Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

How OXY Cut Infrastructure Provisioning from 74 to 4 Days

HashiCorp
04/09/2026
4
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


TL;DR

  • OXY reduced infrastructure provisioning time from 74 days to 30+ days in phase one, targeting 4 days in phase two—a 95% improvement—by implementing HashiCorp Terraform, Vault, and Packer with a platform engineering approach.
  • A comprehensive business impact assessment mapping the 74-day provisioning process across siloed teams became the most effective tool for securing executive buy-in, eliminating the need for lengthy justification presentations.
  • Establishing a cloud operating model with clear ownership boundaries—defining who controls IAM, networking, security policies—solved the shared responsibility challenge and gained buy-in from previously resistant security teams.
  • Building reusable blueprints (golden patterns) for high-impact teams first, combined with continuous feedback loops, shifted the platform team from reactive ticket processing to proactive service delivery.
  • Pairing operators with developers in the platform engineering team bridged critical skills gaps in Git, pipelines, YAML, and Terraform while maintaining operational expertise in networking and security configurations.
  • Creating a Cloud Center of Excellence (CCOE) with FinOps, procurement, and technical stakeholders ensured organizational alignment and removed procurement as a potential blocker to cloud adoption initiatives.

From 100-Year-Old Energy Company to Cloud-First Organization

OXY, a century-old energy company operating across oil and gas, chemicals, and low carbon ventures, embarked on a dramatic infrastructure transformation journey starting from ground zero in 2021. The company faced a critical challenge: their legacy on-premises infrastructure required 74 days and multiple siloed teams to provision a single EC2 instance across development, test, and production environments. This manual, ticket-driven process involved security, networking, compute, and storage teams working in isolation, creating massive bottlenecks that prevented the organization from responding to business needs. The pandemic supply chain crisis of 2018-2019, combined with emerging AI opportunities, forced leadership to reconsider their infrastructure strategy and commit to cloud migration with automation at its core.

The Business Impact Assessment That Changed Everything

Working with HashiCorp's field team, OXY conducted a comprehensive business impact assessment that mapped every step of their provisioning process, identifying which teams were involved, how long each stage took, and where bottlenecks existed. This white-glove assessment revealed the shocking reality: what should take minutes was consuming months of organizational time and resources. The visual representation of this 74-day process became the most powerful selling tool for executive buy-in, eliminating the need for lengthy justification presentations. By applying theory of constraints thinking, the team identified the longest poles in the tent and prioritized automation efforts on the stages that would deliver the most immediate time-to-value improvements, focusing first on low-hanging fruit that could demonstrate quick wins to skeptical stakeholders.

Building the Foundation: Platform Teams and Operating Models

OXY's transformation strategy centered on three foundational elements: establishing a platform engineering team, defining a cloud operating model, and creating reusable blueprints (golden patterns). The platform engineering team combined operators with developers to bridge the skills gap, as traditional infrastructure teams lacked familiarity with Git, Azure DevOps pipelines, YAML, and Terraform. The cloud operating model addressed the shared responsibility challenge by clearly defining ownership—who is accountable for IAM policies, network configurations, security controls, and other cloud constructs. This eliminated the dangerous "everybody owns security" mindset that actually means nobody does. By implementing HashiCorp Vault for just-in-time password rotation and secrets management, the team gained critical buy-in from security stakeholders who had previously been the biggest blockers to cloud adoption.

Phased Approach Delivers Measurable Results

Rather than attempting a complete transformation overnight, OXY adopted a phased approach with clear intermediate goals. Phase one focused on automating AWS account creation as an entry point, reducing provisioning time from 74 days to 30-plus days using Terraform Cloud, Packer for image building, and Vault for security. Phase two targets a four-day provisioning cycle—a 95% reduction from the original baseline. The team celebrates wins monthly with leadership and the broader organization, providing visibility into progress while maintaining momentum. By building blueprints for high-impact application teams first and gathering continuous feedback, the platform team shifted from reactive ticket processing to proactive service delivery. This customer-centric approach, treating internal developers as customers deserving of joy and ease of use, has been critical to driving adoption and cultural transformation across the organization.

Chapters

0:00 - Introduction and OXY Background
1:38 - The Legacy Challenge: 74-Day Provisioning
4:04 - Phased Transformation Strategy
6:52 - Business Impact Assessment Results
11:45 - Overcoming Political and Cultural Barriers
14:19 - Why Cloud and Why HashiCorp
16:01 - Current State and Future Goals
21:36 - Cloud Operating Model and Ownership
23:12 - Building Blueprints and Golden Patterns
25:49 - Workforce Development and Skills Gap
28:01 - Cloud Center of Excellence (CCOE)

Key Quotes

1:50 "We have a very specific teams, groups working in very silo. He works on security, firewall, working on firewalls, and compute and storage same way."
7:10 "It takes 74 days for us to provision the servers today, assuming that you know which tickets to open. And this is only for one environment."
9:35 "If you can work with HashiCorp on doing the BIA, the business impact analysis, I would truly encourage, because this is... You don't need to do the why selling. This itself would do the selling for you."
12:54 "When you go to the cloud, it is no longer a silo tasks. It is a cross-functional process."
14:00 "By implementing what we call cloud operating model, we identify and say, okay, from each team, from each services perspective, we know this is what you owe, you're accountable for, you're support for, and these are the run books that you need to do."
16:38 "Once we had that Volt and just-in-time password rotations, that's when we gained a lot of trust from the security team."

Categories:
  • » Cybersecurity » Application Security
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Cloud Security
  • DevSecOps
  • Best Practices
  • Customer Story
  • Technical Deep Dive
  • Infrastructure automation
  • Cloud migration strategy
  • Platform engineering
  • DevOps transformation
  • Cloud operating models
  • Business impact assessment
  • Organizational change management
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: How OXY Cut Infrastructure Provisioning from 74 to 4 Days

              Upcoming Webinar Calendar

              • 05/12/2026
                11:30 PM
                05/12/2026
                Implementing Effective Strategies for Active Directory Security and Data Protection
                https://www.truthinit.com/index.php/channel/1888/implementing-effective-strategies-for-active-directory-security-and-data-protection/
              • 05/13/2026
                01:00 AM
                05/13/2026
                Transforming the Black Box: Reveal Hidden Threats and AI Risks through Data Lineage
                https://www.truthinit.com/index.php/channel/1890/transforming-the-black-box-reveal-hidden-threats-and-ai-risks-through-data-lineage/
              • 05/13/2026
                05:00 AM
                05/13/2026
                Transforming the Black Box: Revealing AI Risks and Hidden Threats through Data Lineage
                https://www.truthinit.com/index.php/channel/1894/transforming-the-black-box-revealing-ai-risks-and-hidden-threats-through-data-lineage/
              • 05/19/2026
                01:00 PM
                05/19/2026
                Establishing a Robust AI Governance Framework for GenAI Throughout Deployment Phases
                https://www.truthinit.com/index.php/channel/1936/establishing-a-robust-ai-governance-framework-for-genai-throughout-deployment-phases/
              • 05/20/2026
                08:00 AM
                05/20/2026
                Establishing a Robust AI Governance Framework for GenAI Throughout Its Lifecycle
                https://www.truthinit.com/index.php/channel/1937/establishing-a-robust-ai-governance-framework-for-genai-throughout-its-lifecycle/
              • 05/20/2026
                10:00 PM
                05/20/2026
                Establishing a Robust AI Governance Framework for GenAI Throughout Its Lifecycle
                https://www.truthinit.com/index.php/channel/1953/establishing-a-robust-ai-governance-framework-for-genai-throughout-its-lifecycle/
              • 05/21/2026
                11:00 AM
                05/21/2026
                The Autonomous Era: Orchestrating a Resilient Enterprise
                https://www.truthinit.com/index.php/channel/1372/the-autonomous-era-orchestrating-a-resilient-enterprise/
              • 05/27/2026
                04:00 AM
                05/27/2026
                Rivoluziona i rischi dell'AI in opportunità con Netskope AI Security
                https://www.truthinit.com/index.php/channel/1925/rivoluziona-i-rischi-dellai-in-opportunità-con-netskope-ai-security/
              • 05/27/2026
                10:00 AM
                05/27/2026
                Harnessing AI: Transitioning from Illusion to Purposeful Mastery
                https://www.truthinit.com/index.php/channel/1924/harnessing-ai-transitioning-from-illusion-to-purposeful-mastery/
              • 05/28/2026
                01:00 PM
                05/28/2026
                Harnessing AI for Smaller Teams: Strategies for Secure Implementation
                https://www.truthinit.com/index.php/channel/1951/harnessing-ai-for-smaller-teams-strategies-for-secure-implementation/
              • 06/02/2026
                01:00 PM
                06/02/2026
                Spring of Satori: Delving into Recent Findings and the 2026 Threat Landscape
                https://www.truthinit.com/index.php/channel/1930/spring-of-satori-delving-into-recent-findings-and-the-2026-threat-landscape/
              • 06/04/2026
                02:00 AM
                06/04/2026
                Mastering the Unseen: Managing Shadow AI and Agentic MCP Traffic
                https://www.truthinit.com/index.php/channel/1948/mastering-the-unseen-managing-shadow-ai-and-agentic-mcp-traffic/
              • 06/16/2026
                07:00 AM
                06/16/2026
                Transforming Data Risk into Actionable Priorities: Essential Fixes First
                https://www.truthinit.com/index.php/channel/1952/transforming-data-risk-into-actionable-priorities-essential-fixes-first/

              Upcoming Events

              • May
                12

                Implementing Effective Strategies for Active Directory Security and Data Protection

                05/12/202611:30 PM ET
                • May
                  13

                  Transforming the Black Box: Reveal Hidden Threats and AI Risks through Data Lineage

                  05/13/202601:00 AM ET
                  • May
                    13

                    Transforming the Black Box: Revealing AI Risks and Hidden Threats through Data Lineage

                    05/13/202605:00 AM ET
                    • May
                      19

                      Establishing a Robust AI Governance Framework for GenAI Throughout Deployment Phases

                      05/19/202601:00 PM ET
                      • May
                        20

                        Establishing a Robust AI Governance Framework for GenAI Throughout Its Lifecycle

                        05/20/202608:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version