TCG074: From SOAR to Agents: Why Practical Automation Has to Survive Contact with Real Infrastructure
Three infrastructure and automation veterans discuss the evolution from SOAR platforms to AI-driven automation, examining the gap between vendor demos and real-world brownfield infrastructure. They explore how DNS remains critically underappreciated from a security standpoint, and debate whether AI is creating more technical debt than it solves. The conversation emphasizes that automation and AI are tools that elevate engineers rather than replace them.
Summary
The episode features host William, co-host Yvonne, and guest Sif, a long-time infrastructure and automation practitioner who has worked at Infoblox and a SOAR vendor called Swimlane, among others. The conversation opens with nostalgia around early network automation tools, particularly Net MRI, which Sif used at DirecTV to change 30,000 interface descriptions in a single night and later to discover rogue printer devices causing broadcast storms across 19 manufacturing plants. These stories frame the core argument that automation has always been about solving real operational problems at scale, not just replacing manual labor.
The group addresses the fear engineers have around AI replacing jobs, arguing consistently that automation has historically elevated engineers to higher-order work rather than eliminating roles. Sif notes that he has never automated himself out of a job despite decades of automation work. William extends this by arguing that the most valuable engineers are those who identify problems and independently solve them in ways that benefit the business, and that AI creates new roles around governance, prompt engineering, and data science rather than simply eliminating existing ones.
A significant portion of the conversation focuses on the gap between polished vendor demos and the messy reality of brownfield infrastructure. Sif acknowledges that AI and automation solutions work well roughly 90-95% of the time, but real environments always have snowflake systems requiring custom handling. Yvonne argues that customers who actively help vendors understand this gap have outsized influence on product direction, often more than vendors' internal teams, because builders and operators have fundamentally different perspectives.
The discussion shifts to DNS as an underappreciated security surface. Sif describes how DNS logs can quickly answer forensic questions that security teams spend days investigating through other means, and how DNS exfiltration was a known attack vector long before most organizations thought to monitor it. He highlights Infoblox's IETF draft proposal to use DNSSEC-signed records to publish MCP server locations, allowing LLMs to securely discover and connect to vendor AI services through trusted DNS infrastructure rather than through unknown third-party MCP servers.
Yvonne raises the challenge of dependency mapping in multi-cloud environments, noting that the early excitement around cloud was largely a greenfield effect, and that as environments matured into multi-cloud complexity, understanding service interdependencies — including identity systems, DNS, and networking — has become nearly impossible. She warns that AI risks becoming a technical debt accelerator, citing the Jurassic Park principle of being so focused on what can be built that teams skip asking whether it should be built. The group agrees that standard workflow automation is still the right tool for many problems that are being reflexively framed as AI problems, and that the AI SOC as a black box concept is being sold faster than organizations can evaluate whether it actually addresses their specific risks.
About this episode
Eyvonne Sharp and William Collins speak with Sif Baksh, Principal Solutions Architect at Tines, to discuss the power of automation. Sif shares some personal stories of how he has been able to use automation to innovate and modernize networking operations. They also discuss the importance of learning AI and using it as a tool, how<a class="excerpt-read-more" href="https://packetpushers.net/podcasts/the-cloud-gambit/tcg074-from-soar-to-agents-why-practical-automation-has-to-survive-contact-with-real-infrastructure/" title="ReadTCG074: From SOAR to Agents: Why Practical Automation Has to Survive Contact with Real Infrastructure">... Read more »</a>
Key Insights
- Sif argues that he has never automated himself out of a job across decades of network and security automation work, and uses this as evidence that AI will similarly elevate rather than eliminate engineering roles.
- Yvonne claims that customers who actively surface the gap between vendor demos and real-world brownfield environments often have more influence over product roadmaps than vendors' own internal teams, because builders and operators have fundamentally different experiences.
- Sif describes Infoblox's IETF draft proposal to use DNSSEC-signed DNS records to publish MCP server locations, allowing LLMs to securely discover and authenticate vendor AI services without relying on unknown third-party servers.
- Sif contends that DNS logs are one of the fastest and most underused forensic tools in security investigations, capable of answering 'who had this IP and when' questions that security teams spend significant time resolving through other means.
- Yvonne argues that AI carries a high risk of becoming a technical debt generator, noting that the industry lacks the accumulated wisdom to use it intentionally because it hasn't existed long enough to develop best practices.
- The group argues that automation solutions perform at roughly 90-95% reliability in real environments, meaning operators must identify and build exception handling for the snowflake systems that fall outside normal parameters rather than expecting full determinism.
- Yvonne observes that early cloud adoption felt easy largely because it was a greenfield environment, not because cloud itself was inherently simple, and that the complexity has since compounded as organizations accumulated multiple cloud environments with tangled dependency maps.
- William argues that the AI SOC concept is being sold as a black box before organizations have evaluated whether it actually solves their specific business problems and risk posture, mirroring a broader pattern of buying shiny tools before validating fit.
Topics
Transcript
. Welcome to another episode of the Cloud Gambit. I am here on, honestly, it's one of those days where it would be nicer if I was just outside. It is full. It's not super windy, not super humid. The sun is out. The clouds are not out. It's a gorgeous day. Yvonne, my co-host, happens to not live too far from me. So are you experiencing the same beautiful weather, Yvonne? Yes, I am. I look out my window and I see sky and it's officially springtime. So the worst of the cold is behind us. I might have a little bit more left. But super excited that it is springtime and we're through the winter. I do have…
Full transcript available for MurmurCast members
Sign Up to AccessMore from The Everything Feed - All Packet Pushers Pods
TNO071: The Network Team Is Drowning. Is AI the Life Raft? (Sponsored)
Rekha Shenoy and Irfan Kimji from Backbox discuss how the exponential growth of vulnerabilities (49,000 CVEs annually) has made manual network operations unsustainable, and how AI-powered automation can help network teams manage patches and security updates at scale while maintaining human control and oversight.
HN840: How to Make a Technology Buying Decision
Sean Morgan, a research director at Deloro Group, discusses how technology buying decisions should extend beyond engineering specifications to include business alignment, ROI calculations, and understanding total cost of ownership. Engineers must shift from viewing IT as a cost center to positioning it as a business enabler by connecting technical decisions to revenue impact and organizational objectives.
IPB207: Flying Blind: Monitoring Might Not See IPv6
The IPv6 Buzz hosts discuss critical gaps in IPv6 monitoring across enterprise networks, highlighting that many monitoring platforms lack IPv6 awareness, vendor parity, and advanced analytical capabilities. They emphasize that while basic IPv6 data ingestion has improved, sophisticated features like cross-protocol event correlation, extension header analysis, and device identity tracking remain significant industry challenges.
N4N063: Link Layer Discovery Protocol
Link Layer Discovery Protocol (LLDP) is a standardized Layer 2 protocol that enables network devices to announce information about themselves to directly connected neighbors, facilitating network topology discovery and device identification in multi-vendor environments. The protocol uses Ethernet frames with special multicast destination MAC addresses to ensure frames don't propagate beyond immediate neighbors, and includes mandatory TLVs (Type-Length-Values) like chassis ID, port ID, and TTL alongside optional ones for extended information.
TCG083: Superintelligence for Everyone: Who Actually Holds the Power?
Three technology experts discuss Mark Zuckerberg's manifesto on distributed superintelligence, examining whether his promises of universal access and individual empowerment align with infrastructure realities. They conclude that while decentralized AI is theoretically safer than centralized control, the manifesto fails to account for human complexity, existing inequalities, and the enormous capital requirements that will likely concentrate power rather than distribute it.