TGViewer
Channel Public Channel
CatOps

CatOps

@catops

DevOps and other issues by Yurii Rochniak (@grem1in) - SRE @ Preply && Maksym Vlasov (@MaxymVlasov) - Engineer @ Star. Opinions on our own.

We do not post ads including event announcements. Please, do not bother us with such requests!
Subscribers
5.08K
Photos
94
Videos
5
Links
2.7K

Showing posts older than #2664 · Back to latest

Older Posts 20 shown
Post #2663 1.84K
Saturday afternoon is the ideal time to listen to 3 hours of a discussion about AI in the new episode of our CatOps Voice Chat (in Ukrainian).

There are a lot of useful links in the description as well, so check it out!

You can find the new episode on:

- YouTube
- Substack
- Spotify
- Apple Podcasts
- RSS Feed

Hope you enjoy it!

#voice_chat #говорилка #ai
YouTube Говорилка CatOps: AI Всі розмови зараз про AI, от і ми обговорили цю тему. Вийшло аж 3 години. Матеріали, що згадуються у випуску: - https://cline.bot/ - https://replit.com/ - https://github.com/Aider-AI/aider - https://github.com/joshuavial/aider.nvim - https://github.com/exo…
  • 🔥 9
Post #2662 1.94K
Depending on your seniority and title, working with diagrams may take a big chunk of your day-to-day work.

Here's a collection of diagram creation tools, so you could pick something that suits your needs. Some of these
projects are quite famous - others not so much. I personally found some
interesting things there. It's not guaranteed that I will use them, but
still.

Also, speaking of diagrams, I can recommend this talk
from FOSDEM 2023. It's not a super-entertaining one, but it has some
good suggestions on how to draw your diagrams. The talk itself if
wrapped into Kubernetes, but those suggestions are universal.

#diagrams
Generativeprogrammer Architecture Diagramming Tools, and the AI Gap Turning Words Into Architecture — Where’s the AI Tool for That?
  • 👍 11
Post #2660 1.87K
“5 Whys” is a fairly popular framework for searching for a contributing factors of an incident.

However, this framework has its own limitations. Here is an article that presents these limitations in a concise way.

#sre
  • ❤ 2
Post #2659 1.79K
Lurking Variables is a story about contributing factors. Specifically, those factors that people do not take into account right away, or better said, are not instinctively taken into account.

Anyway, this is a good read about a very real problem of confirmation bias when handling incidents.

#sre #incidents
read.thecoder.cafe Lurking Variables: How Hidden Factors Can Mislead Your Analysis Proactively segmenting data per influencing factors can help discover lurking variables before they lead to misinterpretations.
  • ❤ 2
Post #2658 1.82K
​​For today's Donations Monday we have a fundraiser from Dzyga's Paw that they do together with 7 different units. My friend's brother serves in one of those units.

https://send.monobank.ua/jar/7CRy1e16Qk

Here's the description from Dzyga's Paw themselves.

Dzyga’s Paw Fund, in partnership with seven units, is launching a $300,000 fundraiser to provide them with 90 night drones — essential for precision and safety in night operations.
Donate now to support project Triad: https://dzygaspaw.com/triad-night-drones
We are bringing together two powerful forces: our international supporters and Ukrainians backing their brigades. No matter what they say, Ukraine is not tired. Our defenders fight on, and we stand with them. And our friends from all over the world are eager to help us with this mission.
Join our ambassador team to help reach this ambitious goal faster — start a smaller fundraiser! Write to us in DM, and we will provide you with all the information, visuals, and donation chart.
This war has lasted nearly 11 years, and the last three have been the most brutal. Against all odds, Ukraine continues to resist. It is our duty to ensure our defenders have the tools they need to win!

#donations #Ukraine
Post #2655 2.12K
We are continuing our security marathon with some news about very popular NGINX Ingress for Kubernetes.

Wiz Research discovered CVE-2025-1097, CVE-2025-1098, CVE-2025-24514 and CVE-2025-1974, a series of unauthenticated Remote Code Execution vulnerabilities in Ingress NGINX Controller for Kubernetes.

Exploiting these vulnerabilities can lead to unauthorized access to cluster secrets as well as remote code execution inside the ingress pod.

This vulnerability is fixed in Ingress NGINX Controller version 1.12.1 and 1.11.5, but if you cannot upgrade right now for whatever reason, Wiz has other recommendations on how to mitigate this.

P.S. Many thanks to the chat for sharing this story!

#security #kubernetes #nginx
wiz.io CVE-2025-1974: The IngressNightmare in Kubernetes | Wiz Blog Wiz Research uncovered RCE vulnerabilities (CVE-2025-1097, 1098, 24514, 1974) in Ingress NGINX for Kubernetes allowing cluster-wide secret access.
  • ❤ 8
  • 🔥 3
  • 👍 2
  • 😁 1
Post #2654 1.97K
​​Last week, we closed Maksym's jar for Hospitallers in a day! Let's now do the same favor to another ember of our community - Dmytro!

His wife is raising funds to repair two cars for the 41st separate mechanized brigade. The goal of the support jar is 30k UAH. Also, there's a raffle for all the donations which are multiples of 100 UAH.

More info about the raffle is in this Instagram post (in Ukrainian):
https://www.instagram.com/p/DHV5cfCg1GU/

#donations #Ukraine
  • ❤ 2
Post #2652 5.31K
AWS gives a chance to complete some certifications for free, but with few preconditions

Covered certs:
- Foundational: Cloud Practitioner, AI Practitioner
- Associate: Solutions Architect, SysOps Administrator, Developer, Data Engineer, Machine Learning Engineer

Note, that you need to prepare and pass exam(s) before Aug 2025.

#aws #certification
Aws AWS Builder Center Start here. Go anywhere. Welcome to AWS Builder Center, the go-to site for builders to learn, grow, and connect with the AWS community.
  • 🔥 16
Post #2651 2.07K
A sneak peek into the database design based on two incredible books: "Database Internals" by Alex Petrov and "Designing Data-Intensive Applications" by Martin Kleppmann. Mostly on the first one, though.

This article touches topics of ACID, underlaying data structures (B- & LSM-trees), and distributed systems. Just like the aforementioned books, which I also highly recommend!

A random quote:

> Going distributed should be a last mile resort, introducing it to a system adds a ton of complexity, as we will soon learn. Please avoid using distributed systems when non distributed solutions suffice.

#databases
Tontinton Database Fundamentals The fundamental problems a database engineer thinks about in the shower
  • ❤ 8
Post #2650 1.99K
Today, I'd like to share with you a nice YouTube channel Polylog, that does short explainer videos about the computer science concepts.

https://www.youtube.com/@PolylogCS

#programming #cs #youtube
  • 👍 4
Post #2649 2.05K
Python is incredibly popular programming language among DevOps / Site Reliability / Platform specialists. It’s also used as the language of choice to build backend in many companies.

So, here is a book bundle by Packt to enhance your Python skills:

https://www.humblebundle.com/books/python-from-beginner-to-advanced-packt-books

P.S. I know that many folks are skeptical about Packt books, so keep this in mind. I still think it worth sharing, though.
Humble Bundle Humble Tech Book Bundle: Python: From Beginner to Advanced by Packt Learn beginner and advanced Python skills with this library of coding and programming courses by Packt. Pay what you want & support charity!
  • ❤ 2
  • 👾 2
Post #2648 1.8K
​The highest priority after completing the task is to preserve the life and health of the personnel. So, let's help raise money for tactical medicine!

TL;DR: Donate to Monobank jar till EOW and I will double the amount raised[1].

The Hospitallers Battalion is a volunteer formation known for its professionalism and dedication. When I say "voluntarily," I mean that you can join for a rotation, for example, for 2 weeks, and then return to civilian life for a few months before repeating the process. This flexibility allows specialists who, for various reasons, do not want or cannot join AFU still contribute to defensive operations. However, since the Hospitallers are a volunteer formation, their funding relies on donations from ordinary people.

Currently, the Hospitallers are raising 7.5 million UAH (~$180k) for this spring.
Let's aim to raise at least 10k UAH from CatOps by the end of the week, and I will double the amount raised[1].

Monobank jar: https://send.monobank.ua/jar/6eEHjgDTGq

Btw, the Hospitallers offer courses on first aid and tactical medicine that are available to civilians. I recently took the TCCC ASM (3-day) course, and it was excellent. You can check out their courses at Hospitallers Courses site and track new dates on their Telegram channel.

#donations #Ukraine

[1] But not more than 20k UAH/month from me until the fund campaign is closed or until I have doubled the amount, whichever comes first.
  • ❤ 7
Post #2647 1.85K
There are two types of folks: those who pin their dependencies to (often) mutable tags and other pointers, and those who already pin to hash sums.

This is true for GitHub Actions as well. For example, most tags in the tj-actions/changed-files repository were repointed to compromised versions by an attacker, potentially affecting 23,000 repositories until GitHub shut down the entire repository.

Manually pinning dependencies can be tedious, so it's better to utilize tools like Renovate. The SpotOnInc/renovate-config preset does exactly that. Note that you can pin it to a hash sum too, just in case ;)

P.S. If you used that GitHub Action, here is a list of possible mitigation steps: antonbabenko/pre-commit-terraform#837.

#security #github #gha
www.stepsecurity.io Harden-Runner detection: tj-actions/changed-files action is compromised - StepSecurity
  • 👍 2
Post #2646 1.93K
Yet another article from the old archives.

This one is about building a multicluster setup with Kubernetes using Kubernetes tools only. Moreover, there are more tools these days that can help you accomplish the architecture outlined in this article.

For example, you could use ClusterAPI instead of Crossplane for leaf-clusters and so on.

The only sad thing is that Kubernetes doesn’t support federation. So, any viable multi-cluster setup always boils down to two distinct approaches: a bunch of independent clusters, or a single leader with leaves.

#kubernetes
  • 👍 2
Post #2644 2.13K
How to Scale Elasticsearch to Solve Your Scalability Issues is a neat guide for areas where you could optimize your ElasticSearch clusters.

Ties article doesn’t provide any concrete numbers, but gives plenty of suggestions. It makes sense, since any optimization heavily depends on one’s use case.

#elasticsearch
DZone How to Scale Elasticsearch to Solve Your Scalability Issues Learn to scale Elasticsearch efficiently by optimizing sharding, query performance, and memory usage to handle high-traffic, real-time applications seamlessly.
  • 👍 5
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →