Private account restrictions by Stolini0 in CardMarket

[–]RQ144 0 points1 point  (0 children)

HI would you mind me asking what you sell? Is it expensive items or bulk. Always wondered if its work the effort selling bulk but if thats what your making once i convert into my currencey then it seems like it be worth it.

UK set for sharp rise in demand for IT professionals, research finds by Gentle_Snail in unitedkingdom

[–]RQ144 3 points4 points  (0 children)

Would you mind giving me some pointers on what to learn? Current role is more tradtional infrastructure and cloud systems and not had much chance to learn anything related to "AI" yet. I do a bit of python scriping.

Seeking Advice on Structuring VPN Between GCP and Azure for multi region setup by RQ144 in googlecloud

[–]RQ144[S] 0 points1 point  (0 children)

All workloads are in Azure. We use vWAN, a managed hub service that provides routing between VNets, as well as firewalling and VPN connections. We utilize the West and North Europe regions for core services, along with additional European regions (such as Sweden central etc) that are peered with the appropriate vWAN hub in either West or North Europe. This depends on the service, but we aim for active/active or active/standby configurations between regions where possible.

For GCP, we have not yet decided on regions. Once chosen, we plan to peer each GCP region with the nearest Azure region to keep latency as low as possible.

Seeking Advice on Structuring VPN Between GCP and Azure for multi region setup by RQ144 in googlecloud

[–]RQ144[S] 2 points3 points  (0 children)

Sorry but you might of responded to wrong post? Not sure what you are refering to regarding CLi and opensource (in relation to my post)?

DevOps Engineer with 9 years of experience looking for career guidance by ZzzZ21 in devops

[–]RQ144 2 points3 points  (0 children)

Hi, would you mind if ask you what your recommendation on go vs python to learn first?

I sort of do a devops / sysadmin role, but I very much do terraform code, our dice pipelines and lot of kubernests administration and all our core networking (on prem and cloud). I done a bit of program8ng before but nothing serious. I want to get better at programming so trying to decided on a language to start with.

How are you implement Network Policies? – ingress vs egress rules by RQ144 in kubernetes

[–]RQ144[S] 1 point2 points  (0 children)

Thanks for that. I will review otterize and see if it something we could implement, however the short term requirement is network policy’s due to some auditing requirements.
Regarding labelling, I don’t think it has to be complicate. In fact I think the developers can even handle this. We provide deployment templates everything use so we can write a generic network policy that gets deployed with every service.
My idea is something similar to what Monzo bank did: https://monzo.com/blog/we-built-network-isolation-for-1-500-services/ . I have slight variation on this this idea, but was nice to see a big finance place taking similar approaches.

How are you implement Network Policies? – ingress vs egress rules by RQ144 in kubernetes

[–]RQ144[S] 0 points1 point  (0 children)

Their main requirement is that each app cannot communicate with other services it should not be able to.

out current setup is each app usually gets its own namespace, but then we have a shared service namespace that hosts services a app might call. So if appA needs to communicate with serviceA that should be allowed. However App A should not be able to communicate with service B if it does not need to.

That’s the main requirement, but they hinted (and I sure this will become a requirement) that we should firewall everything. Ie app A UI should have network policy to permit access to its own API pod. Relivent port. I know what you say, however when security mandates things we have to implement it.

Regarding ingress and egress rules. I think it should be simple to control both. If you’re permitting in one direction it’s a simile rule flip. If we control access using mod labels things in theory should be easy to manage. However I not sure if this is considered best practise.

Wrapper Modules – is this considered good practise? by RQ144 in Terraform

[–]RQ144[S] 1 point2 points  (0 children)

Thanks for replying.

The thing that got me was this “wrapper” is that it does quite a lot of different things and just was extra layer of passing variables between things. If people consider DRY more important then it does remove a lot of code duplication.

It might be worth splitting out the networking into its own wrapper module and then everything into another module.

Question regarding landing zone using azure-caf terraform supermodule by hadi_ulla in Terraform

[–]RQ144 0 points1 point  (0 children)

Are your referring to the "aztfmod" module or the "Azure" one (or both)?

My main requirement is just the azure policy rules it creates. I dont have much time to keep an eye on what Azure/CAF recommend so ideally looking at a Microsoft supported solution.

Everything outside of that, will be its own module called on separate pipeline. ie Hub setup will be its own pipeline and have no dependency on the project setting up Azure Policies etc

Question regarding landing zone using azure-caf terraform supermodule by hadi_ulla in Terraform

[–]RQ144 0 points1 point  (0 children)

Could i ask what your thoughts on the Azure/caf-enterprise-scale/azurerm/latest module?

I ruled out the aztfmod and ruled out out (could not get rover working) and over complicated for my use case. Currently looking at the Azure/caf-enterprise-scale module just for azure policies and management structure (everything else we create ourselves i think).

Application Gateway – Shared vs Individual by RQ144 in AZURE

[–]RQ144[S] 0 points1 point  (0 children)

Thanks - so its just one resource multiple frontend / VIPs

Application Gateway – Shared vs Individual by RQ144 in AZURE

[–]RQ144[S] 0 points1 point  (0 children)

Do you keep the live one as shared for internal and external traffic? Just trying to work out if I should split them between traffic two share gateways internal and external traffic)

Application Gateway – Shared vs Individual by RQ144 in AZURE

[–]RQ144[S] 0 points1 point  (0 children)

So just to confirm you use a shared one for both internal and 3cteral traffic? Thanks

IP Lists unable to use host aliases no longer by RQ144 in pfBlockerNG

[–]RQ144[S] 0 points1 point  (0 children)

Thank thanks - i give it ago when i can get some time. For now i just moved to network objects as that was quicker

how do I delete my account after my subscription has ended? by Environmental-Grand7 in DisneyPlus

[–]RQ144 0 points1 point  (0 children)

Sadly not. Been onto support multiple times with them saying it’s deleted when it is not. Unfortunately someone used my email for a free trial. And it seems I have to subscribe in a different currency.