CommPulse

CommPulse

1166 parked Settings

The cross-site community pulse: gold-layer posts + comment threads read live from the Communication Hub, ranked by importance. Turn a post into Discord / LinkedIn / X.

redditsysadminView on Reddit

I need a solution for sharing passwords. Current solution that everyone loves: You go to a website. You can enter a password, or have one generated for you. It gives you a public URL. You can choose it to be valid once or for up to 7 days. You give the link to a user, customer, client, whoever. They click it, they get the password in plain text in their browser window. Done. Problem: it's running on an EOL OS, the original programmer is long gone. Need something you get a link, you click it, you get the password. No auth required, can work publicly with no VPN. SaaS solution preferred. submitted by /u/adamtw1010 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

Based on the technical breakdown OpenRemote's maintainers published in their own GitHub Security Advisory earlier this month, here's the architectural impact: The public console registration endpoint is designed for anonymous first-boot enrollment — new console, no creds, register itself. Fine pattern. The problem is the same endpoint's update path: if the submitted id matches an existing console asset, the backend loads it and applies attacker-controlled fields (push provider data, name, version, platform) with no auth header, no ownership check, no realm match. Straight IDOR (CWE-639) sitting in a public write path. Attack precondition is just knowing a valid console asset ID — and the advisory flags that these leak through logs, URLs, API responses, backups, telemetry, support tickets. Not a high bar. Impact: attacker-controlled push token persists on the victim console, redirecting or killing legit notification delivery. Worse in multi-tenant deployments since there's no realm binding at all. Patched in 1.26.2. No CVE indexed on NVD yet as far as I can tell (VulnCheck/other trackers cite CVE-2026-66013, GitHub's own page says "no known CVE" — worth independently verifying before you cite it that way). Wrote up the full attack chain + remediation checklist here for more background: https://www.techgines.com/post/openremote-authentication-bypass-vulnerability-cve-2026-66013 Anyone else seeing IDOR-class bugs specifically in IoT/console registration flows as the pattern replacing classic auth-bypass CVEs this year? Curious if this is a trend in device-onboarding APIs generally or just an OpenRemote-specific miss. submitted by /u/Expert_Sort7434 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

Hi all, Have you ever seen this error on your Dell servers? I’m not sure if this is hardware or firmware issue. Usually prior to this event, the client loses power and then server cannot be powered on again. I either need to remove power supplies and drain the power or in some rare cases, I needed to remove DIMM’s and reconnect. Then it starts okay. More details on errors seen from iDRAC console: The system board fail-safe voltage is outside of range. CPU 1 M23 VTT PG voltage is outside of range. CPU 1 M01 VTT PG voltage is outside of range. CPU 1 M01 VDDQ PG voltage is outside of range. CPU 2 VCORE PG voltage is outside of range. The system is PowerEdge T430, BIOS, iDRAC are on the latest versions. Can it be RAM or settings or hardware failure? TIA. submitted by /u/Le085 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

Just curious how everyone is doing this without reliance on what Accounting uses for their books. If you are given $x budget, how are you keeping tracking of what is spent where, how much on a server, hardware, licenses, etc. If there a centralized way to keep track of all of this that ideally ties into some CMDB or Inventory system for hardware/software. Or is Excel the way to go? submitted by /u/Jaki_Shell [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

I got ip-banned and they told me it was because I had a typo in a URL I entered. The last time I got banned, they said "pressing enter too fast may trigger it". I've not once in my entire life of using the internet (20+ years) have encountered such an annoyingly touchy website. No, this is not some credential based website, a banking website, a government website, or anything high-risk. submitted by /u/ToshPointNo [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

https://craphound.com/overclocked/Cory_Doctorow_-_Overclocked_-_When_Sysadmins_Ruled_the_Earth.html Introduction to When Sysadmins Ruled the Earth Introduction I’ve changed careers every two or three years ever since I dropped out of university in 1990, and one of the best gigs I ever had was working as a freelance systems administrator, working in the steam tunnels of the information age, pulling cables, configuring machines, keeping the backups running, kicking the network in its soft and vulnerable places. Sysadmins are the unsung heroes of the century, and if they’re not busting you for sending racy IMs, or engaging in unprofessional email conduct it’s purely out of their own goodwill. submitted by /u/Eddit13 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

TL;DR: Overwhelmed new sys admin, 2 conflicting bosses, fellow admins leaving. Your experiences? Whoever said two heads are better than one never had two bosses. I am a recent hire at a 200-employee company in France. I originally applied for a help desk role, but was unexpected offered a sys admin role. I was hesitant from the get-go. During the interview, the manager made long spiel about launching projects after projects... as a sys admin sat quietly next to him. When he mentioned that all 2 sys admins were leaving soon, my red flag was higher than Mount Everest. In the end I accepted though. The job market in France is brutal, especially for me as a non-native. At first, it was fine. There's no help desk, but I gladly tackled L1-3 support. There was no ticket system neither, just Teams chats and calls, handled using a spotty remote access app for PCs without any monitoring whatsoever. It was fine, I told myself. I was writing up docs, bettering my French. Administering M365? All good. VoIP system? Sure thing. Router QoS issue? I'll try. As a newbie, it took time, but I did it and made sure I documented everything. Within a few weeks the manager demanded I explain our network topology. He had no idea how everything was connected. Soon he demanded I build a ticket system, ready for production within a few months. I created a rough planning but explained I couldn't promise that timeline as I wasn't even fully onboarded before the departure of the other admins. He wasn't happy. Then I found out I had another manager, the CIO. A living nightmare. He was quietly there the whole time, over a decade with the company. I thought he was a senior dev, as he spent most of his days with the dev team. But no, he's my direct manager.. and I cannot understand him at all. That ticketing system with the planning I made? He re-did with Claude and told me to follow the "handbook". Escalations like declined invoice payments on our licenses or L3 tickets? Can't be bothered with trivial stuff. Discussions about migrating VPN? A long speech about what needs to be done, without an explanation of what I actionably should do. It wasn't until a consultant finally reached out to me after his emails were being ignored that I did "something". At some point, the CIO told me infra bores him. I told myself, that's all right, I have no mentor in him, so I'll try to maintain and improve things the best I personally can.. and count the months when I have enough experience to leave. A few weeks ago we started looking for a help desk intern. I suggested several times that another admin might be necessary, but the CIO said I can handle it alone. I figured, hey, he's a hands-off kind of guy. At least I can choose the candidate that I can work closely with. I even kept him in the loop with HR on the candidate screening process. Radio silence. Today he told me he will be deeply involved indeed. Several levels of interviews planned for each candidate. Technical questions to be developed by him. Yet he still does not talk to HR. He made a weird statement to me once. "For twenty years I had imposter syndrome. I don't anymore." What the hell does that even mean? The thing is, these two heads contradict each other. I will be working on one thing, the other tells me stop focusing on it as it's low priority. The manager will discretely ask me to re-explain concepts explained by the CIO. The CIO will say the manager's decisions are never final. Both declined to validate my vacation, saying I need coverage, then the manager approves after I made him happy with an urgent fix deployment, then the other says we need to hire an intern before approval. It's been three months and I'm exhausted. My heart is racing at work. I scheduled a doctor's appointment. The last admin is leaving soon, the only one who taught me actual stuff. I don't know how I will survive after him. I'm sorry for this long post. I don't have any questions, I just kind of unloaded here. But if anyone experienced something like this, I am curious how it ended up for them. submitted by /u/lemongarble [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditgooglecloudView on Reddit

No Support Available???

by Volpes_Visions

submitted by /u/Volpes_Visions [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

This is my first blog post, developed from a collection of notes in my Obsidian vault. It explores serverless webhook ingestion on AWS, and I’d genuinely appreciate feedback on both the technical content and the article itself. I know the article is long and may combine too many topics in one post, from payload limits and architecture choices to costs, reliability, and operations, but I am sick and tired of superficial takes, SEO-driven content, marketing copy, or AI slop. https://growingbits.dev/serverless/webhook-serverless-ingestion Please tell me where the architecture, assumptions, or explanations could be improved. submitted by /u/MexicanYoda45 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

Hi, I’m a community college IT student in Ontario Canada wondering about if it’s possible to start my career by freelancing for local MSPs? The markets reeeaally bad here for new grads so I’m thinking they’d be more willing to hire a freelancer than take a risk on an employee. I’m also very ADHD and benefit from having my own hours and independence. In terms of skills, I’m good with M365 (Entra, Intune, SharePoint, exchange, graph API), Python, RESTful APIs, powershell, Active Directory, AWS, networking (VLANs, subnetting, TCP/IP model, etc), Linux scripting and commands. I’m also trying to start learning LLM stuff like RAG and vector database cause I think that might be good for MSP automation. I also want to learn servicenow and its API before I graduate. I’m thinking of starting to send out cold emails to MSPs and message people I know from prior years who got jobs at MSPs at the end of this year when I graduate. Is this possible? Or am I just screwed lol. submitted by /u/RelationshipSad4168 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

With MS charging for CoWork on July 1st, we figured we'd still give it a go, since the tool was quite impressive. Microsoft gave us 100k in credit, so we rolled it out to 400-500 users. We spent about 90k of the 100k credit between those users, most of the credits used by the top 10%. At this point we are removing all access until we figure out a better plan and specific business value of CoWork. If someone has a really good idea for an agent that will save time/money, they can use it. Otherwise, it is off the table. I used it a bit, just to test it out. I ran 3 prompts around automated offboarding process I was working on, that was about 24 dollars. If we rolled it out to all 30k users, we'd be around 500k-1mm per month, 6-12mm extra per year, not a small amount, even for a large org. As I said, CoWork is really impressive but CoPilot is going to have to be good enough. submitted by /u/DramaticErraticism [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditgooglecloudView on Reddit

Posting this in case anyone's hit the same wall, or has insight into what's happening server-side. The goal I've got a Nest wired camera pointed at a small parking lot behind my office. I wanted to build something simple: check the lot every so often, count open spots using an AI vision model, and show a live "spots available" number on a little status page. Nothing fancy — just needed a way to reliably grab a still image from the camera on a schedule. What I've built so far Full Device Access / SDM API project setup, OAuth flow, refresh token, the works A Google Apps Script front end (status page + storage) that's fully working and just waiting on real image data Tried Cloud Functions first for the image-capture piece — turns out Cloud Run/Cloud Functions don't support raw UDP at all, so WebRTC media can never actually flow through them (signaling works fine over HTTPS, but the actual RTP video never arrives). Confirmed this is a real platform limitation, not a config issue. Moved the capture piece to a Compute Engine VM instead, which does support normal UDP networking Attempt 1: Pub/Sub camera events Set up the Pub/Sub topic + subscription per the docs, enabled events on the Device Access project, confirmed the publisher permission and subscription are all correctly wired. Validation pings come through fine. Real camera motion/person events never do — not once, across two separate days of testing, with real motion happening right in front of the camera each time. Pulling directly from the subscription (bypassing my own code entirely) confirms it: nothing but the occasional stale permission-check message ever lands in the topic. Attempt 2: WebRTC via aiortc (Python) Got the full offer/answer/ICE/DTLS/SRTP handshake working end-to-end — genuinely happy with how far this got. Audio decodes perfectly, every single time. Video RTP packets are confirmed arriving from Google's server (verified via RTCP sender reports, packet counts climbing normally). But the video frames never make it through aiortc 's jitter buffer / H.264 depacketization — the decoder thread never receives a single video task, despite audio on the same connection working flawlessly. Feels like a real interop gap between aiortc 's RTP handling and whatever Nest's media relay does on the video track specifically. Attempt 3: WebRTC via GStreamer (webrtcbin) Rebuilt the whole capture piece using GStreamer instead, since it's a much more mature, production-grade WebRTC stack. Fixed a string of real issues along the way (missing codec caps causing ICE gathering to never even start, missing data channel per Nest's "must have audio+video+application m-lines" requirement, a couple of SDP formatting quirks). Eventually got ICE gathering to fully complete and produced an offer that structurally matches Google's own published reference example (checked directly against the example in their docs) — same media line order, working negotiation, proper BUNDLE grouping. Sending that offer to GenerateWebRtcStream now returns: { "error": { "code": 500, "message": "Internal error encountered.", "status": "INTERNAL" } } No further detail. I've tried adjusting rtcp-mux vs rtcp-mux-only , port/bundle-only conventions to match Chrome's exact output, Opus channel params, H.264 fmtp params (packetization-mode, profile-level-id) — no change, same generic 500 every time. What's interesting This exact error string ("500: INTERNAL: Internal error encountered.") turns up in multiple long-running GitHub issues against the Home Assistant Nest integration too, going back to 2021 and still being reported this year, with a completely unrelated client stack. So this doesn't seem to be specific to my code — feels like something that trips up the SDM API backend under certain conditions across multiple independent implementations. Where I'm at OAuth, SDM API, and Pub/Sub setup are all confirmed correctly configured ICE/DTLS negotiation completes successfully on the client side Offer SDP structurally matches Google's own documented example The only failure is a completely opaque 500 from Google's own server, with zero actionable detail returned Has anyone gotten a real WebRTC video frame out of a Nest camera via the SDM API recently? Curious whether this is a known current issue, an account/camera-specific quirk, or if there's some other SDP detail that isn't in the docs. Happy to share the full offer SDP / code if it's useful for comparison. submitted by /u/TotallyHorsePancake [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

So I came across aws:GetBatchImage - I was using claude to clean my older images apparently when I pulled I saw some image which are 300 days old and it was in good amount but next day when I decided to pull again the lastpulltime got updated and apparently it was because i was pulling manifest and not the image and there is apparently a different way to disable it by adding exclusion. Updating these detail on last pull actually lets them get you to keep fairly older images and keep on paying for the storage https://github.com/aws/containers-roadmap/issues/2390 https://docs.aws.amazon.com/AmazonECR/latest/userguide/pull-time-update-exclusions-manage.html PS: heading is little incorrect just updating the manifest - its just pulling the manifest submitted by /u/hello-world012 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditdevopsView on Reddit

We had a major production incident a few weeks ago that really exposed how manual our root cause analysis process still is. Incident was pretty standard on paper: error rate spike across a couple of microservices, latency blowup on one critical api, customers hitting timeouts. We have the usual observability stack, distributed tracing, logs, metrics, dashboards, plus tickets and slack channels but getting to "what broke first, and why" was mostly humans correlating tabs manually. The incident response workflow looked like this: jump into the oncall war room, pull up dashboards, zoom in on the time window and pivot between error logs, traces, deploy history, feature flag changes and infra events. someone manually builds an incident timeline, a deploy goes out, error rate spikes shortly after, latency climbs, autoscaling kicks in, db connections start flapping. then another person tries to connect that narrative back to the specific service, function, or config change that caused it, which is the actual root cause analysis part nobody's automated yet. We do have some ai-powered anomaly detection and basic rca signals turned on but in practice they mostly narrow the blast radius instead of giving a confident, explainable root cause. it still feels like humans doing the hard work, with the tooling just providing hints rather than a real diagnosis. Looking for automated root cause analysis tools that can take telemetry, logs, metrics, traces, infra events, together with deploy and feature flag changes and output a credible "this change in this service is most likely the cause, here's why." also interested in platforms where the rca output is good enough to drop straight into a postmortem instead of needing another hour of digging and anything beyond the usual big observability platforms, especially newer ai-native rca tools that sit on top of existing observability instead of trying to replace it, that's noticeably reduced incident triage time or mttr without just adding another noisy dashboard. if you're running any of these in production, what do you still consider "top" for automated root cause analysis today? submitted by /u/Potential_Force_4136 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X
redditsysadminView on Reddit

Sometimes it's the easy fix

by Anonymous1Ninja

Fiber went down, uplink to core.. No activity on link light both sides pull SC connectors, laser, so i know it's not the cable fail over to other uplink is working so I SSH and do a no shut, still off "try replacing the sfps" That was it, an SFP malfunctioned. Thank god it's friday submitted by /u/Anonymous1Ninja [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X

Cloud platforms have made it much easier for teams to build and deploy applications quickly, but I feel the security review process has become more challenging as release cycles get faster. Azure provides a lot of tools for infrastructure security, monitoring, identity management, and compliance, but application-level issues can still be difficult to catch before they reach production. For teams running applications on Azure, what security checks are part of your deployment process before going live? Do you focus more on code reviews, automated testing, manual assessments, vulnerability scanning, or a combination of different approaches? I'm interested in hearing how different teams balance shipping quickly while still maintaining confidence in the security of their applications. submitted by /u/Minute-Vegetable-773 [link] [comments]

Repurpose (generate each channel independently)
Discord
LinkedIn
X