---
title: Automate Everything! (Except Platform Upgrades)
description: When platform upgrades go bad, software development pros don't sweat. Here's 3 easy tips so you feel the same.
image: https://resources.workstate.com/hubfs/blog-images/iam/Automate_Everything_IAM.jpeg
---

[![Workstate](https://resources.workstate.com/hubfs/Workstate-Nov2016/Image/Logo.png "Workstate")](http://workstate.com/)

- Practices 
    - [Technology Team Rental](http://workstate.com/teamrental)
    - [Big Data](http://workstate.com/bigdata)
    - [Cloud Shift](http://workstate.com/cloud-shift)
    - [QA and Testing](http://workstate.com/qa)
    - [Identity and Access Management](http://workstate.com/iam)
    - [Application Security](http://workstate.com/appsecurity)
- [Blog](http://web.workstate.com/blog)
- [Careers](https://workstate.workable.com/)

# Workstate Insights Blog

# Automate Everything! (Except Platform Upgrades)

 May 24, 2017

by [Christian Duvall, Group Vice President, Enterprise Services](https://resources.workstate.com/blog/author/christian-duvall-group-vice-president-enterprise-services)

[![Share on Facebook](https://static.hubspot.com/final/img/common/icons/social/facebook-24x24.png)](http://www.facebook.com/share.php?u=https%3A%2F%2Fresources.workstate.com%2Fblog%2Fautomate-everything-except-platform-upgrades%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on LinkedIn](https://static.hubspot.com/final/img/common/icons/social/linkedin-24x24.png)](http://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fresources.workstate.com%2Fblog%2Fautomate-everything-except-platform-upgrades%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on Twitter](https://static.hubspot.com/final/img/common/icons/social/twitter-24x24.png)](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fresources.workstate.com%2Fblog%2Fautomate-everything-except-platform-upgrades%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fresources.workstate.com%2Fblog%2Fautomate-everything-except-platform-upgrades%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=Automate%20Everything%21%20%28Except%20Platform%20Upgrades%29) [![Share on Email](https://static.hubspot.com/final/img/common/icons/social/email-24x24.png)](mailto:?subject=Check%20out%20https%3A%2F%2Fresources.workstate.com%2Fblog%2Fautomate-everything-except-platform-upgrades%3Futm_medium%3Dsocial%26utm_source%3Demail%20&body=Check%20out%20https%3A%2F%2Fresources.workstate.com%2Fblog%2Fautomate-everything-except-platform-upgrades%3Futm_medium%3Dsocial%26utm_source%3Demail)

![Automate_Everything_IAM.jpeg](https://resources.workstate.com/hs-fs/hubfs/blog-images/iam/Automate_Everything_IAM.jpeg?width=320&name=Automate_Everything_IAM.jpeg)**AKA:** **Backwards Progression – Keeping Control of Your Solution Environment**

Software development has always had its struggles. From dropping your perfectly ordered stack of punch cards to the nightmare known as "[DLL Hell](https://en.wikipedia.org/wiki/DLL_Hell)," developers are not strangers to environmental, platform and ecosystem pains.

In today's world, we have plenty of new challenges. Challenges such as dealing with integrations across [physical and virtual boundaries](http://workstate.com/cloud-shift) or [maintaining identity and access control](http://workstate.com/iam) – no matter where you are working. Interestingly, these are all problems that have arisen due to a thematic force in technology: *Progress*. Over the last month or so, I was reminded of this very force on two individual occasions – and both of these instances were the definite cause of some major struggles for a large development team (but fortunately, not its customers).

The first incident happened when Google automatically rolled out a shiny new version of Chrome – to *mostly* everyone. In this update, Google chose to remove support for the validation of domains using the common name for x.509 (SSL) certificates. So, certificates that did not come with a subject alternative name were immediately rendered invalid.

Bummer.

As the browsers began to automatically update, you could see the trickle turn into a stream ( … and then into a gigantic wave). The QA team started to raise defects, the developers lost their ability to work, and the infrastructure team had to go into firefighting mode to figure out how to get the certs reissued quickly. Nearly everyone was affected.

Of course, Google published an [Intent to Remove](https://groups.google.com/a/chromium.org/forum/#!topic/security-dev/IGT2fLJrAeo) in February, but like most companies, the client did not have its devops team looking at platform risks.

Only a couple of weeks later, some new iOS devices made their way into circulation. These new devices wreaked major havoc in a process that was very (very, very) heavily tested over the last couple of months. While prior devices were locked down by policy, the new ones had iOS 10.3.1 on them, which has some show-stopping issues with the WebSocket protocol. Fortunately, this situation was more isolated, but it definitely cost thousands in dev-hours to isolate and mitigate.

What should we take away from all of this? Here are a few tips to make sure you don’t get bitten when your platforms “progress.”

**Freeze the Production Versions of Your Platforms**  
All things that could impact your solution should be locked down to the patch level. This includes OS, browsers, and any other framework that could be updated. Turn off automatic updates by policy, setting or privileges. If possible, freeze development and QA environments as well, keeping things as controlled as possible.

**Integration Testing**  
Perform integration testing prior to rolling out any platform upgrade. If your QA process doesn’t include an environment with the ability to isolate integrations, you’ll find yourself behind when it really counts.

**Mature Your DevOps Processes**  
At a minimum, your new processes should include monitoring and proactive risk mitigation for all dependencies in your chain. Many platforms allow for alpha- and beta-level access to upcoming versions. A DevOps team firing on all cylinders will vet versions early, then provide feedback to the vendors to try to block potential issues in their platform upgrades.

A little planning can save you a lot of time and the expense of disaster recovery. Don’t hinder your progress … with progress.

Interested in learning more about the fundamentals of Identity and Access Management?

[![Get IAM Primed Now!](https://no-cache.hubspot.com/cta/default/2258296/3543afec-f439-45d5-afbe-3ea824a116c1.png)](https://cta-redirect.hubspot.com/cta/redirect/2258296/3543afec-f439-45d5-afbe-3ea824a116c1)

### Subscribe to Email Updates

### Recent Posts

### Posts by Topic

- [Cloud Shift (17)](https://resources.workstate.com/blog/topic/cloud-shift)
- [IAM (16)](https://resources.workstate.com/blog/topic/iam)
- [Cloud Computing Best Practices (11)](https://resources.workstate.com/blog/topic/cloud-computing-best-practices)
- [Enterprise Identity (10)](https://resources.workstate.com/blog/topic/enterprise-identity)
- [Identity and Access Management (10)](https://resources.workstate.com/blog/topic/identity-and-access-management)
- [Cloud Migration (8)](https://resources.workstate.com/blog/topic/cloud-migration)
- [Technology Team Rental (8)](https://resources.workstate.com/blog/topic/technology-team-rental)
- [Cloud Shift Best Practices (6)](https://resources.workstate.com/blog/topic/cloud-shift-best-practices)
- [Identity (5)](https://resources.workstate.com/blog/topic/identity)
- [Workstate Codes (5)](https://resources.workstate.com/blog/topic/workstate-codes)
- [AWS (4)](https://resources.workstate.com/blog/topic/aws)
- [Application cloud migration (4)](https://resources.workstate.com/blog/topic/application-cloud-migration)
- [Big Data (4)](https://resources.workstate.com/blog/topic/big-data)
- [For Developers (4)](https://resources.workstate.com/blog/topic/for-developers)
- [Indentity and Access Management Best Practices (4)](https://resources.workstate.com/blog/topic/indentity-and-access-management-best-practices)
- [Lift and Shift (4)](https://resources.workstate.com/blog/topic/lift-and-shift)
- [Workstate (4)](https://resources.workstate.com/blog/topic/workstate)
- [Best practices (3)](https://resources.workstate.com/blog/topic/best-practices)
- [Cloud Innovation (3)](https://resources.workstate.com/blog/topic/cloud-innovation)
- [big data insights (3)](https://resources.workstate.com/blog/topic/big-data-insights)
- [Application Security (2)](https://resources.workstate.com/blog/topic/application-security)
- [Google Cloud (2)](https://resources.workstate.com/blog/topic/google-cloud)
- [IdentityServer3 (2)](https://resources.workstate.com/blog/topic/identityserver3)
- [Insider (2)](https://resources.workstate.com/blog/topic/insider)
- [Microsoft Azure (2)](https://resources.workstate.com/blog/topic/microsoft-azure)
- [data intelligence (2)](https://resources.workstate.com/blog/topic/data-intelligence)
- [hadoop (2)](https://resources.workstate.com/blog/topic/hadoop)
- [Azure Active Directory Best Practices (1)](https://resources.workstate.com/blog/topic/azure-active-directory-best-practices)
- [Design Patterns (1)](https://resources.workstate.com/blog/topic/design-patterns)
- [Development teams (1)](https://resources.workstate.com/blog/topic/development-teams)
- [IdentityModel (1)](https://resources.workstate.com/blog/topic/identitymodel)
- [Programmer Productivity (1)](https://resources.workstate.com/blog/topic/programmer-productivity)
- [QA & Testing (1)](https://resources.workstate.com/blog/topic/qa-testing)
- [Technology mentorship (1)](https://resources.workstate.com/blog/topic/technology-mentorship)
- [identity and access management best practices (1)](https://resources.workstate.com/blog/topic/identity-and-access-management-best-practices)

see all

![Round Workstate Logo](https://resources.workstate.com/hs-fs/hubfs/Workstate-Nov2016/Image/Footer%20Logo.png?width=350&name=Footer%20Logo.png "Round Workstate Logo")

Columbus  
Los Angeles  
Pittsburgh  
San Francisco  
Seattle

**OUR PRACTICES**

[Technology Team Rental](http://workstate.com/teamrental)  
[Big Data](http://workstate.com/bigdata)  
[Cloud Shift](http://workstate.com/cloud-shift)  
[Identity and Access Management](http://workstate.com/iam)  
[QA and Testing](http://workstate.com/qa)  
[Application Security](http://workstate.com/appsecurity)

**CONTACT**

  (614) 559-3904  
  [hello@workstate.com](mailto:hello@workstate.com)

30 Spruce St. Suite 300  
Columbus, OH 43215

<https://twitter.com/workstate> <https://www.linkedin.com/company/workstate> <https://facebook.com/workstate>