Go back

Why Developers Are Flocking to CloudBees Unify, and What It Means for DevOps with Shawn Ahmed

40m 12s

Why Developers Are Flocking to CloudBees Unify, and What It Means for DevOps with Shawn Ahmed

In a podcast interview, Sean Armid, CPO of CloudBees, discusses the company's new product, Unify. CloudBees, the founder of Jenkins, launched Unify as a transformative DevSecOps control surface. Unlike traditional platforms, Unify is an operating layer that integrates with existing tools like Jenkins and GitHub Actions, offering centralized governance, automated security, and real-time visibility without forcing disruptive tool replacements. This approach allows enterprises to modernize their pipelines at their own pace. Unify features an "always-on" security model that uses AI to scan, triage, and even automatically fix vulnerabilities across the stack. It also includes an intelligent testing module that predicts failures to speed up developer feedback. The product is designed to resolve the tension between developer speed and enterprise control, particularly in regulated industries, by providing comprehensive compliance monitoring and a clear view of application security posture, enabling safer and faster software delivery.

Transcription

6458 Words, 35319 Characters

English
Welcome back to Future Forward, I'm Nick Kebel, your host. This is our podcast on all things AI. Today I'm delighted to be joined by Sean Armid, Chief Product Officer at Cloudbees who are based out in California. Cloudbees already have over half a million developers using their products and they've just launched a new product called Unify, which is a bit of a game changer for the DevOps community. Unify offers centralized governance, automated security, real-time visibility across tools like Jenkins, GitHub, Actions and others, but here's the thing, without requiring any tool changes. So if you're navigating that balance between developer freedom and enterprise control, don't miss this one. Let's get stuck in. Okay, welcome Sean to our podcast. Thanks for joining us. You work as the CPO for Cloudbees based in the States. Thank you for coming on. Really appreciate your time, Sean. Are you able to give our listeners an overview as to who Cloudbees are? Yeah, of course. Well, first of all, thanks for having me on the on the cast. I appreciate that. That's always nice. Get to speak to you and speak to your audience. Cloudbees is probably most well known, I would say, in the market as the founders of Jenkins. The world renowned, you know, build automation engine in the world, free and open source project created by Kosoka. We are the enterprise version of that. Now, in life of the years, we've kind of gone from not just Jenkins, but also to create and release and bring to market a brand new DevSecOps control surface that's called Unify. And so not only can we meet customers and clients where they are related to the types of buildings they're using and the type of different applications that they have, we can meet their security requirements, but the key sort of headline here I always think about is is that we're the first in the market to kind of to market with a product like this where ripping and replacing things is not the first go to necessary mode of operation, but in fact, it's all about it in the name of the product. It's called Unify. It's about bringing those tools together. So as a company, we're really excited about sort of this transformation for us, where it brings our customers and prospects and clients moving into the future. We're here. We're here to stay and we really love this new Unify product and happy to be able to talk about it on a podcast next. That's just a little bit about the cloud business. Excellent. Thanks for that. Cool. Yeah. So, and so that segues nicely into I guess the sort of the first headline in terms of the product launch around cloud-based Unify. That was launched in May this year, I believe, and obviously a defining moment for you guys. And it's it's I guess sort of looking to change the landscape for the DevOps community at large. And one of the things that I hear a lot is that you guys have framing this as not as a platform, but as an operating layer for sort of the modern enterprise environment, which is obviously a powerful shift in language. And how would you sort of describe the difference and why does that matter, would you say? Yeah. That's a good question. You know, in so many times when we go meet with customers and clients that look at their pipelines and other building software, you know, everybody wants to modernize their pipelines, you know, from maybe sequential processing to meshes go from, you know, primarily image-based build systems to cloud-data build systems. And it's all about the workload. It's all about going faster, better and safer. But the harrowing truth that meets you at the doorstep of that decision. Is oh boy, it means we have to take everything we have. And then rip it, replace it, rewrite it. And that looks like a heavy-duty migration that's going to take multiple years. And which system do we choose? What languages do we choose? How do we do this? And how many phases? And then you just kind of look at the operational expenditure. It's going to take to get there. And it's like a life-altering decisions that you have to make. And that's what essentially Unified does is take that choice away. It says, look, it's a transformative shift. Let's just eliminate that sort of disruptive, rip-and-replace decision you have to make to approach modernization. So what we say is we say unifies at the heart of it embraces and allows developers and operators to sort of continue to use the tools that they prefer to use every single day. And then just integrate across the stack. So our thought process is that Unify is an operating layer. In Control Plane, it's sort of a customer-centric approach as opposed to a vendor approach. It's an operating layer for the modern enterprise. It centralizes the control whether you're using Jenkins, whether you're using GitHub, whether you're using any major CI/CD build tools, any security tools. It just brings it all under one Control Plane and gives visibility across any stack that you have. And I think that's the power of how you want to approach that. Giving yourself the time, the opportunity to sort of migrate things at your own pace, but still be able to support the tools, make nobody angry, but still be able to get the benefit of modernization. So that's kind of our approach and how we think about that problem statement. And we think that we're pretty unique in the way that we are actually approaching that and the playbook that we can give to our customers and clients. That's sort of how I think about it and we're excited about this. Excellent. Okay, you've answered my next question mainly as well because it's not a sort of a rip out job where it's harnessing, I guess, the current stack that the community uses like Jenkins GitHub and so on. And that's what a legacy infrastructure layers. And it's instead of replacing it and having a big sort of upload, then it's you're saying that it's a sort of a migration into a post to the rip out. Yeah, exactly. Imagine a world and where you're an operator and you have multiple build tools, you have multiple source systems, you have multiple places you want to deploy. You've got multiple different types of applications, some that are already cloud native, some that are old legacy and so on. And you're trying to get a hold of all of that real estate and bring it all together. And that's exactly right. It's not a great approach to rip and replace. It's just not the enterprise reality. And that's where you sort of have the ability and unify to bring and and connect these build system and have the system sort of be a control plane all over all of them giving you visibility. Now, simple things, think about it and make like imagine you have a problem with a pipeline, which which build tool do you go to or an application failed, which deployed it, you know, which an environment is it in. And so you're constantly going across and incredibly complex tool change that sort of triage, crash and a system that deeply integrates with them, essentially centralizing it all in one place. It makes it easier for you to use AI. It's helpful to have all the data in one place in a unified foundation. It changes the game in so many ways in terms of how you operate on a day to day better. The bottom line is always what I say Nick, right? For every developer, what do you want? You want more bites at the apple? Give me one more commit, right? Give me just one more full request. Give me a chance to get the feedback loop down. And if you're spending 80% of your time outside of coding as a developer, triaging problems in pipelines and in tests and in security related stuff, you're just not very happy developer. You'd like to be where you love to be and that is coding. And that's what we're enabling people to do is to give that time back. So that's how I think about that, Nick. Okay. Okay. Nice. And with the ever growing subject of AI, you know, it changes every week, doesn't it? It's so quickly, so quick out there. And with the AI generated coding and sort of the I/O Power developer tools that we've had waves and waves of these coming through and there's talk about the future of the developer and all that kind of stuff. And also the the surface of the new attacks and they're going to intensify because it's chicken and egg right? How does Unify, I guess, help development teams dev off environments to cure their pipelines and code in this sort of new I/O driven landscape? Yeah, absolutely. I think he is going to be that teams have the ability to sort of treat security and vulnerabilities. Even more shift left than they did before. I happen to be speaking with a customer of ours the other day, it was showing a little bit how Unify treats security and they said, wow, this is the furthest left we have ever seen security shift. And to us, it was actually a funny statement because we kind of think it's not even shifting left. It is a always on system. Security shouldn't be sequential. It shouldn't be living inside of everybody's pipelines all the time. Security should just be on all the time. So what Unify does, which is kind of unique is It shifts it out of the pipeline and says, build your controls, build your scanning, build your control mechanisms in one place. Store them in one place and enable them across teams and pipelines universally. In this way, whether a change occurs on every commit or whether it's a commit inside the Unify or whether it's deployed to a binary that you then ultimately going to release, the moment these assets are changing that it bidirectionally has the ability to scan them, secure them, take all the vulnerabilities from your various different scanners that you might be using or the open source scanners that we provide, but Unify and bring it into a triage framework where the AI can actually, the micro agent for AI can actually help triage the vulnerability for you across a multitude of systems. Be able to tell you what's wrong, where the problem occurred, give you a fixed possibility and if you use sort of our agentic MCP server, actually tell Unify just at a prompt natural language, hey, do you have an execution plan that you know off that can fix this problem and if you do, just go fix it for me on a different branch, test the code again and then tell me if it worked. So having a system that's sort of a companion to your work in that way is a unique way to approach how you deal with security and a day-to-day basis without necessarily having just a list of things to solving your backlog as a developer and you're like, oh my gosh, I'm gonna have to get to this at some point and it leaves the company, the software, its users vulnerable. And so I think we're kind of unique in that way about how we think about security in Unify. - Yeah, okay, next one, excellent, there's a big token point, definitely. And one of the other ones is, I guess, is sort of major tension out there is speed versus control isn't it, that's always talked about as well largely in the developer community. And Unify claims to deliver velocity with governance. How do you balance those in practice, Sean, especially across sort of that hybrid and very sort of regulated environment? 'Cause I know that there's this sort of big banking and finance sort of sector attached to the product. - Yeah, yeah. We have a lot of customers and clients that use security in a way that we call the mix and balance between speed and control. And it's always a topic of interest for every company. It's like, we can't, if there was a spectrum on one side it's speed and on the other side of that spectrum is full control, you have to calibrate for your company in the right way. There is no sort of like just ring those opposite spectrums to gather all at the same time or pick one or the other. But the calibration needs to be something that the company can. So we thought really part about life, what does that mean to calibrate? How should they be calibrating? 'Cause if you do all control, developers, you know, hard don't have freedom. If you do freedom and speed to just deliver code you've got no control. So that calibration in the middle, what we built this is into Unify, something known as application security modeling and compliance. And what that module, if the system operating on its own does, is essentially allowing the operators, the company to sort of create a harness around the compliance and security requirements and embed it into the organizational model. What that means is it's an always on system, it's always turned out. And so as AI generated code is coming at you, it's fast, but it's fast code. If it is fast code without the right guard rails, it's just a faster way to introduce vulnerabilities in the system. And that's what this Unify platform will do is have that always on harness around it, which you can use as a control surface to say, is this code ready? Is it not? Does it need help? Does it need fixing? Does it meet the standards that we've set? Does it not? And being able to gage your software process sequentially by checking with the system constantly, it provides a pathway, a golden path. For source code to hit production, but also with the guide rail of what minimum viable harness means. And that calibration of minimum viable harness around it means is a dial that you can dial up or down or to the right or to the left yourself. And that sort of control for operators makes it really nice because now they don't have to sort of force embed themselves into the developer's workflows and pipelines. They can set it and forget it. And that's kind of cool. So is this the AI driven sort of testing and optimization layer that you're going to build into it? That's actually separate. Great question, Nick. So testing AI layer and testing right now in every module of a part of our product, you can use AI-related agents to talk to it through via our MCP server. And we've enabled our system to be available to agents to do the work for you. And it's really interesting what we see from developers where, you know, sort of our interface, which we, the client, we've open source client, we've chosen as goose from block. And when you use goose, it's more and more becoming the primary interface for many developers to speak with our unified backend. It's really, really interesting how that's happening. But testing in particular is its own module that you can speak to. It has a visual interface in Unify as well. And that one's kind of smart because there's study after study that says that developers spend more than 50% of their time either waiting for a build or figuring out why a test went sour and so on. So in similar ways, like our security module operates, our testing module operates separate from sequential processing as well. Every time a commit is launched, you probably are going to make some, have some scans and tests and so on and so forth after the build step. And what it does is it constantly observes and says, what are the kind of changes that you made to your code? And ultimately, what kind of failures do you see in your test suites? And what it does over a period of time is learn that so well that he can start predicting. What kind of test failures you're going to have with the changes that you're making. And that module decides, hey, out of 50 tests you're going to run, if there's two tests that are going to fail, he will actually on the fly test those two first and get feedback to the developer immediately. That is the difference between waiting for 50 tests to run over a two hour period of time, let's say, down to just minute seconds and fail it, which gives the developer just one more bite to eat at the apple, right? Which is feedback is fast. I can now go fix the problem and I can go run it again. Every single time that happens, developers are happy. That's kind of what the test module does. And all that triage and all that work is done by the reasoning models inside of the product. You can pick, you can choose your reasoning models if you want to use something different, let our reasoning models from OpenAI or Clod or whatever you're using. Use those reasoning models and the agents will sort of do the triage for you, tell you what problem was failed. And here's another one that they really love with the testing module is like, hey, look, sometimes you're going to make maybe introduce one code change and you introduce that code change. All of a sudden you build things go great in the build, the test starts and now 20 tests failed. And you're like, I just made one code change and those 18 failures, you don't want to go through them one by one. Well, the system does that itself and sort of groups together things that says, you know what? In actuality, you don't have to go through all 18. It's this one code change over here. Or it's this line of code over here that is actually generating all of these 18. So it creates an issue tracker for you, out of your test so you can just focus on the things that's going to make all of that go away. So that's a smart test suite that's inside the system to help developers be more agile and give them more speed but still be safe. Excellent, good stuff. OK. And mentioned earlier, a lot of the customers, I think you guys partner with it is in that sort of banking and finance space. And that industry is very heavily governed, isn't it? There's a lot of governance and I guess security compliance teams have got their ears and eyes around these sort of products and how do we get them into the organization, how do they work, are they fit into their policies and all that kind of stuff. What does this unified guess offer in terms of real time inside, all the ability and unified governance across that complex pipeline of working within those types of environments? Yeah. So the combination of sort of the visibility modules that are inside of the control point and the compliance and security modules, what happens is you generate a ton of data. And once you set up your controls or you're using libraries that we provide with controls, typical controls you want in an enterprise environment, whether those libraries are like GDPR, library, NIST libraries, and so on it so forth, those controlled mechanisms, you're gonna combine with some of your own's and so on and you're gonna create that surface. What all of them do is generate data about your code. And as you know, an application is representative of multiple number of repositories, it's distributed applications come together, you're gonna release code from multiple repositories and ultimately that all rolls up to quote unquote an application that you and I are using, right? Our banking application on our phone. So if you and I are going to access our money, okay, on the phone through this application, you and I wanna know that that is fully tested, secure and not vulnerable. And so what the organization needs before it releases is all of those compliance and security vulnerabilities to be fixed and for them to have visibility into everything that's happening with that application. And that data is generated before the release, right? In the actual sephalph toward development lifecycle. So it takes all that data, aggregates it and creates what's known a posture for your application. How secure is this app? Okay, how many vulnerabilities are there? Which ones are within its SLA? Which ones are outside of its SLA? And being able to sort of have that visibility on the get go can help make tremendously smarter, better, stronger decisions about the readiness of your application before it goes out the door. And that is the power we wanna put in the hands of every company, no matter what build tool you're using, no matter what code where your code live, no matter what kind of application surface is, you want a full view. And that's what compliance gives to you when you use it together with our analytics module together. That visibility is everywhere in the control plane that users can put on top of their tool chain. So that's how we manage and give that to them. And then it's up to the organization to decide how deeply to embed it across their tool chains. - Excellent. And through the years we've spoken to many, many sort of development directors and dev-op leaders who time and time again are promised sort of transformation on many layers. How does Unify actually deliver, I guess, results today and not sort of months and quarters down the road when you're talking sort of enterprise environments. And I know that the product is, it avoids the sort of the rip and replace, which is great. But how would you say it sits to deliver the results faster for the community? - Yeah. Yeah. A lot of it has meant to do with the design principles that we applied when we first started building Unify. And our thought process was we wanted to build Unifying a way that brought you to the aha experience as quickly as possible. And not in terms of months, not in terms of weeks, not even in terms of days, but at the moment you connect your system, what are some of the things that we can generate a Ha system and how can AI play a part? How can a large language model play a part of that? How can the reasoning models play a part in making every experience with Unified to get go very, very rewarding? And so we focused on that and we found some very compelling places where I think organization get really excited about Unify. One of those surface areas is simply just connecting your code repo. The moment you take your code repository, connect to it, the system will interrogate the code. It will automatically create a security profile for that code. It will create and bring all the vulnerabilities into a Unified view. The triage framework turns on. It will even allow you to interrogate the repo and say, does there exists a well known pattern and design workflow for how to release, test, build this code? And it will supply that to you. So we've been very intentional about that design principle in itself. We don't want customers to think about the application or implementation in Unify as a retooling or a rebuilding. When we say we want this to unify everything together, we recognize that you already have a whole bunch of pipelines built and so on. So not only for Jenkins, GitHub and other built tools, do we just have the ability to call on them, but in fact, we import their metadata deeply into the system to control the control surface immediately. A moment you connect Jenkins, you start seeing the pipelines. You start seeing all of those things that exist there. The log runs are in one place connecting to GitHub. If there's action workflows there, they're imported in my Italy. And we have these nice little leak cons and icons and emojis and a whole bunch of other really cool things that we put together to identify that, yeah, you got a whole bunch of pipelines for this code, but this one's coming from that system. This one's coming from over there. That's an aha moment for a lot of operators. The first time they see these systems come together in this way to give them that strength and visibility that they need. So first answer Nick, to your question, saw you not do this in months, weeks, days even is intentional patterns and design of unified to have the aha moments immediately. And that's kind of how we designed unified to begin with. And we're going to continue to work on finding where those surface areas of aha moments can be. At the end of the day, our goal is to make unified as self-healing as possible, right? And be as autonomous or cinema autonomous as possible so that it doesn't get in the way. And that's intentional. A developer's dream. Yeah. We think so. We think so. And I guess, I mean, with now sort of unified was launched in May. But cloudbeats, obviously, you established in 2010, I believe. And you, if I being, I guess that's the foundation and now being launched, have you got a kind of any insights to build a product vision at all or any other maybe releases going down the next 12, 80 months? Wilson Harajan? Oh, yeah. I think I view the world and through this lens as I've seen it. And it became a lot more obvious to us, I think, just right around 2018, 2019, and onwards that as a whole for the industry and the ways that systems of designs are built for build automation and releases and so on, they would come a time where developers and operators would want this layer to be as invisible as possible. But still be available. Still be smart. Still exist. But just get out of the way. So if I think about what reasoning model do, what an agentic AI does, and particularly this thought process going forward with micro agents operating together with a master or orchestrator that's managing and orchestrating across micro agents as these reasoning models get smarter and smarter about it, I think that CloudBees, one day in the next maybe 12 months, would likely be the first system that entirely operates from a text box, so much at box. Imagine the day when your entire DevOps system is instantly available to you in natural language in your text box and you're speaking to your agent, and so speak. So it's not really a chat box, but it's natural language, and you're speaking to the agent. That's a powerful, I think, powerful point of-- I think for the industry, and I think for how these systems operate. Our first story into that is through our goose agentic AI system via MCP servers in our very intentional design and architecture of Unify to be that. So we feel real good about being on the way towards that, when we even see developers today using, as I said, earlier goose, the agent on their laptop as a primary agent to speak to Unify. So if that is true, I think we're not far away from when DevOps system, like CloudBees, is available to you as a companion right next to your coding environment, and you never see a UI for CloudBees. I think that is a very powerful statement I'm making, but that sort of tells you a little bit about what I see and where I think the industry is going generally, and certainly one of the pathways that we will allow our developers that you lose Unify to be able to do. And I think we're not very far away from that. And given the finance industry, the banking finance industry is one of the key sectors that you guys operate in, do you think that there's-- Do you think that leaders in that space, they need to rethink how their environments look if you're talking about that vision in 12, 18 months' time or not put a timeline on it? But, you know, there being no sort of UI in it's a chat box, how does that change for them in their world? I think you know what's really, really interesting, Nick, is many of these financial institutions are already on their way in that direction. I mean, with financial institutions today that you know, built their own internal portals, built their own reasoning models, or sorry, embedded their own reasoning models into their own agents that they've deployed internally. I think financial services institutions are very often on the cutting edge in terms of embracing some of this technology and thinking about it, how that app applies downstream. Granted, some of them are in the early design phases of thinking about it somewhere, a little bit further ahead that we speak to, but I would say that they're very aware of what this does for them. I think the financial services industry understands that technological warfare is the ability to release code fast, soft, and securely for their end users. They see that they have to compete and be able to do that very, very, very increasingly fast, means that you have to embrace and be a part of that sort of transformation that AI has provided all of us with. So I don't see them as waiting. I don't see them as thinking about it right now. I don't think they are going, should we, should we not? It's just they're on a spectrum of how early are they in that stage and how far have they gotten along, but the journey has already begun. So I feel particularly excited because in many ways, that validates a lot of what we're doing, it validates a lot about unifying, where unifying is going. So I think it's an exciting time to be alive with these opportunities. And I think yeah, financial services institutions, there are no slouches to technology. That's for sure. Indeed, indeed. And last question on that, not to label around the banking and finance space, but it's a highly regulated environment and unifies long-term guess into a world of sort of high stakes there. Why do you think that unifies such a strong fit for that sector particularly? Yeah, but particularly because of our security and our compliance modules, just being so heavily embedded inside of unify as a system. And the fact that we are not sequentially operating those layers, but in fact, they operate independently as two way systems and they stand alone on their own. And that modularization puts us in a very, very unique position because we were able to see everything from how people were building their pipelines for Jenkins for 10 years. And we've seen how those pipelines have been built, how they nested, that the logic that they built in. And we saw that writing on the wall a long time ago that this shift left movement into pipelines can't be the way that you would manage it into the future. You would have to modularize it and pull it out of the pipeline. Otherwise, the management of that layer becomes near impossible, slow, brittle, breaks off and is going to generate and create vulnerable surfaces everywhere. So being able to pull that out and create our own module, I think, is the secret sauce behind why I think we're particularly well suited for financial services because it's an ability for organization to set a security and compliance harness around their build jobs, their releases, their binaries, their code, in a way that allows them not to have to continuously manage it in a way that they have to go chase for it in pipelines. And that separates us from the pack in some ways and makes a very clear statement to the how we think about managing that. And I think financial services institutions are telling us that that is perhaps one of the most loved parts of the high experience that our users are having with Unify is essentially that part and experiencing that part from the get go S1. One one organizations SVP of engineering told us just was it about a few weeks ago when they implemented Unify that one of the poor reasons they built and Unify as the control plane was because they didn't want to force security down the throat of their developers. And this provided them with a control surface to put the control around the developers without having to burdening them and still allowing the developers to have to control to use whatever commercial scanners and so on and so forth they wanted. Being able to combine that together created a much more secure surface area without the ops teams feeling like they're burdening the developers and was one of the primary choices for why they felt like going with Unify as what the right choice. So we think that's kind of flexibility adaptability of Unify is a real reason for why we're particularly well suited for the financial services industry. Okay and for those folks who are I guess intrigued by Unify what it can do and how we've talked about it in the last sort of half an hour or so and those folks I guess sort of wrestling with legacy sort of complexity environments and they want to start evaluating and maybe thinking about adopting Unify. How do they go about it? Well easy. Go to cloudbase.io sign up and have at it. But the better way to do it is also to just book a demo with us and click that nice blue button on our website and book a demo and have sometimes sometimes even I'll be the person that jumps up and gets booked. So even I do them because I want to be in front of new customers and prospects. So if you want to see it you might just see me pop up one day. You know on your book to one to give you a demo and and we do it so that it's easy for you to sort of understand the key concept and then the other one is just keep going through a trial with us. You know you want to get you know one or two applications hooked into the system. Maybe you don't want to use multi tenant. Maybe you wanted to use it in a single tenant mode and so on. Super easy. Click that blue button. Get ahold of us and you know within 24 hours you will have somebody contact you that will set it up for you and get you up and running. So we're eager to hear from from from everybody and and that book. Take that book demo button as often as you can. Nice excellent and and finally you've talked nicely and in detail about the the product and and sort of the benefits and the fact that it's you know avoiding that that whole sort of rip and replace and the security elements and the reg elements around it and the industry and and with sort of the DevOps I guess in the environment being flooded with buzzwords one last time what what makes cloud bees which is a unified real and just not another platform promise yeah last words I appreciate that um you know I'll leave you with a few things look um you know it's unified is is as an operating layer it's it's it's built for the modern enterprise that has um you know a lot of assets um it it's centralized as control and it does it across Jenkins it does it across GitHub and any other major build system and see a source code system that you have and and and it's it's built for control and visibility across that stack. Now we always kept on hearing the same thing we want you know we sit for my customers we want to modernize but we don't want to do it if it means we have to rebuild absolutely everything from scratch um diverse stacks you know that that that customers have they aren't a problem to be fixed um they're their their every reality that you kind of have to support and so at the heart of it unify truly embraces that and and fill that gap ultimately um giving the right guide rails across that stack to everybody to deliver faster uh and do it safer uh and it's it's just built in it's not a bolted on and or replace and that's that's unified it's hard and so if if it feels like to you you want to modernize with that we're you know ripping and replacing then we're the solution fee excellent good stuff okay thank you very much you're for um your your take on the the recently launched unified product um anybody that's keen to to reach out they're going to press the the big blue demo button on the on the website we'll put the link out as well so really appreciate your time um and yeah when you launch the chat chat box version um promise to come back on again and talk about that. Now I absolutely will Nick I absolutely will remember along with Unified we've also announced our MCP server and Goose uh so it's available in in preview so go download that and if you want to try out the very first sort of hey I just want to access Unified through my terminal go try it out it's free try try and play try and play nice excellent good stuff Sean I'm at CPO CloudB thanks very much he's I'm really appreciate you coming on. Thanks for having me Nick.

Podcast Summary

Key Points:

  1. CloudBees, known for founding Jenkins, has launched Unify, a new DevSecOps control surface product.
  2. Unify acts as an operating layer that centralizes governance, security, and visibility across existing CI/CD tools (like Jenkins, GitHub Actions) without requiring rip-and-replace migrations.
  3. It shifts security to an "always-on" system, using AI to triage vulnerabilities and automate fixes, while also optimizing testing by predicting failures.
  4. The product helps balance developer velocity and enterprise control, especially in regulated sectors like finance, by providing real-time compliance and application security posture visibility.

Summary:

In a podcast interview, Sean Armid, CPO of CloudBees, discusses the company's new product, Unify. CloudBees, the founder of Jenkins, launched Unify as a transformative DevSecOps control surface. Unlike traditional platforms, Unify is an operating layer that integrates with existing tools like Jenkins and GitHub Actions, offering centralized governance, automated security, and real-time visibility without forcing disruptive tool replacements.

This approach allows enterprises to modernize their pipelines at their own pace. Unify features an "always-on" security model that uses AI to scan, triage, and even automatically fix vulnerabilities across the stack. It also includes an intelligent testing module that predicts failures to speed up developer feedback.

The product is designed to resolve the tension between developer speed and enterprise control, particularly in regulated industries, by providing comprehensive compliance monitoring and a clear view of application security posture, enabling safer and faster software delivery.

FAQs

CloudBees Unify is a DevSecOps control surface that provides centralized governance, automated security, and real-time visibility across tools like Jenkins and GitHub Actions without requiring tool changes.

Unify acts as an operating layer or control plane that integrates existing tools, avoiding disruptive rip-and-replace migrations and allowing organizations to modernize at their own pace.

Unify shifts security out of individual pipelines by centralizing controls and scanning in one place, enabling continuous, always-on security across all tools and assets.

Unify uses application security modeling and compliance modules to create adjustable guardrails, allowing operators to set security standards without embedding directly into developer workflows.

The testing module uses AI to predict and prioritize failing tests, reducing wait times and grouping related failures to help developers quickly identify and fix root causes.

Highly regulated industries like banking and finance benefit from Unify's real-time visibility and governance features, which aggregate compliance data to ensure applications meet security standards before release.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.