Odyssey Platform # 08

Another exciting week in the Platform Engineering ecosystem!

Editor's Note
Welcome to another edition of Odyssey Platform Weekly! This week, weโ€™re diving into fresh insights, key events, and powerful stories shaping the future of platform engineering.

๐Ÿ—ž๏ธ In this newsletter

๐Ÿ—“๏ธ Events

๐Ÿ”ฆ Tool Spotlight

  • Argo Workflows is a Kubernetes-native, container-first workflow engine, enabling teams to orchestrate complex, multi-step pipelines on any Kubernetes clusterโ€”no additional components required.

๐Ÿ”๏ธ Deep Dive

  • Discover how Atlassian's Remote Model Context Protocol (MCP) Server seamlessly connects AI assistants, enterprise data, and secure workflows enabling your teams to query, create, and analyze Jira tickets and Confluence pages through natural language without ever leaving their AI tools. Learn how Atlassian's innovative trinity of Protocol, Security, and Intelligence unlocks zero-friction knowledge management for modern teams.

๐ŸŽฏ Stay Inspired - Case Studies

๐Ÿ‘€ In Case you missed it

  • Latest news & events in the platform engineering domain

๐Ÿ“† Upcoming Events

๐Ÿง  INCIDENT FEST โ€™25

๐Ÿ“… Jul 16, 2025 โ€“ Virtual
Learn how to optimize your cloud spend and maximize the value of your cloud investments with best practices from the FinOps Foundation, United, and more. ๐Ÿ”ฅ
๐Ÿ‘‰ Register here

๐Ÿ”ฆ Tool Spotlight

  • โœ… Scalable orchestration โ€” manage hundreds of parallel tasks using DAG or step-based workflows via Kubernetes CRDs.

  • โœ… Rich artifact and parameter support โ€” handle inputs/outputs through S3, Git, Azure, GCS; use loops, retries, conditionals, and timeouts for robust control

  • โœ… Built-in UI & CLI โ€” visualize workflow execution, debug, and manage via a web UI or CLI .

  • โœ… ML/Data pipelines & CI/CD โ€” ideal for model training, data batch tasks, and Kubernetes-native CI/CD workflows.

Why It Matters:
Argo Workflows brings self-service orchestration to any Kubernetes team, reducing reliance on external batch systemsโ€”making everything from ML pipelines to CI/CD fully declarative and version-controlled.

๐Ÿš€ Deep Dive: Vanta's Cloud-First Compliance Automation

Vanta Architecture

Turn your entire infrastructure into a compliance-ready platform with zero manual overhead

Forget compliance spreadsheets. Vanta just automated the entire security posture of your cloud infrastructure, vendor relationships, and certification pipeline.

The transformation in numbers:

  • 375+ cloud integrations monitor every resource automatically

  • 90% vendor questionnaire automation with AI-powered responses

  • Real-time compliance tracking across AWS, Azure, GCP simultaneously

  • 4-6 week SOC 2 certification vs traditional 6+ months

Cloud Integration Magic That Actually Works

Connect once, monitor everything:

# AWS Integration
โœ… 40+ AWS services auto-monitored
โœ… IAM policies, S3 buckets, RDS encryption
โœ… CloudTrail logs, VPC configurations
โœ… EC2 instances, Lambda functions

# Azure Integration  
โœ… 30+ Azure services tracked real-time
โœ… Key Vault secrets, Storage accounts
โœ… Active Directory, Network Security Groups
โœ… App Services, Container instances

# GCP Integration
โœ… 25+ GCP resources continuously scanned
โœ… Cloud IAM, Cloud Storage encryption
โœ… Compute Engine, Kubernetes clusters
โœ… Cloud SQL, Secret Manager

The beautiful part: Vanta maps every cloud resource to specific compliance controls automatically. Your S3 bucket encryption? Maps to SOC 2 CC6.1. Your IAM policies? Covers multiple ISO 27001 controls.

No manual documentation. No resource tracking spreadsheets. Just plug in your cloud provider and watch compliance happen in real-time.

Vendor Management Revolution

Traditional vendor security reviews = weeks of back-and-forth emails
Vanta vendor management = automated compliance intelligence

Add Any Vendor in 30 Seconds

1. Add vendor contact info
2. Vanta auto-generates security questionnaire
3. AI tracks responses and compliance status
4. Real-time dashboard shows vendor risk scores

What Vanta Handles Automatically:

๐Ÿ” Compliance Verification: Automatically checks if vendors have SOC 2, ISO 27001, PCI DSS
๐Ÿ“Š Risk Scoring: AI analyzes responses and assigns risk ratings
โฐ Certificate Tracking: Monitors expiration dates and renewal status
๐Ÿ“‹ Gap Analysis: Identifies missing certifications and security controls
๐Ÿšจ Alert System: Notifies when vendor compliance status changes

Real Vendor Intelligence Examples:

โœ… Stripe: SOC 2 Type II โœ“, PCI DSS โœ“ (Low Risk)
โš ๏ธ NewVendor: SOC 2 pending, ISO 27001 โœ— (Medium Risk)  
๐Ÿšจ OldTool: SOC 2 expired 30 days ago (High Risk)

The Continuous Compliance Dashboard

Your entire security posture in one view:

Cloud Resources Live Status

AWS Production: 347 resources โœ… 98% compliant
Azure Staging: 156 resources โš ๏ธ 2 findings  
GCP Dev: 89 resources โœ… 100% compliant

Vendor Ecosystem Health

94 Active Vendors:
โ”œโ”€โ”€ 67 SOC 2 Certified โœ…
โ”œโ”€โ”€ 23 In Review Process โณ  
โ”œโ”€โ”€ 4 Missing Certifications ๐Ÿšจ
โ””โ”€โ”€ Auto-questionnaires sent: 15

Framework Coverage

SOC 2 Type II: 156/158 controls โœ… 98%
ISO 27001: 143/147 controls โœ… 97%  
GDPR: 89/91 controls โœ… 97%

Infrastructure-as-Code Integration

Vanta understands your modern stack:

๐Ÿ”„ Kubernetes CIS Benchmarks: Automated cluster security validation
๐Ÿ›ก๏ธ Container Scanning: ECR, GCR, Azure Container Registry integration
โšก Infrastructure Monitoring: Terraform state changes tracked for compliance
๐Ÿ” Vulnerability Management: Real-time scanning across all environments

Example: Kubernetes Security Automation

# Vanta automatically validates:
# โœ… Pod Security Standards
# โœ… Network Policies  
# โœ… RBAC configurations
# โœ… Secret management
# โœ… Resource limits

Vendor Questionnaire AI That Actually Works

The questionnaire automation is genuinely impressive:

Before Vanta:

  • Manual vendor discovery and outreach

  • Custom questionnaires for each vendor

  • Weeks of follow-up emails

  • Manual risk assessment and scoring

  • Spreadsheet tracking (the horror!)

With Vanta AI:

  • Smart Questionnaires: Context-aware questions based on vendor type

  • AI Response Analysis: Understands technical answers and flags risks

  • Compliance Mapping: Links vendor responses to your framework requirements

  • Auto-Renewal: Tracks certification expiry and triggers renewals

  • Risk Intelligence: Correlates vendor security with industry benchmarks

Real Example Flow:

1. Add "CloudFlare" as CDN vendor
2. Vanta auto-sends CDN-specific security questionnaire  
3. AI analyzes responses: "Strong DDoS protection โœ…, SOC 2 Type II โœ…"
4. Risk Score: Low (2/10) - Approved for production use
5. Auto-reminder set for SOC 2 renewal in 11 months

Vanta MCP: AI-Powered Compliance Intelligence

The game-changer nobody's talking about yet:

Vanta's Model Context Protocol (MCP) integration lets you talk to your entire compliance infrastructure through AI. Think ChatGPT for your security posture.

What You Can Do With Natural Language:

You: "Show me all critical compliance findings from last week"
AI: Returns AWS misconfigured S3 buckets, expired vendor certs, failed K8s benchmarks

You: "Which vendors need SOC 2 renewal in the next 90 days?"  
AI: Lists 5 vendors with cert expiry dates and contact details

You: "Generate compliance report for Q4 board meeting"
AI: Creates executive summary with risk metrics and remediation status

You: "What's blocking our ISO 27001 certification?"
AI: Identifies 4 missing controls with specific remediation steps

Real Business Value Examples:

Before MCP: Compliance manager spends 3 hours preparing weekly security reports
With MCP: "Generate this week's security summary" โ†’ Done in 30 seconds

Before MCP: Platform team manually correlates cloud findings across environments
With MCP: "Show me all high-risk findings across prod and staging" โ†’ Instant analysis

Before MCP: Legal team requests vendor security status for contract renewals
With MCP: "Which vendors in this list are SOC 2 compliant?" โ†’ Immediate answers

The AI Assistant That Actually Understands Security:

๐Ÿง  Context-Aware: Knows your specific frameworks, vendors, and cloud setup
โšก Real-Time Data: Pulls live compliance status, not stale reports
๐Ÿ“Š Executive Intelligence: Translates technical findings into business impact
๐Ÿ” Proactive Insights: Identifies compliance risks before they become problems

Example Conversation:

You: "Are we ready for our SOC 2 audit next month?"

AI: "Current readiness: 94% (147/156 controls passing)
    
    Remaining issues:
    โœ… AWS: 2 S3 buckets need encryption (fix ETA: 2 days)
    โš ๏ธ  Vendors: Slack SOC 2 expires in 15 days (renewal in progress)
    ๐Ÿšจ Access Review: 3 users need quarterly review (urgent)
    
    Recommendation: Address access review this week, 
    monitor Slack renewal, AWS fixes can wait until after audit."

The Platform Engineering Win

Why this matters for your infrastructure:

๐ŸŽฏ Zero Compliance Debt: Every new cloud resource automatically inherits compliance monitoring
โšก Deployment Velocity: No "compliance review" bottlenecks in your CI/CD
๐Ÿ›ก๏ธ Vendor Trust: Know exactly which third-parties meet your security standards
๐Ÿ“Š Audit Readiness: Real-time evidence collection across your entire stack
๐Ÿค– AI-Powered Intelligence: Talk to your compliance data like a human conversation

Time savings with MCP integration:

  • Weekly security reports: 3 hours โ†’ 30 seconds

  • Vendor compliance checks: 45 minutes โ†’ 2 minutes

  • Audit prep coordination: 2 weeks โ†’ 3 days

  • Executive compliance briefings: 1 hour โ†’ 5 minutes

The bottom line: Vanta + MCP transforms compliance from a manual, reactive process into conversational infrastructure intelligence that scales with your platform complexity.

Your cloud resources stay compliant by default. Your vendors prove their security automatically. Your audits become a formality instead of a nightmare. And now you can ask questions and get answers instantly, like having a compliance expert available 24/7.

That's not just compliance automation โ€“ that's compliance infrastructure with AI superpowers.

๐ŸŽฏ Stay Inspired - Case Studies

๐Ÿ”น Platform Engineering & CI/CD Modernization๐Ÿš€

Who: Bell Canada โ€” a leader in telecommunications and media across Canada

What They Did:
Partnered with Improving to revamp their platform engineering and infrastructure. The project focused on:

  • Modernizing CI/CD pipelines

  • Implementing zeroโ€‘downtime deployments

  • Enhancing observability and logging

  • Preserving data integrity during releases

Tech Stack & Tools Used:
Kubernetes, OpenShift, GitLab CI/CD, Prometheus for monitoring, containerization, and Infrastructure as Code (IaC)

Why It Matters

โœ… Selfโ€‘service and speed: Platform improvements empower teams to deploy safely and independently.
โœ… Operational resilience: Zero-downtime standards and observability reduce risk during releases.
โœ… Futureโ€‘proof foundation: Modular, IaC-based infrastructure sets the stage for scale and agility.

๐Ÿ‘€ In Case You Missed Itโ€ฆ

Microsoft releases Azure DevOps MCP Server in public preview
Enables GitHub Copilot to access Azure DevOps project data (work items, PRs, test plans, builds) via language promptsโ€”all locally hosted for data privacy .

GitLab 18 launches โ€œGitLab Duoโ€
Highlights include built-in AI features for code suggestions, test generation, plus modular CI/CD and compliance tools like SAST and vulnerability dashboards.

Developer Nation report: AIโ€™s nuanced impact on DORA metrics
AI tools like Copilot slightly boost deployment frequency for top teams, but may not improve lead timesโ€”and could increase change failure rates.

Till next time,