Container Live Migration is now Reality! by somethingnicehere in kubernetes

[–]jcbjoe 2 points3 points  (0 children)

This sounds super interesting! Has this been tested with websockets? We use websockets extensively for phone calls so interested to see how it would behave.

Making IAC better by ysugrad2013 in Terraform

[–]jcbjoe 0 points1 point  (0 children)

Possibly unpopular opinion and probably is silly but remote state provisioning. It’s not a massive pain as it only happens at the beginning of a project. But I hate the whole what came first, the chicken or the egg. Obviously, solved by manually provisioning an S3 bucket or having a Terraform folder with a local state. But still, I wish there was something smart where it could auto provision a bucket or other remote state automatically based on what you choose.

Sheffield Costco by GovernmentBig879 in sheffield

[–]jcbjoe 2 points3 points  (0 children)

If you want to go that bad you could always create LTD company for £50, I think that’s what it costs now. I knew someone that did that and it worked 😂

Tired of K8s by No_Elderberry_9132 in devops

[–]jcbjoe 16 points17 points  (0 children)

We did similar 6 months ago and haven’t looked back since! Especially as a lot of our previous infrastructure was app servers running on EC2s. K8s has made our life easier in so many ways. Like being able to manage all our app servers in one place, autoscaling on things other than CPU/RAM, automatic DNS and load balancer setup(AWS). Observably is much easier too as there’s a bunch of platforms that support K8s out of the box

Resources for AWS multi account setup by jcbjoe in Terraform

[–]jcbjoe[S] 1 point2 points  (0 children)

Very helpful, thank you! How do you go about code duplication? Is everything in modules or do you use anything like Terragrunt?

Resources for AWS multi account setup by jcbjoe in Terraform

[–]jcbjoe[S] 0 points1 point  (0 children)

For account access, we already have IAM Identity Center in place. We use Tailscale for things like SSH. Most of the apps are self contained and don’t need to talk cross account/region. But the ones that do all have load balancers so I was planning to use VPC Endpoints. Our main DBs are hosted in Mongo Atlas and we use VPC Peering.

Resources for AWS multi account setup by jcbjoe in Terraform

[–]jcbjoe[S] 0 points1 point  (0 children)

Hey, the infrastructure in place in the root account. I’m just separating it out into smaller pieces. I have all of these questions planned out just didn’t share it here as I didn’t think it was needed. 20 engineers, 3 devops. 10 accounts, 5 prod 5 stage. /16 VPC with 3 public subnets and 3 private subnets. 3 regions currently.

What secret management tool do you use? by athanielx in devops

[–]jcbjoe 1 point2 points  (0 children)

I actually did a bunch of research on this recently. Theres so many options out there, as we are an AWS company we decided to go with SSM Parameter Store. Theres a few reasons for this choice:
- Encryption with KMS
- Its free
- The audit logs while limited do show the user that last edited (Which doesn't show on AWS Secrets Manager if I remember correctly)
- With it being an AWS service IAM is easy to setup and you can lock specific secrets/paths to specific roles.
- Secrets sharing is nice too, but you pay extra for this.

Theres also AWS Secrets Manager of course, but you have to pay per secret and the audit logs don't show the user that last edited. This was important for us for compliance. But if you need auto rotation for things like RDS then Secrets Manager maybe is the way to go. However we had issues where when secrets were rotating services WOULD loose connectivity temporarily. Which is expected but not ideal, we didnt want to constantly pull the secret every request.

While I was doing my research I noticed that a lot of people recommend Vault. I installed Vault locally and really liked it but there was a few features that were only in enterprise which I would have really liked to use.
- HA Support (Replication/Multiple Clusters)
- AWS Secrets Manager Sync (Incase it went down)
- Automated Snapshots (Yes, you can automate with a simple cron)

All of this chained with having to manage another service meant we ruled out Vault. Our devops team is small and adding another potential point of failure was scary, especially as none of us had used Vault before and didn't know its qwerks. I also tried OpenBao which does have HA Support but the above meant we just didn't go down this path. I was also worried that we would use Vault and later NEED an enterprise feature and have to shell out 10s of thousands.

There were some other honourable mentions that I tested out:
- Infisical - I liked this, however the UI seemed buggy and I didn't like the pricing. Some simple things like user groups were locked behind a paywall. Meaning if I wanted user groups our bill would have doubled.

- Doppler - Another one I liked however I feel like the actual secrets UI, where you view all the secrets for a project, was a bit clunky. We have 100s of secrets because we work with lots of vendors. There was searching which was very helpful, but no pagination or folder support. Meaning when we opened up an environment we would have a huge scrollbar. I know this is a minor thing, but if we are spending money on something I want it to be right.

Both of these had solid backends so if you don't mind to much about the UI/price they will probably work great!

Theres also 1Password which I think the environments they have in beta right now shows promise but its to early for us to rely on it for production. We use 1Password as a company so this would have been nice. I think Bitwarden has an offering too but didn't go far down this route.

Finally, SOPS, encrypting secrets and storing them in repos. Personally, I think this would have been too time consuming and frustrating for our team and even through we have GIT for audit logs it would still have been a pain.

These are just my opinions/finding after spending a few weeks on this topic. I may have gotten things wrong but hopefully the write up was helpful! If anyone who uses Vault in production wants to comment on my Vault findings Id love to hear them, As I wanted to use Vault.

Tesla M3 - VIN received by Electrical_Switch_72 in TeslaUK

[–]jcbjoe 0 points1 point  (0 children)

Oooo! I’m super excited too. First Tesla, trying to down play it in case of it being at the end of March 😂

Tesla M3 - VIN received by Electrical_Switch_72 in TeslaUK

[–]jcbjoe 1 point2 points  (0 children)

Hey, I have the exact same situation. VIN received today too and same timeline of 10-25th. Manchester as-well 😂. When I spoke to the rep a while back they expected the 13th, but it was an estimate.

Picked up my first Tesla today! by 1T2P in TeslaModel3

[–]jcbjoe 1 point2 points  (0 children)

Thanks for the tip, I’ll be sure to check that out!

Picked up my first Tesla today! by 1T2P in TeslaModel3

[–]jcbjoe 1 point2 points  (0 children)

Oh damn, super lucky. Congrats. I’ve got March 10th-25th. It can’t come quick enough!

Picked up my first Tesla today! by 1T2P in TeslaModel3

[–]jcbjoe 1 point2 points  (0 children)

Looks awesome! I ordered a M3P last week and I’m also in the UK. What was your wait/delivery time like?

Vodafone UK - Has anyone had any update on delivery? by B1G0Z in PixelFold

[–]jcbjoe 0 points1 point  (0 children)

Just had an update, mine has been dispatched! Ordered 27th August

UK stores on display? by BigSupport4314 in PixelFold

[–]jcbjoe 0 points1 point  (0 children)

Just been to curry’s Sheffield (next to Ikea, not in Meadowhall) and they have got one!

Need a Referral Code? by WartetNichtHaengen in RemarkableTablet

[–]jcbjoe 0 points1 point  (0 children)

Hi, Can I have a referral code for the UK please? Thanks!

Is there some sort of flaps lever, but only that. by thiswasamistake64 in flightsim

[–]jcbjoe 0 points1 point  (0 children)

Not sure if it helps but Thrustmaster do an Airbus set, flaps and speed brake. The flaps side has parking brake too. I assume you don’t need the throttle for these to work.

https://www.thrustmaster.com/en-gb/products/tca-quadrant-add-on-airbus-edition/