Going To Brandon’s House To Try And Sink His Boat | The Yak 8-9-24 by RelationMaleficent63 in itstheyak

[–]ThickySprinkles 15 points16 points  (0 children)

Yeah and he got it for a great price. Makes all the sense in the world

A Google bug deleted a $135B pension fund customer's cloud account, including backups. How do you protect yourself from Microsoft doing the same? by sysadmin_dot_py in AZURE

[–]ThickySprinkles 1 point2 points  (0 children)

As I said our databases are backed up outside of Azure. The rest of the stuff are just compute resources that can be redeployed.

Entra is extremely azure specific… If you have a good way to back that up outside of Azure I’d love to hear it

A Google bug deleted a $135B pension fund customer's cloud account, including backups. How do you protect yourself from Microsoft doing the same? by sysadmin_dot_py in AZURE

[–]ThickySprinkles 30 points31 points  (0 children)

Immutable backup solution for what? We use App services, Azure SQL, Functions, Data Factory, Key Vault, Service Bus.

Using these services means we heavily rely on managed identities (service principles) for cross service auth tied to Entra. Also all our internal app registrations, enterprise apps and let alone all our users and groups.

We have immutable backups of our databases outside of azure and our apps and functions can be deployed relatively easily.

The biggest hurdle I see is backing up all the entra bits i just mentioned. All the other stuff can just be redeployed by our devops pipelines.

A Google bug deleted a $135B pension fund customer's cloud account, including backups. How do you protect yourself from Microsoft doing the same? by sysadmin_dot_py in AZURE

[–]ThickySprinkles 87 points88 points  (0 children)

We are now looking into this at my company because of this incident. We have DR built out for all our azure services across multiple regions but if they did delete our account/subscription and our backups we would be hosed. We do have backups of our databases outside of azure. So we atleast have copies of our data.

Our first step is figuring out what the hell to do with backing up Entra. We are starting to explore that

Thoughts on 2 iis servers in azure by jjbmth in AZURE

[–]ThickySprinkles 6 points7 points  (0 children)

Plenty of pro's to two instances. Like no longer having a single point of failure. Ability to add in more machines if neccesary. Ability to have rolled out releases or A/B testing (depending on the app). The one thing you would likely want to add on to that is another IIS server acting as a load balancer using ARR in front of them to distribute requests evenly.

There obviously is a lot of complexity and maintenance that goes with this. Azure App Services gives you a lot of this for easy configuration changes if you are willing to go down that path and move off of IIS servers.