office-hours
1004312,744
Public "Office Hours" are held every Wednesday at 11:30 PST via Zoom. It's open to everyone. Ask questions related to DevOps & Cloud and get answers!
👉️ https://cpco.io/slack-office-hours
erikabout 13 hours ago
Wow, 16 year old white hat hacker breaches Microsoft analytics endpoint with full access to something like 17 trillion records. https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records
erik1 day ago
https://news.ycombinator.com/item?id=49893876
I'm not sure this is even conceivable, but... Imagine the bootstrap problem of intelligence systems going down, when no one knows how to bring them back up without the system itself walking them through it... Like if power and intelligence were to go down in a Carrington-class event in 10 years...
Like what would happen to individuals ten years from now who are trying to live if AI suddenly became inaccessible
Of course we all know most humans are useless and unable to survive outside our culture, but the difference is that I'm trying to picture is the individual trying the reason through challenges. The version of this that has been obvious to me up to now is that the individual didn't have the knowledge to look after themselves. But I guess it feels different to conceive of them not having the ability to fully reason on their own...?
To not just lack the objects of intelligence, but the very process of it...
Cyril (runs-on.com)7 days ago
benchmarked the new t8i instance types. Very good price/perf ratio for small CI jobs it seems runs-on.com/benchmarks/aws-ec2-instances/t8i.medium
paulm8 days ago(edited)
aws.amazon.com/about-aws/…/ec2-t8i-instances-ga
People speculated that EC2 "burstable" performance instances were on the way out, with nothing new in the
As of 2026-09-23, for 512 MiB of RAM and a fraction 2 vCPUs, the on-demand price per instance-hour in the
• 0.624¢
• 0.520¢
• 0.420¢
People speculated that EC2 "burstable" performance instances were on the way out, with nothing new in the
t instance type family since t4g was introduced in September, 2020. Here we are, with t8i after 6 years! General performance improvements and an Intel CPU come at a small premium.As of 2026-09-23, for 512 MiB of RAM and a fraction 2 vCPUs, the on-demand price per instance-hour in the
us-east-1 region is:• 0.624¢
t8i.nano (about $4.50 per month)• 0.520¢
t3.nano (under $4 per month)• 0.420¢
t4g.nano (about $3 per month)erik16 days ago
GitHub Actions can now run local actions without requiring a checkout.
github.blog/changelog/2026-07-30-reference-same-repository-actions-with-self-repository-syntax
cc @Michal Tomaszek thanks!
github.blog/changelog/2026-07-30-reference-same-repository-actions-with-self-repository-syntax
cc @Michal Tomaszek thanks!
erik16 days ago
Please, please, please, let this be true. macrumors.com/2026/09/14/siri-can-be-swapped-out-for-chatgpt-claude
paulm28 days ago(edited)
aws.amazon.com/about-aws/…/aws-lambda-full-iam-resource-based-policies
This security improvement lets you edit a Lambda function's resource-based policy. Before, you had to call the
CloudFormation:
Terraform:
Benefits:
• You can use IAM condition keys to intelligently target principals that can invoke a Lambda function.
• You can make permission to invoke a Lambda function exclusive (for example, exclusive to the event source mapping from one particular SQS queue) by adding a
Exclusive permission to invoke a Lambda function is now practical, but I need to check whether old restrictions on role trust (assume role) policies for the Lambda service have been relaxed so it's practical to make an IAM role exclusive to a Lambda function.
This security improvement lets you edit a Lambda function's resource-based policy. Before, you had to call the
lambda:AddPermission API method to add single statements, and all those did was Allow specific principals to lambda:InvokeFunction . For an analogy, compare the expressiveness of security group rules (allow only) and Network Access Control List rules (allow or deny).CloudFormation:
AWS::Lambda::Permission → AWS::Lambda::ResourcePolicyTerraform:
aws_lambda_permission → aws_lambda_policy (proposed in terraform-provider-aws issue 49691 ; not implemented as of v6.62 ; you could use terraform-provider-awscc for now)Benefits:
• You can use IAM condition keys to intelligently target principals that can invoke a Lambda function.
• You can make permission to invoke a Lambda function exclusive (for example, exclusive to the event source mapping from one particular SQS queue) by adding a
Deny statement to complement an Allow statement in the same resource policy or in an identity-based (IAM user or role) policy. Before, you would have needed a Service Control Policy to prevent unintended IAM users and roles from invoking particular Lambda functions.Exclusive permission to invoke a Lambda function is now practical, but I need to check whether old restrictions on role trust (assume role) policies for the Lambda service have been relaxed so it's practical to make an IAM role exclusive to a Lambda function.
erikabout 1 month ago
erikabout 1 month ago
paulmabout 1 month ago(edited)
https://www.linkedin.com/posts/joshpollara_terraform-activity-7497989985753767936-0EEV
An interesting discussion that promises to get more interesting. I'm curious whether there are discernible changes in module download rates.
Terraform module registries are dying.
People can just ask AI to write a local module, and it's actually pretty good at it. Claude has reduced the time it takes to write a module to nearly zero.
An interesting discussion that promises to get more interesting. I'm curious whether there are discernible changes in module download rates.
Cyril (runs-on.com)about 1 month ago
2 projects came out that implement scalable git hosting just by using an s3 bucket as the data plane thanks to the somewhat new conditional PUT primitive supported by S3: gitwal.io by Scott Chacon and github.com/tobi/walgit by Tobi Lutke. Implementations of cursor.com/blog/git-at-any-scale. Makes for a nice reading and I'm sure we'll see many new projects around that.