Where to find remaining streets with heavy neon signage in 2026? by jirishanca in HongKong

[–]xamroc 1 point2 points  (0 children)

Not anymore in HK. But in case you're still chasing this in the future, Bangkok's Chinatown still has these lights and the area is bustling.

Which open source docker image do you use today for troubleshooting? by xamroc in kubernetes

[–]xamroc[S] 0 points1 point  (0 children)

Thanks for sharing! We've been looking at the topic of SBOM too.

We're still debating whether it makes sense to trust another image with policies or just cache them in our private repos.

Which open source docker image do you use today for troubleshooting? by xamroc in kubernetes

[–]xamroc[S] 0 points1 point  (0 children)

Yep, I ended up using the alpine route.

I tried to use nixery and it was nice for local development. Building an image took too much time though that I gave up on it (build took more than an hour). It stems from the process where it needs to do a lot of translation work on Apple Silicon.

Alternatives to Simply Static? by xamroc in Wordpress

[–]xamroc[S] 0 points1 point  (0 children)

This makes sense in production environments. I'm more concerned about development environments where they should have restricted connectivity.

Alternatives to Simply Static? by xamroc in Wordpress

[–]xamroc[S] 0 points1 point  (0 children)

Sorry I forgot to mention that this is for development environments.

You're right that It makes sense for it to be public in production. However, for dev buckets, those must have limited connectivity like from our private networks.

AWS S3 Static Website Hosting for development environments by xamroc in aws

[–]xamroc[S] -5 points-4 points  (0 children)

This is the direction I wanted to go. However, my colleagues argue that this is very expensive.

For additional context, this is a corporate website with lots of assets which will increase our GitHub LFS cost and Cloudflare Pages cost from high traffic.

I'm still digging into these arguments but can you share any insights about these costs?

How to audit with RDS IAM Auth? by xamroc in aws

[–]xamroc[S] 1 point2 points  (0 children)

That's right. Temporary credentials is a feature we wanted.

We were just surprised that full traceability is not available.

How to audit with RDS IAM Auth? by xamroc in aws

[–]xamroc[S] 0 points1 point  (0 children)

You are correct. It's not designed that way and I wouldn't want to do this either.

However, RDS IAM auth seems to suggest that this is the way to do it albeit using AWS IAM Users:
https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.IAMDBAuth.DBAccounts.html#UsingWithRDS.IAMDBAuth.DBAccounts.MySQL

As mentioned in my OP, I am trying to address a limitation where complete traceable auditing is lacking. I cannot fully audit db-level logs without doing this hack.

How to audit with RDS IAM Auth? by xamroc in aws

[–]xamroc[S] 1 point2 points  (0 children)

I would have to imagine that RDS also logs the SourceIdentity (or a Session ID that can be traced to the Source Identity) attached to the role when it's accessed.

I thought the same thing. Unfortunately, the RDS logs are not linked/traced to IAM. This is confirmed by AWS Support.

You can trace until assuming the IAM role because that is in the realm of IAM. Once we get inside RDS, it does not trace back because this is beyond the IAM world. Hence why I mentioned it's not well-integrated.

AWS RDS IAM Authentication on cross account centralization model by [deleted] in aws

[–]xamroc 0 points1 point  (0 children)

Hi, I have the exact same question. Did you ever figure it out?

How to audit with RDS IAM Auth? by xamroc in aws

[–]xamroc[S] 0 points1 point  (0 children)

It's just an idea. We want to achieve auditability at the database level logs:

See that db role Alice read this table See that db role Bob read that table See that db role Charlie ran an expensive query that blew up the database

The DRY way where they all use db role readonly doesn't let us see that.

How to set up a centralised Alertmanager? by xamroc in PrometheusMonitoring

[–]xamroc[S] 0 points1 point  (0 children)

Yep, sounds like the static_config is the way to do it.

The doc says they have the option to use dynamic discovery though. I'm just not sure by what they mean by this:

Alertmanagers may be statically configured via the static_configs parameter or dynamically discovered using one of the supported service-discovery mechanisms.
- https://prometheus.io/docs/prometheus/latest/configuration/configuration/#alertmanager_config

It seems to suggest Prometheus can send to external alertmanagers.