Aspire’s Aju Mathew on DevOps and Generative AI

Written By
James Maguire
James Maguire
Published: Jul 10, 2024
Updated: Sep 23, 2024
1 minute read

Transcription

hi I'm James Maguire and on today's video we're discussing the role of generative Ai and software development we'll be looking at Technologies like devops infrastructure is code and pipeline is code we'll also talk about vulnerability and security assessments which are crucial aspects of the development process to discuss that I'm joined by an industry expert with me is Azu Matthew vice president software engineering and Aspire systems as you very good to have you with us today thank you for having me here James and nice to be here all right we know that generative AI plays a large and growing role in software development specifically in terms of devops how does geni play a role in infrastructure is code well on the devops side um uh specifically on infrastructure as code perspective um devops resources can use uh generative a platforms to generate Scripts uh and these scripts could be for uh arm or terraform templates uh to basically automatically provision infrastructure like networking servers operating systems or storage in uh different supported programming languages both within the cloud or onr this would help in basically reducing the time to build I templates or infrastructure SC templates uh M what about pipeline as as code what's driving this development with generative AI from a pipeline as code perspective uh again devops users can use these platforms to generate build strips uh for build tools like uh namely bamboo Jenkins radle Maven Etc now uh generated build scripts would uh follow industry best practices um and that's how you know I would see you know pipeline is code being impacted using gen yeah vulnerability and security assessments are definitely a crucial aspect of the development process what advice do you give to companies on usage of gen in this sector there are um two potential areas uh where gen platforms can help in the vulnerability and security assessment um one is firstly uh uh is a preventive scenario where the backend API or the front-end code generated by the uh J uh platform already follows the best practices to avoid any vulnerability and security glitches all this can happen through prompt chaining with the right parameters so this is more of a preventive mechanism and from a reactive scenario which is the second scenario where current vulnerability and security assessment tools that we currently use both static and dynamic which um you know currently follows a template or rules based identification of issues would shift to a gen based detection mechanism so all the tool providers um in this space uh would be using jna so that's how uh we see both the preventive and U reactive scenarios panning out well I mean do you think these use cases whether it's pipeliners code or vulnerability security assessments are people using gen gen AI to do this now or is it still on the way and and and a futuristic concept um as far as a preventive scenario it is something that um is is still is current which basically means anything that you generate code with the right parameters it will be uh you know compliant uh basically there won't be any vulnerability or security glitches uh it again depends on how you uh instruct the platform to generate so it is something which is already existing whereas on the reactive side it it is still uh futuristic in the sense uh tool providers uh on the vulnerability and security assessment tools they need to start incorporating gen into their um uh tools so that they use gen instead of you know template or rules based well all right let's look to the future if you look in your crystal ball as you what is your sense of the future of generative AI in devops and security assessments yeah that's a interesting question and and to me uh in the future of devops I would probably expect uh devops users to be able to uh generate both um U especially the infrastructure as code um uh using inputs using um you know application deployment architecture documents as an input and um I would see generative AI going and parsing that document identifying the parameters needed to generate infrastructure code so that is something that we would look forward to um you know in the coming years because U instead of keying in all the parameters data it just reads a deployment architecture document as part of the life cycle and then you know takes it as an input to generate infrastru scope so that's our IAC standpoint similarly um from a pipeliner code standpoint um you know the future that I would see is that uh generative a platforms using the application architecture or design document as the input and and the input would be in terms of you know what programming language am I using uh you know what are the modules and libraries and you know Associated dependencies and using all of this as input basically generating pipeliners code pretty Advanced but you know but I'm sure it's it's possible the near term and if you go into uh future of security assessments um I would expect more of a preventive mechanism because just like devops we would have already heard of Dev secops right so I anticipating concepts of Dev secops getting implemented using gen platforms with basically endtoend security incorporation um you know during application design development test build and infrastructure provisioning so it's basically endtoend uh security implementation uh using gen chips the the devs opsis I think particularly interesting do you think that's right around the corner or is it is it a couple years away see I mean Dev secops already exists as a best practice nowadays it's just a question of using the dev secops concept when you um you know U use J platforms to generate um you know the the stuff that you want in the different sdlc faes right right from design to infrastructure prising so it it will take time for it to uh Reach This stage but the concept of dep secops exist it's just incorporating that into J platforms for the uh through the stlc cycle all right well it's it's going to be a fascinating area to watch as you I really appreciate you sharing expertise today uh thank you very much thank you James

This transcript was generated automatically from the video's captions and may contain errors.

eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Watch my extended interview with Aju Mathew,VP of Software Engineering for Aspire Systems, to learn how AI can support Pipeline as Code processes, security assessments, and more.

James Maguire

James Maguire has been reporting on emerging technology for more than 15 years. He has won two ASBPE Awards of Excellence for in-depth feature articles about cloud computing and artificial intelligence. He has covered the gamut of enterprise and consumer technology, and regularly communicates with leading IT newsmakers, vendors and analysts.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.