When we talk to systems administrators and other IT leaders about what they expect from their management solutions, we tend to hear a few common themes – and one those themes is “Control”. Controlling when, how and where changes are promoted is central to Orca. But that is not quite enough. We also know that you need to control who can view and manage changes. So Orca has taken traditional Role Based Access Control (RBAC) and added new levels of flexibility, convenience and granular control.

See how Orca’s RBAC help you achieve and maintain PCI compliance – Free White Paper

Flexibility: Use Orca how you want – web based interface or API

Users may choose to interact with Orca via its web-based user interface or programmatically through the Orca API. Both methods of access provide role based access control (RBAC). One benefit of having RBAC that applies to both the UI and API is that you can grant restricted permissions to outsourcers or third parties – and you will know they do not have access to sensitive data.

Convenience: Orca Integrates with Microsoft Active Directory (AD)

Orca provides a built-in authentication mechanism as well as integration with Microsoft Active Directory. Many other tools integrate with AD for initial authentication only, but Orca also pulls AD group membership information, allowing you to quickly create Orca teams that mirror your AD groups. In fact, Orca teams can consist of any combination of local users, AD users, or AD groups. This makes it really easy to create teams the way YOU want to create teams, in minutes instead of hours and in just a few clicks. If you want to use your pre-configured Active Directory groups to assign team membership, all you have to do is add the AD group to your team and users in that group automatically get the correct restrictions and object-level permissions. If instead you want to create a team from scratch using local or AD users, you can do that as well!

Click the image for a quick RBAC video explainer

Granularity:

Control over who sees what; who does what

Orca administrators may create teams and assign necessary restrictions and object-level permissions.

Orca’s team based restrictions limit what individual users assigned to a team can do. You can restrict the ability to add/edit/delete ecosystems, nodes, activities, scheduled jobs, job results, calendar events such as maintenance windows or blackouts, and more. Teams can also be granted read-write or read-only privileges for specific ecosystems, activities, and endpoints for very granular access control. For example, the team responsible for your ecommerce application can be the only team with the rights to manage your ecommerce ecosystem. The ecommerce ecosystem can even be completely hidden from non-ecommerce users.

With Orca, you have a flexible, convenient and powerful RBAC system that helps you control precisely which teams and individuals can manage or even view your important ecosystems.

Want to see Orca’s RBAC in action? You are just a phone call away from getting a personal demo. Call us now or request your demo walk-through here.

See how Orca’s RBAC help you achieve and maintain PCI compliance — Free White Paper

RBAC with Orca:
Full control over need to know

See how Orca helps

Enterprise Architects   |   Dev   |   DBA Managers   |   QA   |   IT Ops   |   Security & Compliance   |   Disaster Recovery   |   CIO

Achieving Environment-Aware Releases

| Automation, Why Orca | No Comments
Environment-Aware Releases are Intelligent Releases Wouldn’t it be great to release software knowing ahead of time that your deployment will just work? There are a lot of moving parts and a lot that can go wrong but environment-aware releases can certainly put the odds in your favor. Whether you call them Intelligent Deployments or Environment-Aware Releases, they are simple…in theory. We define Environment-Aware Releases as...

CIO Series: Security & Privacy

| CIO Series, Compliance | No Comments
Forbes contributor Steve Andriole provides his analysis of Top CIO priorities in which he advocates unorthodox approaches to Security & Privacy. Specifically he floats the idea of aligning the budget for Security & Privacy to the organization that is tasked with protecting Security & Privacy. Andriole also cautions against companies which "buy, install and support monster enterprise applications".  We argue that this line of thinking certainly applies to...

Modernizing Your DevOps Tool Chain

| Risk / ROI, Why Orca | No Comments
Build a DevOps tool chain that works today and tomorrow Doing Less with More? Or More with Less? Summary: Choose your DevOps tool chain carefully. Select tools that work with the IT you want and with the IT you have for cross-platform application release and configuration management.  The IT climate of “doing more with less” has evolved into an IT reality of “doing less with more”. Who...

Agile for Ops

| Why Orca | No Comments
IT Operations Teams are Pushed to Keep Up with Dev Can DevOps tools help achieve Agile for Ops? Until now Agile has mostly been applied to Development practices. But where does that leave Ops? Operations teams are naturally being pushed to keep up with Dev's pace. Ops is struggling though. It’s not from a lack of talent. It’s not from a lack of trying. Ops teams...

Unified Application Release and Configuration Automation

| Annoucements, Automation, Why Orca | No Comments
Announcing Unified Application Release and Configuration Automation Orca announces an industry first – a unified application release and configuration automation solution. Previously IT Operations teams required multiple point solutions, homegrown tools and error-prone scripting to release their application from Test to Pre-Production to Production environments - and once that is done to continually manage and orchestrate these environments including related applications, middleware, databases and configurations.  Many users...

CIO Series: Aligning IT to the Business

| CIO Series | No Comments
Every year author, entrepreneur and Forbes contributor Steve Andriole, provides his analysis of Top CIO priorities. While many of the priorities (security, cost, agility, etc.) are predictable, it is Andriole’s analysis and recommendations that are provocative and likely to make CIOs ‘crazy’ (his words). This article covers aligning IT with the business. IT Recommendation 1: Aligning IT with the Business The only way to align technology with...

IT Migration from Today to Someday

| Risk / ROI, Uncategorized, Why Orca | No Comments
“Here is a blank check. Spend whatever you need to modernize our entire IT environment right away”, said no one ever. IT Migration: Bridging Your Today IT to Your 'Someday' IT There are simply too many new game-changing technologies and platforms to adopt all at once. Until ‘someday’ arrives you have to prioritize where and how you spend your limited IT budget. What IT considers ‘legacy’...

Configuration Automation Myths vs Reality

| Automation, Why Orca | No Comments
Myths vs Reality: Configuration Automation & Scripting  Scripting is safe, fast and secure...Or is it? Configuration Management is unnecessary once you migrate to the cloud...Or is it? IT is tough enough without buying into misinformation. We outline some important Configuration Automation Myths vs Realities in this chart. Unlike a mythical (someday) environment, Orca is built for the real world complexities that developers, IT Ops, application owners...

How Orca Works

| How Orca Works | No Comments
Using Orca: A Summary Orca is a unified application release and configuration automation platform that delivers 1) Central, Secure Control & Compliance Enforcement  2) Intelligent Workflow Automation of Linux and Windows ecosystems  3) Application Ecosystem Modeling & Visibility  and 4)  Audit-ready & Reporting. For more information on How Orca Works, please view our Orca product sheet and whitepapers or request a demo overview.  1) Central, Secure Change Control & Compliance Enforcement  Orca inventories...

Scripting-Centric Automation vs Intelligent Workflow Automation

| Automation, How Orca Works | No Comments
Comparing Multi-step Scripting with Drag & Drop Deployments When it comes to deploying changes throughout your enterprise-scale, Linux and Windows application environment, there is Scripting-Centric “Automation”…and there is Intelligent Workflow Automation. Puppet, Chef and Orca are all used to maintain desired state and deploy routine configuration changes. But how they manage configurations and deploy those changes is very different. Puppet and Chef use scripting-centric automation while...

Enforce (don’t just report) configuration compliance and policy

| Control, Why Orca | No Comments
Monitoring is a good start. But it is not enough. Monitoring the applications, OS, and servers that make up your environment is a no-brainer. How many times have you had a customer be the first to inform you there was a problem? Those early alerts about performance problems, outages and security breaches are essential to running a tight IT ship. But they are not enough. Imagine going to a dentist and being...

Ecosystem Modeling for Visibility & Compliance Enforcement

| Ecosystem Visibility, How Orca Works | No Comments
Modeling Your Application Ecosystem Ecosystem Modeling for Visibility & Compliance Enforcement Modeling your application ecosystem (including related applications, databases, middleware and servers in mixed Linux-Windows environments) is a powerful way to create intuitive birds-eye views of your environment as well as granular views of the full stack configurations that tie your infrastructure together - physical, virtual and cloud. Due to limited choices many IT organizations resort...

Automating Configurations in Windows Environments without Scripting

| Automation, Why Orca | No Comments
Configuration Automation for Windows without Scripting  Automating configuration compliance or bulk-deployment in a Windows (or  mixed Windows & Linux) environments has never been easy. Windows Server, IIS, MS SQL Server, MS MQ and SharePoint by their very nature are more complex than many of their non-Windows counterparts. Managing them is hard, so the desire to automate is strong. But frankly most new automation solutions cater...

Less than Free: Puppet, Chef & other Open Source

| Risk / ROI, Why Orca | No Comments
Free isn't Free It is easy to understand the appeal of Open Source tools. After all, immediate gratification, community and a “free” price are certainly attention-getting for many developers. But IT Ops teams and their managers need to be careful to consider all of the costs when choosing free software such as open source versions of Puppet or Chef (especially if they are operating in...

Wishing You a Boring New Year. Drama-Free IT

| Why Orca | No Comments
Wishing you a Boring New Year We wish you a boring new year! We really do. At least at the office. After all there is nothing too exciting about Stability, Support and Security – but we want that for you. The Goal: Drama-Free IT You probably prefer excitement in your favorite sporting and entertainment events and drama at the movies. And if you are like most...

It’s Enterprise “Cold and Flu” Season. Treat the DevOps Disease, Not the Symptoms.

| Control, Why Orca | No Comments
Treat the DevOps Disease, Not Just the Symptoms. The Symptoms You recognize the symptoms a mile away. The early stages of a sore throat. That cough that seems to have come from nowhere. Darn. Why didn’t I get a flu shot this year!? Is the health of your business critical applications really all that different? Here the symptoms are web application performance glitches, security vulnerabilities and even...

Rugged DevOps: the Good, the Bad and the Ugly

| Visibility, Why Orca | No Comments
(Note: an earlier version of this article was first published on DevOps.com http://devops.com/2015/12/22/rugged-devops-good-bad-ugly/) The Good: DevOps has been a success for Dev. With higher expectations, better processes, more management focus and new tools like advanced PaaS and containers, developers are churning out more and more software faster than ever. Success! Or is it? The Bad: DevOps has been a success…for Dev. For Dev teams, this may...

Dev wants Open Source. Ops needs Scale, Stability, Support, Security & Speed. Now What?

| Risk / ROI, Why Orca | No Comments
Note: this article was originally published on DevOps.com http://devops.com/2015/12/09/dev-loves-open-source-ops-needs-scale-now/  Dev Loves Open Source Like so many other areas of enterprise software, when it comes to configuration and release management, many developers naturally gravitate to open source options. It’s no wonder that 90% of code in modern applications is open source - after all, open source provides developers with... Immediate gratification Just Google it! Community Don’t reinvent!...

Application Configuration Management vs Application Release Automation

| How Orca Works, Why Orca | No Comments
MenuNEW! Announcing Unified Application Release AND Configuration Management In today’s world of "“automate all the things"” we hear a lot of questions about the difference between application configuration management and application release automation solutions. We understand the confusion between these related but different concepts and at Orca, we love to simplify things.  So here goes... Most Application Release Automation is limited in scope Whether you call it application...

Announcing Orca 2.1 – New Coverage for Schema, NGINX, NGINX Plus and YAML

| Annoucements, Why Orca | No Comments
See this announcement on DevOps.com http://devops.com/2015/11/20/orcaconfig-announces-new-support-nginx-schema-yaml/   With Orca’s version 2.1, enterprise IT Teams that operate in complex, heterogeneous environments now have even more coverage and support to automatically control their application environments. Users of NGINX and NGINX Plus, MS SQL Server and YAML files can now model their application ecosystem, enforce compliance and control of their application configurations, intelligently automate their workflows, and deliver audit-ready...
Enterprise Architects   |   Dev   |   DBA Managers   |   QA   |   IT Ops   |   Security & Compliance   |   Disaster Recovery   |   CIO