CommPulse

CommPulse

1166 parked Settings

The cross-site community pulse: gold-layer posts + comment threads read live from the Communication Hub, ranked by importance. Turn a post into Discord / LinkedIn / X.

I got a very not expected 500+ euros bill from Azure, which is very hard for me to understand. I used the agents on the marked day probably, but not nearly as they reported, and even technically speaking, this usage is waaay over Azure's model limit. I have a limit of 40k tokens a minute, which is annoying sometimes, but it (should) help prevent cases like this. The graph of input token used show a minute with over 4M tokens. https://preview.redd.it/xc2ei9lcirgh1.png?width=826&format=png&auto=webp&s=20bacbff3d4596890a2c990c25a6fdc67efb67b5 That does not really reflect my use (you can see earlier that evening a small usage of few hundred tokens, that is usually my usage and the rate limit). Did anyone encounter something like that, or maybe someone can help me understand how this was possible? I am assuming they made a mistake honestly submitted by /u/hummus4everyone [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

Ich habe bei Kiro ein Abo abgeschlossen temporiere gedacht für einen Monat. Problem einer Geschichte ist ich kann das Abo nicht mehr ab bestellen und Sie buchen weiterhin ab. Ich habe mich dot an den Support gewandt. Und keiner hat geantwortet. Ich hab's wieder getan und wieder und wieder und wieder. Keine Antwort weiterhin Abbuchungen. Jetzt ist die Frage wie komme ich an den AWS Support ran? Weil das Ganze anscheinend über AWS läuft submitted by /u/Ramba22187 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

Account Verification

by No_Abbreviations_429

3 days ago our AWS account was marked suspended without any notice . We're a startup, building our first product and being locked out of the account is painful right now. All the documents and verifications that were asked have been submitted. Still awaiting resolution. Has anyone else gone through this experience? submitted by /u/No_Abbreviations_429 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

Hi everyone! I have a phone interview for the AWS TAM position in a couple weeks, and I want to try my best to be as prepared as possible for it. Does anyone have any advice on how I could best do so, as Ill be honest Ive tried compiling resources to prepare myself but was a bit overwhelmed with some of the conflicting information on what to prepare for. I'm aware it will predominantly be technical with some behavioural questions, but how should I prepare exactly for the interview as a whole and with what resources? submitted by /u/CryingBananas23 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditdevopsView on Reddit

I did a dumb exercise last week: sat down and wrote out every tool that touches a single deploy on my team, start to finish. Not “tools we have licenses for”, just the ones actually in the critical path of getting one change into production. Landed on 14. Source control. The CI runner. A separate container registry. An image scanner that runs after the registry push. A secrets manager. The Kubernetes dashboard we check for rollout status. A log aggregator. A separate APM/tracing tool, because the logs don't show latency well on their own. An alerting tool that is, confusingly, different from the paging tool. A DNS/cert dashboard. A cost/billing dashboard nobody opens until the invoice is a surprise. The ticketing system for the actual incident. And a chatops bot that glues some of this together, badly. None of these were wrong choices individually. Each one was probably the right call in isolation, at the time it got added. But nobody ever sat down and asked whether this thing talks to the other 13. It's less a stack and more a pile that happens to work most days. What's bugging me isn't the number itself. It's that almost nobody on the team could tell you the number without doing this exercise. We just live inside it. New hires take weeks just to learn where to look when something breaks, and that's before they've learned what any individual tool actually does. So, genuinely curious: if you did this exercise on your own team, what would your number be? And more interesting to me: which of your 10+ tools do you think is actually load-bearing, versus which one is just... there, inherited from a decision three engineers ago that nobody wants to be the one to rip out? Not fishing for “just consolidate everything into one platform” as the answer. I don't think that's automatically true either. Sometimes the sprawl is a symptom of real, unavoidable complexity, not laziness. More curious whether other teams' numbers look like mine, and whether anyone's actually fixed this in a way that stuck. submitted by /u/Complete_Sample_3149 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

Eventually this entire system needs to be torn down and rebuilt, but I need a "temporary" solution that will work for now until that is done. Existing Setup : Server: Windows Server 2019 It is not a DC, because no on-premises AD is being used. Running an ancient accounting program. Shared Folders, which must be Mapped as Network Drives on client machines running Windows. Users defined locally in Windows Server with permission to access Shared Folder. Client Machines: Windows 11 Pro Managed by InTune Login via Entra credentials. Manually mapping a Network Drive for each User to the Server, using their local User defined on the Server. I'd love to be able to Map the Network Drive using each user's Entra credentials, but to do this, the Windows Server would have to be aware of the Entra Users. I know there is no great way to synchronize users from Entra back to an on-premises AD DC, but that's not really what I need. I just need to be able to authenticate Shared Folder access with Entra credentials. Could the Windows Server act as a "pass-through" where it hands off authentication to an LDAP server? I've already set up the AzureAD-LDAP-Wrapper on my local Synology to allow for Entra-based authentication of the Synology's Shared Folders, and it's working well. Is there any way I could point the Windows Server to that same LDAP Wrapper, and then set permissions for the Shared Folders on the Windows Server based on those LDAP users? I'm thinking maybe this is what I need? Configure AD FS to authenticate users stored in LDAP directories in Windows Server 2016 or later Does anyone have any experience trying to do something this stupid? submitted by /u/ZippyDan [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

Our department is finally getting a budget to replace the decade old seating in the server room. I personally use an Hbada X7 Prestige at home and the Alcantara material breathes surprisingly well. The purchasing guy wants to buy those cheap fake leather chairs off Amazon to save money. How do I convince him that synthetic leather is a terrible idea for a room that runs warm all day. submitted by /u/Robin4god [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

Does anyone have any idea on the above question? Both technologies have been available for a long time now - is there some technical reason we can’t have paas windows containers? Is there is, I’d be interested to know what implications that has on aks submitted by /u/catmanjan2 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

Hi, I chose this provoking title on purpose. I am pretty fresh with a small amount of experience (5 years). Our current team lead left the company to look for a different opportunity for his last ten years before retiring. He’s been here for 20+ years and wanted a new experience before enjoying his retirement. Anyways, our CIO told me he sees potential in me and already gives me great challenging projects as he is confident in me. Obviously, I aspire to be the team lead I’ve ever wanted. But I have no idea what my proper duties are. We are a small ish company (250 employees) and I have 5 people under me. As I am pretty young (almost 30 yo), I find it difficult that the older guys will listen to me. Anyone has tips for me? I feel this is the right step into the direction I want to go in. I got a new contract with a good added amount of money and I see me being here for many more years. Sorry for the rambling, I’m a bit nervous. Our CIO will announce his decision in the next week. Thanks and have a great weekend! submitted by /u/DoubleShotStrong [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

Hello, I was able to configure the extension and when I distributed the extension with team they are not redirecting to microsoft idp instead of that they are moving to quick sso, so i am getting error of “something does not compute” Please help us here, i have opened the support but as we don’t have business plans it will take days to be get response team. I am not able to find any documentation as well, AWS document only shows the entra setup create extension and distribute to user but i think it is not working for me. If someone here has already setup that please help me submitted by /u/minor_one [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditdevopsView on Reddit

https://preview.redd.it/bhyfdt5t9pgh1.png?width=1920&format=png&auto=webp&s=e13f6a15dac958b9f4dbcf651a8ef954cf940098 A production server rebooted after an unattended kernel update, which made me rethink how Linux patching should work in production. Rather than just disabling unattended-upgrades, I designed a patch management system around controlled promotion and governance. The approach uses: Aptly for internal package mirrors and immutable snapshots PostgreSQL to enforce promotion gates and maintain an audit trail Grafana for fleet health and CVE visibility Two-phase rollback to revert both the repository and client packages I wrote a detailed article covering the architecture, design decisions, and trade-offs: BLOG: 2ssk.medium.com/patch-management REPO: 2SSK/patchops I'm curious how others handle patch governance. Do you use internal mirrors, Landscape, Satellite, Foreman, Custom tooling, or something else? What has worked well (or poorly) in your environment? [AI has been used in drafting this post] submitted by /u/ban_rakash [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

Any One has any solution on how to solve this error . I am on free tier as of now submitted by /u/Sad-Variation-2598 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

My boss gave me three older workstations to use as a Proxmox cluster. Older in the sense that they are of the DDR3 era anyway he also gave me a UPS and bought two FS 16 port switches for me to set up in an MLAG configuration and learn from my home. Anyways, I was commenting on how I wish I had a PDU to remotely power on and off machines as sometimes like I had to get out of the house and I was working on a net boot project, which meant that if it didn’t work, I had to go home and physically restart the machine lol. Well, he went in the basement of his house and found these two older Minuteman 1600s with the SNMP card in both of them. I was able to find drivers, the Manuel, and even the SMP software for Windows thanks to the Internet archive/Wayback machine they function perfectly and so I’m just wondering, how great of a PDU is this? Is it even technically a PDU I currently have it plugged into my UPS, but since I’m terrified of ruining it, and I know search protectors can be an issue, I wanted to see if anyone who might be familiar with these older machines had any insights or things I should know or do in regards to configuring them or setting them up in a specific configuration We also just got to Pixel 10a’s to run GrapheneOS on as he’s pretty big on privacy and security. He bought them out right so they’re unlocked, but if there’s anything I should know in regards to setting that up, it would also be appreciated. I’m well familiar with flashing custom ROMa and such but things have changed since I was running cyanogen mod on my Samsung Galaxy Nexus lol. Thanks in advance to everyone in this community for making me feel welcome and reassuring me that I’m in the right place because some of that imposter syndrome has seriously lifted as I’ve begun to work with my first clients and projects that will actually be used in prod. submitted by /u/drake90001 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditgooglecloudView on Reddit

Hey everyone, I recently published a technical walkthrough on the Google Cloud Blog around hardening IAM access using IAM Conditions . If you've ever struggled with binding built-in roles (like Project IAM Admin or MCP Tool User roles) to principals while restricting them to only subset of permissions or resources because of lack of support for resource-level bindings or API granularity, IAM conditions will fill that gap for you. Key patterns covered: Scoping projectIamAdmin : For example, instead of giving a builder service account (SA) unrestricted power to assign any role at deployment time, you can use the CEL function iam.googleapis.com/modifiedGrantsByRole to restrict the SA so it can only grant a predefined list of roles (e.g., BigQuery job user, Cloud Trace agent, Logging writer). Included both gcloud CLI and Terraform snippets. Restricting Model Context Protocol (MCP) Tools: The roles/mcp.toolUser role grants access to all MCP servers in a project. Using api.getAttribute('mcp.googleapis.com/tool.name', '') , you can constrain access down to specific tools (like mcp_bigquery-mcp_execute_sql_readonly ). Contextual & Time-Based Access: Brief examples of restricting execution windows using request.time (e.g., weekdays during business hours). Read the full post here: https://cloud.google.com/blog/topics/developers-practitioners/generosity-under-conditions-hardening-google-cloud-access-management/ Curious how others here handle IAM admin restrictions or fine-grained MCP tool access in production? Let me know your thoughts or feedback! submitted by /u/m1nherz [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditdevopsView on Reddit

I’ve been working on an open-source reference implementation of an agentic DevSecOps container-release pipeline. The goal was to keep security decisions deterministic while using an AI agent only to explain findings, prioritize remediation, and make scanner output easier for engineering teams to act on. The pipeline includes: zSonarQube source-code and quality analysis Trivy Dockerfile and Kubernetes misconfiguration scanning Local container-image build Trivy vulnerability and embedded-secret scanning Deterministic release-policy evaluation Claude Sonnet 5 or Google ADK advisory triage HTML, PDF, Markdown, JSON, and SARIF reports Email delivery through Resend Discord notifications Protected human approval Docker Hub publishing only after authorization For the demonstration, the workflow processed an intentionally insecure training fixture and found: 13 SonarQube findings 25 configuration misconfigurations 347 container-image vulnerabilities 372 total Trivy findings 74 policy-blocking findings The workflow continued scanning long enough to collect complete evidence, but the deterministic policy kept the release BLOCKED . Human approval and image publishing were skipped. The Claude advisory successfully analyzed a bounded subset of the scanner evidence. It prioritized remediation and explained possible attack paths, but it could not approve, reject, waive, or override the deterministic policy. The design principle is: The pipeline generates three primary reports: Code and configuration security report Container vulnerability and secret report Consolidated release-security report Repository: https://github.com/DevOpsAIguru123/awesome-agentic-devops/tree/main/agents/container-image-release-advisor Demonstration run: https://github.com/DevOpsAIguru123/awesome-agentic-devops/actions/runs/30590931717 This is an open-source reference implementation rather than a universal production template. Production adoption would require organization-specific policies, isolated builds, artifact signing, provenance, registry controls, and continuous monitoring. I’d appreciate feedback on: Whether AI advisory analysis belongs inside the release pipeline or should run asynchronously How you deliver security findings without overwhelming developers Which additional supply-chain controls you would add Whether a deliberately blocked security workflow should appear red or use a successful “blocked as designed” conclusion submitted by /u/Individual_Walrus425 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

I’m more of a network guy, I don’t work on web servers all that much. I have an internal server, A, that allows external traffic on port 4040, and there is an external server, B, somewhere on the internet that wants to pull data from A. But I want to run all network traffic through a DMZ first, so I put a VM running nginx inside the DMZ… And here is where my understanding gets a bit fuzzy. Server B points to the public IP of the proxy server and sends its request > nginx on the proxy server receives the request from server B and then passes that request to server A > ??? How does server A know to send the requested data to the proxy server? Is there anything I need to configure on server A so it sends the data to the correct server? Also, just ignore any firewall rules in this scenario, I’m not concerned about that. Thanks submitted by /u/heavyPacket [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

We are going to require privileged admins to use device bound passkeys, but we are considering allowing synced passkeys for standard users due to Android version compatibility with device bound passkeys. We cannot require everyone to have Android 15 or higher to reliably support device bound passkeys. Using synced passkeys will allow users who were using SMS 2FA to avoid installing dedicated work apps on their personal phones. Synced passkeys work with the pre-installed iOS and Android password managers plus some third party password managers they may already have installed. However, syncing passkeys has certain risks that using the Microsoft Authenticator app doesn’t have. The Authenticator app Microsoft Work credentials do not sync to every device the user signs in to, unlike synced passkeys. Does this make using synced passkeys for Entra sign in more of a security risk than using password plus 2FA via an authenticator app? submitted by /u/Fabulous_Cow_4714 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

https://preview.redd.it/py187mvx1ogh1.png?width=1055&format=png&auto=webp&s=7ab6509afed08b26651a52697514c88dd05ca01e Does anyone know what this is? I don't have an IAM user with this name. It appeared as an AWS::STS::AssumedRole entry in CloudTrail. I've searched everywhere, but I couldn't find any reference to it. submitted by /u/luizarodrigues [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

Despite mixed feelings on AI, I've been put in charge of deploying enterprise AI and internal agents. Management wants productivity ROI. The problem? Our IT environment is structurally hostile to automation. We run Windows 11 on 16GB laptops with a kernel-level DRM client that: · Encrypts every single file automatically · Blocks screenshots and copy-paste · Logs every file action Add 3 cloud drives (only 1 used), 2 endpoint managers, app blockers, disk encryption, Teams, Copilot, and a separate HQ chat suite. Machines burn out constantly. Culturally, we're zero-trust and hierarchical—speaking up is discouraged. Yet my division is all highly vetted researchers (Masters/PhDs) generating our own IP, no trade secrets. Everything we encrypt is literally the output of our own brains. My AI-ready vision: configurable sandboxes for agents, 100% trust for senior talent (managed via education), AI-first comms, on-prem RAG/backups, selective encryption, biometric MFA, frontier pen-testing, and ZDR with AI labs. Our investment becomes browser Q&A chatbot (pushing employees to leak data into personal ChatGPT to get real work done.) The question: Is there a sensible staged migration path from this mess, or is the DRM architecture so foundational that we need a greenfield rebuild? Our sys admin is solid - he’s just following mandate from above. The problem (I believe) is the decision makers operate with a strict top down mindset and I assume each manager has gone for the safest move to CYA. Is this a stupid idea to ask my sysadmin to brainstorm a greenfield pilot architecture I could possibly make a business case for? Or should I find a way to pass the buck like everyone else? submitted by /u/Jealous-Depth487 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X