logo

NJP

Best Practices for Multi Cloud Management

Import · Dec 09, 2020 · video

good afternoon everyone caresoft technology would like to welcome you to our servicenow webinar before we get started i would like to quickly go over just a few housekeeping items the audio portion of this webinar can be heard through your computer speakers or if you prefer you can listen in using the dial in option displayed on your screen please note all your lines have been muted to reduce any kind of background noise during this presentation if you have any questions throughout the webinar please use that q a pod you see on the left hand side of your screen we will do our best to answer at the end of the presentation or if not we'll make sure to follow up with you all offline just to tell you a little bit about carousel we are a trusted government i.t solutions provider delivering software and support solutions to federal state and local government agencies as well as education and health care caresoft maintains dedicated teams to support sales and marketing for all of its vendors including servicenow google f5 networks and adobe our contact information will be provided at the end of the presentation so please feel free to give us a call or send us an email at this time i'd like to introduce you to our speakers for today we have chris harrell he is id transformation executive with the federal and civilian team that cares at servicenow excuse me and eddie kemp he is the senior advisory solutions consultant with the federal civilian healthcare and financial team at servicenow team the floor it's all yours good morning and thanks for that brooke uh good morning to all and afternoon to some my name is chris harrell servicenow's ip x transformation executive so i specialize in all of our transformative solutions in i.t covering it operations management i t business management asset management devops and and others so access uh you know to i i guess i i cover all of our federal agencies and departments all across this great nation uh brought with me uh the cloud subject matter expert right here at servicenow uh working with cloud and software defined software we're uh for better than the last decade so i i i introduced eddie kemp by eddia please take a few moments to introduce yourself before we begin thanks chris i appreciate that i'm very happy to be here looking forward to working with you all today and learning a little bit more about the cloud offerings from service now specifically on how we can optimize your multi-cloud environments excellent and thank you for that so we've already begun and we've started kicking off with our introduction and opening that we just crossed the next we'll go into an icom overviewer or i t operations management you'll see us abbreviated occasionally with it om or itom and we'll talk about the key capabilities or the components and outcomes that come out of that around visibility health and optimization we may speak a little bit to how we deliver but from there we'll go directly into the use cases right what do we see in terms of what our customers are experiencing out there and what is an actual demonstration of what kind of things we're able to capture what kind of obstacles we're able to navigate around with our actual live environment so uh we'll wrap up with the q a at the very end we'll give a time check and from there any questions that you have uh please feel free to submit them then or as we go through occasionally add them to the chat or there'll be polling questions that will ask you to engage in as we go forward so with no further ado right let's begin to attack uh you know multi-cloud management best practices uh to begin optimizing how it operates in this world so that was an optimizing integration transfer that's right how your customers interact with your environment by boosting their ability to actually be agile and what we're seeing here is an example of our service catalog their ability to launch into an azure environment or red hat uh aws right there have able to have that same look and feel that they would experience in the normal uh or in their consumer marketplace right same kind of amazonish uh field that we continue to hear from our customers and those outcomes will continue to be right this effectively allows them to to move away from managing resources in silos give your customers the ability to launch directly from their environment the resources that they need on demand so what's the challenge here so what we understand is that data exists everywhere in your organization and as we talked about those three key pillars we always have to keep in mind how do we establish visibility how do we maintain our service health and then optimize those decisions so since these applications that our managed cloud our traditional infrastructure exists in several different areas or several different places across our enterprise in order to establish operational excellence right it becomes all about uh having one platform having all of those systems and services and silos inform one cmdb that delivers operational excellence and that excellence will then filter across all of the platform right enabling you to do key things with service management uh your service catalog ask that management when it's all reading from the same platform you're able to deliver that kind of excellence all across your ip landscape so for the three key areas right we talked about those pivotal uh pillars uh these are also the ways that gartner defines it operations management and these three key pillars are just as we continue to highlight right in order to deliver high performing services it's around establishing visibility like starting with an automated population of your cmdb that's aware of the service context being able to deliver service health even if it's in the cloud right and then that last part again right we're just hammering on that point how do you start to optimize cloud span so when we start with that far left piece right about visibility we understand that cmdb is the core right it's the foundation for every it business and it's the foundation of how the servicenow platform begins to start to grow exponentially in terms of the power and value that it delivers so with our cmdb at the core right we're able to address questions around vulnerabilities incidents changes so all of this is able to be tracked and kept in and understood in a real-time fashion so as you think about operating your service environment regardless of where it is you have real-time updates of what's actually happening in your environment to make decisions so as we bring in that information into our cmdb which is our core our foundation it's really important here to see that regardless of what your information is where it exists we have a near limitless set of native integrations our ability to bring and digest information from across your entire landscape right we've seen things with our clouds and cloud native groups here in the top sort of middle left quadrants to sec ops and mobile device management regardless of where you're in the now platform bring all of that in to enrich your cmdb so as you move as you optimize as you make decisions in the cloud you are now able to have a real-time understanding as everything moved and balanced around your cmtp so from there right in terms of establishing visibility we just take it a step further here so again regardless of where your information information is right we're able to establish infrastructure visibility so you understand where your web servers your databases your servers and where they exist but where servicenow starts to differentiate is our ability to then map that service so now you can see right regardless of if that's a cloud environment or not what are the actual dependencies on the core infrastructure or the key servers that we're using to run our environment and then right the last step that we do to continue to differentiate ourselves is as you start to spin up environments in the cloud how can you figure out how that actual service aligns to a business unit now we're able to reduce the noise and figure out which systems what actual applications servers softwares depend on functioning that service that helps us get the understanding of things like unit cost how do we actually figure out the impact of an outage right we're able to do this in an unprecedented fashion and it's automated all in establishing visibility so our customers typically are able to walk away with the full map of their environment what does it look like right this is around establishing visibility into their environment so whether or not it's an on-prem uh device or even something that's hosted into the cloud they have a full view of what that means right visibility across their entire operation of state so the reason that this is important the reason that we want to continue to hammer home this part is because this is the core so once you start thinking about digital transformation and how we start to move and figure out where our organization is going the first step is where are we today right so establishing that visibility across your entire state unlocks all of the power to understand what's our next best move and from there right we talked about it the key is to then have that service contacts to align what those services are where are they actually driving benefits how do we communicate what's going well in our environment and again right those will continue to drive our outcomes so here's our first big pillar in terms of establishing visibility so the next piece in terms of operations and how you operate your environment is to begin to have proactive management so we integrate again right with the near limitless set of out-of-the-box connectors for your monitoring solutions and here we're looking at one for example coming in from a cloud watch all of the alarms all of the snmp traps uh all come in and form your uh event management uh console it allows them to understand what's happening in your environment in real time and with our our service maps now you can attribute where those events or those problems occur all the way to the business unit that drastically improves your velocity and your alignment with the business and then the last part uh you know as uh before we get into our demonstration is just the overview of the the high level discussion of what the expectations were for cloud everyone expected the you know it to be the easy button right if we need to spin up something quick a really quick and femoral uh environment how do we do so you know maybe cloud is the best place to do so and what we found is that actually created a little bit of tension a little bit of struggle or questions throughout the organization right int the ops manager how to figure out how do we maintain the visibility and the health of this thing the cfo then had the question of how do we pay for this right and also secops right how do we make sure that we have the guardrails to continue to keep our arms around what we have and what we've found is that by delivering the servicenow platform all of these questions all of these environments are able to be effectively answered through our hybrid cloud or our agnostic cloud offering that we deliver so again right those three key areas are that that we do incredibly well with it operations that extends itself all the way to our edge right to our cloud is establishing visibility right one single cmdb with one data model that informs it that way we are always certain that throughout the platform everyone's looking at the latest and greatest uh most actionable information that they can use to move forward we're then able to to bind everything that we find across your environment with the ability to monitor its health right is it working is it effective is it needing your service up time and then last part right the the cloud how do we make sure that folks are able to optimize their cloud regardless of what environment that they use today so the next piece before we change gears and go into a live demonstration is it's just kind of a highlight of the use cases right so in terms of optimization what i tend to see a ton of and and eddie will sort of guide us through uh step by step or our you know cloud resources that require you to uh self-service right we want to try to continue to have folks uh serve themselves in terms of what they're looking for we can offer a tiered offering whether it's a small medium large or a silver bronze gold sort of package but how do we enable folks to start to serve themselves in terms of managing their cloud resources what kind of catalog can we start to generate generate that they can take advantage of immediately right service catalog is going to be a common theme that you continue to hear uh as folks think about digital information about how the box or cloud insights is able to move towards savings in terms of because you can't can i start brazilian what we do we're continuing to ask you know are the the tags can we leverage things that we've tagged in azure aws yes i need to get a step further and i actually allow you to uh self-tagging like again like identifying costs uh you know different advice nowadays i think this is a good time to ask our first polling question uh brooke if you wouldn't mind uh bringing that up as we transition off that first pulling question on the screen for you okay and uh eddie uh are you able to take over the screen let's try and do that right now here we go all right can everybody see looks great excellent are we going to wait for the end of the poll or do we want to go ahead and get started you know i'm seeing majority are saying hybrid leave a few votes for um azure aws and gcp but feel free to go ahead and jump in excellent excellent well thanks for the great overview chris thanks for brooks for having us here today and organizing this uh so now we can dive into some of the fun stuff what do these products look like and how do they address these high-level optimization use cases that were discussed uh previously by chris the first one we're going to tackle here is the self service management of cloud resources this is this is a frequent ask from our customers to be able to take more of a packaged approach to be able to bring in the compute network all the configuration necessary and put together infrastructures code and publish it in a a catalog for consumption by users developers so that we have consistency across those products quality and to be able to drive down that time to provision these resources so that they're enabling the velocity of business and the organization so we work across the major clouds we have amazon azure google ibm as well as vmware for on-premise instances and we support many different templating formats including terraform and the procedure is very simple i i'm leaving it here not that we're going to walk through the whole thing but that that it really is as simple as as identifying an item that's going to go in the catalog and then bringing in existing templates or creating your own and then associating those with the template and then create a provisioning and post provisioning policy we'll look into that just a little bit more here in just a minute but it really is that simple to be able to take an arm template associated with a catalog item item publish it and you can literally have new catalog items for your users to consume in a matter of minutes so here's what our demo looks like today this is a multi-tier stack with security services load balancing services databases auto scaling web tiers and i didn't have to know the intricacies of this infrastructure and able to in order to import this and build it for consumption within the service now environment so i think this is going to be a great example of how we can make these services more consumable right so with that i'm going to move over to the demo screen now if i'm logging in as a user this is the catalog view that i would have in this case we only have one catalog item and you can see here that this is a production word press stack it deploys into multiple availability zones it uses firewall load balancing and other constructs that help for resiliency availability and performance and all that is hidden under the cover so that all we need to know is how to come in here and launch this and provision this infrastructure so i'm going to show you just how easy it is to put in this order request now what's interesting here is when we think about catalog items we usually think about a service catalog where i can go in and request an item by going onto a website but this is also programmatically available so i can tie this directly into my jenkins ci cd pipeline with a rest api call and completely automate this in the background there's no human requirement necessary for this to be an integral part of my continuous integration and deployment initiatives okay so but for now we're going to do the old-fashioned way and open up this request form uh as you can see i'm able to populate a lot of the information necessary we'll see some more of that in the next screen here but i can make some very simple selections of who i am what group i want to assign this to i can do cost centers business centers i can link this with existing applications etc one nice thing here is that i can i start with leases on this so nothing runs in perpetuity i i can have different uh schedules associated with this if i'm a developer i may want to assign this to only operate between eight and five on weekdays if this is a production environment then i can set it to always on but this leasing enables me to maintain a level of governance where as the lease date approaches an automated workflow can be triggered to determine whether or not we're going to extend that lease or we're going to let that application stack go ahead and de-provision automatically okay so moving over to the provisioning part this is where we get into some more of the technical details now the neat thing here is from a governance perspective is i can pre-populate these and completely hide the ability of others to come in and change these specifications so a lot of my users may not know what uh what the virtual private data center identification is and so i may want to come in here pre-populate this and even remove this field from the the view of the consumer something with subnets and key names now i can give them the ability to go and select different sizes of virtual machines for their for their deployment a lot of options security options sizing options resiliency options i can come in here and start off with uh two web servers instead of one or i can just bring it down to simple one and let it let's automatically fail again diverse uh availability zone databases lots and lots of options here but as a user i can come in here and select these defaults and then just a matter of minutes i can click provision this uh this new environment and it does take a while so i'm gonna i'm gonna rather than watching the grass grow here we're gonna move over to a environment that i've already established this would be our end result a simple wordpress environment that uh we we can utilize internally this could be any any application again this is just a demonstration of the ability to have a multi-faceted this isn't just spinning up a virtual machine it's the networking it's the security groups it's the firewall policy it's everything that you need to build those secure multi-tier more complicated applications and then what we're going to see here is of the amazon dashboard and see that when we're starting here i've already provisioned a wordpress stack so this is the existing environment and then i have a mid server which is part of the discovery uh package for itt operations management visibility it's a little out of scope for today but it's running in that environment as well and what we're going to see is we're going to come back we're going to see the additional instances and capabilities being launched okay so i can come down here and look at things like our load balancers we have an existing load balancer and you can see we're already starting to get the automatic provisioning of the firewall load balancer the thing that's interesting here is that these components need to be constructed in a certain sequence you want to construct your auto scaling groups before you start setting up virtual machines you want to remove those from load balancers before you try and de-provision a load balancer so the system knows not only the correct order of operations to build those stacks but also the correct order of operations to pause or delete the provision that infrastructure so again i don't need to know a lot about auto scaling groups and and how all of these pieces work together that the auto scaling group is connected to a launch template and all these other things i i don't need to have that information and in fact i can take this same stack and deploy it in other environments like my vmware stack or my azure stack my azure environment and not have to worry too much about the details of the differences in those environments okay and we'll see here in just a minute that this additional these additional instances will start provisioning as the as the auto scaling group comes online so what i want to do now is take a quick look at what this looks like within our our management domain what kind of day two operations can i perform once i've done the provisioning of this environment okay this is our cloud provisioning and governance product provisioning is what i'm focusing on here a little bit but one of the things that to note is that i can assign quotas to organizations individuals so that i can track their spend in terms of uh the number of virtual machines that they have the number of amount of networking they have the total spend i don't have a lot of that data in this particular demo but but uh the idea there is we're going to talk about cost optimization from two different perspectives and within the provisioning and governance perspective it's really about those quotas of validating that there are financial resources available before we provision new resources so if the organization has run out of funds then they can either request more funds or they will not be able to continue doing new provisioning of resources all right so now going back to date two operations once i've built up this stack i can go in and do day two operations so let's see this is the one that's building sorry we want to go to one that is finished and once completed i have detailed information about the deployment including the url to access it when it was updated when my lease will end on that product and what's really interesting is i can temporarily pause the entire stack now this isn't an option that you would see if you go into the amazon console there's not a button that says this whole application infrastructure stack and put it on pause until i'm ready to work on it again you would have to go into all the individual components and pause the pause certain ones delete them rebuild them later et cetera et cetera so this is a very powerful capability you can modify the schedule the lease or you can completely provision or destroy that whole stack and the nice thing there is a nice cleanup because if you're going through this interface as opposed to the multiple pages within the amazon console with extensive knowledge on which parts were built and where be very easy for example to come in here and completely forget to de-provision the databases which could have a substantial cost implication at the end of the month if i'm not de-provisioning my database instances each time i'm de-provisioning a stack okay if there's anything else you want to look at i want to show you quickly what this looks like from an administrative perspective i mean how hard is this to create and deploy new applications it's actually quite simple so first thing we're going to do is we're going to have accounts in the various clouds and this allows us to understand uh what the components are so that whenever i'm trying to provision something i make sure that it it's assigned to one of our available availability zones and we run discovery on this on on a scheduled basis to validate uh our configuration management database or cmdb is up to date and correct with the uh the provisioning that's happening in this infrastructure okay so once i decide that i have um i have a need for a new application stack i can simply come in and create a new step but we're just going to take a look at what we have already created here and what is entailed in creating a a stack in this in this environment okay so uh it's actually very very simple what i started off with is a cloud an existing cloud template as you can see we have versioning of that template so again infrastructure is code if i roll out a new version of software um with a new template and it fails for any reason i can simply archive that and roll back to a known good state when i first looked at the available templates i downloaded this aws template from a a community catalog and there were several errors in it so once i got all those fixed then i came back and i published that as version two and archived the original version and then i can move back and start you know making adjustments enhancements to these in an incremental fashion the system automatically parses out the json or xml files and understands how to what variables are necessary and how to layout the forms all that was done automatically so we had information on that first form and here are all the variables that we gathered to deploy that that infrastructure one of them was just the name of that stack it's very easy to come in here change up default values or again we can hide those those options from the user so that they are uh not needing to know some of the intricacies but i can come in here and very easily change the default value that i want people to use for that that variable and uh and make it easier for the users or the developers to consume that infrastructure okay um then once i'm done with this i simply go and publish this into the catalog item and from the user perspective it is available for consumption all right so that's a lot of interesting ins and outs of our provisioning and governance model again the governance there being do you have the right to utilize this particular catalog item do you have money in your budget to load to launch these types of items and we're going to see here in a minute that we take a very different look at the financials whenever we move to our next use case so i'm going to take just a second here and go to the next use case and as you take that second i think this is a a good time for uh pulling question number three uh brooke excellent if we could pose that to the group have you governed access to the cloud today all right results have started to already come in with most folks fighting no official government i don't know some folks are saying they actually have policy driven guidelines today right maybe those are guardrails that they may want to port over to their new environment good thanks for that and thanks for also joining back to you eddie thanks thank you thank you so the second use case that we looked at that sec and circle and uh that chris introduced us to is really about driving files cost controls so a couple of interesting things about cloud costs we talk a lot about driving down costs but what we find as a rule is that it's really not about driving down costs it's really about controlling costs where do we direct the funds to best meet the goals of the organization we all have finite resources and so we want to make sure that we're allocating those the best way possible to achieve our our business and our mission outcomes and an interesting thing here is a lot of people talk about amazon and other cloud providers wanting to drive as much of that consumption as possible but they too want you to drive the consumption that's best for your organization they provide recommendations that we utilize in part as part of our analysis for uh for recommendations on cost controls because those who spend less but get more value tend to actually consume more so they want to see you get the most value out of those resources and so do we we want to make sure that you're getting them allocated to the right missions and using them efficiently to get the best outcomes okay so let's take a look at what does that look like within our infrastructure so this is a different product this is called cloud insights it's another product within the it optimization product line and as you can see from the dashboard we have a few different ways that we address cloud spend and how uh we can make recommendations uh to make sure that we're utilizing uh these in an efficient manner okay so the first one i want to look at is is the cloud span analytics this gives me lots of ways to slice and dice the environment we use a concept called service categories to normalize what we call compute network storage databases uh so that we don't confuse the terminology between the different cloud providers that we may be utilizing and then we can look at spending trends over time so if i see a piece of this pie i grow from seven percent to ten percent then i can i want to understand what's different in my environment what use cases are driving the the change in the composition of our service categories and i can also again monitor that over time why is my spend going up is it based off of new projects is it based off of success of projects is or is it is it simply inefficient use of resources so we can go to our monthly spend look at how our spend has varied from month to month and how we expect based on a consumption for our future expenditures to look and it looks like again we're we're growing our bill is that because we have new projects is that because projects are are wildly successful or is that because we need to get some better cost controls in place for this environment i'm going to go back to the home page here one of the ways that we do the cost controls is right sizing these environments a lot of organizations are still doing lift and shift to move their workloads from on-premise into cloud environments and when they do so what we're finding is that they're they're often over provisioning the same way that you would provision an on-premise server if you only buy it every 18 or 24 months you're going to get the most server that you can allocated to that resource and we're finding that that is transitioning over into these cloud environments so we have the ability to monitor this capacity memory utilization uh cpu utilization all the the key performance metrics of these systems and make recommendations on what is the best size for these workloads so we can simply go in here and see things like this particular application might be better service moving from an n-class machine to a c-class machine now you'll notice here things like the confidence level the confidence level is built out on several different criteria partly based off of the data that we received on this application the variability in the resource utilization uh whether or not we're recommending a simple upgrade within a product family or moving across uh product families within that that provider so uh we'll give you information about our confidence level and those particular uh recommendations and then you can simply take that that recommendation and and schedule it for provisioning you can have it go through your normal manual approval process or automatic approval but one of the reasons i'm bringing this up is that this is fully integrated into our incident change and event management system so this would register as a change and that change would nullif or augment our understanding of alerts and events coming into the system so it's part of that holistic platform and it's completely integrated into our change management system okay so you pick out an existing template that is a standard change and you can schedule that change to appear in maybe an off hour or during a change menu okay you can see here which items have been scheduled and more importantly which ones have been declined it's okay to come in here and say no i know that this particular system uh was correctly sized for this particular application and in fact i can look at maybe some higher risk systems that i'm not looking to uh to evaluate for changes and resources at this time and once you identify those then then you can get more fidelity on your new recommendations business hours is a very important one we talked about this briefly with the cloud provisioning and governance if it's part of a dev environment we may only want that running during certain hours of the day the demo data is missing from this particular capability so i apologize not being able to show you more but but it's very easy to create uh policies that look at how these uh resources are being utilized when they're being utilized and identify whether or not the change in the hours of operation for those devices will will significantly add to your bottom line okay so existing uh an example of a policy here is um we have we have different types you have manual automatic and report what type of action are we going to take based off of matching within these these policies so let's take a quick look at uh take a look at this rewards processing so rewards processing we've activated this policy and we are identifying recommendations for the specific application set now first thing we need to do is match that application set so we understand which items we are going to be uh targeting for that that recommended action and a a virtual machine can only be a part of one policy and that's for uh simplicity so that you don't have systems going on and off and and having changes based off of several different policies so uh you can modify the order of operations very similar to any type of access control list so that you get the closest match to your policy intended target and then once you've identified that you are looking for systems running on the rewards processing account and that it is part of the production environment then it will match all of those virtual machines come up over here and it will create a report on the utilization uh for this this policy so what this is going to do is it's going to look at how would the financials be impacted if we instigated this this particular business schedule for that particular application and that will provide a report on how much money can be saved if we ran that particular policy another policy might say that we are going to evaluate the uh this these credential are these criteria once we have a match on this environment variable which looks like user exceptions testing then we go ahead and take these scheduled actions that we've changed the schedule to eight to ten weekdays that we have a manual change applied and that we launched these particular workflows for those instances to make sure that they shut down and come back up properly okay so a very powerful tool here where i can identify what's happening in my environment and take automated or manual actions that drive down the unnecessary consumption of some of these resources okay a couple of other items here unassigned resources are very important to identify we want to make sure that all the resources have assigned resources not just from a billing perspective but for the health of the cmdb who do we contact if this has a problem who needs to be notified who needs to make the approvals on changes to policy so it's very important for us to look at what kinds of resources are lacking of the assignment variables and on-premise or legacy infrastructure this is actually one of the last things to get populated whenever you're talking about these new consumption models and the ability to scale very rapidly and operate in a a different paradigm we're going to need that information about who's who's responsible for this who has the authority to make changes or authorize changes and ultimately who owns these applications and can make these cost decisions okay all right lots of stuff here i understand we're not able to go into everything here uh but we have two more little sections we'll go through real fast unused machines is uh very similar to the right sizing but to a greater degree we're identifying that the load or key and metrics that we're obtaining from these indicate that these may be orphaned or no longer usable use any new systems so again we want to validate that that that these recommendations are correct and we have several different actions that we can take like automatically we can automatically turn off the machine we can create or we can delete the associated storage we're working on new actions such as archive that vm before you turn it off so that we have images available to bring that back if necessary so lots of different ways that we can go in here and clean up our environment from these unused resources and then finally we can do some insights on how different organizations within our operation are doing uh for example this is not the one i wanted right now to show the different groups are doing through the and cost of their their systems and so i apologize for not finding that at this moment okay so that's the cloud enterprise product again the idea here the distinction is that we're looking at historical data making recommendations on how to change that change the consumption model so that we can more effectively use our resources that's different than our cloud provisioning and governance which says do you have the available funds to launch these new applications that you're requesting okay all right and then we have one more section which is the policy and tagging compliance this is the new offering um so i do have some screen sets that i'll walk you through on this product very very exciting so what we find is that the tagging is more important to a lot of organizations they're utilizing that for billing for uh for understanding the relationships between cis a version of service mapping for for operations and support capabilities lots and lots of different use cases for for these tagging and unfortunately they don't usually have the tools to ensure that the tagging is compliant with the intentions of the organization i'll give you one example very quickly and that is what tags do you have within your environment we may have some tags that are uh you know using one tag and amazon in a different tag and after that means the same thing can we normalize those across all the environments do we have maybe a tag that is is simply a mistake a misspelled name or or keyword that is is popping up and and looks like a duplicate tag so the second thing that we're going to do is we're going to fix tagging within your inverse structure in a centralized place the tagging can be assigned in so many different places within the infrastructure within the code within the uh the the consoles of the different operating environments so we're bringing all that to one place to say are these matching our tagging governance rule sets and if not let's let's fix that from from one location okay and then one thing that's great about this is the tagging information can then be used more effectively across the entire i.t ecosystem we're seeing that across the line of business owners and and understanding the p ls associated with their applications security operations compliance and again but coming back to cost control we can make sure that the items are being tagged that's feeding into the cloud insights product as well as the provisioning and governance so it's a whole ecosystem of being able to make sure that we're running the right workloads the right way and that we have the visibility and governance to ensure efficient operations the way we do that is with these uh checks the policies we have two types one that can validate the uh the number of packs associated with a particular ci um if it has too few or too many tags there's lots of different use cases for ensuring that the the tags are within a certain range of of counts but more importantly i think is this idea of presence tag you know making sure that the business unit is identified making sure that the maybe the location the business service the costs group whatever is important for you to tag this is the opportunity to create a rule to validate that the unit number one has that tag and number more importantly is that tag correct i can look at amazon and make sure that everything in amazon has an amazon time right i can do similar things with ensuring that everything has a a business unit or or a financial responsibly financially responsible party associated with it so that we can ensure that all those tags are being propagated they're correct and they're usable by all those different subgroups i realize we're running short on time here so i will wrap up very quickly this gives us a health dashboard where we can see how many of those assets or cis are compliant partially compliant or non-compliant and then we also get some information about the tags themselves the governance of the tags you know how many of those are being used uh are we seeing duplicates um uh what are these tags that are only being used once or twice does that have any information does that provide any information for us for uh maybe changing the tag structures or maybe uh deprecating certain tags so lots of opportunity here for creation of rules in a single place to ensure not only that those tags out in your operations environments are correct but as they come back into the cmdb they're consistent and uh work well from both filling operations and security perspectives and that's all i have today we're going to open up for q a awesome thank you guys that was a fantastic presentation i appreciate that as well as all of our attendees uh we do have a few questions rolling in um so i'll spend the last few minutes of addressing those and chris eddie feel free to jump in first one coming in is is this solution fedramp yeah eddie i'll take the first step at that one go for it go for it yes yeah we we agree right uh yes uh the the entire servicenow platform in fact uh is fedramp uh certified uh we've met the the fedramp high requirements for all of our civilian agencies and also a dod i or impact level four for all of our uh dod entities as well so so yes that's a huge year thanks for that question great thank you and yeah we gotta we got two more it looks like um and i'll keep checking to make sure but second one says will any and every machine that i spin up be captured in the servicenow cm db uh that is the intent absolutely so we understand that we're moving into more of an ephemeral world that's where we're getting into technologies like service brass that can normalize the ephemeral and the non-ephemeral environments but yes we're definitely a cognizant of the mode 2 environment but you know we still need that historical information even if a instance only spins up for a short period of time if we're able to correlate that information back into our alerts and events and understand the that you know it was potentially a bad uh instance that there was something on the file system something of that nature that helps us understand and get closure of those issues faster absolutely we want to capture all that data from multiple sources and cross-reference it to get to root cause and problem resolution as soon as possible perfect thank you and we do have a third question um seems this is our last one do you have the ability to integrate with uh terraform absolutely absolutely so terraform is in high demand we're seeing a lot of call for it and yes we could pull in a terraform um template just as easily as we can an aws template or an azure arm template awesome thank you well again thank you chris and eddie for your presentation today we really appreciate it as well as everyone else for attending we hope this webinar has been helpful for you and your organization you took something valuable from this lesson today um if you have any further questions or you'd like to request more information please feel free to reach out i have a few polling questions here for you all um as well as contact information for evan morgan he supports servicenow here at carisof and he can help um answer any questions you have in regard today's subject or we can also um set you up with a demo with eddie chris or someone else on the servicenow side thank you again i'm hoping everyone has a fantastic day thanks everyone

View original source

https://www.youtube.com/watch?v=8Rx1ipMR3Cg