Reddit DevOps
288 subscribers
85 photos
32.6K links
Reddit DevOps. #devops
Thanks @reddit2telegram and @r_channels
Download Telegram
Weekly Self Promotion Thread

Hey r/devops, welcome to our weekly self-promotion thread!

Feel free to use this thread to promote any projects, ideas, or any repos you're wanting to share. Please keep in mind that we ask you to stay friendly, civil, and adhere to the subreddit rules!

https://redd.it/1wm4w4w
@r_devops
Transition to DevSecOps

Hi,

I try to transition from software engineer to DevSecOps but my teamlead is in that state that part can be done by ai more or less

My question is how much of the DevSecOps workflow is automated by ai and how much does it require a person, genuine question since I currently do not sit on that side of the table

https://redd.it/1wm6ov5
@r_devops
Senior engineer said "bastion hosts have been insecure and outdated for 10 years" what am I missing?

I know with the rise of zero trust we are more comfortable with direct access to systems but is it really true that bastion hosts have fallen out of favor in modern companies? What is the new school of thought when it comes to granting secure, monitored access to isolated systems?

Example: database living in prod only allows network traffic from two sources: normal api access via a load balancer and direct access to the underlying host os from one specific known host, the bastion host. The bastion host itself would also be behind a VPN and heavily secured to only allow access from specific developer systems using break glass credentials. My developer suggested we drop the bastion altogether and install a zero trust service on the db itself and the developer laptops to allow them to directly access the dbs.

https://redd.it/1wmdqfw
@r_devops
Where did everyone who was on HCP Vault Secrets end up?

HVS shut down some months ago, and I've been checking some of the write-ups on where people got pushed. HashiCorp's suggested replacement, which is HCP Vault Dedicated, works very differently. A lot of teams chose HVS because they didn't want to write Vault policies or set up authentication themselves, and moving to Dedicated means doing exactly that. The pricing changes too, since you pay for the cluster plus a monthly fee for every app or CI runner that connects to it. A breakdown I saw priced a small production setup with 50 clients at around $4,800 a month. I can't say how representative that is, but it's a long way from per-secret pricing.

For anyone who was on HVS, where did you move, and how hard was it to rewire the integrations?

https://redd.it/1wmgg11
@r_devops
How does your team decide who's allowed to approve risky code changes?

My team's approval process used to just be "ask whoever's around," but now that AI is generating a lot more code, that doesn't really hold up anymore — small changes get the same scrutiny as changes to things like payments or auth, and there's no real record of who actually signed off on what.

Curious how other teams handle this. Do you have actual rules for what needs extra scrutiny and who's allowed to approve it, or is it still pretty informal? How's that going as the volume of changes keeps going up?

https://redd.it/1wmx38d
@r_devops
Trying to get into DevOps. Any suggestions

I've been working as a software engineer for 1.5 years. I want to enter devOps. I'm already good at docker, python, azure.

What else do I need to learn.

Also please suggest certifications, courses, youtube playlists etc.

https://redd.it/1wn2epg
@r_devops
What are your best SRE/DevOps time savers?

Curious what you guys have seen or used that ended up being really useful or saving a ton of time. Could be an automation, internal tool, bot, process, script, platform, or just a small thing that saved a lot of time.

Something you built yourself, or something that was already there when you joined.

What was it?

https://redd.it/1wn4d6w
@r_devops
How do you manage dashboards throughout multiple OpenSearch instances

Hi all,

We operate applications that are shipping logs to 9 OpenSearch instances currently. The objects and dashboards are pretty much always the same but with different namespaces / indexes etc. I was wondering if you also had this trouble what the most convenient way of operation here is. Ideally, I would love to store everything in Git as well but I don't know if there is a more convenient way than doing templating and then letting a GitLab runner execute some API calls for import / updating of objects.

https://redd.it/1wn6zut
@r_devops
What are your tips and tricks for building resiliency into your solutions?

Just wanting to hear industry professionals share their favorite tips and tricks for building. Here are some of mine:

1. Federated Credentials or Hashi Vault to ensure no unexpected expired secrets

2. Adding robust logging as a flag in my own scripts and solutions

3. Adding an alert channel to teams when something breaks or isn't working correctly with a link to the errored line or run

4. Adding a custom agent for every solution codebase

5. Using a team solution stack agent that outlines standards across solutions so throughout our team, we have consistent terminology.

6. Building robust QA testing that gets automated tested once a week to ensure it's not broken when I need it most.

https://redd.it/1wn8veb
@r_devops
Configuration management

Hello all, though I have quite a long experience, I never had to set up a configuration management system for a fleet of applications.
Let me explain better: we deploy our microservices to kubernetes, each with its own configuration. We currently have a jenkins job that creates an application.json (we use .net) that is then deployed as a configmap to kubernetes and referenced in the deployment.

This needs to go away and I said we need to use configmaps and secrets to populate the environment of the app to override the values of the baked in application.json. All good.

Then I started looking for solutions. In the past I worked in a place where we were using Ansible for this task, with many levels (up to 7) and a playbook that will read yaml files in order, merge the values and come up with the final list.

That tends to produce unnecessary duplicates, if I am not sure that a var is defined at level 3 and I have to (re)define it at level 5, I will write it there, then maybe in another level 5 yaml file and lose the hierarchy.

So I was looking at something with a UI that would allow developers to see what they are doing and, at the same time, would provide some sort of access control, to allow access to sensitive data only to trusted colleagues.

I restricted the list to OpenBAO, Infisical and Phase, but all of them have some kind of limit:
- OpenBAO has the same problem as Ansible, you can't see the final result in the UI;
- Phase supports only generation of Secrets, while I need to generate both Configumaps and Secrets (still for Access Control: some users can read only Configmaps, some Secrets too);
- Infisical: it is very expensive and I have just found that you can't get a Pro licence for a self-hosted instance, but you have to go directly to Enterprise, or use their Cloud solution (and I don't find too safe to write my sensitive information in a Cloud solution);

What are you using? Is there some tool I missed?

EDIT: I don't intend to use Ansible!!!!

https://redd.it/1wnb752
@r_devops
4 LPA DevOps fresher — take it or negotiate for more?

I'm finishing 4 months of my DevOps internship at a company, and from October I'll be joining full-time as an Associate DevOps Engineer.

They've offered me 4 LPA (\~₹28K in-hand). I tried negotiating, and they gave me two options:

1. Take a higher package now, but no appraisal/hike in April.

2. Take 4 LPA now and get reviewed in April based on my performance.

I'm confused.

If I take 4 LPA, I'll have around 6 months of full-time experience by April, plus my internship experience. But I don't know how much hike to realistically expect.

If I take the higher package now, I could start applying elsewhere around Jan/Feb and try to switch in April. But by then I'll have only \~3–4 months of full-time experience. Not sure how realistic it is to target 6–7 LPA with that experience.

What would you guys do? Especially people in DevOps/Cloud/SRE — would you take the appraisal route or higher salary now?

https://redd.it/1wni747
@r_devops
For engineers working with Terraform/OpenTofu: what parts of the work are still painful?

For engineers who work with Terraform/OpenTofu and cloud infrastructure:

I'm curious about the day-to-day parts of the work that tend to be repetitive, manual, frustrating, or easy to get wrong.

Not really looking for opinions about which tools are better. I'm more interested in things that **actually happened**.

A few questions:

* Think about the **last Terraform/OpenTofu PR you reviewed**. What did you check, and in what order?
* What's an infrastructure task you did recently that you've already done many times before?
* When was the last time a security scanner flagged something in your infrastructure code? What happened next?
* Have you recently had to check whether a change behaved differently across Terraform versions or between Terraform and OpenTofu? How did you check?
* What's the last infrastructure change that caused a problem or had to be rolled back? How did you discover it?
* Have you ever written a script or small internal tool to automate one of these repetitive tasks? What happened to it?
* If you could permanently remove one infrastructure-related task from your weekly workload, what would it be?

https://redd.it/1wn534a
@r_devops
Small team running 350k+ monthly visitors on managed infra. At what point is owning the infrastructure worth it?

We’ve been running our product on Next.js + Vercel and Supabase. It’s been working well. We’re at 350k+ monthly visitors, around 12k registered users, with web, Android, and Windows apps. Our current infrastructure cost is around $60–70/mo.

We’re now building a second related product, so we’ve started thinking more seriously about infrastructure.

VPS keeps coming up as the obvious cheaper option, but I’m the only one developing right now, so that could add quite a bit of overhead. I might hire someone for the infra side. The whole reason we went with managed services was so we didn’t have to worry about servers.

For people who’ve actually made this switch:

• Is VPS + something like Coolify/Dokploy reasonable for a small team, or is the maintenance overhead bigger than it looks?

• Is there a good middle ground with services like Render, Railway, Fly, or managed Postgres like Neon?

• Does having mostly regional traffic change when it makes sense to move to self-hosting?

• If we do move with two products, would you run both on shared infrastructure or keep them separate?

We just want to make a proper decision before the setup gets more complicated.

https://redd.it/1wnvw3f
@r_devops
How is EscBash?

I want to master DevOps part. I know Linux, Shell Scripting, Docker, AWS and Azure Functions.

I learnt half of it from Abhishek's channel.

Wanted to know if his EscBash subscription is worth it and is actually different from his other content?

Background: I work as a Backend Developer with C#, .NET, Typescript, Node.js, Azure as the stack.

https://redd.it/1wnzs5w
@r_devops
What did you actually do the last time you changed a shared module and didn't know who used it?

Not after best practice, after what actually happened.

Last time you changed a shared module / base image / Helm chart / reusable workflow; how did you work out who'd be affected before you shipped? I've seen it done with grep, with a spreadsheet someone maintained until they left, and with "ship it and see who shouts in Slack", and I don't know which of those are normal.

Rough org size helps if you're willing to say. My assumption is this is a non-problem under \~50 repos and a different animal at 300, but that's a guess and I'd like it corrected.

Asking because I keep getting two completely different answers depending on who I talk to, and I can't tell which one is normal.

https://redd.it/1wo5fyv
@r_devops
I got asked this In a new grad role interview

In an interview for a new grad devops role got asked this. “Who typically owns access to corporate applications: IAM engineers, IT staff, application administrators, or Platform/DevOps engineers?”
How would yall answer

https://redd.it/1wo6dzk
@r_devops
Contractually obligates to update within 3 weeks

So I'm working as main IT guy for a startup, but now we got a contract from the lawyers stating that everytime there is an update we need to have it applied within 3 week. And with everything they mean EVERYTHING, bios updates, kubernetes versions,...

Is this possible, how do you guys handle this or should I say 'this ain't possible, we will to high severity patches in 3 weeks, but nothing more..'??

More info, it's indeed for insurance and the insurance is coming from investors and customers

https://redd.it/1wob1os
@r_devops
Should Devops debug business logic problems ?

I work at a company where my manager decided to remove all the dev access from the production, because they suggest random solution to problems we encounter on production (For e.g they saw that the servers CPU usage is high so they point this as the source of a problem and suggest to restart the service).

That's good but that also restrict them frol seeing live production logs so we need to manually send them the log when there are customers complaints.

My boss proposed another solution which is to learn to business logic of the code itself and debug it ourselves. We then send them evidence + solution, not only logs.

My question is: is this common, should DevOps understand the logic behind an app we deployed and should we identify the root cause of a problem ourselves ?

https://redd.it/1wob57u
@r_devops
CronJobs exceeding their quota

I hope you guys can help; I'm losing my mind.

We have a few jobs setup in our routine in the company which basically poll data from a partner for changes. The problem is this volume of data has grown so much that it:

\- A: Doesn't fit in memory, so I scaled verically.

\- B: Doesn't fit in the time frame anymore. Extending the time limit isn't an option, because it's supposed to finish in under 30 mins because we have other deps.

https://redd.it/1wofkym
@r_devops
How did u find ur first job as a DevOps engineer?

Hi, first of all sorry for my English I'm not a native speaker. I have probably a very common question but I didn't find any info here or anywhere else that gives me any light.

Context: I'm a full stack developer and I have been working for almost five years developing different kind of apps (web apps, desktop apps, libraries, APIs, installers, etc). Two years ago I had a chance in my previous job to build pipelines with gitlab and github, and since then I haven't stop learning. I even deploy a local Jenkins server and build fully functional pipelines that build, test and deploy the back and the front of an app I'm currently developing. I'm now learning a couple things of Azure DevOps.

Now I want to know how did u find DevOps offers? I'm sending at least 1 CV per day. I'm apllying as a junior, also as a semi senior and senior. I don't know why but I didn't even receive a reject mail. I mean there has to be a reason, maybe is the way I built my CV, which is in ATS format. How did u guys (and girls) find DevOps jobs.

Note: I almost forgot this but in my current job I tried to get involved in DevOps stuff, since they are starting to migrate to this practices but they always push me aside, that's why I want to move on to another job.

https://redd.it/1wodqzw
@r_devops