274 karma · joined March 1, 2018
Changes to those groups happen solely by the PR process.
HR, is only responsible for adding them to the single group which allows single sign on access not does not give any other access.
I don't care how safe it is, its nowhere near as safe or reliable as the sales and marketing are pushing. I wish it was criminal how misleading tesla has been regarding reliability, and regarding how close they are to full self driving.
I currently see myself in a position where I'm responsible for direction of a platform.
What best practices are there around common things like urn, config management, infra provisioning, and other common components.
I have my best practices, which I could enforce on users. But how do I know what is most important to focus on.
The actual product is pretty decent. They have sane defaults for security and unlike their open source product they enable security by default.
The management of it sucks. Management console is tied to a single email, theres no MFA, and the ui is only good for creating es instances. Anything production that stores data and open to public internet full stop must have MFA.
I'm not sure what elastic should have done here, but this is not the right move.
A dev moving to sre will often need to be taught the importance of documentation, how to have smaller immediate impacts and a customer service mindset.
Theres a middle ground that is difficult to find, but is essential to balance the value you bring to the company with the amount of future work you're making for yourself.
Some of the worst sre I've seen involve a dev taking the title and refusing to support, collaborate, or communicate. Alongside a former sysadmin that refused to document, bypassed ci/cd process, and constantly declared tasks as impossible.
When I'm interviewing a sre candidate I focus on identifying if this person has behaviors that make them Ill suited for sre. Technical skill is often easily faked, and your behaviors around how you admit you don't know are more telling than you not knowing.
Companies who can do this correctly and cheaply will be able to charge for this service.
Why is a molecules with high energy density so difficult to break down?
Why are there so few natural decomposers of plastics?
Is this because bacteria haven't evolved the correct enzymes, and many other non plastics globally have bacteria consumers that we can just assume that they decompose naturally?
Comparatively, how often do those vehicles cause deaths while directly taking control of the vehicle.
It's actually a somewhat decent way to catch cheaters. As it provides a better likeness score between two code comparisons.
The effort to make that change was significantly less than the continual effort required to deal with the pressures. From a cost perspective their decision makes sense, from a customer perspective less so.
After that close understanding of logical operations like cut, or negation, and the most important was how certain operations could really impact performance to the point the were mostly "outlawed".
It's been years since I've used prolog, but I could probably pick it back up in a few weeks.
This and the other two bugs can be particularly nasty when doing something such as an arena allocator or any other means of user memory pools.
After an incredibly long slog on some particularly nasty corruption issues years ago I was only able to identify the problem by using ld preload and patching memcpy with some simple value and boundary checks for these three problems. Each of them was a source of the corruption.
Sure the default is now main. But for a few months teams came up with their own standards. Now when I'm working on large scale changes across many systems I continously have too be aware of these new defaults.
trunk main dev develop main prod Canary ...etc this is time I wish I didn't have to spend. The amount of effort I've had to spend has done nothing to benefit race relationships and of course we still have master branches laying around.
Cdc also enables all sorts of non obvious changes that are infra focused. It's much easier to update your version of sql server, db2, mongo, etc. If you don't have to worry about every other app and how it connects to your shared service.
You may think that you're being smooth by updating a A record or Cname when doing a migration but very often there's an app out there accessing using an ip.
I can say that we've had our troubles with kafka sure. But app teams 100% love working with it instead of having to have familiarity with all the various data sources we have.
Working with all sorts of different data but all of its kafka is much easier than all sorts of data from Many data sources.
The alternative is modifying your app for arbitrary data access and dealing with auth or giving direct data access.
Giving direct access to your database is fast but leads to very strong data coupling.
Exposing the data through the app layer is slower than cdc kafka integration but comes with a long term commitment to support that access. I have seen these type of data access queries easily hit performance edge cases.
There are other pros and cons but those are the ones that end up being the most troubling.
Often a single apps data can be incredibly valuable and many teams want to access it. So coming up with patterns that
1. Protect the app 2. Protect the data store 3. Decrease the maintenance cost of the app 4. Decrease maintenance cost of the datatype 5. Add sight complexities from kafka.
Can be very valuable.
This means you don't have manage this yourself.
Figuring out how to buy the right one, and then getting frustrated with cross-platform.
Note that I had a beta minecraft account years ago... but I never used it. They did a similar thing a few years ago and people had to migrate their accounts.
Let's hope they don't fuck it up like league. Their account conversion changed my username because I had another account with same login in a different region.
Banks are still in the stone age when it comes to NIST and cyber security.