<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0"><channel><title>Pulumi Blog: Eric Rudder</title><link>https://www.pulumi.com/blog/author/eric-rudder/</link><description>Pulumi blog posts: Eric Rudder.</description><language>en-us</language><pubDate>Thu, 07 Jan 2021 00:00:00 +0000</pubDate><item><title>Pulumi is SOC 2 Certified</title><link>https://www.pulumi.com/blog/pulumis-soc-2-milestone/</link><pubDate>Thu, 07 Jan 2021 00:00:00 +0000</pubDate><guid>https://www.pulumi.com/blog/pulumis-soc-2-milestone/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/pulumis-soc-2-milestone/index.png" /&gt;
&lt;h2 id="pulumis-commitment"&gt;Pulumi’s Commitment&lt;/h2&gt;
&lt;p&gt;Pulumi is committed to operational excellence for our customers and one of the ways that we decided to demonstrate this was by completing our SOC 2 Type 2 Audit. After a lot of hard work these past few months, we are pleased to announce that Pulumi is now &lt;a href="https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services"&gt;SOC 2&lt;/a&gt; compliant!&lt;/p&gt;
&lt;p&gt;The audit involved the entire Pulumi team. We needed to have proper controls in place across the organization and ensure that our key processes were documented and exercised. In addition, we reviewed our vendor selection process and made sure that all of our key partners were compliant with SOC as well. Our team used the overall process as an opportunity to review our overall governance and risk management procedures. Interestingly, the change in our work environment caused by Covid-19 actually helped us stress some of our process and policies, since we were forced to work remotely, much as if we had any type of interesting “event” at our headquarters.&lt;/p&gt;
&lt;p&gt;Of course, we spent a large amount of time reviewing the &lt;a href="https://www.pulumi.com/security/"&gt;security of our service&lt;/a&gt;. Security is already baked into our culture, with processes around training, code reviews, and the like, however, there’s no doubt this process helped us “up our game.” The policies that we already had in place (encryption of data at rest and in transit, auditing, logging, secure backup, etc.) gave us a strong foundation, however, as we reviewed key areas we found several areas for simplification and improvement.&lt;/p&gt;
&lt;h2 id="the-soc-2-journey"&gt;The SOC 2 Journey&lt;/h2&gt;
&lt;p&gt;As an organization, SOC 2 requires us to promise that we abide by well-documented policies, procedures, and operational controls and to prove it to an accredited firm that reviews our operational discipline for several months. We were fortunate to find a great partner that was a superb resource as we initiated our first report. The auditors had to review a tremendous amount of data, much of it over shared screens in Zoom. Their experience also helped us think about how we can continuously improve in several key areas.&lt;/p&gt;
&lt;p&gt;We decided to use a third party tool to help with the process. In retrospect, this was one of the best decisions we made, and picking a tool that fits with your organization is hugely important. Our engineering culture definitely believes in “get clean, stay clean” and a great tool that automates many of the routine checks is indispensable. In addition, having a central dashboard that lets you know “where you are” in your journey is incredibly valuable and can really help motivate the team. The tool also helped us find a number of enhancements that go above and beyond what SOC strictly requires. For example, we created a network diagram, which, while not strictly a SOC requirement, was a suggestion from the tool. Finally, all team members now have agent software on their laptops that helps maintain key standards that we’ve chosen for our security profile.&lt;/p&gt;
&lt;p&gt;In addition, much of the operational excellence for SOC certification requires great DevOps discipline. Here, we had a huge insider’s advantage! We were able to use Pulumi itself to automate key procedures required by the process.&lt;/p&gt;
&lt;h2 id="going-forward"&gt;Going Forward&lt;/h2&gt;
&lt;p&gt;While we already had the key cultural attributes required for operational excellence, our SOC 2 journey was a great way to reinforce the importance of this to the entire team. Security, privacy, and resiliency are everyone’s job!&lt;/p&gt;
&lt;p&gt;We’ve added additional training, and some templates and processes that will help us do an even better job in the future.&lt;/p&gt;
&lt;p&gt;We have a leadership team that reviews key areas of the SOC profile quarterly, with each quarter having a special focus. For example, one quarter may focus on security, while the next may zero-in on disaster recovery. The meetings are documented and any work items identified go onto our team’s task list.&lt;/p&gt;
&lt;p&gt;Most importantly, the journey isn’t over! Pulumi will continue to evolve. The SOC standards will continue to evolve. Industry tools and best practices will continue to evolve. We’ve come a long way since we started our SOC 2 journey and we’re committed to continuing to improve our operational excellence every day.&lt;/p&gt;
&lt;p&gt;If you&amp;rsquo;re interested in learning more about how we approach security at Pulumi or have questions about our SOC 2 process, please &lt;a href="https://www.pulumi.com/contact/"&gt;reach out&lt;/a&gt;. We&amp;rsquo;re happy to share what we&amp;rsquo;ve learned along the way.&lt;/p&gt;</description><author>Eric Rudder</author><category>pulumi-enterprise</category></item><item><title>Infrastructure as Code Resource Naming</title><link>https://www.pulumi.com/blog/infrastructure-as-code-resource-naming/</link><pubDate>Tue, 10 Sep 2019 00:00:00 +0000</pubDate><guid>https://www.pulumi.com/blog/infrastructure-as-code-resource-naming/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/infrastructure-as-code-resource-naming/index.png" /&gt;
&lt;div class="note note-info"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.4a9ac1016b9d8a688a5e7e867f96bdf80115a0739af8c688ba04791e15f64461.svg#p-info-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;We&amp;rsquo;ve introduced a new way to customize or disable auto-naming with a configuration option. See &lt;a href="https://www.pulumi.com/blog/autonaming-configuration/"&gt;Auto-naming Configuration&lt;/a&gt; for more information about all the ways you can customize auto-naming.&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;&amp;ldquo;What&amp;rsquo;s in a name? That which we call a rose by any other name would smell as sweet.&amp;rdquo; William Shakespeare&amp;rsquo;s oft repeated quote was used to help Juliet explain that a &amp;ldquo;Montague&amp;rdquo; is worthy of love. Juliet may have underestimated the importance of a name, however, since things didn&amp;rsquo;t work out so well for everyone in Verona! Many customers have questions about &amp;ldquo;names&amp;rdquo; in Pulumi &amp;ndash; and in an effort to make sure that things work out better for them than they did for Romeo, here&amp;rsquo;s a quick note on naming!&lt;/p&gt;
&lt;p&gt;Usually, folks ask, &amp;ldquo;Why are resources created with funny characters at the end?&amp;rdquo; And more often than not, their next question is, &amp;ldquo;Can I use my own names instead?&amp;rdquo; Fear not! There are good reasons for Pulumi&amp;rsquo;s naming strategy and ultimately, you have complete control over naming.&lt;/p&gt;
&lt;h2 id="logical-vs-physical-names"&gt;Logical vs. Physical Names&lt;/h2&gt;
&lt;p&gt;Cloud resources typically have both a logical and a physical name, and given this level of abstraction, these names may not always match. More often than not, the &lt;a href="https://www.pulumi.com/docs/iac/concepts/resources/names/#autonaming"&gt;physical resource names&lt;/a&gt; in Pulumi are &amp;ldquo;auto-named,&amp;rdquo; and it&amp;rsquo;s this auto-naming that appends a few random characters to end of the physical name.&lt;/p&gt;
&lt;p&gt;Say that you have IAM role with a logical name of &lt;code&gt;role-friar&lt;/code&gt;. Pulumi will choose a physical name for this that looks something more like: &lt;code&gt;role-friar-3742fb&lt;/code&gt;, for several good reasons.&lt;/p&gt;
&lt;p&gt;First and foremost, Pulumi Stacks are often instanced multiple times. Choosing a random suffix ensures that there are no naming collisions, and teams can stand up projects multiple times, for example, in a rapid create/test development cycle, or even in production, where you may want to stand up your Pulumi Stack in different regions for availability and scale.&lt;/p&gt;
&lt;p&gt;Second, physical names are used in important ways when we update our resources. Sometimes, updates can happen in place, however, often updates require a resource to be replaced. Auto-naming helps ensure that Pulumi can stand up the new resource first and update any references to the new name, before deleting the old resource. This allows for zero-downtime updates, which is something we usually want to take advantage of. Indeed, customers often start to override auto-naming, only to realize that it&amp;rsquo;s much easier to let the platform manage this for you, and then revert back to auto-naming.&lt;/p&gt;
&lt;h2 id="controlled-naming"&gt;Controlled Naming&lt;/h2&gt;
&lt;div class="note note-info"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.4a9ac1016b9d8a688a5e7e867f96bdf80115a0739af8c688ba04791e15f64461.svg#p-info-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;We&amp;rsquo;ve introduced a new way to customize or disable auto-naming with a configuration option. See &lt;a href="https://www.pulumi.com/blog/autonaming-configuration/"&gt;Auto-naming Configuration&lt;/a&gt; for more information about all the ways you can customize auto-naming.&lt;/div&gt;
&lt;/div&gt;
&lt;p&gt;There are times, however, where precise naming is important. You might need to match an existing environment, or want to explicitly control other behavior. If you know for certain that you want to control the naming yourself, you can indeed override auto-naming. Simply specify the physical name on your resource during creation. Most resources expose a &lt;code&gt;name&lt;/code&gt; property that may be specified in the argument object to the constructor:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-typescript" data-lang="typescript"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;role&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;aws&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;iam&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;Role&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;role-friar&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;name&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;friar-lawrence&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Sometimes, the &amp;ldquo;name&amp;rdquo; property isn&amp;rsquo;t called name &amp;ndash; just to keep you on your toes. For example, the AWS S3 Bucket requires setting the &lt;code&gt;bucket&lt;/code&gt; property. So, you may have to scan the documentation for the specific resource you are creating to help you with your construction. There are also a few resources (like &lt;code&gt;aws.kms.Key&lt;/code&gt;) that don&amp;rsquo;t have physical names and instead use other auto-generated IDs to uniquely identify them.&lt;/p&gt;
&lt;h2 id="a-happy-ending"&gt;A Happy Ending&lt;/h2&gt;
&lt;p&gt;Eventually the Montagues and Capulets made peace. I&amp;rsquo;m sure you too will find peace with a naming strategy that works for you, whether it&amp;rsquo;s fully automatic, fully manual or a combination of both.&lt;/p&gt;</description><author>Eric Rudder</author><category>features</category></item></channel></rss>