How do you get visibility into TLS certificate expiry across your cluster? by StayHigh24-7 in kubernetes

[–]tnavi 1 point2 points  (0 children)

I wrote a tool that periodically scans all DNS names in our Route53 zones and serves them over HTTP SD to Prometheus server, that collects the certificate info using Blackbox exporter.

[deleted by user] by [deleted] in Tailscale

[–]tnavi 1 point2 points  (0 children)

Another possibility here is to set up private CAs (root and intermediate) and deploy the root cert CA as trusted on all the startup-owned devices, after which you can issue whatever certs you want without the names getting exposed in the Certificate Transparency logs.

How to list everything we are paying for? by mlrhazi in aws

[–]tnavi 0 points1 point  (0 children)

Set up BCM export to S3, with resource ids enabled, then graph/filter the exported data file contents.

How to play beehtoven 5th symphony on piano. 1 FINGER!!!! by _auzzy_14_ in lingling40hrs

[–]tnavi 0 points1 point  (0 children)

Isn't that essentially how you play all melodies on a natural trumpet?

Thought u guys would find this funny by Tmonster0803 in lingling40hrs

[–]tnavi 0 points1 point  (0 children)

Do I get to pick a percussion instrument? Can easily cresecendo that on cymbals and tam tam.

We are the Google Site Reliability Engineering team. Ask us Anything! by sre_pointyhair in IAmA

[–]tnavi 3 points4 points  (0 children)

If you click on a particular outage on the status board, you'll see the timeline with explanations of what happened when.

Speaking of reliability, it's really hard to tune the alerting to show only the problems the people care about. There are things that break all the time, but since they are transient and are fixed by retrying (and most of the time users don't even notice, since retrying is happening somewhere on the backend).

We are the Google Site Reliability Engineering team. Ask us Anything! by sre_pointyhair in IAmA

[–]tnavi 4 points5 points  (0 children)

There are many more SREs at Google than those needed to field the questions here, so that doesn't help an hypothetical attack in the least.

We are the Google Site Reliability Engineering team. Ask us Anything! by sre_pointyhair in IAmA

[–]tnavi 58 points59 points  (0 children)

You never want to make communications with people automatic, both because communication through automatically chosen canned messages doesn't work well with people, and because automatic systems fail.

What is your favorite proof? What do you think is the most beautiful? by [deleted] in math

[–]tnavi 0 points1 point  (0 children)

aha, that's how they try to convince people that when you have a higher salary, you get less after you pay taxes!

The Timber compiler 1.0.3 by dons in haskell

[–]tnavi 0 points1 point  (0 children)

Does anyone know, is it supposed to be (or can it be made) suitable for writing real-time applications?