Earlier quoted context omitted.
Not Windows laptops!
Not even kidding. They gave us a tour of their enterprise datacenter in Detroit and told us that cloud infrastructure was banned. At the time they had a plan to offer a complete in-house alternative to AWS. Meanwhile getting a single outbound port opened through their corporate firewall took several months.
1) There were ways around it via a secure proxy for outbound
2) If proxy was blocked because of your zone, you could escalate and get deviation. Just need the right security person to approve. I've definitely launched stuff in prod and it's like whoops didn't know that would be blocked or forgot to submit to be opened.
3) Maybe you encountered a power tripping "security architect"...gotta find ways to avoid those.
4) Unfortunately in non-IT corporate, you need to not just be able to be good at engineering but good at cutting red tape to keep your team moving. It's time consuming & frustrating.
5) The in-house alternative is PCF, which is phasing out for Azure. I thought PCF was a dumb idea to start.
6) Same red tape exists for Azure :(
I'd say it's worse for security. Maybe this has changed...left GM 6 months ago. I actively refused to migrate to Azure till they worked out the kinks. I'd have to have a frankenstein solution to satisfy their policy. I.e, app is in Azure but dependent web services are internal... Azure is considered external even though it's walled off for us...but it's external and we can't connect internal stuff to it.
We had actual products to deliver and didn't have time to be guinea pigs.