Slide 1

Slide 1 text

LEARNING IN PRODUCTION or why the Apollo 11 landing nearly failed Michiel Rook @michieltcs

Slide 2

Slide 2 text

1969

Slide 3

Slide 3 text

No content

Slide 4

Slide 4 text

No content

Slide 5

Slide 5 text

No content

Slide 6

Slide 6 text

@michieltcs #StandWithUkraine IT ALMOST DIDN'T HAPPEN

Slide 7

Slide 7 text

No content

Slide 8

Slide 8 text

1970

Slide 9

Slide 9 text

No content

Slide 10

Slide 10 text

No content

Slide 11

Slide 11 text

No content

Slide 12

Slide 12 text

2020

Slide 13

Slide 13 text

No content

Slide 14

Slide 14 text

No content

Slide 15

Slide 15 text

No content

Slide 16

Slide 16 text

@michieltcs #StandWithUkraine

Slide 17

Slide 17 text

@michieltcs #StandWithUkraine "SpaceX provided audio recordings from the Crew Dragon’s fi rst orbital test fl ight to help prepare Hurley and Behnken for the ride during launch and re-entry."

Slide 18

Slide 18 text

@michieltcs #StandWithUkraine KEY TAKEAWAYS:

Slide 19

Slide 19 text

@michieltcs #StandWithUkraine TESTING

Slide 20

Slide 20 text

@michieltcs #StandWithUkraine EXPERIMENTATION

Slide 21

Slide 21 text

@michieltcs #StandWithUkraine SIMULATION

Slide 22

Slide 22 text

@michieltcs #StandWithUkraine ADAPTATION

Slide 23

Slide 23 text

@michieltcs #StandWithUkraine "BUT THAT IS ROCKET SCIENCE!"

Slide 24

Slide 24 text

@michieltcs #StandWithUkraine "THAT WOULDN'T WORK HERE"

Slide 25

Slide 25 text

@michieltcs #StandWithUkraine "WE DON'T HAVE THE BUDGET"

Slide 26

Slide 26 text

@michieltcs #StandWithUkraine "WE DON'T HAVE THE PEOPLE"

Slide 27

Slide 27 text

@michieltcs #StandWithUkraine "WE DON'T HAVE THE TIME"

Slide 28

Slide 28 text

@michieltcs #StandWithUkraine WHAT CAN WE LEARN FROM SPACE?

Slide 29

Slide 29 text

@michieltcs #StandWithUkraine WE ARE BUILDING

Slide 30

Slide 30 text

@michieltcs #StandWithUkraine WE ARE PART OF

Slide 31

Slide 31 text

@michieltcs #StandWithUkraine COMPLEX (DISTRIBUTED) SYSTEMS

Slide 32

Slide 32 text

@michieltcs #StandWithUkraine NOT LINEAR NOT NEWTONIAN NOT CARTESIAN

Slide 33

Slide 33 text

@michieltcs #StandWithUkraine CHANGES GENERALLY NOT REVERSIBLE

Slide 34

Slide 34 text

@michieltcs #StandWithUkraine MODEL DOES NOT MATCH REALITY

Slide 35

Slide 35 text

@michieltcs #StandWithUkraine SURPRISING FAILURE MODES

Slide 36

Slide 36 text

@michieltcs #StandWithUkraine "OKAY, BUT WE CAN BUILD SIMPLE THINGS"

Slide 37

Slide 37 text

@michieltcs #StandWithUkraine "WE SHOULD JUST PLAN BETTER"

Slide 38

Slide 38 text

@michieltcs #StandWithUkraine "WE SHOULD JUST BE MORE CAREFUL"

Slide 39

Slide 39 text

@michieltcs #StandWithUkraine "WE SHOULD JUST NOT MAKE MISTAKES"

Slide 40

Slide 40 text

@michieltcs #StandWithUkraine DAV I D WO O D S H T T P S : // YO U T U. B E /G N V X FG C - 5 J W

Slide 41

Slide 41 text

@michieltcs #StandWithUkraine "human failure is the biggest threat to security, therefore we periodically train our employees" (found on linkedin)

Slide 42

Slide 42 text

@michieltcs #StandWithUkraine "OKAY, BUT WHAT IF WE JUST TEST MORE"

Slide 43

Slide 43 text

@michieltcs @michieltcs #StandWithUkraine UNIT TESTS UI / E2E / VISUAL TESTS INTEGRATION / CONTRACT TESTS COST SPEED

Slide 44

Slide 44 text

@michieltcs #StandWithUkraine "Testing shows the presence, not absence, of bugs." E D S G E R W. D I J K S T RA

Slide 45

Slide 45 text

@michieltcs @michieltcs #StandWithUkraine

Slide 46

Slide 46 text

@michieltcs @michieltcs #StandWithUkraine

Slide 47

Slide 47 text

@michieltcs #StandWithUkraine "OKAY, BUT WHAT IF WE STOP CHANGE"

Slide 48

Slide 48 text

@michieltcs #StandWithUkraine "... incidents resulting from change is one of the most e ff ective metrics .... It isn’t a measure of system failures; it’s a measure of departmental failures"

Slide 49

Slide 49 text

@michieltcs #StandWithUkraine "... incidents resulting from change is one of the most e ff ective metrics .... It isn’t a measure of system failures; it’s a measure of departmental failures"

Slide 50

Slide 50 text

@michieltcs #StandWithUkraine "Every week of delay between having an idea and launching it to customers can mean millions of dollars lost in opportunity costs. IT matters." S T E V E S M I T H

Slide 51

Slide 51 text

@michieltcs #StandWithUkraine CHANGE IS INEVITABLE

Slide 52

Slide 52 text

@michieltcs #StandWithUkraine CHANGE IS NECESSARY

Slide 53

Slide 53 text

@michieltcs #StandWithUkraine "IF YOU’VE GOT TO BLAME SOMETHING, BLAME IMPERMANENCE."

Slide 54

Slide 54 text

@michieltcs @michieltcs #StandWithUkraine

Slide 55

Slide 55 text

@michieltcs #StandWithUkraine DEALING WITH THE UNKNOWN

Slide 56

Slide 56 text

@michieltcs #StandWithUkraine BUILD YOUR ADAPTIVE CAPACITY

Slide 57

Slide 57 text

@michieltcs @michieltcs #StandWithUkraine

Slide 58

Slide 58 text

@michieltcs @michieltcs #StandWithUkraine

Slide 59

Slide 59 text

@michieltcs #StandWithUkraine "We don’t rise to the level of our expectations, we fall to the level of our training." A R C H I LO C H U S , G R E E K S O L D I E R , P O E T, C . 6 5 0 B C

Slide 60

Slide 60 text

@michieltcs #StandWithUkraine WHAT DO YOU NEED?

Slide 61

Slide 61 text

@michieltcs #StandWithUkraine TO BUILD AN ADAPTIVE ORGANISATION?

Slide 62

Slide 62 text

@michieltcs #StandWithUkraine ‣ An adaptive architecture ‣ Incremental deployments ‣ Automated provisioning ‣ Ubiquitous telemetry ‣ Chaos Engineering ‣ You Build It You Run It ‣ Post-incident reviews H T T P S : // W W W. S T E V ES M I T H .T EC H / B LO G / B U I L D - O P E RA B I L I T Y- I N /

Slide 63

Slide 63 text

@michieltcs #StandWithUkraine ‣ An adaptive architecture ‣ Incremental deployments ‣ Automated provisioning ‣ Ubiquitous telemetry ‣ Chaos Engineering ‣ You Build It You Run It ‣ Post-incident reviews auto scaling, circuit breakers, health checks H T T P S : // W W W. S T E V ES M I T H .T EC H / B LO G / B U I L D - O P E RA B I L I T Y- I N /

Slide 64

Slide 64 text

@michieltcs #StandWithUkraine ‣ An adaptive architecture ‣ Incremental deployments ‣ Automated provisioning ‣ Ubiquitous telemetry ‣ Chaos Engineering ‣ You Build It You Run It ‣ Post-incident reviews small & frequent deploys, blue/green, canary, rolling, rollbacks H T T P S : // W W W. S T E V ES M I T H .T EC H / B LO G / B U I L D - O P E RA B I L I T Y- I N /

Slide 65

Slide 65 text

@michieltcs #StandWithUkraine ‣ An adaptive architecture ‣ Incremental deployments ‣ Automated provisioning ‣ Ubiquitous telemetry ‣ Chaos Engineering ‣ You Build It You Run It ‣ Post-incident reviews terraform, ansible, packer, etc. H T T P S : // W W W. S T E V ES M I T H .T EC H / B LO G / B U I L D - O P E RA B I L I T Y- I N /

Slide 66

Slide 66 text

@michieltcs #StandWithUkraine ‣ An adaptive architecture ‣ Incremental deployments ‣ Automated provisioning ‣ Ubiquitous telemetry ‣ Chaos Engineering ‣ You Build It You Run It ‣ Post-incident reviews observability and operability H T T P S : // W W W. S T E V ES M I T H .T EC H / B LO G / B U I L D - O P E RA B I L I T Y- I N /

Slide 67

Slide 67 text

@michieltcs #StandWithUkraine ‣ An adaptive architecture ‣ Incremental deployments ‣ Automated provisioning ‣ Ubiquitous telemetry ‣ Chaos Engineering ‣ You Build It You Run It ‣ Post-incident reviews controlled experiments on systems H T T P S : // W W W. S T E V ES M I T H .T EC H / B LO G / B U I L D - O P E RA B I L I T Y- I N /

Slide 68

Slide 68 text

@michieltcs #StandWithUkraine ‣ An adaptive architecture ‣ Incremental deployments ‣ Automated provisioning ‣ Ubiquitous telemetry ‣ Chaos Engineering ‣ You Build It You Run It ‣ Post-incident reviews you OWN it you run it H T T P S : // W W W. S T E V ES M I T H .T EC H / B LO G / B U I L D - O P E RA B I L I T Y- I N /

Slide 69

Slide 69 text

@michieltcs #StandWithUkraine ‣ An adaptive architecture ‣ Incremental deployments ‣ Automated provisioning ‣ Ubiquitous telemetry ‣ Chaos Engineering ‣ You Build It You Run It ‣ Post-incident reviews H T T P S : // W W W. S T E V ES M I T H .T EC H / B LO G / B U I L D - O P E RA B I L I T Y- I N / blameless postmortems, knowledge sharing, learning

Slide 70

Slide 70 text

@michieltcs #StandWithUkraine ‣ An adaptive architecture ‣ Incremental deployments ‣ Automated provisioning ‣ Ubiquitous telemetry ‣ Chaos Engineering ‣ You Build It You Run It ‣ Post-incident reviews H T T P S : // W W W. S T E V ES M I T H .T EC H / B LO G / B U I L D - O P E RA B I L I T Y- I N /

Slide 71

Slide 71 text

@michieltcs #StandWithUkraine INTEGRATE EARLY

Slide 72

Slide 72 text

@michieltcs #StandWithUkraine INTEGRATE OFTEN

Slide 73

Slide 73 text

@michieltcs #StandWithUkraine MAKE THINGS SMALL

Slide 74

Slide 74 text

@michieltcs #StandWithUkraine BIG STEPS

Slide 75

Slide 75 text

@michieltcs #StandWithUkraine FAIL BIG

Slide 76

Slide 76 text

@michieltcs #StandWithUkraine SMALL STEPS

Slide 77

Slide 77 text

@michieltcs #StandWithUkraine FAIL SMALL

Slide 78

Slide 78 text

@michieltcs #StandWithUkraine $ = REALIZED VALUE C R E D I T S TO @ FG O U L D I N G

Slide 79

Slide 79 text

21 Accelerate: State of DevOps 2019 | How Do We Compare? ELITE PERFORMERS Comparing the elite group against the low performers, we find that elite performers have… frequent code deployments 208 TIMES MORE time to recover from incidents 2,604 TIMES FASTER lead time from commit to deploy 106 TIMES FASTER change failure rate (changes are 1/7 as likely to fail) 7 TIMES LOWER Throughput Stability Source: 2019 State Of DevOps report

Slide 80

Slide 80 text

@michieltcs #StandWithUkraine OBSERVABILITY AND OPERABILITY

Slide 81

Slide 81 text

@michieltcs @michieltcs #StandWithUkraine

Slide 82

Slide 82 text

@michieltcs #StandWithUkraine "a measure of how well internal states of a system can be inferred from knowledge of its external outputs." H T T P S : // E N .W I K I P E D I A .O R G / W I K I / O B S E RVA B I L I T Y

Slide 83

Slide 83 text

@michieltcs @michieltcs #StandWithUkraine source: laredoute.io

Slide 84

Slide 84 text

@michieltcs #StandWithUkraine "the properties of a system which make it work well in production " H T T P S : //C O N F LU X D I G I TA L . N E T/ W H AT- I S - O P E RA B I L I T Y

Slide 85

Slide 85 text

@michieltcs #StandWithUkraine "the properties of a system which make it work well in production " H T T P S : //C O N F LU X D I G I TA L . N E T/ W H AT- I S - O P E RA B I L I T Y the operator experience

Slide 86

Slide 86 text

@michieltcs #StandWithUkraine EASY TO DEPLOY

Slide 87

Slide 87 text

@michieltcs #StandWithUkraine EASY TO TEST

Slide 88

Slide 88 text

@michieltcs #StandWithUkraine EASY TO INSPECT

Slide 89

Slide 89 text

@michieltcs #StandWithUkraine FEEDBACK LOOPS

Slide 90

Slide 90 text

@michieltcs @michieltcs #StandWithUkraine

Slide 91

Slide 91 text

@michieltcs #StandWithUkraine

Slide 92

Slide 92 text

@michieltcs #StandWithUkraine CHAOS ENGINEERING

Slide 93

Slide 93 text

@michieltcs #StandWithUkraine "the facilitation of experiments to uncover systemic weaknesses"

Slide 94

Slide 94 text

@michieltcs #StandWithUkraine "the discipline of experimenting on a distributed system in order to build con fi dence in the system’s capability to withstand turbulent conditions in production*"

Slide 95

Slide 95 text

@michieltcs @michieltcs #StandWithUkraine

Slide 96

Slide 96 text

@michieltcs @michieltcs #StandWithUkraine

Slide 97

Slide 97 text

@michieltcs #StandWithUkraine NOT (JUST) ABOUT BREAKING THINGS

Slide 98

Slide 98 text

@michieltcs #StandWithUkraine NOT (JUST) ABOUT BREAKING PROD

Slide 99

Slide 99 text

@michieltcs #StandWithUkraine START SMALL

Slide 100

Slide 100 text

@michieltcs #StandWithUkraine TEST ACC PROD

Slide 101

Slide 101 text

@michieltcs #StandWithUkraine H T T P S : // W W W.YO U T U B E .C O M / WATC H ? V = N O O G K N BW0 G K

Slide 102

Slide 102 text

@michieltcs #StandWithUkraine INCIDENT ANALYSIS

Slide 103

Slide 103 text

@michieltcs #StandWithUkraine "Here's the secret: Incident analysis is not actually about the incident." N O RA J O N ES

Slide 104

Slide 104 text

EVERY INCIDENT IS AN ICEBERG https:/ /www.hdwallpapers.net/nature/the-invisible-part-of-the-iceberg-wallpaper-746.htm

Slide 105

Slide 105 text

@michieltcs #StandWithUkraine ROOT CAUSE ANALYSIS?

Slide 106

Slide 106 text

@michieltcs #StandWithUkraine ROOT CAUSE ANALYSIS?

Slide 107

Slide 107 text

@michieltcs #StandWithUkraine "What you call 'root cause' is simply the place where you stop looking any further." S I D N E Y D E K K E R

Slide 108

Slide 108 text

@michieltcs #StandWithUkraine “What is the cause of the accident? This question is just as bizarre as asking what the cause is of not having an accident.” S I D N E Y D E K K E R

Slide 109

Slide 109 text

@michieltcs #StandWithUkraine “... the more I realized that this accident occurred not because something extraordinary had happened, but rather just the opposite” S C OT T A . S N O O K

Slide 110

Slide 110 text

@michieltcs #StandWithUkraine WHAT THEN?

Slide 111

Slide 111 text

@michieltcs #StandWithUkraine “"Regardless of what we discover, we understand and truly believe that everyone did the best job they could, given what they knew at the time, their skills and abilities, the resources available, and the situation at hand."” H T T P S : // R E T R O S P EC T I V E W I K I .O R G / I N D E X . P H P ? T I T L E = T H E _ P R I M E _ D I R EC T I V E

Slide 112

Slide 112 text

@michieltcs #StandWithUkraine BLAMELESS POSTMORTEMS

Slide 113

Slide 113 text

@michieltcs #StandWithUkraine BLAME AWARE POSTMORTEMS

Slide 114

Slide 114 text

@michieltcs #StandWithUkraine WHAT INFORMATION WAS AVAILABLE?

Slide 115

Slide 115 text

@michieltcs #StandWithUkraine WHAT INFORMATION MADE SENSE?

Slide 116

Slide 116 text

@michieltcs #StandWithUkraine WHAT FACTORS CONTRIBUTED TO THE EVENT?

Slide 117

Slide 117 text

@michieltcs #StandWithUkraine HOW DID THIS DIFFER FROM "NORMAL" OPS?

Slide 118

Slide 118 text

@michieltcs #StandWithUkraine WEAK VS STRONG SIGNALS

Slide 119

Slide 119 text

@michieltcs #StandWithUkraine HOW DID PEOPLE ADAPT?

Slide 120

Slide 120 text

@michieltcs #StandWithUkraine JUST CULTURE

Slide 121

Slide 121 text

@michieltcs #StandWithUkraine DO YOU ENCOURAGE SHARING AND LEARNING?

Slide 122

Slide 122 text

@michieltcs #StandWithUkraine PROTECT PEOPLE THAT SHARE BAD NEWS?

Slide 123

Slide 123 text

@michieltcs #StandWithUkraine CELEBRATE PEOPLE THAT SHARE BAD NEWS?

Slide 124

Slide 124 text

No content

Slide 125

Slide 125 text

@michieltcs #StandWithUkraine IN SUMMARY

Slide 126

Slide 126 text

@michieltcs #StandWithUkraine YOU CAN'T TEST EVERYTHING

Slide 127

Slide 127 text

@michieltcs #StandWithUkraine YOU CAN'T PREPARE FOR EVERYTHING

Slide 128

Slide 128 text

@michieltcs #StandWithUkraine YOU CAN LEARN

Slide 129

Slide 129 text

@michieltcs #StandWithUkraine TO BE PREPARED

Slide 130

Slide 130 text

@michieltcs #StandWithUkraine TO DEAL WITH ANYTHING

Slide 131

Slide 131 text

@michieltcs @michieltcs #StandWithUkraine THANK YOU FOR LISTENING! @michieltcs / @michielrook.bsky.social email: michiel@michielrook.nl www.michielrook.nl

Slide 132

Slide 132 text

@michieltcs @michieltcs #StandWithUkraine https://www.michielrook.nl/2024/08/literature-tips/