#office-hours (2023-11)

“Office Hours” are every Wednesday at 11:30 PST via Zoom. It’s open to everyone. Ask questions related to DevOps & Cloud and get answers! https://cloudposse.com/office-hours

Public “Office Hours” are held every Wednesday at 11:30 PST via Zoom. It’s open to everyone. Ask questions related to DevOps & Cloud and get answers!


Meeting password: sweetops


Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)
06:00:08 PM

@here office hours is starting in 30 minutes! Remember to post your questions here.

Alex Atkinson avatar
Alex Atkinson

Folks are starting to analyze the impact of Hashi’s license change on contributions. https://thenewstack.io/open-source-in-numbers-the-terraform-license-change-impact-on-contribution/

Open Source in Numbers: The Terraform License Change Impact on Contributionattachment image

The increase in pull requests after the license change might seem like a positive sign. However, the data reveals a nuanced picture.


SlackBot avatar
11:53:17 PM
SlackBot avatar
11:53:17 PM


managedkaos avatar
Coming soon! Certified Argo Project Associate | Cloud Native Computing Foundationattachment image

Cloud Native Computer Foundation and Linux Foundation Training and Certification today announced the new Certified Argo Project Associate (CAPA) certification. Argo Project, an open-source…


SlackBot avatar
03:58:22 PM
SlackBot avatar
03:58:22 PM
Matt Gowie avatar
Matt Gowie

Hey folks – Not sure if KCL has been brought up before or not, but one my team members (Kevin) surfaced it recently. In looking into it, I’m interested. It has things that I’d both be excited to use and concerned about being overly complex.

Has anyone used it before in their own environments? Any strong opinions?

I could see this type of configuration language being huge for an atmos v2. I see a lot of the functionality that Atmos has built (imports, schema, etc.) as being first class in KCL, which would reduce a lot of the custom implementation burden. Would be interested to hear thoughts on that!


KCL Tour | KCL programming language.

This page shows how to use major KCL features, from variables and operators to schemas and libraries, with the assumption that you have already known how to program in another language. KCL is mainly inspired by Python, and knowing Python is very helpful for learning KCL.

Eamon Keane avatar
Eamon Keane

It’s a spin out of Ant Group’s internal dev platform, it looks well designed with lots integrations to argo etc.

I don’t think it’s gotten much traction beyond Ant Group or China, but perhaps it will now that it was recently accepted to the CNCF sandbox.

Used by Ant, Huawei, Youzan, etc
Huawei uses this to emit Terraform HCL

https://github.com/cncf/sandbox/issues/48 https://docs.google.com/document/d/1OykvqvhSG4AxEdmDMXilrupsX2n1qCSJUWwTc3I7AOs/edit

I think one of the kcl devs has posted it about before - @Xu Pengfei

KCL Tour | KCL programming language.

This page shows how to use major KCL features, from variables and operators to schemas and libraries, with the assumption that you have already known how to program in another language. KCL is mainly inspired by Python, and knowing Python is very helpful for learning KCL.

Xu Pengfei avatar
Xu Pengfei

Hi, this is Peefy, one of the core maintainers of KCL. It’s great to meet you here and welcome to join our community . KCL has just become a sandbox project for CNCF and is committed to improving the configuration and policy writing experience of API layers such as Kubernetes, Terraform, etc. We will maintain KCL for a long time and improve the user experience of KCL and continuously simplify it. and we will continue to build the community’s KCL module library: https://artifacthub.io/packages/search?org=kcl&sort=relevance&page=1 . In addition, the majority of adopters and communities are actually from outside China, as you can see in GitHub discussions and issue lists. If you have any further interests or encounter any problems, please feel free to communicate with me through any channels (GitHub Discussion, Slack, etc.)

Artifact Hubattachment image

Find, install and publish Kubernetes packages

Eamon Keane avatar
Eamon Keane

good to know, thanks!


Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)
07:01:45 PM

@here office hours is starting in 30 minutes! Remember to post your questions here.


managedkaos avatar

Have you experienced the AWS Builder Studio in NYC?


AWS Builder Studio | Amazon Web Services

AWS Builder Studio is a prototyping lab, experiential showroom, and collaboration space to help drive customer innovation by showcasing the “art of the possible” for building and prototyping on AWS.


Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)

Hey everyone! Cloud Posse is 7 reviews away from becoming an AWS Advanced Partner. Big favor to ask! If you’ve found any part of our weekly “office hours” helpful, please let AWS know by leaving a review.


Matt Gowie avatar
Matt Gowie

Ah this is exciting news Erik – congrats on working your way up the totem pole in there!!



venkata.mutyala avatar

Looks like Quay.io https://status.quay.io/ is having an outage where image pulls are failing. This appears to be impacting popular projects like argocd as well. Anyone here experience something similar and have a recommended solution?

Quay.io Status

Welcome to Quay.io’s home for real-time and historical data on system performance.



Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)
07:02:14 PM

@here office hours is starting in 30 minutes! Remember to post your questions here.

Vlad Ionescu (he/him) avatar
Vlad Ionescu (he/him)

I won’t make it today, sorry

Alanis Swanepoel avatar
Alanis Swanepoel

This just hit one of my security alert threads - pls share - https://www.schneier.com/blog/archives/2023/11/new-ssh-vulnerability.html

Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)

carl carver • November 15, 2023 8:18 PM
I think the summary should’ve included this paragraph too:
The countermeasure to the attacks we describe in this paper is
well known: implementations should validate signatures before
sending them. OpenSSH, the most common SSH implementation
we observed in this data, implements this countermeasure because
it uses OpenSSL to generate signatures, and OpenSSL has included
countermeasures against RSA fault attacks since 2001.


managedkaos avatar
venkata.mutyala avatar

He might be back by Wednesday.

venkata.mutyala avatar

Ideally before tomorrow. It seems like talks are still on-going

Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)

See also ai



jose.amengual avatar
Recent Terraform Cloud Pricing Changes - Sticker Shock?

Terraform Cloud’s recent pricing model changes to RUM pricing are causing sticker shock for some organizations!

Hao Wang avatar
Hao Wang

Hashicorp will be there for a long period but won’t perform as well as before any more

Recent Terraform Cloud Pricing Changes - Sticker Shock?

Terraform Cloud’s recent pricing model changes to RUM pricing are causing sticker shock for some organizations!

Igor Rodionov avatar
Igor Rodionov

This pricing model seems too complicated to estimate the spending.

Igor Rodionov avatar
Igor Rodionov

Take my words back - it is just insane.

Igor Rodionov avatar
Igor Rodionov
Igor Rodionov avatar
Igor Rodionov

Hao Wang avatar
Hao Wang

wow, this CEO is destroying a great company

jose.amengual avatar

and my stocks



SlackBot avatar
04:33:20 PM
SlackBot avatar
04:33:23 PM


Vlad Ionescu (he/him) avatar
Vlad Ionescu (he/him)

I’ll miss today’s call too — sorry!

Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)

Hopefully see you next week!

Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)
07:01:20 PM

@here office hours is starting in 30 minutes! Remember to post your questions here.

Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)

Static checker for GitHub Actions workflow files


SlackBot avatar
07:08:21 AM
SlackBot avatar
07:08:21 AM


venkata.mutyala avatar

Anyone here using vault with a community support backend like S3? ref: https://developer.hashicorp.com/vault/docs/v1.14.x/configuration/storage/s3

S3 - Storage Backends - Configuration | Vault | HashiCorp Developerattachment image

The S3 storage backend is used to persist Vault’s data in an Amazon S3 bucket.


Michael avatar
Amazon EKS Pod Identity simplifies IAM permissions for applications on Amazon EKS clusters | Amazon Web Servicesattachment image

Starting today, you can use Amazon EKS Pod Identity to simplify your applications that access AWS services. This enhancement provides you with a seamless and easy to configure experience that lets you define required IAM permissions for your applications in Amazon Elastic Kubernetes Service (Amazon EKS) clusters so you can connect with AWS services outside […]

OliverS avatar

Curious if anyone has used Gaia https://github.com/gaia-pipeline/gaia


Build powerful pipelines in any programming language.


Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)
07:02:03 PM

@here office hours is starting in 30 minutes! Remember to post your questions here.

lapc20081996 avatar

Hello Erik, is there a Zoom passcode for this meeting? It’s my first time joining, greetings from Costa Rica.

Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)

Sorry I missed your message

Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)

If you signed up at cloudposse.com/office-hours, you should receive an invitation which has the join code

Alex Atkinson avatar
Alex Atkinson

Amazon Q…. With the most annoying notice that WILL NOT GO AWAY!

venkata.mutyala avatar

I was immediately disappointed.

Alex Atkinson avatar
Alex Atkinson


Nenna avatar

Links from today’s office hours:

https://www.broadcom.com/blog/broadcom-announces-successful-acquisition-of-vmware https://docs.newrelic.com/docs/security/new-relic-security/security-bulletins/security-bulletin-nr23-01-security-advisory/ https://aws.amazon.com/about-aws/whats-new/2023/11/aws-backup-restore-testing/ https://aws.amazon.com/about-aws/whats-new/2023/11/dashboard-enhancements-aws-security-hub/ https://aws.amazon.com/about-aws/whats-new/2023/11/new-finding-enrichment-aws-security-hub/ https://aws.amazon.com/about-aws/whats-new/2023/11/aws-security-hub-central-configuration/ https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/config_organization_conformance_pack https://aws.amazon.com/about-aws/whats-new/2023/11/amazon-managed-service-prometheus-agentless-collector-metrics-eks/ https://aws.amazon.com/about-aws/whats-new/2023/11/amazon-efs-250000-iops-per-file-system/ https://aws.amazon.com/about-aws/whats-new/2023/11/automate-aws-control-tower-zone-operations-apis/ https://aws.amazon.com/about-aws/whats-new/2023/11/aws-cloudformation-git-management-stacks/ https://aws.amazon.com/about-aws/whats-new/2023/11/aws-console-to-code-preview-generate-console-actions/ https://aws.amazon.com/about-aws/whats-new/2023/11/aws-amazon-q-preview/ https://aws.amazon.com/blogs/aws/upgrade-your-java-applications-with-amazon-q-code-transformation-preview/ https://aws.amazon.com/blogs/aws/new-amazon-s3-express-one-zone-high-performance-storage-class/ https://www.hashicorp.com/blog/terraform-delivers-launch-day-support-for-amazon-s3-express https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/securityhub_organization_configuration https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/config_organization_conformance_pack https://fireflies.ai/ https://github.com/iann0036/AWSConsoleRecorder https://aws.amazon.com/blogs/aws/improve-developer-productivity-with-generative-ai-powered-amazon-q-in-amazon-codecatalyst-preview/ https://aws.amazon.com/blogs/aws/mutual-authentication-for-application-load-balancer-to-reliably-verify-certificate-based-client-identities/ https://aws.amazon.com/about-aws/whats-new/2023/11/application-load-balancer-availability-target-weights/ https://aws.amazon.com/blogs/aws/mutual-authentication-for-application-load-balancer-to-reliably-verify-certificate-based-client-identities/

