CommPulse

CommPulse

1163 parked Settings

The cross-site community pulse: gold-layer posts + comment threads read live from the Communication Hub, ranked by importance. Turn a post into Discord / LinkedIn / X.

redditdevopsView on Reddit

When I type "google.com", first my browser checks its DNS cache, then the OS cache, and if it still doesn't find the IP, it queries the configured DNS server. Once it gets the IP address, it reaches the Load Balancer, performs the TCP three-way handshake, and then establishes a TLS connection. Once the secure connection is established, the browser sends an encrypted HTTP request to the Load Balancer. The Load Balancer forwards the request to a suitable backend server based on its routing rules. Now let's talk about what happens within the server. The request is processed, the service does whatever work is required, maybe querying a database, calling another service, or executing some business logic, and then sends the response back. But how did the browser send the request in the first place? Your home router uses DHCP to assign your device a private IP address from its pool. Your ISP provides your router with a public IP address. When your browser opens a connection, the operating system assigns it a random ephemeral source port. The router then performs NAT, more specifically PAT, by mapping your device's private IP and source port to its public IP and another source port. It keeps this mapping in its NAT table so that when the response comes back from the server, it knows exactly which device and which browser connection the data belongs to. Once the response reaches your browser, the browser decrypts the HTTPS data using the established TLS session and renders the webpage. HTTPS works over TLS, so both the request and the response are encrypted while in transit. When the connection is no longer needed, the TCP connection is closed, which also ends the TLS session, although modern browsers often keep the connection alive for a while so they can reuse it for subsequent requests. submitted by /u/Bitter_Teaching_2905 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

I'll admit not the best m365 admin since I do not support a big company and just do not do a lot of stuff with it so I thought I would ask. I have been updating documentation in regards to a small non-profit that I support and ensuring that if something were to happen to me then someone would be able to pick up and continue on. One area I missed was making sure that the M365 accounts had a back up authorization capability vs the MS authenticator on my phone. I had a yubikey so I configured things and added the yubikey to the admin account and that is working now BUT it does not allow me to use any other MFA except the passkeys. I understand that passkey/security keys are phishing resistant and better than the codes but I would still like the option when logging on to have the passkey AND the authenticator option available, again right now only passkey is the option. I think it is something I need to change with the conditional access policy, I have passkeys defined but I also have standard MFA defined (2 separate) policies but when I log on it does not present any additional options vs passkey. Anyone know what I am missing? Thanks submitted by /u/bishoptf [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

I want users to be able to use Bluetooth only for passkeys for Microsoft 360 login. Windows Hello will not work for us, so BT is the only option. However, I need to lock it down so users cannot connect bluetooth devices to their workstations. We use Sophos EDR and while it is support to block BT devices, I find it still allows them to connect and it is not reliable at blocking. Thanks. submitted by /u/No_Loss_3996 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

I have come to believe that authselect profiles are a literally unworkable solution. That is, I believe it is literally impossible to create authselect profiles that will interoperate with all imaginable PAM configurations in all cases. It is likely, in computer theory, an undecidable problem. This stems from the fact that PAM allows for conditionals and gotos, while authselect profiles generally hope that you can just toggle lines of PAM code in and out to enable or disable different features. So, for example, if I want to implement MFA, and I want to allow for EITHER password/OTP OR ssh publickey/OTP, I can do this in PAM. But in doing this, I have created code complex enough that it is literally impossible for a set of authselect profiles to have this be a toggle-able feature along side other toggle-able features. The question isn't, do you agree with me. The question is, is there a forum where I can have a productive conversation about this that could actually lead to a better overall design in the long run? submitted by /u/thomasafine [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

afi.ai legit?

by chronopunk

Looking for a 365 backup for a small company and afi has come up in a few places, but I haven't heard much about them. Are they solid? Any gotchas in the pricing? I saw one review that said the bill kept going up and they had a hard time canceling, but I'm not sure how much to credit that. Thanks. submitted by /u/chronopunk [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

Howdy all, I have a new VOIP setup through Ring Central for my home office and have been struggling with poor call quality. I'm able to understand the person on the other line fine and vice versa, but the audio sounds tinny, slightly muffled, and just thin/cheap for lack of a better word. Noticeably worse than when I make calls on my iphone. I am a solo business owner and will be using this line to call out to new and existing clients so it's very important to me that call quality is as good as possible. I've been using my cell for the past 5 years. On to the technical side of things, I am using a Cisco 8851 desk phone with a Jabra Engage 65 SE headset. The desk phone is hardwired with an etherent cord into my router, and I have gig internet. My internet download speed shows as 915 mbps, upload is 40 mbps, latency is 8 ms and jitter is 1 ms. I disabled SIP ALG on my router settings, and the cisco phone is set to use OPUS codec. On the cisco admin portal I have HD voice enabled and bandwidth set to high. I have the same low call quality issues when calling with the Ring central app off my cell phone, which leads me to believe the issue is with the ring central servers. Whenever I call their support though they just tell me they show the quality is fine and close the ticket. I've asked them to confirm the codec they have the account set to, but they don't seem able to do so. Any ideas? I'm tempted to switch VOIP providers at this point, but would be a lot of work, and maybe I'm just expecting too much out of this system. submitted by /u/Joel_Hirschorrn [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

After filling out the startup form from Barclays Eagle Labs, I received a referral code for the Microsoft for Startups program. As a result, I was credited with $100,000. I’ve been emailing support for three days now, asking them to increase my limits for creating machines with GPUs. Support keeps lying to me and isn’t doing anything. They’re denying my requests to create machines with GPUs via email. Where should I turn? Does anyone have any contacts? submitted by /u/AppropriateBoard8397 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

I recently inherited a network component that collects syslogs from various Network devices at my firm. I have checked the Azure costs, Azure LB costs are 800€ for processing 370TiB in July month (private, internal only LB). The 10 collector VM scale set instances behind this LB cost 600€. The VMs, LB are in the same subnet, region.. We do have an Enterprise agreement, it's not that our firm is going bankrupt. I just find it funny that bandwidth costs within the same region (without peering) surpassed the actual infrastructure costs. Have you guys observed something similar? Edit :: Unfortunately, most of the syslogs are UDP bound & sent as soon as they are written, there is little to no compression. This blows up the bandwidth costs. submitted by /u/anxiousvater [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

I have seen people suggesting the fix is to disable IPV6 on the NICs. Doesn’t that put Windows in an unsupported state and potentially break functionality even if you don’t actively use IPV6 networking in your environment? submitted by /u/Fabulous_Cow_4714 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

Web gui for BIND9?

by AgreeableIron811

I am on the hunt for the best UI for my BIND DNS server to use at an enterprise level. I have found some, but they are either too old and not really functioning, or they are GitHub repositories maintained by a single user. How is this? I have also found one that I like, but I can't wholeheartedly say that the code would be suitable for production. Do you have any suggestions? I have also used Webmin, but that's not what I'm looking for. I have also managed bind sevrers manually before without gui. But I am not sure how you guys do it today in 2026? submitted by /u/AgreeableIron811 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

New video diving into STANDARD service endpoints! https://youtu.be/HK6irXQNv2o 00:00 - Introduction 00:19 - Compute and PaaS 02:18 - VNet to PaaS communication 03:04 - Service endpoints 06:16 - Scale and complexity issues 06:57 - Standard service endpoints 07:12 - Network Identifier 08:26 - Network identifier association to subnet 09:07 - Enable NID with a service endpoint 09:39 - Details around Network ID use 10:34 - Demo of assigning NID 14:09 - Using NID with many subnets and service endpoints 14:54 - Associating NID RBAC 16:17 - Using NID to access PaaS resources 16:28 - Using a Network Security Perimeter 17:31 - Updating NSP to accept inbound NID 18:47 - Demo updating NSP 19:57 - Using NID with many NSPs 21:20 - Supported services 22:08 - Don't reuse public IPs with regular services 23:20 - Service endpoint policy support 23:36 - Pricing 25:05 - Scalability solution 25:50 - Close submitted by /u/JohnSavill [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

Where does Amazon Bedrock end, where does Strands start and what is AgentCore actually for? I built the smallest thing that uses all three and wrote it up. Posting in case it saves someone else the same head-scratching. Disclosure: I work for AWS. This is my own blog post and video. It's all one question "what should I make for dinner?", answered three ways: Raw Bedrock via the Converse API. Call bedrock, it runs inference and answers. Ultimately asks you what's in your kitchen, because it can't see anything you don't tell it. A local Strands agent with one tool, get_pantry, and the agentic loop. It's using the same model but now it checks the pantry and builds a real recipe. I didn't write an orchestrator or a parser, Strands is the harness that runs the tool-calling loop. This same agent deployed to AgentCore Runtime. Managed serverless endpoint. Four CLI commands the whole way (create, dev, deploy, invoke). A few things that tripped me up: agentcore create doesn't give you a blank project. It scaffolds a working sample agent (an add_numbers tool plus an example MCP client). Turning it into my agent came down to two file edits, the model ID and the tool plus prompt. The runtime deploys with networkMode: PUBLIC, which reads as scary and isn't. It means reachable over the internet, not open to the world. Every call still needs IAM SigV4 or an OAuth bearer token. "Anyone can call it" really means "anyone you grant bedrock-agentcore:InvokeAgentRuntime to." The CLI-generated IAM execution role is fine for a demo, but the AWS docs say those are meant for dev and test. Scope it to the runtime ARN before anything real goes behind it. Teardown is backwards from what you'd guess. You run agentcore remove all -y then agentcore deploy -y. You deploy the emptied config to tear the resources down. Cost is close to nothing on Free Tier. Chapters 1 and 2 are local Node plus a Bedrock call (this costs a little bit per inference call). Only the deploy makes billable resources and you remove them at the end. agentcore dev serves on port 8080 by default (override with -p <port>). Gotcha: if 8080 is taken, the server quietly moves to 8081 but the invoke still calls 8080 and fails — so pass the same -p to both the dev server and the invoke, e.g. -p 8099 on each. Stack: Node and TypeScript, Claude on Bedrock. Link to full written walkthrough Link to same build as a video on the AWS Developers channel if you prefer video format Happy to answer questions. I usually build Strands agents in Python, but wanted to try this one in TypeScript. If you see something you'd do differently, or you've got tips for anyone else on this stuff, please share out. submitted by /u/j-vogel [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

As an indie developer, I built an AI chat app that I want to release soon. I primarily built on Haiku given my cost. When GPT 5.6 came out I was curious to compare my chatbot with GPT 5.6 Luna, but then learnt that my account did not have access to any GPT 5.6 models because my account was new and new accounts have restrictions on expensive AI models. But now that GPT 5.6 Luna is 5x cheaper than release and ~4x cheaper than Haiku(that I already have access to), I am very interested to switch to Luna for my app before release. I have created a support case request, but I heard that the mods on this group have leverage to get things moving faster. Would the mods be able to help me here? Any other tips to get access to this model or improve my chances of approval? submitted by /u/DragonWarrior55 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

I ask, as someone striving to move up into sys admin related roles. Tier 3 / infra.. I have a BS in IT and about 6 years experience. My career took a bit of a detour. I spent almost two years doing solo IT at a school and I hated it. I definitely had a taste of sys admin work, but without some technical aspects. I am currently back on a tech support team where I finally getting more hands on with a hybrid setup (on premise AD with Intune and Entra..) One consistent thing in my 6 years of IT, is that most infra guys I talked to had no certs at all. The exception was Network admins. Some had the CCNA. I don't tend to learn very well under pressure and I also struggle to want to spend upwards to $400 on a cert. That is a lot of money. I am sure it must depend a lot on what exactly I want to do. I was studying the MD-102 and learned PowerShell and will conitinue that, but I am not going to get the MD-102. Longterm I am interested in Cloud, but also open to hybrid. Overall, I just wonder if there is a bit of a hype for certs. I notice people who press really hard into them are those who are struggling to break into IT. Not those who 6 years experience. The only difference is that I am wanting to push past help desk and I'll have to either force my current experience to work for me or get certs. I just started my current job so I have no idea what all I might be able to get my hands into. Overall, I wonder if many sys admins don't even have certs. Or if you feel it was important for you. submitted by /u/New-Device-5166 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

Hi everyone, I was browsing the official AWS Free Tier page, but I'm finding it a bit tricky to properly filter and separate the "Always Free" services from the "12-Month Free" trials. I have two main questions: Is there a direct link or clean list showing strictly the Always Free services along with their exact monthly allowances (e.g., Lambda 1M requests, DynamoDB 25GB, CloudFront 1TB, etc.)? What actually happens to the account, data, and resources once the 12-month free trial ends? Does AWS delete instances/data, or does the account simply transition into standard pay-as-you-go pricing for any non-Always-Free resources? Do the Always Free quotas remain active indefinitely on the account even after year 1? Thanks in advance for any insights! submitted by /u/ZealousidealCrab5086 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

I'm fixing a Windows 11 Home laptop for one of our MSP customers, and he gave me his Microsoft account email and password. I logged in just fine to his MS account and the laptop with matching serial is indeed listed there. I need the Bitlocker recovery key to attempt to fix the OS damage and get it to boot. I hit Devices then "view recovery keys" or whatever it is on that page and it starts to load the next page then changes the URL slightly and tries to load again then goes back and forth in an infinite loop and never actually loads. I let it go for like a minute and it just reloads the page on a loop. I was in an inprivate Brave window so I figured there's a lot going on there lol. So, I tried a normal window in Firefox - same problem. Tried it in Edge with zero plugins, same problem. Tried it in a blank unmodified WIndows 11 VM in Chrome, nope, same problem. Thought maybe MS has a problem with our IP address or Fortinet web filter is having an issue? I logged into his account on Chrome on my Android phone with wifi turned off so it's using straight to the tower. Nope, same problem. Infinite page load loop. Is this some known problem? Anyone else seeing it and any way around it? Can I view it on a different URL/domain that actually works or something? Microsoft service health status website says everything is working fine (which is commonly a lie) submitted by /u/CeC-P [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

I have an opportunity to get a new job from help desk to a tier 2 position for double my salary. I didn’t sleep last night because I’m so nervous about it. Reality is my resume is good but has gaps and I need to communicate how my troubleshooting skills, ability to work under pressure, and being able to be a team player and effectively escalate tickets qualifies me for the job. Any last minute advice would on how to handle a phone interview would be much appreciated. I’ve been studying and writing answers using the STAR method and questions like, “Tell me about yourself,” “Share your experience in your current role,” “Why are you looking for a new position?” I’ve researched the company and have a good answer as to why the job itself and what they do is of interest to me. I’m worried I’ll over-index on stories of how I help users and why they like me, and I’ll just say a bunch of bullshit. submitted by /u/MENTactual [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

Hello. I'll just get straight into it. I am looking for ways to set the default printer for any user that signs into specific PCs. We are talking multiple lab environments with printers that are assigned to the COMPUTER, not the user. Classroom environment. I am trying to avoid applying configuration to users. I have to believe there is some way to make it so when you sign into a computer, you get assigned a default printer based on the computer's settings. Also, this should work regardless of whether the user has signed in before or not. Take it like this Printer1, Printer2 and Printer3, and Lab1, Lab2, and LAb3 - they are paired accordingly by the number. Labs are their own OUs, we place a GPO in the OU that says "Map printerX" (numbers respective.) No, I do not want to pay for papercut or printlogic. We actually moved away from them for issues, I dunno, it's before me. We have a print server set up and GPOs (not using GPPs) to map the printers to the computers. The only issue is we want that mapped printer to be the default printer when users sign in. I'd like to avoid removing all other printers (print to pdf is still really useful.) I've read a few different ways to assign default printers, but many don't seem to account for wanting a user-agnostic solution. I'm looking for something that will work. Fingers crossed someone might have a suggestion. The only thing I'm really considering is GPP in the user configuration with loopback processing so it only applies to the computers in that OU. I've heard that can slow down Group policy quite a bit though. I've read about setting a scheduled task that runs on log-on to map, but wouldn't that run under the system context still if I am setting it via computer configuration? Thanks. Sorry if I come across bumbling, uninformed, or otherwise. submitted by /u/JrSysAdminZ [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

Hey Azure folks, After years of building and maintaining Azure DevOps platforms I wanted to share patterns that actually work when you have real operational demands and compliance requirements. The challenge most teams face: You start with basic CI CD and it works fine. Then you add more services more environments more compliance requirements and suddenly everything is on fire. How do you scale pipelines without creating unmaintainable mess How do you automate infrastructure without creating constant drift How do you implement security without sacrificing speed How do you keep teams confident enough to deploy multiple times a day I documented what actually works including: Multi stage pipeline architecture with proper approval gates and dependency management Complete YAML pipeline example showing real patterns not toy examples Infrastructure as Code with Terraform integrated into your pipelines Automated testing and security scanning that catches actual problems Workload Identity federation so you never rotate credentials again Branch policies that enforce quality without being theater Container scanning and vulnerability management Connecting Azure DevOps with other tools so engineering and product actually stay aligned The real lesson I learned is that automation at scale isnt about having fancy tools. Its about building processes your team actually trusts. Clear gates proper approvals the ability to rollback in seconds if something goes wrong. I have documented this with code examples architecture diagrams and real lessons learned from actual production deployments. Please check the comment below https://www.reddit.com/r/AZURE/comments/1vegsoi/comment/p1grv62/?utm_source=share&utm_medium=web3x&utm_name=web3xcss&utm_term=1&utm_content=share_button What deployment patterns are you using in your environments What gotchas have you hit that other teams should know about What do you wish you knew when you started scaling your pipelines Would love to hear what works for you and discuss the real challenges of DevOps automation at scale. submitted by /u/muaadasif [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X