#office-hours (2024-09)

“Office Hours” are every Wednesday at 11:30 PST via Zoom. It’s open to everyone. Ask questions related to DevOps & Cloud and get answers! https://cloudposse.com/office-hours

Public “Office Hours” are held every Wednesday at 11:30 PST via Zoom. It’s open to everyone. Ask questions related to DevOps & Cloud and get answers!

https://cpco.io/slack-office-hours

Meeting password: sweetops

2024-09-04

Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)
06:02:56 PM

@here office hours is starting in 30 minutes! Remember to post your questions here.

Nenna avatar

Links from today’s office hours:

https://www.elastic.co/blog/elasticsearch-is-open-source-again https://www.bleepingcomputer.com/news/security/halliburton-cyberattack-linked-to-ransomhub-ransomware-gang/ https://www.dogesec.com/blog/full_text_rss_atom_blog_feeds/ https://llmstxt.org/ https://www.infoq.com/news/2024/09/figma-ecs-kubernetes-eks/?utm_source=tldrdevops https://aws.amazon.com/about-aws/whats-new/2024/08/amazon-s3-conditional-writes/ https://aws.amazon.com/about-aws/whats-new/2024/09/amazon-dynamodb-attribute-based-access-control/ https://repost.aws/articles/ARZy0AK1RZSLSL7wKU8SmO9g/a-first-look-at-aws-cloudformation-iac-generator https://aws.amazon.com/about-aws/whats-new/2024/08/cloudformation-resource-discovery-template-review-iac-generator/ https://github.com/opentofu/opentofu/blob/main/TSC_SUMMARY.md#sanctions-russia-vs-registry-access https://forums.docker.com/t/docker-hub-is-not-accessible-from-russia/141678/12 https://github.com/opentofu/registry/pull/824 https://github.com/yandex-cloud/terraform-provider-yandex/issues/258#issue-1234059608 https://github.com/opentofu/opentofu/releases/tag/v1.8.0-alpha1 https://www.freshrss.org/ https://github.com/muchdogesec/history4feed https://www.arl.org/blog/training-generative-ai-models-on-copyrighted-works-is-fair-use/ https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/cloudformation_stack_set.html https://medium.com/@joachim8675309/devops-concepts-snowflake-vs-phoenix-845e56006ccc https://masterpoint.io/updates/passing-on-crossplane/ https://www.vcluster.com/

2024-09-05

RB avatar

Has anyone checked out stacklok/minder for open source maintenance ? They have a lot of open source rules. I was forwarded this one which proposes a github action per repo in an org for enablement of openssf’s scorecard.

jose.amengual avatar
jose.amengual

looks interesting

Has anyone checked out stacklok/minder for open source maintenance ? They have a lot of open source rules. I was forwarded this one which proposes a github action per repo in an org for enablement of openssf’s scorecard.

2024-09-11

Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)
06:03:43 PM

@here office hours is starting in 30 minutes! Remember to post your questions here.

Petr Dondukov avatar
Petr Dondukov

Is this some kind of meeting?

Petr Dondukov avatar
Petr Dondukov

Hey guys, I sent in an request to connect to future meetings, please approve me)

Petr Dondukov avatar
Petr Dondukov

I can introduce myself, I’m a DevOps engineer and I’m currently looking for ways to lighten our infrastructure built on terraform/terragrunt. My website with contacts: https://d3vops.us

Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)

Sorry, just saw this

Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)

You might have joined an old meeting link

Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)

Have you registered at cloudposse.com/office-hours

Petr Dondukov avatar
Petr Dondukov

I sent in an new request to connect

Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)

Let me know if you don’t get it

Petr Dondukov avatar
Petr Dondukov

I got it, thatnx!

Michael avatar
Michael

Sorry, had to drap for another meeting but great to catch up with everyone

2

2024-09-12

venkata.mutyala avatar
venkata.mutyala
$20 Domain Purchase Exposed .MOBI's Critical Security Flawattachment image

WatchTowr Labs took over the defunct domain of the WHOIS server for the .MOBI TLD, unveiling a major flaw in internet infrastructure.

Joaquin Menchaca avatar
Joaquin Menchaca

So I went to ChatGPT, and asked some questions about concepts I wanted to do, and wow, it is so clear. Questions for concepts I would ask are:

  1. In DevOps, what’s pets vs cattle
  2. In DevOps, what’s bake vs fry
  3. In DevOps, what’s snowflake server vs phoenix server
  4. In DevOps, what’s service discovery vs change configuration In the later, it actually got stuff right. For SD, it mentioned consul, etcd, and kubernetes built-in w kube-proxy, and it also for change configuration, mentioned Puppet, Ansible, and Terraform.
Hao Wang avatar
Hao Wang

the last post is not public accessible

Joaquin Menchaca avatar
Joaquin Menchaca

Does it work now?

Hao Wang avatar
Hao Wang

yeah, it does, thanks

2024-09-13

2024-09-14

2024-09-15

2024-09-16

RB avatar

I came across this OWASP project recently that implements an open source version of AWS PrivateCA without the costs of PrivateCA

https://serverlessca.com/

1
1

2024-09-17

managedkaos avatar
managedkaos

Might not make the meeting but for this week… https://blog.kubecost.com/blog/ibm-acquisition-announcement/

Announcing Kubecost’s Acquisition by IBM!

We are excited to share that we are now part of the IBM family, joining Apptio and Turbonomic to build the leading platform for informing, optimizing and operating cloud investments

2024-09-20

Gervais de Montbrun avatar
Gervais de Montbrun

I’ve requested an invite to the Office Hours call a few times, but never seem to get an invite sent. Any suggestions on what I should do?

Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)

I’ll reach out in DM

Gervais de Montbrun avatar
Gervais de Montbrun

Interesting… Should there be a link or something that allows me to join office hours live?

Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)

Yep, once you receive the invite there will be a Zoom link you can use to join

2024-09-22

Michael avatar
Michael

Super interesting vulnerability discovery that allows remote code execution without any interaction for the Arc Browser: https://kibty.town/blog/arc/

gaining access to anyones browser without them even visiting a website - eva's site

gaining access to anyones browser without them even visiting a website

2024-09-23

2024-09-24

SweetOps avatar
SweetOps
08:30:40 PM
[Best Secrets Management Strategy For EKSCloud Posse Explains](https://www.youtube.com/watch?v=xvZj9KYsLOU)

2024-09-25

SweetOps avatar
SweetOps
05:01:23 PM
[Avoid Platform Fees While Running CI JobsCloud Posse Explains](https://www.youtube.com/watch?v=DnT_yHmKIac)
Erik Osterman (Cloud Posse) avatar
Erik Osterman (Cloud Posse)
06:03:51 PM

@here office hours is starting in 30 minutes! Remember to post your questions here.

venkata.mutyala avatar
venkata.mutyala
System Initiative Revolutionizes DevOps with New Platform that Replaces Infrastructure As Codeattachment image

SAN FRANCISCO – September 25, 2024 – System Initiative today announced the general availability of their revolutionary technology for DevOps Automation. Their intuitive, powerful, and collaborative approach replaces Infrastructure as Code and sets the foundation for a series of disruptive innovation

2
Syed Maad Jahangir avatar
Syed Maad Jahangir

This looks interesting. I will check it out. Also want to find about importing current infra to the tool

System Initiative Revolutionizes DevOps with New Platform that Replaces Infrastructure As Codeattachment image

SAN FRANCISCO – September 25, 2024 – System Initiative today announced the general availability of their revolutionary technology for DevOps Automation. Their intuitive, powerful, and collaborative approach replaces Infrastructure as Code and sets the foundation for a series of disruptive innovation

Matt Gowie avatar
Matt Gowie

Ah did I miss a conversation on this one in yesterday’s office hours? Did anyone have real-life experience of using it yet?

managedkaos avatar
managedkaos

I’ve been hearing about System Initiative for years so I’m glad to see it finally be GA. No experience using it but the buzz has me curious. Looking forward to getting hands on and hearing how other folks fare with testing….and maybe even production deployments!?

elvis lim avatar
elvis lim

ClickOps (with backend typescript)! intriguing !

2

2024-09-26

venkata.mutyala avatar
venkata.mutyala
1
managedkaos avatar
managedkaos

In another slack i commented…
that’s crazy. its another “we made open source and now we’re mad other companies are making money from it” situation.

I mean, I would hope WPEngine would give something back to the code base but, are they legally required to? Is this the beginning of the end of open source WordPress?

Oddly enough, over the past few months I’ve been slowly converting several old WP sites to statics sites on GitHub pages and Netlify. I’m using GCP buckets to serve the images. Its working pretty well.

Hao Wang avatar
Hao Wang

WP uses GPLv2, https://en-ca.wordpress.org/about/license/, but seems WordPress.org does have right to do so, which is not related to the license

License

GNU Public License The license under which the WordPress software is released is the GPLv2 (or later) from the Free Software Foundation. A copy of the license is included with every copy of WordPress, but you can also read the text of the license here. Part of this license outlines requirements for derivative works, such as plugins […]

Hao Wang avatar
Hao Wang
WP Engine is not WordPressattachment image

It has to be said and repeated: WP Engine is not WordPress. My own mother was confused and thought WP Engine was an official thing. Their branding, marketing, advertising, and entire promise to cus…

managedkaos avatar
managedkaos

Ah, so you’re saying, based on the license and the change to revisions, that WP Engine is a derivative work and should be licensed and/or treated differently?

Hao Wang avatar
Hao Wang

no, I meant to say the license do nothing about the dispute between 2 parties, the best way is thru the lawsuit as WP org does

managedkaos avatar
managedkaos

got it.

Hao Wang avatar
Hao Wang

you are wise to convert WP as early as possible for there are so many backdoors in it

Hao Wang avatar
Hao Wang

managedkaos avatar
managedkaos

Main reason why i am converting! I was really active on deploying WP in 2008 - 2019. Then got away from the sites during pandemic. Taking a look at them now, they are all filled with malware. Some really hacky, crazy stuff redirecting site visitors to XXX sites and scammy stuff.

So I turned off all plugins and themes and then scoured the host service for all the hacky PHP files hanging around. Its a mess. I’m resigned to just taking the WP hosting offline and going static.

1
Hao Wang avatar
Hao Wang

you are hero to your clients, responsible

1
venkata.mutyala avatar
venkata.mutyala

We recently launched our site on wordpress. We keep our plugins/etc. up to date. We also use WP Engine so i’m curious to see what a cluster f’ this turns into for us. Fortunately we have a company that manages our wordpress site for us and they are likely going to handle the manual updates for us.

RE: Security. My understand of wordpress is that if you go into the ecosystem you just have to keep it up to date. I suspect the ones that get hacked don’t do this at all.

managedkaos avatar
managedkaos

RE: Security. My understand of wordpress is that if you go into the ecosystem you just have to keep it up to date. I suspect the ones that get hacked don’t do this at all. not in all cases.

In my case, i was updating diligently, even though i was not actively adding to or developing the site. After analyzing my case, its likely my shared VPS was affected and hackers came over from one of my neighbors. They found the WordPress sights and started dropping malware. That is, I have static sites hosted there and none of them were affected. Only the sites that run PHP apps, specifically the WordPress sites.

venkata.mutyala avatar
venkata.mutyala

That would be a KVM/Hypervisor level hack, no?

managedkaos avatar
managedkaos

No clue. I also suspect a bad/hacked plugin that allowed system access on in my home dir on the VPS.

One of the things that caught be off guard, is the spammy stuff installed as a plugin with a valid looking name or was not listed altogether. so when i logged in and updated, i would just update the base WP and any plugins that asked for it.

After folks reported the malware, I started looking at the home dir and found lots of cruft (that i didn’t create/install).

1

2024-09-27

    keyboard_arrow_up