Skip to main content
📬 Get weekly Production AI insights Practical notes on Kubernetes, AI infrastructure and platform engineering. No spam. Subscribe free
Luca Berton at BitBash 2025 in Veenendaal, pointing at the Introducing Microsoft Quantum Computing for Developers slide behind him
Platform Engineering

BitBash 2025 Veenendaal: Quantum, IAM and Dev Box

BitBash 2025 at Info Support in Veenendaal: a Q# quantum session, Henry Been on IAM for engineering platforms, and Erwin Staal on Dev Box and ADE.

LB
Luca Berton
¡ 8 min read

On Saturday 25 January 2025 I spent the day at BitBash at Info Support in Veenendaal. It’s a community conference with a strong Microsoft flavour. One of the banners in the venue read “Active Microsoft community with passion for IT”, next to Info Support’s own “Make IT Awesome Sauce” wall. This edition also had a Ghostbusters theme.

Luca Berton taking a selfie in the Ghostbusters-themed lounge at BitBash 2025, with a Ray's Occult Books set and people in Ghostbusters costumes behind him

The lounge had a Ray’s Occult Books set, proton packs and Ghostbusters in full costume.

I followed three sessions: one on quantum programming, then two on the Azure side of platform engineering, identity and developer environments.

Quantum computing for developers, with Q#

The first session in my photos was an introduction to quantum computing for developers using Microsoft’s tooling. The speaker explained the CHSH game. Two players, here Casper and Vlad, each get a random bit (X and Y) and each answer with an output bit (A and B), without talking to each other. They win when X·Y = A ⊕ B. It’s a classic way to explain entanglement, because players who share entangled qubits can win more often than any classical strategy allows.

The CHSH game slide at BitBash 2025, showing random bits X and Y, output bits A and B, and the winning condition X¡Y = A XOR B

The CHSH game, with players Casper and Vlad.

Then came code. In VS Code, the speaker opened a fresh Q# project, a Main.qs file next to a qsharp.json manifest. The template comment said “This is a minimal Q# program that can be used to start writing Q# code”, above an empty operation Main() : Unit. Later the screen showed the cover of the Apress book Introducing Microsoft Quantum Computing for Developers: Using the Quantum Development Kit and Q# by Johnny Hooyberghs.

Luca Berton pointing at the Introducing Microsoft Quantum Computing for Developers book cover on screen at BitBash 2025

The book behind the session: the Quantum Development Kit and Q#.

Designing an IAM strategy for your engineering platform

Next was Henry Been, described on his title slide as an independent DevOps & Azure architect, trainer for ACG and Pluralsight, and book author. His talk was “Designing an IAM Strategy for your Engineering Platform”. It had three parts: the challenge, the requirements, and a solution built on Microsoft Entra ID with an Access Packages and PIM demo.

The challenge was a “traditional trade-off between two important requirements”. Engineers need access to do their work. At the same time, you have to prevent unauthorized access and stop phishing, mistakes and the misuse of compromised accounts. In many companies, the slide said, the actual situation is complex and can be incomplete. A complex structure of nested Entra ID groups for allocating authorizations has become the de facto standard, and changes to that structure are difficult.

Henry Been presenting the Challenge slide at BitBash 2025: engineers need access versus preventing unauthorized access, phishing and misuse of compromised accounts

The trade-off every platform team has to manage.

His requirements for a better design:

  • Engineers should have (or can easily acquire) the permissions they need to do their job.
  • Provable control of who has which permissions, and why.
  • Permissions are given out by the PO, not by some administrator or the team itself.
  • Compliant with ISO 27001, enforced through technology, with no additional process.
  • An understandable design that is extensible and can be implemented by any engineer in the team.
  • Usable for managing access to Microsoft Entra ID, Azure Cloud, Azure DevOps and more.

The solution used two Entra ID features. An access package is “a grouping of authorizations and everything around those authorizations to govern their usage”. It bundles resources (groups, applications and SharePoint sites) with request and approval rules. Privileged Identity Management separates active role assignments from eligible ones: an eligible assignment has to be activated before it becomes active, so privileged access is just-in-time.

The design then mapped team roles to access. A Product Owner owns the product, builds the backlog and has no technical access. Engineer NonProd can read code, open and approve pull requests, and read and write non-production environments. Engineer Prod can read production. A Stakeholder can read the backlog, dashboards and documentation. An Administrator can read and write in production, marked as a special case.

Design – Roles slide at BitBash 2025 listing Product Owner, Engineer NonProd, Engineer Prod, Stakeholder and Administrator with their permissions

Five roles, each with a one-line description of what it can do.

A later slide showed the “All Products – Administrator” package. It makes the user a member of three groups: one with an eligible Global Administrator role in Entra ID, one that is a member of Project Collection Administrators in Azure DevOps, and one with an Owner RBAC assignment on the Root Management Group in Azure. The results slide listed six outcomes: the business (PO) controls access and authorizations, access reviews are enforced, the solution is workable for engineers, authorizations are provably under control, the justification for every change is logged, and privilege escalation is always logged.

My take: making the Product Owner the approver is the key idea here. It moves access decisions to the person who knows why access is needed, and the platform team stops being a ticket queue for group memberships. The same principle works for Kubernetes namespaces and cloud accounts, not just Azure.

Azure Deployment Environments and Dev Box

The third session was Erwin Staal, Azure Architect according to his title slide, which also carried the Xebia logo and a Microsoft MVP badge. His talk was “Efficient and Secure Software Delivery with Azure Deployment Environments and DevBoxes”. The framing slide put Azure Deployment Environments and Microsoft Dev Box side by side on a shared Dev Center. A little later a slide said “Meet: Toma Toe Pizza”, with a cartoon pizza slice.

Erwin Staal presenting Azure Deployment Environments and Microsoft Dev Box on top of Dev Center at BitBash 2025

Dev Center components slide at BitBash 2025 showing catalogs, environment types, identities, projects, permissions and environment settings

Two products on one Dev Center, and the Dev Center building blocks.

The Dev Center components slide showed the hierarchy. A Dev Center holds catalogs, environment types and identities. Each project under it has its own permissions, environment settings, identities and catalogs. The live demo used a deployment-environments-demo repository with a custom Terraform runner image for ADE. Its Dockerfile was based on Microsoft’s deployment-environments/runners/core image and installed Terraform 1.7.4, and a deploy.sh script ran terraform plan and terraform apply. The comments in the script explained a detail of the integration: ADE expects the output types array, boolean, number, object and string, while Terraform outputs list, bool, number, map, set, string and null. So the script converts the Terraform output with jq and writes it to the file location ADE expects.

He also compared Azure Dev Box with GitHub Codespaces. Codespaces runs Linux, works with repos on GitHub, targets cloud-native apps and is managed from GitHub.com. Dev Box runs Windows, works with any version control system and any workload, and is managed through Endpoint Manager and Intune.

My take: ADE is a good fit for the “self-service environment” part of an internal developer platform, but the output-type mapping shows that some glue code is needed. That glue is what the platform team has to own and version.

Conversations at BitBash

Between sessions I recorded a few short interviews for my channel.

Marc Duiker (Diagrid): durable execution with Dapr

Marc Duiker is a developer advocate at Diagrid, which he described as a company founded by the co-creators of Dapr, the open-source distributed application runtime. He gave the first session of the day, “Failure is not an option”, on durable execution with Dapr: in effect a workflow engine, now built into Dapr, so you write workflows in C#, Java, Python or JavaScript and Dapr schedules them. He sees it as a tool for resilient, event-driven systems and long-running processes that heal themselves.

For the next few years he expects the focus to be on an easy start for developers, without a steep learning curve, and on making these systems easy for operations and platform teams to run at scale in production. His first step for newcomers: learn the ecosystem, go to meetups and conferences, and join the Dapr community calls, held every other week.

Daniel Paulus (The Factory): AI, quantum and Dutch digital identity

Daniel Paulus is Head of Azure Cloud Solutions at The Factory, which he said builds Azure and AWS solutions. He sees two revolutions happening at once, AI and quantum, and wonders how they will join together, though he admits he doesn’t know much about quantum yet. For AI, his worry is compute: it needs a lot of data centres.

His bigger projects include an Azure public cloud migration for the City of Amsterdam, with a lot of compliance work, and DigiD, the national system Dutch citizens use to log in to government services. He also explained eHerkenning, its business counterpart, with which a company authorises employees to deal with the government on its behalf, at assurance levels up to four. Will a digital signature ever count as much as wet ink? He thinks so, but it’s a long journey: selling a house still means a visit to the notary.

Geoffrey Loving (Info Support): recruiting with AI in the loop

Geoffrey Loving is a corporate recruiter at Info Support, the host, after about seven years recruiting in IT. The theme changes every year to keep the day fun: Star Wars last year, Ghostbusters this time, which he thought fits an industry that spends a lot of its time hunting bugs. He recruits medior and senior developers across a wide range, from data engineering to .NET, C# and Java. His view of AI was from his own desk. Five years ago he answered every question in the website chat himself, and now chatbots handle much of it. A poster that once took him a week of trying fonts now takes about an hour with Midjourney. He also sees more AI-written recruiter messages on LinkedIn, which he knows can annoy people.

And for the record: Titus Janssen of the Ghostbusters Dutch division, invited to BitBash as part of the haunted theme, assured me the venue was ghost-free by the time we spoke. His team had caught five, six or seven, depending on who you asked.

Closing

Towards the end of the day, two Ghostbusters in full costume stood next to the stage, with a crew member at the table and two LEGO boxes on it: the Haunted House and the Ghostbusters ECTO-1.

Two people in Ghostbusters costumes and a crew member at the stage table with LEGO Haunted House and Ghostbusters ECTO-1 boxes at BitBash 2025

The Ghostbusters theme ran all the way to the closing.

Free 30-min Production AI consultation

Book Now