Newslurp

<< Stories

BGP Security 🥷, Leaked Environment Variables 🪣, Burn Rate vs. Error Rate 🔥

TLDR DevOps <dan@tldrnewsletter.com>

September 6, 11:16 am

TLDR DevOps
Burn rates offer a more nuanced and effective approach to monitoring service reliability compared to traditional error rates 

TLDR

Together With Chronosphere

TLDR DevOps 2024-09-06

The 5-step practical guide to migrating your observability platform (Sponsor)

Migrating to a new observability platform is a major project that impacts people, processes, and technology.

Many organizations would prefer to postpone migration indefinitely — but getting stuck with incumbent tooling inevitably leads to higher costs, increased developer toil, and unhappy end users.

To make your migration journey less painful, Chronosphere has prepared a handy guide outlining the important factors to look out for across the 5 steps of the migration process: prepare → design → implement → test → adopt.

Take a few minutes to read through the guide and you'll avoid unforced errors when migrating to new observability. Get it here

📱

News & Trends

Making progress on routing security: the new White House roadmap (11 minute read)

This post explains the importance of the Border Gateway Protocol (BGP) for routing internet traffic and the growing need for security measures to prevent route hijacking and leaks. It highlights recent government efforts, including the White House roadmap, to improve BGP security through initiatives like Resource Public Key Infrastructure (RPKI) and Route Origin Validation (ROV).
YubiKeys cryptographic Flaw Let Attackers Clone Devices by Extracting Private Key (3 minute read)

A critical vulnerability in YubiKeys allows attackers to clone devices by extracting private keys, highlighting the importance of constant-time cryptographic implementations and the need for users to update to newer firmware versions.
NIST's post-quantum cryptography standards: Our plans (5 minute read)

HashiCorp's comprehensive approach to post-quantum cryptography standards includes implementing NIST-approved algorithms, developing quantum-safe solutions, and providing guidance to help enterprises protect their sensitive data and prepare for the post-quantum era.
🚀

Opinions & Tutorials

Containerising Azure Functions without Dockerfile (8 minute read)

This article explains how to containerize Azure Functions apps for .NET using two methods: with a Dockerfile and via MSBuild's native containerization support. It provides detailed steps for both approaches, allowing developers to build and run containerized Azure Functions apps locally.
Creating A Git Commit The Hard Way (8 minute read)

This article dives deep into what creating a git commit with the canonical git commit command actually does under the hood. It walks through the underlying git operations that are executed to get it to work.
"SRE" doesn't seem to mean anything useful any more (4 minute read)

This author, frustrated by being stereotyped as merely a "devops" worker due to their Site Reliability Engineer (SRE) background, recounts a pivotal decision at Torq to use gRPC and Protobuf instead of OpenAPI/Swagger. This choice, influenced by past negative experiences at Luminate Security, led to improved system compatibility and coding standards. Despite the success, they feel their broader technical skills are often overlooked.
🧑‍💻

Resources & Tools

The global data community is meeting in Seattle this November. Will you be there? (Sponsor)

PASS Data Community Summit is the place to connect with the incredible data community. Network with speakers and sponsors including Microsoft, AWS, and Google Cloud, and keep up-to-date with the latest trends and technologies with over 150 sessions taking place on-site. Level up your learning with expert advice that you can practically apply in your job, and boost your career with the connections you make. Register before September 17 to save $200 on a 3-day ticket.
Dub (GitHub Repo)

Open-source link management infrastructure. Loved by modern marketing teams like Vercel, Raycast, and Perplexity.
Apprise (GitHub Repo)

Apprise simplifies notifications for developers and system administrators by providing a unified interface to send messages across multiple popular platforms, streamlining the process of integrating notification services into applications and workflows.
🎁

Miscellaneous

Leaked Environment Variables Allow Large-Scale Extortion Operation of Cloud Environments (18 minute read)

This article reveals a cloud extortion operation exploiting overly permissive IAM credentials and exposed environment (.env) files to ransom organizations' cloud data. The attackers gained initial access by scanning the internet for exposed .env files containing sensitive authentication data, which could have been prevented by following cloud security best practices.
AWS IAM: A Comprehensive Guide Toward Least Privilege (9 minute read)

This article emphasizes the importance of applying the principle of least privilege (PoLP) in cloud environments to reduce the risks of credential theft, accidental or intentional data deletion, and other security incidents. It suggests starting with broader permissions and gradually narrowing them while considering the use of more restrictive policies like ViewOnlyAccess or SecurityAudit instead of ReadOnlyAccess for production environments.

Quick Links

Safety first! (2 minute read)

Despite claims of prioritizing safety, tech companies can't truly be "safety first" because production pressure inevitably pushes back against delays, leading to trade-offs between safety and execution that engineers face daily.
Burn Rate Is a Better Error Rate (12 minute read)

Burn rates offer a more nuanced and effective approach to monitoring service reliability compared to traditional error rates, providing clearer insights and enabling more precise alerting for improved system performance.

Love TLDR? Tell your friends and get rewards!

Share your referral link below with friends to get free TLDR swag!
Track your referrals here.

Want to advertise in TLDR? 📰

If your company is interested in reaching an audience of devops professionals and decision makers, you may want to advertise with us.

If you have any comments or feedback, just respond to this email!

Thanks for reading,
Kunal Desai & Martin Hauskrecht


If you don't want to receive future editions of TLDR DevOps, please unsubscribe from TLDR DevOps or manage all of your TLDR newsletter subscriptions.