Skip to content

Add agentic-AI future readiness and scoped CRA supply-chain messaging#206

Open
brianamarie wants to merge 7 commits into
mainfrom
cra-supply-chain-messaging
Open

Add agentic-AI future readiness and scoped CRA supply-chain messaging#206
brianamarie wants to merge 7 commits into
mainfrom
cra-supply-chain-messaging

Conversation

@brianamarie

Copy link
Copy Markdown
Collaborator

Summary

  • CRA / supply chain (pillar + offering scope): Expand security-sovereignty-compliance.md with CRA due diligence, CVE noise, EU manufacturer use cases, and compliance-driven private-fork context. Add private-fork labor cost to cost-optimization.md where fork maintenance is the buyer problem. Extend Expert Support with CVE overload and triage-at-scale scenarios (Linux Foundation CRA readiness report).
  • Agentic AI (data-layer scope): Update future-readiness-ai.md with McKinsey April 2026 stats and governed-retrieval positioning; light alignment in PostgreSQL and PMM messaging. Scope boundary unchanged: database performance, security, and vector retrieval, not agent orchestration or LLM design.
  • Framework: No change to why-percona.md. Private-fork and CVE stewardship stay in pillars and offerings where the situation is specific, not at company-level positioning.

Why we're doing this

Enterprise buyers are moving from GenAI pilots toward agentic workflows, but scaling is stalling on data foundations, not models. McKinsey reports that most organizations experimenting with agents have not scaled them, with data limitations cited as the primary blocker. That reinforces Percona's existing future-readiness thesis: AI value depends on governed, portable database infrastructure teams already operate, not proprietary AI SKUs or parallel ungoverned data silos.

In parallel, EU Cyber Resilience Act pressure and rising CVE noise are pushing manufacturers toward active due diligence on open source dependencies, including databases. That work belongs in security, cost, and Expert Support messaging where the buyer situation is specific, not in top-level company positioning.

Primary impact

Future readiness positioning is the main audience for this change. The McKinsey-backed agentic AI context, governed-retrieval use case, and light PostgreSQL/PMM alignment give field and web teams current buyer language and proof points for why dependable database estates matter as autonomy increases.

CRA and CVE additions are secondary: they support compliance and supply-chain conversations in the security pillar and Expert Support offering without shifting core company framing in why-percona.md.

Made with Cursor

@github-actions

Copy link
Copy Markdown
Contributor

New File Governance Check

No added markdown files detected.

Doc Coverage Check

No new markdown docs detected.

Manual waiver commands (maintainers)

  • /governance-ok all or /governance-all
  • /governance-ok new-file, /governance-ok doc-coverage
  • /governance-reset all or /governance-reset with the same token

Waiver JSON is stored in a hidden PR comment (messaging-governance-waiver-data:v1), same pattern as Impact Check.


Triggered by pull_request. Workflow content-governance-checks.yml. Docs: AUTOMATION.md, automation/README.md.

@github-actions

Copy link
Copy Markdown
Contributor

Messaging Smart Suggestions

File Why impacted Claim Confidence
use-cases-value-pillars/cost-optimization.md PostgreSQL cost/TCO claims usually impact shared value proof messaging. cost 0.65
framework/core-positioning.md PostgreSQL cost/TCO claims usually impact shared value proof messaging. cost 0.95
products/postgresql/messaging.md PostgreSQL cost/TCO claims usually impact shared value proof messaging. cost 0.65
reference/canonical-naming.md License and open source positioning changes are cross-cutting. cost 0.95
reference/banned-terms.md License and open source positioning changes are cross-cutting. cost 0.95
framework/core-positioning.md License and open source positioning changes are cross-cutting. cost 0.95
framework/why-percona.md License and open source positioning changes are cross-cutting. cost 0.95
offerings/expert-support/messaging.md License and open source positioning changes are cross-cutting. cost 0.65
offerings/expertops/messaging.md License and open source positioning changes are cross-cutting. cost 0.95
offerings/expert-consulting/messaging.md License and open source positioning changes are cross-cutting. cost 0.95
offerings/expert-support/messaging.md Offering naming updates should stay aligned across offering pages. cost 0.65
offerings/expertops/messaging.md Offering naming updates should stay aligned across offering pages. cost 0.95
offerings/expert-consulting/messaging.md Offering naming updates should stay aligned across offering pages. cost 0.95
reference/canonical-naming.md Offering naming updates should stay aligned across offering pages. cost 0.95
framework/core-positioning.md Offering naming updates should stay aligned across offering pages. cost 0.95
framework/core-positioning.md Product messaging modules often need checks against company framing and shared pillars or offerings. cost 0.95
framework/why-percona.md Product messaging modules often need checks against company framing and shared pillars or offerings. cost 0.95

Only auto-apply suggestions at high confidence with reviewer approval.


Triggered by pull_request. Workflow smart-suggestions.yml. Docs: AUTOMATION.md, automation/README.md.

@github-actions

github-actions Bot commented Jun 22, 2026

Copy link
Copy Markdown
Contributor

Messaging Impact Check

  • Changed files: 8

postgres-cost-claim (BLOCKING)

PostgreSQL cost/TCO claims usually impact shared value proof messaging.

Required review files:

  • use-cases-value-pillars/cost-optimization.md
  • framework/core-positioning.md
  • products/postgresql/messaging.md

Suggested additional scan:

  • use-cases-value-pillars/*.md

licensing-or-open-source-claims (BLOCKING)

License and open source positioning changes are cross-cutting.

Required review files:

  • reference/canonical-naming.md
  • reference/banned-terms.md
  • framework/core-positioning.md
  • framework/why-percona.md
  • offerings/expert-support/messaging.md
  • offerings/expertops/messaging.md
  • offerings/expert-consulting/messaging.md

Suggested additional scan:

  • use-cases-value-pillars/*.md
  • products/**/messaging.md

offering-name-or-tier-change (WARN)

Offering naming updates should stay aligned across offering pages.

Required review files:

  • offerings/expert-support/messaging.md
  • offerings/expertops/messaging.md
  • offerings/expert-consulting/messaging.md
  • reference/canonical-naming.md
  • framework/core-positioning.md

Suggested additional scan:

  • products/**/messaging.md
  • use-cases-value-pillars/*.md

product-messaging-module-touch (WARN)

Product messaging modules often need checks against company framing and shared pillars or offerings.

Required review files:

  • framework/core-positioning.md
  • framework/why-percona.md

Suggested additional scan:

  • use-cases-value-pillars/*.md
  • offerings/*.md

Manual waiver commands (maintainers):

  • /impact-ok all (optional same-line note after all is ignored)
  • /impact-all (same as /impact-ok all)
  • /impact-ok <exact missing path>
  • /impact-reset all
  • /impact-reset <exact missing path>

Waiver state is stored in <!-- messaging-impact-waiver-data:v1 -->.


Triggered by pull_request. Workflow impact-check.yml. Docs: AUTOMATION.md, automation/README.md.

Comment thread offerings/expert-support/messaging.md Outdated
- **Extended Lifecycle Support (ELS):** When database versions reach End of Life (EOL), Percona experts help teams plan upgrades, align CVE backports to their risk window, and move to supported releases. Expert Support covers Extended Lifecycle Support (ELS) for MySQL and MongoDB, grounded in published release and lifecycle policy.
- **Kubernetes operator planning:** Architecture and cutover plan review for databases on Kubernetes (topology, storage, backups, PMM integration); the customer platform team executes install and Day-2 runbooks, with expert validation at key gates.
- **Operator production escalations:** SLA-backed incident response and advisory troubleshooting for failover, backup and recovery, replication, and upgrade failures on customer-run operator clusters.
- **CVE triage at scale:** Automated scanning and broader project indexing have increased published CVE volume across open source ecosystems ([Linux Foundation 2026 CRA Awareness and Readiness Report](https://www.linuxfoundation.org/research/cra-readiness-2026)). Percona experts help customers prioritize database-layer findings against exploitability and their supported release line, align fixes to published CVE advisories and backport policy, and avoid panic patching or unnecessary downtime when noise exceeds real risk.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@andrey-glazkov is this section all right to add for support and a high CVE scenario?

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I like that we narrow the scope to the databases here!

@janwieremjewicz janwieremjewicz left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To me this reads bad. Hard to understand and not sure what it says at many times. I spent a lot of time reading this and often failed to make sense of it. Too often did I feel as if reading legalese.

Comment thread offerings/expert-support/messaging.md Outdated

- **Who Expert Support is for:** Teams with capable DBAs or SREs who manage their own databases but want reliable expert escalation for production issues, architectural questions, and review of planned changes.
- **Problems Expert Support solves:** Outages and other urgent incidents, replication or high availability failures, performance regressions, uncertain upgrade or migration plans, lifecycle and EOL transition risk, and hard architectural questions.
- **Problems Expert Support solves:** Outages and other urgent incidents, replication or high availability failures, performance regressions, uncertain upgrade or migration plans, lifecycle and EOL transition risk, CVE overload when scanning volume outpaces internal triage capacity, and hard architectural questions.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not 100% sold on the fact that improvements we introduce with CVEs for databases is enough to justify this change. scanner noise is still going to be an issue.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would simplify this to: "CVE volume that outpaces internal triage capacity"

Comment thread offerings/expert-support/messaging.md Outdated
- **Extended Lifecycle Support (ELS):** When database versions reach End of Life (EOL), Percona experts help teams plan upgrades, align CVE backports to their risk window, and move to supported releases. Expert Support covers Extended Lifecycle Support (ELS) for MySQL and MongoDB, grounded in published release and lifecycle policy.
- **Kubernetes operator planning:** Architecture and cutover plan review for databases on Kubernetes (topology, storage, backups, PMM integration); the customer platform team executes install and Day-2 runbooks, with expert validation at key gates.
- **Operator production escalations:** SLA-backed incident response and advisory troubleshooting for failover, backup and recovery, replication, and upgrade failures on customer-run operator clusters.
- **CVE triage at scale:** Automated scanning and broader project indexing have increased published CVE volume across open source ecosystems ([Linux Foundation 2026 CRA Awareness and Readiness Report](https://www.linuxfoundation.org/research/cra-readiness-2026)). Percona experts help customers prioritize database-layer findings against exploitability and their supported release line, align fixes to published CVE advisories and backport policy, and avoid panic patching or unnecessary downtime when noise exceeds real risk.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I like that we narrow the scope to the databases here!

Comment thread products/postgresql/messaging.md Outdated
- Cloud-native operations: The Percona Operator for PostgreSQL automates deployment, scaling, and failover in Kubernetes environments, delivering consistent governance and portability across any cloud.
- Platform portability: Percona Distribution for PostgreSQL ships packages for current Ubuntu LTS releases, including Ubuntu 26.04 on AMD64 and ARM64, so teams can standardize database deployments on their long-term support platform images without retooling the stack.
- AI and analytics readiness: Teams run embeddings and vector search on PostgreSQL using pgvector packaged with other tested distribution components ([third-party components](https://docs.percona.com/postgresql/18/third-party.html)), avoiding a separate AI-only datastore for many workloads. Percona Expert Support includes advisory guidance for pgvector and pgvectorscale production tuning; pgvectorscale is not packaged in Percona Distribution for PostgreSQL.
- AI and analytics readiness: Teams run embeddings and vector search on PostgreSQL using pgvector packaged with other tested distribution components ([third-party components](https://docs.percona.com/postgresql/18/third-party.html)), avoiding a separate AI-only datastore for many RAG and agent retrieval workflows. Percona Expert Support includes advisory guidance for pgvector and pgvectorscale production tuning; pgvectorscale is not packaged in Percona Distribution for PostgreSQL.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't understand why "other tested distribution components" not simply "other components" or "other distribution components".

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TBH reading the whole sentence I would simplify:

thanks to extensions like pgvector teams successfully run AI workloads on PostgreSQL instead of having to learn, deploy and manage a separate AI-only datastore for RAG and agent retrieval workflows.

feels (to me at least) more natural, human written, not AI and robotic...

- **AI and analytics affect business competitiveness:** Real-time and AI-driven workloads demand unified data access, but fragmented systems slow response and inflate both latency and cost per transaction.
- **Downstream costs:** Cloud bills, tool licensing, and staff hours add up on one side; downtime, security gaps, and lost productivity on the other. The average data breach now costs $4.88M ([IBM](https://www.ibm.com/think/insights/cost-of-a-data-breach-2024-financial-industry)), with outage costs in the automotive industry exceeding $2.3M per hour ([Siemens, 2024](https://web.archive.org/web/20260208082933/https://blog.siemens.com/2024/07/the-true-cost-of-an-hours-downtime-an-industry-analysis/)).
- **AI and analytics affect business competitiveness:** Real-time and AI-driven workloads demand unified data access, but fragmented systems slow response and inflate both latency and cost per transaction.
- **Private fork maintenance tax:** Teams that fork open source database components to control patches internally carry recurring integration and merge labor every release cycle. Industry research estimates roughly $258,000 in labor per release cycle for organizations maintaining private open source forks at scale ([Linux Foundation 2026 CRA Awareness and Readiness Report](https://www.linuxfoundation.org/research/cra-readiness-2026)), a hidden people cost that often exceeds license savings.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This finding I believe should be more visible. VERY good framing!

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What about combining this with sustainable founding of open source?

- **Inefficient resource consumption:** Proprietary DBaaS tiers often enforce sizing floors and support bundles that lead to consistent under-utilization and higher long-term spend. At the same time, efforts to reduce cost by scaling down too aggressively can cause underprovisioning, resulting in degraded performance or unexpected downtime.
- **AI and analytics affect business competitiveness:** Real-time and AI-driven workloads demand unified data access, but fragmented systems slow response and inflate both latency and cost per transaction.
- **Downstream costs:** Cloud bills, tool licensing, and staff hours add up on one side; downtime, security gaps, and lost productivity on the other. The average data breach now costs $4.88M ([IBM](https://www.ibm.com/think/insights/cost-of-a-data-breach-2024-financial-industry)), with outage costs in the automotive industry exceeding $2.3M per hour ([Siemens, 2024](https://web.archive.org/web/20260208082933/https://blog.siemens.com/2024/07/the-true-cost-of-an-hours-downtime-an-industry-analysis/)).
- **AI and analytics affect business competitiveness:** Real-time and AI-driven workloads demand unified data access, but fragmented systems slow response and inflate both latency and cost per transaction.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Too short and lacking in essence:

  1. Link to some example, case studies, success stories?
  2. What do we offer to help?
    I am afraid that the fragmented data is something beyond of reach of our services. Do we have any offering regarding consulting on data architecture level across the company for such AI and analytical use cases? I am afraid I am missing the point and value of this :/


- **RAG on PostgreSQL:** Store embeddings alongside relational data for retrieval workflows without a separate vector database contract. Percona packages pgvector in documented PostgreSQL builds; Percona Expert Support includes advisory guidance for pgvector production tuning. Percona focuses on PostgreSQL performance, scalability, and security for vector workloads, not embedding-model or LLM application design.
- **Vector search on Valkey:** Serve low-latency similarity search for AI retrieval tiers on the same operational model as other supported engines. Percona Expert Support and PMM cover Valkey and Redis alongside PostgreSQL and other engines in customer-controlled deployments.
- **Governed retrieval for agent workflows:** Agent pipelines that combine embeddings, relational context, and operational state need governed, low-latency retrieval on infrastructure the customer controls. Percona packages pgvector for PostgreSQL, supports vector search on Valkey, and provides PMM observability plus audit-capable distributions for mixed-engine estates. Percona focuses on database performance, security, and vector retrieval for these workloads, not agent orchestration or LLM application design.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

the opening with governed retrieval does not match what follows as the description of the value. There is exactly zero information about governance or inspection (auditing) of such governance rules enforcement.

- **Fragmented control policies:** Security enforcement differs across platforms: one engine's encryption standard or retention policy rarely matches another's, creating audit gaps and inconsistent governance. One survey flagged legal and geopolitical dependencies (46%) and cybersecurity incidents (42%) as key drivers for IT sovereignty initiatives ([HMS](https://www.analytical-software.de/en/it-sovereignty-in-practice/)).
- **Unverified supply chains:** Only about 20% of organizations generate software bills of materials (SBOMs), leaving most without full traceability into the software they depend on ([arXiv, 2025](https://arxiv.org/pdf/2503.15021)).
- **Unverified supply chains:** Only about 20% of organizations generate software bills of materials (SBOMs), leaving most without full traceability into the software they depend on ([arXiv, 2025](https://arxiv.org/pdf/2503.15021)). Under the EU Cyber Resilience Act, manufacturers placing products on the EU market must exercise active due diligence on third-party and open source components, yet many still passively wait for upstream fixes or maintain private forks that complicate audit trails.
- **CVE noise and triage overload:** Published CVE volume across major open source projects rose sharply in early 2026, driven in part by broader automated scanning and AI-assisted analysis ([Linux Foundation 2026 CRA Awareness and Readiness Report](https://www.linuxfoundation.org/research/cra-readiness-2026)). Manufacturers face more findings to evaluate, not necessarily more exploitable risk, which makes credible prioritization and documented remediation paths more valuable than reactive panic patching.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is true. But databases are but one source of these CVEs. We would need to prove that a big chunk of this noise is coming from databases or that the noise from other sources hides the potential real threats that come rarely but may be missed in the databases and point to this as a value. Otherwise that's not something that reads as an understandable value to me.

- **Lock-in through tooling:** Vendor-specific APIs and managed encryption layers limit portability and make it costly to adapt to new regulatory or business needs. Many firms cite vendor dependency and lack of portability as strategic risks. Adopters of sovereign or independent infrastructure cite freedom from vendor lock-in and stronger strategic control as key benefits ([PureStorage](https://www.purestorage.com/company/newsroom/press-releases/data-sovereignty-emerges-as-critical-business-risk-in-new-geopolitical-era-in.html)).
- **Fragmented control policies:** Security enforcement differs across platforms: one engine's encryption standard or retention policy rarely matches another's, creating audit gaps and inconsistent governance. One survey flagged legal and geopolitical dependencies (46%) and cybersecurity incidents (42%) as key drivers for IT sovereignty initiatives ([HMS](https://www.analytical-software.de/en/it-sovereignty-in-practice/)).
- **Unverified supply chains:** Only about 20% of organizations generate software bills of materials (SBOMs), leaving most without full traceability into the software they depend on ([arXiv, 2025](https://arxiv.org/pdf/2503.15021)).
- **Unverified supply chains:** Only about 20% of organizations generate software bills of materials (SBOMs), leaving most without full traceability into the software they depend on ([arXiv, 2025](https://arxiv.org/pdf/2503.15021)). Under the EU Cyber Resilience Act, manufacturers placing products on the EU market must exercise active due diligence on third-party and open source components, yet many still passively wait for upstream fixes or maintain private forks that complicate audit trails.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Shouldn't we then mention that we do provide SBOMs then?

- **US extraterritorial access risk:** Teams that cannot rely on US hyperscaler control planes need hosting they choose, including non-US infrastructure, because US law can compel technology companies to hand over stored data regardless of server location. Percona does not host customer data; customers run the stack on infrastructure that matches their jurisdictional requirements.
- **Multi-tenant platform isolation:** Shared platforms must separate tenants or business units without control-policy drift. Percona Operators support Kubernetes namespaces, network policies, and RBAC so isolation stays consistent across MySQL, PostgreSQL, and MongoDB-compatible workloads.
- **EU software supply chain compliance:** Teams shipping products with digital elements into the EU must determine whether they are manufacturers under the Cyber Resilience Act and exercise due diligence on open source dependencies, including databases. Private forks add audit burden and recurring integration labor; passive reliance on upstream security fixes does not meet active vulnerability-management expectations. Percona develops and sustains supported database software with public CVE handling and documented lifecycles. Customers remain responsible for their product as manufacturer; Percona helps on the database tier with inspectable software, PMM security findings, and Expert Support for prioritized remediation. Percona does not certify full product CRA compliance.
- **Compliance-driven private forks:** Some teams maintain private forks of database components as a short-term compliance workaround. Industry research estimates roughly $258,000 in labor per release cycle to maintain private open source forks at scale ([Linux Foundation 2026 CRA Awareness and Readiness Report](https://www.linuxfoundation.org/research/cra-readiness-2026)). Supported engagement with sustained upstream distributions reduces divergent codebase debt and strengthens the supply chain evidence manufacturers need.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Carrying own patches is costly and raises the risk of delayed CVE fixes coming from minor upstream releases is what I read. But the way it's written is not clear enough to me. Value is hidden :/

Sovereignty is not only where data sits. It is who can operate your databases and whether you can keep running under supplier or jurisdictional change. Percona delivers software, Expert Support, and Expert Consulting and Services that help teams exercise **data**, **operational**, and **technological** sovereignty across MySQL, MariaDB (Community), PostgreSQL, MongoDB-compatible, Valkey, and Redis. The primary risk is **concentration and continuity risk**: single-provider dependency when teams cannot prove residency, access control, or exit paths.

Across industries, governance, compliance, and hardening requirements are expanding, from GDPR, HIPAA, and PCI-DSS to DISA's STIG guidelines used in public-sector and defense environments. At the same time, hyperscaler ecosystems make it difficult for enterprises to verify what "secure" really means inside managed services. [UNCTAD's overview of data protection and privacy legislation worldwide](https://unctad.org/page/data-protection-and-privacy-legislation-worldwide) documents how many jurisdictions have adopted formal regimes, which enterprises increasingly pair with sovereign-cloud or regional-control strategies. National frameworks beyond Europe, including India's DPDP Act and Brazil's LGPD, add distinct residency and access rules ([Forcepoint global data protection laws, 2026](https://www.forcepoint.com/blog/insights/tracking-global-data-protection-laws-2026)). A majority of organizations prioritize data sovereignty in infrastructure decisions, with strong regional weight in Europe, Middle East, and APAC ([Thales Global Data Threat Report](https://cpl.thalesgroup.com/data-threat-report)).
Across industries, governance, compliance, and hardening requirements are expanding, from GDPR, HIPAA, and PCI-DSS to the EU Cyber Resilience Act (CRA) for products with digital elements sold in Europe, and DISA's STIG guidelines used in public-sector and defense environments. At the same time, hyperscaler ecosystems make it difficult for enterprises to verify what "secure" really means inside managed services. [UNCTAD's overview of data protection and privacy legislation worldwide](https://unctad.org/page/data-protection-and-privacy-legislation-worldwide) documents how many jurisdictions have adopted formal regimes, which enterprises increasingly pair with sovereign-cloud or regional-control strategies. National frameworks beyond Europe, including India's DPDP Act and Brazil's LGPD, add distinct residency and access rules ([Forcepoint global data protection laws, 2026](https://www.forcepoint.com/blog/insights/tracking-global-data-protection-laws-2026)). A majority of organizations prioritize data sovereignty in infrastructure decisions, with strong regional weight in Europe, Middle East, and APAC ([Thales Global Data Threat Report](https://cpl.thalesgroup.com/data-threat-report)).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Read this 3 times. I see a problem and a trend but not the point. Not sure how this bullet fits. Is this to describe the reality? I feel what we want to say is that there is a growing trend to adopt hybrid or on-prem solutions and we can help there, but it's missing here.

Comment thread offerings/expert-support/messaging.md Outdated
- **Extended Lifecycle Support (ELS):** When database versions reach End of Life (EOL), Percona experts help teams plan upgrades, align CVE backports to their risk window, and move to supported releases. Expert Support covers Extended Lifecycle Support (ELS) for MySQL and MongoDB, grounded in published release and lifecycle policy.
- **Kubernetes operator planning:** Architecture and cutover plan review for databases on Kubernetes (topology, storage, backups, PMM integration); the customer platform team executes install and Day-2 runbooks, with expert validation at key gates.
- **Operator production escalations:** SLA-backed incident response and advisory troubleshooting for failover, backup and recovery, replication, and upgrade failures on customer-run operator clusters.
- **CVE triage at scale:** Automated scanning and broader project indexing have increased published CVE volume across open source ecosystems ([Linux Foundation 2026 CRA Awareness and Readiness Report](https://www.linuxfoundation.org/research/cra-readiness-2026)). Percona experts help customers prioritize database-layer findings against exploitability and their supported release line, align fixes to published CVE advisories and backport policy, and avoid panic patching or unnecessary downtime when noise exceeds real risk.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

"avoid panic patching or unnecessary downtime when noise exceeds real risk."

The "noise exceeds real risk" reads a bit overly AI-generated to me.

I think the sentence reads the same if this is dropped.

- **Multi-database vendor consolidation:** One relationship for database support across engines reduces duplicate fees, conflicting SLAs, and slow handoffs when incidents cross systems. Percona consolidates agreements for Expert Support, ExpertOps, and consulting across MySQL, MariaDB (Community), PostgreSQL, MongoDB-compatible environments, Valkey, and Redis so teams coordinate renewal, escalation, and scope in one place.
- **Reduce cloud spend:** Customers ask how to reduce cloud spend when DBaaS minimum tiers, bundled markup, and sizing floors outpace actual use. Managed database services can cost several times more than comparable workloads on VMs or Kubernetes. Percona Experts use PMM, Operators, and rightsizing on customer-chosen infrastructure to align capacity with utilization and lower managed-service premiums.
- **Database workload tuning and rightsizing:** Neglected databases accumulate poor indexing, inefficient queries, and oversized instances, especially when generalist cloud or DevOps teams operate DBaaS without deep database expertise. Percona Experts tune workloads and rightsize instances so teams save on infrastructure whether they stay on DBaaS or run self-managed stacks. Performance gains often let teams scale down instance sizes without sacrificing service levels.
- **Private fork labor vs supported upstream:** Maintaining private forks of database components to control security patches internally consumes engineering hours every release cycle that do not scale with product growth. Supported Percona distributions, public CVE advisories, and Expert Support for backport alignment offer a lower long-term labor path than sustaining divergent codebases, especially as software supply chain regulations raise documentation and due diligence expectations.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maintaining private forks of database components to control security patches internally consumes engineering hours every release cycle that do not scale with product growth.

"do not scale with product growth" does not make a ton of sense in this context. I'd go with something like "...engineering hours every release cycle that compound as upstream divergence widens".

@brianamarie brianamarie added Content & messaging Canonical copy, products, use cases, case studies, and narrative. Needs: product or GTM Product, marketing, or GTM should confirm scope, naming, or positioning. Area: Cross-product Legal, governance, CODEOWNERS, or work spanning multiple product paths. labels Jun 30, 2026
brianamarie and others added 2 commits June 30, 2026 13:27
Extend future-readiness positioning with McKinsey-backed agentic AI
context and governed-retrieval use cases, with light PostgreSQL and PMM
alignment. Add CRA, CVE triage, and private-fork copy in security, cost,
and Expert Support pillars where buyer situations are specific, without
changing company-level why-percona framing.

Co-authored-by: Cursor <cursoragent@cursor.com>
Keep EU Cyber Resilience Act messaging in problem bullets and use
cases rather than the opening regulatory list on the SSC page.

Co-authored-by: Cursor <cursoragent@cursor.com>
@brianamarie
brianamarie force-pushed the cra-supply-chain-messaging branch from 6af294f to 8e08e93 Compare June 30, 2026 11:27
@brianamarie

Copy link
Copy Markdown
Collaborator Author

Hey all, thank you for the feedback. I've pushed a few commits to update the PR to match it:

  • I shortened several of the agentic and future-readiness paragraphs and kept the McKinsey reference as background. The copy now focuses on what shows up at the database layer, like retrieval latency and inconsistent access or audit controls across engines, rather than enterprise-wide data governance.
  • I renamed the agent use case to “Retrieval for agent workflows on databases you already run” and simplified the PostgreSQL AI line and the Expert Support CVE wording. I also removed some of the repeated CRA and private-fork language so those themes aren’t spread across multiple sections.
  • CRA and CVE messaging is still in the security pillar and Expert Support, but it stays limited to database advisories, lifecycles, and triage. The private fork cost point is a single use case at the bottom of the cost pillar, (not in both security + cost,) because it’s uncommon and I didn’t want it to read like a mainstream buyer problem.
  • I added the new McKinsey link to the lychee exclusions file so CI should stop timing out on it. I kept the private fork cost point as a single uncommon use case at the bottom of the cost pillar rather than repeating it in security.

If a particular sentence still reads badly, point me at it and I’ll fix the wording. (Reminder that downstream assets are not written verbatim from messaging, and typically use the organization level plugins available through Claude.) Thank you again!

brianamarie and others added 4 commits July 1, 2026 14:36
Tighten future-readiness copy to the database layer, rename the agent
retrieval use case, and simplify Expert Support CVE and PostgreSQL AI
wording. Deduplicate CRA and private-fork themes across pillars; keep
fork cost as a single uncommon manufacturer use case. Add McKinsey
agentic URL to lychee CI exclusions.

Co-authored-by: Cursor <cursoragent@cursor.com>
Drop redundant CRA certification line from EU supply chain use case.

Co-authored-by: Cursor <cursoragent@cursor.com>
@github-actions

github-actions Bot commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

Markdown hygiene auto-fix

Applied safe markdown hygiene fixes and pushed one bot commit to this PR branch.

Fixed files:

  • use-cases-value-pillars/security-sovereignty-compliance.md

Triggered by pull_request. Workflow markdown-hygiene-autofix.yml. Docs: AUTOMATION.md, automation/README.md.

@thefactremains thefactremains left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment only. The MySQL-relevant content checks out.

Not approving yet on mechanical state: the branch is CONFLICTING and CI is red, with Links (lychee) and impact-check both failing. Ask: rebase on main to clear the conflict and get both checks green, then I will approve.

@brianamarie
brianamarie removed the request for review from tichomir July 7, 2026 10:58
@brianamarie
brianamarie requested review from theTibi and removed request for Cinneely, DavePoole30, ImTheKai and obiyduhata July 7, 2026 10:58
- Cloud-native operations: The Percona Operator for PostgreSQL automates deployment, scaling, and failover in Kubernetes environments, delivering consistent governance and portability across any cloud.
- Platform portability: Percona Distribution for PostgreSQL ships packages for current Ubuntu LTS releases, including Ubuntu 26.04 on AMD64 and ARM64, so teams can standardize database deployments on their long-term support platform images without retooling the stack.
- AI and analytics readiness: Teams run embeddings and vector search on PostgreSQL using pgvector packaged with other tested distribution components ([third-party components](https://docs.percona.com/postgresql/18/third-party.html)), avoiding a separate AI-only datastore for many workloads. Percona Expert Support includes advisory guidance for pgvector and pgvectorscale production tuning; pgvectorscale is not packaged in Percona Distribution for PostgreSQL.
- AI and analytics readiness: With pgvector and other distribution components (see [third-party components](https://docs.percona.com/postgresql/18/third-party.html)), teams run RAG and agent retrieval on PostgreSQL they already operate instead of standing up a separate AI-only datastore. Percona Expert Support includes advisory guidance for pgvector and pgvectorscale production tuning; pgvectorscale is not packaged in Percona Distribution for PostgreSQL.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Just inputting for readability.

Suggested change
- AI and analytics readiness: With pgvector and other distribution components (see [third-party components](https://docs.percona.com/postgresql/18/third-party.html)), teams run RAG and agent retrieval on PostgreSQL they already operate instead of standing up a separate AI-only datastore. Percona Expert Support includes advisory guidance for pgvector and pgvectorscale production tuning; pgvectorscale is not packaged in Percona Distribution for PostgreSQL.
- AI and analytics readiness: pgvector is packaged and tested as part of the distribution's third-party components, so teams can run embeddings and vector search for RAG and agent retrieval directly on PostgreSQL, no separate AI-only datastore required. Percona Expert Support advises on tuning pgvector and pgvectorscale for production; pgvectorscale itself isn't packaged in the distribution.

@brianamarie brianamarie added the Roadmap: soon High confidence next; right after or alongside launch prep. label Jul 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Area: Cross-product Legal, governance, CODEOWNERS, or work spanning multiple product paths. Content & messaging Canonical copy, products, use cases, case studies, and narrative. Needs: product or GTM Product, marketing, or GTM should confirm scope, naming, or positioning. Roadmap: soon High confidence next; right after or alongside launch prep.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants