administrators within the organization,

00:14:57.440 --> 00:14:59.280
and they can then modify and request

00:14:59.280 --> 00:15:00.520
permissions, and then they can be

00:15:00.520 --> 00:15:02.440
reviewed and applied, which is way more

00:15:02.440 --> 00:15:04.040
better than a PAT. It is better, but

00:15:04.040 --> 00:15:05.400
like for some reason I think maybe it's

00:15:05.400 --> 00:15:07.920
just there's some disconnect between the

00:15:07.920 --> 00:15:10.200
powers that be who administer this

00:15:10.200 --> 00:15:12.080
GitHub Enterprise that I'm

00:15:12.080 --> 00:15:13.800
it there's some weird permission problem

00:15:13.800 --> 00:15:16.200
and I can't roll the specific Yeah, I

00:15:16.200 --> 00:15:18.280
wouldn't want to be like the first time

00:15:18.280 --> 00:15:19.880
I worked with GitHub

00:15:19.880 --> 00:15:21.880
PAT like sorry, not personal access

00:15:21.880 --> 00:15:23.880
tokens, but actual proper apps. I had

00:15:23.880 --> 00:15:26.600
full admin, so I could see everything.

00:15:26.600 --> 00:15:29.280
And I wouldn't want or wish upon anyone

00:15:29.280 --> 00:15:31.080
to try and roll out GitHub apps without

00:15:31.080 --> 00:15:33.040
having visibility in like what that

00:15:33.040 --> 00:15:35.120
Yeah, yeah. I I hate that sort of like

00:15:35.120 --> 00:15:36.920
dark pattern when you log in and you

00:15:36.920 --> 00:15:38.720
think you you can see everything.

00:15:38.720 --> 00:15:40.600
>> tell any anyone to say go and do this, I

00:15:40.600 --> 00:15:41.960
need this permission if you can't see

00:15:41.960 --> 00:15:43.240
what is exactly missing.

00:15:43.240 --> 00:15:45.880
>> Exactly. And really this is this is the

00:15:45.880 --> 00:15:47.120
thing I'm hitting my head on when I

00:15:47.120 --> 00:15:49.160
Yeah, so I would recommend create your

00:15:49.160 --> 00:15:51.160
own GitHub app and your own account and

00:15:51.160 --> 00:15:52.480
play around with that to understand how

00:15:52.480 --> 00:15:54.480
it works. I think the most important

00:15:54.480 --> 00:15:56.440
thing to understand is that a GitHub app

00:15:56.440 --> 00:15:58.760
has an identity and it needs to use that

00:15:58.760 --> 00:16:01.680
identity against an installation to get

00:16:01.680 --> 00:16:04.560
a token for then doing activity within a

00:16:04.560 --> 00:16:07.360
repository. So the app identity itself

00:16:07.360 --> 00:16:09.120
does not give you any permission. It's

00:16:09.120 --> 00:16:10.880
the identity plus the installation

00:16:10.880 --> 00:16:12.920
identity, so the app identity plus the

00:16:12.920 --> 00:16:15.280
installation identity together that you

00:16:15.280 --> 00:16:16.960
need to use to get access to a

00:16:16.960 --> 00:16:19.320
repository. That's the only way that you

00:16:19.320 --> 00:16:22.880
need to get um a short-lived token

00:16:22.880 --> 00:16:24.760
from your installation. And and that's

00:16:24.760 --> 00:16:25.920
basically the hardest thing to

00:16:25.920 --> 00:16:28.760
understand because you got a app ID, you

00:16:28.760 --> 00:16:30.839
got a secret key, then you have an

00:16:30.839 --> 00:16:32.760
installation ID, and then you need to

00:16:32.760 --> 00:16:35.120
get a a short-lived token

00:16:35.120 --> 00:16:37.160
to to be able to do things. And it's

00:16:37.160 --> 00:16:39.160
like That makes sense. Spea- Speaking of

00:16:39.160 --> 00:16:41.120
this sort of authentication, so another

00:16:41.120 --> 00:16:43.040
another thing I'm I'm working on is like

00:16:43.040 --> 00:16:45.520
we we have an estate with like 50-plus

00:16:45.520 --> 00:16:48.440
accounts. And uh previously I was being

00:16:48.440 --> 00:16:51.360
quite happy with AWS SSO, but I think

00:16:51.360 --> 00:16:52.839
there's been some advancements. I I

00:16:52.839 --> 00:16:54.400
don't know. Have you ever had the I

00:16:54.400 --> 00:16:56.480
don't know what the new AWS switching

00:16:56.480 --> 00:16:58.760
user experience is like. I mean

00:16:58.760 --> 00:17:01.120
do you ever use multiple sessions and

00:17:01.120 --> 00:17:02.400
switch accounts?

00:17:02.400 --> 00:17:04.120
>> I'm I've I've found something that works

00:17:04.120 --> 00:17:06.000
really well for me and I have not been

00:17:06.000 --> 00:17:07.800
following what are the new ways to do

00:17:07.800 --> 00:17:11.760
things. I used AWS Vault, which is from

00:17:11.760 --> 00:17:13.439
9 Designs, but they no longer

00:17:13.439 --> 00:17:15.520
maintaining it. And it was moved over to

00:17:15.520 --> 00:17:17.839
another maintainer, which probably is

00:17:17.839 --> 00:17:19.040
scary about the last

00:17:19.040 --> 00:17:20.760
>> I mean you assume or something like

00:17:20.760 --> 00:17:23.400
that? Which one? Assume? No. I've heard

00:17:23.400 --> 00:17:25.000
about other There was one famous one

00:17:25.000 --> 00:17:26.880
that even the AWS people were using and

00:17:26.880 --> 00:17:29.160
it was something It was the idea of like

00:17:29.160 --> 00:17:31.280
you you basically have your credential

00:17:31.280 --> 00:17:32.960
management as a platform and then you

00:17:32.960 --> 00:17:34.480
just allocate it to users and then the

00:17:34.480 --> 00:17:35.960
users could just very quickly switch

00:17:35.960 --> 00:17:37.640
roles. It was a service, but then they

00:17:37.640 --> 00:17:39.040
became full paid. It was used to be

00:17:39.040 --> 00:17:40.320
free. It's something like Jump or

00:17:40.320 --> 00:17:42.080
something. Yeah, yeah, that sounds

00:17:42.080 --> 00:17:42.760
familiar. That's

00:17:42.760 --> 00:17:45.040
>> But I never used that. I used AWS Vault.

00:17:45.040 --> 00:17:46.880
I've been so happy with it because it

00:17:46.880 --> 00:17:48.560
can even run as a demon. Like if you

00:17:48.560 --> 00:17:50.040
want to do a Terraform apply, it can

00:17:50.040 --> 00:17:52.720
refresh tokens in the background. It can

00:17:52.720 --> 00:17:53.400
um

00:17:53.400 --> 00:17:54.720
it can do a lot of things.

00:17:54.720 --> 00:17:56.960
>> I I guess when I I got I have a bit of

00:17:56.960 --> 00:17:58.880
PTSD when it comes to Vault. You know

00:17:58.880 --> 00:18:00.040
It's not HashiCorp Vault.

00:18:00.040 --> 00:18:02.000
>> It's not HashiCorp Vault.

00:18:02.000 --> 00:18:05.400
No, no, AWS Vault is a Go binary that

00:18:05.400 --> 00:18:07.600
uses your keychain on my quest Darwin it

00:18:07.600 --> 00:18:09.160
uses your keychain. But if you're on

00:18:09.160 --> 00:18:10.800
Ubuntu, you can you have to have a a

00:18:10.800 --> 00:18:13.080
secure backend and the most common or

00:18:13.080 --> 00:18:15.440
default one on Ubuntu is pass. Uh sorry,

00:18:15.440 --> 00:18:18.200
pass, p a s s. So that takes a bit of

00:18:18.200 --> 00:18:20.400
time to set up. So I just have onboarded

00:18:20.400 --> 00:18:22.520
someone a while ago and he and he was on

00:18:22.520 --> 00:18:24.480
Windows and I told him set up WSL and

00:18:24.480 --> 00:18:27.960
then set up Ubuntu VM and then use pass.

00:18:27.960 --> 00:18:29.800
And there's actually a couple of steps

00:18:29.800 --> 00:18:32.040
to like set up GPG and all that to to

00:18:32.040 --> 00:18:34.800
encrypt your your secrets backend. If

00:18:34.800 --> 00:18:36.640
you're on macOS, it's all keychain and

00:18:36.640 --> 00:18:38.360
no problem. You can you know finger

00:18:38.360 --> 00:18:40.200
fingerprint authenticated. It's pretty

00:18:40.200 --> 00:18:40.440
cool.

00:18:40.440 --> 00:18:41.280
>> Yeah, I

00:18:41.280 --> 00:18:42.760
I've I've used

00:18:42.760 --> 00:18:43.920
like that before. I was just thinking

00:18:43.920 --> 00:18:46.440
more AWS native solutions. And then the

00:18:46.440 --> 00:18:48.600
other Speaking of AWS native solutions,

00:18:48.600 --> 00:18:50.400
I've always found like when you have a

00:18:50.400 --> 00:18:53.080
bazillion AWS accounts,

00:18:53.080 --> 00:18:55.960
like grabbing CloudWatch logs from from

00:18:55.960 --> 00:18:57.360
all those accounts and putting them in a

00:18:57.360 --> 00:18:59.680
one central place. That's usually There

00:18:59.680 --> 00:19:02.160
is some sort of like AWS pattern for it,

00:19:02.160 --> 00:19:03.840
but it's just a nightmare if I remember

00:19:03.840 --> 00:19:05.440
correctly. Like you have to set up

00:19:05.440 --> 00:19:06.720
Kinesis. I can't remember what you have

00:19:06.720 --> 00:19:08.600
to do exactly. And then most people just

00:19:08.600 --> 00:19:10.920
end up setting up DataDog or or and then

00:19:10.920 --> 00:19:12.240
paying through the nose for DataDog. I

00:19:12.240 --> 00:19:15.120
was just curious if you have a go-to way

00:19:15.120 --> 00:19:17.680
of collecting logs from multiple

00:19:17.680 --> 00:19:20.640
accounts. Oh, huh. You know what happens

00:19:20.640 --> 00:19:22.400
when you set up control tower on AWS

00:19:22.400 --> 00:19:24.000
organization, it sets up this really

00:19:24.000 --> 00:19:27.320
advanced um log like audit account and

00:19:27.320 --> 00:19:29.800
it sets up forward like rules

00:19:29.800 --> 00:19:31.400
automatically like like the moment you

00:19:31.400 --> 00:19:33.760
activate control tower, creates like you

00:19:33.760 --> 00:19:34.840
have your maintenance account, it

00:19:34.840 --> 00:19:36.200
creates your audit account, it creates

00:19:36.200 --> 00:19:37.600
your security hub account

00:19:37.600 --> 00:19:38.720
>> so it like sets up like a

00:19:38.720 --> 00:19:41.080
well-architected Yeah, it immediately

00:19:41.080 --> 00:19:43.320
like uh deploys bunch of cloud formation

00:19:43.320 --> 00:19:44.840
stacks all over the place.

00:19:44.840 --> 00:19:46.200
>> I don't think I have access to that in

00:19:46.200 --> 00:19:48.120
my organization, so that's not cool, is

00:19:48.120 --> 00:19:48.480
it?

00:19:48.480 --> 00:19:49.800
>> Yeah. Um

00:19:49.800 --> 00:19:51.720
and then it creates a centralized log

00:19:51.720 --> 00:19:53.200
account and it and it sets up the all

00:19:53.200 --> 00:19:55.120
the forwarding for it as well. I

00:19:55.120 --> 00:19:56.960
remember that it I had to like figure

00:19:56.960 --> 00:19:58.520
out how that worked to kind of disable

00:19:58.520 --> 00:20:00.640
things because it was costing money and

00:20:00.640 --> 00:20:02.040
like I I don't know there were some

00:20:02.040 --> 00:20:04.040
things, but like I was impressed by the

00:20:04.040 --> 00:20:06.000
amount of configuration it did to

00:20:06.000 --> 00:20:08.320
basically fetch all of the logs and

00:20:08.320 --> 00:20:10.000
across all of the organization accounts.

00:20:10.000 --> 00:20:11.200
It's not trivial when you do it

00:20:11.200 --> 00:20:13.280
manually, I must say. I've I've done it

00:20:13.280 --> 00:20:15.480
in the past and it was pain. So when I

00:20:15.480 --> 00:20:17.000
when I onboard like when I have

00:20:17.000 --> 00:20:19.960
Terraform onto an org, I usually have my

00:20:19.960 --> 00:20:22.920
Datadog integration module, which I it's

00:20:22.920 --> 00:20:24.360
a wrapper around the cloud formation

00:20:24.360 --> 00:20:26.120
stacks that Datadog maintains because

00:20:26.120 --> 00:20:27.520
they don't maintain Terraform modules,

00:20:27.520 --> 00:20:29.040
they give you a cloud formation stack.

00:20:29.040 --> 00:20:32.360
>> Oh yeah. So what I did is I parsed out

00:20:32.360 --> 00:20:34.160
the stack the stack variables into

00:20:34.160 --> 00:20:36.280
Terraform variables and I can invoke the

00:20:36.280 --> 00:20:38.240
module and control all of the services

00:20:38.240 --> 00:20:40.160
that are enabled on the accounts like

00:20:40.160 --> 00:20:41.800
disable everything by default explicit

00:20:41.800 --> 00:20:44.400
opt-in because if you have a Datadog

00:20:44.400 --> 00:20:46.280
enabled on your AWS account

00:20:46.280 --> 00:20:48.040
>> to pull the metrics and it starts to

00:20:48.040 --> 00:20:49.840
scrape everything and then you get a

00:20:49.840 --> 00:20:52.320
huge AWS bill because Datadog constantly

00:20:52.320 --> 00:20:54.720
keeps talking to those endpoints.

00:20:54.720 --> 00:20:56.800
>> One thing that we ran into work is that

00:20:56.800 --> 00:20:59.320
the the SLA or whatever for for the

00:20:59.320 --> 00:21:01.320
metrics is actually really slow. I think

00:21:01.320 --> 00:21:03.360
they like it's about 15 minutes by

00:21:03.360 --> 00:21:05.200
default or something. So like if you

00:21:05.200 --> 00:21:07.760
have it in production That's CloudWatch.

00:21:07.760 --> 00:21:10.120
That's like the default AWS um uh you

00:21:10.120 --> 00:21:11.760
have you can you have to go like you

00:21:11.760 --> 00:21:13.520
have to go and say I want more

00:21:13.520 --> 00:21:14.920
aggressive, but then you have to

00:21:14.920 --> 00:21:16.560
acknowledge that it will cost money.

00:21:16.560 --> 00:21:18.680
>> Yeah. So the 15 minute one is default.

00:21:18.680 --> 00:21:20.360
It's not a DataDog problem to be clear,

00:21:20.360 --> 00:21:22.840
but it's but it ultimately when you set

00:21:22.840 --> 00:21:25.120
up DataDog on on AWS you see this

00:21:25.120 --> 00:21:27.120
problem often like why why didn't we see

00:21:27.120 --> 00:21:30.240
this problem earlier? Like well, this is

00:21:30.240 --> 00:21:32.120
the default I'm afraid the 15 minute

00:21:32.120 --> 00:21:34.760
lag. Yeah. Yeah.

00:21:34.760 --> 00:21:37.240
Yes. Okay, so so basically what just to

00:21:37.240 --> 00:21:39.680
summarize what I set up a multi-account

00:21:39.680 --> 00:21:41.800
set up for AWS you probably you want to

00:21:41.800 --> 00:21:44.560
set up control tower to bootstrap it and

00:21:44.560 --> 00:21:46.680
then I mean if you're happy to live with

00:21:46.680 --> 00:21:49.000
that control tower structure. It

00:21:49.000 --> 00:21:51.440
depends. So I mean it will it will set

00:21:51.440 --> 00:21:52.960
up your security hub account. It will

00:21:52.960 --> 00:21:56.120
set up like Yeah, all the defaults.

00:21:56.120 --> 00:21:57.720
So that everything gets aggregated like

00:21:57.720 --> 00:21:59.560
your your your findings from all the

00:21:59.560 --> 00:22:01.120
accounts get aggregated in like a

00:22:01.120 --> 00:22:02.680
centralized dashboard. That's really

00:22:02.680 --> 00:22:04.480
nice. I mean that's I haven't done that

00:22:04.480 --> 00:22:06.320
for the last three or four years. Yeah,

00:22:06.320 --> 00:22:07.560
I'm done with it so I don't know what

00:22:07.560 --> 00:22:09.360
where they are at now. What they are

00:22:09.360 --> 00:22:12.360
doing now. Like like many things

00:22:12.360 --> 00:22:14.080
in the cloud is that cloud sprawl and

00:22:14.080 --> 00:22:16.680
then every every organization I work on

00:22:16.680 --> 00:22:18.200
it like it gets a bit crafty after a

00:22:18.200 --> 00:22:21.000
while and I just I just wish we could

00:22:21.000 --> 00:22:21.960
have

00:22:21.960 --> 00:22:24.240
a firm all accounts and or firm all

00:22:24.240 --> 00:22:27.040
organizations where we just

00:22:27.040 --> 00:22:29.440
move everything to new org but like I

00:22:29.440 --> 00:22:32.000
guess well, also at the same time I've

00:22:32.000 --> 00:22:33.520
worked in a number of enterprises that

00:22:33.520 --> 00:22:35.520
everyone is absolutely allergic when you

00:22:35.520 --> 00:22:37.360
say something like migration. Everyone

00:22:37.360 --> 00:22:38.880
goes no, no, we're not migrating

00:22:38.880 --> 00:22:40.440
anything. This is a funny thing when I

00:22:40.440 --> 00:22:43.080
had discussions about platform with some

00:22:43.080 --> 00:22:46.000
people and they were like okay, so next

00:22:46.000 --> 00:22:47.440
month we'll finally have everything

00:22:47.440 --> 00:22:49.520
nicely like migrated, right? And we'll

00:22:49.520 --> 00:22:52.160
have everything in order. And I'm like

00:22:52.160 --> 00:22:54.880
most likely not cuz cuz there's like or

00:22:54.880 --> 00:22:56.400
there's this discussion about like we

00:22:56.400 --> 00:22:58.000
want to go towards this, but we're in

00:22:58.000 --> 00:22:59.560
the middle of a migration. So if you're

00:22:59.560 --> 00:23:01.080
going to do this it's going to like

00:23:01.080 --> 00:23:03.360
cause a migration on top of a migration.

00:23:03.360 --> 00:23:04.920
And there's this tendency to be like

00:23:04.920 --> 00:23:07.240
don't do that. We going to wait. And I'm

00:23:07.240 --> 00:23:09.560
like, it's always like that. Like,

00:23:09.560 --> 00:23:11.280
you're never done. There's always

00:23:11.280 --> 00:23:11.680
something.

00:23:11.680 --> 00:23:13.720
>> a thing that I wonder if there's like a

00:23:13.720 --> 00:23:15.640
culture in an organization which says

00:23:15.640 --> 00:23:18.360
like that's insane enough to go like,

00:23:18.360 --> 00:23:21.800
"Hey, we're moving from AWS to Azure.

00:23:21.800 --> 00:23:23.240
Like, and we're doing it over the

00:23:23.240 --> 00:23:26.360
weekend. And all our data is uh 2

00:23:26.360 --> 00:23:28.440
terabytes of whatever our data is going

00:23:28.440 --> 00:23:31.000
to be moved." And then And then every,

00:23:31.000 --> 00:23:33.440
you know, week or month they can almost

00:23:33.440 --> 00:23:35.120
do that again and again and again

00:23:35.120 --> 00:23:37.920
because ultimately people get calcified

00:23:37.920 --> 00:23:40.760
in whatever hosting platform they're on.

00:23:40.760 --> 00:23:41.760
And they never can move.

00:23:41.760 --> 00:23:43.960
>> DevOps mantra? Like, if something hurts,

00:23:43.960 --> 00:23:45.160
do it more.

00:23:45.160 --> 00:23:47.120
I've never seen it myself. I've never

00:23:47.120 --> 00:23:49.560
seen it myself. But like, if you don't

00:23:49.560 --> 00:23:51.360
like, just the practice of restoring a

00:23:51.360 --> 00:23:53.320
backup and testing a backup. Like, how

00:23:53.320 --> 00:23:55.360
many people restore a backup? It's so

00:23:55.360 --> 00:23:58.080
rare in reality, in my opinion, um that

00:23:58.080 --> 00:23:59.480
people have the rigor to just Just

00:23:59.480 --> 00:24:00.960
shouldn't say that out

00:24:00.960 --> 00:24:02.640
I know. Hopefully no one at work is

00:24:02.640 --> 00:24:03.560
watching. Hopefully no one at work is

00:24:03.560 --> 00:24:06.120
watching. No, like I was I mean, because

00:24:06.120 --> 00:24:07.440
the cloud gives you so much sense of

00:24:07.440 --> 00:24:09.520
security, cuz we're not doing the

00:24:09.520 --> 00:24:11.760
on-prem data backup tapes that we have

00:24:11.760 --> 00:24:13.160
to like constantly restore. We kind of

00:24:13.160 --> 00:24:15.640
trust AWS backup to work. But they have

00:24:15.640 --> 00:24:17.880
very clear like well-architecture check

00:24:17.880 --> 00:24:19.080
marks. It's like, how many times are you

00:24:19.080 --> 00:24:20.360
restoring your backups? How many times

00:24:20.360 --> 00:24:21.800
are you restoring a backup in a

00:24:21.800 --> 00:24:23.200
different region? How many times are you

00:24:23.200 --> 00:24:25.800
That's all part of the checklist if you

00:24:25.800 --> 00:24:27.080
want to do the well-architected. They're

00:24:27.080 --> 00:24:29.680
very very very long checklists. And I'm

00:24:29.680 --> 00:24:32.080
sorry to think like a cool startup up

00:24:32.080 --> 00:24:34.720
with idea would be like validating that

00:24:34.720 --> 00:24:36.960
restore process, you know, like There's

00:24:36.960 --> 00:24:38.040
quite a few.

00:24:38.040 --> 00:24:40.000
>> Like, when my my friend was going

00:24:40.000 --> 00:24:42.640
towards becoming like an AWS partner

00:24:42.640 --> 00:24:44.560
with with an organization, you have to

00:24:44.560 --> 00:24:46.840
pass those all those checklists. And

00:24:46.840 --> 00:24:48.720
there was a company he found that that

00:24:48.720 --> 00:24:50.640
did everything. So, you just hook it up

00:24:50.640 --> 00:24:52.200
to your account. It goes and find any

00:24:52.200 --> 00:24:54.760
vi- violation, and then deploys a cloud

00:24:54.760 --> 00:24:57.400
formation stack to like rectify it. And

00:24:57.400 --> 00:24:59.680
then he said the moment you stop paying

00:24:59.680 --> 00:25:01.480
or deactivate the account connection,

00:25:01.480 --> 00:25:02.880
all of the cloud it rolls back all of

00:25:02.880 --> 00:25:04.520
the cloud formation stacks. Like you

00:25:04.520 --> 00:25:06.680
can't use the the platform to like

00:25:06.680 --> 00:25:09.240
become the compliant and then disconnect

00:25:09.240 --> 00:25:10.760
it because it kind of like rolls

00:25:10.760 --> 00:25:12.600
everything back and you lose all of the

00:25:12.600 --> 00:25:14.120
things. So he was like, "God damn it,

00:25:14.120 --> 00:25:15.800
like I spent so much time." Because he

00:25:15.800 --> 00:25:17.080
was trying to reverse engineer the

00:25:17.080 --> 00:25:18.600
stacks and snapshot them so that he

00:25:18.600 --> 00:25:20.000
could redeploy them and things that I

00:25:20.000 --> 00:25:20.840
don't know.

00:25:20.840 --> 00:25:22.360
Just to do it quick, but like there's

00:25:22.360 --> 00:25:23.640
quite a few companies that That's kind

00:25:23.640 --> 00:25:26.040
of a dark pattern. I mean

00:25:26.040 --> 00:25:28.200
Maybe with AI today would be so fast to

00:25:28.200 --> 00:25:29.000
do this kind of thing.

00:25:29.000 --> 00:25:30.960
>> exactly. Like you could give a role to

00:25:30.960 --> 00:25:33.680
this restore okay company called restore

00:25:33.680 --> 00:25:36.720
test and maybe a subset of the

00:25:36.720 --> 00:25:39.720
architecture and data somehow. Just It's

00:25:39.720 --> 00:25:42.400
very very difficult with AI now. Because

00:25:42.400 --> 00:25:43.960
when when you look at disaster recovery,

00:25:43.960 --> 00:25:45.480
there's so many different strategies

00:25:45.480 --> 00:25:46.840
that you can use that you can do

00:25:46.840 --> 00:25:49.040
depending on your RTO and your other

00:25:49.040 --> 00:25:51.000
like requirements. Every service has

00:25:51.000 --> 00:25:52.320
different ones. Like do you want

00:25:52.320 --> 00:25:54.080
point-in-time recovery? Do you want

00:25:54.080 --> 00:25:56.040
constant live streaming? Do you want

00:25:56.040 --> 00:25:58.040
complete failover? Do you want pilot

00:25:58.040 --> 00:25:59.160
light? Do you want to pay how much you

00:25:59.160 --> 00:26:00.240
want to pay?

00:26:00.240 --> 00:26:02.280
Yeah, so so AWS has these white papers

00:26:02.280 --> 00:26:03.680
because I had to do disaster recovery

00:26:03.680 --> 00:26:05.760
setup and they have a very detailed

00:26:05.760 --> 00:26:07.880
breakdown of like four strategies. Pilot

00:26:07.880 --> 00:26:10.360
light, live like Yeah, yeah, yeah.

00:26:10.360 --> 00:26:12.440
active passive type of setups. And

00:26:12.440 --> 00:26:14.160
there's so many scenarios they meant to

00:26:14.160 --> 00:26:15.960
protect with and the white paper is

00:26:15.960 --> 00:26:18.120
basically don't choose any strategy

00:26:18.120 --> 00:26:20.360
unless you have well defined your RTO,

00:26:20.360 --> 00:26:22.680
your RPO, whatever. And also what are

00:26:22.680 --> 00:26:25.040
your attack scenarios? You can't build a

00:26:25.040 --> 00:26:26.400
disaster recovery plan if you don't

00:26:26.400 --> 00:26:27.960
define what are the things that you're

00:26:27.960 --> 00:26:30.040
protecting against. Is it a hack? Is it

00:26:30.040 --> 00:26:31.800
an intrusion? Is Yeah, you need to do

00:26:31.800 --> 00:26:33.480
some threat modeling.

00:26:33.480 --> 00:26:35.400
I love I love this thing that I just

00:26:35.400 --> 00:26:35.680
talked about.

00:26:35.680 --> 00:26:38.360
>> That's the white paper. Yeah. But like

00:26:38.360 --> 00:26:39.720
what I'm trying to say here is like

00:26:39.720 --> 00:26:41.360
restoring stuff

00:26:41.360 --> 00:26:43.320
test a lot of that is quite tedious,

00:26:43.320 --> 00:26:47.280
right? If if AI can do

00:26:47.280 --> 00:26:50.320
can run through this exercise without

00:26:50.320 --> 00:26:53.000
people manually cuz like no one wants to

00:26:53.000 --> 00:26:55.480
do a restore because it's boring as hell

00:26:55.480 --> 00:26:56.920
and tedious.

00:26:56.920 --> 00:26:58.560
But it was actually a very fun exercise

00:26:58.560 --> 00:27:00.280
when we did it. It was really fun. Well,

00:27:00.280 --> 00:27:02.400
you you enjoyed but like that's probably

00:27:02.400 --> 00:27:04.240
just a one-off thing. It's like you

00:27:04.240 --> 00:27:06.400
know, I'm doing this for the first time.

00:27:06.400 --> 00:27:08.480
Yeah, but it's very important because

00:27:08.480 --> 00:27:11.160
when we did it we're like we had a plan

00:27:11.160 --> 00:27:14.040
and then when when it happened we we

00:27:14.040 --> 00:27:16.000
simulated it in in non-prod but then we

00:27:16.000 --> 00:27:18.080
actually did it in life as well.

00:27:18.080 --> 00:27:19.440
Um

00:27:19.440 --> 00:27:21.360
it was like

00:27:21.360 --> 00:27:23.880
Uh yeah, it's very clear what my plan is

00:27:23.880 --> 00:27:25.160
but then when you're actually doing it

00:27:25.160 --> 00:27:26.520
there's this all additional stuff that

00:27:26.520 --> 00:27:28.320
were like, yeah, but am I absolutely

00:27:28.320 --> 00:27:29.800
sure? Oh, wait a minute. I need to

00:27:29.800 --> 00:27:31.120
double-check that. Oh, no, this process

00:27:31.120 --> 00:27:32.920
is actually very cumbersome. Like it was

00:27:32.920 --> 00:27:34.520
designed like this and I have to do this

00:27:34.520 --> 00:27:37.160
thing but it wasn't clear to me how to

00:27:37.160 --> 00:27:39.480
validate it. So doing it live, even if

00:27:39.480 --> 00:27:41.080
you have completely automated backup

00:27:41.080 --> 00:27:42.600
restore procedures,

00:27:42.600 --> 00:27:45.280
um the actually validating the the plan

00:27:45.280 --> 00:27:47.000
and the buttons you click is so

00:27:47.000 --> 00:27:49.760
valuable. Yeah. Like if if we could just

00:27:49.760 --> 00:27:52.160
if in light of this AI error that we're

00:27:52.160 --> 00:27:53.880
living in right now, if you could just

00:27:53.880 --> 00:27:56.320
list all the tedious things that we've

00:27:56.320 --> 00:27:58.400
that we couldn't really automate before

00:27:58.400 --> 00:28:00.920
like backup restore testing. If we could

00:28:00.920 --> 00:28:03.520
just list that and now and basically

00:28:03.520 --> 00:28:05.640
prioritize them in a sense cuz now now

00:28:05.640 --> 00:28:07.800
these things are possible without dying

00:28:07.800 --> 00:28:10.520
of boredom to basically get AI to

00:28:10.520 --> 00:28:12.800
validate your backup or to bootstrap

00:28:12.800 --> 00:28:14.920
your your AWS account. I mean, that

00:28:14.920 --> 00:28:16.760
let's be honest like bootstrapping an

00:28:16.760 --> 00:28:20.000
AWS account or organization with control

00:28:20.000 --> 00:28:22.800
with with the with control tower, did

00:28:22.800 --> 00:28:23.920
you say? I forgot the name of the

00:28:23.920 --> 00:28:24.680
product already.

00:28:24.680 --> 00:28:25.720
>> tower from AWS.

00:28:25.720 --> 00:28:27.440
>> I mean, can it even be driven by

00:28:27.440 --> 00:28:29.400
automation actually? These are the

00:28:29.400 --> 00:28:29.920
things that

00:28:29.920 --> 00:28:31.320
>> So this is where I'm not up to date

00:28:31.320 --> 00:28:33.520
because there's many ways to bootstrap

00:28:33.520 --> 00:28:35.800
your AWS account. I I mean, if you put

00:28:35.800 --> 00:28:37.800
in place or your organization, if you

00:28:37.800 --> 00:28:40.120
put in place control tower, you already

00:28:40.120 --> 00:28:42.080
have like a first step but then you can

00:28:42.080 --> 00:28:44.360
also hook it up with way more things

00:28:44.360 --> 00:28:46.560
like control tower has landing zone and

00:28:46.560 --> 00:28:48.680
originally when I tried it out 5 years

00:28:48.680 --> 00:28:50.600
ago it was horrible. It was using

00:28:50.600 --> 00:28:53.160
because the account provisioning was so

00:28:53.160 --> 00:28:55.200
it took so long so much time and you

00:28:55.200 --> 00:28:57.200
couldn't even specify what's the VPC ID.

00:28:57.200 --> 00:28:58.520
Like imagine that you have this

00:28:58.520 --> 00:29:01.400
requirement that every VPC ID uh cider,

00:29:01.400 --> 00:29:03.840
sorry not ID but cider, is separate

00:29:03.840 --> 00:29:05.200
because you need a transit gateway to

00:29:05.200 --> 00:29:07.080
connect everything or interconnect. You

00:29:07.080 --> 00:29:08.240
couldn't do that with control tower

00:29:08.240 --> 00:29:10.360
landing zone. You you had to define the

00:29:10.360 --> 00:29:12.160
cider lanes of the VPC that was going to

00:29:12.160 --> 00:29:13.760
be provisioned in advance in the

00:29:13.760 --> 00:29:15.600
template. You couldn't say like when the

00:29:15.600 --> 00:29:18.040
account gets created go here and

00:29:18.040 --> 00:29:20.040
allocate a cider range and then create

00:29:20.040 --> 00:29:22.280
the VPC with that cider range. I can see

00:29:22.280 --> 00:29:23.520
there's a lot of some automation gaps.

00:29:23.520 --> 00:29:24.560
Like one thing that's always frustrated

00:29:24.560 --> 00:29:25.760
That was 5 years ago. I'm pretty sure

00:29:25.760 --> 00:29:28.040
they already fixed some of that stuff. I

00:29:28.040 --> 00:29:29.920
made a video about this. Like just

00:29:29.920 --> 00:29:32.240
closing an AWS account.

00:29:32.240 --> 00:29:34.080
They also fixed that a lot.

00:29:34.080 --> 00:29:35.840
Before it was not possible there was no

00:29:35.840 --> 00:29:37.920
API but they added APIs and everything.

00:29:37.920 --> 00:29:39.360
>> Yeah, now they have APIs but still

00:29:39.360 --> 00:29:41.800
there's like a very like it's weird.

00:29:41.800 --> 00:29:44.280
Like the the account is like Yeah, the

00:29:44.280 --> 00:29:45.320
recommended practice But it's still

00:29:45.320 --> 00:29:46.520
there for like at least a month or

00:29:46.520 --> 00:29:48.040
something.

00:29:48.040 --> 00:29:49.600
Yeah, the recommended practice for years

00:29:49.600 --> 00:29:51.640
has been you keep a pool of accounts and

00:29:51.640 --> 00:29:53.400
you you allocate the account and then

00:29:53.400 --> 00:29:55.280
you release the account once you're done

00:29:55.280 --> 00:29:57.440
with whatever project that needed the

00:29:57.440 --> 00:30:00.560
account. There's even a whole

00:30:00.560 --> 00:30:02.760
release the account open source. Not

00:30:02.760 --> 00:30:05.880
deleting it. No, no. So you keep a pool

00:30:05.880 --> 00:30:07.040
and you have a

00:30:07.040 --> 00:30:09.320
basically you allocate the account to a

00:30:09.320 --> 00:30:11.640
project, provision it and then when it's

00:30:11.640 --> 00:30:14.120
done you basically new call of it and

00:30:14.120 --> 00:30:15.600
you release it back to the pool. So you

00:30:15.600 --> 00:30:17.480
never destroy it. The account never gets

00:30:17.480 --> 00:30:19.440
created or That's been There's an

00:30:19.440 --> 00:30:20.880
There's an open source framework that

00:30:20.880 --> 00:30:22.520
does that for you. It's been around for

00:30:22.520 --> 00:30:25.280
like I don't know 8 10 years and it's

00:30:25.280 --> 00:30:26.800
still one of the most popular ways. Like

00:30:26.800 --> 00:30:28.160
I talked to someone he says like oh I've

00:30:28.160 --> 00:30:30.040
been working on like account pool

00:30:30.040 --> 00:30:32.280
mechanisms like just a month ago and I

00:30:32.280 --> 00:30:33.240
said oh I remember there was this

00:30:33.240 --> 00:30:34.400
framework he said yeah that's probably

00:30:34.400 --> 00:30:36.080
the one I'm using and it's still the

00:30:36.080 --> 00:30:38.200
same one. But what's Why not just nuke

00:30:38.200 --> 00:30:40.120
it and create a new account in the org?

00:30:40.120 --> 00:30:41.840
I don't understand. You just mentioned

00:30:41.840 --> 00:30:43.600
the account stays around so long. I

00:30:43.600 --> 00:30:45.320
mean, it's always been problematic to

00:30:45.320 --> 00:30:47.960
close the account. And Okay, so this is

00:30:47.960 --> 00:30:49.240
kind of like what I'm working on.

00:30:49.240 --> 00:30:51.520
>> Yeah. Yeah, okay. Okay. By the way,

00:30:51.520 --> 00:30:53.000
yeah, thanks for sharing that thing

00:30:53.000 --> 00:30:54.880
about State Graph. It does look I'm

00:30:54.880 --> 00:30:56.440
really I'm really impressed by State

00:30:56.440 --> 00:30:57.520
Graph's

00:30:57.520 --> 00:31:00.520
landing page. It's so clear what what

00:31:00.520 --> 00:31:03.440
it's doing and how to use it and what

00:31:03.440 --> 00:31:06.800
the what you need to do to start

00:31:06.800 --> 00:31:08.560
you know, how advertisers value and

00:31:08.560 --> 00:31:10.320
things like that. Like This is really

00:31:10.320 --> 00:31:11.840
good. Yeah, they they've been doing a

00:31:11.840 --> 00:31:13.200
lot of demos

00:31:13.200 --> 00:31:15.560
talking about

00:31:15.560 --> 00:31:17.400
what they're trying to achieve. I was

00:31:17.400 --> 00:31:18.960
surprised that because I thought the

00:31:18.960 --> 00:31:21.480
whole idea of State Graph was was to go

00:31:21.480 --> 00:31:23.320
towards a Terralit so that you can

00:31:23.320 --> 00:31:25.440
resolve all of your dependencies

00:31:25.440 --> 00:31:29.840
within a single state, but they added

00:31:29.840 --> 00:31:32.120
multi-state support. And I was like,

00:31:32.120 --> 00:31:33.120
"Oh, it seems you changed your mind."

00:31:33.120 --> 00:31:34.160
They said and they said, "No, no, no,

00:31:34.160 --> 00:31:36.080
that was always the plan. The ability to

00:31:36.080 --> 00:31:37.880
have multiple state within the

00:31:37.880 --> 00:31:40.160
individual state and and be able to plan

00:31:40.160 --> 00:31:42.360
everything without mocks because if you

00:31:42.360 --> 00:31:43.960
do that in Terragrunt, you're going to

00:31:43.960 --> 00:31:46.240
have to specify output mocks

00:31:46.240 --> 00:31:48.240
and things like that.

00:31:48.240 --> 00:31:50.000
Have you given it well? I mean, you

00:31:50.000 --> 00:31:51.800
mentioned it cuz I mean, I'm guessing

00:31:51.800 --> 00:31:54.720
that they want it released, right? It's

00:31:54.720 --> 00:31:56.280
There's It's been

00:31:56.280 --> 00:31:58.440
It's been released.

00:31:58.440 --> 00:32:00.880
Like last week. Okay. The blog doesn't

00:32:00.880 --> 00:32:02.920
seem to reflect that, but whatever.

00:32:02.920 --> 00:32:04.480
>> because there was a release. I think

00:32:04.480 --> 00:32:06.920
they released it just before QCon, but

00:32:06.920 --> 00:32:08.280
like I don't know if they made it open

00:32:08.280 --> 00:32:10.240
source, right? They they said that they

00:32:10.240 --> 00:32:12.080
they couldn't figure out the licensing.

00:32:12.080 --> 00:32:13.280
And this is by the way some very

00:32:13.280 --> 00:32:14.960
interesting article I saw today this

00:32:14.960 --> 00:32:17.880
morning about today there's this

00:32:17.880 --> 00:32:19.640
website. It's a joke, I guess, and I'm

00:32:19.640 --> 00:32:21.560
not sure it's for fun, but what they

00:32:21.560 --> 00:32:23.320
what it does is like

00:32:23.320 --> 00:32:25.600
don't like the Pesky license? Just let

00:32:25.600 --> 00:32:27.920
AI do enough change so that you you make

00:32:27.920 --> 00:32:29.440
it look like it's a different project,

00:32:29.440 --> 00:32:31.360
but it's and you can relicense it under

00:32:31.360 --> 00:32:33.880
your own license that you want. So, they

00:32:33.880 --> 00:32:35.720
said this is like in the enterprise

00:32:35.720 --> 00:32:38.040
today, you don't want to get affected by

00:32:38.040 --> 00:32:39.760
AGPL a fair

00:32:39.760 --> 00:32:42.240
uh GPL that basically is very

00:32:42.240 --> 00:32:44.280
and GPL in in itself like whatever it

00:32:44.280 --> 00:32:45.520
touches you're supposed to then open

00:32:45.520 --> 00:32:47.480
source and so on. So people enterprise

00:32:47.480 --> 00:32:48.960
are very much against it. So any project

00:32:48.960 --> 00:32:51.560
that's GPL or AGPL usually is a no in

00:32:51.560 --> 00:32:52.720
enterprises. So you don't like the

00:32:52.720 --> 00:32:55.480
license? Great. Here's a workflow. Just

00:32:55.480 --> 00:32:58.080
fork it, make it your own license and

00:32:58.080 --> 00:33:00.320
just run it how you want.

00:33:00.320 --> 00:33:02.000
Well, I just get AI to re-implement

00:33:02.000 --> 00:33:03.240
everything I suppose. Is that what

00:33:03.240 --> 00:33:03.960
you're saying, right?

00:33:03.960 --> 00:33:06.920
>> Yeah, I I can share the the link. It's a

00:33:06.920 --> 00:33:08.400
very funny one because I was having this

00:33:08.400 --> 00:33:09.840
discussion

00:33:09.840 --> 00:33:13.560
um with someone. Basically, honestly,

00:33:13.560 --> 00:33:15.880
there was this project and I can read

00:33:15.880 --> 00:33:17.960
the source code because it's MPL Mozilla

00:33:17.960 --> 00:33:20.880
public license, but I can ask an AI to

00:33:20.880 --> 00:33:22.880
rewrite it in a different language. And

00:33:22.880 --> 00:33:24.880
where do I where where do I need to keep

00:33:24.880 --> 00:33:26.160
the license? How do I need to keep the

00:33:26.160 --> 00:33:28.680
attribution if I'm basically rewriting

00:33:28.680 --> 00:33:30.600
it in a different language like I guess

00:33:30.600 --> 00:33:31.640
Yeah, I I've seen that.

00:33:31.640 --> 00:33:33.200
>> AI is reading all the algorithms. I

00:33:33.200 --> 00:33:34.880
mean, that that's assuming big things,

00:33:34.880 --> 00:33:36.280
right? Because I mean, we've been

00:33:36.280 --> 00:33:38.960
chatting about it. I mean, this is what

00:33:38.960 --> 00:33:40.600
your spec ledger project is about in a

00:33:40.600 --> 00:33:42.600
way. It's like I don't think people have

00:33:42.600 --> 00:33:44.520
figured out how to ship with AI, really

00:33:44.520 --> 00:33:46.880
have they? So like You think that the

00:33:46.880 --> 00:33:49.480
ideal pointing an AI agent to an

00:33:49.480 --> 00:33:51.000
existing project and asking it to

00:33:51.000 --> 00:33:54.120
rewrite is not I mean, it's possible.

00:33:54.120 --> 00:33:56.960
It's it's it's bold talk. I mean, it but

00:33:56.960 --> 00:33:58.960
it's it's talk. You want me to share the

00:33:58.960 --> 00:33:59.440
link?

00:33:59.440 --> 00:34:01.520
>> I don't think anyone's really done that

00:34:01.520 --> 00:34:03.640
yet. I mean, it's just hypothetical at

00:34:03.640 --> 00:34:05.600
this point, right? At the risk of

00:34:05.600 --> 00:34:06.880
causing a

00:34:06.880 --> 00:34:09.200
shitstorm, you just showed state graph,

00:34:09.200 --> 00:34:12.679
right? So let me just share my screen.

00:34:12.679 --> 00:34:14.480
And that's not even open source. Maybe

00:34:14.480 --> 00:34:16.960
it's Hold on, screen. Entire screen.

00:34:16.960 --> 00:34:19.280
It's going to It's going to You can see

00:34:19.280 --> 00:34:20.600
it, right? You can see state graph,

00:34:20.600 --> 00:34:22.240
right? Yeah, yeah. I was showing that

00:34:22.240 --> 00:34:22.320
earlier.

00:34:22.320 --> 00:34:24.440
>> So you see this the the landing page.

00:34:24.440 --> 00:34:26.760
Yo, yo, yo, yo. With like sequential

00:34:26.760 --> 00:34:29.919
allocations versus multi-state and uh

00:34:29.919 --> 00:34:32.320
see the difference. It's all SQL.

00:34:32.320 --> 00:34:34.240
>> I just love that landing It's so good.

00:34:34.240 --> 00:34:36.200
Now look at this. Well, he changed it.

00:34:36.200 --> 00:34:38.159
Maybe somebody complained. Well, first

00:34:38.159 --> 00:34:39.720
what I like what I think is funny, I

00:34:39.720 --> 00:34:40.960
didn't even realize you need to do

00:34:40.960 --> 00:34:42.919
squares with the little dots inside.

00:34:42.919 --> 00:34:46.280
Well, there's dot pattern.

00:34:46.280 --> 00:34:48.159
I thought this was very funny. Oh, this

00:34:48.159 --> 00:34:49.120
one is very similar.

00:34:49.120 --> 00:34:51.399
>> cop- copying a He changed it a little

00:34:51.399 --> 00:34:52.760
bit. Before it was way more

00:34:52.760 --> 00:34:55.480
>> page is one thing. Copying

00:34:55.480 --> 00:34:57.480
an actual

00:34:57.480 --> 00:34:59.800
uh Oh, no, this thing works.

00:34:59.800 --> 00:35:02.040
This thing works. It works?

00:35:02.040 --> 00:35:03.800
>> Yeah, yeah. I actually integrated like

00:35:03.800 --> 00:35:05.640
the CDKTF and you see stack ledgers in

00:35:05.640 --> 00:35:07.360
there as well. So, I actually did the

00:35:07.360 --> 00:35:10.080
CDKTF test generator and then I run all

00:35:10.080 --> 00:35:13.440
of it all of these um sample So, what's

00:35:13.440 --> 00:35:15.200
your relationship with this project? You

00:35:15.200 --> 00:35:16.720
just know the guy or something?

00:35:16.720 --> 00:35:18.840
>> I because Okay, so this this is

00:35:18.840 --> 00:35:20.280
basically doing the same thing as State

00:35:20.280 --> 00:35:21.680
Graph, but it's in Rust and it's open

00:35:21.680 --> 00:35:24.200
source. And it's just like he just

00:35:24.200 --> 00:35:26.080
>> What? The idea is very interesting

00:35:26.080 --> 00:35:28.720
because he just re-implements the config

00:35:28.720 --> 00:35:30.680
parser reading the original Terraform

00:35:30.680 --> 00:35:34.560
configuration and then generates the um

00:35:34.560 --> 00:35:36.640
and then invokes the Terraform providers

00:35:36.640 --> 00:35:39.080
directly. So, he implements the the RPC

00:35:39.080 --> 00:35:41.000
protocol that Terraform talks with the

00:35:41.000 --> 00:35:42.480
plugins, right? So, you have the Go lang

00:35:42.480 --> 00:35:46.200
Terraform talking to the protocols and

00:35:46.200 --> 00:35:47.640
um it's

00:35:47.640 --> 00:35:50.640
it just invokes the Sorry, the Go lang

00:35:50.640 --> 00:35:53.560
execution core of Terraform.

00:35:53.560 --> 00:35:55.880
Instantiates the providers and

00:35:55.880 --> 00:35:57.520
communicates to them with the protocol.

00:35:57.520 --> 00:35:59.320
So, this thing does the same thing. It

00:35:59.320 --> 00:36:01.440
It instantiates the protocol Sorry, the

00:36:01.440 --> 00:36:03.280
providers and then it communicates to

00:36:03.280 --> 00:36:06.120
them through gRPC. So, every CRUD action

00:36:06.120 --> 00:36:07.600
that you need to do for every resource

00:36:07.600 --> 00:36:09.920
configuration just initializes Yeah. It

00:36:09.920 --> 00:36:11.400
just calls out straight to the provider.

00:36:11.400 --> 00:36:13.000
>> Okay, but there's also like a database

00:36:13.000 --> 00:36:14.760
aspect to it. Yeah, so this thing is

00:36:14.760 --> 00:36:16.920
like State Graph. It basically uses

00:36:16.920 --> 00:36:19.640
Postgres as the uh SQLite as a as a

00:36:19.640 --> 00:36:21.800
state storage. So, it doesn't support

00:36:21.800 --> 00:36:23.440
like It doesn't do the remote backend

00:36:23.440 --> 00:36:26.080
setup that you can do with S3 um or or

00:36:26.080 --> 00:36:26.600
other of those

00:36:26.600 --> 00:36:27.960
>> Is this

00:36:27.960 --> 00:36:30.240
plagiarism or I'm not too sure how to

00:36:30.240 --> 00:36:31.480
Yeah, this goes back to the to the

00:36:31.480 --> 00:36:33.160
original question. Like this is not even

00:36:33.160 --> 00:36:35.120
looking at the source code. This is just

00:36:35.120 --> 00:36:36.960
looking at the at the landing page and

00:36:36.960 --> 00:36:38.960
duplicating the capabilities. And when I

00:36:38.960 --> 00:36:40.480
talk with him he says the main reason is

00:36:40.480 --> 00:36:41.800
because they didn't have a plan to open

00:36:41.800 --> 00:36:44.240
source it. And I really like the idea.

00:36:44.240 --> 00:36:46.880
And I I didn't think it was that hard to

00:36:46.880 --> 00:36:49.400
build. And if you if you can tell it's

00:36:49.400 --> 00:36:51.480
all AI. And you said like all that's all

00:36:51.480 --> 00:36:54.280
like bold bold talk about AI rebuilding

00:36:54.280 --> 00:36:56.960
products. It's a fact, okay?

00:36:56.960 --> 00:36:59.080
You can rebuild a complete product. Have

00:36:59.080 --> 00:37:00.560
you Have you Have you tried this in

00:37:00.560 --> 00:37:02.320
anger? Is this going to work?

00:37:02.320 --> 00:37:04.400
>> I did I did work it. There was one thing

00:37:04.400 --> 00:37:06.360
that I discovered and I'm not sure if

00:37:06.360 --> 00:37:07.760
they fixed it.

00:37:07.760 --> 00:37:10.320
>> Have you actually compared it with State

00:37:10.320 --> 00:37:13.480
Graph? Oh no. I I Okay. I mean, honestly

00:37:13.480 --> 00:37:15.600
State Graph's been worked on in private

00:37:15.600 --> 00:37:17.640
in in in um

00:37:17.640 --> 00:37:19.160
how you call it stealth mode since

00:37:19.160 --> 00:37:20.680
September. Okay, so a team's been

00:37:20.680 --> 00:37:23.120
working on that for almost half a year

00:37:23.120 --> 00:37:25.600
or 8 months. I cannot tell that this

00:37:25.600 --> 00:37:28.280
project which is maybe 1 month old or

00:37:28.280 --> 00:37:30.560
like a month and a half old is anything

00:37:30.560 --> 00:37:32.640
comparable in terms of like stability

00:37:32.640 --> 00:37:35.400
and features. But the fact is that it

00:37:35.400 --> 00:37:37.840
works. I was able to clone it. I was

00:37:37.840 --> 00:37:39.920
able to use it with Terraform JSON. And

00:37:39.920 --> 00:37:41.960
I was able to Terraform sorry, Oxid

00:37:41.960 --> 00:37:44.080
apply my Terraform configs. And it was

00:37:44.080 --> 00:37:45.640
creating against the Terraform provider.

00:37:45.640 --> 00:37:47.320
It was doing all I guess I guess this is

00:37:47.320 --> 00:37:49.160
the difference between

00:37:49.160 --> 00:37:51.440
a commercial product and something that

00:37:51.440 --> 00:37:54.640
you can just clone out and give a whirl.

00:37:54.640 --> 00:37:56.760
Yes. So so so you you are right in a way

00:37:56.760 --> 00:37:58.640
that you that like that is a pattern

00:37:58.640 --> 00:38:00.400
that people often say. I think there was

00:38:00.400 --> 00:38:03.040
a post about it recently, which is

00:38:03.040 --> 00:38:04.800
people think that they can just rip it

00:38:04.800 --> 00:38:06.440
and then move away from the

00:38:06.440 --> 00:38:08.240
well-established and tested library. And

00:38:08.240 --> 00:38:09.800
they replace it in 30 minutes. And then

00:38:09.800 --> 00:38:12.960
they spend months fixing bugs and and

00:38:12.960 --> 00:38:15.680
basically supporting it. Yeah, so So

00:38:15.680 --> 00:38:17.080
this is the thing I wanted to because

00:38:17.080 --> 00:38:18.720
you you diverted me. You said it's it's

00:38:18.720 --> 00:38:20.560
it's all it's a bold claim, but it it

00:38:20.560 --> 00:38:23.400
holds no reality. But this is the the

00:38:23.400 --> 00:38:25.920
the website which is I think a bit of a

00:38:25.920 --> 00:38:27.000
a joke.

00:38:27.000 --> 00:38:28.880
Um and honestly I think they use the ant

00:38:28.880 --> 00:38:29.520
track thing.

00:38:29.520 --> 00:38:31.120
>> News. I think I read it.

00:38:31.120 --> 00:38:33.160
>> Yeah, it's funny how they like put a

00:38:33.160 --> 00:38:34.440
[ __ ] smear on it.

00:38:34.440 --> 00:38:36.760
>> it is slightly I I mean

00:38:36.760 --> 00:38:38.000
It's hyperbole.

00:38:38.000 --> 00:38:40.200
>> I actually want State Graph to succeed,

00:38:40.200 --> 00:38:42.400
but like when I look at the pricing,

00:38:42.400 --> 00:38:44.560
when I think about the enterprises that

00:38:44.560 --> 00:38:47.080
I work with, it's really hard for them

00:38:47.080 --> 00:38:49.560
to adopt um

00:38:49.560 --> 00:38:52.680
a proprietary product. And uh what How

00:38:52.680 --> 00:38:53.760
do you pronounce this other project?

00:38:53.760 --> 00:38:54.800
Oxid or something?

00:38:54.800 --> 00:38:56.680
>> Yeah, Oxid. I should put the State Graph

00:38:56.680 --> 00:38:59.400
on on here, like I think. Like Oxid is

00:38:59.400 --> 00:39:02.200
actually even though it came later and

00:39:02.200 --> 00:39:04.520
re-implemented State Graph or something

00:39:04.520 --> 00:39:05.840
like that,

00:39:05.840 --> 00:39:07.040
um

00:39:07.040 --> 00:39:10.120
it actually stands a a lot better chance

00:39:10.120 --> 00:39:12.880
of being adopted because

00:39:12.880 --> 00:39:15.400
because people the you know, the

00:39:15.400 --> 00:39:16.880
engineers on the ground can just clone

00:39:16.880 --> 00:39:18.960
it out and try it out. There's like

00:39:18.960 --> 00:39:21.520
So the person that built Oxid, um he

00:39:21.520 --> 00:39:24.080
told me that he has a couple of like

00:39:24.080 --> 00:39:27.760
fintech clients that are looking to roll

00:39:27.760 --> 00:39:29.320
this out across their organization

00:39:29.320 --> 00:39:31.120
because they have such a big Terraform

00:39:31.120 --> 00:39:33.360
state and Terraform is extremely slow.

00:39:33.360 --> 00:39:36.280
And they are seeing like a 10x or you

00:39:36.280 --> 00:39:39.320
know, 20x improvement Yeah, I mean I've

00:39:39.320 --> 00:39:41.080
had this problem so many times and this

00:39:41.080 --> 00:39:43.080
this The trouble is is that none of my

00:39:43.080 --> 00:39:45.120
my projects in GitHub

00:39:45.120 --> 00:39:47.160
um I don't think will give this a proper

00:39:47.160 --> 00:39:49.720
whirl a whirl, like you know, like no

00:39:49.720 --> 00:39:52.040
one has no one has a private project

00:39:52.040 --> 00:39:54.360
that that replicates

00:39:54.360 --> 00:39:57.480
um you know, an enterprise.

00:39:57.480 --> 00:39:58.960
You got rid of the ant track thing?

00:39:58.960 --> 00:40:01.600
>> up, do they? Unless I have my home lab

00:40:01.600 --> 00:40:04.400
my home lab somehow expand dramatically.

00:40:04.400 --> 00:40:05.720
So one of the things that was missing

00:40:05.720 --> 00:40:09.680
was this the the context exposed to the

00:40:09.680 --> 00:40:11.760
the parser, the language parser was

00:40:11.760 --> 00:40:14.440
missing these internal mod like um

00:40:14.440 --> 00:40:17.200
path uh modules for this type of stuff.

00:40:17.200 --> 00:40:19.960
So, I identified there were several like

00:40:19.960 --> 00:40:22.560
in in the context it's missing the path

00:40:22.560 --> 00:40:24.440
module, the path root, the path uh

00:40:24.440 --> 00:40:25.400
current working directory, and the

00:40:25.400 --> 00:40:27.600
workspace name. So, those were a couple

00:40:27.600 --> 00:40:27.800
of things.

00:40:27.800 --> 00:40:30.320
>> hate those those sort of like And this

00:40:30.320 --> 00:40:32.080
also was not implemented, but again, I

00:40:32.080 --> 00:40:35.120
opened this issue February 18th. So,

00:40:35.120 --> 00:40:36.560
maybe they've already implemented

00:40:36.560 --> 00:40:38.200
because I don't think anyone can use

00:40:38.200 --> 00:40:41.280
this if you don't have these functions.

00:40:41.280 --> 00:40:42.720
Right? You need these functions like

00:40:42.720 --> 00:40:45.160
file, template file, dirname. Like these

00:40:45.160 --> 00:40:47.400
were all missing on the initial version.

00:40:47.400 --> 00:40:48.680
So, I'm not sure if he actually fixed

00:40:48.680 --> 00:40:49.680
that. I haven't really looked at the

00:40:49.680 --> 00:40:53.200
latest commits. Yeah. And Taco's guru,

00:40:53.200 --> 00:40:54.600
you're going to have you said you

00:40:54.600 --> 00:40:56.080
mentioned you're going to put

00:40:56.080 --> 00:40:57.920
you're going to put State Graph there.

00:40:57.920 --> 00:40:59.040
You're going to you're going to put

00:40:59.040 --> 00:41:01.040
Oxide there, too? Yeah, oh, another

00:41:01.040 --> 00:41:03.600
thing, he has a platform called Ops Zero

00:41:03.600 --> 00:41:06.720
AI, which is like an agent um

00:41:06.720 --> 00:41:11.680
driven um like for Terraform. So,

00:41:11.680 --> 00:41:14.000
uh he said that he already has Oxide as

00:41:14.000 --> 00:41:15.720
as a back end, like an execution engine

00:41:15.720 --> 00:41:17.960
integrated there. So, this is new

00:41:17.960 --> 00:41:19.400
website again. My gosh.

00:41:19.400 --> 00:41:21.440
>> So, he when I told I showed him Taco's,

00:41:21.440 --> 00:41:23.400
he said, "Why don't you put Ops Zero on

00:41:23.400 --> 00:41:24.960
there?" Because Ops Zero is also

00:41:24.960 --> 00:41:26.680
providing that. So,

00:41:26.680 --> 00:41:30.520
so I think both Ops Zero and Terra team

00:41:30.520 --> 00:41:33.480
Sorry, uh State Graph should go on there

00:41:33.480 --> 00:41:36.400
uh and show like the cost. Cuz like here

00:41:36.400 --> 00:41:39.320
it says 10,000 resources at 12K.

00:41:39.320 --> 00:41:43.080
Um no idea about like what's the

00:41:43.080 --> 00:41:44.600
Is there any because the licensing is

00:41:44.600 --> 00:41:47.240
usually on either the team size, right?

00:41:47.240 --> 00:41:49.800
If you reduce it, you can see Open Taco

00:41:49.800 --> 00:41:52.440
is by user. So, if you have a large

00:41:52.440 --> 00:41:54.720
team, Open Taco quickly becomes way

00:41:54.720 --> 00:41:57.080
expensive uh most expensive if you go

00:41:57.080 --> 00:42:01.280
over 50 users. And then you have the

00:42:01.280 --> 00:42:02.720
then you have the like number of

00:42:02.720 --> 00:42:04.560
resources. So, in my organization we're

00:42:04.560 --> 00:42:06.560
around 25K.

00:42:06.560 --> 00:42:08.800
If we if we look at State Graph pricing,

00:42:08.800 --> 00:42:11.320
they they say 10K. So, I'm already at

00:42:11.320 --> 00:42:14.120
like 12, which is what $1,000 a year?

00:42:14.120 --> 00:42:16.760
$1,000 a month is not that bad. I'm just

00:42:16.760 --> 00:42:19.560
looking at your your tacos guru repo

00:42:19.560 --> 00:42:21.120
here. Like you must

00:42:21.120 --> 00:42:22.960
I mean you said it was AI generated. I

00:42:22.960 --> 00:42:24.720
mean what you have or you have the

00:42:24.720 --> 00:42:26.880
evaluation criteria. Yeah, it was fully

00:42:26.880 --> 00:42:29.240
vibe coded. Zero spec ledger even. But

00:42:29.240 --> 00:42:31.360
can I take over the presentation here?

00:42:31.360 --> 00:42:33.520
Yeah, yeah. So I just I think I'm a

00:42:33.520 --> 00:42:35.160
little bit confused here.

00:42:35.160 --> 00:42:36.800
So you basically rate the fact that it

00:42:36.800 --> 00:42:39.560
has no Kubernetes requirement as higher.

00:42:39.560 --> 00:42:39.960
I thought you

00:42:39.960 --> 00:42:42.000
>> You know what? Yeah, right? No, why? Why

00:42:42.000 --> 00:42:43.760
would you need a Kubernetes cluster to

00:42:43.760 --> 00:42:46.080
run your tacos? Yeah, yeah, yeah, but

00:42:46.080 --> 00:42:47.280
it's it's confusing in the sense that

00:42:47.280 --> 00:42:49.080
you might you might use your terra you

00:42:49.080 --> 00:42:50.960
might use Terraform to bootstrap

00:42:50.960 --> 00:42:52.360
Kubernetes. I know what you

00:42:52.360 --> 00:42:54.760
>> Yeah. So you got like but like someone

00:42:54.760 --> 00:42:56.080
might look at this and say I

00:42:56.080 --> 00:42:57.480
>> Yeah, yeah, yeah, no, no, the way that

00:42:57.480 --> 00:43:00.040
it's formulated it's a bit weird. Um

00:43:00.040 --> 00:43:03.560
but the idea is no k eight means

00:43:03.560 --> 00:43:06.360
basically disqualifies uh I think cube

00:43:06.360 --> 00:43:08.920
terra terra cube, which is a which is an

00:43:08.920 --> 00:43:10.280
open source that you can run on but you

00:43:10.280 --> 00:43:12.160
need Kubernetes, right? You can't you

00:43:12.160 --> 00:43:13.680
can't run it without Kubernetes.

00:43:13.680 --> 00:43:15.640
>> this is this is quite opinionated. Like

00:43:15.640 --> 00:43:17.600
actually on the topic of Why would you

00:43:17.600 --> 00:43:19.400
need

00:43:19.400 --> 00:43:21.520
Yeah, I I I get you. I get you. But it's

00:43:21.520 --> 00:43:23.440
No, that's why the weights are are open,

00:43:23.440 --> 00:43:25.520
right? No, no, no, but look look if you

00:43:25.520 --> 00:43:27.600
don't agree with this weight, you just

00:43:27.600 --> 00:43:29.880
reduce the weight. Yeah, okay, okay.

00:43:29.880 --> 00:43:30.840
That's why the weights are all

00:43:30.840 --> 00:43:33.360
configurable. Really? That's clever. You

00:43:33.360 --> 00:43:35.280
go to tacos guru. If you don't agree

00:43:35.280 --> 00:43:37.920
with the weight of this particular item,

00:43:37.920 --> 00:43:41.440
it's opening you're only saying it

00:43:41.440 --> 00:43:43.000
Oh, so it's telling you in the window.

00:43:43.000 --> 00:43:45.120
Yeah. That's really clever. And it's

00:43:45.120 --> 00:43:47.400
it's affects the the order, right? If

00:43:47.400 --> 00:43:48.800
you say like for example The order

00:43:48.800 --> 00:43:50.760
doesn't seem to change here in the top

00:43:50.760 --> 00:43:51.040
right.

00:43:51.040 --> 00:43:53.640
>> tofu. Change open tofu weight to zero.

00:43:53.640 --> 00:43:55.040
Let's say that you don't care about it

00:43:55.040 --> 00:43:57.160
being Terraform or OpenTofu. Immediately

00:43:57.160 --> 00:44:00.040
see ACP Terraform go up. Then change CDK

00:44:00.040 --> 00:44:03.240
TF to zero. Again, CD ACP Terraform goes

00:44:03.240 --> 00:44:05.160
up. It went up three three spots.

00:44:05.160 --> 00:44:07.200
Terraform went down one.

00:44:07.200 --> 00:44:07.600
Yeah.

00:44:07.600 --> 00:44:09.040
>> You need to put this in the You need to

00:44:09.040 --> 00:44:11.680
put this as a arguments though on the on

00:44:11.680 --> 00:44:12.280
the URL.

00:44:12.280 --> 00:44:13.960
>> if you go on mobile, it tells you a

00:44:13.960 --> 00:44:15.800
little bit more.

00:44:15.800 --> 00:44:18.000
And even also on the I really like that.

00:44:18.000 --> 00:44:19.480
Did you get this Did you come up with

00:44:19.480 --> 00:44:21.320
this idea yourself or you you copied

00:44:21.320 --> 00:44:22.920
another site? I think I need to credit

00:44:22.920 --> 00:44:25.320
all my ideas to my principal architect

00:44:25.320 --> 00:44:27.120
in in in uh

00:44:27.120 --> 00:44:28.880
No, like basically what happened is I

00:44:28.880 --> 00:44:31.120
needed to evaluate platforms to migrate

00:44:31.120 --> 00:44:33.040
to and I had to establish criteria that

00:44:33.040 --> 00:44:35.760
mattered to me. So, based on my story, I

00:44:35.760 --> 00:44:38.080
told Opus like, "Okay, this is how we've

00:44:38.080 --> 00:44:39.680
started. This is how we evolved. This is

00:44:39.680 --> 00:44:41.360
what we have established. This is what

00:44:41.360 --> 00:44:43.600
matters to us. CDK TF we use heavily, so

00:44:43.600 --> 00:44:45.600
it's important." And it came up with a

00:44:45.600 --> 00:44:47.600
bunch of criteria for me, right? And

00:44:47.600 --> 00:44:48.720
then it came up with the with the

00:44:48.720 --> 00:44:50.520
formula to to calculate the score of

00:44:50.520 --> 00:44:52.360
each platform using weights. I think I

00:44:52.360 --> 00:44:53.800
might have suggested to use weights,

00:44:53.800 --> 00:44:55.920
right? And then I I I presented a

00:44:55.920 --> 00:44:58.000
markdown document with with the weight

00:44:58.000 --> 00:44:59.240
calculate like the weights to each

00:44:59.240 --> 00:45:01.520
criteria and somebody said it would be

00:45:01.520 --> 00:45:03.360
nice I I said to them, "Do you agree

00:45:03.360 --> 00:45:05.240
with these weights?" And they said, "It

00:45:05.240 --> 00:45:06.560
would be nice if we could change the

00:45:06.560 --> 00:45:08.400
weights and see how it impacts the

00:45:08.400 --> 00:45:09.080
score."

00:45:09.080 --> 00:45:10.640
>> Nice. Nice. And so I went back to Opus.

00:45:10.640 --> 00:45:12.760
I said like, "Hey, we want to make this,

00:45:12.760 --> 00:45:14.480
you know, an Excel spreadsheet is going

00:45:14.480 --> 00:45:16.200
to suck. So, I'm going to like you might

00:45:16.200 --> 00:45:18.200
as well build a website and then and

00:45:18.200 --> 00:45:20.480
then came up with all of this."

00:45:20.480 --> 00:45:21.680
>> Well, I love what you've done here. It's

00:45:21.680 --> 00:45:23.800
really good. Uh

00:45:23.800 --> 00:45:27.200
the I we we I remember the like

00:45:27.200 --> 00:45:29.000
we play these agile games back in the

00:45:29.000 --> 00:45:30.640
day when you were in the office, you

00:45:30.640 --> 00:45:33.840
know, play points. Uh where you would uh

00:45:33.840 --> 00:45:36.240
poker sort of have sliders in a in a

00:45:36.240 --> 00:45:38.240
sense. You'd ask your client, "How

00:45:38.240 --> 00:45:40.080
important is this to you? How important

00:45:40.080 --> 00:45:41.800
is that to you?" You should see what

00:45:41.800 --> 00:45:45.000
what Opus did with um ThoughtWorks

00:45:45.000 --> 00:45:47.320
um Tech Radar, by the way. I I gave it

00:45:47.320 --> 00:45:49.640
the original Tech Radar open source repo

00:45:49.640 --> 00:45:52.880
and I told it I have analyzed my

00:45:52.880 --> 00:45:55.040
internally technology, right? I I I gave

00:45:55.040 --> 00:45:56.920
it access to look at the GitHub. I

00:45:56.920 --> 00:45:59.440
haven't posted it uh but I kept it

00:45:59.440 --> 00:46:01.440
internally. So, and then I said, "Yeah,

00:46:01.440 --> 00:46:02.880
but this is very nice to see the Tech

00:46:02.880 --> 00:46:04.280
radar and why the dot is there and we

00:46:04.280 --> 00:46:05.520
can click on it and we can see a little

00:46:05.520 --> 00:46:07.320
bit of a discussion why this particular

00:46:07.320 --> 00:46:08.720
technology is here because we haven't

00:46:08.720 --> 00:46:10.400
implemented across most of our

00:46:10.400 --> 00:46:13.320
repositories." Cuz you're on a VPN. I

00:46:13.320 --> 00:46:15.040
don't know. Okay, that's a problem.

00:46:15.040 --> 00:46:16.920
You're you're planning your your holiday

00:46:16.920 --> 00:46:19.480
to to Spain. It's definitely an

00:46:19.480 --> 00:46:23.080
Okay, that's a bug.

00:46:23.080 --> 00:46:24.880
That's interesting. So, so basically I

00:46:24.880 --> 00:46:27.320
gave Opus the GitHub repository and then

00:46:27.320 --> 00:46:29.360
I was like making it to give a

00:46:29.360 --> 00:46:31.680
breakdown. So, whatever tech radar item,

00:46:31.680 --> 00:46:33.640
there's several criteria for this item

00:46:33.640 --> 00:46:36.440
to be there like in that in that in that

00:46:36.440 --> 00:46:39.560
band. And I wanted to show that

00:46:39.560 --> 00:46:42.120
technology being used in these projects

00:46:42.120 --> 00:46:44.200
and these repositories. So, it created

00:46:44.200 --> 00:46:46.640
another page. When you click on any dot,

00:46:46.640 --> 00:46:48.760
it will then show like the bat like the

00:46:48.760 --> 00:46:50.640
number of reports this this technology

00:46:50.640 --> 00:46:53.200
is active in.

00:46:53.200 --> 00:46:56.440
Cool. Cool. Cool. Cool. Opus again just

00:46:56.440 --> 00:46:58.680
expanded on this with the ability to

00:46:58.680 --> 00:47:00.600
give like a slice and dice kind of

00:47:00.600 --> 00:47:02.320
experience of

00:47:02.320 --> 00:47:03.800
Yeah, I like what you've done there. I

00:47:03.800 --> 00:47:07.200
should probably use AI for more

00:47:07.200 --> 00:47:09.920
visualizations like that. And it's hard

00:47:09.920 --> 00:47:11.880
to do it like you can try to create a

00:47:11.880 --> 00:47:13.760
slides or you can try to create an Excel

00:47:13.760 --> 00:47:15.320
spreadsheet or you can try to ask it

00:47:15.320 --> 00:47:17.160
with the color X color draw to to draw

00:47:17.160 --> 00:47:20.520
some diagrams, but the real power, even

00:47:20.520 --> 00:47:21.840
the one that you shared earlier when you

00:47:21.840 --> 00:47:23.160
look at like

00:47:23.160 --> 00:47:24.920
and we never we only did the top row of

00:47:24.920 --> 00:47:28.000
like common agent like bad practices,

00:47:28.000 --> 00:47:29.760
when you hover every single one of them

00:47:29.760 --> 00:47:32.080
gets like a little interactivity. Like

00:47:32.080 --> 00:47:34.120
this type of stuff is so much easier to

00:47:34.120 --> 00:47:36.120
build with um

00:47:36.120 --> 00:47:38.920
with with AI. Yeah. Yeah, I need I need

00:47:38.920 --> 00:47:41.640
to build something like this.

00:47:41.640 --> 00:47:43.040
Uh

00:47:43.040 --> 00:47:46.200
for I mean this I feel like

00:47:46.200 --> 00:47:48.400
when I interact with my open claw, half

00:47:48.400 --> 00:47:50.840
the time I'm just I'm just asking like,

00:47:50.840 --> 00:47:52.960
"Should I buy, you know, this product or

00:47:52.960 --> 00:47:55.280
should or is this product better?" And

00:47:55.280 --> 00:47:57.800
half the time when I talk with AI, I'm

00:47:57.800 --> 00:48:00.720
trying to evaluate some options. So, it

00:48:00.720 --> 00:48:02.080
would be great

00:48:02.080 --> 00:48:04.200
to

00:48:04.200 --> 00:48:06.880
have AI just flesh it out a bit. I

00:48:06.880 --> 00:48:08.760
didn't This was also not my original

00:48:08.760 --> 00:48:10.720
idea because the

00:48:10.720 --> 00:48:11.800
um

00:48:11.800 --> 00:48:14.080
Brickman, Evgeny Brickman from Grant

00:48:14.080 --> 00:48:17.040
Works, he posted a blog on uh on

00:48:17.040 --> 00:48:19.000
LinkedIn saying that he was evaluating,

00:48:19.000 --> 00:48:21.080
I don't know what it was, uh different

00:48:21.080 --> 00:48:24.920
backup uh storage arrays for his home um

00:48:24.920 --> 00:48:27.120
system. And he was waiting them against

00:48:27.120 --> 00:48:29.880
pricing and features and whatever. Uh I

00:48:29.880 --> 00:48:31.400
don't I'm just making up what exactly it

00:48:31.400 --> 00:48:32.640
was, but it was something like that. It

00:48:32.640 --> 00:48:34.360
was something like backup solutions. And

00:48:34.360 --> 00:48:36.440
he had said, "I I used AI to create a

00:48:36.440 --> 00:48:39.160
little like a comparison chart and the

00:48:39.160 --> 00:48:43.280
ability to modify like my criteria." And

00:48:43.280 --> 00:48:45.320
And before I started on tacos.guru, I

00:48:45.320 --> 00:48:47.280
did go back and search for his blog

00:48:47.280 --> 00:48:49.960
post, uh which was on his personal blog,

00:48:49.960 --> 00:48:52.160
and then look again exactly what it was.

00:48:52.160 --> 00:48:53.280
But um

00:48:53.280 --> 00:48:54.680
I didn't remember it exactly right

00:48:54.680 --> 00:48:56.360
because it was a little bit more limited

00:48:56.360 --> 00:48:58.800
than what I wanted. So, I did then just

00:48:58.800 --> 00:49:00.880
take the idea and and and build uh

00:49:00.880 --> 00:49:03.640
tacos.guru. So, so yeah. Yeah. Uh quick

00:49:03.640 --> 00:49:05.040
side note,

00:49:05.040 --> 00:49:06.720
if you were to if you had the

00:49:06.720 --> 00:49:08.360
requirement from a client to to build

00:49:08.360 --> 00:49:11.680
out Kubernetes, would you use Terraform

00:49:11.680 --> 00:49:13.600
or to Yeah, I think so.

00:49:13.600 --> 00:49:15.400
>> bootstrap it? Yeah, yeah, yeah, yeah.

00:49:15.400 --> 00:49:17.600
You wouldn't You wouldn't go CDK? I

00:49:17.600 --> 00:49:19.600
mean, CDK is better fit for AWS

00:49:19.600 --> 00:49:22.160
constructs, right? AWS

00:49:22.160 --> 00:49:22.840
uh

00:49:22.840 --> 00:49:24.320
services.

00:49:24.320 --> 00:49:25.040
>> I have to say

00:49:25.040 --> 00:49:26.920
>> There's the EKS blueprints repository,

00:49:26.920 --> 00:49:29.080
which uses AWS CDK,

00:49:29.080 --> 00:49:32.000
but it was built before the Kubernetes

00:49:32.000 --> 00:49:35.040
CDK. So, there's a CDK for Kubernetes,

00:49:35.040 --> 00:49:37.800
and it automatically creates like the L1

00:49:37.800 --> 00:49:39.600
bindings and then creates L2s, and it's

00:49:39.600 --> 00:49:40.800
really nice.

00:49:40.800 --> 00:49:42.960
Um what that means is that somebody in

00:49:42.960 --> 00:49:45.440
the EKS blueprint repository kind of

00:49:45.440 --> 00:49:46.880
wrote some TypeScript interface to

00:49:46.880 --> 00:49:48.840
represent a Kubernetes manifest, like

00:49:48.840 --> 00:49:50.560
what are the mandatory fields that you

00:49:50.560 --> 00:49:53.280
need to do. Um which is very rudimentary

00:49:53.280 --> 00:49:55.200
and that's how they they bootstrap EKS

00:49:55.200 --> 00:49:58.280
clusters with like very rudimentary um,

00:49:58.280 --> 00:49:59.720
representation of what Kubernetes

00:49:59.720 --> 00:50:02.360
objects are like compared to CD gates

00:50:02.360 --> 00:50:04.200
which automatically

00:50:04.200 --> 00:50:06.360
builds uh, a type script representation

00:50:06.360 --> 00:50:09.840
of every open API open API schema in

00:50:09.840 --> 00:50:12.200
Kubernetes. Okay, so this is this is

00:50:12.200 --> 00:50:14.240
fully EKS but but you would still use

00:50:14.240 --> 00:50:17.200
Terraform, right? Or Yeah, so I I I

00:50:17.200 --> 00:50:18.960
really like CD gate for Kubernetes to

00:50:18.960 --> 00:50:21.480
manage my Kubernetes deployments but

00:50:21.480 --> 00:50:23.000
like not many unless you're in the CD

00:50:23.000 --> 00:50:24.600
gate ecosystem it's probably not worth

00:50:24.600 --> 00:50:26.000
it, right?

00:50:26.000 --> 00:50:27.680
Oh, okay. So you use this to manage your

00:50:27.680 --> 00:50:29.000
deployments but not but not the

00:50:29.000 --> 00:50:32.280
>> Not the actual bootstrap. So what I did

00:50:32.280 --> 00:50:35.120
3 years ago was I implemented

00:50:35.120 --> 00:50:37.520
um, clusters

00:50:37.520 --> 00:50:40.880
using some of the EKS blueprint patterns

00:50:40.880 --> 00:50:42.320
which is like they have like builder

00:50:42.320 --> 00:50:45.040
pattern and other patterns to to to

00:50:45.040 --> 00:50:47.760
build with AWS CD gate. Um, but I didn't

00:50:47.760 --> 00:50:49.960
feel it was such a great experience. It

00:50:49.960 --> 00:50:52.640
became it was not that good. Um,

00:50:52.640 --> 00:50:53.840
Terraform modules are very well

00:50:53.840 --> 00:50:55.920
established like the Terraform module

00:50:55.920 --> 00:50:59.360
for EKS is is well established. Um, I do

00:50:59.360 --> 00:51:02.520
not like it. It's way complicated. Um,

00:51:02.520 --> 00:51:05.160
but it's way more widespread. I mean

00:51:05.160 --> 00:51:06.880
>> Okay, so so if you're deploying

00:51:06.880 --> 00:51:08.760
Kubernetes on

00:51:08.760 --> 00:51:10.640
on AWS you would use this Terraform

00:51:10.640 --> 00:51:13.320
thing. I mean I I wouldn't, right? I

00:51:13.320 --> 00:51:14.960
mean I would I would land in a team that

00:51:14.960 --> 00:51:16.560
does it and I would tell them I think

00:51:16.560 --> 00:51:18.320
I'll I think I used this in the past and

00:51:18.320 --> 00:51:20.000
I thought it was

00:51:20.000 --> 00:51:22.080
really heavyweight but It is very

00:51:22.080 --> 00:51:24.000
heavyweight and and it's impossible to

00:51:24.000 --> 00:51:26.280
support every because you know, EKS team

00:51:26.280 --> 00:51:28.160
keeps adding features like now they have

00:51:28.160 --> 00:51:30.200
completely managed add-ons.

00:51:30.200 --> 00:51:32.280
Yeah, I'm surprised you

00:51:32.280 --> 00:51:34.440
you you didn't gravitate to using CD

00:51:34.440 --> 00:51:36.400
gate for this. I mean it's just I guess

00:51:36.400 --> 00:51:39.400
it's just an experience. My goal with

00:51:39.400 --> 00:51:42.800
Sarah constructs was to port EKS

00:51:42.800 --> 00:51:45.400
blueprints for AWS CD gate to Terraform

00:51:45.400 --> 00:51:48.080
CD gate to get rid of the stupid module.

00:51:48.080 --> 00:51:49.880
So, my goal was to build and I have

00:51:49.880 --> 00:51:52.560
already got EC2 instance profile.

00:51:52.560 --> 00:51:55.040
Um I've got load balancers, everything.

00:51:55.040 --> 00:51:56.760
The only thing I don't have I have auto

00:51:56.760 --> 00:51:59.800
scaling group also, but I don't have

00:51:59.800 --> 00:52:01.480
um

00:52:01.480 --> 00:52:02.800
No, I think I don't have auto scaling

00:52:02.800 --> 00:52:04.840
group. And I need auto scaling group to

00:52:04.840 --> 00:52:08.440
do um self-hosted um configurations.

00:52:08.440 --> 00:52:12.160
The thing is the AWS CDK L2s for EKS

00:52:12.160 --> 00:52:15.520
depend on every single EC2 um every

00:52:15.520 --> 00:52:16.880
single load balance like it depends on

00:52:16.880 --> 00:52:18.800
so many other modules that to get to

00:52:18.800 --> 00:52:20.600
that point, I have to port everything

00:52:20.600 --> 00:52:21.600
else.

00:52:21.600 --> 00:52:23.360
Um but I told you that I like

00:52:23.360 --> 00:52:26.760
>> with the CDK, surely. If all these Yeah,

00:52:26.760 --> 00:52:29.000
I think so. I I think so because

00:52:29.000 --> 00:52:30.800
honestly they it's way more intuitive

00:52:30.800 --> 00:52:32.680
and it's where the the EKS product team

00:52:32.680 --> 00:52:33.960
is probably contributing. Like they

00:52:33.960 --> 00:52:35.040
they're adding the features into

00:52:35.040 --> 00:52:36.760
CloudFormation and then they're adding

00:52:36.760 --> 00:52:38.760
the feature into AWS CDK. And then

00:52:38.760 --> 00:52:40.360
somebody from the community needs to add

00:52:40.360 --> 00:52:42.760
it into Terraform AWS EKS, which becomes

00:52:42.760 --> 00:52:44.720
more and more bloated uh and is an

00:52:44.720 --> 00:52:46.720
absolute nightmare, but for some reason

00:52:46.720 --> 00:52:49.720
still has 5K stars. Yeah. Yeah, I mean

00:52:49.720 --> 00:52:51.680
he's This guy's done a few things. I'm

00:52:51.680 --> 00:52:53.040
trying to remember all the things he's

00:52:53.040 --> 00:52:56.680
done. Um he wrote um the three command

00:52:56.680 --> 00:52:59.240
one which which is which is a which is a

00:52:59.240 --> 00:53:02.080
great example of why you should use CDK.

00:53:02.080 --> 00:53:04.400
Exactly. And the thing is when when he

00:53:04.400 --> 00:53:06.960
was doing YouTube streams on on working

00:53:06.960 --> 00:53:09.320
on this Lambda module, I showed him CDK

00:53:09.320 --> 00:53:10.760
for Terraform. I showed him Terra

00:53:10.760 --> 00:53:12.440
Constructs. I showed him complete

00:53:12.440 --> 00:53:15.080
bundling solution with complete IAM

00:53:15.080 --> 00:53:17.520
permissions preset and he said he really

00:53:17.520 --> 00:53:19.360
liked it, but he wouldn't spend any time

00:53:19.360 --> 00:53:20.520
on it.

00:53:20.520 --> 00:53:21.920
Well, I think he's made a name for

00:53:21.920 --> 00:53:24.320
himself for Terraform. Yeah, he also

00:53:24.320 --> 00:53:26.640
shared he also shared Terra Constructs.

00:53:26.640 --> 00:53:28.240
>> Serverless TF as a newsletter, yeah.

00:53:28.240 --> 00:53:30.200
Yeah. No, this was Yeah, he was building

00:53:30.200 --> 00:53:32.240
Serverless TF and I was like, "Why would

00:53:32.240 --> 00:53:33.800
you do that?" And then he he built

00:53:33.800 --> 00:53:36.160
Compliance TF, which I think makes

00:53:36.160 --> 00:53:38.920
sense. He He's He's built it for a year.

00:53:38.920 --> 00:53:40.920
He wants to like 12 or I don't know how

00:53:40.920 --> 00:53:43.560
many conference talks. It's to you you

00:53:43.560 --> 00:53:44.760
need you can select what sort of

00:53:44.760 --> 00:53:46.320
compliance you want and then it's going

00:53:46.320 --> 00:53:48.520
to bootstrap the modules uh his

00:53:48.520 --> 00:53:49.760
Terraform modules and then it's going to

00:53:49.760 --> 00:53:51.160
apply the compliance rules and it's

00:53:51.160 --> 00:53:52.400
going to make make sure that they are

00:53:52.400 --> 00:53:54.160
compliant to your compliance

00:53:54.160 --> 00:53:56.040
requirements. This actually sounds

00:53:56.040 --> 00:53:58.040
useful for at least one thing that I

00:53:58.040 --> 00:53:59.680
used to work on. Yeah, so for me

00:53:59.680 --> 00:54:01.040
personally

00:54:01.040 --> 00:54:02.960
I feel this is a waste of time and you

00:54:02.960 --> 00:54:05.440
should you should use aspects and you

00:54:05.440 --> 00:54:07.880
should use CDK aspects. Okay, oh yeah.

00:54:07.880 --> 00:54:09.160
Oh actually that's one thing I need to

00:54:09.160 --> 00:54:11.480
work on today. I need to I need to prove

00:54:11.480 --> 00:54:13.840
that that some level two level three

00:54:13.840 --> 00:54:16.160
constructs were deployed in certain

00:54:16.160 --> 00:54:19.560
stacks. Oh yeah, you asked me last time.

00:54:19.560 --> 00:54:21.280
Yeah, I think you we talked about it but

00:54:21.280 --> 00:54:23.600
uh so if I can if I can produce a bill

00:54:23.600 --> 00:54:25.760
of materials to say that this construct

00:54:25.760 --> 00:54:27.200
is here, that's what I need to do. I

00:54:27.200 --> 00:54:29.240
mean compliance half the time it is

00:54:29.240 --> 00:54:31.080
about

00:54:31.080 --> 00:54:32.920
giving a nice list of a bill a bill of

00:54:32.920 --> 00:54:35.080
materials as I like to call it.

00:54:35.080 --> 00:54:38.000
I mean maybe I'm but I am

00:54:38.000 --> 00:54:40.000
I am uh what do you call it Trivy

00:54:40.000 --> 00:54:41.640
fuzzing everything here but yeah, a bill

00:54:41.640 --> 00:54:44.200
of materials I feel is is the critical

00:54:44.200 --> 00:54:46.640
concept. Okay, cool man. We didn't talk

00:54:46.640 --> 00:54:48.960
about a Trivy hack. We did. I mean You

00:54:48.960 --> 00:54:50.960
mentioned about the fork. No, we you

00:54:50.960 --> 00:54:52.680
just quickly short mentioned that you

00:54:52.680 --> 00:54:54.880
could access fork. I mean that's how

00:54:54.880 --> 00:54:57.520
that's how uh Unleash itself. I mean Oh

00:54:57.520 --> 00:54:59.880
man, it's insane to know. Sorry, I

00:54:59.880 --> 00:55:01.560
I can't really share

00:55:01.560 --> 00:55:03.240
WhatsApp, can I? Do you do you have a

00:55:03.240 --> 00:55:05.120
link to that? Yeah, maybe we can at

00:55:05.120 --> 00:55:06.920
least put a link to it. Yeah, so the

00:55:06.920 --> 00:55:08.520
most interesting

00:55:08.520 --> 00:55:09.520
um

00:55:09.520 --> 00:55:11.560
I I I should put the link there but the

00:55:11.560 --> 00:55:13.560
most interesting breakdown I mean first

00:55:13.560 --> 00:55:15.680
of all was three three

00:55:15.680 --> 00:55:16.920
events, right? The first one at the

00:55:16.920 --> 00:55:20.400
beginning of March where the

00:55:20.400 --> 00:55:22.800
claw bot like the hacker bot, the bot

00:55:22.800 --> 00:55:24.600
that was like a claw bot that was

00:55:24.600 --> 00:55:26.880
configured to find vulnerabilities

00:55:26.880 --> 00:55:28.360
basically

00:55:28.360 --> 00:55:32.320
um proved a vulner like a problem with

00:55:32.320 --> 00:55:34.800
the way that the Trivy GitHub workflows

00:55:34.800 --> 00:55:36.440
were set up. I mean it it got some

00:55:36.440 --> 00:55:39.560
compromise into the Trivy set up, right?

00:55:39.560 --> 00:55:41.280
That was the first event.

00:55:41.280 --> 00:55:42.680
Um

00:55:42.680 --> 00:55:45.160
They had to like erase

00:55:45.160 --> 00:55:47.120
maybe the cloud bot hitting five or six

00:55:47.120 --> 00:55:49.720
different targets was to to hide the

00:55:49.720 --> 00:55:51.320
actual Trivy

00:55:51.320 --> 00:55:53.160
um foothold because I think at that

00:55:53.160 --> 00:55:54.960
point they got a foothold, they got some

00:55:54.960 --> 00:55:57.360
credentials, and they got um access to

00:55:57.360 --> 00:55:59.680
Trivy, right? And um

00:55:59.680 --> 00:56:01.920
Trivy had Trivy had nuked the repository

00:56:01.920 --> 00:56:03.880
and had to re- re- re-enable it. Like,

00:56:03.880 --> 00:56:05.600
Trivy was gone. The GitHub action was

00:56:05.600 --> 00:56:07.960
gone for for a few days. And or and

00:56:07.960 --> 00:56:09.320
people were like, "Oh, my Trivy things

00:56:09.320 --> 00:56:11.040
are failing." All of it's because the

00:56:11.040 --> 00:56:12.520
repo was nuked and things like that,

00:56:12.520 --> 00:56:14.560
right? Oh, my god. Yeah, and then the

00:56:14.560 --> 00:56:16.360
second thing that happened is people

00:56:16.360 --> 00:56:18.400
started to realize the binary had

00:56:18.400 --> 00:56:21.640
compromised, and it started stealing

00:56:21.640 --> 00:56:24.480
secrets. So, anyone who had run the

00:56:24.480 --> 00:56:27.440
Trivy action had exfiltrated their

00:56:27.440 --> 00:56:29.520
secrets. Like, it had several paths to

00:56:29.520 --> 00:56:32.000
identify Yeah, but the people don't

00:56:32.000 --> 00:56:33.840
understand the impact because the Trivy

00:56:33.840 --> 00:56:35.280
binary and the GitHub Trivy GitHub

00:56:35.280 --> 00:56:36.960
action and that scanner live in the

00:56:36.960 --> 00:56:39.360
Datadog agent, live in the Go Teleport

00:56:39.360 --> 00:56:41.600
privileged access management repository.

00:56:41.600 --> 00:56:44.320
It is so widespread across the community

00:56:44.320 --> 00:56:48.000
that all of these repositories should

00:56:48.000 --> 00:56:50.360
step forward and highlight how they were

00:56:50.360 --> 00:56:52.520
affected by the hack, if at all. Yeah, I

00:56:52.520 --> 00:56:54.720
mean, I don't want to mention names, but

00:56:54.720 --> 00:56:57.080
I know some big enterprises use Trivy,

00:56:57.080 --> 00:56:59.080
and I just don't know I don't want to

00:56:59.080 --> 00:57:00.520
even think about what the hell's

00:57:00.520 --> 00:57:01.800
happened there.

00:57:01.800 --> 00:57:05.000
Yeah, so it's Luckily, I did I did I did

00:57:05.000 --> 00:57:07.000
search around GitHub to see if anyone in

00:57:07.000 --> 00:57:08.520
my org was using it, and no one was

00:57:08.520 --> 00:57:10.400
using it. But, we don't use containers

00:57:10.400 --> 00:57:12.360
very much, thank god. It's Trivy doesn't

00:57:12.360 --> 00:57:13.680
scan only containers. It was a

00:57:13.680 --> 00:57:16.080
replacement to Terraform scanner

00:57:16.080 --> 00:57:17.800
uh after Terraform scanner was acquired

00:57:17.800 --> 00:57:20.000
by I don't know, was it Snyk? Well, I

00:57:20.000 --> 00:57:21.760
just did a I I did a GitHub search for

00:57:21.760 --> 00:57:23.800
Trivy, and we don't use it, so. Okay.

00:57:23.800 --> 00:57:26.840
So, so it's used for IAC scanning, it's

00:57:26.840 --> 00:57:28.720
used for virtual machine scanning, like

00:57:28.720 --> 00:57:31.040
AMIs. You can run on your Linux Linux

00:57:31.040 --> 00:57:34.760
machine for file system it's downloaded.

00:57:34.760 --> 00:57:35.120
So,

00:57:35.120 --> 00:57:37.760
>> I have always wanted to deploy it.

00:57:37.760 --> 00:57:39.120
Uh but I've used it.

00:57:39.120 --> 00:57:40.720
>> Everyone's been quiet now. Like, no we

00:57:40.720 --> 00:57:43.240
don't use Trivy. No, I I I wanted to

00:57:43.240 --> 00:57:44.880
deploy it and it's I have it on some

00:57:44.880 --> 00:57:46.360
Jira tickets where like we should use

00:57:46.360 --> 00:57:48.600
Trivy for this cuz we pay for snake and

00:57:48.600 --> 00:57:50.520
crowd strike and all this stuff and then

00:57:50.520 --> 00:57:52.040
and then I'm like, why, you know, it we

00:57:52.040 --> 00:57:55.400
can get Trivy. Trivy is good.

00:57:55.400 --> 00:57:57.200
But like, okay, let's let's run through

00:57:57.200 --> 00:57:58.960
this a little bit. So, okay, say there's

00:57:58.960 --> 00:58:02.240
a GitHub action and it steals

00:58:02.240 --> 00:58:05.760
um secrets inside the GitHub action flow

00:58:05.760 --> 00:58:07.640
where the Trivy scan is happening. I

00:58:07.640 --> 00:58:09.880
mean, usually A, they're short-lived and

00:58:09.880 --> 00:58:11.480
B, like what would you even do with

00:58:11.480 --> 00:58:13.880
these secrets? Cuz a lot of the secrets

00:58:13.880 --> 00:58:15.720
like what can you think of a well,

00:58:15.720 --> 00:58:17.400
something that it's looking for like an

00:58:17.400 --> 00:58:19.320
Anthropic API key or

00:58:19.320 --> 00:58:21.400
>> mentioned that you still use PATs. Yeah,

00:58:21.400 --> 00:58:24.600
but aren't PATs Oh, yeah, I on a GitHub

00:58:24.600 --> 00:58:27.440
in GitHub PATs are pretty long-lived

00:58:27.440 --> 00:58:28.200
usually, aren't they?

00:58:28.200 --> 00:58:28.720
>> Yeah.

00:58:28.720 --> 00:58:30.040
And then the second thing that what I

00:58:30.040 --> 00:58:32.160
see that that actually connects very

00:58:32.160 --> 00:58:33.480
well what we were saying earlier with

00:58:33.480 --> 00:58:34.400
GitHub because

00:58:34.400 --> 00:58:37.320
>> PATs. PATs is like a hole in the system,

00:58:37.320 --> 00:58:37.840
isn't it?

00:58:37.840 --> 00:58:41.360
>> Yeah, but also I don't think

00:58:41.360 --> 00:58:43.520
using GitHub apps

00:58:43.520 --> 00:58:45.120
like the way that I see GitHub apps

00:58:45.120 --> 00:58:47.120
being used mostly

00:58:47.120 --> 00:58:50.760
is you use the app ID and its secret key

00:58:50.760 --> 00:58:52.440
to get an installation short-lived

00:58:52.440 --> 00:58:54.560
token. That means

00:58:54.560 --> 00:58:56.240
but that's probably in a separate job,

00:58:56.240 --> 00:58:58.240
you actually do run

00:58:58.240 --> 00:59:02.480
a short step where you get the

00:59:02.480 --> 00:59:03.120
Oh, where

00:59:03.120 --> 00:59:05.560
>> Sorry, I think I need to Sorry, my kid

00:59:05.560 --> 00:59:07.160
is call- calling me. I have to take you

00:59:07.160 --> 00:59:08.680
to school. I think mommy says you have

00:59:08.680 --> 00:59:10.440
to take you to school. Deflection. I

00:59:10.440 --> 00:59:13.040
think my wife told me Deflection. Okay,

00:59:13.040 --> 00:59:14.640
I think let's let's end it there. Sorry,

00:59:14.640 --> 00:59:16.040
I got to take my kids to school. Just

00:59:16.040 --> 00:59:17.680
finish your point and then and then I'll

00:59:17.680 --> 00:59:20.240
close the call. I wonder how effective

00:59:20.240 --> 00:59:21.360
Oh, I think I know what you're saying.

00:59:21.360 --> 00:59:23.520
The PAT becomes a GitHub token. Is the

00:59:23.520 --> 00:59:25.200
PAT still exposed? I think you're you're

00:59:25.200 --> 00:59:27.720
to say. No, the GitHub app the GitHub

00:59:27.720 --> 00:59:28.400
app

00:59:28.400 --> 00:59:30.880
requires a long-lived secret, also. So,

00:59:30.880 --> 00:59:32.840
I don't know how you like you need a a

00:59:32.840 --> 00:59:35.000
the GitHub app key to get a token. So,

00:59:35.000 --> 00:59:37.120
you need to have a key exposed somewhere

00:59:37.120 --> 00:59:38.960
into a workflow that gets a temporary

00:59:38.960 --> 00:59:40.400
token, and then you can use that token

00:59:40.400 --> 00:59:42.320
to do things. So, you need to really

00:59:42.320 --> 00:59:44.520
segregate those two, right?

00:59:44.520 --> 00:59:45.560
Anyway.

00:59:45.560 --> 00:59:48.040
So, so it's still dangerous. It's still

00:59:48.040 --> 00:59:49.840
like still easy to shoot yourself in the

00:59:49.840 --> 00:59:52.480
foot. If in the same runner, you are

00:59:52.480 --> 00:59:54.760
getting the key, getting a token, then

00:59:54.760 --> 00:59:56.200
if that the key is still in that same

00:59:56.200 --> 00:59:57.720
runner, something could accidentally

00:59:57.720 --> 00:59:59.000
trade it. You should really have like a

00:59:59.000 --> 01:00:00.800
separate job, a completely different

01:00:00.800 --> 01:00:03.440
runner, to get a temporary token for for

01:00:03.440 --> 01:00:05.240
the GitHub app, and then feed that into

01:00:05.240 --> 01:00:07.200
your job that needs to do the activity.

01:00:07.200 --> 01:00:09.120
I think the I mean the risk the risk is

01:00:09.120 --> 01:00:11.120
here is that that someone can can get

01:00:11.120 --> 01:00:13.120
into your GitHub account and go crazy, I

01:00:13.120 --> 01:00:15.640
suppose, given a and can can use the

01:00:15.640 --> 01:00:16.920
GitHub app

01:00:16.920 --> 01:00:18.440
permissions to do whatever the GitHub

01:00:18.440 --> 01:00:18.720
app

01:00:18.720 --> 01:00:20.680
>> most people most big organizations have

01:00:20.680 --> 01:00:22.240
approvals and things like that.

01:00:22.240 --> 01:00:23.880
>> GitHub apps usually yeah, they're very

01:00:23.880 --> 01:00:25.960
they they are very fine-grained tokens,

01:00:25.960 --> 01:00:27.440
and every single permission that the

01:00:27.440 --> 01:00:29.720
GitHub app has is way way visible. Like

01:00:29.720 --> 01:00:31.600
it's not like a user that creates a I

01:00:31.600 --> 01:00:33.120
assume you mean GitHub apps, which is

01:00:33.120 --> 01:00:35.120
really hard to set up for some reason.

01:00:35.120 --> 01:00:36.400
You should be using GitHub apps. Yeah,

01:00:36.400 --> 01:00:37.680
it's it's definitely a lot more secure.

01:00:37.680 --> 01:00:39.520
>> We all should be using GitHub apps. And

01:00:39.520 --> 01:00:41.080
apparently you shouldn't be pinning your

01:00:41.080 --> 01:00:43.920
commits to to your GitHub actions, cuz

01:00:43.920 --> 01:00:45.640
that was a long long time established

01:00:45.640 --> 01:00:47.600
pattern, and that's how they got in as

01:00:47.600 --> 01:00:49.520
well. People are now like, "Yeah, you

01:00:49.520 --> 01:00:51.200
can't use a sha because the sha can be

01:00:51.200 --> 01:00:53.040
pulled from a fork, and then you can

01:00:53.040 --> 01:00:54.880
compromise the repo." That's the second

01:00:54.880 --> 01:00:56.720
problem. Anyway.

01:00:56.720 --> 01:00:58.480
Yeah, okay. Well, anyway, great speaking

01:00:58.480 --> 01:01:00.400
with you, Vincent. Yep.

01:01:00.400 --> 01:01:01.680
We'll catch up another time. See you.

01:01:01.680 --> 01:01:05.000
>> Yeah, yeah, yeah. See you. Bye.

