Yes, Policies Can Actually Speed Development

Yes, Policies Can Actually Speed Development

October 31, 2013
By Derek Weeks

5 minute read time

These concepts run counter to fast, agile, based-development. These words make developers cringe, they are "4 letter words." Could it be that the problems with these concepts are not what they are trying to accomplish, but how they are implemented? They are intended to ensure that applications developers create are trusted, that they meet and exceed the expectations of the user, that they drive the business forward without placing the business at risk. Who can argue with that? Sure, developers want to build things fast, but they want to deliver applications with high quality. So, the intent is good, but the implementation is bad.

Before we discuss the problem with policies, let's look at some data. Our survey of 3,500 developers, architects and development managers shows that organizations are exposed.

So what is the problem with policies?

How applications are constructed today exacerbates these implementation problems:

One Potential Approach - Automated Workflow

Ok, so now that you understand the problem, what can you do about it? One potential approach that some organizations and vendors have taken is to take the manual processes and apply workflow. This approach is borne out of the BPM world, with the old thought that if we use automated workflow, the approval process will be streamlined and developers won't be bogged down with manual work. Sounds good?

Well, hold on a minute, because this approach has the following limitations:

So the approach sounds reasonable, even if you cut the approval process in half, you still can't keep up with the volume, variety, complexity and release cadence of components. You still can't provide the up-front flexibility that your developers need to try out new components. You still don't have the ability to guide and enforce action throughout the lifecycle. You still don't have policies that will help manage your production environment.

What's the side effect of policy approaches that don't work? Well, they either slow development, or developers ignore the policies, or developers settle for sub-optimal components because they are on the approved list. Each of these outcomes is a problem. If development is slowed, the business doesn't get what it needs, and finger pointing ensues. If developers bypass the policies, organizations are put at risk because components are not properly vetted. And if developers follow the policy and use outdated components previously approved, they are constructing applications with sub-optimal components. There has to be a better way.

The Better Approach: Automated Policies

Luckily there is a better way, and it's actually not as difficult as it may sound. You can leverage the work that you are already doing with your repository manager and extend governance with automated policies. That's right, instead of automating the workflow, you leverage automated policies that keep up with today's agile, component-based development efforts.

This approach provides the following benefits:

Our Component Lifecycle Management approach leverages automated policies so that you can keep up with the volume of components while providing guidance and flexibility your developers need. And the end result will be that applications that you assemble are trusted and remain trusted over time.

We also realize that there isn't a single correct way to expand your governance approach. Sonatype has designed the CLM so that you can support your most critical needs, and you can expand usage over time. It could be that you want to start by assessing the risk of applications in production. It could be that you want to start by using policies that will manage your release process. Or it could be that you want to use policies to provide guidance to your developers early in the development process. Sonatype supports each of these approaches and more. For more information check out the CLM product.

Written by Derek Weeks
Derek serves as vice president and DevOps advocate at Sonatype and is the co-founder of All Day DevOps, an online community of 65,000 IT professionals.