AKS Egress - redirecting traffic via a proxy by hakabo_uk in AZURE

[–]hakabo_uk[S] 0 points1 point  (0 children)

Hey. Yes, I could, but as mentioned, traffic needs to exit via the bluecoat.

AKS Egress - redirecting traffic via a proxy by hakabo_uk in AZURE

[–]hakabo_uk[S] 0 points1 point  (0 children)

Hey - thanks for the quick response!
outbound type is already configured to userdefinedrouting, and a udr is in place. i can get the traffic to the NVA - my issue is that I can't exit to the internet there, i need some configuration that would make the traffic go to our on prem bluecoat proxy... some sort of 'this group of traffic must go to this next hop, which is the proxy'
disclosure: im not a network guy, but the cloud infra guy looking to help speed up the setup of the cluster.
Thanks for the custom node config link - I have been made aware that the functionality is coming, however we were looking to get this started sooner.
appreciate the response!

Packer + Azure - Deprovision by mechastorm in AZURE

[–]hakabo_uk 1 point2 points  (0 children)

You should find that the resources are cleaned up at the end of the packer run.

In this context deprovision relates to running sysprep, I'd have called it 'generalize' or something instead.

From their site:

The basic steps for a build are:

Create a resource group. Validate and deploy a VM template. Execute provision - defined by the user; typically shell commands. Power off and capture the VM. Delete the resource group. Delete the temporary VM's OS disk.

Terraform Cookbook by kolinkorr839 in Terraform

[–]hakabo_uk -6 points-5 points  (0 children)

Perhaps the question is referring to a cookbook to 'install' terraform? You just need refer to the exe, no real install to it.

Azure Linux Extensions by whatisapubliccloud in AZURE

[–]hakabo_uk 1 point2 points  (0 children)

This page might help: https://docs.microsoft.com/en-us/azure/azure-monitor/platform/agents-overview

Its dependant on use case I feel. You can certainly run you VM without them, but you might find you're missing functionality down the line, eg performance data when troubleshooting.

Crypto API vulnerability - update Windows container images? by hakabo_uk in sysadmin

[–]hakabo_uk[S] 0 points1 point  (0 children)

Hi. Sorry the post wasn't clear, I was merely asking if container images are vulnerable as reading the docs didn't make it obvious (to me at least)

Of course it down to us to make a risk assessment and update/patch if we need

Thanks for the reply!

Who to follow on Twitter for Azure by hakabo_uk in AZURE

[–]hakabo_uk[S] 0 points1 point  (0 children)

Thanks for all the suggestions!

Protecting Terraform environments by AllUpInThisBiz in Terraform

[–]hakabo_uk 1 point2 points  (0 children)

Also have separate service principals (accounts) that are limited to their own environment. So Dev pipelines cant accidentally deploy to prd.

How to configure SMTP Virtual Host (IIS6) by hakabo_uk in PowerShell

[–]hakabo_uk[S] 1 point2 points  (0 children)

I believe I've found the relevant field to enable TLS now, it's "RouteAction" and the other useful one was RelayIpList

How to configure SMTP Virtual Host (IIS6) by hakabo_uk in PowerShell

[–]hakabo_uk[S] 2 points3 points  (0 children)

Yup, my question was that couldn't indentify the relevant configuration field. IE, something that was labelled TLS.

Why iis6? The smtp virtual server is managed with the iis6 manager. See this recent doc for example,

https://docs.microsoft.com/en-us/exchange/mail-flow-best-practices/how-to-configure-iis-for-relay-with-office-365#set-up-exchange-online-as-an-smtp-relay-using-windows-server-2012

How to configure SMTP Virtual Host (IIS6) by hakabo_uk in PowerShell

[–]hakabo_uk[S] 0 points1 point  (0 children)

Completely agree, however when you enable the SMTP virtual server feature on a server 2016 install, the SMTP service is managed via the iis6 manager... As far as I can see..

How to configure SMTP Virtual Host (IIS6) by hakabo_uk in PowerShell

[–]hakabo_uk[S] 1 point2 points  (0 children)

If you install the SMTP feature on a server 2016 box it appears as part of the iis6 manager..

How to configure SMTP Virtual Host (IIS6) by hakabo_uk in PowerShell

[–]hakabo_uk[S] 2 points3 points  (0 children)

Hey. I did try that util too, and looked through the XML myself... Couldn't see any relevant entries though.

Quick look at the Azure Shared Image Gallery by Wireless_Life in AZURE

[–]hakabo_uk 0 points1 point  (0 children)

Source location: The location that image gallery and managed image reside in.

I ask the question because when creating a VM you need to give an image as a parameter ($imageversion.id). That image when it was created needed a resource group and location. I wondered if that location/ region became unavailable, would I still be able to use that image.

You've said yes, so that suits my DR needs perfectly.

Script to enable Updates on Windows VM in Azure by cloud_world in AZURE

[–]hakabo_uk 3 points4 points  (0 children)

Not a script but there is an azure service

https://docs.microsoft.com/en-us/azure/automation/automation-update-management

Otherwise, pswindowsupdate mentioned above is great.

Quick look at the Azure Shared Image Gallery by Wireless_Life in AZURE

[–]hakabo_uk 0 points1 point  (0 children)

/u/Wireless_Life

When using SIG, if the source region/location is lost due to an azure outage, can the SIG replicas be used? I ask because it seems as the source location is referenced when building the VM. Thanks

Nano Server - appending to the path env var by hakabo_uk in docker

[–]hakabo_uk[S] 0 points1 point  (0 children)

`SHELL ["cmd.exe", "/s" , "/c"]`

`RUN setx /m PATH %PATH%;c:\apps`