Endnotes For The DevOps Handbook: How to Create World-Class Agility, Reliability, & Security in Technology Organizations
Authors: Gene Kim, Patrick Debois, John Willis, Jez Humble
Amazon link: https://www.amazon.com/DevOps-Handbook-World-Class-Reliability-Organizations/dp/1942788002/
Anyone interested in the topics covered in The DevOps Handbook will likely find the citations interesting and potentially useful.
I’ve extracted all the endnotes from the book, which are in a very usable form: they show the page number (as per the paperback edition), as well as three words that the citation is anchored to, and then a citation that has been fact-checked.
Enjoy! Pull requests welcome!
Cheers, Gene
-
Page xxii: _Before the revolution…: _ Eliyahu M. Goldratt, Beyond the Goal: Eliyahu Goldratt Speaks on the Theory of Constraints (Your Coach in a Box) (Prince Frederick, Maryland: Gildan Media, 2005), Audiobook.
-
Page xxiv: _Put even more…: _ Jeff Immelt, “GE CEO Jeff Immelt: Let’s Finally End the Debate over Whether We Are in a Tech Bubble,” Business Insider, December 9, 2015, http://www.businessinsider.com/ceo-of-ge-lets-finally-end-the-debate-over-whether-we-are-in-a-tech-bubble-2015-12.
-
Or as Jeffrey…: “Weekly Top 10: Your DevOps Flavor,” Electric Cloud, April 1, 2016, http://electric-cloud.com/blog/2016/04/weekly-top-10-devops-flavor/.
-
Page xxv: Dr. Eliyahu M. Goldratt…: Goldratt, Beyond the Goal.
-
Page xvi: As Christopher Little…: Christopher Little, personal correspondence with Gene Kim, 2010.
-
Page xxvii: As Steven J. Spear…: Steven J. Spear, The High-Velocity Edge: How Market Leaders Leverage Operational Excellence to Beat the Competition (New York, NY: McGraw Hill Education), Kindle edition, chap. 3.
-
_In 2013, the…: _ Chris Skinner, “Banks have bigger development shops than Microsoft,” Chris Skinner’s Blog, accessed July 28, 2016, http://thefinanser.com/2011/09/banks-have-bigger-development-shops-than-microsoft.html/.
-
Page xxviii: _Projects are typically…: _ Nico Stehr and Reiner Grundmann, Knowledge: Critical Concepts, Volume 3 (London: Routledge, 2005), 139.
-
Dr. Vernon Richardson… A. Masli, V. Richardson, M. Widenmier, and R. Zmud, “Senior Executive’s IT Management Responsibilities: Serious IT Deficiencies and CEO-CFO Turnover,” MIS Quaterly (published electronically June 21, 2016).
-
Page xxix: _Consider the following…: _ “IDC Forecasts Worldwide IT Spending to Grow 6% in 2012, Despite Economic Uncertainty,” Business Wire, September 10, 2012, http://www.businesswire.com/news/home/20120910005280/en/IDC-Forecasts-Worldwide-Spending-Grow-6-2012.
-
Page xxxii: _The first surprise…: _ Nigel Kersten, IT Revolution, and PwC, 2015 State of DevOps Report (Portland, OR: Puppet Labs, 2015), https://puppet.com/resources/white-paper/2015-state-of-devops-report?_ga=1.6612658.168869.1464412647&link=blog.
-
Page xxxiii: This is highlighted…: Frederick P. Brooks, Jr., The Mythical ManMonth: Essays on Software Engineering, Anniversary Edition (Upper Saddle River, NJ: Addison-Wesley, 1995).
-
Page xxxiv: As Randy Shoup…: Gene Kim, Gary Gruver, Randy Shoup, and Andrew Phillips, “Exploring the Uncharted Territory of Microservices,” XebiaLabs.com, webinar, February 20, 2015, https://xebialabs.com/community/webinars/exploring-the-uncharted-territory-of-microservices/.
-
_The 2015 State…: _ Kersten, IT Revolution, and PwC, 2015 State of DevOps Report.
-
_Another more extreme…: _ “Velocity 2011: Jon Jenkins, ‘Velocity Culture’,” YouTube video, 15:13, posted by O’Reilly, June 20, 2011, https://www.youtube.com/watch?v=dxk8b9rSKOo; “Transforming Software Development,” YouTube video, 40:57, posted by Amazon Web Service, April 10, 2015, https://www.youtube.com/watch?v=YCrhemssYuI&feature=youtu.be.
-
Page xxxv: Later in his…: Eliyahu M. Goldratt, Beyond the Goal.
-
As with The…: JGFLL, review of The Phoenix Project: A Novel About IT, DevOps, and Helping Your Business Win, by Gene Kim, Kevin Behr, and George Spafford, Amazon.com review, March 4, 2013, http:// www.amazon.com/review/R1KSSPTEGLWJ23; Mark L Townsend, review of The Phoenix Project: A Novel About IT, DevOps, and Helping Your Business Win, by Gene Kim, Kevin Behr, and George Spafford, Amazon.com review, March 2, 2013, http://uedata.amazon.com/gp/customer-reviews/R1097DFODM12VD/ref=cm_cr_getr_d_rvw_ttl?ie=UTF8&ASIN=B00VATFAMI; Scott Van Den Elzen, review of The Phoenix Project: A Novel About IT, DevOps, and Helping Your Business Win, by Gene Kim, Kevin Behr, and George Spafford, Amazon.com review, March 13, 2013, http://uedata.amazon.com/gp/customer-reviews/R2K95XEH5OL3Q5/ref=cm_cr_getr_d_rvw_ttl?ie=UTF8&ASIN=B00VATFAMI.
-
Page 5: One key principle…: Kent Beck, et al., “Twelve Principles of Agile Software,” AgileManifesto.org, 2001, http://agilemanifesto.org/principles.html.
-
Page 6: He concluded that…: Mike Rother, Toyota Kata: Managing People for Improvement, Adaptiveness and Superior Results (New York: McGraw Hill, 2010), Kindle edition, Part III.
-
Page 7: Karen Martin and…: Karen Martin and Mike Osterling, Value Stream Mapping: How to Visualize Work and Align Leadership for Organizational Transformation (New York: McGraw Hill, 2013), Kindle edition, chap 1.
-
Page 9: In this book… Ibid., chap. 3.
-
Page 11: Karen Martin and…: Ibid.
-
Page 17: Studies have shown…: Joshua S. Rubinstein, David E. Meyer, and Jeffrey E. Evans, “Executive Control of Cognitive Processes in Task Switching,” Journal of Experimental Psychology: Human Perception and Performance 27, no. 4 (2001): 763-797, doi: 10.1037//00961523.27.4.763, http://www.umich.edu/~bcalab/documents/RubinsteinMeyerEvans2001.pdf.
-
Page 18: Dominica DeGrandis, one…: “DOES15—Dominica DeGrandis—The Shape of Uncertainty,” YouTube video, 22:54, posted by DevOps Enterprise Summit, November 5, 2015, https://www.youtube.com/watch?v=Gp05i0d34gg.
-
Taiichi Ohno compared… Sami Bahri, “Few Patients-In-Process and Less Safety Scheduling; Incoming Supplies are Secondary,” The Deming Institute Blog, August 22, 2013, https://blog.deming.org/2013/08/fewer-patients-in-process-and-less-safety-scheduling-incoming-supplies-are-secondary/.
-
In other words… Meeting between David J. Andersen and team at Motorola with Daniel S. Vacanti, February 24, 2004; story retold at USC CSSE Research Review with Barry Boehm in March 2004.
-
Page 19: The dramatic differences…: James P. Womack and Daniel T. Jones, Lean Thinking: Banish Waste and Create Wealth in Your Corporation (New York: Free Press, 2010), Kindle edition, chap. 1.
-
Page 20: There are many…: Eric Ries, “Work in small batches,” StartupLessonsLearned.com, February 20, 2009, http://www.startuplessonslearned.com/2009/02/work-in-small-batches.html.
-
Page 21: In Beyond the…: Goldratt, Beyond the Goal.
-
Page 22: As a solution…: Eliyahu M. Goldratt, The Goal: A Process of Ongoing Improvement (Great Barrington, MA: North River Press, 2014), Kindle edition, “Five Focusing Steps.”
-
Page 23: Shigeo Shingo, one…: Shigeo Shingo, A Study of the Toyota Production System: From an Industrial Engineering Viewpoint (London: Productivity Press, 1989); “The 7 Wastes (Seven forms of Muda),” BeyondLean.com, accessed July 28, 2016, http://www.beyondlean.com/7-wastes.html.
-
Page 24: In the book…: Mary Poppendieck and Tom Poppendieck, Implementing Lean Software: From Concept to Cash, (Upper Saddle River, NJ: Addison-Wesley, 2007), 74.
-
The following categories…: Adapted from Damon Edwards, “DevOps Kaizen: Find and Fix What Is Really Behind Your Problems,” Slideshare.net, posted by dev2ops, May 4, 2015, http://www.slideshare.net/dev2ops/dev-ops-kaizen-damon-edwards.
-
Page 28: Dr. Charles Perrow…: Charles Perrow, Normal Accidents: Living with High Risk Technologies (Princeton, NJ: Princeton University Press, 1999).
-
Dr. Sidney Dekker…: Dr. Sidney Dekker, The Field Guide to Understanding Human Error (Lund University, Sweden: Ashgate, 2006).
-
After he decoded…: Spear, The High-Velocity Edge, chap. 8.
-
Dr. Spear extended… Ibid.
-
Page 29: Dr. Peter Senge…: Peter M. Senge, The Fifth Discipline: The Art & Practice of the Learning Organization (New York: Doubleday, 2006), Kindle edition, chap. 5.
-
In one well-documented…: “NUMMI,” This American Life, March 26, 2010, http://www.thisamericanlife.org/radio-archives/episode/403/transcript.
-
Page 30: As Elisabeth Hendrickson… “DOES15 Elisabeth Hendrickson Its All About Feedback,” YouTube video, 34:47, posted by DevOps Enterprise Summit, November 5, 2015, https://www.youtube.com/watch?v=r2BFTXBundQ. “In doings so… Spear, The High-Velocity Edge, chap. 1.
-
Page 31: As Dr. Spear…: Ibid., chap. 4.
-
In the 1700s…: Dr. Thomas Sowell, Knowledge and Decisions (New York: Basic Books, 1980), 222.
-
Page 34: As Gary Gruver…: Gary Gruver, personal correspondence with Gene Kim, 2014.
-
Page 37: For instance, in…: Paul Adler, “Time-and-Motion Regained,” Harvard Business Review, January-February 1993, https://hbr.org/1993/01/time-and-motion-regained.
-
Page 38: The “name, blame…: Dekker, The Field Guide to Understanding Human Error, chap. 1.
-
Dr. Sidney Dekker…: “Just Culture: Balancing Safety and Accountability,” Lund University, Human Factors & System Safety website, November 6, 2015, http://www.humanfactors.lth.se/sidney-dekker/books/just-culture/.
-
Page 39: He observed that…: Ron Westrum, “The study of information flow: A personal journey,” Proceedings of Safety Science 67 (August 2014): 58-63, https://www.researchgate.net/publication/261186680_The_study_of_information_flow_A_personal_journey.
-
As Bethany Macri…: Bethany Macri, “Morgue: Helping Better Understand Events by Building a Post Mortem Tool Bethany Macri,” Vimeo video, 33:34, posted by [email protected], October 18, 2013, http://vimeo.com/77206751.
-
Dr. Spear observes…: Spear, The High-Velocity Edge, chap. 1.
-
In The Fifth…: Senge, The Fifth Discipline, chap. 1.
-
Mike Rother observed…: Mike Rother, Toyota Kata, 12.
-
This is why…: Mike Orzen, personal correspondence with Gene Kim, 2012.
-
Page 41: Consider the following…: “Paul O’Neill,” Forbes, October 11, 2001, http://www.forbes.com/2001/10/16/poneill.html.
-
In 1987, Alcoa…: Spear, The High-Velocity Edge, chap. 4.
-
As Dr. Spear…: Ibid.
-
Page 42: A remarkable example…: Ibid., chap. 5.
-
Page 44: This process of…: Nassim Nicholas Taleb, Antifragile: Things That Gain from Disorder (Incerto), (New York: Random House, 2012).
-
According to Womack…: Jim Womack, Gemba Walks (Cambridge, MA: Lean Enterprise Institute, 2011), Kindle edition, location 4113.
-
Page 45: Mike Rother formalized…: Rother, Toyota Kata, Part IV.
-
Mike Rother observes…: Ibid., Conclusion.
-
Page 51: Therefore, we must…: Michael Rembetsy and Patrick McDonnell, “Continuously Deploying Culture [at Etsy],” Slideshare.net, October 4, 2012, posted by Patrick McDonnel.bl, http://www.slideshare.net/mcdonnps/continuously-deploying-culture-scaling-culture-at-etsy-14588485.
-
In 2015, Nordstrom…: “Nordstrom, Inc.,” company profile on Vault. com, http://www.vault.com/company-profiles/retail/nordstrom-inc/company-overview.aspx.
-
The stage for…: Courtney Kissler, “DOES14 Courtney Kissler Nordstrom Transforming to a Culture of Continuous Improvement,” YouTube video, 29:59, posted by DevOps Enterprise Summit 2014, October 29, 2014, https://www.youtube.com/watch?v=0ZAcsrZBSlo.
-
These organizations were… Tom Gardner, “Barnes & Noble, Blockbuster, Borders: The Killer B’s Are Dying,” The Motley Fool, July 21, 2010, http://www.fool.com/investing/general/2010/07/21/barnes-noble-blockbuster-borders-the-killer-bs-are.aspx.
-
Page 52: As Kissler described…: Kissler, “DOES14 Courtney Kissler Nordstrom.”
-
As Kissler said…: Ibid; Alterations to quote made by Courtney Kissler via personal correspondence with Gene Kim, 2016.
-
Page 53: As Kissler stated…: Ibid; Alterations to quote made by Courtney Kissler via personal correspondence with Gene Kim, 2016.
-
In 2015, Kissler…: Ibid.
-
She continued, “This…: Ibid.
-
Page 54: Kissler concluded, “From…: Ibid.
-
An example of…: Ernest Mueller, “Business model driven cloud adoption: what NI Is doing in the cloud,” Slideshare.net, June 28, 2011, posted by Ernest Mueller, http://www.slideshare.net/mxyzplk/business-model-driven-cloud-adoption-what-ni-is-doing-in-the-cloud.
-
Page 55: Although many believe…: Unpublished calculation by Gene Kim after the 2014 DevOps Enterprise Summit. Indeed, one of… Kersten, IT Revolution, and PwC, 2015 State of DevOps Report.
-
Page 56: CSG (2013): In…: Prugh, “DOES14: Scott Prugh, CSG DevOps and Lean in Legacy Environments,” Slideshare.net, November 14, 2014, posted by DevOps Enterprise Summit, http://www.slideshare.net/DevOpsEnterpriseSummit/scott-prugh.
-
Etsy (2009): In… Rembetsy and McDonnell, “Continuously Deploying Culture [at Etsy].”
-
Page 56: The Gartner research…: Bernard Golden, “What Gartner’s Bimodal IT Model Means to Enterprise CIOs,” CIO Magazine, January 27, 2015, http://www.cio.com/article/2875803/cio-role/what-gartner-s-bimodal-it-model-means-to-enterprise-cios.html.
-
Systems of record…: Ibid.
-
Systems of engagement…: Ibid.
-
Page 57: The data from…: Kersten, IT Revolution, and PwC, 2015 State of DevOps Report.
-
Scott Prugh, VP…: Scott Prugh, personal correspondence with Gene Kim, 2014.
-
Geoffrey A. Moore…: Geoffrey A. Moore and Regis McKenna, Crossing the Chasm: Marketing and Selling High-Tech Products to Mainstream Customers (New York: HarperCollins, 2009), 11.
-
Page 58: Big bang, top-down…: Linda Tucci, “Four Pillars of PayPal’s ‘Big Bang’ Agile Transformation,” TechTarget, August 2014, http://searchcio.techtarget.com/feature/Four-pillars-of-PayPals-big-bang-Agile-transformation.
-
Page 59: The following list…: “Creating High Velocity Organizations,” description of course by Roberto Fernandez and Steve Spear, MIT Sloan Executive Education website, accessed May 30, 2016, http://executive.mit.edu/openenrollment/program/organizational-development-high-velocity-organizations.
-
But as Ron van Kemenade… Ron Van Kemande, “Nothing Beats Engineering Talent: The Agile Transformation at ING,” presentation at the DevOps Enterprise Summit, London, UK, June 30-July 1, 2016.
-
Page 60: Peter Drucker, a…: Leigh Buchanan, “The Wisdom of Peter Drucker from A to Z,” Inc., November 19, 2009, http://www.inc.com/articles/2009/11/drucker.html.
Chapter 6: Understanding the Work in Our Value Stream, Making it Visible, and Expanding it Across the Organization
-
Page 61: Over the years…: Kissler, “DOES14 Courtney Kissler Nordstrom.”
-
Kissler explained:…: Ross Clanton and Michael Ducy, interview of Courtney Kissler and Jason Josephy, “Continuous Improvement at Nordstrom,” The Goat Farm, podcast audio, June 25, 2015, http://goatcan.do/2015/06/25/the-goat-farm-episode-7-continuous-improvement-at-nordstrom/.
-
Page 62: She said proudly…: Ibid.
-
Page 63: Technology executives or…: Brian Maskell, “What Does This Guy Do? Role of Value Stream Manager,” Maskell, July 3, 2015, http://blog.maskell.com/?p=2106http://www.lean.org/common/display/?o=221.
-
Page 64: Damon Edwards observed…: Damon Edwards, “DevOps Kaizen: Find and Fix What Is Really Behind Your Problems,” Slideshare.net, posted by dev2ops, May 4, 2015, http://www.slideshare.net/dev2ops/dev-ops-kaizen-damon-edwards.
-
Page 66: In their book …: Vijay Govindarajan and Chris Trimble, The Other Side of Innovation: Solving the Execution Challenge (Boston, MA: Harvard Business Review, 2010) Kindle edition.
-
Page 67: Based on their…: Ibid., Part I.
-
Page 70: After the near-death…: Marty Cagan, Inspired: How to Create Products Customers Love (Saratoga, CA: SVPG Press, 2008), 12.
-
Cagan notes that…: Ibid.
-
Page 71: Six months after…: Ashlee Vance, “LinkedIn: A Story About Silicon Valley’s Possibly Unhealthy Need for Speed,” Bloomberg, April 30, 2013, http://www.bloomberg.com/bw/articles/2013-04-29/linkedin-a-story-about-silicon-valleys-possibly-unhealthy-need-for-speed.
-
LinkedIn was created…: “LinkedIn started back in 2003 — Scaling LinkedIn A Brief History,” Slideshare.net, posted by Josh Clemm, November 9, 2015, http://www.slideshare.net/joshclemm/how-linkedin-scaled-a-brief-history/3-LinkedIn_started_back_in_2003.
-
One year later…: Jonas Klit Nielsen, “8 Years with LinkedIn – Looking at the Growth [Infographic],” MindJumpers.com, May 10, 2011, http://www.mindjumpers.com/blog/2011/05/linkedin-growth-infographic/.
-
By November 2015…: “LinkedIn started back in 2003,” Slideshare.net.
-
The problem was…: “From a Monolith to Microservices + REST: The Evolution of LinkedIn’s Architecture,” Slideshare.net, posted by Karan Parikh, November 6, 2014, http://www.slideshare.net/parikhk/restli-and-deco.
-
Josh Clemm, a…: “LinkedIn started back in 2003,” Slideshare.net.
-
Page 72: In 2013, journalist…: Vance, “LinkedIn: A Story About,” Bloomberg.
-
Scott launched Operation…: “How I Structured Engineering Teams at LinkedIn and AdMob for Success,” First Round Review, 2015, http://firstround.com/review/how-i-structured-engineering-teams-at-linkedin-and-admob-for-success/.
-
Scott described one…: Ashlee Vance, “Inside Operation InVersion, the Code Freeze that Saved LinkedIn,” Bloomberg, April 11, 2013, http://www.bloomberg.com/news/articles/2013-04-10/inside-operation-inversion-the-code-freeze-that-saved-linkedin.
-
However, Vance described…: Vance, “LinkedIn: A Story About,” Bloomberg.
-
As Josh Clemm…: “LinkedIn started back in 2003,” Slideshare.net.
-
Kevin Scott stated…: “How I Structured Engineering Teams,” First Round Review.
-
Page 73: As Christopher Little…: Christopher Little, personal correspondence with Gene Kim, 2011.
-
Page 74: As Ryan Martens…: Ryan Martens, personal correspondence with Gene Kim, 2013.
-
Page 77: He observed, “After…: Dr. Melvin E. Conway, “How Do Committees Invent?” MelConway.com, http://www.melconway.com/research/committees.html, previously published in Datamation, April 1968. These observations led… Ibid.
-
Page 77: Eric S. Raymond, author…: Eric S. Raymond, “Conway’s Law,” catb. org, accessed May 31, 2016, http://catb.org/~esr/jargon/.
-
Page 78: Etsy’s DevOps journey…: Sarah Buhr, “Etsy Closes Up 86 Percent on First Day of Trading,” Tech Crunch, April 16, 2015, http://techcrunch.com/2015/04/16/etsy-stock-surges-86-percent-at-close-of-first-day-of-trading-to-30-per-share/.
-
As Ross Snyder…: “Scaling Etsy: What Went Wrong, What Went Right,” Slideshare.net, posted by Ross Snyder, October 5, 2011, http://www.slideshare.net/beamrider9/scaling-etsy-what-went-wrong-what-went-right.
-
As Snyder observed…: Ibid.
-
In other words…: Sean Gallagher, “When ‘Clever’ Goes Wrong: How Etsy Overcame Poor Architectural Choices,” Arstechnica, October 3, 2011, http://arstechnica.com/business/2011/10/when-clever-goes-wrong-how-etsy-overcame-poor-architectural-choices/.
-
Snyder explained that…: “Scaling Etsy” Slideshare.net.
-
Page 79: Etsy initially had…: Ibid.
-
In the spring…: Ibid.
-
As Snyder described…: Ross Snyder, “Surge 2011—Scaling Etsy: What Went Wrong, What Went Right,” YouTube video, posted by Surge Conference, December 23, 2011, https://www.youtube.com/watch?v=eenrfm50mXw.
-
Page 80: As Snyder said…: Ibid.
-
Sprouter was one… “Continuously Deploying Culture: Scaling Culture at Etsy Velocity Europe 2012,” Slideshare.net, posted by Patrick McDonnell, October 4, 2012, http://www.slideshare.net/mcdonnps/continuously-deploying-culture-scaling-culture-at-etsy-14588485.
-
They are defined…: “Creating High Velocity Organizations,” description of course by Roberto Fernandez and Steven Spear.
-
Page 82: Adrian Cockcroft remarked… Adrian Cockcroft, personal correspondence with Gene Kim, 2014.
-
Page 84: In the Lean…: Spear, The High-Velocity Edge, chap. 8.
-
As Mike Rother…: Rother, Toyota Kata, 250.
-
Reflecting on shared…: “DOES15 Jody Mulkey DevOps in the Enterprise: A Transformation Journey,” YouTube video, 28:22, posted by DevOps Enterprise Summit, November 5, 2015, https://www.youtube.com/watch?v=USYrDaPEFtM.
-
Page 85: He continued, “The…: Ibid.
-
Pedro Canahuati, their…: Pedro Canahuati, “Growing from the Few to the Many: Scaling the Operations Organization at Facebook,” InfoQ, December 16, 2013, http://www.infoq.com/presentations/scaling-operations-facebook.
-
When departments over-specialize…: Spear, The High-Velocity Edge, chap. 1.
-
Page 86: Scott Prugh writes…: Scott Prugh, “Continuous Delivery,” Scaled Agile Framework, updated February 14, 2013, http://www.scaledagileframework.com/continuous-delivery/.
-
“By cross-training…: Ibid.
-
“Traditional managers will…: Ibid.
-
Page 87: Furthermore, as Prugh…: Ibid.
-
When we value…: Dr. Carol Dweck, “Carol Dweck Revisits the ‘Growth Mindset,’” Education Week, September 22, 2015, http:// www.edweek.org/ew/articles/2015/09/23/carol-dweck-revisits-the-growth-mindset.html.
-
As Jason Cox…: Jason Cox, “Disney DevOps: To Infinity and Beyond,” presentation at DevOps Enterprise Summit 2014, San Francisco, CA, October 2014.
-
Page 88: As John Lauderbach… John Lauderbach, personal conversation with Gene Kim, 2001.
-
Page 89: These properties are…: Tony Mauro, “Adopting Microservices at Netflix: Lessons for Architectural Design,” NGINX, February 19, 2015, https://www.nginx.com/blog/microservices-at-netflix-architectural-best-practices/.;
-
Adam Wiggins, “The Twelve-Factor App,” 12Factor.net, January 30, 2012, http://12factor.net/.
-
Page 90: Randy Shoup, former…: “Exploring the Uncharted Territory of Microservices,” YouTube video, 56:50, posted by XebiaLabs, Inc., February 20, 2015, https://www.youtube.com/watch?v=MRa21icSIQk.
-
Page 91: Amazon CTO Werner…: Larry Dignan, “Little Things Add Up,” Baseline, October 19, 2005, http://www.baselinemag.com/c/a/Projects-Management/Profiles-Lessons-From-the-Leaders-in-the-iBaselinei500/3.
-
Target is the…: Heather Mickman and Ross Clanton, “DOES15
-
Heather Mickman & Ross Clanton (Re)building an Engineering Culture: DevOps at Target,” YouTube video, 33:39, posted by DevOps Enterprise Summit, November 5, 2015, https://www.youtube.com/watch?v=7s-VbB1fG5o.
-
As Mickman described…: Ibid.
-
Page 92: In an attempt… Ibid. Because our team… Ibid. In the following…: Ibid.
-
Page 93: These changes have…: Ibid.
-
The API Enablement…: Ibid.
-
Page 95: At Big Fish…: “Big Fish Celebrates 11th Consecutive Year of Record Growth,” BigFishGames.com, January 28, 2014, http://pressroom.bigfishgames.com/2014-01-28-Big-Fish-Celebrates-11th-Consecutive-Year-of-Record-Growth.
-
Page 96: He observed that…: Paul Farrall, personal correspondence with Gene Kim, January 2015.
-
Farrall defined two…: Ibid., 2014.
-
He concludes, “The…: Ibid.
-
Page 97: Ernest Mueller observed…: Ernest Mueller, personal correspondence with Gene Kim, 2014.
-
As Damon Edwards…: Edwards, “DevOps Kaizen.”
-
Page 98: Dianne Marsh, Director…: “Dianne Marsh ‘Introducing Change while Preserving Engineering Velocity,” YouTube video, 17:37, posted by Flowcon, November 11, 2014, https://www.youtube.com/watch?v=eW3ZxY67fnc.
-
Page 99: Jason Cox said…: Jason Cox, “Disney DevOps.”
-
Page 100: At Etsy, this…: “devopsdays Minneapolis 2015 Katherine Daniels DevOps: The Missing Pieces,” YouTube video, 33:26, posted by DevOps Minneapolis, July 13, 2015, https://www.youtube.com/watch?v=LNJkVw93yTU.
-
Page 102: As Ernest Mueller…: Ernest Mueller, personal correspondence with Gene Kim, 2015.
-
Scrum is an agile…: Hirotaka Takeuchi and Ikujiro Nonaka, “New Product Development Game,” Harvard Business Review (January 1986): 137-146.
-
Page 111: In her presentation…: Em Campbell-Pretty, “DOES14 Em CampbellPretty How a Business Exec Led Agile, Lead, CI/CD,” YouTube video, 29:47, posted by DevOps Enterprise Summit, April 20, 2014, https://www.youtube.com/watch?v=-4pIMMTbtwE.
-
Campbell-Pretty became…: Ibid.
-
Page 112: They created a…: Ibid.
-
Campbell-Pretty observed…: Ibid.
-
Camplbell-Pretty described…: Ibid.
-
Page 115: The first version…: “Version Control History,” PlasticSCM.com, accessed May 31, 2016, https://www.plasticscm.com/version-control-history.html.
-
A version control…: Jennifer Davis and Katherine Daniels, Effective DevOps: Building a Culture of Collaboration, Affinity, and Tooling at Scale (Sebastopol, CA: O’Reilly Media, 2016), 37.
-
Page 118: Bill Baker, a…: Simon Sharwood, “Are Your Servers PETS or CATTLE?,” The Register, March 18 2013, http://www.theregister.co.uk/2013/03/18/servers_pets_or_cattle_cern/.
-
Page 118: At Netflix, the…: Jason Chan, “OWASP AppSecUSA 2012: Real World Cloud Application Security,” YouTube video, 37:45, posted by Christiaan008, December 10, 2012, https://www.youtube.com/watch?v=daNA0jXDvYk.
-
Page 119: The latter pattern…: Chad Fowler, “Trash Your Servers and Burn Your Code: Immutable Infrastructure and Disposable Components,” ChadFowler.com, June 23, 2013, http://chadfowler.com/2013/06/23/immutable-deployments.html.
-
The entire application…: John Willis, “Docker and the Three Ways of DevOps Part 1: The First Way—Systems Thinking,” Docker, May 26, 2015, https://blog.docker.com/2015/05/docker-three-ways-devops/.
-
Page 123: Gary Gruver, former…: Gary Gruver, personal correspondence with Gene Kim, 2014.
-
They had problems…: “DOES15 Mike Bland Pain Is Over, If You Want It,” Slideshare.net, posted by Gene Kim, November 18, 2015, http://www.slideshare.net/ITRevolution/does15-mike-bland-pain-is-over-if-you-want-it-55236521.
-
Page 124: Bland describes how… Ibid. Bland described that… Ibid. As Bland describes… Ibid. As Bland notes…: Ibid.
-
Page 125: Over the next…: Ibid.
-
Eran Messeri, an…: Eran Messeri, “What Goes Wrong When Thousands of Engineers Share the Same Continuous Build?,” presentation at the GOTO Conference, Aarhus, Denmark, October 2, 2013.
-
Messeri explains, “There…: Ibid.
-
All their code…: Ibid.
-
Page 126: Some of the…: Ibid.
-
Page 132: Martin Fowler described…: Martin Fowler, “TestPyramid,” MartinFowler.com, May 1, 2012, http://martinfowler.com/bliki/TestPyramid.html.
-
Page 134: This technique was…: Martin Fowler, “Test Driven Development,” MartinFowler.com, March 5, 2005, http://martinfowler.com/bliki/TestDrivenDevelopment.html.
-
Page 135: Nachi Nagappan, E. Michael…: Nachiappan Nagappan, E. Michael Maximilien, Thirumalesh Bhat, and Laurie Williams, “Realizing quality improvement through test driven development: results and experiences of four industrial teams,” Empir Software Engineering, 13, (2008): 289-302, http://research.microsoft.com/en-us/groups/ese/nagappan_tdd.pdf.
-
In her 2013…: Elisabeth Hendrickson, “On the Care and Feeding of Feedback Cycles,” Slideshare.net, posted by Elisabeth Hendrickson, November 1, 2013, http://www.slideshare.net/ehendrickson/care-and-feeding-of-feedback-cycles.
-
However, merely automating…: “Decreasing false positives in automated testing,” Slideshare.net, posted by Sauce Labs, March 24, 2015, http://www.slideshare.net/saucelabs/decreasing-false-positives-in-automated-testing.; Martin Fowler, “Eradicating Non-determinism in Tests,” MartinFowler.com, April 14, 2011, http://martinfowler.com/articles/nonDeterminism.html.
-
Page 136: As Gary Gruver…: Gary Gruver, “DOES14 Gary Gruver Macy’s Transforming Traditional Enterprise Software Development Processes,” YouTube video, 27:24, posted by DevOps Enterprise Summit 2014, October 29, 2014, https://www.youtube.com/watch?v=-HSSGiYXA7U.
-
Page 139: Randy Shoup, former…: Randy Shoup, “The Virtuous Cycle of Velocity: What I Learned About Going Fast at eBay and Google by Randy Shoup,” YouTube video, 30:05, posted by Flowcon, December 26, 2013, https://www.youtube.com/watch?v=EwLBoRyXTOI.
-
This is sometimes…: David West, “Water scrum-fall is-reality_of_ agile_for_most,” Slideshare.net, posted by harsoft, April 22, 2013, http://www.slideshare.net/harsoft/water-scrumfall-isrealityofagileformost.
-
Gene Kim, “The Amazing DevOps Transformation of the HP LaserJet Firmware Team (Gary Gruver),” ITRevolution.com, 2013, http://itrevolution.com/the-amazing-devops-transformation-of-the-hp-laserjet-firmware-team-gary-gruver/.
-
Gary Gruver and Tommy Mouser, Leading the Transformation: Applying Agile and DevOps Principles at Scale (Portland, OR: IT Revolution Press), 60.
-
Gruver observed, “Without…: Kim, “The Amazing DevOps Transformation ” ITRevolution.com.
-
Page 147: Jeff Atwood, founder…: Jeff Atwood, “Software Branching and Parallel Universes,” CodingHorror.com, October 2, 2007, http://blog.codinghorror.com/software-branching-and-parallel-universes/.
-
148 This is how…: Ward Cunningham, “Ward Explains Debt Metaphor,” c2.com, 2011, http://c2.com/cgi/wiki?WardExplainsDebtMetaphor.
-
Page 149: Ernest Mueller, who…: Ernest Mueller, “2012: A Release Odyssey,” Slideshare.net, posted by Ernest Mueller, March 12, 2014, http://www.slideshare.net/mxyzplk/2012-a-release-odyssey.
-
At that time…: “Bazaarvoice, Inc. Announces Its Financial Results for the Fourth Fiscal Quarter and Fiscal Year Ended April 30, 2012,” BasaarVoice.com, June 6, 2012, http://investors.bazaarvoice.com/releasedetail.cfm?ReleaseID=680964.
-
Page 150: Mueller observed, “It…: Ernest Mueller, “DOES15 Ernest Mueller DevOps Transformations At National Instruments and…,” YouTube video, 34:14, posted by DevOps Enterprise Summit, November 5, 2015, https://www.youtube.com/watch?v=6Ry40h1UAyE.
-
“By running these…: Ibid.
-
Page 151: Mueller further described…: Ibid.
-
However, the data…: Kersten, IT Revolution, and PwC, 2015 State of DevOps Report.
-
Page 153: In 2012, Rossi…: Chuck Rossi, “Release engineering and push karma: Chuck Rossi,” post on Chuck Rossi’s Facebook page, April 5, 2012, https://www.facebook.com/notes/facebook-engineering/release-engineering-and-push -karma-chuck-rossi/10150660826788920.
-
Just prior to…: Ryan Paul, “Exclusive: a behind-the-scenes look at Facebook release engineering,” Ars Technica, April 5, 2012, http://arstechnica.com/business/2012/04/exclusive-a-behind-the-scenes-look-at-facebook-release-engineering/1/.
-
Rossi continued, “If…: Chuck Rossi, “Release engineering and push karma.”
-
The Facebook frontend… Paul, “Exclusive: a behind-the-scenes look at Facebook release engineering,” Ars Technica.
-
He explained that…: Chuck Rossi, “Ship early and ship twice as often,” post on Chuck Rossi’s Facebook page, August 3, 2012, https://www.facebook.com/notes/facebook-engineering/ship-early-and-ship-twice-as-often/10150985860363920.
-
Page 154: Kent Beck, the.. Kent Beck, “Slow Deployment Causes Meetings,” post on Kent Beck’s Facebook page, November 19, 2015), https://www.facebook.com/notes/kent-beck/slow-deployment-causes-meetings/1055427371156793?_rdr=p.
-
Page 157: Scott Prugh, their…: Prugh, “DOES14: Scott Prugh, CSG DevOps and Lean in Legacy Environments.”
-
Prugh observed, “It…: Ibid.
-
Page 158: Prugh writes, “We…: Ibid.
-
Prugh also observes:…: Ibid.
-
In their experiments…: Puppet Labs and IT Revolution Press, 2013 State of DevOps Report (Portland, OR: Puppet Labs, 2013), http://www.exin-library.com/Player/eKnowledge/2013-state-of-devops-report.pdf.
-
Prugh reported that…: Scott Prugh and Erica Morrison, “DOES15
-
Scott Prugh & Erica Morrison Conway & Taylor Meet the Strangler (v2.0),” YouTube video, 29:39, posted by DevOps Enterprise Summit, November 5, 2015, https://www.youtube.com/watch?v=tKdIHCL0DUg.
-
Page 159: Consider the following…: Tim Tischler, personal conversation with Gene Kim, FlowCon 2013. In practice, the… Puppet Labs and IT Revolution Press, 2013 State of DevOps Report.
-
Page 162: The deployment process…: Chad Dickerson, “Optimizing for developer happiness,” CodeAsCraft.com, June 6, 2011, https://codeascraft.com/2011/06/06/optimizing-for-developer-happiness/.
-
As Noah Sussman…: Noah Sussman and Laura Beth Denker, “Divide and Conquer,” CodeAsCraft.com, April 20, 2011, https://codeascraft.com/2011/04/20/divide-and-concur/.
-
Sussman writes, “Through…: Ibid.
-
Page 163: If all the tests…: Ibid.
-
Once it is an.. Erik Kastner, “Quantum of Deployment,” CodeAsCraft.com, May 20, 2010, https://codeascraft.com/2010/05/20/quantum-of-deployment/.
-
Page 168: This technique was…: Timothy Fitz, “Continuous Deployment at IMVU: Doing the impossible fifty times a day,” TimothyFitz.com, February 10, 2009, http://timothyfitz.com/2009/02/10/continuous-deployment-at-imvu-doing-the-impossible-fifty-times-a-day/.
-
This pattern is…: Fitz, “Continuous Deployment,” TimothyFitz.com.; Michael Hrenko, “DOES15 Michael Hrenko DevOps Insured By Blue Shield of California,” YouTube video, 42:24, posted by DevOps Enterprise Summit, November 5, 2015, https://www.youtube.com/watch?v=NlgrOT24UDw.
-
Page 172: One sophisticated example…: Andrew ‘Boz’ Bosworth, “Building and testing at Facebook,” post on Boz Facebook page, August 8, 2012, https://www.facebook.com/notes/facebook-engineering/building-and-testing-at-facebook/10151004157328920; “Etsy’s Feature flagging API used for operational rampups and A/B testing,” GitHub.com, https://github.com/etsy/feature; “Library for configuration management API,” GitHub.com, https://github.com/Netflix/archaius.
-
Page 173: In 2009, when…: John Allspaw, “Convincing management that cooperation and collaboration was worth it,” KitchenSoap.com, January 5, 2012, http://www.kitchensoap.com/2012/01/05/convincing-management-that-cooperation-and-collaboration-was-worth-it/.
-
Page 174: Similarly, as Chuck…: Rossi, “Release engineering and push karma.”
-
For nearly a decade…: Emil Protalinski, “Facebook passes 1.55B monthly active users and 1.01B daily active users,” Venture Beat, November 4, 2015, http://venturebeat.com/2015/11/04/facebook-passes-1-55b-monthly-active-users-and-1-01-billion-daily-active-users/.
-
Page 174: By 2015, Facebook…: Ibid.
-
Eugene Letuchy, an…: Eugene Letuchy, “Facebook Chat,” post on Eugene Letuchy’s Facebook page, May 3, 2008, http://www.facebook.com/note.php?note_id=14218138919&id=944554719.
-
Implementing this computationally-intensive…: Ibid.
-
Page 175: As Letuchy wrote…: Ibid.
-
He observes that…: Kim, Gruver, Shoup, and Phillips, “Exploring the Uncharted Territory of Microservices.”
-
He reflects, “Looking…: Ibid.
-
eBay’s architecture went…: Shoup, “From Monolith to Microservices.”
-
Page 180: Charles Betz, author…: Charles Betz, Architecture and Patterns for IT Service Management, Resource Planning, and Governance: Making Shoes for the Cobbler’s Children (Witham, MA: Morgan Kaufmann, 2011), 300.
-
Page 182: As Randy Shoup…: Randy Shoup, “From the Monolith to Microservices,” Slideshare.net, posted by Randy Shoup, October 8, 2014, http://www.slideshare.net/RandyShoup/goto-aarhus2014-enterprisearchitecturemicroservices.
-
Shoup notes, “Organizations…: Ibid.
-
As Randy Shoup observes…: Ibid.
-
Page 184: One of the most…: Werner Vogels, “A Conversation with Werner Vogels,” acmqueque 4, no. 4 (2006): 14-22, http://queue.acm.org/detail.cfm?id=1142065.
-
Vogel tells Gray…: Ibid.
-
Describing the thought…: Ibid.
-
Vogel notes, “The…: Ibid.
-
Page 185: In 2011, Amazon…: John Jenkins, “Velocity 2011: Jon Jenkins, “Velocity Culture,”” YouTube video, 15:13, posted by O’Reilly, June 20, 2011, https://www.youtube.com/watch?v=dxk8b9rSKOo.
-
Page 185: By 2015, they…: Ken Exner, “Transforming Software Development,” YouTube video, 40:57, posted by Amazon Web Services, April 10, 2015, https://www.youtube.com/watch?v=YCrhemssYuI&feature=youtu.be.
-
The term strangler…: Martin Fowler, “StranglerApplication,” MartinFowler.com, June 29, 2004, http://www.martinfowler.com/bliki/StranglerApplication.html.
-
When we implement…: Boris Lublinsky, “Versioning in SOA,” The Architecture Journal, April 2007, https://msdn.microsoft.com/en-us/library/bb491124.aspx.
-
Page 186: The strangler application…: Paul Hammant, “Introducing Branch by Abstraction,” PaulHammant.com, April 26, 2007, http://paulhammant.com/blog/branch_by_abstraction.html.
-
An observation from…: Martin Fowler, “StranglerApplication,” MartinFowler.com, June 29, 2004, http://www.martinfowler.com/bliki/StranglerApplication.html.
-
Blackboard Inc., is…: Gregory T. Huang, “Blackboard CEO Jay Bhatt on the Global Future of Edtech,” Xconomy, June 2, 2014, http://www.xconomy.com/boston/2014/06/02/blackboard-ceo-jay-bhatt-on-the-global-future-of-edtech/.
-
Page 187: As David Ashman…: David Ashman, “DOES14 David Ashman
-
Blackboard Learn Keep Your Head in the Clouds,” YouTube video, 30:43, posted by DevOps Enterprise Summit 2014, October 28, 2014, https://www.youtube.com/watch?v=SSmixnMpsI4.
-
In 2010, Ashman…: Ibid.
-
How this started…: David Ashman, personal correspondence with Gene Kim, 2014.
-
Ashman noted. “To…: Ibid.
-
Page 188: “In fact,” Ashman…: Ibid.
-
Page 189: Ashman concluded, “Having…: Ibid.
-
Page 195: In Operations, we…: Kim, Behr, and Spafford, The Visible Ops Handbook: Implementing ITIL in 4 Practical and Auditable Steps (Eugene, OR: IT Process Institute, 2004), Kindle edition, Introduction.
-
In contrast, the…: Ibid.
-
In other words…: Ibid.
-
Page 196: To enable this…: “Telemetry,” Wikipedia, last modified May 5, 2016, https://en.wikipedia.org/wiki/Telemetry.
-
McDonnell described how…: Michael Rembetsy and Patrick McDonnell, “Continuously Deploying Culture: Scaling Culture at Etsy Velocity Europe 2012,” Slideshare.net, posted by Patrick McDonnell, October 4, 2012, http://www.slideshare.net/mcdonnps/continuously-deploying-culture-scaling-culture-at-etsy-14588485.
-
McDonnell explained further…: Ibid.
-
By 2011, Etsy… John Allspaw, personal conversation with Gene Kim, 2014.
-
Page 197: As Ian Malpass…: Ian Malpass, “Measure Anything, Measure Everything,” CodeAsCraft.com, February 15, 2011, http://codeascraft.com/2011/02/15/measure-anything-measure-everything/.
-
Page 197: One of the findings…: Kersten, IT Revolution, and PwC, 2015 State of DevOps Report.
-
The top two…: “2014 State Of DevOps Findings! Velocity Conference,” Slideshare.net, posted by Gene Kim, June 30, 2014, http://www.slideshare.net/realgenekim/2014-state-of-devops-findings-velocity-conference.
-
Page 198: In The Art…: James Turnbull, The Art of Monitoring (Seattle, WA: Amazon Digital Services, 2016), Kindle edition, Introduction.
-
Page 200: The resulting capability… “Monitorama Please, no more Minutes, Milliseconds, Monoliths or Monitoring Tools,” Slideshare.net, posted by Adrian Cockcroft, May 5, 2014, http://www.slideshare.net/adriancockcroft/monitorama-please-no-more.
-
Page 201: Scott Prugh, Chief…: Prugh, “DOES14: Scott Prugh, CSG DevOps and Lean in Legacy Environments.” To support these… Brice Figureau, “The 10 Commandments of Logging,” Mastersen’s Blog, January 13, 2013, http://www.masterzen.fr/2013/01/13/the-10-commandments-of-logging/.
-
Page 202: Choosing the right…: Dan North, personal correspondence with Gene Kim, 2016. To help ensure… Anton Chuvakin, “LogLogic/Chuvakin Log Checklist,” republished with permission, 2008, http://juliusdavies.ca/logging/llclc.html.
-
Page 203: In 2004, Kim… Kim, Behr, and Spafford, The Visible Ops Handbook, Introduction.
-
Page 204: This was the…: Dan North, “Ops and Operability,” SpeakerDeck.com, February 25, 2016, https://speakerdeck.com/tastapod/ops-and-operability.
-
As John Allspaw…: John Allspaw, personal correspondence with Gene Kim, 2011.
-
Page 206: This is often…: “Information Radiators,” AgileAlliance.com, accessed May 31, 2016, https://www.agilealliance.org/glossary/incremental-radiators/.
-
Page 207: Although there may.. Ernest Mueller, personal correspondence with Gene Kim, 2014. Prachi Gupta, Director… Prachi Gupta, “Visualizing LinkedIn’s Site Performance,” LinkedIn Engineering blog, June 13, 2011, https://engineering.linkedin.com/25/visualizing-linkedins-site-performance.
-
Page 208: Thus began Eric…: Eric Wong, “Eric the Intern: the Origin of InGraphs,” LinkedIn, June 30, 2011, http://engineering.linkedin.com/32/eric-intern-origin-ingraphs.
-
Wong wrote, “To…: Ibid.
-
At the time…: Ibid.
-
In writing about…: Gupta, “Visualizing LinkedIn’s Site Performance.”
-
Page 210: Ed Blankenship, Senior…: Ed Blankenship, personal correspondence with Gene Kim, 2016.
-
Page 212: However, increasingly these…: Mike Burrows, “The Chubby lock service for loosely-coupled distributed systems,” OSDI’06: Seventh Symposium on Operating System Design and Implementation, November 2006, http://static.googleusercontent.com/media/research.google.com/en//archive/chubby-osdi06.pdf.
-
Page 212: Consul may be…: Jeff Lindsay, “Consul Service Discovery with Docker,” Progrium.com, August 20, 2014, http://progrium.com/blog/2014/08/20/consul-service-discovery-with-docker.
-
Page 213: As Jody Mulkey…: Jody Mulkey, “DOES15 Jody Mulkey DevOps in the Enterprise: A Transformation Journey,” YouTube video, 28:22, posted by DevOps Enterprise Summit, November 5, 2015, https://www.youtube.com/watchv=USYrDaPEFtM.
-
Page 215: In 2015, Netflix… Netflix Letter to Shareholders, January 19, 2016, http://files.shareholder.com/downloads/NFLX/2432188684x0x870685/C6213FF9-5498-4084-A0FF-74363CEE35A1/Q4_15_Letter_to_Shareholders_-_COMBINED.pdf.
-
Roy Rapoport describes…: Roy Rapoport, personal correspondence with Gene Kim, 2014.
-
One of the statistical…: Victoria Hodge and Jim Austin, “A Survey of Outlier Detection Methodologies,” Artificial Intelligence Review 22, no. 2 (October 2004): 85-126, http://www.geo.upm.es/postgrado/CarlosLopez/papers/Hodge+Austin_OutlierDetection_AIRE381.pdf.
-
Rapoport explains that.. Roy Rapoport, personal correspondence with Gene Kim, 2014.
-
Page 216: Rapoport continues, “We…: Ibid.
-
Rapoport states that…: Ibid.
-
As John Vincent…: Toufic Boubez, “Simple math for anomaly detection toufic boubez metafor software monitorama pdx 2014-05-05,” Slideshare.net, posted by tboubez, May 6, 2014, http://www.slideshare.net/tboubez/simple-math-for-anomaly-detection-toufic-boubez-metafor-software-monitorama-pdx-20140505.
-
Page 218: Tom Limoncelli, co-author…: Tom Limoncelli, “Stop monitoring whether or not your service is up!,” EverythingSysAdmin.com, November 27, 2013, http://everythingsysadmin.com/2013/11/stop-monitoring-if-service-is-up.html.
-
Page 219: As Dr. Toufic…: Toufic Boubez, “Simple math for anomaly detection toufic boubez metafor software monitorama pdx 2014-05-05,” Slideshare.net, posted by tboubez, May 6, 2014, http://www.slideshare.net/tboubez/simple-math-for-anomaly-detection-toufic-boubez-metafor-software-monitorama-pdx -20140505.
-
Page 220: Dr. Nicole Forsgren…: Dr. Nicole Forsgren, personal correspondence with Gene Kim, 2015.
-
Page 221: Scryer works by…: Daniel Jacobson, Danny Yuan, and Neeraj Joshi, “Scryer: Netflix’s Predictive Auto Scaling Engine,” The Netflix Tech Blog, November 5, 2013, http://techblog.netflix.com/2013/11 /scryer-netflixs-predictive-auto-scaling.html.
-
Page 222: These techniques are…: Varun Chandola, Arindam Banerjee, and Vipin Kumar, “Anomaly detection: A survey,” ACM Computing Surveys 41, no. 3 (July 2009): article no. 15, http://doi.acm.org/10.1145/1541880.1541882.
-
Tarun Reddy, VP…: Tarun Reddy, personal interview with Gene Kim, Rally headquarters, Boulder, CO, 2014.
-
Page 224: At Monitorama in 2014…: “Kolmogorov-Smirnov Test,” Wikipedia, last modified May 19, 2016, http://en.wikipedia.org/wiki/Kolmogorov%E2%80%93Smirnov_test.
-
Page 225: Even saying Kilmogorov-Smirnov…: ”Simple math for anomaly detection toufic boubez metafor software monitorama pdx 2014-05-05,” Slideshare.net, posted by tboubez, May 6, 2014, http://www.slideshare.net/tboubez/simple-math-for-anomaly-detection-toufic-boubez-metafor-software-monitorama-pdx-20140505.
-
Page 227: In 2006, Nick…: Mark Walsh, “Ad Firms Right Media, AdInterax Sell To Yahoo,” MediaPost, October 18, 2006, http://www.mediapost.com/publications/article/49779/ad-firms-right-media-adinterax-sell-to-yahoo.html?edition=.
-
Galbreath described the…: Nick Galbreath, personal conversation with Gene, 2013.
-
However, Galbreath observed…: Nick Galbreath, “Continuous Deployment The New #1 Security Feature, from BSildesLA 2012,” Slideshare.net, posted by Nick Galbreath, Aug 16, 2012, http://www.slideshare.net/nickgsuperstar/continuous-deployment-the-new-1-security-feature.
-
After observing many…: Ibid.
-
Page 228: Galbreath observes that…: Ibid.
-
Page 231: As Patrick Lightbody… “Volocity 2011: Patrick Lightbody, ‘From Inception to Acquisition,’” YouTube video, 15:28, posted by O’Reilly, June 17, 2011, https://www.youtube.com/watch?v=ShmPod8JecQ.
-
Page 232: As Arup Chakrabarti…: Arup Chakrabarti, “Common Ops Mistakes,” presentation at Heavy Bit Industries, June 3, 2014, http://www.heavybit.com/library/video/common-ops-mistakes/
-
Page 233: More recently, Jeff…: ”From Design Thinking to DevOps and Back Again: Unifying Design & Operations,” Vimeo video, 21:19, posted by William Evans, June 5, 2015, https://vimeo.com/129939230.
-
Page 234: As an anonymous… Anonymous, personal conversation with Gene Kim, 2005.
-
Launch guidance and.. Tom Limoncelli, “SRE@Google: Thousands Of DevOps Since 2004,” YouTube video of USENIX Association Talk, NYC, posted by USENIX, 45:57, posted January 12, 2012, http://www.youtube.com/watchv=iIuTnhdTzK0.
-
Page 238: As Treynor Sloss has…: Ben Treynor, “Keys to SRE” (presentation, Usenix SREcon14, Santa Clara, CA, May 30, 2014), https://www.usenix.org/conference/srecon14/technical-sessions/presentation/keys-sre.
-
Treynor Sloss has resisted…: Ibid.
-
Even when new…: Limoncelli, “SRE@Google.”
-
Tom Limoncelli noted…: Ibid.
-
Page 239: Limoncelli noted, “In…: Ibid.
-
Furthemore, Limoncelli observed…: Tom Limoncelli, personal correspondence with Gene Kim, 2016.
-
Page 239: Limoncelli explained, “Helping…: Ibid., 2015.
-
Page 242: Cook explained that…: Scott Cook, “Leadership in an Agile Age: An Interview with Scott Cook,” Intuit.com, April 20, 2011, https://web.archive.org/web/20160205050418/http://network.intuit.com/2011/04/20/leadership-in-the-agile-age/
-
He continued, “By…: Ibid.
-
Page 243: In previous eras…: “Direct Marketing,” Wikipedia, last modified May 28, 2016, https://en.wikipedia.org/wiki/Direct_marketing.
-
Interestingly, it has…: Freakonomics, “Fighting Poverty With Actual Evidence: Full Transcript,” Freakonomics.com, November 27, 2013, http://freakonomics.com/2013/11/27/fighting-poverty-with-actual-evidence-full-transcript/.
-
Page 244: Ronny Kohavi, Distinguished…: Ron Kohavi, Thomas Crook, and Roger Longbotham, “Online Experimentation at Microsoft,” (paper presented at the Fifteenth ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, Paris, France, 2009), https://exp-platform.com/Documents/ExP_DMCaseStudies.pdf.
-
Kohavi goes on…: Ibid.
-
Page 246: Barry O’Reilly, co-author…: Barry O’Reilly, “How to Implement Hypothesis-Driven Development,” BarryOReilly.com, October 21, 2013, http://barryoreilly.com/2013/10/21/how-to-implement-hypothesis-driven-development/.
-
In 2009, Jim…: Gene Kim, “Organizational Learning and Competitiveness: Revisiting the “Allspaw/Hammond 10 Deploys Per Day at Flickr” Story,” ITRevolution.com, 2015, http://itrevolution.com/organizational-learning-and-competitiveness-a-different-view-of-the-allspawhammond-10-deploys-per-day-at-flickr-story/.
-
Page 247: Stoneham observes that…: Ibid.
-
He continues, “These…: Ibid.
-
Their astounding achievements…: Ibid.
-
Page 248: Stoneham concluded, “This…: Ibid.
-
Page 249: Once a pull…: Scott Chacon, “Github Flow,” ScottChacon.com, August 31, 2011, http://scottchacon.com/2011/08/31/github-flow.html.
-
Page 251: For example, in…: Jake Douglas, “Deploying at Github,” GitHub.com, August 29, 2012, https://github.com/blog/1241-deploying-at-github.
-
A fifteen minute…: John Allspaw, “Counterfactual Thinking, Rules, and the Knight Capital Accident,” KitchenSoap.com, October 29, 2013, http://www.kitchensoap.com/2013/10/29/counterfactuals-knight-capital/.
-
Page 253: One of the core…: Bradley Staats and David M. Upton, “Lean Knowledge Work,” Harvard Business Review, October 2011, https://hbr.org/2011/10/lean-knowledge-work.
-
Page 256: As Giary Özil…: Giray Özil, Twitter post, February 27, 2013, 10:42 a.m., https://twitter.com/girayozil/status/306836785739210752.
-
Page 257: As noted earlier…: Eran Messeri, “What Goes Wrong When Thousands of Engineers Share the Same Continuous Build?,” (2013), http://scribes.tweetscriber.com/realgenekim/206.
-
In 2010, there…: John Thomas and Ashish Kumar, “Welcome to the Google Engineering Tools Blog,” Google Engineering Tools blog, posted May 3, 2011, http://google-engtools.blogspot.com/2011/05/welcome-to-google-engineering-tools.html.
-
This requires considerable…: Ashish Kumar, “Development at the Speed and Scale of Google,” (presentation at QCon, San Francisco, CA, 2010), https://qconsf.com/sf2010/dl/qcon-sanfran-2010/slides/AshishKumar_DevelopingProductsattheSpeedandScaleofGoogle.pdf.
-
Page 258: He said, “I…: Randy Shoup, personal correspondence with Gene Kim, 2014.
-
Page 259: Jeff Atwood, one…: Jeff Atwood, “Pair Programming vs. Code Reviews,” CodingHorror.com, November 18, 2013, http://blog.codinghorror.com/pair-programming-vs-code-reviews/.
-
Page 260: He continued, “Most…: Ibid.
-
Dr. Laurie Williams performed…: “Pair Programming,” ALICE Wiki page, last modified April 4, 2014, http://euler.math.uga.edu/wiki/index.php?title=Pair_programming.
-
She argues that…: Elisabeth Hendrickson, “DOES15 Elisabeth Hendrickson Its All About Feedback,” YouTube video, 34:47, posted by DevOps Enterprise Summit, November 5, 2015, https://www.youtube.com/watch?v=r2BFTXBundQ.
-
Page 261: In her 2015…: Ibid.
-
The problem Hendrickson…: Ibid. Worse, skilled developers… Ibid. Hendrickson lamented that… Ibid.
-
Page 262: That was an actual…: Ryan Tomayko and Shawn Davenport, personal interview with Gene Kim, 2013.
-
It is many…: Ibid.
-
Reading through the…: Ibid.
-
Page 263: Adrian Cockcroft observed…: Adrian Cockcroft, interview by Michael Ducy and Ross Clanton, “Adrian Cockcroft of Battery Ventures – the Goat Farm – Episode 8,” The Goat Farm, podcast audio, July 31, 2015, http://goatcan.do/2015/07/31/adrian-cockcroft-of-battery-ventures-the-goat-farm-episode-8/.
-
Similarly, Dr. Tapabrata Pal…: Tapabrata Pal, “DOES15 Tapabrata Pal Banking on Innovation & DevOps,” YouTube video, 32:57, posted by DevOps Enterprise Summit, January 4, 2016, https://www.youtube.com/watch?v=bbWFCKGhxOs.
-
Jason Cox, Senior…: Jason Cox, “Disney DevOps.”
-
At Target in…: Ross Clanton and Heather Mickman, ‘DOES14 Ross Clanton and Heather Mickman DevOps at Target,” YouTube video, 29:20, posted by DevOps Enterprise Summit 2014, October 29, 2014, https://www.youtube.com/watch?v=exrjV9V9vhY.
-
Page 264: “As we went…: Ibid.
-
She added, “I…: Ibid.
-
Page 271: The result is…: Spear, The High-Velocity Edge, chap. 1.
-
“For such an…: Ibid., chap. 10.
-
A striking example…: Julianne Pepitone, “Amazon EC2 Outage Downs Reddit, Quora,” CNN Money, April 22, 2011, http://money.cnn.com/2011/04/21/technology/amazon_server_outage.
-
In January 2013…: Timothy Prickett Morgan, “A Rare Peek Into The Massive Scale of AWS,” Enterprise Tech, November 14, 2014, http://www.enterprisetech.com/2014/11/14/rare-peek-massive-scale-aws/.
-
Page 272: However, a Netflix…: Adrian Cockcroft, Cory Hicks, and Greg Orzell, “Lessons Netflix Learned from the AWS Outage,” The Netflix Tech Blognetflix-learned-from-aws-outage.html.
-
They did so…: Ibid.
-
Page 273: Dr. Sidney Dekker…: Sidney Dekker, Just Culture: Balancing Safety and Accountability (Lund University, Sweden: Ashgate Publishing Company, 2007), 152.
-
He asserts that…: “DevOpsDays Brisbane 2014 Sidney Decker, "System Failure, Human Error: Who’s to Blame?” Vimeo video, 1:07:38, posted by [email protected], 2014, https://vimeo.com/102167635.
-
Page 273: As John Allspaw…: Jenn Webb, interview with John Allspaw, “PostMortems, Sans Finger-Pointing,” The O’Reilly Radar Postcast, podcast audio, August 21, 2014, http://radar.oreilly.com/2014/08/postmortems-sans-finger-pointing-the-oreilly-radar-podcast.html.
-
Page 274: Blameless post-mortems, a…: John Allspaw, “Blameless PostMortems and a Just Culture,” CodeAsCraft.com, May 22, 2012, http://codeascraft.com/2012/05/22/blameless-postmortems/.
-
Page 276: Ian Malpass, an…: Ian Malpass, “DevOpsDays Minneapolis 2014 -Ian Malpass, Fallible humans,” YouTube video, 35:48, posted by DevOps Minneapolis, July 20, 2014, https://www.youtube.com/watch?v=5NY-SrQFrBU.
-
Dan Milstein, one…: Dan Milstein, “Post-Mortems at HubSpot: What I Learned from 250 Whys,” HubSpot, June 1, 2011, http://product.hubspot.com/blog/bid/64771/Post-Mortems-at-HubSpot-What-I-Learned-From-250-Whys.
-
We may also…: “Post-Mortem for February 24, 2010 Outage,” Google App Engine website, March 4, 2010, https://groups.google.com /forum/#!topic/google-appengine/p2QKJ0OSLc8; “Summary of the Amazon DynamoDB Service Disruption and Related Impacts in the US-East Region,” Amazon Web Services website, accessed May 28, 2016, https://aws.amazon.com/message/5467D2/.
-
This desire to…: Bethany Macri, “Morgue: Helping Better Understand Events by Building a Post Mortem Tool Bethany Macri,” Vimeo video, 33:34, posted by [email protected], October 18, 2013, http://vimeo.com/77206751.
-
For example, as…: Spear, The High-Velocity Edge, chap. 4.
-
Page 278: Dr. Amy C. Edmondson… Amy C. Edmondson, “Strategies for Learning from Failure,” Harvard Business Review, April 2011, https://hbr.org/2011/04/strategies-for-learning-from-failure.
-
Page 279: Dr. Spear summarizes…: Ibid.
-
We now know…: Ibid., chap. 3.
-
However, prior to…: Michael Roberto, Richard M.J. Bohmer, and Amy C. Edmondson, “Facing Ambiguous Threats,” Harvard Business Review, November 2006, https://hbr.org/2006/11/facing-ambiguous-threats/ar/1.
-
They describe how…: Ibid.
-
Page 280: They observe, “Firms…: Ibid.
-
The authors conclude…: Ibid.
-
On failures, Roy…: Roy Rapoport, personal correspondence with Gene Kim, 2012.
-
He continues, “I…: Ibid.
-
Page 281: He concludes, “DevOps…: Ibid.
-
As Michael Nygard…: Michael T. Nygard, Release It!: Design and Deploy Production-Ready Software (Pragmatic Bookshelf: Raleigh, NC, 2007), Kindle edition, Part I.
-
Page 281: An even more…: Jeff Barr, “EC2 Maintenance Update,” AWS Blog, September 25, 2014, https://aws.amazon.com/blogs/aws/ec2-maintenance-update/.
-
As Christos Kalantzis…: Bruce Wong and Christos Kalantzis, “A State of Xen Chaos Monkey & Cassandra,” The Netflix Tech Blog, October 2, 2014, http://techblog.netflix.com/2014/10/a-state-of-xen-chaos-monkey-cassandra.html.
-
Page 282: But, Kalantzis continues…: Ibid.
-
As Kalantzis and…: Ibid.
-
Even more surprising…: Roy Rapoport, personal correspondence with Gene Kim, 2015.
-
Specific architectural patterns…: Adrian Cockcroft, personal correspondence with Gene Kim, 2012.
-
In this section…: Jesse Robbins, “GameDay: Creating Resiliency Through Destruction LISA11,” Slideshare.net, posted by Jesse Robbins, December 7, 2011, http://www.slideshare.net/jesserobbins/ameday-creating-resiliency-through-destruction.
-
Robbins defines resilience…: Ibid.
-
Page 283: Jesse Robbins observes…: Jesse Robbins, Kripa Krishnan, John Allspaw, and Tom Limoncelli, “Resilience Engineering: Learning to Embrace Failure,” amcqueue 10, no. 9 (September 13, 2012): https:// queue.acm.org/detail.cfm?id=2371297.
-
As Robbins quips…: Ibid.
-
As Robbins describes…: Ibid.
-
Robbins explains, “You…: Ibid.
-
Page 284: During that time…: “Kripa Krishnan: ‘Learning Continuously From Failures’ at Google,” YouTube video, 21:35, posted by Flowcon, November 11, 2014, https://www.youtube.com/watch?v=KqqS3wgQum0.
-
Krishnan wrote, “An…: Kripa Krishnan, “Weathering the Unexpected,” Communications of the ACM 55, no. 11 (November 2012): 48-52, http://cacm.acm.org/magazines/2012/11/156583-weathering-the-unexpected/abstract.
-
Some of the learnings…: Ibid.
-
Page 285: As Peter Senge…: Widely attributed to Peter Senge.
-
Page 287: As Jesse Newland…: Jesse Newland, “ChatOps at GitHub,” SpeakerDeck.com, February 7, 2013, https://speakerdeck.com/jnewland/chatops-at-github.
-
Page 288: As Mark Imbriaco…: Mark Imbriaco, personal correspondence with Gene Kim, 2015.
-
They enabled Hubot…: Newland, “ChatOps at GitHub.”
-
Page 289: Hubot often performed…: Ibid.
-
Page 289: Newland observes that…: Ibid.
-
Page 290: Instead of putting…: Leon Osterweil, “Software processes are software too,” paper presented at International Conference on Software Engineering, Monterey, CA, 1987, http://www.cs.unibo.it/cianca/wwwpages/ids/letture/Osterweil.pdf.
-
Justin Arbuckle was…: Justin Arbuckle, “What Is ArchOps: Chef Executive Roundtable” (2013).
-
What resulted was…: Ibid.
-
Arbuckle’s conclusion was…: Ibid.
-
Page 291: By 2015, Google…: Cade Metz, “Google Is 2 Billion Lines of Code— and It’s All in One Place,” Wired, September 16, 2015, http://www.wired.com/2015/09/google-2-billion-lines-codeand-one-place/.
-
The Chrome and…: Ibid.
-
Rachel Potvin, a…: Ibid.
-
Furthermore, as Eran…: Eran Messeri, “What Goes Wrong When Thousands of Engineers Share the Same Continuous Build?” (2013), http://scribes.tweetscriber.com/realgenekim/206.
-
As Randy Shoup…: Randy Shoup, personal correspondence with Gene Kim, 2014.
-
Page 292: Tom Limoncelli, co-author…: Tom Limoncelli, “Yes, you can really work from HEAD,” EverythingSysAdmin.com, March 15, 2014, http://everythingsysadmin.com/2014/03/yes-you-really-can-work-from-head.html.
-
Page 296: Tom Limoncelli describes…: Tom Limoncelli, “Python is better than Perl6,” EverythingSysAdmin.com, January 10, 2011, http://everythingsysadmin.com/2011/01/python-is-better-than-perl6 .html.
-
Page 297: _Google used C…_: “Which programming languages does Google use internally?,” Quora.com forum, accessed May 29, 2016, https:// www.quora.com/Which-programming-languages-does-Google-use-internally.; “When will Google permit languages other than Python, C, Java and Go to be used for internal projects?,” Quora.com forum, accessed May 29, 2016, https://www.quora.com/When-will-Google-permit-languages-other-than-Python-C-Java-and-Go-to-be-used-for-internal-projects/answer/Neil-Kandalgaonkar.
-
In a presentation…: Ralph Loura, Olivier Jacques, and Rafael Garcia, “DOES15 Ralph Loura, Olivier Jacques, & Rafael Garcia Breaking Traditional IT Paradigms to…,” YouTube video, 31:07, posted by DevOps Enterprise Summit, November 16, 2015, https://www.youtube.com/watch?v=q9nNqqie_sM.
-
In many organizations…: Michael Rembetsy and Patrick McDonnell, “Continuously Deploying Culture: Scaling Culture at Etsy Velocity Europe 2012,” Slideshare.net, posted by Patrick McDonnell, October 4, 2012, http://www.slideshare.net/mcdonnps/continuously-deploying-culture-scaling-culture-at-etsy-14588485.
-
At that time, Etsy…: Ibid.
-
Page 298: Over the next…: Ibid.
-
Similarly, Dan McKinley…: Dan McKinley, “Why MongoDB Never Worked Out at Etsy,” McFunley.com, December 26, 2012, http:// mcfunley.com/why-mongodb-never-worked-out-at-etsy.
-
Page 299: One of the…: “Kaizen,” Wikipedia, last modified May 12, 2016, https://en.wikipedia.org/wiki/Kaizen.
-
Dr. Spear explains…: Spear, The High-Velocity Edge, chap. 8.
-
Spear observes that…: Ibid.
-
Page 300: Clanton describes, “We…: Mickman and Clanton, “(Re)building an Engineering Culture.”
-
Ravi Pandey, a…: Ravi Pandey, personal correspondence with Gene Kim, 2015.
-
Clanton expands on…: Mickman and Clanton, “(Re)building an Engineering Culture.”
-
Page 301: In addition to…: Hal Pomeranz, “Queue Inversion Week,” Righteous IT, February 12, 2009, https://righteousit.wordpress.com/2009/02/12/queue-inversion-week/.
-
Page 302: As Dr. Spear…: Spear, The High-Velocity Edge, chap. 3.
-
In an interview with Jessica…: Jessica Stillman, “Hack Days: Not Just for Facebookers,” Inc., February 3, 2012, http://www.inc.com/jessica-stillman/hack-days-not-just-for-facebookers.html.
-
In 2008, Facebook…: AP, “Number of active users at Facebook over the years,” Yahoo! News, May 1, 2013, https://www.yahoo.com/news/number-active-users-facebook-over-230449748.html?ref=gs.
-
During a hack…: Haiping Zhao, “HipHop for PHP: Move Fast,” post on Haiping Zhao’s Facebook page, February 2, 2010, https://www.facebook.com/notes/facebook-engineering/hiphop-for-phpmove-fast/280583813919.
-
In an interview with Cade…: Cade Metz, “How Three Guys Rebuilt the Foundation of Facebook,” Wired, June 10, 2013, http://www.wired.com/wiredenterprise/2013/06/facebook-hhvm-saga/all/.
-
Page 303: Steve Farley, VP…: Steve Farley, personal correspondence with Gene Kim, January 5, 2016.
-
Karthik Gaekwad, who…: “Agile 2013 Talk: How DevOps Change Everything,” Slideshare.net, posted by Karthik Gaekwad, August 7, 2013, http://www.slideshare.net/karthequian/howdevopschangeseverythingagile2013karthikgaekwad/.
-
Page 304: As Glenn O’Donnell…: Glenn O’Donnell, “DOES14 Glenn O’Donnell, Forrester, "Modern Services Demand a DevOps Culture Beyond Apps,” YouTube video, 12:20, posted by DevOps Enterprise Summit 2014, November 5, 2014, https://www.youtube.com/watch?v=pvPWKuO4_48.
-
Page 305: As of 2014…: Nationwide, 2014 Annual Report, https://www.nationwide.com/about-us/nationwide-annual-report-2014.jsp.
-
Steve Farley, VP…: Steve Farley, personal correspondence with Gene Kim, 2016.
-
Page 305: Capital One, one…: “DOES15 Tapabrata Pal Banking on Innovation & DevOps,” YouTube video, 32:57, posted by DevOps Enterprise Summit, January 4, 2016, https://www.youtube.com/watch?v=bbWFCKGhxOs.
-
Dr. Tapabrata Pal…: Tapabrata Pal, personal correspondence with Gene Kim, 2015.
-
Target is the…: “Corporate Fact Sheet,” Target company website, accessed June 9, 2016, https://corporate.target.com/press/corporate.
-
Incidentally, the first…: Evelijn Van Leeuwen and Kris Buytaert, “DOES15 Evelijn Van Leeuwen and Kris Buytaert Turning Around the Containership,” YouTube video, 30:28, posted by DevOps Enterprise Summit, December 21, 2015, https://www.youtube.com/watch?v=0GId4AMKvPc.
-
Page 306: Clanton describes, “2015…: Mickman and Clanton, “(Re)building an Engineering Culture.”
-
At Capital One…: “DOES15 Tapabrata Pal Banking on Innovation & DevOps,” YouTube video, 32:57, posted by DevOps Enterprise Summit, January 4, 2016, https://www.youtube.com/watch?v=bbWFCKGhxOs.
-
Bland explains that…: Bland, “DOES15 Mike Bland Pain Is Over, If You Want It.”
-
Even though they…: Ibid.
-
They used several…: Ibid.
-
Bland described, “The…: Ibid.
-
Bland continues, “One …: Ibid.
-
Page 307: As Bland describes …: Ibid.
-
Bland continues, “It …: Ibid.
-
He continues, “The …: Ibid.
-
Bland describes fixits…: Mike Bland, “Fixits, or I Am the Walrus,” Mike-Bland.com, October 4, 2011, https://mike-bland.com/2011/10/04/fixits.html.
-
This Fixits, as…: Ibid.
Part VI: The Technological Practices Of Integrating Information Security Change Management And Compliance
-
Page 313: One of the top…: James Wickett, “Attacking Pipelines—Security meets Continuous Delivery,” Slideshare.net, posted by James Wickett, June 11, 2014, http://www.slideshare.net/wickett/attacking-pipelinessecurity-meets-continuous-delivery.
-
James Wickett, one…: Ibid.
-
Similar ideas were…: Tapabrata Pal, “DOES15 Tapabrata Pal Banking on Innovation & DevOps,” YouTube video, 32:57, posted by DevOps Enterprise Summit, January 4, 2016, https://www.youtube.com/watch?v=bbWFCKGhxOs.
-
Page 314: Justin Arbuckle, former…: Justin Arbuckle, personal interview with Gene Kim, 2015.
-
He continues, “By…: Ibid.
-
Page 314: This helped the…: Snehal Antani, “IBM Innovate DevOps Keynote,” YouTube video, 47:57, posted by IBM DevOps, June 12, 2014, https:// www.youtube.com/watch?v=s0M1P05-6Io.
-
Page 315: In a presentation…: Nick Galbreath, “DevOpsSec: Appling DevOps Principles to Security, DevOpsDays Austin 2012,” Slideshare, posted by Nick Galbreath, April 12, 2012, http://www.slideshare.net/nickgsuperstar/devopssec-apply-devops-principles-to-security.
-
Furthermore, he states…: Ibid.
-
Page 320: Furthermore, we should…: “OWASP Cheat Sheet Series,” OWASP.org, last modified March 2, 2016, https://www.owasp.org/index.php/OWASP_Cheat_Sheet_Series. The scale of… Justin Collins, Alex Smolen, and Neil Matatall, “Putting to your Robots to Work V1.1,” Slideshare.net, posted by Neil Matatall, April 24, 2012, http://www.slideshare.net/xplodersuv/sf-2013-robots/.
-
In early 2009…: “What Happens to Companies That Get Hacked? FTC Cases,” Giant Bomb forum, posted by SuicidalSnowman, July 2012, http://www.giantbomb.com/forums/off-topic-31/what-happens-to-companies-that-get-hacked-ftc-case-540466/.
-
Page 321: In their previously…: Collins, Smolen, and Matatall, “Putting to your Robots to Work V1.1.”
-
Page 322: The first big…: Twitter Engineering, “Hack Week @ Twitter,” Twitter blog, January 25, 2012, https://blog.twitter.com/2012/hack-week-twitter.
-
Page 323: Josh Corman observed…: Josh Corman and John Willis, “Immutable Awesomeness Josh Corman and John Willis at DevOps Enterprise Summit 2015,” YouTube video, 34:25, posted by Sonatype, October 21, 2015, https://www.youtube.com/watch?v=-S8-lrm3iV4.
-
In the 2014…: Verizon, ”2014 Data Breach Investigations Report,” (Verizon Enterprise Solutions, 2014), https://dti.delaware.gov/pdfs/rp_Verizon-DBIR-2014_en_xg.pdf.
-
Page 324: In 2015, this…: “2015 State of the Software Supply Chain Report: Hidden Speed Bumps on the Way to ‘Continuous,’” (Fulton, MD: Sonatype, Inc, 2015), http://cdn2.hubspot.net/hubfs/1958393/White_Papers/2015_State_of_the_Software_Supply_Chain_Report-.pdf?t=1466775053631.
-
The last statistic…: Dan Geer and Joshua Corman, “Almost Too Big to Fail,” ;login:: The Usenix Magazine, 39, no. 4 (August 2014): 66-68, https://www.usenix.org/system/files/login/articles/15_geer_0.pdf.
-
Page 325: US Federal Government… Wyatt Kash, “New details released on proposed 2016 IT spending,” FedScoop, February 4, 2015, http://fedscoop.com/what-top-agencies-would-spend-on-it-projects-in-2016.
-
As Mike Bland… Bland, “DOES15 Mike Bland Pain Is Over, If You Want It.”
-
Page 326: Furthermore, the Cloud.gov… Mossadeq Zia, Gabriel Ramírez, Noah Kunin, “Compliance Masonry: Bulding a risk management platform, brick by brick,” 18F, April 15, 2016, https://18f.gsa.gov/2016/04/15/compliance-masonry-buildling-a-risk-management-platform/.
-
Marcus Sachs, one…: Marcus Sachs, personal correspondence with Gene Kim, 2010.
-
Page 328: We need to…: “VPC Best Configuration Practices,” Flux7 blog, January 23, 2014, http://blog.flux7.com/blogs/aws/vpc-best-configuration-practices.
-
In 2010, Nick…: Nick Galbreath, “Fraud Engineering, from Merchant Risk Council Annual Meeting 2012,” Slideshare.net, posted by Nick Galbreath, May 3, 2012, http://www.slideshare.net/nickgsuperstar/fraud-engineering.
-
Page 329: Of particular concern…: Nick Galbreath, “DevOpsSec: Appling DevOps Principles to Security, DevOpsDays Austin 2012,” Slideshare.net, posted by Nick Galbreath, April 12, 2013, http://www.slideshare.net/nickgsuperstar/devopssec-apply-devops-principles-to-security.
-
We were always…: Ibid.
-
This was a ridiculously…: Ibid.
-
As Galbreath observed…: Ibid.
-
Page 330: Galbreath observed, “One…: Ibid.
-
As Jonathan Claudius…: Jonathan Claudius, “Attacking Cloud Services with Source Code,” Speakerdeck.com, posted by Jonathan Claudius, April 16, 2013, https://speakerdeck.com/claudijd/attacking-cloud-services-with-source-code.
Chapter 23: Protecting the Deployment Pipeline and Integrating into Change Management and Other Security and Compliance Controls
-
Page 334: ITIL defines utility… Axelos, ITIL Service Transition (ITIL Lifecycle Suite) (Belfast, Ireland: TSO, 2011), 48.
-
Page 337: Salesforce was founded…: Reena Matthew and Dave Mangot, “DOES14 Reena Mathew and Dave Mangot Salesforce,” Slideshare.net, posted by ITRevolution, October 29, 2014, http:// www.slideshare.net/ITRevolution/does14-reena-matthew-and-dave-mangot-salesforce.
-
By 2007, the…: Dave Mangot and Karthik Rajan, “Agile.2013. effecting.a.dev ops.transformation.at.salesforce,” Slideshare.net, posted by Dave Mangot, August 12, 2013, http://www.slideshare.net/dmangot/agile2013effectingadev-opstransformationatsalesforce.
-
Karthik Rajan, then…: Ibid.
-
At the 2014…: Matthew and Mangot, “DOES14 Salesforce.”
-
Page 338: For Mangot and …: Ibid.
-
Furthermore, they noted …: Ibid.
-
Page 339: Bill Massie is…: Bill Massie, personal correspondence with Gene Kim, 2014.
-
Page 340: Because the scope…: “Glossary,” PCI Security Standards Council website, accessed May 30, 2016, https://www.pcisecuritystandards.org/pci_security/glossary.
-
Are code review…: PCI Security Standards Council, Payment Card Industry (PCI) Data Security Stands: Requirements and Security Assessment Procedures, Version 3.1 (PCI Security Standards Council, 2015), Section 6.3.2. https://webcache.googleusercontent.com/search?q=cache:hpRe2COzzdAJ:https://www.cisecuritystandards.org/documents/PCI_DSS_v3-1_SAQ_D_Merchant_rev1-1.docx+&cd=2&hl=en&ct=clnk&gl=us.
-
Page 341: To fulfill this…: Bill Massie, personal correspondence with Gene Kim, 2014.
-
Massie observes that…: Ibid.
-
As a result…: Ibid.
-
Page 342: As Bill Shinn…: Bill Shinn, “DOES15 Bill Shinn Prove it! The Last Mile for DevOps in Regulated Organizations,” Slideshare.net, posted by ITRevolution, November 20, 2015, http://www.slideshare.net/ITRevolution/does15-bill-shinn-prove-it-the-last-mile-for-devops-in-regulated-organizations.
-
Helping large enterprise…: Ibid. Shinn notes, “One … Ibid. “That was fine … Ibid.
-
He explains, “In …: Ibid.
-
Page 343: Shinn states that …: Ibid.
-
Shinn continues, “With…: Ibid.
-
That requires deriving …: Ibid.
-
Shinn continues, “How …: Ibid.
-
Shinn gives an…: Ibid.
-
To helps solve…: James DeLuccia, Jeff Gallimore, Gene Kim, and Byron Miller, DevOps Audit Defense Toolkit (Portland, OR: IT Revolution, 2015), http://itrevolution.com/devops-and-auditors-the-devops-audit-defense-toolkit.
-
Page 344: She made the…: Mary Smith (a pseudonym), personal correspondence with Gene Kim, 2013
-
She observed: … Ibid., 2014.
-
Page 349: As Jesse Robbins…: “Hacking Culture at VelocityConf,” Slideshare. net, posted by Jesse Robbins, June 28, 2012, http://www.slideshare.net/jesserobbins/hacking-culture-at-velocityconf.
-
Page 353: The Lean movement started…: Ries, The Lean Startup.
-
Page 354: A key principal…: Kent Beck et al., “Twelve Principles of Agile Software,” AgileManifesto.org, 2001, http://agilemanifesto.org/principles.html.
-
Page 355: Toyota Kata describes… Rother, Toyota Kata, Introduction.
-
His conclusion was…: Ibid..
-
Page 355: In 2011, Eric…: Ries, The Lean Startup.
-
Page 358: In the Phoenix…: Kim, Behr, and Spafford, The Phoenix Project, 365.
-
Page 360: Myth 1: “Human…: Denis Besnard and Erik Hollnagel, Some Myths about Industrial Safety(Paris, Centre De Recherche Sur Les Risques Et Les Crises Mines, 2012), 3, http://gswong.com/?wpfb_dl=31.
-
Myth 2: “Systems…: Ibid., 4.
-
Myth 3: “Safety…: Ibid., 6.
-
Myth 4: “Accident…: Ibid., 8.
-
Myth 5: “Accident…: Ibid., 9.
-
Myth 6: Safety…: Ibid., 11.
-
Rather, when the…: John Shook, “Five Missing Pieces in Your Standardized Work (Part 3 of 3),” Lean.org, October 27, 2009, http://www.lean.org/shook/DisplayObject.cfm?o=1321.
-
Page 363: Time to resolve…: “Post Event Retrospective Part 1,” Rally Blogs, accessed May 31, 2016, https://www.rallydev.com/blog/engineering/post-event-retrospective-part-i.
-
Bethany Macri, from…: “Morgue: Helping Better Understand events by Building a Post Mortem Tool Bethany Macri,” Vimeo video, 33:34, posted by [email protected], October 18, 2013, http://vimeo.com/77206751.
-
Page 364: These discussions have…: Cockcroft, Hicks, and Orzell, “Lessons Netflix Learned.”
-
Since then, Chaos…: Ibid.