#office-hours (2022-10)
“Office Hours” are every Wednesday at 11:30 PST via Zoom. It’s open to everyone. Ask questions related to DevOps & Cloud and get answers! https://cloudposse.com/office-hours
Public “Office Hours” are held every Wednesday at 11:30 PST via Zoom. It’s open to everyone. Ask questions related to DevOps & Cloud and get answers!
https://cpco.io/slack-office-hours
Meeting password: sweetops
2022-10-03
data:image/s3,"s3://crabby-images/f423c/f423c8e850268e533a4e86e173d6f4a9a3b27039" alt="managedkaos avatar"
Anyone else using Bitbucket for CI/CD? https://bitbucket.org/blog/macos-runners-bitbucket
data:image/s3,"s3://crabby-images/4c4c7/4c4c70aac13fd8c3b7fe6a3c087009cff2be53d6" alt="attachment image"
We are happy to announce that Bitbucket Pipelines now supports macOS self-hosted runners. We have moved from beta to an official…
data:image/s3,"s3://crabby-images/2f9d5/2f9d5857d48ae1a0fdabf9b175a53f1368ef7c21" alt="JoseF avatar"
I been using Bitbucket for pipelines for a while now. What about the runners?
data:image/s3,"s3://crabby-images/4c4c7/4c4c70aac13fd8c3b7fe6a3c087009cff2be53d6" alt="attachment image"
We are happy to announce that Bitbucket Pipelines now supports macOS self-hosted runners. We have moved from beta to an official…
data:image/s3,"s3://crabby-images/f423c/f423c8e850268e533a4e86e173d6f4a9a3b27039" alt="managedkaos avatar"
They’ve added support for macOS.
I’ve been using Bitbucket pipelines for a while as well. I think they do a great job and stay on par with pipeline offerings from GitHub and GitLab.
I think Bitbucket is one of the best pipelines that people don’t think to consider. When i saw this post about new runners, I was just curious what other folks in this community might be using it as well.
2022-10-04
data:image/s3,"s3://crabby-images/55997/55997af58819ac7bd7627fb8710b4092d11fb630" alt="SweetOps avatar"
data:image/s3,"s3://crabby-images/8388f/8388ffb5d3d4593d65f49ba2c3655b95443293e1" alt="Jonas Steinberg avatar"
In case people are interested I’ll be raising the following topic tomorrow during office hours. I think it’s an interesting one and looking to get people’s feedback on it:
https://sweetops.slack.com/archives/CB6GHNLG0/p1664903787880119
Hey everyone,
Looking to have a bit of a debate on the topic of monitoring as code and whether or not *it actually matters*. More specifically: whether having monitors, dashboards, service level objects and the like actually need to be backed by IaC and within a GitOps workflow.
Many of us have monitoring products like datadog or cloudwatch in which the vast majority of monitors, dashboards, SLOs and the like have been clickops’d. For example at my current shop there are about 350 dashboards and almost none are in IaC and what’s more we don’t really know which ones are critical and which ones can be deleted. And the same goes for monitors and SLOs.
Now imagine that you used Terraformer (or equivalent, if there even is such a thing for Cloudformation) to get all these things into terraform and into all the appropriate repos. And then you even took that a step further and developed a system to do this continuously and also to clean up your monitoring product in the meanwhile, e.g. delete any dashboard not label critical
or something.
My questions to the community are: • so what? All of those clickops’d dashboards are backed up by the CSP or 3rd party; if they have a catastrophic event they’ll probably be able to get them back to you? • and do we really want to be writing dashboards as code? It gets fairly ridiculous. • and as for labeling them and then automating their cleanup: will it be that much of a feng shui or cost improvement? Curious about people’s thoughts regarding this topic because now that I have everything in IaC and a potential solution for automating parity and cleanup I find myself asking, “Who cares?” And of course if there are other reasons for storing monitors, dashboards, SLOs and the like as code please bring those up as I’m always interested in learning how other people are solving problems!
2022-10-05
data:image/s3,"s3://crabby-images/8388f/8388ffb5d3d4593d65f49ba2c3655b95443293e1" alt="Jonas Steinberg avatar"
@Erik Osterman (Cloud Posse) I have a meeting that goes until 12PM PT. I can skip it if I need to because I definitely want to raise the observe-as-code debate, but if you have content until 12PM and I can bring that up after that’d be great. Either way just not sure what you have on the agenda today. Thanks!
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Ok, we’ll defer it to 12pm
data:image/s3,"s3://crabby-images/8388f/8388ffb5d3d4593d65f49ba2c3655b95443293e1" alt="Jonas Steinberg avatar"
@Erik Osterman (Cloud Posse) no need, I can miss the other meeting – I’ve thought a lot about this today and yesterday and I want to make sure this gets top treatment so I’ll be there during peak.
data:image/s3,"s3://crabby-images/30ec5/30ec55ecc792bae04c502335beefa8a22a77760a" alt="david.gregory_slack avatar"
Random one: I know the official line is that s3 buckets can’t be moved between accounts, but is that really true even at the “ask AWS support nicely” level? We’ve got a few big enough buckets that, on the face of it, it would cost a few k to copy them from one account to another, which is a blocker for my preferred approach of rebuilding key systems in new accounts to get rid of old cruft. Any stories of non-bank-breaking S3 bucket migrations would be interesting!
data:image/s3,"s3://crabby-images/8388f/8388ffb5d3d4593d65f49ba2c3655b95443293e1" alt="Jonas Steinberg avatar"
@david.gregory_slack I’m not sure if you are aware of the s3p library – but if you do end up copying files I cannot recommend it enough – s3p saved me hours, if not days, on cross-account recursive s3 bucket copying. Pro-tip: spin up a huge ec2 instance or container of some type beforehand, as that will also dramatically help parallelization. Fwiw.
list/copy/sync/compare S3 buckets 5x-50x faster than aws-cli
data:image/s3,"s3://crabby-images/8388f/8388ffb5d3d4593d65f49ba2c3655b95443293e1" alt="Jonas Steinberg avatar"
I should have mentioned: this library is an order of magnitude faster than any other library you will find. At least it was when I used it last year.
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
heads up, we discussed this today
data:image/s3,"s3://crabby-images/30ec5/30ec55ecc792bae04c502335beefa8a22a77760a" alt="david.gregory_slack avatar"
Thanks, hoped to make it but events. Will catch up.
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
@here office hours is starting in 30 minutes! Remember to post your questions here.
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Erik Osterman (Cloud Posse) has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Linda Pham (Cloud Posse) has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Jose Figueredo has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Isaac M has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Allan Swanepoel has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Jonathan Poczatek has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Peter Dada has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
dag viggo lokoeen has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Gabriel Zabal has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Michael Jenkins has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Matt Calhoun has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Guelor Emanuel has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Ralf Pieper has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Jared Richards has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Jonas Steinberg has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Zadkiel has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Ozzy has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/8388f/8388ffb5d3d4593d65f49ba2c3655b95443293e1" alt="Jonas Steinberg avatar"
I’d like to pose a bit of an involved question on what priority observability as code is.
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Marc Tamsky has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Harold Sphinx has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Charles Smith has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
sebastian maniak has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Adedapo Ajuwon has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Vicken Simonian has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Vijay Kukreja has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Ray Botha has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
sebastian maniak has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Eric Berg has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
PePe Amengual has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Vicken Simonian has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Peter Dada has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Vijay Kukreja has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/8388f/8388ffb5d3d4593d65f49ba2c3655b95443293e1" alt="Jonas Steinberg avatar"
Thanks everyone for the awesome discussion today
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
let us know what you end up doing!
data:image/s3,"s3://crabby-images/8388f/8388ffb5d3d4593d65f49ba2c3655b95443293e1" alt="Jonas Steinberg avatar"
I will – I heard you loud and clear on the solution-looking-for-a-problem point, as well as Matt’s “snowflake service” point. I needed to hear those, frankly. Great stuff!!
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Thanks, @Jonas Steinberg @matt @Eric Berg @Alanis Swanepoel for the great discussion today.
data:image/s3,"s3://crabby-images/55997/55997af58819ac7bd7627fb8710b4092d11fb630" alt="SweetOps avatar"
2022-10-12
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
@here office hours is starting in 30 minutes! Remember to post your questions here.
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
Does anybody have experience with AWS EKS using AWS EFS?
I need a place to store/read some data (5-10MB file) very fast and have it available consistently on multiple pods.
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Erik Osterman (Cloud Posse) has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Linda Pham (Cloud Posse) has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Isaac M has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
dag viggo lokoeen has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Matt Calhoun has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Michael Jenkins has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
andy miguel has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Jared Richards has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Amaan Khan has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Jose Figueredo has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Hao Wang has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Oskar Maria Grande has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Andrew Hall has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Jonathan Poczatek has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
sebastian maniak has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Jim Park has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Alexandr Vorona has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Shantanu Gole has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Marc Tamsky has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Oliver Schoenborn has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/ccc2f/ccc2fa08918f9ef77eedc06dd6c68a382465dbd5" alt="Andy Miguel avatar"
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Srivardhan T has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Gabriel Zabal has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Johnmary Odenigbo has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/36360/36360050b703af21eb88ed6d2cdd1a120f237dd2" alt="Linda Pham (Cloud Posse) avatar"
Links from today’s call: https://go.hashicorp.com/index.php/email/emailWebview?md_id=58714 https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/ https://humanitec.com/whitepapers/kubernetes-benchmarking-study-2022 https://www.reddit.com/r/Terraform/comments/xxf691/terraform_plugin_framework_is_now_in_public_beta/ https://twitter.com/iamvlaaaaaaad/status/1534489514818686976
data:image/s3,"s3://crabby-images/55997/55997af58819ac7bd7627fb8710b4092d11fb630" alt="SweetOps avatar"
2022-10-16
data:image/s3,"s3://crabby-images/6153d/6153d2edef856aef90062c1b41d17154c31753dd" alt="venkata.mutyala avatar"
I know there are a number of ways to initialize your vault cluster but personally I am a fan of being able to do things in terraform: https://registry.terraform.io/providers/rickardgranberg/vaultoperator/0.1.6
^^ Sharing in case you folks haven’t heard of it before.
2022-10-19
data:image/s3,"s3://crabby-images/fc91a/fc91ae9dda75d1fd84d9b58b46603c5f44d8bda5" alt="Alanis Swanepoel avatar"
@Erik Osterman (Cloud Posse) - during some of the office hours calls you point to your internal ?confluence? page where you show how you structure aws accounts in an ldap / ou style
data:image/s3,"s3://crabby-images/fc91a/fc91ae9dda75d1fd84d9b58b46603c5f44d8bda5" alt="Alanis Swanepoel avatar"
is there any chance that page is publicly accessible?
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
@here office hours is starting in 30 minutes! Remember to post your questions here.
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
what is cloudposse?
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
who are you?
data:image/s3,"s3://crabby-images/f7f39/f7f39c0ac74e30f2d8925059018551d28d1610c7" alt="Igor M avatar"
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Erik Osterman (Cloud Posse) has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
John Jarvis has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
dag viggo lokoeen has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Vlad Ionescu has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Emile Fugulin has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Michael Jenkins has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Linda Pham (Cloud Posse) has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Jose Figueredo has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Matt Calhoun has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Ozzy has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Isaac M has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Matt Gowie has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Jonas Frank has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Allan Swanepoel has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Jonathan Poczatek has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
RB (Ronak Bhatia) (Cloud Posse) has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
PePe Amengual has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Oliver Schoenborn has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Oskar Maria Grande has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Isa Aguilar has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Joshua Magady has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Vicken Simonian has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Brian Pauley has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Maura Rowell has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/5a811/5a811623f3b687bbfff8fa37646de0b8bf2ef4b8" alt="JJ avatar"
Hey, popping in and out — kids’ bedtimes — but I’ll check out the recording later. Hoping to take advantage of these more; thanks for doing them!
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Jared Richards has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Andrew Vitko has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Devendra Yadav has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
PePe Amengual has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Andrew Nascimento has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Jared Richards has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Arthur Dent has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/36360/36360050b703af21eb88ed6d2cdd1a120f237dd2" alt="Linda Pham (Cloud Posse) avatar"
Link from today’s session: https://github.com/cloudposse/terraform-aws-ecs-cluster/ https://registry.terraform.io/providers/cloudposse/template/2.2.0?pollNotifications=true https://github.blog/2022-10-18-introducing-fine-grained-personal-access-tokens-for-github/ https://github.blog/changelog/2022-10-13-design-improvements-to-github-actions-navigation https://www.docker.com/pricing/october-2022-pricing-change-faq/ https://neon.tech/
Terraform module for provisioning an ECS cluster
data:image/s3,"s3://crabby-images/90be9/90be97770c03b00759ca2d0d237d79b42dc233fe" alt="attachment image"
Fine-grained personal access tokens offer enhanced security to developers and organization owners, to reduce the risk to your data of compromised tokens.
data:image/s3,"s3://crabby-images/3a2fa/3a2faae8a1459874a3406ee0cb3ef413f823e4e4" alt="attachment image"
Design improvements to GitHub Actions navigation
data:image/s3,"s3://crabby-images/85dc1/85dc1f3dd3f04bf10cdb52509e32d41469205897" alt="attachment image"
The price increase will allow us to continue to invest in Docker as developers’s #1 most-used, #1 most-loved and #1 most-wanted tool.
data:image/s3,"s3://crabby-images/55997/55997af58819ac7bd7627fb8710b4092d11fb630" alt="SweetOps avatar"
2022-10-26
data:image/s3,"s3://crabby-images/1f56f/1f56ffd63d6a7249b7f50ce533ad1fd0d08692be" alt="Sean Turner avatar"
Q: How are people enforcing MFA in AWS? Not using AWS SSO at the moment, just IAM Users and IAM Groups. Have seen a cloudtrail solution that uses a cloudwatch metric filter and alarm which does the trick, but is probably very expensive as you need to use cloudtrail.
data:image/s3,"s3://crabby-images/1e7fb/1e7fb012e9114db9a49ef4fb0140243909a277f1" alt="Matt Gowie avatar"
Check out the policy in this AWS Doc: https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_examples_aws_my-sec-creds-self-manage-mfa-only.html
The relevant bit is here:
{
"Sid": "DenyAllExceptListedIfNoMFA",
"Effect": "Deny",
"NotAction": [
"iam:CreateVirtualMFADevice",
"iam:EnableMFADevice",
"iam:GetUser",
"iam:ListMFADevices",
"iam:ListVirtualMFADevices",
"iam:ResyncMFADevice",
"sts:GetSessionToken"
],
"Resource": "*",
"Condition": {
"BoolIfExists": {"aws:MultiFactorAuthPresent": "false"}
}
}
Use this IAM policy to allow users to manage their MFA device in the AWS Management Console.
data:image/s3,"s3://crabby-images/78701/78701e63b3ea513290fca8a066c55cba3d3cb90b" alt="this"
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
``` module “admin_label” { source = “git://github.com/cloudposse/terraform-null-label.git?ref=tags/0.3.3>” namespace = “${var.namespace}” stage = “${var.stage}” name = “${var.admin_name}” delimiter = “${var.delimiter}” attributes = “${var.attributes}” tags = “${var.tags}” }
module “readonly_label” { source = “git://github.com/cloudposse/terraform-null-label.git?ref=tags/0.3.3>” namespace = “${var.namespace}” stage = “${var.stage}” name = “${var.readonly_name}” delimiter = “${var.delimiter}” attributes = “${var.attributes}” tags = “${var.tags}” }
data “aws_caller_identity” “current” {}
data “aws_iam_policy_document” “role_trust” { count = “${local.enabled ? 1 : 0}”
statement { actions = [“sts:AssumeRole”]
principals {
type = "AWS"
identifiers = ["arn<img src="/assets/images/custom_emojis/aws.png" alt="aws" class="em em--custom-icon em-aws">iam:root"]
}
condition {
test = "Bool"
variable = "aws:MultiFactorAuthPresent"
values = ["true"]
} } }
data “aws_iam_policy_document” “manage_mfa” { count = “${local.enabled ? 1 : 0}”
statement { sid = “AllowUsersToCreateEnableResyncTheirOwnVirtualMFADevice”
actions = [
"iam:CreateVirtualMFADevice",
"iam:EnableMFADevice",
"iam:ResyncMFADevice",
]
resources = [
"arn<img src="/assets/images/custom_emojis/aws.png" alt="aws" class="em em--custom-icon em-aws">iam:mfa/&{aws:username}",
"arn<img src="/assets/images/custom_emojis/aws.png" alt="aws" class="em em--custom-icon em-aws">iam:user/&{aws:username}",
] }
statement { sid = “AllowUsersToDeactivateTheirOwnVirtualMFADevice”
actions = [
"iam:DeactivateMFADevice",
]
resources = [
"arn<img src="/assets/images/custom_emojis/aws.png" alt="aws" class="em em--custom-icon em-aws">iam:mfa/&{aws:username}",
"arn<img src="/assets/images/custom_emojis/aws.png" alt="aws" class="em em--custom-icon em-aws">iam:user/&{aws:username}",
]
condition {
test = "Bool"
variable = "aws:MultiFactorAuthPresent"
values = ["true"]
} }
statement { sid = “AllowUsersToDeleteTheirOwnVirtualMFADevice”
actions = [
"iam:DeleteVirtualMFADevice",
]
resources = [
"arn<img src="/assets/images/custom_emojis/aws.png" alt="aws" class="em em--custom-icon em-aws">iam:mfa/&{aws:username}",
"arn<img src="/assets/images/custom_emojis/aws.png" alt="aws" class="em em--custom-icon em-aws">iam:user/&{aws:username}",
]
condition {
test = "Bool"
variable = "aws:MultiFactorAuthPresent"
values = ["true"]
} }
statement { sid = “AllowUsersToListMFADevicesandUsersForConsole”
actions = [
"iam:ListMFADevices",
"iam:ListVirtualMFADevices",
"iam:ListUsers",
]
resources = [
"*",
] } }
data “aws_iam_policy_document” “allow_change_password” { count = “${local.enabled ? 1 : 0}”
statement { actions = [“iam:ChangePassword”]
resources = ["arn<img src="/assets/images/custom_emojis/aws.png" alt="aws" class="em em--custom-icon em-aws">iam:user/&{aws:username}"] }
statement { actions = [“iam:GetAccountPasswordPolicy”] resources = [“*”] }
statement { actions = [“iam:GetLoginProfile”]
resources = ["arn<img src="/assets/images/custom_emojis/aws.png" alt="aws" class="em em--custom-icon em-aws">iam:user/&{aws:username}"]
condition {
test = "Bool"
variable = "aws:MultiFactorAuthPresent"
values = ["true"]
} } }
data “aws_iam_policy_document” “allow_key_management” { statement { actions = [ “iam:DeleteAccessKey”, “iam:GetAccessKeyLastUsed”, “iam:UpdateAccessKey”, “iam:GetUser”, “iam:CreateAccessKey”, “iam:ListAccessKeys”, ]
resources = ["arn<img src="/assets/images/custom_emojis/aws.png" alt="aws" class="em em--custom-icon em-aws">iam:user/&{aws:username}"]
condition {
test = "Bool"
variable = "aws:MultiFactorAuthPresent"
values = ["true"]
} } }
Admin config
locals { enabled = “${var.enabled == “true” ? true : false }” admin_user_names = “${length(var.admin_user_names) > 0 ? true : false}” readonly_user_names = “${length(var.readonly_user_names) > 0 ? true : false}” }
resource “aws_iam_policy” “manage_mfa_admin” { count = “${local.enabled ? 1 : 0}” name = “${module.admin_label.id}-permit-mfa” description = “Allow admin users to manage Virtual MFA Devices” policy = “${join(“”, data.aws_iam_policy_document.manage_mfa.*.json)}” }
resource “aws_iam_policy” “allow_change_password_admin” { count = “${local.enabled ? 1 : 0}” name = “${module.admin_label.id}-permit-change-password” description = “Allow admin users to change password” policy = “${join(“”, data.aws_iam_policy_document.allow_change_password.*.json)}” }
resource “aws_iam_policy” “allow_key_management_admin” { name = “${module.admin_label.id}-allow-key-management” description = “Allow admin users to manage their own access keys” policy = “${data.aws_iam_policy_document.allow_key_management.json}” }
data “aws_iam_policy_document” “assume_role_admin” { count = “${local.enabled ? 1 : 0}”
statement { actions = [“sts:AssumeRole”] resources = [”${join(“”, aws_iam_role.admin.*.arn)}”] } }
resource “aws_iam_policy” “assume_role_admin” { count = “${local.enabled ? 1 : 0}” name = “${module.admin_label.id}-permit-assume-role” description = “Allow assuming admin role” policy = “${join(“”, data.aws_iam_policy_document.assume_role_admin.*.json)}” }
resource “aws_iam_group” “admin” { count = “${local.enabled ? 1 : 0}” name = “${module.admin_label.id}” }
resource “aws_iam_role” “admin” { count = “${local.enabled ? 1 : 0}” name = “${module.admin_label.id}” assume_role_policy = “${join(“”, data.aws_iam_policy_document.role_trust.*.json)}” }
resource “aws_iam_group_policy_attachment” “assume_role_admin” { count = “${local.enabled ? 1 : 0}” group = “${join(“”, aws_iam_group.admin..name)}” policy_arn = “${join(“”, aws_iam_policy.assume_role_admin..arn)}” }
resource “aws_iam_group_policy_attachment” “manage_mfa_admin” { count = “${local.enabled ? 1 : 0}” group = “${join(“”, aws_iam_group.admin..name)}” policy_arn = “${join(“”, aws_iam_policy.manage_mfa_admin..arn)}” }
resource “aws_iam_group_policy_attachment” “allow_chage_password_admin” { count = “${local.enabled ? 1 : 0}” group = “${join(“”, aws_iam_group.admin..name)}” policy_arn = “${join(“”, aws_iam_policy.allow_change_password_admin..arn)}” }
resource “aws_iam_group_policy_attachment” “key_management_admin” { group = “${aws_iam_group.admin.name}” policy_arn = “${aws_iam_policy.allow_key_management_admin.arn}” }
resource “aws_iam_role_policy_attachment” “admin” {
count = “${local.enabled ? 1 : 0}”
role = “${join(“”, aws_iam_role.admin.*.name)}”
policy_arn = “arniam:policy/AdministratorAccess”
}
resource “aws_iam_group_membership” “admin” { count = “${local.enabled && local.admin_user_names ? 1 : 0}” name = “${module.admin_label.id}” group = “${join(“”, aws_iam_group.admin.*.id)}” users = [”${var.admin_user_names}”] }
Readonly config
resource “aws_iam_policy” “manage_mfa_readonly” { count = “${local.enabled ? 1 : 0}” name = “${module.readonly_label.id}-permit-mfa” description = “Allow readonly users to manage Virtual MFA Devices” policy = “${join(“”, data.aws_iam_policy_document.manage_mfa.*.json)}” }
resource “aws_iam_policy” “allow_change_password_readonly” { count = “${local.enabled ? 1 : 0}” name = “${module.readonly_label.id}-permit-change-password” description = “Allow readonly users to change password” policy = “${join(“”, data.aws_iam_policy_document.allow_change_password.*.json)}” }
resource “aws_iam_policy” “allow_key_management_readonly” { name = “${module.readonly_label.id}-permit-manage-keys” description = “Allow readonly users to manage their own access keys” policy = “${data.aws_iam_po…
data:image/s3,"s3://crabby-images/2feaf/2feaf4252029d10b67e57e5def12ff7e3017d6a3" alt="Aritra Banerjee avatar"
We are using a product called gravitational teleport, where mfa is added to github, people login via their github profile and only a particular team has access to the aws console itself
data:image/s3,"s3://crabby-images/1f56f/1f56ffd63d6a7249b7f50ce533ad1fd0d08692be" alt="Sean Turner avatar"
Interesting, thanks. We have some non technical users so doing things through github isn’t as ideal unfortunately
data:image/s3,"s3://crabby-images/2feaf/2feaf4252029d10b67e57e5def12ff7e3017d6a3" alt="Aritra Banerjee avatar"
They have enterprise plans as well with AD integration
data:image/s3,"s3://crabby-images/2feaf/2feaf4252029d10b67e57e5def12ff7e3017d6a3" alt="Aritra Banerjee avatar"
We are using the free version
data:image/s3,"s3://crabby-images/9a0f8/9a0f8d41476ffe9065fbe0b98227d0cdcaa0cd11" alt="Erik Osterman (Cloud Posse) avatar"
@here office hours is starting in 30 minutes! Remember to post your questions here.
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Erik Osterman (Cloud Posse) has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Isaac M has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Oliver Schoenborn has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Vlad Ionescu has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Joe Caulfield has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Linda Pham (Cloud Posse) has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Eric Berg has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Ralf Pieper has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Oliver Schoenborn has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Paul Bullock has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Maura Rowell has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Jared Richards has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Brian Pauley has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Jared Richards has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
sebastian maniak has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Joshua Magady has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Amaan Khan has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Amaan Khan has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Jim Park has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Matt Gowie has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Sean TUrner has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Olad Oke has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Srivardhan T has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/05a48/05a48e22868e427aea8b588026f5a42129269ade" alt="Zoom avatar"
Olad Oke has joined Public “Office Hours”
data:image/s3,"s3://crabby-images/36360/36360050b703af21eb88ed6d2cdd1a120f237dd2" alt="Linda Pham (Cloud Posse) avatar"
Links from office hours: https://github.com/cloudposse/infra-live/pull/184 https://aws.amazon.com/about-aws/whats-new/2022/10/aws-organizations-console-centrally-manage-primary-contact-information-aws-accounts/ https://aws.amazon.com/about-aws/whats-new/2022/10/aws-batch-supports-amazon-eks/ https://devopsian.net/posts/terraform-data-sources-over-remote-state/ https://brendanthompson.com/posts/2022/10/terraform-for-expression https://aws.amazon.com/about-aws/whats-new/2022/10/dark-mode-support-aws-management-console/ and https://aws.amazon.com/about-aws/whats-new/2022/10/amazon-sqs-increased-throughput-quota-fifo-high-throughput-ht-mode-6000-transactions-per-second-tps/ https://github.com/fffaraz/awesome-selfhosted-aws https://www.home-assistant.io/ https://www.iampulse.com/ https://github.com/iann0036/iamlive https://airiam.io/ https://hackingblogs.com/aws-security-tools-detail-guide/ https://docs.aws.amazon.com/IAM/latest/UserGuide/access-analyzer-policy-generation.html
Why Terraform data sources are preferable over remote state, with use-cases using multiple filters based on tags to filter resources dynamically
data:image/s3,"s3://crabby-images/8f1fe/8f1fed43643ef6656d086d028dab0fb32ae24944" alt="attachment image"
Using the for expression in Terraform to filter, group, order and mutate information. With this knowledge in hand you will easily be able to construct complex objects based on existing information/configuration or from configuration passed in via input variables or ingested. Easily create multiple instances of resources or data sources using the for_each meta-argument.
data:image/s3,"s3://crabby-images/55997/55997af58819ac7bd7627fb8710b4092d11fb630" alt="SweetOps avatar"