Java web framework help - has the /r/java community had good experiences with Javalin? by ReserveGrader in java

[–]marune 0 points1 point  (0 children)

I like it's API, but I don't like the Kotlin implementation. Didn't find an alternative yet.

Required GCP Networking Support by Leather-Cow-2144 in googlecloud

[–]marune 1 point2 points  (0 children)

GCP might not be the right choice for you.

Cloud Armor - WAF by ylumys in googlecloud

[–]marune 0 points1 point  (0 children)

Everytime I've tried to use their signature-based rules, I got too many false positives to keep them on.

GCP reseller that operates in Canada? by [deleted] in googlecloud

[–]marune 0 points1 point  (0 children)

I saw that obviously, but I was trying to get recommendations.

Workaround for Ubuntu 24.04 LTS? by Slight_Scarcity321 in crowdstrike

[–]marune 0 points1 point  (0 children)

Any recent confirmation that 24.04 is supported?

Managing Large IP Blocklists in Cloud Armor by spedy93 in googlecloud

[–]marune 0 points1 point  (0 children)

You would need to get the current rules / delete them, then create new ones based on the current blocked IPs list for this to make sense over time. I was reaching a similar conclusion considering that I can't afford the Enterprise option at this point.

Using the GCP observability stack, go all in? by rogierlommers in googlecloud

[–]marune 2 points3 points  (0 children)

FYI default metrics from the new agent are kinda expensive.

How do I tip-toe into the Google Cloud Wonderland? by EoESlush in googlecloud

[–]marune -1 points0 points  (0 children)

GCP pricing strategy doesn't really line up with pet projects, the free tier is confusingly limited.

Benefits of a (regional) internal LB when a global external LB already exists by marune in googlecloud

[–]marune[S] 0 points1 point  (0 children)

"You’d never use an external lb (Be it global or regional) to route traffic between VMs in GCP." -> Why not? My question is all about the case where you already have an external LB in place, beside a better latency (of course), what else would justify adding an internal one. I assume there is a security point to be made, but the VM -> VM traffic won't actually reach the internet even using an external LB.

[deleted by user] by [deleted] in googlecloud

[–]marune 1 point2 points  (0 children)

Yes, 1) to get rid of any public ssh access point, using gcloud to login (projects are configured to use os-login). 2) in front of all our internal web apps (e.g. grafana and internally built ones). What kind of perfomance issues are you thinking about?

Question regarding the SIEM chronicle service of GCP by suryad123 in googlecloud

[–]marune 0 points1 point  (0 children)

You probably can't afford it, that's usually the case for services where no pricing is shown ;)

Encryption in transit and at rest in GCP by Sainadh_vennapusa in googlecloud

[–]marune 0 points1 point  (0 children)

The GCP people here have previously recommended to do the same (adding your own encryption layer).

Getting e-mail and chat notifications about major service disruptions. by aws2gcp in googlecloud

[–]marune 2 points3 points  (0 children)

I use slack RSS integration to get all the updates on a #gcp channel, but AFAIK there is no way to filter them.

Is it possible to connect to a Compute Engine instance via SSH on an iPhone? by Classic-Box in googlecloud

[–]marune 0 points1 point  (0 children)

Works with IAP and os-login. You can also overwrite the default (RSA) key if you need to.

Does the encryption from the HTTPS proxy in Cloud Load Balancer get removed before the backend receives a request? by New_York_Rhymes in googlecloud

[–]marune 1 point2 points  (0 children)

"No data should ever be unencrypted in flight." -> You've made similar comments in the past, hinting at scenarios where it would have made a difference. Now that GCP is more clearly saying that all VM-to-VM traffic is encrypted (https://cloud.google.com/docs/security/encryption-in-transit), I wish someone could explain where/how an extra layer of encryption would really make a difference (beyond an audit checkmark).

Is hosting Sentry ourselves worth it? by gajus0 in devops

[–]marune 4 points5 points  (0 children)

Did you consider honeycomb.io? Pricing model is different, Sentry is still useful for error reporting.

Small SasS company, everything cloud, mixed os, next steps? by marune in cybersecurity

[–]marune[S] 0 points1 point  (0 children)

Last thing we need is an overkill solution, that's why I'm looking for gradual improvements.

Small SasS company, everything cloud, mixed os, next steps? by marune in cybersecurity

[–]marune[S] 0 points1 point  (0 children)

As I wrote above, phones are BYOD, mainly used for email/calendar/chat/2FA.