"on Linux I have to jump through sysctl hoops."
grubby --update-kernel ALL --args ipv6.disable=1
78 publicly visible posts • joined 28 Mar 2013
Guns n Roses Civil War:
What we've got here is failure to communicate
Some men, you just can't reach
So you get what we had here last week
Which is the way he wants it
Well, he gets it
*Whistling*
And I don't like it any more than you men
...
Look at your young men dying
The way they've always done before
...
What's so civil 'bout war anyway?
What do you do when you want change but people will not listen?
"Some developer in your group (a "rogue developer" maybe ?) needed to test something, gave himself all the permissions"
There is your fail, no admins any more so devs can f**k up permissions.
" You want that test account to access production servers ? Why ? For how long ? To do what ? You get that window, then your access is shut down."
No! Prod is higher up the permissions heirarchy and can pull from test, that is how you get new reference data into prod.
Test CANNOT EVER acess prod, dumbass! Prod copys for final validation ARE INDENTICIAL TO PROD SO ARE STILL PROD AND NEED TO BE TREATED AS SUCH.
They do not. I once asked a Power Bi Personal from Microsoft how do you know your changes will not break an important PRODUCTION report?
Do you know which reports are production vs test vs experimental and test ALL PRODUCTION reports will not break before you make a change?
Do clients mark which reports are PRODUCTION?
Answer no. i.e. we do not care. So that is how they save money, no testing!
Once saw someone at a SQL Saturday conference built a whole 1hr talk around a new Power Bi Feature.
They had tested the night before, on the day they got to the screen and...it had gone, turned off.
They had to end their 1hr talk after 10 minutes and look like an idiot, cue all of us walking out into the hallway and hanging around for 50 minutes in the conference place with of course no refreshments and nothing to do!
If you are doing say the Facebook IPO and in that 'critical hour' something in the cloud disappears that you rely on how does that work and you not get sued for millions?
Company IT have change freezes the cloud vendors do not, just asking for trouble and if you are in a large org potentially getting sued for millions.
The problem is that now we have PERSONAL computing and cloud storage so the concept of DEPARTMENTAL and INSTITUTIONAL storage is gone.
Different levels of data storage is forgotten, Important data should be pushed up the heirarchy and labelled so future academics/students can find it for future research.
Given that
a) Without client side encryption Microsoft can see all of your code or if just the database is in Azure then the whole database schema, data and how your application access the database and can therefore determine cases where your app will not scale.
b) https://en.wikipedia.org/wiki/Stac_Electronics
- "examined Stac's code as part of the due diligence process."
- " sued Microsoft for infringement of two of its data compression patents...awarded Stac $120 million in compensatory damages"
What stops Microsoft examining your code/database access and writing a competing app, then producing benchmarks showing your app is slower and does not scale?
Asked that from a developer once and got the reply "I do not care, by the time that happen I will have made my money and moved on" and that their management are the same.
I wonder if the owners of their employer knew about this and considered the threat to their business or even cared?
Would Liberata be one of those?
https://www.moneymarketing.co.uk/news/fsa-fines-liberata-525000-for-system-failures/
https://www.fca.org.uk/publication/final-notices/liberata.pdf
"In total, LFS administers over 1.8 million life and pensions policies comprising over 3,000 different types of savings, investment and retirement products."
"LFS staff must determine the cause of the error message (which is in system code)"
"training for staff was inadequate."
"messages were in system code, rather than 'plain English', making their interpretation difficult."
"Throughout the Relevant Period, LFS failed to take reasonable care to establish effective procedures to investigate and resolve error messages."
"Between January 2005 and December 2005, LFS failed to put in place any controls to monitor the dispatch of documents."
"LFS's reliance on the management information as the only tool to monitor the performance of CIC was not acceptable."
"During the Relevant Period, LFS conducted only sporadic and limited reviews of CIC to ensure that it was operating effectively. In fact, between January 2005 and March 2006, LFS did not conduct any review of CIC."
"As a result of LFS's failure to implement controls which were appropriate for its business, throughout the Relevant Period, it was unable to monitor adequately whether documents were being dispatched to policyholders as required."
"LFS therefore failed to act with due skill, care and diligence by not considering adequately, and acting on, warning signals identified in its management information and not acting properly on clear indications in the March 2006 audit, that policyholders were at risk of not receiving documents."
"As set out in paragraph 5.21 above, the FSA considers that LFS's assumption throughout 2006 that all of the documents within outstanding Contacts were legitimately suppressed was reckless."
"LFS uses a number of automated systems to administer policies. Its principal system, 'Amarta', is a bespoke system developed and maintained by LFS."
Give that my CV and I believe LinkedIn profile mention Liberata, how does this not reflect on me?
The problem is
a) With a GUI and a mindset that "administration is easy" people will tend to keep pressing submit and fill in the mimimun to make the submit button work
b) Wuth a GUI designer seem to always want to have a default for toggles like these. "Boss, what should the default be?"
With a command line, --single_tenant and --multi-tenant and having to BUILD the command people first list the available options and then THINK about selecting the options they need.
Also when people think about automating the process they already have the command to hand!
I have always been of the opion GUI's are GREAT for viewing (READ) not changing (WRITE).
" that the virtualization overhead is less than 5%, which is the lowest overhead in the industry that we’re aware of. "
https://aws.amazon.com/blogs/hpc/bare-metal-performance-with-the-aws-nitro-system/
" The differential in all of the evaluated cases is within 1% of the performance level. "
So IBM are not aware of AWS Nitro? Lol
What process have they to supervise?
Council House Rapairs
Parks Maintenance
School Repairs
What stock do they need to manage?
In the case of council house repairs, the cache of spares they keep - baths, toilets,taps,doors,windows,light fittings...
https://en.wikipedia.org/wiki/Direct_service_organisation
In the case of Parks Maintenance, feeds, fertilizers, weed sprays.
In the case of school reparis, chairs,desks,doors..
In the case of grass cuttings, mowers,hedge trimmers, pruners.
Ah yes, the time a junior I knew managed to set the password change policy wrongly on a customer system for the root password!
The password had to be changed now before logging in as root could complete but also could not be changed for 180 days! Whoops!
They could mount the disk via a CDROM but then needed a call to the vendor for the details on how to get a chroot jail working so the policy could be changed!
"Put it in the Cloud it scales and can be flexed up and down dynamically"
Ha ha ha! How many times do we hear..."oh but that service does not flex...but it will when we fix it." or "we can make those requests much more efficient" how about writing it properly in the first place? It is all about time to code and relibability and efficency are an afterthought now.
"The outage, which occurred on 26 March, brought down Google's cloud services in multiple regions, including Dataflow, Big Query, DialogFlow, Kubernetes Engine, Cloud Firestore, App Engine, and Cloud Console."
1 Cloud, 1 set of cache servers, no seperation to be "efficient". It won't all break at once..LOL!!
Your automated deployment could say deploy 16GB VMs for cache server.
Where they get deployed physically could be anywhere on hypervisors of any size with spare resources.
You say increase the memory on each VM to 32Gb.
You SHOULD have unused memory in your hypervisor pools to allow for unexpected growth when you operate at the size google does.
They have hundreds of thousands if not millions of hypervisors so keep x% free so allow for gorwth, as you use it add more hypervisors to the pool!
But....desktops have gone from 10Mb to 100Mb to 1GB...and stopped.
When are desktops getting 10GB?
1GB/s ~= 100Mb/s, my NVMe SSD is supposed to be faster than that.
If I want to backup my stuff software/pics (currently 570GB) to another desktop it still takes hours!
My NUC has Thunderbolt 3
I tried Thunderbolt 3 (specific card for my motherboard and revision) with a £50 cable (!) and
never got it to work.
Waiting for 10GB to the desktop!
I have come across developers who said why they do this....
Feature X is onyl available in Version Y and higher of browser Z.
How do you know when you can start to use that feature..when only a few percentage of your visitors are still using verions older than that..."we do not care about the last few percent of customers we can drop them as our turnover is 10%+ per month anyway"!!
Otherwise everyone would be compatible with IE6 and legacy compatability code would have to be written for every page!
And
- RBAC is not configured the same way on all platforms
- RBAC may have different capabilities on each platform/version
- Having to configure a person into different RBAC 'groups' on each platform is inefficient/error prone or requires more automation to be built/tested/patched.
- Producing a unifired audit trail across all RBAC platforms is probably either not feasible or painful.
- Not sure how well automation tools support RBAC configuration across platforms
I notice Oracle is not on the list.
All affected people (including on Azure) over to Oracle Cloud.
When that is added then over to Rackspace's Cloud then to...then to..all the way to Dave's Cloud aka Billy Bob's Cloud...aka...keep changing the name/owner every week!
"Well,shucks...sure we can move them there VM's to Suzie's Cloud for yer, yeeee-haw!"
Not that any of the smaller Cloud providers are cowboy's...perish the thought!