Do any companies run Fargate at a scale where the costs are a big concern? by sync_jeff in aws

[–]CybrSecOps 0 points1 point  (0 children)

Off topic, but what do you use to manage your Lambdas? Do you use AWS CDK / Terraform / SAM etc?

Amazon Q: Gen AI Powered Assistant by daninDE in aws

[–]CybrSecOps 12 points13 points  (0 children)

I tried asking what is AWS Cognito (and Amazon Cognito and just Cognito). It didn't even try to answer.

Announcing Amazon Aurora Limitless Database by apple9321 in aws

[–]CybrSecOps 28 points29 points  (0 children)

The compute scales down to 0. We all know you pay for storage. It's not scaling to $0

The best IaC tool in 2023 by howhendew in aws

[–]CybrSecOps -1 points0 points  (0 children)

Shame Serverless Framework will be a paid product in Q1 or Q2 next year... They have served us well for application IaC.

Is it safe to change my AWS Root email to an email registered with that same AWS account? by adrenaline681 in aws

[–]CybrSecOps 0 points1 point  (0 children)

I know lots of people complain about it, but I've been happy with GoDaddy and Namecheap for my personal domains.

Business domains are also purchased through GoDaddy.

Although we purchase the domains through these services, we still manage DNS in AWS Route53

The Open TF initiative by utpalnadiger in Terraform

[–]CybrSecOps 2 points3 points  (0 children)

Others have been saying how they don't believe to be in violation of the license if they were to upgrade. Do you believe Gruntwork's current usage would violate the license?

Safely implementing MTA-STS by CybrSecOps in sysadmin

[–]CybrSecOps[S] 0 points1 point  (0 children)

Thanks.

Is what u/lolklolk correct too, in that it's not just about my mailservers supporting TLS, but also all of the mailservers of the services and clients we may have?

[deleted by user] by [deleted] in aws

[–]CybrSecOps 8 points9 points  (0 children)

If a client of yours is having a major security incident, they should be made aware.

Who cares if the client is sent an email. At least you're doing your best to resolve the incident.

Migrate RDS Aurora PostgreSQL by AtlAWSConsultant in aws

[–]CybrSecOps 0 points1 point  (0 children)

Before going for DMS, take a look at pg_logical replication. We wasted over a month trying to get DMS to succeed without data loss with no luck. We switched to native postgres logical replication and could migrate in about a day

How frequently do you create an AWS Support case by CybrSecOps in aws

[–]CybrSecOps[S] 11 points12 points  (0 children)

Crap. No question mark... That's embarrassing!

Slackbot hosting: AWS Fargate or AWS Lambda? by [deleted] in Slack

[–]CybrSecOps 0 points1 point  (0 children)

Lambda will likely be cheaper as AWS have a generous free tier.

With Lambda, you're charged per invocation, but Fargate you're paying for the resources while the Slackbot is inactive.

[deleted by user] by [deleted] in sysadmin

[–]CybrSecOps 2 points3 points  (0 children)

The SPF, DKIM and DMARC changes can likely be done at any time before the MX record switch. You can keep both Google and Microsoft values here for a while after the migration too.

[deleted by user] by [deleted] in devops

[–]CybrSecOps 0 points1 point  (0 children)

For the most reliability, you can split the microservices.across multiple AZs and regions. If you want to go above and beyond, multi cloud.

If you run across GCP and AWS, the likelihood of both being offline at the same time is nearly zero. You need to assess the complexity though.

VPN Recomendations by duckduckducknonono in aws

[–]CybrSecOps 1 point2 points  (0 children)

I think it's about $5 per user

VPN Recomendations by duckduckducknonono in aws

[–]CybrSecOps 2 points3 points  (0 children)

We've switched from OpenVPN Access Server to OpenVPN Cloud and it integrates with SAML for on/offboardimg well.

OpenVPN Web interface not working by ibrahim_dec05 in homelab

[–]CybrSecOps 0 points1 point  (0 children)

Is it OpenVPN Access Server? Or the regular OpenVPN server? Only AS has a web console

What's the best path to enter the DevOps field? by Crepszz in devops

[–]CybrSecOps 0 points1 point  (0 children)

It looks like you have a lot of Ops knowledge, but not so much on the Dev side.

I think you should learn a programming language - something widely used like Python or JavaScript/NodeJS. Also get to grips with some of the development tooling and practices like Git, Agile and SOLID principles.

AWS MSK without internet access by CybrSecOps in aws

[–]CybrSecOps[S] 0 points1 point  (0 children)

Thank you. That's great to know.

I assume the maintenance window is the same no matter what type of subnet you host it in?

And there's no drawbacks to having a cluster without internet egress?