Reddit DevOps
277 subscribers
69 photos
32.2K links
Reddit DevOps. #devops
Thanks @reddit2telegram and @r_channels
Download Telegram
Bitbucket --> Jenkins trigger – Infrastructure As Code

IAC – Infrastructure As Code.

I'd like to create Bitbucket hooks to trigger Jenkins jobs. But all the ones I've seen can only be created through the UI.

Does this exist? If not, would anyone be interested in developing such a thing?

https://redd.it/ebno75
@r_devops
Stop telling me to log less to Splunk and that Splunk can't scale.

Splunk costs too much. We log 4TB a day we can't scale it. The logs should be better curated, stop logging so much data. We should switch to a cheaper log management system. It's all horseshit. Splunk is amazing, you should log everything. Info level events, metrics, stack traces, E.V.E.R.Y.T.H.I.N.G when you can correlate all of your data points across an organization in one place you have the ultimate tool. How people can't see that boggles my mind.

How to Scale in an Enterprise environment?

1) Get everything into "A" Splunk indexer. Put a Splunk forwarder on it, sylog it and index syslog. Whatever you have to do. There isn't a system data that you can't get into Splunk one way or another.
2) Give different parts of the organization their own Splunk Indexers and Search heads for the applications or infrastructure they maintain. Let them do whatever they want with it. Write tools for them to generate alarms and ticketing from their servers that integrate with your ticketing systems. Rinse, Repeat.
3) Teach developers to write code that takes advantage of KV Pairs in their logging, and encourage them to write MORE logs with timing and metrics tied to events. Encourage everyone to create curated data FROM all the data that is being collected.
4) Forward content that is relevant across orgs to a higher tier of indexers/search heads. This is where the real magic happens.

When a person in application team A can correlate their apps performance with metrics and relevant data from anywhere in their entire stack of dependencies, you win. Granted the people who are capable of doing that are too few and far between but... that is the problem, Not too much data.

https://redd.it/ebqs08
@r_devops
What do you think is the best automated code review integration for Github and OS projects?

I wanted to seek the communities opinion on what you think is the best automated code review integration in Github. Typically I code in either Python or Node, and have tried SonarQube and LGTM. They both have their pros and cons, but I simply dont like the non reviews for LGTM on pushes. It just feels clunky to me. It is also slow as sin.

I know where are a bunch of other ones out there that I found via [https://github.com/joho/awesome-code-review](https://github.com/joho/awesome-code-review), but wanted to see what others experiences are.

​

Crucible Atlassian's on-premise code review tool.

Gerrit Open source git code review tool originating out of Google.

GitHub Git hosting and pioneer of the "Pull Request".

Gitpod Code review pull requests in a full IDE within your browser.

GitRise Slack Reminders for GitHub pull requests

LGTM Automated Git code review for GitHub and Bitbucket pull requests for finding security vulnerabilities and code quality issues.

Phabricator Open source git/mercurial/svn code review tool originating out of Facebook.

PullRequest Code review as a service for GitHub pull requests.

Pull Reminders Automated Slack reminders and metrics for GitHub pull requests.

Reviewable Code review tool built on top of GitHub pull requests.

Review Board Open source review tool that is SCM/platform neutral.

Rubberduck Browser extension to adds code-aware navigation to GitHub pull requests.

Sider Automated code review service for GitHub.

Softagram Automated code change visualization (and dependency analytics) for pull requests, merge requests (GitLab) and patch sets (Gerrit).

SonarCloud Detect code smells, bugs and vulnerabilities in Azure DevOps, Bitbucket and GitHub repositories.

Upsource JetBrain's on-premise git/mercurial/perforce/svn code review tool.

https://redd.it/ebx9rw
@r_devops
Is Chef.io already outdated?

With cloud providers offering both Serverless functions and Container Orchestration, is there still a need for software like Chef? What am I missing?

https://redd.it/eby66u
@r_devops
The #1 bug predictor is not technical, it's organizational complexity

I thought this one might be of interest here :)

TLDR: When Vista flopped after release, Microsoft Research took a deep-dive the Vista code base and tried to figure out what they could change to avoid flaky releases in the future.

What they found was that purely techical measurements like how complex the code is, the test coverage, how many bugs there were in the bug tracker, the number of dependencies, etc, is important, but the number one measure for predicting bugs according to their study was:

Organizational complexity!

https://augustl.com/blog/2019/best_bug_predictor_is_organizational_complexity/

EDIT: Direct link to the paper that this blog post describes in layperson's terms: https://www.microsoft.com/en-us/research/wp-content/uploads/2016/02/tr-2008-11.pdf

https://redd.it/ec9rpj
@r_devops
Best Resources to learn Window server

Hello,

I am about to involve in a deployment project which most components run on Window servers.I am not going to manage window servers after deployment but some knowledge of IIS, configuration, process management and networking are necessary for deployment.I know Linux a bit but no past experience in Window servers.Can you guys please recommend me some resources to learn an overview about Window servers?

https://redd.it/ec9vy4
@r_devops
What do you look for in a CI/CD tool?

I'm trying to figure out what I should be looking for in a CI/CD tool. There's a bunch of companies that have too many different features and whistles. What am I missing that I need in my life? Not interested in Jenkins - plugins and pipeline maintenance are annoying.

https://redd.it/ecewjm
@r_devops
VPO wants to invest a lot of money on On-prem infra, I suggested to better try go Cloud first... He doubts

**TL;DR:**
**I think that MGMT have some fear about the monthly billing of Cloud technologies instead of doing one BIG payment for On-premm infra. How can I present facts to solve this fear?**

So right now I'm the one IT guy who is trying to push everything into the Cloud/devops culture. The company is doing a great effort going agile already, Cloud and Devops are a little slow ATM.

I was requested recently to quote Windows Server licences and other stuff for out site. Let's say we need to invest 1000USD just to have the things needed and then start working on it. Told the boss to better try AWS/Azure first but he said *"well, if I'm gonna spend 10 usd this month but at the end of the year I will pay 1200 USD in total, what would be the benefit of using AWS?"*

I know he is not negligent, he have a real concern that wants to resolve. I'm trying to prepare some numbers to show them the estimated cost of using public cloud in maybe 2 or more years. Does anyone have any other advice to overcome this?

https://redd.it/ecf27w
@r_devops
Are you using SSH certificates (rather than keys)?

Github now support authentication via an OpenSSH certificate: [https://github.blog/2019-08-14-ssh-certificate-authentication-for-github-enterprise-cloud/](https://github.blog/2019-08-14-ssh-certificate-authentication-for-github-enterprise-cloud/).

However, I cannot find any recomendations for a certificate authority to manage these SSH certificates.

There seem to be numerous options surrounding certificate management for servers and productions environments, e.g. BLESS, CASSH etc.

**What would you know of / recommend for managing SSH certificates for developers to access Github?**

In an ideal world, this would allow for custom configuration by developer. It would be able to interact with an existing active directory to authenticate users attempting to create certificates and it would be a managed service.

https://redd.it/ecav32
@r_devops
Which PaaS or IaaS provider to choose (small startup)?

Hi. We're a team of 3 developers, with a very limited DevOps knowledge. I would like to find the best infrastructure provider, which will allow us to develop and deploy with ease, with a limited budget in mind.

Please consider the following setup:
\- 1 client (React.js / Preact)
\- 1 mobile app (React Native)
\- 1 Node.js app (API - GraphQL / Apollo)
\- 1 database (MongoDB)
\- storage for images
\- 2 envs (dev and prod)

With that in mind, which provider would you recommend? From what I understand, Heroku can become expensive very quickly. Is getting into PaaS a wise choice? Maybe there's an IaaS solution that's relatively easy to setup?

Any help will be appreciated.

https://redd.it/eccv2g
@r_devops
What are your best resources to learn observability?

As the title says. Also, which tools are you using to implement them?
I’d like to get the following:
- observability paradigms.
- tools to implement some paradigms.
- specific information about how to implement the paradigm in the above tools.

This usually comes as a regular question in r/devops, so it could be nice to have them aggregated.

https://redd.it/eckww2
@r_devops
Tar up working filesystem?

I want to make containers but I don’t want to have to get it working in a test environment, then do everything all over again to make a Dockerfile. And I don’t trust these scripts that auto generate a Dockerfile. I just want to tar up a working, running filesystem and use that as a container’s fs. Is this possible with existing container technologies?

https://redd.it/ecbj33
@r_devops
A cleaner multi-stage continuous deployment on Kubernetes of a Create React App with kustomize, helm and skaffold

Watch out front end developers, soon you too will be shipping web scale cloud native HTML!

Jokes aside, it's actually a pretty good overview of kustomize, skaffold, multi stage docker builds and all of the other yaml:

https://www.codepedia.org/ama/a-cleaner-multi-stage-deployment-on-kubernetes-of-a-create-react-app-with-kustomize-helm-and-skaffold

https://redd.it/ecoxzq
@r_devops
Do you really need multi-cloud strategy?

How will a multi-cloud be an option for an application where you have rich integration components such as APIs between applications. Latency is a big issue.

https://redd.it/ecpjau
@r_devops
“Ops by Code” - DevOps for Ops

Hello,

since DevOps is mostly used in the development context, I tried to write down my thoughts from the perspective of IT operations.

[https://medium.com/zoisays/ops-by-code-devops-for-ops-771d8cf6a22f?source=friends\_link&sk=6b403f9ed704bd0add9e750fe77d4de8](https://medium.com/zoisays/ops-by-code-devops-for-ops-771d8cf6a22f?source=friends_link&sk=6b403f9ed704bd0add9e750fe77d4de8)

What do you think?

https://redd.it/ecfygp
@r_devops
How to automatically build a project which is not mine?

All my services are based on docker images(*), automatically updated with Watchtower:

- the ones I get from Docker Hub
- and the ones I wrote myself, put in GitLab and have a CI/CD pipeline which is triggered when there is a new commit (and which builds an image and pushes it to a repository of mine)

There is now a project on GitHub I am interested in and would like to package in a docker image. A one-shot `docker build ...` is not difficult - the part I am not sure how to approach is the continuous updates of the image when the source (the project on GitHub above) changes.

The solution I will be using is to have nightly/hourly/... builds, which will eventually catch up with the changes and push a new image to my repository.

Are there better solutions (ones where I could have "something" trigger a build on my side)?

---
(*) while this question revolves around building docker images, it is the general approach I am really interested in (= how to "monitor for changes" a remote project)

https://redd.it/ecbgk0
@r_devops
Traefik 2 with GKE

Dear Peers,
Maybe someone can share your experience
Got following setup : GKE + Traefik as LB via Helm chart
At the moment, have to manually update the DNS A records to point to an externalIP , which gets assigned when we launch Traefik.
Looks like, it is not possible to assign static IP to Traefik to persist between restarts
I've tried following approach
1.gcloud compute addresses create gkestaticip --region

(\* tried alreadt both regional & global)
2. Setting **loadBalancerIP: 35.x.y.z**
No success, Traefik get a fresh IP from gcp the pool

Something i found on medium, though doesnt seem to work
[https://medium.com/faun/how-to-assign-external-ip-address-static-to-a-gcp-kubernetes-engine-service-c5be91cdcfd5](https://medium.com/faun/how-to-assign-external-ip-address-static-to-a-gcp-kubernetes-engine-service-c5be91cdcfd5)

https://redd.it/eca2ld
@r_devops