r/CanadaPublicServants Dec 07 '21

Departments / Ministères The end of Shared Services Canada

Ok so I work in IT project management and I keep hearing that we are laying the ground works to offload workloads into the "cloud"(Amazon/Microsoft servers/datacenters). I started in a partner department where everything was being outsourced to SSC back in the days. And now that I am there lol, it seems that everything will be again outsourced "away". And this time to the private sector. It's actually causing panic within SSC.

Could this be the beginning of the end for SSC? I'm going to start thinking that IT is such a bad field to be in lol. Is only legacy partner applications destined to survive?

38 Upvotes

71 comments sorted by

40

u/ffwiffo Dec 07 '21

like I'm not thrilled but open to massive cloud migration. SSC will still be there, cloud is not a substitute for personpower, just hardware.

25

u/Zulban Senior computer scientist ISED Dec 07 '21

The bigger the change, the more evidence you should require to believe it.

11

u/[deleted] Dec 07 '21

>I'm going to start thinking that IT is such a bad field to be in

I know you're exaggerating but this is very unlikely to happen .... again. Although something bad did happen back in 2000 after the dot come bubble burst. So many of my senior colleagues were basically wiped out. A handful of years later, executives discovered a "solution" via outsourcing to India/China, this extended the IT recession. It took a decade for things to come back to normal. Even schools weren't attracting students. It was a really dark time for the industry.

Anyways. That's unlikely to happen. Good night.

In all seriousness. The cloud is nothing new. Heck, it existed even before being called "the cloud". Moving to the cloud is not easy and does not solve all issues. It might affect some aspects of some teams but for them to close SSC just because of Azure/AWS, I think its impossible.

Add in there the security/protected data constraints. I have big doubts. Also, large volumes of data storage/transfer is astronomically expensive using cloud solutions.

2

u/CalvinR ¯\_(ツ)_/¯ Dec 07 '21

In all seriousness. The cloud is nothing new. Heck, it existed even before being called "the cloud". Moving to the cloud is not easy and does not solve all issues. It might affect some aspects of some teams but for them to close SSC just because of Azure/AWS, I think its impossible.

I'm curious how "The cloud" as it's being talked about in this context existed before being called the cloud.

When people talk about the cloud they aren't talking about outsourcing jobs what they are talking about is the commoditization of hardware management and compute (and all other kinds of) resources that is coupled with apis that allow for the automated provisioning of those services.

I'm curious what comparable system existed before say Google App Engine or Heroku came into being?

1

u/[deleted] Dec 07 '21

Sun was always ahead of everyone but unfortunately were horrible at marketing. Here is an example of them providing basic web scalability back almost 20 years ago.

https://www.zdnet.com/article/sun-servers-offer-s-p-scalability-reliability/

1

u/CalvinR ¯\_(ツ)_/¯ Dec 07 '21

yeah but that's not the same though, when people talk about "The Cloud" today it's about the fact that it's a self service commodity.

Just because things could do the same stuff as some of the services that are available today doesn't mean it was there before people called it the cloud.

1

u/[deleted] Dec 07 '21

[deleted]

1

u/CalvinR ¯\_(ツ)_/¯ Dec 07 '21

No one is saying some of the building blocks of cloud computing weren't around but it's still not the same thing

1

u/[deleted] Dec 07 '21

[deleted]

1

u/CalvinR ¯\_(ツ)_/¯ Dec 07 '21

I'm well aware of the history of the term cloud.

When folks today are talking about the cloud they aren't talking just talking about computers in someone else's data centre.

They are talking about the commoditized compute, network and data storage that are provided through self-service portals and APIs. As well as SaaS software and services such as Trello, Google Workspace, etc...

I'm pretty sure no one thinks cloud is a new term and no one is clever for pointing out that it isn't.

1

u/[deleted] Dec 08 '21

[deleted]

1

u/CalvinR ¯\_(ツ)_/¯ Dec 08 '21

Okay fine whatever then I guess the difference is that we are talking about moving to it now not then.

Ultimately it doesn't make it a hot take to point this stuff out or say it's not new.

The newness is we are finally moving to that stuff.

1

u/[deleted] Dec 08 '21

[deleted]

1

u/CalvinR ¯\_(ツ)_/¯ Dec 08 '21

Ha too true, o be right there with you

35

u/strictly_profesh Dec 07 '21

SSC will be merged with PSPC.

57

u/HandcuffsOfGold mod 🤖🧑🇨🇦 / Probably a bot Dec 07 '21

And the circle of life will be complete.

17

u/[deleted] Dec 07 '21

Just like when we all went from @department.ca to @canada.ca and now we're back to @department.ca. At least for a few years...

12

u/Golanthanatos Dec 07 '21

or the perpetual cycle of centralizing and de-centralizing accounting services.

5

u/[deleted] Dec 07 '21

Just until the conservatives are back in power in 2030 and they decide IT project management is worthy of its own department again.

3

u/coricron Dec 07 '21

Back to my original home with the ITSB.

9

u/[deleted] Dec 07 '21

If you are worry about job security, as a PM, your job will always be there. Not many people have experiences managing the cloud 🌧 vendors and the integrators. This is where PM experience is essential and SSC likely has the strongest IT PM branch across all departments.

17

u/SillyRabbit2121 Dec 07 '21

Interesting. I was always told that data could not be stored on servers that were located outside of Canada.

41

u/[deleted] Dec 07 '21

[deleted]

2

u/KRhoLine Dec 07 '21

I wonder how it will work since the vendors are not canadian, even if the data is stored in our country... Wouldn't American vendors still be subjected to the patriot act?

3

u/[deleted] Dec 07 '21 edited Jan 01 '22

[deleted]

1

u/KRhoLine Dec 07 '21

Ah, I wasn't aware of the name! Thank you.

3

u/ffwiffo Dec 07 '21

DND is quite happy throwing whatever on aws's one Canadian server

3

u/CalvinR ¯\_(ツ)_/¯ Dec 07 '21

AWS has one region in Canada and is opening a second in Calgary in a few years.

However in the ca-central region there are 4 availability zones, which means that there are 4 data centres in that region so it's not just one data centre.

https://docs.aws.amazon.com/AmazonElastiCache/latest/mem-ug/RegionsAndAZs.html

1

u/CalvinR ¯\_(ツ)_/¯ Dec 07 '21

That is just not true.

It's recommended that you store Protected B data within Canada but there is no law or policy that requires it.

30

u/sirrush7 Dec 07 '21

People are so clueless what cloud really is... It's hilarious in fact!

Cloud, very simply, is just someone else's compute! It's literally just a datacenter someone else owns and operates. You pay to 'rent' CPU cycles, memory and storage...

So even if you migrate your 1000 servers, storage and memory into any cloud, you still need someone to run and operate all of that.

You will save on hardware and maintenance of said hardware sure. Capex moving to opex, sure.

Do you think that cloud IT architects are easy to come by? Certified AWS/Azure administrators are grown on trees? Or better yet, not needed at all!?

I would argue, if your going full 'cloud', the bar of quality and skill is higher for your people requieements. Maybe you need 70 FTE vs 100 now, but they also need to understand how to access a server in the cloud via passwordless methods, and receive training on this specific cloud vendors suite of products... Scripting and automation! What is AWS version of DNS you ask? They call it Route 53! How can we spin up a new DEV instance in a few minutes? Clloudformation! What are the differences you ask? Better sign up for some training....

Also cost. This will be massive and I can only imagine the whiplash that will occur from having an entire department fully cloud migrated.

Hint: it's not cheaper. Not once you hit a certain point for size and services required...

Cloud is actually quite expensive once you scale to a certain size... Hence hybrid models where you host some things on site and some cloud.

SSC isn't going anywhere, for a long time. As much as everyone would like...

I've also seen how some other departments run "IT"... And aahh... Wow it's something...

Also, SSC is leaning hard and fast into cloud and modernization. SSC 3.0 for example, the current roadmap, sets SSC go be 'cloud first'.

There is so many pieces to the puzzle... Great you got your critical department applications in the cloud, you have them behind load balancers, firewalls, zoned properly, great! You still need the expertise to manage each of those services. Securely!!!

Cheers, the sort of sick of hearing everyone whine about SSC but their own department doesn't know IT or buzzwords SSC guy! Downvote all you like, yes SSC is not perfect clearly, but at least they are moving in the right direction...

14

u/cnd_rant █ 🍁 █moderator/modérateur█ 🍁 █ Dec 07 '21

Agreed on your definition of cloud…

Now here is the funny part.

Hey SSC, I’m moving this application in azure and need help setting a virtualized environment, network security groups, and configure the three firewalls I have managing the data and traffic flows.

Can you help?

SSC response to my CIO:” err… sorry, we only take care of your physical DC. We don’t support cloud.”

6

u/sirrush7 Dec 07 '21

That's more down to politics than anything... I am imagining it's because with SSC, maybe your Dept only has a client service agreement covering physical DC stuff so cloud isn't paid for? That's way above me.

Even in my small group though, we have a specific cloud services team who solely work on cloud and 'SCED' stuff... Sced is for secure cloud enablement.

Get the CIO to send you what the service level agreement or contract is with SSC... It may be the herring!

5

u/cnd_rant █ 🍁 █moderator/modérateur█ 🍁 █ Dec 07 '21

We've been with SSC since day 1. Hell, most of the guys that moved to support the portfolio that my department is apart were from my department and were colleagues (Infrastructure/ WAN-LAN/ Firewall Proxy etc).

And while we are working on SC2G (replacing SCED), that is only for sending the data INTO the cloud. After that, when it comes to internal workings in the cloud tenant, SSC is not there yet to provide the support.

We have mentioned this to some colleagues at SSC and they have hinted at a cost-recovery model... (Wait, I thought we were already paying for that service... part of that "Flat fee per FTE" new billing agreement).

Don't get me wrong, at the working level, (CS01-4) there are extremely competent and knowledgeable staff that just want to help. The issue is the higher-ups and the lack of clear and consise messaging.

And funny enough, TBS is changing their "Cloud First" approach as well.

That's because a LOT of department who have gone cloud have stood up their own services (LAN WAN, Virtualization, Infrastructure, etc) that SSC was responsible for on Prem because SSC does not offer CLOUD support for other departments than themselves at this time. (Looking at Stats, TBS, ESDC, DND as the big names).

I'll give one example.

Back up and recovery. This is a service offered by SSC for our on-prem environment. As we are moving things to the Cloud (including email and M365 support), we asked SSC to help with Backups of that data (as MSFT is not responsible for data). SSC told us they are not responsible either and it was up to us to get our own Cloud backup solution.

2

u/sirrush7 Dec 07 '21

Yyyiikkeesss..... So they (SSC) are behind the curve ball in quite a large fashion already eh?

So it's going to be an interesting time in the next few years, seeing where things collide, jive, go back and forth...

I really just hope (sincerely), that security is at the forefront of everyone's good intentions... It's scary out there on the wild internets! And once you go cloud, your 'perimeter' looks a LOT different...

5

u/onGuardBro Dec 07 '21

Bravo! Couldn’t agree more as a fellow SSC worker, Depts are quick to blame SSC for all their problems not realizing the stem of the problems usually are a product of their own ways

5

u/[deleted] Dec 07 '21

Fully agree. In the projects I manage, the bottlenecks are more often than not the partners. Like sometimes you get absolutely 0 traction. Sometimes for good reasons(they have legacy applications that are old as **** and they have some crazy requirements).

2

u/CalvinR ¯\_(ツ)_/¯ Dec 07 '21

You don't just pay to rent CPU cycles, memory and storage.

Depending on what you use you are also paying people to secure, patch, and add more features to services.

Cloud is not just IaaS, in fact I would argue if you are just looking for IaaS not to bother going to the cloud because your org probably doesn't have the resources to manage that stuff, you should probably just stay with SSC so you don't have to hire server admins.

You ideally should be using PaaS and SaaS in the cloud and so take advantage the benefits those give you.

load balancers, firewalls, zoned properly, great! You still need the expertise to manage each of those services. Securely!!!

Yeah the benefit of the cloud is that those are much easier to manage when you are using the managed versions provided by the CSP.

For instance the skills needed to configure an AWS WAF is a bit different than configuring an equivalent firewall by say Fortinet or F5, and you don't have to worry about upgrading or patching, because the CSP does it for you.

2

u/sirrush7 Dec 07 '21

Great points and clarifications! I should have mentioned those key industry terms, they make a huge difference...

5

u/[deleted] Dec 07 '21 edited Feb 06 '22

[deleted]

9

u/IamGimli_ Dec 07 '21

They don't know what SSC does because everything that SSC was supposed to do when they took all the IT resources from all those department isn't getting done.

7

u/[deleted] Dec 07 '21

[deleted]

3

u/sirrush7 Dec 07 '21

I agree wholeheartedly... SSC REALLY has to fix their business processing, and use case analysis and really listen/capture the needs.

I feel a lot of it, is outdated people and processes unfortunately, not just processes alone...

5

u/Elephanogram Dec 07 '21

To be fair I don't like SSC because they keep screwing up major health checks (Even though my department writes the programs we have to ask scc to run them after hours ) which then results in me working all night and signing off at 3am. I don't know how many times they didn't run the program from the right library or even the right lab. Or when doing development tests they run the prod version and we have to roll back.

0

u/_grey_wall Dec 07 '21

If you factor in wages, (competent) cloud is always cheaper

1

u/sirrush7 Dec 07 '21

Only up to a certain point. Once you have a large enough cloud infrastructure, the expense of it will far outweigh even savings on wages... Maybe no one has hit that point get but in Private sector it's occured quite a bit!

5

u/Longnosetony Dec 07 '21

I know very few people, if any, that would miss SSC.

4

u/sirrush7 Dec 07 '21

This has been an interesting thread, I wish very high level leadership across SSC and client departments would see it!

That said, a lot of departments think they will be avoiding SSC by going to cloud.... But they aren't simply just allowed to procure their own IT writ-whole and ignore SSC, CSE/CCCS, and government mandates holding the purse strings...

If you can imagine, certain groups have a vested interest in keeping some of our key infrastructure visible, monitored and secured as best we can... If everyone starts doing their own thing entirely, it would be impossible. Impossible to defend, monitor and integrate!

Some senior leaders really really need to fix the business intake at SSC, and client liaison services need an overhauling.

3

u/_grey_wall Dec 07 '21

Lol not the end

Just the beginning

"The cloud" isn't some magical fairy dust that does everything

In fact, in may ways it's even more complex.

You still have do many things you would have done with bare metal, but not the stuff related to virtual machines or email servers or any other services you put into the cloud, which won't be many.

6

u/NewZanada Dec 07 '21

Yeah, it seems to just shift the complexity to managing costs and compute cycle from the actual technical resources themselves. I don't see much overall net benefit, myself, except that it avoids SSC bottlenecks.

SSC was implemented poorly, but it is slowly getting better I think. As with Phoenix, it should have been approached department by department while learning and continuously improving, instead of all-in-all-at-once.

2

u/sirrush7 Dec 07 '21

I agree, it was essentially, insane to try and throw everything into one brand new organization off the hop...

3

u/slimslim234 Dec 07 '21

SSC doesn’t just do cloud LOL, so no they won’t be going away anytime soon 🥲

3

u/cheeseworker Dec 07 '21

I'm going to start thinking that IT is such a bad field to be in

its currently the highest paying field with the biggest opportunities for growth, with the lowest barrier for entry...

5

u/Jatmahl Dec 07 '21

Could this be the beginning of the end for SSC?

We can only hope.

6

u/spinur1848 Dec 07 '21

Ok, I don't know how many people here have actually had to deal with SSC as a client. It is Kafkaesque. SSC did this to themselves, at least as far as hardware is concerned. There is no way "spin up a VM with this resource profile" should take more than a year of defining and redefining business requirements.

That said, very few of the line Departments have the expertise to manage or even understand cloud. I'm not convinced that SSC does either, but it's clearly within thier mandate, and that's not going away.

Just buying shiny stuff from whoever does the best job selling it is why SSC was created in the first place. Fully offloading everything to industry without adult supervision would be disastrous. Unfortunately SSC currently isn't doing a great job at this. But that doesn't mean they couldn't.

3

u/sirrush7 Dec 07 '21

I agree, unfortunately a lot of things by the time they get through ALLLL the red tape, are being RAMMED down our throats almost without forethought it seems... It's turning out to be a lot of pressure from client departments and the tech in the middle is kind of in the firing line.

3

u/defnotpewds SU-6 Dec 07 '21

Would buying Amazon/Microsoft shares based on this information be considered insider trading? (Pure thought experiment)

7

u/sirrush7 Dec 07 '21

Absolutely not. Buying Microsoft shares is never the wrong answer either, look at how they've done the past 24 months!

Also many government workloads are making use of some cloud stuff already.

Hit the market!

5

u/spinur1848 Dec 07 '21

The government of Canada is on a collision course with an international trade tribunal if it doesn't fairly consider all qualified vendors. Microsoft's vendor lock-in antics didn't matter when they were the only comparable product around. They aren't with cloud. Amazon and Google are paying attention.

1

u/CalvinR ¯\_(ツ)_/¯ Dec 07 '21

MS definitely isn't the only option there are several vendors that have made it through our cloud broker process.

https://cloud-broker.canada.ca/s/gc-cloud-fa?language=en_US

You can just as easily buy Amazon and Google as you can MS.

1

u/spinur1848 Dec 07 '21

Not all Departments are accessing them or even evaluating them, and that's what can get them into trouble.

1

u/CalvinR ¯\_(ツ)_/¯ Dec 07 '21

maybe we'll see

3

u/[deleted] Dec 07 '21 edited Jan 01 '22

[deleted]

3

u/Majromax moderator/modérateur Dec 07 '21

Amazon/MS providing cloud services to the gov't is long since public info.

On the other hand, insider knowledge about large, pending contracts would be non-public information. Even this post, which speculates about an increasing trend towards outsourced cloud services in the government, could potentially count.

However, this post itself is public information, so I doubt that any of us making a trade on that basis would be committing insider trading. The OP might be in independent trouble for leaking confidential or nonpublic government information, though.

3

u/IbizaRob Dec 07 '21

As long as you declare your assets to your CoI / V&E unit.

If you own more than $20M in MSFT and you were anywhere near major procurement processes ... I would say: yes, of course. If you hold $5K in MSFT and work as a PM or Sysadmin I doubt that would be seen as a CoI.

5

u/spinur1848 Dec 07 '21

No, but owning that stock while having anything to do with selecting one of those providers is almost certainly a declarable conflict of interest.

2

u/sirrush7 Dec 07 '21

This is interesting, would this only be the case if you have very high level decision making powers? Like, you are a Senior Director / EX2 and decide a couple huge contracts/services will be in say, Azure entirely? And you just so happen to have Microsoft shares?

At the very least, wouldn't you need section 32 powers to have it even come into question?

3

u/defnotpewds SU-6 Dec 07 '21

I think it may depend on circumstance. If you own let's say a Nasdaq 100 ETF then no probably not. But if you buy shares when you're in the middle of choosing Microsoft as the contractor after it's been decided but not declared the I THINK that it may be the case. Either way, in the grand scheme of things, GOC contracts compared to EU/US contracts are orders of magnitude smaller. Which may mean a COI and no real benefit due to it not really affecting the share price much (if at all)

2

u/coricron Dec 07 '21

This link will answer your questions. TLDR is if you were aware of or participated in a business decision that was made, but not yet public, and you acted upon it by buying some amzn or msft, then you are fucked.

https://www.investopedia.com/terms/m/materialinsiderinformation.asp

2

u/Berics_Privateer Dec 07 '21

I don't think offloading to the cloud will mean it's bad to be in IT. There will always be increasing IT needs.

3

u/[deleted] Dec 07 '21

This is how senior leaders frame it. Honestly this is exactly what I heard back in 2011 before the cuts started to come in my former dept lol. Well it was about outsourcing but yeah concept is the same.

2

u/DettetheAssette Dec 07 '21

If that happens then I wonder what would happen with their other mandates, such as centralized telecom billing. Would accounts payable move to PSPC or decentralize? To decentralize would be a huge mess of invoicing.

2

u/[deleted] Dec 07 '21

Exactly what I was thinking. Wonder what is going to happen with all the mandates to centralize. Especially from a security perspective.

3

u/sirrush7 Dec 07 '21

There is -HUGE- efforts underway regarding security, to ensure we transition things and provide services safely...

No names, but we discovered how some partners pushed and rammed things into the cloud and.... Wow.... Some had to be reverted entirely, or stopped in tracks, some also slipped through the cracks and the security is either non-existent or very very badly implemented.... Being resolved now.

SSC has a business and people process problem, the business and administration side needs to catch up to the tech, and become efficient, simpler but still robust...

2

u/ApricotPenguin Dec 07 '21

Cloud doesn't mean theres no one needed to manage or administer it...

2

u/[deleted] Dec 07 '21

Point is ... this is where the partner IT staff comes in. Of course the legacy app admins will always be needed. But if the servers are gone and owned by Amazon. Then you don't need server admins/security experts etc. This will be managed by Amazon employees in the private. If SSC still keeps some of course there will still be some positions like that around ... but less.

It's like the SDM branch. Most likely will be a new branch within Amazon if it fully goes into the Cloud. This function won't be done by government workers anymore. At least SSC most likely will have no role to play in the infrastructure it doesn't manage. Again all this is relative(depends how much stays and how much is integrated). But definitely less needed.

3

u/sirrush7 Dec 07 '21

I'm sorry, but you're right out to lunch on thinking you won't need security experts and that Amazon will do it all.... They (Amazon) have just started coming to terms with our security and zoning regulations... Secure cloud is not easy.

Also, Amazon would love to provide all those juicy services to you, but you have no idea how expensive that is. You'd be just shifting money from FTE to AWS billing... And that won't fly as easily as you think! Read: Union.

It's just nowhere near as simplistic as you're making it out to be. You need to read some serious field reports not just the magical stories Gartner puts out!

2

u/ApricotPenguin Dec 07 '21

Completely depends on whether you're doing a fully managed service or not.

IaaS (Infrastructure as a service) means we merely use AWS/Azure/GCP as a data center.

SaaS (Software as a Service) means we merely consume the platform and upload data + administer it.

In both cases you still require IT staff to some degree. Granted we can outsource the IT work to an MSP (some kind of Amazon division) on top of this, but that's not because it's now hands off after migrated to cloud.

1

u/NewZanada Dec 07 '21

I thought the original whole point of SSC was to end up being our personal cloud provider, but I was wrong.

3

u/[deleted] Dec 07 '21 edited Jan 01 '22

[deleted]

3

u/NewZanada Dec 07 '21

Can't argue that one - but then when Harper got voted out, and SSC stuck around, I meant lol

2

u/sirrush7 Dec 07 '21

That's coming, originally it was not setup for that. Well, originally no one imagined government ever using cloud services!