TGViewer
Channel Public Channel
CatOps

CatOps

@catops

DevOps and other issues by Yurii Rochniak (@grem1in) - SRE @ Preply && Maksym Vlasov (@MaxymVlasov) - Engineer @ Star. Opinions on our own.

We do not post ads including event announcements. Please, do not bother us with such requests!
Subscribers
5.08K
Photos
94
Videos
5
Links
2.7K

Showing posts older than #2907 · Back to latest

Older Posts 20 shown
Post #2906 1.5K
An interesting point of view on reliability through the prism of everyday work and experience from other industries.

The normal work of creating reliability is an article by Lorin Hochstein, that asks: what instead of thinking of how an incident could have been prevented, we ask: what do we do daily to avoid having incidents constantly.

P.S. "Invert, always invert" - Carl Jacobi

#sre #reliability #culture
Surfing Complexity The normal work of creating reliability Here’s a recent comment on LinkedIn from John Allspaw, on a post by Gandhi Mathi Nathan Kumar about availability. Allspaw’s comment is a succinct description of a safety model proposed …
  • 👍 4
  • ❤ 1
Post #2905 1.55K
Continuing with security advisory.

NGINX ngx_http_rewrite_module vulnerability CVE-2026-42945.

~
NGINX Plus and NGINX Open Source have a vulnerability in the *ngx_http_rewrite_module* module. This vulnerability exists when the *rewrite* directive is followed by a *rewrite*, *if*, or *set* directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible. (CVE-2026-42945)


Don't confuse the F5's NGINX Ingress Controller with the community-led ingress-nginx, that is deprecated now.

In any case, though, if you're using the ngx_http_rewrite_module (and it's widely used!), you are likely vulnerable.


#security
F5 NGINX ngx_http_rewrite_module vulnerability CVE-2026-42945 Security Advisory Description NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the "rewrite" directive with a query string is followed (in the same location) by the "if" or "set" directive…
Post #2902 1.4K
​​Enabling horizontal autoscaling with co-operative distributed rate limiting is an old article from Monzo that describes, how they built their internal distributed rate limiting solution.

The interesting part is the reasoning about whether a system works in an adversary environment (public facing) or not (internal system). The main question here: can you trust a client? The answer to this question influences the design a lot!

#system_design
Post #2901 1.58K
​​For today’s Donations Monday, I would like to remind you about one of the smaller fundraisers from the recent digest.

- Radio-electronic equipment for the 25th Brigade.

It’s more than 80% complete, and I’m sure that with your help, we can close it this week.

#donations #Ukraine
  • ❤ 4
Post #2899 1.62K
​​Remember copy.fail which we all checking a week ago?
Here is a continuation - another Linux 0-day to root.
https://github.com/V4bel/dirtyfrag

Btw, I can recommend to checkout https://t.me/setenforce_1 - channel fully dedicated to security, or better say - to vulns that will have real effect on you. No bullshit about "10 common vulns" which you can check on OWASP etc. Love it.

#security #linux
  • 👍 9
  • 🔥 2
Post #2898 1.48K
You may have heard already that Mitchell Hashimoto plans to move Ghostty away from GitHub.

It could be that you plan such a move yourself for whatever reason, but you're not sure yet. Here's a guide on how to push changes to GitHub and Codeberg simultaneously, so you could still keep the door open.

Codeberg is a non-profit European Git hosting. Although, this guide should work for any provider as long as you can use SSH keys for auth.

#programming #github
Scripting on Caffeine Pushing to GitHub and Codeberg Simultaneously with Git Learn how to configure Git to push your code to both GitHub and Codeberg with a single command, including SSH key setup and a handy shell alias for branch-specific control.
  • 👍 5
Post #2896 1.53K
Figma has replaced PGBouncer with their own implementation called PGKeeper written in Go as a connection pooler for Postgres.

I really enjoyed this article, because they go into the implementation depths and describe why certain decisions were taken. Unfortunately, it doesn't always happen in such articles. Also, this is a nice reminder that software engineering is not only about writing CRUDs.

Unfortunately, they do not plan to open source it for now, also because it's too tightly coupled with libraries and approaches Figma uses internally. To be honest, it makes sense for in-house software to aim to one's specific needs rather than being generic enough to be open sourced.

#databases #postgres
Figma PGKeeper: Building the Bouncer We Needed for Postgres | Figma Blog This is the story of why and how we built PGKeeper, a scalable and reliable service to support Figma’s rapidly growing products and database workload.
  • 👍 4
  • 😁 4
Post #2892 1.57K
If you're hosting GitHub Enterprise Server, you need to update to address a recently discovered CVE.

What's interesting about this CVE is that it is a legit CVE that was discovered with AI. As WIZ researchers put it in the related article

Notably, this is one of the first critical vulnerabilities discovered in closed-source binaries using AI, highlighting a shift in how these flaws are identified.


Security notice from GitHub.

Fixed versions:

- GitHub Enterprise Server 3.14.25 or later
- GitHub Enterprise Server 3.15.20 or later
- GitHub Enterprise Server 3.16.16 or later
- GitHub Enterprise Server 3.17.13 or later
- GitHub Enterprise Server 3.18.7 or later
- GitHub Enterprise Server 3.19.4 or later
- GitHub Enterprise Server 3.20.0 or later

P.S. These news came from our chat (in Ukrainian).

#security #github
wiz.io GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blog A CVSS 8.7 vulnerability in GitHub Enterprise Server allows remote code execution. Read the threat brief and find vulnerable GHES instances from Wiz.
Post #2891 1.57K
Apparently, the Dutch Central Bank is opting for the Lidl cloud instead of a US solution as their cloud provider.

Right now, digital sovereignty may sound like loud promises, but this is one of the main issues the European tech sector will have to solve in the nearest future.

P.S. It’s also a bit funny that a grocery store is completing with a book store in cloud computing.

#cloud #lidl
discount-retail-consulting Netherlands: Dutch Central Bank (DNB) goes to Lidl for cloud services Discount Retail Chain Lidl's sister company Schwarz Digits signs a major contract as a supplier of IT services to the Dutch Central Bank (DNB).This was announced by sales director Bernd Wagner on Monday during a major industrial fair in Hanover. Schwarz Gruppe…
  • ❤ 15
  • ❤‍🔥 3
  • 😁 1
Post #2890 1.42K
​​For today’s Donations Monday, I would like to remind you about a smaller fundraiser that I posted several weeks ago. It’s moving, but rather slow. So, let’s boost it!

​​A fundraiser for radio-electronic equipment for the 25th Brigade.

Monobank jar:

https://send.monobank.ua/jar/5cXWfFMLHR

The fundraiser is 60% complete.

#donations #Ukraine
  • ❤ 4
Post #2888 1.76K
The Laws Of Architectural Work is a short article with two important insights about architectural decisions:

- They always come with trade-offs.
- Context matters.

This reminded me of a university professor from back in a day. He used to say: “There is no good solution, there is only an optimal solution for our case”. This phrase pretty much summarizes the whole premise of this article.

In any case, I think it’s an important reminder, taking into account that we can “outsource” more and more coding work, so what we left with is basically architectural work, being it software, infrastructure, networks, or something else.

P.S. This article was written in 2020, so take it into account, when you encounter words “recent” there. I’m digging through my archive of saved articles.

#architecture
Uwe Friedrichsen The laws of architectural work Understanding architectural decisions
  • 👍 3
Post #2887 1.62K
After painful and not particularly successful adoption path of IPv6, a draft proposal for IPv8 is here. However, it has some critical flaws not on the technical, but on the operational and policy level. In short, in its current form, it would make the Internet more prone to be controlled by a centralized entity.

Here’s the draft itself I haven't read it yet, but now I sure will.

#networking
Substack We Need to Talk About the IPv8 Draft The Good, The Bad, and the Heinous
  • 🤡 3
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →