Cloud Vegetables

Steve MacIntyre
CloudX at Fidelity
Published in
4 min readAug 19, 2020

We all remember our parents telling us, “Eat your vegetables! They are good for you.” We started off trying to ignore them, but over time we aged and began to realize the true value. While some we like more than others, we have come to appreciate them all in our daily diet. As Fidelity Investments continues our journey to the cloud, “Cloud vegetables” will help us all be healthier if they become part of our daily diet. So, what are “Cloud Vegetables?” Let’s dig in!

Security Vegetables

The basic vegetables like Potatoes, Carrots, and Peas. They are just there! We need them, can’t avoid them, so we embrace and learn to love them. As Dev teams go to cloud each member becomes a security professional and needs to love their veggies. Every team member should know there are core ingredients “Security Rules of Cloud”, and a great many recipes can be found for how to properly prepare and add security vegetables to your cloud meal (app).

Oh, and no trying to slip the veggies to the dog! (Tried that and got busted when I was young). Application teams still have many traditional security requirements which do not go away when moving to the cloud. Things like Product Management, Authorization Monitoring and Reporting, Records Retention, eCommunications, and many other policies and standards remain as core dietary ingredients for a great cloud meal!

Fast forward and dev teams have created many meals (apps). Some are healthier than others, but all this good eating has done the inevitable and caused us to gain weight (deploy unnecessary resources), feel bloated (spend too much money) or just recognize we need to get healthier and trimmer (clean up our cloud accounts).

Cost Vegetables

Good news! There are vegetables that can help! Spinach, mushrooms, and broccoli help us lose weight and the cloud version of these is Automation. Fidelity uses a 3rd party platform managed by the Security team which is a key to security monitoring and alerting, but also provides a flexible engine which allows us to get thin and reduce our cloud footprint which reduces risk (makes us healthier) and save money (makes us thinner and trimmer).

Over the past quarter the tool was used to remove stale resources in a pilot set of cloud accounts. Removing the bloat (old snapshots for EBS and RDS, unused EBS storage volumes) realized a savings of over $6,000 monthly within just those few accounts.

We got thinner and trimmer quickly. Two of Fidelity’s larger business units (each has their own IT divisions) saw this dietary value and jumped on board quickly to leverage the tool in their environments. They have just started their diet and we can’t wait to see how it goes! Stay tuned for their weigh in down the road!

Good news travels fast, and more subscribers to our dietary plan have lined up to take advantage of this automation.

“Cloud Vegetables” are only part of the meal (app). So where are the recipes? Everyone wants to create delicious, consistent, and well-liked meals, so how do app teams accomplish this goal?

Fitness Vegetables

Sweet Potatoes, Peppers and Beets are good veggies to promote fitness. To help our applications be fit in the cloud there are several things which can help. First is the use of a central content portal we call the “Highway” as the official cookbook. There is an abundance of recipes (reference applications) to help guide a team through their journey and ensure they follow the right path to cloud success!

Following a recipe can be confusing! Using an approved pipeline such as Concourse pipelines to deploy your application, tag your resources, and pass through our automated Cloud Governance Gates will ensure a safe and successful deployment in production!

Adopting an automation first mindset is critical in the cloud and Fidelity’s Enterprise Cloud Computing team provides a cloud friendly way to monitor and ensure your app is cooking as planned using an industry leading cloud monitoring tool. The recipes to success with this tool are also on the Fidelity Cloud Portal called “Highway”!

What a meal!

When put all together “Cloud Vegetables” create a solid base for the many cloud recipes sure to come. They ensure that while there will be many cooks, the final meal (app) delivered is solid, safe and resilient.

OK..hungry now…gotta go eat!

Oh and we are hiring: https://jobs.fidelity.com #fidelityassociate

--

--

Steve MacIntyre
CloudX at Fidelity

VP of Shared Security Services with Enterprise Cloud Computing at Fidelity Investments. Focused on enabling safe adoption of cloud capabilities for the firm.