Issue #36
Read about infrastructure topics and news every week
Nexteam is sponsoring this newsletter. Please tell your friends and colleagues about this publication. Thank you.
Nomad 1.5 beta adds single sign-on and dynamic node metadata
Nomad 1.5 has added new features including single sign-on capabilities and dynamic node metadata. With the addition of single sign-on, users can now authenticate with Nomad using their organization's identity provider. The dynamic node metadata feature allows operators to easily add or remove metadata from nodes, providing more flexibility and easier management. These features aim to improve security, simplify management, and make Nomad more accessible to a wider range of organizations.
https://www.hashicorp.com/blog/nomad-1-5-adds-single-sign-on-and-dynamic-node-metadata
My @heroku account has been deleted, bringing down all my applications
No message, no email. Has anyone ever had this happen to them?
A Safer AWS Organizations Management Role
This post provides guidance on how to create a safer AWS Organizations management role by using the least privilege and reducing the attack surface of the role.
https://medium.com/cloud-security/a-safer-aws-organizations-management-role-e3aa50d543c9
Building a Break Glass Solution with HashiCorp Boundary + Vault
Learn how to design an emergency access account for infrastructure and secrets management using HashiCorp Boundary and Vault. This break-glass solution would enable authorized personnel to gain immediate access to critical resources in case of an emergency and allow for secure secrets rotation.
Microservice Registration And Discovery With Consul In Go
Free Katacoda Kubernetes Tutorials Are Shutting Down
https://kubernetes.io/blog/2023/02/14/kubernetes-katacoda-tutorials-stop-from-2023-03-31/
k8s.gcr.io Image Registry Will Be Frozen From the 3rd of April 2023
The Kubernetes project runs a community-owned image registry called registry.k8s.io to host its container images. On the 3rd of April 2023, the old registry k8s.gcr.io will be frozen and no further images for Kubernetes and related subprojects will be pushed to the old registry.
https://kubernetes.io/blog/2023/02/06/k8s-gcr-io-freeze-announcement/
Kubernetes v1.26: Alpha support for cross-namespace storage data sources
Kubernetes v1.26, released last month, introduced an alpha feature that lets you specify a data source for a PersistentVolumeClaim, even where the source data belong to a different namespace.
https://kubernetes.io/blog/2023/01/02/cross-namespace-data-sources-alpha/
Common misconceptions behind cloud migration failures
This resource examines common causes of failure in cloud migration initiatives, such as inadequate planning, a lack of expertise, unsuitable migration tools, underestimating the complexity of the applications being migrated, and failure to consider security concerns. Additionally, the resource offers advice on how to avoid these challenges and execute a successful cloud migration.
https://ubuntu.com//blog/cloud-migration-failures
Real-time Ubuntu is now generally available
Real-time Ubuntu is now available. The RT Ubuntu release includes a new kernel and toolchain that provide low-latency, deterministic performance for applications that require precise timing and scheduling. The article explains the features of RT Ubuntu, such as the PREEMPT_RT kernel and Xenomai user-space framework, and how they provide real-time capabilities. The article also highlights industries that can benefit from this release, such as robotics, autonomous vehicles, and industrial automation.
https://ubuntu.com//blog/real-time-ubuntu-is-now-generally-available
3 ways to apply security patches in Linux
A short article about applying patches and updating an Ubuntu System.
https://ubuntu.com//blog/3-ways-to-apply-security-patches-in-linux
Kubernetes YAML manifests made easy
Monokle is a set of tools for creating and maintaining high-quality Kubernetes configurations throughout the entire application lifecycle.
Mesa, Disk Encryption, Xfce Packages Update in Tumbleweed
https://news.opensuse.org/2023/02/17/mesa-disk-xfce-up-in-tw/
Monitoring Oracle Servers With Checkmk
How to monitor Oracle servers using the open-source monitoring tool Checkmk. The author describes how to set up Checkmk to monitor Oracle databases, listeners, and other components. The article also provides details on how to configure Checkmk's plugins and how to create custom checks to monitor specific aspects of Oracle servers. Additionally, the article explains how Checkmk can be integrated with other monitoring tools and how to use Checkmk's automation features to simplify server monitoring tasks.
https://www.linuxjournal.com/content/monitoring-oracle-servers-checkmk
What David Flanagan Learned Fixing Kubernetes Clusters
David Flanagan has fixed 50+ Kubernetes clusters as part of his YouTube series, 'Klustered.' He shared what he learned at Civo Navigate.
https://thenewstack.io/what-david-flanagan-learned-fixing-kubernetes-clusters/
https://www.youtube.com/@RawkodeAcademy/videos - @RawkodeAcademy channel
Waiting for Postgres 16: Cumulative I/O statistics with pg_stat_io
A discussion on pg_stat_io view in PostgreSQL, which provides information on the I/O activity of a database. The post explains the columns in the view and how to interpret the information it provides. It also provides examples of how to use the view to identify performance issues related to I/O.
https://pganalyze.com/blog/pg-stat-io
Exposing Postgres Performance Secrets
Long-standing Postgres expert Craig lays out four basic things to set up today to make finding and fixing performance issues faster in the future.
https://www.crunchydata.com/blog/exposing-postgres-performance-secrets
pgpq: Stream Arrow / Parquet Data into Postgres
A new ‘proof of concept stage’ library for streaming Arrow RecordBatches to Postgres in order to bulk load Parquet files. Written in Rust.
https://github.com/adriangb/pgpq
This Month’s Reason Technology will Save the World: Energy Savings and Serverless Principles
Serverless AWS CDK Pipeline Best Practices & Patterns — Part 1
AWS Lambda Layers Best Practices
Best practices for using AWS Lambda Layers to manage and share code across Lambda functions. The article covers topics such as layer versioning, layer size and dependencies, and using layers in a serverless application. It also provides tips on how to troubleshoot and optimize Lambda functions that use layers.
https://www.ranthebuilder.cloud/post/aws-lambda-layers-best-practices
How Rust went from a side project to the world’s most-loved programming language
For decades, coders wrote critical systems in C and C++. Now they turn to Rust.
The anatomy of ransomware events targeting data residing in Amazon S3
Can S3 be a ransomware target?
https://aws.amazon.com/blogs/security/anatomy-of-a-ransomware-event-targeting-data-in-amazon-s3/
Cross-Account Access to an Account in an AWS Organization
systemd 253: You're looking at the future of enterprise Linux boot processes
The first systemd release of 2023 is here, and it introduces a brand-spanking new tool for building Unified Kernel Image (UKI) files.
https://www.theregister.com/2023/02/17/systemd_253/
Incident travel time
This post discusses the significance of a prompt initial response in managing incidents and introduces the concept of travel time to explain this idea. It provides an insightful analysis of why reducing the time it takes to respond to incidents is crucial, especially when responding to critical issues.
Software Bill of Materials devroom
This year at Fosdem, there was a devroom exclusively dedicated to SBOM, and the sessions were recorded and are currently accessible. These sessions covered a range of topics such as case studies, tools, legal discussions, and more.
https://fosdem.org/2023/schedule/track/software_bill_of_materials/
cURL audit: How a joke led to significant findings
The blog post on Trail of Bits provides a summary of a recent security audit and fuzzing effort performed on libcurl and its command-line interface, curl. The audit discovered several security vulnerabilities and provided recommendations for improving the security of the software.
https://blog.trailofbits.com/2023/02/14/curl-audit-fuzzing-libcurl-command-line-interface/
Newsletter sponsor: Nexteam
Technology, Experience, Delivered.
Thanks for reading Infra Weekly Newsletter! Subscribe for free to receive new posts and support my work.




