Podcasts about aws marketplace

  • 94PODCASTS
  • 221EPISODES
  • 34mAVG DURATION
  • 1EPISODE EVERY OTHER WEEK
  • Aug 1, 2026LATEST

POPULARITY

20192020202120222023202420252026


Best podcasts about aws marketplace

Latest podcast episodes about aws marketplace

Ultimate Guide to Partnering™
306 – Why Your AWS Marketplace Strategy Could Become a Single Point of Failure

Ultimate Guide to Partnering™

Play Episode Listen Later Aug 1, 2026 30:56


Don’t get left behind on AWS! Don’t get left behind on AWS! Subscribe to our Newsletter: https://theultimatepartner.com/ebook-subscribe/ Check Out UPX: https://theultimatepartner.com/experience/ In this episode, we go deep inside the AWS Marketplace with Louise Strandoo, who spent nearly a decade building AWS’s marketplace business from the ground up and now leads partner development for AWS’s data, analytics, and storage practice. Louise unpacks COST, the six-pillar framework her team built by studying what actually separates hypergrowth startups and billion-dollar sellers from partners who treat marketplace as a side project. We break down why operational excellence has to be in place before you ever enable your sales team, why executive sponsorship from the top of the organization is what keeps a marketplace strategy from collapsing into a single point of failure, and why product-led growth is no longer optional now that buyers, and increasingly AI agents, expect to try, buy, and deploy software without waiting on a human to close the loop, https://www.youtube.com/watch?v=pwyAP7yVy3I Key Takeaways Success on AWS Marketplace requires a comprehensive framework like COST, not just a simple checklist of tasks. Your product must be something customers actually want to buy, not a subpar offering used merely to test the waters. Operational excellence is required to ensure your marketplace motion has the sustainability to scale globally. Product-Led Growth (PLG) is essential for enabling frictionless procurement, especially as buyers shift toward agent-driven AI solutions. Executive sponsorship is critical; building a strategy without leadership buy-in will prevent it from gaining real traction. Sales alignment ensures reps are appropriately compensated and friction is removed, preventing them from avoiding marketplace transactions. If you're ready to lead through change, elevate your business, and achieve extraordinary outcomes through the power of partnership—this is your community. At Ultimate Partner® we want leaders like you to join us in the Ultimate Partner Experience – where transformation begins. Key Tags AWS Marketplace framework, COST methodology, product-led growth, agentic procurement, hyperscaler ecosystem, operational excellence, revenue friction, private offers, co-sell acceleration, strategic collaboration agreements, resilient architecture, cloud commitments, organizational transformation Key Tags Louise Strandoo Audio Episode [00:00:00] Louise Strandoo: Salespeople, rightly so. They don’t wanna introduce something that’s going to add a complexity to the deal. They’re like, why would AWS wanna be involved? [00:00:11] Vince Menzione: You can feel it happening. The ecosystem is shifting beneath us, the way Hyperscalers are partnering, how AI’s remaking the channel and what it means to win in 2026. [00:00:22] Louise Strandoo: Welcome to the Ultimate Partner Podcast. I’m Vince Menzi. Own [00:00:26] Vince Menzione: your host. And each week I sit down with leaders at the intersection of technology, partnerships and outcomes. The voices shaping how ecosystems actually work. We talk about what’s real, what’s changing, and what it takes to lead in this era where the partner channel isn’t just part of the strategy. [00:00:45] Vince Menzione: It is the strategy because being in the room changes everything. Let’s start. [00:00:53] Louise Strandoo: And Louise Strand, come on out. Come on up. Uh, our first, our first [00:00:59] Vince Menzione: Amazon executive at, at this session. Not our first ever, but our first at this session. [00:01:06] Louise Strandoo: Happy to be [00:01:07] Vince Menzione: thrilled to have you. I, why don’t we sit down on an, um, I’ll have you sit here and, you know, you get, take one of the ultimate partner pillows with you since you’re a first assignment attend. [00:01:15] Louise Strandoo: Wonderful. [00:01:16] Vince Menzione: Uh, [00:01:16] Louise Strandoo: good [00:01:17] Vince Menzione: to hear. So great to have you. I thought maybe we’d start, maybe, uh, with you, uh, explaining your role. Then we can start talking about costs, which is the subject is like near and dear, and we’ll talk about that, about what that is. But I want to keep people on their pins of their seats right now. [00:01:33] Vince Menzione: So tell us, tell us more about you and your role and your journey at AWS. [00:01:37] Louise Strandoo: Yeah, well thanks for having me. Good to see everybody in the room. Um, so my name’s Louise. I have spent the better part of the last nine and a half years at AWS and I spent almost that whole time, probably around eight years. In AWS Marketplaces business Development organization, um, I joined to help startups figure out how to scale their business on the marketplace. [00:02:00] Louise Strandoo: And from there, I grew into a number of different roles, helped ISVs figure out how to scale their marketplace business of all sizes. Um, I worked with some of our top sellers on the marketplace, figure out how to really scale their revenue through the marketplace. Today I am actually the lead of the data analytics and storage partner development team. [00:02:20] Louise Strandoo: Nice. Within the US Tech partnerships organization. So it’s been a really cool transition to go from like all marketplace focused. And throughout that time, marketplace kind of became the center of partnerships. Yep. Within our partner program. Um, so now I manage PDMs and partners and we still talk a lot about marketplace. [00:02:40] Louise Strandoo: Also everything else that we do as a partner. So it’s, um, it’s been a fun journey. [00:02:45] Vince Menzione: And we were talking about this earlier, like you started with Marketplace and then moved out where all the other organizations started from partnership and moved into marketplace. Mm-hmm. Almost the other up. And you have built a framework costs [00:02:59] Louise Strandoo: mm-hmm. [00:03:00] Vince Menzione: Characteristics of successful sellers. And I have a set of operating principles about successful partnering. So I’m really intrigued about this conversation. I was hoping you could walk us through it, like what are these characteristics and where do most partners fall short in terms of characteristics? [00:03:18] Louise Strandoo: Yeah, so, um, like all really good things, cost was an effort that I built alongside a bunch of other really smart people. And we started to have this conversation about what does, uh, you know, what does success look like? We we’re focused in the beginning, in my marketplace journey on getting. Partners to sell on the marketplace, getting them to list and adopt the features. [00:03:41] Louise Strandoo: And of course they’re like, why would we do this? And we’re like, that’s a great question. Let’s figure out like really what the why of this whole thing is. And as we started to get partners who were startups and some of our really large partners activated, we started to see all kinds of value and how marketplace was helping co-sell and all this good stuff. [00:03:59] Louise Strandoo: And we needed to figure out like how do we identify what is like the lightning in the bottle? So we looked across some of the most, uh, hypergrowth companies on the marketplace. Mm-hmm. Some of those startups that had really propelled into major success stories. And then some of those like really scaled enterprise sellers, the one [00:04:17] Vince Menzione: that got to a billion dollars. [00:04:18] Louise Strandoo: Exactly. The market, our billion dollar market market. Billion dollar sellers. Right? Yep. And we looked at what are the common characteristics that all of those partners embody. Yes. And how do we kind of. Define a framework that is not a checklist because a lot of us were doing that at the time. Here’s all the things that you should do to make it work well. [00:04:34] Louise Strandoo: It doesn’t really work from partner to partner. Everyone has a unique go-to market strategy. Yeah, so we developed costs to kind of be this overarching tool that partners can use to say, do we have the right kind of fundamental approach to how we’re going to market with AWS and how we’re thinking about the marketplace. [00:04:51] Louise Strandoo: Do we have the right tools to like bring our overall go-to-market strategy to A AWS and to the marketplace so we’re not doing two separate things. That was sort of the genesis of the idea. Makes [00:05:02] Vince Menzione: a lot of sense. [00:05:04] Louise Strandoo: So, um, the characteristics, there’s six of ’em. I won’t go into detail about every single one. [00:05:11] Louise Strandoo: Oh, [00:05:11] come [00:05:11] Vince Menzione: on. We’ll do that one. Yeah. We have some people in the room that are gonna be intrigued by this. Go ahead. [00:05:16] Louise Strandoo: So, um, the first pillar is. Partnership with AWS, you can’t do marketplace without figuring out what, what’s your overall partner strategy, right? So how are you using the partner programs to drive differentiation in your business? [00:05:30] Louise Strandoo: Yep. How are you using our funding programs to elevate the parts of your business that you really wanna accelerate? Um, and how are you thinking about your partner strategy with AWS overall? [00:05:40] Vince Menzione: Interesting. [00:05:41] Louise Strandoo: The second one is, uh, selection on AWS marketplace. [00:05:44] Vince Menzione: Product selection. [00:05:45] Louise Strandoo: That’s right. [00:05:45] Vince Menzione: Yeah. [00:05:46] Louise Strandoo: You gotta have a product on the marketplace that your customers wanna buy. [00:05:49] Louise Strandoo: I think the biggest thing that partners have done wrong over the years is they think, let’s do crawl, walk, run. We’re gonna put something up there that we’re not, you know, really excited about, but we’ll see how it does and then we’ll try to invest from there. [00:06:03] Vince Menzione: Mm-hmm. [00:06:04] Louise Strandoo: If you put something out there that nobody knows how to sell, then that you’re not excited about, your customers aren’t probably excited about it either. [00:06:09] Louise Strandoo: There’s no reason it’s gonna do well in the marketplace. [00:06:10] Vince Menzione: Yeah. It makes no sense to me. [00:06:12] Louise Strandoo: Yep. So you gotta have something good. You gotta have your marquee product, and then you wanna use features that are gonna help buyers actually access that product in a way that’s frictionless. Yeah. The third one is operational excellence. [00:06:25] Louise Strandoo: So that’s looking at how are you structuring your organization and investing in all the right processes that you need to scale the business. Reporting at a global scale, understanding how to recognize revenue and thinking about all of the in-between moments of. Being on the marketplace, creating an offer, how does your sales team gonna get in touch with you when you need to send that offer out? [00:06:47] Louise Strandoo: And how are you making sure that an alliance person isn’t trying to find an outlet in a random corner of an airport to send a private offer to a customer? All of that structural stuff to make the, the motion scale. [00:07:00] Vince Menzione: So we’re talking product led growth versus. One off or [00:07:04] Louise Strandoo: all of it? All of it. Okay. No matter what kind of partner you are, you have to have operational excellence. [00:07:08] Louise Strandoo: Yeah. To make sure that your marketplace and your partnership motion has sustainability and scale. The next two, I’ll kind of go through fast. There is, yeah. Um, partner commitment to marketplace revenue. So what do you really want Drive from a revenue perspective, right. How do you get your leaders bought in on that, and how do you set a goal that dictates what you’re doing? [00:07:28] Louise Strandoo: And then how do you define sales alignment? From a structural perspective to say we’re gonna remove friction that could get in the way of the field selling this thing. We’re gonna remove things that are, um, negating reps from wanting to go through marketplace because it’s impacting their comp. Yeah. Or it’s really hard. [00:07:46] Louise Strandoo: All of that kind of structural stuff goes into the sales alliance. [00:07:49] Vince Menzione: So there’s, yeah. I wanted to take this apart a little bit too, if you don’t mind. No [00:07:52] Louise Strandoo: problem. [00:07:53] Vince Menzione: Because I think about this a lot. So when you start talking about an organization, you’re talking about what this, we’ll call it an ISV Sure. Or an si, but. [00:08:00] Vince Menzione: You know, ISPs primarily is where it all started. They need to get their internal operational excellence. Right, exactly. Which means their, their ops piece. Yep. And their sales execution. They’re gonna to market all those things. The sales alignment side. Is that their sales teams [00:08:18] Louise Strandoo: correct. [00:08:19] Vince Menzione: Are compensated properly so that they don’t go around the systems. [00:08:22] Vince Menzione: Exactly right. They’re aligned. They’re aligned to go drive the right results. [00:08:25] Louise Strandoo: Exactly. [00:08:26] Vince Menzione: Because they’ve made commitments as well. [00:08:28] Louise Strandoo: Yeah. [00:08:28] Vince Menzione: Yeah. [00:08:29] Louise Strandoo: And I always talk about marketplace, like it is transformation. It’s different. It’s not what you’re doing today. [00:08:35] Vince Menzione: That’s right. [00:08:35] Louise Strandoo: Salespeople, rightly so. They don’t wanna introduce something that’s gonna add a complexity to the deal. [00:08:43] Louise Strandoo: They’re like, why would AWS wanna be involved? Stay away. So if that is already there and then on top of that Mm, they don’t get paid as much when they go direct. [00:08:53] Vince Menzione: Right? Right. [00:08:54] Louise Strandoo: They’re not gonna go through the market nice. [00:08:55] Vince Menzione: No, they’re not. [00:08:55] Louise Strandoo: They’re not gonna bring anything to you and the partnership team saying like, Hey, we really wanna figure out how to make this engine work with AWS So we have to do as much as we can to remove that friction from the experience. [00:09:06] Vince Menzione: So, you know, you mentioned private offers, which made me think about like product-led growth versus private offers. ’cause it’s, it feels like marketplace from the beginning. It’s changed. It [00:09:15] Louise Strandoo: has, [00:09:16] Vince Menzione: you’ve been doing this for a number of years. You were first to market with a marketplace. There was, I’ll call a lot of friction because there was channels and other, other routes to market direct selling. [00:09:27] Vince Menzione: Tell us, take us through some of those experiences. Yeah, yeah. Like what was that like? And then obviously you built cos because you had a lot of field engagement with these organizations trying to get them to go do it the right way. [00:09:38] Louise Strandoo: Right? [00:09:39] Vince Menzione: Yeah. [00:09:39] Louise Strandoo: So it’s interesting actually, when we built the marketplace. [00:09:42] Louise Strandoo: It was completely like a product-led growth motion, as in let’s just figure out a way to let AWS customers find amis in the marketplace. Developers are gonna go get it, and they’re just gonna buy it without any additional push from the field or like co-sell. That doesn’t need to happen. Then we heard from customers, Hey, this is great. [00:10:02] Louise Strandoo: But what we really want is also to be able to buy bigger contracts. We wanna customize our contracts, we wanna negotiate price when we’re buying this on behalf of, you know, large organizations. We’re not just buying what’s on the shelf. We need something more custom. So we introduced this concept of private offers to make sure that we could bring all of that customization into the process. [00:10:23] Louise Strandoo: And then we heard from customers saying, uh, we want to purchase from our preferred channel partners. We really wanna make sure that we’re, you know, not losing that source of, um, engagement with our really critical partners. So we had to figure out, hey, how can we make it so that we’re not competing with the channel? [00:10:41] Louise Strandoo: ’cause we’re not really a channel at all. Right. So we had to go and build our platform that allowed for channel partners to sell through the marketplace and augment that private offer piece to say, Hey, if you want, you can have a channel partner resell your product through the marketplace. So today we kind of see all of those as just different routes to market and different ISVs are gonna embrace different routes to market. [00:11:04] Louise Strandoo: First, the really important thing about costs is that it’s. Pushing partners to think about bringing their go to market strategy that works outside of the partnership to the marketplace. Mm-hmm. So if you’re an ISV that doesn’t sell with channel today, don’t start with channel partners on the marketplace. [00:11:21] Louise Strandoo: Right. If you don’t do product-led growth today, probably figure that out before you start doing it on the marketplace. Yeah. But if you’re doing those things, if you’re not doing those things, you should look at why not, and could we be doing those things and then we have the ways to bring it into your strategy with AWS marketplace. [00:11:38] Vince Menzione: So what separates the partners who kind of build this flywheel of success that you describe from those who treat it maybe as a side project? And do you, do you see less and less of that today too? I wanna, I wanna ask you. [00:11:50] Louise Strandoo: No, I think, um, the more mature the marketplace gets [00:11:57] Vince Menzione: Yeah. [00:11:58] Louise Strandoo: The more obvious some of the, uh, characteristics of success become and the more important. [00:12:06] Louise Strandoo: Embodying that framework becomes for partners as they grow to become the next billion dollar seller, right? And become the next a hundred million dollar seller. Um, I think a couple things come to mind for me. The first thing is that like at AWS overall, we talk a lot about like resilient architecture. We talk a lot about what does it look like to drive successful transformation. [00:12:29] Louise Strandoo: All of that has to happen in the partnership. Partners that have really strong marketplace motions with AWS, they do not have single points of failure. They are not expecting an alliance lead to manage everything and then have the business collapse if they leave. [00:12:46] Vince Menzione: Yeah. [00:12:46] Louise Strandoo: They figure out how to delegate and get buy-in from leadership so that they have multiple folks invested in the strategy for multiple angles so that there’s scalability and sustainability. [00:12:58] Louise Strandoo: Without that. You could do all the things right with costs and if there’s res, if there’s no resiliency, if there’s, if there’s a single point of failure, it doesn’t scale and it doesn’t last. [00:13:09] Vince Menzione: It’s so funny ’cause you haven’t seen my seven principles of, of successful partnering, but we talk about growth mindset, we talk about executive commitment and then clarity on your vision and what you’re hoping to achieve. [00:13:21] Louise Strandoo: Yeah. [00:13:22] Vince Menzione: Like that’s your internal victory. You’ve gotta get those things right. That’s exactly what you just said. A hundred [00:13:26] percent. [00:13:26] Louise Strandoo: And you can’t, you, you know, like if you don’t have that executive sponsorship, [00:13:30] Vince Menzione: yeah, [00:13:32] Louise Strandoo: great. You’ve done the cost framework, but where are you gonna go with it? [00:13:35] Vince Menzione: And it’s not just the sponsorship, it’s. [00:13:38] Vince Menzione: Up in, from the top of the organization all the way down to the selling floor. Completely. Right? [00:13:42] Louise Strandoo: Completely. [00:13:42] Vince Menzione: Everybody has to be aligned. Resources, investments all need to be aligned to this. Mm-hmm. [00:13:47] Louise Strandoo: Mm-hmm. [00:13:47] Vince Menzione: We’re speaking the same language earlier. A hundred percent. I love it. I love it. I love it. Um, so what does, we talked about product-led growth, but I want to maybe jump in here a little bit more. [00:13:58] Vince Menzione: Because I think it’s, it’s becoming more prevalent today, isn’t it? Yeah. It’s like, you know, we talked about private offer. It was really private offers, at least my perspective was a few years ago, I wanna buy something from you. Oh, you have a cloud commitment. I can access the cloud commitment. [00:14:13] Louise Strandoo: Yeah. [00:14:14] Vince Menzione: And so it was always the private offer thing that was going on behind the scenes, which required a lot of internal resources to go drive. [00:14:19] Louise Strandoo: Yep. [00:14:20] Vince Menzione: Let’s talk about product led growth. ’cause that becomes a fly more of a flywheel that’s automated Yeah. And allows you to sell while you’re sleeping kind of thing, you know? [00:14:28] Louise Strandoo: Totally. [00:14:29] Vince Menzione: Yeah. [00:14:30] Louise Strandoo: So I think, um, we have heard a lot from customers saying, okay, when we really need to negotiate and we need something custom, we wanna be able to do that. [00:14:40] Louise Strandoo: But we also wanna be able to purchase things quickly. We don’t wanna have to go out to dinner every time we need to upgrade, uh, like our licenses and get a new contract. We wanna be able to experiment and pick the things that resonate best with the line of business users that are, you know, increasingly taking some of that buying power. [00:14:59] Louise Strandoo: And I think especially now that we’re entering into, you know, the unprecedented, unprecedented times, it’s everything is AI like. There is more, um, pressure than ever to have users quickly figure out, does something add value to me and my business right now? And if it does, then I’m gonna keep using it, and if it doesn’t, I’m gonna go to the next thing. [00:15:22] Guest: Right. [00:15:22] Louise Strandoo: Product led growth is really about eliminating some of that I would say. Paperwork at the start of the process and putting the power in the hands of the user to say, can this product solve your challenge? And as more and more buyers are looking at Agen solutions, they wanna be able to try something, see if it works, and then quickly buy it without having to go through a whole bunch of steps because they have work that needs to be done right now. [00:15:54] Louise Strandoo: So the marketplace, that was our roots, like we started with this PLG motion. So we have all of that foundation to do it, and we’ve spent a lot of time over the last two, three years, like really investing in that from our engineering and roadmap perspective to build a whole bunch of features and capabilities that support product-led growth. [00:16:11] Louise Strandoo: We have things like free trials request, demo request, a private offer if you want to. Um, we introduced something, you know, last year that was an express private offer experience. Hey, you know, you want custom pricing. Request it and we’re gonna give it to you right away because the vendor has populated rate cards. [00:16:26] Louise Strandoo: Right? So all of those things I think are really important right now to say, yeah, when your customers like, wanna get going, now let’s stop. Putting barriers in the way and let your product actually show its value immediately. [00:16:38] Vince Menzione: And you were actually putting buttons or making buttons available Yeah. For people’s websites. [00:16:42] Vince Menzione: Exactly. So they could just say, click here and [00:16:43] Louise Strandoo: buy. Absolutely. We buy with a Ws. You can click from your own website, your own marketing pages to route them to the marketplace. If that’s the preferred way to transact, [00:16:50] Vince Menzione: yeah, why not? [00:16:51] Louise Strandoo: Yeah. [00:16:52] Vince Menzione: So you mentioned ai. We talked a little bit, I call it the tectonic shifts. [00:16:56] Vince Menzione: We, we’ve seen this incredible transformation happening so fast. And now we’re talking about agents. Right. And, uh, John Yo was over here from, uh, earlier from Sugar talking about like, what happens if the buyer is an agent? [00:17:08] Louise Strandoo: Totally. [00:17:09] Vince Menzione: Let’s talk about that. [00:17:10] Louise Strandoo: Yeah. I mean, I think that PLG and like is the right thing to enable a agentic procurement. [00:17:18] Vince Menzione: Yeah. [00:17:19] Louise Strandoo: If, um, you know, like in the, uh. 2019 when private offers were like, that was the big boom. We were like getting people to sign up on the marketplace. All we were focused on was private offers. So many sellers would have products on the marketplace where you’d click and purchase it and it would just say, thanks for buying, and it’d be like, we’ll get in touch with you and like a 24 hours and then we’ll figure it out. [00:17:42] Louise Strandoo: No worries. Thanks for buying. If that doesn’t work. If you’re an agent, it doesn’t work. An agent would be like, okay, this is like a dead end, right? Yeah. Agents are gonna look for products that they can purchase and begin using instantaneously. So yeah, product-led growth is like a really good, um, strategy that ISVs can use to future proof their business and make sure that they’re not just catering to an evolved. [00:18:06] Louise Strandoo: You know, procurement persona who maybe is looking for that faster transaction, but also preparing for that agent persona. Yeah. That is gonna be helping make software procurement scale. [00:18:17] Vince Menzione: So what do the partners in the room need to do to rethink how they think about this? [00:18:22] Louise Strandoo: I think there’s a couple things. I think you know, number one, you can look at the cost framework and start to use it as a jumping off point to evaluate your business. [00:18:31] Louise Strandoo: You can look through a bunch of resources that we’ve put out around costs, and one of the first blogs that I wrote has a Buzzfeed style quiz. You can go through and be like, where are we at? And if you realize after you run through that exercise that you’re farther away from where you wanna be in terms of partnering with AWS, it’s a really good dump like starting point to be like, great, here’s the challenges. [00:18:56] Louise Strandoo: But the biggest message I would relay to the partners is. Do not wait to try to go build this and then bring it to your executives and say, look what I built. It’s not gonna go anywhere. You need to go and use that as the cry to your leadership team. Like escalate. Now here’s the opportunity that we have with AWS. [00:19:17] Louise Strandoo: Let’s look at all of the awesome studies that we and our partners have put out over the years. Look at your competitors that are in the marketplace, your competitors that are partnering with AWS, and start there by saying, we’re. Behind or we’re missing in these areas. We could be doing, you know this, to make our product more a ag agentic ready. [00:19:37] Louise Strandoo: We could be doing more in marketplace to ensure that we’re capitalizing on the private offer business, and we need to figure out how we’re gonna drive commitment now so we can go and build this if you try to build it. Then show the value later. It’s gonna be really hard to then be pushing that boulder up the hill. [00:19:55] Louise Strandoo: So the more that you can lean into getting the sponsorship early on, you’re gonna have a much easier time then navigating, you know, all the hard work that comes with partnership co-sell, um, and, and everything kind of fun that we get to do once we get to go to market with our partners. [00:20:10] Vince Menzione: Do you have one piece of advice for each one of the. [00:20:13] Vince Menzione: Conditions or characteristics for, for, for this group to follow or [00:20:17] Louise Strandoo: think about? I think that, um, the, we didn’t talk about the last one, which is a good one to end on, which is enablement. [00:20:22] Vince Menzione: Yes. [00:20:23] Louise Strandoo: Enablement starts with like most of the time, ISVs in particular, and this, it goes for channel partners as well. [00:20:30] Louise Strandoo: They’re like, we gotta enable the field go and enable all the salespeople why they should do all this stuff. You have to do these things like in some sequence though. So if you go and enable the field, everybody do marketplace and they’re like, how? Where do we go, right? Do we send you the leads? Are we slacking you? [00:20:47] Louise Strandoo: Like are we emailing? Like what do we do? You have to then go back and be like, actually, our operational excellence isn’t sorted out. We need to do that first. And who needs to be enabled from that side of the house? Like don’t forget to enable your rev ops teams, your deal desk teams, all of the teams that are kind of essential to making your partnership with AWS Hum need to be enabled in the way that is relevant for their business. [00:21:10] Louise Strandoo: So when you, you know, think about like what do you need to do across all the pillars? It’s gonna be different depending on what your go-to-market focus is. If you’re a hundred percent focused on selling through SIS today and through channel, maybe product-led growth is not the top priority, but then you need to go and figure out, okay, so how have we. [00:21:28] Louise Strandoo: Figured out which partners we wanna work with on AWS and how have we enabled them and have we communicated that enablement to our salespeople? Are we removing unnecessary barriers to them transacting? That’s what you really gotta figure out. So it’s really about looking at how you execute outside of marketplace, outside AWS, figuring out what that, what are the strongest pieces that you do in your business today, across those pillars, and then asking to replicate that with your partnership with AWS. [00:21:56] Vince Menzione: Nice. So to the room here is, um, if someone in this room doesn’t, does one thing differently on the marketplace, what should it be? [00:22:08] Louise Strandoo: There’s so many things I can think about. I think like first [00:22:12] Vince Menzione: you’re coaching ’em [00:22:13] Louise Strandoo: individually, [00:22:13] Vince Menzione: by the way. Just think about it that way. [00:22:15] Louise Strandoo: One of the first things like, it depends on where you’re like, where you’re at in your journey. [00:22:18] Louise Strandoo: So like, quick show of hands, who is, um, a partner that is like using the marketplace today? [00:22:26] Vince Menzione: There’s quite a few actually. [00:22:27] Louise Strandoo: Okay. Awesome. Thank you for helping drive the marketplace. So for those of you that raised your hands, like my sentiment to you all would be figure out how you are incorporating marketplace as the center of your strategy with AWS. [00:22:44] Louise Strandoo: We are increasingly using marketplace as the point of scale for all things about partnership. All things funding are like increasingly requiring some hook into marketplace. So we can actually provide more funding and scale increase like more. So think about like how do you use marketplaces that like center of your partnership, um, for those of you that are not on the marketplace today and are thinking like, is this something that is valuable to me? [00:23:15] Louise Strandoo: Is this something that I should think about and do? You should absolutely. Go look at who are your competitors? Who are the folks that are already out there on the marketplace and, and why aren’t you there? And then you should start to look at what are the characteristics of successful sellers to map out What could we do and what’s the kind of order of operations that we should take to figure out like, how do we get there? [00:23:40] Louise Strandoo: How do we have a plan from the beginning to get buy-in for our partnership with AWS so that we’re not going about it, expecting that it’s gonna just like drive a bunch of leads to the business. It’s not what it does well, but it is gonna help accelerate the way that you co-sell with AWS, which can be a tremendous value add when done appropriately. [00:23:58] Louise Strandoo: So I think, yeah, like figure out the right way that it’s gonna unlock business value depending on what’s most important to your priority. Um. Today [00:24:08] Vince Menzione: we have about three and a half minutes, and I, I’m eager to see if there’s any questions. I, I, um, I, John’s right here with the mic and I love that. I love the, want to get the interaction here in the room. [00:24:19] Louise Strandoo: Yeah, [00:24:20] Vince Menzione: it’s a great group. [00:24:25] Guest: Oh, [00:24:29] Vince Menzione: can they light up that mic? Maybe [00:24:33] Louise Strandoo: Good. [00:24:37] Vince Menzione: There you go. That’s fine. There you go. It’s working. Alright. [00:24:41] Guest: Thank you so much. This is a really great presentation, first of all. I love it. Um, I’m actually part of the, uh, the GSI, so I work cognizant. My name is Ana Hill, um, and I’m manage alliances with ServiceNow. Um, our goal is in the really near future to really engage with all the hyperscalers in sell. [00:25:00] Guest: So that’s one thing. But my interesting, my question is how do you, how, how does AWS measure success? Of the partners who are on your platform, what are the metrics? How do you determine which partners are actually successful and what other partners can use to learn from that? [00:25:19] Louise Strandoo: Yeah, that’s such a great question. [00:25:21] Louise Strandoo: So, um, something that I think is like super helpful that you bring up is cost is not a, um, a scorecard that says everybody that does all these things is a good partner. It’s basically inputs that we have come up with that are supposed to help with the partnership outcomes. Um, so partners, we measure a whole bunch of different things. [00:25:47] Louise Strandoo: I think PDMs and my team carry goals across like seven different categories. There’s a couple of big things that we look at. We look at the revenue that you drive through the marketplace, so whether that’s through private offers or through your self-service business or through. Selling through a reseller, or if you are the reseller, like what is that resell business or driving? [00:26:05] Louise Strandoo: Um, we look at what are the opportunities that you’re bringing and sharing with AWS and that you’re launching. So through our lead sharing mechanism. Not only what are you launching, but what are you sharing with us that is qualified that you’re bringing the field into? Um, we look at things like migrations and migration, realized revenue. [00:26:25] Louise Strandoo: How are you helping drive customers to the cloud? And how are you helping customers not just get everything set up, but you start actually using it. Um, so we really are gonna look across like a multitude of those metrics and when we look at like which partners are kind of leading the way. We’re gonna start to look at the revenue in those buckets, right? [00:26:44] Louise Strandoo: Like who’s sharing and bringing and growing with us? Who’s bringing more opportunities to engage before it happens on the marketplace? Who’s actually completing that transaction? And then who are helping who, who are the partners? Kind of like leading those big types of transformations, migrations, and, and realize revenue. [00:27:00] Louise Strandoo: This is really great. Yeah. Yeah. [00:27:04] Vince Menzione: Thank you. Any other questions? Come on. We’ve got 30 seconds left. We have time for that one last question. Run over there. John. Come on. [00:27:17] Guest: Thank you again, a great, uh, presentation. One question I had is, uh, this morning, right Jay from, uh, oia, right? He identified a whole bunch of, uh, companies that are doing. [00:27:28] Guest: More than a billion dollars in revenue with AWS. [00:27:30] Louise Strandoo: Mm-hmm. [00:27:31] Guest: What would you say are one or two top qualities among these companies that help some drive? I can give [00:27:36] Louise Strandoo: six. And they’re all of these. Yes. [00:27:39] Vince Menzione: The cost, [00:27:40] Louise Strandoo: but like, I think, um, so I love it. Yeah. My, my team we’re working on some content to better capture, like Yeah. [00:27:48] Louise Strandoo: You, you’ve gotten there, you’ve done the six basic things. Now what happens when you’re a billion dollar business? What does it look like there? It’s a lot of the same stuff, right? Like billion dollar billers on the marketplace. They embody that resilience, for example, in their operational mechanisms. [00:28:03] Louise Strandoo: They’re moving beyond the point of there being like one person that creates private offers and they’re like just part of the partnership team. They activate their, um, their deal desk to really manage private offers and marketplace business at scale. They’re integrating their pipeline to share deals proactively through their CRM system and they have really targeted enablement that is. [00:28:24] Louise Strandoo: Really pushing to the field to make sure that every person in their team understands the value of cloud value of AWS and how marketplace accelerates the pipeline. So the more mature that you become as a marketplace seller, like the more that cost is relevant to help keep you on track and be that kind of north star to say like, you could do a cool bunch of stuff with us, but here’s really where you wanna check and see, like what can you do to evolve the business to the next stage? [00:28:49] Vince Menzione: What you’ve said is so like impactful and we have some experts in the room that do this. They help these organizations better understand it’s really getting into your field organization to help them understand how to. How to show up for meetings with AWS re, like how to, how to, uh, co-sell together, how to think about going after these opportunities. [00:29:09] Vince Menzione: What, when you’re, when you’re talking to customers, potential customers about their cloud commitments, like what are the right questions to ask in the pro? There’s so many things, like I’m sure the costs six has like 150 each [00:29:21] Louise Strandoo: Easily [00:29:21] Vince Menzione: steps. Yeah. You know, to it. [00:29:24] Louise Strandoo: Yeah. And I think like, just to follow on that. [00:29:26] Louise Strandoo: Um, we have partners who have gone and they’ve been like, okay, we’re getting a strategic collaboration agreement with AWS. We’re getting funding, and if they don’t have this, it doesn’t work. It doesn’t work. It fails. So this is really like, yeah, it’s about building that resilient architecture to say, if we go big, do we have the execution plan to succeed? [00:29:47] Louise Strandoo: You can’t start with a plan to say, give us a bunch of funding and we’ll go do it. Your salespeople will say. Know what that is. Don’t care. Yeah. So you have to put all of that, you know, all of those building blocks in first to make sure that we can actually execute. [00:30:01] Vince Menzione: You need alignment from the executive suite down to the selling floor. [00:30:05] Louise Strandoo: A hundred percent. [00:30:06] Vince Menzione: Yeah. [00:30:06] Louise Strandoo: Yep. [00:30:06] Vince Menzione: That’s really what it’s all about. [00:30:07] Louise Strandoo: Yep. [00:30:08] Vince Menzione: Louise, thank you so much. It’s been incredible. So great to have you join us. Thank you [00:30:15] so [00:30:15] Louise Strandoo: much. Yes, thank [00:30:16] Vince Menzione: you. [00:30:16] Louise Strandoo: Thank you, [00:30:16] Vince Menzione: thank you. Thanks for listening to The Ultimate Partner Podcast. If today’s conversation resonated. Share it with a partner leader in your network. [00:30:26] Vince Menzione: Subscribe where you listen, and head over to the Ultimate partner.com for show notes related content and the resources for this episode. And if you haven’t already, now’s the time to register for the Ultimate Partner Live event in Reston, Virginia, October 26th through October 28th. Until next time, keep showing up in the rooms that matter because being in the room changes everything.

GREY Journal Daily News Podcast
How Could Anthropic's IPO Reshape Amazon's Valuation?

GREY Journal Daily News Podcast

Play Episode Listen Later Jul 30, 2026 1:18


Yahoo Finance reported that an Anthropic IPO could represent a $240 billion opportunity for Amazon by combining the mark to market value of Amazon's Anthropic stake with a potential re rating of AWS tied to AI workloads. Amazon committed up to $4 billion to Anthropic in September 2023, and Anthropic designated AWS as its primary cloud provider while adopting Trainium and Inferentia chips and distributing models through Amazon Bedrock. Reports in 2023 and 2024 placed Anthropic's private valuation above $20 billion, while OpenAI's secondary sales implied $80 billion to $100 billion, providing valuation context. Microsoft said AI services contributed 7 points to Azure growth in a 2024 quarter, offering a relevant comparison for how model access can drive cloud demand. Founders should watch how an Anthropic listing affects pricing, procurement, co selling on AWS Marketplace, and vendor lock in risks.Learn more on this news by visiting us at: https://greyjournal.net/news/ Hosted on Acast. See acast.com/privacy for more information.

Ultimate Guide to Partnering™
304 – Building Successful Multi-Product Solutions with Hyperscalers and GSI’s

Ultimate Guide to Partnering™

Play Episode Listen Later Jul 19, 2026 47:12


Don’t Fade and Die in AI Subscribe to our Newsletter: https://theultimatepartner.com/ebook-subscribe/ Check Out UPX: https://theultimatepartner.com/experience/ Matt Yanchyshyn, VP AWS Marketplace, Rekha Thangelapalita, Elastic GSI Leaders; Allison McFadden, Accenture AWS Leader; and James Kang of Nvidia join Ultimate Partner. In this panel discussion, leaders from Elastic, Accenture, Nvidia, and AWS dissect the urgent shifts in the ecosystem, emphasizing that partners must adapt to AI and agentic co-selling or risk fading away completely. The conversation explores the necessity of deep co-engineering, the power of multi-product solutions in the AWS marketplace, and how automated agents are now replacing traditional human sales pipeline progression. By embracing data readiness and strategic collaboration, organizations can survive the “token maxing” era, effectively scale their enterprise opportunities, and align with NVIDIA’s five-layer strategy to dominate the new cloud landscape. https://youtu.be/zUkL4Wqsa68 Key Takeaways AI agents will automate the majority of AWS partner co-selling attachments and opportunity progressions this year. Partners who fail to embrace agentic workflows and automated governance face the existential risk of fading into obsolescence. Successful multi-product offerings require a “blood to all organs” approach that benefits the client, the ISV, the GSI, and the hyperscaler simultaneously. Nvidia’s “five-layer cake” model emphasizes that successful outcomes at the application layer automatically drive growth for all underlying infrastructure. The “token maxing” phenomenon is forcing enterprises to seek cost-effective, open-model alternatives to scale their generative AI securely. Integrating GSIs and ISVs on the AWS marketplace significantly increases enterprise deal sizes and long-term customer renewal rates. If you're ready to lead through change, elevate your business, and achieve extraordinary outcomes through the power of partnership—this is your community. At Ultimate Partner® we want leaders like you to join us in the Ultimate Partner Experience – where transformation begins. Key Tags strategic collaboration agreement, data readiness engine, agentic co-sell, semantic layer, token maxing, five layer cake, accelerated computing platform, open models, cloud consumption, multi-product solutions, partner central agents, propensity data, automated opportunity progression, generative AI governance Transcript Matt Y and Panel Audio Podcast [00:00:00] Vince Menzione: You have a choice. You can embrace them and figure it out and get governance and, and make your data available. Um, use the partner, central agent, move to Agen Co-sell, or you can fade and die. [00:00:11] Vince Menzione: You can feel it happening. The ecosystem is shifting beneath us, the way Hyperscalers are partnering, how AI is remaking the channel and what it means to win in 2026. [00:00:22] Vince Menzione: Welcome to the Ultimate Partner Podcast. I’m Vince Menzi. Own your host. And each week I sit down with leaders at the intersection of technology, partnerships and outcomes. The voices shaping how ecosystems actually work. We talk about what’s real, what’s changing, and what it takes to lead in this era where the partner channel isn’t just part of the strategy. [00:00:44] Vince Menzione: It is the strategy because [00:00:46] Vince Menzione: being in the room changes everything. Let’s start. [00:00:51] Vince Menzione: We’ve got some amazing leaders joining us. So I think probably for a little bit of context, maybe just start with Rika. You can introduce yourself, your role and, uh, what, what you’ve been doing at Elastic. Yeah. [00:01:03] Rekha Thangellapalli: Yeah, sounds great. [00:01:04] Rekha Thangellapalli: Hi everyone. I’m Reka and I lead GSI Alliances at Elastic. Um, for the past 14 years, I’ve had the pleasure of building different kinds of partner ecosystems across companies such as SAP. MuleSoft, Salesforce, Coupa, and now Elastic. Um, I wanna thank Ultimate partner and Vince for having us here today. Thank you and the panel of these incredible speakers for joining me on stage. [00:01:31] Rekha Thangellapalli: Um, very excited for the conversation today. [00:01:33] Vince Menzione: We love Elastic, and you’ve had some of your other leaders on stage at other events. As such, the quality of your leadership team is amazing. Thank you. [00:01:42] Rekha Thangellapalli: I wholeheartedly agree. [00:01:45] Allison McFadden: Excellent. Um, hello everyone. Allison McFadden. I lead our North America AWS practice at Accenture. [00:01:52] Allison McFadden: Uh, I’ve been there for five years, and truth be told, it was my first partnership role, my first formal partnership role. Uh, so I can take some tips from all of you in the room here today. Prior to that, I was 21 years with IBM, and I got into partnerships because my last role at IBM was actually trying to build. [00:02:14] Allison McFadden: Linux business on the mainframe, and I had to have partners. I had to have partners to help me with workloads to run there. So I kind of learned, uh, trial by fire. But I’m excited for the conversation today. Excited to be in this room and excited to talk about what we’re doing with, uh, elastic. Thank you. [00:02:34] James Kang: Uh, my name is James Kang. Nice to see and meet everyone here. Vince, thank you for the opportunity. Thank you [00:02:38] Vince Menzione: for being here. [00:02:39] James Kang: Um, I’m with Nvidia, so I help manage the AWS partnership at Nvidia all up. Um, I guess fun fact, I’m former AWS and so I see a lot of very familiar faces here in the front row. Uh, former colleagues and then current friends. [00:02:56] James Kang: And so, uh, looking forward to the conversation. [00:02:59] Vince Menzione: Great. Well, we’ll start with an easy tia. Matt. This is not directed to you, directed to the others. So what does a successful AWS partnership look like from your C? So we’ll start with Eureka. [00:03:09] Rekha Thangellapalli: Sure. So from an ISV perspective, I think we really are looking at three things. [00:03:15] Rekha Thangellapalli: Uh, mutual investment building together. And scaling together. So when we talk about mutual investment, elastic recently signed a five-year SCA or strategic collaboration agreement with AWS. And while that is a significant milestone in our partnership, for us, what matters more is what it represents, and that is really a long-term commitment from both companies. [00:03:39] Rekha Thangellapalli: Towards product engineering, um, and joint go to market initiatives to deliver value to customers over time. And that’s what we see is that the best partnerships really compound and they build upon each other every year. Um, they don’t necessarily kind of reset every year. Um, next we talk about building together. [00:03:59] Rekha Thangellapalli: So, um. When we talk about joint solutions, we want to deliver solutions that are better together and the customers have to see us that way. And so whether it’s search, observability, or security, we’re looking at taking to market solutions that we can’t or necessarily don’t wanna take on our own. And finally we talk about scaling together. [00:04:22] Rekha Thangellapalli: And this is where marketplace, for instance, plays a big role, um, when customers can draw down on their cloud commitments, transact online and go from, you know, pilot to enterprise scale adoption in hours, not days. Um, this is when really everyone wins. Um, and this is also where partners like Accenture play a critical role. [00:04:47] Rekha Thangellapalli: Um, you know, the incredible amount of expertise that they bring, uh, the managed services capabilities and, um, their data assets actually play a huge role in having our customers realize that value faster. And, um, like Vince mentioned, at the end of the day, best partnerships are all all about creating kind of that. [00:05:07] Rekha Thangellapalli: Self-sustaining flywheel. And so it starts with investing together, building something unique, and having the customers realize that success faster because that success is really the only thing that’s gonna keep that flywheel going for everyone involved. I [00:05:26] Vince Menzione: absolutely. [00:05:26] Allison McFadden: Okay, amazing. I’m gonna riff off a few things Ika said, but from a GSI perspective. [00:05:32] Allison McFadden: A relationship with a WSA successful relationship with AWS looks slightly different. Um, so I think the first thing that we think of in the GSI Community common thread is that the client outcome and delivering value for clients is what we, what we’re striving for. Um, and so the partnership with AWS in that case, um, um, it has to, it has to. [00:06:01] Allison McFadden: Look like one team in front of our clients. So we have to show up indistinguishable, and that’s with AWS and with an ISV partner, it has to look like one solution in front of the client, especially moments that matter. So board meetings, um, you know, the time we’re gonna sign a deal, like we have to look like one team, uh, and keep our our client outcome, um, first and foremost in mind. [00:06:24] Allison McFadden: The second thing, and this is I think where the magic of all the people in this room comes into play. We can have as many discussions at a CEO level as we want. And if our client teams on the ground are not working together, it falls apart. Falls apart directly in front of the client. Yes. And that is a really hard thing to do. [00:06:45] Allison McFadden: So I’m passionate about the alliance work because that that work is what makes it happen at the corporate level. [00:06:53] James Kang: Cool. Um. I’ll start here. So in Nvidia is a accelerated computing platform company. Um, if you asked. Anyone on the, on the street about a year ago, what is ai? A lot of times they would say AI is, is open ai, or it’s philanthropic. [00:07:12] James Kang: Um, Jensen and I’ll, I’ll reference Jensen a lot today, um, because he is our leader, um, but he also sets the strategy in the direction for Nvidia. He talks a lot about AI in the metaphor of a five layer cake. And in terms of the five layer cake, you start off with the foundational bottom layer being power and energy, which sustains. [00:07:32] James Kang: All of our data centers, you move up the stack in terms of chips. So things think of Foxconn, think of TSMC. Next you have the infrastructure layer. So obvious choice is AWS, and then you get to the models where you do have the philanthropics and the open ais. But finally in at the precipice, you have the application layer. [00:07:53] James Kang: Ultimately, the reason why I mentioned all different stacks of the layers, the five layer cake, is the fact that the application layer is the most important. And so when you think about. Partners like Elastic or ServiceNow Trend, ai, CrowdStrike. Every time you pull from the application layer and you see a success, it pulls all five different components of that layer up. [00:08:13] James Kang: And so ultimately, as I think about success, it’s it’s being able to develop these co-sell wins at the application layer and really demonstrating that through extreme co-engineering and co-design with all the different application. Infrastructure, power and energy layers in mind. Um, Jensen also likes to think of himself not only as the CEO and founder, but also as the, the chief Marketing Officer. [00:08:35] James Kang: We are a very event driven company, and so at our big events like GTC or at big industry events like CES or Computex, he likes to show up on the biggest stage, biggest stages and showcase the partnerships with not only ISVs and GSIs, but also with end customers. And so that’s what I think about when I think of SA success. [00:08:56] Vince Menzione: That’s a really good point. You talked about, Allison, you talked about having an alliance strategy, or at least you teed it up, so I thought maybe we would go there for a second. Right? Like, what does a great alliance strategy look like and why is it important to the success of the partnership? [00:09:11] Allison McFadden: Man, I, uh, I have so many opinions on this. [00:09:13] Allison McFadden: We could probably be up here all day. That’s [00:09:15] Vince Menzione: okay. [00:09:16] Allison McFadden: Um, no, I think. Uh, there, there are a couple things, and the first one that comes to mind is focus. We cannot be all things to all people. Um, so when it comes to think about some of the, the work we’re doing with Elastic, we have a very, very clear point of view on what client problem we’re solving, what clients we want to talk to. [00:09:38] Allison McFadden: It helps if, um, from an ISV perspective, if there’s a very clear fit in. The Accenture portfolio or whatever, you know, SI consulting partner. You’re working with a very clear fit in the portfolio and we know what we’re not gonna go after, what we’re not gonna spend our time on because we have, we have this tendency, there’s millions of people. [00:10:00] Allison McFadden: The ecosystem chart that, you know, Vince, you showed up there, there’s so many connections. There’s probably more connections there than there are atoms in the universe, right? So, um. Defining what we do together and what we don’t do together is the first thing that pops to my mind. [00:10:19] Vince Menzione: Reka, do you have a perspective on it since we’re gonna, we’re gonna talk next about what you’ve done together, but, and I also wanna get mass perspective as a hyperscaler partner here as well. [00:10:29] Rekha Thangellapalli: Yeah, I mean from my perspective, I, I’m gonna, you know, kinda echo what Allison said is to be just maniacally focused. Yep. Um, because, especially from my perspective, so Elastic has three different solutions, right? We’ve got search, we’ve got observability, we’ve got security that map to completely different business units within Accenture. [00:10:47] Rekha Thangellapalli: And of course Accenture does a lot of things. And so, you know, when we first came together it was like. Okay, what are we gonna focus on? What industries are we gonna go after? Which segments are we gonna go after? Which customers, you know, um, outcomes are we trying to solve? And I think that sort of maniacal focus is the number one contributing factor to, to the fact that I’m like, up here on stage today. [00:11:12] Rekha Thangellapalli: Great. [00:11:14] Vince Menzione: Matt? Perspective? [00:11:16] Matt Yanchyshyn: Yeah, I, I, I guess I was trying to. To add something, uh, additional from an AWS perspective, uh, when it comes to, you know, what does a great alliance look like? Uh, AWS is obsessed with data, you know, in data we trust. And, and so the best, um, and, and this goes sales business problem, and it’s not just the engineering teams. [00:11:34] Matt Yanchyshyn: And so, uh, you know, Accenture does a good job of this elastic, definitely. And if you can come to the table with, um, quantifiable proof of the value of customer outcomes and partnerships. Um, you’ll win all the time and it’ll be a durable relationship with AWS ’cause we really are this data obsessed company and, and even the most senior sales leaders. [00:11:54] Matt Yanchyshyn: Uh, and so what I mean by that specifically is like if you, if you can show like your a RR to land an a RR conversion ratio, like in in numerical format, it’ll light up our sales leaders and, and they’ll be all, and they will co-sell with you all day long. If you can show the, I mentioned this earlier, like the AWS service, uh, whether you’re consulting company or, um, elastic and, and how the shape of customer accounts change positively when we work together. [00:12:15] Matt Yanchyshyn: That type of sort of quantifiable data works particularly well from an alliance perspective. With AWS as a partner, we, we really are like this data in sort of results out company. Um, so I, yeah, that’s just adding to the great points that were already made. I would say specific to AWS that that’s key. [00:12:30] Matt Yanchyshyn: Yeah. And I’m gonna bring up one more thing. I want to dive in on the, the joint value proposition, but you mentioned something that made a lot of sense and resonated to me about the organizations once you get out of partner, the partner world that we all know and love. Mm-hmm. Once you get down into a field organization or account management organization. [00:12:49] Matt Yanchyshyn: Not as much understanding and really organizations do a bad job here, honestly, in terms of enabling the field organizations. Do you agree? [00:12:58] Allison McFadden: I agree because I, I agree. And, um, you know, I think that’s one of the things, and, and I, I, when I joined Accenture, what we had was a lot of wicked smart architects delivering programs to clients in the field. [00:13:15] Allison McFadden: Very smart, very deep in AWS knowledge. Um, and that was awesome for the 10 clients they were staffed on and to get that understanding of how AWS works and I dream about lar, right? Like, this is a good, you know, but that takes real effort and real work. Yeah. And it’s, it’s um, almost like being a language translator. [00:13:37] Allison McFadden: Yes. For me. Yeah. So, you know, I had to deeply learn AWS so that I could. [00:13:42] Rekha Thangellapalli: Sure. [00:13:42] Allison McFadden: Teach my account teams. My account teams are really smart. They know who they’re selling to. They know their customers. They know what their customers need. They do not know what AWS has to offer always because they’ve got 20 partners lining up to try to tell their stories. [00:13:57] Allison McFadden: Um, they don’t know how to ask of the AWS team or the elastic team or the Nvidia team. Yeah. What they need [00:14:02] Vince Menzione: this co-selling piece. Yeah. [00:14:04] Allison McFadden: And so that is where, um. We had to build that muscle even around our AWS practice, which was a huge practice at Accenture, but we didn’t necessarily surround it with that kind of enablement and um, almost deal coaching layer. [00:14:21] Vince Menzione: So Elastic and Accenture came together. I dunno which one of you wants to lead this part of the conversation, but you will, right? Yeah. So tell us about the genesis of this and why. And a lot of people dunno what Elastic does, but you do some really incredible work. Like I, somebody told me one day was like, oh, you know, Uber, like, that’s elastic, powering all that. [00:14:41] Vince Menzione: Like, we don’t think about that. That the engines that you have and the, the backend to the customers, huge customers. [00:14:48] Rekha Thangellapalli: Yeah, absolutely. Um, so when AWS launched this feature last, um, reinvent where basically it allowed, you know, channel partners such as Accenture to be able to bundle up their services, their data assets with an ISV solution and put it on marketplace, um, you know, Accenture and Elastic immediately saw an opportunity. [00:15:09] Rekha Thangellapalli: Um, at the time most customers were doing gen ai. But they were running into the same challenge, which was that their data just was not ready. And by the way, this is a problem we were solving. Outside of marketplace. I think the, the feature that you guys launched just gave us a way to package it up and to be able to create this repeatable solution, which we call data readiness engine for gen ai and put it on marketplace. [00:15:40] Rekha Thangellapalli: And, um, this to me was a success because. Each company had a clear reason to invest. Um, so for Accenture, they were able to, you know, create a very differentiated services led offering. Uh, for Elastic, we were able to expand on our AI story. And for AWS, um, you know, it drives marketplace adoption, increases cloud consumption, all of that great stuff. [00:16:07] Rekha Thangellapalli: And customers, of course get. A solution to a very real problem that, that they were having. Um, and you know, the surprising part for me going through that journey was that, um. The pitching, the idea, getting the budget, getting the executive sponsorship was actually the easy part. The hard part was getting all three companies to come together, uh, to go from idea to launch in a very ambitious timeline of six weeks. [00:16:37] Rekha Thangellapalli: Nice. And so, you know, this was very much like. Doesn’t matter your title. We’re rolling up our sleeves and we are on this outcome together. Um, and so we literally built a RACI matrix, a project plan, and you know, we had daily standup calls for six weeks where literally. At least one person from each three of these companies called in, you know, got rid of any blockers and we made sure we were on target for that timeline. [00:17:07] Rekha Thangellapalli: Um, and you know, at the end we had a successful launch. But I think my favorite part about the story is the impact that we’re having and, um. My favorite story comes from a global pharmaceutical company that, you know, had basically nine petabytes of data spread across six different continents. Wow. And by working with Accenture and Elastic, they were able to build that trusted foundation that their AI and their agents can, you know, kind of safely tap into and be accessible at scale. [00:17:41] Rekha Thangellapalli: Um, so that’s my version. Allison. [00:17:44] Allison McFadden: Yeah. Well, I don’t have a lot to add. I just, I would say this is a good example of a couple of principles, right? One is having a forcing function is never a bad idea. Sign up for a big event, sign up. I’m like, I’m here with my, you know, Nvidia guys saying, sign up for the event. [00:17:58] Allison McFadden: It’ll make you move quick, right? [00:18:00] Audience Member: Yes. [00:18:00] Allison McFadden: Um, so that is one, but two, one of my mentors once told me, when you’re designing any kind of, you know, offering go to market motion, it has to get blood to all organs. If it does not get blood to all organs, it does not go [00:18:14] Vince Menzione: nice. [00:18:14] Allison McFadden: Um, [00:18:14] Vince Menzione: I love that analogy. [00:18:15] Allison McFadden: Oh, I love it. And I can talk all day. [00:18:17] Allison McFadden: That guy was brilliant. I love him. But, um, no, and, and so Elastic did a really nice job of bringing the tech to the table. Um, our team has to trust in that technology and its ability to scale, right? Um, because at Accenture we have to be able to deploy across 700,000 consultants. Um. And yeah, so I think those are the two, two things that really worked well here is we had, uh, trust in the technology solved a customer need. [00:18:50] Allison McFadden: Um, it drives, we don’t even talk about, like, yes, it drives marketplace revenue, but it unlocks work that we do that drives even more revenue to our AWS Friends. Right. So this is a, this is a, um, product that’s getting your data ready for AG agentic. It’s a messy problem that everyone’s dealing with, and it removes blockers for clients and it unlocks more, you know, ag agentic work on top of that. [00:19:15] Allison McFadden: So, blood to all organs. [00:19:17] Vince Menzione: So, was that the proposal going forward to say we need to have, we need to have trust in the solution. We need to drive significant revenue. It needs to be something all of our, you know, seven, 700,000 people. Can be a part of and help drive? Is that how you think about? [00:19:32] Allison McFadden: Yeah, and for us right now, um, it’s an interesting time for Accenture. [00:19:36] Allison McFadden: Our clients are asking a lot of us, and what it does is it having some of these accelerators helps us deliver cheaper, better, faster to our clients, which is what they’re demanding of us right now. Um, so it’s an accelerator to client outcomes. [00:19:55] Vince Menzione: James, what is NVIDIA’s role and how do, how do you enter the equation here? [00:20:00] James Kang: Yeah, it’s, um, it’s a good question. Um, I, I would say that Nvidia is probably one of the most misunderstood organizations in the world. Um, despite the, uh, the market capitalization in the valuation of the company, we have a very tiny organization. Um, what I mean by that is, um, if you think about. [00:20:20] James Kang: Salesforces and field sales organizations. Um, we’ll take Salesforce as the account or the customer. As an example, we have one account manager at NVIDIA that no, not only covers and is responsible for the relationship with Salesforce, um, but also manages. Automation Anywhere as well as DocuSign. Whereas at AWS, in contrast, like there are full armies and teams Yeah. [00:20:45] James Kang: That are supporting the Salesforce relationship. And so as you think about partnering and working with Nvidia, the focus has to be on really. Extreme co-design, but also being very prescriptive in terms of what are the very specific customer outcomes that we are solving for. And the guidance that I would give is bring in Nvidia into that equation and that conversation as early as possible because that [00:21:10] James Kang: co-engineering and co-design needs to be part of the foundational building blocks in order for you to come out with a end solution that checks all those different requirements. [00:21:20] James Kang: And so I think. Again, like going back to Nvidia, um, we like to talk about two different types of brains. A brain one and a brain two. Uh, brain One you think about the next quarter and making sure that you’re hitting the revenue targets for the next quarter. Brain two, you think about a long-term goals and potentials looking around corners and being very strategic. [00:21:41] James Kang: The saying internally is without Brain one, there is no oxygen, but without brain two, there is no future. And everyone at NVIDIA is trained to think in that brain two mentality. [00:21:52] Vince Menzione: Wow, Matt. [00:21:54] Matt Yanchyshyn: Yeah, I, I was just thinking I love the blood doll organs. Uh, and so just on, on that note, um, and, and, you know, the multi-product solutions that, that you, you built together, uh, that is a really good example of blood do organs because like we all know, that’s how customers buy. [00:22:07] Matt Yanchyshyn: They, they buy solutions and increasingly they’re looking for combinations of ISV, sometimes multiple products from multiple ISVs with services. Uh, often they’re buying it through a resell motion. You know, and they, and, and so that from a customer perspective, they want a single place to go. And so that’s the multi-product solution. [00:22:24] Matt Yanchyshyn: They wanna find everything they need, they need Accenture, they need Elastic to solve a specific solution. And I think where that’s headed is even more specific listings, like with AI powered listing experience, like, you know, elastic Plus Accenture for, I’ll make something up like a manufacturing workload. [00:22:37] Matt Yanchyshyn: And so this solution based. Uh, sort of buying is, is very customer centric. It’s what customers want. We all know that. But that’s, that’s the customer sort of organ, I guess. Um, but then, you know, you all have SCAs and those SCAs have marketplace commits. It helps if that gets transacted through marketplace helps the AWS relationship, you know that that’s an organ. [00:22:55] Matt Yanchyshyn: It’s the relationship. It’s, it’s the commercial construct and that you have, uh, that that’s another organ. You’re marketing people. They, that’s another organ. They don’t wanna land, uh, leads on a static marketing page. They wanna land a lead on a, a storefront with a multi-product solution that can actually convert and that you can actually buy it through that. [00:23:12] Matt Yanchyshyn: So the marketing person’s happy because they, they have less churn. Uh, and then, you know, our reps are happy ’cause guess how they get paid? They retire quota when they sell Marketplace. And they, we also, Jay McMain will tell you, that’s another organ called Jay or on, on you now. Um, [00:23:27] Matt Yanchyshyn: he’ll like that. I’ll call him up and tell him that. [00:23:29] Matt Yanchyshyn: Yeah, [00:23:30] Matt Yanchyshyn: but he, he’ll tell you, you know, don’t believe me. Obviously, never believe Matt, believe, believe the, the data and, and his data shows that. Those deals will close faster and larger if you use marketplace. So that’s, that’s a lot of organs. That’s the whole body. Um, but you know, when you have your customer happy ’cause that’s how they wanna buy your field happy. [00:23:45] Matt Yanchyshyn: Um, and, you know, the relationship happy and you know, your marketing team happy. Uh, and, and Jay happy. Um, and, and you know, I think that multi-product construct and, and the way you kind of use it to model a partnership and the way buyers ultimately wanna buy is, is really powerful. And so I, I think it’s, you know, it’s really a manifestation of how. [00:24:04] Matt Yanchyshyn: We kind of intend and to go to market anyway. Uh, so I think, you know, and thanks for leading the way, by the way. You’re, you’re amongst the very first, so that’s great to see. [00:24:11] Matt Yanchyshyn: So these storefronts are really helping this drive, drive this. Well, [00:24:13] Matt Yanchyshyn: that’s the next evolution. Like we’re talking about the multiproduct solution. [00:24:16] Allison McFadden: I’m JJ Accenture storefront. [00:24:17] Vince Menzione: Yeah. Oh, there you go. I mean, j and j Accenture storefront. [00:24:20] Allison McFadden: We’re gonna talk about that. [00:24:20] Matt Yanchyshyn: Yeah. I mean, [00:24:21] Matt Yanchyshyn: Accenture also leading the way yet again with storefronts. And so I think the combination of. You know, again, I was talking a lot about conversion. Yeah. And you know, buyers know sometimes they know what they wanna buy and, but if you really wanna convert that lead, you wanna land them again, something that combines, you know, elastic Accenture’s services plus software, but in a storefront that is, you know, surrounding with just the solutions they want so they don’t need to kind of go searching. [00:24:42] Matt Yanchyshyn: So, you know, ultimately reducing that time to close, I guess, really ’cause meeting the customer where they are with what they need. [00:24:51] Matt Yanchyshyn: So we talk about co-selling a little bit. We, Jay and I talk about this all the time. We gotta keep looping Jay in here, even though he is not even in town this week, but Reko, um, what does co-sell look like inside Elastic? [00:25:02] Matt Yanchyshyn: You’ve got, we talked about an incredible leadership team. I’ve gotten meet some of your leaders. Seems like you drive, you do a good job internally driving that. Let’s talk a little bit about it. [00:25:11] Rekha Thangellapalli: Yeah, and this is something I’m, I’m personally very passionate about. Um, co-sell is. Very much a journey, not a destination. [00:25:20] Rekha Thangellapalli: And I think step one for us is recognizing the different partner types that we have. Because at Elastic we work with, you know, OEMs, MSPs, resale distributors, GSIs, um, and they all bring something very unique. To the customer lifecycle and they all contribute very differently within, you know, our own sales cycle and sales process. [00:25:45] Rekha Thangellapalli: And so, you know, figuring out what is the unique benefit they bring, how do we enable them? So training and enablement is a huge piece of it, and so is making sure we’ve got the right metrics to measure success. Um, I know a lot of companies look at partner sourced as the north star, and that’s great, right? [00:26:06] Rekha Thangellapalli: Because that is undeniable. You can say, Hey, that would not exist if it wasn’t for my partner team. Um, but we’ve also noticed that when we bring in GSIs, it actually increases renewal rates. It significantly increases. Um, a RR over time. Um, it expands deal sizes and so these are very real metrics that we can point to, um, beyond just the co-sell and the partner sourced number. [00:26:32] Rekha Thangellapalli: Um, so for us it’s looking at it from a very holistic perspective, but also catering it towards that unique partner and making sure we’re doing everything we can to set them up for success and setting up the partnership for success. [00:26:47] Vince Menzione: So clo close win ratios, deal size and renewal rates? [00:26:52] Rekha Thangellapalli: Yes. For specifically for geos size. [00:26:54] Rekha Thangellapalli: Yeah. [00:26:55] Vince Menzione: Very interesting. Allison, uh, what had to change internally to produce these co-selling? We talked a little bit about the field organization and enabling a, a group of, and, you know, account sellers that are very customer focused and enabling them on the co-sell side. What had to change internally to drive that? [00:27:13] Vince Menzione: Yeah. [00:27:14] Allison McFadden: I, I might have already alluded to this a little bit in a previous answer, but, um, creating the capacity to develop, build, and sell these solutions, um, inside of a large GSI, where billable hours is kind of the number one metric on the table. Um. Is part of the investment that we had to make within Accenture to get this done? [00:27:36] Audience Member: Yeah, [00:27:36] Allison McFadden: so expert technology time. So we have technologists that understand the elastic technology. We do similar with Nvidia, by the way, we. We released some of their time to go co-develop the solution because it has to hold technical water, right? It can’t just be a marketing pitch. It can’t just be, it has to be a real, um, what’s the there, there. [00:27:59] Allison McFadden: So in order to actually do proper co-sell, we had to release some of that time. Um, to invest in those partnerships. Um, we’ve also done similar with some industry aligned business development leaders recently, so we have freed their time up to go. Uh. Open new conversations, educate client, account teams, go to clients, have conversations. [00:28:26] Allison McFadden: Um, so that, that’s a new motion that we, uh, have just kind of recently made, um, to allow them, I love this brain one, brain two also, right? So to allow them to focus on brain two, because a lot of our time. Typically spent delivery issues, you know, getting my hours, where am I charging my time? And so just freeing up a little of that capacity to do this work, um, helps get us in this brain two mode where we’re not just living to survive. [00:28:56] Vince Menzione: I. So, Matt, you’ve removed a lot. I mean, one of the things I admire, I admire AWS for being first to market and removing the most friction in marketplace of any of the vendors. Really, truly that. You talked about some of the announcements. How does some of, how does some of this tie PC central agents propensity sales plays, MCP, how does some of this tie to how, how you’re thinking about the future? [00:29:18] Vince Menzione: And how to enable more motions like this. [00:29:20] Matt Yanchyshyn: Yeah. Well, I, I think if you know my boss, UBA Borno, uh, you’ll know that she has a maniacal focus on automation. Yeah. Um, and, uh, co-sell is increasingly automated. You know, you were asking earlier about propensity data. You can get that propensity data in addition to sales plays and, uh, opportunity scores through the partner central agents. [00:29:38] Matt Yanchyshyn: So things that used to require multiple calls to A PDM, if you’re lucky to have one. Yeah. Or a p sm. Uh, you, you can now get through, through these agents, you know, uh, tech Systems, TGS, they, they manage what, over 5,500 customer opportunities with agents that they built on top of our partner Central APIs. [00:29:55] Matt Yanchyshyn: Um, and work Span has built a whole product and business that’s right on leveraging, uh, our APIs, our capabilities to sort of tie into your CRM. So, majority of all opportunities will be progressed and managed by agents. This year at AWS, we already have a majority of all customer opportunities, all app have a partner attached and I, I took a personal goal for a majority of those partner attachments, not to happen from a human. [00:30:22] Matt Yanchyshyn: But from our solution matching engine. And how do you get recommended by that solution? Matching engine, having a healthy ACE pipeline, thanks to partner central agents and the integrations you’re doing. And in addition to being the specializations and doing things like multi-product solutions and ultimately closing opportunities, you dream of LAR and so LAR will help that. [00:30:40] Allison McFadden: It’s more like a nightmare. [00:30:41] Vince Menzione: And so, you know, [00:30:42] Allison McFadden: it’s more like a nightmare, but [00:30:44] Vince Menzione: nightmare. Well, it’s, it’s, yeah. Nightmare of Laura and, and. Nice dreams of PRM, but the, um, but that’s the loop, right? I, I think, uh, increasingly co-sell for us, and in my mind, is largely a hundred percent automated. Yeah. Except for what matters most, those most largest, most strategic, most complex deals. [00:31:01] Vince Menzione: Where our highly paid and very skilled salespeople are most effectively used. [00:31:05] Vince Menzione: Yeah. [00:31:05] Vince Menzione: You know, the days of, you know, this person with 20 years experience selling, clicking, progressing opportunities through a pipeline, uh, should be over. Uh, and, and we need those people out, out selling and, and co-selling. And so that for me. [00:31:19] Vince Menzione: Yeah. That, you know, we talk a lot about co-sell, but I, I’m obsessed with automating as much of the co-sell as possible. [00:31:24] Vince Menzione: I remember going back to the ex Excel spreadsheets and, and that, that seems to be be Viva became spreadsheet jockeys. [00:31:31] Vince Menzione: Yeah. [00:31:32] Vince Menzione: And, and they stopped selling. They forgot how to sell. [00:31:34] Vince Menzione: Yeah. And people spend all this time doing lunch and learns and things like that. [00:31:36] Vince Menzione: And then, you know. Then the salespeople rotate out after 18 months and, and it, that’s, that’s the old days. Uh, you know, the new days are, are AI powered matching algorithms, uh, ag agentic co-sell, using the partner essential agents to get your data and, and putting that data to use automatically and, and what sounded like magic. [00:31:51] Vince Menzione: 12 months ago is being done, you know, by partners at massive scale across thousands of opportunities. You can do it today. And you know, I, there’s a guy named another Mike, right? Mike another Mike who they have, there’s like a guy who’s doing all this and I’m picking on Mike ’cause I, I know their system really well and I know the guy Mike grew easily built it for them. [00:32:08] Vince Menzione: Um, but, you know, I think, yeah, again, in the days of having 10 people sort of doing lunch and learn could be replaced by one or two people, building agents, uh, managing a massive pipeline. And, and that’s the future. [00:32:18] Vince Menzione: Exactly. James, your perspective on what breaks with co-selling? [00:32:22] James Kang: Oh, what breaks co-sell? Um, I would say. [00:32:25] James Kang: It, it starts and finishes with just misalignment and a loss of trust with the customer, especially when you have multiple partners or stakeholders involved. If you’re trying to do a three-way deal with a end customer and you’re not on the same page, you’re not gonna get to a successful outcome on, on the backend. [00:32:44] James Kang: Uh, the fix is a much more complicated story. I would say that to take a step back, um. We’ve talked about the five layer cake. We’ve talked about where NVIDIA kind of fits within the equation. We are invested in the ecosystem and so as different players and application organizations win and see these outcomes for end customers, we celebrate that success. [00:33:07] James Kang: Um, and as part of that kind of ethos of where NVIDIA fits within the ecosystem, we wanna make sure that not only. Our customers, but our partners like ISVs and GSIs are set up for success. Um, we do not as Nvidia sell hardware or GPUs directly to customers We use. Hyperscalers like AWS as kind of our force multiplier. [00:33:31] James Kang: And similarly we think of ISVs and GSIs as the force multipliers in terms of our extensions of how we, we kind of leverage the relationships and build the trust with our end customers. And so going back to kind of the question, Vince, I would say that it all comes back to trust and being able to build that mutual trust. [00:33:48] James Kang: Um, a lot of what we do when we co-sell with AWS is really on the software layer. Um, we actually have more software engineers at NVIDIA than we have hardware engineers, which is a weird thing to say, um, because everyone knows us for our GPUs. But because of that fact, we are heavily invested in Cuda and making sure that Cuda becomes the foundational layer for how not only our ISVs and GSIs, but also our end customers are building. [00:34:12] Vince Menzione: Very cool. So Reiki, you and James together on this production. Versus pilot with the Gentech ai. Tell us a little bit more about that. Where, where are you in the process? [00:34:24] Rekha Thangellapalli: Yeah. So I mean, in general, what we’re seeing out in the market in, in relation to sort of AI and, and customer’s journeys is that, um, at least from an elastic perspective, um, we’re seeing people very much in production when it comes to, you know, kind of AI assistant co-pilot use cases. [00:34:42] Rekha Thangellapalli: So, you know, things like, um, software development, customer support is a big one. Um, any sort of employee productivity use cases where there’s. Still a human in the loop somewhere. Um, and there’s a very like, clear path to value. And so we see the customers being in production excelling there. Um, no problem. [00:35:01] Rekha Thangellapalli: Where we’re seeing people still kind of in the pilot phase is those fully autonomous workflows where there is no human involved. The agent is reasoning on its own. Um, accessing multiple systems and taking an action on the user’s behalf. And what we’re seeing is that it’s not the intelligence of the agent that’s holding it back. [00:35:26] Rekha Thangellapalli: It’s more about giving the right context to the agent and having the right. Security kind of governance controls in place for the company to feel comfortable in putting these fully autonomous workflows into production. And that’s really the conversation we’re having is all right, what are the controls you need in place? [00:35:47] Rekha Thangellapalli: For you to release this to your business unit. Um, and what is the context that the agent is needed before we can comfortably let the agent make the decision on the user’s behalf? Um, James, I’d be interested to hear what you’re, what you’re seeing in the market [00:36:03] James Kang: plus one on all things context. I, I would even go so far as to say, um. [00:36:09] James Kang: H how many folks in the audience have heard of token maxing? Like this new term? [00:36:13] Rekha Thangellapalli: Yeah. Yeah. [00:36:14] James Kang: Um, I’ll, I’ll give a very specific example of, of Uber that went public. With the example of Claude, like they allowed all of their employees to use as many tokens as possible, and within the span of four months, they exhausted their full budget for the year, and so they had to pull back, and now there’s a cap on every employee. [00:36:33] James Kang: I think the number that’s circulating is $1,500 per month per employee, and so I think that is at least. In this multi-phase evolution of where we’re going to be and where we’re today, cost has become kind of the prohibitive force in terms of agentic AI at scale. Um, I think we are working on some very creative solutions in-house and Nvidia. [00:36:55] James Kang: Um. And we saw some really dynamic announcements this week when it comes to all things agent core, um, where we want to focus on very nimble ways for customers to be able to execute and go to market. And one extreme example of that is our investment within our open model strategy. So Nvidia, not only, again, providing GPUs, we actually offer our own op open models, which we call our Nitron models. [00:37:21] James Kang: And through our Nitron models, we are allowing customers to really develop and fine tune their own proprietary models in a cost effective manner. So right alongside the frontier models like OpenAI and Anthropic. It’s not a if then, it’s not an either or statement. It’s a, it’s a permutation, it’s an and So we’re giving you a cost effective alternative to not only bring your AgTech applications at scale by training on Nibo tron, which is open source, but then once you’ve kind of finished and fine tuned that specific training job to be able to. [00:37:53] James Kang: Go ahead and utilize your frontier models, whether it be OpenAI or Claude. And I know there’s other partners here that are providing those kind of different model capabilities. And so I think for us it’s, it’s a matter of choice. We know that this market is dynamic. It’s gonna be evolving over the next coming months as well as the next coming years. [00:38:10] James Kang: Uh, but we believe that we are positioned for a really unique dynamic expansion of AgTech use cases over the, at least the next three to six months. [00:38:20] Vince Menzione: Allison, for the partners in the room who are glazed over right now going, what do I, what do I do over the next 12 months? [00:38:26] Allison McFadden: Should I wake everybody up by saying, yeah, please. [00:38:27] Allison McFadden: Say go hurricanes. [00:38:28] Vince Menzione: Yes. [00:38:29] Allison McFadden: Is there anyone, anybody? Everyone’s like, boo. I get to leave the parade today to go home to parade. I live in Raleigh, so we’ve got our parade on Saturday. Nice. [00:38:39] Vince Menzione: Nice. [00:38:40] Allison McFadden: All right. Wake up. Um, all right. So for the $50 million partners in the room, um. $50 million is not small. You have something that works. [00:38:50] Allison McFadden: Right. This is great. What I would be thinking about is, you know, we’ve talked about focus before, but really doubling down on, you know, what is, what is your industry, what is your client like, ideal client that you serve. And build, um, almost that kind of community. You know, the, the clients we have move from firm to firm to firm. [00:39:17] Allison McFadden: And if you’ve done good work at one, you’re gonna follow ’em to the next. Um, so build that client demand in a specific place or specific client profile that is just like really knocking it out out of the park for you. Um. Scale with marketplace, right? So if you, I, I love some of the data that you were sharing in your talk earlier, um, because it’s like no overhead scaling mechanism. [00:39:45] Allison McFadden: I mean, it’s, it’s fantastic. Um, Accenture, other GSIs like us, we are investing in marketplace. So we’re investing in resources, um, to help us. Use marketplace more with our clients and we’re gonna capture, right, those storefronts. And if you’re present on marketplace, you’re gonna be able to catch, uh, yourself in that wheel. [00:40:09] Allison McFadden: So I think those are the, the kind of couple of things I would say is focus, focus, focus to drive that client demand and use scaling mechanisms like marketplace to really kind of, uh, accelerate. [00:40:24] Vince Menzione: Matt, anything to add there on the. [00:40:26] Vince Menzione: Well just, you know, Ja, James, you, I love the token maxing reference in Uber and it reminds me, you remember when cloud came out and everyone was like, oh, all these people are, are gonna use the cloud and costs are outta control and. [00:40:39] Vince Menzione: Um, a lot of people pulled back from the cloud and, and a lot of those companies no longer exist. And it’s similar with, with, uh, token maxing, like, oh, these agents are outta control. You have a choice. You can embrace them and figure it out and get governance and, and make your data available. Um, use the partner, central agent, move to agent to co-sell, or you can fade and die. [00:40:58] Vince Menzione: And, and that’s, that’s where we’re at. Uh, is, is the, the companies sitting here today embraced the cloud years ago and won. Uh, and and there’s a set of companies here today who are gonna embrace agents in the, for both buyers and sellers, and will win. And there are those who won’t and they won’t win. And so for me, it’s like we’re, we’re at a, we’re at a crossroads. [00:41:18] Vince Menzione: And, and if you’re gonna win, you gotta leap into that, you know? I love it. And, uh, and, and, and it’s, it means the cost of experimentation is so much lower now. Development and, and even business development or software development is, is agent enabled. And so you can take risks, you can experiment and, and you have to, it’s, it’s an existential moment. [00:41:37] Vince Menzione: Agreed. We’ve got a couple minutes left over for any questions. What do you think? Sure. Are there any here. I think there are a couple. Yeah, we’ve got, we’ve got a co-sell question I’m sure coming up here. [00:41:51] Audience Member: Um, I’m Cassandra, I’m the CEO of Partner Tap. And one of the questions I had was, I think, you know, the co-selling between the sellers is where things get. Really, really hard when you’re multi-partner. And so when I was listening, um, with, you know, the Accenture and Elastic together, you talked about how you had, you, you had to get these BD business development people. [00:42:22] Audience Member: Um, is this a new team that is over the client team? And how do these teams interact like with the elastic sellers? Are you doing a lot of coaching to the field and then with if AWS sellers are, are involved, like what is that whole picture? What does look like, [00:42:43] Allison McFadden: like [00:42:44] Audience Member: on the ground? I mean, that is the hardest part, I think, and that’s what we hear. [00:42:48] Allison McFadden: It’s so, it’s so, it’s so tough. Um, and I will, I’ll just say, so our business development leaders that we now have kind of. Expanded their capacity. They have always been, they have always been there. Um, but they have not been well resourced. They haven’t, they haven’t had very clear kind of job description. [00:43:12] Allison McFadden: I’m gonna say I, in the past they have been kind of focused on partner relationship. And so like more like an alliance manager and maybe working on some of the data. Right? So when I say I have nightmares about Lars, because we’re always trying to increase the LAR for Accenture and, and they were focused like in those detailed weeds of like trying to pass ACE and trying to call the PDM and all this stuff. [00:43:39] Allison McFadden: What we are doing is really pivoting them to be proper sales, business development focused on client outcomes and focused on. Technical skills to be able to describe what this solution is to the field. So, um, and because we need, I have many, many questions about, I gotta get agents to work with Eurogen co-sell so that that part somehow goes away. [00:44:05] Allison McFadden: So that’s a, that’s the thing we gotta solve still, but, um, so we’re pivoting them to be kind of driving. More of that co-sell enablement with the field, um, and taking that message to the field rather than being there, waiting for questions to come in from the field, waiting for like our field teams to discover, oh, I saw something that we’re doing with Elastic, like on a press release on LinkedIn. [00:44:30] Allison McFadden: Right. So we’re kind of trying to pivot them to be more proactive. [00:44:33] Vince Menzione: Very cool. [00:44:34] Rekha Thangellapalli: Yeah. And uh, Cassandra, that’s an excellent question because I think. Multi-party, you know, sort of tri-party offerings. The hardest part is operationalizing it at scale, right? Yeah. And so for this particular offering, we are basically having three routes to market. [00:44:51] Rekha Thangellapalli: So one is seeing how this offering fits into our existing elastic go to market. And so I am constantly enabling our field sellers to say, okay, within our three field sales place, here’s exactly where this fits in. Here are, you know, uh. Keywords that you hear in customer conversations where you bring up this offering and here’s a process of how it works. [00:45:14] Rekha Thangellapalli: Um, exactly At what sales stage do I bring in Accenture, how, you know, what are the roles and expectations? Right? So that’s on the elastic side. We’re doing the same thing on the Accenture side. So we’re doing a ton of training enablement and lunch and learns, and we’re also looking at how do we fit into. [00:45:31] Rekha Thangellapalli: Uh, Accenture’s AI transformation projects, we are the semantic layer, right, of their enterprise brain. And so it’s a whole different sales motion, um, and, you know, having the right assets, having the right process again to make sure that that goes smoothly. And then finally, we’re going directly to the customer. [00:45:49] Rekha Thangellapalli: So we are launching multiple external campaigns where, you know, if the customer raises their hand. We will, we will line up immediately. Right. Um, and so, [00:46:01] Allison McFadden: I mean, I can’t, I can’t, I can’t say how important that third leg of the stool is. ’cause the second part, she talked about getting into our catalog is the first thing. [00:46:09] Allison McFadden: ’cause my BU business development leaders have the catalog. Right. And that’s what they’re selling. So what Elastic has done has gotten into one of those offerings and then. If we have a customer that asks for it, that is the fastest way to alignment. That is like the number one thing that we respond to [00:46:26] Vince Menzione: customer at the center. [00:46:27] Vince Menzione: This is great. Well, I think we’re up to time. This was a great session. I want to thank you. This is what a great, what a great group. [00:46:34] Vince Menzione: Thanks for listening to the Ultimate Partner Podcast. If today’s conversation resonated, share it with a partner leader in your network. Subscribe where [00:46:43] Vince Menzione: you listen, and head over to the ultimate partner.com. [00:46:47] Vince Menzione: For show notes related content and the resources for this episode. And if you haven’t already, now’s the time to register for the Ultimate Partner Live Event in Reston, Virginia, October 26th through October 28th. Until next time, keep showing up in the rooms that matter because being in the room changes everything [00:47:09] I.

Ultimate Guide to Partnering™
303 – AWS Marketplace Leader Matt Y Reveals What’s Coming. It’s Tectonic

Ultimate Guide to Partnering™

Play Episode Listen Later Jul 12, 2026 36:20


Don’t let the AI wave crush you. Subscribe to our Newsletter: https://theultimatepartner.com/ebook-subscribe/ Check Out UPX: https://theultimatepartner.com/experience/ Dive into the seismic shifts happening within the AWS Marketplace and discover how AI, self-service product-led growth (PLG), and advanced co-selling strategies are redefining partner success. Matt Yanchyshyn, VP of Marketplace at AWS breaks down the recent announcements from the summit, illustrating how agility and adaptation are crucial to surviving the new agentic future. From lowering professional services fees to the explosion of business applications like ServiceNow, this conversation reveals the hidden mechanics of modern cloud procurement and how you can position your organization to capture massive enterprise opportunities before your competitors do. https://youtu.be/gaWxU1kgCLk Key Takeaways Adapting to the new agentic future requires agility rather than fighting the influx of AI tools. Lowering the listing fee for professional services from 2.5% to 0.5% drastically improves partner economics. Organizations without a self-service or PLG motion on the marketplace are literally leaving money on the table. Millennial buyers increasingly initiate complex enterprise procurements through self-service and AI-driven research. New AI-powered opportunity scoring empowers partners to prove their value internally and to AWS. Marketplace success hinges on optimizing metadata for AI agents, not just traditional SEO. If you're ready to lead through change, elevate your business, and achieve extraordinary outcomes through the power of partnership—this is your community. At Ultimate Partner® we want leaders like you to join us in the Ultimate Partner Experience – where transformation begins. Key Tags: AWS Marketplace, agentic workflow, med pick scoring, phoenix.ai, Cara Cloud, branded storefronts, product-led growth strategy, intrinsic value boost, SaaS evolution, self-service motion, Databricks credit model, Trend Micro companion app, MCP servers, opportunity score tracking, PPA drawdown, concurrent agreements, AAMI structural debt, CXML procurement Transcript: Matt Y Audio Podcast [00:00:00] Matt Y: The ability to adapt with change and kind of roll with punches. ’cause a lot of people are saying like, agents are gonna destroy everything. And, and the opposite has been true. [00:00:08] Vince Menzione: You can feel it happening. The ecosystem is shifting beneath us, the way hyperscalers are partnering, how AI is remaking the channel and what it means to win in 2026. [00:00:19] Vince Menzione: Welcome to the Ultimate Partner Podcast. I’m Vince Menzi, own your host. And each week I sit down with leaders at the intersection of technology, partnerships and outcomes. The voices shaping how ecosystems actually work. We talk about what’s real, what’s changing, and what it takes to lead in this era where the partner channel isn’t just part of the strategy. [00:00:42] Vince Menzione: It is the strategy because being in the room changes everything. [00:00:46] Matt Y: Let’s start. [00:00:50] Vince Menzione: And now on to the really important stuff. So, Matt, I don’t wanna butcher it ’cause I, a couple people have told me how to pronounce your last name and they said use the word magician and you’ll get close to it. But I’m just gonna introduce you as Matt Wy and I’m gonna ask you to pronounce your name on stage, but I want to have you join us. [00:01:08] Vince Menzione: So excited to have Matt wy. After a super busy day and night last night, come over from Brooklyn and join us today. Matt, so great to have you. Thanks. Thank you so much. Thank you so much. Alright, so pronounce your name for us. [00:01:23] Matt Y: Anyone wanna guess? Ian’s? It’s like magician. [00:01:27] Vince Menzione: It’s not that hard, [00:01:28] Matt Y: it’s not that [00:01:28] bad, [00:01:28] Vince Menzione: but I don’t wanna butcher. [00:01:29] Vince Menzione: I wanted to let you do it. Good. [00:01:30] Matt Y: What calls me Matt White. [00:01:31] Vince Menzione: That’s great. [00:01:32] Matt Y: Yeah. [00:01:32] Vince Menzione: So 13 years. [00:01:34] Matt Y: Four coming up on 14 next month. Yeah. [00:01:36] Vince Menzione: Wow. Congratulations. Yeah. So you’ve been there, you’ve been there since the early days. And we, we had a conversation. I had some Microsoft, former Microsoft colleagues. Uh, Theresa Carlson, for those of you who knew the public sector business. [00:01:48] Vince Menzione: Yeah. Who started, I mean, Andy came out, it was so funny because I was there and she was hosting Andy for a dinner and with all the CIOs of the federal government. [00:01:57] Matt Y: Yeah. [00:01:58] Vince Menzione: And she was still at Microsoft and it was actually kind of an interesting time. And she came over and did a lot of great things for a number of years. [00:02:04] Matt Y: Yeah. She [00:02:05] Vince Menzione: and a lot of great [00:02:05] Matt Y: business. [00:02:06] Vince Menzione: Yeah. She really like, it went from employee number one to 7,000. [00:02:09] Matt Y: Yeah. [00:02:09] Vince Menzione: And you, you were, you’ve been there all that whole time. Pretty much. [00:02:12] Matt Y: Yeah, I guess when I started in New York, just down the road, we were, uh, in a Regis facility. There were like 11 of us in, uh, just sitting around a table and we had to speak quietly sometimes because there was a, um. [00:02:21] Matt Y: Some type of a financial services organization down the hall and they’d listen to try and get stock tips on Amazon. Yeah, [00:02:28] Vince Menzione: I love it. [00:02:29] Matt Y: Never leaked. That’s [00:02:29] Vince Menzione: good. I love it. [00:02:30] Matt Y: Yeah, [00:02:30] Vince Menzione: you probably got some great stories and, um, we won’t have time for today ’cause I wanna leave some room for conversations on marketplace end questions. [00:02:38] Matt Y: Yeah. [00:02:38] Vince Menzione: But I would love to invite you back for a real, like, in-depth podcast and I would love to get the whole genesis story. [00:02:44] Matt Y: Let’s do it. [00:02:45] Vince Menzione: We’ll do it. Okay, so let’s talk about, let’s talk about yesterday for you. Uh, some, some really big announcements as well. I thought maybe you could recap a little bit of what’s been going on in the marketplace business and it’s an, it’s been an exciting time. [00:02:58] Matt Y: Yeah. Yeah. You know what’s, I think what was really nice yesterday is it was sort of the combination of bringing, uh, our partner services like Partner Central and all those other services together closer to marketplace. We’ve been doing that over, over several years. So Marketplace has some of its own. [00:03:12] Matt Y: Big announcements, like, uh, we have a, we formalized our list and sell initiative. For example. We have a new, so it we essentially reducing the cost, uh, to list on marketplace through a partner program. [00:03:22] Vince Menzione: Yep. [00:03:22] Matt Y: And incentives associated with that. We have a new AI powered listing experience, which I think is particularly important ’cause I think many of you are like me and watching your SEO numbers go down and watching your agent traffic go up. [00:03:33] Matt Y: And so having, uh, an AI assistance in marketplace to optimize your listings for not just to, you know, retain what you can of your SEO, but prepare for the newent future and improve your GEO as we’re calling it. So that, [00:03:45] Vince Menzione: so it’s GEO now? [00:03:46] Matt Y: Yeah. You know, there’s a little debate right now in the acronym Moral A A EO versus GO I’m going, I’m on the G team, so, yeah. [00:03:52] Vince Menzione: Alright. GEO [00:03:54] Matt Y: It’s like the, the, yeah, they’re gonna win. They’re like the Knicks, but the, um, [00:03:57] Vince Menzione: yeah, yeah, exactly. [00:03:57] Matt Y: But yeah, so AI assisted, uh, I mean, making. The most of, like, essentially marketplace is an excellent conversion engine. And so using AI to help improve that conversion engine in the form of your PDPs for both humans and agents. [00:04:08] Matt Y: So that was an exciting launch. Um, I got the most applause when I announced that. We lowered, we made the economics better for, uh, consulting offers professional services, nice to marketplace. We lowered the listing fee from 2.5 to, to 0.5% and wow, it goes even lower in certain circumstances. So just improving the economics. [00:04:24] Matt Y: I’m really excited to. Really partner with a lot of you to reinvent services through, through the marketplace like we did with SAS and other areas. Uh, and we’re doing with agents right now. So that was a big one. And then a whole series of announcements around, um, how we’re making it easier and more cost effective and more efficient to partner with AWS. [00:04:41] Matt Y: So using AI to, uh, using med pick scoring to automatically progress opportunities so you don’t have to kind of wait on a human. To, to click and progress, you know, that that can take days. And, uh, if you, if you wanna have an opportunity and have that be cos sold with AWS, that can be through a mix of agents for the long tail and with humans in the, in the sort of top end and more complex. [00:05:00] Matt Y: And allowing AI to help all the partners improve their opportunity quality so that we can better co-sell together. So. Yeah, I said AI a lot intentionally. Um, [00:05:09] Audience Guest: yeah, [00:05:10] Matt Y: AI sort of in the whole cycle for buyers, for sellers, uh, for operational efficiency, cost of sales. So a lot of announcements. I think I hit the big ones, so yeah. [00:05:18] Matt Y: I’m Might have missed something there. There we go. [00:05:21] Vince Menzione: George. [00:05:21] Matt Y: Oh, and storefront. Yeah. Thanks George. See, I look at George to see what I missed. Uh, we, we acquired a great company called phoenix.ai late last year. Okay. And you, you actually were said Caresoft and Yeah. Be down. Uh, [00:05:30] Vince Menzione: yeah. [00:05:30] Matt Y: So if you’re familiar with Cara Cloud, they have a procurement portal. [00:05:33] Matt Y: It’s heavy use by the US government, and they, um. Uh, we, we acquired them, uh, the really great growth company. They have over 70 logos now, and they help you build a branded storefront on marketplace, which obviously is important in the government space. If you’re procuring on a certain contract with a certain reseller, um, you know, there’s a certain set of products you’re allowed to buy. [00:05:51] Matt Y: But what we’re finding is even down on Wall Street, you hear, um, enterprises are, are using storefronts for internal procurement and they wanna have a curated collection of, of partner products and, and your own ecosystems internally. So we’re selling to both customers. And also to channel partners to build custom storefronts, branded storefronts for, and [00:06:07] Vince Menzione: it makes total sense, right? [00:06:08] Vince Menzione: Yeah, because you wanna li you wanna limit the, the viewing and, uh, and get, because I mean, how many different listings do we have? Like over 30,000? [00:06:16] Matt Y: Yeah. Yeah. There’s, I think the official numbers over th we have over 36,000. I was checking from over 6,000 vendors. Um, it’s a lot. And, and that’s gonna explode with the AI powered, uh, listing, uh, experience that we launched. [00:06:26] Matt Y: We’re gonna make it easier. And I guess what I’ve been telling partners is. You know, customers aren’t clicking through categories anymore. They’re using AI to search. And so it doesn’t matter how big our catalog is, what matters is being found. And what matters is converting that buyer. So if you have a. [00:06:39] Matt Y: If you’re running a demand gen campaign for say, like, you know, life sciences in, in Jersey and there’s a specific buyer at j and j, you wanna capture, that person doesn’t wanna be just dropped onto a generic marketplace, 30,000 listings. They wanna be dropped in a very specific place where they’re seeing like life sciences offers from Accenture, for example, coupled with a life sciences power thing with Elastic, you know, like, but a solution. [00:07:00] Matt Y: And that they want to land in a curated place where that highly intention buyer can be converted effectively. So that, that’s what we’re doing with all this. [00:07:06] Vince Menzione: And that’s where the GEO comes in because [00:07:09] Matt Y: Yeah. ’cause that buyer might be an agent That’s right. With, and that agent has is even more fickle, honestly. [00:07:14] Matt Y: And you know, what used to be milliseconds for the human before they kind of click away is, is now perhaps microseconds. Yeah. And so, uh, you know, having the right metadata and, and the right positioning, uh, the right story that an agent or a human can pick up to ultimately. Uh, complete their product research and choose your product is, is critical. [00:07:30] Vince Menzione: Very cool. Very cool. So before I, I, I’ve been asked to ask you this because I, I’ve had this con, people have brought come to me and said, you gotta ask Matt about music. He’s a big music guy. And, uh, so what are your favorite bands? [00:07:49] Matt Y: So, I mean, the, the real answer is, uh. I, I go to about a show about every week. [00:07:54] Matt Y: As, as Mike Trill knows, uh, we heard a show last night. Um, we were, uh, just a few hours ago, really? And, uh, um, favorite band, uh, well, I’ll tell, I’ll tell a story. I, I had a side hustle with MTV for years. Um, I used to run a music website. Um, oh, that’s cool. I didn’t know that. It got, it got kind of popular. It got sponsored by, if, if anyone’s into like early hip hop. [00:08:16] Matt Y: It got sponsored by a group called Jurassic Five. ’cause he, one of them reached out to me and said, nice. Hey, uh, you know, I’ve been, I like your website. And he ended up paying for a web, hosting a Dream host, if you remember, of cost back then. [00:08:26] Vince Menzione: Oh, Jesus. [00:08:26] Matt Y: Because I was broke and couldn’t afford it. And then, uh, and then this band sent me like a, a single and said, Hey, you know, trying to get the word out about our little band, can you help us out? [00:08:35] Matt Y: And I put their, uh, I put their, you know, single up on my, on my website and it blew up. And that band is Vampire Weekend. So they’re kind of big now. Wow. Yeah. Um, and uh, that got picked up by like Vanity Fair and all these other guys. And then I got sponsored by MTV to essentially write. Music reviews for years on the side. [00:08:51] Matt Y: So I was working for the Associated Press, laying cable in sports and war and, and, uh, yeah. So Vampire Weekend was good to me that, that they, they kind of paved a way to go to a lot of free shows over the years and a lot of bands and see a lot of great music. But yeah. [00:09:03] Vince Menzione: That is very cool. And that, and how did that get your day? [00:09:05] Vince Menzione: WS It was just a, it was just the technology path that was like, [00:09:09] Matt Y: I mean, it’s a, it’s a, I guess it’s a bit of a long story, but, um, the. There’s many versions of this story. I’ll tell the, tell the one quickly. I was living for free in a Fulbright scholarship house in West Africa. You, we can talk about how that happened another time. [00:09:23] Matt Y: And, uh, a guy had sort of fallen down on the floor ’cause he’d had too much to drink. And I, I sort of lay down beside and be like, Hey man, are you all right? And, um, he, uh. He worked, he, he worked for the Associated Press and next day I had the job, um, being West Africa, head of technology for West Africa. [00:09:37] Matt Y: And because of that, um, and as I learned years later, the AP didn’t have dr they had no disaster recovery. Yeah. And I, I can tell you that now ’cause um, you know, 16 years since I worked there, but they, uh, I put the DR in, um, on AWS and we’re talking like, yeah, 16, 17 years ago. This is early. It was early days. [00:09:56] Matt Y: And I, I swear to God, I paid for. Uh, our AWS bill using, um, taxi receipts, fake taxi receipts that I bought in on Nigerian market, um, because there was no budget and so, you know, it was like 30 bucks. [00:10:08] Vince Menzione: I was gonna say swipe a credit card, but they didn’t [00:10:09] Matt Y: knew that this is the entire press this before. [00:10:11] Vince Menzione: This is before, yeah. [00:10:12] Matt Y: Yeah, like the entire ap. Um, and, uh, so AWS called me like, who are you? Like, why, why are you paying on like this like low limit credit card for like the ap? Like, who are you? And, uh. Next day I had the job. Well, a week later I had the job with aw WS. That so cool. So that’s the story’s [00:10:29] Vince Menzione: cool thing. [00:10:29] Matt Y: Yeah. [00:10:30] Vince Menzione: Very cool. [00:10:31] Vince Menzione: Uh, sports teams. So Knicks fan. [00:10:34] Matt Y: Yeah, I mean, I like the Knicks. Um, they’re h hockey, I’m not allowed to say anything different. No. I appreciate them. Uh, I’m a Raptors fan. I grew up in Toronto mostly. Yeah, yeah. Uh, so, and you know, when they won, uh, that was very exciting as well. So no, Nicks are great. I like the Knicks. [00:10:49] Matt Y: Nothing against the Knicks. Um. They’re fine. Yeah. [00:10:54] Vince Menzione: Hockey, hockey fan. Favorite hockey teams? [00:10:56] Matt Y: Oh yeah. Itron. Maple leaf. Maple leaf. Yeah. They’re gonna, they’re gonna win. Of course. Of course. Yeah. Um, like every year they’re actually, we [00:11:02] Vince Menzione: have some Canadians laughing in the sand. [00:11:03] Matt Y: Well, the leaf are, are, are the Knicks of hockey? [00:11:05] Matt Y: Like Yes, they are. You know, it’s 67 years out, coming up on 68 since they won, so That’s crazy. 53 is nothing. I know. Pain. So. Yeah, definitely the least. Yeah. [00:11:15] Vince Menzione: I love it. I love it. It’s so cool. Yeah. So what was the, uh, what was the, what was the last concert you went to? [00:11:22] Matt Y: Well, literally last night. Oh, it was last, [00:11:23] Vince Menzione: oh, that [00:11:24] Matt Y: was actually concert were my favorite bar in the world. [00:11:26] Matt Y: This place called Sunny’s. Uh, it’s, you know, I, I took Mike and, and Matt from, from Texas and from TGS down there to sort of see my neighborhood and they’re like, where are we? And I’m like, yeah, I live here. Uh, sort of an industrial part of Brooklyn. And, and we went to see, um, I dunno what you would call it, like. [00:11:40] Matt Y: I guess it’d be like roots music. There was a woman with an accordion and a guy with a big cowboy hat. Yeah, it was, it was fun. Yeah. [00:11:47] Vince Menzione: That is so funny. Alright, we’re gonna shift back years. Um, important time right now for partners. What, what should partners be looking out for the most? What would you say to them in terms of what’s the, what’s their real headline for them? [00:11:59] Matt Y: Well, I, I, you know, to borrow from you actually, you know, I liked, uh, the, the principles you had up there and, and with agility, um, you know, there’s a lot of fud flying around right now. You know, people. People were like, oh, it’s the demise of sis with the arrival of ai, you know, everyone’s gonna be using agents. [00:12:13] Matt Y: And then it turns out it’s been a huge boon for most, uh, you know, system integrators and consulting companies that I work with. They all have, you know, the, the good ones especially have vibrant consulting practices now, and everyone is deploying fds, uh, you know, um, the new, the new cool acronym. But it’s, it’s essentially created a huge opportunity for the consulting space. [00:12:31] Matt Y: Uh, and similarly, uh, you know, there there’s this narrative around the sa sa apocalypse, which I really hate, you know, ’cause it was, uh, premature and kind of a trigger reaction from the stock market. And, you know, just look, look what Snowflake did. And, you know, they did what a lot of SaaS companies are doing, but they, they added a nice sort of glaze of positioning and, and, you know, their stock popped and they did pretty well. [00:12:50] Matt Y: And so I think the ability to adapt with change and kind of roll with the punches. ’cause a lot of people are saying like, agents are gonna destroy everything. And, and the opposite has been true. For the more successful consulting companies and software companies who have become agentic. But SaaS hasn’t gone away, you know? [00:13:05] Matt Y: No. Look at our own marketplace. We have this agent marketplace, but people aren’t buying atomic agents at scale. They’re buying ified SaaS solutions with sort of agent sidecars, which has created new opportunities for candidly additional licenses, [00:13:16] Vince Menzione: right? [00:13:16] Matt Y: Um, as customers sort of want to consume more AI services on top of their. [00:13:20] Matt Y: On top of their SaaS solutions. So I think being agile, you know, you see like ServiceNow as part of our billionaires club. Yes. They’re not going anywhere. They’re, yeah. They’re gentrifying. You know, Salesforce has pivoted to this headless model, um, along with Asian Force and using sort of Slack as the operating system. [00:13:34] Matt Y: And, you know, you said like a lot of companies from the seventies aren’t around anymore. They’re gonna be winners and losers. Yeah. Um, but the winners are gonna win even more. And so I, I think what’s so important right now for partners is to not, not bite too hard at the, the latest trend. You know, models are changing and everyone’s like, oh, you know, philanthropics really in the world and they’re wonderful, great to work with, amazing technology. [00:13:55] Matt Y: That’s what people are saying about open AI six months ago. That’s right. And before that, you know, and it, I, I was with Fireworks AI yesterday, a great company and they have some really cool stuff with sort of, um, they believe in more cost effective, uh, open source models essentially, that you can find tune. [00:14:08] Matt Y: Maybe that’s gonna win. I don’t know. Um, is it gonna be sort of domain specific models? Is it gonna be highly capable LLMs? Are LLMs gonna level off as soon as Fable and Mythos are allowed to launch? Maybe. I, I don’t think anyone can predict the future right now. So you have to be agile and you have to kind of seize the opportunities and take a couple punches. [00:14:25] Vince Menzione: Yeah. [00:14:26] Matt Y: You know, and marketplace too, like we’re, you have to be unafraid to experiment right now. Um, you know, that’s hard if your stock’s taking a beating. Um, but this is, it’s a, it is a disruptive time, uh, but it’s creating actually enormous opportunities for growth for partners and, and we really see that, you know, in marketplace specifically within AWS. [00:14:45] Vince Menzione: It, it, it does still feel like the deer in the headlights moment. Right. Would you agree? Like you’re probably taking a lot of meetings and, and calls from ISVs specifically? [00:14:54] Matt Y: Well, [00:14:54] Vince Menzione: that are still trying to figure it out. [00:14:56] Matt Y: Yeah. But it’s everyone. Yeah. I think what’s really interesting, I had a meeting [00:14:58] Vince Menzione: with, it’s not just one. [00:14:59] Matt Y: Yeah. I, well, I had a meeting with one of the leading AI companies, like one of the biggest ones. And they, uh, they demonstrated how they work and they were really proud. They were like, you know, look at our agentic workflow. And I came out at me. I’m like, that’s it. Ours is way better. Like really like, you know, ’cause we we’re, we’re using quick desktop with MCP servers and connectors and all this, and you know, we, we have our own sort of ecosystem of partners, a mix of homegrown software and third party. [00:15:20] Matt Y: And I kinda walked out there and, and looked at, you know, my phone, which has been populated by agents this morning with all the, and I was like, I have a way better agent workflow than this world’s leading supposedly AI company. And I think, um, that really, so during, I, I would, during the headlights, you can call it deer in the headlights, I call it chaos. [00:15:36] Matt Y: And in times of chaos there are people who create. Opportunity again. And so, yeah, there are some people who are stuck and who don’t know what to do, who are over worried about token costs, um, who are not experimenting. But there are a lot of companies, uh, taking this opportunity to kind of pivot their business. [00:15:53] Matt Y: Um, I think, I think we’re in a moment and, uh, yeah, I, I candidly I see more of the latter. I see more experimenting. [00:15:59] Vince Menzione: You mentioned ServiceNow. Any other great examples of that? Organizations that really embraced it? [00:16:04] Matt Y: Uh, yeah. Well, you know, ServiceNow is part of this business applications category, as we call it, in marketplace. [00:16:09] Matt Y: That outside of AI, I think is the fastest growing category in marketplace, which is wild when you think about it. ’cause we’ve historically been an infrastructure partner marketplace with security and data and analytics and, you know, security with channel partners, et cetera. But Salesforce, ServiceNow, Workday, Adobe, you know, I could go on. [00:16:23] Matt Y: They, they are actually. You know, our fastest growing category and yeah, ServiceNow, obviously reinventing itself for ai, Salesforce, but Workday, you know, the workday’s done some, who knows if it’s gonna work, but they, they’re experimenting with essentially like a Databricks, uh, credit style model for like, units of work, uh, which I think is fascinating. [00:16:41] Matt Y: Like everyone’s talking about value-based, outcome-based pricing and meter. And, and you have companies that are ERP companies, you know, like traditional business applications, experimenting with effectively like a metered pay as you go, value based credit model. Again, like who knows if it’s gonna work. [00:16:54] Matt Y: But I think that’s really amazing to see and we need more ISVs experimenting. I, I was talking about trend ai and I know they’re, they’re, they’re one of the sponsors yesterday. You know, many of you know them as Trend Micro back in the day. They’ve successfully reinvented themselves. They built that companion app. [00:17:10] Matt Y: Um, you know, that I think we’re seeing. Just a ton of experimentation in the market across categories. Uh, I could go on and on about partners. Um, yeah, there, I I wouldn’t pick a winner right now. Yeah. [00:17:24] Vince Menzione: You, you, we’ve talked about ai. We’ve talked, talk more about the buying journey and how that’s changing, because again, it feels, it feels like that’s also [00:17:33] Matt Y: Yeah. [00:17:33] Matt Y: So, you know, one of, one of the core, uh, strategic objectives, or we’ll say like the philosophy marketplace is that. Um, financial incentives are important, you know, EDP or PPA drawdown, uh, credits. Like we need to act as an efficient and effective vehicle for allowing buyers to exercise their discounts for, and, and sort of partners to exercise their credits, et cetera. [00:17:55] Matt Y: That, that’s actually important. But what, what a lot of people over rotate on that, and we’re really, one of the things we say a lot inside at Amazon or at AWS marketplace is we want to continue to boost the intrinsic value of marketplace beyond the financial incentives. And well over a quarter of all private offers, private pricing, private, uh, custom terms, et cetera. [00:18:14] Matt Y: Um, begin with a self-service or PLG motion. And partners who don’t have a PLG or self-service motion are literally leaving money on the table. Like if you look at like a Databricks for example, and they did a good job integrating buy with a WS within their SaaS application. They have free trials, they have really strong pego and, and, uh, and PLG motion. [00:18:33] Matt Y: They’re making, I can’t share their numbers obviously, but they’re making a ton of money. On purely self-service motions. And importantly, they’re acquiring new business, new logos that they nurture, you know, really like not just leads but closed opportunities, right? That they lead, they’re growing, uh, at a reasonable conversion rate or or success rate into the next big logos. [00:18:50] Matt Y: And these are over multi-year horizons. They’re patient, you know, they bring in these new logos with PLG, and they’re also bringing banking, a lot of large enterprises. Through self-service. I, I was with data Mask. There’s this great little startup from New Zealand. They’re a New Zealand based company. Um, super nice guy. [00:19:06] Matt Y: And, and, uh, they, they got huge logos. I think they got, what was it? A DP and some huge American logos. Okay. And this like logo in, I think it was Chile, or no, it was Peru. They’ve never been to Peru. They don’t have sales in Peru. Um, and they. Buyers were discovering them self-service and they, they, I think they got something like 13 logos entirely through a self-service motion. [00:19:26] Matt Y: One password will tell you the same thing. I was just with them in Toronto and companies big and small startups and the largest are getting enterprise wins in addition to net new small logos through that PLG. Buyer motion. And that’s because you have a whole generation of CFOs, CTOs, CROs, whatever. The C is [00:19:43] Vince Menzione: millennial [00:19:43] Matt Y: who grew up on their phones. [00:19:45] Vince Menzione: Yeah. [00:19:45] Matt Y: And, and it sounds like, you know, hyperbole, but it’s true. They, they want immediate apps, immediate access. And that actually, you’re like, oh, that never translates to business applications. Turns out it does. It does. And they might not be buying on their phone, but what they are doing is researching and we see the numbers, the amount of customers who are doing their research, and then eventually landing on the page from chat, GPT. [00:20:06] Matt Y: From major financial, like Fortune 500 companies is extremely high. Yeah. Uh, you have procurement team, sourcing team, uh, developers who are starting the research increasingly, like in clawed in chat, GPT, and then, you know, building a proposal and then handing it to their enterprise procurement team. Yeah. [00:20:22] Matt Y: Which is still largely unchanged. So buyer behavior is on the front end, on the research side is really changing. So the [00:20:29] Vince Menzione: discovery is happening through PLG. [00:20:32] Matt Y: Yeah. [00:20:32] Vince Menzione: And then the backend work on private offers and things like that sometimes still happens the old way. [00:20:36] Matt Y: Yeah. Well, and so, you know, it’s [00:20:37] Vince Menzione: fax machine, [00:20:38] Matt Y: some people Yeah, sure. [00:20:39] Matt Y: They’re bringing the deal directly to Marketplace last minute. But even if that deal goes direct, sometimes they’re still beginning their research journey and increasingly using Marketplace as a research vehicle, which is why we launched Agent Mode, um, to help you sort of help you and agents do research. [00:20:51] Matt Y: But that I think if, if I have one piece of device for any partner consulting or ISV is. Don’t leave those leads and that money on the table by not having a PLG self-service strategy like you’re fooling yourself. Uh, and it’s, it’s a huge, it’s a huge, huge business for us. The, the majority of all customers by far on marketplace don’t even have a PPA, uh, and a huge percentage of even those with PPA spend beyond the p. [00:21:17] Matt Y: And so if you’re just think if you’re just using marketplaces as like BPA retirement, you are literally losing money. [00:21:22] Vince Menzione: Yeah. [00:21:22] Matt Y: Yeah. [00:21:23] Vince Menzione: We have a session with Vinod. We’re gonna talk a little bit about that right after. Great. So good. Um, so I, yeah, I think, um. We talked about, we talked about agents, we’ve talked about the millennial buyer, the change in buying behavior. [00:21:40] Vince Menzione: What other, what other areas of aspect I, I, I, I do wanna think about like opening it up though for a second. I think that maybe with maybe nine minutes left. Sure. I just want to get a read from the people in the room. People have questions for Matt that we weren’t able to ask them. Yeah, I think, I think we probably have a few of those. [00:21:57] Vince Menzione: I think that would probably be great. [00:21:58] Matt Y: I can sense the hardball coming. [00:22:00] Vince Menzione: You’ve known each other [00:22:00] Matt Y: a long time. [00:22:01] Vince Menzione: Yeah. No, no. Hardball. We have a mic back here. Okay. I’ll just, we’ll, we’ll, we’ll get you a mic as we are recording. So good. Thank you. [00:22:11] Audience Guest: Uh, Boris Geller with a, a Click PLG is near and dear to my heart. [00:22:17] Audience Guest: We’ve been doing a lot of business in marketplace and I’m still struggling to sell my vision internally on, on, uh, on PLG. Uh, I think. Ag Agent AI is gonna be one of the drivers, and we are already on, uh, agent Marketplace, but I would appreciate guidance on, uh, best practices. How do we kind of, uh, operationalize it? [00:22:41] Audience Guest: It’s, it’s on us, not on you. [00:22:43] Matt Y: Well, no, I think it’s on both of us. You know, we, uh. One thing that we’re trying to do is give you more data to, to sell to your internal stakeholders in your executive suite. The value of co-sell with AWS all up, like finally with what we launched at, uh, the summit yesterday, you now get an opportunity score. [00:23:02] Matt Y: You, you get a number. People have been asking for this for years, so, so you can say when we do this and we, when we give AWS this information. The score goes up and we have a higher propensity to be cos sold by humans or agents before you had to kind of, it was like this mystery you had to guess. And similarly with marketplace, um, we, we have new dashboards that you can use to sort of, you used to have to sit down with us and go through spreadsheets to trace sort of lead to trace the funnel to sort of a close opportunity. [00:23:28] Matt Y: And we’re gonna continue to launch more there. But you now have more data that you can show. You can be like, listen, these are our inbound leads, this how’s converting, and now we have PRM, the partner revenue measurement where we can say like, this is what it’s translating into in terms of. AWS service revenue driven by our product. [00:23:41] Matt Y: And so that being able to tie from that inbound lead from your demand gen campaign through to a converted opportunity to what you actually drive from an AWS impact perspective, so you can, and then what your opportunity score is that data you can use to sell. Not only internally, but to us as well. Yeah, to a skeptical sales team or whatever who’s not maybe, you know, hype on partners in the, in the US West. [00:24:03] Matt Y: You can be like, listen, I don’t care what you think about my business. This is what I’m gonna drive for you with your quarter retirement from an AWS perspective, and this is how the shape of your customer accounts are gonna change. And this is why you should pay attention to my opportunities. ’cause my opportunity score is, is crazy high and I’m giving you insights into business that AWS would not otherwise have. [00:24:19] Vince Menzione: That’s your brand story we’re talking about. [00:24:21] Matt Y: Yeah. [00:24:22] Vince Menzione: Building your story up with within [00:24:25] Matt Y: So it’s, it’s about the data, I guess. And, and you should, you know, you should all actually be [00:24:28] Vince Menzione: Yeah. [00:24:29] Matt Y: Asking me for more data, so, you know, and tell me like, what do you need to sell to your internal stakeholders? ’cause if I can draw a clear line. [00:24:35] Matt Y: From your demand chain campaign that lands on a marketplace, which I know is a conversion machine, it has way better than industry levels of, of conversion rates. And then you can show, hey, if we have a PLG strategy and we land those leads on marketplace, we will convert them with high efficiency, low cost of sales and, and, and have sort of a bifurcated where we can close some through self service, some through express private offers and some through private offers, depending on deal size. [00:24:57] Matt Y: Like you tell A CFO that, and they’re my number one customer now and they love it ’cause they see cost of sales going down, cost of operations going down and business going up. Um, so I think we have more data than we used to use that data. And let me know what other data do you need to make that pitch and make that pitch to the CFO go around the head of sales, all those other people. [00:25:15] Matt Y: Honestly, the CFO is where we get the best leverage. [00:25:18] Vince Menzione: Awesome. Great question. [00:25:23] Matt Y: Gonna bring your mic. [00:25:23] Vince Menzione: We’re, we’re gonna get your mic here. There you go. Oh, [00:25:25] Audience Guest: thank you. So my name’s Jody Cheval and I’m a consultant now, but I was at Workday during when they adopted AWS and it, a sales organization needs propensity to buy data. [00:25:34] Audience Guest: To really drive the sales team to realize the opportunity kind of makes them visualize it. We didn’t struggle, but it was challenging to get that data because at that time we’re getting spreadsheets. So does AWS have a vision of making that API based data that our client, my clients, can get at and bring into a tool to start building account hypothesis based on that data? [00:25:57] Audience Guest: ’cause it really is important to an enterprise sales guy to have the sense that OAWS can help me close this deal. [00:26:03] Matt Y: Yeah. I mean. Part of that. So we, we launched, we’ve been launching part of that in stages and we’re not done. There’s, there’s more coming. Um, part of that is embedded really within the new, uh, partner agent workflows. [00:26:13] Matt Y: We are giving sort of more, uh, information back to you, not just about like what funding programs you’re eligible for, but like, you know, and when, when we will co-sell this deal with you, which is effectively a signal like we, we see this as a high value opportunity, that you have a likelihood of winning internally. [00:26:28] Matt Y: We, we have this solution matching engine that we’re using and we announced. That, that that ties you the partner to a customer specific opportunity that you have a high propensity or the partner has a high propensity to assist with and ultimately win. And now we’ve tied that to our express private offers, which we announced this week. [00:26:44] Matt Y: So it’s an indirect answer to what you’re asking, but a rep can essentially say. Send a private priced offer to the customer on behalf of the partner without having to ring up the partner because they have a high propensity to win this deal with the customer. So we’re progressively launching features like that. [00:26:59] Matt Y: In addition to the propensity to buy data that we do now share. It used to be kind of, again, manual magic depending on who you knew we could share. Now we do share that programmatically, and there’s more to come specifically in that space. Uh, I’d say watch that space. In the next few months, there’s gonna be more data coming away, but we do have the APIs, we have the agent. [00:27:16] Matt Y: We have things like express private office solution matching, and we have been sort of in that space progressively launching features over the last six to 12 months. And, and you should expect to see some more there soon, not just from us or from our partners. [00:27:27] Vince Menzione: Nice. Any announcement dates? [00:27:30] Matt Y: I can’t commit to a date or else my engineers will get mad at me. [00:27:33] Vince Menzione: It looks like we Another question number. Is the mic still back there? Okay. There’s a gentleman over here [00:27:40] Audience Guest: first Go leaves. Um, it’s awesome. I’m right next to. I was right next. [00:27:46] Vince Menzione: We’ve got a lot of great plants here, so, [00:27:49] Audience Guest: um, so this may be a little bit myopic or, or a challenge that we run into, but I love a lot of the innovation that’s looking forward and all the future things that we’re doing. [00:28:00] Audience Guest: One of the things that we’re struggling with is a little bit of almost like tech or structural debt. How do you think about bringing flexibility to the core pieces that underpin all of the innovation, which is. We are self-hosted. So one of our listings is an a MI. You can’t amend an a MI, you have to cancel and start over. [00:28:18] Audience Guest: So a lot of the building blocks, when you think about PLG, if somebody wants to add to that in an a MI listing, it’s, it’s sort of broken. So how are you thinking about taking all of the, the rapidly changing buyer behavior and then looking back at the structural foundation that underpins all of those things, like offers and, and amendments and changes and all of that? [00:28:39] Matt Y: Yeah. I, I promise I didn’t seed that question, but that, that’s a great one. Um, so not to get too in the weeds, but fundamentally, marketplace was built up, um, a bit like AWS like a set, a series of services somewhat independently. And each product type was effectively its own service, SaaS, server images, ais. [00:28:59] Matt Y: Um, what we’ve done recently is now we, we have, we got rid of product types basically on the backend. You, you don’t see it, but what that means, for example, like another thing AAMIs don’t support today, future data agreements. Um, or concurrent agreements, uh, they will all be supported by amis before the end of the year. [00:29:14] Matt Y: ’cause what we’re doing, this fundamental thing that you won’t even see called product offer decoupling. Uh, and it’s a fundamental piece of things that we need to unwind. ’cause we built up, we were moving very quickly over the years. We had a distributed engineering model and we built each product type independently. [00:29:28] Matt Y: And so yeah, if you’re a seller and you’re selling containers, agents, SaaS, amies, um, we’re breaking down the silos between those so that each of them will get the same benefits. And, and by the way, we’re taking the same approach to international. Hopefully you’ve noticed now that. It’s not like a feature launches in the US only and then takes five years to launch in either public sector or another country. [00:29:48] Matt Y: We, we’ve taken a global approach to feature launch and increasingly a product type neutral approach to feature launches. Uh, that’ll be largely resolved before the year’s out. We’re working on it right now. So again, it’s, it should be transparent to you, like you shouldn’t actually see any difference in the, in the experience. [00:30:05] Matt Y: Except that all of those features will be available. So, so that is, uh, actively under work. And that’s actually something if you’d like to try, um, you’re, you’re welcome to. So, yeah, [00:30:17] Vince Menzione: we have time for maybe one more question and we we’re actually gonna have you up here with a couple partners. [00:30:24] Matt Y: Sounds [00:30:24] Vince Menzione: good. Kind of fun. [00:30:32] Audience Guest: Hey, Matt, uh, met Natasha from Dondo. Uh, quick. So great announcements. And you know, you talked about the million, multi-billion dollar, uh, club, and, uh, that’s all great. Uh, in terms of the. Propensity data. I think that’s coming at the center of a lot of things, right? You know, for enterprises, oh, there’s an investment and you tap into that investment. [00:30:53] Audience Guest: But also there’s the other side of the procurement where a lot of customers, sometimes we work with, they’re like, they still wanna go direct for whatever reason, right? So I think there’s an education piece there, but also trying to understand like how we can work together to, you know, get some of that side of the things sorted out as well. [00:31:11] Audience Guest: You know? ’cause a lot of times it’s not about. Just, you know, retiring the, uh, the, the spend comets, but also like, Hey, I’m used, I’m already used that for something else. So maybe that’s not an, uh, something that applies here. And in also in tying that the PLG motion, uh, you know, for the customers you said, you talked about, you know, if there is. [00:31:34] Audience Guest: Leads on the TA table, like where the, it’s not the enterprise, but you know, the others. Um, I feel like it’s more to do, changing the business model at some times. Like with the enterprises, you have the revenue stream coming through, say large deals, right? And all of a sudden you tap into this, you know, PayGo. [00:31:51] Audience Guest: Where it flips the whole equation with, you know, the financing and the, and the, and the revenue measurement. So I think there’s two aspects of how do you kind of cons reconcile those things in terms of, you know, the revenue measurements going forward. [00:32:05] Matt Y: Yeah. So, so two things real quick on the procurement. [00:32:07] Matt Y: Um, yeah, like, yeah, I sort of alluded to this earlier, but, uh. Procurement is a bit late to the AI ag agentic transformation. They’re trying, and there’s a lot of great new incumbents in this space. And the big leaders like, you know, Coupa and Ariba and Oracle are, are, are evolving their products, albeit a bit slowly. [00:32:26] Matt Y: Um, but the, I think, uh, it’s still the long pole in the tent. You know this. And so like, there are two reasons why deals tend to go direct, because it kind of hits a wall of. Legal, uh, you know, procurement, governance, like all that kind of after the selection’s been made, et cetera, or, or they’re, you know, we can’t change. [00:32:44] Matt Y: People are gonna optimize for, for finance, you know, they’re, they’re going to, if they’re getting big discounts. I mean, that is life. I always say it’s like sellers at the most agented company are still gonna chase quota no matter how, you know, crazy. Uh, your, your company is, and it’s the same with, um, with the chief, uh, financial officer and chief procurement officer. [00:33:01] Matt Y: They are going to, they’re literally. Paid to find discounts. And so we’re not, we’re not gonna get rid of financial engineering. That’s a, that’s a thing. What we can do is reduce the friction for procurement. So we launched, for example, like mandatory purchase orders. That was a big thing. We, we have buyer notifications, now we’re making other procure to pay enhancements. [00:33:17] Matt Y: I mean, procurement systems still use like CXML. It’s like, that was, that was cool when I worked for the ap. And like I, I have teenagers that are old, like older than, so they, I, I think, um. Procurement needs to evolve and we’re gonna help it evolve. We’re gonna push it forward and, and we need to make it more seamless for procurement teams so that we remove those objections. [00:33:38] Matt Y: Uh, I can’t remove the financial engineering objection, like, you know, that’s just life. Um, but I can make it irresponsible not to use marketplace ’cause it’s so easy to use. And, uh, that, that’s kind of the approach we’re taking on, on the front end. Uh, you, you know, I think you, you, again, I didn’t see this question. [00:33:52] Matt Y: You, you stepped into a trap. Un unwittingly, um, PLG is not just is for enterprise. And, and PLG doesn’t necessarily mean pego or self-service. Uh, doesn’t necessarily like, uh, most of our self-service efforts are actually focused on private offers. And not necessarily for pego. Uh, when, when I say self-service and, and PLG, uh, it, it can mean all kinds of things like it. [00:34:14] Matt Y: We have requested private offer, requested demo call to actions, buttons that you can put on your listing. For example, you don’t necessarily need a free trial or a metered pay as you go listing to take advantage of those inbound self-service leads. So, and those inbound self-service leads are often massive enterprise deals, like I mentioned specifically, uh, the data mask. [00:34:31] Matt Y: Those giant enterprise deals that they launched came from an enterprise like Fortune 1000 Enterprise in the US that organically discovered their solution on the marketplace using our AI search. And that was a massive enterprise. And so I, I think yes, there is the long tail, you wanna capture a new logo acquisition, but you should think of your product like growth in your self-service strategy as a way to, um, acquire all kinds of leads, including large enterprise. [00:34:54] Matt Y: And so when I say leave money on the table, I’m not just talking about things that are gonna mature over two years or tiny little deals. These could be massive deals. Uh, and, and you’ll accelerate those deals by accelerating their discovery and, and research so that I think that, so, and my advice is don’t, you don’t have to go all in if you don’t have, if you don’t have metering, if you don’t have PayGo, that’s cool. [00:35:13] Matt Y: Start with something simple. Start with a public listing, with a request to private offer like that. That is a, a huge step. That doesn’t take much, and, and it kind of blows my mind still that a lot of companies aren’t doing that yet. [00:35:25] Vince Menzione: Great answer. Well, it’s now time we’re gonna bring, we’re gonna bring, it’s time. [00:35:29] Vince Menzione: We, we’ve got some great partners coming up here, Nvidia Elastic, Accenture gonna all join us for a conversation. Great. And I’m glad that you’re gonna stay with us. And let’s, let’s, well, let’s thank Matt, by the way, for that session. [00:35:41] Matt Y: Thanks. [00:35:42] Vince Menzione: And [00:35:42] Matt Y: thanks for listening to the Ultimate [00:35:44] Vince Menzione: Partner Podcast. If today’s conversation resonated, share it with a partner leader in your network. [00:35:51] Vince Menzione: Subscribe where you listen. And head over to the ultimate partner.com. For show notes related content and the resources for this episode. And if you haven’t already, now’s the time to register for the Ultimate Partner Live Event in Reston, Virginia, October 26th through October 28th. Until next time, keep showing up in the rooms that matter because being in the room changes everything.

What's new in Cloud FinOps?
WNiCF - May 2026 - News

What's new in Cloud FinOps?

Play Episode Listen Later Jun 22, 2026 37:47


Send us Fan MailSummary: In this episode, Frank and SteveO discuss the latest updates in cloud technology for May 2026. They cover AWS's new multi-cloud connectivity with Oracle Cloud Infrastructure, the general availability of Amazon EC2 M3 Ultra Mac instances, and Microsoft's release of V7 VMs powered by Intel Xeon processors. The hosts also delve into Amazon Bedrock's expanded support for request-level usage attribution and service quotas, as well as AWS Marketplace's new programmatic procurement capabilities. The episode wraps up with insights from the FinOps X conference and a discussion on cost management strategies in cloud services.

Partnerships Unraveled
Barry Russell - The open-source foundation of every AI partnership

Partnerships Unraveled

Play Episode Listen Later Jun 4, 2026 26:45 Transcription Available


In this episode of Partnerships Unraveled, we sit down with Barry Russell, Senior Vice-President of Partnerships at Anaconda. Barry helped build AWS Marketplace from a two-pizza team into a global business, spent time at Microsoft and several data-space startups, and has spent just over a year at Anaconda translating that experience into how AI solutions reach enterprise customers at scale.Barry opens with the principle he carried directly out of AWS Marketplace: remove as much friction as possible between where the customer is and the outcome they are trying to reach. At Marketplace, that meant letting customers try software quickly before committing to a multi-year contract. In the AI era, he sees the same dynamic: enterprises want to deploy agents fast, prove they deliver the outcome, and move confidently into production. Anaconda ensures that the open-source components developers use to build AI applications are secure by default, so teams can move from experimentation to production without hitting security roadblocks along the way.What is actually breaking between POC and production comes down to two things: system dependencies that work in a dev environment often do not match what production needs, and CISO teams flagging vulnerability concerns in open-source components. Anaconda addresses both by ensuring the assets a team uses in experimentation carry into production unchanged, with ongoing visibility into vulnerabilities. Barry draws a practical distinction: it is completely fine to discover that an AI application needs a different model or some adjustment. What organizations cannot afford is releasing agents carrying underlying security vulnerabilities. Getting the foundation right from the start is what makes fast, confident iteration possible.With 95% of the Fortune 500 already using Anaconda for data science and machine learning, the company arrives at the AI moment as a trusted workflow layer, ready to help customers close the gap between experimentation and production at the pace the market demands._________________________Learn more about Channext

AWS for Software Companies Podcast
Ep205: AI Teammates Are Here - Asana's Multiplayer Approach to an Agentic Future

AWS for Software Companies Podcast

Play Episode Listen Later May 5, 2026 21:32


Asana CPO Arnab Bose breaks down how AI agents are transforming collaborative work management with multiplayer AI teammates that any team member can coach and correct.Topics Include:Asana is a collaborative work management platform used by 170,000+ companies worldwide.The "Pyramid of Clarity" connects individual tasks all the way up to company strategy.Asana's "work graph" maps tasks, teams, projects, and portfolios in one connected system.Generative AI now converts unstructured data like emails into structured project plans.Asana integrates directly with AWS, Gemini, and Claude to automate that conversion.AI Teammates are first-party agents that take on and complete tasks inside Asana.These agents work in multiplayer mode — visible, collaborative, and team-correctable.A third AI unlock is coming: letting any external agent builder plug into Asana's interface.Asana runs entirely on AWS, including a new FedRAMP moderate GovCloud deployment.AWS Marketplace listings help customers transact faster using existing AWS credits.Arnab advises startups to bet on AWS long-term rather than chasing short-term LLM trends.His 2026 prediction: multi-agent orchestration standards will be the enterprise AI battleground.Participants:Arnab Bose – Chief Product Officer, AsanaSee how Amazon Web Services gives you the freedom to migrate, innovate, and scale your software company at https://aws.amazon.com/isv/

Tech Disruptors
AWS Marketplace VP on the Agent Buying Boom

Tech Disruptors

Play Episode Listen Later Apr 16, 2026 48:56


“Over 80% of Marketplace transactions are still self-service today, but the bulk of the revenue is enterprises buying large contracts,” Matt Yanchyshyn, vice president of AWS Marketplace and Partner Services, tells BI senior technology analyst Anurag Rana. Yanchyshyn explains how AWS Marketplace has evolved from an app-store-style catalog into an enterprise procurement channel offering private offers, co-sell, services, and software. The discussion unpacks why AI agents are the fastest-growing category on Marketplace, the shift toward solution bundles and how AWS is approaching model flexibility, governance and security as agents increasingly do discovery via MCP-style integrations.

The Ravit Show
Enterprise AI in Action: Cognizant and AWS Marketplace at NVIDIA GTC

The Ravit Show

Play Episode Listen Later Apr 16, 2026 4:10


Everyone at #NVIDIAGTC is talking about production AI. I found where to actually see it.Amazon Web Services (AWS) invited their AI Competency partners to demo real world solutions at their booth. My plan is to sit down with each of them and find out what they are building and how enterprises are using it.First up: Hareesh Kommepalli from Cognizant showing a computer vision solution for retail loss prevention.As more retailers move to self-checkout, losses from theft and scanning errors are going up. Cognizant is combining #NVIDIA computer vision with #AWS to help retailers catch those losses as they happen.Cognizant is one of the world's leading professional services companies and they have 25 listings on AWS Marketplace. That tells you something. Retail is just one example. They are working with enterprises on use cases like real time call translation for contact centers, AI agents for SAP, intelligent document processing for insurance, data clean rooms for sports sponsorship, and agentic AI for travel.Check out their listings: https://aws.amazon.com/marketplace/seller-profile?id=2a641c19-3444-4890-9738-e82a8ea39302&trk=5004eff9-71db-4806-9d01-fd7db0dd46bb&sc_channel=elMore AWS AI Competency partners coming throughout the show. Stay tuned.#data #ai #awspartner #cognizant #awsmarketplace #retail #theravitshow

The Ravit Show
Thoughtworks + AWS: Simplifying Enterprise AI

The Ravit Show

Play Episode Listen Later Apr 13, 2026 6:13


AI adoption is not failing because of models. It is failing because of everything around them. At NVIDIA GTC, I spoke with Brian Blanchard from Thoughtworks, on The Ravit Show and this came through clearly.Most enterprises are still missing the basics.- AI-ready data- A proper control plane- Clear operating modelsThoughtworks is tackling this through modernization.From transforming legacy systems to building foundations for agentic AI with strong governance. What stood out is how they are simplifying complexity. Instead of stitching together multiple tools, they are bringing it into one platform. And all of this is built on Amazon Web Services (AWS), using services like SageMaker and Bedrock, with solutions available on AWS Marketplace.This is the real shift. AI is not just a technology problem. It is a systems and operations problem.Check out the video and learn more!!!!#data #ai #awspartner #nvidiagtc #theravitshow

The Ravit Show
Building Flexible AI Systems with Deepset and AWS

The Ravit Show

Play Episode Listen Later Apr 9, 2026 6:12


Everyone is building RAG. But the real question is what comes next. At NVIDIA GTC, I spoke with Jay Wilder from deepset, makers of Haystack, and the focus was clear. Moving from RAG to agents. Deepset, the team behind Haystack, is helping developers build flexible AI systems where you can choose your models, data, and guardrails.What stood out was their demo. They showed how RAG pipelines can evolve into agent-based systems by integrating across ecosystems like AWS, NVIDIA, and tools like Weights & Biases. This is where things get real.In banking, workflows that took weeks are now being done in hours.In pharma, teams are testing and iterating on complex data pipelines much faster.And all of this is built with flexibility in mind. Not locked into one stack. With Amazon Web Services (AWS) as a long-time partner and availability through AWS Marketplace, it is becoming easier for teams to get started and scale.This is the shift I am seeing. From static pipelines to adaptive AI systems.#data #ai #awspartner #NVIDIAGTC #deepset #api #haystack #theravitshow

The Ravit Show
Zilliz + AWS: Scaling Vector Databases for AI

The Ravit Show

Play Episode Listen Later Apr 9, 2026 2:23


Everyone is talking about AI. But what actually powers it? At NVIDIA GTC, I spoke with Travis White from Zilliz at the Amazon Web Services (AWS) booth. Exciting conversation!!!!We talked about vector databases. The layer that helps AI search through images, videos, and text, not just tables. Zilliz offers Milvus (open source) and a managed version on AWS. That means you can scale, stay secure, and avoid managing infrastructure. Real use cases are already here. Autonomous vehiclesDrug discovery, and a few moreYou can also find Zilliz on AWS Marketplace and get started quickly. Simple idea. AI is not just models. It is the data layer underneath. Learn more from the conversation!!!!#data #ai #awspartner #nvidiagtc #theravitshow

The Ravit Show
How Do You Trust AI Agents in Production? Deepchecks + AWS SageMaker Explained

The Ravit Show

Play Episode Listen Later Apr 8, 2026 5:22


One thing I keep thinking about from hashtag#NVIDIAGTC. We are moving too fast in building AI, but not fast enough in validating it. I spoke with David Arakelyan from Deepchecks, and the conversation really came down to trust. Once you move beyond demos, the question is no longer what your AI can do, but whether you can rely on it in production. Deepchecks is focused on this exact problem. Their LLM evaluation and monitoring solution helps teams test and stress their systems before they go live. What stood out was their new feature, Know Your Agent, which lets you generate a full report on your AI system with just an API key and understand where it can break.They are also one of the few solutions integrated directly into AWS SageMaker as a partner app and available on AWS Marketplace, making it easier for teams to bring this layer into their workflows.What do you think about it?#data #ai #awspartner #NVIDIAGTC #deepcheck #api #evals #theravitshow

The Ravit Show
Inside the AWS Marketplace: Deploying Vector Databases and Foundation Models

The Ravit Show

Play Episode Listen Later Apr 7, 2026 5:36


AI agents are everywhere at NVIDIA GTC. But here is what stood out in my conversation with Rudy Chetty from Amazon Web Services (AWS) on The Ravit Show. AWS is leaning heavily into this with Marketplace. A growing hub where you can search, purchase, and deploy AI solutions in minutes. From foundation models to vector databases to monitoring tools, everything is starting to come together in one place.We also talked about the role of partners. Because scaling AI is not a one-company job. It takes an ecosystem. AWS provides the infrastructure.More from the AWS Marketplace Kiosk at GTC.#data #ai #awspartner #nvidiagtc #nvidiagtc2026 #api #awsmarketplace #theravitshow

Ultimate Guide to Partnering™
293 – The $500B Cloud Commitment Opportunity Are You Being Left Behind?

Ultimate Guide to Partnering™

Play Episode Listen Later Mar 31, 2026


Master the $500B Cloud Marketplace Engine Subscribe to our Newsletter:https://theultimatepartner.com/ebook-subscribe/ Check Out UPX:https://theultimatepartner.com/experience/ In this compelling discussion, Vince Menzione sits down with Dexter Hardy, founder of Ntegral and the visionary behind Spark, to deconstruct the massive transformation happening within the cloud ecosystem. Dexter shares his journey of evolving from a traditional systems integrator to a marketplace powerhouse with over 300 solutions and customers in 100 countries, revealing the “Marketplace Operating System” that drives global sales without a massive headcount. They dive deep into the Spark GTM methodology, discussing how companies can bridge the gap between building a solution and actually driving “Get It Now” transactions while navigating the $500 billion committed cloud-spend landscape. From the nuances of multi-party private offers to the critical role of AI in becoming a “frontier firm,” this episode provides a high-level masterclass for any partner looking to turn the marketplace into their most effective revenue stream. https://youtu.be/VLkkuHPpYuk?si=x03Odt2UsCjhtVf4 Key Takeaways The cloud marketplace represents a potential $500 billion in committed spend that partners cannot access without MAC-eligible, transactable solutions. Marketplace as a Service (MaaS) helps traditional SIs pivot to becoming SDCs or ISVs by providing a strategic roadmap for IP conversion. Successful marketplace strategy requires a “Marketplace Operating System” that aligns digital sales with your internal operations and business goals. The “Get It Now” economy allows for 24-hour global sales and lead generation without the need for traditional manual email or phone chains. Becoming a “Frontier Firm” means combining human experience with AI to do things faster, better, and more efficiently than the competition. Co-selling is evolving beyond just the hyperscalers to include rich, multi-party private offers involving resellers and distributors. If you're ready to lead through change, elevate your business, and achieve extraordinary outcomes through the power of partnership—this is your community. At Ultimate Partner® we want leaders like you to join us in the Ultimate Partner Experience – where transformation begins. Key Tags: Integral, Spark, Marketplace as a Service, MaaS, Marketplace Operating System, Marketplace Strategy, Transactable Offers, Get It Now button, SI to ISV pivot, SDC, Microsoft Marketplace, AWS Marketplace, Google Cloud Marketplace, IP Co-sell, MAC eligible, Multi-party private offers, REO, Reseller enabled offers, Cloud Committed Spend, Frontier Firm, AI agents, Spark GTM methodology, Marketplace Optimization, Digital Sales Flywheel. Transcript: Dexter Hardy Audio Episode [00:00:00] Dexter Hardy: AI in the hands of someone who has no idea what they’re doing is just a, it’s a faster way to failure, right? Yeah. ’cause they have, they [00:00:06] Vince Menzione: still don’t understand the concepts. [00:00:11] Vince Menzione: We just finished Ultimate Partners Winter Retreat here in beautiful Boca to a sold out crowd. Today I’m joined by Dexter Hardy, the founder of Integral for a compelling discussion. Dexter, welcome back to the podcast. Great to be here, Vince. It’s [00:00:29] Dexter Hardy: always a pleasure. [00:00:30] Vince Menzione: It is so good to have you back in Boca. [00:00:33] Vince Menzione: Uh, we just wrapped up our ultimate partner executive winter retreat. We call it the Winter Retreat now. [00:00:39] Dexter Hardy: Yep. [00:00:39] Vince Menzione: It’s still February when this airs. It’ll probably be March or April. [00:00:43] Dexter Hardy: Okay. [00:00:43] Vince Menzione: But, um, yeah, the weather in the north has been, they’ve had a tough winter. [00:00:49] Dexter Hardy: Yeah. It’s been brutal [00:00:50] Vince Menzione: for, it’s been brutal. Even, even Atlanta where you are. [00:00:53] Vince Menzione: Had a little bit of winter this year as well. [00:00:54] Dexter Hardy: I was happy to get on the flight. Yeah. It was like 29 degrees the day out, so, [00:00:59] Vince Menzione: so, um, this is your second time Yeah. On Ultimate Partner. And we’ve been friends for, we’re just talking about this. You’ve been to every single one of our Ultimate Partner events. [00:01:10] Vince Menzione: Nine events, [00:01:12] Dexter Hardy: yep. [00:01:12] Vince Menzione: Three times here in Boca and then in other cities like Dallas and Las Colinas. Seattle, Seattle and Reston. Oh my goodness. And we’re back in Seattle again in May. So, uh, we’ve been, we’ve been busy. We’ve been busy. Both of us have [00:01:27] Dexter Hardy: Scott Myer [00:01:28] Vince Menzione: up and we’ve been, and we were introduced. We’ve been friends and worked together. [00:01:31] Vince Menzione: And so I would love to get caught up on you and Integral. [00:01:35] Dexter Hardy: Yeah. [00:01:36] Vince Menzione: Um, the first time we sat down, we talked about Integral as a marketplace. Uh, customer base or, or, or vendor supporting the marketplace. [00:01:45] Dexter Hardy: Yep. [00:01:46] Vince Menzione: And you were, you’ve been, uh, showcased at Microsoft with the Marketplace organization. You’ve done some astounding things in terms of driving business without like a big sales force, you know, and driving marketplace sales, uh, to very high levels. [00:02:02] Dexter Hardy: Yep. [00:02:03] Vince Menzione: And, uh, and now you, I’ll call it a little bit of a twist and turn, but now. You’ve taken all the great learnings, and I’m probably sharing some of your thunder here, but you’ve taken all the great learnings that you’ve had in marketplace and your business [00:02:16] Dexter Hardy: mm-hmm. [00:02:16] Vince Menzione: And now you’re like looking at all these other companies, they’re probably trying to do the same thing and finding ways to help them. [00:02:21] Vince Menzione: So let’s, let’s talk about that. Let’s talk about where you’re going. [00:02:25] Dexter Hardy: Yeah. So, so thanks for that. And it’s always a pleasure to be, you know, in the room with you, especially on the podcast, uh, seeing it grow over the years. And, um, to kind of double click on. How did we get to where we are with, uh, spark Bi Integral? [00:02:40] Dexter Hardy: Um, it’s our marketplace as a service offering. Um, we [00:02:46] Vince Menzione: marketplace as a service. You get that? I just wanna make sure people are listening and watching. Get that. That’s a, that’s a new acronym for me. [00:02:53] Dexter Hardy: That’s a new one. But, but what we, how do we get there? So to your point, yes, we. We’re a, um, marketplace first organization looking at the digital sales leaned in heavily on marketplace. [00:03:08] Dexter Hardy: Um, and what we were doing internally was we created our marketplace operating system. Like literally, how do we run our business? How do we digitize, how do we get those, uh, how do we turn the marketplace into our 24 hour sales guy? Yeah. Taking all those lessons learned how you deal with the hyperscale or how do you understand, you know, the, the signals that’s happening in the market. [00:03:33] Dexter Hardy: Uh, coupling that with, because we’ve been a member of this wonderful organization and getting into the partner community ecosystem, we get asked a million times, I bet. What do you do? How do you do it? That’s help us understand marketplace and so what we. What we saw there was an opportunity to both lean into the challenges that other partners are facing. [00:04:00] Dexter Hardy: If you’re an SI that’s trying to pivot [00:04:02] Vince Menzione: yep, [00:04:03] Dexter Hardy: and be in the marketplace, you’re already established company, how do you create Transactable offers? How do we take the the marketplace opportunity and leverage AI and put our agents in the marketplace? Our aha moment was this is, this is an en enablement opportunity that we can get into and basically be the first ones in because we leaned into it, we understand it. [00:04:35] Dexter Hardy: What makes us different from the other companies is we actually use that methodology every day. [00:04:43] Vince Menzione: For those who maybe didn’t listen to the last podcast we did together, I know this story, but I want others to know the context of it. Tell us about your transformation to a marketplace firm. [00:04:54] Dexter Hardy: Okay, for sure. [00:04:56] Vince Menzione: Maybe the shorter version. [00:04:57] Dexter Hardy: The shorter version, [00:04:57] Vince Menzione: but I, I do know that there was some, you were in business for a long time before this became the business strategy. [00:05:03] Dexter Hardy: Yeah, so the shortened version business founded 2002, Microsoft partner for many years. Yep. 2020. Si. Si as an si. 2020 COVID. [00:05:16] Vince Menzione: Yeah. [00:05:16] Dexter Hardy: Consulting 2.0. [00:05:17] Dexter Hardy: How do you do what you do at scale for others? Taking your ip, converting it. We did that at 2020. Embraced the marketplace. We created our solutions, deploy them to the marketplace. The rest is history. We leaned in how [00:05:32] Vince Menzione: many solutions in the [00:05:33] Dexter Hardy: marketplace, over 300 solutions. I wanna [00:05:35] Vince Menzione: make sure people [00:05:35] Dexter Hardy: got that. [00:05:35] Dexter Hardy: Over a hundred, 300 [00:05:36] Vince Menzione: solutions. [00:05:37] Dexter Hardy: Over 300 solutions. Yeah. Uh, we have. Customers in over a hundred countries. I mean, and [00:05:42] Vince Menzione: yeah. [00:05:43] Dexter Hardy: You know, continuing to build and expand our customer base on a daily basis. And so, [00:05:48] Vince Menzione: and they’re, and they’re buying when you, while you sleep. I mean, we, we’ve known each other pretty well for a number of years. [00:05:54] Vince Menzione: And [00:05:54] Dexter Hardy: yeah, [00:05:54] Vince Menzione: you have customers like, um, I’ll throw out a number, like 25,000 customers, probably, maybe beyond that. And these customers are buying your solutions. All hours of the day and night, [00:06:06] Dexter Hardy: right? Yeah. I I love the get it now button in the marketplace. Literally all they have to do to work with us or transact with us is click on, get It Now, and that’s the transactable offer that everyone, there’s this mystique around. [00:06:19] Dexter Hardy: People are like, well, we don’t have any leads. We can, you know, our, we have an offer in the marketplace and nobody’s clicking on it. And I’m like, Hmm, [00:06:27] Vince Menzione: yeah, [00:06:27] Dexter Hardy: we can help you with that. Right? And so, um, you know, that’s how we. Our, our story with that, our background with that was it’s our 24 hour sales guy. We drive our campaigns, we align with the solution plays. [00:06:41] Dexter Hardy: We’re getting those clicks with, to your point, without this huge army of people. Yeah. And so now we’re saying from a marketplace strategic advisory, a lot of people were saying it earlier, like, you know, marketplace isn’t this adjacent thing to business. How do you strategically think about it as. Um, part of your business all up. [00:07:03] Dexter Hardy: How do you add that as a revenue stream, uh, for your organization? And yeah, there may be some changes that you need to make, you know, how do you incorporate the channel? How do you add in all of the things that you’re currently doing, but create that as a flywheel for this. Get it now economy. [00:07:22] Vince Menzione: So all the, I’m, I’m thinking out loud, like there’s probably a lot of people watching you up on stage at these events talking about how you evolved your company and grew it. [00:07:31] Dexter Hardy: Yeah. [00:07:32] Vince Menzione: Going, that’s me. [00:07:33] Dexter Hardy: Yeah. [00:07:33] Vince Menzione: That’s me. The old, the old version of you absolutely is them. [00:07:37] Dexter Hardy: Yeah. [00:07:38] Vince Menzione: And they all, they all want help. [00:07:39] Dexter Hardy: They all, [00:07:40] Vince Menzione: everybody wants help in marketplace. [00:07:41] Dexter Hardy: Right. And [00:07:43] Vince Menzione: yeah. [00:07:43] Dexter Hardy: And, and to that end. Because I was them. I understand how their mind, it’s a mindset shift, right? You’re saying, okay, we have these traditional sales, we’re a systems integrator, we have all this ip, these, there are all these things that we can do. [00:07:57] Vince Menzione: Yeah. [00:07:58] Dexter Hardy: I don’t, how do we convert this to transact ability? How do we get our sales teams enabled to sell it? And I was, and my, my feedback and my response to that is, well, one, we have a service for that. It’s our marketplace advisor services. I’m sorry for the plug, but not sorry. [00:08:16] Vince Menzione: No, we’re, no, we’re gonna plug today as well. [00:08:18] Vince Menzione: Much as you want. [00:08:19] Dexter Hardy: Yeah. [00:08:20] Vince Menzione: And then I think about this too, because a lot of these sis are developing, we’re just, uh, talking with Agua about MSPs, developing agents for their customers and then making ’em repeatable. [00:08:30] Dexter Hardy: Yep. [00:08:31] Vince Menzione: And so you have other sis that are creating AI tools and agents. Microsoft is created and the, and so has AWS and Google, they’ve created space in their marketplaces for agent AI tools. [00:08:44] Dexter Hardy: Yep. [00:08:45] Vince Menzione: And so now you’ve got all these companies that were traditional sis that are now becoming what we would call ISVs or, or SDCs. And they need help in getting these solutions to the marketplace. [00:08:57] Dexter Hardy: Absolutely. [00:08:58] Vince Menzione: So, so talk about what you’re doing with Spark. [00:09:00] Dexter Hardy: Yeah. So our concept with Spark is. When you look at enablement, so you’ll have platforms that are enablers and a lot of people will say, well, what makes Spark different? [00:09:12] Dexter Hardy: Why? Why you versus Tackle Or Sugar? [00:09:15] Vince Menzione: Yeah. [00:09:15] Dexter Hardy: Any of the other work span. Work span or any, they’re all friendlys to us because we’re meeting you where you are. Right. In order for you to use their platform, you gotta already have the solution together. [00:09:29] Vince Menzione: Yeah. [00:09:30] Dexter Hardy: Right. They can help you deploy. There’s Deploy. They are a deployment firm or [00:09:35] Vince Menzione: Right. [00:09:36] Dexter Hardy: Um, platforms We’re saying [00:09:38] Vince Menzione: they’re middleware in many respects. Correct. Between the, they’re, [00:09:41] Dexter Hardy: they’re integrated into the marketplace. They’re highly embedded into the systems behind it, and we’re saying what happens before that? I have no idea what solution to build. I have no idea how we’re gonna take advantage of Marketplace. [00:09:58] Dexter Hardy: How is Marketplace gonna change? Again, we had these conversations at dinner. Um, [00:10:04] Vince Menzione: yeah, [00:10:04] Dexter Hardy: all of the big players are saying, we have channel, we have our sales teams, we have all these things already. How does marketplace play into that for us? And so that Marketplace strategic advisory goes into it and says, here’s how. [00:10:19] Dexter Hardy: Right. We have a. Our Spark GTM methodology goes into how do those things play together? What are your KPIs or what are your business goals as an organization all up? And then we marry this, basically a Venn diagram of how we marry marketplace with your current objectives. Okay. To not just be this, uh, ubiquitous thing that’s kind of sitting over on the side, like, let’s just put it in marketplace because we need to, and nobody knows it’s there and nobody knows it’s there. [00:10:49] Dexter Hardy: It’s part of. Everything all up. Your messaging, your sales organization, your, um, documentation that you have for your organization. So now everyone understands, not just you as the, let’s say you’re an SI that you were, but you, the si with your agents and how that plays into your bigger value proposition. [00:11:10] Dexter Hardy: So take [00:11:10] Vince Menzione: us through the, go to the methodology you described the Spark methodology. [00:11:15] Dexter Hardy: Yep. So, um, a lot of people, when they think about. The methodology, you’ll say we’re a, we’re an si. I’m just going to use an example. You’re an si. How, how do I get somebody to click on my, my opportunity? How do I get somebody to understand what we have as a value proposition? [00:11:39] Dexter Hardy: And I’d say to people, well, there’s this, it’s part of the methodology. There’s product viability. Can you build something? Versus should you build something. Right. [00:11:50] Vince Menzione: Interesting. [00:11:51] Dexter Hardy: If you are, if you are out there today and you’re saying, I mean, everybody’s seeing Claude, the agents, you can, you can ask AI to build you pretty much anything. [00:12:00] Dexter Hardy: Yeah. [00:12:00] Vince Menzione: Yeah. [00:12:01] Dexter Hardy: Now the question scary and that, that’s a, that, that introduces a new problem. But it’s, can you do it or should you do it? [00:12:08] Vince Menzione: Yes. [00:12:09] Dexter Hardy: And and what I’ll tell people is part of our advisory, so the steps are. What is your North Star right now and what is the software that would enable you to get on that AI rocket ship to propel you even further with where you are? [00:12:27] Dexter Hardy: Those are the solutions that we would try to [00:12:29] Vince Menzione: Okay. [00:12:30] Dexter Hardy: That out, pull out of, uh, as part of that marketplace. Um, advisory Second, what partner or partner organizations are you a member of? Is it Microsoft? Is it the AWS? Is it, you know, Google Cloud? Google Cloud, what have you, and let’s say Microsoft. What are solution plays? [00:12:51] Dexter Hardy: What is Microsoft focused on? How does what you’re doing as an organization align with that go to market? Mm-hmm. Because now you have that jet power of what they’re, um, promoting along with your organization. [00:13:06] Vince Menzione: Nice. [00:13:07] Dexter Hardy: And then the final piece is, well, now that you’ve done that, how do I get it into market? [00:13:12] Dexter Hardy: How do I, uh, get people to click on it? And that’s where some of the secret sauce that I won’t divulge on this, [00:13:19] Vince Menzione: uh, [00:13:20] Dexter Hardy: but there is some secret sauce to getting the ICPs to lean in, getting the [00:13:25] Vince Menzione: Yeah. [00:13:25] Dexter Hardy: You know, you’re listing to light up inside of that. And so that’s. You know, that’s at a high level. That’s kind of how the marketplace, [00:13:32] Vince Menzione: I think what you’re alluding to, and I, I don’t wanna put words in your mouth, but I do think you’ve done a very good job on what I would call maybe digital marketing, maybe. [00:13:41] Vince Menzione: Would that be the right terminology? Yeah. To make your solutions discoverable, to make people understand that they’re out there and to lean in and be able to purchase them. [00:13:51] Dexter Hardy: Yeah. [00:13:52] Vince Menzione: Which I think I would say that’s probably part of the secret sauce, probably of Spark. That is what you’re saying because a lot of organizations struggle here. [00:13:59] Dexter Hardy: Yeah. [00:14:00] Vince Menzione: They put something in the marketplace and nothing ever happens with it. Even even big companies do that. They don’t know how to do it. [00:14:06] Dexter Hardy: So, so yeah. Without divulging the secret sauce, I had a gentleman ask me yesterday, um, during the conference, so how is this different from SEO? I said, good question. [00:14:20] Dexter Hardy: Yeah. Is is SEOS? Is, is SEO involved? Sure, but that’s not the final answer. Because you could do SEO, that doesn’t mean anybody. That just gets you, doesn’t mean anything. Doesn’t mean anything. And so. That’s why I keep going back to this methodology of really aligning it with, uh, what it is you’re trying to accomplish, who it is you’re trying to get to lean in, and then what is the value proposition? [00:14:42] Dexter Hardy: Because at the end of the day, Vince, I think even with any service, like I said, we did our first offerings with our R zero offerings and now we’re doing this. It’s what is the value, right? Um, it’s a hard. Thing to do to really wrap your brain around how your, how your business is going to change from, if you’re doing direct sales and you got your bag and you’re out there selling to now, you mean I don’t have to pick up the phone and call you? [00:15:15] Dexter Hardy: There’s not an email chain that goes out. It’s literally people are just clicking on Get it now to get it [00:15:21] Vince Menzione: and getting it. [00:15:22] Dexter Hardy: That’s a, that’s a mind shift change and that’s. To your point, there is some market, there is some marketing expertise that is required. [00:15:29] Vince Menzione: And we’ve also talked about, I know you and I went down a journey on the co-sell business [00:15:34] Dexter Hardy: Yeah. [00:15:34] Vince Menzione: And how difficult it can be to get a, a seller from a Microsoft or a Google and Amazon involved, unless it’s, you know, a $10 million transaction, they don’t want to get involved. [00:15:45] Dexter Hardy: Right. [00:15:46] Vince Menzione: Uh, you really wanna reach the customer. Because you know, the hyperscalers is great. If you’re driving a ServiceNow or an ADO a big solution, it’s gonna be tens of millions of dollars. [00:15:56] Dexter Hardy: Yeah. [00:15:57] Vince Menzione: But if you are an SI and you’re selling this as part of maybe a services offering, or you’re selling it as, you know, you’re just selling as a standalone. [00:16:04] Dexter Hardy: Right? [00:16:05] Vince Menzione: Um, you want as much eyeballs and transactions as possible and you’re not gonna get that just going co-selling. [00:16:12] Dexter Hardy: Right. And, and the other part of that I will say about co-sell. [00:16:17] Dexter Hardy: I think co-sell has gotten like a dirty rap or bad rap around it. Co-sell is with the hyperscaler, but it’s with other partners too. [00:16:28] Vince Menzione: Sure, [00:16:28] Dexter Hardy: right? Oh yeah, absolutely. So, um, being in the marketplace gives you the option of co-selling would, not just the hyperscaler, but co-selling with other orgs. And so now anytime that you’ve give, you’ve given yourself that X factor on top of your existing ability to deliver. [00:16:44] Dexter Hardy: That’s where you’re seeing the true power of marketplace. [00:16:47] Vince Menzione: And yesterday you were on stage with Jason Rook. [00:16:50] Dexter Hardy: Yeah. [00:16:51] Vince Menzione: And this was part of the conversation. It was you, Jason Rook and Amit Sinha at, at uh, work Span. [00:16:58] Dexter Hardy: Mm-hmm. [00:16:58] Vince Menzione: And part of the conversation was around the, uh, reseller enabled offers. And I think what that’s somewhat of what you’re alluding to is that you have other wait routes to market channels to market. [00:17:10] Dexter Hardy: Right [00:17:11] Vince Menzione: through building other partnerships for co-selling. Yeah. That what you, you were alluding to. Yeah. [00:17:15] Dexter Hardy: So, so yeah, there, there are a million ways to, once you’re in, once you have a transactable offer, that’s when you get the magic unlocks. Right. You, the barrier to entry is being in marketplace with a transactable offer. [00:17:31] Dexter Hardy: And if you’re outside of that loop, again, the REO. You’re not available. Guess who? Guess who can’t do that? [00:17:39] Vince Menzione: Yeah. [00:17:40] Dexter Hardy: If you’re not in the marketplace, you can’t do that. [00:17:41] Vince Menzione: Can’t do that. [00:17:43] Dexter Hardy: Multi-party private offers can’t do that. ’cause you’re not in the marketplace. [00:17:47] Vince Menzione: No. [00:17:48] Dexter Hardy: Right. And so what we’re saying is think about all up, how you’re missing out on. [00:17:56] Dexter Hardy: All of these wonderful opportunities to, I think, I think the number got thrown out a couple of times. Jason ran away from it when you said it’s like a $300 billion number on, he [00:18:07] Vince Menzione: didn’t want, he didn’t, he didn’t want me sharing or he wasn’t, he, he didn’t want to, uh, what, what did he say? Validate that that was the right number, but $300 billion in potential cloud budgets. [00:18:21] Vince Menzione: That you could have access to. We know the number across the three hyperscalers is north of 500 billion. [00:18:27] Dexter Hardy: Yep. [00:18:27] Vince Menzione: It’s just that Microsoft doesn’t break out their numbers and make them public, and so we, you know, [00:18:32] Dexter Hardy: and, and [00:18:33] Vince Menzione: estimates. [00:18:33] Dexter Hardy: What I would tell everyone that’s listening, I would invite you to consider [00:18:37] Vince Menzione: Yeah, [00:18:38] Dexter Hardy: the following. [00:18:39] Dexter Hardy: If you’re not in the marketplace with a IP, co-sale or MAC eligible solution, you’re not eligible for that. [00:18:49] Vince Menzione: That’s right. [00:18:50] Dexter Hardy: Spend. And so is that worth it for you as an organization to say, yes, we need to figure out this and get involved with that? [00:19:01] Vince Menzione: So I’m an SI and I raise my hand. I’m like, Dexter, help me. [00:19:06] Vince Menzione: What happens next? [00:19:08] Dexter Hardy: I would say. Let me introduce you to my team. [00:19:12] Vince Menzione: I love it. I love it. [00:19:13] Dexter Hardy: Um, [00:19:14] Vince Menzione: and you’ve been building your team since, uh, we go back now four years, but like yeah. You, you’ve been growing your business, hired some incredible people in your [00:19:22] Dexter Hardy: team. Yeah, we have some rock stars on our team. I’m really, really happy with my team. [00:19:25] Dexter Hardy: Uh, you know, we’re still growing and it’s, it’s a wonderful thing to be in this economy and still growing. Yes. Um, and like I said, yes, we, I would introduce you to my team and my team would then help you, uh, through. The marketplace advisory. We can help you with the health check. We can do the strategic advisory, the alignment around, here’s what we’re doing. [00:19:47] Dexter Hardy: Another thing that I’ll go ahead and put in here, if you already have listings in the marketplace and people aren’t clicking on them, we have marketplace optimization as well. [00:19:58] Vince Menzione: I love that [00:19:59] Dexter Hardy: because we, again, that conversation comes up all the time. Yeah. We put, we, we invested in Marketplace and we have our listing out there. [00:20:08] Dexter Hardy: Nobody’s clicking on it. Well, we can help you with that too. [00:20:11] Vince Menzione: Yeah. [00:20:12] Dexter Hardy: Right, because to your point, it’s not just building an ar, arbitrarily writing something about it, putting it in marketplace. Right. That’s, that’s an arbitrary approach. We’re saying how do you turn those into a lead gen, revenue gen, um, operation arm of your business. [00:20:29] Vince Menzione: Nice. [00:20:29] Dexter Hardy: Which is what we call market marketplace operating system. [00:20:33] Vince Menzione: Marketplace operating. Okay. So we got another, I got another word I need to learn. Another acronym I need to learn. [00:20:38] Dexter Hardy: Yeah. You know, I [00:20:39] Vince Menzione: less, [00:20:40] Dexter Hardy: I’ve been around Microsoft too long, I guess. [00:20:42] Vince Menzione: Yes. I [00:20:42] Dexter Hardy: created all these, [00:20:45] Vince Menzione: so, um, just perspective could, because you’ve been in the marketplace since we talked about COVID. [00:20:50] Dexter Hardy: Yeah. [00:20:51] Vince Menzione: Really. So that’s five years. Five [00:20:52] Dexter Hardy: years. Yeah. [00:20:54] Vince Menzione: Um, talk about how it’s changed from your perspective. I mean, I, we talk about it all. We talk, we have leaders like Jason and Cyril comes here and. Does, uh, speaks about some changes going on, but tell us your perspective on how it’s evolved. [00:21:08] Dexter Hardy: Um, so the marketplace is always evolving really. [00:21:12] Dexter Hardy: Um, from, from when we got in early in the marketplace. Uh, REO didn’t exist. Multi, multi-party. Private offers didn’t exist. The amount of committed spend on hyperscalers little was, wasn’t there. Um, the seller, the field sellers within the hyperscalers. Marketplace wasn’t part of their thing. So, um, you know, when that, when that frontier, not just that, not to confuse terms when that frontier opened up Yeah. [00:21:43] Dexter Hardy: Like there were, you know, it, it really wasn’t a clear path on how do you channel, how do you do sales, how do you integrate with the team? Um, and now there’s a lot more options, uh, for organizations that want to keep some of those motions together. Disti are now able to get involved with the conversation. [00:22:05] Dexter Hardy: They were kinda locked out for a while, but now with the s and the multi-party private offers and disti are in the conversation, [00:22:12] Vince Menzione: it’s lit up the disti like crazy. Yeah. In fact, we were, we just spent time with a few and some friends there and [00:22:19] Dexter Hardy: yeah. [00:22:19] Vince Menzione: Yeah, it’s been wild to watch this. [00:22:21] Dexter Hardy: Yeah. [00:22:21] Vince Menzione: We haven’t talked about AI very much. [00:22:24] Vince Menzione: I mean, we talked about it from a solution and something you put in the, the market as an agent. But we haven’t talked about the change in a big way. Um, what’s your perspective for the partners out there and how they need to think about AI and embracing it and where they are in the journey? [00:22:41] Dexter Hardy: Yeah. Um, I really, AUL said something, uh, in his, in the panel discussion that he had the other day and it, it just really resonated with me. [00:22:53] Dexter Hardy: Uh, will AI take your job? Probably not. The person who’s using AI [00:23:00] Vince Menzione: will take [00:23:00] Dexter Hardy: the job. Will take you [00:23:01] Vince Menzione: job. Yes. [00:23:02] Dexter Hardy: Same thing. That’s really [00:23:04] Vince Menzione: so true. [00:23:05] Dexter Hardy: Same thing for, same thing for companies. Yeah. If you don’t have, and I, I’ll, I’m, I, I’m really gonna ask, I should have asked Jason this question. Why isn’t there a badge for frontier firms for SDCs? [00:23:21] Dexter Hardy: That’s a solution. Partner badge, not a frontier firm. [00:23:24] Vince Menzione: Yeah, [00:23:24] Dexter Hardy: but I’ll say if your company isn’t investing in combining people and ai, you’re missing the boat. [00:23:36] Vince Menzione: Yeah. So be a frontier firm. [00:23:37] Dexter Hardy: Be a frontier firm where it doesn’t matter if you’re an si, SDC, if you are not leveraging that superpower of how do we do things faster, better, quicker. [00:23:50] Dexter Hardy: Make that part of your go to market and your operating total operations, you’re going to get left behind. [00:23:57] Vince Menzione: Yeah. We’re hearing it loud and clear. I mean, all the sessions we had yesterday. [00:24:02] Dexter Hardy: Yeah. [00:24:02] Vince Menzione: All the people like yourself that have been here are all frontier firms. They’re all companies that have leaned in, in a big way. [00:24:07] Dexter Hardy: Right. [00:24:08] Vince Menzione: Um, and in some respect, I mean, we we’re, I’m, I’m saying proceed with caution because I, I know by 2030 our world is gonna look very radically different than it looks today. [00:24:17] Dexter Hardy: Yep. [00:24:18] Vince Menzione: Uh, we just, I need to make sure we have the security and the governance and the data structure the right way so that we just don’t, things don’t just go crazy in some respects. [00:24:27] Vince Menzione: Right? [00:24:27] Dexter Hardy: Yeah. And I, I do think that, um, to your point, you have to, we still have to keep the human factor in everything that we’re doing. Um, there is, again, it’s AI plus your experience that makes you better. [00:24:46] Vince Menzione: Yeah, agreed. [00:24:47] Dexter Hardy: AI in the hands of someone who has no idea what they’re doing is just a, it’s a faster way to failure, right? [00:24:53] Dexter Hardy: Yeah. Because they have, they still don’t understand the concepts. And so I really want to make sure that, you know, when you think about ai, think about it from the context of experience, right? Yeah. [00:25:06] Vince Menzione: And yeah, we can go, we can go down a, a whole discussion point here about ethics and what I’ll call AI for good. [00:25:14] Vince Menzione: Mm-hmm. Like I said, having the right approach, having an ethical approach. We talked about Microsoft on stage yesterday with people like Brad Smith, who, uh, there’s people that have this, this right philosophy and approach to ai. Right. That [00:25:29] Dexter Hardy: right. [00:25:29] Vince Menzione: It will do good for the world and not bad for the world. [00:25:32] Vince Menzione: Yeah. [00:25:33] Dexter Hardy: And I think that has to be, well, I’ll just speak for myself. Can you do something and should you do something [00:25:42] Vince Menzione: Yeah. [00:25:43] Dexter Hardy: You have to, that should be a question that you’re asking yourself. You should be evaluating and you have to have whatever your moral compass is that has to align with your moral compass. [00:25:53] Dexter Hardy: Yeah. Because they’re, you know, because with AI the can you do something becomes a lot bigger. Yeah. [00:26:02] Vince Menzione: Good point. Good point. [00:26:03] Dexter Hardy: Should you do it well, you know, greater good. I think as a, as a collective, one of the things that’s. If it hasn’t rained true. Uh, we all live on this planet. We all are part of the, we’re all in part of a connected ecosystem. [00:26:21] Dexter Hardy: Um, and so can we do it? Should we do it? Those are questions that we need to, you know, really think about as we continue to leverage AI and do the things that we’re doing. I mean, there’s, there’s a lot of opportunities. [00:26:36] Vince Menzione: Good points, good points. So for partners watching, listening today, um, two, couple things. [00:26:43] Vince Menzione: First of all, it’s changing fast. We need like, what would be, we’re at the beginning of 2026. We’re the first quarter, 2026, maybe the end of the first quarter at this point. [00:26:53] Dexter Hardy: Yeah. [00:26:54] Vince Menzione: What is the one or two or three things that partners need to go do differently or better? And then, um, what would you say to them about marketplace and embracing marketplace? [00:27:09] Dexter Hardy: So I’m gonna answer the second question first. [00:27:12] Vince Menzione: Okay. Sounds good. [00:27:14] Dexter Hardy: Get in the marketplace. [00:27:15] Vince Menzione: Get in the marketplace, [00:27:17] Dexter Hardy: period. [00:27:17] Vince Menzione: Like why wouldn’t you be in the marketplace? [00:27:20] Dexter Hardy: Every hyperscaler has doubled down, tripled down. Yeah. On their marketplace. Microsoft had multiple marketplaces, now it’s just one. [00:27:28] Vince Menzione: Yeah. [00:27:29] Dexter Hardy: Writing should be all over the wall. Not that [00:27:31] Vince Menzione: one. There is, there is no market without marketplace. I mean, literally today, the old way, days of selling, the old days of co-selling are gone. [00:27:39] Dexter Hardy: Yeah. [00:27:39] Vince Menzione: Like the days when we, we got pos and we, we sent a, an Excel spreadsheet to Microsoft to tell ’em about the deals that were co-sell. [00:27:47] Vince Menzione: Ready? Those days are gone. So you’re saying we’ve gotta be in the marketplace now and then, what would you say maybe the one thing that’s, let’s limit it to one for all of our amazing viewers, listeners, and ultimate partner guests, when when you, when I see you in Bellevue again, ’cause you’re gonna be in Bellevue, May 11th to the 13th again. [00:28:08] Vince Menzione: Absolutely. With us helping lead the marketplace conversation. What do they need to be doing now? Right now? Besides getting the marketplace? [00:28:18] Dexter Hardy: Besides getting the marketplace, I, I would, I would do a hard look at operations. [00:28:24] Vince Menzione: Operations. [00:28:25] Dexter Hardy: Like a lot of companies, they’re growing and they, what is it? How are we looking internally in our organizations to figure out again, can we do it? [00:28:34] Dexter Hardy: Should we do it? Companies need to focus on their superpower, even, even the big ones, right? Um, being. Not having the focus, not look, looking at or listening to your why as an organization can, can put you in a, in a really weird space. And so, uh, with everyone being able to grow and do what we’re doing, I would say lean into your why, [00:29:01] Vince Menzione: like into your why. [00:29:02] Dexter Hardy: Lean into your why. [00:29:03] Vince Menzione: I think too, I think what you, what you’re saying here, and I’m, my, my reaction to it too is that, uh, we’re, we’re so caught up in the moment right now. And things are changing, so it feels like they’re changing so fast, like coming back to philanthropic and [00:29:20] Dexter Hardy: yeah. [00:29:20] Vince Menzione: What’s evolved just in the last month or so that people are taking their eye off the why or the wall, so to speak and reacting? [00:29:29] Vince Menzione: Is that, is that your point? [00:29:31] Dexter Hardy: Yeah, that’s my point and, and I’ll give you an example. So AI is different from the following technology, but. And I both were around for the blockchain, blockchain, blockchain conversation. [00:29:45] Vince Menzione: Yeah. [00:29:45] Dexter Hardy: And if you weren’t doing blockchain, you weren’t part of the conversation. I invite you to consider how many conversations have you heard about blockchain do? [00:29:56] Dexter Hardy: Again, AI is a little bit different because it’s, it’s an enabler. It’s, it’s, it’s, it, it does a lot more than that. But I, I will say. AI is gonna become table stakes. And that’s why I say you have to, you have to embrace it as an organization. Yeah. And if you’re not, you’re gonna get left behind. [00:30:13] Vince Menzione: Okay. It’s a drop. [00:30:14] Vince Menzione: Drop the mic moment there. So drop the mic. I’m gonna ask you one more question, personal question. Yeah. I’d love to ask this of every single one of my guests. [00:30:22] Dexter Hardy: Yep. [00:30:23] Vince Menzione: I probably have asked this to you before, but I’m gonna ask it to you again. [00:30:26] Dexter Hardy: Yes. [00:30:28] Vince Menzione: You are hosting a dinner party. You can have this dinner party anywhere in the world. [00:30:32] Vince Menzione: We could talk about locations as well, and you can invite any three guests from the present or the past to this amazing dinner party. [00:30:41] Dexter Hardy: Mm-hmm. [00:30:42] Vince Menzione: Whom would you invite today and why? [00:30:48] Dexter Hardy: Wow. So the last time I answered that question, for those who didn’t hear the first podcast, it was Barack Obama. [00:30:56] Vince Menzione: Yeah. Nelson [00:30:57] Dexter Hardy: Mandela. [00:30:58] Dexter Hardy: And my great-grandparents. [00:30:59] Vince Menzione: Your great-grandparents. I remember your great-grandparents [00:31:02] Dexter Hardy: In this conversation, it’s gonna be more than three people. I’m sorry. [00:31:07] Vince Menzione: All right. But [00:31:07] Dexter Hardy: it make [00:31:08] Vince Menzione: some exceptions here. We’ll make them. [00:31:10] Dexter Hardy: It would be my great-grandparents. Still [00:31:13] Vince Menzione: nice. [00:31:14] Dexter Hardy: My parents and my children. [00:31:18] Vince Menzione: Very cool. [00:31:19] Dexter Hardy: Because I want to look back and let them see the same reason that I had them there before. [00:31:25] Vince Menzione: Yeah. [00:31:26] Dexter Hardy: Look at what you started. [00:31:27] Vince Menzione: Nice. I love that. [00:31:29] Dexter Hardy: Look at the continuation of your legacy in my parents. [00:31:32] Vince Menzione: Yeah. [00:31:32] Dexter Hardy: Look at what I have been able to build because of the investments and the things that you’ve poured into the love, the energy, the effort, the sacrifice, and then the sacrifices that I’m making to pass into that legacy. [00:31:46] Dexter Hardy: The next legacy. So this would be a. This is why I would say leaning to your why, like understand the importance of family. [00:31:54] Vince Menzione: Tell us about your great, your great grandparents. You told me about this on the last podcast for those who didn’t, didn’t listen in. [00:32:01] Dexter Hardy: Yeah. [00:32:02] Vince Menzione: And don’t have the inclination to go back. [00:32:05] Dexter Hardy: Yeah. [00:32:05] Vince Menzione: But I think it’s a great story. [00:32:06] Dexter Hardy: Yeah. So, you know, growing up in the south [00:32:10] Vince Menzione: Yeah. [00:32:10] Dexter Hardy: Alabama specifically, uh, my great grandparents were part of, you know, slavery era. [00:32:16] Vince Menzione: Yep. [00:32:16] Dexter Hardy: Jim Crow. Jim Crow. Crow. Yeah. The whole. [00:32:21] Dexter Hardy: The history of the United States and what, how it was built, you know, [00:32:26] Vince Menzione: an important part of the history of the United States, by the way, that we all should never forget. [00:32:29] Dexter Hardy: Yeah. So again, some of those, some of the ceilings that are out there now, there wasn’t even an option for. [00:32:36] Vince Menzione: Yeah. [00:32:36] Dexter Hardy: And so that’s why I really wanted them to, I would really want them to be here to see something that they probably could never even conceive as an option of, of it being. [00:32:47] Dexter Hardy: Uh, to be able to see where things are and then to, you know, why my kids, if this is where we are right now, I want you to dream big. The same amount of energy it takes to think small is the same amount [00:33:04] Vince Menzione: of energy it takes to think big. Dream big. Dream big. Dream. [00:33:09] Dexter Hardy: Dream big. [00:33:10] Vince Menzione: I think we’re gonna leave on that message. [00:33:12] Dexter Hardy: Yeah, [00:33:12] Vince Menzione: that’s a great message. [00:33:13] Dexter Hardy: Awesome. [00:33:14] Vince Menzione: So great to see you, my friend. It’s [00:33:16] Dexter Hardy: always a pleasure [00:33:16] Vince Menzione: to be with you, so always a real pleasure for me as well. [00:33:19] Dexter Hardy: Yeah, [00:33:19] Vince Menzione: and I want to thank you for watching and listening and being part of Ultimate Partner and the Ultimate Partner YouTube channel and our great guest and friend, Dexter Hardy. [00:33:30] Vince Menzione: Great to see you again. [00:33:31] Dexter Hardy: Always a pleasure us. Thank you, [00:33:33] Vince Menzione: sir. [00:33:33] Dexter Hardy: All right. Appreciate it. Thank you. Thanks. [00:33:35] Vince Menzione: Don’t forget, ultimate Partner Live is coming soon, May 11th through the 13th in beautiful Bellevue, Washington. I hope to see you there.

Spark of Ages
SaaS Isn't Dying. Bad Deals Are/Ankur Srivastava, Priya Ramachandran - Flywl, Cloud Procurement, SaaS-pocalypse ~ Spark of Ages Ep 59

Spark of Ages

Play Episode Listen Later Mar 13, 2026 54:44 Transcription Available


We unpack why the “SaaS-Pocalypse” is less about software dying and more about buyers finally right sizing cloud and marketplace deals with better data. We dig into AI unit economics, token driven cost volatility, and how procurement, FinOps, and venture capital are being rewritten in real time. • Flywl as a cloud meta marketplace across AWS, Azure, and Google Cloud • Buyer pain and buyer empathy as the product design center • Why AI inference costs make traditional FinOps reactive • Treating a marketplace purchase as a transaction lifecycle asset • Real time consumption tracking, alerts, and contract renegotiation timing • Outcome based pricing challenges with token variability and agentic workflows • Revenue recognition uncertainty in consumption and outcome models • Why humans still matter in go to market despite AI agents • The data cleanup problem in procurement and the need for universal product IDs • Why enterprises are not rushing to build all SaaS internally with AI • 2026 VC dynamics, mega rounds, capital concentration, and what counts as real recurring revenue “SaaS-Pocalypse” makes for a great headline, but the real shockwave is quieter and more disruptive: enterprise buyers finally understand their cloud environment well enough to demand better deals, better governance, and real proof of value. We sit down for a roundtable on cloud marketplaces, AI unit economics, and the new reality of software procurement where a purchase is no longer a static line item, it's a living asset you have to monitor, benchmark, and continuously right size. Ankur Srivastava, CEO and founder of Flywl, explains why he built a cloud meta marketplace to unify buying and selling across AWS Marketplace, Azure, and Google Cloud and why “buyer empathy” is the only way to fix a broken procurement playbook. Priya Ramachandran, founder and managing partner at Foster Ventures, connects the dots from operator experience to investing, and breaks down why traditional FinOps can't keep up with AI inference costs, token volatility, and outcome-based pricing models like per ticket resolved. Then we zoom out to the 2026 venture capital environment: mega rounds, capital concentration, and the debate over whether AI-native efficiency makes old funding assumptions obsolete. Along the way, we tackle an agentic economy question: when algorithms negotiate with algorithms, what happens to trust, brand, and human relationships in go to market?Ankur Srivastava: https://www.linkedin.com/in/ankursrivas/Ankur Srivastava is the CEO and Founder of Flywl, the world's first cloud meta-marketplace transforming how enterprises buy and sell software across AWS, Azure, and Google Cloud. Previously, he was an elite sales leader at Amazon Web Services (AWS), where he spent five years as Head of Field and Customer Business Development for the AWS Marketplace.Priya Ramachandran: https://www.linkedin.com/in/sivapriyaramachandran/Priya Ramachandran is the Founder and Managing Partner at Foster Ventures, an early-stage VC firm she built from the ground up to act as the "startup of the VC world". She is an operator-turned-investor with significant experience building and scaling products at companies like Coupa Software, BetterCloud, and Intel.Website: https://www.position2.com/podcast/Rajiv Parikh: https://www.linkedin.com/in/rajivparikh/Sandeep Parikh: https://www.instagram.com/sandeepparikh/Email us with any feedback for the show: sparkofages.podcast@position2.com

The Ravit Show
K2view's Partnership with AWS, Marketplace, 2026 Prediction

The Ravit Show

Play Episode Listen Later Feb 11, 2026 4:54


AI agents did not suddenly appear this year. What changed is that enterprises are finally ready to use them. At AWS re:Invent, I spoke with Ronen Schwartz, CEO of K2view, to talk about what has really shifted in the agent space from last year to this year and why this moment feels different!!!!Here is what we covered • What changed in the agent landscapeLast year was about ideas and experiments. This year is about execution. Ronen shared why agents are moving from demos into real enterprise workflows • K2View on the AWS MarketplaceWe talked about what it means for K2View to be available on the marketplace and how customers can make the most of it, from faster onboarding to simpler adoption • The AWS and K2View partnershipWe discussed how the partnership with AWS helps customers deploy agent driven use cases faster while keeping control over their data • Agentic AI and the re:Invent keynotesWe reflected on the keynote announcements and why agentic AI has become a central theme for AWS and its ecosystemIf you are trying to separate agent hype from what is actually working in production, this conversation brings a grounded perspective!#data #ai #awsreinvent #agents #agenticai #aws #enterprise #k2view #theravitshow

The Ravit Show
Equinix Data Centres, AWS Partnership, Customer Stories and more

The Ravit Show

Play Episode Listen Later Feb 5, 2026 6:26


Most cloud conversations ignore one simple truth. AI only moves as fast as your connectivity. At AWS re:Invent, I spoke to Ed Baichtal, Principal Engineer at Equinix, to talk about what actually sits underneath modern cloud and AI architectures!!!!A few takeaways from the conversation- Equinix operates more than 270 data centers worldwide and acts as the physical home for servers, networks, and cloud on ramps- Equinix is the largest AWS on-ramp provider, with native AWS connectivity built directly into its data centers- The Equinix Fabric Cloud Router is now available on the AWS Marketplace, making multi-cloud connectivity much simpler- Customers can virtually connect up to 25 Gbps to AWS across different regions without deploying physical hardware- AI workloads are pushing serious demand for higher throughput and more reliable connectivity between cloudsOver 3,000 customers are already connected through the Equinix Fabric, which means new connections can happen virtuallyOne customer moved massive volumes of data to AWS in under 30 days using the Fabric Cloud RouterLooking ahead, Equinix plans to introduce Fabric Intelligence in Q1 2026 to make multi-cloud and NeoCloud connectivity even smarterIf you are building AI or multi-cloud systems, this layer matters more than most people realize.#data #ai #awsreinvent #aws #agents #awspartners #agenticai #theravitshow

The Ravit Show
How SREs are Leveraging AI: Coding Agents and the Future of Shell Scripting

The Ravit Show

Play Episode Listen Later Jan 23, 2026 7:53


The future of reliability is not one tool. It is a team of agents working together. At AWS re:Invent, I had a chat with Francois Martel, Field CTO at NeuBird.ai, to talk about how AI is changing the way developers and SREs handle reliability in the real world.Here are the key takeaways from our conversation-- Coding agents are becoming the front door to AITools like GitHub Copilot and Cursor are getting massive adoption. When paired with NeuBird's Hawkeye agentic SRE server, these agents can jump straight into root cause analysis and even take action to remediate issues-- SREs are a natural fit for agentsSREs already live in the command line and think in scripts. Coding agents are an easy and practical entry point for bringing AI into day to day SRE workflows-- Agent adoption is speeding upWe are past experimentation. Customers are seeing value from early use cases, which is pushing broader and faster adoption of agent based systems-- Enterprise security still mattersFor larger organizations, NeuBird can deploy the agent inside the customer's VPC. The data stays in their environment and the full data path remains under their control-- AWS partnership momentumNeuBird is launching a pay as you go offering on the AWS Marketplace. This makes it one of the first agentic SRE servers you can try without long term commitment and connect to tools like AWS, Datadog, Dynatrace, and GrafanaIf you want to see how agentic SRE works in practice, you can start with the pay as you go option or the two week free trial and pairing it with your favorite coding agent.It was great catching up with François again and seeing how NeuBird is pushing the agentic SRE space forward.#data #ai #awsreinvent #aws #agents #awspartners #copilot #agents #theravitshow

WBSRocks: Business Growth with ERP and Digital Transformation
WBSP807: Grow Your Business by Learning from Enterprise Software Stories - Sep 2025, Ep 33, an Objective Panel Discussion

WBSRocks: Business Growth with ERP and Digital Transformation

Play Episode Listen Later Jan 13, 2026 62:19


Send us a textERP and adjacent platform vendors are simultaneously deepening vertical specialization, expanding AI distribution, and accelerating ecosystem-led growth. M&A activity from Advantive acquiring PINPoint, SYSPRO acquiring DATASCOPE, and Sage moving to acquire Fyle reinforces a continued focus on capability-driven expansion rather than broad horizontal reinvention. Product and platform updates from Deltek, Rootstock Software, and NetSuite emphasize AI-assisted productivity, localization, and integration flexibility as table stakes for mid-market and upper-mid-market buyers. At the same time, distribution and partnership strategies—such as Pipefy partnering with Oracle, Sage Intacct listing AI agents on AWS Marketplace, and Versori partnering with SYSPRO—signal a broader shift toward ecosystem-led AI adoption, where value is increasingly delivered through connectors, agents, and composable services rather than monolithic ERP releases.In today's episode, we invited a panel of industry analysts for a live discussion on LinkedIn to analyze current enterprise software stories. We covered many grounds, including the direction and roadmaps of each enterprise software vendor. Finally, we analyzed future trends and how they might shape the enterprise software industry.Video: https://www.youtube.com/watch?v=gLp0RsgggwsQuestions for Panelists?

Irish Tech News Audio Articles
Jentic targets enterprise AI adoption with API readiness platform

Irish Tech News Audio Articles

Play Episode Listen Later Dec 18, 2025 8:46


Interview with Dorothy Creaven and Michael Cordner at AWS re:Invent Dublin-based startup Jentic was the first Irish company to complete the AWS Generative AI Accelerator, which concluded recently at AWS re:Invent in Las Vegas. The company is now focused on building enterprise awareness of its platform, supported by the launch of its AI Readiness Scorecard and its listing on AWS Marketplace. Founded in 2024 by Sean Blanchfield, Michael Cordner, and Dorothy Creaven, Jentic applies middleware and enterprise integration engineering to AI adoption, focusing on how APIs are defined, governed and safely executed by automated and agentic systems. AI adoption with API readiness platform Jentic Jentic operates at the integration layer, working with existing enterprise systems and APIs to make them clearer, more structured and more governable. This allows organisations to connect AI systems to real business infrastructure in a controlled and observable way, without replacing existing platforms or bypassing established security and compliance processes. Built on Enterprise Infrastructure Experience The company's approach is shaped by the founders' backgrounds in building large-scale infrastructure. Blanchfield previously co-founded Demonware, acquired by Activision Blizzard, and PageFair. Cordner co-founded Mindconnex, while Creaven previously led Rent the Runway's Irish operations. Speaking to Irish Tech News at AWS re:Invent, Michael Cordner, CTO of Jentic, said many enterprises are now encountering limits in how their systems were originally built. "We got away with cutting corners for 20 years when we were developing APIs for developers," said Cordner . "But now we're trying to let AI loose on those same APIs, and the standards are much more stringent. Even the most intelligent AI in the world is useless without the right information on how to actually use a system." From Jentic's perspective, the current interest in AI exposes long-standing weaknesses in enterprise integration. Automated systems can reason and decide, but they can only act through APIs. If those interfaces are poorly documented, inconsistently structured or weakly governed, behaviour becomes unpredictable. "We're a business logic and infrastructure layer for AI agents," explains Dorothy Creaven, COO of Jentic. "Software has always been built on APIs, but for AI to connect properly to enterprise systems, there has to be something that can make sense of those APIs and turn them into workflows organisations can rely on." Addressing Enterprise Control and Governance A recurring issue Jentic encounters with enterprise customers is organisational hesitation. Senior leadership often wants progress on AI strategy, while technology and security teams are concerned about control, traceability and risk. "Everyone is afraid to let AI loose in their organisation," Creaven observes. "There's a real concern about what systems might do when nobody is watching, whether actions can be traced, and how failures are handled." To address this, Jentic's platform includes a sandboxed execution environment that mirrors production APIs. This allows organisations to test AI-driven workflows, observe behaviour and understand failure modes before anything is connected to live systems. "We provide an environment that mirrors real APIs, but in a way that's safe," Creaven comments. "You can see exactly what's happening, with auditability and logging, and you can only move forward once you're confident the behaviour is correct." Launch of the AI Readiness Scorecard This approach underpins the launch of Jentic's AI Readiness Scorecard, a free, automated assessment tool introduced at AWS re:Invent. The scorecard evaluates APIs across multiple dimensions, including structure, security, documentation quality and discoverability. According to Jentic, its analysis of more than 1,500 well-known APIs highlights repeated gaps. These include missing authentication details, invalid OpenAPI specifications, i...

AWS for Software Companies Podcast
Ep181: AWS Agentic AI Marketplace as your Growth Multiplier with Atlassian and Netskope

AWS for Software Companies Podcast

Play Episode Listen Later Dec 8, 2025 33:37


Matt Yanchyshyn, AWS Marketplace and Partner Services VP, reveals how AI agents are transforming enterprises worldwide while Atlassian and Netskope leaders share strategies for scaling up Agentic AI marketplace deals.Topics Include:Matt Yanchyshyn of AWS opens with massive shift to multi-agent production systemsEnterprise software seeing huge AI adoption: 33% will include AI by year endAutomated agents now handle Matt's daily workflow, prioritizing emails and messages autonomouslyReal business transformation across financial reporting, demand forecasting, and automated incident managementAWS Marketplace team productivity up 31%, deploying software 27% faster with agentsNew agent mode for Marketplace uses autonomous data collection improving customer experiencesSuccess requires proper data governance with fine-grained access controls for safe operationsQ Developer and Qiro CLI integrate seamlessly into developer workflows without disruptionAWS maintains 400+ MCP servers, shared spec farms enabling teams to collaborate effectivelyEmbedded experts and principal engineers spread agent knowledge and measure productivity closelyAndy Horwitz notes security leads Marketplace growth, primarily through private offer expansionNetskope's new DSPM product addresses AI data security, driving strong customer adoption momentumEnterprise customers now ask if vendors are AWS badged, deals 41-58% largerAndy advises ISVs: prepare sales teams thoroughly, focus co-sell, secure executive buy-inBill Hustad emphasizes distinct marketplace strategy, seller training, and ruthless operational tracking for successParticipants:Bill Hustad - Global Head of Channel and GTM Ecosystems, AtlassianAndy Horwitz – SVP, Global Partner Ecosystems, NetskopeMatt Yanchyshyn – VP, AWS Marketplace & Partner Services, Amazon Web ServicesSee how Amazon Web Services gives you the freedom to migrate, innovate, and scale your software company at https://aws.amazon.com/isv/

Ultimate Guide to Partnering™
278 – AWS Marketplace Unlocked: The AI Agent & Tools Strategy You Need to Win

Ultimate Guide to Partnering™

Play Episode Listen Later Nov 30, 2025 33:01


What if the key to unlocking peak performance is not pushing harder but mastering the art of mental focus and well-being? I traveled to LA to be at Mastery Labs to unlock the secrets of high performance with Michael Gervais, a renowned expert in mindfulness and psychology. This is our annual Holiday episode of Ultimate Guide to Partnering and my gift to you, our amazing listeners, followers, and community. Michael shares how mental training can revolutionize personal and professional approaches to challenges, from his roots in elite sports to shaping corporate cultures. He explores the pivotal moments that sparked his passion, revealing how psychological skills like confidence and focus can be trained to thrive in any environment. This episode highlights actionable strategies for balancing well-being with ambition, applying insights from sports to business, and using mindfulness to direct focus effectively. With stories ranging from surfing competitions to Microsoft's cultural transformation under Satya Nadella, Michael offers a holistic perspective on performance psychology and sustainable success. Thank you for supporting Ultimate Partner and the Ultimate Guide to Partnering Podcast. Please tell your friends, subscribe, and leave us up to a 5-star Review, as it helps us get more amazing guests.

AWS re:Think Podcast
Episode 43: Rethinking Data Infrastructure for AI Agents with Tacnode Context Lake

AWS re:Think Podcast

Play Episode Listen Later Nov 18, 2025 29:43


Data Infrastructure built for humans over the past few decades aren't ideal for AI Agents. In this episode we join Tacnode founder and CEO Xiaowei Jiang to discuss "Context Lakes" - Data Infrastructure built to provide the context, scale and performance needed by AI Agents.Learn more about Tacnode Context Lake:tacnode.ioTacnode Context Lake on AWS:https://aws.amazon.com/blogs/apn/powering-real-time-ai-with-tacnode-context-lake-on-aws/Tacnode on AWS Marketplace:https://aws.amazon.com/marketplace/seller-profile?id=seller-cchnpb2cfdvoqAWS Hosts: Nolan Chen & Malini ChatterjeeEmail Your Feedback: rethinkpodcast@amazon.com

This Week in Startups
Is investing REALLY the hardest job in tech? A TWIST VC Roundtable (ft. Deedy Das and Jay Eum) | E2204

This Week in Startups

Play Episode Listen Later Nov 6, 2025 83:50


Register for Founder University Japan's kickoff! https://luma.com/cm0x90mkToday's show:*On TWiST, Jason welcomes an all-star VC panel — Deedy Das of Menlo Partners and Jay Eum of GFT Ventures — for a deep dive into the shocking scale of early-stage AI raises, a transitional moment for investors, the growing importance of the “prosumer” market, ChatGPT's insane smile curves, and much much more.IN THIS EPISODEWhat the panelists make of Roelof Botha's exit from Sequoia… and is he really going anywhere…Why Jason says VC is no longer the best way to get rich…Why so many private companies are growing SO HUGE before going public…And much more!Timestamps:(00:03:37) Jason is fresh from surviving Riyadh traffic but he's here and introducing our all star panel(00:04:03) Why Jason compares Riyadh to Silicon Valley in the 1960s(00:05:21) Friend of the Pod Roelof Botha is stepping down at Sequoia… our insiders try to guess what might have happened…(10:00) Crusoe - Crusoe is the AI factory company. Reliable infrastructure and expert support. Visit crusoe.ai/startup to reserve your capacity for the latest GPUs today.(00:13:11) Deedy moved up at Menlo without being a venture native… he shares the secrets behind his rise.(00:19:09) Was Roelof wrong about “return-free risk”? Does more capital always = more great companies?(20:00) Northwest Registered Agent - Form your entire business identity in just 10 clicks and 10 minutes. Get more privacy, more options, and more done—visit https://www.northwestregisteredagent.com/twist today!(00:26:54) With so many private companies growing SO HUGE… when is the right time to go public? Considering the case of Glean and Stripe…(30:00) AWS Marketplace - If you're ready to really accelerate your sales cycle, AWS Marketplace is your next stop. Head to https://aws.com/startups to learn more.(00:30:07) Why Jason says venture capital is no longer the best way to get rich(00:32:34) Why AI apps are so appealing to enterprises after years of paying for SaaS(00:36:32) The growing importance of “prosumers”(00:37:31) Why Deedy says a smile curve is the most beautiful depiction of “Product Market Fit”(00:44:36) Why it's still tough to raise pre-seed money, even during an AI “boom”!(00:46:08) Why Jason says the hardest job in the tech ecosystem is being an investor(00:55:52) “Time is one of the primary drivers of venture capital return.” - Jay Eun(00:57:42) Deedy on the shocking amounts being raised by early-stage AI companies(01:00:21) Just how much DO VCs work compared to founders? The panel compares notes.(01:02:53) Are some investors not doing diligence? Deedy on the speed of some AI deals.(01:16:51) The panel picks their fav portfolio company of the moment (or one of their faves)Subscribe to the TWiST500 newsletter: https://ticker.thisweekinstartups.comCheck out the TWIST500: https://www.twist500.comFollow Alex:X: https://x.com/alexLinkedIn: ⁠https://www.linkedin.com/in/alexwilhelmFollow Jason:X: https://twitter.com/JasonLinkedIn: https://www.linkedin.com/in/jasoncalacanisThank you to our partners:Crusoe - Crusoe is the AI factory company. Reliable infrastructure and expert support. Visit crusoe.ai/startup to reserve your capacity for the latest GPUs today.Northwest Registered Agent - Form your entire business identity in just 10 clicks and 10 minutes. Get more privacy, more options, and more done—visitAWS Marketplace - If you're ready to really accelerate your sales cycle, AWS Marketplace is your next stop. Head to https://aws.com/startups to learn more.Check out Jason's suite of newsletters: https://substack.com/@calacanisFollow TWiST:Twitter: https://twitter.com/TWiStartupsYouTube: https://www.youtube.com/thisweekinInstagram: https://www.instagram.com/thisweekinstartupsTikTok: https://www.tiktok.com/@thisweekinstartupsSubstack: https://twistartups.substack.comSubscribe to the Founder University Podcast: https://www.youtube.com/@founderuniversity1916

The Water Tower Hour
Inside Intrusion (INTZ): How Reputation-Based Cyber Defense Is Powering Sustainable Growth

The Water Tower Hour

Play Episode Listen Later Oct 20, 2025 39:17


Send us a textIn this episode of WTR Small-Cap Spotlight, Tony Scott, Chief Executive Officer, and Kimberly Pinson, Chief Financial Officer, of Intrusion Inc. (NASDAQ: INTZ) join co-hosts James Kisner, Managing Director of Technology Research at Water Tower Research, and Tim Gerdeman, Vice Chair, Co-Founder, and Chief Marketing Officer of Water Tower Research.The conversation dives into how Intrusion's Shield platform uses reputation-based threat intelligence and artificial intelligence to detect and block high-risk communications in real time. Scott and Pinson discuss the company's five consecutive quarters of sequential growth, the expansion of Shield Cloud into the AWS Marketplace (with Microsoft Azure coming later in 2025), and emerging opportunities in school safety, utilities, and critical infrastructure.They also touch on Intrusion's disciplined financial strategy, strong gross margins, and growing managed-service-provider channel—all of which position the company for sustained success in both government and commercial cybersecurity markets.

The ERP Advisor
The ERP Minute Episode 196 - July 22nd, 2025

The ERP Advisor

Play Episode Listen Later Jul 22, 2025 3:20


Deltek made a major announcement to start the week, announcing the latest version of Deltek Costpoint. Procore Technologies Inc. announced it has achieved a Federal Risk and Authorization Management Program (FedRAMP) “In Process” designation and is now listed on the FedRAMP Marketplace. Sage announced the availability of Sage Intacct in the new AI Agents and Tools category of AWS Marketplace. Qlik announced the availability of Qlik Cloud Analytics in the new AI Agents and Tools category of AWS Marketplace. Rounding out the week, Aptean announced the expansion of its Global Food & Beverage ERP Partner Program.Connect with us!https://www.erpadvisorsgroup.com866-499-8550LinkedIn:https://www.linkedin.com/company/erp-advisors-groupTwitter:https://twitter.com/erpadvisorsgrpFacebook:https://www.facebook.com/erpadvisorsInstagram:https://www.instagram.com/erpadvisorsgroupPinterest:https://www.pinterest.com/erpadvisorsgroupMedium:https://medium.com/@erpadvisorsgroup

IT Visionaries
What IT Leaders Can Learn from How the Government Buys Tech

IT Visionaries

Play Episode Listen Later Jun 26, 2025 44:04


IT leaders in regulated industries know the pain of navigating outdated, slow procurement systems – especially when critical missions depend on modern tools. In this episode, Bryana Tucci, Lead of the AWS Marketplace for the US Intelligence Community, shares how government agencies are overcoming legacy procurement bottlenecks to access cutting-edge software, AI tools, and cloud services faster and more securely.Listeners will gain insight into:Why traditional government procurement can take up to two years – and how that's changing.How air-gapped environments complicate innovation and what's being done about it.How generative AI is reshaping national security workflows.What kinds of tech companies are best positioned to succeed in the public sector.This episode is a must-listen for IT leaders interested in procurement innovation, cloud adoption in secure environments, and where AI fits into the future of public sector IT. Enjoy!Key Moments00:00 Meet Bryana Tucci, AWS06:58 The Pain Point: Procurement Then vs. Now11:31 Unique Challenges in Public Sector Tech15:55 The Long Road to Selling in Government19:23 Vetting and Onboarding Sellers (how to meet federal standards)23:49 Government + AI: A Game-Changer30:34 Cost Efficiency, Saving Time, and the Future of Procurement41:46 What's Next for AWS Marketplace ---Produced by the team at Mission.org and brought to you by Brightspot.

AWS re:Think Podcast
Episode 38: AI Native Databases with Weaviate

AWS re:Think Podcast

Play Episode Listen Later Apr 30, 2025 24:47


Join Jobi George and Tony Le from Weaviate as we discuss how their AI Native Vector Database is powering modern AI applications. We begin with an intro to Vector Databases followed by common use cases, and how they fit into Agentic Workflows. We also talk about the advantages of using an AI Native Database from the Open Source community. To learn more:Website - www.weaviate.ioLinkedin - https://www.linkedin.com/company/weaviate-io/AWS Marketplace - https://aws.amazon.com/marketplace/seller-profile?id=seller-jxgfug62rvpxsDeveloper Community - https://weaviate.io/developers/weaviate/model-providers/awsInstagram - https://www.instagram.com/weaviate.io/Youtube - https://www.youtube.com/@WeaviateAWS Hosts: Nolan Chen & Malini ChatterjeeEmail Your Feedback: rethinkpodcast@amazon.com

AWS for Software Companies Podcast
Ep096: Navigating Cloud Marketplaces: How Suger is Streamlining Software Distribution

AWS for Software Companies Podcast

Play Episode Listen Later Apr 22, 2025 15:53


Jon Yoo, CEO of Suger, shares how his company automates the complex & challenging workflows of selling software through cloud marketplaces like AWS.Topics Include:Jon Yoo is co-founder/CEO of Suger.Suger automates B2B marketplace workflows.Handles listing, contracts, offers, billing for marketplaces like AWS.Co-founder previously led Confluent's marketplace enablement product.Confluent had 40-50% revenue through cloud marketplaces.Required 10-20 engineers working solely on marketplace integration.Engineers prefer core product work over marketplace integration.Product/engineering leaders struggle with marketplace deployment requirements.Marketplace customers adopt without marketing, creating unexpected management needs.Version control is challenging for marketplace-deployed products.License management through marketplace creates engineering challenges.Suger helps sell, resell, co-sell through AWS Marketplace.Marketplace integration isn't one-time; requires ongoing maintenance.Business users constantly request marketplace automation features.Suger works with Snowflake, Intel, and AI startups.Data security concerns drive self-hosted AI deployments.AI products increasingly deploy via AMI/container solutions.AI products use usage-based pricing, not seat-based.Usage-based pricing creates complex billing challenges.AI products are tested at unprecedented rates.Two deployment options: vendor cloud or customer cloud.SaaS requires reporting usage to marketplace APIs.Customer-hosted deployment simplifies some billing aspects.Marketplaces need integration with ERP systems.Version control particularly challenging for AI products.Companies need automated updates for marketplace-deployed products.License management includes scaling up/down and expiration handling.Suger aims to integrate with GitHub for automatic updates.Participants:· Jon Yoo – CEO and Co-founder, SugerSee how Amazon Web Services gives you the freedom to migrate, innovate, and scale your software company at https://aws.amazon/isv/

AWS for Software Companies Podcast
Ep090: Triple-Digit Growth - How Leading Partners Successfully Leverage AWS Marketplace

AWS for Software Companies Podcast

Play Episode Listen Later Apr 3, 2025 48:21


AWS partners Braze, Qualtrics, and Tealium share strategies for marketplace success, vertical industry expansion, and generative AI integration that have driven significant business growth. Topics Include:Jason Warren introduces AWS Business Application Partnerships panel.Three key topics: Marketplace Strategy, Vertical Expansion, Gen-AI Integration.Alex Rees of Braze, Matthew Gray of Tealium, and Jason Mann of Qualtrics join discussion.Braze experienced triple-digit percentage growth through AWS Marketplace.Braze dedicating resources specifically to Marketplace procurement.Tealium accelerated deal velocity by listing on Marketplace.Tealium saw broader use case expansion with AWS co-selling.Qualtrics views Marketplace listing as earning a "diploma."Understanding AWS incentives and metrics is crucial.Knowing AWS "love language" helps partnership success.Braze saw transaction volume increase between Q1 and Q4.Aligning with industry verticals unlocked faster growth.Tealium sees bigger deals and faster close times.Tealium moved from transactional to strategic marketplace approach.Private offers work well for complex enterprise agreements.Qualtrics measures AWS partnership through "influence, intel, introductions."AWS relationships help navigate IT and procurement challenges.Propensity-to-buy data guides AWS engagement strategy.Marketplace strategy evolving with new capabilities and international expansion.Brazilian marketplace distribution reduces currency and tax challenges.Partnership evolution: sell first, then market, then co-innovate.Braze penetrated airline market through AWS Travel & Hospitality.RFP introductions show tangible partnership benefits.Tealium partnering with Virgin Australia and United Airlines.MUFG bank case study shows joint AWS-Tealium success.Qualtrics won awards despite not completing formal competencies.Focus on fewer verticals yields better results.Gen AI brings both opportunities and regulatory concerns.First-party data rights critical for AI implementation.AWS Bedrock integration provides security and prescriptive solutions.Participants:Alex Rees – Director Tech Partnerships, BrazeJason Mann – Global AWS Alliance Lead, QualtricsMatthew Gray - SVP, Partnerships & Alliances, TealiumJason Warren - Head of Business Applications ISV Partnerships (Americas), AWSSee how Amazon Web Services gives you the freedom to migrate, innovate, and scale your software company at https://aws.amazon/isv/

Web and Mobile App Development (Language Agnostic, and Based on Real-life experience!)
Using AWS Certificate Manager to provision SSL Certificates

Web and Mobile App Development (Language Agnostic, and Based on Real-life experience!)

Play Episode Listen Later Mar 19, 2025 25:54


In this conversation, Krish Palaniappan discusses a critical issue encountered with an API on AWS Marketplace, where they were notified of a lack of usage requests due to an expired SSL certificate. He walks through the steps taken to identify the problem, including checking logs and understanding SSL certificate management. The conversation highlights the importance of proper certificate handling, the challenges faced during the resolution process, and the lessons learned from the experience. Snowpal Products Backends as Services on ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠AWS Marketplace⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ Mobile Apps on ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠App Store⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Play Store⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Web App⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Education Platform⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ for Learners and Course Creators

AWS for Software Companies Podcast
Ep082: Accelerating Profitable Growth with SaaS with DataRobot, LaunchDarkly and ServiceNow

AWS for Software Companies Podcast

Play Episode Listen Later Mar 11, 2025 62:21


Executives from DataRobot, LaunchDarkly and ServiceNow share strategies, actions and recommendations to achieve profitable growth in today's competitive SaaS landscape.Topics Include:Introduction of panelists from DataRobot, LaunchDarkly & ServiceNowServiceNow's journey from service management to workflow orchestration platform.DataRobot's evolution as comprehensive AI platform before AI boom.LaunchDarkly's focus on helping teams decouple release from deploy.Rule of 40: balancing revenue growth and profit margin.ServiceNow exceeding standards with Rule of 50-60 approach.Vertical markets expansion as key strategy for sustainable growth.AWS Marketplace enabling largest-ever deal for ServiceNow.R&D investment effectiveness through experimentation and feature management.Developer efficiency as driver of profitable SaaS growth.Competition through data-driven decisions rather than guesswork.Speed and iteration frequency determining competitive advantage in SaaS.Balancing innovation with early customer adoption for AI products.Product managers should adopt revenue goals and variable compensation.Product-led growth versus sales-led motion: strategies and frictions.Sales-led growth optimized for enterprise; PLG for practitioners.Marketplace-led growth as complementary go-to-market strategy.Customer acquisition cost (CAC) as primary driver of margin erosion.Pricing and packaging philosophy: platform versus consumption models.Value realization must precede pricing and packaging discussions.Good-better-best pricing model used by LaunchDarkly.Security as foundation of trust in software delivery.LaunchDarkly's Guardian Edition for high-risk software release scenarios.Security for regulated industries through public cloud partnerships.GenAI security: benchmarks, tests, and governance to prevent issues.M&A strategy: ServiceNow's 33 acquisitions for features, not revenue.Replatforming acquisitions into core architecture for consistent experience.Balancing technology integration with people aspects during acquisitions.Trends in buying groups: AI budgets and tool consolidation.Implementing revenue goals in product teams for new initiatives.Participants:Prajakta Damle – Head of Product / SVP of Product, DataRobotClaire Vo – Chief Product & Technology Officer, LaunchDarklyAnshuman Didwania – VP/GM, Hyperscalers Business Group, ServiceNowAkshay Patel – Global SaaS Strategist, Amazon Web ServicesSee how Amazon Web Services gives you the freedom to migrate, innovate, and scale your software company at https://aws.amazon/isv/

AWS Podcast
#705: AWS News Update, January 27, 2025

AWS Podcast

Play Episode Listen Later Jan 27, 2025 27:18


Our 3 hosts take you through all the latest news PLUS a new "Top Stories" discussion! Chapters: 00:08 Top Stories 09:52 AWS Marketplace 10:17 Analytics 11:10 Application Integration 12:41 Artificial Intelligence 14:24 Compute 15:16 Customer Engagement 17:46 Databases 19:25 Developer Tools 20:38 End User Computing 21:29 Management and Governance 25:22 Media Services 25:42 Security, Identity and Compliance Shownotes: https://d29iemol7wxagg.cloudfront.net/705ExtendedShownotes.html

The Six Five with Patrick Moorhead and Daniel Newman
The Future Of Cloud Marketplaces With Matt Yanchyshyn - Six Five On The Road at AWS re:Invent

The Six Five with Patrick Moorhead and Daniel Newman

Play Episode Listen Later Dec 12, 2024 19:59


What does the future have in store for cloud marketplaces and their essential role for hyperscalers? Matt Yanchyshyn, VP of Marketplace & Partner Services at AWS, joined host Dion Hinchcliffe on this episode of Six Five On The Road at AWS re:Invent to discuss the rapidly evolving world of cloud marketplaces. Key topics covered: The unprecedented growth of cloud marketplaces and the forces shaping their trajectory AWS Marketplace's strategic vision and its roadmap for the future The revolutionary "Buy with AWS" experience and its implications for commerce How GenAI is reshaping operations and creating new opportunities  

Irish Tech News Audio Articles
ServiceNow and AWS expand strategic collaboration with new capabilities to accelerate AI transformation

Irish Tech News Audio Articles

Play Episode Listen Later Dec 4, 2024 6:24


ServiceNow (NYSE: NOW), the AI platform for business transformation, and Amazon Web Services (AWS) has announced an expanded strategic collaboration with new capabilities to accelerate AI-driven business transformation across every corner of the enterprise. A new connector enables the seamless use of multimodal models developed and trained on Amazon Bedrock for GenAI-powered workflows in the Now Platform. Additional automation solutions and integrations to seamlessly manage security incidents and procurement are now available on the AWS Marketplace. By deepening its collaboration with AWS and expanding geographically to Canada and Europe expected in 2025, the companies are supercharging value to customers across key industries, including telco, technology, financial services, education, and retail. Connecting Amazon Bedrock models to ServiceNow helps enterprises boost the development and deployment of GenAI solutions. The new connector allows customers to connect seamlessly to their choice of third-party models, based on their specific workflow needs, such as summarisation, advanced analytics, or code generation. Data remains private and secure through ServiceNow and AWS, and customers can set up the integration quickly and easily. "Our partnership with AWS is accelerating business transformation for our joint customers," said Paul Fipps, president of Strategic Accounts at ServiceNow. "More than ever before, organisations demand integrated, end-to-end solutions that enhance user experiences and optimise technology investments. Together, ServiceNow's GenAI workflows and AWS's next-gen cloud capabilities deliver on that promise." "We are committed to empowering our customers with the industry's best tools and resources by leveraging AWS Marketplace to build, deploy and scale GenAI," said Chris Grusz, Managing Director, Technology Partnerships, AWS. "Working with ServiceNow, we're helping our enterprise customers accelerate GenAI deployments and get the most value out of their cloud investments." Expanding integrated solutions, now available in AWS Marketplace ServiceNow is also announcing the availability of new solutions in AWS Marketplace, a digital catalog with thousands of software listings from independent software vendors that make it easy to find, test, buy, and deploy software that runs on AWS. ServiceNow Security Incident Response integration with AWS Security Hub: AWS Marketplace - Uses security findings from AWS Security Hub to automate the creation of security incidents in SecOps on the Now Platform, often resulting in faster, more efficient incident response and remediation. Resolved incidents and findings will then automatically be updated in AWS Security Hub. Integration with Amazon Business Procurement - Integrates Amazon Business procurement with ServiceNow Procurement Operations to enable greater visibility into approved suppliers, purchase requests, changes to prices, order confirmation, and shipping notifications. This streamlines the approval and onboarding of Amazon Business as a supplier for the enterprise and provides built-in governance and procurement policies for Now Platform users. Accelerating business outcomes, maximising cloud investment This announcement builds on ServiceNow and AWS's continued collaboration, bringing the advanced cloud capabilities of AWS to the innovative solutions on the Now Platform, helping customers accelerate business outcomes, realise cloud value, enhance digital experiences, and reimagine GenAI-powered workflows. A range of global enterprise customers, including Bell Canada, Boomi and Pearson are already seeing remarkable value and significant cost savings. Bell Canada "ServiceNow has become a cornerstone of Bell Canada's enterprise services strategy to streamline and enhance end-to-end processes," said John Watson, President, Bell Business Markets, AI and FX Innovation. "By harnessing the Now Platform's advanced automation and AI capabilities powered by AWS, we are dr...

AWS Morning Brief
The pre:Invent Crush

AWS Morning Brief

Play Episode Listen Later Nov 25, 2024 11:20


AWS Morning Brief for the week of November 25, with Corey Quinn. Links:Enhanced account linking experience across AWS Marketplace and AWS Partner CentralAmazon API Gateway now supports Custom Domain Name for private REST APIsAmazon Aurora Serverless v2 supports scaling to zero capacityAmazon CloudFront now supports Anycast Static IPsAmazon CloudFront now supports additional log formats and destinations for access logsAmazon CloudFront announces VPC originsAmazon CloudWatch launches full visibility into application transactionsAmazon EC2 now provides lineage information for your AMIsAmazon Q Developer in the AWS Management Console now uses the service you're viewing as context for your chatAmazon WorkSpaces introduces support for Rocky LinuxAWS App Studio is now generally availableAWS CloudTrail Lake launches enhanced analytics and cross-account data accessAWS Compute Optimizer now supports rightsizing recommendations for Amazon AuroraAWS Elastic Beanstalk adds support for Node.js 22AWS Lambda supports Amazon S3 as a failed-event destination for asynchronous and stream event sourcesIntroducing an AWS Management Console Visual Update (Preview)The new AWS Systems Manager experience: Simplifying node managementAWS announces Block Public Access for Amazon Virtual Private CloudLoad Balancer Capacity Unit Reservation for Application and Network Load BalancersAnnouncing Idle Recommendations in AWS Compute OptimizerAnnouncing Savings Plans Purchase AnalyzerAWS Lambda turns ten – looking back and looking aheadBoost Engagement with AWS and Amazon AdsBuild fullstack AI apps in minutes with the new Amplify AI KitImportant changes to CloudTrail events for AWS IAM Identity CenterFollow Corey on BlueSky!Follow Last Week In AWS on BlueSky!

DisrupTV
Cloud Marketplace Innovation & Cognitive Age | Matt Yanchynshyn and John Nosta

DisrupTV

Play Episode Listen Later Oct 21, 2024 61:42


This week on DisrupTV, we interviewed Matt Yanchyshyn, VP, Amazon Web Services (AWS) Marketplace and Partner Services and John Nosta, President at NostaLab. Matt highlighted the growth of AWS Marketplace, which now offers over 42,000 products with ROIs over 200-300%. He emphasized the importance of speed and innovation, noting that AI and large language models (LLMs) are transforming procurement by offering sophisticated recommendations and automated validation. John discussed the cognitive age, where LLMs unlock thoughts, enhancing human cognition and creativity. He stressed the need for businesses to adapt quickly to exponential change, emphasizing continuous learning and ethical stewardship of knowledge. DisrupTV is a weekly podcast with hosts R "Ray" Wang and Vala Afshar. The show airs live at 11:00 a.m. PT/ 2:00 p.m. ET every Friday. Brought to you by Constellation Executive Network: constellationr.com/CEN.

AWS Podcast
#683: Scaling at Speed: Totogi's AWS-Powered Emergency Response

AWS Podcast

Play Episode Listen Later Sep 2, 2024 26:38


Jillian speaks with Danielle Rios, Acting CEO of Totogi . Hear how Totogi, a vertical SaaS company in the telecom industry, onboarded 23 million new customers in 18 days using AWS. Totogi https://totogi.com/charging-as-a-service/charging-as-a-service-on-aws/ Totogi on the AWS Marketplace: https://aws.amazon.com/marketplace/pp/prodview-hnaq62hzpxane?sr=0-2&ref_=beagle&applicationId=AWSMPContessa AWS for Telco: https://aws.amazon.com/telecom/

Web and Mobile App Development (Language Agnostic, and Based on Real-life experience!)
Dealing with Flutter Dependency Conflicts and Third-Party Plugin Changes

Web and Mobile App Development (Language Agnostic, and Based on Real-life experience!)

Play Episode Listen Later Jul 19, 2024 32:10


In this podcast episode, Krish discusses recent changes made to their mobile app built on Flutter. They highlight the challenges faced when upgrading dependencies and dealing with breaking changes. He shares their experience with dependency conflicts and the need to update dependencies incrementally. He also discuss the changes in Facebook login and the introduction of limited login. Krish provides insights into debugging and finding solutions to these challenges. He concludes by mentioning their exploration of AI technologies and the availability of their APIs on AWS Marketplace. Takeaways Regularly upgrading dependencies in a mobile app is important to avoid dependency issues and breaking changes. Handling dependency conflicts can be challenging, especially when using third-party plugins and libraries. Changes in third-party plugins, like Facebook login, can introduce new features and limitations that need to be accounted for. Debugging and finding solutions to issues with upgrades and changes require thorough investigation and sometimes trial and error. Exploring AI technologies and leveraging existing APIs can save time and effort in software development. Chapters 00:00 Introduction and Apologies for the Delay 04:12 Handling Dependency Upgrades and Breaking Changes 08:38 Challenges with Facebook Login and Limited Login 13:04 Debugging and Finding Solutions to Issues 15:28 Importance of Keeping Up to Date with Software Changes 18:16 Exploring AI Technologies and APIs 29:20 Future Topics and Conclusion

AWS Podcast
#664: #664: AWS News Updates, Apr. 22, 2024

AWS Podcast

Play Episode Listen Later Apr 22, 2024 20:15


Jillian and Shruti take you though all the latest and greatest AWS news. Chapters: 00:39 AWS Marketplace; 00:58 Analytics; 02:23 Application Integration; 03:07 Compute; 05:43 Databases; 06:35 Developer Tools; 07:06 End User Computing; 07:21 Front End Web & Mobile; 07:39 Internet of Things; 07:54 Machine Learning; 13:00 Management & Governance; 16:56 Media Services; 18:10 Migration and Transfer; 20:00 Networking & Content Delivery; 23:29 Quantum Technologies; 23:44 Security, Identity & Compliance; 26:25 Solutions; 26:39 Storage.

Ultimate Guide to Partnering™
217 – Decoding AWS Marketplace Success: How Partners Achieved Billions Last Year.

Ultimate Guide to Partnering™

Play Episode Listen Later Apr 15, 2024 37:45


We are excited to launch our first AWS episode in years. Join us as we delve into marketplace development and partnership success at AWS with our special guest, Josh Greene. Josh is responsible for Marketplace Success at AWS and brings over 20 years of experience in startups, channel partners, and ISVs to this role. In this episode, Josh brings valuable insights into driving revenue generation, strategic partnerships, and global expansion, decoding AWS Marketplace Success, and how partners achieved billions last year. Josh shares his expertise as the Sr. Manager of Global Seller Innovation/MP Development at AWS. Discover how AWS and partners leverage cloud commitments for partner success, the strategies behind AWS Marketplace growth, and the pivotal role of partner engineering in streamlining the sales process.  Tune in to learn the importance of collaboration, innovation, and customer obsession in achieving success with AWS Marketplace. Don't miss out on actionable insights to scale your business and drive innovation with AWS.

cloudonaut
#087 Automate all the release processes!

cloudonaut

Play Episode Listen Later Feb 29, 2024 31:00


Andreas and Michael are sharing their learning while building on AWS. This episode is about automating the release process of bucketAV, a software product sold on the AWS Marketplace. Besides that, Andreas and Michael discuss how to reduce costs for GitHub Actions. Last but not least, Andreas asks Michael about his thoughts on the latest AWS announcements.

AWS Podcast
#650: AWS News Updates, Jan. 29, 2024

AWS Podcast

Play Episode Listen Later Jan 29, 2024 22:35


Jillian takes you through all the latest AWS updates! Chapters: 00:48 AWS Marketplace; 01:25 Analytics; 03:04 Application Integration; 03:41 Compute; 08:19 Customer Engagement; 09:13 Databases; 11:39 Developer Tools; 12:41 Front End Web and Mobile; 13:28 Machine Learning; 13:55 Management & Governance; 15:44 Media Services; 15:52 Migration & Transfer; 17:07 Networking & Content Delivery; 18:48 Security, Identity, & Compliance; 19:34 Storage; 20:46 Supply Chain

AWS Podcast
#648: AWS News Updates Jan 15 2024

AWS Podcast

Play Episode Listen Later Jan 15, 2024 56:04


Jillian and Shruti take you through all the updates since re:Invent! AWS Marketplace (01:01); Analytics (01:32); Application Integration (08:04); Compute (09:33); Customer Engagement (22:45); Databases (25:37); Developer Tools (31:39); End User Computing (34:28); Front End Web and Mobile (34:51); Internet of Things (35:13); Machine Learning (36:07); Management & Governance (39:35); Media Services (48:06); Migration & Transfer (48:42); Networking & Content Delivery (49:52); Satellite (51:36); Security, Identity, & Compliance (51:52); Storage (54:22)

Screaming in the Cloud
How Tailscale Builds for Users of All Tiers with Maya Kaczorowski

Screaming in the Cloud

Play Episode Listen Later Dec 19, 2023 33:45


Maya Kaczorowski, Chief Product Officer at Tailscale, joins Corey on Screaming in the Cloud to discuss what sets the Tailscale product approach apart, for users of their free tier all the way to enterprise. Maya shares insight on how she evaluates feature requests, and how Tailscale's unique architecture sets them apart from competitors. Maya and Corey discuss the importance of transparency when building trust in security, as well as Tailscale's approach to new feature roll-outs and change management.About MayaMaya is the Chief Product Officer at Tailscale, providing secure networking for the long tail. She was mostly recently at GitHub in software supply chain security, and previously at Google working on container security, encryption at rest and encryption key management. Prior to Google, she was an Engagement Manager at McKinsey & Company, working in IT security for large enterprises.Maya completed her Master's in mathematics focusing on cryptography and game theory. She is bilingual in English and French.Outside of work, Maya is passionate about ice cream, puzzling, running, and reading nonfiction.Links Referenced: Tailscale: https://tailscale.com/ Tailscale features: VS Code extension: https://marketplace.visualstudio.com/items?itemName=tailscale.vscode-tailscale  Tailscale SSH: https://tailscale.com/kb/1193/tailscale-ssh  Tailnet lock: https://tailscale.com/kb/1226/tailnet-lock  Auto updates: https://tailscale.com/kb/1067/update#auto-updates  ACL tests: https://tailscale.com/kb/1018/acls#tests  Kubernetes operator: https://tailscale.com/kb/1236/kubernetes-operator  Log streaming: https://tailscale.com/kb/1255/log-streaming  Tailscale Security Bulletins: https://tailscale.com/security-bulletins  Blog post “How Our Free Plan Stays Free:” https://tailscale.com/blog/free-plan  Tailscale on AWS Marketplace: https://aws.amazon.com/marketplace/pp/prodview-nd5zazsgvu6e6  TranscriptAnnouncer: Hello, and welcome to Screaming in the Cloud with your host, Chief Cloud Economist at The Duckbill Group, Corey Quinn. This weekly show features conversations with people doing interesting work in the world of cloud, thoughtful commentary on the state of the technical world, and ridiculous titles for which Corey refuses to apologize. This is Screaming in the Cloud.Corey: Welcome to Screaming in the Cloud. I'm Corey Quinn, and I am joined today on this promoted guest episode by my friends over at Tailscale. They have long been one of my favorite products just because it has dramatically changed the way that I interact with computers, which really should be enough to terrify anyone. My guest today is Maya Kaczorowski, Chief Product Officer at Tailscale. Maya, thanks for joining me.Maya: Thank you so much for having me.Corey: I have to say originally, I was a little surprised to—“Really? You're the CPO? I really thought I would have remembered that from the last time we hung out in person.” So, congratulations on the promotion.Maya: Thank you so much. Yeah, it's exciting.Corey: Being a product person is probably a great place to start with this because we've had a number of conversations, here and otherwise, around what Tailscale is and why it's awesome. I don't necessarily know that beating the drum of why it's so awesome is going to be covering new ground, but I'm sure we're going to come up for that during the conversation. Instead, I'd like to start by talking to you about just what a product person does in the context of building something that is incredibly central not just to critical path, but also has massive security ramifications as well, when positioning something that you're building for the enterprise. It's a very hard confluence of problems, and there are days I am astonished that enterprises can get things done based purely upon so much of the mitigation of what has to happen. Tell me about that. How do you even function given the tremendous vulnerability of the attack surface you're protecting?Maya: Yeah, I don't know if you—I feel like you're talking about the product, but also the sales cycle of talking [laugh] and working with enterprise customers.Corey: The product, the sales cycle, the marketing aspects of it, and—Maya: All of it.Corey: —it all ties together. It's different facets of frankly, the same problem.Maya: Yeah. I think that ultimately, this is about really understanding who the customer that is buying the product is. And I really mean that, like, buying the product, right? Because, like, look at something like Tailscale. We're typically used by engineers, or infrastructure teams in an organization, but the buyer might be the VP of Engineering, but it might be the CISO, or the CTO, or whatever, and they're going to have a set of requirements that's going to be very different from what the end-user has as a set of requirements, so even if you have something like bottom-up adoption, in our case, like, understanding and making sure we're checking all the boxes that somebody needs to actually bring us to work.Enterprises are incredibly demanding, and to your point, have long checklists of what they need as part of an RFP or that kind of thing. I find that some of the strictest requirements tend to be in security. So like, how—to your point—if we're such a critical part of your network, how are you sure that we're always available, or how are you sure that if we're compromised, you're not compromised, and providing a lot of, like, assurances and controls around making sure that that's not the case.Corey: I think that there's a challenge in that what enterprise means to different people can be wildly divergent. I originally came from the school of obnoxious engineering where oh, as an engineer, whenever I say something is enterprise grade, that's not a compliment. That means it's going to be slow and moribund. But that is a natural consequence of a company's growth after achieving success, where okay, now we have actual obligations to customers and risk mitigation that needs to be addressed. And how do you wind up doing that without completely hobbling yourself when it comes to accelerating feature velocity? It's a very delicate balancing act.Maya: Yeah, for sure. And I think you need to balance, to your point, kind of creating demand for the product—like, it's actually solving the problem that the customer has—versus checking boxes. Like, I think about them as features, or you know, feature requests versus feature blockers or deal blockers or adoption blockers. So, somebody wants to, say, connect to an AWS VPC, but then the person who has to make sure that that's actually rolled out properly also wants audit logs and SSH session recording and RBAC-based controls and lots of other things before they're comfortable deploying that in their environment. And I'm not even talking about the list of, you know, legal, kind of, TOS requirements that they would have for that kind of situation.I think there's a couple of things that you need to do to even signal that you're in that space. One of the things that I was—I was talking to a friend of mine the other day how it feels like five years ago, like, nobody had SOC 2 reports, or very few startups had SOC 2 reports. And it's probably because of the advent of some of these other companies in this space, but like, now you can kind of throw a dart, and you'll hit five startups that have SOC 2 reports, and the amount that you need to show that you're ready to sell to these companies has changed.Corey: I think that there's a definite broadening of the use case. And I've been trying to avoid it, but let's go diving right into it. I used to view Tailscale as, oh it's a VPN. The end. Then it became something more where it effectively became the mesh overlay where all of the various things that I have that speak Tailscale—which is frankly, a disturbing number of things that I'd previously considered to be appliances—all talk to one another over a dedicated network, and as a result, can do really neat things where I don't have to spend hours on end configuring weird firewall rules.It's more secure, it's a lot simpler, and it seems like every time I get that understanding down, you folks do something that causes me to yet again reevaluate where you stand. Most recently, I was doing something horrifying in front-end work, and in VS Code the Tailscale extension popped up. “Oh, it looks like you're running a local development server. Would you like to use Tailscale Funnel to make it available to the internet?” And my response to that is, “Good lord, no, I'm ashamed of it, but thanks for asking.” Every time I think I get it, I have to reevaluate where it stands in the ecosystem. What is Tailscale now? I feel like I should get the official description of what you are.Maya: Well, I sure hope I'm not the official description. I think the closest is a little bit of what you're saying: a mesh overlay network for your infrastructure, or a programmable network that lets you mesh together your users and services and services and services, no matter where they are, including across different infrastructure providers and, to your point, on a long list of devices you might have running. People are running Tailscale on self-driving cars, on robots, on satellites, on elevators, but they're also running Tailscale on Linux running in AWS or a MacBook they have sitting under their desk or whatever it happens to be. The phrase that I like to use for that is, like, infrastructure agnostic. We're just a building block.Your infrastructure can be whatever infrastructure you want. You can have the cheapest GPUs from this cloud, or you can use the Android phone to train the model that you have sitting on your desk. We just help you connect all that stuff together so you can build your own cloud whatever way you want. To your point, that's not really a VPN [laugh]. The word VPN doesn't quite do it justice. For the remote access to prod use case, so like a user, specifically, like, a developer infra team to a production network, that probably looks the most like a zero-trust solution, but we kind of blur a lot of the lines there for what we can do.Corey: Yeah, just looking at it, at the moment, I have a bunch of Raspberries Pi, perhaps, hanging out on my tailnet. I have currently 14 machines on there, I have my NAS downstairs, I have a couple of EC2 instances, a Google Cloud instance, somewhere, I finally shut down my old Oracle Cloud instance, my pfSense box speaks it natively. I have a Thinkst Canary hanging out on there to detect if anything starts going ridiculously weird, my phone, my iPad, and a few other things here and there. And they all just talk seamlessly over the same network. I can identify them via either IP address, if I'm old, or via DNS if I want to introduce problems that will surprise me at one point or another down the road.I mean, I even have an exit node I share with my brother's Tailscale account for reasons that most people would not expect, namely that he is an American who lives abroad. So, many weird services like banks or whatnot, “Oh, you can't log in to check your bank unless you're coming from US IP space.” He clicks a button, boom, now he doesn't get yelled at to check his own accounts. Which is probably not the primary use case you'd slap on your website, but it's one of those solving everyday things in somewhat weird ways.Maya: Oh, yeah. I worked at a bank maybe ten years ago, and they would block—this little bank on the east coast of the US—they would block connections from Hawaii because why would any of your customers ever be in Hawaii? And it was like, people travel and maybe you're—Corey: How can you be in Hawaii? You don't have a passport.Maya: [laugh]. People travel. They still need to do banking. Like, it doesn't change, yeah. The internet, we've built a lot of weird controls that are IP-based, that don't really make any sense, that aren't reflective. And like, that's true for individuals—like you're describing, people who travel and need to bank or whatever they need to do when they travel—and for corporations, right? Like the old concept—this is all back to the zero trust stuff—but like, the old concept that you were trusted just because you had an IP address that was in the corp IP range is just not true anymore, right? Somebody can walk into your office and connect to the Wi-Fi and a legitimate employee can be doing their job from home or from Starbucks, right? Those are acceptable ways to work nowadays.Corey: One other thing that I wanted to talk about is, I know that in previous discussions with you folks—sometimes on the podcast sometimes when I more or less corner someone a Tailscale at your developer conference—one of the things that you folks talk about is Tailscale SSH, which is effectively a drop-in replacement for the SSH binary on systems. Full disclosure, I don't use it, mostly because I'm grumpy and I'm old. I also like having some form of separation of duties where you're the network that ties it all together, but something else winds up acting as that authentication step. That said, if I were that interesting that someone wanted to come after me, there are easier ways to get in, so I'm mostly just doing this because I'm persnickety. Are you seeing significant adoption of Tailscale SSH?Maya: I think there's a couple of features that are missing in Tailscale SSH for it to be as adopted by people like you. The main one that I would say is—so right now if you use Tailscale SSH, it runs a binary on the host, you can use your Tailscale credentials, and your Tailscale private key, effectively, to SSH something else. So, you don't have to manage a separate set of SSH keys or certs or whatever it is you want to do to manage that in your network. Your identity provider identity is tied to Tailscale, and then when you connect to that device, we still need to have an identity on the host itself, like in Unix. Right now, that's not tied to Tailscale. You can adopt an identity of something else that's already on the host, but it's not, like, corey@machine.And I think that's the number one request that we're getting for Tailscale SSH, to be able to actually generate or tie to the individual users on the host for an identity that comes from, like, Google, or GitHub, or Okta, or something like that. I'm not hearing a lot of feedback on the security concerns that you're expressing. I think part of that is that we've done a lot of work around security in general so that you feel like if Tailscale were to be compromised, your network wouldn't need to be compromised. So, Tailscale itself is end-to-end encrypted using WireGuard. We only see your public keys; the private keys remain on the device.So, in some sense the, like, quote-unquote, “Worst” that we could do would be to add a node to your network and then start to generate traffic from that or, like, mess with the configuration of your network. These are questions that have come up. In terms of adding nodes to your network, we have a feature called tailnet lock that effectively lets you sign and verify that all the nodes on your network are supposed to be there. One of the other concerns that I've heard come up is, like, what if the binary was compromised. We develop in open-source so you can see that that's the case, but like, you know, there's certainly more stuff we could be doing there to prevent, for example, like a software supply chain security attack. Yeah.Corey: Yeah, but you also have taken significant architectural steps to ensure that you are not placed in a position of undue trust around a lot of these things. Most recently, you raised a Series B, that was $100 million, and the fact that you have not gone bankrupt in the year since that happened tells me that you are very clearly not routing all customer traffic through you folks, at least on one of the major cloud providers. And in fact, a little bit of playing a-slap-and-tickle with Wireshark affirm this, that the nodes talk to each other; they do not route their traffic through you folks, by design. So one, great for the budget, I have respect for that data transfer pattern, but also it means that you are in the position of being a global observer in a way that can be, in many cases, exploited.Maya: I think that's absolutely correct. So, it was 18 months ago or so that we raised our Series B. When you use Tailscale, your traffic connects peer-to-peer directly between nodes on your network. And that has a couple of nice properties, some of what you just described, which is that we don't see your traffic. I mean, one, because it's end-to-end encrypted, but even if we could capture it, and then—we're not in the way of capturing it, let alone decrypting it.Another nice property it has is just, like, latency, right? If your user is in the UK, and they're trying to access something in Scotland, it's not, you know, hair-pinning, bouncing all the way to the West Coast or something like that. It doesn't have to go through one of our servers to get there. Another nice property that comes with that is availability. So, if our network goes down, if our control plane goes down, you're temporarily not able to add nodes or change your configuration, but everything in your network can still connect to each other, so you're not dependent on us being online in order for your network to work.And this is actually coming up more and more in customer conversations where that's a differentiator for us versus a competitor. Different competitors, also. There's a customer case study on our website about somebody who was POC'ing us with a different option, and literally during the POC, the competitor had an outage, unfortunately for them, and we didn't, and they sort of looked at our model, our deployment model and went, “Huh, this really matters to us.” And not having an outage on our network with this solution seems like a better option.Corey: Yeah, when the network is down, the computers all turn into basically space heaters.Maya: [laugh]. Yeah, as long as they're not down because, I guess, unplugged or something. But yeah, [laugh] I completely agree. Yeah. But I think there's a couple of these kinds of, like, enterprise things that people are—we're starting to do a better job of explaining and meeting customers where they are, but it's also people are realizing actually does matter when you're deploying something at this scale that's such a key part of your network.So, we talked a bit about availability, we talked a bit about things like latency. On the security side, there's a lot that we've done around, like I said, tailnet lock or that type of thing, but it's like some of the basic security features. Like, when I joined Tailscale, probably the first thing I shipped in some sense as a PM was a change log. Here's the change log of everything that we're shipping as part of these releases so that you can have confidence that we're telling you what's going on in your network, when new features are coming out, and you can trust us to be part of your network, to be part of your infrastructure.Corey: I do want to further call out that you have a—how should I frame this—a typically active security notification page.Maya: [laugh].Corey: And I think it is easy to misconstrue that as look at how terrifyingly insecure this is? Having read through it, I would argue that it is not that you are surprisingly insecure, but rather that you are extraordinarily transparent about things that are relatively minor issues. And yes, they should get fixed, but, “Oh, that could be a problem if six other things happen to fall into place just the right way.” These are not security issues of the type, “Yeah, so it turns out that what we thought was encrypting actually wasn't and we're just expensive telnet.” No, there's none of that going on.It's all been relatively esoteric stuff, but you also address it very quickly. And that is odd, as someone who has watched too many enterprise-facing companies respond to third-party vulnerability reports with rather than fixing the problem, more or less trying to get them not to talk about it, or if they do, to talk about it only using approved language. I don't see any signs of that with what you've done there. Was that a challenging internal struggle for you to pull off?Maya: I think internally, it was recognizing that security was such an important part of our value proposition that we had to be transparent. But once we kind of got past that initial hump, we've been extremely transparent, as you say. We think we can build trust through transparency, and that's the most important thing in how we respond to security incidents. But code is going to have bugs. It's going to have security bugs. There's nothing you can do to prevent that from happening.What matters is how you—and like, you should. Like, you should try to catch them early in the development process and, you know, shift left and all that kind of stuff, but some things are always going to happen [laugh] and what matters in that case is how you respond to them. And having another, you know, an app update that just says “Bug fixes” doesn't help you figure out whether or not you should actually update, it doesn't actually help you trust us. And so, being as public and as transparent as possible about what's actually happening, and when we respond to security issues and how we respond to security issues is really, really important to us. We have a policy that talks about when we will publish a bulletin.You can subscribe to our bulletins. We'll proactively email anyone who has a security contact on file, or alternatively, another contact that we have if you haven't provided us a security contact when you're subject to an issue. I think by far and large, like, Tailscale has more security bulletins just because we're transparent about them. It's like, we probably have as many bugs as anybody else does. We're just lucky that people report them to us because they see us react to them so quickly, and then we're able to fix them, right? It's a net positive for everyone involved.Corey: It's one of those hard problems to solve for across the board, just because I've seen companies in the past get more or less brutalized by the tech press when they have been overly transparent. I remember that there was a Reuters article years ago about Slack, for example, because they would pull up their status history and say, “Oh, look at all of these issues here. You folks can't keep your website up.” But no, a lot of it was like, “Oh, file uploads for a small subset of our users is causing a problem,” and so on and so forth. These relatively minor issues that, in aggregate, are very hard to represent when you're using traffic light signaling.So, then you see people effectively going full-on AWS status page where there's a significant outage lasting over a day, last month, and what you see on this is if you go really looking for it is this yellow thing buried in his absolute sea of green lights, even though that was one of the more disruptive things to have happened this year. So, it's a consistent and constant balance, and I really have a lot of empathy no matter where you wind up landing on that?Maya: Yeah, I think that's—you're saying it's sort of about transparency or being able to find the right information. I completely agree. And it's also about building trust, right? If we set expectations as to how we will respond to these things then we consistently respond to them, people believe that we're going to keep doing that. And that is almost more important than, like, committing to doing that, if that makes any sense.I remember having a conversation many years ago with an eng manager I worked with, and we were debating what the SLO for a particular service should be. And he sort of made an interesting point. He's like, “It doesn't really matter what the SLO is. It matters what you actually do because then people are going to start expecting [laugh] what you actually do.” So, being able to point at this and say, “Yes, here's what we say and here's what we actually do in practice,” I think builds so much more trust in how we respond to these kinds of things and how seriously we take security.I think one of the other things that came out of the security work is we realized—and I think you talked to Avery, the CEO of Tailscale on a prior podcast about some of this stuff—but we realized that platforms are broken, and we don't have a great way of pushing automatic updates on a lot of platforms, right? You know, if you're using the macOS store, or the Android Play Store, or iOS or whatever, you can automatically update your client when there is a security issue. On other platforms, you're kind of stuck. And so, as a result of us wanting to make sure that the fleet is as updated as possible, we've actually built an auto-update feature that's available on all of our major clients now, so people can opt in to getting those updates as quickly as needed when there is a security issue. We want to expose people to as little risk as possible.Corey: I am not a Tailscale customer. And that bugs me because until I cross that chasm into transferring $1 every month from my bank account to yours, I'm just a whiny freeloader in many respects, which is not at all how you folks who never made me feel I want to be very clear on that. But I believe in paying for the services that empower me to do my job more effectively, and Tailscale absolutely qualifies.Maya: Yeah, understood, I think that you still provide value to us in ways that aren't your data, but then in ways that help our business. One of them is that people like you tend to bring Tailscale to work. They tend to have a good experience at home connecting to their Synology, helping their brother connect to his bank account, whatever it happens to be, and they go, “Oh.” Something kind of clicks, and then they see a problem at work that looks very similar, and then they bring it to work. That is our primary path of adoption.We are a bottom-up adoption, you know, product-led growth product [laugh]. So, we have a blog post called “How Our Free Plan Stays Free” that covers some of that. I think the second thing that I don't want to undersell that a user like you also does is, you have a problem, you hit an issue, and you write into support, and you find something that nobody else has found yet [laugh].Corey: I am very good at doing that entirely by accident.Maya: [laugh]. But that helps us because that means that we see a problem that needs to get fixed, and we can catch it way sooner than before it's deployed, you know, at scale, at a large bank, and you know, it's a critical, kind of, somebody's getting paged kind of issue, right? We have a couple of bugs like that where we need, you know, we need a couple of repros from a couple different people in a couple different situations before we can really figure out what's going on. And having a wide user base who is happy to talk to us really helps us.Corey: I would say it goes beyond that, too. I have—I see things in the world of Tailscale that started off as features that I requested. One of the more recent ones is, it is annoying to me to see on the Tailscale machines list everything I have joined to the tailnet with that silly little up arrow next to it of, “Oh, time to go back and update Tailscale to the latest,” because that usually comes with decent benefits. Great, I have to go through iteratively, or use Ansible, or something like that. Well, now there's a Tailscale update option where it will keep itself current on supported operating systems.For some unknown reason, you apparently can't self-update the application on iOS or macOS. Can't imagine why. But those things tend to self-update based upon how the OS works due to all the sandboxing challenges. The only challenge I've got now is a few things that are, more or less, embedded devices that are packaged by the maintainer of that embedded system, where I'm beholden to them. Only until I get annoyed enough to start building a CI/CD system to replace their package.Maya: I can't wait till you build that CI/CD system. That'll be fun.Corey: “We wrote this code last night. Straight to the bank with it.” Yeah, that sounds awesome.Maya: [laugh] You'd get a couple of term sheets for that, I'm sure.Corey: There are. I am curious, looping back to the start of our conversation, we talked about enterprise security requirements, but how do you address enterprise change management? I find that that's something an awful lot of companies get dreadfully wrong. Most recently and most noisily on my part is Slack, a service for which I paid thousands of dollars a year, decided to roll out a UI redesign that, more or less, got in the way of a tremendous number of customers and there was no way to stop it or revert it. And that made me a lot less likely to build critical-flow business processes that depended upon Slack behaving a certain way.Just, “Oh, we decided to change everything in the user interface today just for funsies.” If Microsoft pulled that with Excel, by lunchtime they'd have reverted it because an entire universe of business users would have marched on Redmond to burn them out otherwise. That carries significant cost for businesses. Yet I still see Tailscale shipping features just as fast as you ever have. How do you square that circle?Maya: Yeah. I think there's two different kinds of change management really, which is, like—because if you think about it, it's like, an enterprise needs a way to roll out a product or a feature internally and then separately, we need a way to roll out new things to customers, right? And so, I think on the Tailscale side, we have a change log that tells you about everything that's changing, including new features, and including changes to the client. We update that religiously. Like, it's a big deal, if something doesn't make it the day that it's supposed to make it. We get very kind of concerned internally about that.A couple of things that were—that are in that space, right, we just talked about auto-updates to make it really easy for you to maintain what's actually rolled out in your infrastructure, but more importantly, for us to push changes with a new client release. Like, for example, in the case of a security incident, we want to be able to publish a version and get it rolled out to the fleet as quickly as possible. Some of the things that we don't have here, but although I hear requests for is the ability to, like, gradually roll out features to a customer. So like, “Can we change the configuration for 10% of our network and see if anything breaks before rolling back, right before rolling forward.” That's a very traditional kind of infra change management thing, but not something I've ever seen in, sort of, the networking security space to this degree, and something that I'm hearing a lot of customers ask for.In terms of other, like, internal controls that a customer might have, we have a feature called ACL Tests. So, if you're going to change the configuration of who can access what in your network, you can actually write tests. Like, your permission file is written in HuJSON and you can write a set of things like, Corey should be able to access prod. Corey should not be able to access test, or whatever it happens to be—actually, let's flip those around—and when you have a policy change that doesn't pass those tests, you actually get told right away so you're not rolling that out and accidentally breaking a large part of your network. So, we built several things into the product to do it. In terms of how we notify customers, like I said, that the primary method that we have right now is something like a change log, as well as, like, security bulletins for security updates.Corey: Yeah, it's one of the challenges, on some level, of the problem of oh, I'm going to set up a service, and then I'm going to go sail around the world, and when I come back in a year or two—depending on how long I spent stranded on an island somewhere—now I get to figure out what has changed. And to your credit, you have to affirmatively enable all of the features that you have shipped, but you've gone from, “Oh, it's a mesh network where everything can talk to each other,” to, “I can use an exit node from that thing. Oh, now I can seamlessly transfer files from one node to another with tail drop,” to, “Oh, Tailscale Funnel. Now, I can expose my horrifying developer environment to the internet.” I used that one year to give a talk at a conference, just because why not?Maya: [crosstalk 00:27:35].Corey: Everything evolves to become [unintelligible 00:27:37] email on Microsoft Outlook, or tries to be Microsoft Excel? Oh, no, no. I want you to be building Microsoft PowerPoint for me. And we eventually get there, but that is incredibly powerful functionality, but also terrifying when you think you have a handle on what's going on in a large-scale environment, and suddenly, oh, there's a whole new vector we need to think about. Which is why your—the thought and consideration you put into that is so apparent and so, frankly, welcome.Maya: Yeah, you actually kind of made a statement there that I completely missed, which is correct, which is, we don't turn features on by default. They are opt-in features. We will roll out features by default after they've kind of baked for an incredibly long period of time and with, like, a lot of fanfare and warning. So, the example that I'll give is, we have a DNS feature that was probably available for maybe 18 months before we turned it on by default for new tailnets. So didn't even turn it on for existing folks. It's called Magic DNS.We don't want to touch your configuration or your network. We know people will freak out when that happens. Knowing, to your point, that you can leave something for a year and come back, and it's going to be the same is really important. For everyone, but for an enterprise customer as well. Actually, one other thing to mention there. We have a bunch of really old versions of clients that are running in production, and we want them to keep working, so we try to be as backward compatible as possible.I think the… I think we still have clients from 2019 that are running and connecting to corp that nobody's updated. And like, it'd be great if they would update them, but like, who knows what situation they're in and if they can connect to them, and all that kind of stuff, but they still work. And the point is that you can have set it up four years ago, and it should still work, and you should still be able to connect to it, and leave it alone and come back to it in a year from now, and it should still work and [laugh] still connect without anything changing. That's a very hard guarantee to be able to make.Corey: And yet, somehow you've been able to do that, just from the perspective of not—I've never yet seen you folks make a security-oriented decision that I'm looking at and rolling my eyes and amazed that you didn't make the decision the other way. There are a lot of companies that while intending very well have done, frankly, very dumb things. I've been keeping an eye on you folks for a long time, and I would have caught that in public. I just haven't seen anything like that. It's kind of amazing.Last year, I finally took the extraordinary step of disabling SSH access anywhere except the tailnet to a number of my things. It lets my logs fill up a lot less, and you've built to that level of utility-like reliability over the series of longtime experimentation. I have yet to regret having Tailscale in the mix, which is, frankly, not something I can say about almost any product.Maya: Yeah. I'm very proud to hear that. And like, maintaining that trust—back to a lot of the conversation about security and reliability and stuff—is incredibly important to us, and we put a lot of effort into it.Corey: I really appreciate your taking the time to talk to me about how things continue to evolve over there. Anything that's new and exciting that might have gotten missed? Like, what has come out in, I guess, the last six months or so that are relevant to the business and might be useful for people looking to use it themselves?Maya: I was hoping you're going to ask me what came out in the last, you know, 20 minutes while we were talking, and the answer is probably nothing, but you never know. But [laugh]—Corey: With you folks, I wouldn't doubt it. Like, “Oh, yeah, by the way, we had to do a brand treatment redo refresh,” or something on the website? Why not? It now uses telepathy just because.Maya: It could, that'd be pretty cool. No, I mean, lots has gone on in the last six months. I think some of the things that might be more interesting to your listeners, we're now in the AWS Marketplace, so if you want to purchase Tailscale through AWS Marketplace, you can. We have a Kubernetes operator that we've released, which lets you both ingress and egress from a Kubernetes cluster to things that are elsewhere in the world on other infrastructure, and also access the Kubernetes control plane and the API server via Tailscale. I mentioned auto-updates. You mentioned the VS Code extension. That's amazing, the fact that you can kind of connect directly from within VS Code to things on your tailnet. That's a lot of the exciting stuff that we've been doing. And there's boring stuff, you know, like audit log streaming, and that kind of stuff. But it's good.Corey: Yeah, that stuff is super boring until suddenly, it's very, very exciting. And those are not generally good days.Maya: [laugh]. Yeah, agreed. It's important, but boring. But important.Corey: [laugh]. Well, thank you so much for taking the time to talk through all the stuff that you folks are up to. If people want to learn more, where's the best place for them to go to get started?Maya: tailscale.com is the best place to go. You can download Tailscale from there, get access to our documentation, all that kind of stuff.Corey: Yeah, I also just want to highlight that you can buy my attention but never my opinion on things and my opinion on Tailscale remains stratospherically high, so thank you for not making me look like a fool, by like, “Yes. And now we're pivoting to something horrifying is a business model and your data.” Thank you for not doing exactly that.Maya: Yeah, we'll keep doing that. No, no, blockchains in our future.Corey: [laugh]. Maya Kaczorowski, Chief Product Officer at Tailscale. I'm Cloud Economist Corey Quinn, and this is Screaming in the Cloud. This episode has been brought to us by our friends at Tailscale. If you enjoyed this episode, please leave a five-star review on your podcast platform of choice, whereas if you've hated this podcast, please leave a five-star review on your podcast platform of choice along with an angry, insulting comment that will never actually make it back to us because someone screwed up a firewall rule somewhere on their legacy connection.Corey: If your AWS bill keeps rising and your blood pressure is doing the same, then you need The Duckbill Group. We help companies fix their AWS bill by making it smaller and less horrifying. The Duckbill Group works for you, not AWS. We tailor recommendations to your business and we get to the point. Visit duckbillgroup.com to get started.

Screaming in the Cloud
Keeping Workflows Secure in an Ever-Changing Environment with Adnan Khan

Screaming in the Cloud

Play Episode Listen Later Oct 17, 2023 34:42


Adnan Khan, Lead Security Engineer at Praetorian, joins Corey on Screaming in the Cloud to discuss software bill of materials and supply chain attacks. Adnan describes how simple pull requests can lead to major security breaches, and how to best avoid those vulnerabilities. Adnan and Corey also discuss the rapid innovation at Github Actions, and the pros and cons of having new features added so quickly when it comes to security. Adnan also discusses his view on the state of AI and its impact on cloud security. About AdnanAdnan is a Lead Security Engineer at Praetorian. He is responsible for executing on Red-Team Engagements as well as developing novel attack tooling in order to meet and exceed engagement objectives and provide maximum value for clients.His past experience as a software engineer gives him a deep understanding of where developers are likely to make mistakes, and has applied this knowledge to become an expert in attacks on organization's CI/CD systems.Links Referenced: Praetorian: https://www.praetorian.com/ Twitter: https://twitter.com/adnanthekhan Praetorian blog posts: https://www.praetorian.com/author/adnan-khan/ TranscriptAnnouncer: Hello, and welcome to Screaming in the Cloud with your host, Chief Cloud Economist at The Duckbill Group, Corey Quinn. This weekly show features conversations with people doing interesting work in the world of cloud, thoughtful commentary on the state of the technical world, and ridiculous titles for which Corey refuses to apologize. This is Screaming in the Cloud.Corey: Are you navigating the complex web of API management, microservices, and Kubernetes in your organization? Solo.io is here to be your guide to connectivity in the cloud-native universe!Solo.io, the powerhouse behind Istio, is revolutionizing cloud-native application networking. They brought you Gloo Gateway, the lightweight and ultra-fast gateway built for modern API management, and Gloo Mesh Core, a necessary step to secure, support, and operate your Istio environment.Why struggle with the nuts and bolts of infrastructure when you can focus on what truly matters - your application. Solo.io's got your back with networking for applications, not infrastructure. Embrace zero trust security, GitOps automation, and seamless multi-cloud networking, all with Solo.io.And here's the real game-changer: a common interface for every connection, in every direction, all with one API. It's the future of connectivity, and it's called Gloo by Solo.io.DevOps and Platform Engineers, your journey to a seamless cloud-native experience starts here. Visit solo.io/screaminginthecloud today and level up your networking game.Corey: As hybrid cloud computing becomes more pervasive, IT organizations need an automation platform that spans networks, clouds, and services—while helping deliver on key business objectives. Red Hat Ansible Automation Platform provides smart, scalable, sharable automation that can take you from zero to automation in minutes. Find it in the AWS Marketplace.Corey: Welcome to Screaming in the Cloud, I'm Corey Quinn. I've been studiously ignoring a number of buzzword, hype-y topics, and it's probably time that I addressed some of them. One that I've been largely ignoring, mostly because of its prevalence at Expo Hall booths at RSA and other places, has been software bill of materials and supply chain attacks. Finally, I figured I would indulge the topic. Today I'm speaking with Adnan Khan, lead security engineer at Praetorian. Adnan, thank you for joining me.Adnan: Thank you so much for having me.Corey: So, I'm trying to understand, on some level, where the idea of these SBOM or bill-of-material attacks have—where they start and where they stop. I've seen it as far as upstream dependencies have a vulnerability. Great. I've seen misconfigurations in how companies wind up configuring their open-source presences. There have been a bunch of different, it feels almost like orthogonal concepts to my mind, lumped together as this is a big scary thing because if we have a big single scary thing we can point at, that unlocks budget. Am I being overly cynical on this or is there more to it?Adnan: I'd say there's a lot more to it. And there's a couple of components here. So first, you have the SBOM-type approach to security where organizations are looking at which packages are incorporated into their builds. And vulnerabilities can come out in a number of ways. So, you could have software actually have bugs or you could have malicious actors actually insert backdoors into software.I want to talk more about that second point. How do malicious actors actually insert backdoors? Sometimes it's compromising a developer. Sometimes it's compromising credentials to push packages to a repository, but other times, it could be as simple as just making a pull request on GitHub. And that's somewhere where I've spent a bit of time doing research, building off of techniques that other people have documented, and also trying out some attacks for myself against two Microsoft repositories and several others that have reported over the last few months that would have been able to allow an attacker to slip a backdoor into code and expand the number of projects that they are able to attack beyond that.Corey: I think one of the areas that we've seen a lot of this coming from has been the GitHub Action space. And I'll confess that I wasn't aware of a few edge-case behaviors around this. Most of my experience with client-side Git configuration in the .git repository—pre-commit hooks being a great example—intentionally and by design from a security perspective, do not convey when you check that code in and push it somewhere, or grab someone else's, which is probably for the best because otherwise, it's, “Oh yeah, just go ahead and copy your password hash file and email that to something else via a series of arcane shell script stuff.” The vector is there. I was unpleasantly surprised somewhat recently to discover that when I cloned a public project and started running it locally and then adding it to my own fork, that it would attempt to invoke a whole bunch of GitHub Actions flows that I'd never, you know, allowed it to do. That was… let's say, eye-opening.Adnan: [laugh]. Yeah. So, on the particular topic of GitHub Actions, the pull request as an attack vector, like, there's a lot of different forms that an attack can take. So, one of the more common ones—and this is something that's been around for just about as long as GitHub Actions has been around—and this is a certain trigger called ‘pull request target.' What this means is that when someone makes a pull request against the base repository, maybe a branch within the base repository such as main, that will be the workflow trigger.And from a security's perspective, when it runs on that trigger, it does not require approval at all. And that's something that a lot of people don't really realize when they're configuring their workflows. Because normally, when you have a pull request trigger, the maintainer can check a box that says, “Oh, require approval for all external pull requests.” And they think, “Great, everything needs to be approved.” If someone tries to add malicious code to run that's on the pull request target trigger, then they can look at the code before it runs and they're fine.But in a pull request target trigger, there is no approval and there's no way to require an approval, except for configuring the workflow securely. So, in this case, what happens is, and in one particular case against the Microsoft repository, this was a Microsoft reusable GitHub Action called GPT Review. It was vulnerable because it checked out code from my branch—so if I made a pull request, it checked out code from my branch, and you could find this by looking at the workflow—and then it ran tests on my branch, so it's running my code. So, by modifying the entry points, I could run code that runs in the context of that base branch and steal secrets from it, and use those to perform malicious Actions.Corey: Got you. It feels like historically, one of the big threat models around things like this is al—[and when 00:06:02] you have any sort of CI/CD exploit—is either falls down one of two branches: it's either the getting secret access so you can leverage those credentials to pivot into other things—I've seen a lot of that in the AWS space—or more boringly, and more commonly in many cases, it seems to be oh, how do I get it to run this crypto miner nonsense thing, with the somewhat large-scale collapse of crypto across the board, it's been convenient to see that be less prevalent, but still there. Just because you're not making as much money means that you'll still just have to do more of it when it's all in someone else's account. So, I guess it's easier to see and detect a lot of the exploits that require a whole bunch of compute power. The, oh by the way, we stole your secrets and now we're going to use that to lateral into an organization seem like it's something far more… I guess, dangerous and also sneaky.Adnan: Yeah, absolutely. And you hit the nail on the head there with sneaky because when I first demonstrated this, I made a test account, I created a PR, I made a couple of Actions such as I modified the name of the release for the repository, I just put a little tag on it, and didn't do any other changes. And then I also created a feature branch in one of Microsoft's repositories. I don't have permission to do that. That just sat there for about almost two weeks and then someone else exploited it and then they responded to it.So, sneaky is exactly the word you could describe something like this. And another reason why it's concerning is, beyond the secret disclosure for—and in this case, the repository only had an OpenAI API key, so… okay, you can talk to ChatGPT for free. But this was itself a Github Action and it was used by another Microsoft machine-learning project that had a lot more users, called SynapseML, I believe was the name of the other project. So, what someone could do is backdoor this Action by creating a commit in a feature branch, which they can do by stealing the built-in GitHub token—and this is something that all Github Action runs have; the permissions for it vary, but in this case, it had the right permissions—attacker could create a new branch, modify code in that branch, and then modify the tag, which in Git, tags are mutable, so you can just change the commit the tag points to, and now, every time that other Microsoft repository runs GPT Review to review a pull request, it's running attacker-controlled code, and then that could potentially backdoor that other repository, steal secrets from that repository.So that's, you know, one of the scary parts of, in particular backdooring a Github Action. And I believe there was a very informative Blackhat talk this year, that someone from—I'm forgetting the name of the author, but it was a very good watch about how Actions vulnerabilities can be vulnerable, and this is kind of an example of—it just happened to be that this was an Action as well.Corey: That feels like this is an area of exploit that is becoming increasingly common. I tie it almost directly to the rise of GitHub Actions as the default CI/CD system that a lot of folks have been using. For the longest time, it seemed like a poorly configured Jenkins box hanging out somewhere in your environment that was the exception to the Infrastructure as Code rule because everyone has access to it, configures it by hand, and invariably it has access to production was the way that people would exploit things. For a while, you had CircleCI and Travis-CI, before Travis imploded and Circle did a bunch of layoffs. Who knows where they're at these days?But it does seem that the common point now has been GitHub Actions, and a .github folder within that Git repo with a workflows YAML file effectively means that a whole bunch of stuff can happen that you might not be fully aware of when you're cloning or following along with someone's tutorial somewhere. That has caught me out in a couple of strange ways, but nothing disastrous because I do believe in realistic security boundaries. I just worry how much of this is the emerging factor of having a de facto standard around this versus something that Microsoft has actively gotten wrong. What's your take on it?Adnan: Yeah. So, my take here is that Github could absolutely be doing a lot more to help prevent users from shooting themselves in the foot. Because their documentation is very clear and quite frankly, very good, but people aren't warned when they make certain configuration settings in their workflows. I mean, GitHub will happily take the settings and, you know, they hit commit, and now the workflow could be vulnerable. There's no automatic linting of workflows, or a little suggestion box popping up like, “Hey, are you sure you want to configure it this way?”The technology to detect that is there. There's a lot of third-party utilities that will lint Actions workflows. Heck, for looking for a lot of these pull request target-type vulnerabilities, I use a Github code search query. It's just a regular expression. So, having something that at least nudges users to not make that mistake would go really far in helping people not make these mista—you know, adding vulnerabilities to their projects.Corey: It seems like there's also been issues around the GitHub Actions integration approach where OICD has not been scoped correctly a bunch of times. I've seen a number of articles come across my desk in that context and fortunately, when I wound up passing out the ability for one of my workflows to deploy to my AWS account, I got it right because I had no idea what I was doing and carefully followed the instructions. But I can totally see overlooking that one additional parameter that leaves things just wide open for disaster.Adnan: Yeah, absolutely. That's one where I haven't spent too much time actually looking for that myself, but I've definitely read those articles that you mentioned, and yeah, it's very easy for someone to make that mistake, just like, it's easy for someone to just misconfigure their Action in general. Because in some of the cases where I found vulnerabilities, there would actually be a commit saying, “Hey, I'm making this change because the Action needs access to these certain secrets. And oh, by the way, I need to update the checkout steps so it actually checks out the PR head so that it's [testing 00:12:14] that PR code.” Like, people are actively making a decision to make it vulnerable because they don't realize the implication of what they've just done.And in the second Microsoft repository that I found the bug in, was called Microsoft Confidential Sidecar Containers. That repository, the developer a week prior to me identifying the bug made a commit saying that we're making a change and it's okay because it requires approval. Well, it doesn't because it's a pull request target.Corey: Part of me wonders how much of this is endemic to open-source as envisioned through enterprises versus my world of open-source, which is just eh, I've got this weird side project in my spare time, and it seemed like it might be useful to someone else, so I'll go ahead and throw it up there. I understand that there's been an awful lot of commercialization of open-source in recent years; I'm not blind to that fact, but it also seems like there's a lot of companies playing very fast and loose with things that they probably shouldn't be since they, you know, have more of a security apparatus than any random contributors standing up a clone of something somewhere will.Adnan: Yeah, we're definitely seeing this a lot in the machine-learning space because of companies that are trying to move so quickly with trying to build things because OpenAI AI has blown up quite a bit recently, everyone's trying to get a piece of that machine learning pie, so to speak. And another thing of what you're seeing is, people are deploying self-hosted runners with Nvidia, what is it, the A100, or—it's some graphics card that's, like, $40,000 apiece attached to runners for running integration tests on machine-learning workflows. And someone could, via a pull request, also just run code on those and mine crypto.Corey: I kind of miss the days when exploiting computers is basically just a way for people to prove how clever they were or once in a blue moon come up with something innovative. Now, it's like, well, we've gone all around the mulberry bush just so we can basically make computers solve a sudoku form, and in return, turn that into money down the road. It's frustrating, to put it gently.Adnan: [laugh].Corey: When you take a look across the board at what companies are doing and how they're embracing the emerging capabilities inherent to these technologies, how do you avoid becoming a cautionary tale in the space?Adnan: So, on the flip side of companies having vulnerable workflows, I've also seen a lot of very elegant ways of writing secure workflows. And some of the repositories are using deployment environments—which is the GitHub Actions feature—to enforce approval checks. So, workflows that do need to run on pull request target because of the need to access secrets for pull requests will have a step that requires a deployment environment to complete, and that deployment environment is just an approval and it doesn't do anything. So essentially, someone who has permissions to the repository will go in, approve that environment check, and only then will the workflow continue. So, that adds mandatory approvals to pull requests where otherwise they would just run without approval.And this is on, particularly, the pull request target trigger. Another approach is making it so the trigger is only running on the label event and then having a maintainer add a label so the tests can run and then remove the label. So, that's another approach where companies are figuring out ways to write secure workflows and not leave their repositories vulnerable.Corey: It feels like every time I turn around, Github Actions has gotten more capable. And I'm not trying to disparage the product; it's kind of the idea of what we want. But it also means that there's certainly not an awareness in the larger community of how these things can go awry that has kept up with the pace of feature innovation. How do you balance this without becoming the Department of No?Adnan: [laugh]. Yeah, so it's a complex issue. I think GitHub has evolved a lot over the years. Actions, it's—despite some of the security issues that happen because people don't configure them properly—is a very powerful product. For a CI/CD system to work at the scale it does and allow so many repositories to work and integrate with everything else, it's really easy to use. So, it's definitely something you don't want to take away or have an organization move away from something like that because they are worried about the security risks.When you have features coming in so quickly, I think it's important to have a base, kind of like, a mandatory reading. Like, if you're a developer that writes and maintains an open-source software, go read through this document so you can understand the do's and don'ts instead of it being a patchwork where some people, they take a good security approach and write secure workflows and some people just kind of stumble through Stack Overflow, find what works, messes around with it until their deployment is working and their CI/CD is working and they get the green checkmark, and then they move on to their never-ending list of tasks that—because they're always working on a deadline.Corey: Reminds me of a project I saw a few years ago when it came out that Volkswagen had been lying to regulators. It was a framework someone built called ‘Volkswagen' that would detect if it was running inside of a CI/CD environment, and if so, it would automatically make all the tests pass. I have a certain affinity for projects like that. Another one was a tool that would intentionally degrade the performance of a network connection so you could simulate having a latent or stuttering connection with packet loss, and they call that ‘Comcast.' Same story. I just thought that it's fun seeing people get clever on things like that.Adnan: Yeah, absolutely.Corey: When you take a look now at the larger stories that are emerging in the space right now, I see an awful lot of discussion coming up that ties to SBOMs and understanding where all of the components of your software come from. But I chased some stuff down for fun once, and I gave up after 12 dependency leaps from just random open-source frameworks. I mean, I see the Dependabot problem that this causes as well, where whenever I put something on GitHub and then don't touch it for a couple of months—because that's how I roll—I come back and there's a whole bunch of terrifyingly critical updates that it's warning me about, but given the nature of how these things get used, it's never going to impact anything that I'm currently running. So, I've learned to tune it out and just ignore it when it comes in, which is probably the worst of all possible approaches. Now, if I worked at a bank, I should probably take a different perspective on this, but I don't.Adnan: Mm-hm. Yeah. And that's kind of a problem you see, not just with SBOMs. It's just security alerting in general, where anytime you have some sort of signal and people who are supposed to respond to it are getting too much of it, you just start to tune all of it out. It's like that human element that applies to so much in cybersecurity.And I think for the particular SBOM problem, where, yeah, you're correct, like, a lot of it… you don't have reachability because you're using a library for one particular function and that's it. And this is somewhere where I'm not that much of an expert in where doing more static source analysis and reachability testing, but I'm certain there are products and tools that offer that feature to actually prioritize SBOM-based alerts based on actual reachability versus just having an as a dependency or not.[midroll 00:20:00]Corey: I feel like, on some level, wanting people to be more cautious about what they're doing is almost shouting into the void because I'm one of the only folks I found that has made the assertion that oh yeah, companies don't actually care about security. Yes, they email you all the time after they failed to protect your security, telling you how much they care about security, but when you look at where they invest, feature velocity always seems to outpace investment in security approaches. And take a look right now at the hype we're seeing across the board when it comes to generative AI. People are excited about the capabilities and security is a distant afterthought around an awful lot of these things. I don't know how you drive a broader awareness of this in a way that sticks, but clearly, we haven't collectively found it yet.Adnan: Yeah, it's definitely a concern. When you see things on—like for example, you can look at Github's roadmap, and there's, like, a feature there that's, oh, automatic AI-based pull request handling. Okay, so does that mean one day, you'll have a GitHub-powered LLM just approve PRs based on whether it determines that it's a good improvement or not? Like, obviously, that's not something that's the case now, but looking forward to maybe five, six years in the future, in the pursuit of that ever-increasing velocity, could you ever have a situation where actual code contributions are reviewed fully by AI and then approved and merged? Like yeah, that's scary because now you have a threat actor that could potentially specifically tailor contributions to trick the AI into thinking they're great, but then it could turn around and be a backdoor that's being added to the code.Obviously, that's very far in the future and I'm sure a lot of things will happen before that, but it starts to make you wonder, like, if things are heading that way. Or will people realize that you need to look at security at every step of the way instead of just thinking that these newer AI systems can just handle everything?Corey: Let's pivot a little bit and talk about your day job. You're a lead security engineer at what I believe to be a security-focused consultancy. Or—Adnan: Yeah.Corey: If you're not a SaaS product. Everything seems to become a SaaS product in the fullness of time. What's your day job look like?Adnan: Yeah, so I'm a security engineer on Praetorian's red team. And my day-to-day, I'll kind of switch between application security and red-teaming. And that kind of gives me the opportunity to, kind of, test out newer things out in the field, but then also go and do more traditional application security assessments and code reviews, and reverse engineering to kind of break up the pace of work. Because red-teaming can be very fast and fast-paced and exciting, but sometimes, you know, that can lead to some pretty late nights. But that's just the nature of being on a red team [laugh].Corey: It feels like as soon as I get into the security space and start talking to cloud companies, they get a lot more defensive than when I'm making fun of, you know, bad service naming or APIs that don't make a whole lot of sense. It feels like companies have a certain sensitivity around the security space that applies to almost nothing else. Do you find, as a result, that a lot of the times when you're having conversations with companies and they figure out that, oh, you're a red team for a security researcher, oh, suddenly, we're not going to talk to you the way we otherwise might. We thought you were a customer, but nope, you can just go away now.Adnan: [laugh]. I personally haven't had that experience with cloud companies. I don't know if I've really tried to buy a lot. You know, I'm… if I ever buy some infrastructure from cloud companies as an individual, I just kind of sign up and put in my credit card. And, you know, they just, like, oh—you know, they just take my money. So, I don't really think I haven't really, personally run into anything like that yet [laugh].Corey: Yeah, I'm curious to know how that winds up playing out in some of these, I guess, more strategic, larger company environments. I don't get to see that because I'm basically a tiny company that dabbles in security whenever I stumble across something, but it's not my primary function. I just worry on some level one of these days, I'm going to wind up accidentally dropping a zero-day on Twitter or something like that, and suddenly, everyone's going to come after me with the knives. I feel like [laugh] at some point, it's just going to be a matter of time.Adnan: Yeah. I think when it comes to disclosing things and talking about techniques, the key thing here is that a lot of the things that I'm talking about, a lot of the things that I'll be talking about in some blog posts that have coming out, this is stuff that these companies are seeing themselves. Like, they recognize that these are security issues that people are introducing into code. They encourage people to not make these mistakes, but when it's buried in four links deep of documentation and developers are tight on time and aren't digging through their security documentation, they're just looking at what works, getting it to work and moving on, that's where the issue is. So, you know, from a perspective of raising awareness, I don't feel bad if I'm talking about something that the company itself agrees is a problem. It's just a lot of the times, their own engineers don't follow their own recommendations.Corey: Yeah, I have opinions on these things and unfortunately, it feels like I tend to learn them in some of the more unfortunate ways of, oh, yeah, I really shouldn't care about this thing, but I only learned what the norm is after I've already done something. This is, I think, the problem inherent to being small and independent the way that I tend to be. We don't have enough people here for there to be a dedicated red team and research environment, for example. Like, I tend to bleed over a little bit into a whole bunch of different things. We'll find out. So far, I've managed to avoid getting it too terribly wrong, but I'm sure it's just a matter of time.So, one area that I think seems to be a way that people try to avoid cloud issues is oh, I read about that in the last in-flight magazine that I had in front of me, and the cloud is super insecure, so we're going to get around all that by running our own infrastructure ourselves, from either a CI/CD perspective or something else. Does that work when it comes to this sort of problem?Adnan: Yeah, glad you asked about that. So, we've also seen open-s—companies that have large open-source presence on GitHub just opt to have self-hosted Github Actions runners, and that opens up a whole different Pandora's box of attacks that an attacker could take advantage of, and it's only there because they're using that kind of runner. So, the default GitHub Actions runner, it's just an agent that runs on a machine, it checks in with GitHub Actions, it pulls down builds, runs them, and then it waits for another build. So, these are—the default state is a non-ephemeral runner with the ability to fork off tasks that can run in the background. So, when you have a public repository that has a self-hosted runner attached to it, it could be at the organization level or it could be at the repository level.What an attacker can just do is create a pull request, modify the pull request to run on a self-hosted runner, write whatever they want in the pull request workflow, create a pull request, and now as long as they were a previous contributor, meaning you fixed a typo, you… that could be a such a, you know, a single character typo change could even cause that, or made a small contribution, now they create the pull request. The arbitrary job that they wrote is now picked up by that self-hosted runner. They can fork off it, process it to run in the background, and then that just continues to run, the job finishes, their pull request, they'll just—they close it. Business as usual, but now they've got an implant on the self-hosted runner. And if the runners are non-ephemeral, it's very hard to completely lock that down.And that's something that I've seen, there's quite a bit of that on GitHub where—and you can identify it just by looking at the run logs. And that's kind of comes from people saying, “Oh, let's just self-host our runners,” but they also don't configure that properly. And that opens them up to not only tampering with their repositories, stealing secrets, but now depending on where your runner is, now you potentially could be giving an attacker a foothold in your cloud environment.Corey: Yeah, that seems like it's generally a bad thing. I found that cloud tends to be more secure than running it yourself in almost every case, with the exception that once someone finds a way to break into it, there's suddenly a lot more eggs in a very large, albeit more secure, basket. So, it feels like it's a consistent trade-off. But as time goes on, it feels like it is less and less defensible, I think, to wind up picking out an on-prem strategy from a pure security point of view. I mean, there are reasons to do it. I'm just not sure.Adnan: Yeah. And I think that distinction to be made there, in particular with CI/CD runners is there's cloud, meaning you let your—there's, like, full cloud meaning you let your CI/CD provider host your infrastructure as well; there's kind of that hybrid approach you mentioned, where you're using a CI/CD provider, but then you're bringing your own cloud infrastructure that you think you could secure better; or you have your runners sitting in vCenter in your own data center. And all of those could end up being—both having a runner in your cloud and in your data center could be equally vulnerable if you're not segmenting builds properly. And that's the core issue that happens when you have a self-hosted runner is if they're not ephemeral, it's very hard to cut off all attack paths. There's always something an attacker can do to tamper with another build that'll have some kind of security impact. You need to just completely isolate your builds and that's essentially what you see in a lot of these newer guidances like the [unintelligible 00:30:04] framework, that's kind of the core recommendation of it is, like, one build, one clean runner.Corey: Yeah, that seems to be the common wisdom. I've been doing a lot of work with my own self-hosted runners that run inside of Lambda. Definitionally those are, of course, ephemeral. And there's a state machine that winds up handling that and screams bloody murder if there's a problem with it. So far, crossing fingers hoping it works out well.And I have a bounded to a very limited series of role permissions, and of course, its own account of constraint blast radius. But there's still—there are no guarantees in this. The reason I build it the way I do is that, all right, worst case someone can get access to this. The only thing they're going to have the ability to do is, frankly, run up my AWS bill, which is an area I have some small amount of experience with.Adnan: [laugh]. Yeah, yeah, that's always kind of the core thing where if you get into someone's cloud, like, well, just sit there and use their compute resources [laugh].Corey: Exactly. I kind of miss when that was the worst failure mode you had for these things.Adnan: [laugh].Corey: I really want to thank you for taking the time to speak with me today. If people want to learn more, where's the best place for them to find you?Adnan: I do have a Twitter account. Well, I guess you can call it Twitter anymore, but, uh—Corey: Watch me. Sure I can.Adnan: [laugh]. Yeah, so I'm on Twitter, and it's @adnanthekhan. So, it's like my first name with ‘the' and then K-H-A-N because, you know, my full name probably got taken up, like, years before I ever made a Twitter account. So, occasionally I tweet about GitHub Actions there.And on Praetorian's website, I've got a couple of blog posts. I have one—the one that really goes in-depth talking about the two Microsoft repository pull request attacks, and a couple other ones that are disclosed, will hopefully drop on the twenty—what is that, Tuesday? That's going to be the… that's the 26th. So, it should be airing on the Praetorian blog then. So, if you—Corey: Excellent. It should be out by the time this is published, so we will, of course, put a link to that in the [show notes 00:32:01]. Thank you so much for taking the time to speak with me today. I appreciate it.Adnan: Likewise. Thank you so much, Corey.Corey: Adnan Khan, lead security engineer at Praetorian. I'm Cloud Economist Corey Quinn and this is Screaming in the Cloud. If you've enjoyed this podcast, please leave a five-star review on your podcast platform of choice, whereas if you've hated this podcast, please leave a five-star review on your podcast platform of choice, along with an insulting comment that's probably going to be because your podcast platform of choice is somehow GitHub Actions.Adnan: [laugh].Corey: If your AWS bill keeps rising and your blood pressure is doing the same, then you need The Duckbill Group. We help companies fix their AWS bill by making it smaller and less horrifying. The Duckbill Group works for you, not AWS. We tailor recommendations to your business and we get to the point. Visit duckbillgroup.com to get started.

Screaming in the Cloud
Making a Difference Through Technology in the Public Sector with Dmitry Kagansky

Screaming in the Cloud

Play Episode Listen Later Oct 5, 2023 33:04


Dmitry Kagansky, State CTO and Deputy Executive Director for the Georgia Technology Authority, joins Corey on Screaming in the Cloud to discuss how he became the CTO for his home state and the nuances of working in the public sector. Dmitry describes his focus on security and reliability, and why they are both equally important when working with state government agencies. Corey and Dmitry describe AWS's infamous GovCloud, and Dmitry explains why he's employing a multi-cloud strategy but that it doesn't work for all government agencies. Dmitry also talks about how he's focusing on hiring and training for skills, and the collaborative approach he's taking to working with various state agencies.About DmitryMr. Kagansky joined GTA in 2021 from Amazon Web Services where he worked for over four years helping state agencies across the country in their cloud implementations and migrations.Prior to his time with AWS, he served as Executive Vice President of Development for Star2Star Communications, a cloud-based unified communications company. Previously, Mr. Kagansky was in many technical and leadership roles for different software vending companies. Most notably, he was Federal Chief Technology Officer for Quest Software, spending several years in Europe working with commercial and government customers.Mr. Kagansky holds a BBA in finance from Hofstra University and an MBA in management of information systems and operations management from the University of Georgia.Links Referenced: Twitter: https://twitter.com/dimikagi LinkedIn: https://www.linkedin.com/in/dimikagi/ GTA Website: https://gta.ga.gov TranscriptAnnouncer: Hello, and welcome to Screaming in the Cloud with your host, Chief Cloud Economist at The Duckbill Group, Corey Quinn. This weekly show features conversations with people doing interesting work in the world of cloud, thoughtful commentary on the state of the technical world, and ridiculous titles for which Corey refuses to apologize. This is Screaming in the Cloud.Corey: In the cloud, ideas turn into innovation at virtually limitless speed and scale. To secure innovation in the cloud, you need Runtime Insights to prioritize critical risks and stay ahead of unknown threats. What's Runtime Insights, you ask? Visit sysdig.com/screaming to learn more. That's S-Y-S-D-I-G.com/screaming.My thanks as well to Sysdig for sponsoring this ridiculous podcast.Corey: Welcome to Screaming in the Cloud. I'm Corey Quinn. Technical debt is one of those fun things that everyone gets to deal with, on some level. Today's guest apparently gets to deal with 235 years of technical debt. Dmitry Kagansky is the CTO of the state of Georgia. Dmitry, thank you for joining me.Dmitry: Corey, thank you very much for having me.Corey: So, I want to just begin here because this has caused confusion in my life; I can only imagine how much it's caused for you folks. We're talking Georgia the US state, not Georgia, the sovereign country?Dmitry: Yep. Exactly.Corey: Excellent. It's always good to triple-check those things because otherwise, I feel like the shipping costs are going to skyrocket in one way or the other. So, you have been doing a lot of very interesting things in the course of your career. You're former AWS, for example, you come from commercial life working in industry, and now it's yeah, I'm going to go work in state government. How did this happen?Dmitry: Yeah, I've actually been working with governments for quite a long time, both here and abroad. So, way back when, I've been federal CTO for software companies, I've done other work. And then even with AWS, I was working with state and local governments for about four, four-and-a-half years. But came to Georgia when the opportunity presented itself, really to try and make a difference in my own home state. You mentioned technical debt at the beginning and it's one of the things I'm hoping that helped the state pay down and get rid of some of it.Corey: It's fun because governments obviously are not thought of historically as being the early adopters, bleeding edge when it comes to technical innovation. And from where I sit, for good reason. You don't want code that got written late last night and shoved into production to control things like municipal infrastructure, for example. That stuff matters. Unlike a lot of other walks of life, you don't usually get to choose your government, and, “Oh, I don't like this one so I'm going to go for option B.”I mean you get to do at the ballot box, but that takes significant amounts of time. So, people want above all else—I suspect—their state services from an IT perspective to be stable, first and foremost. Does that align with how you think about these things? I mean, security, obviously, is a factor in that as well, but how do you see, I guess, the primary mandate of what you do?Dmitry: Yeah. I mean, security is obviously up there, but just as important is that reliance on reliability, right? People take time off of work to get driver's licenses, right, they go to different government agencies to get work done in the middle of their workday, and we've got to have systems available to them. We can't have them show up and say, “Yeah, come back in an hour because some system is rebooting.” And that's one of the things that we're trying to fix and trying to have fewer of, right?There's always going to be things that happen, but we're trying to really cut down the impact. One of the biggest things that we're doing is obviously a move to the cloud, but also segmenting out all of our agency applications so that agencies manage them separately. Today, my organization, Georgia Technology Authority—you'll hear me say GTA—we run what we call NADC, the North Atlanta Data Center, a pretty large-scale data center, lots of different agencies, app servers all sitting there running. And then a lot of times, you know, an impact to one could have an impact to many. And so, with the cloud, we get some partitioning and some segmentation where even if there is an outage—a term you'll often hear used that we can cut down on the blast radius, right, that we can limit the impact so that we affect the fewest number of constituents.Corey: So, I have to ask this question, and I understand it's loaded and people are going to have opinions with a capital O on it, but since you work for the state of Georgia, are you using GovCloud over in AWS-land?Dmitry: So… [sigh] we do have some footprint in GovCloud, but I actually spent time, even before coming to GTA, trying to talk agencies out of using it. I think there's a big misconception, right? People say, “I'm government. They called it GovCloud. Surely I need to be there.”But back when I was with AWS, you know, I would point-blank tell people that really I know it's called GovCloud, but it's just a poorly named region. There are some federal requirements that it meets; it was built around the ITAR, which is International Traffic of Arms Regulations, but states aren't in that business, right? They are dealing with HIPAA data, with various criminal justice data, and other things, but all of those things can run just fine on the commercial side. And truthfully, it's cheaper and easier to run on the commercial side. And that's one of the concerns I have is that if the commercial regions meet those requirements, is there a reason to go into GovCloud, just because you get some extra certifications? So, I still spend time trying to talk agencies out of going to GovCloud. Ultimately, the agencies with their apps make the choice of where they go, but we have been pretty good about reducing the footprint in GovCloud unless it's absolutely necessary.Corey: Has this always been the case? Because my distant recollection around all of this has been that originally when GovCloud first came out, it was a lot harder to run a whole bunch of workloads in commercial regions. And it feels like the commercial regions have really stepped up as far as what compliance boxes they check. So, is one of those stories where five or ten years ago, whenever it GovCloud first came out, there were a bunch of reasons to use it that no longer apply?Dmitry: I actually can't go past I'll say, seven or eight years, but certainly within the last eight years, there's not been a reason for state and local governments to use it. At the federal level, that's a different discussion, but for most governments that I worked with and work with now, the commercial regions have been just fine. They've met the compliance requirements, controls, and everything that's in place without having to go to the GovCloud region.Corey: Something I noticed that was strange to me about the whole GovCloud approach when I was at the most recent public sector summit that AWS threw is whenever I was talking to folks from AWS about GovCloud and adopting it and launching new workloads and the rest, unlike in almost any other scenario, they seemed that their first response—almost a knee jerk reflex—was to pass that work off to one of their partners. Now, on the commercial side, AWS will do that when it makes sense, and each one becomes a bit of a judgment call, but it just seemed like every time someone's doing something with GovCloud, “Oh, talk to Company X or Company Y.” And it wasn't just one or two companies; there were a bunch of them. Why is that?Dmitry: I think a lot of that is because of the limitations within GovCloud, right? So, when you look at anything that AWS rolls out, it almost always rolls out into either us-east-1 or us-west-2, right, one of those two regions, and it goes out worldwide. And then it comes out in GovCloud months, sometimes even years later. And in fact, sometimes there are features that never show up in GovCloud. So, there's not parity there, and I think what happens is, it's these partners that know what limitations GovCloud has and what things are missing and GovCloud they still have to work around.Like, I remember when I started with AWS back in 2016, right, there had been a new console, you know, the new skin that everyone's now familiar with. But that old console, if you remember that, that was in GovCloud for years afterwards. I mean, it took them at least two more years to get GovCloud to even look like the current commercial console that you see. So, it's things like that where I think AWS themselves want to keep moving forward and having to do anything with kind of that legacy platform that doesn't have all the bells and whistles is why they say, “Go get a partner [unintelligible 00:08:06] those things that aren't there yet.”Corey: That's it makes a fair bit of sense. What I was always wondering how much of this was tied to technical challenges working within those, and building solutions that don't depend upon things. “Oh, wait, that one's not available in GovCloud,” versus a lack of ability to navigate the acquisition process for a lot of governments natively in the same way that a lot of their customers can.Dmitry: Yeah, I don't think that's the case because even to get a GovCloud account, you have to start off with a commercial account, right? So, you actually have to go through the same purchasing steps and then essentially, click an extra button or two.Corey: Oh, I've done that myself already. I have a shitposting account and a—not kidding—Ministry of Shitposting GovCloud account. But that's also me just kicking the tires on it. As I went through the process, it really felt like everything was built around a bunch of unstated assumption—because of course you've worked within GovCloud before and you know where these things are. And I kept tripping into a variety of different aspects of that. I'm wondering how much of that is just due to the fact that partners are almost always the ones guiding customers through that.Dmitry: Yeah. It is almost always that. There's very few people, even in the AWS world, right, if you look at all the employees they have there, it's small subset that work with that environment, and probably an even smaller subset of those that understand what it's really needed for. So, this is where if there's not good understanding, you're better off handing it off to a partner. But I don't think it is the purchasing side of things. It really is the regulatory things and just having someone else sign off on a piece of paper, above and beyond just AWS themselves.Corey: I am curious, since it seems that people love to talk about multi-cloud in a variety of different ways, but I find there's a reality that, ehh, basically, on a long enough timeline, everyone uses everything, versus the idea of, “Oh, we're going to build everything so we can seamlessly flow from one provider to another.” Are you folks all in on AWS? Are you using a bunch of different cloud providers for different workloads? How are you approaching a cloud strategy?Dmitry: So, when you say ‘you guys,' I'll say—as AWS will always say—“It depends.” So, GTA is multi-cloud. We support AWS, we support OCI, we support Azure, and we are working towards getting Google in as well, GCP. However, on the agency side, I am encouraging agencies to pick a cloud. And part of that is because you do have limited staff, they are all different, right?They'll do similar things, but if it's done in a different way and you don't have people that know those little tips and tricks, kind of how to navigate certain cloud vendors, it just makes things more difficult. So, I always look at it as kind of the car analogy, right? Most people are not multi-car, right? You go you buy a car—Toyota, Ford, whatever it is—and you're committed to that thing for the next 4 or 5, 10 years, however long you own it, right? You may not like where the cupholder is or you need to get used to something, you know, being somewhere else, but you do commit to it.And I think it's the same thing with cloud that, you know, do you have to be in one cloud for the rest of your life? No, but know that you're not going to hop from cloud to cloud. No one really does. No one says, “Every six months, I'm going to go move my application from one cloud to another.” It's a pretty big lift and no one really needs to do that. Just find the one that's most comfortable for you.Corey: I assume that you have certain preferences as far as different cloud providers go. But I've found even in corporate life that, “Well, I like this company better than the other,” is generally not the best basis for making sweeping decisions around this. What frameworks do you give various departments to consider where a given workload should live? Like, how do you advise them to think about this?Dmitry: You know, it's funny, we actually had a call with an agency recently that said, “You know, we don't know cloud. What do you guys think we should do?” And it was for a very small, I don't want to call it workload; it was really for some DNS work that they wanted to do. And really came down to, for that size and scale, right, we're looking at a few dollars, maybe a month, they picked it based on the console, right? They liked one console over another.Not going to get into which cloud they picked, but we wound up them giving them a demo of here's what this looks like in these various cloud providers. And they picked that just because they liked the buttons and the layout of one console over another. Now, having said that, for obviously larger workloads, things that are more important, there is criteria. And in many cases, it's also the vendors. Probably about 60 to 70% of the applications we run are all vendor-provided in some way, and the vendors will often dictate platforms that they'll support over others, right?So, that supportability is important to us. Just like you were saying, no one wants code rolled out overnight and surprise all the constituents one day. We take our vendor relations pretty seriously and we take our cue from them. If we're buying software from someone and they say, “Look, this is better in AWS,” or, “This is better in OCI,” for whatever reasons they have, will go in that direction more often than not.Corey: I made a crack at the beginning of the episode where the state was founded 235 years ago, as of this recording. So, how accurate is that? I have to imagine that back in those days, they didn't really have a whole lot of computers, except probably something from IBM. How much technical debt are you folks actually wrestling with?Dmitry: It's pretty heavy. One of the biggest things we have is, we ourselves, in our data center, still have a mainframe. That mainframe is used for a lot of important work. Most notably, a lot of healthcare benefits are really distributed through that system. So, you're talking about federal partnerships, you're talking about, you know, insurance companies, health care providers, all somehow having—Corey: You're talking about things that absolutely, positively cannot break.Dmitry: Yep, exactly. We can't have outages, we can't have blips, and they've got to be accurate. So, even that sort of migration, right, that's not something that we can do overnight. It's something we've been working on for well over a year, and right now we're targeting probably roughly another year or so to get that fully migrated out. And even there, we're doing what would be considered a traditional lift-and-shift. We're going to mainframe emulation, we're not going cloud-native, we're not going to do a whole bunch of refactoring out of the gate. It's just picking up what's working and running and just moving it to a new venue.Corey: Did they finally build an AWS/400 that you can run that out? I didn't realize they had a mainframe emulation offering these days.Dmitry: They do. There's actually several providers that do it. And there's other agencies in the state that have made this sort of move as well, so we're also not even looking to be innovators in that respect, right? We're not going to be first movers to try that out. We'll have another agency make that move first and now we're doing this with our Department of Human Services.But yeah, a lot of technical debt around that platform. When you look at just the cost of operating these platforms, that mainframe costs the state roughly $15 million a year. We think in the cloud, it's going to wind up costing us somewhere between 3 to 4 million. Even if it's 5 million, that's still considerable savings over what we're paying for today. So, it's worth making that move, but it's still very deliberate, very slow, with a lot of testing along the way. But yeah, you're talking about that workload has been in the state, I want to say, for over 20, 25 years.Corey: So, what's the reason to move it? Because not for nothing, but there's an old—the old saw, “Well, don't fix it if it ain't broke.” Well, what's broke about it?Dmitry: Well, there's a couple of things. First off, the real estate that it takes up as an issue. It is a large machine sitting on a floor of a data center that we've got to consolidate to. We actually have some real estate constraints and we've got to cut down our footprint by next year, contractually, right? We've agreed, we're going to move into a smaller space.The other part is the technical talent. While yes, it's not broke, things are working on it, there are fewer and fewer people that can manage it. What we've found was doing a complete refactor while doing a move anywhere, is really too risky, right? Rewriting everything with a bunch of Lambdas is kind of scary, as well as moving it into another venue. So, there are mainframe emulators out there that will run in the cloud. We've gotten one and we're making this move now. So, we're going to do that lift-and-shift in and then look to refactor it piecemeal.Corey: Specifics are always going to determine, but as a general point, I felt like I am the only voice in the room sometimes advocating in favor of lift-and-shift. Because people say, “Oh, it's terrible for reasons X, Y, and Z.” It's, “Yes, all of your options are terrible and for the common case, this is the one that I have the sneaking suspicion, based upon my lived experience, is going to be the least bad have all of those various options.” Was there a thought given to doing a refactor in flight?Dmitry: So… from the time I got here, no. But I could tell you just having worked with the state even before coming in as CTO, there were constant conversations about a refactor. And the problem is, no one actually has an appetite for it. Everyone talks about it, but then when you say, “Look, there's a risk to doing this,”—right, governments are about minimizing risk—when you say, “Look, there's a risk to rewriting and moving code at the same time and it's going to take years longer,” right, that refactoring every time, I've seen an estimate, it would be as small as three years, as large as seven or eight years, depending on who was doing the estimate. Whereas the lift-and-shift, we're hoping we can get it done in two years, but even if it's two-and-a-half, it's still less than any of the estimates we've seen for a refactor and less risky. So, we're going with that model and we'll tinker and optimize later. But we just need to get out of that mainframe so that we can have more modern technology and more modern support.Corey: It seems like the right approach. I'm sorry, I didn't mean to frame that is quite as insulting as it might have come across. Like, “Did anyone consider other options just out of curi—” of course. Whenever you're making big changes, we're going to throw a dart at a whiteboard. It's not what appears to be Twitter's current product strategy we're talking about here. This is stuff that's very much measure twice, cut once.Dmitry: Yeah. Very much so. And you see that with just about everything we do here. I know, when the state, what now, three years ago, moved their tax system over to AWS, not only did they do two or three trial runs of just the data migration, we actually wound up doing six, right? You're talking about adding two months of testing just to make sure every time we did the data move, it was done correctly and all the data got moved over. I mean, government is very, very much about measure three, four times, cut once.Corey: Which is kind of the way you'd want it. One thing that I found curious whenever I've been talking to folks in the public sector space around things that they care about—and in years past, I periodically tried to, “Oh, should we look at doing some cost consulting for folks in this market?” And by and large, there have been a couple of exceptions, but—generally, in our experience with sovereign governments, more so than municipal or state ones—but saving money is not usually one of the top three things that governments care about when it comes to their AWS's state. Is cost something that's on your radar? And how do you conceptualize around this? And I should also disclose, this is not in any way, shape, or form intended to be a sales pitch.Dmitry: Yeah, no, cost actually, for GTA. Is a concern. But I think it's more around the way we're structured. I have worked with other governments where they say, “Look, we've already gotten an allotment of money. It costs whatever it costs and we're good with it.”With the way my organization is set up, though, we're not appropriated funds, meaning we're not given any tax dollars. We actually have to provide services to the agencies and they pay us for it. And so, my salary and everyone else's here, all the work that we do, is basically paid for by agencies and they do have a choice to leave. They could go find other providers. It doesn't have to be GTA always.So, cost is a consideration. But we're also finding that we can get those cost savings pretty easily with this move to the cloud because of the number of available tools that we now have available. We have—that data center I talked about, right? That data center is obviously locked down, secured, very limited access, you can't walk in, but that also prevents agencies from doing a lot of day-to-day work that now in the cloud, they can do on their own. And so, the savings are coming just from this move of not having to have as much locks away from the agency, but having more locks from the outside world as well, right? There's definitely scaling up in the number of tools that they have available to them to work around their applications that they didn't have before.Corey: It's, on some level, a capability story, I think, when it comes to cloud. But something I have heard from a number of folks is that even more so than in enterprises, budgets tend to be much more fixed things in the context of cloud in government. Often in enterprises, what you'll see is sprawl: someone leaves something running and oops, the bill wound up going up higher than we projected for this given period of time. When we start getting into the realm of government, that stops being a you broke budgeting policy and starts to resemble things that are called crimes. How do you wind up providing governance as a government around cloud usage to avoid, you know, someone going to prison over a Managed NAT Gateway?Dmitry: Yeah. So, we do have some pretty stringent monitoring. I know, even before the show, we talked about fact that we do have a separate security group. So, on that side of it, they are keeping an eye on what are people doing in the cloud. So, even though agencies now have more access to more tooling, they can do more, right, GTA hasn't stepped back from it and so, we're able to centrally manage things.We've put in a lot of controls. In fact, we're using Control Tower. We've got a lot of guardrails put in, even basic things like you can't run things outside of the US, right? We don't want you running things in the India region or anywhere in South America. Like, that's not even allowed, so we're able to block that off.And then we've got some pretty tight financial controls where we're watching the spend on a regular basis, agency by agency. Not enforcing any of it, obviously, agencies know what they're doing and it's their apps, but we do warn them of, “Hey, we're seeing this trend or that trend.” We've been at this now for about a year-and-a-half, and so agencies are starting to see that we provide more oversight and a lot less pressure, but at the same time, there's definitely a lot more collaboration assistance with one another.Corey: It really feels like the entire procurement model is shifted massively. As opposed to going out for a bunch of bids and doing all these other things, it's consumption-based. And that has been—I know for enterprises—a difficult pill for a lot of their procurement teams to wind up wrapping their heads around. I can only imagine what that must be like for things that are enshrined in law.Dmitry: Yeah, there's definitely been a shift, although it's not as big as you would think on that side because you do have cloud but then you also have managed services around cloud, right? So, you look at AWS, OCI, Azure, no one's out there putting a credit card down to open an environment anymore, you know, a tenant or an account. It is done through procurement rules. Like, we don't actually buy AWS directly from AWS; we go through a reseller, right, so there's some controls there as well from the procurement side. So, there's still a lot of oversight.But it is scary to some of our procurement people. Like, AWS Marketplace is a very, very scary place for them, right? The fact that you can go and—you can hire people at Marketplace, you could buy things with a single button-click. So, we've gone out of our way, in my agency, to go through and lock that down to make sure that before anyone clicks one of those purchase buttons, that we at least know about it, they've made the request, and we have to go in and unlock that button for that purchase. So, we've got to put in more controls in some cases. But in other cases, it has made things easier.Corey: As you look across the landscape of effectively, what you're doing is uprooting an awful lot of technical systems that have been in place for decades at this point. And we look at cloud and I'm not saying it's not stable—far from it—but it also feels a little strange to be, effectively, making a similar timespan of commitment—because functionally a lot of us are—when we look at these platforms. Was that something that had already been a pre-existing appetite for when you started the role or is that something that you've found that you've had to socialize in the last couple years?Dmitry: It's a little bit of both. It's been lumpy, agency by agency, I'll say. There are some agencies that are raring to go, they want to make some changes, do a lot of good, so to speak, by upgrading their infrastructure. There are others that will sit and say, “Hey, I've been doing this for 20, 30 years. It's been fine.” That whole, “If it ain't broke, don't fix it,” mindset.So, for them, there's definitely been, you know, a lot more friction to get them going in that direction. But what I'm also finding is the people with their hands on the keyboards, right, the ones that are doing the work, are excited by this. This is something new for them. In addition to actually going to cloud, the other thing we've been doing is providing a lot of different training options. And so, that's something that's perked people up and definitely made them much more excited to come into work.I know, down at the, you know, the operator level, the administrators, the managers, all of those folks, are pretty pleased with the moves we're making. You do get some of the folks in upper management in the agencies that do say, “Look, this is a risk.” We're saying, “Look, it's a risk not to do this.” Right? You've also got to think about staffing and what people are willing to work on. Things like the mainframe, you know, you're not going to be able to hire those people much longer. They're going to be fewer and far between. So, you have to retool. I do tell people that, you know, if you don't like change, IT is probably not the industry to be in, even in government. You probably want to go somewhere else, then.Corey: That is sort of the next topic I want to get into, where companies across the board are finding it challenging to locate and source talent to work in their environments. How has the process of recruiting cloud talent gone for you?Dmitry: It's difficult. Not going to sugarcoat that. It's, it's—Corey: [laugh]. I'm not sure anyone would say otherwise, no matter where you are. You can pay absolutely insane, top-of-market money and still have that exact same response. No one says, “Oh, it's super easy.” Everyone finds it hard. But please continue [laugh].Dmitry: Yeah, but it's also not a problem that we can even afford to throw money at, right? So, that's not something that we'd ever do. But what I have found is that there's actually a lot of people, really, that I'll say are tech adjacent, that are interested in making that move. And so, for us, having a mentoring and training program that bring people in and get them comfortable with it is probably more important than finding the talent exactly as it is, right? If you look at our job descriptions that we put out there, we do want things like cloud certs and certain experience, but we'll drop off things like certain college requirements. Say, “Look, do you really need a college degree if you know what you're doing in the cloud or if you know what you're doing with a database and you can prove that?”So, it's re-evaluating who we're bringing in. And in some cases, can we also train someone, right, bring someone in for a lower rate, but willing to learn and then give them the experience, knowing that they may not be here for 15, 20 years and that's okay. But we've got to retool that model to say, we expect some attrition, but they walk away with some valuable skills and while they're here, they learn those skills, right? So, that's the payoff for them.Corey: I think that there's a lot of folks exploring that where there are people who have the interest and the aptitude that are looking to transition in. So, much of the discussion points around filling the talent pipeline have come from a place of, oh, we're just going to talk to all the schools and make sure that they're teaching people the right way. And well, colleges aren't really aimed at being vocational institutions most of the time. And maybe you want people who can bring an understanding of various aspects of business, of workplace dynamics, et cetera, and even the organization themselves, you can transition them in. I've always been a big fan of helping people lateral from one part of an organization to another. It's nice to see that there's actual formal processes around that for you, folks.Dmitry: Yeah, we're trying to do that and we're also working across agencies, right, where we might pull someone in from another agency that's got that aptitude and willingness, especially if it's someone that already has government experience, right, they know how to work within the system that we have here, it certainly makes things easier. It's less of a learning curve for them on that side. We think, you know, in some cases, the technical skills, we can teach you those, but just operating in this environment is just as important to understand the soft side of it.Corey: No, I hear you. One thing that I've picked up from doing this show and talking to people in the different places that you all tend to come from, has been that everyone's working with really hard problems and there's a whole universe of various constraints that everyone's wrestling with. The biggest lie in our industry across the board that I'm coming to realize is any whiteboard architecture diagram. Full stop. The real world is messy.Nothing is ever quite like it looks like in that sterile environment where you're just designing and throwing things up there. The world is built on constraints and trade-offs. I'm glad to see that you're able to bring people into your organization. I think it gives an awful lot of folks hope when they despair about seeing what some of the job prospects are for folks in the tech industry, depending on what direction they want to go in.Dmitry: Yeah. I mean, I think we've got the same challenge as everyone else does, right? It is messy. The one thing that I think is also interesting is that we also have to have transparency but to some degree—and I'll shift; I know this wasn't meant to kind of go off into the security side of things, but I think one of the things that's most interesting is trying to balance a security mindset with that transparency, right?You have private corporations, other organizations that they do whatever they do, they're not going to talk about it, you don't need to know about it. In our case, I think we've got even more of a challenge because on the one hand, we do want to lock things down, make sure they're secure and we protect not just the data, but how we do things, right, some are mechanisms and methods. But same time, we've got a responsibility to be transparent to our constituents. They've got to be able to see what we're doing, what are we spending money on? And so, to me, that's also one of the biggest challenges we have is how do we make sure we balance that out, that we can provide people and even our vendors, right, a lot of times our vendors [will 00:30:40] say, “How are you doing something? We want to know so that we can help you better in some areas.” And it's really become a real challenge for us.Corey: I really want to thank you for taking the time to speak with me about what you're doing. If people want to learn more, where's the best place for them to find you?Dmitry: I guess now it's no longer called Twitter, but really just about anywhere. Twitter, Instagram—I'm not a big Instagram user—LinkedIn, Dmitry Kagansky, there's not a whole lot of us out there; pretty easy to do a search. But also you'll see there's my contact info, I believe, on the GTA website, just gta.ga.gov.Corey: Excellent. We will, of course, put links to that in the [show notes 00:31:20]. Thank you so much for being so generous with your time. I really appreciate it.Dmitry: Thank you, Corey. I really appreciate it as well.Corey: Dmitry Kagansky, CTO for the state of Georgia. I'm Cloud Economist Corey Quinn, and this is Screaming in the Cloud. If you've enjoyed this podcast, please leave a five-star review on your podcast platform of choice, whereas if you've hated this podcast, please leave a five-star review on your podcast platform of choice along with an angry, insulting comment telling me that I've got it all wrong and mainframes will in fact rise again.Corey: If your AWS bill keeps rising and your blood pressure is doing the same, then you need The Duckbill Group. We help companies fix their AWS bill by making it smaller and less horrifying. The Duckbill Group works for you, not AWS. We tailor recommendations to your business and we get to the point. Visit duckbillgroup.com to get started.

Screaming in the Cloud
Ask Me Anything with Corey Quinn

Screaming in the Cloud

Play Episode Listen Later Oct 3, 2023 53:56


In this special live-recorded episode of Screaming in the Cloud, Corey interviews himself— well, kind of. Corey hosts an AMA session, answering both live and previously submitted questions from his listeners. Throughout this episode, Corey discusses misconceptions about his public persona, the nature of consulting on AWS bills, why he focuses so heavily on AWS offerings, his favorite breakfast foods, and much, much more. Corey shares insights into how he monetizes his public persona without selling out his genuine opinions on the products he advertises, his favorite and least favorite AWS services, and some tips and tricks to get the most out of re:Invent.About CoreyCorey is the Chief Cloud Economist at The Duckbill Group. Corey's unique brand of snark combines with a deep understanding of AWS's offerings, unlocking a level of insight that's both penetrating and hilarious. He lives in San Francisco with his spouse and daughters.Links Referenced: lastweekinaws.com/disclosures: https://lastweekinaws.com/disclosures duckbillgroup.com: https://duckbillgroup.com TranscriptAnnouncer: Hello, and welcome to Screaming in the Cloud with your host, Chief Cloud Economist at The Duckbill Group, Corey Quinn. This weekly show features conversations with people doing interesting work in the world of cloud, thoughtful commentary on the state of the technical world, and ridiculous titles for which Corey refuses to apologize. This is Screaming in the Cloud.Corey: As businesses consider automation to help build and manage their hybrid cloud infrastructures, deployment speed is important, but so is cost. Red Hat Ansible Automation Platform is available in the AWS Marketplace to help you meet your cloud spend commitments while delivering best-of-both-worlds support.Corey: Well, all right. Thank you all for coming. Let's begin and see how this whole thing shakes out, which is fun and exciting, and for some godforsaken reason the lights like to turn off, so we're going to see if that continues. I've been doing Screaming in the Cloud for about, give or take, 500 episodes now, which is more than a little bit ridiculous. And I figured it would be a nice change of pace if I could, instead of reaching out and talking to folks who are innovative leaders in the space and whatnot, if I could instead interview my own favorite guest: myself.Because the entire point is, I'm usually the one sitting here asking questions, so I'm instead going to now gather questions from you folks—and feel free to drop some of them into the comments—but I've solicited a bunch of them, I'm going to work through them and see what you folks want to know about me. I generally try to be fairly transparent, but let's have fun with it. To be clear, if this is your first exposure to my Screaming in the Cloud podcast show, it's generally an interview show talking with people involved with the business of cloud. It's not intended to be snarky because not everyone enjoys thinking on their feet quite like that, but rather a conversation of people about what they're passionate about. I'm passionate about the sound of my own voice. That's the theme of this entire episode.So, there are a few that have come through that are in no particular order. I'm going to wind up powering through them, and again, throw some into the comments if you want to have other ones added. If you're listening to this in the usual Screaming in the Cloud place, well, send me questions and I am thrilled to wind up passing out more of them. The first one—a great one to start—comes with someone asked me a question about the video feed. “What's with the Minecraft pickaxe on the wall?” It's made out of foam.One of my favorite stories, and despite having a bunch of stuff on my wall that is interesting and is stuff that I've created, years ago, I wrote a blog post talking about how machine learning is effectively selling digital pickaxes into a gold rush. Because the cloud companies pushing it are all selling things such as, you know, they're taking expensive compute, large amounts of storage, and charging by the hour for it. And in response, Amanda, who runs machine learning analyst relations at AWS, sent me that by way of retaliation. And it remains one of my absolute favorite gifts. It's, where's all this creativity in the machine-learning marketing? No, instead it's, “We built a robot that can think. But what are we going to do with it now? Microsoft Excel.” Come up with some of that creativity, that energy, and put it into the marketing side of the world.Okay, someone else asks—Brooke asks, “What do I think is people's biggest misconception about me?” That's a good one. I think part of it has been my misconception for a long time about what the audience is. When I started doing this, the only people who ever wound up asking me anything or talking to me about anything on social media already knew who I was, so I didn't feel the need to explain who I am and what I do. So, people sometimes only see the witty banter on Twitter and whatnot and think that I'm just here to make fun of things.They don't notice, for example, that my jokes are never calling out individual people, unless they're basically a US senator, and they're not there to make individual humans feel bad about collectively poor corporate decision-making. I would say across the board, people think that I'm trying to be meaner than I am. I'm going to be honest and say it's a little bit insulting, just from the perspective of, if I really had an axe to grind against people who work at Amazon, for example, is this the best I'd be able to do? I'd like to think that I could at least smack a little bit harder. Speaking of, we do have a question that people sent in in advance.“When was the last time that Mike Julian gave me that look?” Easy. It would have been two days ago because we were both in the same room up in Seattle. I made a ridiculous pun, and he just stared at me. I don't remember what the pun is, but I am an incorrigible punster and as a result, Mike has learned that whatever he does when I make a pun, he cannot incorrige me. Buh-dum-tss. That's right. They're no longer puns, they're dad jokes. A pun becomes a dad joke once the punch line becomes a parent. Yes.Okay, the next one is what is my favorite AWS joke? The easy answer is something cynical and ridiculous, but that's just punching down at various service teams; it's not my goal. My personal favorite is the genie joke where a guy rubs a lamp, Genie comes out and says, “You can have a billion dollars if you can spend $100 million in a month, and you're not allowed to waste it or give it away.” And the person says, “Okay”—like, “Those are the rules.” Like, “Okay. Can I use AWS?” And the genie says, “Well, okay, there's one more rule.” I think that's kind of fun.Let's see, another one. A hardball question: given the emphasis on right-sizing for meager cost savings and the amount of engineering work required to make real architectural changes to get costs down, how do you approach cost controls in companies largely running other people's software? There are not as many companies as you might think where dialing in the specifics of a given application across the board is going to result in meaningful savings. Yes, yes, you're running something in hyperscale, it makes an awful lot of sense, but most workloads don't do that. The mistakes you most often see are misconfigurations for not knowing this arcane bit of AWS trivia, as a good example. There are often things you can do with relatively small amounts of effort. Beyond a certain point, things are going to cost what they're going to cost without a massive rearchitecture and I don't advise people do that because no one is going to be happy rearchitecting just for cost reasons. Doesn't go well.Someone asks, “I'm quite critical of AWS, which does build trust with the audience. Has AWS tried to get you to market some of their services, and would I be open to do that?” That's a great question. Yes, sometimes they do. You can tell this because they wind up buying ads in the newsletter or the podcast and they're all disclaimed as a sponsored piece of content.I do have an analyst arrangement with a couple of different cloud companies, as mentioned lastweekinaws.com/disclosures, and the reason behind that is because you can buy my attention to look at your product and talk to you in-depth about it, but you cannot buy my opinion on it. And those engagements are always tied to, let's talk about what the public is seeing about this. Now, sometimes I write about the things that I'm talking about because that's where my mind goes, but it's not about okay, now go and talk about this because we're paying you to, and don't disclose that you have a financial relationship.No, that is called fraud. I figure I can sell you as an audience out exactly once, so I better be able to charge enough money to never have to work again. Like, when you see me suddenly talk about multi-cloud being great and I became a VP at IBM, about three to six months after that, no one will ever hear from me again because I love nesting doll yacht money. It'll be great.Let's see. The next one I have on my prepared list here is, “Tell me about a time I got AWS to create a pie chart.” I wish I'd see less of it. Every once in a while I'll talk to a team and they're like, “Well, we've prepared a PowerPoint deck to show you what we're talking about.” No, Amazon is famously not a PowerPoint company and I don't know why people feel the need to repeatedly prove that point to me because slides are not always the best way to convey complex information.I prefer to read documents and then have a conversation about them as Amazon tends to do. The visual approach and the bullet lists and all the rest are just frustrating. If I'm going to do a pie chart, it's going to be in service of a joke. It's not going to be anything that is the best way to convey information in almost any sense.“How many internal documents do I think reference me by name at AWS,” is another one. And I don't know the answer to documents, but someone sent me a screenshot once of searching for my name in their Slack internal nonsense thing, and it was about 10,000 messages referenced me that it found. I don't know what they were saying. I have to assume, on some level, just something that does a belt feed from my Twitter account where it lists my name or something. But I choose to believe that no, they actually are talking about me to that level of… of extreme.Let's see, let's turn back to the chat for a sec because otherwise it just sounds like I'm doing all prepared stuff. And I'm thrilled to do that, but I'm also thrilled to wind up fielding questions from folks who are playing along on these things. “I love your talk, ‘Heresy in the Church of Docker.' Do I have any more speaking gigs planned?” Well, today's Wednesday, and this Friday, I have a talk that's going out at the CDK Community Day.I also have a couple of things coming up that are internal corporate presentations at various places. But at the moment, no. I suspect I'll be giving a talk if they accept it at SCALE in Pasadena in March of next year, but at the moment, I'm mostly focused on re:Invent, just because that is eight short weeks away and I more or less destroy the second half of my year because… well, holidays are for other people. We're going to talk about clouds, as Amazon and the rest of us dance to the tune that they play.“Look in my crystal ball; what will the industry look like in 5, 10, or 20 years?” Which is a fun one. You shouldn't listen to me on this. At all. I was the person telling you that virtualization was a flash in the pan, that cloud was never going to catch on, that Kubernetes and containers had a bunch of problems that were unlikely to be solved, and I'm actually kind of enthused about serverless which probably means it's going to flop.I am bad at predicting overall trends, but I have no problem admitting that wow, I was completely wrong on that point, which apparently is a rarer skill than it should be. I don't know what the future the industry holds. I know that we're seeing some AI value shaping up. I think that there's going to be a bit of a downturn in that sector once people realize that just calling something AI doesn't mean you make wild VC piles of money anymore. But there will be use cases that filter out of it. I don't know what they're going to look like yet, but I'm excited to see it.Okay, “Have any of the AWS services increased costs in the last year? I was having a hard time finding historical pricing charts for services.” There have been repricing stories. There have been SMS charges in India that have—and pinpointed a few other things—that wound up increasing because of a government tariff on them and that cost was passed on. Next February, they're going to be charging for public IPV4 addresses.But those tend to be the exceptions. The way that most costs tend increase have been either, it becomes far cheaper for AWS to provide a service and they don't cut the cost—data transfer being a good example—they'll also often have stories in that they're going to start launching a bunch of new things, and you'll notice that AWS bills tend to grow in time. Part of that growth, part of that is just cruft because people don't go back and clean things up. But by and large, I have not seen, “This thing that used to cost you $1 is now going to cost you $2.” That's not how AWS does pricing. Thankfully. Everyone's always been scared of something like that happening. I think that when we start seeing actual increases like that, that's when it's time to start taking a long, hard look at the way that the industry is shaping up. I don't think we're there yet.Okay. “Any plans for a Last Week in Azure or a Last Week in GCP?” Good question. If so, I won't be the person writing it. I don't think that it's reasonable to expect someone to keep up with multiple large companies and their releases. I'd also say that Azure and GCP don't release updates to services with the relentless cadence that AWS does.The reason I built the thing to start with is simply because it was difficult to gather all the information in one place, at least the stuff that I cared about with an economic impact, and by the time I'd done that, it was, well, this is 80% of the way toward republishing it for other people. I expected someone was going to point me at a thing so I didn't have to do it, and instead, everyone signed up. I don't see the need for it. I hope that in those spaces, they're better at telling their own story to the point where the only reason someone would care about a newsletter would be just my sarcasm tied into whatever was released. But that's not something that I'm paying as much attention to, just because my customers are on AWS, my stuff is largely built on AWS, it's what I have to care about.Let's see here. “What do I look forward to at re:Invent?” Not being at re:Invent anymore. I'm there for eight nights a year. That is shitty cloud Chanukah come to life for me. I'm there to set things up in advance, I'm there to tear things down at the end, and I'm trying to have way too many meetings in the middle of all of that. I am useless for the rest of the year after re:Invent, so I just basically go home and breathe into a bag forever.I had a revelation last year about re:Play, which is that I don't have to go to it if I don't want to go. And I don't like the cold, the repetitive music, the giant crowds. I want to go read a book in a bathtub and call it a night, and that's what I hope to do. In practice, I'll probably go grab dinner with other people who feel the same way. I also love the Drink Up I do there every year over at Atomic Liquors. I believe this year, we're partnering with the folks over at RedMonk because a lot of the people we want to talk to are in the same groups.It's just a fun event: show up, let us buy you drinks. There's no badge scan or any nonsense like that. We just want to talk to people who care to come out and visit. I love doing that. It's probably my favorite part of re:Invent other than not being at re:Invent. It's going to be on November 29th this year. If you're listening to this, please come on by if you're unfortunate enough to be in Las Vegas.Someone else had a good question I want to talk about here. “I'm a TAM for AWS. Cost optimization is one of our functions. What do you wish we would do better after all the easy button things such as picking the right instance and family, savings plans RIs, turning off or delete orphan resources, watching out for inefficient data transfer patterns, et cetera?” I'm going to back up and say that you're begging the question here, in that you aren't doing the easy things, at least not at scale, not globally.I used to think that all of my customer engagements would be, okay after the easy stuff, what's next? I love those projects, but in so many cases, I show up and those easy things have not been done. “Well, that just means that your customers haven't been asking their TAM.” Every customer I've had has asked their TAM first. “Should we ask the free expert or the one that charges us a large but reasonable fixed fee? Let's try the free thing first.”The quality of that advice is uneven. I wish that there were at least a solid baseline. I would love to get to a point where I can assume that I can go ahead and be able to just say, “Okay, you've clearly got your RI stuff, you're right-sizing, you're deleting stuff you're not using, taken care of. Now, let's look at the serious architecture stuff.” It's just rare that I get to see it.“What tool, feature, or widget do I wish AWS would build into the budget console?” I want to be able to set a dollar figure, maybe it's zero, maybe it's $20, maybe it is irrelevant, but above whatever I set, the account will not charge me above that figure, period. If that means they have to turn things off if that means they had to delete portions of data, great. But I want that assurance because even now when I kick the tires in a new service, I get worried that I'm going to wind up with a surprise bill because I didn't understand some very subtle interplay of the dynamics. And if I'm worried about that, everyone else is going to wind up getting caught by that stuff, too.I want the freedom to experiment and if it smacks into a wall, okay, cool. That's $20. That was worth learning that. Whatever. I want the ability to not be charged unreasonable overages. And I'm not worried about it turning from 20 into 40. I'm worried about it turning from 20 into 300,000. Like, there's the, “Oh, that's going to have a dent on the quarterlies,” style of [numb 00:16:01]—All right. Someone also asked, “What is the one thing that AWS could do that I believe would reduce costs for both AWS and their customers. And no, canceling re:Invent doesn't count.” I don't think about it in that way because believe it or not, most of my customers don't come to me asking to reduce their bill. They think they do at the start, but what they're trying to do is understand it. They're trying to predict it.Yes, they want to turn off the waste in the rest, but by and large, there are very few AWS offerings that you take a look at and realize what you're getting for it and say, “Nah, that's too expensive.” It can be expensive for certain use cases, but the dangerous part is when the costs are unpredictable. Like, “What's it going to cost me to run this big application in my data center?” The answer is usually, “Well, run it for a month, and then we'll know.” But that's an expensive and dangerous way to go about finding things out.I think that customers don't care about reducing costs as much as they think; they care about controlling them, predicting them, and understanding them. So, how would they make things less expensive? I don't know. I suspect that data transfer if they were to reduce that at least cross-AZ or eliminate it ideally, you'd start seeing a lot more compute usage in multiple AZs. I've had multiple clients who are not spinning things up in multi-AZ, specifically because they'll take the reliability trade-off over the extreme cost of all the replication flowing back and forth. Aside from that, they mostly get a lot of the value right in how they price things, which I don't think people have heard me say before, but it is true.Someone asked a question here of, “Any major trends that I'm seeing in EDP/PPA negotiations?” Yeah, lately, in particular. Used to be that you would have a Marketplace as the fallback, where it used to be that 50 cents of every dollar you spent on Marketplace would count. Now, it's a hundred percent up to a quarter of your commit. Great.But when you have a long-term commitment deal with Amazon, now they're starting to push for all—put all your other vendors onto the AWS Marketplace so you can have a bigger commit and thus a bigger discount, which incidentally, the discount does not apply to Marketplace spend. A lot of folks are uncomfortable with having Amazon as the middleman between all of their vendor relationships. And a lot of the vendors aren't super thrilled with having to pay percentages of existing customer relationships to Amazon for what they perceive to be remarkably little value. That's the current one.I'm not seeing generative AI play a significant stake in this yet. People are still experimenting with it. I'm not seeing, “Well, we're spending $100 million a year, but make that 150 because of generative AI.” It's expensive to play with gen-AI stuff, but it's not driving the business spend yet. But that's the big trend that I'm seeing over the past, eh, I would say, few months.“Do I use AWS for personal projects?” The first problem there is, well, what's a personal project versus a work thing? My life is starting to flow in a bunch of weird different ways. The answer is yes. Most of the stuff that I build for funsies is on top of AWS, though there are exceptions. “Should I?” Is the follow-up question and the answer to that is, “It depends.”The person is worrying about cost overruns. So, am I. I tend to not be a big fan of uncontrolled downside risk when something winds up getting exposed. I think that there are going to be a lot of caveats there. I know what I'm doing and I also have the backstop, in my case, of, I figure I can have a big billing screw-up or I have to bend the knee and apologize and beg for a concession from AWS, once.It'll probably be on a billboard or something one of these days. Lord knows I have it coming to me. That's something I can use as a get-out-of-jail-free card. Most people can't make that guarantee, and so I would take—if—depending on the environment that you know and what you want to build, there are a lot of other options: buying a fixed-fee VPS somewhere if that's how you tend to think about things might very well be a cost-effective for you, depending on what you're building. There's no straight answer to this.“Do I think Azure will lose any market share with recent cybersecurity kerfuffles specific to Office 365 and nation-state actors?” No, I don't. And the reason behind that is that a lot of Azure spend is not necessarily Azure usage; it's being rolled into enterprise agreements customers negotiate as part of their on-premises stuff, their operating system licenses, their Office licensing, and the rest. The business world is not going to stop using Excel and Word and PowerPoint and Outlook. They're not going to stop putting Windows on desktop stuff. And largely, customers don't care about security.They say they do, they often believe that they do, but I see where the bills are. I see what people spend on feature development, I see what they spend on core infrastructure, and I see what they spend on security services. And I have conversations about budgeting with what are you doing with a lot of these things? The companies generally don't care about this until right after they really should have cared. And maybe that's a rational effect.I mean, take a look at most breaches. And a year later, their stock price is larger than it was when they dispose the breach. Sure, maybe they're burning through their ablated CISO, but the business itself tends to succeed. I wish that there were bigger consequences for this. I have talked to folks who will not put specific workloads on Azure as a result of this. “Will you talk about that publicly?” “No, because who can afford to upset Microsoft?”I used to have guests from Microsoft on my show regularly. They don't talk to me and haven't for a couple of years. Scott Guthrie, the head of Azure, has been on this show. The problem I have is that once you start criticizing their security posture, they go quiet. They clearly don't like me.But their options are basically to either ice me out or play around with my seven seats for Office licensing, which, okay, whatever. They don't have a stick to hit me with, in the way that they do most companies. And whether that's true or not that they're going to lash out like that, companies don't want to take the risk of calling Microsoft out in public. Too big to be criticized as sort of how that works.Let's see, someone else asks, “How can a startup get the most out of its startup status with AWS?” You're not going to get what you think you want from AWS in this context. “Oh, we're going to be a featured partner so they market us.” I've yet to hear a story about how being featured by AWS for something has dramatically changed the fortunes of a startup. Usually, they'll do that when there's either a big social mission and you never hear about the company again, or they're a darling of the industry that's taking the world by fire and they're already [at 00:22:24] upward swing and AWS wants to hang out with those successful people in public and be seen to do so.The actual way that startup stuff is going to manifest itself well for you from AWS is largely in the form of credits as you go through Activate or one of their other programs. But be careful. Treat them like actual money, not this free thing you don't have to worry about. One day they expire or run out and suddenly you're going from having no dollars going to AWS to ten grand a month and people aren't prepared for that. It's, “Wait. So you mean this costs money? Oh, my God.”You have to approach it with a sense of discipline. But yeah, once you—if you can do that, yeah, free money and a free cloud bill for a few years? That's not nothing. I also would question the idea of being able to ask a giant company that's worth a trillion-and-a-half dollars and advice for how to be a startup. I find that one's always a little on the humorous side myself.“What do I think is the most underrated service or feature release from 2023? Full disclosures, this means I'll make some content about it,” says Brooke over at AWS. Oh, that's a good question. I'm trying to remember when various things have come out and it all tends to run together. I think that people are criticizing AWS for charging for IPV4 an awful lot, and I think that that is a terrific change, just because I've seen how wasteful companies are with public IP addresses, which are basically an exhausted or rapidly exhausting resource.And they just—you spend tens or hundreds of thousands of these things and don't use reason to think about that. It'll be one of the best things that we've seen for IPV6 adoption once AWS figures out how to make that work. And I would say that there's a lot to be said for since, you know, IPV4 is exhausted already, now we're talking about can we get them on the secondary markets, you need a reasonable IP plan to get some of those. And… “Well, we just give them the customers and they throw them away.” I want AWS to continue to be able to get those for the stuff that the rest of us are working on, not because one big company uses a million of them, just because, “Oh, what do you mean private IP addresses? What might those be?” That's part of it.I would say that there's also been… thinking back on this, it's unsung, the compute optimizer is doing a lot better at recommending things than it used to be. It was originally just giving crap advice, and over time, it started giving advice that's actually solid and backs up what I've seen. It's not perfect, and I keep forgetting it's there because, for some godforsaken reason, it's its own standalone service, rather than living in the billing console where it belongs. But no one's excited about a service like that to the point where they talk about or create content about it, but it's good, and it's getting better all the time. That's probably a good one. They recently announced the ability for it to do GPU instances which, okay great, for people who care about that, awesome, but it's not exciting. Even I don't think I paid much attention to it in the newsletter.Okay, “Does it make economic sense to bring your own IP addresses to AWS instead of paying their fees?” Bring your own IP, if you bring your own allocation to AWS, costs you nothing in terms of AWS costs. You take a look at the market rate per IP address versus what AWS costs, you'll hit break even within your first year if you do it. So yeah, it makes perfect economic sense to do it if you have the allocation and if you have the resourcing, as well as the ability to throw people at the problem to do the migration. It can be a little hairy if you're not careful. But the economics, the benefit is clear on that once you account for those variables.Let's see here. We've also got tagging. “Everyone nods their heads that they know it's the key to controlling things, but how effective are people at actually tagging, especially when new to cloud?” They're terrible at it. They're never going to tag things appropriately. Automation is the way to do it because otherwise, you're going to spend the rest of your life chasing developers and asking them to tag things appropriately, and then they won't, and then they'll feel bad about it. No one enjoys that conversation.So, having derived tags and the rest, or failing that, having some deployment gate as early in the process as possible of, “Oh, what's the tag for this?” Is the only way you're going to start to see coverage on this. And ideally, someday you'll go back and tag a bunch of pre-existing stuff. But it's honestly the thing that everyone hates the most on this. I have never seen a company that says, “We are thrilled with our with our tag coverage. We're nailing it.” The only time you see that is pure greenfield, everything done without ClickOps, and those environments are vanishingly rare.“Outside a telecom are customers using local zones more, or at all?” Very, very limited as far as what their usage looks like on that. Because that's… it doesn't buy you as much as you'd think for most workloads. The real benefit is a little more expensive, but it's also in specific cities where there are not AWS regions, and at least in the United States where the majority of my clients are, there is not meaningful latency differences, for example, from in Los Angeles versus up to Oregon, since no one should be using the Northern California region because it's really expensive. It's a 20-millisecond round trip, which in most cases, for most workloads, is fine.Gaming companies are big exception to this. Getting anything they can as close to the customer as possible is their entire goal, which very often means they don't even go with some of the cloud providers in some places. That's one of those actual multi-cloud workloads that you want to be able to run anywhere that you can get a baseline computer up to run a container or a golden image or something. That is the usual case. The rest are, for local zones, is largely going to be driven by specific one-off weird things. Good question.Let's see, “Is S3 intelligent tiering good enough or is it worth trying to do it yourself?” Your default choice for almost everything should be intelligent tiering in 2023. It winds up costing you more only in very specific circumstances that are unlikely to be anything other than a corner case for what you're doing. And the exceptions to this are, large workloads that are running a lot of S3 stuff where the lifecycle is very well understood, environments where you're not going to be storing your data for more than 30 days in any case and you can do a lifecycle policy around it. Other than those use cases, yeah, the monitoring fee is not significant in any environment I've ever seen.And people view—touch their data a lot less than they believe. So okay, there's a monitoring fee for object, yes, but it also cuts your raw storage cost in half for things that aren't frequently touched. So, you know, think about it. Run your own numbers and also be aware that first month as it transitions in, you're going to see massive transition charges per object, but wants it's an intelligent tiering, there's no further transition charges, which is nice.Let's see here. “We're all-in on serverless”—oh good, someone drank the Kool-Aid, too—“And for our use cases, it works great. Do I find other customers moving to it and succeeding?” Yeah, I do when they're moving to it because for certain workloads, it makes an awful lot of sense. For others, it requires a complete reimagining of whatever it is that you're doing.The early successes were just doing these periodic jobs. Now, we're seeing full applications built on top of event-driven architectures, which is really neat to see. But trying to retrofit something that was never built with that in mind can be more trouble than it's worth. And there are corner cases where building something on serverless would cost significantly more than building it in a server-ful way. But its time has come for an awful lot of stuff. Now, what I don't subscribe to is this belief that oh, if you're not building something serverless you're doing it totally wrong. No, that is not true. That has never been true.Let's see what else have we got here? Oh, “Following up on local zones, how about Outposts? Do I see much adoption? What's the primary use case or cases?” My customers inherently are coming to me because of a large AWS bill. If they're running Outposts, it is extremely unlikely that they are putting significant portions of their spend through the Outpost. It tends to be something of a rounding error, which means I don't spend a lot of time focusing on it.They obviously have some existing data center workloads and data center facilities where they're going to take an AWS-provided rack and slap it in there, but it's not going to be in the top 10 or even top 20 list of service spend in almost every case as a result, so it doesn't come up. One of the big secrets of how we approach things is we start with a big number first and then work our way down instead of going alphabetically. So yes, I've seen customers using them and the customers I've talked to at re:Invent who are using them are very happy with them for the use cases, but it's not a common approach. I'm not a huge fan of the rest.“Someone said the Basecamp saved a million-and-a-half a year by leaving AWS. I know you say repatriation isn't a thing people are doing, but has my view changed at all since you've published that blog post?” No, because everyone's asking me about Basecamp and it's repatriation, and that's the only use case that they've got for this. Let's further point out that a million-and-a-half a year is not as many engineers as you might think it is when you wind up tying that all together. And now those engineers are spending time running that environment.Does it make sense for them? Probably. I don't know their specific context. I know that a million-and-a-half dollars a year to—even if they had to spend that for the marketing coverage that they're getting as a result of this, makes perfect sense. But cloud has never been about raw cost savings. It's about feature velocity.If you have a data center and you move it to the cloud, you're not going to recoup that investment for at least five years. Migrations are inherently expensive. It does not create the benefits that people often believe that they do. That becomes a painful problem for folks. I would say that there's a lot more noise than there are real-world stories [hanging 00:31:57] out about these things.Now, I do occasionally see a specific workload that is moved back to a data center for a variety of reasons—occasionally cost but not always—and I see proof-of-concept projects that they don't pursue and then turn off. Some people like to call that a repatriation. No, I call it as, “We tried and it didn't do what we wanted it to do so we didn't proceed.” Like, if you try that with any other project, no one says, “Oh, you're migrating off of it.” No, you're not. You tested it, it didn't do what it needed to do. I do see net-new workloads going into data centers, but that's not the same thing.Let's see. “Are the talks at re:Invent worth it anymore? I went to a lot of the early re:Invents and haven't and about five years. I found back then that even the level 400 talks left a lot to be desired.” Okay. I'm not a fan of attending conference talks most of the time, just because there's so many things I need to do at all of these events that I would rather spend the time building relationships and having conversations.The talks are going to be on YouTube a week later, so I would rather get to know the people building the service so I can ask them how to inappropriately use it as a database six months later than asking questions about the talk. Conference-ware is often the thing. Re:Invent always tends to have an AWS employee on stage as well. And I'm not saying that makes these talks less authentic, but they're also not going to get through slide review of, “Well, we tried to build this onto this AWS service and it was a terrible experience. Let's tell you about that as a war story.” Yeah, they're going to shoot that down instantly even though failure stories are so compelling, about here's what didn't work for us and how we got there. It's the lessons learned type of thing.Whenever you have as much control as re:Invent exhibits over its speakers, you know that a lot of those anecdotes are going to be significantly watered down. This is not to impugn any of the speakers themselves; this is the corporate mind continuing to grow to a point where risk mitigation and downside protection becomes the primary driving goal.Let's pull up another one from the prepared list here. “My most annoying, overpriced, or unnecessary charge service in AWS.” AWS Config. It's a tax on using the cloud as the cloud. When you have a high config bill, it's because it charges you every time you change the configuration of something you have out there. It means you're spinning up and spinning down EC2 instances, whereas you're going to have a super low config bill if you, you know, treat it like a big dumb data center.It's a tax on accepting the promises under which cloud has been sold. And it's necessary for a number of other things like Security Hub. Control Towers magic-deploys it everywhere and makes it annoying to turn off. And I think that that is a pure rent-seeking charge because people aren't incurring config charges if they're not already using a lot of AWS things. Not every service needs to make money in a vacuum. It's, “Well, we don't charge anything for this because our users are going to spend an awful lot of money on storing things in S3 to use our service.” Great. That's a good thing. You don't have to pile charge upon charge upon charge upon charge. It drives me a little bit nuts.Let's see what else we have here as far as questions go. “Which AWS service delights me the most?” Eesh, depends on the week. S3 has always been a great service just because it winds up turning big storage that usually—used to require a lot of maintenance and care into something I don't think about very much. It's getting smarter and smarter all the time. The biggest lie is the ‘Simple' in its name: ‘Simple Storage Service.' At this point, if that's simple, I really don't want to know what you think complex would look like.“By following me on Twitter, someone gets a lot of value from things I mention offhandedly as things everybody just knows. For example, which services are quasi-deprecated or outdated, or what common practices are anti-patterns? Is there a way to learn this kind of thing all in one go, as in a website or a book that reduces AWS to these are the handful of services everybody actually uses, and these are the most commonly sensible ways to do it?” I wish. The problem is that a lot of the stuff that everyone knows, no, it's stuff that at most, maybe half of the people who are engaging with it knew.They find out by hearing from other people the way that you do or by trying something and failing and realizing, ohh, this doesn't work the way that I want it to. It's one of the more insidious forms of cloud lock-in. You know how a service works, how a service breaks, what the constraints are around when it starts and it stops. And that becomes something that's a hell of a lot scarier when you have to realize, I'm going to pick a new provider instead and relearn all of those things. The reason I build things on AWS these days is honestly because I know the ways it sucks. I know the painful sharp edges. I don't have to guess where they might be hiding. I'm not saying that these sharp edges aren't painful, but when you know they're there in advance, you can do an awful lot to guard against that.“Do I believe the big two—AWS and Azure—cloud providers have agreed between themselves not to launch any price wars as they already have an effective monopoly between them and [no one 00:36:46] win in a price war?” I don't know if there's ever necessarily an explicit agreement on that, but business people aren't foolish. Okay, if we're going to cut our cost of service, instantly, to undercut a competitor, every serious competitor is going to do the same thing. The only reason to do that is if you believe your margins are so wildly superior to your competitors that you can drive them under by doing that or if you have the ability to subsidize your losses longer than they can remain a going concern. Microsoft and Amazon are—and Google—are not in a position where, all right, we're going to drive them under.They can both subsidize losses basically forever on a lot of these things and they realize it's a game you don't win in, I suspect. The real pricing pressure on that stuff seems to come from customers, when all right, I know it's big and expensive upfront to buy a SAN, but when that starts costing me less than S3 on a per-petabyte basis, that's when you start to see a lot of pricing changing in the market. The one thing I haven't seen that take effect on is data transfer. You could be forgiven for believing that data transfer still cost as much as it did in the 1990s. It does not.“Is AWS as far behind in AI as they appear?” I think a lot of folks are in the big company space. And they're all stammering going, “We've been doing this for 20 years.” Great, then why are all of your generative AI services, A, bad? B, why is Alexa so terrible? C, why is it so clear that everything you have pre-announced and not brought to market was very clearly not envisioned as a product to be going to market this year until 300 days ago, when Chat-Gippity burst onto the scene and OpenAI [stole a march 00:38:25] on everyone?Companies are sprinting to position themselves as leaders in the AI space, despite the fact that they've gotten lapped by basically a small startup that's seven years old. Everyone is trying to work the word AI into things, but it always feels contrived to me. Frankly, it tells me that I need to just start tuning the space out for a year until things settle down and people stop describing metric math or anomaly detection is AI. Stop it. So yeah, I'd say if anything, they're worse than they appear as far as from behind goes.“I mostly focus on AWS. Will I ever cover Azure?” There are certain things that would cause me to do that, but that's because I don't want to be the last Perl consultancy is the entire world has moved off to Python. And effectively, my focus on AWS is because that's where the painful problems I know how to fix live. But that's not a suicide pact. I'm not going to ride that down in flames.But I can retool for a different cloud provider—if that's what the industry starts doing—far faster than AWS can go from its current market-leading status to irrelevance. There are certain triggers that would cause me to do that, but at the time, I don't see them in the near term and I don't have any plans to begin covering other things. As mentioned, people want me to talk about the things I'm good at not the thing that makes me completely nonsensical.“Which AWS services look like a good idea, but pricing-wise, they're going to kill you once you have any scale, especially the ones that look okay pricing-wise but aren't really and it's hard to know going in?” CloudTrail data events, S3 Bucket Access logging any of the logging services really, Managed NAT Gateways in a bunch of cases. There's a lot that starts to get really expensive once you hit certain points of scale with a corollary that everyone thinks that everything they're building is going to scale globally and that's not true. I don't build things as a general rule with the idea that I'm going to get ten million users on it tomorrow because by the time I get from nothing to substantial workloads, I'm going to have multiple refactors of what I've done. I want to get things out the door as fast as possible and if that means that later in time, oh, I accidentally built Pinterest. What am I going to do? Well, okay, yeah, I'm going to need to rebuild a whole bunch of stuff, but I'll have the user traffic and mindshare and market share to finance that growth.Early optimization on stuff like this causes a lot more problems than it solves. “Best practices and anti-patterns in managing AWS costs. For context, you once told me about a role that I had taken that you'd seen lots of companies tried to create that role and then said that the person rarely lasts more than a few months because it just isn't effective. You were right, by the way.” Imagine that I sometimes know what I'm talking about.When it comes to managing costs, understand what your goal is here, what you're actually trying to achieve. Understand it's going to be a cross-functional work between people in finance and people that engineering. It is first and foremost, an engineering problem—you learn that at your peril—and making someone be the human gateway to spin things up means that they're going to quit, basically, instantly. Stop trying to shame different teams without understanding their constraints.Savings Plans are a great example. They apply biggest discount first, which is what you want. Less money going out the door to Amazon, but that makes it look like anything with a low discount percentage, like any workload running on top of Microsoft Windows, is not being responsible because they're always on demand. And you're inappropriately shaming a team for something completely out of their control. There's a point where optimization no longer makes sense. Don't apply it to greenfield projects or skunkworks. Things you want to see if the thing is going to work first. You can optimize it later. Starting out with a, ‘step one: spend as little as possible' is generally not a recipe for success.What else have we got here? I've seen some things fly by in the chat that are probably worth mentioning here. Some of it is just random nonsense, but other things are, I'm sure, tied to various questions here. “With geopolitics shaping up to govern tech data differently in each country, does it make sense to even build a globally distributed B2B SaaS?” Okay, I'm going to tackle this one in a way that people will probably view as a bit of an attack, but it's something I see asked a lot by folks trying to come up with business ideas.At the outset, I'm a big believer in, if you're building something, solve it for a problem and a use case that you intrinsically understand. That is going to mean the customers with whom you speak. Very often, the way business is done in different countries and different cultures means that in some cases, this thing that's a terrific idea in one country is not going to see market adoption somewhere else. There's a better approach to build for the market you have and the one you're addressing rather than aspirational builds. I would also say that it potentially makes sense if there are certain things you know are going to happen, like okay, we validated our marketing and yeah, it turns out that we're building an image resizing site. Great. People in Germany and in the US all both need to resize images.But you know, going in that there's going to be a data residency requirement, so architecting, from day one with an idea that you can have a partition that winds up storing its data separately is always going to be to your benefit. I find aligning whatever you're building with the idea of not being creepy is often a great plan. And there's always the bring your own storage approach to, great, as a customer, you can decide where your data gets stored in your account—charge more for that, sure—but then that na—it becomes their problem. Anything that gets you out of the regulatory critical path is usually a good idea. But with all the problems I would have building a business, that is so far down the list for almost any use case I could ever see pursuing that it's just one of those, you have a half-hour conversation with someone who's been down the path before if you think it might apply to what you're doing, but then get back to the hard stuff. Like, worry on the first two or three steps rather than step 90 just because you'll get there eventually. You don't want to make your future life harder, but you also don't want to spend all your time optimizing early, before you've validated you're actually building something useful.“What unique feature of AWS do I most want to see on other cloud providers and vice versa?” The vice versa is easy. I love that Google Cloud by default has the everything in this project—which is their account equivalent—can talk to everything else, which means that humans aren't just allowing permissions to the universe because it's hard. And I also like that billing is tied to an individual project. ‘Terminate all billable resources in this project' is a button-click away and that's great.Now, what do I wish other cloud providers would take from AWS? Quite honestly, the customer obsession. It's still real. I know it sounds like it's a funny talking point or the people who talk about this the most under the cultists, but they care about customer problems. Back when no one had ever heard of me before and my AWS Bill was seven bucks, whenever I had a problem with a service and I talked about this in passing to folks, Amazonians showed up out of nowhere to help make sure that my problem got answered, that I was taken care of, that I understood what I was misunderstanding, or in some cases, the feedback went to the product team.I see too many companies across the board convinced that they themselves know best about what customers need. That occasionally can be true, but not consistently. When customers are screaming for something, give them what they need, or frankly, get out of the way so someone else can. I mean, I know someone's expecting me to name a service or something, but we've gotten past the point, to my mind, of trying to do an apples-to-oranges comparison in terms of different service offerings. If you want to build a website using any reasonable technology, there's a whole bunch of companies now that have the entire stack for you. Pick one. Have fun.We've got time for a few more here. Also, feel free to drop more questions in. I'm thrilled to wind up answering any of these things. Have I seen any—here's one that about Babelfish, for example, from Justin [Broadly 00:46:07]. “Have I seen anyone using Babelfish in the wild? It seems like it was a great idea that didn't really work or had major trade-offs.”It's a free open-source project that translates from one kind of database SQL to a different kind of database SQL. There have been a whole bunch of attempts at this over the years, and in practice, none of them have really panned out. I have seen no indications that Babelfish is different. If someone at AWS works on this or is a customer using Babelfish and say, “Wait, that's not true,” please tell me because all I'm saying is I have not seen it and I don't expect that I will. But I'm always willing to be wrong. Please, if I say something at some point that someone disagrees with, please reach out to me. I don't intend to perpetuate misinformation.“Purely hypothetically”—yeah, it's always great to ask things hypothetically—“In the companies I work with, which group typically manages purchasing savings plans, the ops team, finance, some mix of both?” It depends. The sad answer is, “What's a savings plan,” asks the company, and then we have an educational path to go down. Often it is individual teams buying them ad hoc, which can work, cannot as long as everyone's on the same page. Central planning, in a bunch of—a company that's past a certain point in sophistication is where everything winds up leading to.And that is usually going to be a series of discussions, ideally run by that group in a cross-functional way. They can be cost engineering, they can be optimization engineering, I've heard it described in a bunch of different ways. But that is—increasingly as the sophistication of your business and the magnitude of your spend increases, the sophistication of how you approach this should change as well. Early on, it's the offense of some VP of engineering at a startup. Like, “Oh, that's a lot of money,” running the analyzer and clicking the button to buy what it says. That's not a bad first-pass attempt. And then I think getting smaller and smaller buys as you continue to proceed means you can start to—it no longer becomes the big giant annual decision and instead becomes part of a frequently used process. That works pretty well, too.Is there anything else that I want to make sure I get to before we wind up running this down? To the folks in the comments, this is your last chance to throw random, awkward questions my way. I'm thrilled to wind up taking any slings, arrows, et cetera, that you care to throw my way a going once, going twice style. Okay, “What is the most esoteric or shocking item on the AWS bill that you ever found with one of your customers?” All right, it's been long enough, and I can say it without naming the customer, so that'll be fun.My personal favorite was a high five-figure bill for Route 53. I joke about using Route 53 as a database. It can be, but there are better options. I would say that there are a whole bunch of use cases for Route 53 and it's a great service, but when it's that much money, it occasions comment. It turned out that—we discovered, in fact, a data exfiltration in progress which made it now a rather clever security incident.And, “This call will now be ending for the day and we're going to go fix that. Thanks.” It's like I want a customer testimonial on that one, but for obvious reasons, we didn't get one. But that was probably the most shocking thing. The depressing thing that I see the most—and this is the core of the cost problem—is not when the numbers are high. It's when I ask about a line item that drives significant spend, and the customer is surprised.I don't like it when customers don't know what they're spending money on. If your service surprises customers when they realize what it costs, you have failed. Because a lot of things are expensive and customers know that and they're willing to take the value in return for the cost. That's fine. But tricking customers does not serve anyone well, even your own long-term interests. I promise.“Have I ever had to reject a potential client because they had a tangled mess that was impossible to tackle, or is there always a way?” It's never the technology that will cause us not to pursue working with a given company. What will is, like, if you go to our website at duckbillgroup.com, you're not going to see a ‘Buy Here' button where you ‘add one consulting, please' to your shopping cart and call it a day.It's a series of conversations. And what we will try to make sure is, what is your goal? Who's aligned with it? What are the problems you're having in getting there? And what does success look like? Who else is involved in this? And it often becomes clear that people don't like the current situation, but there's no outcome with which they would be satisfied.Or they want something that we do not do. For example, “We want you to come in and implement all of your findings.” We are advisory. We do not know the specifics of your environment and—or your deployment processes or the rest. We're not an engineering shop. We charge a fixed fee and part of the way we can do that is by controlling the scope of what we do. “Well, you know, we have some AWS bills, but we really want to—we really care about is our GCP bill or our Datadog bill.” Great. We don't focus on either of those things. I mean, I can just come in and sound competent, but that's not what adding value as a consultant is about. It's about being authoritatively correct. Great question, though.“How often do I receive GovCloud cost optimization requests? Does the compliance and regulation that these customers typically have keep them from making the needed changes?” It doesn't happen often and part of the big reason behind that is that when we're—and if you're in GovCloud, it's probably because you are a significant governmental entity. There's not a lot of private sector in GovCloud for almost every workload there. Yes, there are exceptions; we don't tend to do a whole lot with them.And the government procurement process is a beast. We can sell and service three to five commercial engagements in the time it takes to negotiate a single GovCloud agreement with a customer, so it just isn't something that we focused. We don't have the scale to wind up tackling that down. Let's also be clear that, in many cases, governments don't view money the same way as enterprise, which in part is a good thing, but it also means that, “This cloud thing is too expensive,” is never the stated problem. Good question.“Waffles or pancakes?” Is another one. I… tend to go with eggs, personally. It just feels like empty filler in the morning. I mean, you could put syrup on anything if you're bold enough, so if it's just a syrup delivery vehicle, there are other paths to go.And I believe we might have exhausted the question pool. So, I want to thank you all for taking the time to talk with me. Once again, I am Cloud Economist Corey Quinn. And this is a very special live episode of Screaming in the Cloud. If you've enjoyed this podcast, please leave a five-star review wherever you can—or a thumbs up, or whatever it is, like and subscribe obviously—whereas if you've hated this podcast, same thing: five-star review, but also go ahead and leave an insulting comment, usually around something I've said about a service that you deeply care about because it's tied to your paycheck.Corey: If your AWS bill keeps rising and your blood pressure is doing the same, then you need The Duckbill Group. We help companies fix their AWS bill by making it smaller and less horrifying. The Duckbill Group works for you, not AWS. We tailor recommendations to your business and we get to the point. Visit duckbillgroup.com to get started.

Screaming in the Cloud
Building Computers for the Cloud with Steve Tuck

Screaming in the Cloud

Play Episode Listen Later Sep 21, 2023 42:18


Steve Tuck, Co-Founder & CEO of Oxide Computer Company, joins Corey on Screaming in the Cloud to discuss his work to make modern computers cloud-friendly. Steve describes what it was like going through early investment rounds, and the difficult but important decision he and his co-founder made to build their own switch. Corey and Steve discuss the demand for on-prem computers that are built for cloud capability, and Steve reveals how Oxide approaches their product builds to ensure the masses can adopt their technology wherever they are. About SteveSteve is the Co-founder & CEO of Oxide Computer Company.  He previously was President & COO of Joyent, a cloud computing company acquired by Samsung.  Before that, he spent 10 years at Dell in a number of different roles. Links Referenced: Oxide Computer Company: https://oxide.computer/ On The Metal Podcast: https://oxide.computer/podcasts/on-the-metal TranscriptAnnouncer: Hello, and welcome to Screaming in the Cloud with your host, Chief Cloud Economist at The Duckbill Group, Corey Quinn. This weekly show features conversations with people doing interesting work in the world of cloud, thoughtful commentary on the state of the technical world, and ridiculous titles for which Corey refuses to apologize. This is Screaming in the Cloud.Corey: This episode is brought to us in part by our friends at RedHat. As your organization grows, so does the complexity of your IT resources. You need a flexible solution that lets you deploy, manage, and scale workloads throughout your entire ecosystem. The Red Hat Ansible Automation Platform simplifies the management of applications and services across your hybrid infrastructure with one platform. Look for it on the AWS Marketplace.Corey: Welcome to Screaming in the Cloud. I'm Corey Quinn. You know, I often say it—but not usually on the show—that Screaming in the Cloud is a podcast about the business of cloud, which is intentionally overbroad so that I can talk about basically whatever the hell I want to with whoever the hell I'd like. Today's guest is, in some ways of thinking, about as far in the opposite direction from Cloud as it's possible to go and still be involved in the digital world. Steve Tuck is the CEO at Oxide Computer Company. You know, computers, the things we all pretend aren't underpinning those clouds out there that we all use and pay by the hour, gigabyte, second-month-pound or whatever it works out to. Steve, thank you for agreeing to come back on the show after a couple years, and once again suffer my slings and arrows.Steve: Much appreciated. Great to be here. It has been a while. I was looking back, I think three years. This was like, pre-pandemic, pre-interest rates, pre… Twitter going totally sideways.Corey: And I have to ask to start with that, it feels, on some level, like toward the start of the pandemic, when everything was flying high and we'd had low interest rates for a decade, that there was a lot of… well, lunacy lurking around in the industry, my own business saw it, too. It turns out that not giving a shit about the AWS bill is in fact a zero interest rate phenomenon. And with all that money or concentrated capital sloshing around, people decided to do ridiculous things with it. I would have thought, on some level, that, “We're going to start a computer company in the Bay Area making computers,” would have been one of those, but given that we are a year into the correction, and things seem to be heading up into the right for you folks, that take was wrong. How'd I get it wrong?Steve: Well, I mean, first of all, you got part of it right, which is there were just a litany of ridiculous companies and projects and money being thrown in all directions at that time.Corey: An NFT of a computer. We're going to have one of those. That's what you're selling, right? Then you had to actually hard pivot to making the real thing.Steve: That's it. So, we might as well cut right to it, you know. This is—we went through the crypto phase. But you know, our—when we started the company, it was yes, a computer company. It's on the tin. It's definitely kind of the foundation of what we're building. But you know, we think about what a modern computer looks like through the lens of cloud.I was at a cloud computing company for ten years prior to us founding Oxide, so was Bryan Cantrill, CTO, co-founder. And, you know, we are huge, huge fans of cloud computing, which was an interesting kind of dichotomy. Instead of conversations when we were raising for Oxide—because of course, Sand Hill is terrified of hardware. And when we think about what modern computers need to look like, they need to be in support of the characteristics of cloud, and cloud computing being not that you're renting someone else's computers, but that you have fully programmable infrastructure that allows you to slice and dice, you know, compute and storage and networking however software needs. And so, what we set out to go build was a way for the companies that are running on-premises infrastructure—which, by the way, is almost everyone and will continue to be so for a very long time—access to the benefits of cloud computing. And to do that, you need to build a different kind of computing infrastructure and architecture, and you need to plumb the whole thing with software.Corey: There are a number of different ways to view cloud computing. And I think that a lot of the, shall we say, incumbent vendors over in the computer manufacturing world tend to sound kind of like dinosaurs, on some level, where they're always talking in terms of, you're a giant company and you already have a whole bunch of data centers out there. But one of the magical pieces of cloud is you can have a ridiculous idea at nine o'clock tonight and by morning, you'll have a prototype, if you're of that bent. And if it turns out it doesn't work, you're out, you know, 27 cents. And if it does work, you can keep going and not have to stop and rebuild on something enterprise-grade.So, for the small-scale stuff and rapid iteration, cloud providers are terrific. Conversely, when you wind up in the giant fleets of millions of computers, in some cases, there begin to be economic factors that weigh in, and for some on workloads—yes, I know it's true—going to a data center is the economical choice. But my question is, is starting a new company in the direction of building these things, is it purely about economics or is there a capability story tied in there somewhere, too?Steve: Yeah, it's actually economics ends up being a distant third, fourth, in the list of needs and priorities from the companies that we're working with. When we talk about—and just to be clear we're—our demographic, that kind of the part of the market that we are focused on are large enterprises, like, folks that are spending, you know, half a billion, billion dollars a year in IT infrastructure, they, over the last five years, have moved a lot of the use cases that are great for public cloud out to the public cloud, and who still have this very, very large need, be it for latency reasons or cost reasons, security reasons, regulatory reasons, where they need on-premises infrastructure in their own data centers and colo facilities, et cetera. And it is for those workloads in that part of their infrastructure that they are forced to live with enterprise technologies that are 10, 20, 30 years old, you know, that haven't evolved much since I left Dell in 2009. And, you know, when you think about, like, what are the capabilities that are so compelling about cloud computing, one of them is yes, what you mentioned, which is you have an idea at nine o'clock at night and swipe a credit card, and you're off and running. And that is not the case for an idea that someone has who is going to use the on-premises infrastructure of their company. And this is where you get shadow IT and 16 digits to freedom and all the like.Corey: Yeah, everyone with a corporate credit card winds up being a shadow IT source in many cases. If your processes as a company don't make it easier to proceed rather than doing it the wrong way, people are going to be fighting against you every step of the way. Sometimes the only stick you've got is that of regulation, which in some industries, great, but in other cases, no, you get to play Whack-a-Mole. I've talked to too many companies that have specific scanners built into their mail system every month looking for things that look like AWS invoices.Steve: [laugh]. Right, exactly. And so, you know, but if you flip it around, and you say, well, what if the experience for all of my infrastructure that I am running, or that I want to provide to my software development teams, be it rented through AWS, GCP, Azure, or owned for economic reasons or latency reasons, I had a similar set of characteristics where my development team could hit an API endpoint and provision instances in a matter of seconds when they had an idea and only pay for what they use, back to kind of corporate IT. And what if they were able to use the same kind of developer tools they've become accustomed to using, be it Terraform scripts and the kinds of access that they are accustomed to using? How do you make those developers just as productive across the business, instead of just through public cloud infrastructure?At that point, then you are in a much stronger position where you can say, you know, for a portion of things that are, as you pointed out, you know, more unpredictable, and where I want to leverage a bunch of additional services that a particular cloud provider has, I can rent that. And where I've got more persistent workloads or where I want a different economic profile or I need to have something in a very low latency manner to another set of services, I can own it. And that's where I think the real chasm is because today, you just don't—we take for granted the basic plumbing of cloud computing, you know? Elastic Compute, Elastic Storage, you know, networking and security services. And us in the cloud industry end up wanting to talk a lot more about exotic services and, sort of, higher-up stack capabilities. None of that basic plumbing is accessible on-prem.Corey: I also am curious as to where exactly Oxide lives in the stack because I used to build computers for myself in 2000, and it seems like having gone down that path a bit recently, yeah, that process hasn't really improved all that much. The same off-the-shelf components still exist and that's great. We always used to disparagingly call spinning hard drives as spinning rust in racks. You named the company Oxide; you're talking an awful lot about the Rust programming language in public a fair bit of the time, and I'm starting to wonder if maybe words don't mean what I thought they meant anymore. Where do you folks start and stop, exactly?Steve: Yeah, that's a good question. And when we started, we sort of thought the scope of what we were going to do and then what we were going to leverage was smaller than it has turned out to be. And by that I mean, man, over the last three years, we have hit a bunch of forks in the road where we had questions about do we take something off the shelf or do we build it ourselves. And we did not try to build everything ourselves. So, to give you a sense of kind of where the dotted line is, around the Oxide product, what we're delivering to customers is a rack-level computer. So, the minimum size comes in rack form. And I think your listeners are probably pretty familiar with this. But, you know, a rack is—Corey: You would be surprised. It's basically, what are they about seven feet tall?Steve: Yeah, about eight feet tall.Corey: Yeah, yeah. Seven, eight feet, weighs a couple 1000 pounds, you know, make an insulting joke about—Steve: Two feet wide.Corey: —NBA players here. Yeah, all kinds of these things.Steve: Yeah. And big hunk of metal. And in the cases of on-premises infrastructure, it's kind of a big hunk of metal hole, and then a bunch of 1U and 2U boxes crammed into it. What the hyperscalers have done is something very different. They started looking at, you know, at the rack level, how can you get much more dense, power-efficient designs, doing things like using a DC bus bar down the back, instead of having 64 power supplies with cables hanging all over the place in a rack, which I'm sure is what you're more familiar with.Corey: Tremendous amount of weight as well because you have the metal chassis for all of those 1U things, which in some cases, you wind up with, what, 46U in a rack, assuming you can even handle the cooling needs of all that.Steve: That's right.Corey: You have so much duplication, and so much of the weight is just metal separating one thing from the next thing down below it. And there are opportunities for massive improvement, but you need to be at a certain point of scale to get there.Steve: You do. You do. And you also have to be taking on the entire problem. You can't pick at parts of these things. And that's really what we found. So, we started at this sort of—the rack level as sort of the design principle for the product itself and found that that gave us the ability to get to the right geometry, to get as much CPU horsepower and storage and throughput and networking into that kind of chassis for the least amount of wattage required, kind of the most power-efficient design possible.So, it ships at the rack level and it ships complete with both our server sled systems in Oxide, a pair of Oxide switches. This is—when I talk about, like, design decisions, you know, do we build our own switch, it was a big, big, big question early on. We were fortunate even though we were leaning towards thinking we needed to go do that, we had this prospective early investor who was early at AWS and he had asked a very tough question that none of our other investors had asked to this point, which is, “What are you going to do about the switch?”And we knew that the right answer to an investor is like, “No. We're already taking on too much.” We're redesigning a server from scratch in, kind of, the mold of what some of the hyperscalers have learned, doing our own Root of Trust, we're doing our own operating system, hypervisor control plane, et cetera. Taking on the switch could be seen as too much, but we told them, you know, we think that to be able to pull through all of the value of the security benefits and the performance and observability benefits, we can't have then this [laugh], like, obscure third-party switch rammed into this rack.Corey: It's one of those things that people don't think about, but it's the magic of cloud with AWS's network, for example, it's magic. You can get line rate—or damn near it—between any two points, sustained.Steve: That's right.Corey: Try that in the data center, you wind into massive congestion with top-of-rack switches, where, okay, we're going to parallelize this stuff out over, you know, two dozen racks and we're all going to have them seamlessly transfer information between each other at line rate. It's like, “[laugh] no, you're not because those top-of-rack switches will melt and become side-of-rack switches, and then bottom-puddle-of-rack switches. It doesn't work that way.”Steve: That's right.Corey: And you have to put a lot of thought and planning into it. That is something that I've not heard a traditional networking vendor addressing because everyone loves to hand-wave over it.Steve: Well so, and this particular prospective investor, we told him, “We think we have to go build our own switch.” And he said, “Great.” And we said, “You know, we think we're going to lose you as an investor as a result, but this is what we're doing.” And he said, “If you're building your own switch, I want to invest.” And his comment really stuck with us, which is AWS did not stand on their own two feet until they threw out their proprietary switch vendor and built their own.And that really unlocked, like you've just mentioned, like, their ability, both in hardware and software to tune and optimize to deliver that kind of line rate capability. And that is one of the big findings for us as we got into it. Yes, it was really, really hard, but based on a couple of design decisions, P4 being the programming language that we are using as the surround for our silicon, tons of opportunities opened up for us to be able to do similar kinds of optimization and observability. And that has been a big, big win.But to your question of, like, where does it stop? So, we are delivering this complete with a baked-in operating system, hypervisor, control plane. And so, the endpoint of the system, where the customer meets is either hitting an API or a CLI or a console that delivers and kind of gives you the ability to spin up projects. And, you know, if one is familiar with EC2 and EBS and VPC, that VM level of abstraction is where we stop.Corey: That, I think, is a fair way of thinking about it. And a lot of cloud folks are going to pooh-pooh it as far as saying, “Oh well, just virtual machines. That's old cloud. That just treats the cloud like a data center.” And in many cases, yes, it does because there are ways to build modern architectures that are event-driven on top of things like Lambda, and API Gateway, and the rest, but you take a look at what my customers are doing and what drives the spend, it is invariably virtual machines that are largely persistent.Sometimes they scale up, sometimes they scale down, but there's always a baseline level of load that people like to hand-wave away the fact that what they're fundamentally doing in a lot of these cases, is paying the cloud provider to handle the care and feeding of those systems, which can be expensive, yes, but also delivers significant innovation beyond what almost any company is going to be able to deliver in-house. There is no way around it. AWS is better than you are—whoever you happen to—be at replacing failed hard drives. That is a simple fact. They have teams of people who are the best in the world of replacing failed hard drives. You generally do not. They are going to be better at that than you. But that's not the only axis. There's not one calculus that leads to, is cloud a scam or is cloud a great value proposition for us? The answer is always a deeply nuanced, “It depends.”Steve: Yeah, I mean, I think cloud is a great value proposition for most and a growing amount of software that's being developed and deployed and operated. And I think, you know, one of the myths that is out there is, hey, turn over your IT to AWS because we have or you know, a cloud provider—because we have such higher caliber personnel that are really good at swapping hard drives and dealing with networks and operationally keeping this thing running in a highly available manner that delivers good performance. That is certainly true, but a lot of the operational value in an AWS is been delivered via software, the automation, the observability, and not actual people putting hands on things. And it's an important point because that's been a big part of what we're building into the product. You know, just because you're running infrastructure in your own data center, it does not mean that you should have to spend, you know, 1000 hours a month across a big team to maintain and operate it. And so, part of that, kind of, cloud, hyperscaler innovation that we're baking into this product is so that it is easier to operate with much, much, much lower overhead in a highly available, resilient manner.Corey: So, I've worked in a number of data center facilities, but the companies I was working with, were always at a scale where these were co-locations, where they would, in some cases, rent out a rack or two, in other cases, they'd rent out a cage and fill it with their own racks. They didn't own the facilities themselves. Those were always handled by other companies. So, my question for you is, if I want to get a pile of Oxide racks into my environment in a data center, what has to change? What are the expectations?I mean, yes, there's obviously going to be power and requirements at the data center colocation is very conversant with, but Open Compute, for example, had very specific requirements—to my understanding—around things like the airflow construction of the environment that they're placed within. How prescriptive is what you've built, in terms of doing a building retrofit to start using you folks?Steve: Yeah, definitely not. And this was one of the tensions that we had to balance as we were designing the product. For all of the benefits of hyperscaler computing, some of the design center for you know, the kinds of racks that run in Google and Amazon and elsewhere are hyperscaler-focused, which is unlimited power, in some cases, data centers designed around the equipment itself. And where we were headed, which was basically making hyperscaler infrastructure available to, kind of, the masses, the rest of the market, these folks don't have unlimited power and they aren't going to go be able to go redesign data centers. And so no, the experience should be—with exceptions for folks maybe that have very, very limited access to power—that you roll this rack into your existing data center. It's on standard floor tile, that you give it power, and give it networking and go.And we've spent a lot of time thinking about how we can operate in the wide-ranging environmental characteristics that are commonplace in data centers that focus on themselves, colo facilities, and the like. So, that's really on us so that the customer is not having to go to much work at all to kind of prepare and be ready for it.Corey: One of the challenges I have is how to think about what you've done because you are rack-sized. But what that means is that my own experimentation at home recently with on-prem stuff for smart home stuff involves a bunch of Raspberries Pi and a [unintelligible 00:19:42], but I tend to more or less categorize you the same way that I do AWS Outposts, as well as mythical creatures, like unicorns or giraffes, where I don't believe that all these things actually exist because I haven't seen them. And in fact, to get them in my house, all four of those things would theoretically require a loading dock if they existed, and that's a hard thing to fake on a demo signup form, as it turns out. How vaporware is what you've built? Is this all on paper and you're telling amazing stories or do they exist in the wild?Steve: So, last time we were on, it was all vaporware. It was a couple of napkin drawings and a seed round of funding.Corey: I do recall you not using that description at the time, for what it's worth. Good job.Steve: [laugh]. Yeah, well, at least we were transparent where we were going through the race. We had some napkin drawings and we had some good ideas—we thought—and—Corey: You formalize those and that's called Microsoft PowerPoint.Steve: That's it. A hundred percent.Corey: The next generative AI play is take the scrunched-up, stained napkin drawing, take a picture of it, and convert it to a slide.Steve: Google Docs, you know, one of those. But no, it's got a lot of scars from the build and it is real. In fact, next week, we are going to be shipping our first commercial systems. So, we have got a line of racks out in our manufacturing facility in lovely Rochester, Minnesota. Fun fact: Rochester, Minnesota, is where the IBM AS/400s were built.Corey: I used to work in that market, of all things.Steve: Really?Corey: Selling tape drives in the AS/400. I mean, I still maintain there's no real mainframe migration to the cloud play because there's no AWS/400. A joke that tends to sail over an awful lot of people's heads because, you know, most people aren't as miserable in their career choices as I am.Steve: Okay, that reminds me. So, when we were originally pitching Oxide and we were fundraising, we [laugh]—in a particular investor meeting, they asked, you know, “What would be a good comp? Like how should we think about what you are doing?” And fortunately, we had about 20 investor meetings to go through, so burning one on this was probably okay, but we may have used the AS/400 as a comp, talking about how [laugh] mainframe systems did such a good job of building hardware and software together. And as you can imagine, there were some blank stares in that room.But you know, there are some good analogs to historically in the computing industry, when you know, the industry, the major players in the industry, were thinking about how to deliver holistic systems to support end customers. And, you know, we see this in the what Apple has done with the iPhone, and you're seeing this as a lot of stuff in the automotive industry is being pulled in-house. I was listening to a good podcast. Jim Farley from Ford was talking about how the automotive industry historically outsourced all of the software that controls cars, right? So, like, Bosch would write the software for the controls for your seats.And they had all these suppliers that were writing the software, and what it meant was that innovation was not possible because you'd have to go out to suppliers to get software changes for any little change you wanted to make. And in the computing industry, in the 80s, you saw this blow apart where, like, firmware got outsourced. In the IBM and the clones, kind of, race, everyone started outsourcing firmware and outsourcing software. Microsoft started taking over operating systems. And then VMware emerged and was doing a virtualization layer.And this, kind of, fragmented ecosystem is the landscape today that every single on-premises infrastructure operator has to struggle with. It's a kit car. And so, pulling it back together, designing things in a vertically integrated manner is what the hyperscalers have done. And so, you mentioned Outposts. And, like, it's a good example of—I mean, the most public cloud of public cloud companies created a way for folks to get their system on-prem.I mean, if you need anything to underscore the draw and the demand for cloud computing-like, infrastructure on-prem, just the fact that that emerged at all tells you that there is this big need. Because you've got, you know, I don't know, a trillion dollars worth of IT infrastructure out there and you have maybe 10% of it in the public cloud. And that's up from 5% when Jassy was on stage in '21, talking about 95% of stuff living outside of AWS, but there's going to be a giant market of customers that need to own and operate infrastructure. And again, things have not improved much in the last 10 or 20 years for them.Corey: They have taken a tone onstage about how, “Oh, those workloads that aren't in the cloud, yet, yeah, those people are legacy idiots.” And I don't buy that for a second because believe it or not—I know that this cuts against what people commonly believe in public—but company execs are generally not morons, and they make decisions with context and constraints that we don't see. Things are the way they are for a reason. And I promise that 90% of corporate IT workloads that still live on-prem are not being managed or run by people who've never heard of the cloud. There was a decision made when some other things were migrating of, do we move this thing to the cloud or don't we? And the answer at the time was no, we're going to keep this thing on-prem where it is now for a variety of reasons of varying validity. But I don't view that as a bug. I also, frankly, don't want to live in a world where all the computers are basically run by three different companies.Steve: You're spot on, which is, like, it does a total disservice to these smart and forward-thinking teams in every one of the Fortune 1000-plus companies who are taking the constraints that they have—and some of those constraints are not monetary or entirely workload-based. If you want to flip it around, we were talking to a large cloud SaaS company and their reason for wanting to extend it beyond the public cloud is because they want to improve latency for their e-commerce platform. And navigating their way through the complex layers of the networking stack at GCP to get to where the customer assets are that are in colo facilities, adds lag time on the platform that can cost them hundreds of millions of dollars. And so, we need to think behind this notion of, like, “Oh, well, the dark ages are for software that can't run in the cloud, and that's on-prem. And it's just a matter of time until everything moves to the cloud.”In the forward-thinking models of public cloud, it should be both. I mean, you should have a consistent experience, from a certain level of the stack down, everywhere. And then it's like, do I want to rent or do I want to own for this particular use case? In my vast set of infrastructure needs, do I want this to run in a data center that Amazon runs or do I want this to run in a facility that is close to this other provider of mine? And I think that's best for all. And then it's not this kind of false dichotomy of quality infrastructure or ownership.Corey: I find that there are also workloads where people will come to me and say, “Well, we don't think this is going to be economical in the cloud”—because again, I focus on AWS bills. That is the lens I view things through, and—“The AWS sales rep says it will be. What do you think?” And I look at what they're doing and especially if involves high volumes of data transfer, I laugh a good hearty laugh and say, “Yeah, keep that thing in the data center where it is right now. You will thank me for it later.”It's, “Well, can we run this in an economical way in AWS?” As long as you're okay with economical meaning six times what you're paying a year right now for the same thing, yeah, you can. I wouldn't recommend it. And the numbers sort of speak for themselves. But it's not just an economic play.There's also the story of, does this increase their capability? Does it let them move faster toward their business goals? And in a lot of cases, the answer is no, it doesn't. It's one of those business process things that has to exist for a variety of reasons. You don't get to reimagine it for funsies and even if you did, it doesn't advance the company in what they're trying to do any, so focus on something that differentiates as opposed to this thing that you're stuck on.Steve: That's right. And what we see today is, it is easy to be in that mindset of running things on-premises is kind of backwards-facing because the experience of it is today still very, very difficult. I mean, talking to folks and they're sharing with us that it takes a hundred days from the time all the different boxes land in their warehouse to actually having usable infrastructure that developers can use. And our goal and what we intend to go hit with Oxide as you can roll in this complete rack-level system, plug it in, within an hour, you have developers that are accessing cloud-like services out of the infrastructure. And that—God, countless stories of firmware bugs that would send all the fans in the data center nonlinear and soak up 100 kW of power.Corey: Oh, God. And the problems that you had with the out-of-band management systems. For a long time, I thought Drax stood for, “Dell, RMA Another Computer.” It was awful having to deal with those things. There was so much room for innovation in that space, which no one really grabbed onto.Steve: There was a really, really interesting talk at DEFCON that we just stumbled upon yesterday. The NVIDIA folks are giving a talk on BMC exploits… and like, a very, very serious BMC exploit. And again, it's what most people don't know is, like, first of all, the BMC, the Baseboard Management Controller, is like the brainstem of the computer. It has access to—it's a backdoor into all of your infrastructure. It's a computer inside a computer and it's got software and hardware that your server OEM didn't build and doesn't understand very well.And firmware is even worse because you know, firmware written by you know, an American Megatrends or other is a big blob of software that gets loaded into these systems that is very hard to audit and very hard to ascertain what's happening. And it's no surprise when, you know, back when we were running all the data centers at a cloud computing company, that you'd run into these issues, and you'd go to the server OEM and they'd kind of throw their hands up. Well, first they'd gaslight you and say, “We've never seen this problem before,” but when you thought you've root-caused something down to firmware, it was anyone's guess. And this is kind of the current condition today. And back to, like, the journey to get here, we kind of realized that you had to blow away that old extant firmware layer, and we rewrote our own firmware in Rust. Yes [laugh], I've done a lot in Rust.Corey: No, it was in Rust, but, on some level, that's what Nitro is, as best I can tell, on the AWS side. But it turns out that you don't tend to have the same resources as a one-and-a-quarter—at the moment—trillion-dollar company. That keeps [valuing 00:30:53]. At one point, they lost a comma and that was sad and broke all my logic for that and I haven't fixed it since. Unfortunate stuff.Steve: Totally. I think that was another, kind of, question early on from certainly a lot of investors was like, “Hey, how are you going to pull this off with a smaller team and there's a lot of surface area here?” Certainly a reasonable question. Definitely was hard. The one advantage—among others—is, when you are designing something kind of in a vertical holistic manner, those design integration points are narrowed down to just your equipment.And when someone's writing firmware, when AMI is writing firmware, they're trying to do it to cover hundreds and hundreds of components across dozens and dozens of vendors. And we have the advantage of having this, like, purpose-built system, kind of, end-to-end from the lowest level from first boot instruction, all the way up through the control plane and from rack to switch to server. That definitely helped narrow the scope.Corey: This episode has been fake sponsored by our friends at AWS with the following message: Graviton Graviton, Graviton, Graviton, Graviton, Graviton, Graviton, Graviton, Graviton. Thank you for your l-, lack of support for this show. Now, AWS has been talking about Graviton an awful lot, which is their custom in-house ARM processor. Apple moved over to ARM and instead of talking about benchmarks they won't publish and marketing campaigns with words that don't mean anything, they've let the results speak for themselves. In time, I found that almost all of my workloads have moved over to ARM architecture for a variety of reason, and my laptop now gets 15 hours of battery life when all is said and done. You're building these things on top of x86. What is the deal there? I do not accept that if that you hadn't heard of ARM until just now because, as mentioned, Graviton, Graviton, Graviton.Steve: That's right. Well, so why x86, to start? And I say to start because we have just launched our first generation products. And our first-generation or second-generation products that we are now underway working on are going to be x86 as well. We've built this system on AMD Milan silicon; we are going to be launching a Genoa sled.But when you're thinking about what silicon to use, obviously, there's a bunch of parts that go into the decision. You're looking at the kind of applicability to workload, performance, power management, for sure, and if you carve up what you are trying to achieve, x86 is still a terrific fit for the broadest set of workloads that our customers are trying to solve for. And choosing which x86 architecture was certainly an easier choice, come 2019. At this point, AMD had made a bunch of improvements in performance and energy efficiency in the chip itself. We've looked at other architectures and I think as we are incorporating those in the future roadmap, it's just going to be a question of what are you trying to solve for.You mentioned power management, and that is kind of commonly been a, you know, low power systems is where folks have gone beyond x86. Is we're looking forward to hardware acceleration products and future products, we'll certainly look beyond x86, but x86 has a long, long road to go. It still is kind of the foundation for what, again, is a general-purpose cloud infrastructure for being able to slice and dice for a variety of workloads.Corey: True. I have to look around my environment and realize that Intel is not going anywhere. And that's not just an insult to their lack of progress on committed roadmaps that they consistently miss. But—Steve: [sigh].Corey: Enough on that particular topic because we want to keep this, you know, polite.Steve: Intel has definitely had some struggles for sure. They're very public ones, I think. We were really excited and continue to be very excited about their Tofino silicon line. And this came by way of the Barefoot networks acquisition. I don't know how much you had paid attention to Tofino, but what was really, really compelling about Tofino is the focus on both hardware and software and programmability.So, great chip. And P4 is the programming language that surrounds that. And we have gotten very, very deep on P4, and that is some of the best tech to come out of Intel lately. But from a core silicon perspective for the rack, we went with AMD. And again, that was a pretty straightforward decision at the time. And we're planning on having this anchored around AMD silicon for a while now.Corey: One last question I have before we wind up calling it an episode, it seems—at least as of this recording, it's still embargoed, but we're not releasing this until that winds up changing—you folks have just raised another round, which means that your napkin doodles have apparently drawn more folks in, and now that you're shipping, you're also not just bringing in customers, but also additional investor money. Tell me about that.Steve: Yes, we just completed our Series A. So, when we last spoke three years ago, we had just raised our seed and had raised $20 million at the time, and we had expected that it was going to take about that to be able to build the team and build the product and be able to get to market, and [unintelligible 00:36:14] tons of technical risk along the way. I mean, there was technical risk up and down the stack around this [De Novo 00:36:21] server design, this the switch design. And software is still the kind of disproportionate majority of what this product is, from hypervisor up through kind of control plane, the cloud services, et cetera. So—Corey: We just view it as software with a really, really confusing hardware dongle.Steve: [laugh]. Yeah. Yes.Corey: Super heavy. We're talking enterprise and government-grade here.Steve: That's right. There's a lot of software to write. And so, we had a bunch of milestones that as we got through them, one of the big ones was getting Milan silicon booting on our firmware. It was funny it was—this was the thing that clearly, like, the industry was most suspicious of, us doing our own firmware, and you could see it when we demonstrated booting this, like, a year-and-a-half ago, and AMD all of a sudden just lit up, from kind of arm's length to, like, “How can we help? This is amazing.” You know? And they could start to see the benefits of when you can tie low-level silicon intelligence up through a hypervisor there's just—Corey: No I love the existing firmware I have. Looks like it was written in 1984 and winds up having terrible user ergonomics that hasn't been updated at all, and every time something comes through, it's a 50/50 shot as whether it fries the box or not. Yeah. No, I want that.Steve: That's right. And you look at these hyperscale data centers, and it's like, no. I mean, you've got intelligence from that first boot instruction through a Root of Trust, up through the software of the hyperscaler, and up to the user level. And so, as we were going through and kind of knocking down each one of these layers of the stack, doing our own firmware, doing our own hardware Root of Trust, getting that all the way plumbed up into the hypervisor and the control plane, number one on the customer side, folks moved from, “This is really interesting. We need to figure out how we can bring cloud capabilities to our data centers. Talk to us when you have something,” to, “Okay. We actually”—back to the earlier question on vaporware, you know, it was great having customers out here to Emeryville where they can put their hands on the rack and they can, you know, put your hands on software, but being able to, like, look at real running software and that end cloud experience.And that led to getting our first couple of commercial contracts. So, we've got some great first customers, including a large department of the government, of the federal government, and a leading firm on Wall Street that we're going to be shipping systems to in a matter of weeks. And as you can imagine, along with that, that drew a bunch of renewed interest from the investor community. Certainly, a different climate today than it was back in 2019, but what was great to see is, you still have great investors that understand the importance of making bets in the hard tech space and in companies that are looking to reinvent certain industries. And so, we added—our existing investors all participated. We added a bunch of terrific new investors, both strategic and institutional.And you know, this capital is going to be super important now that we are headed into market and we are beginning to scale up the business and make sure that we have a long road to go. And of course, maybe as importantly, this was a real confidence boost for our customers. They're excited to see that Oxide is going to be around for a long time and that they can invest in this technology as an important part of their infrastructure strategy.Corey: I really want to thank you for taking the time to speak with me about, well, how far you've come in a few years. If people want to learn more and have the requisite loading dock, where should they go to find you?Steve: So, we try to put everything up on the site. So, oxidecomputer.com or oxide.computer. We also, if you remember, we did [On the Metal 00:40:07]. So, we had a Tales from the Hardware-Software Interface podcast that we did when we started. We have shifted that to Oxide and Friends, which the shift there is we're spending a little bit more time talking about the guts of what we built and why. So, if folks are interested in, like, why the heck did you build a switch and what does it look like to build a switch, we actually go to depth on that. And you know, what does bring-up on a new server motherboard look like? And it's got some episodes out there that might be worth checking out.Corey: We will definitely include a link to that in the [show notes 00:40:36]. Thank you so much for your time. I really appreciate it.Steve: Yeah, Corey. Thanks for having me on.Corey: Steve Tuck, CEO at Oxide Computer Company. I'm Cloud Economist Corey Quinn, and this is Screaming in the Cloud. If you've enjoyed this podcast, please leave a five-star review on your podcast platform of choice, whereas if you've hated this episode, please leave a five-star review on your podcast platform of choice, along with an angry ranting comment because you are in fact a zoology major, and you're telling me that some animals do in fact exist. But I'm pretty sure of the two of them, it's the unicorn.Corey: If your AWS bill keeps rising and your blood pressure is doing the same, then you need The Duckbill Group. We help companies fix their AWS bill by making it smaller and less horrifying. The Duckbill Group works for you, not AWS. We tailor recommendations to your business and we get to the point. Visit duckbillgroup.com to get started.