<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0"><channel><title>Pulumi Blog: Matty Stratton</title><link>https://www.pulumi.com/blog/author/matt-stratton/</link><description>Pulumi blog posts: Matty Stratton.</description><language>en-us</language><pubDate>Tue, 03 May 2022 10:04:47 -0500</pubDate><item><title>Introducing the Puluminaries</title><link>https://www.pulumi.com/blog/introducing-the-puluminaries/</link><pubDate>Tue, 03 May 2022 10:04:47 -0500</pubDate><guid>https://www.pulumi.com/blog/introducing-the-puluminaries/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/introducing-the-puluminaries/index.png" /&gt;
&lt;p&gt;Pulumi is more than a way to build, deploy, and manage your infrastructure and cloud applications. Pulumi is also a strong and vibrant community. We are very excited to announce and showcase our new program of community champions, the Puluminaries!&lt;/p&gt;
&lt;img src="puluminaries.png" width="500" height="500" alt="Puluminaries logo"/&gt;
&lt;p&gt;The Puluminaries program was created to recognize members of the Pulumi community who are experts and leaders in the field of programming and infrastructure, but also who give back to the community to make it grow! They help others get started, give feedback to make Pulumi&amp;rsquo;s roadmap even better, and educate people through content or public speaking. The program is open to all members of the community, and we welcome anyone to join the program.&lt;/p&gt;
&lt;p&gt;While the Puluminaries themselves have been active in the community for quite some time, we officially launched the program at &lt;a href="https://pulumi.com/pulumi-up"&gt;PulumiUP&lt;/a&gt; in 2022, and it is our pleasure to introduce the first cohort of members to the program!&lt;/p&gt;
&lt;h2 id="meet-the-puluminaries"&gt;Meet The Puluminaries!&lt;/h2&gt;
&lt;h3 id="engin-diri"&gt;Engin Diri&lt;/h3&gt;
&lt;img src="engin-diri.png" width="200" height="200" alt="Engin Diri"/&gt;
&lt;a data-track="twitter" href="https://twitter.com/_ediri"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#b-x"/&gt;&lt;/svg&gt;
&lt;/a&gt;&amp;nbsp;&lt;a data-track="github" href="https://github.com/dirien"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#b-github"/&gt;&lt;/svg&gt;
&lt;/a&gt;
&lt;p&gt;Engin&amp;rsquo;s excitement for Pulumi is not possible to be measured using current science. He will always share his thoughts on new developments in the Pulumi project, as well as join in for fun and discussion in various PulumiVision livestreams!&lt;/p&gt;
&lt;h3 id="joshua-studt"&gt;Joshua Studt&lt;/h3&gt;
&lt;img src="joshua-studt.png" width="200" height="200" alt="Joshua Studt"/&gt;
&lt;a data-track="github" href="https://github.com/orionstudt"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#b-github"/&gt;&lt;/svg&gt;
&lt;/a&gt;
&lt;p&gt;Joshua is a longtime member of the Pulumi community, and he contributed to the implementation of Automation API for C#.&lt;/p&gt;
&lt;h3 id="kat-morgan"&gt;Kat Morgan&lt;/h3&gt;
&lt;img src="kat-morgan.png" width="200" height="200" alt="Kat Morgan"/&gt;
&lt;a data-track="twitter" href="https://twitter.com/usrbinkat"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#b-x"/&gt;&lt;/svg&gt;
&lt;/a&gt;&amp;nbsp;&lt;a data-track="github" href="https://github.com/usrbinkat"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#b-github"/&gt;&lt;/svg&gt;
&lt;/a&gt;&amp;nbsp;&lt;a data-track="linkedin" href="https://linkedin.com/in/usrbinkat"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#b-linkedin"/&gt;&lt;/svg&gt;
&lt;/a&gt;
&lt;p&gt;Kat has been a helpful member of the Pulumi community - not only providing feedback on real-world use of Pulumi, but also sharing her knowledge with &lt;a href="https://konghq.com/webinars/devmyops-deploy-kong-with-pulumi?utm_souce=pulumi&amp;amp;utm_medium=pulumi"&gt;workshops and webinars&lt;/a&gt;&lt;/p&gt;
&lt;h3 id="komal-ali"&gt;Komal Ali&lt;/h3&gt;
&lt;img src="komal-ali.png" width="200" height="200" alt="Komal Ali"/&gt;
&lt;a data-track="twitter" href="https://twitter.com/zwitkali"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#b-x"/&gt;&lt;/svg&gt;
&lt;/a&gt;&amp;nbsp;&lt;a data-track="github" href="https://github.com/komalali"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#b-github"/&gt;&lt;/svg&gt;
&lt;/a&gt;&amp;nbsp;&lt;a data-track="linkedin" href="https://linkedin.com/in/komal-ali"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#b-linkedin"/&gt;&lt;/svg&gt;
&lt;/a&gt;
&lt;p&gt;In addition to being a Puluminary, Komal is also a Pulumni, having spent time working to make Pulumi a better tool for developers - they were ever-present in making our Python SDK better and creating the &lt;a href="https://www.pulumi.com/docs/using-pulumi/automation-api/"&gt;Automation API&lt;/a&gt;!&lt;/p&gt;
&lt;h3 id="paul-hicks"&gt;Paul Hicks&lt;/h3&gt;
&lt;img src="paul-hicks.png" width="200" height="200" alt="Paul Hicks"/&gt;
&lt;a data-track="github" href="https://github.com/tenwit"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#b-github"/&gt;&lt;/svg&gt;
&lt;/a&gt;
&lt;p&gt;Paul seems to have an answer to everything. He is ever-present in the Pulumi Community, sharing his knowledge to folks who are just getting started, but also bringing to bear his real-world expertise in complex Pulumi implementations. Chances are, if you see a great answer to a question in &lt;a href="https://slack.pulumi.com/"&gt;Pulumi Community Slack&lt;/a&gt;, it came from Paul.&lt;/p&gt;
&lt;h3 id="ringo-de-smet"&gt;Ringo De Smet&lt;/h3&gt;
&lt;img src="ringo-smet.png" width="200" height="200" alt="Ringo De Smet"/&gt;
&lt;a data-track="twitter" href="https://twitter.com/ringods"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#b-x"/&gt;&lt;/svg&gt;
&lt;/a&gt;&amp;nbsp;&lt;a data-track="github" href="https://github.com/ringods"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#b-github"/&gt;&lt;/svg&gt;
&lt;/a&gt;
&lt;p&gt;Ringo is one of the founding board members of &lt;a href="https://www.pulumi.com/blog/2022-03-30-introducing-pulumiverse/"&gt;the Pulumiverse&lt;/a&gt; - a place to interact and collaborate on Pulumi-based libraries, projects, and educational materials. Ringo (along with fellow Puluminary Simen A. W. Olsen) have brought their vision for expanding the Pulumi community to life with the creating of this community-operated space! Ringo also created the &lt;a href="https://github.com/ringods/pulumi-resource"&gt;Pulumi Resource Type for Concourse&lt;/a&gt;, and is ever-present in every community he is a part of, not just Pulumi&amp;rsquo;s!&lt;/p&gt;
&lt;h3 id="rizel-scarlett"&gt;Rizel Scarlett&lt;/h3&gt;
&lt;img src="rizel-scarlett.png" width="200" height="200" alt="Rizel Scarlett"/&gt;
&lt;a data-track="twitter" href="https://twitter.com/blackgirlbytes"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#b-x"/&gt;&lt;/svg&gt;
&lt;/a&gt;&amp;nbsp;&lt;a data-track="github" href="https://github.com/blackgirlbytes"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#b-github"/&gt;&lt;/svg&gt;
&lt;/a&gt;&amp;nbsp;&lt;a data-track="linkedin" href="https://www.linkedin.com/in/rizel-bobb-semple/"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#b-linkedin"/&gt;&lt;/svg&gt;
&lt;/a&gt;
&lt;p&gt;Rizel brings her remarkable talent for guidance and teaching to the Pulumi community. She has participated in many Pulumi events, including Cloud Engineering Summit, and &lt;a href="https://youtu.be/2uQEIYuJBZ4"&gt;appearing on the PulumiVision livestream&lt;/a&gt;.&lt;/p&gt;
&lt;h3 id="simen-a-w-olsen"&gt;Simen A. W. Olsen&lt;/h3&gt;
&lt;img src="simen-olsen.png" width="200" height="200" alt="Simen W Olsen"/&gt;
&lt;a data-track="github" href="https://github.com/cobraz"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.70121449e0dde6f8c01ff68423fffaa0336ecc73c7bbc87506404126694ca58c.svg#b-github"/&gt;&lt;/svg&gt;
&lt;/a&gt;
&lt;p&gt;Another one of the founding board members of &lt;a href="https://www.pulumi.com/blog/2022-03-30-introducing-pulumiverse/"&gt;the Pulumiverse&lt;/a&gt;, Simen has a great passion for technology communities, but especially for the Pulumi community. Simen was instrumental on the &lt;a href="https://github.com/pulumi/actions"&gt;Pulumi GitHub Action&lt;/a&gt; rewrite - designing and rearchitecting it in his free time.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Do you know someone who would make a great Puluminary? Let us know! You can email us at da@pulumi.com with your nominations!&lt;/em&gt;&lt;/p&gt;</description><author>Matty Stratton</author><category>community</category></item><item><title>PulumiUP Workshop Series</title><link>https://www.pulumi.com/blog/pulumiup-workshop-series/</link><pubDate>Tue, 03 May 2022 08:46:08 -0500</pubDate><guid>https://www.pulumi.com/blog/pulumiup-workshop-series/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/pulumiup-workshop-series/index.png" /&gt;
&lt;p&gt;At Pulumi, we’re incredibly fortunate to have over 70 integration partners in our ecosystem – helping shared end-users to build, deploy and manage practically any cloud service they can imagine. Our most popular content often includes workshops that show end-users how to use these powerful integrations. This year for PulumiUP, we’re excited to announce that we’ve teamed up with a number of partners to deliver a workshop track that provides hands-on labs and demonstrations for a variety of platforms and scenarios.&lt;/p&gt;
&lt;h3 id="introduction-to-infrastructure-as-code"&gt;Introduction to Infrastructure as Code&lt;/h3&gt;
&lt;p&gt;Thursday, May 5th at 2:30 PM PDT&lt;/p&gt;
&lt;p&gt;We’ll explain the basics of IaC by exploring how to use Pulumi to build, configure and deploy a real-life, modern application using Docker.&lt;/p&gt;
&lt;h3 id="from-zero-to-production-in-kubernetes"&gt;From Zero to Production in Kubernetes&lt;/h3&gt;
&lt;p&gt;Tuesday, May 10th at 9:00 AM PDT&lt;/p&gt;
&lt;p&gt;Our friends from NGINX will show you how to leverage the power of Python with Pulumi to define and manage your Kubernetes deployments and build powerful abstractions that make getting to production easier than ever before. You’ll learn about the new open-source Modern Application Reference Architecture (MARA) that helps you quickly deploy an app platform that includes Amazon EKS, NGINX Kubernetes ingress controller, logstore, logagent, cert-manager, Prometheus, Grafana, and more.&lt;/p&gt;
&lt;h3 id="kubecrash"&gt;Kubecrash&lt;/h3&gt;
&lt;p&gt;Tuesday, May 17th at 9:00 AM PDT&lt;/p&gt;
&lt;p&gt;Join Pulumi and the maintainers of Linkerd, cert-manager, and other projects for a series of crash courses about Kubernetes and cloud-native, open source technologies.&lt;/p&gt;
&lt;h3 id="getting-started-with-azure-and-infrastructure-as-code"&gt;Getting Started with Azure and Infrastructure as Code&lt;/h3&gt;
&lt;p&gt;Wednesday, June 1st at 9:00 AM PDT&lt;/p&gt;
&lt;p&gt;In this workshop, you will use Pulumi&amp;rsquo;s Azure Native Provider, built directly from the Azure API, to provision infrastructure with Pulumi&amp;rsquo;s Typescript SDK. Join Microsoft Sr. Cloud Advocate, April Edwards, and Pulumi Developer Advocate Matty Stratton for this introduction to IaC.&lt;/p&gt;
&lt;h3 id="end-to-end-infrastructure-apps-and-auth-with-auth0"&gt;End-To-End Infrastructure, Apps, and Auth with Auth0&lt;/h3&gt;
&lt;p&gt;Tuesday, June 7th at 4:00 PM PDT&lt;/p&gt;
&lt;p&gt;In this live-coding session, Pulumi and Auth0 will walk through the process of building a three-tier web app: a single-page app built with React, a back end consisting of a REST API managed with Express and MongoDB. Finally, we&amp;rsquo;ll show you how to enable authentication to restrict access to your app.&lt;/p&gt;
&lt;h3 id="aws-immersion-day-hands-on-infrastructure-as-code"&gt;AWS Immersion Day: Hands-On Infrastructure as Code&lt;/h3&gt;
&lt;p&gt;Tuesday, June 14th at 9:00 AM PDT&lt;/p&gt;
&lt;p&gt;Pulumi and friends from VirtusLab and AWS have planned an interactive session to introduce IaC concepts using familiar programming languages to provision modern cloud infrastructure. This session will focus on new Pulumi capabilities.&lt;/p&gt;
&lt;h3 id="gitops-with-github-actions-and-the-pulumi-operator"&gt;GitOps with GitHub Actions and the Pulumi Operator&lt;/h3&gt;
&lt;p&gt;Tuesday, June 21st at 9:00 AM PDT&lt;/p&gt;
&lt;p&gt;Combining GitHub Actions with the Pulumi Kubernetes Operator helps you to implement powerful GitOps workflows and automation for both your infrastructure and workloads. We’ve partnered with the GitHub team to deliver step-by-step labs to help you to get started with GitOps.&lt;/p&gt;
&lt;h3 id="cicd-pipelines-for-kubernetes-apps-with-pulumi--codefresh"&gt;CI/CD Pipelines for Kubernetes Apps with Pulumi &amp;amp; Codefresh&lt;/h3&gt;
&lt;p&gt;Wednesday, June 22nd at 9:30 AM PDT&lt;/p&gt;
&lt;p&gt;The Codefresh team will help you to learn the basics of CI/CD and how to declare cloud resources and set up a simple pipeline for Kubernetes deployments using your favorite programming languages with Pulumi and Codefresh.&lt;/p&gt;
&lt;h3 id="deploying-microservices-with-aws-lambda-and-pulumi"&gt;Deploying Microservices with AWS Lambda and Pulumi&lt;/h3&gt;
&lt;p&gt;Tuesday, June 28, 12:00 PM PDT&lt;/p&gt;
&lt;p&gt;In this workshop, we’ll examine how Pulumi can rapidly accelerate provisioning of cloud infrastructure. We’ll focus on AWS Lambda and build an example set of microservices utilizing AWS’s newest Lambda features. Matty Stratton (Pulumi) and Marina Novikova (AWS) will guide you through the process of provisioning a set of example Lambda resources in AWS.&lt;/p&gt;
&lt;h3 id="getting-started-with-infrastructure-as-code-on-oracle-cloud"&gt;Getting Started with Infrastructure as Code on Oracle Cloud&lt;/h3&gt;
&lt;p&gt;Thursday, July 14th at 9:00 AM PDT
&lt;a href="https://go.oracle.com/LP=127531?elqCampaignId=350230" target="_blank" rel="noopener noreferrer"&gt;Register&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Now that we have a brand new integration with &lt;a href="https://www.pulumi.com/registry/packages/oci"&gt;Oracle Cloud Infrastructure (OCI)&lt;/a&gt; the team is preparing a new workshop to help you to get the most out of the new provider. Laura Santamaria (Pulumi) and Gaurav Jain (Oracle) will show you how to define, deploy and manage OCI resources using your favorite programming languages.&lt;/p&gt;
&lt;h3 id="getting-started-with-infrastructure-as-code-on-digitalocean"&gt;Getting started with Infrastructure as Code on DigitalOcean&lt;/h3&gt;
&lt;p&gt;Thursday, July 28th at 8:00 AM PDT
&lt;a href="https://www.pulumi.com/resources/getting-started-with-infrastructure-as-code-on-digital-ocean"&gt;Register&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;In this hands-on workshop, Matty Stratton (Pulumi) and Chris Sevilleaja (DigitalOcean) will show you how to stand up basic services using Infrastructure as Code with hands-on labs using JavaScript/TypeScript.&lt;/p&gt;</description><author>Matty Stratton</author><author>Isaac Harris</author><category>pulumi-up</category><category>workshop</category></item><item><title>Organizational Patterns: A Developer Portal</title><link>https://www.pulumi.com/blog/organizational-patterns-developer-portal/</link><pubDate>Thu, 30 Dec 2021 11:00:39 -0600</pubDate><guid>https://www.pulumi.com/blog/organizational-patterns-developer-portal/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/organizational-patterns-developer-portal/index.png" /&gt;
&lt;p&gt;Using Pulumi is more than just writing code and components. In addition to common software development practices, there are also a number of success patterns related to how your company or team builds and deploys Pulumi programs to successfully build, deploy, and manage your infrastructure and applications. In this continuation of a series, I will explore one of these patterns - using the Pulumi &lt;a href="https://www.pulumi.com/docs/using-pulumi/automation-api/"&gt;Automation API&lt;/a&gt; to create a developer portal.&lt;/p&gt;
&lt;p&gt;It is becoming more and more common to consider building out centralized web-based &amp;ldquo;portals&amp;rdquo; for developers (and other team members) to provision the infrastructure that their services and applications require. In many ways, the pattern of a developer portal takes portions of both the &lt;a href="https://www.pulumi.com/blog/organizational-patterns-infra-repo/"&gt;Single Infra Repo&lt;/a&gt; and &lt;a href="https://www.pulumi.com/blog/organizational-patterns-automation-team/"&gt;Automation Team&lt;/a&gt; patterns covered in previous posts. The difference is that the developer portal is a single, centralized web application that can be used by multiple teams and organizations to provision infrastructure and applications, rather than writing the Pulumi programs themselves.&lt;/p&gt;
&lt;p&gt;Depending upon the needs of the various teams, the developer portal could include options to deploy virtual machines into the cloud of their choice (or the organization&amp;rsquo;s standard cloud; perhaps the choice isn&amp;rsquo;t&amp;hellip;a choice!), to provision cloud resources such as virtual networks, security groups, database instances, or even deployments to a kubernetes cluster.&lt;/p&gt;
&lt;p&gt;Generally speaking, the developer portal is created and maintained by a central platform team. This is the team who knows the success patterns/standards that are employed by the organization, and can implement these patterns in the developer portal. The platform team is also responsible for maintaining the infrastructure that the developer portal requires.&lt;/p&gt;
&lt;p&gt;One of the great advantages of providing a single portal for provisioning these resources is that all the &amp;ldquo;other stuff&amp;rdquo; that is often required (besides the resources from the hyperscaler) can be handled by the developer portal. For example, if the portal is used to provision a virtual machine, the code behind it can register the virtual machine with the company&amp;rsquo;s infrastructure management system.&lt;/p&gt;
&lt;p&gt;A great example of what is possible in a portal can be seen with &lt;a href="https://github.com/komalali/"&gt;Komal Ali&amp;rsquo;s&lt;/a&gt; example, the &lt;a href="https://github.com/komalali/self-service-platyform"&gt;Self Service Infrastructure Platyform&lt;/a&gt;. This is example code only, but it shows some of the capabilities of a developer portal.&lt;/p&gt;
&lt;p&gt;&lt;img src="platyform.png" alt="Screeshot of the platyform"&gt;&lt;/p&gt;
&lt;p&gt;In the example, the web portal is created using a combination of Python, Flask and Jinja templates (along with the Pulumi Automation API) to provide push-button access to deploy cloud resources according to the standards and patterns of the organization. The code snippets below illustrate some of the concepts (this code is not meant to be run, but rather to illustrate the concepts - the full example code can be found at &lt;a href="https://github.com/komalali/self-service-platyform"&gt;github.com/komalali/self-service-platyform&lt;/a&gt;).&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;flask&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;Blueprint&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;current_app&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;request&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;flash&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;redirect&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;url_for&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;render_template&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;pulumi&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;pulumi_aws&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="nn"&gt;aws&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;pulumi.automation&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="nn"&gt;auto&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;os&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;pathlib&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;Path&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;bp&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;Blueprint&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;virtual_machines&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="vm"&gt;__name__&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;url_prefix&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;/vms&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;instance_types&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;c5.xlarge&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;p2.xlarge&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;p3.2xlarge&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;In the initial snippet above, we are setting up what we need for the Flask application, but the key items to make note of are including the &lt;code&gt;pulumi_aws&lt;/code&gt; and &lt;code&gt;pulumi.automation&lt;/code&gt; packages, which will be used for the cloud specific resources and automation.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;create_pulumi_program&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;keydata&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;str&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;instance_type&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nb"&gt;str&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;ami&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;aws&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ec2&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get_ami&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;most_recent&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="kc"&gt;True&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;owners&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;amazon&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;filters&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;aws&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;GetAmiFilterArgs&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;name&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;values&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;*amzn2-ami-minimal-hvm*&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;])])&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;group&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;aws&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ec2&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;SecurityGroup&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;web-secgrp&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;description&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;Enable SSH access&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;ingress&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;aws&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ec2&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;SecurityGroupIngressArgs&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;protocol&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;tcp&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;from_port&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;22&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;to_port&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;22&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;cidr_blocks&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;0.0.0.0/0&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;)])&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Continuing on, we define the Pulumi program, and set up some of the standard settings that we consider our defaults and that are not selectable by the user.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;server&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;aws&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ec2&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Instance&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;dlami-server&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;instance_type&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;instance_type&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;vpc_security_group_ids&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;group&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;key_name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;keypair&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;ami&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;ami&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;pulumi&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;export&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;public_dns&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;server&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;public_dns&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This final snippet is what creates the actual instance, and it exports the public DNS of the instance so that it can be accessed by the user and presented in the portal.&lt;/p&gt;
&lt;h2 id="conclusion"&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;This pattern has been implemented and deployed at many larger enterprises, where the platform team has the resources to dedicate to managing the portal as an actual product. This is a key part to remember - the developer portal is a product whose consumers are the developers and other teams in the organization, and it needs to be managed as such!&lt;/p&gt;
&lt;p&gt;Don&amp;rsquo;t forget to check out the previous two posts in this series, &lt;a href="https://www.pulumi.com/blog/organizational-patterns-infra-repo/"&gt;Organizational Patterns - A Single Infra Repo&lt;/a&gt; and &lt;a href="https://www.pulumi.com/blog/organizational-patterns-automation-team/"&gt;Organizational Patterns - An Automation Team&amp;quot;&lt;/a&gt;.&lt;/p&gt;</description><author>Matty Stratton</author><category>development-environment</category><category>automation-api</category></item><item><title>Organizational Patterns: An Automation Team</title><link>https://www.pulumi.com/blog/organizational-patterns-automation-team/</link><pubDate>Wed, 22 Dec 2021 11:49:08 -0600</pubDate><guid>https://www.pulumi.com/blog/organizational-patterns-automation-team/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/organizational-patterns-automation-team/index.png" /&gt;
&lt;p&gt;Using Pulumi is more than just writing code and components. In addition to common software development practices, there are also a number of success patterns related to how your company or team builds and deploys Pulumi programs to successfully build, deploy, and manage your infrastructure and applications. In this continuation of a series, I will explore one of these patterns - a specialized automation team.&lt;/p&gt;
&lt;p&gt;I want to approach this pattern with a bit of caution - there are patterns and anti-patterns related to having a single central team focused on automation.&lt;/p&gt;
&lt;p&gt;The anti-pattern is to have an &amp;ldquo;automation team&amp;rdquo; within your organization who is tasked with creating all infrastructure as code for the entire organization. This is a common pattern, but it is generally rife with issues.&lt;/p&gt;
&lt;p&gt;Understanding how to build and deploy a service or application requires a certain amount of domain knowledge of that service. If you have a single set of people across your entire company who need to write Pulumi programs for each and every application or service, you are now expecting that small group to not only be experts in Pulumi, but also every bit of infrastructure and software applications (both third party and created internally) across your organization.&lt;/p&gt;
&lt;p&gt;A more successful pattern is to have the automation team act as enablers and providers for the other groups within the company. This is a team of subject matter experts in using Pulumi, and not only do they have the knowledge to build and deploy infrastructure, but they are familiar with various patterns and good practices for how to build and deploy infrastructure.&lt;/p&gt;
&lt;p&gt;There are different mechanisms for how this automation team can enable others. One way is to embed them temporarily within a product team to work alongside them to build their automation. Then, when the product team is done, the automation team member can go and help another squad.&lt;/p&gt;
&lt;p&gt;Depending upon the size and skills of the company and this group, they may also be responsible for creating training materials for the other groups. These are usually based upon existing Pulumi training materials, but customized for the specific needs and culture of the company.&lt;/p&gt;
&lt;h2 id="reusable-components"&gt;Reusable components&lt;/h2&gt;
&lt;p&gt;This central automation team also often provides reusable components that might be shared across multiple development teams. This helps the individual teams to not have to &amp;ldquo;reinvent the wheel&amp;rdquo; and to bring in these components for their own particular needs.&lt;/p&gt;
&lt;p&gt;As a simple example, a component could be created (and published as a library to be consumed by product teams) that defines a Kubernetes deployment.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-javascript" data-lang="javascript"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kr"&gt;import&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt; &lt;span class="nx"&gt;as&lt;/span&gt; &lt;span class="nx"&gt;deploy&lt;/span&gt; &lt;span class="nx"&gt;from&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;@mycorp/deploy&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kr"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;kuard&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nx"&gt;deploy&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;Deployment&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;kuard&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;image&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;gcr.io/kuard-project/kuard:latest&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;replicas&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;What&amp;rsquo;s happened here in our (incomplete!) example is that the published package only exposes the parts that the team needs to change; the rest is provided by the automation team.&lt;/p&gt;
&lt;p&gt;The application team don’t need to duplicate values (such as ports) because the abstractions cater for them. The application team also didn’t need to apply any metadata, health checks, and environment variables because it can be inferred through convention, increasing velocity across the organization. When values are provided by the application team, they override convention and they can still iterate and experiment, providing feedback to the automation team.&lt;/p&gt;
&lt;h2 id="final-tips"&gt;Final tips&lt;/h2&gt;
&lt;p&gt;One of the more important recommendations for this pattern is to avoid trying to create a &amp;ldquo;mandate&amp;rdquo; for all teams for adoption. The automation team provides capabilities, such as templated CI/CD pipelines, reusable components, and training materials, but it is still up to the individual teams to decide how to use them.&lt;/p&gt;
&lt;h2 id="conclusion"&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;This is a pattern that works well at a larger organization, where it would be beyond the scope of a single group to be able to wrap their understanding around hundreds of services. However, it is a pattern that can be applied to smaller organizations as well!&lt;/p&gt;
&lt;p&gt;Watch for the next post in this series, where we will dig into some other patterns! Or revisit the first post, &lt;a href="https://www.pulumi.com/blog/organizational-patterns-infra-repo/"&gt;Organizational Patterns - A Single Infra Repo&lt;/a&gt;.&lt;/p&gt;</description><author>Matty Stratton</author><category>development-environment</category></item><item><title>Organizational Patterns: A Single Infra Repo</title><link>https://www.pulumi.com/blog/organizational-patterns-infra-repo/</link><pubDate>Fri, 17 Dec 2021 05:46:04 -0600</pubDate><guid>https://www.pulumi.com/blog/organizational-patterns-infra-repo/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/organizational-patterns-infra-repo/index.png" /&gt;
&lt;p&gt;Using Pulumi is more than just writing code and components. In addition to common software development practices, there are also a number of success patterns related to how your company or team builds and deploys Pulumi programs to successfully build, deploy, and manage your infrastructure and applications. In this first post of a series, I will explore one of these patterns - the centralized platform infrastructure repository.&lt;/p&gt;
&lt;p&gt;An emergent organizational pattern these days is that of a centralized &amp;ldquo;platform&amp;rdquo; team, which has various product and service teams (or squads) as internal customers. In this approach, the platform team takes responsibility for the tooling and infrastructure - if it&amp;rsquo;s not directly product related, it usually falls under the responsibility of the platform team. The platform team provides functionality and platforms to be consumed by the product teams.&lt;/p&gt;
&lt;p&gt;For many of the examples I&amp;rsquo;ll be using to illustrate this pattern, I refer to a conversation I had recently with Jacob Foard, who is the Tech Lead for the Platform Team at &lt;a href="https://greenparksports.com/"&gt;GreenPark Sports&lt;/a&gt;. This pattern is used at GreenPark Sports, and he was very clear about the benefits of the pattern.&lt;/p&gt;
&lt;p&gt;One of the key concepts to keep in mind is that when providing a platform, it is made up of more than just the compute and other resources provided by AWS, GCP, Azure, or even your own Kubernetes implementations. The platform also includes the infrastructure that is shared between the various teams, such as monitoring and observability tooling, version control/pipeline services, as well as secret and key management.&lt;/p&gt;
&lt;p&gt;In this pattern, your main infrastructure repository is made up of directories for each product/service that your teams use, in addition to directories for each higher level shared service. Each of these directories is itself a Pulumi program. So it would look something like this:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;├── bluth-apps
│   ├── apps
│   │   ├── apps.go
│   │   ├── bananastand.go
│   │   ├── suddenvalley.go
│   ├── main.go
│   ├── Pulumi.dev.yaml
│   └── Pulumi.prod.yaml
├── datadog
│   ├── main.go
│   └── Pulumi.prod.yaml
├── github
│   ├── main.go
│   └── Pulumi.prod.yaml
├── pkg
│   ├── datadog
│   ├── pagerduty
│   └── vault
└── .etc
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;In the above (fictional, but inspired by the GreenPark Sports pattern) example, the Bluth Company has two main services that are used in all of its environments (&amp;ldquo;Banana Stand&amp;rdquo; and &amp;ldquo;Sudden Valley&amp;rdquo;). The main &lt;code&gt;apps.go&lt;/code&gt; file is the entry point that simply calls functions from each of the various apps to &amp;ldquo;set up&amp;rdquo; those apps, as well as the common infrastructure that an environment might require (networks, storage, etc). Note that the way you structure your code is up to you, and likely will vary depending upon the runtime for your particular Pulumi program, but this is the general idea.&lt;/p&gt;
&lt;p&gt;Similarly, the &lt;code&gt;github&lt;/code&gt; and &lt;code&gt;datadog&lt;/code&gt; directories are Pulumi programs that are responsible for the &amp;ldquo;core&amp;rdquo; infrastructure for those services (perhaps creating roles, etc). The &lt;code&gt;pkg&lt;/code&gt; directory is a directory that contains packages that are used by the other programs to implement that infrastructure. Again, the &lt;code&gt;pkg&lt;/code&gt; convention is used by Go, but other runtimes will have a similar approach.&lt;/p&gt;
&lt;h2 id="examples"&gt;Examples&lt;/h2&gt;
&lt;p&gt;These examples are not complete runnable code, but used to illustrate the pattern. While these examples are using Go, they are written in a way that is compatible with any language that supports the Pulumi language.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;main.go&lt;/code&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-go" data-lang="go"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;package&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;main&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s"&gt;&amp;#34;github.com/bluthcompany/infra/bluth-apps/apps&amp;#34;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s"&gt;&amp;#34;github.com/bluthcompany/infra/pkg/datadog&amp;#34;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s"&gt;&amp;#34;github.com/bluthcompany/infra/pkg/github&amp;#34;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s"&gt;&amp;#34;github.com/pulumi/pulumi/sdk/go/pulumi&amp;#34;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kd"&gt;func&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;main&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;pulumi&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;Run&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kd"&gt;func&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="nx"&gt;pulumi&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;Context&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kt"&gt;error&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="c1"&gt;// Create the apps.&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;apps&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;SetupApps&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;bananastand&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;suddenvalley&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="c1"&gt;// Create the infrastructure.&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;datadog&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;CreateInfrastructure&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;github&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;CreateInfrastructure&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;return&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;nil&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;})&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;code&gt;apps.go&lt;/code&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-go" data-lang="go"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;package&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;apps&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s"&gt;&amp;#34;github.com/pulumi/pulumi/sdk/go/pulumi&amp;#34;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kd"&gt;func&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;SetupApps&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="nx"&gt;pulumi&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;Context&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;setupBananaStand&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;setupSuddenValley&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;code&gt;bananastand.go&lt;/code&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-go" data-lang="go"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;package&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;apps&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;// imports, etc&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kd"&gt;func&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;setupBananaStand&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;ctx&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="nx"&gt;pulumi&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;Context&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="c1"&gt;// Create the banana stand.&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="setting-up-a-new-service-in-the-platform-repository"&gt;Setting up a new service in the platform repository&lt;/h2&gt;
&lt;p&gt;If a service/product team has a new service they want infrastructure for, they simply add a new &lt;code&gt;myapp.go&lt;/code&gt; file to the &lt;code&gt;apps&lt;/code&gt; directory for their service, and add it to the &lt;code&gt;apps.go&lt;/code&gt; file to make sure it is called. This is then submitted as a pull request for the platform team to review.&lt;/p&gt;
&lt;p&gt;One important part of this pattern is that the platform team does not want to be a &amp;ldquo;blocker&amp;rdquo; for the product and service teams. It&amp;rsquo;s key to make sure that you have more than one person able to review and merge these pull requests, and to add sufficient testing into your CI/CD pipeline for this infrastructure repository.&lt;/p&gt;
&lt;h2 id="variations-on-this-pattern"&gt;Variations on this pattern&lt;/h2&gt;
&lt;p&gt;In the fictional Bluth example, there is one Pulumi program that is used regardless of environment, and the different configurations are handled by the use of stacks. However, there are situations where you might have complex enough differences between your environments where the amount of conditionals you require in your code to handle this would make for very challenging maintenance and understanding of the code! This is the case with GreenPark Sports, so in their implementation, instead of a single &lt;code&gt;bluth-apps&lt;/code&gt; directory at the root of the repo, you would instead have &lt;code&gt;bluth-prod&lt;/code&gt;, &lt;code&gt;bluth-dev&lt;/code&gt;, etc.&lt;/p&gt;
&lt;p&gt;This approach does generate duplication of code, and it can provide challenges at scale, but it is up to you and your teams to determine the tradeoffs of the branching/conditional logic vs separate programs.&lt;/p&gt;
&lt;h2 id="conclusion"&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;This pattern works well depending upon the makeup of your teams and services. It is a pattern that facilitates collaboration between teams and focuses on having a central platform team that enables product teams, rather than getting in their way.&lt;/p&gt;
&lt;p&gt;Watch for the next posts in this series, where we will dig into some other patterns as well!&lt;/p&gt;</description><author>Matty Stratton</author><category>development-environment</category></item><item><title>Preview of the Manage Track at Cloud Engineering Summit 2021</title><link>https://www.pulumi.com/blog/cloud-engineering-summit-manage-track/</link><pubDate>Mon, 13 Sep 2021 08:00:00 -0500</pubDate><guid>https://www.pulumi.com/blog/cloud-engineering-summit-manage-track/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/cloud-engineering-summit-manage-track/index.png" /&gt;
&lt;p&gt;The Cloud Engineering Summit 2021 is coming up fast, and the speakers are out! To get you ready to attend, let’s take a look at the sessions for the Manage track.&lt;/p&gt;
&lt;p&gt;The Cloud Engineering Summit’s three tracks are built around three concepts: Build, Manage, and Deploy. I’m Matt Stratton, and I’m your charismatic track chair for Manage. For us, that means managing cloud applications and infrastructure with Policy as Code, visibility, and access controls. For example, managing infrastructure with policies that detect configuration drift, enforce best practices, and even prevent compliance violations before deployment. It means building visibility across your cloud infrastructure so that you always understand its current and past states, including detailed audit history. Finally, you ensure the right guardrails and controls are set in place so that distributed teams can securely develop.&lt;/p&gt;
&lt;p&gt;Without further ado, let’s take a look at each of the talks I’ve selected for you!&lt;/p&gt;
&lt;p&gt;Overwhelmed by permissions and authorization? Me, too. Fortunately, we have Joy Ebertz presenting &lt;em&gt;Authorization: Ensuring Only Ada Can Access Her Files&lt;/em&gt;. Joy is going to cover the various authorization models available to us, with use-cases for each. Authorization can be overwhelming if you don&amp;rsquo;t have a good grasp of the options available to your organization and an understanding of what works when, so I’m excited for this one.&lt;/p&gt;
&lt;p&gt;Taking a higher-level view, Quintessence Anx will be presenting &lt;em&gt;DevSecOps and Secure Incident Response&lt;/em&gt;. The introduction of security to the DevOps equation means some shifts in the way we think about the software development lifecycle, and Quintessence is uniquely qualified to talk about why that’s true. A look inside PagerDuty’s 14 Step Secure Incident Response process promises to be interesting for anyone involved in either development or operations.&lt;/p&gt;
&lt;p&gt;I don&amp;rsquo;t think we have the ability to predict the future, but J. Paul Reed wonders if we can develop the ability to forecast incidents just as we have learned to have staggeringly accurate weather short-term forecasts. With &lt;em&gt;Forecasting the Future: Creating a Radar for Risk&lt;/em&gt;, Paul will share with us how Netflix uses Risk Radar to collect and make sense of risk in their sociotechnical systems.&lt;/p&gt;
&lt;p&gt;When we talk about infrastructure as code, there&amp;rsquo;s more to it than just the code! Fariba Khan and Stephen Van Gordon will take us on a journey with &lt;em&gt;Lifecycle of a Pulumi Program&lt;/em&gt; to share how they leverage a custom state backend with SSO, RBAC, and programmatically configurable pipelines powered by CI/CD tooling and the Pulumi Automation API to drive IaC at their organization.&lt;/p&gt;
&lt;p&gt;Snowflake’s Charles Xu will be here to talk about &lt;em&gt;Day-two Operation of Multi-cloud Kubernetes and Vault&lt;/em&gt;, a very cool overview of Snowflake’s Kubernetes infrastructure and how Pulumi helps, from blue-green updates, to managing Hashicorp Vault, to rotating TLS certificates. This is a pretty complex topic, so I’m very interested to see where it goes!&lt;/p&gt;
&lt;p&gt;Gremlin&amp;rsquo;s Jason Yee comes to us with &lt;em&gt;Trailblazers: exploration, discovery, &amp;amp; navigating failure&lt;/em&gt; - a set of topics that I personally find fascinating and essential! I think we are constantly in a state of discovery and understanding of our complex systems, and learning how to explore them - and work through the inevitable failures - helps us build and operate even more reliable systems.&lt;/p&gt;
&lt;p&gt;Rounding things out is the always incredible Tim Banks, with &lt;em&gt;Toxic Velocity: Speed Kills&lt;/em&gt;. In this talk, Tim is going to cover the various stressors that put pressure on both organizations and individuals, how they affect us, and what it looks like when things start to spiral out of control. I’m excited for this one because while crashes do happen, we’d all like them to happen less often (or not at all!), and being able to identify some of these things before they become a real problem is better for our businesses and our people.&lt;/p&gt;
&lt;p&gt;Explore all of the rest of the great sessions, and don&amp;rsquo;t forget to register for the cloud engineering summit!&lt;/p&gt;</description><author>Matty Stratton</author><category>cloud-engineering</category><category>security</category><category>pulumi-events</category></item><item><title>What Exactly Is Cloud Engineering?</title><link>https://www.pulumi.com/blog/what-exactly-is-cloud-engineering/</link><pubDate>Fri, 23 Jul 2021 12:46:42 -0500</pubDate><guid>https://www.pulumi.com/blog/what-exactly-is-cloud-engineering/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/what-exactly-is-cloud-engineering/index.png" /&gt;
&lt;p&gt;When we think about the idea of &amp;ldquo;cloud engineering,&amp;rdquo; we often think about the concept of taking standard software engineering practices and tools, and making them available and consistent across development, infrastructure, and compliance teams.&lt;/p&gt;
&lt;p&gt;It sounds a lot like what DevOps was supposed to accomplish, right? Many great practices have come out of software engineering that we can apply to operations and infrastructure. Likewise, practices from operational disciplines are equally applicable to development teams.&lt;/p&gt;
&lt;p&gt;In cloud engineering, we look at how all of these practices are available to multiple functions and teams. It&amp;rsquo;s a compelling concept, and the more that we refactor our thinking around this, the more effective we can be at delivering value to our customers and users.&lt;/p&gt;
&lt;p&gt;Cloud engineering has three main components: Build, Deploy, and Manage. These are all different areas, but they have a lot in common. We will dig into each of these areas in detail in upcoming posts in this series, but here are the key concepts around each.&lt;/p&gt;
&lt;h2 id="build"&gt;Build&lt;/h2&gt;
&lt;p&gt;This might sound like it’s just about writing code, but the &lt;em&gt;build&lt;/em&gt; area of cloud engineering is about creating services and infrastructure that provide what our customers need. In today’s world, we use cloud resources to build applications, services, and infrastructure. These resources can make up a shared service platform, giving a single, consistent experience across multiple teams.&lt;/p&gt;
&lt;p&gt;It&amp;rsquo;s also advantageous to create reusable infrastructure components so that application and service delivery focuses on differentiators rather than &amp;ldquo;reinventing the wheel.&amp;rdquo; Reusable components provide a consistent and standard implementation, using our organizations&amp;rsquo; and teams&amp;rsquo; existing practices.&lt;/p&gt;
&lt;p&gt;Besides expressing our own best practices and common configurations and approaches, when we build our infrastructure using standard programming languages, we can take advantage of the entire ecosystem surrounding them! We can leverage existing IDEs, test frameworks and approaches, and other wonderful tools available for those languages. Using modern architectures also focuses on the value our services and platforms provide, rather than bespoke and custom implementations.&lt;/p&gt;
&lt;h2 id="deploy"&gt;Deploy&lt;/h2&gt;
&lt;p&gt;It doesn&amp;rsquo;t count until it&amp;rsquo;s in production, right? Code and infrastructure don&amp;rsquo;t give any value until it&amp;rsquo;s in front of our customers and users. But doing this in a manner that is highly efficient and quality-consistent is key. Deployment processes that take too long or require too many manual steps can block us from getting new features to our customers or resolving service issues.&lt;/p&gt;
&lt;p&gt;When we apply software engineering practices to our deployment processes, this can ensure that we ship the same way, every time. It&amp;rsquo;s become common practice to apply the principles of continuous integration and delivery to our application software, but we can use the same principles with our infrastructure. This means that new and changed infrastructure resources can meet our quality controls and be tracked and understood when we are investigating the dreaded “what changed?” problem.&lt;/p&gt;
&lt;p&gt;The value of automating deployment isn&amp;rsquo;t just about providing the tests; it ensures all the steps we require are performed every time. Regardless of years of experience, every human is capable of missing a step or making an error. We want to have our skilled humans focus on the areas that benefit from human expertise and not waste their time on the things that don&amp;rsquo;t.&lt;/p&gt;
&lt;p&gt;“But what about checklists?” Checklists are great! But they are even better when a human defines them and are run by software. The power of a checklist is in defining steps, and in many ways, automation expresses our checklists in code. Code that can be tested, reviewed, and managed.&lt;/p&gt;
&lt;p&gt;But beyond simple automation, having a unified approach to deployment for both application code and infrastructure changes allows us to consider automation as the key part of the application. We think about infrastructure as a critical and essential component rather than something that happens “on the side.”&lt;/p&gt;
&lt;h2 id="manage"&gt;Manage&lt;/h2&gt;
&lt;p&gt;Getting our services into production is a key step, but it’s not the end. Our customers constantly use our services and applications, and we need to manage all of the resources in use. As it applies to our applications and services, visibility across all of our infrastructure allows everyone on our team, regardless of their role, to have a common understanding of what’s going on.&lt;/p&gt;
&lt;p&gt;You may be familiar with the adage &amp;ldquo;security is everyone&amp;rsquo;s job.&amp;rdquo; What that means in the world of cloud engineering is that we consider security and compliance (whether regulatory policies or organizational policies) to be closely integrated into our work. Treating our policy as code, just as we treat our infrastructure as code, is a powerful idea! When we express these policies as code rather than prose in a document, we can apply these policy checks both before and after we deploy our services and infrastructure. Doing so extends the common &amp;ldquo;vocabulary&amp;rdquo; for collaboration across all teams, regardless of where they sit in the org chart.&lt;/p&gt;
&lt;p&gt;Another key piece of the manage story is that we need controls in place to allow who can make changes and what they can change! We trust our team members to want to do the right thing, but we also need guardrails and controls to ensure that they can do so. This means that we need visibility into all changes that occur - treating our infrastructure just like we do our source code in git! Additionally, having the capability and intentionality around fine-grained access controls is critical to make all of our team members successful, provide reliability around our services, and provide confidence for our customers.&lt;/p&gt;
&lt;h2 id="summary"&gt;Summary&lt;/h2&gt;
&lt;p&gt;When we take the ideas of cloud engineering and apply them to our organizations, we can deliver value to our customers and users. We can do this by applying the practices and tools already available to our teams and applying the same principles to our infrastructure and application code. We get increased collaboration capability within our teams, a higher level of trust and confidence in our services and applications, and a better handle on the complexity of the modern cloud. We will explore some specific practices and tools around each of these areas in future posts and how they can be applied to your organization!&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Do you have a great story around your experiences with cloud engineering? We would love to hear it at the upcoming &lt;a href="https://www.pulumi.com/cloud-engineering/"&gt;Cloud Engineering Summit&lt;/a&gt;! &lt;a href="https://sessionize.com/cloud-engineering-summit-hosted-by-pulumi/"&gt;Submit your proposal to the CFP&lt;/a&gt; by July 31st!&lt;/em&gt;&lt;/p&gt;</description><author>Matty Stratton</author><category>cloud-engineering</category></item></channel></rss>