Damon Edwards
Incident Management
in the Age of DevOps and SRE
Salt Lake City DevOps
Nov 13, 2019
Assertion:
The ability to respond to and resolve incidents is the true
indicator of an organization’s operational capabilities
Assertion 2:
Everybody now works in “Operations"
What Is an Incident?
An unplanned disruption impacting
customers or business operations
What Is an Incident?
An unplanned disruption impacting
customers or business operations
Outages
Service Degradation
What Is an Incident?
An unplanned disruption impacting
customers or business operations
Outages
Service Degradation
Work interruption
Delay/Waiting
“Short-Notice” Requests
Board
Integrated
Board
Integrated
Responsive
Board
Integrated
Responsive
Everywhere
Board
Integrated
Responsive
Everywhere
Always
Board
Integrated
Responsive
Everywhere
Always
Board
Tech Org Execution
Integrated
Responsive
Everywhere
Always
Board
Tech Org Execution
Kubernetes
AWS GCP Azure
Docker
Consul
Terraform Istio
Zipkin
Envoy
Serverless
OpenShift
KafkaLamba
Prometheus
Containerd
Helm
Cloud Foundry
Linkerd
Etcd
CoreDNS
MongoDB
Redis
InfluxDB
Jaeger
gRPC
CRI-O
Cognito
Fargate
Cloud Functions
Cosmos
BigQuery Spark
Rook
Ceph
NGINXHAProxy
Open vSwitch
NSX Sensu
Vault
Aurora
Nomad
Kubernetes
AWS GCP Azure
Docker
Consul
Terraform Istio
Zipkin
Envoy
Serverless
OpenShift
KafkaLamba
Prometheus
Containerd
Helm
Cloud Foundry
Linkerd
Etcd
CoreDNS
MongoDB
Redis
InfluxDB
Jaeger
gRPC
CRI-O
Cognito
Fargate
Cloud Functions
Cosmos
BigQuery Spark
Rook
Ceph
NGINXHAProxy
Open vSwitch
NSX Sensu
Vault
Aurora
Nomad
Kubernetes
AWS GCP Azure
Docker
Consul
Terraform Istio
Zipkin
Envoy
Serverless
OpenShift
KafkaLamba
Prometheus
Containerd
Helm
Cloud Foundry
Linkerd
Etcd
CoreDNS
MongoDB
Redis
InfluxDB
Jaeger
gRPC
CRI-O
Cognito
Fargate
Cloud Functions
Cosmos
BigQuery Spark
Rook
Ceph
NGINXHAProxy
Open vSwitch
NSX Sensu
Vault
Aurora
Nomad
Kubernetes
AWS GCP Azure
Docker
Consul
Terraform Istio
Zipkin
Envoy
Serverless
OpenShift
KafkaLamba
Prometheus
Containerd
Helm
Cloud Foundry
Linkerd
Etcd
CoreDNS
MongoDB
Redis
InfluxDB
Jaeger
gRPC
CRI-O
Cognito
Fargate
Cloud Functions
Cosmos
BigQuery Spark
Rook
Ceph
NGINXHAProxy
Open vSwitch
NSX Sensu
Vault
Aurora
Nomad
SAIL/cornell.edu
Adrian Cockcroft
Developer
Developer
Developer
Developer
Developer
Old Release Still
Running
Release Plan
Release Plan
Release Plan
Release Plan
Deploy
Feature to
Production
Deploy
Feature to
Production
Deploy
Feature to
Production
Deploy
Feature to
Production
Bugs
Deploy
Feature to
Production
Immutable microservice deployment
scales, is faster with large teams and
diverse platform components
DockerCon EU 2014 Architecture enables speed.
Speed is the advantage.
The Three Ways (2013)
The Three Ways (2013) The Five Ideals (2019)
DEV
Go! Go! Go!DEV
Go! Go! Go!DEV …OPS?
0000
Go! Go! Go!DEV …OPS?
0000
Go! Go! Go!DEV …OPS?
Operations:
The Last Mile
1. SRE needs Service Level Objectives, with consequences
2. SREs have time to make tomorrow better than today
3. SRE teams have the ability to regulate their workload
Principles of SRE
1. SRE needs Service Level Objectives, with consequences
2. SREs have time to make tomorrow better than today
3. SRE teams have the ability to regulate their workload
Principles of SRE
1. SRE needs Service Level Objectives, with consequences
2. SREs have time to make tomorrow better than today
3. SRE teams have the ability to regulate their workload
Principles of SRE
DevOps + SRE
Product,
Not Project
Continuous
Delivery
Shift
Left
Error
Budgets
0
100
!!
Toil
Limits
Cloud
Native+ + + + +
DevOps + SRE
Product,
Not Project
Continuous
Delivery
Shift
Left
Error
Budgets
0
100
!!
Toil
Limits
Cloud
Native+ + + + +
Dev Ops
Cross-Functional Team
Cross-Functional Team
DevOps + SRE
Product,
Not Project
Continuous
Delivery
Shift
Left
Error
Budgets
0
100
!!
Toil
Limits
Cloud
Native+ + + + +
Dev Ops
Cross-Functional Team
Cross-Functional Team
DevOps + SRE
Product,
Not Project
Continuous
Delivery
Shift
Left
Error
Budgets
0
100
!!
Toil
Limits
Cloud
Native+ + + + +
“Value-Aligned” and Self-Regulating
Shared
Responsibility
Model
Traditional ITSM
Traditional ITSM
ITIL
1989 - ?
Traditional ITSM
ITIL
1989 - ?
Traditional ITSM
Unintentionally Encourages Silos
ITIL
1989 - ?
Traditional ITSM
X X X XX X
Unintentionally Encourages Silos
ITIL
1989 - ?
Traditional ITSM
X X X XX X
Unintentionally Encourages Silos
Encourages command
& control management
ITIL
1989 - ?
Traditional ITSM
X X X XX X
Unintentionally Encourages Silos
Encourages command
& control management
ITIL
1989 - ?
Old Way
New Way
Old Way
New Way
+
REDeploy.io
There is no root cause.
(That’s just a political distinction)
REDeploy.io
Why?
Why?
Why?
Why?
Why?
There is no root cause.
(That’s just a political distinction)
REDeploy.io
Why?
Why?
Why?
Why?
Why?
There is no root cause.
(That’s just a political distinction)
Right,
Wrong,
Safety II,
and You.
REDeploy.io
Why?
Why?
Why?
Why?
Why?
There is no root cause.
(That’s just a political distinction)
Right,
Wrong,
Safety II,
and You.
Incidents = unplanned investments
REDeploy.io
You
Not
18Million
IT Ops
22.3Million
Developers
Col. John Boyd
OODA Loop
Monitoring
Spotting the knowns
Monitoring
Spotting the knowns
Observability
Interrogating the unknowns
Observability
Interrogating the unknowns
Observability
Interrogating the unknowns
Logging: The event
Observability
Interrogating the unknowns
Logging: The event
Metrics: Data points over time
Observability
Interrogating the unknowns
Logging: The event
Metrics: Data points over time
Tracing: Events in context of a single request
Observability
Interrogating the unknowns
Logging: The event
Metrics: Data points over time
Tracing: Events in context of a single request
Automated Governance
Objective automated attestation of
GRC controls
Automated Governance
Objective automated attestation of
GRC controls
Automated Governance
Objective automated attestation of
GRC controls
Monitoring
Observability
Governance
Everyone
Everyone
Everyone
Everyone
Incident Command
Mobilization, Coordination, Communication
Incident Command
Mobilization, Coordination, Communication
Incident Command System
(FEMA)
Incident Command
Mobilization, Coordination, Communication
Incident Command System
(FEMA)
Incident Command
Mobilization, Coordination, Communication
Incident Command System
(FEMA)
Incident Command
Mobilization, Coordination, Communication
Incident Command System
(FEMA)
Incident Command
Mobilization, Coordination, Communication
Incident Command System
(FEMA)
GitHub: PagerDuty/incident-response-docs
Ops = Platform Eng + SRE
Divide and conquer
Ops = Platform Eng + SRE
Divide and conquer
Ops Platform Eng + SRE
Divide and conquer
SRE: Expert Operators (distributed)
Platform Eng: Build and Operate Platform Services (centralized)
Ops Platform Eng + SRE
Divide and conquer
SRE: Expert Operators (distributed)
Platform Eng: Build and Operate Platform Services (centralized)
Ops Platform Eng + SRE
Divide and conquer
SRE: Expert Operators (distributed)
Platform Eng: Build and Operate Platform Services (centralized)
New Views on Escalations
Avoid… but swarm if you do
Support at
the edge
Swarm
Diagnose: Health checks, exploratory actions
Take Action!
Restore: Restart, repair actions, rollback
The Return of Runbooks
Awhile ago Not that long ago Now
The Return of Runbooks
Awhile ago Not that long ago Now
Runbooks
(Mostly Manual)
The Return of Runbooks
Awhile ago Not that long ago Now
Runbooks
(Mostly Manual) …
The Return of Runbooks
Awhile ago Not that long ago Now
Runbooks
(Mostly Manual)
Runbooks
(Automate!…How?)…
Thanks SRE!
Runbook Automation
Safe self-service access to the expert knowledge
you need to take action.
Runbook Automation
Safe self-service access to the expert knowledge
you need to take action.
Runbook Automation
Safe self-service access to the expert knowledge
you need to take action.
Runbook Automation
Safe self-service access to the expert knowledge
you need to take action.
Moving the bits is the easy part!
Runbook Automation
Safe self-service access to the expert knowledge
you need to take action.
Empower those closest to the action!
Runbook Automation
Safe self-service access to the expert knowledge
you need to take action.
Runbook Automation
Safe self-service access to the expert knowledge
you need to take action.
De-risk!
Runbook Automation
Safe self-service access to the expert knowledge
you need to take action.
Before Runbook Automation…
Before Runbook Automation…
3 options:
1. Decipher the wiki
Before Runbook Automation…
3 options:
1. Decipher the wiki
2.Ad-hoc tool/script usage
Before Runbook Automation…
3 options:
1. Decipher the wiki
2.Ad-hoc tool/script usage
3.ESCALATE!
Before Runbook Automation…
3 options:
…with Runbook Automation
Shorter Incidents. Fewer Escalations.
Before RBA
Shorter Incidents. Fewer Escalations.
Before RBA
With RBA
Shorter Incidents. Fewer Escalations.
With RBA
Shorter Incidents. Fewer Escalations.
Before RBA
Shorter Incidents. Fewer Escalations.
With RBA
Shorter Incidents. Fewer Escalations.
Solve Difficult Security & Compliance Problems
Before RBA
Solve Difficult Security & Compliance Problems
With RBA
Everything Through a SDLC
Promote
Runbooks as a Service
Incidents = unplanned investments …the ROI is up to you.
Recap!
Elevate the Human.
@damonedwards
damon@rundeck.com
Let’s talk…
Special thanks to

Incident Management in the Age of DevOps and SRE