SlideShare a Scribd company logo
Jonathan Le Lous
Director Engineering Engagement and
Release Platforms
Thibault Cohen
Release Platforms Lead
Global Technology
1
DevOps & Insurance Company:
Create a Bridge between
Security and Change
Jonathan -- @jollfr
2
Thibault -- @ttb_lt -- github.com/titilambert
3
4
Ratings
A.M. Best A+
DBRS AA (low)
Fitch AA-
Moody’s A1
S&P AA-
Serving
1 in 3
Canadians
Founded in
1887
Canada’s largest
insurance company
20+
countries
Employee volunteer
hours: 107,288
Community
investment:
$39.9M
Investments in renewable energy and energy efficiency
projects: $10.9B
Manulife economic
impact
Assets managed
and administered
$1 trillion
Statistics as of December 31, 2017
Manulife
5
New technology
companies
Our market is
changing
‘Honouring our Past, Engaging our Future’
“transforming our business to be much more of a technology-driven
company” Roy Gori, Manulife’s CEO.
▪ Legacy – Reducing the Run and Modernize Apps
▪ Net New – Leveraging Micro-services and APIs
6
7
IT Realities
Platform Strategy: Kubernetes & PCF
‘‘While Cloud Foundry's PaaS can free up developers from infrastructure management worries,
Kubernetes' container orchestration and cluster management functions can preserve control over
the infrastructure for ops.’’ TechTarget (03/27/2017)
8
1. Legacy Apps
2. DevOps
1. Build Net New apps
2. Production Platform
1. Convergence strategy
2. Decision Framework
DevOps = removing barriers
=
CI
CD
Example 1: The easy one
▪ All developer teams are using Scrum methodology
▪ All new projects are micro services running in PCF
▪ These projects are stored in GitLab using forking strategy
▪ The CI is based on Jenkins Pipelines
▪ Unit tests, SonarQube, BlackDuck, Fortify, ...
▪ The CD is based on Concourse
▪ 4 persistent PCF environments : DEV/TEST/QA/PROD
10
Example 2: Back to the future
▪ Bring a 28 years old application to Gitlab/Jenkins
▪ Migrate more than 30000 commits from Harvest to Git
▪ Reproduce Harvest concepts with Gitlab/Jenkins
▪ Reduce developer learning curve
▪ Next steps:
▪ Move away from Harvest concepts to standard DevOps concepts
▪ Add more automated tests in Jenkins (SonarQube, BlackDuck, Fortify, ...)
▪ Add more tools in the pipeline (Doxygen, HyperSQL, ...)
11
Automate Best Practices
12
▪ Generic CI: Code Review, Security, Open
Source Governance, QA..
▪ Security:
▪ Automated Security Scans (Code)
▪ Implemented by-default Security tasks
inside project
▪ Risk Fixe: Upstream Contributions
13
▪ By-default Open Standard
▪ Support Communities (event, membership)
▪ Contribute upstream
▪ Hiring Top Talent
▪ Talk at Open Source Events
BUILD: Leverage Open Source
Open Source
Ecosystems
Manulife
Technical
Leader

More Related Content

PPTX
[Konveyor] address technical risks when implementing workload modernization u...
Konveyor
 
PDF
Hybrid and Multi-Cloud Strategies for Kubernetes with GitOps
Sonja Schweigert
 
PDF
How to get Away with K8S - Becoming Production
Amanda Quinto
 
PPTX
[Konveyor] migrate and modernize your application portfolio to kubernetes wit...
Konveyor Community
 
PDF
Continuous Security for GitOps
Weaveworks
 
PDF
Secure GitOps pipelines for Kubernetes with Snyk & Weaveworks
Weaveworks
 
PDF
GitOps (& Flux) for Helm Users with Scott Rigby
Weaveworks
 
PDF
E bpf and profilers
LibbySchulze
 
[Konveyor] address technical risks when implementing workload modernization u...
Konveyor
 
Hybrid and Multi-Cloud Strategies for Kubernetes with GitOps
Sonja Schweigert
 
How to get Away with K8S - Becoming Production
Amanda Quinto
 
[Konveyor] migrate and modernize your application portfolio to kubernetes wit...
Konveyor Community
 
Continuous Security for GitOps
Weaveworks
 
Secure GitOps pipelines for Kubernetes with Snyk & Weaveworks
Weaveworks
 
GitOps (& Flux) for Helm Users with Scott Rigby
Weaveworks
 
E bpf and profilers
LibbySchulze
 

Similar to DevOps & Insurance Company: Create A Bridge Between Security And Change (20)

PDF
Facilitating continuous delivery in a FinTech world with Salt, Jenkins, Nexus...
Chocolatey Software
 
PDF
Facilitating continuous delivery in a FinTech world with Salt, Jenkins, Nexus...
Michel Buczynski
 
PPTX
004 abhishek__Internship_ptt[1] (1).pptx
Afzankhan3
 
PDF
DevOps Engineer Training course online
praveena03290906
 
PDF
DevOps-Engineer-Training-Courses -Online
praveena03290906
 
PDF
DevOps -Engineer-Training-Online-Courses
praveena03290906
 
PDF
Devops -Engineer-Training-Courses-Online
praveena03290906
 
PDF
Introduction to DevOps
OCTO Technology
 
PPTX
InfrastructureDevOps.pptx it is most sui
pmishra37
 
ODP
DevOps @ OpenShift Online
OpenShift Origin
 
PDF
A model of Test Driven Infrastructure
Marc Saettel
 
PDF
SRE and GitOps for Building Robust Kubernetes Platforms.pdf
Weaveworks
 
PDF
Threat Modeling the CI/CD Pipeline to Improve Software Supply Chain Security ...
Denim Group
 
PDF
Promise of DevOps
Juraj Hantak
 
PDF
Coding Secure Infrastructure in the Cloud using the PIE framework
James Wickett
 
PPTX
Dev IS Ops
Jeff Sussna
 
PDF
Innovative DevOps Project Ideas for Students to Practice with Industry.pdf
rose
 
PDF
Cocktail of Environments. How to Mix Test and Development Environments and St...
Aleksandr Tarasov
 
PDF
Introduction To Development And Operations
teekhesawaal
 
PDF
Manufacturing Plus Open Source Equals DevOps
Gordon Haff
 
Facilitating continuous delivery in a FinTech world with Salt, Jenkins, Nexus...
Chocolatey Software
 
Facilitating continuous delivery in a FinTech world with Salt, Jenkins, Nexus...
Michel Buczynski
 
004 abhishek__Internship_ptt[1] (1).pptx
Afzankhan3
 
DevOps Engineer Training course online
praveena03290906
 
DevOps-Engineer-Training-Courses -Online
praveena03290906
 
DevOps -Engineer-Training-Online-Courses
praveena03290906
 
Devops -Engineer-Training-Courses-Online
praveena03290906
 
Introduction to DevOps
OCTO Technology
 
InfrastructureDevOps.pptx it is most sui
pmishra37
 
DevOps @ OpenShift Online
OpenShift Origin
 
A model of Test Driven Infrastructure
Marc Saettel
 
SRE and GitOps for Building Robust Kubernetes Platforms.pdf
Weaveworks
 
Threat Modeling the CI/CD Pipeline to Improve Software Supply Chain Security ...
Denim Group
 
Promise of DevOps
Juraj Hantak
 
Coding Secure Infrastructure in the Cloud using the PIE framework
James Wickett
 
Dev IS Ops
Jeff Sussna
 
Innovative DevOps Project Ideas for Students to Practice with Industry.pdf
rose
 
Cocktail of Environments. How to Mix Test and Development Environments and St...
Aleksandr Tarasov
 
Introduction To Development And Operations
teekhesawaal
 
Manufacturing Plus Open Source Equals DevOps
Gordon Haff
 
Ad

More from Jonathan Le Lous (17)

PDF
OpenStack Overview: Deployments and the Big Tent, Toronto 2016
Jonathan Le Lous
 
PDF
OpenStack in Canada , Toronto 2015
Jonathan Le Lous
 
PDF
DevOps: From IaaS to continuous integration
Jonathan Le Lous
 
PDF
Standards ouverts, interopérabilité et logiciel libre - Canada, 2015
Jonathan Le Lous
 
PDF
Why and how OpenStack must be Free Software ?
Jonathan Le Lous
 
PDF
OpenStack: stratégies et composants - Mars 2014 - Montréal - Québec - Canada
Jonathan Le Lous
 
PDF
L' Open data vu du Cloud computing
Jonathan Le Lous
 
PDF
OpenStack 2013.2 "Havana" - Cloud - Open Source - France
Jonathan Le Lous
 
PDF
Formation et logiciel libre / open source : bilan de l'étude Opiiec 2013
Jonathan Le Lous
 
PDF
Le rôle de la formation dans l’adoption d’une technologie numérique: le cas ...
Jonathan Le Lous
 
PDF
Presentation Communauté des Utilisateurs Français d'OpenStack
Jonathan Le Lous
 
ODP
OpenStack stratégie: fondation, acteurs et composants
Jonathan Le Lous
 
ODP
Logiciel libre: de la liberté à la stratégie
Jonathan Le Lous
 
PDF
Existe-t-il une agilité open source ?
Jonathan Le Lous
 
PDF
Floss Ecosystem - Strategy approach - PhD Work
Jonathan Le Lous
 
PDF
Communauté, utilisateurs, éditeur et intégrateurs : la logique gagnante du lo...
Jonathan Le Lous
 
PDF
Open Source Business Ecosystem - PhD work
Jonathan Le Lous
 
OpenStack Overview: Deployments and the Big Tent, Toronto 2016
Jonathan Le Lous
 
OpenStack in Canada , Toronto 2015
Jonathan Le Lous
 
DevOps: From IaaS to continuous integration
Jonathan Le Lous
 
Standards ouverts, interopérabilité et logiciel libre - Canada, 2015
Jonathan Le Lous
 
Why and how OpenStack must be Free Software ?
Jonathan Le Lous
 
OpenStack: stratégies et composants - Mars 2014 - Montréal - Québec - Canada
Jonathan Le Lous
 
L' Open data vu du Cloud computing
Jonathan Le Lous
 
OpenStack 2013.2 "Havana" - Cloud - Open Source - France
Jonathan Le Lous
 
Formation et logiciel libre / open source : bilan de l'étude Opiiec 2013
Jonathan Le Lous
 
Le rôle de la formation dans l’adoption d’une technologie numérique: le cas ...
Jonathan Le Lous
 
Presentation Communauté des Utilisateurs Français d'OpenStack
Jonathan Le Lous
 
OpenStack stratégie: fondation, acteurs et composants
Jonathan Le Lous
 
Logiciel libre: de la liberté à la stratégie
Jonathan Le Lous
 
Existe-t-il une agilité open source ?
Jonathan Le Lous
 
Floss Ecosystem - Strategy approach - PhD Work
Jonathan Le Lous
 
Communauté, utilisateurs, éditeur et intégrateurs : la logique gagnante du lo...
Jonathan Le Lous
 
Open Source Business Ecosystem - PhD work
Jonathan Le Lous
 
Ad

Recently uploaded (20)

PDF
Research-Fundamentals-and-Topic-Development.pdf
ayesha butalia
 
PDF
OFFOFFBOX™ – A New Era for African Film | Startup Presentation
ambaicciwalkerbrian
 
PDF
Get More from Fiori Automation - What’s New, What Works, and What’s Next.pdf
Precisely
 
PDF
Presentation about Hardware and Software in Computer
snehamodhawadiya
 
PPTX
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
PDF
NewMind AI Weekly Chronicles - July'25 - Week IV
NewMind AI
 
PPTX
The-Ethical-Hackers-Imperative-Safeguarding-the-Digital-Frontier.pptx
sujalchauhan1305
 
PPTX
OA presentation.pptx OA presentation.pptx
pateldhruv002338
 
PDF
A Strategic Analysis of the MVNO Wave in Emerging Markets.pdf
IPLOOK Networks
 
PDF
How Open Source Changed My Career by abdelrahman ismail
a0m0rajab1
 
PDF
Doc9.....................................
SofiaCollazos
 
PPTX
Introduction to Flutter by Ayush Desai.pptx
ayushdesai204
 
PDF
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
PDF
Responsible AI and AI Ethics - By Sylvester Ebhonu
Sylvester Ebhonu
 
PPTX
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
PDF
How ETL Control Logic Keeps Your Pipelines Safe and Reliable.pdf
Stryv Solutions Pvt. Ltd.
 
PDF
Orbitly Pitch Deck|A Mission-Driven Platform for Side Project Collaboration (...
zz41354899
 
PDF
GDG Cloud Munich - Intro - Luiz Carneiro - #BuildWithAI - July - Abdel.pdf
Luiz Carneiro
 
PPTX
The Future of AI & Machine Learning.pptx
pritsen4700
 
PPTX
New ThousandEyes Product Innovations: Cisco Live June 2025
ThousandEyes
 
Research-Fundamentals-and-Topic-Development.pdf
ayesha butalia
 
OFFOFFBOX™ – A New Era for African Film | Startup Presentation
ambaicciwalkerbrian
 
Get More from Fiori Automation - What’s New, What Works, and What’s Next.pdf
Precisely
 
Presentation about Hardware and Software in Computer
snehamodhawadiya
 
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
NewMind AI Weekly Chronicles - July'25 - Week IV
NewMind AI
 
The-Ethical-Hackers-Imperative-Safeguarding-the-Digital-Frontier.pptx
sujalchauhan1305
 
OA presentation.pptx OA presentation.pptx
pateldhruv002338
 
A Strategic Analysis of the MVNO Wave in Emerging Markets.pdf
IPLOOK Networks
 
How Open Source Changed My Career by abdelrahman ismail
a0m0rajab1
 
Doc9.....................................
SofiaCollazos
 
Introduction to Flutter by Ayush Desai.pptx
ayushdesai204
 
AI Unleashed - Shaping the Future -Starting Today - AIOUG Yatra 2025 - For Co...
Sandesh Rao
 
Responsible AI and AI Ethics - By Sylvester Ebhonu
Sylvester Ebhonu
 
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
How ETL Control Logic Keeps Your Pipelines Safe and Reliable.pdf
Stryv Solutions Pvt. Ltd.
 
Orbitly Pitch Deck|A Mission-Driven Platform for Side Project Collaboration (...
zz41354899
 
GDG Cloud Munich - Intro - Luiz Carneiro - #BuildWithAI - July - Abdel.pdf
Luiz Carneiro
 
The Future of AI & Machine Learning.pptx
pritsen4700
 
New ThousandEyes Product Innovations: Cisco Live June 2025
ThousandEyes
 

DevOps & Insurance Company: Create A Bridge Between Security And Change

  • 1. Jonathan Le Lous Director Engineering Engagement and Release Platforms Thibault Cohen Release Platforms Lead Global Technology 1 DevOps & Insurance Company: Create a Bridge between Security and Change
  • 3. Thibault -- @ttb_lt -- github.com/titilambert 3
  • 4. 4 Ratings A.M. Best A+ DBRS AA (low) Fitch AA- Moody’s A1 S&P AA- Serving 1 in 3 Canadians Founded in 1887 Canada’s largest insurance company 20+ countries Employee volunteer hours: 107,288 Community investment: $39.9M Investments in renewable energy and energy efficiency projects: $10.9B Manulife economic impact Assets managed and administered $1 trillion Statistics as of December 31, 2017 Manulife
  • 6. ‘Honouring our Past, Engaging our Future’ “transforming our business to be much more of a technology-driven company” Roy Gori, Manulife’s CEO. ▪ Legacy – Reducing the Run and Modernize Apps ▪ Net New – Leveraging Micro-services and APIs 6
  • 8. Platform Strategy: Kubernetes & PCF ‘‘While Cloud Foundry's PaaS can free up developers from infrastructure management worries, Kubernetes' container orchestration and cluster management functions can preserve control over the infrastructure for ops.’’ TechTarget (03/27/2017) 8 1. Legacy Apps 2. DevOps 1. Build Net New apps 2. Production Platform 1. Convergence strategy 2. Decision Framework
  • 9. DevOps = removing barriers = CI CD
  • 10. Example 1: The easy one ▪ All developer teams are using Scrum methodology ▪ All new projects are micro services running in PCF ▪ These projects are stored in GitLab using forking strategy ▪ The CI is based on Jenkins Pipelines ▪ Unit tests, SonarQube, BlackDuck, Fortify, ... ▪ The CD is based on Concourse ▪ 4 persistent PCF environments : DEV/TEST/QA/PROD 10
  • 11. Example 2: Back to the future ▪ Bring a 28 years old application to Gitlab/Jenkins ▪ Migrate more than 30000 commits from Harvest to Git ▪ Reproduce Harvest concepts with Gitlab/Jenkins ▪ Reduce developer learning curve ▪ Next steps: ▪ Move away from Harvest concepts to standard DevOps concepts ▪ Add more automated tests in Jenkins (SonarQube, BlackDuck, Fortify, ...) ▪ Add more tools in the pipeline (Doxygen, HyperSQL, ...) 11
  • 12. Automate Best Practices 12 ▪ Generic CI: Code Review, Security, Open Source Governance, QA.. ▪ Security: ▪ Automated Security Scans (Code) ▪ Implemented by-default Security tasks inside project ▪ Risk Fixe: Upstream Contributions
  • 13. 13 ▪ By-default Open Standard ▪ Support Communities (event, membership) ▪ Contribute upstream ▪ Hiring Top Talent ▪ Talk at Open Source Events BUILD: Leverage Open Source Open Source Ecosystems Manulife Technical Leader