#office-hours (2021-12)
“Office Hours” are every Wednesday at 11:30 PST via Zoom. It’s open to everyone. Ask questions related to DevOps & Cloud and get answers! https://cloudposse.com/office-hours
Public “Office Hours” are held every Wednesday at 11:30 PST via Zoom. It’s open to everyone. Ask questions related to DevOps & Cloud and get answers!
https://cpco.io/slack-office-hours
Meeting password: sweetops
2021-12-01
I wanna open a discussion regarding tagging/labeling conventions that are used company wide. And what tags do you guys use ?
Something that is a superset to what terraform-null-label
is.
Tags will be used in AWS & Kubernetes for various usecases.
- Resource Identification
- Cost and Billing
- Metadata -> Like Terraform Module that created this resource and the module git hash, etc
- Adding Human Metadata ( Human Labels like Ambassadors’ human annotations )
- Alerting ( based on some tags, alerts severity is determined)
- Adding functionalities ( ex: adding Lifecycle policies based on tags )
- ABAC IAM use cases. My initial set of labels follows Kubernetes’ labeling convention ‘prefix/key = value’ this way it is compatiablie in both AWS && Kubernetes.
Let’s say our company is [acme.io](http://acme.io)
what are the sets of tags you will use ?
Annotating Kubernetes Services for humans Have you ever been asked to troubleshoot a failing Kubernetes service and struggled to find basic informati…
Annotating Kubernetes Services for humans Have you ever been asked to troubleshoot a failing Kubernetes service and struggled to find basic informati…
Terraform Module to define a consistent naming convention by (namespace, stage, name, [attributes]) - GitHub - cloudposse/terraform-null-label: Terraform Module to define a consistent naming conven…
I do like the domain namespaces ala k8s
@Erik Osterman (Cloud Posse) Actually I forked The null-label module internally to add them
@here office hours is starting in 30 minutes! Remember to post your questions here.
Mauricio Wyler has joined Public “Office Hours”
Bye bye Dockerhub hassles ? https://aws.amazon.com/blogs/aws/announcing-pull-through-cache-repositories-for-amazon-elastic-container-registry/
Organizations, development teams, and individual developers who have chosen to use containers to host their applications may prefer, or perhaps are required, to source all images from Amazon Elastic Container Registry to take advantage of its high availability and security. To satisfy those requirements, customers have needed to take on the burden of manually pulling […]
Muzammil Aijaz has joined Public “Office Hours”
Muzammil Aijaz has joined Public “Office Hours”
Tony Scott has joined Public “Office Hours”
Erik Osterman (Cloud Posse) has joined Public “Office Hours”
Yusuf has joined Public “Office Hours”
Mohammed Almusaddar has joined Public “Office Hours”
Andrew Way has joined Public “Office Hours”
Eric Berg has joined Public “Office Hours”
Max Lobur has joined Public “Office Hours”
Andy Miguel (Cloud Posse) has joined Public “Office Hours”
Eric Berg has joined Public “Office Hours”
Benjamin Smith has joined Public “Office Hours”
Matt Andreo has joined Public “Office Hours”
Matt Calhoun has joined Public “Office Hours”
James Haughey has joined Public “Office Hours”
Guilherme Borges has joined Public “Office Hours”
Justin Davis has joined Public “Office Hours”
Tim Gourley has joined Public “Office Hours”
Mike Martin has joined Public “Office Hours”
Mike Marseglia has joined Public “Office Hours”
Mauricio Wyler has joined Public “Office Hours”
Loren Gordon has joined Public “Office Hours”
Sherif Abdel-Naby has joined Public “Office Hours”
links from today’s session:
• https://aws.amazon.com/about-aws/whats-new/2021/11/aws-proton-terraform-infrastructure/
• https://aws.amazon.com/about-aws/whats-new/2021/11/aws-proton-git-infrastructure-code-templates/
• https://github.com/hashicorp/terraform-provider-aws/issues/21951
• https://aws.amazon.com/about-aws/whats-new/2021/11/amazon-emr-serverless-preview/
• https://aws.amazon.com/about-aws/whats-new/2021/11/amazon-msk-serverless-public-preview/
• https://aws.amazon.com/about-aws/whats-new/2021/11/aws-control-tower-terraform/
• https://github.com/aws-ia/terraform-aws-control_tower_account_factory
• https://aws.amazon.com/about-aws/whats-new/2021/11/aws-karpenter-v0-5/
• https://aws.amazon.com/about-aws/whats-new/2021/11/aws-waf-captcha-support/
Patrick Joyce has joined Public “Office Hours”
Mike Martin has joined Public “Office Hours”
Isa Aguilar has joined Public “Office Hours”
Vlad Ionescu has joined Public “Office Hours”
Sorry all system hard crashed
I will rejoin in a few minutes
Hao Wang has joined Public “Office Hours”
No worries, we know how it is!
Erik Osterman (Cloud Posse) has joined Public “Office Hours”
Matt Andreo has joined Public “Office Hours”
Link for the ECR Public Gallery (mirrored official Docker images): https://gallery.ecr.aws/docker
Amazon ECR Public Gallery is a website that allows anyone to browse and search for public container images, view developer-provided details, and see pull commands
Gabriel B has joined Public “Office Hours”
Mike Marseglia has joined Public “Office Hours”
Control Tower blocking regions thing: https://aws.amazon.com/about-aws/whats-new/2021/11/deny-services-operations-aws-regions-control-tower/
Yusuf has joined Public “Office Hours”
Vicken Simonian has joined Public “Office Hours”
Udit Dave has joined Public “Office Hours”
Related: Related: https://www.duckbillgroup.com/blog/aws-cost-allocation-guide-tagging-best-practices/
Looking for AWS tags you can implement immediately? We’ve got you covered.
Florain Drescher has joined Public “Office Hours”
Michael Jenkins has joined Public “Office Hours”
hello all! just reaching out to see if there is an Office Hours or similar recording on the AWS CIS Benchmark.. i see you guys have a super repo but just looking for some context on it TIA
this is a year old, though
2021-12-07
2021-12-08
Soham Dutta has joined Public “Office Hours”
@here office hours is starting in 30 minutes! Remember to post your questions here.
uff, i’ve missed it again, next time
Marc Tamsky has joined Public “Office Hours”
Sam Caneer has joined Public “Office Hours”
David Hawthorne has joined Public “Office Hours”
Andy Miguel (Cloud Posse) has joined Public “Office Hours”
Brandon vh has joined Public “Office Hours”
Vlad Ionescu has joined Public “Office Hours”
gonna miss today, have fun!
Patrick Joyce has joined Public “Office Hours”
Justin Davis has joined Public “Office Hours”
Tim Gourley has joined Public “Office Hours”
Matt Andreo has joined Public “Office Hours”
Erik Osterman (Cloud Posse) has joined Public “Office Hours”
Michael Jenkins has joined Public “Office Hours”
Jim Park has joined Public “Office Hours”
Tony Scott has joined Public “Office Hours”
Luis Masaya has joined Public “Office Hours”
links from today’s session:
• https://aws.amazon.com/premiumsupport/technology/pes/
• https://aws.amazon.com/about-aws/whats-new/2021/12/awf-waf-cloudwatch-log-s3-bucket/
• https://aws.amazon.com/about-aws/whats-new/2021/12/aws-construct-hub-availability/
• https://acloudguru.com/blog/engineering/aws-reinvent-2021-the-biggest-announcements
• https://aws.amazon.com/blogs/aws/top-announcements-of-aws-reinvent-2021/
• https://venturebeat.com/2021/12/03/the-top-12-security-announcements-at-aws-reinvent-2021/
Only lasted 8+ hours… Totally reliable.
Oliver Schoenborn has joined Public “Office Hours”
Oliver Schoenborn has joined Public “Office Hours”
Patrick Jahns has joined Public “Office Hours”
Gabriel Boie has joined Public “Office Hours”
Tim Gourley has joined Public “Office Hours”
Andrew Thompson has joined Public “Office Hours”
All the problems dealing with CRDs: https://github.com/helm/community/blob/main/hips/hip-0011.md
(relates to service meshes)
Helm community content. Contribute to helm/community development by creating an account on GitHub.
love this sort of info thanks for sharing!
Helm community content. Contribute to helm/community development by creating an account on GitHub.
Question: Does AppSync work with Apollo Federation and Gateway? I have already used AppSync with Apollo Server using the schema stitching method, which is now deprecated. It looks like the new Apol…
2021-12-09
James Corteciano has joined Public “Office Hours”
2021-12-10
Has anyone had any success in configuring Persistent Storage when running EKS on Fargate? I’ve been banging my head on this problem for a few days now and it seems the only support for persistent storage is EFS, but i’ve been unable to get it to work, every attempt results in a “SetUp failed for volume… …Could not mount”
I got a little further here… now it’s reporting
Output: Failed to resolve "fs-.efs.us-west-2.amazonaws.com" - check that your file system ID is correct, and ensure that the VPC has an EFS mount target for this file system ID.
See <https://docs.aws.amazon.com/console/efs/mount-dns-name> for more detail.
Attempting to lookup mount target ip address using botocore. Failed to import necessary dependency botocore, please install botocore first.
Warning: config file does not have fall_back_to_mount_target_ip_address_enabled item in section mount.. You should be able to find a new config file in the same folder as current config file /etc/amazon/efs/efs-utils.conf. Consider update the new config file to latest config file. Use the default value [fall_back_to_mount_target_ip_address_enabled = True].
2021-12-15
For today, are we covering log4j security? We have been researching the log4j vulnerability and would be happy to discuss it! https://twitter.com/mazen160/status/1470249301733515266
At FullHunt, we developed, log4j-scan: a fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228. It was mainly for our customers. It’s now open-source! https://github.com/fullhunt/log4j-scan
All FullHunt customers have this RCE resolved now. https://pbs.twimg.com/media/FGde2icX0AEqWqf.jpg
yes, it is on the agenda
At FullHunt, we developed, log4j-scan: a fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228. It was mainly for our customers. It’s now open-source! https://github.com/fullhunt/log4j-scan
All FullHunt customers have this RCE resolved now. https://pbs.twimg.com/media/FGde2icX0AEqWqf.jpg
@here office hours is starting in 30 minutes! Remember to post your questions here.
my q is:
• how does Concurse CI fit / compare with the other tools like Spacelift/ codefresh/ GHA etc
• remind the pattern of using GHA as a CD for TF instead of more expensive tools like spacelift/ codefresh
Gabriel Boie has joined Public “Office Hours”
Andy Miguel (Cloud Posse) has joined Public “Office Hours”
Erik Osterman (Cloud Posse) has joined Public “Office Hours”
Sam Caneer has joined Public “Office Hours”
Andrew Way has joined Public “Office Hours”
Yusuf has joined Public “Office Hours”
Eric Berg has joined Public “Office Hours”
Mazin Ahmed has joined Public “Office Hours”
Michael Jenkins has joined Public “Office Hours”
Tim Gourley has joined Public “Office Hours”
Matt Calhoun has joined Public “Office Hours”
Gabriel Boie has joined Public “Office Hours”
Justin Davis has joined Public “Office Hours”
Loren Gordon has joined Public “Office Hours”
Florain Drescher has joined Public “Office Hours”
Dani Comnea has joined Public “Office Hours”
David Hawthorne has joined Public “Office Hours”
Vigneshkumar Sadasivam has joined Public “Office Hours”
Mauricio Wyler has joined Public “Office Hours”
Thomas Mundt has joined Public “Office Hours”
Andy Roth has joined Public “Office Hours”
links from today’s session:
• https://github.com/hashicorp/terraform/releases/tag/v1.1.0
• https://github.com/oboukili/terraform-provider-argocd
• https://opensource.apple.com/
• https://aws.amazon.com/message/12721/
• https://twitter.com/GovCERT_CH/status/1470097783407398928/photo/1
• https://github.com/orgs/github/projects/4247/views/2?filterQuery=label%3Aactions
Tony Scott has joined Public “Office Hours”
David B has joined Public “Office Hours”
Michael Holt has joined Public “Office Hours”
Oliver Schoenborn has joined Public “Office Hours”
Adedapo Ajuwon has joined Public “Office Hours”
James Corteciano has joined Public “Office Hours”
Uwaila Adams has joined Public “Office Hours”
Patrick Joyce has joined Public “Office Hours”
Oliver Schoenborn has joined Public “Office Hours”
wasim k has joined Public “Office Hours”
Andrew Bost has joined Public “Office Hours”
http://fullhunt.io/ - Search for external attack surfaces of your organization for free, there is also enterprise platform for extra features and continuous monitoring
Discover, monitor, and secure your attack surface. FullHunt delivers the best platform in the market for attack surface security.
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228 - GitHub - fullhunt/log4j-scan: A fully automated, accurate, and extensive scanner for finding log4j RCE CVE…
Andrew Thompson has joined Public “Office Hours”
Michael Jenkins has joined Public “Office Hours”
wrt testing terraform https://github.com/GoogleCloudPlatform/terraform-python-testing-helper (python version)
System crash
@Andy Miguel can you give the closing address
we all jumped off already
sorry all! see you all next week, same place - same time.
Kevin Huang has joined Public “Office Hours”
2021-12-17
2021-12-22
Asis Asis has joined Public “Office Hours”
@here office hours is starting in 30 minutes! Remember to post your questions here.
How are people running spark on kubernetes? I am currently evaluating emr on eks and the spark-on-k8s-operator
Erik Osterman (Cloud Posse) has joined Public “Office Hours”
Andy Miguel (Cloud Posse) has joined Public “Office Hours”
Gerardo Santoveña has joined Public “Office Hours”
Sean Turner has joined Public “Office Hours”
Mauricio Wyler has joined Public “Office Hours”
Eric Berg has joined Public “Office Hours”
Matt Calhoun has joined Public “Office Hours”
Zachary Loeber has joined Public “Office Hours”
Marc Slayton has joined Public “Office Hours”
Michael Jenkins has joined Public “Office Hours”
links from today’s session:
• https://github.com/cloudposse/terraform-aws-cloudfront-s3-cdn/pull/204
• https://github.com/cloudposse/terraform-aws-mwaa/pull/3
• https://github.com/cloudposse/atmos/pull/94
• https://github.com/cloudposse/atlantis/releases/tag/0.8.0
• https://www.datacenterdynamics.com/en/news/aws-has-another-east-coast-cloud-outage/
• https://github.com/hashicorp/terraform/releases/tag/v1.1.2
What was the meeting passcode?
@here our devops #office-hours are starting now! join us on zoom to talk shop url: cloudposse.zoom.us/j/508587304 password: sweetops
Tony Scott has joined Public “Office Hours”
Antarr Byrd has joined Public “Office Hours”
James Haughey has joined Public “Office Hours”
Patrick Joyce has joined Public “Office Hours”
Muzammil Aijaz has joined Public “Office Hours”
Sherif Abdel-Naby has joined Public “Office Hours”
A free service to monitor your SSL certificate expiry. Monitor your SSL certificates and receive notifications when they’re about to expire or change.
Abraham Olu has joined Public “Office Hours”
I have 3 different resource-usage profiles among the K8s services and jobs that I run. I want to isolate the pods with erratic resource usage from the front-end pods, and also run jobs on spot instances. Should I use node groups to do this? Should resource limits be enough to manage this?
Kubernetes Node Autoscaling: built for flexibility, performance, and scalability. https://karpenter.sh - GitHub - aws/karpenter: Kubernetes Node Autoscaling: built for flexibility, performance, and…
Uzuazoraro Etobro has joined Public “Office Hours”
2021-12-29
@here office hours is starting in 30 minutes! Remember to post your questions here.
Question: What is the current best practice for a cold start? I previously used reference-architecture but noticed it has now been archived and looks like Atmos replaces most but cannot find anything about a cold start. Thanks in advance!
Erik Osterman (Cloud Posse) has joined Public “Office Hours”
David Hawthorne has joined Public “Office Hours”
Andy Miguel (Cloud Posse) has joined Public “Office Hours”
Tony Scott has joined Public “Office Hours”
Josh B has joined Public “Office Hours”
Yavor Tomov has joined Public “Office Hours”
Mauricio Wyler has joined Public “Office Hours”
Vlad Ionescu has joined Public “Office Hours”
Ralf-Eric Pieper has joined Public “Office Hours”
Erik Osterman (Cloud Posse) has joined Public “Office Hours”
Zeid has joined Public “Office Hours”
jack lou has joined Public “Office Hours”
Chris Dutton has joined Public “Office Hours”
Yavor Tomov has joined Public “Office Hours”
James Haughey has joined Public “Office Hours”
tylers has joined Public “Office Hours”
Anere Faithful has joined Public “Office Hours”
venkata mutyala has joined Public “Office Hours”
Michael Jenkins has joined Public “Office Hours”
Andrew Thompson has joined Public “Office Hours”
Zachary Loeber has joined Public “Office Hours”
Zadkiel has joined Public “Office Hours”
Guilherme Borges has joined Public “Office Hours”
re:Invent videos are out on YouTube:
• https://www.youtube.com/c/AWSEventsChannel/playlists has helpful playlists
• https://www.youtube.com/c/AWSEventsChannel/videos has all the videos
CFP is open for HashiTalks 2022 https://www.hashicorp.com/blog/hashitalks-2022-call-for-proposals
HashiTalks, our annual, all-day virtual community event, returns for its fourth edition on Thursday, February 17, 2022. Submit your proposals now!
Michael Sew has joined Public “Office Hours”
Uzuazoraro Etobro has joined Public “Office Hours”
Abraham Olu has joined Public “Office Hours”