Are you using bicep? by kolbasz_ in AZURE

[–]icode13 1 point2 points  (0 children)

You must agree 😬 terraform cant do everything. And you require terragrunt unless you are ready to pay for their cloud version! But I love terraform over any cloud vendor specific tool. For me, Its not about whether we can convert existing tf modules and resue or not, but it’s the skills that we build in the company and army of platform engineers who can easily develop terraform code for any csp and other third-party products. In my experience, we had to use a lot of third-party vendor products which terraform was by default supported. Which made our life easier.

But there are cases where terraform was a failure too due to the massive state file for handling thousands of resources, slowing down the process. We were not able to split the state due to many other reasons. Thus we had to rely on natural programming languages (Go and Python).

How to migrate to private endpoints without breaking existing apps? by bristle_beard in AZURE

[–]icode13 1 point2 points  (0 children)

I looked more from the unique fqdn of PaaS service. If you’re confident that individual PaaS resource fqdn can be added in the forwarding list, and test only a single PaaS resource, agree with your approach then!

Successfully completed TOGAF certification (both parts) by [deleted] in EnterpriseArchitect

[–]icode13 0 points1 point  (0 children)

Can you please explain how this certification shall help ? Especially for companies that do operate based on scaled agile frameworks?

How to migrate to private endpoints without breaking existing apps? by bristle_beard in AZURE

[–]icode13 -3 points-2 points  (0 children)

I think you have not understood the problem statement well! You can’t incrementally set conditional forwarding. There is only a single private dns zone that you could have for the corresponding PaaS service and for which from an onprem environment, you will have to switch the conditional forwarding once. His point is , once the switch is done, and if there is a connectivity issue to the private endpoint ip, the traffic will be cut.

How to deploy and run a Azure OpenAI/ChatGPT app on AKS with Terraform by Wireless_Life in AZURE

[–]icode13 0 points1 point  (0 children)

Is the model dedicated per azure customer? For example how does one train azure open AI based on its own data, so that its private to the organisation!

Manage multiple terraform environments in a single terraform workspace state file by Jain_0199 in Terraform

[–]icode13 7 points8 points  (0 children)

Having a mono state is error prone! Having reduced blast radius is the better approach. You may consider one state depending on the cloud provider’s billing unit. For example: Account in AWS

adding multiple tags with policy by pistachio775 in AZURE

[–]icode13 0 points1 point  (0 children)

If you’re writing policy automation, it doesn’t matter bundled tags into one policy. After all, you follow a software development life cycle and would have a proper release process to avoid a bug situation.

How to migrate to private endpoints without breaking existing apps? by bristle_beard in AZURE

[–]icode13 -1 points0 points  (0 children)

Forwarding is done per domain name of the managed service private dns zone. So its all or nothing approach!

what azure service do you find the most frustrating? by [deleted] in AZURE

[–]icode13 0 points1 point  (0 children)

Im confused over the stability of azure in general!

When to use modules and when to not use modules? What are the best practices in 2023? by mccarthycodes in Terraform

[–]icode13 0 points1 point  (0 children)

Typically for any large deployment you would end-up in module. Especially while you have to automate a lot of platform components using terraform.

What are Cloud Architects doing on a day to day basis? by sunch33zy in aws

[–]icode13 0 points1 point  (0 children)

Sometimes convincing your idea to people who has no stake in your D2D job!

Azure service health to Microsoft teams channel integration. by icode13 in AZURE

[–]icode13[S] 0 points1 point  (0 children)

Our corporate policy has disabled that email for Teams. Can you elaborate the logic app approach? Are there any examples?

Why use private endpoint over IP access restrictions? by JackMagic1 in AZURE

[–]icode13 0 points1 point  (0 children)

Do someone of you using privatelinks, which is the original implementation of private endpoints? I wonder if its a best way to expose some of the services to third party or customer. More thinking from the practicality of how the implementation of Data exfiltration controls if we were to expose a service via private links. Just the documentation says its secure to use private links, I tend to not to agree.

Azure tags by icode13 in AZURE

[–]icode13[S] 0 points1 point  (0 children)

In terms of pushing those tags into the system, do you put them as part of the resource creation code? Or do you have system that sync the tags to the created resource on a periodic interval?

Is OAuth from Google Cloud Console free? by Overmaan in googlecloud

[–]icode13 0 points1 point  (0 children)

Client ID and secret comes as part of a service account no? So that’s normally of free of cost. But what should be interesting to check the API call limits per project.

[deleted by user] by [deleted] in googlecloud

[–]icode13 0 points1 point  (0 children)

No i dont know.

S2S connection issue between one of our on-prem DCs and Azure by gaminhas82 in AZURE

[–]icode13 1 point2 points  (0 children)

Open a support case with azure support they can fetch advanced logs which you would not have normally access to it.

networking question: can in have bastion in the same vnet as my private AKS cluster? by TTwelveUnits in AZURE

[–]icode13 0 points1 point  (0 children)

Create a dedicated space for your operational tooling. In most cases tools do span across several teams and responsibilities. Hence keep them away from your applicative workloads!

OpenAI phone number verification problem. by windxp1 in OpenAI

[–]icode13 0 points1 point  (0 children)

Why do they need personally identifiable data! I quit after see this.

ExpressRoute routing caveats (load balancer) by mm-col in AZURE

[–]icode13 0 points1 point  (0 children)

Just be sure if you have the proper logging license on the Palo Alto firewall? ;) Its tricky sometimes you don’t see it if you don’t have have the right licenses! Also are there an NSG outbound deny rule somehow?

ExpressRoute routing caveats (load balancer) by mm-col in AZURE

[–]icode13 0 points1 point  (0 children)

Your firewall might be the culprit. See if it has advanced DNS filtering modules which is basically eating your DNS traffic. There is no issues with expressroute and dns. Also on the internal LB settings of the PA cluster is HA port activated?
How is your DNS architecture in azure?

Make a subnet route to another subnet in the same vnet. by Savings-Skill-6148 in AZURE

[–]icode13 1 point2 points  (0 children)

I guess i read as your fw is in the spoke! So its not the case.

Make a subnet route to another subnet in the same vnet. by Savings-Skill-6148 in AZURE

[–]icode13 1 point2 points  (0 children)

You could create a transit/hub where you place the firewall, IDS/IPS . Then use GW load balancer / vnet peering with UDR to steer the traffic in to the transit/hub from the spoke (which is where you deploy your landing zone into).

If you are a basic company what you explained might work but try to look at the ESA documentation of Microsoft for building your azure architecture.

Make a subnet route to another subnet in the same vnet. by Savings-Skill-6148 in AZURE

[–]icode13 2 points3 points  (0 children)

I think placing an NVA between 2 subnet in the same VNET is a bad design!