TGViewer
Channel Public Channel
CatOps

CatOps

@catops

DevOps and other issues by Yurii Rochniak (@grem1in) - SRE @ Preply && Maksym Vlasov (@MaxymVlasov) - Engineer @ Star. Opinions on our own.

We do not post ads including event announcements. Please, do not bother us with such requests!
Subscribers
5.08K
Photos
94
Videos
5
Links
2.7K

Showing posts older than #2887 · Back to latest

Older Posts 20 shown
Post #2886 1.82K
Do you trust your colleagues?

An article Stop Using Pull Requests from the same author as the previous article in the channel, argues that they may be not ideal.

The core argument is that pull requests were originally created for low trust open source environment, in which contributors may have never seen each other, and often do not know each other at all. Development teams in the corporate world operate on another set of assumptions.

It's interesting that this article also builds up on the ideas of Thierry de Pauw. IIRC, I already posted his talk "Non blocking Pull Requests" on the channel, but in any case, I can do it again.

The main premise of the article is that you need to adopt T*D practices: test-driven development, trunk-based development, and another made-up T*D practice that basically means pair-programming.

From my experience I can say, that eliminating pull requests is probably not something you can do in a short run, but measuring the waiting time before PRs are merged is a good practice. Another good practice is to team-up on tasks or projects. So, basically pair-programming, but several people can still work on different tasks within a project, share context on this project, and thus be able to review each other's work almost immediately without much context switching.

T*D practices are also nice. Honestly, I have an impression that the majority of people are using the trunk-based merge model and continuous deployment these days. Also, it's interesting how AI can facilitate test-driven development: spec (by human) => test (by a machine) => tests review (by humans) => coding (by a machine).

#culture #programming
Substack Stop Using Pull Requests Your team’s code review process is probably an expensive illusion of quality. Here’s what the evidence says, and what to do instead.
  • 🤨 8
  • 😐 2
  • ❤ 1
Post #2885 1.66K
This article may upset some people, but this is a very good retrospective on measuring developer productivity, and what the new AI era may mean for this.

The Developer Productivity Trap is a rather long article, but it totally worth the time! Especially, if you work on the “development experience” side of things or is responsible for engineering metrics. It’s especially valuable read, if you’re on the journey of implementing AI assistants in your company.

#devex #culture
Substack The Developer Productivity Trap Why Everything We Think We Know About Developer Productivity Is Wrong — And Why AI Is Making It Worse
  • 👍 5
Post #2884 1.66K
Yet another article on the topic of technical debt.

It uses Martin Fowler's "Technical Debt Quadrant" to reason about the technical debt and provides some advices on how to address it.

P.S. There is some self-promotion in the end, but it's subtle. So, I would say that this article is still a nice entry point into the topic.

#culture
Medium The Engineer’s Complete Guide to Technical Debt In this guide, you’ll learn how to prevent, fix and manage tech debt. Understand types of tech debt, the cost of tech debt and more.
Post #2883 1.63K
​​For today’s Donations Monday, I’d like to ask you to help with another smaller scale fundraiser for radio-electronic equipment for the 25th Brigade.

Monobank jar:

https://send.monobank.ua/jar/5cXWfFMLHR

The fundraiser is ~41% complete for now.

#donations #Ukraine
  • ❤ 3
Post #2882 1.97K
As you may know, LocalStack deprecates their community version starting from the 23rd of March.

So, here are a few alternatives you may consider:

- MiniStack - a free alternative written in Python.
- Floci - another free alternative written in Java.
- Kumo - a lightweight AWS simulator written in Go.

I haven't tried any of them yet. I guess, I'll need to, since I'm using LocalStack to test my open sourced Terraform module.

#aws #localstack
LocalStack Blog The Road Ahead for LocalStack: Upcoming Changes to the Delivery of Our AWS Cloud Emulators We’re simplifying and improving the LocalStack for AWS experience by unifying Community and Pro into one image, offering a free account-based experience for individuals and open source users, and introducing a new CLI (CLI v2) to power the next generation…
  • 👍 7
Post #2881 1.63K
​​The Comforting Lie Of SHA Pinning is an article inspired by those supply chain attacks that happened lately.

It shows some quirks of how GitHub works with SHAs, which are quite unexpected. The gist and the main excerpt:


From the platform’s perspective, a fork is a separate repository with a shared object graph/history. When the runner resolves the reference, it ultimately looks up the commit in the Git object database; if that object exists and is reachable, it can be used regardless of which fork introduced it. A commit object is globally identifiable. If the SHA exists anywhere reachable, that is apparently sufficient.


The article also describes the way of how to mitigate this risk in GitHub organizations, if you have one.

#security #github
  • 👍 3
  • 🌚 2
Post #2880 1.64K
Terragrunt has released version 1.0. According to them, this is not about a lot of brand-new features, but a commitment to backwards compatibility within the 1.x branch.

The press-release also has an overview of some features that Terragrunt has.

#terraform #terragrut #opentofu
www.gruntwork.io Terragrunt 1.0 Released! Terragrunt 1.0 is officially here after nearly a decade of work, bringing backwards compatibility guarantees and general availability of the Scale Free Tier.
  • 🔥 12
  • 👍 3
  • 🤮 1
Post #2879 1.61K
​​From time to time, I share a standing jar for FPV drones for a guy from my wife’s hometown.

Today, I’d like to share a fundraiser for rehabilitation of his brother-in-arms, who lost his leg near Kostiantynivka. Now he needs to undergo a series of surgeries. Here’s a Monobank jar to help him financially:

https://send.monobank.ua/jar/5AmpbpVRxm

Card number:
4874 1000 2602 4938

#donations #Ukraine
  • 🫡 7
Post #2877 1.75K
Linux - The Good Stuff is a book bundle by No Starch Press that really has good stuff! Including the book I recommend to everyone starting with Linux - "How Linux Works" by Brian Ward and "The Linux Programming Interface" by Michael Kerrisk for those who want to know how Linux works, but on the API level.

There are some other interesting books as well. Yet, this bundle is not cheap: you have to pay at least €56 unlike the usual €20-25 to unlock it.

#books #linux
Humble Bundle Humble Tech Book Bundle: Linux, the Good Stuff by No Starch Unlock new levels of freedom and creativity when you use Linux—master the ins and outs of Linux today and help support charity!
  • 😱 3
Post #2876 1.79K
Post #2875 1.99K
"From April 24 onward, interaction data—specifically inputs, outputs, code snippets, and associated context—from Copilot Free, Pro, and Pro+ users will be used to train and improve our AI models unless they opt out."

Official statement.

You can opt out in Copilot's "Privacy" settings, or migrate to Codeberg :D

#github #ai
The GitHub Blog Updates to GitHub Copilot interaction data usage policy From April 24 onward, interaction data from Copilot Free, Pro, and Pro+ users will be used to train and improve our AI models unless they opt out.
  • ❤ 2
Post #2874 1.88K
Kubernetes' SIG Network released a Ingress2Gateway tool version 1.0.

This is a tool which aim is to help you to migrate your deprecated Nginx Ingress configuration to the new Gateway API. They do not advertise this tool as a one-click migration solution, but rather as a helper to recreate your manifests.

P.S. Cannot wait to see, how this tool would translate all the custom spaghetti server snippets for Nginx 😈

#kubernetes #networking
Kubernetes Announcing Ingress2Gateway 1.0: Your Path to Gateway API With the Ingress-NGINX retirement scheduled for March 2026, the Kubernetes networking landscape is at a turning point. For most organizations, the question isn't whether to migrate to Gateway API, but how to do so safely. Migrating from Ingress to Gateway…
  • 👍 8
  • 😁 2
  • 🙈 1
Post #2873 1.71K
You may already know that Trivy - a popular security scanner - was compromised last Friday.

- Here is a report by Wiz about this breach.
- Here is another article that goes beyond the GitHub Actions exploit.

If you run Trivy in any form, including locally, double-check what and when you ran.

Check if you had in your CI logs lines like below. Especially, if you’re not using curl in your CI normally.

Terminate orphan process: pid (xxxx) (curl)


Check if you have this file on your local machine or a non-GHA executor: ~/.config/systemd/user/sysmon.py.

You may need to rotate a lot of credentials as a fallout of this breach.

Also, as harsh as it sounds, this line from one of the articles above makes sense:

~
Stop using Trivy. This isn’t the first time Aqua Security’s infrastructure has been compromised, and the `aqua-bot` account that enabled this attack was reportedly left exposed from a previous incident earlier in March that was never fully contained. That’s not a one-off failure; it’s an organizational pattern. A security scanning tool that can’t secure its own supply chain is a liability, not an asset. Remove `trivy-action` from your workflows and the Trivy CLI from your toolchains.


#security
wiz.io Trivy Compromised by "TeamPCP" | Wiz Blog Breaking down the March 2026 Trivy supply chain attack. TeamPCP compromised trivy + trivy-action & setup-trivy GitHub Actions, deploying credential stealers.
  • ❤ 8
Post #2872 1.46K
For today's Donations Monday, I'd like to share with you a Monobank jar from a friend of mine, who had his birthday last weekend.

https://send.monobank.ua/jar/AYR2HGkbxg

Jar card number:

4874100025989107

He currently serves in Armed Forces of Ukraine, and has a Telegram channel about books (in Ukrainian) that he still updates, albeit not as often as before for obvious reasons. You can subscribe there as well!

#donations #Monday
send.monobank.ua Безпечний переказ коштів Надсилайте безкоштовно та безпечно кошти
  • ❤ 3
  • 👍 2
  • 🔥 1
Post #2870 1.93K
A former colleague of mine wrote an article on how to write better tests with AI.

I recall, there were debates, what should a human write: tests or the implementation. Now, there are debates on whether a human should open their IDE at all.

This article is front-end focused, but it has some actionable and more or less universal advice on how to make AI do tests better. At the end of the day, AI is just another tool and the whole trick is in how good do you apply it.

#ai #programming
Adithemighty How to Help AI Write Better Tests AI-generated tests verify that code runs, not that it's correct. Custom commands, a quality gate, and coverage targets turn AI into a genuinely powerful testing partner.
  • ❤ 4
Post #2869 1.77K
I guess many of you are familiar with the concept of OKRs - Objective-Key-Results. OKRs have been around for quite some time. So, of course, there is a book about it.

Here is a short summary of this book by someone on the internet, alongside with their rating and recommendation for whom this book may be interesting.

Now, you can easily generate a book summary using AI these days. The summary itself is not the reason I want to share it with you. I think, writing such summaries is a great way of conceptualizing books for yourself in the first place. I keep telling myself, I should do this as well. Unfortunately, I am lazy :\

#books #okr #management
grahammann.net Measure What Matters: OKR Summary & Key Lessons by John Doerr OKRs (Objectives and Key Results) focus organizations on ambitious goals with measurable outcomes—a system used by Google, Intel, and the Gates Foundati...
  • ❤ 4
Post #2868 1.53K
​​For today’s Donations Monday, I’d like to remind you about the UA Responders foundation that raises money for the rehabilitation of Ukrainian veterans.

#donations #Ukraine
  • 🫡 5
Post #2867 1.88K
A colleague of mine wrote an article on using Cloudflare Tunnels to securely connect to your self-hosted things. It specifically covers quirks of connecting mobile apps, since not all of them can handle auth redirects correctly.

This is a nice read if you have a home lab or anything self-hosted. However, you can also use Cloudflare Tunnels for your business cases, like exposing your staging backend to test mobile devices, etc.

#security #cloudflare
Medium Making Cloudflare Tunnels Work with Mobile Apps Using mTLS (VPN Alternative) (VPN Alternative)
  • 🔥 8
  • 👎 1
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →