Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Built to Leave - The Off Switch and The Exit

Built to Leave - The Off Switch and The Exit

In this presentation, I dive into what it takes to build systems that make it easy to leave when one or more switched get pulled.

This version of the talk was given at devopsdays Graz in September 2026.

Avatar for Kerim Satirli

Kerim Satirli PRO

September 05, 2026

More Decks by Kerim Satirli

Other Decks in Programming

Transcript

  1. Ten lessons from 2025 1 2 3 jurisdiction first, topology

    second standardize IAM across platforms define encryption domain and owner 6 7 8 provenance is border control train for crosscloud incidents vendors are (also) part of your system 4 evidence is a product, too 5 guidelines are not guardrails 9 egress is policy not a line-item 10 practice failover and deletion often
  2. Two lessons for 2027 1 2 3 jurisdiction first, topology

    second standardize IAM across platforms define encryption domain and owner 6 7 8 provenance is border control train for crosscloud incidents vendors are (also) part of your system 4 evidence is a product, too 5 guidelines are not guardrails 9 egress is policy not a line-item 10 practice failover and deletion often
  3. 24 hours early warning 72 hours initial notifications 14 days

    final report CRA Article 14 reporting obligations
  4. replaces NISG 2018 45k operators in scope (up from 1k)

    it is okay to panic (but do so calmly) NISG 2026 enters into force
  5. Layers 8 INTELLIGENCE (models, inference, agents) switch owner: __________________ 7

    OBSERVABILITY (metrics, logs, traces) switch owner: __________________ 6 DNS, TLS, and EDGE (routing, security, connectivity) switch owner: __________________ 5 SOURCE and FORGE VCS, CI/CD, packages) switch owner: __________________ 4 IDENTITY and SECRETS RBAC, crypto, policies) switch owner: __________________ 3 DATA (state, lineage, restores) switch owner: __________________ 2 COMPUTE and STORAGE (config, lifecycle, capacity) switch owner: __________________ 1 FACILITY and NETWORK (access, power, peering) switch owner: __________________
  6. Company scan Murtal Fördertechnik GmbH employees 1.500 runtime local +

    hyperscaler product conveyor belts delivery Forge + CI (all SaaS CRA in scope AI coding assistant SaaS NIS2 "important entity" identity Identity Provider SaaS
  7. · shared switch · their switch · our switch Mapped

    layers 8 INTELLIGENCE hosted model API 7 OBSERVABILITY SaaS APM 6 DNS, TLS, and EDGE DNS at registrar CDN and WAF SaaS 5 SOURCE and FORGE SaaS forge and CI public image registry 4 IDENTITY and SECRETS SaaS identity provider 3 DATA Postgres 2 COMPUTE and STORAGE Hyperscaler, EU region 1 FACILITY and NETWORK colocated, Styria coding-assistant pilot secrets in CI vault object storage ISP VMware estate model hub
  8. One switch, pulled Nov 2023 during 2024 acquisition closes perpetual

    licenses retired only subscriptions allowed
  9. One switch, pulled Nov 2023 during 2024 during 2026 acquisition

    closes perpetual licenses retired only subscriptions allowed cost increases ranging from 150% to 1000%
  10. Who left, who stayed ABLE TO LEAVE UNABLE TO LEAVE

    • replatformed, for 83% savings • Telco provider with no exit plan • moved 20k virtual machines • renewal price up 150  1000% • 70% of customers expected to leave • filed lawsuit in court over gouging "Able to Leave" is about engineering.
  11. 1 Everything from code. 2 Thin provider layers. inspect repository

    to map what services are provider-specific
  12. 1 Everything from code. 2 Thin provider layers. 3 Own

    your artifacts. mirror images, modules, packages, and module weights pin by digest, sign, scan for malware and other vulnerabilities
  13. 1 Everything from code. 2 Thin provider layers. 3 Own

    your artifacts. 4 Data with a way out. use open formats, test restores, protect lineage
  14. 1 Everything from code. 2 Thin provider layers. 3 Own

    your artifacts. 4 Data with a way out. 5 Identity, DNS, and TLS federate identity, make DNS portable, reissue TLS
  15. ________ hours to exit How many hours to leave, rebuild,

    and restore before you can cut over DNS and identity fully?
  16. "Exit" drill new cloud account and provider infrastructure and secrets

    restore data from backups cutover all DNS What broke? What took longer? Why? stop the clock
  17. One switch, mitigated 8 INTELLIGENCE hosted model API 7 OBSERVABILITY

    SaaS APM 6 DNS, TLS, and EDGE DNS at registrar CDN and WAF SaaS 5 SOURCE and FORGE SaaS forge and CI public image registry 4 IDENTITY and SECRETS SaaS identity provider 3 DATA Postgres 2 COMPUTE and STORAGE Hyperscaler, EU region 1 FACILITY and NETWORK colocated, Styria coding-assistant pilot secrets in CI vault object storage ISP VMware estate model hub
  18. One switch, mitigated CAN SWITCH OFF CANNOT SWITCH OFF •

    inference API • weights files on your disk(s) • hosted models • local model runners • pricing and terms • local coding assistants • open weights models • access for EU organizations
  19. yes What to keep local touches sensitive data local, always

    decide, then pin but document it no decide, then pin hosted is fine, no needs frontier-level capabilities yes
  20. Assessing cost PAY OUT PAY IN • no exit fee

    • additional engineering effort • negotiation leverage • mirroring and signing infras • audit evidence as by-product • cost of hardware GPU, memory)
  21. high Assessing risk MIRROR, ESCROW, CONTRACT BUILD TO LEAVE public

    registries identity provider ACCEPT AND DOCUMENT MIRROR, ESCROW, CONTRACT marketing website ERP systems low risk a switch is pulled firmware pipeline low blast radius if the switch is pulled high
  22. Right to Leave 11 Jan 2024 12 Sep 2025 12

    Jan 2027 Data Act in force switching rights apply switching charges prohibited The "Right to Leave" is now law. The "Ability to Leave" is still engineering.
  23. 300 hours to exit :) Bring your "exit" plan to

    your next contract renewal meeting.